Report Content

EU and NATO respond in 2026 to Russian hybrid attacks — why a protocol does not replace deterrence

On September 28, 2026, EU states discussed a NATO-like response to Russian hybrid attacks. The proposal is politically noteworthy, but militarily still empty. It primarily shows that Europe is now talking about sabotage, disinformation, and attacks on critical infrastructure as if it were a common defense case — without yet having the institution that could turn this into a reliable response.

This is the real contradiction. The EU has sanctions instruments, NATO has Article 5 and military command structures. However, there is a gray area in between where a damaged undersea cable, a fire in a logistics facility, or a cyberattack are politically difficult to attribute. This is exactly where Moscow operates.

A NATO model without Article 5

NATO hybrid warfare communications network with armored vehicles and satellite links

According to reports from Politico and Euronews, European governments are considering a joint procedure that would allow for faster consultations, a common attribution, and coordinated countermeasures after a hybrid attack. This sounds like NATO, but it is something different. Article 5 contains a political commitment to collective assistance; an EU protocol would initially be just a decision-making mechanism.

This distinction is not academic. In a conventional attack, the target, weapon, and perpetrator are usually visible. In the case of sabotage, investigators must piece together evidence from intelligence services, telecommunications data, and forensic analyses. This makes the political decision slower — and the attacker gains time to sow doubt. A protocol can shorten this delay. However, it cannot automatically improve the evidence situation or relieve member states of the political will to hold Russia publicly accountable.

The EU already has a framework for resilience, attribution, and sanctions with its Hybrid Toolbox. The problem is not the complete absence of instruments, but their fragmentation. Foreign policy, internal security, cyber defense, and military deterrence fall under different jurisdictions. An attack on a power grid is primarily a security issue, while an attack on a NATO base is an alliance issue. Russia exploits this institutional separation.

Why more coordination is not yet deterrence

The debate comes at a time of growing concern about Russian sabotage attempts in Europe. Reuters reported on September 23 that European governments see an increasing shadow war activity, but do not anticipate an imminent Russian attack on NATO. This combination is strategically dangerous: the threat is serious enough to incur costs, but ambiguous enough not to trigger an automatic military response.

This is attractive for Moscow. A hybrid attack does not need to go undetected to be successful. It is sufficient if the response from the affected parties is slow, nationally fragmented, or legally disputed. The operational gain lies in the delay. A damaged cable forces Europe not only to repair it but also to discuss whether it was even an attack.

Therefore, a European protocol would only make sense if it defines three concrete thresholds. First, it must be clear which national authorities will exchange information within a few hours. Second, there needs to be a common evidence and attribution structure that does not start from scratch with each incident. Third, countermeasures must be predetermined — such as coordinated sanctions, protection of critical infrastructure, and the enhancement of military surveillance.

Without these pre-decisions, the protocol remains another declaration of European readiness to act. Europe already has many of those. What is missing is not the next political formula, but the ability to apply it under time pressure.

NATO remains indispensable

An EU mechanism must not be misunderstood as a substitute for NATO structures. NATO possesses military situational awareness, integrated air and naval forces, as well as American capabilities for intelligence gathering and strategic communication. The EU can coordinate sanctions, organize civilian resilience, and protect the internal market. However, it cannot quickly duplicate the entire military deterrence of the alliance.

Germany, in particular, should clearly articulate this boundary. Berlin rhetorically supports European sovereignty but remains dependent on transatlantic structures for intelligence, satellite communication, and extensive air defense. An EU protocol that obscures this dependency would be institutional cosmetics. A protocol that reveals it and clarifies the division of labor between the EU and NATO could, on the other hand, be useful.

The crucial question, therefore, is not whether Europe announces a NATO-like response. What matters is whether an attack on a cable, a satellite link, or a logistics chain triggers a common political and operational response within 24 hours. If the response continues to depend on national vetoes and unclear attribution, deterrence remains weak.

Europe's uncomfortable choice

The debate about hybrid attacks is a step forward because it no longer accepts the old dichotomy between war and peace. However, institutional progress must not be confused with military capability. A protocol can shorten Europe's reaction time; it cannot eliminate Europe's dependence on American intelligence and NATO leadership overnight.

Europe thus faces a sober dilemma. It must respond to hybrid attacks collectively without duplicating NATO, and it must build its own capabilities without postponing the response for years. More coordination is necessary, but it is not yet deterrence. The bitter truth is: Europe can afford a process that is too slow — Russia can exploit it.

Sources: Politico, EU seeks NATO-style response to Russian hybrid attacks, 28.09.2026; Euronews, Increased Russian sabotage attempts prompts EU response, 28.09.2026; Reuters, Europeans warn of rising Russian sabotage but see no imminent NATO attack, 23.09.2026; European Union, EU Hybrid Toolbox; NATO, Hybrid threats and resilience.

Classification
Region
Europe
Analytical Domain
Strategic
Primary Category / Secondary Categories
Political-Military / Information Operations
SALUTE Report
Size
Not specified
Activity
Discussion of a NATO-like response to Russian hybrid attacks
Location
Europe
Unit
European Union, NATO
Time
September 28, 2026
Equipment
-
Summary

On September 28, 2026, EU states discussed a NATO-like response to Russian hybrid attacks, highlighting the need for faster consultations and coordinated measures. The proposal lacks military substance and is primarily a political mechanism, as Russia exploits the institutional separation between security and military responses. The EU has resilience tools but needs a unified framework to effectively respond to hybrid threats.

Key Facts
  • EU states discussed a NATO-like response to Russian hybrid attacks on September 28, 2026.
  • The proposal lacks military substance and is primarily a political mechanism.
  • Russia is exploiting the institutional separation between security and military responses in Europe.
  • The EU has tools for resilience and sanctions but lacks a unified military response framework.
  • A protocol for hybrid attacks could improve response times but does not replace NATO's military capabilities.

Related Entities

Belligerent