Deterrence by dismantlement: Europe must make sabotage harder to repeat

The Council on Operational Resilience in Europe (CORE) is a next generation think-and-do tank going beyond traditional research, events and strategy. We offer operational technology, consultancy and exercises so you become resilient to today's challenges.



We cover the entire resilience value chain, from conducting secure research to empowering the society to withstand pressure. We leverage our experience across academia, the innovation ecosystem, government and the international community, including NATO, the European Union and the World Bank.
Protect the foundations of innovation by safeguarding research, intellectual property, sensitive data and trusted partnerships throughout the creation, collaboration and exchange of valuable knowledge.

Martin examines the development of defence and national security AI systems and the conditions European companies face when building a product in this field.
Ivan argues what happens when AI agents interact with one another without direct human participation, and what such systems may mean in practice.
For government institutions
For critical infrastructure operators
For research organisations
For local authorities and communities
For private companies
For investors and fund managers
On 8 September, Romania's intelligence service announced that it had prevented a Russian-coordinated sabotage operation involving surveillance of military facilities and Ukrainian cargo aircraft. A week earlier, Germany attributed August's attempted explosive-drone attack at Leipzig/Halle airport to Russia. These cases demand operational deterrence and defence alongside resilience against physical hybrid threats. At the 15–16 October European Council, leaders should agree to pool protective capabilities and disrupt enabling networks, backed by a protocol under the EU Hybrid Toolbox for rapid assessment and response. The objective should be deterrence by dismantlement: reducing adversaries' capacity to organise and repeat attacks.
Resilience needs operational protection
Europe has strengthened its response to disinformation, propaganda and election interference through the Foreign Information Manipulation and Interference Toolbox and closer coordination. It has also adopted cable-security and counter-drone plans. The next step is to connect these commitments to readily available capabilities, overcoming the institutional divisions between intelligence, infrastructure protection and law enforcement.
The distinction between digital and physical threats is increasingly misleading. An August investigation disclosed that December's cyberattack on a Polish heat-and-power plant had stopped a steam turbine. Operators prevented disruption to household heating. That successful response demonstrates the value of resilience, but also the need to prevent hostile access from becoming physical disruption.
Protecting information spaces cannot stop an explosive drone or defend a cable landing station. Nor can authorities rely indefinitely on expensive interceptors against inexpensive drones. Ukraine's experience points towards layered protection using affordable systems that can be upgraded rapidly. Protection must extend to ports, energy installations and transport hubs inside Europe, not only its external borders.
Sabotage can force Europeans to divert resources, undermine confidence in essential services and complicate support for Ukraine. A damaged connection may be repaired quickly; persistent uncertainty about whether the next attack can be stopped carries a broader political cost. Repeated disruption can become coercion without approaching the threshold of conventional war.
Dismantle the means of attack
Deterrence by dismantlement would connect this protective effort to sustained action against the people, financing and logistics enabling attacks. It complements deterrence through denial and punishment; it does not replace them. Its contribution is to make disruption cumulative: each investigation should leave an adversary with fewer usable networks and resources.
There is a tested foundation. In March, a joint investigation supported by Eurojust and Europol identified 22 suspects in a cross-border parcel-arson campaign. Such cooperation can connect offences that appear isolated nationally. However, arresting expendable recruits will have limited deterrent value if recruiters, payment channels and logistical intermediaries remain available. Investigations should therefore systematically pursue the enabling network, not conclude with the immediate perpetrator.
There are legitimate objections. National authorities control security operations; intelligence cannot always be disclosed; premature attribution risks error and escalation. A common protocol should not lower evidential standards or transfer command to Brussels. Protective deployments need not await public attribution, while coercive measures require a sound legal basis and review. NATO should retain its collective-defence role. The alternative, fragmented national responses, leaves adversaries opportunities to relocate their activities and impose repeated disruption on European services and support for Ukraine.
Give dismantlement an operational timetable
October's European Council should set three tasks.
First, the High Representative and Commission should present the protocol by December, implementing Council's March conclusions on hybrid threats. Following a serious suspected physical hybrid attack, the EU Hybrid Fusion Cell should aim to provide a preliminary assessment within 24 hours, drawing on national reports and stating uncertainties. Within 72 hours, ministers should receive response options identifying the responsible authority, legal basis and available resources. Immediate protection must not wait for this process.
Second, the Commission's plan to explore rapid counter-drone teams by year-end should produce national commitments to a deployable pool by June 2027. Member States should earmark crews, mobile sensors and affordable interception systems, agreeing assistance requests, deployment permissions and command arrangements beforehand. The joint European drone and seabed defence projects proposed in July should prioritise these capability gaps, including surveillance and inspection equipment around critical cables. Member States should finance initial standby capacity, using the European Defence Industry Programme for eligible joint capability development. Funding must cover maintenance and regular upgrades, informed by Ukraine's experience.
Third, national prosecutors should use Eurojust-supported joint investigations whenever evidence links attacks across borders, with Europol tracing associated networks. The Council should promptly assess Germany's proposed hybrid-sanctions listings. Member States should pair any listings with investigations into the organisers' financial and logistical support, pursuing criminal asset seizures where the evidence permits. By June 2027, ministers should review deployment times, protective equipment actually available and networks disrupted. A joint exercise with NATO and infrastructure operators should test the protocol across drone, cable and energy incidents.
Inaction would leave Europe paying repeatedly to restore services while hostile networks reconstitute. October should mark a shift from commitments to capabilities. Europe's answer to the next attack should leave fewer means for the one after it.
On 8 September, Romania's intelligence service announced that it had prevented a Russian-coordinated sabotage operation involving surveillance of military facilities and Ukrainian cargo aircraft. A week earlier, Germany attributed August's attempted explosive-drone attack at Leipzig/Halle airport to Russia. These cases demand operational deterrence and defence alongside resilience against physical hybrid threats. At the 15–16 October European Council, leaders should agree to pool protective capabilities and disrupt enabling networks, backed by a protocol under the EU Hybrid Toolbox for rapid assessment and response. The objective should be deterrence by dismantlement: reducing adversaries' capacity to organise and repeat attacks.
Resilience needs operational protection
Europe has strengthened its response to disinformation, propaganda and election interference through the Foreign Information Manipulation and Interference Toolbox and closer coordination. It has also adopted cable-security and counter-drone plans. The next step is to connect these commitments to readily available capabilities, overcoming the institutional divisions between intelligence, infrastructure protection and law enforcement.
The distinction between digital and physical threats is increasingly misleading. An August investigation disclosed that December's cyberattack on a Polish heat-and-power plant had stopped a steam turbine. Operators prevented disruption to household heating. That successful response demonstrates the value of resilience, but also the need to prevent hostile access from becoming physical disruption.
Protecting information spaces cannot stop an explosive drone or defend a cable landing station. Nor can authorities rely indefinitely on expensive interceptors against inexpensive drones. Ukraine's experience points towards layered protection using affordable systems that can be upgraded rapidly. Protection must extend to ports, energy installations and transport hubs inside Europe, not only its external borders.
Sabotage can force Europeans to divert resources, undermine confidence in essential services and complicate support for Ukraine. A damaged connection may be repaired quickly; persistent uncertainty about whether the next attack can be stopped carries a broader political cost. Repeated disruption can become coercion without approaching the threshold of conventional war.
Dismantle the means of attack
Deterrence by dismantlement would connect this protective effort to sustained action against the people, financing and logistics enabling attacks. It complements deterrence through denial and punishment; it does not replace them. Its contribution is to make disruption cumulative: each investigation should leave an adversary with fewer usable networks and resources.
There is a tested foundation. In March, a joint investigation supported by Eurojust and Europol identified 22 suspects in a cross-border parcel-arson campaign. Such cooperation can connect offences that appear isolated nationally. However, arresting expendable recruits will have limited deterrent value if recruiters, payment channels and logistical intermediaries remain available. Investigations should therefore systematically pursue the enabling network, not conclude with the immediate perpetrator.
There are legitimate objections. National authorities control security operations; intelligence cannot always be disclosed; premature attribution risks error and escalation. A common protocol should not lower evidential standards or transfer command to Brussels. Protective deployments need not await public attribution, while coercive measures require a sound legal basis and review. NATO should retain its collective-defence role. The alternative, fragmented national responses, leaves adversaries opportunities to relocate their activities and impose repeated disruption on European services and support for Ukraine.
Give dismantlement an operational timetable
October's European Council should set three tasks.
First, the High Representative and Commission should present the protocol by December, implementing Council's March conclusions on hybrid threats. Following a serious suspected physical hybrid attack, the EU Hybrid Fusion Cell should aim to provide a preliminary assessment within 24 hours, drawing on national reports and stating uncertainties. Within 72 hours, ministers should receive response options identifying the responsible authority, legal basis and available resources. Immediate protection must not wait for this process.
Second, the Commission's plan to explore rapid counter-drone teams by year-end should produce national commitments to a deployable pool by June 2027. Member States should earmark crews, mobile sensors and affordable interception systems, agreeing assistance requests, deployment permissions and command arrangements beforehand. The joint European drone and seabed defence projects proposed in July should prioritise these capability gaps, including surveillance and inspection equipment around critical cables. Member States should finance initial standby capacity, using the European Defence Industry Programme for eligible joint capability development. Funding must cover maintenance and regular upgrades, informed by Ukraine's experience.
Third, national prosecutors should use Eurojust-supported joint investigations whenever evidence links attacks across borders, with Europol tracing associated networks. The Council should promptly assess Germany's proposed hybrid-sanctions listings. Member States should pair any listings with investigations into the organisers' financial and logistical support, pursuing criminal asset seizures where the evidence permits. By June 2027, ministers should review deployment times, protective equipment actually available and networks disrupted. A joint exercise with NATO and infrastructure operators should test the protocol across drone, cable and energy incidents.
Inaction would leave Europe paying repeatedly to restore services while hostile networks reconstitute. October should mark a shift from commitments to capabilities. Europe's answer to the next attack should leave fewer means for the one after it.