
Deterrence by dismantlement: Europe must make sabotage harder to repeat
Europe's answer to physical hybrid attack should be deterrence by dismantlement: pooling protective capabilities and disrupting the networks that enable sabotage, so each investigation leaves an adversary fewer means to repeat it.
On 8 September, Romania's intelligence service announced that it had prevented a Russian-coordinated sabotage operation involving surveillance of military facilities and Ukrainian cargo aircraft. A week earlier, Germany attributed August's attempted explosive-drone attack at Leipzig/Halle airport to Russia. These cases demand operational deterrence and defence alongside resilience against physical hybrid threats. At the 15–16 October European Council, leaders should agree to pool protective capabilities and disrupt enabling networks, backed by a protocol under the EU Hybrid Toolbox for rapid assessment and response. The objective should be deterrence by dismantlement: reducing adversaries' capacity to organise and repeat attacks.
Resilience needs operational protection
Europe has strengthened its response to disinformation, propaganda and election interference through the Foreign Information Manipulation and Interference Toolbox and closer coordination. It has also adopted cable-security and counter-drone plans. The next step is to connect these commitments to readily available capabilities, overcoming the institutional divisions between intelligence, infrastructure protection and law enforcement.
The distinction between digital and physical threats is increasingly misleading. An August investigation disclosed that December's cyberattack on a Polish heat-and-power plant had stopped a steam turbine. Operators prevented disruption to household heating. That successful response demonstrates the value of resilience, but also the need to prevent hostile access from becoming physical disruption.
Protecting information spaces cannot stop an explosive drone or defend a cable landing station. Nor can authorities rely indefinitely on expensive interceptors against inexpensive drones. Ukraine's experience points towards layered protection using affordable systems that can be upgraded rapidly. Protection must extend to ports, energy installations and transport hubs inside Europe, not only its external borders.
Sabotage can force Europeans to divert resources, undermine confidence in essential services and complicate support for Ukraine. A damaged connection may be repaired quickly; persistent uncertainty about whether the next attack can be stopped carries a broader political cost. Repeated disruption can become coercion without approaching the threshold of conventional war.
Dismantle the means of attack
Deterrence by dismantlement would connect this protective effort to sustained action against the people, financing and logistics enabling attacks. It complements deterrence through denial and punishment; it does not replace them. Its contribution is to make disruption cumulative: each investigation should leave an adversary with fewer usable networks and resources.
There is a tested foundation. In March, a joint investigation supported by Eurojust and Europol identified 22 suspects in a cross-border parcel-arson campaign. Such cooperation can connect offences that appear isolated nationally. However, arresting expendable recruits will have limited deterrent value if recruiters, payment channels and logistical intermediaries remain available. Investigations should therefore systematically pursue the enabling network, not conclude with the immediate perpetrator.
There are legitimate objections. National authorities control security operations; intelligence cannot always be disclosed; premature attribution risks error and escalation. A common protocol should not lower evidential standards or transfer command to Brussels. Protective deployments need not await public attribution, while coercive measures require a sound legal basis and review. NATO should retain its collective-defence role. The alternative, fragmented national responses, leaves adversaries opportunities to relocate their activities and impose repeated disruption on European services and support for Ukraine.
Give dismantlement an operational timetable
October's European Council should set three tasks.
First, the High Representative and Commission should present the protocol by December, implementing Council's March conclusions on hybrid threats. Following a serious suspected physical hybrid attack, the EU Hybrid Fusion Cell should aim to provide a preliminary assessment within 24 hours, drawing on national reports and stating uncertainties. Within 72 hours, ministers should receive response options identifying the responsible authority, legal basis and available resources. Immediate protection must not wait for this process.
Second, the Commission's plan to explore rapid counter-drone teams by year-end should produce national commitments to a deployable pool by June 2027. Member States should earmark crews, mobile sensors and affordable interception systems, agreeing assistance requests, deployment permissions and command arrangements beforehand. The joint European drone and seabed defence projects proposed in July should prioritise these capability gaps, including surveillance and inspection equipment around critical cables. Member States should finance initial standby capacity, using the European Defence Industry Programme for eligible joint capability development. Funding must cover maintenance and regular upgrades, informed by Ukraine's experience.
Third, national prosecutors should use Eurojust-supported joint investigations whenever evidence links attacks across borders, with Europol tracing associated networks. The Council should promptly assess Germany's proposed hybrid-sanctions listings. Member States should pair any listings with investigations into the organisers' financial and logistical support, pursuing criminal asset seizures where the evidence permits. By June 2027, ministers should review deployment times, protective equipment actually available and networks disrupted. A joint exercise with NATO and infrastructure operators should test the protocol across drone, cable and energy incidents.
Inaction would leave Europe paying repeatedly to restore services while hostile networks reconstitute. October should mark a shift from commitments to capabilities. Europe's answer to the next attack should leave fewer means for the one after it.
How to cite
Council on Operational Resilience in Europe (2026). Deterrence by dismantlement: Europe must make sabotage harder to repeat. Council on Operational Resilience in Europe, Sofia.
Related publications
All publications- From minerals to missions: Europe's military AI imperative
- Retool Europe: put idle industry to work for defence
- Unorthodox Warfare: The Russian Orthodox Church and the Kremlin's Hybrid Warfare in the Sahel
- Data Spaces Against Hybrid Warfare: A Novel Way to Achieve Resilience
- The Role of Dual-Use Technologies in Hybrid Warfare: A Double-Edged Sword?
- Is Hybrid Warfare Changing due to Climate Change?
- Hybrid Warfare: How to Escape the Conceptual Gray-Zone
- Revolutionising Hybrid Warfare: The Role of Artificial Intelligence
- The Decline of Russian Hybrid Warfare? Lessons From Ukraine
- In Search of Hybrid Warfare: The Chinese Doctrine
- NATO Cyber Defence Policy and Hybrid Threats: The Way to Enhance Our Resilience