- ANALIZA
- WIADOMOŚCI
How Europe must respond to Russian hybrid attacks
Europe is facing permanent hybrid operations conducted by the Russian Federation, aimed at internal destabilisation, weakening response capabilities and undermining the position of European states within allied structures. The response cannot be limited to defensive and reactive measures alone.
It is necessary to pursue a multi-layered policy of deterrence, in which the military, cyber, economic and information components function as part of one coordinated strategy. The Director General of the Estonian Foreign Intelligence Service has pointed out that the key challenge remains maintaining the logic of deterrence in the long term – in one year, three years, five years and ten years. This is fundamental for the security of the Alliance, especially as Russia will try to slow down European rearmament through hybrid activities rather than through direct military escalation.
A coherent and conscious information policy
Europe needs a coherent and conscious information policy that does not merely react to crises, but builds societal resilience, not for years, but for decades. Three elements are crucial: media literacy, transparency of state institutions in situations of threat, and the rapid and reliable communication of facts by governments and armed forces. Only in this way can the space in which Russian disinformation operates be reduced.
Societies must understand that information hygiene is part of national and European security, just as important as the defence of borders or critical infrastructure.
An additional element should be active prevention in the information domain. This means not only countering disinformation, but also building public awareness of the nature of modern information operations. A society resilient to manipulation becomes part of the security system. That is why media education, fast and reliable communication by public institutions, and transparency in crisis situations should become a permanent component of European security strategies.
It must be stressed that Russia does not need a military victory in order to achieve its objectives. It is enough for Moscow to weaken Europe’s ability to distinguish truth from falsehood and to make citizens doubt their own institutions. Therefore, the answer cannot be only counter-narratives, but the conscious building of cognitive resilience. Such actions must be carried out in schools, the media, administration and everyday civic life. The war being fought today is not only taking place in trenches, but also in people’s minds. At this moment, Russia remains on the offensive, while Europe is too often on the defensive.
Strengthening critical infrastructure
Another recommendation, based on the experience of hybrid attacks, concerns the need to strengthen the protection of critical infrastructure – from transport, energy and telecommunications to water supply systems. This is crucial because any disruption to the continuity of such infrastructure may lead to a loss of control over the economy at local or national level depending on the scale of the threat, undermine territorial integrity and significantly reduce the resilience of the population.
The fact that so many important infrastructure projects are currently being developed across Europe – including nuclear power plants, offshore wind farms linked to the energy transition, railway modernisation, road infrastructure and logistics hubs – gives hostile services another field of activity. This creates the need to secure such projects through appropriate solutions at state and European level.
Actions in cyberspace
In cyberspace, Europe should develop the concept of active defence, based not only on responding to incidents, but also on precisely disrupting the infrastructure and tools used by groups sponsored by Russia. This makes it possible to reduce the scale of threats before they escalate.
Coordination between national cyber commands, CERT structures, intelligence services and NATO partners should be permanent, not incidental. Offensive actions in cyberspace, conducted below the threshold of armed conflict, are a real tool of deterrence. They do not require the use of military force, but they can produce tangible operational and psychological effects.
European states can conduct such activities together with NATO allies, as cyber forces are being constantly developed across the Alliance. Some countries, including Poland, have already created advanced military cyber structures, which should provide a positive impulse for further development across Europe.
Military activity in cyberspace should be complemented by counter-intelligence and preventive measures carried out by national security services. The Polish Internal Security Agency, for example, has launched a special Telegram chatbot allowing people to report sabotage attempts or recruitment efforts by foreign services quickly and anonymously. This is particularly important because Telegram remains one of the main platforms used by hostile services to recruit so-called “disposable agents”, often through apparently harmless job offers or small paid tasks.
See also 
Cooperation between Kyiv and Europe
European states must strengthen cooperation with Kyiv in order to identify, track and prosecute individuals suspected of sabotage or diversion. One negative example was the incident involving a parcel containing explosive material found in a warehouse at a sorting facility in central Poland. So far, the only person convicted in that case has been Kristina S., who was fined more than PLN 18,000.
It should be emphasised that the people who planned to send explosive devices remain at large, including the key figure in the case, Yurii Kovalenko. He is wanted by the Provincial Police Headquarters in Katowice and is also subject to an Interpol Red Notice. However, the case files indicate that Ukrainian services will not hand over their citizen to Poland.
This case also highlighted the need to tighten procedures for inspecting vehicles at eastern border crossings. According to information from the Border Guard and Customs Service, Kristina’s vehicle was X-rayed on its way to Poland, but officers focused mainly on traces related to the smuggling of alcohol and cigarettes.
The Ukrainian side should intensify its efforts to prevent and combat acts of sabotage and diversion carried out by its citizens. At the same time, every effort should be made to deepen information cooperation with European partners, as its current scope remains limited.
Similar shortcomings can be seen in cooperation between special services. It is in the interest of the government in Kyiv to communicate more clearly how Russian services recruit Ukrainian citizens. The current message, supported by the figures mentioned in the report, reinforces a narrative in which Ukrainians appear to be the sole perpetrators of sabotage activities. This must be countered in the information sphere. Individuals holding Ukrainian passports may be responsible for specific actions, but part of the responsibility also lies with the authorities in Kyiv and Ukrainian embassies across Europe, including in Warsaw.
The Ukrainian offensive
A Russia weakened internally is less capable of conducting information warfare and sabotage on the territory of NATO countries. That is why support for Kyiv remains one of the key instruments of European security policy, and its continuation should be treated as an investment in the long-term stability of the region.
The transfer of weapons and components that allow Ukraine to strike targets on Russian territory is essential. Defence against hybrid attacks is one thing, but offensive action is also a demonstration of strength that the Kremlin can understand. In addition to defensive capabilities, Europe must have credible potential that makes the aggressor pay a real price.
Defence, deterrence, diplomacy and destroy
The offensive dimension of the response is not only about the use of weapons. It also includes planned information, diplomatic and military actions that demonstrate readiness without uncontrolled escalation. Regular NATO exercises on the eastern flank, weapons demonstrations and the public presentation of new defence capabilities are all elements of deterrence that Moscow understands very well.
Europe, together with its allies, should build a message based on strength, stability and cohesion. Every statement, every action and every military movement must be part of one carefully considered narrative, so that Russia not only sees Europe’s preparedness, but also understands that testing it may bring real consequences.
This concept is based on one principle, referred to as “4D”: defence, deterrence, diplomacy and destroy. It assumes that the actions of the Alliance must be conducted in parallel: firm defence and deterrence, diplomacy, and readiness to destroy the opponent’s capabilities when the situation requires it.
Europe’s response to Russian hybrid activities must combine resilience with initiative. Sanctions, military support for Ukraine, active defence in cyberspace and international cooperation form a coherent system of pressure that limits the Kremlin’s room for manoeuvre. In the longer term, it is not individual incidents, but consistency and decisive action by European states that will determine the level of security and define Europe’s role in the wider security architecture.
To overcome Russian narratives, Europe needs a comprehensive strategy for responding to hybrid threats, based on strong deterrence and offensive responses. A coherent information policy, strengthening military potential, increasing efforts to protect the civilian population and securing critical infrastructure are equally important. Europe is capable of counter-attacking. Some of these operations have already begun.



