New research suggests that fears of escalation and difficulties reaching collective agreement are limiting Europe's willingness to use the tools already at its disposal.
Europe's cyber deterrence problem goes beyond cyberattacks
Europe's cyber deterrence problem goes beyond cyberattacks
As Russia and other adversaries combine cyberattacks with sabotage, disinformation campaigns, and economic pressure, Europe faces a growing challenge in deterring threats that cross the boundaries of traditional national security. The problem is not simply one of defense. Responding to these activities requires governments to decide when and how to retaliate without provoking a larger confrontation. The scale of the challenge is considerable. More than 140 drone incursions were documented across Europe between 2024 and 2026, according to figures cited by the Royal United Services Institute (RUSI), alongside cyber incidents and suspected acts of sabotage. While these activities frequently serve overlapping strategic objectives, the institutions responsible for responding to them remain divided across diplomatic, economic, intelligence, and military functions. Europe's fragmented response contrasts with the more coordinated strategies employed by the states responsible for many of these threats. “One commonality between Russia, China and Iran is that they don’t think about deterrence or hybrid activity as separate cyber, influence, and economic measures,” Dr Louise Marie Hurel, Senior Research Fellow in RUSI’s Cyber and Tech research group and co-author of a September 2026 report on deterrence, told The Beiruter. The difficulty of responding to hybrid threats is particularly apparent in Europe's confrontation with Russia, where cyber operations have accompanied suspected infrastructure sabotage, disinformation campaigns and incursions into NATO airspace. In September 2025, Russian drones entered Polish airspace, prompting Warsaw to invoke NATO's Article 4 consultation mechanism. Three months later, a coordinated cyberattack targeted Polish energy infrastructure. Such incidents expose the difficulty European governments face in determining when and how to respond to different forms of hostile activity. Research by Hurel and Gareth Mott suggests that Europe's hesitation stems less from a lack of capabilities than from fears of escalation and difficulties securing collective agreement. “Two key factors lie behind self-deterrence among countries across Europe and NATO. The first is overestimating escalation risks,” Hurel said. The second obstacle, Hurel explained, is the difficulty of collective decision-making. EU diplomatic and sanctions mechanisms can require unanimity, delaying responses when member states have different assessments of the threat. Smaller countries may also be reluctant to act independently if they lack the resources to withstand retaliation. Hurel pointed to coalitions of willing states as one way to overcome these constraints, allowing governments to coordinate responses without waiting for agreement across the entire EU. Britain has used public attribution of Russian military intelligence operations alongside sanctions and coordinated statements from international partners, demonstrating how several instruments can reinforce one another. Access to European markets, financial systems and technology offers another means of deterring malicious cyber activity. The United States has already demonstrated how trade measures can be linked to cybersecurity concerns. In 2018, Washington cited Chinese cyber intrusions aimed at obtaining commercially valuable information among the practices underlying tariffs that eventually covered approximately $370 billion in Chinese imports. Under the Biden administration, the United States also imposed 25% tariffs on Chinese ship-to-shore cranes in 2024, amid concerns about potential Chinese access to American port infrastructure. Although neither case proves that tariffs deter cyberattacks, both demonstrate how economic restrictions could complement diplomatic and cyber measures. “One way for Europe to strengthen its response is through coalitions of willing states,” Hurel said. The EU already has a cyber sanctions framework and a separate regime targeting Russia's destabilizing hybrid activities. Hurel suggested that these mechanisms could be adapted to address other states responsible for, or tolerant of, malicious cyber activity. Yet deterrence need not rely exclusively on punishment. Hurel's research also considers how governments could combine restrictions with incentives, offering technical assistance, investment, or improved economic cooperation to countries that take meaningful steps to prevent malicious activity originating from their territory. Although Russia dominates Europe's immediate security concerns, a deterrence strategy designed primarily around Moscow may be less effective against China, Iran or other states, whose economic vulnerabilities and diplomatic priorities differ. China presents a particularly complex calculation. Hurel explained that Beijing is accustomed to accusations from Washington, but attribution by countries with which it maintains important regional relationships may carry greater reputational consequences. Economic measures also require careful consideration given China's importance to European trade and technology supply chains. The challenge becomes more complicated when governments are neither close allies nor outright adversaries. Countries across Africa and other regions may maintain diplomatic relationships with Europe while relying on Chinese telecommunications infrastructure or maintaining security ties with Russia. Some may lack the resources to prevent malicious cyber operations conducted through networks within their borders, while others may be reluctant to confront the states responsible. Hurel pointed to the American military's “Hunt Forward” operations as one possible model. These missions deploy cyber teams to consenting partner countries to identify hostile activity within their networks. According to RUSI, U.S. Cyber Command has undertaken more than 100 such deployments across more than 30 countries in recent years. “Tailoring deterrence should not be limited to imposing costs on adversaries,” Hurel said. Rather than relying exclusively on retaliation, European governments could use intelligence cooperation, technical assistance and economic incentives to encourage countries to prevent malicious activity originating from their territory. Such partnerships could make it more difficult for hostile actors to exploit foreign infrastructure while giving participating governments a greater stake in preventing cyber threats. Europe already possesses many of the instruments needed to deter hostile cyber activity. As hostile states continue to combine digital operations with other forms of coercion, the credibility of European deterrence will ultimately be measured not only by its ability to identify cyberattacks, but by its willingness to respond.European states need to take the same approach to cyber deterrence, coordinating diplomatic, economic, and security tools rather than treating cyber threats in isolation.
When restraint becomes a vulnerability
Western governments overestimate how likely adversaries are to respond disproportionately to offensive cyber activity.
Economic power as a cyber weapon
Sanctions regimes could also be tailored to particular adversaries, while existing economic tools could be used more proactively to deter malicious cyber activity.
Different adversaries, different calculations
In a multipolar world, managing relationships with third countries, including those that are neither close allies nor direct adversaries, is equally important.
