Europe must learn to operate under permanent strategic pressure

#CriticalThinking

Peace, Security & Defence

Picture of Gábor Iklódy
Gábor Iklódy

Senior Fellow for Peace, Security and Defence at Friends of Europe, and former Assistant Secretary General for Emerging Security Challenges at the North Atlantic Treaty Organization (NATO)

Last week, Polish Prime Minister, Donald Tusk, warned that Russia could increasingly test European countries through attacks designed to appear accidental or remain ambiguous, while French President Emmanuel Macron ordered France to raise its vigilance against intensifying Russian hybrid threats and strengthen the protection of critical infrastructure. Their warnings point to a reality that Europe still struggles to translate into the way it operates: the continent is neither at peace in the traditional sense nor at war in the conventional sense. It is living under sustained strategic pressure.

Europe has spent the past several years rediscovering defence. Military expenditure is rising rapidly. Governments are rebuilding depleted inventories, expanding production capacity and trying to overcome the fragmentation of Europe’s defence industrial base. The European Union is mobilising financial and regulatory instruments that would have been politically difficult to imagine only a few years ago. At the same time, Ukraine’s extraordinary capacity for innovation, adaptation and rapid technological development is increasingly being integrated into European thinking.

All of this is necessary. But it addresses only part of the problem.

Current efforts are geared primarily towards preparing Europe for the possibility of a future high-intensity military confrontation. Rightly so: this is a scenario where no mistakes are allowed. However, already today, it is experiencing another form of confrontation simultaneously. Cyberattacks, sabotage, interference with critical infrastructure, hostile influence operations, GPS disruption, drone incursions, and other forms of coercion increasingly form part of Europe’s everyday security environment.

Recent events have made the problem harder to dismiss. Russian attacks close to NATO borders have repeatedly triggered Polish air-defence precautions. European governments are confronting suspicious drone activity, increasingly sophisticated acts of sabotage, and cyber operations whose origins or intentions may initially be unclear, but many of them by now have been sufficiently attributed. Meanwhile, hundreds of ageing tankers associated with Russia’s so-called shadow fleet continue to transport Russian oil while using complex ownership structures, changing flags, and other techniques intended to conceal their intent and frustrate enforcement.

None of these challenges fit comfortably into Europe’s traditional distinction between peace and war, which has thus far been binary: as long as we are not at war, we are at peace.

Russia does not need to cross NATO’s borders with armoured divisions to impose severe costs on Europe. If its objective is to destabilise Europe from within and weaken its resolve to support Ukraine, there are other, predominantly non-kinetic ways of achieving the same goal. It can probe vulnerabilities, disrupt infrastructure, undermine public trust in institutions, and create uncertainty while exploiting ambiguity about attribution, intent and response thresholds.

This creates a different security requirement. There is absolutely no doubt that Europe must strengthen its ability to deter and defend. But it’s not enough: it must also develop the ability to endure.

Endurance is more than resilience. Resilience usually describes the ability to absorb disruption and recover from it. Endurance means something more demanding: maintaining essential functions, continuing to take decisions, and pursuing strategic objectives while disruption and hostile pressure continue.

Ukraine demonstrates this distinction every day. Its energy system has not merely had to recover after Russian attacks. It has had to continue providing electricity while the attacks themselves continue, repeatedly repairing, decentralising, rerouting and adapting the system as Russia changes its targeting. The relevant measure of success is therefore not whether disruptions occur. We know they do. It is whether the essential function survives. That should increasingly be Europe’s benchmark as well. There is much that Europe can learn from Ukraine in this respect. The challenge is not only to draw those lessons, but to translate them into European practice.

The central question is no longer simply whether Europe is prepared for war. It is whether Europe is organised to function effectively in the security environment in which it already finds itself.

Viewed from that perspective, six weaknesses stand out.

1. Rules and authorities designed for a clear distinction between peace and war

European democracies deliberately constrain the exercise of state power. That is a strength, not a weakness, deeply rooted in Europe’s history. But many of our legal authorities, administrative procedures, and political assumptions were developed for an environment in which the distinction between normality and emergency was considerably clearer.

Hybrid confrontation exploits precisely this distinction, and Russia’s shadow fleet serves as a prime example.

Europe knows perfectly well what the problem is. Russia assembled a vast network of often ageing tankers, opaque ownership structures, and shifting flags to continue exporting oil and circumvent Western sanctions and restrictions. The EU has progressively responded by banning listed vessels from European ports and services, targeting companies and individuals supporting the network and tightening restrictions on tanker sales.

Yet listing a ship and physically constraining what it can do are very different things.
A tanker sailing through international waters raises questions about flag-state jurisdiction, the law of the sea, the grounds on which it may be boarded and the authority of individual European states to intervene. Suspicious registration, sanctions evasion, or environmental risk do not automatically provide unlimited authority to stop a vessel and carry out a non-compliant boarding.

Europe has therefore spent several years gradually constructing the legal and operational basis for stronger action. The EU has moved from sanctioning vessels towards targeting their support ecosystem and making greater use of flag verification and maritime enforcement. This is progress. But it also exposes the underlying problem.

Russia could construct and operate the shadow fleet faster than Europe could establish the legal, institutional, and operational mechanisms required to constrain it.
The same asymmetry can arise elsewhere. What authority exists to neutralise an unidentified drone approaching critical infrastructure? When does suspicious activity around an undersea cable justify intervention? What evidence is required before a cyber operation can trigger measures extending beyond normal incident response, within the cyber realm or beyond? The answer cannot be to abandon legal safeguards. It must be to make the law better suited to the operating environment.

Europe should systematically identify the gaps between recognising hostile activity and possessing the authority to act against it. Recurring categories of hostile behaviour should have pre-agreed legal options and graduated response authorities rather than requiring governments to improvise after every incident.

The objective is not permanent emergency powers. It is a legal framework capable of moving proportionately along the continuum between normal administration and national emergency.

2. Decision-making that moves more slowly than the threat

Europe’s second vulnerability is time.

Our institutions are designed to consult, coordinate, and seek consensus. Under normal circumstances, this approach provides legitimacy and reduces the possibility of costly mistakes. However, under persistent strategic pressure it can also create predictable delays.

Drone incursions make the problem tangible. Take the example of a drone entering or approaching European airspace. A radar could detect suspicious activity, but what exactly is it? Is it armed? Is its presence intentional, accidental or the result of electronic interference? Who makes the decision in this case? Civilian aviation authorities, police, defence ministry, or armed forces? Can it safely be destroyed as it flies over populated territory? At what point does an unidentified object become a hostile one? These are not theoretical questions, but ones that authorities are confronted with time and time again in their work.

Russian attacks against Ukraine have repeatedly required Poland to scramble aircraft and activate both ground-based air defences and radar systems as a precaution. Recent incidents near the Polish-Ukrainian border have also demonstrated that even activity that is nominally directed at Ukraine can create immediate risks to NATO territory and infrastructure through which European support reaches Ukraine.

The military response to a conventional aircraft entering sovereign airspace rests upon decades of doctrine, procedures, and delegated authorities. Cheap drones, ambiguous trajectories, and hybrid intent create a much less mature decision environment. Recent NATO responses point precisely in this direction: adapting procedures and capabilities so that low-cost, ambiguous threats can be dealt with rapidly without relying disproportionately on high-end military assets.

The dilemma is revealing. Waiting for certainty may mean acting too late. Acting immediately may mean escalating unnecessarily or creating greater danger on the ground. Endurance therefore requires decision-making at the speed of the incident.

That means agreeing response ladders beforehand. What indicators trigger heightened surveillance? When can electronic countermeasures be used? When does responsibility transfer from civilian to military authorities? Who can authorise physical interception? What happens when the same incident affects several countries?
Not every decision can wait to reach prime ministers or defence ministers.

Ukraine again provides a useful contrast. Because it is fighting a full-scale war, it has been forced to delegate authority, shorten feedback loops, and allow decisions to be taken closer to where the problem occurs. Europe faces a more ambiguous challenge. It is not at war in the conventional sense, yet it is increasingly exposed to hostile actions for which normal peacetime procedures may be too slow or restrictive. This is precisely where the binary distinction between peace and war becomes problematic. Europe cannot simply import Ukraine’s wartime arrangements, but it can learn the organisational principle: decide in advance who is empowered to act when predictable situations occur, including those that fall short of openly recognised war.

3. Fragmented responsibility for problems that cross every boundary

Hybrid pressure rarely respects organisational charts. A cyber intrusion into an electricity operator may begin as an IT-security problem but rapidly become something much larger. If electricity supply is disrupted, telecommunications, transport, hospitals, financial services, and government operations may all be affected. Intelligence agencies may need to determine attribution. Police may investigate criminal activity. And armed forces may have to protect physical infrastructure.

Yet responsibility for managing these consequences remains divided between ministries, agencies, levels of government, EU institutions, NATO structures, and private companies. Energy provides an especially useful test case. If an adversary penetrates a power operator’s systems, the question is not simply whether the cyberattack can be contained, but whether electricity can continue to be supplied.

That immediately raises operational questions extending far beyond the remit of cyber security teams. Who decides whether parts of the network should be disconnected? Can operators shift to manual procedures? Which other operators need warning? What happens if communications fail simultaneously? Which hospitals, military installations, or transport systems receive priority?

This is why Europe needs increasingly to think in terms of missions rather than institutions. The relevant question is not simply which organisation is responsible for energy, cyber defence, or telecommunications, but what essential function must continue, which actors and systems are necessary to sustain it, and what dependencies connect them? Keeping electricity flowing is the mission. Protecting each institution individually is not enough.

4. Critical dependencies that are understood individually but insufficiently in a wider system

Europe has accumulated large quantities of resilience regulation, risk assessments, contingency plans, and sector-specific requirements. Yet compliance is not the same as operational readiness. An organisation may satisfy every regulatory requirement while remaining unable to perform its essential mission when several dependencies fail simultaneously. The energy example demonstrates why.

A power operator may possess redundant servers, backup generators and sophisticated cyber protection. Its control centres, however, could depend upon a telecommunications provider whose backup electricity lasts only several hours. Perhaps specialised repair teams cannot reach damaged substations because transport infrastructure is disrupted. Maybe, replacement transformers come from a small number of suppliers with long delivery times.

Each individual organisation may have a resilience plan. The system may nevertheless contain a critical vulnerability nobody owns.

Ukraine has discovered many of these dependencies through necessity rather than planning. Repeated Russian attacks on its electricity system have forced operators and government authorities to decentralise generation, protect infrastructure physically, maintain stocks of critical equipment, improvise repairs, and continuously change how the network operates. The International Energy Agency has drawn broader lessons from this experience for dealing not only with military attack but also with cyber incidents, extreme weather events, and major infrastructure failures.

Europe should identify these vulnerabilities through deliberate testing rather than discover them only when they are exploited by an adversary. This is where resilience needs to move from assumption to demonstration.

Critical systems should be subjected regularly to realistic stress tests asking a straightforward question: can the essential mission continue when the system is under sustained hostile pressure? These exercises should deliberately cause things to fail. Remove communications. Disable part of the electricity network. Introduce corrupted data. Make a critical decision-maker unavailable. Interrupt a supplier. Force operators to work manually. Combine a cyberattack with physical disruption and disinformation. Then observe what happens.

The purpose is not to pass an inspection. It is to discover where endurance breaks down. Dependencies should be mapped, assumptions challenged, systems stressed, weaknesses identified, remedies introduced, and the system tested again.
That creates a continuous cycle: identify – stress-test – learn – adapt – retest.

5. Deterrence that concentrates on punishment more than on denying benefits

Hybrid operations present Europe with a difficult deterrence problem. Attribution may take time. Responsibility may deliberately be obscured. Individual incidents may remain below thresholds that would justify a major response. Retaliating against every hostile act is neither realistic nor necessarily desirable.

This can create the impression that hybrid aggression is effectively cost-free. The examples considered above, however, point towards another way of thinking about deterrence.

Why operate a shadow fleet? Because it allows Russia to preserve oil revenues despite sanctions. Why probe European airspace or critical infrastructure with drones? Because doing so can generate uncertainty, undermine public trust in institutions, impose costs and expose hesitation about how Europe will respond. Why attack an electricity network? Because disruption can propagate through society and potentially weaken political resolve.

The common objective is effect. Europe must therefore become better both at denying those effects and at imposing costs when hostile activity can be sufficiently attributed. The two are complementary: endurance reduces the benefits of aggression, while credible consequences increase its price.

The shadow fleet should become progressively more expensive and difficult to operate. Drone incursions should encounter predictable and increasingly effective responses, while Europe should retain the option of imposing costs in other domains where appropriate. Cyberattacks on energy infrastructure should confront systems capable of isolating compromised components while continuing to provide essential services.

This is deterrence by denial translated into the hybrid environment. It does not eliminate the need for consequences. Where responsibility can be established, Europe retains a wide range of possible responses – legal action, sanctions, asset freezes or confiscations, diplomatic action, and other proportionate instruments. But we also know that endurance itself contributes to deterrence.

If an attack cannot shut down the electricity network, sabotage cannot seriously interrupt military logistics, and interference cannot paralyse political decision-making, the strategic return on hostile activity declines. The same applies when infrastructure disruption produces rapid adaptation rather than cascading failure.

Europe’s message should increasingly be: “you may be able to disrupt us, but you will not achieve your strategic objective.”

6. Institutions that investigate incidents but do not learn quickly enough from them

Finally, Europe has a learning problem.

Each cyber-attack, drone incursion, sabotage attempt or infrastructure failure generates investigations, reports and recommendations. But lessons often remain inside individual organisations or sectors, and procurement, regulation, and institutional reform continue to operate on much slower cycles.

Ukraine provides a particularly clear counterexample. The technological competition surrounding drones and electronic warfare has forced Ukrainian units and companies into extraordinarily rapid adaptation cycles. A successful drone or countermeasure may provide an advantage for only a limited period before the adversary develops a response. Operators identify problems at the front; engineers modify hardware or software; revised systems return to operational use; the enemy adapts; and the cycle begins again.

The European Commission itself has highlighted the following model: decentralised decision-making, rapid testing under operational conditions, and direct feedback between end-users and developers have enabled Ukrainian companies to deliver and modify systems in weeks rather than conventional procurement cycles.

The lesson for Europe is that adaptation speed has become a security capability in its own right. Europe therefore needs institutional mechanisms for continuous operational learning. Every significant incident and exercise should generate structured lessons: what happened, what worked, where decisions stalled, which assumptions proved wrong and what needs to change.

More importantly, those lessons must lead to modified procedures, authorities, technologies or training – followed by subsequent tests. This is where the Ukrainian model and the critical-infrastructure example converge. The cycle is the same: identify – test – learn – adapt – retest.

The metric of success should therefore not be the number of exercises conducted, reports produced or regulations adopted. It should increasingly be how quickly demonstrated weaknesses are corrected.

From preparedness to endurance

These four examples (shadow-fleet enforcement, drone incursions, critical energy infrastructure, and Ukraine’s adaptation cycle) may appear very different. But they are not. Each exposes a different aspect of the same structural problem.

The shadow fleet exposes the gap between recognising hostile behaviour and possessing sufficiently agile authorities to counter it. Drone incursions expose the gap between the speed of an incident and the speed of decision-making. Energy infrastructure exposes the dependencies between public and private systems and the difference between protecting an organisation and maintaining an essential mission.

Ukraine exposes the importance of continuous adaptation when the adversary is learning at the same time. Together they point towards a changed European operating model. None of this requires Europe to declare itself at war. In fact, doing so could obscure rather than clarify the challenge.

The objective should instead be to acknowledge that the operating environment has changed. Europe faces a prolonged period in which strategic competition, coercion, and hostile activity can occur continuously without crossing neatly into what European governments and institutions traditionally recognise as war. That environment requires Europe to move beyond the binary choice between normal peacetime administration and wartime mobilisation. Institutions must be capable of shifting progressively along a continuum of readiness: monitoring, protecting, responding, reinforcing and, where necessary, escalating, without waiting for a political declaration that normality has ended.

This is where the emerging concept of a European Defence Union should start.
The debate understandably concentrates on capabilities: weapons, industrial capacity, financing, procurement, and military readiness. These are indispensable. But a European Defence Union ultimately has to answer a more fundamental question: what must Europe be able to continue doing when it is under sustained attack?

Electricity must continue to flow. Communications must function. Governments must take decisions. Military forces and equipment must move. Financial systems must operate. Democratic institutions must remain credible. Citizens must receive reliable information. Support for Ukraine must continue.

Defence therefore cannot be separated from the ability of European societies to function. This is the essence of endurance. And it changes the question Europe should ask itself.

Instead of preparing only for the nightmare scenario of a future war, Europe must also prepare for the reality of prolonged strategic pressure in which disruption, intimidation, and attack become recurring features of everyday security. The task is not to predict every attack. It is to build a Europe capable of continuing to operate when they come.


The views expressed in this #CriticalThinking article reflect those of the author(s) and not of Friends of Europe.

Related activities

view all
view all
view all
Track title

Category

00:0000:00
Stop playback
Video title

Category

Close
Africa initiative logo

Dismiss