European governments are rebuilding civil defence systems, strengthening emergency medical capacity and preparing populations for major disruption as intelligence assessments warn that Russia could intensify hybrid operations against NATO. Denmark now assesses that there is a low but increasing risk of limited military attacks, while reports of a CIA warning about drones launched from commercial vessels have added to concerns over the changing security environment.
By Open Chronicle with agencies | September 28, 2026
BRUSSELS — European governments are accelerating preparations for a security environment increasingly shaped by drones, sabotage, cyberattacks and military provocations as intelligence assessments warn that Russia could intensify operations against NATO countries during the coming months.
The immediate concern is not primarily that Moscow is preparing a conventional invasion of NATO territory.
Instead, European intelligence assessments increasingly focus on a more ambiguous scenario: limited attacks, covert operations and hybrid actions designed to cause disruption while making it difficult for governments to determine whether NATO’s collective defence threshold has been crossed.
A new assessment from Denmark’s Defence Intelligence Service, known as FE, states that Russia is likely to further escalate its hybrid campaign against NATO and the West in the coming months.
The Danish agency assesses that there is a “low, but increasing risk” that Russia could conduct limited military attacks against a NATO country even while the war in Ukraine continues.
FE considers a full scale Russian invasion of a NATO member unlikely, but says such a scenario can no longer be excluded.
Reports of CIA warning raise concern in southern Europe
One of the most alarming scenarios to emerge involves the possibility of drones being launched against southern European targets from commercial vessels.
US intelligence services reportedly warned several European governments about a possible Russian operation involving drones launched from merchant ships appearing to be normal commercial traffic.
The reported scenario involves Russian drones with ranges of approximately 600 kilometres potentially being launched towards targets in Spain, France or Italy.
Such an operation would represent a particularly difficult challenge for European security services because the launch platforms could blend into ordinary commercial maritime traffic before an attack.
The reported warning has intensified attention on the vulnerability of southern Europe at a time when much of NATO’s defensive planning has traditionally concentrated on the alliance’s eastern flank.
NATO urges calm while acknowledging long term threat
NATO Secretary General Mark Rutte has urged governments not to panic while acknowledging the seriousness of the security environment.
“Our assessment is that the Russian threat exists and is a long term one,” Rutte said.
He urged European allies to remain calm, continue strengthening their preparedness and maintain support for Ukraine.
The message reflects the balance NATO is attempting to maintain.
Alliance officials want governments to prepare for increasingly serious security threats without creating the impression that a large scale Russian attack on NATO territory is considered imminent.
Denmark warns hybrid campaign could intensify
The latest Danish intelligence assessment provides one of the clearest official descriptions of the evolving threat.
FE concluded that Russia is expected to further escalate its hybrid campaign against NATO and Western countries over the coming months.
It also assessed that the risk of limited military attacks against a NATO country is increasing.
Such an attack would not necessarily resemble the conventional invasion Russia launched against Ukraine.
Instead, the concern is that Moscow could use operations whose origin, purpose or military significance is initially difficult to establish.
An earlier Danish intelligence assessment warned that Russia was seeking to create uncertainty over what kinds of attacks would trigger NATO’s Article 5 collective defence commitment.
Sabotage, cyberattacks and military provocations below the threshold of conventional war could be used to test both the political cohesion and response mechanisms of the alliance.
The strategic importance of ambiguity is increasingly central to European thinking about the Russian threat.
Poland warns of possible drone and missile incidents
Polish Prime Minister Donald Tusk has issued an unusually explicit warning about the possibility of Russian actions affecting NATO territory.
Speaking to the Polish parliament on September 17, Tusk said intelligence received by Warsaw indicated that Russian planning included possible hybrid drone and missile strikes against countries supporting Ukraine, including Poland.
“There is a real risk” that drones or other projectiles could enter one or more NATO countries on the eastern flank and cause destruction, Tusk said.
He warned that Moscow could then portray such incidents as accidental in an effort to weaken NATO governments’ willingness to invoke alliance defence provisions.
For Poland, which shares borders with Ukraine, Belarus and Russia’s Kaliningrad region, the possibility of military incidents crossing into NATO territory has become an increasingly important element of national security planning.
European leaders warn about Russian escalation
The warnings have also reached Europe’s political leadership.
Earlier this month, Italian Prime Minister Giorgia Meloni said Russian provocations were increasing because Russian President Vladimir Putin “needs to shift attention, seeking an escalation with Europe, away from a situation on the battlefield that is not going as he had promised.”
British Air Chief Marshal John Stringer, NATO’s deputy supreme allied commander, has also warned that Putin is becoming “increasingly cavalier, dangerous, and risk accepting” as the war in Ukraine continues.
Stringer said the Russian president was seeking to divide Western allies.
The assessments reinforce concerns that Moscow could attempt to exploit political disagreements within NATO without deliberately initiating a conventional conflict with the entire alliance.
Europe rebuilds civil defence
The warnings are accelerating a transformation already underway across Europe.
Civil defence structures that were reduced or neglected following the end of the Cold War are being reconsidered as governments prepare for crises involving war, sabotage, cyberattacks, infrastructure failures and natural disasters.
The European Commission’s Preparedness Union Strategy seeks to establish a broader approach to major emergencies involving governments, businesses, emergency services and citizens.
One of its most visible proposals is the development of guidelines allowing Europeans to remain self sufficient for at least 72 hours during a major disruption.
Brussels is also developing preparedness standards for hospitals, schools, telecommunications and transportation while calling for larger stockpiles of critical equipment.
The objective is to create societies capable of continuing to function even when normal infrastructure is disrupted.
Households encouraged to prepare for emergencies
Several European countries are going further.
Norway recommends that households maintain enough essential supplies to function for approximately one week without normal infrastructure or immediate government assistance.
Swedish authorities advise residents to identify nearby civil defence shelters and maintain emergency supplies including water, food, medicines, first aid materials, warm clothing, identification documents, flashlights, cash and power banks.
The objective is not simply preparation for conventional warfare.
A major cyberattack, prolonged electricity failure, telecommunications disruption, sabotage operation or attack against transport infrastructure could create many of the same immediate requirements for civilians.
Europe’s emerging preparedness strategy therefore treats military and civilian resilience as increasingly interconnected.
Germany invests heavily in civil protection
Germany has become one of the most important examples of Europe’s renewed focus on civil defence.
Berlin has committed approximately $11 billion through 2029 to modernising civil protection, warning systems, emergency equipment and crisis response capabilities.
German authorities are also expanding specialised medical task forces designed to operate during mass casualty incidents and national defence emergencies.
Hospitals have consequently become part of the continent’s wider civil military planning.
German civil protection authorities have warned that civilian hospitals could be required to treat large numbers of wounded military personnel alongside civilian casualties during a NATO defence emergency.
That possibility requires planning not only for hospital beds but also blood supplies, medical transport, pharmaceuticals, communications and the ability to continue operating during major infrastructure disruption.
Lithuania strengthens emergency medical network
Lithuania is also integrating its healthcare system into national security planning.
Twenty three strategically important hospitals, together with emergency medical and blood services, have been designated as the backbone of the country’s crisis medical system.
The Baltic states are simultaneously expanding regional health cooperation for scenarios involving major emergencies and armed conflict.
For countries geographically close to Russia and Belarus, medical preparedness is increasingly viewed as part of national resilience rather than exclusively as a public health responsibility.
Cyberattacks remain central to the threat
The military dimension represents only part of the security challenge.
NATO has condemned persistent Russian malicious cyberactivity directed against allied governments and critical infrastructure.
The European Union has said Russian linked cyberoperations have targeted countries including France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania and Finland.
Government systems and critical infrastructure have been among the reported targets.
The potential consequences are extensive.
Energy networks, telecommunications systems, government databases, transportation infrastructure, financial institutions and healthcare networks could all create widespread disruption if compromised.
Electronic warfare has created another concern, particularly around the Baltic region, where GPS jamming and spoofing can interfere with navigation and aviation.
Drones transform European security
Unidentified drones have become another increasingly prominent security problem.
Germany has reported a sharp rise in unauthorised drone activity around sensitive infrastructure since Russia’s invasion of Ukraine in 2022, with authorities suspecting foreign state involvement in some cases.
Berlin has expanded federal police counter drone powers and approved additional aviation security measures.
German authorities have also accused Russia of orchestrating an attempted drone attack at Leipzig Halle Airport in August, where authorities found a drone carrying explosives near a Ukrainian aircraft.
Moscow denied responsibility.
The wider problem extends beyond Germany.
Small drones can be difficult to detect, relatively inexpensive to deploy and capable of threatening airports, military installations, energy facilities and other sensitive infrastructure.
The possibility that drones could also be launched from commercial vessels adds another dimension to the challenge.
Sabotage and infrastructure protection
European governments are strengthening protection around infrastructure considered essential during a military or national emergency.
Ports, railways, energy facilities, telecommunications networks, airports and undersea infrastructure have assumed greater strategic importance.
European Union sanctions have targeted entities that the bloc says participated in surveillance of undersea infrastructure and electronic warfare involving GPS jamming and spoofing around the Baltic region.
The European Council has also condemned what it describes as Russia’s coordinated campaign involving sabotage, cyberattacks, foreign information manipulation and other destabilising activities against European countries and partners.
The possibility of sabotage now forms an increasingly important part of European emergency planning.
Germany describes a daily hybrid confrontation
The cumulative effect is changing how European officials describe the security environment.
German Interior Minister Alexander Dobrindt said last month that Germany was “not at war” but had become a daily target of hybrid warfare.
He cited espionage, sabotage, cyberattacks and covert foreign operations as elements of the challenge confronting the country.
The distinction is important.
European governments are not describing themselves as being in a conventional war with Russia, but they increasingly view activities below the threshold of open warfare as part of a sustained security confrontation.
A conflict below the threshold of conventional war
The most difficult challenge confronting NATO may ultimately be determining when hybrid activity becomes military aggression.
A conventional invasion by Russian armed forces would present NATO with a relatively clear political and military situation.
A drone launched from an unidentified commercial vessel is different.
So is a cyberattack against an electricity network, sabotage of transport infrastructure or an apparently accidental missile strike.
Determining responsibility can take time.
That uncertainty could complicate political decision making precisely when governments need to respond rapidly.
Poland’s warning reflects this concern.
Tusk suggested that Moscow could seek to present damaging incidents on NATO territory as accidents, potentially weakening political support for a collective alliance response.
Article 5 and the problem of ambiguity
Article 5 of the North Atlantic Treaty establishes the principle that an armed attack against one NATO member is considered an attack against them all.
Hybrid operations complicate that principle because individual incidents may not immediately resemble a traditional armed attack.
An unexplained explosion, cyberattack, damaged undersea cable or unidentified drone may initially offer little evidence about responsibility.
Attribution therefore becomes strategically important.
If an adversary can cause significant disruption while maintaining uncertainty about responsibility, it can potentially create political disagreements among NATO members about how to respond.
European intelligence assessments increasingly suggest that this ambiguity may itself be part of the strategy.
Preparedness becomes part of deterrence
Europe’s response is therefore increasingly focused on resilience as well as conventional military strength.
The European Commission’s approach calls for governments, businesses, emergency services, critical infrastructure operators and ordinary citizens to participate in preparedness rather than treating national defence exclusively as the responsibility of armed forces.
Hospitals capable of operating during mass casualty emergencies, households prepared for temporary disruption, telecommunications networks with redundancy and governments capable of maintaining essential services all reduce the potential effectiveness of hybrid attacks.
Civil defence is consequently becoming part of deterrence.
An adversary has fewer opportunities to create strategic disruption if societies can absorb an attack and continue functioning.
Europe prepares for an uncertain security environment
Current intelligence assessments do not conclude that Russia is preparing an imminent large scale invasion of NATO territory.
The Danish assessment considers such an invasion unlikely while warning that the possibility can no longer be completely excluded.
The more immediate concern is less dramatic but potentially more difficult to manage.
Europe may face an extended period in which the boundary between peace and conflict becomes increasingly difficult to define.
Drones, cyberattacks, sabotage, electronic interference, information operations and limited military incidents could create disruption without producing the unmistakable beginning of a conventional war.
That ambiguity is now influencing how European governments prepare their militaries, hospitals, infrastructure and populations.
After decades in which large scale civil defence gradually disappeared from everyday European life, preparedness is returning to the centre of the continent’s security strategy.