Sittings · Document
Hybrid warfare and the protection of the EU’s territorial integrity and critical security and defence infrastructure
Parliament's resolution on hybrid warfare and the protection of the EU's territorial integrity and critical security and defence infrastructure.¶ It finds that hybrid attacks have escalated since Russia's war against Ukraine, names Russia as the primary threat, and lists recent attacks on EU territory.¶¶¶ It calls for a proactive EU strategy: closing legal gaps, treating sub-threshold operations as collective security matters, and building a cross-domain action plan with retaliation options.¶¶¶ It demands stronger action on FIMI, cognitive security, cybersecurity, critical infrastructure, undersea cables, space, energy, supply chains and situational awareness.¶¶¶ It asks for a horizontal EU sanctions framework for hybrid threats, a 'Black Book of Hybrid Aggression', and an Article 42(7) playbook.¶¶¶ It calls for deeper EU-NATO coordination and support to Ukraine, Moldova, Armenia, the Western Balkans and other partners, including Taiwan.¶¶¶
Key points
- Calls on the EU and Member States to recognise hybrid acts as a form of warfare even without conventional force, and to treat sub-threshold operations as collective security matters.¶¶
- Affirms Russia, directly or via proxies such as Belarus, is the gravest hybrid-threat state actor, and notes campaigns by China, Iran, North Korea and non-state actors.¶
- Calls for the EU FIMI toolkit to integrate countermeasures against reflexive control, and for standardised pre-bunking, rapid-response mechanisms and a strengthened Rapid Alert System.¶¶
- Calls on the Commission, High Representative and Member States to operationalise the FIMI Toolbox and apply the FIMI Deterrence Playbook, including coordinated public attribution and restrictive measures.¶
- Calls for stronger enforcement of EU rules on recommendation-system transparency, political advertising and coordinated inauthentic behaviour, and for treating AI as both threat vector and defence capability.¶¶
- Calls for sovereign cyber capabilities including offensive ones, harmonised incident-reporting obligations, and swift operationalisation of the EU Cyber Defence Coordination Centre.¶¶¶
- Condemns hybrid attacks on critical infrastructure and calls for protection of space systems, energy infrastructure, undersea cables and maritime zones, including boarding of shadow-fleet vessels.¶¶¶
- Calls for full and timely implementation of the CER and NIS2 Directives, rapid implementation of the strengthened FDI screening mechanism, and a 'Buy European' approach for critical infrastructure.¶¶
- Calls for supply chain security assessments across all critical infrastructure sectors and for reducing dependence on high-risk non-EU countries, particularly China.¶
- Calls for a shared threat picture, strengthened SIAC and intelligence sharing, a secure information-sharing system, and a 'Black Book of Hybrid Aggression' presented to Parliament annually.¶¶¶
- Calls for a cross-domain action plan against hybrid warfare, a single point of coordination between the Commission and the EEAS, and a horizontal EU sanctions framework for hybrid threats.¶¶
- Calls for an Article 42(7) playbook, use of the solidarity clause, and increased EU-NATO cooperation, exercises and alignment of hybrid threat pictures.¶¶¶
Who is affected
- EU Member States, which must implement resilience rules, share intelligence and harmonise laws on hybrid response.¶¶¶
- Critical infrastructure operators and private owners, subject to public-private cooperation frameworks and defence-relevant resilience standards.¶
- Candidate and partner countries including Ukraine, Moldova, Armenia and the Western Balkans, which receive hybrid resilience support.¶¶
- Online platforms, which face stronger enforcement on advertising, recommendation systems and manipulated content.¶
- SMEs, start-ups and technology providers, whose participation in EU programmes and procurement is sought.¶
Figures and deadlines
- Russian state-controlled media budget projected at approximately EUR 1,56 billion, 7 % higher than in 2025.¶
- Ceuta assault carried out on 30 and 31 July 2026.¶
- Sanctions regime targeting Russia's destabilising activities established in October 2024.¶
- Horizontal cyber sanctions regime established in 2019.¶
- 'Black Book' would document hybrid operations from the past 10 years.¶
- Cable protection zones criminalise damage beyond the 12-nautical-mile territorial sea limit.¶
- EU legal and financial framework under the next multiannual financial framework 2028-2034.¶
- First permanent UN Global Mechanism on cybersecurity launched in March 2026.¶
Legal basis: Articles 42(7) and 222 TEU, and Title V of the Treaty on European Union on the common security and defence policy.¶¶
Written by a language model from the full text only; every figure comes from the text and ¶ links to the paragraph it rests on. Check the text itself before relying on it.