European capitals are now debating whether they need something closer to a NATO-style collective response after a year of Russian-linked sabotage, cyber attacks, arson, the destruction of a rail line in Poland, and an attempted drone attack at Leipzig airport, which Germany formally attributed to Moscow in September. None of these incidents has crossed the threshold for triggering NATO’s Article 5. That appears to be precisely the point of the problem: activity can remain below the threshold for collective military defence while still imposing real costs and testing how far European governments are prepared to respond collectively.
Deterrence depends on cost, and sub-threshold attacks are engineered to avoid one. Each incident alone is too limited to justify a military response and attribution is usually contested; together they impose real, cumulative costs on airports, infrastructure, and any business operating near the exposure. Existing tools were built for a different problem: NATO's patrol missions respond after the fact, and Article 4 gives allies a forum to consult without any obligation to act. The EU's own foreign policy chief has described the Leipzig plot as bearing "all the hallmarks of state terrorism" while admitting no response has yet been found.
The proposed fix has a structural weakness worth pricing in. Von der Leyen's collective-response mechanism, like the sanctions package that stalled the same week, would still require unanimity among EU member states, and unanimity has repeatedly proven to be Russia's most reliable point of leverage inside European decision-making. Germany's own response so far, closing a Russian consulate and revoking the operating rights of a Russian cultural centre in Berlin, has already been criticised at home and abroad as too mild for the scale of the provocation.
Attribution is a communications decision as much as a security one. Germany's choice to publicly name Russia was a deliberate escalation, not simply a finding of fact; Russia's denial and counter-accusation of fabricated hybrid-attack narratives was equally deliberate. Both statements target public opinion, including support for continued aid to Ukraine, more than they target each other, and each side is trying to own the story before the other does.
The underlying dilemma is real, and it is not simply a question of political will. A robust collective response carries a risk of escalation and requires a degree of unity that European governments have not always found easy to maintain. But doing too little carries its own risk: it can create the impression that low-level aggression is relatively cheap and that activity below the Article 5 threshold will not generate a meaningful collective response.
That is what makes the pattern more significant than any single incident. Each episode is limited enough to be dismissed on its own. Taken together, repeated attacks without a clear and credible response can begin to test the deterrent effect of the alliance itself, according to officials and analysts following the pattern. The difficult question for European governments is therefore not simply how to respond to one attack, but how to respond consistently without turning every incident into a step towards a wider confrontation.
What this means in practice
- Airports, logistics, telecoms, rail, and defence-adjacent suppliers now sit inside a blended physical-and-cyber threat model; a Starlink ground station fire in Poland attributed to sabotage is a recent example of the two layers being attacked together.
- Companies in exposed sectors should build their own incident and communications playbooks rather than waiting for a collective governmental response that may not arrive, or may arrive too slowly to matter.
- Treat the unanimity requirement as a standing constraint on how fast and how firmly Europe can actually respond, a factor worth modelling into any exposure assessment involving EU-facing infrastructure.