Hybrid warfare and the protection of the EU’s territorial integrity and critical security and defence infrastructure
The European Parliament adopted by 470 votes to 129, with 62 abstentions, a resolution on hybrid warfare and the protection of the EUs territorial integrity and critical security and defence infrastructure.
Hybrid warfare: between war and peace
Parliament stressed that hybrid operations are deliberate, combined, intelligence-led and coordinated acts by states, including through non-state actors, intermediaries and proxies. They are designed to appear as isolated incidents and remain below the threshold of armed conflict, while having the potential to produce effects comparable to conventional aggression. The primary objective of hybrid warfare is to destabilise, divide and undermine the EU and its Member States by exploiting systemic vulnerabilities, and weakening their security, resilience and democratic foundations, and their defence readiness.
Parliament affirmed that Russia, acting directly or via multiple proxies such as Belarus, is the gravest hybrid-threat state actor targeting the EU and its Member States. It stressed that EU must adopt a comprehensive approach to hybrid threats that addresses not only Russian and Belarusian activities but also the growing strategic role of China, Iran and North Korea in enabling and amplifying hostile actions against European interests and security.
The Commission and the Council are invited to assess the adequacy of existing EU legal frameworks for addressing hybrid threats, close identified gaps, and treat sub-threshold hybrid operations that cannot be addressed through law enforcement alone as collective security matters, requiring a combined civil-military response.
Information warfare, cognitive security and societal resilience
Parliament expressed concern at the growing scale of cognitive warfare together with foreign information manipulation and interference, which aims to erode societal trust in democratic institutions, increase polarisation, undermine democratic decision-making and public support for European security and defence, including support for Ukraine. AI tools - deepfakes, algorithmic amplification and automated account networks - make influence operations faster, cheaper and harder to detect.
The resolution stressed that information manipulation and interference activities carried out from abroad must be treated as a serious security threat requiring an operational approach, better coordination and collaboration among Member States at all levels, including early detection, adequate response options and stronger protection of democratic processes, particularly during electoral periods.
Given that hybrid threats target society as a whole, Parliament believes that resilience against hybrid threats must extend beyond military, technical and institutional measures by bringing together public authorities, the private sector, civil society, academia and independent media to strengthen democratic trust, public awareness and societal preparedness, thereby fostering a new European security culture. Members stressed the need to strengthen public resilience to foreign information manipulation and interference and called on the Commission to take further steps by providing cognitive vulnerability mapping and resilience benchmarks.
Cybersecurity
Cyberattacks have become a central element of hybrid campaigns that leverage the increasing digitalisation of critical sectors such as healthcare, finance and energy. Parliament called for mechanisms to combat information manipulation and interference activities conducted from abroad to be systematically integrated with cybersecurity capabilities in order to detect coordinated manipulation infrastructures, identify those responsible, and neutralise them at an early stage.
Members recommended that the Commission examine proposals to establish a more harmonised framework to assist Member States in the planning, operational coordination, and implementation of cyber operations. They called for greater harmonisation of incident reporting obligations and key legal concepts across EU cybersecurity and resilience frameworks. The Commission and Member States, in cooperation with NATO, should examine the legal, procedural, and operational prerequisites for proportionate, legally compliant cyber countermeasures.
Critical infrastructure
Parliament condemned the hybrid attacks targeting the EUs critical infrastructure in particular energy, transport, communications and satellite infrastructure, including that for military mobility, maritime infrastructure, and submarine cables. It urged the Commission and the Member States to establish, within the framework of the next Multiannual Financial Framework (2028-2034), a European legal and financial framework guaranteeing sufficient protection and resilience for critical energy infrastructure. More generally, it is essential to strengthen surveillance, detection, and defence capabilities against air and maritime threats.
Parliament called for the swift implementation of the Critical Entity Resilience (CER) Directive and the NIS2 Directive, which represent significant steps forward in strengthening resilience against hybrid attacks.
The resolution called on Member States to conduct regular preparedness and resilience exercises for critical infrastructure, including joint exercises, and to urgently provide the priority capabilities identified in the White Paper on European Defence, particularly in the areas of air and missile defence, drones and counter-drone systems.
Considering the EU's structural dependence on high-risk non-EU countries, particularly China, Members called on the Commission to redouble its efforts to reduce strategic dependencies and on Member States to diversify supply chains and prioritise European and like-minded suppliers in strategic sectors whenever security considerations so require.
The resolution urged Member States to increase intelligence sharing and stressed the obligation to systematically incorporate data-driven and intelligence-based assessments into EU crisis planning and management. It affirmed that the Single Intelligence Analysis Capability (SIAC) should be the single hub for intelligence within the European institutions.