NEWS & CONTEXTEuropean securityCritical infrastructureEconomic transmission

Russia’s Hybrid War: Europe’s Cost of Disruption

Germany’s attribution of the attempted Leipzig attack to Russia has triggered a diplomatic confrontation. Yet the strength of Europe’s response is not measured by the force of its condemnation alone. It depends on keeping transport, energy and communications running, restoring them when they fail, and establishing responsibility through evidence.

Published: Updated: Free to readReading time: about 35 minutes

“Hybrid war” describes pressure exerted through combinations of sabotage, cyber activity and information manipulation. It does not mean that conventional war has begun across Europe. Intent and state involvement must be assessed on the evidence in each case.[10]

The story in 30 seconds

What happened

Germany attributed the Leipzig incident to Russia; diplomatic countermeasures have followed.

The central issue

The leverage comes not only from damaged assets, but from interrupted operations and delayed recovery.

Who bears the cost

Effects reach logistics, infrastructure, suppliers and households through different channels and at different speeds.

The biggest uncertainty

The command chain in individual cases, the risk of recurrence, and how much loss countermeasures actually prevent.

The conclusion

Judge deterrence by whether it reduces the attacker’s payoff while preserving normal economic activity.

Contents

Europe’s vulnerability is disruption, not destruction alone

The question facing Europe is not simply whether Russian military forces will surge across its borders. Accumulating uncertainty around airports, communications, energy and logistics can itself become a security pressure, making ordinary decisions harder for governments and businesses. Even limited physical damage can leave a substantial burden when shutdowns, safety checks and the search for alternatives take longer than the initial incident.

On 1 September 2026, Germany’s government attributed the 4 August hybrid attack at Leipzig/Halle Airport to Russia. It reiterated that assessment at its 2 September press conference. What became explicit was the German government’s attribution; determining the criminal liability of individual perpetrators in court is a separate matter.[1][2]

That distinction should not become an excuse to minimise the threat. A company does not need to wait for a final judgment on foreign-state involvement before preparing an alternative communications link or delivery route. Punishment and coercive measures against a state, however, demand evidence about who did what. Protection and accountability can advance together without operating on identical evidentiary standards or timetables.

Limited damage does not mean an absence of pressure

An incident that causes no major destruction may still leave additional security requirements or altered operating procedures. Conversely, repeated reports of attacks can coexist with stable throughput, rapid recovery and contained costs, suggesting that the attacker has failed to secure the intended political effect. A simple incident count gives the same weight to an unsuccessful operation and a successful disruption.

Europe is therefore poorly described by a binary choice between helplessness and safety. The useful questions are which functions are exposed, how readily alternatives can replace them, and which costs persist after operations recover. Following those questions across countries and industries offers a better guide than either a blanket narrative of crisis or reassurance unsupported by evidence.

The “cost of disruption” is not a statistical estimate of Europe’s aggregate losses. It is a way of separating the consequences of interrupted activity into assets, time, transactions and trust. Estimating actual losses requires identifying the affected function, the duration of interruption, available substitutes and contractual terms. One airport incident cannot by itself yield an estimate of the effect on European growth or inflation.

How the Leipzig incident became a diplomatic confrontation

The incident began with the discovery of an explosives-equipped drone at Leipzig/Halle Airport during the night of 4–5 August 2026. The German government’s account distinguishes the interior minister’s description on 5 August from the government’s attribution on 1 September. The discovery of the device, the identity of its operator and the source of any instructions are distinct questions.[18]

Germany’s Foreign Office announced on 1 September 2026 that the Russian consulate-general in Bonn would close on 18 September, alongside termination of the agreement concerning the Russian House in Berlin. It also envisaged proposals for additional EU sanctions listings. A national decision, its implementation date and a proposed EU measure represent different stages; an announcement does not put every proposed sanction into effect.[1][3]

On 2 September 2026, NATO’s Secretary General expressed solidarity with Germany in remarks alongside the President of the European Commission. On 3 September, the United Kingdom’s Foreign, Commonwealth & Development Office announced that it had summoned Russia’s chargé d’affaires. The involvement of allies demonstrates that the political reach of the incident extends beyond Germany.[4][5]

Distinguish Russia’s denial from its countermeasures

Russia’s embassy in Germany rejected the accusations in a statement on 1 September 2026. On 7 September, Russia’s Foreign Ministry announced that the German consulate-general in St Petersburg must cease operating by 18 September. It also ordered German Goethe cultural centres to stop operating and their posted staff to leave by 13 September. These are announced Russian measures; their deadlines should be distinguished from the dates on which operations actually end.[6][7]

The immediate implication is a narrowing of diplomatic and cultural channels. Fewer points of contact may inconvenience businesses, residents and participants in cultural exchanges. Closing a consulate-general does not, however, sever every diplomatic relationship between the countries. Assessing the severity of the response requires considering the channels and alternative services that remain.

Diplomatic pain is also different from damage to operational capability. Closing facilities may constrain personnel or contacts, but it does not necessarily eliminate command structures, financing channels or outside intermediaries. Whether the measures make future operations harder, rather than merely increasing reciprocal inconvenience, depends on subsequent enforcement and investigations.

Russia’s denial is the position of the party contesting responsibility; Germany’s attribution is a government’s security assessment. Presenting both does not establish that the evidence supporting them carries equal weight. What matters is not the intensity of the language but progress in the investigation, the specificity of the assessment and the measures tied to it.

Sabotage is real—but not every disruption is sabotage

It would be equally mistaken to reduce the threat to suspicious flying objects or anonymous warnings. On 24 October 2025, the Crown Prosecution Service reported sentencing in the arson case targeting warehouses holding aid for Ukraine. The fire occurred in east London in March 2024, and the CPS described a link to the Wagner Group. Unlike a government accusation alone, this case reached a concrete outcome in criminal proceedings.[8]

There is a counterexample. On 13 October 2025, Swedish prosecutors announced that they had closed the preliminary sabotage investigation into damage to a Sweden–Latvia communications cable on 26 January. They concluded that it was an accident rather than a deliberate act, describing a combination of rough weather, technical deficiencies and shortcomings in seamanship. A severed subsea cable does not, by itself, establish state sabotage.[9]

Keep four evidentiary questions separate

Four questions help clarify the distinction. Did physical damage or operational disruption occur? Was it intentional? Was it linked to a foreign state agency or an intermediary acting for one? And which offence has been established against which individual, through which legal process? A yes to the first question does not automatically settle the others.

Figure 1 | Different incidents, different evidentiary positions

Government attribution, criminal findings and an accidental explanation are different kinds of evidence.

Position at each source’s publication date. Findings in one case do not determine another.[1][8][9]

CaseWhat the source establishesWhat it does not establish
Leipzig / 1 Sep 2026German government attribution to RussiaEvery participant’s conviction or the full command chain
UK warehouse arson / 24 Oct 2025CPS published sentencing outcomesResponsibility for other incidents elsewhere
Communications cable / 13 Oct 2025Swedish prosecutors concluded it was accidentalThat other cable incidents were also accidents

This is not an exercise in downplaying damage. Preventing an accident may require maintenance or navigation improvements; deterring deliberate sabotage may require intelligence sharing, investigations and constraints on personnel or financing. Confusing causes can misdirect spending even when budgets rise. Treating every failure as an enemy action can conceal ordinary maintenance deficiencies.

The existence of accidents is no reason to dismiss sabotage that has been established. Accidental damage and intentional attacks can occur in the same region at the same time. When an assessment changes, the correction should apply to that case and to arguments that depended on it. One finding cannot settle whether the broader European threat exists.

Economic vulnerability and the cause of an attack are separate questions. Ageing assets, weather, congestion and deferred maintenance may prolong disruption regardless of whether anyone caused it deliberately. That distinction also informs the analysis of Rhine logistics and German industry (full article requires paid access). The point is not to conflate natural hazards with hostile action, but to identify inadequate replacement capacity that either can expose.

The hybrid threat and Europe’s institutional response

NATO describes hybrid methods as combinations of military and non-military means, and overt and covert activity, including cyberattacks, disinformation, economic pressure and irregular action. Looking only for visible explosions therefore misses part of the threat. Equally, dissent or criticism of an unpopular policy cannot simply be classified as a foreign operation.[10]

The Danish Security and Intelligence Service’s 2026 Modus report describes how foreign intelligence services recruit intermediaries through social media, drawing on criminal contacts and financial vulnerability. Such arrangements create distance between those issuing instructions and those carrying them out. The involvement of a local criminal alone does not prove direction by a foreign government.[11]

Rules exist; their effectiveness remains a separate question

The European Union adopted a sanctions framework addressing Russian destabilising activities on 8 October 2024. On 16 March 2026, the Council adopted conclusions on strengthening its capacity to counter hybrid threats. On 13 July 2026, it announced measures concerning nine individuals and four entities in connection with cyberattacks and destabilising activity. Those numbers span separate sanctions regimes; they are not additions to a single list.[12][13][14]

Figure 2 | Separate incidents, announcements and deadlines

A single timeline contains dates with different meanings.

As of 8 September 2026. 13 and 18 September are future implementation deadlines.[1][2][5][7][14]

  1. Sanctions action

    EU announced measures concerning nine people and four entities across separate regimes.

  2. Incident

    Attempted attack at Leipzig/Halle Airport.

  3. Attribution

    Germany attributed responsibility to Russia and announced measures.

  4. Allied response

    UK announced that it had summoned Russia’s chargé d’affaires.

  5. Countermeasures

    Russia announced measures concerning German diplomatic and cultural facilities.

  6. Implementation deadlines

    Departure of posted cultural staff and cessation of consular operations.

Additional listings, joint statements and facility closures demonstrate political resolve. More institutional activity does not automatically mean less operational risk. If intermediaries can be replaced while the same activity continues, expanding a list may be insufficient. Conversely, measures may be effective even without prominent arrests if they make preparation harder or prevent operations from reaching execution.

Observation is difficult. Fewer attacks may indicate deterrence, but may also reflect a pause, a shift in targets or delayed detection. More recorded incidents can result from better reporting and monitoring as well as a greater threat. Policy evaluation therefore needs separate measures for detection, execution, damage and recovery time.

Implementation also requires cross-border coordination and a clear domestic allocation of responsibility. A telecom operator, a police investigation, an aviation safety authority and a foreign ministry have different objectives. Even when one office believes it has the complete picture, alternative transport or public communication can fall between institutions. Connecting political commitments to operating procedures is the next challenge.

Four cost ledgers reveal losses that headlines miss

The first ledger is physical assets: repairs, replacement and safety verification. A small repair bill does not necessarily imply a small social cost. An inexpensive component can still cause a long delay if specialised staff or the necessary approval process are unavailable. Conversely, damage to an expensive asset may have limited effects on users when backup capacity works.

The second ledger is flows. When goods, electricity, data or people cannot reach where they are needed, the consequences include waiting time, missed deadlines and lost sales opportunities. Timing matters as well as duration: an interruption at peak demand, just before a shipment deadline or when inventories are low has different consequences from an equally long interruption under easier conditions.

Two ledgers remain after service is restored

The third ledger covers preparedness and transactions: security staff, backup equipment, extra inventory, screening and contract revisions. Revenue may be unchanged while a business must commit more cash to inventory, increasing its working-capital burden. These expenditures can also prevent future losses, so counting all of them as waste would be equally misleading.

The fourth ledger concerns confidence and choices. If suppliers doubt delivery reliability, customers defer bookings or companies reconsider investment locations, effects may persist after operations resume. Attributing such changes to a particular hostile operation requires caution, however: interest rates, demand, exchange rates and regulation may have changed behaviour for other reasons.

Figure 3 | Disruption feeds four cost ledgers

Repair can end before the costs of delay, preparedness and lost confidence do.

SG Group analysis. Arrows show conditional relationships, not amounts or probabilities.

01 Assets

Damage and safety checks

Repair, replacement and restart conditions

02 Flows

Interrupted or delayed functions

Waiting, deadlines and sales opportunities

03 Preparedness

Preparation for recurrence

Security, inventory and screening costs

04 Confidence

Reassessment of reliability

Changes in contracts, investment and demand

The four ledgers cannot simply be added together. When sales are recovered later, treating every delayed sale as a permanent loss overstates the damage. Revenue lost by one airport or carrier may also shift to another. Company-level losses, national losses of value added and inconvenience to users are different concepts and should not be combined as if they were interchangeable amounts.

The availability of spare capacity on alternative routes also determines the cost. An uncongested substitute can absorb disruption relatively quickly; an already busy one can transmit delays to other regions and industries. The existence of another airport or communications link on a map does not establish that it can process the required volume at the required time.

For energy, distinguish stocks from deliverability

In energy, this means looking beyond stored volumes to withdrawal, transport and receiving capacity. Adequate aggregate stocks can coexist with tight conditions at a particular location if delivery routes are constrained. The guide to natural-gas prices, storage, weather and pipelines explains the distinction between total supply and the ability to deliver it.

For management, the useful question is not which building is largest but which process is hardest to replace. Production might be transferable while shipments remain blocked because inspection results cannot be transmitted. This is not an argument for publishing vulnerabilities. It is an argument for moving internal continuity planning from an inventory of assets to an understanding of how operations depend on one another.

Recovery is not complete merely because power returns or a connection is restored. Backlogged orders may still need processing, data may require validation and normal delivery times may not yet be achievable. Following the entire path back to normal operations reveals what continues to tie up cash and staff after the visible damage has been repaired.

Recovery and accountability run on different clocks

Hybrid threats force defenders to make decisions at different speeds. Airport and power-system operators must make rapid choices about suspension and resumption while prioritising safety. Investigations into intent, state involvement and individual responsibility require corroboration and due process. Imposing the pace of the latter on the former risks unnecessarily prolonged interruption of normal activity.

The first clock measures continuity and recovery: what to suspend, what to keep running and which alternative to use. The second measures evidence and accountability: recording events, preserving relevant information and building an assessment across institutions. The two processes share information, but demanding rapid recovery is not the same as demanding rapid condemnation.

NATO’s guidance on Article 3 of the North Atlantic Treaty and civil preparedness likewise treats the continuity of civilian functions as a foundation of defence, emphasising advance planning and regular exercises. An alternative route existing on paper is not the same as one that can be used during a crisis. Tested switching times and clear responsibility can matter more than the number of installed systems.[17]

Figure 4 | Run both clocks together

Rapid recovery is not rapid condemnation.

SG Group analysis. Segment widths do not represent elapsed time.

Continuity clockProtect safetyUse alternativesRestore functionsClear the backlog
Accountability clockRecord and preserveCorroborateAssess involvementApply due process

Some preparations do not depend on attribution

Measures such as maintaining more than one way to contact suppliers, prioritising tasks after restoration and assigning responsibility for staff communication can be useful before anyone knows whether an incident was deliberate. They do not require identifying an adversary. Responding to an observed loss of function can benefit businesses and users more directly than speculatively naming a culprit.

Speed is not a reason to discard evidence. Responsibilities and points of contact should be established in advance so that restoration and preservation do not work against one another. Actual response should follow operator and authority instructions; ordinary users should not approach dangerous objects or suspicious equipment. The pursuit of information must not obstruct safety.

The two clocks also improve policy evaluation. Recovery times may shorten even while an investigation continues, indicating greater protective capacity. Conversely, rapid attribution does not resolve operational weaknesses if the same facility repeatedly stops functioning. The speed of issuing a statement and the speed of restoring service should not be collapsed into one performance measure.

The information shared between businesses and government need not include the entire investigation. Companies need to know which operations may continue, which restrictions apply and when the next update is due. Authorities need an accurate picture of disruption and available alternatives. Protecting sensitive information does not require leaving users without operational guidance.

Overstatement and understatement: three counterarguments

The first objection is that Europe is overreacting and turning ordinary accidents into security crises. The Swedish cable case shows that an accidental explanation can indeed be correct. This is a valid warning against prejudging individual incidents. It is not a reason to disregard criminal findings in other cases or to dismiss every specific government assessment.[8][9]

The second objection is that continued attacks prove European deterrence has completely failed. Measuring deterrence solely by an absence of attempts would count disrupted preparations as failures as well. The relevant questions concern success rates, damage, recovery and the effort required from the attacker. An inability to prevent every attempt is very different from an inability to protect anything.

Both forceful and restrained responses carry costs

The third objection is that forceful countermeasures invite escalation, making a low-profile response preferable. Reciprocal facility closures can indeed burden residents and cultural exchanges with no connection to the incident. Yet consistently unobtrusive responses may also encourage an attacker to underestimate the costs. The design question is not simply whether to be strong or weak, but which conduct to penalise and which channels to preserve.

What is often overstated is the leap from one incident to general war or a large inflation shock. Military significance, logistical damage and market-price effects are not identical. Markets may register a threat while continuing supply and effective substitution limit its price impact. Nor can a falling price prove safety, or a rising price prove that an attack succeeded.

What is often understated is the accumulation of less visible recurring costs and slower decisions. Allocating staff and cash to security, contract screening and reserve inventory can change profits and investment capacity without changing revenue. Spread thinly across many companies, this burden may never appear as a dramatic one-day loss. A modest but persistent expense can matter more to management than a one-off repair.

More recorded incidents may also reflect better observation

Another possibility is that stronger monitoring makes activity appear to increase. New reporting channels, more security staff or broader definitions may bring previously unrecorded events into a dataset. Counts drawn from different populations, periods or classification rules cannot establish a trend on their own. Separating attacks, suspicions, false alarms and accidents is essential to informed vigilance.

Accepting disconfirming evidence is not a concession to an adversary. A society able to correct mistakes is better placed to secure trust in later, accurate warnings. Repeatedly presenting suspicion as certainty risks making an important warning sound like another false alarm. Information quality is therefore part of long-term defensive capacity, not merely a matter of presentation.

SG Group View: reduce the payoff from disruption

SG Group assesses Europe’s response by how much it reduces the payoff from an attack, rather than by the number of statements or sanctions. The payoff need not be monetary: it may involve delayed assistance, administrative confusion, social division or more hesitant businesses. An adversary’s precise objectives may be unknowable, but institutions can still make those outcomes harder to achieve.

The first proposition is that a function that can be restored quickly is harder to use as an instrument of sustained coercion. This is not a universal answer: rapid recovery cannot undo deaths or irreversible damage. For attacks aimed at interrupting activity, however, replacement capacity and effective restart procedures can reduce the economic and political payoff.

The second proposition is that responses must reach reusable financing, coordination and support arrangements, not only individual intermediaries. If replacing a low-level operative leaves the same function intact, the underlying capability persists. Investigations and sanctions may slow preparation when they increase the cost of maintaining support arrangements. The number of listed people cannot establish that effect automatically.

Connect resilience, accountability and public trust

The third proposition is that credible accountability supports durable deterrence. A response that explains the connection between evidence and measures, corrects mistakes and avoids collectively treating uninvolved people as enemies is better placed to sustain domestic support and allied cooperation. Accumulating defensible decisions can build greater tolerance for persistent burdens than rhetorical displays of unity.

Figure 5 | Three pillars that reduce the attacker’s payoff

Resilience, accountability and trust are complements, not substitutes.

SG Group analysis. Evaluate continuity, harm and the specificity of investigative findings.

Reduce disruption

Replacement capacity and recovery procedures

Prevent prolonged interruption

Constrain recurrence

Address support capabilities and responsibility

Raise the cost of preparation and repetition

Protect public trust

Evidence, proportionality and correction

Sustain cooperation and legitimacy

These elements are complementary. Focusing only on restoration may leave room for repeated attacks; focusing only on sanctions may leave operational vulnerabilities intact. Communication alone does not increase the capacity to reduce harm. Investment in continuity, investigations and trust should be treated as different components of one response, not substitutes for one another.

This view would weaken if better recovery failed to contain losses because attackers could easily shift to other, severe forms of harm. If activity continued at the same pace and scale after support arrangements were constrained, the measures might not be reaching essential components. Conversely, better continuity, shorter recovery times and more specific investigative findings would justify a more positive assessment even without prominent public declarations.

Europe being shaken is not the same as Europe being defeated. Pressure describes an adversary’s actions; defeat would imply that the intended objectives had been achieved. Maintaining assistance, public safety, business continuity and evidence-based accountability can contain the effects of coercion even while the pressure continues.

Who bears the costs, and where does demand increase?

Users and operators of the affected facility bear the first burden. Operators must restore service while maintaining safety; users face waiting, rescheduling and incomplete information. Those costs do not necessarily fall immediately on the party ultimately responsible under a contract. Reimbursement of expenses and compensation for lost time may remain unresolved well after the event.

The next burden falls on counterparties that were not directly affected. Missing components or documents may prevent a planned process from starting. When many customers seek alternatives at once, normally uncongested providers can become bottlenecks. Supply-chain dependencies are not limited to moving goods: payments, authentication, inspection and bookings also rely on information flows.

Figure 6 | Costs differ by actor and time horizon

Those bearing the first burden may not bear the final cost.

Conditional impact analysis. Compensation and liability depend on contracts and applicable rules.

ActorEarly effectLater burdenOften overlooked
OperatorsSuspension and safety checksMaintenance, security, backup capacityReopening differs from full normalisation
CounterpartiesDelayed deliveries or informationExtra inventory and contract changesExposure without direct damage
Households and usersRebooking and waitingChanges in charges or conveniencePass-through is neither uniform nor immediate
Public authoritiesCoordination and protectionBudgets, supervision, implementationLimits to shifting costs to firms
Protection and recovery providersEnquiries and potential ordersStaffing, procurement, delivery obligationsMore demand is not necessarily more profit

More demand does not guarantee higher profits

Providers of security, communications redundancy, maintenance and recovery support may see new demand. That does not guarantee higher profits. Specialist labour shortages, procurement delays, contractual liability and competitive tenders may squeeze returns. Merely classifying a company as security-related cannot establish an investment advantage.

Public authorities face choices between protective expenditure and other priorities. Shifting every cost to the private sector may be particularly difficult for smaller firms. Unconditional public coverage, however, may weaken incentives for operators to prepare. Responsibility should reflect the public importance of the function, what the operator can control and where losses spread.

For households, the effects extend beyond higher bills. Rearranging commutes or travel, time spent seeking information and uncertainty can all impose burdens. Between an incident in Europe and a Japanese household’s finances, however, lie several transmission stages involving transport, energy, exchange rates and contracts. An incident alone cannot establish a particular increase in the following month’s bill.

The timing differs as well. Operational disruption appears quickly; changes in insurance, contracts, budgets or location decisions may follow later. Calm near-term prices do not prove that medium-term business costs have disappeared. Equally, effective adaptation can prevent initial disruption from becoming a permanent burden. Continued observation should therefore focus on whether adaptation is succeeding.

Three transmission channels to Japan, households and markets

The first transmission channel to Japan is business activity linked to Europe. Companies with European offices, counterparties, logistics or information-service dependencies can be affected without being attacked themselves. Exposure depends on which functions are outsourced or located where, not simply on nationality or headquarters. A company need not own a European factory to rely on a European service.

The second channel is adjustment in energy and transport. If European supply or receiving constraints persist and replacement purchases rise, cargo allocation and transport demand elsewhere may change. Inventories, seasonality, contracts and spare shipping or infrastructure capacity can cushion the effect. Treating a local European disruption as an equivalent reduction in global supply risks overstating the impact.

Separate physical changes from market interpretations

The third channel runs through financial markets. Reassessment of risk can affect currencies, interest rates, equities and credit conditions, but there is no single predetermined direction. A supply concern that raises inflation anxiety differs from a demand shock that encourages expectations of lower interest rates. The dominant force cannot be identified from the emotional impact of a headline alone.

Figure 7 | Transmission to Japan is conditional

Several stages separate a European incident from Japanese prices or earnings.

SG Group conditional analysis; not a display of current market prices or realised losses.

Business and supply chains

European disruption → transactions and deadlines → Japanese operations

Alternatives, dependency and recovery time

Energy and transport

Changed purchasing → cargo allocation and prices → contractual transmission

Stocks, seasonality, capacity and FX

Financial markets

Risk reassessment → rates, FX and credit → firms and households

Whether supply anxiety or weaker demand dominates

In energy markets, prices for near-term delivery and later delivery answer different questions. A temporary constraint may affect their spread, but demand and seasonality can change it as well. The guide to energy calendar spreads and seasonality helps distinguish the overall price level from the timing of the scarcity that markets may be pricing.

Gold should not be assumed to rise simply because an event is geopolitical. Interest rates, the dollar, liquidity and investors’ transactions can act at the same time. The guide to gold and real yields across different regimes explains why a single factor need not produce a fixed response. The purpose is to separate drivers, not to derive a trading direction for gold or currencies from this incident.

For households, the practical starting point is the service they have contracted and the information supplied by its provider. For travel, that means airlines and travel companies; for electricity and gas, contractual terms and provider notices. These are more directly relevant than a general crisis headline. The incident does not, by itself, establish a need to trade financial products urgently or stockpile goods on the basis of uncertain information.

Do not equate price transmission with investment returns

For management, distinguishing responses under different conditions is more useful than committing to one forecast. A short delay might be absorbed by existing buffers, with a switch to alternatives only if it persists. Actual thresholds depend on operational importance and contractual obligations. No single inventory target or spending allocation can be prescribed for every company.

The timing of comparison data matters too. Overlaying an intraday event on weekly statistics and attributing the following week’s change entirely to that event invites causal mistakes. A publication date is different from the period a statistic covers. Understanding the supply-and-demand changes already under way is a prerequisite to assessing what the new event changed.

Four conditional scenarios: focus on the triggers, not a point forecast

The first scenario is absorbed pressure: incidents or alerts continue, but critical services remain available, substitutes work and additional business costs stay limited. Political tension could remain elevated while economic spillovers are contained. Quiet markets alone would not establish this outcome; both actual operations and costs would need to support it.

The second scenario is chronic friction: repeated increases in inspection, security, delays and reserve inventory rather than one enormous loss. Margins and investment capacity could deteriorate gradually without a sharp fall in headline economic indicators. The key question would be whether the cost of maintaining or returning to normal operations is rising, not merely whether incident counts are increasing.

Figure 8 | Four paths and evidence that would change them

Scenarios map conditions for changing a view; they are not probability estimates.

SG Group conditional scenarios. Area and ordering do not indicate likelihood.

Absorbed pressure

Substitutes work and extra costs stay contained

Continuity and short recovery

Reassess if extra costs become persistent

Chronic friction

Recurring security, screening and inventory costs

Pressure on margins and investment capacity

Weakens if costs return to normal

Compound interruption

Multiple constraints with little spare capacity

Delays spread across regions or industries

Weakens if alternatives absorb disruption

Escalation through miscalculation

Severe harm or a widening cycle of measures

Responses broaden beyond previous limits

Restraint and maintained channels argue against it

Simultaneity and spare capacity determine the downside

The third scenario is compound interruption. If several important functions are constrained at the same time and alternatives have little spare capacity, a short disruption can become a wider delay. This is not a claim about a future attack plan. The same conditions can arise when ordinary accidents or weather overlap; the point is that thin buffers amplify the effects.

The fourth scenario is escalation through miscalculation. Major casualties, compelling evidence of serious state involvement or retaliation against forceful countermeasures could require a broader response. None of those outcomes follows inevitably from an individual incident. Restraint, diplomatic contact and allied coordination may still work; a tail risk should not be treated as the central expectation.

Rather than assign fixed probabilities, it is more useful to identify which observations support each explanation. Shorter recovery times would favour the first; persistent additional costs, the second; simultaneous functional failures, the third; and a rapid broadening of measures, the fourth. No single number should trigger a definitive reclassification without corroborating information.

Conditional analysis is not intended to make a view evasive. It establishes in advance what would cause that view to change. The guide to macro scenario analysis likewise separates assumptions, transmission channels and confirming observations. A framework that can be revised when its premises fail is more useful than retrofitting an explanation to market prices.

What remains uncertain: command, scale and deterrence

The first uncertainty concerns how far individual cases will establish a chain between operatives and decision-makers. Government attribution matters, but does not automatically reveal every participant’s role, every financing flow or the full scope of involvement. Investigations and legal proceedings may add specificity or require parts of an initial account to change.

The second uncertainty is the relationship between incident totals and actual losses. Combining attempts, suspicions, accidents, interference and information operations mixes different phenomena. Repair bills, delayed transactions and sales recovered later must also be separated. Adding figures without consistent definitions and observation periods does not produce a reliable total burden for Europe.

A quiet period proves neither success nor permanent safety

The third uncertainty is the effect of countermeasures. Over a short period, it can be difficult to distinguish successful deterrence from an adversary’s decision to pause. Preparedness costs may rise even without a major incident. Conversely, more reports may reflect better early detection. The direction of a count alone cannot establish policy performance.

The fourth uncertainty is the gap between political intent and political results. An attempt to divide a society could conceivably strengthen solidarity instead. A policy change following an incident cannot be attributed solely to it without further evidence. Elections, fiscal pressures, diplomacy and domestic policy debates can change at the same time.

Finally, Europe cannot be described as having a single uniform condition. Facilities, national institutions, industrial structures and available substitutes differ. Successful recovery in one region does not guarantee preparedness elsewhere, and weakness at one site does not establish continent-wide helplessness. The broader the claim, the more important it is to test it against specific functions and places.

What to watch next: implementation, operations and evidence

The first checkpoints concern implementation of diplomatic measures. Russia specified 13 September 2026 for the departure of posted cultural-centre staff and 18 September for the German consulate-general. Germany also scheduled the Bonn consulate-general’s closure for 18 September. These dates are implementation checkpoints, not dates on which an attack or market movement is expected.[1][7]

For the EU regime addressing Russian destabilising activities, the extension announced on 3 October 2025 runs until 9 October 2026. Any renewal or amendment should be checked against Council decisions and the Official Journal. An existing measure’s end date is not the same as the date on which a new decision will be adopted, and its future content should not be assumed.[15]

Figure 9 | A dated watchlist tied to observable outcomes

After announcements, watch implementation, operations and new evidence.

As of 8 September 2026. Plans and deadlines are not completed outcomes.[1][7][15][16]

  • 13 Sep 2026Russian deadline for posted cultural staff to leave

    Implementation and information for users

  • 18 Sep 2026Consular-measure deadlines in Germany and Russia

    Cessation of operations and alternative services

  • 9 Oct 2026End of the current EU sanctions extension

    New Council and Official Journal decisions

  • After 17 Jul 2026After the CER identification deadline

    National designation, notification and supervision

  • OngoingOutages, recovery, investigations, disclosures

    Functions, duration, costs and specific responsibility

A legal deadline is not evidence that implementation is complete

The EU Critical Entities Resilience Directive, or CER Directive, required member states to identify critical entities by 17 July 2026. Risk assessments, protective measures and reporting of significant incidents form part of the framework. The passage of that deadline does not establish that every country and operator has completed implementation. National designation, notification and supervision remain important checkpoints.[16]

At the operating level, continuity and restoration matter more than the number of announced measures. Operator outage notices, reopening information, explanations of alternative arrangements and relevant costs in company disclosures can help. Comparisons should use consistent periods and definitions and distinguish ordinary maintenance or seasonal effects. A short restoration time means less if a substantial backlog remains.

For investigations, watch for new official accounts, charges and court findings. A suspect being identified, a charge being filed and a conviction are distinct developments. Rather than read a government statement as if it already contained a criminal verdict, ask what has become more specific and what has changed. This avoids both excessive certainty and indiscriminate scepticism.

For readers, a practical sequence is: what happened, what stopped, what recovered and which costs remained? Updates on attribution should be followed alongside that sequence, not substituted for it. The more serious the news, the more useful it is to return to relevant functions and conditions rather than simply follow an expanding stream of headlines.

The final assessment: preserving normal life under pressure

Europe’s challenge cannot be resolved solely by deciding which side of the verbal boundary between war and peace it occupies. People commute, companies deliver, public authorities function and assistance continues. Pressure that makes these ordinary activities more expensive, slower and less reliable sits at the intersection of security and economics. The diplomatic confrontation over Leipzig has brought that intersection into focus.

Converting every accident into hostile action would misdiagnose the problem. Using every uncertainty as a reason to postpone protection would leave essential functions exposed. The task is to be careful about causation while improving preparations that remain useful before causation is settled: accelerate the recovery clock without corrupting the accountability clock.

Deterrence is tested not only by the force of condemnation, but by the ability to keep society functioning—and to restore it when disrupted.

For management, the useful task is not only to imagine a maximum loss but to establish where operations could stop and how they would restart. For households, it is to separate general anxiety from the condition of contracted services. For market participants, it is to distinguish political significance from the conditions necessary for price transmission. Different readers need different evidence from the same event.

Europe’s strength cannot be measured by a promise that no incident will ever occur. It rests on containing harm, restoring essential functions, preventing costs from spreading without limit and pursuing responsibility through evidence. Continued improvement can reduce the political and economic payoff even when attacks persist. Concrete performance, rather than stronger adjectives, should determine how that assessment evolves.

Frequently asked questions

How does hybrid warfare differ from conventional war?

Hybrid methods combine military and non-military, overt and covert means. They can accompany armed conflict or exert pressure without an obvious conventional armed attack. The label alone does not determine legality or the appropriate response; the specific conduct, harm and responsibility matter. Russian-speaking residents or people critical of government policy cannot be linked to an operation without evidence of relevant conduct.[10]

Does sabotage automatically trigger NATO Article 5?

No. NATO states that hybrid actions could lead to a decision to invoke Article 5, not that every incident automatically produces the same response. Allied political decisions and the nature and scale of the action matter. Nor does the absence of an Article 5 decision rule out policing, diplomacy, sanctions or infrastructure protection. Responses are available before a situation becomes an overt conventional war.[10]

Are all subsea cable incidents suspected of Russian involvement attacks?

No. Physical damage, intent and state involvement are different questions. The accidental explanation announced by Swedish prosecutors on 13 October 2025 illustrates that distinction. It does not prove that other incidents were accidents too. Each investigation must be followed on its own evidence and assessments revised when findings change. Critical infrastructure requires vigilance and accurate diagnosis together.[9]

Should cyberattacks, power failures and logistics disruption be counted together?

One attack can cause several failures, while unrelated causes can occur at the same time. Depending on the purpose, counts should distinguish attacks, affected facilities, interrupted functions and users. Double-counting one event across several damage categories can exaggerate the threat; calling it one incident can also conceal its breadth. The starting point is to establish the unit the statistic actually counts.

Will European disruption immediately raise Japanese energy bills?

Not uniformly. Changes in European purchasing would have to affect cargo allocation or prices and then pass through exchange rates, contracts and tariff arrangements before reaching households. A local disruption absorbed quickly may have limited effects. Provider notices and contractual terms are more directly useful than estimating a bill from a headline. Wholesale spot prices and retail tariffs are different things.

Does this guarantee better results for defence or cybersecurity companies?

Potential new demand is different from a company’s ability to increase earnings. Timing, delivery capacity, recruitment costs, contract terms and competition shape the outcome. Expectations may also already be reflected in market valuations. Exposure to a theme does not establish an investment return; revenue opportunity, margins, cash flow and valuation require separate analysis.

Should businesses wait until state involvement is established?

Not before preparing to protect ordinary operations. Alternative contacts, restart priorities, supplier notices and clear responsibilities can help in accidents as well as attacks. Public accusations against a person or state, however, require care about evidence and official findings. Separating operational response from public claims about causation allows preparation without unnecessary overreaction.

What evidence would change this assessment?

A changed attribution following an investigation or court finding would require revising arguments that depend on that case. If improved preparedness failed to reduce harm or downtime, the limits of a resilience-led approach would need examination. Conversely, stable essential services, contained additional costs and demonstrable constraints on support capabilities would strengthen the assessment of deterrence. Consistency across several observations matters more than a brief quiet period.

Sources and further reading

Primary sources

  1. [1] German Federal Foreign Office · 2026-09-01Russian responsibility for the attempted Leipzig attack: joint press conference
  2. [2] German Federal Government · 2026-09-02Government press conference of 2 September 2026
  3. [3] German Federal Foreign Office · 2026-09-02Government press conference: measures concerning Russia
  4. [4] NATO · 2026-09-02Remarks with the President of the European Commission
  5. [5] UK Foreign, Commonwealth & Development Office · 2026-09-03UK summons Russian Chargé d’Affaires after reckless attack on Leipzig airport
  6. [6] Russian Embassy in Germany / Russian Foreign Ministry official channel · 2026-09-01Embassy statement rejecting German accusations
  7. [7] Russian Foreign Ministry official channel · 2026-09-07Countermeasures concerning German diplomatic and cultural facilities
  8. [8] Crown Prosecution Service · 2025-10-24Updated with sentence: plot to sabotage Ukrainian aid warehouses on UK soil
  9. [9] Swedish Prosecution Authority · 2025-10-13Förundersökning om grovt sabotage av kommunikationskabel läggs ned
  10. [10] NATO · 2026-01-29Countering hybrid threats
  11. [11] Danish Security and Intelligence Service (PET) · 2026 edition · p. 8Modus: Hvordan opererer fremmede stater og deres efterretningstjenester?
  12. [12] Council of the European Union · 2024-10-08 framework establishedRussia’s hybrid activities: EU sanctions
  13. [13] Council of the European Union · 2026-03-16Council adopts conclusions on advancing the EU’s capacity to counter hybrid threats
  14. [14] Council of the European Union · 2026-07-13Russian cyber-attacks and destabilising activities: nine individuals and four entities sanctioned
  15. [15] Council of the European Union · 2025-10-03Russian hybrid threats: restrictive measures prolonged by another year
  16. [16] Publications Office of the European Union / EUR-Lex · 2024-02-19 · Directive (EU) 2022/2557Making critical entities more resilient
  17. [17] NATO · 2024-11-13Resilience, civil preparedness and Article 3
  18. [18] German Federal Government · 2026-08-05 / 2026-09-01 statementsQuestions and answers on hybrid attacks and drone incidents

Related reporting

  1. Reuters · 2026-09-07Russia closes German consulate in St Petersburg after drone spat
  2. Associated Press · 2026-09-07Russia shuts German consulate in St. Petersburg in tit-for-tat move after Leipzig drone incident