Skip to content
International Security

EU’s Emergency Security Protocol: Answering Hybrid Attacks

/ 12 min read / Malik Tanveer Dhool
← Back to Blog
Share X in

WarBrief Live | October 1, 2026 | Intelligence Analysis

On September 28, 2026, European Union defence and foreign ministers held their first substantive debate on a proposed EU emergency security protocol — a standing mechanism that would let any member state trigger urgent, bloc-wide coordination when a hybrid attack lands. Commission President Ursula von der Leyen, who unveiled the idea in her mid-September State of the European Union address, called it “Europe’s own Article 4”: the bloc’s answer to the sabotage, arson, drone incursions and cyberattacks that European governments blame on Russia. It would cover incidents below the threshold of armed aggression — the grey zone where most of this year’s escalation has happened — and sit at the heart of a new EU Security Strategy expected before year’s end.

European governments say the pressure campaign is intensifying. Over the summer, drone overflights, crashes and explosions became near-daily occurrences in parts of eastern Europe, and German officials have accused Russia of being behind an attempted armed drone attack at Leipzig/Halle airport. The question now is whether the EU can build a response faster than the campaign is expanding — and without duplicating NATO’s machinery.

Key Takeaways

  • EU ministers held their first substantive discussion on September 28 of an Emergency Security Protocol — “Europe’s own Article 4” — covering drone incursions, sabotage, arson and cyberattacks that fall below the threshold of armed aggression.
  • Any single member state could trigger the mechanism; all 27 governments would then convene to coordinate a response. Tools under discussion include sanctions, visa restrictions, expert teams and funding — once responsibility for an attack is clearly attributed.
  • The case files behind the push: an attempted drone attack on a Ukrainian aircraft at Leipzig/Halle airport in August (which Berlin blames on Russia), a mid-August arson attack on Estonia’s Milrem Robotics (under investigation as possible sabotage), and a blown-up rail track in Poland (which Warsaw blames on Russia). Moscow denies involvement in all cases.
  • Roadblocks remain: NATO duplication fears, the attribution problem, and uncertain buy-in among the 27. Foreign policy chief Kaja Kallas called the September 28 session “a very initial discussion”; fuller proposals are expected in the new EU Security Strategy next month.

What the Emergency Security Protocol is

The proposal originated with Ursula von der Leyen’s State of the European Union address in mid-September, where she pitched a “counter-hybrid playbook” and “a mechanism to flank NATO’s ‘Article 4′”. “As the threat level climbs, so must Europe’s preparedness,” she told the European Parliament in Strasbourg. The mechanism would allow any EU country to call urgent talks in a crisis and build consensus on responding to incidents in the grey zone below open aggression.

EU foreign policy chief Kaja Kallas, who is developing the proposal together with von der Leyen, told reporters after the September 28 Foreign Affairs Council that it would apply to “everything that is under the threshold of armed aggression” — drone incursions, sabotage, arson and cyberattacks — once attribution is sufficiently clear. The discussion, she said, would look at “the broader strategy against hybrid attacks” and examine “what are the tools that we can use on different levels?”

The Article 4 comparison is deliberate but distinct. When triggered at NATO level, Article 4 requires member countries to consult whenever an ally feels its security is threatened — but as Kallas put it, “Article Four in NATO is just consultations. It’s not any kind of action plan.” The EU mechanism is meant to go further than consultation, examining what member states could actually do once an attack is attributed.

Ministers pressed Kallas hard on one point: the EU must not duplicate NATO protocol. “Many stress that it has to be absolutely complementarity with NATO,” she said. “We don’t create anything additional, but this has to work hand in hand.” Kallas said she had discussed the issue with NATO Secretary General Mark Rutte, and was candid about the state of play: not all ministers took the floor, she could not say how many of the 27 backed the mechanism, and “today was a very initial discussion, which means that we take this forward.”

Background and timeline

Drone caught in a radar sweep over a European airport at night, illustrating the drone incursions driving the EU emergency security protocol debate
AI-generated illustration
  • Mid-September 2026: Von der Leyen proposes the emergency security protocol in her State of the Union address. The European Parliament adopts a resolution saying hybrid attacks can amount to warfare, identifying Russia as the main state-sponsored threat to the EU, and calling for a single coordination centre, a horizontal EU sanctions regime for hybrid actors, and consideration of Article 42(7) in the gravest cases.
  • September 25: The Council of the EU publishes its Forward Look, with defence and hybrid threats on the ministers’ agenda.
  • September 26: A Russian aircraft breaches Finnish airspace over the Gulf of Finland; Finnish and Swedish fighter jets scramble.
  • September 28: The Foreign Affairs Council in Brussels holds the first substantive ministerial discussion of the protocol. The same day, the Council approves five European Defence Projects of Common Interest (EDPCIs): DECODER for drones and counter-drones, IMSD for maritime and seabed defence, SPACE for space capabilities, EU-FIAMD for integrated air and missile defence, and Eastern Flank Watch for the eastern border. Defence Commissioner Andrius Kubilius cites a funding ambition of around €190 billion by 2036.
  • Late September: Estonia, Latvia and Lithuania reportedly send a confidential letter to von der Leyen requesting €500 million for counter-drone capabilities, according to Finnish daily Iltalehti; Lithuania’s Defence Minister Robertas Kaunas confirmed the joint submission to Reuters.
  • September 30: Russia declares European arms factories supplying Ukraine “potential military targets”, in a warning from Foreign Ministry spokeswoman Maria Zakharova that sharpens the escalation ladder the protocol is meant to address.
  • October 15–16: The European Council summit in Brussels is set to debate defence readiness, Ukraine funding and the frozen-assets question.

The case files: a summer of sabotage

The protocol debate is driven by a summer of incidents. Every attribution of Russian authorship below is a government’s claim, and Russian officials deny involvement in the cases raised by European governments.

The most prominent case came in August, when German authorities accused Russia of being behind an attempted armed drone attack on a Ukrainian aircraft at Leipzig/Halle airport. The episode — an armed drone at a major civilian airport — crystallised the hybrid threat in a single image and has become the reference case in the Brussels debate.

In mid-August, Estonian authorities began investigating an arson attack on the defence contractor Milrem Robotics as possible sabotage. Around the same period, Polish officials blamed Russia for the blowing up of a rail track. Incidents in Denmark, Lithuania and Poland were cited as further examples of the changing security environment, and reporting on the September 28 ministers’ meeting described drone overflights, crashes and explosions as near-daily occurrences in parts of eastern Europe over the summer.

Kallas framed the campaign as strategic, not opportunistic. “We need to be vigilant because we see in the intelligence that Russia is planning more sabotage acts,” she said as she arrived for the talks, adding that such attacks are aimed at European democracy — seeking to divide communities and intimidate them into withdrawing support for Ukraine.

Why it matters

A sensor and radar drone wall protecting a European border, part of the EU's counter-drone response to hybrid threats under the emergency security protocol
AI-generated illustration

For ordinary Europeans, hybrid warfare does not arrive as a declaration of war — it arrives as a closed airport, a disrupted railway, a breached airspace, or a cyberattack on a hospital or power grid. The Leipzig/Halle episode put civil aviation squarely in the crosshairs, and the proposed drone wall along the eastern flank is explicitly meant to protect airports and critical infrastructure from drone disruptions. Airspace closures and flight diversions are the costs passengers pay when the grey zone heats up.

There is also a hard security logic. The grey zone is precisely where NATO’s Article 5 does not apply: sabotage, arson and drone incursions sit below the armed-attack threshold, which is why a separate EU playbook is needed at all. Russia’s September 30 warning that European arms factories are “potential military targets” — analysed by WarBrief here — shows how fast that ladder can be climbed, from covert sabotage to overt threats against defence industry on EU soil.

The economics are substantial. The Commission allocated €400 million for drones and counter-drone capabilities in February; the Baltic states are now asking for another €500 million; and the five EDPCIs carry a funding ambition of around €190 billion by 2036. These are taxpayer funds being mobilised for a threat most voters experience only as news headlines — which is why, for a fuller picture of the doctrine at stake, our primer on hybrid warfare and our analysis of cyber intelligence in conflict prevention remain essential reading.

How the playbook would work in practice

As currently outlined, the protocol would operate in four stages:

1. Trigger. Any single EU member state that identifies a hybrid threat can invoke the mechanism, convening all 27 governments. The low trigger threshold is deliberate: hybrid attacks are designed to be deniable and fast, so the response cannot wait for unanimity-building.

2. Convene. Foreign and defence ministers coordinate through the EU institutions — the Commission and the European External Action Service — to assess the incident and the available tools. Kallas and von der Leyen are developing the framework as part of a new EU Security Strategy, with fuller proposals expected next month.

3. Attribute. This is the hard step, and ministers know it. Estonian Defence Minister Martin Herem called for establishing clear attribution before any public action, citing the German approach to Leipzig/Halle as a model. Officials are calling for stepped-up intelligence cooperation and fuller use of the EU Intelligence and Situation Centre (INTCEN) to improve attribution of drone, cyber and sabotage incidents. Without fast, publishable attribution, the protocol cannot move past step two.

4. Respond. The toolbox under discussion includes further sanctions and tighter visa rules for Russian tourists, as floated by Finnish Defence Minister Antti Häkkänen; dispatching expert teams to advise on security and increasing funding, per a senior EU official; and the hardware layer — DECODER counter-drone systems and the Eastern Flank Watch drone wall. EU Defence Commissioner Andrius Kubilius told the Financial Times that “if we are facing hybrid warfare, we need to have hybrid defense,” and reporting on the ministers’ debate says any answer should be painful at a comparable level to the original act.

Two honest caveats apply. First, the details are still vague: diplomats describe the concept as a framework rather than a plan, with no predetermined responses and uncertainty over whether a majority of capitals even supports it. Second, ministers at the same September 28 session agreed on distributing €6.6 billion from the European Peace Facility — with air defence the “key priority” for Ukraine — but made no new pledges for air-defence interceptors, a gap between rhetoric and resources that the protocol alone cannot close.

Different perspectives

Frontline states want urgency. Finland’s Häkkänen argued each country must act while the EU and NATO strengthen coordination; Estonia’s Herem wants attribution discipline first, action second. For the Baltic and Nordic states, hybrid pressure is a daily condition, not a scenario — their €500 million counter-drone request is the bill attached to the debate.

NATO-conscious capitals want guardrails. Several ministers insisted the EU mechanism must complement rather than duplicate alliance processes — the “hand in hand” demand that dominated the September 28 press conference. Kallas’s counter-argument is structural: NATO’s Article 4 only mandates consultation, while the EU protocol would plan actual responses, so the two do not overlap.

Non-NATO EU members bring their own lens. Irish foreign minister Helen McEntee — Ireland being one of four EU states outside NATO — argued the bloc must be able to “not just respond when incidents happen, but also pre-empt possible escalations”. Moscow, for its part, denies involvement in the cases European governments have raised.

The sceptics’ core case is simple: without fast, publishable attribution, agreed tools and majority buy-in, a protocol risks becoming a press conference rather than a deterrent — a venue for coordinating outrage after incidents like Leipzig/Halle, not preventing the next one.

What to watch next

The new EU Security Strategy is the first milestone: officials say fuller protocol proposals will land next month, with publication expected before year’s end. The October 15–16 European Council will show whether leaders attach political weight — and money — to the idea, alongside defence readiness, Ukraine funding and the frozen-assets debate.

On the hardware side, watch the drone wall: the European Drone Defence Initiative is reported to target initial capability by the end of 2026, the Baltic €500 million request needs a Commission answer, and the newly approved DECODER and Eastern Flank Watch projects must convert EDPCI status into funded deployments. Attribution standards — the least visible but most decisive element — will determine whether the protocol ever gets triggered in anger.

WarBrief will track the October summit and the Security Strategy’s release. Follow our Conflict Zones desk and Intelligence Reports for continuing coverage.

Frequently asked questions

What is the EU’s emergency security protocol?
A proposed EU mechanism, unveiled by Commission President Ursula von der Leyen in her mid-September State of the European Union address, that would let any member state trigger urgent bloc-wide coordination in response to hybrid attacks — drone incursions, sabotage, arson and cyberattacks. EU ministers held their first substantive discussion of the idea on September 28, 2026, and fuller proposals are expected in a new EU Security Strategy.

How is it different from NATO’s Article 4?
Von der Leyen called it “Europe’s own Article 4”, but EU foreign policy chief Kaja Kallas drew a sharp distinction: NATO’s Article 4 only requires allies to consult when a member’s security is threatened — “it’s not any kind of action plan” — while the EU mechanism would examine what member states could actually do in response. The EU version is designed to complement NATO, not duplicate it.

What counts as a hybrid attack?
Attacks that fall below the threshold of armed aggression but threaten national security: drone overflights and incursions, sabotage and arson against infrastructure or defence firms, cyberattacks, disinformation and election interference. The summer’s case files include the alleged drone attack at Leipzig/Halle airport, the Milrem Robotics arson in Estonia and rail sabotage in Poland.

Why do governments say attribution matters so much?
Because the protocol can only move to a response once responsibility is clearly established. Estonian Defence Minister Martin Herem argued for proving attribution before any public action, citing Germany’s handling of the Leipzig/Halle case as a model. Faster, publishable attribution is widely seen as the mechanism’s biggest practical obstacle.

When will the protocol be operational?
It is still a proposal, not a policy. The September 28 ministerial discussion was, in Kaja Kallas’s words, “a very initial discussion”, and diplomats describe the details as vague. Fuller proposals are expected in the EU’s new Security Strategy, which officials say should appear before year’s end.

Sources

Written by

Malik Tanveer Dhool

Defense and intelligence analysis for WarBrief.live. Covering conflict, technology, and geopolitical strategy.