Who’s to Defend Europe? The Russian Cyberthreat and NATO-EU Coordination Failure
In June 2017, malware disguised as a ransomware attack spread from a Ukrainian accounting platform, M.E.Doc, which is used for tax filing. It reached its peak global spread within hours after traversing country networks in a matter of minutes (GSI, 2017; CISA, 2018). M.E.Doc crippled high profile corporations, such as Maersk and Merck, shut down hospitals, and caused an estimated $10 billion in damages across 65 countries, making it the most destructive cyberattack recorded to this day (Steinberg et al., 2021). Despite such significant damages on European soil, Article 5 was not triggered within NATO and a coordinated EU reaction did not follow the cyberthreat. Additionally, no single institution was put in charge of resolving this crisis (Greenberg, 2018). Since at least 2007, Russian cyber-operations have targeted critical infrastructure with increasing sophistication in Eastern Europe. In light of the Eurasia Group’s identification of Russia’s hybrid war with NATO as a top 5 political risk in 2026 (Eurasia Group, 2026), a coordination between NATO’s military cyber mandate and the EU’s civilian resilience framework must be found, or else this structural vulnerability will continue to be exploited.
The Threat Landscape
Russian hybrid warfare and cyberattacks are not new. The first Russian cyberattack with indications of political motivations dates back to April-May 2007. Following a diplomatic dispute between Russia and Estonia, a three-week Distributed-Denial-of-Service (DDoS) attack struck the Estonian government and Estonia’s parliamentary portals, ministries, news outlets, internet service providers, major banks and small businesses (Pamment & Sazonov, 2019). These attacks were the main driver behind NATO’s publication of its first Policy on Cyber Defense in January 2008, which claimed that cyberattacks constituted an act of war under the Washington Treaty’s Article 5 (NATO, 2024). Even though stakeholders did not attribute these threats to the Russian government, after a technical and linguistic analysis of the code, they identified Russian-affiliated actors as the people who executed them.
Russia’s cyberattacks have become more sophisticated since this incident. The attacks accompanied the Russian intervention of Georgia in 2008, crippling government communication structures. In both 2015 and 2016, the GRU-affiliated Sandworm group, which was later found responsible for the NotPetya attacks, attacked power grid infrastructure in Kyiv. In the 2015 attack alone, over 225,000 customers were left without power (Dragos, 2017). Cyberwarfare has subsequently become a defining feature of the ongoing Russian-Ukrainian conflict, and its spill-over effects affect Russia’s neighbouring states (ENISA, 2023).
The most recent studies about Russia’s cybertactics are worrisome for members of NATO and the EU. Accompanying the vast increase in the number of Russian-attributed cyberattacks, a 2025 study by Microsoft found that nine out of ten countries attacked by Russian cyberwarfare were members of the NATO Alliance (the tenth being Ukraine). Additionally, it revealed that attacks against them have increased by 25% during that year, with the most targeted sector being their governments (Microsoft, 2025). In September 2025, the Bratislava-based ESET discovered HybridPetya, a technically enhanced copycat of the 2017 attacks malware uploaded from Poland, capable of bypassing UEFI Secure Boot protections on modern systems (ESET, 2025). Though not yet deployed, its existence signals that the malware ecosystem is actively iterating on history’s most destructive cyberattack.
The Institutional Gap
The reason for a failure of collective responses from Western European countries part of the European Union lies in the division between NATO’s military mandate and the EU’s civilian one. When lines are blurred between clandestine-made malware and a state-orchestrated attack, this gap becomes an Achilles’ heel that complicates cybersecurity provisions in Europe.
NATO’s cyber posture is both military and reactive. Its 2008 Cyber Defence Policy has reaffirmed cyberspace as a domain of operations, establishing that attacks on allied cyberspace can trigger collective defence under Article 5 (NATO, 2024). The institution has established a multiorganizational architecture to prevent such threats. The Cyber Defence Committee, Allied Command Operations, NATO Communications and Information Agency, and NATO Cyber Security Centre at SHAPE in Mons all contribute to an integrated military cyber defence framework (NATO, 2024). In June 2025, NATO member states committed to spending 3.5 to 5 percent of the organization’s GDP on defence, explicitly including cybersecurity within defence-related investment categories (NATO, 2025). Yet NATO’s mandate does not allow for its members to take an active role in the protection of civilian infrastructure from cyberattacks. This example of a reactive posture (Nielsen & Pontbriand, 2024) can become an issue when civilian infrastructure, such as power grids and financial systems, are among primary targets.
On the other hand, the EU’s mandate is regulatory and civilian. It has constructed a substantial civilian cybersecurity framework (European Commission, 2025). A recent 2024 study found that 154 EU legal documents and 26 actors are held responsible for cybersecurity policy, covering sectors from finance and energy to transport, health, and government services (Rupp, 2024). This breadth is also its weakness because it leads to fragmentation, inconsistency, and coordination complexity across institutions, sectors, and member states. The EU lacks a unified military command structure and its collective defence clause under Article 42(7) TEU states the necessity for political agreement rather than automatic enforcement. This serves as a significant constraint when immediate response is required (Clapp & Verhelst, 2022). The EU Cyber Diplomacy Toolbox, which was first deployed in 2020 to sanction GRU officers responsible for the 2015 Bundestag hack, illustrates its developed workarounds at the diplomatic level (Council of the EU, 2020). However, on a defense level, it remains weak and cannot substitute coordinated action.
The result is a gap that is both structural and predictable. When NotPetya struck Ukrainian infrastructure in 2017, it simultaneously compromised civilian logistics systems and military-adjacent communications networks. Neither institution had clear primacy. The 2023 EU-NATO Joint Declaration acknowledged the need for deeper cyber cooperation but has not yet established an enforcement mechanism for collective response. Three structural barriers continue to explain why this gap persists: the absence of shared classified communication channels between institutions, uneven national cyber preparedness across member states that generates scepticism about collective assistance, and the near-total absence of joint exercises since 2003 (Lété & Pernik, 2017). As such, this coordination failure is what allows Russian operations to go virtually unreprimanded. The deliberate use of criminal-affiliated actors rather than uniformed military units is not logistical convenience, but rather a doctrinal choice designed to exploit the civilian-military divide.
The Way Forward
In a European context, where individual countries lack the capacity to respond to cyberthreats, the policy prescription for the region’s security is not novel in its broad outlines. The literature has called for closer EU-NATO cooperation for over a decade (Pernik, 2014; Lété, 2019; Poptchev, 2020). Therefore, there is a need for sequenced specificity about what such cooperation should look like and in what order it should be built.
The most immediately achievable reform is joint exercises. NATO’s annual Cyber Coalition Exercise, which is one of the world’s largest multinational cyber defence drills, should be opened to EU institutions and PESCO member states. This requires political will without treaty change; therefore, it is possible in the short term. The current situation in which the two institutions most responsible for European security have not conducted a single joint exercise in over two decades is institutionally inexplicable given the threat environment.
This may, in turn, pave the way for shared situational awareness. The absence of immediate classified communication channels between ENISA and NATO’s Cyber Security Centre means that in the event of a major attack, the two institutions are sharing information through informal, slow mechanisms at precisely the moment when speed is most consequential. A formal information sharing protocol with agreed classification standards should be embedded in the next iteration of the EU-NATO Joint Declaration, with a compliance review mechanism attached.
The goal behind this should become a jointly agreed set of threshold criteria that define when a cyberattack triggers collective response, through which institution, and by what timeline. The current ambiguity around Article 5 versus Article 42(7) is not a grey area that responsible institutions can afford to leave permanently unresolved. A joint working group should be tasked specifically with producing this framework, drawing a meaningful distinction between criminal, hybrid, and state-directed attacks and assigning institutional primacy accordingly.
Final Words
NotPetya cost $10 billion and paralysed infrastructure across 65 countries without triggering institutional response. Nearly a decade later, the architecture that failed in 2017 remains unreformed while the threat only increases. With 42 Russian-attributed incidents recorded in 2023 alone and HybridPetya signalling active iteration on history’s most destructive cyberattack, the question is no longer whether Europe will face a comparable assault, but whether its two principal security institutions will have closed the gap before it arrives. Europe cannot afford to answer the next NotPetya in the same way it answered the last one.
Bibliography
CISA (2018). “Petya ransomware”. Cybersecurity and Infrastructure Security Agency. Available at: https://www.cisa.gov/news-events/alerts/2017/07/01/petya-ransomware
CSIS (2026). “Significant Cyber Incidents Since 2006.” Center for Strategic and International Studies. [Report] Available at: https://www.csis.org/programs/strategic-technologies-program/significant-cyber-incidents
Council of the EU (2020). EU imposes the first ever sanctions against cyber-attacks. Council of the European Union. [Online Source] Available at: https://www.consilium.europa.eu/en/press/press-releases/2020/07/30/eu-imposes-the-first-ever-sa nctions-against-cyber-attacks/
Dragos Inc. (2017). CRASHOVERRIDE. Analysis of the Threat to Electric Grid Operations. [Report]. Available at: https://nsarchive.gwu.edu/document/15319-dragos-crashoverride-analyzing-threat
ENISA (2023). ENISA Threat Landscape 2023. [Report]. Available at: https://www.enisa.europa.eu/sites/default/files/publications/ENISA%20Threat%20Landscape%2 02023.pdf
ESET (2025). “Introducing HybridPetya: Petya/NotPetya copycat with UEFI Secure Boot bypass”. ESET Research. [Online Source]. Available at: https://www.welivesecurity.com/en/eset-research/introducing-hybridpetya-petya-notpetya-copyc at-uefi-secure-boot-bypass/
Eurasia Group (2026). “Eurasia Group’s Top Risks for 2026”. Eurasia Group [Online Source]. Available at: https://www.eurasiagroup.net/issues/top-risks-2026
Greenberg, A. (2018). “The untold story of NotPetya, the most devastating cyberattack in history.” Wired. Available at:
https://www.wired.com/story/notpetya-cyberattack-ukraine-russia-code-crashed-the-world/
GSI (2017). “Collateral damage: NotPetya takes Russia’s cyber war global”. Global Security Intelligence / S-RM. [Online Source]. Available at: https://gsi.s-rminform.com/articles/collateral-damage-notpetya-takes-russias-cyber-war-global
Lété, B. (2019) “Chapter 4. Cooperation in Cyberspace” in Lindstorm, G. & Tardy T. (eds.) The EU and NATO. The essential partners. European Union Institute for Security Studies. Paris. DOI: 10.2815/493939
Lété, B., Pernik, P. (2017). “EU-NATO Cybersecurity and Defense Cooperation: From Common Threats to Common Solutions”. German Marshall Fund of the United States. Available at: https://www.gmfus.org/sites/default/files/EU-NATO%20Cybersecurity%20and%20Defense%20 Cooperation%20edit.pdf
Microsoft (2025). Microsoft Digital Defense Report. [Report]. Available at: https://www.microsoft.com/en-us/corporate-responsibility/cybersecurity/microsoft-digital-defens e-report-2025/
Nielsen, R., Pontbriand, K. (2024). “‘Hands off the keyboard’: NATO’s cyber-defense of civilian critical infrastructure” Defense Studies, 25(3). (pp. 519-542). Available at: https://www.tandfonline.com/doi/full/10.1080/14702436.2025.2454353?af=R#abstract
North Atlantic Treaty Organization (NATO) (2024). “Cyber defense”. North Atlantic Treaty Organization. [Online Source]. Available at: https://www.nato.int/en/what-we-do/deterrence-and-defence/cyber-defence
North Atlantic Treaty Organization (NATO) (2025). “Defense expenditures and NATO’s 5% commitment”. North Atlantic Treaty Organization. [Online Source]. Available at: https://www.nato.int/en/what-we-do/introduction-to-nato/defence-expenditures-and-natos-5-com mitment
Pamment, J., Sazonov, V. (2019). “Hybrid Threats: 2007 cyberattacks on Estonia”. NATO Strategic Communications Center for Excellence. [Report]. Available at: https://stratcomcoe.org/publications/hybrid-threats-2007-cyber-attacks-on-estonia/86
Pernik, P. (2014). “Improving Cyber Security: NATO and the EU”. International Center for Defense Studies. Available at: https://icds.ee/wp-content/uploads/2010/02/Piret_Pernik_-_Improving_Cyber_Security.pdf
Poptchev, P. (2020). “NATO-EU Cooperation in Cybersecurity and Cyber Defence Offers Unrivalled Advantages”. Information & Security, 45. (pp. 35-55). Available at: https://isij.eu/system/files/download-count/2023-01/4503_nato_eu_cybersecurity_cooperation.pd f
Steinberg, S., Stepan, A., Neary, K. (2021). “NotPetya: A Columbia University Study”. Columbia’s School of International and Public Affairs (SIPA). New York. Available at: https://www.sipa.columbia.edu/sites/default/files/2022-11/NotPetya%20Final.pdf
