Location:RUSI, 61 Whitehall
Start date:21/09/2026
End date:21/09/2026
Event Organiser:Royal United Services Institute (RUSI)
RUSI members’ event moderated by Rachel Ellehuus, Director General, RUSI. Panel to include:
- Ben Hillier, Head of Cyber Policy, NATO; and
- Kaja Ciglic, Senior Director Cybersecurity Policy & Digital Diplomacy, Microsoft
A November 2025 coordinated cyber-attack struck distributed energy sites across Poland, done by the same group responsible for the 2015 and 2016 attacks on Ukraine’s power grid. It did not arrive alone. Two months earlier, around twenty drones had crossed into Polish airspace, prompting Poland to invoke Article 4 of the North Atlantic Treaty; information operations amplifying denials of Russian culpability followed. One campaign, at least three domains, and a European response still largely organised around tackling one threat at a time.
Poland is not exceptional. Europe has seen possibly more than 140 drone incursions over ports, air bases and aircraft carriers, alongside persistent subsea cable sabotage, influence campaigns and a sustained tempo of malicious cyber activity – including state harbouring of criminal groups, criminal fronts for state operations, and prepositioning in critical national infrastructure held in reserve.
Much of it is ambiguous by design, and hard to attribute, legally or technically. The defence of territory and national interests in the face of hybrid threats will increasingly rely on how well European states can integrate and coordinate capabilities to achieve deterrence outcomes, including in and through cyberspace. While a whole-of-government approach that uses all levers of state power is needed to degrade adversaries’ strategic advantage in cyberspace, operationalisation can often be more challenging than not.




