1 October 2026

5 min read

Qtr 3, 2026 | War in Peace: The (un)deniable threat to Europe’s critical infrastructure

Global Risk Bulletin
EU data bits and bytes wave ripples image

Safeguarding critical infrastructure has emerged as a key security priority for European governments in recent years. Neo Tsotetsi discusses the threat landscape driving this reprioritisation, and evaluates the risk posed to commercial operators in these sectors across the coming year.  

In August, British authorities reported that a cyberattack had forced a small-scale power generator to suspend operations for four days in July. The government did not identify those responsible, although public reporting linked the incident to Iran-affiliated hackers. The disruption was limited, but it illustrates the growing threat to European critical infrastructure from geopolitically motivated sabotage and terrorism. Iran-linked actors have used such attacks to impose costs on states aligned with the US and Israel beyond the conventional battlefield. Russian-linked actors, meanwhile, have sought to damage and disrupt transport, energy and communications infrastructure as part of a broader ‘grey zone’ campaign against European North Atlantic Treaty Organisation (NATO) members and supporters of Ukraine. Over the coming year, European infrastructure is likely to face an elevated risk of deniable and opportunistic disruption, ranging from cyber intrusions and interference with communications systems to proxy-enabled physical sabotage. Such activity will heighten geopolitical tensions and increasingly carry operational and commercial consequences.

Critical sectors

As stipulated by European Union (EU) Commission
European Union (EU)

260929 War in Peace_graphs-01

In the crosshairs

Critical infrastructure has become an increasingly attractive target for hostile actors because disruption at a single site can generate cascading economic, political and social effects far beyond the immediate point of attack. The EU’s Critical Entities Resilience Directive (CERD) defines critical entities as providers of services essential to societal functions, economic activity, public health and safety, or the environment. Yet, the preparedness of many such operators for the present threat environment remains uneven. Much of Europe’s infrastructure was designed during a less contested security era and was not necessarily built to withstand the combined physical and digital threats they currently face.

The risk is heightened by the interdependence of essential systems: disruption to power, telecommunications or transport can rapidly affect businesses, public services and supply chains. Perpetrators also frequently seek to preserve plausible deniability, using proxies and covert methods to obscure responsibility. This complicates not only prevention, but also the political and legal threshold for a proportionate response. For hostile actors, attacks on civilian-facing services can therefore generate outsized disruption, financial loss and public anxiety without requiring a large-scale or openly attributable attack. 

Critical sectors

As stipulated by European Union (EU) Commission
European Union (EU)

War in Peace_graphs-03-2

Threading the needle

European governments are acutely aware of the current threat environment and need to strengthen critical infrastructure resilience, but converting broad political commitments into effective protection will prove to be politically challenging. The EU’s CERD, which details the need for member states to comprehensively address the resilience of critical entities, required members to transpose common rules into national law by October 2024. It also requires them to develop national resilience strategies, assess systemic risks and identify operators providing essential services. Designated entities need then assess their own exposure and implement proportionate resilience measures. However, delivery is varied between countries, due to differences in regulatory capacity, public funding, threat perception and the fragmented ownership of infrastructure, much of which is privately operated or crosses national borders.

NATO’s 2025 commitment to spend 5 percent of GDP on defence by 2035 includes at least 3.5 percent on core defence requirements and up to 1.5 percent on broader security investments, such as critical infrastructure protection, network defence, and civil preparedness. However, this increased funding does not automatically guarantee improved infrastructure security. Governments are having to balance such investments against competing military, fiscal and social priorities, while operators face the practical challenge of upgrading ageing systems without interrupting essential services. National initiatives such as Sweden’s Total Defence model can strengthen continuity planning and civil preparedness, but the scale, cost and cross-border character of Europe’s infrastructure will make comprehensive protection difficult.

Weathering the storm

As Europe’s security environment becomes more volatile, companies that operate, or depend heavily on, critical infrastructure face a more turbulent risk outlook. For operators themselves, the immediate concern is direct damage to their property and personnel. However, the commercial exposure is usually far broader: even a contained incident can halt production, interrupt access to essential inputs, and require costly rerouting. The resulting costs can spread rapidly through dependent businesses and supply chains, particularly where firms rely on just-in-time operations or have limited alternatives to a disrupted service. For companies, the approach to building resilience will include investing in the physical security of their assets and understanding dependencies on logistics routes, communications networks and contingency capacity.

Case study: 2024 cargo flight sabatoage
Target countries
United Kingdom (UK), Poland
Targeted sectors
Transport (Logistics)
Method of sabotage
Courier parcels containing sophisticated self-igniting incendiary devices, mailed from Lithuania to destinations in the UK and Poland. Intended to detonate on transiting cargo airplanes 
Outcome
  • Parcels addressed to the UK: one caught fire and detonated at the Leipzig/Halle Airport in Germany, and the other detonated in a warehouse in Birmingham
  • Parcels addressed to Poland: one detonated inside a truck near Warsaw, while other malfunctioned
Immediate impact
Severe damage to truck and customers' cargo in Poland, including the full payload of one freight trailer (estimated to be roughly USD 200,000); limited damage in Leipzig and Birmingham
Knock-on impact 
  • Significant disruptions to depots in Leipzig and Birmingham, as well as in- and outbound cargo flights
  • Increased security protocols for freight forwarders including mandatory x-ray scans and more stringent ID requirements for senders
  • Increased insurance premiums for aviation cargo operators

While European governments broadly concur on the importance and urgency of critical infrastructure resilience, the tension between their long-term strategic priority and present political realities has the potential to be a stumbling block. Governments are likely to strengthen planning, intelligence-sharing and protective capabilities, particularly where recent incidents have exposed clear vulnerabilities. However, improving resilience requires substantial, long-term spending on systems whose value is often most apparent when disruption does not occur. In a constrained fiscal environment, governments will need to balance these investments against competing priorities, while making a clearer case for how increased infrastructure resilience protects both essential services and wider economic security.

Subscribe to our insights

Get industry news and expert insights straight to your inbox.