Europe is learning the wrong lesson from Russia's drone war

A sign reading "No drone zone" at Brussels Airport in Zaventem, Belgium, on Nov. 5, 2025. (Nicolas Tucat/AFP via Getty Images)

Megi Benia
Founder and Director of the Strategic Security Initiative
European governments are preparing for a form of confrontation that their current investments do not fully match.
While Russian-linked sabotage usually uses drones, logistics networks, criminal intermediaries, and deniable proxies against European cities, official policies and national strategies remain focused on detecting and intercepting each incident as it arises.
This approach treats only the instrument of attack, leaving the vulnerability it exploits mainly overlooked.
That vulnerability is clear: Europe's security architecture remains slow, fragmented, and expensive to mobilize across agencies and national boundaries.
In this environment, drone incursions become just separate incidents, while the problem of long, inefficient responses remains unaddressed. The incident at Leipzig/Halle Airport on Aug. 4 with a quadcopter carrying plastic explosives that went unnoticed by security systems and landed near a Ukrainian cargo aircraft without detonating, belongs to a wider pattern of Russian sabotage activities against European cities, especially those targeting the major airports across the continent.
Each case, whether or not an attack was intended or completed, leaves the same residue of uncertainty, and that uncertainty is what makes cheap, deniable activity so effective against institutions that are otherwise highly capable.
A drone flying near or above an airport can disrupt the normal performance of critical civilian infrastructure by forcing the immediate closure of airports, overloading the work of police and intelligence services, and occupying resources even if no attack follows.
Democratic governments have legitimate reasons to take ambiguous threats seriously, but that very prudence can hand Moscow and its proxies an operational advantage, since an attacker capable of creating enough doubt to interrupt normal activity has no need to defeat an air-defense system at all.

Thus, the strategic value of such operations is their ability to force the defender to spend time, resources, and political capital determining whether an attack is actually taking place.
Under these conditions, Europe may win individual tactical engagements while losing the broader struggle over resources, resilience, and tempo.
More importantly, Europe's reading of Russia's drone campaign in Ukraine has focused attention on counter-drone technology, sensors, and interception systems, all of which are necessary for protecting infrastructure but cannot compensate for the institutional fragmentation that an adversary is actively exploiting.
In fact, Ukraine's experience demonstrates the importance of an organizational approach.
Against years-long Russian drone attacks, Ukraine has progressively connected battlefield reporting, air-surveillance data, acoustic and other sensor inputs, drone feeds, and intelligence into increasingly integrated situational-awareness and command systems, including the DELTA platform, allowing information from different sources to be brought together and distributed to those responsible for action.

It has also adapted its response architecture by combining centralized information with distributed defensive capabilities, enabling units and mobile teams to respond to threats without waiting for every decision to move through a complicated process of hierarchy.
As a result, Ukraine streamlined the process of detection, identification, decision, and action. This is a useful model that Europe should explore.
Attribution is another problem, because deniable sabotage is designed to take advantage of the interval between an incident and a verdict.
When investigators need weeks to establish responsibility, as it was during the Leipzig incident, where German authorities took around four weeks to publicly assign responsibility to Russia, attribution becomes a retrospective exercise and no longer functions as an indispensable aspect of deterrence and defense.
Indeed, public attribution requires credible evidence, and obtaining one might take a long time before authorities establish rock-solid data. .
However, when a citizen is suddenly stranded at an airport due to a drone-related disruption, the consequences of delayed decision-making are immediate and tangible.

To effectively address these challenges, Europe needs to organize counter-sabotage efforts that would incorporate connections, allowing aviation authorities, law enforcement, intelligence services, and armed forces to share information across institutional and national boundaries before an incident becomes a crisis.
In this process, applying lessons from the Ukrainian experience is essential because Ukraine has been forced to solve the problem Europe now faces, and it has learned to turn fragmented information into a usable operational picture and then convert that picture into action before an adversary can weaponize the gap.
Intercepting a drone can prevent an incident, but it cannot address the broader system behind it, leaving the entire process supporting a single drone operation largely intact.
Herewith, success should not be measured by the number of intercepted drones, as it reflects little about the capabilities of the entire system.
The decisive advantage is ensuring that Russia, not Europe, is forced to react, robbed of initiative, denied the ability to dictate the tempo, and made to confront operational costs and risks. Because only by reclaiming the initiative can Europe shift from a posture of reaction to one of control and force its adversaries onto the defensive.
Editor's note: The opinions expressed in the op-ed section are those of the authors and do not purport to reflect the views of the Kyiv Independent.








