Russia’s September 7 decision to close Germany’s consulate in St. Petersburg transforms a disputed hybrid-security incident into a widening diplomatic confrontation. The episode demonstrates how operations below the threshold of conventional war can migrate from the shadows into formal interstate relations.
By Vladimir Tsakanyan, Ph.D.
Center for Cyber Diplomacy and International Security (CCD-IS)
Hybrid conflict is often described as competition below the threshold of war.
Europe is now confronting a more difficult possibility:
What happens when activity below that threshold begins producing consequences above it?
On September 7, Russia ordered Germany’s Consulate-General in St. Petersburg to cease operations, escalating an increasingly serious diplomatic confrontation between Moscow and Berlin.
Russia also confirmed the closure of Germany’s Goethe-Institut cultural centers in the country.
The immediate dispute began earlier.
Germany accused Russia of responsibility for an attempted attack involving an explosives-laden drone discovered near a Ukrainian aircraft at Leipzig/Halle Airport in August. Moscow has rejected the accusation.
Berlin subsequently moved against Russian diplomatic and cultural institutions in Germany.
Moscow has now retaliated.
The sequence is strategically important because it demonstrates how an alleged covert operation can migrate through several different layers of international confrontation:
suspected sabotage;
intelligence attribution;
public accusation;
diplomatic punishment;
allied coordination;
and finally interstate retaliation.
No declaration of war occurred.
Article 5 was not invoked.
Yet relations between two major European powers have deteriorated because of an incident situated inside the increasingly dangerous space between espionage, sabotage, cyber operations and conventional armed conflict.
That space is becoming one of the central arenas of European security.
The Hybrid Conflict Has Entered Diplomacy
Hybrid operations derive much of their utility from ambiguity.
Sabotage can be conducted through intermediaries.
Cyber operations can be routed through infrastructure in third countries.
Intelligence services can use contractors or criminal networks.
Information operations can be separated from formal government communications.
Responsibility can be denied.
That ambiguity makes it possible to impose costs without necessarily accepting the political consequences associated with overt military action.
But ambiguity has limits.
Once a government publicly attributes an operation to another state and imposes consequences, the confrontation changes.
The operation leaves the covert domain.
It becomes diplomacy.
Germany’s response to the Leipzig incident and Russia’s September 7 retaliation illustrate that transition.
The important question is therefore no longer simply whether European intelligence services can identify hybrid operations.
It is whether European institutions possess a coherent political framework for what happens after attribution.
Attribution Is Becoming an Instrument of Statecraft
Public cyber and hybrid attribution has evolved significantly over the past decade.
Governments once hesitated to reveal intelligence assessments about malicious state activity.
Today, attribution increasingly performs a strategic function.
It identifies responsibility.
It creates a public record.
It allows allies to coordinate.
It provides political justification for sanctions or other measures.
And it reduces the protection that hostile actors receive from plausible deniability.
The Leipzig confrontation demonstrates the consequences.
Germany did not merely announce that a suspicious drone had been discovered.
It publicly assigned responsibility.
That attribution created the political foundation for subsequent measures against Russian institutions.
Russia responded by rejecting the allegation and imposing reciprocal consequences.
Attribution therefore did something important:
It transformed intelligence into foreign policy.
This is increasingly central to cyber diplomacy as well.
A technical investigation may begin with malware, infrastructure, communications records or forensic evidence.
Its ultimate consequence may be diplomatic expulsions, sanctions or changes in interstate relations.
The boundary between cybersecurity and diplomacy is consequently becoming thinner.
The Real Contest Is Below Article 5
NATO’s collective-defense architecture remains extraordinarily powerful against conventional military aggression.
That strength creates an incentive for adversaries to operate elsewhere.
A direct attack on NATO territory risks a collective military response.
A covert act of sabotage creates a more complicated decision.
So does a cyber intrusion.
So does interference with infrastructure.
So does an influence operation.
So does the use of proxies.
Each can impose costs while creating uncertainty about whether the incident is serious enough to justify a major collective response.
This is not a weakness in Article 5 itself.
Article 5 was never intended to function as the routine response mechanism for every hostile act committed against an Alliance member.
The vulnerability lies in the space underneath it.
If an adversary can repeatedly impose meaningful costs while remaining below the threshold for collective military defense, then deterrence requires additional mechanisms.
Europe increasingly needs a credible ladder of consequences between doing nothing and invoking Article 5.
Europe Is Beginning to Build That Ladder
The European Union already possesses important components.
Its Hybrid Toolbox allows the EU to coordinate responses to campaigns involving sabotage, cyber operations, foreign information manipulation and interference, attacks on critical infrastructure and other forms of destabilization.
The EU also maintains a dedicated sanctions framework addressing Russian destabilizing activities.
Hybrid Rapid Response Teams can support member states and partners.
The Cyber Diplomacy Toolbox provides another mechanism for responding collectively to malicious cyber activity.
These instruments demonstrate an important evolution in European security.
Collective defense no longer begins only when military forces move.
It increasingly includes coordinated attribution, sanctions, intelligence sharing, resilience, diplomatic action and technical assistance.
This architecture remains less dramatic than Article 5.
That may be precisely its purpose.
The objective is to create consequences without automatically transforming every hybrid incident into a military crisis.
September 7 Shows Why This Matters
Today’s Russian action demonstrates that hybrid confrontation can produce a diplomatic escalation cycle of its own.
One state attributes an operation.
It imposes consequences.
The accused state denies responsibility.
It retaliates.
Diplomatic representation decreases.
Cultural institutions close.
Political rhetoric hardens.
Allies become involved.
The original operation may have been designed to remain below the threshold of war.
Its political consequences do not necessarily remain there.
This creates a paradox.
Hybrid activity is attractive partly because it appears controllable.
A state may believe that sabotage, cyber operations or covert interference can impose costs while avoiding conventional escalation.
But once attribution becomes public, domestic and allied political pressures begin influencing the response.
The initiator no longer controls the entire escalation process.
The target does not either.
Hybrid conflict therefore contains an escalation risk that is frequently underestimated.
Ambiguity may delay confrontation.
It does not guarantee that confrontation remains limited.
Kallas’s Warning Changes the European Context
The broader European reaction is equally significant.
On September 7, EU High Representative Kaja Kallas warned that Russian hybrid activity against European states is continuing to intensify and said Europe should prepare for further provocations.
That language matters.
It frames incidents such as Leipzig not simply as isolated law-enforcement cases but as elements of a broader strategic challenge.
Once governments adopt that interpretation, their response changes.
The relevant question is no longer:
Who committed this particular act?
It becomes:
Is this incident part of a continuing campaign?
That shift from incident-based analysis to campaign-based analysis is essential.
Hybrid strategies benefit when governments examine every incident separately.
A suspicious drone becomes an aviation-security problem.
A cyber intrusion becomes a cybersecurity problem.
A damaged cable becomes an infrastructure problem.
An influence operation becomes an election-security problem.
A sabotage attempt becomes a criminal investigation.
Individually, each may appear manageable.
Collectively, they may represent a strategy.
Cyber Operations Fit Naturally Into This Environment
Cyber operations are especially valuable in hybrid competition because they provide enormous flexibility.
An actor can conduct reconnaissance without disruption.
It can establish access and wait.
It can steal information.
It can compromise suppliers.
It can interfere with communications.
It can target public institutions.
It can probe critical infrastructure.
And it can use proxies whose relationship with the state remains deliberately unclear.
Cyber operations also create an attribution challenge.
Technical evidence may indicate connections to known infrastructure or previously observed actors without immediately proving political direction from a government.
This creates time.
And time can be strategically useful to the attacker.
The target must investigate before responding.
Allies must evaluate the evidence.
Governments must decide how much intelligence they are willing to reveal.
Diplomats must construct a common position.
By the time attribution becomes public, the original operation may be months old.
For deterrence, that delay matters.
Consequences are most credible when adversaries can connect them to the behavior that produced them.
Europe Needs Collective Attribution
This leads to one of the most important challenges for European cyber diplomacy.
Collective defense requires collective confidence.
An individual government may possess compelling intelligence.
But if its allies cannot independently evaluate that intelligence, coordinated action becomes more difficult.
Not every intelligence source can be made public.
Nor should it be.
But Europe needs mechanisms that allow governments to share sufficient evidence quickly enough to produce credible common assessments.
The objective should not be perfect certainty.
International politics rarely provides it.
The objective should be sufficient shared confidence for collective political action.
This is particularly important when hostile operations deliberately exploit jurisdictional boundaries.
A cyber operation may use infrastructure in several countries.
A sabotage network may recruit individuals across Europe.
Cryptocurrency may finance intermediaries.
Communications may pass through commercial platforms headquartered elsewhere.
The operation is transnational.
The investigation and response must increasingly become transnational as well.
Diplomatic Retaliation Has Limits
Closing consulates and cultural institutions sends a political message.
It also imposes costs.
But diplomacy faces an important limitation.
Every reciprocal closure reduces channels of communication.
That may be desirable when diplomatic facilities are believed to facilitate intelligence activity.
But it also reduces the institutional infrastructure available during future crises.
This produces another paradox.
As confrontation intensifies, governments may simultaneously have stronger reasons to punish one another and stronger reasons to maintain communication.
Cyber and hybrid crises make this particularly important.
A serious cyber incident involving critical infrastructure can develop quickly.
Governments need mechanisms to communicate intentions.
They need channels through which warnings can be delivered.
They need methods for distinguishing deliberate escalation from unintended consequences.
Diplomatic pressure and diplomatic communication therefore have to coexist.
Punishment without communication can create uncertainty.
Communication without consequences can create impunity.
Cyber diplomacy operates between those two risks.
The Objective Should Be Deterrence Below War
Europe does not need to treat every hybrid operation as an act of war.
Doing so would create instability and potentially give relatively small incidents disproportionate strategic consequences.
Instead, Europe needs credible deterrence below war.
That requires several layers.
First, resilience.
Operations become less attractive when targets are difficult to disrupt.
Second, attribution.
Plausible deniability becomes less valuable when governments can expose operations quickly and credibly.
Third, collective consequences.
An adversary should not be able to isolate individual European states and absorb separate national responses.
Fourth, proportionality.
Consequences must be strong enough to matter without automatically producing uncontrolled escalation.
Fifth, communication.
Adversaries must understand why consequences were imposed and what behavior would produce further action.
These elements together form a deterrence architecture appropriate to hybrid conflict.
The Cyber Diplomacy Toolbox Is Becoming a Security Instrument
This has important implications for how cyber diplomacy itself should be understood.
Cyber diplomacy is often associated with negotiations over norms, confidence-building measures and responsible state behavior.
Those functions remain important.
But cyber diplomacy increasingly operates inside active strategic competition.
It coordinates attribution.
It organizes allied responses.
It communicates thresholds.
It supports sanctions.
It builds coalitions.
It strengthens partner resilience.
It helps prevent technical incidents from becoming uncontrolled geopolitical crises.
In that sense, cyber diplomacy is becoming part of deterrence.
Not because diplomats conduct cyber operations.
But because cyber power without political coordination produces limited strategic effect.
Technical capability identifies and disrupts threats.
Diplomacy converts those actions into international consequences.
The Risk Is Normalization
Europe’s greatest danger may not be one catastrophic hybrid operation.
It may be gradual normalization.
A cyberattack occurs.
Then sabotage.
Then another suspicious drone.
Then interference with infrastructure.
Then an influence campaign.
Each event receives attention.
Each eventually disappears from the news cycle.
Over time, hostile activity becomes part of the expected political environment.
That would represent a strategic success for the attacker.
The objective of deterrence is not only preventing catastrophic attacks.
It is preventing hostile activity from becoming an accepted cost of normal international relations.
Europe therefore needs to demonstrate that operations deliberately kept below the threshold of war can still accumulate meaningful consequences.
Otherwise, the gray zone becomes a sanctuary.
Bottom Line Assessment
Russia’s September 7 decision to close Germany’s consulate in St. Petersburg is more than another episode in deteriorating German-Russian relations.
It reveals the escalation pathway of modern hybrid conflict.
A covert incident becomes an investigation.
An investigation becomes attribution.
Attribution becomes diplomatic action.
Diplomatic action produces retaliation.
Allies become involved.
And an operation originally situated below the threshold of conventional war begins affecting the formal architecture of interstate relations.
That is the strategic significance of the current confrontation.
Europe’s challenge is not simply determining whether individual hybrid incidents cross the threshold for Article 5.
It is developing credible collective consequences for operations deliberately designed never to cross it.
The EU already possesses many of the necessary instruments.
Cyber diplomacy.
Hybrid-response mechanisms.
Sanctions.
Collective attribution.
Intelligence cooperation.
Resilience programs.
Partnership with NATO.
The next step is integrating them into a coherent deterrence strategy.
Europe should not have to choose between tolerating hybrid aggression and escalating directly toward military confrontation.
There is a large strategic space between those outcomes.
That is precisely the space Russia and other states have learned to exploit.
Europe’s security will increasingly depend on whether it can defend that space itself.
Vladimir Tsakanyan, Ph.D.
Center for Cyber Diplomacy and International Security (CCD-IS)


Leave a comment