Europe’s Benchmark Against Hybrid Threats: Russia, China, and Iran Seek to Weaken the West

September 20, 2026

Ruth Ferrero, a professor of Political Science at the Complutense University of Madrid, meets in Madrid with Teija Tiilikainen (Finland, 1964), director of the European Centre of Excellence for the Lucha contra las Amenazas Híbridas (Hybrid CoE) since 2019. Halfway between a think tank and a research institute, Hybrid CoE is a key player in European and Western security. The center’s figurehead agrees to speak with Agenda Pública about its work, the challenges Europe faces, and the geopolitical outlook.

Funded in 2017 during a period of rising non-traditional threats, today the center brings together all the European Union member states as well as NATO. Although its work is independent, Hybrid CoE operates in constant coordination with all member countries to prevent and better understand threats such as disinformation, electoral interference, or attacks on critical infrastructures. 


 

Teija Tiilikainen has been the director of Hybrid CoE since 2019. Photo: Agenda Pública / Tania Sieira


What is the origin of the European Centre of Excellence for the Fight Against Hybrid Threats? How is its relationship with the EU and NATO?

The center, when created, provided services to governments, acting as a kind of secretariat responsible for coordinating and organizing work among the member states. 

Initially, the United States, the United Kingdom, the Nordic countries (only Finland and Sweden), the Baltic states (Estonia, Latvia, and Lithuania) and Spain formed nine in total. It was launched that very summer of 2017. On the other hand, the center maintains a relationship with the EU and NATO in that it is open to the accession of members from both organizations. Currently all members of both NATO and the EU are part of the center.

What are the main tasks carried out at the center?

We are an expert organization with three tasks focused on supporting governments in the fight against hybrid threats. That is its nature: it was created because new security threats and challenges emerged, accompanied by new tactics.

“In 2014, the annexation of Crimea occurred without any war, foreign interference in elections began to be observed with greater frequency, and a phenomenon called instrumentalized migration emerged”

In 2014, Crimea was annexed by Russia without any armed conflict, and some new tools were used for that operation. Europe and also the United States began to observe increasing foreign interference in elections. A phenomenon called instrumentalized migration appeared, and all of these were new tools of power projection. In that context, these countries felt it was something that needed to be studied in more detail and that governments affected should be advised and supported to address this phenomenon. It was decided that the best way to counter these threats was to do so collectively, rather than each country creating its own center of excellence. Therefore, supporting governments to address hybrid threats means we carry out different types of specialized tasks, studies and analytical work, but we also offer training and exercises to governments or provide them with our platform to discuss and share best practices. That is basically the main task.

The second task assigned to the center is somewhat more specific, since both the EU and NATO, as well as other organizations, participate in our activities. Both have their own tools aimed at establishing hybrid countermeasures, so our role is to facilitate cooperation among the organizations involved. We have several work strands through which we try to bring them closer and discuss gaps or potential needs for greater cooperation. 

The third task is the one we are carrying out now: raising public awareness about hybrid threats. These threats do not stop at borders and are not solely a threat to governments; they also affect societies. The center was entrusted with the task of making this kind of threat visible. We engage with the media, organize events, seminars and debates. We involve academics in our work and try to bring these threats to light. 

As for the tasks we carry out now, the range of hybrid threats is very broad, and we try to do both conceptual work to help governments address the phenomenon and empirical work, in which we observe trends, patterns or cases of hybrid threats.

“We are analyzing the actors behind hybrid threats, namely Russia, China, Iran and North Korea: countries that declare themselves in defense of a hostile West”

We also try to increasingly examine best practices on how to counter, prevent, and protect ourselves. When there is good policy, law, or any other measure established in a country, we are very interested in sharing that good practice among the 36 governments. On the other hand, we are analyzing the actors behind hybrid threats, that is, Russia, China, Iran and North Korea—countries that openly state that they must use the full range of tools at their disposal in their supposed defense against a hostile West. Of course, they turn history on its head. They are very open about their approach of using every tool at their disposal. We analyze their thinking, their doctrines, their strategies. We compare them as actors in terms of tactics and means they employ. We also have a certainty now: we are paying more attention to some neighboring regions [the Caucasus], as well as Africa, because important things are happening there that are highly detrimental to us. We are analyzing both the hybrid commercial activities of China and Russia in African countries and how they could affect us.

There are many other topics that worry us as well. For instance, we are also turning our attention to the north and the Arctic region. The priorities and points of interest are set annually by the 36 countries, the EU, and NATO. The topics I mentioned are what concern them most right now, and we try to respond to that demand.

So you are describing questions that are identified by different member states, and from the center you offer analyses and prevention tools to address them, correct?

That’s right. They propose topics that matter to them, and we compile and coordinate the program so that it is coherent. We can start implementing each proposal, but a pre-organizational phase is necessary. We are expected to lead the debate, so from the center we also contribute our own proposals about what we see happening now and what we believe deserves more attention.

“We must show the way regarding new forms of threat: that’s why we are working on the use of emerging technologies and artificial intelligence”

We must not be too reactive, but at the same time it is necessary to show the way regarding new forms of threat. That is why we are also working on the use of emerging technologies, artificial intelligence, etc., and there seems to be a strong demand from countries for us to study them. The cyber domain is full of different areas of specialization, but that is how we operate.
 

Teija Tiilikainen warns that countries such as Russia, China, or North Korea oppose the West. Photo: Agenda Pública / Tania Sieira

And moving to a more conceptual framework, for the general public. Could you tell us what the current definition of hybrid threats is? How is this concept defined?

We define hybrid threats as the use of non-conventional tools—often a mix of several tools—that are employed in a concerted way to affect the target, so that the target country makes suboptimal decisions with respect to its own interests. In short, this means that non-traditional instruments are used, but also conventional tools, such as armed force or political and diplomatic apparatus, in different combinations to influence the target country’s policy decisions, especially in the area of foreign policy. There must be active intent, as well as a clear objective and goal. What differentiates this type of threat from others are these tools.

These are not only the traditional instruments of international politics, but also electoral interference, the widespread manipulation of the information space, and instrumentalized migration, attacks on critical infrastructures, economic coercion, etc. All of them are different and complex tools.

So there are three main blocks of issues you call critical. First, real critical infrastructures. Electoral interference would come second. And third, these threats to critical infrastructures. I’d like to go one by one, starting with attacks on these critical infrastructures. For example, Nord Stream. What happened there? There was a great deal of speculation about what occurred. Initially, it was said to be a Russian attack. Then, apparently, it was another kind of attack.

We operate at a strategic level. We are not an intelligence service or an operational entity. Therefore, we do not have the capacity to initiate investigations. All that is the prerogative of the authorities. What we do is monitor and analyze these things to find common patterns, but also to identify the tools to counter them or to improve resilience. Because our task is to help the Government counter them, not to do the work that their authorities do. Critical infrastructures are very difficult to protect because our societies, as we know, depend heavily on many kinds of these vital infrastructures. They can be financial systems, energy, technology… Not to mention the mutual interdependencies of these systems. 

So we have created a situation in which the whole society can be paralyzed quite easily. Basically, with a single entry point, if chosen wisely, the entire society can be paralyzed and physical damage can also be caused. We now know this, and there is a lot of information about the efforts or interests shown by hostile actors toward these critical infrastructures and their weak points.

“What our center tries to do is enrich the debate about what could be done, but a hallmark of these operations is that they are very hard to detect”

Therefore, what our center tries to do is improve this debate about what could be done.

You yourself mentioned that a feature of these operations is that they are very hard to detect.

Indeed, we cannot point to the perpetrators. We rarely can initiate suggested processes because there are no identifiable perpetrators. And this is part of these threats, because as part of these alarms the secondary effect is to increase the sense of insecurity and undermine public trust in its own government. If this kind of thing begins to happen, and I can assure you that last autumn in the Baltic Sea was one of those periods when cases multiplied, governments had to admit that we do not know who was responsible. There may be a state actor behind it, but we are not sure.

Acts of sabotage were also carried out with skill and, in most cases, outside the jurisdiction of the coastal state, so maritime law did not allow the coastal state to initiate an investigation or board the vessel.

We operate in the context of a global conflict and there are actors who publicly state that they need to weaken the West because the West has dominated the global stage for too long. This is the case with Russia as well as China, which articulate the need to use the full range of tools at their disposal to undermine the West”. Therefore, regardless of who is behind the various specific cases, we must think about the resilience of these vulnerabilities evident in the realm of critical infrastructures. And also, when it comes to financial systems, we must stress the importance of cyber tools. I will not describe what could happen, but a large-scale catastrophe could easily occur.

Ruth Ferrero delved into the center’s specific tasks. Photo: Agenda Pública / Tania Sieira

How are possible attacks on electoral systems being addressed? And, how do you advise governments to act against these interferences?

There are different approaches. Our main product regarding anti-interference in elections is training. It is a course we deliver to governments interested in it. We call it the prevention of electoral interference, and it is offered to countries as elections approach. It is periodic training, so our experts plan it together with national experts. We want to tailor the training to the geopolitical and national situation and try to anticipate the forms of interference that could occur in that particular country. We base it on incidents of interference we have recorded in previous elections. We also use them as training material. 

We have a specific manual in which we have prepared recommendations for governments on aspects to consider, two years before elections, and six months before elections. Because there are two different things in this regard: technical procedures during the electoral process, where technological tools play a role; and campaigns, candidates and all the discourse that takes place within social networks. In the second case there is also a strong influence from technologies.

“From the center we develop a manual to help decision-makers plan their own policies and the protection of the election process”

The manual’s objective is to help decision-makers plan their own policies and protect the electoral process. When we plan that exercise together with the country’s government, we encourage them to bring to the center, during training, the various authorities responsible. In some cases we are told that this is the first time a group of this kind has met. So we could also facilitate some national cooperation within the countries.

During the early years we managed to promote greater regulation of social networks, as has been done now at the EU level. We promoted legislation specifically on identifying suspicious funding. Therefore, our activities can take very different levels, from macro proposals regarding the regulatory framework, for example, to more case-by-case advisory or recommendations to governments. We have also published publicly accessible works, mainly on policies, not on specific cases, because there is also NATO’s Center of Excellence. I think the Stratcom Center in Riga has published a report on cases because they checked them, but we do not necessarily have access to highly detailed information.

So we rely on secondary sources and open-source material in this regard. Unfortunately, there are a large number of proven cases of foreign interference in elections: Moldova or Romania and previously France, Germany, or the 2016 United States elections.

The US elections were the beginning and then Brexit followed, right?

Correct, more or less that is the origin of all this: the alarm began then. It was at that moment that the discourse started. But, as we know, it is very, very difficult to identify because in many cases these narratives are built on fertile ground that is exploited to deepen and expand a particular political position or discourse. So it is not so much that they are creating new situations, but that they are taking advantage of divisions or the national history. Then, of course, they amplify and direct it.

“The Moldovan elections were unique in terms of the tools used for interference, and although Moldova is not a member state of the center, we used its experience for our work”

For example, the Moldovan elections were unique in terms of the tools used. This case, although Moldova is not a member state of our center and not part of NATO, we have used its experience extensively in our work. In fact, we organize an annual workshop on the topic with representatives from most of the countries and visitors. And everyone contributes to the table with some findings from their own country, concerns or cases that occurred, tools used. Then we use that as a large information aggregator.

To select best practices…

We collect the best practices and discuss among national experts whether there are things we could do together, whether there are things the center could do better or more often, whether there are new vulnerabilities, etc. Of course, this is quite delicate, if someone has detected new vulnerabilities in systems or new tools I mean.

Providing a platform for countries to meet is an important form of activity appropriate for us. Governments bring experience and we provide the platform. We organize an event, encourage them to send a national expert responsible for national election security or something similar, and then we craft a two-day program.

Tiilikainen and Ferrero align on the importance of electoral interference. Photo: Agenda Pública / Tania Sieira

Thinking of Romania, what happened when the attack occurred and the Government asked for advice? The whole process was very fast and the elections were canceled. Later, the Venice Commission said that this was not constitutional.

When something serious happens, we are not the first actors to intervene. We also try to avoid getting too involved in internal affairs. Our vocation is to advise in advance, support them, create policies, tools and means. Consequently, often we do not have the capacity to, when something happens, give them immediate guidance. It is not within your mandate or ours to act that way. It would be extremely difficult because we do not have access to the internal information we would need to respond. In the case of Romania, regarding whether there should be new elections or not, our role is limited. That would overburden us given the resources and goals we have.

Then, as you just mentioned, the center always works with open sources.

Yes. We do not have access to classified information. At the beginning you asked about our experts: we have 55 people working at the center, a little over half of them are experts hired directly from the academic world, think tanks and also from the public administration. Then, around 20 are experts loaned by governments, again mostly coming from the administration. But some countries have also hired experts from the academic world, one from a central bank, a journalist, depending on our thematic needs and priorities. The country that decided to loan an expert or hire a central-bank expert is concerned about vulnerabilities in financial systems. By sending an expert in that field, they wanted to support our work on that issue. That is, roughly, how it works.

The last block is dedicated to what is probably the most diffuse issue, which is information. At this point, how is your institution addressing this enormous threat to democratic societies? How do you identify when a disinformation campaign is underway?

First, I want to underscore the importance of information. I personally call it the manipulation of the information space, because I think that helps to better understand the problem’s comprehensive nature. So these information campaigns are aimed at a particular audience, but the broader manipulation of the information space relies on the strategic narratives of countries that seek to revise the current international order. These strategic narratives are used to tell a very different story about their own role in international politics and their goals in foreign policy. 

I think this is what lies behind targeted disinformation campaigns. These campaigns are largely based on their strategic narratives, on what they want to achieve with their policies. When acting at a strategic level, when an operation is underway, we do not interfere or get involved. But we want to make the threat visible. And that means acting at a macro level, for example, showing what these narratives mean.

“In the ongoing war against Ukraine, manipulation of the information space, which is everywhere, is a very important element for Russia because it helps it continue the invasion”

Because, for example, in the ongoing war against Ukraine, this manipulation of the information space everywhere is a crucial element that allows Russia to continue the war, as they gain support from their own population. But not only that, they also gain support from many other countries, thanks to their skillful strategic narratives, which frame the core cause of the war as Western hostility and Ukrainian regime atrocities. We operate at that level and analyze these strategic narratives so that our public and ordinary citizens can see the connection between specific campaigns underway in their countries and broader approaches.

We have published a substantial amount of material on specific disinformation campaigns, but also on ways to counter them. We have published works on Ukraine and how that country has managed to counter Russian operations during the war. This is a joint effort between one of our experts and a Ukrainian expert. It is not an openly published piece, but the results of the annual workshops I mentioned, where we collected best practices, what helped, and what succeeded at the national level. 

In this debate on how to counter, we have cooperated and continue to cooperate with social media platforms. We try to urge them to fulfill their responsibility to monitor and track what is happening. On the other hand, we are discussing with experts in education, and this is where media literacy comes into play. I am increasingly concerned about the future, because we know that, when we look at the figures, the younger generation gets its information from online sources rather than from quality journalism. The entire information space is undergoing a deep transformation. The debate about post-truth or post-reality is always present.

The creation of false narratives and historical distortions can also take the form of hybrid threats, according to Teija Tiilikainen. Photo: Agenda Pública / Tania Sieira

Post-truth is one of the most precise labels for all this. How to address this situation? You mentioned that it is based on different kinds of regulation to prevent these campaigns or even moderate social networks, but the more critical positions argue that there could be a clash between freedom of expression and regulation. Regulation could be interpreted as censorship, because ultimately who decides what is true and what is not? For me, this is one of the main difficulties in addressing this. How do you see it?

I think that, since this is the adversaries’ tactic, they try to push us to compromise on our values to be accused of hypocrisy. This is part of the impact in many cases. Finland had to close its entire eastern border with Russia when it continued instrumentalized migration operations. A new law was subsequently enacted that, according to many experts, contradicted human rights conventions and EU human rights legislation. The aim is to find those vulnerabilities so that our governments face great difficulty in finding a balanced solution. Because this is about balancing freedom of expression with national security. If someone wants to influence public opinion or lead political campaigns before elections, what are the limits? If we want to hold firmly to our freedom of expression and also want to maintain a positive view of social platforms as a space for democratic debate, what can we do?

I wanted to ask your view on what are the main hybrid threats EU member states currently face and which actors you have identified as responsible for those threats. You mentioned Russia, China, and Iran. But what is the situation now with Trump in the White House?

Well, there are also dividing lines within the EU and NATO. Among democratic countries there are differences of opinion, but the threat to democracies and the democratic principle is very real. This is the objective because it is the main threat to authoritarian regimes. The more democracy advances on the ground and comes closer to their borders, the more fragile or questioned are authoritarian systems. 

As for the role of U.S. leadership globally and Europe as a partner, I think it is key and it has not changed. 

“The comprehensive manipulation of the information space is the most important threat we face because it also has long-term consequences”

I would say, based on what we have just discussed, that the comprehensive manipulation of the information space is the number one threat because it also has long-term consequences. Think of Africa, and what is happening there with the entry of other actors. In addition, China is actively using the war against Ukraine to promote its own role as a responsible, Western actor, to blame the West for its practices and repeating, more or less, the Russian narrative about the origins of the war. We are not there. We are not in a position to correct the message.

Because we are not coherent.

We are not coherent and we are different. The EU is a different kind of actor from the rest because it does not have a strong strategic narrative to promote, unlike these countries. And the EU is a union of democracies.

No, it is not a country.

No. By nature, we are in a somewhat tougher position to respond to that threat. I think this is very worrying because, in the long term, but also in the short term, we will see the consequences. European countries are divided; they hold quite different opinions on the origins of the war against Ukraine. So there are countries where more than half the population supports the Russian narrative about Western hostility and planned hostilities and security threats to Russia. Or that Finland and Sweden join NATO because the United States demanded and exerted pressure on them. We see concretely in our countries that in Finland, support for NATO was around 20% until the aggression began.

Now there are NATO military deployments on our eastern border [Finland’s], which is why the border is closed, though also due to the Russian operation. 

Thank you very much.

Natalie Foster

I’m a political writer focused on making complex issues clear, accessible, and worth engaging with. From local dynamics to national debates, I aim to connect facts with context so readers can form their own informed views. I believe strong journalism should challenge, question, and open space for thoughtful discussion rather than amplify noise.