The lesson from Germany: under-reacting to hybrid threats is dangerous

Berlin’s hurried shift to actively defending against hybrid threats shows the danger of cumulative under-reaction to hostile state-backed activity. Underreaction can leave democracies more vulnerable to sustained coercion, interference and sabotage, ultimately making them preferred targets.
This is a warning for Indo-Pacific countries, which confront similar hostile activities but lack agreed frameworks, common terminology and shared threat assessments. Germany’s experience shows the need for stronger national resilience, clearer attribution thresholds, wider response options and expected action from partners.
The challenge is to build credible deterrence and regional mechanisms before hostile activity becomes normalised.
In August, three drones carrying explosives were found at Halle airport in Leipzig, a major hub for military supplies to Ukraine. A month later, the German government concluded that Russia was responsible, assessing that the operation bore the hallmarks of Moscow’s hybrid playbook seen in Ukraine and elsewhere in Europe.
What followed was the familiar European script: Berlin summoned the Russian ambassador, closed Russia’s consulate-general in Bonn and terminated the lease of the Russian cultural centre in Berlin. Germany also said it would seek additional EU sanctions, including tighter travel controls for Russian nationals and stronger action against the shadow fleet.
However, public attribution itself was a departure from Germany’s earlier caution. Attribution such as this is more effective while hostile activity remains relatively low. Waiting until attacks become severe can leave governments appearing reactive and allow the aggressor to control the pace of confrontation.
For years, Berlin hesitated to treat individual acts of Russian hostility as parts of a coordinated campaign. This was partly because of concerns about escalation and Germany’s historical, Germany is now trying to close that gap.
Berlin should also define the label ‘hybrid threats’ to expound the seriousness of activities it confronted: coordinated acts of multi-domain interference, sabotage, information manipulation and coercion below the threshold of outright conflict. Moscow’s operations are persistent and increasingly kinetic, making the distinction between hybrid threats and open conflict harder to sustain.
The Indo-Pacific faces similar threats and lacks Europe’s cohesive security architecture. The EU and NATO provide established mechanisms for information-sharing, political coordination, collective signalling and coordinated assistance. Nothing comparable exists across the Indo-Pacific. Regional countries instead have widely different threat perceptions, institutional capacities and relationships with major powers. Many remain reluctant even to use the term ‘hybrid threats’, fearing it could imply geopolitical alignment.
Germany’s experience shows that resilience and deterrence begin at home. Attribution alone doesn’t create deterrence.
The first priority is ensuring that intelligence and counter-espionage laws remain fit for purpose. Germany has begun amending laws to allow agencies to take protective measures against hybrid threats. It has also established the Joint Centre for Countering Hybrid Threats, bringing together federal and state intelligence, security and law-enforcement authorities for joint analysis and coordinated responses.
The second priority is expanding the countermeasures available to governments and signalling credible defence capabilities. Military signalling can help deter hybrid threats by showing that a country has escalation options. NATO’s air activity in the Baltic region, including an unannounced exercise around the Russian enclave of Kaliningrad in August, shows how such signalling can demonstrate capability and collective resolve.
Diplomatic and economic measures remain important, but they produce diminishing returns when repeatedly relied upon. EU sanctions have imposed costs on Moscow but seem not to have changed its behaviour.
Germany’s experience has a direct lesson for Australia. Australia has the intelligence, law-enforcement, diplomatic and defence capabilities to identify attackers and their tactics. The challenge is to connect these capabilities into a coherent response framework and support regional partners develop complementary mechanisms.
Publicly identifying attackers is the first step in signalling that coercive behaviour will not go unnoticed or unanswered. The annual threat assessment from the Australian Security Intelligence Organisation contributes to this.
Democracies need credible options in-between inaction and military escalation. These could include exposing proxy networks, pursuing criminal prosecutions and coordinating sector-specific responses in areas such as cyber, infrastructure security and economic coercion. Responses need not mirror the initial attack, but they should raise the cost of continued hostile activity while remaining lawful and proportionate.
The Indo-Pacific will not replicate NATO or the European Union. Its security architecture is too diverse and its political relationships too complex. But regional states can still cooperate on specific problems, and Australia can help mature the mechanisms to make that cooperation possible.
The objective is to make clear that hostile activity will be detected, attributed and met with a proportionate response. Germany’s experience shows the danger of waiting until a pattern is undeniable before acting. For Australia and its partners, the time to build credible deterrence against hybrid threats is before the next campaign begins, not after it has become entrenched.
