Security1 distinct publisher2 min readPublished
At Munich, EU and NATO officials asked for the power to strike back at Russia and China. The newsletter Seriously Risky Business points out that the sanctions and expulsions Europe already holds have gone unused, so defenders should plan on the current tempo holding.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Cyber operations appeal to a cabinet because they are deniable. Tom Uren's objection, in the Seriously Risky Business newsletter, is that deniability disqualifies them from the job the Munich speakers described: an operation Moscow can absorb without acknowledging changes no Russian decision, so anything that would actually stop the sabotage has to hurt, which means big and noisy [8]. NATO members with far more mature offensive programmes have not run cyber sabotage campaigns inside Russia, which is why Uren reads the missing ingredient as will rather than tooling [9].
The cheaper instruments are already in hand. Uren names three lines of non-cyber pressure Europe has chosen not to apply: more sanctions, going after the shadow fleet that moves oil around the existing ones, and closing Russian consulates while expelling diplomats [10]. Three named, none used [15]. Each carries lower escalation risk and less legal ambiguity than a destructive network operation, and each has an obvious owner inside a foreign ministry. His inference follows from that: capitals that decline the expulsion will hesitate at the destructive operation too, whenever the capability finally lands [13].
The activity underneath the rhetoric is not primarily a network problem. GRU handlers are using the Wagner Group to recruit disposable locals, per Financial Times reporting cited in the newsletter [5], and the resulting incidents have been irritating rather than lethal or economically serious [11]. Prosecutions land on the recruits and have not touched the campaign's tempo [12]. What has moved is ambition: fifteen defendants charged over parcel bombs sent through Lithuanian delivery firms [6], with reporting that the next phase targeted cargo aircraft bound for the United States and Canada [7]. The charges are on the record; the cargo-plane stage is reporting rather than an indictment [7].
Shekerinska named China alongside Russia [2], but the whole cost menu on the table concerns Russia, and the call itself is being driven by Russian aggression in Europe [18]. No one at Munich, including the intelligence chiefs who echoed Virkkunen [16], described an instrument aimed at Chinese operations. For defenders the planning assumption does not move this quarter. Poland's grid was targeted late last year [3], the proxy sabotage continues [4], and the deterrent being requested needs both a procurement cycle and a political decision that has already failed a much easier test. Uren does support building sovereign European capability, partly because the alliance looks less reliable than it did [14]. That is an argument about the next five years, not a change to the threat model for grid operators and delivery networks being probed now.
Ranked by verification strength, evidence, and original report placement.
Speaking on the sidelines of the Munich Security Conference last week, the European Commission's Executive Vice President for Tech Sovereignty, Security and Democracy, Henna Virkkunen, told Politico that "it's not enough that we are just defending ... We also have to have offensive capacity".
At the same conference, NATO Deputy Secretary General Radmila Shekerinska said the alliance's collective objective should be "to take action and to be able to strike back" against cyber threats, and called out Russia and China as significant threats.
Other European officials at the conference, including intelligence chiefs, expressed similar sentiments about the need for offensive capacity.
The call for offensive capability is primarily being driven by Russian aggression against Europe.
Late last year Russia targeted Poland's electricity grid with a cyber operation.
Russia is currently running a real-world sabotage campaign across Europe, and while there is a cyber element, much of it relies on recruiting local proxies.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 26, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Washington names industrial-scale distillation, then hands the detection bill to abuse teams1 distinct publisher
build
Europe's arms plants are burning, and the arsonists are being hired locally1 distinct publisher
security
Anthropic says AI ran the intrusion, not the briefing: thirty targets, one operator1 distinct publisher
security
China got the handcuffs on Chen Zhi. Expect the fraud to change address, not stop1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named quotes, borrowed reporting, an unverifiable negative
The checkable parts hold up: two officials quoted by name and title, a Lithuanian prosecution with a defendant count and a stated allegation, a cyber operation against Poland's grid. But almost none of it is first-hand — Politico took the Virkkunen interview, the Financial Times broke the GRU-Wagner recruitment — and the sentence the argument turns on, that more capable NATO members have launched no cyber sabotage campaigns in Russia, is a claim about the absence of covert activity. That is unprovable by construction, and it carries the weight.
Nothing here to count
We can't score this one. Every operational fact in the story belongs to the adversary — one intrusion into Poland's grid, 15 people charged in Lithuania, proxies recruited over Telegram. On the European side there is no unit, no authority, no budget line and no operation, only two people saying capability is needed. Inferring a level of European offensive cyber activity from that silence would be inventing the number.
The ask outruns the record
The overstatement sits with the officials, not with the reporting. "Offensive capacity" and "strike back" were said in Munich with nothing attached: no doctrine, no cost, no timeline, no named capability — while three concrete measures Europe already controls go unused. Tom Uren is the corrective rather than the amplifier, which keeps this well short of the top of the scale; his own forecast that Europe will stay trigger shy is argued by analogy and marked as a hunch.
A disclosed sponsor, and officials asking for a mandate
runZero's sponsorship is disclosed in the first line and buys placement, not the argument — nothing in the column moves a product. The livelier interest belongs to the people being quoted: a Commission executive vice president whose portfolio is tech sovereignty and a NATO deputy secretary general, both making the case for a new mission at the conference where mandates get contested. Uren's incentive pushes the other way; puncturing an official ask is this newsletter's stock in trade, and that cuts both directions.
Solid facts, one person's verdict
Split the story and confidence splits with it. The reported facts would survive a check; the conclusion is a single analyst's, hedged in the text as "we wonder", with no European government given a chance to answer and no member state asked whether it already holds the tools. One publisher, two borrowed scoops, and a central inference about covert operations that nobody can corroborate — that ceiling is as high as this goes.