France plans to protect critical infrastructure under threat of Russian cyber and drone attacks, as the EU learns to improve information sharing networks.
In the US, most headlines related to war have centered on the US-Israel war on Iran, a conflict that started almost seven months ago with sweeping attacks on the Persian nation. In the war on Iran, the US’s initial attacks were cyber-enabled, with US CYBERCOM and SPACECOM working alongside Israeli forces to “disrupt and confuse the enemy.” This was answered with a surge in activity from Iran-linked hackers, who hacked public cameras in Israel, the old personal email of FBI Director Kash Patel, and Medical tech company, Stryker. More recently, the US has even issued a series of sanctions (Operation Economic Outcast) to curb Iran’s digital assets and technology exports. Across the pond, the US-Iran war has also featured in news publications, but in competition with another, older war story - the war between Russia and Ukraine. While Russia’s war in Ukraine started in 2022 (and has been brewing since 2014), it has something in common with the more recent war in Iran: cyber-enabled warfare.
Cyber-enabled warfare in the Russo-Ukraine war attracted global attention in mid-2025 with Ukraine’s Operation Spider Web. There, 117 remotely controlled drones, hidden around Russian air bases, were used to deliver extensive strikes on Russian aircraft. These damages allegedly totalled $7 billion in irreparable losses, not including the value of the strategic information stolen from Russia’s warplane maker in Ukraine’s hack. Russia has also used their cyber capabilities to hurt Ukraine, reaching organizations in government, finance, and even charity and aid. Russia’s hacks stretch further than Ukraine, however. In 2022, Microsoft reported that Russian-linked hackers targeted governments, think tanks, businesses and aid organizations in 42 countries that support Ukraine, as part of a cyber espionage campaign. These efforts came alongside disinformation and propaganda operations powered by artificial intelligence (AI) - not unlike the attacks on the 2024 Paris Olympics - to deflect from Russian war crimes.
Now, one European country is taking action to protect against cyberattacks and drone attacks from Russia. On September 18th, 2026, French leaders met to discuss the threat of Russian attacks. French President Emmanuel Macron explained the context for the meeting when talking to reporters: “In recent weeks, the threat - particularly the Russian hybrid threat - facing Europeans and France has intensified… The intent is to intimidate us and break our effort to support Ukraine. The result will be the exact opposite. We are not intimidated because we know that our security today and tomorrow is at stake in Ukraine.”
Franceinfo reported on the meeting, and noted that several key infrastructure sectors - power plants and electrical grids, rail systems, telecommunications, and water systems - were discussed as potential strategic sites of attack. General of the French Air Force and a former fighter pilot, General Patric Dutartre commented on how prepared he felt to face the challenge, in French: “You should know that French airfields, the main ones of course, are prepared against drone attacks or intrusions. But we can imagine that all the sensitive sites associated with the defense could be targeted”.
France has been monitoring the cyberattacks wrought by Russian hackers for a while, with their Ministry for Europe and Foreign Affairs releasing a statement in July calling out and condemning a series of cyber attacks on the country in a cyber espionage effort. There, the ministry promised action against these malicious cyber activities: “Alongside its partners and within the framework of international law, France is determined to use all available means to anticipate, discourage and respond to destabilizing activities targeting it in cyberspace, including in the lead-up to the upcoming 2027 elections.” The September 18th meeting builds on this declaration, with President Macron asking his government “to prepare a plan to protect our critical infrastructure”.
The rest of the European Union (EU), which has also been targeted by offensive Russian cyber operations, has been focusing on their cybersecurity defenses in a more general capacity than France. The EU’s Court of Auditors published a report on ‘Detecting and responding to cybersecurity incidents’, to understand how the EU cybersecurity landscape is positioned to address cyberattacks. They discovered that “EU actions only partially facilitate the detection of and response to significant and large-scale cybersecurity incidents…Limited information sharing, reporting weaknesses and considerable implementation delays prevent EU networks from reaching their full potential.”
The report makes five recommendations: fortify intelligence sharing between EU states, strengthen systems for situational awareness and perfect information sharing, incorporate the European Cybersecurity Alert System across the EU security networks, support financial beneficiaries in the Digital Europe Programme with adequate funding, and build out the Digital Europe Programme’s cybersecurity performance monitoring framework.
Limited information sharing was a critical point emphasized in the report. One member of the Court of Auditors, Marius Hyzler commented on the report: “The EU has made progress in creating a cybersecurity cooperation framework but it is not yet working with due effectiveness. When a serious cyber incident occurs, timely and usable information is essential: without them, networks and mechanisms lose much of their added value.” While it may be a while before the EU is able to take in all the recommendations in the report, they are already rolling out the cyber incident reporting rules for manufacturers of digital products, as prescribed in the Cyber Resilience Act. With luck, this will help kickstart a stronger framework for information sharing across the EU.