Part I — Situation overview
Alexander Dobrindt, the German interior minister, put it in an interview given to a German paper on Sunday 9 August that Germany faces hybrid warfare attacks “on a daily basis”. Espionage, sabotage, cyberattacks and covert operations whose purpose is to destabilise the country or to cause direct damage are, in his words, a “permanent reality”. The minister did not name which foreign powers stand behind the attacks; a spokesperson for the German foreign ministry had mentioned Russia a few days earlier as the source of the daily influence attempts. The Moscow side rejected the whole matter, and the Russian embassy in Berlin called the Leipzig case an “invented provocation”.
The statement was a response to two concrete events. In the first week of August a drone loaded with explosives was found at Leipzig-Halle airport, according to German information within metres of a Ukrainian transport aircraft. The airport is a strategic hub: a point of departure for NATO consignments — among them military consignments bound for Ukraine — the largest European air base of an international courier service, and the temporary home of several Ukrainian freight aircraft relocated here away from the Russian attacks. After this, on Thursday evening two drones were detected over the Bundeswehr facility at Mechernich near Bonn; according to German press reports the base stores components used for the maintenance of Patriot type air defence systems. Military police were the first to attend the scene, after which the local police took the case over. According to press reports the German government would double the federal drone defence expert staff — from 150 to 300 people — and raise the number of related bases from four to eight.
The regional picture strengthens this pattern: in recent weeks similar cases, individually explicable but taken together systemic, occurred alike in the Baltic region, in the Western Balkans and along the Romanian–Bulgarian border section. The series of drone detections has kept European airspace surveillance on alert since last year, and it was this that put the idea of an EU-level “drone wall” on the agenda.
MIAK’s reading is that the news is not the latest incident but the classification. When the government of a member state speaks not of an individual case but of a daily, permanent phenomenon, it thereby also changes the legal and organisational category of handling it. An incident is handled by the police in an investigative procedure; a permanent threat state, by contrast, has to be handled with a budget, with competences designated in advance and with a regular reporting regime. In Hungary this switch has not yet happened, and the most important missing element is not technology but clarity about competences. Drone detection and drone defence lie today at the intersection of the law enforcement and the defence remit: the protection of military objects is a defence task, whereas the protection of civilian critical infrastructure — airport, power plant, railway hub, waterworks — is a law enforcement one, that is, the competence of the police. The two categories are not interchangeable, and the German case showed precisely how often a single event runs across from one to the other: the military police began it, the local police continued it. This is the character of the problem — not the absence of a defence capability, but the lack of clarity about who is the primary responder at a given facility, and who may give the order to intervene.
Part II — Literature foundation
Two classics give a frame for interpreting sub-threshold violence. Carl von Clausewitz (Prussian military officer and writer on the theory of war, the founder of modern strategic theory) develops in On War the thesis that war does not interrupt political intercourse but is its continuation by other means — for him armed action is a particular language of political thought, with a grammar of its own but not a logic of its own. It follows that an event insignificant in military terms may also be a politically weighty communication, if the sender’s intent is the signal. The work The Art of War by Sun Tzu (ancient Chinese commander, author of the first known strategic treatise) describes the same phenomenon from the side of reconnaissance: the purpose of probing disturbance is not to cause damage but to make the opposing party’s own defence system readable from its response. And the NIS2 Directive of the European Union gives that legal framework, in force and binding on Hungary as well, which prescribes for the operators of critical sectors a concrete incident reporting obligation measured in hours — that is, the institutional half of the answer does not have to be invented, only domestic practice has to be aligned with it. The detailed treatment of the literature — author by author, with quotations — can be found in the 6.4 Literature in detail section.
📖 Source: Carl von Clausewitz: On War; Sun Tzu: The Art of War; Directive (EU) 2022/2555 of the European Parliament and of the Council (the NIS2 Directive)
Part III — MIAK’s concrete proposal
MIAK proposes three measurable measures. None of them requires the setting up of a new institution, and all three build on existing EU obligations.
3.1 Fixing a drone defence responsibility matrix in legislation (adoption by 31 March 2027)
The most urgent gap is not the defensive device but the order of responsibility. MIAK proposes that a matrix by type of facility be prepared at the level of legislation — not in an internal procedural order — answering four questions: who is the primary detector, who is the primary responder, who may give the order to neutralise, and at what threshold the case has to be handed over to the other body. The matrix should separate military objects, where organisations subordinated to the defence ministry act; civilian critical infrastructure, where the police is responsible; and those mixed situations — for example a civilian airport also handling NATO traffic — where the exact moment of handover has to be fixed. The level of legislation matters because neutralisation is a coercive measure directed at an aircraft, and the legal basis for that cannot be an internal instruction. This is the point of connection between HV12 geostrategic defence planning and the KB1 criminal data platform; from the side of decision modelling it is what gives real content to HV13 multi-model crisis management, since the same sequence of events has to be thought through as a criminal matter, as a military threat and as a political signal alike.
3.2 An annual, public hybrid threat report (first edition in the first quarter of 2027)
One lesson of the German case is that public classification is itself an instrument: by a government stating how many cases have occurred, the next one also becomes more expensive for the attacker. MIAK proposes that a public, aggregated report be prepared every year on domestic hybrid-type incidents: the number of cases by type (airspace, cyber, sabotage, influence), the sectors affected, the average time between detection and reporting, and the state of attribution — without any operational detail or data from an ongoing investigation getting into it. An aggregated, statistical communication does not harm operational security, but it makes it possible for the policy debate to be conducted on data and not on assumptions. This is the putting into practice of the HV11 strategic communication programme point, and from the side of data infrastructure it is one output of the D5 cybersecurity strategy. In connection with the report it also has to be fixed what the Hungarian state says before attribution — because in Clausewitz’s reading (see 6.4.1) silence and guesswork alike strengthen the sender’s message.
3.3 Initiating a regional incident sharing channel (launch in autumn 2026)
The sequence of events is regional, yet the response is national. The Lithuanian, Croatian, Bulgarian, Romanian and German cases are separate national investigative matters, but taken together they give a pattern — which today nobody sees as a whole quickly enough. MIAK proposes that Hungary initiate a simple, technical-level incident sharing channel between the Visegrád Four, Romania and Bulgaria: a fixed data sheet, a set deadline, a list of contact persons, and a joint analysis every six months. The proposal is deliberately modest — it asks not for a new agency but for data exchange between existing national bodies. This is the direct application of KP10 regional resilience building, and on the technical side the natural extension of HV1 cyber defence capacity development to low-altitude airspace monitoring. The diplomatic cost of the channel is low, but its yield appears at once: a case detected in Hungary will immediately be comparable with what happened in the region a week earlier.
The three proposals are bound together by a single principle: a lasting threat cannot be handled with ad hoc instruments. The matrix says who acts; the report shows what happened; and the regional channel shows that what we see here as an individual case is already a series elsewhere. All three do the same thing: they bring the weighing of options forward, ahead of the incident.
Part IV — Expected effects and risks
| Dimension | Expected effect | Risk |
|---|---|---|
| Defence | The matrix of competences reduces response time and removes the possibility of shifting responsibility | A rigid classification may force a bad decision in an atypical situation; a documented possibility of departing from it is needed |
| Law enforcement | The task of protecting civilian critical infrastructure becomes explicit and plannable | The new task falling to the police may remain without resources if the matrix is not accompanied by a capacity estimate |
| Rule of law | Raising the power to neutralise to the level of statute gives a predictable legal basis for the coercive measure | A broadly worded authorisation to neutralise carries a fundamental rights risk; a narrow, itemised formulation is needed |
| International relations | Regional data exchange strengthens Hungary’s position on the Central European security agenda | If data sharing turns into a political attribution dispute, the credibility of the technical channel suffers |
The most sensitive point of judgement is the relationship between publicity and operational security. An annual threat report is useful if it is concrete enough for the policy debate to rest on data, but not so concrete that the attacker can read out of it where the domestic detection blind spots are. This line cannot be drawn in general terms; in practice an aggregated breakdown by type and by sector is safe, whereas one by site and by point in time is not. The second sensitive point is the power to neutralise. The forcible defeat of a flying device is a serious intervention even if the device is small and unmanned — the legislation therefore has to define precisely the threshold, the considerations to be weighed and the obligation of after-the-fact documentation. The aim is not a broader authorisation but an unambiguous one: today it is uncertainty that makes the worst outcomes — delay, or action without a legal basis — possible at one and the same time.
Part V — Measurability and summary
5.1 What is worth tracking? (proposed KPIs)
Four proposed performance indicators (KPIs, Key Performance Indicators) from which, in a year or two, it will be visible whether preparedness has improved:
- Whether the responsibility matrix by type of facility was prepared by 31 March 2027, promulgated at the level of legislation. A binary, document-based indicator.
- The average time in hours between detection and official reporting, by type of incident. This has an EU point of reference: NIS2 prescribes 24 hours for the first report on significant incidents.
- The number of incidents featuring in the public annual threat report by type. An indicator starting from zero; a rise may mean not necessarily a worse situation but also better detection — which is why the figure for detection capacity is needed alongside it.
- The number of cases shared via the regional incident sharing channel every six months, together with the share of those cases in which sharing took place within 72 hours.
5.2 Summary
MIAK’s message: hybrid threat exists in Hungary today as an investigative matter, while it is already a permanent state. Concretely, it asks the government that the drone defence responsibility matrix by type of facility be prepared at the level of legislation, in a joint submission by the defence and the interior ministries, that the annual, public hybrid threat report be launched, and that Hungary initiate the regional incident sharing channel. Of the public it asks that instead of the news value of individual cases it demand these three documents — because the next drone detection says nothing in itself about whether we have become better prepared.
Two MIAK foundational values move in this matter. Accountability, because in an unclear situation of competences it is always possible, after the events, to explain why the given body was not the one with jurisdiction — the matrix closes off precisely this escape route, and that is a protection for the government as well, not only an obligation. And openness, because the annual threat report is the cheapest instrument of deterrence: from the attacker’s point of view the most valuable outcome is invisible success, and aggregated data made public takes that away. Where society knows what is happening, half of an operation aimed at destabilisation already does not work.
Part VI — Justifications and further sources
6.1 The press framing by spectrum
On this topic the framing of the international press separated not along a left–right axis but along an axis of genre. The Brussels policy band — Politico Europe — handled the ministerial statement as a political event and highlighted the domestic political connection: the piece put the September east German state elections and the electoral aspect of the influence attempts at the focus of the story, that is, it read the hybrid operation primarily as a question of German domestic political stability.
The global news agency band, by contrast, stayed with the facts. Al Jazeera’s report quoted the ministerial formulation precisely, carried the Russian embassy’s denial, and — this was the most concrete policy yield of the day’s selection — brought the figures of the planned doubling of drone defence capacity. The same piece drew attention to the fact that in one regional incident the defence ministry of the country concerned did not itself assume intent — that is, individual elements of the series are each disputable. The BBC’s report concentrated on the details of the Mechernich detection: on the function of the base, on the alternating roles of the military police and the local police, and on the wider connection that it was last year’s European wave of drone detections that put EU-level air defence cooperation on the agenda.
The Central European analytical band — background materials of regional analytical workshops — treated the phenomenon not as an incident but as a question of societal resilience, emphasising that the first line against acts of sabotage is the citizen himself. The most striking difference between the bands is therefore the level of analysis: the policy band saw the elections in the story, the news band the case, the regional band societal preparedness. The question of competences — who has jurisdiction when a drone is detected — came up in none of the bands, even though it is precisely this that can be read most clearly out of the factual material of the German reports.
6.2 Facts and data
| Item | Value | Source |
|---|---|---|
| Time and place of the ministerial statement | 9 August 2026, Sunday interview in a German paper | Politico Europe, 9 August 2026; Al Jazeera, 9 August 2026 |
| The office holder making the statement | Alexander Dobrindt, German interior minister | Politico Europe, 9 August 2026 |
| The content of the classification | hybrid warfare attacks “on a daily basis”; espionage, sabotage, cyberattack, covert operations as a “permanent reality” | Al Jazeera, 9 August 2026 |
| The Leipzig case | a drone loaded with explosives at Leipzig-Halle airport, within metres of a Ukrainian transport aircraft | Politico Europe, 9 August 2026 |
| The function of Leipzig airport | NATO transport hub, European air base of a large international courier service, temporary base of Ukrainian freight aircraft | Politico Europe, 9 August 2026 |
| The Mechernich case | two drones over a Bundeswehr facility, evening of 6 August 2026 | BBC, 9 August 2026 |
| The function of the Mechernich base | storage of maintenance components for Patriot air defence systems (German press report) | BBC, 9 August 2026 |
| The order of the bodies acting | military police, then the local police | BBC, 9 August 2026 |
| The planned German drone defence staff | from 150 to 300 people; the number of related bases from 4 to 8 | Al Jazeera, 9 August 2026 (following Bild) |
| The position of the Russian side | the Leipzig case is an “invented provocation” | Al Jazeera, 9 August 2026 |
| NIS2 first reporting deadline | 24 hours from becoming aware of the significant incident | NIS2 Directive, Article 23(4)(a) |
| NIS2 incident notification and final report deadline | 72 hours, and at the latest one month respectively | NIS2 Directive, Article 23 and recital (102) |
Two pairs of figures deserve separate attention. The first is the doubling of the expert staff and the doubling of the number of bases: the proportion indicates that the German response is not about defensive weaponry but about presence and coverage — that is, there too the bottleneck is regarded as detection rather than defence. This is instructive for Hungarian planning as well: HV1 cyber defence capacity development has to extend to the sensor side of low-altitude airspace monitoring too, not only to network protection. The second is the relationship between the NIS2 24-hour reporting deadline and domestic practice: the directive has long been in force, but there is no public Hungarian summary of reporting discipline. This is one of the most easily produced lines of the report proposed in point 3.2 — the data comes into being, it is simply not public.
6.3 Policy dimensions
- Defence (programme points) — the airspace protection of military objects, low-altitude detection capacity and multi-model crisis management (programme point ID: HV1, HV11, HV12, HV13);
- Public safety and law enforcement (programme points) — the law enforcement protection of civilian critical infrastructure and the handling of incident data (programme point ID: KB1);
- Digitalisation and AI regulation (programme points) — the cybersecurity strategy and the domestic implementation of EU incident reporting obligations (programme point ID: D5);
- Foreign policy (programme points) — building regional resilience and cooperation on data sharing (programme point ID: KP10).
6.4 Literature in detail
6.4.1 Carl von Clausewitz: On War
Clausewitz’s best-known thesis is that war does not interrupt political intercourse but is its particular continuation. In his formulation “war is nothing but the continuation of political intercourse with the admixture of other means” — and precisely for this reason the events of war remain bound throughout to those political lines which determined the relationship of the parties in peace as well. Elsewhere he sums the same thing up thus: war is “another kind of writing and language of political thoughts. It has its own grammar, but its logic is not its own.” This idea is directly applicable to the present situation. Two drones flying over a military base are an insignificant event in military terms: they cause no damage, they disable no capability. In political terms, however, they are a precise communication — they say that the sending party is able to approach the place where the other party maintains its air defence. If the receiving side handles this exclusively as a criminal event, then in the Clausewitzian sense it does not even read the message: it concerns itself with the grammar, not with the logic. The threat report proposed by MIAK in point 3.2 is therefore not only a register but also a response — the aggregated, public datum is itself a political communication, addressed to the sender.
📖 Source: Carl von Clausewitz: On War
6.4.2 Sun Tzu: The Art of War
The part of Sun Tzu’s treatise dealing with reconnaissance describes the method we would today call probing. The advice runs thus: “Disturb him, and learn from how he acts, or precisely how he fails to act in response. Force him to reveal himself, so that he himself lays bare his vulnerable points.” The essence of the sentence is that the value of a provocation lies not in the damage inherent in it but in the reaction it triggers: the defending party shows with its response what it sees, how quickly it acts, and who decides. This is exactly the pattern shown by the series of European drone detections — individually explicable, harmless cases which together add up to the mapping of a defence system. There is an unpleasant consequence too: every uncertain, delayed or mutually contradictory official response is in itself information for the other side. If at a Hungarian incident first one body and then another appears at the scene, and clarifying the competence takes hours, that is the most valuable datum for the probing party. The responsibility matrix proposed in point 3.1 is therefore not only a question of operation but an instrument of defence: it is a fast, unambiguous and always identical response out of which the least can be read.
📖 Source: Sun Tzu: The Art of War
6.4.3 The NIS2 Directive of the European Union
The EU directive on the cybersecurity of critical sectors matters in this topic because it lays down concrete obligations measured in hours where the domestic debate today moves in generalities. The directive prescribes that essential and important entities submit an early warning in the case of a significant incident “without undue delay and in any event within 24 hours of becoming aware of the significant incident”. In it they also have to indicate whether the incident is suspected of having been caused by unlawful or malicious acts, and whether it may have a cross-border impact. This has to be followed within 72 hours by a detailed incident notification, and at the latest within one month by a final report. The other side of the system is regulated too: the designated response body has to give feedback within 24 hours of receiving the early warning, and on request has to provide operational advice. Three elements can be taken over directly from this structure into the present proposals. The first is that the reporting obligation is graduated: it does not ask for a complete analysis at once but for a fast signal and details later — this is the model that would work for drone detections too. The second is that the directive expressly asks for intent and cross-border impact to be indicated, that is, the assessment of the hybrid character is an expectation even within today’s legal framework. The third is that the legislation also regulates the time for a response — the regional channel proposed by MIAK in point 3.3 would extend this logic beyond the national border.
📖 Source: Directive (EU) 2022/2555 of the European Parliament and of the Council (the NIS2 Directive)
6.5 International comparison
In settling drone defence competences European practice is divided between two models. In one, the protection of military objects and of civilian critical infrastructure is strictly separated, and the exact legal moment of handover is fixed; in the other, a joint response unit operating with the participation of several bodies acts in every case, with leadership designated in advance. Both are workable, but experience shows that the system that fails is the one falling between the two: where competence is separated in principle but the conditions of handover are not fixed, response time is spent on organisational consultation. The German case — military police start, local police continue — is a clean example of the separated model, and it worked precisely because the order of handover was known.
An annual, public threat report is established practice in the Baltic and Nordic states, and by experience it brings a double yield. On the one hand the public series of figures ties the policy and budgetary debate to data: it becomes visible in which sectors the number of incidents is rising, and resources can be assigned to that. On the other hand regular publication increases societal preparedness itself, because the population becomes used to the fact that such cases exist, and so panic-mongering built on them is less effective. Data sharing at the regional level, by contrast, advances more slowly: the technical channels exist, but the speed of sharing typically depends on the political readiness to attribute — which is why MIAK proposes an expressly technical, data-sheet-based solution that does not require a joint political position.
6.6 Related MIAK programme points
Defence
- HV1 — Cyber defence capacity development
- HV11 — Strategic communication and information protection
- HV12 — Geostrategic defence planning
- HV13 — Multi-model crisis management decision-making
Public safety and law enforcement
- KB1 — Criminal data platform
Digitalisation and AI regulation
- D5 — Cybersecurity strategy
Foreign policy
- KP10 — Regional resilience building
Proposed new programme point: A drone defence responsibility matrix — for the Defence area, with an order of competences and of command promulgated at the level of legislation, by type of facility.
6.7 List of sources
Press sources (MIAK foreign press monitor, 10 August 2026 — topic 1):
- [Politico Europe] Germany battling ‘daily’ hybrid warfare attacks, minister warns — https://www.politico.eu/article/germany-battling-daily-hybrid-warfare-attacks-minister-warns/
- [Al Jazeera] Germany warns of ‘daily hybrid warfare’ after explosive-laden drone found — https://www.aljazeera.com/news/2026/8/9/germany-warns-of-daily-hybrid-warfare-following-suspected-drone-attack
- [BBC] Drones spotted over German base days after Leipzig bomb incident — https://www.bbc.co.uk/news/articles/cwyeg1ljp2eo
- [Deutsche Welle] Migrant tunnels in Lithuania direct suspicion towards Minsk — https://www.dw.com/en/migrant-tunnels-in-lithuania-direct-suspicion-towards-minsk/a-78280640
- [Visegrad Insight] Citizens Are First in Line Against Russia’s Sabotage in CEE — https://visegradinsight.eu/citizens-are-first-in-line-against-russian-sabotage-in-cee/
Knowledge-base references (books):
- 📖 Carl von Clausewitz: On War
- 📖 Sun Tzu: The Art of War
- 📖 Directive (EU) 2022/2555 of the European Parliament and of the Council (the NIS2 Directive)
Note: the local file path of the books does not appear in the visible text of the blog — only the author and the title. The file path is an internal matter of the generation process, not the reader’s.
MIAK internal materials:
- MIAK policy area: Defence (programme points; programme point ID: HV1, HV11, HV12, HV13)
- MIAK policy area: Public safety and law enforcement (programme points; programme point ID: KB1)
- MIAK policy area: Digitalisation and AI regulation (programme points; programme point ID: D5)
- MIAK policy area: Foreign policy (programme points; programme point ID: KP10)
- MIAK foreign press monitor, 10 August 2026 — topic 1, score: 93/100
Additional public data sources (where used):
- ENISA — European cybersecurity threat report (Threat Landscape)
- NATO Hybrid CoE (Helsinki) — hybrid threat analyses
- Eurocontrol — European drone incident statistics
Generation metadata
- Input press monitor: MIAK foreign press monitor, 10 August 2026
- Generation date: 10 August 2026 14:10 CEST
- Tokens used (total): 113,000 (see frontmatter
tokens_breakdown) - Translation: Hungarian original at /blog/2026-08-10-hibrid-fenyegetes-uzemmod-dronvedelmi-felelossegi-matrix-incidensbejelentes/
Related earlier analyses
- The consultation is already under way — Hungary’s homework on the American force realignment — 2026-08-05
- When the rule appears but the framework is missing: the rotational load-shedding order and the legal vacuum around voluntary power curtailment — 2026-08-01
- A ten-metre crater in a Polish wheat field: the threshold of Article 4 and the missing Hungarian airspace-violation procedure — 2026-07-31
Comments
The comment system will be available soon.