Journalist Ruth Ferrero meets in Madrid with Teija Tiilikainen (Finland, 1964), director of the European Centre of Excellence for Countering Hybrid Threats (Hybrid CoE) since 2019. Positioned halfway between a think tank and a research institute, the Hybrid CoE is a key player in European and Western security. The public face of this centre agrees to speak with Agenda Pública about its work, the challenges Europe faces, and the geopolitical landscape.
Founded in 2017 during years of growing non-conventional threats, the centre now brings together all EU member states as well as those of NATO. While its work is independent, the Hybrid CoE operates in constant coordination with all member countries to prevent and better understand threats such as disinformation, electoral interference, or attacks on critical infrastructure
Teija Tiilikainen is director at 'Hybrid CoE' since 2019. Photo: Agenda Pública / Tania Sieira
What is the origin of the European Centre of Excellence for Countering Hybrid Threats? What is its relationship with the EU and NATO?
When the Centre was created, it provided services to governments with specialized functions. In 2017 there were nine governments to start with.
At the beginning, the United States, the United Kingdom, the Nordic countries (only Finland and Sweden), the Baltic countries (Estonia, Latvia and Lithuania) and Spain were in: nine in total. It was launched that same summer of 2017 and, a couple of months later, Spain joined, which is why we also say it is a founding member. On the other hand, the Centre is related to the EU and NATO in that it is open to the accession of the members of both. At present, all the members of both have joined.
What are the main tasks carried out at the European Centre of Excellence for Countering Hybrid Threats?
We are an organisation of experts with three tasks focused on supporting governments in combating hybrid threats. That is the nature of the Centre: it was created because new security threats emerged—new tactics.
"In 2014, Crimea was annexed without any kind of war, foreign interference in elections began to be increasingly observed, and a phenomenon known as instrumentalised migration emerged"
In 2014, Crimea was annexed by Russia without any kind of declared war, and some new tools were used for that operation. Europe—and also the United States—began to observe increasing foreign interference in elections. A phenomenon known as “instrumentalized migration” appeared, and all these were new tools for projecting power. In that context, these countries felt that this was something that needed more detailed study and that governments should be advised and supported in addressing it. The idea was that it would be better to do this jointly, rather than for each country to create its own centre of excellence. Therefore, supporting governments in countering hybrid threats means that we carry out different kinds of specialized tasks, studies and analytical work. But we also provide training and exercises for governments, or we offer our platform for them to discuss and share best practices. That is basically the main task.
The second task entrusted to the Centre is a bit more specific, since both the EU and NATO, as organisations, take part in our activities. And both have their own tools with which they have begun to establish hybrid countermeasures. We are supposed to facilitate cooperation between them as organisations. We have some workstreams through which we try to bring them closer together and discuss the gaps or potential needs for deeper cooperation.
The third task is what we are doing now: raising public awareness about hybrid threats. These do not stop at the border or represent a threat exclusively against governments; they also constitute interference in societies. The Centre was given the task of raising awareness and making this kind of threat visible. We talk to the media, we organise events, seminars, and debates. We involve academics in our work and try to make these kinds of threats visible.
As for the tasks we are carrying out now, the range of hybrid threats is very broad, and we try to do both conceptual work—to help government address the phenomenon—and empirical work, in which we observe trends, patterns or cases of hybrid threats.
"We are analyzing the actors behind hybrid threats, namely Russia, China, Iran and North Korea: countries that declare themselves in supposed defence against a hostile West"
We also increasingly try to examine best practices on how to counter, prevent and protect. When there is a good policy, law or any other measure established in a given country, we are very interested in sharing that good practice among the 36 governments. We are also analyzing the actors behind hybrid threats—namely Russia, China, Iran, and North Korea—countries that openly declare that they must use the full range of tools at their disposal in their supposed defence against a hostile West. Of course, they flip the narrative. They are very open about their approach of using all the tools at their disposal. We analyze their mindset and doctrines, their strategies. We compare them as actors in terms of the tactics and means they use. Now, we also have a certainty: we are paying more attention to some neighbouring regions [the Caucasus], and also to Africa, because important developments are taking place there that are very detrimental to us. We are analyzing both the hybrid commercial activities of China and Russia in African countries and how they could affect us.
There are many other issues that concern us. For example, we also turn our attention to the North and the Arctic region. The expectations come annually from the 36 countries, the EU, and NATO. The topics I am mentioning are what concern them most now, we try to then respond to that demand.
So they raise issues that are being identified in different Member States and you try to provide analysis and preventive tools to address them, right?
That’s right. They propose topics that are essential to them, and we compile and coordinate the programme to make it coherent. We can start implementing each of the proposals, but an initial organizing phase is necessary. We are expected to lead the debate, so the Centre also brings its own proposals on what we see happening now and where we think we should pay more attention.
"It is necessary to show the way with regard to new forms of threat: that is why we are working on the use of emerging technologies and artificial intelligence"
Furthermore, we should not be too reactive, but at the same time it is necessary to show the way with regard to new forms of threat. That is why we are also working on the use of emerging technologies, artificial intelligence, etc., and there seems to be great demand from countries for us to study them. The cyber domain is full of different areas of specialization, but that is how we operate.
Teija Tiilikainen points out that countries such as Russia, China or North Korea are acting against West. Photo: Agenda Pública / Tania Sieira
Moving to a more conceptual framework, just for the public: could you tell us what the definition of hybrid threats currently is in EU countries? How is this concept defined?
We define hybrid threats as the use of non-conventional tools—often different tools—used in a concerted way to affect the target so that the targeted country makes suboptimal decisions with respect to its own interests. In short, this means that non-traditional instruments are used, but also conventional tools, such as armed force or military, political and diplomatic apparatuses, in different combinations in order to influence the target country's political decisions, many times in foreign policy. There has to be an active intent, as well as an aim and an objective. What sets it apart from other types of threats are these tools.
It is not only about those traditional instruments we know from international politics, but also about electoral interference, the widespread manipulation of the information space and instrumentalized migration, attacks on critical infrastructure, economic coercion, etc. All of these are different, complex tools.
So there are three main blocks of issues you mention as critical. First, actual critical infrastructure. Electoral interference would come second. And third would be misinformation. I would like to go one by one, starting with attacks against critical infrastructure. For example, Nord Stream. What happened there? There was a lot of speculation about what occurred. At first, it was said to be a Russian attack. Later, apparently, it was another kind of attack.
We operate at the strategic level. We are not an intelligence service or an operative entity. Therefore, we do not have operational capacity to launch an investigation. All that is the responsibility of the authorities. What we do is monitor and analyze these things to identify common patterns, but also to find tools to counter them or improve resilience. Because our task is to help government counter them, not to do the work that their authorities do.
Critical infrastructure is very hard to protect because our societies, as we know, depend heavily on many kinds of vital infrastructure. These can be financial systems, energy, technology… Not to mention the mutual interdependencies of these systems.
So we have created a situation in which the whole of society can be paralyzed quite easily. Basically, with a single point of entry, if chosen cleverly, the entire society can be paralyzed and physical damage can also be caused. We now know this, and there is a lot of information about the efforts or interest hostile actors are showing toward this critical infrastructure and its weak points.
"What our Centre is trying to do is improve this debate about what could be done, but a feature of these operations is that they are very difficult to detect"
Therefore, what our Centre tries to do is improve this debate about what could be done. You yourself have mentioned that a feature of these operations is that they are very difficult to detect. We certainly cannot point to those responsible. We can rarely initiate the proposed processes because there are no culprits. And this is part of these threats, because as part of these alarms, the side effect is to increase the feeling of insecurity and decrease the population’s trust in their own government. Because if these kinds of things start to happen—and I can assure you that last autumn in the Baltic Sea was one of those periods when we saw them multiply—governments, one after another, had to admit that we don’t know who was responsible. There may be a state actor behind it, but we’re not sure.
Acts of sabotage were also carried out skillfully and in most cases outside the jurisdiction of the coastal state, such that the law of the sea did not allow the coastal state to launch any investigation or board the vessel.
When there is a global conflict and there are actors who publicly declare that they need to weaken the West because the West has dominated the global stage for too long—this is what both Russia and China are telling their global audience—that they must use the entire range of tools available to them to weaken the West. Therefore, regardless of who is behind the various specific cases, we must think about the resilience of these vulnerabilities that are evident in the realm of critical infrastructure. And also, if we think about financial systems, we have to underscore the importance of cyber tools. I am not describing what could happen, but a major catastrophe could easily occur.
Ruth Ferrero delved into the specific tasks carried out by the centre. Photo: Agenda Pública / Tania Sieira
On the second block, how are you, first, addressing possible attacks or the identification of vulnerabilities in different electoral systems and, second, advising governments to act against this interference? What tools are you using to tell different governments: "Look, you are being attacked in the course of an election"?
There are different ways. Our main product with regard to our work to counter electoral interference is training. It is a training programme we provide to governments that are interested in it. We call it "prevention of electoral interference," and it is offered to countries in which elections are approaching. It is a periodic training, so our experts plan it together with national experts. We want to tailor the training to the geopolitical and national situation and try to anticipate the forms of interference that could occur in that specific country. We draw on interference cases we have collected from previous elections. Not only that, but we also use them as training material.
We have a specific handbook in which we have prepared recommendations for governments on aspects to be considered two years before elections, six months before elections. Because in this regard there are two different things: there is the technical procedure during the electoral process itself, in which technological tools play a role. But there are also campaigns, candidates and all the discourse that takes place on social media. In this second case, technologies also have a strong influence.
"From the Centre we prepare a handbook to help decision-makers plan their own policies and the protection of elections"
The aim of the handbook is to help decision-makers plan their own policies and the protection of elections. At the same time, when we plan that exercise together with the country’s government, we encourage them to bring, when the training is held at the Centre, the different responsible authorities. There are cases in which we are told that it is the first time such a group has met. Therefore, we could also facilitate some national cooperation within countries.
In the early years we already promoted stricter regulation of social media companies, as has now been done at the EU level. Thus, we have promoted legislation on malicious financing. Therefore, our activities can take place at very different levels, with these macro-level proposals relating to the regulatory framework, for example. And from there, we can move to more case-by-case advice or recommendations to governments. We have also published openly public work, mainly on policies, not on specific cases, because there is also the NATO Centre of Excellence. I believe the StratCom Centre in Riga has published a report on cases because they verified them, but we do not necessarily have access to highly detailed information.
So we rely on secondary sources and open-source material in this respect. Unfortunately, there are many proven cases of foreign interference in elections: Moldova or Romania and, earlier, France, Germany or the 2016 U. elections.
The US elections were the beginning and then came Brexit, right?
Correct—more or less that is the origin of it all: the alarm began then. It was at that moment that the public conversation started. But, as we know, it is very, very difficult because, in many cases, there is fertile ground that they can continue to exploit for the proliferation of these narratives. So it is not so much that they are creating new situations as that they are exploiting divisions or national history. Then, of course, they amplify and target them.
"The Moldovan elections were unique in terms of the tools that were used for interference, and although Moldova is not part of the Centre, we use their experience for our work"
For example, the Moldovan elections were unique in terms of the tools that were used. This case—even though Moldova is not a member state of our Centre because it is not a NATO member—has been used a lot by us, and we have also used their experience in our work. Moreover, we organise an annual workshop on the topic with representatives from most countries and guests. And everyone brings to the table some findings from their own country, concerns, or cases that have occurred, tools used. Then we also use that as a great aggregator of information.
To select best practices.
We compile best practices and discuss among national experts whether there are things we could do together, whether there are things the Centre could do better or more often, whether there are new vulnerabilities. Of course, this is quite sensitive—if someone has detected new vulnerabilities in systems, or new tools, I mean.
Providing a platform for countries to meet is an important and appropriate form of activity for us. Governments have the expertise and we provide the platform. We organise an event, encourage them to send a national expert responsible for national election security or something similar, and then we design a two-day programme.
Tiilikainen y Ferrero share a common view on electoral interference. Photo: Agenda Pública / Tania Sieira
Thinking about Romania, what happened when the attack occurred and the Government requested your advice? The whole process was very fast and they cancelled the elections. Afterward, the Venice Commission said that was not constitutional.
When something serious happens, we are not the first responders. Moreover, we try to avoid getting too involved in domestic affairs. Our vocation is to advise in advance, support them, create policies, tools, and means. Consequently, many times we do not have the capacity, when something happens, to give them immediate advice. It is neither in their mandate nor in ours to act like that. It would be extremely difficult because we also do not have access to their internal information. Lacking the information we would need to be able to respond—in the case of Romania, whether there should be new elections or not—our role is limited. That would be asking too much of us for the means we have and for our objectives.
As you have just mentioned, the Centre always works with open sources.
Yes. We do not have access to classified information. At the beginning you asked me about our experts: we have 55 people working at the Centre; a little more than half are experts hired directly from academia, think tanks and also the public administration. Then, around 20 are experts seconded by governments, again mostly from the administration—different ministries, etc. But some countries have also seconded experts from academia, one from a central bank, a journalist—depending on our thematic needs and also on their priorities. The country that decided to second an expert or hire an expert from a central bank is concerned about vulnerabilities in financial systems. By sending an expert from that field, they wanted to support our work on that topic. That is, roughly speaking, how it works.
The last block is devoted to what is probably the most diffuse issue, which is information. At this point, how is your institution addressing this enormous threat to democratic societies? How do you identify that a disinformation campaign is underway?
First, I would highlight the importance of information. I personally call it, or give it the name, "manipulation of the information space," because I think this helps to better understand the integral nature of the problem. So these information campaigns are mainly directed at a particular audience, but the broader manipulation of the information space is based on the strategic narratives of countries that want to revise the current international order. These strategic narratives are being used to tell a very different story about their own role in international politics and their objectives in international politics.
I think this is what lies behind targeted disinformation campaigns. These campaigns are mainly based on their strategic narratives—on what they want to achieve with their policies. Operating at the strategic level, when an operation is underway, we do not interfere or get involved in it. But we want to make the threat visible. And that means that we act at the macro level, for example, by showing what these strategic narratives mean.
"In the ongoing war against Ukraine, the manipulation of the information space, which is everywhere, is a very important element for Russia because it helps it to continue with its invasion"
Because, for example, in the ongoing war against Ukraine, this manipulation of the information space everywhere is a very important element in Russia’s ability to continue the war, since they are securing the support of their own population. But not only that; they are also securing the support of many other countries thanks to their skillful strategic narratives, in which the fundamental cause of the war is found in the West and in Western hostilities, in addition to the atrocities of the Ukrainian regime. We operate at that level and analyze these strategic narratives so that our audience and ordinary citizens also see the connection between some specific campaigns being carried out in their countries and their broader approaches.
We have published quite a lot of material on specific disinformation campaigns, but also on ways to counter them. We have published work on Ukraine and on how that country has managed to counter Russian operations during the war. This is a joint effort between one of our experts and a Ukrainian expert. It is not an openly public publication, so to speak, but rather the results of the annual workshops I mentioned, in which we compile best practices—what has helped and what has succeeded at the national level.
In this discussion about how to counter, we have cooperated and continue to cooperate with social media platforms. We try to encourage them to live up to their responsibility to monitor and track what is happening. On the other hand, we are debating with education experts, and this is where media literacy comes into play. I am increasingly worried about the future, because we know that, when we look at the figures, the younger generation gets its information from online sources and not from quality journalism. The entire information space is in deep transition. This debate about post-truth or post-reality is always present.
The creation of false narratives and historical distortions can also take the form of hybrid threats, according to Teija Tiilikainen. Photo: Agenda Pública / Tania Sieira
Post-truth is one of the most accurate names for all this. How do you think it should be addressed? You have mentioned relying on different types of regulation to prevent these campaigns or talking to social media and so on, but the criticism says: "Look, there can be a conflict between freedom of expression and thought. Who is the one who decides: ‘This is true and this is not true’?" For me, that is one of the main difficulties in addressing this situation. How do you see it?
I think that, because this is the adversaries’ tactic, they try to push us to compromise our values in order to accuse us of being hypocrites. This is part of the playbook in many cases. Finland had to close its entire eastern border with Russia when the latter continued to carry out instrumentalised migration operations. Then a new law was also enacted which, according to many experts, contradicted human rights conventions and EU human rights law. Their aim is to find those vulnerabilities so that our governments have great difficulty finding a balanced solution. Because this is about finding a balance between freedom of expression and national security. If someone wants to influence public opinion or run political campaigns before elections, where are the limits? If we basically want to hold on to our freedom of expression and also want to maintain a positive view of social media platforms as a space for democratic debate, what can we do?
I wanted to ask your view on what the main hybrid threats facing EU Member States are right now. Also on which actors you have identified as responsible for those threats. Because you have mentioned Russia, China and Iran. But what is the situation now with Trump in the White House?
Well, so far there are dividing lines within the EU and NATO as well. Among democratic countries there are differences of opinion, but the threat against democracies and the democratic principle is very real. This is the target because it is the main threat to authoritarian regimes. The more democracy is promoted on the ground and the closer it gets to their borders, the more authoritarian systems are weakened or called into question. As for the role of US leadership at the global level and Europe as a partner, I think it is something key and that has not changed.
"The comprehensive manipulation of the information space is the most important threat we face, because it also has long-term consequences"
I would say that, based on what we have just discussed, the comprehensive manipulation of the information space is the number one threat, because it also has long-term consequences. Think of Africa, what is happening there with the entry of other actors. In addition, China is actively using the war against Ukraine to advance its own role as the responsible actor, the Western one, to blame the West for its practices and to more or less repeat the Russian narrative about the origins of the war. We are not in a position to correct the message.
Because we are not consistent.
We are not consistent and we are different. The EU is a different kind of actor from the rest because it does not have a very strong strategic narrative to promote, unlike these countries. And the EU is an alliance, a union of democracies.
It is not a country.
No. By nature, we are in a more difficult position to respond to that threat. I think this is very concerning because, in the long term—but also in the short term—we will see the consequences. European countries are divided; they have quite different opinions about the origins of the war against Ukraine. So there are countries in which more than half the population supports the Russian narrative about Western hostility and about planned hostilities and security threats against Russia. Or that Finland and Sweden are joining NATO because the United States demanded it and exerted pressure on them. We see concretely in our countries that, in Finland, support for NATO was around 20% until the aggression began.
Now there are NATO military installations on our eastern border [Finland’s]; for this reason the border is closed, although it is also due to the Russian operation.
Many thanks, Teija.