Direkt zum Seiteninhalt springen

Keeping the Lights On: How the OSCE is navigating growing cybersecurity challenges

SWP Podcast 2026/eP 03, 20.07.2026 Forschungsgebiete

As geopolitical tensions shift into cyberspace, the OSCE faces mounting challenges. With Russia among its 57 members, the concept of consensus-based security is under strain. Alexandra Paulus and Nadja Douglas analyse if and how the OSCE can adapt to an increasingly contested cyber landscape.

Wenn Sie diesen Drittanbieter-Inhalt aktivieren, ermöglichen Sie dem betreffenden Anbieter, Ihre Nutzungsdaten zu erheben. Weitere Informationen zur Nutzung von Drittanbieter-Inhalten erhalten Sie in unserer Datenschutzerklärung.
Datenschutzerklärung anzeigen

Disclaimer: This transcript has been generated by AI. It is not a fully edited and proofread text.

Host: As geopolitical tensions play out increasingly in cyberspace and these evolving security threats are compounded by the rapid rise of AI, the Organisation for Security and Cooperation in Europe, better known as the OSCE, has its work cut out. And with Russia among the OSCE's 57 members, its consensus-based approach to security is being undermined by an aggressor sitting at the table. You're listening to the latest podcast from the German Institute for International and Security Affairs. Or SWP for short, here in Berlin. In today's episode, we're asking how to keep the lights on in increasingly dark times as
Russia continues its war in Ukraine and targets fellow OSCE states with cyber attacks and as Five Eyes intelligence agencies warn that AI will render cyber defence capabilities outdated in months, not years. I'm your host, Esme Nicholson. And to discuss the state of cyber security in Europe and beyond, I'm joined today by SWP's Alexandra Paulus and Nadja Douglas. Alexandra Paulus heads up SWP's research cluster, Cyber Security and Digital Policy, and her work intersects technology, security and defence policy and examines the societal, political and military potential of critical technologies as well as the risks
that they pose. Alexandra, welcome to the studio.

Alexandra Paulus: Thanks for having me.

Host: Nadja Douglas leads the SWP OSCE project, working to define the OSCE's changing role in a new European security order. Nadia's research focuses on the political and defence aspects of European security, Eastern partnerships and the Republic of Moldova. Nadja, welcome to the studio.

Nadja Douglas: Thank you. Glad to be here.

Host: So we have a rather fraught cyber security situation within the OSCE's 57-nation membership, set against a challenging geopolitical situation and a rapidly changing technological landscape, not least because of AI. How resilient is the cyber defence sector and the OSCE? Alexandra, perhaps you could start by painting a picture of current challenges.

Alexandra Paulus: Sure. So the cyber security situation has been worsening for years or decades even to illustrate only last year, 2025, cyber operations caused harms to the German economy to an equivalent of 4.5 of the German GDP. So that is a huge number. And also just to illustrate with one incident that can show us what harm such cyber operations can cause. At the end of last year as well, in December, Russian actors came very close to taking out parts of the Polish energy sector. So that would have caused a massive blackout in at the end of December when it was very cold. So with creating huge harms for the civilian populations in a EU and NATO country. So the challenge of cyber security and cyber operations really affects all parts of society. It can affect individuals, but also, of course, critical infrastructures like the energy sector, militaries and, of course, the economy. And, yeah, cyber diplomacy is really the quest to have international dialogues and alleviate these threats to international security. And there you can sort of have four pillars. You can have the international law question that defines what states are legally not permitted to do to each other. You can have norms that are legally, but more politically binding, seen as sort of a softer instrument to also create these these guardrails and rules for what states should and shouldn't do. Then you have confidence building measures that are supposed to decrease the chance of inadvertent escalation of conflict. And then there's cyber capacity building that's meant to increase the capability levels of all players involved. So in all, we have seen some important successes in these fields, but overall, they have remained rather limited, I'd say.

Host: Well, we'll come to some more detail on that later. But and you mentioned cyber diplomacy. Nadia, what are the OSCE's main challenges right now? It places a lot of emphasis on consensus. What are the main challenges, though, right now?

Nadja Doulas: We all know the OSCE is all about peace, security, stability in Europe. I don't want to go into too much historical detail now, but confidence building measures have always been at the core and heart of this organization. So here are the OSCE differentiates between conventional sort of military CBMs, CSBMs, information exchanges, transparency, verification measures are the answers and non-military CBMs that are there to build trust through active activities in the fields of political, economic agreements, societal and cultural measures. So cyber CBMs, confidence and security building measures, they have come on top because participating states during the last decade realized that first, there is rapid digitalization happening. Second, no state will be able to provide its own national cybersecurity without international cooperation because of the cross-border nature of the cyber realm. And third, simply extending existing political-military CSBMs would not work because of the particularities of the cyber domain. So the OSCE has adopted in total 16 so-called cyber ICT CBMs. What's an ICT CBM? You're about to tell me, aren't you? So there is no consensus within the organization whether to call it now cyber or information and communication technology. So that's why it's slash cyber ICT. So on the basis of the decisions of the Permanent Council, which is the principal decision-making body. So the biggest challenge now is the loss of geopolitical trust since 2022. Russia's war of aggression against Ukraine has eroded the basis of consensus within the OSCE as a whole. And as Alexandra has already said, we're witnessing growing numbers of cyber incidents since 2022 in the OSCE region, but not only, of course. But the political will to further develop the CBMs, it's not there anymore because we're facing a low trust environment. What is remarkable, and I close with that, is that there is an informal working group on cyber ICT security within the OSCE. And it remains basically one of the last places within the organization, and I would even say anywhere, where Russia still participates in the discussion and exchange is possible. So CBMs continue to be implemented by the majority of the participating states, and that's quite stunning. And the organization could potentially or eventually build upon this.

Host: Just to get to what they could build upon, could you maybe give me an example of some of the CBMs that are being implemented, and then maybe assess whether these existing confidence building measures are actually adequate?

Nadja Douglas: I would say there are two CBMs that kind of stand out because they're picking up what CSBMs, the confidence and security building measures, were initially meant to do. They reduce the risk of war escalation or escalation arising from miscalculation, misperceptions, or lack of communication. There's first CBM-8, the national points of contact network. It facilitates direct communication. That's kind of a structural analog to the Cold War classical red telephone between the US and the Soviet Union. These direct communications links are essential today. Also, they're kind of analog to the military-to-military
consultation mechanism built into the Vienna document, which is the principal confidence-building measure instrument of the political-military dimension of the OSC. The second one is CBM-3 on voluntary consultations to reduce risk of misperception in the event of a cybersecurity incident. And this mirrors basically the clarification mechanisms in Chapter 3 of the Vienna document. What's the idea behind it? It's better to raise it directly and get clarification before drawing false conclusions or retaliating.

Host: And these all sound perfectly sensible. I guess my question is, considering the rapidly changing cybersecurity landscape, are these measures then adequate? Again, if I can just ask Nadia to respond, and then 'm going to come back to Alexandra.

Nadja Douglas: I guess the question is not really whether they are adequate or not. It's the only thing we have, or the participating states have. As you rightly mentioned, the OSC is a consensus-based organization. And therefore, at the moment, there is no leeway, no room for maneuver to actually reach a consensus on something else. And it's good that they exist. Had they not been adopted previously, today it would be impossible.

Host: And Alexandra, what's your take? Does technology itself present additional hurdles or even complicate these confidence-building measures?

Alexandra Paulus: So maybe let's focus on cyber operations here, rather than technologies in general, because I think that's maybe for another podcast episode. But so I think, as Nadia said, if the idea is that confidence-building measures are supposed to prevent unintended conflict escalation, the first question should be, well, do cyber operations tend to contribute to conflict escalation? And there, it's actually quite interesting to look at some research that answers that question, that
found that actually cyber operations often tend to be rather de-escalatory. So we have seen many cases in which cyber operations were, for example, conducted as an alternative to a kinetic airstrike, for example. So the most famous example is probably the joint U.S.-Israeli Stuxnet malware, which was supposed to prevent Iran from gaining nuclear weapons. That was really used as an alternative to a kinetic strike on a nuclear enrichment facility in Iran. So that is not maybe seen as really an escalatory measure. But I'm sure that there can be some cases in which cyber operations can also contribute to escalation. But it's important, I think, to always have this in mind, because also, Nadia, you said that cyber is now seen, or the cyber domain is seen as a domain of war. And I think that is, of course, true. But it's, of course, also important to keep in mind the role that cyber operations have played in military conflict so far, because this holds a lesson for us for the design of such confidence building measures as well. And what we have seen is really that cyber operations are much more of a critical enabler that support other military functions and are much less used to conduct harm in itself. So, for example, cyber operations have been used a lot to gather intelligence, to prepare other operations, for example, to gather location data. We've seen this in the recent U.S. and Israeli war in Iran. They have also been used to support traditional kinetic strikes, so, for example, to turn off air defenses and then make airstrikes easier. And then in much more select cases, they have been used to conduct sabotage. But I think it's important to keep this in mind. But if we, of course, consider the fact that, as Nadia well pointed out, information and communications technologies are inherently dual use, so they can be used for both civilian and military purposes, still, the main threats are outside of armed conflict. When we look at, for example, the threats that Germany is facing, the main threats
are not even coming from state actors, but from criminals. And so one problem with cybersecurity is simply that you have these very many different actors that are sometimes using even similar tooling, but with different objectives to different effects. And it's quite hard to disentangle that and then to understand, well, what can a policy instrument like a confidence-building measure do for me in this case? So it's just important to keep in mind that there are many different actors at play, and an instrument like a confidence-building measures can only have an effect on some of these.

Host: Nadja?

Nadja Douglas: Yes, that's very true. And I want to concur with one point Alexandra made. As part of the OCE project, we look at the incident data of the European repository for cyber incidents. And interestingly, the severity factor of incidents usually lies below what would be considered a threat hold for conventional response. So although there are no standard threat holds yet, but one thing I would rectify, first, CBMs are not designed to prevent or reduce the number of malicious cyber attacks, particularly not those originating from non-state actors or criminal organizations or proxies. But they can make their
accidental deployment less likely or less, there's less unintended escalation. And then the other thing is, even though they are below a certain threshold, the constant cumulative effect of being targeted can be destabilizing over longer periods of time.

Host: Well, and you've given us, both of you have given us a sense of the current cybersecurity situation, but perhaps we could dig a little deeper. And Nadja, you actually just started to talk about the rise in incidents, but could you tell us more about the rise in incidents within the OSCE, among members of the OSCE?

Nadja Douglas: Yes, that's exactly what we're looking at in our project. The overall number of cyber incidents has increased since 2022 by several hundred percent. I cannot give you the exact data, but in the period before 2022, it was just above a hundred. And now since 2025, we're over thousands. Since Russia's full-scale invasion of Ukraine. Yeah. So the incidents, they are definitely driven by the war. Russia is one of the main aggressors.

Host: Well, Alexandra, tell us more about the aggressors and the main actors that they're targeting.

Alexandra Paulus: Looking at the aggressors, it is entirely clear that the main threat is coming from Russia, both for state-sponsored operations and also for non-state actors, because Russia is the most important safe harbor, so to speak, for cyber criminals. But it's also important to see that there is really a large gray area between these two ends of the spectrum. So there's also a myriad ways in which the Russian state is cooperating, directing, tolerating, just having different symbiotic relationships with non-state actors, be they criminals or activists, et cetera. And so that makes it, of course, much harder to respond when you're not entirely sure if you want to respond politically or diplomatially, if you're not entirely sure to what extent this is a state operation. And then I think with a view to the operations, it's just important to keep in mind that you need to distinguish between espionage operations on the one hand and then sabotage on the other. So the incidents we've spoken about up to date have been, for example, the energy sector in Poland, of course, that is a sabotage operation. These tend to target a critical infrastructure. Another blatant example we saw also in 2025 and last year was one that targeted a hydropower dam in Norway, which was basically they opened the floodgates and left them open for hours and it took hours until people noticed that something was off. And we're not sure what happened there or what the perpetrators were, what their objectives were. So probably they were just testing when are people noticing, how are they responding, much as in the Polish case, where, by the way, there has been absolutely no diplomatic or any other response to date.

Host: Testing the waters,so to speak.

Alexandra Paulus: Exactly. And then the other factor is espionage, right? So the newspapers here in Germany have been full over the past months regarding Russian cyber espionage using the messaging app signal. But again, it would work with any other messaging app because what they're targeting here or what they're abusing is people's trust in other people and in messages they receive from people they don't know. And so there, of course, cyber espionage is again just a really critical enabler for actors like Russia to gather information about, for example, in that case, political leadership.

Host: So coming back to attempts to find solutions, Nadja, which regional organizations are implementing some of the measures you've mentioned and what are those measures and what results have they yielded so far?

Nadja Douglas: From our qualitative research and interviews, it emerged that inter-regional cooperation becomes increasingly important. And from looking at it from the global UN level, regional organizations, they are regarded as incubators and also supporters and facilitators of the global UN level CBMs. I would say even various regional organizations have specialized in different pillars of this UN framework. The OC, by the way, was the front runner and first organization to develop cyber
confidence building measures. Other organizations have followed suit. I would mention here the Organization of American States, OAS. They address traditional confidence building measures since the 1990s and they have now a list of so-called non-traditional that's mainly but not only cyber confidence building measures. And then there's other organizations like ASEAN, which is the Association of Southeast Asian Nations. They engage in the context of preventive diplomacy and also in the context of the ASEAN Regional Forum with cyber security and confidence building measures. And finally, I want to mention also one African organization is the Economic Union of West African states. That's the first region in Africa that has successfully established a set of three CBMs for cyber security and the OC served sort of as a role model here. And now at UN level, there's since last year the new UN permanent global mechanism and it's being discussed that these inter-regional exchanges between these various regional organizations, they could take place more frequently, for example, at the margins of plenary meetings. And it's even discussed if this could be become institutionalized.

Host: Alexandra, the various measures that these organizations are implementing, to what extent or have they helped fend off cyber attacks? If so, which ones and how?

Alexandra Paulus: Yeah, so I'm really a bit pessimistic when it comes to that because there are, of course, important methodological challenges when we want to answer that question. So if CBMs are effective at what they do in the sense of preventing unintended conflict escalation, it is very likely that from the outside we won't know because very likely military planners, et cetera, simply won't tell us what they would have done in the absence of a point of contact in country X, Y, Z.
But from the outside, what I as a political scientist can study, I can look at statements in which one country blames another for a cyber operation, for example. I can look at cybersecurity policy strategies. I can look at other like diplomatic statements, et cetera. And basically, confidence building measures play no role whatsoever in any of these. And so that then made me wonder why is that so? And I think it's important to once again take a step back and look at what cyber CBMs are doing. So in essence, you are transposing an established concept that was developed for conventional weapons and want to apply that to a new
technology, to a new space that simply functions differently. And so I think for some kinds of confidence building measures, that works well. I think also for cybersecurity, you can share information about points of contact that has been, I think, implemented very well in different organizational settings. You can share information about your strategy, about your policy, so that works well. But for example, when it comes to sharing information about your weapons, it is not problematic if I tell you how many tanks I have because that does not diminish the number or the quality of the tank. However, if I tell you exactly what kind
of software exploits I have or in what way I intend to use my cyber force, that then does diminish the value of the skills, the exploits, et cetera, because this information loses value over time. So it's just almost impossible to share information about quote-unquote cyber weapons because I think that term is not analytically useful. but yeah,it just doesn't translate very well.
Host: Well, considering the difficulties that cyber security presents simply because of its nature as Alexandra has described, Nadja, how effective is the OSCE at all right now given that Russia is at the table?

Nadja Dougas: CBMs have multiple functions and I do believe that we should not look at the topic only from a Eurocentric, NATO-centric perspective. We're here comfortably set in Western security alliances, but the OSCE has another function. We already touched upon it, the capacity building, that the OSCE is an important platform and process for capacity building for smaller states on the one hand, but also for states that are relatively new to the cyber security discussion and provide them with the opportunity to discuss this issue with more cyber mature states. And I want to give an example. As part of our research, among others, we also focus on vulnerable states and them being targeted, for example, by Russia. And two countries have faced major hybrid destabilization campaigns by Kremlin-oriented actors that has been the Republic of Moldova and Armenia. So both countries struggled because they were targeted by coordinated hybrid campaigns that linked, that was the interesting thing, they linked cyber operations with foreign information manipulation and interference, short, FIMI. So despite the fact that they faced these enormous challenges during the election periods and beyond that, they managed this
difficult period. And why has that been the case because they have built up their resilience and they have been receivers of capacity building endeavors, among others, in the context of the OEC. And they do not have so many other forums to engage with other states. Of course, Moldova now has other avenues due to its status as an accession country to the EU. But they do, within the OEC, they do exchange about these issues in the informal working group. For example, they give updates about their cyber infrastructure, about new legislation, and they do that despite the fact that Russia is sitting at the table. Yes, so I do believe that they really profit from this exchange and the DOC.

Host: Alexandra, what are the other options? Where should we look to for solutions that will actually improve cyber security and cyber diplomacy as you've been talking about?

Alexandra Paulus: I think it's fair to maintain these forums. Nadia, you mentioned the global mechanism at the United Nations and also, of course, you've spoken a lot about regional organizations. So I think it's very valuable to have these communication channels with different actors. So it's, of course, important to maintain the dialogue. But I think also the case can be made that states should not dedicate too many resources on these forums because with a view to the current international situation, it is just very likely that they won't yield very many results. So instead, I think states should do, or it's important to focus on two things. First, there can be smaller bilateral or even minilateral formats that can make progress on specific issues. One example is the counter ransomware initiative, where I think now more than 60 countries have come together that want to fight ransomware because they've seen this as an important political problem and they are just focusing on this one problem. It's a big problem, of course, but they are very focused on what they do, and I think that makes it more likely to have results there. Another such process exists for the problem of spyware and other surveillance tools. So I think that is a much more helpful way forward than these all encompassing processes. And then the second thing is that states should use tools to hold irresponsible states accountable. So again, there are instruments available. There's the EU cyber diplomacy toolbox. Well, states should use them, for example, by discussing sanctions or by at least responding diplomatically to incidents like the one in Poland.

Host: Well, finally, it's policy recommendations time. If you'd continue, Alexandra, what are the next steps? In concrete terms, what should states and organizations be doing?

Alexandr Paulus: I hink in addition to these points to really impose costs on aggressors, a very basic thing, but it can never hurt to say it again in cybersecurity circles, we just need to get better at protecting ourselves and at getting the basics right. When you look at cybersecurity incidents and why they were successful, it's always the same reasons. And it has been so for at least a decade, if not decades. As a government, you can use incentives, you can use regulation, and you should, in my view, you should impose sanctions if entities like, for example, critical infrastructures don't comply, or also especially for military targets. But then I think a really important point in my view is that in the end, you don't want a very targeted cybersecurity strategy, not just one domain strategy, but you want a multi-domain strategy. You want to focus on the aggressors, and you need to think of this as not just a cyber problem, but rather the rise in cyber operations from Russia points to the need for a coherent EU strategy on Russia and for coherent EU responses to cyber operations, just like other operations
from Russia.

Host: And Nadja, what are your policy recommendations?

Nadja Douglas: It's actually difficult to define concrete policy recommendations because it remains a balancing act between what is necessary and what is politically feasible. And as we already said, the situation within the OEC is rather complicated because it's a consensus-based organization. And I already stated that the informal working group where Russia is part of is considered a technical body. That means political questions, questions of attribution, they are kept outside. And this is what we should focus on. If relations on the diplomatic political level are turned sour, it's more important to focus on the collaboration
between, at the technical level, between CERTs and CERTs. So keep talking in as far as it's possible. And keep the attribution question excluded, for example.

Host: Well, no doubt we will keep talking at a later date, but that just about rounds off our discussion on cybersecurity threats for now. I'd like to thank our guests, Alexandra Paulos and Nadja Douglas, for their insight. You can find links to their latest work and publications in the podcast show notes. And if you like what you hear, you can subscribe to us in the usual places, including Spotify and Apple. And you can also keep up to date with the latest analyses from SWP on Blue Sky. Today's episode was brought to you by our editor, Maya Dähne, by me, your host, and of course, by our guests, Alexandra Paulus and Nadja Douglas. Thank you for tuning in.

Nadja Douglas is a Senior Associate of SWP‘s Eastern Europe/Eurasia Research Division. She leads the SWP OSCE project, working to define the OSCE's changing role in a new European security order. Alexandra Paulus is a Senior Associate of the International Security Research Division at SWP. She heads up SWP's research cluster „Cyber Security and Digital Policy“.