Not Every Drone Is an Attack. How Can You Recognise the One That Might Be?

7. októbra 2026

A drone flying over a power plant, airport or water facility does not have to cause any physical damage to disrupt its operations. It may be enough for it to appear in the wrong place at the wrong time, while the critical entity has no idea what it is doing there. This is precisely why attention in Europe is shifting from technologies designed to neutralise drones to something less visible: the ability of critical entities to detect an incident in time, assess it correctly and manage it without unnecessary losses.

What exactly has the EU adopted?


The European Commission has moved from declarations to concrete documents and deadlines. In October 2025, it presented the Defence Readiness Roadmap 2030, which includes two flagship initiatives – the European Drone Defence Initiative, focused on counter-drone defence, and Eastern Flank Watch, aimed at strengthening surveillance of the eastern flank. The counter-drone initiative is expected to have initial operational capacity by the end of 2026 and to be fully operational by the end of 2027.


This was followed by the EU Action Plan on Drone and Counter-Drone Security, presented on 11 February 2026. It is built around four priorities: preparedness, detection capabilities, response coordination and defence readiness. The Commission also proposed that Member States appoint national drone security coordinators. The plan explicitly addresses civilian internal security and the protection of sensitive sites, including the EASA framework with protocols and maps of restricted zones, as well as the development of a system for managing drone traffic at low altitudes through U-Space.


For critical infrastructure operators, the practical conclusion is clear: the European framework is being developed now, and the national requirements that emerge from it will ultimately affect individual sites and their security management.


When a drone brings an airport to a standstill


The fact that a drone does not have to cause physical damage to create a serious problem has been demonstrated by incidents at European airports.


In September 2026, aircraft movements at Brussels Airport were suspended for approximately half an hour after a drone was spotted. The infrastructure itself remained undamaged, but operations did not. At the moment the decision had to be made, however, nobody knew whether it was an unauthorised recreational flight, an accident or a deliberate test of response times. Until the purpose of the flight is known, the risk cannot be ruled out. And this uncertainty is at the heart of the problem. Restricting operations may be necessary, but it can also trigger a chain of consequences for passengers, suppliers and related services.


The opposite end of the spectrum was illustrated in August 2026, when a drone was detected near Leipzig/Halle Airport and explosives were found associated with it. The same category of technology represented a completely different level of threat, including the possibility of a hybrid dimension.


Comparing these two cases shows that the drone’s location alone is not enough. Its real significance emerges from the context: repeated sightings, the time and location of the incident, the pattern of movement over the site and links to other security events. Individual reports that appear insignificant when viewed separately may, when assessed together, reveal a pattern – surveillance of a facility, mapping of its operations or testing the response of security personnel.


Slovakia has tested its response in the field


Slovakia is also testing its preparedness in practice. During an exercise in eastern Slovakia in September 2026, scenarios involving the violation of airspace by a drone were also practised.


The value of such exercises, however, lies not only in the technical component. They show how quickly information reaches the people who need it, who assesses the situation, who has the authority to make a decision and how the different organisations coordinate their response. This is usually where the difference between a plan in a file and actual preparedness becomes visible: if an employee does not know whom to report suspicious activity to, or if decision-making authority is spread across several people or organisations, even high-quality detection technology loses much of its value.


Four questions to answer before an incident


Preparedness does not start with buying sensors. It starts with understanding your own facility, its vulnerabilities and the consequences that a disruption could have. In practice, four areas are particularly important:


  • Vulnerable points. Which parts of the site, technological nodes or activities could be threatened through surveillance or intervention from above? Particular attention should be paid to locations where even a short-term disruption could affect the provision of an essential service.


  • Incident response. Who receives the report, who assesses the situation and who decides whether to restrict operations or call in the relevant authorities? The procedure must be usable even by an employee experiencing such an incident for the first time, and it must be accessible outside normal working hours.


  • Recording and sharing information. How does information reach management, security personnel and the relevant authorities? Records should be kept in a way that makes it possible to compare repeated incidents over time. Without this, patterns of behaviour cannot be identified.


  • Continuity of operations. What happens if a particular activity has to be temporarily restricted? Is there an alternative operating mode, and do employees know how to activate it without waiting for instructions from senior management?


None of these questions requires a major investment. Clear responsibilities, effective reporting procedures and regular testing of response processes will often improve preparedness more than new hardware.


Detection and intervention are not the same thing


Detection systems can identify the presence of a drone and track its flight path. They generally cannot reliably determine the purpose of the flight or identify the operator – yet this is precisely the information decision-makers need. Detecting a drone alone therefore does not answer the question of what action should be taken.


It is equally important to distinguish between three different tasks: detecting, assessing the level of risk and intervening. Disabling or disrupting a drone is subject to legal and security restrictions and, in most cases, is not within the authority of the facility operator. The choice of a technical solution should therefore be based on the specific risks, the characteristics of the site and the actual possibilities for coordination with the relevant authorities. What makes sense at an airport may not be proportionate for a water facility or a large industrial site.


The first minutes matter


"The biggest problem may not be the drone itself, but the time we have to make a decision. If we cannot quickly assess what is happening and who needs to respond, even a minor incident can have unnecessarily serious consequences,” says Tibor Straka, President of the Critical Infrastructure Association of the Slovak Republic.


This capability is built before an incident, not during it. In practice, it can be summarised in four steps that every critical entity should define down to specific names and phone numbers:


  • Detect: what is happening, where the drone is and how it is moving;
  • Assess: whether it may pose a risk and what its possible target could be;
  • Respond: who takes action and what measures are legally and practically possible at that moment;
  • Maintain operations: how to minimise the impact of the incident on the provision of the essential service.


Underlying all of this is the ability to share information with the police, security authorities and other operators. Without this, every sighting remains an isolated piece of information.


Drones can also provide protection


Drones are not only a risk. They have proven useful for border monitoring, the inspection of large sites and construction projects, search and rescue operations and emergency response – precisely the types of activities that can help protect critical infrastructure.


What matters is not simply that a drone is present, but who is operating it, for what purpose and whether its flight is consistent with the applicable rules.


Detection is not the end of the incident



A drone incident does not necessarily mean an attack or damage. It may, however, be the first indication that someone is observing a facility, testing its response or looking for a way to disrupt its operations.


For a critical entity, it is therefore not enough simply to detect a drone. It must be able to assess what its presence may mean, determine how to respond and, at the same time, maintain the provision of the essential service – particularly at a time when the European framework for this area is taking increasingly concrete shape.


7. októbra 2026
Dron nad elektrárňou, letiskom alebo vodárenským objektom nemusí nič poškodiť, aby narušil jeho fungovanie. Stačí, že sa objaví v nesprávnom čase na nesprávnom mieste a kritický subjekt nevie, čo tam robí. Práve preto sa pozornosť v Európe presúva od samotných technológií na zneškodnenie dronov k niečomu menej viditeľnému: k schopnosti kritických subjektov incident včas zachytiť, správne vyhodnotiť a zvládnuť bez zbytočných strát.
2. októbra 2026
A series of expert articles by the Critical Infrastructure Association of the Slovak Republic on essential services under Annex No. 1 to Act No. 367/2024 Coll. on Critical Infrastructure
2. októbra 2026
Séria odborných článkov Asociácie kritickej infraštruktúry Slovenskej republiky o základných službách podľa prílohy č. 1 zákona č. 367/2024 Z. z. o kritickej infraštruktúre
29. septembra 2026
The incident at the primary school in Staškov brings back a topic that deserves continuous attention, not just attention in the aftermath of an incident. The protection of soft targets should form part of a systematic security policy, with clearly defined measures, responsibilities and preparedness for various types of threats.
29. septembra 2026
Udalosť v základnej škole v Staškove pripomína tému, ktorá si zaslúži pozornosť priebežne, nie až po incidente. Ochrana mäkkých cieľov by mala byť súčasťou systematickej bezpečnostnej politiky, s jasne nastavenými opatreniami, zodpovednosťami a pripravenosťou na rôzne typy hrozieb.
24. septembra 2026
We are continuing the series of expert articles by the Critical Infrastructure Association of the Slovak Republic, in which we gradually introduce the individual essential services listed in Annex No. 1 to Act No. 367/2024 Coll. on Critical Infrastructure. Having covered the operation of pipelines for the transport of crude oil and motor fuels, today we move one step upstream to a service that stands at the very beginning of the entire oil chain: crude oil extraction.
24. septembra 2026
Pokračujeme v sérii odborných článkov Asociácie kritickej infraštruktúry Slovenskej republiky, v ktorej postupne predstavujeme jednotlivé základné služby uvedené v prílohe č. 1 zákona č. 367/2024 Z. z. o kritickej infraštruktúre. Po tom, ako sme sa venovali prevádzkovaniu potrubí na prepravu ropy a pohonných látok, sa dnes posúvame o krok proti prúdu k službe, ktorá stojí úplne na začiatku celého ropného reťazca: ťažbe ropy.
21. septembra 2026
On 16 September 2026, a test carried out in Norway demonstrated a new dimension of satellite navigation security. Europe’s Galileo system was tested under so-called spoofing conditions — a situation in which a receiver is fed a fake signal and may therefore receive incorrect information about its position.
21. septembra 2026
16. septembra 2026 sa v Nórsku uskutočnil test, ktorý ukázal nový rozmer bezpečnosti satelitnej navigácie. Európsky systém Galileo bol testovaný v podmienkach tzv. Spoofingu, teda situácie, pri ktorej je prijímaču podstrčený falošný signál a ten môže dostať nesprávnu informáciu o svojej polohe.
14. septembra 2026
The Critical Infrastructure Association of the Slovak Republic continues its series of articles focusing on basic services under Act No. 367/2024 Coll. on Critical Infrastructure. This time, we look at a basic service that remains largely invisible to the public, yet its disruption can have an immediate impact on transport, industry and the wider economy – the operation of pipelines for the transportation of crude oil and fuels.