Not Every Drone Is an Attack. How Can You Recognise the One That Might Be?
A drone flying over a power plant, airport or water facility does not have to cause any physical damage to disrupt its operations. It may be enough for it to appear in the wrong place at the wrong time, while the critical entity has no idea what it is doing there. This is precisely why attention in Europe is shifting from technologies designed to neutralise drones to something less visible: the ability of critical entities to detect an incident in time, assess it correctly and manage it without unnecessary losses.
What exactly has the EU adopted?
The European Commission has moved from declarations to concrete documents and deadlines. In October 2025, it presented the Defence Readiness Roadmap 2030, which includes two flagship initiatives – the European Drone Defence Initiative, focused on counter-drone defence, and Eastern Flank Watch, aimed at strengthening surveillance of the eastern flank. The counter-drone initiative is expected to have initial operational capacity by the end of 2026 and to be fully operational by the end of 2027.
This was followed by the EU Action Plan on Drone and Counter-Drone Security, presented on 11 February 2026. It is built around four priorities: preparedness, detection capabilities, response coordination and defence readiness. The Commission also proposed that Member States appoint national drone security coordinators. The plan explicitly addresses civilian internal security and the protection of sensitive sites, including the EASA framework with protocols and maps of restricted zones, as well as the development of a system for managing drone traffic at low altitudes through U-Space.
For critical infrastructure operators, the practical conclusion is clear: the European framework is being developed now, and the national requirements that emerge from it will ultimately affect individual sites and their security management.
When a drone brings an airport to a standstill
The fact that a drone does not have to cause physical damage to create a serious problem has been demonstrated by incidents at European airports.
In September 2026, aircraft movements at Brussels Airport were suspended for approximately half an hour after a drone was spotted. The infrastructure itself remained undamaged, but operations did not. At the moment the decision had to be made, however, nobody knew whether it was an unauthorised recreational flight, an accident or a deliberate test of response times. Until the purpose of the flight is known, the risk cannot be ruled out. And this uncertainty is at the heart of the problem. Restricting operations may be necessary, but it can also trigger a chain of consequences for passengers, suppliers and related services.
The opposite end of the spectrum was illustrated in August 2026, when a drone was detected near Leipzig/Halle Airport and explosives were found associated with it. The same category of technology represented a completely different level of threat, including the possibility of a hybrid dimension.
Comparing these two cases shows that the drone’s location alone is not enough. Its real significance emerges from the context: repeated sightings, the time and location of the incident, the pattern of movement over the site and links to other security events. Individual reports that appear insignificant when viewed separately may, when assessed together, reveal a pattern – surveillance of a facility, mapping of its operations or testing the response of security personnel.
Slovakia has tested its response in the field
Slovakia is also testing its preparedness in practice. During an exercise in eastern Slovakia in September 2026, scenarios involving the violation of airspace by a drone were also practised.
The value of such exercises, however, lies not only in the technical component. They show how quickly information reaches the people who need it, who assesses the situation, who has the authority to make a decision and how the different organisations coordinate their response. This is usually where the difference between a plan in a file and actual preparedness becomes visible: if an employee does not know whom to report suspicious activity to, or if decision-making authority is spread across several people or organisations, even high-quality detection technology loses much of its value.
Four questions to answer before an incident
Preparedness does not start with buying sensors. It starts with understanding your own facility, its vulnerabilities and the consequences that a disruption could have. In practice, four areas are particularly important:
- Vulnerable points. Which parts of the site, technological nodes or activities could be threatened through surveillance or intervention from above? Particular attention should be paid to locations where even a short-term disruption could affect the provision of an essential service.
- Incident response. Who receives the report, who assesses the situation and who decides whether to restrict operations or call in the relevant authorities? The procedure must be usable even by an employee experiencing such an incident for the first time, and it must be accessible outside normal working hours.
- Recording and sharing information. How does information reach management, security personnel and the relevant authorities? Records should be kept in a way that makes it possible to compare repeated incidents over time. Without this, patterns of behaviour cannot be identified.
- Continuity of operations. What happens if a particular activity has to be temporarily restricted? Is there an alternative operating mode, and do employees know how to activate it without waiting for instructions from senior management?
None of these questions requires a major investment. Clear responsibilities, effective reporting procedures and regular testing of response processes will often improve preparedness more than new hardware.
Detection and intervention are not the same thing
Detection systems can identify the presence of a drone and track its flight path. They generally cannot reliably determine the purpose of the flight or identify the operator – yet this is precisely the information decision-makers need. Detecting a drone alone therefore does not answer the question of what action should be taken.
It is equally important to distinguish between three different tasks: detecting, assessing the level of risk and intervening. Disabling or disrupting a drone is subject to legal and security restrictions and, in most cases, is not within the authority of the facility operator. The choice of a technical solution should therefore be based on the specific risks, the characteristics of the site and the actual possibilities for coordination with the relevant authorities. What makes sense at an airport may not be proportionate for a water facility or a large industrial site.
The first minutes matter
"The biggest problem may not be the drone itself, but the time we have to make a decision. If we cannot quickly assess what is happening and who needs to respond, even a minor incident can have unnecessarily serious consequences,” says Tibor Straka, President of the Critical Infrastructure Association of the Slovak Republic.
This capability is built before an incident, not during it. In practice, it can be summarised in four steps that every critical entity should define down to specific names and phone numbers:
- Detect: what is happening, where the drone is and how it is moving;
- Assess: whether it may pose a risk and what its possible target could be;
- Respond: who takes action and what measures are legally and practically possible at that moment;
- Maintain operations: how to minimise the impact of the incident on the provision of the essential service.
Underlying all of this is the ability to share information with the police, security authorities and other operators. Without this, every sighting remains an isolated piece of information.
Drones can also provide protection
Drones are not only a risk. They have proven useful for border monitoring, the inspection of large sites and construction projects, search and rescue operations and emergency response – precisely the types of activities that can help protect critical infrastructure.
What matters is not simply that a drone is present, but who is operating it, for what purpose and whether its flight is consistent with the applicable rules.
Detection is not the end of the incident
A drone incident does not necessarily mean an attack or damage. It may, however, be the first indication that someone is observing a facility, testing its response or looking for a way to disrupt its operations.
For a critical entity, it is therefore not enough simply to detect a drone. It must be able to assess what its presence may mean, determine how to respond and, at the same time, maintain the provision of the essential service – particularly at a time when the European framework for this area is taking increasingly concrete shape.







