A drone, probably carrying explosives, slipped into Lithuania from Belarus in the middle of the night. NATO jets shot it down over the countryside, the first such downing in the country’s history. A senior adviser at Lithuania’s crisis centre explains what the incident exposed and why Russia profits from fear.
Two Italian Eurofighters intercepted the drone shortly after midnight on 15 September. The jets had scrambled from Šiauliai air base, where they serve on NATO’s air policing mission. The incident put the Alliance’s eastern flank back in the spotlight. Two weeks later, NATO Secretary General Mark Rutte described the downing as a case of “collective defence in action”. He also announced further efforts to strengthen the Alliance’s air defence and counter-drone capabilities.
Lithuania already hosts a multinational NATO presence and the Alliance’s air policing mission. Yet the episode highlights the growing security pressures facing the Baltic region, from airspace incursions and drones to broader hybrid threats. That is the view of Darius Buta, chief adviser at Lithuania’s National Crisis Management Centre, who spoke to EU Perspectives.
What are the main security and crisis-management challenges currently facing Lithuania?
The National Crisis Management Centre deals with a broad spectrum of risks to Lithuania’s national security and resilience. These can be grouped into three main categories. The first comprises natural hazards, including severe storms and floods. The second covers emergencies resulting from accidents or technological failures, such as major fires and industrial or infrastructure incidents. The third concerns deliberate hostile activity, including sabotage, cyberattacks, disinformation, and other hybrid operations.
Within the third category, the most significant challenge is the sustained threat posed by Russia’s hostile policy towards the West, its war of aggression against Ukraine, and the intensification of sabotage and other disruptive activities targeting infrastructure across Europe. These threats are increasingly interconnected: a physical incident may be accompanied by cyber activity, information manipulation, or attempts to undermine confidence in public institutions. Our task is therefore not only to respond to individual incidents, but also to maintain a comprehensive threat picture, assess potential consequences, coordinate preparedness, and, when necessary, support a whole-of-government response.
What have recent drone incidents taught Lithuania about its vulnerabilities?
The lessons can be grouped into three closely connected areas. First, the incidents have underscored the need for a layered and integrated approach to air defence. This is not solely a military issue. It also concerns the protection of critical infrastructure, civilian facilities, and the continuity of essential services. Effective protection requires timely detection, reliable identification, rapid information-sharing, and a clearly defined response chain.
Second, inter-agency coordination is critical. The challenge is not limited to the procurement of equipment. Institutions must also develop common operating procedures, clarify responsibilities, and regularly test decision-making and communication arrangements. The National Crisis Management Centre helps coordinate this work, while procedures and capabilities are tested through national and international exercises.
Third, society has an important role. Lithuania is refining its public-warning arrangements, including cell-broadcast and SMS-based alerts, but a warning is effective only if people understand what it means and know how to respond. Authorities therefore need to communicate continuously about drone-related risks, appropriate conduct during an incident, and the precautions to take when a suspicious object is found. Reports from members of the public can support faster detection and verification, but people should never approach, touch, or attempt to move a fallen object.
Do you see Russia exploiting drones as a tool of provocation or hybrid warfare?
Yes. Drones can serve several purposes in a hybrid campaign: they can test detection and response systems, create uncertainty, disrupt civilian activity, threaten critical infrastructure, and generate material for information operations. At the same time, each incident must be assessed on the basis of verified evidence. The origin, trajectory, and intent of an unmanned aircraft should not be presumed before the competent authorities have completed their assessment.
Russia is already exploiting drone-related incidents in the information domain. — Darius Buta, chief adviser at Lithuania’s National Crisis Management Centre
Russia is already exploiting drone-related incidents in the information domain. A recurring narrative falsely alleges that Lithuania and other Baltic states allow Ukrainian forces to use their territory or airspace for strikes against targets in Russia. This narrative seeks to shift responsibility for the consequences of Russia’s war against Ukraine, portray NATO Allies as direct participants in the conflict, and create friction between partners.
We cannot exclude other hostile actions intended to destabilise the region or provoke disagreement among Allies. Drones may also be used to damage critical infrastructure or disrupt essential services. Lithuania is therefore strengthening the resilience and protection of critical infrastructure and intensifying coordination among national authorities and Allied partners. The key principle is to combine vigilance and preparedness with evidence-based public communication, avoiding both complacency and premature attribution.
Beyond drones, which Russian hybrid threats concern you most?
Russia employs a broad hybrid toolbox, ranging from information manipulation, cyber operations, and economic coercion to sabotage, intimidation, and other forms of covert or deniable activity. The most serious concern is not any single instrument in isolation, but the coordinated use of several instruments to exploit vulnerabilities, disrupt essential services, influence political decision-making, and weaken public trust.
A central objective of Kremlin communication is to create the impression that Russia is omnipotent, that Western societies are paralysed by fear, and that support for Ukraine is unsustainable. — Darius Buta, chief adviser at Lithuania’s National Crisis Management Centre
At the same time, these activities should be assessed soberly. A central objective of Kremlin communication is to create the impression that Russia is omnipotent, that Western societies are paralysed by fear, and that support for Ukraine is unsustainable. Overstating the effectiveness of Russian operations can inadvertently reinforce that narrative. The appropriate response is therefore to identify threats early, strengthen resilience, investigate and disrupt hostile activity, communicate verified facts, and demonstrate that institutions and society can continue to function under pressure.
What should NATO’s role be in protecting Lithuania against these threats? What more should the EU do to strengthen crisis preparedness and resilience?
Hybrid threats against Lithuania are part of Russia’s broader hostile activity against the West. NATO and the European Union have different but complementary instruments, and effective deterrence requires them to be coordinated and mutually reinforcing.
NATO’s primary role is deterrence and collective defence. Eastern Sentry strengthens vigilance and the coordination of Allied capabilities across the eastern flank, while Baltic Sentry reinforces the protection of critical undersea infrastructure in the Baltic Sea.
NATO should continue to strengthen integrated air and missile defence, accelerate the development and deployment of interoperable counter-drone capabilities, improve information-sharing, and support regular exercises that test military and civilian decision-making under hybrid pressure. NATO’s deployment of a Counter-Hybrid Support Team to Lithuania in early 2026, in response to security challenges linked to smuggling balloons from Belarus, was a practical example of targeted Allied support.
The EU can add particular value through its regulatory, financial, civil-protection, and sanctions instruments. It should further strengthen the resilience of critical entities and essential services, support cross-border preparedness, improve civil-military cooperation, and expand exercises involving civilian authorities, infrastructure operators, and the private sector. EU funding can also help member states address capability gaps in areas such as detection, secure communications, emergency warning, and infrastructure protection.
Ultimately, resilience depends on connecting national preparedness with NATO’s defence capabilities and the EU’s civilian and regulatory tools. Common threat assessments, compatible procedures, regular exercises, and coordinated public communication are essential if Europe is to respond effectively to complex, cross-sectoral threats.