Security is often understood as the absence of crises. Yet this definition is incomplete. The absence of a crisis is not the same as security, because the lack of a visible threat does not mean that threats have disappeared. In many cases, the greatest vulnerabilities accumulate precisely during periods when states and societies feel secure. Stability, when it ceases to be viewed as a temporary political outcome and begins to be treated as a natural and permanent condition, can dull threat perception, slow institutional adaptation, and distort strategic priorities. The experience of NATO and the European Union over the past three decades provides a valuable case study of how this dynamic unfolds. Today, NATO’s approach to resilience, cyber defence, and critical infrastructure protection demonstrates that security is not produced solely at the front line. It is generated through the functioning of society as a whole.

The issue, therefore, is not whether stability is desirable. Stability is undoubtedly a positive condition. The danger lies in believing that it possesses an almost timeless permanence and can sustain itself indefinitely. Such assumptions encourage states to interpret future threats through the categories of the past. The security studies literature has long shown that threat perception, despite being one of the field’s central concepts, is often shaped by ambiguous definitions, psychological assumptions, and untested beliefs. Decision-makers operating under conditions of uncertainty and information overload frequently rely on analogies, cognitive shortcuts, and framing effects when assessing risks. Institutions, meanwhile, tend to respond in ways that preserve their existing structures and responsibilities. For this reason, periods of stability can become not only periods of comfort, but also periods of strategic blindness.

Historical background

A look at Europe’s strategic discourse after the Cold War reveals that a sense of security relief became embedded not only in practice but also at the conceptual level. Javier Solana’s 2003 strategy paper, A Secure Europe in a Better World, described Europe as more prosperous, secure, and free than at any other point in its history. The document framed this condition as a historical achievement and reflected the broader optimism of the period.

At the same time, the paper did not ignore the existence of threats. It acknowledged that conflict had not entirely disappeared from the Balkans, identified energy dependence as a growing concern, and noted that emerging threats were becoming more diffuse, less visible, and harder to predict than traditional strategic challenges. It also explicitly argued that these threats could not be addressed through military means alone. Yet despite these observations, the overall tone of the document was not that of a continent facing an imminent security crisis. Rather, it reflected a Europe living in an era of manageable risks. In other words, Europe recognised the risks it faced, but it did not place them at the top of its hierarchy of strategic priorities.

A similar mindset can be found in NATO’s 2010 Strategic Concept. The document famously stated that “Today, the Euro-Atlantic area is at peace, and the threat of a conventional attack against NATO territory is low.” Few sentences capture the strategic climate of that period more accurately. The same document also warned about the growing frequency and sophistication of cyber attacks and highlighted the damage they could inflict on governments, economies, transportation systems, and critical infrastructure.

The problem, therefore, was not that threats went unnoticed. Policymakers were aware of many of the challenges that would later become central security concerns. The problem was that these threats were treated as peripheral rather than fundamental. Put differently, Europe and NATO did not fail because they overlooked danger altogether; they failed because they misjudged its place within the broader hierarchy of threats.

Psychology and institutional behaviour

This failure is not merely geopolitical; it is also cognitive and institutional. Recent scholarship on threat perception points out that while the concept of “threat” is frequently used in international relations, there is often considerable ambiguity regarding what constitutes an actual danger, what represents a signal of hostile intent, and what is simply uncertainty. Behavioural approaches further suggest that decision-makers do not process information in a fully rational or neutral manner. Instead, they rely on heuristics, analogies, framing effects, and status quo biases when interpreting complex environments. Beliefs often emerge not from an objective assessment of available evidence but from the way existing mental frameworks categorise and interpret new information.

As a result, political actors frequently understand new challenges through old analogies. They tend to devote disproportionate attention to threats that are visible, measurable, and familiar, while giving less priority to diffuse, low-intensity, and transnational forms of hybrid pressure. The danger is not necessarily that emerging threats remain invisible. Rather, they are often recognised but placed outside the core focus of strategic attention.

Institutional dynamics reinforce these cognitive tendencies. Research on how international organisations and large bureaucracies respond to external pressure generally identifies three broad patterns of behaviour: inertia, adaptation, and resilience-building. In practice, institutions often either delay meaningful action, pursue limited adjustments to maintain support and legitimacy, or develop more durable capabilities after a crisis has exposed their weaknesses.

This framework can be applied to both NATO and European institutions. Areas such as defence planning, procurement, force structure, and strategic culture are inherently slow to change. Moreover, the literature on defence innovation consistently shows that perceptions of threat and vulnerability are among the strongest drivers of adaptation. Yet meaningful adaptation often accelerates only after an adversary’s capabilities become clearly visible. Institutional failure, therefore, rarely stems from complete ignorance. More often, it results from an inability to assign the right priorities at the right time. The problem is not that institutions know nothing, but that they fail to act on what they already know before circumstances force them to do so.

The illusion of stability in Europe

Europe provides a particularly clear illustration of this dynamic. In the post-Cold War era, economic interdependence, institutional integration, and the idea of a rules-based order came to be seen as the foundations of European security. This approach produced undeniable successes. The likelihood of war within the continent declined dramatically, and successive rounds of enlargement helped create a broader zone of stability.

Yet this very success also encouraged a dangerous assumption: that security was no longer something that needed to be actively maintained but rather a condition that could simply be inherited. European relations with Russia before 2014 offer a complex but instructive example. Russia was viewed not only as a potential strategic competitor but also as an energy supplier, a trading partner, and an integrated part of the wider European economic landscape. This perspective was not irrational. However, it tended to place economic functionality above long-term security concerns.

The annexation of Crimea transformed vulnerabilities that had previously been treated as largely theoretical into strategic realities. One of the clearest indicators of this mindset can be found in defence spending patterns. According to data from the European Defence Agency, defence expenditures among EDA member states declined by 10.7 per cent in real terms between 2005 and 2015, despite a modest nominal increase over the same period. The decline was particularly pronounced between the spending peak of 2007 and the low point reached in 2013. NATO data further show that in 2014 only three Allies met the Alliance’s benchmark of spending 2 per cent of GDP on defence, while the combined defence investment of European Allies and Canada stood at just 1.4 per cent of their collective GDP.

These figures reflected more than budgetary preferences; they reflected how threats were prioritised. The central mistake was not that Europe valued peace. The mistake was the assumption that peace would continue automatically, at little cost, and largely independent of external shocks. Stability came to be viewed not as a condition requiring constant maintenance but as a permanent feature of the strategic environment. History would soon demonstrate otherwise.

Hybrid blind spots

The reduction in defence spending became even more consequential when combined with growing energy dependence. According to Eurostat, the European Union's overall energy import dependency stood at 56 per cent in 2021, while its dependence on imported natural gas reached 83 per cent. During the same year, approximately 44 per cent of the EU’s natural gas imports originated from Russia, a figure that the European Commission similarly estimated at around 45 per cent of total gas imports. In practical terms, Europe was not merely an economic area dependent on imported energy; it was also embedded in a supply relationship capable of constraining its strategic autonomy.

Following Russia’s full-scale invasion of Ukraine, this dependence was reduced at remarkable speed. By 2025, the share of Russian gas in total EU gas imports had fallen to roughly 12 per cent. Yet this achievement should not be interpreted as evidence that the problem had been addressed in advance. Rather, it demonstrates how a structural vulnerability was managed only after a crisis had already emerged and at considerable economic and political cost.

A similar gap in prioritisation can be observed in the field of hybrid threats. Beginning in 2016, European institutions adopted a more explicit language regarding the challenge. The 2018 Joint Communication of the European Commission and the European External Action Service argued that hybrid activities undermine public trust while targeting government institutions and the fundamental values of democratic societies. The 2021 progress report further described hybrid threats as one of the most complex challenges facing both the European Union and its member states, emphasising that effective responses require an approach that extends beyond government institutions and encompasses society as a whole.

NATO has reached similar conclusions. The Alliance defines hybrid methods as activities that blur the distinction between war and peace, combining tools such as cyber attacks, disinformation campaigns, economic coercion, and irregular armed actors. What is particularly striking is that NATO had already warned in its 2010 Strategic Concept that cyber attacks could damage critical infrastructure, government systems, and supply networks. The threats themselves, therefore, did not suddenly appear. What changed was their form. Traditional military dangers did not disappear; they evolved into challenges increasingly focused on exploiting systemic vulnerabilities rather than conducting direct conventional attacks.

This distinction matters. The problem was never the absence of warning signs. Many of the risks that dominate contemporary security debates had already been identified years earlier. The real blind spot lay in the assumption that these emerging vulnerabilities could remain secondary concerns while the broader security environment stayed fundamentally stable. As long as stability appeared intact, threats targeting the resilience of societies, institutions, and infrastructure were rarely treated with the same urgency as conventional military risks.

NATO’s adaptation process and contemporary threats

This does not mean that NATO fundamentally misidentified the threat. A more accurate interpretation is that the alliance gradually improved its understanding of emerging risks but often accelerated institutional adaptation only after major events had already occurred. NATO’s decision at the 2014 Wales Summit to reverse the trend of declining defence spending was not accidental. The Readiness Action Plan adopted that same year became the most significant reinforcement of NATO’s deterrence and defence posture since the end of the Cold War. The package included assurance measures for Allies on the eastern flank, adjustments to force structure, the expansion of the NATO Response Force, and the creation of the Very High Readiness Joint Task Force. It marked the first major strategic awakening of the post-Cold War era, the moment when threat perception shifted back toward the kinetic dimension of security.

The deeper transformation, however, became evident after 2022 at the conceptual level. NATO’s 2022 Strategic Concept openly stated that “the Euro-Atlantic area is not at peace.” The document describes the security environment as one characterised by strategic competition, pervasive instability, and recurring shocks. Hybrid tactics, disinformation, manipulation of energy supplies, and economic coercion are no longer treated as secondary concerns but as central elements of the contemporary security landscape.

The Madrid Summit Declaration reinforced this shift by defining resilience as both a national responsibility and a collective commitment. Allies pledged to accelerate adaptation against cyber and hybrid threats, strengthen energy security, and apply NATO’s 360-degree approach across all domains. This evolution is significant because it demonstrates how the Alliance has reconnected its traditional understanding of collective defence with issues such as civilian preparedness, energy security, technological resilience, and the information environment.

Current threat assessments further confirm this transformation. NATO now defines cyber defence as a core component of deterrence and defence, has recognised cyberspace as an operational domain since 2016, and decided at the 2024 Washington Summit to establish the Integrated Cyber Defence Centre. The European External Action Service has likewise spent the past decade developing capabilities to counter foreign information manipulation and interference, explicitly identifying such activities as efforts to increase polarisation, undermine democratic processes, and erode public trust. At the same time, the European Union’s Critical Entities Resilience Directive, which entered into force in 2023, aims to strengthen the resilience of sectors including energy, transportation, healthcare, banking, digital infrastructure, and public administration against sabotage, terrorism, insider threats, and other major disruptions.

Taken together, these developments point to a broader shift in how security is understood. Security is no longer defined solely by the protection of territorial borders. It increasingly depends on the resilience of networks, institutions, information systems, critical infrastructure, and the continuity of social and economic life.

The European experience suggests that the real danger lies not in stability itself, but in the belief that stability is permanent. During periods of crisis, states often become more alert, innovative, and cautious. Extended periods of calm, by contrast, can dull threat perception and reduce the sense of urgency needed for adaptation. Security policy should therefore not be built on the assumption that threats will disappear but on the expectation that they will evolve.

This lesson extends well beyond Europe. In today’s international environment, conventional deterrence remains necessary, but it is no longer sufficient on its own. Competitors do not exert pressure solely at borders. They target energy flows, public opinion, electoral processes, digital networks, critical infrastructure, and institutional trust.

The policy implication is not alarmism. Increasing defence spending may be necessary, but it is not a strategy by itself. More important is the development of a more flexible and interdisciplinary understanding of threats, one that limits excessive reliance on analogies and status quo assumptions in decision-making. It requires sustained investment in energy diversification, cyber defence, critical infrastructure protection, civilian preparedness, institutional learning, and information integrity. European institutions themselves have acknowledged for years that contemporary threats cannot be addressed through military instruments alone.

What is needed, therefore, is not a louder language of war but a stronger capacity for adaptation. Not a narrower definition of threats but a more flexible security mindset. Not greater panic, but greater resilience.

One final observation is worth emphasising. The period in which a state feels most secure may sometimes be the very period in which the foundations of future crises are being laid.