Summary
- The partnership was announced during UK–Germany talks in Berlin on 8 October.
- The governments committed to monitoring, mitigating and countering hybrid threats.
- Operational measures, funding and delivery milestones have not been fully specified.
The British and German governments have agreed to expand cooperation against cyberattacks, sabotage and other hybrid threats, placing protection of critical infrastructure alongside their broader security and economic relationship.
The counter-hybrid partnership was announced during talks in Berlin on 8 October between UK Prime Minister Andy Burnham and German Chancellor Friedrich Merz. A UK government statement says the countries will work together to improve their ability to monitor, mitigate and respond to hostile activity that crosses traditional boundaries between cyber operations and physical interference.
The joint statement identifies democratic and societal resilience as well as critical national infrastructure. Those priorities acknowledge that campaigns may combine interference with communications networks, disruption of essential services, coercion, disinformation and direct sabotage. The documents do not, however, identify a single dedicated operational command or set out a comprehensive new funding allocation for the cyber component.
Both governments have previously warned about hostile state activity affecting European infrastructure. The new agreement creates an additional bilateral framework, but its operational significance will depend on how intelligence is exchanged, how incidents are escalated and whether public and private infrastructure operators receive common guidance.
Cybersecurity responsibilities are distributed across agencies, regulators, service providers and operators, which can make incidents involving cross-border infrastructure difficult to coordinate. Telecommunications routes, energy interconnections and transport networks may span multiple jurisdictions even when the immediate breach is detected within one country.
The governments are also discussing cooperation on emerging technologies, industrial development and space capabilities. Those subjects have their own objectives and should not be presented as measures already delivered under the counter-hybrid partnership. The wider relationship provides context for the security agreement rather than proof of specific cyber outcomes.
The publication of a joint statement establishes political commitment, but it does not yet show how success will be measured. Evidence of implementation would include identified responsible agencies, working arrangements for incident cooperation and milestones for assessing infrastructure preparedness.
London and Berlin have framed the partnership as an answer to growing shared threats. The next stage will be translating that declaration into operational mechanisms that institutions and infrastructure operators can use during an incident.
The two countries already participate in NATO and a range of European security cooperation arrangements. A bilateral initiative can therefore add operational value only to the extent that it defines mechanisms for sharing intelligence, coordinating incident response or protecting infrastructure that falls across borders. The published commitments need to be distinguished from capabilities that are already in place.
Cyber intrusions and physical sabotage can also intersect without being the same kind of incident. Disrupting a cable or energy installation may have immediate physical effects; compromising the digital systems used to manage a service can instead damage confidentiality, integrity or availability. Coordination between authorities responsible for these domains becomes more complex when evidence crosses technical and national boundaries.
Germany is an important manufacturing, logistics and energy partner for the United Kingdom. Disruption to transport infrastructure or a major supplier can affect organisations on both sides even when only one country hosts the targeted facility. The policy therefore has potential relevance beyond the government bodies directly involved, although no particular private-sector reporting duty should be inferred without published implementing measures.
International attribution presents a related challenge. Security agencies may share assessments of hostile activity while differing in which intelligence they can publish. Jointly issued information can strengthen the public technical record, but attribution statements remain assessments rather than evidence that a court has determined responsibility for individual operations.
Much will depend on follow-through: designated points of contact, exercises, escalation protocols and a method for turning technical warnings into protective actions. These are practical elements of interstate cooperation, not commitments that can be assumed from the announcement alone. The government documents provide a starting framework; evidence of implementation will emerge as specific programmes are described.





