This website uses cookies

Read our Privacy policy and Terms of use for more information.

On 1 September 2026 the transmission operator 50Hertz said that the general electricity supply had at no time been impaired. The next day Amprion, the transmission operator in the Rhineland, said the same of an incident near one of its own installations. Just under eight months earlier, on a January morning in Berlin, a distribution operator could say only that it was still unclear when power would be restored. The two substation attacks came about 12 hours apart on 1 September, improvised explosive devices at a substation in Brandenburg in the morning and, that evening, a short circuit at Bergheim near Cologne that investigators put down to a deliberate act. A suspect was arrested on 8 September. Weeks earlier, data had flowed out of the Berlin state government's own network in a cyber attack, and when an extortion deadline expired the material was released publicly.

From these events, we find that an operator, a city administrator, and a municipal authority are all committed to one of three outcomes before anything happens. Reroute, rebuild, or expose. Which of the three a service faces is not a reading of how bad the attack was. This brief covers how long a service stays down and what decided that. It does not cover who attacked, what the damage cost, or whether any of it could have been stopped on the day. This edition follows three countries, three kinds of attack, and three different recovery timelines. The “clocks”, as we call them here, measure how long it takes to restore critical services to an affected population. None of these outcomes was determined on the day of the event. Each was decided in the years before, in the mundane decisions of services, specifications, and contracts.

What we're reviewing in this issue:

  1. What set the recovery clock in the attacks on European infrastructure since 2021, from two substations in one day to a capital city that lost control of its data, reviewed case by case for how services were restored.

  2. The Berlin data theft, where there was no recovery clock at all, because the timeline and publication belonged to the attacker, not the city.

  3. Why the decision logic for who is inside the protection regime actually measures something else, where its requirement came from, and the three-way decision a community makes long before an attack arrives.

logo

This analysis continues for paid subscribers.

Intelligence by Crisis Lab delivers a focused analytical brief, companion toolkit, and audio briefing every two weeks. Built for professionals who manage crisis, security, and resilience.

Get the Full Brief