Help us fight against disinformation

M

Take action to stand for a democratic, inclusive Europe, and against disinformation and hate. We rely on donations for our campaigns & actions, and to develop the tech tools needed for a citizen-driven democracy. 
For long-term impact, consider making a monthly contribution, to shape the future of Europe together. 

DISRUPT White Paper

Saman Nazari, Alliance4Europe
Dr. Lumi Sarvela, Alliance4Europe

Main Contributors:

Angela Gramada, Association of Experts for Security and Global Affairs (ESGA)
Gloria Trifonova, Center for the Study of Democracy (CSD)
Jakub Szymik, CEE Digital Democracy Watch (CEEDDW)
Julian Neylan, Alliance4Europe (A4E).
Kristína Šefčíková, Prague Security Studies Institute (PSSI)
Omri Preiss, Alliance4Europe (A4E).
Ondřej Perušič, Prague Security Studies Institute (PSSI)
Pavel Havlicek, Association for International Affairs (AMO)
Rositsa Dzhekova, Center for the Study of Democracy (CSD)
Stepanka Lukesova, Association for International Affairs (AMO)
Sorin Ionita, Expert Forum (EFOR)

Contributing Organisations:
Pravda.PL
FakeNews.PL
NASK
New Data Academy
OpenMinds
Charles University
IICT
Central European Digital Media Observatory
CeMAS, Centre for the Study of Organized Hate
Demagog
Context
Friedrich Naumann Foundation
Casimir Paulaski Foundation
CBZC
LSEG Risk Intelligence,
FEMBLOC,
Indetrics,
Institute of Public Affairs,
VIGILIA,
ITSP Kybernetes
Bulgarian-Romanian Observatory of Digital Media (BROD) – coordinated by the GATE Institute.

Contributing Individuals:
Wojciech Dzięgiel, Casimir Pulaski Foundation
Wywrót, Centralne Biuro Zwalczania Cyberprzestępczości
Vojtěch Kupka, CEDMO & Charles University
Dobromił Wereszczyński, CEE Digital Democracy Watch
Gregor Bauer, CeMAS - Center für Monitoring, Analyse und Strategie
Ammaarah Nilafdeen, Center for the Study of Organized Hate
Natália Sabol Tkáčová, Friedrich Naumann Foundation for Freedom Central Europe
Mateusz Zadroga, Fundacja "Przeciwdziałamy Dezinformacji" - FakeNews.pl
Todor Kiriakov, Identrics
Devora Kotseva, Identrics
Yordan Terziev, IICT-BAS
Sonia Horonziak, Institute of Public Affairs
Mariusz Żabiński, Instytut Technologii Społeczno-Politycznych Kybernetes
Zhanna, Kondzirska, London Stock Exchange Group, Risk Intelligence
Michal Marek, NASK
Nicolae Tibrigan, New Data Academy
Yuliia Dukach, OpenMinds
Julia Mikzińska, Stowarzyszenie Pravda

DISRUPT White Paper

A Whole-of-Society Approach to Defending Democracy Against Influence Operations

 

Read White Paper Here

Access toolkit here.

Influence operations targeting democratic societies have evolved in scale, coordination and strategic sophistication. They constitute a systemic risk to European democratic processes, public trust and societal cohesion, as well as long-term competitiveness and resilience. This threat is increasingly being recognised at both European and national levels, with detection capacity across the Union having significantly improved. However, no overarching coordinated method had yet been developed to systematically disrupt influence operations. 

This white paper provides a first-of-a-kind operational toolkit to disrupt influence operations. The proposed  Disruption Toolkit operationalises a whole-of-society approach, providing:

  1. A Disruption Framework comprising all the actions a practitioner can take to prepare the evidence needed for disruption, the disruption steps available, and steps to mitigate the effect of an influence operation if disruption fails or takes a long time;
  2. Guides and templates for the preparation, disruption, and mitigation measures;
  3. Step-by-step workflows to analyse, disrupt and mitigate six different kinds of influence operations, based on the Disruption Framework. These include coordinated inauthentic behaviour, deepfakes and manipulated content, Impersonation, sanctions circumvention, doxing and gendered smear campaigns targeting political candidates. 
  4. An adaptation of these workflows to the national context of four EU countries;
  5. A digital research infrastructure, the Threat Intelligence Database and Coordination Platform (TRANSCRIPT), to enable the operationalisation of the framework, the aggregation of cases and threat actors’ assets, and the steps that have been taken to disrupt them. 

While the framework was foremost developed to equip non-government actors, it is also a tool to support the work of governments. 

The Framework represents the formalisation of the concrete collective experience of the largest counter-disinformation networks in Europe, involving open source intelligence researchers, fact-checkers, policy-makers, journalists, academics, stratcom professionals, cyber security experts, and national authorities across Europe. 

The framework introduces a lifecycle-based model structured around three phases:

  • Prepare – data collection, documentation, attribution and qualification of an influence operation;
  • Disrupt – who to contact, when and how to disrupt ongoing activities. 
  • Mitigate – mitigating the harm from the operation and building long-term resilience.

This core model can be adapted to different national contexts, in Europe and beyond, by mapping relevant national actors, mandates, capacity, and legal frameworks. The Framework presented in this White Paper has already been localised, through a co-creative process, to the Romanian, Bulgarian, Polish and Czech contexts. 

Practically, the framework enables the creation of national taskforces who have set workflows on how to detect, disrupt, and mitigate influence operations, in collaboration with government agencies. With shared standards, established frameworks, and common tools, these national taskforces can establish a pan-European decentralised web of responders who continuously disrupt threats towards European democracies, while being able to mobilise against regional or global crises. Additionally, the Framework lays the basis for a digital research infrastructure dedicated to data sharing, knowledge aggregation, a best practice repository, and response monitoring. 

The Framework makes the most of what Europe has, because disruption is an immediate need. At the EU level, the framework complements and makes the most of existing legal and resilience instruments, without necessarily requiring further regulatory harmonisation. improving interoperability across Member States. It makes use of existing capabilities by providing the operational sequencing layer required for coordinated incident management under the emerging European Democracy Shield architecture. Embedding the framework logic within cross-border coordination mechanisms would strengthen collective situational awareness and alignment of disruption in multi-state incidents. Crucially, the framework is intended to protect fundamental rights within a democratic system, including the rights to freedom of expression and association. 

The Disruption Toolkit represents a united European solution to a global challenge. It builds on years of theoretical research funded by the Horizon Europe Programme (e.g. the DISARM Framework), as well as on the experience of the Counter Disinformation Network (CDN), the EU-funded European Digital Media Observatory (EDMO) network, the Polish Resilience Council, the Digital Service Act implementation and the Code of Conduct on Disinformation Rapid Response System. 

The Disruption Framework represents a scalable, concrete model to achieve the objectives of the European Democracy Shield and truly protect citizens from influence operations.

Key Takeaways for Decision-Makers

  • By disrupting influence operations, we protect free and democratic discourse, acting on manipulative, inauthentic behaviour and threat actor infrastructure, rather than ever-changing content or narratives. 
  • The gap is operational timing, not capability – Member States already possess detection, regulatory and mitigation capacity. The recurring vulnerability lies in delayed escalation and uncoordinated workflows between detection and disruption.
  • Response and resilience require standardisation, not centralisation. – The framework model (Prepare → Disrupt → Mitigate) sets a basic standard for evidence gathering, analysis and then points towards countermeasures. This improves coordination while fully respecting subsidiarity and national mandates.
  • Early disruption reduces systemic harm – Structured disruption reduces the exposure of citizens to influence operations,   reducing over-reliance on post-impact communication and reputational repair.
  • Whole-of-society capacity can be operationalised – Civil society, media and independent monitoring actors frequently detect incidents first. Structured workflows and coordination mechanisms ensure early warning strengthens institutional response without transferring enforcement authority.
  • A common operational language enhances EU interoperability – Embedding the framework within the European Democracy Shield architecture – including coordination through the Democracy Resilience Centre – would improve cross-border incident alignment and collective response coherence without requiring legal harmonisation.

 

Read White Paper Here

Acknowledgements:

The development of the DISRUPT toolkit and its components would not have been possible without the contributions of the over 180 individuals consulted. While Alliance4Europe held the pen, we have tried to channel the collective knowledge provided to us into this toolkit. Thank you for your contribution! 

The Disrupt framework builds on and learns from existing works, such as the DISARM Blue and Red Frameworks, Check First’s RADAR, Carl Miller’s D-RAIL, and CeMAS Integrated FIMI Response Model. 

A special thank you to our subgrantees AMO, PSSI, CSD, CEEDDW, Expert Forum, and ESGA for their excellent national knowledge and support in convening. We are also very grateful for the many government agencies that took the time to speak with us and share their insights. Furthermore, thank you to the networks EDMO and CAAD for helping us consult organisations outside our existing circles. 

Thank you to NASK, Gate Institute, SWPS and ANCOM for hosting and helping convene workshops.

Finally, thank you to all the members of the CDN with whom we have worked over the past two years on more than 100 cases and numerous successful disruptions of influence operations. This experience has laid the foundation for many of the measures and workflows we have included in the toolkit.