Insights & Commentary
•
Elections

Two Models of Election Defense: Standing Infrastructure versus Crisis Response

Denis Starovoytov
25 Sep 26
•
3 min read

Not every country waits for an election crisis to build its defenses. Across Northern and Eastern Europe, a second model has taken shape alongside the more dramatic cases that dominate headlines: permanent, standing institutional infrastructure that treats election interference as a continuous state function rather than an emergency to be managed after the fact. Comparing the two models side by side says as much about how election monitoring should be designed as either case does on its own.

The standing-defense model: Estonia, Latvia, Lithuania, Germany, Sweden

Estonia treats this as routine institutional work. The Estonian Internal Security Service (Kaitsepolitseiamet, KAPO) has published a public annual review of national security threats every year since 1998, one of the longest-running exercises in transparency of its kind anywhere (KAPO). Around the March 2023 parliamentary election, KAPO's monitoring fed into public reporting on a cluster of several hundred coordinated accounts pushing narratives aimed at Estonia's Russian-speaking communities, while Estonia's cybersecurity authority separately confirmed the election infrastructure itself faced attempted cyberattacks. Nothing here escalated into a constitutional crisis - the system simply absorbed the attempt and kept reporting on it publicly, year after year.

Latvia runs a similar continuous-monitoring posture through its Constitution Protection Bureau (SAB), which regularly publishes unclassified assessments of Russian propaganda directed at the country. Its most recent annual report explicitly forecasts that Russia will attempt to influence Latvia's autumn 2026 parliamentary election, and frames the threat level as a standing planning input rather than a one-off alert (SAB, 2026). The clearest documented incident remains a hack of a major Latvian social network on a past election day, which displayed pro-Kremlin imagery but was assessed to have had no effect on the vote itself - a genuine attempt, contained without disrupting the process.

Lithuania follows the same pattern through its State Security Department (VSD), which maintains a public English-language reporting stream specifically tracking influence activity against Lithuania (VSD). Notably, when ODIHR assessed Lithuania's 2024 presidential election, its own pre-election report flagged disinformation and intolerant online rhetoric as an area meriting deeper monitoring - a sign that even a well-defended system still has visible gaps worth tracking.

Germany shows the model at its most explicit. Ahead of the snap February 2025 federal election, the Federal Office for the Protection of the Constitution (BfV) stood up a dedicated task force combining domestic security, cyber, and international partners specifically to counter election interference, describing the effort as part of the state's ordinary responsibility to protect the Bundestag election (Federal Ministry of the Interior, BMI). That structure paid off analytically: German authorities were later able to attribute a specific campaign, internally known as Storm-1516, that fabricated corruption allegations against a leading candidate, and the government stated on the record that Russia had sought to influence and destabilise the election through it. Having named institutional capacity in place before the vote is precisely what made a specific, attributed finding possible after it.

Sweden offers the most mature version of this model. Sweden has run dedicated counter-influence task forces around every recent national and European election since 2018, coordinated first through its Civil Contingencies Agency (MSB) and, since 2022, through a purpose-built Psychological Defence Agency (MPF) - a standing government body whose sole mandate is identifying and countering foreign information influence aimed at the country (International IDEA, "Protecting Electoral Integrity: The Case of Sweden"). Tellingly, Sweden's own monitoring authority stated publicly ahead of one past EU election that it had found no evidence of a coordinated influence campaign - proof that a standing system's value isn't limited to catching threats, it also produces a credible, evidence-based "no incident" finding, which is its own form of institutional confidence.

The crisis-response model: Romania and Moldova

The contrast with the cases covered in the previous piece in this series is instructive. Romania's December 2024 election annulment and Moldova's contested 2024 presidential election and EU referendum both involved genuine, well-documented interference - vote-buying networks, cross-platform coordination, declassified intelligence findings. But in both cases, the response mechanism was reactive: an election observation mission deployed for one electoral cycle (as with ODIHR's mission to Moldova), or a constitutional court acting under emergency pressure once evidence had already surfaced (as in Romania). There was no year-round domestic institution publishing a running assessment the way KAPO, SAB, VSD, BfV, or MPF do. The system worked, in the sense that interference was detected and acted on, but it worked under acute time pressure rather than through a standing monitoring capability built in advance.

What the comparison says about monitoring design

The five standing-defense cases share a structural feature that the two crisis-response cases lack: a named, permanent institution with a publication habit, producing regular, dated, citable output whether or not anything alarming is happening in a given year. That habit is what allows a government to make a specific, attributed claim quickly when something does happen - as Germany did with Storm-1516 - rather than reconstructing the picture retroactively under public pressure, as Romania had to.

For anyone building or relying on election-integrity monitoring, the lesson isn't that crisis-driven detection fails - both Romania and Moldova show it can still work. It's that a standing capability changes what the detection actually costs: continuous collection and structured reporting turn what would otherwise be an emergency reconstruction into a routine update to an existing file.

Sources

1. Kaitsepolitseiamet (KAPO) - Annual Reviews: https://kapo.ee/en/content/annual-reviews/

2. SAB (Constitution Protection Bureau, Latvia) - reporting via Yahoo News / LSM (2026): https://www.yahoo.com/news/articles/latvia-intelligence-warns-russia-increasingly-123000616.html

3. VSD (State Security Department, Lithuania) - Influence Activities Against Lithuania: https://www.vsd.lt/en/reports/influence-activities-against-lithuania/russia-seeks-to-discredit-lithuania-increasingly-accusing-it-of-rewriting-history-promoting-nazism-and-spreading-russophobia/

4. Federal Ministry of the Interior (BMI, Germany) - Protecting the Bundestag Elections from Hybrid Threats, Including Disinformation: https://www.bmi.bund.de/SharedDocs/faqs/EN/topics/disinformation/bt_wahl_2025/faq_liste.html

5. International IDEA - Protecting Electoral Integrity: The Case of Sweden: https://www.idea.int/publications/catalogue/html/protecting-electoral-integrity-case-sweden

6. OSCE/ODIHR - Moldova 2024 Presidential Election and Constitutional Referendum: Election Observation Mission Final Report (2025): https://odihr.osce.org/odihr/elections/moldova/588014

7. European Parliament / EPRS - Mis- and Disinformation on Social Media and Related Risks to Election Integrity (2024): https://www.europarl.europa.eu/thinktank/en/document/EPRS_ATA(2024)767150

‍

Denis Starovoytov
25 Sep 26
•
3 min read
Ready to
explore Trementum?

If you’d like to see how Trementum Platform could work on your data, we can prepare a live demo tailored to your use cases.