Lithuania, the alliance’s canary¶
Lithuania, and cyber power as a network rather than an actor
A small state on NATO’s eastern edge appears in the cyber story in one of two roles: as a victim, on the receiving end of Russian denial-of-service raids, or as a dutiful member ticking the alliance’s boxes. Lithuania has been both. In June 2022 pro-Russian hacktivists took state services offline in retaliation for its enforcement of EU sanctions on transit to Kaliningrad. It runs a national cyber-security centre, a national response team, the usual furniture.
The striking thing is what is missing. There is no named Lithuanian actor to point at and indict, no group the reporting can turn into a face on a poster. A small, exposed state with no strategic depth does not build an autonomous offensive apparatus. It does something else: it disperses its cyber capability across institutions and alliances, makes it interoperable with larger systems, and turns national expertise into something other states can use. The unit of analysis is not an actor. It is a mesh.
Exposure without depth¶
Lithuania has close to the wrong physical properties for cyber autonomy. It is small, its networks sit next to Russian and Belarusian ones, it borders Kaliningrad, it remembers occupation, and its security problem is larger than the resources of the state. The rational response is not to build a great power’s capability in miniature. It is to make national capability interoperable with larger systems and to turn national expertise into something other states can draw on. Unable to absorb or solve threats alone, the state makes interoperability its capability, distributes that capability across national institutions, and plugs it into NATO, EU, US and partner structures. It gains security by making itself useful to the network, and the network gains a forward sensor.
The same condition shows outside cyber. Lithuania’s decision to admit Taiwan’s representative office under its own name in 2021 drew heavy Chinese economic pressure, and exports to China collapsed, cut by nearly ninety per cent. The episode is not a cyber event, but it sits on the same substrate: Lithuania accepts an exposure a larger, more entangled state would find harder to absorb, and leans on wider European and allied structures to keep that exposure from turning into isolation.
The loop is short. Exposure drives the state to make its capability useful to the network; usefulness deepens its embedding in allied and partner structures; the embedding yields security and reach; and the reach funds more usefulness still. It closes and it reinforces, which is why a small state can grow steadily more central to a system larger than itself without ever growing into a great power.
Exporting participation¶
The coupling runs the other way from a great power’s. Where a larger state concentrates capability, Lithuania distributes and exports it, and the export is participation rather than a tool. It is the lead participant in the EU’s Cyber Rapid Response Teams, a multinational capability it has helped build and run, and in 2024 it led the project’s sixth rotation. That year the teams were activated for Lithuania’s own European Parliament elections and twice for Moldova, the second the largest such deployment to that point, eight member states supplying experts who ran vulnerability assessments, penetration testing and monitoring through an election and a referendum. The thing that travels is not a Lithuanian weapon. It is Lithuanian participation made portable: people, procedures, threat analysis and response capacity that can be assembled somewhere else.
A platform, not a weapon¶
The most revealing Lithuanian cyber institution is not a national unit at all. The Regional Cyber Defence Centre in Kaunas was set up in 2021 as a joint Lithuanian-American initiative, with Ukraine and Georgia brought into the structure and Poland joining later. Its remit is practical rather than ceremonial: threat analysis, information exchange, training, exercises and research, a regional cooperation platform through which experts from partner countries rotate, working incidents and vulnerabilities and passing the results between institutions. The arrangement reverses the usual picture of a small state asking a large ally for cover. Lithuania supplies a place where several states combine their capabilities. The product is not a Lithuanian cyber weapon. It is interoperability, which is where the word network stops being a metaphor.
The canary detects first¶
The 2021 investigation of Chinese-made phones is the same arrangement in another form. Lithuania’s national cyber centre took apart Huawei, Xiaomi and OnePlus 5G devices sold in the country and found four substantive risks, three in the Xiaomi handset and one in the Huawei, including software able to censor phrases such as “Free Tibet.” The deputy defence minister advised the public to stop buying Chinese phones and to get rid of the ones they owned. The finding gave Lithuania no new capability of its own. It gave a larger network an early observation. A canary is useful not because it is stronger than the mine but because its exposure lets it notice something first, and a small, technically capable state on the frontline is exposed enough to notice and quick enough to say so.
Capability in circulation¶
Capability flows into Lithuania as well as out. In 2022 a US Cyber National Mission Force team ran a defensive hunt operation on Lithuanian networks, working alongside the national cyber centre and defence specialists and returning the findings to Lithuanian and American defenders alike. This is neither dependence nor autonomy in the usual sense. Lithuania supplies access, local knowledge and a defended environment; the larger partner supplies extra people and tools; and the line between national capability and allied capability is left deliberately porous. What looks from outside like a small state hosting a big one is, closer up, a network in which capability circulates.
No core to point at¶
Look at who actually carries out a Lithuanian cyber action and the single actor dissolves. A national exercise team is assembled from the defence ministry, the cyber-security centre, the armed forces, the criminal police, energy operators, the volunteer Riflemen’s Union and the universities, and fielded jointly with the Netherlands. The rapid-response team is European. The regional centre is bilateral with the United States and open to partners. There is no core to point at, because the capability is constituted as a network spanning national, military, EU, bilateral, commercial and volunteer bodies. The entity doing the work is a coalition, and calling it Lithuania is a convenience.
The mesh acquires a node¶
In January 2025 Lithuania stood up something closer to a conventional national cyber authority. Its new Cyber Defence Command is responsible for planning and executing cyber operations as well as defending military systems and running military information networks. A concentrated national node is exactly what a state like this has avoided. But the concentration is built around interoperability: the command’s own remit is to make Lithuanian military systems interoperable with NATO and other national and institutional systems and to coordinate cyber operations inside the wider defence structure. The command also corrects an easy overstatement. It would be wrong to say Lithuania has no offensive cyber capability, since planning and executing cyber operations is part of the command’s stated remit. What the public record does not provide is a clearly attributable Lithuanian offensive campaign. The observable signature is overwhelmingly defensive, collaborative and interoperable; the rest may simply be classified.
Strategy, or the only option¶
Whether the dispersal is a chosen strategy or the only shape available to a state too small to hoard is not something the record settles. A larger exposed state might concentrate what Lithuania distributes. Exposure plus alliance-embedding appears to produce a distributed, outward-facing capability, but exposure and smallness arrive together here and do not separate cleanly.
A small state’s cyber power does not have to be a smaller-scale version of a great power’s. Lithuania has built something else: capability that becomes more useful as it crosses its own borders. Its institutions connect to allied ones, its specialists enter multinational teams, its threat findings circulate, and its networks become places where larger partners operate. The state buys security partly by not keeping cyber capability exclusively national.
The canary, then, is not simply the state that gets hit first. It is the node through which the network learns that something has entered the mine. And that leaves a question hanging over the idea of a state cyber actor at all. Once capability is distributed across institutions, alliances, contractors and markets, the named actor may never have been the thing to look for. Lithuania is only the case where the label is hardest to mistake for the thing.