13/05/2026
Foreign Information Manipulation and Interference is not a new problem. But the way institutions respond to it too often is: fragmented, reactive, and inconsistent across borders. RESONANT’s Deliverable 4.1 – Methodological Toolkit and Policy Recommendations Report – is a direct attempt to fix that.
Released as a key output of Work Package 4, D4.1 is the result of a collaboration between FORMIT (project coordinator and task lead) and URJC – Universidad Rey Juan Carlos – which led the policy recommendations component. Together, they’ve produced a document that bridges two things that usually get treated separately: how you analyse a FIMI incident, and how you decide what to do about it.
A methodology built for practitioners, not just specialists
The detection methodology at the heart of D4.1 was designed specifically for security researchers and practitioners who are not OSINT specialists – a gap explicitly identified in the field. The goal was to make structured FIMI analysis accessible beyond the small community of highly specialised investigators, without sacrificing analytical rigour.
The process moves from detection to response through a clear workflow. Incidents are identified using observable, measurable indicators mapped to Tactics, Techniques and Procedures (TTPs). Evidence is assessed using a “Rule of Two” – at minimum two independent sources from different measurement surfaces.
Impact is scored based on scope, duration, reversibility, and whether vulnerable groups (such as diaspora communities, journalists, or human rights defenders) are directly affected.
The result feeds into an Evidence × Severity matrix that assigns each case to one of three response tracks:
- Signal (monitor and document);
- Mitigate (activate proportionate countermeasures);
- High-priority (coordinate, escalate, and engage competent authorities).
The logic is borrowed from engineering risk management and adapted to the specific dynamics of information operations — making it both theoretically grounded and operationally practical.
The methodology was tested through simulation-based case replays using documented incidents from the RESONANT evidence base, with an additional real-life round applied to a previously unanalysed suspected FIMI case. This validation process confirmed internal coherence and practical usability, while also identifying areas for further refinement.
From indicators to policy: the URJC contribution
While FORMIT developed the detection methodology, URJC led Task 4.2 – translating those findings into concrete, governance-ready policy recommendations. The approach chosen was a two-round policy e-Delphi involving over 20 multidisciplinary experts: researchers, policymakers, practitioners, legal experts, and civil society representatives from across the EU. The Delphi process wasn’t designed to reach consensus for its own sake. It was designed to surface the strongest evidence-based positions on contested governance questions – thresholds for action, institutional responsibilities, coordination interfaces, transparency requirements – across the four pillars of the EU FIMI Toolbox: situational awareness, resilience, disruption and regulation, and diplomatic responses.
The results are concrete. Five measures emerged with strong cross-round convergence: a shared taxonomy and interoperability standard (STA3), escalation paths for non-law-enforcement actors (R4), standardised handover templates for platform interfaces under the DSA (DR2), a regulatory focus on manipulation infrastructures rather than content alone (DR3), and clear criteria for escalating FIMI patterns to EU-level foreign policy instruments (DP1). Each is presented as a fully developed policy recommendation record – with decision inputs, enabling conditions, governance allocation, indicative sequencing, and IPCR relevance.
Why it matters
What D4.1 ultimately provides is alignment: a framework where what gets measured can directly inform what gets decided, and where operational findings can be translated into policy without losing precision or proportionality. It embeds rights-by-design principles throughout – from data minimisation to safeguards for vulnerable groups – ensuring that the response to FIMI doesn’t compromise the democratic values it’s meant to protect.
The deliverable feeds directly into the next phases of RESONANT: validation through tabletop exercises and focus group policy discussions, and eventual consolidation in the final RESONANT Handbook (D4.3).
The challenge of responding to foreign information manipulation consistently and at scale across the EU remains significant. D4.1 doesn’t solve it – but it provides the methodological and policy architecture to get meaningfully closer.
Organisation / Author: FONDAZIONE FORMIT