The “Aggregated” Accumulation of Events Doctrine: Three Operational Hypotheticals

by | Aug 7, 2026

Accumulation

Editors’ note: This post is based on the author’s forthcoming contribution to “What if in 2031” in a fall/winter publication at the NATO Defence College (Rome). The post’s hyperlinks connect readers to actual events that are analogous to those presented in its hypotheticals.

Imagine that on December 7, 2031, three cyber incidents hit and subsequently crippled Europe.

Apple Update

A compromised update to Apple’s operating system (iOS-32) for iPhones and iPads reaches users on the European continent and in the United Kingdom. Apple sends the update after it being fined by the European Commission for violating the EU’s Enhanced Digital Service Act 2031 that sought to strengthen privacy for EU-citizens. iOS-32 unwittingly includes a new version of the malware DynoWiper, rendering Apple Pay and AppCoin—used by 37% of the 453 million Europeans (and Britons)—unavailable.

Within an hour, Apple users blame the EU-fines and criticize Apple and EU-governments on TikTok and Telegram. Virtual agitators, using massive AI-generated social media reposts, prompt popular uproar on the continent and in Britain. Soon, a mob appears at Apple’s Battersea office, harasses a visit by King Charles, and turns violent when security guards and police attempt to gain control. Within 12-hours riots and looting of Apple stores erupt in Rome, Milan, Paris, Marseille, Birmingham, and Brussels. In 48 hours, hundreds of shops and EU-agencies are looted and set on fire.

Trains

Simultaneously, the Pan-European Railway Enterprise (PERE), established in 2027 to implement the 2030 Paris-2 Climate Accord and providing semi-high-speed connections between Europe’s capitals, is hit by ransomware. The malware, Matroshka-4, exploits a zero-day defect in PERE-operational control (and safety) systems and causes a shutdown of PERE’s rail safety system bringing trains to a standstill. PERE-customers, making up 30% of intra-European travel are stranded across Europe. Hundreds of passengers must be evacuated, an operation that takes two days. One renegade high-speed train, however, escapes the PERE safety lockdown and collides with another, causing several deaths.

Power

By sunset on 7 December, power goes down in Stockholm, causing the Fjärrvärme (city heating system) to collapse after contingency measures fail. Some two million inhabitants and companies revert to emergency power installations. As winter hit Sweden early, government forecasting predicts multiple casualties. Soon after, the Scandinavian High Voltage Direct Current 400/420kV connection between Sweden and Denmark, also fails to offer back-up service and power fails in Jutland as well.

Attribution

By the evening of 8 December, attribution indicators surface. First, forensics offered by Apple, prove that the iOS-32 update had been issued from within Apple’s Silicon Valley location but effectively originated from Belarusian IP-ranges. Second, shared intelligence from the newly established Joint UK-EU Intelligence Fusion Cell, indicate that the malware that crippled PERE was designed by a Chechnyan hacking collective, “NASH,” known for strong ties with Russia’s Foreign Intelligence Service (SVR). Last, the Swedish Security Service (Säkerhetspolisen) soon concludes that sabotage at one of the 380kV-substations caused the Scandinavian connection breakdown. CCTV-footage and facial recognition software lead to the subsequent arrest of three operatives with Russian and Belarusian diplomatic credentials.

Legal Deterrence and Hybrid Threats

These three events, and their direct digital and indirect physical and cognitive effects, illustrate the importance of determining how to deter hybrid threats. It has been argued that a clear and effective legal framework is key to establish credible deterrent capability. Part of any such legal framework is clarity of the armed attack threshold permitting victim States to resort to the use of force in self-defence to deter and counter hybrid threats and attacks.

Accordingly, the work on which this post is based investigates the possibility of the NATO North Atlantic Council (NAC) applying a so-called aggregated “accumulation of events doctrine” in response to hybrid attacks, using the above fictitious scenario. Based on the events and their impacts and the subsequent violent reactions, the study imagines a NAC response investigation including consideration of legal and strategic options and their consequences. The study addresses both classic and post-9/11 notions of self-defence as well as established “accumulation of events” doctrines. The study then investigates an updated accumulation or aggravation of targets and attackers approaches to response options after hybrid and cyber attacks.

Accumulating Attacks by Victims and Authors

Continuing the scenario, suppose that on the morning of December 9, 2031, the NAC convenes in Brussels. After deliberations, taking into account the above events, and after having registered numerous hybrid incidents in the preceding five years, NATO’s Secretary General issues the following statement, “The Council has determined that these three attacks were directed from abroad against NATO members and regards them as covered by Article 5 of the Washington Treaty. Accordingly, they amount to an armed attack against all NATO members for purposes of Article 5.” Suppose further that on 12 December, after meeting with the NAC, the Secretary General advises, “the Council has determined that the three events amounting to attacks against the NATO members on 7 December, were directed from abroad and shall therefore comprehensively be regarded as an action covered by Article 5 of the Washington Treaty. As a result, NATO-members are entitled to resort to armed force in self-defence.”

Invoking self-defence for only the second time in its history, the NAC would be required to address legal issues concerning the threshold of effects for an armed attack, whether separate events and effects may be aggregated to meet that threshold, the relevance of the attack affecting multiple victims, and the relevance of the attack involving multiple perpetrators.

Accumulating Attacks

The casus foederis to invoke NATO’s collective self-defence mechanism rests in Article 5 of the NATO Washington Treaty (1949). Without defining the term itself, Article 5, consistent with Article 51 of the UN Charter, was initially conceived to deter and defend against conventional military or nuclear kinetic armed attacks (see Figure 1) in the Industrial Age.

Figure 1: Classic armed attack and self-defence

This classic view, however, has been supplemented for two reasons. First, attacks against the United States on 9/11 solidified the view that the use of terrorism and non-military means (even by non-State actors) that generate effects of severity and on a scale comparable to conventional State-authored attacks meet the threshold of armed attack for the purposes of the Washington Treaty and the UN Charter (see Figure 2).

Picture 2

Figure 2: Armed attack by non-state actor (AQ) and self-defence at ‘9/11’

Second, the transition from the Industrial Age to the Information Age introduced sophisticated (hard and soft) cyber capabilities enabling a wide range of actors to maliciously exploit and interfere with States’ critical dependencies and infrastructure. Further, digitalised social interactions have seeped into warfare and have required NATO allies to reaffirm their defence mandate and to recognize cyberspace as a domain of military and wartime operations. Accordingly, NATO has indicated that both “cyber operations” and “hybrid operations against Allies could reach the level of an armed attack.” For cyber operations, the “scale and effect” (see Tallinn Manual 2.0, p. 339) criteria for an armed attack have also incorporated in the various national strategies.

With its fictitious decision, firstly, the NAC has applied the Nadelstichtaktik or “accumulation of events” doctrine to aggregate the attacks. Individually, none of the events imagined above which lack substantial impact in terms of scale and effect, likely meets the armed attack threshold. However, as an armed attack denotes “a reasonably significant use of force originating or directed from abroad”, jurisprudence and legal doctrine already accept the idea that (see Figure 3) “a series of smaller related armed incidents which have the common purpose of destabilizing the victim State or exacting political concessions from it” (see Gill & Fleck, p. 219) could amount to an armed attack.

Picture 3

Figure 3: Accumulation of attacks and self-defence

Accumulating Victims and Authors of Attacks

Secondly, in response to the scenarios above, the NAC, facing hybrid threats and seeking effective cross-domain deterrence, might be expected to also aggregate both the victims and the authors of the attacks (see Figure 4).

It is true that the basic notion of self-defence is based on the understanding of a single author attacking a single victim State. However, bilateral and collective self-defence arrangements (such as NATO and EU), in a way, already aggregate victimhood by regarding an attack against one member as an attack on all. This notion of collective self-defence beyond (individual) self-help, also resonates in the plea for collective countermeasures, where not (only) the victim state, but also other States exercise (non-forceful) rights.

Figure 4: Armed attack (2031 aggregated accumulation) and self-defence

The NAC in this instance has also departed from identifying single authorship. This made sense once the attacks by proxy originated or were controlled or directed from abroad and the various actors were sufficiently related (see Gill & Fleck, p. 213). A common goal or a coordinated campaign under some kind of unified command and control could establish such a relationship. In such cases, “[credible], reliable and sufficient” evidence on the origin and authorship is required. This will often take significant time. Moreover, it may be hard to establish the interrelationships between the authors.

Authorship itself may come in three shapes: 1) States acting on their own or in concert; 2) non-State actors (NSA) acting either under the control or direction, or with the substantial involvement of a State (see Paramilitary Activities, para. 195); or 3) NSAs acting alone. Especially establishing NSA authorship with State direction or involvement, is crucial to attribute the acts to the State(s) involved. Under the secondary rules of State responsibility this is regularly done in bilateral or multilateral situations. In the present scenario, however, the relationship between the authors and the States involved might take the shape of a multimode network and the crucial hurdle is one of the primary rules of jus ad bellum, that is, who is the author of the armed attack (that triggers the right to self-defence).

As hybrid, and especially cyber attacks, by definition and composition are characterised by their various military and non-military components and their intermediate facilitators, it will be difficult to designate single elements. Just as the series of attacks as a whole is considered the casus foederis, and “all for one, and one for all” is the core of the Alliance, it would illogical to segregate the authors without considering the network between them. Looking back, if a former Warsaw Pact multinational force of 2 States would have crossed the Inner Deutsche Grenze on behalf of that alliance, NATO would likely have considered all Warsaw Pact members responsible and could have resorted in self-defence against any of them.

This diversity of authors and their origin is, and has been common in military alliances for decades, also in NATO itself. This approach accounts for modern force composition with its public and private, military and non-military parts (e.g. for logistics, intelligence gathering, force protection) responsible for a common effort. Apart from issues of State responsibility, the acts of such a force acting under a unified command—whoever the author might be—are considered the acts of the force in common understanding.

Hence, the present aggregation of authorship bridged the final hurdle in the 2031 application of the Nadelstichtaktik.

Conclusion

Our fictitious NAC interpretation and invocation of Article 5 NATO Treaty in response to several hybrid, cyber incidents hitting multiple States, would, in theory, fundamentally reshape NATO’s legal and strategic potential to deter, and to respond to, hybrid threats. Specifically, by applying the accumulation of events doctrine in an aggregated manner, that is by aggregating effects, victims and attackers, the NAC decision would, for the first time, establish that a series of small, hybrid and cyber attacks may trigger the right to self-defence and collective self-defence under international law. Such a NAC decision would recognize aggregated authorship, aggregated victimhood, and aggregated effects as sufficient bases for forceful responses under the Charter and Washington Treaty.

Strategically, this interpretation of Article 5 of the NATO Washington Treaty (and Article 51 of the UN Charter), would clearly reinforce the Alliance’s commitment to protect and defend member States from an increasingly prevalent form of non-kinetic and/or hybrid threats. It would mark a significant shift in historical approaches and opinions on self-defence and would enhance NATO’s and member States’ capabilities, aimed at deterring as well as defending and responding against both kinetic and non-kinetic hybrid and cyber attacks.

The author wishes to thank Dr Hans Bodden Hosang, Prof Terry Gill, Dr Kathuna Burkadze, and Dr Florence Gaub for their suggestions to this post.

***

Brigadier-General Paul Ducheine (Army Legal Service) is the Deputy Director of the Research Division of NATO’s Defense College (Rome).

The views expressed are those of the author, and do not necessarily reflect the official position of the United States Military Academy, Department of the Army, or Department of Defense.

Articles of War is a forum for professionals to share opinions and cultivate ideas. Articles of War does not screen articles to fit a particular editorial agenda, nor endorse or advocate material that is published. Authorship does not indicate affiliation with Articles of War, the Lieber Institute, or the United States Military Academy West Point.

 

 

 

 

 

 

Photo credit: Xavier Cee via Unsplash