The NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE) has opened its call for papers for CyCon 2027, the 19th International Conference on Cyber Conflict, to be held in Tallinn from 25–28 May 2027 under the theme "Unified Response." The programme committee's invitation is unusually candid about where it thinks the real obstacle lies: not in detection tools or malware signatures, but in law. Submissions are explicitly sought on "the conditions enabling or constraining coordinated responses across jurisdictions and sectors" and on "legal, policy, and technical barriers to collective action, and ways to overcome them."
That framing matters because CyCon is not a niche academic gathering. It draws more than 800 officials, military lawyers, and technologists from roughly 50 countries, and its legal track has previously shaped real doctrine — the Tallinn Manual project, hosted by CCDCOE and published by Cambridge University Press, is the closest thing cyber conflict has to an authoritative restatement of how international law applies to state behavior online. A Tallinn Manual 3.0 process, led by Professor Michael Schmitt with General Editors Liis Vihul and Marko Milanović, has been underway since 2021 and is due to conclude around the time CyCon 2027 convenes. Naming "Unified Response" as next year's theme is a signal that the drafters see jurisdictional fragmentation, not technical capability, as the binding constraint on collective cyber defense.
The Case for a Unified Command
There is a genuine argument for tighter legal integration, and it deserves to be stated plainly before it's argued against. NATO's own Article 5 — the collective-defense clause — has never been definitively triggered by a cyber incident, and alliance members remain divided on what threshold of damage would qualify. That ambiguity is not academic hedging; it is a real deterrence gap. An adversary calibrating a cyberattack to stay just below the threshold that provokes a NATO-wide response faces little practical risk, precisely because no member state wants to pre-commit to a bright line that could later constrain its own discretion. Meanwhile, attribution — figuring out who actually launched an operation — is difficult enough that adversaries routinely use proxies and false-flag techniques specifically to exploit the resulting hesitation. A more centralized structure, with pre-agreed jurisdictional handoffs and a lower bar for invoking mutual assistance, would plausibly close that seam and make deterrence more credible.
The European Union has already moved further in that direction than NATO has. The Cyber Solidarity Act (Regulation (EU) 2025/38, adopted 19 December 2024 and in force since 15 January 2025) establishes "Cross-Border Cyber Hubs" pooling national monitoring centers from at least three member states, plus an EU Cybersecurity Reserve of vetted private responders that can be dispatched to a member state hit by a major incident. As the Estonian think tank ICDS argued in an August 2025 analysis, the Act effectively fills a gap NATO has left open by design — moving the EU's cybersecurity posture "from regulatory to operational" precisely because the alliance's own Article 5 ambiguity left member states without a fallback.
Why Centralization Is the Wrong Fix
But the CyCon 2027 brief should not be read as an invitation to design a NATO cyber command with binding authority over national response decisions, and the alliance would be wise not to build one. Sovereignty over how a state investigates and responds to an intrusion on its own networks is not bureaucratic friction to be engineered away — it is the mechanism by which elected governments remain accountable for decisions with escalation risk. A binding, pre-committed threshold for collective cyber response would also hand adversaries a target: any fixed line becomes something to probe and route around, while ambiguity, however frustrating to planners, currently forces caution on all sides.
The more productive path is the one the EU and NATO have already started down piecemeal: interoperability agreements, shared situational-awareness feeds, and voluntary mutual-assistance arrangements like the Cybersecurity Reserve, rather than a rewritten treaty obligation. Estonia's own experience illustrates the stakes without requiring a new legal architecture to address them. The country's cyber authority, RIA, recorded 10,185 cyber incidents in 2025 — a record — including 756 denial-of-service attacks, more than a third higher than the year before. Crucially, RIA also reported that the share of DDoS attacks actually disrupting services fell sharply from historical norms, evidence that better detection and existing cross-border information sharing are already working without a new command structure forcing the outcome.
CyCon's legal track is well positioned to do something more useful than propose a treaty rewrite: produce model interoperability agreements, clarify how existing frameworks like the Cyber Solidarity Act and NATO's own crisis-response mechanisms can hand off to one another without duplicating authority, and pressure-test where genuine legal ambiguity (rather than political reluctance) is actually the blocker. Tallinn, a decade after the Manual that carries its name reshaped the field, is a fitting place to make that distinction. The alliance doesn't need one unified law to respond to cyberattacks — it needs its existing, sovereignty-respecting arrangements to interoperate faster than adversaries can adapt to them.