3. General principles of international law, including the law on State responsibility The customary international law on State responsibility, much of which is reflected in the International Law Commission's Articles on the Responsibility of States for Internationally Wrongful Acts (ARSIWA), applies to State behaviour in cyberspace. Under the law on State responsibility, there will be an internationally wrongful act of a State when its conduct in cyberspace—whether by act or omission—is attributable to it and constitutes a breach of one of its international obligations. To the extent that a State enjoys the right to exercise sovereignty over objects and activities within its territory, it necessarily shoulders corresponding responsibilities to ensure those objects and activities are not used to harm other States. In this context, we note it may not be reasonable to expect (or even possible for) a State to prevent all malicious use of ICT infrastructure located within its territory. However, in Australia's view, if a State is aware of an internationally wrongful act originating from or routed through its territory, and it has the ability to put an end to the harmful activity, that State should take reasonable steps to do so consistent with international law. States are entitled, in their sole discretion, and based on their own judgement, to attribute unlawful cyber activities to another State. States should act reasonably when drawing conclusions based on the facts before them. A cyber activity will be attributable to a State under international law where, for example, the activity was conducted by an organ of the State; by persons or entities exercising elements of governmental authority; or by non-State actors operating under the direction or control of the State. Australia recognises the need to distinguish between different attribution assessments, including factual attribution (which includes an assessment of technical and other contextual information) and legal attribution (that there has been a breach of international law), as well as the political decision to convey – publicly or privately – those attribution assessments. If a State is a victim of malicious cyber activity, which is attributable to a perpetrator State, the victim-State may be able to take countermeasures under certain circumstances. Countermeasures are measures, which would otherwise be unlawful, taken to secure cessation of, or reparation for, the other State’s unlawful conduct. Countermeasures may be cyber in nature or taken through alternative means, such as temporarily not performing certain bilateral treaty obligations owed to a State. Countermeasures in cyberspace cannot amount to a use of force and must be proportionate. States are able to respond to other States’ malicious activity with acts of retorsion, which are unfriendly acts that are not inconsistent with any of the State’s international obligations. If a State is the victim of harmful conduct in cyberspace, that State could be entitled to remedies in the form of restitution, compensation or satisfaction. In the cyber context, this may mean that the victim-State could, for example, seek replacement of damaged hardware or compensation for the foreseeable physical and financial losses resulting from the damage to servers, as well as assurances or guarantees of nonrepetition. 28 May 2021 [Annex: cyber case studies] 5 www.internationalcybertech.gov.au

Select target paragraph3