3. General principles of international law, including the law on State responsibility
The customary international law on State responsibility, much of which is reflected in the International Law
Commission's Articles on the Responsibility of States for Internationally Wrongful Acts (ARSIWA), applies to
State behaviour in cyberspace. Under the law on State responsibility, there will be an internationally
wrongful act of a State when its conduct in cyberspace—whether by act or omission—is attributable to it
and constitutes a breach of one of its international obligations.
To the extent that a State enjoys the right to exercise sovereignty over objects and activities within its
territory, it necessarily shoulders corresponding responsibilities to ensure those objects and activities are
not used to harm other States. In this context, we note it may not be reasonable to expect (or even possible
for) a State to prevent all malicious use of ICT infrastructure located within its territory. However, in
Australia's view, if a State is aware of an internationally wrongful act originating from or routed through its
territory, and it has the ability to put an end to the harmful activity, that State should take reasonable steps
to do so consistent with international law.
States are entitled, in their sole discretion, and based on their own judgement, to attribute unlawful cyber
activities to another State. States should act reasonably when drawing conclusions based on the facts
before them.
A cyber activity will be attributable to a State under international law where, for example, the activity was
conducted by an organ of the State; by persons or entities exercising elements of governmental authority;
or by non-State actors operating under the direction or control of the State.
Australia recognises the need to distinguish between different attribution assessments, including factual
attribution (which includes an assessment of technical and other contextual information) and legal
attribution (that there has been a breach of international law), as well as the political decision to convey –
publicly or privately – those attribution assessments.
If a State is a victim of malicious cyber activity, which is attributable to a perpetrator State, the victim-State
may be able to take countermeasures under certain circumstances. Countermeasures are measures, which
would otherwise be unlawful, taken to secure cessation of, or reparation for, the other State’s unlawful
conduct. Countermeasures may be cyber in nature or taken through alternative means, such as temporarily
not performing certain bilateral treaty obligations owed to a State.
Countermeasures in cyberspace cannot amount to a use of force and must be proportionate.
States are able to respond to other States’ malicious activity with acts of retorsion, which are unfriendly
acts that are not inconsistent with any of the State’s international obligations.
If a State is the victim of harmful conduct in cyberspace, that State could be entitled to remedies in the
form of restitution, compensation or satisfaction. In the cyber context, this may mean that the victim-State
could, for example, seek replacement of damaged hardware or compensation for the foreseeable physical
and financial losses resulting from the damage to servers, as well as assurances or guarantees of nonrepetition.
28 May 2021
[Annex: cyber case studies]
5
www.internationalcybertech.gov.au