455
denmark’s position paper
With regard to the application of IHL in the cyber domain one key issue
concerns the definition of attack and under which circumstances a cyber operation can amount to an attack.
Denmark is a party to the four Geneva Conventions and Additional Protocols
and defines cyber-attack within the meaning of Article 49 of Additional
Protocol I. Denmark takes the view that a cyber operation may be considered
an attack in the context of an armed conflict where it produces effects akin to
those of a kinetic attack. Consequently, a cyber operation will constitute an
attack if it can be reasonably expected to cause injury, death, or physical damage to individuals or objects. This definition also includes activity where substantial destruction is caused as a foreseeable secondary effect. For instance,
if a military air traffic control system through a cyber operation is taken out of
operation which causes foreseeable loss of human life or substantial damage
to or destruction of physical objects.
Although digital data cannot generally in and of itself be considered an
object under IHL, the destruction of data may have such adverse secondary
effects on individuals or physical objects that the operation may nonetheless
qualify as an attack. This may be the case where the destruction of data foreseeably results in injury, death or physical damage, in which case the objects or
individuals subject hereto can be considered the object of the attack. Similarly,
an operation targeting data upon which the functionality of an object relies
could qualify as an attack depending on the nature and scale of the damage
foreseeably resulting from the operation in question.
Where a cyber operation amounts to an attack it is subject to the same rules
and requirements as those applicable to attacks conducted in the physical
domain. These include, inter alia, the principles of military necessity, distinction, proportionality, and humanity.
In situations where a cyber operation does not amount to an attack the relevant rules of IHL that address conducts or effects falling below the threshold of
an attack nevertheless apply. This includes but is not limited to the obligation
of constant care by which States are required to take all reasonable precautions to spare the civilian population as well as civilian individuals and objects,
including essential civilian infrastructure, services, and data, when planning or
conducting cyber operations in the context of hostilities.
Note from the publisher
The authors mentioned at the start of this article, Jeppe Mejer Kjelgaard and
Ulf Melgaard, are only responsible for the introduction to this position paper.
The position paper is a product of the government of Denmark.
Downloaded from Brill.com 03/27/2024 10:42:51AM
distributed under the terms
of the CC BY 4.0 license.
https://creativecommons.org/licenses/by/4.0/
via Open Access. This is an open access article
Nordic Journal of International
Law 92 (2023) 446–455