455 denmark’s position paper With regard to the application of IHL in the cyber domain one key issue concerns the definition of attack and under which circumstances a cyber operation can amount to an attack. Denmark is a party to the four Geneva Conventions and Additional Protocols and defines cyber-attack within the meaning of Article 49 of Additional Protocol I. Denmark takes the view that a cyber operation may be considered an attack in the context of an armed conflict where it produces effects akin to those of a kinetic attack. Consequently, a cyber operation will constitute an attack if it can be reasonably expected to cause injury, death, or physical damage to individuals or objects. This definition also includes activity where substantial destruction is caused as a foreseeable secondary effect. For instance, if a military air traffic control system through a cyber operation is taken out of operation which causes foreseeable loss of human life or substantial damage to or destruction of physical objects. Although digital data cannot generally in and of itself be considered an object under IHL, the destruction of data may have such adverse secondary effects on individuals or physical objects that the operation may nonetheless qualify as an attack. This may be the case where the destruction of data foreseeably results in injury, death or physical damage, in which case the objects or individuals subject hereto can be considered the object of the attack. Similarly, an operation targeting data upon which the functionality of an object relies could qualify as an attack depending on the nature and scale of the damage foreseeably resulting from the operation in question. Where a cyber operation amounts to an attack it is subject to the same rules and requirements as those applicable to attacks conducted in the physical domain. These include, inter alia, the principles of military necessity, distinction, proportionality, and humanity. In situations where a cyber operation does not amount to an attack the relevant rules of IHL that address conducts or effects falling below the threshold of an attack nevertheless apply. This includes but is not limited to the obligation of constant care by which States are required to take all reasonable precautions to spare the civilian population as well as civilian individuals and objects, including essential civilian infrastructure, services, and data, when planning or conducting cyber operations in the context of hostilities. Note from the publisher The authors mentioned at the start of this article, Jeppe Mejer Kjelgaard and Ulf Melgaard, are only responsible for the introduction to this position paper. The position paper is a product of the government of Denmark. Downloaded from Brill.com 03/27/2024 10:42:51AM distributed under the terms of the CC BY 4.0 license. https://creativecommons.org/licenses/by/4.0/ via Open Access. This is an open access article Nordic Journal of International Law 92 (2023) 446–455

Select target paragraph3