452 DENMARK effects resulting from an action, which would otherwise qualify as an armed attack. Thus, Denmark considers that a cyber operation, which e.g. leads to serious injury or death, or which causes significant physical damage, may qualify as an armed attack. This could be the case if a cyber attack leads to the disabling of an air traffic control system which causes planes to crash or an interference with the operating system of a power station, which causes serious physical damage. Certain States take the view that an armed attack can only be undertaken by State actors or entities acting under the control or instruction of States, and thus no right to self-defense exists against an armed attack by a non-State actor. Denmark does not share this view, but contends that State practice supports that a State might in some instances and under certain conditions be permitted to exercise self-defence against an armed attack by a non-State actor. 5 State responsibility Denmark is of the view that the general rules of State responsibility apply in cyberspace. A State bears international responsibility if it breaches an international obligation owed to another State. A State may be responsible under international law for acts undertaken by an organ of the State or by actors exercising government authority on behalf of that State. Acts by a non-State actor may be attributable to a State where the non-State actor carries out a cyber operation under the instruction of, or under the direction or control of that State, or where the State actor acknowledges and adopts the operations carried out by the non-State actor as its own. Each State may decide whether to publicly attribute cyber acts to other States or not. There is no obligation under international law for States to share documentation or other evidence supporting an attribution. The application of international law and State responsibility does not depend on public attribution. 6 Due diligence Denmark is of the view that a State may bear international responsibility where a State fails to take adequate measures against a non-State actor - or third State - that conducts harmful cyber operations against another State from its territory or other cyber infrastructure under its effective control. Downloaded from Brill.com 03/27/2024 10:42:51AM via Open Access. This is an open access article distributed under the terms Nordic Journal of International Law 92 (2023) 446–455 of the CC BY 4.0 license. https://creativecommons.org/licenses/by/4.0/

Select target paragraph3