6 international law. Attribution should be in line with our stated positions in national and international fora, where we champion a free, open, peace and secure cyberspace, and adhere to norms of state behaviour. It should enhance the UK’s reputation as a competent cyber actor and weigh up the risk of misattribution. e. Wider response options: the effect of UK attribution on other deterrence activity, which the UK government has agreed or is implementing. The timing of attribution should be calibrated to enhance the impact of other responses. There are challenges to attribution in cyberspace, but this does not mean it is impossible. Nor should it be viewed in isolation; it is one tool amongst many in a range of options (political, diplomatic, and economic) to respond to malicious cyber activity, with the aim of deterring this activity. Norm 3 (UNGGE 2015 report, paragraph 13c) – States should not knowingly allow their territory to be used for internationally wrongful acts using ICTs. The United Kingdom has criminalised wrongful acts using ICTs through, for example, the Computer Misuse Act3. This makes it an offence to conduct unauthorised access to computer systems, and to use this access to facilitate other offences, such as modifying or damaging computer systems and networks. Overall Strategy: The 2015 National Security Strategy (NSS)4 confirmed that cyber remains a top threat to the UK’s economic and national security. The threat posed by cyber attacks continues to grow in scale and complexity. The National Cyber Security Strategy (NCSS) recognised that to achieve the desired outcomes over the five years of the strategy required the UK Government to intervene more actively and to use increased investment. The NCSS is supported by £1.9billion of transformational investment up until 2021. Active Cyber Defence: Through the National Cyber Security Centre, the UK has taken an interventionist approach aimed at making the UK an unattractive target to criminals or states. The UK’s Active Cyber Defence Programme (ACD) is an automated set of interventions intended to tackle a range of commodity attacks. It aims to tackle, in a relatively automated way, a significant proportion of the cyberattacks that hit the UK. In other words, ACD aims to protect the majority of people in the UK from the majority of the harm, caused by the majority of the attacks, for the majority of the time. This has demonstrated that there are targeted interventions that governments can take – alongside the private sector – to improve the digital homeland. UK ACD measures have: 3 https://www.legislation.gov.uk/ukpga/1990/18/contents 4 https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/55 5607/2015_Strategic_Defence_and_Security_Review.pdf

Select target paragraph3