be qualified as a use of force if its scale and effects reached the same level as those of the use of force in non-cyber operations. International law does not provide a clear definition of ‘use of force’. The government endorses the generally accepted position that each case must be examined individually to establish whether the ‘scale and effects’ are such that an operation may be deemed a violation of the prohibition of use of force. In their 2011 advisory report ‘Cyber Warfare’, the Advisory Council on International Affairs (AIV) and the Advisory Committee on Issues of Public International Law (CAVV) noted that, ‘The customary interpretation of this provision is that all forms of armed force are prohibited. Purely economic, diplomatic and political pressure or coercion is not defined as force under article 2, paragraph 4. Suspending trade relations or freezing assets, for example, can be very disadvantageous to the state affected but has not to date been considered a prohibited form of force within the meaning of the Charter. Armed force that has a real or potential physical impact on the target state is prohibited.’ 8 In the view of the government, at this time it cannot be ruled out that a cyber operation with a very serious financial or economic impact may qualify as the use of force. It is necessary, when assessing the scale and effects of a cyber operation, to examine both qualitative and quantitative factors. The Tallinn Manual 2.0 refers to a number of factors that could play a role in this regard, including how serious and far-reaching the cyber operation’s consequences are, whether the operation is military in nature and whether it is carried out by a state. 9 These are not binding legal criteria. They are factors that could provide an indication that a cyber operation may be deemed a use of force, and the government endorses this approach. It should be noted in this regard that a cyber operation that falls below the threshold of use of force may nonetheless be qualified as a prohibited intervention or a violation of sovereignty. The due diligence principle The due diligence principle holds that states are expected to take account of other states’ rights when exercising their own sovereignty. The principle is articulated by the International Court of Justice, for example, in its judgment in the Corfu Channel Case, 10 in which it held that states have an obligation to act if they are aware or become aware that their territory is being used for acts contrary to the rights of another state. It should be noted that not all countries agree that the due diligence principle constitutes an obligation in its own right under international law. The Netherlands, however, does regard the principle as an obligation in its own right, the violation of which may constitute an internationally wrongful act. In the context of cyberspace, the due diligence principle requires that states take action in respect of cyber activities: - carried out by persons in their territory or where use is made of items or networks that are in their territory or which they otherwise control; that violate a right of another state; and whose existence they are, or should be, aware of. 11 To this end a state must take measures which, in the given circumstances, may be expected of a state acting in a reasonable manner. It is not relevant whether the cyber activity in question is carried out by a state or non-state actor, or where this actor is located. If, for example, a cyberattack is carried out against the Netherlands using servers in another country, the Netherlands may, on the basis of the due diligence principle, ask the other country to shut down the servers, regardless of whether or not it has been established that a state is responsible for the cyberattack. ‘Cyber Warfare’, Advisory report no 77, AIV/no. 22, CAVV December 2011, p. 20. Tallinn Manual 2.0, Rule 69. 10 Corfu Channel Case; Assessment of Compensation (United Kingdom v. Albania), International Court of Justice (ICJ), 9 April 1949, para. 22. 11 Corfu Channel Case; Assessment of Compensation (United Kingdom v. Albania), International Court of Justice (ICJ), 9 April 1949, para 44. The International Court of Justice concluded that the constructive knowledge standard of the due diligence principle (within the meaning of international law) is also met if a state should have known that the activity in question took place on its territory. Specifically this means that a state has an obligation to do everything feasible. Precisely what constitutes fulfilment of this requirement in the context of cyberspace is currently still a matter of debate. 8 9 4

Select target paragraph3