Switzerland's position paper on the application of international law in cyberspace
in turn to respect the territorial integrity of the neutral country. Therefore they may not conduct
related cyber operations from installations that are either on the territory or under the exclusive
control of the neutral country. 15 Parties to the conflict are also prohibited from taking control of
a neutral country's computer systems in order to carry out such operations. 16
Because of the global cross border nature of cyberspace, there are also limits to the rights
and duties of a neutral country in terms of territoriality – airspace can be closed for certain
flying objects, for example, but the same targeted approach cannot be used for data traffic on
the internet. Another issue is that data are not only transmitted via terrestrial and cable
channels but also via satellites located in outer space, which puts them outside the scope of
application of the law of neutrality. Such factors must be taken into consideration when it
comes to applying the rights and duties of neutral countries in cyberspace.
In principle, belligerent states are not permitted to damage the data networks of neutral
countries when undertaking combat operations via their own computer networks. Neutral
countries may not support conflicting parties with either troops or their own weapons. In terms
of military cyber operations in connection with an international armed conflict, this means that
a neutral country must prevent parties to the conflict from using its military-controlled systems
or networks. In general, military networks are shielded and not publicly accessible.
6.
State responsibility
The customary international rules on state responsibility are largely reflected in the draft
articles issued by International Law Commission. 17 They are also applicable to cyber incidents.
They provide that any state action in violation of international law shall entail the international
responsibility of that state, upon which a claim for full reparation may be made. This only
applies if the action can be legally attributed to the state and is deemed to constitute an
internationally wrongful act, i.e. in violation of international law.
6.1. Attribution
Attribution of a cybersecurity incident refers to the identification of the perpetrator and
describes a holistic, interdisciplinary process. This includes analysing the technical and legal
aspects of the incident, factoring in the geopolitical context, and using the entire intelligence
spectrum for the purpose of gathering information. Using this approach, a state can attribute a
cyber incident to another state or a private actor, either publicly or not, and it can decide to
take further political measures.
The process described above includes legal attribution, which ascertains whether a cyber
incident can be legally attributed to a state and if that state can be held responsible under
international law in accordance with the rules on state responsibility; it also concerns how the
injured state may respond (known as countermeasures, see section 6.2). The conduct of any
state organ or person exercising an inherently governmental function is always legally
15
16
17
Art. 2 and Art. 3 Convention Respecting the Rights and Duties of Neutral Pow ers and Persons in Case of
War on Land (Hague V), 18 October 1907, SR 0.515.21; Art. 2 and Art. 5 Convention Concerning the Rights
and Duties of Neutral Pow ers in Naval War (Hague XIII), 18 October 1907, SR 0.515.22.
Art. 1 Convention Respecting the Rights and Duties of Neutral Pow ers and Persons in Case of War on
Land (Hague V), 18 October 1907, SR 0.515.21.
ILC Draft Articles on the Responsibility of States for Internationally Wrongful Acts, August 2001.
5/11