Switzerland's position paper on the application of international law in cyberspace in turn to respect the territorial integrity of the neutral country. Therefore they may not conduct related cyber operations from installations that are either on the territory or under the exclusive control of the neutral country. 15 Parties to the conflict are also prohibited from taking control of a neutral country's computer systems in order to carry out such operations. 16 Because of the global cross border nature of cyberspace, there are also limits to the rights and duties of a neutral country in terms of territoriality – airspace can be closed for certain flying objects, for example, but the same targeted approach cannot be used for data traffic on the internet. Another issue is that data are not only transmitted via terrestrial and cable channels but also via satellites located in outer space, which puts them outside the scope of application of the law of neutrality. Such factors must be taken into consideration when it comes to applying the rights and duties of neutral countries in cyberspace. In principle, belligerent states are not permitted to damage the data networks of neutral countries when undertaking combat operations via their own computer networks. Neutral countries may not support conflicting parties with either troops or their own weapons. In terms of military cyber operations in connection with an international armed conflict, this means that a neutral country must prevent parties to the conflict from using its military-controlled systems or networks. In general, military networks are shielded and not publicly accessible. 6. State responsibility The customary international rules on state responsibility are largely reflected in the draft articles issued by International Law Commission. 17 They are also applicable to cyber incidents. They provide that any state action in violation of international law shall entail the international responsibility of that state, upon which a claim for full reparation may be made. This only applies if the action can be legally attributed to the state and is deemed to constitute an internationally wrongful act, i.e. in violation of international law. 6.1. Attribution Attribution of a cybersecurity incident refers to the identification of the perpetrator and describes a holistic, interdisciplinary process. This includes analysing the technical and legal aspects of the incident, factoring in the geopolitical context, and using the entire intelligence spectrum for the purpose of gathering information. Using this approach, a state can attribute a cyber incident to another state or a private actor, either publicly or not, and it can decide to take further political measures. The process described above includes legal attribution, which ascertains whether a cyber incident can be legally attributed to a state and if that state can be held responsible under international law in accordance with the rules on state responsibility; it also concerns how the injured state may respond (known as countermeasures, see section 6.2). The conduct of any state organ or person exercising an inherently governmental function is always legally 15 16 17 Art. 2 and Art. 3 Convention Respecting the Rights and Duties of Neutral Pow ers and Persons in Case of War on Land (Hague V), 18 October 1907, SR 0.515.21; Art. 2 and Art. 5 Convention Concerning the Rights and Duties of Neutral Pow ers in Naval War (Hague XIII), 18 October 1907, SR 0.515.22. Art. 1 Convention Respecting the Rights and Duties of Neutral Pow ers and Persons in Case of War on Land (Hague V), 18 October 1907, SR 0.515.21. ILC Draft Articles on the Responsibility of States for Internationally Wrongful Acts, August 2001. 5/11

Select target paragraph3