Switzerland's position paper on the application of international law in cyberspace
permissible. Cyber countermeasures do not have to directly target the computer system
originally used to commit the incident in question; injured states are permitted to take other
measures as long as they are aimed at the responsible state ceasing its conduct that is in
breach of international law. This means that depending on the specific circumstances, it may
be permissible under international law to use cyber countermeasures to block the computer
system abroad originally used to commit the incident. Likewise, in some cases it may be
permissible to compromise computer systems abroad even if they were not the original source
of the incident.
In addition to countermeasures, the rules governing state responsibility also provide for special
circumstances precluding the wrongfulness of conduct that would otherwise not be in
conformity with the international obligations of the state concerned. For example, a state may
be exempted from complying with such an obligation if it is the only way for it to safeguard its
essential interests from grave and imminent peril. Therefore the narrowly defined exceptions
provided for by the rules governing state responsibility may also apply in the context of cyber
operations.23
6.3. Due diligence
The principle of due diligence has evolved over a long period of time. Switzerland views due
diligence as part of customary international law and applicable to cyberspace. The ICJ
describes the concept of due diligence as a standard of conduct mean ing "every State's
obligation not to allow knowingly its territory to be used for acts contrary to the rights of other
States."24 The doctrine of due diligence reflects fundamental principles of international law
(including state sovereignty, equality, territorial integrity and non-interference).
The principle of due diligence is also applicable to cyberspace. Consequently, a state that is
or should be aware of cyber incidents that violate the rights of another state is obliged to take
all reasonable measures that are appropriate to stop or minimise the risks of such incidents.
Due diligence is a variable standard and depends on the capacities and capabilities of a state
as well as the particular circumstances of each case. Territorial states are obliged to use all
reasonable means to prevent serious harm being caused to another state by activities taking
place within their territory or in an area under their effective control. This makes due diligence
an obligation of conduct, not of result. If the aforementioned conditions exist, the state in
question is obliged under international law to close any loopholes immediately and assist in
intercepting and tracing the incident.
Due diligence applies in particular to actions by private individuals that violate the rights of
other states (e.g. hackers) and cannot be (clearly) attributed to the state in accordance with
the rules of attribution (see section 6.1). If the aforementioned conditions exist and the state
in question fails to fulfil due diligence requirements, the injured state may take
countermeasures in accordance with the rules governing state responsibility in order to induce
the responsible state to meet its obligations. Possible countermeasures outlined above may
be taken both outside and inside the cyber domain. The responsible state may also be
required to make reparations. 25
23
24
25
Chapter V, ILC Draft Articles on the Responsibility of States for Internationally Wrongful Acts, August 2001.
Corfu Channel case, ICJ Reports 1949, para. 44. Due diligence is both a general principle of international
law , w idely recognised as part of customary international law , and a prominent legal element in various
international agreements w here it has been enshrined, defined and further developed (e.g. environmental
law , human rights law , IHL, global health law ).
Art. 31, ILC Draft Articles on the Responsibility of States for Internationally Wrongful Acts, August 2001.
7/11