incidental loss of civilian life, injury to civilians and damage to civilian objects.43 This might
encompass gathering intelligence on the network in question through mapping or other
processes in order to assess the attack’s likely effects. Also, the inclusion of a deactivation
mechanism or a specific configuration of the cyber tool which limits the effects on the
intended target might be considered. Moreover, if it becomes apparent that the target is not
a military one or is subject to special protection, those who plan, approve or execute the
cyber attack must refrain from executing or suspend the attack. The same applies when the
attack may be expected to cause excessive collateral damage to civilians and civilian
objects.44
The obligation to take precautions in attack is complemented by the obligation to conduct
weapon reviews of any new means or method of cyber warfare to determine whether its
employment would, in some or in all circumstances, be prohibited by international law.45 The
findings of such reviews, to the extent that they identify legal constraints for the
employment of means and methods in particular operational settings, should serve as a basis
for operational planning. However, the means and methods used in cyber warfare are
typically tailored to their targets, as they generally involve exploiting vulnerabilities that are
specific to the target and the operational context. This entails that the development of
means or the adoption of the method will often coincide with the planning of a concrete
operation. Thus, the obligation to take precautions in attack and the requirement of a legal
review remain separate requirements, but may overlap in substance.
IV. States’ response options
a) Attribution
Attributing a cyber incident is of critical importance as a part of holding States responsible
for wrongful behaviour and for documenting norm violations in cyberspace. It is also a
prerequisite for certain types of responsive action. As regards the attribution of certain acts
to States under international law, Germany applies the relevant customary law rules on
State responsibility also to acts in cyberspace, subject to any lex specialis provisions. Inter
alia, cyber operations conducted by State organs are attributable to the State in question.46
The same applies with regard to persons or entities which are empowered by the law of a
State to exercise elements of the governmental authority and act in that capacity in the
particular instance.47 Attribution is not excluded because such organ, person or entity acting
in an official capacity exceeds its authority or contravenes instructions – cyber operations
43
44
45
46
47
Cf. Additional Protocol I (note 35), art. 57 para. 2 (a) (ii); Tallinn Manual 2.0 (note 4), rule 116.
Additional Protocol I (note 35), art. 57 para. 2 (a) (iii); art. 57 para. 2 (b); Tallinn Manual 2.0 (note 4), rules 117, 119.
In Germany, the legal review is carried out by the steering committee for the review of new weapons and methods
of warfare under the direction of the Directorate-General for Legal Affairs, Joint service regulation A 2146/1.
Cf. International Law Commission (ILC), Draft Articles on Responsibility of States for Internationally Wrongful
Acts, 2001, in: Report of the International Law Commission on the work of its fifty-third session, 23 April – 1 June
and 2 July – 10 August 2001, Official Records of the General Assembly, Fifty-sixth Session, Supplement No. 10,
UN Doc. A/56/10, 26 et seq., art. 4; Tallinn Manual 2.0 (note 4), rule 15.
Cf. Draft Articles on State Responsibility (note 46), art. 5; Tallinn Manual 2.0 (note 4), rule 15.
10