incidental loss of civilian life, injury to civilians and damage to civilian objects.43 This might encompass gathering intelligence on the network in question through mapping or other processes in order to assess the attack’s likely effects. Also, the inclusion of a deactivation mechanism or a specific configuration of the cyber tool which limits the effects on the intended target might be considered. Moreover, if it becomes apparent that the target is not a military one or is subject to special protection, those who plan, approve or execute the cyber attack must refrain from executing or suspend the attack. The same applies when the attack may be expected to cause excessive collateral damage to civilians and civilian objects.44 The obligation to take precautions in attack is complemented by the obligation to conduct weapon reviews of any new means or method of cyber warfare to determine whether its employment would, in some or in all circumstances, be prohibited by international law.45 The findings of such reviews, to the extent that they identify legal constraints for the employment of means and methods in particular operational settings, should serve as a basis for operational planning. However, the means and methods used in cyber warfare are typically tailored to their targets, as they generally involve exploiting vulnerabilities that are specific to the target and the operational context. This entails that the development of means or the adoption of the method will often coincide with the planning of a concrete operation. Thus, the obligation to take precautions in attack and the requirement of a legal review remain separate requirements, but may overlap in substance. IV. States’ response options a) Attribution Attributing a cyber incident is of critical importance as a part of holding States responsible for wrongful behaviour and for documenting norm violations in cyberspace. It is also a prerequisite for certain types of responsive action. As regards the attribution of certain acts to States under international law, Germany applies the relevant customary law rules on State responsibility also to acts in cyberspace, subject to any lex specialis provisions. Inter alia, cyber operations conducted by State organs are attributable to the State in question.46 The same applies with regard to persons or entities which are empowered by the law of a State to exercise elements of the governmental authority and act in that capacity in the particular instance.47 Attribution is not excluded because such organ, person or entity acting in an official capacity exceeds its authority or contravenes instructions – cyber operations 43 44 45 46 47 Cf. Additional Protocol I (note 35), art. 57 para. 2 (a) (ii); Tallinn Manual 2.0 (note 4), rule 116. Additional Protocol I (note 35), art. 57 para. 2 (a) (iii); art. 57 para. 2 (b); Tallinn Manual 2.0 (note 4), rules 117, 119. In Germany, the legal review is carried out by the steering committee for the review of new weapons and methods of warfare under the direction of the Directorate-General for Legal Affairs, Joint service regulation A 2146/1. Cf. International Law Commission (ILC), Draft Articles on Responsibility of States for Internationally Wrongful Acts, 2001, in: Report of the International Law Commission on the work of its fifty-third session, 23 April – 1 June and 2 July – 10 August 2001, Official Records of the General Assembly, Fifty-sixth Session, Supplement No. 10, UN Doc. A/56/10, 26 et seq., art. 4; Tallinn Manual 2.0 (note 4), rule 15. Cf. Draft Articles on State Responsibility (note 46), art. 5; Tallinn Manual 2.0 (note 4), rule 15. 10

Select target paragraph3