remain as to the military use of the object under consideration, it shall be presumed not to
be so used.39
The benchmark for the application of the principle of distinction is the effect caused by a
cyber attack, irrespective of whether it is exercised in an offensive or a defensive context.
Thus, computer viruses designed to spread their harmful effects uncontrollably cannot
distinguish properly between military and civilian computer systems as is required under IHL
and their use is therefore prohibited as an indiscriminate attack. In contrast, malware that
spreads widely into civilian systems but damages only a specific military target does not
violate the principle of distinction. Given the complexity of cyber attacks, the limited options
to comprehensively appraise their nature and effects and the high probability of an impact
on civilian systems, having recourse to the appropriate expertise to assess potential
indiscriminate effects throughout the mission planning process is of key importance to
Germany.
A cyber attack directed against a military target which is nevertheless expected to cause
incidental loss of civilian life, injury to civilians, damage to civilian objects, or a
combination thereof, is also prohibited under IHL if such incidental effects would be
excessive in relation to the concrete and direct military advantage anticipated.40 If a cyber
attack is executed in conjunction with other forms of military action, such as attacks with
conventional weapons directed against the same installation, the military advantage and the
collateral damage must be considered with regard to the ‘attack […] as a whole and not only
[…] [with regard to] isolated or particular parts of the attack.’41
Assessing collateral damage and incidental injury or loss of life when conducting a
proportionality analysis can be even more difficult in the context of cyber operations as
compared to more traditional, i.e. physical, means or methods of warfare. This however does
not discharge those planning and coordinating attacks from taking into account their
foreseeable direct and indirect effects.
(2) The obligation to take precaution in planning and executing a cyber attack
A corollary to the prohibition of indiscriminate cyber attacks is the duty to take constant care
to spare the civilian population, civilians and civilian objects during hostilities involving cyber
operations.42
Those who plan, approve or execute attacks must take all feasible precautions in the
choice of means and methods with a view to avoiding, and in any event minimizing,
39
40
41
42
Additional Protocol I (note 35), art. 52 para. 3.
Additional Protocol I (note 35), art. 51 para. 5 (b); Tallinn Manual 2.0 (note 4), rule 113.
Declarations made by Germany at the time of ratification of Additional Protocol I (note 35), see ‘Bekanntmachung
über das Inkrafttreten der Zusatzprotokolle I und II zu den Genfer Rotkreuz-Abkommen von 1949’ (Notice
concerning the entry into force of Additional Protocols I and II to the 1949 Geneva Red Cross Conventions), 30
July 1991, BGBl. 1991 II, 968, 969; Tallinn Manual 2.0 (note 4), rule 113, commentary, para. 10.
Additional Protocol I (note 35), art. 57 para. 1; Tallinn Manual 2.0 (note 4), rule 114.
9