remain as to the military use of the object under consideration, it shall be presumed not to be so used.39 The benchmark for the application of the principle of distinction is the effect caused by a cyber attack, irrespective of whether it is exercised in an offensive or a defensive context. Thus, computer viruses designed to spread their harmful effects uncontrollably cannot distinguish properly between military and civilian computer systems as is required under IHL and their use is therefore prohibited as an indiscriminate attack. In contrast, malware that spreads widely into civilian systems but damages only a specific military target does not violate the principle of distinction. Given the complexity of cyber attacks, the limited options to comprehensively appraise their nature and effects and the high probability of an impact on civilian systems, having recourse to the appropriate expertise to assess potential indiscriminate effects throughout the mission planning process is of key importance to Germany. A cyber attack directed against a military target which is nevertheless expected to cause incidental loss of civilian life, injury to civilians, damage to civilian objects, or a combination thereof, is also prohibited under IHL if such incidental effects would be excessive in relation to the concrete and direct military advantage anticipated.40 If a cyber attack is executed in conjunction with other forms of military action, such as attacks with conventional weapons directed against the same installation, the military advantage and the collateral damage must be considered with regard to the ‘attack […] as a whole and not only […] [with regard to] isolated or particular parts of the attack.’41 Assessing collateral damage and incidental injury or loss of life when conducting a proportionality analysis can be even more difficult in the context of cyber operations as compared to more traditional, i.e. physical, means or methods of warfare. This however does not discharge those planning and coordinating attacks from taking into account their foreseeable direct and indirect effects. (2) The obligation to take precaution in planning and executing a cyber attack A corollary to the prohibition of indiscriminate cyber attacks is the duty to take constant care to spare the civilian population, civilians and civilian objects during hostilities involving cyber operations.42 Those who plan, approve or execute attacks must take all feasible precautions in the choice of means and methods with a view to avoiding, and in any event minimizing, 39 40 41 42 Additional Protocol I (note 35), art. 52 para. 3. Additional Protocol I (note 35), art. 51 para. 5 (b); Tallinn Manual 2.0 (note 4), rule 113. Declarations made by Germany at the time of ratification of Additional Protocol I (note 35), see ‘Bekanntmachung über das Inkrafttreten der Zusatzprotokolle I und II zu den Genfer Rotkreuz-Abkommen von 1949’ (Notice concerning the entry into force of Additional Protocols I and II to the 1949 Geneva Red Cross Conventions), 30 July 1991, BGBl. 1991 II, 968, 969; Tallinn Manual 2.0 (note 4), rule 113, commentary, para. 10. Additional Protocol I (note 35), art. 57 para. 1; Tallinn Manual 2.0 (note 4), rule 114. 9

Select target paragraph3