reiterated by U.S. DOD General Counsel Paul C. Ney, Jr. that a “cyber operation by a State
that interferes with another country’s ability to hold an election or that manipulates another
country’s election results would be a clear violation of the rule of non-intervention.”
I will now turn into addressing three somewhat related topics: due diligence, attribution and
countermeasures.
The concept of due diligence means that States should take reasonable measures to avoid
or minimize harm to other States, and seems to be useful in fields such as international
environmental law. In the 2015 UN GGE Report the concept was addressed as the basis for
a voluntary, non-binding norm of responsible State behavior, providing that States should not
allow their territory to be used for the commission of international wrongful acts. There was
wisdom in mentioning it in the chapter covering norms of responsible State behavior, as it
does not, at this point in time, translate into a binding rule of international law in the cyber
context. This was the position expressed by other States as well.
As I mentioned regarding the examples of maritime blockade and neutrality, we have to be
careful in applying to the cyber domain rules that emerged in a different, distinct context. For
instance, in the field of environmental law, where much of the focus and application of due
diligence obligations has been in recent years, the acting State typically has control, or at
least oversight, over the harmful activity (for example, regulating a polluting power plant).
However, cyberspace is mostly private and decentralized.
The inherent different features of cyberspace – its decentralization and private
characteristics – incentivize cooperation between States on a voluntary basis, such as with
the case of national Computer Emergency Response Teams (CERTs). CERTs are already
doing what could arguably fall into that category: exchanging information with one another,
as well as cooperating with each other in mitigating incidents. However, we have not seen
widespread State practice beyond this type of voluntary cooperation, and certainly not
practice grounded in some overarching opinio juris, which would be indispensable for a
customary rule of due diligence, or something similar to that, to form.
The issue of attribution is also widely debated with respect to cyber operations. Some have
suggested that there needs to be more legal certainty with respect to attribution, in order to
avoid mistaken attribution, which can lead to conflict escalation. This is increasingly
becoming more of a theoretical issue. Over time, the attribution capabilities of States have
improved, and even States with lesser capabilities have been able to rely on solid
information provided by other States and by the private sector. In any event, this is a
technical matter – a factual one – and I would advise against over-regulating the issue.
That being said, there is also the question of public perceptions – because sometimes, when
an offensive cyber operation is public and the attribution is public, the government needs to
communicate with its citizens, and with the international community at large, in order for its
positions and actions to be understood. But there will be cases when a State will prefer not to
7/9