I’ll start by stating the obvious: the law of armed conflict and its fundamental principles
generally apply to cyber operations conducted in the context of an armed conflict. Indeed,
“the right of belligerents to adopt means of injuring the enemy is not unlimited,” even in the
cyber domain.
Israel is a party to the Four Geneva Conventions and other treaties[1] governing particular
aspects of conduct in armed conflict and is also bound by applicable customary law. Israel –
like the United States and others – is not a party to the Additional Protocols and is not bound
by them as a matter of treaty law. However, we see the following as consistent with the
relevant customary law and the Additional Protocols.
One of the key issues, in the conduct of hostilities in particular, is how to define “attacks”, and
in which circumstances cyber operations amount to attacks under LOAC. The concept of
attack is central to targeting operations and only acts amounting to attacks are subject to the
“targeting rules” relating to distinction, precautions and proportionality.
The definition of attack in LOAC requires several elements, but I will focus on those aspects
carrying special relevance in the cyber context. Specifically, I will address the element
requiring that an act will constitute an attack only if it is expected to cause death or injury to
persons or physical damage to objects, beyond de minimis.
One aspect of this element concerns the reasonably expected consequences of the act in
question. Reasonably expected consequences are those that are anticipated with some
likelihood of occurrence, and entail adequate causal proximity to the act.
A second aspect in this element is the type of required damage. The requirement for physical
damage has been accepted law since the introduction of the legal term of art attack into the
LOAC discourse. For this reason, practices such as certain types of electronic warfare,
psychological warfare, economic sanctions, seizure of property and detention have never
been considered to be attacks as such, and accordingly, were not considered as subject to
LOAC targeting rules.
Only when a cyber operation is expected to cause physical damage, will it satisfy this
element of an attack under LOAC. In the same vein, the mere loss or impairment of
functionality to infrastructure would be insufficient in this regard, and no other specific rule to
the contrary has evolved in the cyber domain.
However, if an impediment to functionality is caused by physical damage, or when an act
causing the loss of functionality is a link in a chain of the expected physical damage, that act
may amount to an attack. For example, if a cyber operation is intended to shut down
electricity in a military airfield, and as a result is expected to cause the crash of a military
aircraft – that operation may constitute an attack (subject, of course, to the additional
elements for attacks under LOAC).
4/9