I’ll start by stating the obvious: the law of armed conflict and its fundamental principles generally apply to cyber operations conducted in the context of an armed conflict. Indeed, “the right of belligerents to adopt means of injuring the enemy is not unlimited,” even in the cyber domain. Israel is a party to the Four Geneva Conventions and other treaties[1] governing particular aspects of conduct in armed conflict and is also bound by applicable customary law. Israel – like the United States and others – is not a party to the Additional Protocols and is not bound by them as a matter of treaty law. However, we see the following as consistent with the relevant customary law and the Additional Protocols. One of the key issues, in the conduct of hostilities in particular, is how to define “attacks”, and in which circumstances cyber operations amount to attacks under LOAC. The concept of attack is central to targeting operations and only acts amounting to attacks are subject to the “targeting rules” relating to distinction, precautions and proportionality. The definition of attack in LOAC requires several elements, but I will focus on those aspects carrying special relevance in the cyber context. Specifically, I will address the element requiring that an act will constitute an attack only if it is expected to cause death or injury to persons or physical damage to objects, beyond de minimis. One aspect of this element concerns the reasonably expected consequences of the act in question. Reasonably expected consequences are those that are anticipated with some likelihood of occurrence, and entail adequate causal proximity to the act. A second aspect in this element is the type of required damage. The requirement for physical damage has been accepted law since the introduction of the legal term of art attack into the LOAC discourse. For this reason, practices such as certain types of electronic warfare, psychological warfare, economic sanctions, seizure of property and detention have never been considered to be attacks as such, and accordingly, were not considered as subject to LOAC targeting rules. Only when a cyber operation is expected to cause physical damage, will it satisfy this element of an attack under LOAC. In the same vein, the mere loss or impairment of functionality to infrastructure would be insufficient in this regard, and no other specific rule to the contrary has evolved in the cyber domain. However, if an impediment to functionality is caused by physical damage, or when an act causing the loss of functionality is a link in a chain of the expected physical damage, that act may amount to an attack. For example, if a cyber operation is intended to shut down electricity in a military airfield, and as a result is expected to cause the crash of a military aircraft – that operation may constitute an attack (subject, of course, to the additional elements for attacks under LOAC). 4/9

Select target paragraph3