The existence of physical damage is assessed purely on objective and technical grounds. It
is a factual question and as such does not depend on the subjective perception or the
manner in which the other side chooses to address the loss or impairment of functionality.
Finally, the fact that a cyber operation is not an attack does not mean that no legal limitations
apply thereto. Indeed, there are general obligations in LOAC that apply to all military
operations regardless of being attacks or not. Central among those is the requirement to
consider the danger posed to the civilian population in the conduct of military operations. It is
widely accepted today that parties to conflicts cannot blatantly disregard such harmful effects
to the civilian population in their military operations. But there are also more specific
protections that may apply to actions other than attacks. For example, cyber operations
affecting medical units are regulated and limited, inter alia, by the LOAC obligation to respect
and protect medical units, which applies regardless of whether the act constitutes an attack
or not.
Moving on from the issue of attack, another question which is especially relevant to the cyber
domain is whether the term “object”, as it is understood in LOAC, encompasses computer
data. This bears implications with regard to the implementation of the LOAC rules relating to
distinction, precautions and proportionality.
Objects for the purposes of LOAC have always been understood to be tangible things and
this understanding is not domain-specific. It is therefore our position that, under the law of
armed conflict, as it currently stands, only tangible things can constitute objects.
Here, again, this does not mean that cyber operations adversely affecting computer data are
unregulated. In particular, when an operation involving the deletion or alteration of computer
data is still reasonably expected to cause physical damage to objects or persons and fulfills
the other elements required to constitute an attack, the operation would be subject to LOAC
targeting rules. Likewise, one must have regard to rules, which are not dependent on the
concept of objects, such as the obligation to respect and protect medical units.
Observations on other legal issues pertinent to cyber operations
Now, in addition to the jus ad bellum and LOAC, there are other legal frameworks pertinent
to cyber operations that do not center on armed conflicts. Given their importance, I believe it
is valuable to address them shortly, and perhaps leave some room for further thought.
I will start by addressing perhaps the broadest topic, which continues to be a subject of
vibrant discussion: sovereignty. To begin with, there are diverging views regarding whether
sovereignty is merely a principle, from which legal rules are derived, or a binding rule of
international law in itself, the violation of which could be considered an internationally
wrongful act. This issue has many facets, and while I will not offer any definitive position for
the time being, I would like to stress a number of important point.
5/9