disclose the attack, the attribution, or any ensuing actions taken – for diverse reasons such
as national security and foreign relations. Either way, as a matter of international law, the
choice whether or not to disclose the attribution information remains at the exclusive
discretion of the State.
With respect to the issue of countermeasures, I would like to echo the positions taken by the
UK, the US and other States, to the effect that there is no absolute duty under international
law to notify the responsible State in advance of a cyber-countermeasure. Prior notification is
perhaps more realistic and practical in fields such as international trade, allowing the
responsible State to reconsider its actions without frustrating the ability of the injured State to
take the intended countermeasures. However, in the cyber domain, where the pace of events
can be extremely fast and the other side may thwart the action if it anticipates it, announcing
a cyber-countermeasure in advance would often negate its utility and effectiveness, and in
some instances undermine the interests of the injured State, as well as render the
countermeasure obsolete.
Concluding Remarks
One last point: I have focused thus far on cyber operations, but it is important to keep in mind
that the application of international law to cyberspace is much broader than the issues I
touched upon. Questions relating to cybersecurity, cybercrime, digital trade, and human
rights in the cyber domain, are just a few examples. I think that international law has a crucial
role to play in addressing these topics. By focusing on these topics, international law can
contribute to enhancing global stability in a concrete way. We hope to share our views on
these and other topics as well in due course.
I wish to conclude my remarks by taking a step back. In the discussions that we are having
on the application of international law in dealing with emerging technologies, I think that the
challenges lie not in identifying the basic rules of international law – the prohibition on the
use of force, self-defense, non-intervention, territorial sovereignty, etc. – but in determining
when and how they apply in new circumstances. Picture the land, air, and sea domains of
international law as independent trees, each with its own branches and leaves, each yielding
its own fruit. Each of these trees is sustained by common ingredients – soil, water, sunlight –
yet each tree grows differently, depending on the external conditions, the type of seeds sown
and how the roots grow. We now have a new tree whose roots are just beginning to take
shape – international law of cyber operations is a nascent field. It is emerging from the same
grounds of international law, the same core principles at the heart of the international system,
and its leaves and fruits will bear some similarities to the other fields of law – but we do not
expect that it will be identical, once fully grown. So, while the vast majority of States agree on
the starting point of the application of international law to cyber operations, the international
community is still very much at the beginning of the journey and the applicability of each
existing rule of international law to the cyber domain requires careful assessment and review.
Thanks again for inviting me to speak here today. I look forward to your questions.
8/9