15. In general, the impact or severity of cyber effects will be evaluated in the same
manner and according to the same criteria as for physical activities. Cyber activities
that rise above a level of negligible or de minimis effects, causing significant harmful
effects within the territory of another State without that State’s consent, could
amount to a violation of the rule of territorial sovereignty with respect to the affected
State. It is also important to note that cyber activities with effects in another State do
not constitute physical presence in the territory of that State. As such, territorial
sovereignty is not violated by virtue merely of remote activities having been carried
out on or through the cyber infrastructure located within the territory of another
State. Furthermore, cyber activities carried out remotely from within Canada with
negligible effects in a foreign State do not involve an extraterritorial exercise of
enforcement jurisdiction by Canada.
16. Cyber activities that cause a loss of functionality with respect to cyber infrastructure
located within the territory of the affected State may also constitute a violation of
territorial sovereignty if the resulting loss of functionality causes significant harmful
effects similar to those caused by physical damage to persons or property. For
example, a violation of the territorial sovereignty will occur when the cyber activity
creates a significant harmful effect that necessitates the repair or replacement of
physical components of cyber infrastructure in the affected State. The loss of
functionality of physical equipment that relies on the affected infrastructure in order
to operate could also form part of the violation. The assessment of the effects
includes both intended and unintended consequences that reach the threshold
required to trigger a violation.
17. The rule of territorial sovereignty does not require consent for every cyber activity
that has effects, including some loss of functionality, in another State. Activities
causing negligible or de minimis effects would not constitute a violation of territorial
sovereignty regardless of whether they are conducted in the cyber or non-cyber
context. Nor are States precluded by the rule of territorial sovereignty from taking
measures that have negligible or de minimis effects to defend against the harmful
activity of malicious cyber actors or to protect their national security interests. For
example, Canada considers that a cyber activity that requires rebooting or the
reinstallation of an operating system is likely not a violation of territorial sovereignty.
18. The other key basis for assessing a violation of territorial sovereignty is whether a
cyber activity interferes with or usurps the inherently governmental functions of
another State. Cyber activities that have significant harmful effects on the exercise
of inherently governmental functions would constitute an internationally wrongful
act. For Canada, this would include government activities in areas such as health
care services, law enforcement, administration of elections, tax collection, national
defence and the conduct of international relations, and the services on which these
depend. There can be a violation of territorial sovereignty by way of effects on
governmental functions regardless of whether there is physical damage, injury, or
loss of functionality. An example would be a cyber activity that interrupts health care
delivery by blocking access to patient health records or emergency room services,
resulting in risk to the health or life of patients.
3/14