be qualified as a use of force if its scale and effects reached the same level as those of the use of
force in non-cyber operations.
International law does not provide a clear definition of ‘use of force’. The government endorses the
generally accepted position that each case must be examined individually to establish whether the
‘scale and effects’ are such that an operation may be deemed a violation of the prohibition of use of
force. In their 2011 advisory report ‘Cyber Warfare’, the Advisory Council on International Affairs
(AIV) and the Advisory Committee on Issues of Public International Law (CAVV) noted that, ‘The
customary interpretation of this provision is that all forms of armed force are prohibited. Purely
economic, diplomatic and political pressure or coercion is not defined as force under article 2,
paragraph 4. Suspending trade relations or freezing assets, for example, can be very
disadvantageous to the state affected but has not to date been considered a prohibited form of force
within the meaning of the Charter. Armed force that has a real or potential physical impact on the
target state is prohibited.’ 8 In the view of the government, at this time it cannot be ruled out that a
cyber operation with a very serious financial or economic impact may qualify as the use of force.
It is necessary, when assessing the scale and effects of a cyber operation, to examine both
qualitative and quantitative factors. The Tallinn Manual 2.0 refers to a number of factors that could
play a role in this regard, including how serious and far-reaching the cyber operation’s consequences
are, whether the operation is military in nature and whether it is carried out by a state. 9 These are
not binding legal criteria. They are factors that could provide an indication that a cyber operation
may be deemed a use of force, and the government endorses this approach. It should be noted in
this regard that a cyber operation that falls below the threshold of use of force may nonetheless be
qualified as a prohibited intervention or a violation of sovereignty.
The due diligence principle
The due diligence principle holds that states are expected to take account of other states’ rights
when exercising their own sovereignty. The principle is articulated by the International Court of
Justice, for example, in its judgment in the Corfu Channel Case, 10 in which it held that states have
an obligation to act if they are aware or become aware that their territory is being used for acts
contrary to the rights of another state. It should be noted that not all countries agree that the due
diligence principle constitutes an obligation in its own right under international law. The Netherlands,
however, does regard the principle as an obligation in its own right, the violation of which may
constitute an internationally wrongful act.
In the context of cyberspace, the due diligence principle requires that states take action in respect
of cyber activities:
-
carried out by persons in their territory or where use is made of items or networks that
are in their territory or which they otherwise control;
that violate a right of another state; and
whose existence they are, or should be, aware of. 11
To this end a state must take measures which, in the given circumstances, may be expected of a
state acting in a reasonable manner. It is not relevant whether the cyber activity in question is
carried out by a state or non-state actor, or where this actor is located. If, for example, a cyberattack
is carried out against the Netherlands using servers in another country, the Netherlands may, on
the basis of the due diligence principle, ask the other country to shut down the servers, regardless
of whether or not it has been established that a state is responsible for the cyberattack.
‘Cyber Warfare’, Advisory report no 77, AIV/no. 22, CAVV December 2011, p. 20.
Tallinn Manual 2.0, Rule 69.
10
Corfu Channel Case; Assessment of Compensation (United Kingdom v. Albania), International Court of Justice
(ICJ), 9 April 1949, para. 22.
11
Corfu Channel Case; Assessment of Compensation (United Kingdom v. Albania), International Court of Justice
(ICJ), 9 April 1949, para 44. The International Court of Justice concluded that the constructive knowledge
standard of the due diligence principle (within the meaning of international law) is also met if a state should
have known that the activity in question took place on its territory. Specifically this means that a state has an
obligation to do everything feasible. Precisely what constitutes fulfilment of this requirement in the context of
cyberspace is currently still a matter of debate.
8
9
4