Authored By: Akanksha Aaditya Hardenia
I. Introduction
The proliferation of digital infrastructure has transformed cyberspace into a fifth domain of State activity, alongside land, sea, air, and outer space. Cyber operations conducted by States and non-State actors now threaten critical infrastructure, financial systems, electoral processes, and military capabilities across the globe. Unlike conventional domains of conflict, cyberspace is borderless, largely privately owned, and characterised by the ease with which malicious actors can obscure their identity. These features have generated a fundamental legal question: does international law, developed largely in the context of physical territory and kinetic force, adequately regulate State conduct in cyberspace?
This article examines the application of international law to cybersecurity, focusing on four central themes: the general applicability of international law to cyberspace, the principle of sovereignty and non-intervention, the law governing the use of force and self-defence, and the practical difficulties of attribution and State responsibility. It further surveys existing normative frameworks, including the Tallinn Manual project, the United Nations Group of Governmental Experts (UN GGE) and Open-Ended Working Group (OEWG) processes, and the Budapest Convention on Cybercrime, before identifying persistent gaps that continue to challenge the international legal order.
II. The Applicability of International Law to Cyberspace
It is now widely accepted, at least as a matter of principle, that existing international law applies to State conduct in cyberspace; no State has seriously argued that cyberspace constitutes a legal vacuum. The Tallinn Manual 2.0, produced by an international group of experts under the auspices of the NATO Cooperative Cyber Defence Centre of Excellence, opens with the proposition that international law applies to cyber operations.
This consensus was echoed by the 2015 UN Group of Governmental Experts, which affirmed that international law, and in particular the Charter of the United Nations, is applicable to State use of information and communications technologies.
Notwithstanding this consensus at the level of principle, considerable disagreement persists concerning how specific rules apply in practice. States differ, for example, on the threshold at which a cyber operation amounts to a prohibited use of force, on whether and how the right of self-defence may be triggered by a cyber attack, and on the precise contours of sovereignty as applied to cyber infrastructure. The result is a body of law that is formally applicable but substantively contested, producing significant uncertainty for States seeking to regulate their own conduct and to respond to hostile operations directed against them.
III. Sovereignty and the Principle of Non-Intervention
Sovereignty is the foundational principle of the international legal order and its application to cyberspace remains one of the most contested questions in the field. Two broad positions have emerged. The first treats sovereignty as a binding primary rule, such that any unauthorised cyber intrusion into another State’s territory, including into servers or infrastructure located there, constitutes a violation of that State’s sovereignty regardless of the operation’s effects. The second, associated principally with the position articulated by the United States, treats sovereignty as a principle informing the interpretation of other rules rather than as a standalone prohibition, leaving greater latitude for low-level cyber espionage and intelligence-gathering operations.
The principle of non-intervention, closely related to sovereignty, prohibits coercive interference by one State in the internal or external affairs of another. The International Court of Justice in the Nicaragua case confirmed that the principle forbids all States from intervening, directly or indirectly, in matters in which each State is permitted to decide freely.
Applied to cyberspace, this principle has been invoked in relation to cyber-enabled electoral interference, disinformation campaigns, and operations targeting a State’s critical infrastructure or financial systems. However, the requirement that intervention be coercive has proven difficult to apply to cyber operations, many of which achieve their effects through subtler means such as the manipulation of information rather than direct compulsion, leaving States and commentators divided over precisely which cyber activities cross the threshold of unlawful intervention.
IV. The Prohibition on the Use of Force
Article 2(4) of the United Nations Charter prohibits the threat or use of force by States against the territorial integrity or political independence of any State.
The prevailing approach for determining whether a cyber operation rises to the level of a use of force is the ‘scale and effects’ test, which asks whether the consequences of a cyber operation are comparable to those produced by traditional kinetic force, drawing on the reasoning of the International Court of Justice in Nicaragua.
Under this approach, a cyber operation that causes physical destruction, injury, or death, such as an attack that damages critical infrastructure or disables a power grid with resulting harm to persons or property, would likely qualify as a use of force. Conversely, cyber operations that cause purely economic loss, disruption, or inconvenience, without physical damage, are generally regarded as falling below this threshold, however disruptive they may be in practice. This distinction has proven difficult to apply to hybrid operations, such as those combining cyber intrusion with disinformation, or to cumulative campaigns composed of numerous individually minor incidents that collectively produce significant harm.
V. Self-Defence and the Right to Respond
Article 51 of the Charter preserves the inherent right of individual or collective self-defence in the event of an armed attack, a right widely accepted as extending to cyber operations that meet the requisite threshold of gravity.
A cyber operation must therefore not only qualify as a use of force but rise to the higher threshold of an ‘armed attack’ before a victim State may lawfully invoke self-defence, and any responsive measures must satisfy the customary requirements of necessity and proportionality. In practice, States have more frequently relied on the law of countermeasures, permitting proportionate responses to internationally wrongful acts that fall short of an armed attack, as a more flexible tool for responding to hostile cyber conduct, though countermeasures themselves may not involve the use of force and remain subject to their own procedural constraints, including prior notification requirements that many States regard as ill-suited to the speed of cyber operations.
VI. Attribution and State Responsibility
Perhaps the most significant practical obstacle to the enforcement of international law in cyberspace is attribution. Under the customary rules on State responsibility, a cyber operation is attributable to a State where it is conducted by an organ of that State or by a person or group acting on its instructions or under its direction or control.
Technical attribution, identifying the origin of a cyber operation, is often possible only after prolonged forensic investigation, if at all, given the ease with which malicious actors employ proxy servers, botnets, and false-flag techniques to disguise their location and identity. Legal attribution presents a further, distinct challenge, requiring proof of a sufficient nexus between the State and the operators, a standard that has generated debate over whether the ICJ’s demanding ‘effective control’ test from Nicaragua is appropriately calibrated to State-sponsored proxy operations conducted through loosely affiliated hacking groups, patriotic hackers, or criminal networks operating with a degree of State toleration or encouragement.
The consequence is a persistent accountability gap: States frequently possess high confidence intelligence attributing an operation to a hostile actor, yet are unwilling or unable to disclose the evidentiary basis for that attribution without compromising sensitive sources and methods, or are unable to meet the evidentiary standards that would be demanded before an international tribunal. This gap allows hostile State and State-sponsored conduct to persist with limited practical consequence under international law, even where the underlying primary rules are not seriously in dispute.
VII. Existing International Frameworks
The United Nations Processes
Since 2004, the United Nations has convened successive Groups of Governmental Experts to consider how international law applies to State use of information and communications technologies, culminating in the 2015 report endorsed by consensus at the General Assembly.
A further Group of Governmental Experts reported in 2021, reaffirming the applicability of international law and elaborating a set of voluntary, non-binding norms of responsible State behaviour, including commitments not to knowingly damage critical infrastructure and to respond to requests for assistance from States whose critical infrastructure has been subject to malicious cyber acts.
Alongside the GGE, the Open-Ended Working Group, open to the full UN membership, has continued this work, concluding its most recent mandate with a substantive final report addressing confidence-building measures, capacity-building, and the establishment of a permanent, single-track mechanism for future discussions.
The Tallinn Manual Project
The Tallinn Manual 2.0, though non-binding and produced by independent experts rather than States, represents the most comprehensive attempt to restate how existing international law applies to cyber operations, addressing peacetime legal regimes such as sovereignty, jurisdiction, and State responsibility, alongside the law of armed conflict.
Its influence on State practice and academic discourse has been considerable, frequently cited by national governments in their own statements on the application of international law to cyberspace, even where individual States depart from specific rules proposed by the expert group.
The Budapest Convention on Cybercrime
At the level of criminal law rather than public international law governing State conduct, the Budapest Convention on Cybercrime remains the principal multilateral treaty addressing cybercrime, establishing common offences and facilitating international cooperation and mutual legal assistance among States parties.
Its reach is limited by the relatively small number of States parties outside Europe and the Americas, and by the emergence of a competing instrument, the UN Convention against Cybercrime, reflecting divisions between States over the appropriate balance between international cooperation and concerns regarding human rights and State sovereignty over domestic internet governance.
VIII. Persistent Gaps and Challenges
Despite these developments, significant gaps remain. First, the absence of a binding treaty specifically addressing State cyber conduct leaves the field governed largely by contested interpretations of pre-existing rules and non-binding voluntary norms, a point long recognised by commentators who observe that the ‘law of cyber’ remains an emergent and unsettled body of the law of nations.
Second, the absence of a dedicated international tribunal with compulsory jurisdiction over inter-State cyber disputes means that disagreements over the application of primary rules are rarely authoritatively resolved, leaving States to act as interpreters and enforcers of the law in their own cause. Third, the involvement of private actors, including technology companies that own and operate the majority of global digital infrastructure, sits uneasily within a legal framework built around State-to-State obligations, raising unresolved questions about the extent to which private conduct can trigger, or should be regulated by, public international law.
Fourth, as one senior legal adviser to the US State Department observed in an influential address setting out an early articulation of official government views, the challenge is less a matter of identifying gaps in the substantive rules than of achieving genuine international consensus on how those rules translate into operational practice.
This diagnosis remains apt: the difficulty confronting cybersecurity governance is not primarily one of a normative vacuum, but of translating broadly-worded, generally-applicable rules into operable standards capable of guiding State conduct and resolving disputes in a domain characterised by speed, anonymity, and diffuse private-sector involvement.
IX. Conclusion
International law applies to cyberspace as a matter of settled principle, yet the practical content of that law remains unsettled in critical respects. Sovereignty, the use-of-force threshold, self-defence, and the rules of attribution and State responsibility all sit atop a body of doctrine developed for physical conflict and imperfectly transplanted onto a domain defined by anonymity, speed, and private ownership of infrastructure. The Tallinn Manual, the UN GGE and OEWG processes, and treaties such as the Budapest Convention have made important contributions toward clarifying State obligations, but none constitutes a comprehensive, binding, and universally accepted framework.
Going forward, the international community faces a choice between continuing incremental clarification of existing rules through State practice and expert restatement, or pursuing a dedicated multilateral treaty addressing cyber conduct directly. Given the strategic value that many States attach to ambiguity in this domain, the former path appears more probable in the near term, leaving international law to develop, as it so often has, through the accumulation of practice, dispute, and interpretation rather than through comprehensive codification.
1. Michael N Schmitt (ed), Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations (2nd edn, Cambridge University Press 2017) rule 1.
2. UNGA, ‘Report of the Group of Governmental Experts on Developments in the Field of Information and Telecommunications in the Context of International Security’ (22 July 2015) UN Doc A/70/174, para 28(b).
3. Case Concerning Military and Paramilitary Activities in and against Nicaragua (Nicaragua v United States of America) (Merits) [1986] ICJ Rep 14, para 205.
4. Charter of the United Nations (adopted 26 June 1945, entered into force 24 October 1945) 1 UNTS XVI, art 2(4).
5. Schmitt (n 3) rule 71 and commentary, discussing the threshold of ‘scale and effects’ derived from Nicaragua (n 5).
6. Charter of the United Nations (n 1) art 51.
7. International Law Commission, ‘Articles on Responsibility of States for Internationally Wrongful Acts’ (2001) UN Doc A/56/10, art 8.
8. UNGA, ‘Report of the Group of Governmental Experts on Developments in the Field of Information and Telecommunications in the Context of International Security’ (28 May 2021) UN Doc A/76/135.
9. UNGA, ‘Final Substantive Report of the Open-Ended Working Group on Security of and in the Use of Information and Communications Technologies 2021-2025’ (2025) UN Doc A/AC.292/2025/CRP.1.
10 UNGA, 'Final Substantive Report of the Open-Ended Working Group on Security of and in the Use of Information and Communications Technologies 2021-2025' (2025) UN Doc A/AC.292/2025/CRP.1.
11 Michael N Schmitt (ed), Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations (2nd edn, Cambridge University Press 2017) rule 1.
12 Convention on Cybercrime (adopted 23 November 2001, entered into force 1 July 2004) ETS No 185 ('Budapest Convention').
13 Kristen E Eichensehr, 'The Cyber-Law of Nations' (2015) 103 Georgetown Law Journal 317, 340-345.
14 Harold Hongju Koh, 'International Law in Cyberspace' (Remarks at USCYBERCOM Inter-Agency Legal Conference, 18 September 2012) reproduced in (2012) 54 Harvard International Law Journal Online 1.

