Lieber Institute White Paper: Responding to Malicious or Hostile Actions underneath Worldwide Legislation

Lieber Institute White Paper: Responding to Malicious or Hostile Actions underneath Worldwide Legislation

Current consultations with senior authorized advisers have highlighted the necessity for a transparent map of response choices accessible to States going through hostile or malicious actions, whether or not attributable to a different State or a non-State actor. In spite of everything, to reply successfully to such actions, States, together with these working collectively, want to know the complete vary of responses allowed by worldwide legislation, together with the authorized limits on their use. The ensuing circulation chart and my abstract of the choices are reproduced right here for Articles of Conflict readers. They’re my views on the topic and don’t essentially symbolize these of america Army Academy or some other U.S. authorities entity.


Worldwide legislation permits for a big selection of lawful responses to hostile or malicious actions. They vary from arbitration and judicial settlement to motion approved or mandated by the Safety Council underneath Chapter VII of the Safety Council, an choice that will even embrace makes use of of drive. However normally worldwide legislation, 4 response choices loom giant—retorsion, countermeasures, necessity, and self-defense. On this submit, I’ll define their key necessities and limitations. The circulation chart beneath, which Wolff Heintschel von Heinegg, Liis Vihul, and I developed for Cyber Legislation Worldwide’s capacity-building programs, units forth an method to pondering by means of these responses. I’ve barely modified it to be used within the non-cyber context. The unique and an armed battle companion chart, along with a complete rationalization of each, could be discovered right here.

Lieber Institute White Paper: Responding to Malicious or Hostile Actions underneath Worldwide Legislation


 Acts of retorsion are unfriendly however lawful reactions by one State to a different. Examples (within the absence of a treaty prohibition on the contrary) embrace, inter alia, diplomatic protests, financial or commerce sanctions, closing ports to ships flagged within the goal State, declaring diplomats persona non grata, closing diplomatic services, recalling diplomats, calling off State visits, decreasing or canceling growth or navy assist, withdrawing from worldwide organizations, imposing limits on entry into the State’s territory by nationals of the goal State, and withdrawing from or terminating a treaty in response to its phrases.

The only real requirement for qualification as an act of retorsion is that it not breach any worldwide legislation obligations, comparable to these present in worldwide human rights legislation or a treaty bearing on the matter. As a result of they’re by definition lawful, acts of retorsion are at all times accessible in response to a different State’s motion. Certainly, they’re even, however not solely, accessible when the State in opposition to which they’re directed has not violated worldwide legislation. Additional, there is no such thing as a requirement for discover (except imposed by a treaty bearing on the matter) earlier than partaking in retorsion, neither is there any evidentiary commonplace with respect to the motion to which the retorsion responds. Lastly, acts of retorsion usually are not topic to any requirement of proportionality, and there’s no requirement that an act of retorsion be more likely to trigger the goal State to desist.

As with every response, acts of retorsion are topic to the duty of peaceable settlement of disputes mentioned beneath. Generally, although, that obligation won’t have an effect on the choice to resort to retorsion as a result of acts of retorsion are usually unlikely to hazard “worldwide peace and safety.”


Countermeasures are responses that might be illegal underneath worldwide legislation, however for the truth that they reply to a different State’s illegal motion and are designed to place an finish to it and/or safe reparations for hurt suffered. To take a easy instance, if a State’s warships in one other State’s territorial waters have interaction in espionage in opposition to the coastal nation, these ships are violating the legislation of the ocean’s “harmless passage” regime that allows transit by means of territorial waters as long as vessels do nothing adversarial to the coastal State. In response, the coastal State could be entitled to, as an illustration, take the countermeasure of closing its territorial sea to all ships flagged within the first State till the warships desist.

The best to take countermeasures is present in customary worldwide legislation. With regard to figuring out the principles, the Worldwide Legislation Fee’s Articles on State Duty are thought-about a usually dependable restatement of the customary guidelines governing countermeasures (ASR, arts. 22, 49-54). Like necessity and self-defense (see beneath), countermeasures are “circumstances precluding wrongfulness” underneath worldwide legislation (ASR, ch. V).

As a result of they permit an “injured State” (the State in opposition to which the illegal exercise was initially directed) to have interaction in in any other case illegal actions in opposition to the “accountable State” (the State that engaged within the illegal conduct), countermeasures are topic to strict limitations. Key amongst these are the next.

    • States might solely take countermeasures in response to an “internationally wrongful act,” which requires attribution (factual and authorized) to a State and breach of an obligation that State owes the injured State. Acts by non-State people or teams don’t open the door to countermeasures except they’re legally attributable to a State (however see the opportunity of motion in opposition to non-State actors based mostly on the territorial State’s failure to adjust to its due diligence obligation). The almost certainly foundation for authorized attribution is that the non-State actor is appearing pursuant to the “directions or course or management” of a State (ASR, artwork. 8).
    • Solely States are entitled to take countermeasures; personal entities might act on behalf of a State in executing countermeasures, however the State will probably be accountable for the conduct underneath the legislation of State duty.
    • An injured State might not take countermeasures for any goal aside from inflicting the accountable State’s illegal exercise to stop or securing reparations which might be due. Retribution, retaliation, or punishment usually are not professional functions of countermeasures (or of some other response choice). As a result of countermeasures are designed to terminate the accountable State’s illegal conduct and safe reparations, they might not be escalatory or unlikely to succeed.
    • Countermeasures usually are not accessible till the wrongful conduct by the accountable State has commenced. They should be terminated as soon as the wrongful conduct ceases. The only real exception is, as famous, taking or persevering with countermeasures to safe reparations nonetheless as a result of injured State.
    • An injured State ought to notify the accountable State of its intention to take countermeasures and afford the latter a possibility to stop its illegal conduct and/or present reparations due. Nonetheless, this requirement is excused when the necessity for countermeasures is “pressing,” a place taken by most States which have spoken to the difficulty within the cyber context (e.g., France, Netherlands, Norway, United Kingdom, United States).
    • Countermeasures can not contain the “use of drive” (U.N. Constitution, 2(4)). A forceful response is just permissible in self-defense in opposition to an armed assault (see beneath) or pursuant to Safety Council authorization or mandate underneath Chapter VII of the UN Constitution. Countermeasures shouldn’t be confused with belligerent reprisals, an especially restricted response choice throughout worldwide armed conflicts.
    • Countermeasures should be “commensurate with the damage suffered” and contemplate the gravity of the wrongful act and the appropriate involved (ASR, artwork. 51). In different phrases, the injured State’s countermeasure should be proportionate to the dimensions and nature of the unique illegal motion by the accountable State. This differs from proportionality within the legislation of self-defense, the place proportionality is assessed by reference to what’s required to finish the armed assault to which it responds (see beneath).
    • Worldwide legislation is unsettled whether or not “collective countermeasures” are permissible. They contain one State aiding one other’s countermeasures or appearing on its behalf (see evaluation right here).

Regardless of these limitations, a number of points of countermeasures facilitate their use. Importantly, countermeasures needn’t be in form, both by way of the worldwide legislation rule concerned or the character of the countermeasure. For instance, an injured State might reply to a breached treaty obligation with a countermeasure that might in any other case violate a customary worldwide legislation rule and vice versa. Take into account the non-innocent passage instance above. The injured coastal State may reply by, as an illustration, denying touchdown rights offered for in a bilateral settlement to plane registered within the accountable State. Or it may conduct cyber operations in opposition to personal entities within the accountable State that might in any other case violate the accountable State’s sovereignty. This is a vital facet of countermeasures, for injured States might lack the capability to reply in form.

As these examples illustrate, the injured State doesn’t should direct a countermeasure on the entity that engaged within the preliminary illegal conduct. As an illustration, assume the accountable State’s intelligence company is concerned in illegal cyber operations, comparable to inflicting injury to the injured State’s authorities methods. The injured State might direct countermeasures on the intelligence company’s cyber infrastructure, that of uninvolved authorities companies, and even private-sector methods.

This instance illustrates a vital facet of the response. Countermeasures might terminate the illegal conduct to which they reply both straight or not directly. Within the earlier instance, operations disabling the intelligence service’s methods would straight finish the accountable State’s illegal conduct. Nonetheless, as a result of these methods would doubtless be safe, the injured State may choose to strain the accountable State by concentrating on different methods, thereby not directly forcing it to desist.


Like countermeasures, the “plea of necessity” is a circumstance precluding wrongfulness (ASR, artwork. 25). Accordingly, it permits a State to have interaction in what would in any other case be illegal conduct. Necessity is offered as the idea for an in any other case illegal response solely in excessive circumstances. But, the plea of necessity has a number of benefits that will make it accessible in instances the place countermeasures usually are not.

There are 4 cumulative situations precedent to partaking in an in any other case illegal response pursuant to the plea.

    • The plea of necessity is just accessible in conditions that current a “grave and imminent peril” to the State. Worldwide legislation doesn’t outline the time period grave, however the Tallinn Guide 2.0 specialists agreed {that a} “peril is grave when the menace is very extreme. It includes interfering with an curiosity in a elementary method, like destroying the curiosity or rendering it largely dysfunctional” (Rule 26 commentary).
    • Grave peril that’s imminent or ongoing should be posed to an “important curiosity” of the State. Like “grave peril,” the time period important curiosity lacks a definitive definition in worldwide legislation. Nonetheless, the Tallinn Guide 2.0 specialists “agreed that a vital curiosity is one that’s of elementary and nice significance to the State involved. The willpower of whether or not an curiosity is important is at all times contextual. Essentiality of a selected curiosity can also be, to an extent, more likely to range from State to State.” The time period certainly would come with the well being of the inhabitants; the financial and monetary methods; the nationwide meals, energy, and water provides; and nationwide safety. Providers offered by most crucial infrastructure, comparable to the ability grid, would qualify as important, though designation as essential isn’t required to qualify as important.
    • The grave peril the State’s important curiosity is going through should be “imminent.” This consists of conditions through which the hurt is going on or impending. In different phrases, necessity permits for anticipatory responses (see additionally the dialogue beneath on imminency in self-defense).
    • A fourth requirement is that the measure being thought-about to finish the grave and imminent peril to a vital curiosity should be the one approach to safeguard that curiosity. From a sensible perspective, this doesn’t imply that the motion being thought-about must be the one conceivable approach to take care of the scenario. As a substitute, it should be the one fairly possible technique of addressing it. There isn’t any requirement to aim speculative or unlikely measures.

Along with the 4 situations, appearing based mostly on necessity is prohibited if the motion would have an effect on the important curiosity of one other State. Moreover, a State might not look to the plea of necessity when it has contributed to the scenario, as with Russia’s illegal aggression in opposition to Ukraine motivating cyber assaults in opposition to Russian targets.

Regardless of these limitations, the plea of necessity presents two benefits over countermeasures. First, there is no such thing as a requirement that the peril be attributable to the breach of any worldwide legislation rule. For instance, there may be uncertainty over the edge at which a cyber operation violates a State’s sovereignty, quantities to intervention in a State’s inside affairs, or rises to the extent of a use of drive. As a result of necessity needn’t reply to an illegal act, such uncertainty wouldn’t preclude taking measures based mostly on the plea of necessity.

Second, and relatedly, countermeasures are solely accessible in response to actions attributable to different States. This situation is typically an impediment to a response both due to the problem of factual attribution or as a result of the requisite nexus between a non-State actor’s motion and a State is inadequate to legally attribute it to a State. Nonetheless, the plea of necessity is offered within the face of motion by non-State actors that can’t reliably be attributed to a State and when the motion’s originator is unknown. In each instances, the State might reply although its response might violate a world legislation obligation owed one other State.

As an example, contemplate hostile cyber operations right into a State that’s disrupting essential infrastructure. The State’s cyber drive has the technical functionality to conduct disabling operations in opposition to the attacker however is unsure as to its id or location. Nonetheless, the plea of necessity would doubtless justify the response.


The fourth main response choice accessible to States going through hostile actions is appearing pursuant to the appropriate of self-defense, which is a circumstance precluding wrongfulness (ASR, artwork. 21). The United Nations Constitution supplies for the appropriate of self-defense in Article 51, which displays, in important half, customary worldwide legislation. As a response operation, it’s distinctive, for it permits the State to make use of drive, which is mostly prohibited pursuant to Article 2(4) of the UN Constitution and customary legislation. The one different clear authorized foundation for a response at using drive stage is Safety Council authorization or mandate underneath Chapter VII of the Constitution. Article 51 supplies that self-defense could also be exercised collectively and requires makes use of of drive in self-defense to be reported to the Safety Council.

There are 4 situations precedent to responses based mostly on self-defense.

    • First, in response to Article 51, self-defense is just accessible within the face of an “armed assault.” Though a major navy assault qualifies, there may be relative uncertainty as to when else the appropriate of self-defense is triggered. That is particularly so with cyber operations that may severely disrupt one other State with out inflicting bodily injury or damage, as within the case of a major cyber operation in opposition to the goal State’s financial system. The legislation is unsettled on this matter, though some States have taken the place that, relying on the “scale and results” of the results, non-destructive and non-injurious cyber operations can qualify as an armed assault (e.g., France and Singapore). France is of the view {that a} very extreme financial cyber assault may quantity to an armed assault.

America has adopted a comparatively liberal method to the that means of “armed assault” by equating it to the “use of drive” (see, e.g., right here). Most different States, together with NATO allies, which have taken a place on the matter, characterize armed assaults as, within the phrases of the Worldwide Courtroom of Justice within the Paramilitary Actions case, the “most grave varieties” of using drive. The sensible impact of this disagreement is that america would label an motion as an armed assault meriting a response in self-defense at a decrease stage than that of most different States. As NATO (Brussels Summit) and particular person States (e.g., France and Singapore) have noticed, a number of associated actions by the identical actor could also be aggregated to succeed in the armed assault stage.

    • A forcible response in self-defense should be “essential.” Necessity within the self-defense context signifies that the State going through the armed assault should use measures at using drive stage of severity to defeat or in any other case terminate the armed assault. If non-forcible measures, comparable to countermeasures, would suffice, the sufferer State might not use drive in self-defense.
    • A 3rd requirement is temporal; it additionally derives from the precept of necessity. The armed assault to which the defensive use of drive responds should be underway or imminent. Worldwide legislation is unsettled as as to if imminence denotes hurt that’s about to occur or additionally refers to conditions through which the “final window of alternative” to counter the armed assault successfully is about to shut (see, e.g., the S. and Australian positions). Additional, as a result of self-defense is just accessible within the face of an imminent or ongoing armed assault, a State that has been the sufferer of such an assault might not reply in self-defense as soon as the assault is over. Nonetheless, if the operation in query is however one in a sequence of assaults, the appropriate of self-defense stays intact till that marketing campaign is over.
    • The ultimate self-defense requirement is proportionality. As understood within the legislation of self-defense, proportionality limits a State appearing in self-defense to these actions which might be required to move off the upcoming armed assault or defeat an ongoing one. This may increasingly restrict the defensive response to much less extreme motion than the State is experiencing, however which is nonetheless more likely to defeat the armed assault. However, making use of the identical logic, a defensive response can fulfill the proportionality criterion although its severity exceeds that of the armed assault, as long as a response at that stage is required to defeat the armed assault.

There are a number of ongoing debates relating to the train of the appropriate of self-defense. Two stand out. The primary includes whether or not an operation on the armed assault stage of severity by a non-State actor qualifies as an armed assault for the needs of the legislation of self-defense. In its Paramilitary Actions judgment, the Worldwide Courtroom of Justice held that solely assaults by non-State actors on behalf of a State or with its substantial involvement triggered the appropriate of self-defense; the Courtroom seems to have maintained this place in different instances (Armed Actions judgement and Wall advisory opinion). Nonetheless, quite a few States have adopted the place that self-defense is offered in response to non-State actor assaults missing a relationship to a State. As an illustration, that is the view, as an illustration, of america, United Kingdom, Germany, and the Netherlands (see right here).

The second debate issues the place defensive actions might happen. Undeniably, they’re permissible within the territory of a State engaged in an armed assault, the sufferer State’s territory, and the commons (worldwide waters and airspace, and outer area). The disagreement is about whether or not a State might take forcible defensive measures into the territory of a State that isn’t accountable for the armed assault. Some States argue that doing so is impermissible and would violate, at a minimal, the sovereignty of the State into which the operation is carried out. America and quite a few different States take the place doing so is allowed when the territorial State is “unwilling or unable” to place an finish to the hostile operations emanating from its territory (or underneath different distinctive circumstances).

Peaceable Settlement of Disputes

It should be cautioned that any response should be per worldwide legislation obligations to settle disputes peacefully. There are two. First, in response to Article 33(1) of the UN Constitution, the States concerned in a dispute should “initially, search an answer by negotiation, inquiry, mediation, conciliation, arbitration, judicial settlement, resort to regional companies or preparations, or different peaceable technique of their very own alternative” whether it is more likely to “endanger the upkeep of worldwide peace and safety.” In different phrases, States concerned in a dispute that dangers breaking out into a world armed battle or that may contain using drive have an affirmative obligation to attempt settling the matter peacefully. Solely as soon as peaceable choices fail, or are certain to fail if tried, does the opportunity of utilizing drive come up underneath the appropriate of self-defense or Safety Council motion.

Second, whereas there is no such thing as a obligation to attempt to settle a dispute except it dangers hostilities or different makes use of of drive, ought to an try be made to take action, the try should be carried out “by peaceable means in such a fashion that worldwide peace and safety, and justice, usually are not endangered” (UN Constitution, artwork. 2(3)). The idea of “peaceable means” excludes non-forceful responses which might be more likely to escalate to a use of drive.


Hostile and malicious actions in opposition to or into States are all too widespread. Thankfully, as illustrated on this white paper, worldwide legislation often leaves the door open to a sensible and efficient response. Nonetheless, as a result of some response choices contain conduct that might in any other case be illegal, it imposes strict and nuanced limitations on when and the way they might be carried out. States contemplating a response to hostile or malicious actions could be assured {that a} response choice is offered however ought to navigate by means of them rigorously.


Michael N. Schmitt is the G. Norman Lieber Distinguished Scholar at america Army Academy at West Level. He’s additionally Professor of Public Worldwide Legislation on the College of Studying and Professor Emeritus and Charles H. Stockton Distinguished Scholar-in-Residence at america Naval Conflict Faculty.



Photograph credit score: U.S. Air Power Tech. Sgt. Alexandre Monte