Yours Lawfully Podcast
Yours Lawfully Podcast
The digital battlefield: How tech shapes modern war.
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
“Not every attack is visible and not every war is declared.”
In recent decades, conflict has moved beyond physical borders into the digital realm. Cyber operations now have the power to disrupt critical infrastructure, manipulate information, and cause real-world harm without a single shot being fired.
In this episode of Yours Lawfully, we are joined by Dr. Elizabeth Hofberger-Pippan, who brings expert insight into how international law is adapting to this evolving landscape. From the “scale and effects” test in cyber warfare to the legal challenges of attribution, we unpack how states respond to threats that are often invisible and difficult to trace.
We also explore the rise of information warfare, where disinformation and digital influence campaigns blur the line between peace and conflict.
As the battlefield becomes increasingly intangible, the question remains: can law keep pace with a war that is fought in code rather than combat?
In the last few decades, the way states weight work has changed in ways that are not always visible. Conflicts that once depended on physical force, land, borders, and conventional weapons have increasingly more core to beta digital infrastructure. A cyber attack can disrupt electricity across an entire region. It can lock a hospital out of its own system. Or it can quietly exploit sensitive information. All without a single chart being filed. At the same time, information itself has become a strategic concept. Now it promotes a manipulated content it can make in trust, it can polarize society, and it can also influence electrodes. So in today's episode, we'll explore the emerging digital battlefield. We'll look at how cyber operations work in practice and how information becomes weaponized and what does international law currently say about this act. Our aim here is to not only just understand what digital warfare looks like, but what it means for the future of conflict and rule of law. Welcome to today's episode of Yours Lawfully, based out of Queen Mary's award-winning commercial law clinic. We are Nityayan Ashwati, LLM student at Queen Mary University of London. Today we are incredibly lucky to be joined by Dr.
SPEAKER_02Elizabeth Hofberger Pippen, who serves as a policy advisor for security policy and international order at the Vienna office of the Conrad Adenauer Foundation. Her research focuses on international law, armed conflicts, and the legal implications of emerging technologies. We invited her because her work speaks directly to the transition from traditional warfare to digital operations, including cyber attacks, state surveillance, and the challenges surrounding attribution. Thank you for joining us today. Would you like to introduce yourself?
SPEAKER_00Yes, thank you very much for this very kind introduction. I will also just add a few things. Hello, everyone. So the last couple of years I've been working at the intersection of international law and politics with a very specific focus on everything that relates to digitalization, to new technologies, to military robotics, and also, of course, the cyber realm. And I'm very happy to be here today.
SPEAKER_01Thank you. Dr. Pippen, it's great to have you with us today. Dr. Pippin, when we talk about digital warfare, we often focus on incidents that show how cyber operations can cause real-world harm without conventional military force. A key example could be the 2015 cyber attack on Ukraine's power grid, which shut down substations and it has left hundreds of thousands of civilians without electricity during winter. The attack has affected essential services, it has delayed emergency response, and it has also required manual intervention to restore power. So, my question to you is in the context of the incidents like the 2015 attack on Ukraine's power grid, how does international law differentiate between cybercrime and acts of cyber warfare?
SPEAKER_00Yes, thank you very much. So I think before we answer the question, um, how we can actually assess and determine what happened, for example, in Ukraine in 2015, it is always helpful to bear in mind that we have at least two separate so-called bodies of law, uh, that is the use ad bellum and the use in bellum. And when we talk about the use ad bellum, the right or the legal possibilities to wage war, we need to take into consideration that we have at least two different possibilities to do so. There is, of course, this absolute prohibition on the use of force under international law, and with very few exceptions. The one is, of course, if the Security Council adopts a resolution and mandates the use of force, which is not very relevant in the context of the cyber operations. And then, on the other hand, we also have, of course, the inherent right of states to defend themselves, that also applies only under very narrow circumstances. So this is like the first body of law that we need to have a look at. And then we have the second body of law, which is, of course, to use in bellow. So the law that applies if there is already an armed conflict, and the law that needs to be adhered to by the respective parties to the conflict. When we think about Russia's war of aggression against Ukraine, that certainly is an international armed conflict. So what happens with cyber as such, we always need to ask ourselves when we talk about the use at Bellum, is the cyber operation equal or very similar to the use of physical force to clear conventional military force? And what turned out in the past in the various discussions on cyber operations and international law in general, is the question of whether a particular cyber operation actually has effects on the physical in the physical world, so to say. If you think about the term scale and effects that has actually evolved in the discussions on the legitimacy of states to defend themselves under Article 51 of the United Nations Charter, there it is normally the rule that an armed attack, for example, only occurs if it reaches a certain level of intensity. And the International Court of Justice used the terminology scale and effects. So an armed attack and a conventional armed attack needs to reach a certain threshold. It needs to reach a certain scale and certain level of intensity. The terminology, as I said by the ICHA, was scale and effects. And the same question actually arises, or the same terminology should be used and is already being used by a number of states if they want to assess whether a cyber operation might, for example, amount to the use of force under international law. So what we can see is it is very difficult to qualify a certain cyber operation as a violation of the use prohibition on the use of force. And even in the use of inbell, it is very difficult because we always need to ask ourselves: is that particular operation similar, equal to the physical world, so to say, are there any effects on the physical world? Sometimes it's not even necessary to have clear effects in the physical world because the devastating consequences might be indirect but still severe. So to sum up, we need to bear in mind there are two different bodies of law, and we need to assess each operation individually and always bear in mind these two different bodies of law have different legal underpinnings.
SPEAKER_01Thank you, Ms. Pippin. That's really interesting and some really helpful information to know. So at what point does a cyber attack become serious enough to be treated as use of force or an armed attack? So where does the international law draw the line here?
SPEAKER_00Yes, so in order to assess whether a particular cyber operation constitutes use of force, that also is a violation of the prohibition on the use of force as enshrined in Article 2, paragraph 4 of the United Nations Charter, it is really helpful to look at the effects of a particular cyber operation. If we think of a cyber operation that has almost no effects on the physical world, for example, the I don't know, maybe the blockade of um just or the functionality of a IT infrastructure in a big company, for example, or even a bank, that might not be that severe. But let's assume that cyber operation has more severe effects on the physical world in the physical realm. What if, for example, traffic lights stop to work and there are hundreds of accidents? What about trails get derailed? What about, for example, I don't know, um, airports need to close, or there are any other accidents, maybe even not as a direct but an indirect consequence of that particular cyber operation? And then we come very close to, or we can say it's very similar to an operation that would have been undertaken by using conventional military force. So the most important aspect is we we should not focus so much on what kind of measures, what kind of technologies are being used, but rather what kind of effects are being created. So this is very much a effects-based approach. And the effects-based approach is actually the approach that is also being applied by, I would say, the majority of the international community. So, for example, the United States, Israel, Germany, many other states are applying that effects-based approach. And the Tallinn manual, which is more or less a composition of different rules that were established or clarified in the context of international law by experts that have also strong military backgrounds that really have deep insights into the particular, most pertinent questions. And the Tallinn manual, there are actually three different Tallinn manuals. And in the Tallinn manual, um, it was discussed whether this kind of effects-based approach should actually be taken one step further and say, well, what we really need to look into is, as I've mentioned before, the scale and effects of a particular cyber operation. And if the scale and effects are paramount, equal, similar to that of conventional physical force, we would certainly need to say, well, in this case, that particular cyber operation amounts to the use of force. However, we also need to be very careful because what would be the next step, so to say? The prohibition on the use of force is one thing, but you've mentioned another very important term, which is armed attack. An armed attack normally is even higher than the, so to say, average use of force. An armed attack, the International Court of Justice has mentioned, for example, in its Nicaragua case of 1986, but also in the Oil Platforms case of 2005, that an armed attack is the use of military force, but with a higher level of intensity. With it used the term scale and effects as well, by the way. And we are boring that terminology to talk about cyber in the context of the provision on the use of force. But as I said, an armed attack needs to be very severe. And very severe meaning if you think about the classical scenario back in 2001, the terror attacks 9-11 undertaken by a non-state actor that received very much support from a state, actually, from the then Taliban regime ruling in Afghanistan back then. So kind of a state actor, even though even that is legally speaking um at least disputed. But what I really want to emphasize here, an armed attack needs to be very severe. And we can we can certainly make the case that even a cyber operation can be so severe that it amounts to an armed attack. And if you think about Article 51, UN Charter, there are other rules in international law that's that's directly relate to Article 51. It is Article 5, the NATO treaty, and then we also have Article 42, paragraph 7, of the EU treaty. And both those those rules, those those norms, they also borrow the terminology of Article 51 and say, well, in case there is an armed attack on um on one of the 10 the states or the territories within NATO or within the European Union, we consider that, at least in the context of NATO, as an attack on us all, and we're going to defend ourselves militarily. And NATO has already clarified that there might be situations that are so severe, cyber operations that are so severe that it's it actually constitutes an armed attack and that would trigger the applicability of Article V. The European Union has been a bit more, I would say, cautious with that approach, but that certainly might be the case. But that would really depend on the respective circumstances. But if there is the loss of functionality of the entire banking system, insurance companies, traffic lights, flooding maybe of lands, land or even urban areas, for example, if the attack is so severe, we can certainly also make the case that a cyber operation not only amounts to the prohibition on the use of force, or not only amounts to use of force, but also to around attack.
SPEAKER_01Great. Uh that's some really interesting information to hear about. So let's move to the topic two, information warfare. Ashwati will take on from here.
SPEAKER_02Before we move on to topic two, I kind of want to float um a follow-up question. Like you said, it's a scale and effect. But when it comes to things like disrupts the banking system of a country, it's considered quite severe. So, for example, if the airport system of a country was attacked, um, I I would personally think that's less severe. Depending on the situation, could that still be considered severe? And also I wanted to ask: could you give us a little explanation on what the UN charter is for our listeners who are not from a legal background? Is it kind of like the Bible of international law?
SPEAKER_00Yes, very like great questions. So I think regarding the airport situation, it is very important that we always differentiate between two scenarios, actually. The one where we say, okay, there is a temporary loss of functionality that might end up in a huge administrative burden. But apart from the fact that the travelers might be very frustrated for obvious reasons and there might be economic losses, that is one thing. But let's assume the cyber operation is very complex, and you're not only um, for example, trying to temporarily close the airport or uh via cyber attack so that communication is just not possible anymore and passports cannot be produced, for example, that is one thing. But another thing would be let's assume the cyber operation is a bit more complex and direct communication with pilots, for example, gets hampered or kind of distracted, or there might even be false information and even data that are being manipulated. And for example, one pilot just receives so much incorrect information that he or she might, for example, create an accident that leads to the death of, I don't know, the passengers. And that would certainly be something where we would say, okay, there is clear physical damage to people and even to property. And this is something where we we would might say, okay, is there a similar situation in the so-called physical world with uh with an attack by, I don't know, conventional weapons? And would that even be like a very similar scenario? And I would say whenever there is damage to people, like real physical damage to people and to property, then we come very close to um a scenario where we'd say this is a prohibition on the use of force. It always depends, of course, on the relevant circumstances. We would certainly need more particular information, but just closing the airport, so to say, by infiltrating the IT system and by, you know, just preventing people from issuing the passports and communicating with each other, that might not be probably or very certainly not amount to the prohibition on the use of force or amounts to or would not be a violation of that rule. But anything that uh creates physical effects by causing accidents and stuff like that, that would certainly at least fall under uh above the radar. So that would say, okay, this would be a threshold we would certainly need to look into. Again, it always depends on our relevant circumstances. Um, but but that would certainly be something, even when with regard to the prohibition of the use of force, um, in in conventional terms, there is still arguably always a little bit of a threshold, at least. I mean, not every single, I don't know, for example, skirmish between military forces automatically is a prohibition on the use of uh violation on the prohibition on the use of force. There arguably most people would say at least there is some some kind of intensity required. A an unintentional uh border transgression might not, in the eyes of uh some people, might not be a prohibition on the use of force. So there are there are different opinions regarding um the the intensity also um here in this regard. Maybe just to add on this, um what we also need to bear in mind is um there is this principle in international law that all states are sovereign, and that means even though there might not be a violation on the prohibition on the use of force, at least there might be a violation on the principle of a state's or the state's sovereignty. And here again, we need to be careful because some states, such as the United Kingdom, as far as I remember, do not consider sovereignty a right on its own. It's just a principle that is kind of intertwined with other rules of international law that kind of helps us interpret other rules of international law. However, other states again consider sovereignty a right on its own. So even though there might not be a violation of the prohibition on the use of force in some contexts and in some cyber operations, there might at least like the minimum a violation of the principle of sovereignty, which would then allow the affected state to take specific countermeasures. So that is something. And coming back to the question about the nature of the United Nations Charter. So the United Nations Charter is like the founding document of the of uh the United Nations as such. They were founded in 1945, um, after the tragical, and that is probably not even enough said, uh, the um after the devastating things that happened, the death of over six million Jews, but also other people who were just not um, so to say, in line with the then Nazi regime. That is the reason why we have the United Nations and the Founding Treaty, the UN Charter, is the document we always refer to. The the rules that are most important for us is Article 2, paragraph 4, which enshrines the prohibition on the use of force. And then, and I think we're going to talk about that as well, Article 2, paragraph seven, which enshrines actually the prohibition of intervention. That might also be relevant, especially when we talk about interference in elections by cyber tools. So that's it.
SPEAKER_02That's a great segue into our next topic, actually. So that's exactly what we wanted to talk about. So I'm just gonna get into it. That was very insightful. Thank you. So moving beyond attacks and physical infrastructure, conflict increasingly plays out in the information space. States and non-state actors now use disinformation, bot networks, and manipulated content to influence public opinion, polarized societies, and undermine trust in democratic institutions. A recent example of online information warfare comes from the lead up to the 2025 parliamentary elections in Moldova, where election monitors and researchers reported coordinated AI-driven disinformation targeting support for EU integration and the pro-European Party of Action and Solidarity. These campaigns allegedly use networks of spoof websites and inauthentic social media accounts, often powered by AI-generated personas, to amplify narratives aligned with Russian messaging without directly interfering with the voting process itself. Moldovan authorities responded with investigations and arrests, which raises the question of propaganda has existed for decades, but it has generally been through word of mouth or posters. But how does modern information warfare, especially through digital platforms and automated networks, differ from earlier forms? And why does that distinction matter legally?
SPEAKER_00Yes, thank you so much. So I think you've made a very important point. Information warfare, it is kind of a very broad term that actually has existed for many years. Uh and and even when we look back at ancient and in ancient times, the combination of, for example, sometimes clear military means and other non-military measures to implement geostrategic interests has characterized the world or world politics for years. And this is very important, even for decades or even hundreds for years. So I think before we answer the question about election interference and new technologies, we need to probably need to take a step back and say, well, this has existed for many, many years, that states not only refer to military means to implement, as I said, or enforce their geostrategic interests, but also to non-military means, which are also equally important. You've probably come across the term hybrid warfare in the media, for example, or even in the literature, and states also frequently refer to this term, which actually means the combination of military as well as civilian measures to implement and impose geostrategic interests. And some people speak of a gray area because hybrid warfare actually means that states increasingly refer to measures that are below the threshold of clear military force in order to impose, in order to implement their geostrategic interests. So, for example, instead of attacking another state militarily, states have taken the decision to influence that state, to change its uh political situation, so to say, to polarize society. And here, in that particular regard, um, new technologies, bots, for example, uh, Other kind of networks, but also information campaigns on the internet in general play a very important role. So you were mentioning Moldova, which is really, really important. But I was also thinking about the situation in Germany, because we in Germany are face a very tra tragical developments at the moment, to be very honest, because we see and we can actually, we are noting that our society is being more and more polarized. And I think that the what is happening on social media, for example, disinformation, misinformation, and so on and so forth certainly plays a very big role in this regard. And the most important question here is does international law still play a role here, or is that rather something that is more a domestic thing where domestic stakeholders need to take action? And the answer is well, um, international law actually plays a very big role in this regard. First of all, there is the prohibition of intervention enshrined in Article 2, paragraph 7 of the UN Charter, which says that it is prohibited to interfere in a state's internal affairs. Internal affairs meaning there are certain areas that only a state is responsible for, such as elections. But even, for example, maintaining a health and security system is also something that is very much the responsibility of a state as such, taking care of its own citizens, for example. But elections, the elections and the responsibility to have elections, to organize them, to guarantee that they are fair, that they are democratic, is a state's prerogative. So if another state, for example, infiltrates social media channels, creates bots and other kinds of factories, whatever, to disinform voters, potential voters, about, for example, a certain candidate, to discredit a certain candidate, to discredit a certain candidate by claiming that candidate, as we've also seen, for example, in the elections, the presidential elections back in 2016, what happened with Hillary Clinton, this was severe. And I think there is this prohibition of intervention. We just need to find out what international law actually says about intervention and the prohibition of intervention. And what international law says about it, we can again refer back to the International Court of Justice in the Nicaragua case, is if the state is literally compelled because of that intervention, to take specific measures to adapt its behavior, if there is this kind of element where a state is literally forced to take specific measures in order to still be able to undertake or to still be able to assume its responsibilities as a state, then the stakes are very high that this specific act, for example, by uh election interference by cyber means constitutes a prohibition of intervention, which clearly is against international law, and the the affected state then would have the right to take specific, of course, non-military countermeasures against that state. And I think that is certainly relevant. However, um, this kind of intervention, the prohibition of intervention, and the fact that a state is forced to adapt its behavior is something that is um in practice, it might happen, yes, but many interventions, when you see, for example, the interference in social media channels and the different bots and other illegal players in this field, uh sometimes it it they slip under the radar of the prohibition of intervention. They slip under this threshold. And then there is not so much international law can actually do or can actually provide. There is, of course, um, there are still human rights, yes, but we need to make sure or be aware of the fact that actually states are bound by human rights, and they may need to make sure that third parties do not violate human rights. That is true. But in the end, here comes a here here's a very difficult thing where international law does not provide too many questions or too many answers, sorry, too many answers because uh certain acts are just below this kind of threshold. And there might be two different solutions to that problem. One solution would be to say, well, one specific act, even if it does not reach a certain threshold, should not be viewed in isolation. If we have a hundred specific acts that fall under a certain threshold individually, taking them together, assessing them in general as a group of acts, we can make or could make the argument, okay, wow, now so many different acts have taken place, we come closer to the violation of a particular norm under international law. So there is this argument to say, well, don't assess each individual attack individually, take them together and try to evaluate is our assessment now different? In practice, for example, we might see the parallel occurrence of different acts of different types. Election interference on one day, a military, small military intervention in a country's north the other day, and then there might be a cyber attack on um the affected states, for example, foreign ministry, and then there might be, I don't know, it might be effects on the state's um airport, and then there might be maybe um other military acts. So what I want to say here is the occurrence, parallel occurrence and parallel acts um occurring together might change our legal assessment. Maybe an individual act does not amount to the provisional use of force, but maybe if we have hundreds of them, maybe it does. So this would be one way to see this kind of the term hybrid warfare in a more in a more broader context. The most crucial question still is who are the perpetrators, of course. And they are very often very difficult. It's often very difficult to identify them. Sometimes it's simply not possible.
SPEAKER_02That's really insightful, actually. I think um your point about kind of assessing them as a parallel occurrence of acts is a very interesting one. I I didn't think of it in that way.
SPEAKER_01So moving on, topic three attribution and legal frameworks, which brings us to the most central challenges in cyber conflict, that is attribution. Unlike conventional attacks, cyber operations can be routed through multiple states, can rely on compromised infrastructure, or deliberately use false flags, making it difficult to determine who is actually responsible. Because of this, attribution is often described as central to how international law approaches cyber conflict. Yet it remains one of the hardest issues to resolve in practice. When responsibility is unclear, states are left facing real harm, but uncertain about how or whether they can respond lawfully. So, uh, my first question to Paspipan is for someone outside the legal world, would you be able to explain about what exactly attribution is and why is attribution so central to how international law works in uh cyber conflict?
SPEAKER_00Yes, so attribution can in international law actually relates to the question if the violation um of a norm of international law can actually be attributed to a particular state. That is the normal or the standard question. The state as such cannot act on its own. It always needs normally state organs. For example, a soldier is a state organ, so if a soldier violates international law, that particular act can actually be attributed to that particular state he or she is working for because a state organ is always a representative of the state or the state itself. So this is the general um and standard rule of attribution. A state cannot act on its own, it needs state organs. Sometimes private individuals are directed or controlled by a state, and then even under very narrow circumstances, the acts of private actors can also be attributed to a state. This is like the standard question. We do have the International Law Committee's draft rules on state responsibility and they entail rules on attribution in articles four and so on and so forth. However, in the cyber context, attribution is a bit different because it actually raises the question whether a particular or who is responsible for a particular cyber attack. And as you've already mentioned at the beginning, identifying the perpetrators in the context of cyber operations is very, very tricky because of false flag operations, because we are still in the digital realm. So everything gets very, very complicated. And it is important to emphasize that in terms of attributing a certain cyber operation to a particular perpetrator, it might be a state actor, a non-state actor, it might be a non-state actor working for the state, being directed by that state, or it might be an on-state actor which just does everything on its own without state involvement, right? So there are many different ways how states and non-state actors can actually work together or not in a cyber context. And it is really important to bear in mind that in order to identify those perpetrators, we need to combine actually legal, political, and technical aspects. And I would like to start with the technical aspects. So you've mentioned, for example, false flag operations. It is absolutely paramount to say, well, exactly. We need to assess the technical side of things first. For example, do we have an IP number? Do we have maybe kind of other technological parameters, maybe zero-day exploits or whatever, in order to say, okay, these are indicators that a particular cyber operation has been undertaking, perpetrator A, working for state B, for example. And then comes the legal side of things. For example, is it true that that non-state actor has been working for a state? Has the state controlled that non-state actor? Is there any other state involvement in order to have kind of an orientation here? And then also the political dimension. And I think the political dimension cannot be overestimated in this regard. When I say political dimension, I mean there are certain indicators in order to assess who is responsible for a cyber operation that are not technical and that are not legal, but that are very important. For example, do we know, and um, and here again, new technology can play a very important role. Do we actually see more frequent attacks from a particular geographical region in the last couple of months? So let's assume there is not only one single cyber attack on February 5th, 2026, for example, but there are hundreds, even thousands of cyber attacks that can actually be located, um, at least the servers themselves can be located in the territory of state A. Let's assume that. And then the chance actually, or the possibility and the probability that that particular cyber operation actually stems from that state, at least from its territory, certainly is something that needs to be taken into consideration. So there are certain kinds of certain patterns that we need to interpret and take into consideration in order to attribute a certain cyber operation to a particular actor. One thing. Another thing is there are certain organizations and even platforms, online platforms, that actually monitor cyber events literally worldwide on a daily basis. And they can tell you the structure, the topology of a typical particular cyber operation, for example, is very similar to, let's say, cyber operations that have been undertaken by, for example, Russian Fancy Bear. So you can see that with the help of those organizations, with the help of those platforms, you can again identify certain patterns in order to increase the probability or to have more information whether or not the particular operation has been undertaken by a respective actor. So not only technical aspects play a role, not only legal aspects, but this kind of more political side or this pattern recognition. And here again, artificial intelligence could actually play a crucial role because it is very good at pattern recognition. And so we can monitor cyber events and better particular categories, so to say, and better assess them from a technical, political, and legal perspective. So this is really important. Because if a state is responsible for a cyber operation, the affected state can, for example, take measures against him. Maybe in practice, how do states act in practice? That might also be probably something listeners are might be very much interested in. It's interesting because um after the cyber operation or this kind of cyber attack, um Notpatya many years ago against Ukraine and many Ukrainian companies. I'm not going into details here, the response was interesting. It was not so much about did they really know, did Ukraine, Ukraine really know that Notpetya came from Russia actually? Well, the response by the United Kingdom and the Netherlands was they identified actually Russia as the perpetrator, but without actually qualifying the specific act and what kind of rule of international law was violated by the Notpatya attacks. The European Union, as such, for example, was primarily referring to a violation of international law without qualifying the specific event and telling or identifying whether or not a particular rule of international law was violated. But what is important is very often these kind of political elements that are referred to, they very often play a crucial role when states in practice hold a state responsible for a particular cyber operation. Sometimes they might not have all the information, but because of that pattern recognition, they take the decision to say, well, we're going to hold that state accountable because we have these kind of parameters and this kind of information.
SPEAKER_01Thank you, Ms. Pippin. That's some insightful information, I must say. So uh adding on, my next question too is when attribution is unclear or it's inconclusive, how does that affect the legal options available to a state under international law?
SPEAKER_00Yes. So if we are uncertain about attribution, um, especially with regard to a state, I mean um there are two different um things to that. First of all, holding someone accountable, a state or a non-state actor, actually we're doing that in order to assess our legal options. What can we do in response, right? So this is why we actually undertake measures of attribution. And it is important that in practice, most states do not take offensive measures when it comes to responses to cyber operations. Most states still take the decision to hold back and just defend themselves by increasing cyber protection, by making their systems, both in the public institutions as well as in the private sector, more secure to say, well, we need better ICT infrastructure, we need better cybersecurity, we need to have cybersecurity in place and really, you know, have this huge wall around us so that we cannot be as affected by cyber attacks. So that's not like an international law question. They can do whatever in order to increase their cybersecurity. It gets tricky when we undertake countermeasures to hold a state responsible for a potential cyber operation. And countermeasures, of course, can never be military countermeasures because it is just prohibited unless there was an armed attack. And then there is a possibility to defend yourself within the realm of Article 51 of the UN Charter. But any other cyber operation below that threshold does not allow for military countermeasures. But there are discussions going on, including in Germany, whether a state can take offensive cyber countermeasures, destroying the cyber infrastructure of a particular state, for example. And here the legal situation gets very tricky. Because in that case, we need to be 100% sure that particular cyber operation they are undertaking offensive countermeasures against stems from a particular state, or that the behavior of a non-state actor can really be attributed to that state. If that nonstate actor is a private entity, the state must at least have effective control over that private actor. If there is a private, for example, a hacker who infiltrates systems, destroys them with physical effect in the real world, a state can only be held responsible for that hacker, that private hacker, if the state controls that private actor within the meaning of Article 8 of the ILC draft articles on state responsibility. So here we need to be very, I would say, very cautious. Very certain, we can never be absolutely certain in a cyber context, but we need to be, we need to undertake our best efforts to really make sure if we hold a state responsible for a particular cyber operation, that it was this state. Because there is also this risk of miscalculation, which, at least in a security context, could then also increase escalation. If there is already tensions going on between two states, or there are tensions going on between several states, and we hold someone responsible for something the state has not done that might increase the risk of escalation.
SPEAKER_01Thank you, Ms. Pippin. That's some uh great information that we gathered today.
SPEAKER_02Today we explored how conflict has moved into the digital sphere, from cyber attacks with real-world consequences to information warfare and the persistent challenge of attribution. The battlefield is no longer defined by geography, but by code, infrastructure, and influence, blurring the lines between war and flood. As technology evolves faster than regulation, the pressing question is whether our legal and ethical frameworks can keep peace.
SPEAKER_01A massive thank you to Dr. Enzev Giffin for joining us. Thoughts, feedback, and questions are welcome. Thank you for listening to us.