Skip to main content
ExplainerCyber LawEvidence PackAug 31, 2026, 4:56 AM· 5 min read

The Legal Architecture of Cyber Warfare: Applying Jus ad Bellum and Jus in Bello to State-Sponsored Operations

International law governs cyber warfare by translating physical thresholds into algorithmic effects, but state practice continues to exploit the legal gray zone below the threshold of armed conflict.

By Miguel Carvalho

International Legal Scholars 40%State Military Commands 40%Humanitarian Organizations 20%
International Legal Scholars
Argues that existing international law, including the UN Charter and IHL, applies fully to cyberspace and seeks to codify specific rules for digital operations.
State Military Commands
Prioritizes operational flexibility, often maintaining strategic ambiguity regarding exact legal thresholds to avoid restricting offensive cyber capabilities.
Humanitarian Organizations
Focuses on the protection of civilians, arguing strongly that essential civilian data must be legally protected as an 'object' under International Humanitarian Law.

The competing cases

International Legal Scholars

Academics and legal experts seeking to codify how traditional laws of war apply to digital networks.

This perspective, most prominently represented by the authors of the Tallinn Manual, argues that the digital domain does not require a new treaty, but rather a rigorous translation of existing law. They assert that the 'scale and effects' test is sufficient to determine when a cyber operation constitutes a use of force. Their primary focus is establishing a predictable legal framework that holds states accountable for operations that cause severe disruption, even if those operations do not result in physical kinetic damage.

State Military Commands

National defense establishments balancing legal compliance with the need to maintain offensive and defensive cyber capabilities.

Military commands generally accept that international law applies to cyberspace, but they often resist overly restrictive interpretations of what constitutes a protected 'object' or a 'use of force.' By maintaining strategic ambiguity, states preserve the flexibility to conduct intelligence gathering, network preparation, and low-level disruptions without triggering the legal thresholds of armed conflict. They frequently argue that data, being intangible, does not automatically receive the same IHL protections as physical civilian infrastructure.

Humanitarian Organizations

Entities focused on mitigating the human cost of conflict, advocating for strict protections of civilian data and infrastructure.

Organizations like the ICRC view the legal architecture through the lens of civilian harm. They argue that the destruction of digital records—such as wiping a hospital's patient database or a municipality's social security registry—can cause humanitarian crises as severe as bombing a physical facility. This camp pushes for a broad interpretation of IHL that explicitly classifies essential civilian data as a protected object, requiring militaries to take extreme precautions to prevent cascading network effects.

What’s at stake

The rules of engagement in cyberspace determine whether a state-sponsored hack against critical infrastructure is treated as espionage, a criminal act, or an act of war that legally justifies a kinetic military response.

The legal architecture of cyber warfare rests on a simple but contested premise: a line of code can constitute an act of war, provided its consequences mirror those of a bomb. For decades, international law has divided conflict into two distinct domains: jus ad bellum, which governs the right to go to war, and jus in bello, which dictates the laws of conduct within an armed conflict. Applying these centuries-old frameworks to digital networks requires translating physical thresholds into algorithmic effects.[1][4]

This translation is not merely an academic exercise. It dictates whether a state-sponsored intrusion into a power grid is classified as espionage, a criminal act, or an "armed attack" that legally justifies a kinetic military response. The evidence pack surrounding this architecture reveals a system where the extremes are well-defined, but the operational middle remains a vast legal gray zone where state actors continuously test boundaries.[3][7]

The foundational threshold is jus ad bellum, anchored in Article 2(4) of the United Nations Charter, which prohibits the "use of force" between states. In the cyber domain, legal consensus relies heavily on the "scale and effects" test. If a cyber operation produces physical destruction or human casualties comparable to a conventional kinetic weapon, it crosses the threshold and triggers the right to self-defense under Article 51.[1][4]

The legal threshold for an armed attack in cyberspace relies heavily on the scale and effects of the operation.

The Tallinn Manual 2.0, the most comprehensive academic synthesis of how international law applies to cyberspace, codifies this in its rules. A cyber operation that deliberately triggers a meltdown at a nuclear facility, disables air traffic control systems to cause crashes, or opens the floodgates of a dam is universally recognized by legal scholars as a use of force.[3][5]

However, the evidence for consensus weakens significantly below the threshold of physical destruction. The vast majority of state-sponsored cyber operations—data theft, network disruption, and economic espionage—do not cause kinetic damage. Legal scholars and state doctrines diverge sharply on whether severe economic damage or the mass deletion of civilian data constitutes a use of force, leaving a gap that intelligence agencies routinely exploit.[1][7]

Once the threshold of armed conflict is crossed, the framework shifts to jus in bello, or International Humanitarian Law (IHL). The core principles of IHL—distinction, proportionality, and precaution—apply to cyber operations just as they do to artillery strikes. The International Committee of the Red Cross (ICRC) has explicitly stated that IHL governs cyber warfare during armed conflict, emphasizing that the digital domain is not a lawless void.[2][6]

The principle of distinction requires militaries to differentiate between civilian and military targets. In cyberspace, this presents a profound structural challenge. The internet is inherently dual-use; military communications, logistics, and command systems routinely ride on civilian fiber-optic networks, commercial cloud infrastructure, and shared satellite links.[2][3]

The majority of state-sponsored cyber operations remain below the threshold of physical destruction.
The principle of distinction requires militaries to differentiate between civilian and military targets.

Striking a military server hosted in a civilian data center requires a rigorous proportionality assessment. The anticipated military advantage of the cyber operation must be weighed against the expected incidental harm to civilian infrastructure. If a malware payload designed to disable a military logistics node risks cascading into the civilian healthcare network sharing the same routing infrastructure, IHL demands precautionary measures to limit the spread.[2][6]

The evidence regarding the protection of data under IHL remains highly contested. Traditional IHL protects civilian "objects" from attack. A critical legal debate centers on whether digital data constitutes an "object." If it does, deleting civilian data—such as national health records, banking ledgers, or electoral rolls—is a war crime.[2][4]

The ICRC argues strongly that essential civilian data must be protected, noting that the destruction of digital records can cause more severe humanitarian consequences than the destruction of physical buildings. Yet, several major military powers have historically resisted classifying intangible data as a protected object, fearing it would overly restrict their offensive cyber capabilities and intelligence-gathering operations.[2][6]

Another structural vulnerability in the legal architecture is the problem of attribution. Both jus ad bellum and jus in bello require identifying the actor responsible for an operation. Cyber warfare frequently employs proxies, false flags, and decentralized advanced persistent threat (APT) groups to obscure state involvement and maintain plausible deniability.[1][4]

International Humanitarian Law requires militaries to apply the principles of distinction and proportionality to digital targets.

The legal standard for attributing proxy actions to a state requires demonstrating "effective control" over the non-state actors. In the digital realm, proving that a state intelligence agency directed a specific ransomware syndicate to attack a hospital—rather than merely tolerating their existence within its borders—is an evidentiary hurdle that international courts have yet to fully resolve.[3][7]

The Tallinn Manual 2.0 attempts to bridge these gaps by outlining 154 rules governing cyber operations, expanding beyond wartime to include peacetime legal regimes like state sovereignty and non-intervention. It asserts that a cyber operation violating a state's sovereignty, even if it falls short of a use of force, is an internationally wrongful act requiring countermeasures.[3][5]

Yet, the Tallinn Manual is an academic study, not a binding treaty. State practice—the actual behavior of nations—often diverges from academic consensus. States frequently conduct operations that violate sovereignty but carefully calibrate them to remain below the threshold that would trigger Article 51 self-defense rights, effectively normalizing a baseline level of digital hostility.[1][5]

This calibration has created a persistent "gray zone" of continuous, low-level cyber conflict. Operations like the disruption of electoral systems, the deployment of wiper malware against corporate networks, and the manipulation of financial data operate in a space where the legal consequences are ambiguous and the enforcement mechanisms are weak.[4][7]

The dual-use nature of internet infrastructure complicates the legal requirement to distinguish between civilian and military targets.

The future of this legal architecture depends on how states publicly articulate their cyber doctrines. While some nations have begun publishing formal legal positions on how international law applies to cyberspace, many prefer strategic ambiguity, allowing them maximum operational flexibility without committing to restrictive legal interpretations that could limit future capabilities.[1][7]

Ultimately, the application of jus ad bellum and jus in bello to cyberspace demonstrates the resilience of international law, but also its limits. The principles of distinction and proportionality remain valid, but the interconnected, intangible nature of digital infrastructure requires a continuous, evidence-based reassessment of what constitutes an attack, an object, and an act of war.[2][6][7]

Unsettled ground

  • How international tribunals will ultimately rule on the mass destruction of civilian data that results in severe economic harm but no physical casualties.
  • The exact threshold at which a cumulative series of low-level, non-kinetic cyber operations legally constitutes an 'armed attack.'
  • How states will legally attribute and respond to cyber operations conducted entirely by autonomous, AI-driven malware systems.

Sources

Source coverage

7 outlets

3 viewpoints surfaced

International Legal Scholars 40%State Military Commands 40%Humanitarian Organizations 20%
  1. [1]U.S. Naval War College Digital CommonsState Military Commands

    Cyberspace and the Jus ad Bellum: The State of Play

    Read on U.S. Naval War College Digital Commons
  2. [2]ICRC Humanitarian Law & Policy BlogHumanitarian Organizations

    Towards common understandings: the application of established IHL principles to cyber operations

    Read on ICRC Humanitarian Law & Policy Blog
  3. [3]American University National Security Law BriefInternational Legal Scholars

    The Tallinn Manual 2.0 on Nation-State Cyber Operations Affecting Critical Infrastructure

    Read on American University National Security Law Brief
  4. [4]Penn State Journal of Law & International AffairsInternational Legal Scholars

    The Jus Ad Bellum in Cyberspace: A New Framework

    Read on Penn State Journal of Law & International Affairs
  5. [5]Atlantic CouncilInternational Legal Scholars

    Tallinn Manual 2.0 Clarifies How International Law Applies to Cyber Operations

    Read on Atlantic Council
  6. [6]UNICRIHumanitarian Organizations

    The application of international humanitarian law to non-kinetic cyber operations

    Read on UNICRI
  7. [7]Factlen Editorial Team

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team

Comments

Stay informed

Every angle. Every day.

Get defense security stories with full source coverage and perspective breakdowns delivered to your inbox.