top of page

Cyber Operations Below the Use-of-Force Threshold: Operationalising a Due Diligence Standard for Responsible State Conduct in Cyberspace

Policy Brief · International Law & Cyber Operations


This policy brief argues that international law needs a workable standard for cyber operations that fall below the Use-of-Force Threshold but still cause serious cross-border harm. Ransomware, disruptive intrusions, intellectual-property theft, and abuse of cloud or telecommunications infrastructure often do not trigger Article 2(4) of the UN Charter or the law of self-defense. The brief, therefore, proposes a capacity-calibrated due diligence standard focused on what a host state should reasonably do once it knows, or under the proposed standard reasonably should have known, that infrastructure within its territory, jurisdiction, or control is being used against another state.



Executive Summary


Most harmful cyber operations do not resemble traditional armed attacks. They can paralyze hospitals, disrupt public services, compromise data, or support hostile intelligence activity without reaching the scale and effects normally associated with the use of force. That leaves a difficult legal and policy gap: the victim state may suffer serious harm, while the territorial or host state may not be legally responsible for the underlying operation because the conduct is not attributable to it.


The brief does not claim that every harmful cyber operation creates state responsibility. It keeps the distinction between attribution and due diligence clear. Attribution asks whether the hostile cyber conduct can legally be treated as the act of a state. Due diligence asks a different question: once a state has notice that infrastructure under its jurisdiction is being misused, what must that state do about it?


The central argument is that states should not wait for full agreement on whether cyber due diligence is already binding customary international law. That point remains contested. Some states and regional organizations treat due diligence as flowing from sovereignty or responsible state behavior, while others have refused to recognize a specific customary obligation for cyber activities. The brief, therefore, recommends a practical middle course: states should converge around a defined operational standard through national positions, regional arrangements, and the UN Global Mechanism on ICT security.


The proposed standard would apply when cyber infrastructure within a state’s territory, jurisdiction, or control is used for conduct contrary to another state’s rights and causing, or creating a serious risk of, significant adverse consequences. It would be an obligation of conduct, not an obligation to guarantee that harm stops. A state would be judged by the reasonable and feasible measures available to it, including investigation, evidence preservation, cooperation, notification, containment, disruption, prevention of recurrence, and documentation.


Key Recommendations


  1. Adopt a defined operational due diligence standard rather than relying on vague diplomatic commitments or overstated claims of settled custom.

  2. Trigger the standard when a state has actual knowledge, or under the brief’s proposed constructive-knowledge threshold, reasonably should have known, of harmful cyber activity using infrastructure under its territory, jurisdiction, or control.

  3. Limit the standard to conduct contrary to another state’s rights that causes, or creates a serious risk of, significant adverse consequences, so minor or routine incidents do not trigger the full framework.

  4. Require states to assess the credibility and seriousness of information received before escalating the matter into formal response obligations.

  5. Require technically and legally feasible investigation, evidence preservation, and cooperation with the affected state, including through established incident-response channels.

  6. Give domestic authorities clear legal powers to require reasonable containment or disruption measures from infrastructure providers, subject to due process and proportionality safeguards.

  7. Use regional bodies, including the European Union, the African Union, and comparable organizations, to translate the standard into guidance for national CERTs and CSIRTs.

  8. Encourage states to document and, where appropriate, share response measures through mechanisms such as the UN Points of Contact Directory, building the practice and evidentiary record needed for future legal development.


Also read


Why the Use-of-Force Threshold Matters


The Use-of-Force Threshold matters because it marks the point at which the most serious rules of the jus ad bellum become relevant. Cyber operations that cross that threshold may implicate Article 2(4) of the UN Charter and, in the most severe cases, the right of self-defense. But most harmful cyber operations sit below that line. They are serious enough to damage public institutions, private infrastructure, and national security, yet not severe enough to be treated as a force.


That creates a recurring mismatch between legal categories and operational reality. A hospital ransomware attack, a cross-border intrusion into public networks, or the use of a third state’s cloud infrastructure by criminal operators may create major consequences without giving the victim state a clear use-of-force claim. Sovereignty, non-intervention, and state responsibility may help in some cases, but they do not by themselves answer what the host state must do when the wrongdoing is carried out by others from within its cyber ecosystem.


The brief’s contribution is to shift the debate away from abstract disagreement and toward an operational test. The key issue is not only whether cyber due diligence is already a binding custom. The more immediate problem is that states, private infrastructure providers, and victim governments lack a shared account of reasonable conduct after notice. A due diligence standard can reduce that uncertainty without turning every harmful packet of data into strict state liability.


The proposal is realistic because it does not impose identical burdens on all states. A state with advanced cyber agencies, mature incident-response structures, and regulatory authority over major cloud providers can do more than a state with limited technical capacity. The standard, therefore, scales with capacity while preserving a baseline expectation of cooperation. It also recognizes the role of private infrastructure: many meaningful responses will require states to act through legal authority over ISPs, cloud hosts, telecommunications carriers, and other private actors.


The brief is also cautious about legal status. It distinguishes actual knowledge grounded in Corfu Channel from the proposed constructive-knowledge extension. It treats “reasonably should have known” as a policy proposal for an operational standard, not as settled law. That distinction matters. Overclaiming the law would make the proposal less credible; underclaiming the need for action would leave victim states exposed to repeated harm with no predictable expectation of assistance.


Suggested Citation

Edmarverson A. dos Santos, Cyber Operations Below the Use-of-Force Threshold: Operationalizing Due Diligence in Cyberspace, Diplomacy & Law, 2026.


Diplomacy and Law Logo
bottom of page