eBooks

Cyber Law

Introduction

0713
2026
978-3-8385-6587-3
978-3-8252-6587-8
UTB 
Stefan A. Kaiser
Stephan Hobe
10.36198/9783838565873

Der schnelle Einstieg ins Thema Das englischsprachige Lehrbuch führt prägnant in die Querschnittsmaterie des Cyberrechts ein. Es erläutert die Terminologie, definiert den Rechtsbereich und beleuchtet das Cyberrecht völkerrechtlich. Auch auf die Bedeutung des Cyberrechts in der Luftfahrt und auf Cyberaktivitäten im Weltraum geht es ein. Die Themen Automatisierung und Künstliche Intelligenz lässt es zudem nicht außer Acht. Das Buch richtet sich an Studierende der Rechtswissenschaften, der Luft- und Raumfahrttechnik sowie der Informatik.

9783838565873/9783838565873.pdf
<?page no="0"?> Stefan A. Kaiser Stephan Hobe Cyber Law <?page no="1"?> utb 6587 Eine Arbeitsgemeinschaft der Verlage Brill | Schöningh - Fink · Paderborn - Vandenhoeck & Ruprecht · Göttingen - Böhlau · Wien · Köln Verlag Barbara Budrich · Opladen · Toronto facultas · Wien Walter de Gruyter · Berlin · Boston Haupt Verlag · Bern Verlag Julius Klinkhardt · Bad Heilbrunn Mohr Siebeck · Tübingen Narr Francke Attempto Verlag - expert verlag · Tübingen Psychiatrie Verlag · Köln Psychosozial-Verlag · Gießen Ernst Reinhardt Verlag · München transcript Verlag · Bielefeld Verlag Eugen Ulmer · Stuttgart UVK Verlag · München Waxmann · Münster · New York wbv Publikation · Bielefeld Wochenschau Verlag · Frankfurt am Main <?page no="2"?> Stefan A. Kaiser, LL.M. (McGill), is a Visiting Lecturer at the Faculty of Law at the University of Cologne’s Insti‐ tute of Air Law, Space Law and Cyber Law, and retired Legal Advisor of the NATO Airborne Early Warning and Control Force. Professor Dr. Stephan Hobe is the director of the Insti‐ tute of Air Law, Space Law and Cyber law at the University of Cologne and the Head of the International Investment Law Centre Cologne. He is member of numerous national and international law associations and has authored around 500 articles and books. <?page no="3"?> Stefan A. Kaiser / Stephan Hobe Cyber Law Introduction <?page no="4"?> DOI: https: / / doi.org/ 10.36198/ 9783838565873 © UVK Verlag 2026 ‒ Ein Unternehmen der Narr Francke Attempto Verlag GmbH + Co. KG Dischingerweg 5 · D-72070 Tübingen Das Werk einschließlich aller seiner Teile ist urheberrechtlich geschützt. Jede Verwertung außerhalb der engen Grenzen des Urheberrechtsgesetzes ist ohne Zustimmung des Verlages unzulässig und strafbar. Das gilt insbesondere für Vervielfältigungen, Übersetzungen, Mikro‐ verfilmungen und die Einspeicherung und Verarbeitung in elektronischen Systemen. Alle Informationen in diesem Buch wurden mit großer Sorgfalt erstellt. Fehler können dennoch nicht völlig ausgeschlossen werden. Weder Verlag noch Autor: innen oder Heraus‐ geber: innen übernehmen deshalb eine Gewährleistung für die Korrektheit des Inhaltes und haften nicht für fehlerhafte Angaben und deren Folgen. Diese Publikation enthält gegebenenfalls Links zu externen Inhalten Dritter, auf die weder Verlag noch Autor: innen oder Herausgeber: innen Einfluss haben. Für die Inhalte der verlinkten Seiten sind stets die jeweiligen Anbieter oder Betreibenden der Seiten verantwortlich. Internet: www.narr.de eMail: info@narr.de Einbandgestaltung: siegel konzeption | gestaltung Druck: Elanders Waiblingen GmbH utb-Nr. 6587 ISBN 978-3-8252-6587-8 (Print) ISBN 978-3-8385-6587-3 (ePDF) ISBN 978-3-8463-6587-8 (ePub) Umschlagabbildung: © NicoElNino ∙ iStock Autorenbild Kaiser: © privat Autorenbild Hobe: © privat Bibliografische Information der Deutschen Nationalbibliothek Die Deutsche Nationalbibliothek verzeichnet diese Publikation in der Deutschen Nationalbibliografie; detaillierte bibliografische Daten sind im Internet über http: / / dnb.dnb.de abrufbar. <?page no="5"?> 9 11 1.1 11 1.1.1 12 1.1.2 13 1.1.3 14 1.2 15 1.2.1 16 1.2.2 16 1.2.3 17 1.2.4 19 1.2.5 20 1.3 20 1.3.1 21 1.3.1.1 21 1.3.1.2 21 1.3.2 22 1.3.2.1 23 1.3.2.2 23 1.3.2.3 25 1.3.2.4 25 1.4 26 1.4.1 26 1.4.2 27 1.4.2.1 28 1.4.2.2 29 1.4.3 30 1.4.4 31 Contents Preface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Chapter One · Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Examples of Definitions . . . . . . . . . . . . . . . . . . . . . . . . . . . . Other Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . The Role of Terminology and Definitions . . . . . . . . . . . . . Technical Background . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Computers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Data, Information and Software . . . . . . . . . . . . . . . . . . . . . Networks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Peripheral Devices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Cloud Computing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Distinctions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Cyber Activity and Cyberspace . . . . . . . . . . . . . . . . . . . . . Cyber Activities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Cyber Space . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Non-Networked Activities . . . . . . . . . . . . . . . . . . . . . . . . . Physical Acts Against Infrastructure . . . . . . . . . . . . . . . . . Harmful Radio Interference and Jamming . . . . . . . . . . . . Spoofing of Navigation and Surveillance Signals . . . . . . . Directed Energy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . The Role of Law . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Non-Binding Standards . . . . . . . . . . . . . . . . . . . . . . . . . . . . Unauthorised Cyber Activities . . . . . . . . . . . . . . . . . . . . . Preventive Cyber Security Measures . . . . . . . . . . . . . . . . . Attribution and Liability . . . . . . . . . . . . . . . . . . . . . . . . . . . Armed Conflict . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Information Content, Digital Market and Participation . <?page no="6"?> 35 2.1 35 2.2 39 2.3 42 2.3.1 44 2.3.2 45 2.4 46 2.4.1 47 2.4.2 49 2.4.3 50 2.5 52 2.6 54 2.6.1 55 2.6.2 56 2.6.3 57 59 3.1 59 3.1.1 59 3.1.2 60 3.1.3 61 3.1.4 62 3.2 65 3.2.1 65 3.2.2 66 3.3 68 3.3.1 68 3.3.2 69 3.3.3 69 3.4 71 3.4.1 72 3.4.2 73 3.4.3 73 3.4.4 75 3.5 78 3.6 80 Chapter Two · Cyber Law and Public International Law . . . . . . . . . . . . Sovereignty . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Public International Law Principles applicable to Cyber Activities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Jurisdiction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Jurisdiction in Cyber Space? . . . . . . . . . . . . . . . . . . . . . . . . Jurisdiction linked to Cyber Activities . . . . . . . . . . . . . . . State Responsibility . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Legal Attribution . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Factual Attribution of Cyber Activities . . . . . . . . . . . . . . . Breach of International Obligations . . . . . . . . . . . . . . . . . . Criminal Law Treaties . . . . . . . . . . . . . . . . . . . . . . . . . . . . Armed Conflict . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Self-Defence and Armed Attack . . . . . . . . . . . . . . . . . . . . . Cyber Activities in Armed Conflict . . . . . . . . . . . . . . . . . . International Humanitarian Law . . . . . . . . . . . . . . . . . . . . Chapter Three · Unauthorised Cyber Activities and Cyber Security . . . Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Examples of Definitions . . . . . . . . . . . . . . . . . . . . . . . . . . . . Confidentiality, Integrity, Availability . . . . . . . . . . . . . . . . Distinctions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Unauthorised Cyber Activities . . . . . . . . . . . . . . . . . . . . . . Methods and Vulnerabilities . . . . . . . . . . . . . . . . . . . . . . . . Criminal Cyber Activities . . . . . . . . . . . . . . . . . . . . . . . . . . Unauthorised Actors . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Motivation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Sophistication . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Attribution . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Cyber Security Measures . . . . . . . . . . . . . . . . . . . . . . . . . . . Risk Management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Behavioural Measures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Organisational and Operational Measures . . . . . . . . . . . . Technical Measures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Mandatory Law and Voluntary Schemes . . . . . . . . . . . . . Safety Standards versus Security Standards . . . . . . . . . . . 6 Contents <?page no="7"?> 3.7 80 3.8 81 83 4.1 83 4.1.1 83 4.1.1.1 84 4.1.1.2 84 4.1.1.3 86 4.1.2 87 4.1.2.1 87 4.1.2.2 87 4.1.3 90 4.1.3.1 90 4.1.3.2 92 4.1.3.3 95 4.2 96 4.3 98 4.4 99 101 5.1 101 5.1.1 101 5.1.2 105 5.1.2.1 105 5.1.2.2 105 5.1.3 109 5.1.3.1 110 5.1.3.2 112 5.1.3.3 114 5.1.3.4 115 5.2 117 5.3 118 5.4 120 Active Measures against Actors of Unauthorised Cyber Activities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Remarks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Chapter Four · Cyber Activities in the Aviation Sector . . . . . . . . . . . . . . Cyber Security in the Aviation Sector . . . . . . . . . . . . . . . . Technical Background . . . . . . . . . . . . . . . . . . . . . . . . . . . . . The Role of Communications and Networks . . . . . . . . . . Air-Ground Communications . . . . . . . . . . . . . . . . . . . . . . . Ground-Ground Communications and Networks . . . . . . Vulnerabilities and Threats . . . . . . . . . . . . . . . . . . . . . . . . . Vulnerabilities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Threats . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Legal Sources and Approaches . . . . . . . . . . . . . . . . . . . . . . International Civil Aviation Organisation . . . . . . . . . . . . European Union and European Union Aviation Safety Agency . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Other Regulations, Standards and Guidance . . . . . . . . . . Criminal Liability . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Private Liability . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Remarks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Chapter Five · Cyber Activities in the Space Sector . . . . . . . . . . . . . . . . . Cyber and Communication Security in the Space Sector Technical Background . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Vulnerabilities and Threats . . . . . . . . . . . . . . . . . . . . . . . . . Vulnerabilities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Threats . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Legal Sources and Approaches . . . . . . . . . . . . . . . . . . . . . . National Legislation, Policy and Guidance . . . . . . . . . . . . European Union . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Best Practice Guidelines . . . . . . . . . . . . . . . . . . . . . . . . . . . Harmful Radio Interference . . . . . . . . . . . . . . . . . . . . . . . . State Responsibility and Liability . . . . . . . . . . . . . . . . . . . . Cyber Infrastructure in Outer Space . . . . . . . . . . . . . . . . . Remarks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Contents 7 <?page no="8"?> 123 6.1 123 6.1.1 123 6.1.1.1 123 6.1.1.2 125 6.1.2 126 6.1.3 128 6.2 131 6.2.1 132 6.2.2 135 6.2.3 135 6.2.4 138 6.2.4.1 139 6.2.4.2 139 6.2.4.3 140 6.2.4.4 140 6.2.5 141 6.2.6 143 6.3 144 6.4 145 6.5 146 149 150 Chapter Six · Automation and Artificial Intelligence . . . . . . . . . . . . . . . . Automation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Concepts and Terminology . . . . . . . . . . . . . . . . . . . . . . . . . Automation of Kinetic Functions . . . . . . . . . . . . . . . . . . . . Automation of Non-Kinetic Functions . . . . . . . . . . . . . . . Automation in Aviation and Space Operations . . . . . . . . Legal Considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Artificial Intelligence . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Concepts and Terminology . . . . . . . . . . . . . . . . . . . . . . . . . Artificial Intelligence in Aviation and Space Operations Legal Considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . EU Approach to Artificial Intelligence . . . . . . . . . . . . . . . Prohibited AI Practices . . . . . . . . . . . . . . . . . . . . . . . . . . . . High-Risk AI Systems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Certain AI Systems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . General Purpose AI Models . . . . . . . . . . . . . . . . . . . . . . . . EASA Approach to Artificial Intelligence . . . . . . . . . . . . UN Approach to Artificial Intelligence . . . . . . . . . . . . . . . Cyber Nexus of Automation and AI . . . . . . . . . . . . . . . . . . Side Note: Legal Personality? . . . . . . . . . . . . . . . . . . . . . . . Remarks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . For further reading . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Index . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 Contents <?page no="9"?> Preface Cyber law is a cross-sectional discipline. It has numerous intersections with tech‐ nology, law and the industrial, governmental and military sectors where cyber activities are undertaken. On the technology side, computers, data, information, networks, telecommunications and automated kinetic systems are involved. On the legal side, there are implications of public, private and international law. The point of origin of this book is cyber activities, as opposed to cyber space. Cyber law is understood as the law relating to cyber activities. Like for other activities, humans bear indispensable responsibility for cyber activities. This book is an elaboration of lectures on cyber law held at the Institute of Air Law, Space Law and Cyber Law of the University of Cologne. The purpose of this lecture was twofold: to give a general introduction to cyber law and to show its interrelation with air and space law. This book introduces to the law relating to authorised and unauthorised cyber activities from a perspective of public international and European Union law, mainly during peacetime. Its focus is not on domestic law, information content, data protection, the promotion of digital markets and transactions affected over the internet. It neither addresses freedom of speech, hate speech and social media. An introductory chapter concisely maps the technical and legal notions of cyber activities (→ chapter one). Regarding public international law, it is shown how cyber activities in inter-State relations match existing legal concepts (→ chapter two). Cyber security is a field of high practical relevance for protecting against unauthorised cyber activities (→ chapter three). Following the objectives of the Institute, special emphasis is put on legal cyber aspects in the aviation and space sectors. Cyber security plays a central role in both sectors. Special issues arise from the creation of network infrastructures in outer space (→ chapters four and five). Automation and artificial intelligence are distinct but related to cyber activities. Legal considerations and existing regulatory approaches to automation and artificial intelligence are discussed. Automation is highly advanced in aviation and space flight (→-chapter six). Special thanks go to Dr. Martha Mejía-Kaiser for her expert inputs to this book. Cologne, March 2026 Stefan A. Kaiser Stephan Hobe <?page no="10"?> 1 Tom Standage, The Victorian Internet, page 1, London, 1998. “During Queen Victoria’s reign, a new communications technology was developed that allowed people to communicate almost instantly across great distances, … cables spanned continents and oceans, it revolutionized business practice, gave rise to new forms of crime, and inundated its users with a deluge of information. … Secret codes were devised by some users, and cracked by others. The benefits of the network were relentlessly hyped by its advocates, and dismissed by its sceptics. Gov‐ ernments and regulators tried and failed to control the new medium. Attitudes to everything from newsgathering to diplomacy had to be completely rethought. Meanwhile, out of the wires, a technological sub‐ culture with its own customs and vocabulary was establishing itself.” Tom Standage on electric telegraphy in the nineteenth century 1 10 Preface <?page no="11"?> 1 Norbert Wiener, Cybernetics: Or Control and Communication in the Animal and the Machine. Paris, Cambridge, Mass., 1948. 2 Wiener, id., page 4. Chapter One · Introduction Cyber law is difficult to grasp. The technical meaning of cyber is diffuse. What is broadly called cyber has an impact on society, culture, human and business relations. Law makers endeavour to establish rules for human conduct, when using complex and continuously evolving cyber technology. Cyber applications can affect all spheres of human life. The technical and human variables create difficulties for any kind of rulemaking that we may call cyber law. Governments wish to protect legitimate users and innocent by-standers, prevent misuse and sanction related crime. This is the foundation of what can be called cyber law. But what is cyber? 1.1 Terminology Understanding the concept of cyber is a pre-requisite for understanding the relations of humans engaged in cyber activities and hence the basis of cyber law. However, the term cyber is inconsistently used in different contexts. Etymologically, the term cyber is derived from ancient Greek ‘kybernetes’ which addressed a person in charge of steering or piloting a maritime vessel. In 1948 the mathematician and philosopher Norbert Wiener created the modern term of cybernetics. In his groundbreaking work he combined computing and automated control loops with communication and the impact on living beings. 1 His theories extended beyond mechanical means for control loops. He suggested that for these purposes a computing machine should operate numerically, with electronics, without human intervention during the sequence of operation and include a data memory. 2 <?page no="12"?> 3 Organisation for International Standardization, IEC 27032: 2012, section 4.21. 4 National Institute of Standards and Technology, US Department of Commerce, NIST Special Publication 800-30 5 US. Air Force Doctrine, Joint Publication 3-12, Cyberspace Operations 1.1.1 Examples of Definitions Today, the term cyber is used broadly for modern electronics and digital data in computers and networks, but there is no internationally agreed definition. Existing definitions have different focus and remain vague and broad. Various institutions define cyber not as a stand-alone term, but with additional attributes like cyberspace, cyber environment or cyber ecosystem. Cyberspace has become a common notion used in everyday language. The Organisation for International Standardization defines cyberspace as “complex environment resulting from the interaction of people, software and services on the Internet by means of technology devices and networks connected to it, which does not exist in any physical form.”  3 This definition rightly identifies that cyberspace does not exist in any physical form, which means cyberspace is not a physical space. However, the phrase ‘complex environment resulting from the interaction of people’ does not add value. It fails to define how people interact with software, services, technology devices and connected networks or how the listed software, hardware and service interact with each other. In a similar fashion, the National Institute of Standards and Technology (NIST) of the US Department of Commerce defines cyberspace as: “A global domain within the information environment consisting of the interde‐ pendent network of information systems infrastructures including the Internet, telecommunications networks, computer systems, and embedded processors and controllers.”  4 The US. Air Force uses an almost identical definition of cyberspace: “Cyberspace is a global domain within the information environment … consisting of the interdependent networks of information technology infrastructures and resident data, including the internet, telecommunications networks, computer systems, and embedded processors and controllers.”  5 Both definitions use the phrase ‘global domain within the information environment’ which remains an empty shell. It does not define the nature 12 Chapter One · Introduction <?page no="13"?> 6 National Institute of Standards and Technology, US Department of Commerce, NIST Special Publication 800-30 7 International Telecommunication Union, Rec. ITU-T X.1205 (04/ 2008), 3.2.4 8 International Convention on Cyber Crime, Budapest, 2001, ETS 185 9 International Convention on Cyber Crime, id. Article 1. or function of cyberspace, nor the delimitations of such a space. The enu‐ meration of technical elements neither explains the functional relationship between them, nor does it give an insight into the meaning of cyberspace. Ecosystem is a term that gained popularity more recently. NIST defines cyber ecosystem as: “The aggregation and interactions of a variety of diverse participants (such as private firms, non‐profits, governments, individuals, and processes) and cyber devices (computers, software, and communications technologies).”  6 This definition focuses on the interaction of humans and technical devices. Like the other definitions, it fails to characterize how they interact with cyber technology. Apart from that, the term cyber ecosystem can be misperceived. It is not related to the original meaning of an ecosystem that supports biological life. Even more loose is the following definition of the International Telecom‐ munication Union (ITU) of cyber environment: “This includes users, networks, devices, all software, processes, information in storage or transit, applications, services, and systems that can be connected directly or indirectly to networks.”  7 This phrase is a mere summary of connected system elements that does not lead to a conceptual description of cyber. 1.1.2 Other Terminology The Budapest Convention on Cyber Crime 8 takes a different approach. It does not define the term cyber and mentions it only in its title. Instead, the definition section includes terms like computer system, computer data and data traffic. 9 Moreover, in its section on ‘criminal offences against the confidentiality, integrity and availability of computer data and systems’ the Convention determines six criminal offences that use software and computer technology as a tool: illegal access, illegal interception, data 1.1 Terminology 13 <?page no="14"?> 10 International Convention on Cyber Crime, id., Articles. 2 - 5, 7, 8. interference, system interference and computer related forgery and fraud. 10 This methodology avoids defining cyber, but nevertheless determines, for purposes of criminal law, seven generic activities which use technical means of computer data and systems. This approach is rooted in the requirement of specificity in criminal law. Clear and precise terminology of criminal offences is to assure legal certainty and fairness of process. Interestingly, the Budapest Convention provides a clearer picture of (selected, criminal) cyber activities than the definitions mentioned above. For the sake of completeness, some other terms should be mentioned which are partly used synonymously for the concepts addressed by term cyber or overlap with it. Not surprisingly, these terms are similarly vague and broad and lack a generally accepted definition. Digitalization refers to the technical change from analogue to digital data formats which are the basis for today’s computers and networks. From a technical viewpoint, digitalization highlights the binary nature of digital data, but not connectivity and inter-operability of networks. In non-technical contexts, digitalization is often used more generally to express the changes in human interaction when using digital data and information, computers and networks instead of non-electric, especially paper-based, means. The expressions internet or on-line are frequently used as attributes to other terms, for example as internet law or on-line law. In a narrow tech‐ nical sense, both internet and on-line relate to a (continuous) networking functionality, but in public usage it comprises more generally human inter‐ action with networked computers. Information and Communication Technology (ICT) is a generic term for hardand software of computers, networks and connected peripheral devices. The concept of information society is focused on the societal impact of the use and processing of digital information, even though it does not mention the digital format of information and the (ICT) infrastructure required for it. 1.1.3 The Role of Terminology and Definitions Precise definitions are key for any analysis of legal relations among humans. This applies especially to technologies, whose concepts are not precisely re‐ flected in the terminology used by the public. Cyber terminology originates from the technical area. With the transition from specialist applications to 14 Chapter One · Introduction <?page no="15"?> consumer products and services, the language of technical experts used for cyber technologies found its way to everyday language of the public. While the cyber terminology among experts appears not to have been consistent from the beginning, its use in public is adding more imprecisions. As law does not anticipate, but follows societal and technical develop‐ ments, lawyers take the language which is commonly used in the specific field and in society. Lawyers have thus adopted the existing language used in public for cyber technologies with all its inaccuracies. Unlike other disciplines, lawyers do not, or only exceptionally, work with numerics, mathematical equations or graphics. Language is the tool of law. The use of imprecise and non-standardized terminology leads to inconsistent results in legal practice. Precision of language determines the precision of law. Even more complicating is the metaphoric use of language. The common term cyberspace can be misleading, because it is not a physical, three-dimensional space. Legal concepts about the status of physical spaces cannot be applied. The same applies to the metaphoric use of the term ecosystem. It appears that technical specialists use this term to express human factors and human interaction with information technology. Differently thereto, lawyers need not highlight that humans use and interact with technology like cyber. The focus of law is on the rights and obligations of humans. For legal purposes, broad inclusive definitions are not helpful, up to the point where they become meaningless. When terms are not well or too broadly defined, or when metaphoric language is used, they become black boxes with unclear content. Instead, definitions should be more narrowly focused to concentrate on what is important. In a legal context, definitions of technology should portray the technical functionality. A mere listing of (technical) elements and features is not sufficient. A machine or technical feature is more than the sum of its elements. A definition needs to express the functional concept behind terminology. 1.2 Technical Background Understanding the functional concepts behind the technology generically called cyber require a look at the involved technical elements and their interaction. Important technical elements are computers, digital data, soft‐ ware, networks and peripheral systems. 1.2 Technical Background 15 <?page no="16"?> 1.2.1 Computers Computers cover a broad range of hardware electronics from large main‐ frame computers to personal computers. Many of them are not even called computers, like smart phones or smart watches. Many are embedded in machinery as complex as aircraft, spacecraft, industrial special purpose machines, cars down to household appliances. Even chipcards, like bank or credit cards, can qualify as computers because they possess, at small scale, the crucial hardware features of a computer. What are these features? The heart of a computer is its central processing unit (CPU). This is a piece of hardware which consists of a microprocessor that can process digital data. A microprocessor is assisted by hardware for memorizing data. Essential is also a Random Access Memory (RAM), a fast short-term memory for data during the processing activity of the CPU. The hardware architecture of a CPU is designed to allow the processing of data in different ways. The hardware of a CPU does not determine how data is processed. The way of processing is determined by software. Software contains instructions for a CPU how to treat data and to store the result. With these instructions, the software programs a CPU. CPUs are freely programmable for any desired application. 1.2.2 Data, Information and Software For computing, both data and software are in digital format. This format is machine readable, can be electronically transmitted, and its smallest unit (bit) consists of only two (digital) states: zero or one. Data is the matter which a computer processes. Different to data, information is understood as a more complex structured assembly of processed data which has a meaning in a context. Software is a special type of information which consists of a compilation of lines of digital code. These lines of code determine how a CPU is processing data. Its structure forms self-executable instructions for a CPU, which does not need to be called or triggered for each step. The content of software (semantics) is designed for prompting a (processing) step of the CPU. The various lines of code of software are compiled in a coherent way (syntax). 16 Chapter One · Introduction <?page no="17"?> 1.2.3 Networks Networks are a means of signal transmission. Signals can be electrically transmitted through wires, optically through fibre or wirelessly between radio transmitting and receiving stations. Cables with wires or fibres span over land and at the bottom of the seas. Wireless transmissions use electromagnetic waves which can travel through the Earth’s atmosphere or involve radio stations on board of space objects in outer space, most notably telecommunication satellites. Wired telecommunication started as electrical telegraphy in the 19 th century, followed by telephony and, in the early 20 th century by wireless radio transmissions. Following a few decades of experimentation, starting in the 1980s networks transitioned on a broad scale from analogue to digital formats of data transmission. After some Californian universities had connected their internal computer networks, the introduction of the Transmission Control Protocol and the Internet Protocol (TCP/ IP) allowed for interoperability of different networks. This led in the early 1990s to an opening of this network to other users and became the beginning of the internet. Internet and IP-Based Networks The internet is understood as the network of networks which uses soft‐ ware-based protocols for achieving interoperability. Internet Protocol (IP) based networks consist of software and hardware infrastructure. The hard‐ ware entails computers with specialized network functions, for example switches, routers and servers. The hardware of an Internet Protocol based network comprises the same type of computers it connects, but with software that performs network functions. A crucial technical feature of IP-based networks is packet switched data transmission: Information sent across a network is divided into small packets which include routing and address information. The packets are independently routed to the receiver and can take different paths through networks. Finally, the various packets are reassembled to the original information. As an advantage, packet switched transmissions use bandwidth efficiently and routing is flexible. No communication line needs to be reserved for transmitting specific information to a receiver, as opposed to so-called circuit switching. 1.2 Technical Background 17 <?page no="18"?> 11 E.g. the seven layer Open Systems Interconnection (OSI) model. 12 The current IP protocol versions 4 and 6 (IPv4, IPv6) originate from the 1981 Defense Advanced Research Projects Agency’s (DARPA) Internet Protocol Specification, pre‐ pared by the Information Sciences Institute of the University of Southern California, 🔗 https: / / www.rfc-editor.org/ rfc/ rfc791 (accessed March 2026) - IPv6 is based on rfc8200 of the Internet Engineering Task Force (IETF), 🔗 https: / / www.rfc-editor.org/ rfc/ rfc82 00 (accessed March 2026) The technical functioning of the internet can best be described by so-called layer models. Depending on the degree of detail, models with a different number of layers are used. 11 Each layer explains a certain network function and uses different standardized software protocols. For simplicity, only the following four layers are explained here: • The Physical Layer consists of hardware like (end-user) computers of Local Area Networks and IP-based network and communication infrastructure. • The Data Link Layer is the interface of Local Area Networks (LAN) with the internet (layer). It uses the so-called Address Resolution Protocol (ARP) to translate IP addresses of the internet to hardware addresses of the LAN’s physical layer, and vice versa. • The Transport and Internet Layers are the central elements of this model. They connect Local Area Networks among each other. The Transport Control Protocol (TCP) manages packet switching. The Internet Protocol (currently versions IPv4, IPv6) implements the internet layer and achieves the addressing of hardware for the transmission of packets. • At the Application Layer, end-users receive and transmits informa‐ tion. HTTP (Hypertext Transfer Protocol) and JPEG ( Joint Photographic Experts Group) are examples of protocols used in this layer. Each of these layers has its specific function. Each layer uses specific standardized protocols. The Transport and Internet Layers form the con‐ nection of local networks and are the core of the internet as network of networks. Interoperability of the crucial Transport and Internet Layers is mainly achieved through two elements: the same protocols (TCP/ IP) and standardized and administered (IP) addresses and domain names. TCP/ IP protocols are open, public domain standards. 12 The centralized, worldwide coordination of internet addresses and domain names is achieved by the 18 Chapter One · Introduction <?page no="19"?> 13 www.icann.org (accessed March 2026) Internet Corporation for Assigned Names and Numbers (ICANN). It was incorporated in California in 1998 as a not-for-profit partnership. 13 The success and worldwide acceptance of the internet is a result of open protocols and worldwide address coordination. Another factor for success is the decentralized ownership of infrastructure. Telecommuni‐ cation service providers and local network operators, including private, commercial and governmental users, voluntarily connect their hardware infrastructure. With open protocols and address coordination, they achieve global connectivity and interoperability of the constantly growing internet and connected local networks. The success of IP-based networks led tradi‐ tional wired telephone networks to migrate to IP-based technology, called voice over internet protocol (VoIP). Modern cellular telephone networks, especially the fourth and fifth generation (4G, 5G) are also IP-based, so that they provide internet connectivity. Their wirelessly connected user units become part of the internet infrastructure. Due to standardized signal formats, IP-based networks can transmit not only digital information which represents facts, but software alike. Such software can (re-)program the computer at the receiver end of the transmission. Unauthorised reprogramming is one of the starting points for cyber security. 1.2.4 Peripheral Devices For several decades, computers were operated as data islands. Data in‐ puts were processed, stored and an output was generated and displayed. Computers controlled physical functions only in a limited fashion, for example printers or scanners. Specialized control functions of physical devices have been used for decades, for example in aviation and automotive electronics, but they were not connected to networks. This changed with increasing use of the internet and plummeting cost of electronics. A new generation of physical devices which formerly had not been controlled by electronics were given the capability to connect to the internet. They became network connected peripheral devices, controlled and monitored by computer technology, acting in the physical world. The area of applications of peripheral devices is far-ranging, from industrial, commercial, scientific, military to domestic applications, for example smart homes. The integration 1.2 Technical Background 19 <?page no="20"?> of peripheral devices is commonly called the Internet of Things (IoT). It allows control and monitoring of peripheral devices in the physical sphere over distance, but also information exchanges between peripheral devices and sensors, for example cameras. Automated applications are related to peripheral devices. Control and monitoring functions of physical peripheral devices can take the role of networked automation with reduced or no human intervention. Today, many critical infrastructures, for example in the sectors of energy, traffic, water and medicine, are dependent on these control and monitoring functions. This is one of the reasons, why the internet and connected networks themselves are treated as critical infrastructure today. Acts directed against and through the internet can influence connected peripheral devices in the physical sphere and pose threats to safety related functions and critical infrastructure. Such kind of acts against and through networks need to be distinguished from physical acts against physical infrastructures and devices directly. 1.2.5 Cloud Computing Increasing speed and bandwidth of internet connections allow users to ex‐ ternalize part of their physical computer hardware. Data centres can provide their physical computer hardware to users over the internet. As a business model, data centres offer against reimbursement on-demand services like software, databases, and analytics which run on their hardware. They also provide platforms for running and developing software applications. These services are called cloud computing, because users do not know the physical location of the infrastructures where the software is running. The term cloud does not imply that these infrastructures are in the airspace or outer space. In States where a data centre provides its cloud computing services, the legal protections of users can be lower than in the State from where he accesses these services. 1.3 Distinctions Considering the manifold technical and human aspects, several factual and legal distinctions should be made for clarification of the concept of cyber in legal contexts and to sharpen the focus of this book. 20 Chapter One · Introduction <?page no="21"?> 1.3.1 Cyber Activity and Cyberspace 1.3.1.1 Cyber Activities The concept of ‘cyber activity’ appears best suited to portray the relations of legal subjects engaged in networked computing of digital data and information. Legal rights and obligations result from acts and omissions of legal subjects. The intangible nature of digital computer operations through networks does not change this concept. Legal subjects, and ultimately humans, operate computers and networks. They are legally responsible for their activities, regardless of the technology they use to accomplish the effects. Computers, networks, digital data and information including software are tools of this human activity. These tools are neither subjects of law themselves, nor does the intangible, non-physical nature of cyber activities release humans of their responsibility for them. A legal subject, who initiates cyber activities creates a legal link with other subjects, whose rights and interests are affected by these cyber activities. In law, such links result in rights and obligations. The concept of cyber activity characterizes best the factual situation that leads to these rights and obligations. Cyber activities relate to the technical handling of digital data in com‐ puters and networks. Broadly speaking, they are about the technical steps of processing and transmitting digital data and for which humans are ultimately responsible. For this book, the term cyber activity is understood as • the processing or transmission of digital data and information • through a (IP-based) network • which affects (at distance) another computer and/ or the digital data and information therein (with possible effects on peripheral systems). 1.3.1.2 Cyber Space While the term cyber space is widely used and accepted, it creates confusion in a legal context. Cyber space is not a physical, three-dimensional space. The metaphoric, non-physical concept of cyber space does not properly characterize the relationship between legal subjects engaged in networked 1.3 Distinctions 21 <?page no="22"?> 14 Bin Cheng, The Extraterrestrial Application of International Law, 18 CLP (1965), 132-152, reprinted in Bin Cheng, Studies in International Space Law, 70, at 73. 15 For more details see infra 2.3.1, 2.3.2. computing of digital data and information. In public international law, two-dimensional areas and three-dimensional spaces are a means to geo‐ graphically delineate the limits of State sovereignty and jurisdiction. In a legal analysis, the concept of cyber space can lead into a wrong direction. In absence of a spatial quality of cyber space, there is no reason to wonder about its legal status, be it as an international space where States cannot claim sovereignty, as a ‘global commons’ or analogies thereto. Likewise, the concept of cyber space is prone to create confusion about State jurisdiction. Jurisdiction is the authority of a State to exercise pre‐ scriptive, enforcement and judicial powers. Jurisdiction is exercised either within sovereign territory, or quasi-territorially over a State’s national ships, aircraft, spacecraft and persons in international areas or spaces. 14 None of these categories apply in so-called cyber space. No person is physically located in cyberspace. The physical infrastructure which supports cyber activities exists in the physical world, typically in national territory and thus falls under territorial jurisdiction. For quasi-territorial jurisdiction in cyberspace, there would need to be something (in this non-existing space! ) equivalent to nationally registered ships, aircraft or spacecraft. However, digital data and information are non-physical in nature and lack nationality. There is no legal concept by which States can exercise jurisdiction over intangible digital data and information which is routed and dispersed by packet switching through privately owned network infrastructure located in the territory of many States. This leads to the conclusion that the concept of cyber activities captures the legal relations among the involved legal entities by far better than the concept of cyber space. 15 1.3.2 Non-Networked Activities Considering that cyber activities use technical means for processing and transmitting digital data on computers and through networks, they must be distinguished from other causes which lead to adverse effects to computers, networks and the data and which may look as if they were caused by a cyber activity. 22 Chapter One · Introduction <?page no="23"?> 16 A different case is a power outage (resulting in a computer shutdown) following an unauthorised cyber activity against the controls of a power grid. This is not a physical act against the energy and ICT infrastructure. 17 For example, radio links between satellites and ground, terrestrial microwave point-to-point links, cellular networks, Wireless LAN, Bluetooth, Near Field Commu‐ nication (NFC). IP-based networks are the technical elements which allow cyber activities to cause adverse effects on other computers or their connectivity. Networks create a technical communication link between legal subjects which are the basis for legal relations among them. A paramount characteristic of cyber activities is their effect through a network. They need a functioning network for creating an effect elsewhere. Digital data including software are the tools for creating these effects. This distinguishes cyber activities from activities with adverse effects on computers and networks which are not routed through networks. These kinds of activities apply other means to disrupt, deny, degrade or destroy computers, networks or data. 1.3.2.1 Physical Acts Against Infrastructure Physical acts can disrupt, degrade or destroy the functioning of hardware and cables. Computers and networks depend on them as physical infrastruc‐ ture. A data cable can be severed or disconnected. The power supply of infrastructure can be disrupted as easily as pulling a plug or cutting a cable. Hardware can be damaged or destroyed by physical means. All these acts impact the physical infrastructure from the outside, not through networks and not by digital data or software. These physical acts do not constitute cyber activities, even though their effects on the system and data may look similar. 16 Protection against these kinds of activities is sought by physical security measures. 1.3.2.2 Harmful Radio Interference and Jamming Harmful radio interference is performed with transmitters of radio waves. Harmful radio interference describes a disruptive effect in wireless tele‐ communications. When wireless radio links form part of digital networks including the internet, harmful radio interference can disrupt digital data transmissions. 17 Harmful interference results from the physical properties of electromagnetic wave propagation. It is a physically intrinsic cause 1.3 Distinctions 23 <?page no="24"?> 18 International Radio Telegraph Convention, Berlin, 1906, Article 8. 19 Constitution of the International Telecommunication Union, adopted by the 2018 Plenipotentiary Conference, Collection of the Basic Texts of the International Telecom‐ munication Union adopted by the Plenipotentiary Conference, edition of 2019. 20 ITU Radio Regulations, edition of 2020, Article 1.166. 21 International Civil Aviation Organisation (ICAO), AN-Conf/ 14-WP/ 63, 27/ 6/ 24, Avia‐ tion Safety and Security Concerns Regarding Interference to the Globel Navigation Satellite System (GNSS). of conflict in international radio telecommunications and was regulated already in 1906. 18 For this reason, Article 45 (1) of the Constitution of the International Telecommunications Union (ITU) 19 provides today: “All stations, whatever their purpose, must be established and operated in such a manner as not to cause harmful interference to the radio services or communications of other Member States or of recognized operating agencies, or of other duly authorised operating agencies which carry on a radio service, and which operate in accordance with the provisions of the Radio Regulations.” The ITU Radio Regulations 20 explain radio interference in more detail as an energy like interaction between electromagnetic waves: “The effect of unwanted energy due to one or a combination of emissions, radiations, or inductions upon reception in a radiocommunication system, manifested by any performance degradation, misinterpretation, or loss of information which could be extracted in the absence of such unwanted energy.” Intentional harmful interference is also called jamming. There can be legitimate reasons for jamming, for example for the protection of security areas. Jamming is no cyber activity, because it impedes wireless connections for the purpose of data transmissions with energy from outside and not through a network. An emitter or transmitter is required for generating the electromagnetic energy to interfere with the radio wave that carries data. This can result in a complete disturbance of the radio link and disruption of the data stream, like the effect when physical network infrastructure is disabled. Jamming can also be applied against Global Navigation Satellite Systems (GNSS) signals to prevent receivers from providing position and time outputs. 21 It is not a cyber activity. 24 Chapter One · Introduction <?page no="25"?> 22 ICAO, ibid. Up to 700 daily GPS jamming and spoofing events. See also Fred George, GPS Needs To Toughen Up, Or Get Trampled Down, Aviation Week and Space Technology, 13 May 2025. 23 Like the Global Positioning System (GPS) (USA), Galileo (EU), GLONASS (Russia), Beidou (China). 24 Aviation: Secondary Surveillance Radar (SSR), Automatic Dependent Surveillance (ADS), maritime: Automatic Identification System (AIS). 25 Spoofing of wireless navigation or surveillance signals is not to be confused with spoofing of data through IP-based networks, for example, by creating a wrong identity to gain access to restricted information. 26 Secure World Foundation, Global Counterspace Capabilities, An Open Source Assess‐ ment, Executive Summary, 04 2025. 1.3.2.3 Spoofing of Navigation and Surveillance Signals Spoofing is a method of deception by transmitting information with fake content. In recent years there was a strong increase in spoofing of navi‐ gation or surveillance through wirelessly transmitted signals. 22 Different to jamming, spoofing is not to interfere with and disturb a radio carrier wave, but to transmit a fake signal on the same frequency of the carrier. These signals mimic wrong navigation, surveillance or timing information of aircraft, ships and other users. This is possible because the signals of Global Navigation Satellite Systems 23 and surveillance systems 24 are propagated wirelessly on standardized carrier frequencies. Like jamming, spoofing of navigation or surveillance signals requires a dedicated radio transmitter. It exploits the open character of wireless transmissions. Since the deceptive signal is transmitted wirelessly, it needs to be distinguished from (networked) cyber activities. 25 1.3.2.4 Directed Energy Strikes with directed energy can be performed through special emitters of energy. The energy can consist of particles or of focused electromagnetic waves. Directed energy can target space objects. Lasers can be used for temporarily or permanently blinding the sensors and cameras of satellites and the eyes of aircraft pilots. Future forms of directed energy against space objects could possibly directly destroy electronics on-board satellites. The resulting damage could be like that of an electromagnetic pulse, but without releasing kinetic energy. A few States are currently developing and testing directed energy weapons as capabilities for use in outer space. 26 Directed energy emissions do not belong in the category of cyber activities. 1.3 Distinctions 25 <?page no="26"?> 27 The International Organisation for Standardization (ISO), International Standard ISO/ IEC 27000, 5. ed., 2018-02: The ISO/ IEC 27000 family of standards on Information Security Management Systems includes more specific standards on requirements (ISO/ IEC 27001, 27006, 27009), on general guidelines (ISO/ IEC 27002, 27003, 27004, 27005, 27013, 27014, 27021), on specific sectors (ISO/ IEC 27011: telecommunications 1.4 The Role of Law Law is a normative discipline. It governs the relations between legal subjects, including humans, legal entities and States. Law governs human behaviour, acting for themselves or for legal entities and States, and the impact of such behaviour on others. As a normative discipline, law is not descriptive like social or political sciences, but it determines rights and obligations of legal subjects to interact fairly. Law does not govern technology itself, but how humans should interact when they use technology. Technical devices or computers are not addres‐ sees of law, because they are not subjects of law. Law about technology, cyber or other, determines how humans ought to use technology safely, securely, fairly and efficiently while maintaining the interests and rights of others. The connectivity of networks, especially the internet, is a technical link which creates relations among legal subjects. Peripheral devices have ex‐ tended possible conflicts to the physical sphere and automated applications. This was not a factor, when computers were operated in isolation and information was not exchanged. There is no internationally set definition of cyber law. The legal relations created through cyber activities among legal subjects can span across international borders, because the internet extends across them. Different legal rules can apply in different jurisdictions for the same cyber activity. Moreover, relations among States can be affected, which are governed by public international law. 1.4.1 Non-Binding Standards Different to law, which is legally binding, standardisation bodies have estab‐ lished non-binding and voluntary standards on the security of information and cyber technologies. The International Organisation for Standardization (ISO), a worldwide federation of national standards bodies, has established the ISO/ IEC 27000 family of standards on Information Security Management Systems. 27 Experts compiled these standards by consensus which are con‐ 26 Chapter One · Introduction <?page no="27"?> organisations, ISO/ IEC 27017, 27018: cloud services, ISO/ IEC 27019: energy, ISO 27799: health) and on control, like cybersecurity guidelines for internet security (ISO/ IEC 27032). 28 National Institute of Standards and Technology (NIST), US Department of Commerce, NIST Special Publication (SP) 800 on information security. This series consists of hundreds of Special Publications, for example on risk assessment and management (NIST SP 800-30, 800-37, 800-39) and security and privacy controls for systems and organisations (NIST SP 800-53, 800-53A, 800-53B). sidered as the international state of the art. Likewise, the National Institute of Standards and Technology (NIST) of the US Department of Commerce established non-binding and voluntary guidelines on information security issued as the NIST Special Publications 800 series. 28 There are numerous reasons for corporate or government organisations to voluntarily conform to the requirements of such non-binding and volun‐ tary standards, for example due to their self-interest in • protecting their computers, networks, data and information and con‐ nected peripheral devices, • assuring their continuity of operations following unauthorised cyber activities, • creating confidence for customer, business and government relations, • demonstrating due diligence (supported by a certification process) when defending against negligence claims after being targeted by unauthor‐ ised cyber activities. 1.4.2 Unauthorised Cyber Activities Unauthorised cyber activities are a root cause for legal conflicts. Cyber ac‐ tivities may not only be used for legitimate purposes but can be undertaken for unauthorised uses, some of which are even qualified as criminal acts. These cyber activities, undertaken with or without intent, can be called unauthorised, because techniques are applied that the effected legal entity has not agreed to and which compromise the confidentiality, integrity or availability of computers, digital data or information. Unauthorised cyber activities often use software to reprogram the target computer, for example for cracking the security precautions to obtain access to the target computer and its data. 1.4 The Role of Law 27 <?page no="28"?> 29 However, a cyber activity without consent of the person operating or holding the affected system or information can be authorised under (national) law for reasons of public security, e.g. for authorities investigating crimes. For this book an unauthorised cyber activity is understood as • the processing or transmission of digital data and information • through a (IP-based) network • with a technique which affects (at distance) the confidentiality, integrity or availability of another computer and/ or the digital data and information therein (with possible effects on peripheral systems) • without consent (of the person operating the affected computer, the digital data and information therein and/ or peripheral systems). 29 Hacking is a common term synonymously used for unauthorised cyber activities. It is a broad expression for unauthorised access to computers, networks, digital data and information without being specific about the applied method, the target and purpose of the activity. 1.4.2.1 Preventive Cyber Security Measures Preventive measures against unauthorised cyber activities are generally addressed as cyber security. They encompass technical, behavioural and organisational elements. Existing law, lex ferenda or non-binding standards can establish a normative framework for defining requirements of suitable measures. Technical preventive measures are to assure the technical resilience of computer systems and networks, like encryption and system compartmen‐ talisation, and active protections like firewalls and detection systems. Behavioural preventive measures relate to human interaction with computers and networks for the protection against unauthorised cyber activities. They include human training for creating personal awareness of the vulnerabilities of and threats to the systems and cautious conduct when handling these systems, also called hygiene. Organisational preventive measures are to establish and maintain standing organisational structures (in organisations, businesses, etc.) which can swiftly react to unauthorised cyber activities, communicate, re-establish 28 Chapter One · Introduction <?page no="29"?> 30 For clarification: Other forensically methods are required for identifying the origin of unauthorised non-networked activities, because they take effect through other means than data or software. service, and reduce the exposure to threats in the future. The organisational structures can relate to risk management, incident identification, analysis and response, and cooperation and information sharing with relevant cyber security bodies and peers. Compliance of organisations with such preventive measures, whether mandated by law or established by a non-binding regime, can also be an indicator for due diligence to protect their systems, data and information against unauthorised cyber activities. Evidence of due diligence can mitigate the liability exposure of organisations after an unauthorised cyber activity. 1.4.2.2 Attribution and Liability A case-by case incident analysis and identification of the type and origin of the incident are of central importance for the subsequent legal handling of an unauthorised cyber activity. This analysis can lead to the attribution of an unauthorised cyber activity to a legal subject as its originator. Attribution is the pre-requisite for establishing a legal obligation of the originator of an unauthorised cyber activity and for lodging legal action against him for breach of third-party rights. However, attribution can be difficult to prove and it remains the main obstacle for determining such legal obligations. Attribution has two elements: factual and legal attribution. Factual attribution can be accomplished by the maturing field of cyber forensics. It is a technical process for establishing the factual basis of attribution. Cyber forensics can analyse data and software used for an unauthorised cyber activity and help to identify the source of the activity. Unauthorised cyber activities leave data traces, like fingerprints, which can help identify their origin. 30 Cyber forensics is far from perfect and needs to be further developed and perfected. However, when cyber forensics identifies the technical origin of an unauthorised cyber activity, it cannot pinpoint the legal subject who acted as offender. Legal attribution helps to link a legal subject to the source of an unau‐ thorised cyber activity. Classical legal methods for establishing or facilitating legal attribution are rules, for example, on organisational responsibility, responsibility for vicarious agents, presumption of fault, reversal of the 1.4 The Role of Law 29 <?page no="30"?> 31 International Law Commission, Responsibility of States for Internationally Wrongful Acts, report reproduced in UNGA Res. 56/ 83 (annex) of 12 December 2001, Article 12. 32 For example, the unauthorised cyber activity conducted by the Russian Federation against Ukraine on 24 February 2022. It targeted the satellite KA-SAT / Viasat commu‐ nications network which caused indiscriminate outages and disruptions across several public authorities, businesses and users in Ukraine, see: Council of the EU, Press Release, 10 May 2022, Russian cyber operations against Ukraine: Declaration by the High Representative on behalf of the European Union. 33 For details see: Rain Ottis, NATO Cooperative Cyber Defence Centre of Excellence, Tallinn, Analysis of the 2007 Cyber Attacks Against Estonia from the Information Warfare Perspective, 🔗 https: / / ccdcoe.org/ uploads/ 2018/ 10/ Ottis2008_AnalysisOf200 7FromTheInformationWarfarePerspective.pdf (accessed March 2026) 34 This event also led to the establishment of the NATO Cooperative Cyber Defence Centre of Excellence (NATO CCD COE) and the subsequent creation of the Tallinn Manual, an academic compilation of non-binding rules by scholars and practitioners which burden of proof and non-fault liability regimes. While national legislators can establish such rules in national law, the introduction of such rules in the relation among States, through public international law, faces high political hurdles. Given the determination of attribution, legal action against those who launch unauthorised activities and breach third-party rights can either be based on existing national private law regimes of restitutive or compensa‐ tory liability, national criminal liability or, in relations among States, State responsibility for breach of an international obligation. 31 1.4.3 Armed Conflict Most unauthorised cyber activities are undertaken in peacetime. Different legal rules apply to unauthorised cyber activities in armed conflict. Cyber activities can be used as force enablers in support of own forces during armed conflicts. Cyber activities have become essential means in modern warfare for communications, navigation, surveillance, intelligence, reconnaissance, connected automated logistics and weapon capabilities. Unauthorised cyber activities during armed conflict are intended to disrupt, deny, degrade or destroy capabilities of adversaries. 32 The law of armed conflict including international humanitarian law applies in such cases. For the study of cyber law, it should be noted that the broad and systematic campaign of unauthorised cyber activities against Estonian critical infra‐ structure in April 2007 33 became a starting point of in-depth studies of legal aspects of cyber activities. 34 From a military law perspective, a key question 30 Chapter One · Introduction <?page no="31"?> addresses cyber activities in the context of the law of armed conflict: Michael N. Schmitt (ed.), Tallinn Manual on the International Law Applicable to Cyber Warfare, Cambridge University Press, 2013. 35 Like an armed attack as a prerequisite for collective self-defence in Article 5 of the North Atlantic Treaty, 34 UNTS 243. 36 For example, the Tallinn Manual 1.0, supra note 35, Rule 90: “A cyber attack is a cyber operation, whether offensive or defensive, that is reasonably expected to cause injury or death to persons or damage or destruction to objects.” 37 For example, the International Standardisation Organisation (ISO), standard ISO/ IEC 27000: 2018 on information technology, section 3.2, defines attack as ”attempt to destroy, expose, alter, disable, steal or gain unauthorised access to or make unauthorised use of an asset”. was whether this event could be deemed an armed attack 35 and under what circumstance it could constitute a casus belli. Starting during the first decade of the millennium, discussions in the legal literature concentrated on the threshold when an unauthorised cyber activity reaches the level of use of force or an armed attack. These elaborations should not be confused with the legal scenarios which apply to unauthorised cyber activities during peacetime. Related to this discussion is the use of the term cyber-attack. Military lawyers tend to limit its meaning to unauthorised cyber activities which by scales and effects represent an armed attack. 36 However, in public usage and in non-military publications 37 the term cyber-attack is used more widely and partly synonymously for deliberate unauthorised cyber activities. 1.4.4 Information Content, Digital Market and Participation Having identified cyber activities and unauthorised cyber activities as conceptual entry points to cyber law, they must be distinguished from content and market related legal aspects. These aspects are beyond the focus of this book but are mentioned in the following for the sake of completeness. Even when a cyber activity does not use data-based techniques to com‐ promise confidentiality, integrity or availability, it may nevertheless violate third party rights rooted in the content of information. Information which can be found today in digital form in computers and networks have been existing similarly in traditional, analogue form or on paper-based media. When this information content is distributed in new digital formats, it can become more critical in range and effects. Existing legislation on content related aspects protects third party rights in different contexts, for example: 1.4 The Role of Law 31 <?page no="32"?> 38 See for example UNGA Res. 73/ 179, Right to privacy in the digital age, 17 December 2018 39 See for example Regulation (EU) 2016/ 679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) 40 See for example Regulation (EU) 2022/ 868 of the European Parliament and of the Council of 30 May 2022 on European data governance (Data Governance Act) 41 See for example Directive 2001/ 29/ EC of the European Parliament and of the Council of 22 May 2001 on the harmonisation of certain aspects of copyright and related rights in the information society 42 See for example Directive 2009/ 24/ EC of the European Parliament and of the Council of 23 April 2009 on the legal protection of computer programs 43 See for example Regulation (EU) 2022/ 2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market for Digital Services (Digital Services Act) 44 See for example Council of Europe, International Convention on Cyber Crime, Buda‐ pest, 2001, ETS 185, Arts. 9, 10. 45 See for example Regulation (EU) 2021/ 784 of the European Parliament and of the Council of 29 April 2021 on addressing the dissemination of terrorist content online • the right to privacy, 38 • the protection and processing of personal data, 39 • the protection and processing of private non-personal data, like machine data, 40 • the protection of intellectual and data property rights, including copy‐ right, 41 and software, 42 • the prevention of spreading illegal content and disinformation to protect fundamental rights of users and providing rules for online intermedia‐ ries to that effect, 43 • content related criminal acts like child pornography and infringement of copyright, 44 and • combatting the dissemination of terrorist online content. 45 Another category of legislation promotes the creation, functioning and use of fair and accessible digital markets, digital platforms, digital commercial relations (e-commerce) and digital government relations (e-government), for example with rules on 32 Chapter One · Introduction <?page no="33"?> 46 See for example Regulation (EU) 2023/ 2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data (Data Act) 47 See for example Regulation (EU) 2022/ 868 of the European Parliament and of the Council of 30 May 2022 on European data governance (Data Governance Act) 48 See for example Regulation (EU) 2022/ 1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector (Digital Markets Act) • fair access to and fair use of data, 46 • the promotion of data sharing for the benefit of businesses and individ‐ uals, 47 and • fairness rules for large online platforms as ‘gatekeepers’ to online markets. 48 1.4 The Role of Law 33 <?page no="35"?> Chapter Two · Cyber Law and Public International Law Cyber law can be defined as law relating to cyber activities. It is a cross-sectional discipline about cyber activities in domestic and inter‐ national law. Cyber activities have become increasingly significant for relations among States. Cross border data and information exchanges are an element of globalization. They affect not only worldwide relations among private persons but also among States. States are actors and targets of cyber activities. Malicious cyber activities can pose risks to international security, economic and social relations, and safety. Unau‐ thorised cyber activities can be directed against critical infrastructures and disrupt essential services to the public, communities and commerce. With disinformation campaigns, certain States attempt to influence public opinion, foreign elections and undermine trust in foreign State institutions. The role of cyber activities for military purposes and in armed conflict is constantly increasing. States are subjects of public international law. Their relationships are governed by public international law. Cyber activities in inter-State relations are thus governed by existing legal concepts of public interna‐ tional law. 2.1 Sovereignty Sovereignty is a cardinal principle of state theory. Sovereignty denotes the exclusive, supreme and inalienable legal authority of a State to exercise power within its area of governance. It is an important element of statehood, the quality of being a State. The Montevideo Convention of 1933 reflects the customarily recognized elements of a State: <?page no="36"?> 1 Montevideo Convention on Rights and Duties of States, 1933, USTS 881, Article 1. 2 Georg Jellinek, Allgemeine Staatslehre, Recht des modernen Staates, vol. 1, Berlin, 1900, 2. ed. 1905, p.-381-420. “The State as a person of international law should possess the following qualifica‐ tions: (a) a permanent population; (b) a defined territory; (c) government; and (d) capacity to enter into relations with other States.”  1 The first three elements form the so-called three element theory. 2 These three elements are objective or material elements. In a modern State the permanent population is the sovereign and as such it holds the right of self-determination. The element of government is the organisational means of a State to exercise its sovereign powers. The government acts as the executive agent of the population. These powers include the exclusive authority to legitimately exercise force within its territory. As a subject of public international law, a State must have the right and authority to act. Sovereignty signifies this legal right and authority. The defined territory determines and spatially limits the geographical area where a State exercises its supreme sovereign powers. Sovereignty is exclusive. Within its defined territory only one State can exercise sovereign powers through its government. Sovereignty is supreme. It is legally the highest power in a State. No other State, private or non-governmental body can assume a higher authority to exercise powers in its territory. Sovereignty is inalienable. As an indispensable characteristic of statehood, sovereignty is vested in a State as long as it exists. In the relationship among States, sovereignty has a different function. In inter-state relations it signifies the triad of equality, political independ‐ ence and territorial integrity. This is the result of immanent limitations of sovereignty. The supreme and exclusive exercise of sovereign rights of a State reaches only as far, as it does not interfere with equal supreme and exclusive sovereign rights of another State. This leads to the territorial limitations of sovereignty. In public international law, sovereignty is one of the principal foundations for the equality of States, their territorial integrity and political independ‐ ence. The Treaty of Westphalia of 1648, which established a new European peace order after the 30 years’ war, first codified these modern elements of sovereignty in inter-state relations. It recognized the unmolested exercise 36 Chapter Two · Cyber Law and Public International Law <?page no="37"?> 3 Peace Treaty between the Holy Roman Emperor and the King of France and their respective Allies, Münster, Westphalia, 24 October 1648. 4 Island of Palmas Case, (The Netherlands vs. the United States), Permanent Court of Arbitration 2 RIAA (1928) p.-829 5 Charter of the United Nations, 26 June 1945, 1 UNTS XVI. 6 United Nations Convention on the Law of the Sea (UNCLOS), 10 December 1982, 1833UNTS 397, Article 2. of powers of the involved monarchs. 3 To this effect, Max Huber held as sole arbitrator in the island of Palma case of 1928: “Sovereignty in the relations between States signifies independence. Independence in regard to a portion of the globe is the right to exercise therein, to the exclusion of another State, the functions of a State.”  4 In modern public international law, the principle of equality is prominently restated in Article 2 (1) of the Charter of the United Nations: “The Organisation is based on the principle of the sovereign equality of all its Members”.  5 When entering into mutual relations, States need to recognize each other as equal partners who interact at eye level. For that reason, the three objective State elements of population, territory and government are supplemented by the subjective element of the ‘capacity to enter relations with other States’. A State cannot fulfil this requirement by itself. It needs formal recognition by other States. Only upon acts of recognition, States endorse and accept the statehood of another equal State. The recognition of a State entails the recognition of its sovereignty. Sovereignty in National Territory and International Spaces States hold territorial sovereignty authority in their national territory. Borders of their national territory delimitate their area of exclusive sover‐ eignty. National territory includes land territory, the territorial sea and the airspace above. The customary status of the territorial sea is recognized in the United Nations Convention on the Law of the Sea: “1. The sovereignty of a coastal State extends, beyond its land territory and internal waters … to an adjacent belt of sea, described as the territorial sea. 2. This sovereignty extends to … its bed and subsoil.”  6 “Every State has the right to establish the breadth of its territorial sea up 2.1 Sovereignty 37 <?page no="38"?> 7 UNCLOS, id., Article 3. 8 Convention on International Civil Aviation, 7 December 1944, 15 UNTS 295, Article 1. 9 Convention on International Civil Aviation, id., Article 2. 10 UNCLOS, supra note 6, Article 89. 11 UNCLOS, id., Articles 86, 87. 12 Treaty on Principles Governing the Activities of States in the Exploration and Use of Outer Space, including the Moon and Other Celestial Bodies (Outer Space Treaty) 27 January 1967, 610 UNTS 205, Article II. to a limit not exceeding 12 nautical miles, measured from baselines…”.  7 The Chicago Convention recognizes furthermore that sovereignty extends to the airspace above the territory and territorial sea of States: “The contracting States recognize that every State has complete and exclusive sovereignty over the airspace above its territory.”  8 “For the purposes of this Convention the territory of a State shall be deemed to be the land areas and territorial waters adjacent thereto under the sovereignty … of such State.”  9 Different to national territories, States cannot claim or exercise sovereignty in international areas and spaces. Sovereignty does not extend to the high seas and the airspace above or to outer space. To this end, the UN Sea Law Convention of 1982 restates the customary principle: “No State may validly purport to subject any part of the high seas to its sovereignty.”  10 The high seas comprise all parts of the sea other than the territorial sea, the exclusive economic zone or internal waters of States. The high seas are open to all States. With due regard of the interests of other States, they can exercise the freedom of the high seas which includes, inter alia, the freedom of sea navigation, overflight, fishing and scientific research. 11 Different to the exclusivity of sovereign rights, these freedoms constitute non-exclusive rights of use. The due regard principle is applied to warrant the non-exclusive freedoms of other States on an equal footing. The regime of outer space follows a similar pattern: “Outer space, including the moon and other celestial bodies, is not subject to national appropriation by claim of sovereignty, by means of use or occupation, or by any other means.”  12 38 Chapter Two · Cyber Law and Public International Law <?page no="39"?> 13 Outer Space Treaty, id., Article IX. 14 UN Charter, supra note 5, Article 2(1). 15 UN Charter, id., Article 2(3). 16 UNGA Res. 73/ 27, Developments in the field of information and telecommunications in the context of international security, 5 December 2018, section 1.1. This principle of responsible State behaviour was recommended by the Group of Governmental Experts (GGE) on Developments in the Field of Information and Telecommunications in the Context of International Security, UNGA 70/ 174, 22 July 2017, section 13.(a). States may explore and use outer space on a non-exclusive basis “with due regard to the corresponding interests of all other States Parties to the Treaty”. 13 2.2 Public International Law Principles applicable to Cyber Activities In the relation among States, public international law sets the guardrails for cyber activities. From the large body of public international law, the United Nations (UN) Charter restates fundamental principles according to which States shall act. These principles apply to cyber activities like to any other activities of States. The principle of the sovereign equality 14 is the basis for the freedom of action of States in their international relations, also when exercising cyber activities. The element of equality indicates the immanent limitations of the freedom of action which requires respect and due regard for the interest of other States. In practice, public international law sets the limits of the freedom action in international relations among States. The settlement of disputes by peaceful means is a principle for excluding non-peaceful State activities and conduct: “All Members shall settle their international disputes by peaceful means in such a manner that international peace and security, and justice, are not endangered.”  15 In 2018 the UN General Assembly reiterated that States: “… should cooperate in developing and applying measures to increase stability and security in the use of [information and communication technologies (ICTs)] and to prevent ICT practices that are acknowledged to be harmful or that may pose threats to international peace and security.”   16 Non-peaceful cyber activities could for example be directed against the functioning of critical infrastructure and public services, also when they 2.2 Public International Law Principles applicable to Cyber Activities 39 <?page no="40"?> 17 UNGA Res. 73/ 27, id., section 1.6., GGE UNGA 70/ 174 id., section 13.(f). 18 UN Charter, id., Article 2(4). 19 UN Charter, id., Article 1 (1), (2), (3). 20 UN Charter, id., Article 2(7). 21 UN Charter, id., Article 2(1). remain below the level of the use of force. The UN General Assembly specifically addressed information and communication technology threats against critical infrastructure: “A State should not conduct or knowingly support ICT activity contrary to its obli‐ gations under international law that intentionally damages critical infrastructure or otherwise impairs the use and operation of critical infrastructure to provide services to the public.”  17 The principle on refraining from the use of force addresses situations in the relation among States which reach and surpass the level of armed conflict. “All Members shall refrain in their international relations from the threat or use of force against the territorial integrity or political independence of any state, or in any other manner inconsistent with the Purposes of the United Nations.”  18 Embedded in this principle are two elements that qualify as legal principles by themselves: the inviolability of territorial integrity and political independence. Both are subsets of State sovereignty. In addition, the principle of non-use of force relates to the purposes of the United Nations which entail, inter alia, maintaining international peace and security, equal rights and self-determination of peoples and international cooperation. 19 Use of force means physical force. Cyber activities with kinetic effects can fall in this category. Only when the use of force is directed against the territorial integrity, the political independence or is inconsistent with the purposes of the Charter, it qualifies as a matter of inter-State relations. The principle of non-interference in the internal or external affairs of another State can also be applied to cyber activities. The UN Charter reaffirms that the United Nations shall not “…intervene in matters which are essentially within the domestic jurisdiction of any state or shall require the Members to submit such matters to settlement …”.  20 Following the concept of sovereign equality, 21 the principle of non-inter‐ ference applies likewise among States. In the Corfu Channel Case the 40 Chapter Two · Cyber Law and Public International Law <?page no="41"?> 22 Corfu Channel (United Kingdom v. Albania), Judgment of 9 April 1949: ICJ Reports 1949, p.-35. 23 Military and Paramilitary Activities in and Against Nicaragua (Nicaragua v. United States of America), Merits, Judgment, I.C.J. Reports 1986, p.-14, para 174. 24 Universal Declaration of Human Rights, UNGA Res. 217 (III) A, 10 December 1948. 25 International Covenant on Civil and Political Rights, 16 December 1966, 999 UNTS 171. 26 European Convention for the Protection of Human Rights and Fundamental Freedoms, 4 November 1950, 312 ETS 5. 27 UN General Assembly, The right to privacy in the digital age, UNGA Res. 79/ 175, 17 December 2024, section 8.(a). International Court of Justice objected against unilateral intervention and thus affirmed the principle of non-intervention among States: “The Court can only regard the alleged right of intervention as the manifestation of a policy of force, … and such … cannot … find a place in international law. Intervention … from the nature of things, it would be reserved for the most powerful States, and might easily lead to perverting the administration of international justice itself.”  22 In the Nicaragua Case the International Court of Justice recognized the principles of non-use of force, non-intervention, independence and territo‐ rial integrity as customary law: “non-use of force, non-intervention, respect for the independence and territorial integrity of States … continue to be binding as part of customary international law … .”  23 Also relevant for cyber activities of States are human rights, as for example listed in the Universal Declaration of Human Rights (UDHR), 24 the International Covenant on Civil and Political Rights (ICCPR), 25 and the European Convention for the Protection of Human Rights (ECHR). 26 Human rights form the basic legal foundation of relationships between States and natural persons. Human rights are inherently and inalienably vested in every natural person. States must apply human rights universally to citizens or foreigners and inside or outside of their area of jurisdiction. This applies to any effect of cyber activities which can be attributed to States. Considering technological developments, the UN General Assembly specified the right of privacy enshrined in existing human rights instruments to the needs of the digital age. By resolution it calls upon States “To respect and protect the right to privacy, both online and offline, including in the context of digital communications and new and emerging technologies”.  27 2.2 Public International Law Principles applicable to Cyber Activities 41 <?page no="42"?> 28 UN Human Rights Council, The promotion, protection and enjoyment of human rights on the Internet, Resolution 47/ 16, 13 July 2021. Moreover, the UN Human Rights Council adopted resolutions on the promotion, protection and enjoyment of human rights on the Internet. 28 2.3 Jurisdiction Jurisdiction is the authority of a State to impose its laws and powers on subordinated persons and objects. It is a sub-set of the supreme sovereign powers of a State. Subordination is a corollary to the supreme powers. Following the division of government in three branches, jurisdiction can be divided into prescriptive, enforcement and adjudicatory jurisdiction. The supremacy and exclusivity of jurisdiction follow a similar pattern like for sovereignty. Supreme and exclusive jurisdiction applies within State territory. Outside of the territory there are limitations, especially for enforcement jurisdiction. Territorial jurisdiction applies within the territory of States, their territorial sea and their national airspace. Within their defined territory States have prescriptive jurisdiction for establishing a legal order in the spheres of criminal, private and administrative law applicable to persons, citizens and non-citizens, and to moveable and immovable objects. Similarly, States hold adjudicatory jurisdiction over persons in their territory and over the status of objects. With the exclusive authority for exercising force, States possess enforcement jurisdiction within their territory. Outside their territory, States can exercise personal jurisdiction. It applies to citizens by virtue of their nationality. For activities of these nationals outside of national territory, States can exercise prescriptive and adjudicatory jurisdiction. They can legislate rules and their courts can adjudicate them. For non-citizens outside of national territory, prescriptive and adjudicatory jurisdiction is typically limited to their acts which have an effect in national territory or on their nationals. In any case, a State holding personal prescriptive and adjudicatory jurisdiction has no authority of enforcement in foreign territory. Quasi-territorial jurisdiction is a functional concept for extending territorial jurisdiction of States to their ships, aircraft and spacecraft outside national territory, especially in international areas and space. Quasi-territo‐ 42 Chapter Two · Cyber Law and Public International Law <?page no="43"?> 29 UNCLOS, supra note 6. 30 Convention on International Civil Aviation, supra note 8, Article 17. rial jurisdiction does not convey jurisdiction over international areas and spaces as such. The link to ships, aircraft and spacecraft is established by national registration. Quasi-territorial jurisdiction extends to persons onboard. Lacking governmental enforcement bodies on board, it can serve as legal basis for the authority of the commander to maintain discipline aboard. States apply quasi-territorial jurisdiction within the limits and scope recognized or agreed by international law, for example on the high seas for ships flying their flag as detailed in the United Nations Convention on the Law of the Sea: “Article 91 … 1. Every State shall fix the conditions for the grant of its nationality to ships, for the registration of ships in its territory, and for the right to fly its flag. Ships have the nationality of the State whose flag they are entitled to fly. There must exist a genuine link between the State and the ship… Article 92 … 1. Ships shall sail under the flag of one State only and … shall be subject to its exclusive jurisdiction on the high seas. … Article 94 … 1. Every State shall effectively exercise its jurisdiction and control in administrative, technical and social matters over ships flying its flag. 2. In particular …(b) assume jurisdiction under its internal law over each ship flying its flag and its master, officers and crew …”.  29 These provisions contain all elements for establishing national jurisdiction over objects and person in an international area. Nationality of the ship is derived from registration and indicated by the flag. A genuine link must exist between flag State and the ship to avoid flags of convenience. Exclusive jurisdiction of the registering State relates to the ship and persons onboard on the high seas. This exclusivity recognized by international law constitutes a legal defence against possible acts of other States. The nationality of aircraft is determined by registration: “Aircraft have the nationality of the State in which they are registered.”  30 Non-exclusive criminal jurisdiction aboard aircraft is established under Article 3 of the Tokyo Convention: “1. The State of registration of the aircraft is competent to exercise jurisdiction over offences and acts committed on board. … 2.3 Jurisdiction 43 <?page no="44"?> 31 Convention on Offences and Certain Other Acts Committed on Board Aircraft, 14 September 1963, 704 UNTS 219. 32 Outer Space Treaty, supra note 12, Article VIII. 33 First mention of cyber space in William Gibson, Burning Chrome, Omni Magazine, July 1982, p.-72. 34 See supra 1.1.1. 3. This Convention does not exclude any criminal jurisdiction exercised in accordance with national law.”  31 In outer space jurisdiction of the State of registration is established for space objects and persons onboard by the Outer Space Treaty: “A State Party to the Treaty on whose registry an object launched into outer space is carried shall retain jurisdiction and control over such object, and over personnel thereof, while in outer space or on a celestial body.”  32 2.3.1 Jurisdiction in Cyber Space? Cyber space is not a suitable concept for establishing jurisdiction. Cyber space is not a physical space. Its borders cannot be defined. There are no persons or objects in cyber space. Spatial and quasi-territorial concepts of public international law cannot be applied lacking a stable anchoring point. The notion of cyber space became widely known through science fiction novels of William Gibson in the 1980s, in which cyber punks act in cyber space. 33 What may be an entertaining idea for a fictious dystopian storyline, it is not a solid foundation for a legal concept. Nevertheless, information technology professionals frequently use the term cyber space which has found its way into legal definitions and texts. 34 In public international law contexts, the term cyber space can wrongly suggest similarity to the legal concepts of international airspace or outer space and related quasi-territorial jurisdiction. For more than one hundred years, no one in the legal community came up with the idea that telegraph or telephone messages were subject to a special legal regime because their electrical signals travel through a non-physical sovereign free space. Lacking the quality of two-dimensional areas or three-dimensional spaces, like the high seas or outer space, no analogy can be drawn for the so-called cyber space for establishing jurisdiction over persons and objects. This is not the only conceptual problem. Even if cyber space was a sovereign-free space in the sense of public international law, 44 Chapter Two · Cyber Law and Public International Law <?page no="45"?> 35 The same applies to persons and infrastructure on board of nationally registered ships, aircraft and spacecraft (quasi-territorial jurisdiction). 36 See infra 2.5. what would the jurisdiction of States relate to? In cyber space there is no equivalent to persons or nationally registered ships, aircraft or space objects. Information transiting through cyber space does not qualify for an analogy with ships, aircraft or spacecraft. Information is not nationally assigned in a similar way as with a flag or registration. More complicating, packet switching in IP-based networks splits information into myriads of data packages which take different routes before being put together again at their destination. Alone for practicable reasons, it does not make sense to establish jurisdiction over information or data packages. 2.3.2 Jurisdiction linked to Cyber Activities Jurisdiction can be linked to cyber activities like to any other activities. Relevant for legal relations between subjects of law are the effects of their activities. The effects can be of physical nature or consist of information, like declarations of will. The same applies to cyber activities. Effects from cyber activities result from information generated or transmitted through networks or from control commands for kinetic peripheral devices gener‐ ated or transmitted that way. Jurisdiction applies to legitimate and wrongful cyber activities. Jurisdiction provides States with the authority to impose laws and enforcement upon subordinated persons and objects. In their territories States hold prescriptive, enforcement and adjudicatory jurisdiction for cyber activities. Persons engaged in cyber activities or cyber infrastructure within their territory can be the links to territorial jurisdiction. 35 In many instances, no specific legislation is required for cyber activities. For example, a cyber activity which controls a kinetic function that leads to bodily injury usually constitutes a criminal offence under existing domestic law. However, many States have enacted cyber specific criminal laws as modelled in the Budapest Cyber Crime Convention. 36 More difficult is law enforcement including investigation, identification and prosecution. Even though a State holds enforcement jurisdiction in its territory, executive bodies face complications in case of cyber activities. Cyber activities originating in or having effect in the territory need to be attributed to a person who is subjected to jurisdiction. The activity itself 2.3 Jurisdiction 45 <?page no="46"?> 37 See infra 3.3.3. 38 See Michael N. Schmitt (ed.), Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations, Cambridge University Press 2017, Rule 10. 39 Based on Article 1, International Law Commission, Responsibility of States for Inter‐ nationally Wrongful Acts (ARSIWA), 2001, Annex to UNGA Res. 56/ 83 of 12 December 2001. can be the starting point for investigations. The practical hurdle is cyber forensics. If successful, it can deliver evidence for the factual attribution of the cyber activity to a person. 37 Objects in the territory which are used for cyber activities can be another link to jurisdiction. Infrastructure hardware which stores data seems most suitable for this purpose, when crucial information can be found to reside there in national territory. Hardware used only for transmission more likely disqualifies because of transmission speed and information fragmentation through packed switching. During transmissions, information and control commands disperse on the internet like in a short living cloud. Transient fragments of information can hardly be used for purposes of establishing territorial jurisdiction. For their nationals engaged in (unauthorised) cyber activities outside of their territory, States hold prescriptive State jurisdiction. They can legislate rules governing them when they engage in cyber or other activities. Many cyber activities take place across borders. Unauthorised cyber activities can be initiated in one State and have a detrimental effect in another. States hold prescriptive jurisdiction over foreign nationals, when their cyber activities target essential State interests or their nationals. 38 For enforcement in foreign territory, they need to cooperate with the State where the person is located, for example with an extradition agreement. 2.4 State Responsibility State responsibility for cyber activities concerns States as actors, or situa‐ tions when States are deemed to be actors. A State bears international responsibility for acts, including cyber activities, 39 which are attributable to it and constitute a breach of international law. State responsibility relates to obligations among States. When States are responsible for cyber activities, they have a different role compared to jurisdiction, which concerns their authority in relation to subordinated persons and objects. 46 Chapter Two · Cyber Law and Public International Law <?page no="47"?> 40 ARSIWA, id. 41 UNGA Res. 56/ 83, Responsibility of States for internationally wrongful acts, 11 Decem‐ ber 2001. 42 Attribution is recognized as an element of responsibility in ARSIWA, supra note 39, Article 2. 43 ARSIWA, id., Articles 4, 5, 7. Today, the understanding of State responsibility is strongly influenced by the 2001 report of the International Law Commission (ILC) on State Responsibility. 40 The Articles of this report are not binding, but the UN General Assembly commended them to the attention of governments. 41 The focus of the ILC is on internationally wrongful acts of States. However, the significance of the concept of State responsibility is broader, as it embodies attribution as well. 42 The concept of attribution concerns both legitimate and wrongful activities. It means a State is legally held to have initiated and undertaken an activity or is deemed to have done so. An example of a legitimate cyber activity is the digital conveyance of a governmental statement or declaration of will over the internet, which is attributed to the State. Due diligence obligations also fall in this category of State responsibility. States must exercise reasonable care to prevent breaches of international law. These are anticipatory obligations of State responsibility before a breach of an international obligation materializes. Legal attribution consists of recognized principles which identify the kind of acts of natural persons which can be attributed to a State as its own. Concerning cyber activities, it is more difficult to establish factual attribution, namely, to provide evidence that an activity was undertaken by a person or a group on behalf of a State. 2.4.1 Legal Attribution Acts are attributed to a State when they are exercised by its legislative, executive or judicial organs. 43 This applies likewise to cyber activities. Organs are the generic bodies empowered to act on behalf of a State. The conduct of private persons or groups of persons who are not organs of a State can generally not be attributed to a State. For example, States are not responsible for the conduct of their citizens. However, there are exceptions in the following circumstances: 2.4 State Responsibility 47 <?page no="48"?> 44 ARSIWA, id., Articles 5, 7. 45 ARSIWA, id., Article 8. 46 Case Concerning Military and Paramilitary Activities in and against Nicaragua (Nicar‐ agua v. United States of America), Merits, Judgment, I.C.J. Reports 1986, p.-51, para 86. 47 ARSIWA, supra note 39, Article 11. 48 United States Diplomatic and Consular Staff in Tehran, Judgment, I.C.J. Reports 1980, p.-35, para 74. 49 Corfu Channel case, Judgment of 9 April 1949, I.C.J. Reports 1949, p.-22. Acts of non-State actors can be attributed to a State when, they are empowered by the law of the State to act on its behalf. 44 The empowerment by law takes account of the increasing corporatization of governmental functions. The conduct of non-State actors can be attributed to a State when they act based on its instructions or under its direction or control. 45 Planning, direction and support of the non-State actors can amplify the required degree of control. 46 Even though non-State actors may have initiated and undertaken activi‐ ties by themselves, these acts are attributable to a State when it subsequently acknowledges or adopts them as its own. 47 This concept is built on the Diplomatic and Consular Staff Case of the International Court of Justice. It held that the independent militants became ‘agents’ of the State, because it had approved, endorsed and perpetuated their acts, which had earlier been undertaken independently: “The result of that policy was fundamentally to transform the legal nature of the situation created …. The approval given to these facts by … organs of the … State, and the decision to perpetuate them, translated … [this factual situation] into acts of that State. The militants … had now become agents of the … State for whose acts the State itself was internationally responsible.”   48 Furthermore, malicious conduct of non-State actors can be attributed to a State when it consciously tolerates such conduct. A breach of international obligations can be accomplished by omissions, for example when a State does not warn of known threats that pose a serious risk to other States. The International Court of Justice established in the Corfu Channel Case also a link of this obligation to its territory, as a flow down of sovereignty, by holding: “ … every State's obligation not to allow knowingly its territory to be used for acts contrary to the rights of other States.”  49 48 Chapter Two · Cyber Law and Public International Law <?page no="49"?> 50 UNGA Res. 73/ 27, supra note 16, section 1.3., GGE UNGA 70/ 174, section 13.(c). 51 For more details, see supra 1.4.2.2, infra 3.2.1, 3.3.2, 3.3.3. The UN General Assembly has reaffirmed this principle in the context of cyber activities: “States should not knowingly allow their territory to be used for internationally wrongful acts using ICTs [Information and Computer Technologies]. States must not use proxies to commit internationally wrongful acts using ICTs and should seek to ensure that their territory is not used by non-State actors to commit such acts.”  50 The threshold for the level of knowledge of private activities in the territory should not be too low, as to prevent an international obligation of States to over control and over survey their population. Activities independently conducted by non-State actors whose conduct cannot be attributed to a State do not fall under public international law and State responsibility. If their activities, including cyber activities, violate rights of foreign persons or property, remedies must be sought under domestic law. Nevertheless, if a State knows about and tolerates serious violations, for example of human rights, which originate from its territory, it should take necessary measures to avoid attribution under the Corfu Channel dictum. 2.4.2 Factual Attribution of Cyber Activities A key problem is the factual attribution of an unauthorised cyber activity to an originator. Effects of cyber activities can unfold worldwide and across borders. The internet does not per se disclose the identity of originators of unauthorised cyber activities. Cyber activities of States can be for legitimate or for unauthorised purposes. Factual attribution is not an issue for legitimate cyber activities, for example when it is in the interest of a State to distribute information as its official communication. Factual attribution becomes an issue, when a State or its proxies conceal a cyber activity or its originator. Factual attribution relies on cyber forensics. It can trace and analyse the methods of unauthorised cyber activities, of the exploited vulnerabilities and the level of sophistication. 51 Cyber forensics is a new discipline. Many insufficiencies of these modern methods of evidence collection remain but the quality of cyber forensics is improving. Findings of cyber forensics can be 2.4 State Responsibility 49 <?page no="50"?> 52 UNGA Res. 73/ 27, supra note 16, section 1.2. GGE UNGA 70/ 174, section 13.(b). 53 ARSIWA, id., Article 2. 54 ARSIWA, id., Article 12. combined with evidence from other sources. Secret services can for example provide information about the relationship between non-State cyber actors and foreign governments. The UN General Assembly highlighted that attribution for cyber incidents must be supported by verifiable evidence of their origin: “… the indication that an ICT [Information and Communications Technology] activity was launched or otherwise originates from the territory or objects of the ICT infrastructure of a State may be insufficient in itself to attribute the activity to that State. Accusations of organizing and implementing wrongful acts brought against States should be substantiated. In case of ICT incidents, States should consider all relevant information, including the larger context of the event, the challenges of attribution in the ICT environment and the nature and extent of the consequences.”  52 In domestic legislations, systemic difficulties in presenting evidence, for example in product liability, are typically facilitated by special procedural rules on presumption or reversing of proof. This is not a feasible solution in public international law. States will not agree to a treaty law regime which attributes acts of unknown originators to them merely by rules of presumption or reversal of proof. The objective of factual attribution is to establish causal and organisa‐ tional links between actors, cyber activities and their effects. These effects can be kinetic or non-kinetic. The effects and their severity are the factual elements for establishing whether a State breached international obligations. 2.4.3 Breach of International Obligations Responsibility of a State for internationally wrongful acts requires conduct, by action or omission, which can be attributed to the State and constitutes a breach of an international obligation. 53 “There is a breach of an international obligation by a State when an act of that State is not in conformity with what is required of it by that obligation, regardless of its origin or character.”  54 50 Chapter Two · Cyber Law and Public International Law <?page no="51"?> 55 See supra 2.2. 56 An exception is computer, information and network infrastructure, because it works non-kinetically. In case of cyber activities, relevant obligations can be, inter alia, the princi‐ ples of peaceful settlement of disputes, non-use of force, non-intervention and human rights. 55 Any breach must be determined on a case-by-case basis considering all relevant factual circumstances. One of these circumstances is the effect of a cyber activity and if it reaches a level that the responsible State can be considered as not to conform with what is required. Cyber activities with kinetic effects can degrade or destroy physical objects, like critical infrastructure, 56 and disrupt or suppress their function‐ ality. Their physical effects can injure or kill persons or jeopardize their safety. Depending on the specific fact pattern, breaches of the obligations of non-use of force and human rights are perceivable. However, not every kinetic effect of a cyber activity reaches the level of severity that leads to a breach of its obligations. For example, the deactivation of a luggage delivery system at a foreign airport can likely not be qualified as a breach of the principle of non-interference. There is no fixed threshold for the level of severity. It must be established in each individual case considering the injury of another State’s protected rights. Nonetheless, in peacetime relations this threshold should be below the level of the use of force in armed conflict. An impacted State cannot be reasonably held to endure on its territory during peacetime physical effects up to the level of use of force. A breach of international obligations is more difficult to determine for cyber activities with non-kinetic effects. In relations between States, non-kinetic effects often comprise unauthorised access to sensitive govern‐ mental information (often called cyber espionage) or spreading of unwanted information over the internet (disinformation campaigns and propaganda). Based on evidence, the collection of sensitive government information may be qualified as interference with internal affairs of State, particularly, when information is obtained by methods like illegal access or interference. It seems more difficult to establish, based on evidence, if disinformation cam‐ paigns and propaganda violate the principle of non-interference. Although these campaigns may appear to interfere with independent and unbiased political opinion making and even to influence foreign elections, at the bottom line, these practices exploit social behaviour of foreign populations. Growing portions of population obtain their political information from 2.4 State Responsibility 51 <?page no="52"?> 57 Council of Europe, Convention on Cybercrime, Budapest, 23 November 2001, ETS No. 185. 58 United Nations Convention against Cybercrime, Annex to UNGA Res. 79/ 243, 24 December 2024. 59 UNCLOS, supra note 6, Articles 112, 113. internet platforms today. It seems challenging to qualify in a specific case the exploitation of these social and cultural behaviours as non-interference with the internal affairs. 2.5 Criminal Law Treaties Treaty law is a source of public international law. In the field of cyber activities international treaties have so far concentrated on criminal law. This resulted in the Budapest Convention on Cybercrime of the Council of Europe 57 and the United Nations Convention against Cybercrime. 58 The two conventions do not prescribe international crimes. Respecting the exclusive prescriptive jurisdiction of States for criminal law, the two conventions rather contain model building blocks for inclusion in national criminal laws. The goal is to harmonize national criminal laws of the participating States for cyber activities. Also in other instances, States harmonized criminal law rules for the prosecution of private acts against legitimate activities of States (and their nationals) in exercise of their sovereign freedom of action. For example, the United Nations Convention of the Law of the Sea takes a similar path for submarine cables and pipelines on the bed of the high seas. The right of States to lay submarine cables and pipelines is connected to the adoption of national laws which render the wilful or culpably negligent damage of cables and pipelines a punishable offence. 59 The Budapest Convention on Cybercrime was established in the frame‐ work of the Council of Europe in 2001 and is open to all States. It is in force with more than 80 ratifications. Almost half of the State Parties to the Budapest Convention are not members of the Council of Europe (2026). The Convention requires implementation of substantive and procedural criminal law rules in national criminal law. It includes seven criminal offences against the confidentiality, integrity and availability of computer data and systems: illegal access, illegal interception, data interference, system inter‐ ference, misuse of devices, computer related forgery and computer related 52 Chapter Two · Cyber Law and Public International Law <?page no="53"?> 60 Budapest Convention on Cybercrime, supra note 57, Articles 2-8, for more details of the offences see infra 3.2.2. 61 Budapest Convention, id., Articles 9, 10. 62 Budapest Convention, id., Articles 16-22. 63 Budapest Convention, id., Articles 23-35. 64 Additional Protocol to the Convention on Cybercrime, concerning the criminalisation of acts of a racist and xenophobic nature committed through computer systems, Strasbourg, 28 January 2003, ETS No. 189. 65 Second Additional Protocol to the Convention on Cybercrime on enhanced co-opera‐ tion and disclosure of electronic evidence, Strasbourg, 12. May 2022, ETS No. 224. 66 United Nations Convention against Cybercrime, supra footnote 58. 67 UN Convention against Cybercrime, id., Articles 15-17. 68 UN Convention against Cybercrime, id., Article 40.1. fraud. 60 Another two offences relate to content: child pornography and infringements of copyright and related rights. 61 Procedural rules concentrate on powers to investigate cybercrime, on securing of electronic evidence and jurisdiction. 62 Member States agree on international co-operation in investigations, proceedings and evidence collection concerning criminal offences related to computer systems and data, in extradition and in mutual assistance. 63 Two Additional Protocols add criminal offences of a racist and xenophobic nature committed through computer systems, 64 and provisions on enhanced cooperation and disclosure of electronic evidence. 65 The United Nations Convention against Cybercrime was adopted by consensus through the UN General Assembly 66 and is open to signature since October 2025 but not yet in force (2026). In large parts, it duplicates the Budapest Convention on Cybercrime or contains similar wording. Noteworthy are the differences. The draft UN Convention includes offences not covered by the Budapest Convention: the solicitation of children for sexual offences, non-consensual dissemination of intimate images and laundering of proceeds of crime, 67 but it does not contain offences related to copyright infringement. Unlike the Budapest Convention, the UN draft limits the sharing of electronic evidence to offences under the Convention and serious crimes. 68 The enhanced measures of electronic evidence of the Second Additional Protocol to the Budapest Convention are also not included. During the drafting phase, concerns about risks of misuse of the UN Convention in the then current text version almost led to a failure of the project. Agreement on the text was finally reached after the inclusion of provisions on respect for human rights, protection of personal data, non-discrimination during mutual legal assistance, the right to fair trial and 2.5 Criminal Law Treaties 53 <?page no="54"?> 69 UN Convention against Cybercrime, id., Articles 6, 21.4, 24, 36, 42.22. See also Council of Europe, Briefing note, Conventions on cybercrime: The Budapest Convention and the draft UN treaty, 27 August 2024, 🔗 https: / / rm.coe.int/ conventions-on-cybercrime -the-budapest-convention-and-the-draft-un-tre/ 1680b1631a (accessed March 2026). 70 Treaty between the United States and other Powers Providing for the Renunciation of War as an Instrument of National Policy, Paris, 27 August 1928, 94 LNTS 57, Art. I. 71 Carl von Clausewitz, Vom Kriege, Berlin, 1832, 1. Book, 1. Chapter, Section 24 72 UN Charter, supra note 5, Articles 42, 43. defence and other procedural protections. 69 In the future, practice will show if these safeguards suffice. 2.6 Armed Conflict The United Nations Charter of 1945 is the central instrument for maintaining international peace and security in public international law since World War II. Cornerstones of this world peace order are the principles to refrain from the use or threat of force and the peaceful settlement of disputes under Article 2(3), (4). The UN Charter builds upon the idea of the historic Briand-Kellog Pact of 1928: “The High Contracting Parties solemnly declare … that they condemn recourse to war for the solution of international controversies, and renounce it, as an instrument of national policy in their relations with one another.”  70 The peace order of the UN Charter is a conceptual antipode to the polit‐ ico-military notion of von Clausewitz in 1832 that [translation] “war is merely a continuation of politics by other means.” 71 Hostilities and armed conflicts are unfortunately facts of international relations. Involved parties tend to justify their armed activities within the existing framework of the UN Charter. The Charter provides for two exceptions to the principle of refraining from the use of force: measures of force decided by the UN Security Council 72 and the inherent right of self-defence of States. Given the long ongoing political impasse of the Security Council, States regularly tend to justify their use of force as self-defence. 54 Chapter Two · Cyber Law and Public International Law <?page no="55"?> 73 Letter from Mr. Webster to Mr. Fox, 24 April 1841, British & Foreign State Papers, vol. 30, p.-195. 74 Nicaragua Case, supra note 23, p.-93, para. 195. 2.6.1 Self-Defence and Armed Attack Article 51 of the UN Charter recognizes the customary right of self-defence of States as an instant short-term measure against an armed attack until the Security Council can intervene: “Nothing in the present Charter shall impair the inherent right of individual or collective self-defence if an armed attack occurs against a Member of the United Nations, until the Security Council has taken measures necessary to maintain international peace and security.” Article 51 of the UN Charter does not detail the requirements of the customary right of self-defence. Already in 1842, in the diplomatic exchange of letters about the Caroline Case, the requirement of an ‘imminent’ attack was specified, which has become part of customary law: “It will be … to show a necessity of self-defence, instant, overwhelming, leaving no choice of means, and no moment for deliberation.”  73 Self-defence is only deemed necessary against an act which has the gravity to be called ‘overwhelming’, which requires instant reaction and, without a moment for deliberation, permits no other means to avert it. Some States attempt to stretch the requirement of imminence for justifying their so-called pre-emptive strikes as self-defence, well before an armed attack is imminent. The Nicaragua Case of the International Court of Justice provides further clarification on the nature of the acts which constitute armed attacks: “In the case of individual self-defence, the exercise of this right is subject to the State concerned having been the victim of an armed attack. … in customary law, the prohibition of armed attacks may apply to the sending by a State of armed bands to the territory of another State, if such an operation, because of its scale and effects, would have been classified as an armed attack … had it been carried out by regular armed forces. … the concept of "armed attack" includes … also assistance to rebels in the form of the provision of weapons or logistical or other support. Such assistance may be regarded as a threat or use of force, or amount to intervention in the internal or external affairs of other States.”  74 2.6 Armed Conflict 55 <?page no="56"?> 75 Nicaragua Case, id., p.-93, para. 194. 76 Michael N. Schmitt (ed.), Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations, Cambridge University Press, 2017, Rule 69, section 9 proposes the following factors for assessing the scale and effects of a cyber activity: severity, immediacy, directness, invasiveness, measurability of effects, military character, State involvement and presumptive legality The scale and effects of an act determine if it qualifies as an armed attack. The engagement of non-State actors, providing them with weapons, logistical or other support can be equivalent in its scale and effects to an armed attack by armed forces in foreign territory. The Court furthermore recognized that “… whether the response to the attack is lawful depends on observance of the criteria of the necessity and the proportionality of the measures taken in self-defence.”  75 2.6.2 Cyber Activities in Armed Conflict Cyber activities have become indispensable tools of modern warfare. During armed conflict they can be used as a means of • communication among own forces and among the population, • remote control of military infrastructure and weapons, • disruption of adversary (IP-based) communication and adversary infra‐ structure and weapons, • exploiting of adversary mobile IP-based communication networks for targeting (of aerial drones) in adversary territory, and • spreading information and propaganda as part of information warfare. If a cyber activity qualifies as an armed attack (in the meaning of Article 51 of the UN Charter) depends on the level of scales and effects. This needs to be assessed on a case-by-case basis. Relevant is the degree of inflicted harm and the effect of the cyber activity. 76 Cyber activities which affect automated processes or cause kinetic effects, for example against critical infrastructure, qualify more easily to have effects equivalent to the use of force or an armed attack. Their scale must be assessed in each individual case. Cyber activities which unauthorisedly access, deny access or use, erase or manipulate data without kinetic effects, typically do not reach this level of scale and effects. States have an inherent right of self-defence against malicious cyber activities which reach by their scale and effects the level of an imminent armed attack. States may exercise their right of self-defence also by engaging 56 Chapter Two · Cyber Law and Public International Law <?page no="57"?> 77 See also supra 1.4.3. 78 ARSIWA, supra note 39, Arts. 49-53. cyber means, subject to necessity and proportionality, following the dictum of the Nicaragua Case. However, the question if malicious cyber activities constitute an armed attack and justify (collective) self-defence seems to have become obsolete due to practical developments. This question was raised after the large scale and highly coordinated cyber campaign against Estonian government, banking, and media websites in April 2007. 77 Today the focus has shifted. The tactical engagement of (military) cyber activities shows two main scenarios: • In most cases, cyber activities form part of hybrid threats below the threshold of armed attack, use of force or armed conflict. • In armed conflicts, cyber activities play an important role parallel to and in conjunction with traditional (kinetic) weapons of land, air and sea forces. In both scenarios, cyber activities are not first strike armed attacks. A State can undertake temporary and proportionate countermeasures, as last resort, against cyber activities which constitute internationally wrongful acts and remain below the threshold of the use of force. 78 Countermeasures are legally justified acts as reaction to and against wrongful acts but would otherwise be considered unlawful. The conditions of last resort, temporary nature, proportionality and compliance with peremptory norms must be strictly followed. 2.6.3 International Humanitarian Law During armed conflict, international humanitarian law protects people who are not participating in hostilities, and it restricts the means and methods of war. International humanitarian law provides for reduced protections during wartime, when the higher levels of protection of human rights law cannot be upheld. Cyber activities can be engaged in armed conflicts with similar effects as traditional weapons of war. They can be used as a means of unilateral first strikes or for self-defence. When their effects reach the level equivalent to the use of force during armed conflict, cyber activities are subject to inter‐ national humanitarian law like any other military means and methods of 2.6 Armed Conflict 57 <?page no="58"?> 79 See also Instructions for the Government of Armies of the United States in the Field, General Orders No. 100 (Lieber Code), 1863, Article 14. 80 See also Protocol Additional to the Geneva Conventions of 12 August 1949 and relating to the Protection of Victims of International Armed Conflicts (Protocol I), 8 June 1977, Articles 48, 49(3). 81 See also Protocol Additional, id., Articles 51(5)(b), 57(2)(a)(iii), (b). 82 See also Protocol Additional, id., Article 1(2). 83 See infra 6.1.3. war. In this case the basic principles of necessity, distinction, proportionality and humanity apply. The principle of military necessity limits a State to use force only to the extend required for achieving the military purpose to gain military advantage with minimum loss of life and destruction. 79 As a pre-requisite for compliance with military necessity, the principle of distinction requires to distinguish between armed forces and civilians, between combatants and non-combatants, and between objects that can be attacked for military purposes and protected civilian objects. 80 The principle of proportionality prohibits military attacks which cause excessive loss of live and injury of civilians and excessive damage to civilian objects in relation to the expected military advantage. 81 The principle of humanity prohibits the unnecessary infliction of suffering, injury or destruction. 82 Compliance with international humanitarian law is a central discussion point about the use of autonomous weapons systems, also in connection with artificial intelligence. 83 58 Chapter Two · Cyber Law and Public International Law <?page no="59"?> 1 United Nations Charter, 26 June 1945, 1 UNTS XVI, Article I 1. Chapter Three · Unauthorised Cyber Activities and Cyber Security Cyber security is a key element for the protection of digital information and systems against unauthorised cyber activities. The concept of security deserves a closer look and how it interrelates to unauthorised cyber activi‐ ties. 3.1 Terminology 3.1.1 Security Security is a broad term. It can be understood as prevention of and defence against threats created by humans. Security can relate to threats originating from any kind of legal subject, from individuals to private and public legal entities including States. The term national security is used for the protection and defence of States in relation to other States for assuring the protection and defence of their people, assets and rights. Related is the term of maintaining international peace and security among all States as a core function of the United Nations. 1 Security needs to be distinguished from safety. This distinction tends to be overlooked, especially in languages which use the same term for safety and security. Safety relates to risks caused by malfunctioning of (technical) systems, which typically endanger human health, life or property. The following example can serve as illustration of this distinction. The proper design, manufacturing and maintenance of brakes and steering of a car are a matter of safety. The purpose of car safety is to protect the health, life and property of drivers, passengers and innocent by-standers during typical modes of operation. Different thereto, the protection against theft of a car, or the protection against human manipulation of brakes and steering fall under the concept of security. States play a crucial role in maintaining security. They hold police authority for internal security and national security authority for external relations with other States. This does however not imply that other legal <?page no="60"?> 2 See supra 1.4.2. 3 See also European Network and Information Security Agency (ENISA), Definition of Cybersecurity - Gaps and overlaps in standardisation, December 2015. 4 Organisation of International Standardization (ISO), International Standard 22340, Security and resilience — Protective security — Guidelines for an enterprise protective security architecture and framework, 1.ed 2024, 3.4. 5 Reproduced in the (USA) National Institute of Standards and Technology (NIST) SP 800-12, section 1.4. subjects have no role in security matters. Who operates or owns an asset or system prone to security vulnerabilities should undertake protection measures as a matter of due diligence; the owner or operator cannot solely rely on the protection and defence of executive State bodies. The protection against unauthorised cyber activities 2 falls under the concept of (cyber) security. Security is a safeguard against threats created by humans. A person who applies techniques which adversely affect digital information and systems of other legal subjects without their consent, acts unauthorisedly. Security protects against such threats. 3.1.2 Examples of Definitions Numerous definitions for cyber security and information security in dif‐ ferent contexts can be found in applicable regulations and non-binding standards and guidelines. 3 One of the definitions of the ISO is contained in standard 22340, which defines cyber security as the: “… protection of the confidentiality, integrity, and availability of digital systems (hardware, software and associated infrastructure) from unauthorised digital access, harm or misuse, or attack scenarios that involve deliberate exploitation of computer systems, digitally-dependent enterprise networks and control systems.”  4 US legislation 44 U.S.C., Sec. 3542 5 uses similar elements for the definition of information security: “The protection of information and information systems from unauthorised access, use, disclosure, disruption, modification, or destruction in order to provide confiden‐ tiality, integrity, and availability.” The International Telecommunications Union uses an overly long definition of cyber security in ITU.T, X.1205, which reads abbreviatedly: 60 Chapter Three · Unauthorised Cyber Activities and Cyber Security <?page no="61"?> 6 Regulation (EU) 2019/ 881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification (Cybersecurity Act). 7 Regulation (EU) 2019/ 881, id, Article 6 (2), (5), (6). 8 See supra 1.4.4. 9 ISO/ IEC international standard 27000, Information technology, Security techniques, 5.ed 2018-02, section 3.10 “… Cybersecurity strives to ensure the attainment and maintenance of the security properties of the organisation and user's assets against relevant security risks in the cyber environment. The general security objectives comprise the following: availability; integrity, which may include authenticity and non-repudiation; and confidentiality.” Article 2 of the EU Cyber Security Act 6 defines cyber security in connection with cyber threat: “(1) ‘cybersecurity’ means the activities necessary to protect network and informa‐ tion systems, the users of such systems, and other persons affected by cyber threats; … (8) ‘cyber threat’ means any potential circumstance, event or action that could damage, disrupt or otherwise adversely impact network and information systems, the users of such systems and other persons”. These definitions do not use the term ‘unauthorised cyber activities’ but, except for ITU, they list specific activities that fall under the umbrella of unauthorised cyber activities: unauthorised digital access, harm, misuse, deliberate exploitation, disclosure, disruption, modification or destruction. 3.1.3 Confidentiality, Integrity, Availability ISO, NIST, ITU, the EU 7 and other institutions use the terms ‘confidentiality’, ‘integrity’ and ‘availability’, often as a fixed tripartite concept. This concept relates to information security and describes unauthorised activities not by their methods, but by their effects on protected information and related systems. It also distinguishes unauthorised cyber activities from violations of information content. 8 The ISO/ IEC international standard 27000 defines these three terms as follows: Confidentiality is the “property that information is not made available or disclosed to unauthorised individuals, entities or processes”.  9 3.1 Terminology 61 <?page no="62"?> 10 ISO/ IEC international standard 27000, id., section 3.36. 11 ISO/ IEC international standard 27000, id., section 3.7. 12 ISO/ IEC international standard 27000, id., section 3.6. 13 ISO/ IEC international standard 27000, id., section 3.48. Integrity’ is the “property of accuracy and completeness”.  10 Availability’ is the “property of being accessible and usable on demand by an authorised entity”.  11 Confidentiality relates to information (including data and software) which is to be protected against disclosure and access to unauthorised individuals, entities or processes for maintaining privacy or intellectual property of the given information. When integrity relates to information, it signifies its accuracy and completeness without damage, modification or destruction. Integrity of information includes the concepts of ‘authenticity’ and ‘non-repudiation’. ‘Authenticity’ is the “property that an entity is what it claims to be”. 12 ‘Non-re‐ pudiation’ means the “ability to prove the occurrence of a claimed event or action and its originating entities” 13 - or in other words: if an event is properly attributed to its originator. For systems (including computers, networks and peripheral devices) integrity indicates their proper functioning. Availability relates likewise to information and systems and is to assure authorised users have timely, unhindered and reliable access to information and functioning computers, networks and peripheral systems. 3.1.4 Distinctions For the purpose of this book, the authors define: Cyber security as the • protection of digital data, information, computers, networks and peripheral systems • to assure their confidentiality, integrity and availability • against unauthorised cyber activities (i.e. with techniques using data and information through networks that have an adverse effect on the target information and system without the operator’s / owner’s consent). 62 Chapter Three · Unauthorised Cyber Activities and Cyber Security <?page no="63"?> 14 ISO, International Standard ISO/ IEC 27032, 2 nd ed., 2023-06, Cybersecurity - Guidelines for Internet Security, section 5. 15 ISO, International Standard, id., section 3.11. 16 Supra 1.3.2.1 17 ISO, International Standard ISO/ IEC 27000: 2016, supra note 9, section 2.33. The ISO uses cyber security as the umbrella concept for internet security, web security and network security. In this context, ISO understands 14 • networks to include hardware as routers, hubs, cabling, telecommuni‐ cations controllers, and key distribution centres, • web as the concept of sharing of information by the file transfer protocol (FTP) and the use of the HTTP protocol through which URL addresses can be accessed, • and the Internet as the ‘global system of inter-connected networks in the public domain’. 15 Numerous sets of non-binding standards and guidelines approach cyber security not in isolation but link it to information security and physical security. For ISO, experts in the field collect best practices and provide voluntary elements for organisations to protect the confidentiality, integrity and availability of their digital information systems also against physical acts of humans 16 and against detrimental environmental impacts, like fire and flooding. Information security is a broader concept than cyber security. It protects digital information, and non-digital information in paper form and related archives. ISO defines it in an all-encompassing manner as “preservation of confidentiality, integrity and availability of information” 17 without any qualifiers on the format of the information, the nature of the threat and without mentioning systems on which information resides or through which it is passed. Cyber security is a sub-set of information security. Certain (behavioural, organisational and operational) information security measures can also be applied to cyber security, while technical cyber security measures are specific to cyber security. The concept of information security includes protections against non-networked threats, especially physical acts against infrastructure, the latter also being addressed as physical security. Physical security reaches beyond information security. It includes “measures used to provide physical protection of resources against deliberate 3.1 Terminology 63 <?page no="64"?> 18 ISO, International Standard 7498-2: 1989, section 3.3.41. 19 ISO, International Standard ISO/ IEC 22237-1: 2021, section 3.1.25. 20 Directive (EU) 2022/ 2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities (CER Directive). and accidental threats.”  18 In the context of information technology, ISO links physical security to ‘availability’ and defines it as “measures (combining physical and technological controls), procedures and respon‐ sibilities to maintain the desired level of availability for the facilities and infrastruc‐ tures of the data centres in relation to access control and environmental events”.  19 Whereas unauthorised cyber activities are undertaken through networks under the cover of anonymity, physical acts use other methods which impact information technology infrastructure from outside. For the investigation of physical acts, conventional forensic methods can be used to identify the physical location and type of impact. Examples of physical security breaches related to digital information and systems are damage to computers with a hammer, disconnection of cables or forced access into a computer room. For assuring the physical security of critical infrastructures, the European Union enacted the so-called CER Directive (EU) 2022/ 2557. 20 Communication security describes the protection of data and infor‐ mation to assure their confidentiality, integrity and availability against unauthorised access and interception during transmissions. Communica‐ tion security serves the protection of data and information transmissions through radio links, wires and fibres. It overlaps with cyber, information and physical security. Examples of digital communication security breaches are exploitations of wireless data transmissions through WLAN, Bluetooth or Near-Field Communication (NFC). Tapping into data transmitted through manipulated cable connections also constitutes a compromise of physical security. Exposed organisations usually apply a holistic security approach for the protection of their digital information and systems. This approach includes cyber security, the broader concept of information security, physical secur‐ ity, communication security and business continuity. All these security elements have their specific roles and are addressed by ISO and NIST standards. While recognizing this broader security scenario, unauthorised 64 Chapter Three · Unauthorised Cyber Activities and Cyber Security <?page no="65"?> cyber activities result in specific cyber threats. They require specific cyber security measures and specific cyber forensics. 3.2 Unauthorised Cyber Activities 3.2.1 Methods and Vulnerabilities Numerous technical methods can undermine the confidentiality, integrity and availability of digital information and systems. Many unauthorised cy‐ ber activities use software to re-program computers, networks or peripheral devices. Software not authorised by the target computer’s operator or owner and introduced with malicious intent is broadly addressed as malware. Different methods exist for introducing malware to targeted computers. Trojan type malware hides malicious code in inconspicuous software. Viruses replicate themselves by modifying software used by the victim. Worms replicate themselves and spread further to affect other software applications. The variants of malware are countless. Their numbers and levels of sophistication are constantly increasing. Malware which compromises the confidentiality of information normally requires the breach of integrity of the system that holds it. Spyware is a general term for malware which compromises confidentiality. Active eavesdropping or network sniffing use malware to secretly monitor (network) communications and capture transmitted data. Structured query language (SQL) injections replace data inputs (for example a password) of innocent users by malware which can compromise the integrity their system. So-called botnets compromise the integrity of systems by unauthorisedly exercising central control over groups of computers of unauthorised actors. Ransomware is a type of malware which compromises availability. It encrypts victims’ data for the purpose of demanding ransom in turn for decryption and recovering availability. Even without introducing malware, the transmission of data through networks can be targeted and misused by Denial of Service (DOS) strikes. They spam and overload target computers or servers with large volumes of data traffic and make them unavailable for users. Large numbers of coordinated DOS activities are also called Directed Denial of Service (DDOS). Botnets are often used for launching DDOS strikes. 3.2 Unauthorised Cyber Activities 65 <?page no="66"?> Technical methods and malware are often combined with the exploitation of behavioural, operational, organisational or technical vulnerabilities. Exploitations of human behaviour can be combined with malware, for example by phishing. It involves deceptive messages or websites which victims deem credible for convincing them to provide information, or to open links or attachments which contain malware. For that purpose, an actor may create so called spoofed websites or email addresses to mislead the victim. Exploitation of supply chain vulnerabilities is a method of inten‐ tionally compromising the integrity of digital systems of business partners of organisations whose sensitive information is targeted. This method is directed against smaller organisations in the supply chain which hold sensitive information of the target organisation, but whose protections of digital systems are considered weaker. Exploitation of supply chain vulnerabilities are typically used to gain unauthorised access to technical information and intellectual property of research and development. Users who do not encrypt their LAN or WLAN connection pose a (behavioural) vulnerability for the confidentiality of their transmitted infor‐ mation. Likewise, certain encryption weaknesses of short-range wireless connections like of Bluetooth or Near Field Communications (NFC) can be exploited. The use of hidden back doors and (not yet) known software glitches are technical vulnerabilities whose exploitation requires sophisticated back‐ ground knowledge or system analytics. Back doors are intentionally hidden access points to gain access to a system without authentication. They can be established for (governmental) security purposes or for maintenance of software and hardware developers. The exploitation of unknown glitches or vulnerabilities of software or hardware for which the developer had no time to fix are also known as zero-day-exploits. 3.2.2 Criminal Cyber Activities For cyber security, which is to guard against infractions of confidentiality, integrity and availability, it is not relevant whether unauthorised cyber activities are undertaken with guilt in the sense of criminal law. However, cyber activities can become criminal offences, when actors fulfil the requirements established by national criminal laws. The Budapest 66 Chapter Three · Unauthorised Cyber Activities and Cyber Security <?page no="67"?> 21 Council of Europe, Convention on Cybercrime, Budapest, 23 November 2001, ETS No. 185, see also supra 2.5. 22 Budapest Convention, id., Article 2. 23 Budapest Convention, id., Article 3. 24 Budapest Convention, id., Article 4. 25 Budapest Convention, id., Article 5. 26 Budapest Convention, id., Article 7. 27 Budapest Convention, id., Article 8. Convention 21 has established model criminal cyber offences for adoption by signatory States in their national criminal laws. Seven of these model criminal offences reflect the categories of unauthorised cyber activities against the confidentiality, integrity and availability and, in addition, they require the offender to act with intent: • Intentional illegal access comprises “the access to the whole or any part of a computer system without right.”  22 • Intentional illegal interception encompasses “the interception without right, made by technical means, of non-public transmissions of computer data to, from or within a computer system, including electromagnetic emissions from a computer system carrying such computer data.”  23 • Intentional data interference covers criminal offences against the integ‐ rity (damage, deletion, deterioration and alteration) and availability (suppression) of data. 24 • Intentional system interference includes criminal offences against the integrity and availability of systems through unauthorised hindering of a computer system by “inputting, transmitting, damaging, deleting, altering or suppressing computer data.”  25 • Intentional computer-related forgery is a criminal offense for unauthor‐ ised input, alteration, deletion or suppression of data that makes them inauthentic and thus effects their integrity. 26 • Computer-related fraud comprises cases when someone meets the fact pattern of the offences of data interference or system interference with the intention to cause loss of property of another and with benefit for oneself. 27 3.2 Unauthorised Cyber Activities 67 <?page no="68"?> 3.3 Unauthorised Actors Unauthorised cyber activities are activities undertaken by legal subjects who (detrimentally) effect digital information or systems of others without their consent. These unauthorised actors can be persons who act on their own or on behalf of governmental, commercial or non-profit organisations. 3.3.1 Motivation The motivation of unauthorised actors is diverse. Private persons may perform unauthorised cyber activities to show their skill or the weaknesses of their victims’ organisation. So-called hacktivists act with political, ideo‐ logical or religious motives. Frustrated employees, or others with insider information, can misuse their knowledge or their digital access to turn against their own organisation. When these groups engage intentionally in unauthorised cyber activities, they usually meet the requirements of a criminal offence. Many actors with criminal intent launch their activities for personal gain. They are habitually called cyber criminals, even though the scope of criminal offences under the Budapest Convention is broader. Unauthorised actors with malicious intent are also called black-hat hackers, as opposed to white-hat hackers whose actions are authorised. The latter run cyber activities against the digital information and systems of organisations with the target organisation’s consent for testing the resilience of their systems and identifying vulnerabilities. Critical is the role of so-called grey-hat hackers who pretend to do the same testing and identifying as white-head hackers, but without the consent of the affected organisation. Lacking this consent, grey-hat hackers cannot themselves legally justify their unauthorised cyber activities. States operate or support unauthorised cyber activities for political or ideological reasons. Certain States use cyber activities to weaken other States and their societies for example by spreading propaganda, engaging in cyber espionage or disrupting critical infrastructure and public live. In the military field, States use unauthorised cyber activities to weaken opponent military capabilities and intelligence, also in peacetime and below the threshold of armed attack. 68 Chapter Three · Unauthorised Cyber Activities and Cyber Security <?page no="69"?> 28 For more details of Stuxnet, see e.g. Marie Baezner, Patrice Robin, Center for Security Studies (CSS), ETH Zürich, Hotspot Analysis: Stuxnet, Zürich, October 2017, Version 1, 🔗 https: / / css.ethz.ch/ content/ dam/ ethz/ special-interest/ gess/ cis/ center-for-securities -studies/ pdfs/ Cyber-Reports-2017-04.pdf (accessed March 2026) 3.3.2 Sophistication Different actors use different tools and apply different levels of sophistica‐ tion for their unauthorised cyber activities. For example, young persons who act for personal fun, but also hacktivists may use malware or malware tools readily available in the darknet. The same applies to criminals who obtain ransomware this way. Unauthorised actors with advanced coding knowledge can invest greater effort and skill in composing more sophistica‐ ted malware tailored to break into well secured systems or to target specific software applications. The upper end of sophistication can be found in State funded or sponsored activities. An example is Stuxnet, a malware worm which was discovered in 2010 after it had infected computers of the nuclear enrichment plant in Natanz in Iran. Stuxnet was introduced to the Local Area Network through USB flash drives which were dropped at the facility. Stuxnet exploited four existing software vulnerabilities (‘zero-day-exploits’) and targeted industrial digital controllers which operated centrifuges for uranium enrichment. Stuxnet did not affect other digital applications. After infection, the centrifuges started to spin irregularly until their physical damage. Soon after the discovery of Stuxnet, it was concluded that only State actors could launch this kind of operation, given the complexity of the malware, the exploitation of four vulnerabilities and the pinpointed targeting of the centrifuges. Evidence points primarily to the USA and Israel as originators of Stuxnet. 28 3.3.3 Attribution Attribution is crucial for linking an actor to an unauthorised cyber activity. It takes unauthorised actors out of anonymity and is the basis for holding them responsible and liable. Factual attribution is based on forensic methods to produce evidence. Cyber forensic tools and methods are improving, but more refinement is desirable. Cyber forensics faces many unknown variables and is not an easy task. One of the puzzle stones is malware. Malware used for an unauthorised cyber activity can provide clues to the method of the originator. The level 3.3 Unauthorised Actors 69 <?page no="70"?> 29 See also supra 2.4.1. 30 Budapest Convention, supra note 21, Article 12 - Corporate Liability. of sophistication can give hints about the actor. Since actors launch their unauthorised cyber activities repeatedly or in a similar fashion, they use the same malware or variants of an earlier version. This malware, or its core, may originate from a common source, perhaps from the darknet, and can contain language snippets, which point to the language of the actors. More sophisticated malware has its characteristics as well. An experienced programmer does not each time write malware from the ground up but relies on proven elements of the code. This programmer may exploit for different malware the same vulnerabilities of software and systems. Copying and pasting elements of malware code saves time and effort for programmers but leaves identifiable traces for forensic analysts. Similar traces can be linked to the same originator. Should in a specific instance, the trail to the originator of one unauthorised cyber activity be identified, the entire series of activities can be related. Legal attribution supplements factual attribution. Existing legal con‐ cepts can for example establish organisational responsibility and liability, provided evidence is established through factual attribution. Different to existing concepts for international responsibility which apply among States in public international law, 29 responsibility and liability for most unauthor‐ ised cyber falls under domestic law. For example, domestic private law jurisdictions recognize organisational or corporate negligence in one way or another. It is based on the concept of an organisational duty of care. As a duty of care, an organisation must avoid harm to others by establishing proper organisational structures and responsibilities, to act legally, to implement adequate safety and security precautions and to exercise oversight. In practice, this implies an organisa‐ tion can be held responsible and liable, if an unauthorised cyber activity originates from its sphere, even if no individual can be pinpointed. This can be the case, when there is evidence that an unauthorised cyber activity originated from an organisation’s systems, like their Local Area Network (LAN). The same conceptual line follows the Budapest Convention for establish‐ ing corporate criminal liability: 30 70 Chapter Three · Unauthorised Cyber Activities and Cyber Security <?page no="71"?> 31 Directive (EU) 2022/ 2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, (NIS 2 Directive) Article 1, 1. “2 … each Party shall take the measures necessary to ensure that a legal person can be held liable where the lack of supervision or control by a natural person … has made possible the commission of a criminal offence … for the benefit of that legal person by a natural person acting under its authority. 3 … the liability of a legal person may be criminal, civil or administrative. 4 Such liability shall be without prejudice to the criminal liability of the natural persons who have committed the offence.” For the prevention of misuse of their systems and for the avoidance of private and criminal liability, there is an incentive for organisations to establish cyber security measures. 3.4 Cyber Security Measures A broad spectrum of cyber security measures has been developed, given the diversity of cyber threats, unauthorised actors and vulnerabilities of digital information and systems. These measures can be roughly grouped in behavioural, organisational/ operational and technical measures. They are derived from practical experience. Experts of national and international standardization bodies, most notably the ISO, have established a large set of security standards for voluntary application by affected organisations. In parallel thereto, national legislation can mandate national organisa‐ tions to implement cyber security measures for their digital information and systems. For example, the European NIS2 Directive establishes measures for achieving a high common level of cyber security. 31 It applies cross-sector wide to private and public entities which qualify as medium-sized enter‐ 3.4 Cyber Security Measures 71 <?page no="72"?> 32 Directive (EU) 2022/ 2555, id., Article 2 and Annex I: The sectors of high criticality are energy, transport (including air transport), banking, financial market infrastructures, health, drinking and waste-water, digital infrastructure, information and computer technology service management, public administration and space. 33 Directive (EU) 2022/ 2555, id., Article 2, Annex II: The other critical sectors are postal and courier services, waste management, manufacture, production and distribution of chemicals, production, processing and distribution of food, manufacturing (of medical devices, computers, electronic, optical, electrical products, machinery and vehicles), digital providers (of online marketplaces, search engines, social networking services platforms), research. 34 Directive (EU) 2022/ 2555, id., Article 21, 1. 35 Organisation of International Standardization, International Standard ISO/ IEC 27001, 3 rd ed. 2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements, 6.1.2, 6.1.3, 8.2, 8.3. prises (with exceptions) of sectors of high criticality 32 and other critical sectors. 33 3.4.1 Risk Management Risk Management is the central element for selecting appropriate and proportional cyber security measures to the specific cyber security needs of an organisation. Organisations in critical, but different sectors have different exposures to threats. Risk management helps to match suitable and proportionate measures with existing exposures. There is no ‘one size fits all’. For that reason, the EU NIS2 Directive provides: “… that essential and important entities take appropriate and proportionate tech‐ nical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations … and to prevent or minimise the impact of incidents … Taking into account the state-of-the-art and, where applicable, relevant European and international standards, as well as the cost of implementation, the measures … shall ensure a level of security of network and information systems appropriate to the risks posed. When assessing the proportionality of those measures, due account shall be taken of the degree of the entity’s exposure to risks, the entity’s size and the likelihood of occurrence of incidents and their severity, including their societal and economic impact.”  34 ISO standards specify in more detail the planning and operating of informa‐ tion security risk assessment and treatment as elements for establishing an information security management system. 35 72 Chapter Three · Unauthorised Cyber Activities and Cyber Security <?page no="73"?> 36 Regulation (EU) 2019/ 881 (Cybersecurity Act), supra note 6, Art. 4.7, also EU Dir. 2022/ 2555 (NIS2), supra note 31, Art. 21.2 (g). 37 ISO International Standard ISO/ IEC 27002, 3rd ed. 2022, Information security, cyberse‐ curity and privacy protection — Information security controls, 6.3. 38 ISO International Standard ISO/ IEC 27002, id., 5.4, 5.17, 6.1 - 6.5, 6.8, also EU Dir. 2022/ 2555 (NIS2), supra note 31, Art. 21.2 (i). 3.4.2 Behavioural Measures Measures for improving behaviour relate to the interface between human action and digital technology. Behavioural measures aim to heighten indi‐ vidual awareness of cyber threats, system vulnerabilities and information sensitivities. They aim to strengthen the secure handling of cyber operations with necessary safeguards and to introduce response measures, in case of a security breach. In the same vein, the EU Cybersecurity Act highlights the promotion of “a high level of cybersecurity awareness, including cyber-hygiene and cyber-literacy among citizens, organisations and businesses.” 36 Organisations seeking protection under the ISO 27000 standard series need to implement for their management and staff information security awareness, education and training. 37 Human resource managers need to raise security awareness and run security training and awareness pro‐ grammes. Personnel need to be briefed on the secure handling of digital information and systems. Levels of authorised access require to be estab‐ lished and administered. Behavioural measures seamlessly connect with organisational measures for human resource security. These measures commence prior to employment with candidate screening and the terms and conditions of employment. During employment, measures encompass their responsibilities for the use of secret authentication and their role in the reporting of information security events and weaknesses. Non-compliance of staff can lead up to disciplinary measures and termination or change of employment conditions. 38 3.4.3 Organisational and Operational Measures Organisational and operational measures are tailored to private and public organisations which operate information systems, and process, store and distribute information. Many of these elements which are developed more broadly for information security can be used for cyber security. Many 3.4 Cyber Security Measures 73 <?page no="74"?> 39 ISO International Standard ISO/ IEC 27002, id., 5.2, 5.3, 5.8, 8.25, 8.32, also EU Dir. 2022/ 2555 (NIS2), id., Art. 21.2 (e). 40 ISO International Standard ISO/ IEC 27002, id., 5.9 - 5.18, 8.2 - 8.4, also EU Dir. 2022/ 2555 (NIS2), id., Art. 21.2 (j). 41 ISO International Standard ISO/ IEC 27002, id., 5.14, 5.37, 8.6, 8.7, 8.13, 8.15, 8.17, 8.19 - -8.21, 8.32. 42 ISO International Standard ISO/ IEC 27002, id., 5.19---5.21. 43 ISO International Standard ISO/ IEC 27002, id., 5.29, also EU Dir. 2022/ 2555 (NIS2), supra note 31, Art. 21.2 (b), (c). elements overlap with the related fields of physical and communication security. A broad range of organisational and operational measures are pro-active to reduce the risk of security violations. Information security requirements and specifications are intended to apply to all phases of the lifetime of digital systems from development, through acquisition, maintenance and to subsequent changes. They include the organisational structure of informa‐ tion security, roles and responsibilities within the organisation, separation of functions, and information security in project management. 39 As an organisational measure, digital assets including mobile devices should be inventoried, their acceptable use and handling be defined and asset return be controlled. Information should be classified and labelled. Special attention is to be paid to access control to networks and services. This comprises access control policies, user access management, and system and application access control. 40 Operational procedures, operational software, and change and capacity management should be documented. Controls should be established against malware, for information back-up procedures, logging and monitoring. Measures for communication security comprise network controls, security of network services, segregation of networks and information transfers with other organisations. 41 Recognizing vulnerabilities of supply chains, organisational cyber security measures should incorporate supply chain relationships and agreements, their review and monitoring. 42 Organisational cyber security measures can also be reactive in nature, most notably the management of information security incidents. At its core, incident management is an organised and structured collection and exchange of information about security breaches to warn and inform other users, to take appropriate preventive action, and to assure business continuity. 43 Affected organisations need to report security incidents and 74 Chapter Three · Unauthorised Cyber Activities and Cyber Security <?page no="75"?> 44 ISO International Standard ISO/ IEC 27002, id., 6.8, 5.24 - 5.28, EU Dir. 2022/ 2555 (NIS2), id., Art. 21.2 (d). 45 ISO International Standard ISO/ IEC 27019: 2024, 3.1.3. 46 EU Dir. 2022/ 2555 (NIS2), supra note 31, Arts. 1.2, 10, 11, 12.1, 12.2, 13.1-4, 15, 23. weaknesses for their assessment timely to a centralized designated point or body. Relevant information is gathered in a data base for collection of evidence and learning from information security incidents. 44 A central organisational element are computer security incident response teams (CSIRT). These are “teams of security experts to support the handling of information security incidents”. 45 The EU NIS2 Directive follows the same pattern, as it requires Member States to designate or establish CSIRTs. It imposes reporting obligations on defined entities and establishes rules and obligations on cyber security information sharing and a European vulnerability data base. 46 3.4.4 Technical Measures Technical cybersecurity measures are to assure the technical resilience of digital systems and networks for the protection of their confidentiality, integrity and availability. Technical measures, practices and standards relate specifically to the technical nature of digital systems including networks. Technical cyber security measures consist of dedicated software, hardware or a combination thereof. Due to the continuous development of technology and emerging cyber threats, technical measures require constant adaptations for countering upcoming cyber threats. Technical measures thus need to be dynamic to warrant their effectiveness. Moreover, many technical measures are not neutral regarding a specific technology, creator or manufacturer. Operators purchase a specific hardware or subscribe to software products or services for the protection of their digital systems, networks and digital information. The dynamic nature and the lack of technology neutrality create diffi‐ culties in the rulemaking for technical cyber security measures. Rules on technical measures require flexibility to adjust to technical developments. They should not favour a certain technology or product. In practice, rules on technical measures are more generic than behavioural, organisational and operational measures. They often tend to express operational procedures, rather than technology itself. References to existing technical standards can 3.4 Cyber Security Measures 75 <?page no="76"?> 47 EU Dir. 2022/ 2555 (NIS2), id., Article 25. 48 ISO International Standard 24100, 2010, 3.9. avoid mentioning specific technology but remain generic. An example is Article 25 of the EU NIS2 Directive: 47 “1. … Member States shall, without imposing or discriminating in favour of the use of a particular type of technology, encourage the use of European and international standards and technical specifications relevant to the security of network and information systems. ENISA … shall draw up advice and guidelines regarding the technical areas to be considered … as well as regarding already existing standards, including national standards, which would allow for those areas to be covered.” While the EU NIS 2 Directive provides detail of organisational and opera‐ tional cyber security measures, the reference to unspecified standards under Article 25 of the EU NIS2 Directive set a more general frame for technical cyber security measures. The mentioned European, international and national standards create a link to existing standards systems like the ISO 27000 series and its implementations through national (European) standardization organisations. Typical technical cyber security measures are encryption, virtual private networks, firewalls, intrusion detection and prevention systems, system separation and redundancy. Encryption is a technical measure for the protection of confidentiality and integrity of information. It is a “function of transforming data by the discipline of cryptography so as to make the data undecipherable to anyone other than the legitimate sender and receiver”. 48 The purpose of encryption is to limit access to authorised users. A coding process is used to encrypt information into a cyphertext which can be decoded only with a key held by authorised users. Encryption can be applied to digital systems, data or to network connections. It can be accomplished by software or be embedded in hardware. Virtual Private Networks (VPN) are special applications of encryption. VPNs create encrypted virtual networks within unprotected networks like the internet. VPNs use unprotected networks as a transport medium but are logically separated which permits their protection by means of cryptography. 76 Chapter Three · Unauthorised Cyber Activities and Cyber Security <?page no="77"?> 49 EU Dir. 2022/ 2555 (NIS2), supra note 31, Art. 21.2 (h). 50 ISO International Standard 27002, supra note 37, 8.24. 51 ISO International Standard ISO/ IEC 27033. 5 th ed. 2013, Information technology - Secur‐ ity techniques - Network security - Part5: Securing communications across networks using Virtual Private Networks (VPNs). 52 ISO International Standard ISO/ IEC 27033, 2015, Information technology — Security techniques — Network security — Part 1: Overview and concepts, 3.12. 53 ISO International Standard ISO/ IEC 27039, 2015, Information technology — Security techniques — Selection, deployment and operations of intrusion detection and preven‐ tion systems (IDPS), 2.20. The use of both, encryption and VPNs need to be embedded in opera‐ tional and organisation support policies and procedures. 49 For example, the management of keys is a weak element and requires special policy and controls. 50 Trusted and transparent providers need to be engaged for encryption and VPNs to warrant robust encryption and updates. Despite encryption, providers of secure encrypted networks and services may have access to the unencrypted clear text information. VPNs must be properly installed and configured. Network access must be secure to prevent leaks of the VPN communication channel. 51 Firewalls can be used to securely connect IP-based networks and to prevent unauthorised intrusions into protected networks. They consist of systems of hardware and software elements. A firewall is a “type of security barrier placed between network environments — consisting of a dedicated device or a composite of several components and techniques — through which all traffic from one network environment traverses to another, and vice versa, and only authorised traffic, as defined by the local security policy, is allowed to pass”.  52 Firewalls are used at the interface between networks with different levels of trustworthiness. They filter data traffic based on fixed sets of rules, which require constant updating for adjustment to emerging threats. Intrusion detection and prevention systems (IDPS) go a step further. They detect and prevent suspiciously malicious data traffic and activities which has passed already beyond a firewall. Intrusion detection and preven‐ tion systems are “software applications or appliances that monitor systems for malicious activities … [and] have the potent to prevent some intrusions upon detection.” 53 3.4 Cyber Security Measures 77 <?page no="78"?> 54 ISO International Standard ISO/ IEC 27002, supra note 37, 8.31. 55 ISO International Standard ISO/ IEC TS 22237-31, 2023, Information technology — Data centre facilities and infrastructures — Part 31: Key performance indicators for resilience, 3.1.27. 56 E.g. ISO International Standard ISO/ IEC 27002, supra note 37, 5.31-5.34. IDPS can detect (and prevent) cyber threats based on untypical anomalies in a network. Like encryption and virtual private networks, firewalls and IDPS are not technology neutral. Their value depends on trusted and transparent providers for employing effective and updated technical solutions. Different thereto, certain features of system architecture, like system separation and redundancy, are not dependent on a specific technology or provider. They qualify as technical cyber security measures, for example, the separation of operational system environments from development and testing. 54 Related is system redundancy. Duplication of devices and functional elements for performing the same task provides spare alternative system resources in case of failure. 55 3.5 Mandatory Law and Voluntary Schemes The parallelism of non-binding cyber security standards like those of ISO and binding law in EU member States add complexity to their implemen‐ tation. Standards of the ISO are voluntary and more detailed than the EU legislation. Non-binding standards enable organisations to establish a framework for managing cyber security. Even without binding effect, organisations have a self-interest in effectively managing cyber security of their digital systems, networks and information. They have an interest in avoiding damage through cyber threats and to ensure business continuity. They can seek for voluntary certification of their information security management system under ISO standards and interact with other certified organisations for assuring supply chain security. Despite the voluntary na‐ ture of standards and related certification, pertinent legislation, contractual obligations, intellectual property and privacy rights apply and must be complied with. 56 In contrast thereto, the European Union’s Cybersecurity Act is legally binding. Together with the NIS2 Directive, which requires implementation into national law, the European Union has established a legally binding interface by referencing non-binding standards. Compliance with cyber se‐ 78 Chapter Three · Unauthorised Cyber Activities and Cyber Security <?page no="79"?> 57 Regulation (EU) 2019/ 881 (Cybersecurity Act), supra note 6, Arts. 46-65. 58 Regulation (EU) 2019/ 881, id., Article 46.1. 59 Regulation (EU) 2019/ 881, id., Articles 52, 54.1.c, 56, 60. 60 Regulation (EU) 2019/ 881, id., Articles 53, 56. 61 Directive (EU), 2022/ 2555 (NIS2), supra note 31, Articles 24, 20.1. curity rules and standards of organisations under EU legislation is achieved through a cybersecurity certification framework under the Cybersecurity Act. 57 This certification framework “shall provide for a mechanism to establish European cybersecurity certification schemes and to attest that the [information and communications technology] products, … services and … processes that have been evaluated in accordance with such schemes comply with specified security requirements for the purpose of protecting the availability, authenticity, integrity or confidentiality of stored or transmitted or processed data or the functions or services offered by, or accessible via, those products, services and processes throughout their life cycle.”  58 Certification under the EU framework needs to reference European or national standards as certification basis. EU legislation does not contain these standards for the sake of technology neutrality. Certification is accom‐ plished at three assurance levels: basic, substantial and high. Conformity bodies issue European cybersecurity certificates for the basic and substantial levels and national cybersecurity certification authorities for the high level. National accreditation bodies accredit the conformity of assessment bodies. 59 However, organisations are authorised to self-assess conformity at the basic level. Important to note, certification is voluntary, but the EU Commission will assess regularly if certification needs to be mandated, considering the criticality of the sector. 60 To this end, the EU NIS2 Directive provides that EU Member States may require entities of critical and highly critical sectors to use certified products, services and processes to demonstrate compliance with cyber security measures. Management bodies of these entities need to approve measures, oversee their implementation and can be held liable for infringements. 61 Certification schemes can thus become a support tool for enforcement within the EU framework. 3.5 Mandatory Law and Voluntary Schemes 79 <?page no="80"?> 62 See also Regulation (EU) 2024/ 2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act). 3.6 Safety Standards versus Security Standards Technical safety standards must not be confused with (cyber) security standards. Technical safety standards exist for many safety-critical products, but they need to be distinguished from cyber security requirements. This applies also to consumer and domestic products with embedded digital elements, from digital household appliances to smart watches and baby monitors. 62 Safety standards are not suitable to address security aspects. The following example illustrates this difference: Numerous safety requirements exist for cars, because their use and operation are critical to the safety of drivers, passengers and other traffic participants. Safety requirements exist for example for brakes and steering. They need to be designed, manufactured, operated and maintained to warrant a suitable level of safety, considering the speed and mass of the vehicle and typical road and weather conditions. However, safety standards do not provide (security) protections against human manipulations of brakes and steering, for example against cutting hydraulic lines. The following distinction is therefore drawn: Safety standards assure technical safety. They are designed to assure with sufficient probability that a machine, it’s components and related procedures can be safely operated in their typical modes of operation to prevent harm to humans and property. Security standards assure protection against unauthorised human in‐ tervention. They are designed to assure with sufficient probability that an unauthorised person cannot intentionally compromise the safe operation of a machine, it’s components and related procedures. 3.7 Active Measures against Actors of Unauthorised Cyber Activities Active measures against unauthorised actors, so called back-hacking, are subject to stringent legal restrictions. The legal order sets the framework for cyber activities like for any other human activity. An unauthorised or criminal activity does not authorise a victim to engage in similar activities 80 Chapter Three · Unauthorised Cyber Activities and Cyber Security <?page no="81"?> 63 For Germany, see also Federal Constitutional Court, BVerfGE 120, 274---350. 64 International Law Commission, Responsibility of States for Internationally Wrongful Acts, 2001, Annex to UNGA Res. 56/ 83 of 12 December 2001, Articles 49 - 53. against the offender. For example, a victim of burglary is not authorised to burgle the premises of the burglar. Likewise, a victim of an unauthorised cyber activity has no legal justification to access the digital system or network for identification of an unauthorised actor, for gathering evidence for prosecution, or for retrieval or erasure of stolen digital information. Subject to (different) national security legislation and existing court warrants, governmental security bodies can be authorised to access digital systems and networks of alleged offenders for the purpose of identification and evidence collection. Proportionality is a key requirement for such national authorisations under security laws and court orders. The protection of confidentiality and integrity of digital systems and information needs to be balanced against substantiated indications of significant risks to superseding higher legal interest. 63 Moreover, measures of national security bodies for the identification of actors of unauthorised cyber activities and evidence collection face territorial limitations of enforcement jurisdiction, when digital systems are located in other States. In relations between States, active countermeasures against unauthorised cyber activities which constitute an internationally wrongful act can be considered lawful, provided they are temporary, proportionate and are a measure of last resort. 64 3.8 Remarks Cyber security protects digital information, systems and networks against unauthorised cyber activities. Unauthorised cyber activities exploit digital connectivity and interoperability through IP-based networks. Connectiv‐ ity and interoperability are double edged. They support economical and logistical efficiency but also create vulnerabilities and provide access to unauthorised actors. For many years, the internet was used for information exchange only, without any connection to kinetic systems in the real world. Connectivity and interoperability of one integrated global internet became a formula for success. They support the economic logic for unfolding scalable business models, accessing international markets and reducing costs. Connectivity 3.8 Remarks 81 <?page no="82"?> 65 Supra 1.2.4. and interoperability through one internet are cost efficient for routing logic functions of worldwide real-world kinetic applications including those of critical infrastructures. However, network vulnerabilities and cyber threats that may have been acceptable for non-kinetic information require more caution when controlling peripheral devices like critical infrastructures. 65 Connectivity and interoperability create single points of failure. They make the internet not only the network of networks, but a single logic platform for all connected peripheral devices. Global centralization through connectivity and interoperability for critical infrastructures can undermine national and regional independence. Critical infrastructures and systems can become dependent on international actors and vulnerabilities. Previously, critical infrastructures were not dependent on web-based control architectures. These systems were designed with technically diverse elements; they were often compartmentalized and decentralized. Connec‐ tivity and interoperability are conceptional antipodes thereto. Existing cyber security standards and rules address the vulnerabilities originating from connectivity and interoperability. Cyber security is based on a complex system of behavioural, organisational, operational and tech‐ nical measures. Assuring cyber security through non-binding standards and binding rules like those of the European Union takes a huge organisational, financial and human resource effort. The European Union’s approach to cyber security, especially with the NIS2 Directive, follows, duplicates and partly references concepts developed in technical standard setting like those of the ISO. The European Union establishes a heavy bureaucratic structure for cyber security, but compliance is intended to be reached with a certification scheme, like the mechanisms of non-binding standards. Economic and industrial benefits seem to prevent a more critical look at the downsides of using internet connectivity and interoperability for controlling critical infrastructures. A stronger role of system diversity, com‐ partmentalization and decentralization for logic controls of infrastructure is after all a decision of economics and politics, not of law. 82 Chapter Three · Unauthorised Cyber Activities and Cyber Security <?page no="83"?> Chapter Four · Cyber Activities in the Aviation Sector For many decades aircraft have been using electronics and automation for flight control. With the introduction of digital technology and networking, cyber activities became a factor for the entire aviation sector. Not only aircraft are affected but systems and infrastructure that support aviation, part of which can be relevant for flight safety. 4.1 Cyber Security in the Aviation Sector Cyber security in the aviation sector serves two main areas of protection. Cyber security for flight safety functions prevents aviation accidents and protects life, health and property. Cyber security for non-safety functions assures the continuity, regularity and efficiency of civil aviation as a critical segment of the traffic sector. 4.1.1 Technical Background Modern aircraft have numerous onboard computer systems for flight safety and non-safety functions. With increasing size of aircraft, manual flight controls consisting of cables, pulleys and hydraulic systems were replaced by electronics. In the late 1980’s the Airbus 320 was the first commercial transport aircraft with fly-by-wire technology. All pilot inputs to the aircraft’s control surfaces are transmitted with electric signals through wire, specialized microprocessors and electric actuators. They are comple‐ mented by a feedback control loop with sensors. Flight Management Systems (FMS) automate these processes further by integrating navigation and flight planning for safe performance and efficiency. Comprehensive and redundant computer systems onboard relief pilot workload for all aspects of flight. High reliability is paramount because these computerized functions have a direct impact on flight safety. Over the years, this automation has reduced the number of crew on the flight deck. Unmanned Aircraft Systems with no pilot on board go even one step farther. Independent thereof, many <?page no="84"?> non-safety relevant functions for passenger services and comfort onboard are computerized today, like passenger inflight entertainment systems. Aviation organisations on the ground also operate computer systems with a flight safety impact. Air Navigation Service Providers (ANSP) provide services on the ground for the operation of aircraft, like air traf‐ fic control, air traffic services, communication, navigation, surveillance, meteorological and flight information service. Other technical aviation or‐ ganisations possess sensitive information on aviation safety and intellectual property. They are involved in the entire life cycle of aircraft, from aircraft design to manufacturing, aircraft operations and maintenance, or provide aircraft products and services in connected supply chains. Non-flight safety related computer systems of airports and airlines support the availability, regularity and efficiency of civil aviation. Computer outages of airport services like passenger and baggage handling, and ramp services for aircraft hinder air traffic. They can have ripple effects on the rotation of aircraft fleets and the regularity of air traffic in the region. Outages of computer-based airline ticketing, reservation and customer serv‐ ice functions have similar impacts. Moreover, these systems hold sensitive personal and financial data of passengers. 4.1.1.1 The Role of Communications and Networks The use of networks for systems, organisations and infrastructures in the aviation sector is the nexus to (unauthorised) cyber activities. Airborne and ground-based computer systems of the aviation sector can technically be integrated into existing networks when connectivity is established. Interoperability allows data exchanges with the same data and transmission formats. Connectivity between aircraft and ground-stations requires radio communication links. The ongoing migration from analog voice and data communications to digital formats including internet protocols can create interoperability with existing ground networks. 4.1.1.2 Air-Ground Communications Dependent on their functionality, different communication links which establish connectivity between aircraft and ground systems and networks can be distinguished. Aviation safety-related are Aeronautical Operational Control (AOC) and Air Traffic Service (ATS) Communications. Non-aviation 84 Chapter Four · Cyber Activities in the Aviation Sector <?page no="85"?> safety related are Aeronautical Administrative Communications (AAC) and Aeronautical Passenger Communications (APC). Aeronautical Operational Control (AOC) includes air-ground com‐ munication for flight operations, maintenance support, communications management, weather reports and position re-porting to airline operations centres. With the increasing use of digital computer technology in aircraft, the integration of aircraft systems into (ground-based) networks seem a plausible direction of development. One step already taken in some modern aircraft like the Airbus 380, Airbus 350 and Boeing 787 is the use of IP-based network architectures onboard aircraft. They run on commer‐ cial-off-the-shelf (COTS) hardware components and save cost, weight and development time. They serve fly-by-wire flight control, Flight Manage‐ ment Systems, cockpit displays for navigation, surveillance and other flight relevant information and utility systems. While IP-networked functions provide interoperability on board, it does not imply they are connected to ground-based systems. In this case additional technical safeguards like encryption and firewalls are required for cyber security. Air Traffic Services (ATS) Communication includes radio transmis‐ sions between aircraft and air traffic service units for air traffic control, flight information and alerting. For many years ATS Communications has been accomplished by (unencrypted) voice two-way radio transmissions only. In designated airspaces, it is partly replaced by text messaging via so-called Controller-Pilot Data Link Communications (CPDLC), which is migrating from unencrypted to encrypted messaging standards. Aeronautical Administrative Communication consists of private correspondence between aircraft operators and their aircraft for scheduling, crew rotations, seat reservations, but also for the transmission of technical data from aircraft sensors which facilitate maintenance and fault monitor‐ ing. At airports, aircraft can download this kind of information through Wireless Local Area Networks provided by airports (GateLink). Aeronautical Passenger Communication comprises connections with onboard public correspondence facilities and public networks, like passen‐ ger telephone, messaging and internet. They use on-board networks and are typically connected to ground-based networks via satellite. Ground-based and space-based radio navigation aids like Very High Fre‐ quency Omnidirectional Range (VOR), Instrument Landing Systems (ILS) and Global Navigation Satellite Systems do not use IP-based networks, but dedicated radio frequencies for unencrypted reception by civil aviation users. 4.1 Cyber Security in the Aviation Sector 85 <?page no="86"?> 1 See also Convention on International Civil Aviation (Chicago Convention), 7 December 1944, 15 UNTS 295, Annex 10, Telecommunications, Vol. III, Part I, Chapter 8. 2 See also European Union Aviation Safety Agency (EASA), Acceptable Means of Compliance (AMC) 20-25, Airworthiness and operational consideration for Electronic Flight Bags. 4.1.1.3 Ground-Ground Communications and Networks Electronic ground-ground communications in the aviation sector have taken the same path of migration to IP-based networks like in many other sectors. For aviation safety applications the Aeronautical Fixed Telecommuni‐ cation Network (AFTN) 1 is a long-established concept for fixed ground networks enabling voice and data transmissions between air navigation service providers, airports and government agencies. Today’s AFTN is based on internet protocol data formats and encryption. Apart from the Aeronautical Fixed Telecommunication Network, com‐ puter systems of technical aviation organisations involved in the design, manufacturing, operations and maintenance of aircraft and aviation systems use internet connectivity. In a role-shared industry they need to exchange information for sustaining design and supply chains. Like in other business and industry sectors, non-safety related com‐ puter systems of airports, airlines and aviation service providers typically have internet connectivity. Certain systems need internet access for direct customer access, like ticketing, booking and check-in. Other computer systems in the aviation sector are used for internal administrative non-safety related services only; their internet connectivity support the work of their employees. Organisations like Air Navigation Services Providers may also use administrative networks for internal non-safety functions which are separated from their access to the Aeronautical Fixed Telecommunication Network. Electronic flight bags are newer critical system element with IP-based network connectivity. 2 Pilots use electronic flight bags onboard aircraft as a modern replacement of traditional paper documents. Electronic flight bags consist of portable (tablet) computers with specialized software applications for aircraft, navigational reference materials, flight planning and perform‐ ance calculations. Flight relevant information needs to be downloaded to electronic flight bags via the internet prior to flight. 86 Chapter Four · Cyber Activities in the Aviation Sector <?page no="87"?> 3 ENISA Threat Landscape: Transport Sector ( January 2021 to October 2022), March 2023. A map with a selection of recent cyber security breaches in the aviation sector can be found at the European Air Traffic Management Computer Emergency Response Team (EATM-CERT), 🔗 https: / / www.google.com/ maps/ d/ embed? mid=1ptVIma0CZqoPiN -zsomzbRVQDRS7BXGk&ll=22.434633202655892%2C0&z=2 (accessed March 2026) 4.1.2 Vulnerabilities and Threats 4.1.2.1 Vulnerabilities Ground-based networks connected to aviation safety and non-safety func‐ tions pose numerous vulnerabilities. The possibility of integrating aircraft systems into networks has the potential of aggravating this situation. IP-based networks and signal protocol commonality facilitate unauthorised cyber activities against computer systems used for aviation safety and non-safety purposes. Increasing connectivity among actors in the aviation industry from aircraft operators, airports, air navigation service providers, developers, manufacturers and maintainers enlarge the number of weak spots. They increase vulnerabilities through the design, supply and service chains. Commercial off-the-shelf (COTS) electronic components in the aviation sector render the exploitation of hardware vulnerabilities and backdoors possible. As a matter of communication security - different to cyber security-, radio links between aircraft and the ground have traditionally been a potential vulnerability for unauthorised activities. Increasing dependency on radio links for data streams to and from aircraft add new complexity and vulnerability. Aircraft wireless communication, navigation and surveillance functions are not cyber activities, but they can be jammed and spoofed. 4.1.2.2 Threats Like in other sectors, the motivation of unauthorised actors determines their methods and targets. They do not exploit every vulnerability, but those which are suitable and easily achievable for their purpose. Numerous unauthorised cyber activities attempt to target the aviation sector every day. The ENISA Threat Landscape of 2023 3 helps to realistically portray the types of threats and their targets in the aviation sector. Most unauthorised cyber activities in aviation target non-safety applications of airlines, airspace users and airports. In the years 2021 and 2022 data breaches amounted to 43 % and ransomware to 36 % with a significant 4.1 Cyber Security in the Aviation Sector 87 <?page no="88"?> 4 ENISA Threat Landscape: Transport Sector, id., pages 26, 27. 5 ENISA Threat Landscape: Transport Sector, id., pages 27, 28. 6 ENISA Threat Landscape: Transport Sector, id., page 28. overlap of these two categories. A main target were computer systems of airlines or of their service providers holding passenger personal and financial data. For example, from the system of the airline passenger service provider SITA, hundreds of thousands passenger data were extracted (March 2021); a data breach at Air India compromised the data of 4.5 million customers (May 2021); Bangkok Air suffered a leak of passenger data after a ransomware attack (August 2021); ransomware led to hundreds of stranded passengers of SpiceJet in India (May 2022); passenger data of TAP Air Portugal were leaked after a ransomware attack (August 2022). 4 The pattern of these unauthorised cyber activities shows the actors’ motivation of personal gain. Victims are also individuals whose personal data were compromised. Ransomware attacks and data breaches do not only relate to passenger and customer data, but also to commercial, technical information and personal information of staff. Examples of such activities were ransomware attacks against the French manufacturer Dassault ( January 2022), Swissport International (February 2022), the French defence and technology group Thales Group (October 2022), the US aerospace and defence company Genesys Aerosystems (October 2022) and a data breach of 6.5 Terabyte at Turkish Airlines affecting flight and crew information (May 2022). 5 Ideological interest groups, hacktivists and increasingly State sponsored, supported or tolerated actors use Directed Denial of Service attacks (DDoS) to disrupt and delay air traffic. Examples in 2022 were DDoS attacks against the Israel Airport Authority (April 2022) and pro-Russian actors who launched DDoS attacks against Italian ministries and airports (May 2022), against Lithuanian airports (by group NoName057, June 2022), against Bratislava, Budapest and Bulgarian airports (October 2022) and against major U.S. airports (by group Killnet, October 2022). 6 Industrial espionage can take the form of data breaches against com‐ puter systems which hold intellectual property. Victims in the aviation sector are aircraft designers, operators, maintainers and organisations of the supply and design chain. They are often also part of the defence industry, which can make them a target of State sponsored or supported cyber activities. Due to reasons of national security, many cases are not disclosed 88 Chapter Four · Cyber Activities in the Aviation Sector <?page no="89"?> 7 Sydney J. Freedberg Jr., Top Official Admits F-35 Stealth Fighter Secrets Stolen, 20 June 2013, Breaking Defense, 🔗 https: / / breakingdefense.com/ 2013/ 06/ top-official-ad mits-f-35-stealth-fighter-secrets-stolen/ , (accessed March 2026; Jacob Appelbaum et.al., NSA Preps America for Future Battle, Der Spiegel 17 January 2015, 🔗 https: / / www .spiegel.de/ international/ world/ new-snowden-docs-indicate-scope-of-nsa-preparation s-for-cyber-battle-a-1013409.html (accessed March 2026). 8 Sally Miles, Did China Steal F-35 Technology The Investigation Explained, TechGain, 29 September 29, 2025, 🔗 https: / / techgain.co.uk/ did-china-steal-f-35-technology-the -investigation-explained/ (accessed March 2026). 9 Federal Aviation Administration, Review of Web Applications Security and Intrusion Detection in Air Traffic Control Systems, Report Number: FI-2009-049, 4 May 2009. or their impact is denied. A prominent case of industrial espionage was the data compromise at manufacturer Lockheed Martin connected to the design of their fifth generation F-35 stealth fighter jet. It became publicly known in 2009. Leaked US documents attribute it to Chinese hackers (code-named Byzantine Hades). 7 The design of the Chinese Chengdu J-20 and Shenyang FC-31 fighter aircraft show great similarity to the F-35 regarding the overall appearance, canopy, weapons bay, radar absorbent materials and pilot interfaces with helmet displays. 8 Unauthorised cyber activities against aviation safety-relevant sys‐ tems and networks are an exception. One may conclude that security measures are sufficiently high for aviation-safety systems, but their po‐ tentially severe impact deserves continuous vigilance and improvement. For example, the air traffic control systems in Alaska experienced an early well-known security breach in 2006. With a viral attack from the internet against an administrative network of the US Federal Aviation Administration (FAA) unauthorised actors obtained information used to control a portion of the FAA mission-support network. The FAA was forced to shut-down part of their air traffic control system in Alaska. 9 This example shows that mission safety systems and information should be strictly separated from non-safety administrative systems. Public organisations like ENISA did not report any known unauthorised cyber activities during recent years which intruded or obstructed flight control of aircraft. Jamming and spoofing of Global Navigation Satellite Systems (GNSS) have become common practice. GNSS like the US GPS or the Euro‐ pean Galileo systems are often spammed or spoofed as defensive measures during armed conflicts. GNSS are not aviation specific radio navigation systems, but aviation heavily relies on them. Jamming and spoofing of GNSS signals are a matter of communication security. Both techniques do not fall 4.1 Cyber Security in the Aviation Sector 89 <?page no="90"?> 10 See supra 1.3.2.2, 1.3.2.3. 11 For an updated map of worldwide GPS jamming and spoofing, see SkAI Data Services, Real-time detection of GPS spoofing and jamming, 🔗 https: / / gpswise.aero/ (accessed March 2026) 12 Convention on International Civil Aviation, supra note 1, Arts. 37, 38, 54 (l), 90. under cyber activities because they are not affected through a network. GNSS signals are intentionally blocked through emissions of radio signals (jamming) or manipulated signals are transmitted for causing aircraft to deviate from their routes (spoofing). 10 During recent armed conflicts, GNSS signals were jammed around the conflict zones for preventing adversaries to use GNSS signals for precision targeting. The positions of civil aircraft in and around conflict zones are spoofed to mimic false positions for adversary surveillance. From 2022, during the Russian - Ukrainian war, jamming of GNSS signals extended to the Baltic States, Poland and sometimes to eastern parts of Germany. 11 4.1.3 Legal Sources and Approaches 4.1.3.1 International Civil Aviation Organisation Standard setting for international civil aviation is a central function of the International Civil Aviation Organisation (ICAO). The ICAO Council has the authority to adopt international standards and (non-binding) recommended practices, groups of which are designated for convenience as Annexes to the Convention. ICAO contracting States undertake to implement international ICAO standards as their national regulations and practices but need to notify ICAO in case of differences. 12 Most ICAO Annexes relate to the safety of civil aviation. However, Annex 17 contains international standards and recommended practices for the security of civil aviation against human made threats. Standard 4.9.1 of Annex 17 addresses measures relating to cyber threats: “Each Contracting State shall ensure that operators or entities as defined in the national civil aviation security programme or other relevant national documentation identify their critical information and communications technology systems and data used for civil aviation purposes and, in accordance with a risk assessment, develop and implement, as appropriate, measures to protect them from unlawful interference.” 90 Chapter Four · Cyber Activities in the Aviation Sector <?page no="91"?> 13 ICAO Doc. 8973---Restricted, chapter 18 for cyber security. 14 ICAO Doc. 10213 — Restricted, unrestricted Doc. 10213 extract. 15 ICAO Aviation Cybersecurity Strategy, endorsed during the 40th Session of the ICAO Assembly, 2019, with the pillars: international cooperation, governance, effective legis‐ lation and regulations, cyber security policy, information sharing, incident management and emergency planning, capacity building, training and cybersecurity culture. 16 ICAO Cybersecurity Action Plan, 2 nd ed. January 2022. The scope of this standard comprises cyber, information and communication security for systems and data used for civil aviation. This standard requires relevant entities to identify critical systems and data, to undertake a risk assessment and to carry out appropriate protection measures. It is left up to States to define in their national aviation security programmes which entities fall under this requirement. Recommended Practice 4.9.2 of Annex 17 adds slightly more detail: “Each Contracting State should ensure that the measures implemented protect, as appropriate, the confidentiality, integrity and availability of the identified critical systems and/ or data. The measures should include, inter alia, security by design, supply chain security, network separation, and the protection and/ or limitation of any remote access capabilities, as appropriate and in accordance with the risk assessment carried out by its relevant national authorities.” Following the general line of cyber security standards, this recommendation mentions risk assessment and the triad of confidentiality, integrity and availability. The protection measures put an emphasis also on security by design, network separation and limited remote access. Security standards and recommended practices in Annex 17 remain generic. The reason behind is the sensitive nature of dynamically updated protective measures against human made threats. The distribution of infor‐ mation about more specific security measures and guidance is restricted to aviation security stakeholders. More specific, but restricted, guidance to ICAO Annex 17 is contained in the ICAO Aviation Security Manual. 13 In addition, the restricted ICAO Global Cyber Risk Considerations 14 focus on methodology to integrate cyber risks into aviation risk management and on the global cyber threat and risk landscape. As a policy document, the ICAO Aviation Cybersecurity Strategy reiterates seven general cyber security pillars for a framework to protect civil aviation. 15 The ICAO Cybersecurity Action Plan 16 elaborates on these pillars and specifies measures and tasks, indicators and priorities. Among 4.1 Cyber Security in the Aviation Sector 91 <?page no="92"?> 17 ICAO Cybersecurity Action Plan, id., 8.1, 8.2. 18 ICAO Cybersecurity Action Plan, id., 10.1 - 10.3. 19 ICAO, Cyber Information Sharing, version 1, 2024. 20 ICAO, Cybersecurity Culture in Civil Aviation, January 2022. 21 ICAO Cybersecurity Action Plan, supra footnote 16, 6.1, 6.3. 22 ICAO Cybersecurity Action Plan, id., 7.1-7.4. For Beijing Convention and Protocol see infra. 4.2. 23 Regulation (EU) 2018/ 1139 of the European Parliament and of the Council of 4 July 2018 on common rules in the field of civil aviation and establishing a European Union Aviation Safety Agency. them are generally known cyber security concepts adjusted to civil aviation, like the elaboration of cyber security policies including the identification of cyber-risks to civil aviation. 17 Other adopted concepts of the Cyberse‐ curity Action Plan are incident response capabilities, emergency response planning, incident detection, analysis and response and the development of a crisis coordination cell for civil aviation cyber security. 18 ICAO has furthermore worked out details on information sharing 19 and on behavioural and personnel management aspects. 20 From a legal perspective it is worth noting that the Cybersecurity Action Plan refers to accountability in the context of a governance structure. 21 Moreover, the Action Plan foresees to review existing international air law instruments as they relate to cyber security, to keep ICAO provisions aligned with cyber security needs, to encourage States to ratify the Beijing Convention and Protocol and to formulate appropriate national rules and regulations. 22 The generic wording of ICAO standard 4.9.1 together with numerous guidance and explanatory material leave States a wide margin of discretion for implementation into national regulation and practice. 4.1.3.2 European Union and European Union Aviation Safety Agency In the European Union, the European Union Aviation Safety Agency (EASA) has the role of ensuring aviation safety and environmental protection through common rules in EU Member States. From a public international law perspective, EASA harmonizes the implementation of ICAO standards in the Member States. EASA was established by the so-called Basic Regulation (EU) 2018/ 1139 on common rules in the field of civil aviation. 23 In its 92 Chapter Four · Cyber Activities in the Aviation Sector <?page no="93"?> 24 Regulation (EU) 2018/ 1139, id., Article 4.1. (d) 25 Regulation (EU) 2018/ 1139, id., Article 88.1. 26 Commission Delegated Regulation (EU) 2022/ 1645 of 14 July 2022 laying down rules for the application of Regulation (EU) 2018/ 1139 … as regards requirements for the management of information security risks with a potential impact on aviation safety, Articles. 1, 2.1. 27 Regulation (EU) 2022/ 1645, id., Articles 2.2. 28 Regulation (EU) 2022/ 1645, id., Annex Information Security - Organisation Require‐ ments, PART-IS.D.OR 200-260: Information security management systems, risk assess‐ ment and treatment, internal and external reporting scheme, information security incidents - detection, response, and recovery, response to findings notified by authority, contracting of information security management activities, personnel requirements, record-keeping, information security management manual, changes and continuous improvement of information security management system. current version, the Basic Regulation expressly refers to the role of the EU Commission, EASA and the Member States in cyber security: “1. When taking measures under this Regulation the Commission, the Agency and the Member States shall: …. (d) take into account interdependencies between the different domains of aviation safety, and between aviation safety, cyber security and other technical domains of aviation regulation”  24 “The Commission, the Agency and the Member States shall cooperate on security matters related to civil aviation, including cyber security, where interdependencies between civil aviation safety and security exist.”  25 With this mandate of the Basic Regulation, EASA can harmonize civil aviation security regulations, when they affect the safety of civil aircraft and their flight. However, this role does not include security matters which merely influence the regularity, efficiency or economy of the aviation sector. Regulation (EU) 2022/ 1645 establishes requirements for production and design organisations, aerodrome operators and apron management service providers to identify and manage information security risks with poten‐ tial impact on aviation safety. 26 The term ‘information security’ extends the scope of the regulation beyond cyber security, provided there is a potential impact on aviation safety functions. As lex specialis, Regulation (EU) 2022/ 1645 is without prejudice to information security and cyberse‐ curity requirements established by more general EU regulations. 27 The organisational requirements of the civil aviation specific Regulation (EU) 2022/ 1645 resemble measures of the general information security toolbox. 28 4.1 Cyber Security in the Aviation Sector 93 <?page no="94"?> 29 Commission Implementing Regulation (EU) 2023/ 203 of 27 October 2022 laying down rules for the application of Regulation (EU) 2018/ 1139 … as regards requirements for the management of information security risks with a potential impact on aviation safety. This regulation covers under Art. 2.1: maintenance organisations, continuing airworthiness management organisations (CAMO), air operators, approved training organisations (ATOs), aircrew aero-medical centres, flight simulation training device (FSTD) operators, air traffic controller training organisations, U-space service providers, single common information service providers. 30 Commission Implementing Regulation (EU) 2015/ 1998 of 5 November 2015 laying down detailed measures for the implementation of the common basic standards on aviation security, as amended by Commission Implementing Regulation (EU) 2019/ 1583 of 25 September 2019, 11.7, 11.1.2, 11.2.8. 31 EASA Executive Director Decision ED 2020/ 006/ R of 24 June 2020, preamble (17). Regulation (EU) 2023/ 203 imposes these organisational information security requirements on more organisations with a potential impact on aviation safety. 29 Apart from aviation safety, Regulation (EU) 2025/ 1998 on aviation security requires airport operators, air carriers and entities defined in national civil aviation security programme to identify and protect critical information and communications technology systems and data from cyber-attacks, and to background-check and train personnel. 30 The EASA (Executive Director) Decision 2020/ 006/ R entitled ‘aircraft cybersecurity’ goes beyond behavioural, operational and organisational cyber security aspects. It makes technical cyber security measures part of the certification process of aircraft and components: “Since aircraft systems are increasingly interconnected, and thus potentially vulner‐ able to security threats, EASA needs to consider state-of-the-art means of protection against these threats when certifying new products or new parts.“  31 Recognizing the security threats from interconnection of communication and information aircraft systems, this EASA decision amended the certifica‐ tion specifications and acceptable means of compliance itemized by aircraft and part categories. As an example, the certification specifications for large aeroplanes (CS-25), section 1319 (a) reads: “Aeroplane equipment, systems and networks, considered separately and in relation to other systems, must be protected from intentional unauthorised electronic inter‐ actions (IUEIs) that may result in adverse effects on the safety of the aeroplane. Protection must be ensured by showing that the security risks have been identified, assessed and mitigated as necessary.” 94 Chapter Four · Cyber Activities in the Aviation Sector <?page no="95"?> 32 EASA Certification Standard 25.1319 (b). 33 See supra 3.6. 34 Directive (EU) 2022/ 2555 of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS2), Art. 4.2. 35 Directive (EU) 2022/ 2555, id., Articles 2.1, 2.2, Annex I 2.(a). 36 European Civil Aviation Conference (ECAC), Doc. 30 (Security), part II, chapter 14, Restricted. 37 For example: International Air Transport Association (IATA), Aviation Cyber Security Guidance Material, ed.1, February 2021 38 For example: Airports Council International (ACI), Cybersecurity Incident Response Guidelines White Paper, First Edition. The scope of this provision is limited to security breaches that effect the safety of certified aircraft. It is technology neutral and leaves it to the dis‐ cretion of manufacturers and operators which appropriate state-of-the-art protections to take. This protective requirement is expanded to Continued Airworthiness so that technical measures for aircraft equipment, systems and networks are also maintained against new emerging unauthorised methods of electronic interactions. 32 These amendments, while unspecific, show the different nature of security standards as opposed to safety stand‐ ards. 33 The NIS2 Directive and its implementations to national law apply only subsidiarily to the aviation sector in the European Union. Aviation sector-specific Union legal acts for information and cyber security under Basic Regulation (EU) 2018/ 1139 take priority. 34 The NIS2 Directive applies to public or private entities of sectors of high criticality of a certain size. It lists air carriers, airport managing bodies and operators of air traffic control services as part of the highly critical traffic sector. 35 The NIS2 Directive can apply to other entities of the aviation sector for functional areas without potential impact on aviation safety. 4.1.3.3 Other Regulations, Standards and Guidance Several organisations of the aviation sector have established standards or guidance to cyber and information security, for example at the regional level. 36 These sets of provisions are often aviation-oriented adaptions of general cyber and information security standards like the ISO 27000 series. Depending on the issuing organisation, they relate to air carriers, 37 airports 38 4.1 Cyber Security in the Aviation Sector 95 <?page no="96"?> 39 For example: Civil Air Navigation Services Organisation (CANSO), Standard of Excel‐ lence in Cybersecurity, September 2020; Eurocontrol, ATM Cyber Security Maturity Model, September 2019; European Standards, EN 16495, Air Traffic Management. Information security for organisations supporting civil aviation operations, July 2019, European Organisation for Civil Aviation Equipment (EUROCAE), ED-205A, Process Standard for Security Certification and Declaration of ATM ANS Ground Systems, July 2022. 40 For example: Radio Technical Commission for Aeronautics (RTCA), DO-326A, Airwor‐ thiness Security Process Specification, August 2014; DO-356-A, Airworthiness Security Methods and Considerations, June 2018; EUROCAE ED-202A, Airworthiness Security Process Specification, June 2014; ED-203A, Airworthiness Security Methods and Con‐ siderations, June 2018; Aeronautical Radio Incorporated (ARINC), Specification 823 P1/ P2, Data Link Security, December 2007 / March 2008; ARINC Report 852, Guidance for Security Event Logging in an IP Environment, June 2017. or air navigation services providers. 39 A few technical organisations provide specific technical security guidance to the aviation sector more broadly. 40 It is difficult to maintain an overview of this fragmented landscape of source documents. This fragmentation is a result of voluntary certification schemes and of the wide margin of discretion regulators have granted actors in the aviation sector to assure their compliance with cyber security requirements. 4.2 Criminal Liability Criminal liability can be linked to security violations. It falls under the prerogative of national legislatures to enact criminal law for security violations that surpass a defined threshold of severity and culpability. Since many decades, acts against the safety of civil aviation have not only been addressed through preventive instruments like ICAO Annex 17, but also by international conventions on criminal air law. These conventions establish a common international ground for national criminal laws relating to unlawful seizure of aircraft or unlawful acts against the safety of civil aviation. Recognizing the prescriptive jurisdiction of States in the field of criminal law, these conventions have no directly binding effect and require implementation into national criminal law through the national legislative process. Criminal offences cannot substitute preventive security rules. They supplement them with the purpose of penalizing unlawful and guilty offenders. Older criminal air law instruments were drafted in times before cyber activities existed. The elements of criminal offences defined in these instru‐ 96 Chapter Four · Cyber Activities in the Aviation Sector <?page no="97"?> 41 Convention for the Suppression of Unlawful Acts against the Safety of Civil Aviation, Montreal, 23 September 1971, 974 UNTS 177. 42 Montreal Convention 1971, id., Article 1 d), e). 43 Convention on the Suppression of Unlawful Acts Relating to International Civil Aviation, Beijing, 10 September 2010 ICAO Doc. 9960. ments can be applied to unauthorised cyber activities only, when they are worded broadly. This is the case of Article 1 b) of the Montreal Convention of 1971: “Any person commits an offence if he unlawfully and intentionally … destroys an aircraft in service or causes damage to such an aircraft which renders it incapable of flight or which is likely to endanger its safety in flight”.  41 This language does not specify the method of the unlawful and intentional activity. An intentional unauthorised cyber activity qualifies, provided it meets the effects: the destruction of or damage to an aircraft which renders it incapable of flight or endangers its flight safety. This construct of the Montreal Convention of 1971 establishes a factual threshold for criminal liability of unauthorised cyber activities: business interruption or economic losses in the aviation sector do not lead to criminal liability under this convention. Moreover, the Montreal Convention provides some more specific wording considering technology and information used already in 1971: “Any person commits an offence if he unlawfully and intentionally … d) destroys or damages air navigation facilities or interferes with their operation, if any such act is likely to endanger the safety of aircraft in flight; or e) communicates information which he knows to be false, thereby endangering the safety of aircraft in flight.”  42 These criminal offences relate to breaches of communication and informa‐ tion security which endanger the safety of aircraft in flight. Air navigation facilities support wireless aeronautical communication, navigation and sur‐ veillance services in voice and data formats. Likewise, the term ‘information’ can be interpreted to comprise modern data communication. The Beijing Convention of 2010 43 provides further clarification. It consolidates and restates the cited offences of the Montreal Convention of 1971. For this purpose, it defines the term ‘air navigation facilities’ to include “signals, data, information or systems necessary for the navigation of the 4.2 Criminal Liability 97 <?page no="98"?> 44 Beijing Convention 2010, id., Article 2 (c). 45 Protocol Supplementary to the 1970 Hague Convention for the Suppression of Unlawful Seizure of Aircraft, Beijing, 10 September 2010, ICAO Doc. 9959. 46 Protocol Supplementary to the 1970 Hague Convention, id., Art. II, which replaces Art. 1 of the Convention for the Suppression of Unlawful Seizure of Aircraft, The Hague, 16 December 1970, 860 UNTS 105. The scope of Art. 1 of the 1970 Hague Convention was limited to offenders on board who seize or exercise control of that aircraft. 47 Convention for the Unification of Certain Rules Relating to International Carriage by Air, Warsaw, 12 October 1929, 137 LNTS 11 (Warsaw Convention), modernized by the Convention for the Unification of Certain Rules for International Carriage by Air, Montreal 28 May 1999, 2242 UNTS 309 (1999 Montreal Convention). aircraft”. 44 This definition indicates air navigation facilities can encompass systems which use digital and networked signals and data. The Beijing Supplementary Protocol of 2010 45 reflects more directly that advancing technology can be used to commit criminal acts against the control and thus the safe operation of aircraft: “Any person commits an offence if that person unlawfully and intentionally seizes or exercises control of an aircraft in service by force or threat thereof, or by coercion, or by any other form of intimidation, or by any technological means.”  46 The term ‘by any technological means’ is technology neutral. It comprises unauthorised cyber activities undertaken through networks breaches of communication or information security, also from the ground, with the effect of seizing or exercising control of an aircraft in service. 4.3 Private Liability Private air liability applies after damage has occurred, also when damage was caused by a security breach. Like criminal air liability, private air liability is reactive in nature, and it does not substitute preventive aviation security standards and rules. The so-called Warsaw/ Montreal system 47 provides for compensation by the air carrier for death or injury of passengers, damage or loss of baggage and damage or loss of cargo, caused by accidents during international air carriage. More specifically, Article 17.1 of the modernized text of the Montreal Convention (1999) on death or injury of passengers reads: “The carrier is liable for damage sustained in case of death or bodily injury of a passenger upon condition only that the accident which caused the death or injury 98 Chapter Four · Cyber Activities in the Aviation Sector <?page no="99"?> 48 With the possibility to exonerate themselves for damages exceeding a limit (adjusted from time to time) per passenger, when they prove the damages were not due to their negligence or solely due to the negligence of a third party; 1999 Montreal Convention, id., Article 21. took place on board the aircraft or in the course of any of the operations of embarking or disembarking.” This clause is intended to offer a broad protection of passengers on board aircraft without restricting the root causes of the accident. It establishes private liability of air carriers also for third party security violations, including unauthorised cyber activities, that result in the death or injury of passengers during flight. What appears modern and farsighted, has its downsides. Air carriers bear the burden of private liability for unauthorised cyber activities in relation to passengers. 48 Fortunately, no cases of aircraft accidents with death or injury of passengers are so far known as result of unauthorised cyber activities. 4.4 Remarks Although cyber threats against aviation-safety functions are currently very limited, a trend is visible of giving up technological independence in this field. For many years, aviation electronics was not inter-operable with non-aviation systems. Specialized electronics for aviation automation is replaced today by IP-based networks and commercial off-the-shelf (COTS) hardware. For preventing the exploitation of IP-based network and COTS vulnerabilities, technical measures need to be taken like in other sectors. The price for the technical and financial benefits of IP-based interconnection and COTS is stronger dependence on continuously updated technical cyber security measures. It is a plausible step to make technical cyber security measures part of aircraft certification as in EASA Decision 2020/ 006/ R and related certifica‐ tion specifications. However, the large margin of discretion for choosing a specific technical cyber security measures under this EASA decision complicates the decision making of aircraft designers and manufacturers. As it looks, aircraft designers and manufactures will not step back using COTS electronic components for aviation safety-critical functions. 4.4 Remarks 99 <?page no="100"?> Despite the increasing use of IP-based interoperability, network intercon‐ nection for aircraft systems should be limited and secured to the highest extend possible. Secured connectivity between aircraft and air traffic man‐ agement, especially air traffic control requires special attention. Aviation safety and non-safety functions need to be separated. Given the overall security situation, like in other sectors, organisations in the aviation sector go for a holistic approach by taking measures to assure cyber, information, communication and physical security. As a matter of communication security, GNSS jamming and spoofing have a special impact on aviation. This vulnerability should be addressed by ensuring redundancy and diversity of radio navigation systems on aircraft and on the ground infrastructure side. 100 Chapter Four · Cyber Activities in the Aviation Sector <?page no="101"?> Chapter Five · Cyber Activities in the Space Sector From its beginning, space operations have been dependent on wireless remote control. In the United States the moon programme of the 1960s was a catalyst for the development from vacuum tubes to solid-state electronics and from analogue to digital computing. The Apollo moon program introduced digital fly-by-wire control and computer guidance systems. Hardware development was complemented by dedicated soft‐ ware, data management and the integration of systems. At this time, space flight electronics were applications specific equipment at high cost. From space operations it found its way to aviation, later to industrial applications. Today it is commonplace in business, domestic and personal use. 5.1 Cyber and Communication Security in the Space Sector The space sector is dependent on digital data, systems and networks like any other sector. With the evolution of systems and networks from dedicated technology and signal protocols to interoperable IP-based formats, cyber security becomes indispensable for the operation of spacecraft. Cyber security must likewise be assured for payload applications of spacecraft and supporting system elements on the ground. Besides cyber security, communication security becomes a separate pillar for assuring secure wireless signal connections among spacecraft and ground stations. 5.1.1 Technical Background For space operations, the space and the ground segments must be distin‐ guished. The space segment consists of the launch vehicle, the spacecraft and its payload. The launch vehicle launches spacecraft into Earth orbits, or onto trajectories to other celestial bodies or deep space. Launch vehicles typically consist of various stages, some of which remain in outer space after placing spacecraft on their orbit or trajectory. Spacecraft are the flight <?page no="102"?> 1 For more details of space system segments, see Klaus Wittmann, Nicolaus Hanowski, 1.2 Space Missions in: Wilfried Ley et. al., Handbook of Space Technology, Wiley, London, 2009. 2 For more details of satellite communications, see Hans Dodel, 7.2 Communications, in: Wilfried Ley, et. al., id. vehicles which carry payloads. They consist of a mechanical structure, also called ‘bus’, power supply, thermal subsystem, attitude control, communi‐ cations, data processing and propulsion. Spacecraft provide payloads with energy and enable them to keep the position and orientation required for their mission. Spacecraft are designed to serve as suitable platforms for the needs of each individual payload. 1 Payloads are the application element of space missions. Aside from the small number of space missions which carry humans, there are three main space applications: communication, remote sensing and navigation. Initially, satellite communications of telephone and television was un‐ dertaken as fixed satellite service only: A geostationary telecommunications satellite positioned quasi-stationary at 36.000 kilometres above a fixed point over the Earth’s equator, for example over the Atlantic, served as a relay station between ground stations in Europe on one side, and America on the other. The large distance between the surface and the satellite requires large antennas at the ground. Each radio connection needs two wireless paths. One from a sending ground station up to the satellite (uplink) and one down to the receiving ground station (downlink). Geostationary communication satellites have a large area of coverage. One satellite can serve fixed satellite services between two continents. Technical disadvantages are the large size of ground-based antennas and time delays for transmissions. Mobile satellite services provide direct wireless connections between smaller mobile units and communication satellites. Satellites need to be closer to the Earth for receiving signals from small mobile units with weaker signal output than from larger ground station antennas. Communication satellites in low Earth orbits below 2000 kilometres have smaller areas of coverage on the ground. For achieving wide area or global coverage of mobile satellite services, constellations with up to tens of thousands of satellites are currently set up in low earth orbits. 2 No more than about three percent of global telecommunications is routed through satellite connections. More than 97 percent of intercontinental tele‐ communications currently use cables on land or the ocean floor, increasingly with fibre-optics. 102 Chapter Five · Cyber Activities in the Space Sector <?page no="103"?> 3 For more details of remote sensing, see Klaus Dieter Reiniger, Gunter Schreier, 7.1 Earth Observation, in Wilfried Ley, id. 4 Four global navigation satellite systems are in operation: The Global Positioning System (GPS) of the U.S., GLONASS of the Russian Federation, Galileo of the European Union and BeiDou of China. 5 For more details on satellite navigation, see Stefan Sassen, 7.3 Navigation, in: Wilfried Ley, supra note 1. Satellite remote sensing requires other types of payloads. Satellite remote sensing serves Earth observation for purposes like climate, weather, environment, agriculture, disaster management and national security. Key elements of remote sensing payloads are sensors which pick up emitted or reflected electromagnetic waves of diverse portions of the spectrum. The payload transmits data of sensor measurements to ground stations. 3 Global satellite navigation is performed by constellations of about 20 to 30 satellites typically in medium high orbits at about 20,000 kilometres. 4 Navigation payloads of each satellite of the constellation broadcast position messages from accurately known orbital positions together with highly ac‐ curate timing messages. The timing messages are generated by synchronized onboard atomic clocks. The calculation of a user position is not performed by the payloads in outer space, but by user units with a method called multi-lateration. User units are multichannel receivers. They simultaneously receive the broadcast messages of many navigation satellites. They process the known position of the origin of the signal and the time difference of the received signals. The time difference is the result of the different distances messages travel from the satellites to a user unit. With the known position of and the distance to at least four satellites, the user unit can calculate its three-dimensional position. 5 The ground segment complements the space segment. It consists of control centres and ground station networks with antennas. Different con‐ trol centres execute different functions for flight operations and payloads respectively. Control centres for flight operations exercise command and control functions for spacecraft. They transmit command signals and control the spacecraft regarding flight dynamics, manoeuvring and station keeping. They monitor telemetry of power, temperature and attitude. The ground segment for communication payloads transmits and receives the signals of users and connects them to terrestrial landline and wireless communication networks. The ground segment for remote sensing payloads consists of the data reception through station networks, data libraries 5.1 Cyber and Communication Security in the Space Sector 103 <?page no="104"?> and some level of pre-processing which converts raw data to value added information products. The products are subsequently distributed to users, typically via networks. The ground mission segments of navigation satellites systems have another role. They control and monitor the accuracy and integrity of the broadcast navigation signals. Monitoring is accomplished through a larger network of sensor stations. Based on the monitoring inputs, adjustments of orbit and clock data are sent to each navigation payload, for maintaining the accuracy of the system within defined tolerances. The Role of Communications and Networks Networked communication is an indispensable part of space operations. Infrastructure for flight control and payload control can be integrated into existing ground-based networks. Networks of the space sector have been migrating from specialized signal protocols to Internet Protocol-based (IP) networks, and from proprietary hardware to commercial off-the-shelf (COTS) products. This applies also to flight control communications, so called Telemetry, Tracking and Command (TTC). Due to older still operating space segments, networks for TTC are often of a hybrid structure. TTC for legacy mission can be encapsulated and transmitted through IP-based networks. The ground segment for communication payloads is the connecting element to communication networks. As a matter of its functionality, it is connected to existing ground-based communication networks. It is designed for large data throughputs. Also ground based data centres of remote sensing are typically connected to public communication networks. Networks in the space sector cover more than the ground-segments for flight and payload control. Like other industries, the space sector is a highly diversified industry with contracted service providers and large supply chains. Services for flight and payload can be outsourced and provided via networks by third party specialists. Organisations use networks during the development and pre-launch phase of space flight hardware. Organisations like space agencies operate administrative networks, not directly connected to space flight operations. Wireless communication links between the space and ground segments for flight and payload control play a central role in space operations. Intersatellite links among communication satellites of large constellations increasingly use optical communications with modulated lasers. 104 Chapter Five · Cyber Activities in the Space Sector <?page no="105"?> 6 See supra 1.3.1.1, 1.3.2.2, 1.3.2.3. 5.1.2 Vulnerabilities and Threats 5.1.2.1 Vulnerabilities Unauthorised cyber activities through connected ground networks can affect flight control and payload systems. Manipulation of flight control, or more precisely of telemetry, tracking and command, can physically seize, misroute or damage a spacecraft and possibly cause physical damage to third parties in outer space or on Earth. Unauthorised intrusion of payload systems can lead to disruption, access to or manipulation of satellite communications or remote sensing data. Communication security is likewise important for space operations as cyber security. Due to their physical properties, wireless links between ground and space segments can be subject to harmful radio interference and disruption of connections. Unless encryption is applied, the confidentiality of information transmitted over wireless radio links between ground and space segments can be compromised. Jamming and spoofing of radio signals, just like tapping into radio signals, are not cyber activities as defined in this book, because they are non-networked activities. 6 Jamming of satellite links and tapping into their content require radio equipment like antennas, transmitters and receivers. This equipment can look like a satellite ground station. More recently, manoeuvres of certain satellites in the geostationary region led to the suspicion they position their antennas for tapping into radio links of communication satellites. Jamming and spoofing of Global Navigation Satellite Systems (GNSS) are an inherent vulnerability, due to the low signal strength of the navigation and timing signals. As can be seen in recent armed conflicts, jamming and spoofing of navigation signals has become a common practice with effects also beyond the territory of parties to the conflict. 5.1.2.2 Threats There is only limited visibility of cyber, communication and information security breaches in the space sector. The ENISA report on the space threat 5.1 Cyber and Communication Security in the Space Sector 105 <?page no="106"?> 7 ENISA, Space Threat Landscape, March 2025, 🔗 https: / / www.enisa.europa.eu/ public ations/ enisa-space-threat-landscape-2025 (accessed March 2026) 8 ENISA, Space Threat Landscape, id., p.-30. 9 OPSGROUP, GPS Spoofing, Final Report of the GPS Spoofing Working Group, 6 September 2024, 🔗 https: / / ops.group/ dashboard/ wp-content/ uploads/ 2024/ 09/ GPS-S poofing-Final-Report-OPSGROUP-WG-OG24.pdf (accessed March 2026) 10 Windward, Middle East on the Precipice: GPS Jamming in the Arabian Gulf and Strait of Hormuz Disrupts 970 Ships Daily, 19 June 2025, 🔗 https: / / windward.ai/ blog/ middle -east-on-the-precipice-gps-jamming-in-the-arabian-gulf-and-strait-of-hormuz-disrupt s-970-ships-daily/ (accessed March 2026) 11 In aviation, GNSS signals are used to generate surveillance data transmission, so called Automatic Dependent Surveillance (ADS). In shipping the same is achieved through Automatic Identification System (AIS). 12 See also supra 4.1.2.2. landscape of 2025 lists trends of threats. 7 According to ENISA’s assessment, jamming of radio signals to and from satellites was the most frequent threat, for example jamming of GNSS signals. Another frequent category was Computer Network Exploitation (CNE), which means unauthorised collection of data from digital systems and networks. Far less frequent were unauthorised activities against (flight or payload) control functions. 8 It is difficult to quantitively assess the impact of GNSS jamming and spoofing on users. Jamming and spoofing do not affect the payload of nav‐ igation satellites. They deny or degrade navigation radio signals receivable by a non-quantifiable number of users. Continuous and systematic jamming and spoofing in wide areas around conflicts zones in Russia/ Ukraine and the Middle East affect users since 2023 on a daily basis. During August 2024, a total of 41,000 aircraft experienced spoofing, up to 1500 flights were impacted per day. 9 Between 15 and 18 June 2025 an average of 972 ships per day experienced GPS jamming in the Arabian Gulf and the Strait of Hormuz. 10 Denied or degraded GNSS signals impact other functionalities in aviation and shipping, for example surveillance. 11 As a high-tech industry, the space sector is vulnerable to unauthorised collection of data from digital systems and networks for industrial and State espionage. The aerospace industry, with an overlap in the areas of aviation and military, can be victim of these unauthorised cyber activities. 12 Not all cases become publicly known. The following data breaches at space agencies, research and operations centres serve as examples: An online intruder stole secret data of Delta and Atlas rocket engines at the Marshall Space Flight Center (2002). Unauthorised cyber activities, suspected of Chinese origin, against US defence and aerospace installations 106 Chapter Five · Cyber Activities in the Space Sector <?page no="107"?> 13 For all cases, see Jason Fritz, Satellite hacking: A guide for the perplexed, in: Culture Mandala: The Bulletin of the Centre for East-West Cultural and Economic Studies, Vol. 10, No.1, December 2012 - May 2013, p. 32, 33, see also Keith Epstein, Ben Elgin, Network Security Breaches Plague NASA, BusinessWeek, 20 November 2008. 14 Phil Muncaster, German space centre endures cyber attack, The Register, 2014, 🔗 http s: / / www.theregister.com/ 2014/ 04/ 15/ dlr_attacked_china_apt_trojans/ (accessed March 2026) 15 The Washington Post, Chinese hack U.S. weather systems, satellite network, 12 November 2014 16 Darlene Storm, Attackers hack European Space Agency, leak thousands of credentials ‘for the lulz’, Computerworld, 14 December 2015, 🔗 https: / / www.computerworld .com/ article/ 1641903/ attackers-hack-european-space-agency-leak-thousands-of-crede ntials-for-the-lulz.html (accessed March 2026) 17 The Asahi Shimbun, Hackers took over accounts of JAXA president, other directors, 7 October 2024, 🔗 https: / / www.asahi.com/ ajw/ articles/ 15456087 (accessed March 2026) and NASA, collected large amounts of information including those of pro‐ pulsion systems, solar panelling and fuel tanks for the Mars Reconnaissance Orbiter (2003-2006). Malignant software (stame.exe) targeted the Kennedy Space Center and sent 20 gigabytes of information, also about the Space Shuttle, to a computer system in Taiwan (2005). Following a phishing email, budget and financial information was compromised at NASA Headquarters (2006). Networks for the processing data of the Earth Observation System were compromised at the Goddard Space Flight Center (2007). A Romanian hacker disclosed credentials of administrative networks of allegedly the Goddard Space Flight Center and the European Space Agency (ESA) (2011). The Jet Propulsion Laboratory detected unauthorised cyber activities from Chinese based IP addresses giving access to most JPL networks (2011). 13 Coordinated and systematic employment of Trojans at Germany’s space research centre DLR targeted computers used by researchers and system administrators (2013). 14 Websites of the U.S. National and Atmospheric Administration (NOAA) were compromised and led NOAA to switch off customer services (2014). 15 Anonymous hackers compromised ESA websites and disclosed personal information of staff, contractors and details of ESA databases and sub-domains (2015). 16 Hackers obtained from the Japan Aerospace Exploration Agency ( JAXA) personal data of 5000 employees, other information and took over accounts of 200 employees, including of four board directors and its president (2023). 17 Unauthorised activities against flight and payload control functions are rare but critical. Operators can lose control over a spacecraft. With loss of flight control, the space segment may be damaged or destroyed, third 5.1 Cyber and Communication Security in the Space Sector 107 <?page no="108"?> 18 For the case see Epstein/ Elgin, supra note 13. NASA advisory cited after Epstein/ Elgin. 19 2011 Report to Congress of the U.S.-China Economic and Security Review Commission, 112 th Congress, 1 st Session, November 2011, p.-215, 216. parties may suffer damage and space debris can be generated. The following cases illustrate the severity of their effects. ROSAT is a prominent case of manipulated flight controls. In 1998 the German registered X-ray research ROSAT satellite’s attitude inexplicably changed, so that its high-resolution imager was pointed to the sun. The critical instrument was damaged and rendered the satellite useless. Internal, non-disclosed NASA investigations linked the loss of ROSAT’ to an earlier cyber-intrusion at the Goddard Space Flight Center. It allegedly originated from Russia. Already in 1997, computers in the X-ray Astrophysics Section at Goddard had been unauthorisedly accessed. Large amounts of data were compromised and transferred overseas through the internet. A 1999 NASA advisory stated about network intrusions which had taken place since May 1997: “Hostile activities compromised [NASA] computer systems that directly and in‐ directly deal with the design, testing, and transferring of satellite package com‐ mand-and-control codes”.  18 Four cases of reported unauthorised cyber activities against the command and control of space segments relate to the U.S. earth observations satellites Landsat-7 and Terra EOS AM-1. The incidents against Landsat-7 lasted 12 or more minutes on 20 October 2007 and on 23 July 2008 respectively. The occurrences did not reach so far as commanding the satellite. However, on 20 June and on 22 October 2008, the intruder is said to have achieved all steps for commanding the Terra EOS AM-1 satellite, but no commands were issued. Access to the command-and-control links of the satellites were supposedly reached through a commercially operated ground station in Svalbard, Norway, which was connected to the U.S. control centres through public Internet for data access and file transfers. 19 In another instance, the payload of the International Space Station (ISS) was compromised in 2008. Hackers loaded a Trojan in computers of the Johnson Space Center in Houston, Texas, for gaining uplink access to the ISS. Certain payload operations on board were disrupted, including email connectivity. 108 Chapter Five · Cyber Activities in the Space Sector <?page no="109"?> 20 Cyber Peace Institute, Case study Viasat, June 2022, 🔗 https: / / cyberconflicts.cyberpe aceinstitute.org/ law-and-policy/ cases/ viasat (accessed March 2026) A clear distinction should be drawn between compromises of the ground segment and connected networks including the internet. A compromise of a ground-based systems is not a compromise of a space system, even though the data stream derives from a space system. For example, the Viasat incident of 24 February 2022 is frequently mistaken as an unauthorised cyber activity against a space system. This is not correct. In the Viasat case, malware targeted modems and routers of ground-based communication networks with connection to Viasat’s KA-SAT satellite network. Satellite payloads or satellite ground stations were not targeted. One day prior to Russia’s invasion into Ukraine, tens of thousands of subscribers in Ukraine and Europe lost internet access. In Germany, an energy company lost remote monitoring capability of 5,800 wind turbines. On 10 May 2022, public state‐ ments the EU, the U.S., UK, Australia, New Zealand, and Canada attributed the identified malware to the Russian military intelligence (GRU). 20 The Viasat case illustrates the connectivity of ground-based communication systems with communication satellite payloads. Even though the effects led to loss of (satellite) connectivity, the targeted system elements were part of ground-based communication networks. 5.1.3 Legal Sources and Approaches Cyber and communication security are a matter of concern in all areas of the space sector. Despite numerous data breaches and unauthorised collections of data from ground-based systems and networks, they are structurally similar to incidents in other industries. Existing national cyber security regulations apply to these systems and networks in national territories. Space and ground segments deserve special attention due to their technical specifics. 5.1 Cyber and Communication Security in the Space Sector 109 <?page no="110"?> 21 Treaty on Principles Governing the Activities of States in the Exploration and Use of Outer Space, including the Moon and Other Celestial Bodies, 27 January 1967, 610 UNTS 206. 22 The Space Industry Regulations 2021, UK Statutory Instruments 2021 No. 792, Part 11, Chapter 3. 5.1.3.1 National Legislation, Policy and Guidance States have jurisdiction over their national space segments under Article VIII of the Outer Space Treaty: 21 “A State Party to the Treaty on whose registry an object launched into outer space is carried shall retain jurisdiction and control over such object, and over any personnel thereof, while in outer space or on a celestial body. …” Moreover, States hold the supreme decision-making authority over space activities of non-governmental entities, as provided in Article VI of the Outer Space Treaty: “… The activities of non-governmental entities in outer space … shall require authorisation and continuing supervision by the appropriate State Party to the Treaty. …” Non-governmental entities require for their space activities prior authorisa‐ tion of a State. This can typically be a State with a genuine link to the entity or the State from whose territory a space object is intended to be launched. The authorisation serves as a leverage of States for mandating requirements and conditions of the envisaged space activity. After authorisation, continued supervision grants States the authority for assuring compliance with these requirements and conditions. Articles VI and VIII of the Outer Space Treaty are the international legal foundations for national space legislations. An increasing number of States has enacted national space laws and regulations. Requirements and conditions of authorisations typically focus on safety, liability and insurance. States increasingly include (cyber) security measures in their national space legislation, policy and guidance. The following national instruments serve as examples. In the United Kingdom, the Space Industry Regulations of 2021 govern cyber security requirements for all who intend to conduct spaceflight activities. 22 Regulation 185 thereof is a key provision: 110 Chapter Five · Cyber Activities in the Space Sector <?page no="111"?> 23 Presidential Memorandum on Space Policy Directive-5, Cybersecurity Principles for Space Systems (SPD-5), 4 September 2020. “(1) A licensee must draw up and maintain a cyber security strategy for the network and information systems … used in relation to spaceflight operations for which it is responsible. (2) The strategy must … (h) ensure that the systems are protected from (i) unauthorised access or interference, (ii) other unlawful occurrences, and (iii) cyber threat, and (i) ensure that the licensee’s suppliers and their supply chain specify in their security protocols how they will achieve the cyber security requirements set out in the strategy.” The UK regulator gives the licensee a wide margin of discretion, when it requires a licensee to draw up and maintain a cyber security strategy. It does not require him to comply with fixed cyber security rules or standards. The definitions section further clarifies, that ‘unauthorised access or interference’ includes radio interference. Communication security is thus to be covered by the licensee’s strategy, as is supply chain security. In the United States of America, Space Policy Directive-5 (SPD-5) estab‐ lishes key cyber security principles to guide and serve as the foundation the cyber protection of space systems. 23 The principles encompass a risk based approach and call for cyber security plans of owners and operators, also with elements of physical security, communication security, and measures for behavioural hygiene and supply chains: “(a) Space systems and their supporting infrastructure, including software, should be developed and operated using risk-based, cybersecurity-informed engineering. … (b) Space system owners and operators should develop and implement cybersecurity plans for their space systems … [including] : (i) Protection against unauthorised access to critical space vehicle functions … (ii) Physical protection measures … (iii) Protection against communications jamming and spoofing … (iv) Protection of ground systems, operational technology, and information process‐ ing systems … (v) Adoption of appropriate cybersecurity hygiene practices, physical security for automated information systems, and intrusion detection methodologies for system elements … 5.1 Cyber and Communication Security in the Space Sector 111 <?page no="112"?> 24 Space Policy Directive-5, id., Section 4 - Principles. 25 Ibid. 26 Japan, Ministry of Economy, Trade and Industry, Manufacturing Industries Bureau, Space Industry Office, Guidelines on Cybersecurity Measures for Commercial Space Systems Ver 1.0, 21 July 2022. 27 Japan Space Law Association, The Guidelines on Cybersecurity Measures for Commer‐ cial Space Systems version 1.0, 🔗 https: / / japan-space-law-association.org/ en/ 806/ (accessed March 2026) 28 Directive (EU) 2022/ 2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union. See also supra 3.5. (vi) Management of supply chain risks …”.  24 As an executive-level memorandum, SPD-5 is not binding legislation, but it directs federal agencies to apply these principles in their relations with space system owners and operators. Reflecting its non-enforceable nature towards owners and operators, the policy states: “(c) Implementation of these principles, through rules, regulations, and guidance, should enhance space system cybersecurity, including through the consideration and adoption, where appropriate, of cybersecurity best practices and norms of behavior. (d) Space system owners and operators should collaborate to promote the develop‐ ment of best practices, to the extent permitted by applicable law. …”.  25 In Japan the government issued Guidelines on Cybersecurity Measures for Commercial Space Systems in 2022. 26 While these measures are voluntary for space operators, their publication by the Japanese government lends them considerable credibility. Subject of the guidelines are Earth observation satellites and ground systems. All phases of satellite system are covered including design, development, manufacturing, operation, maintenance, and disposal. The guidelines foresee operators to implement cyber security measures for the space segment (also for radio communication links), for operation facilities (TTC station, receiving station and network, mission control), for facilities of satellite development and manufacturing, and for facilities of satellite data utilization. 27 5.1.3.2 European Union The Network and Information Security Directive (NIS2) is the central element of cyber security legislation in the European Union. 28 The directive 112 Chapter Five · Cyber Activities in the Space Sector <?page no="113"?> 29 COM(2025) 335 final, Proposal for a Regulation of the European Parliament and of the Council on the safety, resilience and sustainability of space activities in the Union Brussels, 25. June 2025. 30 COM(2025) 335 final, id., Articles 75-94. 31 COM(2025) 335 final, id., Article 5(16): Space operators include spacecraft operators, launch operators, launch site operators and in-space operation and service providers. applies, inter alia, to medium-sized entities of so-called sectors of high criticality. Annex I ‘space’ lists as sector of high criticality: “11. … Operators of ground-based infrastructure, owned, managed and operated by Member States or by private parties, that support the provision of space-based services, excluding providers of public electronic communications networks”. The focus is on ground-based infrastructure. It does not mention the space segment. Apparently, this follows from the experience that unauthorised cyber activities, which are undertaken through a network, typically exploit the vulnerabilities of ground networks for accessing the space segment. The wording of Annex I does not encompass communication security of radio links between ground networks and satellites or between satellites. Public electronic communication networks are excluded in the space section of the annex, because they are already listed under digital infrastructure. More detailed cyber security requirements for the space sector are fore‐ seen in the future EU Space Act. 29 The Space Act is an ongoing legislative initiative for unifying rules and conditions of the Member States’ space activities. It is currently a proposal for an EU Regulation but gives already valuable insight into the European Commission’s approach to resilience and cyber security. For clarification, the EU Space Act does not create international space law in parallel to the Outer Space Treaty. Like for other national space legislations, Articles VI and VIII of the Outer Space Treaty are the starting points for the EU Space Act. Member States of the European Union retain the authority for authorizing and licensing their national space activities and for jurisdiction on their national space objects. The EU Space Act will unify Member States’ future (national) legislation in that field. It cannot deprive them of their sovereign authority und obligations under the Outer Space Treaty. The draft EU Space Act’s chapter on ‘resilience of space infrastructure’ 30 applies to space operators who operate space infrastructures. 31 This chapter partly overlaps with the NIS-2 Directive and the CER Directive on physical 5.1 Cyber and Communication Security in the Space Sector 113 <?page no="114"?> 32 COM(2025) 335 final, id., Article 75. - Directive (EU) 2022/ 2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities (CER). 33 COM(2025) 335 final, id., Article 82. 34 COM(2025) 335 final, id., Articles 76, 77. 35 COM(2025) 335 final, id., Articles 80, 81, 84, 86, 87: identification and management of information and assets, management and control of access rights, prevention and protection, back-up management and redundancy, business continuity, response and recovery plans. 36 COM(2025) 335 final, id., Articles 83, 91, 93, 94: detection and monitoring of incidents, handling of incidents, reporting of significant incidents, Space Resilience Network. 37 COM(2025) 335 final, id., Article 85: cryptography and encryption. 38 COM(2025) 335 final, id., Article 89: learning and training. 39 COM(2025) 335 final, id., Article 92. 40 🔗 https: / / spaceshield.esa.int/ matrices/ space/ (accessed March 2026). For the ESA cyber security strategy and policy see also: 🔗 https: / / esamultimedia.esa.int/ docs/ cor porate/ ESA_Cyber_Security_Resilience_Achievement.pdf (accessed March 2026) security. Depending on certain criteria, it applies as lex specialis to the NIS-2 Directive and is complementary to the CER Directive. 32 Physical resilience measures are expressly addressed. 33 The chapter is detailed and replicates many elements of the NIS-2 Directive. A central point is risk management through the lifecycle of space missions. 34 Organisational and operational measures are addressed in detail, 35 as are incidents. 36 Other aspects are technical measures, 37 human resource issues 38 and supply chain risk management. 39 5.1.3.3 Best Practice Guidelines Risk-based cyber security approaches, as increasingly foreseen in national laws and regulations, leave space operators a broad margin of discretion for implementation. Regardless of national legal obligations, space operators have a self-interest in protecting their highly value assets and activities against security breaches. Best practice guidelines can provide specific meas‐ ures and tools for assuring resilience of space systems and confidentiality, integrity and authenticity of digital data. For this purpose, the European Space Agency (ESA) applies the Space Attacks and Countermeasures En‐ gineering Shield (Space Shield). 40 It is a primarily engineering driven matrix of 14 groups of space system specific security vulnerabilities with more than 100 techniques and sub-techniques for their prevention and mitigation. The ESA Space Shield lists vulnerabilities of the ground and space segments 114 Chapter Five · Cyber Activities in the Space Sector <?page no="115"?> 41 The Aerospace Corporation, Space Attack Research & Tactic Analysis (SPARTA) version 3.2, 🔗 https: / / sparta.aerospace.org/ (accessed March 2026) 42 National Aeronautics and Space Administration, Space Security: Best Practices Guide (BPG), SS BPG, REV B, 19 January 2024, section 1.4.2, 🔗 -https: / / swehb.nasa.gov/ spac es/ SWEHBVD/ pages/ 146540183/ 7.22+-+Space+Security+Best+Practices+Guide? previe w=/ 146540183/ 154501144/ Space%20Security%20Best%20Practices%20Guide%20BPG%2 0REV%20B.pdf (accessed March 2026) 43 Constitution of the International Telecommunication Union (Geneva, 1992), as amen‐ ded by 197 PP-98, Article 45.1. and of space-link communications. The techniques reach beyond cyber security and include information, communication, physical and supply chain security. Space specific threats like (foreign) orbital reconnaissance and interference with laser communication are considered as well. The ESA Space Shield is based on the methodology of the Space Attack Research & Tactic Analysis (SPARTA) of the Aerospace Corporation. 41 In the U.S., the National Aeronautics and Space Administration (NASA) also follows the SPARTA methodology. 42 5.1.3.4 Harmful Radio Interference Radio interference with signals among space objects and ground stations constitute the central communication vulnerability of space systems. Albeit not a matter of cyber security, it relates to communication security. For the time being, jamming and spoofing of signals of Global Navigation Satellite Systems (GNSS) are an area of concern. The International Telecommuni‐ cation Union (ITU) is the international body for addressing harmful radio interference. Article 45.1 of the ITU Constitution establishes the principle for avoidance of harmful radio interference to the detriment of other States: “All stations, whatever their purpose, must be established and operated in such a manner as not to cause harmful interference to the radio services or communications of other Member States … and which operate in accordance with the provisions of the Radio Regulations.”  43 This also applies to installations for national defence services, as far as possible: 5.1 Cyber and Communication Security in the Space Sector 115 <?page no="116"?> 44 ITU Constitution, id., as amended by 202, 203, PP-98, Article 48. 45 ITU Radio Regulations, edition 2020, Article 15.22 § 14, 15.23 § 15. 46 ICAO Assembly Resolution A42-2: Infraction of the Convention on International Civil Aviation by the Russian, ICAO Provisional Edition, Provisions adopted by the Assembly, October 2025. “1 Member States retain their entire freedom with regard to military radio installa‐ tions. 2 Nevertheless, these installations must, so far as possible, observe statutory provisions … to prevent harmful interference …”.  44 However, the resolution of conflicts in case of harmful interference is in the hands of the affected States, based on sovereign equality: “It is essential that Member States exercise the utmost goodwill and mutual assistance in the application of the provisions of Article 45 of the Constitution and of this Section to the settlement of problems of harmful interference. … In the settlement of these problems, due consideration shall be given to all factors involved …”.  45 In case of intentional large-scale radio frequency interference (RFI) of GNSS signals which reach hundreds of kilometres beyond national borders, amicable settlements between the involved States tend to end up in a deadlock. Utmost goodwill, mutual assistance and due consideration do not help when the interfering State is unwilling to stop its conduct. However, recourse to international fora can result in a multilateral condemnation. To that end, the Assembly of the International Civil Aviation Organisation (ICAO) adopted Resolution A 42-2 in October 2025, by which it: “1. Endorses the determination of the ICAO Council that GNSS-RFI in the Baltic, Eastern and Northern European regions originating from the territory of the Russian Federation and its harmful impact on the safety and security of international civil aviation goes against the principles enshrined in the Convention on International Civil Aviation, and constitutes an infraction of that Convention; 2. Condemns the Russian Federation for the recurring GNSS-RFI originating there‐ from that is jeopardizing the safety and security of international civil aviation; 3. Urgently calls upon the Russian Federation to comply strictly with its obligations under the Convention on International Civil Aviation, in order to cease the recurrence of such GNSS-RFI activities …”.  46 116 Chapter Five · Cyber Activities in the Space Sector <?page no="117"?> 47 ICAO Assembly Resolution A42-3: Infraction of the Convention on International Civil Aviation by the Democratic People’s Republic of Korea, ICAO Provisional Edition, id. 48 Outer Space Treaty, supra note 21. 49 Convention on International Liability for Damage Caused by Space Objects, 29 March 1972, 961 UNTS 187. The ICAO Assembly adopted a similar Resolution condemning GNSS-RFI on the Korean peninsula originating from the Democratic People’s Republic of Korea. 47 5.2 State Responsibility and Liability Unauthorised cyber activities which influence space flight control and cause physical damage to third parties on the ground can lead to adverse consequences under international space law. As a principle of international space law, space activities are attributed to States whether undertaken by governmental or non-governmental entities. Article VI the Outer Space Treaty 48 states: “States Parties to the Treaty shall bear international responsibility for national activities in outer space … whether such activities are carried on by governmental agencies or by non-governmental entities, and for assuring that national activities are carried out in conformity with the provisions set forth in the present Treaty. …” When an unauthorised cyber activity interferes with the flight of a space object, the responsible State of that space object continues to be legally responsible under Article VI, also when it has lost technical command and flight control over it. The situation becomes more momentous when the interfered space object causes physical third-party damage on the surface of the Earth. In this case, Article II Liability Convention 49 applies: “A launching State shall be absolutely liable to pay compensation for damage caused by its space object on the surface of the Earth or to aircraft in flight.” The launching State bears absolute liability for physical third-party damage on the Earth resulting from unauthorised (cyber) activities which affect their space objects to change their trajectory, to collide, fragment or crash. Different thereto, States bear no liability under Article II of the Liability Convention, when unauthorised (cyber) activities affect payloads. The services of satellite payloads are provided through wireless communications 5.2 State Responsibility and Liability 117 <?page no="118"?> 50 Constitution of the International Telecommunication Union (Geneva, 1992), as amen‐ ded by 183 PP-98, Article 36. 51 See supra 5.1.3.1. 52 Most prominent constellations are Starlink (of SpaceX, USA) with currently about 10,000 in orbit and a planned final constellation of 50,000 satellites or more; Project Kuiper of Amazon (USA) with a planned constellation of 3,236 up to 7700 satellites, EutelSat OneWeb (UK) with currently more than 600 satellites in LEO, combined with about 30 satellites in geostationary orbit; Guowang (China) with a planned constellation of about 13,000 satellites. for which States accept no responsibility and no damage claims. Article 36 of the Constitution of the International Telecommunication Union (ITU) states: “Member States accept no responsibility towards users of the international telecom‐ munication services, particularly as regards claims for damages.”  50 Article II of the Liability Convention establishes absolute liability of launch‐ ing States for the protection of innocent by-standers against physically impacted damage. For achieving this broad liability cover, launching States also bear the burden of unauthorised (cyber) activities against the flight control of their space objects resulting in such damage. So far, no liability claims were raised for damage resulting from deprived flight controls of space objects. However, there is no specific legal basis for holding States responsible and absolutely liable for national cyber activities that trigger a space segment of another State to cause damage on the Earth. As a legal precaution, States should require operators to apply (cyber) security measures and resilience of flight control under their authorisation and supervision regime of Article VI of the Outer Space Treaty. 51 5.3 Cyber Infrastructure in Outer Space Space infrastructure can become part of the cyber infrastructure. This applies foremost to the forthcoming large low earth orbit satellite constella‐ tions for mobile internet communications. Users on the ground can directly access these space-based networks with small mobile user units. Large LEO satellite constellations are currently established with tens of thousands of satellites. 52 The final total number of satellites of all constellations will by far exceed 100,000. Each satellite of such a constellation acts like a space-based cell of a terrestrial mobile cellular network. The satellite cells 118 Chapter Five · Cyber Activities in the Space Sector <?page no="119"?> 53 Constitution of the International Telecommunication Union (Geneva, 1992), as amen‐ ded 196 PP-98, Article 44.2. are connected among each other by inter satellite links, typically with optical laser communication. Each constellation constitutes an independent global physical network layer detached from territory. They work like IP-based worldwide intranets. Connection to the internet is accomplished through gateway ground stations with radio links to the constellations and (fibre optic) landlines to the internet. Technical control of gateway ground stations can be used to determine the degree of access to the internet. Mobile space-based internet of large constellations serves niche markets. Large constellations can serve locations on Earth without ground-based internet connectivity, airline passengers or military applications during armed conflict. They are not competitors to fibre optic cables which handle about 97 percent of worldwide internet traffic with superior speeds. The number of large constellations which can be placed in low earth orbits is limited. Not only the available radio spectrum is a limited resource. Tens of thousands of satellites increase collision and fragmentation risks in low earth orbits and jeopardize the sustainable access to outer space. Article 44.2 of the ITU Constitution recognizes the radio-frequency spectrum and satellite orbits as limited resources: 53 “In using frequency bands for radio services, Member States shall bear in mind that radio frequencies and any associated orbits … are limited natural resources and that they must be used rationally, efficiently and economically, … so that countries or groups of countries may have equitable access to those orbits and frequencies, taking into account the special needs of the developing countries and the geographical situation of particular countries.” This provision of the ITU Constitution follows the more general principle of Article I of the Outer Space Treaty: “The … use of outer space … shall be carried out for the benefit and in the interests of all countries, irrespective of their degree of economic or scientific development, and shall be the province of all mankind. Outer space … shall be free for … use by all States without discrimination of any kind, on a basis of equality and in accordance with international law … ” 5.3 Cyber Infrastructure in Outer Space 119 <?page no="120"?> Considering that the limited natural resources can sustain only a few large communication satellite constellations in low earth orbits, States which authorise or operate them make use of a limited global resource. The core issue is how these global resources and the systems which exploit them can be used rationally, efficiently and economically for the benefit and in the interest of all countries without discrimination. Connected to this issue are economic, political and military impacts of global communications and information oligopolies. Control of internet gateways can be used as key for influencing access to information content in the constellation network, also for political purposes. Operators must be prevented to escape national jurisdiction and control, only because their global internet infrastructure is beyond national territory. Misuse of dominant market positions in the served niche markets must be avoided. Protections are needed against unfair and biased terms and conditions of users. Fundamental rights of users must be protected, including privacy and intellectual property rights. States need to maintain authority over the use of satellite internet in case of military operations, especially during armed conflict. Decisions whether to support a belligerent with services crucial for military targeting or defence, or to deny such support, should not be in the hands of non-governmental operators. States can establish jurisdiction as part of their authorisation and supervision under Articles VI and VIII of the Outer Space Treaty, also for the economic, political and military impacts of global mobile communication systems. National jurisdiction may also be established at the location of internet gateway ground stations. It remains open, how to protect the benefit and interests of all countries, not only national interests. 5.4 Remarks The track record of cyber security violations in the space sector indicates a focus on industrial and State supported unauthorised collection of infor‐ mation. These incidents are similar to those in the aerospace and military industry. Unauthorised (cyber) activities against control functions of the space segment are specific to space operations, but known incidents of that type are an exception so far. Regardless of mandatory security requirements under national law, space operators have a self-interest in protecting their assets and space activities. The scope of the ESA Space Shield and the NASA 120 Chapter Five · Cyber Activities in the Space Sector <?page no="121"?> 54 See also Fred George, Navigating the Future, Aviation Week & Space Technology, 28 July - 10 August 2025, p. 52. Such measures can be, for example, controlled reception pattern antennas, dual frequency and integrity certified GNSS constellations, multi constellation receivers, signal encryption and global differential GNSS. 55 See Fred George, id. Alternative navigation systems in aviation are legacy radio navigation aids (VOR, DME, ILS), Inertial Navigation Systems, future enhanced versions of eLoran and eDME and magnetic navigation farther out in the future. Sparta best practice guidelines extend beyond cyber security and includes communication, information, physical and supply chain security. Communication security is a critical aspect in space operations. Increas‐ ing encryption of signals between space segment and ground segments can mitigate this risk, but not for legacy space systems. Radio frequency inter‐ ference of signals from Global Navigation Satellites Systems has become a growing problem for users. There is a lack of international enforceability against States which persistently deny, degrade or distort navigation signals. Technical solutions seem the most plausible way forward for assuring secure satellite navigation services. 54 The vulnerabilities of satellite navigation should nevertheless motivate safety critical sectors like aviation to redun‐ dantly use alternative technologies independent of satellite services. 55 Large satellite constellations in low earth orbits are presently used for establishing cyber infrastructures. Other than public perception may suggest, they serve only niche markets. The benefit to niche markets appears disproportionate to the use of the limited radio frequency and orbital resources. Congestion of low earth orbits can become a critical hindrance for the sustainable access to outer space by all States. National regimes are unsuitable for regulating global communication and internet systems in outer space which exhaust limited global resources. International space law must prevail over national interests. 5.4 Remarks 121 <?page no="123"?> 1 See supra 1.2.4. Chapter Six · Automation and Artificial Intelligence Automation, artificial intelligence and cyber activities are distinct but interrelated concepts. Artificial intelligence is a software tool that supports automation. As such, the purpose of automation and artificial intelligence overlap. Both, automation and artificial intelligence typi‐ cally use cyber activities, or more precisely networked data exchanges. 6.1 Automation Automation describes the use of mechanical or electronic machinery for the execution of functions without human participation. Developing from mechanical and analogue technology, today, automation relies on computer technology supported by software. 6.1.1 Concepts and Terminology 6.1.1.1 Automation of Kinetic Functions From its origin, automation of kinetic functions related to mechanical functions with analogue features, for example mechanical calculators or mechanically automated weaving looms. The ‘logic’ of these automated applications was either embedded in the mechanical hardware, with metal registers and pins for mechanical calculators, or in strings of punch cards for weaving looms. Today, automation of kinetic functions is accomplished with computer technology and software. Peripheral devices 1 create the link to the kinetic sphere, for example in industrial or domestic machinery. The automation of kinetic functions is an interface of cyber activities with the real world. Actuators translate electronic commands into kinetic actions. Sensors measure physical properties of the real world, like temperature, pressure or motion and translate them into machine readable data. The term robotics is often synonymously used for the automation of kinetic functions. It is derived from the concept of robot, an originally <?page no="124"?> 2 SAE International, Standard J3016 for Taxonomy and Definitions for Terms Related to On Road Motor Vehicle Automated Driving Systems, Automated Driving, 30 April 2021. Six levels of driving automation are defined in SAE International Standard J3016: 0 - no automation, 1 - driver assistance, 2 - partial automation, 3 - conditional automation, 4 - high automation, 5 - full automation; 🔗 https: / / www.sae.org/ standards/ j3016_20 2104-taxonomy-definitions-terms-related-driving-automation-systems-road-motor-ve hicles (accessed March 2026). Russian term for a manual worker with humanoid appearance. The concept of robotics or robots is used today for a specific set of automated kinetic functions, for example as industrial welding robots or automated applica‐ tions for the surface exploration of celestial bodies. The term robotics does not indicate whether mechanical, electronic, analogue or digital technology is used. Remote control is a concept for controlling kinetic functions from distance, typically through a radio control link or through a (IP-based) network. Different to an automated or autonomous system where the control of the kinetic function is executed through a logic element in the device, humans control remote controlled functions from distance. Typical applications are drones, of which most today are remotely controlled, but certain functions can be accomplished in an automated or even autonomous fashion. The term of Internet of Things (IoT) is used as well for remote control of kinetic functions but is more specific on the use of IP-based networks for operating remote control data links. The Internet of Things is about the control of kinetic peripheral devices through the internet. There is not just one type or mode of automation. Different levels of automation need to be distinguished. The Society of Automotive Engineers (SAE), a private standard setting organisation, has early recognized that technical standards for the automation of road traffic need to distinguish between different levels of driving automation. 2 This distinction is helpful for studying the technical and legal aspects of automation, not only in the automotive field. Autonomy describes the highest level of automation. Autonomy indi‐ cates an automated (kinetic) action which is exercised independently from direct human control under all foreseeable circumstances. The level of automation determines the relationship between humans and an automated system. Autonomous systems operate without ‘humans in the loop’. This means, an autonomous system takes over technical control of the system 124 Chapter Six · Automation and Artificial Intelligence <?page no="125"?> 3 Jonathan Stuart Ward, Adam Barker, Undefined by Data: A Survey of Big Data Definitions, 🔗 -https: / / arxiv.org/ pdf/ 1309.5821.pdf (accessed March 2026). under all circumstances. For lower levels of automation, humans must be in the loop to oversee the automation process and to take over control, when the situation requires. From a legal perspective it is critical, if autonomy should go so far as to completely exclude human intervention, even if so desired by an operator or user. Autonomy means independence of human control, not of networked connectivity. Autonomous systems may depend on information provided through networks, although they operate independently of direct human control. Autonomous systems can be subject to information exchanges which have an impact on their control. They are not necessarily isolated data islands. The term autonomy or autonomous system is presently used in an inflationary fashion for automated systems which meet only a lower level of automation. For legal purposes, the proper level of automation should be correctly indicated. Manufacturers and system integrators who label their products as autonomous may set unrealistic expectations of users and their actual role to supervise and control automated systems. 6.1.1.2 Automation of Non-Kinetic Functions The automation of non-kinetic functions relates to the automation of data analytics. Automated data analytics reaches beyond data processing through a microprocessor. It means the filtering and combination of digital data to achieve new meaningful information. This automated process is similar to the human interpretation of facets of information for achieving new insights. Modern automated data analytics, especially through artificial intelligence, can foster new awareness. It is likewise important for analysing large amounts of data which are continuously generated by sensors and other sources, and which require interpretation in a volume beyond the available capacity of human analysts. The automated analysis of large amounts of data is often addressed as Big Data. However, definitions of Big Data typically mention only its properties of volume, velocity, variety and veracity. 3 These definitions of Big Data describe its quantitative and qualitative features but miss its role in automated data analytics. 6.1 Automation 125 <?page no="126"?> 4 See supra 4.1.1. 5 Also critical on single pilot operations: Broderick et.al., AW&ST, 16-29 October 2023, p 32. 6 ICAO, Convention on International Civil Aviation (Chicago Convention), 7 December 1944, 15 UNTS 295, Annex 11, Air Traffic Services, Chapter 1, Definitions. 6.1.2 Automation in Aviation and Space Operations Automation plays a significant role in aviation and space operations. Automation followed the technical complexity of aircraft from early days. Lawrence Sperry demonstrated gyroscopic indicators and mechanical auto‐ pilots for aircraft already in 1914. Modern automation of flight controls uses onboard computer systems and digital data processing. The control logic is executed by digital autopilots and flight management systems for controlling engines, control surfaces and flaps through electric fly-by-wire connections. 4 Navigation, including automated landings, surveillance and numerous aircraft subsystems are likewise digitally controlled. In combina‐ tion, these onboard computer systems help pilots manage complex systems and procedures, reduce their workload and they increase safety and effi‐ ciency. The levels of automation in aircraft are steadily increasing with a ten‐ dency to evolve to single pilot operations, remote control from the ground and (autonomous) Unmanned Aircraft Systems. It is not only a technical question whether to reduce the cockpit crew to one single pilot or even to remote control. Passengers trust in human pilots onboard, who themselves wish to return home safely. The presence of pilots raises passengers’ confidence in the safety of flight. 5 Automation strongly impacts air traffic control. Air traffic control service is “provided for the purpose of … preventing collisions between aircraft … and expediting and maintaining an orderly flow of air traffic.”  6 With increasing levels of information technology and automation, modern air traffic control has evolved to a discipline of information management with automated real time information exchange among ground and air stations. Software tools support air traffic controllers for using airspace more efficiently and reducing separation among aircraft while taking into account optimized individual flight profiles, weather, obstacles and other airspace limitations and hazards. 126 Chapter Six · Automation and Artificial Intelligence <?page no="127"?> 7 Contributing to the crash of Air Inter 148 on 20 January 1992 was a confusing indication of the descent rate and glide slope on the flight control unit. A contributing factor for the crash of Birgen Air 301 on 6 March 1996 was an obstructed pitot tube which led to incorrect airspeed readings and confusion of the flight crew. 8 The crew of China Airlines 006 from Taipei to Los Angeles on 19 February 1985 tem‐ porarily lost control and altitude after the autopilot effectively masked the approaching onset of the loss of control and the captain relied on the autopilot. Contributing factors Since the beginning of spaceflight, space objects were remotely controlled from the Earth. Except for a smaller number of flights with humans onboard, remote control and automation was the only way for controlling the trajec‐ tory of spacecraft and the functioning of their payloads. This is typically accomplished by a mix of remote control and different levels of automation. For deep space operations with large communication time delays, remote control from the Earth is not feasible. They require autonomous systems for certain phases of operations, for example for landing spacecraft on Mars or for time critical manoeuvres in deep space. Shortcomings of Aircraft Flight Automation Flight automation of aircraft has improved the overall safety record of avi‐ ation over many years, but it can also create negative effects. It can increase the complexity of the human machine interface in the cockpit, especially during untypical flight situations. Automated systems bear the risk of being misunderstood or mishandled by pilots and human operators. Weak points are sensor malfunctions or discrepancies and design shortcomings of the pilot-machine interface. Human-machine interfaces need to be designed for pilots to possess comprehensive situational awareness so they can promptly and intuitively intervene. The combination of sensor deficiencies and human-machine design limitations increases complexity and increases pilot workload up to loss of situational awareness and factual control. In a critical situation, automation issues and human errors can become an intertwined sequence of reactions without escape. Typical systemic shortcomings of flight and cockpit automation with effects on the human-machine interface are • incorrect situational indications, for example of aircraft attitude, flight control, aircraft systems, navigation, airspace and air traffic, 7 • incorrect or misleading indications about the status or mode of automa‐ tion in flight critical situations, 8 6.1 Automation 127 <?page no="128"?> to the crash of prototype Airbus A 330, F-WWKH, on 30 June 1994 were the impossibility of the crew to identify in which mode the automatic pilot was set and their confidence in the anticipated reactions of the aircraft. 9 The crash of Turkish Airlines 1951 on 25 February 2009 was triggered by a faulty radio altimeter which led the automated system (autothrottle) reduce engine thrust before the aircraft had touched down. Primary causes for the crash of Air France 447 on 1 June 2009 were obstructions of airspeed sensors with ice crystals which led to the disengagement of the automated system (autopilot and auto-thrust). The crashes of Lion Air 610 on 29 October 2018 and of Ethiopian Airlines 302 on 10 March 2019, both Boeing 737 MAX aircraft, were caused by the erroneous data of a single, non-redundant, angle of attack sensor that mislead automated flight control (Manoeuvring Characteristics Augmentation System) to go into a nosedive while the automated system complicated pilots to regain control. 10 Contributing factor to the crash of a military General Atomics Predator B unmanned aircraft on 25 April 2006 was an “unresolved lock-up” of the computer console of the operating pilot on the ground. Contributing factor to Lufthansa 2904 overshooting runway in Warsaw on 14 September 1993 were 1. the control logic which resulted in the lack of possibility of immediate actuation of the aircraft's brakes and 2. that in emergency the crew was unable to override the system and to operate ground spoilers and engine thrust reversers. 11 This was a factor in the accidents of China Airlines 006 and Air France 447, supra at notes 8 and 9. • sensor shortcomings or discrepancies with impact on flight automation, 9 • complication or impediment of automated system preventing pilot from intervening in a critical situation (the automated system overrides the pilot), 10 • complexity of system preventing pilots regain (manual) control of aircraft after the automated system is switched off. 11 6.1.3 Legal Considerations Legal factors like responsibility, attribution and control are critical for the operation of autonomous systems. Other than for systems with a lower level of automation, the operator’s possibility for intervening an autonomous process can be factually reduced or prevented. In legal relations, persons bear the responsibility for their activities and failures when they affect other persons. Responsibility means they are legally answerable to other members of society for their actions, omissions and consequences thereof. Like for any other activity, persons are respon‐ sible when they engage, use and operate technical means. This should not be different for automated systems up to the level of autonomy. Operators 128 Chapter Six · Automation and Artificial Intelligence <?page no="129"?> should not escape responsibility only because they did not directly and promptly cause an incriminating event. Even when an operator is out of the direct control loop of an automated sequence, he can be held responsible under the theory of adequate causation, provided the resulting action or damage is typical and foreseeable according to general life experience. An operator who starts an autonomous system triggers a chain of autonomous actions for which he is out of the loop. This is an intrinsic risk of operating an autonomous system. The operator of the system cannot renounce responsibility for typical and foreseeable consequences. Responsibility serves as a means of legal attribution. An operator’s responsibility for an autonomous kinetic system attributes the autonomous action of his system to him as a subject of law, as if he had directly initiated the kinetic action himself. If the autonomous action damages third parties’ life, health or property, the operator can become liable under domestic rules of law for criminal or private liability. For respecting the integrity of others and limiting their liability exposure, operators of autonomous systems need to take measures of due diligence to safeguard the fundamental rights of third parties. A possible measure of due diligence is enclosing the area of impact of an autonomous system or operating it at large distance to others. This has some similarity to the due diligence of a domestic animal keeper who keeps his animal on leash or in an enclosed compound. Autonomous (deep) space operations are a good example of keeping possible adverse effects at distance to others. An operator’s responsibility is linked to his effective technical control over an autonomous system. Responsibility constitutes a legal obligation in relation to affected parties. Different thereto, an operator’s control constitutes a factual means to manage and influence the consequences of an autonomous system’s actions. Considering an operator’s responsibility, it is counter-productive to design an autonomous system that restricts an operator’s ability to intervene, once he has initiated the autonomous chain of events. After starting an autonomous function, the operator has passed the point of no return. He is deprived of his only tool of factually controlling the sequence of events for which he is responsible. For achieving a sufficient level of control over an autonomous system, human override and fallback modes are highly desirable design features. Override modes should allow to put a human back into the loop, when a human decision maker finds it necessary in a (safety) critical situation. Con‐ sidering the complex decision-making matrix of automated and autonomous 6.1 Automation 129 <?page no="130"?> 12 The three ‘laws’ were published in different wording, for example in: Isaac Asimov, I, Robot, in: Runaround, Spectra Books, New York. 1942. systems, fallback modes could be layered, as to reduce autonomy to lower levels of automation with human guidance and oversight. Override and fallback modes should be designed to allow the re-introduction of humans into the loop in an intuitive manner. Responsibility for autonomous systems should not only be vested with operators. It is desirable that (national) regimes provide for fair sharing of responsibility among involved actors. For example, manufacturers, pro‐ grammers and providers of services and information have a direct influence on the automated decision making of autonomous systems, especially when they are run by artificial intelligence. Manufacturers and programmers need to be transparent about algorithms, the decision factors and priorities. Moreover, operators need to know which information inputs drive the decision making of the autonomous system they engage. The technical control logic of automation, notable of autonomous systems driven by artificial intelligence, does not exist in a legal vacuum. Automated and autonomous systems need to be designed to respect fundamental rights of users and impacted third parties, including their life, health and property. Their design should furthermore respect the common good of the environment and public order. Isaac Asimov’s robot laws of 1942 12 can be interpreted as an exemplifi‐ cation of the protection of fundamental rights applied to the relationship between autonomous systems (robots) and humans. As a product of Asi‐ mov’s science fiction literature, these fictive principles are neither laws nor standards. Yet they express that autonomous systems must not harm humans, obey human orders, and prevent human misuse for harming other humans: “1. A robot may not injure a human being or, through inaction, allow a human being to come to harm. 2. A robot must obey the orders given it by human beings except where such orders would conflict with the First Law. 3. A robot must protect its own existence as long as such protection does not conflict with the First or Second Laws”. Waivers and disclaimers are unsuitable legal constructs for addressing the responsibility for autonomous systems. Waiving or disclaiming respon‐ 130 Chapter Six · Automation and Artificial Intelligence <?page no="131"?> 13 See also supra 2.6.3. 14 See also United Nations, General Assembly, Report of the Secretary-General, Lethal autonomous weapons systems, A/ 79/ 88, 01 July 2024, 🔗 https: / / docs.un.org/ en/ A/ 79/ 88 (accessed March 2026). sibility and liability render undesirable results of autonomous actions to be events of force majeure. This is not legitimate, because it deprives affected third parties of their fundamental rights and releases operators, manufac‐ turers and from their liability. When an operator starts an autonomous chain of events, he cannot claim resulting unwanted effects to be force majeure. Autonomous systems in armed conflict require special legal considera‐ tions. Autonomous weapons systems can select the scope, scale and severity of physical (lethal) force following a pre-programmed pattern without direct human control. Once engaged, it becomes unclear if a human or a machine launched an automated action of force and who took targeting decisions. The discussion about the use of autonomous weapons systems follows two schools of thought. One position argues autonomous weapons systems can more neutrally than humans comply with international humanitarian law, especially with the principles of proportionality and of distinction between legitimate military targets and protected persons. 13 The opposite position argues that autonomous weapon systems undermine human command responsibility, they are not free from errors and prejudice and that an autonomous activation of weapons without humans in the loop lowers the threshold for the use of force. Since military objectives are the main reason for applying physical force in armed conflicts, they will likely be the main driver and objective for engaging autonomous weapons. Compliance with international humanitarian law may become only a subordinated objective of the deployment of autonomous weapons. 14 6.2 Artificial Intelligence Artificial Intelligence (AI) is a software tool which strongly impacts the development of automated and autonomous systems. Software is key for the control logic of automation and autonomy based on information and com‐ puter technology. The introduction of AI software instead of conventional software enlarges the capabilities of automated and autonomous systems. 6.2 Artificial Intelligence 131 <?page no="132"?> 15 Organisation for Economic Co-operation and Development, Recommendation of the Council on Artificial Intelligence, 2024, 🔗 -https: / / legalinstruments.oecd.org/ en/ instr uments/ oecd-legal-0449 (accessed March 2026). 16 Regulation (EU) 2024/ 1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (AI Act), Art. 3 (1). 17 Levels of autonomy should better read: levels of automation. 6.2.1 Concepts and Terminology The term AI is often used synonymously with automation and autonomy. Existing definitions do not portray the characteristics of AI. They usually mix it with the concepts of automated and autonomous systems. It seems many drafters of legal and policy documents avoid defining AI. They use the term AI system instead, like the Organisation for Economic Co-operation and Development (OECD): “An AI system is a machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. Different AI systems vary in their levels of autonomy and adaptiveness after deployment.”   15 The European Union uses a similar definition: “AI system’ means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.”  16 These definitions do not clarify that AI is software which runs on computer systems. By mentioning input-output, they merely paraphrase the general principle of cause and effect. The only hint to the specifics of AI lies in the word ‘adaptiveness’, which is not further explained. Rather than defining AI itself, they refer to different levels of autonomy 17 of the systems in which they are embedded, and to physical and virtual environments. Both definitions avoid addressing the core concept of AI. What is AI, other than a placeholder for automated and autonomous systems? AI is a special type of software. It is different to conventional software, which produces deterministic results: the same data inputs generate the same outputs. AI software produces non-deterministic results: the same 132 Chapter Six · Automation and Artificial Intelligence <?page no="133"?> data inputs generate somewhat different outputs from time to time. This feature of AI results from algorithms which work with statistical models. Another element of AI is so-called machine learning. AI software does not only (statistically) process input datasets for generating a data output. It can use the same data input to adjust its (statistical) model for processing. Over time, AI software adapts its methods of data processing based on the datasets it has already processed earlier. For legal purposes, the authors define AI as follows: Artificial Intelligence is software based automated data analysis that generates non-deterministic outputs through statistical models, includ‐ ing machine learning.- The word intelligence lends additional misconceptions to AI. Many tend to understand it as human intelligence or super-human intelligence. In contrast to the versality of creative and rational human thinking, AI merely simulates human intelligence. The output of AI may look like the result human thinking. But it is the result of statistics. It is neither creative nor the outcome of evidence-based reasoning. AI cannot create new complex perceptions based on rationale. What are the special capabilities of AI? With statistical methods, AI can identify and compare patterns and detect anomalies. AI can filter regular patterns from the inputs received. With vast speed it can identify similar patterns and compare and connect them based on calculated probabilities. This AI capability can be used for the detection of anomalies, for example in images for medical diagnostics, in sensor data for automated navigation in uncertain environments or in network activity for cyber threat detection. Based on the identification and comparison of patterns, AI can take a more active role and reproduce similar patterns. This capability called generative AI is a strong tool for modelling and predictions of developments. An example is the modelling of the state of space debris in Earth orbits. AI applications today are not as versatile as human thinking. They excel in limited areas as expert systems. Today, generative AI can create new contexts in areas like images, audio, video and language. Taking language as an example, with so-called Large Language Models (LLM), AI can be trained by using large amounts of text for recognizing, processing and generating a human language. AI can thus achieve a high level of proficiency 6.2 Artificial Intelligence 133 <?page no="134"?> in producing text. The text output may read like that of a human, but it is the result of statistics. With a Large Language Model, AI does not create its own consciousness about the meaning of this text. Expert systems work well when their structural rules can be realistically portrayed in a statistical model, for example the grammar and semantics of a human language. Algorithms play a central role in AI. They form the core of AI software. Algorithms are finite sequences of mathematical instruction sets to perform a specific task. They process informational inputs following their pre-de‐ termined logic based on defined circumstances. So-called reinforcement learning algorithms enable AI to learn optimal processing methods through trial and error, for which they receive rewards or penalties as feedback. AI is data dependent. Data inputs need to represent evidence-based facts for AI to produce meaningful outputs for real world solutions. Factually correct and unbiased input is crucial for AI to create information that matches reality. However, in AI analytics, quantity defeats quality. It creates outputs based on statistical quantity of information. AI cannot verify if data represent real world facts. Quality assurance for data inputs requires human control and oversight. Sensors can be a data source for AI. For example, for situational aware‐ ness and collision avoidance, automated traffic applications can use optical sensors for different wavelengths, radar, and laser-based light detection and ranging (LiDAR). Sensors can create independent data inputs designed for the given purpose. However, sensors may not fully capture the entire scope and scale of details for a complete depiction of reality. Information in data bases for scientific purposes should be screened to contain only selected and verified data for producing realistic results of AI analysis. For example, for medical diagnosis AI can be trained with verified images of malign and benign cell structures. AI can compare the verified images with images taken of a patient and indicate the best matches - to be confirmed by a medical professional. The rigorous screening and verification of data bases used as input determine the quality of this diagnostic method. The internet is not a good source for AI data inputs. Information on the internet is not verified, and not all websites are trustworthy. Information bubbles and echo chambers on the internet distort the quantitative repre‐ sentation of information. Safety-relevant and scientific applications require a higher standard of quality and verification. Moreover, internet-based data inputs for AI are prone to the same cyber vulnerabilities as other activities on the internet. Manipulated data streams can lead to distorted AI outputs. 134 Chapter Six · Automation and Artificial Intelligence <?page no="135"?> 18 For the following list, see An AI Glossary, Aviation Week &Space Technology, 13-26 January 2025, p.-41. 6.2.2 Artificial Intelligence in Aviation and Space Operations The aviation and space sectors traditionally have a high level of automation. AI is emerging in these sectors. However, for reasons of safety the industry is cautious with AI controlled automation of kinetic functions, like flight control and air traffic control. Numerous applications in the aviation and space sectors can be supported by AI: 18 • For designing aircraft and spacecraft, generative engineering helps to optimize designs, structural components and aerodynamic properties. • Predictive maintenance is a proactive strategy which uses sensors and automated tools to analyse the technical state of equipment for scheduling maintenance before potential failures happen. • Flightpaths of aircraft and air traffic control routing can be optimized. • Obstacle recognition and swarm coordination for unmanned aircraft systems. • Space object trajectory optimization, including spacecraft navigation, target detection and collision avoidance. • Natural language processing can for example support voice-controlled cockpit systems, monitor and analyse air traffic control communications and analyse maintenance logbooks. • AI supported computer vision can assist in obstacle detection and avoidance, landings, image-based navigation, target recognition and augmented reality flight training. • Satellite imagery can be analysed with support of AI as one field of Big Data. 6.2.3 Legal Considerations AI is a versatile feature. Legal implications of its use depend on how AI is applied and how it interacts with other legal subjects. AI can be used as an instrument to control kinetic or non-kinetic automated systems up to the level of autonomy. The key legal issues of autonomous systems with kinetic functions are responsibility, control and attribution when there is no human in the control loop. For these autonomous systems there is no difference whether 6.2 Artificial Intelligence 135 <?page no="136"?> 19 See supra 1.2.5. 20 For example, the European Commission used AI ethics guidelines established by an expert group as a foundation for the EU Artificial Intelligence Act; EU guidelines on ethics in artificial intelligence: Context and implementation, European Parliamentary Research Service, EPRS BRI (2019) 640163; High-Level Expert Group on Artificial Intelligence, Ethics Guidelines for Trustworthy AI, High-Level Expert Group on Artificial Intelligence, 08 April 2019. they are logic controlled by AI or by conventional software. Legal implica‐ tions can be mitigated or prevented with spatial or functional separation of the effects those systems have on others. AI used for the non-kinetic functions comprises the creation of infor‐ mation. Legal issues arise when two conditions are met. Firstly, AI generated information is spread or made accessible and, secondly, it affects the rights of others. The internet and AI models on connected cloud platforms 19 play a crucial role in the indiscriminate distribution of information. When images, audio or video are processed with AI in a way to create false impressions of the actions, statements or opinions of individuals or organisations, their rights are affected. Factually incorrect, unfair or defamatory information violate the personal and privacy rights of individuals. The digital manipula‐ tion of images, audio or video of a persons, objects or events for the purpose of maliciously spreading false information is commonly called deep fake. In the relationship between States the distribution of false AI generated information is a matter of propaganda and can influence public opinion, also for interfering with democratic processes in another State. Ethics is considered as a possible means for assuring the rule of law when applying AI functionalities. Ethics describes a set of moral principles for proper and fair human behaviour in societal relations. Different to law, ethical principles are not binding. Ethics can serve as guidance for binding legal regulations 20 but should not be understood as a stand-alone tool for self-regulation by the AI industry. Non-binding and non-enforceable ethical norms alone cannot sufficiently protect fundamental rights of users and third parties. Trustworthiness is considered an important element for AI. Trustwor‐ thiness is a social concept which evolves from the subjective experience of users. Users trust an AI application resulting from their practical experience when they consider it safe, secure, fair and usable for their purposes. The EU High-Level Expert Group on Artificial Intelligence has established a list with 136 Chapter Six · Automation and Artificial Intelligence <?page no="137"?> 21 High Level Expert Group, id., The key requirements are human agency and oversight, technical robustness and safety, privacy and data governance, transparency, diversity, non-discrimination and fairness, environmental and societal well-being and accounta‐ bility. 22 Like OpenAI, Anthropic, Meta, Cohere, xAI. 23 Like Amazon Web Services, Microsoft Azure, Google Cloud Platform. 24 Regulation (EU) 2024/ 1689 (AI Act), supra note 16, Article 3 (3). 25 Regulation (EU) 2024/ 1689, id., Article 3 (4). 26 About responsibility for automated and autonomous systems, see supra 6.1.3. seven (objective) key requirements for trustworthy AI. 21 The Group possibly used the subjective concept of trustworthiness instead of mandating their key requirements to be binding. Different to legally binding requirements, the concept of trustworthiness is weaker and non-binding. Various contributors have different roles in the creation, operation and application of AI. Legal responsibilities of contributors need to be appropriate to their roles. At the beginning of the chain, developers design and program AI models; 22 cloud and infrastructure providers run platforms for AI models. 23 The European Union calls this group ‘providers’. 24 Only when trained, AI models can be operated and used for specific kinetic or non-kinetic applications. The European Union calls commercial person and entities involved in the use and operation at the application level ‘deployers’. 25 Transparency is key for both, providers and deployers. The quality of the AI output depends on the quality of the algorithm and of the data inputs and training. Algorithms may not exactly portray the rules of structure or they may be biased. The intentions of the programmer of the algorithm may be different than those of the operator or end user. Equally important, also the quality of data inputs impacts the learning process of AI. This puts quality requirements on the data source, their selection, and objectivity. Regardless of their distance to a specific application, providers of AI models need to be transparent about the design and their algorithms’ structure, scope, priorities and impartiality. An operator’s responsibility for an AI enabled automated and autono‐ mous kinetic system should not be different to the responsibility of a similar non-AI enabled system. 26 In both cases, the operator should not be released from responsibility for this system only because he cannot stop it after he put it into operation. Consequences or damage which are typical and foreseeable according to general life experience and which result from the 6.2 Artificial Intelligence 137 <?page no="138"?> operation of an AI enabled kinetic automated or autonomous system need to be attributable to the system operator. Even when humans are (temporarily) out of the loop, their oversight is the link with their responsibility. Human oversight is a prerequisite for deciding if and when to intervene in an AI enabled autonomous activity and to take over human control. Responsibility for non-kinetic AI applications follows another concept. It relates to AI generated information and their release. Responsibility for AI generated information arises primarily through its distribution rather than its actual creation by AI. Its (detrimental) legal effects unfold when factually incorrect, unfair or defamatory information is released or made accessible to public, usually over the internet. Apart from the operator level, providers of AI models, whether used for kinetic or non-kinetic functions, should be responsible that the design, structure and function of their models meet the specification they commu‐ nicate to operators and users. The design of AI models, the underlying algorithms and the specific AI applications must comply with the rule of law. For AI which controls kinetic functions this means, first of all, the protection of fundamental rights, including life, health and property of all affected persons. For AI generated information additional focus must be on the protection of personal, privacy and intellectual property rights, prevention of hate-speech, non-interference with the public development of informed opinion, respect of democratic principles, impartiality and fairness. 6.2.4 EU Approach to Artificial Intelligence Earlier than other States, the European Union enacted detailed regulations for AI applications with the Artificial Intelligence Act (AI Act). The purpose of the AI Act which is binding in all EU Member States is twofold. Firstly, the AI Act is to “promote the uptake of human-centric and trustworthy artificial intelligence … while ensuring a high level of protection of health, safety, fundamental rights, including democracy, the rule of law and environmental protection, against the harmful effects of AI systems”. 138 Chapter Six · Automation and Artificial Intelligence <?page no="139"?> 27 Regulation (EU) 2024/ 1689, supra note 16, Article 1. 28 Ibid. 29 Regulation (EU) 2024/ 1689, id., Article 5. Exceptions apply, for example for narrowly defined objectives of law enforcement. 30 Regulation (EU) 2024/ 1689, id., Articles 6-27. Secondly, the commercial and industrial policy purpose is to improve the functioning of the internal European market and to support innovation. 27 The AI Act takes a risk-based approach. AI applications are regulated only as far as necessary to address specific levels of risk. Requirements and obligations are structured contingent upon different categories: prohibited AI practices, high-risk AI systems, certain AI systems and general-purpose AI models. 28 6.2.4.1 Prohibited AI Practices Prohibited AI practices apply to AI systems placed on the market and put into service which affect the personal sphere of individuals and include subliminal and manipulative techniques, which exploit vulnerability of people, their classification or remote identification through biometrics. 29 This category applies only to cases of personal information, their collection and evaluation. Automated or autonomous kinetic applications do not fall under this category. 6.2.4.2 High-Risk AI Systems AI systems are considered of high-risk, when they are used as a safety component of a product or fall under EU health and safety harmonisation legislation (e.g. toys, aviation, cars, medical devices, lifts). This category is tailored to automated and autonomous systems with kinetic functionalities. They are subject to a long list of requirements: risk management systems, data governance, technical documentation and record keeping, transpar‐ ency and provision of information to deployers, human oversight, accuracy, robustness and cybersecurity, and obligations of providers, deployers and other parties. Distinct obligations of providers and deployers are specified in detail. As one of the obligations, deployers of a high-risk AI systems shall perform a fundamental rights impact assessment. 30 6.2 Artificial Intelligence 139 <?page no="140"?> 31 Regulation (EU) 2024/ 1689, id., Article 50. 32 Ibid. 33 Regulation (EU) 2024/ 1689, id., Article 3 (63). 6.2.4.3 Certain AI Systems Less stringent are the requirements for so-called certain AI systems. This category comprises AI systems “intended to interact directly with natural persons … unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use.” 31 This category concerns non-kinetic systems which generate or analyze information, typically provided or distributed over the internet. Certain AI systems generate or manipulate synthetic audio, image, video or text content, and they can deploy emotion recognition and biometric categori‐ zation systems. Providers and deployers of such systems must be transparent about the involvement of AI. Affected individuals must be informed they are interacting with such an AI system or that information was artificially generated or manipulated. Manipulated information includes deep fakes. 32 6.2.4.4 General Purpose AI Models The European Union created the category of so-called general purpose AI models for assigning obligations to providers of AI models. They are distinct from obligations of deployers who integrate them for applications, which fall under the other three categories. AI models are software with algorithms which can be trained by vast datasets for accomplishing specific applications. A general-purpose AI model “… displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications …”.  33 Providers of general purpose AI model must draw up and keep technical documentation of the model, make documentation available to AI system providers who intend to integrate the model into their systems, make publicly available a summary of the data content used for training of the 140 Chapter Six · Automation and Artificial Intelligence <?page no="141"?> 34 Regulation (EU) 2024/ 1689, id., Article 53.1. 35 Regulation (EU) 2024/ 1689, id., Article 3 (65). 36 Regulation (EU) 2024/ 1689, id., Article 55.1. 37 For example, when image or video manipulations put a person into a sexual context. 38 EASA, Artificial Intelligence Roadmap 2.0, Human-centric approach to AI in aviation, May 2023. 39 Regulation (EU) 2024/ 1689, supra note 16, Preamble (50), Article 6.1 (a), Annex I B. 20. 40 Regulation (EU) 2024/ 1689, id., Article 108, which amended Articles 17.3, 19.4, 43.3, 47.3, 57, 58.3 of Regulation (EU) 2018/ 1139 of the European Parliament and of the Council of 4 July 2018 on common rules in the field of civil aviation and establishing a European Union Aviation Safety Agency (EASA Basic Regulation). model, and put in place a policy compliant with copyright and related rights. 34 Additional obligations apply for providers of general purpose AI models with systemic risk, which pertains to AI models with “a significant impact on the Union market due to their reach, or … negative effects on public health, safety, public security, fundamental rights, or the society as a whole …”.  35 Providers of general-purpose AI models with systemic risk must further perform model evaluations, assess and mitigate possible systemic risks, keep track of serious incidents and corrective measures and ensure an adequate level of cyber and physical security. 36 The EU deserves credit for being a pioneer in the regulation of AI and its applications. In practice however, it appears difficult to draw clear dividing lines between the established categories. When does a deep-fake of a ‘certain AI system’ become a prohibited practice? 37 Within the category of high-risk AI system, the EU approach mixes AI with automation of kinetic systems. These points add complexity. The overall regulatory system of the AI Act is administratively heavy. Its level of detail complicates practical implementation. It is questionable whether the detailed AI Act has a chance to succeed in a networked world with cross-border business models. 6.2.5 EASA Approach to Artificial Intelligence The Artificial Intelligence Roadmap 2.0 38 is the European Union Avia‐ tion Safety Agency’s concept for implementing AI in aviation. The EU AI Act categorizes AI systems in civil aviation as high-risk systems when they are safety components. 39 To that end, the AI Act 40 amended the EASA 6.2 Artificial Intelligence 141 <?page no="142"?> 41 Regulation (EU) 2024/ 1689, id., Articles 8-15. 42 EASA AI Roadmap, supra note 38, section G.1. 43 Supra 6.1.2. Basic Regulation for rulemaking in the areas of airworthiness, air traffic management, air navigation services and unmanned aircraft, so that the requirements for high-risk AI systems, which are safety components, are taken into account. Consequently, EASA delegated and implementing acts which relate to AI systems as safety components in said areas must consider as requirements: risk management systems, data governance, technical doc‐ umentation and record keeping, transparency and provision of information to deployers, human oversight, accuracy, robustness and cybersecurity. 41 The Artificial Intelligence Roadmap is focused on high-risk AI systems with kinetic functionalities. Within this high-risk category, EASA intends to follow an AI trustworthiness concept for which it distinguishes different levels of automation: “Level 1 AI: Assistance to Human 1A: Human augmentation 1B: Human cognitive assistance in decision-making and action selection Level 2 AI: Human-AI Teaming 2A: Human and AI-based system cooperation 2B: Human and AI-based system collaboration Level 3 AI: Advanced Automation 3A: AI-based system performs decisions and actions overridable by humans, 3B: AI-based system performs non-overridable decisions and actions [autonomy] (e.g. to support safety functions upon loss of human oversight)”  42 Flight and cockpit automation are well advanced. Many shortcomings of automation have been experienced and studied. 43 However, the Roadmap does not address known issues of flight and cockpit automation, like defi‐ ciencies of sensors and human-machine interfaces. The Roadmap follows the EU’s objective of achieving trustworthy AI, instead of emphasizing the trust of flying customers in air transportation. Passengers’ trust is built upon a solid safety track record of aircraft, not on a hypothetical trust in a virtual black box component which non-deterministically controls an aircraft. The Roadmap’s level 3 B, non-overridable autonomy for aircraft high risk functions, must be questioned. Taking humans out of the loop, 142 Chapter Six · Automation and Artificial Intelligence <?page no="143"?> 44 EASA AI Roadmap, supra note 38, section H. 45 UNGA Res. 78/ 265, 21 March 2024, Seizing the opportunities of safe, secure and trustworthy artificial intelligence systems for sustainable development. without possibility for intervention, eliminates human oversight and control functions necessary as a correlate for human responsibility. The EASA Roadmap follows the EU’s concepts for AI industrial policy and regulation. The EASA Roadmap seems to support the integration of AI in aviation high risk functions not for safety reasons, but for AI industry and EU policy demands. The EASA rulemaking concept for AI is a flow-down from the EU AI Act. 44 Considering the existing high level of automation in aviation, traditional software in aviation high-risk functions should only be replaced by AI software, when there is a compelling proven safety requirement to do so. 6.2.6 UN Approach to Artificial Intelligence The United Nations General Assembly Resolution on Artificial Intelligence of 21 March 2024 45 addresses AI in the context of sustainable development goals and of bridging the digital divide between nations and regions of different levels of development. This landmark resolution was backed by more than 120 nations and adopted without voting. Albeit not legally binding, this resolution highlights basic principles applicable to AI, as it “2. Resolves to promote safe, secure and trustworthy artificial intelligence systems … 5. Emphasizes that human rights and fundamental freedoms must be respected, protected and promoted throughout the life cycle of artificial intelligence systems, calls upon all Member States … to refrain from or cease the use of artificial intelligence systems that are impossible to operate in compliance with international human rights law or that pose undue risks to the enjoyment of human rights, … 6. Encourages all Member States … to promote safe, secure and trustworthy artificial intelligence systems in an inclusive and equitable manner, and for the benefit of all, … 7. Recognizes … that data is fundamental to the development and operation of artificial intelligence systems …“. 6.2 Artificial Intelligence 143 <?page no="144"?> 46 For example, Regulation (EU) 2023/ 1230 of the European Parliament and of the Council of 14 June 2023 on machinery, Directive 2001/ 95/ EC of the European Parliament and of the Council of 3 December 2001 on general product safety. 47 For example, Regulation (EU) 2016/ 679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation). 6.3 Cyber Nexus of Automation and AI Many automated systems and AI are dependent on cyber, or more precisely on network and internet connectivity and data. Connectivity offers commu‐ nication channels for data. The internet stands also for vast amounts of data which can be used for different purposes. The role of connectivity is different for automated systems with kinetic or non-kinetic functionalities. Data inputs for networked automated systems with kinetic functions usually consist of data for command-and-control and for situational aware‐ ness. Networked command-and-control inputs for kinetic applications are a characteristic of applications of the Internet of Things. Command and control inputs are important for all levels of automation, also for human override commands in autonomous applications. Situational awareness data can originate from connected external sensors or from sources available on the internet, like weather information. Data from open internet sources require verification and quality assurance. Data outputs mostly consist of data on the status of the system, to provide information for human oversight, and possibly for contributing to situational awareness of other systems, for example for collective swarm control. The physical action of an automated kinetic system does not take place in the virtual sphere. Regulations on health and (physical) safety apply to the protection of fundamental rights of impacted persons, 46 also when they are affected by kinetic functions of automated systems. Automated systems with non-kinetic functions analyse and gener‐ ate information. This is increasingly accomplished with AI. They can receive and collect data through networks. Depending on the purpose and the quality of the processing and analysis, data inputs from open sources over the internet require filtering, verification and quality control. Different to kinetic systems, the product of non-kinetic systems is information which can be digitally distributed over the internet. Distribution and release of incorrect, unfair or defamatory information can violate privacy rights 47 and intellectual property rights. Regardless how it is created, incriminating 144 Chapter Six · Automation and Artificial Intelligence <?page no="145"?> 48 See supra 6.2.4. 49 Regulation (EU) 2022/ 2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services (Digital Services Act), Article 6.1. 50 Leaving aside the common practice of creating several layers of companies with ownership relations for attempting to disguise and escape obligations of human control and taxation. 51 See also Convention on Access to Information, Public Participation in Decision-making and Access to Justice in Environmental Matters, 25 June 1998, 2161 UNTS 447, Article 9.3. content is attributable to persons who bring it into circulation. For the digital distribution of information generated or manipulated with AI, the requirements for certain AI systems apply as well. 48 Platform operators of websites or social medial who host incriminating information must expeditiously remove or disable access to the illegal content upon obtaining knowledge or awareness of the illegal activity, to escape liability under the EU Digital Services Act. 49 For the reason of data dependency and internet connectivity, automated systems and AI applications require cyber security measures like other digital systems, networks, data and information. 6.4 Side Note: Legal Personality? There is no reason for granting AI applications legal personality or treating them as distinct subjects of law. The widespread perception of AI as similar or superior to human intelligence seems to fuel such ideas, also for humanoid AI enabled robots. The structure and nature of AI and its applications do not fulfil the legal requirements and societal motivation for granting legal personality. Legal personality is the characteristic of being a subject of law. Subjects of law interact with each other as equal partners with mutual rights and obligations. Legal orders also recognize non-human entities as legal persons, for example incorporated companies. They bear own legal rights and obligations and can legally interact with other legal subjects. Despite their separate legal personality, there is always a human who takes effective control of these artificial entities. 50 The same applies to States under public international law; States act through humans who represent State organs. Furthermore, legal orders can establish protective rights or standing in court for animals or the natural environment. 51 6.4 Side Note: Legal Personality? 145 <?page no="146"?> However, there is no reason to treat AI, AI applications or AI controlled robots as equal partners of humans and other legal entities. There are likewise no legal requirements and no societal motivation to grant AI applications own rights or to release them from human responsibility. For what reason should AI be granted fundamental rights for the protection of its life, health, property and privacy? Why should AI be granted protective rights like those for animals or the environment? What would be the societal benefit of recognizing such rights? Should humans be allowed to switch off an AI application which violates someone’s rights, or should this AI application have a right to continue its ‘life’, perhaps subject to social rehabilitation? Human responsibility does not match with a construct of distinct legal personality for AI. AI is a tool for humans. Humans can employ it in numerous ways to support human activity. AI applications work for humans, not for themselves. For that reason, humans retain responsibility and oversight of AI-controlled activities. If AI applications were granted legal personality, it would abolish human oversight and control. Moreover, it implied the transfer of responsibility to AI applications for their activities, and of liability for their AI generated (detrimental) results. The creation of a distinct separate legal personality would release humans from their responsibility and liability for AI applications, although they engaged them in the first instance. The protection of potentially affected persons precludes releasing humans from their responsibility for AI applications. 6.5 Remarks The dividing line between automation and AI is blurred. Software is a tool for information and computer technology-based automation. AI is a special type of software which can control automation in more sophisticated ways than traditional software. The blurred dividing line between automation and AI in the technical field tends to lead to mingled concepts for regulating AI. In automation, legal issues are most prominent in autonomous systems as the highest level of automation. Key issues are humans out of the control loop, shortcomings of the human-machine interface and improper portrayal of the real-world situation by sensors. The control loop issue in autonomous systems is a question of the relationship between humans and machines. The approaches of engineering 146 Chapter Six · Automation and Artificial Intelligence <?page no="147"?> and law are different. From an engineering perspective, there are two opposite schools of thought. On the one side, autonomous machines are held to be superior to humans in all situations; no human intervention is required. On the other, humans are held to be superior and therefore should have the chance to intervene, when they deem it necessary. From a legal perspective, the concept of (human) responsibility prevails. As subjects of law, humans are responsible for their activities in relation to other subjects of law. Applying the concept of adequate causation, their activities can be attributed to them, also when sequences of actions are executed autonomously. As subjects of law, humans must be able to exercise oversight over autonomous systems and to retain sufficient control for intervening, when necessary. Human responsibility carries the special obligation of continued supervision and control when releasing automated activities into service, from the point before humans go (temporarily) out of the loop. Contrary to that, a machine cannot replace a human as a subject of law and bear its legal responsibilities. Practical experience, for example in aviation, shows the critical role of human-machine interfaces in automation. These interfaces, also called user surfaces, must be designed to allow humans to physically and mentally interact and interfere with automated and autonomous systems in an intuitive fashion. From a legal perspective, human-machine interfaces are a means of exercising human responsibility. Interfaces provide human access to systems for intervening as a means to supervise, oversee and control automated activities and to establish the human role in the control loop. Practical experience in aviation shows the critical role of sensor data in flight automation. Their input is required for a realistic portrayal of real-world situations. Malfunctioning or insufficient sensors and weak‐ nesses of their designs continue to be weak spots for automation. It seems unlikely AI can overcome these shortcomings. The difficulties of regulating AI are somewhat different. The central problem concerns the depiction of non-deterministic working methods for regulating the protection of users and affected persons. Algorithms are unknown black boxes, unless their creators and programmers are transparent and disclose their designs, priorities and biases. The application level of AI is the connecting point with automated systems for kinetic or non-kinetic functionalities. It is at the application level where AI controls an automated system. Transparency is required about the training and purpose of AI applications and whether they serve the interest and intentions of the end user. Statistical models cannot qualitatively evaluate a real-world 6.5 Remarks 147 <?page no="148"?> situation. From a legal standpoint, software developers of AI models and creators and trainers of AI applications bear responsibility for their products under the same rationale as operators of automated systems. The actions of their products are attributable to them as socially adequate consequences of their business motivated endeavour. They must use due diligence when they design and train their products to generate reasonably foreseeable results. Not unlikely, actors will try to escape responsibility, and liability in case of damage, by finger pointing to other players in the multi-layered value creation chain. Information and computer technology, including automation, IA and cyber, is an industrial endeavour which follows economic rationales. In‐ ternet based businesses are built on scalable multiplication to produce increased output and profit. This industry promotes reliance on one system, most notably the internet, for cost savings, interoperability and economic scalability, but does neither promote system redundancy and diversity, nor geographical or national independence. In contrast, system redundancy and diversity are a hallmark of the aerospace industry’s traditional safety focus. Moreover, economic rationale considers humans in the value chain as a cost factor. From this perspective, automation and AI are suitable instru‐ ments for reducing human involvement. Repetitive human functions should be automated for cost savings, but what are repetitive functions? Statistics is not a good judge. Humans have more control functions than statistics show or algorithms pretend. Automation and AI can rationalize many automated kinetic functions and analyse and generate information. But it creates new systemic weaknesses and failures which need human interaction. Human controllers of automated systems need to act as supervisors and humans in the loop. Humans must filter and verify artificially generated and manipulated information to warrant correct and fair information. Statistics cannot replace facts. Humans need to protect truth. Humans need to protect humans and property. Regulation of automation and IA must appreciate the (supervisory) role of humans and resist the temptation to take them out of the loop for cost reasons. 148 Chapter Six · Automation and Artificial Intelligence <?page no="149"?> For further reading Arnaud, Andreas von / Decken, Kerstin von der/ Matz-Lück, Nele (eds.), German Yearbook of International Law - Focus: International Law and the Dehumanisa‐ tion of Activities, Vol. 60 (2017), Duncker & Humblot, Berlin, 2018. Grundmann, Thomas/ Hey, Johanna/ Hobe, Stephan et. al. (eds.), Die Macht der Algorithmen, Vol. 1, Nomos, Baden-Baden 2023 Kaiser, Stefan A./ Mejia-Kaiser, Martha, Cyber Security in Air and Space Law, German Journal of Air and Space Law, Carl Heymanns, Vol. 64, 2/ 2015, p.-396 Kaiser, Stefan A., Legal Approaches to Network Driven Space Applications, in Blount, P.J. et.al. (eds.), Proceedings of the International Institute of Space Law, Eleven, The Hague 2017, p.-215 Kaiser, Stefan A., The Concept of Interference in Telecommunications, Outer Space and Cyber Activities, German Journal of Air and Space Law, Carl Heymanns, Vol. 71, 4/ 2022, p.-579 Kaiser, Stefan A., Autonomous Systems and Artificial Intelligence in Air and Space Law, in: Hobe, Stephan (ed.), Liber Amicorum instituti iuris aeris, spatialis et cybernetici in centenarium, Carl Heymanns 2025, p.-501 Mejía-Kaiser, Martha, The Geostationary Ring: Practice and Law, Chapter 9: Un‐ authorized Cyber Activities, Brill/ Nijhoff, Leiden/ Boston 2020 |- 🔗 https: / / brill .com/ display/ title/ 55905? srsltid=AfmBOoofrb6VsB7a_9ZvP8NOIfyBxDvNbLMA v8p9ApDX59YwbEhxrrRh Schmitt, Michael N. (ed.), Tallinn Manual on the International Law Applicable to Cyber Warfare. Cambridge University Press, 2013 Schmitt, Michael N. (ed.), Tallinn Manual 2.0 on the International Law applicable to Cyber Operations, Cambridge University Press, 2017 Scott, Benjamyn I., Aviation Cybersecurity: Regulatory Approach in the European Union, Eleven, The Hague 2019 Ziolkowski, Katharina (ed.), Peacetime Regime for State Activities in Cyberspace. International Law, International Relations and Diplomacy, NATO CCD COE Publication, Tallinn 2013 |- 🔗 https: / / ccdcoe.org/ uploads/ 2018/ 10/ PeacetimeReg ime.pdf <?page no="150"?> Index active eavesdropping-65 activities independently conducted by non-State actors-49 aeronautical administrative communication-85 Aeronautical Fixed Telecommunication Network (AFTN)-86 Aeronautical Operational Control (AOC)-85 aeronautical passenger communication-85 AI, generative-133 AI Models-140 AI Practices, prohibited-139 aircraft-43 aircraft flight automation-127 air-ground communications-84 airspace-38 Air Traffic Services (ATS)-85 AI systems-132 AI systems, certain-140 AI systems, high-risk-139 algorithms-134 application layer-18 armed attack-55 armed conflict-30, 54, 56, 131 artificial intelligence-131 Artificial Intelligence Act (AI Act)-138 Artificial Intelligence Roadmap 2.0-141 attribution-29, 69, 129 automated systems with kinetic functions-144 automated systems with non-kinetic functions-144 automation-123 automation in aviation and space operations-126 automation of kinetic functions-123 automation of non-kinetic functions-125 autonomous systems with kinetic functions-135 autonomy-124 availability-61 aviation sector-83 back doors-66 back-hacking-80 behavioural measures-73 behavioural preventive measures-28 Beijing Convention (2010)-97 Beijing Supplementary Protocol (2010)-98 best practice guidelines-114 big data-125 black-hat hackers,-68 botnets-65 breach of international obligations-50 Budapest Convention-52, 70 Caroline Case-55 cloud computing-20 commercial off-the-shelf (COTS) 87, 99, 104 communication security-64, 101, 105 computer-16 computer-related forgery-67 computer-related fraud-67 <?page no="151"?> computer systems with a flight safety impact-84 confidentiality-61 control loop-146 Convention on International Civil Aviation-90 copyright-32 Corfu Channel Case-48 criminal cyber activities-66 criminal law treaties-52 criminal liability-96 cyber activities-21, 45 cyber activities against aviation safety-relevant systems and networks-89 cyber activities with kinetic effects-51 cyber activities with non-kinetic effects-51 cyber crime-52 cyber criminals-68 cyber ecosystem-13 cyber environment-13 cyber-hygiene-73 cyber infrastructure in outer space-118 cyber security-59, 62, 101 cyber security measures-71 cyber space-12, 21, 44 data-16 data breaches-87 data dependent-134 data interference-67 data link layer-18 Denial of Service (DOS)-65 dentify and compare patterns-133 digitalization-14 digital market-31 Diplomatic and Consular Staff Case-48 Directed Denial of Service (DDOS)-65 Directed Denial of Service attacks (DDoS)-88 directed energy-25 directive (EU) 2022/ 2555-71 disclaimers-130 domain names-18 due diligence-129 effective technical control-129 electronic flight bags-86 encryption-76 ethics-136 European Convention for the Protection of Human Rights (ECHR)-41 European Space Agency (ESA)-114 European Union-92, 112, 138 European Union Aviation Safety Agency-92, 141 EU Space Act-113 expert systems-133 exploitation of supply chain vulnerabilities-66 exploitations of human behaviour-66 factual attribution-29, 49, 69 fair sharing of responsibility-130 firewalls-77 flight and payload control-107 Flight Management Systems (FMS)-83 fly-by-wire-83 fundamental rights-130 Global Navigation Satellite Systems (GNSS)-105, 115 grey-hat hackers-68 ground-ground communications-86 Index 151 <?page no="152"?> ground segment-103 Guidelines on Cybersecurity Measures for Commercial Space Systems-112 hackers-68 hacking-28 harmful radio interference-23, 115 high seas-38 human responsibility-146 human rights-41 humans in the loop-124 ICAO aviation cybersecurity strategy-91 ICAO cybersecurity action plan-91 illegal access-67 illegal interception-67 industrial espionage-88 information-16 Information and Communication Technology (ICT)-14 information content-31 information security-63 information society-14 integrity-61 intelligence-133 International Civil Aviation Organisation-90 International Civil Aviation Organisation (ICAO)-116 International Covenant on Civil and Political Rights (ICCPR)-41 International Humanitarian Law-57 International Law Commission (ILC) on State Responsibility-47 International Organisation for Standardization (ISO)-26 international spaces-37 International Telecommunication Union (ITU)-115 internet-17 internet law-14 Internet of Things (IoT)-20, 124 Internet Protocol (IP) based networks-17 Intrusion Detection and Prevention Systems (IDPS)-77 Isaac Asimov’s robot laws-130 ITU Constitution-115, 119 jamming-23 Jamming and spoofing of Global Navigation Satellite Systems (GNSS)-89 jamming and spoofing of radio signals-105f. Japan-112 jurisdiction-42 kinetic effects-51 kinetic functions-135, 144 large constellations-119 Large Language Models (LLM)-133 legal attribution-29, 47, 70 legal personality-145 liability-29, 117 Liability Convention-117 limited resource-119 low earth orbit-118-121 malware-65 measures-73, 75 methods-65 Montreal Convention (1971)-97 Montreal System-98 152 Index <?page no="153"?> motivation-68 National Aeronautics and Space Administration (NASA)-115 National Institute of Standards and Technology (NIST)-27 national legislation-110 national territory-37 Network and Information Security Directive (NIS2)-112 networks-17 Nicaragua Case-41, 55 non-binding standards-26 non-flight safety related computer systems-84 non-interference-40 non-kinetic functions-136, 144 onboard computer systems-83 on-line law-14 online platforms-33 open protocols and worldwide address coordination-19 operational measures-73 organisational measures-73 organisational preventive measures-28 outer space-38 outer space treat-110 Outer Space Treaty-44, 117, 119 packet switched data transmission-17 payloads-102 peripheral devices-19 personal jurisdiction-42 Physical Acts Against Infrastructure 23 physical layer-18 physical security-63 political independence-40 preventive cyber security measures-28 private liability-98 protection and processing of personal data-32 protection and processing of private non-personal data-32 protection of intellectual and data property rights-32 protocols-18 public international law-35, 39 quasi-territorial jurisdiction-42 radio navigation aids-85 ransomware-65, 87 redundancy-78 refraining from the use of force-40 Regulation (EU) 2018/ 1139-92 Regulation (EU) 2019/ 881-73, 79 Regulation (EU) 2022/ 1645-93 Regulation (EU) 2024/ 1689-132 remote control-124 responsibility-128, 137 right to privacy-32 risk management-72 robotics-123 robot laws-130 rule of law-138 safety-59 safety standards-80 satellite communications-102 satellite navigation-103 satellite remote sensing-103 security-59 security standards-80 selected and verified data-134 self-defence-55 Index 153 <?page no="154"?> sensors-134 settlement of disputes by peaceful means-39 ships-43 software-16 sophistication-69 sovereign equality-39 sovereignty-35 Space Attack Research & Tactic Analysis (SPARTA)-115 Space Attacks and Countermeasures Engineering Shield (Space Shield)-114 spacecraft-101 Space Industry Regulations (2021)-110 space objects-44 Space Policy Directive-5 (SPD-5)-111 space sector-101 space segment-101 spoofing-25 state-35 state responsibility-46, 117 system interference-67 system separation-78 technical measures-75 technical preventive measures-28 Telemetry, Tracking and Command (TTC)-104 territorial integrity-40 territorial jurisdiction-42 territorial sea-37 Threats-87, 105 Tokyo Convention-43 transparency-137 transport and internet layers-18 trojan-65 trustworthiness-136 unauthorised actors-68 unauthorised collection of data-106 unauthorised cyber activities-27 United Kingdom-110 United Nations-143 United Nations (UN) Charter-39 United Nations Convention on the Law of the Sea-43 United States of America-111 Universal Declaration of Human Rights (UDHR)-41 Unmanned Aircraft Systems-83 Virtual Private Networks (VPN)-76 viruses-65 vulnerabilities-65, 87, 105 waivers-130 Warsaw System-98 white-hat hackers-68 worms-65 zero-day-exploits-66 154 Index <?page no="155"?> ISBN 978-3-8252-6587-8 A quick introduction to the topic This English-language publication provides a concise introduction to the interdisciplinary field of cyber law. It explains terminology, defines the legal area and examines cyber law from an international law perspective. It also addresses legal aspects of cyber activities in the aviation and space sectors. Furthermore, it discusses the topics of automation and artificial intelligence. List of Chapters: 1. Introduction 2. Cyber Law and Public International Law 3. Unauthorised Cyber Activities and Cyber Security 4. Cyber Activities in the Aviation Sector 5. Cyber Activities in the Space Sector 6. Automation and Artificial Intelligence The book is aimed at students of law, aerospace engineering and computer science. Law | Aerospace Engineering Computer Science This is a utb volume from UVK Verlag. utb is a cooperation of publishing houses with one common goal: to publish textbooks and learning media for successful studies. utb.de Scan this QR-Code for further Information. Rules for the Digital Age