Skip to main content

LUP Student Papers

LUND UNIVERSITY LIBRARIES

Viktlös folkrätt i cyberrymden? En kritisk analys av non-interventionsprincipen och ansvarsluckan vid cyberangrepp

Bokwall, Sofie LU (2026) LAGF03 20261
Department of Law
Faculty of Law
Abstract (Swedish)
Med hänsyn till det försämrade säkerhetspolitiska läget har cyberangrepp blivit ett allt vanligare inslag i internationella relationer. Eftersom dessa åtgärder sällan uppnår tröskeln för väpnat våld enligt FN-stadgans artikel 2(4) aktualiseras i stället den internationella sedvanerättsliga principen om non-intervention. Syftet med denna uppsats är att redogöra för och kritiskt analysera non-interventionsprincipens tillämplighet på cyberangrepp mot infrastruktur. Särskilt behandlas förutsättningarna för att utkräva statsansvar när operationer utförs av icke-statliga aktörer. Undersökningen genomförs med en rättsdogmatisk metod i kombination med ett kritiskt perspektiv, med huvudsaklig utgångspunkt i Internationella domstolens praxis,... (More)
Med hänsyn till det försämrade säkerhetspolitiska läget har cyberangrepp blivit ett allt vanligare inslag i internationella relationer. Eftersom dessa åtgärder sällan uppnår tröskeln för väpnat våld enligt FN-stadgans artikel 2(4) aktualiseras i stället den internationella sedvanerättsliga principen om non-intervention. Syftet med denna uppsats är att redogöra för och kritiskt analysera non-interventionsprincipens tillämplighet på cyberangrepp mot infrastruktur. Särskilt behandlas förutsättningarna för att utkräva statsansvar när operationer utförs av icke-statliga aktörer. Undersökningen genomförs med en rättsdogmatisk metod i kombination med ett kritiskt perspektiv, med huvudsaklig utgångspunkt i Internationella domstolens praxis, International Law Commissions artiklar om statsansvar samt expertdoktrinen Tallinn Manual 2.0.
Uppsatsen visar att den gällande folkrättsliga ramen har betydande brister av-seende att erbjuda drabbade stater ett ändamålsenligt skydd. Tillämpningen försvåras av att traditionella rekvisit är svårförenliga med cyberrymden. För det första utgör tvångsrekvisitet ett hinder. Cyberangrepp lamslår ofta samhällsviktiga funktioner men faller utanför den strikta definitionen av tvång, eftersom det saknar uttryckliga diktatoriska krav. För det andra medför det stränga kravet på effektiv kontroll för hänförbarhet en omfattande ansvars-lucka när stater utnyttjar privata hackergrupper. Slutligen konstateras att principen om tillbörlig aktsamhet brister som alternativ ansvarsgrund till följd av bevisproblem rörande staters kunskapskrav och territoriella kontroll.
Slutsatsen är att det rådande rättsläget i praktiken skyddar den angripande staten snarare än den drabbade. Så länge tongivande cybernationer i sin stats-praxis upprätthåller en strategisk tystnad för att bevara sin egen handlingsfrihet hämmas normutvecklingen. Cyberrymdens unika karaktär skapar alltså en rättslig obalans som det traditionella folkrättsliga systemet har svårt att hantera. (Less)
Abstract
In the context of a deteriorating security landscape, cyberattacks have become increasingly frequent in international relations. Because these operations rarely meet the threshold for the use of force under Article 2(4) of the UN Charter, the principle of non-intervention serves as the applicable legal framework. The purpose of this thesis is to describe and critically analyze the applicability of the non-intervention principle to cyberattacks targeting infrastructure. In particular, it examines the prerequisites for establishing state responsibility when such operations are conducted by non-state actors. The study uses a legal dogmatic method combined with a critical perspective, drawing primarily on the jurisprudence of the International... (More)
In the context of a deteriorating security landscape, cyberattacks have become increasingly frequent in international relations. Because these operations rarely meet the threshold for the use of force under Article 2(4) of the UN Charter, the principle of non-intervention serves as the applicable legal framework. The purpose of this thesis is to describe and critically analyze the applicability of the non-intervention principle to cyberattacks targeting infrastructure. In particular, it examines the prerequisites for establishing state responsibility when such operations are conducted by non-state actors. The study uses a legal dogmatic method combined with a critical perspective, drawing primarily on the jurisprudence of the International Court of Justice, the International Law Commission’s Articles on State Responsibility, and the expert doctrine Tallinn Manual 2.0.
The thesis demonstrates that the current framework of international law has significant shortcomings in providing adequate protection to targeted states. The application of the law is impeded by the difficulty of adapting traditional legal criteria to cyberspace. First, the element of coercion poses a major obstacle. While cyberattacks often paralyze vital societal functions, they fall outside the strict legal definition of coercion because they generally lack explicit dictatorial demands. Second, the strict requirement of effective control required for attribution creates an accountability gap when states use private hacker groups. Finally, the thesis concludes that the principle of due diligence fails as an alternative basis for responsibility due to evidentiary challenges regarding state knowledge and territorial control.
The conclusion is that the current legal paradigm, in practice, shields the at-tacking state rather than protecting the victim state. As long as leading cyber nations maintain strategic silence in their state practice to preserve their offensive freedom of action, the development of legal norms will be impeded. Consequently, the unique nature of cyberspace creates a legal imbalance that the traditional system of international law is ill-equipped to manage. (Less)
Please use this url to cite or link to this publication:
author
Bokwall, Sofie LU
supervisor
organization
course
LAGF03 20261
year
type
M2 - Bachelor Degree
subject
keywords
Folkrätt, cyberangrepp, cyberrymden, non-interventionsprincipen, suveränitet
language
Swedish
id
9228018
date added to LUP
2026-08-25 11:15:27
date last changed
2026-08-25 11:15:27
@misc{9228018,
  abstract     = {{In the context of a deteriorating security landscape, cyberattacks have become increasingly frequent in international relations. Because these operations rarely meet the threshold for the use of force under Article 2(4) of the UN Charter, the principle of non-intervention serves as the applicable legal framework. The purpose of this thesis is to describe and critically analyze the applicability of the non-intervention principle to cyberattacks targeting infrastructure. In particular, it examines the prerequisites for establishing state responsibility when such operations are conducted by non-state actors. The study uses a legal dogmatic method combined with a critical perspective, drawing primarily on the jurisprudence of the International Court of Justice, the International Law Commission’s Articles on State Responsibility, and the expert doctrine Tallinn Manual 2.0.
The thesis demonstrates that the current framework of international law has significant shortcomings in providing adequate protection to targeted states. The application of the law is impeded by the difficulty of adapting traditional legal criteria to cyberspace. First, the element of coercion poses a major obstacle. While cyberattacks often paralyze vital societal functions, they fall outside the strict legal definition of coercion because they generally lack explicit dictatorial demands. Second, the strict requirement of effective control required for attribution creates an accountability gap when states use private hacker groups. Finally, the thesis concludes that the principle of due diligence fails as an alternative basis for responsibility due to evidentiary challenges regarding state knowledge and territorial control.
The conclusion is that the current legal paradigm, in practice, shields the at-tacking state rather than protecting the victim state. As long as leading cyber nations maintain strategic silence in their state practice to preserve their offensive freedom of action, the development of legal norms will be impeded. Consequently, the unique nature of cyberspace creates a legal imbalance that the traditional system of international law is ill-equipped to manage.}},
  author       = {{Bokwall, Sofie}},
  language     = {{swe}},
  note         = {{Student Paper}},
  title        = {{Viktlös folkrätt i cyberrymden? En kritisk analys av non-interventionsprincipen och ansvarsluckan vid cyberangrepp}},
  year         = {{2026}},
}