Cyber warfare law turns on a threshold question the UN Charter never anticipated: when does an operation conducted through networks amount to a use of force under Article 2(4), or to an armed attack triggering the right of self-defence under Article 51? Most state cyber activity is deliberately placed below both lines. The Journal's work in this subject addresses the threshold itself, the frameworks proposed for locating it, and what states and companies actually do in the space beneath it.

From the Schmitt Analysis to the Tallinn Manual

The established approach to the use-of-force line has been a multi-factor assessment weighing such matters as the scope, intensity and directness of an operation's effects — an approach carried into the Tallinn Manual, the restatement prepared by a NATO-convened group of experts and published as Tallinn Manual 2.0 by Cambridge University Press in 2017. Cyber Redux: The Schmitt Analysis, Tallinn Manual and US Cyber Policy sets out James McGhee's argument that the Schmitt Analysis is outdated and inadequate to modern cyber threats, that the Tallinn Manual fails to provide concrete and actionable guidance, and that the United States needs a coherent cyber policy aligned with international law. Cyber Attacks and the Laws of War reaches a different assessment of the same body of law. Working through the jus ad bellum difficulty of defining force and armed attack, and then the jus in bello principles of military necessity, distinction, proportionality, perfidy and neutrality, it concludes that the existing framework, while imperfect, is a useful starting point for regulating the use of cyber weapons. Cyberwarfare: Attribution, Preemption, and National Self Defense proposes replacing the assessment altogether with an "Effects Test", and adapting the Caroline Doctrine on anticipatory self-defence to the cyber context under stricter scrutiny of the underlying intelligence.

What a third edition of the Tallinn Manual would have to settle

Whether the Tallinn Manual needs a third edition, and what such an edition would resolve, is the live question in this area. Tallinn Manual 3.0: Sovereignty and Attribution in 2025 argues that it does, and identifies three gaps. The first is attribution where an AI system initiates harmful conduct: effective-control and overall-control doctrines assume a state directing a non-state actor, and autonomous agents that adapt and execute without direct human input do not fit the model. The article proposes a rebuttable presumption of state responsibility for AI systems launched from government infrastructure or developed by national intelligence entities. The second is digital sovereignty, which the article argues should extend beyond physical intrusion to algorithmic control, data governance and cross-border digital infrastructure, given operations that target financial or electoral systems without causing physical harm. The third is hybrid conflict: pointing to coordinated sabotage efforts against the United Kingdom and to the India–Pakistan escalation, in which cyberattacks accompanied kinetic strikes and propaganda campaigns, it argues that cyber conduct embedded in a broader state strategy cannot be evaluated in isolation. AI Cyber Threats and the Future of Cybersecurity Law develops the same strain doctrinally, arguing that autonomy complicates intent, causation and attribution together, and that evidentiary standards come under pressure where an output cannot be traced back to human reasoning.

Below the threshold: response, reporting and the attribution timeline

Most cyber operations never approach Article 51. Cyber Warfare Legal Frameworks and International Law describes operations that disrupt infrastructure, manipulate information or steal data without physical damage, and the corresponding difficulty of deciding when such conduct is an unlawful intervention or a use of force. Comparative Cyber Incident Response turns to the consequences for the entities on the receiving end, comparing four regimes that each reflect a different theory of governance: sector-based oversight and market disclosure in the United States, harmonised risk management and notification duties in the European Union, national-security and data-control framing in China, and centralised rapid reporting in India. Its observation bears directly on the threshold debate — regulators generally trigger on impact rather than on certainty of attribution, so a company runs a technical-confidence timeline and a legal-notice timeline at once, and the article recommends treating attribution as a staged assessment rather than a precondition to reporting. It also notes that the Foreign Sovereign Immunities Act constrains private civil recovery against foreign states, since even where exceptions apply a plaintiff still carries the attribution proof burden. Resilience, Perseverance and Fortitude: Lessons from My Parents is an essay rather than a doctrinal piece: Rhea Siers argues from her parents' survival of the Holocaust that resilience and the development of norms for the responsible use of technology remain necessary in the cyber age.

The threshold, the response, and who can now reach it

Silicon Trenches: Use of Force in the Cyber Age states the structural problem plainly: an offensive cyber operation needs little more than a talented pool of hackers, a computer and connectivity, so a poor state can damage a richer one's infrastructure and economy without firing a shot. That democratisation of capability is what puts pressure on every threshold test in this subject.

Rethinking the Prohibition on the Use of Force in the Light of Economic Cyber Warfare: Towards a Broader Scope of Article 2(4) of the UN Charter presses on the threshold itself. Ido Kilovaty argues that Article 2(4) of the UN Charter should reach economic cyber-attacks and not only those producing physical effects, on the ground that the kinetic/non-kinetic distinction is outdated when severe economic harm is comparable to physical harm, and proposes factors for assessing when an economic attack qualifies.

On response, Cyber Enhanced Sanction Strategies: Do Options Exist? argues that financial sanctions frequently miss their targets and take years to bite, and proposes Cyber Enhanced Sanctions — digital techniques offering reversibility, secured communications and humanitarian relief through digital channels — applied to a case study of United States measures against Russia over Ukraine. The Supreme Art of War, on Subduing the Enemy without Fighting: Defending Defense Supply Chain Against Foreign Adversaries by Taking Proactive Measures to Enforce §889(a)(1)(B) of the Fiscal Year 2019 National Defense Authorization Act works a narrower statutory lever, the enforcement of §889(a)(1)(B) of the Fiscal Year 2019 National Defense Authorization Act against foreign adversaries in the defence supply chain.

On capability and warning, North Korea: The Cyber Wild Card 2.0 draws on the Department of Defense's reporting to Congress, which treats offensive cyber operations as a cost-effective route to asymmetric, deniable options for a state with a bleak economic outlook, and distinguishes the DPRK's aims from the PRC's espionage and commercial advantage. Cyber-World War III: Origins reads the trends of 2017 as warning signs by analogy to those underestimated before the First World War.