Rules of Restraint for a Borderless Domain | Why Cyberspace Needs a Humanitarian Approach
Introduction
Every domain of conflict has eventually had to learn restraint. The first Geneva Convention of 1864 grew out of one man's horror at what he saw after a single battle, and it rested on an idea that has since become the backbone of humanitarian law: even in war, there are things that must not be done to people. Cyberspace is the newest domain to face that test, and it is arguably the hardest. Code carries no uniform, an intrusion crosses borders without anyone noticing, and the same network can serve a soldier, a shopkeeper and a schoolchild at once. Whether the actor is a criminal group, an intelligence service or a military cyber unit, the consequences land on ordinary people. That is the case for a humanitarian approach to cyberspace, and it is why it has moved from a courtesy to a matter of national security.
Why the humanitarian lens matters to every nation
Cyberspace does not sort itself into civilian and military zones. The International Committee of the Red Cross (ICRC) has pointed out for years that military networks lean on civilian cyber infrastructure such as undersea cables, satellites and routers, while civilian supply chains and essential services run over the same channels. A cyber operation aimed at one can land on the other, and the ICRC has warned that incidental harm in this domain risks being widespread and crossing national borders.
It helps to separate three situations, because different rules govern each. Cybercrime, such as ransomware against a hospital, is a matter for criminal law and international police cooperation. Intrusion and espionage in peacetime fall under domestic law and the norms of responsible state behaviour agreed at the United Nations. Cyber operations during an armed conflict fall under international humanitarian law (IHL), which the ICRC and a growing number of states hold applies to cyber means just as it applies to any other weapon or method of warfare. Its core principles, humanity, necessity, proportionality and distinction, were linked to cyberspace in the 2021 report of the UN Group of Governmental Experts. Under those principles civilians and civilian infrastructure must not be attacked, and medical facilities enjoy special protection.
For a nation, the practical point is simpler. Its own hospitals, grids, water systems and payment networks are exactly the assets that erode first when restraint erodes. A country that argues for humanitarian limits is protecting itself as much as anyone else.
A lesson from Lebanon
The events of 17 and 18 September 2024 in Lebanon show what happens when everyday technology stops being trustworthy. On the first day, thousands of pagers detonated across the country within roughly an hour of each other. The next day, hand held radios followed. By the account UN High Commissioner for Human Rights Volker Türk gave the Security Council on 20 September, at least 37 people had been killed, including two children, and more than 3,400 had been injured in Lebanon alone. UN experts noted that medical personnel were among the dead.
Attribution in this case remained a matter of public allegation rather than official claim, and this piece does not try to settle it. What matters here is the method and how the UN read it legally. Türk told the Council that IHL prohibits booby traps in the form of apparently harmless portable objects designed and constructed to contain explosives, and that violence intended to spread terror among civilians is a war crime. He added that striking thousands of people simultaneously, without knowing who held the devices, where they were or who stood nearby, violates international human rights law and, where applicable, IHL. His summary was that this cannot become the new normal, and he called for an independent, thorough and transparent investigation.
The pager episode was physical, with explosives concealed in hardware, not malicious code. It belongs in a discussion of cyberspace because of how it worked: a compromised supply chain turned an ordinary civilian communication tool into a weapon. That is the same trust relationship every digital system depends on. When people cannot assume that the devices and software they use are what they appear to be, the line between civilian object and military instrument, the foundation of humanitarian law, survives on paper while wearing away in practice.
The Digital Emblem Project
What it is:Think of the red cross on a hospital roof or an ambulance. It tells anyone who sees it that the building or vehicle is protected and must not be attacked. The Digital Emblem is the same idea for computer systems. It is a digital marker, built on a cryptographic signature, that a protected server or network broadcasts to signal that it belongs to a medical or humanitarian organisation entitled to protection under international humanitarian law. The organisations allowed to use it are the same ones entitled to use the physical emblem.
What it aims to achieve:Its purpose is recognition. Someone probing a network cannot see a red cross, and may not realise they have entered a medical facility's systems or a Red Cross office. The digital emblem lets that fact be detected and verified by machines, so a military cyber unit or any other operator can recognise the system and avoid it. It does not create any new legal protection, and it does not replace cybersecurity. Like the physical emblem, it cannot stop an attack on its own. It makes existing protection visible.
Why it was created:The physical emblem has worked for more than 150 years, but it has no natural place online. Cyber operations are becoming a regular feature of armed conflict, and humanitarian bodies are targeted by criminals seeking money as well as by state linked actors. The ICRC learned this directly in 2022, when a breach of its own servers exposed the data of more than 515,000 people in vulnerable situations. It began researching a digital equivalent and, with ETH Zurich, developed a technical standard.
Where it stands today:The idea has moved from concept to working prototype. In October 2024, Resolution 2 was adopted at the International Conference of the Red Cross and Red Crescent, which includes all 196 states party to the Geneva Conventions, affirming that the duty to respect and protect medical services and humanitarian personnel applies to their use of information and communication technologies. In July 2026, the ICRC, with Microsoft's support, presented the emblem in Geneva and announced the next phase, with several national Red Cross societies already testing it. That phase is expected to take several years. Technical standards still need to be developed through bodies such as the International Telecommunication Union and the Internet Engineering Task Force, and international law would need to recognise the emblem formally, through an amendment to the Geneva Conventions framework or a new protocol.
For nations, the emblem offers a practical way to mark hospital and humanitarian networks as off limits, and it removes the excuse of not knowing when a marked system is attacked. That makes accountability clearer. It also supports the central argument of this piece: humanitarian principles only work in cyberspace if they can be seen and acted on, not just written down. Its success will depend on whether the people it addresses, state cyber forces and criminal groups alike, choose to honour it, which is why adoption and enforcement at national level will matter as much as the technology.
What nations can do now
None of this requires waiting for a new treaty. A country can publicly state its national position on how international law, including IHL, applies to cyber operations, since the ICRC itself treats the publication of national views as a form of capacity building. It can classify healthcare, humanitarian, water and energy networks as protected critical infrastructure in its national cyber strategy, and plan to adopt the digital emblem for its own hospitals as standards mature. It can invest in supply chain assurance for the devices and software that civilians and governments depend on, which is the most direct lesson of the Lebanon episode. It can ensure that military cyber units are trained in IHL and that cyber capabilities undergo legal review with an eye to humanitarian impact. And it can treat ransomware against hospitals as the serious crime it is, backed by international cooperation on evidence and victim protection.
Conclusion
A humanitarian approach to cyberspace is sometimes dismissed as idealism. It is closer to enlightened self interest. Every state relies on the reciprocal restraint that keeps hospitals, grids and communications networks out of the crossfire, and every state is, at some point, on the receiving end of the alternative. The Lebanon episode showed how quickly trust in ordinary technology can fail, and the Digital Emblem shows one way the international community is trying to rebuild it. Nations that commit early, in doctrine, in procurement and in practice, will help decide whether cyberspace develops guardrails or simply learns to live without them. The idea behind the first Geneva Convention was that even conflict has limits. Cyberspace is where that argument now needs to be made again.
References
- ICRC, "ICRC proposes digital red cross/crescent emblem to signal protection in cyberspace." https://www.icrc.org/en/document/icrc-proposes-digital-red-crosscrescent-emblem-signal-protection-cyberspace
- ETH Zurich, "Digital emblem for humanitarian law in cyberspace." https://ethz.ch/en/news-and-events/eth-news/news/2023/11/digital-emblem-for-humanitarian-law-in-cyberspace.html
- Digital Watch Observatory, "ICRC unveils digital emblem to protect humanitarian organisations online." https://dig.watch/updates/icrc-digital-emblem-cybersecurity
- Geneva Solutions, "ICRC and Microsoft launch digital emblem to prevent cyberattacks." https://genevasolutions.news/peace-humanitarian/icrc-and-microsoft-launch-digital-emblem-to-prevent-cyberattacks
- "Making humanitarian protection visible in cyberspace: The promise of the Digital Emblem." https://blogs.microsoft.com/on-the-issues/2026/07/09/making-humanitarian-protection-visible-in-cyberspace-the-promise-of-the-digital-emblem/
- ICRC Humanitarian Law and Policy Blog, "IHL's lighthouse: navigating towards a digital emblem." https://blogs.icrc.org/law-and-policy/2026/01/15/ihls-lighthouse-navigating-towards-a-digital-emblem/
- Digital Watch Observatory, "Building Trust and Protection for Essential Digital Services: From Standards to Deployment." https://dig.watch/event/wsis-forum-2026/building-trust-and-protection-for-essential-digital-services-from-standards-to-deployment
- UN OHCHR, "Exploding pagers and radios: A terrifying violation of international law, say UN experts." https://www.ohchr.org/en/press-releases/2024/09/exploding-pagers-and-radios-terrifying-violation-international-law-say-un
- UN OHCHR, "Disrespect for international law is a matter of international peace and security, High Commissioner Türk tells the UN Security Council." https://www.ohchr.org/en/statements-and-speeches/2024/09/disrespect-for-international-law-a-matter-of-international-peace-and-security-hc
- ASIL Insights, "Cyber Operations under International Humanitarian Law: Perspectives from the ICRC." https://asil.org/insights/volume-24-issue-11/
- Pager Attack in Lebanon, CyberPeace Blog https://cyberpeace.org/resources/blogs/pager-attack-in-lebanon

.webp)



