Santiago Lopez de Toledo

Policy & Legal

Policy Papers

Legal and doctrinal analysis of state behavior in cyberspace, grounded in the Tallinn Manual and international law.

NYU · Cyber Law · Legal & Strategic

Should Nation-States Retaliate Against Cyber Intelligence Operations?

A legal and strategic analysis using Operation Aurora and Stuxnet as case studies

Examines when a state may lawfully respond to a cyber intelligence operation under the Tallinn Manual 2.0, working through sovereignty, attribution, and the line between retorsions and countermeasures. Uses Aurora and Stuxnet as contrasting case studies to argue that retaliation should stay non-forcible even when a cyber operation crosses into use of force.

“Nation states not only should retaliate against CYBINT operations, but they must. Failing to respond to repeated cyber intrusions signals weakness.”
International LawTallinn ManualAttribution
Read PDF →
NYU · Cyber Law · Legal Analysis

The 2014 Sony Pictures Breach: A Legal Analysis

A companion legal analysis of the Lazarus Group operation, focused on jurisdiction and individual responsibility

Works through the Sony breach under the peacetime legal framework: attribution to North Korea’s Reconnaissance General Bureau, whether the operation constituted a prohibited intervention or use-of-force threat, and what jurisdiction the US actually held over the individual indicted. Concludes that while Park Jin Hyok holds no immunity, the US cannot enforce jurisdiction inside North Korean territory, leaving public attribution and sanctions as the only real remedy.

“State responsibility and individual responsibility operate at a parallel level; one does not exclude the other.”
JurisdictionState ResponsibilityExtradition
Read PDF →