Process of formally attributing a cyber operation to a sovereign state or to entities acting at its direction or under its control.
State attribution is a process at once technical, legal and political, by which a cyber operation is imputed to a sovereign state or to entities acting at its direction or under its control. In the context of LMA cyber war clauses, it determines whether exclusions linked to state-backed cyber operations apply. The A versions of the clauses (5564A, 5565A, 5566A, 5567A) contain an explicit attribution clause specifying that the insured and insurer will consider such objectively reasonable evidence as is available, including formal or official attribution by the government of the state where the affected computer system is located. This wording does not alter the insurer's burden of proof but guides the method of assessment. The B versions lack it: attribution must then be proven under the law applicable to the contract. The Hamilton variant introduces a dispute settlement mechanism through an independent umpire in the event of persistent disagreement over attribution. Attribution is structurally difficult: it requires extensive forensic analysis, geopolitical intelligence and often public or governmental intelligence. It can be contested over time, and the absence of official attribution does not mean the state in question is not responsible.
After the 2021 Colonial Pipeline cyberattack, attributed to the DarkSide group without official state imputation, insurers were able to treat the claim as an ordinary cybercriminal act. In contrast, WannaCry (2017) was officially attributed to North Korea by the United States and the United Kingdom, potentially qualifying the attack as a state-backed cyber operation under LMA clauses.
attribution d'une cyberattaque, attribution d'une opération cyber, state attribution, attribution cyber