Red Cross publishes rules of engagement for civilian hackers
bbc.com
bbc.com
Do not direct cyber-attacks against civilian objects
Do not use malware or other tools or techniques that spread automatically and damage military objectives and civilian objects indiscriminately
When planning a cyber-attack against a military objective, do everything feasible to avoid or minimise the effects your operation may have on civilians
Do not conduct any cyber-operation against medical and humanitarian facilities
Do not conduct any cyber-attack against objects indispensable to the survival of the population or that can release dangerous forces
Do not make threats of violence to spread terror among the civilian population
Do not incite violations of international humanitarian law
Comply with these rules even if the enemy does not
Hackers engaging in warfare are not likely interested in laws. People responsible for securing things and protecting people should keep that in mind. Anyone engaging in warfare is effectively an enemy combatant in the eyes of their opponents regardless of being civilian or soldier.
[1] - https://www.youtube.com/watch?v=Wxi-IUnCN_8 [video][1 min]
Absolutely. I should have added that as well. Well meaning hacktivists may or may not be aware of or in denial about the risks they are taking on.
So from attacked parties' p.o.v., one can secure systems, mitigate attacks, take attacked systems offline, maybe counter-attack (like try wiping systems that attack, legal or not), but practically always the hackers behind an attack will remain out of reach. At most one may get lucky & identify attack as orchestrated by a specific hacking group.