In partnership with the Department for Science, Innovation and Technology, with support from TechUK
Executive summary
Cybersecurity regulation presents a fragmented landscape. This fragmentation can place a high compliance burden on regulated organisations while not necessarily improving security outcomes because a disproportionate amount of time and security budget is spent on administrative tasks rather than fulfilling critical cybersecurity functions.
The Wilton Park Dialogue showed that there is opportunity for governments and stakeholders to convene in an international effort to improve regulatory coherence across jurisdictions. This report identifies five core themes of the current situation discussed at the Dialogue and ten recommendations that would make a tangible difference for regulatory alignment. Participants discussed which organisations could take on the specific tasks, which included those present at the Dialogue as well as other institutions such as the Organisation for Economic Cooperation and Development (OECD) and the Group of Seven (G7).
Recommendations I, II, VII and VIII also contribute here.
1. Focus on ‘why’.
Regulation should be considered only where crucial, and it should be shaped by a clear understanding of its ultimate purpose: maintaining resilience of important digital systems and keeping people safe. Certain good practices should be deployed in regulatory policy development to ensure that regulations fulfil this ultimate purpose, are effective and efficient, and are coherent with approaches in other jurisdictions.
Recommendation I: Create common ‘good practice’ principles for developing cyber regulation and ensure these principles are utilised.
Recommendation II: Develop a decision-making framework for policymakers, to guide the utilisation of these principles and to help signpost users to useful resources (eg, useful existing research and other forms of evidence).
Recommendation III: Focus on tackling divergence around incident reporting requirements, which should bring immediate benefit to both regulated businesses and regulators. Agreeing on the fundamental purpose of this reporting may help jurisdictions move closer to aligning on the requirements they set.
Recommendation IV: Consider the role that AI can and can’t play in tackling the problem of cyber regulatory divergence across borders.
2. Political support.
Meaningful international regulatory cooperation on this topic requires high-level political buy-in. This is because cybersecurity is a cross-cutting domain, and choices around cybersecurity regulation can also have important national security, socioeconomic resilience, and economic competitiveness implications.
Recommendation V: Secure buy-in from key players in national cyber regulatory ecosystems as well as a central executive body of government
Recommendation VI: Improve the evidence base around the economic cost of misaligned cyber regulations.
Taxonomy. There is ample disagreement on definitions of core terminology used in cybersecurity regulation, and “speaking the same language” is a pre-requisite to international regulatory coherence.
Recommendation VII: Create a common taxonomy, building on existing resources.
3. Trust.
Cooperation on regulation requires trust in two aspects: international trust for coalition-forming, and trust in people doing work and the way that work is done.
Recommendation VIII: Support the creation of a mechanism to provide strategic direction and to support monitoring and accountability for this work.
Recommendation IX: Create an internationally shared cyber assurance model.
4. Sovereignty.
It is likely that certain regulatory requirements will remain misaligned. This is because national cyber regulations are linked to diverse threat pictures and socioeconomic contexts, and governments have different risk appetites and different levels of concern for digital sovereignty. However, if governments can align on 80% of their requirements, that will make a substantial difference to businesses’ compliance burdens.
Recommendation X: Construct and offer a regulatory requirements menu.
Introduction
Digitisation in organisations, combined with cyber threats emanating from a range of sources, has exposed critical cybersecurity vulnerabilities across countries’ economies. Given that the market has not successfully addressed these challenges by itself, many governments have intervened to establish, or are developing, cybersecurity regulations. However, differing approaches in the development of regulations have resulted in regulatory divergence. This divergence, in turn, places additional burdens on regulated organisations that must now comply with regulations across different jurisdictions. Aside from the economic cost of compliance, industry voices have also noted that the weight of adhering to these new requirements may also lead to ‘box ticking’ rather than thorough efforts to build meaningful cybersecurity. Industry has called for greater coherence in global cybersecurity regulations and for government-led progress in this space.
Fundamentally, there is an opportunity for governments to convene together with stakeholders to formulate ‘good practice’ principles for developing cyber regulation in a way that should reduce fragmentation. There is a need to expressly recognise that a problem exists, to understand the causes of the current situation, and build a shared commitment to improving it. Within this, stakeholders must be afforded opportunity to share their experiences and points of view. Further, there are both overarching approaches to regulation as well as specific details of cybersecurity which require elucidation. This clarification should help to identify the tangible actions that can be taken to impactfully address: i) issues identified in current regulations; and ii) the development of future regulation.
These efforts will help build an international community of partners who, with different strengths, can collectively achieve greater interoperability and cooperation around cyber regulation.