Skip to main content

Focus on 'why'

4 – 6 March 2026

iStock-2156764471-scaled

Regulation does not arise spontaneously; it is the result of careful deliberation by policymakers. Indeed, due to cost implications, regulation is a tool of last resort wielded only by governments when two conditions are met: a market fails to self-correct against (perceived) harms to consumers, the economy, or the environment; all other measures short of regulations, such as incentives, voluntary codes of practice or technical standards, have been exhausted without having the desired effect.

For cybersecurity, there is an opportunity to focus on why governments have decided that regulation is required and what the intended outcome is.  Although governments are often driven by similar imperatives, fragmentation is introduced, for instance, when i) regulation is used to pursue too many objectives; ii) when evidence for policy design and review is lacking; or iii) when regulations are developed without reference to existing international standards and norms.

Cyber regulation should be shaped by a clear purpose and designed to introduce only the minimum distortions necessary to achieve that purpose. The purpose should be maintaining resilience of important digital systems and keeping people safe. Focusing on the ‘why’ of cyber regulation leads to several potential actions.

First (Recommendation I), the process by which regulation is developed can be harmonised. At present, even if countries independently arrive at a similar decision that cyber regulation is required, once they reach this point, there is divergence in the way this regulation is developed, which results in different requirements. By adopting common approaches to regulatory development, countries are more likely to translate shared regulatory objectives (the ‘why’) into aligned regulatory requirements.

There is merit to developing a set of principles that could be used by governments to design and implement cyber regulations. Examples of such principles might include: i) anchoring regulations in international standards; ii) utilising common terms and definitions; iii) striving for co-creation with industry; iv) ensuring that regulations are evidence informed. The approach would benefit from being risk-based and largely or entirely outcomes-based, and should consider special measures for SMEs.

Participants suggested that an organisation like the OECD would be well-placed to develop and promote this work. The OECD is a well-established norm-setter and can convene different communities (for instance, through its regulatory policy work as well as its digital security work), and it could develop these principles as an OECD Recommendation. A major focus of this activity should be ensuring that any principles are adopted and used consistently in regulatory development processes.

Second (Recommendation II), a decision-making framework could be developed. This framework should help legislators when they run into questions around how to implement certain principles or where certain principles seem to conflict in a particular setting.

Third (Recommendation III), one area of cyber regulation that could be prioritised for more immediate wins is incident reporting. Existing regulations are generally very prescriptive around incident reporting, and detail between jurisdictions differ greatly, for example, around what qualifies as an incident, what information must be contained within a report, and within what timeframe an organisation must report an incident. Relatively small changes to incident reporting requirements could significantly reduce the burden faced by regulated organisations as well as regulators. More developed thinking about the purpose of incident reporting can help clarify timeliness, proportionality and information sharing, which can ultimately improve the interoperability of regulations.

Finally (Recommendation IV), the proliferation of artificial intelligence tools warrants consideration of the role AI might play in addressing the problem of fragmented cyber regulation. Part of the problem of fragmented regulation could potentially be addressed through AI, for instance, by handling the administrative burden or duplicative requirements. However, AI is not a silver bullet, since it cannot handle conflicting requirements and it cannot decide what to report. In thinking about the ‘why’ of this initiative, it is worth unpicking areas that cannot be resolved through AI as a priority.

Want to find out more?


Sign up to our newsletter