While cybersecurity is inherently a technological domain, regulation is a policy matter. Cyber regulation should be grounded in a deep understanding of the technical dimensions of the problem and of different response options, but it will also be informed by political choices. It is also a cross-cutting domain, which is linked to many different public activities and ministerial portfolios.
International cooperation on cyber regulation will require high-level buy-in and active support. This is for a variety of reasons, including: i) it will force trade-offs that only senior leaders can resolve, ii) it will require coordination across powerful institutions; iii) it signals credibility to partners and industry (that the direction of travel is stable); iv) it manages risk and accountability. A senior governmental champion can also help to marshal resources and inspire action. The core recommendation (Recommendation V) here is to identify and secure buy-in from a senior public figure who has significant influence in decisions made around cyber regulation, as well as a key figure or figures within a country’s executive branch. The former would create a banner under which other regulatory cooperation activities can be unified, and the latter would support coordination and additional pressure, where required.
Additionally (Recommendation VI), a rigorous analysis of the economic cost of misaligned cyber regulations could be developed. Such an analysis would explain to policymakers why they should care about this issue, why they should consider taking reform measures (that may not be easy) to address it, and which intervention areas they should prioritise. It should also help build political support behind reforms. Participants expressed the view that the OECD, which is an established and respected authority for data collection and analysis, would be well-placed to take this work forward.
Finally, they have also agreed that a high-level platform such as the G7 Leaders’ or Digital and Technology Track could be used to advocate for international cyber regulation cooperation and to highlight, at a high-level, cooperation in this space. This would help raise awareness of the initiative to participating governments, as well as among industry and other stakeholders in those countries.