In the two ‘why’ areas of cyber regulation, with their ties to national and economic security, governments are often highly reluctant to relinquish sovereign control. These areas lie at the core of states’ fundamental responsibilities, and failing to, or appearing to fail to, take accountability and appropriate action in these areas could be politically prohibitive because these are two areas that citizens expect their governments to own. Therefore, the default response of governments when faced with challenges in this arena is to close ranks rather than open up. In addition, national cyber regulations are linked to specific domestic contexts, and this can mean that certain countries cannot align on particular requirements.
Consequently, international cooperation is something that must be fought for, rather than something that happens naturally. This dynamic can also result in a strong digital sovereignty push. In areas considered nationally sensitive (such as economic and national security), governments can seek to keep their population’s data within their own borders, and they can seek to ensure that their infrastructure is controlled by domestic entities. This might mean, for example, that incident report information is kept proprietary and shared with partners only on a need-to-know basis.
To address this constraint on international cooperation, potential actions can draw on recommendations noted previously in this report. First, high-level political support, for example through the G7, would not only create a unifying banner but also send a strong signal that countries are open to international cooperation. The more parties join this effort, the more normalised cooperation becomes, and countries that pursue a solely sovereign approach to cyber regulation will be outliers that do not benefit from the advantages afforded by regulatory cooperation. Additionally, it could be worthwhile considering ways to increase accountability around the efforts participating governments are taking to cooperate internationally, for instance, by developing a channel for governments to report on the actions they are taking.
Second, generating trust through a harmonised regulation development process, as well as a shared assurance model, could help overcome countries’ propensity to default to closed ranks. With increased trust, initiatives such as sharing information from incident reporting are more likely to gain traction, benefiting the wider international community. This could be used to improve the evidence base that should inform regulatory choices.
Linked to this, basing new regulations on existing international standards can support regulatory cooperation by providing a common, credible base. A range of stakeholders are naturally involved in the development of international standards, and this usually improves their applicability across various contexts as well as their quality for addressing a particular problem. This is why “anchoring in international standards” is suggested as one of the principles for a common set of good practices for developing cyber regulations.
Finally (Recommendation X), one approach may be to develop a mechanism that can help us to accommodate “an imperfect world”: help countries adopt mostly similar approaches while retaining elements that are unique to their context. This could be done through a ‘menu’ of regulatory requirements. Governments would use this menu to select elements to include in their regulations, with the ambition that around eighty per cent of requirements should be similar. This menu should create commonality between jurisdictions, yet also enable countries to select options which suit their contexts. Consistent with their sovereignty ambitions, this means that countries retain a degree of control over the whole menu and specific control over the bespoke elements. At the same time, regulated organisations would have a level of certainty that no more than one-fifth of requirements in any given jurisdiction would be novel, therefore decreasing the burden of compliance.