Skip to main content

Taxonomy

4 – 6 March 2026

iStock-2156764471-scaled

It is abundantly clear that cyber regulation is rife with specialist terminology. This is expected, given it is a technical field, but it becomes a problem when the international community lacks agreed definitions on core terminology. Across jurisdictions, a term may be used to refer to different concepts/requirements, while different terms may be used to describe the same concept. The lack of consistency across the international landscape leads to different cyber regulations. For example, the definition of a reportable ‘incident’ can vary significantly between countries, even where regulations use the same term: ‘incident reporting’. Therefore, regulated entities need to keep track of these different definitions to know whether an incident triggers a reporting requirement in any given jurisdiction.

The recommendation (Recommendation VII) that flows from the terminology problem is to create a taxonomy. A taxonomy would contain agreed definitions to create a baseline from which governments can derive cyber regulations. By using the same terms consistently, countries can avoid unintended divergence between their cyber regulations. Participants noted that an institution like the OECD could take this forward, utilising existing resources (for instance, taxonomy work developed by the European Cyber Security Organisation) and potentially working with other partners, including those that attended this Dialogue.

Want to find out more?


Sign up to our newsletter