Skip to main content

Trust

4 – 6 March 2026

iStock-2156764471-scaled

Central to regulatory cooperation is trust. Trust is required both at the international level and the operational level. International government-to-government trust is a critical part of forming coalitions, which can be a vehicle for furthering dialogue (under the political banner outlined above) as well as inviting additional countries into the fold, thereby increasing the reach and effect of regulatory cooperation. At an operational level, trust is about the people delivering cybersecurity work, especially assurance work, and the way that work is done. Trust in the (assurance) process results in trust in the outputs of the process; in practical terms, regulators and organisations can use outputs produced by international partners without a high degree of additional scrutiny.

To build these kinds of trust, two recommendations should be considered. First (Recommendation VIII), regulatory cooperation requires steering and coordination. To meaningfully address the problem, action will be required in different settings, and it would be helpful to give legislators and regulators a view of what is happening across these different settings. Some kind of coordinating body or instrument should help increase transparency around the actions taken by participating legislators. Additionally, it could be used to share resources, challenges, and to identify new areas where interventions may be needed (for instance, new standards development work, in an area that might be ripe for regulation). This mechanism should also be used to ensure that efforts to address this problem are truly multistakeholder, and that different stakeholders can feed views into fora where they might not have an equal seat at the table. 

Second (Recommendation IX), directly addressing the opportunity to create trust in assurance work, there is an opportunity to create a shared cyber assurance model. This model would be used by assurance bodies to ensure confidence in the way assurance work is carried out in different jurisdictions, by enabling the bodies to recognise the work of international counterparts. Industry-focused member organisations would be well-positioned to develop this model, to involve international peers as appropriate, and to promote and raise awareness of the model among cyber assurance bodies and industry peers.

Want to find out more?


Sign up to our newsletter