Cyberspace has become the most consequential domain of contemporary geopolitics, yet its governance remains stubbornly under-institutionalized. Unlike the nuclear era, which produced treaties, verification regimes, and dedicated agencies within decades, cyber governance has evolved as a patchwork of overlapping and often competing forums.

The result is a landscape where the United Nations Group of Governmental Experts coexists uneasily with the parallel Open-Ended Working Group, where NATO's Cooperative Cyber Defence Centre of Excellence operates alongside bilateral confidence-building channels, and where private technology firms wield governance authority rivaling states. This institutional fragmentation reflects both the novelty of the domain and the deep normative disagreements between democratic and authoritarian powers.

What emerges is a governance architecture caught between aspiration and paralysis. Norms have accumulated on paper without meaningful enforcement. Attribution capabilities have advanced technically while remaining politically contested. Trust-building mechanisms exist but struggle to keep pace with escalation dynamics. Understanding this ecosystem requires moving beyond the treaty-centric assumptions of twentieth-century international law toward a networked model of governance, one that acknowledges the distributed, hybrid, and rapidly evolving nature of cyber threats and the institutions attempting to manage them.

Norm Development Progress and Its Limits

The UN Group of Governmental Experts (GGE) process, running intermittently from 2004 to 2021, produced what remains the foundational normative framework for state behavior in cyberspace. Its 2013 and 2015 reports affirmed that international law, including the UN Charter, applies to cyberspace, and articulated eleven voluntary norms of responsible state behavior.

These norms include prohibitions on attacking critical infrastructure, obligations to assist states responding to malicious activity emanating from their territory, and commitments to protect the integrity of the ICT supply chain. Their voluntary and non-binding character was both the price of consensus and the source of their weakness.

The 2021 bifurcation into parallel tracks, with the Russian-initiated Open-Ended Working Group (OEWG) running alongside a final GGE, revealed the deepening geopolitical fissures. Where Western states emphasize applying existing international law, Russia and China have pushed for a new binding treaty that would grant states greater sovereignty over information flows, a position with troubling implications for internet freedom.

Observance of stated norms has been inconsistent at best. The 2017 NotPetya attack targeted critical infrastructure globally. Ransomware campaigns emanating from permissive jurisdictions violate the due diligence norm routinely. Supply chain compromises like SolarWinds demonstrate the gap between declared principles and operational practice.

Yet the normative infrastructure is not empty scaffolding. It provides vocabulary for diplomatic protest, benchmarks for coalition-building, and reference points for domestic policy. Norms shape expectations even when they fail to constrain behavior, and their gradual accretion may prove more durable than treaty-based approaches ill-suited to a domain evolving faster than ratification cycles.

Takeaway

In domains evolving faster than treaties can be negotiated, voluntary norms may accomplish more through gradual expectation-shaping than binding rules accomplish through formal obligation.

The Attribution Problem and Deterrence Erosion

Deterrence theory, forged in the nuclear era, presupposes the ability to identify an attacker and impose costs credibly. Cyberspace inverts this assumption. Attacks routinely traverse compromised infrastructure across multiple jurisdictions, employ off-the-shelf tools that obscure sponsorship, and leverage plausibly deniable proxies including criminal groups operating with state acquiescence.

Attribution operates on three distinct levels: technical (which machines conducted the operation), operational (which group orchestrated it), and strategic (which political authority directed it). Each level requires different evidence and confers different legal and political implications. Confusion among these levels frequently muddles public discourse and diplomatic exchanges.

The institutional response has been uneven. Intelligence agencies have developed sophisticated attribution capabilities, but sharing evidence risks compromising sources and methods. Private threat intelligence firms increasingly perform public attribution, effectively privatizing a function historically reserved to states. Joint attributions, such as the coordinated Five Eyes and EU statements on Russian and Chinese operations, represent a partial solution through pooled credibility.

The attribution asymmetry further complicates deterrence. Democratic states face domestic legal and evidentiary standards before responding; authoritarian states do not. This asymmetry incentivizes gray-zone operations calibrated to remain below thresholds triggering coordinated response, producing what scholars have termed the persistent engagement dilemma.

Institutional innovation is emerging around this challenge. Proposals for an independent international attribution body, modeled loosely on the Organisation for the Prohibition of Chemical Weapons, remain politically unrealistic but conceptually illuminating. More promising are hybrid arrangements combining state intelligence, private forensics, and academic verification, a networked approach befitting the distributed nature of the problem itself.

Takeaway

When the technical difficulty of proving 'who did it' outpaces the political need to respond, deterrence gives way to ambiguity, and ambiguity favors those who care less about being seen as legitimate.

Confidence Building Measures and Escalation Management

Confidence-Building Measures (CBMs) draw on Cold War precedents, particularly the hotlines, notification requirements, and observation protocols that reduced miscalculation risks between superpowers. Their translation to cyberspace has been imperfect but instructive, with the OSCE producing the most developed regional framework through its 2013 and 2016 CBM decisions.

The OSCE measures include designated points of contact for cyber incidents, voluntary information exchange on national strategies and threat perceptions, and consultation mechanisms during periods of tension. Similar arrangements have emerged in the ASEAN Regional Forum and through bilateral channels, notably the intermittently functional US-China and US-Russia cyber working groups.

The theoretical logic is sound: escalation in cyberspace often stems from misperception rather than intent. An operation designed as espionage may be interpreted as preparation for attack. Access maintained for contingency purposes may be read as active targeting. CBMs create channels for clarification before crises spiral, functioning as diplomatic circuit breakers.

Implementation, however, reveals persistent challenges. Points of contact must be staffed by personnel with both technical competence and diplomatic authority, a rare combination. Information sharing requires trust that shared intelligence will not be exploited. During acute crises, the very channels designed to reduce escalation are often the first casualties of political rupture.

The most promising evolution involves embedding CBMs within broader networks of professional relationships, including Track 1.5 dialogues, joint exercises, and standing forums linking Computer Emergency Response Teams. These dense institutional connections create redundant pathways for communication that individual bilateral channels cannot provide, embodying the networked governance model that cyberspace ultimately demands.

Takeaway

The most dangerous conflicts often begin not with hostile intent but with sincere misunderstanding; institutions that clarify signals are quieter, and more consequential, than those that constrain behavior.

The institutions of international cyber cooperation reveal both the possibilities and limits of governance in domains that predate their regulatory frameworks. Norms have accumulated without enforcement mechanisms. Attribution has advanced technically without resolving politically. Confidence-building measures exist without reliably functioning during the crises they were designed to address.

Yet dismissing this architecture as failure misreads what governance means for a novel domain. The relevant comparison is not to mature regimes like nuclear non-proliferation but to the early decades of any transnational challenge, when institutions grope toward function through iteration and improvisation.

The trajectory suggests that effective cyber governance will not resemble a treaty-based order but a networked ecosystem: overlapping forums, hybrid public-private arrangements, and dense professional relationships that collectively achieve what no single institution can. Designing for this reality, rather than mourning the treaty regime that will not come, is the central task ahead.