====== Cybersecurity, cybercrime and critical infrastructure ====== //As of 1 October 2026.// ===== Overview ===== This subject area covers three related bodies of rules. First, criminal law: treaties oblige their parties to criminalise attacks on computer systems and data, to provide investigative powers for electronic evidence and to cooperate across borders. Second, the security and resilience of networks and critical infrastructure, addressed in the European Union by binding obligations on operators and authorities. Third, State conduct: the UN framework of responsible State behaviour includes voluntary norms on protecting critical infrastructure and on cooperation in incidents. Criminal-law instruments address individuals; they do not regulate State cyber operations under international law. ===== Main points of debate ===== * **Two cybercrime treaties.** The Budapest Convention (2001) and the UN Convention against Cybercrime (2024) coexist; their relationship is discussed by States and commentators. * **Safeguards.** During the negotiation of the UN Convention, some States, human rights organisations and industry groups raised concerns about the breadth of cooperation for "serious crimes" and the adequacy of safeguards; other States regarded the text as balanced. * **Critical infrastructure.** There is no universally agreed definition; States differ on which sectors, such as electoral systems or health care, should be treated as critical. * **Voluntary or binding.** The norms on critical infrastructure are voluntary; proposals for binding rules on State conduct remain contested. ===== Entries ===== * [[law:coe:budapest|Budapest Convention on Cybercrime (2001)]] – offences, procedural powers, cooperation. * [[law:un:cybercrime_convention|UN Convention against Cybercrime (2024)]] – global cybercrime treaty. * [[law:eu:nis2_cer|EU NIS2 and CER Directives (2022)]] – obligations for essential and critical entities. * [[law:un:ict_norms|UN framework of responsible State behaviour in cyberspace]] – norm 13(f) on critical infrastructure. * [[law:soft:paris_call|Paris Call for Trust and Security in Cyberspace (2018)]] – multistakeholder declaration. * [[law:regional:sco_2009|SCO Agreement on International Information Security (2009)]] – regional cooperation agreement. * [[law:eu:cyber_sanctions|EU cyber sanctions regime (2019)]] – restrictive measures after cyber-attacks. * [[gaps:nc3|Gap: protection of nuclear command, control and communications]] – no specific instrument. * [[law:soft:pall_mall|Pall Mall Process Code of Practice for States (2025)]] – commitments on commercial cyber intrusion capabilities. * [[law:eu:cyber_resilience_act|EU Cyber Resilience Act (2024)]] – security requirements and vulnerability reporting for products. * [[law:eu:product_liability|EU Product Liability Directive (2024)]] – liability for defective software, including cybersecurity. ===== See also ===== * [[topics:un_processes|UN processes and institutions]] * [[topics:data_surveillance|Data and surveillance]] * [[topics:gaps|Regulatory gaps]] * [[topics:private_actors|Private actors, liability and insurance]] * [[:timeline|Timeline]] · [[:glossary|Glossary]]