Table of Contents

Cybersecurity, cybercrime and critical infrastructure

As of 1 October 2026.

Overview

This subject area covers three related bodies of rules. First, criminal law: treaties oblige their parties to criminalise attacks on computer systems and data, to provide investigative powers for electronic evidence and to cooperate across borders. Second, the security and resilience of networks and critical infrastructure, addressed in the European Union by binding obligations on operators and authorities. Third, State conduct: the UN framework of responsible State behaviour includes voluntary norms on protecting critical infrastructure and on cooperation in incidents. Criminal-law instruments address individuals; they do not regulate State cyber operations under international law.

Main points of debate

Entries

See also