LawyersForPeace.Online

a curated map of the law of peace in the cyber & information sphere

User Tools

Site Tools


topics:cybersecurity

This is an old revision of the document!


Cybersecurity, cybercrime and critical infrastructure

As of 1 October 2026.

Overview

This subject area covers three related bodies of rules. First, criminal law: treaties oblige their parties to criminalise attacks on computer systems and data, to provide investigative powers for electronic evidence and to cooperate across borders. Second, the security and resilience of networks and critical infrastructure, addressed in the European Union by binding obligations on operators and authorities. Third, State conduct: the UN framework of responsible State behaviour includes voluntary norms on protecting critical infrastructure and on cooperation in incidents. Criminal-law instruments address individuals; they do not regulate State cyber operations under international law.

Main points of debate

  • Two cybercrime treaties. The Budapest Convention (2001) and the UN Convention against Cybercrime (2024) coexist; their relationship is discussed by States and commentators.
  • Safeguards. During the negotiation of the UN Convention, some States, human rights organisations and industry groups raised concerns about the breadth of cooperation for “serious crimes” and the adequacy of safeguards; other States regarded the text as balanced.
  • Critical infrastructure. There is no universally agreed definition; States differ on which sectors, such as electoral systems or health care, should be treated as critical.
  • Voluntary or binding. The norms on critical infrastructure are voluntary; proposals for binding rules on State conduct remain contested.

Entries

See also

topics/cybersecurity.1790863283.txt.gz · Last modified: by lfpo