The quiet war and global cybersecurity efforts

Governments are increasingly on the frontline of cyber threats, with public administrations, particularly in Western countries, experiencing a significant and growing number of incidents that are becoming more sophisticated as well as more frequent. Attribution has also become a prominent feature of cyber diplomacy, with groups of states increasingly issuing coordinated statements identifying actors they believe to be responsible for campaigns targeting critical networks. Beyond the visible disruption caused by hacktivist activities such as distributed denial-of-service attacks lies a quieter and potentially more strategic concern: state-linked actors seeking to establish a persistent presence within critical infrastructure, potentially positioning themselves for future operations.

For business, the threat has also been industrialised. Ransomware remains the single most impactful threat, and the economics are stark: across UK, EU and US a global breach cost is now sitting above record tens of million. The weak point is no longer the outside of the system. The supply chain. When a trusted vendor gets compromised it can let attackers in. People are also still failing to protect themselves with phishing and stolen credentials being the common ways in. The picture is one of patient, revenue-driven adversaries exploiting the seams between organisations rather than their walls.

The response is slowly converging on two principles: shared responsibility and collective defence. The UN Convention against Cybercrime, adopted in late 2024 and signed by dozens of nations the following year, is the first universal framework for cross-border evidence sharing and round-the-clock cooperation, though it has yet to enter into force. On the other hand, Europe is building the densest regulatory regime: NIS2 spreads cybersecurity duties across eighteen critical sectors and puts personal accountability on executives, while the Cyber Resilience Act pushes liability onto the makers of connected products across their entire lifecycle. NATO has stood up an integrated cyber defence centre and made clear that an attack on one is a concern for all. From Washington’s hundred-initiative implementation plan to Australia’s decade-long strategy and India’s incident agency handling millions of cases a year, cybersecurity has moved from the IT basement to the core of statecraft.

The UK is an example of a country taking the threat seriously but still trying to keep up. The National Cyber Security Centre (NCSC) estimates over five million cybercrimes against British businesses annually, roughly one every six seconds. The average cost of a significant attack on a single firm now approaches £195,000, with the annual bill to UK organisations put at some £14.7 billion. The UKs response is quite coherent with the NCSC running services to filter out traffic and a scheme to help companies cut incidents. The government has also launched a Cyber Resilience Pledge and a new Cyber Security and Resilience Bill to make companies more secure. However, even the NCSC is warning that the threats are getting more complex and they are preparing for a future with intelligence.

There are still a lot of problems with putting these plans into action. The UN treaty is contested on human-rights grounds as the United States argues it is unlikely to ratify without meaningful safeguards, and remains short of the ratifications needed to take effect. Even Europe’s flagship NIS2 is patchy, with roughly half of member states missing the transposition deadline. Regulation itself has become a burden: most security leaders say fragmented rules across jurisdictions make compliance harder, not easier. Many organisations also lack the talent they need to stay secure.

The defining factor in all of this is the artificial intelligence. On the offensive side, AI has crossed from experiment to operations: most of the social-engineering activity now appears AI-assisted, and threat-intelligence teams are tracking malware that rewrites its own code to evade detection, state actors plugging language models directly into their tooling, and underground markets selling jailbroken systems. Yet AI is equally the defensive mainstream. Most organisations now use it for phishing detection and anomaly response. The conclusion taking shape is that resilience will not come from any single treaty or tool, but from a feedback loop: vendor liability, real-time information sharing, AI-equipped defenders, and the political will to name aggressors. The organisations genuinely cutting breach costs are those deploying AI and automation at depth, even as most still lack the governance to use it safely.

There are still open questions about how all of this will play out. Will the UN treaty mature into a genuine cooperation tool, or become a vehicle for surveillance? Can European rules raise the baseline without fragmenting the global market? Will AI tip the balance toward defenders or toward adaptive, autonomous malware? These are not just questions but real risks that demand action. Navigating all of this requires expert judgement. That is where specialists such as Pacta Global add value, translating a fast-moving threat landscape into a concrete, defensible strategy. The questions remain open, but the cost of waiting does not. The next step is to seek expert counsel before someone else exploits the gap.

Yevgen Lisuchenko, Special Advisor on Political and Human Rights

Previous
Previous

The Role of Global Leaders in Addressing CrisEs Beyond Statements

Next
Next

Beyond National Jurisdiction: The BBNJ Agreement Ushers in a New Era of Ocean Governance