The Cyber Diplomacy Council
Strengthening how nations cooperate, negotiate, and build trust in cyberspace.
Why Cyber Diplomacy
Cyberspace is the one domain where states interact every single day
Every geopolitical crisis now has a cyber dimension. Attacks target elections, hospitals, energy grids, and the cables that carry the world’s data. Yet cyberspace is also where international cooperation is most tested and most needed. The Council gives this permanent front of diplomacy a neutral, multilateral home.
Advise
Governments and international organizations
Convene
Diplomats and Cyber leaders across divides
Publish
Analysis for the Global Report
Build Capacity
Cyber expertise in Public and Private Sectors
What is Cyber Diplomacy?
Cyber diplomacy is the conduct of international relations with, about, and through cyberspace, by states and non-state actors, to establish norms of responsible behavior, prevent and de-escalate conflict, protect critical infrastructure, and ensure every nation can secure its digital foundations.
Cyber diplomacy is the most established branch of tech diplomacy. Scholars André Barrinha and Thomas Renard, in a foundational study of the field, define it as the use of diplomatic resources and the performance of diplomatic functions to secure national interests with regard to cyberspace. In practice, it has two decades of institutional history: the UN has negotiated norms of responsible state behavior since 2004, the Budapest Convention set the first international standard on cybercrime, the Paris Call for Trust and Security in Cyberspace gathered states, companies, and civil society behind common principles, and dozens of nations have appointed cyber ambassadors.
Building on this emerging scholarship, and applying the WAT framework for tech diplomacy developed by the Tech Diplomacy Global Institute, our definition spans three connected dimensions:
Diplomacy with cyber actors. Diplomatic engagement with the full ecosystem that shapes security in cyberspace: national CERTs and security agencies, technology and cloud providers, telecommunications and cable operators, the security research community, and civil society. In cyberspace, most critical infrastructure is privately owned, and diplomacy must engage wherever responsibility resides.
Diplomacy about cyberspace. The negotiation of the rules, norms, and institutions governing state behavior in cyberspace: the UN framework of responsible state behavior, confidence-building measures, cybercrime cooperation, and the governance of the internet’s shared foundations.
Diplomacy through cyber capability. The strategic dimension of cyber power in statecraft: how cyber resilience underpins national credibility, how capacity building extends influence and partnership, and how digital tools are transforming the practice of diplomacy itself.
Unlike AI or quantum, cyber diplomacy is not preparing for a coming disruption. It is managing a permanent condition. States will compete in cyberspace indefinitely, which is exactly why the domain needs standing diplomatic machinery rather than crisis response. The Cyber Diplomacy Council exists to strengthen that machinery: a neutral, multilateral body where governments, international organizations, researchers, and industry build the trust that cyberspace requires.
The Challenge
A widening gap between norms and behavior
The world is not short of cyber norms. It is short of compliance with them, and of the capacity to uphold them. Agreed frameworks exist at the UN, in regional organizations, and in multistakeholder initiatives, yet malicious activity keeps escalating in scale and sophistication.
Three tensions define the current moment:
The accountability deficit. Norms of responsible state behavior have been agreed by consensus, but attribution remains politically fraught and violations carry few consequences. Each unanswered attack erodes the credibility of the framework itself.
The capacity divide. A minority of states have national cyber strategies, functioning CERTs, and trained cyber negotiators. Most of the world’s governments must defend expanding digital economies with limited technical means and little voice in the forums where rules are shaped. In cyberspace, the weakest links are shared vulnerabilities.
The fragmenting agenda. Cyber issues are negotiated across a growing patchwork of processes: UN bodies, regional organizations, plurilateral coalitions, and bilateral channels. Competing visions of sovereignty and openness pull these processes apart, while new risks, from AI-driven attacks to the coming quantum transition, outpace them all.
The Council’s work addresses all three: strengthening accountability, widening participation, and connecting the fragmented landscape of cyber governance.
The Council’s Mandate
What the Council is charged to do
The Council operates under a two-year renewable mandate from the Institute; the current mandate runs from 2026 to 2028. Within it, the Cyber Diplomacy Council brings together cyber ambassadors, security researchers, former ministers, and industry leaders to:
- Advance the implementation of international norms and confidence-building measures for responsible state behavior in cyberspace, building on the UN framework
- Strengthen international cooperation on the protection of critical digital infrastructure, from undersea cables and cloud systems to the networks underpinning the global economy
- Support cyber capacity building in developing nations, so that cyber governance reflects all regions rather than only advanced cyber powers
- Facilitate dialogue between governments and technology companies on incident response, supply-chain security, and shared defense of the digital commons
- Contribute the Council’s analysis to the Global Technology Diplomacy Report and support the cybersecurity curriculum of the Tech Diplomacy Global Executive Program
Focus Areas
Where the Council concentrates its work
For its 2027–2028 mandate, the Council concentrates its work on five focus areas:
01. Norms implementation and accountability.
Turning the agreed UN framework of responsible state behavior into practice: implementation guidance, confidence-building measures, and approaches to attribution that states across regions can support.
02. Critical infrastructure diplomacy.
International cooperation to protect the infrastructure every nation depends on: undersea cables, satellites and ground stations, cloud services, energy grids, and healthcare systems.
03. Cyber capacity building.
Helping developing nations build national cyber strategies, incident-response capability, and trained cyber negotiators, in coordination with TDGI’s Tech Ambassador Initiative.
04. Cyber diplomacy and emerging technologies.
The new threat landscape created by AI-enabled attacks and the coming quantum transition, in close coordination with the Institute’s AI Diplomacy and Quantum Diplomacy Councils.
05. Public-private cyber diplomacy.
Engaging technology companies as indispensable actors in cyber stability: joint incident response, ransomware cooperation, supply-chain trust, and the responsibilities of platforms and providers.
HOW WE WORK
The Council convenes its annual plenary at the Tech Diplomacy Global Forum in Paris and meets virtually throughout the year. Its members contribute to the Global Technology Diplomacy Report, advise governments through TDGI’s advisory services, and support the cybersecurity curriculum of the Tech Diplomacy Global Executive Program.
Each year, the Council selects a small number of priority questions and produces practical outputs: briefings that a foreign ministry can act on, frameworks a negotiator can use, and recommendations that connect the worlds of cybersecurity practice and diplomacy.
Who should join the Council
Membership in the Cyber Diplomacy Council is by application and invitation. We welcome candidates who bring one or more of the following:
- Senior diplomatic or government experience with cyber portfolios, such as cyber ambassadors, national cybersecurity coordinators, and senior negotiators
- Recognized expertise in cybersecurity research, incident response, or cyber policy
- Leadership experience in technology, telecommunications, or security companies with international engagement
- Perspectives from regions underrepresented in global cyber debates
Council members serve in their personal capacity for a renewable two-year term, aligned with the Council’s mandate. The Council maintains geographic, gender, and sectoral balance as a matter of principle: the security of cyberspace cannot be negotiated by a handful of capitals alone.
Applications for the 2026–2028 mandate are open until 30 September 2026.
Our Partners