2026 Geneva Dialogue Masterclass #3
Time: 15:00–17:00 CET
Cyber risk is becoming harder to define consistently. Geopolitical fragmentation, conflicts that combine kinetic and cyber operations, and fast-moving technological change — especially AI — are all reshaping what we mean by critical infrastructure protection. What counts as critical, who is responsible for protecting it, and what kind of harm we are trying to prevent are no longer settled questions.
Some of these pressures are speeding up timelines that existing frameworks were not built for: vulnerability discovery, disclosure, and response have traditionally assumed human-speed operations, and AI-assisted tools are now testing whether that assumption still holds. Others are expanding the scope of the problem: dependencies once seen as secondary — cloud services, software supply chains, AI infrastructure — now carry risks once associated mainly with sectors such as energy or finance, while conflicts that mix physical and digital attacks blur the line between cybersecurity and broader crisis response. Throughout, the resulting harms — disruption, cascading losses, erosion of public trust — remain difficult to measure or attribute, even as the systems involved grow more interconnected and faster-moving.
In 2026, the Geneva Dialogue is focused on stress-testing cybersecurity practices and agreed cyber norms under real-world conditions. This masterclass launches the third thematic cycle of 2026, focusing on critical infrastructure protection and cyber harm. It brings together perspectives from private sector cybersecurity practice, strategic policy, the wider cybersecurity research community, and academia and civil society to discuss how technology, geopolitics, and conflict are changing what counts as critical infrastructure, how we understand risk, and where current approaches to cyber harm still fall short.
It follows the first masterclass in the series:
- Shared Code, Shared Risk: How Are Security Responsibilities Allocated?, which examined security responsibilities in open-source software supply chains; and
- Emerging technologies and cybersecurity: Can governance adapt to speed, scale, and uncertainty?, which focused on risks and opportunities from emerging tech for cybersecurity.







