By Yang Jeong Yoon (National Security Research Institute (NSR), Republic of Korea) in conversation with Anastasiya Kazakova (Cyber Diplomacy Knowledge Fellow and Geneva Dialogue Project Coordinator, DiploFoundation).

Critical infrastructure protection (CIP) sits at an odd moment in cyber policy and cyber diplomacy: everyone agrees it matters, yet the ground it stands on keeps shifting. Data centers (including with AI), subsea cables, and cloud dependencies now sit alongside the traditional sectors of energy, telecoms, and finance, while the line between defending a network and neutralizing a threat before it strikes is being redrawn in real time.

The Geneva Dialogue on Responsible Behaviour in Cyberspace focuses in 2026 on stress-testing existing cyber norms and cybersecurity practices against real-world challenges, including emerging technological developments and shifting national practice. Korea offers a particularly sharp case study for this kind of stress test: highly digitalised, deeply interconnected with the global economy, and operating in a distinctive security environment shaped by complex relationships with its neighbor – North Korea.

In this interview, Yang Jeong Yoon shares her perspective on how the concept of CIP is evolving, what tendencies can be named in national regulatory practice, and what place active cyber defense occupies in South Korea’s approach to CIP — and where that evolution is exposing gaps that international norms and national frameworks alike have yet to close.

Convergence in principle, divergence in practice

Yang describes the current global trend as convergence in principles and problem perception, even as significant differences remain in national frameworks and implementation. Compared with fifteen or twenty years ago, the biggest change isn’t that governments have agreed on a single definition of critical infrastructure. As Yang puts it, “they have increasingly converged on their understanding of the nature of the risks and what needs to be protected.” Where critical infrastructure protection was once more asset-centric and sector-specific, focused on individual facilities or networks, the approach today is far more service-centric, risk-based, and resilience-oriented, with growing emphasis on the continuity of essential services and the ability to restore critical functions quickly.

Cyber-physical convergence is central to this shift, in Yang’s view. As operational technology and industrial control systems become increasingly networked, cyber and physical risks can no longer be treated as entirely separate categories: a cyber intrusion can produce physical consequences, while physical disruption can affect the digital systems operations and recovery depend on. Governments are therefore increasingly integrating cyber and physical risk management within broader resilience frameworks.

None of this, Yang cautions, amounts to convergence toward a single definition or regulatory model. What is designated as critical, which entities are covered, who regulates them, and what obligations apply still vary considerably, shaped by national economic structures, legal traditions, and security environments — differences that geopolitical factors such as technological sovereignty and trusted-vendor policies can reinforce even among like-minded countries. Korea’s own framework for protecting major information and communications infrastructure reflects this: a national adaptation of broadly shared principles rather than a departure from them. For international cooperation, Yang argues, the priority should not be identical definitions or institutions, but sufficient conceptual and operational interoperability to enable effective cooperation on risk assessment, information sharing, incident response, and supply-chain risk management.

Interdependence without surrendering sovereignty

As infrastructure becomes more transnational — cloud services, subsea cables, cross-border supply chains — are governments adapting their frameworks to that interdependence, or doubling down on sovereignty-based, nationally bounded definitions of what counts as “critical”?

Yang sees governments pursuing both directions at once, and does not consider them contradictory. Infrastructure such as cloud services, subsea cables, and global supply chains can no longer be fully understood within a single state’s territory or jurisdiction — a single essential service may depend simultaneously on data centers, networks, and sub-tier suppliers spread across multiple countries. No national framework, however sophisticated, can fully identify or mitigate risks originating outside its jurisdiction, which is why governments are increasingly building explicit transnational-dependency measures into their frameworks, from supply-chain risk assessments to subsea cable resilience initiatives (e.g., 2026 ASEAN Guidelines for Strengthening Resilience and Repair of Submarine Cables).

At the same time, Yang argues, deepening interdependence has made governments more cautious, not less, about who controls the infrastructure they rely on. They are paying closer attention to who would control a system in a crisis, where data sits and under which jurisdiction, and whether dependence on an external provider could become a national security vulnerability. In this light, “sovereignty” no longer means bringing all infrastructure back within national borders; it means maintaining control over critical functions, avoiding overreliance on any single source of dependency, and preserving the capacity to sustain or restore essential services during a crisis. Data localisation rules, trusted-vendor and equipment-screening regimes, foreign-investment restrictions, and export controls are all, in this sense, sovereignty-based responses to transnational risk. “The meaning of sovereignty itself is evolving,” Yang says — “becoming less about territorial control over infrastructure and more about the ability to determine who can be trusted to operate, supply, and maintain systems that are functionally transnational.”

For Korea specifically, Yang sees this tension as especially acute, given how deeply the country is tied into global digital infrastructure while facing a distinctive security environment. Bringing all critical infrastructure within national borders is neither realistic nor desirable; what matters more is distinguishing between acceptable external dependencies, dependencies that need fallback and recovery capacity, and functions that must remain under national control regardless of cost. Governments, in short, are not choosing between interdependence and sovereignty — they are learning to manage the former in ways that preserve the latter.

Consultation without authority — still the default

Non-state actors — industry, civil society, the technical community, academia — are routinely consulted on CIP policy but rarely given formal decision-making authority. Yang’s assessment is that this remains the default model, even as the line between consultation and actual influence grows blurrier in practice. Governments remain reluctant to delegate formal authority: decisions about what counts as critical, what obligations apply, and what level of risk is acceptable are, in the end, questions of public authority and national security.

But formal authority, Yang notes, doesn’t tell the whole story. Much of today’s critical infrastructure is privately owned, and governments often lack the technical knowledge or operational visibility to assess risk independently. As a result, industry and the technical community are increasingly shaping the substance of policy — defining standards, identifying vulnerabilities, sharing threat information — even where governments retain final legal authority. Academia and civil society play a more indirect role, influencing how risks are conceptualised or raising questions of accountability and rights rather than shaping technical standards directly.

Korea illustrates the challenge well: its traditionally government-centered approach to cybersecurity is increasingly tested by infrastructure that depends on private sector technologies and services, which means effective policy now requires sustained cooperation with operators, cybersecurity companies, and researchers. The real test, Yang suggests, is whether governments can institutionalise this kind of involvement early enough to shape how a problem is defined — rather than inviting external expertise only after the decisions have largely been made.

Where norms meet the real world

When you compare how international processes (UN norms, regional bodies) frame CIP with how it’s actually implemented nationally, where’s the widest gap between the stated principle and the practiced approach?

For Yang, “the widest gap between international principles and national practice lies not in the lack of agreed norms, but in how those norms are implemented in practice.” At the international level, there is already a fairly comprehensive set of expectations. The UN norms of responsible State behaviour call on states to refrain from damaging other states’ critical infrastructure, protect their own, respond to requests for assistance, protect CERTs and CSIRTs, and promote supply chain integrity, while states retain sovereign authority over what counts as critical domestically.

The real gap, Yang argues, appears when these shared principles have to function across different national systems during an actual incident. States may agree that critical infrastructure shouldn’t be targeted, but define “critical” differently; they may agree on the value of assistance, but the procedures for requesting or providing it vary considerably; and even where information sharing is supported in principle, classification rules, attribution uncertainty, and political sensitivities can limit what is actually shared and how fast. The same dynamic plays out with supply chains: international norms increasingly recognise the interconnected nature of ICT infrastructure, but the authority to investigate, regulate, and respond still stops largely at national borders.

Korea, Yang notes, can designate and protect its own critical information and communications infrastructure through domestic law, but that infrastructure’s resilience increasingly depends on technologies and suppliers beyond Korea’s jurisdiction — meaning national measures remain necessary but no longer sufficient. The main gap is one between normative agreement and operational reciprocity: the priority for international cooperation going forward should be less about new high-level principles and more about operationalising existing norms — strengthening points of contact, assistance procedures, and CERT/CSIRT cooperation so that different national systems can actually coordinate under real operational pressure.

What belongs on the critical list today

Korea designates critical infrastructure through a formal government listing process under its Act on the Protection of Information and Communications Infrastructure. Rather than naming a single facility that belongs on that list, Yang reframes the question: the more pressing issue is how quickly the designation system can identify newly emerging dependencies in the first place. That process works well for sectors whose criticality is already established, but it can lag when technological dependencies shift quickly — something Yang sees reflected in recent efforts to treat cloud services as a distinct area of vulnerability assessment.

AI data centers and large-scale GPU and computing infrastructure stand out as the clearest current example. Data centers themselves aren’t new, but their scale, function, and the degree to which other critical services now depend on them have changed dramatically with the growth of generative AI — concentrating GPU capacity, data, and models while depending heavily on electricity, cooling, and telecommunications networks. The key question, in Yang’s view, isn’t whether every AI data center should be formally designated, but at what point the concentration of compute capacity becomes a nationally significant dependency capable of producing cascading effects across finance, telecoms, and public services — effects a traditional asset- or sector-based designation approach may not fully capture.

The same structural mismatch, Yang argues, applies to hyperscale cloud services, subsea cables, and satellite communications, all of which span multiple countries and operators with ownership and jurisdiction distributed across borders. This isn’t unique to South Korea: most national CIP frameworks were built around identifiable sectors and domestic operators, and emerging infrastructures combining private and transnational ownership challenge that model everywhere. It may be especially visible in Korea, though, because designation and oversight are organized largely around individual government ministries, while infrastructure such as AI data centers cuts across electricity, telecommunications, data, and cloud policy simultaneously. The task ahead, Yang concludes, is not simply expanding the list, but building a framework that can identify emerging dependencies and cross-sector risk concentrations before they become systemically critical.

When cyber and kinetic planning finally meet

Are cyber and kinetic defense actually being planned together within today’s fragmented institutional structure, or do they remain in separate silos even as the threats converge?

Yang’s answer is that institutional silos remain real, but operational integration is moving faster than the institutions themselves. Most governments still divide cyber responsibilities across intelligence services, military cyber commands, law enforcement, and civilian agencies, each governed by different legal authorities and thresholds for action — boundaries that are difficult, and in some cases undesirable, to fully dissolve. What has changed more significantly, in Yang’s assessment, is how cyber threats are folded into operational planning: increasingly treated not as a separate technical problem but as one element of a broader multi-domain threat environment alongside electronic warfare, space systems, drones, and GPS disruption.

Korea’s Ulchi Freedom Shield exercises illustrate the point well: cyber threats are now incorporated alongside conventional and non-kinetic threats within combined defense scenarios, including responses to cyberattacks alongside missile threats, GPS jamming, and drones — reflecting lessons from contemporary conflicts. The significance, Yang stresses, isn’t that militaries run separate “cyber exercises,” but that cyber scenarios are embedded within the same crisis environment as physical military threats. She expects this pattern to hold well beyond South Korea, since cyber kinetic integration tends to happen first at the operational level, where planners must weigh cyber and kinetic effects against the same problem and timeline, while institutional integration lags behind due to differing legal and accountability frameworks. South Korea’s broader exercises also point to a wider need for whole-of-government and civil-military coordination, given that cyberattacks on telecommunications, energy, or financial services could unfold alongside conventional military operations in a real crisis. The operative question, in Yang’s framing, isn’t whether cyber and kinetic defense sit inside the same organisation, but whether different institutions can share situational awareness and coordinate responses quickly when it matters.

Where active defense starts to blur into offense

South Korea, alongside the US and Japan, is moving toward a more assertive active cyber defense posture. Is the legal line between active defense and hack-back holding up through that shift, or is it blurring the way it has elsewhere — and what would a credible legal safeguard actually need to look like?

Yang doesn’t think the legal boundary between active cyber defense and offensive cyber operations has disappeared, but she acknowledges it’s becoming harder to explain through a simple defense/offense distinction. Where cyber defense was traditionally about detecting and blocking threats within national networks, more recent active cyber defense approaches are proactive by design — identifying attack infrastructure before damage occurs, tracking threat actors, and in some cases disrupting their capabilities. The purpose may remain defensive even as the means and effects move closer to what has traditionally counted as offensive.

South Korea’s legal developments, in Yang’s view, exemplify this shift concretely. The National Intelligence Service Act tasks the NIS with collecting and distributing intelligence on international and state-sponsored hacking organisations, and the 2025 Regulations on Cyber Services expanded cybersecurity intelligence activities to include “response measures” aimed at identifying, checking, and blocking threats from North Korea and other actors. Importantly, Yang points out, “preemptive neutralisation” isn’t just rhetoric in the policy rationale — it’s built into the substantive framework for response measures, establishing a legal basis for preemptively neutralising state-sponsored hacking activity. That represents a move beyond intelligence collection or post-incident response, toward institutionalising a genuinely proactive cyber defense posture.

Yang is careful, though, not to read this as South Korea broadly authorising offensive operations or “hack-back” in a general sense: incorporating preemptive neutralisation into the legal framework is different from specifying exactly what technical measures, targets, and effects are permissible, and the publicly available framework doesn’t disclose that operational detail. This, for Yang, is precisely why the old question — “is this action defensive or offensive?” — is no longer sufficient. The same technical measure can carry a different legal character depending on its purpose, target, authority, and circumstances. What matters more is who has authority to act, at what threshold, under what authorisation, and with what permissible effects. A credible legal safeguard, in her view, needs clear legal authority, defined thresholds, authorisation procedures, necessity and proportionality requirements, effective oversight, and — where a measure could affect systems outside national jurisdiction — a clear relationship to international law and other states’ sovereignty. South Korea’s shift, Yang concludes, is best understood not as a move “from defense to offense,” but as an expansion from prevention and response toward a more proactive posture. As she puts it, “the more explicitly proactive authorities such as ‘preemptive neutralisation’ are established, the more clearly the legal and procedural boundaries governing who may exercise those authorities… need to be defined.”

Redefining cyber harm

Asked whether a specific case had changed how she personally defines “cyber harm,” Yang points not to a single incident but to a shift in scale: North Korea’s cryptocurrency theft, and the way its proceeds get converted into broader national security capabilities. For years, Yang defined cyber harm the way much of the early cybersecurity literature does — in terms of data compromised, systems disrupted, or direct financial loss. From that lens, cryptocurrency theft looked like a form of cyber-enabled financial crime.

The North Korean case made that definition difficult to sustain, in Yang’s account. North Korean state-linked actors have repeatedly been tied to large-scale cryptocurrency theft, which both the South Korean government and international assessments link to financing for the country’s nuclear and ballistic-missile programs — a connection South Korea’s 2024 National Cybersecurity Strategy makes explicit. The insight, for Yang, is that “non-physical harm originating in cyberspace does not necessarily remain non-physical”: theft produces an immediate financial effect, but once the proceeds convert into resources supporting military capability, a direct strategic line runs from cyber activity to physical security threats. That reframes how severity should be measured — not just by the value of what’s stolen, but by what those resources enable downstream.

Yang frames this as a distinct form of cyber-physical convergence, different from the more familiar case of a cyberattack directly causing physical damage: cyber operation → financial gain → military capability → physical security threat. Cyberspace doesn’t produce the physical effect directly here — it generates the resources that strengthen physical capability elsewhere. Treating North Korean cyber operations as simple cybersecurity incidents or financial crime, in Yang’s view, risks underestimating their broader national security consequences. As a result, she now defines cyber harm more broadly than he might have fifteen or twenty years ago: not only the direct harm to systems, data, and victims, but the downstream security effects — how resources or capabilities generated through cyberspace can be converted into strategic or physical threats. The boundary between non-physical cyber harm and physical security harm, in her assessment, is far more permeable than traditional definitions suggested.

Conclusion: institutions catching up to convergence

Across all questions we asked, a single thread runs through Yang’s answers: definitions, institutions, and legal categories built for a more compartmentalised world are being outpaced by risks that don’t respect those compartments — cyber and physical, national and transnational, defensive and offensive, financial and strategic. South Korea’s experience, from AI data centers to preemptive neutralisation to the strategic afterlife of stolen cryptocurrency, offers a concentrated view of a challenge facing most national CIP frameworks: not a lack of shared principles, but the slower, harder work of making institutions, definitions, and legal authorities keep pace with how the risks themselves are converging.