Reflections from the Geneva Dialogue Masterclass #3 – 2026 on critical infrastructure protection and cyber harm
The third Geneva Dialogue masterclass of 2026 opened with a poll. Participants were asked which of a set of pressures worried them most about critical infrastructure protection right now: AI-accelerated threats, geopolitical conflict blurring kinetic and digital lines, public-private cooperation that still isn’t working, or the difficulty of measuring real harm until it is too late. AI and the tempo it forces onto defenders got the most votes. Measuring harm received the fewest – not because it matters less, several participants suggested over the following two hours, but because it is the hardest of the four to see coming.
Three lead discussants set the stage for the session:
- Dr Bushra Al Blooshi, Director of Governance and Risk Management for Cybersecurity at the Dubai Electronic Security Center, bringing recent, direct experience of critical infrastructure protection under active regional conflict
- Ms Melissa Hathaway, President of Hathaway Global Strategies and senior advisor at Harvard Kennedy School’s Belfer Center, who led cyberspace policy reviews for two US presidential administrations and has been tracking critical infrastructure incidents for over a decade
- Ms Alicia Fawcett, who leads emerging technology initiatives – quantum, among them – at Accenture in Switzerland, bringing a private-sector consulting vantage point across sectors and geographies
What emerged over the following two hours was not a settled definition of critical infrastructure, but rather a discomfort, directly pointed out by several participants . New dependencies, new incidents, new technologies – and yet, it feels like we are stuck on the same page. The threats have changed, but the open questions on who is responsible, what gets enforced, whether norms hold under pressure – largely haven’t.
The very definition of critical infrastructure itself is still evolving – raising the question of what it even means now, as new dependencies emerge and technological change outpaces regulatory frameworks that were never built for either.
Is critical infrastructure still the right category?
Asked how the understanding of critical infrastructure protection had changed over the past year, Dr Al Blooshi was direct: the list of so-called ‘traditional’ sectors (e.g. energy, water, finance, government services) hasn’t gone away, but it no longer captures what actually determines harm. She highlighted two developments that changed: the first was an expert group she joined with the ITU, UNDDR and SciencePo, which found that up to 89% of digital disruptions are triggered by natural hazards, and that the damage comes not from the initial event but from cascading effects nobody had mapped in advance. She pointed to the 2024 Red Sea cable cuts, which disrupted a quarter of Asia-Europe internet traffic during a period of regional shipping conflict. To this day, no consensus exists on whether the cause was deliberate or accidental. ‘That’s the pattern now’, she said. ‘We can no longer even tell an act of war from an accident caused by one.’
The second was the region’s own experience of active conflict, which exposed dependencies on undersea cables, on data centres, and on connectivity assumptions that had never been stress-tested at this scale. Most emergency plans assume one problem at a time – something that happens, gets fixed with a known procedure, and ends. That’s how risk registers and business continuity plans are usually built. But real disruptions don’t work that way. Several pressures often hit together, feed into each other, and outlast the backup systems built to handle them. A heatwave strains the grid right when demand peaks. A cable cut hits a network that’s already stretched thin. When that happens, the failure doesn’t stay in one system or one sector – it spreads.
Ms Hathaway gave the historical context. The term ‘critical infrastructure’ emerged in the mid-1990s to describe assets made newly vulnerable by interconnectedness and automation. Since then, she argued, governments have focused policy on protecting assets and logical infrastructure rather than on holding the companies that build products and services accountable. Definitions diverge sharply across jurisdictions: in particular, the USA lists 16 sectors; China’s catch-all formulation sweeps in almost anything that could harm national security, economic security or people’s livelihoods; the UK’s definition centres on what government itself is prepared to help secure, and has recently been extended to cover data centres. Recalling a decade-plus of incidents, Ms Hathaway also argued that neither regulation nor the 2015 UN GGE norm against peacetime attacks on critical infrastructure has meaningfully held. Her conclusion: the industry needs to shift its attention from protecting infrastructure to mapping the services and dependencies that determine how fast (and whether) recovery is possible when networked systems are breached ‘at speed and scale that are currently indefensible’.
Ms Fawcett highlighted the growing systemic interdependencies created by emerging technologies, noting that advances in quantum computing, agentic AI, and potentially soon superintelligence are accelerating the development of complex technological dependencies faster than institutions can identify, understand, and manage them. A failure at one point in a system that is this interconnected is, increasingly, a failure everywhere. She argued for reframing the conversation around cyber resilience rather than protection, since resilience captures the proactive posture such as disaster recovery planning, vulnerability information-sharing, business continuity, which sector-by-sector protection frameworks were never designed to enforce.
The dependencies nobody had on a list a year ago
Asked what they would now classify as critical infrastructure that wasn’t on any official list a year or two ago, the panel and audience converged on a wide range of answers:
- Undersea cables, which Ms Hathaway noted, carry 99% of the world’s data and roughly USD 10 trillion in daily transactions. They have experienced a string of cuts across links connecting Norway, Sweden, Finland, Estonia, and the Shetland Islands over the past two years – some plausibly deliberate, some plausibly accidental, with no reliable way to distinguish between the two.
- Data centres and data embassies, i.e. the practice (pioneered by Estonia in Luxembourg roughly a decade ago) of holding nation’s critical data outside its own borders, which Dr Al Blooshi said Dubai and a small number of other jurisdictions are now actively revisiting given the regional instability.
- Concentration risk in cloud and frontier AI, where a handful of providers underpin services across sectors and geographies, creating a ‘one-to-many’ exposure that Ms Hathaway compared to the financial sector’s own concentration-risk thinking.
- Digital trust infrastructure – identity providers, authentication platforms, public key infrastructure, and increasingly machine-to-machine identity layers – which some participants argued is becoming as critical as the sectors it authenticates access to, alongside trust itself as a form of social infrastructure that authentication mechanisms can only formalise, not create.
- Space-based infrastructure – positioning, navigation, timing, satellite communications, earth observation – which participants also flagged as an invisible dependency underneath much of what is treated as purely terrestrial critical infrastructure, and one still largely confined to disarmament conversations rather than critical infrastructure ones.
So, does critical’’ remain a useful single category, or whether the field needs degrees of criticality? For instance, systems critical to fail vs. systems critical to recover?
When physical and digital risk can no longer be planned separately
The session highlighted a structural question: with kinetic and cyber operations increasingly mixed in active conflict, should the institutional line between physical and digital risk – still reflected in separate sector leads and departments in most governments – be treated as artificial?
Dr Al Blooshi described Dubai’s approach: a resilience centre that has, over the past two to three years, combined all categories of national risk – natural hazard and cyber alike – into a single register reviewed monthly across sector representatives. She credited that consolidation, built up before the conflict in the Middle East started, with keeping critical services (e.g. airports, power, airlines) running through disruption, which attracted international attention. But, at the same time, she admitted that new risks specific to the conflict still require new measures the existing framework hadn’t anticipated. The broader point is that responsibility for digital infrastructure protection can no longer sit with a CISO alone: given how much of national service delivery is now digitilised, it runs from national leadership down through sector leads, with the CISOs as the last point of contact, rather than the owner of it.
AI-accelerated vulnerability discovery is breaking the disclosure model?
Is it a problem of updating existing disclosure practices, or a sign that the entire model built for human-speed work needs to be rethought?
What Ms Hathaway suggested, looking at the numbers, was: she didn’t believe any national coordination centre was ready to receive, let alone triage, the volume of disclosures now arriving. Microsoft’s most recent Patch Tuesday alone included 974 vulnerabilities, of which around 115 were critical or zero-day. Microsoft’s total for the year to 8 September already exceeded 3,000, against roughly 1,200 for the whole of the previous year. A multinational, running 50-plus hardware and software products, she argued, simply does not have the operational capacity to triage disclosures at that rate across every vendor – a gap she linked directly to burnout among security staff, and to the fact that AI frontier models are now doing a large share of the vulnerability-finding that used to be distributed more slowly across the human research community.
But she also highlighted the deeper cause to decades of ‘irresponsible engineering’, where an ICT industry shipped products with exploitable vulnerabilities without the accountability standards, and the consequences have been eventually imposed on other customers. Now AI-generated code is adding new flaws on top, and companies still aren’t spending enough on defensive tools and capacity to match what AI has enabled on the attacking side.
Ms Fawcett, speaking from a private-sector perspective, highlighted how differences in regulatory frameworks and the pace of decision-making in the public sector are widening the gap between the two sectors. Compliance regulations routinely outpace what companies can actually deliver operationally, in part because regulators and industry aren’t in continuous conversation about what is feasible before rules are set. The result, in her description, is organisations ‘playing along… to satisfy compliance requirements’ without addressing why the underlying timelines can’t be met. Both she and Ms Hathaway agreed the core tension is timing: AI products reach the market and get built into other companies’ products faster than regulators can keep up.
Ms Hathaway further highlighted another problem: AI is quietly breaking other bodies of law, and nobody’s tracking it:
- Data protection laws – whose data trained the model, where it’s stored, and whether it was ever licensed to be used that way?
- Consent – did anyone actually opt in to having their data used, or their conversations recorded? Most countries’ surveillance law says recording without consent is illegal – but does that apply to a chatbot?
- Contract and terms-of-use law – whether an AI product is commercial (governed by the terms of use you agree to, like any consumer contract) or sovereign (state-built and state-controlled), determines which legal framework applies to it at all – and that distinction is rarely clear to the people using it.
- Export control – is AI dual-use technology? Ms Hathaway said that, in the USA, some are already discussing whether it should fall under a Wassenaar-style regime, though she herself was skeptical this would help, given the risk of simply splitting the world along East-West lines.
From partnership to obligation: is the public-private relationship changing?
We asked the room: given how much of the AI instrument used for both attack and defence sits with a small number of private actors, is the relationship between government and industry still meaningfully a ‘partnership’ – or is it becoming an obligation imposed by governments increasingly competing with each other in cyberspace?
Ms Fawcett stressed the need for a reciprocal relationship as the basis for proactive and sustainable cooperation between the public and private sectors. She pointed to the opportunities for mutually beneficial activities such as sharing threat intelligence, responding jointly to attacks on shared infrastructure, and other activities that can be the start of legal and regulatory structures built on true collaboration, not unilateral edicts. However, some participants were more sceptical and mentioned the current geopolitical friction which makes it harder to convene the technical, political and diplomatic communities in the same room. It was also noted that AI expertise sits almost entirely in the private sector, with regulation in the USA unlikely. One participant raised a question, without resolving it, whether the field needs to return to an arms-control-style track rather than a regulatory one?
Implications for cyber norms and confidence-building measures
Implementation gaps between norms and practice remain. Ms Hathaway pointed to a pattern of incidents affecting critical infrastructure since the 2015 UN GGE agreement not to target such infrastructure in peacetime, without attributing any of them to a specific state, as evidence that the norm’s translation into practice remains uneven.
Narrow, technical harmonisation is working where broad norms aren’t. Dr Al Blooshi pointed to concrete counterexamples to the broader gridlock: Singapore’s initiative to harmonise IoT cybersecurity labelling, and a separate working group harmonising the certification of cyber professionals. Neither addresses critical infrastructure protection directly, but both suggest that narrow-scope, technical harmonisation – rather than comprehensive regulation of ‘the ICT sector’ as a whole – is where multilateral cooperation is actually producing results.
Where new risks get discussed institutionally is, in itself, an open question. As mentioned earlier, one participant noted that dependencies on positioning, navigation, and satellite communications are increasingly critical, yet the topic remains largely confined to disarmament forums, rather than critical infrastructure or cyber-norms discussions. Other participants raised a related structural question in the chat – whether the right ‘track’ for AI-driven risk to critical infrastructure is regulation, export control, arms control, or a standards-body approach – and suggested the field may need to revisit the arms-control frame that shaped early cyber-norms work, rather than assuming today’s institutional home is the right one.
What the session left open
Several tensions came up without resolution; several participants said this reflected where the field genuinely stands right now, rather than it presented a gap in the discussion.
Whether ‘critical infrastructure’ remains the right frame at all. Ms Fawcett’s preference for ‘continuous resilience’ over ‘static protection,’ and the open question of whether criticality should be graded rather than binary, was raised but not settled (nor was the underlying question of who currently has the authority to decide).
Whether the right forum for progress is regulatory, diplomatic, or something closer to arms control. The idea that the field may need to return to an arms-control-style approach to AI, given the apparent unlikelihood of near-term regulation in major jurisdictions, drew interest but no consensus, and sits in tension with a more optimistic read on incentive-based, benefit-sharing cooperation.
Whether the coming quantum transition will be absorbed any better than the current AI shock. Quantum matters here for a concrete reason: once current encryption breaks, every critical system that depends on it – banking, power grid controls, health records, government communications – becomes exposed at once, rather than gradually. Google’s 2029 estimate for when that could happen was flagged as a deadline the world wasn’t prepared for, with only the financial sector visibly ahead in migrating to post-quantum-resistant systems. One view was that this readiness gap is also a knowledge gap: decision-makers who don’t yet understand how frontier AI works are unlikely to be ready to manage a quantum transition on top of it, especially arriving this close behind the AI shock. That urgency wasn’t universal, though – a dissenting view in the chat called the quantum risk ‘FUD’, citing data showing that 71% of web traffic is already running on post-quantum-secure connections, a reminder that not every critical infrastructure operator needs to treat this as equally urgent today.
Whether the trajectory is toward cooperation or toward isolation. Asked to project two to five years forward, views were different. One view: countries will split into two groups. Those with their own AI capability and strong ties to tech providers will move ahead. Everyone else will fall behind. Another view: full agreement on new rules isn’t realistic soon. A more workable goal is agreeing on how to recover together when something breaks – tested first through informal, non-government dialogue like this one, before it reaches formal diplomacy. A third, more pessimistic view: expect more countries going it alone – building their own digital systems instead of shared ones. Financial services may be the one exception, since a major bank failure would hurt everyone at once.
The third masterclass was part of the Geneva Dialogue’s 2026 programme, focused on stress-testing agreed cyber norms and cybersecurity practices under conditions of geopolitical pressure, technological acceleration, and systemic interdependency. The findings will inform the third chapter of the Geneva Manual on Responsible Behaviour in Cyberspace.





