Norms 2.0
Ontology, taxonomy, norm
Perhaps the obvious starting place is to ask if the use of cyber weapons is even in our writ. Earlier I drew parallels between the use of bioweapons - a category of munition that has both norms and binding regulations governing their use - to cybersecurity. Are malware packages and hacking tools a form of munition and if so, are the norms covering their use part of the field of cybersecurity1?
If you start researching cybersecurity norms first thing in the morning, you’ll find yourself with plenty of time for a lengthy lunch. A review of the current international consensus reveals fewer than a handful of foundational agreements, though one, the Budapest Convention, is essentially superseded by the UN Convention against Cybercrime (UNCAC), so perhaps three. Of the remaining two, none have any binding obligations. It’s noteworthy, though not entirely surprising, that the US is not a signatory to the UNCAC.
I want to talk about norms in the cybersecurity context, but let me begin by defining the ecosystem we’re talking about. To use a now less common term, cyberspace, which is a layered, interdependent system in which digital actions propagate across technical, physical, and institutional domains, and where certain classes of systems - those sustaining human life, shared infrastructure, and societal legitimacy - possess a higher moral and functional status requiring both restraint and active stewardship by state actors. It is a system with keystone species (DNS, hospitals), shared habitats (supply chains), and cascading failures; failures that propagate across human, technical, and institutional planes.
But I feel it’s necessary to work our way to norms from more general primitives. So let’s talk about the four ontological classes that come to mind:
Human life systems (a biophysical layer)
Shared systemic infrastructure (a digital commons layer)
Institutional systems (the socio-political layer)
Actors (a layer of agency)
In the biophysical layer, digital disruption leads to immediate physical harm. In this class we have the obvious, such as hospitals and other medical facilities, industrial control systems (such as water, power, and nuclear), and the not so obvious, such as emergency response systems.
The commons layer is where any “corruption” leads to systemic loss of trust or function across many actors. I would place items like DNS or supply chains in this class - perhaps even software ecosystems. Systems where the fragility is manifest through interdependence.
For the socio-political layer, we see any sort of manipulation can lead to a loss of legitimacy or social order. The most timely example of this is the attempted election interference from Russia in support of Trump. But equally as valid is the onslaught facing academic research and science - both from the administration and from malign foreign actors and insiders.
Finally, with the agency layer, we have both state and non-state actors; but in either case I personally view the state as the primary unit of accountability - even in a transnational digital system.
Layered over these we can create a simple tiered ontology of harm. From 1. immediate physical harm (death and injury), 2. systemic functional collapse (internet instability), to 3. institutional/epistemic harm (corruption of knowledge or loss of trust).
At this point I think we’re ready to start talking about norms, but I want to offer up one more ontology on the way, an ontology of norms. I think this is the easiest to define: we have obligational and prohibitive norms. Prohibitive norms are those where an actor must show restraint, e.g., don’t attack hospitals or don’t poison supply chains. This is analogous to the prohibition on attacking ambulances in war zones. An obligational norm is one where you must act. Inaction itself is a form of harm. Examples of this would be safe-haven accountability or mutual assistance. Critically, responsibility extends beyond direct action.
Essentially I’m arguing that it’s sufficient for our purposes to say the world consists of: life-critical systems (which must never fail), shared infrastructure (which must remain trustworthy), institutions (which must remain legitimate) and actors (must exercise restraint and responsibility). For our purposes, harm flows upward from technical disruption to human and societal consequences.
Ontologies tell us things about reality - that is, what exists and what fundamentally matters. If we’re going to move toward defining norms of behavior, then we need to place everything into a taxonomy. The taxonomy is how I’m going to arrange the elements of the ontology. The taxonomy is what we say out loud: a structured list of norms. The ontology is the quieter claim underneath it: a theory of what kinds of systems exist, which ones matter more than others, and how harm actually propagates between them. If the ontology is wrong or incoherent, the taxonomy will feel arbitrary. If the ontology is sound, the taxonomy becomes almost inevitable. I think of it as the index of rules built on the ontological models. This is necessary if we’re to move beyond abstractions and to discrete action statements2.
So anchoring my taxonomy of cybersecurity norms are human safety and life-critical systems. These are non-negotiable prohibition norms. They represent an absolute floor, for which violations create a direct risk to human life. Expanding slightly on the examples I gave above, we have three fundamental norms:
Medical sanctuary
No targeting of healthcare systems, public health infrastructure, or medical supply chains.Life-critical infrastructure protection
No operations against ICS (power, water, nuclear, etc.) where failure cascades into physical harm.Emergency response immunity
No disruption of CERTs/CSIRTs or disaster-response networks.
(You’re probably already scoffing since we know hospitals and ICS systems are regularly targeted today. Remember, we’re building norms at this point, not looking at what’s actually happening. It’s what’s happening that’s a forcing function for the creation of these norms.)
Next in our taxonomy we have the integrity of shared systems. What might be called the digital commons. These preserve the baseline trust required for a functioning global digital ecosystem.
Core internet infrastructure protection
No tampering with DNS, NTP, BGP, routing, or physical backbone systems.Supply chain integrity
No deliberate insertion of vulnerabilities into widely used software, hardware, or open-source ecosystems.Responsible vulnerability handling
Maintain disciplined vulnerability disclosure practices (VEP-style), with narrow and time-bound exceptions.
Third in the taxonomy is something we might call institutional integrity and civil order. These are norms that if realized would protect societal and governance functions from destabilization.
Electoral non-interference
No manipulation of election infrastructure or outcomes.Civic and knowledge system protection
No disruption or destruction of academic research, scientific collaboration, or public knowledge systems.
Finally, drawing from my comment on state obligations in the agency layer above, we have state responsibility and active obligations that apply across all domains - they’re not a separate category but a behavioral overlay.
Safe-haven accountability aka due diligence
States must not allow their territory to be used for persistent cyber harm.Mutual assistance norm
States should assist in the defense and recovery of critical civilian systems under attack.
It’s natural to look at these and ask how they’re articulated by your organization, which is probably not a “state” (nation state or otherwise). I suspect that while it may appear the most aspirational, this last category may prove to be the most relevant for commercial and academic organizations.
This taxonomy adapts the traditional principles of kinetic non-combatant immunity to the realities of a digital ecosystem, though I’ve tried to expand on that a bit to address our modern digital ecosystem. At least, I believe it provides a reasonable framework for further expansion. I suspect a fuller analysis would look at each proposed norm (and others, it’s by no means comprehensive) and weigh it against impact and resilience for the purposes of finely tailoring each norm. I’ve drawn them with a fairly broad brush here.
But we should consider the issue I dismissed as an aside above, that is, what do we see in practice today and how does the ground reality of modern cyber attacks influence our thinking about norms?
I’m not going to detail just how bad it is right now - I’m really struggling to identify any cybersecurity norms in effect. Half the email I get from Federal authorities is concerned with attacks on infrastructure - that of water and power. The other half are the steady drumbeat of health systems having data stolen or patient systems disrupted. In a world where a superpower states, “A whole civilization will die tonight, never to be brought back again; I don't want that to happen but it probably will,” how are we to argue for restraint from criminal organizations? Norms matter, even when they’re being ignored.
Naturally the frustration you’re probably experiencing stems from what seems like an insurmountable problem: it feels like there’s little or nothing any of us, or even our organizations, can do to establish international norms, norms that appear to be ignored, violated, or deliberately undermined daily. While it’s true that a norm remains voluntary until it’s codified in law, I think it’s important to remember that by definition a norm is “a shared expectation about appropriate behavior within a community, sustained not primarily through formal enforcement, but through mutual recognition, reputation, and the prospect of inclusion or exclusion3”.
Thinking about how we choose to express that shared expectation allows me one last ontology, one not of agency, but of expression. This differs from the agency layer I described above, for I’m not talking about the “agency to behave according to norms” but rather, “how norms are instantiated at different levels of social organization”. One deals with the capacity to act, while the other is how norms are operationalized.
This is the moment, in a piece that might be seen as somewhat discouraging, of surprising optimism. For despite our apparent individual insignificance in the grander scope of society, norms begin with the aggregation of behavior and belief, which we express through actions and words. Our agency may feel miniscule, but generally speaking, this is how things actually work. One voice at a time.
Norms are expressed differently depending on the level of the actor - not just who acts, but how those norms are instantiated. The same norm does not look the same at each level. For example, “don’t attack hospitals” becomes for the state, a matter of international law or doctrine. For an organization it becomes reflected in architectural controls, segmentation, and incident response priorities. For an individual, it is represented by ethical restraint and professional norms.
It is at this point we should pause and ask how we can contribute to the establishment of these norms. I strongly believe that the most powerful tool we have is voice. If a nation state attacks a hospital in a war zone, or targets an ambulance (or uses an ambulance to move troops) we express outrage. Headlines scream, international committees form and sometimes even warrants are issued. Does behavior change? Are the culpable held to account? Rarely, but that’s almost beside the point. Norms are expressed and codified and this is for the betterment of society4.
Yet, we don’t see this same outrage when a cyberattack unfolds. Worse, we reflexively blame the victims. But we must stop conflating a defensive vulnerability with a moral transgression. Soul searching is warranted if your EMR system falls victim to a ransomware attack, but surely the true sin is that of the attacker who is placing financial gain over human health and life safety.
How we give voice to an event - with apologies or with anger; wearing shame or giving it - is how we have normalized cyberattacks. And it is with that voice we have the agency of expression.
I want to return to one other element I think we can succeed at - that is, to establish as a norm the notion of mutual defense. Right now, when we talk about helping each other during an incident, or sharing out incident details, we get wrapped around the axle debating incident reporting timelines, liability risks, and PR messaging control. All of these are valid institutional concerns, but we allow this administrative minutiae to obscure a fundamental engineering truth: our multi-institutional technical ecosystem operates as a singular, dynamic system that must be informed and enhanced by collective telemetry.
Rather than provide a single solution to this question, let me frame it as a series of questions for reflection. What specific policy, legal, or contractual constraint most frequently delays or prevents us from sharing incident information in real time? Which of those constraints is truly non-negotiable, and which persists out of habit or risk aversion? If we had to share meaningful incident data within 24 hours, what would break first - legal review, communications, or technical readiness?
Translating these questions into immediate operational realities is where the fault lines appear. What mechanism exists today for rapidly engaging external expertise during an incident - and how often has it been used? If that mechanism didn’t exist, how would we assemble trusted external support within hours? What would a ‘mutual aid’ model actually look like between peer institutions: who calls whom, through what channel, with what data?
To close the loop from expression back to actual norm formation, we have to ask the structural questions: what would it take for rapid, reciprocal incident sharing to become expected behavior rather than exceptional? How would we signal - through our own actions - that we are committed to mutual defense as a norm? What would we publicly praise or criticize to reinforce that expectation across the community?
I offer up this list of questions as little thought grenades, you can pull the pin on them at your leisure if you’re so inclined. But while sharing between colleagues does take place, as I’ve mentioned before, far more than our counsels would probably approve, it remains much more idiosyncratic, often relationship based, and is too unsystematic to even begin to consider norm establishing.
This brings us back to the ontology of expression. It’s easy to look at global cyber norms and assume responsibility lies elsewhere - with nation-states, tribunals, or federal frameworks. But a norm is not a document; it is a pattern of behavior. It exists only to the extent that it is enacted.
For you that means your agency is not abstract. The norm of mutual defense takes shape every time you call a peer to share an active indicator of compromise. It takes shape when you push past reflexive legal caution to share critical telemetry, or when you use your voice to shame those attacking you.
When you choose transparency over posture, you are not just managing an incident. You are engineering the digital commons. You are turning an aspirational norm into something real - something practiced, expected, and ultimately, durable.
We did see an attempt, perhaps purely performative, to impose a norm on ransomware actors during COVID, https://www.bleepingcomputer.com/news/security/ransomware-gangs-to-stop-attacking-health-orgs-during-pandemic/. I’m not sure anyone believes this had any real impact, but as I’ll discuss later, it’s still a valuable attempt.
I, like most people, get a bit sloppy when discussing ontologies and taxonomies. Too often, I move between terms as if they were interchangeable. I really need to spend more time reading Jessica Talisman’s substack. You can tell by my reformulation and repetition that I’m working out and testing my own understanding throughout this last passage.
I realize this is a weak salve for those who suffered from the breach of those norms.


