Inside Our Cyberdiplomacy Training: From UN Norms to Crisis Communications
A 10-hour, two-day intensive on how states, institutions and the private sector actually practise diplomacy in cyberspace — from UN norms to crisis communications during a live incident.
Cyberspace governance runs on voluntary norms and confidence-building measures rather than a single binding treaty, and that makes it a genuinely difficult field to get a practitioner's grounding in. Our Cyberdiplomacy Training program is built to close that gap for diplomats, national cybersecurity and CERT officials, corporate and critical-infrastructure leaders, policy analysts, and international-affairs professionals alike — a mixed room, deliberately, because in practice that's who ends up in the room when a state-linked incident happens.
Day 1 — Foundations of Cyberdiplomacy & International Law
The day opens by grounding the field in the incidents that actually shaped it: Estonia's 2007 distributed denial-of-service campaign, the 2017 NotPetya attack, and the SolarWinds compromise. From there, participants trace the UN cyber norms process from the Groups of Governmental Experts (GGE), through the Open-Ended Working Group (OEWG), to today's permanent UN Global Mechanism on Cybersecurity, launched March 2026 — including the 11 voluntary norms of responsible state behaviour agreed in 2015 that still anchor the process, and how the new Global Mechanism's Plenary, Dedicated Thematic Groups, Points of Contact directory, and five-year Review Conference cycle actually work. The day closes on international law: does existing law apply to cyberspace, how is sovereignty contested, how are frameworks like the Tallinn Manual used (and disputed) — plus the practical challenge of attribution — followed by a simulated norm-negotiation workshop.
Day 2 — Practising Cyberdiplomacy
The second day moves from institutions to incidents. Participants cover the regional confidence-building mechanisms that reduce the risk of miscalculation between states — the OSCE's cyber CBMs, the ASEAN Regional Forum, the OAS process, plus bilateral hotlines — and the role the private sector, civil society and technical community play in a process that is formally state-led. From there, the focus shifts to cyber crisis diplomacy: how states manage a state-linked incident diplomatically, coordinated public attribution, the sequencing of diplomatic protest and sanctions, and the risks of getting attribution wrong, plus the disinformation dimension that now accompanies most major incidents. The program closes with a cross-border incident simulation and a certification assessment.
Two Formats, Same Content
The in-person intensive runs as two consecutive full days on-site at your ministry, agency or organisation, or at our training centres in the US and India — ideal for a single delegation or intact team that wants focused, distraction-free immersion. The live online format delivers the same ten hours (commonly five 2-hour live sessions across two weeks) in rolling monthly cohorts, built for distributed delegations and multi-agency teams spread across time zones. Both formats are delivered live by the same facilitators — never pre-recorded — and both conclude with a NABET-recognised Certificate of Completion in Cyberdiplomacy.
No diplomatic or legal background is required — institutional and legal concepts are explained in plain language for a genuinely mixed room. Ready to bring this to your team or delegation? Get in touch through our Training page and we'll confirm the next available cohort or scope an on-site date.
.png)

Comments