Cybersecurity Law and Policy: A Comprehensive Review of Emerging Global Frameworks
Keywords:
cybersecurity law; global frameworks; comparative regulation; GDPR; NIS2; Budapest Convention; UN Cybercrime Convention; critical infrastructure; data protection; cyber norms; regulatory convergence; digital governance; emerging economies; international lawAbstract
The first quarter of the twenty-first century has witnessed an unprecedented proliferation of cybersecurity legal and regulatory frameworks across the world, as governments at every level of development have grappled with the escalating threats posed by cybercrime, state-sponsored cyber operations, critical infrastructure attacks, data breaches, and the systemic security vulnerabilities embedded in an increasingly digital global economy. From the European Union's landmark General Data Protection Regulation and NIS2 Directive to the United States' sector-specific regulatory evolution and emerging comprehensive legislative proposals; from China's sovereign cybersecurity architecture to the nascent but rapidly developing frameworks of Africa, Latin America, and Southeast Asia; and from the evolving treaty landscape anchored by the Budapest Convention and the newly adopted United Nations Cybercrime Convention to the voluntary norm frameworks developed by successive UN Groups of Governmental Experts, the global cybersecurity legal landscape of 2025 is simultaneously richer, more complex, and more fragmented than at any previous point in the digital era.