Spring 2026 Aspen Digital Global Cybersecurity Group Meeting

Executive Summary and Insights

September 18, 2026

Strategic cyber priorities:

  • Tie national strategies to executable tasks and accountable institutions. Across regions, participants stressed that a strategy without concrete actions, owners, and measurable outcomes risks becoming only a “piece of paper.” Cyber policy must be a political priority, not solely a technical one, and international cooperation must be designed to respect different levels of maturity, political reality, and national sovereignty.

Public-private partnerships for critical infrastructure:

  • Move from goodwill to good governance through reciprocal, operational partnerships. Operators and governments should commit to two-way information sharing backed by safe-harbor protections for good-faith disclosure, with Japan’s designation of critical infrastructure categories and its proactive intelligence sharing requirements offered as a model to codify collaboration in law and practice.

Governance of emerging AI cyber capabilities:

  • Shift from vulnerability management to harm management. As AI compresses the time between vulnerability discovery and exploitation, participants urged investment in segmentation, containment, runtime governance, and open-source security to reduce the “blast radius” of attacks rather than relying on patching alone.

Sub-national coordination:

  • Strengthen vertical coordination so national strategy reaches the local level. National governments should supply the funding, standards, and workforce pathways that lift, not replace, municipal and regional capacity, recognizing that local authorities are closest to citizens and critical services, but often the least resourced to act at speed. Participants urged a move away from one-off grants toward continuous shared and managed security services, treating cybersecurity as a common good, since national resilience is only as strong as its least protected node.

Global cyber policy cooperation:

  • Build interoperable standards while avoiding “regulatory colonialism.” Shared frameworks for software bills of materials (SBOM), internet of things (IoT), and supply-chain transparency can provide neutral ground for cooperation across political systems but must be backed by capacity-building, technical support, and local flexibility.
  • Treat trusted relationships as strategic infrastructure. Formal diplomatic processes move slowly, while smaller, trusted communities and ecosystems can produce faster outcomes. In a fragmented technology environment, resilience must be built through practical, trust-based cooperation rather than formal structures alone.

Strategies to disrupt the global scam economy:

  • Align incentives across the full digital and financial ecosystem. Because most scam infrastructure runs through the private sector, effective disruption requires coordinated law-enforcement cooperation, telecommunication and financial regulations, identity security, anti-money-laundering action, and victim support, alongside public education and “digital mindfulness.”

Cyber operations in modern warfare:

  • Prioritize resilience and preparedness over deterrence. Participants emphasized hardening critical infrastructure, clarifying rules of engagement, and preparing for long-duration conflict and sustained operational capability before a crisis begins.

Integration of AI into national security:

  • Keep humans accountable while using AI actively for defense. Governments should define clear AI use cases and limits, finance resilient assurance capabilities, and regulate for transparency and human responsibility in addition to preparing for emerging risks such as agentic insider threats and a coming wave of AI-generated vulnerabilities.

Read the full summary of insights and reflections in the report linked above.

Convened by Aspen Digital, a program of the Aspen Institute, in collaboration with the National Cybersecurity Office of the Government of Japan.