Cybersecurity for the Connected Age

Working together, government and industry can help the world’s citizens reap the benefits of the digital economy while protecting our safety, security, and privacy.

About the Site

The world is more connected now than ever. Half the world’s population is now online, and billions of connected devices are connecting a wide variety of our daily activities to the Internet of Things. While these online connections bring opportunity, they also create risk, including large-scale data theft, privacy violations, phishing scams, ransomware, and malicious information operations that affect millions of people around the world each year.

Addressing this challenge to the digital economy, requires innovative cybersecurity practices and tools to defend the integrity, privacy, and utility of the Internet ecosystem. Although businesses, private citizens, and government agencies all share responsibility for enhancing cybersecurity, the government plays a singular role.

10072026bsacyberagcover

BSA’s 2027 Global Cyber Agenda

BSA recommends that governments prioritize deploying AI for cybersecurity, giving cybersecurity professionals priority access to frontier AI cybersecurity systems, improving vulnerability management, modernizing legacy systems, and building resilience into systems. BSA also recommends aligning regulations to strengthen cybersecurity, upgrading to post-quantum cryptography, and measuring cybersecurity outcomes.

Download Agenda

Given the new cyber landscape, BSA recommends government prioritize:

Click the icons to expand the area.

Leading organizations are already deploying AI to strengthen cybersecurity but adoption remains uneven across sectors and organizations. Policymakers should encourage and incentivize the deployment of AI-enabled tools, including those that enable internal runtime visibility and data-level controls, in addition to cybersecurity tools that help organizations defend against increasingly fast, scalable, and sophisticated external threats.

Companies developing advanced frontier AI cybersecurity systems are already taking steps to provide trusted defenders with early or priority access to these capabilities, but policymakers should work with industry and other stakeholders to support a predictable, structured, transparent, and globally aligned public-private partnership for determining which organizations can access the most capable systems and under what conditions.

Given frontier AI cybersecurity systems’ ability to discover vulnerabilities, and chain comparatively low-level vulnerabilities together to increase their impact, policymakers should invest in the infrastructure to collect, analyze, score, and publish information about vulnerabilities; support the development and deployment of patches, including for open-source software; and encourage organizations to leverage network or host-level protections called virtual patches or vulnerability shields.

Legacy and bespoke systems, more commonly used in government agencies, often operate beyond their supported life cycles or cannot be effectively patched or secured. In an environment in which malicious actors can use AI to discover and exploit vulnerabilities faster and at greater scale, these systems increasingly represent high-risk weak points. Policymakers should prioritize modernizing outdated systems and reforming procurement practices to encourage secure, updatable, and resilient technologies over the long term, including deploying post-quantum encryption.

Even before the rise of autonomous AI security systems, organizations needed to place greater emphasis on cyber resilience. Today, however, organizations must increase investment in their ability to continue operating during cyber incidents and recover to a trusted state quickly. Policymakers should support these efforts by encouraging clear recovery objectives and promoting
capabilities such as AI-enabled recovery tools, immutable storage, and regularly tested restoration processes.

Fragmented and overlapping cybersecurity regulations continue to shift resources away from cybersecurity and to compliance checklists, particularly in the realm of cyber incident reporting. While this challenge is not new, it is more urgent in an era of AI-enabled cyber threats, where defenders must move faster and operate at greater scale. Policymakers should align and streamline cybersecurity requirements across sectors and jurisdictions.

The timing of the arrival of cryptographically relevant quantum computers remains uncertain, but “harvest-now, decrypt-later” attacks are here today and the transition to post-quantum cryptography (PQC) will take years to complete. Organizations should leverage available AI-enabled solutions to inventory cryptographic assets and take risk-based approaches to deploying PQC today so they can upgrade without disrupting critical operations. Policymakers should accelerate this transition by supporting upgrade road maps, prioritizing high-value systems, updating procurement guidance and approach, and encouraging the adoption of PQC standardized by the National Institute of Standards and Technology (NIST) across the public and private sectors.

Organizations should track operational metrics such as mean time to detect, mean time to respond, as well as vulnerability remediation timelines, to ensure investments are delivering real-world improvements. Policymakers should work with industry to develop, support, and use these metrics to ensure cybersecurity requirements drive concrete cybersecurity improvements.

Report: BSA International Cybersecurity Policy Framework

The Cybersecurity Policy Framework provides a recommended model for a comprehensive national cybersecurity policy.

See Report

In strategy documents, organization, and budgets, governments should emphasize strong, collaborative cybersecurity as a critical element of national security.