March 2026 marked a historic moment for international cybersecurity: the first meeting of the United Nations Permanent Mechanism on cybersecurity took place only a few months after the formal signing of the UN Convention on Cybercrime (the Hanoi Convention). Both instruments seek to regulate complementary areas of international relations, yet they rest on fundamentally different regulatory logics. Drawing on the Copenhagen School securitisation theory, this article argues that cyberspace is the object of two competing securitising moves – one framing it as a domain of international peace and security, the other as a transnational criminal threat – and that the resulting governance architecture is co-produced not only by states but also by transnational technology corporations, whose infrastructural and normative authority supplies the technical content that makes such threat constructions credible. The article analyses the institutional architecture of the UN Permanent Mechanism, the December 2025 ICC Prosecutor’s policy on cyber-enabled crimes, and the role of private technology actors in shaping international legal norms.
You may also start an advanced similarity search for this article.