Every time you send an email, make an online payment, or store a file on the cloud, your data passes through a maze of networks – and not all of them are safe. Cyber threats are no longer the exclusive concern of governments or large corporations. They affect journalists, students, businesses, and ordinary citizens every day. Protecting information in this environment requires two things working together: technology that can shield data from attackers, and law that can hold those attackers accountable. Neither works well without the other. This post breaks down both pillars – the technological frameworks for cyber security, and the legal structures that give them teeth.
Table of Contents
- Why cyber security needs both technology and law
- Technological innovations for security
- Encryption: the backbone of data protection
- Steganography: hiding data in plain sight
- Unilateral security technologies
- Bilateral and trilateral security technologies
- Multilateral security mechanisms
- The role of legislation in cyber security
- The Budapest Convention: a landmark legal framework
- What cyber law must prohibit
- Why international legal cooperation matters
- Technology and law as a unified system
Why cyber security needs both technology and law
Technology alone can build walls, but without law, there is no penalty for those who scale them. Law alone can define crimes, but without technology, there is nothing to detect or stop them. Effective cyber security sits at the intersection of both. The technological side addresses how data is protected; the legal side determines what happens when that protection is breached. Understanding these two dimensions together gives a much clearer picture of how digital security actually works in practice.
Technological innovations for security
The foundation of cyber security is a set of technical tools and methods designed to protect data at every stage – whether it’s sitting on a local device, traveling across a network, or stored in the cloud. These tools have grown significantly more sophisticated over the years, evolving in response to increasingly complex threats like Trojan horse malware, ransomware, and spyware. Broadly, these technologies can be grouped by the number of parties involved in their operation – from tools a single user controls independently, to systems that require cooperation across thousands of participants.
Encryption: the backbone of data protection
Encryption transforms readable data into an unreadable format that can only be decoded with the correct key. It is the most fundamental tool in digital security. Modern encryption algorithms such as AES (Advanced Encryption Standard) and RSA (Rivest-Shamir-Adleman) are designed to secure data by ensuring its confidentiality, integrity, and authenticity. These algorithms serve as the first line of defense, making data inaccessible to anyone who doesn’t possess the decryption key – whether the data is stored locally or transmitted across a network.
Steganography: hiding data in plain sight
Steganography takes a different approach: rather than scrambling data, it hides the very existence of a message within an ordinary-looking file. Steganography is the practice of concealing information within another message or file to avoid detection – the hidden data is then extracted at its destination. A common technique, for example, involves embedding a secret message in the pixels of a digital image, where the change is invisible to the human eye. Unlike encryption, which makes content unreadable, steganography makes content invisible.
When both techniques are combined, the result is significantly stronger protection. Steganography hides data within images, audio, or video, while cryptography ensures that data remains unintelligible to cyber attackers. If an attacker intercepts encrypted data, it at least reveals that something secret is being communicated. But if that encrypted data is also hidden within an image, the attacker may not even know there is anything to intercept. This layered approach addresses both visibility and accessibility risks at once.
It is worth noting that steganography has a dual character. Security professionals use it to protect sensitive communications and embed digital watermarks in copyrighted content. But threat actors also use it to conceal malicious code within seemingly normal files, bypassing antivirus software that is not designed to detect steganographic manipulation. This makes awareness of the technique important for both defenders and attackers.
Unilateral security technologies
The simplest category of cyber security tools are unilateral technologies – measures that a single user can deploy on their own, without needing to coordinate with anyone else. These are self-contained, user-controlled protections.
Local storage encryption is a key example: a user can encrypt the files on their own device so that, even if the device is stolen or accessed without permission, the data remains unreadable. Similarly, using certified or open-source software is a proactive unilateral measure. Because open-source code is publicly visible, its community of users and developers can inspect it for hidden vulnerabilities or malicious code – a crucial consideration, given that 90-98% of code used in modern applications is open source, yet most organizations focus their security attention only on the small slice of proprietary code they write themselves.
Trojans are particularly relevant here. A Trojan horse is malware that disguises itself as a legitimate program to gain unauthorized access to a system. Using software only from trusted, verified sources – and keeping it updated – is one of the most effective unilateral defenses against such threats. Security software such as antivirus and anti-malware programs can help detect, quarantine, and remove Trojans when kept up to date.
Bilateral and trilateral security technologies
Many security scenarios involve communication between two or more parties, which is where bilateral and trilateral technologies come in. These require coordination and mutual agreement to function.
Bilateral security technologies involve two communicating parties negotiating a shared security mechanism. A common example is a secure communication protocol agreed upon by both a sender and receiver – such as an encrypted messaging system where both parties use the same keys. The security depends on both sides following the same rules. This is sometimes described as a mutual arrangement, where each party’s protection is tied to the other’s cooperation.
Trilateral technologies bring in a trusted third party to manage accountability, access control, or identity verification. Security gateways are one example: an external server or service that authenticates users before granting access to a resource, acting as a neutral intermediary between the requester and the resource owner. Digital pseudonyms are another: rather than using a real identity, users interact under a verifiable but unlinkable alias managed by a trusted third-party system. This enables accountability – you can prove you are a registered user – without revealing who you actually are. According to research on multilateral security from Springer, such systems are among the structured tools developed specifically to balance individual privacy with systemic accountability in digital environments.
Multilateral security mechanisms
The most complex category involves multilateral security technologies, which depend on cooperation among large numbers of participants – often spread across organizations, countries, or entire internet infrastructures. These systems are designed to protect users at scale, particularly from surveillance and identity exposure.
Three key protection goals define multilateral security: anonymity (the ability to use a service without being identified), unobservability (the ability to communicate without others knowing that communication is happening), and unlinkability (the inability to connect separate actions back to the same individual). Technologies like anonymization networks, mix networks, and privacy-preserving protocols are designed to provide these guarantees across large, distributed systems.
These protections matter enormously in a world where data flows across borders and surveillance capabilities are expanding. As noted in research on multilateral approaches to improving global cyber security, governments, businesses, and individuals all benefit from cyberspace – but the same environment that enables communication also creates opportunities for criminals, state-sponsored actors, and other bad actors to exploit network infrastructure. Effective multilateral security technologies help ensure that users retain control over their digital identities even when using shared, global networks.
The role of legislation in cyber security
Technology can protect data, but it cannot punish those who attack it. That is where law comes in. Legal frameworks are essential for defining what constitutes a cybercrime, establishing investigative powers, and creating the basis for international cooperation.
The Budapest Convention: a landmark legal framework
The most significant international legal instrument in this space is the Budapest Convention on Cybercrime, formally known as the Council of Europe Convention on Cybercrime (CETS No. 185). It is the first international treaty specifically addressing Internet and computer-related offenses, developed with the purpose of harmonizing national laws, enhancing investigative techniques, and fostering greater cooperation among nations in the fight against cybercrime. Opened for signature in November 2001, it entered into force in July 2004 and as of June 2025, 80 states have ratified the Convention, with others in the process of joining.
What cyber law must prohibit
Effective cyber legislation must clearly define and criminalize a specific set of behaviors. The Budapest Convention provides a useful template. It requires signatory states to criminalize:
Illegal access – unauthorized entry into a computer system or network. Illegal interception – the unauthorized interception of non-public transmissions of computer data using technical means, which the Convention treats as a privacy violation analogous to wiretapping. Data interference – intentionally damaging, altering, deleting, or suppressing computer data. System interference – disrupting the functioning of an information system, including through denial-of-service attacks. Misuse of devices – producing, distributing, or possessing tools specifically designed to commit cybercrimes.
Beyond these core offenses, the Convention also addresses computer-related forgery, fraud, and offenses involving child exploitation online. Importantly, it provides investigative powers to collect or record data either directly or by compelling service providers to cooperate – including the real-time interception of communications under lawful authorization.
Why international legal cooperation matters
Cybercrimes rarely respect national borders. An attacker in one country can target systems in another in seconds. This is why the Budapest Convention also establishes a framework for mutual assistance, including requests for access to stored computer data, real-time collection of traffic data, and interception of content data, with a 24/7 network of contact points for urgent assistance among member states.
The Convention has had a measurable impact beyond its member states. Its influence on domestic legislation globally means that, as dozens of countries have agreed that certain behaviors are unacceptable in cyberspace, and these prohibitions have been written into national law, creating an expanding zone of consensus about what constitutes criminal conduct online.
At the diplomatic level, multilateral partnerships have further strengthened this consensus. In 2013, several countries including the United States, China, and Russia reached a landmark consensus that international law, including the UN Charter, applies in cyberspace – establishing that the digital world is not a lawless zone, but is governed by the same foundational rules as the physical world.
Technology and law as a unified system
It is tempting to view cyber security as a purely technical problem – something to be solved by better software, stronger encryption, or more sophisticated tools. But even the most advanced encryption is useless if there is no legal consequence for those who attempt to break it. Conversely, even the most comprehensive cybercrime law is ineffective if there are no technical systems in place to detect breaches, collect evidence, and attribute attacks.
The relationship between technology and law in cyber security is not a hierarchy – one does not serve the other. They are interdependent. Technological tools create the conditions under which law can function; legal frameworks set the boundaries within which technology must operate. Together, they form the twin pillars on which meaningful cyber security rests. For individuals, organizations, and states alike, understanding both dimensions is not optional – it is the baseline requirement for operating safely in the digital world.
What do you think? As cyber threats evolve faster than legislation can keep up, should there be a binding global cybercrime treaty that all nations are required to ratify – and who should have the authority to enforce it? And at the individual level, if powerful privacy technologies like steganography and anonymization networks can be used by both security professionals and criminals, how should society decide where to draw the line on their availability?
References
- https://vercara.digicert.com/resources/trojan-horse-malware
- https://dl.acm.org/doi/fullHtml/10.1145/3675888.3676053
- https://www.kaspersky.com/resource-center/definitions/what-is-steganography
- https://link.springer.com/article/10.1007/s10207-024-00853-9
- https://security.pditechnologies.com/blog/steganography-in-cybersecurity-a-growing-attack-vector/
- https://sequoiacap.com/article/dan-lorenc-chainguard-spotlight/
- https://en.wikipedia.org/wiki/Trojan_horse_(computing)
- https://link.springer.com/chapter/10.1007/11766155_1
- https://www.mitre.org/sites/default/files/pdf/12_3718.pdf
- https://legalclarity.org/what-is-the-budapest-convention-on-cybercrime/
- https://cjil.uchicago.edu/print-archive/when-cyber-defense-crime-evaluating-active-cyber-defense-measures-under-budapest
- https://www.congress.gov/treaty-document/108th-congress/11/document-text
- https://www.ictlc.com/a-new-look-at-the-budapest-convention-on-cybercrime/?lang=en
- https://afsa.org/diplomacy-cyberspace
Leave a Reply