Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Cyberspace is best understood as a shared global system with commons-like properties—not as a legally ownerless domain. Its networks, software, data, cloud platforms, cables, domain-name services and devices cross borders, but the underlying infrastructure is largely owned by companies and located within national jurisdictions. Securing it therefore requires layered stewardship: governments set rules and coordinate defense, providers protect essential infrastructure, vendors build safer products, and organizations and users manage their own risks.

That is the useful starting point of Lt. Gen. Davinder Kumar’s article “Securing Cyberspace: A Global Commons,” published on November 17, 2015. Its strategic insight remains relevant, but the “global commons” description should be treated as an analogy and policy framework—not settled international law.

What cyberspace actually is

Cyberspace is the interconnected digital environment created by information and communications technologies. It includes networks, computers, mobile devices, industrial systems, software, data, users, cloud services and the electromagnetic means that connect them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

It is broader than the Internet. The Internet is a global network of networks that uses common protocols. Cyberspace also includes private networks, military systems, operational technology, closed enterprise environments, applications, identity systems and the physical infrastructure that makes digital communication possible.

#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

The information environment is broader still. It includes how information is created, stored, transmitted, interpreted and used, including influence and public communication. These terms overlap, but treating them as identical can obscure important questions about ownership, responsibility and law.

What does “global commons” mean?

In strategic discussions, a global commons is a domain used by many actors that no single state can completely own or control. The sea, airspace beyond national territory and outer space are common examples in policy literature. These domains enable commerce, communication, movement and security, while their misuse can impose costs on everyone else.

Cyberspace shares several of those characteristics. It is globally interconnected, valuable to civilian and military users, and dependent on cooperation across borders. A vulnerable software component, compromised certificate authority or disrupted routing service can affect people and organizations far beyond the system’s owner.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

But the analogy has limits. Cyberspace is not a single undivided resource, and it is not physically detached from states. Submarine cables, data centers, exchanges, towers, routers and power systems occupy real places. Cloud platforms, registries, registrars, telecommunications networks and software companies exercise substantial control. Governments can regulate operators, restrict access, require data localization, filter traffic and conduct surveillance.

Scholarly and policy treatments therefore describe the classification as contested or imperfect. The Cambridge discussion of cyberspace and global commons and the Global Commission on Internet Governance both illustrate why the phrase is useful as a strategic idea but inadequate as a complete legal definition.

The most accurate formulation is this: cyberspace is a shared global system whose benefits and risks extend beyond individual owners, while its components remain subject to ownership and national jurisdiction.

Why cyberspace is difficult to govern

Cyberspace is simultaneously civilian, commercial, governmental and military. A single cloud service may host a hospital, a bank, a government contractor and an ordinary consumer application. The same network infrastructure can carry routine business traffic during the day and support emergency or military communications during a crisis.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

It is also layered and rapidly changing. Ownership at one layer does not confer control over the others. A company may operate an application but depend on a cloud region, an identity provider, a content-delivery network, several software libraries, a domain registrar and multiple telecommunications carriers.

National borders have not disappeared online. They remain important for jurisdiction, regulation, evidence collection and physical infrastructure. However, cross-border dependencies make unilateral security measures incomplete. An organization may be incorporated in one country, store data in another, rely on suppliers in several more and serve users worldwide.

Governance is consequently fragmented among national laws, regulators, technical standards, contracts, industry practices, international norms and institutions. There is no single global authority that controls all of cyberspace, but it is also inaccurate to say that cyberspace has no governance at all.

The collective-action problem

The central security problem is that the cost of protection is often local while the benefit is distributed. A registrar that protects its domain-management accounts helps prevent harm to users, customers and other networks. A software vendor that rapidly fixes a vulnerability reduces exploitation across the entire customer base. A cloud provider’s resilience protects thousands of dependent businesses.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Those wider benefits can encourage underinvestment. An operator may delay a costly upgrade because the immediate savings are visible while the avoided harm would be shared by others. A supplier may prioritize speed and convenience over secure design. Organizations may assume that another company, regulator or security vendor will absorb the consequences of failure.

Supply chains intensify the problem. A weakness in a widely used library, update mechanism, identity provider or managed service can create simultaneous exposure for organizations that never directly chose the vulnerable component. Security is therefore not only a matter of defending individual endpoints. It is also a matter of protecting shared enabling infrastructure.

The hidden infrastructure of the commons

Layer Examples What can go wrong
Physical Submarine cables, data centers, towers, power and cooling Damage, interception, environmental disruption or prolonged outages
Network Routers, carriers, Internet exchanges and routing protocols Loss of connectivity, traffic diversion or routing manipulation
Naming DNS, registries, registrars and DNSSEC Redirection, domain impersonation, unauthorized changes or outages
Trust Certificate authorities and identity providers Credential theft, fraudulent certificates or broad authentication failure
Platform Cloud services, CDNs, SaaS platforms and APIs Cascading outages, misconfiguration or concentration risk
Software Operating systems, libraries, firmware and update systems Supply-chain compromise, unpatched vulnerabilities or malicious updates
Human Administrators, users, executives and policymakers Phishing, weak access controls, poor decisions and inadequate coordination

Carnegie’s analysis of cyberspace-enabling infrastructure highlights why these layers matter. Attacking a single organization can be damaging; attacking systems such as DNS, root services, certificate authorities, cables, routers or data centers can create consequences for many unrelated users.

Who controls cyberspace?

The simplistic answer that “nobody owns cyberspace” is wrong. Control is distributed among many actors:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • States and regulators create laws, impose obligations, control physical territory and conduct diplomacy and national defense.
  • Telecommunications carriers and Internet exchanges connect networks and manage important transport infrastructure.
  • Cloud, CDN and security providers operate platforms through which large volumes of traffic and applications pass.
  • Registries, registrars and certificate authorities help establish naming and digital trust.
  • Hardware and software vendors determine how products are designed, updated and supported.
  • Standards bodies maintain technical specifications that allow independent systems to interoperate.
  • Enterprises, universities and consumers configure systems, protect accounts and determine how services are used.
  • Criminal groups and state-sponsored operators seek to exploit or disrupt the same systems.

This is a polycentric system: different actors control different layers and have different incentives, capabilities and legal responsibilities. The challenge is to coordinate those centers of control without creating unnecessary centralization or weakening openness.

The main threats

Criminal activity

Ransomware, business-email compromise, credential theft, fraud, data extortion, botnets and distributed denial-of-service attacks are usually motivated by money or access. Exposed cloud consoles, weak identity controls and reused credentials can allow criminals to move quickly from one account or supplier into many others.

State and strategic operations

States and state-linked groups may conduct espionage, steal intellectual property, pre-position inside critical infrastructure, support influence operations or disrupt government, defense, telecommunications, energy, financial, health and transportation systems. A network intrusion may be intended not for immediate damage, but to preserve access for use during a future political or military crisis.

Systemic infrastructure failures

Some incidents are dangerous because of where they occur rather than because of the malware involved. DNS compromise, routing manipulation, certificate-authority failure, submarine-cable disruption, cloud concentration, identity-provider outages, insecure Internet of Things devices and vulnerable open-source dependencies can affect many organizations at once.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why “cyberwar” is not enough

Cyberwar is a dramatic but imprecise organizing concept. Not every breach is an act of war, and not every disruptive cyber operation meets the same legal or strategic threshold. Cybercrime, espionage, sabotage, influence operations and military support activities may overlap technically while differing substantially in motive, law and response.

Rank #3
FortiGate-40F Firewall Appliance plus 1 Year FortiCare Premium and FortiGuard Unified Threat Protection (UTP) (FG-40F-BDL-950-12)
  • INTEGRATED FIREWALL APPLIANCE AND SECURITY SERVICES: Comes with FortiGate-40F Firewall Appliance, 1 year of FortiCare Premium, and FortiGuard Unified Threat Protection.
  • UTP SECURITY FEATURES: Offers protection from advanced threats with DNS filtering, URL filtering, video filtering, and controls against botnets.
  • IDEAL FOR SMALLER SETTINGS: Best suited for small to mid-sized businesses needing reliable security without the complexity of larger systems.
  • CONTINUOUS SUPPORT AND MAINTENANCE: FortiCare Premium ensures that technical help is readily available to manage and troubleshoot issues.
  • COMPACT AND EFFECTIVE: Provides a powerful, yet compact security solution that effectively protects against a wide range of cyber threats.

A better analysis asks four questions:

  1. What system or service was targeted?
  2. What effect did the operation produce—loss of confidentiality, manipulation, disruption, physical damage or economic harm?
  3. Who was affected, directly and indirectly?
  4. What response options are available under domestic and international law?

Attribution is also difficult. Technical indicators may reveal infrastructure or tools without proving who authorized an operation. Public attribution can impose diplomatic costs and establish expectations, but governments may avoid revealing intelligence sources and methods. The absence of public attribution does not necessarily mean the absence of confidence; it may reflect operational secrecy.

International rules and competing models

Cyber governance contains several different kinds of rule:

  • Binding international law, including obligations that states interpret and apply to cyber operations.
  • Political commitments and norms that express expectations for responsible state behavior without functioning as a single global treaty.
  • Technical standards that make systems interoperable and can improve security.
  • National laws and regulation covering privacy, critical infrastructure, cybercrime, reporting and data handling.
  • Contracts and industry requirements that allocate duties among providers, customers and suppliers.
  • Voluntary frameworks that help organizations organize risk-management decisions.

States disagree over sovereignty, surveillance, human rights, data flows, offensive operations, critical-infrastructure protection, encryption and the role of the United Nations versus multistakeholder institutions. The debate is not simply “open Internet versus government control.” It also involves security versus privacy, resilience versus concentration, attribution versus secrecy, interoperability versus localization, and regulation versus innovation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A state may describe filtering or shutdowns as security or sovereignty measures, while others view them as restrictions on access, openness and human rights. Security is not identical to control: a highly centralized network may be easier to regulate, but it can also create single points of failure, reduce privacy and enable political abuse.

The Internet Governance Forum has emphasized practical implementation through security by design, standards deployment, stronger cooperation between incident-response teams and law enforcement, and respect for human rights. Its cybersecurity reports illustrate why norms require operational mechanisms rather than declarations alone.

What public-private cooperation must actually do

“Public-private partnership” is useful only when it describes specific mechanisms. Effective cooperation can include:

  • Structured threat-intelligence sharing with clear handling rules.
  • Coordinated vulnerability disclosure and reliable security-update channels.
  • Computer emergency response team coordination.
  • Joint exercises involving providers, regulators, law enforcement and affected sectors.
  • Sector-specific information-sharing organizations.
  • Procurement rules that reward secure-by-design products.
  • Minimum security requirements for critical suppliers.
  • Emergency communication channels and pre-agreed escalation procedures.
  • Cross-border law-enforcement cooperation and evidence preservation.
  • Transparent reporting from cloud, platform and security providers.

Information sharing alone is not enough. Participants need trust, privacy safeguards, liability clarity, useful data, timely action and a demonstrated ability to respond. Smaller operators also need affordable access to expertise rather than obligations they cannot realistically meet.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A practical framework: NIST CSF 2.0

For organizations, the most useful bridge from global strategy to daily security is NIST Cybersecurity Framework 2.0, published on February 26, 2024. It is voluntary, outcome-oriented and designed for organizations of different sizes, sectors and maturity levels. It does not prescribe one fixed set of controls or automatically secure an organization.

  1. Govern: Set cybersecurity strategy, define accountability, establish policy, oversee risk and set supply-chain expectations.
  2. Identify: Create an accurate picture of assets, dependencies, business priorities, vulnerabilities and likely consequences.
  3. Protect: Apply identity management, access control, training, data security, platform security and other safeguards.
  4. Detect: Monitor for anomalous activity, vulnerabilities and indicators of compromise.
  5. Respond: Contain incidents, communicate with stakeholders, analyze what happened and coordinate decisions.
  6. Recover: Restore services, verify that recovery is safe, communicate status and improve based on lessons learned.

The framework is most valuable when it assigns owners and connects security decisions to business outcomes. A board should know which services are essential, how long they can be unavailable, which suppliers they depend on and how restoration will be funded and tested.

How the framework changes by organization

  • Small organization: Prioritize multi-factor authentication, software updates, email protection, endpoint security, tested backups, least-privilege access and a simple incident plan before buying complex platforms.
  • Cloud operator: Focus on tenant isolation, identity security, secure configuration, resilience across regions, logging, abuse response and transparent dependency management.
  • Government agency: Add mission continuity, operational technology, classified or sensitive information handling, interagency coordination, alternate communications and exercises involving national-level partners.
  • Critical-infrastructure operator: Treat availability, safety and recovery as equal to confidentiality. Legacy and operational systems may require compensating controls, segmentation and carefully scheduled maintenance rather than ordinary IT patching.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

DNS: a concrete example of shared security

The Domain Name System translates human-readable domain names into IP addresses. It is also an important point for security policy and a source of signals about malicious activity. A DNS outage can make a service unreachable; unauthorized DNS changes can redirect users or undermine confidence in a domain.

Rank #4
SonicWall TZ270W Wireless Gen7 Firewall | SMB Wi-Fi Security Appliance with 2 Gbps Firewall Speed, Integrated Wireless Radios, Threat Protection, and Cloud Management (02-SSC-2823)
  • SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
  • Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
  • Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
  • Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
  • Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.

Organizations should distinguish authoritative DNS, which publishes the records for a domain, from recursive DNS, which looks up records on behalf of users and applications.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For high-value domains, practical protections include:

  • Using DNSSEC where the domain and operational environment support it.
  • Enabling multi-factor authentication on registrar and DNS-provider accounts.
  • Using registry-lock or equivalent controls for critical domains.
  • Monitoring for unauthorized record, nameserver and delegation changes.
  • Restricting administrative access and reviewing it regularly.
  • Maintaining resilient DNS arrangements where the risk justifies more than one provider.
  • Documenting emergency contacts and recovery procedures.

DNSSEC authenticates the integrity and origin of DNS data. It does not encrypt DNS queries, guarantee availability, protect registrar credentials or secure an endpoint. NIST’s SP 800-81 Revision 3, Secure Domain Name System Deployment Guide, finalized in March 2026, provides current deployment guidance.

Important trade-offs

Openness versus control

Interoperability and open access support innovation and commerce, but they can also accelerate abuse and exploitation. Centralized controls may improve security in some settings while increasing censorship, surveillance, concentration and the impact of a single failure.

Resilience versus concentration

Large providers can deliver security and availability capabilities that small operators could not build alone. Dependence on a small number of cloud, DNS, identity or security providers can nevertheless turn a local failure into a systemic outage. Redundancy should be evaluated by actual independence, not merely by purchasing multiple services that rely on the same underlying provider.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Security versus usability

Strong authentication, segmentation, encryption, device management and detailed logging add cost and friction. Controls should be proportionate to the consequences of compromise and designed so that users can follow them reliably.

Regulation versus innovation

Baseline requirements can reduce negligent practices and improve supply-chain security. Poorly designed rules can create overlapping obligations, encourage checkbox compliance or burden small organizations without improving resilience.

Common mistakes

  • Discussing cyberspace as an intangible cloud while ignoring cables, power, data centers and people.
  • Calling every intrusion cyberwar.
  • Assuming national borders no longer matter.
  • Treating public-private cooperation as a mailing list rather than an operating capability.
  • Relying on compliance certificates without testing detection, containment and restoration.
  • Buying tools before identifying assets, dependencies and recovery priorities.
  • Ignoring domain registrars, DNS, identity providers, software dependencies and suppliers.
  • Failing to test whether backups can actually be restored.
  • Assuming DNSSEC provides encryption.
  • Believing that one security vendor eliminates systemic risk.

What securing the commons should mean

Perfect prevention is impossible. The realistic objective is to reduce systemic risk, preserve interoperability, make attacks less profitable and limit the duration and reach of failures.

That requires responsibility at every layer:

Actor Primary responsibilities
Governments Law, diplomacy, national defense, critical-infrastructure policy, incident coordination, capacity-building and rights protections
Infrastructure operators Secure networks, cloud systems, DNS, routing, certificates and platforms; provide resilience, transparency and abuse response
Technology vendors Secure development, vulnerability handling, supported products, trustworthy updates and useful security documentation
Organizations Risk management, identity protection, access control, segmentation, monitoring, backups, exercises and recovery planning
Users Multi-factor authentication, updates, cautious handling of messages, secure devices and prompt reporting
International institutions Norm development, technical coordination, standards, incident-response cooperation and capacity-building

The responsibility is shared, but it is not identical. A consumer cannot secure a submarine cable, and a cloud provider cannot decide an organization’s recovery priorities. Effective stewardship means placing each obligation with the actor that has the authority, visibility and capability to meet it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Conclusion

Cyberspace should be governed as a shared global system while recognizing that its infrastructure is neither ownerless nor beyond national jurisdiction. The “global commons” idea is valuable because it emphasizes shared dependence and the consequences of neglect. It becomes misleading when used to claim that cyberspace is legally equivalent to the high seas or outer space.

The durable answer is layered cooperation: international norms and national law, secure infrastructure and products, responsible platform operations, resilient organizations, and users who are protected rather than blamed for failures they cannot control. The test of that model is not whether incidents disappear. It is whether the system can resist, contain and recover from them without sacrificing the openness, privacy and interoperability that make cyberspace valuable.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.