The whole conversation about securing new tech is stuck on myths that make good policy and defense almost impossible to build. The UN Security Council’s discussions on cybersecurity constantly show how much basic misinformation is out there, distracting everyone from the attacks that are actually happening and the practical ways to stop them.
Key Takeaways
- Securing new tech isn’t just for spies. It takes real public-private international teamwork.
- You can’t just ‘trace the IP’, real cyberattack attribution is slow, painstaking forensic work.
- Firewalls and defenses aren’t enough. Deterrence now demands proactive threat intel and even some offensive capability.
- There are no real ‘rules of the road’ for cyber warfare yet. Consensus on binding international law is a long way off, especially for state-sponsored attacks.
- Your tech supply chain is a huge risk. Securing it means deep vendor vetting and constant monitoring, not just checking a box.
Myth 1: Cybersecurity for Emerging Tech is Primarily a Military or Intelligence Concern
The idea that the biggest cyber threats to things like AI or quantum computing are only a problem for the military or spy agencies is flat-out wrong. That thinking completely misses how these attacks affect everyday civilian life and the economy. A 2025 World Economic Forum (WEF) report pointed out that 85% of critical infrastructure in developed countries is owned by the private sector, and those are the real targets. When attackers hit the operational technology (OT) in power grids, water treatment plants, or transit systems, often by exploiting AI-driven controls, the results can be devastating. Just look at the 2024 incident where a ransomware variant got into an AI-powered industrial control system at a major European seaport. It shut the port down for days. Lloyd’s of London estimated the economic damage was in the hundreds of millions of Euros, proving that civilian infrastructure isn’t just collateral damage, it’s the main event. The UN Security Council keeps repeating that this requires a whole-of-society effort, because with everything so interconnected, a breach in one private company can bring down an entire sector.
Myth 2: Cyberattack Attribution is Straightforward and Immediate
The media loves to show investigators pointing a finger at a specific country or hacker group minutes after an attack. In the real world, attributing a sophisticated attack, especially one from an advanced persistent threat (APT) hitting new tech, is a slow grind that can take months or even years of digital forensics. Attackers are masters of disguise, routing their attacks through hacked servers in a dozen countries, using anonymizing tools, and deliberately copying the tactics, techniques, and procedures (TTPs) of other groups to throw investigators off the scent. As the United Nations Office for Disarmament Affairs (UNODA) noted in an April 2026 statement, “the challenges of attribution often delay international responses and complicate efforts to hold perpetrators accountable.” Take the 2025 cyber espionage campaign against a bunch of biotech firms. The goal was to steal IP on genetic sequencing. Initial evidence pointed to one nation-state, but after a consortium of security firms including Mandiant (now part of Google Cloud) dug in, they found a totally unknown group using custom malware and zero-day exploits. This made definitive state attribution next to impossible, leaving diplomats fumbling and making a coordinated security response incredibly difficult.
Myth 3: A Purely Defensive Cybersecurity Posture is Sufficient
Too many organizations, and even some countries, think cybersecurity is just about building a strong wall with firewalls, intrusion detection systems, and antivirus software. While you absolutely need that stuff, it’s not nearly enough to stop a smart, well-funded attacker. The UN Security Council’s own discussions keep circling back to the need for more proactive strategies. This means building out threat intelligence capabilities so you can see an attack coming instead of just cleaning up after it. The idea of “active defense”, taking lawful steps to disrupt an attack in progress, is also gaining ground. This isn’t about ‘hacking back’ (which is usually illegal). It’s about using intelligence to proactively harden your systems, hunt for threats that are already inside your network, and share actionable intel with others. For example, the US Cybersecurity and Infrastructure Security Agency (CISA) put a lot of money into its Joint Cyber Defense Collaborative (JCDC) to get private companies and government agencies sharing real-time threat data and coordinating their defense. A real strategy for new tech security has to combine defense with intel gathering and active threat hunting, because you have to assume the bad guys will eventually find a way over your wall.
Myth 4: International Cybersecurity Norms are Well-Established and Universally Accepted
Anyone who tells you there’s a clear ‘Geneva Convention’ for cyberspace is misinformed. Yes, there’s been some progress with UN groups like the GGE and OEWG, but we’re a long way from a global consensus on binding rules, especially when it comes to what’s legal in cyber warfare. The UN Security Council struggles with this constantly. For instance, what even counts as an “armed attack” in cyberspace that would trigger the right to self-defense under Article 51 of the UN Charter? Some countries argue it has to involve physical destruction or death, while others say a debilitating attack on a power grid or financial system is enough. Is turning off the lights an act of war? Nobody can agree. This ambiguity creates a massive gray area where state-sponsored hacking can operate without fear of immediate, unified international consequences. A 2023 report from the UN Secretary-General on this very topic pointed to ongoing “divergent interpretations” among states, confirming the legal framework is anything but settled.
Myth 5: Securing the Supply Chain for Emerging Technologies is a Solved Problem
Thinking you can secure the supply chain for advanced semiconductors or AI components with standard procurement forms and basic vendor checks is a dangerous mistake. The supply chain for new tech is a tangled, global web of third-party vendors, sub-component makers, and software developers, and it’s often impossible to see every link. Any one of those links can introduce a huge vulnerability, from a compromised hardware implant to malicious code injected during a software update. The US National Institute of Standards and Technology (NIST) has published its Cybersecurity Supply Chain Risk Management (C-SCRM) guidance, which basically says you have to practice paranoid vigilance: continuously monitor everything, rigorously vet all suppliers, and demand a software bill of materials (SBOM) for anything you buy. The 2024 discovery of backdoors in firmware from a major industrial IoT device manufacturer shows how bad this can get. The backdoors were there for two years before anyone found them. Inserted by what was likely a state actor, they could have given someone the keys to critical infrastructure all over the world. The UN Security Council is now focused on this because they know a single compromised chip from one country can create a global security hole for everyone. The assumptions we’re working with are old. To get this right, we need to be more realistic, more proactive, and work together internationally, because the digital future we’re building depends on it.
What is meant by “emerging technologies” in a cybersecurity context?
These are new, fast-moving technologies with huge economic and social effects that also create new security headaches. We’re talking about things like artificial intelligence (AI), quantum computing, advanced biotech, AR/VR, and next-gen IoT devices. Each one opens up a whole new set of potential vulnerabilities and attack methods.
Why is cybersecurity for emerging technologies a concern for the UN Security Council?
The UN Security Council sees it as a threat to international peace and security. A major cyberattack, especially one that hits critical infrastructure or uses AI in autonomous weapons, could easily destabilize a country, wreck an economy, or cause a shooting war to break out. That makes it a global governance problem.
How does AI impact cybersecurity for both defenders and attackers?
AI helps and hurts. For defenders, it’s great for automating threat detection and spotting unusual activity that a human analyst might miss. For attackers, it’s a tool to build smarter malware that can change on the fly, run huge phishing campaigns, and find software vulnerabilities automatically, creating a constant arms race.
What are “zero-day exploits” and why are they dangerous for emerging tech?
A “zero-day” is an attack that uses a security flaw that the software maker doesn’t know about and hasn’t patched. They’re especially bad for new technologies because the systems are so complex and new that finding all the bugs before release is nearly impossible. An attacker who finds one has a powerful weapon, because there are “zero days” of warning for defenders.
What role do international norms play in securing cyberspace?
They’re supposed to be the ‘rules of the road’ for how countries behave online, developed through UN processes to create stability and reduce the risk of conflict. In theory, they clarify what’s acceptable and what’s not. In practice, they’re voluntary and every country interprets them differently, so they have very little teeth.