In all popular web-pages it is possible to increase and decrease font size by holding Ctrl-key (in OS X Cmd-key) and pressing “+” or “-“-key. It is very convenient to use mouse: holding Ctrl and scrolling mouse central scroll button. It is possible to go back to normal size pressing Ctrl and 0-keys.
Navigation with a keyboard
Our website can also be navigated using a keyboard only. Navigation is done using the Tab key. With each press, the focus moves to the next element. The currently active element is marked by the boxes around it. To activate the link in focus, press Enter on the keyboard.
If you think you see this text unintentionally
It might happen, that some elements of our webpage or platform did not arrive to you as planned, they are served from some buffer (cache). To resolve it, please try to do “hard refresh”, hold down Ctrl (Control) + Shift and type R.
For more information about hard refresh in different systems and browsers, please choose some of the results of Google Search: browser hard refresh.
Still no help with actual content?
Second option will be to try to clean up the cache on your own browser. Please choose some of the appropriate results of Google Search: browser clear cache.
After that, you might refresh your query again or order new login token to be sent to your email once again.
Still no help?
Sorry for inconvenience. Please take a snapshot of your browser configuration by visiting webpage www.whatismybrowser.com and send the unique link of it by email to .
Thank you!
Reflecting EU CyberNet Summer School 2026: Andrea Calderaro
EU CyberNet discussed with Summer School 2026 participants their experience and thoughts on the future of cyber diplomacy. Read an interview with our co-organiser Andrea Calderaro, Project Director of EU Cyber Direct.
With the first substantive meeting of the UN Global Mechanism on ICT security in July 2026, cyber diplomacy has just moved from two decades of ad hoc formats into a permanent institutional home, which turns the challenge from securing institutional standing into delivering on what it promised. Permanence is itself a test, because the practices established in the first cycle become the baseline for everything that follows.
Why did you decide to teach in the Summer School, what spoke to you the most and what do you hope trainees take from this training into their daily work?
My enthusiasm for sharing knowledge, perspectives and expertise rests in a constant passion to learn from the exchange with the diverse expertise, backgrounds and regional perspectives available in these settings. Capacity building is indeed not training, but a reciprocal effort to build common knowledge, and a programme that treats it as transmission, from those who know to those who need to know, will produce neither knowledge nor capacity. In particular, this Summer School has brought together an outstanding variety of profiles, backgrounds and regional experience, with practitioners working in very different national settings. That is precisely the configuration cyber diplomacy capacity building efforts should aim for. Learning how to bridge multilateral processes with national priorities, and how to translate diplomatic efforts into the daily work of the technical, scientific and industry communities and vice versa, is where capacity is actually built.
A norm that no state has the institutional capacity to implement is not a security outcome, it is a statement of intent. Diplomacy sets the expectation. Capacity determines whether that expectation ever reaches a national CERT, a regulator or an operator.
What do you think are the current challenges in cyber diplomacy? How are they related to cybersecurity? What are the most pressing issues in your daily line of work?
With the first substantive meeting of the UN Global Mechanism on ICT security in July 2026, Cyber Diplomacy has just moved from two decades of ad hoc formats into a permanent institutional home, which turns the challenge from securing institutional standing into delivering on what it promised. Permanence is itself a test, because the practices established in the first cycle become the baseline for everything that follows.
Three challenges follow. The first is participation. Expectations are high on how the new Mechanism will integrate stakeholder expertise into the multilateral format itself. The establishment of the Dedicated Thematic Groups, designed to draw on non-state perspectives, is one of the most significant achievements of Cyber Diplomacy so far, because it formalises stakeholder contribution rather than leaving it to each process to arrange anew. The modalities remain uncertain, however, and it is not yet clear how to ensure that the Groups become a channel through which expertise reaches decisions rather than a venue where it is merely heard.
The second is capacity. Capacity building is still largely treated as a broad concept, on the assumption that all agree what it is and what is needed. I believe instead that the dedicated attention the Mechanism gives it, through its own Thematic Group, is an opportunity to reflect on new modalities and ambitions, and to read capacity building as cyber accountability building rather than as a supplementary programme.
The third is convergence. Cyber Diplomacy has had difficulty integrating the impact of emerging technologies, including AI, into its negotiations. The Mechanism may create the opportunity to bring the AI governance and cybersecurity tracks together, and the open question is whether they will address shared inequalities or reproduce them in parallel.
The link to cybersecurity is direct. A norm that no state has the institutional capacity to implement is not a security outcome, it is a statement of intent. Diplomacy sets the expectation. Capacity determines whether that expectation ever reaches a national CERT, a regulator or an operator. In my own work, the most pressing issue is exactly that translation: how a commitment agreed in New York becomes something that changes practice at home.
From your perspective as an instructor, what do you expect EU CyberNet to provide or facilitate?
A week of training produces a cohort, but what turns a cohort into capacity is what happens in the eleven months that follow. EU CyberNet is remarkably well placed to provide that continuity, because it holds the two assets that are hardest to build: a standing expert pool and durable regional relationships. Sustaining the alumni network beyond the week itself, so that participants keep a working channel to one another and to the expert pool as their institutional roles evolve, is where a training programme becomes something more durable than a training programme.
The implication is that cyber diplomacy capacity building is not a peripheral activity but the mechanism through which the field connects to the expertise it depends on, and that this requires deliberately diversifying who is in the room.
What is one thing that has stuck with you from this year’s Summer School?
How distant the multilateral processes still are from the daily work of practitioners and national agencies. The expertise in the room was considerable, and participants were working on precisely the questions the negotiations address, yet what was shared about how those negotiations actually run was genuinely new to many of them and, by their own account, directly useful. That gap is the finding. The implication is that cyber diplomacy capacity building is not a peripheral activity but the mechanism through which the field connects to the expertise it depends on, and that this requires deliberately diversifying who is in the room. National experts, regulators, incident response teams and the technical and industry communities hold the operational knowledge that makes commitments realistic, and they are also the actors who would translate those commitments into practice at home. Without them, negotiations proceed on assumptions about national capability that no one in the room is positioned to test, and outcomes arrive in capitals with no one prepared to act on them. Widening the audience is therefore not a matter of inclusion for its own sake. It is what allows cyber diplomacy to benefit from national expertise, and national expertise to benefit from cyber diplomacy.
About Andrea Calderaro
Through my entire career, research and studies, my work has been led by the question of how to design modalities and formats that make technology governance accessible to most and capable of reflecting regional perspectives and priorities. In cyber diplomacy, reaching that condition is critical so that multilateralism can draw on the complementary expertise the task requires, and at the same time represent regional priorities and the specific challenges that come with them. It is in the nature of any global challenge that the actors negotiating how to face it are accountable to one another, and that accountability holds only where each of them can act at home on what is agreed. A seat at the table is not the same as the capacity to act on what is decided there. The first is now widely available. The second requires a serious fine-tuning of capacity building efforts. The EU has built an outstanding range of instruments for this, spanning diplomacy, capacity building and research, and connecting them to one another is what leads both my scholarly work and my role as Director of EU Cyber Direct at the European Union Institute for Security Studies.
Background
EU CyberNet Summer School 2026, titled “Cyber Diplomacy: From Norms to Actions – Governing Cyberspace in a Fractured World” was organised by EU CyberNet in partnership with EU Cyber Direct, and Cyber 4.0 with expertise from the European External Action Service at the European University Institute in Florence, Italy from 29 to 31 July 2026. Summer School 2026 was led by Isabella Brunner (EU CyberNet instructor), Andrea Calderaro (EU Cyber Direct, European Union Institute for Security Studies – EUISS) and Michal Aendenhof (European Union External Action Service – EEAS) . Read more here.
How did you like this content?
Did this article answer all your questions? Give us your feedback and help us improve!
EU CyberNet launches a podcast series to bridge the expertise from EU CyberNet’s Expert Pool and its partners to wider cybersecurity and cyber capacity building community on people, policies and practices shaping cybersecurity globally.
EU CyberNet has published the ninth blog article in its Expert Blog Series. The ninth article, titled “When AI Makes Cybersecurity Decisions: Five Governance Questions Every Organisation Should Answer” is written by EU CyberNet Expert Anahiby Becerril.
EU CyberNet has published the eight blog article in its Expert Blog Series. The eight article, titled “The Institutional AI Dependency Test: Can Public Services Continue When AI Cannot Be Trusted? An Evidence-Led Governance Exercise for Cyber Resilience” is written by EU CyberNet Expert Andra T. Alcalá.
EU CyberNet asked four EU CyberNet Summer School 2026 participants – Gabrielle Botbol, Emmanuel Chagara, Olesya Danylchenko and Lisbeth Laurie – to share their experience in the Summer School.
EU CyberNet,together with LAC4, participated in the EU-LAC Digital Alliance technical exchange visit on cybersecurity and secure connectivity in Central America and the Cybersec Summit 2026 in San José, Costa Rica on 11-12 August 2026.
EU CyberNet asked four EU CyberNet Summer School 2026 participants – Gabrielle Botbol, Emmanuel Chagara, Olesya Danylchenko and Lisbeth Laurie – to share their experience in the Summer School.