The digital realm connects over two-thirds of humanity – approximately 5.6 billion people in 2025 – yet no individual, government, or organization fully controls it. The online world has a physical dimension because all the computers, servers, cables, satellites, routers, and data centers that comprise the Internet – this digital realm – exist somewhere and belong to someone. Yet the digital realm, often referred to as cyberspace, also exists as a distinct domain with its own operational logic, including international standards, and governance structures.
Today’s Internet began in the late 1960s as ARPANET, a pioneering project funded by the U.S. Department of Defense’s Advanced Research Projects Agency (DARPA). It achieved a historic breakthrough by introducing packet switching, a method that broke data into smaller chunks to travel independently across a decentralized network. In 1969, UCLA and Stanford University successfully transmitted the very first interconnected node-to-node message. This foundational infrastructure expanded rapidly during the 1970s and 1980s, eventually adopting the TCP/IP protocol suite that established a universal, standardized language for computers to communicate globally, laying the groundwork for modern cyberspace.
From these novel beginnings, cyberspace has evolved into a mainstay of human activity and civilization. Global banking, electrical grids, supply chains, and all other major contemporary systems rely on digital infrastructure. The great majority of international financial transactions are settled through networked systems, and billions of people depend daily on cloud computing, mobile networks, and internet-connected services. Humanity’s economic productivity, social cohesion, and national security are now inseparable from the stability of cyberspace.
However, the legal foundations of this ecosystem have created deep systemic friction; for instance, regulatory frameworks like Section 230 of the Communications Decency Act – originally designed to foster early internet innovation – have produced unintended consequences by shielding platforms from liability. This broad immunity has not only introduced severe cybersecurity vulnerabilities by disincentivizing proactive defenses against malicious infrastructure, it has also led to profound societal impacts by allowing digital manipulation, polarization, and algorithmic harm to undermine democratic processes and social cohesion.
Driven by the misaligned incentives resulting from these early policy choices, cyberspace has become extraordinarily vulnerable. While the digital world possesses resilient qualities because of its decentralized architecture, in many respects it is also brittle, and without significant interventions it will become increasingly so. A disruption in one sector or region can rapidly cascade and cause further disruptions across borders and sectors. For example, in 1988, as a high-risk experiment, a computer programmer launched the “Morris worm” and unintentionally infected and crashed an estimated 10% of Internet servers. The crisis inspired the creation of the CERT Control Center (computer emergency response team) to coordinate research on software bugs that affect Internet security. In another example, almost two decades ago, in 2008, a local order by the Pakistani government to block YouTube accidentally leaked to the rest of the world, resulting in a global internet blackout that knocked the video platform offline for millions of users worldwide. This crisis exposed a dangerous, foundational flaw in how the internet directs traffic: network providers blindly trusted each other’s routing signals without checking their accuracy. The chaos demonstrated that a single administrative error in one country could quickly and easily cripple global digital infrastructure. The speed, scale, and interconnectedness of cyberspace create systemic risks unlike those found in traditional physical infrastructure.
These contradictions stem partly from the nature of cyberspace itself and early policy choices intended to help it flourish. As a network of nodes operating at near light speed, it is discontinuous – information does not “stop” between nodes. Concepts such as near and far or adjacent do not function in cyberspace the same way they do in the physical world. Contrary to popular belief, borders abound in cyberspace because there are routers, switches, servers, filters, and firewalls everywhere, but these borders rarely align with the arbitrary political borders humanity has drawn across the Earth. Almost everything can potentially connect to everything else, and what happens in one part of cyberspace can almost instantaneously affect every other part.
These characteristics mean that while cyberspace does not constitute a global commons in the traditional sense of international waters or Antarctica, it nevertheless exhibits many of the characteristics of a shared global domain and common good. Like other public goods, cyberspace requires governance mechanisms capable of protecting collective interests while preserving security, openness, innovation, and freedom.
Without effective stewardship, cyberspace risks falling further prey to a digital tragedy of the commons – overrun by cybercriminals, disinformation actors, hostile intelligence services, and free riders who exploit the system without contributing to its security and sustainability. The free market alone has not optimally supported the common-good dimensions of cyberspace.
The magnitude of cybercrime demonstrates this danger clearly. Estimates vary, but some projections place the annual global cost of cybercrime at trillions of dollars per year. If cybercrime were measured as a national economy, it would rival the GDP of the world’s largest countries. The harms include ransomware attacks on hospitals, financial fraud, cryptocurrency theft, online child exploitation, intellectual property theft, attacks on water systems and power grids, phishing scams, identity theft, election interference, and distributed denial-of-service (DDoS) attacks capable of disrupting critical infrastructure. And nation-states can leverage the vulnerabilities that enable these harms as central tools of geopolitical competition, putting other countries, their people, and their values at risk.
The rise of AI-assisted cybercrime and cyber operations further compounds these threats. Anthropic’s April 2026 announcement regarding its unreleased Claude Mythos Preview model set off global alarms due to its unprecedented ability to autonomously identify, link, and exploit long-hidden security vulnerabilities across major operating systems and web browsers. The model demonstrated a radical shift in threat capability by exposing decades-old flaws in highly secure, hardened software – prompting Anthropic to withhold it from public release and instead limit its access to governments and critical infrastructure defenders through a select coalition known as Project Glasswing. Generative AI systems increasingly enable sophisticated phishing campaigns, automated vulnerability discovery, deepfake-enabled fraud, and scalable social engineering operations.
Cybersecurity experts are increasingly warning that humanity faces not only criminal cyber threats but also systemic risks associated with cyber warfare and infrastructure collapse. Nation states now maintain offensive cyber capabilities capable of targeting power grids, hospitals, communications infrastructure, transportation systems, and financial institutions. Some experts describe cyberspace as the fifth domain of warfare, alongside land, sea, air, and space.
Beyond intentional attacks, natural phenomena also threaten the stability of the digital commons. A sufficiently severe solar storm – sometimes referred to as a “Carrington Event,” referencing the massive 1859 geomagnetic storm – could damage satellites, electrical grids, submarine cables, and communications systems across continents. Modern civilization has never experienced a Carrington-scale event in the age of cloud computing and globally interconnected infrastructure. A major geomagnetic storm today could disable financial systems, internet routing, GPS navigation, and electrical transmission systems simultaneously.
Humanity must therefore invest in cyber resilience as a global public good. Recommended measures include:
- Secure-by-design-and-default software and hardware;
- Greater redundancy in critical communications infrastructure;
- Hardened electrical grids and satellite systems;
- International backup coordination mechanisms;
- Improved cybersecurity standards for critical infrastructure;
- Public-private emergency cyber response systems;
- Expanded cyber hygiene education;
- Greater investment in open-source security infrastructure;
- Resilient local mesh networks and offline failover systems;
- Scenario planning for catastrophic cyber or solar events.
Because cyberspace is inherently transnational, governance cannot rely solely on nation states. Instead, cyberspace governance has evolved through a “multi-stakeholder” model involving governments, private companies, technical communities, civil society organizations, nonprofits, and academic institutions.
A remarkable ecosystem of organizations has emerged to govern, secure, and sustain cyberspace.
The International Telecommunication Union (ITU), founded in 1865 and later integrated into the United Nations system in 1947, coordinates global telecommunications and radio spectrum governance. The ITU played a foundational role in international communications long before the Internet era and remains an important venue for debates about digital governance and standards.
The Institute of Electrical and Electronics Engineers (IEEE), formally established in 1963, develops many of the technical standards that underpin global digital infrastructure, including networking technologies such as Wi-Fi and Ethernet.
The Internet Engineering Task Force (IETF), founded in 1986, develops the technical protocols and standards that enable the Internet to function. Through its open and collaborative model, the IETF has helped maintain interoperability across the global Internet. One of its major contemporary efforts involves advancing stronger encryption standards and next-generation transport security protocols to improve end-to-end privacy and resilience against surveillance and cyberattack.
The Internet Society (ISOC), established in 1992, supports the open development and accessibility of the Internet globally and serves as an institutional home closely connected to the IETF process.
The Internet Corporation for Assigned Names and Numbers (ICANN), established in 1998, coordinates key technical functions of the global Internet, including domain names and IP address systems. One of the most historically significant moments in Internet governance occurred on October 1, 2016, when oversight of ICANN’s Internet Assigned Numbers Authority (IANA) functions transitioned from the United States Government to the global multi-stakeholder community. This transition represented a landmark moment in the evolution of global digital governance – encapuslating a shift away from unilateral governmental stewardship toward a more internationally distributed governance model for the Internet commons.
Together, ISOC, ICANN, the IETF, the Regional Internet Registries, and a few others, are collectively known as the I* (I-star) group, responsible for coordinating the technical infrastructure of the Internet.
The United Nations established the Internet Governance Forum (IGF) in 2006 to serve as a neutral, multi-stakeholder space for global policy dialogue, explicitly separating policy debate from technical internet management. While technical organizations like ICANN manage domain names and IP addresses, the IETF develops core network protocols, and ISOC promotes open internet development, the IGF holds no decision-making or operational power over them. Instead, it acts as an umbrella discussion forum where these technical bodies, governments, civil society, and private companies meet on equal footing. This unique relationship allows technical experts from ICANN, ISOC, and the IETF to inform global policy discussions, while ensuring that the actual infrastructure of the internet remains managed by technical experts rather than political entities.
The Mutually Agreed Norms for Routing Security initiative (MANRS), launched in 2014 by the Internet Society, works to improve the security and resilience of global Internet routing infrastructure from blind trust to strict verification, meeting the need demonstrated by the 2008 Pakistan / YouTube incident.
Other organizations focus specifically on cyber defense and digital safety. The Forum for Incident Response and Security Teams (FIRST), founded in 1990, brings together security researchers to limit the damage of security incidents by exchanging information. The Messaging Anti-Abuse Working Group (MAAWG), established in 2004, fights online abuse such as phishing, spam, denial-of-service attacks, and more. The Global Anti Scam Alliance, founded in 2019, coordinates international efforts to combat online fraud and digital scams. The Global Cyber Alliance, founded in 2015 by law enforcement and private sector partners, develops practical tools to reduce cyber risk globally. The Cyber Threat Alliance, established in 2014, enables cybersecurity companies to share threat intelligence collaboratively to improve collective defense. Protect.ngo, formerly the Cyber Peace Institute, founded in 2019, advocates for the protection of civilians in cyberspace and works to reduce harms caused by cyberattacks, especially against vulnerable populations and critical services. Common Good Cyber, founded in 2022, focuses on strengthening cybersecurity for civil society organizations and advancing cybersecurity as a public-interest issue.
Together, these and many other cyber-focused civil society organizations illustrate how cyberspace governance increasingly depends upon distributed institutional stewardship rather than centralized sovereign control.
At the same time, major governance tensions remain unresolved. One important example concerns the future of encrypted Internet transport protocols. The IETF and broader technical community have increasingly pushed toward stronger end-to-end encryption and more privacy-preserving Internet architecture. These efforts seek to reduce surveillance, improve user security, and defend against cybercrime and authoritarian misuse of network infrastructure.
However, stronger encryption standards also create challenges for cyber security monitoring systems that rely on visible network metadata and packet inspection. In recent years, the IETF has advanced privacy-enhancing technologies that previously remained visible to network operators. These developments improve user privacy and reduce surveillance risks, but some argue that they also reduce visibility into malicious traffic, complicating threat detection. These tensions between privacy, security observability, and network management have become central governance debates in the future evolution of Internet architecture.
This tension illustrates a broader reality: cyberspace governance often involves balancing competing legitimate interests – privacy, security, reliability, innovation, sovereignty, openness, commerce, and civil liberties.
The governance of cyberspace therefore requires a sophisticated, layered, and adaptive approach. Several principles may help guide future governance efforts:
- Preserve the open and interoperable nature of the Internet;
- Protect human rights and freedom of expression online;
- Strengthen international cooperation against cybercrime;
- Increase transparency and accountability in digital governance institutions;
- Promote cyber resilience as a global public good;
- Expand participation from civil society and developing countries;
- Support open technical standards and secure-by-design infrastructure;
- Enforce norms limiting cyberattacks on civilian infrastructure;
- Encourage responsible state behavior in cyberspace;
- Invest in long-term resilience against catastrophic digital disruption.
Philanthropy has a particularly important role to play in this evolving ecosystem.
Historically, philanthropy has helped build many public service institutions, yet it still devotes relatively limited resources to cyberspace governance and digital public infrastructure compared to the scale of humanity’s dependence on these systems.
There are several areas where philanthropy could make transformative contributions:
- Providing financial support to grantees to cover their cybersecurity;
- Funding research into scalable technical and policy solutions to reduce legacy technical debt globally;
- Supporting nonprofit cyber defense organizations;
- Funding cybersecurity capacity building in developing countries;
- Supporting digital rights and civil liberties organizations;
- Funding open-source security infrastructure;
- Expanding cyber education and workforce development;
- Supporting research into catastrophic cyber risk and solar resilience;
- Supporting cyber peacebuilding and conflict prevention initiatives;
- Supporting election integrity and anti-disinformation programs;
- Building resilience for hospitals, schools, NGOs, and local governments;
- Supporting international multi-stakeholder governance processes.
Philanthropy is uniquely positioned to fund areas neglected by governments and markets alike – especially preventative investments whose benefits are diffuse, long-term, and global.
The digital commons cannot sustain itself automatically. Humanity must actively govern, secure, and invest in cyberspace if it wishes to preserve an open, stable, and trustworthy Internet for future generations.
Like climate stability, biodiversity, or public health, cybersecurity increasingly functions as a shared planetary challenge. The future of cyberspace will depend not only on technology, but on governance, cooperation, institutional innovation, and collective stewardship.
The Internet has become one of humanity’s most important shared systems. Protecting it may ultimately become one of civilization’s defining governance challenges of the twenty-first century.
| Grantmakers can connect with peers through the the NetGain Partnership and collaborate to “influence policy, markets, norms, and the design and use of the internet and information technologies to make the world a better place.” The Internet Governance Forum Trust Fund helps donors to support inclusive, global level dialog to shape digital public policy. The How to Fund Tech Guide offers foundations a useful starting point for evaluating technology-related grants. The Common Good Cyber Fund serves as a regranter to support nonprofit cybersecurity advisors. Finally, donors concerned about solar storms should review the 2008 report on Severe Space Weather Events, and explore joining forces with RADAR, a global effort to develop future-ready power grids managed by the Electric Power Research Institute. |