














Canada recently signed the United Nations Convention against Cybercrime, a comprehensive global treaty that aims to boost international collaboration to fight cybercrime and facilitate the sharing of electronic evidence in serious criminal cases.
Signing is just the first step; a country becomes legally bound only after ratification, acceptance, or approval. After years of work, the convention was adopted by the UN General Assembly on December 24, 2024, opened for signature on October 25, 2025, at a signing ceremony held in Hanoi, Vietnam, and will remain open for signature at UN headquarters in New York until the end of this calendar year. As of July 21, 2026, three countries have completed the process of ratification, acceptance, or approval, and the treaty will come into force 90 days after 40 countries ratify it.
It’s the early stages, and while Canada’s effort is notable, the treaty’s overall significance is not just in the number of signatories. It’s in creating a stronger foundation for international cooperation against cross-border and cross-technology criminal activities.
Cybercriminals deliberately use fragmentation to thwart law enforcement by distributing their infrastructures across multiple countries with victims worldwide. And their financial networks are kept separate from both victims and infrastructure, making tracking even harder. This complexity undermines cyber defenses and law enforcement because stolen credentials stolen in one jurisdiction are often sold in others, used to breach systems elsewhere, and then monetized through various crime intermediaries.
This issue extends beyond technical concerns, leading to legal and operational delays exactly when defenders and investigators need to respond most quickly. And worse, malicious infrastructure can be swapped out, data can vanish, assets can be redirected, and threat actors can adjust their operations before traditional cross-border procedures can keep up.
The treaty seeks to reduce some of that friction by establishing a shared framework for issues like cybercrime offenses, investigative procedures, electronic evidence, extradition, mutual legal assistance, asset recovery, victim protection, and international cooperation. It also requires participating states to set up 24x7 contact points to offer immediate help with cybercrime and electronic evidence matters.
These mechanisms assist authorities in preserving evidence, finding suspects, sharing information, and responding to emergencies more efficiently. For countries with underdeveloped cybercrime laws, investigative skills, or international partnerships, the treaty can also serve as a foundation for building these capabilities.
The treaty establishes a critical common legal framework for governments. However, transforming this framework into real change demands continuous operational collaboration. Its rules on prevention, international cooperation, technical support, and information sharing strengthen four key capabilities necessary for effective public-private partnerships.
For nearly 15 years, Fortinet has worked with public- and private-sector partners to build these four pillars into a practical model for combating cybercrime. That experience has consistently demonstrated why no single participant can see or act against the entire criminal ecosystem.
Law enforcement possesses the investigative powers and legal authority to arrest and prosecute offenders within established jurisdictions. Private-sector organizations offer additional but complementary forms of visibility. Cybersecurity firms, technology vendors, financial institutions, telecom companies, researchers, and infrastructure operators can detect malicious activity, criminal networks, or emerging tactics before a case is brought to law enforcement.
The challenge lies in connecting these sources of intelligence through trusted mechanisms that allow information to be validated, enriched, shared, and acted upon at the speed cybercrime requires. The treaty addresses this need through provisions that foster cooperation among law enforcement, justice authorities, the private sector, civil society, academia, and other stakeholders. It also promotes technical assistance, training, capacity building, and the exchange of expertise and knowledge.
That is a critical acknowledgment of how cybercrime disruption functions in practice. A public-private partnership isn’t just an add-on starting after governments formulate their strategies. It’s an integral component of the operational model essential for an effective response.
Fortinet has seen the value of this model through years of collaboration with organizations such as INTERPOL, the World Economic Forum, the Cyber Threat Alliance, and Crime Stoppers International.
For nearly a decade, Fortinet has participated in INTERPOL’s Global Cybercrime Expert Group. FortiGuard Labs researchers assist INTERPOL-led efforts by providing intelligence and technical knowledge to help investigators detect malicious networks and cybercriminal activities. Fortinet is also a founding member of the Cyber Threat Alliance, which brings cybersecurity providers together to share timely threat intelligence that improves collective detection and response. And through the World Economic Forum’s Cybercrime Atlas, private-sector partners collaborate to map criminal ecosystems and create intelligence packages that can support coordinated action by law enforcement.
These collaborations have supported global efforts against ransomware, business email compromise, online fraud, digital extortion, and other cyber-enabled crimes. The Cyber Threat Alliance strengthens intelligence sharing across the cybersecurity industry. INTERPOL has repeatedly emphasized that its private-sector partners offer critical intelligence, investigative support, and training to help countries identify offenders and respond to suspicious IP addresses, domains, and command-and-control servers. This highlights the distinction between simple information exchange and gathering intelligence for specific operational goals.
Our recent collaboration with Crime Stoppers International advances this model even further by tackling another key challenge: gathering actionable intel on cybercriminal individuals and organizations. The newly established Cybercrime Bounty program offers a secure, anonymous platform for individuals and ethical hackers to share information about cybercriminal actors and networks through this shared incentives initiative. Crime Stoppers International supplies the trusted reporting framework, while Fortinet offers threat intelligence expertise to verify and interpret the data before, when suitable, forwarding it to law enforcement.
The treaty also places substantial emphasis on technical assistance and capacity building, particularly for developing countries. This emphasis is vital because cybercriminals do not confine their operations to jurisdictions with mature investigative resources.
When defensive, investigative, or judicial capacity is limited, criminals find room to develop infrastructure, recruit accomplices, launder money, and target victims in other locations. These weaknesses become vulnerabilities within the broader digital ecosystem.
Capacity building must therefore extend beyond just technology acquisition. It also involves developing investigative skills, enhancing digital forensics, training prosecutors and judges, improving evidence-handling methods, forming partnerships with private-sector providers, and establishing procedures that enable the rapid sharing of intelligence without compromising privacy or due process.
The private sector can support global capacity building by sharing technical expertise, emerging threat intelligence, training resources, and practical experience. Through the Fortinet Training Institute, the NSE Certification program, and its network of academic and training partners, Fortinet helps develop the skills individuals and organizations need to defend networks, investigate cybercrime, and support coordinated response efforts.
In June 2026, Fortinet fulfilled its five-year pledge to train more than 1 million people in cybersecurity ahead of schedule. This work supports the UN Convention against Cybercrime’s emphasis on technical assistance and capacity building by helping more countries and organizations participate effectively in cybercrime prevention, investigation, and disruption.
International cooperation on electronic evidence must also be rooted in the rule of law. Throughout the treaty’s development, civil society groups, tech companies, and human rights specialists voiced concerns about potential misuse of cybercrime laws, investigative powers, and cross-border data requests.
As a result, the final treaty includes provisions on human rights, proportionality, privacy, due process, child protection, and grounds for refusing certain requests. These safeguards must be implemented through national legislation and operational practice. Cooperation cannot be sustainable if it undermines the trust of the people, researchers, service providers, and institutions whose participation it requires.
This principle also extends to legitimate cybersecurity research, where ethical researchers play a crucial role in identifying vulnerabilities before criminals can exploit them. It is vital that any implementation clearly separates legitimate security activities from malicious actions.
While the UN Convention treaty offers a framework, each country is responsible for deciding how many of its provisions to adopt into national law and practice. Continuous meaningful engagement with civil society, security research communities, private-sector entities, and human rights experts will be crucial throughout both the ratification and implementation phases.
Canada’s signature adds critical momentum, but it is not the same as ratification or implementation. The treaty will not enter into force until 40 states become parties, and its ultimate impact will depend on what happens after that threshold is reached.
Countries will need to align their laws, establish operational procedures, designate points of contact, train personnel, and develop mechanisms for cooperation. They will also need to build the trusted relationships that allow public agencies and private organizations to work together before a crisis occurs.
Cybercriminals have already built global, collaborative, and highly specialized ecosystems. Defenders must be equally coordinated.
The UN Convention against Cybercrime represents an important opportunity to move from fragmented cooperation toward a more consistent global model. Realizing that opportunity will require governments, law enforcement, international organizations, civil society, and the private sector to treat collaboration not as a statement of intent, but as a sustained operational commitment.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。