Skip to main content
Media & Entertainment

International Cybersecurity Law and Governance: A Book Review

August 8, 2026By HRU LEGAL

International Cybersecurity Law and Governance: A Book Review

If you have ever wondered what actually happens, legally speaking, when a hospital's computer systems are hijacked by hackers in another country, or when a state-backed group interferes with another nation's power grid, you have bumped into one of the hardest and newest problems in international law. There is no single global "cyber law" the way there is a Constitution or a Penal Code. Instead, there is a patchwork of treaties written before the internet existed, newer conventions that only some countries have signed, informal norms that everyone talks about but few enforce, and a lot of grey area in between.

A new academic textbook, International Cybersecurity Law and Governance, written by Prof. (Dr) Said Gulyamov, Dr Yevgeniy Kolenko, and Shakhzod Musaev, tries to map this messy terrain for students and practitioners. The book was recently reviewed by Dr Islambek Rustambekov, Acting Rector of Tashkent State University of Law, in a piece published on SCC Times. That review is thoughtful but written in fairly academic language and aimed at readers who already know the field. This piece takes the same material and unpacks it in simple terms, adds context for readers who are new to the subject, and goes a little deeper into why each point actually matters.

Why a Textbook on Cybersecurity Law Even Needs to Exist

Most law students grow up studying branches of law that have existed for decades, sometimes centuries: contracts, torts, criminal law, constitutional law. Cybersecurity law is different. It sits at the intersection of three things that are all moving targets at once: technology, which changes every few years; international politics, where countries disagree sharply on how much control a government should have over the internet; and traditional legal doctrine, which was written for a physical world of borders, territory, and armies.

That mismatch creates real practical problems. When a cyberattack crosses borders in milliseconds, which country's laws even apply? When an attack is carried out through servers in three different nations by an actor whose identity is deliberately hidden, how do you assign legal responsibility? When a cyberattack disables a hospital's systems and, as a result, a patient dies, is that an act of war, a crime, or something the law hasn't quite named yet?

These are not hypothetical questions. They come up constantly, and lawyers, diplomats, and judges need a reliable base of study material to work from. That is the gap this textbook is trying to fill, and it is the reason the reviewer opens by stressing just how relevant and timely the subject is, both for advancing legal theory and for training the next generation of specialists who will actually have to deal with these problems in government, in the UN, and in private practice.

What the Book Tries to Do Differently

According to the review, the authors did not simply summarise existing law. They tried to build an original structure that gives students a complete, connected picture of international cybersecurity law rather than a list of disconnected topics. A few things stand out about the approach:

It systematises a scattered field. Cybersecurity law does not live in one treaty or one code. It is spread across cybercrime conventions, humanitarian law principles, data protection regulations, and the informal practices of states and international bodies. The book attempts to organise all of this into a coherent structure and classify the different types of legal instruments involved, which is genuinely useful because most students encounter this material piecemeal, through separate courses or scattered reading, and rarely see how the pieces connect.

It looks at what states actually do, not just what treaties say. International law on paper and international law in practice are often two different things. The book pays close attention to how states and international organisations are actually behaving in cyberspace right now, which gives students a much more realistic picture than a purely textual reading of old treaties would.

It tackles the hardest question in the field head-on. One of the most difficult and contested areas of this subject is whether, and how, the laws of armed conflict apply to cyber operations. Can a cyberattack ever be treated the same way as a missile strike? The book takes this on directly, which the reviewer singles out as an innovative and valuable contribution because so much existing material either avoids the question or treats it superficially.

It teaches through cases. Rather than only presenting rules in the abstract, the authors have built a case-analysis methodology so students can practise applying the law to real, messy fact patterns, which is exactly the skill they will need once they leave the classroom.

Going Deeper: What the Reviewer Thinks Is Missing

A good academic review does not just praise a book; it also points out where it could be stronger. Dr Rustambekov offers ten specific, detailed suggestions, and it is worth walking through what each of these actually means in simple terms, because together they paint a picture of just how wide this subject really is.

1. Bring in the philosophy of the "information society." Before you can regulate the internet, it helps to understand the ideas that shaped how societies think about technology and law in the first place. Thinkers like Manuel Castells and Jürgen Habermas wrote influential theories about how information technology reshapes social and political institutions. The reviewer suggests the book would benefit from grounding its legal analysis in this broader intellectual history, rather than jumping straight into rules.

2. Rethink territorial sovereignty for a borderless space. One of the oldest ideas in international law is that a state has supreme authority within its own territory. But data does not really respect borders; a single email can cross five countries in a second. The reviewer wants a deeper look at whether, and how, the old idea of territorial sovereignty can be meaningfully applied to cross-border data flows, which is really a question about how much control any single country can legitimately claim over something that physically passes through, but doesn't stay in, its jurisdiction.

3. Cover the competing global approaches to fighting cybercrime. The book already discusses the Budapest Convention on Cybercrime, which is the oldest and most widely referenced international treaty on the subject, first opened for signature in 2001. But not every country has signed on to it, and some, including Russia, have pushed for an alternative: a new United Nations convention on cybercrime with different terms. The reviewer wants students to see both sides of this debate, since it reflects a genuine split in how the world is approaching cybercrime cooperation.

4. Dig deeper into the law of cyber warfare. This is arguably the single most difficult question in the entire field: can existing international humanitarian law, the law that governs armed conflict, apply to attacks carried out purely through computer code? The reviewer points to the Tallinn Manual, a detailed academic study on how international law applies to cyber warfare, as a resource the book should engage with more closely, along with the significant disagreements that manual has generated among experts.

5. Recognise the role of technical, non-government organisations. Governments and the UN are not the only players setting the rules of the internet. Technical bodies like ICANN, which manages the internet's domain name system, and IETF, which develops many of the internet's core technical standards, quietly shape global norms in ways that traditional international law rarely accounts for. The reviewer wants their role explored in more depth.

6. Explain how national cyber-emergency teams cooperate across borders. Almost every country now has some version of a Computer Emergency Response Team, or CERT, that responds to major cyber incidents. But when an attack crosses borders, how are these teams legally allowed to share threat information with each other? The review suggests this cross-border cooperation, and the legal basis for it, deserves closer examination.

7. Address artificial intelligence and quantum computing. These are the two technologies most likely to reshape cybersecurity law over the next decade. AI can be used both to launch and to defend against attacks, and quantum computing threatens to eventually break much of today's encryption. The reviewer suggests a dedicated section on how these emerging technologies are already forcing lawmakers to rethink existing rules.

8. Look at cybersecurity in outer space. This point is easy to overlook but genuinely important. Modern life, from GPS navigation to weather forecasting to military communication, depends heavily on satellites, and those satellite systems are themselves vulnerable to cyberattack. The reviewer wants the book to expand its treatment of how international law protects, or fails to protect, space-based infrastructure from cyber threats.

9. Cover cryptocurrency and blockchain risks. Digital currencies and blockchain systems create new avenues for money laundering and terrorism financing that traditional financial regulation was not built to catch. The reviewer suggests a dedicated legal analysis of this fast-moving area.

10. Compare global approaches to cross-border data protection. Different regions have taken very different approaches to protecting personal data as it flows across borders, from the European Union's GDPR, to California's CCPA, to China's own data protection framework. The reviewer suggests the book would benefit from directly comparing these regimes, since understanding those differences is essential for any lawyer working on international data transfers.

Taken together, these ten points are not really criticisms of what the book gets wrong. They read more like a wish list from someone who found the book valuable enough to want even more from it, which is itself a strong compliment.

What the Reviewer Ultimately Concludes

Despite this long list of suggestions, the review's overall verdict is clearly positive. Several strengths are highlighted repeatedly:

  • Breadth. The book is described as covering an unusually wide span of the subject, from foundational legal theory all the way to the practical mechanics of international cooperation against cyber threats.
  • Interdisciplinary thinking. The authors are praised for weaving together legal analysis with the technological, political, and economic realities of cybersecurity, rather than treating law as if it exists in isolation from the world it regulates.
  • Practical grounding. Real cases, real examples from state practice, and practical exercises are built into the text, which the reviewer sees as essential for turning theoretical knowledge into a skill students can actually use.
  • Forward-looking content. Rather than only describing settled law, the book also offers the authors' own views on where the field is heading next.
  • Clarity of writing. The structure is described as logical and the language as accessible, while still maintaining enough rigour to be useful for advanced, not just introductory, courses.

The review closes by recommending the textbook for publication and for use in training the next generation of international law and cybersecurity specialists.

Why This Kind of Book Matters Right Now

Stepping back from the specifics of this one review, it is worth asking why a book like this matters at all, especially to readers who are not cybersecurity specialists.

The honest answer is that the gap this book is trying to close affects almost everyone indirectly. Hospitals, banks, power grids, election systems, and government services are all now run on digital infrastructure, and that infrastructure is a constant target. When something goes wrong, whether it is a hospital's patient records being locked by ransomware or a country's power grid being knocked offline, the legal response depends entirely on whether there are clear rules for who is responsible, which country's courts or agencies can act, and what counts as an acceptable response.

Right now, much of that legal groundwork is still being built in real time, through exactly the kind of academic scholarship this textbook represents, through UN negotiations, and through slow, case-by-case state practice. A textbook that manages to organise this field clearly, connect it to real examples, and remain readable is genuinely useful, not just for law students, but for policymakers, technology companies, and anyone trying to understand how the rules of the internet are actually being written.

Who Should Read It

Based on the review, this book is best suited to:

  • Law students specialising in international law, technology law, or national security law
  • Practising lawyers advising governments or companies on cross-border cyber incidents
  • Policy professionals working on cybersecurity strategy or diplomacy
  • Anyone teaching or studying how international law is adapting to the digital age

Readers looking for a beginner's introduction to "what is cybersecurity" may find it dense, since it is written as a university-level textbook. But for anyone who already has a basic grounding in international law and wants a structured, up-to-date map of how that law applies to cyberspace, the review suggests this is a strong and serious addition to the field.

This blog is a summary and analysis based on a published book review. It is for general informational purposes only and does not constitute legal advice or an endorsement of the book's contents. For guidance on cybersecurity law or related legal questions, please contact our team.