Operationalizing Digital Resilience: Implementing WSIS+20 and the Global Digital Compact Across Critical Infrastructure
WSIS Forum 2026 - Session 235 - 9 July 2026
VIDEO | AUDIO | RECAP EN / FR / ES | SLIDES | REPORT | ARCHIVE | PERMALINK
Moderator: Maarten Botterman – Director, GNKS Consult BV
Speakers: Vinton G. Cerf - former Chief Internet Evangelist, Google; Marina Pappas - Institute Director, Marconi Society; Victor Kuarsingh - Internet Resilience Institute, Marconi Society; Ram Mohan - Chief Strategy Officer, Identity Digital; Philippe Fouquart - Senior Expert, Orange; Dr. Moritz Müller - Research Engineer, SIDN; Katarina Garic - CMO, SCION Association; Raneem Zaitoun - Youth Ambassador, Internet Society
Framing the Challenge
Maarten Botterman opened the session by arguing that digital resilience has become an essential prerequisite for societies that increasingly depend on trustworthy Internet infrastructure. He emphasized that resilience is not automatic but requires deliberate design, coordination, and sustained investment. The session drew on work undertaken through the Marconi Society’s Internet Resilience Institute to explore practical approaches for implementing the goals of WSIS+20 and the Global Digital Compact.
Marina Pappas explained that the Marconi Society’s Internet Resilience Institute originated from a simple but provocative question posed during its inaugural workshop: if the Internet suffered a global failure, what would be required to reboot it? That question shifted attention from recovering after failures toward designing systems capable of withstanding and adapting to disruption. She stressed that resilience is fundamentally a multistakeholder challenge requiring shared accountability, practical guidance, and collaborative frameworks rather than isolated technical solutions.
Vint Cerf: Resilience as the Foundation of the Future Internet
Vinton Cerf argued that resilience underpins the ambitions of both WSIS+20 and the Global Digital Compact. Reliable digital infrastructure must encompass far more than hardware reliability, extending to trustworthy software, dependable operations, and confidence that systems behave predictably under normal and adverse conditions.
He noted that Internet reliability depends upon numerous interconnected layers:
electrical power
terrestrial and submarine communications infrastructure
satellite connectivity
transport protocols such as TCP/IP and QUIC
application platforms including the Web
countless services operating above them
Because failures frequently emerge through hidden dependencies, Cerf argued that identifying and understanding these interdependencies is one of the most important tasks facing the Internet community.
He observed that resilience must also account for systems operating under continuous stress, including:
increasing demand exceeding available capacity
cyberattacks
malware
denial-of-service attacks
politically motivated Internet shutdowns
Drawing lessons from the Internet’s development, Cerf identified several enduring design principles that continue to strengthen resilience:
simplicity reduces unnecessary complexity and failure points
layered architecture allows technologies to evolve independently while preserving stable interfaces
multistakeholder cooperation enables independently operated networks to function as a unified Internet
open standards support interoperability across diverse operators
the end-to-end principle allows innovation without requiring continual changes to the network itself
He also highlighted the Internet’s tradition of creating new institutions whenever emerging challenges demanded them, citing organizations including the Internet Architecture Board, IETF, IRTF, ICANN, the Internet Society, Regional Internet Registries, Computer Emergency Response Teams, FIRST, and the Internet Governance Forum.
Cerf concluded that future resilience efforts should focus on systematically identifying architectural dependencies while developing measurable metrics to evaluate whether resilience is genuinely improving.
Mapping Dependencies Through “The Life of a Packet”
Victor Kuarsingh introduced work undertaken by the Internet Resilience Institute to visualize how an apparently simple Internet transaction actually depends on a remarkably complex ecosystem.
Using the example of a Zoom call, he showed that communication traverses numerous independently operated components including:
mobile access networks
Internet service providers
cloud provider infrastructure
subsea cables
backbone networks
application providers
supporting infrastructure
The exercise demonstrated that no single organization possesses complete visibility across the entire communications path.
Kuarsingh described a layered infrastructure model separating:
user-facing Internet services
underlying communications infrastructure
critical dependency layers
Those dependency layers include elements such as:
electrical power
data centres
emergency services
construction and physical infrastructure
supporting utilities
He emphasized that these dependencies are often circular. Digital infrastructure depends upon sectors such as energy, while those sectors themselves increasingly rely upon Internet connectivity. Understanding these relationships provides the foundation for meaningful resilience planning.
Business Resilience Beyond Traditional Continuity Planning
Ram Mohan argued that the Internet has evolved from being merely another communications system into essential critical infrastructure supporting financial markets, public services, and global communications.
While the Internet itself was designed to route around failures, he noted that many organizations depending upon it have not adopted equivalent resilience practices.
A central problem, he argued, is that organizations frequently mistake redundancy for resilience. Backup connections may appear independent while actually sharing common vulnerabilities such as:
physical infrastructure
upstream providers
power supplies
cloud platforms
These hidden dependencies frequently remain invisible until simultaneous failures occur.
Mohan stressed that resilience planning should assume outages will happen rather than treating them as unlikely events.
He presented a voluntary operational framework consisting of four stages:
Assess
identify Internet-dependent business functions
classify operational criticality
evaluate readiness
Model
build realistic risk scenarios
assess likelihood and impact
learn from actual incidents rather than hypothetical extremes
Plan
prepare technical infrastructure
establish backup systems
develop communications plans
train operational staff
Own and Test
assign clear responsibility
regularly test failover capabilities
update plans after incidents
create continuous learning cycles
He emphasized that resilience only becomes operational when someone owns responsibility, exercises the plan regularly, and incorporates lessons learned.
Operational Perspectives from Internet Operators
Philippe Fouquart described resilience from the perspective of Orange, which operates telecommunications networks across Europe, Africa, and the Middle East.
He explained that Internet service providers are often the first organizations contacted when users experience outages, requiring rapid identification of whether failures originate within their own infrastructure or elsewhere across increasingly complex supply chains.
Modern mobile services, he noted, involve multiple independent organizations including:
radio access network providers
core network vendors
cloud providers
public key infrastructure operators
DNS resolver operators
number portability services
Because resilience depends upon every participant, understanding organizational dependencies is as important as understanding technical ones.
Fouquart also emphasized supplier diversity, arguing that resilience requires avoiding excessive dependence on any single vendor or provider.
SIDN: Technical and Strategic Resilience
Dr. Moritz Müller described resilience practices developed by SIDN, operator of the Dutch .nl country-code domain.
He identified two complementary categories of resilience:
technical resilience
strategic resilience
Technical resilience has required expanding DNS infrastructure globally to withstand localized outages while deliberately relying on multiple external providers instead of operating entirely in-house.
However, SIDN also investigates hidden dependencies by examining whether providers share:
upstream networks
software platforms
operational infrastructure
The organization continually measures these overlaps to reduce systemic risk.
Müller observed that geopolitical developments have recently become an increasingly significant resilience consideration. As a result, SIDN migrated from US-based infrastructure providers toward European providers to reduce strategic dependency arising from political uncertainty.
He added that SIDN ultimately seeks provider-agnostic operations that allow infrastructure to move between suppliers whenever circumstances require, although achieving that flexibility remains a long-term objective.
SCION: Alternative Architectures for Critical Infrastructure
Katarina Garic presented SCION as an alternative networking architecture designed specifically for highly resilient critical infrastructure.
She explained that SCION improves resilience through three principal characteristics:
connectivity delivered through federations of Internet service providers rather than single providers
user control over routing choices based on performance, sovereignty, or policy requirements
complete visibility across the communications supply chain
Greater transparency reduces third-party risk while allowing organizations to understand and control network dependencies more effectively.
Garic cited deployment within Switzerland’s financial sector through the Secure Swiss Finance Network, supporting over 300 financial institutions and processing approximately CHF 220 billion in transactions daily. Since entering production in 2022, she reported that the platform had experienced no outages or security incidents.
A Human-Centred View of Resilience
Raneem Zaitoun argued that discussions of resilience frequently concentrate on infrastructure while overlooking the people whose lives depend upon it.
She observed that every technical dependency ultimately serves human users, whose vulnerability varies dramatically depending upon their circumstances.
For example, failure scenarios differ significantly between:
large enterprises
governments
mobile-first users
young people in the Global South
individuals working within informal economies
For many users, there is no practical redundancy or institutional backup when connectivity fails.
Zaitoun noted that young people represent the largest cohort of new Internet users globally, with many relying exclusively on mobile connectivity under precisely these vulnerable conditions.
She proposed incorporating lived experience directly into resilience modelling by testing dependency maps against realistic user scenarios—for example, examining how service failures affect a teenager in Lagos dependent upon mobile Internet access. Including organizations representing such users would strengthen resilience frameworks by grounding them in practical realities rather than enterprise assumptions alone.
Discussion and Closing Reflections
During discussion, Wout de Natris questioned how organizations could encourage senior executives to invest in resilience before incidents occur, noting that many significant breaches reveal prior warnings that were ignored. He also asked whether CEOs and boards should face greater accountability when technical advice is disregarded.
Maarten Botterman acknowledged that resilience increasingly extends beyond technical operations into corporate governance. Emerging legislation already places greater responsibility on boards of directors for ensuring resilient services.
He emphasized that conferences alone cannot improve resilience unless they inspire practical action. Pointing to Cloudflare’s transparent handling of a major outage as an example of good practice, he argued that organizations must prepare for failures collectively, respond openly when incidents occur, and continue strengthening resilience through cooperation across governments, industry, technical communities, and civil society.
The session concluded with a call for participants to apply the guidance developed by the Marconi Society, deepen understanding of infrastructure dependencies, and translate resilience principles into operational practice across organizations and critical infrastructure.
RESOURCES
WSIS Forum 2026 — Session 235 — official agenda page for this session on operationalizing digital resilience
Marconi Society Internet Resilience Institute — the institute that convened the panel and its resilience workstreams
Life of a Packet mapping — documented in the IR Institute’s “Internet Resilience Frameworks for Coordinated Global Action” report, on the Marconi reports library
Business Resilience Guide — the IR Institute guide Ram Mohan urged organizations to adopt, on the Marconi reports library
Global Digital Compact — UN framework for resilient, trustworthy digital infrastructure cited throughout
SCION architecture — the next-generation routing approach Katarina Garic presented, behind the Secure Swiss Finance Network
SCION Association — non-profit driving global SCION adoption across critical sectors
SIDN — Dutch .nl registry; Dr. Moritz Müller on DNS and strategic resilience
DC-ISSS / IS3C — Wout de Natris’s coalition on deploying security-related Internet standards, tied to his accountability question
Internet Society Youth Ambassador Program — Raneem Zaitoun’s panel role


