Tuvalu faces an existential challenge. At the current rate of climate-change driven sea-level rise, this small Pacific island state could be submerged within decades. The encroaching ocean poses a profound question: What happens to a country without land?
At the 27th annual United Nations Climate Change Conference in 2022, Tuvalu’s then-Foreign Minister Simon Kofe announced a bold strategy for the nation to become the world’s first ‘digital nation’. Rather than treating digitisation as a symbolic archive, the initiative seeks to create a fully functional digital continuity of the state: official records, cultural heritage, territorial maps, and government systems would be preserved online, enabling Tuvalu to continue existing even if its physical territory disappears.
The initiative forms part of Tuvalu’s broader Future Now: Preparing Today to Secure Tomorrow programme (known in Tuvaluan as ‘Te Ataeao Nei’). It reflects decades of climate advocacy in which Tuvalu has highlighted that climate change threatens not just territory but self‑determination and political autonomy.
Under the digital nation initiative, the government is undertaking a plethora of activities, including three‑dimensional mapping of all 124 islands and islets and upgrades to national communications infrastructure to support cloud‑based governance. To complement this, Tuvalu has also amended its constitution to affirm that its statehood will continue, ‘notwithstanding the impacts of climate change or other causes resulting in loss to the physical territory.’
Recent steps toward this vision have included strengthening digital connectivity through the 2025 launch of the Tuvalu Vaka submarine cable, advancing the three-dimensional mapping and digitisation of cultural and governmental records, and consolidating the international recognition and support necessary to preserve state continuity despite potential territorial loss.
Digital nations
While the framing of a ‘digital nation’ does highlight the preservation of national identity, it is also concerned with ensuring the continuity of Tuvalu as a functioning state despite the possible loss of habitable territory. But can a state continue to exist when its core governmental functions depend on externally hosted digital systems?
Although traditional conceptions of the state place significant emphasis on territory, recent international legal scholarship and state practice increasingly recognise the possibility that statehood may persist despite territorial loss through continued recognition, international relations, and political legitimacy.
Yet, legal continuity alone does not guarantee functional continuity. A state must also retain the ability to perform governmental functions, provide services, maintain institutions, and connect with its population. With the loss of its physical territory, a fully digitally sustained Tuvalu would rely heavily on digital infrastructure and systems hosted abroad, placing core governmental functions beyond its direct control.
The challenge for Tuvalu therefore becomes not only whether it can continue to exist legally as a state, but how it can maintain the practical ability to exercise sovereignty – its authority to govern and make decisions independently – when the infrastructure and systems through which it governs are controlled by actors beyond its jurisdiction.
Against this background, international cybersecurity governance, in particular the United Nations framework of responsible state behaviour in cyberspace, provides an important lens through which to examine the implications of a digitally sustained state. But is the framework equipped to address a situation in which the continued exercise of state authority depends on digital infrastructure and systems located beyond the state’s jurisdiction?
The limits of existing international cybersecurity governance
Developed through six UN groups of governmental experts (GGEs) and successive open-ended working groups (OEWGs), states have established a framework of responsible state behaviour in cyberspace comprising voluntary norms, cyber confidence-building measures, capacity-building principles, and the application of existing international law, including the UN Charter. The framework was developed to promote stability, cooperation, and responsible conduct between states in cyberspace. More recently, the UN Global Mechanism for ICT Security was set up to provide a permanent platform through which states can continue discussing its implementation and future development.
While the framework has made an important contribution to international cybersecurity governance, it was developed primarily around interactions between territorial states. The eleven voluntary norms focus on responsible state behaviour but presume that states retain authority over the systems upon which essential governmental functions depend. For example, they encourage states to protect critical infrastructure, assist others during cyber incidents, and prevent their territory from being used for malicious cyber activity. These norms assume that states can identify, regulate, and secure the infrastructure within their territory.
Similarly, confidence-building measures seek to improve communication, transparency, and cooperation during cyber incidents between sovereign governments exercising authority within their territory. Capacity-building initiatives aim to strengthen national capabilities, reflecting the understanding that cyber vulnerabilities can largely be addressed through the development of domestic institutions, expertise, and infrastructure.
The same territorial logic is evident in discussions around international law. By affirming that existing international law applies in cyberspace, the framework has encouraged important debates concerning sovereignty, non-intervention, and state responsibility, particularly how these principles constrain state behaviour through obligations relating to unlawful interference, due diligence, and responsibility for cyber activities.

However, these discussions have largely examined how states can protect their sovereignty from external cyber operations, rather than situations where the exercise of sovereign authority itself depends on digital infrastructure located beyond a state’s territorial control.
The challenge is further complicated by the growing role of private actors. Cloud providers, telecommunications companies, and technology platforms increasingly operate infrastructure upon which governments depend, yet the framework’s expectations are directed primarily at states.
Taken together, the framework’s various components reveal the underlying territorial understanding of sovereignty. While digital technologies may transform how governments operate, the framework was developed around the assumption that the exercise of state authority remains rooted in institutions, infrastructure, and jurisdiction connected to territory under a state’s control.
This assumption rarely attracts attention because, for most states, digital technologies have tended to supplement rather than replace the territorial foundations of sovereignty. For example, in 2006, the Maldives opened an ‘embassy’ in the virtual world Second Life, primarily as a tool for representation and economic promotion, allowing the country to engage with a global audience and attract tourism and investment through a virtual platform. Estonia launched an e-Residency programme in 2014 to enable foreign nationals to access Estonian digital services, establish businesses, and participate in the country’s economy without ever setting foot on its territory. More recently, following Russia’s full-scale invasion in 2022, Ukraine has come to rely on emergency data migration, cloud services hosted abroad, and international technical assistance to maintain essential governmental functions.
Rethinking sovereignty in practice
Tuvalu presents a challenge that existing international cybersecurity governance has not fully anticipated. While its digital nation initiative has emerged from the existential threat posed by climate change, its significance extends beyond climate adaptation. The prospect of a state continuing to exercise authority through digitally mediated institutions raises broader questions about sovereignty, control, and dependency in an increasingly interconnected world.
If governmental authority depends on digital infrastructure located in foreign jurisdictions and operated by private actors, traditional assumptions linking sovereignty to territorial control become increasingly difficult to sustain. The UN Framework, with its territorial understanding of sovereignty, is only partially equipped to address this challenge, offering limited guidance for situations where the continued exercise of state authority depends on external digital infrastructure beyond a state’s control.
As states increasingly rely on digital systems to deliver public services, communicate with citizens, maintain official records, and perform core governmental functions, sovereignty has become increasingly intertwined with the security and resilience of the infrastructure on which those functions depend.
In this sense, Tuvalu is not simply a climate story. Rather, it represents an extreme example of a broader transformation already underway. The challenge for international cybersecurity governance may therefore be not only protecting states in cyberspace, but understanding how the exercise of state authority itself is being reshaped by digital technologies.






