Four things, each with their own time horizon and in parallel.
1. Norms for cyber warfare and international cyber activity to be developed. (The US may not be able to lead this post-Snowden, but they should try and should be involved.)
2. Cooperation on international standards, development and funding in cyberspace to improve and prove the security of networks, protocols, hardware and software.
3. Deescalation of cyber capabilities and activities. These exercises can be expressed in many ways such as 'cyber-free days' where nations show their good intentions by withholding operations in good faith.
4. International investment, development, data sharing and standardization of forensics capabilities to squeeze the attribution problem. This may be done in lockstep with protocol development.
But at its root there are three reasons nations hack one another: intelligence, intellectual property, sabotage.
Whatever deterrents and legal frameworks are in place will need to be as or more compelling than the motivations for cyberactivity. Whatever can be done to limit what can be gained by intelligence, sabotage and IP theft will in turn limit cyber activity. So a fifth item would be to reexamine and double down on the international peace keeping frameworks that discourage the listed above.