UN Global Mechanism on cybersecurity begins work with focus on participation and consensus
The UN’s new permanent cyber mechanism began its substantive work by adopting its first programme of work while exploring how consensus, stakeholder participation, and practical cooperation will shape future discussions on international ICT security.
The United Nations’ new permanent mechanism on international cybersecurity has begun its substantive work, opening a new phase of multilateral discussions on responsible state behaviour in cyberspace.
The first substantive session of the Global Mechanism on Developments in the Field of ICTs in the Context of International Security opened on 20 July at UN Headquarters in New York under the chairmanship of Ambassador Egriselda López of El Salvador. The meeting marked the first time member states had convened within a standing UN framework dedicated to ICT security and responsible state behaviour.
The mechanism succeeds years of negotiations under the Open-Ended Working Group and is intended to provide a permanent, single-track forum for discussions across five established pillars, such as existing and potential ICT threats, rules and norms of state behaviour, the application of international law, confidence-building measures, and capacity development.
In a pre-recorded statement, UN Under-Secretary-General and High Representative for Disarmament Affairs Izumi Nakamitsu described the mechanism as holding ‘tremendous promise’. She highlighted its permanent and consensually agreed character and called for stakeholder engagement to take place in a systematic, sustained, and substantive manner.
A permanent forum takes shape
Opening the session, López described the meeting as a historic moment that would help shape not only the first two-year cycle of the mechanism but also the UN’s wider approach to ICT security in the years ahead.
She acknowledged that the forum was beginning its work amid a complex international environment marked by attacks against critical infrastructure, disruptions to digital supply chains, the use of ICTs in conflicts, and the growing interaction between cybersecurity and emerging technologies such as AI.
The Chair also emphasised that agreement would require sustained diplomatic effort.
‘Consensus is not automatic,’ López told delegations, arguing that it must be built through commitment, flexibility, and political will.
She noted that multilateral processes are often advanced through ‘small steps, difficult compromises, and the willingness to keep talking even when there are differences’.
The session achieved an early procedural milestone with the adoption, by consensus, of the provisional agendas for the 2026 and 2027 plenary sessions. The mechanism also noted its provisional programme of work, creating a framework for the substantive discussions scheduled for the week.
The mechanism tests its approach to stakeholder participation
A substantial part of the opening discussion focused on how non-governmental stakeholders should participate in the mechanism.
Under the agreed accreditation procedure, applications are accepted unless a member state submits a written objection. The Chair reported that she had held consultations with states that raised objections, although the positions of the concerned governments remained unchanged.
Several delegations expressed concern that a large proportion of stakeholder applicants had not received accreditation. They argued that technical experts, civil society organisations, industry representatives, and academic institutions can provide knowledge that supports informed negotiations and practical implementation.
The issue was particularly important for smaller and developing states, some of which said they rely heavily on external partners because they have limited domestic technical and diplomatic capacity.
Kiribati emphasised that technical partners and regional organisations had contributed to its national cybersecurity posture and helped shift international discussions from problem identification to solution delivery. It called for greater transparency around objections, arguing that explanations could help states understand and potentially address the concerns raised.
‘Transparency here costs the objecting state little; silence costs the rest of us a great deal,’ the delegation said.
Other delegations placed greater emphasis on ensuring that participating organisations meet the agreed standards of objectivity and impartiality. They maintained that the non-objection procedure was negotiated by consensus and that states retained the right to raise concerns about individual applicants.
The discussion, therefore, reflected a broader institutional question of how the mechanism can preserve state oversight while gaining access to the technical expertise needed for meaningful cybersecurity cooperation.
Participation rules remain important for thematic work
Delegations also considered how stakeholder participation should function in the Dedicated Thematic Groups scheduled to meet from 7 to 11 December.
The mechanism will operate two such groups. One will address general substantive issues, while the other will focus on capacity development. Their purpose is to enable more detailed and interactive discussions that build on the work of the annual plenary.
Some delegations argued that, because the thematic groups are informal, they should be able to include a wide range of experts and stakeholders without requiring the same accreditation process used for formal plenary sessions.
Others maintained that the agreed participation modalities for the mechanism should apply consistently across all its formats. From this perspective, applying different rules to the thematic groups could weaken their intergovernmental character or create uncertainty over the status of their outcomes.
The debate highlighted the need for predictable working methods before the December meetings. Clear guidance on participation, expert briefings, meeting formats, and reporting procedures will be particularly important for delegations with limited resources.
Procedural questions shape preparations for thematic discussions
The Chair also announced the appointment of four co-facilitators for the thematic groups, selected from Australia, Egypt, Malaysia, and the Netherlands.
López said the appointments reflected geographic and gender balance and that the co-facilitators would serve in their personal capacities under the principles of neutrality, impartiality, and inclusion.
Many delegations welcomed the appointments as a practical step towards ensuring that preparations for the December meetings could move forward. They viewed the selection of facilitators as consistent with practices used in other UN processes.
Other delegations preferred the appointments to be formally agreed upon by consensus among all member states. They argued that the mechanism’s state-led character requires collective agreement on both procedural and substantive decisions.
The exchange demonstrated that the meaning of consensus will remain an important issue as the new forum develops its institutional practices. The challenge will be to preserve the confidence of all states while allowing the mechanism to carry out the organisational work needed to function effectively.
From general debate to practical cooperation
Beyond the procedural questions, delegations began outlining how the thematic groups could contribute to the mechanism’s wider objectives.
Several countries supported focused, scenario-based discussions addressing concrete challenges such as ransomware, attacks against critical infrastructure, AI security, operational technology, quantum readiness, and post-quantum cryptography.
Others emphasised that the groups should maintain a balanced approach across all five pillars of the framework and avoid prioritising specific topics without the agreement of member states.
Capacity development emerged as a particularly important theme. Developing and smaller states highlighted the role of partnerships with governments, international organisations, industry, academia, and civil society in strengthening national cyber resilience.
Questions of accessibility were also raised. Colombia and Mexico called for simultaneous interpretation to support participation by experts from different linguistic communities, while Mauritius stressed the need for clear rules, timelines, and coordination between the two thematic groups.
These proposals suggest that the success of the mechanism will depend not only on reaching agreements at the diplomatic level but also on translating them into practical cooperation that responds to national needs.
Building consensus in a permanent mechanism
The opening plenary showed that establishing a permanent international forum involves more than adopting a mandate. Member states must also develop shared expectations about participation, decision-making, working methods, and the relationship between formal negotiations and technical expertise.
Despite differing interpretations of some procedures, delegations broadly reaffirmed their support for the Global Mechanism and its objective of strengthening international cooperation on ICT security.
The consensus adoption of the agenda provided a foundation for the substantive work ahead. The Chair also pledged to continue consultations with states and maintain sustained dialogue with stakeholders.
The mechanism’s first session, therefore, represents both an institutional achievement and an early test of multilateral cooperation. Its ability to deliver practical results will depend on whether member states can balance inclusivity, state leadership, procedural predictability, and the consensus principle on which the forum was founded.
As the mechanism moves towards its first Dedicated Thematic Group meetings in December, the immediate priority will be to turn its permanent mandate into working arrangements capable of supporting trust, resilience, and responsible state behaviour in cyberspace.
Track all key moments from the First substantive session of the UN Global Mechanism on cybersecurity on our dedicated page.
Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!
