UN Global Mechanism on ICT security identifies ransomware and AI among key global cyber threats
The UN’s new permanent cyber mechanism shifted its focus to substantive discussions, with member states identifying ransomware, AI-enabled threats, critical infrastructure protection, and capacity development as key priorities for future international cooperation.
The UN’s new permanent mechanism on international cybersecurity shifted from organisational discussions to substantive exchanges on the evolving cyber threat landscape, with member states identifying ransomware, attacks on critical infrastructure, and the malicious use of AI among the most pressing challenges requiring international cooperation.
Meeting during the first substantive plenary session of the Global Mechanism on Developments in the Field of ICTs in the Context of International Security, delegates also continued discussions on the organisation of the mechanism’s Dedicated Thematic Groups (DTGs), which are expected to play a central role in translating years of normative work into practical cooperation.
While delegations expressed different views on some procedural aspects of the DTGs, there was broad agreement that the groups should focus on practical, action-oriented work and avoid duplicating discussions already taking place during the annual plenary sessions.
Dedicated Thematic Groups take shape
Several delegations described the DTGs as one of the Global Mechanism’s most important innovations, providing an opportunity for more detailed discussions than are possible during formal plenary meetings.
Brazil, Argentina, Chile, Kiribati and New Zealand encouraged the groups to concentrate on a limited number of priority topics capable of producing practical recommendations. Germany similarly proposed focusing on thematically coherent issues, including ransomware and the protection of critical infrastructure, while ensuring that discussions ultimately feed back into the plenary through concrete recommendations.
A recurring message throughout the discussion was that the mechanism should now move from establishing common principles towards supporting their implementation. Several delegations cautioned that attempting to address too many issues simultaneously could reduce the effectiveness of the DTGs, advocating a focused approach instead during their first biennium.
Delegations also highlighted the importance of maintaining predictable working methods, ensuring meaningful participation by all regions, and enabling smaller countries to contribute effectively throughout the process.
Broad support for stakeholder expertise
Another recurring theme was the value of involving technical expertise in DTG work.
Countries from different regions highlighted the contributions that academia, the private sector, civil society, and technical organisations can make to understanding rapidly evolving cyber threats and supporting the implementation of agreed commitments.
Oman stressed that governments alone cannot access all relevant technical knowledge, while Argentina called for transparent and predictable arrangements for stakeholder participation. France argued that cybersecurity requires cooperation across different communities, describing cyber diplomacy as a ‘team sport’. The African Group likewise recognised that expertise from non-state actors complements the intergovernmental character of the mechanism.
Many delegations also underlined that meaningful stakeholder engagement would be particularly valuable during the more interactive discussions planned within the thematic groups.
Ransomware and critical infrastructure emerge as shared priorities
As discussions moved to the evolving cyber threat landscape, a strong degree of convergence emerged across regions.
Ransomware was consistently identified as one of the most significant threats facing governments, businesses, and societies. Delegations pointed to attacks affecting healthcare, public administration, financial services, energy systems, telecommunications, and other essential services.
Several countries drew on national experience to illustrate the impact of such incidents. Costa Rica referred to the disruption caused by major ransomware attacks in 2022, while Ireland highlighted the effects of the 2021 cyberattack on its health service. Singapore noted that nearly 8,000 ransomware incidents were publicly reported worldwide during 2025, underlining the increasingly transnational nature of the threat.
The protection of critical infrastructure also emerged as a common concern. Delegations discussed the resilience of healthcare systems, government services, energy networks, transport infrastructure, telecommunications, and undersea cables, with several suggesting these issues should become early priorities for the DTGs.
AI reshapes the cyber threat landscape
The malicious use of AI featured prominently throughout the session, with delegations from all regions describing its growing impact on cybersecurity.
Countries warned that AI is accelerating the speed and sophistication of cyber operations while lowering barriers to entry for malicious actors. Among the concerns raised were AI-enabled phishing campaigns, automated vulnerability discovery, deepfakes, synthetic media, disinformation, and attacks targeting AI systems themselves.
Several delegations also pointed to emerging challenges, including quantum computing, post-quantum cryptography, commercial spyware, and increasingly sophisticated cybercrime ecosystems. While views differed on whether these developments require new international norms, there was broad recognition that the mechanism should continue examining their implications within its existing mandate.
Capacity building remains central for developing countries
Capacity building remained a cross-cutting priority throughout the session, particularly for developing countries and small island developing states.
The African Group called for practical implementation of existing capacity-building initiatives, including the ICT security cooperation portal, fellowship programmes, and the global network of national points of contact. Other delegations highlighted regional initiatives aimed to strengthening resilience, improving cyber hygiene, and supporting national institutions.
Small island developing states added an important practical perspective to the discussion. Vanuatu described how cyber resilience has become closely linked to disaster preparedness, while Nauru observed that countries connecting to the internet today immediately face the full spectrum of contemporary cyber threats rather than encountering them gradually over time.
The session concluded with the Chair confirming that consultations on the DTGs would continue ahead of their first meetings in December. While some organisational questions remain under discussion, the exchanges demonstrated growing convergence on the substantive issues likely to shape the mechanism’s future work, particularly ransomware, critical infrastructure protection, AI-enabled threats, and strengthening cyber capacity across all regions.
Track all key moments from the First substantive session of the UN Global Mechanism on cybersecurity on our dedicated page.
Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!
