UN Global Mechanism on ICT security begins translating cyber norms into practice

The UN’s permanent cyber mechanism shifted its focus from identifying cyber threats to implementing existing international commitments, with member states broadly prioritising practical cooperation, capacity development, and the application of agreed cyber norms.

Global Mechanism on ICT security

The UN’s permanent cyber mechanism has begun shifting from identifying cyber threats towards implementing the international commitments already agreed by member states, with delegations broadly calling for practical action under the existing UN framework for responsible state behaviour in cyberspace.

During the fourth meeting of the first substantive session of the Global Mechanism on Developments in the Field of ICTs in the Context of International Security, member states concluded discussions on the evolving cyber threat landscape before turning their attention to the implementation of the 11 voluntary and non-binding norms first agreed by the UN Group of Governmental Experts in 2015.

While views differed on whether additional norms may eventually be required, a broad range of delegations agreed that the immediate priority should be helping countries apply the existing framework through practical cooperation, capacity development, and exchanges of national experience.

From agreement to implementation

The discussion reflected a broader evolution in international cyber diplomacy.

Rather than negotiating new principles, many delegations argued that the Global Mechanism should now concentrate on translating existing commitments into national legislation, operational practices, and international cooperation.

The Pacific Islands Forum, speaking through Tonga, noted that many countries, particularly small island developing states, are still developing the institutional and technical capacity needed to implement the agreed norms. It called for the mechanism to support this work through practical guidance, peer learning, and contributions from technical experts, regional organisations, academia, civil society, and the private sector.

The European Union similarly presented an overview of how its member states are implementing the norms through legislation, institutional arrangements, and operational cooperation, encouraging other countries to share their own experiences. The EU also described the Dedicated Thematic Groups (DTGs) as the appropriate forum for developing practical approaches linked to specific cybersecurity challenges.

Existing norms remain the foundation

Many delegations stressed that the 11 voluntary norms continue to provide a sufficient framework for responsible state behaviour.

Countries, including the Republic of Korea, Vanuatu, Portugal, Botswana, Nigeria, Ireland, New Zealand, and Costa Rica, argued that implementation should take precedence over negotiating additional commitments.

Several delegations highlighted the voluntary implementation checklist developed through previous UN processes as a practical tool for helping governments assess progress and exchange good practices. Others suggested that publishing national implementation experiences could improve transparency and strengthen mutual confidence.

Capacity development emerged as a recurring theme throughout the discussion, with many speakers emphasising that successful implementation depends on strengthening national institutions, technical expertise, incident response capabilities, and regional cooperation.

Some states support further normative development

Although implementation attracted broad support, several delegations argued that the framework should continue evolving alongside technological change.

China, Morocco, Armenia, Thailand, Brazil, Iran, and Cuba suggested that emerging issues, including AI, data security, supply chain resilience, and new forms of cyber activity, may eventually require additional voluntary norms or, in some cases, legally binding international instruments.

Rather than presenting these approaches as mutually exclusive, several countries argued that implementation and discussions on possible future norms could proceed in parallel, provided decisions continue to be reached through consensus.

Threat discussions reinforce implementation priorities

Before moving to the norms agenda, delegations completed their discussion on the evolving cyber threat landscape.

Countries highlighted ransomware, attacks on critical infrastructure, AI, disinformation, supply chain vulnerabilities, and cybercrime as continuing challenges requiring closer international cooperation.

Ghana described efforts to strengthen the protection of critical information infrastructure following the disruption caused by damage to a submarine cable, while Pakistan warned that cyber threats are increasingly intertwined with geopolitical competition and emerging technologies. Institutional participants, including the International Committee of the Red Cross, Interpol, and the African Union, contributed perspectives on cyber operations during armed conflict, organised cybercrime, and the importance of strengthening cyber resilience across developing countries.

Summarising the discussion, the Chair highlighted recurring calls for greater information sharing, cooperation, capacity development, incident response, and resilience, noting that these priorities would help shape the future work of the mechanism.

Dedicated Thematic Groups move to the centre of the process

Throughout the session, delegations repeatedly pointed to the Dedicated Thematic Groups as the mechanism’s primary vehicle for turning broad political agreement into practical cooperation.

States proposed using the groups to exchange implementation experiences, discuss specific cyber challenges, develop scenario-based exercises, refine the voluntary implementation checklist, and strengthen cooperation across the five pillars of the UN cyber framework.

Alongside these substantive discussions, several rights of reply reflected wider geopolitical tensions among some member states. However, the majority of interventions remained focused on practical implementation and strengthening the shared framework for responsible state behaviour in cyberspace.

The session, therefore, marked an important transition for the Global Mechanism. Having identified many of the principal cyber threats facing states, delegations increasingly turned their attention to the practical question of how existing international commitments can be translated into national action and international cooperation.

Track all key moments from the First substantive session of the UN Global Mechanism on cybersecurity on our dedicated page.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!