The UK government plans to introduce default overnight social media restrictions for 16- and 17-year-olds, alongside measures to limit features designed to encourage prolonged platform use.
Social media platforms will be expected to activate overnight restrictions from midnight to 6 a.m. by default for users in this age group. Teenagers will be able to change the settings, but the protections will be enabled automatically.
Autoplay and continuously personalised content feeds will also be disabled by default. The government said these features can encourage prolonged use and reinforce potentially addictive patterns of engagement.
The measures are intended to avoid a sudden reduction in online protections when children turn 16. They complement the government’s previously announced plans to prohibit social media services from being offered to children under 16 from spring 2027.
The proposals follow a government pilot involving more than 300 teenagers and parents across the UK. Participating families said the overnight restrictions became part of their routines and helped improve sleep and concentration.
Technology Secretary Liz Kendall said older teenagers should retain greater independence while continuing to receive protection from features that could negatively affect their wellbeing.
The government also plans additional protections for children using AI chatbots. Proposed measures include encouraging regular breaks for users under 18 and taking action against services that provide dangerous, misleading or unverified mental health advice.
Ministers will work with regulators and other government departments to consider further restrictions, including possible bans on chatbots considered to pose a serious risk to children. Guidance for children, parents and guardians will also be added to the Kids Online Safety Hub.
Schools will strengthen media literacy through Relationships, Sex and Health Education classes covering AI, chatbots, misinformation and harmful online content. From September 2028, media literacy will also be embedded across the National Curriculum, including lessons on AI, data science, source analysis and technological bias.
The first regulations supporting the under-16 social media restrictions are expected to be presented to Parliament by the end of 2026, with implementation and enforcement planned for spring 2027.
Why does it matter?
The proposals reflect a growing shift from focusing solely on access to social media towards regulating how digital services are designed and used. By targeting autoplay, personalised feeds and AI chatbots alongside age-based protections, the government is seeking to address features that may contribute to excessive use and online harms.
If adopted, the measures could further shape debates on youth online safety beyond the UK, reinforcing the trend towards safety-by-design, stronger protections for minors and greater platform responsibility for children’s digital wellbeing.
Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!
Australia’s eSafety Commissioner has published its third transparency report assessing how major technology companies are tackling child sexual exploitation and abuse under the country’s Basic Online Safety Expectations.
The report concludes that significant gaps remain across major platforms, particularly in responding to the growing threat of sexual extortion targeting children and young adults.
The report examines the practices of Apple, Discord, Google, Meta, Microsoft, Snap and WhatsApp, highlighting shortcomings in proactive detection technologies, reporting tools and safety measures. According to eSafety, many platforms in Australia are not fully using available technologies, including language analysis tools capable of identifying coercive scripts used by offenders.
The report also identifies weaknesses in reporting mechanisms across several messaging services and notes that private messaging and video environments remain particularly challenging for detecting sexual extortion and livestreamed child sexual abuse.
Between July and December 2025, eSafety received more than 2,000 complaints relating to sexual extortion, with men aged 18 to 24 accounting for the largest group of victims. Separate research with the Australian Institute of Criminology found that more than one in ten adolescents aged 16 to 18 had experienced sexual extortion, while more than half of victims were first targeted before the age of 16.
The report also notes that Microsoft is currently the only provider using dedicated tools to detect and disrupt livestreamed child sexual abuse during video calls.
While eSafety acknowledged incremental improvements—including Google’s and Snap’s enhanced detection of known child sexual abuse material, Meta’s expanded grooming detection and Discord’s blocking of known child sexual abuse URLs—it argued that much stronger action is still needed.
The Commissioner called for wider deployment of proactive detection technologies, faster responses to victim reports and greater investment in tools capable of preventing abuse before it occurs.
Why does it matter?
The report highlights growing regulatory expectations that online platforms should actively prevent child sexual exploitation rather than rely primarily on user reports. As threats such as sexual extortion become more sophisticated, regulators are increasingly scrutinising whether companies are deploying available technologies to detect and disrupt abuse.
The findings also reinforce a broader shift towards safety-by-design in online regulation. By identifying gaps in detection, reporting and intervention, the report could increase pressure on technology companies to strengthen protections across messaging, social media and video services.
Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!
The ninth meeting of the Global Mechanism on ICTs and International Security focused on capacity building as a central pillar of the UN framework for responsible state behaviour in cyberspace . Delegations broadly agreed that capacity building is indispensable for mitigating cyber threats and enabling all states, particularly developing countries, to implement the agreed framework effectively .
Multiple states emphasised that effective capacity building must be demand-driven, nationally owned, sustainable, and free from political conditionalities . Thailand highlighted the importance of addressing advanced threats including AI security and post-quantum cryptography , while the Philippines stressed that capacity building should span the full spectrum of cybersecurity, from incident response to cyber diplomacy . Zimbabwe and Indonesia both underscored the need to develop national cybersecurity strategies, legal frameworks, and computer emergency response teams . Several delegations, including Suriname and Tuvalu, drew attention to the particular challenges faced by small and developing states, including limited resources and geographic isolation .
Saudi Arabia outlined numerous international initiatives, including the Global Cybersecurity Forum, a UNITAR office dedicated to cybersecurity in Riyadh, and a programme that has trained women from over 67 countries in cybersecurity leadership . The Netherlands and Australia both highlighted the Women in Cyber Fellowship as a valuable programme expanding women’s participation in UN cyber processes . Notably, women delivered approximately 50% of all statements during the session .
Interpol and the OSCE described practical capacity-building activities, including joint law enforcement operations and regional workshops on international cyber diplomacy and critical infrastructure protection . Kuwait proposed the development of a voluntary scenario-based capacity-building module on international law within the global portal, complementing India’s pledge to support the portal’s technical establishment .
Chair Egriselda López concluded the session by noting the broad convergence on capacity building as a universal need and outlined next steps, including circulating a preliminary proposal for the Dedicated Thematic Groups by the end of August and convening DTG meetings in December 2025 . She called on all delegations to approach the intersessional period with flexibility and a commitment to producing concrete, action-oriented results .
Keypoints
Overall Purpose
The discussion took place during the ninth meeting of the first substantive plenary session of the 2026 Global Mechanism on Progress in ICTs and International Security. The primary goal was for member states and accredited entities to deliver statements on the agenda item of developing and implementing capacity building in cybersecurity, with a view to informing the work of the forthcoming Dedicated Thematic Groups (DTGs), particularly DTG-2 on capacity building, scheduled for December 2026.
—
Major Discussion Points
Capacity building as a foundational and cross-cutting pillar of the UN framework: Multiple delegations emphasised that capacity building is not merely one pillar among others but the essential enabler underpinning all aspects of the agreed framework for responsible state behaviour in ICTs. The Philippines described it as “the foundation that enables all states to participate meaningfully” , Indonesia stated that “without adequate capacity, implementations of all pillars of the global mechanisms would be difficult to achieve” , and the Dominican Republic called it “the cost-cutting and enabling factor without which the other norms and commitments under the framework for responsible state behaviour will just remain words on a page” . The Chair echoed this consensus in her closing remarks .
Principles guiding effective capacity building – demand-driven, nationally owned, and sustainable: There was broad convergence across delegations that capacity building must adhere to specific principles to be effective. Zimbabwe , Indonesia , Tuvalu , and the Philippines all stressed that programmes must be demand-driven, nationally owned, needs-based, sustainable, and free from political conditionalities. The Dominican Republic further recommended that any voluntary fund include measurable metrics , and Suriname highlighted the particular challenges faced by resource-constrained nations .
Gender inclusion and women’s participation in cybersecurity: Several delegations and the Chair highlighted the importance of gender-responsive capacity building. Thailand referenced the Women in International Security and Cyberspace Fellowship and the Women Thailand Cyber Top Talent Competition . Saudi Arabia noted a specialised programme for women in cybersecurity with graduates from over 67 countries . The Netherlands expressed pride in its support for the Women in Cyber Fellowship . Australia noted that women delivered just over 50% of statements during the plenary session , and the Chair celebrated this milestone as a defining feature of the mechanism’s first session .
The role of regional organisations, international partners, and multi-stakeholder actors: Delegations consistently recognised that no state can build cyber resilience alone and that regional bodies, international organisations, the private sector, civil society, and the technical community are indispensable partners. Thailand highlighted the ASEAN-Japan Cybersecurity Capacity Building Centre , Zimbabwe and the African Union Commission pointed to the Malabo Convention and the Common African Position , INTERPOL described its operational capacity-building model embedding training within real-world operations , and the OSCE outlined its decade-long programme of workshops on cyber confidence-building measures . The Kenya ICT Action Network and FIRST both called for non-state actors to be systematically integrated as co-designers of capacity-building programmes .
Establishment and operationalisation of the Global ICT Security Cooperation and Capacity Building Portal: Several delegations, notably Kuwait, welcomed the proposed Global Portal as a practical, neutral, one-stop-shop platform for sharing best practices, mapping capacity-building activities, and supporting implementation of voluntary norms . Kuwait proposed a voluntary scenario-based capacity-building module on international law to be integrated into the portal . The Secretariat confirmed that India had pledged financial support for the portal’s technical establishment and maintenance, and that a proposal document had been made available . The Chair noted the portal’s importance as a concrete deliverable from the OEWG final report .
—
Overall Tone
The overall tone of the discussion was constructive, cooperative, and optimistic, with a strong sense of shared purpose. Delegations from all regions expressed genuine commitment to the mechanism and to advancing capacity building as a collective endeavour. Developing countries spoke candidly about their constraints and needs, while donor states and international organisations outlined concrete contributions, creating a tone of mutual accountability rather than confrontation.
The one notable shift in tone occurred near the end of the session, when the Russian Federation exercised its right of reply to condemn what it described as “outrageous anti-Russian attacks” from Italy’s delegation the previous day , and Ukraine responded by reaffirming its right to self-defence under Article 51 of the UN Charter . This brief exchange introduced a moment of geopolitical tension into an otherwise collaborative session. However, the Chair’s closing remarks swiftly restored the prevailing spirit of multilateralism and consensus, concluding with an optimistic call for flexibility and continued dialogue as the mechanism moves towards its December DTG sessions .
Speakers Overview
P
Philippines
116 wpm · 4 min
I
Indonesia
124 wpm · 3 min
AU
African Union Commission
128 wpm · 3 min
K
Kuwait
136 wpm · 6 min
T
Thailand
98 wpm · 5 min
S
Suriname
126 wpm · 3 min
F
FIRST
115 wpm · 2 min
N
Netherlands
169 wpm · 3 min
Y
Yemen
96 wpm · 4 min
I
Interpol
127 wpm · 4 min
A
Australia
144 wpm · 2 min
DR
Dominican Republic
124 wpm · 5 min
P
Paraguay
172 wpm · 3 min
O
OSCE
128 wpm · 4 min
Z
Zimbabwe
129 wpm · 4 min
T
Tuvalu
119 wpm · 3 min
SA
Saudi Arabia
130 wpm · 5 min
S
Secretary
135 wpm · 2 min
CE
Chair Egriselda López
118 wpm · 27 min
FE
Future Earth Systems
118 wpm · 3 min
KI
Kenya ICT Action Network
111 wpm · 2 min
RF
Russian Federation
148 wpm · 2 min
U
Ukraine
151 wpm · 32 s
Ninth Meeting of the First Substantive Plenary Session: Developing and Implementing Capacity Building
#
Opening and Procedural Matters
Chair Egriselda López opened the ninth and final meeting of the first substantive plenary session of the 2026 Global Mechanism on Progress in the Area of ICTs and International Security, calling the session to order and directing delegates to the last agenda item: developing and implementing capacity building . Noting that the day marked the conclusion of the programme of work, she reminded delegations that whilst no preset time limit applied to interventions, she encouraged abridged statements to allow all speakers to be heard, with full versions to be submitted to the Secretariat . Thirteen requests for the floor had been received, and the Chair announced the first five speakers as Thailand, Saudi Arabia, the Philippines, Zimbabwe, and the Kingdom of the Netherlands .
—
#
Capacity Building as a Foundational and Cross-Cutting Pillar
A defining theme of the session was the near-universal agreement that capacity building is not merely one pillar among equals within the UN framework for responsible state behaviour in ICTs, but rather the foundational enabler underpinning all other pillars [S52][S69]. Thailand opened by affirming that “capacity building is indispensable in mitigating malicious cyber activities and strengthening cyber resilience” and should “remain a central pillar of our collective efforts, enabling all states, particularly developing countries, to address the challenges and opportunities presented by emerging technologies” . The Philippines articulated this most precisely, stating that capacity building “is not a stand-alone pillar, but an enabler of all five pillars, strengthening the ability of states to implement international law, operationalise the voluntary norms, develop confidence-building measures, and participate effectively in regular institutional dialogue” . Indonesia reinforced this framing, asserting that “without adequate capacity, implementations of all pillars of the global mechanisms would be difficult to achieve” . The Dominican Republic went further, describing capacity building as “the cross-cutting and enabling factor without which the other norms and commitments under the framework for responsible state behaviour will just remain words on a page” . The Kenya ICT Action Network, speaking on behalf of civil society and technical stakeholders, similarly described it as “a fundamental bridge that converts abstract norms on paper into operational resilience on the ground” . The Chair’s concluding remarks confirmed this consensus, noting that “the vast majority of member states see capacity building as a fundamental pillar for exercising the other pillars” [S52][S79].
—
#
Core Principles Governing Effective Capacity Building
Alongside this conceptual consensus, delegations converged strongly on the principles that should govern how capacity building is designed and delivered [S88]. There was broad agreement that programmes must be demand-driven, nationally owned, needs-based, sustainable, and free from political conditionalities. The Philippines called for capacity building that is “demand-driven, nationally owned, sustainable, and responsive to nationally identified priorities,” emphasising that it should “empower states to develop enduring institutional, legal, technical, operational, and policy capabilities rather than provide one-time assistance” . Thailand similarly stressed that “such efforts must be need-based, tailored to national priorities and responsive to national capacities” . Zimbabwe, aligning itself with the ICC statement before making its national remarks, articulated the most comprehensive formulation, stating that capacity building “should be nationally owned, demand-driven, needs-based, sustainable, transparent, and free from conditionalities” and must “empower states to build lasting resilience rather than create technological dependence” . Indonesia explicitly added that it must be “free from political conditionalities to bridge digital divides” , a formulation echoed by Tuvalu, which called for “country-owned and needs-driven” approaches supported by “state-led assessments” to ensure support is “tailored and practical” . FIRST, the global forum of incident response and security teams, reinforced this from a practitioner perspective, noting that capacity building “must be locally driven, responsive to national priorities and sustained over a longer period of time” rather than delivered through “short-term interventions” . Interpol similarly confirmed that “sustainable operational capabilities” result when capacity building is “nationally owned, driven by identified needs, and crucially tailored to the distinct responsibility of relevant national actors” . The Chair’s closing summary reflected this consensus, noting that capacity building “must be sustained, coordinated, and contextualised in the needs and realities of states without applying a one-size-fits-all approach” [S122][S123].
—
#
National and Regional Capacity Building Initiatives
A substantial portion of the session was devoted to delegations describing concrete capacity building initiatives already underway at national, bilateral, and regional levels, demonstrating that practical cooperation is delivering results even as the global mechanism is being established [S129].
Saudi Arabia outlined an extensive portfolio of international initiatives, framing them as stemming from “its belief in the importance of dialogue, the exchange of expertise, and capacity building at the global level” . These included the Global Cybersecurity Forum (GCF), established as “a global platform bringing together stakeholders from various sectors, including the private sector, academia, and the technical community” ; the Global Initiative for Child Protection in Cyberspace and the Global Initiative for Women’s Empowerment in Cybersecurity, launched by Crown Prince Mohammed bin Salman ; the Global Initiative for International Capacity Building in Cyberspace in partnership with the United Nations ; and, in partnership with UNITAR, a dedicated cybersecurity office headquartered in Riyadh to launch capacity building initiatives and joint research programmes . Saudi Arabia also reported that its specialised programme to train women in cybersecurity for leadership positions had seen “representatives from more than 67 countries” graduate , and that it had partnered with the World Economic Forum to establish the Centre for Cybersecurity Economics in Riyadh . Notably, Saudi Arabia, in partnership with UNODA, launched during this session a capacity-building programme specifically for representatives participating in the global mechanism, aimed at supporting the effective participation of states in the mechanism’s work .
Thailand highlighted the ASEAN-Japan Cybersecurity Capacity Building Centre as “a key platform for strengthening regional cyber capacity,” noting its collaboration with partners including the United States, the United Kingdom, Canada, Switzerland, and the Netherlands, as well as civil society organisations . Thailand also described working with UNIDIR, Canada, the European Union, and the ICT for Peace Foundation to improve capacity building at national and regional levels . Thailand proposed that DTG-2 on capacity building prioritise discussions on advanced cyber threats including “AI and security, quantum readiness, post-quantum cryptography, and operational technology security,” as well as assistance with national legal and policy frameworks, though Thailand’s statement was cut off before this second point could be fully articulated .
The Philippines described its ongoing efforts to strengthen its cybersecurity ecosystem through “investments in institutional development, workforce capacity, the protection of critical information infrastructure, and international cooperation,” recognising in particular the contributions of UNIDIR, whose “workshops and technical engagements have strengthened national expertise” . The Philippines also highlighted the ITU Academy’s HERS CyberTrack programme, through which three Filipino women cybersecurity policy professionals were participating in the cyber policy and diplomacy track .
The Dominican Republic, as host of the Cyber Capacity Centre for Latin America and the Caribbean (LAC4) in Santo Domingo, described providing “technical diplomatic assistance directly to states without the intermediary of additional global bodies” . It reported training “more than 900 police officers, judges and prosecutors” through EU programmes – referred to in the transcript as GLACY-e and GLACY+ – with some graduates becoming instructors themselves . The Dominican Republic also described embedding cyber diplomacy in permanent specialist master’s training programmes so that “all diplomats will have the basic tools that will allow them to become significantly involved into these increasingly cross-cutting disseminations” . Paraguay similarly highlighted its new National Security Strategy developed in collaboration with the OAS and the C-CERT Americas network for cyber incident response and prevention . Paraguay also specifically acknowledged the Women in Cyber Programme (supported by Canada, the OAS, and the Global Forum on Cyber Expertise), the UNIDIR training course on international law and cyberspace, the United Nations Singapore Fellowship Programme, and the ODA Programme as valuable contributions to its capacity building efforts.
Indonesia pointed to ASEAN’s Cybersecurity Cooperation Strategy for 2026-2030 as demonstrating “how tailored long-term programs can strengthen national and regional resilience” . Indonesia also emphasised that capacity building “should include training for policymakers and technical experts, academia, legal experts, and other relevant stakeholders to ensure a holistic and comprehensive approach,” and proposed that DTG-2 focus on “critical information infrastructure protections, cyber crisis management, and strengthening the capacity of CERT and C-CERT” . The Netherlands, aligning itself with the EU statement before making its national remarks, described its long-standing commitment to cyber capacity building worldwide, including supporting “development and implementation of national cybersecurity strategies, incident response capabilities and policies for vulnerability disclosure” and strengthening CERTs and national agencies globally .
Zimbabwe welcomed the establishment of DTG-2 pursuant to General Assembly Resolution 79-237, noting that “its creation reflects the shared recognition that capacity building is essential to narrowing the digital divide, strengthening national resilience, and ensuring that all states, regardless of their size or technical capacity, can implement the agreed framework effectively” . Zimbabwe also welcomed the voluntary fund and fellowship programmes established under Resolution 79-237, noting that “these initiatives will help broaden participation and make expertise more accessible.” It further referenced the Malabo Convention and the Common African Position on the Application of International Law in Cyberspace as important regional frameworks underpinning Africa’s approach to cyber capacity building, and called for “greater coordination among existing capacity-building initiatives to maximize their impact, avoid duplication, and better respond to national needs” , highlighting the Global Points of Contact Directory as “one of the most practical achievements of the open-ended working group” .
—
#
Challenges Facing Developing and Geographically Disadvantaged States
Several delegations drew attention to the structural barriers that make capacity building particularly challenging for developing countries, small island developing states, landlocked nations, and post-conflict countries [S79].
Suriname, speaking for the first time and aligning itself with the CARICOM statement delivered by the Bahamas, described capacity building as “an investment in national resilience, institutional development, economic stability, and public trust” rather than “simply a technical exercise” . It noted that “limited financial and human resources often require difficult choices, yet the cost of insufficient investment is far greater, exposing countries to disruption of essential services, economic losses, and weakened public confidence” . Suriname also highlighted the growing importance of cybersecurity as its emergent offshore oil and gas sector creates new opportunities for economic growth while simultaneously expanding the need to protect critical infrastructure .
Tuvalu, aligning with the Pacific Island Forum, emphasised that capacity building “is the fundamental foundation for small island developing states such as my own country, Tuvalu, to effectively implement cyber norms, strengthen our national preparedness, and engage meaningfully in UN cyber processes” . It highlighted “significant constraints including limited resources, geographic isolation, and high connectivity costs” and called for international support that is “predictable, sustainable, and delivered through diverse channels, including remote and hybrid training, the use of micro-modules, and sustained mentorship programs” .
Paraguay introduced a structural dimension often absent from such discussions, noting that “asymmetries generate insecurity” and that “sustainable growth in cybersecurity will not be possible without the sustainable growth of a digital economy,” particularly for landlocked countries without direct access to the maritime backbones of the internet, through which 95% of web information still passes .
Yemen, speaking for the first time, described the situation of post-conflict and least developed countries most starkly, stating that “a weakness in one link means the entire chain falls apart” and calling for “practical support” to “bolster their infrastructure of control and surveillance” and establish national cybersecurity centres . Yemen noted that it has enacted a law against cybercrime and on the protection of data, and has established a national cybersecurity centre. It also described 12-month long-term training programmes designed to build the capacity of staff in cybersecurity and legal evidence, strengthening national capacity to counter transnational cybercrime. Yemen called for “swift action in terms of the two DTGs in December 2026” .
FIRST added a systemic critique, noting that “funding is often limited to short-term project cycles, while reporting requirements are increasingly complex and fragmented across donors,” and that “these constraints undermine the long-term investments that meaningfully advance capacity-building requirements” .
—
#
Gender Inclusion and Women’s Participation
Gender-responsive capacity building and women’s participation in cybersecurity emerged as a particularly strong area of consensus, with multiple delegations and the Chair celebrating concrete progress [S81][S85][S90].
Thailand recognised the importance of gender-responsive programmes, highlighting the Women in International Security and Cyberspace Fellowship and the Women Thailand Cyber Top Talent Competition, which aims to “enhance women’s practical cybersecurity skills, reach the gender gap, and cultivate a new generation of highly skilled cybersecurity professionals” . The Netherlands expressed “special appreciation of the Women in Cyber Fellowship, coordinated by UNIDIR, to which the Kingdom of the Netherlands is a proud donor,” noting that it “has strengthened the participation of women in UN cyber processes” and “provided training to excellent results” . The Netherlands encouraged all delegations “in a position to do so to contribute to the work of the Fellowship and broader to ensure that we bridge the gender divide” . Tuvalu acknowledged the fellowship as “invaluable” in enhancing its participation in UN cyber discussions . The African Union Commission emphasised that capacity building must promote “gender equality and while giving young Africans the knowledge and skills that they need to become innovative actors and to work in cybersecurity” .
Australia, together with Canada, Germany, New Zealand, the Netherlands, and the United Kingdom, reaffirmed its support for the Women in Cyber Fellowship and noted a historic milestone: “women delivered just over 50% of the statements during this plenary session,” continuing “the trend of gender parity” seen in the final sessions of the OEWG . The Chair confirmed this figure in her closing remarks, noting that “of the 324 statements made this week, 162 were delivered by women, and that is indeed 50%” , describing this as a defining feature of the mechanism’s first session and affirming that “their leadership and experience constitutes a reminder that building a safer, more secure digital environment requires all of the talent and participation of women” .
Australia’s statement on gender inclusion was delivered under agenda item 8 (other matters), emphasising that “achieving meaningful gender inclusion is also essential to building a more effective, representative and resilient international cyber environment” . It noted that through the Women in Cyber Fellowship, Australia and partner countries are “helping expand opportunities for women from underrepresented and developing states to participate in UN cybersecurity processes, strengthen professional networks and contribute their expertise to national and international policymaking” . Australia encouraged all delegations to “continue efforts to promote the full equal and meaningful participation and leadership of women across all aspects of the global mechanisms” .
—
#
The Role of International Organisations and Non-State Actors
International organisations and accredited non-state entities made substantive contributions that enriched the discussion with operational experience and practical tools [S80][S92].
Interpol described its approach of embedding capacity building throughout the operational cycle, using the football team metaphor to illustrate that “different types of players, goalkeepers, defenders, or strikers, may need different specialized forms of training” . It provided a concrete example in which 13 countries from the Middle East and North Africa received specialised training and participated in tabletop exercises, before Interpol coordinated a joint operation against phishing and malware that resulted in the arrest of “over 200 suspects, who had been linked to 3,867 identified victims” . Interpol also highlighted the growing industrialisation of cybercrime and its work developing practical guidance for the responsible use of AI in law enforcement, including a toolkit and e-learning course . It measured the success of capacity building by what member countries are equipped to do: “conduct more effective investigations, identify and arrest offenders, dismantle malicious infrastructure and criminal networks, trace and recover illicit processes, and support victims” .
The OSCE described nearly a decade of capacity building activities linked to its confidence-building measures, including workshops on critical information infrastructure protection, cross-sector cooperation, and threat information sharing . It highlighted its annual training on international cyber diplomacy, which in November of the previous year gathered 18 participants from Eastern and Southeastern Europe, Central Asia, South Caucasus, and Mongolia . The OSCE also described a regional workshop that brought together 14 policymakers to strengthen national capacities on the applicability of international law to state use of ICTs .
Chris Sampson of Future Earth Systems, speaking from the perspective of the technical community, proposed that enterprise architecture tools such as capability maps and capability maturity models could assist member states in “prioritisation and planning for capacity building in each of your jurisdictions,” identifying which capabilities are needed across government and the broader economy . FIRST called for “stronger partnerships among states, private sectors, civil society, and the technical community with donors and implementers working together effectively in public-private partnerships” , and specifically noted that regions such as the Western Balkans and Africa demonstrate that “greatest impact is achieved when international organizations work closely with local stakeholders.” The Kenya ICT Action Network argued that capacity building “must not be a top-down, copy-paste exercise” and that programmes “will need to be co-designed, co-created with local institutions to address specific regional threat landscapes, local language realities, and human rights impacts” – including protecting civil society and vulnerable populations from technology-facilitated abuse . It called for the global mechanism to “systematically integrate non-state actors as co-designers, co-creators, trainers, and evaluators of capacity-building programs to ensure accountability and measurable impact” .
The African Union Commission welcomed the establishment of DTG-2 and described capacity building as “a strategic investment in digital development” and “an essential lever for consolidating international peace and security in cyberspace” . It committed to supporting member states in implementing the Common African Position on the Application of International Law in Cyberspace and the UN Framework on Responsible Behaviour of States , framing these efforts within the aspirations of Agenda 2063 as the continental development framework guiding Africa’s digital transformation.
—
#
The Global ICT Security Portal and Kuwait’s Proposal
The establishment and operationalisation of the Global ICT Security Cooperation and Capacity Building Portal attracted significant attention as a concrete deliverable from the OEWG final report [S131][S132].
Kuwait delivered one of the most detailed and operationally specific contributions of the session, grounding its proposals in specific provisions of the OEWG final report – including paragraphs 8, 9, 39, 43D2, 53, 53G, and 56 – demonstrating a detailed engagement with the agreed text. Kuwait explicitly welcomed India’s important commitment to supporting the establishment and operationalisation of the global portal as a confidence-building gesture, and expressed readiness to work with India to explore how its previously developed digital tool on voluntary non-binding norms could be “technically aligned with the portal architecture” . Kuwait proposed developing “a voluntary scenario-based capacity building module on international law and the use of ICT within the global portal” . Kuwait envisioned the portal as a “modular one-stop-shop approach,” with one component supporting practical implementation of voluntary non-binding norms and another facilitating capacity building and “deeper common understanding concerning the application of international law” . The proposed scenario bank would contain “neutral and hypothetical scenarios relating to the use of ICTs in the context of international security,” submitted voluntarily by member states, experts, and relevant UN entities . Member states could voluntarily provide their views on applicable rules and principles of international law, with the tool explicitly designed not to “determine whether interpretation is correct, rank national positions, or replace intergovernmental negotiations” . Kuwait argued this approach would “maximize existing resources, avoid unnecessary duplication, and help transform the global portal into an interactive capacity-building environment supporting continuous learning and more focused intergovernmental discussion” .
The Secretariat provided a brief update confirming that India had pledged financial support for the technical establishment and maintenance of the portal, enabling its development “in the current budgetary and liquidity constraints of the United Nations Secretariat” . The Secretariat noted that an initial proposal document was available as A-AC.292-2025-1 and committed to providing a more substantive update at future sessions . The Dominican Republic complemented this discussion by recommending that the portal serve primarily to “map activities to avoid fragmentation of international efforts” and function as a coordination tool rather than a new implementing body, and that any voluntary fund include “metrics so that we can measure results” [S133][S134].
—
#
The Role of DTG-2 and the Dedicated Thematic Groups
Multiple delegations addressed the role of the Dedicated Thematic Group on Capacity Building (DTG-2) as a pivotal mechanism for translating the session’s normative consensus into concrete, action-oriented outcomes [S63].
The Netherlands argued that the global mechanism “should not be a one- or two-way street, but rather should act as a place where ideas, needs, experiences, innovations and resources all come together,” and that “the role of DTG2 in this sense will be pivotal for the global mechanism’s success” . It called for DTG-2 to “function as a space for genuine collaboration to ensure that capacity building is implemented in an effective, pragmatic and responsive manner” . Indonesia envisioned the global mechanism, including through the DTGs, as “a hub for coordinating capacity-building efforts, matching needs with resources, and ensuring that assistance is accessible to all member states” . Zimbabwe welcomed the establishment of DTG-2 pursuant to General Assembly Resolution 79-237, noting that “its creation reflects the shared recognition that capacity building is essential to narrowing the digital divide, strengthening national resilience, and ensuring that all states, regardless of their size or technical capacity, can implement the agreed framework effectively” . Yemen called for “swift action in terms of the two DTGs in December 2026” .
—
#
Rights of Reply: Russia and Ukraine
Near the close of the session, the Russian Federation exercised its right of reply to condemn what it described as “outrageous anti-Russian attacks” from the Italian delegation the previous day, alleging that Ukraine’s attacks on Russian civilian infrastructure had not been mentioned and that “some delegations have appeared here not to engage in professional dialogue, but to settle political scores and to reproduce propaganda clichés” . Russia argued that “such an approach undermines the work of the global mechanism” . Ukraine responded by reaffirming that it “remains under Russia’s aggression and is conducting the defense under the Article 51 of the UN Charter,” and that “public attribution and restrictive measures are applied for a reason,” namely “to manifest a joint protest against malicious behavior that undermines security in the use of the ICTs and on the global scale” . This brief but sharp exchange introduced a moment of geopolitical tension into an otherwise cooperative session, underscoring the broader political context in which the mechanism operates.
—
#
Chair’s Concluding Remarks and Next Steps
Chair Egriselda López delivered extensive concluding remarks that synthesised the week’s deliberations and set out a clear plan for the intersessional period. She began by thanking all delegations for their substantive statements and participation, recognising the effort of those who had travelled from far to attend and the support of states that had enabled the participation of delegations from developing countries . She noted that the session had produced “broad, diverse and representative participation,” strengthening “the truly global character of this mechanism” . The Chair also expressed deep gratitude to the co-facilitators of both DTGs, noting that they “have already begun their work and have shown from the outset a firm commitment to the success of this mechanism,” recognising their willingness, hard work, and leadership.
The Chair reflected on the quality and precision of the statements made during the week, noting that delegations had come with “national statements, regional statements, statements on behalf of groups of countries and also working documents and concrete proposals that will be immensely useful in the next phase of our work” . She celebrated the 50% gender parity in statements as a defining feature of the session, describing it as a milestone that “proudly bears the hallmark of these women” . The Chair also specifically thanked Julie and Ligia from her team, as well as the young intern whose “great enthusiasm and a readiness to learn” had contributed to the work of the Chair during this historic first session.
On the substance of the capacity building discussion, the Chair confirmed the broad convergence on capacity building as “a shared and universal need” , noting that delegations had described a wide range of capacity building activities including “tabletop exercises, workshops, specialised trainings, exchanges of good practices in the area of information security, and also assistance in developing policies and regulatory frameworks” . She welcomed bilateral, regional, and sub-regional activities, including the Women in Cyber programme and the UNODA-Saudi Arabia programme to support developing country participation .
Turning to next steps, the Chair outlined her intention to make “the most effective possible use of the intersessional period, which runs from today until the start of the DTGs scheduled from 7 to 11 December this year” . She committed to working closely with the co-facilitators to structure the DTGs “in an integrated and cross-cutting way with the aim of offering more specialised action-oriented spaces fully aligned with the framework’s five pillars” , building on her non-paper of 29 June as the basis for the DTG organisation proposal. She indicated that a preliminary proposal for the organisation of the DTGs, including an agenda and topics for consideration, would be circulated “toward the end of August” . The Secretariat would also facilitate the creation of a roster of experts foreseen in Resolution A/80/257 to support DTG deliberations , and the Chair would convey guiding questions ahead of each DTG meeting with sufficient advance notice .
The Chair made an explicit and candid appeal for flexibility from all delegations, acknowledging that “the DTGs have no prior template to build on” and that “there is no ready-made formula we can simply copy” . She asked delegations to receive the August proposal “as a serious, balanced, good faith basis on which to begin building without delay,” noting that “consensus cannot in practice become an endless negotiation over every word of an initial proposal” . She also confirmed that El Salvador would present to the First Committee the resolution endorsing the plenary session and DTG deliberations, with the expectation that it would be adopted without a vote .
The Chair concluded by affirming that “together we are writing the first page in the history of the global mechanism” and that “even in an extremely complex international environment, dialogue, cooperation and the quest for consensus are all still possible” . She expressed confidence that, with the same determination and flexibility she had called for, the mechanism could “produce concrete results” commensurate with what member states expect of it .
The first substantive plenary session of the 2026 Global Mechanism on Advancements in the Area of ICTs in the Context of International Security was formally closed .
—
Chair Egriselda López
We’re about to begin. The ninth meeting of the substantive plenary session of the 2026 Global Mechanism on Progress in the Area of ICTs and International Security and Supporting Responsible Behaviour of States in the Use of ICTs is called to order. We are now going to move to the last item on our agenda, Developing and Implementing Capacity. building. As I said yesterday, we will hear the remaining speakers on our list this morning. It is worth repeating what you already know. There is no preset time limit for your interventions but nonetheless, I would be grateful if you would consider delivering an abridged version of your statement and sending the full version to eStatements and the Secretariat and the Chair’s team so that we can hear all delegations wishing to speak. As you also know, today is our last day and so we must finish our programme of work. For reference, a timer will be displayed on the screen. There are now 13 requests for the floor. If you haven’t yet done so and you do wish to take the floor, please indicate this so that we can hear you. You can record your request to speak in the list of speakers. And I’m going to tell you the first five speakers on the list. We will begin with Thailand, followed by Saudi Arabia, then the Philippines, Zimbabwe, and the Kingdom of the Netherlands. Thailand, you have the floor.
—
Thailand
Thank you, Madam Chair. Thailand recognizes that capacity building is indispensable in mitigating malicious cyber activities and strengthening cyber resilience. In line with the OEWG Second Annual Progress Report, we support the operationalization of the capacity building principle to ensure a sustainable, inclusive, and neutral approach to capacity building that respects national security and security of the environment. and national sovereignty. Capacity building should remain a central pillar of our collective efforts, enabling all states, particularly developing countries, to address the challenges and opportunities presented by emerging technologies. While strengthening cyber resilience to be effective, such efforts must be need -based, tailored to national priorities and responsive to national capacities. Thailand supports the capacity -building mechanism outlined in the OEWG final report and looks forward to their effective implementation under the global mechanism, namely the establishment of the Global ICT Security Cooperation and Capacity Building Portal as a practical and neutral platform to facilitate cooperation among states. The high -level global roundtable on ICT security capacity building and other similar initiatives to enhance the participation of developing countries in the global mechanism. At the regional level, Thailand places great importance to the ASEAN -Japan Cybersecurity Capacity Building Center as a key platform for strengthening regional cyber capacity. The center has been also co -working with other partners, including the United States, the United Kingdom, Canada, Switzerland, and the Netherlands, as well as civil society organizations and other stakeholders. Thailand has also been working with various partners, including UNIDER, Canada, the European Union, Plinkendale, Institute, the Simpson Center, and the ICT for Peace Foundation to improve capacity building at both national and regional levels. Thailand recognizes the importance of gender -responsive capacity -building programs which have enabled the more meaningful and inclusive participation of women in relevant meetings and processes. These include, for example, the Women in International Security and Cyberspace Fellowship and the Women Thailand Cyber Top Talent Competition, which aims to enhance women’s practical cybersecurity skills, reach the gender gap, and cultivate a new generation of highly skilled cybersecurity professionals. In addition, Thailand recognizes the importance of strengthening capacity -building across both technical and strategic policy dimensions, with a view to enable diplomats and policymakers to participate meaningfully in international discussions, safeguard national interests, and contribute to reducing risk of misperception and miscalculation among states. As highlighted in our intervention on Monday, Thailand reiterates that capacity building should remain at the heart of our cooperation and deliberations, both independently and within the dedicated thematic groups. In this regard, Thailand proposed that the DTG -2 on capacity building prioritize discussions on the following areas. First, addressing advanced cyber threats including AI and security, quantum readiness, post -quantum cryptography, and operational technology security. Second, providing assistance with national legal and policy frameworks, and the
—
Chair Egriselda López
Thank you very much. I give the floor to Saudi Arabia.
—
Saudi Arabia
Thank you, Madam Chair. The Kingdom of Saudi Arabia places international cooperation and partnership building at the heart of its effort to strengthen cybersecurity. This is stemming from its belief in the importance of dialogue, the exchange of expertise, and capacity building at the global level. Given cyberspaces’ close connection today to the growth of economies, the prosperity of societies, the security of individuals, and the stability of states, and its cross -border nature, hence the importance of unifying and aligning international efforts grows ever more. greater in order to seize opportunities and confront challenges in cyberspace through investment in people. In this context, the Kingdom has launched numerous initiatives aimed at building states’ capacities in cyberspace. These include the Kingdom’s establishment of the Global Cybersecurity Forum, GCF, to serve as a global platform bringing together stakeholders from various sectors, including the private sector, academia, and the technical community, with the aim of promoting international dialogue, developing partnerships, and launching qualitative initiatives that contribute to building a safer and more stable cyberspace. Further, His Royal Highness Prince Mohammed bin Salman bin Abdulaziz Al Saud, Crown Prince and Prime Minister, may God preserve him, also launched the Global Initiative for Child Protection in Cyberspace, and the Global Initiative for Women’s Empowerment in Cybersecurity. The GCF is working to implement the projects arising from these two initiatives. In addition, the Kingdom launched the Global Initiative for International Capacity Building in Cyberspace in partnership with the United Nations and its specialized organs and agencies. As part of implementing this global initiative and to support the work of the open -ended working group on information and communication technologies in the context of international security, the Kingdom, in partnership with the UNODA, launched during this session of the work of the mechanism a capacity -building program for representatives participating in this to support the effective participation of states in this mechanism. The Kingdom is also implementing a specialized program to train women in cybersecurity so they can take up leadership positions. In this field, To date, representatives from more than 67 countries have graduated from this program Further, in partnership with the World Economic Forum the Kingdom launched the Centre for Cybersecurity Economics headquartered in Riyadh which works to provide reliable information and in -depth studies enabling decision makers around the world to build a deep understanding of the close relationship between economies and cybersecurity This also includes providing robust tools for formulating policies and strategies that ensure protection of the global economy It is also worth noting that last June, the Kingdom in partnership with the United Nations Institute for Training and Research, UNITAR launched the A UNITAR office dedicated to cybersecurity headquartered in Riyadh. This office will work to launch a number of initiatives and projects in capacity building and the development of cybersecurity -related policies and implementing joint research and development programs. This would contribute to developing the skills of a wide range of beneficiaries and specialists in the area and strengthening cybersecurity at the international level. Madam Chair. The Kingdom of Saudi Arabia continues to implement initiatives related to capacity building in the field of cybersecurity. This is stemming from its firm belief in upholding the principle of cooperation and consolidating joint international action towards every effort that serves development and prosperity for all countries of the world. We will continue to contribute to the work of the global mechanism and to support the participation of states representatives in its work, thereby contributing to enriching the work of this important forum, which will be reflected in strengthening international peace and security. I thank you.
—
Chair Egriselda López
Muchísimas gracias. Doy ahora la palabra. Thank you. And I now give the floor to the Philippines.
—
Philippines
Madam Chair, capacity building is the foundation that enables all states to participate meaningfully in advancing international ICT security and implementing the agreed UN framework. It is not a stand -alone pillar, but an enabler of all five pillars, strengthening the ability of states to implement international law, operationalize the voluntary norms, develop confidence -building measures, and participate effectively in regular institutional dialogue. For the Philippines, effective capacity building is most impactful when it is demand -driven, nationally owned, sustainable, and responsive to nationally identified priorities. Capacity building should empower states to develop enduring institutional, legal, technical, operational, and policy capabilities rather than provide one -time assistance. This approach promotes national resilience while narrowing capacity gaps and enabling more inclusive international cooperation. At the national level, the Philippines continues to strengthen its cybersecurity ecosystem through investments in institutional development, workforce capacity, the protection of critical information infrastructure, and international cooperation. We appreciate the support of partner states, regional organizations, and international institutions in advancing these efforts through training, technical cooperation, and knowledge sharing. In particular, we recognize the valuable contributions of UNIDIR, whose workshops and technical engagements, have strengthened national expertise and supported the Philippines’ effective participation in international discussions on ICT security. The Philippines also believes that inclusive and meaningful participation strengthens the sustainability of capacity building. We therefore welcome initiatives that expand women’s participation in cybersecurity. Through the ITU Academy’s HERS CyberTrack program, three Filipino women cybersecurity policy professionals representing three government agencies are participating in the cyber policy and diplomacy track, strengthening national technical expertise and supporting sustainable capacity development while broadening participation in international cyber policy discussions. Madam Chair, capacity building should remain practical, implementation -oriented, and responsive to the evolving needs of member states. The global mechanism can play an important role by facilitating access to expertise, technical assistance, and knowledge sharing. In accordance with the needs and circumstances of recipient states. The Philippines supports capacity building. across the full spectrum of cybersecurity, including cyber threat intelligence analysis and information sharing, cyber incident response, digital forensics, ransomware preparedness, protection of critical information infrastructure, cybersecurity governance, emerging technologies, cyber policy and diplomacy, and the implementation of the agreed UN framework, among others. Such initiatives would facilitate peer learning, strengthen technical and operational capacities, foster trusted cooperation among member states, and support nationally identified capacity needs. Regional organizations can make valuable contributions by identifying regional priorities, coordinating technical cooperation, and facilitating peer learning among member states. Likewise, the expertise of the private sector, industry, academia, and the technical community can complement national efforts by contributing operational knowledge and practical experience, consistent with the agreed modalities of the UN. This mechanism, and while fully respecting its state -led nature. Madam Chair, capacity building is a long -term investment in international peace, security, and sustainable development. The Philippines remains committed to advancing capacity building through practical cooperation, dialogue, technical assistance, and the voluntary exchange of experience. By strengthening national capacities and promoting inclusive and sustainable partnerships, the global mechanism can support the agreed framework and contribute to an open, secure, stable, accessible, peaceful, and interoperable ICT environment for all. Thank you, Madam Chair.
—
Chair Egriselda López
Muchisimas gracias. Thank you very much. Zimbabwe.
—
Zimbabwe
Thank you, Chair. Zimbabwe aligns itself with the statement delivered by the ICC. and wishes to make the following additional remarks in a national capacity. Zimbabwe welcomes the establishment of the dedicated… thematic group on capacity building pursuant to General Assembly Resolution 79 -237. Its creation reflects the shared recognition that capacity building is essential to narrowing the digital divide, strengthening national resilience, and ensuring that all states, regardless of their size or technical capacity, can implement the agreed framework effectively. My delegation looks forward to working closely with you, the co -facilitators, and all delegations to advance this shared objective. Madam Chair, Zimbabwe wishes to acknowledge the valuable contributions of member states, regional organizations, the United Nations System, UNIDIR, and other partners that continue to support cyber capacity building across the world. These initiatives have strengthened national institutions, fostered technical expertise, and reinforced international cooperation. At the same time, Zimbabwe reiterates that capacity building is essential to narrowing the digital divide, strengthening national resilience, and strengthening national resilience. It should be nationally owned, demand -driven, needs -based, sustainable, transparent, and free from conditionalities. It should respond to nationally identified priorities, strengthen domestic institutions and capabilities, and empower states to build lasting resilience rather than create technological dependence. Effective capacity building requires sustained support to strengthen the policy, legal, institutional, and technical foundations of cybersecurity. This includes developing national cybersecurity strategies and legal frameworks, establishing and strengthening computer emergency response teams and computer security incident response teams, protecting critical infrastructure, enhancing incident response capabilities, promoting secure information sharing, and developing a skilled cybersecurity workforce. Madam Chair, Zimbabwe welcomes the opportunity. Thank you. Fund and the fellowship programs established under Resolution 79 -237. These initiatives will help broaden participation and make expertise more accessible. We also encourage greater coordination among existing capacity -building initiatives to maximize their impact, avoid duplication, and better respond to national needs. In this regard, Zimbabwe considers the Global Points of Contact Directory to be one of the most practical achievements of the open -ended working group. We encourage wider participation in future simulations and continued efforts to strengthen both diplomatic and technical national points of contact. Zimbabwe believes that regional organizations are indispensable partners in translating global commitments into practical implementation. The Malabo Convention and the Common African Position on the Application of International Law in Cyberspace provide an important continuity. The International Foundation for the Development of International Law and the International Law and the International Foundation for the Development of International Law and the International International Foundation for the Development of International Law and the International Foundation for International Law and the International Foundation for the Development of International Law and the Within the Southern African Development Thank you. Thank you very much. As we commence the work of this dedicated thematic group, Zimbabwe is confident that the spirit of cooperation and consensus that established this mechanism will continue to guide our work. We look forward to the practical, inclusive, and implementation-oriented discussions in December 2020. Thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to the Kingdom of the Netherlands.
—
Netherlands
Thank you, Chair. The Kingdom of the Netherlands aligns itself with the statement delivered by the European Union. Please allow me to add the following remarks in my national capacity. Chair, the commitment of the Kingdom of the Netherlands to strengthen cybercapacity worldwide is a long -standing one. We regard cybercapacity building as an essential enabler to promote responsible state behavior and consider it an indispensable pillar for a secure, inclusive and human -centered digital transformation. It is, above all, the most practical way to support a resilient cyberspace and to empower countries to develop their own strategies, national policies, institutions and skills in order to protect their digital infrastructures, economies and societies. When discussing cybercapacity building, the UN Global Mechanism should therefore not be a one – or two -way street, but rather should act as a place where ideas, needs, experiences, innovations and resources all come together. In other words, it should function as a platform where all stakeholders can learn from each other and jointly shape solutions. The role of DTG2 in this sense will be pivotal for the global mechanism’s success. The Kingdom of the Netherlands would like to see DTG2 function as a space for genuine collaboration to ensure that capacity building is implemented in an effective, pragmatic and responsive manner. The meaningful and unimpeded participation of multi -stakeholder community is imperative to this aim. Chair, the Kingdom of the Netherlands works closely with international partners, including the EU, UNIDER and through the Talent Mechanism, to improve cybersecurity and foster sustainable capacity building. Together, we support partner countries in many different manners. We have supported development and implementation of national cybersecurity strategies, incident response capabilities and policies for vulnerability disclosure. We also work to strengthen SEARCH and C -SEARCH and other relevant national agencies worldwide, and we will continue these efforts in the future. We would like to express our special appreciation of the Women in Cyber Fellowship, coordinated by UNIDER, to which the Kingdom of the Netherlands is a proud donor. The Women in Cyber Fellowship has… strengthened the participation of women in UN cyber processes… previously in the OEWG and currently in the Global Mechanism and has provided training to excellent results. In the recognition that policies in the cyber domain ought to be gender responsive and inclusive and realizing that women still are underrepresented in the digital and cybersecurity workforce, we encourage all delegations in a position to do so to contribute to the work of the Fellowship and broader to ensure that we bridge the gender divide. Chair, we believe that meaningful progress in the field of cybersecurity can only be achieved through cooperation. No country can secure cyberspace alone. The Kingdom of the Netherlands therefore stands ready to work with all interested parties, states, regional organizations, the private sector, the technical community and civil society to advance cybercapacity building in a way that is practical, inclusive and fully aligned with our shared commitments on the UN processes.
—
Chair Egriselda López
Thank you very much. I’m going to read now the next five countries. Paraguay. Suriname, the Dominican Republic, Paraguay, Indonesia, and Tuvalu.
—
Suriname
Madam Chair, Suriname aligns itself with the statement delivered on behalf of the Caribbean community by the Bahamas yesterday and wishes to add the following in its national capacity. Since this is the first time speaking, allow me to express our sincere appreciation for the opportunity to contribute to the important work of the global mechanism. As part of a proud Caribbean nation and one of the world’s most forested countries, with over 90 % of our territory covered by tropical rainforests, Suriname understands that resilience is built through partnership, solidarity, and responsible stewardship. These same values guide our approach to the digital domain. No state can build cyber resilience alone, and our collective security depends on ensuring that all countries have the capacity to participate safely and meaningfully in cyberspace. For Suriname, capacity building is not simply a technical exercise. It is an investment in national resilience, institutional development, economic stability, and public trust. Building that capacity requires sustained investment in skilled professionals, effective national institutions such as the CSIRT, strong legal and policy frameworks, secure digital infrastructure, and meaningful regional and international cooperation. For Suriname, these investments can be challenging. For more information, visit www .suriname .org. Limited financial and human resources often require difficult choices, yet the cost of insufficient investment is far greater, exposing countries to disruption of essential services, economic losses, and weakened public confidence. For Suriname, this is becoming increasingly important as our emergent offshore oil and gas sector creates new opportunities for sustainable economic growth, while also expanding the need to protect critical infrastructure against evolving cyber threats. Strong cybersecurity is therefore essential to safeguarding our development and maintaining the confidence of citizens, partners, and investors. Mademche Capacity building Capacity building is an investment in disability and prosperity of all. It must be practical, sustainable, and tailored to national circumstances. Suriname looks forward to working with the global mechanism and our partners to strengthen international cooperation and advance inclusive, well -financed capacity -building initiatives that ensure no countries left
—
Chair Egriselda López
Thank you. I now give the floor to the Dominican Republic.
—
Dominican Republic
Thank you. Thank you, Madam Chair, and good morning. The Dominican Republic reiterates its adherence to the joint statement delivered by Chile on behalf of a group of Latin American countries at the beginning of this segment. And we wish to add the following remarks to our national capacity. As the host country of a regional cybercapacity center and as a hub for two capacity-building programs in combating cybercrimes over the last 10 years, we are absolutely… Thank you. capacity building is not just an additional pillar. It is the foundation, it is the cost-cutting and enabling factor without which the other norms and commitments under the framework for responsible state behaviour will just remain words on a page. It is from this conviction that the Dominican Republic has gone for building a South-South cooperation platform for our region. By way of example of good practices, the Cyber Capacity Centre for Latin America and the Caribbean, LAC4, with its C… in Santo Domingo has provided technical diplomatic assistance directly to states without the intermediary of additional global bodies. This is not just about punctual capacity building, but about the long-term process of individuals who develop their installed capacity as well as certificates, together with the support from other programs, such as the Cybersecurity Program of the Organization of American States and the Digital Alliance of the EU, first core CARICOM impact, SICA, and the Andean community, to name but a few examples. The fight against cybercrime is not part of the scope of this group, but it is worth underscoring this reference to highlight the importance of this. The Dominican Republic is a… regional hub of the Glazi E and Glazi Plus of the EU and building capacity in cyber crime is part of the program and through this we have trained more than 900 police officers, judges and prosecutors. Some of them have also become instructors and we have trained prosecutors and judges not only in our country but also in other countries of the region facilitating, bringing together these different frameworks. We’ve also advanced the sustainability of these programs by incorporating a number of basic trainings to the official schools of public administration and police. For instance we’re also working on including the first responders training into the training of our national police force. in addition to the criminal justice system but also the nature of diplomacy they’re affected by this. Our continuous education program has therefore been included in constant diplomatic training. We’re also including cyber diplomacy in the permanent specialist master’s training program so that all people diplomats will have the basic tools that will allow them to become significantly involved into these increasingly cross -cutting disseminations. This confirms something that we have said before. Capacity -building programs work better when they combine sustained mentorship with networks of peer -peer cooperation, not just independent freestanding workshops. Chair, this allows us to offer the dedicated thematic group a key recommendation. Instead of duplicating the functions across other areas, the overall portal should help us map activities to avoid fragmentation of international efforts. We reiterate the principles that should guide our… our work, transparency, local demand, sustainability, inclusivity, and respect for national sovereignty. And we support the idea that any voluntary fund for capacity -building should include metrics so that we can measure results. And finally, we make available to the thematic group and other delegations our experience, both institutionally and personally, and we look forward to contributing actively to the working document to be put forward by the group of Latin American countries
—
Chair Egriselda López
Thank you. I now give the floor to Paraguay.
—
Paraguay
Thank you. Allow me to begin by congratulating you, Your Excellency, and your team for the hard work in preparing and leading this first substantive session of the global mechanism. Paraguay reiterates its firm commitment to an inclusive, transparent, and results -oriented mechanism, and we welcome and support your proposals. At the same time, we would call on delegations to… …advance in their preparations for the dedicated thematic groups with a view to a productive session in December under your leadership. On the subject of consideration, Paraguay aligns itself with the joint statement delivered by Chile on behalf of a group of Latin American countries on capacity building. And we heard this yesterday. Furthermore, we highlight that capacity building implies institutional growth and the development of skills in a sustainable way for the protection and prevention of cyber threats in order to guarantee data security and sovereignty. On this point, we wish to highlight that asymmetries generate insecurity. Sustainable growth in cybersecurity will not be possible without the sustainable growth of a digital economy. This digital economy is facing significant challenges in countries such as Paraguay. Countries that do not have direct access to the maritime backbones of the Internet, 95 % of the information on the web still passes through this. This information is nothing more than a product of digital services. And therefore, we also would like to take this opportunity to thank other countries for sharing their capacity building. I’d like to thank non -governmental organizations and the academic world. That has all contributed. To reducing the cybersecurity gap in our country. An example of this is the new National Security Strategy. It was built in collaboration with the Organization of American States and the Ministry of Information and Communication Technology of Paraguay, and that was launched last year. We’d also like to sincerely thank the organizations and countries that supported our national efforts in strengthening the capacities of technical and diplomatic specialists. We wish to highlight the Women in Cyber Program, supported by the Government of Canada, the OAS, and the Global Forum on Cyber Expertise. Also, the UNIDIL training course on training in international and cyber space, the United Nations Singapore Fellowship Program, and the ODA Program, and its donors, who have allowed us to participate in this first substantive session, and other similar initiatives. With respect to specific incidents, we highlight the importance of the C -Cert America’s network for the response and prevention of cyber incidents. These examples serve to demonstrate that combating and preventing cyber threats are effective when we truly strengthen, and we are committed to protecting, and we are committed to protecting, and we are committed to protecting, and we are committed to protecting, and we are committed to protecting, and we are committed to protecting, Madam Chair, ladies and gentlemen, Paraguay believes in multilateralism will continue to support constructive dialogue that takes into account the concerns of all parties to this forum. We have sent this statement to the Secretary of Publication. Thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to Indonesia to be followed by Tuvalu, Kuwait and Yemen. Indonesia, you have the floor.
—
Indonesia
Thank you, Madam Chair. Growing reliance on digital technologies across all sectors, combined with increasingly sophisticated cyber threats has made the need for robust ICT capacities more urgent than ever. In this evolving landscape, the state must be equipped with the technical skills and institutional readiness needed to safeguard critical infrastructure, protect sensitive data and maintain resilient digital ecosystems. Building such capabilities requires practical training, secure network practices and coordinated incident response mechanisms that enable governments to anticipate and mitigate emerging risks. In this context, Indonesia reaffirms that capacity building is a cornerstone of global cyber stability and a priority for the global mechanisms. Without adequate capacity, implementations of all pillars of the global mechanisms would be difficult to achieve. My delegation underscores that capacity building must be demand -driven, sustainable, inclusive, and free from political conditionalities. In order to bridge digital divides and ensure that all states can safely and securely seize the benefits of digital technologies. In this regard, we emphasize that capacity building should support the development of national cybersecurity strategies, incident response capabilities, critical infrastructure protections, and legal and policy frameworks. Capacity building should also, therefore, include training for policymakers and technical experts, academia, legal experts, and other relevant stakeholders to ensure a holistic and comprehensive approach. Regional initiatives over valuable models, ASEAN’s capacity -building ecosystems, as reflected in ASEAN’s Cybersecurity Cooperation Strategy for 2026 -2030, demonstrate how tailored long -term programs can strengthen national and regional resilience. Such initiatives highlight the importance of partnerships that respect national priorities and build capabilities that endure. Madam Chair, Indonesia believes that the global mechanisms, including through DTGs, could serve as a hub for coordinating capacity -building efforts, matching needs with resources, and ensuring that existence is accessible to all member states. Capacity -building must empower developing states to secure their digital ecosystem, participate fully in global discussions, and contribute to a stable and peaceful ICT environment. For Indonesia, some of the capabilities of the DTGs are the following. Capacity -building areas that are important to consider, including critical… information infrastructure protections, cyber crisis management, and strengthening the capacity of CERT and C -CERT. Indonesia stands ready to work with all partners to advance capacity building that is equitable, effective, and responsive to the
—
Chair Egriselda López
Thank you very much. I now give the floor to Tuvalu.
—
Tuvalu
Madam Chair, Tuvalu aligns itself with the statement delivered by the Kingdom of Tonga on behalf of the Pacific Island Forum and wishes to offer the following remarks in our national capacity. Tuvalu reaffirms its commitment to a secure and trusted digital environment as a prerequisite for our national development and resilience. Looking ahead to the dedicated thematic group sessions in December, we underscore that capacity building is a key part of our national development and resilience. Capacity building is the fundamental foundation for small island developing states such as my own country, Tuvalu, to effectively implement cyber norms. strengthen our national preparedness, and engage meaningfully in EU and cyber processes. Fourth, value capacity building must be country -owned and needs -driven. Our national priorities are focused on strengthening cybersecurity governance, enhancing incident response capabilities, and advancing the cyber pillar of our national security policy. To ensure support is tailored and practical, we strongly encourage the adoption of state -led assessments. Madam Chair, we also highlight the importance of equitable access. Our states often face significant constraints including limited resources, geographic isolation, and high connectivity costs. To be effective, international support is encouraged and must be predictable, sustainable, and delivered through diverse channels, including remote and hybrid training, the use of micro -modules, and sustained mentorship program. Furthermore, we advocate for the transparent and neutral global mechanism characterized by clear information on assistance and robust safeguards for data protection. Consistent with the OEWG principles, within our region, Tuvalu continues to support strong cooperation, particularly through Paxon and regional hubs that effectively leverage existing expertise. Madam Chair, Tuvalu also stressed that capacity building must empower small island states to engage effectively in UN cyber processes. This requires cooperation. We require practical support such as targeted training, remote access and assistance with drafting. In this regard, Tuvalu acknowledges the invaluable support of UNDA and partners women in cyber fellowship, which has been instrumental in enhancing our participation in this vital discussion and strengthen our national capacity in ICT security. Madam Chair, Tuvalu stands ready to collaborate with all delegations to ensure that global mechanisms evolve into an inclusive, practical and effective platform that strengthens global cyber stability. We must ensure this architecture serves all nations equitably, leaving no one behind.
—
Chair Egriselda López
Thank you very much. I now give the floor to Kuwait.
—
Kuwait
Madam Chair, as the outtest, the delegation of Kuwait wishes to congratulate you on assuming the chair of the global mechanism. We welcome you and wish you very success in guiding this important process in an inclusive, transparent and action -oriented manner. Kuwait attach particular importance to capacity building as a practical mean of enabling all states to participate meaningfully on an equal footing in the work of the global mechanism. As recognized in paragraph 8 and 9 of the OEWG final report, capacity building cuts across all pillars of our work requires a holistic approach and must be accelerated in light of rapid development in the digital landscape. Thank you. This is particularly relevant to international law as reaffirmed in paragraph 39, international law in particular, the charter of the OEWG. United Nations is applicable and essential to maintaining peace, security and stability in the ICT environment. Our challenge is, therefore, to deepen common understanding of how particular rules and principles apply to specific ICT activities and factual circumstances. The final report provides a strong basis for particular work in this area. Paragraph 43D2 calls for online and in -person training courses and modules as well as online resources, libraries and how international law applies to the use of ICT. In addition, paragraph 53 envisages the global ICT security cooperation and capacity building portal as the official website of the global mechanism, a central location for practical information and platform for sharing best practices. And capacity building information to also state that the portal should evolve over time to meet. the need of states. Paragraph 53G also recognized the possibility of integrating into the portal a digital tool supporting the national implementation of voluntary non -binding norms and the norms checklist recommendation 56 further calls for the establishment of the portal through a step -by -step model approach. Kuwait welcomes India’s important commitment to supporting the establishment and operationalization of the global portal. In the spirit of confidence building and capacity building, Kuwait stands ready to work closely with India to explore how the digital tool previously developed by Kuwait to support implementation of the voluntary non -binding norms could be technically aligned with the portal architecture and at a later stage presented for possible integration into the main global portal being operationalized. Proportionalized with India support. Separately, but in a complementary manner, Kuwait proposes the development of a voluntary scenario -based capacity building module on international law and the use of ICT within the global portal. The model should build on rather than duplicate existing tools and methodologies such as the Inudair scenario -based training activities, OSCE cyber diplomacy exercise, ASEAN operational exercise, the Talon workshop on international law and cyber operation, and international cyber law interactive toolkits. While this initiative differs in the scope and methodology, they demonstrate the value of using practical tools. The proposed model could build on and complement this work within the inclusive, universal, and intergovernmental framework of the United Nations global mechanism. proposed digital tool could contain a structured bank of neutral and hypothetical scenarios relating to the use of ICTs in the context of international security. Scenarios could be submitted voluntarily by member states, experts nominated by states, relevant United Nations entities, and, where appropriate, other institutions in accordance with the modalities of the global mechanism. Member states could participate voluntarily by providing their views on the rules and principles of international law they consider relevant, the fact they regard as legally significant, the legal threshold that may be applicable, and the issues on which further clarification or common understanding may be required. The tool could not determine whether interpretation is correct, rank national position, or replace intergovernmental negotiations. Rather, it would organize voluntary views, clarify the reasoning behind different approaches, and help distinguish legal disagreements from differences arising from factual, and not from factual, and not from factual, and not from factual, and not from factual, and not from factual, and not from factual, and not from factual, and not from factual, and not from factual, and not from factual, and not from factual, and not from factual, and not from factual, and not from factual, and not from factual, and not from factual, and not from factual, and not from factual, and not from factual, and not from factual, and not from factual, and not from factual, and not from factual, and not from factual, assumptions. This could support state developing national positions and strengthening coordination among legal, diplomatic, policy and technical communities because technology methods and risk are are changing rapidly, the scenario bank should not be static. The resulting contribution could inform capacity-building workshops, dedicated thematic group discussions, and substantive preliminary sessions. Taking together these proposals supports a modular one-stop-shop approach to the global portal. One component could support practical implementation of the voluntary binding norms, while another could facilitate capacity-building and deeper common understanding concerning the application of international law. Kuwait believes this practical, voluntary, and complementary approach would maximize existing resources, avoid unnecessary duplication, and help transform the global portal into an interactive capacity-building environment supporting continuous learning and more focused intergovernmental discussion. Thank you, Madam Chair. Thank you.
—
Chair Egriselda López
Thank you very much I now give the floor to the delegation of Yemen
—
Yemen
Madam Chair this is my first statement so I thank you for your able leadership of the work of this global mechanism which reaffirms the common responsibility for protecting cyberspace my delegation aligns itself with the statement delivered by the Arab group my country believes that stability in cyberspace is a vital component of the economy and of national security there are myriad challenges in the world in particular in my country nonetheless we are working responsibly on the security of our country to strengthen our national mechanisms At present, we are focusing on legislative aspects. For instance, we have a law against cybercrime and on the protection of data. What’s more, we’ve begun setting up a national center, the Center for Cybersecurity, which identifies threats and cyber incidents. Madam Chair, these national efforts show us the most important reality, which is you cannot create a safe cyber system when there’s a gap among countries in this area. Because a weakness in one link means the entire chain falls apart. Capacity building is not only an agenda item, it’s a mechanism. to strengthen national security and to deliver concrete results. I have a few more points. Madam Chair, we need to move from words to actions. Developing countries, in particular LDCs and post -conflict countries, need support, practical support. This in order to bolster their infrastructure of control and surveillance. In particular, we need national centers to respond to cyber threats and to threats in cyberspace. Second, we must launch sustainable training initiatives. We have 12 -month long -term training programs. These programs… build capacity of staff in this area, and in terms of legal evidence, this strengthens our national capacity in order to counter transnational cybercrime. Third, these approaches need to be in keeping with national priorities so that capacity -building programs are effective. Thus, what are the national needs, what are the national requirements? That must be ascertained with no politicization. Madam Chair, my country has committed to upholding international law. We are certain that collective action through partnerships in this area can allow us to achieve security and stability in cyberspace. To avoid threats going forward. we thus call for swift action in terms of the two DTGs in December 2026. Thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to the African Union and I’ll be followed by Interpol and the OSCE.
—
African Union Commission
Thank you. Thank you, Madam President. Thank you, Madam Chair, for giving the floor to the African Union. The African Union Commission aligns itself with the statement delivered by the African Group. We would like to add several remarks in addition on this matter which is of particular importance. The African Union Commission welcomes the establishment of DTG 2 on capacity building. For the African Union capacity building for the African Union capacity building for the African Union capacity building for the African Union capacity building for the African Union capacity building for the African Union capacity building for the African Union capacity building for the African Union capacity building for the African Union capacity building is a strategic investment in digital development. It also represents an essential lever for consolidating international peace and security in cyberspace in accordance with the objectives of the Continental Initiative aiming to silence the guns in Africa. Madam Chair, for the African Union Commission, capacity building must be conceived as a sustainable investment, an investment in resilient institutions, this while promoting gender equality and while giving young Africans the knowledge and skills that they need to become innovative actors and to work in cybersecurity. And to ensure the digital transformation of the continent in accordance with the aspirations of Agenda 2063. This is a fundamental principle of the African Union Commission and should be encouraged by the global mechanism as a vector for capacity building rooted in the context -based needs, national ownership, and learning among peers. The African Union Commission welcomes the staunch commitment of regional organizations and international partners to capacity building in cybersecurity on the continent. We intend to push forward with this cooperation to support member states in enacting confidence -building measures and implementing the Common African Position on the Application of International Law in Cyberspace and to support the African Union Commission in the implementation of the United Nations Framework on Responsible Behavior of States. as well as technical capacity building, prevention, detection, and response to cyber threats. Madam Chair, the African Union Commission remains convinced that sustainably building capacity requires international cooperation, grounded in mutual trust, in respect for digital sovereignty, and shared responsibility. We reaffirm our commitment to work with all partners in order to support the implementation of the United Nations Framework and to contribute to international peace and security in cyberspace. I thank you, Madam Chair.
—
Interpol
Madam Chair, distinguished delegates, thank you for this opportunity to contribute to the discussion on capacity building. As many delegations have already emphasized, cybercapacity building is essential to enable all states, irrespective of their level of technological development, to translate the commitments reflected in the UN Framework on Responsible State Behavior into practical action. In Interpol’s experience, capacity building results in sustainable operational capabilities and measurable outcomes when it is nationally owned, driven by identified needs, and crucially tailored to the distinct responsibility of relevant national actors. To continue the football metaphor introduced by the steam delegate from Canada, if we think of cybersecurity as a team sport, we should acknowledge that different types of players, goalkeepers, defenders, or strikers, may need different specialized forms of training. In this regard, Interpol’s main focus is on strengthening the capabilities of the law enforcement community at the national, regional, and global level. Our approach is to embed capacity building throughout the operational cycle to ensure that skills and techniques learned by investigators are then applied in the real world Our operation ramps provide a clear example Ahead of the operational phase, 13 countries from the Middle East and North Africa received specialized training, taking part in tabletop exercises focused on technical threats Interpol then coordinated the participating countries in a joint operation against fishing and malware Together, they arrested over 200 suspects, who had been linked to 3 ,867 identified victims As the threat landscape evolves, capacity building must also empower countries to address emerging challenges During the discussion on threats, my colleague explained that cybercrime is becoming increasingly industrialized This especially happened in the Middle East, where the threat of cybercrime is becoming increasingly industrialized The threat of cybercrime is becoming increasingly industrialized The threat of cybercrime is becoming increasingly industrialized The threat of cybercrime is becoming increasingly industrialized The threat of cybercrime is becoming increasingly industrialized To strengthen awareness, this week Interpol issued a new report on the industrialization of cybercrime, which not only maps the criminal ecosystem, but also proposes a framework for collective action. On artificial intelligence, together with Uniqui, Interpol has developed practical guidance for the responsible use of AI in law enforcement, including a toolkit and a related e -learning course. Through our latest initiative, Project Horizon, Interpol is also helping countries to strengthen preparedness and response capabilities against the criminal use of AI. Madam Chair, effective capacity building is the foundation for strengthening global cyber resilience. Ultimately, cyber capacity building must deliver practical results. For Interpol, its success is measured by what member countries are equipped to do, conduct more effective investigations, identify and arrest offenders, dismantle malicious infrastructure and criminal networks, trace and recover illicit processes, and support victims. These efforts directly contribute to the implementation of the UN Framework on Responsible State Behavior, such as Norm D, on cooperating to combat the criminal and terrorist misuse of ICTs. In conclusion, Madam Chair, Interpol remains committed to supporting member countries and ensuring that no country is left behind. We look forward to sharing our expertise on capacity building with the global mechanism, including during the dedicated systematic group in December. I thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much I now give the floor to the Organisation for Security and Cooperation in Europe, the OSCE
—
OSCE
Thank you very much, Madam Chair. The OSCE is well known for its work on cyber CBMs, and their implementation goes hand-in-hand with capacity building. In an effort to build states’ capacities, the OSC Secretary is organizing various activities since almost a decade. In the early stages, these workshops aimed to raise awareness about the CBMs in general. However, in recent years, the focus has shifted to more specific discussions on selected CBMs. To share some concrete examples, in one of the workshops… participants explored how closer cooperation between governments and private operators can improve information sharing, resilience, and incident responses in critical information sectors. A workshop organized earlier this year focused on translating critical information infrastructure protection concepts into practical action, enabling participants to identify critical infrastructure, assess risks, develop mitigation measures, and improve cross -sector and cross -border cooperation. Another workshop aimed to enhance effective national preparedness, crisis management, and coordination mechanism through exploring the connection between threat information sharing, OSC CBM -1, vulnerability disclosure, OSC CBM -16, and critical infrastructure protection, OSC CBM -16. While the OSC mainly focuses on confidence -based, building measures in cyberspace, our capacity building activities also support the broader implementation of the UN Framework for Responsible State Behaviour in Cyberspace. In November last year, the OSCE Secretary held its fourth annual training on international cyber diplomacy, gathering 18 participants from Eastern and Southeastern Europe, Central Asia, South Caucasus and Mongolia to build national capacities to engage in international cyber policy deliberations. The first edition of this training event was organized in 2022 to underline the importance of participating in international discussions on cyberspace. As these discussions grow in both significance and complexities, it is essential for all states to develop a good understanding of the issues discussed and to have the resources required to make meaningful contributions. Last year’s workshop placed particular emphasis on the outcomes of the second OED and examined the provisions of the global mechanism. Understanding these developments can help national representatives prepare to engage more effectively in future global discussions on cyber governance. I would like to express my gratitude to Ms. Catherine Preissman of UNOD for her contribution to the discussions, as well as to representatives of Canada, Estonia, France, Germany, Switzerland, and the United Kingdom, who have participated in the OEWG discussions. Some of them are also today in the room for sharing their expertise and practical experience about the UN level negotiations. Representatives of other regional organizations also contributed to the event. Furthermore, training participants benefited from presentations by stakeholders from Germany, Singapore, and the UK, who have followed the OEWG and also contributed to the discussions. While more and more states are developing national positions, and international law, the OEC is also supporting participating states in building capacities in this regard. A regional workshop brought together 14 policymakers with the aim to strengthen national capacities on the applicability of international law to state use of ICTs and promoted responsible state behavior in cyberspace. The participants gave practical insights into key rules and principles of international law and explored how these rules apply to cyberspace. The workshop also highlighted the importance of developing national positions on the applicability of international law in cyberspace to increase transparency and support stable relations between states. The OECD Secretary can deliver these activities thanks to the financial and substantive support of participating states for which we are grateful. Thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much. now that we have heard all delegations on this agenda item and in accordance with our modalities i would like to open up the floor to accredited entities under this agenda item of capacity building uh you’ll be given the floor for three minutes i have three requests we will begin with future earth systems
—
Future Earth Systems
thank you madam chair chris sampson from future earth systems speaking from the perspective of the technical community academia and civil society in regards to capacity building the enterprise architecture practice i referred to in my earlier intervention offers some useful frameworks that can assist member states and the general mechanism in particular the concept of capability maps and models may prove useful capability maps can help to clarify which capabilities are needed across different parts of government and the broad economy for implementing the norms and participating positively in the cbms and managing their ongoing operation and adaption as conditions continue to change. This includes government business capabilities such as legislative, regulatory, policy design and service delivery but also data application platform and technology infrastructure capabilities and digital literacy for citizens, businesses and other organisations across your economies which are all part of ensuring a stable, secure, safe and performant online environment for your communities. Maps of these capabilities can assist with prioritisation and planning for capacity building in each of your jurisdictions. Capability models on the other hand provide greater insights into each capability for instance showing how key roles, processes and information flows for that particular capacity. Capability and how you can measure your current… state of capability maturity against best practice and targeted maturity frameworks. In the case of cyber security, these include capabilities such as identifying assets and threats, protecting against these threats with practices such as vulnerability management, detecting and responding to intrusions and incidents, recovering and strengthening controls after incidents and the overall governance and risk management practices for effective oversight. These capability frameworks and architectural modelling practice overall can also assist with the identification of alignment between the agreed norms and CBMs and your local jurisdictional legislative and regulatory frameworks and in turn the systemised observability of effectiveness of the overall governance and risk management practices. These instruments in achieving the strategic outcomes of a cyberspace that supports peace and security for all. If helpful, I will aim to provide some further insights into these practices as part of the forthcoming DTGs. Thank you all again for welcoming multi -stakeholder participation.
—
Chair Egriselda López
Thank you very much for that statement. I now give the floor to response and security teams first.
—
FIRST
Thank you, Honorable Chair. Capacity building is a cornerstone of the approach, cyber community and capacity building. The ultimate objective is to enable states to safeguard their sovereignty and autonomy in cyberspace. Achieving this requires more than technical expertise or the ability to do so. It requires the ability to respond to cyber threats. It requires empowering all relevant stakeholders from incident responders and… technical experts to diplomats and policymakers to protect national interest effectively. Because cyberspace transcends national borders, regional and international cooperation is indispensable. At the same time, effective capacity building cannot be achieved through short -term interventions. It must be locally driven, responsive to national priorities and sustained over a longer period of time. First, together with many partners, a partner organization is actively advancing this vision. Experience from regions such as the Western Balkans and Africa demonstrate that greatest impact is achieved when international organizations work closely with local stakeholders and the international community to achieve the highest possible outcomes. And coordinate their efforts rather than operate in isolation. Funding is often limited to short -term project cycles, while reporting requirements are increasingly complex and fragmented across donors. These constraints undermine the long -term investments that meaningfully advance capacity -building requirements. Capacity -building is a shared responsibility. It calls for stronger partnerships among states, private sectors, civil society, and the technical community with donors and implementers working together effectively in public -private partnerships. First, looks forward to supporting the work of the global mechanisms, particularly the dedicated thematic groups, to help advance sustainable cyber capacity -building that delivers lasting resilience, strengthen international relationships, further security, and creates enduring value for all. Thank you.
—
Chair Egriselda López
Muchisima grazia. Thank you very much. I now give the floor… Kenya ICT Action Network. Thank
—
Kenya ICT Action Network
you so much Madam Chair for once again giving us this opportunity. So again I deliver this on behalf of the civil society and technical stakeholders who are actively engaged in delivering digital capacity building across the global south. So we look at capacity building not just an auxiliary component of international cyber security but as a fundamental bridge that converts abstract norms on paper into operational resilience on the ground. As we conclude this dedicated session on capacity building I want to say that One, it would be important to ensure that initiatives are truly demand -driven and human -centric. And so capacity building must not be a top -down, copy -paste exercise. Programs will need to be co -designed, co -created with local institutions to address specific regional threat landscapes, local language realities, and human rights impacts, including protecting civil society and vulnerable populations from the technology -facilitated abuse. And secondly, it’s to recognize non -state actors as capacity partners. So civil society organizations, academia, and technical communities do possess deep localized expertise and local threat temerity. And therefore, the global mechanism… will need to systematically integrate non -state actors as co -designers… co -creators, trainers, and evaluators of capacity -building programs to ensure accountability and measurable impact. And so cyber resilience cannot be built in silos. It needs to be achieved through state resources and cannot be achieved through state resources alone. So we stand ready to partner with member states to ensure that capacity -building within this global mechanism delivers practical,
—
Chair Egriselda López
Thank you very much. Thank you all for those valuable statements. I have received a request for a right of reply, and so I will give the floor to the delegation of the Russian Federation.
—
Russian Federation
Madam Chair we’re compelled to avail ourselves of the right of reply this is due to what we heard yesterday we heard outrageous anti -Russian attacks from the delegate of Italy the colleague mentioned some attacks on civilian infrastructure of Ukraine but for some reason they failed to mention the regular and fully real attacks by Ukraine on the civilian infrastructure of Russia perhaps that’s because the aforementioned Italian delegate and the Italian mechanism was indeed created in order to they’ve created a mechanism to facilitate attacks against Russia we know the answer to that my delegation has already spoken about the members of NATO’s coordination and support for the attacks against the information structure of my country and against its citizens Chair my delegation I’m going to take a few minutes to ask you to ask you to and I will and I will condemns the ceaseless attempts to politicize discussions around the global mechanism. What’s more, in the forum, such baseless accusations have been heard. It seems that some delegations have appeared here not to engage in professional dialogue, but to settle political scores and to reproduce propaganda cliches. We believe that such an approach undermines the work of the global mechanism, and it takes away time, and it demonstrates a lack of respect to all participants in the negotiations process. Thank you.
—
Chair Egriselda López
Muchas gracias. Thank you very much. Ukraine has requested the use of the floor. I understand for a right of reply.
—
Ukraine
Yes, thank you, Madam Chair. This is, we would like to take the floor to remind everyone that Ukraine remains under Russia’s aggression and is conducting the defense under the Article 51 of the UN Charter. And also we would like to state here that public attribution and restrictive measures are applied for a reason. And the reason is to manifest a joint protest against malicious behavior that undermines security in the use of the ICTs and on the global scale. Thanks.
—
Chair Egriselda López
Gracias. Thank you. Okay, so we have now heard the last speaker under this agenda item. Before I share some remarks of my own with you, I would like to give the floor to the Secretariat. to deliver a brief report on the global portal on cooperation and capacity building in the area of security of ICTs. Let me remind delegations that in the final report of the OEWG on the security of ICTs and their use, 2021 through 2025, which is in document A, stroke 80, stroke 257, seven states decided to establish this portal and an update was requested from the secretariat before the first plenary. And so I would now like to give the floor to the secretariat to provide this information.
—
Secretary
Thank you very much, Madam Chair. Thank you very much, Madam Chair, for this opportunity for a very brief update. Just to recall to delegations, by its resolution 80, stroke 60, the open -ended working group on security of and in the use of ICTs. The General Assembly requested the Secretary General to provide the necessary support to establish a dedicated global information and communications technology security cooperation and capacity building portal. The proposal for such a portal remained under discussion in the framework of the OEWG since 2022. And a growing number of states expressed positive opinions on this proposal, offering views on its objective purpose, content and substance. Subsequently, the final report of the OEWG, as mentioned by Madam Chair and later endorsed by the General Assembly via Resolution 8016, requested the establishment of the global ICT security portal via a step by step modular approach. The U .N. Secretary General. The Secretariat was therefore requested to provide an update on the establishment and operationalization of the portal prior to the first substantive plenary session. I’m afraid it’s during the session, but hopefully still of use. And. Further to the UN Secretariat, it was also requested to prepare an initial report outlining a proposal for the portal. And that document is available on the website and as A -AC .292 -2025 -1. Further to, I would like to express our deep appreciation to the delegation of India for its pledge to support with financial resources the technical establishment of the portal and its maintenance. We are deeply grateful to India for its support, which is enabling us to develop the portal in the current budgetary and liquidity constraints of the United Nations Secretariat. So we will be working. We will be working closely with India to further that project, nd we look forward to giving a more substantive update in future sessions. Thank you very much, Madam Chair.
—
Chair Egriselda López
I thank the Secretary for that valuable report. So as we have done over the course of this week, I would also like to provide some brief feedback on this agenda item. Capacity building is without a doubt fundamental. This shared understanding has been revealed in the number of delegations who have taken the floor under this agenda item. The states from across the world’s regions agree that capacity building is necessary in order to progress in the implementation of the framework on the responsible behavior of states and ICTs. This is not unique to one region. This is a… Shared and universal need. We have also heard from delegations who described capacity building… building activities that they have benefited from in a number of different fora. Some examples of this have been tabletop exercises, workshops, specialised trainings, exchanges of good practices in the area of information security, and also assistance in developing policies and regulatory frameworks amongst others in this very broad range of possibilities where capacity building is involved. I was also pleased to hear about activities underway, including bilateral regional and sub -regional activities. And in this connection, I welcome the important programmes such as Women in Cyber and the programme set up by the UNODA together with the Kingdom of Saudi Arabia to support the programme. Delegations, especially from developing countries. The inclusive participation is critical and fundamental to our process. Also during the debate we heard some proposals for activities, including in the context of DTG2 and also in connection with the points of contact directory. There’s no doubt that the dedicated thematic groups are going to play a very important role in supporting us towards concrete proposals, but also action -oriented proposals. Similarly, we also heard indications as to how capacity building should be done. Some of you mentioned that it must be sustained, coordinated, and contextualized in the needs and realities of states without applying a one -size -fits -all approach. This fails to take account of the specificities of each country and each region. It’s clear that the vast majority of member states see capacity building as a fundamental pillar for exercising the other pillars. but also to ensure this meaningful participation that reduces gaps and enables all states to take advantage of our digital ecosystem. Distinguished colleagues, we have completed our consideration of this agenda item, agenda item five. As you know, discussions of an integrated policy -oriented and cross -cutting nature on the five pillars of the framework for responsible state behavior in the use of information and communications technologies in accordance with Annex C of A -79 -214, including in particular paragraph nine and Annex I. And of A -80 -257. Before I deliver some concluding remarks, I would like to give the floor to any delegation wishing to speak under item 8, which is other matters. I believe that Australia wishes to make a statement under this agenda item. Australia, you have the floor.
—
Australia
Thank you, Madam Chair. Australia believes that achieving meaningful gender inclusion is also essential to building a more effective, representative and resilient international cyber environment. Women remain underrepresented across many cyber security and international security forums, yet their expertise and leadership are critical to shaping policies that respond to the needs of all users of ICTs. Through our ongoing support of the Women in Cyber Fellowship, Australia and partner countries, Canada, Germany, New Zealand, the Netherlands and the United Kingdom, are helping expand opportunities for women from underrepresented and developing states to participate in UN cybersecurity processes, strengthen professional networks and contribute their expertise to national and international policymaking. It has been truly heartening not only to hear statements delivered by fellows of this program throughout the plenary session this week, but also to hear directly from them the benefit they have gained from participating in this training program. We also wish to note for the record that women delivered just over 50 % of the statements during this plenary session. This continues the trend of gender parity that we have seen over the last final sessions of the OEWG and a welcome indicator of the progress we have made over the years. We encourage everyone to continue efforts to promote the full equal and meaningful participation and leadership of women across all aspects of the global mechanisms. Thank you, Chair.
—
Chair Egriselda López
Thank you very much I would like to ask if any other delegations wish to take the floor under this agenda item this not being the case I would like to deliver some concluding remarks and this will include my thoughts as to the next steps for the mechanism Distinguished colleagues this week all of us together we wrote the first page in the history of this global mechanism I would like to begin by thanking everyone here who made that possible I thank all of the delegations for their substantive statements and their participation during this first substantive session I’d also like to I recognise and appreciate the effort of many delegations. Many of you have travelled from very far to be here at this first session, and your presence here is a clear sign of the collective commitment that you all have to the mechanism, and I would like to sincerely thank you for that. As I also indicated just a few minutes ago, I’d also like to reiterate my thanks to all states who have contributed to making possible the participation of a number of delegations, especially from developing countries, and it is thanks to this support that I believe that this first session has had broad, diverse and representative participation, and this has strengthened the truly global character of this mechanism. I have been able to witness the genuine interest of all delegations in ensuring the success of this mechanism and it is this spirit that fills me with optimism because it confirms that we all share the same goal building a mechanism that can produce concrete results and that addresses the expectations that member states have placed in this mechanism when they decided to create it and I would like to highlight the quality and the precision of the statements made this week. You have come to this session with national statements, regional statements, statements on behalf of groups of countries and you have also come with working documents and concrete proposals that will be immensely useful in the next phase of our work especially as we come to preparedness. Thank you very much. meeting of the dedicated thematic groups, the DTGs. The wealth of our deliberations also reflects the very nature of this process. Behind the statements from delegations, there are teams made up of diplomats, technical experts, legal advisors, and professions from a number of different disciplines whose experience and knowledge has significantly enriched our deliberations. And it is this diversity of perspectives that constitutes, without a doubt, one of the greatest strengths of this mechanism. Allow me also to highlight one aspect that is worthy of special recognition. And as our Australian colleague has mentioned, this week we have seen very significant participation from women diplomats, women diplomats. Women technical experts, women academics, and professionals who have contributed to… the extremely high quality of our deliberations. According to the data shared by the Secretary just a few moments ago, of the 324 statements made this week, 162 were delivered by women, and that is indeed 50%. And this first page in the history of the mechanism proudly bears the hallmark of these women. Their leadership and experience constitutes a reminder that building a safer, more secure digital environment requires all of the talent and participation of women. And so now, in the spirit of multilingualism, allow me to continue in English. Dear colleagues, after each of the substantive segments, I have tried to share brief summaries of the main ideas we heard. I noted on each occasion these exercises were never intended to be used. exhaustive since it would be impossible to fully capture the depth and all the details of every contribution. They were rather a preliminary effort to identify the points where we observed the greatest convergence. The same story we began writing this week now needs a clear plan to carry it forward and allowed me to share some guidance on the next steps. They are both from this week’s discussion and from the mandate entrusted to me as chair of the GMEC during its first biennium. My intention is to make the most effective possible use of the intersessional period, which runs from today until the start of the DTG’s schedule from 7 to 11 December this year. We have before us the responsibility of translating the ideas and the concepts of the DTG’s priorities and proposals heard this week into a work agenda that allows the DTG’s to begin their work in an organized, efficient manner. with a clear orientation towards implementation. In close coordination with the co -facilitators, we will use this time to continue exchanging ideas and explore how to structure the work of the DTGs in an integrated and cross -cutting way with the aim of offering more specialized action -oriented spaces fully aligned with the framework’s five pillars, while always keeping in mind the particularities of DTG 1 and 2. And I will work very closely with the co -facilitators of both groups who have already begun their work and have shown from the outset a firm commitment to the success of this mechanism. I am deeply grateful for your willingness, your hard work, and also your leadership. As indicated in my non -paper of 29 June, I intend to ensure that the DTGs fulfill their function effectively. I have listened carefully to the message repeated by many, many delegations. The DTGs must add value to the mechanism, focus on specialized action -oriented discussions, and avoid becoming a repetition of the debates that we have already held in the plenary. In the coming months, building on that document and in consultation with all member states, the Presidency will present an initial proposal for the organization of the DTGs with an agenda and topics for consideration. The first draft of the phase is we still have left to write. Absolutely. As I mentioned. We hope to circulate the preliminary proposal toward the end. of August. Dear colleagues, this is perhaps the most important request I make of you today. I need your flexibility. I say this candidly because I’m very aware of the scale of what lies ahead. The DTGs have no prior template to build on. We must define the topics, the structure, and orientation of the work. There is no ready -made formula we can simply copy. It is up to us to draft it. And I also know that consensus is and will remain the guiding principle of this process, and I will preserve it. But consensus cannot in practice become an endless negotiation over every word of an initial proposal. I don’t think we have that kind of time. Between now and December, we must design together a working structure that still doesn’t exist and that will only be possible if we approach the task with flexibility. That is why I ask you to receive that proposal. We will circulate in August as a serious, balanced, good faith basis on which to begin building without delay. I will remain fully, fully available to hear you throughout the intersessional period. But I needed to be clear that the same spirit of flexibility that has defined this week must also accompany us in everything ahead. Importantly, later on, the Secretariat will facilitate the creation of the roster of experts foreseen in A. slash 80 slash 257 with a view to forming a diverse and geographically balanced group of specialists to support the DTG’s deliberation. The presidency will also circulate guiding questions ahead of each DTG meeting with sufficient advance notice and will convey all this information through a note addressed to all delegations. As for the outcomes of the DTG’s, I will continue consulting with states on the modalities for their transmission and consideration at the 2027 plenary session, always with a view to preserving decision -making under the principle of consensus. And as a tradition, El Salvador will present to the First Committee the resolution endorsing the plenary session and the DTG’s deliberation. I will continue discussing the DTG’s session with the expectation that it will be adopted without a vote. ok now bear with me as I switch into French sorry if I butchered a bit we have a very ambitious program of work before us and I would like to be clear about two points firstly the chair and my team will continue to dedicate their tireless efforts to meeting the expectations that member states have placed in us secondly the success of the global mechanism will not depend only on the chair we need the support, experience and cooperation of all delegations each one according to their capabilities and strengths this has always been and will continue to be a process led by Member States. I would also like to appreciate the valuable contribution of our stakeholders who participated during this week in accordance with the modalities agreed by Member States. Their technical knowledge, practical experience and specialised perspectives have enriched our deliberations and they show once again that the effective implementation of the global framework requires the participation and cooperation of a range of actors. The Chair will continue to promote this productive exchange during the intersessional period within the intergovernmental framework established by Member States. I’m afraid that my multilingualism does have its limits and I’m afraid that I’m not going to be able to do that. I’m afraid I have no other language to share with you so I will conclude as I began in Spanish. I would like to express my sincere thanks to the Secretariat of the United Nations, especially the Office for Disarmament Affairs. Their professionalism, dedication and continuous support have been absolutely crucial for the holding of this first substantive session. Thank you all. I also extend my thanks to the interpreters. Thank you to the interpreters, the conference service team, the technical team, and all of the individuals who are very often working behind the scenes to ensure that our work goes ahead smoothly, has gone ahead smoothly this week. And, of course, I have a special word for my team, to Julie and Ligia. Over recent months and during this particularly intense week, they… have worked with extraordinary professionalism and commitment to prepare each detail of this process. I’d also like to thank our young intern who has great enthusiasm and a readiness to learn and has contributed to the work of the chair during this historic first session. As I said on Monday, you have a committed chair available and fully dedicated to this goal, which is to successfully bring about our global mechanism. As I said at the start of my remarks, together we are writing the first page in the history of the global mechanism, and this page cannot be erased now. we have a record that even in an extremely complex international environment dialogue, cooperation and the quest for consensus are all still possible and we have decided to use them what follows will depend on us and so we continue to write this history with the same determination the same ambition and flexibility that I asked of you just a moment ago and so I am convinced that if we do so we will build a mechanism that can produce concrete results and that is is commensurate with what member states expect of it. I thank you. Thank you. Today we have reached the end of our agenda. Thank you very, very much, all of you, for good use of the time. The first meeting of the substantive plenary session of 2026 of the Global Mechanism on Advancements in the Area of ICTs in the Context of International Security and the Advancement of Responsible Behaviour of States in the Use of ICTs is closed.
Published by DiploFoundation (2011)— Malta: 4th Floor, Regional Building Regional Rd. Msida, MSD 2033, Malta Switzerland: Rue de Lausanne 56 CH-1202 Genève 21, Switzerland Serbia: Gavrila P. 44A Address Code 112410 11000 Beograd, Serbia E-mail: d…
Adoption of the agenda and organization of work— By advocating for international cooperation and partnerships, Paraguay recognises the need for a collective response to the complexities of transnational crime. Paraguay’s actions underscore its influential advocacy for …
Ad Hoc Consultation: Monday 5th February, Morning session— Additionally, Paraguay supports the United States’ proposal for the naming of the convention, considering its title and spirit as potent symbols that can unify international efforts against cyber threats. This endorsemen…
Acknowledgements— 7 Tuvalu joined the Commonwealth and the UN in 2000 (Ministry of Foreign Affairs and Trade- New Zealand) At the international level, Tuvalu maintains diplomatic relations with various countries (Box 2.1.3) in Asia, Mid…
High-level SIDS Ministerial Dialogue: Key Challenges and Opportunities— Above all, Tuvalu confronts the existential threat of climate change; although it contributes minimally to global emissions, the nation bears the full brunt of its adverse impacts. These effects are not isolated to envir…
Ad Hoc Consultation: Tuesday 30th January, Morning session— In the previous draft, ‘theft’ and ‘fraud’ were two separate articles. The ‘theft’ article was deleted, but was later amalgamated into the ‘fraud’ article, which is why ‘theft’ still appears. The Russian Federation suppo…
Multistakeholder Partnerships for Thriving AI Ecosystems— – Role/Title: Audience participant (part of a German group; specific affiliation not specified)[S1][S2][S3] – Role/Title: Parliamentary State Secretary at Germany’s Federal Ministry for Economic Cooperation and Developm…
AI Meets Agriculture Building Food Security and Climate Resilien— -Role/Title:Secretary, Ministry of Agriculture and Farmer Welfare, Government of India[S3][S4][S5] -Role/Title:Secretary, Ministry of Agriculture and Farmers’ Welfare, Government of Maharashtra; Moderator/Host of the se…
Keynote Adresses at India AI Impact Summit 2026— -Jacob Helberg- Role/Title: Undersecretary of State for Economic Affairs, United States; Area of Expertise: Economic policy, international trade, technology cooperation[S10][S11]. -S. Krishnan- Role/Title: Secretary (go…
Foreword by Chair of ICT Association Suriname Anuskha Varsha Sonai Chair ICT Associatie Suriname However, there is still much to be done if the ICT industry is to play a more significant role in the development and …
Creating opportunities— Personally, I am not involved with negotiations in the IT sector. However, I argue for universal Internet access to anybody who will listen, and I teach and share knowledge with as many as possible on how to use the Inte…
CSIRTs: A Global Dialogue with Cyber Incident Responders | IGF 2023— FIRST’s fundamental purpose is to offer a secure and confidential environment allowing these varied teams to coordinate and exchange intelligence, addressing cyber threats that are by nature transnational. However, FIRST…
Masterclass#1— Drawing on personal experiences from Egypt and participation in the board of the Forum of Incident Response and Security Teams (FIRST), the speaker highlighted the particular challenges in developing regions. These areas…
INTERNATIONAL CIIP HANDBOOK 2008 / 2009— FIRST is the only worldwide global CSIRT forum, and its members are experts from across the field and from all over the world. With its global scope and its heterogeneous character, FIRST supports and collaborates with e…
Transforming Agriculture_ AI for Resilient and Inclusive Food Systems— – Affiliation: Netherlands – Role/Title: (Representative of the Netherlands) – Role/Title: Senior Researcher Thank you, Ambassador. And on behalf of the OECD, I just want to thank once again the Netherlands for the le…
Ad Hoc Consultation: Friday 2nd February, Afternoon session— By championing inclusive and pragmatic global governance, the Netherlands solidifies its position as a driving force for collective action and widespread progress in the international arena. The expanded summary provided…
Agenda item 5 : Day 4 Morning session— In the area of Confidence-Building Measures (CBMs), the Netherlands values their role in enhancing transparency, fostering trust, and promoting cooperation between states. Their support for adapting CBMs drawn from their…
Ad Hoc Consultation: Wednesday 31st January, Afternoon session— Bilateral Treaties in Brazil’s Proposal: Expressing support for Brazil’s proposal regarding bilateral treaties or agreements, Yemen simultaneously notes the limited additional value of this proposal, given the existing f…
Ad Hoc Consultation: Thursday 8th February, Morning session— In the context of bolstering peace, justice, and institutional effectiveness on the international stage, Yemen’s contributions have stood out for their emphasis on achieving legislative inclusivity and legal clarity. Ini…
The International Criminal Police Organization— The International Criminal Police Organization, commonly known as Interpol, is an international organization that facilitates worldwide police cooperation and crime control.
Webinar – session 1— Jackson Cheboi:Thank you very much, Dr. Arie. Just to mention FASTA-S Interpol is an organization comprising of 196 member countries and each country has at least one node, that’s the NCB, National Central Bureau, which …
Adoption of the agenda and organization of work— Australia’s position suggests that safeguarding human rights is both a moral and a legal necessity, vital for maintaining treaty credibility and global trust. In cyber security deliberations, particularly concerning draf…
Ad Hoc Consultation: Wednesday 7th February, Afternoon session— Thailand has been an participant in international diplomatic efforts, consistently demonstrating a constructive and positive disposition towards fostering international cooperation and consensus-building. The nati…
Multistakeholder Partnerships for Thriving AI Ecosystems— – Role/Title: Audience participant (part of a German group; specific affiliation not specified)[S1][S2][S3] – Role/Title: Chairperson and CEO, Salesforce South Asia; Former Chairperson, State Bank of India[S16][S17] I …
Building Climate-Resilient Systems with AI— – Affiliation: Google – Role/Title: Director for Sustainability – Role/Title: Founding Partner, Climate Collective – Role/Title: Global Director of Climate Operations – Role/Title: Speaker / Representative, Universit…
ISBN:— – H.E. Dr. Amani Abou-Zeid, African Union Commission – H.E. Ms. Aurélie Adam Soulé Zoumarou, Benin – Dr. Ann Aerts, Novartis Foundation – H.E. Dr Mohammed Bin Saud Al Tamimi, Communications and Information Technology…
De-briefing and Next steps— The analysis presents a compelling case for the enhancement of learning initiatives throughout Africa, focusing specifically on the crucial role the African Union Commission (AUC) could play in fostering educational deve…
7th meeting – Plenary Session— Speakers from all regions agreed that regional organisations play a vital role in advancing CBMs and that their experiences should inform global implementation. The African Group encouraged the global mechanism to streng…
Transforming Agriculture_ AI for Resilient and Inclusive Food Systems— – Affiliation: State Polytechnic of Malang, Indonesia[S3] – Role/Title: Indonesian Air Force officer; Professor at the State Polytechnic of Malang; Co-inventor of the Knowledge Growing System – Role/Title: Senior Resea…
Panel Discussion: 01— -Affiliation:Ministry of Communications, Indonesia -Role/Title:Vice Minister of Communications, Indonesia Debjani Ghosh distinguished fellow Niti Aayog, I request Ms. Debjani Ghosh to kindly join us AI Summit is a plac…
The Russia-Ukraine War and Southeast Asia— 107. The West and NATO, in my view, were not uninvolved bystanders who had no role to play in the current situation. 126. One thing about Ukraine is clear though. Its defence has been nothing short of heroic against…
Agents of inclusion: Community networks & media meet-up | IGF 2023— Carlos Baca:Thank you. Thank you. Thank you. Carlos. Our next speaker is Nwendoa Kiibuba from Kenya. And he is one of the board members of the KIKTA-NET, that is the Kenyan ICT Action Network. And he’s also one of the de…
Parliamentary diplomacy and Internet policy making— Grace Mutung’u is an associate at the Kenya ICT Action Network (KICTANet) and an affiliate at the Berkman Klein Center for Internet and Society. She is also an assistant curator for the GIP Digital Watch observatory, and…
Webinar – session 1— David Ndeje, the Communications Officer for the Kenya ICT Action Network (KIKTANET), detailed the organisation’s crucial role in creating a cohesive force among different stakeholders in Kenya’s ICT policy sphere. KIKTAN…
6th meeting – Plenary Session— The knowledge base confirms that Egriselda López of El Salvador serves as Chair of the Global Mechanism on ICTs in the Context of International Security, and that the first substantive plenary session opened at UN Headqu…
Executive training for the Kuwait Diplomatic Institute— Kuwait’s diplomacy by 2035 aims to actively engage in multilateral forums such as the United Nations, the Gulf Cooperation Council (GCC), and the Arab League. By participating in these forums, Kuwait intends to advocate …
Ad Hoc Consultation: Wednesday 7th February, Morning session— In essence, Kuwait’s involvement in the convention is characterised by a proactive yet conciliatory approach. Their contributions place substantial emphasis on regional consensus, the utilisation of established legislati…
Opening of the session— Capacity building should support implementation of norms, international legal dialogue, and confidence-building measures in an integrated manner
Objectives— 63. We will implement the Global Digital Compact, within our own countries and at regional and global levels, taking into account different national realities, capacities, and levels of development, and respecting nation…
Objectives— 62. We will implement the Global Digital Compact, within our own countries and at regional and global levels, respecting and taking into account legal frameworks , national capacities, policies and priorities. 63. Govern…
Agenda item 6: other matters— Indonesia: Thank you, Mr. Chair. Indonesia affirms its view that capacity building, including the transfer of knowledge, skills, and technology, is essential to narrowing the digital divide between developed and devel…
Agenda item 5 : Day 4 Afternoon session— It could serve as a tool for matching recipients’ needs with available assistance. These considerations occur within the OEWG framework, highlighting cybersecurity’s multifaceted importance on a worldwide scale. The sta…
2nd meeting – Plenary Session— How should the global mechanism address the growing shortage of cybersecurity experts globally, and what role should the UN play in coordinating capacity-building efforts? How should the global mechanism ensure that its…
WSIS women and girls trendsetters and action plan— This tension has clear policy background. WSIS and digital cooperation traditions emphasise multistakeholder collaboration, capacity development and practical exchange across actors[S104][S105]. At the same time, UN Wome…
Media Remuneration Policy Analysis Mitchell began by establishing her background and the context for CNTI’s work. Coming from 25 years at the Pew Research Center where she helped l…
A Clash of Professional Cultures: The David Kelly Affair— Finally, the following two quotes provide further background context in support of the policy-promoting rather than intelligence-sharing aims of the dossier. The first comes from an email from Danny Pruce (a Foreign Offi…
A. Overview— Capacity-building should be based on mutual trust, demand-driven, correspond to nationally identified needs and priorities, and be undertaken in full recognition of national ownership. Partners in capacity-building parti…
Agenda item 6— Chair:Thank you, UNIDIR, for your statement and also for all the work that you do. Friends, it’s ten minutes to one, and I have no further speakers on capacity building. I just wanted to share some very quick points to s…
Plenary session on CBMs and capacity building— The identification of the requirement for enhanced support for developing countries in cybersecurity led to suggestions of establishing specialised programmes and mobilising resources, including mentioning a UN programme…
Agenda item 6— Furthermore, capacity building measures are advised to be demand-driven, unconditional, sustainable, and holistic, ensuring lasting benefits and adherence to the guiding principles of SDG 17. The anticipation surrounding…
Agenda item 5 : Day 4 Morning session— The commitment to capacity building is underscored by South Africa with the understanding that it should be evidence-based, politically neutral, transparent, accountable, and free of preconditions. This principled stance…
Cybersecurity Policy Foundations— Cybersecurity and international peace.The module discusses risks of cyber armament and conducting warfare by cyber means. We examine the existing UN framework for responsible state behaviour in cyberspace, encompassing c…
Shaping a UN Cyber Programme of Action | IGF 2023 Open Forum #84— Ellie McDonald has presented the concept of a Cyber Programme of Action (POA), which has garnered support from a group of UN member states. The POA aims to address threats in cyberspace and promote engagement and coopera…
6th meeting – Plenary Session— Developing Capacity LTD, represented by Robert Collett, described its work during the OEWG in providing unofficial transcripts, contributing to politically neutral side events, and producing reports in response to the Ch…
2nd meeting – Plenary Session— Brazil recommends that DTG 2 begin its work with a comprehensive diagnostic assessment of the current capacity-building landscape. This would involve identifying existing initiatives, evaluating their strengths and weakn…
Cybersecurity, cybercrime, and online safety— In conclusion, the analysis calls for gender perspectives and a human rights-based approach to be integrated into cybersecurity policies. It emphasizes the importance of multistakeholder governance, civil society organiz…
5th meeting Plenary Session— #Transition to the International Law Agenda Item The fifth meeting of the substantive plenary session of the 2026 Global Mechanism on Development in the field of information and communication technologies (ICTs) in the …
4th meeting – Plenary Session— Geopolitical tensions — particularly between Israel and Iran, and between Russia and Ukraine — were explicitly raised during the session, with right-of-reply exchanges reflecting deep disagreements over alleged malicious…
7th meeting – Plenary Session— Ireland argues that the expertise and experience of stakeholders from academia, the technical community, civil society and the private sector should play a strong role in the CBM implementation process. Practical tools, …
Who’s behind a cyberattack?— Political and legal attribution is in general a prerogative of states. However, it is the private sector, technical community, andcivil societywho can meaningfully support states with technical attribution.Non-state acto…
Geneva Dialogue | The launch of the Geneva Manual— Vulnerabilities in digital products and networks leading to cyberthreats raise security concerns from individual users to international security and peace. While States hold primary responsibility, meaningful cooperation…
WSIS women and girls trendsetters and action plan— This tension has clear policy background. WSIS and digital cooperation traditions emphasise multistakeholder collaboration, capacity development and practical exchange across actors[S104][S105]. At the same time, UN Wome…
WSIS Action Line C7 E-environment— Ms. Ponce is explicit that a clear legal mandate is needed to ensure consistency in reporting and a high level of compliance, noting that ARCEP’s legal mandate was formally expanded in 2021 to compel data collection acro…
vi CONTENTS— John Tirman’s chapter, ”Civil wars, globalization, and the ‘Washington Consensus”’, adopts a critical approach with reference to the possible links between international organizations and armed conflict. He considers t…
Agenda item 6: other matters— India: Thank you, Mr. Chair. The international community’s ability to prevent or mitigate the impact of malicious ICD activities depends on the capacity of each state to prepare and respond. Capacity-building is the…
Global Cybersecurity Index & Cyberwellness Profiles— The ICT Security Portal is a measure defined in the Austrian Cybersecurity Strategy and is officially recognized as the national or sector-specific program for sharing cybersecurity assets within the public sector. It wa…
7th meeting – Plenary Session— Capacity building was identified as a cross-cutting enabler underpinning all pillars of the framework for responsible state behaviour, not merely a standalone pillar. It was described as the bridge between political comm…
Agenda item 6— Chair:Thank you, UNIDIR, for your statement and also for all the work that you do. Friends, it’s ten minutes to one, and I have no further speakers on capacity building. I just wanted to share some very quick points to s…
Agenda item 5 : Day 4 Afternoon session— Finally, Thailand underlines the need for gender sensitivity in cyber security capacity-building endeavours, exemplified by the success of the Women in Cyber Fellowship Programme in fostering an inclusive initiative. The…
Webinar session— The participants generally viewed the achievement of consensus on a final report as a significant success, particularly given the current challenging geopolitical climate and deep divisions between states on cyber issues…
Plenary session on CBMs and capacity building— The identification of the requirement for enhanced support for developing countries in cybersecurity led to suggestions of establishing specialised programmes and mobilising resources, including mentioning a UN programme…
UN OEWG 2021-2025 10th substantive session— Regional and international cooperation are key themes, withthe EU and its member statessupporting regional confidence-building processes and capacity-building programs. Similarly,Kazakhstan advocated for regional coordin…
UN OEWG 2021-2025 9th substantive session— The concept of the Needs-Based ICT Security Capacity Building Catalogue was not extensively discussed in most of the sessions of theUN OEWG 2021-2025 9th Substantive Session. However, there was some discussion on the int…
UN OEWG 2021-2025 Final Report— e) States discussed the initial report76prepared by the UN Secretariat outlining a proposal for the development and operationalization of a dedicated Global ICT Security Cooperation and Capacity Building Portal (GSCCP)….
Agenda item 6: other matters— India: Thank you, Mr. Chair. The international community’s ability to prevent or mitigate the impact of malicious ICD activities depends on the capacity of each state to prepare and respond. Capacity-building is the…
3rd meeting – Plenary Session— The Chair requested that delegations deliver abridged statements and submit full versions to eStatements and the Chair’s team, in order to accommodate all speakers within the available conference time. The Chair’s proce…
Closure of the session— Chair: Thank you so much, Philippines, for your statement and also for your suggestions. Distinguished delegates, we have two more speakers who are on the list, Uruguay and Latvia. And then after that, I intend to ma…
Capacity building as an enabler of all five pillars – not a standalone item but the foundation for implementing international law, voluntary norms, confidence-building measures, and institutional dialogue (Philippines)
Arg. 1
Explanation
The Philippines argues that capacity building is not merely one pillar among equals but rather the foundational enabler that makes all other pillars of the UN framework functional. Without it, states cannot effectively implement international law, operationalise voluntary norms, develop confidence-building measures, or participate in institutional dialogue.
Evidence
The Philippines explicitly stated that capacity building ‘is not a stand-alone pillar, but an enabler of all five pillars, strengthening the ability of states to implement international law, operationalize the voluntary norms, develop confidence-building measures, and participate effectively in regular institutional dialogue’ .
Major Discussion Point
Major discussion point 1: The Fundamental Role of Capacity Building in Cybersecurity and the UN Framework
Agreed with
IndonesiaThailandZimbabweTuvaluYemenKuwaitSurinameAfrican Union Commission
on: Capacity building is fundamental and indispensable to the implementation of the entire UN framework on responsible state behaviour in ICTs
Capacity building must be demand-driven, nationally owned, sustainable, and responsive to nationally identified priorities rather than providing one-time assistance (Philippines)
Arg. 2
Explanation
The Philippines contends that effective capacity building must be grounded in the specific needs and priorities of recipient states, rather than being imposed from outside or delivered as isolated interventions. The goal should be to build enduring institutional, legal, technical, operational, and policy capabilities.
Evidence
The Philippines stated that effective capacity building ‘is most impactful when it is demand-driven, nationally owned, sustainable, and responsive to nationally identified priorities’ and should ’empower states to develop enduring institutional, legal, technical, operational, and policy capabilities rather than provide one-time assistance’ .
Major Discussion Point
Major discussion point 2: Principles Guiding Effective Capacity Building
The Philippines strengthens its cybersecurity ecosystem through investments in institutional development, workforce capacity, protection of critical information infrastructure, and international cooperation, with support from UNIDIR (Philippines)
Arg. 3
Explanation
The Philippines highlights its national efforts to build a robust cybersecurity ecosystem through multiple investment streams and international partnerships. It specifically recognises UNIDIR's contributions through workshops and technical engagements that have strengthened national expertise.
Evidence
The Philippines noted it ‘continues to strengthen its cybersecurity ecosystem through investments in institutional development, workforce capacity, the protection of critical information infrastructure, and international cooperation’ , and recognised ‘the valuable contributions of UNIDIR, whose workshops and technical engagements have strengthened national expertise and supported the Philippines’ effective participation in international discussions on ICT security’ .
Major Discussion Point
Major discussion point 3: National and Regional Capacity Building Initiatives and Programmes
The Philippines welcomes the ITU Academy's HERS CyberTrack programme, through which three Filipino women cybersecurity policy professionals are participating in the cyber policy and diplomacy track (Philippines)
Arg. 4
Explanation
The Philippines highlights a concrete example of gender-inclusive capacity building through the ITU Academy's HERS CyberTrack programme, which is enabling Filipino women professionals to strengthen their expertise in cyber policy and diplomacy. This initiative is presented as contributing to both national technical capacity and broader participation in international cyber policy discussions.
Evidence
The Philippines noted that ‘through the ITU Academy’s HERS CyberTrack program, three Filipino women cybersecurity policy professionals representing three government agencies are participating in the cyber policy and diplomacy track, strengthening national technical expertise and supporting sustainable capacity development while broadening participation in international cyber policy discussions’ .
Major Discussion Point
Major discussion point 4: Gender Inclusion and Women’s Participation in Cybersecurity
Agreed with
ThailandNetherlandsSaudi ArabiaAfrican Union CommissionTuvaluAustraliaChair Egriselda López
on: Gender-responsive capacity building and women's participation in cybersecurity are essential priorities
Regional organisations are indispensable partners in translating global commitments into practical implementation, identifying regional priorities, and facilitating peer learning among member states (Philippines)
Arg. 5
Explanation
The Philippines argues that regional organisations play a vital complementary role in the global capacity building architecture by contextualising global commitments to regional realities and enabling peer learning. This positions regional bodies as essential intermediaries between global frameworks and national implementation.
Evidence
The Philippines stated that ‘regional organizations can make valuable contributions by identifying regional priorities, coordinating technical cooperation, and facilitating peer learning among member states’ .
Major Discussion Point
Major discussion point 6: Multi-Stakeholder Participation and the Role of Non-State Actors
Agreed with
IndonesiaThailandZimbabweTuvaluOSCE
on: Regional organisations play an indispensable role in translating global commitments into practical capacity building at the national level
The private sector, industry, academia, and the technical community can complement national efforts by contributing operational knowledge and practical experience, consistent with agreed modalities and the state-led nature of the mechanism (Philippines)
Arg. 6
Explanation
The Philippines acknowledges the valuable role that non-state actors can play in supplementing national capacity building efforts, while emphasising that such contributions must remain consistent with the intergovernmental nature of the UN mechanism. This reflects a balanced approach to multi-stakeholder engagement.
Evidence
The Philippines noted that ‘the expertise of the private sector, industry, academia, and the technical community can complement national efforts by contributing operational knowledge and practical experience, consistent with the agreed modalities of the UN’ mechanism ‘and while fully respecting its state-led nature’ .
Major Discussion Point
Major discussion point 6: Multi-Stakeholder Participation and the Role of Non-State Actors
Capacity building as a cornerstone of global cyber stability, without which implementation of all pillars of the global mechanism would be difficult (Indonesia)
Arg. 1
Explanation
Indonesia asserts that capacity building is not peripheral but central to the entire global mechanism, arguing that without adequate capacity, none of the other pillars can be effectively implemented. This reflects the view that technical and institutional readiness is a prerequisite for meaningful participation in global cyber governance.
Evidence
Indonesia stated that it ‘reaffirms that capacity building is a cornerstone of global cyber stability and a priority for the global mechanisms’ and that ‘without adequate capacity, implementations of all pillars of the global mechanisms would be difficult to achieve’ .
Major Discussion Point
Major discussion point 1: The Fundamental Role of Capacity Building in Cybersecurity and the UN Framework
Agreed with
PhilippinesThailandZimbabweTuvaluYemenKuwaitSurinameAfrican Union Commission
on: Capacity building is fundamental and indispensable to the implementation of the entire UN framework on responsible state behaviour in ICTs
Capacity building must be demand-driven, sustainable, inclusive, and free from political conditionalities to bridge digital divides (Indonesia)
Arg. 2
Explanation
Indonesia emphasises that capacity building must adhere to core principles that protect the sovereignty and agency of recipient states, particularly developing countries. The explicit rejection of political conditionalities reflects concern that capacity building should not be used as a tool of geopolitical influence.
Evidence
Indonesia underscored ‘that capacity building must be demand-driven, sustainable, inclusive, and free from political conditionalities in order to bridge digital divides and ensure that all states can safely and securely seize the benefits of digital technologies’ .
Major Discussion Point
Major discussion point 2: Principles Guiding Effective Capacity Building
Indonesia highlights ASEAN's Cybersecurity Cooperation Strategy for 2026-2030 as a model of tailored long-term regional programmes that strengthen national and regional resilience (Indonesia)
Arg. 3
Explanation
Indonesia points to ASEAN's regional cybersecurity strategy as a concrete example of how tailored, long-term regional programmes can effectively build both national and collective resilience. This is presented as a model that respects national priorities while fostering sustained regional cooperation.
Evidence
Indonesia noted that ‘ASEAN’s capacity-building ecosystems, as reflected in ASEAN’s Cybersecurity Cooperation Strategy for 2026-2030, demonstrate how tailored long-term programs can strengthen national and regional resilience’ and highlight ‘the importance of partnerships that respect national priorities and build capabilities that endure’ .
Major Discussion Point
Major discussion point 3: National and Regional Capacity Building Initiatives and Programmes
Agreed with
PhilippinesThailandZimbabweTuvaluOSCE
on: Regional organisations play an indispensable role in translating global commitments into practical capacity building at the national level
The global mechanism, including through DTGs, could serve as a hub for coordinating capacity building efforts, matching needs with resources, and ensuring assistance is accessible to all member states (Indonesia)
Arg. 4
Explanation
Indonesia envisions the global mechanism and its dedicated thematic groups as a central coordination platform that can efficiently connect states' capacity building needs with available resources. This hub model would help avoid duplication and ensure equitable access to assistance.
Evidence
Indonesia stated that it ‘believes that the global mechanisms, including through DTGs, could serve as a hub for coordinating capacity-building efforts, matching needs with resources, and ensuring that existence is accessible to all member states’ , and identified specific priority areas including ‘critical information infrastructure protections, cyber crisis management, and strengthening the capacity of CERT and C-CERT’ .
Major Discussion Point
Major discussion point 5: The Role of the Global Mechanism, DTG2, and the Global ICT Security Portal
Agreed with
ZimbabweDominican RepublicKuwait
on: Greater coordination among existing capacity building initiatives is needed to avoid duplication and fragmentation
Disagreed with
KuwaitDominican RepublicSecretary
on: The role and design of the global ICT security portal
DTG2 should focus on critical information infrastructure protection, cyber crisis management, and strengthening the capacity of CERTs and C-CERTs (Indonesia)
Arg. 5
Explanation
Indonesia proposes specific thematic priorities for the dedicated thematic group on capacity building, focusing on practical operational areas that directly affect states' ability to protect their digital infrastructure and respond to cyber incidents. These priorities reflect Indonesia's view of the most urgent capacity gaps.
Evidence
Indonesia identified ‘capacity-building areas that are important to consider, including critical information infrastructure protections, cyber crisis management, and strengthening the capacity of CERT and C-CERT’ as priorities for the DTGs .
Major Discussion Point
Major discussion point 5: The Role of the Global Mechanism, DTG2, and the Global ICT Security Portal
Disagreed with
ThailandKuwaitDominican Republic
on: Thematic priorities for DTG2 on capacity building
128
WPM
401
Words
3 min
Time
Capacity building as a strategic investment in digital development and an essential lever for consolidating international peace and security in cyberspace (African Union Commission)
Arg. 1
Explanation
The African Union Commission frames capacity building not merely as a technical activity but as a strategic investment that serves both digital development and broader peace and security objectives. This framing connects cybersecurity capacity to the AU's continental initiative to silence the guns in Africa.
Evidence
The African Union Commission stated that ‘capacity building is a strategic investment in digital development’ and ‘represents an essential lever for consolidating international peace and security in cyberspace in accordance with the objectives of the Continental Initiative aiming to silence the guns in Africa’ .
Major Discussion Point
Major discussion point 1: The Fundamental Role of Capacity Building in Cybersecurity and the UN Framework
on: Capacity building is fundamental and indispensable to the implementation of the entire UN framework on responsible state behaviour in ICTs
Capacity building must be conceived as a sustainable investment in resilient institutions, promoting gender equality and empowering young people (African Union Commission)
Arg. 2
Explanation
The African Union Commission argues that capacity building must go beyond short-term technical assistance to become a sustainable investment that builds lasting institutional resilience. It specifically emphasises the dual imperatives of gender equality and youth empowerment as integral to this vision.
Evidence
The African Union Commission stated that ‘capacity building must be conceived as a sustainable investment, an investment in resilient institutions, this while promoting gender equality and while giving young Africans the knowledge and skills that they need to become innovative actors and to work in cybersecurity’ and to ‘ensure the digital transformation of the continent in accordance with the aspirations of Agenda 2063’ .
Major Discussion Point
Major discussion point 2: Principles Guiding Effective Capacity Building
The African Union Commission emphasises that capacity building must promote gender equality and give young Africans the knowledge and skills needed to become innovative actors in cybersecurity (African Union Commission)
Arg. 3
Explanation
The African Union Commission specifically highlights gender equality and youth empowerment as central pillars of its approach to cybersecurity capacity building. This reflects the AU's broader development agenda under Agenda 2063, which envisions an inclusive digital transformation of the continent.
Evidence
The African Union Commission emphasised that capacity building must promote ‘gender equality and while giving young Africans the knowledge and skills that they need to become innovative actors and to work in cybersecurity’ and to ensure ‘the digital transformation of the continent in accordance with the aspirations of Agenda 2063’ .
Major Discussion Point
Major discussion point 4: Gender Inclusion and Women’s Participation in Cybersecurity
on: Gender-responsive capacity building and women's participation in cybersecurity are essential priorities
136
WPM
864
Words
6 min
Time
Capacity building as a practical means of enabling all states to participate meaningfully and on an equal footing in the global mechanism (Kuwait)
Arg. 1
Explanation
Kuwait frames capacity building as the practical mechanism through which the principle of sovereign equality can be realised in the context of the global mechanism. Without adequate capacity, smaller or less technically advanced states cannot participate on equal terms with more developed nations.
Evidence
Kuwait stated that it ‘attaches particular importance to capacity building as a practical mean of enabling all states to participate meaningfully on an equal footing in the work of the global mechanism’ and that ‘capacity building cuts across all pillars of our work requires a holistic approach and must be accelerated in light of rapid development in the digital landscape’ .
Major Discussion Point
Major discussion point 1: The Fundamental Role of Capacity Building in Cybersecurity and the UN Framework
Agreed with
PhilippinesIndonesiaThailandZimbabweTuvaluYemenSurinameAfrican Union Commission
on: Capacity building is fundamental and indispensable to the implementation of the entire UN framework on responsible state behaviour in ICTs
Kuwait welcomes India's commitment to supporting the establishment of the global portal and proposes development of a voluntary scenario-based capacity building module on international law and ICT use within the portal (Kuwait)
Arg. 2
Explanation
Kuwait proposes a concrete addition to the global ICT security portal in the form of a voluntary scenario-based module that would help states develop common understanding of how international law applies to ICT activities. This tool would organise voluntary state views on legal questions without determining correct interpretations or replacing intergovernmental negotiations.
Evidence
Kuwait welcomed ‘India’s important commitment to supporting the establishment and operationalization of the global portal’ and proposed ‘the development of a voluntary scenario-based capacity building module on international law and the use of ICT within the global portal’ , noting that the tool ‘could not determine whether interpretation is correct, rank national position, or replace intergovernmental negotiations’ but would ‘organize voluntary views, clarify the reasoning behind different approaches’ .
Major Discussion Point
Major discussion point 5: The Role of the Global Mechanism, DTG2, and the Global ICT Security Portal
Agreed with
ZimbabweDominican RepublicIndonesia
on: Greater coordination among existing capacity building initiatives is needed to avoid duplication and fragmentation
Disagreed with
Dominican RepublicIndonesiaSecretary
on: The role and design of the global ICT security portal
98
WPM
463
Words
5 min
Time
Capacity building as indispensable in mitigating malicious cyber activities and strengthening cyber resilience, and should remain a central pillar of collective efforts (Thailand)
Arg. 1
Explanation
Thailand asserts that capacity building is not optional but indispensable for addressing malicious cyber activities and building resilience across all states, particularly developing countries. It should be central to collective efforts and aligned with the OEWG's principles of sustainability, inclusivity, and neutrality.
Evidence
Thailand stated that it ‘recognizes that capacity building is indispensable in mitigating malicious cyber activities and strengthening cyber resilience’ and that ‘capacity building should remain a central pillar of our collective efforts, enabling all states, particularly developing countries, to address the challenges and opportunities presented by emerging technologies’ .
Major Discussion Point
Major discussion point 1: The Fundamental Role of Capacity Building in Cybersecurity and the UN Framework
Agreed with
PhilippinesIndonesiaZimbabweTuvaluYemenKuwaitSurinameAfrican Union Commission
on: Capacity building is fundamental and indispensable to the implementation of the entire UN framework on responsible state behaviour in ICTs
Capacity building must be need-based, tailored to national priorities, and responsive to national capacities, respecting national sovereignty (Thailand)
Arg. 2
Explanation
Thailand emphasises that capacity building efforts must be customised to the specific needs and circumstances of each state rather than applying a uniform approach. This principle of tailoring is linked to respect for national sovereignty and the recognition that different states have different starting points and priorities.
Evidence
Thailand stated that ‘while strengthening cyber resilience to be effective, such efforts must be need-based, tailored to national priorities and responsive to national capacities’ , and supported ‘the operationalization of the capacity building principle to ensure a sustainable, inclusive, and neutral approach to capacity building that respects national security and national sovereignty’ .
Major Discussion Point
Major discussion point 2: Principles Guiding Effective Capacity Building
Thailand places great importance on the ASEAN-Japan Cybersecurity Capacity Building Centre and works with partners including UNIDIR, Canada, the EU, and civil society organisations to improve capacity building at national and regional levels (Thailand)
Arg. 3
Explanation
Thailand highlights its engagement in regional and bilateral capacity building initiatives, positioning the ASEAN-Japan Cybersecurity Capacity Building Centre as a key regional platform. It also notes its diverse partnerships with international organisations and civil society.
Evidence
Thailand stated that it ‘places great importance to the ASEAN-Japan Cybersecurity Capacity Building Center as a key platform for strengthening regional cyber capacity’ , noting the centre co-works with partners including ‘the United States, the United Kingdom, Canada, Switzerland, and the Netherlands, as well as civil society organizations’ . Thailand also noted working with ‘UNIDER, Canada, the European Union, Plinkendale Institute, the Simpson Center, and the ICT for Peace Foundation’ .
Major Discussion Point
Major discussion point 3: National and Regional Capacity Building Initiatives and Programmes
Agreed with
PhilippinesIndonesiaZimbabweTuvaluOSCE
on: Regional organisations play an indispensable role in translating global commitments into practical capacity building at the national level
Thailand recognises the importance of gender-responsive capacity building programmes, highlighting the Women in International Security and Cyberspace Fellowship and the Women Thailand Cyber Top Talent Competition (Thailand)
Arg. 4
Explanation
Thailand highlights two specific programmes that promote women's participation in cybersecurity: an international fellowship and a national competition. These initiatives are presented as practical tools for closing the gender gap and developing a new generation of skilled cybersecurity professionals.
Evidence
Thailand recognised ‘the importance of gender-responsive capacity-building programs which have enabled the more meaningful and inclusive participation of women in relevant meetings and processes’, citing ‘the Women in International Security and Cyberspace Fellowship and the Women Thailand Cyber Top Talent Competition, which aims to enhance women’s practical cybersecurity skills, reach the gender gap, and cultivate a new generation of highly skilled cybersecurity professionals’ .
Major Discussion Point
Major discussion point 4: Gender Inclusion and Women’s Participation in Cybersecurity
Agreed with
PhilippinesNetherlandsSaudi ArabiaAfrican Union CommissionTuvaluAustraliaChair Egriselda López
on: Gender-responsive capacity building and women's participation in cybersecurity are essential priorities
The DTG on capacity building should prioritise discussions on advanced cyber threats including AI security, quantum readiness, post-quantum cryptography, and assistance with national legal and policy frameworks (Thailand)
Arg. 5
Explanation
Thailand proposes specific thematic priorities for the dedicated thematic group on capacity building, focusing on emerging and advanced technological threats as well as foundational governance frameworks. This reflects Thailand's view that capacity building must keep pace with the rapidly evolving threat landscape.
Evidence
Thailand proposed that ‘the DTG-2 on capacity building prioritize discussions’ on ‘addressing advanced cyber threats including AI and security, quantum readiness, post-quantum cryptography, and operational technology security’ and ‘providing assistance with national legal and policy frameworks’ .
Major Discussion Point
Major discussion point 5: The Role of the Global Mechanism, DTG2, and the Global ICT Security Portal
Disagreed with
IndonesiaKuwaitDominican Republic
on: Thematic priorities for DTG2 on capacity building
126
WPM
336
Words
3 min
Time
Capacity building as an investment in national resilience, institutional development, economic stability, and public trust, not simply a technical exercise (Suriname)
Arg. 1
Explanation
Suriname argues that capacity building must be understood in its full breadth as an investment that touches on multiple dimensions of national life, including resilience, institutions, economy, and public trust. This framing elevates capacity building beyond a purely technical domain into a matter of national development.
Evidence
Suriname stated that ‘for Suriname, capacity building is not simply a technical exercise. It is an investment in national resilience, institutional development, economic stability, and public trust’ , requiring ‘sustained investment in skilled professionals, effective national institutions such as the CSIRT, strong legal and policy frameworks, secure digital infrastructure, and meaningful regional and international cooperation’ .
Major Discussion Point
Major discussion point 1: The Fundamental Role of Capacity Building in Cybersecurity and the UN Framework
Agreed with
PhilippinesIndonesiaThailandZimbabweTuvaluYemenKuwaitAfrican Union Commission
on: Capacity building is fundamental and indispensable to the implementation of the entire UN framework on responsible state behaviour in ICTs
Capacity building must be practical, sustainable, and tailored to national circumstances, avoiding a one-size-fits-all approach (Suriname)
Arg. 2
Explanation
Suriname emphasises that capacity building must be adapted to the specific circumstances of each country, particularly smaller developing nations with limited resources. The call for practical and sustainable approaches reflects the reality that many countries face difficult trade-offs in allocating limited resources.
Evidence
Suriname stated that ‘capacity building is an investment in disability and prosperity of all. It must be practical, sustainable, and tailored to national circumstances’ , noting that ‘limited financial and human resources often require difficult choices, yet the cost of insufficient investment is far greater, exposing countries to disruption of essential services, economic losses, and weakened public confidence’ .
Major Discussion Point
Major discussion point 2: Principles Guiding Effective Capacity Building
on: Capacity building must be demand-driven, nationally owned, needs-based, sustainable, and free from political conditionalities
Limited financial and human resources create difficult choices for countries like Suriname, yet the cost of insufficient investment is far greater, exposing countries to disruption of essential services and economic losses (Suriname)
Arg. 3
Explanation
Suriname highlights the difficult resource constraints faced by small developing nations and argues that the cost of underinvesting in cybersecurity capacity far outweighs the cost of investment. The emergence of an offshore oil and gas sector adds urgency to protecting critical infrastructure.
Evidence
Suriname noted that ‘limited financial and human resources often require difficult choices, yet the cost of insufficient investment is far greater, exposing countries to disruption of essential services, economic losses, and weakened public confidence’ . It also highlighted that ‘an emergent offshore oil and gas sector creates new opportunities for sustainable economic growth, while also expanding the need to protect critical infrastructure against evolving cyber threats’ .
Major Discussion Point
Major discussion point 7: Addressing the Digital Divide and Supporting Developing Countries
115
WPM
277
Words
2 min
Time
Capacity building must be locally driven, responsive to national priorities, and sustained over a longer period rather than through short-term interventions (FIRST)
Arg. 1
Explanation
FIRST argues that effective capacity building cannot be achieved through brief, isolated interventions but requires sustained, locally grounded engagement over time. This principle is presented as essential to achieving meaningful and lasting improvements in national cyber capabilities.
Evidence
FIRST stated that ‘effective capacity building cannot be achieved through short-term interventions. It must be locally driven, responsive to national priorities and sustained over a longer period of time’ , and noted that ‘experience from regions such as the Western Balkans and Africa demonstrate that greatest impact is achieved when international organizations work closely with local stakeholders and the international community’ .
Major Discussion Point
Major discussion point 2: Principles Guiding Effective Capacity Building
Capacity building is a shared responsibility calling for stronger partnerships among states, private sector, civil society, and the technical community, with donors and implementers working together effectively (FIRST)
Arg. 2
Explanation
FIRST argues that no single actor can bear the full responsibility for capacity building and that effective outcomes require genuine collaboration across all stakeholder groups. This includes ensuring that donors and implementers work in coordinated rather than fragmented ways.
Evidence
FIRST stated that ‘capacity-building is a shared responsibility. It calls for stronger partnerships among states, private sectors, civil society, and the technical community with donors and implementers working together effectively in public-private partnerships’ .
Major Discussion Point
Major discussion point 6: Multi-Stakeholder Participation and the Role of Non-State Actors
Funding is often limited to short-term project cycles while reporting requirements are increasingly complex and fragmented across donors, undermining long-term capacity building investments (FIRST)
Arg. 3
Explanation
FIRST identifies a structural problem in the funding landscape for capacity building: the mismatch between short-term funding cycles and the long-term nature of meaningful capacity development. Complex and fragmented reporting requirements further compound this challenge.
Evidence
FIRST noted that ‘funding is often limited to short-term project cycles, while reporting requirements are increasingly complex and fragmented across donors. These constraints undermine the long-term investments that meaningfully advance capacity-building requirements’ .
Major Discussion Point
Major discussion point 7: Addressing the Digital Divide and Supporting Developing Countries
169
WPM
497
Words
3 min
Time
The global mechanism should function as a platform where all stakeholders can learn from each other and jointly shape solutions, with DTG2 playing a pivotal role as a space for genuine collaboration (Netherlands)
Arg. 1
Explanation
The Netherlands argues that the global mechanism should not be a one-directional transfer of knowledge but a genuine multilateral platform where ideas, needs, experiences, and resources converge. DTG2 is identified as pivotal to realising this vision of collaborative capacity building.
Evidence
The Netherlands stated that ‘the UN Global Mechanism should therefore not be a one- or two-way street, but rather should act as a place where ideas, needs, experiences, innovations and resources all come together’ and ‘should function as a platform where all stakeholders can learn from each other and jointly shape solutions’, with ‘the role of DTG2 in this sense will be pivotal for the global mechanism’s success’ .
Major Discussion Point
Major discussion point 5: The Role of the Global Mechanism, DTG2, and the Global ICT Security Portal
The Netherlands works with international partners including the EU and UNIDIR to support development of national cybersecurity strategies, incident response capabilities, and vulnerability disclosure policies worldwide (Netherlands)
Arg. 2
Explanation
The Netherlands highlights its concrete contributions to global cybersecurity capacity building through partnerships with the EU, UNIDIR, and the Talent Mechanism. These efforts span multiple dimensions of cybersecurity governance, from strategy development to technical incident response.
Evidence
The Netherlands stated that it ‘works closely with international partners, including the EU, UNIDER and through the Talent Mechanism, to improve cybersecurity and foster sustainable capacity building’ and has ‘supported development and implementation of national cybersecurity strategies, incident response capabilities and policies for vulnerability disclosure’ , as well as working ‘to strengthen SEARCH and C-SEARCH and other relevant national agencies worldwide’ .
Major Discussion Point
Major discussion point 3: National and Regional Capacity Building Initiatives and Programmes
The Netherlands expresses special appreciation for the Women in Cyber Fellowship coordinated by UNIDIR, encouraging all delegations to contribute to bridging the gender divide in the digital and cybersecurity workforce (Netherlands)
Arg. 3
Explanation
The Netherlands highlights its financial support for the Women in Cyber Fellowship and calls on other delegations to contribute to this initiative. The appeal is grounded in the recognition that women remain underrepresented in the digital and cybersecurity workforce and that policies must be gender responsive.
Evidence
The Netherlands expressed ‘special appreciation of the Women in Cyber Fellowship, coordinated by UNIDER, to which the Kingdom of the Netherlands is a proud donor’ , noting that the Fellowship ‘has strengthened the participation of women in UN cyber processes’ and encouraging ‘all delegations in a position to do so to contribute to the work of the Fellowship and broader to ensure that we bridge the gender divide’ .
Major Discussion Point
Major discussion point 4: Gender Inclusion and Women’s Participation in Cybersecurity
Agreed with
ThailandPhilippinesSaudi ArabiaAfrican Union CommissionTuvaluAustraliaChair Egriselda López
on: Gender-responsive capacity building and women's participation in cybersecurity are essential priorities
The meaningful and unimpeded participation of the multi-stakeholder community is imperative to ensuring capacity building is implemented in an effective, pragmatic, and responsive manner (Netherlands)
Arg. 4
Explanation
The Netherlands argues that the multi-stakeholder community must be able to participate fully and without obstruction in the capacity building work of the global mechanism. This participation is presented as a prerequisite for effective, pragmatic, and responsive implementation.
Evidence
The Netherlands stated that ‘the meaningful and unimpeded participation of multi-stakeholder community is imperative to this aim’ of ensuring ‘that capacity building is implemented in an effective, pragmatic and responsive manner’ .
Major Discussion Point
Major discussion point 6: Multi-Stakeholder Participation and the Role of Non-State Actors
Disagreed with
Kenya ICT Action NetworkPhilippinesRussian Federation
on: The appropriate role and scope of multi-stakeholder participation in the global mechanism's capacity building work
96
WPM
376
Words
4 min
Time
Capacity building as a mechanism to strengthen national security and deliver concrete results, particularly for developing and post-conflict countries (Yemen)
Arg. 1
Explanation
Yemen frames capacity building as a practical mechanism for strengthening national security rather than merely an agenda item, emphasising the need for concrete results. This perspective is grounded in Yemen's own experience as a post-conflict country working to build national cybersecurity institutions.
Evidence
Yemen stated that ‘capacity building is not only an agenda item, it’s a mechanism to strengthen national security and to deliver concrete results’ , and noted its national efforts including ‘a law against cybercrime and on the protection of data’ and ‘setting up a national center, the Center for Cybersecurity, which identifies threats and cyber incidents’ .
Major Discussion Point
Major discussion point 1: The Fundamental Role of Capacity Building in Cybersecurity and the UN Framework
Agreed with
PhilippinesIndonesiaThailandZimbabweTuvaluKuwaitSurinameAfrican Union Commission
on: Capacity building is fundamental and indispensable to the implementation of the entire UN framework on responsible state behaviour in ICTs
Developing countries, particularly LDCs and post-conflict countries, need practical support to bolster their infrastructure, establish national cybersecurity centres, and launch sustainable long-term training programmes (Yemen)
Arg. 2
Explanation
Yemen calls for practical, targeted support for the most vulnerable countries, including least developed countries and those emerging from conflict. The emphasis is on building foundational infrastructure and sustainable training rather than one-off assistance.
Evidence
Yemen stated that ‘developing countries, in particular LDCs and post-conflict countries, need support, practical support’ to ‘bolster their infrastructure of control and surveillance’ and ‘national centers to respond to cyber threats’ , and called for ‘sustainable training initiatives’ including ’12-month long-term training programs’ that ‘build capacity of staff in this area’ .
Major Discussion Point
Major discussion point 7: Addressing the Digital Divide and Supporting Developing Countries
Disagreed with
IndonesiaZimbabweTuvalu
on: Whether capacity building should be free from political conditionalities and how this principle should be operationalised
A weakness in one country's cyber capacity means the entire chain falls apart, as no safe cyber system can be created when there are gaps among countries (Yemen)
Arg. 3
Explanation
Yemen articulates an interdependence argument: that cybersecurity is a collective good where the weakest link determines the strength of the whole system. This framing makes capacity building for developing countries a matter of global, not just national, security.
Evidence
Yemen stated that ‘you cannot create a safe cyber system when there’s a gap among countries in this area. Because a weakness in one link means the entire chain falls apart’ .
Major Discussion Point
Major discussion point 7: Addressing the Digital Divide and Supporting Developing Countries
127
WPM
531
Words
4 min
Time
Capacity building results in sustainable operational capabilities when it is nationally owned, driven by identified needs, and tailored to the distinct responsibilities of relevant national actors (Interpol)
Arg. 1
Explanation
Interpol draws on its operational experience to argue that capacity building is most effective when it is customised to the specific roles and responsibilities of different national actors, such as law enforcement. A one-size-fits-all approach fails to account for the specialised needs of different professional communities.
Evidence
Interpol stated that ‘capacity building results in sustainable operational capabilities and measurable outcomes when it is nationally owned, driven by identified needs, and crucially tailored to the distinct responsibility of relevant national actors’, using the football metaphor that ‘different types of players, goalkeepers, defenders, or strikers, may need different specialized forms of training’ .
Major Discussion Point
Major discussion point 2: Principles Guiding Effective Capacity Building
on: Capacity building must be demand-driven, nationally owned, needs-based, sustainable, and free from political conditionalities
Interpol's Operation HAECHI demonstrates embedded capacity building throughout the operational cycle, with 13 MENA countries receiving specialised training leading to the arrest of over 200 suspects (Interpol)
Arg. 2
Explanation
Interpol presents a concrete operational example of how capacity building embedded within real operations produces measurable results. The operation demonstrates that training followed by coordinated joint action can yield significant law enforcement outcomes.
Evidence
Interpol described that ‘ahead of the operational phase, 13 countries from the Middle East and North Africa received specialized training, taking part in tabletop exercises focused on technical threats’ and that ‘Interpol then coordinated the participating countries in a joint operation against fishing and malware. Together, they arrested over 200 suspects, who had been linked to 3,867 identified victims’ .
Major Discussion Point
Major discussion point 3: National and Regional Capacity Building Initiatives and Programmes
144
WPM
231
Words
2 min
Time
Australia, together with Canada, Germany, New Zealand, the Netherlands, and the United Kingdom, supports the Women in Cyber Fellowship and notes that women delivered just over 50% of statements during the plenary session (Australia)
Arg. 1
Explanation
Australia highlights the Women in Cyber Fellowship as a concrete mechanism for expanding women's participation in UN cybersecurity processes, particularly from underrepresented and developing states. The statistic that women delivered over 50% of statements during the plenary is presented as evidence of meaningful progress.
Evidence
Australia noted that ‘through our ongoing support of the Women in Cyber Fellowship, Australia and partner countries, Canada, Germany, New Zealand, the Netherlands and the United Kingdom, are helping expand opportunities for women from underrepresented and developing states to participate in UN cybersecurity processes’ , and that ‘women delivered just over 50% of the statements during this plenary session’, continuing ‘the trend of gender parity that we have seen over the last final sessions of the OEWG’ .
Major Discussion Point
Major discussion point 4: Gender Inclusion and Women’s Participation in Cybersecurity
Agreed with
ThailandPhilippinesNetherlandsSaudi ArabiaAfrican Union CommissionTuvaluChair Egriselda López
on: Gender-responsive capacity building and women's participation in cybersecurity are essential priorities
124
WPM
596
Words
5 min
Time
The Dominican Republic hosts the Cyber Capacity Centre for Latin America and the Caribbean (LAC4) and has trained over 900 police officers, judges, and prosecutors through EU programmes, building South-South cooperation (Dominican Republic)
Arg. 1
Explanation
The Dominican Republic presents itself as a regional hub for cybersecurity capacity building in Latin America and the Caribbean, highlighting the LAC4 centre and its EU-supported programmes. The training of over 900 criminal justice professionals demonstrates the scale and practical impact of these initiatives.
Evidence
The Dominican Republic noted that ‘the Cyber Capacity Centre for Latin America and the Caribbean, LAC4, with its centre in Santo Domingo has provided technical diplomatic assistance directly to states’ , and that as ‘a regional hub of the Glazi E and Glazi Plus of the EU’, it has ‘trained more than 900 police officers, judges and prosecutors’ , with some becoming instructors who train professionals in other countries of the region .
Major Discussion Point
Major discussion point 3: National and Regional Capacity Building Initiatives and Programmes
Capacity building programs are most effective when they combine sustained mentorship with networks of peer-to-peer cooperation rather than independent freestanding workshops (Dominican Republic)
Arg. 2
Explanation
The Dominican Republic draws on its experience as a regional capacity building hub to argue that sustained mentorship combined with peer networks produces better outcomes than isolated workshops. This lesson is offered as a concrete recommendation for the dedicated thematic group.
Evidence
The Dominican Republic stated that ‘capacity-building programs work better when they combine sustained mentorship with networks of peer-peer cooperation, not just independent freestanding workshops’ , and offered this as ‘a key recommendation’ to the dedicated thematic group .
Major Discussion Point
Major discussion point 2: Principles Guiding Effective Capacity Building
The overall portal should help map activities to avoid fragmentation of international efforts, and any voluntary fund should include metrics to measure results (Dominican Republic)
Arg. 3
Explanation
The Dominican Republic argues that the global portal should serve a coordination function by mapping existing capacity building activities to prevent duplication and fragmentation. It also calls for accountability mechanisms in the form of measurable metrics for any voluntary fund.
Evidence
The Dominican Republic stated that ‘instead of duplicating the functions across other areas, the overall portal should help us map activities to avoid fragmentation of international efforts’ , and that it supports ‘the idea that any voluntary fund for capacity-building should include metrics so that we can measure results’ .
Major Discussion Point
Major discussion point 5: The Role of the Global Mechanism, DTG2, and the Global ICT Security Portal
Agreed with
ZimbabweIndonesiaKuwait
on: Greater coordination among existing capacity building initiatives is needed to avoid duplication and fragmentation
Disagreed with
KuwaitIndonesiaSecretary
on: The role and design of the global ICT security portal
172
WPM
505
Words
3 min
Time
Paraguay developed a new National Security Strategy in collaboration with the OAS and highlights the C-CERT Americas network for cyber incident response and prevention (Paraguay)
Arg. 1
Explanation
Paraguay presents its new National Security Strategy as an example of successful international collaboration in capacity building, developed jointly with the OAS. It also highlights the C-CERT Americas network as an effective regional mechanism for cyber incident response.
Evidence
Paraguay noted that ‘the new National Security Strategy was built in collaboration with the Organization of American States and the Ministry of Information and Communication Technology of Paraguay, and that was launched last year’ , and highlighted ‘the importance of the C-Cert America’s network for the response and prevention of cyber incidents’ .
Major Discussion Point
Major discussion point 3: National and Regional Capacity Building Initiatives and Programmes
Asymmetries generate insecurity, and sustainable growth in cybersecurity will not be possible without sustainable growth of a digital economy, particularly for landlocked countries without direct access to maritime internet backbones (Paraguay)
Arg. 2
Explanation
Paraguay argues that cybersecurity gaps are inseparable from broader digital economic inequalities, and that addressing one requires addressing the other. It highlights the specific disadvantage faced by landlocked countries that lack direct access to the maritime infrastructure that carries most internet traffic.
Evidence
Paraguay stated that ‘asymmetries generate insecurity. Sustainable growth in cybersecurity will not be possible without the sustainable growth of a digital economy’ , noting that ‘countries that do not have direct access to the maritime backbones of the Internet, 95% of the information on the web still passes through this’ face particular challenges .
Major Discussion Point
Major discussion point 7: Addressing the Digital Divide and Supporting Developing Countries
128
WPM
573
Words
4 min
Time
The OSCE organises capacity building workshops on confidence-building measures, critical information infrastructure protection, and international cyber diplomacy training for states across Eastern Europe, Central Asia, and beyond (OSCE)
Arg. 1
Explanation
The OSCE describes its extensive portfolio of capacity building activities that have evolved from general awareness-raising to more specific, practical workshops on selected confidence-building measures. These activities span multiple regions and cover both technical and diplomatic dimensions of cybersecurity.
Evidence
The OSCE described workshops on ‘how closer cooperation between governments and private operators can improve information sharing, resilience, and incident responses in critical information sectors’ , on ‘translating critical information infrastructure protection concepts into practical action’ , and its ‘fourth annual training on international cyber diplomacy, gathering 18 participants from Eastern and Southeastern Europe, Central Asia, South Caucasus and Mongolia’ .
Major Discussion Point
Major discussion point 3: National and Regional Capacity Building Initiatives and Programmes
Agreed with
PhilippinesIndonesiaThailandZimbabweTuvalu
on: Regional organisations play an indispensable role in translating global commitments into practical capacity building at the national level
129
WPM
504
Words
4 min
Time
Capacity building as essential to narrowing the digital divide and ensuring all states can implement the agreed framework effectively (Zimbabwe)
Arg. 1
Explanation
Zimbabwe frames capacity building as the essential mechanism for closing the gap between states with different levels of technical and institutional development, enabling all to participate in implementing the agreed UN framework. This reflects the view that the framework's effectiveness depends on universal participation.
Evidence
Zimbabwe stated that ‘capacity building is essential to narrowing the digital divide, strengthening national resilience, and ensuring that all states, regardless of their size or technical capacity, can implement the agreed framework effectively’ .
Major Discussion Point
Major discussion point 1: The Fundamental Role of Capacity Building in Cybersecurity and the UN Framework
Agreed with
PhilippinesIndonesiaThailandTuvaluYemenKuwaitSurinameAfrican Union Commission
on: Capacity building is fundamental and indispensable to the implementation of the entire UN framework on responsible state behaviour in ICTs
Capacity building must be nationally owned, demand-driven, needs-based, sustainable, transparent, and free from conditionalities (Zimbabwe)
Arg. 2
Explanation
Zimbabwe articulates a comprehensive set of principles that should govern capacity building, emphasising national ownership and the absence of conditionalities as particularly important. These principles are presented as essential to ensuring that capacity building empowers rather than creates dependency.
Evidence
Zimbabwe stated that capacity building ‘should be nationally owned, demand-driven, needs-based, sustainable, transparent, and free from conditionalities’ and ‘should respond to nationally identified priorities, strengthen domestic institutions and capabilities, and empower states to build lasting resilience rather than create technological dependence’ .
Major Discussion Point
Major discussion point 2: Principles Guiding Effective Capacity Building
Zimbabwe acknowledges the Global Points of Contact Directory as one of the most practical achievements of the OEWG and encourages wider participation in future simulations (Zimbabwe)
Arg. 3
Explanation
Zimbabwe highlights the Global Points of Contact Directory as a tangible and practical outcome of the OEWG process that facilitates communication and cooperation between states. It calls for broader participation in simulations to strengthen both diplomatic and technical national points of contact.
Evidence
Zimbabwe stated that it ‘considers the Global Points of Contact Directory to be one of the most practical achievements of the open-ended working group’ and encouraged ‘wider participation in future simulations and continued efforts to strengthen both diplomatic and technical national points of contact’ .
Major Discussion Point
Major discussion point 3: National and Regional Capacity Building Initiatives and Programmes
Greater coordination among existing capacity building initiatives is needed to maximise impact, avoid duplication, and better respond to national needs (Zimbabwe)
Arg. 4
Explanation
Zimbabwe calls for improved coordination among the many existing capacity building initiatives to ensure they complement rather than duplicate each other. This coordination is presented as essential to maximising the impact of available resources and better serving national needs.
Evidence
Zimbabwe stated that it ‘encourages greater coordination among existing capacity-building initiatives to maximize their impact, avoid duplication, and better respond to national needs’ .
Major Discussion Point
Major discussion point 7: Addressing the Digital Divide and Supporting Developing Countries
Agreed with
Dominican RepublicIndonesiaKuwait
on: Greater coordination among existing capacity building initiatives is needed to avoid duplication and fragmentation
119
WPM
378
Words
3 min
Time
Capacity building as an essential enabler for small island developing states to implement cyber norms and engage meaningfully in UN cyber processes (Tuvalu)
Arg. 1
Explanation
Tuvalu argues that capacity building is particularly fundamental for small island developing states, which face unique constraints that make it difficult to implement cyber norms and participate in international processes without targeted support. This framing highlights the specific vulnerabilities of SIDS in the cyber domain.
Evidence
Tuvalu stated that ‘capacity building is the fundamental foundation for small island developing states such as my own country, Tuvalu, to effectively implement cyber norms, strengthen our national preparedness, and engage meaningfully in EU and cyber processes’ .
Major Discussion Point
Major discussion point 1: The Fundamental Role of Capacity Building in Cybersecurity and the UN Framework
Agreed with
PhilippinesIndonesiaThailandZimbabweYemenKuwaitSurinameAfrican Union Commission
on: Capacity building is fundamental and indispensable to the implementation of the entire UN framework on responsible state behaviour in ICTs
Capacity building must be country-owned and needs-driven, with state-led assessments to ensure support is tailored and practical (Tuvalu)
Arg. 2
Explanation
Tuvalu emphasises that capacity building must be grounded in the specific priorities and needs of recipient states, with state-led assessments ensuring that external support is genuinely tailored rather than generic. This principle protects national ownership of the capacity building process.
Evidence
Tuvalu stated that ‘capacity building must be country-owned and needs-driven’ with ‘national priorities focused on strengthening cybersecurity governance, enhancing incident response capabilities, and advancing the cyber pillar of our national security policy’, and strongly encouraged ‘the adoption of state-led assessments’ to ensure ‘support is tailored and practical’ .
Major Discussion Point
Major discussion point 2: Principles Guiding Effective Capacity Building
Tuvalu acknowledges the invaluable support of UNIDIR's Women in Cyber Fellowship in enhancing participation in UN cyber discussions and strengthening national capacity in ICT security (Tuvalu)
Arg. 3
Explanation
Tuvalu specifically recognises the Women in Cyber Fellowship as having made a tangible difference to its ability to participate in UN cyber processes and build national capacity. This testimony from a small island developing state underscores the fellowship's impact on the most resource-constrained participants.
Evidence
Tuvalu ‘acknowledges the invaluable support of UNDA and partners women in cyber fellowship, which has been instrumental in enhancing our participation in this vital discussion and strengthen our national capacity in ICT security’ .
Major Discussion Point
Major discussion point 4: Gender Inclusion and Women’s Participation in Cybersecurity
Agreed with
ThailandPhilippinesNetherlandsSaudi ArabiaAfrican Union CommissionAustraliaChair Egriselda López
on: Gender-responsive capacity building and women's participation in cybersecurity are essential priorities
Small island developing states face significant constraints including limited resources, geographic isolation, and high connectivity costs, requiring international support that is predictable, sustainable, and delivered through diverse channels including remote and hybrid training (Tuvalu)
Arg. 4
Explanation
Tuvalu articulates the specific structural disadvantages faced by small island developing states in building cybersecurity capacity, including geographic isolation and high connectivity costs. It calls for international support that is adapted to these realities through flexible delivery modalities.
Evidence
Tuvalu noted that ‘our states often face significant constraints including limited resources, geographic isolation, and high connectivity costs’ and that ‘to be effective, international support is encouraged and must be predictable, sustainable, and delivered through diverse channels, including remote and hybrid training, the use of micro-modules, and sustained mentorship program’ .
Major Discussion Point
Major discussion point 7: Addressing the Digital Divide and Supporting Developing Countries
Disagreed with
IndonesiaZimbabweYemen
on: Whether capacity building should be free from political conditionalities and how this principle should be operationalised
130
WPM
603
Words
5 min
Time
Saudi Arabia has launched multiple global initiatives including the Global Cybersecurity Forum, the Global Initiative for Child Protection in Cyberspace, the Global Initiative for Women's Empowerment in Cybersecurity, and a UNITAR office dedicated to cybersecurity headquartered in Riyadh (Saudi Arabia)
Arg. 1
Explanation
Saudi Arabia presents a comprehensive portfolio of global capacity building initiatives that it has established or co-launched, covering multiple dimensions of cybersecurity from child protection to women's empowerment. The establishment of a dedicated UNITAR office in Riyadh represents a significant institutional commitment.
Evidence
Saudi Arabia described the establishment of ‘the Global Cybersecurity Forum, GCF’ , the launch of ‘the Global Initiative for Child Protection in Cyberspace, and the Global Initiative for Women’s Empowerment in Cybersecurity’ , the ‘Global Initiative for International Capacity Building in Cyberspace in partnership with the United Nations’ , and ‘in partnership with the United Nations Institute for Training and Research, UNITAR launched a UNITAR office dedicated to cybersecurity headquartered in Riyadh’ .
Major Discussion Point
Major discussion point 3: National and Regional Capacity Building Initiatives and Programmes
Saudi Arabia implements a specialised programme to train women in cybersecurity for leadership positions, with representatives from more than 67 countries having graduated (Saudi Arabia)
Arg. 2
Explanation
Saudi Arabia highlights a concrete programme specifically designed to prepare women for leadership roles in cybersecurity, with a significant international reach spanning over 67 countries. This programme is presented as part of Saudi Arabia's broader commitment to gender inclusion in cybersecurity.
Evidence
Saudi Arabia stated that it ‘is also implementing a specialized program to train women in cybersecurity so they can take up leadership positions. To date, representatives from more than 67 countries have graduated from this program’ .
Major Discussion Point
Major discussion point 4: Gender Inclusion and Women’s Participation in Cybersecurity
Agreed with
ThailandPhilippinesNetherlandsAfrican Union CommissionTuvaluAustraliaChair Egriselda López
on: Gender-responsive capacity building and women's participation in cybersecurity are essential priorities
135
WPM
321
Words
2 min
Time
The Secretariat confirms that India has pledged financial support for the technical establishment and maintenance of the global ICT security portal, enabling its development despite UN budgetary constraints (Secretary)
Arg. 1
Explanation
The Secretariat provides an update on the status of the global ICT security portal, confirming that India's financial pledge is enabling its development at a time when the UN faces significant budgetary and liquidity constraints. This represents a critical enabling contribution to a key mechanism of the global framework.
Evidence
The Secretariat expressed ‘deep appreciation to the delegation of India for its pledge to support with financial resources the technical establishment of the portal and its maintenance’, noting that ‘we are deeply grateful to India for its support, which is enabling us to develop the portal in the current budgetary and liquidity constraints of the United Nations Secretariat’ .
Major Discussion Point
Major discussion point 5: The Role of the Global Mechanism, DTG2, and the Global ICT Security Portal
Disagreed with
KuwaitDominican RepublicIndonesia
on: The role and design of the global ICT security portal
118
WPM
3176
Words
27 min
Time
The Chair notes that of 324 statements made during the session, 162 were delivered by women, representing 50%, marking a significant milestone in the history of the mechanism (Chair Egriselda López)
Arg. 1
Explanation
The Chair highlights the achievement of gender parity in statement delivery during the first substantive session of the global mechanism as a significant milestone. This statistic is presented as evidence that the mechanism is beginning its work with a strong foundation of inclusive participation.
Evidence
The Chair stated that ‘of the 324 statements made this week, 162 were delivered by women, and that is indeed 50%’ and that ‘this first page in the history of the mechanism proudly bears the hallmark of these women’ .
Major Discussion Point
Major discussion point 4: Gender Inclusion and Women’s Participation in Cybersecurity
Agreed with
ThailandPhilippinesNetherlandsSaudi ArabiaAfrican Union CommissionTuvaluAustralia
on: Gender-responsive capacity building and women's participation in cybersecurity are essential priorities
The Chair intends to circulate a preliminary proposal for the organisation of the DTGs toward the end of August, calling on delegations to approach it with flexibility as a good faith basis for building the work structure (Chair Egriselda López)
Arg. 2
Explanation
The Chair outlines the next steps for the mechanism, including the circulation of a preliminary proposal for the DTGs' organisation by the end of August. She explicitly calls for flexibility from delegations, acknowledging that the DTGs have no prior template and that consensus cannot become an obstacle to progress.
Evidence
The Chair stated that she hopes ‘to circulate the preliminary proposal toward the end of August’ and asked delegations ‘to receive that proposal we will circulate in August as a serious, balanced, good faith basis on which to begin building without delay’ , noting that ‘the DTGs have no prior template to build on. We must define the topics, the structure, and orientation of the work’ .
Major Discussion Point
Major discussion point 5: The Role of the Global Mechanism, DTG2, and the Global ICT Security Portal
118
WPM
359
Words
3 min
Time
Enterprise architecture tools such as capability maps and models can assist member states in prioritising and planning capacity building, identifying which capabilities are needed across government and the broader economy (Future Earth Systems)
Arg. 1
Explanation
Future Earth Systems proposes that enterprise architecture practices, specifically capability maps and models, offer practical frameworks for structuring and prioritising capacity building efforts. These tools can help states identify gaps, measure maturity, and plan systematically across government and the broader economy.
Evidence
Future Earth Systems explained that ‘capability maps can help to clarify which capabilities are needed across different parts of government and the broad economy for implementing the norms and participating positively in the CBMs’ , and that ‘capability models on the other hand provide greater insights into each capability’ including ‘how you can measure your current state of capability maturity against best practice and targeted maturity frameworks’ .
Major Discussion Point
Major discussion point 6: Multi-Stakeholder Participation and the Role of Non-State Actors
111
WPM
256
Words
2 min
Time
Civil society organisations, academia, and technical communities possess deep localised expertise and should be systematically integrated as co-designers, co-creators, trainers, and evaluators of capacity building programmes (Kenya ICT Action Network)
Arg. 1
Explanation
The Kenya ICT Action Network argues that non-state actors bring irreplaceable localised knowledge and expertise that should be formally integrated into capacity building design and delivery, not merely consulted. This systematic integration is presented as essential for accountability and measurable impact.
Evidence
The Kenya ICT Action Network stated that ‘civil society organizations, academia, and technical communities do possess deep localized expertise and local threat temerity’ and that ‘the global mechanism will need to systematically integrate non-state actors as co-designers, co-creators, trainers, and evaluators of capacity-building programs to ensure accountability and measurable impact’ .
Major Discussion Point
Major discussion point 6: Multi-Stakeholder Participation and the Role of Non-State Actors
Disagreed with
NetherlandsPhilippinesRussian Federation
on: The appropriate role and scope of multi-stakeholder participation in the global mechanism's capacity building work
Capacity building cannot be achieved through state resources alone and must be co-designed with local institutions to address specific regional threat landscapes, local language realities, and human rights impacts (Kenya ICT Action Network)
Arg. 2
Explanation
The Kenya ICT Action Network argues that effective capacity building requires co-design with local institutions to ensure it is genuinely responsive to specific regional contexts, including language and human rights considerations. State resources alone are insufficient to achieve the depth and breadth of capacity building needed.
Evidence
The Kenya ICT Action Network stated that ‘capacity building must not be a top-down, copy-paste exercise. Programs will need to be co-designed, co-created with local institutions to address specific regional threat landscapes, local language realities, and human rights impacts, including protecting civil society and vulnerable populations from the technology-facilitated abuse’ , and that ‘cyber resilience cannot be built in silos’ and ‘cannot be achieved through state resources alone’ .
Major Discussion Point
Major discussion point 6: Multi-Stakeholder Participation and the Role of Non-State Actors
Russia condemns what it characterises as outrageous anti-Russian attacks from the Italian delegation, arguing that Ukraine's attacks on Russian civilian infrastructure were not mentioned, and that such politicisation undermines the work of the global mechanism (Russian Federation)
Arg. 1
Explanation
Russia uses its right of reply to contest what it characterises as one-sided accusations from Italy regarding attacks on civilian infrastructure, arguing that Ukraine's attacks on Russian infrastructure were ignored. Russia frames this as an example of the politicisation that undermines the global mechanism's work.
Evidence
Russia stated that it ‘heard outrageous anti-Russian attacks from the delegate of Italy’ who ‘mentioned some attacks on civilian infrastructure of Ukraine but for some reason they failed to mention the regular and fully real attacks by Ukraine on the civilian infrastructure of Russia’ , and condemned ‘the ceaseless attempts to politicize discussions around the global mechanism’, arguing that ‘such baseless accusations have been heard’ and that ‘such an approach undermines the work of the global mechanism’ .
Major Discussion Point
Major discussion point 8: Politicisation of the Global Mechanism and Right of Reply
Disagreed with
Ukraine
on: The politicisation of the global mechanism and the legitimacy of public attribution and restrictive measures
151
WPM
82
Words
32 s
Time
Ukraine reaffirms that it remains under Russian aggression and is conducting its defence under Article 51 of the UN Charter, and that public attribution and restrictive measures are applied to manifest joint protest against malicious behaviour undermining ICT security (Ukraine)
Arg. 1
Explanation
Ukraine responds to Russia's right of reply by reaffirming the legal basis for its actions under the UN Charter's right of self-defence. It also defends the practice of public attribution and restrictive measures as legitimate tools for signalling collective opposition to malicious cyber behaviour.
Evidence
Ukraine stated that it wishes ‘to remind everyone that Ukraine remains under Russia’s aggression and is conducting the defense under the Article 51 of the UN Charter’ , and that ‘public attribution and restrictive measures are applied for a reason. And the reason is to manifest a joint protest against malicious behavior that undermines security in the use of the ICTs and on the global scale’ .
Major Discussion Point
Major discussion point 8: Politicisation of the Global Mechanism and Right of Reply
Disagreed with
Russian Federation
on: The politicisation of the global mechanism and the legitimacy of public attribution and restrictive measures
Session Knowledge Graph
Speakers · Topics · Arguments · Relationships
Interactive graph · embed active
Agreed Points
Capacity building is fundamental and indispensable to the implementation of the entire UN framework on responsible state behaviour in ICTs
There was near-universal agreement across all delegations that capacity building is not a peripheral or optional element but a foundational requirement for the entire global mechanism. The Philippines explicitly stated it is ‘not a stand-alone pillar, but an enabler of all five pillars’ , while Indonesia affirmed that ‘without adequate capacity, implementations of all pillars of the global mechanisms would be difficult to achieve’ . Thailand described it as ‘indispensable in mitigating malicious cyber activities’ , Zimbabwe as ‘essential to narrowing the digital divide’ , and Tuvalu as ‘the fundamental foundation for small island developing states’ . Yemen stated it is ‘not only an agenda item, it’s a mechanism to strengthen national security’ , Kuwait emphasised it as ‘a practical mean of enabling all states to participate meaningfully on an equal footing’ , Suriname framed it as ‘an investment in national resilience, institutional development, economic stability, and public trust’ , and the African Union Commission called it ‘a strategic investment in digital development’ .
Capacity building as an enabler of all five pillars – not a standalone item but the foundation for implementing international law, voluntary norms, confidence-building measures, and institutional dialogue (Philippines)
Capacity building as a cornerstone of global cyber stability, without which implementation of all pillars of the global mechanism would be difficult (Indonesia)
Capacity building as indispensable in mitigating malicious cyber activities and strengthening cyber resilience, and should remain a central pillar of collective efforts (Thailand)
Capacity building as essential to narrowing the digital divide and ensuring all states can implement the agreed framework effectively (Zimbabwe)
Capacity building as an essential enabler for small island developing states to implement cyber norms and engage meaningfully in UN cyber processes (Tuvalu)
Capacity building as a mechanism to strengthen national security and deliver concrete results, particularly for developing and post-conflict countries (Yemen)
Capacity building as a practical means of enabling all states to participate meaningfully and on an equal footing in the global mechanism (Kuwait)
Capacity building as an investment in national resilience, institutional development, economic stability, and public trust, not simply a technical exercise (Suriname)
Capacity building as a strategic investment in digital development and an essential lever for consolidating international peace and security in cyberspace (African Union Commission)
Policy Context (Knowledge Base)
This consensus is well-established across multiple UN processes. The OEWG fourth substantive session confirmed capacity building as cross-cutting and essential for implementing the UN Framework for Responsible State Behaviour [S98], and India explicitly described it as ‘the common thread that connects focus areas of the OEWG’ [S116]. The broader UN cybersecurity framework, encompassing norms, confidence-building measures, and capacity development, is discussed in cybersecurity policy foundations literature [S97].
PhilippinesIndonesiaThailandZimbabweTuvaluYemenKuwaitSurinameAfrican Union Commission
Capacity building must be demand-driven, nationally owned, needs-based, sustainable, and free from political conditionalities
A strong and consistent consensus emerged around the core principles that should govern capacity building. The Philippines called for it to be ‘demand-driven, nationally owned, sustainable, and responsive to nationally identified priorities’ , while Indonesia underscored it must be ‘demand-driven, sustainable, inclusive, and free from political conditionalities’ . Thailand emphasised efforts ‘must be need-based, tailored to national priorities and responsive to national capacities’ , and Zimbabwe articulated the most comprehensive list, stating it ‘should be nationally owned, demand-driven, needs-based, sustainable, transparent, and free from conditionalities’ . Tuvalu called for ‘country-owned and needs-driven’ approaches with ‘state-led assessments’ , Suriname insisted it ‘must be practical, sustainable, and tailored to national circumstances’ , FIRST argued it ‘must be locally driven, responsive to national priorities and sustained over a longer period’ , and Interpol confirmed that ‘sustainable operational capabilities’ result when capacity building is ‘nationally owned, driven by identified needs’ .
Capacity building must be demand-driven, nationally owned, sustainable, and responsive to nationally identified priorities rather than providing one-time assistance (Philippines)
Capacity building must be demand-driven, sustainable, inclusive, and free from political conditionalities to bridge digital divides (Indonesia)
Capacity building must be need-based, tailored to national priorities, and responsive to national capacities, respecting national sovereignty (Thailand)
Capacity building must be nationally owned, demand-driven, needs-based, sustainable, transparent, and free from conditionalities (Zimbabwe)
Capacity building must be country-owned and needs-driven, with state-led assessments to ensure support is tailored and practical (Tuvalu)
Capacity building must be practical, sustainable, and tailored to national circumstances, avoiding a one-size-fits-all approach (Suriname)
Capacity building must be locally driven, responsive to national priorities, and sustained over a longer period rather than through short-term interventions (FIRST)
Capacity building results in sustainable operational capabilities when it is nationally owned, driven by identified needs, and tailored to the distinct responsibilities of relevant national actors (Interpol)
Policy Context (Knowledge Base)
This principle has been consistently articulated across UN processes. South Africa called for capacity building to be ‘evidence-based, politically neutral, transparent, accountable, and free of preconditions’ [S95], Iran emphasised political neutrality and freedom from conditions [S96], and agenda item 6 discussions confirmed the demand-driven, unconditional, sustainable framing with reference to SDG 17 guiding principles [S94].
Gender-responsive capacity building and women's participation in cybersecurity are essential priorities
There was broad and enthusiastic consensus across all regions on the importance of gender-responsive capacity building and women’s participation. Thailand highlighted the Women in International Security and Cyberspace Fellowship and the Women Thailand Cyber Top Talent Competition , the Philippines noted three Filipino women participating in the ITU Academy’s HERS CyberTrack programme , the Netherlands expressed ‘special appreciation of the Women in Cyber Fellowship, coordinated by UNIDER’ and encouraged all delegations to contribute , Saudi Arabia reported that ‘representatives from more than 67 countries have graduated’ from its women’s cybersecurity leadership programme , the African Union Commission called for ‘promoting gender equality and while giving young Africans the knowledge and skills’ , Tuvalu acknowledged the Women in Cyber Fellowship as ‘invaluable’ , Australia noted that ‘women delivered just over 50% of the statements during this plenary session’ , and the Chair confirmed that ‘162 were delivered by women, and that is indeed 50%’ .
Thailand recognises the importance of gender-responsive capacity building programmes, highlighting the Women in International Security and Cyberspace Fellowship and the Women Thailand Cyber Top Talent Competition (Thailand)
The Philippines welcomes the ITU Academy's HERS CyberTrack programme, through which three Filipino women cybersecurity policy professionals are participating in the cyber policy and diplomacy track (Philippines)
The Netherlands expresses special appreciation for the Women in Cyber Fellowship coordinated by UNIDIR, encouraging all delegations to contribute to bridging the gender divide in the digital and cybersecurity workforce (Netherlands)
Saudi Arabia implements a specialised programme to train women in cybersecurity for leadership positions, with representatives from more than 67 countries having graduated (Saudi Arabia)
The African Union Commission emphasises that capacity building must promote gender equality and give young Africans the knowledge and skills needed to become innovative actors in cybersecurity (African Union Commission)
Tuvalu acknowledges the invaluable support of UNIDIR's Women in Cyber Fellowship in enhancing participation in UN cyber discussions and strengthening national capacity in ICT security (Tuvalu)
Australia, together with Canada, Germany, New Zealand, the Netherlands, and the United Kingdom, supports the Women in Cyber Fellowship and notes that women delivered just over 50% of statements during the plenary session (Australia)
The Chair notes that of 324 statements made during the session, 162 were delivered by women, representing 50%, marking a significant milestone in the history of the mechanism (Chair Egriselda López)
Policy Context (Knowledge Base)
This priority reflects a broader consensus across multiple forums. The IGF Day 0 event on gender, diversity and cybersecurity recorded high-level consensus among speakers on prioritising gender mainstreaming and inclusive approaches [S106]. Analysis of cybersecurity governance frameworks similarly calls for gender perspectives and a human rights-based approach to be integrated into cybersecurity policies [S105].
ThailandPhilippinesNetherlandsSaudi ArabiaAfrican Union CommissionTuvaluAustraliaChair Egriselda López
Regional organisations play an indispensable role in translating global commitments into practical capacity building at the national level
Multiple delegations and organisations affirmed the critical role of regional bodies in bridging global frameworks and national implementation. The Philippines stated that ‘regional organizations can make valuable contributions by identifying regional priorities, coordinating technical cooperation, and facilitating peer learning among member states’ . Indonesia pointed to ‘ASEAN’s Cybersecurity Cooperation Strategy for 2026-2030’ as demonstrating ‘how tailored long-term programs can strengthen national and regional resilience’ . Thailand highlighted the ‘ASEAN-Japan Cybersecurity Capacity Building Center as a key platform for strengthening regional cyber capacity’ . Zimbabwe noted that ‘regional organizations are indispensable partners in translating global commitments into practical implementation’ . Tuvalu emphasised cooperation ‘through Paxon and regional hubs that effectively leverage existing expertise’ . The OSCE described its extensive portfolio of regional workshops on confidence-building measures and international cyber diplomacy training .
Regional organisations are indispensable partners in translating global commitments into practical implementation, identifying regional priorities, and facilitating peer learning among member states (Philippines)
Indonesia highlights ASEAN's Cybersecurity Cooperation Strategy for 2026-2030 as a model of tailored long-term regional programmes that strengthen national and regional resilience (Indonesia)
Thailand places great importance on the ASEAN-Japan Cybersecurity Capacity Building Centre and works with partners including UNIDIR, Canada, the EU, and civil society organisations to improve capacity building at national and regional levels (Thailand)
The OSCE organises capacity building workshops on confidence-building measures, critical information infrastructure protection, and international cyber diplomacy training for states across Eastern Europe, Central Asia, and beyond (OSCE)
PhilippinesIndonesiaThailandZimbabweTuvaluOSCE
Greater coordination among existing capacity building initiatives is needed to avoid duplication and fragmentation
Several delegations converged on the need for better coordination to prevent duplication and fragmentation of capacity building efforts. Zimbabwe called for ‘greater coordination among existing capacity-building initiatives to maximize their impact, avoid duplication, and better respond to national needs’ . The Dominican Republic argued that ‘the overall portal should help us map activities to avoid fragmentation of international efforts’ . Indonesia envisioned the global mechanism as ‘a hub for coordinating capacity-building efforts, matching needs with resources’ . Kuwait proposed a modular approach to the global portal that would ‘maximize existing resources, avoid unnecessary duplication’ .
Greater coordination among existing capacity building initiatives is needed to maximise impact, avoid duplication, and better respond to national needs (Zimbabwe)
The overall portal should help map activities to avoid fragmentation of international efforts, and any voluntary fund should include metrics to measure results (Dominican Republic)
The global mechanism, including through DTGs, could serve as a hub for coordinating capacity building efforts, matching needs with resources, and ensuring assistance is accessible to all member states (Indonesia)
Kuwait welcomes India's commitment to supporting the establishment of the global portal and proposes development of a voluntary scenario-based capacity building module on international law and ICT use within the portal (Kuwait)
Policy Context (Knowledge Base)
Brazil explicitly recommended that DTG 2 begin with a comprehensive diagnostic assessment of the current capacity-building landscape, identifying existing initiatives and making recommendations for optimisation [S103]. This reflects a recurring concern in UN cyber discussions about fragmentation of efforts.
ZimbabweDominican RepublicIndonesiaKuwait
Similar Viewpoints
These speakers share a strong conviction that capacity building must be grounded in the specific needs and sovereignty of recipient states, rejecting top-down or supply-driven approaches. The Philippines emphasised building ‘enduring institutional, legal, technical, operational, and policy capabilities rather than provide one-time assistance’ . Zimbabwe insisted it must ’empower states to build lasting resilience rather than create technological dependence’ . Tuvalu called for ‘state-led assessments’ to ensure support is ‘tailored and practical’ . FIRST noted that ‘greatest impact is achieved when international organizations work closely with local stakeholders’ , and Interpol used the football metaphor to illustrate that ‘different types of players…may need different specialized forms of training’ .
These speakers share a practical, implementation-oriented vision for what the dedicated thematic group on capacity building should achieve. Thailand proposed that DTG-2 ‘prioritize discussions’ on ‘addressing advanced cyber threats including AI and security, quantum readiness, post-quantum cryptography’ . Indonesia identified ‘critical information infrastructure protections, cyber crisis management, and strengthening the capacity of CERT and C-CERT’ as key areas . The Dominican Republic argued that ‘capacity-building programs work better when they combine sustained mentorship with networks of peer-peer cooperation, not just independent freestanding workshops’ . FIRST emphasised that capacity building ‘must be locally driven, responsive to national priorities and sustained over a longer period’ .
These speakers share a commitment to multi-stakeholder participation in capacity building, though with varying emphases on the degree of integration. The Netherlands argued that ‘the meaningful and unimpeded participation of multi-stakeholder community is imperative’ . The Kenya ICT Action Network called for the global mechanism to ‘systematically integrate non-state actors as co-designers, co-creators, trainers, and evaluators’ . FIRST described capacity building as ‘a shared responsibility’ requiring ‘stronger partnerships among states, private sectors, civil society, and the technical community’ . The Philippines acknowledged that non-state actors ‘can complement national efforts by contributing operational knowledge and practical experience’ while ‘fully respecting its state-led nature’ .
These speakers from developing and geographically disadvantaged countries share a common perspective on the structural barriers they face in building cybersecurity capacity. Yemen called for ‘practical support’ for ‘LDCs and post-conflict countries’ to ‘bolster their infrastructure’ . Suriname noted that ‘limited financial and human resources often require difficult choices, yet the cost of insufficient investment is far greater’ . Tuvalu highlighted ‘significant constraints including limited resources, geographic isolation, and high connectivity costs’ and called for ‘remote and hybrid training’ and ‘micro-modules’ . Paraguay argued that ‘asymmetries generate insecurity’ and highlighted the disadvantage of countries without ‘direct access to the maritime backbones of the Internet’ .
These speakers share a concrete commitment to gender inclusion in cybersecurity, backed by specific programmes and financial contributions. Saudi Arabia reported that ‘representatives from more than 67 countries have graduated’ from its women’s cybersecurity leadership programme . Thailand cited the Women in International Security and Cyberspace Fellowship and the Women Thailand Cyber Top Talent Competition as tools to ‘cultivate a new generation of highly skilled cybersecurity professionals’ . The Netherlands described itself as ‘a proud donor’ to the Women in Cyber Fellowship and encouraged all delegations to contribute . Australia highlighted that ‘women delivered just over 50% of the statements during this plenary session’ , continuing ‘the trend of gender parity’ .
These speakers from developing regions share an emphasis on practical, concrete achievements and South-South cooperation as models for effective capacity building. The Dominican Republic highlighted LAC4 as providing ‘technical diplomatic assistance directly to states without the intermediary of additional global bodies’ and training ‘more than 900 police officers, judges and prosecutors’ . Paraguay pointed to its National Security Strategy developed ‘in collaboration with the Organization of American States’ and the C-CERT Americas network . Zimbabwe highlighted the Global Points of Contact Directory as ‘one of the most practical achievements of the open-ended working group’ and encouraged ‘wider participation in future simulations’ .
Unexpected Consensus
What is unexpected is the degree to which a single specific programme – the Women in Cyber Fellowship coordinated by UNIDIR – received explicit, enthusiastic endorsement from states spanning very different geopolitical positions and levels of development. A small island developing state like Tuvalu described it as ‘invaluable’ , while a major donor state like the Netherlands called itself ‘a proud donor’ . Australia reported the remarkable statistic that ‘women delivered just over 50% of the statements during this plenary session’ , and the Chair confirmed this as ‘50%’ , framing it as a historic milestone. This convergence across developed and developing states, donors and recipients, on a single programme’s value was notably strong and suggests the Fellowship has achieved a rare cross-cutting legitimacy.
Given the often contentious debates in UN forums about the role of non-state actors in intergovernmental processes, it is notable that both state delegations and non-state actors found common ground on the value of multi-stakeholder participation in capacity building. The Philippines, a state delegation, acknowledged that non-state actors ‘can complement national efforts’ while ‘fully respecting its state-led nature’ . The Netherlands called for ‘meaningful and unimpeded participation of multi-stakeholder community’ . The Kenya ICT Action Network called for systematic integration of non-state actors , FIRST described capacity building as ‘a shared responsibility’ , and Future Earth Systems offered concrete technical tools . This convergence between state and non-state actors on the value of multi-stakeholder engagement, even within the constraints of a state-led mechanism, represents an unexpected area of practical consensus.
It is somewhat unexpected that states from very different regions – the Gulf (Kuwait), Latin America (Dominican Republic), Southeast Asia (Indonesia) – converged on a specific and ambitious vision for the global portal as an coordination hub rather than a passive information platform. Kuwait proposed a ‘voluntary scenario-based capacity building module on international law’ and a ‘modular one-stop-shop approach’ . The Dominican Republic called for the portal to ‘help us map activities to avoid fragmentation’ and include ‘metrics so that we can measure results’ . Indonesia envisioned it as ‘a hub for coordinating capacity-building efforts, matching needs with resources’ . The Secretariat confirmed India’s financial pledge is enabling development despite ‘budgetary and liquidity constraints’ , adding a practical dimension to this consensus.
Overall Assessment
The discussion revealed an exceptionally high level of consensus across all participating delegations and organisations on the fundamental importance of capacity building, the principles that should govern it, and the need for gender-inclusive approaches. Key areas of agreement included: (1) capacity building as a cross-cutting enabler of all pillars of the UN framework, not merely one pillar among equals ; (2) the core principles of national ownership, demand-driven approaches, sustainability, and freedom from political conditionalities ; (3) the indispensable role of regional organisations in translating global commitments into practical action ; (4) the importance of gender-responsive capacity building and the Women in Cyber Fellowship in particular ; (5) the need for better coordination to avoid duplication and fragmentation ; and (6) the value of multi-stakeholder participation within the state-led framework . Developing countries, particularly small island developing states and post-conflict countries, consistently highlighted their specific constraints and the need for tailored, sustainable support . The Chair’s concluding remarks confirmed these shared understandings and outlined next steps including circulation of a preliminary proposal for DTG organisation by end of August .
Points of Difference
The appropriate role and scope of multi-stakeholder participation in the global mechanism's capacity building work
The Netherlands argued that ‘the meaningful and unimpeded participation of multi-stakeholder community is imperative’ to effective capacity building, and Kenya ICT Action Network called for non-state actors to be ‘systematically integrate[d] as co-designers, co-creators, trainers, and evaluators’ . By contrast, the Philippines, while welcoming non-state contributions, explicitly qualified this by insisting it must be ‘consistent with the agreed modalities of the UN’ mechanism ‘and while fully respecting its state-led nature’ . Russia’s broader condemnation of what it saw as politicisation reflects a more restrictive view of what kinds of participation and statements are appropriate within the mechanism, implicitly pushing back against the expansive multi-stakeholder vision.
The meaningful and unimpeded participation of the multi-stakeholder community is imperative to ensuring capacity building is implemented in an effective, pragmatic, and responsive manner (Netherlands)
Civil society organisations, academia, and technical communities possess deep localised expertise and should be systematically integrated as co-designers, co-creators, trainers, and evaluators of capacity building programmes (Kenya ICT Action Network)
The private sector, industry, academia, and the technical community can complement national efforts by contributing operational knowledge and practical experience, consistent with agreed modalities and the state-led nature of the mechanism (Philippines)
Russia condemns what it characterises as outrageous anti-Russian attacks from the Italian delegation, arguing that Ukraine's attacks on Russian civilian infrastructure were not mentioned, and that such politicisation undermines the work of the global mechanism (Russian Federation)
Policy Context (Knowledge Base)
This tension has clear policy background. WSIS and digital cooperation traditions emphasise multistakeholder collaboration, capacity development and practical exchange across actors [S104][S105], while concerns have been raised that voluntary and ethical frameworks often lack safeguards [S113]. The IGF 2023 Open Forum on the Cyber Programme of Action similarly debated the role of stakeholders in a human-centric and rights-respecting framework [S99], and the 2nd meeting of the Global Mechanism’s organisational session addressed the need for clearly defined responsibilities between plenaries and DTGs [S102].
Whether capacity building should be free from political conditionalities and how this principle should be operationalised
Indonesia explicitly demanded that capacity building be ‘free from political conditionalities’ , and Zimbabwe similarly insisted it be ‘free from conditionalities’ . Yemen and Tuvalu, while not using the same language, emphasised the need for practical, unconditional support for the most vulnerable states . This cluster of positions implicitly tensions with the approaches of donor states such as the Netherlands, Australia, and Saudi Arabia, who frame their capacity building contributions in terms of their own strategic priorities and partnership frameworks , without explicitly addressing the conditionality concern. The disagreement is not openly confrontational but reflects a structural tension between recipient and donor perspectives on the terms of capacity building assistance.
Capacity building must be demand-driven, sustainable, inclusive, and free from political conditionalities to bridge digital divides (Indonesia)
Capacity building must be nationally owned, demand-driven, needs-based, sustainable, transparent, and free from conditionalities (Zimbabwe)
Developing countries, particularly LDCs and post-conflict countries, need practical support to bolster their infrastructure, establish national cybersecurity centres, and launch sustainable long-term training programmes (Yemen)
Small island developing states face significant constraints including limited resources, geographic isolation, and high connectivity costs, requiring international support that is predictable, sustainable, and delivered through diverse channels including remote and hybrid training (Tuvalu)
Policy Context (Knowledge Base)
While the principle of freedom from political conditionalities commands broad rhetorical support [S94][S95][S96], operationalising it remains contested. The Dominican Republic’s call for metrics and accountability in voluntary funds sits in tension with developing countries’ resistance to conditionalities, reflecting a structural ambiguity present in earlier OEWG discussions where the principle was affirmed but its practical application left undefined [S98].
IndonesiaZimbabweYemenTuvalu
The politicisation of the global mechanism and the legitimacy of public attribution and restrictive measures
Russia used its right of reply to condemn what it described as ‘outrageous anti-Russian attacks’ from Italy and argued that ‘such baseless accusations’ and ‘attempts to politicize discussions around the global mechanism’ undermine its work . Ukraine responded by asserting it ‘remains under Russia’s aggression and is conducting the defense under the Article 51 of the UN Charter’ and defended ‘public attribution and restrictive measures’ as legitimate tools ‘to manifest a joint protest against malicious behavior that undermines security in the use of the ICTs’ . This represents a direct and irreconcilable disagreement about the legitimacy of attribution, the characterisation of the conflict, and the appropriate boundaries of political discourse within the mechanism.
Russia condemns what it characterises as outrageous anti-Russian attacks from the Italian delegation, arguing that Ukraine's attacks on Russian civilian infrastructure were not mentioned, and that such politicisation undermines the work of the global mechanism (Russian Federation)
Ukraine reaffirms that it remains under Russian aggression and is conducting its defence under Article 51 of the UN Charter, and that public attribution and restrictive measures are applied to manifest joint protest against malicious behaviour undermining ICT security (Ukraine)
Policy Context (Knowledge Base)
Geopolitical tensions, particularly between Russia and Ukraine and between Israel and Iran, were explicitly raised during plenary sessions with right-of-reply exchanges reflecting deep disagreements over alleged malicious ICT activities [S108]. On attribution specifically, authoritative sources note that political and legal attribution is a prerogative of states, while the private sector, technical community, and civil society can meaningfully support states with technical attribution [S110], creating a structural tension when attribution is used to justify restrictive measures within a multilateral forum.
Russian FederationUkraine
Thematic priorities for DTG2 on capacity building
States proposed divergent priorities for DTG2. Thailand focused on emerging and advanced technological threats including ‘AI and security, quantum readiness, post-quantum cryptography, and operational technology security’ . Indonesia emphasised operational infrastructure priorities: ‘critical information infrastructure protections, cyber crisis management, and strengthening the capacity of CERT and C-CERT’ . Kuwait proposed a novel legal-technical tool – a ‘voluntary scenario-based capacity building module on international law and the use of ICT within the global portal’ – while the Dominican Republic focused on coordination and accountability, calling for the portal to ‘map activities to avoid fragmentation’ and for voluntary funds to ‘include metrics so that we can measure results’ . These differing priorities reflect genuine disagreement about what DTG2 should focus on first.
The DTG on capacity building should prioritise discussions on advanced cyber threats including AI security, quantum readiness, post-quantum cryptography, and assistance with national legal and policy frameworks (Thailand)
DTG2 should focus on critical information infrastructure protection, cyber crisis management, and strengthening the capacity of CERTs and C-CERTs (Indonesia)
Kuwait welcomes India's commitment to supporting the establishment of the global portal and proposes development of a voluntary scenario-based capacity building module on international law and ICT use within the portal (Kuwait)
The overall portal should help map activities to avoid fragmentation of international efforts, and any voluntary fund should include metrics to measure results (Dominican Republic)
ThailandIndonesiaKuwaitDominican Republic
The role and design of the global ICT security portal
Kuwait proposed an ambitious interactive legal module within the portal, envisioning it as a ‘modular one-stop-shop approach’ with components supporting ‘practical implementation of the voluntary binding norms’ and facilitating ‘deeper common understanding concerning the application of international law’ . The Dominican Republic took a more modest coordination-focused view, arguing the portal should primarily ‘map activities to avoid fragmentation’ . Indonesia envisioned the mechanism broadly as ‘a hub for coordinating capacity-building efforts, matching needs with resources’ . The Secretariat’s update confirmed the portal is still in early development , suggesting that the divergent visions for its scope and function have not yet been resolved and will need to be negotiated.
Kuwait welcomes India's commitment to supporting the establishment of the global portal and proposes development of a voluntary scenario-based capacity building module on international law and ICT use within the portal (Kuwait)
The overall portal should help map activities to avoid fragmentation of international efforts, and any voluntary fund should include metrics to measure results (Dominican Republic)
The global mechanism, including through DTGs, could serve as a hub for coordinating capacity building efforts, matching needs with resources, and ensuring assistance is accessible to all member states (Indonesia)
The Secretariat confirms that India has pledged financial support for the technical establishment and maintenance of the global ICT security portal, enabling its development despite UN budgetary constraints (Secretary)
Policy Context (Knowledge Base)
The concept of a global ICT security cooperation and capacity-building portal was introduced in earlier OEWG sessions as a tool for customised capacity-building [S117]. Austria’s national ICT Security Portal offers a concrete precedent as an officially recognised inter-ministerial initiative [S118], but the gap between national-level design and a global coordination mechanism contributes to disagreement about scope and governance of such a portal.
KuwaitDominican RepublicIndonesiaSecretary
Unexpected Differences
It was unexpected that FIRST, a technical community organisation, directly criticised the structural funding practices of donor states by noting that ‘funding is often limited to short-term project cycles, while reporting requirements are increasingly complex and fragmented across donors’ and that ‘these constraints undermine the long-term investments that meaningfully advance capacity-building requirements’ . This implicitly challenges the very donor states – Netherlands , Australia , Saudi Arabia – who were simultaneously presenting their capacity building contributions as exemplary. In a session characterised by consensus and mutual appreciation, this structural critique from a non-state actor was notably candid and created an implicit tension that no state directly addressed.
The eruption of a direct Russia-Ukraine political confrontation in the middle of a session dedicated to capacity building was unexpected. Neither Russia nor Ukraine had taken the floor during the substantive capacity building discussion, yet the session concluded with a sharp exchange about civilian infrastructure attacks, attribution, and the legitimacy of the mechanism itself. Russia’s accusation that ‘some delegations have appeared here not to engage in professional dialogue, but to settle political scores and to reproduce propaganda cliches’ and Ukraine’s invocation of Article 51 self-defence rights introduced a level of political conflict that stood in stark contrast to the cooperative, consensus-oriented tone of all other speakers. This disagreement was unexpected given the technical and developmental focus of the agenda item.
It was unexpected that the Dominican Republic – itself a developing country and regional capacity building hub – called for voluntary funds to ‘include metrics so that we can measure results’ , while other developing countries such as Zimbabwe , Indonesia , and Yemen emphasised that capacity building must be free from conditionalities and that national needs must be ‘ascertained with no politicization’ . The Dominican Republic’s call for metrics and accountability, while framed as a transparency measure, could be seen as introducing a form of conditionality that other developing states were explicitly resisting. This intra-developing-country tension was unexpected and was not directly addressed by any speaker.
Overall Assessment
The session was characterised by a high degree of surface-level consensus on the fundamental importance of capacity building, with virtually all speakers agreeing that it is essential, must be demand-driven, nationally owned, sustainable, and inclusive. However, beneath this consensus lay meaningful disagreements on: (1) the scope and nature of multi-stakeholder participation, with a spectrum from the Philippines’ state-led model to Kenya ICT Action Network’s call for systematic non-state co-design ; (2) the specific thematic priorities for DTG2, with Thailand , Indonesia , Kuwait , and the Dominican Republic proposing divergent agendas; (3) the design and scope of the global ICT security portal ; (4) the structural adequacy of current funding mechanisms, as critiqued by FIRST ; and (5) a sharp political disagreement between Russia and Ukraine that disrupted the cooperative tone of the session. The implicit tension between donor and recipient perspectives on conditionalities also represents a structural disagreement that was not openly confronted.
All these speakers agreed that capacity building must be demand-driven, nationally owned, and tailored to national circumstances . However, they diverged on emphasis and specific mechanisms: Thailand and Philippines focused on the principle of tailoring and sustainability; Zimbabwe and Indonesia explicitly added the rejection of conditionalities ; Tuvalu specifically called for 'state-led assessments' as the mechanism to ensure tailoring ; and Suriname and Yemen emphasised the resource constraints that make these principles difficult to implement in practice . The shared goal of nationally owned, demand-driven capacity building thus masks disagreement about how to operationalise it and what safeguards are needed.
Capacity building must be need-based, tailored to national priorities, and responsive to national capacities, respecting national sovereignty (Thailand) Capacity building must be demand-driven, nationally owned, sustainable, and responsive to nationally identified priorities rather than providing one-time assistance (Philippines) Capacity building must be demand-driven, sustainable, inclusive, and free from political conditionalities to bridge digital divides (Indonesia) Capacity building must be nationally owned, demand-driven, needs-based, sustainable, transparent, and free from conditionalities (Zimbabwe) Capacity building must be country-owned and needs-driven, with state-led assessments to ensure support is tailored and practical (Tuvalu) Capacity building must be practical, sustainable, and tailored to national circumstances, avoiding a one-size-fits-all approach (Suriname) Developing countries, particularly LDCs and post-conflict countries, need practical support to bolster their infrastructure, establish national cybersecurity centres, and launch sustainable long-term training programmes (Yemen)
All four speakers agreed that non-state actors have an important role in capacity building . However, they disagreed on the degree and nature of that role. The Netherlands called for 'meaningful and unimpeded participation' , suggesting a broad and unrestricted role. Kenya ICT Action Network went further, calling for systematic integration as 'active co-designers, co-creators, trainers, and evaluators' . FIRST framed it as 'shared responsibility' requiring 'stronger partnerships' . The Philippines, by contrast, qualified non-state contributions as complementary and explicitly subordinate to the 'state-led nature' of the mechanism , reflecting a more cautious position on the scope of non-state actor involvement.
The meaningful and unimpeded participation of the multi-stakeholder community is imperative to ensuring capacity building is implemented in an effective, pragmatic, and responsive manner (Netherlands) The private sector, industry, academia, and the technical community can complement national efforts by contributing operational knowledge and practical experience, consistent with agreed modalities and the state-led nature of the mechanism (Philippines) Civil society organisations, academia, and technical communities possess deep localised expertise and should be systematically integrated as co-designers, co-creators, trainers, and evaluators of capacity building programmes (Kenya ICT Action Network) Capacity building is a shared responsibility calling for stronger partnerships among states, private sector, civil society, and the technical community, with donors and implementers working together effectively (FIRST)
All speakers agreed on the importance of gender inclusion in cybersecurity capacity building . However, they approached it differently: Australia and the Netherlands framed it primarily through the Women in Cyber Fellowship as a specific programme ; Saudi Arabia emphasised its own national programme with a global reach of 67 countries ; the African Union Commission embedded gender equality within a broader development agenda linked to Agenda 2063 ; and Tuvalu spoke from the perspective of a beneficiary state for whom the fellowship was 'invaluable' . The shared goal of gender inclusion thus coexists with different framings — some donor-centric, some development-centric, some beneficiary-centric — that could lead to disagreements about programme design and governance.
Agreed
ThailandSaudi ArabiaNetherlandsAustraliaAfrican Union CommissionTuvalu
Contested
Thailand recognises the importance of gender-responsive capacity building programmes, highlighting the Women in International Security and Cyberspace Fellowship and the Women Thailand Cyber Top Talent Competition (Thailand) Saudi Arabia implements a specialised programme to train women in cybersecurity for leadership positions, with representatives from more than 67 countries having graduated (Saudi Arabia) The Netherlands expresses special appreciation for the Women in Cyber Fellowship coordinated by UNIDIR, encouraging all delegations to contribute to bridging the gender divide in the digital and cybersecurity workforce (Netherlands) Australia, together with Canada, Germany, New Zealand, the Netherlands, and the United Kingdom, supports the Women in Cyber Fellowship and notes that women delivered just over 50% of statements during the plenary session (Australia) The African Union Commission emphasises that capacity building must promote gender equality and give young Africans the knowledge and skills needed to become innovative actors in cybersecurity (African Union Commission) Tuvalu acknowledges the invaluable support of UNIDIR’s Women in Cyber Fellowship in enhancing participation in UN cyber discussions and strengthening national capacity in ICT security (Tuvalu)
All four speakers agreed that capacity building must be sustained over time rather than delivered through one-off interventions . However, they disagreed on the modalities: the Dominican Republic emphasised peer-to-peer networks and mentorship ; FIRST highlighted the structural problem of short-term funding cycles undermining long-term investment ; Interpol argued for embedding capacity building within operational cycles ; and Tuvalu called for remote and hybrid delivery modalities suited to geographic isolation . These different emphases reflect genuine disagreement about how sustained capacity building should be structured and delivered.
Agreed
Dominican RepublicFIRSTInterpolTuvalu
Contested
Capacity building programs are most effective when they combine sustained mentorship with networks of peer-to-peer cooperation rather than independent freestanding workshops (Dominican Republic) Capacity building must be locally driven, responsive to national priorities, and sustained over a longer period rather than through short-term interventions (FIRST) Capacity building results in sustainable operational capabilities when it is nationally owned, driven by identified needs, and tailored to the distinct responsibilities of relevant national actors (Interpol) Small island developing states face significant constraints including limited resources, geographic isolation, and high connectivity costs, requiring international support that is predictable, sustainable, and delivered through diverse channels including remote and hybrid training (Tuvalu)
Key Takeaways
Capacity building is universally recognised as the foundational enabler of all five pillars of the UN Framework on Responsible State Behaviour in ICTs, not merely a standalone agenda item, with consensus across all regional groups that without it, implementation of international law, voluntary norms, confidence-building measures, and institutional dialogue cannot be achieved effectively.
Effective capacity building must adhere to core principles: it must be demand-driven, nationally owned, needs-based, sustainable, transparent, inclusive, and free from political conditionalities or a one-size-fits-all approach, with programmes co-designed to reflect specific national and regional circumstances.
A wide range of national, regional, and international capacity building initiatives are already underway, including Saudi Arabia’s Global Cybersecurity Forum and UNITAR office in Riyadh, the ASEAN-Japan Cybersecurity Capacity Building Centre, the Dominican Republic’s LAC4 centre, INTERPOL’s operational capacity building model, and the OSCE’s international cyber diplomacy training, demonstrating that practical cooperation is already delivering results.
Gender inclusion has achieved a historic milestone in this first substantive session of the Global Mechanism, with women delivering 50% of the 324 statements made during the week, and programmes such as the Women in Cyber Fellowship coordinated by UNIDIR are credited as instrumental in achieving this progress.
India’s financial pledge to support the technical establishment and maintenance of the Global ICT Security Cooperation and Capacity Building Portal is a significant concrete development, enabling the Secretariat to proceed with portal development despite UN budgetary constraints.
The Dedicated Thematic Group on Capacity Building (DTG2) is widely seen as pivotal to the success of the Global Mechanism, with delegations calling for it to function as a genuine collaborative space focused on specialised, action-oriented discussions rather than repeating plenary debates.
The digital divide remains a critical concern, with developing countries, small island developing states, landlocked nations, LDCs, and post-conflict countries facing disproportionate constraints including limited resources, geographic isolation, and short-term funding cycles that undermine long-term capacity building investments.
Multi-stakeholder participation, including civil society, academia, the private sector, and the technical community, is recognised as essential to effective capacity building, with calls for these actors to be systematically integrated as co-designers and co-creators rather than peripheral contributors.
Coordination among existing capacity building initiatives is urgently needed to avoid fragmentation and duplication of efforts, with the Global ICT Security Portal identified as a potential tool for mapping activities and matching needs with resources.
The session concluded with a political exchange between Russia and Ukraine, with Russia condemning what it characterised as politicisation of the mechanism by the Italian delegation, and Ukraine reaffirming its right to self-defence under Article 51 of the UN Charter, highlighting ongoing tensions that risk undermining the cooperative spirit of the mechanism.
Resolutions & Action Items
The Chair will circulate a preliminary proposal for the organisation and agenda of the Dedicated Thematic Groups (DTG1 and DTG2) toward the end of August 2025, in close coordination with the co-facilitators, calling on all delegations to receive it with flexibility as a good faith basis for building the work structure.
The Secretariat will facilitate the creation of a roster of experts foreseen in Resolution A/80/257 with a view to forming a diverse and geographically balanced group of specialists to support DTG deliberations.
The Secretariat will work closely with India to develop the Global ICT Security Cooperation and Capacity Building Portal, with a more substantive update to be provided at future sessions; the initial proposal document is available as A-AC.292-2025-1.
The Chair will convey guiding questions ahead of each DTG meeting with sufficient advance notice and will communicate all relevant information through a note addressed to all delegations.
El Salvador will present to the First Committee the resolution endorsing the plenary session and the DTG deliberations, with the expectation that it will be adopted without a vote.
The DTG2 on capacity building is scheduled to meet from 7 to 11 December 2025, with the intersessional period running from the close of this session until that date.
Kuwait has proposed developing a voluntary scenario-based capacity building module on international law and ICT use within the global portal, and has indicated readiness to work with India to explore how its previously developed digital tool on voluntary non-binding norms could be technically aligned with the portal architecture.
The Chair will continue consulting with states on the modalities for the transmission and consideration of DTG outcomes at the 2027 plenary session, preserving decision-making under the principle of consensus.
Australia, Canada, Germany, New Zealand, the Netherlands, and the United Kingdom reaffirmed their ongoing support for the Women in Cyber Fellowship and encouraged all delegations in a position to do so to contribute to the programme.
The Dominican Republic offered to make available to DTG2 and other delegations its institutional and personal experience in capacity building, and indicated it would contribute actively to the working document to be put forward by the group of Latin American countries.
Thailand proposed that DTG2 prioritise discussions on advanced cyber threats including AI security, quantum readiness, post-quantum cryptography, and operational technology security, as well as assistance with national legal and policy frameworks.
Indonesia proposed that DTG2 focus on critical information infrastructure protection, cyber crisis management, and strengthening the capacity of CERTs and C-CERTs as priority capacity building areas.
Unresolved Issues
The precise structure, topics, and working methods of DTG1 and DTG2 remain to be defined, as there is no prior template to build on and the Chair acknowledged that the work structure does not yet exist and must be drafted collaboratively.
The modalities for the transmission and consideration of DTG outcomes at the 2027 plenary session have not yet been determined and remain under consultation.
The question of how to ensure sustainable, long-term funding for capacity building initiatives remains unresolved, with FIRST highlighting that funding is often limited to short-term project cycles and reporting requirements are increasingly complex and fragmented across donors.
The extent to which non-state actors, including civil society, academia, and the private sector, will be formally integrated into DTG processes and capacity building programme design remains unclear, given the state-led nature of the mechanism.
How the Global ICT Security Portal will evolve over time to meet the needs of states, including the potential integration of Kuwait’s digital tool on voluntary norms and a scenario-based module on international law, has not been determined and will require further technical and intergovernmental discussion.
The challenge of ensuring equitable access to capacity building for small island developing states, landlocked countries, LDCs, and post-conflict countries, given their specific constraints of geographic isolation, limited resources, and high connectivity costs, has been raised but no concrete funding or delivery mechanisms have been agreed.
The issue of political tensions within the mechanism, as illustrated by the exchange between Russia and Ukraine, raises unresolved questions about how the mechanism will manage politicisation and maintain a cooperative atmosphere conducive to substantive work.
How to measure the results and impact of capacity building initiatives, including through metrics for any voluntary fund, has been raised by the Dominican Republic but not agreed upon.
The question of how to avoid duplication and fragmentation across the many existing bilateral, regional, and international capacity building initiatives, and how the Global Mechanism will coordinate these efforts in practice, remains to be worked out.
The specific modalities for integrating gender-responsive approaches systematically across all capacity building programmes under the Global Mechanism have not been formally agreed, despite broad rhetorical support.
Suggested Compromises
The Chair proposed that delegations receive the preliminary DTG organisational proposal to be circulated in August as a serious, balanced, and good faith basis on which to begin building without delay, implicitly asking states to refrain from treating it as an opening position for exhaustive word-by-word negotiation, in order to make practical progress within the available intersessional time.
Kuwait suggested a modular, one-stop-shop approach to the Global Portal, whereby different components could address different needs, such as one component supporting practical implementation of voluntary norms and another facilitating capacity building on international law, thereby accommodating diverse state priorities without requiring agreement on a single unified design.
The Dominican Republic suggested that rather than duplicating functions across other areas, the overall portal should serve as a mapping tool to avoid fragmentation, implicitly proposing that existing initiatives be recognised and coordinated rather than replaced by new mechanisms.
The Netherlands suggested that the Global Mechanism should function not as a one- or two-way street but as a platform where ideas, needs, experiences, innovations, and resources all come together, implicitly proposing a multilateral and multi-directional model of cooperation as a middle ground between donor-recipient and purely intergovernmental approaches.
INTERPOL’s framing of capacity building as tailored to the distinct responsibilities of different national actors, using the football team metaphor of different players needing different training, implicitly suggested a compromise between universal standards and fully bespoke national programmes, advocating for role-specific but coordinated capacity building.
The Chair’s closing remarks implicitly proposed a procedural compromise by committing to preserve consensus as the guiding principle while asking delegations to exercise flexibility in the intersessional period, acknowledging that consensus cannot in practice become an endless negotiation over every word of an initial proposal.
“Capacity building is not a stand-alone pillar, but an enabler of all five pillars, strengthening the ability of states to implement international law, operationalise the voluntary norms, develop confidence-building measures, and participate effectively in regular institutional dialogue.”
“Asymmetries generate insecurity. Sustainable growth in cybersecurity will not be possible without the sustainable growth of a digital economy. Countries that do not have direct access to the maritime backbones of the Internet — 95% of the information on the web still passes through this — face significant challenges.”
“Kuwait proposed the development of a voluntary scenario-based capacity building module on international law and the use of ICTs within the global portal, containing a structured bank of neutral and hypothetical scenarios. The tool would organise voluntary views, clarify the reasoning behind different approaches, and help distinguish legal disagreements from differences arising from factual assumptions.”
“Instead of duplicating the functions across other areas, the overall portal should help us map activities to avoid fragmentation of international efforts. Capacity-building programmes work better when they combine sustained mentorship with networks of peer-to-peer cooperation, not just independent freestanding workshops.”
“For Suriname, this is becoming increasingly important as our emergent offshore oil and gas sector creates new opportunities for sustainable economic growth, while also expanding the need to protect critical infrastructure against evolving cyber threats. Strong cybersecurity is therefore essential to safeguarding our development and maintaining the confidence of citizens, partners, and investors.”
“Interpol’s main focus is on strengthening the capabilities of the law enforcement community. Our operation ramps provide a clear example: ahead of the operational phase, 13 countries from the Middle East and North Africa received specialised training, taking part in tabletop exercises focused on technical threats. Interpol then coordinated the participating countries in a joint operation against phishing and malware. Together, they arrested over 200 suspects linked to 3,867 identified victims.”
“Capacity building is not only an agenda item, it’s a mechanism to strengthen national security and to deliver concrete results. We need to move from words to actions. Developing countries, in particular LDCs and post-conflict countries, need practical support to bolster their infrastructure of control and surveillance.”
“The UN Global Mechanism should not be a one- or two-way street, but rather should act as a place where ideas, needs, experiences, innovations and resources all come together — a platform where all stakeholders can learn from each other and jointly shape solutions. The meaningful and unimpeded participation of the multi-stakeholder community is imperative to this aim.”
“The Russian Federation condemned what it described as ‘outrageous anti-Russian attacks’ from Italy, alleging that NATO members have created mechanisms to facilitate attacks against Russia’s information infrastructure, and accused some delegations of appearing ‘not to engage in professional dialogue, but to settle political scores and to reproduce propaganda clichés.’”
“Women delivered just over 50% of the statements during this plenary session. This continues the trend of gender parity that we have seen over the last final sessions of the OEWG and is a welcome indicator of the progress we have made over the years.”
How can capacity building be effectively structured to address advanced cyber threats including AI and security, quantum readiness, post-quantum cryptography, and operational technology security?
Thailand
Thailand proposed that DTG-2 on capacity building prioritise these specific areas, indicating a need for further research and structured discussion on how the global mechanism can address these emerging technological challenges in a practical and actionable way.
How can national legal and policy frameworks be strengthened through capacity building assistance, and what models of support are most effective?
Thailand
Thailand raised this as a priority area for DTG-2, suggesting that further exploration is needed on how international capacity building can best support states in developing their domestic legal and regulatory cybersecurity frameworks.
How can the Global ICT Security Cooperation and Capacity Building Portal be operationalised in a step-by-step modular approach, and what content and functions should it prioritise?
Multiple speakers referenced the portal as a key deliverable. The Secretariat confirmed it is under development with India’s financial support, but a full proposal is still pending. Further research is needed on its architecture, content, and how it can serve as a one-stop-shop for capacity building resources.
How can a voluntary scenario-based capacity building module on international law and the use of ICTs be developed within the global portal without duplicating existing tools such as UNIDIR scenario-based training, OSCE cyber diplomacy exercises, and the Tallinn workshop?
Kuwait
Kuwait proposed a specific digital tool containing hypothetical scenarios to help states understand how international law applies to ICT activities. Further research is needed on its design, methodology, governance, and how it complements rather than duplicates existing instruments.
How can Kuwait’s previously developed digital tool to support implementation of voluntary non-binding norms be technically aligned with the global portal architecture being operationalised with India’s support?
Kuwait
Kuwait expressed readiness to work with India to explore technical alignment of its existing tool with the portal. This raises questions about interoperability, technical standards, and governance arrangements that require further investigation.
How can capacity building initiatives be better coordinated to avoid fragmentation and duplication of international efforts, and what role should the global portal play in mapping existing activities?
Dominican Republic, Zimbabwe, FIRST
Multiple delegations highlighted the risk of fragmentation across the many existing capacity building programmes. Further research is needed on how a mapping function within the portal or DTG-2 could systematically catalogue and coordinate these efforts.
What metrics and evaluation frameworks should be used to measure the results and impact of voluntary capacity building funds and programmes?
Dominican Republic
The Dominican Republic explicitly called for metrics to measure results of any voluntary fund for capacity building. This points to a gap in current frameworks and a need for research into appropriate, agreed indicators of capacity building effectiveness.
How can capacity building programmes be designed to combine sustained mentorship with peer-to-peer cooperation networks rather than relying on standalone workshops?
Dominican Republic
The Dominican Republic drew on its experience to argue that programmes work better with sustained mentorship and peer networks. Further research is needed on how this model can be scaled and institutionalised within the global mechanism.
How can the global mechanism ensure that capacity building is genuinely demand-driven and nationally owned, rather than imposed through top-down or politically conditioned approaches?
Zimbabwe, Indonesia, Tuvalu, Kenya ICT Action Network, FIRST
Multiple delegations and civil society actors stressed that capacity building must be free from conditionalities and responsive to nationally identified priorities. Further research is needed on governance models and accountability mechanisms that ensure this principle is upheld in practice.
How can small island developing states and least developed countries access predictable, sustainable, and remotely delivered capacity building support given their geographic isolation, limited resources, and high connectivity costs?
Tuvalu, Suriname, Yemen
These delegations highlighted specific structural barriers faced by vulnerable states. Further research is needed on tailored delivery mechanisms such as micro-modules, hybrid training, and sustained mentorship that can reach these states effectively.
How can state-led needs assessments be systematically adopted to ensure that international capacity building support is tailored and practical for recipient states?
Tuvalu
Tuvalu strongly encouraged the adoption of state-led assessments as a prerequisite for effective support. Further research is needed on what standardised or flexible assessment frameworks could be developed and how they could feed into the global mechanism’s coordination functions.
How can regional organisations such as ASEAN, the African Union, CARICOM, SICA, and the Andean Community be better integrated as partners in translating global capacity building commitments into practical regional implementation?
Zimbabwe, Indonesia, African Union Commission, Philippines
Several delegations emphasised the indispensable role of regional bodies. Further research is needed on how the global mechanism can formally recognise and coordinate with these organisations without duplicating their work.
How can the Malabo Convention and the Common African Position on the Application of International Law in Cyberspace be used as frameworks to guide capacity building efforts on the African continent?
Zimbabwe, African Union Commission
Both delegations referenced these African frameworks as important foundations. Further research is needed on how they can be operationalised through capacity building and how they interact with the broader UN framework.
How can the Global Points of Contact Directory be further developed and expanded, and what role can future simulations play in strengthening both diplomatic and technical national points of contact?
Zimbabwe
Zimbabwe highlighted the directory as one of the most practical achievements of the OEWG and called for wider participation in simulations. Further research is needed on how to increase uptake, improve the directory’s functionality, and design effective simulation exercises.
How can capacity building for law enforcement communities be embedded throughout the operational cycle to address the industrialisation of cybercrime, including the criminal use of artificial intelligence?
Interpol
Interpol described its operational approach and highlighted the growing industrialisation of cybercrime as a challenge. Further research is needed on how law enforcement capacity building can be systematically integrated into the global mechanism’s framework, particularly for developing countries.
How can artificial intelligence be used responsibly in law enforcement and cybersecurity contexts, and what guidance frameworks are needed to govern its use?
Interpol
Interpol referenced its joint work with UNODC on AI guidance for law enforcement and its Project Horizon initiative. Further research is needed on how such guidance can be developed, disseminated, and incorporated into capacity building programmes globally.
How can capability maps and capability maturity models be applied to help member states prioritise and plan capacity building across government and the broader economy?
Future Earth Systems
Future Earth Systems proposed enterprise architecture frameworks as practical tools for capacity building planning. Further research is needed on how these models can be adapted to the diverse contexts of member states and integrated into the DTG-2 work programme.
How can non-state actors including civil society, academia, and the technical community be systematically integrated as co-designers, trainers, and evaluators of capacity building programmes within the global mechanism?
Kenya ICT Action Network, FIRST, Netherlands
These actors argued that cyber resilience cannot be built through state resources alone and that non-state expertise is essential. Further research is needed on governance modalities that allow meaningful non-state participation while preserving the state-led nature of the mechanism.
How can capacity building programmes be made more gender-responsive and inclusive, and what mechanisms can ensure women’s sustained participation in cybersecurity and international cyber policy processes?
Thailand, Saudi Arabia, Philippines, Netherlands, Australia, African Union Commission
Multiple delegations highlighted the gender gap in cybersecurity and welcomed programmes such as the Women in Cyber Fellowship. Further research is needed on how gender-responsive design can be mainstreamed across all capacity building initiatives and how progress can be measured.
How can the dedicated thematic group DTG-2 on capacity building be structured to add genuine value to the global mechanism, avoid repetition of plenary debates, and produce action-oriented outcomes?
Chair Egriselda López, Netherlands, Philippines, Indonesia
The Chair and several delegations stressed that DTG-2 must be focused and practical rather than duplicative. Further research and consultation are needed on the agenda, topics, working methods, and expected outputs of DTG-2 ahead of its December 2026 session.
How can the global mechanism support developing countries, least developed countries, and post-conflict states in building national cybersecurity infrastructure including CERTs, CSIRTs, and national cybersecurity centres?
Yemen, Zimbabwe, Suriname, Indonesia
These delegations highlighted the acute need for foundational infrastructure support. Further research is needed on what models of sustained technical and financial assistance are most effective for states at early stages of cybersecurity development.
How can capacity building address the specific cybersecurity risks associated with emerging economic sectors such as offshore oil and gas, and how can critical infrastructure protection be tailored to national development contexts?
Suriname
Suriname raised the specific challenge of protecting its emerging offshore energy sector from cyber threats. This points to a need for research on sector-specific capacity building approaches that align with national development priorities.
How can long-term training programmes of twelve months or more be designed and funded to build sustainable national capacity in cybersecurity, particularly for post-conflict and least developed countries?
Yemen
Yemen called for sustained training initiatives rather than short-term interventions. Further research is needed on funding models, programme design, and how such initiatives can be coordinated through the global mechanism.
How can the ASEAN Cybersecurity Cooperation Strategy for 2026-2030 serve as a model for other regions in designing tailored, long-term capacity building programmes that respect national priorities?
Indonesia
Indonesia highlighted ASEAN’s regional strategy as a valuable model. Further research is needed on how its lessons can be extracted, adapted, and shared with other regional groupings through the global mechanism.
How can the global mechanism’s voluntary fund for capacity building be designed to ensure transparent, inclusive, and results-oriented allocation of resources, including clear metrics for measuring impact?
Dominican Republic, Zimbabwe
Both delegations called for transparency and measurable results in any voluntary fund. Further research is needed on fund governance, eligibility criteria, reporting requirements, and how to balance donor priorities with recipient needs.
How can cyber diplomacy and cyber policy training be systematically incorporated into national diplomatic training programmes to ensure that all diplomats have foundational competencies in ICT security issues?
Dominican Republic
The Dominican Republic described its experience of embedding cyber diplomacy in permanent specialist master’s training. Further research is needed on how this model can be replicated and supported through the global mechanism for states with limited training infrastructure.
How can the OSCE’s model of translating confidence-building measures into practical capacity building workshops be adapted and shared with other regional organisations and the global mechanism?
OSCE
The OSCE described a decade of experience linking CBMs with capacity building. Further research is needed on how these methodologies, including tabletop exercises and international law workshops, can be scaled and made available to a broader set of states.
How can capacity building support states in developing national positions on the applicability of international law in cyberspace, and what tools can help distinguish legal disagreements from factual misunderstandings?
Kuwait, OSCE
Both Kuwait and the OSCE highlighted the challenge of deepening common understanding of how international law applies to ICT activities. Further research is needed on pedagogical tools, scenario-based exercises, and intergovernmental processes that can advance this understanding without prejudging legal outcomes.
Disclaimer: This is not an official session record. DiploAI generates these resources from audiovisual recordings, and they are presented as-is, including potential errors. Due to logistical challenges, such as discrepancies in audio/video or transcripts, names may be misspelled. We strive for accuracy to the best of our ability.
The eighth meeting of the Global Mechanism on ICTs in the Context of International Security focused on capacity building as a foundational pillar for implementing the framework for responsible state behaviour in cyberspace . Chair Egriselda López noted 49 speakers had requested the floor, reflecting the topic’s importance, and urged delegations to manage their time carefully .
A broad consensus emerged across regional groupings that capacity building is an essential precondition for all states to implement agreed norms, with many delegations stressing that cyber threats respect no borders and that collective security depends on closing capability gaps between developed and developing nations . Delegations consistently called for capacity building to be demand-driven, nationally owned, sustainable, inclusive, and tailored to each state’s specific context, explicitly rejecting one-size-fits-all approaches . Several speakers, including Malawi and Rwanda, emphasised that for developing countries the challenge is not a lack of political will but a lack of resources, technical expertise, and sustained support .
Concrete institutional proposals featured prominently. India announced it would fund the full operationalisation of the Global ICT Security Cooperation and Capacity Building Portal , while multiple delegations welcomed the UN Voluntary Fund and the dedicated Thematic Group 2 (DTG2) as vehicles for translating political commitments into practical action . The Russian Federation proposed UN-auspiced cyber-attack response drills , and Switzerland highlighted efforts to establish a community hub in Geneva following the closure of the Global Forum on Cyber Expertise .
Gender inclusion and fellowship programmes received strong endorsement, with delegations from Kiribati, Bahamas, Ghana, Albania, and others crediting the Women in International Security and Cyberspace Fellowship with enabling their participation in the session . Small island developing states, particularly from the Pacific, drew attention to practical barriers such as time-zone disadvantages and the need for hybrid participation to be genuinely equitable .
The discussion concluded with broad agreement that DTG2 should deliver concrete, measurable outputs – including needs mapping, matchmaking between assistance and recipients, and sustainable financing – and that the success of the global mechanism will ultimately be judged by whether it strengthens the real-world cyber resilience of every member state .
Keypoints
Overall Purpose
The discussion is the eighth meeting of the 2026 substantive plenary session of the Global Mechanism on Developments in the Field of ICTs in the Context of International Security. The specific agenda item under discussion is developing and implementing capacity building measures in the field of ICT security. Delegations from across the globe are sharing national experiences, articulating priorities, and making recommendations for how the newly established global mechanism – particularly its Dedicated Thematic Group 2 (DTG2) – should approach cyber capacity building to ensure all states can meaningfully implement the framework for responsible state behaviour in cyberspace.
—
Major Discussion Points
Capacity building as a foundational and cross-cutting pillar of the framework for responsible state behaviour. Numerous delegations emphasised that without adequate technical, institutional, legal, and human capacities, all other pillars of the framework – norms, international law, and confidence-building measures – cannot be effectively implemented. Capacity building was described not as optional assistance but as a prerequisite for meaningful participation, particularly for developing countries and small island developing states.
The principle that capacity building must be demand-driven, nationally owned, tailored, and sustainable. A strong consensus emerged that capacity building should reflect the priorities identified by recipient states themselves, avoid one-size-fits-all approaches, and produce lasting institutional resilience rather than short-term training outputs. Delegations repeatedly stressed that single workshops do not build institutions, and that long-term, sustained partnerships are essential.
The role of the UN Voluntary Fund, the Global ICT Security Cooperation and Capacity Building Portal, and the UN fellowship programmes in operationalising capacity building. Multiple delegations welcomed the establishment of these mechanisms and called for their swift operationalisation. India announced it would provide full funding for the portal’s technical development. Iran proposed that the voluntary fund be treated as a first priority for DTG2. The Women in International Security and Cyberspace (WIC) Fellowship was widely praised, with several delegates – including from Kiribati, Albania, Botswana, Ghana, and the Bahamas – personally acknowledging it as transformative for their participation.
The digital divide and the particular challenges faced by developing countries, small island developing states, and the Global South. Many delegations highlighted that the gap between developed and developing states in cyber capabilities is a systemic vulnerability for the entire digital ecosystem. Delegations from the Pacific Islands, Africa, Latin America, and the Caribbean described concrete resource constraints, limited personnel, and the difficulty of sustaining reforms without predictable international support. Kiribati’s delegation poignantly noted that even meeting times create inequitable burdens for small Pacific states.
The structure, mandate, and expected outputs of DTG2, and the importance of avoiding duplication while building on existing initiatives. Delegations called on DTG2 to move beyond dialogue towards practical, measurable, and action-oriented outcomes, including needs mapping, matchmaking between needs and available resources, and the development of concrete implementation guidance. Several delegations stressed that DTG2 should complement rather than duplicate existing regional and bilateral efforts, and that its work should be coordinated with DTG1 to ensure capacity building responds to identified implementation challenges.
—
Overall Tone
The overall tone of the discussion was constructive, collaborative, and largely consensual, with a strong undercurrent of urgency from developing and small island states. Delegations across all regions expressed genuine commitment to advancing capacity building and showed considerable alignment on core principles such as national ownership, demand-driven approaches, sustainability, and inclusivity.
There were moments of political tension, particularly when Italy , Ukraine , and the Russian Federation addressed the conflict in Ukraine, with Italy and Ukraine referencing Russian cyber aggression against civilian infrastructure and the Tallinn Mechanism, while Russia presented its own capacity building initiatives and called for depoliticised cooperation. Cuba and Iran also introduced a more critical note, calling for the removal of unilateral coercive measures that restrict ICT access for developing states .
Switzerland introduced a note of institutional concern, expressing regret at the exclusion of non-governmental stakeholders from the global mechanism and warning that this limits the practical expertise available to DTG2 .
Despite these tensions, the session maintained a predominantly positive and forward-looking character, with many delegations expressing personal gratitude for fellowship programmes and reaffirming their commitment to working constructively within the new mechanism. The tone grew increasingly warm and personal towards the end of the session, with several delegates – including from Kiribati , Marshall Islands , and Tonga – delivering particularly moving statements about what capacity building means in practice for the smallest and most vulnerable states.
Speakers Overview
RO
Republic of Korea
136 wpm · 2 min
N
Naoero
128 wpm · 3 min
I
Israel
124 wpm · 4 min
DR
Democratic Republic of the Congo
119 wpm · 5 min
B
Brazil
127 wpm · 4 min
M
Mexico
130 wpm · 2 min
C
Canada
123 wpm · 3 min
J
Japan
113 wpm · 2 min
B
Botswana
112 wpm · 4 min
RF
Russian Federation
146 wpm · 6 min
R
Rwanda
111 wpm · 4 min
E
Ecuador
85 wpm · 4 min
T
Tonga
140 wpm · 3 min
G
Guyana
184 wpm · 2 min
B
Bahamas
103 wpm · 6 min
C
Cameroon
126 wpm · 5 min
M
Mauritius
141 wpm · 4 min
I
Italy
127 wpm · 6 min
MI
Marshall Islands
158 wpm · 2 min
U
Uruguay
124 wpm · 3 min
I
India
168 wpm · 4 min
S
Switzerland
134 wpm · 5 min
BA
Bosnia and Herzegovina
126 wpm · 3 min
G
Germany
142 wpm · 4 min
C
China
99 wpm · 4 min
SA
South Africa
118 wpm · 2 min
A
Australia
146 wpm · 4 min
F
France
93 wpm · 3 min
S
Serbia
113 wpm · 2 min
V
Vanuatu
129 wpm · 3 min
G
Ghana
93 wpm · 4 min
S
Singapore
137 wpm · 3 min
G
Guatemala
141 wpm · 3 min
I
Ireland
138 wpm · 2 min
NZ
New Zealand
141 wpm · 2 min
A
Argentina
167 wpm · 4 min
C
Cambodia
100 wpm · 7 min
K
Kiribati
137 wpm · 6 min
A
Albania
121 wpm · 7 min
CD
Cote d'Ivoire
105 wpm · 4 min
U
Ukraine
152 wpm · 4 min
M
Malawi
126 wpm · 5 min
IR
Islamic Republic of Iran
126 wpm · 4 min
CE
Chair Egriselda López
135 wpm · 9 min
C
Cuba
125 wpm · 4 min
M
Malaysia
119 wpm · 3 min
Expanded Summary: Eighth Meeting of the 2026 Substantive Plenary Session – Developing and Implementing Capacity Building Measures
#
Opening and Procedural Context
Chair Egriselda López opened the eighth meeting of the 2026 substantive plenary session of the Global Mechanism on Developments in the Field of ICTs in the Context of International Security by calling the session to order and directing delegates to the final agenda item: developing and implementing capacity building measures . Noting that 49 delegations had requested the floor – a figure she described as reflecting the importance and relevance of the topic – the Chair urged speakers to consider delivering shorter oral statements and submitting full versions as e-statements to the Secretariat . A clock was displayed on screen to assist with time management . The volume of requests for the floor was itself a signal of the centrality of capacity building to the membership’s concerns, a theme that would be reinforced throughout the session [S194].
—
#
Capacity Building as the Foundational Pillar of the Framework
A near-universal consensus emerged across all regional groupings that capacity building is not a secondary or optional element of the framework for responsible state behaviour in cyberspace but its essential prerequisite. Cote d’Ivoire, aligning with the African Group, stated that for many states capacity building remains “the essential precondition for implementing the framework for the responsible behavior of states in the use of ICTs,” noting that digital transformation simultaneously opens immense prospects for development and increases exposure to cyber attacks, disruptions of essential services, and digital fraud . Critically, Cote d’Ivoire argued that “security collective cannot rest on national capacities, which are deeply unequal,” and that the digital environment requires resilience even from states with limited resources .
South Africa reinforced this framing, maintaining that capacity building is “a cross-cutting issue on the pillars of the global mechanism” and that member states remain at varying levels of implementation due to differing contexts and capabilities . Malawi elevated the argument further, stating that “if the cumulative and evolving framework represents our shared vision for responsible state behavior in cyberspace, then capacity building is what makes that vision achievable,” and insisting that it should be understood not as assistance from some states to others but as “a shared investment in international peace and security” . Rwanda similarly concluded that without the necessary institutions, legal frameworks, technical expertise, and skilled professionals, “commitments cannot be implemented, norms cannot be operationalised and resilience cannot be strengthened” .
Australia drew on the accumulated experience of the OEWG and GGEs to make the same point with particular clarity: “Norms, law and confidence building measures don’t implement themselves. People implement them. Institutions implement them. Capability implements them” . Cameroon stated that “a framework without capacity remains an aspiration. Norms without the ability to implement them remain commitments. And cooperation without shared capabilities cannot deliver lasting results” . Cameroon also grounded this argument in a long-standing African understanding “that the strength of a community is measured by its ability to uplift and empower all its members.” This framing – that capacity building is the operational bridge between political commitment and practical implementation – was echoed by virtually every delegation that took the floor [S196][S197].
—
#
Core Principles: Demand-Driven, Nationally Owned, Sustainable, and Inclusive
Alongside the foundational argument, an equally strong consensus emerged on the principles that should govern effective capacity building. Delegations consistently called for approaches that are demand-driven, nationally owned, tailored to the specific circumstances of recipient states, and sustainable over time, explicitly rejecting one-size-fits-all models [S198][S199].
Cote d’Ivoire stated that capacity building “must be voluntary, inclusive, sustainable, transparent, and based on the needs expressed by the beneficiary states themselves” and “must take into account local realities and produce measurable results” . South Africa called for efforts guided by the capacity building principles encapsulated in paragraph 56 of the 2021 OEWG final report . Malawi argued that capacity building “must therefore remain demand-driven, tailored to national priorities, and responsive to the different levels of development and capacities of member states,” and should “promote self-sufficiency by enabling states to develop enduring institutions, skilled professionals, and resilient national partners rather than creating long-term dependency” .
Cambodia articulated a comprehensive set of principles, stating that capacity building must be “demand-driven, tailored to national circumstances, and grounded in national ownership,” as well as “sustainable and results-focused,” “evidence-based, politically neutral, transparent and accountable, and provided without conditions” . Korea stated that capacity building “should not be driven solely by the priorities of providers or follow a one-size-fits-all approach” but should be “demand-driven and tailored to the specific needs and priorities of recipient states,” and emphasised that unnecessary duplication of existing capacity building efforts should be avoided in favour of enhanced coordination, complementarity, and efficient use of available resources . Germany argued that capacity building initiatives are “most successful when implemented through a co-creation approach, whereby donor and recipient states collaborate closely to jointly design, develop, and implement programs based on the UN principles for cybercapacity building” .
The principle of sustainability received particular emphasis. Kiribati stated plainly that “a single training builds a memory. It does not build an institution” . Tonga provided a concrete national illustration, noting that the response to a cyber attack on its health system succeeded “because the relationships and capabilities behind it had been invested in over years and not weeks” . Nauru warned that “support delivered in fragments leaves fragments behind” and called for capacity building that is “cumulative, each engagement building on the last, developing our own people rather than substituting for them, and lasting beyond any single project cycle” .
—
#
The Digital Divide and the Particular Challenges of Developing and Small Island States
Many delegations highlighted the structural inequality between developed and developing states in cyber capabilities as a systemic vulnerability for the entire digital ecosystem [S163]. Malawi stated that “for developing countries, however, the challenge is often not lack of commitment, but a lack of resources, expertise, and opportunities to translate political commitments into operational capabilities” . Rwanda echoed this, noting that “in many developing countries the challenge is no longer or not a lack of commitment. It is a lack of resources, technical expertise and opportunities to build national capacities” .
Brazil framed the digital divide as rendering international cooperation “an urgent imperative in order to expand the capacity of states to force their resilience, mitigate risks, and respond to ICT incidents” , and argued that “no country can tackle threats in the digital domain in isolation, and vulnerability left unaddressed in one state is a vulnerability available to be exploited against all” . Cuba described “the vast, gaping digital divide and the enormous economic difficulties faced by developing countries” as placing them in a position of asymmetry in preventing, detecting, and tackling ICT threats .
Pacific Island states offered some of the most vivid and analytically precise accounts of what resource constraints mean in practice [S204][S205][S207]. Nauru, with a population of 12,000, stated that “political will is not a scarce resource. Capacity is. A committed small state can draft the laws, set the strategies, and design the institution. What it cannot do alone is staff them, sustain them, and grow the expertise they require” . Kiribati described how each of its national cybersecurity achievements – its strategy, its maturity assessment, its digital government project – “was years of work for a very small number of people” . The Marshall Islands, making its first-ever intervention in this process – having not previously spoken at the OEWG – described how digital connectivity is “the difference between a family divided by the ocean and one able to speak across it,” but that “the very connection that can lift a remote nation can also expose it,” and that “the smallest and most distant among us have the least to fall back on when it does” . The Marshall Islands delegate closed with the Marshallese word “Komoltada” – thank you – a detail that humanised the intervention.
Vanuatu offered a counterpoint that was equally powerful: testifying that “two decades of sustained national investment supported by genuine partnerships have given Vanuatu the strongest cyber security standing in our region by international assessment,” it argued that “the return on well-designed capacity building is measurable, and sceptics of this pillar should study the Pacific before doubting it” . This evidence-based framing reinforced the broader argument that sustained, country-owned investment produces results [S200].
—
#
Gender Inclusion and the Women in International Security and Cyberspace Fellowship
Gender inclusion emerged as one of the most consistently endorsed themes of the session, with delegations across all regions affirming that it is a substantive component of effective capacity building rather than an afterthought. Malawi stated that “inclusive cybersecurity is stronger cybersecurity” and that “when women participate fully as policymakers, technical experts, incident responders, diplomats, and leaders our institutions become more resilient and our responses more effective” . Brazil argued that ensuring women and persons from marginalised populations are included in the ICT security workforce “should be treated by the DTG2 as a substantive component of capacity building rather than an afterthought” . Botswana reinforced that “all capacity-building efforts must systematically adopt a gender-sensitive perspective, and that true cyber resilience cannot be achieved while a gender-digital divide persists” .
The Women in International Security and Cyberspace (WIC) Fellowship received particularly strong and personal endorsement from delegations across different regions and development levels. Malawi commended UNIDIR and sponsoring states for the fellowship and welcomed the launch of UNIDIR’s Compendium of Good Practices on Gender Mainstreaming in Cybersecurity . Canada stated that it proudly contributes to the WIC Fellowship and supported the Compendium of Good Practices on Gender Equality and Cybersecurity, noting that “gender responsive approaches can strengthen cyber resilience, improve governance, and contribute to more sustainable capacity building outcomes” . Switzerland observed that the fellowship demonstrates “this added value concretely, supporting diplomats in bringing their expertise and perspectives directly into this room” .
Several delegates offered personal testimony about the fellowship’s transformative impact. Kiribati stated that two of its three-person delegation were present through the WIC Fellowship and one through the UN Sponsorship Programme, and that “not one of us will be in this room without those programs,” drawing a sharp distinction: “The training is not incidental to the travel. It is what turns attendance into participation” . Tonga expressed gratitude to UNIDIR and donor partners for allowing its small nation to participate in the fellowship, which “greatly assisted us and has also allowed our small delegation to participate in this substantive plenary session” . Albania acknowledged participating in the session as part of the WIC Fellowship, made possible through the support of the Netherlands, describing it as “a strong community of women whose expertise and engagement contributes meaningfully to the United Nations discussions on cybersecurity” . Bosnia-Herzegovina’s delegate noted that her presence at the session “reflects our strong commitment to women’s leadership and equal representation in cyber diplomacy.” Ghana’s delegate noted that she is herself a WIC fellow , and the Bahamas shared that participation in the WIC programme over the previous two weeks demonstrated that “sustained investment in people creates lasting national and international impact” . Ghana also highlighted the “HESCYBER Tract” as an initiative that has expanded opportunities for women from developing countries.
—
#
National Experiences and Concrete Capacity Building Efforts
A significant portion of the session was devoted to delegations sharing national experiences, which collectively illustrated both the diversity of approaches and the common challenges faced across different contexts.
Cote d’Ivoire described strengthening its institutional architecture through the National Agency for Information Systems Security and working to develop sectoral incident response mechanisms and train staff . Malawi outlined a comprehensive national programme including child online protection training for teachers across all education divisions, university cyber drills, women in cyber initiatives, and specialised technical training through the national CERT . Albania reported delivering over 50 activities targeting professionals, the public and private sector, and vulnerable groups including persons with disabilities, the Roma community, visually impaired individuals, and elderly people, with over 7,700 participants in the previous year alone .
India highlighted its bilateral practice through the Indian Technical and Economic Cooperation Programme, through which “in the last five years alone, we have offered close to 50,000 fully funded training opportunities to professionals from Global South countries, spanning nearly 400 courses at over 100 premier Indian institutions, with a substantial and growing share dedicated specifically to ICT, cybersecurity, e-commerce and the development of new technologies” . Mauritius noted that it hosts one of the ITU Global Academy Training Centres, where dedicated training programmes on cybersecurity norms and CBMs have been conducted annually since 2021, attended by over 20 countries, and extended an open invitation for member states to register on the ITU Academy portal for future trainings .
Nauru described advancing “our most ambitious cyber and digital reform program in our national history,” with a cybersecurity bill in the final stages of government consideration, alongside a digital transformation bill and data protection bill, and national cybersecurity and child online protection strategies being developed in parallel with ITU assistance . Ecuador described developing a national cybersecurity policy for 2026-2029 with seven pillars, one of which is linked to international cooperation and cyber diplomacy, incorporating emerging technologies such as AI, quantum computing, and the Internet of Things . The Bahamas described the formal launch of CertBS, its National Computer Incident Response Team, in December 2023, and reinforced the lesson that “capacity building is more effective when it’s tailored to the reality of the recipient” . The Bahamas also highlighted specific national programmes including its annual cybersecurity conference, the CyberShark Capture the Flag competition (referred to in the transcript as “Capture the Fly”), a national cyber hygiene school roadshow, and targeted training for policymakers, women, and youth.
Guyana supported both the UN Voluntary Fund and the capacity building portal, and noted that it had recently joined the Latin American Caribbean Cyber Competency Centre (LAC4) . The Democratic Republic of the Congo described its national digital plan comprising 69 priority projects across four pillars including infrastructure and governance, which led to the establishment of an agency for digital technologies, the ratification of a digital code, and the development of a national cybersecurity strategy. Serbia highlighted its distinctive dual role as both a beneficiary of international cooperation and capacity building programmes and an contributor to regional cooperation in South-East Europe, including through the exchange of expertise, joint exercises, and cooperation between national CERTs.
Ireland expressed support for the further development of a digital tool for state implementation of the UN framework, building on the voluntary norms implementation checklist – a concrete proposal for the DTG2 agenda. Singapore announced that it would run the seventh iteration of the United Nations Singapore Cyber Fellowship (UNSCF) the following month, reflecting its sustained commitment to multilateral capacity building .
—
#
Key Institutional Proposals: The Voluntary Fund, the Portal, and Fellowship Programmes
Several concrete institutional mechanisms received broad support across the session. The UN Voluntary Fund for ICT Security Capacity Building was widely endorsed as a priority. South Africa stated that it looks forward to further discussions on the development and operationalisation of the fund . Malawi welcomed its establishment, noting that for many developing countries “meaningful participation in this process depends not only on political will, but also on all the availability of practical support” . Iran argued that advancing the fund “should be one of the first priorities of the DTG-2,” citing paragraph 58 of the OEWG final report as the agreed basis for this . Guyana supported both the fund and the portal .
The most significant announcement of the session came from India, which revealed that it will “be providing the entire funding towards the operationalization of this portal as a portal of the United Nations, so that concrete, tangible action can finally follow years of discussion” . India noted that the proposal for the portal was originally an Indian initiative first tabled in 2022 and was ultimately endorsed by the General Assembly through Resolution 80-16 . India described the portal as comprising “a repository of resources, a capacity-building calendar, a needs-based catalogue of opportunities, and an interactive discussion board,” with CERT India undertaking the technical consultancy work required for the portal’s testing and infrastructure development . India emphasised that it sees “genuine and lasting value in this portal if properly used and populated by member states with actionable needs-based information” and believes it can “play a meaningful role in bridging the capacity gap that continues to separate developed and developing states in the domain of ICT security provided it is treated by all of us as a living tool rather than a static repository” .
The Russian Federation formally presented an initiative to conduct drills on responding to computer attacks under UN auspices, describing “real-time virtual competitions among national teams on a training base provided by the operator, during which they will simulate responding to various types of malicious activities in accordance with a pre-prepared scenario,” with technical and diplomatic points of contact from the UN Global Intergovernmental Points of Contact Directory also participating . Russia stated that it plans to work with the UN Secretariat on implementation with its own financial, organisational, and methodological support , and noted existing experience from exercises held on the margins of the signing of the UN Convention against Cybercrime in Hanoi in 2025, as well as on the margins of the Digitalization of Industrial Russia Conference in Nizhny Novgorod and the ICT Crime 2026 Conference in St Petersburg . Russia also described its universities as offering training to students from Asia, Africa, the Middle East, and Latin America in specialisations including information and computer security, methods for detecting and countering network computer attacks, methods and techniques for protecting information from unauthorised access, open source intelligence gathering, countering ICT crime, techniques for investigating ICT-related crimes, international cooperation in this area, and computer forensics. Russia further invited all partners to participate in three upcoming events: the Global Digital Forum in Moscow (8-10 October), Kazan Digital Week (September), and the 20th International Forum Partnership of State Business and Civil Society in Ensuring International Information Security in Moscow (22-24 September).
Switzerland announced that the Geneva Centre for Security Sector Governance (referred to in the transcript as DKEF) has entered into partnership with Switzerland to host a community hub designed to carry forward the coordination and multi-stakeholder engagement functions previously performed by the Global Forum on Cyber Expertise (GFCE), which has ceased operations . The hub was announced during Geneva Cyber Week in May 2026. Switzerland described the hub as adopting “a for the community by the community approach” that will “facilitate continued coordination, multi-stakeholder engagement and the development of sustainable governance models for cyber capacity building” , drawing on the rich ecosystem of international Geneva including UNIDIR, ITU, and the Diplo Foundation .
China announced, at the 2026 International AI Conference, the formation of an international AI cooperation organisation composed of 29 founding member states, and committed – through President Xi Jinping’s announcement – to providing 5,000 AI fellowships to developing countries over the next five years to support international AI development and capacity building .
—
#
The Dedicated Thematic Group on Capacity Building (DTG2): Mandate and Expected Outputs
The Dedicated Thematic Group on Capacity Building (DTG2) was widely described as one of the most important innovations of the new global mechanism, with its December 2025 meeting characterised as the first real test of whether the mechanism can convert discussion into delivery [S210]. Malawi called on the thematic groups to “become platforms where member states openly exchange experiences, identify common challenges, showcase successful practices, and develop practical recommendations that support implementation across all five pillars of the framework” . Tonga stated that it “warmly welcomes the establishment of the dedicated thematic group on capacity building, and we see the December meetings as the first true test of whether this mechanism can convert deliberation into delivery” .
Kiribati asked that the December meeting focus on “concrete, measurable outputs: mapping needs against what already exists, developing tools states can actually use, and identifying sustainable financing” . Vanuatu articulated three specific outputs it hopes the DTGs will deliver: “an honest global mapping of needs against provision, exposing the mismatches that everyone suspects and nobody has documented, a capacity-building portal shaped around how officials in recipient states actually work, and credible progress on financing that does not evaporate with the next budget cycle” . Nauru called on DTG2 to provide “a clear picture of where needs and existing support do and do not meet” and “a capacity building portal designed for the official with 10 minutes to spare, not the ministry that is equipped with a dedicated research team” .
Brazil argued that DTG2’s work “should not start from scratch” but should “build upon the experience accumulated in the previous process, including activities such as the 2024 Global Roundtable on ICT Security Capacity Building and the mapping exercise carried out by the Secretariat” . Iran proposed that proposals on capacity building from the first and second OEWGs be consolidated into a single compilation prepared under the Chair’s authority to serve as the basis for focused discussions within DTG2 , and also called for specific reference to paragraph 53b of the OEWG Final Report regarding the UN-Singapore Cyber Fellowship Programme. Argentina called for DTG2 to have “a technical and results-oriented focus” and to play “a central role in developing recommendations and draft concrete, practical, action-oriented decisions aimed at being elevated formally to consideration by the plenary” .
Several delegations addressed the relationship between DTG1 and DTG2. France argued that “the discussions within the dedicated thematic group one should therefore provide a basis for guiding the work of the dedicated thematic group number two, ensuring a fruitful dialectic between these two” , and called for the topics of the thematic groups to be selected as soon as possible to allow countries to nominate experts and prepare substantive contributions . Malaysia similarly saw “real value in ensuring closer alignment between the DTGs” so that if states continue to highlight difficulties in implementing norms, capacity building activities should respond directly to that need . Mexico, however, explicitly stated that “DTG2 has its own mandate for accelerating capacity building in the area of ICT security and therefore its work should not be understood as being subordinate to or conditioned by the first Dedicated Thematic Group” .
—
#
The Role of the UN and the Global Mechanism in Coordinating Capacity Building
A recurring theme was the appropriate role of the United Nations in leading, coordinating, and implementing capacity building efforts, with delegations articulating distinct and sometimes divergent positions. Brazil argued that “the United Nations must play a larger role in capacity building on ICT security” and that “centralizing information on the many existing initiatives would facilitate access by those who need them most” . Iran argued more forcefully that “the role of the United Nations should extend beyond merely coordinating and matchmaking capacity building initiatives undertaken by other actors” and that “existing capacity building initiatives outside the United Nations should complement and support the work of the UN, not the other way around” – a position that places the UN in a leading rather than merely facilitative role. Israel offered a complementary but distinct perspective, arguing that “the global mechanism must also serve as an effective coordinator” by “mapping national needs, sharing best practices, and matching requirements with available resources” rather than “reinventing the wheel or duplicating already successful capacity building frameworks” .
Australia described the challenge as “not a lack of goodwill, expertise or programs” but rather “how to bring together a mature but fragmented ecosystem of states, regional organisations, international organisations, development partners, industry, academia and civil society and turn it into something greater than the sum of its parts” .
Switzerland introduced a note of institutional concern, expressing regret at “the wide-range veto against stakeholder participation in the global mechanism,” arguing that “stakeholders are not observers of capacity building. They are among its principal implementers and knowledge holders. Excluding them does not protect the intergovernmental character of this process. It deprives it of the very expertise that DTG2 was created to mobilise” . Japan similarly called for “securing the participation and proposals of a wide range of stakeholders, including the private sector” in DTG2 . Ukraine, however, expressed reservations about “government-sponsored entities” among stakeholders whose “primary purpose is to explain their government’s position,” arguing that “governments should explain their position themselves” in plenary sessions . Ukraine also noted that it “did not exercise the right of veto this time, although we have our reservations” regarding stakeholder participation in the DTGs – a significant procedural statement reflecting the contested nature of this question.
—
#
Regional Cooperation and the Role of Regional Organisations
There was strong consensus that regional organisations and regional cooperation mechanisms are essential partners in capacity building and should be actively leveraged by the global mechanism [S202]. Cote d’Ivoire recommended strengthening “the role of the African Union Regional Economic Commissions and the African Training Centers so that assistance is adapted to national and sub-regional contexts” . Botswana maintained that “the global mechanism must work hand-in-hand with regional and sub-regional bodies to roll out capacity-building initiatives,” noting that these organisations “understand the unique political and physical challenges of their member states very well” .
Australia argued that “the most successful capacity building is often regional, built on shared experiences, shared challenges and shared trust” and that DTG2 “should actively amplify regional initiatives, not because regional work is an alternative to global cooperation, but because it’s one of the strongest foundations for it” . Singapore described its capacity building programmes working with Pacific Island Forum member states and ASEAN, including the first workshop for Pacific Islands Forum and ASEAN member states conducted under the Singapore Cyber Leaders Programme in December of the previous year . Japan described providing “multi-layered and comprehensive assistance through practical exercises conducted by the Japan ASEAN Society for Cybersecurity Capacity Building Center” and hosting the Industrial Control Systems Cybersecurity Week for the region annually . Ghana welcomed the continued emphasis on South-South, triangular, and regional cooperation as valuable complements to North-South partnerships .
Vanuatu stated that the Joint Pacific Islands Forum paper on capacity building submitted to the OEWG “remains Vanuatu’s reference point for this pillar” and asked that the mechanism treat it “as a standing Pacific input to its capacity-building agenda” . New Zealand similarly recommended the Pacific Islands Forum working paper to the mechanism and described its own capacity building efforts as focused in the Pacific region, including building CERT capabilities, developing national cybersecurity strategies, and supporting public awareness campaigns .
—
#
Co-creation, Multi-stakeholder Approaches, and Partnerships
Several delegations identified co-creation – the joint design, development, and implementation of capacity building programmes by donors, implementers, and recipient states – as a best practice model. Germany described the Western Balkan Cyber Diplomacy Network, jointly established with Western Balkan partners in May 2025, as an illustration of this approach, guided by designated focal points from Ministries of Foreign Affairs who jointly identify regional priorities and decide on initiatives , explicitly acknowledging Singapore and Canada’s prior mentions of co-creation in the same session. Singapore proposed developing “a co-creation model that places national priorities at the center, leverages regional coordination as the primary platform for needs identification and consolidation, and uses international mechanisms to facilitate visibility, coordination and partnerships” .
Canada offered a memorable analogy to illustrate the co-creation model: “the beneficiaries of capacity building are the players on the fields they are the ones who are living the match and who know where the gaps are. Non-governmental stakeholders are the coaches. Donor countries for their part are the supporters or fans who fund the coaches and follow the score closely. Co-creation means making sure that these three players are talking about the same match before deciding how to play it” . Canada also highlighted its support for UNIDIR’s work in a multi-year project involving eight countries – Thailand, Vietnam, Indonesia, Malaysia, Laos, Cambodia, Pakistan, and the Philippines – that brings together government entities, academia, civil society, and the private sector .
Mexico proposed moving away from traditional donor-beneficiary categories towards “an approach that recognises the providers of assistance for capacity building,” arguing that this “would foster more horizontal, inclusive and needs-based cooperation that is based on the needs expressed by states themselves” . This reframing – that all states can contribute knowledge, experience, and good practices according to their capacities – was consistent with India’s emphasis on South-South cooperation and its own role as a provider of capacity building to the Global South .
—
#
Geopolitical Tensions and Contested Issues
Beneath the broadly cooperative atmosphere, several significant fault lines emerged. Italy explicitly referenced the Tallinn Mechanism as “a platform of countries that since 2023 has been providing civilian cyber support to Ukraine as the latter endures the ongoing unjustified and unprovoked Russian war of aggression that is horrendously targeting civilian critical infrastructure both at central and local level, which is a blatant violation of the UN framework of responsible state behavior in the use of ICTs” . Italy also noted that its statement incorporated contributions by four Italian stakeholders who had been objected to by the Russian Federation – a specific geopolitical tension arising within the session itself. Ukraine similarly highlighted the Tallinn Mechanism as “the leading platform for coordinating civilian cyber assistance to Ukraine” and described it as demonstrating “how practical international cooperation can produce tangible results” , while referring to “persistent cyber-aggression by a certain P5 member” .
Iran, Cuba, China, and Russia introduced a different dimension, arguing that capacity building must also address barriers to technology access. Iran stated that “restrictive measures in the ICT environment can significantly hinder the development, security, and resilience of ICT ecosystems” and that the global mechanism “should also consider practical measures to address and prevent such restrictive practices, including unilateral coercive measures that adversely affect the ICT capacities of a state” . Cuba called for “an end to all unilateral coercive measures that limit exchanges or progress and digital learning environments” . China argued that “relevant cooperation should not come with conditions especially” and that “countries have the right to choose independently their digital and technical products” . Russia stated that “any attempts to restrict countries’ access to advanced ICTs or to increase their technological dependence on dominant states in the sphere are unacceptable” .
—
#
Practical Accessibility and Inclusive Participation
An unexpected but important dimension of the discussion concerned the practical accessibility of the global mechanism itself as a capacity building and equity issue. Kiribati raised the issue of meeting times with particular force, noting that “Kiribati is 19 hours ahead of this room. A 10 o’clock meeting in New York is a 5 o’clock the following morning in our capital,” and that requiring officials who “hold our entire national cyber security function” to choose between attending the mechanism and defending their country “is not participation. It is endurance” . Kiribati argued that rotating meeting times is “the simplest least inclusion this mechanism could offer” . Tonga underlined that “hybrid participation in the DTGs is not a convenience but a condition of equity,” noting that Pacific states will never be able to travel with large delegations .
The Chair responded directly to Kiribati’s concern, acknowledging that she cannot promise to change the general meeting times of the global mechanism but committing that “next time I’m going to meet with you virtually is going to be at your convenient time” – making clear that this personal commitment applied to her own virtual engagements with Kiribati rather than to the mechanism’s formal schedule . This personal commitment from the Chair represented a rare and concrete response to a structural barrier to participation raised during the session.
—
#
Emerging Technologies and Evolving Capacity Building Needs
Several delegations noted that the rapidly evolving technological landscape – particularly the emergence of artificial intelligence, quantum computing, cloud services, and the Internet of Things – is reshaping the cyber threat environment and must be integrated into capacity building agendas. Italy argued that “as emerging technologies such as AI, cloud, quantum and the Internet of Things expand the digital ecosystem, cybercapacity building ensures these innovations are adopted securely” . Rwanda noted that “new technologies including artificial intelligence and quantum computing continue to reshape the cyber landscape” and that the achievements of the OEWG should be preserved and built upon in this context . Ecuador described incorporating AI, quantum computing, and the Internet of Things into its new national cybersecurity policy .
Vanuatu identified a particularly distinctive need, noting that its region requires “the capacity to assess emerging technologies such as artificial intelligence, cloud services, and satellite connectivity, before adopting them,” describing this as what it takes “to digitalize safely on the front line of a changing climate” . The Bahamas similarly noted that “small island development states need capacity building that includes emerging technologies such as AI to ensure that we grow with the evolving state of technology” . Brazil highlighted that “developing and retaining enough qualified personnel is an ongoing challenge” given the rapidly evolving pace of digital technologies, “and even more so from a gender, race, and disability-sensitive lens” . China’s commitment to 5,000 AI fellowships for developing countries over five years, announced at the 2026 International AI Conference, is directly relevant to this dimension of the capacity building agenda .
—
#
Measuring Success and the Path Forward
The session concluded with broad agreement that the measure of successful capacity building must be concrete outcomes rather than process metrics. Malawi stated that “the measure of successful capacity building is not the number of workshops conducted or certificates awarded. It is whether countries live better prepared to prevent cyber incidents, respond effectively when they occur, and contribute meaningfully to international cooperation” . Cambodia stated that “the success of these efforts should be measured by concrete results: stronger institutions, better prepared personnel, and more resilient essential services” . New Zealand structured its contribution around four principles – coherent, contextualised, calibrated, and constructive – with the final one explicitly linked to “actually leading to practical support and improved outcomes” .
Malawi called on the mechanism to ensure “that capacity building remains practical, inclusive, and results-oriented, so that every member state has not only one seat at the table, but also the capability to contribute meaningfully to our shared objective of an open, secure, stable, accessible, and peaceful ICT environment” . Rwanda expressed the hope that “if we succeed in this, this mechanism will be remembered for the capacities it strengthened and the trust it helped build among the states” . The Chair noted that 14 requests remained under the agenda item and that the remaining speakers – beginning with Thailand, Saudi Arabia, and the Philippines – would be heard the following morning, which would be the final meeting of the session .
—
Chair Egriselda López
Good afternoon to all. I call to order the eighth meeting of the 2026 substantive plenary session of the Global Mechanism on Developments in the Field of ICTs in the Context of International Security and Advancing Responsible State Behavior in the Use of ICTs. We will now continue with the presentation. The final item of our agenda, which is developing and implementing capacity building measures. as I have told you during the meeting this morning we have a very lengthy list of speakers which demonstrates the importance and the relevance of this topic to most of you however this will require us to manage our time very carefully therefore I reiterate that while there is no set time limit for statements you could consider delivering a shorter version of your statement than submitting the full version through e -statements to the secretariat and to the chair’s team for your information there are 49 requests for the floor if you have not yet pressed the button to request to speak please do so right now if you are going to speak on behalf of a group of states please also indicate this to the Secretariat so that we can make the relevant adjustments to the list of speakers. And also, for your information, for your reference, there will be a clock on the screen. I think you already know this, but I will recall it just the same. We will now begin with the first speaker, which is Cote d ‘Ivoire, followed by
—
Cote d'Ivoire
South Africa. Madam Chair, Cote d ‘Ivoire aligns itself with the statement made by Nigeria on behalf of the African group and would like to make the following observations in its national capacity. Madam Chair, my delegation welcomes the fact that a specific discussion is dedicated to capacity building, which for many states remains the… essential precondition for implementing the framework for the responsible behavior of states in the use of ICTs. the digital transformation undoubtedly opens up immense prospects for development for our societies. However, it also increases their exposure to cyber attacks, disruptions of essential services, digital fraud, and the criminal exploitation of new technologies. In the face of these threats, which know no borders, my delegation is of the view that security collective cannot rest on national capacities, which are deeply unequal. The digital environment requires resilience from states that have even limited resources. Cote d ‘Ivoire believes that capacity building must be voluntary, inclusive, sustainable, transparent, and inclusive. and based on the needs expressed by the beneficiary states themselves. It must take into account local realities and produce measurable results. At the national level, my country has strengthened its institutional architecture, in particular through the National Agency for Information Systems Security and the CIT Cote d ‘Ivoire. My country is also working to develop sectoral incident response mechanisms. We are working on training staff and ensuring better coordination between those responsible for digital security and public administration officials. Madam Chair, national efforts in order to fully bear fruit must be supported by more accessible and better coordinated international cooperation. That is why my delegation would suggest the following three recommendations. First of all, under the auspices of the UN to develop a tool that will allow states to identify their needs and then connect them with partners, programs, and available financing. Secondly, attach a particular prerogative to CRT, the protection of critical infrastructure, simulation exercises, and the training of diplomats, technicians, judges, and other law enforcement services. Third, strengthen the role of the African Union Regional Economic Commissions and the African Training Centers so that assistance is adapted to national and sub -regional contexts. Madam Chair, Cote d ‘Ivoire calls for more ambitious, inclusive, international cooperation that includes women and youth and promotes transfer of knowledge and the development of lasting local expertise. because strengthening the capacities of each and every one of us means strengthening the digital
—
Chair Egriselda López
Thank you very much. So the chair, I now give the floor to the delegation of South Africa, followed by Malawi.
—
South Africa
Chair, South Africa aligns with a statement delivered by Nigeria on behalf of the African group and would like to make the following remarks in our national capacity. South Africa maintains the view that capacity building is a cross -cutting issue on the pillars of the global mechanism. Given that member states remain at varying levels of implementation of the framework for responsible use of ICTs due to various factors including differing contexts and capabilities, capacity building is therefore an important and essential part of the global mechanism. In addressing cyber security threats, and building resilience to such threats, the implementation of norms for responsible state behavior, the application of international law to the use of ICTs, and the implementation of CBMs. South Africa continues to support capacity -building efforts that are needs -based and practical, guided by capacity -building principles encapsulated in paragraph 56 of the 2021 OEWG final report. Programs such as the Women in International Security and Cyberspace Fellowship remain essential in building the necessary cybersecurity capacity. Also critical is sustainable and practical funding to support capacity -building activities, particularly for the globally. In this context, we look forward to further discussions on the development and operationalization of the UN Voluntary Fund. for capacity building, as well as the establishment of the dedicated Global ICT Security Cooperation and Capacity Building Portal to strengthen international cooperation and assistance on ICT security. Thank you, Chair.
—
Chair Egriselda López
Thank you very much. I now give the floor to Malawi, followed by Italy and Brazil.
—
Malawi
Madam Chair, understanding the value of every second, I will do my best to share our national statement on CBMs in a reasonable time. My delegation once again thanks you for giving us the floor. If the cumulative and evolving framework represents our shared vision for responsible state behavior in cyberspace, then capacity building is what makes that vision achievable. The Republic of Malawi believes that capacity building should not be the only way to achieve that vision. It should not be viewed as assistance provided by some states to others. Rather, it is a shared investment in international peace and security. Cyber threats do not recognize borders and weaknesses in one part of our interconnected digital ecosystem. And a weakness in one part of our interconnected digital ecosystem can have consequences far beyond national frontiers. For developing countries, however, the challenge is often not lack of commitment, but a lack of resources, expertise, and opportunities to translate political commitments into operational capabilities. Addressing this gap requires sustained partnerships, predictable support, and above all, respectful national ownership. Capacity building must therefore remain demand -driven, tailored to national priorities, and responsive to the different levels of development and capacities of member states. Equally important, it should promote self -sufficiency by enabling states to develop enduring institutions, skilled professionals, and resilient national partners. Thank you. rather than creating long -term dependency. Madam Chair, as we begin operationalizing the global mechanism, the dedicated thematic groups present an important opportunity to move beyond dialogue towards practical implementation. They should become platforms where member states openly exchange experiences, identify common challenges, showcase successful practices, and develop practical recommendations that support implementation across all five pillars of the framework. The Republic of Malawi further welcomes establishment of the voluntary fund under the global mechanism. For many developing countries, meaningful participation in this process depends not only on political will, but also on all the availability of practical support. The voluntary fund therefore represents an important investment in ensuring equitable participation and strengthening the implementation of our shared commitment. Capacity building must also be inclusive In this regard, my delegation would like to specially recognize UNIDIR and all sponsoring states’ efforts in supporting the WIC fellowship We also would like to congratulate UNIDIR’s launch of the Compendium of Good Practices on Gender Mainstreaming in Cybersecurity The Compendium provides practical guidance that can assist member states in integrating gender perspectives into national cybersecurity policies, institutions, and capacity building initiatives We commend UNIDIR for advancing this important work and we affirm that inclusive cybersecurity is stronger cybersecurity When women participate fully as policymakers, technical experts, incident responders, diplomats, and leaders our institutions become more resilient and our responses more effective Thank you At the national level, the Republic of Malawi continues to prioritize investment in people as the foundation of cyber resilience Through national awareness, professional development, and cybersecurity education, we are strengthening institutional capacity and developing the next generation of cybersecurity professionals. This includes delivering child online protection training for teachers across all education divisions, conducting university cyber drills to build practical skills, advancing women in cyber initiatives to promote greater participation in the field, and providing specialized technical training through the Malawi National CERT, as well as our established sector certs. These efforts reflect our conviction that sustainability is the key to success. Sustainable cybersecurity begins with sustainable human capacity. Madam Chair, to conclude, the measure of successful capacity building is not the number of workshops conducted or certificates awarded. It is whether countries live better prepared to prevent cyber incidents, respond effectively when they occur, and contribute meaningfully to international cooperation. As we move from establishing the global mechanism to implementing its mandate, let us ensure that capacity building remains practical, inclusive, and results -oriented, so that every member state has not only one seat at the table, but also the capability to contribute meaningfully to our shared objective of an open, secure, stable, accessible, and peaceful ICT environment. I thank you.
—
Chair Egriselda López
Muchisimas gracias, Doja. Many thanks. I now give the floor to Italy, followed by Brazil and Rwanda.
—
Italy
Good afternoon, and thank you, Madam Chair, for giving me the floor. Italy fully aligns itself with Australia. Italy has made a statement delivered by the European Union and wishes to add what follows in its national capacity, also incorporating some contributions by the four Italian stakeholders objected by the Russian Federation. Cybercapacity building is essential for strengthening national resilience against increasingly sophisticated cyber threats in today’s interconnected world In the current geopolitical landscape strong cyber capabilities help safeguard critical infrastructure protect national security and reduce dependence on external actors As emerging technologies such as AI, cloud, quantum and the Internet of Things expand the digital ecosystem cybercapacity building ensures these innovations are adopted securely Ultimately, it promotes international cooperation, trust and stability in cyberspace while supporting sustainable digital development Existing national and regional experience demonstrate that combined combining assessment, innovation, training and practical implementation produces measurable improvements in cyber resilience Madam Chair, cybercapacity building is a qualifying element of Italy’s national cybersecurity strategy and of our national cyberdiplomacy Firmly convinced by the effectiveness of the multi -stakeholder approach which has been highlighted also by other delegations such as Tonga we have developed a robust national ecosystem of public and private entities that are engaged whenever requests for assistance and cooperation are presented A key role in this scheme is played by the Italian National Competence Centers for Cybersecurity and Digital Transformation The principles of sustainability, inclusivity and alignment with SDGs underpin Italy’s CCB approach Efforts must respect human rights and fundamental freedoms also incorporating a gender perspective This goes hand in hand with the implementation of the UN Pact for the Future and the Global Digital Compact A particularly meaningful strategy is the Maté Plan for Africa, promoted by the Italian government to bring about a paradigm shift in relations with African nations and peoples, generating shared opportunities, benefits and development. The plan promotes a model of cooperation between equals, built on trust and mutual respect. The strategy aims to support the sustainable development of the African continent in all its dimensions, including the digital one, through ongoing dialogue and the joint selection of the projects and investments considered most effective to respond to the concrete priorities of its peoples. Some examples of CCB projects supported by Italy range from developing national cybersecurity strategies to training personnel, from delivering ICT products to crafting systems. Some examples of CCB projects supported by Italy range from developing national cybersecurity strategies to creating awareness -raising campaigns. We do that bilaterally with several partners as well as through multilateral organizations such as the World Bank, UNIDIR and ITU. Within the other multilateral initiatives in this field, I would like to particularly mention the Tallinn Mechanism, which is a platform of countries that since 2023 has been providing civilian cyber support to Ukraine as the latter endures the ongoing unjustified and unprovoked Russian war of aggression that is horrendously targeting civilian critical infrastructure both at central and local level, which is a blatant violation of the UN framework of responsible state behavior in the use of ICTs. Madam Chair, dear colleagues, capacity building should remain the central pillar of the global mechanism. Initiatives should be demand -driven, sustainable, coordinated, and based on localization. while avoiding duplication of existing efforts. Beyond the technical training, capacity building should encompass institutional development, cybersecurity governance, policy support, workforce development, awareness programs, and the strengthening of national cyber ecosystems, as also recalled, for instance, by Nigeria. All of the above bearing in mind the advancements of EDTs and their impact on cybersecurity. Against this backdrop, DTG1 will be essential to deepen the interconnection between CCB and the other pillars, whereas DTG2 will have the extraordinary opportunity to define possible templates of CCB projects or best practices, making sure that nobody is left behind, as several delegations of Africa and Oceania have emphasized during the past few days. Madam Chair, Italy stands ready. Italy stands ready to contribute to these efforts by sharing practical experiences and supporting collaborative initiatives. that strengthen global cyber resilience through measurable, operational, and trusted collaboration so as to concretely nurture the conditions for a broad implementation of the UN framework of responsible state behavior, which is the very mandate of this global mechanism. Thank you.
—
Chair Egriselda López
Thank you. I now give the floor to Brazil, followed by Rwanda.
—
Brazil
Thank you, Presidenta. Madam Chair, Brazil Unlines itself is a statement made by Chile on behalf of a number of Latin American countries and would like to add a few comments in its national capacity. Building capacities in the field of ICT security is the foundation for our countries to benefit in a sustainable way from digital transformation, a key enabler of socioeconomic development, while adequately addressing the needs of the world. Thank you. The digital divide adds a central layer to this challenge, rendering international cooperation an urgent imperative in order to expand the capacity of states to force their resilience, mitigate risks, and respond to ICT incidents. My delegation believes that the United Nations must play a larger role in capacity building on ICT security. Centralizing information on the many existing initiatives would facilitate access by those who need them most, by concentrating all possibilities in one place. More importantly, having the United Nations take part in those efforts ensures closer alignment with the priority issues identified by the membership and better compliance with the capacity building principles. Brazil looks forward to the December session of DTG2. Its work should not start from scratch. It should build upon the experience accumulated in the previous process, including activities such as the 2024 Global Roundtable on ICT Security Capacity Building and the mapping exercise carried out by the Secretariat to survey the global landscape of capacity building programs and initiatives. Having a clear, updated picture of what exists helps optimize synergies, avoid duplications, and promote a systematic matchmaking effort. Given the rapidly evolving pace of digital technologies, developing and retaining enough qualified personnel is an ongoing challenge, and even more so from a gender, race, and disability -sensitive lens. Ensuring that women and persons belonging to marginalized populations are duly qualified and effectively included in the ICT security workforce is essential to a more secure cyberspace and should be treated by the DTG2 as a substantive component of capacity building rather than an afterthought. So, Madam Chair, by way of conclusion, my delegation highlights that the interconnected and transnational nature of cyberspace means that security is even more of a collective endeavor than in other arenas. No country can tackle threats in the digital domain in isolation, and vulnerability left unaddressed in one state is a vulnerability available to be exploited against all. The strategic importance of ICT security capacity building lies in the need to enhance systemic resilience and ensure confidentiality, integrity, and availability of digital ecosystem resources. International capacity building efforts need to be held high in every country’s priority list for ICT security and will continue to play a crucial role in our common goal of an open, secure, stable, peaceful, accessible, and interoperable
—
Chair Egriselda López
Thank you. I now give the floor to Rwanda.
—
Rwanda
Thank you very much, Chair, for giving me the floor. First, Chair, we want to thank you and your team for excellent leadership and guiding us in this session. Chair, we align ourselves with the statement delivered on behalf of the African group. Madam Chair and colleagues, over the past days, we have engaged in rich and thoughtful discussions on evolving cyber threats, landscape, responsible state behaviors, international law, and confidence -building measures. While perspectives have naturally differed, one message emerged with remarkable clarity. No state can address today’s cyber challenge alone. Our collective security depends on one strong cooperation, greater trust, and shared responsibility. We are committed to ensuring that the security of our communities is maintained. to responsible action. The establishment of this global mechanism gives us the opportunity to translate that shared understanding into practical actions and results. Madam Chair and colleagues, as we turn to capacity building, we are discussing the foundation upon which every other pillar depends. Without the necessary institutions, legal frameworks, technical expertise and skilled professionals, commitments cannot be implemented, norms cannot be operationalized and resilience cannot be strengthened. Randa’s own experience has demonstrated that building cybersecurity capacity requires sustained investment, sound public policy and strong national institutions. But it has also shown that nationalization, national efforts alone are not enough. Cyber threats knows no borders and like we the diplomats they never wait for visas That is why international cooperation remains indispensable The open -ended working group laid a solid foundation through initiatives such as the Global Points of Contact Directory confidence -building measures and the inaugural Global Roundtable on ICT security capacity building was in the direct direction We should preserve these achievements and build upon them as new technologies including artificial intelligence and quantum computing continue to reshape the cyber landscape Madam Chair In many developing countries the challenge is no longer or not a lack of commitment It is a lack of resources, technical expertise and opportunities to build national capacities Closing these gaps, as most have said, should be our collective objective. Our shared digital ecosystem will only be as resilient as the capacity of every state to prevent them. As this global mechanism begins and continues its work, let us ensure that capacity building remains practical and accessible to all states. If we succeed in this, this mechanism will be remembered for the capacities it strengthened and the trust it helped build among the states. Thank
—
Chair Egriselda López
I thank the Deputy Permanent Representative of Rwanda for that statement and I give the floor to the Permanent Representative of Ecuador. Ambassador, you have the floor.
—
Ecuador
Thank you, Madam Chair. Thank you, Madam Chair. Thank you, Madam Chair. Also, Ecuador is developing its national cybersecurity policy for 2026 through 2029. This is aimed at building a resilient ecosystem and shared responsibility. One of these seven pillars is linked to international cooperation and cybernetic diplomacy, and it recognizes the need to complement national capacity with knowledge, resources, and technical assistance. This vision aligns with the overall principles of responsible state behavior. Colleagues, capacity building must be sustainable. It must be oriented, results-oriented, and it must be equipped with adequate financing and enjoy participation from a broad range of sectors. including all stakeholders and concerned individuals. We are focused also on a culture of cybersecurity, building this culture in small and medium-sized companies, and we believe that international cooperation can help us overcome these challenges. these initiatives should foresee the challenges of emerging technologies such as AI quantum computing and the internet of things all of these are areas that Ecuador has incorporated into its new national policy and so my delegation gives particular importance to the dedicated thematic group on capacity building and it should bring us closer to the realities in different countries and promote measures to help countries diagnose and assist in their challenges. It could also promote indicators for assessing results, monitoring follow -up mechanisms and better coordination between the needs of states and the offers of cooperation that are available. The thematic group should address also the risks associated with this and developing national capacity and it should avoid addressing issues that fall to other fora. Let me reiterate the willingness of my delegation to contribute to the development of this global mechanism and of course I couldn’t fail to mention how happy I am to see you leading our work and you will always have our full support. Thank you.
—
Chair Egriselda López
Thank you very much. Thank you very much, Ambassador, for that support. Thank you also for those… words. I now give the floor to the next delegations which are Kiribati, Cambodia and Mauritius. Kiribati, you have the floor.
—
Kiribati
Madam Chair, Kiribati aligns itself with the statement delivered by the Kingdom of Tonga on behalf of the Pacific Island Forum members and we endorse in particular the Forum’s view that capacity building is the enabler underpinning everything else we do here. A framework that only some state can implement is not yet a framework for all. We speak from experience. Our national cyber security strategy was developed through broad multi -stakeholder consultation with technical support from the International Telecommunication Union, ITU. Our national cyber security maturity assessment undertaken with the Oceania Cyber Security Center gave us an evidence base that has shaped our priorities ever since. and through the Kiribati Digital Government Project supported by the World Bank we are building the institutions and infrastructure on which secure digital services are debent. Madam Chair, I want to be plain about what that took. Each of those was years of work for a very small number of people, not one arrived complete. What our partners gave us was not the capability delivered ready-made. It was the chance to build our home and the patience to let us do it. That is the first lesson and the most important. capacity building works when it is country -owned our partners supported priorities that Kiribati identified not priorities identified for us the second is that it must be sustained a single training builds a memory a single training builds a memory it does not build an institution And the third is that it must be inclusive Government alone did not build Kiribati’s cyber security Our churches, our communities, our private sector, our schools and our regional partners each carry part of it In a society as small as ours, inclusion is not a procedural courtesy It is the only way capacity is built at all And the only way it stays Madam Chair, we warmly welcome the dedicated thematic group on capacity building December is this mechanism’s first opportunity to show that it can convert discussion into delivery And Kiribati asked that it focus on concrete, measurable output Mapping needs against what already exists Developing tools states can actually use And identifying sustainable financing We support the fullest use of experts briefing Thank you Which are of particular value to delegations that cannot bring their own experience and Madam Chair, permit me one practical word because it is a capacity question too Kiribati is 19 hours ahead of this room a 10 o ‘clock meeting in New York is a 5 o ‘clock the following morning in our capital when we ask that meeting times be rotated as the forum have asked we are not asking for comfort we are asking that the officers who hold our entire national cyber security function and who must be at their desk the same day are not required to choose between attending this mechanism and defending their country hybrid participation matter enormously to us but hybrid at 5 in the morning sessions after session is not participation it is endurance an inclusive mechanism must be inclusive in the practical design of its work and this is the simplest least inclusion this mechanism could offer Madam Chair inclusive closing permit me to say something on behalf of my delegation Kiribati’s delegation to this session is three people Two are here through the Women in Cyber Fellowship One is here under the United Nations Sponsorship Program Not one of us will be in this room without those programs And without the training that came with them I say that plainly because it is true And because those who sustain this program Should hear it said aloud They did not buy Kiribati’s seat They made it possible for Kiribati to use one What we brought to this room, our experience Our position, our voice is our own What those programs gave us was the chance to bring it To the state and partners who made this possible We thank you The training is not incidental to the travel It is what turns attendance into participation Madam Chair, this is what capacity building looks like When it is a program that is not incidental It looks like a delegation that would otherwise not be here we are not asking to be carried we are asking to be equipped so the next time this room meets Kiribati can arrive not only with needs to describe but with the experience to offer that is the measure by which we will judge this mechanism and it is a contribution we intend to make I thank you Madam Chair
—
Chair Egriselda López
I thank you so much for your remarks I cannot promise to change the time that we meet in the global mechanism however you have my commitment that next time I’m going to meet with you virtually is going to be at your convenient time not your time thank you now I want to give the floor to the delegation of Cambodia to be followed by Mauritius.
—
Cambodia
Thank you Madam Chair Cambodia is a country that is taking concrete steps to strengthen its national cyber resilience We are advancing our Cambodia appreciates your leadership in the effort of your team in preparing for and convening for this first substantive plenary of the global mechanism We welcome this opportunity to contribute to the discussion on capacity building and to promote the practical implementation of our agreed framework Digital transformation is among Cambodia’s key priority. We are building a digital government economy and society while recognizing that digital progress and cyber resilience must advance together. Sustainable development cannot rest on insecure digital foundations yet significant capacity gaps persist Developing countries face increasingly sophisticated malicious ICT activity much of which is cross -border, while operating with constrained technical, institutional and financial resources. In an interconnected environment, weakness in one part of the digital ecosystem can create risks across borders. Closing these gaps is therefore an investment in our collective security. Cambodia considers capacity building essential to the effective implementation of the framework of responsible state behavior in the use of ICTs. We emphasize three priorities. First, capacity building must be demand -driven, tailored to national circumstances, and grounded in national ownership. For Cambodia, capacity building must be demand -driven, tailored to national circumstances, and grounded in national ownership. For Cambodia, capacity building must be demand -driven, tailored to national circumstances, and grounded in national ownership. For Cambodia, capacity building must be demand -driven, tailored to national circumstances, and grounded in national ownership. For Cambodia, capacity building must be demand -driven, tailored to national circumstances, and grounded in national ownership. protecting critical information infrastructure, strengthening national and sectoral incident response capabilities, and securing digital government services. Programs should be designed jointly with recipient states and aligned with their national strategies, institutional context, and implementation timelines. Second, capacity building must be sustainable and results -focused. One -off training alone is insufficient. True resilience is built when we train local trainers, establish robust institutional memory, and strengthen our national pool of cybersecurity professionals. Cambodia welcomes international partnerships that support joint research and knowledge exchange, facilitated access to relevant technologies. and university -level collaboration to build the next generation of our cyber workforce. Third, capacity building should be evidence -based, politically neutral, transparent and accountable, and should be provided without conditions. It should be inclusive, non -discriminatory, undertaken through voluntary partnership, and implemented with full respect for state sovereignty, human rights and fundamental freedoms. Madam Chair, Cambodia is taking concrete steps to strengthen its national cyber resilience. We are advancing our national cybersecurity legal and policy framework, strengthening cancer and incident response capabilities, and strengthening our national cybersecurity legal and policy framework. and enhancing the security of our digital government services. services. We appreciate that recent Cambodia UNIDEAR cyber capacity building and policy training jointly organized by Cambodia’s Ministry of Post and Telecommunications and the UNIDEAR with support from the Government of Canada. And we also value capacity building support from the Government of Australia and other partners as well as regional cooperation through the ASEAN Singapore Cyber Security Centre of Excellence and the ASEAN Japan Cyber Security Capacity Building Centre. The global mechanism should add practical value to these national and regional efforts. Cambodia encourages close coordination between the two dedicated thematic groups so that implementation challenges identified. And in substantive discussions can confirm tailored capacity building partnership. We also support voluntary needs assessment, matchmaking between identified needs and available assistance, resource mobilization, knowledge sharing, and measurable follow-up. Cambodia underscores the state-led and intergovernmental character of the global mechanism and the principle of consensus in its decision-making. In accordance with the agreed modalities, its capacity-building work should draw on relevant technical expertise and build on regional experience, including ASEAN’s effort. To implement the voluntary non-binding norms, it should also avoid duplication, make effective use of the United Nations system, and relevant partners. The success of these efforts should be measured by concrete results. stronger institutions, better prepared personnel, and more resilient essential services. In closing, Cambodia reiterates its commitment to working constructively with all member states to promote an open, secure, stable, accessible and peaceful ICT environment in which no state is left behind. Thank you, Madam Chair.
—
Chair Egriselda López
Thank you. I now give the floor to Mauritius to be followed by Nauru, Singapore, and the Islamic Republic of Iran.
—
Mauritius
Madam Chair, good afternoon and thanks for giving me the floor. We underscore that capacity building remains, a cornerstone for advancing international peace. security and stability in the use of information and communication technologies. In an increasingly interconnected digital landscape, the ability of all states, particularly developing countries and small island developing states, to effectively prevent, detect, respond to and recover from cyber incidents is essential. Capacity building must be inclusive, demand -driven and sustainable. It should reflect national priorities and contexts while promoting ownership and long -term resilience. In this regard, Madam Chair, we emphasize the importance of strengthening legal policy, technical and institutional capabilities, including the development of national cybersecurity strategies, protection of critical information infrastructure and enhancement of incident response mechanism. We further highlight the need for enhanced cooperation and coordination among the states, regional organizations, the private sector, academia and civil society. Public -private partnerships play a vital role in sharing expertise, resources, and best practices. At the same time, capacity -building efforts should avoid duplication and ensure better alignment with existing initiatives. Transparency, trust, and confidence -building are fundamental. We support the exchange of information on national experiences, lessons learned, and good practices. In addition, the existing voluntary repositories and platforms for capacity -building can facilitate matchmaking between needs and available resources. This could further discuss in the established dedicated thematic group on capacity -building. It is also essential to integrate capacity -building with in -depth discussions on the applicability of international law, norms of responsibility and behavior, and confidence -building measures. This holistic approach will ensure that capacity -building is a key part of the capacity -building process. This holistic approach will ensure that capacity -building contributes meaningfully to a secure, stable, and peaceful cyberspace. we would like to highlight that the mainstreaming of the principles of transparency trust and human rights into capacity building programs including through agenda responsive approaches and the integration of agenda respective into the national ICT policies should be enhanced during the course of this particular process Madam Chair, we strongly believe that development of mentorship programs to supplement training particularly for CERTs and C -CERTs and strengthening of cooperation between incident response teams through joint training and mutual assistance arrangements is important and should be expanded. We further express support for existing initiatives such as the Global Cybersecurity Cooperation Portal designed by India and the UN Cyber Resilience Academy under UNIDR and also initiatives from the OAS, OSCE and Asian regions We firmly believe that these tools and capacity building efforts can provide practical support and long -term resources for states especially those with limited capacity Finally, Madam Chair, allow me to reiterate that Mauritius hosts one of the ITU Global Academy Training Centre, where dedicated training programs focusing on cybersecurity norms and CBMs implementation have been conducted on an annual basis since 2021. Past training sessions were attended by over 20 countries across the globe, and we encourage interested delegations present here to register on ITU Academy portal for future trainings in that regard. Madam Chair, finally, we reaffirm that capacity building should be guided by the principles of inclusivity, accessibility, and equality, ensuring that no state is left behind. Thank you, Madam Chair.
—
Naoero
Thank you, Madam Chair. Naira offers the following national remarks in alignment with the statement delivered by Tsonga on behalf of the Pacific Islands. I’ll inform members on capacity building. When Naoero first addressed this mechanism in March, we said that our focus was implementation and that success should be measured by whether support is accessible and equitable for those who need it most. Four months on, we returned to report what implementation has meant at home and to hold this mechanism to the same test. Since March, NARO has advanced our most ambitious cyber and digital reform program in our national history. The NARO cybersecurity bill is in the final stage of consideration by our government, with a digital transformation bill and data protection bill to follow. Our national cybersecurity strategy and national child online protection strategy are being developed in parallel with assistance of ITU. And our national search and development program is being developed in parallel with ITU. The Naoero security arrangements are taking shape. The draft legislation was open for public comment. because in Nauru, the community that legislation serves is never far from the government that drafts it. These reforms are aligned with the framework of responsible state behavior and with our region’s instruments so that what we build nationally serves what we have agreed to internationally. Madam Chair, Nauru, a country with a population of 12 ,000 people, offers this account for a reason. It demonstrates that political will is not a scarce resource. Capacity is. A committed small state can’t drop the laws, set the strategies, and design the institution. What it cannot do alone is staff them, sustain them, and grow the expertise they require. When the officials concerned already carry several portfolios each, capacity building for a state like Nauru must therefore be a part of the policy. A phobia -cumulative Each engagement building on the last Developing our own people rather than substituting for them And lasting beyond any single project cycle Support delivered in fragments Leave fragments behind We therefore look to the DTG on capacity building in December To move on from principle to program Now let us ask a specific A clear picture of where needs and existing support do and do not meet. A capacity building portal designed for the official with 10 minutes to spare, not the ministry that is equipped with a dedicated research team and serious attention to sustainable financing. We also encourage the cross-cutting group to treat capacity as a threat running through every pillar. Because of many states, it is the difference between endorsing the framework and living it. I thank you. Muchísimas gracias.
—
Chair Egriselda López
Thank you very much. I now give the floor to Singapore.
—
Singapore
Thank you, Madam Chair. As highlighted by many delegations today, cybercapacity building is an essential component of international efforts to promote an open, secure, stable, interoperable and resilient ICT environment. States have consistently highlighted the importance of building technical, legal, policy, operational and diplomatic capacities to enable effective implementation of the UN Framework for Responsible State Behaviour in Cyberspace. Capacity building should be needs -based, nationally owned, practical and coordinated. Precisely because of the complex challenges in cyberspace as articulated by states, it is important that we continue to support action -oriented capacity building ICT security which can equip states to deal with and respond effectively to these emerging threats. Madam Chair, Singapore remains… committed to cyber capacity building. We need cyber capacity building to close the gaps in cyber capabilities and for countries to contribute meaningfully to international cyber discussions. In this regard, cross -regional exchanges and sharing can also be an extremely useful form of capacity building, and participants often equip each other as much as the trainers who provide capacity building. In this regard, Singapore capacity building programs are now privileged to work with members from the Pacific Island Forum member states as well as ASEAN. Under the Singapore Cyber Leaders Program, the ASEAN Singapore Cyber Security Centre of Excellence conducted our first workshop for the Pacific Islands Forum member states and ASEAN member states in December last year. The next workshop will be conducted in November this year, and we look forward to the participation from ASEAN as well as Pacific Island colleagues. Next month, Singapore will run the seventh iteration of the United Nations Singapore Cyber Fellowship, or the UNSCF. The UNSCF seeks to empower senior officials with interdisciplinary expertise to effectively oversee national cyber and digital security policy, strategy and operations requirements. Selection letters have gone out and we look forward to welcoming fellows to the seventh iteration of the UNSCF. As discussions under this UN global mechanism advance, there is an opportunity to consider how international coordination mechanisms can better support cyber capability capacity building efforts. We could work together to develop a co -creation model that places national priorities at the center, leverages regional coordination as the primary platform for needs identification and consolidation, and uses international mechanisms to facilitate visibility, coordination and partnerships. Effective coordination of international capacity building is not a one -time exercise, but a continuous and evolving commitment. Addressing the full range of ICT capacity building needs requires approaches that are both inclusive and inclusive. and universal. We look forward to more focused discussions on how to accelerate capacity building in DTG2 and stand ready to contribute to
—
Chair Egriselda López
Thank you. I now give the floor to the Islamic Republic of Iran. They will be followed by Canada, Guatemala, New Zealand, Cuba and Mexico. Iran, you have the floor.
—
Islamic Republic of Iran
Thank you, Madam Chair. Throughout the discussions in both the first and second OEWG, member states have consistently underscored the vital importance of capacity building for the security of and in the use of ICTs. This common understanding is reflected in the final report of both OEWG and in the annual progress reports of the second OEWG. However, despite this strong political commitment, no concrete operation capacity building measures have yet been adopted at the UN. The global mechanism should now translate this political commitment into practical action by developing and implementing concrete UN -led capacity building initiatives Given the central role of the United Nations in promoting the security of and in the use of ICTs existing capacity building initiatives outside the United Nations should complement and support the work of the UN, not the other way around In this regard, my delegation believes that the role of the United Nations should extend beyond merely coordinating and matchmaking capacity building initiatives undertaken by other actors Madam Chair, we are not beginning our discussions on the capacity building pillar from scratch During both the first and second open -ended working groups we have discussed the role of the United Nations in promoting and implementing Member States put forward several concrete and action -oriented proposals on capacity building These proposals are already reflected in the final and annual reports of the OEWG. We therefore propose that they be consolidated into a single compilation prepared under your authority to serve as the basis for focused, practical and action discussions within the second DTG. Among these proposals, the establishment of a voluntary United Nations Fund should be an accorded priority. As reflected in paragraph 58 of the OEWG final report, Member States agreed to continue discussions within the global mechanism on the development and operationalization of a voluntary UN Fund to support the capacity building of States in the security of and in the use of ICTs. Advancing this initiative should therefore be one of the first priorities of the DTG -2. During the OEWG process, Member States recognized the UN -Singapore Cyber Fellowship Program as a valuable initiative for enhancing understanding across the policy, operational, technical, legal and diplomatic dimensions of ICT security This recognition is reflected in paragraph 53b of the OEWG Final Report Building on this agreed outcome, as highlighted by the African Group and several other delegations we propose that the establishment of a UN Cyber Fellowship Program be considered as another priority item for discussion within the second DTG Capacity building is not limited to positive measures aimed at addressing the needs and priorities of developing countries It also requires the removal of obstacles and barriers that impede States’ ability to access ICT resources and develop their national capacity Restrictive measures in the ICT environment can significantly hinder the development, security, and resilience of ICT ecosystems Such measures undermine existing capacities and impede efforts to strengthen them Accordingly, the global mechanism should also consider practical measures to address and prevent such restrictive practices, including unilateral coercive measures that adversely affect the ICT capacities of a state This should constitute another priority area for discussion within the second DTG I
—
Chair Egriselda López
Thank you very much I now give the floor to the delegation of Canada
—
Canada
Thank you, Madam Chair. Canada has national experience in capacity building. For example, Canada is proud to support UNIDIR’s work in Southeast Asia. This is a multi-year project that involves eight countries, Thailand, Vietnam, Indonesia, Malaysia, Laos, Cambodia, Pakistan, and the Philippines. These workshops and training sessions have brought together a range of government entities, academia, civil society, and the private sector across the region. Canada will be able to elaborate on good practices in the area of co-creation for these activities at DTG2 in December. Canada is also… pleased to have supported the Compendium of Good Practices on Gender Equality and Cybersecurity, recently published by the Stimson Center and Unidear. This compendium shows how gender responsive approaches can strengthen cyber resilience, improve governance, and contribute to more sustainable capacity building outcomes. One of the examples identified in that compendium is, of course, the Wake Fellowship, to which Canada proudly contributes. The energy of the women in this room is inspiring to all, and we thank them. Dear colleagues, one of the foundations of effective capacity building is collaboration. In this regard, Canada believes it is useful to strengthen relationships between donors, implementers, and beneficiaries. Each plays a distinct role in ensuring that capacity building efforts are tailored, effective, and sustainable. Madam Chair allow me one last parallel with soccer following that analogy the beneficiaries of capacity building are the players on the fields they are the ones who are living the match and who know where the gaps are non -governmental stakeholders are the coaches they must listen to the players and adjust the game plan donor countries for their part are the supporters or fans who fund the coaches and follow the score closely co -creation means making sure that these three players are talking about the same match before deciding how to play it Madam Chair we are enthusiastic about the idea of elaborating on good practices and co -creating on capacity building at the thematic group in December we we We will thus together raise the level of each of our teams together.
—
Chair Egriselda López
Thank you very much, says the chair. And I now give the floor to the delegation of Guatemala.
—
Guatemala
Thank you, Madam Chair. As this is the first time my delegation takes the floor, allow me to convey my delegation’s congratulations on your leadership and to recognize the dedication with which you and your team have guided the work of this mechanism. Guatemala appreciates the efforts made to promote an inclusive and transparent process. Guatemala also aligns itself with the statement made by the delegation of Chile on behalf of a group of countries and wishes to make some additional remarks in its national capacity. Madam Chair, my delegation believes that capacity building constitutes one of the fundamental pillars of the framework for responsible state behavior. Thank you. ICTs. It also represents an indispensable condition for all states to be able to participate safely, effectively, and meaningfully in the digital environment. For Guatemala, capacity building should not be understood solely as technical assistance. It is a comprehensive process that strengthens institutions, develops human resources, promotes public policies, improves national resilience, and helps narrow the digital divides that still persist in some states. In this context, capacity building is the element that makes it possible to translate the commitments and consensus reached into concrete institutional, technical, and human capacities at the national level. It also helps strengthen the resilience of states, facilitate the effective implementation of the framework for responsible behavior, and ensure that all countries, regardless of their level of development, can participate on more equitable terms in collective efforts to promote security and stability in the digital environment. Thank you. Madam Chair, we also believe it is important to continue promoting initiatives related to the protection of critical infrastructure the strengthening of national C -CERTS and CERTS cyber diplomacy the application of the norms of responsible behavior, incident response and the challenges associated with emerging technologies including artificial intelligence Madam Chair, in the digital and cyber security ecosystem human resources are always the most important in Guatemala where only a small percentage of people have higher education in computer science and even fewer experts this is a major problem, big problem it is necessary to work together with NGOs and private sector private initiatives including academia to strengthen fellowship programs which are very useful to countries like Guatemala when our own resources are insufficient that’s why we are very enthusiastic about such mechanisms Finally, Guatemala reaffirms its commitment to work together to promote an approach to capacity building that is inclusive, action -oriented, and based on the needs of states, as we are convinced that no state can be fully secure until all of us have the capacities necessary to meet the challenges of the digital environment. Thank you very
—
Chair Egriselda López
Thank you very much, Guatemala. I now give the floor to New Zealand.
—
New Zealand
Thank you, Chair. New Zealand aligns with the statement delivered by the Kingdom of Tonga on behalf of the Pacific Islands Forum, and we reiterate the key message that capacity building is the enabler that underpins all aspects of the global mechanisms work. We also recommend to you a Pacific Islands Forum working paper submitted to the OEWG last year that outlined regional capacity building priorities. New Zealand’s capacity building efforts are focused in our Pacific region, including building CERT capabilities, developing natural gas, international cyber security strategies, and cyber security public awareness campaigns. We’re also pleased to be supporting the Women in International Security at Cyberspace Fellowship which last week saw 37 fellows from 30 countries build connections and explore key issues shaping cyber security These fellows have also enriched discussions this week across every agenda item Looking forward, this new global mechanism, including DTG2 should deliver an approach on capacity building that is coherent, contextualised, calibrated and constructive It should be coherent by responding to identified needs and avoiding duplication It should be contextualised by ensuring capacity building is tailored to cultural contexts, economic conditions and geographic circumstances It should be calibrated to UNAT operating context And most importantly it should be constructive by actually leading to practical support and improved outcomes ultimately success will be measured by whether the global mechanism makes a difference. And to borrow a sentiment from some of our Pacific colleagues, if the mechanism makes a difference in the context of Pacific Island member states, then you can guarantee that it will make a difference for all member
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Cuba, followed by Mexico, and then India.
—
Cuba
Thank you, Madam Chair. Madam Chair, as a delegation from a developing country, we firmly defend the creation and strengthening of capacity, capacity building. In this regard, we support the Disarmament Affairs Division for supporting the development of developing countries in the work of the global mechanism, especially at this first plenary. Thank you for this plenary session. Their program has not only fostered the participation of developing countries in the formal meetings of the mechanism, but it has also held additional activities on capacity building on relevant topics. Also, it is worth expanding the traditional forms of capacity building limited to good practices and exchange of information. We have seen that this is not sufficient to transform the digital divide into digital opportunities. The vast, gaping digital divide and the enormous economic difficulties faced by developing countries puts us in a position of asymmetry, and also in terms of preventing, detecting, and tackling threats in the area of ICTs. Very often, these come from areas where there is greater technological development, and often these are used as a pretext for… …actions further down the line. Capacity building or strengthening should not be limited to those topics that do not… impact the essence of cybersecurity. The United Nations has a key role to play in this regard. Bilateral and regional initiatives, south and triangular initiatives should also complement the global efforts that are within reach of all. As regards the work of the dedicated thematic groups, we note that the selection of topics should be done by consensus. The dedicated thematic groups should contribute to stemming the growing threat of the use of ICTs in the context of international security, specifically by achieving a global commitment for the use of ICTs for exclusively peaceful ends for the benefit of cooperation and the development of people. The prohibition on the use of ICTs as a pretext to launch wars, the prohibition on the use of ICTs as a pretext to threats or the use of force, a prohibition on the militarization of cyberspace, and also the elimination of the vast technological gap and the barriers placed on developing countries as regards investing in their own ICT security infrastructure. The CG2 of the global mechanism has greater emphasis on capacity building, and this could contribute to achieving real commitments, especially for developing countries in order for them to provide to developing countries who requested assistance and cooperation, including financial resources and technology transfer, bearing in mind the specific needs of each country. This idea is supported by the vast majority of developing countries, and so far we have not found, and it’s a vision response. And we especially call for an end to all unilateral coercive measures that limit exchanges or progress and digital learning environments, just to mention a few examples. We cannot talk about cooperation and capacity building in real terms when there are still destructive and discriminatory practices that persist. In order to detect and respond to the malicious use of ICTs, we must have inclusive, universal and non -discriminatory access to information and knowledge related to ICTs. And this is why it is necessary for measures or activities aimed at capacity building implemented by this global mechanism be directed to making possible this access and to closing the digital divide.
—
Chair Egriselda López
I thank you. Thank you very much. I now give the floor to the Delegation. The Delegation of Mexico.
—
Mexico
Thank you. Mexico aligns itself with the statement delivered by Chile on behalf of a… group of Latin American states and wishes to add the following remarks on its national capacity. Madam Chair, Mexico considers that capacity building should be responsive to the needs, priorities and context identified by states themselves. In order for such initiatives to be truly effective, they should incorporate a gender perspective, they should recognize the differing levels of development and promote sustainability, interoperability and national ownership. Also, we reiterate that Dedicated Thematic Group 2, DTG 2, has its own mandate for accelerating capacity building in the area of ICT security and therefore its work should not be understood as being subordinate to or conditioned by the first Dedicated Thematic Group. The two groups, together with the plenary, should complement each other in order to avoid duplication and generate practical, coherent outcomes. At the same time, we believe that the focus of our work should be on the development of should evolve beyond the traditional vision of assistance and cooperation. The mechanism should reflect the idea that all states can contribute knowledge, experience and good practices in accordance with their capacities and their areas of expertise. In this regard, it would be appropriate to move towards an approach that recognises the providers of assistance for capacity building rather than resorting to the traditional categories such as donors and beneficiaries. This doing so would foster more horizontal, inclusive and needs -based cooperation that is based on the needs expressed by states themselves. Finally, Mexico considers it essential to ensure predictable and sustainable financing to enable all states to participate fully in capacity building activities. In this context, we believe it is necessary. Thank you. and the fellowship program provided for in the modalities in order to expand the access of developing
—
Chair Egriselda López
I thank you. I now give the floor to India to be followed by Albania, Botswana, Guyana and Vanuatu. I now give the floor to the ambassador and permanent representative of India. You have the floor.
—
India
Thank you, Madam Chair. It’s a matter of great satisfaction for me to address this plenary on an agenda item that India has from the very outset of the open -ended working group process considered central to building a truly inclusive and secure cyberspace. Madam Chair, for the Global South, digital technology has been transformative. A genuine enabler of economic prosperity and accelerated progress on the global front, the global front is a key element of the global front. On the sustainable development goals, India’s own experience with open, inclusive digital public infrastructure. exemplified by the India stack model has shown that technology’s benefits can only be fully realized when accompanied by robust security and the capability to defend against emerging threats. This is precisely why India has consistently emphasized that capacity building cannot be treated as a residual or secondary pillar. It must be targeted, it must be needs -driven, contest -specific, politically neutral and transparent. Madam Chair, India’s own bilateral practice reflects this conviction that capacity building for the Global South must be substantive and sustained, not just symbolic. Through the Indian Technical and Economic Cooperation Program, one of the oldest institutionalized arrangements of its kind, in the last five years alone, we have offered close to 50 ,000 fully funded training opportunities to professionals from Global South countries, spanning nearly 400 courses at over 100 premier Indian institutions, with a substantial and growing share dedicated specifically to ICT, cybersecurity, e -commerce and the development of new technologies and technologies. We have also offered a wide range of training opportunities to professionals from emerging technologies such as artificial intelligence and big data analytics. We share this experience to underline that scaled, demand -driven capacity building for the global south is both achievable and effective when pursued with sustained political will. India therefore warmly welcomes the establishment of a dedicated thematic group focused specifically on cyber capacity building. It’s a structural recognition of the priority this issue deserves within the global mechanism. In this regard, we welcome and look forward to the constructive role that the co -facilitators have envisaged to play in this DTG. We also take this opportunity to stress that the DTG should function through synchronized, topic -based agendas, expert briefings and clear reporting modalities to the plenary so as to sharpen the practical output of this mechanism. Madam Chair, it is with particular happiness that my delegation recalls that the proposal for a dedicated global ICT security and security program and capacity building portal was originally an Indian initiative first tabled in 2022. We are deeply gratified that this idea has found resonance across the membership, particularly among global South countries, and was ultimately endorsed by the General Assembly through Resolution 80 -16 as part of the final OEWG report to be developed through a step -by -step modular approach. We are pleased to announce today that having seen this idea through years of deliberation to consensus and eventual adoption, India will be providing the entire funding towards the operationalization of this portal as a portal of the United Nations, so that concrete, tangible action can finally follow years of discussion. India’s support will help enable the technical establishment of the portal and its maintenance, ensuring that the platform envisaged, comprising a repository of resources, a capacity -building calendar, a needs -based catalogue of opportunities, and an interactive discussion board, can move from design to reality. CERT India will undertake the technical consultancy work required for the portal’s testing and infrastructure development. We wish to place on record that India sees genuine and lasting value in this portal if properly used and populated by member states with actionable needs -based information We believe this platform can play a meaningful role in bridging the capacity gap that continues to separate developed and developing states in the domain of ICT security provided it is treated by all of us as a living tool rather than a static repository Madam Chair, India remains committed to ensuring that this global mechanism translates years of patient multilateral negotiation into concrete outcomes that matter on the ground particularly for those states that need capacity support the most We look forward to working with the Chair, the co -facilitators of the DTGs and all member states to take this important work forward Thank you Madam Chair Many thanks for your statement
—
Albania
Thank you, Madam Chair. Albania aligns itself with the statement delivered by the European Union and wishes to add the following remarks in its national capacity. Albania regards capacity building as a cornerstone of the framework for responsible state behavior in cyberspace and an indispensable enablement for international peace, security, and sustainable development. We reaffirm that capacity building is one of the most practical and impactful ways to support states in addressing existing and emerging ICT threats and implementing agreed commitment on ICT security. Albania supports capacity building that is demand -driven, needs -based, sustainable, transparent, and nationally owned. We stress that such efforts should be inclusive, accessible, and responsible to the specific needs and priorities of each state, particularly in cases of the small countries. Effective capacity building strengthens not only technical capacities, but also institutions, policies, partnerships, and a cybersecurity culture embraced by people as professionals and also as individuals. In concrete terms, Albania has expanded its capacity building efforts across the three pillars of people, processes, and technology. Our experience with severe cyber attacks shows that cyber resilience depends not only on technology, but also on strong institutions, skilled professionals, informed decision makers and citizens, and trusted partnerships at national, regional, and international levels. Following our investment in technology and security of the system Albania has strengthened cyber security resilience through new laws and procedures that define the organization and responsibility of cyber security institution response team and the emergency and crisis response team as well as the protection of critical and important information infrastructure and cyber security risk assessment During last year the National Cyber Security Authority delivered a broad program of activities national and international to raise awareness, strengthen education and build practice cyber security capacity across society Over 50 activities targeted professionals, the public and private sector critical and important infrastructure, businesses and SMEs through cyber hygiene training, conferences, regional event and practice oriented webinars Thank you In additional 11 dedicated activities and awareness sessions were organized for persons with disabilities, the Roma community, visually impaired individuals, elderly people, and other groups with more limited access to technology and digital education. Particular emphasis was placed on children and youth education, professional cybersecurity training, and support for women and girls in cybersecurity. Weekly activities at schools across the country have reached several thousand students, helping them to learn about safety and well -being online. Last year alone, these activities engaged directly over 7 ,700 participants, compared to 6 ,500 we had in the previous year. And from those, the majority were employees of public and private institutions and citizens, while over 1 ,000 participants received… Over 1 ,000 participants received… Over 1 ,000 people received expert -level cybersecurity training. An increasing number of international events, which have brought up to 30 countries in one event only, make us believe that this work is very important, help us all together to meet the challenges of today’s world in cyberspace. Albania continues to work closely with international partners and is grateful for their support with particular emphasis on cooperation in the Western Balkan. Through international events and platforms, we have brought together technical teams, legal experts, diplomats, and with strong emphasis, bringing together young people in order to exchange experiences, strengthen cooperation, and promote practical cybersecurity learning for today and for the future. These investments have enabled dialogue and reinforced our shared commitment to building cyber resilience through cooperation, training, and trusted partnership. Looking ahead, Albania strongly supports the work of the global mechanism and the principal inclusive intergovernmental platform for advancing dialogue and cooperation on ICT security. We welcome the dedicated focus on capacity building with the mechanism and believe it offers valuable opportunities to strengthen practical cooperation, facilitate exchange of experiences, and identify concrete avenues for assistance and partnership. We also support efforts aimed at improving coordination among existing initiatives, promoting transparency regarding available assistance, and facilitating better matching between identified needs and available resources. Such efforts can emphasize effectiveness, avoid duplication, and contribute to more sustainable capacity building outcomes. As we move forward, capacity building should continue to serve as a bridge between policy and implementation, helping all states strengthen resilience, build trust, and contribute to our shared objective of an open, secure, stable, accessible, and peaceful ICT environment. Last but not least, I would also like to express my appreciation for the opportunity to participate at this session as part of the Women in Cyber Fellowship, made possible for us through the support of the government of the Netherlands. I am proud to be part of this capacity building program, a strong community of women whose expertise and engagement contributes meaningfully to the United Nations discussions on cybersecurity. I thank you, Madam Chair.
—
Botswana
Thank you Madam Chair Botswana aligns itself with the statement delivered on behalf of the African group by the Federal Republic of Nigeria and wishes to make this statement in its national capacity Chair Cyber capacity building is not a secondary consideration in the discussions of this forum. It is the fundamental pillar upon which the framework for responsible state behavior rests As my delegation has continuously stressed during the OEWG sessions, there is an undeniable correlation between a country’s capacity gaps and its digital vulnerabilities In this regard, Botona welcomes the operationalization of the dedicated thematic group on capacity building within this global mechanism We believe the discourse by this group must prioritize concrete needs -based support over a one -size -fits -all mandate, while ensuring that national ownership remains at the heart of all initiators Chair, closing the digital divide and translating agreed norms and CBMs into practice requires actionable capacity building. We encourage the DTG -2 to focus on strengthening member states’ institutional readiness, specifically in developing sound legislative and regulatory frameworks and sound national policies. Equally essential is building technical cyber defense capabilities, strengthening critical infrastructure resilience, and investing in human capital through targeted cybersecurity education. Botswana reinforces the widely shared sentiment among developing nations that capacity building must be sustainable and adaptable in accordance with criteria that aligns with their recipient states’ unique internal realities and demands, which should be implemented. We should be voluntarily identified by the states themselves. Botswana firmly maintains that the global mechanism must work hand -in -hand with regional and sub -regional bodies to roll out capacity -building initiatives. These organizations understand the unique political and physical challenges of their member states very well. Formally leveraging these regional hubs under the global mechanism will maximize resources efficiently. Botswana acknowledges and thanks the UND for its sustained contribution to national capacity -building initiatives, including through its international law program, which helps states develop national positions. Furthermore, their new regional liaison program reinforces a shared commitment to the principles of capacity -building. Botswana reinforces that all capacity -building efforts must systematically adopt a gender -sensitive perspective, and that true cyber resilience cannot be achieved while a gender -digital divide persists. We must continue to build the capacity of women cyber professionals while deploying gender-inclusive cybersecurity awareness strategies. This is why Botswana is particularly grateful to INDI and its dedicated state partners for bridging the gender gap in global digital governance through the Women in International Security and Cyberspace Fellowship, of which Botswana is a proud beneficiary. This program ensures that women’s voices are actively shaping international security dialogues and contributing to the future of global cybersecurity. I thank you, Chair.
—
Chair Egriselda López
Thank you very much. I now give the floor to Guyana to be followed by Vanuatu, the Russian Federation, and then the Republic of Korea.
—
Guyana
Thank you, Madam Chair. Guyana aligns with the statement delivered by the Bahamas on behalf of CARICOM and adds the following remarks in our national capacity. For developing countries like Guyana, ICT capacity building is essential to bridging the digital divide and should be continuous and cross-cutting. In this regard, we underscore the importance of identifying ICT capacity gaps, taking account of country -specific challenges and needs. Strengthening the capacities of developing countries should be viewed as part of the greater global ICT security and as part of efforts to accelerate implementation of the 2030 Agenda for Sustainable Development. ICT capacity building is critical for addressing ICT vulnerabilities, mitigating ICT threats, ensuring incident responses and strengthening digital resilience. Training at technical, legal, policy and other relevant levels, information sharing, exchange of best practices and experiences and technology transfers can help to effectively advance these efforts at the national, regional and international levels. There is also a need for multilateral collaboration, including public -private partnerships, regional and sub -regional cooperation and cooperation between states and relevant stakeholders. ICT capacity building is an important part of the ICT security and security strategy. ICT capacity building is an important part of the ICT security and security strategy. ICT capacity building is an important part of the ICT security and security strategy. ICT capacity building is an important part of the ICT security and security strategy. ICT capacity building is an important part of the ICT security and security strategy. ICT capacity building is an important part of the ICT security and security strategy. ICT capacity building is an important part of the ICT security and security strategy. ICT capacity building is an important part of the ICT security and security strategy. Building on OEWG and ICTs, Guyana supports the operationalization of the Global ICT Security Cooperation and Capacity Building Portal and the establishment of the UN Voluntary Fund for ICT Security Capacity Building. We believe that these would be beneficial in supporting the capacity building needs and initiatives of states. We also welcome the dedicated thematic group aimed at accelerating ICT security capacity building. Cognizant of both ICT threats and benefits, Guyana’s digital transformation has been guided by its ICT Master Plan 2030 and the National Cybersecurity Policy Framework. We have invested in developing our ICT infrastructure to improve public services, enhance cybersecurity awareness, and promote digital literacy. Guyana also recently joined the Latin American Caribbean Cyber Competency Center, LAC4, as we continue to strengthen our cybersecurity capacity and digital resilience. Finally, Guyana emphasizes that ICT capacity building is critical to the global mechanism in ICTs and for promoting an open, secure, stable, accessible, and peaceful ICT environment. I thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much I now give the floor to Vanuatu
—
Vanuatu
Madam Chair, Vanuatu aligns itself with the statement delivered by Tonga on behalf of the Pacific Islands Forum members and adds the following in its national capacity Vanuatu can testify that capacity building works Two decades of sustained national investment supported by genuine partnerships have given Vanuatu the strongest cyber security standing in our region by international assessment We say this without complacency Our gaps remain real and our resources thin but with purpose the return on well -designed capacity building is measurable and skeptics of this pillar should study the Pacific before doubting it Because we have seen what works Vanuatu is equally clear about what does not and our region is a place where our region has put that learning on the record The Joint Pacific Islands Forum paper on capacity building submitted to the OEWG remains Vanuatu’s reference point for this pillar. Its principles bear repeating in this new setting. Capacity building in our region must be Pacific -led, with activities co -designed by those they serve, contextualized, because one size fits no body, coordinated so that partners complement rather than groud each other, sustainable, outlasting the funding cycles that create it, and inclusive of our societies in full. The paper also identified needs this room will hear from few other regions, climate -resilient digital infrastructure, and the capacity to assess emerging technologies such as artificial intelligence, cloud services, and satellite connectivity, before adopting them. These are not generic asks. They describe what it takes to digitalize safely on the front line of a changing climate, and Vanuatu asks that this mechanism treat the paper as a standing Pacific input to its capacity -building agenda. Madam Chair, the dedicated thematic group on capacity -building gives that agenda its first institutional home, and Vanuatu wants December to be remembered as the moment this mechanism started delivering. We hope the DTGs deliver three outputs, an honest global mapping of needs against provision, exposing the mismatches that everyone suspects and nobody has documented, a capacity -building portal shaped around how officials in recipient states actually work, and credible progress. On financing that does not evaporate with the next budget cycle. We further encourage the gross -cutting thematic group to embed capacity considerations in its treatment of every pillar. Vanuatu’s earlier remarks on norms implementation and legal capability both, in the end, resolve into capacity questions. Vanuatu came to the OEWG to ensure that the smallest states would shape this agenda rather than receive it. The Pacific paper is proof of that intent. This mechanism’s task is to prove
—
Chair Egriselda López
Thank you very much. I now give the floor to the Russian Federation.
—
Russian Federation
Madam Chair, the development of practical, action -oriented recommendations and initiatives for capacity building in the field of ICT security is one of the priorities of the global mechanism. We believe that such measures must meet the specific needs of the European Union. of the global self when it comes to bridging the digital divide. They must be depoliticized and open and carried out on the basis of respect for state sovereignty. At the same time, we believe that any attempts to restrict countries’ access to advanced ICTs or to increase their technological dependence on dominant states in the sphere are unacceptable. This includes the monopolization of the ICT global market by the latter and or with their facilitation. Madam Chair, in our view, the time has come to move from discussions about the importance of capacity building to concrete practical steps. I have the honor on behalf of the Russian Federation to present an initiative to conduct drills on responding to computer attacks under the auspices of the United Nations. We are convinced that the key factor in ensuring information security is not the ICTs themselves, but the human being who operates the relevant software. The ICTs are the most important resources for the development of the ICTs. The ICTs are the most important resources for the development of the ICTs. The ICTs are the most important resources for the development of the ICTs. The ICTs are the most important resources for the development of the ICTs. And while the latter can be purchased, the task of equipping operators with skills, expertise, and real -world expertise is far more complex. It is precisely this challenge that the proposed drills are designed to address. I refer to real -time virtual competitions among national teams on a training base provided by the operator, during which they will simulate responding to various types of malicious activities in accordance with a pre -prepared scenario. The technical and diplomatic points of contact of the UN Global Intergovernmental Points of Contact Directory also participate in the exercises. I stress that in accordance with the principles of the UN Charter, exclusively defensive actions are practiced. The results are assessed either in person or in a hybrid format, using a rating system based on the team’s performance and completion of tasks stipulated in the scenario. A working document with more detailed information is available on the website of the Global Mechanism. The Russian Federation already has experience in conducting such exercises. Drills with broad international participation were held on the margins of the signing of the UN Convention against Cybercrime in Hanoi in 2025, as well as on the margins of the Digitalization of Industrial Russia Conference in Nizhny Novgorod and the ICT Crime 2026 Conference in St. Petersburg. The drills we propose are focused on the broadest possible range of countries, primarily developing countries, and they aim to practice interaction within the framework of the UN POC Directory. Thus, the initiative is aimed at assisting the mechanism in two areas at once, capacity building and confidence building. We plan to work with the UN Secretariat and specialized departments. to work with them on the implementation of this initiative with Russia’s financial, organizational, and methodological support, and member states will be duly informed afterwards. Madam Chair, given the needs of the Global South, we place a particular emphasis on one of the key aspects of assistance in strengthening ICT security, training personnel. In Russian universities, there are several thousand students currently studying in relevant specialized fields, including free of charge from Asia, Africa, the Middle East, and Latin America. They are offered higher education and additional professional education programs, as well as advanced training courses. The specializations include information and computer security, methods for detecting and encountering network computer attacks, methods. and techniques for protecting information from unauthorized access, open source intelligence gathering. countering ICT crime, techniques for investigating ICT -related crimes, and international cooperation in this area, as well as computer forensics. Given our experience and capacity, we express our readiness to establish mutually beneficial cooperation with interested, competent agencies of other countries across the full range of issues relating to the training of foreign experts at Russian universities in the field of information security. Together with the private sector, we also organize annual international events dedicated to assisting developing countries in the field of ICT security. This year’s main event will be the Global Digital Forum, which will be held in Moscow on October 8th through October 10th. Another major annual forum will take place in September in Kazan. That’s Kazan Digital Week. And with the assistance of the National Association for International Information Security, we are organizing the 20th International Forum Partnership of State Business and Civil Society in Ensuring International Information Security in Moscow on September 22-24. We invite all partners to participate. Thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of the Republic of Korea to be followed by Germany, France, Switzerland and Serbia.
—
Republic of Korea
Thank you, Chair. The Republic of Korea reaffirms the fundamental importance of capacity building as the foundation underpinning our five pillars of the Framework for Responsible State Behavior in the use of ICPs. As cyber threats become increasingly sophisticated, the absence of adequate policy, technical, legal and operational capacity will limit not only individual states’ ability to respond effectively, but also the international community’s broader efforts to enhance security and security of the country. In this regard, the Republic of Korea looks forward to substantive and action -oriented discussion under DTG -2. We also believe that capacity building should not be driven solely by the priorities of providers or follow a one -size -fits -all approach, whether it should be demand -driven and tailored to the specific needs and priorities of recipient states. We remain committed to maintaining close dialogue with our partners to ensure that international capacity building efforts are effective, sustainable, and responsive to those needs. At the same time, we should avoid unnecessary duplication of existing capacity building efforts and instead seek to enhance coordination, complementarity, and efficient use of available resources. We look forward to the global mechanisms serving as an effective platform for promoting international cooperation on capacity building and for strengthening coordination among member states
—
Chair Egriselda López
Thank you very much. I now give the floor to Germany.
—
Germany
Thank you, Madam Chair, for giving me the floor. Germany fully aligns itself with the statement of the European Union and wishes to add the following remarks in its national capacity. Madam Chair, you have mentioned on different occasions that we should start focusing on action -oriented capacity building as part of the global mechanism. We support this approach. There is consensus that capacity building is a key element to implement the consensus framework. Germany believes that this unity is something we should build on and that it is time to take concrete steps. Like for most delegations in the room, capacity building has become an important resource to promote a peaceful, open, stable, accessible and secure cyberspace at home and abroad. Germany believes that capacity building can only be effective when it is aligned with the specific needs and priorities of each nation. In particular, capacity -building initiatives are most successful when implemented through a co -creation approach, as mentioned by Singapore and Canada, whereby donor and recipient states collaborate closely to jointly design, develop, and implement programs based on the UN principles for cybercapacity building. One example of such a co -creation approach is the Western Balkan Cyber Diplomacy Network, which Germany jointly established with its partners in the Western Balkan region in May 2025. The network is guided by designated focal points from the Ministries of Foreign Affairs of participating countries, which jointly identify regional cybercapacity -building priorities and decide on the initiatives needed to address them. This example illustrates, and as mentioned by Nigeria, Cambodia, and Malawi, cybercapacity -building programs should be demand -driven, targeted, and nationally owned. Such an approach fosters holistic community building among states, stakeholders, and the private sector alike, reflecting the borderless nature of cyber threats and the need for collaborative responses. When looking ahead, Germany believes that DTT2 and the annual Global Roundtable offer valuable platforms for a wide range of in -depth discussions on best practices in capacity building among policymakers, practitioners, and stakeholders from all sectors. Especially including experts from the private sector, academia, and industry will contribute to real -life and practical discussions. Both opportunities, though, should complement each other. In practical terms for Germany, this would mean hands -on and interactive discussions in DTT2 that facilitate the exchange of experiences and practical expertise. The Roundtable could complement DTT2 by providing a platform bringing together donors and recipient states. Furthermore, Germany would like to reiterate the importance of developing global portals in close coordination with existing initiatives and in alignment with existing regional portals to avoid duplication, enhance efficiency, and ensure complementarity. Also, we would like to highlight the important work of regional organizations when it comes to cybercapacity building. As an example, from our region, the OSCE Secretariat is a trusted partner across the region and provides valuable work when it comes to the implementation of CBMs. To conclude, by embracing a holistic, comprehensive, and demand -driven approach to cybercapacity building, both in the plenary and DTG meetings, this mechanism can ensure that every country is empowered to participate in an open, safe, secure, and resilient digital future, and that no country is left behind. Thank you, Madam Chair.
—
France
Thank you very much. Thank you. this connection, first of all, echoes the link that France has pointed out between the two thematic groups. The United Nations must contribute to effective capacity building, but this can only be achieved by having a thorough understanding of the threats and challenges that these capabilities must address. The discussions within the dedicated thematic group one should therefore provide a basis for guiding the work of the dedicated thematic group number two, ensuring a fruitful dialectic between these two. Secondly, any discussion on capacity building, particularly within DTG2, must be underpinned by existing capacity building initiatives, the ones that exist perhaps elsewhere. Regional organisations as well as other UN entities have a key role to play in sharing their experience and best practices. Various experts… both governmental and non -governmental, as well as stakeholders… should have a place in the second group. They are often the ones who develop or participate in capacity building programmes and without them these programmes would be nothing more than empty shells. And this is why, Madam Chair, and as a final point, please allow me to reiterate France’s call for the topics of the thematic groups to be selected as soon as possible. This will make it possible for countries to nominate experts. It will allow the co -facilitators to work alongside you to guide the upcoming discussions and enable the countries and parties to prepare substantial contributions to make before these groups. Madam Chair, France stands ready to be fully engaged in these discussions and we reiterate our full support for your chairpersonship. I thank you.
—
Chair Egriselda López
Merci beaucoup. Thank you very much. I now give the floor to Switzerland. They will be followed by… …by Serbia and Tonga.
—
Switzerland
Thank you, Madam Chair. Switzerland views cyber capacity building as a process that is nationally owned, expert -led and collaborative, and which depends on strong coordination between the intergovernmental process and the wider community of practitioners. Throughout this week, we have seen what capacity building delivers, substantive and constructive contributions from delegations that have enriched our discussions. As our Canadian colleague has just highlighted, programs such as the Women in Cyber Fellowship demonstrate this added value concretely, supporting diplomats in bringing their expertise and perspectives directly into this room. We therefore welcome the newly established DGT2 on cyber capacity building and congratulate the Chair, you, Madam, on appointing the co -facilitators. DGT2 and the roundtables are vital steps towards its future. We are achieving this coordination, and Switzerland is committed to supporting them. Effective coordination, strong partnerships and reduced fragmentation are needed for cybercapacity building, as well as a better match between needs and available expertise and stronger links between regional and global efforts. It is crucial that the intergovernmental process has a robust connection to the broader cybercapacity building community, which provides invaluable expertise, practical experience and implementation capabilities. In this regard, Switzerland would once again like to express its regret at the wide -range veto against stakeholder participation in the global mechanism. Stakeholders are not observers of capacity building. They are among its principal implementers and knowledge holders. Excluding them does not protect the intergovernmental character of this process. It deprives it of the very expertise that G2 was created to mobilize. At the same time, we recognize that their contribution to advancing cybercapacity building will inevitably be limited by available resources and how frequently DGT2 and the roundtables can meet. This is precisely why Switzerland believes it is essential for the cybercapacity building community to remain constructively and consistently organized and engaged between the sessions of the DGT2 and the roundtables. In this context, Switzerland acknowledges the previous contributions of the Global Forum on Cyber Expertise, the GFCE. In recent years, the GFCE has served as a key platform bringing together governments, international organizations, the private sector, civil society and technical experts to facilitate knowledge exchange and support coordination across the cybercapacity building ecosystem, including by facilitating the very fellowship whose impact we witnessed this week. Now that the GFCE Foundation has had to cease its operations, these functions no longer have a dedicated home. Yet they remain essential to ensuring that cyber capacity building efforts remain coherent, inclusive and responsive to evolving needs. Switzerland has therefore been working with community members to identify ways to build on the valuable contributions of the GFCE, while addressing the lessons learned from its shortcomings. During the Geneva Cyber Week in May 2026, the Geneva Centre for Security Sector Governance, DKEF, announced its partnership with Switzerland to host a community hub explicitly designed to carry these functions forward. Adopting for the community by the community approach, the hub will facilitate continued coordination, multi -stakeholder engagement and the development of sustainable governance models for cyber capacity building. Crucially. The hub should complement the efforts of the global mechanism. It will support connectivity across the community and draw on the rich ecosystem of international Geneva, including institutions and organizations such as UNIDIR, ITU and Diplo Foundation. It will also strengthen the link between strategic discussions and practical implementation, which is essential for the success of the global mechanism. Geneva offers a unique ecosystem of relevant expertise and stakeholders and can serve as a bridge between the intergovernmental process and the wider cyber capacity building community. We look forward to discussing this proposal further with delegations and you, Madam Chair, and to supporting DGT2’s work in the years ahead. We are committed to ensuring that this and future efforts reinforce rather than duplicate the objectives of the global mechanism. We thank all the delegations that have expressed their support for this
—
Chair Egriselda López
Thank you very much. I now give the floor to Serbia to be followed by Tonga and then Argentina.
—
Serbia
Thank you, Madam Chair. The Republic of Serbia has aligned itself with the statement delivered by the European Union delegation and makes the following brief comments on national capacity. For Serbia, capacity building is a central element in ensuring that the benefits of this mechanism reach all UN member states. We believe that strengthening technical expertise, institutional capacities and legal frameworks is essential to enabling states to better prevent, detect and respond to malicious ICT activities. Capacity building is not only an investment in national resilience, but also an important contribution to a more secure, stable and peaceful ICT environment for all. Serbia supports capacity building that is needs -based, demand -driven, sustainable, and coordinated. The United Nations, given its universal character, is uniquely placed to facilitate coordination, connect needs with available resources, and avoid duplication of efforts. In this regard, Serbia welcomes the role of the dedicated thematic groups in enhancing coordination, facilitating the exchange of experiences, and promoting a more effective approach to capacity building. Serbia approaches this pillar from a distinctive position. We have benefited from international cooperation and capacity building programs and projects with a wide range of partners, while investing substantially in our own national capabilities and contributing actively to the regional cooperation in Southeast Europe, including through the exchange of expertise, joint exercises, and the cooperation between national certs. This experience confirms that well -targeted, locally -owned capacity building delivers tangible results. Finally, Serbia underlines the importance of the full, equal, and meaningful participation of women in all processes related to ICT security. Thank you.
—
Chair Egriselda López
Thank you very much. Tonga, you have the floor.
—
Tonga
Madam Chair, Tonga aligns itself with the statement delivered by my colleague on behalf of the Pacific Islands Forum members and offers the following national remarks. Our own experiences with serious incidents have taught us what capacity building must be. It must be needs-based and country-driven. Our priorities are set in Nuku’alofa, shaped by our own frameworks and our most effective partnerships. Bilateral, regional, and multilateral have been those that supported our direction rather than substituting their own. It must be sustained. Institutions like CERT Tonga were not built by single workshops, and the response to last year’s attack on our health system succeeded because the relationships and capabilities behind it had been invested in over years and not weeks. It must be inclusive. In a kingdom of some 170 islands, resilience is carried by government, but also by our communities. Stakeholder inclusion is not a formality of process for Tonga. It is how capability reaches the people who need it. For the same reason, we support meaningful stakeholder participation in the work of this mechanism. Madam Chair, Tonga warmly welcomes the establishment of the dedicated thematic group on capacity building, and we see the December meetings as the first true test of whether this mechanism can convert deliberation into delivery. We encourage the DTG to work towards concrete results. The cross-cutting thematic group should apply the same capacity lens across all pillars, because a state that cannot implement the framework, is not protected by it. And we underline that hybrid participation in the DTGs. is not a convenience but a condition of equity. We will never be able to travel from the Pacific with a large delegation. On the other hand, we are grateful to UNIDER and the support of the donor partners for their continuous support and for allowing our small nation to take part in the Women in International Security and Cyberspace Fellowship last week, which has greatly assisted us and has also allowed our small delegation to participate in this substantive plenary session. Madam Chair, Tonga came through disaster with the help of its partners. and the strength of its people. We ask this mechanism to make that kind of resilience possible for every state. I thank you.
—
Chair Egriselda López
Muchísimas gracias. Thank you very much. I now give the floor to the delegation of Argentina.
—
Argentina
Thank you, Madam Chair. My delegation aligns with the joint statement delivered by Chile on behalf of a group of countries from our region. We wish to add the following remarks to our national capacity. First of all, we believe that within the dedicated thematic group 2 on capacity building, the work could be oriented towards identifying national needs and regional needs in capacity building, as well as putting together best practices to foster complementarity between existing countries. We also believe that the work of the Commission on the Development of National Sustainable Development will be able to facilitate the development of national sustainability. We also believe that the work of the Commission on the Development of National Sustainable Development We also believe that the work of the Commission We also believe that the work of the Commission on the Development of National Sustainable Development will be able to facilitate the development of national sustainability. We also believe that the work of the Commission implementing the agreed framework. Second, we believe that capacity building should continue to be understood in a broad sense, which is to say the training activities should not be based only on capacity building or strengthening human resources, but rather this training should be accompanied and should complement necessary capacity for securing ICT infrastructure and improving cyber resilience software. The capacity building should be focused on ensuring each country’s ability to develop and implement its own protection strategies in accordance with its own priorities and national policy. We believe it’s essential for capacity building to address the needs identified by the beneficiary country itself, bearing in mind that specific geographical circumstances, thus avoiding any kind of standardised or models or one -size -fits -all that ignores the differences between national contexts. Fourth, my delegation believes that thematic group two should maintain a technical and results -oriented focus. And this is, as regards the practical functioning of the second group, we believe that this DTG2 should play a central role in developing recommendations and draft concrete, practical, action -oriented decisions aimed at being elevated formally to consideration by the plenary. In our view, it would be desirable, as far as possible, for the proposals emanating from the second group should address the broad level issues. This would allow the plenary to be more inclusive and inclusive. The second group would be the first group to be able to participate in the work. The third group would be the first group to be able to participate in the work. The fourth group would be the first group to be able to participate in the work. The fifth group would be the first group to be able to participate in the work. The sixth group would be the first group to be able to participate in the work. The eighth group would be the first group to be able to participate in the work. The ninth group would be the first group to be able to participate in the work. to focus its efforts on the adoption of decisions, avoiding bringing into the plenary technical issues that could previously have been resolved in the thematic groups. This is particularly important if we bear in mind the extremely limited time that the plenary has in order to simultaneously address national interventions on the five pillars, substantive discussion and the discussion and negotiation of the texts and the outcomes of the different thematic groups. This is why Argentina believes that DTG 2 should focus on submitting to plenaries sufficiently sufficiently technical and mature texts that have broad support between the delegations participating. In this way, it could contribute to more efficient decision-making that is results-oriented. I thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor. to Uruguay to be followed by the Marshall Islands and then the Democratic Republic of the Congo Ukraine and Japan
—
Uruguay
Thank you Madam Chair Uruguay is aligned with the statement delivered by Chile on behalf of the Group of Latin American States furthermore I deliver this statement in our national capacity Uruguay wishes to underscore the importance of the substantive work of this mechanism reflecting the priorities of all regions especially in the area of capacity building for our region this is a fundamental pillar for moving towards an open, secure stable, accessible and peaceful ICT environment and this is why we have sought to submit a working paper as stated in the original statement. Without a solid basis, it’s going to be difficult for us to implement the mechanism or to participate on an equal footing in these fora. So capacity building is necessary to strengthen resilience and collective security. We consider this session to lay the foundations for dedicated thematic group two to be agile and be able to be results -oriented and have technical assistance. We believe this should be a practical mechanism that should link the practical needs of states with tangible solutions and effective cooperation. Capacity building activities must address the priorities identified by states themselves. It should include amongst other… things strengthening cybersecurity capacity, incident response capacity, protection of critical information infrastructure, and the implementation of confidence -building measures. Lastly, Uruguay wishes to highlight the value of regional and international initiatives for the furtherance of capacity building, especially those by UNIDIR, the Organization of American States, and we wish to highlight especially the Women in Cyber program. Uruguay has been a beneficiary of this on a number of occasions. It has significantly contributed to strengthening technical capacity and to promoting greater participation of women in the area of cybersecurity. These initiatives have shown themselves to be effective tools for strengthening national capacity, and this is why we… encourage you to continue strengthening them to… in their reach and to integrate cooperation across different programs in order to maximize their impact, to make the most of synergies and to avoid duplication, I
—
Chair Egriselda López
Thank you very much. I now give the floor to the Marshall Islands.
—
Marshall Islands
Thank you, Madam Chair. The Republic of the Marshall Islands has not previously spoken at this process or at the open -ended working group. We are honored to take the floor now on this important issue. We wish to begin by expressing our sincere gratitude to the Pacific colleagues who have carried the priorities of our region into this room with such conviction, and Maulo Apito in particular to the Kingdom of Tonga who have delivered the Pacific Islands Forum statements on our behalf. We align ourselves fully with the Pacific position. Madam Chair, the Marshallese people live across atolls scattered over a vast, expansive ocean separated by hundreds of miles of open sea. In this context, digital connectivity is the difference between a family divided by the ocean and one able to speak across it, between an outer island left on its own and an outer island reached by a doctor, a teacher or a warning before the storm. Digital connection for a nation such as ours can be transformational in itself. Yet what arrives from beyond the horizon can carry harm as well as hope. The very connection that can lift a remote nation can also expose it. And the smallest and most distant among us have the least to fall back on when it does. Promise and peril arrive together. This is why the Marshall Islands places capacity building at the heart of our first intervention in this process. For nations like ours, capacity building is how the promise of digital connection is made safe. We ask that this mechanism, reach even the most distant shores, so that no nation is left beyond its horizon. We are grateful to stand with our Pacific family and we are ready to take our place in advancing this work. Komoltada, thank you.
—
Chair Egriselda López
Muchisimas gracias. Thank you very much. And it is indeed excellent that you’re participating in the global mechanism. Welcome. I now give the floor to the Democratic Republic of the Congo.
—
Democratic Republic of the Congo
Madam Chair, the Democratic Republic of the Congo aligns itself with the statement made by Nigeria on behalf of the African group and we would like to make the following remarks in our national capacity. My delegation believes that capacity building is the foundation for the effective implementation of the entire United Nations framework on the responsible behavior of states in cyberspace. without human institutional technical and legal capacities at the necessary level states and particularly developing countries cannot fully participate in the collective efforts that seek to promote a safe, stable, secure, accessible cyber environment for my delegation capacity building needs to be guided by needs expressed by states and be part of a long -term inclusive and results -oriented approach. Assistance programs need to be developed in collaboration with beneficiary countries in order to ensure their national ownership and their effectiveness. Madam Chair, the DRC underscores the need to strengthen national capacities in a number of priority areas. These include the developing national cybersecurity strategies training, or rather developing adapted legal and normative frameworks, strengthening national response teams, fighting cybercrime, and training for public officials, law enforcement agents, and others. It is with this in mind that we adopted our national digital plan and this policy document includes 69 priority projects with around four pillars, including infrastructure use, governance. This has led us to establish an agency for the development of digital technologies. We have ratified a digital code. We also have a national cybersecurity strategy and other projects that are today operational. My delegation also attaches. Particularly, we have a national cybersecurity strategy and other projects that are today operational. We have a national cybersecurity strategy and other projects that are today operational. The development of skills, investing in training, research, higher education, talent development. This is all essential to ensuring developing countries to have long -term national expertise and to fully participate in international discussions on ICT issues. In this regard, the DRC supports initiatives that seek to establish a United Nations fellowship program for cybersecurity, which is meant to facilitate knowledge transfer, develop technical expertise, and ensure the participation of developing countries in the work of the global mechanism. We also support the swift operationalization of the global cooperation and capacity -building mechanisms. We also support the capacity -building portal for ICT security, which… will align countries’ needs with offers of assistance, it will improve coordination of various initiatives, and it will promote a more equitable distribution of the available resources. We would like to thank and commend the government of Singapore with its fellowship program for member states, as well as the remarkable work carried out by UNIDIR in order to support states’ capacities through its fellowship program for women in the AI sphere and the various tools that it provides. The DRC believes that capacity building must also promote regional and south -south cooperation. Regional organizations such as the AU and regional economic commissions play an essential role in sharing good practices. Developing joint… Training programs and sharing technical resources. These… initiatives are a useful complement to efforts at the international level. To conclude, the DRC remains fully engaged alongside all member states to ensure that capacity building remains a priority within the global mechanism so that all countries, without exception, can participate effectively, equitably, and in a lasting manner in the governance of international cybersecurity. We look forward to seeing how, despite the liquidity crisis the United Nations is going through, this pillar will be made operational in a practical sense. Thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Ukraine, to be followed by Japan, Australia, the Bahamas, and Ghana.
—
Ukraine
Thank you, Chair. Ukraine aligns itself with the statement delivered earlier by the European Union and would like to add some points in our national capacity. First, as many other states, particularly in reference to the statements delivered earlier in the morning, for example, by Australia, Malaysia, OEC in a regional perspective and others, Ukraine recognizes the strong connection that exists between confidence -building measures and capacity -building. To our understanding, joint exercises, both tabletop and capture -the -flag, contribute greatly to both. As well as the Women in Cyber Fellowship, the UN -Singapore Cyber Fellowship, the work of UNIDIR, the activities conducted within the OEC, the support in human capacity -building were received from Canada, Denmark, France, Germany, Estonia, and others. On the national level, Ukraine has started the Women in Cyber Security Program, and the UN has been working closely with the UN to develop and implement the program. The UN has been working closely with the UN to develop and implement the program. our side is ready to cooperate with other states in this regard. It is worth noting that the most recent CTF competition held in Ireland had a 100 % female team from Ukraine that took part, as well as it was noting the mutually beneficial cooperation with Poland in the field of promoting cybersport. We also attach great importance to bilateral cyber dialogues. We see them as a valuable tool for both capacity and confidence building. Such dialogues help to both exchange experiences and shape the expectations from each other. On our path to joining the European Union, we continue to deepen cooperation with the European Union in cyber defence, protection of critical infrastructure, crisis response, cyber diplomacy, countering hybrid threats, and the development of new technologies. We are in alignment with the European cyber security standards. In turn, Ukraine contributes unique frontline experience. acquired while defending ourselves against the persistent cyber -aggression by a certain P5 member. We practice the similar approach to our partners outside of the EU. Second, global mechanism as a capacity -building tool in itself. We see DTGs as a tool for the capacity -building for government representatives, allowing them to benefit from the best and the most relevant expertise that can contribute to the inclusivity of the decision -making process. For the record, Ukraine did not exercise the right of veto this time, although we have our reservations. Particularly, we consider as irrelevant to the purpose of the DTGs the presence among the stakeholders of the government -sponsored entities, the primary purpose of which is to explain their government’s position. We believe that governments should explain their position themselves in the government. We will continue to do so in the course of plenary sessions. In this respect, and due to a significant… number of the VTUD stakeholders. We invite the Chairpersonship and the Secretariat to consider reserving time for the thematic workshops in the course of December session, so the willing majority could benefit from the broadest available expertise, as well as to determine the possibilities to engage the additional expertise on the national level. Third, the infrastructural capacity building. In this respect, it is important to highlight the work of the Tallinn Mechanism, which has become the leading platform for coordinating civilian cyber assistance to Ukraine. Through coordinated international support, it has played a crucial role in maintaining essential public services and strengthening the resilience of Ukraine’s digital infrastructure under the cyber aggression. The Tallinn Mechanism demonstrates how practical international cooperation can produce tangible results and offers a valuable model for future international efforts to enhance cyber resilience. Having said that, Ukraine is committed to ensuring reiterates the intent to further engage in the constructive manner in the capacity-building activities within the global mechanism and beyond. Thank you.
—
Chair Egriselda López
Thank you very much. Japan has the floor.
—
Japan
Thank you, Madam Chair. Japan attaches great importance to capacity -building. Japan believes that capacity -building is a fundamental tool for fostering common understandings of international law and norms as well as confidence -building measures among member states. It is also an essential tool for strengthening cyber resilience in the international community as a whole. Madam Chair, in this context, let me touch upon a couple of Japan’s efforts in the Indo -Pacific region. Japan is providing multi -layered and comprehensive assistance through practical exercises conducted by the Japan ASEAN Society for Cybersecurity Capacity Building Center. AJCCBC, and issue specific seminars to enhance capabilities in international law and policy, among other initiatives. In addition, Japan, in collaboration with the U .S. and EU, hosts the Industrial Control Systems Cybersecurity Week for the region every year, offering hands -on training, workshops, and seminars led by experts from Japan, the U .S., and the EU, as well as networking among participants. Madam Chair, discussing capacity building in the global mechanism, we believe it is important to take into account the needs of each member state’s draw on the expertise of the private sector, and through information sharing and coordination among relevant countries, eliminate duplication and wasting assistance. From this perspective, with regard to DTG2, we believe it is important to move forward in a way that realizes efficient and effective capacity building by securing the participation and proposals of a wide range of stakeholders, including the private sector. Madam Chair, aiming to maintain and develop a free, fair, and secure cyberspace, Japan will engage actively and constructively in discussions in the global mechanism,
—
Chair Egriselda López
Thank you very much. I now give the floor to Australia.
—
Australia
Thank you. Thank you, Chair. Australia aligns with the statement delivered by Tonga on behalf of the Pacific Islands Forum. If there is one lesson from the OEWG and the GGEs, it is this. that a framework is only as strong as our ability to implement it. Norms, law and confidence building measures don’t implement themselves. People implement them. Institutions implement them. Capability implements them. And that is why cyber capacity building remains indispensable to international peace and security. And it’s why the creation of DTG2 is one of the most important innovations in our new mechanism. A dedicated forum focused not only on discussing capacity building, but accelerating it, coordinating it and making it more effective. The challenge before us is not a lack of goodwill, expertise or programs. The challenge is how to bring together a mature but fragmented ecosystem of states, regional organisations, international organisations, development partners, industry, academia and civil society and turn it into something great. Greater than the sum of its parts. That should be our ambition for DTG2. Australia sees three priorities. First, we need to listen better. Capacity building starts with examining our assumptions and understanding the needs identified by states and by communities themselves. The OEWG repeatedly recognise that there is no one -size -fits -all or all -one -size -fits -none approach to cyber capacity building and that efforts must be tailored to national circumstances and national priorities. DTG2 should become a platform where states can openly discuss challenges to implementation of our framework, share lessons learned and help us collectively understand where the most urgent gaps remain. Second, we need to connect better. Many of the solutions already exist. Around the world, governments, development agencies, regional organisations, the private sector, academia and civil society are delivering high -quality cyber capacity building programs every day. Too often, however, those seeking support don’t know where to find it. and those offering support do not always know where it is most needed. Good ideas remain disconnected from funding, from expertise or from the implementation partners. DTG2 has a unique opportunity to help bridge those gaps. Through the Capacity Building Roundtable, through stakeholder engagement and through DTG2 itself, we can become a platform for coordination and for sustainable partnership. Not duplicating existing efforts and not competing with them, but connecting them. Third, we need to build regionally. The most successful capacity building is often regional, built on shared experiences, shared challenges and shared trust. The Pacific knows this, ASEAN knows this, the African Union knows this. Australia believes that DTG2 should actively amplify regional initiatives, not because regional work is an alternative to global cooperation, but because it’s one of the strongest foundations for it. Chair, perhaps the most important thing and an important lesson from our previous processes is that cyber capacity building is a strategic investment in collective security. When one state becomes more resilient, we all become more resilient. And that’s why Australia has invested consistently in gender -responsive, rights -respecting and evidence -based cybercapacity building across our region. And it’s why we’ll continue to do so. As this mechanism begins its work, Australia stands ready to work with all states, all regions and all stakeholders to ensure that we deliver
—
Chair Egriselda López
Muchas gracias. Thank you. I now give the floor to the Bahamas.
—
Bahamas
Madam Chair, the Bahamas aligns itself with the statement delivered on behalf of Caribbean community CARICOM and offers the following remarks in its national capacity. As reflected in that statement, sustained demand-driven capacity building remains essential to closing our region’s gap in cyber resilience, including cyber legislation, workforce development, and the protection of critical infrastructure. For the Bahamas, capacity building is a central pillar of our national cybersecurity strategy and the foundation on which effective implementation of the UN Framework for Responsible State Behavior depends. We speak from recent experience. CertBS, our National Computer Incident Response Team, was formally launched in December 2023 with a small team and a broader national mandate. Our establishment has reinforced an important lesson. Capacity building is more effective when it’s tailored to the reality of the recipient. For new and emerging certs like the Bahamas, this means targeted role-specific training aligned with the maturity of the national team and delivered in ways that strengthens capacity without disrupting day-to-day operations. Structured maturity model provides a practical roadmap, enabling teams to progress. From foundational incident response to more advanced operational services. We also emphasize the importance of building capacity beyond the technical communities. Policy and senior decision makers must understand cyber risks so that they can advance legislation, strengthen governance, prioritize the protection of critical infrastructure, and provide the strategic leadership needed to build national resilience. Leadership-level capacity building is what transforms technical capacity into national action. Madam Chair, capacity building should also create opportunities for exposure and collaboration. Placing developing technical teams alongside more mature, experienced counterparts through staff exchange, study visits, mentoring, and joint exercise accelerates learning in ways that formal training alone cannot. Moreover, small island development states need capacity building that includes emerging technologies such as AI to ensure that we grow with the evolving state of technology. We encourage the global mechanism to promote these practical peer-to-peer partnerships. The Bahamas has benefited greatly from the support of a wide variety of regional and international partners whose investment has been instrumental in strengthening our national cybersecurity capacity. We are deeply grateful for their partnership, generosity, and continued commitment to our development. Personally, I have also experienced over the last two weeks the value of international capacity building through the WIC program. I extend my sincere thanks to its donors, organizers, facilitators, mentors, and my fellow WIC fellows. It is this testament that sustained investment in people creates lasting national and international impact. Finally, Madam Chair, the Bahamas is committed to the practical implementation of capacity-building initiatives and to working closely with regional and international partners to maximize their impact. We believe that sustainable cybersecurity begins with people. Building a resilient digital framework requires long-term investment in education, awareness, leadership, workforce development. Through initiatives such as our annual cybersecurity conference and our CyberShark Capture the Fly competition that’s hosted next month, Our national cyber hygiene school roadshow and targeted training for policymakers, women and youth, we are laying the foundation for sustainable cybersecurity workforce and for strengthening resilience across our nation and our region. The Bahamas stands ready to share its CERT establishment journey with member states beginning with, sorry, let’s start that again. The Bahamas stands ready to share its CERT establishment journey with member states who are beginning their own and to support a capacity building agenda that is practical, sustainable, demand driven and responsive to the needs of small island development states. Thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much. I now give the floor to Ghana. They will be followed by Bosnia -Herzegovina. China, Ireland, Malaysia and Cameroon.
—
Ghana
Madam Chair, Ghana aligns itself with the statement of the African Group and delivers the statement in its national capacity. Ghana recognises capacity building as a cornerstone of the cumulative and evolving framework for responsible state behaviour in the use of ICTs. It enables states to prevent, detect, respond to and recover from cyber threats while participating meaningfully in international cooperation. In this regard, we welcome the establishment of the Global ICT Security Cooperation and Capacity Building Portal, the UN Voluntary Fund and the Fellowship Programme and encourage dialogue. We encourage further early operationalisation alongside continued support for national security. cyber exercises and the global point of contact directory for capacity building to be effective it must be needs driven nationally owned and tailored to each country’s context priorities and level of cyber maturity there is no one -size -fits -all approach national priorities should guide the design and delivery of capacity building programs to ensure long -term impact and sustainable resilience capacity building should also extend beyond technical training it shall strengthen institutions leadership and human capital across government law enforcement and diplomacy academia and the private sector while fostering collaboration across technical, legal, policy, and operational communities. Ghana further underscores the importance of mainstreaming gender across all capacity -building initiatives. Increasing opportunities for women through training, mentorship, fellowship, and leadership programs is essential to building a more inclusive and resilient cybersecurity ecosystem. In this regard, Ghana commends initiatives such as the UNIDIR Women in Cyber Fellowship, of which I am a fellow, and the HESCYBER Tract, which have expanded opportunities for women from developing countries to contribute to the development of cybersecurity. Ghana contributes meaningfully to national, regional, and global cybersecurity discussions. Ghana remains grateful to the organizers and partners and sponsors for the continued support and engagement on these capacity -building programs. We also welcome the continued emphasis on South -South, Triangular, and Regional Cooperation, which complements North -South partnerships by providing peer learning, knowledge exchange, and the sharing of practical experience. Regional organizations remain important partners in strengthening institutional capacities and supporting implementation. Finally, Ghana recognizes the valuable contributions of the private sector, academia, civil society, and the technical community. Multi -stakeholder partnership. will be essential to ensuring that no country is left behind. Ghana remains committed to working with member states and all stakeholders to advance an inclusive, sustainable and action -oriented capacity building under the global mechanism. Thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to Bosnia Herzegovina.
—
Bosnia and Herzegovina
Thank you, Madam Chair. While we align with the statements of the European Union, I would like to add some observations in my national capacity. For Bosnia Herzegovina, cyber capacity building is vital and must remain a central pillar under the global mechanism complementing bilateral, regional and multi -stakeholder efforts. The relevance of capacity building has only increased due to the rapidly evolving threat landscape. The growing sophistication of malicious ICT activities serve as a constant reminder that cyberspace is deeply interconnected and that all states share exposure to this risk. In light of these realities, capacity building is no longer a matter of choice but a collective responsibility. Some of the constraints countries face in building cybersecurity capabilities are well known, such as lack of technical expertise, gaps in institutional frameworks, and limited access to advanced technologies. Yet, these challenges manifest differently across national contexts, shaped by each state’s unique legal, institutional, and socioeconomic environment. It is precisely for this reason that our discussion today is held. Our discussion must address two necessary considerations. First, efforts must ensure inclusivity so that all member states, regardless of their level of resources, can benefit from coherent and coordinated support. Second, capacity building must be guided by effective partnership, matching the right needs with the right expertise. In this regard, Bosnia -Herzegovina deeply appreciates the ongoing support from its international partners, particularly the European Union and its member states, which directly contributes to capacity building projects and progress in my country. Madam Chair, for state resilience to be truly effective, capacity building must be sustainable rather than ad hoc. We need long -term strategies that invade skills and institutional memory, ensuring capabilities are not only built but maintained as threats evolve. Furthermore, this process must be fully inclusive, engaging governments, the private sector, academia and civil society. We need efforts for Bosnia -Herzegovina integrating a gendered perspective and a shared vision. This is essential. My presence here today reflects our strong commitment to women’s leadership and equal representation in cyber diplomacy. Finally, looking ahead, we will continue to strongly support work of this pillar, as capacity building remains critical to turning agreed norms into practice and strengthening our shared resilience. Thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to China.
—
China
Thank you, Madam Chair. China supports that within the UN framework to strengthen capacity building and related international cooperation. With support, the formation of DTG2 and the hope that the first biennial meeting will make substantial gains with respect to the capacity building and related international cooperation. With support, the formation of DTG2 and related international cooperation. China believes that the international cooperation in capacity building should be action -oriented, should be able to create fair, equal and non -discriminatory environment and carry out the international cooperation in this field should respect the sovereign right and digital right of each country. And the countries in the global south must not be coerced to choose sides in this cooperation. Relevant cooperation should not come with conditions especially. There should not be a condition for international cooperation in capacity building by excluding the international cooperation in capacity building. There should not be a condition for international cooperation in capacity building by excluding certain products from certain countries. countries have the right to choose independently their digital and technical products based on their own conditions but without the right to choose there will not be digital sovereignty last week China held the 2026 International AI Conference and announced the formation of the international corporation organization which is composed of the 29 founding member states the establishment of this organization is China’s action to respond to the call from the global south to unite the international community to promote the development and the promotion of international AI technology China’s President Xi Jinping announced that in order to support the international AI development and the capacity building in international AI in the next five years, China will provide 5 ,000 AI fellowships to the developing countries and to create new momentum for the digital cooperation in the digital world. These actions not only will be helpful to help the Global South to fill their digital gap, but will be also beneficial to increase the abilities of the countries to be empowered in terms of AI security. So the AI empowered the safer cyberspace. Thank you, Chair.
—
Chair Egriselda López
Thank you I now give the floor to Ireland and will be followed by Malaysia
—
Ireland
Thank you Madam Chair Ireland aligns with the intervention made on behalf of the European Union and makes the following comments in our national capacity Closing the digital divide to ensure all states can harness the benefits of ICTs while mitigating global cyber risks through capacity Thank you, Chair. Thank you. We must work towards effective delivery of capacity building and the sharing of national best practices to help states implement the UN Framework of Responsible State Behaviour in their national and regional frameworks. Capacity building must be based on the needs identified by individual states, as many here have already said, and be country -driven. The limited resources available must be used in the most effective way possible, avoiding duplication. Again, as mentioned by many here, participation by many participants in the OEWG and now in the Global Mechanism has been assisted through various programmes, mostly organised through the UN with support from member states. These efforts must continue to ensure the broadest possible involvement of participants so that all contribute to our deliberations here and have their views reflected in how this process develops. Ireland supports the further development of a digital tool for state implementation of the UN framework building on the voluntary norms implementation checklist and the role of the global roundtable on capacity building and ensuring enhanced coordination and cooperation including matchmaking between regional priorities and donor offerings Discussions at DTG1 and DTG2 must be aligned so that the discussions at the first are reflected in the work undertaken in the second Discussions should also focus on the role of the multi -stakeholder community in the design and delivery of cyber capacity building ensuring effective coordination with the work being done by regional organisations ensuring the effective inclusion on women and youth in cyber capacity building efforts and generally work to mainstream the agreed ICT security capacity building guidelines as adopted in the 2021 OEWG
—
Chair Egriselda López
Thank you very much. I now give the floor to to be followed by Cameroon. And I hope we will still have time remaining for the next speakers, which would be Israel and Thailand.
—
Malaysia
Thank you, Madam Chair. Malaysia views capacity building as a crucial nabla of the UN Framework for Responsible Sleep Behaviour in the use of YCTs. Without adequate capacity, commitments relating to norms, confidence -building measures and international law cannot be effectively implemented. Given the different levels of cyber -maturity among states, capacity building remains essential to ensure that no state is left behind. It should therefore be practical, demand -driven and tailored to national circumstances. Malaysia has benefited from regional and international partnerships, including through ASEAN and partners such as Unidia in strengthening our cyber capabilities. Drawing from these experiences, Malaysia would like to highlight three considerations to guide future capacity building efforts under the global mechanism. First, capacity building should respond to concrete needs identified by states. It should move beyond awareness raising and support the development of capabilities that are relevant to national circumstances and priorities. For example, some states may require support in developing cyber legislation and policies, while others may need assistance in strengthening critical infrastructure protection. A one -size -fits -all approach may not deliver sustainable outcomes. Malaysia’s experience with the Malaysia -Unidia Cyber Capability Building Programme has demonstrated that the best results come from programmes designed. in close consultation with the beneficiary state. Second, we encourage greater focus on the protection of critical information infrastructure, which forms the backbone of our economies and societies. Given the cross -border nature of cyber threats, the global mechanism has an important role in supporting states to develop the necessary capabilities to address these shared challenges. Third, we see real values in ensuring closer alignment between the DTGs. If states continue to highlight difficulties in implementing the norm on critical infrastructure protection, capacity building activities should respond directly to the need. Scratch alignment will ensure that our work remains evidence -based and responsive to actual challenges. Madam Chair, capacity building is the basis, and it is the bridge between the agreed commitments. and effective implementation. By building this bridge according to the principles we have agreed upon, we can strengthen the ability of all states to benefit from and contribute to the global mechanism. Thank you.
—
Chair Egriselda López
Muchísimas gracias. Thank you very much. I now give the floor to the delegation of Cameroon.
—
Cameroon
One element among many of the global mechanism, it is the foundation upon which its success will ultimately be built. A framework without capacity remains an aspiration. Norms without the ability to implement them remain commitments. And cooperation without shared capabilities cannot deliver lasting results. This is why Cameroon believes that the success of the global mechanism would depend on its capacity to transform political commitments into practical outcomes. Particularly for states that require support to fully participate in shaping a secure, stable and peaceful ICT environment. Let me therefore begin by reiterating my delegation statement earlier this week. The global mechanism must ultimately be assessed by its ability to deliver meaningful and measurable results. Nowhere is this more important than the area of capacity building. Capacity building is the foundation upon which all other pillars of the framework depend. Without adequate technical, institutional, and human capacities, states cannot effectively implement norms apply international law, or participate fully in confidence -building measures. For developing countries, capacity building is therefore not an optional component of the global mechanism. It is the prerequisite for meaningful participation and sustainable implementation. In this regard, Cameroun welcomes the establishment of the dedicated thematic group on capacity building. We believe that this group should serve as a central platform for technical cooperation, peer learning and implementation, and the development of the global community. building on the valuable work already undertaken under the OEWG process. As mentioned by other member states, the DGJ should complement plenary discussions with more interactive and implementation -oriented formats, including expert -led technical workshops, country case studies, and peer -to -peer exchanges. These formats will enable member states to share experiences, identify common challenges, and develop solutions adapted to their respective national circumstances. The DGJ should focus on deliverables that provide practical support to member states. We would encourage the development of concise implementation guidance, a mechanism to facilitate greater alignment between national capacity -building needs and available expertise, technical assistance and support, as well as recommendations to strengthen coordination and resource, for capacity -building initiatives. Madam Chair, the success of DGT2 will depend on a genuine spirit of partnership, solidarity, and shared responsibility. Developed countries can contribute through technical assistance, expertise and resources. International and regional organizations can strengthen coordination and support implementation. The private sector and academia can provide innovation, specialized knowledge, and practical experience. At the same time, developing countries must continue to articulate their priorities clearly, strengthen national ownership, and make full use of the opportunities for cooperation offered by the global mechanism. Only through such a balanced, inclusive, and cooperative approach will the DGT2 be able to deliver lasting benefits for all member states. In conclusion, Madam Chair, Cameroon remains firmly committed to advancing the capacity -building pillar of the framework for responsible development. Thank you. We believe that a focused, inclusive and implementation -oriented digital tool can make a tangible contribution to strengthening national capacities, narrowing the digital divide and enhancing international cooperation. This vision is also rooted in a long -standing African understanding that the strength of a community is measured by its ability to uplift and empower all its members. In this spirit, capacity building is not only about sharing knowledge and expertise, it is about building collective resilience and shared prosperity. Cameroon stands ready to work with all delegations to ensure that DTG2 becomes a resource -oriented platform capable of of transforming our shared commitments into concrete progress and lasting benefits for all Member States. I thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much. I now give the floor to Israel.
—
Israel
Thank you, Chair, and I apologize. up front for being the one delaying everyone from their evening activities, but I’ll try to be very concise. Thanks, Madam Chair, for giving us the floor. The global growth, scale, and sophistication of cyber threats continue to challenge defensive capabilities worldwide. Cyber capacity building is not merely a supportive measure. It is a strategic imperative. It must be treated as a political neutral and practical endeavor placed at the very core of the global mechanisms mandate. Israel continues to actively champion global resilience through concrete, action -oriented initiatives. Our efforts focus on three key pillars. Cyber resilience, fostering international cooperation to protect critical infrastructure and mitigate cross -border systematic risks. Counter -ransomware cooperation, partnering with international allies, to combat ransomware through our joint technical exercises. rapid information sharing, and actionable cert -to -cert collaboration, and lastly, human capital and education. Investing heavily in grassroots cyber literacy, workforce development, and academic programs designed to build sustainable, long -term talent pipelines and vibrant cyber ecosystems. Madam Chair, one example we can provide to prove how capacity building is exercised in the international arena can be the crystal ball. The crystal ball platform and the CRI mentorship. These initiatives under the umbrella of the International Counter -Ransom Initiative, the CRI, Israel together with its partners developed and launched the crystal ball, which is a secure cloud -based platform to share threat indicators, analyze complex cyber attacks, and coordinate responses in real time. Israel also provides partners with training and mentorship programs to help build national, counter -ransomware capabilities. Additionally, Madam Chair, effective capacity building must be inherently needs -driven, flexible, and inclusive. Cyber resilience cannot be imposed through a one -size -fits -all approach. It requires actively listening to the specific developmental and operational priorities of recipient states. To succeed, we must also adopt a whole -of -society perspective, leveraging the technical expertise of all relevant stakeholders, and in particular, the tech community and academia. To maximize impact, the global mechanism must also serve as an effective coordinator. Rather than reinventing the wheel or duplicating already successful capacity building frameworks, our efforts should focus on mapping national needs, sharing best practices, and matching requirements with available resources. By promoting transparency and voluntary information sharing on capacity building programs, we can eliminate duplication, optimize resource allocation, and ensure assistance that the system reaches where it’s needed most. Israel stands ready to share from its vast experience based on its very robust cybersecurity ecosystem and assist the global mechanism in becoming a truly inclusive platform, a corner store for advancing resilience, cybersecurity, and responsible state behavior in the digital sphere. In a similar vein, Israel strongly supports prioritizing capacity building within the dedicated thematic groups. Capacity building offers us… It’s a unique space to generate tangible value, foster mutual confidence, and build operational trust, all while sidestepping political divides. Ultimately… It is through practical capacity building that our shared diplomatic consensus translates into real world protection on the ground. For these reasons, Madam Chair, capacity building remains not only a favorable focal point, but in our view can serve as an essential point of departure for the DTG’s agenda. I thank you.
—
Chair Egriselda López
Muchísimas gracias. Thank you very much. Right. We have used all the time available this afternoon. I know that it has been rather a long afternoon, but I do believe it has been a productive one. There are still 14 requests under this agenda item, and so we will hear the remaining speakers tomorrow. We are going to begin with the first three, Thailand, Saudi Arabia and the Philippines. That will be tomorrow morning. And let me remind you that tomorrow is our last. Meeting. We just have our meeting tomorrow morning, and so we will have to complete our work then. Once we have exhausted the list of speakers under this agenda item, we. the chair will deliver some remarks in order to set out the path forward. So, without further ado, I will see
The knowledge base references the ‘Global Mechanism on ICT security’ and its organisational sessions [S2] and [S139], as well as a ‘7th meeting – Plenary Session’ [S136], which is consistent with the report’s reference to an eighth meeting. The body’s full name aligns with references in the knowledge base to ‘Developments in the Field of Information and Telecommunications’ [S92].
2
This procedural practice is confirmed as a recurring chair instruction. [S141] records an identical request from the Chair at a prior plenary session: ‘The Chair requests that delegations consider delivering shorter versions of their statements and sending the full version to eStatements and the Chair’s team.’
3
[S218] confirms that ‘Cote d’Ivoire emphasizes the crucial role of capacity building in supporting the effective implementation of the Responsible Behaviour Framework’ and that ‘capacity building is essential to address the challenges faced by developing countries in implementing norms.’ [S119] also records Côte d’Ivoire taking the floor during the relevant agenda item.
4
[S222] records South Africa acknowledging that ‘member states have varying views on the nature of the framework for the future mechanism,’ which is broadly consistent with the report’s characterisation of South Africa’s position on differing capabilities and contexts. [S217] also notes that capacity building was widely seen as ‘a cross-cutting foundational element essential for effective implementation.’
5
[S147] confirms that ‘Multiple speakers emphasized the importance of capacity building, either as a dedicated thematic group or as a cross-cutting issue across all pillars.’ [S217] similarly notes ‘remarkable consensus’ on capacity building as ‘a cross-cutting foundational element.’
6
The knowledge base does not contain a direct record of Rwanda’s statement. However, [S139] records a closely parallel formulation from the organisational session of the Global Mechanism, stating that ‘capacity building as a key pillar of the global mechanism is essential to effectively address growing cyber threats and bridge existing gaps among states,’ which provides supporting context for the general argument attributed to Rwanda.
7
[S92] records Ecuador making a closely related point: ‘For my country, digital transformation is a priority, and that’s why we are decisively working on cybersecurity,’ reflecting the dual nature of digital transformation as both opportunity and risk, consistent with the framing attributed to Cote d’Ivoire in the report.
8
[S136] confirms that the 7th meeting plenary session ‘transitioned to the capacity’ building agenda item, and [S217] and [S218] both record substantive discussions on capacity building under the relevant agenda item, consistent with the report’s description of the eighth meeting’s focus.
Adoption of the agenda and organization of work— In summary, the Republic of Korea emerges as a supportive and engaged advocate for regulations that align closely with international human rights standards and the objectives of SDG 16, underscoring the importance of lea…
Closing Ceremony and Orientation for WAIGF 2025— – Kinyo Sawaboke: Communications Officer at National Information Technology Development Agency Audience: Good evening everyone. I am Abdul Idris, a Nigerian. I’m a program analyst from National Assembly Service. Thank y…
Adoption of the agenda and organization of work— Israel has been part of the process since its inception Israel’s consistently positive stance on various facets of the negotiations shows its constructive and proactive role in international policy formation. By endorsi…
Any other business /Adoption of the report/ Closure of the session— It becomes apparent that Israel is keen to play a constructive role in multilateral dialogues and is dedicated to contributing positively to international mechanisms that promote the rule of law, strong institutions, and…
Published by DiploFoundation (2011)— Malta: 4th Floor, Regional Building Regional Rd. Msida, MSD 2033, Malta Switzerland: Rue de Lausanne 56 CH-1202 Genève 21, Switzerland Serbia: Gavrila P. 44A Address Code 112410 11000 Beograd, Serbia E-mail: d…
(Day 2) General Debate – General Assembly, 79th session: morning session— Félix-Antoine Tshisekedi Tshilombo – Congo: President of the United Nations General Assembly, it is an immense honor for me to speak to you today for the first time since the Congolese people vested once again their …
Republic of Congo— Official UNOG website:https://www.ungeneva.org/en/blue-book/missions/member-states/democratic-republic-congo ThePermanent Mission of the Democratic Republic of the Congo to the UN Officeand other international organisat…
7th edition— Brazil has been one of the most countries in global digital politics and is the largest Internet market in Latin America. As a democratic and developing country with a vibrant digital space, Brazil has great poten…
Opening of the session— Brazil’s stance on a series of matters pertaining to human rights and the advancement of an international convention is markedly positive and aimed at fostering collaboration. The country firmly stands by Article 5, reco…
Framework Agreement of the Pacific Alliance— (4) Value Added Services are not those services in which for their establishment, operation or exploitation use is made of transmission infrastructure owned by the service provider, unless the service provider has the co…
The New Public Diplomacy— ‘to promote Canada as a good neighbor and reliable partner of the United States’. 22 Are there structural factors at work to support the role of Norway in such a ‘humanitarian superpower’ niche? Phrasing the …
What is the Foreign Ministry?— | | Foreign and Commonwealth Office (UK) Adaptive Diplomacy (2006) | Department of Foreign Affairs and International Trade (Canada) Int…
Adoption of the agenda and organization of work— Japan has actively engaged in the convention negotiation process, demonstrating a steadfast commitment to fostering an inclusive, transparent, and fair environment. This positive approach is reflected in Japan’s recent a…
Ad Hoc Consultation: Wednesday 31st January, Afternoon session— Overall, Japan appears to be a supportive and cooperative entity in international policy discussions, engaging constructively with various international proposals. Lack of specifics about the proposals, Japan’s reasons f…
Ad Hoc Consultation: Monday 5th February, Afternoon session— This careful attention to detail ensures a balance between national caution and international cooperation, reflecting Japan’s role as a conscientious and considered actor on the world stage. The summary accurately reflec…
(Day 2) General Debate – General Assembly, 79th session: morning session— Mokgweetsi Eric Keabetswe Masisi – Botswana : Mr. President, Excellencies, Distinguished Ladies and Gentlemen, I wish to start by extending my congratulations to you on your election as President of the General Assembl…
Agenda item 6— In conclusion, Botswana envisions the OEWG playing a crucial role in enabling the exchange of expertise and capabilities in a multi-stakeholder environment that is aligned with regional and national efforts. Such collabo…
Ad Hoc Consultation: Tuesday 30th January, Morning session— In the previous draft, ‘theft’ and ‘fraud’ were two separate articles. The ‘theft’ article was deleted, but was later amalgamated into the ‘fraud’ article, which is why ‘theft’ still appears. The Russian Federation suppo…
Ad Hoc Consultation: Monday 5th February, Morning session— Rwanda agrees with the title ‘countering the cybercrime’ Rwanda’s proactive efforts in seeking a transparent and concordant legal framework to counter cyber threats exemplify its role in fostering international justice …
(Day 6) General Debate – General Assembly, 79th session: morning session— Ernest Rwamucyo – Rwanda: At the outset, I would like to congratulate Ambassador Philemon Young on assuming the presidency of the 79th UN General Assembly and assure him of Rwanda’s full support. As we conclude the 7…
Ad Hoc Consultation: Monday 5th February, Morning session— The supporting facts for Tonga’s stance, albeit succinct, are unequivocally affirmative and propose precise modifications to the draft to optimise its content, signalling an and constructive participation in the p…
Acknowledgements— 2016). Tonga and the Solomon Islands have longstanding relations, with Tonga’s peace keeping mission support to the RAMSI (Regional Assistance Mission to Solomon Islands), which were ‘led and fund…
(Day 2) General Debate – General Assembly, 79th session: afternoon session— – Mohamed Irfaan Ali – Guayana: President of the Cooperative Republic of Guyana Leaders highlighted their countries’ specific development priorities and challenges. Mohamed Irfaan Ali of Guyana emphasized his country’s …
9821st meeting— – Guyana: Representative (role not specified)
Published by DiploFoundation (2011)— Malta: 4th Floor, Regional Building Regional Rd. Msida, MSD 2033, Malta Switzerland: Rue de Lausanne 56 CH-1202 Genève 21, Switzerland Serbia: Gavrila P. 44A Address Code 112410 11000 Beograd, Serbia E-mail: d…
UNITED NATIONS HANDBOOK 2019-20— As at 31 July 2019, 193 states were represented in the General Assembly. These states, together with their dates of admission to the UN, are: | Afghanistan .. .. .. .. .. .. .. .. .. .. .. | .. 19 Nov 1946 …
(Day 4) General Debate – General Assembly, 79th session: morning session— – Philip Edward Davis: Prime Minister and Minister for Finance of the Bahamas Climate change emerged as a dominant theme, with leaders emphasizing the urgent need for action and increased financing. Prime Minister Mia A…
The Role of Nigeria In Restoring Peace In West Africa— For instance, Nigeria is largely bordered in the South by Cameroon, which has similarities with some Nigerian villages. Yaounde is a name of town in the Nigeria’s border communities and same name is today given to the ca…
Ad Hoc Consultation: Friday 9th February, Morning session— By endorsing Egypt’s amendment, Cameroon is playing a key role in promoting transparency and efficient communication, pivotal for the smooth enactment of the document’s goals. In summary, Cameroon is proactively engaging…
UNITED NATIONS HANDBOOK 2019-20— As at 31 July 2019, 193 states were represented in the General Assembly. These states, together with their dates of admission to the UN, are: | Afghanistan .. .. .. .. .. .. .. .. .. .. .. | .. 19 Nov 1946 …
By the Same Author— Mauritius gained Independence in 1968, its freedom movement led by Sir Seewoosagur Ramgoolam, the first Prime Minister. The constitution is based on the British parliamentary model, with a ceremonial head of state, and e…
Agenda item 5 : Day 4 Afternoon session— Mauritius collaborates with regional and global partners, including Africa Cert, the Southern African Development Community (SADC), and ITU, on capacity-building projects. These collaborative efforts include organising c…
INTRODUCTION— A fundamental goal of scientific research is to improve the quality of life of people and the social context in which they live. In the near future, Artificial Intelligence (AI) will offer increasingly effective too…
Stefano Baldi Pasquale Baldocci— As for Italian history in general, Sergio Romano has written several titles in the area. Particularly important is his History of Italy from the Risorgimento to Today . Originally published in French in 1977 , it…
On the origins of World War I— Italy’s role in destroying the Congress of Berlin balance of power seems beyond dispute. The authors also blame Italy for being thefirst European power to use war as a means of reducing social tension at home. Indeed, Gi…
UNITED NATIONS HANDBOOK 2019-20— As at 31 July 2019, 193 states were represented in the General Assembly. These states, together with their dates of admission to the UN, are: | Afghanistan .. .. .. .. .. .. .. .. .. .. .. | .. 19 Nov 1946 …
Adoption of the agenda and organization of work— Furthermore, Uruguay is committed to ongoing diplomatic dialogue during informal consultations on Articles 5 and 24. It aims to be a constructive force in the refinement of the convention’s text, ensuring legal rigour an…
UNGA/DAY 1/PART 2— National identity:Uruguay is a small country with a deep vocation for peace and respect. Its political system is based on consensus, and its institutions are robust. The country is a “fraternal and hospitable land” for m…
Regional Leaders Discuss AI-Ready Digital Infrastructure— – Affiliation: Government of India[S10] – Role/Title: Country Director for India, Asian Development Bank (ADB) – Role/Title: Secretary, Ministry of Statistics and Programme Implementation, Government of India
AI Transformation in Practice_ Insights from India’s Consulting Leaders— -Affiliation:Government of India (Capacity Building Commission) -Affiliation:Not specified -Role/Title:Consultant, Capacity Building Commission, Government of India -Role/Title:Not specified (audience participant) -R…
Multistakeholder Partnerships for Thriving AI Ecosystems— – Role/Title: Audience participant (part of a German group; specific affiliation not specified)[S1][S2][S3] – Role/Title: Chairperson and CEO, Salesforce South Asia; Former Chairperson, State Bank of India[S16][S17]
Research Collection— 19 Based on the title of David D. Newsom’s article on the Swiss role in the hostage crisis, which was first published in a commemorative publication for Ambassador Probst: David D. Newsom, ‘The Sensiti…
UN: Summit of the Future Global Call— The analysis reveals Switzerland’s role as a proponent of international cooperation and dialogue. By supporting initiatives like the Summit of the Future and the Pact for the Future, Switzerland positions itself as a fac…
Panel Discussion AI in Healthcare India AI Impact Summit— -Affiliation:Invalude, Canton Broad, Switzerland[S4] -Affiliation:Not specified in transcript (moderator role)[S2] -Role/Title:India Relations Advisor at Invalude (innovation and investment promotion agency of Canton B…
Diplomacy, international intervention and post-War Reconstruction— The analysis of the peace operations in Bosnia and Herzegovina presented in this paper shows that the new international security environment with its transnational threats required international cooperation, role-sharing…
Multistakeholder Partnerships for Thriving AI Ecosystems— – Role/Title: Audience participant (part of a German group; specific affiliation not specified)[S1][S2][S3] – Role/Title: Parliamentary State Secretary at Germany’s Federal Ministry for Economic Cooperation and Developm…
By the Same Author— Germany is the world’s most decentralized large country, in political and socioeconomic structure. Its nearest comparison is the US, a continental landmass nation of a different order, and possibl…
UNITED NATIONS HANDBOOK 2019-20— * Original members, that is, those that participated in the UN Conference on International Organisation at San Francisco or had previously signed the UN Declaration of 1 January 1942, and that signed and ratified the Cha…
I. Multilateral institutions under adjustment pressure— China plays a special role in all international organizations. While China has formally declared its solidarity with the South, its behavior has traditionally been reserved, if not enigmatic. It may be no mor…
(Day 1) General Debate – General Assembly, 79th session: morning session— Cyril Ramaphosa – South Africa: Thank you, Your Excellency, the Chair of the Assembly. We take this opportunity to thank the United Nations Assembly to give us a chance to speak. Thirty years ago, South Africa was bor…
Ad Hoc Consultation: Thursday 8th February, Morning session— Speaking from a national perspective, the representatives communicated that they could fully endorse the Article. This strong endorsement indicates compatibility with national policies or a strategic international stance…
Adoption of the agenda and organization of work— Australia’s position suggests that safeguarding human rights is both a moral and a legal necessity, vital for maintaining treaty credibility and global trust. In cyber security deliberations, particularly concerning draf…
Closure of the session— For the past four years, France has been actively collaborating with a diverse group of states to lay the groundwork for a future Responsible Identification (RID) mechanism. With a single-track cycle of continuous improv…
The New Public Diplomacy— After Vichy came the Fourth Republic and then the Fifth, which is France’s current political and cultural incarnation. Of course it’s true that there is continuity underneath the change. The French people and Fr…
UNSC meeting: Strengthening UN peacekeeping— Serbia:Thank you, Mr. President. Thank you very much for convening this important meeting. Mr. President, distinguished members of Security Council, ladies and gentlemen, Serbia is a strong supporter of multilateralism a…
UNSC meeting: Multilateral cooperation for peace and security— Serbia:Mr. President, the world of today is faced with numerous and serious challenges that necessitate close cooperation by us all, as well as responsibility in quest for proper and applicable answers. Serbia considers …
(Day 1) General Debate – General Assembly, 79th session: morning session— Aleksandar VuÄiÄ – Serbia: Madam President, Excellencies, ladies and gentlemen, Mahatma Gandhi said, there is no path to peace. Peace is the path. In the same spirit of fraternal love and open heart, I address you …
Ad Hoc Consultation: Wednesday 31st January, Afternoon session— In summary, Vanuatu’s clear commendation for both the wording and the title of the text denotes a robust congruence with its stance, suggesting that the revisions have suitably incorporated changes that favour Vanuatu, e…
How Trust and Safety Drive Innovation and Sustainable Growth— and then we’re going to dive right into my immediate left. I have Alex Reed -Gibbons, who is the CEO of the Center for Democracy and Technology, one of the leading advocacy organizations in the world, working on civil ri…
Ad Hoc Consultation: Friday 9th February, Morning session— Singapore is actively engaged in the sphere of international law, particularly with regard to the treaty ratification process outlined in Article 64. The country has expressed a positive stance on the idea of raising the…
Ad Hoc Consultation: Friday 2nd February, Afternoon session— Ireland’s alignment with the EU highlights their commitment to collaboration and adherence to the EU’s stance on legal matters. Ireland’s nuanced handling of international law serves as a strategic, yet discerning, ende…
Acknowledgements— At the regional level, New Zealand, a metropolitan Pacific Islands and the closest neighbor to the PLG states, does not constitute the vulnerability criteria as a Pacific small island, but it plays an important role as a…
Ad Hoc Consultation: Monday 5th February, Morning session— New Zealand can support the U.S. proposal for the title and to remove the list of crimes in the final PP New Zealand can support the U.S. proposal for the title. Surprisingly, New Zealand shared Egypt’s unease concerni…
UNSC meeting: Strengthening UN peacekeeping— Argentina is one of the vice-chairs of C34 In this speech, Argentina reaffirms its commitment to United Nations peacekeeping operations and emphasises the need for a comprehensive approach to maintaining international p…
Adoption of the agenda and organization of work— Argentina reiterated its willingness to collaborate in consensus building In summary, Argentina’s diplomatic engagement and flexible approach to achieving consensus demonstrate their dedication to fostering cooperative …
UN: Summit of the Future Global Call— Cambodia:His Excellency Nangolo Mbomba, President of the Republic of Namibia. His Excellency Olaf Scholz, Chancellor of the Federal Republic of Germany. His Excellency Antonio Guterres, Secretary-General of the United Na…
(Day 5) General Debate – General Assembly, 79th session: morning session— Chenda Sophea Sok – Cambodia: Mr. President, Excellencies, Distinguished Delegates, Your chosen theme, Leaving No One Behind, Acting Together for the Advancement of Peace, Sustainable Development and Human Dignity for…
PREAMBLE— Cambodia has achieved complete peace and maintained territorial integrity, national unity, political stability, and socio-economic development, thanks to the win-win policy. The implementation of in-depth reform programs…
Ad Hoc Consultation: Thursday 8th February, Afternoon session— Indeed, they contend that the incorporation of such equivocal language compromises legal clarity—a cornerstone of International Law that could potentially lead to interpretive conflicts and discord. Moreover, Kiribati ha…
Ad Hoc Consultation: Wednesday 7th February, Afternoon session— Albania’s efforts epitomize its role as a collaborator and mediator in shaping progressive and inclusive legislative outcomes in international relations. In its role within the international community, Albania has adopt…
Ad Hoc Consultation: Friday 9th February, Morning session— These efforts reflect Albania’s dedication to upholding international standards and fostering effective partnerships that advance shared goals, highlighting its role as a cooperative and consistent participant in the rea…
Ad Hoc Consultation: Monday 5th February, Morning session— Albania has demonstrated a clear alignment with the United States on a variety of issues relating to the document under discussion during the chairing session. Notably, Albania concurs with the US regarding the document’…
DIPLOFOUNDATION UNIVERSITY OF MALTA— Côte d’Ivoire’s foreign policy and diplomatic alliances in the sub-region shifted further under the presidency of Laurent Gbagbo whose opposition to Taylor led to the formation of new alliances with anti-Taylor Liber…
The Russia-Ukraine War and Southeast Asia— 107. The West and NATO, in my view, were not uninvolved bystanders who had no role to play in the current situation. 126. One thing about Ukraine is clear though. Its defence has been nothing short of heroic against…
May, 2011— – The dramatic fall of the Shah’s empire with its strong domestic level of control, powerful army and notable external political and economic ambitions, which projected the Shah of Ian not only as the most …
6th meeting – Plenary Session— The knowledge base confirms that Egriselda López of El Salvador serves as Chair of the Global Mechanism on ICTs in the Context of International Security, and that the first substantive plenary session opened at UN Headqu…
Ad Hoc Consultation: Thursday 8th February, Morning session— Cuba has exhibited a proactive role in diplomatic negotiations, especially on issues pivotal to developing countries. The nation recognises the advancements in the dialogue, showing satisfaction with the current state of…
7th meeting – Plenary Session— Capacity building was identified as a cross-cutting enabler underpinning all pillars of the framework for responsible state behaviour, not merely a standalone pillar. It was described as the bridge between political comm…
Opening of the session— Capacity building should be needs-based, sustainable, and respect state sovereignty
Main Session | Best Practice Forum on Cybersecurity— Capacity building programs should be designed in consultation with recipient countries and shaped according to their specific needs, interests, and situations. This bespoke approach is more effective than untargeted or i…
Successes & challenges: cyber capacity building coordination | IGF 2023— Additionally, both donors and implementers could benefit from developing and adopting broader measurements of impact beyond individual projects. Insufficient domestic coordination is identified as a potential challenge i…
5th meeting Plenary Session— The Republic of Korea argues that the global mechanism should continue to serve as a platform for deepening understanding of the realities of cyberspace and for progressively developing common understanding of how existi…
3rd meeting – Plenary Session— How can cyber threat information sharing be made genuinely accessible to small island developing states and other developing countries with limited technical capacity? How can the global mechanism address the nexus betw…
Ad Hoc Consultation: Wednesday 31st January, Morning session— Nauru’s position is expressed with a neutral sentiment, indicating a realistic recognition of the country’s circumstances. As a developing nation, Nauru faces challenges due to inadequate technological capabilities and a…
Agenda item 6: other matters— Capacity building efforts should be tailored to the realities of small island developing states
Closure of the session/OEWG 2025— Capacity building is widely seen as a critical cross-cutting issue that should be addressed across all aspects of the future mechanism
WSIS women and girls trendsetters and action plan— This tension has clear policy background. WSIS and digital cooperation traditions emphasise multistakeholder collaboration, capacity development and practical exchange across actors[S104][S105]. At the same time, UN Wome…
Media Remuneration Policy Analysis Mitchell began by establishing her background and the context for CNTI’s work. Coming from 25 years at the Pew Research Center where she helped l…
A Clash of Professional Cultures: The David Kelly Affair— Finally, the following two quotes provide further background context in support of the policy-promoting rather than intelligence-sharing aims of the dossier. The first comes from an email from Danny Pruce (a Foreign Offi…
Masterclass#1— Gregor Ramus :Thank you very much, Melanie, and good day to everyone. It’s nice to see you. It’s the first time I’m part of this group, so I’m a newcomer. I have some slides. I hope the colleagues from Diplo can share th…
Main Session | Dynamic Coalitions— Small Island Developing States (SIDS) encounter specific obstacles in their digital development due to their unique characteristics. These challenges include limited resources, remoteness, and vulnerability to external e…
Addressing the Challenges of a Unified SIDS Digital Platform— Given the limitations of small island developing states in terms of size and resources, there is an argument for giving them special consideration. SIDS face unique challenges in actively participating in international d…
A view on digital divide and economic development— In many developing countries, this synergy is not verified, especially in the context of information and communication technologies (ICTs) as they continue to lack ICT infrastructure, capacities for protection and cybers…
Building a Digital Society, from Vision to Implementation— All speakers acknowledge that small island developing states face similar challenges including funding constraints, infrastructure limitations, and capacity building needs. They agree that collaboration and partnerships …
Agenda item 6: other matters— India: Thank you, Mr. Chair. The international community’s ability to prevent or mitigate the impact of malicious ICD activities depends on the capacity of each state to prepare and respond. Capacity-building is the…
7th meeting – Plenary Session— Argentina proposes a division of labour between the two DTGs, with DTG1 examining the operationalisation of CBMs through exchanging national and regional experiences and developing practical guidance, while DTG2 identifi…
2nd meeting – Plenary Session— All delegations addressing the reporting question agreed that a clear link between DTG work and the plenary is essential. Brazil called for ‘a clear procedure to elevate DTG’s report and negotiate the recommendations to …
4th meeting – Plenary Session— Africa continues to face an evolving ICT threat landscape, including malicious cyber activities targeting critical infrastructures, ransomware, online fraud, supply chain vulnerabilities, and the growing challenges of ar…
Opening of the session— Fiji, representing the Pacific Islands Forum, focused on capacity building as a foundational cross-cutting pillar enabling implementation across all framework areas. The Forum emphasized particular vulnerabilities of sma…
Agenda item 5 : Day 4 Afternoon session— Rwanda:Thank you, Chair. This being the first time that our delegation is taking the floor, Rwanda would like to express its appreciation to you and the Secretariat for your dedication in executing the mandate of the OEW…
UN OEWG 2021-2025 Final Report— a) Member States of the Global Mechanism are committed to engaging with other interested parties and stakeholders, including businesses, non-governmental organizations, and academia (henceforth “stakeholders”) in a sys…
6th meeting – Plenary Session— How can the mechanism establish regular virtual or hybrid engagement opportunities—such as quarterly or half-yearly meetings—to maintain meaningful stakeholder participation between formal sessions? on:Meaningful and in…
Global challenges for the governance of the digital world— Florian Martin-Bariteau:So consensus is very hard to achieve with such a diverse group, often starting from opposite views. But this is what makes global consensus more powerful, when all stakeholders and all regions can…
Welcome 2015 ‒ a year of cyber(in)security— Developing institutional and professional capacities is recognised in various forums as a precondition for successful implementation of confidence-building measures. Capacity building, however, goes beyond training sessi…
Dynamic Coalition Collaborative Session— Development | Sociocultural Rajendra argues that capacity building extends far beyond just technical skills to include changing mindsets, improving governance structures, and fostering collaboration across different dis…
Informal Stakeholder Consultation Session— -Capacity Building and Youth Engagement: Strong advocacy for localized, context-driven capacity building that goes beyond technical training to include policy literacy, leadership development, and meaningful participatio…
OEWG and Cybersecurity Negotiations at the United Nations— Expectedly, Russia, Iran, Cuba, and Pakistan underlined that there are gaps caused by unique attributes and the transnational nature of ICTs which could only be filled by the development of legally binding instruments. R…
United States International Cyberspace & Digital Policy Strategy— A persistent cyber threat, the Russian government is refining its cyber espionage, cyberattack, influence, and information manipulation capabilities to threaten other states and to weaken U.S. alliances and partnerships….
Agenda item 6— It was acknowledged that capacity-building solutions need to be tailored to address the specific challenges and vulnerabilities faced by individual states, including their technological, economic, and geopolitical contex…
Cyberspace Needs You: Attracting Women to Cybersecurity Careers— Dr. Cécile Aptel:So again, I think having working places that are inclusive, that are flexible enough to attract and retain women, that women feel that they belong there. But I think that some additional measures are nee…
7th meeting – Plenary Session— Capacity building as a cross-cutting prerequisite for effective CBM implementation: Delegations from developing countries, particularly from Africa, the Pacific, Latin America, and the Caribbean, stressed that capacity b…
Agenda item 5 : Day 4 Afternoon session— Capacity building underpins the implementation of the framework of responsible state behavior, including international law, norms, and trust-building.
Main Session | Dynamic Coalitions— Small Island Developing States (SIDS) encounter specific obstacles in their digital development due to their unique characteristics. These challenges include limited resources, remoteness, and vulnerability to external e…
Addressing the Challenges of a Unified SIDS Digital Platform— Given the limitations of small island developing states in terms of size and resources, there is an argument for giving them special consideration. SIDS face unique challenges in actively participating in international d…
Hybrid conference: The future of (multilateral) diplomacy— Are there any specific challenges faced by small and developing countries?These countries face additional challenges, including slow, sparse, or intermittent Internet access, poor telecommunications infrastructure, fragi…
Building a Digital Society, from Vision to Implementation— All speakers acknowledge that small island developing states face similar challenges including funding constraints, infrastructure limitations, and capacity building needs. They agree that collaboration and partnerships …
UN General Assembly 66th Plenary Meeting – WSIS Plus 20 High-Level Review— The Pacific Island Forum calls for enhanced technical cooperation and capacity building specifically designed for small island developing states. Many Pacific countries face constraints in deploying emerging technologies…
Agenda item 6— Key points and proposals discussed included the need for national ICT policies and strategies, robust ICT infrastructure, national certs or cyber agencies, societal awareness of ICT security, and tools and skills for ide…
Opening of the session— Capacity building interacts with other issues Capacity building is essential for political and institutional resource development. Ecuador is grateful for language on gender in capacity building being highlighted as cr…
Capacity Building Approaches Islamic Republic of Iran: Thank you, Mr. Chair. On CBMs, in paragraph 46L, we welcome the reference to facilitating equitable access for all states to the market for ICT security goods an…
Open Forum #60 Safe Digital Space for Children— Ahmad Bhinder: Thank you, Afrooz, so much. And OK, so let me start by saying a few words. I will not take much of your time. And then we would really go ahead and listen from all the experts panelists from here. So…
Young people's mental health in an online world— Both speakers challenged loose public use of addiction language. Niels said directly that ‘we need to stop using this term’ and that the issue is better understood through suffering and retention-oriented design rather t…
Ministerial Roundtable— Doreen Bogdan-Martin: infrastructure resilience and protecting cultural and linguistic diversity. And I’m also hearing this this push for continuous investment in inclusive digital access, digital literacy, education, a…
Agenda item 5 : Day 4 Morning session— Ghana:Mr. Chair, on this thematic area, Ghana supports the following additional CBMs. Cert-to-cert cooperation, cooperation between states on capacity building to close the digital divide, protection of critical informat…
Des voix africaines plus fortes dans le numérique— En ce qui concerne le renforcement des capacités, le Ghana a noté que de nombreux pays en développement ne disposent pas de capacités suffisantes en matière de cybersécurité, de cybercriminalité, de protection et de …
Stronger digital voices from Africa— On cybersecurity , Nigeria and Côte d’Ivoire highlighted the transnational nature of cybercrimes. Côte d’Ivoire pointed out that resolutely tackling cybercrime and other transnational threats will create a stable and res…
Capacity building is the foundation underpinning all five pillars of the Framework for Responsible State Behavior in ICTs.
Arg. 1
Explanation
The Republic of Korea reaffirms that capacity building is fundamental to the entire framework for responsible state behaviour in the use of ICTs. Without adequate policy, technical, legal, and operational capacity, individual states and the international community as a whole will be limited in their ability to respond effectively to cyber threats.
Evidence
The Republic of Korea stated that the absence of adequate policy, technical, legal and operational capacity will limit not only individual states’ ability to respond effectively, but also the international community’s broader efforts to enhance security .
Major Discussion Point
Capacity building as a foundational pillar of the ICT security framework
Agreed with
BotswanaRwandaMalawiCameroonGhanaAlbaniaKiribatiNew ZealandTongaMalaysiaGuatemalaSouth AfricaCote d'IvoireDemocratic Republic of the CongoAustraliaMarshall Islands
on: Capacity building is the foundational pillar upon which all other pillars of the ICT security framework depend
Capacity building must be demand-driven and tailored to the specific needs of recipient states, avoiding a one-size-fits-all approach.
Arg. 2
Explanation
The Republic of Korea emphasised that capacity building should not be driven solely by the priorities of providers, but should instead respond to the specific needs and priorities of recipient states. Close dialogue with partners is necessary to ensure that international capacity building efforts are effective, sustainable, and responsive.
Evidence
Korea stated that capacity building should not follow a one-size-fits-all approach, but should be demand-driven and tailored to the specific needs and priorities of recipient states, and that they remain committed to maintaining close dialogue with partners to ensure efforts are effective and sustainable .
on: Capacity building must be demand-driven, needs-based, nationally owned, and tailored to the specific circumstances of recipient states, avoiding a one-size-fits-all approach
Duplication of existing capacity building efforts should be avoided through enhanced coordination and complementarity.
Arg. 3
Explanation
The Republic of Korea stressed the importance of avoiding unnecessary duplication of existing capacity building efforts. Instead, states should seek to enhance coordination, complementarity, and efficient use of available resources.
Evidence
Korea explicitly stated that unnecessary duplication of existing capacity building efforts should be avoided and that coordination, complementarity, and efficient use of available resources should be sought .
on: Duplication of existing capacity building efforts must be avoided through enhanced coordination, complementarity, and efficient use of available resources
Disagreed with
CubaIslamic Republic of IranBrazilGermany
on: The scope of capacity building: whether it should include technology transfer and financial resources as binding commitments
The global mechanism should serve as an effective platform for promoting international cooperation on capacity building.
Arg. 4
Explanation
The Republic of Korea expressed its expectation that the global mechanism will serve as an effective platform for promoting international cooperation on capacity building and for strengthening coordination among member states. This includes looking forward to substantive and action-oriented discussions under DTG-2.
Evidence
Korea stated it looks forward to substantive and action-oriented discussion under DTG-2 and to the global mechanism serving as an effective platform for promoting international cooperation on capacity building and for strengthening coordination among member states .
Major Discussion Point
Role of the global mechanism in capacity building
128
WPM
443
Words
3 min
Time
Small island states demonstrate strong political will for cyber reform, but lack the resources and personnel to sustain national cyber institutions.
Arg. 1
Explanation
Nauru presented its own experience as evidence that political will is not the limiting factor for small states; rather, it is the lack of resources, technical expertise, and opportunities to build national capacities. Even with ambitious legislative and policy reforms underway, small states cannot staff, sustain, or grow the expertise their institutions require.
Evidence
Nauru described advancing its most ambitious cyber and digital reform programme in its national history, including a cybersecurity bill, digital transformation bill, data protection bill, and national cybersecurity strategy, all developed with ITU assistance . Nauru noted that a committed small state can draft laws, set strategies, and design institutions, but cannot alone staff them, sustain them, and grow the expertise they require, especially when officials carry several portfolios each .
Major Discussion Point
Challenges faced by small island developing states in cyber capacity building
Capacity building for small states must be cumulative, building on each engagement and developing local people rather than substituting for them.
Arg. 2
Explanation
Nauru argued that support delivered in fragments leaves only fragments behind. Effective capacity building must be phobia-cumulative, with each engagement building on the last, developing local people rather than substituting for them, and lasting beyond any single project cycle.
Evidence
Nauru stated that capacity building must be phobia-cumulative, with each engagement building on the last, developing their own people rather than substituting for them, and lasting beyond any single project cycle, warning that support delivered in fragments leaves fragments behind .
Major Discussion Point
Principles for effective and sustainable capacity building
Agreed with
MalawiCambodiaKiribatiTongaBosnia and HerzegovinaBahamas
on: Capacity building must be sustained over time and promote self-sufficiency rather than dependency, as single training events do not build institutions
DTG2 should move from principles to concrete programmes, including a clear mapping of needs and a user-friendly capacity building portal.
Arg. 3
Explanation
Nauru called on the dedicated thematic group on capacity building to move beyond principles and deliver specific, practical outputs. These should include a clear picture of where needs and existing support do and do not meet, and a capacity building portal designed for the official with limited time, not a well-resourced ministry.
Evidence
Nauru asked DTG2 for a clear picture of where needs and existing support do and do not meet, and a capacity building portal designed for the official with 10 minutes to spare, not the ministry equipped with a dedicated research team, as well as serious attention to sustainable financing .
Capacity should be treated as a cross-cutting thread running through every pillar of the global mechanism.
Arg. 4
Explanation
Nauru encouraged the cross-cutting thematic group to treat capacity as a thread running through every pillar of the framework, because for many states, capacity is the difference between endorsing the framework and actually living it.
Evidence
Nauru encouraged the cross-cutting group to treat capacity as a threat running through every pillar, noting that for many states it is the difference between endorsing the framework and living it .
Major Discussion Point
Capacity building as a cross-cutting issue
124
WPM
534
Words
4 min
Time
Cyber capacity building is a strategic imperative that must be placed at the core of the global mechanism's mandate.
Arg. 1
Explanation
Israel argued that cyber capacity building is not merely a supportive measure but a strategic imperative. It must be treated as a politically neutral and practical endeavour placed at the very core of the global mechanism's mandate.
Evidence
Israel stated that cyber capacity building is not merely a supportive measure but a strategic imperative that must be treated as a politically neutral and practical endeavour placed at the very core of the global mechanism’s mandate .
Israel's capacity building efforts focus on cyber resilience, counter-ransomware cooperation, and human capital development.
Arg. 2
Explanation
Israel outlined three key pillars of its capacity building approach: fostering international cooperation to protect critical infrastructure, partnering with international allies to combat ransomware through joint technical exercises and cert-to-cert collaboration, and investing in grassroots cyber literacy, workforce development, and academic programmes.
Evidence
Israel described its three key pillars as cyber resilience for critical infrastructure protection, counter-ransomware cooperation through joint technical exercises and rapid information sharing, and human capital and education through grassroots cyber literacy and workforce development .
Major Discussion Point
National capacity building initiatives and programmes
The Crystal Ball platform and CRI mentorship programme demonstrate practical international capacity building in action.
Arg. 3
Explanation
Israel provided the Crystal Ball platform as a concrete example of how capacity building is exercised in the international arena. Developed under the International Counter-Ransomware Initiative, it is a secure cloud-based platform for sharing threat indicators, analysing cyber attacks, and coordinating responses in real time, complemented by training and mentorship programmes.
Evidence
Israel described the Crystal Ball platform as a secure cloud-based platform developed with partners under the International Counter-Ransomware Initiative to share threat indicators, analyse complex cyber attacks, and coordinate responses in real time, alongside training and mentorship programmes to build national counter-ransomware capabilities .
Major Discussion Point
Concrete examples of international capacity building initiatives
Effective capacity building must be needs-driven, flexible, inclusive, and adopt a whole-of-society perspective.
Arg. 4
Explanation
Israel stressed that cyber resilience cannot be imposed through a one-size-fits-all approach. It requires actively listening to the specific developmental and operational priorities of recipient states and adopting a whole-of-society perspective that leverages the technical expertise of all relevant stakeholders, particularly the tech community and academia.
Evidence
Israel stated that effective capacity building must be inherently needs-driven, flexible, and inclusive, and that cyber resilience requires actively listening to the specific developmental and operational priorities of recipient states and adopting a whole-of-society perspective leveraging the technical expertise of all relevant stakeholders .
Major Discussion Point
Principles for effective capacity building
The global mechanism should serve as an effective coordinator, mapping needs, sharing best practices, and matching requirements with available resources rather than duplicating existing frameworks.
Arg. 5
Explanation
Israel argued that the global mechanism should focus on coordination rather than reinventing the wheel or duplicating already successful capacity building frameworks. By promoting transparency and voluntary information sharing on capacity building programmes, the mechanism can eliminate duplication, optimise resource allocation, and ensure assistance reaches where it is needed most.
Evidence
Israel stated that the global mechanism must serve as an effective coordinator, focusing on mapping national needs, sharing best practices, and matching requirements with available resources, and that promoting transparency and voluntary information sharing can eliminate duplication and optimise resource allocation .
Major Discussion Point
Role of the global mechanism in coordinating capacity building
Agreed with
Republic of KoreaGermanyAustraliaBrazilMauritiusIrelandNew ZealandUruguayJapanSingapore
on: Duplication of existing capacity building efforts must be avoided through enhanced coordination, complementarity, and efficient use of available resources
Capacity building offers a unique space to generate tangible value, foster mutual confidence, and build operational trust while sidestepping political divides.
Arg. 6
Explanation
Israel strongly supports prioritising capacity building within the dedicated thematic groups, viewing it as a unique space to generate tangible value and foster mutual confidence. Practical capacity building is how shared diplomatic consensus translates into real-world protection on the ground.
Evidence
Israel stated that capacity building offers a unique space to generate tangible value, foster mutual confidence, and build operational trust while sidestepping political divides, and that it is through practical capacity building that shared diplomatic consensus translates into real-world protection on the ground .
Major Discussion Point
Capacity building as a confidence-building measure
Capacity building is the foundation for the effective implementation of the entire UN framework on responsible state behaviour in cyberspace.
Arg. 1
Explanation
The DRC argued that without adequate human, institutional, technical, and legal capacities, states, particularly developing countries, cannot fully participate in collective efforts to promote a safe, stable, secure, and accessible cyber environment. Capacity building must be guided by needs expressed by states and be part of a long-term, inclusive, and results-oriented approach.
Evidence
The DRC stated that without human, institutional, technical, and legal capacities at the necessary level, states and particularly developing countries cannot fully participate in collective efforts to promote a safe, stable, secure, accessible cyber environment, and that capacity building needs to be guided by needs expressed by states and be part of a long-term inclusive and results-oriented approach .
Major Discussion Point
Capacity building as a prerequisite for framework implementation
Agreed with
Republic of KoreaBotswanaRwandaMalawiCameroonGhanaAlbaniaKiribatiNew ZealandTongaMalaysiaGuatemalaSouth AfricaCote d'IvoireAustraliaMarshall Islands
on: Capacity building is the foundational pillar upon which all other pillars of the ICT security framework depend
The DRC has adopted a national digital plan with priority projects across four pillars, including establishing a digital technology development agency and a national cybersecurity strategy.
Arg. 2
Explanation
The DRC described its national digital plan, which includes 69 priority projects across four pillars including infrastructure, use, and governance. This has led to the establishment of an agency for the development of digital technologies, the ratification of a digital code, and the development of a national cybersecurity strategy.
Evidence
The DRC described adopting a national digital plan with 69 priority projects across four pillars including infrastructure, use, and governance, leading to the establishment of an agency for the development of digital technologies, ratification of a digital code, and a national cybersecurity strategy .
Major Discussion Point
National capacity building initiatives
The DRC supports the establishment of a UN fellowship programme for cybersecurity to facilitate knowledge transfer and ensure developing countries' participation.
Arg. 3
Explanation
The DRC expressed support for initiatives to establish a United Nations fellowship programme for cybersecurity, which is meant to facilitate knowledge transfer, develop technical expertise, and ensure the participation of developing countries in the work of the global mechanism.
Evidence
The DRC stated it supports initiatives to establish a United Nations fellowship programme for cybersecurity to facilitate knowledge transfer, develop technical expertise, and ensure the participation of developing countries in the work of the global mechanism .
Major Discussion Point
UN fellowship programmes for cybersecurity
The DRC supports the swift operationalisation of the global ICT security cooperation and capacity building portal to align needs with offers of assistance.
Arg. 4
Explanation
The DRC expressed support for the swift operationalisation of the global cooperation and capacity building mechanisms, including the capacity building portal for ICT security. This portal would align countries' needs with offers of assistance, improve coordination of various initiatives, and promote a more equitable distribution of available resources.
Evidence
The DRC stated it supports the swift operationalisation of the global cooperation and capacity-building mechanisms and the capacity-building portal for ICT security, which will align countries’ needs with offers of assistance, improve coordination of various initiatives, and promote a more equitable distribution of available resources .
Major Discussion Point
Global ICT security cooperation portal
Agreed with
South AfricaMalawiGuyanaIndiaGhanaIslamic Republic of Iran
on: The operationalisation of the UN Voluntary Fund for ICT security capacity building and the Global ICT Security Cooperation and Capacity Building Portal are priority mechanisms for the global mechanism
Capacity building must promote regional and South-South cooperation, with regional organisations playing an essential role.
Arg. 5
Explanation
The DRC argued that capacity building must also promote regional and South-South cooperation. Regional organisations such as the African Union and regional economic commissions play an essential role in sharing good practices, developing joint training programmes, and sharing technical resources, complementing efforts at the international level.
Evidence
The DRC stated that capacity building must promote regional and South-South cooperation, and that regional organisations such as the AU and regional economic commissions play an essential role in sharing good practices, developing joint training programmes, and sharing technical resources as a useful complement to international efforts .
Major Discussion Point
Regional and South-South cooperation in capacity building
on: Regional cooperation and regional organisations play an essential role in effective capacity building and should be leveraged by the global mechanism
127
WPM
457
Words
4 min
Time
Building ICT security capacities is the foundation for countries to benefit sustainably from digital transformation while addressing security needs.
Arg. 1
Explanation
Brazil argued that building capacities in the field of ICT security is the foundation for countries to benefit in a sustainable way from digital transformation, which is a key enabler of socioeconomic development. The digital divide adds a central layer to this challenge, making international cooperation an urgent imperative.
Evidence
Brazil stated that building capacities in the field of ICT security is the foundation for countries to benefit in a sustainable way from digital transformation, a key enabler of socioeconomic development, and that the digital divide renders international cooperation an urgent imperative to expand the capacity of states to forge their resilience, mitigate risks, and respond to ICT incidents .
Major Discussion Point
Capacity building as a foundation for digital development
The United Nations must play a larger role in capacity building on ICT security, centralising information on existing initiatives.
Arg. 2
Explanation
Brazil argued that the United Nations must play a larger role in capacity building on ICT security. Centralising information on the many existing initiatives would facilitate access by those who need them most, and having the UN take part in those efforts ensures closer alignment with the priority issues identified by the membership and better compliance with capacity building principles.
Evidence
Brazil stated that the United Nations must play a larger role in capacity building on ICT security, that centralising information on existing initiatives would facilitate access by those who need them most, and that UN participation ensures closer alignment with priority issues identified by the membership and better compliance with capacity building principles .
Major Discussion Point
Role of the United Nations in capacity building
Disagreed with
CubaIslamic Republic of IranRepublic of KoreaGermany
on: The scope of capacity building: whether it should include technology transfer and financial resources as binding commitments
DTG2 should build upon the experience accumulated in the previous OEWG process, including the 2024 Global Roundtable and the Secretariat's mapping exercise.
Arg. 3
Explanation
Brazil emphasised that DTG2's work should not start from scratch but should build upon the experience accumulated in the previous process. This includes activities such as the 2024 Global Roundtable on ICT Security Capacity Building and the mapping exercise carried out by the Secretariat to survey the global landscape of capacity building programmes and initiatives.
Evidence
Brazil stated that DTG2 should build upon the experience accumulated in the previous process, including the 2024 Global Roundtable on ICT Security Capacity Building and the mapping exercise carried out by the Secretariat to survey the global landscape of capacity building programmes, noting that a clear, updated picture of what exists helps optimise synergies, avoid duplications, and promote systematic matchmaking .
Major Discussion Point
Building on previous OEWG work in DTG2
Agreed with
Republic of KoreaGermanyAustraliaIsraelMauritiusIrelandNew ZealandUruguayJapanSingapore
on: Duplication of existing capacity building efforts must be avoided through enhanced coordination, complementarity, and efficient use of available resources
Ensuring women and marginalised populations are included in the ICT security workforce must be treated as a substantive component of capacity building, not an afterthought.
Arg. 4
Explanation
Brazil highlighted that developing and retaining qualified personnel is an ongoing challenge, especially from a gender, race, and disability-sensitive lens. Ensuring that women and persons belonging to marginalised populations are duly qualified and effectively included in the ICT security workforce is essential to a more secure cyberspace and should be treated by DTG2 as a substantive component of capacity building.
Evidence
Brazil stated that developing and retaining enough qualified personnel is an ongoing challenge from a gender, race, and disability-sensitive lens, and that ensuring women and persons belonging to marginalised populations are duly qualified and effectively included in the ICT security workforce is essential and should be treated by DTG2 as a substantive component of capacity building rather than an afterthought .
Major Discussion Point
Gender and inclusion in capacity building
Agreed with
MalawiBotswanaMexicoCanadaSouth AfricaTongaUruguayAlbaniaGhanaBahamasMauritiusCote d'IvoireSerbiaBosnia and Herzegovina
on: Gender inclusion and the Women in International Security and Cyberspace Fellowship are essential components of effective and inclusive capacity building
Cybersecurity is a collective endeavour and vulnerability left unaddressed in one state is a vulnerability available to be exploited against all.
Arg. 5
Explanation
Brazil concluded by highlighting that the interconnected and transnational nature of cyberspace means that security is even more of a collective endeavour than in other arenas. No country can tackle threats in the digital domain in isolation, and a vulnerability left unaddressed in one state is a vulnerability available to be exploited against all.
Evidence
Brazil stated that no country can tackle threats in the digital domain in isolation, and vulnerability left unaddressed in one state is a vulnerability available to be exploited against all, and that the strategic importance of ICT security capacity building lies in the need to enhance systemic resilience and ensure confidentiality, integrity, and availability of digital ecosystem resources .
Major Discussion Point
Collective security and interdependence in cyberspace
130
WPM
304
Words
2 min
Time
Capacity building should be responsive to the needs, priorities, and context identified by states themselves, incorporating a gender perspective and promoting sustainability and national ownership.
Arg. 1
Explanation
Mexico argued that for capacity building initiatives to be truly effective, they must be designed around the needs and priorities identified by states themselves. They should incorporate a gender perspective, recognise differing levels of development, and promote sustainability, interoperability, and national ownership.
Evidence
Mexico stated that capacity building should be responsive to the needs, priorities and context identified by states themselves, and that to be truly effective, initiatives should incorporate a gender perspective, recognise differing levels of development, and promote sustainability, interoperability and national ownership .
Major Discussion Point
Principles for effective capacity building
Agreed with
MalawiBotswanaBrazilCanadaSouth AfricaTongaUruguayAlbaniaGhanaBahamasMauritiusCote d'IvoireSerbiaBosnia and Herzegovina
on: Gender inclusion and the Women in International Security and Cyberspace Fellowship are essential components of effective and inclusive capacity building
DTG2 has its own independent mandate for accelerating capacity building and should not be subordinate to or conditioned by DTG1.
Arg. 2
Explanation
Mexico emphasised that the Dedicated Thematic Group 2 has its own mandate for accelerating capacity building in the area of ICT security, and its work should not be understood as being subordinate to or conditioned by the first Dedicated Thematic Group. The two groups, together with the plenary, should complement each other to avoid duplication and generate practical, coherent outcomes.
Evidence
Mexico reiterated that DTG2 has its own mandate for accelerating capacity building in the area of ICT security and that its work should not be understood as being subordinate to or conditioned by DTG1, and that the two groups together with the plenary should complement each other to avoid duplication and generate practical, coherent outcomes .
Major Discussion Point
Role and mandate of DTG2
Disagreed with
FranceIrelandMalaysia
on: The relationship and hierarchy between DTG1 and DTG2
The mechanism should move beyond traditional donor-beneficiary categories towards a more horizontal, inclusive, and needs-based approach to cooperation.
Arg. 3
Explanation
Mexico argued that the focus of work should evolve beyond the traditional vision of assistance and cooperation. The mechanism should reflect the idea that all states can contribute knowledge, experience, and good practices, moving towards an approach that recognises providers of assistance rather than resorting to traditional categories such as donors and beneficiaries.
Evidence
Mexico stated that the mechanism should reflect the idea that all states can contribute knowledge, experience and good practices, and that it would be appropriate to move towards an approach that recognises the providers of assistance for capacity building rather than resorting to traditional categories such as donors and beneficiaries, fostering more horizontal, inclusive and needs-based cooperation .
Major Discussion Point
Rethinking the donor-beneficiary paradigm in capacity building
Predictable and sustainable financing is essential to enable all states to participate fully in capacity building activities.
Arg. 4
Explanation
Mexico considered it essential to ensure predictable and sustainable financing to enable all states to participate fully in capacity building activities. This includes support for fellowship programmes provided for in the modalities in order to expand access for developing countries.
Evidence
Mexico stated that it considers it essential to ensure predictable and sustainable financing to enable all states to participate fully in capacity building activities, and referenced the fellowship programme provided for in the modalities in order to expand the access of developing countries .
Major Discussion Point
Financing for capacity building
123
WPM
347
Words
3 min
Time
Canada supports UNIDIR's multi-year capacity building work in Southeast Asia as an example of effective national experience in capacity building.
Arg. 1
Explanation
Canada highlighted its support for UNIDIR's work in Southeast Asia as a concrete example of its national experience in capacity building. This multi-year project involves eight countries and brings together government entities, academia, civil society, and the private sector across the region.
Evidence
Canada described its support for UNIDIR’s work in Southeast Asia as a multi-year project involving eight countries – Thailand, Vietnam, Indonesia, Malaysia, Laos, Cambodia, Pakistan, and the Philippines – with workshops and training sessions bringing together a range of government entities, academia, civil society, and the private sector .
Major Discussion Point
National capacity building initiatives and programmes
Canada supports the Compendium of Good Practices on Gender Equality and Cybersecurity, demonstrating how gender-responsive approaches strengthen cyber resilience.
Arg. 2
Explanation
Canada expressed its support for the Compendium of Good Practices on Gender Equality and Cybersecurity, recently published by the Stimson Center and UNIDIR. The compendium shows how gender-responsive approaches can strengthen cyber resilience, improve governance, and contribute to more sustainable capacity building outcomes.
Evidence
Canada stated it was pleased to have supported the Compendium of Good Practices on Gender Equality and Cybersecurity, recently published by the Stimson Center and UNIDIR, noting that it shows how gender-responsive approaches can strengthen cyber resilience, improve governance, and contribute to more sustainable capacity building outcomes .
Major Discussion Point
Gender and inclusion in capacity building
Agreed with
MalawiBotswanaBrazilMexicoSouth AfricaTongaUruguayAlbaniaGhanaBahamasMauritiusCote d'IvoireSerbiaBosnia and Herzegovina
on: Gender inclusion and the Women in International Security and Cyberspace Fellowship are essential components of effective and inclusive capacity building
Effective capacity building requires strengthening relationships between donors, implementers, and beneficiaries through a co-creation approach.
Arg. 3
Explanation
Canada argued that one of the foundations of effective capacity building is collaboration, and that it is useful to strengthen relationships between donors, implementers, and beneficiaries. Each plays a distinct role in ensuring that capacity building efforts are tailored, effective, and sustainable, and co-creation means ensuring all three parties are aligned on the same goals.
Evidence
Canada stated that one of the foundations of effective capacity building is collaboration and that it is useful to strengthen relationships between donors, implementers, and beneficiaries, each playing a distinct role in ensuring that capacity building efforts are tailored, effective, and sustainable, and that co-creation means making sure these three players are talking about the same match before deciding how to play it .
Canada is enthusiastic about elaborating on good practices and co-creating capacity building approaches at DTG2 in December.
Arg. 4
Explanation
Canada expressed enthusiasm about the opportunity to elaborate on good practices and co-create on capacity building at the thematic group meeting in December. Canada indicated it would be able to share good practices in the area of co-creation for its Southeast Asia activities at DTG2.
Evidence
Canada stated it would be able to elaborate on good practices in the area of co-creation for its Southeast Asia activities at DTG2 in December, and expressed enthusiasm about elaborating on good practices and co-creating on capacity building at the thematic group in December .
on: The December DTG2 meeting must deliver concrete, practical, and measurable outputs rather than further discussion of principles
113
WPM
271
Words
2 min
Time
Capacity building is a fundamental tool for fostering common understandings of international law, norms, and confidence-building measures among member states.
Arg. 1
Explanation
Japan argued that capacity building is not only essential for strengthening cyber resilience in the international community as a whole, but also serves as a fundamental tool for fostering common understandings of international law and norms as well as confidence-building measures among member states.
Evidence
Japan stated that capacity building is a fundamental tool for fostering common understandings of international law and norms as well as confidence-building measures among member states, and is also an essential tool for strengthening cyber resilience in the international community as a whole .
Major Discussion Point
Capacity building as a confidence-building measure
Japan provides multi-layered and comprehensive capacity building assistance in the Indo-Pacific region through practical exercises and issue-specific seminars.
Arg. 2
Explanation
Japan described its capacity building efforts in the Indo-Pacific region, including practical exercises conducted by the Japan-ASEAN Cybersecurity Capacity Building Centre and issue-specific seminars to enhance capabilities in international law and policy. Japan also co-hosts Industrial Control Systems Cybersecurity Week with the US and EU, offering hands-on training and workshops.
Evidence
Japan described providing multi-layered and comprehensive assistance through practical exercises conducted by the Japan-ASEAN Society for Cybersecurity Capacity Building Center and issue-specific seminars, and co-hosting the Industrial Control Systems Cybersecurity Week for the region every year with the US and EU, offering hands-on training, workshops, and seminars led by experts .
Major Discussion Point
National capacity building initiatives and programmes
DTG2 should secure the participation and proposals of a wide range of stakeholders, including the private sector, to realise efficient and effective capacity building.
Arg. 3
Explanation
Japan argued that when discussing capacity building in the global mechanism, it is important to take into account the needs of each member state, draw on the expertise of the private sector, and through information sharing and coordination among relevant countries, eliminate duplication and wasting of assistance. For DTG2, Japan believes it is important to move forward in a way that secures the participation and proposals of a wide range of stakeholders.
Evidence
Japan stated that it is important to take into account the needs of each member state, draw on the expertise of the private sector, and through information sharing and coordination among relevant countries, eliminate duplication and wasting assistance, and that with regard to DTG2, it is important to move forward in a way that realises efficient and effective capacity building by securing the participation and proposals of a wide range of stakeholders, including the private sector .
Major Discussion Point
Multi-stakeholder participation in capacity building
Agreed with
Republic of KoreaGermanyAustraliaBrazilIsraelMauritiusIrelandNew ZealandUruguaySingapore
on: Duplication of existing capacity building efforts must be avoided through enhanced coordination, complementarity, and efficient use of available resources
Disagreed with
SwitzerlandUkraineCambodiaCuba
on: Whether stakeholders (non-governmental actors) should have a meaningful role in the dedicated thematic groups
Cyber capacity building is the fundamental pillar upon which the framework for responsible state behaviour rests, with an undeniable correlation between capacity gaps and digital vulnerabilities.
Arg. 1
Explanation
Botswana argued that cyber capacity building is not a secondary consideration but the fundamental pillar upon which the framework for responsible state behaviour rests. There is an undeniable correlation between a country's capacity gaps and its digital vulnerabilities, making the operationalisation of the dedicated thematic group on capacity building essential.
Evidence
Botswana stated that cyber capacity building is not a secondary consideration but the fundamental pillar upon which the framework for responsible state behaviour rests, and that there is an undeniable correlation between a country’s capacity gaps and its digital vulnerabilities .
Major Discussion Point
Capacity building as a foundational pillar of the ICT security framework
Agreed with
Republic of KoreaRwandaMalawiCameroonGhanaAlbaniaKiribatiNew ZealandTongaMalaysiaGuatemalaSouth AfricaCote d'IvoireDemocratic Republic of the CongoAustraliaMarshall Islands
on: Capacity building is the foundational pillar upon which all other pillars of the ICT security framework depend
DTG2 must prioritise concrete, needs-based support over a one-size-fits-all mandate, focusing on institutional readiness, legislative frameworks, and human capital development.
Arg. 2
Explanation
Botswana argued that the discourse of DTG2 must prioritise concrete, needs-based support over a one-size-fits-all mandate, while ensuring that national ownership remains at the heart of all initiatives. The group should focus on strengthening member states' institutional readiness, developing sound legislative and regulatory frameworks, building technical cyber defence capabilities, and investing in human capital through targeted cybersecurity education.
Evidence
Botswana stated that DTG2 must prioritise concrete needs-based support over a one-size-fits-all mandate while ensuring national ownership remains at the heart of all initiatives, and encouraged DTG2 to focus on strengthening member states’ institutional readiness, specifically in developing sound legislative and regulatory frameworks, building technical cyber defence capabilities, strengthening critical infrastructure resilience, and investing in human capital through targeted cybersecurity education .
Major Discussion Point
Priorities for DTG2
Agreed with
ItalyGhanaGuatemalaBahamasMauritiusAlbania
on: Capacity building must be inclusive and extend beyond technical training to encompass institutional development, policy support, workforce development, and awareness programmes
The global mechanism must work hand-in-hand with regional and sub-regional bodies to roll out capacity building initiatives, maximising resources efficiently.
Arg. 3
Explanation
Botswana firmly maintained that the global mechanism must work hand-in-hand with regional and sub-regional bodies to roll out capacity building initiatives. These organisations understand the unique political and physical challenges of their member states, and formally leveraging these regional hubs under the global mechanism will maximise resources efficiently.
Evidence
Botswana stated that the global mechanism must work hand-in-hand with regional and sub-regional bodies to roll out capacity-building initiatives, noting that these organisations understand the unique political and physical challenges of their member states very well, and that formally leveraging these regional hubs under the global mechanism will maximise resources efficiently .
Major Discussion Point
Regional cooperation in capacity building
Agreed with
AustraliaCote d'IvoireDemocratic Republic of the CongoGhanaGermanyGuyanaVanuatuNew ZealandKiribati
on: Regional cooperation and regional organisations play an essential role in effective capacity building and should be leveraged by the global mechanism
All capacity building efforts must systematically adopt a gender-sensitive perspective, as true cyber resilience cannot be achieved while a gender-digital divide persists.
Arg. 4
Explanation
Botswana reinforced that all capacity building efforts must systematically adopt a gender-sensitive perspective, arguing that true cyber resilience cannot be achieved while a gender-digital divide persists. Botswana expressed particular gratitude for the Women in International Security and Cyberspace Fellowship, which bridges the gender gap in global digital governance.
Evidence
Botswana reinforced that all capacity-building efforts must systematically adopt a gender-sensitive perspective and that true cyber resilience cannot be achieved while a gender-digital divide persists, and expressed particular gratitude to UNIDIR and its dedicated state partners for bridging the gender gap in global digital governance through the Women in International Security and Cyberspace Fellowship, of which Botswana is a proud beneficiary .
Major Discussion Point
Gender and inclusion in capacity building
Agreed with
MalawiBrazilMexicoCanadaSouth AfricaTongaUruguayAlbaniaGhanaBahamasMauritiusCote d'IvoireSerbiaBosnia and Herzegovina
on: Gender inclusion and the Women in International Security and Cyberspace Fellowship are essential components of effective and inclusive capacity building
Botswana acknowledges UNIDIR's sustained contribution to national capacity building, including through its international law programme and new regional liaison programme.
Arg. 5
Explanation
Botswana acknowledged and thanked UNIDIR for its sustained contribution to national capacity building initiatives, including through its international law programme which helps states develop national positions. Botswana also noted that UNIDIR's new regional liaison programme reinforces a shared commitment to the principles of capacity building.
Evidence
Botswana acknowledged and thanked UNIDIR for its sustained contribution to national capacity-building initiatives, including through its international law programme which helps states develop national positions, and noted that their new regional liaison programme reinforces a shared commitment to the principles of capacity-building .
Major Discussion Point
Role of international organisations in capacity building
146
WPM
812
Words
6 min
Time
Capacity building measures must be depoliticised, open, and carried out on the basis of respect for state sovereignty, without restricting countries' access to advanced ICTs.
Arg. 1
Explanation
The Russian Federation argued that practical, action-oriented recommendations for capacity building must meet the specific needs of the Global South in bridging the digital divide, and must be depoliticised and open. Any attempts to restrict countries' access to advanced ICTs or to increase their technological dependence on dominant states are unacceptable.
Evidence
The Russian Federation stated that capacity building measures must be depoliticised and open and carried out on the basis of respect for state sovereignty, and that any attempts to restrict countries’ access to advanced ICTs or to increase their technological dependence on dominant states are unacceptable, including the monopolisation of the ICT global market .
Major Discussion Point
Principles for capacity building and opposition to unilateral restrictive measures
Disagreed with
Islamic Republic of IranCubaChinaItalyUkraine
on: Whether unilateral coercive measures and technology access restrictions should be addressed within the global mechanism's capacity building agenda
Russia proposes conducting UN-auspiced drills on responding to computer attacks, focusing on real-time virtual competitions among national teams to build practical skills.
Arg. 2
Explanation
The Russian Federation presented an initiative to conduct drills on responding to computer attacks under the auspices of the United Nations. These would involve real-time virtual competitions among national teams on a training base, simulating responses to various types of malicious activities, with technical and diplomatic points of contact from the UN Global Intergovernmental Points of Contact Directory also participating.
Evidence
Russia announced an initiative to conduct drills on responding to computer attacks under UN auspices, describing them as real-time virtual competitions among national teams simulating responses to various types of malicious activities in accordance with a pre-prepared scenario, with technical and diplomatic points of contact from the UN Global Intergovernmental Points of Contact Directory also participating, assessed either in person or in a hybrid format using a rating system .
Major Discussion Point
Concrete capacity building initiatives proposed
Russia already has experience conducting international cyber drills and plans to work with the UN Secretariat to implement this initiative with Russia's financial, organisational, and methodological support.
Arg. 3
Explanation
The Russian Federation noted that it already has experience in conducting such exercises, with drills held on the margins of international events in Hanoi, Nizhny Novgorod, and St. Petersburg. Russia plans to work with the UN Secretariat to implement this initiative with its own financial, organisational, and methodological support.
Evidence
Russia stated it already has experience in conducting such exercises, with drills held on the margins of the signing of the UN Convention against Cybercrime in Hanoi in 2025, the Digitalization of Industrial Russia Conference in Nizhny Novgorod, and the ICT Crime 2026 Conference in St. Petersburg, and plans to work with the UN Secretariat on implementation with Russia’s financial, organisational, and methodological support .
Major Discussion Point
Concrete capacity building initiatives proposed
Russian universities offer thousands of training opportunities to students from developing countries in ICT security-related fields, and Russia is ready to establish mutually beneficial cooperation with interested countries.
Arg. 4
Explanation
The Russian Federation highlighted that several thousand students from Asia, Africa, the Middle East, and Latin America are currently studying in relevant specialised fields at Russian universities, including free of charge. Russia expressed readiness to establish mutually beneficial cooperation with interested agencies of other countries across the full range of issues relating to the training of foreign experts in information security.
Evidence
Russia stated that in Russian universities there are several thousand students currently studying in relevant specialised fields, including free of charge from Asia, Africa, the Middle East, and Latin America, covering specialisations such as information and computer security, methods for detecting and countering network computer attacks, and computer forensics, and expressed readiness to establish mutually beneficial cooperation with interested competent agencies of other countries .
Major Discussion Point
National capacity building initiatives and programmes
Russia organises annual international events dedicated to assisting developing countries in ICT security, including the Global Digital Forum and Kazan Digital Week.
Arg. 5
Explanation
Together with the private sector, Russia organises annual international events dedicated to assisting developing countries in the field of ICT security. These include the Global Digital Forum in Moscow, Kazan Digital Week, and the International Forum on Partnership of State, Business and Civil Society in Ensuring International Information Security.
Evidence
Russia stated that together with the private sector it organises annual international events dedicated to assisting developing countries in the field of ICT security, including the Global Digital Forum to be held in Moscow on October 8-10, Kazan Digital Week in September, and the 20th International Forum Partnership of State Business and Civil Society in Ensuring International Information Security in Moscow on September 22-24 .
Major Discussion Point
National capacity building initiatives and programmes
111
WPM
409
Words
4 min
Time
No state can address today's cyber challenges alone; collective security depends on strong cooperation, greater trust, and shared responsibility.
Arg. 1
Explanation
Rwanda emphasised that despite differing perspectives in discussions, one message emerged with clarity: no state can address cyber challenges in isolation. Collective security requires cooperation, trust, and shared responsibility, and the global mechanism provides an opportunity to translate this shared understanding into practical actions.
Evidence
Rwanda stated that no state can address today’s cyber challenge alone and that collective security depends on strong cooperation, greater trust, and shared responsibility, and that the establishment of the global mechanism gives the opportunity to translate that shared understanding into practical actions and results .
Major Discussion Point
Collective security and interdependence in cyberspace
Capacity building is the foundation upon which every other pillar of the framework depends, as without institutions, legal frameworks, and skilled professionals, commitments cannot be implemented.
Arg. 2
Explanation
Rwanda argued that capacity building is the foundational pillar of the global mechanism, upon which all other pillars depend. Without the necessary institutions, legal frameworks, technical expertise, and skilled professionals, commitments cannot be implemented, norms cannot be operationalised, and resilience cannot be strengthened.
Evidence
Rwanda stated that without the necessary institutions, legal frameworks, technical expertise and skilled professionals, commitments cannot be implemented, norms cannot be operationalised and resilience cannot be strengthened .
Major Discussion Point
Capacity building as a foundational pillar of the ICT security framework
Agreed with
Republic of KoreaBotswanaMalawiCameroonGhanaAlbaniaKiribatiNew ZealandTongaMalaysiaGuatemalaSouth AfricaCote d'IvoireDemocratic Republic of the CongoAustraliaMarshall Islands
on: Capacity building is the foundational pillar upon which all other pillars of the ICT security framework depend
Rwanda's own experience demonstrates that building cybersecurity capacity requires sustained investment, sound public policy, and strong national institutions, but national efforts alone are insufficient.
Arg. 3
Explanation
Rwanda drew on its own national experience to illustrate that building cybersecurity capacity requires sustained investment, sound public policy, and strong national institutions. However, Rwanda also acknowledged that national efforts alone are not enough, as cyber threats know no borders and international cooperation remains indispensable.
Evidence
Rwanda stated that its own experience has demonstrated that building cybersecurity capacity requires sustained investment, sound public policy and strong national institutions, but that national efforts alone are not enough, and that cyber threats know no borders, making international cooperation indispensable .
Major Discussion Point
National capacity building and the need for international cooperation
In many developing countries, the challenge is not a lack of commitment but a lack of resources, technical expertise, and opportunities to build national capacities.
Arg. 4
Explanation
Rwanda highlighted that for many developing countries, the barrier to effective cybersecurity is not political will but rather a lack of resources, technical expertise, and opportunities to build national capacities. Closing these gaps should be a collective objective, as the shared digital ecosystem will only be as resilient as the capacity of every state.
Evidence
Rwanda stated that in many developing countries the challenge is not a lack of commitment but a lack of resources, technical expertise and opportunities to build national capacities, and that closing these gaps should be the collective objective, as the shared digital ecosystem will only be as resilient as the capacity of every state to prevent threats .
Major Discussion Point
Challenges faced by developing countries in cyber capacity building
The global mechanism should ensure that capacity building remains practical and accessible to all states, building on the foundations laid by the OEWG.
Arg. 5
Explanation
Rwanda called for the global mechanism to ensure that capacity building remains practical and accessible to all states as it begins and continues its work. Rwanda also highlighted that the OEWG laid a solid foundation through initiatives such as the Global Points of Contact Directory, confidence-building measures, and the inaugural Global Roundtable on ICT security capacity building, which should be preserved and built upon.
Evidence
Rwanda highlighted that the open-ended working group laid a solid foundation through initiatives such as the Global Points of Contact Directory, confidence-building measures, and the inaugural Global Roundtable on ICT security capacity building, and called for these achievements to be preserved and built upon as new technologies continue to reshape the cyber landscape . Rwanda further stated that the global mechanism should ensure that capacity building remains practical and accessible to all states .
Major Discussion Point
Building on previous OEWG work and ensuring accessible capacity building
85
WPM
308
Words
4 min
Time
Ecuador is developing a national cybersecurity policy for 2026–2029 that includes international cooperation and cybernetic diplomacy as one of its seven pillars.
Arg. 1
Explanation
Ecuador described its ongoing development of a national cybersecurity policy for 2026 through 2029, aimed at building a resilient ecosystem and shared responsibility. One of the seven pillars of this policy is linked to international cooperation and cybernetic diplomacy, recognising the need to complement national capacity with knowledge, resources, and technical assistance.
Evidence
Ecuador stated that it is developing its national cybersecurity policy for 2026 through 2029, aimed at building a resilient ecosystem and shared responsibility, with one of its seven pillars linked to international cooperation and cybernetic diplomacy, recognising the need to complement national capacity with knowledge, resources, and technical assistance .
Major Discussion Point
National capacity building initiatives and policies
Capacity building must be sustainable, results-oriented, adequately financed, and inclusive of all stakeholders, including addressing emerging technologies such as AI and quantum computing.
Arg. 2
Explanation
Ecuador argued that capacity building must be sustainable, results-oriented, and equipped with adequate financing, while enjoying participation from a broad range of sectors and stakeholders. Ecuador also emphasised that capacity building initiatives should foresee the challenges of emerging technologies such as AI, quantum computing, and the Internet of Things, all of which have been incorporated into Ecuador's new national policy.
Evidence
Ecuador stated that capacity building must be sustainable, results-oriented, and equipped with adequate financing and enjoy participation from a broad range of sectors, and that initiatives should foresee the challenges of emerging technologies such as AI, quantum computing, and the Internet of Things, all of which Ecuador has incorporated into its new national policy .
Major Discussion Point
Principles for effective capacity building and emerging technologies
The dedicated thematic group on capacity building should promote indicators for assessing results, monitoring and follow-up mechanisms, and better coordination between states' needs and available cooperation offers.
Arg. 3
Explanation
Ecuador expressed particular importance for the dedicated thematic group on capacity building, arguing it should bring the mechanism closer to the realities of different countries and promote measures to help countries diagnose and address their challenges. It should also promote indicators for assessing results, monitoring and follow-up mechanisms, and better coordination between the needs of states and available cooperation offers.
Evidence
Ecuador stated that the dedicated thematic group on capacity building should bring the mechanism closer to the realities in different countries, promote measures to help countries diagnose and assist in their challenges, promote indicators for assessing results, monitoring follow-up mechanisms, and better coordination between the needs of states and the offers of cooperation that are available .
Major Discussion Point
Priorities for DTG2 and monitoring of capacity building
The thematic group should address risks associated with developing national capacity while avoiding duplication with other fora.
Arg. 4
Explanation
Ecuador argued that the dedicated thematic group should address the risks associated with developing national capacity and should avoid addressing issues that fall to other fora. This reflects a concern for efficiency and coherence in the global mechanism's work.
Evidence
Ecuador stated that the thematic group should address the risks associated with developing national capacity and should avoid addressing issues that fall to other fora .
Major Discussion Point
Scope and mandate of DTG2
140
WPM
372
Words
3 min
Time
Effective capacity building must be needs-based and country-driven, with the most effective partnerships being those that support a country's own direction rather than substituting their own priorities.
Arg. 1
Explanation
Tonga drew on its own national experience to argue that capacity building must be needs-based and country-driven, with priorities set nationally. The most effective bilateral, regional, and multilateral partnerships have been those that supported Tonga's own direction rather than substituting their own priorities.
Evidence
Tonga stated that capacity building must be needs-based and country-driven, with priorities set in Nuku’alofa and shaped by their own frameworks, and that the most effective partnerships have been those that supported their direction rather than substituting their own .
Major Discussion Point
Principles for effective capacity building
Agreed with
Republic of KoreaMalawiCambodiaBotswanaGermanyAustraliaCote d'IvoireMexicoKiribatiGhanaAlbaniaSerbiaArgentinaIrelandMalaysiaNew ZealandSouth AfricaVanuatu
on: Capacity building must be demand-driven, needs-based, nationally owned, and tailored to the specific circumstances of recipient states, avoiding a one-size-fits-all approach
Capacity building must be sustained over years, not weeks, as demonstrated by Tonga's response to a cyber attack on its health system succeeding because relationships and capabilities had been invested in over time.
Arg. 2
Explanation
Tonga provided a concrete national example to illustrate that capacity building must be sustained over time. The response to a cyber attack on Tonga's health system succeeded because the relationships and capabilities behind it had been invested in over years, not weeks, demonstrating that institutions like CERT Tonga were not built by single workshops.
Evidence
Tonga stated that institutions like CERT Tonga were not built by single workshops, and that the response to last year’s attack on their health system succeeded because the relationships and capabilities behind it had been invested in over years and not weeks .
Major Discussion Point
Sustainability of capacity building efforts
Agreed with
MalawiCambodiaKiribatiNaoeroBosnia and HerzegovinaBahamas
on: Capacity building must be sustained over time and promote self-sufficiency rather than dependency, as single training events do not build institutions
Capacity building must be inclusive, with stakeholder inclusion being not a procedural formality but the means by which capability reaches the people who need it.
Arg. 3
Explanation
Tonga argued that in a kingdom of some 170 islands, resilience is carried not only by government but also by communities. Stakeholder inclusion is not a formality of process for Tonga but rather how capability reaches the people who need it, and for this reason Tonga supports meaningful stakeholder participation in the work of the mechanism.
Evidence
Tonga stated that in a kingdom of some 170 islands, resilience is carried by government but also by communities, and that stakeholder inclusion is not a formality of process for Tonga but is how capability reaches the people who need it, and that for the same reason they support meaningful stakeholder participation in the work of the mechanism .
Major Discussion Point
Inclusive and multi-stakeholder approach to capacity building
The December DTG meeting is the first true test of whether the global mechanism can convert deliberation into delivery, and hybrid participation in DTGs is a condition of equity, not merely a convenience.
Arg. 4
Explanation
Tonga welcomed the establishment of the dedicated thematic group on capacity building and viewed the December meetings as the first true test of whether the mechanism can convert deliberation into delivery. Tonga also underlined that hybrid participation in the DTGs is not a convenience but a condition of equity, as Pacific states will never be able to travel with large delegations.
Evidence
Tonga stated that it sees the December meetings as the first true test of whether the mechanism can convert deliberation into delivery, and underlined that hybrid participation in the DTGs is not a convenience but a condition of equity, noting that they will never be able to travel from the Pacific with a large delegation .
Major Discussion Point
Inclusive participation and hybrid access in the global mechanism
A state that cannot implement the framework is not protected by it, so the cross-cutting thematic group should apply a capacity lens across all pillars.
Arg. 5
Explanation
Tonga argued that the cross-cutting thematic group should apply the same capacity lens across all pillars of the framework, because a state that cannot implement the framework is not protected by it. This reflects Tonga's view that capacity building is a prerequisite for meaningful participation in the framework.
Evidence
Tonga stated that the cross-cutting thematic group should apply the same capacity lens across all pillars, because a state that cannot implement the framework is not protected by it .
Major Discussion Point
Capacity building as a cross-cutting issue
Agreed with
Republic of KoreaBotswanaRwandaMalawiCameroonGhanaAlbaniaKiribatiNew ZealandMalaysiaGuatemalaSouth AfricaCote d'IvoireDemocratic Republic of the CongoAustraliaMarshall Islands
on: Capacity building is the foundational pillar upon which all other pillars of the ICT security framework depend
Tonga expresses gratitude to UNIDIR and donor partners for the Women in International Security and Cyberspace Fellowship, which enabled its small delegation to participate in the substantive plenary session.
Arg. 6
Explanation
Tonga expressed gratitude to UNIDIR and donor partners for their continuous support and for allowing Tonga to take part in the Women in International Security and Cyberspace Fellowship, which greatly assisted the delegation and enabled its small nation to participate in the substantive plenary session.
Evidence
Tonga stated that it is grateful to UNIDIR and the support of the donor partners for their continuous support and for allowing their small nation to take part in the Women in International Security and Cyberspace Fellowship last week, which has greatly assisted them and allowed their small delegation to participate in the substantive plenary session .
Major Discussion Point
Value of fellowship programmes for small island developing states
Agreed with
MalawiBotswanaBrazilMexicoCanadaSouth AfricaUruguayAlbaniaGhanaBahamasMauritiusCote d'IvoireSerbiaBosnia and Herzegovina
on: Gender inclusion and the Women in International Security and Cyberspace Fellowship are essential components of effective and inclusive capacity building
184
WPM
450
Words
2 min
Time
ICT capacity building is essential for bridging the digital divide in developing countries and should be continuous and cross-cutting.
Arg. 1
Explanation
Guyana argued that for developing countries like itself, ICT capacity building is essential to bridging the digital divide and should be continuous and cross-cutting. Strengthening the capacities of developing countries should be viewed as part of the greater global ICT security effort and as part of efforts to accelerate implementation of the 2030 Agenda for Sustainable Development.
Evidence
Guyana stated that for developing countries like Guyana, ICT capacity building is essential to bridging the digital divide and should be continuous and cross-cutting, and that strengthening the capacities of developing countries should be viewed as part of the greater global ICT security and as part of efforts to accelerate implementation of the 2030 Agenda for Sustainable Development .
Major Discussion Point
Capacity building as a tool for bridging the digital divide and advancing development
ICT capacity building is critical for addressing ICT vulnerabilities, mitigating threats, ensuring incident response, and strengthening digital resilience through training, information sharing, and technology transfers.
Arg. 2
Explanation
Guyana highlighted that ICT capacity building is critical for addressing ICT vulnerabilities, mitigating threats, ensuring incident responses, and strengthening digital resilience. Training at technical, legal, policy, and other relevant levels, information sharing, exchange of best practices, and technology transfers can help advance these efforts at national, regional, and international levels.
Evidence
Guyana stated that ICT capacity building is critical for addressing ICT vulnerabilities, mitigating ICT threats, ensuring incident responses and strengthening digital resilience, and that training at technical, legal, policy and other relevant levels, information sharing, exchange of best practices and experiences and technology transfers can help to effectively advance these efforts .
Major Discussion Point
Scope and purpose of ICT capacity building
There is a need for multilateral collaboration, including public-private partnerships, regional and sub-regional cooperation, and cooperation between states and relevant stakeholders.
Arg. 3
Explanation
Guyana emphasised the need for multilateral collaboration to advance ICT capacity building, including public-private partnerships, regional and sub-regional cooperation, and cooperation between states and relevant stakeholders. This reflects Guyana's view that no single actor can address ICT capacity needs alone.
Evidence
Guyana stated that there is a need for multilateral collaboration, including public-private partnerships, regional and sub-regional cooperation and cooperation between states and relevant stakeholders .
Major Discussion Point
Multi-stakeholder and multilateral collaboration in capacity building
Agreed with
BotswanaAustraliaCote d'IvoireDemocratic Republic of the CongoGhanaGermanyVanuatuNew ZealandKiribati
on: Regional cooperation and regional organisations play an essential role in effective capacity building and should be leveraged by the global mechanism
Guyana supports the operationalisation of the Global ICT Security Cooperation and Capacity Building Portal and the establishment of the UN Voluntary Fund for ICT Security Capacity Building.
Arg. 4
Explanation
Guyana expressed support for the operationalisation of the Global ICT Security Cooperation and Capacity Building Portal and the establishment of the UN Voluntary Fund for ICT Security Capacity Building, believing these would be beneficial in supporting the capacity building needs and initiatives of states.
Evidence
Guyana stated that it supports the operationalisation of the Global ICT Security Cooperation and Capacity Building Portal and the establishment of the UN Voluntary Fund for ICT Security Capacity Building, and believes that these would be beneficial in supporting the capacity building needs and initiatives of states .
Major Discussion Point
Global ICT security cooperation portal and voluntary fund
Agreed with
South AfricaMalawiIndiaGhanaDemocratic Republic of the CongoIslamic Republic of Iran
on: The operationalisation of the UN Voluntary Fund for ICT security capacity building and the Global ICT Security Cooperation and Capacity Building Portal are priority mechanisms for the global mechanism
Guyana's digital transformation has been guided by its ICT Master Plan 2030 and National Cybersecurity Policy Framework, and Guyana recently joined LAC4 to strengthen its cybersecurity capacity.
Arg. 5
Explanation
Guyana described its national digital transformation as being guided by its ICT Master Plan 2030 and the National Cybersecurity Policy Framework, with investments in ICT infrastructure, cybersecurity awareness, and digital literacy. Guyana also recently joined the Latin American Caribbean Cyber Competency Center (LAC4) to continue strengthening its cybersecurity capacity and digital resilience.
Evidence
Guyana stated that its digital transformation has been guided by its ICT Master Plan 2030 and the National Cybersecurity Policy Framework, with investments in developing ICT infrastructure to improve public services, enhance cybersecurity awareness, and promote digital literacy, and that Guyana recently joined the Latin American Caribbean Cyber Competency Center, LAC4, to continue strengthening its cybersecurity capacity and digital resilience .
Major Discussion Point
National capacity building initiatives and policies
103
WPM
576
Words
6 min
Time
Capacity building is most effective when tailored to the reality of the recipient, including targeted role-specific training aligned with the maturity of the national team.
Arg. 1
Explanation
The Bahamas drew on its experience establishing CertBS, its National Computer Incident Response Team, to argue that capacity building is more effective when tailored to the reality of the recipient. For new and emerging CERTs, this means targeted role-specific training aligned with the maturity of the national team and delivered in ways that strengthen capacity without disrupting day-to-day operations.
Evidence
The Bahamas stated that its establishment of CertBS reinforced the lesson that capacity building is more effective when tailored to the reality of the recipient, meaning targeted role-specific training aligned with the maturity of the national team and delivered in ways that strengthen capacity without disrupting day-to-day operations, with structured maturity models providing a practical roadmap for progression .
Major Discussion Point
Principles for effective and tailored capacity building
Capacity building must extend beyond technical communities to include policy and senior decision makers, as leadership-level capacity building transforms technical capacity into national action.
Arg. 2
Explanation
The Bahamas emphasised the importance of building capacity beyond technical communities to include policy and senior decision makers. These leaders must understand cyber risks so they can advance legislation, strengthen governance, prioritise critical infrastructure protection, and provide the strategic leadership needed to build national resilience, as leadership-level capacity building is what transforms technical capacity into national action.
Evidence
The Bahamas stated that policy and senior decision makers must understand cyber risks so that they can advance legislation, strengthen governance, prioritise the protection of critical infrastructure, and provide the strategic leadership needed to build national resilience, and that leadership-level capacity building is what transforms technical capacity into national action .
Major Discussion Point
Broadening the scope of capacity building beyond technical training
Agreed with
ItalyGhanaGuatemalaMauritiusBotswanaAlbania
on: Capacity building must be inclusive and extend beyond technical training to encompass institutional development, policy support, workforce development, and awareness programmes
Capacity building should create opportunities for peer-to-peer learning through staff exchanges, study visits, mentoring, and joint exercises, which accelerate learning in ways formal training alone cannot.
Arg. 3
Explanation
The Bahamas argued that capacity building should create opportunities for exposure and collaboration, placing developing technical teams alongside more mature, experienced counterparts. Staff exchanges, study visits, mentoring, and joint exercises accelerate learning in ways that formal training alone cannot, and the global mechanism should promote these practical peer-to-peer partnerships.
Evidence
The Bahamas stated that placing developing technical teams alongside more mature, experienced counterparts through staff exchange, study visits, mentoring, and joint exercises accelerates learning in ways that formal training alone cannot, and encouraged the global mechanism to promote these practical peer-to-peer partnerships .
Major Discussion Point
Peer-to-peer learning and practical partnerships in capacity building
Small island developing states need capacity building that includes emerging technologies such as AI to ensure they grow with the evolving state of technology.
Arg. 4
Explanation
The Bahamas highlighted that small island developing states need capacity building that includes emerging technologies such as AI to ensure that they grow with the evolving state of technology. This reflects the particular vulnerability and need of SIDS to keep pace with technological developments.
Evidence
The Bahamas stated that small island development states need capacity building that includes emerging technologies such as AI to ensure that they grow with the evolving state of technology .
Major Discussion Point
Capacity building for emerging technologies in small island developing states
Sustainable cybersecurity begins with people, requiring long-term investment in education, awareness, leadership, and workforce development.
Arg. 5
Explanation
The Bahamas concluded by arguing that sustainable cybersecurity begins with people and requires long-term investment in education, awareness, leadership, and workforce development. The Bahamas described its own national initiatives, including an annual cybersecurity conference, a Capture the Flag competition, a national cyber hygiene school roadshow, and targeted training for policymakers, women, and youth, as laying the foundation for a sustainable cybersecurity workforce.
Evidence
The Bahamas stated that sustainable cybersecurity begins with people and that building a resilient digital framework requires long-term investment in education, awareness, leadership, and workforce development, and described national initiatives including an annual cybersecurity conference, a CyberShark Capture the Flag competition, a national cyber hygiene school roadshow, and targeted training for policymakers, women and youth as laying the foundation for sustainable cybersecurity workforce and resilience .
Major Discussion Point
Sustainable capacity building through long-term investment in people
Agreed with
MalawiCambodiaKiribatiTongaNaoeroBosnia and Herzegovina
on: Capacity building must be sustained over time and promote self-sufficiency rather than dependency, as single training events do not build institutions
The Women in International Security and Cyberspace Fellowship demonstrates the value of sustained investment in people, creating lasting national and international impact.
Arg. 6
Explanation
The Bahamas shared a personal account of experiencing the value of international capacity building through the WIC programme over the previous two weeks. The Bahamas argued that this is a testament that sustained investment in people creates lasting national and international impact, and expressed sincere thanks to the programme's donors, organisers, facilitators, mentors, and fellow participants.
Evidence
The Bahamas stated that personally experiencing the value of international capacity building through the WIC programme over the last two weeks is a testament that sustained investment in people creates lasting national and international impact, and extended sincere thanks to its donors, organisers, facilitators, mentors, and fellow WIC fellows .
Major Discussion Point
Value of fellowship programmes for capacity building
Agreed with
MalawiBotswanaBrazilMexicoCanadaSouth AfricaTongaUruguayAlbaniaGhanaMauritiusCote d'IvoireSerbiaBosnia and Herzegovina
on: Gender inclusion and the Women in International Security and Cyberspace Fellowship are essential components of effective and inclusive capacity building
126
WPM
587
Words
5 min
Time
Capacity building is the foundation upon which all other pillars of the framework depend, and without adequate capacities, states cannot implement norms, apply international law, or participate fully in confidence-building measures.
Arg. 1
Explanation
Cameroon argued that a framework without capacity remains merely an aspiration, and that norms without the ability to implement them remain only commitments. For developing countries in particular, capacity building is not an optional component of the global mechanism but a prerequisite for meaningful participation and sustainable implementation.
Evidence
Cameroon stated that a framework without capacity remains an aspiration, norms without the ability to implement them remain commitments, and cooperation without shared capabilities cannot deliver lasting results, and that without adequate technical, institutional, and human capacities, states cannot effectively implement norms, apply international law, or participate fully in confidence-building measures .
Major Discussion Point
Capacity building as a foundational pillar of the ICT security framework
Agreed with
Republic of KoreaBotswanaRwandaMalawiGhanaAlbaniaKiribatiNew ZealandTongaMalaysiaGuatemalaSouth AfricaCote d'IvoireDemocratic Republic of the CongoAustraliaMarshall Islands
on: Capacity building is the foundational pillar upon which all other pillars of the ICT security framework depend
The dedicated thematic group on capacity building should serve as a central platform for technical cooperation, peer learning, and implementation, using interactive and implementation-oriented formats such as expert-led workshops and peer-to-peer exchanges.
Arg. 2
Explanation
Cameroon welcomed the establishment of DTG2 and argued it should complement plenary discussions with more interactive formats, including expert-led technical workshops, country case studies, and peer-to-peer exchanges. These formats would enable member states to share experiences, identify common challenges, and develop solutions adapted to their respective national circumstances.
Evidence
Cameroon stated that DTG2 should complement plenary discussions with more interactive and implementation-oriented formats, including expert-led technical workshops, country case studies, and peer-to-peer exchanges, enabling member states to share experiences, identify common challenges, and develop solutions adapted to their respective national circumstances .
on: The December DTG2 meeting must deliver concrete, practical, and measurable outputs rather than further discussion of principles
DTG2 should focus on deliverables that provide practical support to member states, including concise implementation guidance, mechanisms to align national needs with available expertise, and recommendations to strengthen coordination of capacity building resources.
Arg. 3
Explanation
Cameroon argued that DTG2 should focus on concrete deliverables rather than abstract discussions. These should include concise implementation guidance, a mechanism to facilitate greater alignment between national capacity building needs and available expertise and technical assistance, as well as recommendations to strengthen coordination and resources for capacity building initiatives.
Evidence
Cameroon encouraged the development of concise implementation guidance, a mechanism to facilitate greater alignment between national capacity-building needs and available expertise, technical assistance and support, as well as recommendations to strengthen coordination and resources for capacity-building initiatives .
Major Discussion Point
Concrete outputs expected from DTG2
Agreed with
MalawiCambodiaAustraliaNew Zealand
on: The measure of successful capacity building should be concrete outcomes rather than process metrics such as number of workshops or certificates
The success of DTG2 requires a genuine spirit of partnership and shared responsibility, with developed countries contributing technical assistance, international organisations strengthening coordination, and developing countries articulating their priorities clearly.
Arg. 4
Explanation
Cameroon argued that the success of DTG2 depends on a balanced, inclusive, and cooperative approach involving all actors. Developed countries can contribute through technical assistance, expertise, and resources; international and regional organisations can strengthen coordination; the private sector and academia can provide innovation and specialised knowledge; while developing countries must articulate their priorities clearly and strengthen national ownership.
Evidence
Cameroon stated that the success of DGT2 will depend on a genuine spirit of partnership, solidarity, and shared responsibility, with developed countries contributing through technical assistance, expertise and resources, international and regional organisations strengthening coordination and supporting implementation, the private sector and academia providing innovation and specialised knowledge, and developing countries articulating their priorities clearly and strengthening national ownership .
Major Discussion Point
Multi-stakeholder partnership in capacity building
Capacity building is not only about sharing knowledge and expertise but about building collective resilience and shared prosperity, rooted in an African understanding that the strength of a community is measured by its ability to uplift all its members.
Arg. 5
Explanation
Cameroon concluded by grounding its vision of capacity building in a long-standing African understanding that the strength of a community is measured by its ability to uplift and empower all its members. Capacity building is therefore not merely a technical exercise but a means of building collective resilience and shared prosperity.
Evidence
Cameroon stated that its vision is rooted in a long-standing African understanding that the strength of a community is measured by its ability to uplift and empower all its members, and that capacity building is not only about sharing knowledge and expertise but about building collective resilience and shared prosperity .
Major Discussion Point
Philosophical foundations of capacity building
141
WPM
537
Words
4 min
Time
Capacity building is a cornerstone for advancing international peace, security, and stability in the use of ICTs, and must be inclusive, demand-driven, and sustainable, reflecting national priorities and promoting long-term resilience.
Arg. 1
Explanation
Mauritius underscored that capacity building remains a cornerstone for advancing international peace, security, and stability in the use of ICTs, particularly for developing countries and small island developing states. It must be inclusive, demand-driven, and sustainable, reflecting national priorities and contexts while promoting ownership and long-term resilience.
Evidence
Mauritius stated that capacity building remains a cornerstone for advancing international peace, security and stability in the use of ICTs, and that it must be inclusive, demand-driven and sustainable, reflecting national priorities and contexts while promoting ownership and long-term resilience .
Capacity building efforts should strengthen legal, policy, technical, and institutional capabilities, including national cybersecurity strategies, protection of critical information infrastructure, and enhancement of incident response mechanisms.
Arg. 2
Explanation
Mauritius emphasised the importance of strengthening legal, policy, technical, and institutional capabilities as part of capacity building. This includes the development of national cybersecurity strategies, protection of critical information infrastructure, and enhancement of incident response mechanisms, alongside enhanced cooperation among states, regional organisations, the private sector, academia, and civil society.
Evidence
Mauritius emphasised the importance of strengthening legal policy, technical and institutional capabilities, including the development of national cybersecurity strategies, protection of critical information infrastructure and enhancement of incident response mechanisms, and further highlighted the need for enhanced cooperation and coordination among states, regional organisations, the private sector, academia and civil society .
Major Discussion Point
Scope and content of capacity building
Agreed with
ItalyGhanaGuatemalaBahamasBotswanaAlbania
on: Capacity building must be inclusive and extend beyond technical training to encompass institutional development, policy support, workforce development, and awareness programmes
Capacity building must be integrated with in-depth discussions on the applicability of international law, norms of responsible behaviour, and confidence-building measures to ensure a holistic approach.
Arg. 3
Explanation
Mauritius argued that it is essential to integrate capacity building with in-depth discussions on the applicability of international law, norms of responsibility and behaviour, and confidence-building measures. This holistic approach will ensure that capacity building contributes meaningfully to a secure, stable, and peaceful cyberspace.
Evidence
Mauritius stated that it is essential to integrate capacity-building with in-depth discussions on the applicability of international law, norms of responsibility and behaviour, and confidence-building measures, and that this holistic approach will ensure that capacity-building contributes meaningfully to a secure, stable, and peaceful cyberspace .
Major Discussion Point
Capacity building as a cross-cutting issue
Mauritius hosts an ITU Global Academy Training Centre where dedicated training programmes on cybersecurity norms and CBMs implementation have been conducted annually since 2021, reaching over 20 countries.
Arg. 4
Explanation
Mauritius highlighted its role as a host of one of the ITU Global Academy Training Centres, where dedicated training programmes focusing on cybersecurity norms and CBMs implementation have been conducted on an annual basis since 2021. Past training sessions were attended by over 20 countries across the globe, and Mauritius encouraged interested delegations to register on the ITU Academy portal for future trainings.
Evidence
Mauritius stated that it hosts one of the ITU Global Academy Training Centres, where dedicated training programmes focusing on cybersecurity norms and CBMs implementation have been conducted on an annual basis since 2021, with past training sessions attended by over 20 countries across the globe, and encouraged interested delegations to register on the ITU Academy portal for future trainings .
Major Discussion Point
National and regional capacity building initiatives
Mentorship programmes for CERTs and strengthening cooperation between incident response teams through joint training and mutual assistance arrangements should be expanded.
Arg. 5
Explanation
Mauritius expressed strong belief in the development of mentorship programmes to supplement training, particularly for CERTs and sector CERTs. It also emphasised the importance of strengthening cooperation between incident response teams through joint training and mutual assistance arrangements, arguing these should be expanded.
Evidence
Mauritius stated that it strongly believes that the development of mentorship programmes to supplement training particularly for CERTs and C-CERTs and strengthening of cooperation between incident response teams through joint training and mutual assistance arrangements is important and should be expanded .
Major Discussion Point
Practical mechanisms for capacity building
Capacity building should be guided by the principles of inclusivity, accessibility, and equality, ensuring that no state is left behind, and should mainstream gender perspectives into programmes and national ICT policies.
Arg. 6
Explanation
Mauritius reaffirmed that capacity building should be guided by the principles of inclusivity, accessibility, and equality, ensuring that no state is left behind. It also highlighted the importance of mainstreaming principles of transparency, trust, and human rights into capacity building programmes, including through gender-responsive approaches and the integration of gender perspectives into national ICT policies.
Evidence
Mauritius stated that the mainstreaming of the principles of transparency, trust and human rights into capacity building programmes, including through gender-responsive approaches and the integration of gender perspectives into national ICT policies, should be enhanced, and reaffirmed that capacity building should be guided by the principles of inclusivity, accessibility, and equality, ensuring that no state is left behind .
Major Discussion Point
Gender and inclusion in capacity building
Agreed with
MalawiBotswanaBrazilMexicoCanadaSouth AfricaTongaUruguayAlbaniaGhanaBahamasCote d'IvoireSerbiaBosnia and Herzegovina
on: Gender inclusion and the Women in International Security and Cyberspace Fellowship are essential components of effective and inclusive capacity building
127
WPM
710
Words
6 min
Time
Cyber capacity building is essential for strengthening national resilience against sophisticated cyber threats, safeguarding critical infrastructure, and ensuring that emerging technologies are adopted securely.
Arg. 1
Explanation
Italy argued that cyber capacity building is essential in today's interconnected world, helping to safeguard critical infrastructure, protect national security, and reduce dependence on external actors. As emerging technologies such as AI, cloud, quantum, and the Internet of Things expand the digital ecosystem, cyber capacity building ensures these innovations are adopted securely.
Evidence
Italy stated that cyber capacity building is essential for strengthening national resilience against increasingly sophisticated cyber threats, that strong cyber capabilities help safeguard critical infrastructure, protect national security and reduce dependence on external actors, and that as emerging technologies expand the digital ecosystem, cyber capacity building ensures these innovations are adopted securely .
Major Discussion Point
Strategic importance of cyber capacity building
Italy has developed a robust national ecosystem of public and private entities for cyber capacity building, guided by principles of sustainability, inclusivity, and alignment with the SDGs, incorporating a gender perspective.
Arg. 2
Explanation
Italy described its multi-stakeholder approach to cyber capacity building, which has produced a robust national ecosystem of public and private entities engaged whenever requests for assistance and cooperation are presented. The principles of sustainability, inclusivity, and alignment with the SDGs underpin Italy's approach, and efforts must respect human rights and fundamental freedoms while incorporating a gender perspective.
Evidence
Italy stated that it has developed a robust national ecosystem of public and private entities engaged whenever requests for assistance and cooperation are presented, and that the principles of sustainability, inclusivity and alignment with SDGs underpin Italy’s CCB approach, with efforts respecting human rights and fundamental freedoms and incorporating a gender perspective .
Major Discussion Point
National capacity building approach and principles
Italy's Mattei Plan for Africa promotes a model of cooperation between equals, supporting sustainable digital development of the African continent through ongoing dialogue and joint selection of projects.
Arg. 3
Explanation
Italy highlighted the Mattei Plan for Africa as a particularly meaningful strategy, promoted by the Italian government to bring about a paradigm shift in relations with African nations. The plan promotes a model of cooperation between equals, built on trust and mutual respect, aiming to support the sustainable development of the African continent including in the digital dimension through ongoing dialogue and joint selection of projects.
Evidence
Italy described the Mattei Plan for Africa as promoting a model of cooperation between equals, built on trust and mutual respect, aiming to support the sustainable development of the African continent in all its dimensions including the digital one, through ongoing dialogue and the joint selection of projects and investments considered most effective to respond to the concrete priorities of its peoples .
Major Discussion Point
Regional and bilateral capacity building initiatives
Italy supports capacity building initiatives ranging from developing national cybersecurity strategies to training personnel, delivered bilaterally and through multilateral organisations such as the World Bank, UNIDIR, and ITU.
Arg. 4
Explanation
Italy described a range of cyber capacity building projects it supports, from developing national cybersecurity strategies to training personnel, delivering ICT products, and creating awareness-raising campaigns. These are delivered both bilaterally with several partners and through multilateral organisations such as the World Bank, UNIDIR, and ITU.
Evidence
Italy stated that examples of CCB projects it supports range from developing national cybersecurity strategies to training personnel, from delivering ICT products to crafting systems, and creating awareness-raising campaigns, delivered bilaterally with several partners as well as through multilateral organisations such as the World Bank, UNIDIR and ITU .
Major Discussion Point
National capacity building initiatives and programmes
Disagreed with
Islamic Republic of IranSwitzerlandBrazilRussian Federation
on: The role and primacy of the United Nations versus other actors in leading capacity building efforts
Capacity building should be demand-driven, sustainable, coordinated, and based on localisation, encompassing institutional development, cybersecurity governance, policy support, workforce development, and awareness programmes.
Arg. 5
Explanation
Italy argued that capacity building initiatives should be demand-driven, sustainable, coordinated, and based on localisation, while avoiding duplication of existing efforts. Beyond technical training, capacity building should encompass institutional development, cybersecurity governance, policy support, workforce development, awareness programmes, and the strengthening of national cyber ecosystems.
Evidence
Italy stated that capacity building should remain demand-driven, sustainable, coordinated, and based on localisation while avoiding duplication of existing efforts, and that beyond technical training, capacity building should encompass institutional development, cybersecurity governance, policy support, workforce development, awareness programmes, and the strengthening of national cyber ecosystems .
Major Discussion Point
Principles and scope of effective capacity building
Agreed with
GhanaGuatemalaBahamasMauritiusBotswanaAlbania
on: Capacity building must be inclusive and extend beyond technical training to encompass institutional development, policy support, workforce development, and awareness programmes
DTG1 will be essential to deepen the interconnection between cyber capacity building and other pillars, while DTG2 has the opportunity to define templates of CCB projects or best practices to ensure no one is left behind.
Arg. 6
Explanation
Italy outlined distinct roles for the two dedicated thematic groups. DTG1 will be essential to deepen the interconnection between cyber capacity building and the other pillars of the framework, while DTG2 will have the extraordinary opportunity to define possible templates of CCB projects or best practices, making sure that nobody is left behind.
Evidence
Italy stated that DTG1 will be essential to deepen the interconnection between CCB and the other pillars, whereas DTG2 will have the extraordinary opportunity to define possible templates of CCB projects or best practices, making sure that nobody is left behind, as several delegations of Africa and Oceania have emphasised .
Major Discussion Point
Role of dedicated thematic groups in capacity building
158
WPM
302
Words
2 min
Time
For small and remote island nations, digital connectivity is transformational but also exposes them to harm, making capacity building essential to making the promise of digital connection safe.
Arg. 1
Explanation
The Marshall Islands described how digital connectivity is the difference between families divided by the ocean and those able to communicate across it, and between outer islands left isolated and those reached by essential services. However, the very connection that can lift a remote nation can also expose it, and the smallest and most distant nations have the least to fall back on when harm occurs.
Evidence
The Marshall Islands stated that digital connectivity is the difference between a family divided by the ocean and one able to speak across it, between an outer island left on its own and one reached by a doctor, a teacher or a warning before the storm, but that what arrives from beyond the horizon can carry harm as well as hope, and that the smallest and most distant among them have the least to fall back on when it does .
Major Discussion Point
Unique digital connectivity challenges and vulnerabilities of small island developing states
Capacity building is how the promise of digital connection is made safe for nations like the Marshall Islands, and the global mechanism must reach even the most distant shores so that no nation is left beyond its horizon.
Arg. 2
Explanation
The Marshall Islands placed capacity building at the heart of its first intervention in the global mechanism process, arguing that for nations like theirs, capacity building is how the promise of digital connection is made safe. The Marshall Islands asked that the mechanism reach even the most distant shores so that no nation is left beyond its horizon.
Evidence
The Marshall Islands stated that capacity building is how the promise of digital connection is made safe for nations like theirs, and asked that the mechanism reach even the most distant shores so that no nation is left beyond its horizon .
Major Discussion Point
Capacity building as a prerequisite for safe digital development in small island states
Agreed with
Republic of KoreaBotswanaRwandaMalawiCameroonGhanaAlbaniaKiribatiNew ZealandTongaMalaysiaGuatemalaSouth AfricaCote d'IvoireDemocratic Republic of the CongoAustralia
on: Capacity building is the foundational pillar upon which all other pillars of the ICT security framework depend
The Marshall Islands aligns fully with the Pacific Islands Forum position on capacity building and expresses gratitude to Pacific colleagues, particularly Tonga, for carrying regional priorities into the global mechanism.
Arg. 3
Explanation
The Marshall Islands noted that it had not previously spoken at this process or at the open-ended working group, and expressed sincere gratitude to Pacific colleagues who have carried the priorities of the region into the room with conviction. The Marshall Islands aligned itself fully with the Pacific position on capacity building.
Evidence
The Marshall Islands expressed sincere gratitude to Pacific colleagues who have carried the priorities of their region into the room with such conviction, and in particular to the Kingdom of Tonga who delivered the Pacific Islands Forum statements on their behalf, and stated that they align themselves fully with the Pacific position .
Major Discussion Point
Regional solidarity and collective advocacy in capacity building
124
WPM
337
Words
3 min
Time
Capacity building is a fundamental pillar for moving towards an open, secure, stable, accessible, and peaceful ICT environment, and without a solid basis it will be difficult to implement the mechanism or participate on an equal footing.
Arg. 1
Explanation
Uruguay underscored the importance of the substantive work of the mechanism reflecting the priorities of all regions, especially in the area of capacity building. For Uruguay's region, capacity building is a fundamental pillar for moving towards an open, secure, stable, accessible, and peaceful ICT environment, and without a solid basis it will be difficult to implement the mechanism or participate on an equal footing.
Evidence
Uruguay stated that for their region, capacity building is a fundamental pillar for moving towards an open, secure, stable, accessible and peaceful ICT environment, and that without a solid basis it will be difficult to implement the mechanism or to participate on an equal footing in these fora, and that capacity building is necessary to strengthen resilience and collective security .
Major Discussion Point
Capacity building as a foundational pillar for equitable participation
DTG2 should be agile, results-oriented, and serve as a practical mechanism linking the practical needs of states with tangible solutions and effective cooperation.
Arg. 2
Explanation
Uruguay argued that the current session should lay the foundations for DTG2 to be agile and results-oriented with technical assistance. DTG2 should be a practical mechanism that links the practical needs of states with tangible solutions and effective cooperation, with capacity building activities addressing the priorities identified by states themselves.
Evidence
Uruguay stated that it considers the session to lay the foundations for dedicated thematic group two to be agile and be able to be results-oriented and have technical assistance, and that it should be a practical mechanism that links the practical needs of states with tangible solutions and effective cooperation, with capacity building activities addressing the priorities identified by states themselves .
on: The December DTG2 meeting must deliver concrete, practical, and measurable outputs rather than further discussion of principles
Capacity building activities should include strengthening cybersecurity capacity, incident response, protection of critical information infrastructure, and implementation of confidence-building measures.
Arg. 3
Explanation
Uruguay outlined the substantive areas that capacity building activities should address, including strengthening cybersecurity capacity, incident response capacity, protection of critical information infrastructure, and the implementation of confidence-building measures. These should be among the priorities identified by states themselves.
Evidence
Uruguay stated that capacity building activities must address the priorities identified by states themselves and should include amongst other things strengthening cybersecurity capacity, incident response capacity, protection of critical information infrastructure, and the implementation of confidence-building measures .
Major Discussion Point
Scope and content of capacity building
Regional and international initiatives such as those by UNIDIR and the OAS, especially the Women in Cyber programme, have proven effective tools for strengthening national capacity and should be continued and expanded.
Arg. 4
Explanation
Uruguay highlighted the value of regional and international initiatives for the furtherance of capacity building, particularly those by UNIDIR and the Organization of American States. Uruguay specifically commended the Women in Cyber programme, of which it has been a beneficiary on multiple occasions, noting that it has significantly contributed to strengthening technical capacity and promoting greater participation of women in cybersecurity.
Evidence
Uruguay highlighted the value of regional and international initiatives for the furtherance of capacity building, especially those by UNIDIR and the Organization of American States, and specifically highlighted the Women in Cyber programme, of which Uruguay has been a beneficiary on a number of occasions, stating that it has significantly contributed to strengthening technical capacity and promoting greater participation of women in the area of cybersecurity .
Major Discussion Point
Value of fellowship and regional programmes for capacity building
Agreed with
MalawiBotswanaBrazilMexicoCanadaSouth AfricaTongaAlbaniaGhanaBahamasMauritiusCote d'IvoireSerbiaBosnia and Herzegovina
on: Gender inclusion and the Women in International Security and Cyberspace Fellowship are essential components of effective and inclusive capacity building
Cooperation across different programmes should be integrated to maximise impact, make the most of synergies, and avoid duplication in capacity building efforts.
Arg. 5
Explanation
Uruguay encouraged the continuation and strengthening of effective capacity building initiatives, and called for the integration of cooperation across different programmes in order to maximise their impact, make the most of synergies, and avoid duplication. This reflects Uruguay's concern for efficiency and coherence in the global capacity building ecosystem.
Evidence
Uruguay encouraged the continuation and strengthening of effective capacity building initiatives and their reach, and called for the integration of cooperation across different programmes in order to maximise their impact, to make the most of synergies and to avoid duplication .
Major Discussion Point
Coordination and efficiency in capacity building
Agreed with
Republic of KoreaGermanyAustraliaBrazilIsraelMauritiusIrelandNew ZealandJapanSingapore
on: Duplication of existing capacity building efforts must be avoided through enhanced coordination, complementarity, and efficient use of available resources
168
WPM
729
Words
4 min
Time
Capacity building cannot be treated as a residual or secondary pillar; it must be targeted, needs-driven, context-specific, politically neutral, and transparent.
Arg. 1
Explanation
India argued that for the Global South, digital technology has been transformative, but its benefits can only be fully realised when accompanied by robust security and the capability to defend against emerging threats. This is why India has consistently emphasised that capacity building must be central to the global mechanism, not treated as an afterthought.
Evidence
India stated that capacity building cannot be treated as a residual or secondary pillar and must be targeted, needs-driven, contest-specific, politically neutral and transparent, drawing on India’s own experience with open, inclusive digital public infrastructure exemplified by the India Stack model .
India's bilateral capacity building practice through the Indian Technical and Economic Cooperation Programme has offered close to 50,000 fully funded training opportunities to Global South professionals over five years, demonstrating that scaled, demand-driven capacity building is achievable.
Arg. 2
Explanation
India described its extensive bilateral capacity building efforts through the Indian Technical and Economic Cooperation Programme, one of the oldest institutionalised arrangements of its kind. Over the last five years, India has offered nearly 50,000 fully funded training opportunities spanning approximately 400 courses at over 100 premier Indian institutions, with a substantial share dedicated to ICT, cybersecurity, and emerging technologies.
Evidence
India stated that through the Indian Technical and Economic Cooperation Programme, in the last five years alone, it has offered close to 50,000 fully funded training opportunities to professionals from Global South countries, spanning nearly 400 courses at over 100 premier Indian institutions, with a substantial and growing share dedicated specifically to ICT, cybersecurity, e-commerce and the development of new technologies .
Major Discussion Point
National capacity building initiatives and programmes
India will provide the entire funding for the operationalisation of the Global ICT Security Cooperation and Capacity Building Portal as a United Nations portal, moving from design to reality.
Arg. 3
Explanation
India announced that it will provide the entire funding towards the operationalisation of the Global ICT Security Cooperation and Capacity Building Portal, an initiative originally proposed by India in 2022 and subsequently endorsed by the General Assembly. India's support will enable the technical establishment and maintenance of the portal, which will comprise a repository of resources, a capacity building calendar, a needs-based catalogue of opportunities, and an interactive discussion board.
Evidence
India announced that it will be providing the entire funding towards the operationalisation of the portal as a portal of the United Nations, so that concrete, tangible action can finally follow years of discussion, and that CERT India will undertake the technical consultancy work required for the portal’s testing and infrastructure development .
Major Discussion Point
Global ICT security cooperation portal
Agreed with
South AfricaMalawiGuyanaGhanaDemocratic Republic of the CongoIslamic Republic of Iran
on: The operationalisation of the UN Voluntary Fund for ICT security capacity building and the Global ICT Security Cooperation and Capacity Building Portal are priority mechanisms for the global mechanism
The dedicated thematic group on capacity building should function through synchronised, topic-based agendas, expert briefings, and clear reporting modalities to sharpen the practical output of the global mechanism.
Arg. 4
Explanation
India welcomed the establishment of a dedicated thematic group focused specifically on cyber capacity building as a structural recognition of the priority this issue deserves. India stressed that the DTG should function through synchronised, topic-based agendas, expert briefings, and clear reporting modalities to the plenary so as to sharpen the practical output of the mechanism.
Evidence
India stated that it welcomes and looks forward to the constructive role that the co-facilitators have envisaged to play in the DTG, and stressed that the DTG should function through synchronised, topic-based agendas, expert briefings and clear reporting modalities to the plenary so as to sharpen the practical output of the mechanism .
Major Discussion Point
Role and working methods of DTG2
The Global ICT Security Cooperation and Capacity Building Portal can play a meaningful role in bridging the capacity gap between developed and developing states if treated as a living tool rather than a static repository.
Arg. 5
Explanation
India expressed its belief in the genuine and lasting value of the portal if properly used and populated by member states with actionable, needs-based information. India emphasised that the platform can meaningfully bridge the capacity gap that continues to separate developed and developing states in the domain of ICT security, provided it is treated as a living tool rather than a static repository.
Evidence
India stated that it sees genuine and lasting value in the portal if properly used and populated by member states with actionable needs-based information, and believes the platform can play a meaningful role in bridging the capacity gap that continues to separate developed and developing states in the domain of ICT security, provided it is treated as a living tool rather than a static repository .
Cyber capacity building is a process that is nationally owned, expert-led, and collaborative, depending on strong coordination between the intergovernmental process and the wider community of practitioners.
Arg. 1
Explanation
Switzerland described its view of cyber capacity building as a process that requires national ownership, expert leadership, and collaboration. It emphasised that strong coordination between the intergovernmental process and the wider community of practitioners is essential for effective capacity building.
Evidence
Switzerland stated that it views cyber capacity building as a process that is nationally owned, expert-led and collaborative, and which depends on strong coordination between the intergovernmental process and the wider community of practitioners .
Major Discussion Point
Principles for effective capacity building
Switzerland regrets the wide-ranging veto against stakeholder participation in the global mechanism, as stakeholders are among the principal implementers and knowledge holders of capacity building, not merely observers.
Arg. 2
Explanation
Switzerland expressed regret at the exclusion of stakeholders from the global mechanism, arguing that stakeholders are not observers of capacity building but among its principal implementers and knowledge holders. Excluding them does not protect the intergovernmental character of the process but deprives it of the very expertise that DTG2 was created to mobilise.
Evidence
Switzerland stated that it would like to express its regret at the wide-range veto against stakeholder participation in the global mechanism, noting that stakeholders are not observers of capacity building but are among its principal implementers and knowledge holders, and that excluding them does not protect the intergovernmental character of the process but deprives it of the very expertise that DTG2 was created to mobilise .
Major Discussion Point
Multi-stakeholder participation in capacity building
Disagreed with
JapanUkraineCambodiaCuba
on: Whether stakeholders (non-governmental actors) should have a meaningful role in the dedicated thematic groups
The cyber capacity building community must remain constructively and consistently organised and engaged between sessions of DTG2 and the roundtables, given the limitations on how frequently these bodies can meet.
Arg. 3
Explanation
Switzerland recognised that the contribution of stakeholders to advancing cyber capacity building will inevitably be limited by available resources and the frequency with which DTG2 and the roundtables can meet. This is why Switzerland believes it is essential for the cyber capacity building community to remain constructively and consistently organised and engaged between sessions.
Evidence
Switzerland stated that it recognises that the contribution of stakeholders to advancing cybercapacity building will inevitably be limited by available resources and how frequently DTG2 and the roundtables can meet, and that this is precisely why it believes it is essential for the cybercapacity building community to remain constructively and consistently organised and engaged between the sessions of the DTG2 and the roundtables .
Major Discussion Point
Coordination and continuity in capacity building
Switzerland is working with community members to establish a community hub at the Geneva Centre for Security Sector Governance to carry forward the functions previously performed by the Global Forum on Cyber Expertise, which has ceased operations.
Arg. 4
Explanation
Switzerland acknowledged the previous contributions of the Global Forum on Cyber Expertise (GFCE) as a key platform for knowledge exchange and coordination across the cyber capacity building ecosystem. Now that the GFCE Foundation has ceased operations, Switzerland announced a partnership with the Geneva Centre for Security Sector Governance to host a community hub designed to carry these functions forward using a community-by-community approach.
Evidence
Switzerland stated that the GFCE has served as a key platform bringing together governments, international organisations, the private sector, civil society and technical experts to facilitate knowledge exchange and support coordination, but that now that the GFCE Foundation has had to cease its operations, these functions no longer have a dedicated home . Switzerland further announced that during the Geneva Cyber Week in May 2026, the Geneva Centre for Security Sector Governance announced its partnership with Switzerland to host a community hub explicitly designed to carry these functions forward, adopting a community-by-community approach to facilitate continued coordination, multi-stakeholder engagement and the development of sustainable governance models for cyber capacity building .
Major Discussion Point
Coordination mechanisms for the cyber capacity building community
The Geneva community hub will complement the efforts of the global mechanism by supporting connectivity across the capacity building community and strengthening the link between strategic discussions and practical implementation.
Arg. 5
Explanation
Switzerland described how the proposed Geneva community hub would complement rather than duplicate the efforts of the global mechanism. The hub will draw on the rich ecosystem of international Geneva, including institutions such as UNIDIR, ITU, and Diplo Foundation, and will strengthen the link between strategic discussions and practical implementation.
Evidence
Switzerland stated that the hub should complement the efforts of the global mechanism, will support connectivity across the community and draw on the rich ecosystem of international Geneva, including institutions and organisations such as UNIDIR, ITU and Diplo Foundation, and will strengthen the link between strategic discussions and practical implementation, which is essential for the success of the global mechanism .
Major Discussion Point
Role of Geneva ecosystem in supporting capacity building
126
WPM
370
Words
3 min
Time
Cyber capacity building is vital and must remain a central pillar under the global mechanism, complementing bilateral, regional, and multi-stakeholder efforts, as the growing sophistication of malicious ICT activities makes it a collective responsibility.
Arg. 1
Explanation
Bosnia and Herzegovina argued that cyber capacity building is vital and must remain a central pillar under the global mechanism. The growing sophistication of malicious ICT activities serves as a constant reminder that cyberspace is deeply interconnected and that all states share exposure to risk, making capacity building no longer a matter of choice but a collective responsibility.
Evidence
Bosnia and Herzegovina stated that cyber capacity building is vital and must remain a central pillar under the global mechanism complementing bilateral, regional and multi-stakeholder efforts, and that the growing sophistication of malicious ICT activities serves as a constant reminder that cyberspace is deeply interconnected and that capacity building is no longer a matter of choice but a collective responsibility .
Major Discussion Point
Capacity building as a collective responsibility
Capacity building challenges manifest differently across national contexts shaped by each state's unique legal, institutional, and socioeconomic environment, requiring efforts that ensure inclusivity and effective partnership matching needs with expertise.
Arg. 2
Explanation
Bosnia and Herzegovina acknowledged that while some constraints in building cybersecurity capabilities are well known, such as lack of technical expertise and limited access to advanced technologies, these challenges manifest differently across national contexts. The discussion must therefore address two considerations: ensuring inclusivity so all member states can benefit from coherent support, and ensuring effective partnership that matches the right needs with the right expertise.
Evidence
Bosnia and Herzegovina stated that challenges manifest differently across national contexts, shaped by each state’s unique legal, institutional, and socioeconomic environment, and that the discussion must address two necessary considerations: ensuring inclusivity so that all member states regardless of their level of resources can benefit from coherent and coordinated support, and ensuring capacity building is guided by effective partnership matching the right needs with the right expertise .
Major Discussion Point
Principles for effective and inclusive capacity building
Capacity building must be sustainable rather than ad hoc, requiring long-term strategies that build skills and institutional memory, and must be fully inclusive, engaging governments, the private sector, academia, and civil society with a gendered perspective.
Arg. 3
Explanation
Bosnia and Herzegovina argued that for state resilience to be truly effective, capacity building must be sustainable rather than ad hoc. Long-term strategies are needed that build skills and institutional memory, ensuring capabilities are not only built but maintained as threats evolve. The process must also be fully inclusive, engaging all relevant actors and integrating a gendered perspective.
Evidence
Bosnia and Herzegovina stated that capacity building must be sustainable rather than ad hoc, requiring long-term strategies that build skills and institutional memory ensuring capabilities are not only built but maintained as threats evolve, and that the process must be fully inclusive, engaging governments, the private sector, academia and civil society, and integrating a gendered perspective and a shared vision .
Major Discussion Point
Sustainability and inclusivity of capacity building
on: Gender inclusion and the Women in International Security and Cyberspace Fellowship are essential components of effective and inclusive capacity building
142
WPM
532
Words
4 min
Time
Capacity building is a key element to implement the consensus framework, and it is time to take concrete steps building on the unity that exists among member states on this issue.
Arg. 1
Explanation
Germany argued that there is consensus that capacity building is a key element to implement the consensus framework, and that this unity is something to build upon. Germany expressed support for the chair's approach of focusing on action-oriented capacity building as part of the global mechanism.
Evidence
Germany stated that there is consensus that capacity building is a key element to implement the consensus framework, and that this unity is something to build on and that it is time to take concrete steps .
Major Discussion Point
Capacity building as a foundational pillar of the ICT security framework
Capacity building initiatives are most successful when implemented through a co-creation approach, whereby donor and recipient states collaborate closely to jointly design, develop, and implement programmes based on UN principles for cyber capacity building.
Arg. 2
Explanation
Germany argued that capacity building can only be effective when aligned with the specific needs and priorities of each nation. In particular, capacity building initiatives are most successful when implemented through a co-creation approach, as mentioned by Singapore and Canada, whereby donor and recipient states collaborate closely to jointly design, develop, and implement programmes.
Evidence
Germany stated that capacity-building initiatives are most successful when implemented through a co-creation approach, as mentioned by Singapore and Canada, whereby donor and recipient states collaborate closely to jointly design, develop, and implement programmes based on the UN principles for cybercapacity building .
Major Discussion Point
Co-creation and partnership in capacity building
Agreed with
Republic of KoreaMalawiCambodiaBotswanaAustraliaCote d'IvoireMexicoTongaKiribatiGhanaAlbaniaSerbiaArgentinaIrelandMalaysiaNew ZealandSouth AfricaVanuatu
on: Capacity building must be demand-driven, needs-based, nationally owned, and tailored to the specific circumstances of recipient states, avoiding a one-size-fits-all approach
Disagreed with
CubaIslamic Republic of IranBrazilRepublic of Korea
on: The scope of capacity building: whether it should include technology transfer and financial resources as binding commitments
The Western Balkan Cyber Diplomacy Network, jointly established by Germany and its partners in May 2025, exemplifies a demand-driven, nationally owned, co-creation approach to cyber capacity building.
Arg. 3
Explanation
Germany provided the Western Balkan Cyber Diplomacy Network as a concrete example of a co-creation approach to cyber capacity building. The network is guided by designated focal points from the Ministries of Foreign Affairs of participating countries, which jointly identify regional cyber capacity building priorities and decide on the initiatives needed to address them.
Evidence
Germany described the Western Balkan Cyber Diplomacy Network, which it jointly established with partners in the Western Balkan region in May 2025, as guided by designated focal points from the Ministries of Foreign Affairs of participating countries, which jointly identify regional cybercapacity-building priorities and decide on the initiatives needed to address them .
Major Discussion Point
Regional and bilateral capacity building initiatives
DTG2 and the annual Global Roundtable offer valuable but complementary platforms for capacity building discussions, with DTG2 focused on hands-on interactive discussions and the Roundtable providing a platform for donors and recipient states.
Arg. 4
Explanation
Germany outlined distinct but complementary roles for DTG2 and the annual Global Roundtable. DTG2 should facilitate hands-on and interactive discussions that enable the exchange of experiences and practical expertise, while the Roundtable could complement DTG2 by providing a platform bringing together donors and recipient states.
Evidence
Germany stated that DTG2 and the annual Global Roundtable offer valuable platforms for in-depth discussions on best practices in capacity building among policymakers, practitioners, and stakeholders from all sectors, and that in practical terms this would mean hands-on and interactive discussions in DTG2 that facilitate the exchange of experiences and practical expertise, with the Roundtable complementing DTG2 by providing a platform bringing together donors and recipient states .
Major Discussion Point
Role of DTG2 and the Global Roundtable in capacity building
Global portals should be developed in close coordination with existing initiatives and regional portals to avoid duplication, enhance efficiency, and ensure complementarity, with regional organisations playing an important role in cyber capacity building.
Arg. 5
Explanation
Germany emphasised the importance of developing global portals in close coordination with existing initiatives and in alignment with existing regional portals to avoid duplication, enhance efficiency, and ensure complementarity. Germany also highlighted the important work of regional organisations, citing the OSCE Secretariat as a trusted partner providing valuable work on the implementation of confidence-building measures.
Evidence
Germany stated that it would like to reiterate the importance of developing global portals in close coordination with existing initiatives and in alignment with existing regional portals to avoid duplication, enhance efficiency, and ensure complementarity, and highlighted the important work of regional organisations, citing the OSCE Secretariat as a trusted partner across the region providing valuable work on the implementation of CBMs .
Major Discussion Point
Coordination and efficiency in capacity building
Agreed with
BotswanaAustraliaCote d'IvoireDemocratic Republic of the CongoGhanaGuyanaVanuatuNew ZealandKiribati
on: Regional cooperation and regional organisations play an essential role in effective capacity building and should be leveraged by the global mechanism
International cooperation in capacity building should be action-oriented, creating a fair, equal, and non-discriminatory environment that respects the sovereign right and digital right of each country, without coercing Global South countries to choose sides.
Arg. 1
Explanation
China argued that international cooperation in capacity building should be action-oriented and must create a fair, equal, and non-discriminatory environment. Such cooperation should respect the sovereign right and digital right of each country, and countries in the Global South must not be coerced to choose sides in this cooperation.
Evidence
China stated that international cooperation in capacity building should be action-oriented, should be able to create a fair, equal and non-discriminatory environment, and that carrying out international cooperation in this field should respect the sovereign right and digital right of each country, and that countries in the global south must not be coerced to choose sides in this cooperation .
Major Discussion Point
Principles for capacity building and opposition to unilateral restrictive measures
Relevant cooperation should not come with conditions, including conditions that exclude certain products from certain countries, as countries have the right to independently choose their digital and technical products.
Arg. 2
Explanation
China argued that relevant cooperation should not come with conditions, particularly conditions that exclude certain products from certain countries. Countries have the right to independently choose their digital and technical products based on their own conditions, and without this right there will be no digital sovereignty.
Evidence
China stated that there should not be a condition for international cooperation in capacity building by excluding certain products from certain countries, and that countries have the right to choose independently their digital and technical products based on their own conditions, but without the right to choose there will not be digital sovereignty .
Major Discussion Point
Digital sovereignty and non-discriminatory access in capacity building
Disagreed with
Islamic Republic of IranRussian FederationCubaItalyUkraine
on: Whether unilateral coercive measures and technology access restrictions should be addressed within the global mechanism's capacity building agenda
China established an international AI cooperation organisation with 29 founding member states and announced 5,000 AI fellowships for developing countries over five years to support AI development and capacity building in the Global South.
Arg. 3
Explanation
China described its recent establishment of an international AI cooperation organisation composed of 29 founding member states, announced at the 2026 International AI Conference. China's President Xi Jinping announced that China will provide 5,000 AI fellowships to developing countries over the next five years to support international AI development and capacity building, creating new momentum for digital cooperation.
Evidence
China stated that last week it held the 2026 International AI Conference and announced the formation of an international corporation organisation composed of 29 founding member states, and that China’s President Xi Jinping announced that in order to support international AI development and capacity building, in the next five years China will provide 5,000 AI fellowships to developing countries to create new momentum for digital cooperation .
Major Discussion Point
National capacity building initiatives and programmes
China supports the formation of DTG2 and hopes the first biennial meeting will make substantial gains with respect to capacity building and related international cooperation.
Arg. 4
Explanation
China expressed support for the formation of DTG2 and its work on capacity building and related international cooperation. China hopes that the first biennial meeting of DTG2 will make substantial gains in this area.
Evidence
China stated that it supports the formation of DTG2 and hopes that the first biennial meeting will make substantial gains with respect to capacity building and related international cooperation .
Major Discussion Point
Role of DTG2 in capacity building
118
WPM
236
Words
2 min
Time
Capacity building is a cross-cutting issue on all pillars of the global mechanism, and is an important and essential part of the mechanism given that member states remain at varying levels of implementation.
Arg. 1
Explanation
South Africa maintained that capacity building cuts across all pillars of the global mechanism, not just one. Because member states are at varying levels of implementation of the framework for responsible use of ICTs due to differing contexts and capabilities, capacity building is essential to addressing cyber security threats, building resilience, implementing norms, applying international law, and implementing confidence-building measures.
Evidence
South Africa stated that capacity building is a cross-cutting issue on the pillars of the global mechanism, and that given member states remain at varying levels of implementation of the framework due to various factors including differing contexts and capabilities, capacity building is an important and essential part of the global mechanism in addressing cyber security threats, building resilience, implementing norms, applying international law, and implementing CBMs .
Major Discussion Point
Capacity building as a cross-cutting and foundational issue
Agreed with
Republic of KoreaBotswanaRwandaMalawiCameroonGhanaAlbaniaKiribatiNew ZealandTongaMalaysiaGuatemalaCote d'IvoireDemocratic Republic of the CongoAustraliaMarshall Islands
on: Capacity building is the foundational pillar upon which all other pillars of the ICT security framework depend
South Africa supports capacity building efforts that are needs-based and practical, guided by the capacity building principles in paragraph 56 of the 2021 OEWG final report.
Arg. 2
Explanation
South Africa expressed continued support for capacity building efforts that are grounded in the principles agreed upon in the 2021 OEWG final report. Practical and needs-based approaches are essential to ensuring that capacity building delivers meaningful results for all member states.
Evidence
South Africa stated that it continues to support capacity-building efforts that are needs-based and practical, guided by capacity-building principles encapsulated in paragraph 56 of the 2021 OEWG final report .
Major Discussion Point
Principles for effective capacity building
Agreed with
Republic of KoreaMalawiCambodiaBotswanaGermanyAustraliaCote d'IvoireMexicoTongaKiribatiGhanaAlbaniaSerbiaArgentinaIrelandMalaysiaNew ZealandVanuatu
on: Capacity building must be demand-driven, needs-based, nationally owned, and tailored to the specific circumstances of recipient states, avoiding a one-size-fits-all approach
The Women in International Security and Cyberspace Fellowship and sustainable, practical funding are essential components of capacity building, particularly for developing countries.
Arg. 3
Explanation
South Africa highlighted the Women in International Security and Cyberspace Fellowship as an essential programme for building necessary cybersecurity capacity. South Africa also stressed the critical importance of sustainable and practical funding to support capacity building activities, particularly for developing countries globally.
Evidence
South Africa stated that programmes such as the Women in International Security and Cyberspace Fellowship remain essential in building the necessary cybersecurity capacity, and that sustainable and practical funding to support capacity-building activities, particularly for developing countries globally, is also critical .
Major Discussion Point
Fellowship programmes and financing for capacity building
Agreed with
MalawiBotswanaBrazilMexicoCanadaTongaUruguayAlbaniaGhanaBahamasMauritiusCote d'IvoireSerbiaBosnia and Herzegovina
on: Gender inclusion and the Women in International Security and Cyberspace Fellowship are essential components of effective and inclusive capacity building
South Africa looks forward to further discussions on the development and operationalisation of the UN Voluntary Fund for capacity building and the establishment of the dedicated Global ICT Security Cooperation and Capacity Building Portal.
Arg. 4
Explanation
South Africa expressed anticipation for further discussions on two key mechanisms: the UN Voluntary Fund for capacity building and the Global ICT Security Cooperation and Capacity Building Portal. Both are seen as important tools for strengthening international cooperation and assistance on ICT security.
Evidence
South Africa stated that it looks forward to further discussions on the development and operationalisation of the UN Voluntary Fund for capacity building, as well as the establishment of the dedicated Global ICT Security Cooperation and Capacity Building Portal to strengthen international cooperation and assistance on ICT security .
Major Discussion Point
Global ICT security cooperation portal and voluntary fund
Agreed with
MalawiGuyanaIndiaGhanaDemocratic Republic of the CongoIslamic Republic of Iran
on: The operationalisation of the UN Voluntary Fund for ICT security capacity building and the Global ICT Security Cooperation and Capacity Building Portal are priority mechanisms for the global mechanism
146
WPM
541
Words
4 min
Time
A framework is only as strong as the ability to implement it, and cyber capacity building is therefore indispensable to international peace and security.
Arg. 1
Explanation
Australia drew on the lesson from the OEWG and GGEs that norms, law, and confidence-building measures do not implement themselves — people, institutions, and capability do. This is why cyber capacity building remains indispensable to international peace and security, and why the creation of DTG2 is one of the most important innovations in the new mechanism.
Evidence
Australia stated that if there is one lesson from the OEWG and the GGEs, it is that a framework is only as strong as the ability to implement it, that norms, law and confidence-building measures don’t implement themselves but that people, institutions, and capability implement them, and that this is why cyber capacity building remains indispensable to international peace and security .
Major Discussion Point
Capacity building as indispensable to framework implementation
Agreed with
MalawiCambodiaCameroonNew Zealand
on: The measure of successful capacity building should be concrete outcomes rather than process metrics such as number of workshops or certificates
The challenge is not a lack of goodwill or programmes but how to bring together a fragmented ecosystem of actors and turn it into something greater than the sum of its parts.
Arg. 2
Explanation
Australia argued that the global cyber capacity building ecosystem is mature but fragmented, involving states, regional organisations, international organisations, development partners, industry, academia, and civil society. The ambition for DTG2 should be to bring these actors together into a coherent whole that is greater than the sum of its parts.
Evidence
Australia stated that the challenge before the mechanism is not a lack of goodwill, expertise or programmes, but how to bring together a mature but fragmented ecosystem of states, regional organisations, international organisations, development partners, industry, academia and civil society and turn it into something greater than the sum of its parts, and that this should be the ambition for DTG2 .
Major Discussion Point
Coordination and coherence in the global capacity building ecosystem
Agreed with
Republic of KoreaGermanyBrazilIsraelMauritiusIrelandNew ZealandUruguayJapanSingapore
on: Duplication of existing capacity building efforts must be avoided through enhanced coordination, complementarity, and efficient use of available resources
DTG2 should become a platform where states can openly discuss implementation challenges, share lessons learned, and collectively understand where the most urgent gaps remain.
Arg. 3
Explanation
Australia identified listening better as its first priority for DTG2, arguing that capacity building starts with understanding the needs identified by states and communities themselves. DTG2 should become a platform for states to openly discuss challenges to implementation of the framework, share lessons learned, and help collectively understand where the most urgent gaps remain.
Evidence
Australia stated that capacity building starts with examining assumptions and understanding the needs identified by states and communities themselves, and that DTG2 should become a platform where states can openly discuss challenges to implementation of the framework, share lessons learned and help collectively understand where the most urgent gaps remain .
Major Discussion Point
Role and priorities of DTG2
Agreed with
Republic of KoreaMalawiCambodiaBotswanaGermanyCote d'IvoireMexicoTongaKiribatiGhanaAlbaniaSerbiaArgentinaIrelandMalaysiaNew ZealandSouth AfricaVanuatu
on: Capacity building must be demand-driven, needs-based, nationally owned, and tailored to the specific circumstances of recipient states, avoiding a one-size-fits-all approach
DTG2 has a unique opportunity to connect those seeking support with those offering it, bridging gaps between good ideas, funding, expertise, and implementation partners.
Arg. 4
Explanation
Australia identified connecting better as its second priority, noting that many solutions already exist but those seeking support often do not know where to find them, and those offering support do not always know where it is most needed. DTG2 has a unique opportunity to bridge these gaps through the Capacity Building Roundtable, stakeholder engagement, and DTG2 itself.
Evidence
Australia stated that many of the solutions already exist but those seeking support don’t know where to find it and those offering support do not always know where it is most needed, and that DTG2 has a unique opportunity to help bridge those gaps through the Capacity Building Roundtable, stakeholder engagement and DTG2 itself, becoming a platform for coordination and sustainable partnership rather than duplicating or competing with existing efforts .
on: The December DTG2 meeting must deliver concrete, practical, and measurable outputs rather than further discussion of principles
DTG2 should actively amplify regional capacity building initiatives, as the most successful capacity building is often regional, built on shared experiences, challenges, and trust.
Arg. 5
Explanation
Australia identified building regionally as its third priority, arguing that the most successful capacity building is often regional, built on shared experiences, shared challenges, and shared trust. DTG2 should actively amplify regional initiatives not as an alternative to global cooperation but as one of the strongest foundations for it.
Evidence
Australia stated that the most successful capacity building is often regional, built on shared experiences, shared challenges and shared trust, and that DTG2 should actively amplify regional initiatives, not because regional work is an alternative to global cooperation, but because it is one of the strongest foundations for it .
Major Discussion Point
Regional approaches to capacity building
Agreed with
BotswanaCote d'IvoireDemocratic Republic of the CongoGhanaGermanyGuyanaVanuatuNew ZealandKiribati
on: Regional cooperation and regional organisations play an essential role in effective capacity building and should be leveraged by the global mechanism
Cyber capacity building is a strategic investment in collective security, as when one state becomes more resilient, all states become more resilient.
Arg. 6
Explanation
Australia argued that cyber capacity building is a strategic investment in collective security, not merely a bilateral or charitable endeavour. When one state becomes more resilient, all states benefit, which is why Australia has invested consistently in gender-responsive, rights-respecting, and evidence-based cyber capacity building across its region.
Evidence
Australia stated that cyber capacity building is a strategic investment in collective security, that when one state becomes more resilient, all become more resilient, and that this is why Australia has invested consistently in gender-responsive, rights-respecting and evidence-based cybercapacity building across its region .
Major Discussion Point
Collective security rationale for capacity building
93
WPM
269
Words
3 min
Time
There is a necessary link between the two dedicated thematic groups, as the United Nations can only contribute to effective capacity building by having a thorough understanding of the threats and challenges that these capabilities must address.
Arg. 1
Explanation
France argued that the discussions within DTG1 should provide a basis for guiding the work of DTG2, ensuring a fruitful dialectic between the two groups. Effective capacity building requires first understanding the threats and challenges it must address, making the two groups interdependent.
Evidence
France stated that the United Nations must contribute to effective capacity building, but this can only be achieved by having a thorough understanding of the threats and challenges that these capabilities must address, and that the discussions within the dedicated thematic group one should therefore provide a basis for guiding the work of the dedicated thematic group number two, ensuring a fruitful dialectic between these two .
Major Discussion Point
Relationship between DTG1 and DTG2
Disagreed with
MexicoIrelandMalaysia
on: The relationship and hierarchy between DTG1 and DTG2
Any discussion on capacity building within DTG2 must be underpinned by existing capacity building initiatives, with regional organisations and other UN entities playing a key role in sharing experience and best practices.
Arg. 2
Explanation
France argued that discussions on capacity building, particularly within DTG2, must build upon existing capacity building initiatives rather than starting from scratch. Regional organisations and other UN entities have a key role to play in sharing their experience and best practices, and various governmental and non-governmental experts and stakeholders should have a place in the second group.
Evidence
France stated that any discussion on capacity building, particularly within DTG2, must be underpinned by existing capacity building initiatives, that regional organisations as well as other UN entities have a key role to play in sharing their experience and best practices, and that various experts, both governmental and non-governmental, as well as stakeholders, should have a place in the second group as they are often the ones who develop or participate in capacity building programmes .
Major Discussion Point
Building on existing initiatives and multi-stakeholder participation in DTG2
The topics of the thematic groups should be selected as soon as possible to allow countries to nominate experts, enable co-facilitators to guide discussions, and allow parties to prepare substantial contributions.
Arg. 3
Explanation
France called for the topics of the thematic groups to be selected as soon as possible, arguing that early selection would enable countries to nominate appropriate experts, allow co-facilitators to work alongside the chair to guide upcoming discussions, and enable countries and parties to prepare substantial contributions before the groups meet.
Evidence
France stated that it reiterates its call for the topics of the thematic groups to be selected as soon as possible, as this will make it possible for countries to nominate experts, allow the co-facilitators to work alongside the chair to guide the upcoming discussions, and enable the countries and parties to prepare substantial contributions to make before these groups .
Major Discussion Point
Procedural priorities for the dedicated thematic groups
113
WPM
261
Words
2 min
Time
Capacity building is a central element in ensuring that the benefits of the global mechanism reach all UN member states, as strengthening technical expertise, institutional capacities, and legal frameworks is essential to enabling states to prevent, detect, and respond to malicious ICT activities.
Arg. 1
Explanation
Serbia argued that capacity building is central to ensuring the global mechanism's benefits reach all member states. Strengthening technical expertise, institutional capacities, and legal frameworks is essential not only for national resilience but also as an important contribution to a more secure, stable, and peaceful ICT environment for all.
Evidence
Serbia stated that for it, capacity building is a central element in ensuring that the benefits of the mechanism reach all UN member states, and that strengthening technical expertise, institutional capacities and legal frameworks is essential to enabling states to better prevent, detect and respond to malicious ICT activities, and that capacity building is not only an investment in national resilience but also an important contribution to a more secure, stable and peaceful ICT environment for all .
Major Discussion Point
Capacity building as a foundational pillar for equitable participation
Serbia supports capacity building that is needs-based, demand-driven, sustainable, and coordinated, with the United Nations uniquely placed to facilitate coordination and connect needs with available resources.
Arg. 2
Explanation
Serbia expressed support for capacity building that adheres to key principles: needs-based, demand-driven, sustainable, and coordinated. Serbia also highlighted the unique role of the United Nations, given its universal character, in facilitating coordination, connecting needs with available resources, and avoiding duplication of efforts.
Evidence
Serbia stated that it supports capacity building that is needs-based, demand-driven, sustainable, and coordinated, and that the United Nations, given its universal character, is uniquely placed to facilitate coordination, connect needs with available resources, and avoid duplication of efforts .
Major Discussion Point
Principles for effective capacity building and the role of the UN
Agreed with
Republic of KoreaMalawiCambodiaBotswanaGermanyAustraliaCote d'IvoireMexicoTongaKiribatiGhanaAlbaniaArgentinaIrelandMalaysiaNew ZealandSouth AfricaVanuatu
on: Capacity building must be demand-driven, needs-based, nationally owned, and tailored to the specific circumstances of recipient states, avoiding a one-size-fits-all approach
Serbia's distinctive position as both a beneficiary and contributor to regional cooperation confirms that well-targeted, locally owned capacity building delivers tangible results.
Arg. 3
Explanation
Serbia described its distinctive position in the capacity building landscape, having benefited from international cooperation and capacity building programmes while also investing substantially in its own national capabilities and contributing actively to regional cooperation in Southeast Europe. This dual experience confirms that well-targeted, locally owned capacity building delivers tangible results.
Evidence
Serbia stated that it has benefited from international cooperation and capacity building programmes and projects with a wide range of partners, while investing substantially in its own national capabilities and contributing actively to regional cooperation in Southeast Europe, including through the exchange of expertise, joint exercises, and cooperation between national CERTs, and that this experience confirms that well-targeted, locally-owned capacity building delivers tangible results .
Major Discussion Point
National experience with capacity building
Serbia underlines the importance of the full, equal, and meaningful participation of women in all processes related to ICT security.
Arg. 4
Explanation
Serbia concluded its statement by emphasising the importance of gender inclusion in ICT security processes. The full, equal, and meaningful participation of women in all processes related to ICT security is a principle Serbia considers essential.
Evidence
Serbia stated that it underlines the importance of the full, equal, and meaningful participation of women in all processes related to ICT security .
Major Discussion Point
Gender and inclusion in capacity building
Agreed with
MalawiBotswanaBrazilMexicoCanadaSouth AfricaTongaUruguayAlbaniaGhanaBahamasMauritiusCote d'IvoireBosnia and Herzegovina
on: Gender inclusion and the Women in International Security and Cyberspace Fellowship are essential components of effective and inclusive capacity building
129
WPM
428
Words
3 min
Time
Two decades of sustained national investment supported by genuine partnerships have given Vanuatu the strongest cybersecurity standing in its region, demonstrating that the return on well-designed capacity building is measurable.
Arg. 1
Explanation
Vanuatu testified from its own national experience that capacity building works, citing two decades of sustained investment and genuine partnerships as having produced the strongest cybersecurity standing in the Pacific region by international assessment. While acknowledging remaining gaps and thin resources, Vanuatu argued that sceptics of the capacity building pillar should study the Pacific before doubting it.
Evidence
Vanuatu stated that two decades of sustained national investment supported by genuine partnerships have given Vanuatu the strongest cyber security standing in its region by international assessment, and that with purpose the return on well-designed capacity building is measurable, and that sceptics of this pillar should study the Pacific before doubting it .
Major Discussion Point
Evidence that capacity building works
Capacity building in the Pacific must be Pacific-led, co-designed by those it serves, contextualised, coordinated, sustainable, and inclusive, as articulated in the Joint Pacific Islands Forum paper submitted to the OEWG.
Arg. 2
Explanation
Vanuatu outlined the principles for effective capacity building in the Pacific region, drawn from the Joint Pacific Islands Forum paper on capacity building submitted to the OEWG. These principles include Pacific leadership, co-design by those the activities serve, contextualisation, coordination among partners, sustainability beyond funding cycles, and full societal inclusion.
Evidence
Vanuatu stated that capacity building in its region must be Pacific-led with activities co-designed by those they serve, contextualised because one size fits no body, coordinated so that partners complement rather than crowd each other, sustainable outlasting the funding cycles that create it, and inclusive of their societies in full, as articulated in the Joint Pacific Islands Forum paper on capacity building submitted to the OEWG .
Major Discussion Point
Principles for effective capacity building in the Pacific context
Agreed with
BotswanaAustraliaCote d'IvoireDemocratic Republic of the CongoGhanaGermanyGuyanaNew ZealandKiribati
on: Regional cooperation and regional organisations play an essential role in effective capacity building and should be leveraged by the global mechanism
The Pacific has unique capacity building needs including climate-resilient digital infrastructure and the capacity to assess emerging technologies before adopting them, which the global mechanism should treat as standing Pacific input.
Arg. 3
Explanation
Vanuatu highlighted that the Pacific region has specific capacity building needs not commonly heard from other regions, including climate-resilient digital infrastructure and the capacity to assess emerging technologies such as artificial intelligence, cloud services, and satellite connectivity before adopting them. Vanuatu asked that the mechanism treat the Pacific Islands Forum paper as a standing Pacific input to its capacity building agenda.
Evidence
Vanuatu stated that the Pacific Islands Forum paper identified needs this room will hear from few other regions, including climate-resilient digital infrastructure and the capacity to assess emerging technologies such as artificial intelligence, cloud services, and satellite connectivity before adopting them, describing what it takes to digitalise safely on the front line of a changing climate, and asked that the mechanism treat the paper as a standing Pacific input to its capacity-building agenda .
Major Discussion Point
Unique capacity building needs of Pacific island states
The December DTG meeting should deliver three concrete outputs: an honest global mapping of needs against provision, a user-friendly capacity building portal, and credible progress on sustainable financing.
Arg. 4
Explanation
Vanuatu called for the December DTG meeting to be remembered as the moment the mechanism started delivering, and specified three concrete outputs it hopes to see. These are an honest global mapping of needs against provision that exposes mismatches, a capacity building portal shaped around how officials in recipient states actually work, and credible progress on financing that does not evaporate with the next budget cycle.
Evidence
Vanuatu stated that it hopes the DTGs deliver three outputs: an honest global mapping of needs against provision exposing the mismatches that everyone suspects and nobody has documented, a capacity-building portal shaped around how officials in recipient states actually work, and credible progress on financing that does not evaporate with the next budget cycle .
Vanuatu came to the OEWG to ensure that the smallest states would shape the capacity building agenda rather than merely receive it, and the Pacific Islands Forum paper is proof of that intent.
Arg. 5
Explanation
Vanuatu articulated its broader ambition for the global mechanism: that the smallest states should be shapers of the capacity building agenda, not passive recipients. The Pacific Islands Forum paper submitted to the OEWG is presented as evidence of this intent, and the mechanism's task is to prove it can deliver on that promise.
Evidence
Vanuatu stated that it came to the OEWG to ensure that the smallest states would shape this agenda rather than receive it, that the Pacific paper is proof of that intent, and that the mechanism’s task is to prove it can deliver .
Major Discussion Point
Agency of small island states in shaping the capacity building agenda
93
WPM
405
Words
4 min
Time
Capacity building is a cornerstone of the framework for responsible state behaviour in ICTs, enabling states to prevent, detect, respond to, and recover from cyber threats while participating meaningfully in international cooperation.
Arg. 1
Explanation
Ghana recognised capacity building as a cornerstone of the cumulative and evolving framework for responsible state behaviour in the use of ICTs. Without adequate capacity, states cannot effectively engage with cyber threats or contribute meaningfully to international cooperation efforts.
Evidence
Ghana stated that capacity building enables states to prevent, detect, respond to and recover from cyber threats while participating meaningfully in international cooperation, and welcomed the establishment of the Global ICT Security Cooperation and Capacity Building Portal, the UN Voluntary Fund and the Fellowship Programme .
Major Discussion Point
Capacity building as a foundational pillar of the ICT security framework
Agreed with
South AfricaMalawiGuyanaIndiaDemocratic Republic of the CongoIslamic Republic of Iran
on: The operationalisation of the UN Voluntary Fund for ICT security capacity building and the Global ICT Security Cooperation and Capacity Building Portal are priority mechanisms for the global mechanism
Capacity building must be needs-driven, nationally owned, and tailored to each country's context, priorities, and level of cyber maturity, with no one-size-fits-all approach.
Arg. 2
Explanation
Ghana emphasised that effective capacity building cannot follow a uniform template but must be guided by national priorities and adapted to each country's specific context and level of cyber maturity. National priorities should guide the design and delivery of capacity building programmes to ensure long-term impact and sustainable resilience.
Evidence
Ghana stated that for capacity building to be effective it must be needs-driven, nationally owned and tailored to each country’s context, priorities and level of cyber maturity, and that there is no one-size-fits-all approach, with national priorities guiding the design and delivery of capacity building programmes to ensure long-term impact and sustainable resilience .
Major Discussion Point
Principles for effective capacity building
Agreed with
Republic of KoreaMalawiCambodiaBotswanaGermanyAustraliaCote d'IvoireMexicoTongaKiribatiAlbaniaSerbiaArgentinaIrelandMalaysiaNew ZealandSouth AfricaVanuatu
on: Capacity building must be demand-driven, needs-based, nationally owned, and tailored to the specific circumstances of recipient states, avoiding a one-size-fits-all approach
Capacity building should extend beyond technical training to strengthen institutions, leadership, and human capital across government, law enforcement, diplomacy, academia, and the private sector.
Arg. 3
Explanation
Ghana argued that capacity building must go beyond purely technical training to encompass a broader range of actors and competencies. This includes fostering collaboration across technical, legal, policy, and operational communities, and strengthening institutions and human capital at all levels.
Evidence
Ghana stated that capacity building should extend beyond technical training to strengthen institutions, leadership and human capital across government, law enforcement and diplomacy, academia and the private sector, while fostering collaboration across technical, legal, policy, and operational communities .
Major Discussion Point
Scope and content of capacity building
Agreed with
ItalyGuatemalaBahamasMauritiusBotswanaAlbania
on: Capacity building must be inclusive and extend beyond technical training to encompass institutional development, policy support, workforce development, and awareness programmes
Gender must be mainstreamed across all capacity building initiatives, with increased opportunities for women through training, mentorship, fellowship, and leadership programmes being essential to a more inclusive and resilient cybersecurity ecosystem.
Arg. 4
Explanation
Ghana underscored the importance of integrating gender perspectives into all capacity building efforts. Increasing opportunities for women through various programmes is essential to building a more inclusive and resilient cybersecurity ecosystem, and Ghana commended initiatives such as the UNIDIR Women in Cyber Fellowship.
Evidence
Ghana stated that it further underscores the importance of mainstreaming gender across all capacity-building initiatives, and that increasing opportunities for women through training, mentorship, fellowship, and leadership programmes is essential to building a more inclusive and resilient cybersecurity ecosystem, commending initiatives such as the UNIDIR Women in Cyber Fellowship, of which the speaker is a fellow, and the HESCYBER Tract .
Major Discussion Point
Gender and inclusion in capacity building
Agreed with
MalawiBotswanaBrazilMexicoCanadaSouth AfricaTongaUruguayAlbaniaBahamasMauritiusCote d'IvoireSerbiaBosnia and Herzegovina
on: Gender inclusion and the Women in International Security and Cyberspace Fellowship are essential components of effective and inclusive capacity building
South-South, triangular, and regional cooperation complements North-South partnerships by providing peer learning, knowledge exchange, and the sharing of practical experience, with regional organisations remaining important partners.
Arg. 5
Explanation
Ghana welcomed the continued emphasis on South-South, triangular, and regional cooperation as valuable complements to traditional North-South partnerships. Regional organisations play an important role in strengthening institutional capacities and supporting implementation of the framework.
Evidence
Ghana stated that it welcomes the continued emphasis on South-South, Triangular, and Regional Cooperation, which complements North-South partnerships by providing peer learning, knowledge exchange, and the sharing of practical experience, and that regional organisations remain important partners in strengthening institutional capacities and supporting implementation .
Major Discussion Point
Regional and South-South cooperation in capacity building
Agreed with
BotswanaAustraliaCote d'IvoireDemocratic Republic of the CongoGermanyGuyanaVanuatuNew ZealandKiribati
on: Regional cooperation and regional organisations play an essential role in effective capacity building and should be leveraged by the global mechanism
Multi-stakeholder partnerships involving the private sector, academia, civil society, and the technical community are essential to ensuring that no country is left behind in capacity building.
Arg. 6
Explanation
Ghana recognised the valuable contributions of the private sector, academia, civil society, and the technical community to capacity building efforts. Multi-stakeholder partnerships are essential to ensuring that no country is left behind, and Ghana committed to working with all stakeholders to advance an inclusive, sustainable, and action-oriented capacity building agenda.
Evidence
Ghana stated that it recognises the valuable contributions of the private sector, academia, civil society, and the technical community, and that multi-stakeholder partnership will be essential to ensuring that no country is left behind, and that Ghana remains committed to working with member states and all stakeholders to advance an inclusive, sustainable and action-oriented capacity building under the global mechanism .
Major Discussion Point
Multi-stakeholder participation in capacity building
137
WPM
440
Words
3 min
Time
Cyber capacity building is an essential component of international efforts to promote an open, secure, stable, interoperable, and resilient ICT environment, requiring technical, legal, policy, operational, and diplomatic capacities.
Arg. 1
Explanation
Singapore highlighted that states have consistently emphasised the importance of building a broad range of capacities to enable effective implementation of the UN Framework for Responsible State Behaviour in Cyberspace. Capacity building should be needs-based, nationally owned, practical, and coordinated to address the complex challenges in cyberspace.
Evidence
Singapore stated that cybercapacity building is an essential component of international efforts to promote an open, secure, stable, interoperable and resilient ICT environment, and that states have consistently highlighted the importance of building technical, legal, policy, operational and diplomatic capacities to enable effective implementation of the UN Framework for Responsible State Behaviour in Cyberspace, and that capacity building should be needs-based, nationally owned, practical and coordinated .
Major Discussion Point
Strategic importance of cyber capacity building
Cross-regional exchanges and sharing can be an extremely useful form of capacity building, as participants often equip each other as much as the trainers who provide capacity building.
Arg. 2
Explanation
Singapore argued that capacity building is not a one-directional transfer from providers to recipients, but a mutual exchange where participants enrich each other's understanding. Cross-regional exchanges, such as those between Pacific Island Forum member states and ASEAN, exemplify this approach.
Evidence
Singapore stated that cross-regional exchanges and sharing can be an extremely useful form of capacity building, and that participants often equip each other as much as the trainers who provide capacity building, noting that Singapore’s capacity building programmes are now privileged to work with members from the Pacific Island Forum member states as well as ASEAN .
Major Discussion Point
Peer-to-peer and cross-regional learning in capacity building
Singapore runs the UN Singapore Cyber Fellowship to empower senior officials with interdisciplinary expertise to effectively oversee national cyber and digital security policy, strategy, and operations.
Arg. 3
Explanation
Singapore described its UN Singapore Cyber Fellowship as a concrete national capacity building initiative aimed at senior officials. The fellowship seeks to build interdisciplinary expertise across policy, operational, technical, legal, and diplomatic dimensions of ICT security.
Evidence
Singapore stated that next month it will run the seventh iteration of the United Nations Singapore Cyber Fellowship, which seeks to empower senior officials with interdisciplinary expertise to effectively oversee national cyber and digital security policy, strategy and operations requirements, and that selection letters have gone out with fellows to be welcomed to the seventh iteration .
Major Discussion Point
National capacity building initiatives and programmes
International coordination mechanisms should be developed through a co-creation model that places national priorities at the centre, leverages regional coordination for needs identification, and uses international mechanisms to facilitate visibility, coordination, and partnerships.
Arg. 4
Explanation
Singapore proposed a co-creation model for international capacity building coordination that centres national priorities, uses regional platforms as the primary vehicle for identifying and consolidating needs, and relies on international mechanisms to provide visibility and facilitate partnerships. Effective coordination is a continuous and evolving commitment, not a one-time exercise.
Evidence
Singapore stated that there is an opportunity to consider how international coordination mechanisms can better support cyber capability capacity building efforts, and proposed working together to develop a co-creation model that places national priorities at the centre, leverages regional coordination as the primary platform for needs identification and consolidation, and uses international mechanisms to facilitate visibility, coordination and partnerships, noting that effective coordination is not a one-time exercise but a continuous and evolving commitment .
Major Discussion Point
Co-creation and coordination in international capacity building
Agreed with
Republic of KoreaGermanyAustraliaBrazilIsraelMauritiusIrelandNew ZealandUruguayJapan
on: Duplication of existing capacity building efforts must be avoided through enhanced coordination, complementarity, and efficient use of available resources
Capacity building constitutes one of the fundamental pillars of the framework for responsible state behaviour in ICTs and is an indispensable condition for all states to participate safely, effectively, and meaningfully in the digital environment.
Arg. 1
Explanation
Guatemala argued that capacity building is not merely a supplementary element but a fundamental pillar of the framework for responsible state behaviour. Without it, states cannot participate safely or effectively in the digital environment, making it an indispensable precondition for meaningful engagement.
Evidence
Guatemala stated that its delegation believes that capacity building constitutes one of the fundamental pillars of the framework for responsible state behaviour in ICTs, and that it also represents an indispensable condition for all states to be able to participate safely, effectively, and meaningfully in the digital environment .
Major Discussion Point
Capacity building as a foundational pillar of the ICT security framework
Agreed with
Republic of KoreaBotswanaRwandaMalawiCameroonGhanaAlbaniaKiribatiNew ZealandTongaMalaysiaSouth AfricaCote d'IvoireDemocratic Republic of the CongoAustraliaMarshall Islands
on: Capacity building is the foundational pillar upon which all other pillars of the ICT security framework depend
Capacity building should be understood as a comprehensive process that strengthens institutions, develops human resources, promotes public policies, improves national resilience, and helps narrow digital divides, not solely as technical assistance.
Arg. 2
Explanation
Guatemala argued for a broad conception of capacity building that goes well beyond technical assistance. It encompasses institutional strengthening, human resource development, public policy promotion, and resilience improvement, and serves as the mechanism for translating agreed commitments into concrete national capacities.
Evidence
Guatemala stated that for it, capacity building should not be understood solely as technical assistance, but is a comprehensive process that strengthens institutions, develops human resources, promotes public policies, improves national resilience, and helps narrow the digital divides that still persist in some states, and that it is the element that makes it possible to translate commitments and consensus reached into concrete institutional, technical, and human capacities at the national level .
Major Discussion Point
Scope and content of capacity building
Agreed with
ItalyGhanaBahamasMauritiusBotswanaAlbania
on: Capacity building must be inclusive and extend beyond technical training to encompass institutional development, policy support, workforce development, and awareness programmes
In Guatemala, human resources are the most important element in the digital and cybersecurity ecosystem, and fellowship programmes are very useful for countries with insufficient own resources to develop expertise.
Arg. 3
Explanation
Guatemala highlighted the critical importance of human capital development in the cybersecurity ecosystem, noting that only a small percentage of Guatemalans have higher education in computer science and even fewer are experts. Fellowship programmes are therefore particularly valuable for countries like Guatemala where own resources are insufficient.
Evidence
Guatemala stated that in the digital and cyber security ecosystem human resources are always the most important, and that in Guatemala where only a small percentage of people have higher education in computer science and even fewer experts, this is a major problem, making it necessary to work together with NGOs and private sector initiatives including academia to strengthen fellowship programmes which are very useful to countries like Guatemala when own resources are insufficient .
Major Discussion Point
Human capital development and fellowship programmes
Guatemala reaffirms its commitment to an inclusive, action-oriented approach to capacity building based on the needs of states, as no state can be fully secure until all have the capacities necessary to meet digital challenges.
Arg. 4
Explanation
Guatemala concluded by reaffirming its commitment to a collective approach to capacity building, grounded in the recognition that individual state security is inseparable from the security of all. An inclusive, action-oriented, and needs-based approach is therefore essential.
Evidence
Guatemala reaffirmed its commitment to work together to promote an approach to capacity building that is inclusive, action-oriented, and based on the needs of states, as it is convinced that no state can be fully secure until all of us have the capacities necessary to meet the challenges of the digital environment .
Major Discussion Point
Collective security rationale for capacity building
Guatemala supports initiatives related to the protection of critical infrastructure, strengthening of national CERTs, cyber diplomacy, application of norms of responsible behaviour, incident response, and addressing challenges associated with emerging technologies including artificial intelligence.
Arg. 5
Explanation
Guatemala outlined specific substantive areas that capacity building should address, covering both technical and diplomatic dimensions. The delegation emphasised the importance of addressing emerging technologies, including artificial intelligence, as part of a comprehensive capacity building agenda.
Evidence
Guatemala stated that it believes it is important to continue promoting initiatives related to the protection of critical infrastructure, the strengthening of national C-CERTs and CERTs, cyber diplomacy, the application of the norms of responsible behaviour, incident response and the challenges associated with emerging technologies including artificial intelligence .
Major Discussion Point
Scope and content of capacity building
138
WPM
320
Words
2 min
Time
Closing the digital divide to ensure all states can harness the benefits of ICTs while mitigating global cyber risks is a central purpose of capacity building, requiring effective delivery and sharing of national best practices.
Arg. 1
Explanation
Ireland framed capacity building as essential to closing the digital divide and enabling all states to benefit from ICTs while managing cyber risks. Effective delivery of capacity building and sharing of national best practices are necessary to help states implement the UN Framework of Responsible State Behaviour in their national and regional frameworks.
Evidence
Ireland stated that closing the digital divide to ensure all states can harness the benefits of ICTs while mitigating global cyber risks through capacity building is a central concern, and that the mechanism must work towards effective delivery of capacity building and the sharing of national best practices to help states implement the UN Framework of Responsible State Behaviour in their national and regional frameworks .
Major Discussion Point
Capacity building as a tool for bridging the digital divide
Capacity building must be based on the needs identified by individual states and be country-driven, with limited resources used in the most effective way possible, avoiding duplication.
Arg. 2
Explanation
Ireland emphasised that capacity building must be grounded in the needs identified by individual states themselves and be country-driven in its design and delivery. Given the limited resources available, it is essential to use them as effectively as possible and to avoid duplication of efforts.
Evidence
Ireland stated that capacity building must be based on the needs identified by individual states, as many have already said, and be country-driven, and that the limited resources available must be used in the most effective way possible, avoiding duplication .
Major Discussion Point
Principles for effective capacity building
Agreed with
Republic of KoreaGermanyAustraliaBrazilIsraelMauritiusNew ZealandUruguayJapanSingapore
on: Duplication of existing capacity building efforts must be avoided through enhanced coordination, complementarity, and efficient use of available resources
Participation programmes organised through the UN with support from member states must continue to ensure the broadest possible involvement of participants so that all contribute to deliberations and have their views reflected in the process.
Arg. 3
Explanation
Ireland highlighted that participation by many delegations in the OEWG and now in the Global Mechanism has been assisted through various programmes organised through the UN with support from member states. These efforts must continue to ensure the broadest possible involvement so that all views are reflected in how the process develops.
Evidence
Ireland stated that participation by many participants in the OEWG and now in the Global Mechanism has been assisted through various programmes, mostly organised through the UN with support from member states, and that these efforts must continue to ensure the broadest possible involvement of participants so that all contribute to deliberations and have their views reflected in how this process develops .
Major Discussion Point
Inclusive participation in the global mechanism
Ireland supports the further development of a digital tool for state implementation of the UN framework, building on the voluntary norms implementation checklist and the role of the global roundtable on capacity building.
Arg. 4
Explanation
Ireland expressed support for developing practical digital tools to assist states in implementing the UN framework, building on existing instruments such as the voluntary norms implementation checklist. The global roundtable on capacity building should play a role in enhancing coordination and cooperation, including matchmaking between regional priorities and donor offerings.
Evidence
Ireland stated that it supports the further development of a digital tool for state implementation of the UN framework building on the voluntary norms implementation checklist and the role of the global roundtable on capacity building and ensuring enhanced coordination and cooperation including matchmaking between regional priorities and donor offerings .
Major Discussion Point
Practical tools for framework implementation
Discussions at DTG1 and DTG2 must be aligned so that discussions in the first are reflected in the work undertaken in the second, and should focus on multi-stakeholder roles, regional coordination, gender and youth inclusion, and mainstreaming agreed ICT security capacity building guidelines.
Arg. 5
Explanation
Ireland called for coherence between the two dedicated thematic groups, arguing that the discussions in DTG1 should inform and be reflected in the work of DTG2. The discussions should also address the role of the multi-stakeholder community, coordination with regional organisations, inclusion of women and youth, and mainstreaming of agreed capacity building guidelines.
Evidence
Ireland stated that discussions at DTG1 and DTG2 must be aligned so that the discussions at the first are reflected in the work undertaken in the second, and that discussions should also focus on the role of the multi-stakeholder community in the design and delivery of cyber capacity building, ensuring effective coordination with the work being done by regional organisations, ensuring the effective inclusion of women and youth in cyber capacity building efforts, and generally work to mainstream the agreed ICT security capacity building guidelines as adopted in the 2021 OEWG .
Major Discussion Point
Alignment and priorities for the dedicated thematic groups
Disagreed with
MexicoFranceMalaysia
on: The relationship and hierarchy between DTG1 and DTG2
141
WPM
265
Words
2 min
Time
Capacity building is the enabler that underpins all aspects of the global mechanism's work, and the Pacific Islands Forum working paper on regional capacity building priorities should be recommended to the mechanism.
Arg. 1
Explanation
New Zealand reiterated the key message from the Pacific Islands Forum that capacity building is the enabler underpinning all aspects of the global mechanism's work. New Zealand also recommended the Pacific Islands Forum working paper submitted to the OEWG, which outlined regional capacity building priorities, as a valuable reference for the mechanism.
Evidence
New Zealand stated that it reiterates the key message that capacity building is the enabler that underpins all aspects of the global mechanisms work, and recommended the Pacific Islands Forum working paper submitted to the OEWG last year that outlined regional capacity building priorities .
Major Discussion Point
Capacity building as a foundational pillar of the ICT security framework
Agreed with
Republic of KoreaBotswanaRwandaMalawiCameroonGhanaAlbaniaKiribatiTongaMalaysiaGuatemalaSouth AfricaCote d'IvoireDemocratic Republic of the CongoAustraliaMarshall Islands
on: Capacity building is the foundational pillar upon which all other pillars of the ICT security framework depend
New Zealand's capacity building efforts are focused in the Pacific region, including building CERT capabilities, developing national cybersecurity strategies, and running cybersecurity public awareness campaigns.
Arg. 2
Explanation
New Zealand described its national capacity building efforts as concentrated in the Pacific region, covering a range of practical areas. These include building CERT capabilities, developing national cybersecurity strategies, and conducting cybersecurity public awareness campaigns, as well as supporting the Women in International Security and Cyberspace Fellowship.
Evidence
New Zealand stated that its capacity building efforts are focused in the Pacific region, including building CERT capabilities, developing national cybersecurity strategies, and cyber security public awareness campaigns, and that it is pleased to be supporting the Women in International Security at Cyberspace Fellowship which last week saw 37 fellows from 30 countries build connections and explore key issues shaping cyber security .
Major Discussion Point
National capacity building initiatives and programmes
Agreed with
BotswanaAustraliaCote d'IvoireDemocratic Republic of the CongoGhanaGermanyGuyanaVanuatuKiribati
on: Regional cooperation and regional organisations play an essential role in effective capacity building and should be leveraged by the global mechanism
The global mechanism and DTG2 should deliver a capacity building approach that is coherent, contextualised, calibrated, and constructive, ultimately measured by whether it makes a practical difference.
Arg. 3
Explanation
New Zealand outlined four key qualities that the global mechanism's approach to capacity building should embody: coherence by responding to identified needs and avoiding duplication; contextualisation by tailoring to cultural, economic, and geographic circumstances; calibration to the UN operating context; and constructiveness by actually leading to practical support and improved outcomes.
Evidence
New Zealand stated that the global mechanism, including DTG2, should deliver an approach on capacity building that is coherent by responding to identified needs and avoiding duplication, contextualised by ensuring capacity building is tailored to cultural contexts, economic conditions and geographic circumstances, calibrated to the UN operating context, and most importantly constructive by actually leading to practical support and improved outcomes, and that success will ultimately be measured by whether the global mechanism makes a difference .
Major Discussion Point
Principles and standards for effective capacity building under the global mechanism
Agreed with
MalawiCambodiaCameroonAustralia
on: The measure of successful capacity building should be concrete outcomes rather than process metrics such as number of workshops or certificates
If the global mechanism makes a difference in the context of Pacific Island member states, it can guarantee to make a difference for all member states.
Arg. 4
Explanation
New Zealand argued that the Pacific Island states serve as a meaningful test case for the global mechanism's effectiveness. If the mechanism can demonstrably improve capacity building outcomes for Pacific Island member states, this would be evidence that it is working for all member states.
Evidence
New Zealand stated that to borrow a sentiment from some of its Pacific colleagues, if the mechanism makes a difference in the context of Pacific Island member states, then you can guarantee that it will make a difference for all member states .
Major Discussion Point
Measuring the effectiveness of the global mechanism
167
WPM
617
Words
4 min
Time
DTG2 should focus on identifying national and regional capacity building needs and compiling best practices to foster complementarity between existing initiatives.
Arg. 1
Explanation
Argentina believes that within DTG2, the work should be oriented towards identifying national and regional capacity building needs, as well as putting together best practices to foster complementarity between existing countries and initiatives. This approach would help avoid duplication and ensure that the group's work adds practical value.
Evidence
Argentina stated that within DTG2 the work could be oriented towards identifying national needs and regional needs in capacity building, as well as putting together best practices to foster complementarity between existing countries .
Major Discussion Point
Priorities and working methods for DTG2
Capacity building should be understood broadly, encompassing not only human resource training but also securing ICT infrastructure and improving cyber resilience, focused on each country's ability to develop its own protection strategies.
Arg. 2
Explanation
Argentina argued that capacity building should not be limited to training activities for human resources but should also complement necessary capacity for securing ICT infrastructure and improving cyber resilience. The focus should be on ensuring each country's ability to develop and implement its own protection strategies in accordance with its own priorities and national policy.
Evidence
Argentina stated that capacity building should continue to be understood in a broad sense, meaning training activities should not be based only on capacity building or strengthening human resources, but should be accompanied by and complement necessary capacity for securing ICT infrastructure and improving cyber resilience software, and should focus on ensuring each country’s ability to develop and implement its own protection strategies in accordance with its own priorities and national policy .
Major Discussion Point
Scope and content of capacity building
Capacity building must address the needs identified by the beneficiary country itself, taking into account specific geographical circumstances and avoiding standardised or one-size-fits-all models.
Arg. 3
Explanation
Argentina emphasised that capacity building must be demand-driven and tailored to the specific context of each beneficiary country, including its geographical circumstances. Standardised models that ignore differences between national contexts should be avoided.
Evidence
Argentina stated that it believes it is essential for capacity building to address the needs identified by the beneficiary country itself, bearing in mind specific geographical circumstances, thus avoiding any kind of standardised or models or one-size-fits-all that ignores the differences between national contexts .
Major Discussion Point
Principles for effective capacity building
Agreed with
Republic of KoreaMalawiCambodiaBotswanaGermanyAustraliaCote d'IvoireMexicoTongaKiribatiGhanaAlbaniaSerbiaIrelandMalaysiaNew ZealandSouth AfricaVanuatu
on: Capacity building must be demand-driven, needs-based, nationally owned, and tailored to the specific circumstances of recipient states, avoiding a one-size-fits-all approach
DTG2 should play a central role in developing concrete, practical, action-oriented recommendations and decisions to be elevated to the plenary, with proposals addressing broad-level issues to allow the plenary to focus on adoption of decisions.
Arg. 4
Explanation
Argentina argued that DTG2 should maintain a technical and results-oriented focus, developing recommendations and draft concrete, practical, action-oriented decisions aimed at being formally elevated to consideration by the plenary. Proposals from the second group should address broad-level issues so that the plenary can focus its limited time on adoption of decisions rather than resolving technical issues.
Evidence
Argentina stated that DTG2 should play a central role in developing recommendations and draft concrete, practical, action-oriented decisions aimed at being elevated formally to consideration by the plenary, and that proposals emanating from the second group should address broad-level issues, allowing the plenary to focus its efforts on the adoption of decisions and avoiding bringing into the plenary technical issues that could previously have been resolved in the thematic groups .
on: The December DTG2 meeting must deliver concrete, practical, and measurable outputs rather than further discussion of principles
DTG2 should submit to plenaries sufficiently technical and mature texts with broad support among delegations to contribute to more efficient, results-oriented decision-making.
Arg. 5
Explanation
Argentina argued that given the extremely limited time the plenary has to simultaneously address national interventions on five pillars, substantive discussions, and negotiation of outcomes, DTG2 should focus on submitting texts that are sufficiently mature and have broad support. This would contribute to more efficient decision-making that is results-oriented.
Evidence
Argentina stated that DTG2 should focus on submitting to plenaries sufficiently technical and mature texts that have broad support between the delegations participating, noting that this is particularly important given the extremely limited time that the plenary has to simultaneously address national interventions on the five pillars, substantive discussion and the discussion and negotiation of the texts and the outcomes of the different thematic groups .
Major Discussion Point
Efficiency and decision-making in the global mechanism
100
WPM
705
Words
7 min
Time
Digital transformation is a key priority for Cambodia, but sustainable development cannot rest on insecure digital foundations, and developing countries face increasingly sophisticated malicious ICT activity with constrained resources.
Arg. 1
Explanation
Cambodia emphasised that while digital progress is a key national priority, cyber resilience must advance alongside it. Developing countries face increasingly sophisticated cross-border malicious ICT activity while operating with constrained technical, institutional, and financial resources, making closing these gaps an investment in collective security.
Evidence
Cambodia stated that it is building a digital government, economy, and society while recognising that digital progress and cyber resilience must advance together, and that sustainable development cannot rest on insecure digital foundations, yet significant capacity gaps persist as developing countries face increasingly sophisticated malicious ICT activity, much of which is cross-border, while operating with constrained technical, institutional and financial resources .
Major Discussion Point
Challenges faced by developing countries in cyber capacity building
Capacity building must be demand-driven, tailored to national circumstances, and grounded in national ownership, with programmes designed jointly with recipient states and aligned with their national strategies.
Arg. 2
Explanation
Cambodia emphasised that capacity building must respond to national priorities, including protecting critical information infrastructure, strengthening incident response capabilities, and securing digital government services. Programmes should be designed jointly with recipient states and aligned with their national strategies, institutional context, and implementation timelines.
Evidence
Cambodia stated that capacity building must be demand-driven, tailored to national circumstances, and grounded in national ownership, with national priorities including protecting critical information infrastructure, strengthening national and sectoral incident response capabilities, and securing digital government services, and that programmes should be designed jointly with recipient states and aligned with their national strategies, institutional context, and implementation timelines .
Major Discussion Point
Principles for effective capacity building
Agreed with
Republic of KoreaMalawiBotswanaGermanyAustraliaCote d'IvoireMexicoTongaKiribatiGhanaAlbaniaSerbiaArgentinaIrelandMalaysiaNew ZealandSouth AfricaVanuatu
on: Capacity building must be demand-driven, needs-based, nationally owned, and tailored to the specific circumstances of recipient states, avoiding a one-size-fits-all approach
Capacity building must be sustainable and results-focused, building local trainers, institutional memory, and a national pool of cybersecurity professionals rather than relying on one-off training.
Arg. 3
Explanation
Cambodia argued that one-off training alone is insufficient for building true resilience. Sustainable capacity building requires training local trainers, establishing robust institutional memory, and strengthening the national pool of cybersecurity professionals, supported by international partnerships for joint research, knowledge exchange, and university-level collaboration.
Evidence
Cambodia stated that one-off training alone is insufficient and that true resilience is built when local trainers are trained, robust institutional memory is established, and the national pool of cybersecurity professionals is strengthened, and that Cambodia welcomes international partnerships that support joint research and knowledge exchange, facilitated access to relevant technologies, and university-level collaboration to build the next generation of the cyber workforce .
Major Discussion Point
Sustainability of capacity building efforts
Agreed with
MalawiKiribatiTongaNaoeroBosnia and HerzegovinaBahamas
on: Capacity building must be sustained over time and promote self-sufficiency rather than dependency, as single training events do not build institutions
Capacity building should be evidence-based, politically neutral, transparent, accountable, inclusive, non-discriminatory, and provided without conditions, with full respect for state sovereignty, human rights, and fundamental freedoms.
Arg. 4
Explanation
Cambodia outlined a set of principles that should govern capacity building, emphasising that it must be evidence-based and politically neutral, as well as inclusive and non-discriminatory. It should be undertaken through voluntary partnership and implemented with full respect for state sovereignty, human rights, and fundamental freedoms.
Evidence
Cambodia stated that capacity building should be evidence-based, politically neutral, transparent and accountable, and should be provided without conditions, and that it should be inclusive, non-discriminatory, undertaken through voluntary partnership, and implemented with full respect for state sovereignty, human rights and fundamental freedoms .
Major Discussion Point
Principles for effective capacity building
Disagreed with
SwitzerlandJapanUkraineCuba
on: Whether stakeholders (non-governmental actors) should have a meaningful role in the dedicated thematic groups
Cambodia is advancing its national cybersecurity legal and policy framework and has benefited from capacity building support from UNIDIR, Canada, Australia, and regional cooperation through ASEAN mechanisms.
Arg. 5
Explanation
Cambodia described concrete national steps it is taking to strengthen cyber resilience, including advancing its national cybersecurity legal and policy framework and enhancing the security of digital government services. Cambodia also acknowledged capacity building support from UNIDIR, Canada, Australia, and regional cooperation through ASEAN mechanisms.
Evidence
Cambodia stated that it is advancing its national cybersecurity legal and policy framework, strengthening CERT and incident response capabilities, and enhancing the security of its digital government services, and appreciated the recent Cambodia-UNIDIR cyber capacity building and policy training jointly organised by Cambodia’s Ministry of Post and Telecommunications and UNIDIR with support from the Government of Canada, as well as capacity building support from Australia and regional cooperation through the ASEAN Singapore Cyber Security Centre of Excellence and the ASEAN Japan Cyber Security Capacity Building Centre .
Major Discussion Point
National capacity building initiatives and programmes
The global mechanism should encourage close coordination between the two dedicated thematic groups so that implementation challenges identified in substantive discussions can inform tailored capacity building partnerships.
Arg. 6
Explanation
Cambodia encouraged close coordination between the two dedicated thematic groups so that implementation challenges identified in substantive discussions can confirm tailored capacity building partnerships. The mechanism should also support voluntary needs assessment, matchmaking between identified needs and available assistance, resource mobilisation, knowledge sharing, and measurable follow-up.
Evidence
Cambodia encouraged close coordination between the two dedicated thematic groups so that implementation challenges identified in substantive discussions can confirm tailored capacity building partnerships, and also supported voluntary needs assessment, matchmaking between identified needs and available assistance, resource mobilisation, knowledge sharing, and measurable follow-up .
Major Discussion Point
Coordination between dedicated thematic groups
The success of capacity building efforts should be measured by concrete results: stronger institutions, better prepared personnel, and more resilient essential services.
Arg. 7
Explanation
Cambodia argued that the success of capacity building efforts under the global mechanism should not be measured by process indicators alone but by concrete outcomes. These include stronger institutions, better prepared personnel, and more resilient essential services.
Evidence
Cambodia stated that the success of these efforts should be measured by concrete results, including stronger institutions, better prepared personnel, and more resilient essential services .
Major Discussion Point
Measuring the effectiveness of capacity building
Agreed with
MalawiCameroonAustraliaNew Zealand
on: The measure of successful capacity building should be concrete outcomes rather than process metrics such as number of workshops or certificates
137
WPM
765
Words
6 min
Time
A framework that only some states can implement is not yet a framework for all, and capacity building is the enabler underpinning everything else done in the global mechanism.
Arg. 1
Explanation
Kiribati aligned with the Pacific Islands Forum view that capacity building is the enabler underpinning all other work in the mechanism. Kiribati argued plainly that a framework that only some states can implement is not yet a framework for all, drawing on its own national experience to illustrate this point.
Evidence
Kiribati stated that it endorses the Forum’s view that capacity building is the enabler underpinning everything else done in the mechanism, and that a framework that only some states can implement is not yet a framework for all .
Major Discussion Point
Capacity building as a foundational pillar of the ICT security framework
Agreed with
Republic of KoreaBotswanaRwandaMalawiCameroonGhanaAlbaniaNew ZealandTongaMalaysiaGuatemalaSouth AfricaCote d'IvoireDemocratic Republic of the CongoAustraliaMarshall Islands
on: Capacity building is the foundational pillar upon which all other pillars of the ICT security framework depend
Kiribati's national cybersecurity strategy was developed through broad multi-stakeholder consultation with ITU support, and its maturity assessment with the Oceania Cyber Security Centre shaped its priorities.
Arg. 2
Explanation
Kiribati described how its national cybersecurity strategy was developed through broad multi-stakeholder consultation with technical support from the ITU, and how a national cybersecurity maturity assessment undertaken with the Oceania Cyber Security Centre provided an evidence base that shaped its priorities. The Kiribati Digital Government Project supported by the World Bank is also building institutions and infrastructure for secure digital services.
Evidence
Kiribati stated that its national cybersecurity strategy was developed through broad multi-stakeholder consultation with technical support from the ITU, that its national cybersecurity maturity assessment undertaken with the Oceania Cyber Security Centre gave it an evidence base that has shaped its priorities ever since, and that through the Kiribati Digital Government Project supported by the World Bank it is building the institutions and infrastructure on which secure digital services depend .
Major Discussion Point
National capacity building initiatives and programmes
Agreed with
BotswanaAustraliaCote d'IvoireDemocratic Republic of the CongoGhanaGermanyGuyanaVanuatuNew Zealand
on: Regional cooperation and regional organisations play an essential role in effective capacity building and should be leveraged by the global mechanism
Capacity building works when it is country-owned, with partners supporting priorities that the country itself identified rather than priorities identified for it.
Arg. 3
Explanation
Kiribati drew on its national experience to identify country ownership as the first and most important lesson of effective capacity building. Partners gave Kiribati not capability delivered ready-made, but the chance to build its own capacity and the patience to let it do so, supporting priorities that Kiribati itself identified.
Evidence
Kiribati stated that what its partners gave was not capability delivered ready-made but the chance to build their home and the patience to let them do it, and that capacity building works when it is country-owned, with partners supporting priorities that Kiribati identified, not priorities identified for them .
Major Discussion Point
Principles for effective capacity building
Agreed with
Republic of KoreaMalawiCambodiaBotswanaGermanyAustraliaCote d'IvoireMexicoTongaGhanaAlbaniaSerbiaArgentinaIrelandMalaysiaNew ZealandSouth AfricaVanuatu
on: Capacity building must be demand-driven, needs-based, nationally owned, and tailored to the specific circumstances of recipient states, avoiding a one-size-fits-all approach
Capacity building must be sustained, as a single training builds a memory but does not build an institution.
Arg. 4
Explanation
Kiribati identified sustainability as the second key lesson of effective capacity building, arguing that a single training event builds a memory but does not build an institution. Long-term, sustained engagement is required to develop genuine institutional capacity.
Evidence
Kiribati stated that the second lesson is that capacity building must be sustained, noting that a single training builds a memory but does not build an institution .
Major Discussion Point
Sustainability of capacity building efforts
Agreed with
MalawiCambodiaTongaNaoeroBosnia and HerzegovinaBahamas
on: Capacity building must be sustained over time and promote self-sufficiency rather than dependency, as single training events do not build institutions
Capacity building must be inclusive, as in small societies inclusion is not a procedural courtesy but the only way capacity is built and sustained.
Arg. 5
Explanation
Kiribati identified inclusion as the third key lesson, arguing that in a society as small as Kiribati's, inclusion is not a procedural courtesy but the only way capacity is built at all and the only way it stays. Kiribati's cybersecurity was built not by government alone but by churches, communities, the private sector, schools, and regional partners.
Evidence
Kiribati stated that the third lesson is that capacity building must be inclusive, noting that government alone did not build Kiribati’s cybersecurity and that churches, communities, the private sector, schools, and regional partners each carry part of it, and that in a society as small as theirs, inclusion is not a procedural courtesy but the only way capacity is built at all and the only way it stays .
Major Discussion Point
Inclusive and multi-stakeholder approach to capacity building
The December DTG meeting should focus on concrete, measurable outputs including mapping needs against what already exists, developing tools states can actually use, and identifying sustainable financing.
Arg. 6
Explanation
Kiribati welcomed the dedicated thematic group on capacity building and asked that the December meeting focus on concrete, measurable outputs rather than further discussion. These outputs should include mapping needs against what already exists, developing tools states can actually use, and identifying sustainable financing.
Evidence
Kiribati stated that it asked the December meeting to focus on concrete, measurable outputs, including mapping needs against what already exists, developing tools states can actually use, and identifying sustainable financing .
on: The December DTG2 meeting must deliver concrete, practical, and measurable outputs rather than further discussion of principles
Meeting times should be rotated to accommodate delegations from different time zones, as hybrid participation at 5am session after session is not participation but endurance, and an inclusive mechanism must be inclusive in the practical design of its work.
Arg. 7
Explanation
Kiribati raised the practical issue of meeting times, noting that as a country 19 hours ahead of New York, a 10am meeting in New York is 5am the following morning in Kiribati. Kiribati argued that requiring officials who hold the entire national cybersecurity function to choose between attending the mechanism and defending their country is not genuine inclusion, and that rotating meeting times is the simplest form of inclusion the mechanism could offer.
Evidence
Kiribati stated that it is 19 hours ahead of the meeting room, meaning a 10 o’clock meeting in New York is 5 o’clock the following morning in its capital, and that when it asks for meeting times to be rotated it is not asking for comfort but asking that the officers who hold the entire national cybersecurity function and who must be at their desk the same day are not required to choose between attending the mechanism and defending their country, and that hybrid at 5 in the morning session after session is not participation but endurance .
Major Discussion Point
Inclusive participation and hybrid access in the global mechanism
Fellowship and sponsorship programmes that enabled Kiribati's delegation to participate demonstrate what capacity building looks like in practice, turning attendance into participation by equipping delegates with training, not just travel.
Arg. 8
Explanation
Kiribati shared that its delegation of three people came to the session through the Women in Cyber Fellowship and the United Nations Sponsorship Programme, and that without those programmes none of them would be in the room. Kiribati argued that the training provided by these programmes is not incidental to the travel but is what turns attendance into participation.
Evidence
Kiribati stated that its delegation of three people includes two who are there through the Women in Cyber Fellowship and one through the United Nations Sponsorship Programme, and that not one of them would be in the room without those programmes, and that the training is not incidental to the travel but is what turns attendance into participation .
Major Discussion Point
Value of fellowship programmes for small island developing states
121
WPM
790
Words
7 min
Time
Capacity building is a cornerstone of the framework for responsible state behaviour in cyberspace and an indispensable enabler for international peace, security, and sustainable development.
Arg. 1
Explanation
Albania regarded capacity building as one of the most practical and impactful ways to support states in addressing existing and emerging ICT threats and implementing agreed commitments on ICT security. Effective capacity building strengthens not only technical capacities but also institutions, policies, partnerships, and a cybersecurity culture embraced by people as professionals and individuals.
Evidence
Albania stated that it regards capacity building as a cornerstone of the framework for responsible state behaviour in cyberspace and an indispensable enablement for international peace, security, and sustainable development, and that it is one of the most practical and impactful ways to support states in addressing existing and emerging ICT threats and implementing agreed commitments on ICT security .
Major Discussion Point
Capacity building as a foundational pillar of the ICT security framework
Agreed with
Republic of KoreaBotswanaRwandaMalawiCameroonGhanaKiribatiNew ZealandTongaMalaysiaGuatemalaSouth AfricaCote d'IvoireDemocratic Republic of the CongoAustraliaMarshall Islands
on: Capacity building is the foundational pillar upon which all other pillars of the ICT security framework depend
Albania supports capacity building that is demand-driven, needs-based, sustainable, transparent, and nationally owned, and that is inclusive, accessible, and responsive to the specific needs and priorities of each state.
Arg. 2
Explanation
Albania expressed support for capacity building that adheres to key principles including being demand-driven, needs-based, sustainable, transparent, and nationally owned. Such efforts should be inclusive, accessible, and responsive to the specific needs and priorities of each state, particularly small countries.
Evidence
Albania stated that it supports capacity building that is demand-driven, needs-based, sustainable, transparent, and nationally owned, and stressed that such efforts should be inclusive, accessible, and responsible to the specific needs and priorities of each state, particularly in cases of small countries .
Major Discussion Point
Principles for effective capacity building
Agreed with
Republic of KoreaMalawiCambodiaBotswanaGermanyAustraliaCote d'IvoireMexicoTongaKiribatiGhanaSerbiaArgentinaIrelandMalaysiaNew ZealandSouth AfricaVanuatu
on: Capacity building must be demand-driven, needs-based, nationally owned, and tailored to the specific circumstances of recipient states, avoiding a one-size-fits-all approach
Albania's experience with severe cyber attacks shows that cyber resilience depends not only on technology but also on strong institutions, skilled professionals, informed decision makers, and trusted partnerships at national, regional, and international levels.
Arg. 3
Explanation
Albania drew on its own experience with severe cyber attacks to argue that resilience is multidimensional. It requires not only technological investment but also strong institutions, skilled professionals, informed decision makers and citizens, and trusted partnerships across multiple levels.
Evidence
Albania stated that its experience with severe cyber attacks shows that cyber resilience depends not only on technology, but also on strong institutions, skilled professionals, informed decision makers and citizens, and trusted partnerships at national, regional, and international levels .
Major Discussion Point
Multidimensional nature of cyber resilience
Albania's National Cyber Security Authority delivered a broad programme of activities including awareness raising, education, and practical cybersecurity capacity building across society, reaching over 7,700 participants in the last year alone.
Arg. 4
Explanation
Albania described a comprehensive national capacity building programme delivered by its National Cyber Security Authority, covering professionals, the public and private sector, critical infrastructure, businesses, and SMEs. The programme also included dedicated activities for persons with disabilities, the Roma community, visually impaired individuals, elderly people, and other groups with limited access to technology.
Evidence
Albania stated that during the last year the National Cyber Security Authority delivered a broad programme of activities nationally and internationally to raise awareness, strengthen education and build practical cybersecurity capacity across society, with over 50 activities targeting professionals, the public and private sector, critical and important infrastructure, businesses and SMEs, and an additional 11 dedicated activities for persons with disabilities, the Roma community, visually impaired individuals, elderly people, and other groups with more limited access to technology, engaging directly over 7,700 participants .
Major Discussion Point
National capacity building initiatives and programmes
Albania strongly supports the global mechanism as the principal inclusive intergovernmental platform for advancing dialogue and cooperation on ICT security, and welcomes the dedicated focus on capacity building within the mechanism.
Arg. 5
Explanation
Albania expressed strong support for the global mechanism as the principal inclusive intergovernmental platform for advancing dialogue and cooperation on ICT security. Albania welcomed the dedicated focus on capacity building within the mechanism, believing it offers valuable opportunities to strengthen practical cooperation, facilitate exchange of experiences, and identify concrete avenues for assistance and partnership.
Evidence
Albania stated that it strongly supports the work of the global mechanism as the principal inclusive intergovernmental platform for advancing dialogue and cooperation on ICT security, and that it welcomes the dedicated focus on capacity building within the mechanism, believing it offers valuable opportunities to strengthen practical cooperation, facilitate exchange of experiences, and identify concrete avenues for assistance and partnership .
Major Discussion Point
Role of the global mechanism in capacity building
Albania supports efforts to improve coordination among existing initiatives, promote transparency regarding available assistance, and facilitate better matching between identified needs and available resources.
Arg. 6
Explanation
Albania expressed support for efforts aimed at improving coordination among existing capacity building initiatives, promoting transparency regarding available assistance, and facilitating better matching between identified needs and available resources. Such efforts can emphasise effectiveness, avoid duplication, and contribute to more sustainable capacity building outcomes.
Evidence
Albania stated that it supports efforts aimed at improving coordination among existing initiatives, promoting transparency regarding available assistance, and facilitating better matching between identified needs and available resources, noting that such efforts can emphasise effectiveness, avoid duplication, and contribute to more sustainable capacity building outcomes .
Major Discussion Point
Coordination and efficiency in capacity building
Albania expressed appreciation for participating in the Women in Cyber Fellowship, made possible through the support of the Netherlands, as a strong community of women whose expertise contributes meaningfully to UN cybersecurity discussions.
Arg. 7
Explanation
Albania concluded by expressing personal appreciation for the opportunity to participate in the session as part of the Women in Cyber Fellowship, made possible through the support of the Government of the Netherlands. Albania described the fellowship as a strong community of women whose expertise and engagement contributes meaningfully to United Nations discussions on cybersecurity.
Evidence
Albania stated that it would like to express appreciation for the opportunity to participate at the session as part of the Women in Cyber Fellowship, made possible through the support of the government of the Netherlands, and that it is proud to be part of this capacity building programme, a strong community of women whose expertise and engagement contributes meaningfully to the United Nations discussions on cybersecurity .
Major Discussion Point
Value of fellowship programmes for capacity building
Agreed with
MalawiBotswanaBrazilMexicoCanadaSouth AfricaTongaUruguayGhanaBahamasMauritiusCote d'IvoireSerbiaBosnia and Herzegovina
on: Gender inclusion and the Women in International Security and Cyberspace Fellowship are essential components of effective and inclusive capacity building
105
WPM
402
Words
4 min
Time
Capacity building is an essential precondition for implementing the framework for responsible state behaviour in ICTs, as digital transformation increases exposure to cyber threats while national capacities remain deeply unequal.
Arg. 1
Explanation
Cote d'Ivoire welcomed the dedicated discussion on capacity building, arguing that for many states it remains the essential precondition for implementing the framework for responsible state behaviour. While digital transformation opens immense prospects for development, it also increases exposure to cyber attacks, disruptions of essential services, digital fraud, and criminal exploitation of new technologies.
Evidence
Cote d’Ivoire stated that capacity building remains the essential precondition for implementing the framework for the responsible behaviour of states in the use of ICTs, and that digital transformation undoubtedly opens up immense prospects for development but also increases exposure to cyber attacks, disruptions of essential services, digital fraud, and the criminal exploitation of new technologies .
Major Discussion Point
Capacity building as a prerequisite for framework implementation
Agreed with
Republic of KoreaBotswanaRwandaMalawiCameroonGhanaAlbaniaKiribatiNew ZealandTongaMalaysiaGuatemalaSouth AfricaDemocratic Republic of the CongoAustraliaMarshall Islands
on: Capacity building is the foundational pillar upon which all other pillars of the ICT security framework depend
Collective security cannot rest on deeply unequal national capacities, and the digital environment requires resilience from states even with limited resources.
Arg. 2
Explanation
Cote d'Ivoire argued that in the face of cyber threats that know no borders, collective security cannot rest on national capacities that are deeply unequal. The digital environment requires resilience from all states, including those with limited resources.
Evidence
Cote d’Ivoire stated that in the face of these threats which know no borders, collective security cannot rest on national capacities which are deeply unequal, and that the digital environment requires resilience from states that have even limited resources .
Major Discussion Point
Collective security and interdependence in cyberspace
Capacity building must be voluntary, inclusive, sustainable, transparent, and based on the needs expressed by beneficiary states themselves, taking into account local realities and producing measurable results.
Arg. 3
Explanation
Cote d'Ivoire outlined the principles that should govern capacity building, emphasising that it must be voluntary, inclusive, sustainable, and transparent. It must be based on the needs expressed by beneficiary states themselves, take into account local realities, and produce measurable results.
Evidence
Cote d’Ivoire stated that capacity building must be voluntary, inclusive, sustainable, transparent, and based on the needs expressed by the beneficiary states themselves, and that it must take into account local realities and produce measurable results .
Major Discussion Point
Principles for effective capacity building
Agreed with
Republic of KoreaMalawiCambodiaBotswanaGermanyAustraliaMexicoTongaKiribatiGhanaAlbaniaSerbiaArgentinaIrelandMalaysiaNew ZealandSouth AfricaVanuatu
on: Capacity building must be demand-driven, needs-based, nationally owned, and tailored to the specific circumstances of recipient states, avoiding a one-size-fits-all approach
Cote d'Ivoire has strengthened its institutional architecture through the National Agency for Information Systems Security and is working on sectoral incident response mechanisms, staff training, and coordination between digital security and public administration officials.
Arg. 4
Explanation
Cote d'Ivoire described its national capacity building efforts, including strengthening its institutional architecture through the National Agency for Information Systems Security and CIT Cote d'Ivoire. The country is also working to develop sectoral incident response mechanisms, train staff, and ensure better coordination between those responsible for digital security and public administration officials.
Evidence
Cote d’Ivoire stated that at the national level it has strengthened its institutional architecture, in particular through the National Agency for Information Systems Security and the CIT Cote d’Ivoire, and that it is also working to develop sectoral incident response mechanisms, training staff, and ensuring better coordination between those responsible for digital security and public administration officials .
Major Discussion Point
National capacity building initiatives and programmes
Cote d'Ivoire recommends developing a UN tool to identify states' needs and connect them with partners, programmes, and financing; prioritising CRT, critical infrastructure protection, simulation exercises, and training of diplomats and technical staff; and strengthening the role of African regional bodies.
Arg. 5
Explanation
Cote d'Ivoire put forward three specific recommendations for improving international capacity building cooperation. These include developing a UN tool for needs identification and matchmaking, attaching particular importance to critical infrastructure protection, simulation exercises, and training of diplomats and technical staff, and strengthening the role of the African Union, regional economic commissions, and African training centres.
Evidence
Cote d’Ivoire recommended first developing under UN auspices a tool to allow states to identify their needs and connect them with partners, programmes, and available financing; second, attaching particular prerogative to CRT, the protection of critical infrastructure, simulation exercises, and the training of diplomats, technicians, judges, and other law enforcement services; and third, strengthening the role of the African Union, Regional Economic Commissions, and African Training Centres so that assistance is adapted to national and sub-regional contexts .
Major Discussion Point
Concrete recommendations for improving international capacity building
Agreed with
BotswanaAustraliaDemocratic Republic of the CongoGhanaGermanyGuyanaVanuatuNew ZealandKiribati
on: Regional cooperation and regional organisations play an essential role in effective capacity building and should be leveraged by the global mechanism
Cote d'Ivoire calls for more ambitious, inclusive international cooperation that includes women and youth and promotes transfer of knowledge and development of lasting local expertise.
Arg. 6
Explanation
Cote d'Ivoire concluded by calling for more ambitious and inclusive international cooperation in capacity building. This cooperation should include women and youth and promote the transfer of knowledge and the development of lasting local expertise, as strengthening the capacities of each state means strengthening the digital ecosystem for all.
Evidence
Cote d’Ivoire called for more ambitious, inclusive, international cooperation that includes women and youth and promotes transfer of knowledge and the development of lasting local expertise, noting that strengthening the capacities of each and every one means strengthening the digital ecosystem .
Major Discussion Point
Inclusive and gender-responsive capacity building
Agreed with
MalawiBotswanaBrazilMexicoCanadaSouth AfricaTongaUruguayAlbaniaGhanaBahamasMauritiusSerbiaBosnia and Herzegovina
on: Gender inclusion and the Women in International Security and Cyberspace Fellowship are essential components of effective and inclusive capacity building
152
WPM
631
Words
4 min
Time
There is a strong connection between confidence-building measures and capacity building, with joint exercises contributing greatly to both.
Arg. 1
Explanation
Ukraine recognised the strong connection between confidence-building measures and capacity building, arguing that joint exercises, both tabletop and capture-the-flag, contribute greatly to both pillars simultaneously. This reflects Ukraine's view that the two pillars are mutually reinforcing rather than separate endeavours.
Evidence
Ukraine stated that it recognises the strong connection that exists between confidence-building measures and capacity-building, and that joint exercises, both tabletop and capture-the-flag, contribute greatly to both .
Major Discussion Point
Relationship between confidence-building measures and capacity building
Ukraine has benefited from international capacity building support from multiple partner states and has launched its own Women in Cyber Security Programme.
Arg. 2
Explanation
Ukraine acknowledged the value of capacity building support received from Canada, Denmark, France, Germany, Estonia, and others, as well as programmes such as the Women in Cyber Fellowship and the UN-Singapore Cyber Fellowship. Ukraine also noted that it has started its own Women in Cyber Security Programme and is ready to cooperate with other states in this regard.
Evidence
Ukraine mentioned the Women in Cyber Fellowship, the UN-Singapore Cyber Fellowship, the work of UNIDIR, and support in human capacity-building received from Canada, Denmark, France, Germany, Estonia, and others . Ukraine also stated that it has started the Women in Cyber Security Programme and is ready to cooperate with other states in this regard .
Major Discussion Point
National capacity building initiatives and international cooperation
Bilateral cyber dialogues are a valuable tool for both capacity and confidence building, helping to exchange experiences and shape mutual expectations.
Arg. 3
Explanation
Ukraine argued that bilateral cyber dialogues serve a dual purpose, contributing to both capacity building and confidence building simultaneously. Such dialogues help states exchange experiences and shape expectations from each other, making them a particularly efficient form of international cooperation.
Evidence
Ukraine stated that it attaches great importance to bilateral cyber dialogues and sees them as a valuable tool for both capacity and confidence building, noting that such dialogues help to both exchange experiences and shape the expectations from each other .
Major Discussion Point
Bilateral cooperation as a capacity and confidence-building tool
Ukraine contributes unique frontline experience in cyber defence acquired while defending against persistent cyber aggression, which it shares with partners inside and outside the EU.
Arg. 4
Explanation
Ukraine highlighted that its path towards EU membership has deepened cooperation in cyber defence, protection of critical infrastructure, crisis response, and cyber diplomacy. Ukraine argued that it contributes unique frontline experience acquired while defending against persistent cyber aggression, which it shares with partners both within and outside the EU.
Evidence
Ukraine stated that on its path to joining the European Union it continues to deepen cooperation with the EU in cyber defence, protection of critical infrastructure, crisis response, cyber diplomacy, countering hybrid threats, and the development of new technologies, and that Ukraine contributes unique frontline experience acquired while defending against the persistent cyber-aggression by a certain P5 member .
Major Discussion Point
National experience and contribution to international cyber capacity building
The dedicated thematic groups should serve as a capacity building tool for government representatives, allowing them to benefit from the best and most relevant expertise to contribute to inclusive decision-making.
Arg. 5
Explanation
Ukraine viewed the DTGs not only as forums for discussing capacity building but as capacity building tools in themselves, allowing government representatives to benefit from expert knowledge. Ukraine also invited the Chairpersonship and Secretariat to consider reserving time for thematic workshops during the December session so that the willing majority could benefit from the broadest available expertise.
Evidence
Ukraine stated that it sees DTGs as a tool for capacity-building for government representatives, allowing them to benefit from the best and most relevant expertise that can contribute to the inclusivity of the decision-making process . Ukraine also invited the Chairpersonship and Secretariat to consider reserving time for thematic workshops in the course of the December session so the willing majority could benefit from the broadest available expertise .
Major Discussion Point
Role of DTGs as capacity building tools
Disagreed with
SwitzerlandJapanCambodiaCuba
on: Whether stakeholders (non-governmental actors) should have a meaningful role in the dedicated thematic groups
The Tallinn Mechanism demonstrates how practical international cooperation can produce tangible results in maintaining essential public services and strengthening digital infrastructure resilience under cyber aggression.
Arg. 6
Explanation
Ukraine highlighted the work of the Tallinn Mechanism as the leading platform for coordinating civilian cyber assistance to Ukraine, arguing that it has played a crucial role in maintaining essential public services and strengthening the resilience of Ukraine's digital infrastructure. Ukraine presented the Tallinn Mechanism as a valuable model for future international efforts to enhance cyber resilience.
Evidence
Ukraine stated that the Tallinn Mechanism has become the leading platform for coordinating civilian cyber assistance to Ukraine, playing a crucial role in maintaining essential public services and strengthening the resilience of Ukraine’s digital infrastructure under cyber aggression, and that it demonstrates how practical international cooperation can produce tangible results and offers a valuable model for future international efforts to enhance cyber resilience .
Major Discussion Point
Practical models for international cyber capacity building cooperation
Disagreed with
Islamic Republic of IranRussian FederationCubaChinaItaly
on: Whether unilateral coercive measures and technology access restrictions should be addressed within the global mechanism's capacity building agenda
126
WPM
666
Words
5 min
Time
Capacity building should not be viewed as assistance provided by some states to others but as a shared investment in international peace and security.
Arg. 1
Explanation
Malawi argued that capacity building must be reconceptualised as a collective endeavour rather than a charitable transfer from developed to developing states. Since cyber threats do not recognise borders, weaknesses in one part of the interconnected digital ecosystem can have consequences far beyond national frontiers, making capacity building a matter of shared interest.
Evidence
Malawi stated that capacity building should not be viewed as assistance provided by some states to others but rather as a shared investment in international peace and security, and that cyber threats do not recognise borders and a weakness in one part of the interconnected digital ecosystem can have consequences far beyond national frontiers .
Major Discussion Point
Reconceptualising capacity building as a shared investment
Agreed with
Republic of KoreaBotswanaRwandaCameroonGhanaAlbaniaKiribatiNew ZealandTongaMalaysiaGuatemalaSouth AfricaCote d'IvoireDemocratic Republic of the CongoAustraliaMarshall Islands
on: Capacity building is the foundational pillar upon which all other pillars of the ICT security framework depend
For developing countries, the challenge is often not lack of commitment but a lack of resources, expertise, and opportunities to translate political commitments into operational capabilities.
Arg. 2
Explanation
Malawi highlighted that developing countries face a structural gap between political will and operational capacity, arguing that the barrier is not commitment but resources and expertise. Addressing this gap requires sustained partnerships, predictable support, and respectful national ownership.
Evidence
Malawi stated that for developing countries the challenge is often not lack of commitment but a lack of resources, expertise, and opportunities to translate political commitments into operational capabilities, and that addressing this gap requires sustained partnerships, predictable support, and above all, respectful national ownership .
Major Discussion Point
Challenges faced by developing countries in cyber capacity building
Capacity building must be demand-driven, tailored to national priorities, and promote self-sufficiency by enabling states to develop enduring institutions and skilled professionals rather than creating long-term dependency.
Arg. 3
Explanation
Malawi argued that effective capacity building must respond to the priorities of recipient states and be designed to build lasting self-sufficiency. The goal should be to enable states to develop enduring institutions, skilled professionals, and resilient national partners, rather than creating long-term dependency on external support.
Evidence
Malawi stated that capacity building must remain demand-driven, tailored to national priorities, and responsive to the different levels of development and capacities of member states, and that equally important, it should promote self-sufficiency by enabling states to develop enduring institutions, skilled professionals, and resilient national partners rather than creating long-term dependency .
Major Discussion Point
Principles for effective and sustainable capacity building
Agreed with
CambodiaKiribatiTongaNaoeroBosnia and HerzegovinaBahamas
on: Capacity building must be sustained over time and promote self-sufficiency rather than dependency, as single training events do not build institutions
The dedicated thematic groups should become platforms where member states openly exchange experiences, identify common challenges, showcase successful practices, and develop practical recommendations supporting implementation across all five pillars.
Arg. 4
Explanation
Malawi argued that as the global mechanism begins operationalising, the dedicated thematic groups present an important opportunity to move beyond dialogue towards practical implementation. These groups should serve as platforms for knowledge exchange and the development of actionable recommendations.
Evidence
Malawi stated that the dedicated thematic groups present an important opportunity to move beyond dialogue towards practical implementation, and that they should become platforms where member states openly exchange experiences, identify common challenges, showcase successful practices, and develop practical recommendations that support implementation across all five pillars of the framework .
Major Discussion Point
Role and priorities of the dedicated thematic groups
on: The December DTG2 meeting must deliver concrete, practical, and measurable outputs rather than further discussion of principles
The voluntary fund under the global mechanism represents an important investment in ensuring equitable participation and strengthening the implementation of shared commitments, particularly for developing countries.
Arg. 5
Explanation
Malawi welcomed the establishment of the voluntary fund under the global mechanism, arguing that for many developing countries, meaningful participation depends not only on political will but also on the availability of practical support. The voluntary fund therefore represents a critical investment in equitable participation.
Evidence
Malawi stated that the Republic of Malawi welcomes the establishment of the voluntary fund under the global mechanism, and that for many developing countries, meaningful participation in this process depends not only on political will but also on the availability of practical support, making the voluntary fund an important investment in ensuring equitable participation and strengthening the implementation of shared commitments .
Major Discussion Point
Financing for equitable participation in the global mechanism
Agreed with
South AfricaGuyanaIndiaGhanaDemocratic Republic of the CongoIslamic Republic of Iran
on: The operationalisation of the UN Voluntary Fund for ICT security capacity building and the Global ICT Security Cooperation and Capacity Building Portal are priority mechanisms for the global mechanism
Inclusive cybersecurity is stronger cybersecurity, and when women participate fully as policymakers, technical experts, incident responders, diplomats, and leaders, institutions become more resilient and responses more effective.
Arg. 6
Explanation
Malawi argued that gender inclusion in cybersecurity is not merely a procedural matter but a substantive contributor to stronger security outcomes. Malawi commended UNIDIR's launch of the Compendium of Good Practices on Gender Mainstreaming in Cybersecurity as a practical tool for integrating gender perspectives into national cybersecurity policies and capacity building initiatives.
Evidence
Malawi stated that inclusive cybersecurity is stronger cybersecurity, and that when women participate fully as policymakers, technical experts, incident responders, diplomats, and leaders, institutions become more resilient and responses more effective . Malawi also commended UNIDIR for launching the Compendium of Good Practices on Gender Mainstreaming in Cybersecurity, which provides practical guidance for integrating gender perspectives into national cybersecurity policies, institutions, and capacity building initiatives .
Major Discussion Point
Gender and inclusion in capacity building
Agreed with
BotswanaBrazilMexicoCanadaSouth AfricaTongaUruguayAlbaniaGhanaBahamasMauritiusCote d'IvoireSerbiaBosnia and Herzegovina
on: Gender inclusion and the Women in International Security and Cyberspace Fellowship are essential components of effective and inclusive capacity building
Malawi's national capacity building efforts include child online protection training for teachers, university cyber drills, women in cyber initiatives, and specialised technical training through national CERTs.
Arg. 7
Explanation
Malawi described a range of concrete national capacity building activities, reflecting its conviction that sustainability is the key to success and that sustainable cybersecurity begins with sustainable human capacity. These efforts span education, professional development, and gender inclusion.
Evidence
Malawi stated that its national capacity building efforts include delivering child online protection training for teachers across all education divisions, conducting university cyber drills to build practical skills, advancing women in cyber initiatives to promote greater participation in the field, and providing specialised technical training through the Malawi National CERT as well as established sector CERTs .
Major Discussion Point
National capacity building initiatives and programmes
The measure of successful capacity building is not the number of workshops or certificates but whether countries are better prepared to prevent cyber incidents, respond effectively, and contribute meaningfully to international cooperation.
Arg. 8
Explanation
Malawi argued for a results-oriented conception of capacity building success, rejecting process metrics in favour of outcome-based assessment. The true measure is whether states are genuinely better equipped to prevent and respond to cyber incidents and to contribute to international cooperation.
Evidence
Malawi stated that the measure of successful capacity building is not the number of workshops conducted or certificates awarded, but whether countries are better prepared to prevent cyber incidents, respond effectively when they occur, and contribute meaningfully to international cooperation .
Major Discussion Point
Measuring the effectiveness of capacity building
Agreed with
CambodiaCameroonAustraliaNew Zealand
on: The measure of successful capacity building should be concrete outcomes rather than process metrics such as number of workshops or certificates
126
WPM
531
Words
4 min
Time
Despite strong political commitment to capacity building across two OEWGs, no concrete operational capacity building measures have yet been adopted at the UN, and the global mechanism must now translate political commitment into practical action.
Arg. 1
Explanation
Iran argued that while member states have consistently underscored the vital importance of capacity building throughout both OEWGs, this has not translated into concrete operational measures at the UN level. The global mechanism must now bridge this gap by developing and implementing concrete UN-led capacity building initiatives.
Evidence
Iran stated that despite strong political commitment, no concrete operational capacity building measures have yet been adopted at the UN, and that the global mechanism should now translate this political commitment into practical action by developing and implementing concrete UN-led capacity building initiatives .
Major Discussion Point
Translating political commitment into concrete capacity building action
The role of the United Nations in capacity building should extend beyond merely coordinating and matchmaking initiatives undertaken by other actors, and existing initiatives outside the UN should complement UN work, not the other way around.
Arg. 2
Explanation
Iran argued that the UN should play a central and leading role in capacity building on ICT security, not merely a coordinating function. Existing capacity building initiatives outside the UN should complement and support the work of the UN, rather than the UN serving as a secondary actor.
Evidence
Iran stated that given the central role of the United Nations in promoting the security of and in the use of ICTs, existing capacity building initiatives outside the United Nations should complement and support the work of the UN, not the other way around, and that the role of the United Nations should extend beyond merely coordinating and matchmaking capacity building initiatives undertaken by other actors .
Major Discussion Point
Role of the United Nations in leading capacity building
Proposals from previous OEWGs on capacity building should be consolidated into a single compilation to serve as the basis for focused, practical discussions within DTG2.
Arg. 3
Explanation
Iran proposed that the discussions on capacity building should not start from scratch, as member states put forward several concrete and action-oriented proposals during both OEWGs that are already reflected in the final and annual reports. Iran proposed that these be consolidated into a single compilation prepared under the Chair's authority to serve as the basis for DTG2 discussions.
Evidence
Iran stated that during both OEWGs member states put forward several concrete and action-oriented proposals on capacity building already reflected in the final and annual reports of the OEWG, and proposed that they be consolidated into a single compilation prepared under the Chair’s authority to serve as the basis for focused, practical and action discussions within the second DTG .
Major Discussion Point
Building on previous OEWG work in DTG2
The establishment of a voluntary UN Fund for capacity building should be accorded priority as one of the first priorities of DTG2, as agreed in paragraph 58 of the OEWG final report.
Arg. 4
Explanation
Iran argued that advancing the establishment of a voluntary UN Fund for capacity building should be one of the first priorities of DTG2, noting that member states had already agreed to continue discussions on this in the global mechanism. This reflects Iran's view that concrete financial mechanisms are essential to meaningful capacity building.
Evidence
Iran stated that as reflected in paragraph 58 of the OEWG final report, member states agreed to continue discussions within the global mechanism on the development and operationalisation of a voluntary UN Fund to support the capacity building of states in the security of and in the use of ICTs, and that advancing this initiative should therefore be one of the first priorities of DTG-2 .
Major Discussion Point
UN Voluntary Fund for capacity building
Agreed with
South AfricaMalawiGuyanaIndiaGhanaDemocratic Republic of the Congo
on: The operationalisation of the UN Voluntary Fund for ICT security capacity building and the Global ICT Security Cooperation and Capacity Building Portal are priority mechanisms for the global mechanism
Disagreed with
CubaBrazilRepublic of KoreaGermany
on: The scope of capacity building: whether it should include technology transfer and financial resources as binding commitments
The establishment of a UN Cyber Fellowship Programme should be considered as another priority item for discussion within DTG2, building on the recognised value of the UN-Singapore Cyber Fellowship.
Arg. 5
Explanation
Iran proposed that the establishment of a UN Cyber Fellowship Programme be considered as a priority item for DTG2, building on the recognition of the UN-Singapore Cyber Fellowship Programme in paragraph 53b of the OEWG Final Report. This proposal was also highlighted by the African Group and several other delegations.
Evidence
Iran stated that during the OEWG process, member states recognised the UN-Singapore Cyber Fellowship Programme as a valuable initiative, as reflected in paragraph 53b of the OEWG Final Report, and proposed that the establishment of a UN Cyber Fellowship Programme be considered as another priority item for discussion within the second DTG, as highlighted by the African Group and several other delegations .
Major Discussion Point
UN fellowship programmes for cybersecurity
Capacity building also requires the removal of obstacles and barriers that impede states' ability to access ICT resources, including unilateral coercive measures that adversely affect ICT capacities.
Arg. 6
Explanation
Iran argued that capacity building is not limited to positive measures addressing the needs of developing countries but also requires removing obstacles that impede states' ability to access ICT resources and develop national capacity. Restrictive measures, including unilateral coercive measures, can significantly hinder the development, security, and resilience of ICT ecosystems.
Evidence
Iran stated that capacity building also requires the removal of obstacles and barriers that impede states’ ability to access ICT resources and develop their national capacity, and that restrictive measures in the ICT environment can significantly hinder the development, security, and resilience of ICT ecosystems, undermining existing capacities and impeding efforts to strengthen them, and that the global mechanism should consider practical measures to address and prevent such restrictive practices, including unilateral coercive measures that adversely affect the ICT capacities of a state .
Major Discussion Point
Removing barriers to ICT access as part of capacity building
Disagreed with
Russian FederationCubaChinaItalyUkraine
on: Whether unilateral coercive measures and technology access restrictions should be addressed within the global mechanism's capacity building agenda
135
WPM
1179
Words
9 min
Time
The chair acknowledges the importance of inclusive participation and commits to accommodating different time zones in future virtual meetings with small island delegations.
Arg. 1
Explanation
Following Kiribati's statement about the difficulty of participating in meetings held at 5am local time, the Chair acknowledged the concern and made a personal commitment to accommodate Kiribati's time zone in future virtual meetings. While the Chair could not promise to change the general meeting times of the global mechanism, she offered a practical gesture of inclusion.
Evidence
The Chair stated that she cannot promise to change the time that the global mechanism meets, however she committed that the next time she meets with Kiribati virtually it will be at their convenient time, not their time .
Major Discussion Point
Inclusive participation and hybrid access in the global mechanism
125
WPM
552
Words
4 min
Time
Traditional forms of capacity building limited to good practices and exchange of information are insufficient to transform the digital divide into digital opportunities.
Arg. 1
Explanation
Cuba argued that the traditional approach to capacity building, focused primarily on sharing good practices and information exchange, has proven insufficient to address the structural digital divide facing developing countries. The vast digital divide and enormous economic difficulties of developing countries create a position of asymmetry that requires more substantive action.
Evidence
Cuba stated that it is worth expanding the traditional forms of capacity building limited to good practices and exchange of information, noting that this has not been sufficient to transform the digital divide into digital opportunities, and that the vast, gaping digital divide and the enormous economic difficulties faced by developing countries puts them in a position of asymmetry in terms of preventing, detecting, and tackling threats in the area of ICTs .
Major Discussion Point
Limitations of traditional capacity building approaches
The United Nations has a key role to play in capacity building, complemented by bilateral, regional, south-south, and triangular initiatives that should be within reach of all.
Arg. 2
Explanation
Cuba argued that the UN must play a central role in capacity building on ICT security, while bilateral, regional, south-south, and triangular initiatives should complement global efforts. Critically, these efforts must be accessible to all states, not just those with greater resources.
Evidence
Cuba stated that the United Nations has a key role to play in this regard, and that bilateral and regional initiatives, south and triangular initiatives should also complement the global efforts that are within reach of all .
Major Discussion Point
Role of the United Nations and complementary cooperation mechanisms
The selection of topics for the dedicated thematic groups should be done by consensus, and the groups should contribute to stemming the growing threat of ICTs in the context of international security.
Arg. 3
Explanation
Cuba argued that the selection of topics for the dedicated thematic groups must be done by consensus, reflecting the intergovernmental and inclusive character of the process. The groups should contribute to achieving a global commitment for the use of ICTs for exclusively peaceful ends and to addressing the militarisation of cyberspace.
Evidence
Cuba stated that the selection of topics for the dedicated thematic groups should be done by consensus, and that the dedicated thematic groups should contribute to stemming the growing threat of the use of ICTs in the context of international security, specifically by achieving a global commitment for the use of ICTs for exclusively peaceful ends, a prohibition on the use of ICTs as a pretext to launch wars or threats or the use of force, a prohibition on the militarisation of cyberspace, and the elimination of the vast technological gap and barriers placed on developing countries .
Major Discussion Point
Governance and mandate of the dedicated thematic groups
Disagreed with
SwitzerlandJapanUkraineCambodia
on: Whether stakeholders (non-governmental actors) should have a meaningful role in the dedicated thematic groups
DTG2 should contribute to achieving real commitments for developing countries, including financial resources and technology transfer, bearing in mind the specific needs of each country.
Arg. 4
Explanation
Cuba argued that DTG2 should go beyond discussion to deliver real commitments for developing countries, particularly in terms of financial resources and technology transfer. This vision is supported by the vast majority of developing countries but has not yet found a concrete response.
Evidence
Cuba stated that DTG2 of the global mechanism has greater emphasis on capacity building and could contribute to achieving real commitments, especially for developing countries, in order to provide developing countries who requested assistance and cooperation, including financial resources and technology transfer, bearing in mind the specific needs of each country, and that this idea is supported by the vast majority of developing countries .
Major Discussion Point
Concrete commitments for developing countries in capacity building
Disagreed with
Islamic Republic of IranBrazilRepublic of KoreaGermany
on: The scope of capacity building: whether it should include technology transfer and financial resources as binding commitments
All unilateral coercive measures that limit exchanges or progress in digital learning environments must be ended, as inclusive, universal, and non-discriminatory access to ICT knowledge is necessary to detect and respond to malicious use of ICTs.
Arg. 5
Explanation
Cuba called for an end to all unilateral coercive measures that limit digital exchanges and learning, arguing that such destructive and discriminatory practices are incompatible with genuine cooperation and capacity building. Inclusive, universal, and non-discriminatory access to ICT information and knowledge is a prerequisite for effective detection and response to malicious ICT use.
Evidence
Cuba called for an end to all unilateral coercive measures that limit exchanges or progress and digital learning environments, stating that cooperation and capacity building cannot be discussed in real terms when destructive and discriminatory practices persist, and that in order to detect and respond to the malicious use of ICTs, inclusive, universal and non-discriminatory access to information and knowledge related to ICTs is necessary .
Major Discussion Point
Removing barriers to ICT access as part of capacity building
Disagreed with
Islamic Republic of IranRussian FederationChinaItalyUkraine
on: Whether unilateral coercive measures and technology access restrictions should be addressed within the global mechanism's capacity building agenda
Capacity building activities implemented by the global mechanism must be directed at making possible inclusive, universal, and non-discriminatory access to ICT knowledge and at closing the digital divide.
Arg. 6
Explanation
Cuba argued that the capacity building activities of the global mechanism must be fundamentally oriented towards enabling access and closing the digital divide, rather than focusing narrowly on technical training. This reflects Cuba's view that structural inequalities in access to ICT knowledge are the root cause of capacity gaps.
Evidence
Cuba stated that it is necessary for measures or activities aimed at capacity building implemented by the global mechanism to be directed at making possible inclusive, universal and non-discriminatory access to information and knowledge related to ICTs and to closing the digital divide .
Major Discussion Point
Capacity building as a tool for closing the digital divide
119
WPM
358
Words
3 min
Time
Capacity building is a crucial pillar of the UN Framework for Responsible State Behaviour in ICTs, and without adequate capacity, commitments relating to norms, confidence-building measures, and international law cannot be effectively implemented.
Arg. 1
Explanation
Malaysia argued that capacity building is essential to ensuring that no state is left behind, given the different levels of cyber maturity among states. Without sufficient capacity, states cannot translate their political commitments into operational realities across the other pillars of the framework.
Evidence
Malaysia stated that capacity building is a crucial pillar of the UN Framework for Responsible State Behaviour in the use of ICTs, and that without adequate capacity, commitments relating to norms, confidence-building measures and international law cannot be effectively implemented, and that given the different levels of cyber-maturity among states, capacity building remains essential to ensure that no state is left behind .
Major Discussion Point
Capacity building as a foundational pillar of the ICT security framework
Agreed with
Republic of KoreaBotswanaRwandaMalawiCameroonGhanaAlbaniaKiribatiNew ZealandTongaGuatemalaSouth AfricaCote d'IvoireDemocratic Republic of the CongoAustraliaMarshall Islands
on: Capacity building is the foundational pillar upon which all other pillars of the ICT security framework depend
Capacity building should respond to concrete needs identified by states, moving beyond awareness raising to support the development of capabilities relevant to national circumstances and priorities, with a one-size-fits-all approach unlikely to deliver sustainable outcomes.
Arg. 2
Explanation
Malaysia emphasised that effective capacity building must be grounded in the specific needs and circumstances of each recipient state, rather than following a uniform template. Malaysia's own experience with the Malaysia-UNIDIR Cyber Capability Building Programme demonstrated that the best results come from programmes designed in close consultation with the beneficiary state.
Evidence
Malaysia stated that capacity building should respond to concrete needs identified by states, moving beyond awareness raising and supporting the development of capabilities relevant to national circumstances and priorities, and that a one-size-fits-all approach may not deliver sustainable outcomes, with Malaysia’s experience with the Malaysia-UNIDIR Cyber Capability Building Programme demonstrating that the best results come from programmes designed in close consultation with the beneficiary state .
Major Discussion Point
Principles for effective capacity building
Agreed with
Republic of KoreaMalawiCambodiaBotswanaGermanyAustraliaCote d'IvoireMexicoTongaKiribatiGhanaAlbaniaSerbiaArgentinaIrelandNew ZealandSouth AfricaVanuatu
on: Capacity building must be demand-driven, needs-based, nationally owned, and tailored to the specific circumstances of recipient states, avoiding a one-size-fits-all approach
Greater focus should be placed on the protection of critical information infrastructure, which forms the backbone of economies and societies, given the cross-border nature of cyber threats.
Arg. 3
Explanation
Malaysia highlighted the protection of critical information infrastructure as a priority area for capacity building under the global mechanism. Given that cyber threats cross borders, the global mechanism has an important role in supporting states to develop the necessary capabilities to address these shared challenges.
Evidence
Malaysia stated that it encourages greater focus on the protection of critical information infrastructure, which forms the backbone of economies and societies, and that given the cross-border nature of cyber threats, the global mechanism has an important role in supporting states to develop the necessary capabilities to address these shared challenges .
Major Discussion Point
Scope and content of capacity building
Closer alignment between the two dedicated thematic groups is essential, so that if states continue to highlight difficulties in implementing norms on critical infrastructure protection, capacity building activities should respond directly to that need.
Arg. 4
Explanation
Malaysia argued for a strong linkage between DTG1 and DTG2, ensuring that implementation challenges identified in substantive discussions directly inform the capacity building agenda. This alignment would ensure that the mechanism's work remains evidence-based and responsive to actual challenges faced by states.
Evidence
Malaysia stated that it sees real value in ensuring closer alignment between the DTGs, and that if states continue to highlight difficulties in implementing the norm on critical infrastructure protection, capacity building activities should respond directly to that need, with such alignment ensuring that the mechanism’s work remains evidence-based and responsive to actual challenges .
Major Discussion Point
Coordination between dedicated thematic groups
Disagreed with
MexicoFranceIreland
on: The relationship and hierarchy between DTG1 and DTG2
Capacity building is the bridge between agreed commitments and effective implementation, and by building this bridge according to agreed principles, all states can be strengthened in their ability to benefit from and contribute to the global mechanism.
Arg. 5
Explanation
Malaysia concluded by framing capacity building as the essential link between political agreement and practical action. By adhering to agreed principles in designing and delivering capacity building, the global mechanism can ensure that all states are genuinely empowered to participate and contribute.
Evidence
Malaysia stated that capacity building is the basis and the bridge between agreed commitments and effective implementation, and that by building this bridge according to the principles agreed upon, the ability of all states to benefit from and contribute to the global mechanism can be strengthened .
Major Discussion Point
Capacity building as a bridge between commitment and implementation
Malaysia has benefited from regional and international partnerships, including through ASEAN and UNIDIR, in strengthening its cyber capabilities, and draws on these experiences to guide future capacity building efforts under the global mechanism.
Arg. 6
Explanation
Malaysia described its own experience as a beneficiary of capacity building support through regional and international partnerships as informing its perspective on what works. This practical experience grounds Malaysia's recommendations for how the global mechanism should approach capacity building.
Evidence
Malaysia stated that it has benefited from regional and international partnerships, including through ASEAN and partners such as UNIDIR in strengthening its cyber capabilities, and that drawing from these experiences, Malaysia would like to highlight three considerations to guide future capacity building efforts under the global mechanism .
Major Discussion Point
National experience with capacity building
Session Knowledge Graph
Speakers · Topics · Arguments · Relationships
Interactive graph · embed active
Agreed Points
Capacity building is the foundational pillar upon which all other pillars of the ICT security framework depend
There was near-universal agreement across all delegations that capacity building is not a secondary or optional element but the foundational pillar upon which the entire framework for responsible state behaviour in ICTs rests. Rwanda stated that without the necessary institutions, legal frameworks, technical expertise and skilled professionals, commitments cannot be implemented, norms cannot be operationalised and resilience cannot be strengthened . Kiribati endorsed the view that capacity building is the enabler underpinning everything else, and that a framework that only some states can implement is not yet a framework for all . Tonga argued that a state that cannot implement the framework is not protected by it . Australia drew on the lesson from the OEWG and GGEs that norms, law and confidence-building measures do not implement themselves but that people, institutions, and capability do . Cameroon stated that a framework without capacity remains an aspiration, norms without the ability to implement them remain commitments, and cooperation without shared capabilities cannot deliver lasting results .
Capacity building is the foundation underpinning all five pillars of the Framework for Responsible State Behavior in ICTs.
Cyber capacity building is the fundamental pillar upon which the framework for responsible state behaviour rests, with an undeniable correlation between capacity gaps and digital vulnerabilities.
Capacity building is the foundation upon which every other pillar of the framework depends, as without institutions, legal frameworks, and skilled professionals, commitments cannot be implemented.
Capacity building should not be viewed as assistance provided by some states to others but as a shared investment in international peace and security.
Capacity building is the foundation upon which all other pillars of the framework depend, and without adequate capacities, states cannot implement norms, apply international law, or participate fully in confidence-building measures.
Capacity building is a cornerstone of the framework for responsible state behaviour in ICTs, enabling states to prevent, detect, respond to, and recover from cyber threats while participating meaningfully in international cooperation.
Capacity building is a cornerstone of the framework for responsible state behaviour in cyberspace and an indispensable enabler for international peace, security, and sustainable development.
A framework that only some states can implement is not yet a framework for all, and capacity building is the enabler underpinning everything else done in the global mechanism.
Capacity building is the enabler that underpins all aspects of the global mechanism's work, and the Pacific Islands Forum working paper on regional capacity building priorities should be recommended to the mechanism.
A state that cannot implement the framework is not protected by it, so the cross-cutting thematic group should apply a capacity lens across all pillars.
Capacity building is a crucial pillar of the UN Framework for Responsible State Behaviour in ICTs, and without adequate capacity, commitments relating to norms, confidence-building measures, and international law cannot be effectively implemented.
Capacity building constitutes one of the fundamental pillars of the framework for responsible state behaviour in ICTs and is an indispensable condition for all states to participate safely, effectively, and meaningfully in the digital environment.
Capacity building is a cross-cutting issue on all pillars of the global mechanism, and is an important and essential part of the mechanism given that member states remain at varying levels of implementation.
Capacity building is an essential precondition for implementing the framework for responsible state behaviour in ICTs, as digital transformation increases exposure to cyber threats while national capacities remain deeply unequal.
Capacity building is the foundation for the effective implementation of the entire UN framework on responsible state behaviour in cyberspace.
A framework is only as strong as the ability to implement it, and cyber capacity building is therefore indispensable to international peace and security.
Capacity building is how the promise of digital connection is made safe for nations like the Marshall Islands, and the global mechanism must reach even the most distant shores so that no nation is left beyond its horizon.
Policy Context (Knowledge Base)
This framing is directly echoed by multiple delegations in the Global Mechanism sessions. Liberia stated that ‘capacity building is not an issue of choice. It is the foundation upon which all other pillars rest. Without it, commitments remain aspirational,’ and Rwanda reinforced that ‘capacity building is not just a supporting element, it is the foundation’ [S173]. The Pacific Islands Forum similarly characterised capacity building as ‘a foundational cross-cutting pillar enabling implementation across all framework areas’ [S174]. India further described capacity building as ‘the common thread that connects focus areas of the OEWG’ [S165].
Republic of KoreaBotswanaRwandaMalawiCameroonGhanaAlbaniaKiribatiNew ZealandTongaMalaysiaGuatemalaSouth AfricaCote d'IvoireDemocratic Republic of the CongoAustraliaMarshall Islands
Capacity building must be demand-driven, needs-based, nationally owned, and tailored to the specific circumstances of recipient states, avoiding a one-size-fits-all approach
There was overwhelming consensus that capacity building must be grounded in the specific needs and priorities of recipient states, with national ownership at its core. Korea stated that capacity building should not follow a one-size-fits-all approach but should be demand-driven and tailored to the specific needs and priorities of recipient states . Tonga stated that its priorities are set in Nuku’alofa, shaped by its own frameworks, and that the most effective partnerships have been those that supported its direction rather than substituting their own . Kiribati stated that what its partners gave was not capability delivered ready-made but the chance to build its own capacity and the patience to let it do so . Cambodia stated that programmes should be designed jointly with recipient states and aligned with their national strategies, institutional context, and implementation timelines . Germany stated that capacity building initiatives are most successful when implemented through a co-creation approach whereby donor and recipient states collaborate closely .
Capacity building must be demand-driven and tailored to the specific needs of recipient states, avoiding a one-size-fits-all approach.
Capacity building must be demand-driven, tailored to national priorities, and promote self-sufficiency by enabling states to develop enduring institutions and skilled professionals rather than creating long-term dependency.
Capacity building must be demand-driven, tailored to national circumstances, and grounded in national ownership, with programmes designed jointly with recipient states and aligned with their national strategies.
DTG2 must prioritise concrete, needs-based support over a one-size-fits-all mandate, focusing on institutional readiness, legislative frameworks, and human capital development.
Capacity building initiatives are most successful when implemented through a co-creation approach, whereby donor and recipient states collaborate closely to jointly design, develop, and implement programmes based on UN principles for cyber capacity building.
DTG2 should become a platform where states can openly discuss implementation challenges, share lessons learned, and collectively understand where the most urgent gaps remain.
Capacity building must be voluntary, inclusive, sustainable, transparent, and based on the needs expressed by beneficiary states themselves, taking into account local realities and producing measurable results.
Capacity building should be responsive to the needs, priorities, and context identified by states themselves, incorporating a gender perspective and promoting sustainability and national ownership.
Effective capacity building must be needs-based and country-driven, with the most effective partnerships being those that support a country's own direction rather than substituting their own priorities.
Capacity building works when it is country-owned, with partners supporting priorities that the country itself identified rather than priorities identified for it.
Capacity building must be needs-driven, nationally owned, and tailored to each country's context, priorities, and level of cyber maturity, with no one-size-fits-all approach.
Albania supports capacity building that is demand-driven, needs-based, sustainable, transparent, and nationally owned, and that is inclusive, accessible, and responsive to the specific needs and priorities of each state.
Serbia supports capacity building that is needs-based, demand-driven, sustainable, and coordinated, with the United Nations uniquely placed to facilitate coordination and connect needs with available resources.
Capacity building must address the needs identified by the beneficiary country itself, taking into account specific geographical circumstances and avoiding standardised or one-size-fits-all models.
Capacity building must be based on the needs identified by individual states and be country-driven, with limited resources used in the most effective way possible, avoiding duplication.
Capacity building should respond to concrete needs identified by states, moving beyond awareness raising to support the development of capabilities relevant to national circumstances and priorities, with a one-size-fits-all approach unlikely to deliver sustainable outcomes.
The global mechanism and DTG2 should deliver a capacity building approach that is coherent, contextualised, calibrated, and constructive, ultimately measured by whether it makes a practical difference.
South Africa supports capacity building efforts that are needs-based and practical, guided by the capacity building principles in paragraph 56 of the 2021 OEWG final report.
Capacity building in the Pacific must be Pacific-led, co-designed by those it serves, contextualised, coordinated, sustainable, and inclusive, as articulated in the Joint Pacific Islands Forum paper submitted to the OEWG.
Policy Context (Knowledge Base)
This principle is reflected in deliberations at the OEWG, where it was acknowledged that ‘capacity-building solutions need to be tailored to address the specific challenges and vulnerabilities faced by individual states, including their technological, economic, and geopolitical contexts’ [S188]. Localised, context-driven approaches were also strongly advocated in informal stakeholder consultations, which called for capacity building ‘beyond technical training to include policy literacy, leadership development, and meaningful participation in governance processes’ [S183].
Republic of KoreaMalawiCambodiaBotswanaGermanyAustraliaCote d'IvoireMexicoTongaKiribatiGhanaAlbaniaSerbiaArgentinaIrelandMalaysiaNew ZealandSouth AfricaVanuatu
Capacity building must be sustained over time and promote self-sufficiency rather than dependency, as single training events do not build institutions
Multiple delegations converged on the principle that one-off training events are insufficient and that genuine capacity building requires sustained, long-term investment. Kiribati stated plainly that a single training builds a memory but does not build an institution . Tonga provided a concrete national example, noting that the response to a cyber attack on its health system succeeded because the relationships and capabilities behind it had been invested in over years and not weeks . Nauru warned that support delivered in fragments leaves fragments behind, and called for capacity building that is cumulative with each engagement building on the last . Cambodia stated that one-off training alone is insufficient and that true resilience is built when local trainers are trained and robust institutional memory is established . Malawi argued that capacity building should promote self-sufficiency by enabling states to develop enduring institutions, skilled professionals, and resilient national partners rather than creating long-term dependency .
Capacity building must be demand-driven, tailored to national priorities, and promote self-sufficiency by enabling states to develop enduring institutions and skilled professionals rather than creating long-term dependency.
Capacity building must be sustainable and results-focused, building local trainers, institutional memory, and a national pool of cybersecurity professionals rather than relying on one-off training.
Capacity building must be sustained, as a single training builds a memory but does not build an institution.
Capacity building must be sustained over years, not weeks, as demonstrated by Tonga's response to a cyber attack on its health system succeeding because relationships and capabilities had been invested in over time.
Capacity building for small states must be cumulative, building on each engagement and developing local people rather than substituting for them.
Capacity building must be sustainable rather than ad hoc, requiring long-term strategies that build skills and institutional memory, and must be fully inclusive, engaging governments, the private sector, academia, and civil society with a gendered perspective.
Sustainable cybersecurity begins with people, requiring long-term investment in education, awareness, leadership, and workforce development.
Policy Context (Knowledge Base)
This position has historical grounding in earlier cyber governance discussions, where it was noted that ‘capacity building goes beyond training sessions, and includes a comprehensive set of learning, coaching, research, and policy’ development activities [S181]. The multidimensional nature of capacity building – encompassing governance structures and mindset change, not merely technical skills – has been consistently emphasised across forums [S182].
MalawiCambodiaKiribatiTongaNaoeroBosnia and HerzegovinaBahamas
Gender inclusion and the Women in International Security and Cyberspace Fellowship are essential components of effective and inclusive capacity building
There was broad consensus across geographically diverse delegations on the importance of gender inclusion in capacity building and the particular value of the Women in International Security and Cyberspace Fellowship. Malawi stated that inclusive cybersecurity is stronger cybersecurity, and that when women participate fully as policymakers, technical experts, incident responders, diplomats, and leaders, institutions become more resilient and responses more effective . Botswana reinforced that all capacity-building efforts must systematically adopt a gender-sensitive perspective and that true cyber resilience cannot be achieved while a gender-digital divide persists . Brazil stated that ensuring women and persons belonging to marginalised populations are duly qualified and effectively included in the ICT security workforce is essential and should be treated by DTG2 as a substantive component of capacity building rather than an afterthought . Multiple delegations including Tonga , Albania , Ghana , Bahamas , and Uruguay specifically acknowledged the Women in Cyber Fellowship as a concrete example of effective capacity building in action.
Inclusive cybersecurity is stronger cybersecurity, and when women participate fully as policymakers, technical experts, incident responders, diplomats, and leaders, institutions become more resilient and responses more effective.
All capacity building efforts must systematically adopt a gender-sensitive perspective, as true cyber resilience cannot be achieved while a gender-digital divide persists.
Ensuring women and marginalised populations are included in the ICT security workforce must be treated as a substantive component of capacity building, not an afterthought.
Capacity building should be responsive to the needs, priorities, and context identified by states themselves, incorporating a gender perspective and promoting sustainability and national ownership.
Canada supports the Compendium of Good Practices on Gender Equality and Cybersecurity, demonstrating how gender-responsive approaches strengthen cyber resilience.
The Women in International Security and Cyberspace Fellowship and sustainable, practical funding are essential components of capacity building, particularly for developing countries.
Tonga expresses gratitude to UNIDIR and donor partners for the Women in International Security and Cyberspace Fellowship, which enabled its small delegation to participate in the substantive plenary session.
Regional and international initiatives such as those by UNIDIR and the OAS, especially the Women in Cyber programme, have proven effective tools for strengthening national capacity and should be continued and expanded.
Albania expressed appreciation for participating in the Women in Cyber Fellowship, made possible through the support of the Netherlands, as a strong community of women whose expertise contributes meaningfully to UN cybersecurity discussions.
Gender must be mainstreamed across all capacity building initiatives, with increased opportunities for women through training, mentorship, fellowship, and leadership programmes being essential to a more inclusive and resilient cybersecurity ecosystem.
The Women in International Security and Cyberspace Fellowship demonstrates the value of sustained investment in people, creating lasting national and international impact.
Capacity building should be guided by the principles of inclusivity, accessibility, and equality, ensuring that no state is left behind, and should mainstream gender perspectives into programmes and national ICT policies.
Cote d'Ivoire calls for more ambitious, inclusive international cooperation that includes women and youth and promotes transfer of knowledge and development of lasting local expertise.
Serbia underlines the importance of the full, equal, and meaningful participation of women in all processes related to ICT security.
Capacity building must be sustainable rather than ad hoc, requiring long-term strategies that build skills and institutional memory, and must be fully inclusive, engaging governments, the private sector, academia, and civil society with a gendered perspective.
Policy Context (Knowledge Base)
The importance of gender-inclusive cybersecurity policy has been recognised at the IGF, where civil society and the United Nations were identified as key actors in ensuring gender-inclusive policies [S191]. Practical measures to attract and retain women in cybersecurity, including inclusive workplace structures and targeted programmes, have been discussed in authoritative forums [S192]. The broader WSIS review process also surfaced gender-based digital violence as an urgent concern requiring structural responses [S184].
MalawiBotswanaBrazilMexicoCanadaSouth AfricaTongaUruguayAlbaniaGhanaBahamasMauritiusCote d'IvoireSerbiaBosnia and Herzegovina
Duplication of existing capacity building efforts must be avoided through enhanced coordination, complementarity, and efficient use of available resources
Numerous delegations stressed the importance of avoiding duplication in the fragmented global capacity building landscape. Korea explicitly stated that unnecessary duplication of existing capacity building efforts should be avoided and that coordination, complementarity, and efficient use of available resources should be sought . Australia described the challenge as not a lack of goodwill, expertise or programmes, but how to bring together a mature but fragmented ecosystem and turn it into something greater than the sum of its parts . Israel argued that the global mechanism must serve as an effective coordinator, focusing on mapping national needs, sharing best practices, and matching requirements with available resources rather than reinventing the wheel . Germany emphasised the importance of developing global portals in close coordination with existing initiatives and in alignment with existing regional portals to avoid duplication, enhance efficiency, and ensure complementarity . Brazil noted that a clear, updated picture of what exists helps optimise synergies, avoid duplications, and promote systematic matchmaking .
Duplication of existing capacity building efforts should be avoided through enhanced coordination and complementarity.
Global portals should be developed in close coordination with existing initiatives and regional portals to avoid duplication, enhance efficiency, and ensure complementarity, with regional organisations playing an important role in cyber capacity building.
The challenge is not a lack of goodwill or programmes but how to bring together a fragmented ecosystem of actors and turn it into something greater than the sum of its parts.
DTG2 should build upon the experience accumulated in the previous OEWG process, including the 2024 Global Roundtable and the Secretariat's mapping exercise.
The global mechanism should serve as an effective coordinator, mapping needs, sharing best practices, and matching requirements with available resources rather than duplicating existing frameworks.
Capacity building efforts should avoid duplication and ensure better alignment with existing initiatives.
Capacity building must be based on the needs identified by individual states and be country-driven, with limited resources used in the most effective way possible, avoiding duplication.
The global mechanism and DTG2 should deliver a capacity building approach that is coherent, contextualised, calibrated, and constructive, ultimately measured by whether it makes a practical difference.
Cooperation across different programmes should be integrated to maximise impact, make the most of synergies, and avoid duplication in capacity building efforts.
DTG2 should secure the participation and proposals of a wide range of stakeholders, including the private sector, to realise efficient and effective capacity building.
International coordination mechanisms should be developed through a co-creation model that places national priorities at the centre, leverages regional coordination for needs identification, and uses international mechanisms to facilitate visibility, coordination, and partnerships.
Policy Context (Knowledge Base)
The need to avoid duplication and redundancy was explicitly raised in the first meeting of the organisational session of the Global Mechanism, where it was stated as essential ‘to clearly delineate the mandates and competencies of each working forum in order to avoid duplication and redundancy, strengthen the coherence of the process, and optimize the use of time and resources’ [S190].
Republic of KoreaGermanyAustraliaBrazilIsraelMauritiusIrelandNew ZealandUruguayJapanSingapore
The operationalisation of the UN Voluntary Fund for ICT security capacity building and the Global ICT Security Cooperation and Capacity Building Portal are priority mechanisms for the global mechanism
Several delegations expressed strong support for two specific mechanisms: the UN Voluntary Fund for capacity building and the Global ICT Security Cooperation and Capacity Building Portal. South Africa stated that it looks forward to further discussions on the development and operationalisation of the UN Voluntary Fund for capacity building, as well as the establishment of the dedicated Global ICT Security Cooperation and Capacity Building Portal . Malawi welcomed the establishment of the voluntary fund, noting that for many developing countries, meaningful participation depends not only on political will but also on the availability of practical support . India made the landmark announcement that it will provide the entire funding towards the operationalisation of the portal as a United Nations portal . Iran argued that advancing the voluntary UN Fund should be one of the first priorities of DTG2, as reflected in paragraph 58 of the OEWG final report . The DRC supported the swift operationalisation of the portal, noting it would align countries’ needs with offers of assistance and promote a more equitable distribution of available resources .
South Africa looks forward to further discussions on the development and operationalisation of the UN Voluntary Fund for capacity building and the establishment of the dedicated Global ICT Security Cooperation and Capacity Building Portal.
The voluntary fund under the global mechanism represents an important investment in ensuring equitable participation and strengthening the implementation of shared commitments, particularly for developing countries.
Guyana supports the operationalisation of the Global ICT Security Cooperation and Capacity Building Portal and the establishment of the UN Voluntary Fund for ICT Security Capacity Building.
India will provide the entire funding for the operationalisation of the Global ICT Security Cooperation and Capacity Building Portal as a United Nations portal, moving from design to reality.
Capacity building is a cornerstone of the framework for responsible state behaviour in ICTs, enabling states to prevent, detect, respond to, and recover from cyber threats while participating meaningfully in international cooperation.
The DRC supports the swift operationalisation of the global ICT security cooperation and capacity building portal to align needs with offers of assistance.
The establishment of a voluntary UN Fund for capacity building should be accorded priority as one of the first priorities of DTG2, as agreed in paragraph 58 of the OEWG final report.
Policy Context (Knowledge Base)
Support for the Global ICT Security Cooperation and Capacity Building Portal has been expressed across multiple delegations and forums. Thailand gave ‘firm backing to the development of this portal, envisaging it as a comprehensive platform guided by the interests of states’ [S167]. A UN Cyber Dialogue report also noted ‘support for the proposed global ICT Security Cooperation and Capacity Building portal with diverse funding sources’ [S166].
South AfricaMalawiGuyanaIndiaGhanaDemocratic Republic of the CongoIslamic Republic of Iran
Regional cooperation and regional organisations play an essential role in effective capacity building and should be leveraged by the global mechanism
There was strong consensus that regional organisations and regional cooperation mechanisms are essential components of effective capacity building and should be actively leveraged by the global mechanism. Botswana firmly maintained that the global mechanism must work hand-in-hand with regional and sub-regional bodies, noting that these organisations understand the unique political and physical challenges of their member states very well . Australia argued that the most successful capacity building is often regional, built on shared experiences, shared challenges, and shared trust, and that DTG2 should actively amplify regional initiatives . Cote d’Ivoire recommended strengthening the role of the African Union, Regional Economic Commissions, and African Training Centres so that assistance is adapted to national and sub-regional contexts . The DRC stated that regional organisations such as the AU and regional economic commissions play an essential role in sharing good practices, developing joint training programmes, and sharing technical resources . Ghana welcomed the continued emphasis on South-South, triangular, and regional cooperation as valuable complements to traditional North-South partnerships .
The global mechanism must work hand-in-hand with regional and sub-regional bodies to roll out capacity building initiatives, maximising resources efficiently.
DTG2 should actively amplify regional capacity building initiatives, as the most successful capacity building is often regional, built on shared experiences, challenges, and trust.
Cote d'Ivoire recommends developing a UN tool to identify states' needs and connect them with partners, programmes, and financing; prioritising CRT, critical infrastructure protection, simulation exercises, and training of diplomats and technical staff; and strengthening the role of African regional bodies.
Capacity building must promote regional and South-South cooperation, with regional organisations playing an essential role.
South-South, triangular, and regional cooperation complements North-South partnerships by providing peer learning, knowledge exchange, and the sharing of practical experience, with regional organisations remaining important partners.
Global portals should be developed in close coordination with existing initiatives and regional portals to avoid duplication, enhance efficiency, and ensure complementarity, with regional organisations playing an important role in cyber capacity building.
There is a need for multilateral collaboration, including public-private partnerships, regional and sub-regional cooperation, and cooperation between states and relevant stakeholders.
Capacity building in the Pacific must be Pacific-led, co-designed by those it serves, contextualised, coordinated, sustainable, and inclusive, as articulated in the Joint Pacific Islands Forum paper submitted to the OEWG.
New Zealand's capacity building efforts are focused in the Pacific region, including building CERT capabilities, developing national cybersecurity strategies, and running cybersecurity public awareness campaigns.
Kiribati's national cybersecurity strategy was developed through broad multi-stakeholder consultation with ITU support, and its maturity assessment with the Oceania Cyber Security Centre shaped its priorities.
Policy Context (Knowledge Base)
Regional capacity building experiences have been shared within OEWG processes, with Slovenia, for example, detailing its experiences in regional cyber capacity building [S188]. The African Commission also encouraged DTG1 to prioritise regional perspectives in addressing the evolving ICT threat landscape [S172].
BotswanaAustraliaCote d'IvoireDemocratic Republic of the CongoGhanaGermanyGuyanaVanuatuNew ZealandKiribati
The December DTG2 meeting must deliver concrete, practical, and measurable outputs rather than further discussion of principles
There was strong consensus, particularly among small island developing states and developing countries, that the December DTG2 meeting must move beyond discussion of principles to deliver concrete, actionable outputs. Kiribati asked that the December meeting focus on concrete, measurable outputs, including mapping needs against what already exists, developing tools states can actually use, and identifying sustainable financing . Vanuatu stated that it hopes the DTGs deliver three outputs: an honest global mapping of needs against provision exposing mismatches, a capacity-building portal shaped around how officials in recipient states actually work, and credible progress on financing that does not evaporate with the next budget cycle . Tonga viewed the December meetings as the first true test of whether the mechanism can convert deliberation into delivery . Nauru called on DTG2 to move beyond principle to programme . Cameroon argued that DTG2 should complement plenary discussions with more interactive and implementation-oriented formats, including expert-led technical workshops, country case studies, and peer-to-peer exchanges .
The December DTG meeting should focus on concrete, measurable outputs including mapping needs against what already exists, developing tools states can actually use, and identifying sustainable financing.
DTG2 should move from principles to concrete programmes, including a clear mapping of needs and a user-friendly capacity building portal.
The December DTG meeting should deliver three concrete outputs: an honest global mapping of needs against provision, a user-friendly capacity building portal, and credible progress on sustainable financing.
The December DTG meeting is the first true test of whether the global mechanism can convert deliberation into delivery, and hybrid participation in DTGs is a condition of equity, not merely a convenience.
The dedicated thematic groups should become platforms where member states openly exchange experiences, identify common challenges, showcase successful practices, and develop practical recommendations supporting implementation across all five pillars.
The dedicated thematic group on capacity building should serve as a central platform for technical cooperation, peer learning, and implementation, using interactive and implementation-oriented formats such as expert-led workshops and peer-to-peer exchanges.
DTG2 has a unique opportunity to connect those seeking support with those offering it, bridging gaps between good ideas, funding, expertise, and implementation partners.
Canada is enthusiastic about elaborating on good practices and co-creating capacity building approaches at DTG2 in December.
DTG2 should be agile, results-oriented, and serve as a practical mechanism linking the practical needs of states with tangible solutions and effective cooperation.
DTG2 should play a central role in developing concrete, practical, action-oriented recommendations and decisions to be elevated to the plenary, with proposals addressing broad-level issues to allow the plenary to focus on adoption of decisions.
The measure of successful capacity building should be concrete outcomes rather than process metrics such as number of workshops or certificates
Several delegations converged on the view that capacity building success must be measured by real-world outcomes rather than process indicators. Malawi stated that the measure of successful capacity building is not the number of workshops conducted or certificates awarded, but whether countries are better prepared to prevent cyber incidents, respond effectively when they occur, and contribute meaningfully to international cooperation . Cambodia stated that the success of these efforts should be measured by concrete results, including stronger institutions, better prepared personnel, and more resilient essential services . New Zealand stated that success will ultimately be measured by whether the global mechanism makes a difference . Australia argued that the ambition for DTG2 should be to turn the fragmented ecosystem into something greater than the sum of its parts .
The measure of successful capacity building is not the number of workshops or certificates but whether countries are better prepared to prevent cyber incidents, respond effectively, and contribute meaningfully to international cooperation.
The success of capacity building efforts should be measured by concrete results: stronger institutions, better prepared personnel, and more resilient essential services.
DTG2 should focus on deliverables that provide practical support to member states, including concise implementation guidance, mechanisms to align national needs with available expertise, and recommendations to strengthen coordination of capacity building resources.
A framework is only as strong as the ability to implement it, and cyber capacity building is therefore indispensable to international peace and security.
The global mechanism and DTG2 should deliver a capacity building approach that is coherent, contextualised, calibrated, and constructive, ultimately measured by whether it makes a practical difference.
MalawiCambodiaCameroonAustraliaNew Zealand
Capacity building must be inclusive and extend beyond technical training to encompass institutional development, policy support, workforce development, and awareness programmes
Multiple delegations agreed that capacity building must go beyond purely technical training to encompass a broader range of competencies and actors. Italy argued that beyond technical training, capacity building should encompass institutional development, cybersecurity governance, policy support, workforce development, awareness programmes, and the strengthening of national cyber ecosystems . Ghana stated that capacity building should extend beyond technical training to strengthen institutions, leadership and human capital across government, law enforcement and diplomacy, academia and the private sector . Guatemala argued that capacity building should not be understood solely as technical assistance but is a comprehensive process that strengthens institutions, develops human resources, promotes public policies, and improves national resilience . The Bahamas emphasised that policy and senior decision makers must understand cyber risks so they can advance legislation, strengthen governance, and provide strategic leadership, as leadership-level capacity building is what transforms technical capacity into national action .
Capacity building should be demand-driven, sustainable, coordinated, and based on localisation, encompassing institutional development, cybersecurity governance, policy support, workforce development, and awareness programmes.
Capacity building should extend beyond technical training to strengthen institutions, leadership, and human capital across government, law enforcement, diplomacy, academia, and the private sector.
Capacity building should be understood as a comprehensive process that strengthens institutions, develops human resources, promotes public policies, improves national resilience, and helps narrow digital divides, not solely as technical assistance.
Capacity building must extend beyond technical communities to include policy and senior decision makers, as leadership-level capacity building transforms technical capacity into national action.
Capacity building efforts should strengthen legal, policy, technical, and institutional capabilities, including national cybersecurity strategies, protection of critical information infrastructure, and enhancement of incident response mechanisms.
DTG2 must prioritise concrete, needs-based support over a one-size-fits-all mandate, focusing on institutional readiness, legislative frameworks, and human capital development.
Effective capacity building strengthens not only technical capacities, but also institutions, policies, partnerships, and a cybersecurity culture embraced by people as professionals and also as individuals.
Policy Context (Knowledge Base)
This broad conception of capacity building is well-established across multiple forums. It was argued that capacity building ‘extends far beyond just technical skills to include changing mindsets, improving governance structures, and fostering collaboration across different disciplines’ [S182]. Informal stakeholder consultations similarly called for capacity building that goes ‘beyond technical training to include policy literacy, leadership development, and meaningful participation in governance processes’ [S183]. Earlier cyber governance literature also defined capacity building as encompassing ‘a comprehensive set of learning, coaching, research, and policy’ activities [S181].
Pacific Island states shared a distinctive and coherent perspective on capacity building, grounded in their unique geographic, demographic, and resource constraints. Kiribati stated that a framework that only some states can implement is not yet a framework for all , and described how each of its national cybersecurity achievements took years of work for a very small number of people . Nauru, with a population of 12,000, demonstrated that political will is not a scarce resource but capacity is, noting that a committed small state can draft laws, set strategies, and design institutions but cannot alone staff them, sustain them, and grow the expertise they require . Tonga provided a concrete example of how sustained investment paid off when its health system was attacked, with the response succeeding because relationships and capabilities had been invested in over years . Vanuatu testified that two decades of sustained national investment supported by genuine partnerships have given it the strongest cybersecurity standing in its region . The Marshall Islands described how digital connectivity is the difference between families divided by the ocean and those able to communicate across it, but that the very connection that can lift a remote nation can also expose it . All Pacific delegations aligned with the Pacific Islands Forum statement and called for the December DTG meeting to deliver concrete results, with hybrid participation treated as a condition of equity rather than a convenience .
African delegations, all aligning with the African Group statement delivered by Nigeria, shared a consistent perspective emphasising that capacity building is the foundational prerequisite for meaningful participation in the global mechanism. Cote d’Ivoire stated that for many states, capacity building remains the essential precondition for implementing the framework for responsible state behaviour . South Africa maintained that capacity building is a cross-cutting issue on all pillars of the global mechanism and that member states remain at varying levels of implementation due to differing contexts and capabilities . Rwanda highlighted that in many developing countries the challenge is not a lack of commitment but a lack of resources, technical expertise, and opportunities to build national capacities . Botswana stated there is an undeniable correlation between a country’s capacity gaps and its digital vulnerabilities . Cameroon argued that a framework without capacity remains an aspiration and that for developing countries, capacity building is not an optional component but a prerequisite for meaningful participation . The DRC stated that without human, institutional, technical, and legal capacities at the necessary level, states and particularly developing countries cannot fully participate in collective efforts .
Latin American and Caribbean delegations, many aligning with the statement delivered by Chile on behalf of a group of countries, shared a consistent perspective on capacity building as essential to equitable participation in the digital environment. Brazil argued that the digital divide renders international cooperation an urgent imperative to expand the capacity of states to forge their resilience, mitigate risks, and respond to ICT incidents . Mexico emphasised that the mechanism should reflect the idea that all states can contribute knowledge, experience, and good practices, moving towards a more horizontal approach rather than traditional donor-beneficiary categories . Ecuador described its national cybersecurity policy with international cooperation as one of its seven pillars . Uruguay stated that without a solid basis it will be difficult to implement the mechanism or to participate on an equal footing . Guatemala reaffirmed that no state can be fully secure until all have the capacities necessary to meet the challenges of the digital environment .
Russia, Cuba, China, and Iran shared a distinctive perspective that capacity building must not only provide positive support but also remove barriers and restrictive measures that impede states’ access to ICT resources. Russia stated that any attempts to restrict countries’ access to advanced ICTs or to increase their technological dependence on dominant states are unacceptable, including the monopolisation of the ICT global market . Cuba called for an end to all unilateral coercive measures that limit digital exchanges and learning, arguing that cooperation and capacity building cannot be discussed in real terms when destructive and discriminatory practices persist . China argued that relevant cooperation should not come with conditions, particularly conditions that exclude certain products from certain countries, and that countries have the right to independently choose their digital and technical products . Iran stated that restrictive measures in the ICT environment can significantly hinder the development, security, and resilience of ICT ecosystems, and that the global mechanism should consider practical measures to address and prevent such restrictive practices, including unilateral coercive measures .
Several delegations emphasised the importance of multi-stakeholder participation in capacity building, though with varying degrees of emphasis on the formal inclusion of non-state actors in the global mechanism itself. Switzerland expressed regret at the exclusion of stakeholders from the global mechanism, arguing that stakeholders are not observers of capacity building but among its principal implementers and knowledge holders, and that excluding them deprives the mechanism of the very expertise that DTG2 was created to mobilise . Japan argued that it is important to draw on the expertise of the private sector and that DTG2 should secure the participation and proposals of a wide range of stakeholders . Germany argued that a co-creation approach fosters holistic community building among states, stakeholders, and the private sector alike . Tonga stated that stakeholder inclusion is not a formality of process but how capability reaches the people who need it, and supported meaningful stakeholder participation in the work of the mechanism . France argued that various governmental and non-governmental experts and stakeholders should have a place in DTG2 as they are often the ones who develop or participate in capacity building programmes .
Several delegations addressed the relationship between the two dedicated thematic groups, with broad agreement that they should be aligned and complementary, though with some nuance about the nature of that relationship. France argued that discussions within DTG1 should provide a basis for guiding the work of DTG2, ensuring a fruitful dialectic between the two . Malaysia stated that it sees real value in ensuring closer alignment between the DTGs, so that if states continue to highlight difficulties in implementing norms, capacity building activities should respond directly to that need . Ireland stated that discussions at DTG1 and DTG2 must be aligned so that the discussions at the first are reflected in the work undertaken in the second . Italy outlined distinct but complementary roles for the two groups, with DTG1 deepening the interconnection between capacity building and other pillars, and DTG2 defining templates of CCB projects or best practices . Mexico, however, emphasised that DTG2 has its own independent mandate and its work should not be understood as being subordinate to or conditioned by DTG1 .
Unexpected Consensus
It was somewhat unexpected that the Chair herself acknowledged and responded positively to Kiribati’s practical complaint about meeting times, making a personal commitment to accommodate Kiribati’s time zone in future virtual meetings. Kiribati made a pointed argument that a 10am meeting in New York is 5am the following morning in its capital, and that requiring officials who hold the entire national cybersecurity function to choose between attending the mechanism and defending their country is not genuine inclusion . Tonga underlined that hybrid participation in the DTGs is not a convenience but a condition of equity, noting that Pacific states will never be able to travel with large delegations . The Chair responded by acknowledging she cannot promise to change the general meeting times of the global mechanism, but committed that the next time she meets with Kiribati virtually it will be at their convenient time . This practical acknowledgement of the structural barriers to participation by small island states, and the Chair’s personal commitment to address it, represented an unexpected moment of consensus on the operational dimensions of inclusive participation.
There was unexpected and powerful consensus across geographically diverse delegations that fellowship and sponsorship programmes are not merely logistical conveniences but substantive capacity building interventions that directly shape the quality of international deliberations. Kiribati stated plainly that its delegation of three people came to the session through the Women in Cyber Fellowship and the United Nations Sponsorship Programme, and that not one of them would be in the room without those programmes, arguing that the training is not incidental to the travel but is what turns attendance into participation . Tonga expressed gratitude to UNIDIR and donor partners for allowing its small nation to take part in the Women in International Security and Cyberspace Fellowship, which greatly assisted its delegation and allowed it to participate in the substantive plenary session . Albania, a European country, also acknowledged participating in the session as part of the Women in Cyber Fellowship, describing it as a strong community of women whose expertise and engagement contributes meaningfully to UN discussions on cybersecurity . The Bahamas shared a personal account of experiencing the value of the WIC programme over the previous two weeks, calling it a testament that sustained investment in people creates lasting national and international impact . This convergence of testimony from delegations across different regions and development levels on the transformative value of fellowship programmes was a notably powerful and unexpected area of consensus.
There was unexpected consensus across delegations from both developed and developing countries that capacity building should be reconceptualised as a strategic investment in collective security rather than a charitable transfer. Malawi argued that capacity building should not be viewed as assistance provided by some states to others but rather as a shared investment in international peace and security . Brazil stated that no country can tackle threats in the digital domain in isolation, and vulnerability left unaddressed in one state is a vulnerability available to be exploited against all . Australia argued that cyber capacity building is a strategic investment in collective security, and that when one state becomes more resilient, all become more resilient . Rwanda stated that collective security depends on strong cooperation, greater trust, and shared responsibility . Cameroon grounded this in an African philosophical tradition, stating that the strength of a community is measured by its ability to uplift and empower all its members . This reframing of capacity building from charity to collective self-interest was articulated consistently across delegations from very different geopolitical positions, representing a notable area of unexpected convergence.
India’s announcement that it will provide the entire funding for the operationalisation of the Global ICT Security Cooperation and Capacity Building Portal as a United Nations portal was a significant and unexpected development. India described this as an initiative it had originally tabled in 2022 that had found resonance across the membership and was ultimately endorsed by the General Assembly through Resolution 80-16 . India announced that CERT India will undertake the technical consultancy work required for the portal’s testing and infrastructure development . This concrete financial commitment from a Global South country to fund a United Nations portal for the benefit of all member states, particularly developing countries, represented an unexpected demonstration of South-South leadership in capacity building. Multiple delegations had already expressed support for the portal’s operationalisation, including South Africa , Guyana , and the DRC , making India’s announcement a moment of convergence between expressed need and concrete action. India emphasised that the portal can play a meaningful role in bridging the capacity gap between developed and developing states if treated as a living tool rather than a static repository .
Overall Assessment
The discussion on capacity building in the context of ICT security demonstrated an exceptionally high level of consensus across geographically, politically, and economically diverse delegations. The core principles of effective capacity building — that it must be demand-driven, nationally owned, sustainable, inclusive, and tailored to the specific circumstances of recipient states — were endorsed by virtually every delegation that took the floor. There was also broad agreement that capacity building is not a secondary or optional element of the framework for responsible state behaviour but its foundational prerequisite, without which commitments on norms, international law, and confidence-building measures cannot be operationalised. The December DTG2 meeting was widely seen as a critical test of whether the global mechanism can translate years of discussion into concrete, practical action. Specific mechanisms including the UN Voluntary Fund, the Global ICT Security Cooperation and Capacity Building Portal, and fellowship programmes such as the Women in International Security and Cyberspace Fellowship received broad support. India's announcement of full funding for the portal operationalisation was a landmark moment of concrete commitment. Areas of divergence were relatively limited and largely concerned the role of the United Nations versus other actors in leading capacity building efforts, the extent to which unilateral restrictive measures constitute barriers to capacity building, and the degree of formal stakeholder inclusion in the global mechanism's work.
Points of Difference
The role and primacy of the United Nations versus other actors in leading capacity building efforts
Iran argued forcefully that the UN should play a central and leading role, with existing initiatives outside the UN complementing UN work rather than the reverse . Brazil similarly called for the UN to play a larger role and centralise information . By contrast, Switzerland lamented the exclusion of non-governmental stakeholders, arguing they are principal implementers whose exclusion deprives the process of essential expertise . Italy and others pointed to the value of bilateral and multilateral channels beyond the UN, including the World Bank and ITU . Russia emphasised depoliticisation and sovereignty, implicitly resisting a dominant UN role that could be used to impose conditions . This reflects a fundamental tension between those who want a strong, centralised UN-led approach and those who prefer a more pluralistic ecosystem of providers.
The role of the United Nations should extend beyond merely coordinating and matchmaking capacity building initiatives undertaken by other actors, and existing initiatives outside the UN should complement UN work, not the other way around.
Switzerland regrets the wide-ranging veto against stakeholder participation in the global mechanism, as stakeholders are among the principal implementers and knowledge holders of capacity building, not merely observers.
Italy supports capacity building initiatives ranging from developing national cybersecurity strategies to training personnel, delivered bilaterally and through multilateral organisations such as the World Bank, UNIDIR, and ITU.
The United Nations must play a larger role in capacity building on ICT security, centralising information on existing initiatives.
Capacity building measures must be depoliticised, open, and carried out on the basis of respect for state sovereignty, without restricting countries' access to advanced ICTs.
Islamic Republic of IranSwitzerlandItalyBrazilRussian Federation
Whether stakeholders (non-governmental actors) should have a meaningful role in the dedicated thematic groups
Switzerland explicitly regretted the ‘wide-range veto against stakeholder participation’ and argued that excluding stakeholders ‘deprives it of the very expertise that DTG2 was created to mobilise’ . Japan similarly called for securing ‘the participation and proposals of a wide range of stakeholders, including the private sector’ . Ukraine, however, expressed reservations about government-sponsored entities among stakeholders, arguing that ‘governments should explain their position themselves’ , and invited the Chairpersonship to consider reserving time for thematic workshops for the ‘willing majority’ . Cambodia underscored the ‘state-led and intergovernmental character of the global mechanism’ . Cuba insisted that topic selection be done by consensus , implicitly resisting stakeholder-driven agendas. This reflects a genuine divide between those favouring robust multi-stakeholder engagement and those prioritising the intergovernmental character of the process.
Switzerland regrets the wide-ranging veto against stakeholder participation in the global mechanism, as stakeholders are among the principal implementers and knowledge holders of capacity building, not merely observers.
DTG2 should secure the participation and proposals of a wide range of stakeholders, including the private sector, to realise efficient and effective capacity building.
The dedicated thematic groups should serve as a capacity building tool for government representatives, allowing them to benefit from the best and most relevant expertise to contribute to inclusive decision-making.
Capacity building should be evidence-based, politically neutral, transparent, accountable, inclusive, non-discriminatory, and provided without conditions, with full respect for state sovereignty, human rights, and fundamental freedoms.
The selection of topics for the dedicated thematic groups should be done by consensus, and the groups should contribute to stemming the growing threat of ICTs in the context of international security.
Policy Context (Knowledge Base)
The OEWG 2021-2025 Final Report established that ‘Member States of the Global Mechanism are committed to engaging with other interested parties and stakeholders, including businesses, non-governmental organizations, and academia in a systematic, sustained, and substantive manner’ [S177]. However, the question of how this commitment translates into formal roles within dedicated thematic groups remains contested. Hybrid and virtual engagement opportunities for stakeholders between formal sessions have been proposed as one avenue [S178]. The difficulty of achieving consensus among diverse stakeholders is a recognised structural challenge in global governance [S179].
SwitzerlandJapanUkraineCambodiaCuba
The relationship and hierarchy between DTG1 and DTG2
Mexico explicitly stated that DTG2’s work ‘should not be understood as being subordinate to or conditioned by the first Dedicated Thematic Group’ , insisting on DTG2’s independent mandate. France, however, argued that ‘the discussions within the dedicated thematic group one should therefore provide a basis for guiding the work of the dedicated thematic group number two’ , suggesting a directional relationship from DTG1 to DTG2. Ireland called for alignment so that ‘discussions at the first are reflected in the work undertaken in the second’ . Malaysia similarly saw ‘real value in ensuring closer alignment between the DTGs’ . This reflects a substantive disagreement about whether DTG2 is an equal and independent body or one that should be informed and guided by DTG1’s findings.
DTG2 has its own independent mandate for accelerating capacity building and should not be subordinate to or conditioned by DTG1.
There is a necessary link between the two dedicated thematic groups, as the United Nations can only contribute to effective capacity building by having a thorough understanding of the threats and challenges that these capabilities must address.
Discussions at DTG1 and DTG2 must be aligned so that discussions in the first are reflected in the work undertaken in the second, and should focus on multi-stakeholder roles, regional coordination, gender and youth inclusion, and mainstreaming agreed ICT security capacity building guidelines.
Closer alignment between the two dedicated thematic groups is essential, so that if states continue to highlight difficulties in implementing norms on critical infrastructure protection, capacity building activities should respond directly to that need.
Policy Context (Knowledge Base)
Different delegations have proposed distinct models for the DTG relationship. Argentina proposed ‘a division of labour between the two DTGs, with DTG1 examining the operationalisation of CBMs through exchanging national and regional experiences and developing practical guidance, while DTG2 identifies the capacities required to support this operationalisation effort’ [S169]. The European Union emphasised that DTG1 and DTG2 should be ‘interconnected and complementary,’ with discussions on specific threats in DTG1 informing capacity-building gap identification in DTG2 [S171]. Brazil and Kiribati stressed the need for a clear procedure to link DTG work to the plenary for formal adoption [S170].
MexicoFranceIrelandMalaysia
Whether unilateral coercive measures and technology access restrictions should be addressed within the global mechanism's capacity building agenda
Iran argued that the global mechanism should ‘consider practical measures to address and prevent such restrictive practices, including unilateral coercive measures that adversely affect the ICT capacities of a state’ . Russia similarly stated that ‘any attempts to restrict countries’ access to advanced ICTs or to increase their technological dependence on dominant states are unacceptable’ . Cuba called for ‘an end to all unilateral coercive measures that limit exchanges or progress and digital learning environments’ . China argued that cooperation ‘should not come with conditions’ including ‘excluding certain products from certain countries’ . In sharp contrast, Italy explicitly referenced the Tallinn Mechanism providing cyber support to Ukraine against ‘the ongoing unjustified and unprovoked Russian war of aggression’ , and Ukraine highlighted the Tallinn Mechanism as a model for international cooperation . This reflects a deep geopolitical divide about what constitutes legitimate versus illegitimate restrictions on ICT access.
Capacity building also requires the removal of obstacles and barriers that impede states' ability to access ICT resources, including unilateral coercive measures that adversely affect ICT capacities.
Capacity building measures must be depoliticised, open, and carried out on the basis of respect for state sovereignty, without restricting countries' access to advanced ICTs.
All unilateral coercive measures that limit exchanges or progress in digital learning environments must be ended, as inclusive, universal, and non-discriminatory access to ICT knowledge is necessary to detect and respond to malicious use of ICTs.
Relevant cooperation should not come with conditions, including conditions that exclude certain products from certain countries, as countries have the right to independently choose their digital and technical products.
Italy supports the Tallinn Mechanism, which is a platform providing civilian cyber support to Ukraine as the latter endures the ongoing unjustified and unprovoked Russian war of aggression that is horrendously targeting civilian critical infrastructure.
The Tallinn Mechanism demonstrates how practical international cooperation can produce tangible results in maintaining essential public services and strengthening digital infrastructure resilience under cyber aggression.
Policy Context (Knowledge Base)
Cuba has argued within the OEWG that the spirit of dialogue and shared interest in ICT security should prevail in establishing the new mechanism, implicitly referencing concerns about external restrictions on technology access [S189]. This tension between technology transfer as a capacity building obligation and technology access restrictions as a geopolitical tool reflects a longstanding North-South divide in ICT governance discussions.
Islamic Republic of IranRussian FederationCubaChinaItalyUkraine
The scope of capacity building: whether it should include technology transfer and financial resources as binding commitments
Cuba called for DTG2 to deliver ‘real commitments’ including ‘financial resources and technology transfer’ for developing countries , going beyond voluntary matchmaking. Iran prioritised the voluntary UN Fund as a first-order priority . Brazil called for the UN to centralise information and play a larger role . In contrast, Korea and Germany focused on coordination, complementarity, and co-creation rather than binding financial commitments , suggesting a preference for voluntary, flexible arrangements. This reflects a tension between developing countries seeking structural financial commitments and developed countries preferring voluntary, demand-driven cooperation frameworks.
DTG2 should contribute to achieving real commitments for developing countries, including financial resources and technology transfer, bearing in mind the specific needs of each country.
The establishment of a voluntary UN Fund for capacity building should be accorded priority as one of the first priorities of DTG2, as agreed in paragraph 58 of the OEWG final report.
The United Nations must play a larger role in capacity building on ICT security, centralising information on existing initiatives.
Duplication of existing capacity building efforts should be avoided through enhanced coordination and complementarity.
Capacity building initiatives are most successful when implemented through a co-creation approach, whereby donor and recipient states collaborate closely to jointly design, develop, and implement programmes based on UN principles for cyber capacity building.
Policy Context (Knowledge Base)
Argentina noted that capacity building for ICTs in the context of international security ‘has been addressed extensively and intensively’ throughout the OEWG process, reflecting the depth of disagreement on this question [S176]. The broader debate on whether capacity building obligations should be binding mirrors similar tensions in AI governance, where inclusion and voice for countries outside dominant technology centres has been emphasised as essential to avoid exclusion [S180].
CubaIslamic Republic of IranBrazilRepublic of KoreaGermany
Unexpected Differences
In a discussion ostensibly about technical and policy capacity building, Pacific small island states raised the procedural issue of meeting times as a substantive equity concern. Kiribati argued that being required to attend meetings at 5am ‘session after session is not participation but endurance’ , and that rotating meeting times is ‘the simplest least inclusion this mechanism could offer’ . Tonga similarly stated that ‘hybrid participation in the DTGs is not a convenience but a condition of equity’ . The Chair acknowledged the concern but could not promise to change general meeting times . This was unexpected because it reframed a logistical matter as a fundamental capacity building and inclusion issue, revealing that the mechanism’s own design may inadvertently exclude the very states most in need of capacity building. No other delegation explicitly addressed this concern, suggesting it may not be widely appreciated by larger or better-resourced delegations.
In a session focused on cooperative capacity building, Russia proposed conducting UN-auspiced cyber drills and highlighted its existing experience running such exercises, including ‘on the margins of the signing of the UN Convention against Cybercrime in Hanoi in 2025’ . This was unexpected because Italy simultaneously referenced the Tallinn Mechanism providing cyber support to Ukraine against ‘the ongoing unjustified and unprovoked Russian war of aggression’ , and Ukraine highlighted the Tallinn Mechanism as a model for international cooperation while referring to ‘persistent cyber-aggression by a certain P5 member’ . The juxtaposition of Russia presenting itself as a capacity building partner while being simultaneously accused of cyber aggression by other delegations created an implicit but sharp disagreement about the credibility and legitimacy of Russia’s capacity building proposals, even though no delegation directly challenged Russia’s proposal in their statements.
Switzerland raised the unexpected issue that the Global Forum on Cyber Expertise (GFCE) Foundation ‘has had to cease its operations’ , leaving a gap in the coordination of the cyber capacity building community. Switzerland announced a new partnership with the Geneva Centre for Security Sector Governance to host a community hub to fill this gap . This was unexpected in the context of the discussion because no other delegation acknowledged or responded to the GFCE’s closure, despite it having been a significant coordination platform. The silence of other delegations on this point suggests either that the closure was not widely known, or that there is implicit disagreement about whether a new Geneva-based hub is the appropriate response, particularly given that some delegations (especially from the Global South) might prefer a more UN-centric solution rather than a Geneva-based multi-stakeholder hub.
India’s announcement that it would provide ‘the entire funding towards the operationalisation of this portal as a portal of the United Nations’ was a significant and unexpected development. While other developing country delegations had called for the portal’s operationalisation , none had anticipated that a single country would unilaterally fund the entire initiative. This creates an implicit tension: the portal is meant to be a UN mechanism serving all member states, yet its operationalisation will be entirely funded by one country (India), raising questions about governance, neutrality, and whether this represents a form of the ‘conditions’ that other delegations (notably Cuba , Iran , and Russia ) warned against in capacity building cooperation. No delegation explicitly raised this concern in their statements, making it an unexpected latent disagreement.
Overall Assessment
The discussion revealed a broadly cooperative atmosphere on the surface, with near-universal agreement on the importance of capacity building as a foundational pillar of the ICT security framework. However, beneath this consensus lay several significant fault lines. The most substantive disagreements concerned: (1) the role of the UN versus other actors in leading capacity building, with Iran and Cuba pushing for a stronger, more centralised UN role while Western states preferred a pluralistic ecosystem; (2) the inclusion of non-governmental stakeholders in the dedicated thematic groups, with Switzerland and Japan advocating for robust multi-stakeholder participation while Cambodia and Ukraine emphasised the intergovernmental character of the process; (3) the relationship between DTG1 and DTG2, with Mexico insisting on DTG2's independence while France and Malaysia argued for DTG1 to guide DTG2; (4) the geopolitical dimension of capacity building, with Russia, Iran, Cuba, and China arguing that unilateral coercive measures and technology access restrictions must be addressed, while Western states (particularly Italy and Ukraine) framed Russia itself as a source of cyber threats rather than a legitimate capacity building partner; and (5) the depth of financial commitments required, with developing countries seeking binding commitments including technology transfer while developed countries preferred voluntary, co-creation-based approaches. The Pacific small island states introduced an unexpected but important dimension by reframing meeting logistics as a fundamental equity and capacity building issue.
There is near-universal agreement that capacity building must be demand-driven, nationally owned, and tailored to the specific needs and circumstances of recipient states, rejecting a one-size-fits-all approach [13-14, 47, 158-163, 232, 325-326, 364, 488, 502, 582-584, 612, 748, 806, 857, 869, 872-876]. However, speakers diverged on how to operationalise this principle: some emphasised co-creation between donors and recipients [502, 244], others stressed Pacific or regional leadership , and still others focused on the UN's role in facilitating needs identification [20, 87-89]. The shared goal of demand-driven capacity building thus masks significant differences about who should lead the process and through what mechanisms.
Agreed
Cote d'IvoireMalawiCambodiaMexicoRepublic of KoreaGermanyAustraliaKiribatiVanuatuRwandaBotswanaGhanaMalaysiaArgentinaIreland
Contested
Capacity building must be voluntary, inclusive, sustainable, transparent, and based on the needs expressed by beneficiary states themselves, taking into account local realities and producing measurable results. Capacity building must be demand-driven, tailored to national priorities, and promote self-sufficiency by enabling states to develop enduring institutions and skilled professionals rather than creating long-term dependency. Capacity building must be demand-driven, tailored to national circumstances, and grounded in national ownership, with programmes designed jointly with recipient states and aligned with their national strategies. Capacity building should not be driven solely by the priorities of providers or follow a one-size-fits-all approach, whether it should be demand-driven and tailored to the specific needs and priorities of recipient states. Capacity building initiatives are most successful when implemented through a co-creation approach, whereby donor and recipient states collaborate closely to jointly design, develop, and implement programmes based on UN principles for cyber capacity building. DTG2 should become a platform where states can openly discuss implementation challenges, share lessons learned, and collectively understand where the most urgent gaps remain. Capacity building works when it is country-owned, with partners supporting priorities that the country itself identified rather than priorities identified for it. Capacity building in the Pacific must be Pacific-led, co-designed by those it serves, contextualised, coordinated, sustainable, and inclusive. In many developing countries, the challenge is not a lack of commitment but a lack of resources, technical expertise, and opportunities to build national capacities. Cyber capacity building is the fundamental pillar upon which the framework for responsible state behaviour rests, with an undeniable correlation between capacity gaps and digital vulnerabilities. Capacity building must be needs-driven, nationally owned, and tailored to each country’s context, priorities, and level of cyber maturity, with no one-size-fits-all approach. Capacity building must address the needs identified by the beneficiary country itself, taking into account specific geographical circumstances and avoiding standardised or one-size-fits-all models. Capacity building must be based on the needs identified by individual states and be country-driven, with limited resources used in the most effective way possible, avoiding duplication. Capacity building should respond to concrete needs identified by states, moving beyond awareness raising to support the development of capabilities relevant to national circumstances and priorities. Capacity building must be demand-driven, tailored to national priorities, and responsive to the different levels of development and capacities of member states.
Virtually all developing country delegations agreed on the need for the UN Voluntary Fund and the Global ICT Security Cooperation and Capacity Building Portal [33, 52-54, 257-259, 354-357, 422-423, 678-679, 805]. India went further by announcing it would fund the entire operationalisation of the portal . However, there was disagreement about the priority and scope of these mechanisms: Iran argued the voluntary fund should be 'one of the first priorities of DTG-2' , while others treated it as one element among many. Cuba called for binding financial commitments and technology transfer , going beyond the voluntary nature of the fund that most others endorsed. Mexico emphasised the need for 'predictable and sustainable financing' without specifying the mechanism.
Agreed
South AfricaMalawiIndiaGuyanaIranDRCRwandaBotswanaGhanaMexicoUruguayCote d'Ivoire
Contested
South Africa looks forward to further discussions on the development and operationalisation of the UN Voluntary Fund for capacity building and the establishment of the dedicated Global ICT Security Cooperation and Capacity Building Portal. The voluntary fund under the global mechanism represents an important investment in ensuring equitable participation and strengthening the implementation of shared commitments, particularly for developing countries. India will provide the entire funding for the operationalisation of the Global ICT Security Cooperation and Capacity Building Portal as a United Nations portal, moving from design to reality. Guyana supports the operationalisation of the Global ICT Security Cooperation and Capacity Building Portal and the establishment of the UN Voluntary Fund for ICT Security Capacity Building. The establishment of a voluntary UN Fund for capacity building should be accorded priority as one of the first priorities of DTG2, as agreed in paragraph 58 of the OEWG final report. The DRC supports the swift operationalisation of the global ICT security cooperation and capacity building portal to align needs with offers of assistance. The global mechanism should ensure that capacity building remains practical and accessible to all states, building on the foundations laid by the OEWG. All capacity building efforts must systematically adopt a gender-sensitive perspective, as true cyber resilience cannot be achieved while a gender-digital divide persists. Capacity building is a cornerstone of the framework for responsible state behaviour in ICTs, enabling states to prevent, detect, respond to, and recover from cyber threats while participating meaningfully in international cooperation. Predictable and sustainable financing is essential to enable all states to participate fully in capacity building activities. Regional and international initiatives such as those by UNIDIR and the OAS, especially the Women in Cyber programme, have proven effective tools for strengthening national capacity and should be continued and expanded. Cote d’Ivoire recommends developing a UN tool to identify states’ needs and connect them with partners, programmes, and financing.
There was broad agreement that the December DTG2 meeting must deliver concrete, practical outputs rather than further discussion of principles [149, 222-223, 437-439, 592-593, 749, 900-905]. However, speakers diverged on what those outputs should be: Pacific states focused on mapping needs, a user-friendly portal, and sustainable financing [438-439, 222-223]; Iran called for consolidating previous OEWG proposals ; Germany emphasised hands-on interactive discussions and complementarity with the Global Roundtable ; and Argentina focused on DTG2 producing mature texts for plenary adoption . The shared urgency for action thus coexisted with different visions of what 'action' means.
The challenge is not a lack of goodwill or programmes but how to bring together a fragmented ecosystem of actors and turn it into something greater than the sum of its parts. The December DTG meeting should focus on concrete, measurable outputs including mapping needs against what already exists, developing tools states can actually use, and identifying sustainable financing. The December DTG meeting should deliver three concrete outputs: an honest global mapping of needs against provision, a user-friendly capacity building portal, and credible progress on sustainable financing. The December DTG meeting is the first true test of whether the global mechanism can convert deliberation into delivery, and hybrid participation in DTGs is a condition of equity, not merely a convenience. DTG2 should move from principles to concrete programmes, including a clear mapping of needs and a user-friendly capacity building portal. Capacity building is the enabler that underpins all aspects of the global mechanism’s work, and the Pacific Islands Forum working paper on regional capacity building priorities should be recommended to the mechanism. Capacity building is how the promise of digital connection is made safe for nations like the Marshall Islands, and the global mechanism must reach even the most distant shores so that no nation is left beyond its horizon. The dedicated thematic groups should become platforms where member states openly exchange experiences, identify common challenges, showcase successful practices, and develop practical recommendations supporting implementation across all five pillars. The global mechanism should ensure that capacity building remains practical and accessible to all states, building on the foundations laid by the OEWG. DTG2 should build upon the experience accumulated in the previous OEWG process, including the 2024 Global Roundtable and the Secretariat’s mapping exercise. Proposals from previous OEWGs on capacity building should be consolidated into a single compilation to serve as the basis for focused, practical discussions within DTG2. DTG2 and the annual Global Roundtable offer valuable but complementary platforms for capacity building discussions, with DTG2 focused on hands-on interactive discussions and the Roundtable providing a platform for donors and recipient states.
There was widespread agreement on the importance of gender inclusion in capacity building, with many delegations praising the Women in International Security and Cyberspace Fellowship [31, 55, 269-270, 326, 385-386, 399-402, 576, 637-639, 807-809]. However, Brazil went further by arguing that gender, race, and disability perspectives should be treated as 'a substantive component of capacity building rather than an afterthought' , suggesting that current approaches remain insufficient. Mexico called for incorporating 'a gender perspective' as a design principle , while some delegations mentioned gender only briefly or in passing. The depth of commitment and the specific mechanisms proposed varied considerably across delegations.
Agreed
MalawiBotswanaGhanaSerbiaAlbaniaBosnia and HerzegovinaUruguayCote d'IvoireBrazilMexicoCanadaMauritiusBahamas
Contested
Inclusive cybersecurity is stronger cybersecurity, and when women participate fully as policymakers, technical experts, incident responders, diplomats, and leaders, institutions become more resilient and responses more effective. All capacity building efforts must systematically adopt a gender-sensitive perspective, as true cyber resilience cannot be achieved while a gender-digital divide persists. Gender must be mainstreamed across all capacity building initiatives, with increased opportunities for women through training, mentorship, fellowship, and leadership programmes being essential to a more inclusive and resilient cybersecurity ecosystem. Serbia underlines the importance of the full, equal, and meaningful participation of women in all processes related to ICT security. Albania expressed appreciation for participating in the Women in Cyber Fellowship, made possible through the support of the Netherlands, as a strong community of women whose expertise contributes meaningfully to UN cybersecurity discussions. Capacity building must be sustainable rather than ad hoc, requiring long-term strategies that build skills and institutional memory, and must be fully inclusive, engaging governments, the private sector, academia, and civil society with a gendered perspective. Regional and international initiatives such as those by UNIDIR and the OAS, especially the Women in Cyber programme, have proven effective tools for strengthening national capacity and should be continued and expanded. Cote d’Ivoire calls for more ambitious, inclusive international cooperation that includes women and youth and promotes transfer of knowledge and development of lasting local expertise. Ensuring women and marginalised populations are included in the ICT security workforce must be treated as a substantive component of capacity building, not an afterthought. The mechanism should move beyond traditional donor-beneficiary categories towards a more horizontal, inclusive, and needs-based approach to cooperation. Canada supports the Compendium of Good Practices on Gender Equality and Cybersecurity, demonstrating how gender-responsive approaches strengthen cyber resilience. Capacity building should be guided by the principles of inclusivity, accessibility, and equality, ensuring that no state is left behind, and should mainstream gender perspectives into programmes and national ICT policies. The Women in International Security and Cyberspace Fellowship demonstrates the value of sustained investment in people, creating lasting national and international impact.
All these speakers agreed that capacity building must be inclusive and involve a broad range of actors beyond central government. However, they differed on the nature and extent of that inclusion: Switzerland explicitly lamented the exclusion of non-governmental stakeholders from the global mechanism itself , while Tonga and Kiribati focused on community-level inclusion within their own societies [587-591, 149]. Germany and Japan emphasised private sector and industry participation in DTG2 discussions [508, 729]. Cambodia, while supporting inclusive approaches, simultaneously underscored the 'state-led and intergovernmental character of the global mechanism' , creating tension with Switzerland's position. The shared value of inclusivity thus masked disagreement about whether non-state actors should participate in the intergovernmental process itself.
Switzerland regrets the wide-ranging veto against stakeholder participation in the global mechanism, as stakeholders are among the principal implementers and knowledge holders of capacity building, not merely observers. The challenge is not a lack of goodwill or programmes but how to bring together a fragmented ecosystem of actors and turn it into something greater than the sum of its parts. Capacity building initiatives are most successful when implemented through a co-creation approach, whereby donor and recipient states collaborate closely to jointly design, develop, and implement programmes based on UN principles for cyber capacity building. DTG2 should secure the participation and proposals of a wide range of stakeholders, including the private sector, to realise efficient and effective capacity building. Capacity building must be inclusive, with stakeholder inclusion being not a procedural formality but the means by which capability reaches the people who need it. Capacity building must be inclusive, as in small societies inclusion is not a procedural courtesy but the only way capacity is built and sustained. Capacity building should be evidence-based, politically neutral, transparent, accountable, inclusive, non-discriminatory, and provided without conditions, with full respect for state sovereignty, human rights, and fundamental freedoms.
Key Takeaways
Capacity building is universally recognised as the foundational pillar upon which all other elements of the UN Framework for Responsible State Behaviour in Cyberspace depend; without adequate technical, institutional, human, and legal capacities, norms cannot be operationalised, international law cannot be applied, and confidence-building measures cannot be implemented.
There is a strong consensus that capacity building must be demand-driven, nationally owned, needs-based, sustainable, inclusive, transparent, and tailored to the specific circumstances and priorities of each state, explicitly rejecting one-size-fits-all approaches.
The digital divide between developed and developing countries represents a critical structural inequality that undermines collective cyber security; closing this gap is framed not as charity but as a shared investment in international peace and security, since a vulnerability in one state is a vulnerability exploitable against all.
Gender inclusion is a substantive component of effective capacity building, not an afterthought; the Women in International Security and Cyberspace (WIC) Fellowship and UNIDIR’s Compendium of Good Practices on Gender Mainstreaming in Cybersecurity are widely commended as concrete examples of inclusive capacity building that directly enriched the plenary discussions.
Despite strong political commitment expressed across two OEWGs, no concrete operational capacity building measures have yet been adopted at the UN level; the global mechanism is now expected to translate years of deliberation into practical, measurable action.
The Dedicated Thematic Group on Capacity Building (DTG2) is regarded as one of the most important innovations of the new mechanism, with its December 2025 meeting widely described as the first real test of whether the mechanism can convert discussion into delivery.
Regional organisations, including the African Union, ASEAN, Pacific Islands Forum, OAS, and OSCE, are recognised as essential partners in capacity building, with the most effective programmes often being regionally grounded, co-designed, and contextualised.
Co-creation — whereby donor and recipient states, alongside non-governmental stakeholders, jointly design, develop, and implement capacity building programmes — is identified as a best practice model that produces more effective, sustainable, and nationally owned outcomes.
Sustainable financing is a critical unresolved challenge; the UN Voluntary Fund for ICT Security Capacity Building is widely supported as a priority mechanism, and India announced it will provide full funding for the operationalisation of the Global ICT Security Cooperation and Capacity Building Portal as a UN portal.
Practical accessibility of the global mechanism itself is a capacity building issue; delegations from small island developing states and remote nations highlighted that hybrid participation at inconvenient hours and the absence of fellowship support would effectively exclude them from meaningful engagement.
Emerging technologies including artificial intelligence, quantum computing, cloud services, and the Internet of Things are reshaping the cyber threat landscape and must be integrated into capacity building agendas to ensure states can adopt innovations securely.
Confidence-building measures and capacity building are deeply interconnected pillars; joint exercises, bilateral cyber dialogues, and fellowship programmes contribute simultaneously to both, and DTG2 should reflect this cross-cutting relationship.
The measure of successful capacity building is not the number of workshops or certificates produced, but whether states are better prepared to prevent cyber incidents, respond effectively, and contribute meaningfully to international cooperation.
Resolutions & Action Items
India announced it will provide entire funding for the operationalisation of the Global ICT Security Cooperation and Capacity Building Portal as a UN portal, with CERT India undertaking technical consultancy work for the portal’s testing and infrastructure development.
The Russian Federation formally presented an initiative to conduct drills on responding to computer attacks under UN auspices, involving real-time virtual competitions among national teams, and stated it plans to work with the UN Secretariat on implementation with Russia’s financial, organisational, and methodological support.
Switzerland announced that the Geneva Centre for Security Sector Governance (DCAF) has entered into partnership with Switzerland to host a community hub designed to carry forward the coordination and multi-stakeholder engagement functions previously performed by the Global Forum on Cyber Expertise (GFCE), which has ceased operations.
China announced the formation of an international AI cooperation organisation with 29 founding member states and committed to providing 5,000 AI fellowships to developing countries over the next five years to support international AI development and capacity building.
The Chair confirmed that the December DTG2 meeting will be the first dedicated session on capacity building under the global mechanism, with remaining speakers from the current session to continue the following morning.
Delegations broadly agreed that DTG2 should build upon the experience accumulated in the OEWG process, including the 2024 Global Roundtable on ICT Security Capacity Building and the Secretariat’s mapping exercise, rather than starting from scratch.
Iran proposed that proposals on capacity building from the first and second OEWGs be consolidated into a single compilation prepared under the Chair’s authority to serve as the basis for focused discussions within DTG2.
Multiple delegations called for the topics of the thematic groups to be selected as soon as possible to allow countries to nominate experts and prepare substantive contributions, with France explicitly urging early selection.
Australia, Germany, Singapore, and Canada each proposed or endorsed a co-creation model for capacity building programmes, placing national priorities at the centre and involving donors, implementers, and beneficiaries in joint design.
Mauritius highlighted that it hosts an ITU Global Academy Training Centre conducting annual cybersecurity training attended by over 20 countries and encouraged interested delegations to register on the ITU Academy portal for future trainings.
Kiribati formally requested that meeting times be rotated to accommodate delegations in distant time zones, framing this as a condition of genuine inclusivity rather than a matter of comfort.
Ukraine invited the Chairpersonship and Secretariat to consider reserving time for thematic workshops during the December session so that the willing majority could benefit from the broadest available expertise.
Unresolved Issues
The precise mandate, agenda topics, working methods, and format of DTG2 remain to be determined; France and others called for topics to be selected as soon as possible, but no agreement on specific topics was reached during the session.
The operationalisation of the UN Voluntary Fund for ICT Security Capacity Building, including its governance structure, eligibility criteria, contribution mechanisms, and disbursement modalities, remains to be worked out in DTG2.
The question of stakeholder participation in the global mechanism and its thematic groups remains contested; Switzerland expressed regret at the veto against stakeholder participation, while Ukraine raised concerns about government-sponsored entities among stakeholders, and no resolution was reached.
The relationship and division of labour between DTG1 and DTG2 is not fully settled; Mexico stressed that DTG2 should not be subordinate to DTG1, while France and Malaysia argued that DTG1 discussions should inform and guide DTG2’s work, and Italy suggested DTG1 would deepen interconnections while DTG2 would define templates.
How to address unilateral coercive measures and technology access restrictions that impede states’ ability to develop ICT security capacity remains unresolved and politically contested, with Iran and Cuba calling for the global mechanism to address this and other delegations not engaging with the proposal.
The question of how to ensure sustainable, predictable financing for capacity building beyond the voluntary fund — including how to avoid dependence on short-term project cycles — was raised by multiple delegations but not resolved.
The practical design of hybrid participation arrangements for DTG2 and future sessions, including meeting times that accommodate Pacific and other distant time zones, was raised by Kiribati and Tonga but not formally addressed.
How the global mechanism will coordinate with and avoid duplicating the extensive existing landscape of bilateral, regional, and multilateral capacity building programmes without creating additional bureaucratic burden remains to be worked out.
The future governance and sustainability of the community hub being established by DCAF and Switzerland to replace the GFCE’s coordination functions, and its relationship to the intergovernmental process, remains to be discussed with delegations and the Chair.
How to ensure that the Global ICT Security Cooperation and Capacity Building Portal, funded by India, is treated as a living tool populated with actionable information by all member states rather than a static repository, and how its governance will be structured, remains to be determined.
The selection of specific topics for DTG2’s December meeting has not yet been announced, leaving delegations unable to nominate appropriate experts or prepare targeted contributions.
How to systematically integrate capacity building considerations as a cross-cutting thread across all five pillars of the framework within the cross-cutting thematic group’s work remains to be operationalised.
Suggested Compromises
Several delegations, including Mexico and Argentina, suggested that DTG2 and DTG1 should be understood as complementary and equal rather than hierarchical, with DTG2 having its own independent mandate while the two groups coordinate to avoid duplication and generate coherent outcomes — a framing that attempts to bridge differing views on their relationship.
Canada proposed a co-creation analogy framing beneficiaries, non-governmental stakeholders, and donor countries as players, coaches, and supporters respectively, all needing to agree on the same match before deciding how to play — suggesting a collaborative rather than donor-driven model that could bridge the traditional donor-beneficiary divide.
Mexico proposed moving away from the traditional categories of ‘donors’ and ‘beneficiaries’ towards an approach that recognises all states as potential providers of knowledge, experience, and good practices according to their capacities, which could help bridge the political divide between developed and developing countries on the nature of capacity building relationships.
Germany and Singapore both proposed a co-creation model as a middle ground between purely top-down donor-driven programmes and purely bottom-up recipient-driven requests, with joint design, development, and implementation as the basis for effective and sustainable capacity building.
Australia suggested that DTG2 should focus on connecting existing solutions to those who need them rather than creating new programmes, which could serve as a compromise between those calling for new UN-led initiatives and those wishing to avoid duplication of existing efforts.
Switzerland’s proposal for a community hub hosted by DCAF to carry forward GFCE functions could serve as a compromise between those who want robust multi-stakeholder engagement in capacity building coordination and those who insist on the intergovernmental character of the global mechanism, by situating stakeholder coordination outside but complementary to the formal process.
The framing of capacity building as a ‘shared investment in international peace and security’ rather than assistance from some states to others, as articulated by Malawi and echoed by others, represents a conceptual compromise that could help bridge the political divide between developed and developing countries on the nature and obligations of capacity building.
Iran’s proposal to consolidate capacity building proposals from the two OEWGs into a single compilation under the Chair’s authority could serve as a procedural compromise that gives developing countries confidence that previous proposals will not be lost while providing a structured basis for focused DTG2 discussions acceptable to all.
“Kiribati’s delegation to this session is three people. Two are here through the Women in Cyber Fellowship. One is here under the United Nations Sponsorship Program. Not one of us will be in this room without those programs… What those programs gave us was the chance to bring it. To the state and partners who made this possible. We thank you. The training is not incidental to the travel. It is what turns attendance into participation.”
“The measure of successful capacity building is not the number of workshops conducted or certificates awarded. It is whether countries are better prepared to prevent cyber incidents, respond effectively when they occur, and contribute meaningfully to international cooperation.”
“Capacity building is not limited to positive measures aimed at addressing the needs and priorities of developing countries. It also requires the removal of obstacles and barriers that impede states’ ability to access ICT resources and develop their national capacity. Restrictive measures in the ICT environment can significantly hinder the development, security, and resilience of ICT ecosystems. Such measures undermine existing capacities and impede efforts to strengthen them. Accordingly, the global mechanism should also consider practical measures to address and prevent such restrictive practices, including unilateral coercive measures that adversely affect the ICT capacities of a state.”
“India will be providing the entire funding towards the operationalization of this portal as a portal of the United Nations, so that concrete, tangible action can finally follow years of discussion. India’s support will help enable the technical establishment of the portal and its maintenance, ensuring that the platform envisaged — comprising a repository of resources, a capacity-building calendar, a needs-based catalogue of opportunities, and an interactive discussion board — can move from design to reality.”
“We speak from experience… What our partners gave us was not the capability delivered ready-made. It was the chance to build our home and the patience to let us do it. That is the first lesson and the most important. Capacity building works when it is country-owned… The second is that it must be sustained. A single training builds a memory. It does not build an institution. And the third is that it must be inclusive. Government alone did not build Kiribati’s cyber security. Our churches, our communities, our private sector, our schools and our regional partners each carry part of it.”
“Nauru, a country with a population of 12,000 people, offers this account for a reason. It demonstrates that political will is not a scarce resource. Capacity is. A committed small state can draft the laws, set the strategies, and design the institution. What it cannot do alone is staff them, sustain them, and grow the expertise they require. When the officials concerned already carry several portfolios each, capacity building for a state like Nauru must therefore be cumulative — each engagement building on the last, developing our own people rather than substituting for them, and lasting beyond any single project cycle. Support delivered in fragments leaves fragments behind.”
“Switzerland would once again like to express its regret at the wide-range veto against stakeholder participation in the global mechanism. Stakeholders are not observers of capacity building. They are among its principal implementers and knowledge holders. Excluding them does not protect the intergovernmental character of this process. It deprives it of the very expertise that DTG2 was created to mobilise.”
“Vanuatu can testify that capacity building works. Two decades of sustained national investment supported by genuine partnerships have given Vanuatu the strongest cybersecurity standing in our region by international assessment. We say this without complacency. Our gaps remain real and our resources thin. But with purpose, the return on well-designed capacity building is measurable, and sceptics of this pillar should study the Pacific before doubting it.”
“The Russian Federation presents an initiative to conduct drills on responding to computer attacks under the auspices of the United Nations… real-time virtual competitions among national teams on a training base provided by the operator, during which they will simulate responding to various types of malicious activities… The technical and diplomatic points of contact of the UN Global Intergovernmental Points of Contact Directory also participate in the exercises.”
“Mexico considers it appropriate to move towards an approach that recognises the providers of assistance for capacity building rather than resorting to the traditional categories such as donors and beneficiaries. This would foster more horizontal, inclusive and needs-based cooperation.”
How can a UN-led tool be developed to help states identify their capacity-building needs and connect them with partners, programmes, and available financing?
Cote d'Ivoire
Many developing states lack the means to identify and access relevant capacity-building resources. A centralised UN matchmaking tool could systematically bridge this gap, making it a priority area for DTG2 to explore in concrete terms.
How should the UN Voluntary Fund for ICT security capacity building be operationalised, and what governance structures should guide it?
South Africa, Iran, Guyana, Ghana, Democratic Republic of the Congo, Malawi
Multiple delegations referenced the Voluntary Fund as an agreed priority from the OEWG final report but noted that no concrete operational steps have yet been taken. Clarifying its design, eligibility criteria, and disbursement mechanisms is essential for equitable participation.
How should the dedicated Global ICT Security Cooperation and Capacity Building Portal be designed and populated so that it is genuinely useful to officials in recipient states with limited time and resources?
Brazil, India, Guyana, Ghana, Nauru, Vanuatu
India announced funding for the portal, but several delegations raised practical concerns about usability. Research into user-centred design for officials managing multiple portfolios is needed to ensure the portal functions as a living tool rather than a static repository.
What concrete, measurable outputs should DTG2 produce at its December 2026 meeting, and how should its work be structured to move from principle to programme?
Kiribati, Nauru, Vanuatu, Tonga, Australia, Malawi, Cameroon, Argentina
Numerous delegations expressed concern that discussions risk remaining aspirational. Defining specific deliverables—such as a global needs mapping, portal design, and financing progress—before December is critical to demonstrating the mechanism’s practical value.
How can existing capacity-building proposals from the first and second OEWGs be consolidated into a single compilation to serve as a practical basis for DTG2 discussions?
Iran
Iran proposed that the Chair compile all member state proposals on capacity building from previous OEWG processes. This would prevent duplication of effort and allow DTG2 to build on accumulated consensus rather than starting from scratch.
Should a dedicated UN Cyber Fellowship Programme be established, and if so, what should its scope, eligibility, and funding model be?
Iran, Democratic Republic of the Congo, African Group (via Nigeria)
The UN-Singapore Cyber Fellowship is recognised in the OEWG final report, but several delegations called for a broader UN-led fellowship. Further research is needed on how such a programme would complement existing initiatives without duplication.
How can unilateral coercive measures and other restrictive practices that impede states’ access to ICT resources and capacity-building opportunities be addressed within the global mechanism?
Iran, Cuba, Russian Federation, China
Several delegations argued that capacity-building discussions cannot be separated from barriers to technology access. Whether and how the global mechanism should address such measures is an unresolved question requiring further deliberation.
How should DTG1 and DTG2 be coordinated so that implementation challenges identified in substantive discussions directly inform tailored capacity-building partnerships?
Cambodia, Malaysia, France, Ireland, Mexico
Multiple delegations stressed that the two thematic groups must be aligned—threats and norms discussed in DTG1 should feed directly into the capacity-building agenda of DTG2. The precise coordination mechanism has not yet been defined.
How can capacity-building efforts be made genuinely sustainable and avoid creating long-term dependency in recipient states?
Malawi, Kiribati, Nauru, Bahamas, Bosnia and Herzegovina
Delegations repeatedly distinguished between one-off training and institution-building. Research into models that develop local trainers, institutional memory, and national expertise pipelines—rather than substituting for them—is needed to guide DTG2 recommendations.
How should meeting times and hybrid participation arrangements for the global mechanism be structured to ensure genuine inclusion of small island developing states and Pacific nations?
Kiribati, Tonga, Vanuatu
Kiribati highlighted that a 10 a.m. New York meeting is 5 a.m. the following morning in their capital, forcing officials to choose between attending the mechanism and performing their national cybersecurity duties. Practical solutions to time-zone inequity remain unaddressed.
How can the global mechanism develop a co-creation model for capacity building that places national priorities at the centre, uses regional coordination for needs identification, and leverages international mechanisms for visibility and partnerships?
Singapore, Germany, Canada
Singapore proposed a co-creation model as a structural approach, and Germany and Canada elaborated on it with examples. The specific design of such a model—including roles for donors, implementers, and beneficiaries—requires further elaboration before DTG2.
What role should non-governmental stakeholders, including the private sector, academia, and civil society, play in DTG2, given the veto exercised against broader stakeholder participation?
Switzerland, Japan, Ukraine, France, Australia
Switzerland expressed regret at the veto against stakeholder participation, arguing that excluding implementers deprives the process of essential expertise. Ukraine raised concerns about government-sponsored entities posing as civil society. The appropriate modalities for stakeholder engagement remain contested and unresolved.
How can the functions previously performed by the Global Forum on Cyber Expertise (GFCE), which has ceased operations, be carried forward to maintain coordination across the cyber capacity-building ecosystem?
Switzerland
Switzerland announced a new community hub hosted by DCAF in Geneva to fill the gap left by the GFCE’s closure. Whether this hub, or an alternative arrangement, can effectively sustain multi-stakeholder coordination and complement the global mechanism requires further discussion and research.
How should the global mechanism conduct an honest global mapping of capacity-building needs against existing provision to expose mismatches that are widely suspected but not yet documented?
Vanuatu, Nauru, Australia, Brazil
Several delegations called for an evidence-based picture of where needs and support do and do not meet. Brazil referenced the 2024 Global Roundtable mapping exercise as a starting point, but a comprehensive, updated, and publicly accessible mapping exercise has not yet been undertaken.
How can capacity-building efforts be made genuinely gender-responsive, and how should gender be treated as a substantive component rather than an afterthought in DTG2’s work?
Brazil, Malawi, Botswana, Mexico, Albania, Bosnia and Herzegovina, Ghana
Multiple delegations called for gender to be mainstreamed across all capacity-building initiatives. The UNIDIR Compendium of Good Practices on Gender Mainstreaming was welcomed, but how its guidance should be operationalised within the global mechanism’s work programme remains an open question.
How can capacity-building for emerging technologies—including artificial intelligence, quantum computing, cloud services, and the Internet of Things—be integrated into the global mechanism’s agenda in a way that is accessible to developing and small island states?
Ecuador, Italy, Rwanda, Vanuatu, Bahamas
Several delegations noted that their national policies already address emerging technologies but that international capacity-building has not kept pace. Research into how the global mechanism can support states in assessing and safely adopting these technologies is needed.
How should the topics for DTG1 and DTG2 be selected, and how quickly should this be done to allow states and co-facilitators to prepare substantive contributions?
France
France called for the topics of the thematic groups to be selected as soon as possible so that countries can nominate experts and co-facilitators can guide upcoming discussions. The selection process and timeline have not yet been determined.
How can regional organisations—including the African Union, ASEAN, Pacific Islands Forum, and regional economic commissions—be formally leveraged within the global mechanism to maximise resources and ensure capacity building is adapted to sub-regional contexts?
Multiple delegations argued that regional bodies understand local political and physical challenges better than global institutions. The precise modalities for integrating regional organisations into the global mechanism’s capacity-building architecture have not been defined.
How can the global mechanism develop indicators and monitoring mechanisms to assess the results of capacity-building initiatives and measure whether countries are better prepared to prevent and respond to cyber incidents?
Ecuador, Malawi, New Zealand
Malawi argued that success should be measured not by workshops conducted but by operational preparedness. Ecuador called for indicators and follow-up mechanisms. Developing agreed metrics for capacity-building outcomes is an unresolved research and policy question.
How should DTG2 handle the relationship between capacity building and the removal of barriers—such as technology transfer restrictions and export controls—that impede developing states’ ability to build ICT security infrastructure?
Cuba, Iran, Russian Federation
Several delegations argued that capacity building cannot be effective while structural barriers to technology access persist. Whether the global mechanism has a mandate to address such barriers, and if so how, is a contested question requiring further deliberation.
How can the global mechanism ensure that capacity-building support is cumulative and builds on previous engagements rather than being delivered in disconnected fragments?
Nauru, Kiribati, Malawi
Nauru described the need for capacity building to be ‘phobia-cumulative’, with each engagement building on the last. Kiribati noted that a single training builds a memory but not an institution. Research into programme design models that ensure continuity across funding cycles is needed.
How can the Russian Federation’s proposed UN-auspiced cyber drills—involving national teams responding to simulated attacks using the UN Points of Contact Directory—be evaluated and potentially integrated into the global mechanism’s capacity-building agenda?
Russian Federation
Russia presented a formal initiative for virtual cyber drills under UN auspices, citing existing experience from events in Hanoi, Nizhny Novgorod, and St Petersburg. Whether and how this initiative aligns with the mechanism’s principles and complements existing exercises requires further assessment by member states.
How should the global mechanism address the specific capacity-building needs of small island developing states, including climate-resilient digital infrastructure and the assessment of satellite connectivity and cloud services before adoption?
Pacific and Caribbean delegations identified needs that differ substantially from those of larger states, including infrastructure resilience in the face of climate change. These context-specific needs have not yet been systematically incorporated into the global mechanism’s capacity-building agenda.
How can the global mechanism promote South-South, triangular, and regional cooperation as complements to North-South partnerships in capacity building?
Ghana, Democratic Republic of the Congo, Cuba, Mexico
Several delegations called for moving beyond traditional donor-beneficiary models towards more horizontal cooperation. Research into effective South-South and triangular modalities that can be facilitated through the global mechanism is needed.
How should DTG2 treat capacity building as a cross-cutting issue running through all five pillars of the framework, rather than as a standalone pillar?
Nauru, Tonga, Vanuatu, South Africa
Multiple delegations argued that capacity is the difference between endorsing the framework and living it, and that the cross-cutting thematic group should embed capacity considerations in its treatment of every pillar. The practical mechanism for doing so has not been defined.
Disclaimer: This is not an official session record. DiploAI generates these resources from audiovisual recordings, and they are presented as-is, including potential errors. Due to logistical challenges, such as discrepancies in audio/video or transcripts, names may be misspelled. We strive for accuracy to the best of our ability.
The seventh meeting of the substantive plenary session of the Global Mechanism on ICT security focused primarily on two agenda items: confidence-building measures (CBMs) and capacity building . Delegates from numerous states and regional organisations took the floor to share national experiences and recommendations for advancing the practical implementation of the agreed framework for responsible state behaviour in cyberspace.
On confidence-building measures, there was broad consensus that the Global Points of Contact Directory represents a significant achievement of the Open-Ended Working Group and should be further operationalised . Multiple delegations, including Vanuatu, Australia, and Germany, stressed that the directory must complement rather than replace existing diplomatic and regional communication channels, and that it should be used in good faith and with due regard for the capacity constraints of smaller states . Côte d’Ivoire and Cameroon recommended organising regular UN-sponsored simulation exercises and strengthening CBMs at the regional and sub-regional level . The Russian Federation noted that 125 states had joined the directory but highlighted practical challenges, including “dead contacts” and politically motivated non-responses, calling for a standardised communication template and in-person meetings of POC representatives .
Several delegations, including Tonga and the Dominican Republic, emphasised that confidence is built through sustained cooperation before a crisis occurs, citing real-world examples such as Tonga’s joint public attribution following a health system cyberattack . Regional organisations, including the OSCE and the African Union, shared their experiences implementing CBMs and recommended institutionalising dialogue between the global mechanism and regional bodies .
On capacity building, which formed the second major agenda item, the Pacific Islands Forum, the African Group, the European Union, and a Latin American group all underscored that capacity building is a cross-cutting enabler underpinning all pillars of the framework . Delegations called for the Dedicated Thematic Group 2 (DTG2) to serve as a strategic coordination platform that is demand-driven, nationally owned, and avoids duplication of existing initiatives . Practical proposals included a voluntary UN ICT Security Capacity Building Fund, a fellowship programme for developing countries, and the Global ICT Security Cooperation and Capacity Building Portal .
Overall, the discussion reflected strong agreement that the global mechanism must move beyond political commitments towards concrete, inclusive, and operationally effective implementation of both confidence-building measures and capacity-building initiatives, ensuring that no state, particularly small island developing states and least developed countries, is left behind .
Keypoints
Overall Purpose
The discussion takes place during the seventh meeting of the substantive plenary session of the Global Mechanism on ICT security. Its primary purpose is to advance international dialogue on confidence-building measures (CBMs) and capacity building in cyberspace, with a focus on translating previously agreed frameworks into practical, operational tools that reduce the risk of misunderstanding, escalation, and conflict among states.
—
Major Discussion Points
The Global Points of Contact (POC) Directory as a central confidence-building tool: Multiple delegations welcomed the establishment of the Global Intergovernmental Points of Contact Directory as a flagship practical achievement, while stressing that its value depends on use, regular testing, and good-faith engagement. Concerns were raised about “dead contacts,” low response rates, and misuse of the directory. Russia reported receiving 2,576 inquiries in the past year, with only approximately 48% responded to. Germany noted receiving repetitive, identical messages from a certain state that did not reflect responsible use of the directory. States broadly agreed the directory should complement, not replace, existing diplomatic and technical channels.
Operationalising CBMs through the Dedicated Thematic Groups (DTGs): A strong consensus emerged that the DTGs represent a critical opportunity to move beyond abstract political commitments and translate the eight agreed voluntary global CBMs into concrete, practical action. Argentina proposed that DTG1 focus on exchanging national and regional experiences and developing practical guidance, while DTG2 could identify capacity needs and promote voluntary exercises. The Dominican Republic cautioned that a designated contact point on paper is not the same as one capable of responding 24 hours a day, 365 days a year. Several delegations, including Tonga on behalf of the Pacific Islands Forum, urged that DTGs avoid becoming additional negotiating rooms reproducing procedural disagreements. – The role of regional organisations in implementing CBMs: Numerous delegations highlighted the indispensable role of regional bodies – including ECOWAS, the OAS, ASEAN, the African Union, the OSCE, and Pacific regional mechanisms – in developing and implementing CBMs tailored to local realities. The OSCE noted it was the first regional organisation to develop cyber CBMs and has 16 CBMs with years of practical implementation experience, including an “Adopt-a-CBM” initiative. The African Union Commission recommended that the global mechanism institutionalise regular technical dialogue with regional organisations and facilitate integration of regional POC networks with the global directory. Cross-regional learning and avoiding duplication were consistently emphasised.
Capacity building as a cross-cutting prerequisite for effective CBM implementation: Delegations from developing countries, particularly from Africa, the Pacific, Latin America, and the Caribbean, stressed that capacity building is not a secondary issue but a strategic enabler underpinning all pillars of the framework. CARICOM identified three regional priorities: cyber law, sustained cyber capacity building, and critical infrastructure protection for small states. The Philippines, Ireland, and Australia all noted that many states face institutional, technical, and resource constraints that prevent meaningful participation in CBMs. Calls were made for demand-driven, nationally owned, sustainable, and inclusive capacity-building initiatives, including a voluntary UN ICT Security Capacity Building Fund and a fellowship programme for developing countries.
Coherence, non-duplication, and the voluntary nature of CBMs: A recurring theme was the need to ensure that the expanding architecture of communication channels and CBM initiatives remains coherent and does not create burdens for states – particularly smaller ones – operating multiple channels through the same handful of officials. Vanuatu articulated this concern directly, calling for clear guidance on which channels serve which purpose and consistency in points of contact. Cuba and Iran both emphasised that the voluntary nature of CBMs must be preserved and that measures must respect sovereignty and non-interference in internal affairs. Germany stressed that any CBM, existing or newly proposed, should be concrete, action-oriented, voluntary, and focused on building transparency rather than creating obligations. —
Overall Tone
The overall tone of the discussion is constructive, cooperative, and pragmatic, with a shared sense of purpose around implementing the agreed framework for responsible state behaviour in cyberspace. Delegations across all regions expressed genuine commitment to advancing CBMs and capacity building, and there was broad convergence on key principles such as voluntariness, inclusivity, and the need to move from political commitments to practical action.
The tone remained largely consistent throughout, though it shifted slightly in emphasis as the session progressed. Early interventions from smaller states such as Vanuatu and Tonga introduced a grounded, operational perspective, highlighting the real-world constraints faced by nations with limited diplomatic and technical resources. Later contributions from larger delegations and regional organisations added layers of institutional experience and specific proposals. Germany’s remarks introduced a mildly cautionary note regarding the misuse of the POC directory, reflecting underlying tensions about good-faith engagement. The session on capacity building in the latter portion carried a more urgent and advocacy-driven tone, particularly from African and Latin American group statements, which framed capacity building as a matter of equity and sustainable development rather than merely a technical concern. There were no significant moments of open disagreement, though divergent priorities – particularly between developed and developing states – were evident beneath the surface of diplomatic language.
Speakers Overview
NO
NIgeria on behalf of African Group
108 wpm · 9 min
I
Israel
126 wpm · 3 min
A
Argentina
113 wpm · 5 min
DR
Dominican Republic
109 wpm · 6 min
C
Cameroon
115 wpm · 5 min
C
Cuba
110 wpm · 3 min
G
Germany
161 wpm · 4 min
CD
Côte d'Ivoire
123 wpm · 4 min
T
Tonga
122 wpm · 2 min
TO
Tonga on behalf of Pacific Islands Forum
120 wpm · 5 min
I
Ireland
151 wpm · 2 min
N
Netherlands
131 wpm · 4 min
V
Vanuatu
122 wpm · 3 min
C
Chile
107 wpm · 4 min
CR
Chile Representative on behalf of Latin American group
129 wpm · 7 min
NM
North Macedonia
123 wpm · 2 min
BA
Bosnia and Herzegovina
125 wpm · 2 min
O
OSCE
160 wpm · 4 min
N
Norway
152 wpm · 2 min
U
Uruguay
123 wpm · 2 min
G
Ghana
108 wpm · 3 min
M
Malawi
101 wpm · 4 min
P
Philippines
116 wpm · 4 min
BO
Bahamas on behalf of the CARICOM
96 wpm · 6 min
IR
Islamic Republic of Iran
88 wpm · 4 min
T
Tuvalu
115 wpm · 4 min
B
Botswana
126 wpm · 4 min
RF
Russian Federation
145 wpm · 5 min
A
Australia
145 wpm · 4 min
T
Thailand
110 wpm · 2 min
M
Malaysia
98 wpm · 3 min
AU
African Union Commission
106 wpm · 4 min
DR
Democratic Republic of Congo
89 wpm · 5 min
EU
European Union
119 wpm · 6 min
DF
DMUN Foundation
133 wpm · 2 min
V
Vietnam
125 wpm · 2 min
I
Iraq
114 wpm · 3 min
C
Colombia
112 wpm · 4 min
CR
Costa Rica
119 wpm · 3 min
N
Nigeria
118 wpm · 4 min
M
Morocco
107 wpm · 4 min
M
Mozambique
92 wpm · 2 min
CE
Chair Egriselda López
106 wpm · 16 min
Expanded Summary: Seventh Meeting of the Substantive Plenary Session of the Global Mechanism on ICT Security
#
Opening and Agenda
The seventh meeting of the substantive plenary session of the Global Mechanism on ICT security was called to order by Chair Egriselda López . In accordance with the programme of work, the session continued with the list of speakers on the agenda item on confidence-building measures (CBMs), with 22 requests for the floor outstanding at the start of proceedings . The session subsequently moved to a second major agenda item on developing and implementing capacity building . Throughout both segments, delegations from all regions, as well as regional organisations and accredited stakeholders, took the floor to share national experiences, highlight operational challenges, and advance proposals for the practical implementation of the agreed framework for responsible state behaviour in cyberspace.
—
#
Confidence-Building Measures: Foundational Principles and Broad Consensus
There was near-universal agreement across the session that CBMs are indispensable practical tools for fostering trust, transparency, predictability, and cooperation among states, contributing to international peace and security in cyberspace . Nigeria, speaking on behalf of the African Group, affirmed that CBMs are essential for reducing the risk of misunderstanding and miscalculation . Israel described CBMs as allowing states to build practical procedures during peacetime that can be directly utilised for de-escalation, communication, and risk reduction during geopolitical crises . Australia characterised CBMs as tools for reducing the risk of misinterpretation, escalation, and conflict, helping states build relationships and establish communication channels before a crisis occurs so that these channels can be used effectively during and after cyber incidents .
Côte d’Ivoire offered a normative framing, observing that in cyberspace, uncertainty about the origin, intention, or scale of an incident can rapidly give rise to misunderstandings and stoke tensions, and that the lack of reliable communication channels can transform a technical incident into a political crisis . The delegation argued that trust is not something that can be declared by fiat but is built by dialogue, transparency, predictability, and results-based cooperation . Cameroon similarly described CBMs as providing one of the most direct avenues for translating political commitments into practical cooperation, contributing to reducing misunderstandings, preventing misperceptions, and lowering the risk of unintended escalations . North Macedonia noted that CBMs are among the most valuable outcomes of the Open-Ended Working Group (OEWG) process, demonstrating that states can agree on practical measures to strengthen trust and improve communication even in a complex and rapidly evolving cyber environment .
Norway outlined three specific points on CBMs: first, that CBMs provide practical tools for implementing agreed commitments through mechanisms such as points of contact, dialogue, sharing of best practices, and information sharing; second, that CBMs enable practical cooperation between states, creating opportunities to exchange experiences, share best practices, and strengthen implementation of the framework including resilience, incident response, and protection of critical infrastructure; and third, that effective implementation requires capacity and broad participation including through the inclusion of women. Norway also noted that capacity building and confidence building are mutually reinforcing.
Several delegations introduced important nuances to this broad consensus. Cuba explicitly stated that CBMs on their own do not guarantee the strictly peaceful use of ICTs and that they are merely complementary to binding norms, emphasising that the voluntary nature of CBMs must prevail and that different phases of confidence building must respect sovereignty and non-interference in internal affairs . Cuba also stressed that the establishment of binding norms within the UN framework is itself one of the pillars for international confidence building . Germany, by contrast, argued that any CBM – existing or newly proposed – should be concrete, action-oriented, and voluntary in nature, and should avoid entering the field of expectations or even obligations , reflecting a preference for keeping CBMs strictly voluntary rather than moving towards binding frameworks.
—
#
The Global Points of Contact Directory: Achievements and Operational Challenges
The Global Intergovernmental Points of Contact (POC) Directory was consistently identified as the flagship practical achievement of the OEWG . Tonga strongly supported the directory as the flagship practical achievement and commended UNODA for its continued operationalisation . Argentina underscored the directory as one of the most relevant milestones achieved in the OEWG . The Russian Federation, which claimed the directory was established on its initiative, described it as enabling the first universal confidence-building measure in the field of international information security, establishing a mechanism for preventing interstate conflicts in the information space . By the time of the session, 125 states had joined the directory .
Despite this broad support, the session surfaced significant operational challenges. The Russian Federation provided detailed statistics, reporting that its POC had received 2,576 inquiries in the previous year, of which only approximately 48% were responded to . Russia attributed this to what it termed “dead contacts” – where organisations or individuals not authorised to engage in specialised cooperation are designated to the directory – as well as the continuous availability problems of technical POCs, and cases where certain capitals simply ignore requests for political reasons . Russia called for the finalisation of a standardised communication template as a priority task, noting that a draft had been presented by UNODA but had not been substantively discussed before the OEWG’s final report was adopted . Russia also called upon the Chair to include a separate agenda item in the Global Mechanism’s programme of work for discussing issues related to supporting and improving the POC directory , and proposed in-person meetings of POC representatives as envisaged in the OEWG final report . Russia additionally announced plans to contribute to the development of the POC directory by practising POC interaction under a Russian Capacity Building Initiative, which it indicated it would introduce under the relevant agenda item.
Germany’s subsequent intervention introduced a notable moment of diplomatic tension. Without naming Russia explicitly, Germany reported that its technical POC had received repetitive, identical messages from a certain state that did not take into account its replies, characterising this as “clearly not in line with the purpose of the UN POC directory” and as not presenting “a responsible or sincere use of the directory” . This exchange revealed that political dynamics were already manifesting within what was designed as a non-politicised, technical communication mechanism . Germany indicated that its Federal Foreign Office serves as the diplomatic POC and its Cyber Security Agency as the technical POC, and that it remains open to engaging in good faith with all interested parties .
Australia reinforced the need for responsible use, calling for requests through the directory to be proportionate, purposeful, and made with due regard to the capacity constraints of smaller states . Australia explicitly warned that the directory should not be treated as a mechanism for overwhelming national points of contact, creating unreasonable expectations of response, or as a substitute for existing procedures where other channels are more appropriate . Thailand supported regular communication checks, simulation exercises, and continued engagement to ensure the directory remains effective when needed most . Thailand also considered the communication template provided by the Secretariat pursuant to A/79/14 as a useful tool and suggested incorporating elements such as urgency and confidentiality to better reflect operational needs, particularly in time-sensitive or critical situations. The African Union Commission recommended facilitating the integration of regional points of contact with the global POC directory , while Cameroon envisioned the directory evolving from a repository of contacts into a dynamic instrument for cooperation with progressively enhanced functionalities .
A recurring theme across multiple delegations – including Ireland, the Netherlands, Germany, Vanuatu, and Australia – was that the POC directory must complement rather than replace existing diplomatic and technical communication channels . Ireland stated it should be used in good faith as a complement to existing channels . The Netherlands argued that its strength and added value lie in establishing lines of contact where these previously were unavailable or unclear, and that it should not replace existing POC networks or other diplomatic channels . Germany similarly argued the directory is not intended to replace established channels such as FIRST, the network of CERTs, CERT-to-CERT cooperation, or law enforcement cooperation . Malaysia mentioned the ASEAN Regional Forum Points of Contact Directory as an example of how regional efforts can complement the implementation of CBMs. Vanuatu articulated this concern most directly from the perspective of small administrations, noting that the international community is multiplying its channels of communication and requesting clear guidance on which channels serve which purpose, consistency in points of contact where national structures allow it, and no duplication of what already functions elsewhere .
—
#
Vanuatu and Tonga: Pacific Perspectives on Practical Confidence Building
Vanuatu offered one of the session’s most conceptually distinctive contributions, reframing the discussion on the POC directory from a quantitative to a qualitative lens. The delegation observed that “confidence is not built by the number of channels that exist, or the volume of requests within them, but by the certainty of what happens when one is used” . Vanuatu also drew a compelling analogy between disaster response and cyber incident cooperation, noting that when disaster strikes its islands, information flows between governments within hours – offers of assistance, coordination of relief, verification of facts on the ground – and that this habit of rapid, trusted state-to-state communication in physical emergencies is precisely the habit the CBM agenda seeks to create for digital ones . The delegation argued that a region accustomed to cooperating through cyclones is well-placed to cooperate through cyber incidents .
Vanuatu further emphasised transparency as a measure available to every state regardless of size, noting its own openness about national arrangements, legislative development including its data protection and privacy bill, and assessments of the threat environment . The delegation called for the structured exchange of such national information within the mechanism, not as a reporting burden, but as routine practice that prevents misreading between states . Vanuatu also supported regular communications exercises for the directory, sustained training for designated officials with attention to continuity as personnel change, and the preservation of hybrid modalities so that distance never determines who participates in building confidence .
Tonga provided the session’s most powerful empirical illustration of CBMs working in practice. The delegation noted that when its health system was attacked the previous year, established relationships with partners enabled rapid assistance and ultimately a joint public attribution with Australia and New Zealand . Tonga characterised this as demonstrating “what confidence building measures look like when they work: relationships built before the crisis, exercised during it and deepened after it” . Tonga’s CERT, established by cabinet decision in 2016 as among the first national CERTs in the Pacific, had worked within the Pacific Cyber Security Operational Network, where incident responders share information and build the personal trust on which crisis cooperation depends . Tonga accordingly urged the mechanism to “keep the CBM agenda modest in rhetoric and ambitious in practice” – a directory that works, points of contact who are trained and exercised, regional experience feeding global learning, and hybrid participation so that officials from Nukuʻalofa can engage .
—
#
CBMs as Preventive Diplomacy: The Dominican Republic’s Regional Lessons
The Dominican Republic offered a particularly candid and analytically rigorous contribution, drawing on its experience as chair of the OAS working group on CBMs in cyberspace during the 2024-2025 session . The delegation argued that the challenge is no longer normative but practical, since global CBMs benefit from broad political backing but what is lacking is translating these CBMs into established capacities . Crucially, the Dominican Republic drew a sharp distinction between CBMs as preventive diplomacy tools and real-time incident response mechanisms, noting from regional experience that when ransomware struck essential public services, “bilateral technical direct cooperation was key” and that CBMs helped to boost confidence and trust in order to engage and host technical assistance and act rapidly – but were not themselves the response mechanism .
The Dominican Republic also called for transparency in POC directory response metrics, arguing that sharing these metrics would reflect both the real results of implementation and the real commitment of each party . The delegation highlighted the OAS’s development of a common severity scale for incidents, which allows all members to understand and recognise how serious an incident affecting another member state is, and noted that measuring severity can help prioritise and scale cooperation between national CERTs . The delegation also emphasised that no CBM can be implemented in a void and that national mechanisms and practical measures are needed to turn these tools into regulations and achieve institutional continuity when staff turnover occurs – a challenge particularly relevant in Latin American countries .
—
#
Operationalising CBMs Through the Dedicated Thematic Groups
A strong consensus emerged that the Dedicated Thematic Groups (DTGs) represent the primary vehicle for translating agreed CBMs into practical action. Israel stated that the DTGs must prioritise further developing and operationalising CBMs, as they hold great potential for immediate positive impact and for generating beneficial momentum for the global mechanism . Chile viewed the DTGs as offering a valuable opportunity to go into further depth on the role of international organisations in effective CBM implementation, exchanging national experiences and good practices . Argentina proposed a division of labour between DTG1, which could examine the operationalisation of CBMs by exchanging national and regional experiences and developing practical guidance, and DTG2, which could identify the capacities required to support this operationalisation effort, including proposals to strengthen national capacities of contact points and promote voluntary exercises .
Argentina further expressed hope that the DTGs would establish themselves as spaces for technical work capable of producing substantive recommendations and decisions on CBMs for consideration by the plenary, and that these recommendations would subsequently be reviewed, fine-tuned, and negotiated by states in plenary deliberations . Cameroon offered a distinctive framing, stating that “the success of the DTGs is a confidence building measure” given its capacity to bring states together to strengthen exchanges and enable a lasting culture of cooperation in cyberspace to emerge. This vision of DTGs as quasi-negotiating spaces producing actionable outputs was not universally shared. The Pacific Islands Forum, speaking through Tonga, explicitly warned that DTGs should not become additional negotiating rooms that reproduce the same procedural disagreements or simply repeat plenary discussions, with their value to be measured by whether they help countries make progress . The Netherlands suggested that simulation exercises within DTGs could demonstrate how public-private partnerships could concretely benefit an open, free, and secure cyberspace . North Macedonia called for CBMs to be reflected in DTG work through sharing of national experience, practical implementation approaches, and good practices, while avoiding duplication of plenary discussions .
—
#
Regional Organisations: Indispensable Partners in CBM Implementation
Delegations from all regions consistently highlighted the indispensable role of regional organisations in developing and implementing CBMs tailored to local realities. The African Group encouraged the global mechanism to strengthen coordination and complementarity between global and regional confidence-building initiatives, promote linkages between regional POC networks and the global directory, support regional cyber exercises and capacity building, and encourage voluntary exchange of national experiences and good practices . Chile argued that the exchange of good practices between regional mechanisms could make meaningful contributions to strengthening CBM implementation globally, avoiding duplications and making the most of lessons learned in different contexts .
Uruguay highlighted the OAS experience as a practical model, noting that since 2018 it has designated and updated its technical contact points in the OAS framework and participates actively in cooperation mechanisms such as CERT Americas, promoting the exchange of technical information including indicators, good practices, and strengthening of state capacities . Ghana pointed to the ECOWAS regional framework on cyber ICT confidence-building measures, which establishes practical mechanisms including national diplomatic and technical points of contact and information-sharing arrangements . The Philippines, as ASEAN Chair in 2026, welcomed progress in operationalising the ASEAN Regional CERT as an important step toward raising the regional cybersecurity posture through timely information sharing and coordinated incident response .
The OSCE described itself as the first regional organisation to develop cyber confidence-building measures and noted it has many years of experience in the practical implementation of its 16 CBMs . The OSCE described its “Adopt-a-CBM” initiative, through which 26 participating states have adopted nine CBMs and significantly contributed to their meaningful implementation . The OSCE also noted that it held its sixth annual meeting of technical and policy points of contact in Vienna the previous month, where the global mechanism was discussed with the aim of raising awareness . The OSCE Secretariat referenced a non-paper on inter-regional cooperation submitted by Switzerland to the second OEWG in June 2024, prepared with contributions from seven regional organisations, which provided recommendations on how regional organisations could contribute to future discussions .
The African Union Commission endorsed the African Group’s statement and provided additional detail on its own work, noting that the common African position on the application of international law to cyberspace reaffirms the importance of the peaceful settlement of disputes in cyberspace . The Commission stated that its ambition is not to reproduce existing models or multiply the number of CBMs, but to set out concrete, adapted measures suited to African realities that can be effectively implemented across the various regions of the continent, drawing on experience from economic and regional committees including ECOWAS . The Commission recommended that the global mechanism institutionalise a technical and regular dialogue with regional organisations, strengthen support to regional organisations for CBM development and implementation, and facilitate the integration of regional points of contact with the global POC directory .
Bosnia and Herzegovina highlighted the launch of the Western Balkans Cyber Diplomacy Network in 2025, supported by the German Federal Foreign Office, as a regional initiative representing the region’s shared commitment to addressing cross-border cyber challenges through dialogue and cooperation . Germany noted its close work with ECOWAS member states and the ECOWAS Commission in their journey towards the adoption of a first set of CBMs in Africa , and co-hosted a side event with Ghana and the Dominican Republic on regional best practices for CBM implementation .
Cuba introduced an important caveat, arguing that each region or sub-region has unique characteristics and that measures implemented at these levels cannot be considered single global models or benchmarks . The African Union Commission similarly stated that its ambition is not to reproduce existing models , reflecting a shared concern that regional approaches should be contextually adapted rather than universally imposed.
—
#
Simulation Exercises, Training, and Practical Cooperation
Multiple delegations emphasised that simulation exercises, regular training, and practical cooperation activities are essential for building confidence before crises occur. Côte d’Ivoire recommended regularly organising under UN auspices simulation exercises that bring together points of contact, national incident response teams, and relevant authorities . Argentina supported continuing voluntary exercises, gradually fine-tuning their modalities and exchanging experiences that encourage practical use of the POC directory . Australia highlighted its Cyber Rapid Assistance for Pacific Incidents and Disasters programme as an example of building trust and habits of trust between states and regions, emphasising that cooperation must be established before it is needed in a crisis . The OSCE described its scenario-based exercises as usually well received by participants, helping them understand the practical application of CBMs . Thailand supported regular communication checks, simulation exercises, and continued engagement to ensure the directory remains effective when needed most .
Botswana provided a detailed account of its national CBM implementation, noting that it has operationalised its national cybersecurity strategy and established the Botswana Computer Incident Response Team under the Botswana Communications Regulatory Authority to coordinate incident management, issue threat advisories, and safeguard national critical infrastructure . Botswana also described its engagement in formal bilateral and sub-regional information-sharing protocols among CERTs within the SADC region, its participation as a continental partner under the African CERT umbrella, and its formal public-private partnerships, threat intelligence sharing, and academic collaboration . Malawi noted its role as Vice Chair of the SADC CICERT working group and its engagement with FIRST, Africa CERT, and the ITU .
—
#
Iran’s Proposals for New Confidence-Building Measures
The Islamic Republic of Iran introduced two substantive proposals that went beyond the consensus positions of most other delegations. First, Iran highlighted a proposal from paragraph 47k of the OEWG final report for a new CBM aimed at facilitating access by all states to ICT security products and tools, arguing that this strengthens national capacities while simultaneously promoting cooperation, trust, and confidence among states . Second, drawing on paragraph 52 of the OEWG final report, Iran proposed that the global mechanism prepare a consolidated list of technical terms used in consensus-based OEWG reports and undertake discussions to develop common understandings of key concepts such as ICTs, ICT infrastructure, ICT environment, and malicious use of ICTs . Iran called for both proposals to be considered by the first DTG and incorporated into the existing set of eight voluntary global CBMs . These proposals touched on politically sensitive issues – including technology transfer, export controls, and definitional disputes – that are likely to resurface in the DTGs.
—
#
Capacity Building: A Cross-Cutting Strategic Priority
The second major agenda item – developing and implementing capacity building – generated an equally extensive discussion, with 43 requests for the floor received . There was strong consensus across all regional groups that capacity building is a cross-cutting enabler underpinning all pillars of the framework for responsible state behaviour, not merely a standalone pillar . The Pacific Islands Forum, speaking through Tonga, described capacity building as “the enabler that underpins all aspects of our work,” foundational to responding to threats, implementing norms, engaging meaningfully in international law discussions, and sustaining CBMs, and argued it should not be siloed . The African Group stated that for African countries, capacity building is not an auxiliary issue but a strategic enabler for achieving a secure, resilient, and inclusive digital future as digital transformation accelerates across the continent .
Costa Rica offered one of the session’s most memorable formulations, warning that “without capacities, we run the risk of building a legally elegant infrastructure that is operationally useless” . The delegation described capacity building as a bridge between consensus and action, arguing that voluntary norms, international law, CBMs, and due diligence can only be turned into policies and practical steps if states have technical, legal, and institutional capacities that are up to the mark . Costa Rica also highlighted that legal interpretation requires specialised institutional capacities, including the ability to evaluate incidents, establish national positions on the application of international law to cyberspace, understand different legal thresholds, and participate responsibly in international debates . Morocco similarly described capacity building as “the guiding thread that runs through all the other pillars of responsible behavior” .
Vietnam stated that capacity building is essential for states to develop common understanding of voluntary non-binding norms of responsible state behaviour, shared experiences, and best practices in applying these norms to protect critical infrastructure and supply chains. Vietnam supported flexible and inclusive capacity building to bridge the digital divide, incorporating gender equality and awareness raising. Vietnam also announced its initiative to establish an Asia-Pacific Regional Cybercrime Center in Hanoi in cooperation with UNODC, as a follow-up to the ratification of the UN Convention against Cybercrime, welcoming participation of other states and stakeholders as sponsors and partners.
—
#
DTG2 as the Main Platform for Capacity Building Dialogue
The Latin American group, with Chile speaking on behalf of Argentina, Brazil, Colombia, Costa Rica, Ecuador, Guatemala, Honduras, Mexico, Paraguay, Peru, the Dominican Republic, and Uruguay, called for DTG2 to be established as the main platform for dialogue on capacity building within the global mechanism, playing a fundamental role as a space for strategic coordination to facilitate information exchange, articulate synergies between existing mechanisms, and identify opportunities for cooperation . The group announced it would soon present a working document with concrete proposals on the future functions, priorities, and modalities of DTG2 . The group also emphasised that both DTGs play different but complementary roles and must be worked on together in a balanced way, with the cross-cutting nature of capacity building reflected throughout .
The African Group called for DTG2 to build upon rather than duplicate the valuable outcomes of the OEWG, and welcomed a proposal for a structured diagnostic assessment of the current capacity-building landscape as a DTG2 deliverable . The group outlined African capacity-building priorities including strengthening national cybersecurity strategies and governance frameworks, developing legislative and regulatory frameworks, enhancing technical and operational capabilities including national and sectoral CERTs, building cyber diplomacy expertise, promoting cyber resilience for critical infrastructure, supporting digital forensics and cybercrime investigation, and fostering regional cooperation and information sharing . The African Group also supported practical initiatives including the Global ICT Security Cooperation and Capacity Building Portal, the Point of Contact Directory, strengthened national CERTs, a Voluntary UN ICT Security Capacity Building Fund and Programme to Develop Cyber Security Professionals, and a United Nations ICT Security Fellowship Programme for developing countries with attention to least developed countries and small island developing states. The European Union highlighted its significant investment of 100 million euros across 27 projects globally and its commitment to continue investing, recognising capacity building as an essential pillar of security and stability in cyberspace . The EU also proposed that the global roundtable on capacity building could play a coordination role, bringing together capacity-building implementers for exchange of information and best practices, feeding into plenary and DTG2 discussions .
CARICOM, with the Bahamas speaking on behalf of the 14-member Caribbean community, specifically welcomed the establishment of DTG2 on capacity building, describing it as “a cornerstone of the evolving framework for responsible state behaviour in cyberspace.” CARICOM identified three regional priorities: cyber law and modern legal and regulatory frameworks, sustained cyber capacity building for resilience and technical expertise, and critical infrastructure protection for small states . CARICOM noted that the 2025 OAS IDB Cybersecurity Report confirmed both progress and persistent gaps in resources, workforce development, and cross-sector coordination across the region , and supported capacity-building initiatives that are voluntary, demand-driven, sustainable, transparent, and based on national ownership .
—
#
Demand-Driven, Nationally Owned, and Sustainable Capacity Building
A strong consensus emerged that capacity building must be demand-driven, nationally owned, sustainable, and tailored to the specific needs and priorities of countries . The African Group underscored that effective capacity building must respect national sovereignty and regional perspectives and realities . Colombia emphasised the value of South-South and triangular cooperation as particularly valuable modalities for capacity building, facilitating the exchange of knowledge and good practices while taking account of local realities and priorities . Colombia also proposed incorporating analysis of specific real case studies and hypothetical scenarios into DTG2 discussions to generate concrete lessons and practical recommendations . Iraq stressed that capacity building should receive financial and technical support so that equal opportunities are available to all states, with special attention to developing countries and countries emerging from conflict . Nigeria called for DTG2 to prioritise strengthening national cybersecurity strategies, legal and governance frameworks, technical capabilities including CERTs, and expertise in cyber diplomacy, digital forensics, and cybercrime investigations . Nigeria also supported practical initiatives including the Global ICT Security Cooperation and Capacity Building Portal, strengthened national CERTs, a Voluntary UN ICT Security Capacity Building Fund, and a UN ICT Security Fellowship Programme for developing countries, particularly least developed countries and small island developing states .
—
#
Small Island Developing States and the Digital Divide
Small island developing states and geographically distant delegations consistently emphasised that their unique circumstances create specific challenges for CBM implementation and that the global mechanism must be designed with these constraints in mind. Tuvalu highlighted its Tuvalu Subsea Cable as a vital digital lifeline and called for clear international guidance for the protection of subsea infrastructure, seeking an explicit CBM commitment from all member states and stakeholders to share best practices to safeguard this essential digital lifeline from both natural hazards and malicious cyber threats . Tuvalu also introduced the concept of “capacity sovereignty,” arguing that international cooperation must shift away from short-term external consulting and towards tangible long-term training of local technical teams, with true confidence established where every state possesses the sovereign ability to manage its own digital systems independently . Tuvalu announced it would host the 19th Asia-Pacific Telecommunication Policy and Regulation Forum from 4 to 6 August, framing it as a practical confidence-building measure in itself .
Botswana argued that global transparency initiatives must be paired with concrete technical assistance to address the digital divide, and that states should leverage regional and sub-regional platforms to strengthen operational mechanisms . The Pacific Islands Forum called for improvements to accreditation and participation modalities so that stakeholder participation is real rather than nominal, and urged that meeting times be rotated so Pacific delegations are not consistently asked to participate in the middle of the night . The Democratic Republic of Congo joined calls from Colombia and Mexico to promote multilingualism as a guarantor of inclusivity in negotiation spaces, ensuring effective participation by everyone .
—
#
Stakeholder Engagement: Private Sector, Civil Society, Academia, and Youth
There was broad agreement on the importance of stakeholder engagement from the private sector, civil society, academia, and the technical community for effective CBM implementation and capacity building. Ireland argued that the expertise and experience of these stakeholders should play a strong role in the process, with practical tools, best practices, and examples feeding engagement and allowing CBMs to be reflected in national and regional structures . Ireland also highlighted specific CBMs to be implemented, including sharing national ICT-related information and actions, exchanging experience on protecting critical infrastructure, promoting information exchange and cooperation and partnerships between states to strengthen ICT security capacity, and organising regular seminars, workshops, and training programmes on ICT security. Australia stated that industry and the technical community, civil society, and academia are often closest to vulnerabilities, incidents, and emerging risks, and that their expertise can help states understand threats, improve prevention and response, strengthen supply chain resilience, and translate CBMs into practical action, while preserving the intergovernmental nature of decision-making . Uruguay highlighted that public-private partnerships are essential given that a significant part of critical information infrastructure is operated by non-governmental actors or is part of the supply chain . The Pacific Islands Forum strongly supported the substantive inclusion of stakeholders in both formal and informal settings and the fullest possible use of expert briefings within the DTGs .
The DMUN Foundation, speaking on behalf of the Youth Publications and Socioeconomic Forum, introduced the novel argument that youth engagement should be considered a practical confidence-building measure in itself, including through structured dialogues between governments and youth, support for youth-led cyber awareness initiatives, and opportunities for young experts to participate in regional and international CBM activities . The Foundation noted that today’s youth are the first generation to grow up in an environment where cyber incidents, online disinformation, and AI-generated content are part of everyday life, yet are rarely included in discussions on how trust and confidence in cyberspace should be built . Nigeria commended initiatives such as the UNODA and donor-sponsored Women in International Security and Cyberspace Fellowship as making valuable contributions to broadening inclusive participation .
—
#
Chair’s Summary and Transition to Capacity Building
Before giving the floor to Botswana, Chair López acknowledged that it was the last day for Ambassador Norman of the Netherlands serving as Special Envoy for Cyber Issues, and called for a round of applause from the room in recognition of his long journey in the mechanism.
In her closing summary of the CBMs agenda item, Chair López noted that delegations had reflected on the eight global measures, including information exchange measures, collaboration between the public and private sectors, and capacity building as a cross-cutting topic . She welcomed state participation in the POC directory and expressed hope that universal participation would eventually be achieved, urging all states that had not yet done so to appoint and nominate diplomatic contact points and engage in verifications to ensure these contacts remain and operational . The Chair noted that all statements had been taken as important inputs for determining how to structure discussions in the DTGs .
Following the conclusion of the CBMs agenda item, the Chair opened the floor to accredited stakeholders in accordance with the modalities established in Annex 1 of A/82/57, allowing them to make oral statements with a strict limit of three minutes each . The session then transitioned to the capacity building agenda item, with 43 requests for the floor received . The meeting was adjourned with 49 requests still outstanding under the capacity building item, with the Chair announcing that the remaining delegations would be heard in the afternoon session at 3 p.m. .
—
#
Overall Assessment
The seventh meeting of the substantive plenary session demonstrated a remarkably high level of consensus across geographically and politically diverse delegations on the fundamental importance of CBMs and capacity building as pillars of the framework for responsible state behaviour in cyberspace. The core principles of CBMs as practical tools, the value of the POC directory, the importance of capacity building, the role of regional organisations, and the need for practical operationalisation through DTGs commanded near-universal support. The most significant areas of tension – the implicit Russia-Germany conflict over good-faith use of the POC directory , Cuba’s distinct position on binding norms , and the burden placed on small island developing states by multiplying communication channels – were present in the discussions, though not always directly contested. Among the most analytically substantive contributions were those that combined concrete evidence or lived experience with normative framing, exemplified by Tonga’s account of its health system attack , the Dominican Republic’s lessons from regional ransomware incidents , and Costa Rica’s formulation about “legally elegant but operationally useless” infrastructure . These contributions deepened the level of analysis and set a practical standard against which the global mechanism’s future work in the DTGs will be measured.
—
Chair Egriselda López
So please take your seats. Buenos dias. Se declara abierta la sesión. Very good morning. I call to order the seventh meeting of the substantive plenary session of the Global Mechanism on ICT security. The meeting is called to order. According to our program of work, and like I announced yesterday afternoon, we will be continuing with our list of speakers on the agenda item on confidence -building measures. I’d just like to underscore that we still have 22 requests for the floor. Let me just read the first five to speak this morning. We have Vanuatu, Chile, Israel, Cote d ‘Ivoire. Thank you. and the last speaker, Ireland. I give the floor first to Vanuatu.
—
Vanuatu
Madam Chair, Vanuatu aligns itself with the statement delivered by Tonga on behalf of the Pacific Islands Forum members and adds the following in its national capacity. Vanuatu approaches confidence -building measures with a specific concern, coherence. The international community is, rightly, multiplying its channels of communication. The Global Points of Contact Directory under this mechanism, the 24 -7 network under the United Nations Convention against Cybercrime, long -standing third -to -third relationships and regional arrangements. Vanuatu participates in this expanding architecture and we support the Directory wholeheartedly. But we speak from the standpoint, of the administrations that must operate all of these channels at once, often through the same handful of officials. Our request to this mechanism is that the directory be developed in deliberate awareness of the wider ecosystem, clear guidance on which channels serves which purpose, consistency in points of contact where national structures allow it, and no duplication of what already functions elsewhere. elsewhere. Confidence is not built by the number of channels that exist, or the volume of requests within them, but by the certainty of what happens when one is used. Second, Vanuatu sees a dimension of confidence building that our own circumstances make vivid. When disaster strikes our islands, information flows between governments within hours. Offers of assistance, coordination of relief, verification of facts on the ground. That habit of rapid, trusted state -to -state communication in physical emergencies is precisely the habit the CPM agenda seeks to create for digital ones. and the two should reinforce each other. A region accustomed to cooperating through cyclones is well -placed to cooperate through cyber incidents, and Vanuatu will continue working with our Pacific partners to make that connection real in practice. Third, we emphasize transparency as a measure available to every state regardless of size. Vanuatu has sought to be open about our national arrangements, our legislative development, including our data protection and privacy bill, and our assessments of the threat environment. We encourage the structured exchange of such national information within this mechanism, not as a reporting burden, but as the routine feasibility that prevents misreading between states. Finally, Madam Chair, Measures on paper acquire meaning through practice. 1 .2 supports regular communications exercises for the directory, sustained training for designated officials with attention to continuity as personal change, and the preservation of hybrid modalities so that distance never determines who participates in building confidence. We look forward to the dedicated demographic groups in December carrying this pillar forward in exactly that practical register. I thank you.
—
Chile
Thank you. During the process of the Open -Ended Working Group 2021 -2025, the international community made significant progress in this regard, including the adoption of new global measures, the establishment of the Global Rules on Contact Points, the strengthening of the exchange of experience between states. Now it’s time for the global mechanism to consolidate its achievements and to decisively move towards effective implementation. In this regard, for Chile, confidence -building measures must be understood not only as a raft of political commitments, but also as practical tools that facilitate cooperation, that strengthen transparency, that reduce the risk of misunderstandings, and that contribute to preventing escalations derived from the use of ICTs. we therefore believe it is particularly important for the global mechanism to dedicate efforts to the exchange of national experiences in the implementation of these measures and including the functioning of contact points mechanisms for diplomatic and technical consultations and the voluntary exchange of information on incidents all of that’s very important for chile there is a lot of space to harness the experience that different regional organizations have in this regard also in this regard we believe that the exchange of good practices between regional mechanisms could make meaningful contributions to strengthening the implementation of the confidence building measures globally avoiding duplications and making the most of lessons learned in different contexts madam chair for chile the dedicated thematic groups offer up a valuable opportunity to go into further depth into discussions on the issue of international relations and the role of international organizations in the effective implementation of confidence -building measures. These groups in particular could be great spaces for exchanging national experiences and for exchanging good practices and engaging in measures to work towards cooperation to strengthen these measures in specific areas such as coordinated responses to cyber incidents. In our opinion, confidence -building measures are also a cross -cutting part of the framework for responsible state behaviour and are important for helping implement the other pillars. That’s why we believe that the global mechanism must continue to engage in substantive discussions focused on identifying new opportunities to strengthen the implementation of these measures, including those geared towards protecting critical infrastructure and essential services. given the growing impact of cyber incidents on our societies. Finally, Chile reiterates its commitment to continue to make commitments to strengthening this pillar and to working with all states to make headway in the effective implementation of the Framework for
—
Chair Egriselda López
The Chair thanks Chile and gives the floor to the Delegation of Israel.
—
Israel
Good morning, Chair. Good morning, Distinguished Delegates. Madam Chair, Israel aligns itself with the joint statement delivered by the Distinguished Representative of the Dominican Republic on behalf of the Cross -Regional Group of Confidence Builders and wishes to add some brief remarks from our own national perspective. Developing sustainable international cooperation requires a broad range of approaches and approaches, a solid foundation of trust, making confidence -building measures an indispensable pillar of this mechanism. CBMs allow states to build practical procedures during times of peace that can be directly utilized for de -escalation, communication and risk reduction during a geopolitical crisis Israel is proud to actively engage in the organization of global CBMs The global POC directory, Israel actively participated in the ping test and other activities under the national points of contact and we look forward to actively working with designated global POCs to turn this directory into a meaningful responsive tool for crisis communication The cross -regional collaboration together with an open cross -regional group of member states under the capable leadership of Germany Israel continues to brainstorm and advance practical voluntary CBMs suggestions to reduce the chances of strategic conflict and to address strategic misunderstandings on the multilateral engagement beyond the UN, Israel continues to contribute its national experience to regional and inter -regional bodies, including the OECD, Council of Europe, the OECD, in the framework of the Mediterranean Partnerships, as well as other formal and informal forums. The global mechanism work should prioritize harmonizing its work with other multilateral forums and regional forums and ensure that all outcomes are mutually reinforcing. Continuing to operationalize CBMs must be a priority for the global mechanism. CBMs hold great potential, in our view, for immediate positive impact and for generating beneficial momentum for the global mechanism. Accordingly, we believe that the DTGs must also prioritize further developing and operationalizing CBMs including those we and other delegates highlighted this week. Thank you.
—
Chair Egriselda López
Muchísimas gracias. Thank you very much. I give the floor now to the delegation of Côte d ‘Ivoire.
—
Côte d'Ivoire
Madame la Présidente. Madame Chair, in taking the floor for the first time, my delegation would like to extend to you its warm congratulations and we thank you for your leadership as you lead our work and you may remain assured of our full support. We endorse the statement delivered by Nigeria on behalf of the African Group and in our national capacity, we would like to offer the following comments on this agenda item. Madame Chair, Côte d ‘Ivoire considers confidence -building measures as an essential tool for prevention, cooperation, and for de -escalation in the area of information and communication technology. In cyberspace, uncertainty about the origin, the intention, or the scale of an incident can rapidly give rise to misunderstandings and it can stoke tensions among states. The lack of reliable communication channels can transform a technical incident into a political crisis. Confidence -building measures need to precisely allow us to prevent that from happening. My delegation welcomes in this regard the establishment of the global POC directory. We encourage all states to participate in that directory and to regularly update their information and to appoint as quickly as possible diplomatic and technical points of contact that are able to intervene rapidly in the event of an incident. My country also supports the elaboration of voluntary communications models. These tools must, however, remain agile. Thank you. easy to use and well adapted to emergency situations without imposing any procedures that might slow down exchanges. Madam Chair, my delegation would like to set out the following three recommendations. First, regularly organize under the auspices of the UN simulation exercises that bring together points of contact, national teams for responding to incidents, and relevant authorities. Second, strengthen CBMs at the regional and sub -regional level. In Africa, especially in West Africa, the growing interconnection of our economies, of our financial networks, and of our digital infrastructures call for mechanisms of cooperation that are more structured among states, CRETs, and regional organizations. Third, promote a culture of restraint and responsibility. Thank you. When incidents happen, states must prioritize consultations, the exchange of information, and a rigorous establishment of the facts while avoiding any premature accusations that might fuel escalation. At the national level, Cote d ‘Ivoire is developing permanent cooperation frameworks and frameworks for sharing information among officials for security in the area of information systems. We intend to deepen this work with our regional and international partners. For my delegation, trust is not something that can be declared by fiat. It is built by dialogue, transparency, predictability, and results -based cooperation. The global mechanism must become the
—
Chair Egriselda López
Now I give the floor to Ireland, followed by Tonga, Uruguay, Argentina, the Kingdom of the Netherlands and Botswana.
—
Ireland
Thank you, Madam Chair. Ireland aligns with the intervention made on behalf of the European Union and makes the following comments in our national capacity. The voluntary global confidence -building measures are valuable tools to enhance transparency and predictability, as well as to reduce the risk of misunderstanding, escalation and conflict. In this regard, there is a need to further develop and implement the CBMs and for further improvement of the functioning of States’ engagements with the POC Directory. As others have mentioned, the POC Directory should be used in good faith and as a complement to existing channels of communication between States. We are open to exploring further development of the POC Directory as we learn more from its use. In addition to the POC Directory, we also must move forward on implementation of the other CBMs including by sharing national ICT -related information. actions, exchanging experience on protecting critical infrastructure, promoting information exchange and cooperation and partnerships between states to strengthen ICT security capacity, and by organising regular seminars, workshops and training programmes on ICT security. Our exchanges, particularly in the DTGs, should include discussions on how confidence -building measures can be operationalised effectively, as well as building trust and confidence amongst states. In this regard, and as many earlier interventions on the CBMs have made clear, capacity building is an essential prerequisite for successful implementation of the CBMs for many states. It is also important to learn from the experience of regional organisations and engage with them as we move forward in this process. It must also be said that the expertise and experience of stakeholders from academia, the technical community, civil society and the private sector should also play a strong role in this process. practical tools, best practices and examples should feed our engagement and allow us to reflect the CBMs into our national and regional structures Madam Chair let me once again assure you of Ireland’s commitment to engaging with you and with the global mechanism to advance international security and stability for us all Thank you Madam Chair
—
Chair Egriselda López
Thank you I had read out the list of countries that were going to take the floor in this segment however I’ve been notified that Nigeria will be speaking on behalf of the African group so I’ll give Nigeria the floor right now to make that statement Thank you Sorry Madam Chair
—
NIgeria on behalf of African Group
Thank you I have the honour to speak on behalf of the African group on CBM The African group will affirm that confidence building measures the most important part of the CBMs and that the CBMs will be the most important part of the CBMs the most important part of the CBMs and that the CBMs will be are indispensable for fostering trust, transparency, predictability and cooperation among states, thereby contributing to international peace, security and stability in cyberspace. African experience in conflict prevention and security cooperation, including through the African peace and security architecture, demonstrates the value of sustained dialogue, effective communication channels and cooperative approaches to addressing shared security challenges. These principles are equally relevant to strengthening confidence and reducing the risk of misunderstanding and miscalculation in cyberspace. The group underscores the important role of regional and sub -regional organizations in advancing confidence -building, through dialogue, information sharing, cyber diplomacy and practical cooperation among member states. Strengthening synergies between regional and global initiatives will enhance coherence, inclusivity, and effective implementation of UN framework. Accordingly, the African group encourages the global mechanism to 1. Strengthen coordination and complementarity between global and regional confidence -building initiatives. 2. Promote linkages between regional point -of -contact networks and the Global Point of Contact Directory. Three, support regional cyber exercise, capacity building, and other practical cooperation activities. And lastly, encourage the voluntary exchange of national experiences, good practices, and lessons learned in implementing confidence building measures. I thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much. I give the floor to the delegation of Tonga.
—
Tonga
Madam Chair, Tonga aligns itself with the statement delivered by my colleague on behalf of the Pacific Islands Forum members and offers the following remarks in its national capacity. For the Kingdom of Tonga, our confidence -building measures are where the framework of responsible state behavior becomes most immediately rare. Small states do not maintain wide networks of diplomats tasked with cyber -related cooperation. When an incident strikes, trusted, predictable lines of communication between states are needed. Tonga therefore strongly supports the Global Points of Contact Directory as the flagship practical achievement of the OEWG, and we commend UNODA for its continued operationalization. In addition, Tonga is working to ensure our own participation in that directory is complete and complete. Thank you. Chair. Tonga has been building confidence in practice for a decade. CERT Tonga was established by cabinet decision in 2016 among the first national CERTs in the Pacific and has worked since then within the Pacific Cyber Security Operational Network where our regions, incident responders share information and build the personal trust on which crisis of cooperation depends. When our health system was attacked last year, established relationships with partners enabled rapid assistance and ultimately a joint public attribution with Australia and New Zealand. This is what confidence building measures look like when they work. Relationships built before the crisis. exercise during it and deepened after it Tonga accordingly encourages this mechanism to keep the CBM agenda modest in rhetoric and ambitious in practice a directory that works, point of context who are trained and exercised regional experience feeding global learning and hybrid participation so that officials from Nuku ‘alofa can engage
—
Chair Egriselda López
Thank you very much I give the floor now to the delegation of Uruguay who will be followed by Uruguay and then the Kingdom of the Netherlands Uruguay please
—
Uruguay
Thank you very much Madam Chair For Uruguay, CBMs are an essential tool to strengthen an international cooperation, reduce risks of escalation and improve prevention and responses to ICT security incidents, particularly those that affect critical infrastructure and critical information infrastructure. In this regard, we welcome progress made in the open -ended working group, in particular the development of the global directory of points of contact and the template for communication. Regional experience in the Organization of American States shows the practical value of CBNs. Since 2018, Uruguay has designated and updated its technical contact points in the framework of the OAS and is participating actively in cooperation mechanisms such as the CERT to the Americas, where we are promoting the exchange of technical information, including indicators, good practices, and strengthening of capacities of the states and the region. The experience of the OAS emphasizes the importance of combining the OAS and the U .S. transparency, communication between contact points, technical cooperation and dialogue with the private sector, academia and civil society and the technical community. Given that a significant part of critical information infrastructure are operated by non -governmental actors or are part of the supply chain, public -private partnerships are essential to strengthen prevention, early alerts, early warnings and fighting malicious information. In this regard we understand that this progress must serve as a basis to continue to operationalise CBM measures strengthening the capacities of all states and
—
Chair Egriselda López
The Chair thanks Uruguay, gives the floor to Argentina who will be followed by the Netherlands. Argentina thank you very much Madam Chair.
—
Argentina
My delegation aligns itself with the joint statement made by the Dominican Republic on behalf of a group of countries. who are building confidence and we wish to make this statement in our national capacity. CBMs are one of the most operational components of the framework for responsible state behaviour. This new step in the global mechanism consists precisely in introducing these measures to bring about more confidence and exchange between states. Argentina believes that CBMs should constitute a cross -cutting element running through all of the work of the two dedicated thematic groups. The nature of these provides us an opportunity to respond to the different mandates and to identify common challenges, to compile good practices and regional experiences, to establish early warnings and to adopt measures and recommendations that are focused on making the already agreed measures operational. for us, the DTG1 could be an appropriate framework to examine the operationalisation of CBMs by exchanging national experience and regional experiences developing practical guidance for their use, strengthening interoperability between existing global regional and sub -regional mechanisms and drafting recommendations on their use and early warnings on ICT incidents, in particular the ones that affect critical infrastructure. DTG2 in turn could contribute to identifying the capacities required in order to support this operationalisation effort, including proposals to strengthen the national capacities of the contact points, to promote voluntary exercises to facilitate the exchange of knowledge and experience between states and to support the development of the capacities required to effectively implement these measures, including participation in the global directory. And the global directory indeed could be used more effectively. Argentina underscores the points of contact directory, which is one of the most relevant milestones achieved in the open -ended working group. However, the success of this tool will not only depend on periodically carrying out connectivity tests or ping tests, but rather also states acquiring the confidence required to use it as an effective channel for communication when the circumstances require it. In this regard, we support continuing the voluntary exercises, gradually fine -tuning its modalities and exchanging experiences, that encourage its practical use. We believe that the global mechanism could benefit from the added experience in regional and sub -regional, at the regional and sub -regional levels. And in our region, we have the group within the OAS, as well as the cybersecurity working group of MERCOSUR, which are examples of good practice of exchange of information. And these can contribute to strengthening confidence between states and can offer up useful lessons learned for the future work of the global mechanism. Looking at the beginning of the DTGs, my delegation hopes that these spaces will establish themselves as spaces for technical work that are able to establish substantive recommendations and decisions on confidence -building measures, for the consideration of disciplinary. We trust that these recommendations will be able to be subsequently reviewed, fine -tuned and negotiated by states in the framework of the plenary deliberations during the CBM pillar. This will allow the plenary meetings of this global mechanism to progressively work towards more interactive dialogue and results -focused dialogue where states can focus on our efforts on building consensus on concrete proposals. In my delegation’s view, this dynamic will strengthen the operationalisation of CBMs, enabling us to translate the consensus reached into practical cooperation tools and concrete
—
Chair Egriselda López
will be followed by Botswana and Cuba. The Netherlands, please.
—
Netherlands
The Kingdom of the Netherlands aligns itself with a statement delivered by the European Union. Furthermore, we have supported a cross -regional statement as delivered by the Dominican Republic. Please allow me to make some further comments in my national capacity. In a world where threats are rapidly becoming more sophisticated and lines between state and non -state threats are increasingly blurred, building trust between parties has never been more relevant. The non -exhaustive list of voluntary CBMs, along with other established regional instruments, certainly has an important role to play in building trust between member states. Please allow me to make three comments on how the implementation of the CBMs aids building trust between member states. First, the Kingdom of the Netherlands believes that the implementation and use of CBMs should be well integrated in the work of the DTGs, where CBMs can be used as an effective lens to suggest pathways to build trust between states in the line of concrete cyber threats. In simulation exercises, we could for example see how public -private partnership could concretely benefit an open, free and secure cyberspace, and help prevent and address incidents taking place in cyberspace. In this manner, DTGs will offer the opportunity to discuss CBM operationalization. Secondly, with regards to the implementation of the POC directory, it is important to underline that the strength and added value are found in establishing lines of contact, where these previously were unavailable or unclear. We should look at it as a complementary tool to existing POC networks and channels of communication that already function appropriately, not as a replacement or a duplication. It is therefore that the voluntary nature of the instrument aids its functioning to strengthen and supplement existing Member States’ policies and initiatives. And finally, in line with CBM3, the Kingdom of the Netherlands encourages all Member States and regional organizations to continue to develop the national positions on how international law applies in cyberspace, and to make these views available to a wider public. By openly and clearly communicating on how we interpret international law in cyberspace, we avoid miscommunication. and miscalculation, leading to a more solid basis to establish trust over time. We recognize that not all states will have the resources available to embark on such an extensive procedure alone. The Kingdom of the Netherlands therefore stands ready to share its best practices with all member states who are in the process of developing their position. Madam Chair, the eight CBMs that we have established through the Open End Working Group provides us with a solid basis of continued efforts to break down the walls of misunderstanding that still exist between some of us. To make a success of the UN global mechanism means to adequately capitalize on this basis and ensure the full implementation of the instruments we so diligently designed. Thank you very much.
—
Chair Egriselda López
Thank you very much for your statement. Before I give the floor to… to the next speaker, I have been informed… that this is the last day for Ambassador Norman. And that’s really significant. It’s really significant of you serving as a special envoy for cyber issues of the Kingdom of the Netherlands. And your long journey in this mechanism is coming to an end. So I’d like to wish you all the best with the future. And I’d like to ask for a loud round of applause for the ambassador from the room, please. Thank you very much. Very well. Back to our list of speakers. I give the floor to Botswana, followed by Cuba and then Australia.
—
Botswana
Thank you, Madam Chair. The Republic of Botswana aligns itself with the statement of the African group as presented by the Federal Republic of Nigeria. We wish to make this statement in our national capacity. Chair, in an increasingly interconnected global landscape, confidence -building measures serve as an indispensable tool to foster transparency and build sustained trust among nations. For CBMs to deliver on their intent, the global mechanism must prioritize inclusive participation, ensure actionable implementation, and focus on the practical implementation of the normative framework for responsible state behavior in the cyberspace. Botswana views the effective implementation of global CBMs through a functional perspective that ties digital security directly to sustainable socioeconomic development and national resilience. Botswana knows that global transparency initiatives must be paired with concrete technical assistance. to address the digital divide. Furthermore, states should be leveraging the regional and sub -regional platforms to strengthen operational mechanisms, including direct set -to -set cooperation and critical infrastructure protection. This would provide the most effective pathway towards building global trust and incident response readiness the world over. Botswana continues to take steps to implement the voluntary CBMs nationally. Botswana has operationalized its national cybersecurity strategy and established the Botswana Computer Incidence Response Team under the Botswana Communications Regulatory Authority to coordinate incident management, issue threat advisories, and safeguard national critical infrastructure. To strengthen international crisis communications, Botswana has undertaken the development of a new system of designation and submission of national POCs across both diplomatic and technical levels to populate the POC directory. Over and above the already stated legislative and policy initiatives, Botswana intends to expand its contributions to global CBM implementation through concrete, actionable initiatives. Botswana engages in formal, bilateral, and sub -regional information sharing protocols among CERTs within the SADC region to improve real -time threat reporting and cross -border incident response. Additionally, Botswana participates as a continental partner under the African CERT umbrella to align its cyber defenses with the broader Pan -African threat sharing protocols and incident response metrics. Further, recent internal cybersecurity activities reflect the implementation of CBMs through the formal public -private partnerships, threat intelligence sharing, and academic collaboration. These initiatives focus on transparency, incident response, and security. These initiatives focus on response readiness and workforce upskilling to collaboratively ensure the security of Botswana’s critical infrastructure. The Botswana Communications Regulatory Authority has signed several memoranda of understanding with global cybersecurity firms and these partnerships deliver real -time intelligence on emerging threats and share best practices in cyber defense capabilities. Additionally, several academic institutions and industry players regularly host cybersecurity symposiums and thought leadership sessions to forge coordinated responses to cyber threats. In conclusion, Chair, the Botswana delegation continues to reiterate that discussions at this global mechanism should include pairing confidence -building measures with targeted technical assistance initiatives that ensure that nations are not left behind due to resource constraints. This approach directly supports member states in protecting their critical frameworks while bridging existing capability gaps. Thank you, Chair.
—
Cuba
Thank you Madam Chair Ensuring information exchange and dialogue on the use of ICTs and international security in the global mechanism is in itself a CBM We hope that all delegations will be able to continue to develop on these dialogues within this framework with mutual respect, constructively considering the diversity of positions and different understandings of each of the five pillars These type of measures are important as a complementary way of promoting cooperation and transparency as well as the exchange of good practices reducing the risk of conflicts and contributing to their peaceful settlement On a domestic level we have designated focal points to participate in the points of contact directory. And we call that the different phases for confidence building must respect sovereignty and the non -interference in the internal affairs of states. Confidence based on transparent and respectful exchange is important and respecting the rights of countries to establish in this sphere as well as in others bilateral cooperation, whatever bilateral cooperation that they believe is relevant. The establishment of binding norms within the framework of the UN and complying with them subsequently is one of the pillars for international confidence building is important. The voluntary nature of confidence building measures must prevail. Each region or sub -region has its unique characteristics, and that’s why the measures implemented at these levels cannot be considered single global models or benchmarks, closing the digital gap and ensuring universal, inclusive and non -discriminatory access to information and knowledge. through ICTs can contribute to building confidence. And this will help to achieve internet governance where states work in equal conditions to play their different roles and responsibilities in international public policy in this area. Another important confidence -building measure is for states to abstain from engaging in any unilateral coercive measure that impedes universal access to the benefits of ICTs. By way of conclusion, we reiterate that CBMs on their own do not guarantee the strictly peaceful use of ICTs. Rather, they are just
—
Chair Egriselda López
I give the floor to Australia who will be followed by the following five speakers. Ghana, Malawi, the Philippines, the Islamic Republic of Iran and Cameroon. Australia please.
—
Australia
Thank you Madam Chair. Australia aligns itself with the statement delivered by the Kingdom of Tonga on behalf of the Pacific Islands Forum members as well as by the Dominican Republic on behalf of the Cross Regional Confidence Builders Group and makes these additional remarks in our national capacity. Confidence building measures or CBMs are practical tools for reducing the risk of misinterpretation, escalation and conflict in cyberspace. They help states build relationships, establish procedures and create channels of communication before a crisis occurs so that these channels can be used effectively during and after cyber incidents. The global mechanism should focus on making the agreed CBMs operational in national, regional and global context. we should not simply continue describing CBMs in abstract terms. The task before us is to help states use them through capacity building, technical assistance, guidance, exercises and sustained engagement. This is particularly important for states and regions with more limited capacity where trusted relationships, clear communication pathways and practical cooperation can make a significant difference. The mechanism should support practical operation before, during and after cyber incidents. This includes incident management cooperation, mutual assistance and stronger channels between national authorities, CERTs and other relevant technical bodies. Regional arrangements, including initiatives such as Australia’s Cyber Rapid Assistance for Pacific Incidents and Disasters, or Cyber Rapid, program have an important role to play in building trust and habits of trust between states and regions. We need to have a process of cooperation before they are needed in a crisis. Discussions in the plenaries and DTGs should help connect these regional experiences, share lessons learned, and support states to develop communication procedures that are practical, reliable, and appropriate to their national circumstances. The Global Points of Contact Directory is an important achievement and a valuable confidence -building tool, but the directory must be used in a way that builds trust rather than straining it. It is voluntary, but not a replacement for diplomatic channels, regional mechanisms, public communications, state -to -state engagement, or other forms of information exchange. States should always remain free to engage through channels most appropriate to the circumstances. For the POC directory to remain useful, it should be actively maintained, regularly tested, and supported by clear expectations of good faith use. Requests through the directory should be proportionate, purposeful, and, as already mentioned by our regional neighbours, made with due regard. To the capacity constraints of smaller states. It should not be treated as a mechanism for overwhelming national points of contact, creating unreasonable expectations of response, or as a substitute for existing procedures where other channels are more appropriate. Used carefully and responsibly, the directory can help break down barriers and strengthen confidence between states. The global mechanism should also help states operationalize other practical CBMs that reduce risk and build resilience. This includes cooperation on vulnerability disclosure and mitigation, supply chain integrity, and national capacity building. For many states, the ability to participate meaningfully in CBMs depends on having the right technical, policy, and institutional foundations in place. Capacity building is not separate from confidence building. It enables states to use CBMs effectively, respond to incidents, share information, and engage with partners on a more equal footing. Australia also underlines the importance of stakeholder engagement here. Industry and the technical community, civil society and academia are often closest to vulnerabilities, incidents and emerging risks Their expertise can help states understand threats, improve prevention and response strengthen supply chain resilience and translate CBMs into practical action while preserving the intergovernmental nature of decision making Chair, Australia wants the global mechanism to be a forum where CBMs are implemented, exercised and improved over time This forum should support the reasonable use and maintenance of the POC directory including through regular communication checks and how the DTGs can help states operationalise CBMs in ways that are practical, voluntary and responsive to capacity
—
Chair Egriselda López
Thank you, I give the floor now to Ghana
—
Ghana
Thank you Chair Ghana aligns itself with a statement delivered by the Distinguished Minister of Nigeria on behalf of the African group and will deliver the statement in its national capacity. Ghana recognizes confidence -building measures as practical tools for strengthening trust, transparency, and cooperation among states. As cyber threats increasingly target critical information infrastructure, CBMs play an important role in enhancing communication, reducing misunderstandings, and supporting coordinated responses. Ghana welcomes the establishment of the global mechanism as an important platform for advancing dialogue cooperation and the practical implementation of confidence -building measures. It provides an opportunity to strengthen trust among states and promote collective action in addressing existing and emerging ICT threats. Drawing on international good practices and adapting them to regional realities ECOWAS has developed a regional framework on cyber ICT confidence -building measures with the participation of Ghana. The ECOWAS directive establishes practical mechanisms, including national diplomatic and technical points of contact and information -sharing arrangements that strengthen cooperation and contribute to regional resilience. Ghana also reaffirms its support for the continued implementation of the Global Points of Contact Directory as a voluntary mechanism that facilitates timely communication, cooperation and coordination among states in responding to ICT -related incidents. As tactile infrastructure becomes increasingly interconnected, no country can protect its communities. I’m not quite calling information infrastructure alone. Regional initiatives such as those of ECOWAS provide valuable experience that can inform the implementation of the global mechanism on confidence -building measures and strengthen international cooperation. The site event co -sponsored by the Dominican Republic Ghana in Germany highlighted how regional organizations’ implementation of CBMs provides a practical avenue for advancing the implementation of CBMs under the global mechanism. Madam Chair, Ghana remains committed to working with member states and all relevant stakeholders to support the operationalization of confidence -building measures. Thank you.
—
Malawi
I thank you for giving my delegation the floor. As previously highlighted by other member states, confidence -building measures remain among the most practical and effective means of strengthening international peace and security in the use of ICTs. By promoting transparency, predictability, and cooperation, they reduce misunderstandings and misperceptions, while fostering the trust necessary for timely communication and coordinated responses to cyber incidents. We welcome the broad convergence of views expressed during our discussions. We note the emphasis placed by several delegations, including the Dominican Republic, the European Union, and the statement delivered by Tonga on behalf of the Pacific Islands Forum. On operationalizing confidence -building measures, through the dedicated thematic groups, strengthening the point -of -contact directory, promoting regular communication, and conducting simulation exercises. We also share the views expressed by Costa Rica and Kiribati that confidence -building measures should remain practical and technical with trust being built through sustained cooperation and operational engagement For the Republic of Malawi, confidence -building measures are already reflected in our national practice Through the Malawi Computer Emergency Response Team we continue to strengthen trusted channels for information sharing, vulnerability coordination, incident response and technical cooperation with regional and international partners At the regional level, Malawi is proud to serve as the Vice Chair of the SADIC CICERT working alongside member states to strengthen trusted information sharing, coordinated incident response and regional cyber resilience Thank you We also actively engage with the Forum of Incident Response and Security Teams, the Africa CERT and the ITU recognizing that sustained cooperation remains fundamental to building confidence among states. Madam Chair, as this global mechanism advances its work, Malawi believes that dedicated thematic groups should focus on translating our commitment into practical action by strengthening the point -of -contact directory, promoting regular communication among national points of contact, supporting voluntary cyber exercises, facilitating exchanges of national experiences, and enhancing regional and international cooperation. Confidence is not built during a crisis. It is built beforehand through sustained cooperation, transparency, and trust. The Republic of Malawi remains committed to working with all member states to ensure that confidence -building measures are are practical, inclusive, and implementation-oriented, therefore contributing to a stable, secure, peaceful, and accessible ICT environment for all. I thank you, Chair.
—
Chair Egriselda López
Thank you very much. I give the floor to the Philippines.
—
Philippines
Madam Chair, confidence -building measures remain one of the most practical means of translating the agreed UN framework into concrete cooperation among member states. By strengthening transparency, timely communication, predictability and trust, they reduce the risk of misunderstanding and miscalculation while reinforcing the implementation of the broader framework for responsible state behavior in the use of ICTs. The Philippines strongly supports the operationalization of CBMs, particularly the continued operationalization of the Global Points of Contact Directory established on the ICT framework. under the UN framework. Regular engagement among POCs, simulation and tabletop exercises, voluntary testing of communication procedures, and exchanges of operational experience can improve preparedness and enhance timely communication during ICT -related incidents. Practical implementation of the initial list of voluntary global confidence -building measures should remain a priority for this mechanism. The Philippines emphasizes that capacity -building is indispensable for the effective implementation of confidence -building measures. Many member states continue to face institutional, technical, and resource constraints that affect their ability to operationalize national points of contact, participate in cyber exercises, exchange technical information, and respond effectively to ICT -related incidents. Continued support for demand -driven, nationally owned, and sustainable capacity building will therefore be foundational to confidence -building efforts across all regions. Madam Chair, regional organizations play an important role in translating CBMs into practical cooperation. As ASEAN Chair in 2026, the Philippines welcomed the progress in operationalizing the ASEAN Regional Cert, an important step toward raising the regional cybersecurity posture through timely information sharing, coordinated incident response, and exchange of best practices. Together with the implementation of the ASEAN Cybersecurity Cooperation Strategy 2026 -2030, this initiative reinforced trusted relationships among competent authorities, improved regional preparedness, and complemented the work of the global mechanism and provided a global framework for cooperation. We will provide valuable lessons that can inform the development and implementation of CBMs. The Philippines also believes that confidence -building can benefit the expertise and operational experience of relevant stakeholders from the private sector, industry, academia, and the technical community. Their practical insights can support their implementation, improve cyber resilience, and facilitate understanding of emerging technologies while fully respecting the state -led nature of this process. Madam Chair, ultimately, the success of confidence -building lies not in the number of measures we adopt, but in the trust, cooperation, and resilience they generate. The Philippines, therefore, remains committed to advancing practical implementation through improved communication, sustained CBMs, regional cooperation, and inclusive partnerships. Thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much. Now, I’d… Announced the other speakers. However, the Secretariat has told me that there’s going to be more speakers on behalf of… CARICOM, so I’m going to give CARICOM the floor now and then we’ll we’ll get back to our list of speakers. CARICOM, please. Microphone for the Bahamas, please. Go ahead.
—
Bahamas on behalf of the CARICOM
Madam Chair, I have the honor to deliver this statement on behalf of the 14-member state of the Caribbean community, CARICOM. CARICOM welcomes the establishment of the dedicated thematic group and recognize DTG2 on capacity building as a cornerstone of evolving framework for responsible state behavior in cyberspace. As a small island development state, CARICOM members are actively strengthening our national cybersecurity ecosystem through the development of institutional framework, technical experts, and national capabilities. The 2025 OAS IDB Cybersecurity Report, based on the Oxford Cybersecurity Capacity Majority Model, confirms both our progress and our challenges. The region has approved across all five dimensions of the model since 2020, yet persistent gaps in resources, workforce development, and cross-sector coordination continue to expose us to an increasingly complex threat environment. These findings underscore a central truth. Resilience cannot be achieved by individual states alone. Effective capacity. Capacity building requires sustained international, again, cooperation, coordination, and partnership. That responds to the needs and the priorities. of the recipient state. It is against this backdrop that CARICOM highlights three regional priorities. First, cyber law, modern legal and regulatory frameworks that enable our states to address cyber crime, protect data, and cooperate across borders. Second, sustained cyber capacity building that develop resilience, institution, technical expertise, and a skilled workforce. Third, critical infrastructure for small states. The challenge begins with the very ability to define, identify, and classify critical infrastructure. and extends to protecting it with limited resources. Targeted assistance in these areas would deliver the greatest impact to our region. CARICOM, therefore, supports capacity -building initiatives that are voluntary, demand -driven, sustainable, transparent, and based on national ownership, and is consistent with the principle endorsed by the Open Ending Working Group. Capacity -building is not a one -time activity, but a long -term investment that enables states to develop resilient institutions, strengthen technical expertise, establish effective legal and policy framework, and build a skilled cybersecurity workforce. Evidence -based tools such as cybersecurity capacity maturity model demonstrate the value of measuring maturity over time, allowing assistance to be made. And, of course, we have to be targeted where nationally defined needs are the greatest. Madam Chair, CARICOM also emphasizes that capacity -building efforts must remain accessible to all developing countries, particularly those whose unique circumstances and resources constraints may be limited in their ability to respond effectively to evolving ICT threats. Enhanced cooperation among member states, regional organizations, the UN nation system and other relevant stakeholders can promote the exchange of experts, best practice and technical assistance. Finally, Madam Chair, CARICOM welcomes ongoing efforts to enhance coordination and coherent amount existing capacity -building initiatives with a view to avoiding duplication, optimizing available resources and ensuring that assistance reached the most needed. We are also supporting the strengthening of mechanisms that force the dialogue between states seeking assistance and those able to provide it, in line with our nationally defined priorities. As we continue our work under the global mechanism, CARICOM remains committed to advancing focus, practical action -orientated discussions that translate shared principles into concrete support of member states. In this spirit, we look forward to contributing constructively to efforts that promote a more secure, resilient and
—
Chair Egriselda López
Thank you very much. I give the floor now to the Islamic Republic of Iran.
—
Islamic Republic of Iran
Madam Chair, the Islamic Republic of Iran has actively promoted CBM initiatives on a bilateral, regional and multilateral level. We have held consultations with a broad range of partners and we are expanding our bilateral cooperation in this field. At the regional level, these efforts have been advanced through the Shanghai Cooperation Organisation, BRICS Cooperation and various regional initiatives in the Middle East and the Persian Gulf. These initiatives constitute an important foundation for strengthening confidence and transparency and my delegation remains committed to further advancing such efforts. Madam Chair, Paragraph 47k of the Open -ended Working Group Final Report. reaffirms the importance of continuing discussions on the development and implementation of confidence -building measures within the global mechanism. In this context, states took note of a proposal for a new confidence -building measure aimed at facilitating access by all states to ICT security products and tools. My delegation considers that this proposal is particularly valuable. The OEWG has already recognized by consensus that capacity -building programs are an important confidence -building measure, since they provide an important avenue of collaboration that strengthens relationships, builds trust, and enhances confidence among states. Facilitating access to ICT security products and tools reflects precisely this understanding. The OEWG deliberately recognised that the five pillars are mutually reinforcing and complementary to one another. Some measures naturally have implications across more than one pillar and the proposal on access to ICT security products and tools is one such measure. It strengthens national capacities while simultaneously promoting cooperation, trust and confidence among states. In addition, paragraph 52 of the final report encourages states on a voluntary basis to continue to work together and to continue sharing their national views on technical ICT terms and terminology. and on the basis of this proposal my delegation believes that the global mechanism could take a practical step forward by preparing a consolidated list of technical terms used in the consensus -based reports of the OEWG and subsequently undertake discussions to develop common understandings of key concepts such as ICTs, ICT infrastructure, ICT environment and malicious use of ICTs. We therefore believe that these two proposals of new approaches for CBMs reflected in the final report of the OEWG should be considered by the first dedicated thematic group and be incorporated into the existing set of eight voluntary global confidence -building measures. Thank you very much.
—
Chair Egriselda López
Muchas gracias. Thank you very much. I give the floor now to Cameroon.
—
Cameroon
Madam Chair, we need to address crises and confidence -building measures can prevent them. That’s the fundamental value. No response can be based only on technical capacity. It is also based on transparency, dialogue, and ongoing cooperation among states. Confidence -building measures provide one of the most direct avenues for translating political commitments into practical cooperation. By promoting communication, predictability, and information exchange, CBMs contribute to reducing misunderstandings, preventing misperceptions, and lowering the risk of unintended escalations arising from the use of ICTs. For developing countries, CBMs are not merely diplomatic instruments. They are practical tools that enable more inclusive participation in the international ICT security framework. They complement capacity -building efforts by creating the trust and predictability of the ICTs. They are also the necessary for states to cooperate effectively, exchange information, and respond collectively to shared challenges. In this regard, Cameroon welcomes the establishment of the dedicated thematic group on confidence -building measures. We believe that this group should serve as an operational platform to strengthen cooperation, promote transparency, and support the effective implementation of the agreed CBMs. Madam Chair, Cameroon welcomes the progress achieved under this pillar, including the establishment of the Global Intergovernmental Points of Contact Directory and the eight voluntary global confidence -building measures agreed upon in the second annual progress report. These achievements represent important milestones. However, their value will ultimately depend on their effective implementation. A mechanism is only effective when states have the capacity and confidence to use it. In this spirit, Cameroon wishes to propose three priorities. Firstly, strengthen the operational effectiveness of the global POC directory The directory should continue to evolve from a repository of contacts into a dynamic instrument for cooperation Its functionalities could be progressively enhanced to facilitate secure communication, voluntary information exchange consultations among points of contacts and the sharing of good practices Over time, it should contribute to building a genuine community of practice among points of contact Secondly, promoting regional and cross -regional cooperation The global mechanism should facilitate exchanges of experience among member states and regional organizations through workshops and knowledge -sharing initiatives Regional experiences, including those from Africa who can provide valuable lessons and contribute to strengthening global cooperation while avoiding duplication And lastly, supporting the practical implementation of CBN’s The European Commission’s The global mechanism should encourage voluntary implementation guidance, practical communication tools, and capacity -building activities adapted to national circumstances, continued dialogue on relationships between CBNs, international law, and the other pillars of the framework which can further enhance transparency and predictability among states. Madam President, Madam Chair, at a time in which the digital world is becoming even more interconnected, responding to crises requires us to adopt the necessary measures, and CBNs really are an investment in the future. They develop cooperation habits, they strengthen institutional links, and they prepare states to act collectively in response to emerging challenges. For Cameroon, the success of the DTGs is a confidence building measure, given its capacity to bring states together to strengthen exchanges and to enable a lasting cultural cooperation in cyberspace to emerge. This approach is in line with the entrenched African conviction that collective security is based on the contribution of one and all, and it ensures the capacity of the international community to advance together in a spirit of solidarity and shared responsibility. Cameroon stands ready to work with all delegations so that the pillars of the CBMs can become a true instrument for practical cooperation, contributing to a more predictable,
—
Chair Egriselda López
Thank you very much. I’ll read the next five speakers. First, we have Norway, Thailand, Malaysia, the Russian Federation, and then North Macedonia. Norway, you have the floor.
—
Norway
Thank you, Chair. Since this is the first time we’re taking the floor, we would like to congratulate you on the appointment and commend the Chair for the strong and clear leadership that you have shown for and the guidance that provided for this session. Let me also express our appreciation for the support given by the Secretariat in this regard. Norway aligns itself with the statement delivered by the European Union. We would also like to make the following remarks in a national capacity. There is no doubt that the cyber threat landscape is evolving rapidly. Technology moves faster than policy, and it challenges our ability to have the best response. As we move from the open and the working group to the G7, confidence -building measures have an important role to play in making the framework for responsible state behavior operational. but you wanted to share three points with you in this regard first, CBMs provide practical tools for implementing our agreed commitments mechanisms such as point of contact, dialogue, sharing of best practices and information sharing help reduce risk prevent misunderstandings and contribute to stability and security in cyberspace second, CBMs enable practical cooperation between states they create opportunity to exchange experiences share best practices and strengthen implementation of the framework including with regard to resilience incident response and protection of critical infrastructure third, effective implementation requires capacity and broad participation including through the inclusion of women capacity building and confidence building are mutually reinforcing and we should continue to draw on the expertise of stakeholders including industry, academia, the technology the technical community and civil society to support implementation and strengthen cyber resilience globally Norway therefore echoes the concerns being raised with regards to the objection of the majority of stakeholders that applied within the procedure for Norway the priorities is therefore to elaborate and strengthen implementations of the CBMs we have already agreed on CBMs are practical means of translating the UN framework into concrete action building trust, enhancing resilience and contributing to international peace and security Norway looks forward to further this work in the D2Ds Thank you Madam
—
Chair Egriselda López
Chair Muchisimas gracias Thank you very much I give the floor to Thailand.
—
Thailand
Thailand fully supports continual exchanges of views in the global mechanism on developing and implementing CBMs and sharing of national views to enhance transparency and mutual understanding among states Thailand supports the implementation of the 8 CBMs adopted in the OEWG 2024 Annual Progress Report as essential tools for mitigating ICT related threats and reducing tension and reducing misunderstandings and miscalculations as well as the Global Point of Contact Directory as a concrete contribution by the OEWG to build trust and confidence among states. Thailand emphasizes the importance of strengthening capacity -building efforts for POCs, which enhances close coordination amongst them and encourages exchange of best practices between global and regional POCs to ensure effective and seamless response to cybersecurity challenges. Thailand considers the Template for Communication example provided by the Secretariat pursuant to A79 -14 as a useful tool to facilitate communication and assistance among POCs. We suggest incorporating elements such as urgency and confidentiality to better reflect operational needs particularly in time -sensitive or critical situations. we also reaffirmed the importance of flexibility for contact, particularly during emergencies. Thailand supports the role of regional bodies in implementing CBMs and see great importance of cross -regional cooperation in exchanging information and good practices to strengthen collective regional cybersecurity. Last, Thailand also considers the substantive dialogue within the OEWG and the ongoing discussion in the global mechanism to be constructive CBM in themselves and recognizes the vital role of the UN in supporting the global implementation of
—
Chair Egriselda López
Thank you very much. I give the floor to Malaysia.
—
Malaysia
Thank you. Madam Chair, Malaysia agrees that confidence -building measures remain an important pillar of the UN framework. As the cyber threat landscape continues to evolve and our reliance on ICTs grows, the value of CBMs in building trust and reduce the risk of misunderstanding among states becomes even more important. Having agreed on a strong set of CBMs through previous UN processes, our priority now should be to support their practical implementation. In this regard, DTG can provide a platform for states to exchange implementation experiences, practical challenges and lesson learned. It should also leverage on regional experiences, recognising that regional mechanisms have accumulated valuable practical expertise in implementing CBMs. Regional initiatives such as the ASEAN Regional Forum Points of Contact Directory demonstrate how regional efforts can complement the implementation of CBMs. We encourage continued cross -regional exchanges through this DTG to further share practical experiences, and lesson learned. Madam Chair, as many delegations have highlighted, effective implementation of agreed CBMs requires States to have the necessary capacities, knowledge and resources to translate commitments into practical actions. Thank you, Chair. Thank you, Chair. In this regard, Malaysia sees DTG as an important platform for turning agreed confidence -building measures into practical action. By identifying state capacity -building needs and facilitating access to relevant expertise and support, DTG can help ensure that capacity -building efforts are responsive to national needs and strengthen the implementation of the agreed CBMs. Madam Chair, Malaysia welcomes the continued operationalisation of the UN Global Intergovernmental Points of Contact Directory and supports UNODEL’s ongoing effort to ensure that it remains practical and operational. As cyber incidents continue to evolve in scale and complexity, timely communication between states becomes increasingly important. We therefore support regular communication checks, simulation exercises and continued engagement to ensure that directory remains effective. when it is needed the most. Ultimately, we hope that our discussion will lead to practical outcomes. Malaysia looks forward to work with all delegations to ensure that our agreed CBMs are not only agreed upon, but
—
Chair Egriselda López
Thank you very much. I give the floor now to the Russian Federation.
—
Russian Federation
Madam Chair, we are convinced, and this view is shared by the majority of member states, that the main practical outcome of the work of the Open Internet Working Group has been the establishment on Russia’s initiative of the Global Intergovernmental Points of Contact Directory. This was a consensus -based decision, and it enabled the implementation of the first universal competence -building measure in the first year of the European Union. in the field of international information security, establishing a mechanism for preventing interstate… conflicts in the information space through exchanging information and identifying sources of malicious activity in the digital environment. Crucially, the POC director is designed to foster professional non -politicized contacts between specialists from member states as an alternative to the pernicious practice of making political attributions of unsubstantiated political attributions of computer attacks. By now, 125 states have joined the directory. That’s a positive indicator, but we urge all remaining member states to join the directory by designating appropriate diplomatic and technical points of contact. We extend our appreciation to the United Nations Office for Disarmament Affairs for its sincere efforts to operationalize the POC directory, including through regular pink tests, exercises, and briefings. We also acknowledge the contribution of the UN Institute for Disarmament Research in raising awareness among developing countries of the goals and objectives of the POC directory by organizing, with the support of my country, a series of thematic seminars in 2025. It should be acknowledged that, as it is currently in its initial stages, the directory faces a number of challenges. I’ll give you some statistics about the Russian POCs for last year. There were 2 ,576 inquiries. Out of those, around 48 % of them were responded to. That’s due to a number of reasons. First and foremost, this is due to what we call dead contacts and a misinterpretation of the objectives of technical POCs when designated authorized bodies to the directory. Organizations, instead of national technical response teams, organizations or individuals who are not authorized to engage in specialized cooperation are designated to the directory, who are unable to ensure the continuity of the POC. This is due to the continuous availability of the POC. of technical POCs, which produces problems in processing requests from other states. Obviously, we also encounter cases where certain capitals simply ignore our requests for political reasons. Incidentally, that applies specifically to those countries that make unsubstantiated accusations regarding the supposed involvement of other states in various computer attacks. These issues can and should be addressed within the global mechanism, which is assuming oversight of the POC directory. The priority task is to finalize a standardized communication template. That step will simplify cooperation between POCs by clearly defining the information needed for the analysis of attacks and incidents. Colleagues from the UNODA have presented relevant considerations last year, but there wasn’t enough time. for a substantive discussion during the approval process for the OEWG’s final report. Our position is that the draft could serve as a basis for a communications template between diplomatic POCs, but precise technical data is required for the needs of technical POCs. We’re ready to join the discussion, and Russia has specific drafts in this regard. In our view, we need to resolve the issue of dead contacts by notifying states of the results of ping tests. What is also needed is something envisaged in the final report of the OEWG, the in -person meetings of representatives of POCs. We plan to contribute to the development of the POC directory by practicing POC’s interaction under the Russian Capacity Building Initiative, which I’ll introduce under the relevant agenda item. We’re convinced that discussions on the full gamut of issues having to do with the POC directory, that such discussions must be organized immediately, conducted with the participation of absolutely all states, and on the principle of consensus. call upon the Chair to include a separate item in the Global Mechanisms Program of Work for discussing issues related to supporting the work and improving
—
Chair Egriselda López
Thank you very much. I give the floor to the Delegation of North Macedonia.
—
North Macedonia
Madam Chair, North Macedonia aligns itself with the statement delivered by the European Union on this agenda item and in our national capacity would like to add additional remarks. Confident building measures are among the most valuable outcomes of the OEWG process. They demonstrate that even in a complex and rapidly evolving cyber environment, states can agree on practical measures and strengthen trust, improve communication, and contribute to international peace and security. From my country, confident building measures are practical tools. that help reduce misunderstanding, straighten cooperation, and lower the risk of unintended escalation practically during significant ICT incidents when timely communication between states is essential. Coming from a region where cooperation and dialogue have been essential for building confidence, we have seen the value of regular communication, information sharing, and practical cooperation. Trusted relationships developed over time become especially valuable when quick coordination is needed. This experience reinforces our belief that regional and global efforts should complement one another. As we move from agreeing on these measures to implementing them, our focus should be on making them work in practice. We also welcome the continued development of the Global Point of Contact Directory as an important practical tool for timely communication and coordination among states. We look forward to seeing confident building measures reflecting in the work of the thematic groups through the sharing of national experience, practical implementation approaches and good practices, while avoiding duplication of discussions taking place in the plenary session. Such exchanges can help translate our common commitment into effective action. North Macedonia remains committed to work with all partners to future straightening trust, transparency and stability in cyberspace.
—
Chair Egriselda López
Thank you very much. Let me just read the next five speakers. We have Tuvalu, Germany, Mozambique, the DRC and the Dominican Republic. Tuvalu. You have the floor.
—
Tuvalu
Madam Chair, Tuvalu Online itself is the statement delivered by the Kingdom of Tonga on behalf of the Pacific Islands Forum. As a Pacific Ocean State, our approach to regional security is firmly anchored in the Boyd Declaration. The Declaration guides us to look at security in a comprehensive way, integrating human well-being, climate resilience, and digital sovereignty. For Tuvalu, cybersecurity is not just a theoretical concern. It is fundamental to our development as a digital nation. Through our tobacco subsidy cable, we are establishing the infrastructure that connects our islands to the global community. Protecting this digital lifeline is, therefore, a core national priority. However, this lifeline requires a robust security posture to match. We are breaching the gap between policy and practice by finalizing our computer crime and cybercrime bill and laying the foundational groundwork for our national search. Third, for a small island developing state, this transition is complex. It requires moving beyond general dialogue to actionable technical support. As a practical contribution to this global effort, I am pleased to announce that Tuvalu will host a 19th Asia -Pacific Telecommunication Policy and Regulation Forum from 4th to 6th August this year. We view this forum as a technology, and a sensible confidence -building measure in itself. a platform for the transparency, information exchange, and capacity building that this mechanism advocates for. We see the three clear areas where this global mechanism can help us move from dialogue to implementation. First, we must operationalize the global intergovernmental points of contact directory. For states currently building their technical capacity, this directory is vital, we need this tool to prioritize the incident notification protocol, allowing us to integrate into regional security network and enable a reciprocal exchange of threat intelligence. Second, we need to focus on capacity sovereignty. International cooperation must shift away from short -term external consulting and towards a tangible. Long -term training of our own local technical teams, true confidence is established where every state, regardless of its size, possesses the sovereign ability to manage its own digital system independently. Finally, there is the issue of critical assets protection. Our developer subsidy cable is a vital digital artery for Tuvalu. We urge this mechanism to establish clear international guidance for the protection of subsea infrastructure. We seek an explicit CBM, a commitment from all member states and stakeholders to share best practice to safeguard this essential digital lifeline from both natural hazard and malicious cyber threats. Madam Chair, Tuvalu is doing the heavy lifting at home. We are building the laws and the frameworks of our institutions. We invite this mechanism to provide the practical operational framework that supports these efforts, ensuring that no Pacific Ocean state is left behind. I thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much I give the floor to the delegation of Germany
—
Germany
Thank you Madam Chair Germany aligns itself with the statement of the EU and of the informal open trust regional group of confidence builders and we will make the following remarks in our national capacity Confidence building measures are action oriented voluntary cyber diplomacy tools at the discretion of states that can help reduce tensions and the risk of miscalculation The last open ended working group has established eight global confidence building measures building on the work of the informal open trust regional group of confidence builders It is our view that now we should dedicate our resources to build a common understanding and identify best practices in their implementation The global mechanism, especially the DTGs provide an opportunity to develop ways to operationalize this key pillar of the framework in a practical way and can act as a forum for trust regional learning Thank you I’d like to echo Ghana’s remarks on the side event Ghana, the Dominican Republic and Germany co -hosted yesterday on regional best practices for the implementation of CBMs. It highlighted the practical, concrete value that confidence -building measures can add in solving real -world policy challenges. It also underlined the value of cross -regional exchanges, partnerships and capacity building for CBM implementation. It is clear that CBMs cannot be considered in isolation of other pillars. The exercise of confidence -building measures requires capacity building to enable all states meaningful and inclusive participation in their implementation. Germany attaches great value to the implementation of confidence -building measures that are tailored to the regional context and needs. Through our regional partnerships, we are working together in our exchanging experiences with different regional organizations in the development, adoption and implementation of CBMs. For example, over the past years, Germany has worked closely together with ECOWAS member states in the ECOWAS Commission in their journey towards the adoption of a first set of CBMs in Africa. Germany has been a consistent supporter of discussing and adopting CBMs that are concrete, action -oriented and voluntary in nature, that build on consensus and that are focused on building transparency, cooperation and stability between states. At a minimum, any CBM existing or re -proposed should fulfill these criteria and avoid entering the field of expectations or even obligations. Finally, a few remarks on the POC directory. It is designed as a voluntary practical tool at the discretion of states. In addition and in complementarity to it, there are established channels such as FIRST, the network of certs, search -to -cert or law enforcement cooperation, as well as relevant and existing regional, POC networks in accordance with their respective specific setups. These are practical and tested channels and the POC network is not intended to and in our view should not replace those channels Neither should it replace other diplomatic channels that are appropriate to address strategic security concerns It has however great potential and in our view that is the main purpose of the directory to facilitate the voluntary coordination and communication between states and to enhance cooperation and build mutual trust on the basis of good faith engagement Germany is and has always been open to engaging in a good faith spirit in the directory Our Federal Foreign Office serves as the diplomatic POC Germany’s Cyber Security Agency serves as the technical POC We reported last year that we have received repetitive, identical messages from a certain state to which we have initially replied in good faith Our Cyber Security Agency confirmed, received and recommended an appropriate course of action involving a second authority to address the content of the request However, despite these indications, our technical POC continued receiving repeated identical requests from the same sender, whilst not taking into account our replies. This is clearly not in line with the purpose of the UN POC directory and does not present a responsible or sincere use of the directory. Germany continues to engage with all interested parties on good faith requests through the POC directory and also
—
Chair Egriselda López
Thank you very much. I give the floor to Mozambique.
—
Mozambique
Madam Chair, Mozambique aligns itself with the statement delivered by Nigeria on behalf of the African group and wishes to convey the following remarks in its national capacity. Mozambique considers confidence -building measures to be one of the most practical pillars of the global mechanism. For developing countries, Confidence -building measures should move beyond political commitments and translate into concrete mechanisms that strengthen confidence, reduce the risk of misunderstanding and miscalculation, and improve collective resilience against cyber threats. Mozambique, therefore, supports the development of practical confidence -building measures, including strengthened cooperation among national CSRTs, effective point -of -contact, voluntary information sharing, joint cyber exercises, early warning mechanisms, and regular exchange of good practices. These measures should be implemented in a manner that respects national sovereignty, national priorities, and different levels of capacity. Mozambique encourages the mechanism to facilitate cooperation across the global, regional, and national levels, ensuring that confidence -building measures remain practical, inclusive, and accessible to all states, particularly developing countries. Ultimately, effective confidence -building measures are essential instruments for preventing conflict, enhancing transparency, promoting stability, and strengthening international peace and security in cyberspace. Madam Chair, confidence cannot be declared. It must be earned through consistent cooperation. Mozambique stands ready to work with all member states to make confidence -building measures a practical reality that strengthens peace, security, and stability in cyberspace. Thank you very much.
—
Democratic Republic of Congo
Thank you. rapid developments, trust among states is indispensable to international cooperation that is effective. My delegation believes that confidence -building measures must be enacted in a practical, transparent, and inclusive manner, taking account of the priorities of every state. Eight, this must ensure a climate of predictability, dialogue, and comprehension. In this regard, my delegation encourages the strengthening of communications mechanisms among states, and we welcome the establishment and the effective implementation of the global POC directory. Such a mechanism will facilitate the exchange of information and the rapid management of information. of cyber incidents, and they will curb the risk of escalation, resulting from a misinterpretation or a lack of communications. Madam Chair, my delegation also supports the development of the voluntary cyber simulations and capacity building as well, aiming to improve the preparation of states to cybersecurity incidents. These incidents foster the sharing of best practices, but also the development of common framework and competence building measures to ensure the success of these measures. That will depend on how the different participants take ownership of them to ensure this effectiveness and inclusivity. My delegation joins the call sounded by Columbia in Mexico to promote multilingualism. Multilingualism is a guarantor of inclusivity. And spaces for negotiation. And it has ensured the effective participation by everyone and the best results in the involvement of everyone. My delegation also encourages states to share on a voluntary basis their national experience in terms of cybersecurity. strategy, the protection of essential infrastructure, risk management, and response to incidents. When we can foster mutual trust and understanding among states, the DRC also underscores the importance of regional cooperation. Regional and sub -regional organizations play a decisive role in the implementation of CBMs by facilitating the sharing of experience, coordinating responses to threats, developing capacity that is in line with local realities. In Africa, the AU initiatives and sub -regional initiatives are the invaluable framework which needs to be strengthened and aligned with global efforts. The Democratic Republic of the Congo remains convinced that CBMs need to be tightly linked to other measures. They will be more effective when they are coupled with sound national capacity and the international community. norms of responsible behavior by states and in line with international law and with strengthened operational capacity. Finally, my delegation believes that the global permanent mechanism is a unique opportunity to promote and evaluate regularly CBMs and which CBMs are the most effective to meet the needs of all states, in particular developing states. The Democratic Republic of the Congo reaffirms its commitment to actively contribute to the development and the implementation of CBMs and fostering cooperation, stability, and preserving a cyberspace that is open, secure, safe, stable, and peaceful. Thank you.
—
Chair Egriselda López
Thank you very much. Now I give the floor to the Dominican Republic, followed by Bosnia Herzegovina, the African Union. and the Organisation for Security and Co -operation in Europe. And with these speakers, that will bring us to the end of this agenda item. The DR, please.
—
Dominican Republic
Thank you very much, Madam Chair. The Dominican Republic reiterates the fact that we align ourselves with the joint statement delivered by our delegation yesterday on behalf of our regional group. In our national capacity, we would like to expand on some of the concrete thoughts shared on confidence -building measures. As chair of the working group on CBMs in cyberspace of the Organisation of American States during the 2024 to 2025 session and as members of this same group since it was created in 2020, we have seen from experience and we have closely followed the establishment of a regional framework of CBMs and the full recognition of what has worked as well as what hasn’t worked. The challenge is no longer a normative one, it’s a practical one because global CBMs benefit from very broad political backing we’re aware of that. However, what is lacking is translating these CBMs into established capacities. In practice, for example from other directories we’ve learnt that a designated contact point on paper is not the same as a designated focal point that is in a position to respond 24 hours a day, 365 days of the year while it’s true that the global directory of points of contact has periodic exercises, verification exercises and ping tests the metrics, response metrics for us should be shared because this transparency would reflect number one the real results of implementation and two the real commitment of each and every one of the parties when it comes to ransomware against essential public services in our region just a few years ago we saw something that must be recognised frankly and that is that CBMs are preventive diplomacy tools, they’re tools of preventive diplomacy they are not necessarily mechanisms that are actionable in real time to respond to incidents and what this crisis in that state taught us was that bilateral technical direct cooperation was key. Without a doubt, CBMs helped to boost confidence and trust in order to engage and host technical assistance and act rapidly. That was significant and there was the establishment of the common scale on the severity of incidents and that allows all members to be able to understand and recognise just how serious the incident that another member state is dealing with is. Another important thing is the way this framework on the CBMs was established. measuring severity can help us to prioritize and scale cooperation between national CERTs. No CBM can be implemented in a void. In order to do that, we require a national mechanism and practical measures to be able to turn these tools into regulations and achieve institutional continuity when we have staff turnover. And this is particularly relevant in Latin American countries like ours. So we would be grateful if we could recognize in every state these regional CBM and specialized and technical assistance measures such as the Cyber Security Center for Latin America in the Caribbean that currently has its headquarters in Santo Domingo in the Dominican Republic. That is an example of how point -to -point cooperation can sustain capacity building. Just to wrap up now, Madam Chair, we would like to reiterate the fact that we stand ready to share our regional experience with the global mechanism, and this including through the working document of the confidence builders that we prepared upstream from the December session, so with the December session in mind. This global mechanism, and this is the last thing I’m going to say, makes it clear that states can’t build their capacities from zero, but rather they need to work through the regional mechanisms that already work, promoting in turn the efficient and effective use of resources, the limited resources that states have available to them. Thank you very much, Madam Chair.
—
Chair Egriselda López
Thank you very much, says the Chair, and I give the floor to Bosnia and Herzegovina.
—
Bosnia and Herzegovina
Thank you. Thank you Madam Chair While we align with the statement of the European Union I would like to add some comments in my national capacity Confidence building measures are essential to reducing the risk of misunderstandings and conflicts in cyberspace Mindful of their vital role we strongly believe that the work of the global mechanism should focus on raising awareness of CBMs at national, regional and global levels drawing in particular on the experiences and practices of regional organizations in this field By offering valuable lessons and tested approaches regional organizations play an important role in enhancing transparency, predictability and cooperation among states At this juncture allow me to highlight that Bosnia and Herzegovina has, over the past years increased its engagement in regular regional and cross -regional exchanges of experiences and good practices including within Western Balkans, the Organization for Security and Cooperation in Europe, as well as with the European Union. Starting from our own region, we attach particular importance to strengthening joint efforts and mutual trust. In this spirit, we actively engage in initiatives such as the Berlin Process. A key milestone in this regard was the launch of the Western Balkan Cyber Diplomacy Network in 2025, an initiative supported by the German Federal Foreign Office. The network represents yet another example of the region’s shared commitment to addressing cross -border cyber challenges through dialogue and cooperation. Madam Chair, because cyber challenges are inherent, they are completely borderless. Bosnia and Herzegovina will continue to engage in constructive manner and contribute with its utmost capacities to advancing the effective implementation of confidence -building measures. I thank you.
—
Chair Egriselda López
Thank you very much. I give the floor to the African Union.
—
African Union Commission
Thank you, Madam President. Thank you, Madam Chair. The African Union Commission endorses the statement of the African Group, and we would like to provide more information on what the African Union is currently doing in terms of confidence -building measures. From the State Department, I would like to thank the African Union for its support. From the standpoint of the Commission of the African Union, of the African position, the common African position, On the application of international law to cyberspace, that position reaffirms the importance of the peaceful settlement of disputes in cyberspace. That priority guides our action. In this regard, confidence -building measures are an essential pillar of our efforts, seeking to strengthen cybersecurity and build digital trust and promote cooperation regionally and internationally. In this regard, the Continental Framework of the African Union offers a sound basis for fostering cooperation, sharing, training, and strengthening collective resilience among member states, in particular in the context of the peace and security architecture. It is our conviction that trust cannot be established by responding urgently to a crisis. It needs to be built beforehand so as to prevent conflicts and to cultivate trust in the long term, including when there are disagreements. In this spirit, the African Union Commission has committed to a thinking about measures the continent could take adapted to the regional realities of the continent. This process draws on experience gained in economic and regional committees, in particular ECOWAS, and it also draws on best practices developed by other international organizations. We have an ambition, and it’s not to reproduce existing models, and it’s not to multiply the number of confidence -building measures. Our ambition is to set out concrete, adapted measures adapted to African realities, measures that can be effectively implemented. in the various regions of our continent. A way of conclusion, we would like to set out three recommendations for the global mechanism to allow that mechanism to support and strengthen the work done by the African Union. First, institutionalize a technical and regular dialogue between the global mechanism and regional organizations. Second, strengthen support provided to regional organizations for the development and the implementation of CBMs. Third, and finally, facilitate the integration of the regional points of contact with the global POC directory. I thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much. Okay. We’ll give the floor to the Organization for Security and Cooperation in Europe, the OSCE, please.
—
OSCE
Thank you Madam Chair for giving me the floor and since it’s the first time I’m speaking I would like to congratulate you for your appointment to chair the global mechanism. Many delegations have mentioned the work done by regional organizations on CBM so please allow me to share some experiences from one of these regional organizations. I will present a shortened version but will share in writing the more detailed statement. The Organization for Security and Cooperation in Europe was the first regional organization to develop cyber confidence building measures and has many years of experience in the practical implementation of its 16 CBMs. The OSC has started to work on CBMs in the early 2010s on the initiative of some members of the GGE with the objective to complement the work in the United Nations. How does the OSC implement the CBMs? First and foremost, the OSC is a global organization that is committed to the security and co-operation The OSC is the first international organization to develop cyber confidence building measures The OSC is the first international organization to develop cyber confidence building measures The OSC is the first international organization to develop cyber confidence building measures The OSC is the first international organization to develop cyber confidence building measures and has many years of experience in the field of cyber confidence building. OSC participating states have committed to regularly give updates on how they are implementing the CBMs on national level In practice, this is done in the informal working group on cyber the format to discuss cyber ICT security within the OSC meeting four times a year Another form of implementation is the Adopt-a-CBM initiative when one state or group of states is championing the implementation of a specific CBM To this date, 26 OSC participating states have adopted nine CBMs and significantly contributed to the meaningful implementation of those CBMs A third form of implementation is capacity building activities namely trainings and workshops delivered by the Secretariat These events usually involve a scenario-based exercise which helps understanding the practical application of the CBMs and the CBMs’ ability to implement the CBMs and is usually well received by the participants The regional work on CBMs is not done in isolation but also in connection with the UN-level discussions. Last month, the OSCE held the sixth annual meeting of Technical and Policy Point of Contact, nominated in line with OSCE CBM No. 8 in Vienna. This year, we discussed, amongst others, the global mechanism, with the aim of raising awareness on this first. substantive session. I would like to express my gratitude to Ms. Julia Rodriguez of the chairs team and Ms. Catherine Priceman of UNODA for their valuable contributions to our meeting. The latter brings me to the last point I would like to mention, namely inter -regional cooperation and the role of regional organizations in implementing the framework of responsible state behavior in cyberspace. The OSCE Secretariat has been advocating for the cooperation between regional organizations on cyber issues since a decade. The role regional organizations play in implementing the UN -level recommendations has been highlighted in the GG and OEWG reports. I would like to recall a non -paper on inter -regional cooperation and the role of regional organizations, which was submitted by Switzerland to the second open -ended working group in June 2024. And also mentioned yesterday by the Swiss representative in his intervention. The non -paper was prepared with contributions by seven regional organizations, giving a brief snapshot of what their contributions to the implementation of the UN framework is, as well as recommendations how regional organizations could contribute to future discussions. In conclusion, I would like to reiterate the OSCE Secretary’s continued readiness and availability to share its regional experiences and lessons learned. Thank you.
—
Chair Egriselda López
Thank you very much. Very well. Before we move on to the next agenda item, I’d like to just recall the following, established in Annex 1 of A8257. And I’ll just quote, accredited parties can attend, and the sub -entrepreneurial sessions and the… regional mechanisms and make oral statements during the dedicated sessions for stakeholders. They can also make oral statements after states if time is available and at the discretion of the chair. This is the case for review conferences and substantive plenary sessions. According to these modalities and in a spirit of compromise with the interested stakeholders who have a lot of experience in this area I’d like to open the floor now for accredited entities precisely on this agenda item, CBMs. And the floor will be given to them with a strict limit of three minutes each. I
—
DMUN Foundation
Thank you, Madam Chair, again for the floor. My name is Keo Lee, and I take the floor on behalf of the Youth Publications and Socioeconomic Forum, a subsidiary program of the DMUN Foundation. While confidence -building measures are ultimately about reducing uncertainty and strengthening trust between states, confidence in cyberspace cannot exist solely between governments. It must extend to the people who use digital technologies every day. Especially young people. Today’s youth are the first generation to grow up in an environment where cyber incidents, online disinformation, and AI -generated content are part of everyday life. Despite being among the most affected stakeholders, young people are rarely included in discussions on how trust and confidence in cyberspace should be built. We therefore encourage member states to consider youth engagement as a practical confidence -building measure. This can include structured dialogue, shortcomings, structured dialogues between governments and youth, and support for youth -led cyber awareness initiatives, and opportunities for young experts to participate in regional and international confidence -building activities. Youth exchanges across borders can also help foster mutual understanding, build professional networks among future cybersecurity leaders, and promote a shared culture of responsibility. These people -to -people connections reinforce the trust that formal confidence -building measures seek to achieve. Finally, confidence -building efforts should ensure the meaningful participation of young people from developing countries and underrepresented communities. Cybersecurity is a shared global responsibility, and trust is built more effectively when large segments, including the next generation, are included in opportunities to contribute and help shape the future of cyberspace. Thank you.
—
Chair Egriselda López
Thank you very much we have heard the last speaker under this item I thank you for this very interesting exchange of views as I’ve done for the other agenda items I would like to briefly summarize our discussion you have reflected on the eight global measures which include information exchange measures including sharing national strategies legislation, good practices collaboration between the public and private sector and capacity building measures which without a doubt is a cross -cutting topic we heard about the value of the points of contact delivery directory rather the global measures many delegations agree that this is a important confidence building tool, a voluntary one that can strengthen cooperation and reduce misinterpretation and instability and CBMs can strengthen cooperation, the risks from erroneous transactions, errors of calculation and all of these measures can foster stability in the digital sector. I also welcome state’s participation in this directory and I hope that we’ll eventually be able to achieve universal participation. Like in past practice, I would urge all of those who haven’t yet done so to appoint and nominate diplomatic contact points and engage in the verifications to ensure that these contact points remain and operational given that the real value of them is precisely them being able to respond in a timely manner to ICT incidents. we also heard the value that member states attached to these measures that are vital for the implementation of the framework on responsible state behavior so thank you all of you for all of your statements we’ve taken note of all of them and they are important inputs for us for us to be able to determine the way forward specifically exactly how we’ll structure the discussions in the dtgs we’ll now move on to our final agenda item which is developing and implementing capacity building as you know like for the other agenda items there’s no pre -established list of speakers so i’d invite you all to press your microphone button wow that was quick to express your intentions i reiterate that there is no established time limit for your statements but I would be very grateful if you could consider delivering a shorter statement and send the full version of your statements to eStatements to the Secretariat and to the Chairs team that way we’ll be able to hear from all delegations for reference and to help you we’ll display the clock on the screen I give the floor to Tonga on behalf of PEF followed by the European Union Chile speaking on behalf of a group of countries and Nigeria on behalf of the African group. Tonga, please.
—
Tonga on behalf of Pacific Islands Forum
Thank you, Chair. I have the honor to deliver this statement on behalf of the members of the Pacific Islands Forum with a presence of the United Nations, namely Australia, the Cook Islands, Fiji, Kiribati, the Federated States of Micronesia, the Republic of the Marshall Islands, Nauru, New Zealand, Palau, Papua New Guinea, Samoa, Solomon Islands, Tuvalu, Vanuatu, and my own country, Tonga. Chair, capacity building is the enabler that underpins all aspects of our work. It is foundational to responding to threats, implementing norms, engaging meaningfully in the discussion of international law, and to sustaining confidence -building measures. It should not be siloed. And should remain a cross -cutting threat through all of the mechanisms worked. Our priorities remain practical and grounded in operational needs. They include critical infrastructure and critical information infrastructure protection, cyber incident response, technical implementation, legislative and policy development, workforce development, public awareness and cyber hygiene, legal capacity building, regional CBMs, and support to understand and manage AI -related cybersecurity risks. These are the issues that matter to countries and communities, and they should guide the work of the global mechanism. We are particularly hopeful that the dedicated thematic working groups, through their informal and action -oriented approach, can help address many of these issues. The DTGs, should be used to identify needs, share practical experience, connect states with relevant expertise, and help match national and regional priorities with appropriate support. They should not become additional negotiating rooms that reproduce the same procedural disagreements, nor they should simply repeat plenary discussions. Their value will be measured by whether they help countries make progress. Stakeholder engagement is essential to this effort. Our member states consistently find the technical expertise of the multi -stakeholder community, academia, civil society, the private sector, and the technical community to be of real and practical value. Meaningful capacity building depends on access to that expertise. If we want capacity building, we need to be able to do it. We need stakeholders. We therefore strongly support the substantive inclusion in both formal and informal settings, and we support the fullest possible use of expert briefings within the dedicated thematic groups. Such briefings are of genuine benefit to smaller delegations, and we trust they will be delivered in an appropriate manner. We continue to urge improvements to accreditation and participation modalities so that stakeholder participation is real rather than nominal. Accessibility is also a capacity -building issue. Hybrid modalities, travel support, regional workshops, and time zone sensitive scheduling all affect whether small delegations can participate. We welcome hybrid modalities. Modalities for the DTGs. but again ask for meeting times to be rotated so Pacific delegations are not consistently asked to participate in the middle of the night. An inclusive global mechanism must be inclusive, not only in principle, but in the practical design of its work. In the Pacific, distance has never meant disconnection. Across our ocean, communities have navigated by knowing the winds, reading the currents, and keeping sight of the stars. That spirit should guide this global mechanism. We need a process that helps states find their cause through a changing digital environment, not by adding complexity, but by building trust, sharing knowledge, and delivering practical support where it is needed most. Let this mechanism progress. We need a place where we can be more than a place where we describe the challenges before us. Let it become a way to move together with purpose towards stronger resilience, meaningful capacity, and a secure, stable, open, and peaceful ICT environment for all. Thank you, Chair.
—
Chair Egriselda López
Muchísimas gracias. Thank you. Before giving the floor to the following speaker, I’ll inform you that we’ve received 43 requests for the floor. Thank you, therefore, for indicating if you would like to take the floor so that we, together with the Secretariat, can decide the total number of delegations who wish to intervene. I now give the floor to the European Union.
—
European Union
Thank you, Chair, for giving me the floor. Chair, colleagues, I have the honor to speak on behalf of the European Union. Thank you. The candidate countries North Macedonia, Montenegro, Serbia, Albania, Ukraine, the Republic of Moldova, Bosnia and Herzegovina, Georgia, and the after -country Norway, member of the European Economic Area, as well as San Marino, align themselves with this statement. As set out in the final OEWG report, cybercapacity building is a priority of the international community and should continue to be a central issue under the global mechanism, complementing the efforts at regional and bilateral level, as well as with the multi -stakeholder community. Currently, many developing and emerging economies lack the technical expertise and institutional policies, as well as frameworks necessary to address cyber threats effectively. This not only undermines their digital development, but also impacts international security, and stability. Therefore, the work under the global mechanism should enable exchanges that allow for the identification of an evolving list of concrete gaps and needs for cybercapacity building efforts, as well as facilitate recipients and donors, including from the multi -stakeholder community, to connect. The aim should be to translate the UN framework of responsible state behavior in cyberspace into practical cybersecurity measures to enhance national resilience and to implement cybercapacity building projects on this basis on the ground. States can contribute to this by identifying gaps, seeking coordination and cooperation for effective delivery of capacity building, and by sharing their national best practices. On how they implement the UN framework of responsible state behavior in their regional and national frameworks. Such exchanges should take place in DTG 2 and could take into account the exchanges in DTG 1 on best practices and concrete cybersecurity measures needed at national level to address cyber threats and on the application of international law, voluntary norms and CVMs in the context of specific challenges Further discussions could take place in the plenary and in DTG 2 including on broader questions related to cybercapacity building as a policy These discussions could include the further development of a digital tool to support states’ implementation of the UN framework building on the voluntary norms implementation checklist the role of the multi -stakeholder community in the design and delivery of cybercapacity building on the role of regional organizations in ensuring effective coordination or on how to best mainstream the agreed ICT security capacity building guidelines as adopted in the 2021 OEWG report into relevant ICT security cyber capacity building programming. Also, the global roundtable on capacity building could play a role in ensuring enhanced coordination and cooperation. For instance, by bringing together capacity building implementers for exchange of information and best practices, feeding into the discussions in the plenary and DTG2. The EU and its member states will aim to avoid duplication with discussions between the plenary, DTG2, and the global roundtable and pursue a streamlined approach. Moreover, the EU has significantly invested in cybercapacity building over recent years and will continue to do so in the coming years, working on cybercapacity building projects with partners in all regions globally. Currently, in addition to EU member states’ individual projects and initiatives, such as the Global Gateway, the EU is working with partners on 27 projects with a value of 100 million euros, and we will continue to invest, recognizing capacity building as an essential pillar of security and stability in cyberspace, as well as our partnerships. Furthermore, the EU and member states will continue to promote coordination and cooperation, including with international organizations and other stakeholders, such as industry, civil society, and education, and academia to ensure meaningful allocation of scarce resources and to deliver capacity building activities in an effective and sustainable manner. Ultimately, the global mechanism is the unique opportunity to ensure we enhance global cyber resilience by translating the UN framework into concrete national cybersecurity measures and based on this by delivering cyber capacity building that is inclusive, needs -based and grounded in equal partnerships.
—
Chair Egriselda López
Muchas gracias. Muchísimas gracias. Thank you very much. I give the floor to the delegation of Chile, speaking on behalf of a group of states.
—
Chile Representative on behalf of Latin American group
Thank you, Madam Chair. It’s my honor to take the floor on behalf of the following delegations from the Latin American region. Argentina, Brazil, Colombia, Costa Rica, Ecuador, Guatemala, Honduras, Mexico, Paraguay, Peru, the Dominican Republic and Uruguay. Please allow us to begin by congratulating you Madam Chair for your leadership of this first substantive session of the Global Mechanism We reiterate our full support to your work and our commitment to an inclusive, transparent, results -focused mechanism Madam President, the creation of the Global Mechanism marks the beginning of a new step forward in the work of the United Nations on ICTs After more than two decades of work engaged in by the open -ended working groups and the groups of governmental experts What we need to do now is focus our efforts on the implementation of a constantly evolving framework for responsible state behaviour In this step, capacity building will continue to play an absolutely key role As the… This is the final report of the open -ended working group from 2021 to 2025 states, capacity building is a cross -cutting part of the framework for responsible state behavior and one of the essential functions of the new global mechanism. It strengthens resilience, it contributes to reducing digital gaps, it facilitates the effective implementation of the agreements reached and promotes international cooperation to preserve international peace and security. In this regard, we appreciate the establishment of the dedicated thematic group on capacity building, bearing in mind that this is a significant milestone and follows up on the work that our countries have been promoting constantly over the last few years through joint statements, working documents and concrete proposals focused on strengthening the role of this dimension. And in the permanent mechanism. capacity building is a key element that enables states to effectively implement the different components of the framework for responsible state behavior their cross -cutting nature does not reduce but rather strengthens the needs and importance of having a dedicated thematic group that will enable a strategic coherent results focus direction to be taken in this regard we believe that both dtgs play different roles however also relevant complementary roles and and must be worked on together in a balanced way the cross -cutting themes that run through both groups reflect the fact that the implementation of the framework requires a certain amount of time and effort to implement the framework and to implement the framework substantive analysis of emerging challenges as well as a systemic effort to strengthen the capacities of states Madam Chair, we believe that the DTG on capacity building must be established as the main platform for dialogue on this issue within the framework of the global mechanism playing a fundamental role as a space for strategic coordination to facilitate the exchange of information and experience to articulate synergies between existing mechanisms and to identify opportunities for cooperation that can respond to the needs expressed by states. What’s more, we recognise the significant contribution that in line with the modalities agreed on, academia, civil society, the private sector, the technical community and other stakeholders can play here. Madam Chair, in this new step in the global mechanism, for us, discussions on capacity building must be focused on the… on practical implementation, because this is the link that enables us to turn political commitments made at the UN into concrete capacities on a domestic level. In this sense, the DTG can take as an initial basis the report on the analysis to study the panorama of programs and initiatives for capacity buildings within and outside the United Nations on a global and regional scale. That’s in document 292 2024 slash two. And this can contribute, among other things, to identifying national regional thematic needs for capacity building to exchange experiences, good practices and lessons learned to promote the participation of women in capacity building activities, to promote associations and cooperation networks between countries to strengthen North, South, South, South and triangular cooperation to improve. improve coordination and complementarity between different international, regional and sub -regional initiatives that already exist, and to identify opportunities for technical assistance and institutional strengthening to support the implementation of responsible state behaviour, and to establish action -focused recommendations for the consideration of the plenary. In light of the above, and in the spirit of contributing constructively to the deliberations of this DTG, we’re delighted to announce that we will soon be presenting a working document with concrete proposals on the future functions, priorities and modalities of the work of that group. We hope that the above -mentioned document will enrich the deliberations in the mechanism and will facilitate the development of an ambitious, inclusive and flexible programme of work that That is results focused. Furthermore, we reiterate the fact that we stand fully ready to work with all delegations and other stakeholders to develop proposals and initiatives. And we invite those who are engaging in efforts in this area to join this process in order to build a common, inclusive approach. Thank you very much.
—
Chair Egriselda López
Thank you very much. I give the floor to the delegation of Nigeria, speaking on behalf of the African group.
—
NIgeria on behalf of African Group
Thank you Madam Chair I have the honour to deliver this statement on behalf of the African Group The African Group welcomes the establishment of dedicated thematic group 2 on capacity building and consider it an important opportunity to consolidate and advance the significant progress achieved under the OEWG where capacity building emerged as an essential part of international cooperation and assistance in the security of and in the use of information and communication technologies For African countries, capacity building is not an auxiliary issue. It is a strategic enabler for achieving a secure, resilient and inclusive digital future As a digital transformation accelerates across our continent, strengthening national and regional cyber capacity remain essential to enabling states to prevent, detect, respond to, and recover from cyber threats while advancing sustainable development in line with African Union Agenda 2063, the Digital Transformation Strategy for Africa from 2020 to 2030. The African group, therefore, believes that the work of the DTG Group 2 should build upon, rather than duplicate, the valuable outcome of open-ended working groups, the extensive valuable discussions, recommendations, and confidence built over successful OEWG sections, provide a strong foundation for developing practical, coordinated, and action-oriented approaches to capacity building under global mechanism. The group welcomes proposer for a structured diagnostic assessment of the current capacity building landscape as an LADTG2 deliverable and encourages the co-facilitator to take this forward. African capacity building priorities remain clear. Strengthening national cyber security strategies and governance framework, developing legislative and regulatory frameworks, enhancing technical and operational capabilities, including national and sectoral computer security incident response teams, building cyber diplomacy expertise, promoting cyber resilience for critical infrastructure and critical information infrastructure, supporting digital forensic and cyber crime investigation, advocacy, and development. Advancing cyber security, education and workforce development, and fostering regional cooperation and information sharing. Madam Chair, we also underscore that effective capacity building must be demand -driven, nationally owned, sustainable, and tailored to the specific needs and priorities of countries. We must underscore regional perspectives and reality to capacity building. Capacity building should also promote inclusive approach through the meaningful participation of women, men, youth, academia, the technical community, civil society, and private sector, recognizing that cybersecurity is a shared responsibility requiring all of society approaches. The African group encourages all member states to complete their nomination to the Global Point of Contact Directory as an immediate concrete confidence building step. The African group further recognizes and appreciates the long -standing partnerships that have supported cybersecurity capacity building across the continent. We commend the continued cooperation and assistance provided by a range of partner countries and regional and international organizations through technical assistance, training programs, institutional support, knowledge exchange, and financial resources. These partnerships have contributed significantly to strengthening cyber resilience across African states. As we move forward, the DGT2 should serve as a platform for enhanced coordination, transparency, and coherence among existing capacity building initiatives, avoid duplication, maximize available resources, facilitate the sharing of good practices, and other much -needed. Thank you. and regional capacity building need with available expertise and support. These tools should be allocated adequate time within the program of work, commensurate with the centrality of capacity building to the mechanism mandates. Reporting and review arrangements should be proportionate to national capacity and designed to encourage rather than deter participation. Madam Chair, the African Group encourages progress on practical initiatives including the Global ICT Security Corporation and Capacity Building Portal, the Point of Contact Directory, Cyber SSI, Strengthen National Center, a Voluntary UN ICT Security Capacity Building Fund and Program to Develop Cyber Security Professionals. The African Group also reiterates its call for a united, national ICT Security Fellowship Program. for developing countries with attention to least developed countries and small island developing states designed to ensure efficiency, transparency, and equitable accesses. Madam Chair, the African Group’s reiterate that sustained investment in cyber security capacity building is essential for the effective implementation of UN Framework of Responsible State Behavior in the security and use of ICT. DGT2 presents an important opportunity to translate commitment into practical outcome and ensure that all states, particularly developing countries, can participate fully and benefit from a secure, resilient, stable, and peaceful cyber space. I thank you, Madam Chair, and I also seek your attention. to call upon my colleague to deliver our national statement. Thank you, Madam Chair.
—
Chair Egriselda López
Of course. Thank you very much.
—
Nigeria
Madam Chair, Nigeria aligns itself with the statement delivered on behalf of the African group and wishes to make the following remarks in its national capacity. My delegation comments your leadership in guiding our work towards a practical, inclusive, and action -oriented global mechanism. Nigeria welcomes the establishment of a dedicated thematic group to our capacity building and considers it as a vital platform for translating the substantial progress achieved under the open -ended working group into concrete and sustainable outcomes. For Nigeria, capacity building is the cornerstone of an open, secure, stable, accessible, and resilient cyberspace. It is essential for implementing the UN framework of responsible state behavior in the use of ICTs and enabling developing countries to address evolving cyber threats. Capacity building efforts should be demand -driven, nationally owned, sustainable, and tailored to national priorities, while strengthening institutions’ human capital and resilient cyber ecosystem. In this regard, Nigeria believes DTG2 should prioritize strengthening national cybersecurity strategies, legal and governance framework, technical capabilities, including C -sets, and expertise in cyber diplomacy, digital forensic, cybercrime investigations, and the promotion of critical infrastructure and critical information infrastructure. As emerging technologies continue to evolve rapidly, our capacity -building efforts should equally invest in cybersecurity education, digital skill development, research and innovation, while promoting indigenous expertise that enables sustainable national ownership of cybersecurity capabilities. Nigeria attaches particular importance to practical cooperation. We support enhanced cooperation amongst governments, regional organizations, academia, the private sector, civil society, and the technical community to promote knowledge sharing, cyber exercises, straight intelligence exchange, vulnerability assessment, and dissemination of good practices. Such cooperation should complement the state -led nature of this mechanism while strengthening collective cyber resilience. Madam Chair, Nigeria supports practical initiatives that deliver tangible outcomes, including the Global ICT Security Cooperation and Capacity Building Portal, the Global Points of Contact Directory, Strengthed National SETS and SISETS, a Voluntary UN ICT Security Capacity Building Fund, and the United Nations ICT Security Fellowship Program to expand opportunities to developing countries, particularly leaders. These developed countries are the ones that will be able to do so. and small island developing states. We further underscore the importance of ensuring the full, equal, and meaningful participation of women and youth in cybersecurity capacity -building programs. We commend initiatives such as UNIDEL and donor sponsorship of women in international security and cyberspace fellowship, which has made valuable contributions to broadening inclusive participation in international cyber discussions. Ultimately, Nigeria believes DTG2 should coordinate existing capacity -building initiatives, avoid duplication, match identifying needs with valuable expertise and resources, and promote coherent implementation. Given its central role in advancing responsible state behavior in cyberspace, capacity -building should receive adequate attention throughout the work of this mechanism. Nigeria remains committed to working constructively with all member states to ensure that capacity building delivers practical, equitable and lasting benefit for all I thank you Madam Chair
—
Chair Egriselda López
Thank you I will read the next delegations to speak hoping that we can hear from all of these during this segment this morning we have Vietnam, Iraq, Colombia, Morocco, Costa Rica and Cote d ‘Ivoire. Vietnam you have the floor.
—
Vietnam
Thank you Madam Chair Vietnam strongly believes that capacity building is essential to international cooperation in ICT security Through capacity building, states may develop common understanding of voluntary, non -binding norms of responsible state behavior, shared experiences and best practices in applying these norms to protect critical infrastructure and supply chains Thank you Madam Chair to ensure cyber engine hygiene and security by design. The voluntary norms are to elaborate and not to replace the international law, including the Charter of the United Nations, which are without doubt applicable to cyber domain. States need the capacity to understand how international law applies to cyberspace and if a gap exists. In the process, the United Nations shall play the central role, and the discussion in the dedicated thematic groups should focus on the applicability of sovereignty equality, non -intervention in internal affairs, international humanitarian law, the clarification of cyber sovereignty, cyber warfare, and peaceful settlement of disputes in ICT contexts. With the conviction that every state has the right to have a free and equal right to the rights of its citizens, and the right to development, Vietnam supports the flexible and inclusive capacity building To bridge the digital divide, it should incorporate the gender equality and awareness raising, particularly for people vulnerable to cyber offenses. In this direction, Vietnam is taking the initiative to establish an Asia -Pacific Regional Cybercrime Center in Hanoi, in cooperation with the UNODC, as a follow -up of the ratification of the United Nations Convention against Cybercrime. We would welcome the participation of other steps and stakeholders as sponsors and partners in the center. I thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much. I give the floor to Iraq.
—
Iraq
Thank you, Madam President. Building capacities is a basic pillar of responsible state behavior in ICT use and an indispensable demand to enable all states, particularly developing countries, to effectively participate in promoting peace and stability in cyberspace and benefit from the opportunities made available by digital transformation. Capacity building must also be based on principles of universality, transparency, and sustainability. It should be anchored in national needs and priorities of states while respecting their sovereignty and their rights to define their national and security demands in such a manner that guarantees preventing any further widening of the digital gap between developed and developing nations. We stress the importance of promoting peace and stability and promoting international and regional cooperation through knowledge transfer, technical assistance, and the development of new technologies. support for best institutional practices, and providing national support while supporting legislative frameworks and training national workforce, enabling them to prevent, respond, and recover from cyber threats. We also welcome initiatives aimed at coordinating our efforts for capacity building within the United Nations. We stress the importance of avoiding duplication among different programs and guaranteeing the optimal use of available resources in a manner that leaves a sustainable and tangible benefit to states. It is important to say that… that building capacities should get financial and technical support so that equal opportunities be available… to all states to benefit from international programs and initiatives. Special attention should be given to the needs of developing countries and countries emerging from conflict in a manner that enables such countries to implement the international framework of responsible state behavior. In conclusion, Iraq would like to renew its commitment to participate actively in international efforts aimed at promoting capacity building because we believe that promoting national capacities is the basis for a stable, comprehensive, and secure cyberspace that supports sustainable development and promoting international peace and security. Thank you,
—
Chair Egriselda López
Thank you very much. I give the floor to the delegation of Colombia, who will be followed by Morocco.
—
Colombia
Madam President. Madam Chair, Colombia aligns itself with the statement made by Chile on this agenda item. In our national capacity we’d like to make the following remarks. As we stated during the session in March, my delegation welcomes the creation of the second DTG which we believe is fundamental to promote a boost to capacity building that is effective, sustainable and tailored to the needs of the states that ask for assistance. Capacity building must be understood as an investment in the stability of the global digital environment and as a factor that can boost the implementation of the framework for responsible state behaviour. In this context, it’s important to remember that the vulnerabilities and lackings in the technical, legal and institutional capacities of a state can have repercussions on the stability and integrity of the whole of the digital system. It’s for this reason that strengthening national capacities also constitutes a contribution to the collective security of cyberspace. Based on this premise, it’s essential to harness the comparative advantages and specialised experience of some states and regions to promote more effective cooperation that’s tailored to the needs of the beneficiary countries. In this effort, modalities like South -South cooperation and triangular cooperation can play a particularly valuable role since they facilitate the exchange of knowledge and good practices, taking account of the local realities and priorities. Thank you. Additionally, my delegation wishes to underscore some elements that could contribute to making the DTG2 work more practical and results focused and more dynamic. First of all, for us, it would be useful to include the analysis of specific real case studies, as well as hypothetical ones that could help us to learn concrete lessons and make practical recommendations in areas like cooperation in response to cyber events, to develop guides on how to respond and to engage in some simulation exercises. Secondly, my delegation underscores the value of exchanging experiences so that states can share good practices. As well as challenges and lessons learned. This exercise could focus, among other things, on assessing. the maturity of the infrastructure for responses to these events, as well as identifying vulnerabilities and engaging in sectoral responses. Finally, for Colombia, it’s a priority to avoid duplication of efforts and to maximize the resources we have available. The mechanism offers the right platform to identify initiatives that are currently ongoing to generate complementarity between them and to engage in more effective coordination based on the needs and priorities of different states. Madam Chair, capacity building should not be thought of as an exercise that’s focused only on complying with indicators or ticking boxes. For it to have sustainable results, it must begin with a rigorous diagnosis, establish a strategy with clear goals and have mechanisms that enable us to measure the real impact in time. This is the only way we’ll manage to turn this into an aspiration on paper, into a tangible reality that is able to rise to the challenges that we face. Thank you.
—
Chair Egriselda López
Thank you, Columbia, says the Chair. I now give the floor to the delegation of Morocco, followed by Costa Rica.
—
Morocco
Madame la Présidente. Madame Chair. Capacity building is not a secondary issue. It is the guiding thread that runs through all the other pillars of responsible behavior. Consensus was reached during the last OEWG among member states. They rallied around a simple principle. Strengthening capacity needs to be financially accessible and adapted to the needs of every state inter alia. The credibility of the global mechanism largely highlights the hinges on our collective capacity to translate our ideas into projects and our projects into concrete results. The capacity building pillar offers us in this regard a genuine opportunity to move forward swiftly and successfully. The initiatives already undertaken are, in our view, an important point of departure for implementing the capacity building portal and to create a voluntary fund on capacity building and programs based on the real needs and based on the abilities of every country. Other projects, doubtless, will emerge as our work continues or in the second thematic DTG. These collective avenues will become fully relevant, however, when they are coupled with the efforts of every state. In this regard, Morocco has… continued at the national level its capacity building work, which is a separate part of its national cybersecurity strategy. We work consistently in order to improve our national task force. In terms of initial training, we have carried out cybersecurity training in close partnership with academia in order to ensure our markets have what they need. Our investments have borne fruit here. We’ve undertaken targeted programs and training cybersecurity professionals, and this is directly related to cooperation agreements that we have entered into. These international efforts are also put to the service of the region. We’re also working. In. the National African Cybersecurity Network. In this context, we initiated the creation of CERTs, and they’re headquartered in Morocco. And capacity building in Africa is their priority area of action. We hope this contribution will be useful for efforts in Africa. This CERT started its work last June, and there was a training cycle aimed at African security agencies. Other initiatives have already been scheduled for the coming months. Madam Chair, my delegation encourages multiple capacity building initiatives to be set up in developing countries, and developing countries stand in particular need. In that regard, we’d like to share some thoughts about the fact that this remains a major challenge for many countries. this momentum will contribute to global resilience while limiting the need for national training. We think this dimension should be given particular attention in our debate, and it would be useful to consider it during the information sessions. Thank you very much.
—
Chair Egriselda López
I give the floor to Costa Rica, followed by Cote d Ivory.
—
Costa Rica
Madam Chair, Costa Rica thanks you for this opportunity to take the floor. On this item, capacity building, we believe that this is perhaps the most relevant item in the global mechanism and an essential condition to implement the framework for responsible state behavior in the use of ICTs. First of all, capacity building is a bridge between consensus and action. voluntary norms, international law, confidence building measures, due diligence and national resilience. These can only be turned into policies and practical steps if states have technical, legal and institutional capacities that are up to the mark. Without capacities, we run the risk of building a legally elegant infrastructure that is operationally useless. Second, Costa Rica supports this pillar being focused on specific prevention, detection and response capacities. And this must include identifying threats and vulnerabilities, protecting critical infrastructure and government systems, early detection of incidents, coordinated responses, recovering essential services and bolstering institutional continuity. A lack of national capacities increases our collective vulnerabilities. And can bring about cross -border and cross -regional impacts. thirdly the legal interpretation also requires specialized institutional capacities states must be able to evaluate incidents establish national positions on the application of international law to cyberspace to understand the different legal thresholds to participate responsibly in debates and contributes to common understanding that’s why it’s fundamental to develop cyber diplomacy strategies that articulate legal technical and political knowledge that enable us to coherently represent national interests in international fora and to facilitate the building of consensus competence building measures and cooperation mechanisms between states finally perspectives on due diligence must be coupled with technical assistance and support if we want states to be able to adopt reasonable measures in line with their own capacity to prevent halt or mitigate harmful cyber events we must be able to develop legislation, certs, contact points, legal and judicial capacities and inter -institutional coordination. Madam Chair, Costa Rica believes that capacity building must be sustainable, inclusive, regional and focused on human rights with the participation of governments, the private sector, civil society and the technical community. Investing in national cyber resilience is also the same as contributing to international stability. That’s why Costa Rica supports the initiatives being undertaken to build regional and global financing mechanisms for capacity building in countries. And this requires more cooperation between the public and private sectors. This work will contribute to building an open, safe, stable, accessible, peaceful and interoperable cyberspace. Thank you very much.
—
Chair Egriselda López
I take it that we’ve run out of time for this morning’s meeting. We still have 49 requests for the floor under this agenda item. So we will hear from the other delegations this afternoon in the same room at 3 p .m. And what I’ll do right now is just read out the first 10 delegations to speak this afternoon so that you can be ready to speak this afternoon. So we’ll begin with Cote d ‘Ivoire, who will be followed by South Africa, then Malawi, the Islamic Republic of Iran, Italy, Brazil, Rwanda, Kiribati, Cambodia and Mauritius. The meeting is adjourned. Thank you. Thank you. Thank you. Thank you.
The knowledge base indicates that the Global Mechanism on ICT Security was established with its first substantive plenary session scheduled for July 2026 [S190][S191]. The report describes a ‘seventh meeting of the substantive plenary session of the Global Mechanism on ICT security,’ which appears inconsistent with the knowledge base timeline. Additionally, [S192] references a ‘Seventh OEWG Session on ICT Security,’ suggesting the session described in the report may actually be the seventh meeting of the OEWG (Open-Ended Working Group), not of the Global Mechanism. The report may be conflating or mislabelling the body in question.
2
The knowledge base confirms Nigeria spoke on behalf of the African Group in OEWG discussions on agenda item 5 [S68][S154]. CBMs are also broadly described as serving to reduce misunderstanding and prevent conflict escalation [S88], corroborating the substance of Nigeria’s statement.
3
The knowledge base confirms that the OEWG process produced agreed voluntary global confidence-building measures, described as helping build trust and foster mutual understanding among states [S195]. This provides context supporting North Macedonia’s characterisation of CBMs as valuable OEWG outcomes, though North Macedonia’s specific statement is not directly corroborated.
4
The knowledge base confirms that capacity building (agenda item 5 or 6 depending on the session) was a substantive agenda item discussed in OEWG plenary sessions, with multiple delegations taking the floor on this topic [S18][S23][S142].
5
The knowledge base broadly confirms this characterisation of CBMs. [S125] describes CBMs as ‘multifaceted tools essential for fostering transparency, cooperation, and stability while reducing conflicts by preventing misunderstandings and easing tensions.’ [S124] similarly notes CBMs as vital tools for enhancing cyber stability.
6
The knowledge base does not provide specific figures on the number of speakers queued for the CBMs agenda item. However, multiple sources confirm that CBMs attracted broad participation from delegations across regions in OEWG sessions [S68][S120][S154], providing general context for a large speakers’ list.
DIPLOFOUNDATION UNIVERSITY OF MALTA— Côte d’Ivoire’s foreign policy and diplomatic alliances in the sub-region shifted further under the presidency of Laurent Gbagbo whose opposition to Taylor led to the formation of new alliances with anti-Taylor Liber…
University of Malta Faculty of Arts DiploFoundation— 12) Energy. Between the two countries, there is an electrical interconnection. Côte d ‘ Ivoire provides the main part of the electricity used in Burkina Faso. This is very strategic for these countries. – 13) …
Agenda item 6: other matters/OEWG 2025— – Pacific Islands Forum – Tonga: Speaking on behalf of Pacific Islands Forum member states – The Pacific Islands Forum, represented by Tonga, emphasised the need for a limited number of thematic groups to enable partici…
Adoption of the agenda and organization of work— Israel has been part of the process since its inception Israel’s consistently positive stance on various facets of the negotiations shows its constructive and proactive role in international policy formation. By endorsi…
Any other business /Adoption of the report/ Closure of the session— It becomes apparent that Israel is keen to play a constructive role in multilateral dialogues and is dedicated to contributing positively to international mechanisms that promote the rule of law, strong institutions, and…
Ad Hoc Consultation: Wednesday 31st January, Afternoon session— Additionally, it exhibits flexibility, contemplating a Brazilian proposal and suggesting a refined change to the term “Secretariat,” advocating instead for “Secretariat Services.” This change highlights Colombia’s constr…
Any other business /Adoption of the report/ Closure of the session— Colombia has showcased its dedication to furthering gender equality, affirming its commitment to integrating a gender perspective across its official documentation and policy-making endeavours in alignment with Sustainab…
Acknowledgements— 7 Tuvalu joined the Commonwealth and the UN in 2000 (Ministry of Foreign Affairs and Trade- New Zealand) At the international level, Tuvalu maintains diplomatic relations with various countries (Box 2.1.3) in Asia, Mid…
High-level SIDS Ministerial Dialogue: Key Challenges and Opportunities— Above all, Tuvalu confronts the existential threat of climate change; although it contributes minimally to global emissions, the nation bears the full brunt of its adverse impacts. These effects are not isolated to envir…
(Day 2) General Debate – General Assembly, 79th session: morning session— Mokgweetsi Eric Keabetswe Masisi – Botswana : Mr. President, Excellencies, Distinguished Ladies and Gentlemen, I wish to start by extending my congratulations to you on your election as President of the General Assembl…
Agenda item 6— In conclusion, Botswana envisions the OEWG playing a crucial role in enabling the exchange of expertise and capabilities in a multi-stakeholder environment that is aligned with regional and national efforts. Such collabo…
Ad Hoc Consultation: Tuesday 30th January, Morning session— In the previous draft, ‘theft’ and ‘fraud’ were two separate articles. The ‘theft’ article was deleted, but was later amalgamated into the ‘fraud’ article, which is why ‘theft’ still appears. The Russian Federation suppo…
Ad Hoc Consultation: Tuesday 6th February, Morning session— Furthermore, it reflects an understanding of the importance of a common linguistic framework in reinforcing international partnerships – a key element for the achievement of sustainable development and effective global c…
UNSC meeting: Multilateral cooperation for peace and security— Mozambique:Mr. President, Mozambique highly commends the initiative of the Russian Federation for convening this open debate under the theme multilateral cooperation in the interest of a more just, democratic, and sustai…
The art of bending without breaking: Vietnam's quiet power play — Even before China’s rise in economic and technological avenues, China had regarded Vietnamese-style communism as troublesome and could never compel Hanoi to pursue its interests. After Vietnam had invaded Cambodia to ove…
Balancing act: advocacy with big tech in restrictive regimes | IGF 2023— Trinh Huu Long:Yeah, thank you very much for having me. I have a presentation. May I share my screen or? Yeah, I think so. Great. I’m finding my screen. Please bear with me. Super. Yeah, we can see it now. Thank you very…
Conversation: 01— -Paula Bogantes Zamora- Area of expertise: Science, innovation, technology and telecommunications policy. Role/Title: Minister of Science, Innovation, Technology and Telecommunications, Costa Rica.[S12] Additional conte…
Ad Hoc Consultation: Monday 5th February, Morning session— The supporting facts for Tonga’s stance, albeit succinct, are unequivocally affirmative and propose precise modifications to the draft to optimise its content, signalling an and constructive participation in the p…
Acknowledgements— 2016). Tonga and the Solomon Islands have longstanding relations, with Tonga’s peace keeping mission support to the RAMSI (Regional Assistance Mission to Solomon Islands), which were ‘led and fund…
Public Diplomacy and Nation Brand— Morocco is part of the Maghreb region (Algeria, Tunisia, Libya and Mauritania) and part of Africa, but is not acting in any of their unions because of divisions on the issue of the ‘Western Sahara’. Mor…
Ad Hoc Consultation: Tuesday 6th February, Morning session— During a formal session, the chairperson acknowledged the presence and contributions of various national delegations, with a specific commendation directed towards Morocco for its involvement in an information system. Th…
The New Public Diplomacy— ‘Norway’ is an unusually mobile presence in the world. The reputation of its shipping fleet – one of the world’s largest – for efficiency, safety and cleanliness enhances the generally positive image of the Atlanticorien…
Public Diplomacy and Nation Brand— – Limited capabilities: Small, limited material capabilities facilitate the role as peace mediator. This can be turned into a ‘comparative advantage’ for Norway internationally. – Unthreatening: No perceive…
Ad Hoc Consultation: Wednesday 31st January, Afternoon session— In summary, Norway emerges as a conciliatory and collaborative figure in the article discussions. Its positive sentiment, endorsement of both the article in its present form and the proposal by the US and EU in Paragraph…
The Role of Nigeria In Restoring Peace In West Africa— For instance, Nigeria is largely bordered in the South by Cameroon, which has similarities with some Nigerian villages. Yaounde is a name of town in the Nigeria’s border communities and same name is today given to the ca…
Ad Hoc Consultation: Friday 9th February, Morning session— By endorsing Egypt’s amendment, Cameroon is playing a key role in promoting transparency and efficient communication, pivotal for the smooth enactment of the document’s goals. In summary, Cameroon is proactively engaging…
UNITED NATIONS HANDBOOK 2019-20— As at 31 July 2019, 193 states were represented in the General Assembly. These states, together with their dates of admission to the UN, are: | Afghanistan .. .. .. .. .. .. .. .. .. .. .. | .. 19 Nov 1946 …
Adoption of the agenda and organization of work— Furthermore, Uruguay is committed to ongoing diplomatic dialogue during informal consultations on Articles 5 and 24. It aims to be a constructive force in the refinement of the convention’s text, ensuring legal rigour an…
UNGA/DAY 1/PART 2— National identity:Uruguay is a small country with a deep vocation for peace and respect. Its political system is based on consensus, and its institutions are robust. The country is a “fraternal and hospitable land” for m…
The Role of Nigeria In Restoring Peace In West Africa— For example, the nation’s peace was relatively threatened when the federal government of Nigeria, during General Ibrahim Badamosi Babangida (IBB)’s administration announcement that Nigeria was going …
Transforming Agriculture_ AI for Resilient and Inclusive Food Systems— – Affiliation: Netherlands – Role/Title: (Representative of the Netherlands) – Role/Title: Senior Researcher Thank you, Ambassador. And on behalf of the OECD, I just want to thank once again the Netherlands for the le…
Ad Hoc Consultation: Friday 2nd February, Afternoon session— By championing inclusive and pragmatic global governance, the Netherlands solidifies its position as a driving force for collective action and widespread progress in the international arena. The expanded summary provided…
Agenda item 5 : Day 4 Morning session— In the area of Confidence-Building Measures (CBMs), the Netherlands values their role in enhancing transparency, fostering trust, and promoting cooperation between states. Their support for adapting CBMs drawn from their…
Diplomacy, international intervention and post-War Reconstruction— The analysis of the peace operations in Bosnia and Herzegovina presented in this paper shows that the new international security environment with its transnational threats required international cooperation, role-sharing…
Multistakeholder Partnerships for Thriving AI Ecosystems— – Role/Title: Audience participant (part of a German group; specific affiliation not specified)[S1][S2][S3] – Role/Title: Parliamentary State Secretary at Germany’s Federal Ministry for Economic Cooperation and Developm…
By the Same Author— Germany is the world’s most decentralized large country, in political and socioeconomic structure. Its nearest comparison is the US, a continental landmass nation of a different order, and possibl…
UNITED NATIONS HANDBOOK 2019-20— * Original members, that is, those that participated in the UN Conference on International Organisation at San Francisco or had previously signed the UN Declaration of 1 January 1942, and that signed and ratified the Cha…
The Role of Government and Innovators in Citizen-Centric AI— – Role/Title: Panel moderator/host; senior role at the European Commission (referred to as “my boss” by Roberto Viola)[S6] precisely this, how do we sort of build capacity in order for this technology to be applied sign…
European Union— The European Union (EU) is a regional intergovernmental organization aimed at enhancing economic and political cooperation among its 28 member states. It operates through various institutions like the European Parliament…
European Union— The EU, through its institutions (such as the European Parliament, the Council of the EU, and the European Commission), works on a wide range of policy areas, from agriculture and competition, to environment and transpor…
Reforms proposed by small states— Permanent Mission of Barbados to the United Nations on behalf of the Caribbean Community (CARICOM). (2008). Statement on Agenda Item 9: Report of the United Nations Security Council and Agenda Item 111: On the Question o…
Ad Hoc Consultation: Tuesday 30th January, Morning session— CARICOM maintains that the preamble should emphasize international cooperation and the role of stakeholders. Guyana represents 14 member states of the CARICOM community in this viewpoint. In summary, CARICOM’s p…
CARICOM at the UN— Guyana and Saint Vincent and the Grenadines can be strong advocates on behalf ofCARICOMand the wider SIDS community, particularly for the issues that are important to SIDS. As a matter of fact, in speaking to the press, …
May, 2011— 1. Iraq is the closest country to Iran and considered as its gate to the Middle East, therefore any actual penetration of Iran must need Iraq as a corridor that secure contiguity between Iran and the Gulf states…
UNGA/DAY 1/PART 2— Role in the international community:Iraq, which has a long history and has triumphed over terrorism, has regained its rightful place in the international community. The country is a founding member of many organisations,…
Ad Hoc Consultation: Wednesday 31st January, Morning session— In summary, Iraq’s proactive role in advocating for unequivocal language and resolute support for developing nations in international compacts mirrors a wider global conversation on fostering an equitable international f…
Adoption of the agenda and organization of work— Australia’s position suggests that safeguarding human rights is both a moral and a legal necessity, vital for maintaining treaty credibility and global trust. In cyber security deliberations, particularly concerning draf…
Ad Hoc Consultation: Wednesday 7th February, Afternoon session— Thailand has been an participant in international diplomatic efforts, consistently demonstrating a constructive and positive disposition towards fostering international cooperation and consensus-building. The nati…
Ad Hoc Consultation: Wednesday 31st January, Afternoon session— In summary, Vanuatu’s clear commendation for both the wording and the title of the text denotes a robust congruence with its stance, suggesting that the revisions have suitably incorporated changes that favour Vanuatu, e…
Ad Hoc Consultation: Friday 9th February, Morning session— As for the aspects of convention ratification thresholds, Vanuatu aligns with the United States and Mexico, endorsing an elevated participation requirement as specified in Article 64, calling for a minimum ratification b…
Published by DiploFoundation (2011)— Malta: 4th Floor, Regional Building Regional Rd. Msida, MSD 2033, Malta Switzerland: Rue de Lausanne 56 CH-1202 Genève 21, Switzerland Serbia: Gavrila P. 44A Address Code 112410 11000 Beograd, Serbia E-mail: d…
Ad Hoc Consultation: Friday 2nd February, Afternoon session— Ireland’s alignment with the EU highlights their commitment to collaboration and adherence to the EU’s stance on legal matters. Ireland’s nuanced handling of international law serves as a strategic, yet discerning, ende…
Closure of the session— – North Macedonia: Representative of North Macedonia Chair: Thank you very much Côte d’Ivoire. Indonesia to be followed by North Macedonia. Chair: Thank you very much, Indonesia. North Macedonia, to be followed by Ar…
UNITED NATIONS HANDBOOK 2019-20— * Original members, that is, those that participated in the UN Conference on International Organisation at San Francisco or had previously signed the UN Declaration of 1 January 1942, and that signed and ratified the Cha…
UNSC meeting: Strengthening UN peacekeeping— Argentina is one of the vice-chairs of C34 In this speech, Argentina reaffirms its commitment to United Nations peacekeeping operations and emphasises the need for a comprehensive approach to maintaining international p…
Adoption of the agenda and organization of work— Argentina reiterated its willingness to collaborate in consensus building In summary, Argentina’s diplomatic engagement and flexible approach to achieving consensus demonstrate their dedication to fostering cooperative …
ISBN:— – H.E. Dr. Amani Abou-Zeid, African Union Commission – H.E. Ms. Aurélie Adam Soulé Zoumarou, Benin – Dr. Ann Aerts, Novartis Foundation – H.E. Dr Mohammed Bin Saud Al Tamimi, Communications and Information Technology…
De-briefing and Next steps— The analysis presents a compelling case for the enhancement of learning initiatives throughout Africa, focusing specifically on the crucial role the African Union Commission (AUC) could play in fostering educational deve…
Opening of the session— – Nigeria – Speaking on behalf of the African Group Chair: Thank you very much, European Union. Could you kindly share the statement with us, please? Thank you very much. Nigeria for African Group to be followed by Fiji…
Published by DiploFoundation (2011)— Malta: 4th Floor, Regional Building Regional Rd. Msida, MSD 2033, Malta Switzerland: Rue de Lausanne 56 CH-1202 Genève 21, Switzerland Serbia: Gavrila P. 44A Address Code 112410 11000 Beograd, Serbia E-mail: d…
(Day 2) General Debate – General Assembly, 79th session: morning session— – Félix-Antoine Tshisekedi Tshilombo – President of the Democratic Republic of the Congo Félix-Antoine Tshisekedi Tshilombo – Congo: President of the United Nations General Assembly, it is an immense honor for me to s…
Republic of Congo— Official UNOG website:https://www.ungeneva.org/en/blue-book/missions/member-states/democratic-republic-congo ThePermanent Mission of the Democratic Republic of the Congo to the UN Officeand other international organisat…
May, 2011— – The dramatic fall of the Shah’s empire with its strong domestic level of control, powerful army and notable external political and economic ambitions, which projected the Shah of Ian not only as the most …
Ad Hoc Consultation: Thursday 8th February, Morning session— Cuba has exhibited a proactive role in diplomatic negotiations, especially on issues pivotal to developing countries. The nation recognises the advancements in the dialogue, showing satisfaction with the current state of…
Ad Hoc Consultation: Wednesday 7th February, Morning session— Their emphasis on both consensus and human rights protection showcases a comprehensive approach to cybercrime; one firmly grounded in the rule of law, individual liberties, and international partnerships. In summary, Chi…
Masterclass#1— CBMs were discussed as vital tools for enhancing cyber stability, especially in the context of increasing geopolitical tensions. It was noted that certain CBMs have gained relevance in such an environment, underscoring t…
Dedicated stakeholder session— CBMs enable states to enhance their information and communications technology (ICT) security, contributing to maintaining international peace and the responsible use of cyberspace. They also support the implementation of…
5th meeting Plenary Session— Nigeria, speaking on behalf of the African Group, reaffirmed that international law, including the UN Charter, applies to the use of ICTs and remains essential to maintaining international peace, security, and stability….
African perspective: Cybersecurity and cyber diplomacy— Collaborative actions to safeguard cyberspace are pivotal for maintaining human rights and guaranteeing a stable and secure international milieu. Given the worldwide scope of the internet, aspiring policy solutions and p…
UNSC meeting: Regional arrangements for peace— Ethiopia:Thank you, Mr. President, for giving me the floor. We thank Brazil for organizing this important open debate on the topic of the contributions of regional mechanisms for peace and security. I also wish to thank …
Welcome to the IGF2021 Final report!— It was noted thatcyber norms should continue to be developed at the UNwith more systemic involvement of other stakeholders as they can help build and implement the framework. It is especially crucial forunderrepresented …
2nd meeting – Plenary Session— The African group identifies capacity building as a strategic cross-cutting priority that requires sustainable, need-based support, particularly for developing countries. This is seen as essential for enabling all states…
Agenda item 5 : Day 4 Afternoon session— Capacity building must be needs-based and respectful of state sovereignty. Enhancing cyber resilience through capacity building directly aids in supporting states’ economic vitality and overarching prosperity. The appro…
Track one diplomacy— Track one diplomacy, despite scepticism due to non-state actors and digital communication, remains essential to the international system. Its main significance lies in its authority, as only state representatives can cre…
Future of International Cyber Diplomacy: Comprehensive Discussion Report— All speakers emphasize that the global mechanism cannot operate in isolation but must coordinate with other UN bodies, regional organizations, and existing processes to avoid fragmentation and maximize effectiveness.
WSIS women and girls trendsetters and action plan— This tension has clear policy background. WSIS and digital cooperation traditions emphasise multistakeholder collaboration, capacity development and practical exchange across actors[S104][S105]. At the same time, UN Wome…
Media Remuneration Policy Analysis Mitchell began by establishing her background and the context for CNTI’s work. Coming from 25 years at the Pew Research Center where she helped l…
A Clash of Professional Cultures: The David Kelly Affair— Finally, the following two quotes provide further background context in support of the policy-promoting rather than intelligence-sharing aims of the dossier. The first comes from an email from Danny Pruce (a Foreign Offi…
UN OEWG 2021-2025 10th substantive session— During thededicated stakeholder session, the need to “expand participation in the POC Directory and build capacity, especially for developing countries” was highlighted. Germany and France emphasized the “responsible use…
3rd meeting – Plenary Session— Dynamic expert-based discussions in thematic groups (Egypt) Expert briefings within the mechanism (Japan) Evidence-based forward-looking dialogue in DTG1 (Chile) Action-oriented mechanism with concrete outcomes (Kiribati…
4th meeting – Plenary Session— The role of Dedicated Thematic Groups (DTGs) in advancing the normative framework is referenced in[S101], where the African Group alludes to the discussion paper on stakeholder modality and dedicated thematic groups for …
(Day 5) General Debate – General Assembly, 79th session: afternoon session— The level of disagreement among speakers was moderate. While there were clear differences on some regional issues, there was also significant common ground on broader global challenges such as climate change and the need…
WSIS ActionLine C6 Enabling Environment— This question is critical because standard benchmarking frameworks are often designed with more developed or larger economies in mind. Small island developing states face unique geographic, financial, and infrastructural…
Presentation of outcomes to the plenary— The analysis presents a multifaceted discussion on the intersection of international policy and the distinct challenges Small Island Developing States (SIDs) face, underscoring the drawbacks of one-size-fits-all policies…
Philip J. Perinchief— Small states, in every sphere of natural and human activity, are negatively and disproportionately impacted by crises, when compared to their hegemonic, larger and stronger counterparts. This dissertation is a study not…
4th meeting – Plenary Session— A broad consensus emerged that the DTGs should serve as practical, action-oriented forums for advancing implementation of the normative framework. Romania stated that ‘the DTGs could play an important role in this respec…
3rd meeting – Plenary Session— The Dedicated Thematic Groups (DTGs) were widely seen as the primary vehicle for translating high-level threat discussions into practical, action-oriented outcomes, with calls for expert briefings, evidence-based dialogu…
A. Overview— 9.Roles of the diplomatic and technical POCs.The diplomatic and technical POCs are envisaged to have differentiated roles. Accordingly, diplomatic POCs would communicate with other diplomatic POCs and technical POCs woul…
IG entering the ‘premier league’ of global governance— The second is to foster policy coherence, i.e. to avoid duplication of efforts and to preserve policy coherence across the many initiatives, conferences, and events that take place.
Successes & challenges: cyber capacity building coordination | IGF 2023— Furthermore, the discussion emphasizes the importance of coordinating with multiple stakeholders or through bilateral interactions to maximize development impact. It highlights the need to reduce duplication and harmoniz…
Main Session on Future of Digital Governance | IGF 2023— Lastly, the importance of building upon existing principles in policy-making and creating new solutions was highlighted. The analysis emphasised the importance of incorporating established principles rather than continuo…
Agenda item 5 : Day 4 Morning session— Canada:Thank you, Mr. Chair. Canada welcomes the ongoing process towards the operationalization of the Global Points of Contact directory. Mr. Chair, Canada believes that an effective implementation is key to developing …
Dedicated stakeholder session— Capacity building was identified as a complementary aspect to CBMs, with a strategy needed to coordinate work with regional and sub-regional organizations. The involvement of multiple stakeholders, including academia, th…
UN OEWG 2021-2025 9th substantive session— Overall, these discussions reflect a collective emphasis on standardization, improved communication, and proactive use of the Global POC Directory to address cybersecurity challenges effectively. Unifying SummaryThe dis…
UN OEWG 2021-2025 10th substantive session— During thededicated stakeholder session, the need to “expand participation in the POC Directory and build capacity, especially for developing countries” was highlighted. Germany and France emphasized the “responsible use…
PERMANENT MISSION OF THE REPUBLIC OF' SINGAPORE— 37. During the fourth, fifth as well as informal sessions of the OEWG, States continued discussions on confidence-building measures (CBMs). States, reaffirming the cumulative and evolving framework for responsible Stat…
UN OEWG 2021-2025 10th substantive session— During thededicated stakeholder session, the need to “expand participation in the POC Directory and build capacity, especially for developing countries” was highlighted. Germany and France emphasized the “responsible use…
3rd meeting – Plenary Session— Dynamic expert-based discussions in thematic groups (Egypt) Expert briefings within the mechanism (Japan) Evidence-based forward-looking dialogue in DTG1 (Chile) Action-oriented mechanism with concrete outcomes (Kiribati…
4th meeting – Plenary Session— A broad consensus emerged that the DTGs should serve as practical, action-oriented forums for advancing implementation of the normative framework. Romania stated that ‘the DTGs could play an important role in this respec…
Opening of the session— Referenced non-paper on role of regional organizations with examples from ASEAN, African Union, ECOWAS, EU, Pacific Island Forum, OAS, and OSCE
2nd meeting – Plenary Session— Capacity building as a strategic priority, particularly for developing and small island states.Multiple delegations, especially from the African Group, the Pacific Islands Forum, and small island developing states, empha…
Masterclass#1— Kerry-Ann Barrett :I’m going to kind of just give I’m going to kind of just give up probably just a reflection on your question, Melanie because it’s often said that the CPMs aren’t determined in order of priority so is …
OEWG 2021-2025 third annual progress report (APR)— In addition to the Global CBMs listed above States have included the following as additional voluntary global CBMs: a) States voluntarily identify and consider CBMs appropriate to their specific contexts, and cooperate …
OEWG and Cybersecurity Negotiations at the United Nations— Mexico argued that the development of new CBMs should remain on a voluntary basis. Pakistan proposed to focus on new CBMs in areas such as capacity building, research in cybersecurity, exchange of best practices and addr…
Organisational session of the UN Global Mechanism on ICT security— Beyond the organisational session, the Global Mechanism will convene in different formats. It will hold substantive plenary sessions once a year during each biennial cycle, thefirst being scheduled for July 2026. Proce…
First substantive session of the UN Global Mechanism on cybersecurity— Global Mechanism on ICT Security It will hold substantive plenary sessions once a year during each biennial cycle, the first being scheduled for July 2026. The Global Mechanism will convene in different formats. The f…
Opening Session | Seventh OEWG Session on ICT Security — Chair:Thank the Under-Secretary-General for her pre-recorded remarks, and I think it’s important that we reflect on her statement. Distinguished delegates, I’m very delighted to see so many familiar faces in France and a…
WS #190 Securing critical infrastructure in cyber: Who and how?— Vladimir Radunovic: Yes, I actually wanted to connect to what our colleague mentioned. The context that we are discussing this is the UN agreement within the General Assembly, ultimately before, by all the states of…
CBMs as essential tools for preventing escalation and fostering trust – CBMs are indispensable for fostering trust, transparency, predictability and cooperation among states, contributing to international peace and security in cyberspace (NIgeria on behalf of African Group)
Arg. 1
Explanation
The African Group affirms that confidence-building measures are indispensable for fostering trust, transparency, predictability and cooperation among states. These measures contribute directly to international peace, security and stability in cyberspace.
Evidence
The African Group explicitly affirmed that CBMs are indispensable for fostering trust, transparency, predictability and cooperation among states, thereby contributing to international peace, security and stability in cyberspace .
Major Discussion Point
Major Discussion Point 1: The Role and Importance of Confidence-Building Measures (CBMs) in International ICT Security
African peace and security architecture as a model for cyber cooperation – African experience in conflict prevention and security cooperation, including through the African peace and security architecture, demonstrates the value of sustained dialogue and cooperative approaches relevant to cyberspace (NIgeria on behalf of African Group)
Arg. 2
Explanation
The African Group draws on the continent's experience in conflict prevention and security cooperation, including through the African peace and security architecture, as a model for cyber cooperation. The principles of sustained dialogue, effective communication channels and cooperative approaches are equally relevant to reducing the risk of misunderstanding and miscalculation in cyberspace.
Evidence
The African Group noted that African experience in conflict prevention and security cooperation, including through the African peace and security architecture, demonstrates the value of sustained dialogue, effective communication channels and cooperative approaches to addressing shared security challenges, and that these principles are equally relevant to strengthening confidence and reducing the risk of misunderstanding and miscalculation in cyberspace .
Major Discussion Point
Major Discussion Point 4: Regional Cooperation and the Role of Regional Organisations in CBM Implementation
Regional organisations play an important role in advancing CBMs – The global mechanism should strengthen coordination and complementarity between global and regional confidence-building initiatives and promote linkages between regional POC networks and the global directory (NIgeria on behalf of African Group)
Arg. 3
Explanation
The African Group underscores the important role of regional and sub-regional organisations in advancing confidence-building through dialogue, information sharing, cyber diplomacy and practical cooperation. The group encourages the global mechanism to strengthen coordination between global and regional initiatives and promote linkages between regional POC networks and the global directory.
Evidence
The African Group encouraged the global mechanism to strengthen coordination and complementarity between global and regional confidence-building initiatives, promote linkages between regional point-of-contact networks and the Global Point of Contact Directory, support regional cyber exercises and capacity building, and encourage the voluntary exchange of national experiences and good practices .
Major Discussion Point
Major Discussion Point 4: Regional Cooperation and the Role of Regional Organisations in CBM Implementation
Agreed with
ChileUruguayGhanaPhilippinesAfrican Union CommissionOSCEBosnia and HerzegovinaTongaGermany
on: Regional organisations play an important role in advancing CBMs and their experiences should inform global implementation
Capacity building as a strategic enabler for African countries – For African countries, capacity building is not an auxiliary issue; it is a strategic enabler for achieving a secure, resilient and inclusive digital future as digital transformation accelerates across the continent (NIgeria on behalf of African Group)
Arg. 4
Explanation
The African Group views capacity building as a strategic enabler rather than a secondary concern, essential for achieving a secure, resilient and inclusive digital future. As digital transformation accelerates across the continent, strengthening national and regional cyber capacity remains essential for states to prevent, detect, respond to and recover from cyber threats.
Evidence
The African Group stated that for African countries, capacity building is not an auxiliary issue but a strategic enabler for achieving a secure, resilient and inclusive digital future, and that strengthening national and regional cyber capacity remains essential to enabling states to prevent, detect, respond to and recover from cyber threats while advancing sustainable development in line with African Union Agenda 2063 and the Digital Transformation Strategy for Africa 2020-2030 .
Major Discussion Point
Major Discussion Point 6: Capacity Building as a Cross-Cutting Priority and Enabler of CBM Implementation
Agreed with
Tonga on behalf of Pacific Islands ForumIrelandChile Representative on behalf of Latin American groupPhilippinesBahamas on behalf of the CARICOMCosta RicaVietnamNigeriaMorocco
on: Capacity building is a cross-cutting priority and essential enabler for effective CBM implementation
Capacity building must be demand-driven, nationally owned and sustainable – Effective capacity building must be demand-driven, nationally owned, sustainable, and tailored to the specific needs and priorities of countries, respecting national sovereignty (NIgeria on behalf of African Group)
Arg. 5
Explanation
The African Group emphasises that effective capacity building must be demand-driven, nationally owned, sustainable and tailored to the specific needs and priorities of countries. It must also promote inclusive approaches through the meaningful participation of women, men, youth, academia, the technical community, civil society and the private sector.
Evidence
The African Group underscored that effective capacity building must be demand-driven, nationally owned, sustainable and tailored to the specific needs and priorities of countries, and must promote inclusive approaches through the meaningful participation of women, men, youth, academia, the technical community, civil society and the private sector, recognising that cybersecurity is a shared responsibility requiring all-of-society approaches .
Major Discussion Point
Major Discussion Point 6: Capacity Building as a Cross-Cutting Priority and Enabler of CBM Implementation
Agreed with
Bahamas on behalf of the CARICOMIraqNigeriaColombia
on: Capacity building must be demand-driven, nationally owned, sustainable and tailored to specific national needs
Need for a voluntary UN ICT Security Capacity Building Fund – The African Group encourages progress on practical initiatives including a Voluntary UN ICT Security Capacity Building Fund and a UN ICT Security Fellowship Programme for developing countries, particularly least developed countries and small island developing states (NIgeria on behalf of African Group)
Arg. 6
Explanation
The African Group encourages progress on a range of practical initiatives to support capacity building, including a Voluntary UN ICT Security Capacity Building Fund and a UN ICT Security Fellowship Programme. These initiatives should be designed to ensure efficiency, transparency and equitable access, with particular attention to least developed countries and small island developing states.
Evidence
The African Group encouraged progress on practical initiatives including the Global ICT Security Cooperation and Capacity Building Portal, the Point of Contact Directory, strengthened national CERTs, a Voluntary UN ICT Security Capacity Building Fund, and a UN ICT Security Fellowship Programme for developing countries with attention to least developed countries and small island developing states, designed to ensure efficiency, transparency and equitable access .
Major Discussion Point
Major Discussion Point 6: Capacity Building as a Cross-Cutting Priority and Enabler of CBM Implementation
Women's meaningful participation in cybersecurity – Effective capacity building must promote inclusive approaches through the meaningful participation of women, men and youth, recognising that cybersecurity is a shared responsibility requiring all-of-society approaches (NIgeria on behalf of African Group)
Arg. 7
Explanation
The African Group stresses that capacity building must promote inclusive approaches that ensure the meaningful participation of women, men and youth alongside academia, the technical community, civil society and the private sector. Cybersecurity is a shared responsibility requiring all-of-society approaches.
Evidence
The African Group stated that capacity building should promote inclusive approaches through the meaningful participation of women, men, youth, academia, the technical community, civil society and the private sector, recognising that cybersecurity is a shared responsibility requiring all-of-society approaches .
Major Discussion Point
Major Discussion Point 11: Inclusive Participation, Digital Divide and Small Island Developing States
CBMs as practical tools for de-escalation – CBMs allow states to build practical procedures during peacetime that can be directly utilised for de-escalation, communication and risk reduction during geopolitical crises (Israel)
Arg. 1
Explanation
Israel argues that CBMs serve as practical tools built during peacetime that can be directly utilised when geopolitical crises arise. They provide established procedures for de-escalation, communication and risk reduction before tensions escalate.
Evidence
Israel stated that CBMs allow states to build practical procedures during times of peace that can be directly utilised for de-escalation, communication and risk reduction during a geopolitical crisis .
Major Discussion Point
Major Discussion Point 1: The Role and Importance of Confidence-Building Measures (CBMs) in International ICT Security
Agreed with
NIgeria on behalf of African GroupAustraliaMalawiMozambiqueNorwayNorth MacedoniaCameroonCôte d'IvoireChair Egriselda López
on: CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace
Disagreed with
CubaGermanyNetherlands
on: Whether CBMs alone are sufficient or must be complemented by binding norms
DTGs should prioritise further developing and operationalising CBMs – The DTGs must prioritise further developing and operationalising CBMs, as they hold great potential for immediate positive impact and for generating beneficial momentum for the global mechanism (Israel)
Arg. 2
Explanation
Israel believes that CBMs hold great potential for immediate positive impact and for generating beneficial momentum for the global mechanism. Accordingly, the dedicated thematic groups must prioritise further developing and operationalising CBMs, including those highlighted by delegates during the session.
Evidence
Israel stated that CBMs hold great potential for immediate positive impact and for generating beneficial momentum for the global mechanism, and accordingly that the DTGs must also prioritise further developing and operationalising CBMs including those highlighted by delegates during the week .
Major Discussion Point
Major Discussion Point 3: Operationalisation of CBMs through Dedicated Thematic Groups (DTGs)
Agreed with
ArgentinaTonga on behalf of Pacific Islands ForumChileNorth MacedoniaMalaysiaGermany
on: DTGs should focus on practical, action-oriented work to operationalise CBMs rather than reproducing procedural disagreements
Global mechanism should harmonise with other multilateral and regional forums – The global mechanism's work should prioritise harmonising with other multilateral and regional forums and ensure that all outcomes are mutually reinforcing (Israel)
Arg. 3
Explanation
Israel emphasises that the global mechanism should prioritise harmonising its work with other multilateral and regional forums to ensure that all outcomes are mutually reinforcing. This includes Israel's own contributions to regional and inter-regional bodies such as the OECD, Council of Europe and Mediterranean Partnerships.
Evidence
Israel noted that it continues to contribute its national experience to regional and inter-regional bodies including the OECD, Council of Europe and the framework of the Mediterranean Partnerships, and stated that the global mechanism’s work should prioritise harmonising with other multilateral and regional forums to ensure all outcomes are mutually reinforcing .
Major Discussion Point
Major Discussion Point 5: Coherence and Avoiding Duplication Across Multiple Communication Channels and Mechanisms
Agreed with
VanuatuNetherlandsGermanyCameroonColombiaEuropean Union
on: Avoiding duplication across multiple communication channels and mechanisms is essential for coherence and effectiveness
CBMs as cross-cutting elements of the responsible state behaviour framework – CBMs are one of the most operational components of the framework for responsible state behaviour and should constitute a cross-cutting element running through all work of the dedicated thematic groups (Argentina)
Arg. 1
Explanation
Argentina views CBMs as one of the most operational components of the framework for responsible state behaviour, providing opportunities to respond to different mandates, identify common challenges and compile good practices. CBMs should constitute a cross-cutting element running through all of the work of the two dedicated thematic groups.
Evidence
Argentina stated that CBMs are one of the most operational components of the framework for responsible state behaviour and that CBMs should constitute a cross-cutting element running through all of the work of the two dedicated thematic groups .
Major Discussion Point
Major Discussion Point 1: The Role and Importance of Confidence-Building Measures (CBMs) in International ICT Security
DTG1 for operationalising CBMs and DTG2 for capacity building support – DTG1 could examine operationalisation of CBMs by exchanging national and regional experiences, while DTG2 could identify capacities required to support this operationalisation effort (Argentina)
Arg. 2
Explanation
Argentina proposes a division of labour between the two DTGs, with DTG1 examining the operationalisation of CBMs through exchanging national and regional experiences and developing practical guidance, while DTG2 identifies the capacities required to support this operationalisation effort. Both groups should work in a complementary manner.
Evidence
Argentina proposed that DTG1 could be an appropriate framework to examine the operationalisation of CBMs by exchanging national and regional experiences, developing practical guidance, strengthening interoperability between existing mechanisms and drafting recommendations on early warnings on ICT incidents, while DTG2 could contribute to identifying capacities required to support this operationalisation effort, including proposals to strengthen national capacities of contact points and promote voluntary exercises .
Major Discussion Point
Major Discussion Point 3: Operationalisation of CBMs through Dedicated Thematic Groups (DTGs)
Agreed with
IsraelTonga on behalf of Pacific Islands ForumChileNorth MacedoniaMalaysiaGermany
on: DTGs should focus on practical, action-oriented work to operationalise CBMs rather than reproducing procedural disagreements
DTGs should lead to practical outcomes and recommendations – Argentina hopes DTGs will establish themselves as spaces for technical work able to establish substantive recommendations and decisions on CBMs for consideration by the plenary, progressively working towards more interactive, results-focused dialogue (Argentina)
Arg. 3
Explanation
Argentina hopes the DTGs will establish themselves as spaces for technical work capable of producing substantive recommendations and decisions on CBMs for consideration by the plenary. This dynamic would allow plenary meetings to progressively work towards more interactive, results-focused dialogue where states can build consensus on concrete proposals.
Evidence
Argentina expressed hope that the DTGs would establish themselves as spaces for technical work able to establish substantive recommendations and decisions on CBMs for consideration by the plenary, and that these recommendations would be subsequently reviewed, fine-tuned and negotiated by states in the framework of plenary deliberations, allowing the plenary to progressively work towards more interactive and results-focused dialogue .
Major Discussion Point
Major Discussion Point 3: Operationalisation of CBMs through Dedicated Thematic Groups (DTGs)
Disagreed with
Tonga on behalf of Pacific Islands ForumRussian Federation
on: The role of the dedicated thematic groups (DTGs) — whether they should produce negotiated outcomes or remain technical exchange forums
Voluntary cyber exercises to build confidence and practical skills – Argentina supports continuing voluntary exercises, gradually fine-tuning their modalities and exchanging experiences that encourage practical use of the POC directory and other CBMs (Argentina)
Arg. 4
Explanation
Argentina supports continuing voluntary exercises to encourage the practical use of the POC directory and other CBMs, gradually fine-tuning their modalities and exchanging experiences. The success of the directory will depend not only on connectivity tests but on states acquiring the confidence required to use it as an effective channel for communication when circumstances require it.
Evidence
Argentina underscored that the success of the POC directory will not only depend on periodically carrying out connectivity tests or ping tests, but also on states acquiring the confidence required to use it as an effective channel for communication when circumstances require it, and expressed support for continuing voluntary exercises, gradually fine-tuning their modalities and exchanging experiences that encourage practical use .
Major Discussion Point
Major Discussion Point 8: Simulation Exercises, Training and Practical Cooperation Activities
Agreed with
Côte d'IvoireTongaAustraliaOSCEBotswanaThailand
on: Simulation exercises, regular training and practical cooperation activities are essential for building confidence before crises occur
109
WPM
632
Words
6 min
Time
CBMs as preventive diplomacy tools – CBMs are preventive diplomacy tools, not necessarily mechanisms actionable in real time to respond to incidents; bilateral technical direct cooperation is key during actual crises (Dominican Republic)
Arg. 1
Explanation
The Dominican Republic draws on regional experience to argue that CBMs are tools of preventive diplomacy rather than mechanisms actionable in real time during incidents. During an actual crisis involving ransomware against essential public services, bilateral technical direct cooperation proved to be the key response mechanism, while CBMs helped boost confidence and trust to engage and host technical assistance.
Evidence
The Dominican Republic noted that from experience with other directories, a designated contact point on paper is not the same as a focal point able to respond 24 hours a day, 365 days a year, and that when ransomware struck essential public services in the region, CBMs proved to be preventive diplomacy tools rather than real-time response mechanisms, with bilateral technical direct cooperation being key .
Major Discussion Point
Major Discussion Point 1: The Role and Importance of Confidence-Building Measures (CBMs) in International ICT Security
Disagreed with
CubaGhanaOSCEAfrican Union Commission
on: Whether regional CBM models should inform or be adopted as global benchmarks
115
WPM
583
Words
5 min
Time
CBMs as instruments for inclusive participation – For developing countries, CBMs are not merely diplomatic instruments but practical tools that enable more inclusive participation in the international ICT security framework (Cameroon)
Arg. 1
Explanation
Cameroon argues that for developing countries, CBMs go beyond diplomatic instruments and serve as practical tools that enable more inclusive participation in the international ICT security framework. They complement capacity-building efforts by creating the trust and predictability necessary for states to cooperate effectively, exchange information and respond collectively to shared challenges.
Evidence
Cameroon stated that for developing countries, CBMs are not merely diplomatic instruments but practical tools that enable more inclusive participation in the international ICT security framework, and that they complement capacity-building efforts by creating the trust and predictability necessary for states to cooperate effectively, exchange information and respond collectively to shared challenges .
Major Discussion Point
Major Discussion Point 1: The Role and Importance of Confidence-Building Measures (CBMs) in International ICT Security
Agreed with
NIgeria on behalf of African GroupIsraelAustraliaMalawiMozambiqueNorwayNorth MacedoniaCôte d'IvoireChair Egriselda López
on: CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace
POC Directory as a dynamic instrument for cooperation – The directory should evolve from a repository of contacts into a dynamic instrument for cooperation, with functionalities progressively enhanced to facilitate secure communication and voluntary information exchange (Cameroon)
Arg. 2
Explanation
Cameroon proposes that the POC directory should evolve beyond a static repository of contacts into a dynamic instrument for cooperation. Its functionalities could be progressively enhanced to facilitate secure communication, voluntary information exchange, consultations among points of contact and the sharing of good practices, ultimately contributing to building a genuine community of practice.
Evidence
Cameroon proposed that the directory should continue to evolve from a repository of contacts into a dynamic instrument for cooperation, with functionalities progressively enhanced to facilitate secure communication, voluntary information exchange, consultations among points of contacts and the sharing of good practices, and that over time it should contribute to building a genuine community of practice among points of contact .
Major Discussion Point
Major Discussion Point 2: The Global Points of Contact (POC) Directory – Implementation and Challenges
Agreed with
TongaIrelandNetherlandsAustraliaRussian FederationThailandAfrican Union CommissionArgentinaChair Egriselda López
on: The Global POC Directory is an important achievement that should be actively maintained, regularly tested and used in good faith as a complement to existing channels
Disagreed with
Russian FederationAustraliaGermany
on: The appropriate scope and use of the POC Directory — whether it should be used proactively for information exchange or reserved for crisis communication
Avoiding duplication between global and regional mechanisms – The global mechanism should facilitate exchanges of experience among member states and regional organisations through workshops and knowledge-sharing initiatives, avoiding duplication of what already functions elsewhere (Cameroon)
Arg. 3
Explanation
Cameroon recommends that the global mechanism facilitate exchanges of experience among member states and regional organisations through workshops and knowledge-sharing initiatives. Regional experiences, including those from Africa, can provide valuable lessons and contribute to strengthening global cooperation while avoiding duplication.
Evidence
Cameroon proposed that the global mechanism should facilitate exchanges of experience among member states and regional organisations through workshops and knowledge-sharing initiatives, noting that regional experiences including those from Africa can provide valuable lessons and contribute to strengthening global cooperation while avoiding duplication .
Major Discussion Point
Major Discussion Point 5: Coherence and Avoiding Duplication Across Multiple Communication Channels and Mechanisms
Agreed with
VanuatuIsraelNetherlandsGermanyColombiaEuropean Union
on: Avoiding duplication across multiple communication channels and mechanisms is essential for coherence and effectiveness
Voluntary exchange of national experiences and good practices – The global mechanism should encourage voluntary implementation guidance, practical communication tools, and capacity-building activities adapted to national circumstances, and continued dialogue on relationships between CBMs, international law and other pillars (Cameroon)
Arg. 4
Explanation
Cameroon recommends that the global mechanism encourage voluntary implementation guidance, practical communication tools and capacity-building activities adapted to national circumstances. Continued dialogue on the relationships between CBMs, international law and the other pillars of the framework can further enhance transparency and predictability among states.
Evidence
Cameroon proposed that the global mechanism should encourage voluntary implementation guidance, practical communication tools and capacity-building activities adapted to national circumstances, and that continued dialogue on relationships between CBMs, international law and the other pillars of the framework can further enhance transparency and predictability among states .
Major Discussion Point
Major Discussion Point 7: Transparency, Information Sharing and Voluntary Exchange of National Experiences
110
WPM
334
Words
3 min
Time
CBMs as complementary to binding norms – CBMs on their own do not guarantee the strictly peaceful use of ICTs; they are complementary to binding norms and must respect sovereignty and non-interference in internal affairs (Cuba)
Arg. 1
Explanation
Cuba argues that CBMs alone do not guarantee the strictly peaceful use of ICTs and are complementary to binding norms established within the UN framework. The voluntary nature of CBMs must prevail, and different phases of confidence building must respect sovereignty and the principle of non-interference in the internal affairs of states.
Evidence
Cuba stated that CBMs on their own do not guarantee the strictly peaceful use of ICTs and that the different phases for confidence building must respect sovereignty and the non-interference in the internal affairs of states, and that the voluntary nature of confidence-building measures must prevail .
Major Discussion Point
Major Discussion Point 1: The Role and Importance of Confidence-Building Measures (CBMs) in International ICT Security
Disagreed with
IsraelGermanyNetherlands
on: Whether CBMs alone are sufficient or must be complemented by binding norms
Regional CBMs should not be treated as single global models – Each region or sub-region has unique characteristics, and measures implemented at these levels cannot be considered single global models or benchmarks (Cuba)
Arg. 2
Explanation
Cuba emphasises that each region or sub-region has unique characteristics, and therefore measures implemented at these levels cannot be considered single global models or benchmarks. Closing the digital gap and ensuring universal, inclusive and non-discriminatory access to ICTs can also contribute to building confidence.
Evidence
Cuba stated that each region or sub-region has unique characteristics and that the measures implemented at these levels cannot be considered single global models or benchmarks, and that closing the digital gap and ensuring universal, inclusive and non-discriminatory access to information and knowledge through ICTs can contribute to building confidence .
Major Discussion Point
Major Discussion Point 4: Regional Cooperation and the Role of Regional Organisations in CBM Implementation
Disagreed with
GhanaOSCEAfrican Union CommissionDominican Republic
on: Whether regional CBM models should inform or be adopted as global benchmarks
Substantive dialogue within the mechanism as a CBM in itself – Ensuring information exchange and dialogue on the use of ICTs and international security in the global mechanism is in itself a CBM; these dialogues must be conducted with mutual respect and constructively (Cuba)
Arg. 3
Explanation
Cuba argues that ensuring information exchange and dialogue on the use of ICTs and international security within the global mechanism is itself a confidence-building measure. These dialogues must be conducted with mutual respect, constructively, and with consideration for the diversity of positions and different understandings of each of the five pillars.
Evidence
Cuba stated that ensuring information exchange and dialogue on the use of ICTs and international security in the global mechanism is in itself a CBM, and that all delegations should be able to continue to develop these dialogues within this framework with mutual respect, constructively, considering the diversity of positions and different understandings of each of the five pillars .
Major Discussion Point
Major Discussion Point 7: Transparency, Information Sharing and Voluntary Exchange of National Experiences
161
WPM
668
Words
4 min
Time
CBMs as voluntary and action-oriented cyber diplomacy tools – CBMs are action-oriented voluntary cyber diplomacy tools at the discretion of states that can help reduce tensions and the risk of miscalculation (Germany)
Arg. 1
Explanation
Germany characterises CBMs as action-oriented voluntary cyber diplomacy tools at the discretion of states that can help reduce tensions and the risk of miscalculation. Germany has been a consistent supporter of discussing and adopting CBMs that are concrete, action-oriented and voluntary in nature, building on consensus and focused on transparency, cooperation and stability between states.
Evidence
Germany stated that CBMs are action-oriented voluntary cyber diplomacy tools at the discretion of states that can help reduce tensions and the risk of miscalculation, and that Germany has been a consistent supporter of discussing and adopting CBMs that are concrete, action-oriented and voluntary in nature, that build on consensus and are focused on building transparency, cooperation and stability between states .
Major Discussion Point
Major Discussion Point 1: The Role and Importance of Confidence-Building Measures (CBMs) in International ICT Security
Disagreed with
CubaIsraelNetherlands
on: Whether CBMs alone are sufficient or must be complemented by binding norms
DTGs as forums for trust-building and learning – The global mechanism, especially the DTGs, provides an opportunity to develop ways to operationalise the CBM pillar in a practical way and can act as a forum for cross-regional learning (Germany)
Arg. 2
Explanation
Germany views the global mechanism, especially the DTGs, as providing an opportunity to develop ways to operationalise the CBM pillar in a practical way. The DTGs can act as a forum for cross-regional learning, and Germany echoes the value of cross-regional exchanges, partnerships and capacity building for CBM implementation as highlighted at a side event co-hosted with Ghana and the Dominican Republic.
Evidence
Germany stated that the global mechanism, especially the DTGs, provides an opportunity to develop ways to operationalise the CBM pillar in a practical way and can act as a forum for cross-regional learning, and echoed Ghana’s remarks on the side event co-hosted by Ghana, the Dominican Republic and Germany on regional best practices for the implementation of CBMs, which highlighted the practical, concrete value that CBMs can add in solving real-world policy challenges .
Major Discussion Point
Major Discussion Point 3: Operationalisation of CBMs through Dedicated Thematic Groups (DTGs)
Agreed with
IsraelArgentinaTonga on behalf of Pacific Islands ForumChileNorth MacedoniaMalaysia
on: DTGs should focus on practical, action-oriented work to operationalise CBMs rather than reproducing procedural disagreements
Concerns about repeated, bad-faith use of the directory – Germany reported receiving repetitive, identical messages from a certain state that did not take into account replies, which is not in line with the purpose of the UN POC Directory and does not represent responsible or sincere use (Germany)
Arg. 3
Explanation
Germany raised concerns about the misuse of the POC directory, reporting that its Cyber Security Agency received repetitive, identical messages from a certain state that did not take into account Germany's replies or recommended course of action. Germany characterised this as clearly not in line with the purpose of the UN POC directory and not representing responsible or sincere use.
Evidence
Germany reported that its Federal Foreign Office serves as the diplomatic POC and its Cyber Security Agency as the technical POC, and that despite initially replying in good faith and recommending an appropriate course of action, the technical POC continued receiving repeated identical requests from the same sender whilst not taking into account Germany’s replies, which Germany characterised as clearly not in line with the purpose of the UN POC directory and not representing responsible or sincere use .
Major Discussion Point
Major Discussion Point 2: The Global Points of Contact (POC) Directory – Implementation and Challenges
Disagreed with
Russian FederationAustraliaCameroon
on: The appropriate scope and use of the POC Directory — whether it should be used proactively for information exchange or reserved for crisis communication
POC Directory as complementary to, not replacing, existing channels – The strength and added value of the POC Directory are found in establishing lines of contact where these previously were unavailable or unclear; it should be a complementary tool, not a replacement for existing POC networks (Netherlands)
Arg. 4
Explanation
Germany argues that the POC directory is designed as a voluntary practical tool at the discretion of states, and that in addition to it there are established channels such as FIRST, the network of CERTs, CERT-to-CERT cooperation and law enforcement cooperation, as well as relevant existing regional POC networks. The POC directory should not replace those channels or other diplomatic channels appropriate for addressing strategic security concerns.
Evidence
Germany stated that the POC directory is designed as a voluntary practical tool at the discretion of states, and that in addition and in complementarity to it there are established channels such as FIRST, the network of CERTs, CERT-to-CERT or law enforcement cooperation, as well as relevant and existing regional POC networks, and that the POC network is not intended to and should not replace those channels or other diplomatic channels appropriate to address strategic security concerns .
Major Discussion Point
Major Discussion Point 5: Coherence and Avoiding Duplication Across Multiple Communication Channels and Mechanisms
Agreed with
VanuatuIsraelNetherlandsCameroonColombiaEuropean Union
on: Avoiding duplication across multiple communication channels and mechanisms is essential for coherence and effectiveness
on: The appropriate role and purpose of the Global POC Directory — whether it is a primary crisis communication tool or strictly a supplementary channel
123
WPM
438
Words
4 min
Time
CBMs built through dialogue and transparency – Trust is not something that can be declared by fiat; it is built by dialogue, transparency, predictability, and results-based cooperation (Côte d'Ivoire)
Arg. 1
Explanation
Côte d'Ivoire emphasises that trust cannot be declared by fiat but must be built through dialogue, transparency, predictability and results-based cooperation. The global mechanism must become the appropriate forum for this trust-building process.
Evidence
Côte d’Ivoire stated that trust is not something that can be declared by fiat but is built by dialogue, transparency, predictability and results-based cooperation .
Major Discussion Point
Major Discussion Point 1: The Role and Importance of Confidence-Building Measures (CBMs) in International ICT Security
Agreed with
NIgeria on behalf of African GroupIsraelAustraliaMalawiMozambiqueNorwayNorth MacedoniaCameroonChair Egriselda López
on: CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace
Regular simulation exercises under UN auspices – Côte d'Ivoire recommends regularly organising under UN auspices simulation exercises that bring together points of contact, national incident response teams and relevant authorities (Côte d'Ivoire)
Arg. 2
Explanation
Côte d'Ivoire recommends that the UN regularly organise simulation exercises that bring together points of contact, national incident response teams and relevant authorities. This is one of three concrete recommendations made by the delegation to strengthen CBM implementation.
Evidence
Côte d’Ivoire set out three recommendations, the first of which was to regularly organise under the auspices of the UN simulation exercises that bring together points of contact, national teams for responding to incidents and relevant authorities .
Major Discussion Point
Major Discussion Point 8: Simulation Exercises, Training and Practical Cooperation Activities
Agreed with
ArgentinaTongaAustraliaOSCEBotswanaThailand
on: Simulation exercises, regular training and practical cooperation activities are essential for building confidence before crises occur
122
WPM
274
Words
2 min
Time
Strong support for the POC Directory as a flagship achievement – Tonga strongly supports the Global Points of Contact Directory as the flagship practical achievement of the OEWG and commends UNODA for its continued operationalisation (Tonga)
Arg. 1
Explanation
Tonga strongly supports the Global Points of Contact Directory as the flagship practical achievement of the OEWG and commends UNODA for its continued operationalisation. Small states like Tonga particularly need trusted, predictable lines of communication between states when an incident strikes, as they do not maintain wide networks of diplomats tasked with cyber-related cooperation.
Evidence
Tonga stated that small states do not maintain wide networks of diplomats tasked with cyber-related cooperation, and that when an incident strikes, trusted, predictable lines of communication between states are needed, and therefore strongly supports the Global Points of Contact Directory as the flagship practical achievement of the OEWG, commending UNODA for its continued operationalisation .
Major Discussion Point
Major Discussion Point 2: The Global Points of Contact (POC) Directory – Implementation and Challenges
Agreed with
IrelandNetherlandsAustraliaRussian FederationThailandAfrican Union CommissionArgentinaCameroonChair Egriselda López
on: The Global POC Directory is an important achievement that should be actively maintained, regularly tested and used in good faith as a complement to existing channels
Pacific regional cooperation as a model for cyber incident response – CERT Tonga was established in 2016 and has worked within the Pacific Cyber Security Operational Network; when Tonga's health system was attacked, established relationships enabled rapid assistance and joint public attribution with Australia and New Zealand (Tonga)
Arg. 2
Explanation
Tonga presents its own experience as a concrete example of CBMs working in practice. CERT Tonga was established in 2016 and has worked within the Pacific Cyber Security Operational Network, building personal trust among incident responders. When Tonga's health system was attacked, established relationships enabled rapid assistance and ultimately a joint public attribution with Australia and New Zealand.
Evidence
Tonga noted that CERT Tonga was established by cabinet decision in 2016 among the first national CERTs in the Pacific and has worked within the Pacific Cyber Security Operational Network where regions’ incident responders share information and build personal trust, and that when its health system was attacked last year, established relationships with partners enabled rapid assistance and ultimately a joint public attribution with Australia and New Zealand .
Major Discussion Point
Major Discussion Point 4: Regional Cooperation and the Role of Regional Organisations in CBM Implementation
Agreed with
NIgeria on behalf of African GroupChileUruguayGhanaPhilippinesAfrican Union CommissionOSCEBosnia and HerzegovinaGermany
on: Regional organisations play an important role in advancing CBMs and their experiences should inform global implementation
Tonga's CERT as an example of CBMs working in practice – Tonga's experience with its health system attack demonstrated what CBMs look like when they work: relationships built before the crisis, exercised during it, and deepened after it (Tonga)
Arg. 3
Explanation
Tonga uses its own experience with a health system attack to illustrate what effective CBMs look like in practice. The key lesson is that relationships must be built before a crisis, exercised during it and deepened after it, rather than being established in the midst of an emergency.
Evidence
Tonga described its experience when its health system was attacked, noting that established relationships with partners enabled rapid assistance and ultimately a joint public attribution with Australia and New Zealand, and characterised this as what CBMs look like when they work: relationships built before the crisis, exercised during it and deepened after it .
Major Discussion Point
Major Discussion Point 8: Simulation Exercises, Training and Practical Cooperation Activities
on: Simulation exercises, regular training and practical cooperation activities are essential for building confidence before crises occur
Small states face unique challenges in CBM implementation – Small states do not maintain wide networks of diplomats tasked with cyber-related cooperation; when an incident strikes, trusted, predictable lines of communication between states are needed (Tonga)
Arg. 4
Explanation
Tonga highlights the unique challenges faced by small states in CBM implementation, noting that they do not maintain wide networks of diplomats tasked with cyber-related cooperation. This makes trusted, predictable lines of communication between states particularly critical when an incident strikes.
Evidence
Tonga stated that small states do not maintain wide networks of diplomats tasked with cyber-related cooperation, and that when an incident strikes, trusted, predictable lines of communication between states are needed .
Major Discussion Point
Major Discussion Point 11: Inclusive Participation, Digital Divide and Small Island Developing States
120
WPM
593
Words
5 min
Time
DTGs should focus on practical, technical work rather than procedural disagreements – DTGs should be used to identify needs, share practical experience, connect states with relevant expertise, and help match national and regional priorities with appropriate support, not become additional negotiating rooms (Tonga on behalf of Pacific Islands Forum)
Arg. 1
Explanation
The Pacific Islands Forum, speaking through Tonga, argues that DTGs should be used to identify needs, share practical experience, connect states with relevant expertise and help match national and regional priorities with appropriate support. They should not become additional negotiating rooms that reproduce the same procedural disagreements or simply repeat plenary discussions.
Evidence
Tonga on behalf of the Pacific Islands Forum stated that the DTGs should be used to identify needs, share practical experience, connect states with relevant expertise and help match national and regional priorities with appropriate support, and that they should not become additional negotiating rooms that reproduce the same procedural disagreements, nor simply repeat plenary discussions, with their value to be measured by whether they help countries make progress .
Major Discussion Point
Major Discussion Point 3: Operationalisation of CBMs through Dedicated Thematic Groups (DTGs)
on: DTGs should focus on practical, action-oriented work to operationalise CBMs rather than reproducing procedural disagreements
Disagreed with
ArgentinaRussian Federation
on: The role of the dedicated thematic groups (DTGs) — whether they should produce negotiated outcomes or remain technical exchange forums
Capacity building as foundational to all aspects of the mechanism's work – Capacity building is the enabler that underpins all aspects of the work; it is foundational to responding to threats, implementing norms, engaging meaningfully in international law discussions, and sustaining CBMs (Tonga on behalf of Pacific Islands Forum)
Arg. 2
Explanation
The Pacific Islands Forum argues that capacity building is the enabler that underpins all aspects of the mechanism's work, including responding to threats, implementing norms, engaging meaningfully in discussions of international law and sustaining CBMs. It should not be siloed but should remain a cross-cutting thread through all of the mechanism's work.
Evidence
Tonga on behalf of the Pacific Islands Forum stated that capacity building is the enabler that underpins all aspects of the work, that it is foundational to responding to threats, implementing norms, engaging meaningfully in the discussion of international law and sustaining confidence-building measures, and that it should not be siloed but should remain a cross-cutting thread through all of the mechanism’s work .
Major Discussion Point
Major Discussion Point 6: Capacity Building as a Cross-Cutting Priority and Enabler of CBM Implementation
Agreed with
NIgeria on behalf of African GroupIrelandChile Representative on behalf of Latin American groupPhilippinesBahamas on behalf of the CARICOMCosta RicaVietnamNigeriaMorocco
on: Capacity building is a cross-cutting priority and essential enabler for effective CBM implementation
Stakeholder engagement essential for capacity building – Meaningful capacity building depends on access to the expertise of the multi-stakeholder community, academia, civil society, the private sector and the technical community; stakeholders must be substantively included in both formal and informal settings (Tonga on behalf of Pacific Islands Forum)
Arg. 3
Explanation
The Pacific Islands Forum emphasises that meaningful capacity building depends on access to the expertise of the multi-stakeholder community, including academia, civil society, the private sector and the technical community. The Forum strongly supports the substantive inclusion of stakeholders in both formal and informal settings and supports the fullest possible use of expert briefings within the dedicated thematic groups.
Evidence
Tonga on behalf of the Pacific Islands Forum stated that member states consistently find the technical expertise of the multi-stakeholder community, academia, civil society, the private sector and the technical community to be of real and practical value, and that meaningful capacity building depends on access to that expertise, strongly supporting the substantive inclusion in both formal and informal settings and the fullest possible use of expert briefings within the dedicated thematic groups .
Major Discussion Point
Major Discussion Point 9: Stakeholder Engagement – Private Sector, Civil Society, Academia and Technical Community
Agreed with
IrelandAustraliaUruguayEuropean UnionDMUN Foundation
on: Stakeholder engagement from the private sector, civil society, academia and the technical community is important for effective CBM implementation
Pacific states should not be consistently disadvantaged by meeting times – Meeting times should be rotated so Pacific delegations are not consistently asked to participate in the middle of the night; an inclusive global mechanism must be inclusive not only in principle but in the practical design of its work (Tonga on behalf of Pacific Islands Forum)
Arg. 4
Explanation
The Pacific Islands Forum raises the practical concern that Pacific delegations are consistently asked to participate in meetings in the middle of the night due to time zone differences. The Forum calls for meeting times to be rotated and for hybrid modalities to be welcomed, arguing that an inclusive global mechanism must be inclusive not only in principle but in the practical design of its work.
Evidence
Tonga on behalf of the Pacific Islands Forum welcomed hybrid modalities for the DTGs but asked for meeting times to be rotated so Pacific delegations are not consistently asked to participate in the middle of the night, stating that an inclusive global mechanism must be inclusive not only in principle but in the practical design of its work .
Major Discussion Point
Major Discussion Point 11: Inclusive Participation, Digital Divide and Small Island Developing States
151
WPM
345
Words
2 min
Time
POC Directory as a complement, not replacement, to existing channels – The POC Directory should be used as a complement to existing channels of communication between states, not as a replacement or duplication of established diplomatic or technical channels (Ireland)
Arg. 1
Explanation
Ireland argues that the POC Directory should be used in good faith and as a complement to existing channels of communication between states. Ireland is open to exploring further development of the directory as more is learned from its use.
Evidence
Ireland stated that the POC Directory should be used in good faith and as a complement to existing channels of communication between states, and that Ireland is open to exploring further development of the POC Directory as more is learned from its use .
Major Discussion Point
Major Discussion Point 2: The Global Points of Contact (POC) Directory – Implementation and Challenges
Agreed with
NetherlandsGermanyAustraliaVanuatu
on: The POC Directory should complement, not replace, existing diplomatic and technical communication channels
on: The appropriate role and purpose of the Global POC Directory — whether it is a primary crisis communication tool or strictly a supplementary channel
Sharing national ICT-related information and protecting critical infrastructure – States must move forward on implementation of CBMs including by sharing national ICT-related information, exchanging experience on protecting critical infrastructure, and promoting information exchange and cooperation between states (Ireland)
Arg. 2
Explanation
Ireland argues that in addition to the POC Directory, states must move forward on implementation of other CBMs. This includes sharing national ICT-related information, exchanging experience on protecting critical infrastructure, promoting information exchange and cooperation, and organising regular seminars, workshops and training programmes on ICT security.
Evidence
Ireland stated that in addition to the POC Directory, states must move forward on implementation of other CBMs including by sharing national ICT-related information, exchanging experience on protecting critical infrastructure, promoting information exchange and cooperation and partnerships between states to strengthen ICT security capacity, and by organising regular seminars, workshops and training programmes on ICT security .
Major Discussion Point
Major Discussion Point 7: Transparency, Information Sharing and Voluntary Exchange of National Experiences
Expertise of stakeholders should play a strong role – The expertise and experience of stakeholders from academia, the technical community, civil society and the private sector should play a strong role in the CBM implementation process, with practical tools and best practices feeding engagement (Ireland)
Arg. 3
Explanation
Ireland argues that the expertise and experience of stakeholders from academia, the technical community, civil society and the private sector should play a strong role in the CBM implementation process. Practical tools, best practices and examples should feed engagement and allow CBMs to be reflected into national and regional structures.
Evidence
Ireland stated that the expertise and experience of stakeholders from academia, the technical community, civil society and the private sector should also play a strong role in the CBM implementation process, and that practical tools, best practices and examples should feed engagement and allow CBMs to be reflected into national and regional structures .
Major Discussion Point
Major Discussion Point 9: Stakeholder Engagement – Private Sector, Civil Society, Academia and Technical Community
Agreed with
AustraliaUruguayTonga on behalf of Pacific Islands ForumEuropean UnionDMUN Foundation
on: Stakeholder engagement from the private sector, civil society, academia and the technical community is important for effective CBM implementation
131
WPM
480
Words
4 min
Time
Need for simulation exercises within DTGs – In simulation exercises within DTGs, states could see how public-private partnerships could concretely benefit an open, free and secure cyberspace and help prevent and address incidents (Netherlands)
Arg. 1
Explanation
The Netherlands proposes that simulation exercises within DTGs could demonstrate how public-private partnerships can concretely benefit an open, free and secure cyberspace and help prevent and address incidents. In this manner, DTGs will offer the opportunity to discuss CBM operationalisation.
Evidence
The Netherlands stated that in simulation exercises within DTGs, states could see how public-private partnerships could concretely benefit an open, free and secure cyberspace and help prevent and address incidents taking place in cyberspace, and that in this manner DTGs will offer the opportunity to discuss CBM operationalisation .
Major Discussion Point
Major Discussion Point 3: Operationalisation of CBMs through Dedicated Thematic Groups (DTGs)
POC Directory as complementary to, not replacing, existing channels – The strength and added value of the POC Directory are found in establishing lines of contact where these previously were unavailable or unclear; it should be a complementary tool, not a replacement for existing POC networks (Netherlands)
Arg. 2
Explanation
The Netherlands argues that the strength and added value of the POC Directory lie in establishing lines of contact where these previously were unavailable or unclear. It should be viewed as a complementary tool to existing POC networks and channels of communication that already function appropriately, not as a replacement or duplication.
Evidence
The Netherlands stated that the strength and added value of the POC Directory are found in establishing lines of contact where these previously were unavailable or unclear, and that it should be looked at as a complementary tool to existing POC networks and channels of communication that already function appropriately, not as a replacement or a duplication .
Major Discussion Point
Major Discussion Point 5: Coherence and Avoiding Duplication Across Multiple Communication Channels and Mechanisms
Agreed with
VanuatuIsraelGermanyCameroonColombiaEuropean Union
on: Avoiding duplication across multiple communication channels and mechanisms is essential for coherence and effectiveness
Disagreed with
Russian FederationGermanyAustraliaIrelandVanuatu
on: The appropriate role and purpose of the Global POC Directory — whether it is a primary crisis communication tool or strictly a supplementary channel
Developing national positions on international law in cyberspace – The Netherlands encourages all member states and regional organisations to continue to develop national positions on how international law applies in cyberspace and make these views available to a wider public, to avoid miscommunication and miscalculation (Netherlands)
Arg. 3
Explanation
The Netherlands encourages all member states and regional organisations to continue developing national positions on how international law applies in cyberspace and to make these views available to a wider public. By openly and clearly communicating on how international law is interpreted in cyberspace, states can avoid miscommunication and miscalculation, leading to a more solid basis for establishing trust over time.
Evidence
The Netherlands encouraged all member states and regional organisations to continue to develop national positions on how international law applies in cyberspace and to make these views available to a wider public, stating that by openly and clearly communicating on how international law is interpreted in cyberspace, states avoid miscommunication and miscalculation, leading to a more solid basis to establish trust over time, and that the Netherlands stands ready to share its best practices with all member states in the process of developing their position .
Major Discussion Point
Major Discussion Point 7: Transparency, Information Sharing and Voluntary Exchange of National Experiences
Disagreed with
CubaIsraelGermany
on: Whether CBMs alone are sufficient or must be complemented by binding norms
122
WPM
424
Words
3 min
Time
Need for coherence across multiple communication channels – The international community is multiplying its channels of communication; Vanuatu requests that the directory be developed in deliberate awareness of the wider ecosystem, with clear guidance on which channels serve which purpose (Vanuatu)
Arg. 1
Explanation
Vanuatu raises the concern that the international community is multiplying its channels of communication, creating a burden for small administrations that must operate all of these channels at once, often through the same handful of officials. Vanuatu requests that the directory be developed in deliberate awareness of the wider ecosystem, with clear guidance on which channels serve which purpose and no duplication of what already functions elsewhere.
Evidence
Vanuatu noted that the international community is multiplying its channels of communication, including the Global Points of Contact Directory, the 24/7 network under the UN Convention against Cybercrime, bilateral relationships and regional arrangements, and that Vanuatu speaks from the standpoint of administrations that must operate all of these channels at once, often through the same handful of officials, requesting that the directory be developed in deliberate awareness of the wider ecosystem with clear guidance on which channels serve which purpose and no duplication of what already functions elsewhere .
Major Discussion Point
Major Discussion Point 5: Coherence and Avoiding Duplication Across Multiple Communication Channels and Mechanisms
Agreed with
IsraelNetherlandsGermanyCameroonColombiaEuropean Union
on: Avoiding duplication across multiple communication channels and mechanisms is essential for coherence and effectiveness
on: The appropriate role and purpose of the Global POC Directory — whether it is a primary crisis communication tool or strictly a supplementary channel
Transparency as a measure available to every state regardless of size – Vanuatu emphasises transparency as a measure available to every state regardless of size, encouraging the structured exchange of national information within the mechanism as routine practice that prevents misreading between states (Vanuatu)
Arg. 2
Explanation
Vanuatu emphasises transparency as a confidence-building measure available to every state regardless of size. Vanuatu has sought to be open about its national arrangements, legislative development and assessments of the threat environment, and encourages the structured exchange of such national information within the mechanism as routine practice that prevents misreading between states.
Evidence
Vanuatu emphasised transparency as a measure available to every state regardless of size, noting that Vanuatu has sought to be open about its national arrangements, legislative development including its data protection and privacy bill, and assessments of the threat environment, and encouraged the structured exchange of such national information within the mechanism not as a reporting burden but as routine practice that prevents misreading between states .
Major Discussion Point
Major Discussion Point 7: Transparency, Information Sharing and Voluntary Exchange of National Experiences
Importance of training and continuity for designated officials – Vanuatu supports regular communications exercises for the directory, sustained training for designated officials with attention to continuity as personnel change, and preservation of hybrid modalities so that distance never determines who participates (Vanuatu)
Arg. 3
Explanation
Vanuatu supports regular communications exercises for the directory and sustained training for designated officials, with particular attention to continuity as personnel change. The preservation of hybrid modalities is also important so that distance never determines who participates in building confidence.
Evidence
Vanuatu stated that measures on paper acquire meaning through practice, and supported regular communications exercises for the directory, sustained training for designated officials with attention to continuity as personnel change, and the preservation of hybrid modalities so that distance never determines who participates in building confidence .
Major Discussion Point
Major Discussion Point 8: Simulation Exercises, Training and Practical Cooperation Activities
Hybrid modalities essential for inclusive participation – Vanuatu supports the preservation of hybrid modalities so that distance never determines who participates in building confidence; accessibility is also a capacity-building issue (Vanuatu)
Arg. 4
Explanation
Vanuatu argues that hybrid modalities must be preserved so that distance never determines who participates in building confidence. This is particularly important for small island states whose officials may be unable to travel to participate in person.
Evidence
Vanuatu supported the preservation of hybrid modalities so that distance never determines who participates in building confidence .
Major Discussion Point
Major Discussion Point 11: Inclusive Participation, Digital Divide and Small Island Developing States
107
WPM
412
Words
4 min
Time
DTGs as platforms for exchanging national experiences and good practices – The dedicated thematic groups offer a valuable opportunity to go into further depth on international relations and the role of international organisations in effective implementation of CBMs, exchanging national experiences and good practices (Chile)
Arg. 1
Explanation
Chile views the dedicated thematic groups as valuable opportunities to go into further depth on discussions about international relations and the role of international organisations in the effective implementation of CBMs. These groups could be great spaces for exchanging national experiences, good practices and engaging in measures to strengthen cooperation in specific areas such as coordinated responses to cyber incidents.
Evidence
Chile stated that the dedicated thematic groups offer a valuable opportunity to go into further depth into discussions on the issue of international relations and the role of international organisations in the effective implementation of CBMs, and that these groups could be great spaces for exchanging national experiences and good practices and engaging in measures to work towards cooperation to strengthen these measures in specific areas such as coordinated responses to cyber incidents .
Major Discussion Point
Major Discussion Point 3: Operationalisation of CBMs through Dedicated Thematic Groups (DTGs)
Agreed with
IsraelArgentinaTonga on behalf of Pacific Islands ForumNorth MacedoniaMalaysiaGermany
on: DTGs should focus on practical, action-oriented work to operationalise CBMs rather than reproducing procedural disagreements
Cross-regional exchanges to avoid duplication and share lessons learned – The exchange of good practices between regional mechanisms could make meaningful contributions to strengthening CBM implementation globally, avoiding duplications and making the most of lessons learned in different contexts (Chile)
Arg. 2
Explanation
Chile believes that the exchange of good practices between regional mechanisms could make meaningful contributions to strengthening CBM implementation globally. This approach would avoid duplications and make the most of lessons learned in different contexts.
Evidence
Chile stated that the exchange of good practices between regional mechanisms could make meaningful contributions to strengthening the implementation of CBMs globally, avoiding duplications and making the most of lessons learned in different contexts .
Major Discussion Point
Major Discussion Point 4: Regional Cooperation and the Role of Regional Organisations in CBM Implementation
Agreed with
NIgeria on behalf of African GroupUruguayGhanaPhilippinesAfrican Union CommissionOSCEBosnia and HerzegovinaTongaGermany
on: Regional organisations play an important role in advancing CBMs and their experiences should inform global implementation
CBMs must address protection of critical infrastructure – The global mechanism must continue to engage in substantive discussions focused on identifying new opportunities to strengthen CBM implementation, including those geared towards protecting critical infrastructure and essential services (Chile)
Arg. 3
Explanation
Chile argues that the global mechanism must continue to engage in substantive discussions focused on identifying new opportunities to strengthen CBM implementation, including those geared towards protecting critical infrastructure and essential services. This is particularly important given the growing impact of cyber incidents on societies.
Evidence
Chile stated that the global mechanism must continue to engage in substantive discussions focused on identifying new opportunities to strengthen the implementation of CBMs, including those geared towards protecting critical infrastructure and essential services, given the growing impact of cyber incidents on societies .
Major Discussion Point
Major Discussion Point 10: Protecting Critical Infrastructure and Addressing Emerging Threats
129
WPM
846
Words
7 min
Time
DTG2 as the main platform for capacity building dialogue – The DTG on capacity building must be established as the main platform for dialogue on this issue within the global mechanism, playing a fundamental role as a space for strategic coordination to facilitate information exchange and articulate synergies (Chile Representative on behalf of Latin American group)
Arg. 1
Explanation
The Latin American group argues that the DTG on capacity building must be established as the main platform for dialogue on this issue within the global mechanism. It should play a fundamental role as a space for strategic coordination to facilitate the exchange of information and experience, articulate synergies between existing mechanisms and identify opportunities for cooperation that respond to the needs expressed by states.
Evidence
The Latin American group stated that the DTG on capacity building must be established as the main platform for dialogue on this issue within the framework of the global mechanism, playing a fundamental role as a space for strategic coordination to facilitate the exchange of information and experience, to articulate synergies between existing mechanisms and to identify opportunities for cooperation that can respond to the needs expressed by states .
Major Discussion Point
Major Discussion Point 6: Capacity Building as a Cross-Cutting Priority and Enabler of CBM Implementation
Agreed with
NIgeria on behalf of African GroupTonga on behalf of Pacific Islands ForumIrelandPhilippinesBahamas on behalf of the CARICOMCosta RicaVietnamNigeriaMorocco
on: Capacity building is a cross-cutting priority and essential enabler for effective CBM implementation
123
WPM
274
Words
2 min
Time
CBMs as valuable outcomes of the OEWG process – CBMs are among the most valuable outcomes of the OEWG process, demonstrating that even in a complex and rapidly evolving cyber environment, states can agree on practical measures to strengthen trust and improve communication (North Macedonia)
Arg. 1
Explanation
North Macedonia views CBMs as among the most valuable outcomes of the OEWG process, demonstrating that states can agree on practical measures even in a complex and rapidly evolving cyber environment. These measures help reduce misunderstanding, strengthen cooperation and lower the risk of unintended escalation, particularly during significant ICT incidents when timely communication between states is essential.
Evidence
North Macedonia stated that CBMs are among the most valuable outcomes of the OEWG process, demonstrating that even in a complex and rapidly evolving cyber environment, states can agree on practical measures and strengthen trust, improve communication and contribute to international peace and security, and that from its country, CBMs are practical tools that help reduce misunderstanding, strengthen cooperation and lower the risk of unintended escalation practically during significant ICT incidents when timely communication between states is essential .
Major Discussion Point
Major Discussion Point 1: The Role and Importance of Confidence-Building Measures (CBMs) in International ICT Security
Agreed with
NIgeria on behalf of African GroupIsraelAustraliaMalawiMozambiqueNorwayCameroonCôte d'IvoireChair Egriselda López
on: CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace
CBMs should be reflected in DTG work through sharing of national experiences – CBMs should be reflected in the work of the thematic groups through sharing of national experience, practical implementation approaches and good practices, while avoiding duplication of plenary discussions (North Macedonia)
Arg. 2
Explanation
North Macedonia looks forward to seeing CBMs reflected in the work of the thematic groups through the sharing of national experience, practical implementation approaches and good practices. This should be done while avoiding duplication of discussions taking place in the plenary session.
Evidence
North Macedonia stated that it looks forward to seeing CBMs reflected in the work of the thematic groups through the sharing of national experience, practical implementation approaches and good practices, while avoiding duplication of discussions taking place in the plenary session, and that such exchanges can help translate common commitment into effective action .
Major Discussion Point
Major Discussion Point 3: Operationalisation of CBMs through Dedicated Thematic Groups (DTGs)
Agreed with
IsraelArgentinaTonga on behalf of Pacific Islands ForumChileMalaysiaGermany
on: DTGs should focus on practical, action-oriented work to operationalise CBMs rather than reproducing procedural disagreements
125
WPM
271
Words
2 min
Time
Western Balkans Cyber Diplomacy Network as a regional initiative – The launch of the Western Balkans Cyber Diplomacy Network in 2025, supported by the German Federal Foreign Office, represents the region's shared commitment to addressing cross-border cyber challenges through dialogue and cooperation (Bosnia and Herzegovina)
Arg. 1
Explanation
Bosnia and Herzegovina highlights the launch of the Western Balkans Cyber Diplomacy Network in 2025 as a key milestone in regional cyber cooperation. Supported by the German Federal Foreign Office, the network represents the region's shared commitment to addressing cross-border cyber challenges through dialogue and cooperation.
Evidence
Bosnia and Herzegovina noted that a key milestone was the launch of the Western Balkans Cyber Diplomacy Network in 2025, an initiative supported by the German Federal Foreign Office, and that the network represents yet another example of the region’s shared commitment to addressing cross-border cyber challenges through dialogue and cooperation .
Major Discussion Point
Major Discussion Point 4: Regional Cooperation and the Role of Regional Organisations in CBM Implementation
Agreed with
NIgeria on behalf of African GroupChileUruguayGhanaPhilippinesAfrican Union CommissionOSCETongaGermany
on: Regional organisations play an important role in advancing CBMs and their experiences should inform global implementation
160
WPM
635
Words
4 min
Time
OSCE as the first regional organisation to develop cyber CBMs – The OSCE was the first regional organisation to develop cyber confidence-building measures and has many years of experience in practical implementation of its 16 CBMs, including through the Adopt-a-CBM initiative (OSCE)
Arg. 1
Explanation
The OSCE was the first regional organisation to develop cyber confidence-building measures and has many years of experience in their practical implementation. The OSCE's 16 CBMs are implemented through various mechanisms including regular updates from participating states, the Adopt-a-CBM initiative where states champion specific CBMs, and capacity building activities including scenario-based exercises.
Evidence
The OSCE stated that it was the first regional organisation to develop cyber confidence-building measures and has many years of experience in the practical implementation of its 16 CBMs, and that to date 26 OSCE participating states have adopted nine CBMs through the Adopt-a-CBM initiative, significantly contributing to the meaningful implementation of those CBMs .
Major Discussion Point
Major Discussion Point 4: Regional Cooperation and the Role of Regional Organisations in CBM Implementation
Agreed with
NIgeria on behalf of African GroupChileUruguayGhanaPhilippinesAfrican Union CommissionBosnia and HerzegovinaTongaGermany
on: Regional organisations play an important role in advancing CBMs and their experiences should inform global implementation
Disagreed with
CubaGhanaAfrican Union CommissionDominican Republic
on: Whether regional CBM models should inform or be adopted as global benchmarks
OSCE capacity building through scenario-based exercises – The OSCE delivers capacity building activities including trainings and workshops with scenario-based exercises that help participants understand the practical application of CBMs, which is usually well received (OSCE)
Arg. 2
Explanation
The OSCE delivers capacity building activities including trainings and workshops with scenario-based exercises that help participants understand the practical application of CBMs. These events are usually well received by participants and represent a concrete form of CBM implementation.
Evidence
The OSCE stated that a third form of implementation is capacity building activities, namely trainings and workshops delivered by the Secretariat, and that these events usually involve a scenario-based exercise which helps understanding the practical application of the CBMs and is usually well received by the participants .
Major Discussion Point
Major Discussion Point 8: Simulation Exercises, Training and Practical Cooperation Activities
on: Simulation exercises, regular training and practical cooperation activities are essential for building confidence before crises occur
152
WPM
355
Words
2 min
Time
CBMs provide practical tools for implementing agreed commitments – CBMs provide practical tools for implementing agreed commitments; mechanisms such as points of contact, dialogue, sharing of best practices and information sharing help reduce risk, prevent misunderstandings and contribute to stability and security in cyberspace (Norway)
Arg. 1
Explanation
Norway argues that CBMs provide practical tools for implementing agreed commitments, with mechanisms such as points of contact, dialogue, sharing of best practices and information sharing helping to reduce risk, prevent misunderstandings and contribute to stability and security in cyberspace. Norway's priority is to elaborate and strengthen implementation of the CBMs already agreed upon.
Evidence
Norway shared three points, the first being that CBMs provide practical tools for implementing agreed commitments, with mechanisms such as points of contact, dialogue, sharing of best practices and information sharing helping to reduce risk, prevent misunderstandings and contribute to stability and security in cyberspace .
Major Discussion Point
Major Discussion Point 1: The Role and Importance of Confidence-Building Measures (CBMs) in International ICT Security
Agreed with
NIgeria on behalf of African GroupIsraelAustraliaMalawiMozambiqueNorth MacedoniaCameroonCôte d'IvoireChair Egriselda López
on: CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace
123
WPM
240
Words
2 min
Time
OAS regional experience as a model for CBM implementation – Regional experience in the OAS shows the practical value of CBMs; Uruguay has designated and updated its technical contact points in the OAS framework since 2018 and participates in cooperation mechanisms such as CERT Americas (Uruguay)
Arg. 1
Explanation
Uruguay highlights the practical value of CBMs through its regional experience in the Organisation of American States. Since 2018, Uruguay has designated and updated its technical contact points in the OAS framework and participates actively in cooperation mechanisms such as CERT Americas, promoting the exchange of technical information and strengthening of state capacities.
Evidence
Uruguay stated that regional experience in the OAS shows the practical value of CBMs, and that since 2018, Uruguay has designated and updated its technical contact points in the framework of the OAS and is participating actively in cooperation mechanisms such as CERT Americas, where it is promoting the exchange of technical information including indicators, good practices and strengthening of capacities of states in the region .
Major Discussion Point
Major Discussion Point 4: Regional Cooperation and the Role of Regional Organisations in CBM Implementation
Agreed with
NIgeria on behalf of African GroupChileGhanaPhilippinesAfrican Union CommissionOSCEBosnia and HerzegovinaTongaGermany
on: Regional organisations play an important role in advancing CBMs and their experiences should inform global implementation
Public-private partnerships essential for critical infrastructure protection – Given that a significant part of critical information infrastructure is operated by non-governmental actors or is part of the supply chain, public-private partnerships are essential to strengthen prevention, early alerts and fighting malicious information (Uruguay)
Arg. 2
Explanation
Uruguay argues that public-private partnerships are essential to strengthen prevention, early alerts and fighting malicious information, given that a significant part of critical information infrastructure is operated by non-governmental actors or is part of the supply chain. The OAS experience emphasises the importance of combining transparency, communication between contact points, technical cooperation and dialogue with the private sector, academia and civil society.
Evidence
Uruguay stated that the experience of the OAS emphasises the importance of combining transparency, communication between contact points, technical cooperation and dialogue with the private sector, academia and civil society and the technical community, and that given that a significant part of critical information infrastructure is operated by non-governmental actors or is part of the supply chain, public-private partnerships are essential to strengthen prevention, early alerts, early warnings and fighting malicious information .
Major Discussion Point
Major Discussion Point 9: Stakeholder Engagement – Private Sector, Civil Society, Academia and Technical Community
Agreed with
IrelandAustraliaTonga on behalf of Pacific Islands ForumEuropean UnionDMUN Foundation
on: Stakeholder engagement from the private sector, civil society, academia and the technical community is important for effective CBM implementation
108
WPM
306
Words
3 min
Time
ECOWAS regional framework as a practical example – ECOWAS has developed a regional framework on cyber ICT confidence-building measures with Ghana's participation, establishing practical mechanisms including national diplomatic and technical points of contact (Ghana)
Arg. 1
Explanation
Ghana highlights the ECOWAS regional framework on cyber ICT confidence-building measures as a practical example of regional CBM implementation. The ECOWAS directive establishes practical mechanisms including national diplomatic and technical points of contact and information-sharing arrangements that strengthen cooperation and contribute to regional resilience.
Evidence
Ghana stated that drawing on international good practices and adapting them to regional realities, ECOWAS has developed a regional framework on cyber ICT confidence-building measures with the participation of Ghana, and that the ECOWAS directive establishes practical mechanisms including national diplomatic and technical points of contact and information-sharing arrangements that strengthen cooperation and contribute to regional resilience .
Major Discussion Point
Major Discussion Point 4: Regional Cooperation and the Role of Regional Organisations in CBM Implementation
Agreed with
NIgeria on behalf of African GroupChileUruguayPhilippinesAfrican Union CommissionOSCEBosnia and HerzegovinaTongaGermany
on: Regional organisations play an important role in advancing CBMs and their experiences should inform global implementation
Disagreed with
CubaOSCEAfrican Union CommissionDominican Republic
on: Whether regional CBM models should inform or be adopted as global benchmarks
101
WPM
375
Words
4 min
Time
CBMs as practical tools reducing misunderstanding – CBMs are practical tools for reducing the risk of misinterpretation, escalation and conflict in cyberspace, helping states build relationships and establish communication channels before a crisis occurs so that these channels can be used effectively during and after cyber incidents (Australia)
Arg. 1
Explanation
Malawi affirms that CBMs remain among the most practical and effective means of strengthening international peace and security in the use of ICTs. By promoting transparency, predictability and cooperation, they reduce misunderstandings and misperceptions while fostering the trust necessary for timely communication and coordinated responses to cyber incidents.
Evidence
Malawi stated that confidence-building measures remain among the most practical and effective means of strengthening international peace and security in the use of ICTs, and that by promoting transparency, predictability and cooperation, they reduce misunderstandings and misperceptions while fostering the trust necessary for timely communication and coordinated responses to cyber incidents .
Major Discussion Point
Major Discussion Point 1: The Role and Importance of Confidence-Building Measures (CBMs) in International ICT Security
Agreed with
NIgeria on behalf of African GroupIsraelAustraliaMozambiqueNorwayNorth MacedoniaCameroonCôte d'IvoireChair Egriselda López
on: CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace
POC Directory requires capacity building to be effective – Many states face institutional, technical and resource constraints affecting their ability to operationalise national points of contact; capacity building is indispensable for effective implementation (Philippines)
Arg. 1
Explanation
The Philippines emphasises that capacity building is indispensable for the effective implementation of CBMs, as many member states continue to face institutional, technical and resource constraints. These constraints affect their ability to operationalise national points of contact, participate in cyber exercises, exchange technical information and respond effectively to ICT-related incidents.
Evidence
The Philippines emphasised that capacity building is indispensable for the effective implementation of CBMs, and that many member states continue to face institutional, technical and resource constraints that affect their ability to operationalise national points of contact, participate in cyber exercises, exchange technical information and respond effectively to ICT-related incidents .
Major Discussion Point
Major Discussion Point 2: The Global Points of Contact (POC) Directory – Implementation and Challenges
Agreed with
NIgeria on behalf of African GroupTonga on behalf of Pacific Islands ForumIrelandChile Representative on behalf of Latin American groupBahamas on behalf of the CARICOMCosta RicaVietnamNigeriaMorocco
on: Capacity building is a cross-cutting priority and essential enabler for effective CBM implementation
ASEAN Regional CERT as a step toward regional cybersecurity posture – As ASEAN Chair in 2026, the Philippines welcomed progress in operationalising the ASEAN Regional CERT, an important step toward raising the regional cybersecurity posture through timely information sharing and coordinated incident response (Philippines)
Arg. 2
Explanation
The Philippines highlights the progress in operationalising the ASEAN Regional CERT as an important step toward raising the regional cybersecurity posture. Together with the implementation of the ASEAN Cybersecurity Cooperation Strategy 2026–2030, this initiative reinforces trusted relationships among competent authorities, improves regional preparedness and complements the work of the global mechanism.
Evidence
The Philippines stated that as ASEAN Chair in 2026, it welcomed the progress in operationalising the ASEAN Regional CERT, an important step toward raising the regional cybersecurity posture through timely information sharing, coordinated incident response and exchange of best practices, and that together with the implementation of the ASEAN Cybersecurity Cooperation Strategy 2026-2030, this initiative reinforced trusted relationships among competent authorities and improved regional preparedness .
Major Discussion Point
Major Discussion Point 4: Regional Cooperation and the Role of Regional Organisations in CBM Implementation
Agreed with
NIgeria on behalf of African GroupChileUruguayGhanaAfrican Union CommissionOSCEBosnia and HerzegovinaTongaGermany
on: Regional organisations play an important role in advancing CBMs and their experiences should inform global implementation
96
WPM
531
Words
6 min
Time
CARICOM priorities for capacity building – CARICOM highlights three regional priorities: cyber law and modern legal frameworks, sustained cyber capacity building for resilience and technical expertise, and critical infrastructure protection for small states with limited resources (Bahamas on behalf of the CARICOM)
Arg. 1
Explanation
CARICOM highlights three regional priorities for capacity building: cyber law and modern legal and regulatory frameworks, sustained cyber capacity building that develops resilience, technical expertise and a skilled workforce, and critical infrastructure protection for small states. The challenge for small states begins with the very ability to define, identify and classify critical infrastructure and extends to protecting it with limited resources.
Evidence
CARICOM highlighted three regional priorities: first, cyber law and modern legal and regulatory frameworks that enable states to address cybercrime, protect data and cooperate across borders; second, sustained cyber capacity building that develops resilience, technical expertise and a skilled workforce; and third, critical infrastructure protection for small states, noting that the challenge begins with the very ability to define, identify and classify critical infrastructure and extends to protecting it with limited resources .
Major Discussion Point
Major Discussion Point 6: Capacity Building as a Cross-Cutting Priority and Enabler of CBM Implementation
Agreed with
NIgeria on behalf of African GroupIraqNigeriaColombia
on: Capacity building must be demand-driven, nationally owned, sustainable and tailored to specific national needs
CARICOM faces persistent gaps despite progress – The 2025 OAS IDB Cybersecurity Report confirms both progress and challenges for CARICOM; persistent gaps in resources, workforce development and cross-sector coordination continue to expose the region to an increasingly complex threat environment (Bahamas on behalf of the CARICOM)
Arg. 2
Explanation
CARICOM acknowledges both progress and persistent challenges in its cybersecurity capacity. The 2025 OAS IDB Cybersecurity Report, based on the Oxford Cybersecurity Capacity Maturity Model, confirms that while the region has improved across all five dimensions since 2020, persistent gaps in resources, workforce development and cross-sector coordination continue to expose it to an increasingly complex threat environment.
Evidence
CARICOM noted that the 2025 OAS IDB Cybersecurity Report, based on the Oxford Cybersecurity Capacity Maturity Model, confirms both progress and challenges, and that the region has improved across all five dimensions of the model since 2020, yet persistent gaps in resources, workforce development and cross-sector coordination continue to expose it to an increasingly complex threat environment .
Major Discussion Point
Major Discussion Point 11: Inclusive Participation, Digital Divide and Small Island Developing States
Facilitating access to ICT security products and tools as a new CBM – Iran considers the proposal for a new CBM aimed at facilitating access by all states to ICT security products and tools to be particularly valuable, as it strengthens national capacities while simultaneously promoting cooperation, trust and confidence (Islamic Republic of Iran)
Arg. 1
Explanation
Iran considers the proposal for a new CBM aimed at facilitating access by all states to ICT security products and tools to be particularly valuable. This measure strengthens national capacities while simultaneously promoting cooperation, trust and confidence among states, reflecting the OEWG's recognition that capacity-building programmes are an important confidence-building measure.
Evidence
Iran noted that paragraph 47k of the OEWG Final Report reaffirms the importance of continuing discussions on the development and implementation of CBMs, and that states took note of a proposal for a new CBM aimed at facilitating access by all states to ICT security products and tools, which Iran considers particularly valuable as it strengthens national capacities while simultaneously promoting cooperation, trust and confidence among states .
Major Discussion Point
Major Discussion Point 10: Protecting Critical Infrastructure and Addressing Emerging Threats
115
WPM
459
Words
4 min
Time
Subsea cable infrastructure as a critical asset requiring international guidance – Tuvalu urges the mechanism to establish clear international guidance for the protection of subsea infrastructure, seeking an explicit CBM commitment from all member states to share best practices to safeguard this essential digital lifeline (Tuvalu)
Arg. 1
Explanation
Tuvalu urges the mechanism to establish clear international guidance for the protection of subsea infrastructure, which it describes as a vital digital artery. Tuvalu seeks an explicit CBM commitment from all member states and stakeholders to share best practices to safeguard this essential digital lifeline from both natural hazards and malicious cyber threats.
Evidence
Tuvalu noted that its developer subsea cable is a vital digital artery and urged the mechanism to establish clear international guidance for the protection of subsea infrastructure, seeking an explicit CBM commitment from all member states and stakeholders to share best practices to safeguard this essential digital lifeline from both natural hazards and malicious cyber threats .
Major Discussion Point
Major Discussion Point 10: Protecting Critical Infrastructure and Addressing Emerging Threats
Capacity building for small island developing states requires long-term investment – International cooperation must shift away from short-term external consulting and towards tangible long-term training of local technical teams; true confidence is established where every state possesses the sovereign ability to manage its own digital systems independently (Tuvalu)
Arg. 2
Explanation
Tuvalu argues that international cooperation must shift away from short-term external consulting and towards tangible long-term training of local technical teams. True confidence is established where every state, regardless of its size, possesses the sovereign ability to manage its own digital systems independently.
Evidence
Tuvalu stated that international cooperation must shift away from short-term external consulting and towards tangible long-term training of local technical teams, and that true confidence is established where every state, regardless of its size, possesses the sovereign ability to manage its own digital systems independently .
Major Discussion Point
Major Discussion Point 11: Inclusive Participation, Digital Divide and Small Island Developing States
Botswana's CERT and national cybersecurity strategy for critical infrastructure – Botswana has operationalised its national cybersecurity strategy and established the Botswana Computer Incident Response Team to coordinate incident management, issue threat advisories and safeguard national critical infrastructure (Botswana)
Arg. 1
Explanation
Botswana has taken steps to implement voluntary CBMs nationally, including operationalising its national cybersecurity strategy and establishing the Botswana Computer Incident Response Team under the Botswana Communications Regulatory Authority. This team coordinates incident management, issues threat advisories and safeguards national critical infrastructure.
Evidence
Botswana stated that it has operationalised its national cybersecurity strategy and established the Botswana Computer Incident Response Team under the Botswana Communications Regulatory Authority to coordinate incident management, issue threat advisories and safeguard national critical infrastructure, and has undertaken the development of a new system of designation and submission of national POCs across both diplomatic and technical levels to populate the POC directory .
Major Discussion Point
Major Discussion Point 10: Protecting Critical Infrastructure and Addressing Emerging Threats
Capacity building must address the digital divide – Global transparency initiatives must be paired with concrete technical assistance to address the digital divide; states should leverage regional and sub-regional platforms to strengthen operational mechanisms (Botswana)
Arg. 2
Explanation
Botswana argues that global transparency initiatives must be paired with concrete technical assistance to address the digital divide. States should leverage regional and sub-regional platforms to strengthen operational mechanisms, including direct state-to-state cooperation and critical infrastructure protection, as the most effective pathway towards building global trust and incident response readiness.
Evidence
Botswana stated that global transparency initiatives must be paired with concrete technical assistance to address the digital divide, and that states should be leveraging the regional and sub-regional platforms to strengthen operational mechanisms, including direct state-to-state cooperation and critical infrastructure protection, as this would provide the most effective pathway towards building global trust and incident response readiness .
Major Discussion Point
Major Discussion Point 11: Inclusive Participation, Digital Divide and Small Island Developing States
Botswana's national cybersecurity activities as CBM implementation – Botswana's recent internal cybersecurity activities reflect CBM implementation through formal public-private partnerships, threat intelligence sharing and academic collaboration, focusing on response readiness and workforce upskilling (Botswana)
Arg. 3
Explanation
Botswana describes its recent internal cybersecurity activities as reflecting CBM implementation through formal public-private partnerships, threat intelligence sharing and academic collaboration. These initiatives focus on response readiness and workforce upskilling to collaboratively ensure the security of Botswana's critical infrastructure.
Evidence
Botswana stated that recent internal cybersecurity activities reflect the implementation of CBMs through formal public-private partnerships, threat intelligence sharing and academic collaboration, focusing on response readiness and workforce upskilling to collaboratively ensure the security of Botswana’s critical infrastructure, and that the Botswana Communications Regulatory Authority has signed several memoranda of understanding with global cybersecurity firms delivering real-time intelligence on emerging threats and sharing best practices in cyber defence capabilities .
Major Discussion Point
Major Discussion Point 8: Simulation Exercises, Training and Practical Cooperation Activities
Agreed with
Côte d'IvoireArgentinaTongaAustraliaOSCEThailand
on: Simulation exercises, regular training and practical cooperation activities are essential for building confidence before crises occur
145
WPM
673
Words
5 min
Time
Challenges with dead contacts and misuse of the directory – The directory faces challenges including dead contacts, misinterpretation of objectives of technical POCs, and cases where capitals ignore requests for political reasons; around 48% of Russia's inquiries were responded to (Russian Federation)
Arg. 1
Explanation
The Russian Federation reports that the POC directory faces a number of challenges in its initial stages. These include dead contacts, misinterpretation of the objectives of technical POCs when designated authorised bodies to the directory, and cases where certain capitals simply ignore requests for political reasons. Russia reports that around 48% of its 2,576 inquiries in the past year were responded to.
Evidence
The Russian Federation provided statistics showing that there were 2,576 inquiries from Russian POCs in the past year, of which around 48% were responded to, attributing this to dead contacts, misinterpretation of the objectives of technical POCs, and cases where certain capitals simply ignore requests for political reasons, particularly those countries that make unsubstantiated accusations regarding the supposed involvement of other states in computer attacks .
Major Discussion Point
Major Discussion Point 2: The Global Points of Contact (POC) Directory – Implementation and Challenges
Disagreed with
GermanyAustraliaNetherlandsIrelandVanuatu
on: The appropriate role and purpose of the Global POC Directory — whether it is a primary crisis communication tool or strictly a supplementary channel
Need for universal participation in the directory – 125 states have joined the directory, which is positive, but all remaining member states should join by designating appropriate diplomatic and technical points of contact (Russian Federation)
Arg. 2
Explanation
The Russian Federation notes that 125 states have joined the POC directory, which it considers a positive indicator, but urges all remaining member states to join by designating appropriate diplomatic and technical points of contact. Russia credits the establishment of the directory to its own initiative and views it as the main practical outcome of the OEWG.
Evidence
The Russian Federation stated that 125 states have joined the directory, which is a positive indicator, but urged all remaining member states to join the directory by designating appropriate diplomatic and technical points of contact .
Major Discussion Point
Major Discussion Point 2: The Global Points of Contact (POC) Directory – Implementation and Challenges
Agreed with
TongaIrelandNetherlandsAustraliaThailandAfrican Union CommissionArgentinaCameroonChair Egriselda López
on: The Global POC Directory is an important achievement that should be actively maintained, regularly tested and used in good faith as a complement to existing channels
Disagreed with
ArgentinaTonga on behalf of Pacific Islands Forum
on: The role of the dedicated thematic groups (DTGs) — whether they should produce negotiated outcomes or remain technical exchange forums
Need for standardised communication templates – A priority task is to finalise a standardised communication template to simplify cooperation between POCs by clearly defining the information needed for analysis of attacks and incidents (Russian Federation)
Arg. 3
Explanation
The Russian Federation argues that a priority task is to finalise a standardised communication template to simplify cooperation between POCs by clearly defining the information needed for the analysis of attacks and incidents. Russia notes that UNODA presented relevant considerations last year but there was not enough time for substantive discussion, and that Russia has specific drafts to contribute.
Evidence
The Russian Federation stated that the priority task is to finalise a standardised communication template that will simplify cooperation between POCs by clearly defining the information needed for the analysis of attacks and incidents, noting that UNODA presented relevant considerations last year but there was not enough time for a substantive discussion during the approval process for the OEWG’s final report, and that Russia has specific drafts in this regard .
Major Discussion Point
Major Discussion Point 2: The Global Points of Contact (POC) Directory – Implementation and Challenges
Disagreed with
AustraliaGermanyCameroon
on: The appropriate scope and use of the POC Directory — whether it should be used proactively for information exchange or reserved for crisis communication
145
WPM
647
Words
4 min
Time
CBMs as practical tools reducing misunderstanding – CBMs are practical tools for reducing the risk of misinterpretation, escalation and conflict in cyberspace, helping states build relationships and establish communication channels before a crisis occurs so that these channels can be used effectively during and after cyber incidents (Australia)
Arg. 1
Explanation
Australia argues that CBMs are practical tools for reducing the risk of misinterpretation, escalation and conflict in cyberspace. They help states build relationships, establish procedures and create channels of communication before a crisis occurs so that these channels can be used effectively during and after cyber incidents.
Evidence
Australia stated that CBMs are practical tools for reducing the risk of misinterpretation, escalation and conflict in cyberspace, and that they help states build relationships, establish procedures and create channels of communication before a crisis occurs so that these channels can be used effectively during and after cyber incidents .
Major Discussion Point
Major Discussion Point 1: The Role and Importance of Confidence-Building Measures (CBMs) in International ICT Security
Agreed with
NIgeria on behalf of African GroupIsraelMalawiMozambiqueNorwayNorth MacedoniaCameroonCôte d'IvoireChair Egriselda López
on: CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace
Need for the directory to be actively maintained and tested – For the POC Directory to remain useful, it should be actively maintained, regularly tested, and supported by clear expectations of good faith use; requests should be proportionate and purposeful (Australia)
Arg. 2
Explanation
Australia argues that for the POC Directory to remain useful, it should be actively maintained, regularly tested and supported by clear expectations of good faith use. Requests through the directory should be proportionate, purposeful and made with due regard to the capacity constraints of smaller states.
Evidence
Australia stated that for the POC Directory to remain useful, it should be actively maintained, regularly tested and supported by clear expectations of good faith use, and that requests through the directory should be proportionate, purposeful and made with due regard to the capacity constraints of smaller states, and should not be treated as a mechanism for overwhelming national points of contact or creating unreasonable expectations of response .
Major Discussion Point
Major Discussion Point 2: The Global Points of Contact (POC) Directory – Implementation and Challenges
Agreed with
IrelandNetherlandsGermanyVanuatu
on: The POC Directory should complement, not replace, existing diplomatic and technical communication channels
Disagreed with
Russian FederationGermanyCameroon
on: The appropriate scope and use of the POC Directory — whether it should be used proactively for information exchange or reserved for crisis communication
Cyber Rapid Assistance for Pacific Incidents and Disasters as a model – Australia's Cyber Rapid Assistance for Pacific Incidents and Disasters programme has an important role to play in building trust and habits of trust between states and regions; cooperation must be established before it is needed in a crisis (Australia)
Arg. 3
Explanation
Australia highlights its Cyber Rapid Assistance for Pacific Incidents and Disasters (Cyber Rapid) programme as an example of regional arrangements that play an important role in building trust and habits of trust between states and regions. The key principle is that cooperation must be established before it is needed in a crisis.
Evidence
Australia stated that regional arrangements including initiatives such as Australia’s Cyber Rapid Assistance for Pacific Incidents and Disasters, or Cyber Rapid, programme have an important role to play in building trust and habits of trust between states and regions, and that there needs to be a process of cooperation before they are needed in a crisis .
Major Discussion Point
Major Discussion Point 8: Simulation Exercises, Training and Practical Cooperation Activities
Agreed with
Côte d'IvoireArgentinaTongaOSCEBotswanaThailand
on: Simulation exercises, regular training and practical cooperation activities are essential for building confidence before crises occur
Industry and technical community closest to vulnerabilities and risks – Industry and the technical community, civil society and academia are often closest to vulnerabilities, incidents and emerging risks; their expertise can help states understand threats, improve prevention and response, and translate CBMs into practical action (Australia)
Arg. 4
Explanation
Australia underlines the importance of stakeholder engagement, arguing that industry and the technical community, civil society and academia are often closest to vulnerabilities, incidents and emerging risks. Their expertise can help states understand threats, improve prevention and response, strengthen supply chain resilience and translate CBMs into practical action while preserving the intergovernmental nature of decision-making.
Evidence
Australia stated that industry and the technical community, civil society and academia are often closest to vulnerabilities, incidents and emerging risks, and that their expertise can help states understand threats, improve prevention and response, strengthen supply chain resilience and translate CBMs into practical action while preserving the intergovernmental nature of decision-making .
Major Discussion Point
Major Discussion Point 9: Stakeholder Engagement – Private Sector, Civil Society, Academia and Technical Community
Agreed with
IrelandUruguayTonga on behalf of Pacific Islands ForumEuropean UnionDMUN Foundation
on: Stakeholder engagement from the private sector, civil society, academia and the technical community is important for effective CBM implementation
Cooperation on vulnerability disclosure and supply chain integrity – The global mechanism should help states operationalise practical CBMs that reduce risk and build resilience, including cooperation on vulnerability disclosure and mitigation, supply chain integrity and national capacity building (Australia)
Arg. 5
Explanation
Australia argues that the global mechanism should help states operationalise practical CBMs that reduce risk and build resilience. This includes cooperation on vulnerability disclosure and mitigation, supply chain integrity and national capacity building, recognising that for many states the ability to participate meaningfully in CBMs depends on having the right technical, policy and institutional foundations in place.
Evidence
Australia stated that the global mechanism should also help states operationalise other practical CBMs that reduce risk and build resilience, including cooperation on vulnerability disclosure and mitigation, supply chain integrity and national capacity building, and that for many states the ability to participate meaningfully in CBMs depends on having the right technical, policy and institutional foundations in place .
Major Discussion Point
Major Discussion Point 10: Protecting Critical Infrastructure and Addressing Emerging Threats
110
WPM
247
Words
2 min
Time
Support for communication checks and simulation exercises – Thailand supports regular communication checks, simulation exercises and continued engagement to ensure the directory remains effective when needed most (Thailand)
Arg. 1
Explanation
Thailand supports regular communication checks, simulation exercises and continued engagement to ensure that the POC directory remains effective when it is needed most. Thailand also considers the Template for Communication provided by the Secretariat as a useful tool to facilitate communication and assistance among POCs.
Evidence
Thailand stated that it supports regular communication checks, simulation exercises and continued engagement to ensure that the directory remains effective when it is needed the most, and considers the Template for Communication example provided by the Secretariat pursuant to A79-14 as a useful tool to facilitate communication and assistance among POCs .
Major Discussion Point
Major Discussion Point 2: The Global Points of Contact (POC) Directory – Implementation and Challenges
Agreed with
Côte d'IvoireArgentinaTongaAustraliaOSCEBotswana
on: Simulation exercises, regular training and practical cooperation activities are essential for building confidence before crises occur
Dialogue within the OEWG and global mechanism as constructive CBMs – Thailand considers substantive dialogue within the OEWG and the ongoing discussion in the global mechanism to be constructive CBMs in themselves, recognising the vital role of the UN in supporting global implementation (Thailand)
Arg. 2
Explanation
Thailand considers the substantive dialogue within the OEWG and the ongoing discussion in the global mechanism to be constructive CBMs in themselves. Thailand recognises the vital role of the UN in supporting the global implementation of CBMs.
Evidence
Thailand stated that it considers the substantive dialogue within the OEWG and the ongoing discussion in the global mechanism to be constructive CBMs in themselves, and recognises the vital role of the UN in supporting the global implementation of CBMs .
Major Discussion Point
Major Discussion Point 7: Transparency, Information Sharing and Voluntary Exchange of National Experiences
98
WPM
338
Words
3 min
Time
DTGs as platforms for exchanging national experiences and good practices – The dedicated thematic groups offer a valuable opportunity to go into further depth on international relations and the role of international organisations in effective implementation of CBMs, exchanging national experiences and good practices (Chile)
Arg. 1
Explanation
Malaysia sees the DTGs as an important platform for turning agreed CBMs into practical action. By identifying state capacity-building needs and facilitating access to relevant expertise and support, DTGs can help ensure that capacity-building efforts are responsive to national needs and strengthen the implementation of agreed CBMs.
Evidence
Malaysia stated that it sees the DTG as an important platform for turning agreed confidence-building measures into practical action, and that by identifying state capacity-building needs and facilitating access to relevant expertise and support, DTG can help ensure that capacity-building efforts are responsive to national needs and strengthen the implementation of the agreed CBMs .
Major Discussion Point
Major Discussion Point 3: Operationalisation of CBMs through Dedicated Thematic Groups (DTGs)
Agreed with
IsraelArgentinaTonga on behalf of Pacific Islands ForumChileNorth MacedoniaGermany
on: DTGs should focus on practical, action-oriented work to operationalise CBMs rather than reproducing procedural disagreements
106
WPM
385
Words
4 min
Time
African Union developing adapted CBMs for African realities – The African Union Commission is developing concrete measures adapted to African realities that can be effectively implemented in the various regions of the continent, drawing on experience from economic and regional committees (African Union Commission)
Arg. 1
Explanation
The African Union Commission is committed to developing concrete measures adapted to African realities that can be effectively implemented in the various regions of the continent. The ambition is not to reproduce existing models or multiply the number of CBMs, but to set out concrete, adapted measures drawing on experience from economic and regional committees such as ECOWAS.
Evidence
The African Union Commission stated that its ambition is not to reproduce existing models and not to multiply the number of confidence-building measures, but to set out concrete, adapted measures adapted to African realities that can be effectively implemented in the various regions of the continent, drawing on experience gained in economic and regional committees, in particular ECOWAS, and on best practices developed by other international organisations .
Major Discussion Point
Major Discussion Point 4: Regional Cooperation and the Role of Regional Organisations in CBM Implementation
Agreed with
NIgeria on behalf of African GroupChileUruguayGhanaPhilippinesOSCEBosnia and HerzegovinaTongaGermany
on: Regional organisations play an important role in advancing CBMs and their experiences should inform global implementation
Disagreed with
CubaGhanaOSCEDominican Republic
on: Whether regional CBM models should inform or be adopted as global benchmarks
Importance of integrating regional POC networks with the global directory – The global mechanism should facilitate the integration of regional points of contact with the global POC directory to strengthen coherence and complementarity (African Union Commission)
Arg. 2
Explanation
The African Union Commission recommends that the global mechanism facilitate the integration of regional points of contact with the global POC directory. This is one of three recommendations made to allow the global mechanism to support and strengthen the work done by the African Union.
Evidence
The African Union Commission set out three recommendations for the global mechanism, the third of which was to facilitate the integration of the regional points of contact with the global POC directory .
Major Discussion Point
Major Discussion Point 2: The Global Points of Contact (POC) Directory – Implementation and Challenges
on: The Global POC Directory is an important achievement that should be actively maintained, regularly tested and used in good faith as a complement to existing channels
89
WPM
458
Words
5 min
Time
Voluntary exchange of national cybersecurity strategies and risk assessments – States should share on a voluntary basis their national experience in terms of cybersecurity strategy, protection of essential infrastructure, risk management and response to incidents, fostering mutual trust and understanding (Democratic Republic of Congo)
Arg. 1
Explanation
The Democratic Republic of Congo encourages states to share on a voluntary basis their national experience in terms of cybersecurity strategy, protection of essential infrastructure, risk management and response to incidents. This voluntary exchange can foster mutual trust and understanding among states.
Evidence
The Democratic Republic of Congo encouraged states to share on a voluntary basis their national experience in terms of cybersecurity strategy, the protection of essential infrastructure, risk management and response to incidents, noting that this can foster mutual trust and understanding among states .
Major Discussion Point
Major Discussion Point 7: Transparency, Information Sharing and Voluntary Exchange of National Experiences
Multilingualism as a guarantor of inclusivity – The DRC joins the call to promote multilingualism as a guarantor of inclusivity in negotiation spaces, ensuring effective participation by everyone and the best results in the involvement of everyone (Democratic Republic of Congo)
Arg. 2
Explanation
The Democratic Republic of Congo joins the call to promote multilingualism as a guarantor of inclusivity in negotiation spaces. Multilingualism ensures the effective participation of everyone and the best results in the involvement of all parties.
Evidence
The Democratic Republic of Congo joined the call sounded by Colombia and Mexico to promote multilingualism as a guarantor of inclusivity in spaces for negotiation, stating that it has ensured the effective participation by everyone and the best results in the involvement of everyone .
Major Discussion Point
Major Discussion Point 11: Inclusive Participation, Digital Divide and Small Island Developing States
119
WPM
664
Words
6 min
Time
Coordination between global roundtable and DTGs – The global roundtable on capacity building could play a role in ensuring enhanced coordination and cooperation, bringing together capacity building implementers for exchange of information and best practices, feeding into plenary and DTG2 discussions (European Union)
Arg. 1
Explanation
The European Union proposes that the global roundtable on capacity building could play a role in ensuring enhanced coordination and cooperation by bringing together capacity building implementers for exchange of information and best practices. This would feed into discussions in the plenary and DTG2, with the EU aiming to avoid duplication between these different forums.
Evidence
The European Union stated that the global roundtable on capacity building could play a role in ensuring enhanced coordination and cooperation, for instance by bringing together capacity building implementers for exchange of information and best practices, feeding into the discussions in the plenary and DTG2, and that the EU and its member states will aim to avoid duplication with discussions between the plenary, DTG2 and the global roundtable and pursue a streamlined approach .
Major Discussion Point
Major Discussion Point 5: Coherence and Avoiding Duplication Across Multiple Communication Channels and Mechanisms
Agreed with
VanuatuIsraelNetherlandsGermanyCameroonColombia
on: Avoiding duplication across multiple communication channels and mechanisms is essential for coherence and effectiveness
EU investment in cybercapacity building globally – The EU is working with partners on 27 projects with a value of 100 million euros and will continue to invest, recognising capacity building as an essential pillar of security and stability in cyberspace (European Union)
Arg. 2
Explanation
The European Union highlights its significant investment in cybercapacity building, noting that it is currently working with partners on 27 projects with a value of 100 million euros. The EU will continue to invest, recognising capacity building as an essential pillar of security and stability in cyberspace and of its partnerships.
Evidence
The European Union stated that it has significantly invested in cybercapacity building over recent years and will continue to do so, noting that in addition to EU member states’ individual projects and initiatives such as the Global Gateway, the EU is working with partners on 27 projects with a value of 100 million euros, and will continue to invest, recognising capacity building as an essential pillar of security and stability in cyberspace .
Major Discussion Point
Major Discussion Point 6: Capacity Building as a Cross-Cutting Priority and Enabler of CBM Implementation
Multi-stakeholder community role in designing and delivering capacity building – The role of the multi-stakeholder community in the design and delivery of cybercapacity building should be further discussed, recognising that industry, civil society and academia contribute meaningfully to effective and sustainable capacity building (European Union)
Arg. 3
Explanation
The European Union argues that the role of the multi-stakeholder community in the design and delivery of cybercapacity building should be further discussed. The EU and member states will continue to promote coordination and cooperation with international organisations and other stakeholders such as industry, civil society, education and academia to ensure meaningful allocation of scarce resources and deliver capacity building activities in an effective and sustainable manner.
Evidence
The European Union stated that further discussions could include the role of the multi-stakeholder community in the design and delivery of cybercapacity building, and that the EU and member states will continue to promote coordination and cooperation including with international organisations and other stakeholders such as industry, civil society and academia to ensure meaningful allocation of scarce resources and deliver capacity building activities in an effective and sustainable manner .
Major Discussion Point
Major Discussion Point 9: Stakeholder Engagement – Private Sector, Civil Society, Academia and Technical Community
Agreed with
IrelandAustraliaUruguayTonga on behalf of Pacific Islands ForumDMUN Foundation
on: Stakeholder engagement from the private sector, civil society, academia and the technical community is important for effective CBM implementation
Youth engagement as a practical confidence-building measure – Member states should consider youth engagement as a practical CBM, including structured dialogues between governments and youth, support for youth-led cyber awareness initiatives, and opportunities for young experts to participate in regional and international CBM activities (DMUN Foundation)
Arg. 1
Explanation
The DMUN Foundation argues that confidence in cyberspace cannot exist solely between governments but must extend to the people who use digital technologies every day, especially young people. Member states should consider youth engagement as a practical CBM, including structured dialogues, support for youth-led cyber awareness initiatives and opportunities for young experts to participate in regional and international CBM activities.
Evidence
The DMUN Foundation stated that today’s youth are the first generation to grow up in an environment where cyber incidents, online disinformation and AI-generated content are part of everyday life, and despite being among the most affected stakeholders, young people are rarely included in discussions on how trust and confidence in cyberspace should be built, and therefore encouraged member states to consider youth engagement as a practical CBM including structured dialogues between governments and youth, support for youth-led cyber awareness initiatives and opportunities for young experts to participate in regional and international CBM activities .
Major Discussion Point
Major Discussion Point 9: Stakeholder Engagement – Private Sector, Civil Society, Academia and Technical Community
Agreed with
IrelandAustraliaUruguayTonga on behalf of Pacific Islands ForumEuropean Union
on: Stakeholder engagement from the private sector, civil society, academia and the technical community is important for effective CBM implementation
125
WPM
274
Words
2 min
Time
Capacity building as a bridge between consensus and action – Capacity building is a bridge between consensus and action; voluntary norms, international law, CBMs and due diligence can only be turned into policies and practical steps if states have technical, legal and institutional capacities (Costa Rica)
Arg. 1
Explanation
Vietnam strongly believes that capacity building is essential to international cooperation in ICT security. Through capacity building, states may develop common understanding of voluntary norms of responsible state behaviour and shared experiences and best practices in applying these norms to protect critical infrastructure and supply chains.
Evidence
Vietnam stated that through capacity building, states may develop common understanding of voluntary, non-binding norms of responsible state behaviour, shared experiences and best practices in applying these norms to protect critical infrastructure and supply chains, and to ensure cyber hygiene and security by design .
Major Discussion Point
Major Discussion Point 6: Capacity Building as a Cross-Cutting Priority and Enabler of CBM Implementation
Agreed with
NIgeria on behalf of African GroupTonga on behalf of Pacific Islands ForumIrelandChile Representative on behalf of Latin American groupPhilippinesBahamas on behalf of the CARICOMCosta RicaNigeriaMorocco
on: Capacity building is a cross-cutting priority and essential enabler for effective CBM implementation
Capacity building requires financial and technical support for equal opportunities – Capacity building should get financial and technical support so that equal opportunities are available to all states to benefit from international programmes and initiatives, with special attention to developing countries and countries emerging from conflict (Iraq)
Arg. 1
Explanation
Iraq stresses the importance of providing financial and technical support for capacity building so that equal opportunities are available to all states to benefit from international programmes and initiatives. Special attention should be given to the needs of developing countries and countries emerging from conflict.
Evidence
Iraq stated that capacity building should get financial and technical support so that equal opportunities be available to all states to benefit from international programmes and initiatives, and that special attention should be given to the needs of developing countries and countries emerging from conflict in a manner that enables such countries to implement the international framework of responsible state behaviour .
Major Discussion Point
Major Discussion Point 6: Capacity Building as a Cross-Cutting Priority and Enabler of CBM Implementation
Agreed with
NIgeria on behalf of African GroupBahamas on behalf of the CARICOMNigeriaColombia
on: Capacity building must be demand-driven, nationally owned, sustainable and tailored to specific national needs
112
WPM
503
Words
4 min
Time
Capacity building initiatives should avoid duplication and maximise resources – The mechanism offers the right platform to identify ongoing initiatives, generate complementarity between them, and engage in more effective coordination based on the needs and priorities of different states (Colombia)
Arg. 1
Explanation
Colombia argues that avoiding duplication of efforts and maximising available resources is a priority. The mechanism offers the right platform to identify initiatives that are currently ongoing, generate complementarity between them and engage in more effective coordination based on the needs and priorities of different states.
Evidence
Colombia stated that for it, it is a priority to avoid duplication of efforts and to maximise the resources available, and that the mechanism offers the right platform to identify initiatives that are currently ongoing, to generate complementarity between them and to engage in more effective coordination based on the needs and priorities of different states .
Major Discussion Point
Major Discussion Point 5: Coherence and Avoiding Duplication Across Multiple Communication Channels and Mechanisms
Agreed with
VanuatuIsraelNetherlandsGermanyCameroonEuropean Union
on: Avoiding duplication across multiple communication channels and mechanisms is essential for coherence and effectiveness
South-South and triangular cooperation as valuable modalities – Modalities like South-South cooperation and triangular cooperation can play a particularly valuable role in capacity building, facilitating the exchange of knowledge and good practices while taking account of local realities and priorities (Colombia)
Arg. 2
Explanation
Colombia argues that modalities like South-South cooperation and triangular cooperation can play a particularly valuable role in capacity building, as they facilitate the exchange of knowledge and good practices while taking account of local realities and priorities. These modalities leverage the comparative advantages and specialised experience of some states and regions.
Evidence
Colombia stated that it is essential to harness the comparative advantages and specialised experience of some states and regions to promote more effective cooperation tailored to the needs of beneficiary countries, and that modalities like South-South cooperation and triangular cooperation can play a particularly valuable role since they facilitate the exchange of knowledge and good practices, taking account of local realities and priorities .
Major Discussion Point
Major Discussion Point 6: Capacity Building as a Cross-Cutting Priority and Enabler of CBM Implementation
Agreed with
NIgeria on behalf of African GroupBahamas on behalf of the CARICOMIraqNigeria
on: Capacity building must be demand-driven, nationally owned, sustainable and tailored to specific national needs
119
WPM
412
Words
3 min
Time
Capacity building as a bridge between consensus and action – Capacity building is a bridge between consensus and action; voluntary norms, international law, CBMs and due diligence can only be turned into policies and practical steps if states have technical, legal and institutional capacities (Costa Rica)
Arg. 1
Explanation
Costa Rica argues that capacity building is a bridge between consensus and action, as voluntary norms, international law, CBMs and due diligence can only be turned into policies and practical steps if states have the necessary technical, legal and institutional capacities. Without capacities, there is a risk of building a legally elegant infrastructure that is operationally useless.
Evidence
Costa Rica stated that capacity building is a bridge between consensus and action, and that voluntary norms, international law, confidence-building measures, due diligence and national resilience can only be turned into policies and practical steps if states have technical, legal and institutional capacities that are up to the mark, warning that without capacities there is a risk of building a legally elegant infrastructure that is operationally useless .
Major Discussion Point
Major Discussion Point 6: Capacity Building as a Cross-Cutting Priority and Enabler of CBM Implementation
Agreed with
NIgeria on behalf of African GroupTonga on behalf of Pacific Islands ForumIrelandChile Representative on behalf of Latin American groupPhilippinesBahamas on behalf of the CARICOMVietnamNigeriaMorocco
on: Capacity building is a cross-cutting priority and essential enabler for effective CBM implementation
Capacity building priorities for developing countries – Nigeria believes DTG2 should prioritise strengthening national cybersecurity strategies, legal and governance frameworks, technical capabilities including CERTs, and expertise in cyber diplomacy, digital forensics and cybercrime investigations (Nigeria)
Arg. 1
Explanation
Nigeria believes DTG2 should prioritise a range of capacity building areas for developing countries, including strengthening national cybersecurity strategies, legal and governance frameworks, technical capabilities including CERTs, and expertise in cyber diplomacy, digital forensics and cybercrime investigations. Nigeria also attaches particular importance to practical cooperation among governments, regional organisations, academia, the private sector, civil society and the technical community.
Evidence
Nigeria stated that it believes DTG2 should prioritise strengthening national cybersecurity strategies, legal and governance frameworks, technical capabilities including CERTs, and expertise in cyber diplomacy, digital forensics, cybercrime investigations and the promotion of critical infrastructure and critical information infrastructure, and that as emerging technologies continue to evolve rapidly, capacity-building efforts should equally invest in cybersecurity education, digital skill development, research and innovation .
Major Discussion Point
Major Discussion Point 6: Capacity Building as a Cross-Cutting Priority and Enabler of CBM Implementation
Agreed with
NIgeria on behalf of African GroupBahamas on behalf of the CARICOMIraqColombia
on: Capacity building must be demand-driven, nationally owned, sustainable and tailored to specific national needs
Capacity building as a bridge between consensus and action – Capacity building is a bridge between consensus and action; voluntary norms, international law, CBMs and due diligence can only be turned into policies and practical steps if states have technical, legal and institutional capacities (Costa Rica)
Arg. 1
Explanation
Morocco argues that capacity building is not a secondary issue but the guiding thread that runs through all the other pillars of responsible behaviour. The credibility of the global mechanism hinges on the collective capacity to translate ideas into projects and projects into concrete results.
Evidence
Morocco stated that capacity building is not a secondary issue but the guiding thread that runs through all the other pillars of responsible behaviour, and that the credibility of the global mechanism largely hinges on the collective capacity to translate ideas into projects and projects into concrete results .
Major Discussion Point
Major Discussion Point 6: Capacity Building as a Cross-Cutting Priority and Enabler of CBM Implementation
Agreed with
NIgeria on behalf of African GroupTonga on behalf of Pacific Islands ForumIrelandChile Representative on behalf of Latin American groupPhilippinesBahamas on behalf of the CARICOMCosta RicaVietnamNigeria
on: Capacity building is a cross-cutting priority and essential enabler for effective CBM implementation
CBMs as practical tools reducing misunderstanding – CBMs are practical tools for reducing the risk of misinterpretation, escalation and conflict in cyberspace, helping states build relationships and establish communication channels before a crisis occurs so that these channels can be used effectively during and after cyber incidents (Australia)
Arg. 1
Explanation
Mozambique considers CBMs to be one of the most practical pillars of the global mechanism. For developing countries, CBMs should move beyond political commitments and translate into concrete mechanisms that strengthen confidence, reduce the risk of misunderstanding and miscalculation, and improve collective resilience against cyber threats.
Evidence
Mozambique stated that for developing countries, confidence-building measures should move beyond political commitments and translate into concrete mechanisms that strengthen confidence, reduce the risk of misunderstanding and miscalculation, and improve collective resilience against cyber threats .
Major Discussion Point
Major Discussion Point 1: The Role and Importance of Confidence-Building Measures (CBMs) in International ICT Security
Agreed with
NIgeria on behalf of African GroupIsraelAustraliaMalawiNorwayNorth MacedoniaCameroonCôte d'IvoireChair Egriselda López
on: CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace
The eight global CBMs and the POC Directory are important confidence-building tools that can strengthen cooperation and reduce misinterpretation – The Chair summarised that delegations reflected on the eight global measures, including information exchange, public-private collaboration and capacity building, and that the POC Directory is an important voluntary confidence-building tool (Chair Egriselda López)
Arg. 1
Explanation
The Chair summarised the discussion by noting that delegations had reflected on the eight global measures, which include information exchange measures such as sharing national strategies, legislation and good practices, collaboration between the public and private sector, and capacity building measures. She affirmed that the POC Directory is an important voluntary confidence-building tool that can strengthen cooperation and reduce misinterpretation and instability.
Evidence
The Chair stated that delegations had reflected on the eight global measures including information exchange measures such as sharing national strategies, legislation and good practices, collaboration between the public and private sector, and capacity building measures, and that the POC Directory is an important confidence-building tool, a voluntary one that can strengthen cooperation and reduce misinterpretation and instability, and that CBMs can strengthen cooperation, reduce risks from errors of calculation and foster stability in the digital sector .
Major Discussion Point
Major Discussion Point 1: The Role and Importance of Confidence-Building Measures (CBMs) in International ICT Security
Agreed with
NIgeria on behalf of African GroupIsraelAustraliaMalawiMozambiqueNorwayNorth MacedoniaCameroonCôte d'Ivoire
on: CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace
Universal participation in the POC Directory should be achieved – The Chair welcomed state participation in the directory and expressed hope that universal participation would eventually be achieved (Chair Egriselda López)
Arg. 2
Explanation
The Chair expressed her welcome for state participation in the POC Directory and her hope that universal participation would eventually be achieved. This reflects the broader consensus among delegations that the directory's value depends on the widest possible participation by member states.
Evidence
The Chair stated that she welcomed state participation in the directory and hoped that eventually universal participation would be achieved .
Major Discussion Point
Major Discussion Point 2: The Global Points of Contact (POC) Directory – Implementation and Challenges
Agreed with
TongaIrelandNetherlandsAustraliaRussian FederationThailandAfrican Union CommissionArgentinaCameroon
on: The Global POC Directory is an important achievement that should be actively maintained, regularly tested and used in good faith as a complement to existing channels
Contact points must be and operational to respond in a timely manner to ICT incidents – The Chair urged all states that had not yet done so to appoint and nominate diplomatic contact points and engage in verifications to ensure contact points remain and operational (Chair Egriselda López)
Arg. 3
Explanation
The Chair urged all states that had not yet done so to appoint and nominate diplomatic contact points and to engage in verification exercises to ensure that these contact points remain and operational. She emphasised that the real value of contact points lies precisely in their ability to respond in a timely manner to ICT incidents.
Evidence
The Chair urged all those who had not yet done so to appoint and nominate diplomatic contact points and engage in verifications to ensure that these contact points remain and operational, given that the real value of them is precisely their ability to respond in a timely manner to ICT incidents .
Major Discussion Point
Major Discussion Point 2: The Global Points of Contact (POC) Directory – Implementation and Challenges
CBMs are vital for implementing the framework on responsible state behaviour – The Chair noted that member states attached great value to CBMs as vital for the implementation of the framework on responsible state behaviour (Chair Egriselda López)
Arg. 4
Explanation
The Chair noted in her summary that member states had expressed the value they attach to CBMs as vital instruments for the implementation of the framework on responsible state behaviour. She indicated that all statements had been taken note of as important inputs for determining the way forward, specifically how discussions in the DTGs would be structured.
Evidence
The Chair stated that she had heard the value that member states attached to these measures as vital for the implementation of the framework on responsible state behaviour, and that all statements had been taken note of as important inputs for determining the way forward, specifically how discussions in the DTGs would be structured .
Major Discussion Point
Major Discussion Point 1: The Role and Importance of Confidence-Building Measures (CBMs) in International ICT Security
Session Knowledge Graph
Speakers · Topics · Arguments · Relationships
Interactive graph · embed active
Agreed Points
CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace
There was near-universal agreement that CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace. The African Group affirmed that CBMs are indispensable for fostering trust, transparency, predictability and cooperation . Israel stated that CBMs allow states to build practical procedures during peacetime for de-escalation and risk reduction during geopolitical crises . Australia described CBMs as practical tools for reducing the risk of misinterpretation, escalation and conflict . Malawi and Mozambique echoed this view . Norway emphasised that CBMs provide practical tools for implementing agreed commitments . North Macedonia noted that CBMs are among the most valuable outcomes of the OEWG process . Côte d’Ivoire stressed that trust is built by dialogue, transparency, predictability and results-based cooperation . The Chair summarised this broad consensus in her closing remarks .
CBMs as essential tools for preventing escalation and fostering trust – CBMs are indispensable for fostering trust, transparency, predictability and cooperation among states, contributing to international peace and security in cyberspace (NIgeria on behalf of African Group)
CBMs as practical tools for de-escalation – CBMs allow states to build practical procedures during peacetime that can be directly utilised for de-escalation, communication and risk reduction during geopolitical crises (Israel)
CBMs as practical tools reducing misunderstanding – CBMs are practical tools for reducing the risk of misinterpretation, escalation and conflict in cyberspace, helping states build relationships and establish communication channels before a crisis occurs so that these channels can be used effectively during and after cyber incidents (Australia)
CBMs as practical tools reducing misunderstanding – CBMs are practical tools for reducing the risk of misinterpretation, escalation and conflict in cyberspace, helping states build relationships and establish communication channels before a crisis occurs so that these channels can be used effectively during and after cyber incidents (Australia)
CBMs as practical tools reducing misunderstanding – CBMs are practical tools for reducing the risk of misinterpretation, escalation and conflict in cyberspace, helping states build relationships and establish communication channels before a crisis occurs so that these channels can be used effectively during and after cyber incidents (Australia)
CBMs provide practical tools for implementing agreed commitments – CBMs provide practical tools for implementing agreed commitments; mechanisms such as points of contact, dialogue, sharing of best practices and information sharing help reduce risk, prevent misunderstandings and contribute to stability and security in cyberspace (Norway)
CBMs as valuable outcomes of the OEWG process – CBMs are among the most valuable outcomes of the OEWG process, demonstrating that even in a complex and rapidly evolving cyber environment, states can agree on practical measures to strengthen trust and improve communication (North Macedonia)
CBMs as instruments for inclusive participation – For developing countries, CBMs are not merely diplomatic instruments but practical tools that enable more inclusive participation in the international ICT security framework (Cameroon)
CBMs built through dialogue and transparency – Trust is not something that can be declared by fiat; it is built by dialogue, transparency, predictability, and results-based cooperation (Côte d'Ivoire)
The eight global CBMs and the POC Directory are important confidence-building tools that can strengthen cooperation and reduce misinterpretation – The Chair summarised that delegations reflected on the eight global measures, including information exchange, public-private collaboration and capacity building, and that the POC Directory is an important voluntary confidence-building tool (Chair Egriselda López)
Policy Context (Knowledge Base)
This consensus is well-established within the UN OEWG framework, where delegations broadly affirmed that CBMs should be implemented gradually and that the POC directory constitutes a good starting point [S158]. The African Group explicitly called for continued discussion on how CBMs can be effectively operationalised in response to severe incidents [S156], reinforcing their practical utility.
NIgeria on behalf of African GroupIsraelAustraliaMalawiMozambiqueNorwayNorth MacedoniaCameroonCôte d'IvoireChair Egriselda López
The Global POC Directory is an important achievement that should be actively maintained, regularly tested and used in good faith as a complement to existing channels
Speakers broadly agreed that the Global POC Directory is a significant achievement that must be actively maintained and used in good faith. Tonga described it as the flagship practical achievement of the OEWG . Ireland and the Netherlands both argued it should be used as a complement to, not a replacement for, existing channels . Australia called for it to be actively maintained, regularly tested and supported by clear expectations of good faith use, with requests being proportionate and purposeful . The Russian Federation urged all remaining states to join . Thailand supported regular communication checks and simulation exercises . The African Union Commission recommended integrating regional POC networks with the global directory . The Chair urged all states to appoint and nominate diplomatic contact points and engage in verifications .
Strong support for the POC Directory as a flagship achievement – Tonga strongly supports the Global Points of Contact Directory as the flagship practical achievement of the OEWG and commends UNODA for its continued operationalisation (Tonga)
POC Directory as a complement, not replacement, to existing channels – The POC Directory should be used as a complement to existing channels of communication between states, not as a replacement or duplication of established diplomatic or technical channels (Ireland)
POC Directory as complementary to, not replacing, existing channels – The strength and added value of the POC Directory are found in establishing lines of contact where these previously were unavailable or unclear; it should be a complementary tool, not a replacement for existing POC networks (Netherlands)
Need for the directory to be actively maintained and tested – For the POC Directory to remain useful, it should be actively maintained, regularly tested, and supported by clear expectations of good faith use; requests should be proportionate and purposeful (Australia)
Need for universal participation in the directory – 125 states have joined the directory, which is positive, but all remaining member states should join by designating appropriate diplomatic and technical points of contact (Russian Federation)
Support for communication checks and simulation exercises – Thailand supports regular communication checks, simulation exercises and continued engagement to ensure the directory remains effective when needed most (Thailand)
Importance of integrating regional POC networks with the global directory – The global mechanism should facilitate the integration of regional points of contact with the global POC directory to strengthen coherence and complementarity (African Union Commission)
Voluntary cyber exercises to build confidence and practical skills – Argentina supports continuing voluntary exercises, gradually fine-tuning their modalities and exchanging experiences that encourage practical use of the POC directory and other CBMs (Argentina)
POC Directory as a dynamic instrument for cooperation – The directory should evolve from a repository of contacts into a dynamic instrument for cooperation, with functionalities progressively enhanced to facilitate secure communication and voluntary information exchange (Cameroon)
Universal participation in the POC Directory should be achieved – The Chair welcomed state participation in the directory and expressed hope that universal participation would eventually be achieved (Chair Egriselda López)
Policy Context (Knowledge Base)
The POC Directory was launched with 109 countries joining within its first six months [S160], and subsequent sessions emphasised expanding participation and building capacity, especially for developing countries [S170]. Discussions at the 9th substantive OEWG session highlighted standardisation, improved communication, and proactive use of the Directory [S168], while Canada welcomed ongoing operationalisation efforts [S166].
TongaIrelandNetherlandsAustraliaRussian FederationThailandAfrican Union CommissionArgentinaCameroonChair Egriselda López
The POC Directory should complement, not replace, existing diplomatic and technical communication channels
Multiple speakers converged on the view that the POC Directory should complement rather than replace existing channels. Ireland stated it should be used in good faith as a complement to existing channels . The Netherlands argued its strength lies in establishing lines of contact where previously unavailable, and should not replace existing POC networks or diplomatic channels . Germany similarly argued the directory is not intended to replace established channels such as FIRST, CERT-to-CERT cooperation or law enforcement cooperation . Australia stated states should always remain free to engage through channels most appropriate to the circumstances . Vanuatu requested clear guidance on which channels serve which purpose and no duplication of what already functions elsewhere .
POC Directory as a complement, not replacement, to existing channels – The POC Directory should be used as a complement to existing channels of communication between states, not as a replacement or duplication of established diplomatic or technical channels (Ireland)
POC Directory as complementary to, not replacing, existing channels – The strength and added value of the POC Directory are found in establishing lines of contact where these previously were unavailable or unclear; it should be a complementary tool, not a replacement for existing POC networks (Netherlands)
POC Directory as complementary to, not replacing, existing channels – The strength and added value of the POC Directory are found in establishing lines of contact where these previously were unavailable or unclear; it should be a complementary tool, not a replacement for existing POC networks (Netherlands)
Need for the directory to be actively maintained and tested – For the POC Directory to remain useful, it should be actively maintained, regularly tested, and supported by clear expectations of good faith use; requests should be proportionate and purposeful (Australia)
Need for coherence across multiple communication channels – The international community is multiplying its channels of communication; Vanuatu requests that the directory be developed in deliberate awareness of the wider ecosystem, with clear guidance on which channels serve which purpose (Vanuatu)
Policy Context (Knowledge Base)
The OEWG framework explicitly envisages differentiated roles for diplomatic and technical POCs, with diplomatic POCs communicating with diplomatic counterparts and technical POCs with technical counterparts [S161]. Delegations also emphasised building on existing POC infrastructures from regional organisations rather than replacing them [S158].
IrelandNetherlandsGermanyAustraliaVanuatu
Capacity building is a cross-cutting priority and essential enabler for effective CBM implementation
There was strong consensus that capacity building is a cross-cutting priority and essential enabler for effective CBM implementation. The African Group stated that for African countries, capacity building is not an auxiliary issue but a strategic enabler . The Pacific Islands Forum argued it is foundational to all aspects of the mechanism’s work and should not be siloed . Ireland noted that capacity building is an essential prerequisite for successful CBM implementation for many states . The Latin American group called for DTG2 to be established as the main platform for capacity building dialogue . The Philippines emphasised that capacity building is indispensable for effective CBM implementation . Costa Rica described capacity building as a bridge between consensus and action . Morocco called it the guiding thread running through all pillars of responsible behaviour .
Capacity building as a strategic enabler for African countries – For African countries, capacity building is not an auxiliary issue; it is a strategic enabler for achieving a secure, resilient and inclusive digital future as digital transformation accelerates across the continent (NIgeria on behalf of African Group)
Capacity building as foundational to all aspects of the mechanism's work – Capacity building is the enabler that underpins all aspects of the work; it is foundational to responding to threats, implementing norms, engaging meaningfully in international law discussions, and sustaining CBMs (Tonga on behalf of Pacific Islands Forum)
Expertise of stakeholders should play a strong role – The expertise and experience of stakeholders from academia, the technical community, civil society and the private sector should play a strong role in the CBM implementation process, with practical tools and best practices feeding engagement (Ireland)
DTG2 as the main platform for capacity building dialogue – The DTG on capacity building must be established as the main platform for dialogue on this issue within the global mechanism, playing a fundamental role as a space for strategic coordination to facilitate information exchange and articulate synergies (Chile Representative on behalf of Latin American group)
POC Directory requires capacity building to be effective – Many states face institutional, technical and resource constraints affecting their ability to operationalise national points of contact; capacity building is indispensable for effective implementation (Philippines)
CARICOM priorities for capacity building – CARICOM highlights three regional priorities: cyber law and modern legal frameworks, sustained cyber capacity building for resilience and technical expertise, and critical infrastructure protection for small states with limited resources (Bahamas on behalf of the CARICOM)
Capacity building as a bridge between consensus and action – Capacity building is a bridge between consensus and action; voluntary norms, international law, CBMs and due diligence can only be turned into policies and practical steps if states have technical, legal and institutional capacities (Costa Rica)
Capacity building as a bridge between consensus and action – Capacity building is a bridge between consensus and action; voluntary norms, international law, CBMs and due diligence can only be turned into policies and practical steps if states have technical, legal and institutional capacities (Costa Rica)
Capacity building priorities for developing countries – Nigeria believes DTG2 should prioritise strengthening national cybersecurity strategies, legal and governance frameworks, technical capabilities including CERTs, and expertise in cyber diplomacy, digital forensics and cybercrime investigations (Nigeria)
Capacity building as a bridge between consensus and action – Capacity building is a bridge between consensus and action; voluntary norms, international law, CBMs and due diligence can only be turned into policies and practical steps if states have technical, legal and institutional capacities (Costa Rica)
Policy Context (Knowledge Base)
Capacity building was identified as a complementary aspect to CBMs across multiple OEWG sessions, with calls for a coordinated strategy involving regional and sub-regional organisations and multi-stakeholder participation [S167]. Malaysia specifically welcomed provisions on targeted capacity-building to encourage onboarding of states to the POC Directory [S159], and Canada supported work to help developing states participate effectively [S166].
NIgeria on behalf of African GroupTonga on behalf of Pacific Islands ForumIrelandChile Representative on behalf of Latin American groupPhilippinesBahamas on behalf of the CARICOMCosta RicaVietnamNigeriaMorocco
Regional organisations play an important role in advancing CBMs and their experiences should inform global implementation
Speakers from all regions agreed that regional organisations play a vital role in advancing CBMs and that their experiences should inform global implementation. The African Group encouraged the global mechanism to strengthen coordination between global and regional initiatives . Chile argued that exchange of good practices between regional mechanisms could strengthen CBM implementation globally . Uruguay highlighted the OAS experience . Ghana pointed to the ECOWAS regional framework . The Philippines highlighted the ASEAN Regional CERT . The African Union Commission described its work developing adapted CBMs for African realities . The OSCE shared its extensive experience as the first regional organisation to develop cyber CBMs . Tonga presented its Pacific cooperation experience as a concrete example of CBMs working in practice .
Regional organisations play an important role in advancing CBMs – The global mechanism should strengthen coordination and complementarity between global and regional confidence-building initiatives and promote linkages between regional POC networks and the global directory (NIgeria on behalf of African Group)
Cross-regional exchanges to avoid duplication and share lessons learned – The exchange of good practices between regional mechanisms could make meaningful contributions to strengthening CBM implementation globally, avoiding duplications and making the most of lessons learned in different contexts (Chile)
OAS regional experience as a model for CBM implementation – Regional experience in the OAS shows the practical value of CBMs; Uruguay has designated and updated its technical contact points in the OAS framework since 2018 and participates in cooperation mechanisms such as CERT Americas (Uruguay)
ECOWAS regional framework as a practical example – ECOWAS has developed a regional framework on cyber ICT confidence-building measures with Ghana's participation, establishing practical mechanisms including national diplomatic and technical points of contact (Ghana)
ASEAN Regional CERT as a step toward regional cybersecurity posture – As ASEAN Chair in 2026, the Philippines welcomed progress in operationalising the ASEAN Regional CERT, an important step toward raising the regional cybersecurity posture through timely information sharing and coordinated incident response (Philippines)
African Union developing adapted CBMs for African realities – The African Union Commission is developing concrete measures adapted to African realities that can be effectively implemented in the various regions of the continent, drawing on experience from economic and regional committees (African Union Commission)
OSCE as the first regional organisation to develop cyber CBMs – The OSCE was the first regional organisation to develop cyber confidence-building measures and has many years of experience in practical implementation of its 16 CBMs, including through the Adopt-a-CBM initiative (OSCE)
Western Balkans Cyber Diplomacy Network as a regional initiative – The launch of the Western Balkans Cyber Diplomacy Network in 2025, supported by the German Federal Foreign Office, represents the region's shared commitment to addressing cross-border cyber challenges through dialogue and cooperation (Bosnia and Herzegovina)
Pacific regional cooperation as a model for cyber incident response – CERT Tonga was established in 2016 and has worked within the Pacific Cyber Security Operational Network; when Tonga's health system was attacked, established relationships enabled rapid assistance and joint public attribution with Australia and New Zealand (Tonga)
DTGs as forums for trust-building and learning – The global mechanism, especially the DTGs, provides an opportunity to develop ways to operationalise the CBM pillar in a practical way and can act as a forum for cross-regional learning (Germany)
Policy Context (Knowledge Base)
Delegations broadly supported building on existing POC infrastructures from regional organisations and integrating them to avoid duplication of effort [S158]. Germany and France specifically suggested learning from regional examples to ensure responsible use of the POC Directory [S170].
NIgeria on behalf of African GroupChileUruguayGhanaPhilippinesAfrican Union CommissionOSCEBosnia and HerzegovinaTongaGermany
Capacity building must be demand-driven, nationally owned, sustainable and tailored to specific national needs
Multiple speakers agreed that capacity building must be demand-driven, nationally owned, sustainable and tailored to specific national needs. The African Group underscored that effective capacity building must be demand-driven, nationally owned, sustainable and tailored to the specific needs and priorities of countries . CARICOM supported capacity-building initiatives that are voluntary, demand-driven, sustainable, transparent and based on national ownership . Iraq stressed that capacity building should be anchored in national needs and priorities while respecting sovereignty . Nigeria called for capacity building efforts to be demand-driven, nationally owned, sustainable and tailored to national priorities . Colombia emphasised the value of South-South and triangular cooperation in facilitating knowledge exchange while taking account of local realities .
Capacity building must be demand-driven, nationally owned and sustainable – Effective capacity building must be demand-driven, nationally owned, sustainable, and tailored to the specific needs and priorities of countries, respecting national sovereignty (NIgeria on behalf of African Group)
CARICOM priorities for capacity building – CARICOM highlights three regional priorities: cyber law and modern legal frameworks, sustained cyber capacity building for resilience and technical expertise, and critical infrastructure protection for small states with limited resources (Bahamas on behalf of the CARICOM)
Capacity building requires financial and technical support for equal opportunities – Capacity building should get financial and technical support so that equal opportunities are available to all states to benefit from international programmes and initiatives, with special attention to developing countries and countries emerging from conflict (Iraq)
Capacity building priorities for developing countries – Nigeria believes DTG2 should prioritise strengthening national cybersecurity strategies, legal and governance frameworks, technical capabilities including CERTs, and expertise in cyber diplomacy, digital forensics and cybercrime investigations (Nigeria)
South-South and triangular cooperation as valuable modalities – Modalities like South-South cooperation and triangular cooperation can play a particularly valuable role in capacity building, facilitating the exchange of knowledge and good practices while taking account of local realities and priorities (Colombia)
Policy Context (Knowledge Base)
This principle is reinforced by IGF discussions emphasising the need to reduce duplication, harmonise efforts, and create sustainable outcomes through coordination [S164]. The importance of avoiding one-size-fits-all approaches is particularly salient given the distinct constraints faced by small island developing states and other vulnerable nations [S151][S152].
NIgeria on behalf of African GroupBahamas on behalf of the CARICOMIraqNigeriaColombia
DTGs should focus on practical, action-oriented work to operationalise CBMs rather than reproducing procedural disagreements
There was broad agreement that DTGs should focus on practical, action-oriented work to operationalise CBMs. Israel stated that DTGs must prioritise further developing and operationalising CBMs . Argentina proposed a division of labour between DTG1 for CBM operationalisation and DTG2 for capacity building support . The Pacific Islands Forum argued DTGs should not become additional negotiating rooms reproducing procedural disagreements . Chile viewed DTGs as valuable opportunities for exchanging national experiences and good practices . North Macedonia called for CBMs to be reflected in DTG work through sharing of national experience while avoiding duplication of plenary discussions . Germany described the DTGs as providing an opportunity to operationalise the CBM pillar in a practical way and act as a forum for cross-regional learning .
DTGs should prioritise further developing and operationalising CBMs – The DTGs must prioritise further developing and operationalising CBMs, as they hold great potential for immediate positive impact and for generating beneficial momentum for the global mechanism (Israel)
DTG1 for operationalising CBMs and DTG2 for capacity building support – DTG1 could examine operationalisation of CBMs by exchanging national and regional experiences, while DTG2 could identify capacities required to support this operationalisation effort (Argentina)
DTGs should focus on practical, technical work rather than procedural disagreements – DTGs should be used to identify needs, share practical experience, connect states with relevant expertise, and help match national and regional priorities with appropriate support, not become additional negotiating rooms (Tonga on behalf of Pacific Islands Forum)
DTGs as platforms for exchanging national experiences and good practices – The dedicated thematic groups offer a valuable opportunity to go into further depth on international relations and the role of international organisations in effective implementation of CBMs, exchanging national experiences and good practices (Chile)
CBMs should be reflected in DTG work through sharing of national experiences – CBMs should be reflected in the work of the thematic groups through sharing of national experience, practical implementation approaches and good practices, while avoiding duplication of plenary discussions (North Macedonia)
DTGs as platforms for exchanging national experiences and good practices – The dedicated thematic groups offer a valuable opportunity to go into further depth on international relations and the role of international organisations in effective implementation of CBMs, exchanging national experiences and good practices (Chile)
DTGs as forums for trust-building and learning – The global mechanism, especially the DTGs, provides an opportunity to develop ways to operationalise the CBM pillar in a practical way and can act as a forum for cross-regional learning (Germany)
Policy Context (Knowledge Base)
A broad consensus emerged across plenary sessions that DTGs should serve as practical, action-oriented forums for advancing implementation of the normative framework [S155][S157]. Romania explicitly stated that DTGs could play an important role as venues for exchanging views and formulating recommendations [S155].
IsraelArgentinaTonga on behalf of Pacific Islands ForumChileNorth MacedoniaMalaysiaGermany
Simulation exercises, regular training and practical cooperation activities are essential for building confidence before crises occur
Speakers widely agreed that simulation exercises, regular training and practical cooperation activities are essential for building confidence before crises occur. Côte d’Ivoire recommended regularly organising UN-auspiced simulation exercises bringing together points of contact, national incident response teams and relevant authorities . Argentina supported continuing voluntary exercises to encourage practical use of the POC directory . Tonga illustrated what CBMs look like when they work through its health system attack experience: relationships built before the crisis, exercised during it and deepened after it . Australia emphasised that cooperation must be established before it is needed in a crisis . The OSCE described its scenario-based exercises as usually well received . Thailand supported regular communication checks and simulation exercises .
Regular simulation exercises under UN auspices – Côte d'Ivoire recommends regularly organising under UN auspices simulation exercises that bring together points of contact, national incident response teams and relevant authorities (Côte d'Ivoire)
Voluntary cyber exercises to build confidence and practical skills – Argentina supports continuing voluntary exercises, gradually fine-tuning their modalities and exchanging experiences that encourage practical use of the POC directory and other CBMs (Argentina)
Tonga's CERT as an example of CBMs working in practice – Tonga's experience with its health system attack demonstrated what CBMs look like when they work: relationships built before the crisis, exercised during it, and deepened after it (Tonga)
Cyber Rapid Assistance for Pacific Incidents and Disasters as a model – Australia's Cyber Rapid Assistance for Pacific Incidents and Disasters programme has an important role to play in building trust and habits of trust between states and regions; cooperation must be established before it is needed in a crisis (Australia)
OSCE capacity building through scenario-based exercises – The OSCE delivers capacity building activities including trainings and workshops with scenario-based exercises that help participants understand the practical application of CBMs, which is usually well received (OSCE)
Botswana's national cybersecurity activities as CBM implementation – Botswana's recent internal cybersecurity activities reflect CBM implementation through formal public-private partnerships, threat intelligence sharing and academic collaboration, focusing on response readiness and workforce upskilling (Botswana)
Support for communication checks and simulation exercises – Thailand supports regular communication checks, simulation exercises and continued engagement to ensure the directory remains effective when needed most (Thailand)
Stakeholder engagement from the private sector, civil society, academia and the technical community is important for effective CBM implementation
There was broad agreement on the importance of stakeholder engagement for effective CBM implementation. Ireland argued that the expertise and experience of stakeholders from academia, the technical community, civil society and the private sector should play a strong role . Australia stated that industry and the technical community are often closest to vulnerabilities and emerging risks . Uruguay highlighted that public-private partnerships are essential given that significant parts of critical information infrastructure are operated by non-governmental actors . The Pacific Islands Forum strongly supported the substantive inclusion of stakeholders in both formal and informal settings . The EU called for continued promotion of coordination with industry, civil society and academia . The DMUN Foundation called for youth engagement as a practical CBM .
Expertise of stakeholders should play a strong role – The expertise and experience of stakeholders from academia, the technical community, civil society and the private sector should play a strong role in the CBM implementation process, with practical tools and best practices feeding engagement (Ireland)
Industry and technical community closest to vulnerabilities and risks – Industry and the technical community, civil society and academia are often closest to vulnerabilities, incidents and emerging risks; their expertise can help states understand threats, improve prevention and response, and translate CBMs into practical action (Australia)
Public-private partnerships essential for critical infrastructure protection – Given that a significant part of critical information infrastructure is operated by non-governmental actors or is part of the supply chain, public-private partnerships are essential to strengthen prevention, early alerts and fighting malicious information (Uruguay)
Stakeholder engagement essential for capacity building – Meaningful capacity building depends on access to the expertise of the multi-stakeholder community, academia, civil society, the private sector and the technical community; stakeholders must be substantively included in both formal and informal settings (Tonga on behalf of Pacific Islands Forum)
Multi-stakeholder community role in designing and delivering capacity building – The role of the multi-stakeholder community in the design and delivery of cybercapacity building should be further discussed, recognising that industry, civil society and academia contribute meaningfully to effective and sustainable capacity building (European Union)
Youth engagement as a practical confidence-building measure – Member states should consider youth engagement as a practical CBM, including structured dialogues between governments and youth, support for youth-led cyber awareness initiatives, and opportunities for young experts to participate in regional and international CBM activities (DMUN Foundation)
Policy Context (Knowledge Base)
Multi-stakeholder participation was consistently encouraged across OEWG sessions, with academia, the private sector, civil society, and technical communities identified as essential contributors to CBM implementation [S167]. The DTG framework was also designed to incorporate expert briefings and evidence-based dialogue with multi-stakeholder participation [S157].
IrelandAustraliaUruguayTonga on behalf of Pacific Islands ForumEuropean UnionDMUN Foundation
Avoiding duplication across multiple communication channels and mechanisms is essential for coherence and effectiveness
Multiple speakers agreed on the importance of avoiding duplication across multiple communication channels and mechanisms. Vanuatu, speaking from the perspective of small administrations operating multiple channels through the same handful of officials, requested clear guidance on which channels serve which purpose and no duplication of what already functions elsewhere . Israel called for the global mechanism to prioritise harmonising with other multilateral and regional forums . The Netherlands argued the POC directory should be a complementary tool, not a replacement . Germany similarly argued the directory should not replace established channels . Cameroon recommended avoiding duplication of what already functions elsewhere . Colombia prioritised avoiding duplication of efforts and maximising available resources . The EU aimed to avoid duplication between the plenary, DTG2 and the global roundtable .
Need for coherence across multiple communication channels – The international community is multiplying its channels of communication; Vanuatu requests that the directory be developed in deliberate awareness of the wider ecosystem, with clear guidance on which channels serve which purpose (Vanuatu)
Global mechanism should harmonise with other multilateral and regional forums – The global mechanism's work should prioritise harmonising with other multilateral and regional forums and ensure that all outcomes are mutually reinforcing (Israel)
POC Directory as complementary to, not replacing, existing channels – The strength and added value of the POC Directory are found in establishing lines of contact where these previously were unavailable or unclear; it should be a complementary tool, not a replacement for existing POC networks (Netherlands)
POC Directory as complementary to, not replacing, existing channels – The strength and added value of the POC Directory are found in establishing lines of contact where these previously were unavailable or unclear; it should be a complementary tool, not a replacement for existing POC networks (Netherlands)
Avoiding duplication between global and regional mechanisms – The global mechanism should facilitate exchanges of experience among member states and regional organisations through workshops and knowledge-sharing initiatives, avoiding duplication of what already functions elsewhere (Cameroon)
Capacity building initiatives should avoid duplication and maximise resources – The mechanism offers the right platform to identify ongoing initiatives, generate complementarity between them, and engage in more effective coordination based on the needs and priorities of different states (Colombia)
Coordination between global roundtable and DTGs – The global roundtable on capacity building could play a role in ensuring enhanced coordination and cooperation, bringing together capacity building implementers for exchange of information and best practices, feeding into plenary and DTG2 discussions (European Union)
Policy Context (Knowledge Base)
Policy coherence and avoidance of duplication are recognised priorities across multiple UN digital governance forums [S162][S163]. IGF discussions on cyber capacity building coordination similarly emphasised the need to reduce duplication and harmonise efforts [S164], and delegations in the OEWG context called for integrating regional POC infrastructures to avoid duplicating effort [S158].
VanuatuIsraelNetherlandsGermanyCameroonColombiaEuropean Union
Similar Viewpoints
Small and developing states share a common perspective that their unique circumstances create specific challenges for CBM implementation and that the global mechanism must be designed with these constraints in mind. Tonga noted that small states do not maintain wide networks of diplomats tasked with cyber-related cooperation . Vanuatu emphasised that distance should never determine who participates in building confidence and supported hybrid modalities . Tuvalu called for a shift from short-term external consulting to long-term training of local technical teams . CARICOM acknowledged persistent gaps in resources, workforce development and cross-sector coordination . Botswana argued that global transparency initiatives must be paired with concrete technical assistance to address the digital divide .
Russia, Germany and Australia all identified practical challenges with the functioning of the POC Directory, though from different perspectives. Russia reported that only around 48% of its 2,576 inquiries were responded to, attributing this to dead contacts and political reasons . Germany reported receiving repetitive, identical messages from a certain state that did not take into account its replies, characterising this as not in line with the purpose of the directory . Australia called for the directory to be actively maintained, regularly tested and supported by clear expectations of good faith use, with requests being proportionate and purposeful . All three implicitly or explicitly called for better norms around responsible use of the directory.
Regional groupings from Africa, the Pacific, Latin America and the EU all converged on the view that capacity building is a central, cross-cutting priority for the global mechanism. The African Group stated that for African countries, capacity building is not an auxiliary issue but a strategic enabler . The Pacific Islands Forum argued it is foundational to all aspects of the mechanism’s work and should not be siloed . The Latin American group called for DTG2 to be established as the main platform for capacity building dialogue . The EU highlighted its significant investment of 100 million euros across 27 projects and its commitment to continue investing .
Pacific Island states and Australia shared a common perspective on the importance of building relationships and cooperation before crises occur, drawing on concrete Pacific regional experience. Tonga described how established relationships enabled rapid assistance when its health system was attacked, characterising this as what CBMs look like when they work . Vanuatu drew on the analogy of rapid state-to-state communication during physical emergencies such as cyclones as a model for digital emergencies . Australia highlighted its Cyber Rapid Assistance for Pacific Incidents and Disasters programme as an example of building trust and habits of trust before a crisis .
Cuba and the Dominican Republic both offered nuanced perspectives on the limitations of CBMs, emphasising that they are not sufficient on their own. Cuba argued that CBMs do not guarantee the strictly peaceful use of ICTs and are complementary to binding norms, with the voluntary nature of CBMs needing to prevail [191, 194, 198-199]. The Dominican Republic drew on regional experience to argue that CBMs are tools of preventive diplomacy rather than real-time response mechanisms, with bilateral technical direct cooperation proving key during an actual ransomware crisis . Both speakers thus cautioned against over-reliance on CBMs as standalone solutions.
Developing countries and small island developing states shared a common view that financial and technical support mechanisms are needed to ensure equitable access to capacity building. The African Group called for a Voluntary UN ICT Security Capacity Building Fund and a UN ICT Security Fellowship Programme with particular attention to least developed countries and small island developing states . CARICOM emphasised that capacity building efforts must remain accessible to all developing countries . Iraq stressed that capacity building should receive financial and technical support so that equal opportunities are available to all states . Tuvalu called for a shift from short-term external consulting to long-term training of local technical teams .
Unexpected Consensus
It was somewhat unexpected that Cuba and Thailand, states that might not always be expected to align, both independently argued that the substantive dialogue within the global mechanism itself constitutes a confidence-building measure. Cuba stated that ensuring information exchange and dialogue on the use of ICTs and international security in the global mechanism is in itself a CBM . Thailand similarly considered the substantive dialogue within the OEWG and the ongoing discussion in the global mechanism to be constructive CBMs in themselves . This meta-level argument about the process being part of the outcome represents an interesting area of convergence across different geopolitical perspectives.
It was unexpected that Russia and Germany, states with significant geopolitical tensions, both raised concerns about misuse or ineffective use of the POC Directory, albeit from opposite perspectives. Russia reported that only around 48% of its inquiries were responded to, attributing some of this to political reasons , while Germany reported receiving repetitive, identical messages from a certain state that did not take into account its replies . Although each state was implicitly or explicitly pointing at the other, both agreed that the directory was not being used as intended in some cases. Australia reinforced this by calling for clear expectations of good faith use and proportionate, purposeful requests . This convergence on the need for better norms around directory use, despite coming from very different political positions, represents an unexpected area of agreement.
Both Vanuatu and Tonga drew on their experience with physical disasters as a model for cyber incident cooperation, which was an unexpected and distinctive contribution to the discussion. Vanuatu noted that when disaster strikes its islands, information flows between governments within hours, and that this habit of rapid, trusted state-to-state communication in physical emergencies is precisely the habit the CBM agenda seeks to create for digital ones . Tonga similarly drew on its experience with the Pacific Cyber Security Operational Network, where relationships built through physical emergency cooperation translated into effective cyber incident response . This framing of physical disaster cooperation as a template for cyber cooperation was a distinctive Pacific perspective not raised by other regions.
Cuba and the African Union Commission, from quite different political perspectives, both argued that regional CBMs should not be treated as universal models. Cuba stated that each region or sub-region has unique characteristics and that measures implemented at these levels cannot be considered single global models or benchmarks . The African Union Commission similarly stated that its ambition is not to reproduce existing models but to set out concrete, adapted measures adapted to African realities . This convergence between a state known for its emphasis on sovereignty and non-interference and a regional organisation seeking to develop its own adapted approach represents an unexpected alignment on the importance of contextual adaptation.
Overall Assessment
The discussion revealed a very high level of consensus across geographically and politically diverse delegations on the fundamental importance of CBMs as practical tools for reducing misunderstanding, escalation and conflict in cyberspace. There was near-universal agreement on the value of the Global POC Directory as a flagship achievement, the need for it to be actively maintained and used in good faith as a complement to existing channels, and the importance of capacity building as a cross-cutting priority. Regional organisations were widely recognised as playing a vital role in advancing CBMs, with their experiences seen as valuable inputs for global implementation. The DTGs were broadly supported as platforms for practical, action-oriented work rather than procedural negotiation. Stakeholder engagement from the private sector, civil society, academia and the technical community was also widely endorsed. Areas of nuance included the limitations of CBMs as standalone tools (Cuba, Dominican Republic), practical challenges with the POC Directory's functioning (Russia, Germany, Australia), and the need to avoid treating regional CBMs as universal models (Cuba, African Union Commission). The distinctive Pacific perspective on physical disaster cooperation as a model for cyber incident cooperation was an unexpected contribution. Developing countries and small island developing states consistently emphasised the need for financial and technical support mechanisms, long-term capacity building investment and hybrid participation modalities to ensure inclusive participation.
Points of Difference
The appropriate role and purpose of the Global POC Directory — whether it is a primary crisis communication tool or strictly a supplementary channel
The Russian Federation views the POC Directory as the primary practical outcome of the OEWG and reports that around 48% of its 2,576 inquiries were responded to, attributing low response rates to dead contacts and political obstruction . Russia calls for a separate agenda item to discuss directory improvements and urges all states to join . By contrast, Germany explicitly reported receiving repetitive, identical messages from a certain state that did not take into account its replies, characterising this as not in line with the purpose of the directory . The Netherlands and Ireland both emphasised that the directory should be a complementary tool to existing channels, not a replacement . Vanuatu highlighted the burden placed on small administrations that must operate multiple channels at once . Australia stressed that requests must be proportionate and purposeful, and that the directory should not be used to overwhelm national points of contact . These positions reflect a fundamental tension between states that wish to use the directory as a primary communication mechanism and those that insist it must remain strictly supplementary.
Challenges with dead contacts and misuse of the directory – The directory faces challenges including dead contacts, misinterpretation of objectives of technical POCs, and cases where capitals ignore requests for political reasons; around 48% of Russia's inquiries were responded to (Russian Federation)
Concerns about repeated, bad-faith use of the directory – Germany reported receiving repetitive, identical messages from a certain state that did not take into account replies, which is not in line with the purpose of the UN POC Directory and does not represent responsible or sincere use (Germany)
POC Directory as complementary to, not replacing, existing channels – The strength and added value of the POC Directory are found in establishing lines of contact where these previously were unavailable or unclear; it should be a complementary tool, not a replacement for existing POC networks (Netherlands)
POC Directory as a complement, not replacement, to existing channels – The POC Directory should be used as a complement to existing channels of communication between states, not as a replacement or duplication of established diplomatic or technical channels (Ireland)
Need for coherence across multiple communication channels – The international community is multiplying its channels of communication; Vanuatu requests that the directory be developed in deliberate awareness of the wider ecosystem, with clear guidance on which channels serve which purpose (Vanuatu)
Need for the directory to be actively maintained and tested – For the POC Directory to remain useful, it should be actively maintained, regularly tested, and supported by clear expectations of good faith use; requests should be proportionate and purposeful (Australia)
Policy Context (Knowledge Base)
This tension is evident in OEWG records, where some delegations called for proactive use of the Directory for information exchange while others emphasised its supplementary nature [S168]. The formal framework envisages differentiated diplomatic and technical roles [S161], but the boundary between proactive and reactive use remains contested.
Whether CBMs alone are sufficient or must be complemented by binding norms
Cuba explicitly stated that CBMs on their own do not guarantee the strictly peaceful use of ICTs and that they are merely complementary to binding norms, emphasising that the voluntary nature of CBMs must prevail and that different phases of confidence building must respect sovereignty and non-interference . Cuba also stressed that the establishment of binding norms within the UN framework is one of the pillars for international confidence building . In contrast, Israel, Germany and the Netherlands focused on the value of voluntary CBMs as practical tools for de-escalation and trust-building without explicitly calling for binding norms . Germany specifically stated that any CBM should avoid entering the field of expectations or even obligations , suggesting a preference for keeping CBMs strictly voluntary rather than moving towards binding frameworks.
CBMs as complementary to binding norms – CBMs on their own do not guarantee the strictly peaceful use of ICTs; they are complementary to binding norms and must respect sovereignty and non-interference in internal affairs (Cuba)
CBMs as practical tools for de-escalation – CBMs allow states to build practical procedures during peacetime that can be directly utilised for de-escalation, communication and risk reduction during geopolitical crises (Israel)
CBMs as voluntary and action-oriented cyber diplomacy tools – CBMs are action-oriented voluntary cyber diplomacy tools at the discretion of states that can help reduce tensions and the risk of miscalculation (Germany)
Developing national positions on international law in cyberspace – The Netherlands encourages all member states and regional organisations to continue to develop national positions on how international law applies in cyberspace and make these views available to a wider public, to avoid miscommunication and miscalculation (Netherlands)
CubaIsraelGermanyNetherlands
Whether regional CBM models should inform or be adopted as global benchmarks
Cuba explicitly cautioned that regional or sub-regional CBM measures cannot be considered single global models or benchmarks, given that each region has unique characteristics . The African Union Commission similarly stated that its ambition is not to reproduce existing models but to set out concrete measures adapted to African realities . However, Ghana and the OSCE presented their regional frameworks as practical examples that could inform global implementation , and the Dominican Republic drew on OAS experience to offer lessons for the global mechanism . This creates a tension between those who wish to draw on regional experience as a source of global learning and those who resist the imposition of any regional model as a universal standard.
Regional CBMs should not be treated as single global models – Each region or sub-region has unique characteristics, and measures implemented at these levels cannot be considered single global models or benchmarks (Cuba)
ECOWAS regional framework as a practical example – ECOWAS has developed a regional framework on cyber ICT confidence-building measures with Ghana's participation, establishing practical mechanisms including national diplomatic and technical points of contact (Ghana)
OSCE as the first regional organisation to develop cyber CBMs – The OSCE was the first regional organisation to develop cyber confidence-building measures and has many years of experience in practical implementation of its 16 CBMs, including through the Adopt-a-CBM initiative (OSCE)
African Union developing adapted CBMs for African realities – The African Union Commission is developing concrete measures adapted to African realities that can be effectively implemented in the various regions of the continent, drawing on experience from economic and regional committees (African Union Commission)
CBMs as preventive diplomacy tools – CBMs are preventive diplomacy tools, not necessarily mechanisms actionable in real time to respond to incidents; bilateral technical direct cooperation is key during actual crises (Dominican Republic)
CubaGhanaOSCEAfrican Union CommissionDominican Republic
The appropriate scope and use of the POC Directory — whether it should be used proactively for information exchange or reserved for crisis communication
Russia envisions the directory as an tool for professional, non-politicised contacts between specialists, and calls for standardised communication templates and in-person meetings of POC representatives . Cameroon similarly envisions the directory evolving into a dynamic instrument for cooperation with progressively enhanced functionalities . However, Germany’s experience of receiving repetitive, identical messages that were not responsive to its replies illustrates the risk of the directory being used in ways that strain rather than build trust . Australia explicitly warned that the directory should not be treated as a mechanism for overwhelming national points of contact or creating unreasonable expectations of response , suggesting a more cautious and limited scope for its use.
Need for standardised communication templates – A priority task is to finalise a standardised communication template to simplify cooperation between POCs by clearly defining the information needed for analysis of attacks and incidents (Russian Federation)
Need for the directory to be actively maintained and tested – For the POC Directory to remain useful, it should be actively maintained, regularly tested, and supported by clear expectations of good faith use; requests should be proportionate and purposeful (Australia)
Concerns about repeated, bad-faith use of the directory – Germany reported receiving repetitive, identical messages from a certain state that did not take into account replies, which is not in line with the purpose of the UN POC Directory and does not represent responsible or sincere use (Germany)
POC Directory as a dynamic instrument for cooperation – The directory should evolve from a repository of contacts into a dynamic instrument for cooperation, with functionalities progressively enhanced to facilitate secure communication and voluntary information exchange (Cameroon)
Policy Context (Knowledge Base)
Germany and France emphasised responsible use of the POC Directory and learning from regional examples [S170], while the 9th substantive OEWG session discussions reflected calls for more proactive and standardised use [S168]. This divergence reflects an unresolved question about the Directory’s operational mandate.
Russian FederationAustraliaGermanyCameroon
The role of the dedicated thematic groups (DTGs) — whether they should produce negotiated outcomes or remain technical exchange forums
Argentina expressed hope that the DTGs would establish themselves as spaces for technical work capable of producing substantive recommendations and decisions on CBMs for consideration by the plenary, envisioning a process where recommendations are subsequently reviewed, fine-tuned and negotiated by states . The Pacific Islands Forum, speaking through Tonga, explicitly warned that DTGs should not become additional negotiating rooms that reproduce the same procedural disagreements or simply repeat plenary discussions, with their value to be measured by whether they help countries make progress . Russia called for a separate agenda item in the global mechanism’s programme of work for discussing issues related to supporting and improving the POC directory , suggesting a preference for more formal, structured deliberation. These positions reflect differing visions of whether the DTGs should be action-oriented technical forums or quasi-negotiating spaces.
DTGs should lead to practical outcomes and recommendations – Argentina hopes DTGs will establish themselves as spaces for technical work able to establish substantive recommendations and decisions on CBMs for consideration by the plenary, progressively working towards more interactive, results-focused dialogue (Argentina)
DTGs should focus on practical, technical work rather than procedural disagreements – DTGs should be used to identify needs, share practical experience, connect states with relevant expertise, and help match national and regional priorities with appropriate support, not become additional negotiating rooms (Tonga on behalf of Pacific Islands Forum)
Need for universal participation in the directory – 125 states have joined the directory, which is positive, but all remaining member states should join by designating appropriate diplomatic and technical points of contact (Russian Federation)
Policy Context (Knowledge Base)
Plenary discussions reflected a broad preference for DTGs as practical, action-oriented forums rather than negotiating bodies [S155][S157], yet the tension between producing actionable recommendations and avoiding formal negotiation remains present in the design of the global mechanism [S148].
ArgentinaTonga on behalf of Pacific Islands ForumRussian Federation
Unexpected Differences
While the POC Directory was designed as a non-politicised, technical communication tool, the statements of Russia and Germany revealed an unexpected and direct implicit conflict over its use. Russia reported that around 48% of its 2,576 inquiries were responded to, attributing low response rates partly to cases where capitals ignore requests for political reasons, specifically targeting countries that make unsubstantiated accusations regarding computer attacks . Germany, without naming Russia explicitly, reported receiving repetitive, identical messages from a certain state that did not take into account its replies, characterising this as clearly not in line with the purpose of the directory . This exchange was unexpected because the directory was intended to foster professional, non-politicised contacts , yet the statements of both delegations revealed that geopolitical tensions are already manifesting within this supposedly technical mechanism, undermining its foundational premise.
Cuba and Thailand both argued that the substantive dialogue within the global mechanism is itself a confidence-building measure , which was an unexpected framing not shared by most other delegations. Cuba used this argument to emphasise that dialogues must be conducted with mutual respect and consideration for the diversity of positions , which could be read as a caution against pressure to adopt specific CBM frameworks. Israel, by contrast, focused on the need for the DTGs to prioritise further developing and operationalising concrete CBMs , implying that dialogue alone is insufficient and that tangible outputs are needed. This disagreement over whether process itself constitutes a CBM was unexpected and has implications for how the mechanism’s success should be measured.
While there was broad support for the POC Directory, an unexpected tension emerged between small island developing states and larger states over the practical burden the directory places on small administrations. Vanuatu explicitly noted that it speaks from the standpoint of administrations that must operate all channels at once, often through the same handful of officials , and requested clear guidance on which channels serve which purpose to avoid duplication . Tonga similarly noted that small states do not maintain wide networks of diplomats tasked with cyber-related cooperation . Australia acknowledged this by calling for requests to be made with due regard to the capacity constraints of smaller states . However, Russia called for universal participation and urged all remaining states to join the directory , without explicitly addressing the capacity burden this places on small states. This tension was unexpected given the general consensus on the directory’s value.
Iran proposed two new CBMs for consideration by the first DTG: facilitating access by all states to ICT security products and tools, and developing a consolidated list of technical terms used in OEWG reports . This was unexpected because most other delegations, including Germany, Israel and Australia, focused exclusively on implementing the existing eight agreed CBMs rather than expanding the list. Germany explicitly stated that at a minimum, any CBM existing or re-proposed should fulfil criteria of being concrete, action-oriented and voluntary, and should avoid entering the field of expectations or even obligations , which could be read as a cautious response to proposals for new measures. Australia similarly focused on making agreed CBMs operational . This divergence over whether to expand or consolidate the CBM framework was not widely anticipated.
Overall Assessment
The discussion revealed a broadly cooperative atmosphere with strong consensus on the importance of CBMs and capacity building as pillars of the framework for responsible state behaviour. However, significant disagreements emerged beneath this surface consensus, particularly around: (1) the appropriate use and scope of the POC Directory, with an implicit but pointed conflict between Russia and Germany over good-faith use ; (2) whether CBMs should remain strictly voluntary or be complemented by binding norms, with Cuba taking a distinct position ; (3) the role of regional models in informing global CBM frameworks, with tension between those who see regional experience as universally instructive and those who resist any single model ; (4) the nature and mandate of the DTGs, with disagreement over whether they should produce negotiated outcomes or remain technical exchange forums ; and (5) the burden placed on small island developing states by multiplying communication channels . Capacity building discussions were more consensual in principle but diverged on modalities, funding responsibilities and the role of the multi-stakeholder community .
All these speakers agreed that the POC Directory should not replace existing communication channels and that coherence across multiple mechanisms is essential [13-17, 147-149, 76-77, 471-473, 218-221, 41-42]. However, they disagreed on the implications: Vanuatu focused on the administrative burden on small states operating multiple channels simultaneously , while Germany and Australia raised concerns about misuse and disproportionate use of the directory [473-474, 219-221]. The Netherlands and Ireland framed the issue as one of complementarity and added value [147-149, 76-77], whereas Israel emphasised the need for harmonisation across multilateral forums more broadly .
Agreed
VanuatuNetherlandsIrelandGermanyAustraliaIsrael
Contested
Need for coherence across multiple communication channels – The international community is multiplying its channels of communication; Vanuatu requests that the directory be developed in deliberate awareness of the wider ecosystem, with clear guidance on which channels serve which purpose (Vanuatu) POC Directory as complementary to, not replacing, existing channels – The strength and added value of the POC Directory are found in establishing lines of contact where these previously were unavailable or unclear; it should be a complementary tool, not a replacement for existing POC networks (Netherlands) POC Directory as a complement, not replacement, to existing channels – The POC Directory should be used as a complement to existing channels of communication between states, not as a replacement or duplication of established diplomatic or technical channels (Ireland) POC Directory as complementary to, not replacing, existing channels – The POC Directory is designed as a voluntary practical tool at the discretion of states; it should not replace established channels such as FIRST, the network of CERTs, or other diplomatic channels (Germany) Need for the directory to be actively maintained and tested – For the POC Directory to remain useful, it should be actively maintained, regularly tested, and supported by clear expectations of good faith use; requests should be proportionate and purposeful (Australia) Global mechanism should harmonise with other multilateral and regional forums – The global mechanism’s work should prioritise harmonising with other multilateral and regional forums and ensure that all outcomes are mutually reinforcing (Israel)
All speakers agreed that capacity building is a cross-cutting priority essential for implementing the framework for responsible state behaviour, and that it must be demand-driven, nationally owned and sustainable [692-694, 609-612, 672, 647-651, 759-760, 747-748]. However, they diverged on emphasis and modality: the African Group and Latin American group stressed the need for a dedicated DTG2 as the main platform [685-687, 672], while the EU highlighted its own significant financial investment and the role of the multi-stakeholder community in design and delivery . Colombia emphasised South-South and triangular cooperation as particularly valuable modalities , while Iraq focused on the need for financial and technical support to ensure equal opportunities . These differences reflect varying perspectives on who should lead and fund capacity building efforts.
Agreed
NIgeria on behalf of African GroupTonga on behalf of Pacific Islands ForumChile Representative on behalf of Latin American groupEuropean UnionColombiaIraq
Contested
Capacity building must be demand-driven, nationally owned and sustainable – Effective capacity building must be demand-driven, nationally owned, sustainable, and tailored to the specific needs and priorities of countries, respecting national sovereignty (NIgeria on behalf of African Group) Capacity building as foundational to all aspects of the mechanism’s work – Capacity building is the enabler that underpins all aspects of the work; it is foundational to responding to threats, implementing norms, engaging meaningfully in international law discussions, and sustaining CBMs (Tonga on behalf of Pacific Islands Forum) DTG2 as the main platform for capacity building dialogue – The DTG on capacity building must be established as the main platform for dialogue on this issue within the global mechanism, playing a fundamental role as a space for strategic coordination to facilitate information exchange and articulate synergies (Chile Representative on behalf of Latin American group) EU investment in cybercapacity building globally – The EU is working with partners on 27 projects with a value of 100 million euros and will continue to invest, recognising capacity building as an essential pillar of security and stability in cyberspace (European Union) South-South and triangular cooperation as valuable modalities – Modalities like South-South cooperation and triangular cooperation can play a particularly valuable role in capacity building, facilitating the exchange of knowledge and good practices while taking account of local realities and priorities (Colombia) Capacity building requires financial and technical support for equal opportunities – Capacity building should get financial and technical support so that equal opportunities are available to all states to benefit from international programmes and initiatives, with special attention to developing countries and countries emerging from conflict (Iraq)
All these speakers agreed that stakeholders from the private sector, civil society, academia and the technical community have an important role to play in CBM implementation and capacity building [82, 229, 621-625, 654, 114-115, 145-146]. However, they differed on the extent and nature of that role: the Pacific Islands Forum called for the fullest possible use of expert briefings within DTGs and improvements to accreditation and participation modalities , while Australia and Ireland emphasised preserving the intergovernmental nature of decision-making [229, 82]. Cuba, though not listed here, implicitly resisted broader stakeholder roles by emphasising state sovereignty and non-interference . The EU focused on coordination and avoiding duplication in stakeholder-delivered capacity building .
Agreed
IrelandAustraliaTonga on behalf of Pacific Islands ForumEuropean UnionUruguayNetherlands
Contested
Expertise of stakeholders should play a strong role – The expertise and experience of stakeholders from academia, the technical community, civil society and the private sector should play a strong role in the CBM implementation process, with practical tools and best practices feeding engagement (Ireland) Industry and technical community closest to vulnerabilities and risks – Industry and the technical community, civil society and academia are often closest to vulnerabilities, incidents and emerging risks; their expertise can help states understand threats, improve prevention and response, and translate CBMs into practical action (Australia) Stakeholder engagement essential for capacity building – Meaningful capacity building depends on access to the expertise of the multi-stakeholder community, academia, civil society, the private sector and the technical community; stakeholders must be substantively included in both formal and informal settings (Tonga on behalf of Pacific Islands Forum) Multi-stakeholder community role in designing and delivering capacity building – The role of the multi-stakeholder community in the design and delivery of cybercapacity building should be further discussed, recognising that industry, civil society and academia contribute meaningfully to effective and sustainable capacity building (European Union) Public-private partnerships essential for critical infrastructure protection – Given that a significant part of critical information infrastructure is operated by non-governmental actors or is part of the supply chain, public-private partnerships are essential to strengthen prevention, early alerts and fighting malicious information (Uruguay) Need for simulation exercises within DTGs – In simulation exercises within DTGs, states could see how public-private partnerships could concretely benefit an open, free and secure cyberspace and help prevent and address incidents (Netherlands)
African delegations broadly agreed that regional organisations play a decisive role in CBM implementation and that global efforts should strengthen rather than duplicate regional mechanisms [87-93, 236-237, 553-556, 343, 177-178, 480]. However, they differed on the degree of autonomy for regional approaches: the African Union Commission explicitly stated it does not wish to reproduce existing models , while Ghana and the African Group pointed to ECOWAS as a model that could inform global implementation [236-237, 87-93]. Cameroon focused on avoiding duplication , while Botswana and Mozambique emphasised the need for concrete national and regional mechanisms tailored to developing country realities [177-178, 480].
Agreed
NIgeria on behalf of African GroupGhanaAfrican Union CommissionCameroonBotswanaMozambique
Contested
Regional organisations play an important role in advancing CBMs – The global mechanism should strengthen coordination and complementarity between global and regional confidence-building initiatives and promote linkages between regional POC networks and the global directory (NIgeria on behalf of African Group) ECOWAS regional framework as a practical example – ECOWAS has developed a regional framework on cyber ICT confidence-building measures with Ghana’s participation, establishing practical mechanisms including national diplomatic and technical points of contact (Ghana) African Union developing adapted CBMs for African realities – The African Union Commission is developing concrete measures adapted to African realities that can be effectively implemented in the various regions of the continent, drawing on experience from economic and regional committees (African Union Commission) Avoiding duplication between global and regional mechanisms – The global mechanism should facilitate exchanges of experience among member states and regional organisations through workshops and knowledge-sharing initiatives, avoiding duplication of what already functions elsewhere (Cameroon) Botswana’s CERT and national cybersecurity strategy for critical infrastructure – Botswana has operationalised its national cybersecurity strategy and established the Botswana Computer Incident Response Team to coordinate incident management, issue threat advisories and safeguard national critical infrastructure (Botswana) CBMs as practical tools reducing misunderstanding – For developing countries, CBMs should move beyond political commitments and translate into concrete mechanisms that strengthen confidence, reduce the risk of misunderstanding and miscalculation, and improve collective resilience against cyber threats (Mozambique)
Latin American delegations broadly agreed on the value of DTGs for exchanging national and regional experiences and on the importance of building on existing regional mechanisms such as the OAS [123-124, 32-33, 517-523, 112-113]. However, they differed on the nature of CBMs: the Dominican Republic drew a sharp distinction between CBMs as preventive diplomacy tools and real-time crisis response mechanisms, arguing that bilateral technical cooperation was key during actual incidents , while Argentina and Chile focused more on the operationalisation of CBMs through the DTGs without drawing this distinction as sharply [123-124, 32-33]. Uruguay emphasised the OAS experience as a practical model , while the Dominican Republic highlighted lessons learned from ransomware incidents in the region .
Agreed
ArgentinaChileDominican RepublicUruguay
Contested
DTG1 for operationalising CBMs and DTG2 for capacity building support – DTG1 could examine operationalisation of CBMs by exchanging national and regional experiences, while DTG2 could identify capacities required to support this operationalisation effort (Argentina) DTGs as platforms for exchanging national experiences and good practices – The dedicated thematic groups offer a valuable opportunity to go into further depth on international relations and the role of international organisations in effective implementation of CBMs, exchanging national experiences and good practices (Chile) CBMs as preventive diplomacy tools – CBMs are preventive diplomacy tools, not necessarily mechanisms actionable in real time to respond to incidents; bilateral technical direct cooperation is key during actual crises (Dominican Republic) OAS regional experience as a model for CBM implementation – Regional experience in the OAS shows the practical value of CBMs; Uruguay has designated and updated its technical contact points in the OAS framework since 2018 and participates in cooperation mechanisms such as CERT Americas (Uruguay)
Key Takeaways
Confidence-Building Measures (CBMs) are widely recognised as indispensable tools for fostering trust, transparency, predictability and cooperation among states, contributing to international peace and security in cyberspace. There was broad consensus across all regional groups on their fundamental importance.
The Global Points of Contact (POC) Directory was identified as the flagship practical achievement of the Open-Ended Working Group (OEWG), with 125 states having joined. However, delegates acknowledged it faces significant operational challenges including dead contacts, low response rates (Russia reported approximately 48% of its inquiries were responded to), and instances of bad-faith or politically motivated non-responses.
There was strong consensus that CBMs are preventive diplomacy tools rather than real-time incident response mechanisms. The Dominican Republic highlighted from regional experience that bilateral technical direct cooperation is key during actual crises, with CBMs serving to build the trust that enables such cooperation.
The Dedicated Thematic Groups (DTGs) were broadly supported as the primary vehicles for translating agreed CBMs into practical action, with DTG1 focused on operationalising CBMs and DTG2 focused on capacity building. Multiple delegations emphasised these groups should produce practical, action-oriented outcomes rather than reproducing procedural disagreements from plenary sessions.
Regional organisations — including the OSCE, ECOWAS, OAS, ASEAN, African Union, and Pacific Islands Forum mechanisms — were consistently highlighted as valuable repositories of practical experience in CBM implementation that should inform and complement global-level work, with strong calls to avoid duplication.
Capacity building was identified as a cross-cutting enabler underpinning all pillars of the framework for responsible state behaviour, not merely a standalone pillar. It was described as the bridge between political commitments and practical implementation, particularly for developing countries, small island developing states, and least developed countries.
The POC Directory must be used in good faith and as a complement to — not a replacement for — existing diplomatic channels, regional mechanisms, and state-to-state engagement. Germany explicitly reported instances of repeated, identical, bad-faith requests from a specific state that did not take into account replies, which it characterised as inconsistent with the directory’s purpose.
Stakeholder engagement from the private sector, civil society, academia and the technical community was broadly supported as essential to effective CBM implementation and capacity building, while preserving the intergovernmental nature of decision-making.
Coherence across the expanding ecosystem of communication channels and mechanisms was identified as a priority concern, particularly for small states with limited officials managing multiple parallel channels simultaneously.
Inclusive participation — including through hybrid modalities, equitable meeting scheduling, multilingualism, and meaningful engagement of women and youth — was identified as a structural prerequisite for an effective global mechanism.
Resolutions & Action Items
States that have not yet done so were urged to join the Global POC Directory by designating appropriate diplomatic and technical points of contact, with a goal of achieving universal participation.
UNODA was commended for its ongoing operationalisation of the POC Directory, including regular ping tests, exercises and briefings, and was implicitly tasked with continuing these activities.
The finalisation of a standardised communication template for the POC Directory was identified as a priority task, with Russia indicating it has specific draft proposals and is ready to engage in discussion.
The DTGs were tasked with serving as platforms for exchanging national experiences, identifying capacity building needs, sharing good practices, and producing substantive recommendations for consideration by the plenary.
The Latin American group (Chile on behalf of Argentina, Brazil, Colombia, Costa Rica, Ecuador, Guatemala, Honduras, Mexico, Paraguay, Peru, Dominican Republic and Uruguay) announced it would soon present a working document with concrete proposals on the future functions, priorities and modalities of DTG2 on capacity building.
The Dominican Republic indicated it would prepare a working document on confidence-building measures for the December session, drawing on the cross-regional confidence builders group’s experience.
The African Group called for progress on specific practical initiatives including the Global ICT Security Cooperation and Capacity Building Portal, strengthened national CERTs, a Voluntary UN ICT Security Capacity Building Fund, and a UN ICT Security Fellowship Programme for developing countries.
The Russian Federation called upon the Chair to include a separate agenda item in the Global Mechanism’s programme of work specifically for discussing issues related to supporting and improving the POC Directory.
Regular simulation exercises and communication checks involving points of contact, national incident response teams and relevant authorities were recommended, including under UN auspices.
Tuvalu announced it would host the 19th Asia-Pacific Telecommunication Policy and Regulation Forum from 4 to 6 August, framing it as a practical confidence-building measure in itself.
Vietnam announced an initiative to establish an Asia-Pacific Regional Cybercrime Centre in Hanoi in cooperation with UNODC, welcoming participation from other states and stakeholders.
The African Union Commission committed to developing concrete CBMs adapted to African realities, drawing on experience from economic and regional committees including ECOWAS.
The OSCE indicated its continued readiness and availability to share regional experiences and lessons learned with the global mechanism.
The African Union Commission recommended that the global mechanism: institutionalise a technical and regular dialogue with regional organisations; strengthen support to regional organisations for CBM development and implementation; and facilitate integration of regional points of contact with the global POC Directory.
Unresolved Issues
The appropriate scope and boundaries of the POC Directory remain contested — specifically, how to balance its voluntary nature with expectations of responsiveness, and how to address politically motivated non-responses without undermining the directory’s credibility.
The question of how to address bad-faith or abusive use of the POC Directory (such as repeated identical requests that ignore replies) was raised by Germany but no agreed mechanism for addressing such conduct was identified.
The challenge of ‘dead contacts’ in the POC Directory — where designated officials are no longer active, authorised, or able to respond — was identified as a significant operational problem without a clear agreed solution, beyond general calls for states to update their information.
The precise division of labour and complementarity between DTG1 and DTG2, and between the DTGs and the plenary, remains to be worked out in practice, with risks of duplication or procedural disagreement noted by several delegations.
How to ensure that capacity building is genuinely demand-driven and nationally owned, rather than donor-driven, while still achieving coordination and avoiding duplication across the many existing initiatives, remains an unresolved structural challenge.
The question of whether and how to develop new CBMs — including Iran’s proposals on facilitating access to ICT security products and tools, and developing a consolidated list of technical ICT terms — was raised but not resolved, with Iran calling for these to be incorporated into the existing set of eight voluntary global CBMs.
The relationship between the global mechanism’s CBM work and parallel processes (including the UN Convention against Cybercrime’s 24/7 network, regional arrangements, and bilateral channels) and how to ensure coherence without creating confusion for small states managing multiple channels simultaneously, was identified but not resolved.
How to operationalise the POC Directory as an effective crisis communication tool — rather than merely a directory of contacts — including the development of in-person meetings of POC representatives as envisaged in the OEWG final report, remains to be addressed.
The financing of capacity building for developing countries, small island developing states and least developed countries — including the proposed Voluntary UN ICT Security Capacity Building Fund — was called for by multiple delegations but no concrete funding commitments or mechanisms were agreed.
How to meaningfully integrate stakeholder participation (private sector, civil society, academia, technical community) into the DTGs and other mechanism work, while preserving the intergovernmental nature of decision-making, remains an open question with differing views on the appropriate modalities.
The scheduling of DTG meetings in ways that do not systematically disadvantage Pacific and other geographically distant delegations was raised as an unresolved practical concern.
The question of how to measure and report on the real-world implementation and effectiveness of CBMs — including response metrics for the POC Directory — was raised by the Dominican Republic but not resolved.
How to protect critical subsea cable infrastructure through international guidance or an explicit CBM commitment, as proposed by Tuvalu, was raised but not addressed by other delegations.
Suggested Compromises
Multiple delegations suggested that the POC Directory should be understood as a complementary tool to existing channels rather than a replacement, which represents an implicit compromise between those who see it as a primary crisis communication mechanism and those who prefer to rely on established bilateral and regional channels.
The framing of CBMs as voluntary and action-oriented tools at the discretion of states — rather than obligations or benchmarks — was broadly accepted as a compromise position that accommodates both those seeking stronger commitments and those emphasising sovereignty and non-interference.
The suggestion that regional CBM frameworks should not be treated as single global models or benchmarks (Cuba, echoed by others) represents a compromise between the desire for global coherence and the recognition of regional diversity and different levels of development.
The proposal that DTG1 focus on operationalising CBMs while DTG2 focuses on capacity building, but that both groups work in a complementary and balanced manner with CBMs as a cross-cutting theme, represents a structural compromise between those who wanted capacity building to be the primary focus and those who prioritised CBM operationalisation.
The suggestion by Argentina that DTG recommendations be subsequently reviewed, fine-tuned and negotiated by states in plenary deliberations represents a compromise between those seeking more binding DTG outputs and those insisting on plenary primacy for consensus-based decisions.
The framing of the global roundtable on capacity building as a coordination mechanism that feeds into — rather than duplicates or replaces — DTG2 discussions represents a suggested compromise on the architecture of the mechanism’s capacity building work.
Germany’s articulation that the POC Directory has great potential primarily to facilitate voluntary coordination and communication between states and enhance cooperation on the basis of good faith engagement — rather than serving as a mechanism for addressing strategic security concerns — represents a suggested compromise on the directory’s scope and purpose.
The broad acceptance that capacity building is both a standalone pillar and a cross-cutting enabler of all other pillars represents a compromise between those who wanted it treated primarily as a dedicated thematic area and those who argued it should permeate all aspects of the mechanism’s work.
“Vanuatu’s observation that ‘confidence is not built by the number of channels that exist, or the volume of requests within them, but by the certainty of what happens when one is used.’ They also drew a compelling analogy between disaster response communication habits and cyber incident response, arguing that ‘a region accustomed to cooperating through cyclones is well-placed to cooperate through cyber incidents.’”
“Tonga’s statement: ‘When our health system was attacked last year, established relationships with partners enabled rapid assistance and ultimately a joint public attribution with Australia and New Zealand. This is what confidence building measures look like when they work. Relationships built before the crisis, exercised during it and deepened after it.’ Tonga also urged the mechanism to ‘keep the CBM agenda modest in rhetoric and ambitious in practice.’”
“The Russian Federation’s detailed statistical disclosure: ‘There were 2,576 inquiries [to Russian POCs last year]. Out of those, around 48% of them were responded to.’ The Russian delegation attributed this to ‘dead contacts,’ misdesignation of technical POCs, and cases where ‘certain capitals simply ignore our requests for political reasons.’ Russia also called for a separate agenda item dedicated to POC directory governance.”
“Germany’s disclosure that its technical POC ‘continued receiving repeated identical requests from the same sender, whilst not taking into account our replies,’ characterising this as ‘clearly not in line with the purpose of the UN POC directory and does not present a responsible or sincere use of the directory.’”
“The Dominican Republic’s frank assessment: ‘CBMs are preventive diplomacy tools, they are not necessarily mechanisms that are actionable in real time to respond to incidents.’ They also called for transparency in POC directory response metrics, arguing this ‘would reflect the real results of implementation and the real commitment of each and every one of the parties.’”
“Côte d’Ivoire’s recommendation to ‘promote a culture of restraint and responsibility,’ specifying that ‘when incidents happen, states must prioritize consultations, the exchange of information, and a rigorous establishment of the facts while avoiding any premature accusations that might fuel escalation.’”
“Australia’s nuanced warning that the POC directory ‘should not be treated as a mechanism for overwhelming national points of contact, creating unreasonable expectations of response, or as a substitute for existing procedures where other channels are more appropriate,’ and that requests ‘should be proportionate, purposeful’ and made ‘with due regard to the capacity constraints of smaller states.’”
“Iran’s proposal that the global mechanism ‘prepare a consolidated list of technical terms used in the consensus-based reports of the OEWG and subsequently undertake discussions to develop common understandings of key concepts such as ICTs, ICT infrastructure, ICT environment and malicious use of ICTs,’ and that access to ICT security products and tools be recognised as a new CBM.”
“Tuvalu’s call for ‘an explicit CBM — a commitment from all member states and stakeholders to share best practice to safeguard [subsea cable] essential digital lifeline from both natural hazard and malicious cyber threats,’ and their framing of ‘capacity sovereignty’ as requiring ‘long-term training of our own local technical teams’ rather than ‘short-term external consulting.’”
“Costa Rica’s warning that ‘without capacities, we run the risk of building a legally elegant infrastructure that is operationally useless,’ and their argument that ‘legal interpretation also requires specialised institutional capacities’ including the ability to ‘evaluate incidents, establish national positions on the application of international law to cyberspace, to understand the different legal thresholds.’”
How can the Global Points of Contact Directory be developed with deliberate awareness of the wider ecosystem of communication channels, including the 24/7 network under the UN Convention against Cybercrime and existing third-party relationships?
Vanuatu
Vanuatu raised the concern that small administrations must operate multiple communication channels simultaneously, often through the same handful of officials. Clarifying which channel serves which purpose and avoiding duplication is essential for practical implementation, particularly for smaller states.
How can the habit of rapid, trusted state-to-state communication developed during physical emergencies (e.g., cyclones) be formally connected to and reinforced by cyber incident response frameworks?
Vanuatu
Vanuatu observed that Pacific states already cooperate effectively during natural disasters and suggested this existing culture of cooperation could be leveraged for cyber incidents. Further research into how emergency communication habits translate to digital contexts could yield practical CBM models.
What are the most effective modalities for regular communications exercises for the Global POC Directory, and how should training for designated officials be structured to ensure continuity when personnel change?
Vanuatu, Tonga, Argentina, Dominican Republic, Malaysia, Australia
Multiple delegations highlighted that the directory’s value depends on trained, points of contact. Understanding how to design exercises and training programmes that account for staff turnover and varying national capacities is a key operational gap.
How can the Dedicated Thematic Groups (DTGs) best facilitate the exchange of national experiences and regional good practices on CBM implementation, particularly regarding contact point mechanisms, diplomatic and technical consultations, and voluntary incident information exchange?
Chile, Argentina, Ireland, Malaysia, North Macedonia
Several delegations identified the DTGs as the primary vehicle for operationalising CBMs but noted that their structure and focus need to be clearly defined to avoid duplicating plenary discussions and to produce substantive, actionable recommendations.
How should the Global Mechanism harmonise its CBM work with other multilateral and regional forums (e.g., OECD, Council of Europe, Mediterranean Partnerships) to ensure mutually reinforcing outcomes?
Israel
Israel stressed the need for coherence across multilateral and regional bodies. Further research is needed on how to map existing CBM frameworks and identify overlaps, gaps, and opportunities for alignment without creating conflicting obligations.
What practical mechanisms can be established to promote a culture of restraint and responsibility among states when cyber incidents occur, including prioritising consultation and rigorous fact-finding before making public attributions?
Côte d'Ivoire, Russian Federation, Cameroon
Several delegations warned that premature or unsubstantiated political attributions of cyber attacks can escalate tensions. Research into norms and procedures for responsible attribution and restraint is needed to complement existing CBMs.
How can simulation exercises involving points of contact, national CERTs, and relevant authorities be regularly organised under UN auspices, and what format would be most effective for different regional contexts?
Multiple delegations called for regular simulation exercises as a practical CBM, but the design, frequency, and inclusivity of such exercises remain open questions requiring further development and research.
What are the specific metrics and response rates for the Global POC Directory, and should these be made publicly available to improve transparency and accountability?
Dominican Republic, Russian Federation
The Dominican Republic called for sharing response metrics to reflect real implementation results and commitment. The Russian Federation provided statistics showing approximately 48% response rates to its POC inquiries. Understanding the causes of non-response and how to improve them is a critical area for further investigation.
How can ‘dead contacts’ in the Global POC Directory be identified and resolved, and what notification mechanisms should be established to inform states of ping test results?
Russian Federation
The Russian Federation identified dead contacts and misdesignation of technical POCs as significant operational problems. Developing a systematic process for identifying, notifying, and resolving inactive or incorrectly designated contacts is essential for the directory’s effectiveness.
What should a standardised communication template for the Global POC Directory contain, particularly to meet the distinct needs of diplomatic versus technical points of contact?
Russian Federation, Thailand
The Russian Federation noted that a draft template was presented by UNODA but not fully discussed before the OEWG’s final report. Thailand suggested incorporating urgency and confidentiality elements. Further deliberation on the template’s content and format is needed.
How can in-person meetings of POC representatives be organised, and what would be the most effective format and frequency for such gatherings?
Russian Federation
The OEWG final report envisaged in-person meetings of POC representatives, but the modalities for such meetings have not been determined. Research into how other international POC networks (e.g., OSCE) organise such meetings could inform this process.
How should the Global Mechanism address cases where states ignore POC directory requests for political reasons, and what norms of good faith use should be established?
Russian Federation, Germany, Australia
Both the Russian Federation and Germany reported instances of bad faith or politically motivated non-engagement with the directory. Establishing clear expectations and norms for responsible use of the directory is an unresolved issue requiring further discussion.
Should a new confidence-building measure be developed to facilitate access by all states to ICT security products and tools, and how would this interact with existing CBMs and capacity-building efforts?
Islamic Republic of Iran
Iran highlighted a proposal from the OEWG final report (paragraph 47k) for a new CBM on access to ICT security products and tools. Whether and how to incorporate this into the existing eight voluntary CBMs requires substantive discussion in the DTGs.
Could the Global Mechanism prepare a consolidated list of technical ICT terms and develop common understandings of key concepts such as ‘ICTs’, ‘ICT infrastructure’, ‘ICT environment’, and ‘malicious use of ICTs’?
Islamic Republic of Iran
Iran referenced paragraph 52 of the OEWG final report encouraging voluntary sharing of national views on technical terminology. A lack of common definitions can impede cooperation and mutual understanding; developing shared terminology is a foundational research and policy task.
How can regional CBM frameworks (e.g., ECOWAS, OAS, ASEAN, OSCE, African Union) be better integrated with the Global POC Directory and the global CBM framework to avoid duplication and maximise coherence?
African Union Commission, Nigeria on behalf of African Group, Ghana, Philippines, Malaysia, OSCE
Multiple delegations and regional organisations highlighted the risk of fragmentation and duplication between regional and global CBM mechanisms. Research into how to map, align, and institutionalise linkages between these frameworks is a priority.
How can capacity building and confidence building be better integrated as mutually reinforcing pillars, ensuring that states have the institutional, technical, and human resource foundations needed to implement CBMs effectively?
Several delegations noted that many states cannot implement CBMs without first receiving capacity-building support. Research into how to sequence and link these two pillars in practice, particularly for developing countries, is essential.
What role should academia, the technical community, civil society, and the private sector play in the design and delivery of CBMs and capacity-building activities, and how can their participation be structured within the intergovernmental nature of the mechanism?
Ireland, Uruguay, Norway, Australia, Philippines, Tonga on behalf of Pacific Islands Forum, European Union
Multiple delegations stressed the value of multi-stakeholder expertise but also the need to preserve the state-led nature of the process. Defining appropriate modalities for stakeholder engagement in both DTGs and plenary sessions is an open question.
How can the POC Directory be used to build trust rather than strain it, and what guidelines should govern proportionate and purposeful use of the directory, particularly with regard to the capacity constraints of smaller states?
Australia, Germany, Netherlands
Australia warned against overwhelming smaller states’ POCs with disproportionate requests, while Germany reported receiving repetitive, identical messages. Developing clear guidelines for responsible and proportionate use of the directory is a pressing operational need.
How can cooperation on vulnerability disclosure, mitigation, and supply chain integrity be operationalised as practical CBMs, and what role can the Global Mechanism play in facilitating this?
Australia
Australia highlighted vulnerability disclosure and supply chain integrity as practical CBMs that could reduce risk and build resilience. Further research into how these can be structured as voluntary, implementable measures within the global framework is needed.
How can the Western Balkans Cyber Diplomacy Network and similar sub-regional initiatives serve as models for building cyber confidence in other regions, and what lessons can be drawn for the global mechanism?
Bosnia and Herzegovina
Bosnia and Herzegovina highlighted the 2025 launch of the Western Balkans Cyber Diplomacy Network as a regional CBM initiative. Studying its design and early outcomes could provide transferable lessons for other regions and for the global mechanism.
How can the African Union’s continental CBM framework be developed in a way that is adapted to African regional realities rather than reproducing existing models, and how should it be integrated with global efforts?
African Union Commission
The African Union Commission stated its ambition to develop concrete, adapted CBMs suited to African realities rather than copying existing frameworks. Research into what specific measures would be most effective and implementable across Africa’s diverse sub-regions is needed.
How should the OSCE’s ‘Adopt-a-CBM’ initiative and its annual meetings of technical and policy points of contact be used as models or inputs for the Global Mechanism’s CBM implementation approach?
OSCE
The OSCE shared extensive experience with its 16 CBMs and the Adopt-a-CBM initiative, where 26 participating states have adopted nine CBMs. Examining how this model could be adapted for the global mechanism’s broader and more diverse membership is a valuable area for further research.
How can inter-regional cooperation between regional organisations on cyber CBMs be institutionalised, and what role should a formal dialogue mechanism between the Global Mechanism and regional organisations play?
OSCE, African Union Commission, Nigeria on behalf of African Group
The OSCE referenced a non-paper on inter-regional cooperation submitted by Switzerland in 2024. The African Union Commission called for institutionalised technical dialogue between the global mechanism and regional organisations. Developing a formal framework for this cooperation is an unresolved structural question.
How can youth be meaningfully included in CBM discussions and activities, and what specific mechanisms (e.g., structured dialogues, youth-led initiatives, cross-border exchanges) would be most effective?
DMUN Foundation
The DMUN Foundation highlighted that young people are among the most affected by cyber incidents yet are rarely included in CBM discussions. Research into effective models for youth engagement in international cybersecurity governance is needed.
How can the Global Mechanism ensure that capacity-building efforts are demand-driven, nationally owned, and sustainable rather than supply-driven or short-term, and what assessment tools (e.g., cybersecurity capacity maturity models) should be used to measure progress?
CARICOM (Bahamas), Nigeria on behalf of African Group, Colombia, Costa Rica, Morocco
Multiple delegations stressed that capacity building must be tailored to national needs and priorities rather than imposed externally. Research into how to design assessment frameworks and matching mechanisms that connect recipient needs with available expertise and funding is a priority.
How can the DTG2 on capacity building serve as a strategic coordination platform rather than duplicating plenary discussions, and what specific deliverables (e.g., diagnostic assessments, needs mapping, action-oriented recommendations) should it produce?
Chile on behalf of Latin American group, Nigeria on behalf of African Group, Colombia, European Union
Several delegations called for DTG2 to be results-focused and action-oriented, but the specific format, deliverables, and relationship to plenary discussions remain to be defined. Clarifying the DTG’s mandate and working methods is essential for its effectiveness.
How can South-South and triangular cooperation modalities be better utilised for cybersecurity capacity building, and what role can regional mechanisms play in facilitating these exchanges?
Colombia, Chile on behalf of Latin American group
Colombia and the Latin American group highlighted South-South and triangular cooperation as particularly valuable for sharing contextually relevant knowledge. Research into existing models and how they can be scaled or formalised within the global mechanism is needed.
How can real case studies and hypothetical scenarios be incorporated into DTG2 discussions to generate concrete lessons and practical recommendations on cyber incident response cooperation?
Colombia
Colombia proposed using specific case studies and simulation exercises within DTG2 to move beyond abstract discussion. Developing a methodology for selecting, presenting, and drawing lessons from such cases is an area requiring further work.
How can the Global ICT Security Cooperation and Capacity Building Portal, the Voluntary UN ICT Security Capacity Building Fund, and the UN ICT Security Fellowship Programme be operationalised and adequately resourced?
Nigeria on behalf of African Group, Nigeria (national capacity)
The African Group and Nigeria called for progress on these specific initiatives as practical capacity-building tools. The modalities, governance, funding mechanisms, and eligibility criteria for these instruments remain to be developed.
How can the full, equal, and meaningful participation of women and youth in cybersecurity capacity-building programmes be ensured, and what specific initiatives or fellowship programmes have proven effective?
Nigeria (national capacity), Nigeria on behalf of African Group, Norway
Multiple delegations stressed the importance of gender-inclusive capacity building. Research into effective models, such as the UNODA and donor-sponsored Women in International Security and Cyberspace Fellowship, and how to scale them is needed.
How can the Asia-Pacific Regional Cybercrime Centre being established in Hanoi (in cooperation with UNODC) contribute to regional capacity building and CBM implementation, and how can other states and stakeholders participate?
Vietnam
Vietnam announced the initiative to establish an Asia-Pacific Regional Cybercrime Centre and invited participation from other states and stakeholders. Further research into its mandate, governance, and relationship to the global mechanism is needed.
How can the protection of critical subsea cable infrastructure be addressed through explicit international CBMs, and what guidance should the Global Mechanism develop on this issue?
Tuvalu
Tuvalu highlighted its Tuvalu Subsea Cable as a vital digital lifeline and called for explicit CBMs and international guidance on protecting subsea infrastructure from both natural hazards and malicious cyber threats. This is an emerging area with limited existing international guidance.
How can the Global Mechanism support ‘capacity sovereignty’ — the long-term training of local technical teams rather than reliance on short-term external consulting — and what modalities would best achieve this?
Tuvalu
Tuvalu called for a shift from short-term external consulting to sustainable, locally owned technical capacity. Research into effective models for building indigenous cybersecurity expertise in small island developing states is a priority area.
How can hybrid participation modalities and time-zone-sensitive scheduling be improved to ensure that small and geographically distant delegations (e.g., Pacific Island states) can participate meaningfully in DTG meetings?
Tonga on behalf of Pacific Islands Forum, Vanuatu
Pacific delegations noted that current meeting times often require them to participate in the middle of the night. Research into how to design inclusive participation modalities that do not systematically disadvantage certain regions is needed.
How can the Global Mechanism’s accreditation and participation modalities for non-state stakeholders be improved to ensure that their engagement is substantive rather than nominal?
Tonga on behalf of Pacific Islands Forum
The Pacific Islands Forum expressed concern that stakeholder participation is currently more nominal than real. Research into how other UN mechanisms have successfully integrated multi-stakeholder expertise while preserving the intergovernmental nature of decision-making could inform improvements.
How can the severity scale for cyber incidents developed within the OAS framework be adapted or adopted at the global level to help states prioritise and scale cooperation between national CERTs?
Dominican Republic
The Dominican Republic highlighted the OAS’s common incident severity scale as a practical tool that enables states to understand and respond proportionately to incidents affecting other members. Exploring whether and how this could be adopted globally is a valuable area for further research.
How can institutional continuity for CBM implementation be maintained during staff turnover, particularly in developing countries, and what mechanisms (e.g., documented procedures, institutional memory systems) are most effective?
Dominican Republic
The Dominican Republic identified staff turnover as a significant challenge for sustaining CBM implementation, particularly in Latin American countries. Research into best practices for institutional continuity in cybersecurity governance is needed.
How can the Cyber Security Centre for Latin America and the Caribbean (headquartered in Santo Domingo) serve as a model for point-to-point cooperation that sustains capacity building, and how can similar regional centres be established in other regions?
Dominican Republic
The Dominican Republic highlighted this centre as an example of how regional specialised technical assistance can sustain capacity building. Research into its governance model, funding, and outcomes could inform the establishment of similar centres elsewhere.
How can the Global Mechanism facilitate a structured diagnostic assessment of the current global capacity-building landscape to identify gaps, avoid duplication, and match needs with available expertise and resources?
Nigeria on behalf of African Group, European Union, Colombia
Multiple delegations called for a systematic mapping of existing capacity-building initiatives. The African Group specifically welcomed a proposal for a structured diagnostic assessment as a DTG2 deliverable. Developing the methodology and scope for such an assessment is a priority research task.
How can the Global Roundtable on Capacity Building be used to enhance coordination among capacity-building implementers, and how should its outputs feed into DTG2 and plenary discussions?
European Union
The EU suggested the Global Roundtable on Capacity Building could play a coordination role, but its relationship to the DTGs and plenary has not been clearly defined. Research into effective models for such roundtables in other UN contexts could inform its design.
How can the voluntary norms implementation checklist be further developed into a digital tool to support states’ implementation of the UN framework, and what features would make it most useful for diverse national contexts?
European Union
The EU proposed building on the voluntary norms implementation checklist to develop a broader digital support tool. Research into user needs, technical requirements, and governance of such a tool is needed before it can be developed.
How can the ICT security capacity-building guidelines adopted in the 2021 OEWG report be mainstreamed into relevant ICT security and cyber capacity-building programming at national and regional levels?
European Union
The EU called for mainstreaming the 2021 OEWG capacity-building guidelines into programming. Research into how these guidelines are currently being used, where gaps exist, and how to promote their adoption is needed.
How can the applicability of international law to cyberspace — including sovereignty, non-intervention, international humanitarian law, and the peaceful settlement of disputes — be clarified through capacity-building activities, and what role should the DTGs play in this?
Vietnam, Costa Rica
Vietnam and Costa Rica highlighted that states need capacity to understand how international law applies to cyberspace and to develop national positions. Research into effective training and capacity-building modalities for cyber law and diplomacy is needed.
How can the Global Mechanism support the development of cyber diplomacy strategies that integrate legal, technical, and political knowledge, enabling states to coherently represent national interests in international fora?
Costa Rica
Costa Rica identified cyber diplomacy as a specialised capacity that many states lack. Research into what constitutes effective cyber diplomacy training and how it can be delivered in a sustainable, regionally adapted manner is a priority.
How can public-private partnerships be structured within the global CBM and capacity-building framework to leverage private sector expertise on vulnerabilities, incidents, and emerging risks while preserving the intergovernmental nature of decision-making?
Netherlands, Uruguay, Botswana, Philippines, Costa Rica
Multiple delegations highlighted the importance of public-private partnerships but also the need to maintain state leadership. Research into effective governance models for such partnerships in the cybersecurity context is needed.
How can the Global Mechanism develop and promote national positions on how international law applies in cyberspace, and what support can be provided to states that lack the resources to undertake this process independently?
Netherlands
The Netherlands called on all member states to develop and publish national positions on international law in cyberspace and offered to share best practices. Research into what support mechanisms (e.g., model frameworks, technical assistance, peer review) would be most effective for resource-constrained states is needed.
Disclaimer: This is not an official session record. DiploAI generates these resources from audiovisual recordings, and they are presented as-is, including potential errors. Due to logistical challenges, such as discrepancies in audio/video or transcripts, names may be misspelled. We strive for accuracy to the best of our ability.
The sixth plenary meeting of the UN Global Mechanism on ICTs in the context of international security opened with statements from fourteen accredited non-governmental stakeholders, followed by an interactive dialogue with member states, before transitioning to discussions on international law and confidence-building measures (CBMs).
Several stakeholder organisations raised urgent concerns about the exclusion of over sixty entities from formal participation, calling on member states to honour multi-stakeholder principles affirmed in the Global Digital Compact and to disclose the basis of their objections. The Discover MUN Foundation, speaking for children and youth, demanded age-disaggregated data on malicious ICT activity, a dedicated youth capacity-building track, and recognition of youth engagement as a confidence-building measure in its own right. ICANN, the Internet Society, and FIRST each highlighted the indispensable role of the technical community in DNS security, routing resilience, and incident response, urging states to engage actively with existing multi-stakeholder mechanisms.
The Centre for Humanitarian Dialogue drew attention to the largely unexplored challenge of designing cyber confidence-building measures for post-conflict environments, noting that malware cannot be corralled or observed in the way conventional weapons can. On international law, a broad cross-regional majority reaffirmed that existing international law, including international humanitarian law and human rights law, applies fully in cyberspace, while states such as Algeria and Nicaragua called for the progressive development of legally binding instruments.
The ICRC urged states to focus discussions on how IHL limits ICT operations causing non-physical damage and to address the growing use of AI in military cyber activities.
Switzerland and Australia emphasised that the dedicated thematic groups (DTGs) should translate legal convergences into practical, scenario-based implementation work.
Regarding confidence-building measures, delegations broadly supported the operationalisation of the eight voluntary CBMs agreed under the previous Open-Ended Working Group, with particular emphasis on the Global Points of Contact Directory as a practical tool for crisis communication.
Small island developing states, including Kiribati and Nauru, stressed that the directory and related CBMs are not merely convenient but essential for states lacking extensive bilateral cyber channels.
Regional organisations were consistently highlighted as laboratories for CBM implementation, with the Pacific Cybersecurity Operational Network cited as a model of trust built through routine operational contact.
The session concluded with the Chair noting eighteen remaining speakers on confidence-building measures, confirming that discussions would continue the following day, underscoring the depth of engagement this foundational plenary had generated.
Keypoints
Overall Purpose
The discussion took place during the sixth meeting of the first plenary session of the UN Global Mechanism on ICTs in the context of international security. The session aimed to advance responsible state behaviour in the use of ICTs by hearing contributions from accredited non-governmental stakeholders, debating the application of international law to cyberspace, and discussing the development and implementation of confidence-building measures (CBMs) among member states.
—
Major Discussion Points
Stakeholder participation and accreditation concerns: Multiple accredited organisations and member states raised serious concerns about the large number of stakeholder entities – over 60 – that had been blocked from participating in the plenary sessions without any stated basis for objection. Speakers argued that this undermined the multi-stakeholder principles affirmed in the Global Digital Compact and the World Summit on Information Society. Canada specifically named excluded organisations from Mexico, Brazil, Peru, Panama, Ghana, Nigeria, and South Africa as examples of the harm caused by these vetoes. The Association for Progressive Communications described the situation as “an injury inflicted on itself” by the mechanism. Several delegations, including the EU, Chile, and Germany, echoed these concerns and called for transparent, criteria-based accreditation practices.
The role and rights of children, youth, and vulnerable communities in cyberspace: The Discover MUN Foundation, speaking on behalf of the Major Group for Children and Youth, called for age-disaggregated data on malicious ICT activity, a dedicated children and youth capacity-building track, and recognition of meaningful youth engagement as a confidence-building measure in its own right. The Association for Progressive Communications and InternetLab highlighted the disproportionate impact of cyber threats on women, LGBTQI+ people, human rights defenders, and communities in the Global South, calling for gender-sensitive cybersecurity laws and evidence-based approaches to differentiated harms. Access Now documented 313 Internet shutdowns in 2025, 125 of which occurred in conflict situations, underscoring the human cost of ICT misuse. – Application of international law to cyberspace, including IHL and human rights law: A significant portion of the discussion focused on how existing international law – including sovereignty, non-intervention, the prohibition on the use of force, international humanitarian law (IHL), and international human rights law – applies to state conduct in cyberspace. Switzerland, Australia, and the ICRC emphasised that IHL applies to ICT activities in armed conflict and called for focused discussions on protecting civilian infrastructure, medical facilities, and humanitarian organisations from cyber harm. Algeria and Nicaragua supported the elaboration of legally binding international instruments to provide greater legal clarity, arguing that voluntary norms alone are insufficient. The United States, by contrast, maintained that existing international law remains fit for purpose and opposed any effort to use the mechanism as a vehicle for treaty-making. – Operationalisation of confidence-building measures (CBMs), particularly the Global Points of Contact Directory: Numerous delegations stressed the importance of moving from endorsement to practical implementation of the eight voluntary CBMs agreed under the OEWG. The Global Points of Contact (POC) Directory was widely cited as one of the most significant achievements of the previous process, with states such as Kiribati, Nauru, and Singapore emphasising its critical value for small island developing states that lack extensive bilateral cyber channels. Speakers called for regular communication checks, simulation exercises, and capacity-building support to ensure the directory functions effectively in real incidents. Regional organisations such as the Pacific Cybersecurity Operational Network (PACSON) and the OSCE were highlighted as valuable laboratories for CBM implementation.
Capacity building as a cross-cutting priority, especially for developing countries: Across all agenda items, delegations and stakeholders consistently identified capacity building as essential to enabling all states – particularly developing countries and small island developing states – to participate meaningfully in the framework. Developing Capacity LTD highlighted the Sybil Portal as an existing repository of resources, while Chatham House referenced its operationalisation paper on cyber capacity-building principles. The African Union reported convening a workshop in Addis Ababa in June 2026 to strengthen member states’ capacity to develop national positions on international law in cyberspace. The Dominican Republic’s cross-regional group announced a forthcoming working paper on CBM implementation drawing on regional best practices. —
Overall Tone
The overall tone of the discussion was constructive and collaborative, with delegates and stakeholders expressing genuine commitment to advancing responsible state behaviour in cyberspace. However, there was a notable undercurrent of frustration – particularly regarding the exclusion of accredited stakeholders – which surfaced repeatedly across both the stakeholder segment and state interventions. The tone became more pointed during the international law debate, where clear divisions emerged between states favouring legally binding instruments and those insisting existing law is sufficient, reflecting deeper geopolitical tensions. By the confidence-building measures segment, the atmosphere shifted towards a more pragmatic and solution-oriented register, with many delegations sharing concrete national experiences and expressing optimism about the mechanism’s potential to deliver practical results. Throughout, the Chair maintained a measured and inclusive tone, actively encouraging dialogue and acknowledging all contributions.
Speakers Overview
DM
Discover MUN Foundation
137 wpm · 4 min
I
ICANN
108 wpm · 4 min
FS
FutureEarth Systems
127 wpm · 3 min
FO
Forum of Incident Response and Security Teams
118 wpm · 5 min
CF
Centre for Humanitarian Dialogue Representative
130 wpm · 3 min
DC
Developing Capacity LTD
123 wpm · 4 min
II
IMQ Intuity SPA
118 wpm · 3 min
MS
Moscow State Institute of International Relations
129 wpm · 3 min
IS
Internet Society
163 wpm · 4 min
KI
Kenya ICT Action Network
112 wpm · 4 min
AF
Association for Progressive Communications
144 wpm · 5 min
RI
Royal Institute of International Affairs (Chatham House) Representative
165 wpm · 5 min
I
InternetLab
122 wpm · 4 min
AN
Access Now
144 wpm · 4 min
C
Canada
139 wpm · 4 min
J
Japan
110 wpm · 1 min
M
Mexico
131 wpm · 2 min
EU
European Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San Marino
157 wpm · 7 min
C
Chile
136 wpm · 1 min
G
Germany
179 wpm · 48 s
US
United States
154 wpm · 1 min
I
ICRC
108 wpm · 6 min
S
Switzerland
164 wpm · 9 min
A
Australia
152 wpm · 4 min
N
Nicaragua
130 wpm · 2 min
A
Algeria
157 wpm · 4 min
AU
African Union
104 wpm · 4 min
TD
The Dominican Republic
143 wpm · 3 min
TO
Tonga on behalf of the Forum of Pacific Islands
113 wpm · 3 min
RO
Republic of Korea
127 wpm · 2 min
CR
Costa Rica
164 wpm · 3 min
A
Albania
124 wpm · 6 min
I
Italy
126 wpm · 4 min
K
Kiribati
115 wpm · 5 min
UK
United Kingdom
138 wpm · 2 min
S
Serbia
123 wpm · 2 min
SA
South Africa
189 wpm · 3 min
S
Singapore
172 wpm · 3 min
N
Naoero
127 wpm · 4 min
PN
Papua New Guinea
131 wpm · 7 min
IC
International Chamber of Commerce
143 wpm · 4 min
CE
Chair Egriselda López
125 wpm · 18 min
Expanded Summary: Sixth Meeting of the First Plenary Session of the UN Global Mechanism on ICTs in the Context of International Security
#
Opening and Session Overview
Chair Egriselda López called to order the sixth meeting of the first plenary session of the UN Global Mechanism on ICTs in the context of international security, formally titled the Global Mechanism on ICTs in the Context of International Security and Advancing Responsible State Behaviour in the Use of ICTs . Following the resolution of technical difficulties, the Chair outlined the session’s agenda, noting that fourteen accredited organisations had requested the floor and would each be allocated four minutes . She expressed particular gratitude to stakeholders who had travelled to New York to contribute to the mechanism’s work . The session proceeded through three substantive phases: a stakeholder segment, an interactive dialogue with member states, and discussions on international law and confidence-building measures (CBMs), concluding with eighteen delegations still on the speakers’ list for the CBM agenda item, confirming that discussions would continue the following day .
—
#
Stakeholder Segment: Substantive Contributions from Accredited Organisations
A recurring theme throughout the stakeholder segment was concern about the exclusion of numerous organisations from formal participation in the mechanism. Multiple stakeholders raised objections to the blocking of accredited entities, and this concern was subsequently echoed by several member states in the interactive dialogue. The following summaries note where individual speakers addressed this theme.
The Discover MUN Foundation, speaking on behalf of the Major Group for Children and Youth – described as the mandated children and youth constituency at the UN representing over 20,000 distinct youth organisations – opened the stakeholder segment with a series of concrete demands . The Foundation highlighted that dual-use technologies, from AI-driven malware to deepfake social engineering, are being weaponised against digital spaces, with children and young people facing the most immediate attacks on their digital safety and rights . It called on member states to consider age-disaggregated data on malicious ICT activity in their submissions, and to take account of General Comment No. 25 of the Committee on the Rights of the Child, which establishes that children’s rights apply fully and equally in the digital environment . On capacity building, the Foundation called for a dedicated children and youth track modelled on successful examples such as the UNIDIR Women in International Security and Cyberspace Fellowship, which effectively integrates young technical experts in national delegations . Consistent with the Youth Peace and Security Agenda under Security Council Resolution 2250, it further called for meaningful engagement with children and youth to be recognised as a confidence-building measure in its own right .
The Foundation also addressed the critical issue of stakeholder participation directly, noting that objections lodged against more than sixty stakeholder entities – including NGOs, universities, and technical bodies – without any stated basis whatsoever cannot be considered consistent with inclusivity . It called upon member states to honour the multi-stakeholder principles affirmed in both the Global Digital Compact and the WSIS+20 review by disclosing the basis of their objections, and thanked the EU and its member states for acting as a leading example of transparency in this regard . The Foundation concluded with a call for transparent, criteria-based accreditation practices to ensure predictable, principled, and objective procedures for stakeholder participation, arguing that an open, secure, stable, and accessible ICT environment cannot be built behind closed doors .
ICANN, the Internet Corporation for Assigned Names and Numbers, described its role in coordinating Internet unique identifiers and combating misuse of domain names through contractual obligations, consensus policies, technical coordination, and collaboration with organisations operating the DNS . It clarified that ICANN does not regulate Internet content or investigate cybercrime. It emphasised that no single stakeholder can address these challenges alone, with registries, registrars, governments, law enforcement, technical experts, civil society, and the private sector each bringing different responsibilities and capabilities . ICANN highlighted the Coalition for Digital Africa as an example of multi-stakeholder capacity building, bringing together African governments, regional organisations, academia, the private sector, and the technical community to strengthen DNS security and resilience . It encouraged all member states to actively participate in the Government Advisory Committee (GAC), which advises the ICANN board on public policy issues related to its mission, including matters affecting the security, stability, and resilience of Internet unique identifier systems . ICANN also invited delegates to a joint briefing with the Internet Society and the ITU entitled “Demystifying the Internet: Collaborative Security Approaches”, to be held the following day .
FutureEarth Systems, represented by Chris Sampson – who noted the benefit of having discussed and analysed the Open-Ended Working Group (OEWG) process as part of the ongoing Geneva Dialogue, with thanks to the Government of Switzerland – introduced the concept of enterprise architecture as a tool of potential value to the global mechanism . Enterprise architecture maps how policy intent, legal and regulatory frameworks, capabilities and processes, data, and technical systems all align – analogous, Sampson suggested, to a city plan that ensures roads, utilities, and buildings work together efficiently and can adapt as the city grows . He argued that this approach can bridge from policy and guidance to implemented operational systems, ensuring optimal alignment of resources and a clearer focus on measurable strategic outcomes . Crucially, he emphasised that such an approach would not alter negotiated outcomes but could strengthen the mechanism, improve capacity building, and support implementation for all communities . Industry, he noted, is already innovating at this level, including in cybercrime, and cyber defence needs to be a globally interconnected ecosystem with more effective collaborative systems and shared data between state and regional institutions .
The Forum of Incident Response and Security Teams (FIRST), established over thirty-five years ago and currently comprising 874 incident response and security teams across 118 countries, reiterated its appreciation for the Chair’s efforts to engage all stakeholders in an open, transparent, and inclusive manner . FIRST supported the joint multi-stakeholder statement on objections to stakeholder participation, in line with the agreed modalities contained in the 2025 OEWG Final Report . It emphasised that stakeholders from industry, academia, and professional and technical organisations play indispensable roles in supporting the implementation of cyber norms and confidence-building measures (CBMs), providing timely operational responses to emerging threats, facilitating responsible vulnerability disclosure, and strengthening cybersecurity capacity building at national, regional, and global levels . FIRST called upon states to support international collaboration among incident responders and to ensure that such cooperation remains non-politicised, consistent with the relevant UNGGE 2021 report .
The Centre for Humanitarian Dialogue, a private diplomacy organisation acting on principles of humanity, impartiality, neutrality, and independence, raised a largely unexplored issue: the challenge of designing confidence-building measures for the cyber and information domain after armed conflict . It observed that the end of a war is not the beginning of peace but a volatile in-between situation where forces still oppose each other, trust does not exist, and small incidents can carry big consequences . While military and diplomatic experts have developed mechanisms to stabilise truces in physical domains – land, sea, and air – no ceasefire, armistice, or peace agreement in history has ever had to pay heed to the cyber and information domain – a gap the Centre argued must now be addressed . The Centre highlighted the unique challenges posed by cyberspace: it is not possible to watch computer code, nor can algorithms be conveniently corralled or disabled; malware can be developed anywhere, transported on a chip, and deployed from any point on earth, making it effectively indestructible . It encouraged the global mechanism to consider and develop ideas for confidence building in the cyber and information domain after armed conflict, and offered the Centre’s expertise in mediating for peace as a resource .
Developing Capacity LTD, represented by Robert Collett, described its work during the OEWG in providing unofficial transcripts, contributing to politically neutral side events, and producing reports in response to the Chair’s guiding questions, including a series of tabletop exercises culminating in a Chatham House report on how agreed principles might be applied in practice . Looking ahead, Collett recommended three priority areas for structuring the work of the Dedicated Thematic Groups (DTGs): first, aiming for quick wins by coordinating, matchmaking, and mobilising funding for capacity-building activities that directly support the mechanism and the implementation of the agreed framework; second, addressing the deeper strategic challenge of increasing resources available for cyber capacity building both internationally and domestically; and third, improving the quality, efficiency, and demand-driven nature of cyber capacity building by promoting and operationalising the principles already agreed by the OEWG . Developing Capacity LTD also highlighted the Sybil Portal, a repository with 74 documents on relevant thematic areas and information on 100 past cyber capacity-building projects, noting that the portal has previously received support from the Dutch government and is currently undergoing a period of renewal .
IMQ Intuity SPA, an Italian company specialising in cyber resilience through realistic attack simulations, shared insights from hundreds of simulations conducted as part of Italy’s national cyber capacity-building programme . The company observed that cyber risks rarely emerge from a single vulnerability but more often from the interaction between technology, people, processes, suppliers, physical infrastructure, and the decisions that connect them . The growing challenge, it argued, is not the number of vulnerabilities but the growing number of interdependencies . IMQ Intuity described its approach of “turning the map around” – rather than asking how to defend, asking where an attacker would begin – as a method for revealing dependencies, challenging assumptions, and understanding what truly matters before a crisis occurs . It concluded that responsible state behaviour requires responsible preparation, meaning not merely deploying technologies but understanding complexity, recognising interdependencies, and preparing leaders and institutions to make sound decisions under uncertainty .
The Moscow State Institute of International Relations (MGIMO University) described its IDENTITY project – ICT Digital Related Education for Non-Technical and International Affairs Talented Youth – which was recognised at the World Summit on Information Society in Geneva as a champion in the e-learning category . The project offers free, short-term, open-enrolment, distance education courses called “Digital Weeks”, focusing on the international agenda in ICT and information security, national IT strategies, and AI and data governance skills . MGIMO also called for recognition of the importance of neutrality of large language models (LLMs) with regard to international affairs, the everyday work of diplomats, and media coverage of world events, noting that it has identified profound inconsistencies, irregularities, and sentiment shifts in LLM responses on international affairs issues, as well as a lack of language and cultural diversity in LLM outputs . It announced the development of reproducible benchmark tests to identify these anomalies, proposing this work as a basis for standardisation of LLM evaluation .
The Internet Society, a global non-profit organisation founded by Internet researchers since 1992, welcomed the launch of the first substantive plenary session and emphasised that the mechanism’s success will be determined by whether it can turn agreed norms into practical, real-world impact for the billions of people who rely on the Internet every day . It described its work on routing security through the Mutually Agreed Norms for Routing Security (MANRS) initiative, community networks, Internet exchange points, and its Global Common Goods Cyber Initiative, which connects resources to fund non-profits supporting critical cybersecurity infrastructure and protecting vulnerable groups from digital harm . The Internet Society also noted that it is co-organising, with the Permanent Missions of Kenya and Bulgaria alongside ICANN and the ITU, the joint briefing entitled “Demystifying the Internet: Collaborative Security Approaches” to be held the following day. It argued that the Internet is not solely run by governments but by a distributed ecosystem of network operators, standards bodies, and technical experts, and that decisions on cyber norms, international law, and confidence building should prioritise input from those who build and secure its infrastructure . It called on member states to ensure stakeholder accreditation and participation modalities are implemented in a predictable, transparent, and non-arbitrary manner .
The Kenya ICT Action Network (KICTANET), presenting outcomes from consultations with a broader multi-stakeholder community, called for the structural integration of multi-stakeholder approaches into informal consultations, technical drafting, and policy implementation . It emphasised that digital security is fundamentally about human safety, and that resources need to move beyond high-level legal meetings towards strengthening local incident response teams, defending civic space, and protecting vulnerable communities from technology-facilitated abuse . KICTANET proposed that the DTGs be prioritised as actionable vehicles for problem-solving, with civil society and governments co-designing workable responses to critical infrastructure vulnerabilities and AI-amplified harms . It also called for the establishment of formal channels to ingest grassroots data, particularly from developing nations, to ensure that international norms respond to real-world harms , and requested the possibility of virtual quarterly or half-yearly meetings to make engagement more continuous and meaningful .
The Association for Progressive Communications (APC), an international not-for-profit membership organisation with 74 organisational members and associates across 60 countries, called for state-led capacity-building programmes to address the disproportionate impact of cyber threats on vulnerable communities including women, LGBTQI+ people, and human rights defenders . APC documented how digital surveillance is used to intimidate, silence, and restrict women’s participation in civic and political life, and called for further work on the gendered impact of cyber mercenary hack-for-hire spyware actors . It described the mechanism’s exclusion of many stakeholders as “an injury inflicted on itself”, arguing that civil society and academic research have often been the source of empirical evidence on harms such as ransomware . APC also urged the mechanism to ensure that cybersecurity laws and policies aid rather than overreach or oppress, and called for gender-sensitive cybersecurity laws that holistically address digital violence . It urged attention to how the race for AI deployment in the public sector is impacting security vulnerabilities and affecting vulnerable communities .
Chatham House (the Royal Institute of International Affairs) welcomed the global mechanism as providing a standing space to continue building shared understanding and to support implementation over time . It emphasised that the existence of resources is not the same as the capacity to use them, and that guidance cannot implement itself – many states face technical, institutional, or financial constraints that make implementation difficult even when practical guidance is readily available . Chatham House argued that the multi-stakeholder community is not a bystander but a partner in implementation, with industry, technical organisations, academia, and civil society already helping to translate the framework into operational guidance, often in direct partnership with states . It also noted that the environment the framework is intended to govern continues to evolve, with more states adopting offensive cyber postures, the growing use of proxy actors, the emergence of frontier AI models, and the wider availability of sophisticated cyber intrusion tools all changing the operational landscape . Chatham House concluded with the observation that “resonance matters as much as resourcing” – norms will only shape behaviour if they are understood beyond the negotiating room as practical expectations, and making the framework tangible is itself a form of implementation .
InternetLab, a Brazilian think tank dedicated to producing knowledge at the intersection of digital technologies and human rights, expressed disappointment at the number of organisations blocked from participating in formal sessions . It encouraged discussions closely connected to the needs identified by member states and focused on practical implementation, with DTG1 examining how emerging developments affect the implementation of the existing UN framework rather than creating parallel normative processes . InternetLab underscored that the framework operates within international law, including international human rights law and, where applicable, international humanitarian law (IHL) . It cited its own research on online gender-based political violence against women politicians in Brazil, documenting how coordinated attacks disproportionately target women and members of historically marginalised communities, with clear implications for democratic participation and the design of effective, rights-respecting cybersecurity responses . For DTG2, it encouraged discussions on sustainable, demand-driven, and inclusive cyber capacity building, with priorities including better coordination among existing initiatives, support for states with limited resources, and cooperation on secure open-source cybersecurity tools .
Access Now, a grassroots-to-global organisation defending the digital rights of individuals and communities most at risk, aligned itself with the statement made by KICTANET on existing threats surrounding the unchecked proliferation of commercial spyware, surveillance, and state-sponsored cyber harassment . It noted that out of 313 Internet shutdowns documented in 2025, 125 occurred in situations of conflict, impeding access to essential services and communication . Access Now identified three priority areas for the DTGs: making the human cost of critical infrastructure attacks visible and foregrounding the role of civil society in its defence, including protecting tools like strong encryption and independent research capabilities ; addressing the specific security vulnerabilities introduced by AI tools, with a human rights-respecting approach at the centre ; and building on the substantial body of state practice affirming that international human rights law and IHL apply to state cyber behaviour, turning consensus into shared understanding and implementation .
—
#
Interactive Dialogue: State Responses to Stakeholder Contributions
Following the stakeholder segment, the Chair opened the floor for an interactive dialogue with member states . Canada welcomed the interventions by accredited stakeholders but noted that they were “too few”, observing that a number of interventions demonstrated the readiness of the multi-stakeholder community to contribute on practical matters in the DTGs . Canada specifically named stakeholders from Mexico, Brazil, Peru, Panama, Ghana, Nigeria, and South Africa as having been vetoed, and expressed hope for more meaningful and inclusive opportunities for all stakeholders to engage in December .
Japan affirmed that as cyber threats become increasingly sophisticated and complex, it is critical to draw on the private sector’s expertise for recognising threats and implementing countermeasures, and expressed strong hope to further strengthen public-private collaboration within the UN framework through expert briefings and interactive discussions, especially in the DTGs . Mexico welcomed the practice of displaying organisations’ names on screens as reflecting the importance of meaningful participation, and urged stakeholders to draft specific inputs for DTG discussions, including guides, guidelines, methodologies, models, or good practices to support states in implementing the framework on responsible behaviour, particularly examples that could benefit a developing country like Mexico .
The European Union, speaking on behalf of a broad group of aligned states, thanked stakeholders for participating in what it acknowledged had been a challenging environment, and expressed strong interest in their contributions not only through statements but also on specific challenges to be discussed in the DTGs . The EU encouraged stakeholders to continue contributing by enhancing cooperation with states, building capacities, and strengthening cyber resilience through research, training, and dedicated activities . Chile thanked stakeholders for their participation, affirmed that their voices are essential to reflect the reality on the ground, and explicitly rejected the amount of objections voiced against their participation, including from institutions in Chile’s own region . Germany echoed these concerns and highlighted that the organisation Interface, which had produced a study and survey comparing the global state of CBM implementation, was not allowed to attend – work that Germany considered directly relevant to the mechanism’s discussions .
In response to Mexico’s question about practical implementation tools, several stakeholders provided concrete answers. Chatham House referenced its report on the operationalisation of cyber capacity-building principles, the Geneva Dialogues manual offering concrete guidance on implementing specific norms such as supply chain security and responsible vulnerability disclosure, the Paris Call for Trust and Security in Cyberspace, and sector-specific guidance from organisations such as the Cyber Peace Institute on protecting the healthcare sector . It noted that the multi-stakeholder community is discussing mapping these resources and making them available to states . Developing Capacity LTD highlighted the Sybil Portal as a repository standing ready to serve as a state and stakeholder platform . FIRST noted its 31 member teams in Mexico and an upcoming Mexico City Technical Colloquium, offering to support Mexico and other interested states through its global membership network . FutureEarth Systems offered to meet with Mexican representatives to explore how enterprise architecture can assist states with implementation of the norms . The Internet Society described its policymaker programme, which helps diplomats understand how the Internet works, how it evolves, and the standards that underpin it, enabling better-informed cyber policy .
—
#
International Law: Convergences and Fault Lines
The session then returned to the agenda item on international law, with Switzerland, the United States, Australia, Nicaragua, Algeria, the African Union, and the ICRC taking the floor . Switzerland, aligning with a joint cross-regional statement on international law and IHL, welcomed the growing number of states – more than forty – that have issued positions on international law in cyberspace, and noted that more than thirty-six national and two regional positions have been published . It argued that the new mechanism offers the opportunity to turn statements and written positions into lively and substantive discussions based on real-world scenarios in the DTGs, describing this as an innovative step forward . Switzerland specifically supported concrete discussions on the protection of critical infrastructure such as hospitals, water systems, and energy networks from malicious ICT operations, both in times of peace and in armed conflict . It highlighted the ICT work stream under the Global Initiative to Galvanise Political Commitment to IHL, co-chaired with Ghana, Luxembourg, and Mexico, as an invaluable complementary platform for substantive discussions on IHL and ICTs, noting that discussions have moved beyond whether IHL applies to the more practical question of how it applies . Switzerland also described a meeting of a cross-regional group on Mount Rigi in April 2026, where representatives from fifteen states discussed the concrete application of international law and IHL in cyberspace through real-world scenarios .
The United States reiterated its view that existing international law applies to activities in cyberspace and remains fit for purpose, stating firmly that it will not support language suggesting new binding obligations are required or that existing legal obligations are somehow insufficient . It warned that any proposal to use DTG1 to relitigate international law as a “stalking horse for treaty making” duplicates work already done and keeps discussions stagnant, and stated that it would not agree to a discussion topic that would be “hijacked” for that purpose . The United States argued that the mechanism should focus on implementing the eleven norms states have already committed to, rather than relitigating settled ground to “manufacture the appearance of a gap that does not already exist” .
Australia, aligning with the Pacific Islands Forum statement and the cross-regional statement on international law, affirmed that all states have agreed existing international law applies to state conduct in cyberspace and that it is indispensable in advancing responsible state behaviour . It noted that the OEWG saw states solidify and add granularity to several specific areas of convergence, including on the application of the principle of sovereignty, non-intervention, the prohibition on the use of force, and the peaceful settlement of disputes . However, Australia expressed regret that the OEWG final report did not reflect other areas in which states had worked hard to identify common ground, including on the ways in which international human rights law, the law of state responsibility, and IHL apply . It called for the DTGs to bring together legal, technical, and diplomatic expertise to elaborate in substantive ways exactly how these areas of law apply, using concrete cyber incident scenarios to build confidence and shared understanding . Australia also emphasised that capacity building remains essential to ensuring that discussions reflect the full breadth of experience in the room, and committed to supporting efforts to help all states develop and share their national positions .
Nicaragua called for the debate on the application of international law to continue in a careful, inclusive, and intergovernmental manner, emphasising the need to build common understanding while avoiding interpretations that could favour the militarisation of cyberspace . It cited the UN Convention against Cybercrime as evidence that the international community can make headway through dialogue and consensus towards multilateral instruments, and called for keeping open the debate on the progressive development of the international legal framework, including the possibility of drafting legally binding instruments . Nicaragua also stressed that this process must be coupled with effective international cooperation, capacity building, and technology transfer to enable everyone to participate in equal conditions .
Algeria aligned with the African Group statement and endorsed the African Union’s common position on the application of international law in cyberspace, reaffirming that international law, including sovereignty, non-interference, the prohibition of the threat or use of force, IHL, and international human rights law, fully applies in cyberspace . It emphasised that developing countries face unique challenges in meeting their obligations due to resource constraints and technical gaps, and called for enhanced international cooperation and concrete capacity-building measures grounded in state sovereignty and national ownership . Algeria explicitly supported the elaboration of a legally binding international instrument, arguing that the unique attributes of cyberspace – including the speed and sophistication of attacks, the difficulty of attribution, the vulnerability of critical infrastructure, and the evolving nature of cyber threats – demand legal clarity and certainty rather than interpretative ambiguity . It argued that since the international community has successfully agreed on eleven non-binding norms, it should certainly be able to elaborate legally binding rules .
The African Union, aligning with what the transcript records as “the Afghan group” statement (likely a transcription error for “African Group”), described its Common African Position on the Application of International Law to the Use of ICTs in Cyberspace as an important milestone in strengthening Africa’s collective voice on international cyber policy . It noted that some AU member states are already developing their own national positions, and described a workshop convened by the AU Commission from 1 to 3 June 2026 in Addis Ababa to strengthen the capacity of AU member states to develop national positions on the application of international law to cyberspace . The AU emphasised that capacity building is not only about strengthening technical capacity but also includes building legal, diplomatic, and institutional expertise to enable all member states to participate effectively and on an equal footing .
The ICRC emphasised three key points on international law . First, when ICT capabilities are used for military purposes in situations of armed conflict, their use must comply with existing IHL rules, citing the October 2024 resolution of the 34th International Conference of the Red Cross and Red Crescent, which affirmed that IHL rules and principles serve to protect civilian populations against risks arising from ICT activities . Second, the ICRC called on states to focus especially on the limits that IHL imposes on ICT activities that result in non-physical damage, arguing that in today’s ICT-reliant societies it is critical to protect the ICT systems that underpin civilian life and digital data against damage and destruction . Third, the ICRC called on states to focus parts of the DTGs on how international law addresses new developments and technologies, including identifying legal and practical measures to implement rules prohibiting child recruitment, agreeing on practical measures to prevent civilian hackers from committing IHL violations, and building shared understanding on the risks that arise when civilian ICT infrastructure is used for military purposes . The ICRC also called on member states to consider whether existing international law provides sufficient safeguards against harm from increasingly autonomous ICT capabilities, or whether additional limits are needed .
The Chair provided a brief summary of the international law discussion, noting that the majority of delegations underscored that the global mechanism must continue to encourage discussions on the applicability of international law to ICTs, and that the development of a common understanding is fundamental to establishing a safe, stable, and predictable digital environment . She noted that some delegations had called for continued exploration of fundamental legal concepts including sovereignty, non-interference, the peaceful settlement of disputes, state responsibility, IHL, and international human rights law, and encouraged continued efforts to support capacity building and promote dialogue between legal and technical communities .
—
#
Confidence-Building Measures: From Endorsement to Operationalisation
The session’s final substantive segment addressed the development and implementation of confidence-building measures. The Dominican Republic, speaking on behalf of the open, informal, cross-regional group of Global Mechanism Confidence Builders – comprising sixteen states including Argentina, Australia, Brazil, Canada, Chile, Colombia, Czech Republic, Fiji, Germany, Israel, the Republic of Korea, Mexico, the Kingdom of the Netherlands, Singapore, Uruguay, and the Dominican Republic – reaffirmed commitment to the eight voluntary global CBMs adopted by the previous OEWG . The group recognised that the global mechanism’s plenary sessions and DTG meetings provide complementary but distinct ways for states to identify areas of convergence and needs for further discussion in CBM implementation . It announced that it is preparing a working paper ahead of the December session highlighting the practical value of CBMs, drawing on implementation experience at the regional and sub-regional levels, and presenting best practices and a comparative perspective of how CBMs are operationalised in practice .
Tonga, speaking on behalf of the Pacific Islands Forum members, emphasised that CBMs are particularly important for regions and states with limited capacity, helping to build trust, reduce the risk of misperception and escalation, and create channels that can be used before, during, and after cyber incidents . It highlighted the Pacific Cybersecurity Operational Network (PACSON) as especially valuable, including through third-to-third cooperation, national and regional exercises, practical incident communication procedures, and opportunities for officials and technical experts to build relationships before a crisis occurs . Tonga stressed that the focus at this stage is the implementation of existing CBMs, requiring capacity building, technical assistance, guidance, exercises, and sustained engagement, and called for the global mechanism to help states use the CBMs rather than simply continue to describe them . It called for the Global POC Directory to be actively maintained and used proportionately, purposefully, and with due regard for the capacity constraints of smaller states .
The European Union, speaking on behalf of a broad group of aligned states, described confidence building as a long-term progressive commitment requiring sustained and genuine engagement . It called for the mechanism’s work on CBMs to focus as a priority on the operationalisation of the voluntary non-exhaustive list of CBMs agreed under the OEWG, encouraging participation by states and complementing the work of regional organisations including the OSCE, OAS, ARF, and ECOWAS . The EU supported integrating the POC directory into the global mechanism’s portal as an initial step, while remaining open to exploring further development based on lessons learned . It also supported organising regular seminars, workshops, and training programmes on ICT security, promoting information exchange on cooperation and partnerships between states, and sharing national ICT strategies, policies, and legislation on a voluntary basis .
The Republic of Korea described the establishment of the UN Global Mechanism Point of Contact Directory as one of the most significant achievements of the OEWG, with the potential to strengthen confidence among states by facilitating timely and effective communication during cyber incidents and crises . It expressed strong support for the joint statement delivered by the Dominican Republic and emphasised that the POC directory must be used responsibly and in good faith, consistent with its purpose of facilitating cooperation, and should not be misused or exploited for purposes inconsistent with its original intent . Costa Rica supported the Global POC Directory as a valuable operational tool for facilitating urgent communication, managing cross-border incidents, reducing misunderstandings, and preventing escalation, and emphasised that legal transparency through publishing national positions on international law also serves as a confidence-building measure .
Albania, drawing on its experience as a country that continues to face persistent malicious cyber activities against its critical infrastructure, described its approach to CBMs as resting on cooperation across several layers – political, diplomatic, and technical – through the UN, EU, OSCE, ITU, Western Balkans frameworks, and bilateral relations, with each layer reinforcing the others . It described its participation in the Global POC Directory, its support for the Women in Cyber Fellowship as a confidence-building measure in itself, and its progressive alignment with EU cybersecurity frameworks including the transposition of the NIS2 directive into national law . Albania also described regional initiatives including the Adriatic Five meetings, the Western Balkan Policy Roundtable, the Western Balkan Cyber Dialogue, and Western Balkan Cyber Camps, arguing that these projects build the professional and institutional relationships on which CBMs ultimately depend . It concluded with the observation that cooperation builds capacity, capacity builds trust, and trust builds still more cooperation – which is, in Albania’s view, exactly how confidence building is meant to work .
Italy, aligning with the EU statement, emphasised the particular importance of regional CBMs, especially those developed by the OSCE, and highlighted the value of multinational cyber exercises, cyber ranges, crisis management simulations, and structured information-sharing mechanisms involving governments, critical infrastructure operators, industry, academia, and research organisations . It described its own implementation of CBMs including nominating POCs for the global directory, sharing concept papers and national strategies, promoting capacity-building projects, and organising workshops with a whole-society approach . Italy argued that the DTGs can play a crucial role in this area, with DTG1 discussing how to apply CBMs in specific situations or scenarios and DTG2 crafting tailored capacity-building projects .
Kiribati, aligning with the Pacific Islands Forum statement, offered one of the session’s most striking formulations: for small island developing states, predictable, trusted mechanisms for communication between states are not a convenience but “the difference between facing an incident alone and facing it with help” . It attached great importance to the Global POC Directory and encouraged continued practical support for its use so that the directory works as intended in a real incident and not only on paper . Kiribati also observed that the Pacific experience is that confidence is built through practice, not declarations, citing PACSON (also referred to as PAXEN in some statements) as a model of incident-responsive shared threat information and personal trust built through routine contact . It drew two lessons from this experience: that CBMs succeed when they are simple, sustained, and relationship-based, with ambition measured in reliability rather than the number of measures adopted; and that regional organisations are not merely implementers of globally agreed CBMs but laboratories for them, and the mechanism should draw systematically on regional experience .
The United Kingdom supported the identification of concrete, action-oriented ways to implement the UN framework, including through CBMs, and described the Global POC Directory as a positive practical example emerging from the OEWG . It clarified that the directory’s purpose is to facilitate secure and direct communications between states to prevent and address serious ICT incidents, and that it complements a range of formal and informal networks . Importantly, the United Kingdom noted that the existence of the POC directory does not alter a state’s right to attribute irresponsible cyber behaviour to another state, and that states may decide that using the directory is not appropriate if it is clear that malicious cyber activity is part of a deliberate state-sponsored campaign .
Papua New Guinea, aligning with the Pacific Islands Forum statement, paid special tribute to the delegation of Singapore for its leadership in setting the stage through the OEWG process, and noted that ICT is one of the twelve core national development strategic priorities under its current medium-term development plan . It described a Pacific Regional Digital Transformation Summit and Pacific Cyber Week taking place in Papua New Guinea that same week, and emphasised that digital transformation can only succeed when people, governments, businesses, and other stakeholders have confidence and trust that the digital environment is safe, secure, and reliable . Papua New Guinea called for the global mechanism to help countries strengthen core capabilities including cyber hygiene, national incident response, legal and regulatory frameworks, and the skills required by officials, technical experts, regulators, and law enforcement agencies . It stressed that capacity building must be demand-driven, nationally owned, and responsive to each country’s level of digital maturity, and acknowledged the support of development partners including UNIDIR and Australia for gender-sensitive capacity-building support .
Canada described its recent publication of responses to the UNIDIR survey on the implementation of norms, international law, CBMs, and capacity building as a concrete practice of CBM-3 on information sharing . It expressed support for holding a second simulation exercise on the Global POC Directory in the autumn to reduce the risk of misunderstanding or escalation during significant or urgent incidents . Canada also described its organisation of tabletop exercises with FIFA World Cup host cities and critical infrastructure operators, as well as collaboration with Mexico, Execon [as transcribed], and US CERTs on relevant information sharing as an example of CBM operationalisation through simulation exercises . It concluded with the observation that confidence-building measures are like sportsmanship in football – they foster healthy communication between players acting in good faith, whether from cyber agencies, ministries of foreign affairs, or non-governmental stakeholders .
Serbia, aligning with the EU statement, described CBMs as practical, voluntary, non-politicised tools that enhance transparency and predictability and reduce the risk that an ICT incident is misperceived and escalates . It welcomed the operationalisation of the Global POC Directory and described its designation of both diplomatic and technical points of contact, as well as its sponsorship of OSCE CBM-9 on national terminologies and definitions in the field of information security . South Africa recognised a significant step in the development of cybersecurity and called for member states to support the full operationalisation of the eight global CBMs through international cooperation at UN, regional, and sub-regional levels . It supported the continuation of the UNIDIR Women in International Security and Cyberspace Fellowship and the proposed voluntary fund to support participation of developing countries in the global mechanism .
Singapore emphasised that CBMs are a team effort requiring states to share best practices, potential pitfalls, and ways around them, and that different regions have different ways of implementing CBMs . It supported UNODA’s ongoing efforts to operationalise the POC directory through capacity-building initiatives, simulation exercises, and engagement with regional mechanisms to promote interoperability and the sharing of best practices, while noting that it would be important to allow for the POC directory to be used in a flexible way so that states may use it as needed before more standard templates and procedures for its use are developed . Nauru, speaking in alignment with the Pacific Islands Forum statement, described the context of small administrations where the people responsible for cybersecurity, diplomacy, and digital policy are often one and the same within the public service, and emphasised that CBMs must be inclusive by design to accommodate small bureaucracies as well as large ones . Nauru announced that it will assume the chairmanship of PACSON and intends to strengthen the connection between the Pacific’s operational cooperation and the global mechanism’s CBMs, inviting other regions and the mechanism itself to engage in that spirit during its chairmanship .
Switzerland, in its second intervention of the session, emphasised that the challenge is not to develop new CBMs but to implement those already agreed effectively, and called for efforts to focus on translating existing commitments into practice, sharing experiences, and identifying implementation gaps and good practices . It highlighted the role of regional and sub-regional organisations in promoting dialogue, facilitating capacity building, and adapting CBMs to regional contexts while remaining anchored in the global UN framework . Switzerland referenced a non-paper submitted to the OEWG in June 2025 on the role of regional organisations in implementing the UN Framework, recommending the establishment of a structured exchange between the global mechanism and regional and sub-regional organisations . It also emphasised the value of voluntary transparency measures including designating national points of contact, exchanging information on national implementation, and cooperation through exercises and information sharing .
—
#
Conclusion
The Chair closed the session by thanking all delegations for their very substantial contributions across all agenda items, noting that the stakeholder community is without doubt a fundamental part of the mechanism’s work . She confirmed that eighteen delegations remained on the speakers’ list for the confidence-building measures agenda item and that discussions would continue the following morning, before formally closing the session .
The session as a whole demonstrated both the depth of engagement that the mechanism’s first substantive plenary had generated and the significant unresolved tensions that will shape the mechanism’s work in the months ahead. Three fault lines were particularly evident: first, the contested question of stakeholder accreditation, with numerous delegations and civil society organisations calling for transparent, criteria-based procedures and expressing concern at the blocking of over sixty entities without stated justification; second, the divergence between states favouring the elaboration of legally binding instruments and those insisting that existing international law is sufficient and that the mechanism should focus on implementation rather than new normative development; and third, the challenge of operationalising CBMs equitably across states with vastly different technical, institutional, and financial capacities – a concern articulated with particular force by small island developing states, for whom reliable communication mechanisms are not a diplomatic convenience but a practical necessity.
—
Chair Egriselda López
Thank you so much for your patience. And I guess that we solved these technical issues, so we’re ready to begin. And now you can put your headsets. Muy buenas tardes. A very good afternoon. I call to order the sixth meeting of the plenary session 2026 of the global mechanism on ICTs in the context of international security and advancing responsible state behavior in the use of ICTs. The meeting is called to order. According to our program of work and also the consensus -based modalities on the participation of state, non -governmental stakeholders in the works of our mechanism. we will now have our meeting on accredited entities for our work right now I have 14 accredited organisations who have requested the floor I will give the floor to each speaker for 4 minutes before I give the floor to the first speaker who is Discover MUN Foundation I’d like to express my thanks to all of you for participating in this first plenary session of the mechanism, thank you I know that many of you are not based in New York so thank you for the interest that you’ve shown thank you for your time and coming and contributing to the work of this mechanism The Chair is very grateful to all of you I now give the floor to Discover MUN Foundation
—
Discover MUN Foundation
Madam Chair, I have the honour to take the floor on behalf of the Major Group for Children and Youth the mandated Children and Youth Constituency at the UN representing over 20 ,000 distinct youth organisations Excellencies, cyber security risks and automated exploits are escalating at an unprecedented speed today Dual -use technologies, from AI -driven malware to deepfake social engineering are being weaponised to target digital spaces When everyday ICT tools are repurposed for malicious cyber activities it is young people, particularly children who face immediate attacks to their digital safety and rights In this context, please allow me to deliver a few words of advice I would like to deliver the following demands on behalf of children and youth First, we believe the Member States must consider age -related disaggregated data on malicious ICT activity in their submissions under this pillar. We call upon delegations to consider General Comment No. 25 of the Committee on Rights of the Child, which establishes that rights of children apply fully and equally in the digital environment. Second, for capacity building, we call for the establishment of a dedicated children and youth track within the mechanisms sponsorship and capacity building activities. We believe that such activities must be modeled on successful examples of capacity building for marginalized stakeholders in the UN system, such as the Women in International Security and Cyberspace Fellowship organized by the UN Institute for Disarmament Research, which effectively integrates young technical experts in national delegations. Third, consistent with the Youth Peace and Security Agenda under Security Council Resolution 2250, we call for meaningful engagement with children and youth to be recognised by the mechanism as a confidence -building measure in its own right. Madam Chair, please allow me now to turn to the critical issue of stakeholder participation. My delegation thanks you for your letter dated 1st June and for your tireless efforts to uphold the transparency required by the modalities document in A -80 -257. We note that these modalities were agreed by consensus on the understanding that inclusivity would be the norm and objection be the exception. But objections that are lodged against more than 60 stakeholder entities, including non -governmental organisations, universities and technical bodies, without any stated basis whatsoever, cannot be. They cannot be considered as inclusivity. We call upon Member States to honour the multi -stakeholder principles that they affirmed in both the Global Digital Compact and the World Summit for Information Society Plus 20 review by disclosing the basis of their objections In this context, we thank the distinguished delegations of the European Union and its Member States for acting as a leading example of what transparency means pertaining to stakeholder participation Excellencies, we fully support the Chair’s efforts for mediation but further demand that this mechanism work towards transparent, criteria -based accreditation practices to ensure predictable, principled and objective procedures concerning stakeholder and rightholder participation Excellencies, an open, secure, stable, accessible ICT environment cannot and will never be built behind closed doors Just like many of our other distinguished colleagues present here today, children and youth remain ready to bring constructive contributions Thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to the Internet Cooperation for Assigned Numbers, followed by Future Us Systems. Thank you, Chair, for the opportunity to contribute to this discussion. Internet Cooperation for Assigned Names and Numbers, or otherwise ICANN, coordinates the Internet Unique Identifiers.
—
ICANN
Thank you. and requires coordinated action across the Internet ecosystem. ICANN does not regulate Internet content or investigate cybercrime. Instead, it plays its part with regard to the wider online harm mitigation efforts by combating misuse of domain names through contractual obligations, consensus policies, technical coordination, capacity development, and collaboration with organizations that operate the DNS. No single stakeholder can address these challenges alone. Registries, registrars, governments, law enforcement, technical experts, civil society, the private sector, and others across the Internet community, each brings different responsibilities, expertise, and capabilities. ICANN works to increase the visibility of capacity -building efforts among UN member states One example is the Coalition for Digital Africa which brings together African governments, regional organizations, academia the private sector and the technical community to strengthen DNS security and resilience build local technical expertise and expand opportunities for participation in the Internet governance ICANN multi -stakeholder model provides the mechanism for this cooperation It’s supporting organizations and advisory committees bring technical expertise, operational experience, business perspective, public interest and end -user needs into policy development Governments have a unique and essential role within this model through the Government Advisory Committee or the GAC The GAC advises The GAC advises the government advisory committee The GAC advises the ICANN board on public policy issues related to ICANN’s mission including matters affecting the security, stability, and resilience of Internet’s unique identifier systems that includes domain name system. Through the Government Advisory Committee, governments bring a public policy perspective directly into ICANN’s work as an integral part of the multi -stakeholder model. I would like to use this opportunity to encourage all Member States to actively participate in the work of the Government Advisory Committee, ensuring DNS flawless functioning. And if you do not have a representative, please reach out to us. We have a staff here in New York, and we would be happy to provide all the information you might need. Last but not least, I would like to invite you to the briefing entitled Demystifying the Internet Collaborative Security Approaches that ICANN, the Internet Society, and the ITU are giving tomorrow in Conference Room 8 during the lunch break. Madam Chair, Excellencies, dear colleagues we are looking forward to observing the global mechanism plenary sessions and we are at your disposal
—
Chair Egriselda López
Thank you very much. I now give the floor to FutureEarth Systems followed by Forum of Incident Response and Security Teams first
—
FutureEarth Systems
Thank you Madam Chair for your leadership and the opportunity to address this plenary. My name is Chris Sampson from FutureEarth Systems I have the privilege of participating as an independent accredited stakeholder. I have spent many decades designing whole of government systems, ICT policy and strategy public and private sector innovation and socio -economic development with a special interest in regional, rural and remote community socio -economic equity in the digital age I have also had the benefit of discussing and analysing the GGE and Open Ended Working Group as part of the ongoing Geneva Dialogue, with many thanks to the Government of Switzerland. I want to highlight the potential value of the practice of enterprise architecture to the work of this general mechanism. Enterprise architecture maps out how policy intent, legal and regulatory frameworks, capabilities and processes, data and technical systems all align. Think of it like a city plan. It ensures that roads, utilities and buildings work together efficiently and can adapt as the city grows. Using architecture practice in this way can bridge from policy and guidance to implemented operational systems, ensuring optimal alignment of resources and a clearer focus on achieving measurable strategic outcomes. This approach can help us harness the positive opportunities of ICTs, including AI and quantum. It forms the blueprints for real -time sensory systems which can adapt themselves much more dynamically to changing conditions and challenges. These are the new generation of systems that will enable human society to operate at the next level of complexity with peace and security for all. Madam Chair, industry is already innovating at this level. We can see it in both regulated and unregulated global trade, including cybercrime. Cyber defence needs to be a globally interconnected ecosystem itself, with much more effective collaborative systems and shared data between our state institutions and our regional and global institutions, so we can strengthen the system. We can strengthen the capabilities. collectively and continuously enabling every community to operate in peace and security. An architectural approach will help us build on the norms as systems and realise the value of the multi -stakeholder participation that you have all worked so hard to bring together. Importantly, such an approach would not alter negotiated outcomes. Rather, it could strengthen the mechanism, improve capacity building and support implementation for all communities, ensuring human use of ICTs are stewarded responsibly, enabling human flourishing for generations to come. I commend the work of all involved and would be honoured to contribute. Thank you very much, Madam Chair.
—
Chair Egriselda López
Thank you very much. I give the floor now to First. First followed by Centre for Humanitarian Dialogue.
—
Forum of Incident Response and Security Teams
Honourable Chair, Distinguished Delegates and Stakeholders, thank you for inviting FIRST to contribute to the first plenary meetings of the UN Global Mechanism. We reiterate our appreciation for the Chair’s sincere and sustained effort to engage all stakeholders in an open, transparent and inclusive manner. In this regard, FIRST supports the joint multi -stakeholder statement on the objection to the participation of stakeholders in the plenary meeting of the Global Mechanism, in line with the agreed modalities contained in the 2025 OEWG Final Report. Stakeholders from industry, academia and professional and technical organizations, including FIRST, play indispensable roles in supporting the implementation of cyber norms and confidence -building measures, providing timeframes, timely operational responses to emerging cyber threats, facilitating the responsible disclosure of vulnerabilities affecting ICT -enabled critical infrastructure, strengthening cybersecurity capacity -building efforts at the national, regional, and global levels. Members of FIRST have participated in their individual capacities in the UNGGE process since 2012, and FIRST has proudly supported the work of the Open -Ended Working Group since 2019. As the Global Forum of Incident Response and Security Teams established over 35 years ago, FIRST membership currently includes 874 incident response and security teams across 118 countries. Our members include national certs, private sector academic certs, as well as product security and incident response teams. With respect to the ongoing discussions on international law, the stakeholder community can make valuable contributions by facilitating and expanding capacity -building efforts in this area. In particular, the technical community, and especially incident response and security professionals, can provide practical experiences and expertise on how international law applies in cyberspace and help strengthen states’ cyber resilience and preparedness in support of the UN Framework for Responsible State Behavior in Cyberspace, including the implementation of cyber norms and confidence -building measures. We are pleased to contribute. In the past to the OEWG Global Roundtable on Cybersecurity Capacity Building held two years ago, and looking ahead, we hope that similar open, transparent, inclusive consultations will continue to convene through the dedicated thematic groups. We emphasize the importance of a holistic approach to cybersecurity that is grounded on good governance, meaningful stakeholder engagement, and strong cybersecurity communities. Addressing today’s rapidly evolving cyber threats requires diverse expertise, close collaboration among government, industry, academia, and the technical community. During cyber incidents, certs and security professionals routinely exchange threat intelligence, coordinated mitigation measures in real time through trusted, secure, and often informal channels. First, calls upon states to support international collaboration among incident responders and to ensure that such cooperation remains non -politicized, consistent with the relevant UNGGE 2021 report. We look forward to continuing to support the work of the global mechanism and contributing to the shared objectives of a secure, stable, peaceful, and resilient cyberspace. Thank you.
—
Chair Egriselda López
Thank you very much I give the floor to Centre for Humanitarian Dialogue followed by Developing Capacity LTD
—
Centre for Humanitarian Dialogue Representative
Madam Chairperson thank you for giving me the floor I’m speaking on behalf of the Centre for Humanitarian Dialogue a private diplomacy organisation acting from principles of humanity impartiality, neutrality and independence allow me to suggest an issue for consideration that the United Nations have not fully explored confidence building in the cyber and information domain after an armed conflict preparing for peace after war has become timely again the end of a war is not the beginning of peace it is the beginning of a volatile in -between situation forces are still opposing each other, trust does not exist There’s a risk of renewed hostilities, and small incidents can carry big consequences. Military and diplomatic experts have learned to address such hazards. They have developed mechanisms to stabilize a truce, surrendering weapons, placing them under third -party control, nominating mediators, exchanging envoys, establishing joint commissions. Such measures typically focus on the physical, reflecting the traditional domains of warfare. Land, sea, and air. Technological progress has opened a new non -physical domain, cyberspace. No ceasefire, armistice, or peace agreement in history ever had to pay heed to the cyber and information domain. This must not change. Designing confidence -building measures for the non -physical cyber and information domain is a struggle. it is possible to follow troop deployments to count guns, to observe ships and aircraft but it is not possible to watch computer code nor can algorithms be conveniently contoned assembled in one place or disabled malware can be developed anywhere, transported on a chip deployed from any point of earth it is effectively indestructible moreover, since cyber operations are often used in hybrid campaigns or to prepare a kinetic battlefield ICT incidents can raise suspicion in a no -trust security environment such as shortly after a war this is ever more dangerous with this in mind, I encourage the global mechanism to consider and develop ideas for confidence building in the cyber and information domain after armed conflict the Centre for Humanitarian Dialogue which has some expertise in mediating for peace would be happy to assist should to take us up. Thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to Developing Capacity LDT, followed by IMQ and SPA.
—
Developing Capacity LTD
Thank you, Madam Chair and distinguished delegates, for the opportunity to speak today. My name is Robert Collett and I am the Director of Developing Capacity, an organisation focused on capacity building and AI for diplomacy. During the OEWG, we were pleased to support the process by providing unofficial transcripts, contributing to politically neutral side events and producing reports in response to the Chair’s guiding questions. Most significant among these was a series of tabletop exercises on the principles agreed by the OEWG, culminating in a Chatham House report on how they might be applied in practice. I am pleased to say that stakeholders have already begun mobilising Thank you. My organisation joined meetings in advance of this session to agree how we can best assist, and we hope that more experts will be able to speak alongside us in the future. Several capacity -building practitioners, including myself, have recently published articles with practical suggestions for the mechanism that we will submit to the document repository. But you also have more than two decades of research, conference outcomes and lessons to draw upon. This includes the work of previous OEWGs, organisations in the UN system such as ITU, World Bank and UNIDIR, regional organisations and specialist forums. Many excellent suggestions have already been made. However, if I were to prioritise three areas as you structure the work of DTG2, they would be the following. First, aim for quick wins by coordinating, matchmaking and mobilising funding for capacity building activities that directly support the global mechanism and the implementation of the agreed framework. Second, address the deeper strategic challenge of increasing the resources available for cybercapacity building both internationally and domestically. And third, aim to improve the quality, efficiency and demand -driven nature of cybercapacity building. This could be achieved by promoting and operationalising the principles already agreed by the OEWG. Stakeholders stand ready to assist with this work and developing capacity looks forward to contributing. Thank you, Madam Chair.
—
IMQ Intuity SPA
Thank you, Madam Chair. Distinguished delegates, thank you for giving stakeholders the opportunity to contribute to these important discussions. My name is Matteo Tomiazzo, and I represent IMQ Intuity, an Italian company specializing in cyber resilience through realistic attack simulations, contributing to Italy’s national cyber capacity building program. Across hundreds of realistic attack simulations, we have rapidly observed the same pattern. Cyber risks rarely emerge from a single vulnerability. More often, it emerges from the interaction between technology, people, processes, suppliers, physical infrastructure, and the decisions that connect them. The challenge is no longer the number of vulnerabilities. It is the growing number of interdependencies. As our societies become increasingly interconnected, cyber incidents no longer remain confined to technology. A technical compromise can rapidly become operational, disrupting economic impact and ultimately societal consequences. Our experience has taught us that resilience begins by turning the map around. rather than asking how we defend ourselves we ask different questions if we were the attacker where would we begin looking at ourselves through the eyes of those who seek to exploit us reveals dependencies challenges assumptions and help us understand what truly matters before a crisis occurs we have learned another important lesson resilience is rarely limited by technology alone more often it is limited by assumptions that have never been challenged technology helps us protect what we already know changing perspective helps us discover what we have not yet seen realistic simulations do more than test technologies they reveal systematic interactions expose cascading effects and challenge assumptions before real adversaries do resilience is not about protecting everything equally it begins by understanding what is truly critical Every security decision is ultimately a decision about risk. Madam Chair, the framework developed through the global mechanisms provides an essential foundation for responsible state behavior in cyberspace. From our operational experience, we would like to offer one practical reflection. Responsible behavior requires responsible preparation. Preparation means more than deploying technologies. It means understanding complexity, recognizing interdependencies, preparing leaders and institutions to make sound decisions under uncertainty, and challenging assumptions before they become vulnerabilities. Stakeholders have a unique role to play in reaching the open discussion with neutral, factual, and operational evidence from the field. Cybersecurity has been described as a technological challenge. Our experience suggests something different. It is fundamentally a challenge of understanding complexity, and
—
Chair Egriselda López
Thank you very much. I now give the floor to the Moscow State Institute of International Relations, followed by the Internet Society.
—
Moscow State Institute of International Relations
Thank you, Madam Chair, distinguished delegates. Thank you for the opportunity to address this session. Thank you, Madam Chair, for extensive preliminary work conducted before the start of the session. We appreciate the opportunity to engage with accredited NGOs and interested states on capacity-building initiatives. Gimel University has a longstanding academic tradition and expertise in international law and security. From this viewpoint, we believe that universal, legally binding international agreements in information security domain will deliver sustainable long-term outcomes rather than voluntary non-binding norms of state behavior. On capacity-building initiatives, in 2023, we launched a training program to enhance the digital skills for GIMO students studying in non-technical fields, including the future diplomats. More than 2,300 students completed the program to date. This year, GIMO students will be able to learn more about the GIMO program and learn more We proposed an educational project called IDENTITY, which stands for ICT Digital Related Education for Non-Technical and International Affairs Talented Youth. And this project was recognized at the World Summit on Information Society in Geneva as a champion in e-learning category. This award allows us to present our best cases, our best practices to a wider audience by offering free, short-term, open enrollment, distant education courses called Digital Weeks, focusing on international agenda in ICT and information security, national IT strategies, fostering data, AI, and data governance skills, as well as addressing best practices on engaging with ICT. We are also open to share our curriculum details and competence framework that other universities and training centers can adopt in interested member states. On research agenda, in the research field, Mgimon calls for recognition of importance of neutrality of large language models with regard to international affairs, everyday work of diplomats, and media coverage of world events. We are able to identify profound inconsistencies, irregularities, and sentiment shifts in large language model responses on international affairs issues and problems. Lack of language and cultural diversity in the outputs of LLM is also an area of concern. We are developing a set of reproducible tests of benchmark design to identify these anomalies. anomalies. We believe that this work could be the basis of a standardization of a large language model evaluation. McGuimau University stands ready to cooperate with accredited partners and member states on educational programs, research projects, and practical capacity -building initiatives. Thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much. And I give the floor to Internet Society, who will be followed by Kenya ICT Action Network.
—
Internet Society
Thank you, Madam Chair. As this is my first time participating in the global mechanism on behalf of the Internet Society, I would like to welcome the launch of the first substantive plenary session and congratulate you on your election as chair. This mechanism represents years of hard -won consensus, and its success will be determined by whether it can turn around agreed norms into practical, real -world impact for the billions of people who rely on the Internet every day. Since 1992, the Internet Society, a global nonprofit organization founded by Internet researchers, has been a key part of the Internet Society’s Pioneers has promoted the development of the Internet as a global technical infrastructure, a resource to enrich people’s lives, and a force for good in society. There are community members, special interest groups, and over 130 chapters worldwide. Our organization advocates for Internet policies and technologies that keep the Internet open, globally connected, and secure. We come to the table with operational experience and technical expertise as a part of the broader technical community, which is comprised of various organizations. These organizations build the Internet and make it resilient. Specifically, standards developed through the Internet Engineering Task Force, or the IETF, through its open bottom -up process, underpin much of the day -to -day security of the Internet. And the same open participation model proves that effective multi -stakeholder collaboration can deliver. Beyond standards, through initiatives like mutually agreed norms and routing security or manners, we support the development of routing security practices to reduce systemic vulnerabilities and improve the security of the Internet. and global routing. By working with local communities to build Internet infrastructure and skills through community networks and Internet exchange points, this mechanism directly advances the capacity -building goals that it has rightfully prioritized. Additionally, through our Global Common Goods Cyber Initiative and our engagement with cybersecurity community, we help connect resources seeking to fund nonprofits across the globe whose works support the following objectives. Maintenance of critical cybersecurity infrastructure, delivery of scalable support to secure Internet users from digital harm, including state -directed cyber activity and digital transnational repression, and the advancement of safer Internet for vulnerable groups and high -risk communities, including civil society and journalists. We would be really glad to bring these perspectives to the dedicated thematic groups, particularly that on capacity -building. Our core message today is this. We believe that this mechanism’s long -term success will be served by meaningful and sustained engagement of non -government. mental stakeholders. This is not a courtesy. It is essential. The Internet is not solely run by governments. It is run by a distributed ecosystem of network operators, standard bodies like the IETF and technical experts. Decisions on cyber norms, international law and confidence building should make the input from these stakeholders who build and secure its infrastructure prioritized. Otherwise, the mechanism risks being disconnected from operational reality. Therefore, we would like to call on member states to ensure stakeholder accreditation and participation modalities are implemented in predictable, transparent and non -reactive manner to include actors without ECOSOC status through fair application and the non -objective process. Preserve and strengthen the multi -stakeholder model that keeps the Internet resilient, innovative and globally interoperable and offers stakeholders an opportunity to contribute substantively to the DTGs, allowing stakeholders to bring their insights and perspectives, to continue to contribute and better the the results to be implemented and supported. The Internet Society looks forward to constructively and substantively contributing to the global mechanism. And before I close, I would like to invite you all to the briefing that will be co -organizing with the Permanent Missions of Kenya and Bulgaria, alongside ICANN and the ITU, entitled Demystifying the Internet Collaborative Security Approaches. It will be taking place tomorrow
—
Chair Egriselda López
Thank you very much. And I’ll give the floor to Kenya ICT Action Network, followed by Association for Progressive Communications.
—
Kenya ICT Action Network
Thank you so much, Madam Chair. I’m making this statement on behalf of KICTANET, and it reflects outcomes from consultations with a broader multi -stakeholder. community that have been taking place in preparation for this week. We congratulate you, Madam Chair, on convening this historic substantive plenary. As this global mechanism establishes its first permanent foundation, we face a decisive choice. Either repeat the familiar rituals of diplomatic deliberations or pioneer a collaborative more capable of confronting borderless digital threats. To deliver real stability, this mechanism will need to consider new ground in several ways, as we put it to you. In our humble consideration, one, we would like consideration of consultations with a structural integration that considers multi -stakeholder approaches We call for the recognition and utilization of non -static expertise to be systematically woven into informal consultations, technical drafting, and policy implementation. So there is need for multi -stakeholder approaches in the ways that things will move from now. Two, we call for the delivery of human -centric, demand -driven capacity building, and we are saying that digital security is fundamentally about human safety. Resources, therefore, need to move beyond high -level legal meetings towards strengthening local incident response teams, defending civic space, and protecting vulnerable communities from technology -facilitated abuse. Three, make the dedicated thematic groups actionable vehicles for problem -solving and aim to create real -world impact. We propose that the DTGs be prioritized. We propose that the DTGs be prioritized. civil society and governments co -design workable responses to critical infrastructure vulnerabilities and AI -amplified harms in space. And finally, four, anchor policy in ground -level cyber threats. Non -state actors and private sector operate on the front lines of threat detection, incident response, and human rights monitoring. We humbly call for consideration to establish formal channels to ingest grassroots data, in particular from developing nations. This will ensure internal norms respond to real -world harms. And, Chair, we also request that if we can set up meetings, either virtual where we can just be appraising ourselves either quarterly or half -yearly, so that we make this engagement possible. real. And so to secure cyberspace, we call for shared stewardship across all sectors and Kictanet and the broader multistakeholder community that have been participating this week remain fully committed to partnering with member states to ensure our digital future remains safe, open, and anchored in human dignity. Thank you so much, Madam Chair.
—
Chair Egriselda López
Thank you, Kictanet, and I’ve heard you. Loud and clear. I now give the floor to Association for Progressive Communications, followed by the Royal Institute of International Affairs.
—
Association for Progressive Communications
Chair, colleagues, I speak to you today on behalf of the Association for Progressive Communications. Since this is the first time that APC is taking the floor, let me first congratulate you on your appointment, Madam Chair, and our appreciation for the efforts that you, the Secretariat, as well as the co -facilitators have been making at helping us engage and aid the mechanism. For those of you who may be unfamiliar, APC is an international not -for -profit membership organization born in 1990 whose network includes 74 organizational members and many associates across 60 countries. We are also proud to have several of our members present here in the mechanism today. From our beginning, our network has believed that it is crucial for the international system to engage with civil society, public interest technologists, and grassroots communities on the political and policy aspects of technology development. APC has engaged with the UN’s discussions on global cybersecurity across the successive OEWGs, and we are glad to see this permanent mechanism come into operation. We do believe that state -led and multilateral system capacity building programs must address the disproportionate impact of cyber threats faced by vulnerable communities including women, LGBTQI plus people and human rights defenders The unique threats that different communities in the Global South face are often unrecognized or even unrecorded and therefore not catered for in these discussions and processes In effect, they are invisible Your Excellencies, the reality is that cyber threats, models and actors are different in different communities Civil society can support this by providing evidence to better understand and mitigate these differentiated effects Based on interviews and testimonies from women in public -facing roles members of the APC network have documented how digital surveillance is used to intimidate, silence and restrict women’s participation in civic and political life In that regard, we therefore hope that the global mechanism builds on the recognition documented by the second OEWG of the harms posed by the global growth of the cyber mercenary hack for hire spyware sector and the harms it unleashes on human rights defenders, journalists and activists working on women and LGBTQI issues. We call on further work on the gendered impact of these efforts and how vulnerable communities are impacted by cyber mercenary actors. Chair, as you have heard from me, it has often been society and academic research which has documented the empirical evidence of the harms of matters such as ransomware or more. It is therefore crucial that the global mechanism overcome the injury it inflicted on itself by the initial locking of so many stakeholders who we need to see sitting besides us here. Madam Chair, APC and its members have been organising training activities to equip stakeholders with the capacities needed to engage in global cyber security policy discussions. We urge you to ensure that this process is both enabling and a safe space so that these communities who we are building capacity with training can take part and we have civil society, vulnerable communities and security researchers actively participating here. We also believe that the global mechanism and its DTGs must help states build appropriate cybersecurity laws and policies which aid and do not overreach or oppress. Our members and partners have urged governments to implement gender -sensitive cybersecurity laws that holistically address digital violence and build appropriate rapid response mechanisms. We hope that this is prioritized by the DTGs. Excellencies, we urge you to pay attention to how the race for AI development impacts the global majority, particularly in an information security context. We believe that the mechanism and the DTGs should focus on how the current race for AI deployment, particularly in the public sector, is impacting security vulnerabilities and in turn affecting vulnerable communities. We also believe that in the sphere of AI and cybersecurity, the mechanism should ensure that the lessons of the last two decades of human rights and feminist approaches to technology is a foundation we build on. Madam Chair, rest assured that all stakeholders, whether accredited or not, stand ready to help you in this process. We urge you to listen to us. We share critical information. That helps patch the problems that we see in our global ICT systems. Thank you.
—
Chair Egriselda López
Thank you very much I now give the floor to the Royal Institute of International Affairs followed by InternetLab.
—
Royal Institute of International Affairs (Chatham House) Representative
Thank you Madam Chair for the opportunity to speak today and for your tremendous efforts in fostering an inclusive process and establishing strong foundations for the work of this mechanism The global mechanism gives us something two decades of cyber diplomacy have been working towards a standing space to continue building shared understanding and to support implementation over time States have agreed on a framework for responsive state behavior and that agreement provides an important foundation Our focus now should be on what it will take to ensure that the framework is reflected in practice First on implementation, as many delegations highlighted yesterday the dedicated thematic groups will be central to closing the implementation gap and we have shared our views on how best they can be structured and we will continue to do so Thank you States also have a strong foundation to build on They have already developed a significant body of guidance through previous UN processes and at the national level complemented by practical resources from the multistakehold community such as, for example, the paper Chatham House developed on the operationalization of the cybercapacity building principles that my colleague mentioned But we should also be honest The existence of resources is not the same as the capacity to use them Guidance cannot implement itself Many states are committed to implementing the framework but continue to face technical, institutional, or financial constraints as well as competing priorities that make doing so difficult even when practical guidance is readily available This is where the multistakeholder community is not a bystander but a partner in implementation Industry, technical organizations, academia, and civil society already help translate the framework into operational guidance often in direct partnership with states The challenge is not whether this expertise exists but whether it can be implemented and whether states will make full use of it We therefore encourage states to to draw more deliberately on that expertise, both within and beyond these official sessions, especially as many stakeholders actively working on these issues have had their accreditation to the official meetings denied. Second, while implementation is rightly the priority for this phase of this mechanism, we should not lose sight of the fact that the environment the framework is intended to govern continues to evolve. More states are adopting offensive cyber postures, the growing use of proxy actors, the emergence of frontier AI models and their implications for cybersecurity, and the wider availability of sophisticated cyber intrusion tools are all changing the operational landscape. This is precisely why the mechanism has such an important role to play, not only in supporting implementation of existing commitments, but in continuing to build shared understanding of what responsive behavior means as technology and state practice evolve. Finally, we would note that resonance matters as much as resourcing. The norms will only shape behavior if they are understood beyond this room, not as lists of letters, but as the practical expectations that sit behind them. Expectations such as protecting critical infrastructure, cooperating in responding to cyber incidents, or taking reasonable steps to ensure that a state’s territory is not used for internationally wrongful ICT activity. Connecting those expectations to real incidents and real operational challenges helps make the framework something people can recognize, relate to, and ultimately implement. Making it tangible is in itself a form of implementation, and multi -stakeholders can help with that, provided states create space to bring them into that work. We are committed to continuing to coordinate amongst the broader multi -stakeholder community to provide expertise in all ways available to us and help ensure that the global mechanism delivers on its objectives. Thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to Internet Lab and lastly to Access Lab.
—
InternetLab
Madam Chair, I’m delivering this statement on behalf of Internet Lab, a Brazilian think tank dedicated to producing knowledge at the intersection of digital technologies and human rights. This statement also reflects consultations with the broader multistakeholder community conducted in preparation for this week’s discussions. I want to start by briefly manifesting our disappointment with the number of organizations that have been blocked from participating in the formal sessions of the global mechanism, many of whom have provided their support and expertise to this process without any political agenda. We, therefore, appreciate your commitment, Madam Chair, to ensuring broader and meaningful stakeholder participation in the DTGs, including the participation of non -accredited stakeholders in line with established UN practice for international and international relations. informal working methods. Looking ahead, we encourage discussions that are closely connected to the needs identified by member states during the plenary and that focus on practical implementation. For DTG1, discussions should examine how emerging developments affect the implementation of existing UN framework rather than creating parallel normative processes. In this regard, we underscore that this framework operates within international law, including international human rights law and, where applicable, international humanitarian law. We also encourage discussions grounded in concrete case studies and implementation expertises. This exercise should be guided by a set of previously identified guiding questions, allowing stakeholders’ contributions to address the issue that co -facilitators consider most relevant in light of the views expressed by member states. We also believe that it is essential to examine how the use and misuse of ICTs affect individuals and communities differently. This includes considering specific risks faced by women and other historically marginalized groups. An inclusive and evidence -based understanding of these differentiated impacts is necessary to ensure that responses to cybersecurity challenges are both effective and rights -respecting. For instance, for instance, our own resources, our own research on online gender -based political violence against women politicians in Brazil has documented how coordinated attacks disproportionately target women and members of other historically marginalized communities, with clear implications for the impact of ICTs. for democratic participation and for the design of effective rights -respecting cybersecurity responses. For DTG2, we encourage discussions on sustainable, demand -driven, and inclusive cyber capacity building that build on the process achieved in the WGG and focus on implementation. Priorities should include better coordination among existing initiatives, support for states with limited resources, and cooperation for secure open -source cybersecurity tools. As an organization for the global majority, we emphasize that effective capacity building requires meaningful engagement with priorities of the global majority states, while drawing on the expertise of civil society, academia, the technical community, and the private sector. Capacity building initiatives should also be accessible, context -sensitive, and responsive to those most affected by cyber threats. Madam Chair, we remain committed to supporting this process in a constructive spirit and look forward to continue to work with member states and all stakeholders to ensure that the global mechanism becomes an effective, inclusive, and actual orientated platform. Thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to Access Now.
—
Access Now
Thank you, Madam Chair. I am making this statement on behalf of Access Now, a grassroots to global organization that defends and extends the digital rights of individuals and communities most at risk. Our statement today reflects outcomes from consultations with the broader stakeholder community that have been taking place in preparation for this week. As stakeholders, we look forward to sharing our expertise and experiences during the DTG in December in a constructive and actionable way. Thank you. On existing and potential threats, Access Now fully aligns itself with the statement made yesterday by Kenya ICT Action Network, particularly the existing threats surrounding the unchecked proliferation of commercial spyware, surveillance, and state -sponsored cyber harassment used to monitor, intimidate, and silence journalists, human rights defenders, and political dissent. With respect to threats posed by ICTs in armed conflict, we echo the statement made yesterday by ICRC regarding the alarming range of ICT operations that have disabled the provision of essential services for civilian populations. Out of the 313 Internet shutdowns documented by Access Now and the Keep It On Coalition in 2025, 125 shutdowns occurred. In situations of conflict, impeding access to essential services and communication. in light of these existing and potential threats we would like to underscore three priority areas for further discussion during the dtgs first we urge that the dtgs to make the human cost of critical infrastructure attacks visible and foreground the role of civil society in its defense this requires direct engagement with and the protection of the human beings who make cyber security possible including those who provide research and handle incident response especially regarding to digital security threats against those most vulnerable this cannot remain an aspiration states must ensure that national critical infrastructure protection frameworks give real operational effect to their human rights obligations while protecting tools like strong encryption and independent research capabilities that enable civil society to contribute Second, the rapid increase in capabilities of AI models is a major topic of discussion. We echo calls not to duplicate existing UN processes grappling the questions regarding AI, but rather to build on such discussions with a focus on the unique issues and value of the global mechanism. With that, we call for the specific recognition of how AI tools are beset by glaring security vulnerabilities that have grave consequences for the confidentiality of our data, information integrity, and access to and the availability of systems. These are all problems that a human rights respecting approach can help solve. When human rights are successfully placed at the center of discussions on AI, as witnessed in other UN processes, the outcomes shift to concrete and forcible protections for those most at risk. Third, DTG1 should build on the substantial body of state practice already affirming that international human rights law and international humanitarian law apply to state cyber behavior and turn consensus into shared understanding implementation. We commend the growing number of states that have proactively published national positions on the application of international law to cyberspace and call on states to ensure that the same rigor is reflected domestically so that national cybersecurity laws, policies, and strategies are developed and implemented consistent with their international human rights law and international humanitarian law obligations. In conclusion, Madam Chair, we reiterate our intention to support all states present in this room, especially small states and those with disabilities. We also want to thank you for your support in delivering on the commitments made in the framework of responsible state behavior and the objectives for the global mechanism. Thank you.
—
Chair Egriselda López
Muchas gracias. Thank you very much to all of you. First, for your very substantial contributions. all of you who are here in the room like I said at the beginning of this segment as well as to all of you who are following us remotely the community of stakeholders is without a doubt a fundamental part of our work and you have a lot of experience and considerable knowledge and we will continue to work closely with you to achieve meaningful progress my team and I have taken due note of all of your comments, your invitations the calls to action that you’ve made we would also be grateful if you could please share your statements with us not only with the Secretariat but with the Chair’s team please, we’d be grateful for that thank you I’d now like to open the floor for any delegation who would like to react to any of the statements made by the organisations that we’ve just heard from this afternoon in the spirit of having an interactive dialogue. So if any delegation would like to take the floor, you may do so now by pressing your microphone button and the Secretariat will take note of it. Canada, you have the floor.
—
Canada
Thank you very much, Madam Chair, for this new opportunity to take the floor on this important matter. We welcome the interventions by the stakeholders that have been accredited to this plenary session. Unfortunately, they are too few. A number of interventions delivered today demonstrate the readiness and willingness of colleagues from the multi -stakeholder community to contribute further on practical matters in the context of the dedicated thematic groups. Their contributions span the breadth of priorities identified by states over the course of the week for each of the DTGs, including on technical and other forms of capacity building, on international law and norms implementation, as well as other important matters, such as the particular impacts of given threats on gender and youth. While we heard stakeholders from a number of regions today, we would have benefited from much more robust cross -regional representation of stakeholders if they had not been vetoed. I am referring here to stakeholders from Mexico, Brazil, Peru, Panama, Ghana, Nigeria, and South Africa. We look forward to more meaningful and more inclusive opportunities for all stakeholders to engage in December. Thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much. And I’ll give the floor to the Delegation of Japan.
—
Japan
Thank you, Madam Chair. Well, thank you, Madam Chair. As cyber security, cyber threats become increasingly sophisticated and complex, it is critical to draw on the private sector’s expertise for recognizing threats and implementing concrete countermeasures. Japan attaches great importance to a multi -stakeholder approach in the global mechanism. In this regard, Japan highly values this session and strongly hopes to further strengthen public -private collaboration within the United Nations framework through expert briefings and interactive discussions between the public and private sectors, especially including the discussion of the DTGs. With a wide range of stakeholders’ participation, we hope that Member States’ awareness and understanding of cyber security will deepen further. Thank you very much.
—
Chair Egriselda López
Thank you very much. I’d like to ask whether any other delegation would like to take the floor in this interactive segment. Mexico, you have the floor.
—
Mexico
Thank you very much Madam Chair I’d like to begin by thanking you and the Secretariat for organising this segment which is a very important one for Mexico. We’d like to welcome the fact that on this occasion the screens reflect the names of the organisations taking the floor and for Mexico this is a practice that does not only give visibility to the valuable contributions of each and every organisation but also reflects the importance that this mechanism attaches to the meaningful participation of all stakeholders. My country took note of the contributions made, in addition to the ones also made in writing. Preparing for the meeting on the dedicated thematic groups in December, my country would like to urge stakeholders to consider drafting specific inputs for the issues under discussion, so that we can use these not only for the discussions in the meetings, but also for the analyses, the technical analyses that member states will be engaging in on this process in their respective capitals. Further, as far as possible, I’d like to ask a question. It’s more of a general question. I don’t necessarily need a response, but if there’s any stakeholder that is in a position to answer it, we’d be… grateful to have an answer to it and of course we also remain available outside of the room to discuss it. It would be very beneficial if you could be able to share any example of any work, any ongoing work that you are engaging in, for example any guides, guidelines, methodologies, models or any good practices to support states to implement the framework on responsible behaviour. In particular Mexico would like to know whether there’s any example that you could share that could benefit a developing country like Mexico and that takes account of our perspectives.
—
Chair Egriselda López
Thank you, says the Chair for your question and your statement. Would any delegation like to take the floor right now? I see there are. Is that the European Union? Please go ahead
—
European Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San Marino
Thank you very much Chair, first of all thank you very much for offering the opportunity for stakeholders to speak during our session today but also for your earlier engagement with the stakeholders prior to this plenary session. Also yesterday the two stakeholders that were able to come in after the threat section really dedicating their interventions to the topic that we are discussing at that moment is very useful to bring the stakeholders and states closer to each other when it comes to advancing international security and stability in cyberspace. So we very much welcome your efforts We also wanted to say thank you to the stakeholders for participating We know it’s been a challenging environment for you but we are very much interested in your contributions not only when it comes to the statements that you are able to make today as well as the states that you have been able to make today able to make in the run -up to this session, but also your contribution when it comes to specific challenges that we will be discussing in the dedicated thematic groups. Furthermore, we encourage you to continue to contribute to this effort by enhancing the cooperation with states working together on the ground, building capacities also from states in implementing the UN Framework of Responsible State Behavior and enhancing their cyber resilience through your research, through your trainings, and through the dedicated activities that you employ. And we look very much forward to continue the cooperation with you and with states on this important matter.
—
Chair Egriselda López
So thank you very much. Muchísimas gracias. Thank you very much. I don’t have any other delegation on my list to take the floor in this segment. So I will… give the different stakeholder organizations the opportunity to answer… the question posed by the delegation of Mexico on whether you could share any example of any work that you are engaging in, whether it’s a guide model, methodologies to support states for the implementation of the Framework on Responsible Behaviour. If any of you would be interested in briefly answering this question then please press your microphone button so that we can see who is requesting the floor. Before that though I’ll give the floor to the International Chamber of Commerce who had asked to take the floor in this space
—
International Chamber of Commerce
and you have four minutes. I have the honour to deliver this statement on behalf of the International Chamber of Commerce, the institutional representative of more than 45 million companies in over 170 countries and an observer to the United Nations General Assembly. ICC has engaged in the open -ended working group since its inception and looks forward to contributing with the same commitment to the work of the new UN global mechanism on cybersecurity. The mechanism begins its work at a critical moment. Businesses are operating in an environment marked by geopolitical tension, economic uncertainty, and a sustained rise in malicious cyber activity targeting governments, companies, critical infrastructure, and essential services. The success of the mechanism will depend not only on the quality of intergovernmental dialogue, but also on its ability to draw on the expertise, experience, and capabilities of the broader cybersecurity community. The OEWG demonstrated the value of stakeholder engagement, and the global mechanism should build on that experience by ensuring that industry, the technical community, and civil society can contribute in a meaningful, structured, and predictable manner across all areas of its work. The dedicated thematic groups provide an important opportunity to translate dialogue into practical and meaningful dialogue. and practical cooperation. Business stands ready to contribute operational expertise, technical knowledge, and implementation experience, particularly in the areas of existing and emerging threats and cybersecurity capacity building. First, on existing and emerging threats. The private sector is often the first to identify, analyze, and respond to new cyber risks. Companies possess real -time visibility into threat trends across networks, sectors, and geographies, as well as practical experience in mitigating attacks and strengthening resilience. This operational insight can help the DTGs develop a more comprehensive understanding of the evolving threat landscape, identify emerging risks, and support the sharing of good practices that reduce cyber risks across the digital ecosystem. Industries’ expertise and practical experience can support discussions on topics such as protecting critical infrastructure, essential services, and global supply chains, strengthening cyber resilience and incident preparedness, particularly for small and medium -sized enterprises. improving coordinated vulnerability disclosure and reducing systemic risks, facilitating threat information sharing and public -private cooperation, promoting secure -by -design approaches and responsible security practices, addressing emerging technological developments and their cybersecurity implications, and supporting the practical implementation of agreed norms and confidence -building measures. Second, capacity building should be an integral part of the mechanism’s work. Cybersecurity capacity strengthens confidence in the online environment, supports meaningful digital inclusion, and helps countries protect their citizens, businesses, and critical infrastructure. Yet significant gaps remain, particularly in the development and implementation of national cyber strategies, incident response capabilities, technical expertise, and institutional frameworks. The private sector is making substantial contributions through technical assistance, workforce, and skills development, awareness raising, knowledge sharing, incident preparedness, and the provision of practical tools and resources. Businesses also work alongside governments and other stakeholders to strengthen institutional capabilities, improve resilience, and share operational expertise Finally, meaningful stakeholder participation is not merely desirable It is essential to the success of the global mechanism Cybersecurity discussions cannot be separated from the systems, services, and infrastructure they seek to secure Much of the world’s digital infrastructure is designed, operated, and maintained by the private sector while technical experts and civil society bring additional expertise and perspectives that strengthen cybersecurity outcomes In closing, business looks forward to being a constructive and partner in the global mechanism We can contribute by sharing real -time threat intelligence, operational expertise, and lessons learned from securing networks, supporting incident response, strengthening supply chain resilience, and
—
Chair Egriselda López
Thank you very much Thank you I have a request from the delegation of Chile please go ahead
—
Chile
thank you very much Madam Chair, we just wanted to take the floor like Canada and the European Union on this stakeholder segment and we wish to thank you for facilitating the work of the global mechanism to all the organisations we thank you very much for being here this afternoon with us, your participation is fundamental, you bring practical experience specialised knowledge and I talk about concrete challenges that can help us and to support the effective implementation of the mechanism we reject the amount of objections voiced on your participation including from institutions from our own region your voice is very important in order to reflect listen to diverse voices and reflect the reality on the ground and we hope you will be able to continue to contribute through the dedicated thematic groups, thank you very much
—
Chair Egriselda López
thank you Now we’ll give the floor back to the different stakeholders so that they can answer the question made by the Mexican delegation. I’d be grateful if you could do it as briefly and concisely as possible so that we can hear from everyone who’s requested the floor. So I’ll give the floor first to the Royal Institute of International Affairs, who will be followed by the Association for Progressive Communications.
—
Royal Institute of International Affairs (Chatham House) Representative
Thank you for the delegate from Mexico for this concrete question and for all other delegations for their words of support. There’s already a meaningful body of practical work to draw on. I mentioned in my intervention the Chatham House report providing concrete recommendations for the operationalization of the cybercapacity building principles. This could be obviously highly relevant to DTG2. But also other organizations have produced important tools and resources. I mentioned the one I’m aware of and colleagues might. I want to complement that. The Geneva Dialogues manual offers concrete guidance on implementing specific norms. like supply chain security and responsible vulnerability disclosure. The Paris Call for Trust and Security in Cyberspace brings together commitments from states, companies, and civil society around shared principles. And organizations like the Cyber Peace Institute, now called Protect NGO, have produced sector -specific guidance, for example, on protecting the healthcare sector from cyber harm. We have been discussing as a multi -stakeholder community perhaps mapping these resources and making them available to states, and we welcome views on what would be the most useful format to you when we do so. Thank
—
Chair Egriselda López
Thank you very much. Yes, that would certainly be very valuable. I now give the floor to the Association for Progressive Communication. Please go ahead.
—
Association for Progressive Communications
Thank you so much, Madam Chair, and again thank you to the delegate from Mexico for the pointed question. As my colleague from the Royal Society for International Affairs mentioned, there are a range of resources the society makes available, from the Association for Progressive Communication, Thank you very much. Thank you very much. Thank you very much. Thank you very much
—
Chair Egriselda López
I now give the floor to Developing Capacity
—
Developing Capacity LTD
So the international community of stakeholders and governments have for several years been building a repository to answer that very question it’s called the Sybil Portal it has 74 documents which are on the thematic area that you’re interested in and also information on 100 past cyber capacity building projects in that area it’s received a lot of support in the past from the Dutch government it’s currently going through a period of renewal which I was discussing with other stakeholders earlier today and it stands ready to be a state and stakeholder platform for hosting these sort of resources going into the future Thank you very much
—
Chair Egriselda López
And I give the floor to Foreign Incident Response Force and Security Teams.
—
Forum of Incident Response and Security Teams
Thank you for the delegates from Mexico. We really appreciate, you know, any joint cooperation that would result, you know, in supporting Mexico applying the models for best practices and implementing state -responsible behavior in cyberspace. In relation to FIRST, the Foreign Incident Response and Security Team, we already have 31 team members from Mexico, which is really a sizable number of members. And there is an upcoming event happening in Mexico City. It’s the Mexico City Technical Colloquium taking place next month. We have different mechanisms by which we can support efforts in, you know, in different parts of the world, you know, evidently. If we have, you know, so many members, it, you know. set the ground for further cooperation. We can also share experiences from other parts of the world. So we welcome continuous dialogue with countries that are interested in support from FIRST and FIRST membership would be more than happy to give that support extended in different shapes and forms depending on the current situation. Thank you.
—
Chair Egriselda López
Muchísimas gracias. Thank you very much. First I now give the floor to Future Earth Systems.
—
Future Earth Systems
Thank you Madam Chair. Rather than take time up during this session I would be happy to meet with the Honourable Representatives from Mexico as a follow up to explore how enterprise architecture can assist states with implementation of the norms. Also thank you to representatives for your positive feedback to our participation today. Thank you Madam Chair.
—
Chair Egriselda López
Muchísimas gracias. Thank you very much for your kind availability. I give the floor finally to Internet Society.
—
Internet Society
Thank you, Madam Chair. I already mentioned the IETF, the Internet Engineering Task Force. The Internet Society specifically offers a policymaker program to policymakers, and it specifically goes over how the Internet works, provides visibility on Internet standards development processes, and the idea is to work with diplomats to understand how the Internet works, how it evolves, and the standards that underpin it. So that we can all collectively develop and implement better policies. I’m happy to connect after this as well to provide more information to the Mexican delegate. Thank you.
—
Chair Egriselda López
Muchisimas gracias a todos. Thank you very much, all of you, for these responses and follow -up comments. I see that Germany has requested the
—
Germany
floor. Thank you Madam Chair and I would like to take the opportunity to echo what colleagues have said from the EU, Canada, Mexico and Chile with regard to the importance of this exchange and that we also regret once more and we have to highlight this that we only had a limited number of participants in this interactive exchange that we very much value. In this regard we would just want to highlight one piece of work that has been presented by an organization that was not allowed to come here it is the organization Interface that has presented a study and a survey that compares the global state of labour regard to a CBM implementation and we consider this survey and this analysis quite useful for the interaction and engagement that we will have very likely already this afternoon. Thank you very much Chair.
—
Chair Egriselda López
Thank you very much Germany for this information. Once again, thank you very much to all of you. Thank you very much. that interaction was very valuable with all of you stakeholders. So I’d like to close this part of the meeting. And just like I said this morning, we’re going to go back to international law. There are still six speakers on my list, so I’ll read them out so that we can begin with the statement. So we have Switzerland, the United States, Australia, Nicaragua, Algeria, the African Union, and the ICRC. Switzerland, you have the floor.
—
Switzerland
Madam Chair, Switzerland fully aligns itself with the joint statement on international law and IHL that we delivered this morning. This morning on behalf of a cross -regional group of states. We will therefore limit ourselves to the following points in our national capacity. Switzerland welcomes the second joint statement on international law delivered by Australia and many other statements in this regard. The number of states that have issued these, more than 40, underscores the relevance of the discussions to date on international law, especially also on IHL and international human rights law. Additionally, more than 36 national and two regional positions on the application of international law in cyberspace have been published. All of this shows that there is great interest in continuing these discussions, but not in any manner. The new mechanism offers the opportunity to turn statements and written positions into lively and substantial discussions based on real -world scenarios in the DTGs. That is likely to be an innovative step forward. Madam Chair, Switzerland stands ready to participate actively in the dedicated thematic group. As mentioned in our joint statement, we support concrete discussions on real -world scenarios, particularly on the protection of critical infrastructure, such as hospitals, water systems, and energy networks from malicious ICT operations, both in times of peace and in armed conflict. We also support expert briefings on specific topics of international law, IHL, and international human rights law, and would also like to once again highlight the importance of the inclusion of stakeholders in these discussions. In our view, the success of the global mechanism is connected to the recording of both emerging convergence and open questions. Documenting this progression is what will distinguish this mechanism from its predecessors. Madam Chair, discussions on the concrete application of international law take place not only in the United States, but also in the United States. Not only here in New York, but also elsewhere. In this regard, we would like to highlight the ICT work stream under the Global Initiative to Galvanize Political Commitment to IHL and the meetings of our cross -regional group on international law and IHL in cyberspace. Switzerland is honored to co -chair, together with Ghana, Luxembourg, and Mexico, the ICT work stream of the Global IHL Initiative. This process provided an invaluable complementary platform for very substantive discussions on IHL and ICTs among states and key stakeholders. We have moved beyond the question of whether IHL applies to ICT activities in armed conflict to the more practical and pressing question of how it applies. The discussions have reaffirmed that reliable ICT infrastructure and services are indispensable for successful IHL and ICT work. IHL is a key part of the IHL work, and it is a key part of the IHL work. IHL is a key part of the IHL work. IHL is a key part of the IHL work. IHL is a key part of the IHL work. IHL is a key part of the IHL work. IHL is a key part of the IHL work. IHL is a key part of the IHL work. IHL is a key part of the IHL work. IHL is a key part of the IHL work. IHL is a key part of the IHL work. They have equally underscored that civilians and other protected persons and objects must be safeguarded against the dangers arising from ICT activities during armed conflict. We encourage everyone to draw on these rich discussions and the outcome document and to continue developing and promoting a shared understanding on how IHL applies concretely. In addition, in April this year, representatives from 15 states from our cross -regional group gathered for the second time on Mount Rigi in Switzerland to discuss the concrete application of international law and IHL in cyberspace in an informal setting, allowing us to dive deeper into real -world scenarios. Initiatives like these foster a better understanding of other states’ concerns and support the discussions in the UN without duplicating them. Finally, IHL is a global, inclusive, and inclusive organization that is committed to the development of IHL -related issues. We would like to thank the ICRC for submitting their working paper entitled Preventing ICT Threats to the Civilian Population in Times of Armed Conflict, Six Humanitarian and Legal Priorities, to the GMAC. We invite states to use it as a basis for focused discussions on international humanitarian law. While all six priorities are important, we believe that the issue of ICT operations targeting medical facilities and humanitarian organizations is one that all
—
Chair Egriselda López
Thank you very much. I give the floor to the delegation of the United States, who will be followed by Australia.
—
United States
Thank you, Madam Chair. Further to the statement we set out yesterday, I wanted to reiterate again our view that existing international law applies to activities in cyberspace and remains fit for purpose. The United States will not support language suggesting new binding obligations are required or that existing legal obligations are somehow insufficient. We believe that any proposal to use this pillar or to use it in G1 to relitigate international law as a stalking horse for treaty making duplicates work that has already been done and it keeps discussions on this topic very stagnant We have shown extreme flexibility over the course of these discussions in the OEWG but we will not agree to a discussion topic that will be hijacked for that purpose Our previous discussions on international law have demonstrated that existing legal obligations remain fit for purpose So further discussion of international law in this mechanism should be anchored in concrete threats and practical tools for addressing them I believe that’s also something that’s been echoed throughout the day Finally, Madam Chair, the United States believes that we should use our time in this GPM to implement the 11 norms states have already committed to and not to relitigate settled ground to manufacture the appearance of a gap that does not already exist. Thank you so much.
—
Chair Egriselda López
Thank you very much. I now give the floor to Australia, who will be followed by Nicaragua.
—
Australia
Thank you, Chair. Australia is pleased to align with the Pacific Islands Forum statement delivered by Tonga and the cross -regional statement on international law delivered by my colleague. And we make the following remarks in our national capacity. All states have agreed existing international law applies to state conduct in cyberspace. And that, as my colleague from Kiribati powerfully set out, it is indispensable in advancing responsible state behavior in cyberspace and in maintaining the international peace and security on which all states rely. In the GGEs and the OEWG that preceded this forum and in other valuable platforms, we have discussed and reached convergences on how international law applies to cyber activities. and the OEWG saw states solidify and add granularity to several specific areas of convergence. Some of these, including on the application of the principle of sovereignty, non -intervention, the prohibition on the use of force, and the peaceful settlement of disputes, were reflected in the OEWG’s 2025 final report. This report provides a strong foundation for our work. However, we regret that it did not reflect other areas in which states had worked hard to identify common ground, including on the ways in which international human rights law, the law of state responsibility, and international humanitarian law apply. In this respect, the two cross -regional groups of states on international law made significant contributions to advance and to document discussions in the OEWG, and the number and diversity of states that joined statements delivered by those groups today and the number and diversity of states that joined statements delivered by those groups today demonstrates the broad appetite to prioritize international law in this mechanism. taking the work of these groups as our baseline and their cross -regional character as our example we must now take up the opportunity that this mechanism offers to consolidate common understandings between states to actionable effect this can start by leveraging the integrated and inclusive platform of the dtgs bringing together legal technical and diplomatic expertise to elaborate in substantive ways exactly how these areas of law apply here states can have tangible and cross -cutting engagement on how relevant law intersects with norms and practical measures to address the pressing security threats that states have outlined in recent days australia’s experience has shown that applying international law to concrete cyber incident scenarios helps to build confidence and shared understanding demonstrate the practical value and comprehensiveness of the existing legal framework you and connect it tangibly to implementation action Incorporating the perspective of legal and technical experts will enrich and ground the outcomes of these discussions. Chair, we echo the views expressed by others in this session that capacity building remains essential to ensuring that the outcomes of our discussion reflect the full breadth of experience in this room. Australia will continue supporting efforts, including through DTG2, to ensure all states can contribute meaningfully to and benefit from the discussions on how international law applies to cyberspace. This includes identifying and championing needs -driven training and supporting more states to develop and share their national positions. Chair, international law’s contribution to peace and stability in relation to cyberspace can only be fully realized when states share common understandings of what our international legal obligations require in practice and a robust commitment to implement
—
Chair Egriselda López
Thank you very much. I give the floor now to the delegation of Nicaragua.
—
Nicaragua
Thank you very much, Madam Chair. For Nicaragua, the particularities of cyberspace require the debate on the application of international law to continue to be engaged in in a careful, inclusive and intergovernmental manner. In this regard, for us it’s necessary to continue to build a common understanding on the way international law should apply to this sphere, bearing in mind its specific characteristics and avoiding interpretations that could favour the militarisation of cyberspace. The UN Convention against Cybercrime demonstrates that against the new challenges derived from the use of ICTs, the international community can make headway. through dialogue and consensus towards multilateral instruments. This experience confirms the importance of keeping open the debate on the progressive development of the international legal framework, including the possibility of drafting international legally binding instruments that enable us to respond to emerging challenges in this area. Madam Chair, for developing countries, this process must be coupled with effective international cooperation, capacity building and technology transfer that enable everyone to participate in equal conditions in the debates on and drafting of international law. National capacities are limited, including by UCMs, that widen the digital gap and affect the right to development of our peoples. Nicaragua reiterates its commitment to a balanced mechanism focused on concrete results that promotes the peaceful use of ICTs. Thank you very much, Madam Chair.
—
Chair Egriselda López
Thank you. Thank you very much. I give the floor now to Algeria.
—
Algeria
Thank you, Madam Chair. Algeria aligns itself with the statement delivered earlier by Nigeria on behalf of the African group and wishes to express the following points to share its views on the applicability of international law to cyberspace, a matter of fundamental importance for our collective security and stability. First, Algeria fully endorses the common position of the African Union on the application of international law and the use of ICTs. This common position is grounded in clear principles of international law, which form the basis of our engagement in the global mechanism. In this regard, Algeria reaffirms that international law, along with the purposes and principles enshrined in the international law, is a fundamental part of the international law. In this regard, Algeria reaffirms that international law, along with the purposes and principles enshrined in the international law, is a fundamental part of the international law, along with the purposes and principles enshrined in the international law. In this regard, Algeria reaffirms that international law, along with the purposes and principles enshrined in the international law, is a fundamental part of the international law, along with the purposes and principles enshrined in the international law. In this regard, Algeria reaffirms that international law, along with the purposes and principles enshrined in the international law, fully in cyberspace. State sovereignty, the principles of non -interference in internal affairs, non -intervention, govern the conduct of states in the cyber domain. The prohibition of the threat or use of force also fully applies to cyberspace. Both international humanitarian law and international human rights law apply offline and online. And the rules of state responsibility and due diligence are fully applicable in this context. Second, Algeria emphasizes that developing countries face unique challenges in meeting their obligation in the applicability of international law in the use of ICTs due to resource constraints and technical gaps. Algeria calls for enhanced international cooperation and concrete capacity -building measures grounded in state sovereignty, national ownership, and respect for national identified priorities. The legal framework and the development dimension are inseparable, since the effective application of international law in cyberspace requires that all states have the capacity needed to implement their obligations meaningfully and equitably. Third, on the question of the elaboration of legally binding international instruments, Algeria supports the elaboration of such an instrument. While discussions on how existing international law applies to cyberspace remain of paramount importance, we should now move towards a more focused and practical stage, collectively negotiating how states must behave in cyberspace. Of course, building on the existing relevant United Nations framework. The unique attributes of cyberspace, particularly the speed and sophistication of attacks, the difficulty of attribution, the vulnerability of critical infrastructure, and the evolving nature of cyber threats, demand legal clarity and certainty, not interpretative ambiguity. Furthermore, a legally binding international instrument would provide this global mechanism with institutional vitality, direction, and the ability to translate decades of productive discussions into meaningful and action -oriented outcomes. The technicity and the complexity of cyberspace, alongside time -consuming elaboration of legally binding instruments, are without doubt. Without any doubt. conditions to be taken into consideration, but they are certainly not insurmountable obstacles. The international community has a long -standing experience and practice in codifying norms and customary law into legally binding international instruments. This is why, since we have successfully and collectively agreed on 11 non -binding norms, we should certainly be able to elaborate legally binding rules. I thank you, Madam Chair. Muchísimas gracias. Thank you very much. I now give the floor to the African Union. Thank you, Madam Chair.
—
African Union
The African Union aligns itself with the statement of the Afghan group and welcomes the opportunity to contribute to this conversation. I thank the African Union for its contributions on the applicability of international law in the use of ICTs. The AU’s engagement on this issue is guided by the Common African Position on the Application of International Law to the Use of ICTs in Cyberspace, which represents an important milestone in strengthening Africa’s collective voice on international cyber policy. The Common African Position provides a shared co -foundation for AU member states to engage constructively in global discussions while recognizing that member states may continue to develop and articulate their own national legal positions. We are encouraged to see that this work is increasingly lucrative. Reflected at the national levels, some AU member states are already starting to develop their own national positions. These developments demonstrate that AU member states are making meaningful contributions to the evolution of state practice and the clarification of how international law applies in cyberspace. Recognizing that many member states continue to seek technical and legal expertise in this area, the AU has also promoted capacity building. The AU Commission convened a workshop from 1st to 3rd June 2026 in Addis Ababa to strengthen capacity of AU member states to develop national positions on the application of international law to cyberspace. The workshop reflected the growing demand among AU member states for practical support for the development of capacity building. The AU Commission has also promoted capacity building in understanding international law, engaging in legal analysis, and translating global consensus. into national policy. Madam Chair, these experiences demonstrate that capacity building is not only about strengthening technical capacity, but it is also including building legal, diplomatic, and institutional expertise to enable all member states to participate effectively and on an equal footing in the development and implementation of international law in cyberspace. In this regard, the AU considers that capacity building on the applicability of international law to be an important area of work for global mechanism, including within the dedicated thematic groups, which will contribute to a more inclusive informed and representative global discussion. To conclude, Madam Chair, the AU remains committed to working with regional organizations and international partners to strengthen shared understanding of international law in cyberspace and to ensure that all member states have the capacity to participate meaningfully in shaping a secure, stable, accessible and peaceful ICT environment. I thank you, Madam Chair.
—
ICRC
Muchísimas gracias, señora Presidenta. Distinguished delegates, the ICRC is grateful for the opportunity to address the global mechanism on the issue of how international law applies to the use of ICTs. As highlighted by many delegations, the use of ICTs by states and non -state actors is a reality in many of todayís armed conflicts. Against this background, the ICRC would like to emphasize three key points on international law. First, when ICT capabilities are used for military purposes in situations of armed conflicts, their use must comply with the existing rules of IHL. Many delegations have stressed this point in their statements today, as well as in national and regional positions on how international law applies to the use of ICTs. Importantly, in October 2024, the 34th International Conference of the Red Cross and Red Crescent, which brought together all states, adopted a resolution on ICT activities during armed conflict, which affirms that, and I quote, In situations of armed conflict, IHL rules and principles serve to protect civilian populations and other protected persons and objects, including, again, the risks arising from ICT activities. This should be the starting point for further discussions in this global mechanism, while recognizing that nothing in IHL can be construed as legitimizing or authorizing any act of aggression or any other use of force inconsistent with the Charter of the UN. Building on this acquis, the ICRC urges states to focus discussions on fostering common understanding on how international humanitarian law applies to the use of ICTs by states. As highlighted in our statement on threats yesterday, contemporary armed conflicts show that military ICT activities pose risks to civilian populations, to civilian infrastructure, and to civilian data. While shared understanding on the limits that IHL imposes on the use of ICTs are emerging, for instance, on the organization of ICTs, and the obligation to respect and protect medical services, states have recognized that certain questions require further discussion. In this respect, the ICRC calls on states to focus especially on the limits that IHL imposes on ICT activities that result in non -physical damage because in today’s ICT -reliant societies, it is critical to protect the ICT systems that underpin civilian life in societies as well as digital data against damage and destruction. In this respect, and as mentioned also by the joint statement delivered by Switzerland earlier, we invite you to build on the in -depth discussions held by over 100 states and other stakeholders under the ICT mainstream of the Global Initiative to Guidance for the Adolescent to International Humanitarian Law and to consider its forthcoming outcome document on upholding international humanitarian law in the use of ICTs during arms. Thank you. The document provides guidance to facilitate the implementation of IHL obligations in a manner consistent with the protective purpose of IHL. Third, with conflict dynamics and technology evolving at great speed, ICRC calls on states to focus parts of the dedicated thematic groups to how international law addresses some of these new developments and technologies. This includes, for instance, identifying legal and practical measures to implement the international law rules that prohibit child recruitment and use in hostilities, agreeing on practical measures that states must take to prevent civilian hackers from committing IHL violations through ICT activities, building shared understanding on the risks that arise when ICT infrastructure, such as civilian data centers, are used for military purposes, and identify practical measures to protect civilian ICT infrastructure from the dangers of hostilities. in addition as we have heard by several delegations the use of artificial intelligence in ICT activities may increase their speed, scale and potential for harm while IHL applies to ICT operations in armed conflict including those that involve the use of AI or other emerging technologies the ICRC calls on member states to consider whether existing international law provides sufficient safeguards against the harm that increasingly autonomous ICT capabilities can cause or whether additional limits are needed we thank you for your attention.
—
Chair Egriselda López
Thank you very much we’ve just heard our last speaker under this agenda item I thank all of the delegations for this very very substantial exchange on international law and like I did for other agenda items that we’ve dealt with I’d just like to give you a brief recap and some feedback on what we’ve just heard I thank you all for your statements, not only on a national level, but also for your joint statements made on behalf of groups. And I encourage you to engage in these interregional efforts as we engage in these discussions, especially given the limited capacity of small delegations who find it difficult to participate across the process. Now, without attempting to be exhaustive, I’d like to give you a brief summary of what we’ve just heard. So the majority of the delegations underscored that the global mechanism must continue to encourage the discussions that were begun during the first open -ended working group on the way that international law is applicable to ICTs. Further, it was reaffirmed that the development of a common understanding is fundamental if we are to establish a safe, stable and predictable digital environment. Some delegations stated that it was still necessary to continue to explore and discuss fundamental legal concepts, including, and I’m just mentioning some of them, mentioned in the room, sovereignty, non -interference, the peaceful settlements of disputes, the responsibility of states for internationally elicited acts, international humanitarian law and international human rights law, among others. I thank the delegations that shared their good practices on the elaboration of their national positions on the way to interpret the applicability of international law in cyberspace, as well as the update on previously updated positions. Finally, delegations underscored that these legal debates must be accessible to all states and that capacity building and technical cooperation based on scenarios are fundamental. Furthermore, they underscored… that these can support the work undertaken by states to develop national perspectives without losing sight of regional efforts. I’d encourage you to continue your efforts to support capacity building to facilitate these regional exchanges and also to promote dialogue between the different legal and technical communities to foster an exchange of specialised knowledge. Thank you very much. Right now, we will begin the agenda item on developing and implementing confidence building measures. You’re welcome to press the microphone button to indicate your interest in taking the floor. I would like to make an announcement also that in terms of housekeeping that the interpreters would be very grateful if you could send your statements to eStatement eStatement .com. Before you deliver your statement on the floor, as far as possible. Thank you very much. now just like I mentioned there’s no established time limit for your statements however I would be very grateful if you could kindly consider delivering a much shorter abridged version of your statement and you can send the full version of your statement to the secretariat and to the chairs team and this way we can hear from all delegations just for reference we’re going to continue to use the countdown clock that will remain visible on the screens if any of you would like to take the floor on behalf of a group of states please approach the secretariat so that we can correctly reflect that on the list of speakers finally we’d be very grateful if you could also take this moment to give us a few minutes to reflect on some of the things that we’ve been to reflect your interest in taking the floor because it’s getting close to 5 pm and it’s very likely we’ll be continuing this agenda item tomorrow so we need to have the full list of speakers we need to have the full list of all of those who want to take the floor on this agenda item this afternoon. Thank you. Now I give the floor to the Delegation of the Dominican Republic who will be speaking on behalf of a group of states.
—
The Dominican Republic
Gracias, señora Presidenta y buenas tardes. Thank you, Madam Chair, and a very good afternoon. On behalf of the open, informal, cross -regional group of the Global Mechanism Confidence Builders, over the years we have grown into one of the biggest cross -regional groups now comprising the following states. Argentina, Australia, Brazil, Canada, Chile, Colombia, Czech Republic, Fiji, Germany, Israel, Republic of Korea, Mexico, the Kingdom of the Netherlands, Singapore, Uruguay, and my own, the Dominican Republic. We welcome the adoption of and reaffirm our commitment to the eight voluntary global confidence -building measures adopted by the previous open -ended working group. These measures constitute a fundamental pillar of the framework for responsible state behavior in cyberspace. The establishment of the global mechanism now provides an important opportunity to move progressively from their endorsement towards their practical and inclusive operationalization and implementation. As a group, we recognize that the global mechanism’s plenary sessions and the meetings of the dedicated thematic working groups, DTGs, with their modalities in accordance with Annex I of the final report of the 2021 -2025 OEWG, which is the first of its kind. We provide complementary but distinct ways for states to identify areas of convergence and needs for further discussions in the area of CBM implementation. Discussions of the CBMs cannot be had in isolation. It is our view that capacity building and international cooperation are essential to enabling all states, particularly developing countries, to participate meaningfully in the implementation of global CBMs. In addition, the CBMs can support the implementation of the different pillars of the framework by strengthening communication, facilitating cooperation, increasing transparency, and helping states prevent and manage risks associated with ICT incidents. We see the DTGs as playing a particularly important role in facilitating cross -cutting integrated and policy -oriented discussions on commonly shared challenges and identifying these synergies across pillars. To this end, this group is currently preparing a working paper ahead of the December session in which we will highlight the practical value of CBMs in a comprehensive way to help states prevent and manage risks associated with ICT incidents. We will also highlight the practical value of CBMs in addressing specific policy challenges. Drawing on implementation experience at the regional and sub regional levels, the paper will present best practices and offer a comparative perspective of how CBMs are operationalized in practice. On this basis, it seeks to provide guidance on how CBMs can be integrated in DTG discussions on specific challenges, including by drawing on contributions from stakeholders in accordance with Annex I of the Final Report of the 2021-2025 OEWG. The paper is expected to be ready ahead of the December session and will be uploaded to the website accordingly. To close, this group looks forward to working with you, Madam Chair, on advancing the implementation of this pillar of the framework in a constructive, inclusive, and practical way. I thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much. I give the floor to Tonga, speaking on behalf of the Forum of Pacific Islands.
—
Tonga on behalf of the Forum of Pacific Islands
Thank you. Thank you, Chair. I have the honor to deliver this statement on behalf of the members of the Pacific Islands Forum with a presence of the United Nations, namely Australia, the Cook Islands, Fiji, Kiribati, the Federated States of Micronesia, the Republic of the Marshall Islands, Nauru, New Zealand, Palau, Papua New Guinea, Samoa, Solomon Islands, Tuvalu, Vanuatu, and my own country, Tonga. Chair, CBMs are particularly important for regions and states with limited capacity. They help build trust, reduce the risk of misperception and escalation, and create channels that can be used before, during, and after cyber incidents. For the Pacific, regional -level CBMs, such as the Pacific Cybersecurity Operational Network, are especially valuable. including third -to -third cooperation, national and regional exercises, practical incident communication procedures, and opportunities for officials and technical experts to build relationships before a crisis occurs. As with norms, our focus at this stage is the implementation of the existing CBMs. We need support to make the agreed CBMs operational in national and regional contexts. This requires capacity building, technical assistance, guidance, exercises, and sustained engagement. The global mechanism should help states use the CBMs, not simply continue to describe them. The Pacific comments the successful operationalization of the global CBMs in the region. The global points of contact, POC directory. To remain effective… it is important that this directory is actively maintained, strengthened and made genuinely useful in practice under the global mechanism, including through regular communication checks and continued support for those states that are still completing their nominations. Confidence -building measures play a critical role in building trust, and they matter most in regions such as ours with limited capacity. For a network of this kind to build trust rather than strain it, it must be used in good faith. We will welcome a shared understanding that the POC network be used proportionately, purposefully and with due regard for the capacity constraints of smaller states. Used in that spirit, the directory remains among the most valuable confidence -building tools
—
Chair Egriselda López
Thank you very much to Tonga I now give the floor to the European Union who will be followed by the following countries the Republic of Korea, Costa Rica Albania, Italy Kiribati and the United Kingdom
—
European Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San Marino
The EU, please. Chair, colleagues, I have the honour to speak on behalf of the EU and its member states. The candidate countries Turkey, North Macedonia, Montenegro, Serbia, Albania, Ukraine, the Republic of Moldova, Bosnia-Herzegovina and Georgia, and the EFTA country Norway, member of the European Economic Area, as well as San Marino, align themselves with this statement. Building trust and confidence is a long-term progressive commitment that requires the sustained and genuine engagement of states. Under the Open Internet Working Group, we have made significant progress in launching concrete initiatives to contribute to this, including the agreement of eight confidence-building measures. The measures agreed upon under the Open Internet Working Group, but also those at regional level, are crucial for deepening common understanding and building trust and confidence in the EU. prevent misunderstandings, reducing the risk of misperception and escalation, and increasing the predictability of state behavior, which ultimately will contribute to greater stability in cyberspace. The work on confidence-building measures under the global mechanism should therefore as a priority focus on the operationalization of the voluntary non-exhaustive list of CBNs as agreed under the Open Ended Working Group. Efforts should aim to encourage participation by states as well as to complement the work of regional organizations, notably the OSCE, OAS, ARF, and ECOWAS. In this regard, the global mechanism should initially focus on raising awareness and elaborating on the existing confidence-building measures, both at global and regional level, as well as to provide states and regional groups with practical tools, best practices, and examples to translate the CBNs into our national legislation, policies, and mechanisms. In this context, we welcome simulation exercises that could support the identification of practical measures in this context. The IONIS member states affirm the value of the POC directory as a CVM and as a tool to provide states with direct means of contact in situations where they do not have these means already existing. The global POC directory could facilitate engagement between states in case of cyber incidents when dealing with a lack of understanding on whom to reach out to. In this way, the POC directory could provide a complementary tool to member states’ incident response in cases where they do not have these contexts already or they don’t already have existing relationships on cybersecurity matters. To further develop the directory, the IONIS member states initially support the integration of the directory into the GSCCP, so the portal that we agreed upon. The IONIS member states initially support the integration of the directory into the GSCCP, The IONIS member states initially support the integration of the directory into the GSCCP, so the portal that we agreed upon. The IONIS member states initially support the integration of the directory into the GSCCP, so the portal that we agreed upon. The IONIS member states initially support the integration of the directory into the GSCCP, so the portal that we agreed upon. global mechanism. And we’re also open to exploring further development of the directory, however, based on lessons learned from its use. We consider it important, however, to avoid duplication of efforts with existing networks of POCs and with existing regional and bilateral relations. We stress that the POC directory is a tool that can be useful when other means are lacking, but which should not replace existing cooperation efforts or established means of context between states. In addition to the voluntary POC directory, the EU and its member states support the operationalization of the other eight CBMs. And the plenary and the DDGs could facilitate this work, for instance, by sharing national ICT strategies, policies, legislation, concept papers, best practices on a voluntary basis under DTG 1 in line with CBM 3. and in our exchanges on protection of critical infrastructure, in line with CBM -7. We could also promote the information exchange on cooperation and partnerships between states to strengthen ICT security capacity and enable CBM implementation, which is in line with CBM -5. And intersessionally and in the margins of our sessions, as well as part of our capacity -building efforts, we could organize regular seminars, workshops, and training programs on ICT security in line with CBM -6. The global mechanism discussions will enable us to take forward the achievements on the CBMs under the Open End Working Group, further outlining their value in presenting cyber incidents and in building trust, transparency, and stability in cyberspace. We could also incorporate them into our regional and national practices as co -operatives. We could also incorporate complementary tools to the application of international law and norms of responsible state behavior in cyberspace. And we look forward to working with you Thank you very much.
—
Republic of Korea
Thank you, Madam Chair. As technology continues to advance, cyber threats are growing in both scale and sophistication, and such threats have the potential to undermine trust among states. In this context, confidence -building measures are essential to enhance predictability and stability in cyberspace and to prevent misunderstanding and miscalculation among states. Strengthening confidence -building measures at the international level is also indispensable to enhancing resilience in cyberspace. Just as the open -ended working group itself served as an important confidence -building measure by fostering dialogue and transparency among states, we expect the global mechanism to play a similar role in promoting trust, transparency, and sustained cooperation. The Republic of Korea believes that establishment of the UN Global Mechanism Point of Contact Directory to be one of the most significant achievements of the OEWG. The directory has the potential to strengthen confidence among states by facilitating timely and effective communication during cyber incidents and crises. We therefore look forward to the continued operation of the POC directory, including regular exercise and capacity -building activities under the global mechanism. At the same time, the UN POC directory is intended to be used on a voluntary basis by member states and should not be misused or exploited for purposes inconsistent with its original intent. The POC directory should be used responsibly and in good faith, consistent with its purpose of facilitating cooperation, and effective communication among member states. Additionally, we reaffirm our strong support for the joint statement delivered by the Dominican Republic. The Republic of Korea looks forward to actively participating in these efforts to further strengthen discussions on confidence -building measures under the global mechanism. In particular, we believe the experiences and the best practices of regional organizations that have successfully implemented confidence -building measures can provide valuable guidance for developing effective confidence -building measures at the global level as well. I thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Costa Rica, followed by Albania.
—
Costa Rica
Madam Chair, Costa Rica considers confidence -building measures to be an essential element of stability in cyberspace, not only because they reduce the risk of escalation, in conflicts between states, but also because they foster cooperation among them. First, confidence -building measures should be understood as practical preventive tools achieved through the creation of known, accessible and functional communication channels prior to the onset of a crisis. To this end, Costa Rica supports the voluntary exchange of information, communication protocols for incidents and regional exercises and simulations that strengthen collective preparedness. Second, Costa Rica highlights the utility of the Global Directory at points of contact. This instrument is a valuable operational tool for facilitating urgent communication, managing cross -border incidents, reducing misunderstandings and preventing escalation in the event of conflict. To fulfil this function, it must be kept up -to -date, tested periodically and integrated with actual national capabilities, including computer security incident response. To ensure that the system is fully operational, it must be equipped with the necessary equipment, equipment and equipment to ensure that the system is fully operational. To ensure that the system is fully operational, it must be equipped with the necessary equipment, equipment and equipment to ensure that the system is fully operational. To ensure that the system is fully operational, it must be equipped with the necessary equipment, equipment and equipment to ensure that the system is fully operational. To ensure that the system is fully operational, it must be equipped with the necessary equipment, equipment and equipment to ensure that the system is fully operational. To ensure that the system is fully operational, it must be equipped with the necessary equipment, equipment and equipment to ensure that the system is fully operational. Third, legal transparency also serves as a confidence -building measure. National positions regarding international law in cyberspace provide insight into how states interpret principles such as sovereignty, non-intervention, due diligence, attribution, the use of force, international humanitarian law, and human rights. By publishing its national position on the application of international law in cyberspace, Costa Rica states its conviction that this type of transparency helps reduce uncertainty, strengthen shared expectations, and facilitate dialogue among states. Finally, building trust in cyberspace requires linking law, technology, and diplomacy. Attribution, evidence, incidents, response, and crisis communication are simultaneously legal, technical, and political matters. Therefore, the global mechanism must promote forums for exchange among diplomats, legal advisors, technical experts, CSIRTs, the private sector, the CIS. Madam Chair, Costa Rica hopes that this mechanism will foster concrete, inclusive and results-oriented confidence-building measures Greater communication, transparency and cooperation mean reduced risks in cyberspace enhanced security for people and essential services and greater international stability I thank you
—
Chair Egriselda López
Thank you. I give the floor now to Albania, who will be followed by Italy.
—
Albania
Thank you, Madam Chair. Albania aligns itself with the EU statement on this item and wishes to add the following on its national capacity. As a country which continues to face persistent malicious cyber activities against its critical infrastructure, we know firsthand the trust between countries, and states built through practical cooperation is what determines how quickly and effectively we can respond when an incident occurs. Confidence -building measures remain for Albania one of the most concrete and immediate useful outcomes of this process. Albania’s approach to CBMs rests on cooperation across several layers, political, diplomatic and technical, through the UN, European Union, OSCE, ITU, Western Balkan, First Trusted Introducer and numerous other countries’ organizations which we work on bilateral relations, each of those cooperation reinforcing each other. At the United Nations level, Albania has appointed its point of contact at the Global Point of Contact Directory and continues to support its further operationalization as a practical tool that turns confidence into concrete communication channels in time of crisis. We also value highly the Women in Cyber Fellowship, which we consider a confident building measures in itself, having brought valuable perspectives and a more resilient cyberspace. With the support of the Netherlands, Germany, previously from the United States, we have been present and part of these discussions in the UN since 2022, and now at the global mechanism we are present with a bigger delegation, diplomatic and technical. Participation on those meetings have not only increased our confidence and understanding on the cyberspace, but we understood that Albania has taken the necessary steps forward. We have learned from experience of other countries, but also given contribution to share our own experiences. With the European Union, Albania as a candidate country for membership is progressively aligning with the EU Cyber Security Aki. including through the transposition of all the NISTU directive into national laws, sub -laws and numerous procedures, and benefiting from the EU support programs, then strengthen operational cooperation and information sharing among Western Balkan cybersecurity diplomatic and technical bodies. Through the OSCE, Albania actively participates in the informal working group on cyber CBMs, regularly reporting and implementation of CBM 8 and 15, working particularly on the protection of critical information infrastructure and the exchange of national points of contact. With ITU, Albania engages in joint project training dialogues that strengthen the international cooperation and communication between the EU and the European Union. We also strengthen collective security while using many resources of ITU in cooperating with other countries. At the regional level, Albania has invested significantly in building trust among Western Balkan states and beyond. This includes initiatives such as the Adriatic Five meetings, the Western Balkan Policy Roundtable, supported from the Dutch government, the Western Balkan Cyber Dialogue, supported from DICAF, technical workshops supported by UNDP, and numerous training and conferences organized with the WB3C centers. Albania has also launched programs such as Western Balkan Cyber Camps, alumni events for participants. And it’s preparing for the next regional cyber marathon now under development. These projects bring together young cyber professionals from across the region and help build the professional and institutional relationship on which CBMs ultimately depend. Albania also seeks new and less conventional partnership because we believe that international relations always leave room for deeper cooperation and confidence building. For example, just yesterday, we became as the newest member of the International Coalition on Cybersecurity Workforce, joining United Kingdom, Canada, United Arab Emirates, Ghana, Japan, Singapore, and Nigeria. For Albania, these different frameworks are not parallel tracks, but a single one, mutually reinforcing all the efforts we are doing in cybersecurity. Cooperation with all those frameworks, together with our regional partnership, have directly strengthened our national capacities. And it is this increase of capacities that, in turn, allow us to be a more reliable and predictable partner for the others. This is, in Albania’s view, exactly how confident building is meant to work, cooperation building capacity, capacity building trust, and trust builds still back cooperation among the countries. Albania, therefore, reiterates its support for the integration of CBMs across the work of the global mechanism and stands ready to share its national experience with the other states, particularly on the operationalization of points of contact, information sharing arrangements, and joint training and exercises. At the end of the day, it’s important to know who do we call, who we trust, and where we turn for the support in a moment of difficulty when we have a big cyber attack. This is why confidence building sustained through cooperation at every level, global, regional, bilateral, remains for Albania central to the European Union. to a more stable, secure, and predictable cyberspace. Thank you, Madam Chair.
—
Chair Egriselda López
Muchísimas gracias. Thank you very much. I give the floor to the delegation of Italy, followed by Kiribati, the United Kingdom, Papua
—
Italy
Italy fully aligns itself with the statement delivered by the European Union and wishes to add a few considerations from its national perspective, also benefiting from contributions of the four stakeholders objected by the Russian Federation. In an environment where cyber threats increasingly transcend national borders, CBMs remain an essential tool to strengthen trust, transparency, and cooperation among states. Reducing risks of misunderstanding contributes to preventing escalation and supporting stability in the use of ICTs. The initial list of voluntary global confidence -building measures contained in Annex B to the third OEWG annual progress report was a very useful tool, and we hope that this global mechanism will take that in due consideration for its future works. Regarding the implementation of the UN confidence -building measures, I would like to briefly share that Italy has nominated since the very beginning its POCs for the global directory. We keep exchanging views on ICT matters at bilateral and multilateral level. We regularly share concept papers, national strategies, policies, and programs, as well as information on ICT institutions and structures, for example, through advisories, alerts, reports of our national cybersecurity agency. We promote and support capacity -building projects. We organize workshops and seminars with a whole -society approach. We contribute to the EU policies regarding the protection of critical infrastructure and critical information infrastructure. We actively promote opportunities for public -private partnership at national and multilateral level. But more work has to be done, and we are committed to continue on this path. We also would like to emphasize the particular importance of regional confidence -building measures. For instance, those developed by the OSCE, which we regard as highly effective. Among the others, Italy actively contributes to CBM -8 on points of contacts and CBM -14 fostering public -private partnerships to address shared cybersecurity challenges. Italy underscores the private sector’s pivotal role in enhancing resilience and addressing multifaceted cyber threats. We are committed to ensuring that the EU and the EU -CBN partnership recognize the importance of cross -regional collaboration to enhance CBM. By integrating lessons learned from diverse frameworks and sharing experiences, Italy is committed to contribute to a more adaptable and comprehensive approach to trust building in cyberspace. Existing experiences demonstrate the value of multinational cyber exercises, cyber ranges, crisis management simulations, and structured information sharing mechanisms involving governments, critical infrastructure operators, industry, academia, and research organizations. Developing common operational playbooks and trusted networks before crises occur can strengthen collective preparedness and coordinated response capabilities. The involvement of technical stakeholders in all these activities and exchanges can significantly enhance the effectiveness of these measures by providing practical expertise and facilitating cooperation. And incorporating cooperation across sectors. This is why, once again, DTGs can play a crucial role also in this area. DTG 1 can discuss how to apply CBMs in a specific situation or scenario, whereas DTG 2 can craft tailored projects to build capacity. Italy always stands ready to share its experiences, lessons learned, and proposals in implementing CBMs. Thank you.
—
Chair Egriselda López
Thank you very much. Thank you very much. I give the floor now to the delegation of Kiribati.
—
Kiribati
Thank you, Madam Chair. Kiribati aligns itself with the statement delivered by the Kingdom of Tonga on behalf of the Pacific Islands Forum members and adds the following in its national capacity. Madam Chair, if this first session is to set a pattern for all that follow, confidence building is where this mechanism can show its value soonest. For small island developing states like Kiribati, CBMs are among the most immediately practical elements of the framework of responsible state behavior. We do not maintain extensive networks of bilateral channels or cyber attachés. Predictable, trusted mechanisms for communication between states are, for us, not a convenience. They are the difference between facing an incident alone and facing it with help. For this reason, Kiribati attaches great importance to the global point of contact directory. We commend the Secretariat and UNODA for its establishment and operationalization, and Kiribati is working to finalize its own participation. We encourage… We encourage continued practical support for its use. so that the directory works as intended in the real incident and not only on paper. And we would gently encourage all states to use the network in the cooperative incident -related spirit for which it was designed, mindful that for a small administration, every message received draws on the same small team that defends our networks. It works. We were encouraged to hear earlier this week offers of assistance extended to states such as ours. We value such offers greatly. They are a reminder of what these gatherings are truly for. This plenary is not only where we discuss confidence building in the abstract. It is where confidence is built, where a small state like Kiribati can meet the partners it may one day need to call upon and where offers of assistance are made and remembered. For states like ours, that is among the most valuable things this mechanism can offer. Madam Chair, the Pacific experience is that confidence is built through practice, not declarations. Our region has been doing this work for years. Through the Pacific Cybersecurity Operational Network, PAXEN, our incident -responsive shared threat information and built the personal trust on which crisis communication ultimately depends. KITIVS was proud to host a recent PAXEN gathering, bringing our region’s cybersecurity professionals together to train, share, and strengthen the relationships that make PAXEN possible. We make cooperation work when an incident strikes. Through Cyber Safety Pacifica and other regional programs, our law enforcement agencies cooperate daily. And under the Boyer Declaration, Pacific Islands Forum members have recognized cybersecurity within our expanded concept of security, giving regional political packing to this practical cooperation. We draw two lessons from this experience that we believe are relevant globally. First, CBMs succeed when they are simple, sustained, and relationship -based. Their ambition should be measured in reliability, not in the number of measures adopted. Second, regional organizations are not merely implementers of globally agreed CBMs. They are laboratories for them. These mechanisms should draw substance. systematically on regional experience, including through regular exchanges with regional parties, and should help connect regional networks, such as Paxson, with their counterparts in other regions, so that what works in one part of the world does not have to be discovered anew in every other. KIDVS therefore encourages the mechanism to keep its works on CBMs firmly practical, strengthening the directory, supporting exercises and communication checks, ensuring designated points of contact receive the training their role demands, and enabling hybrid participation so that officials from capitals as distant as Tarawa in KIDVS can take part meaningfully. Confidence, Madam Chair, is our region’s currency. From this perspective, from this first session, it has begun to invest in this mechanism and to return
—
Chair Egriselda López
Thank you very much Kiribati I now give the floor to the United Kingdom followed by Papua New Guinea
—
United Kingdom
Thank you Chair The United Kingdom supports the identification of concrete action -oriented ways to implement the UN framework on responsible state behaviour in cyberspace including through confidence -building measures As recognised in previous consensus reports confidence -building measures can contribute to preventing conflicts, avoiding misperception and misunderstandings and the reduction of tensions The UN point of contact directory is a positive practical example of a CBM emerging from the 2021 -25 OEWG as Kiribati has just outlined so clearly According to OEWG and GG consensus reports the directory’s purpose is to provide a way to facilitate secure and direct communications between states to prevent and address serious ICT incidents through a network of points of contact that could be reached in times of urgency it complements a range of formal and informal networks that exist to share information on cyber incidents if a state detects malicious cyber activity emerging from another state they may choose to use the POC directory or other cert -to -cert networks if they feel this will help to address the incident equally, they may decide that using the POC directory is not an appropriate response if it is clear that the malicious cyber activity is part of a deliberate state -sponsored campaign the existence of the POC directory doesn’t alter a state’s right to attribute irresponsible cyber behaviour to another state if they wish to do so. Thank you, Chair
—
Chair Egriselda López
Thank you very much I give the floor now to Papa Papua New Guinea, followed by Canada and Serbia.
—
Papua New Guinea
Madam Chair, Excellencies and Distinguished Delegates, at the outset, Papua New Guinea congratulates Madam Chair and your Distinguished Delegation of El Salvador on your important mandate and for the laudable leadership in guiding this process. This comes immediately on the heels of the recently highly successful and landmark inaugural Global AI Governance Dialogue in Geneva, whose process, Madam Chair, you so aptly also co-chaired with the Distinguished Delegation of Estonia. Be rest assured of Papua New Guinea’s trust and confidence in you, Madam Chair, and also our constructive support and best wishes. Let me also take this opportunity to pay special tribute to the Distinguished Delegation of Singapore for the sterling role and leadership in setting the stage through the OEWG process that has brought us to this stage. Madam Chair, Papua New Guinea aligns with the statement delivered on behalf of the Pacific Islands Forum by the Distinguished Delegation of Tonga, and we would like to make additional points in our national capacity. The welcome robust exchanges so far in this meeting is a clear statement to the high importance we all place on this critical agenda. For Papua New Guinea, information and communication technology is one of the 12 core national development strategic priorities under our current medium-term development plan 4. This week in Papua New Guinea, leaders from government, industry, international partners have convened for the Pacific Regional Digital Transformation Summit and the Pacific Cyber Week to consider how digital technologies are shaping our shared future. We recognize a fundamental and clear message in this domain. That is, digital transformation can only succeed when people, governments, businesses, and other stakeholders have confidence and trust that the digital environment is safe, secure, and reliable. As Papua New Guinea recently highlighted during the Global AI, Dialogue on AI Governance, digital technologies must remain human-centered. and serve as an enabler of sustainable development. Building trust and confidence in cyberspace is therefore fundamental to ensuring that all countries can harness the opportunities of digital transformation while safeguarding international peace and security. For us, such confidence is built through trusted relationships, open communication, and practical cooperation. It also depends on countries having the capacity to prevent, detect, and respond to cyber incidents, protect critical infrastructure, and maintain essential services during times of disruption. Madam Chair, Papua New Guinea believes that global mechanisms should help countries strengthen the core capabilities needed to manage cyber risk. This includes strengthening cyber hygiene, national incident response, C-Certs and CERTs, legal and regulatory, and the like. The policy frameworks and the skills required by officials, technical experts, regulators, law enforcement agencies, and critical infrastructure operators. These practical investments strengthen resilience and deepen trust between states. Importantly, in our view, capacity building for this sector is critical. It should be demand-driven, nationally owned, and responsive to each country’s level of digital maturity. For developing countries, particularly small island developing states, including my own country, Papua New Guinea, strengthening institutional and technical capacities remains pivotal to implementing the agreed framework for responsible state behavior in cyberspace. Confidence-building measures should likewise produce practical outcomes. Regular communication between national point of contact, timely information sharing, joint cyber exercises, technical cooperation, and the exchange of lessons learned can be a key factor in the development of a sustainable, and help countries prepare for cyber incidents before they occur. These partnerships build trust, reduce misunderstandings, and strengthen regional and international cooperation. Madam Chair, the Pacific Regional Discussion taking place this week in Papua New Guinea also reminds us that cybersecurity is not only a technical method. It is a foundation for economic growth, digital trade, investment, innovation, and public confidence in digital services. As more countries expand digital government and digital economies, strengthening cyber resilience becomes a shared responsibility. The rapid advancement of emerging technologies, including AI, further reinforces the importance of resilient cyber ecosystem and international cooperation that must keep pace with technological change. We must ensure that technological progress narrows, not widens the digital divide. enabling all states to participate safely, securely and meaningfully in the global digital economy. In this context, Papua New Guinea would like to acknowledge the support of its development partners such as UNIDIR and the delegation of Australia for the continuing gender -sensitive capacity -building support including this meeting for our representatives’ participation and that of other female representation in the Pacific region. This is of added value and most welcome with gratitude. Papua New Guinea believes partnership in the ICT domain must be based on respect for international law and each country’s national sovereignty and territorial integrity. Madam Chair, to conclude, we encourage the global mechanism and its dedicated sematic groups to remain focused on implementation. Success should be measured by concrete progress, stronger national systems and the development of the global digital economy. More effective international partnership and cooperation between countries and targeted support that enable all states, particularly developing countries and small island states, to shape, own, and drive the national engagement in the digital domain in a safe, secure, and trustworthy environment. Papua New Guinea is committed to do its part in implementing the UN Framework for Responsible State Behavior in Cyberspace, including its five pillars.
—
Chair Egriselda López
Thank you. Muchísimas gracias. Thank you very much. I now give the floor to Canada, followed by Serbia and South Africa.
—
Canada
Merci, Madame la Présidente. Thank you, Madam Chair. As mentioned earlier this week, we recently published the responses of Canada to the survey managed by UNIDIR on the implementation of norms, international law, confidence -building measures, and capacity building. This is an example of the concrete practice of the CBM -3 on information sharing. The survey is available on the website of Canada within the UNIDIR cyber portal. By making this information public and easily accessible, Canada is demonstrating transparency with regard to certain practices that could inspire others. Madam Chair, we take note of the efforts of the Secretariat to build up the capacity of states to use the Global Contact Points Directory. The Directory has the main goal of facilitating communication during significant or urgent incidents, and this is laid out in its mandate as reflected in paragraph 5 of Annex A of the Annual Report 2022. Canada welcomed the information session on the Global Directory organized by the Secretariat on June 26. We support the holding of a second simulation exercise in the fall, which will… will help to reduce the risk of misunderstanding or escalation during significant or urgent incidents. In addition, and to give you an example of the practice of other CBMs, we note that Canada is organizing and taking part in seminars, webinars, and side events as planned for CBM 6. For example, since March alone, Canada has taken part in a webinar organized by Let’s Talk Cyber on the outcomes of the OEWG and the future of the GMAC, a webinar organized by EU Cyber Direct on trans -regional collaboration of stakeholders, the Cyber Diplomacy School of Talent, as well as the UNIDIR conference on cyber stability. Madam Chair, allow me to speak for a moment about soccer, or football, as it’s called in the rest of the world. Another practice of operationalizing the CBMs would be exercises involving simulation, or rather technology. Tabletop exercises. And it’s one of the host countries of the FIFA World Cup. Cup, we organized these tabletop exercises with cities that were hosting matches as well as critical infrastructure operators. We also collaborated with Mexico, Execon, and U .S. CERTs by helping to coordinate relevant information sharing. These are the practices that we can talk about during the DTGs that will take place in December. Confidence -building measures are a bit like sportsmanship and soccer. They foster healthy communication between players playing in good faith, whether they come from cyber agencies, ministries of foreign affairs, or non-governmental stakeholders. Thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much. I give the floor to the delegation of Serbia.
—
Serbia
Thank you, Madam Chair. The Republic of Serbia aligned itself with the EU’s statement. Allow me to add just a few remarks from the national perspective. In an environment of heightened tension, confidence -building measures are among the most valuable instruments at our disposal. Practical, voluntary, non -politicized tools that enhance transparency and predictability and reduce the risk that an ICT incident is misperceived and escalates. CBMs allow states with different perspectives to cooperate directly. And Serbia sees this area as one where the mechanism can deliver visible results quickly. Serbia welcomes the operationalization of the Global Points of Contact Directory as a concrete, universal confidence -building measure. We designated both diplomatic and technical points of contact. And we believe that regular communication checks, PINCS exercises, and scenario -based simulation exercises will keep the ICT system in place. The directory allowed and genuinely useful in a crisis. Serbia also draws on its regional experience As a participating state of the OSCE we are actively contributing to the development and implementation of the Cyber ICT security confidence building measures including by sponsoring CBM -9 on national terminologies and definitions in the field of information security This experience demonstrates the value of practical cooperation aimed at improving mutual understanding and reducing the risk of
—
Chair Egriselda López
Thank you very much I give the floor to the delegation of South Africa who will be followed by Singapore, Nauru, Switzerland, Vanuatu and Chile South Africa please
—
South Africa
Thank you Chairperson We recognize that the adoption of the third annual program is a significant step towards the development of the cyber security We are committed to ensuring that the cyber security system is a key part of the security and security of the entire country is a key part of the security and security of the entire country is a key part of the security and security of the entire country is a key part of the security and security of the entire country is a key part of the security and security of the entire country We are committed to ensuring that the cyber security system in which member states agreed to establish this global mechanism on security of and in the use of information communications technologies was an important confidence -building measure. The final report of the OEWG recommended that states should continue discussions on the development and implementation of CBMs in the GM. It has been critical that member states have a forum to discuss the rapid development of technology in the United Nations and to address matters related to the responsible behavior of states in the use of ICTs. Member states can support and facilitate full operationalization of the eight global CBMs through international cooperation at a UN regional and sub -regional level. This support could take the form of workshops and roundtable discussions to share experiences and expertise, engage in dialogue, dialogue twice, and identify some of the non -contentious areas and move to more sensitive ones as we continue to build layers of understandings and trust between states. Chairperson, the increasing participation by member states in the Global Points of Contact Directory is another CBM. We believe that by narrowing the capacity gap through capacity -building programs, the goal of achieving maximum participation in the Global POC Directory is attainable. Member states are encouraged to share success stories from assistance received through interaction with the Global POCs during a cyber incident. We regard the POC Directory as a first step to greater cooperation between states on identifying and responding to threats to ICT security. The eight voluntary CBMs adopted by the OEWG in its third APR are simple steps that member states take every day to a greater or lesser degree. CBM 1 requests that member states nominate Points of Contact for the Global POC Directory. CBM 2 requests that Member States continue exchanging views and undertaking bilateral, sub -regional, regional and cross -regional and multilateral dialogues and consultations CBM 8 requests that States strengthen public -private partnerships on ICT security It is a sign of Member States’ commitment that several CBMs are already being undertaken by many delegations at the national level Further discussion on all eight CBMs could take place in the DTGs at appropriate intervals Chairperson, capacity -building initiatives have also brought Member States together at the UN and achieved consensus in a difficult geopolitical context Our delegation believes that the proposal for a global cybersecurity cooperation and capacity -building portal linked to the work of the global mechanism should be further elaborated on the dedicated thematic in the DTGs and the dedicated thematic group meetings in December 2026 The proposed voluntary fund to support participation of developing countries in the global mechanism and capacity building is also a CBM. In this regard, we support the continuation of the UNIGA Women in International Security and Cyberspace Fellowship, which has created a support system for delegations, regardless of their affiliations with the Global North or the Global South. I thank you.
—
Singapore
Thank you, Madam Chair. Singapore believes that one of the key needs in this global mechanism is for states which are already implementing CBMs to share best practices, the potential pitfalls in implementations, and the ways around them. Madam Chair, like cybersecurity, CBMs are a team effort. They are not a concept that can be practiced in isolation, by one state alone. CBMs are a team effort. Having the respective CBMs as a concept is a good start, but we need to work towards actionable efforts towards their implementation. We need to deepen efforts to collectively enhance one another’s capacity to implement these measures. Regional organizations are very important to this cause. Different regions have different ways of implementing CBMs. DTG 1 should consider how we can involve regional organizations to share the experiences that could be useful from a cross -regional perspective. Madam Chair, we are also pleased to see the efforts to ensure that a global intergovernmental points of contact directory remains a useful and effective initiative for all UN member states. The POC’s directory is an important addition to the other existing channels that can be leveraged by states to reach out to each other in the event of a situation. The POC’s directory is an important addition to the other existing channels that can be leveraged by states to reach out to each other in the event of a situation. The POC’s directory is an important addition to the other existing channels that can be leveraged by states to reach out to each other in the event of a situation. The POC’s directory is an important addition to the other existing channels that can be leveraged by states to reach out to each other in the event of a situation. The POC’s directory is an important addition to the other existing channels that can be leveraged by states to reach out to each other in the event of a situation. The POC’s directory is an important addition to the other existing channels that can be leveraged by states to reach out to each other in the event of a situation. The POC’s directory is an important addition to the other existing channels that can be leveraged by states to reach out to each other in the event of a situation. and may require capacity building at the national level to implement processes to allow for the effective operationalization of the directory. In this regard, it would be important to allow for the POC’s directory to be used in a flexible way so that states may use it as needed before we develop more standard templates and procedures for its use. As such, we support UNODIS ongoing efforts to operationalize the use of the POC directory to capacity building initiatives, simulation exercises, and engagement with regional mechanisms to promote interoperability and the sharing of best practices. The feedback from these activities can then be collated to form the basis for the further refining of the directory. Singapore has participated in the PING tests conducted and will continue to do so to ensure that the directory remains a practical tool and relevant initiative for our continued cooperation. Thank you, Madam Chair.
—
Naoero
Thank you, Madam Chair. NARO speaks in alignment with the statement delivered on behalf of the Pacific Islands Forum members with regards to CBNs. We offer our national statement as follows. In NARO, the people responsible for our cybersecurity, our diplomacy, and our digital policy are often one and the same within our public service. This is not a complaint. Rather, this is our context. Where measures for transparency and communication are built, the consideration for us is how can administrations like ours use them? Measures can assume large bureaucracies as well as small ones. To be so, they have to be, without exception, inclusive by design. Our intention is not at all to slow down the progress of any state. but to be confident in moving forward from where we are. It is precisely because we are small that CBMs matter so much to NARO. In a serious ICT incident, a small state’s response begins with a question. Who do we call? The Global Point of Contact Directory exists to answer that question, and NARO values it accordingly. We are committed to registering to the POC and playing our full part in the directory. We support the continuing program of capacity building for states to make full use of it. Thank you to UNODA for steering us. We also see value in states sharing their national frameworks and legislative developments through this mechanism. Openness about how each of us organizes our cyber governance is itself a confidence-building measure, and one NATO is applying through the reform that our government is undergoing, as alluded to in previous statements. Madam Chair, in a few days’ time, NATO will assume the chairmanship of the Pacific Cyber Security Operational Network, PACSON, for the coming year. We are proud to take on this responsibility. And we do so with purpose. Paxon connects the incident responders of our region in working-level cooperation, week in and week out, and it has shown NADO that trust between technical teams is built through routine contact long before a crisis makes it necessary. As incoming chair, NADO intends to bring that regional experience to bear here. We will work to strengthen the connection between the Pacific’s operational cooperation and the global measure this mechanism develops so that each informs the other. We invite other regions and the mechanism itself to engage with us in that spirit during our chairmanship. Our priorities for this pillar follow from all of the above. Keep the directory practical and exercised. Invest in the training of designated officials whose competence is what the measures ultimately rest on. Draw deliberately on regional networks as sources of tested practice. I thank you.
—
Chair Egriselda López
Thank you very much and I wish you every success in the role that you’ll be assuming soon We don’t have long left so we’re not going to be able to finish our list of speakers this afternoon I’ll give the floor to Switzerland and if we have enough time I’ll give it to Vanuatu after Switzerland otherwise Vanuatu will be the first speaker tomorrow morning Switzerland please
—
Switzerland
Switzerland recognizes the importance of confidence -building measures as an essential part of the UN framework for responsible state behavior in cyberspace such measures help to reduce the risk of misunderstandings misperceptions and unintended escalations arising from the use of ICTs they promote transparency, predictability and cooperation between states thereby strengthening international peace and security our dependence on digital technologies grows so does the importance of implementing practical measures to foster trust and resilience Switzerland would like to emphasize that the challenge is not to develop new confidence -building measures but to implement those that have already been agreed effectively the eight initial CBMs developed at the Open Ended Working Group are the first to be implemented in the UN and the first to be implemented in the EU and the first to be implemented in the EU and the first to be implemented in the EU and the first to be implemented in the EU and the first to be implemented in the EU and the first to be implemented in the EU Our efforts should therefore focus on translating these commitments into practice, sharing experiences and identifying both implementation gaps and good practices. DGT1 is particularly well suited to this task. This will take time and is an ongoing process, as our experience at the OSC shows. In this regard, regional and sub -regional organizations play a particularly important role. They are well placed to promote dialogue among neighboring states, facilitate capacity building, develop practical implementation guidance and adapt confidence -building measures to regional contexts while remaining firmly anchored in the global UN framework. We would like to refer to the non -papers submitted to the Open -Ended Working Group in June 2025 on the role of regional organizations in implementing the UN Framework for Responsible State Behavior and Cybersecurity. Thank you. One of its key recommendations is the establishment of a structured exchange between the global mechanism and regional and sub -regional organizations. This would enable lessons learned to be shared, promote coherence across regions, avoid duplication of efforts, and strengthen the implementation of the framework at all levels. Switzerland believes that the global mechanism should serve as both a forum for dialogue among states and a platform connecting regional implementation efforts, facilitating the exchange of best practices, and supporting the dissemination of successful confidence -building initiatives. I witnessed such an exchange in June this year at the meeting organized by the OSCE with German support and saw the added value it brought between regional organizations. We also wish to emphasize the value of voluntary transparency measures, including designating national points of contact, exchanging information on national implementation, and cooperation through exercises and information sharing. These measures strengthen communication channels prior to incidents and foster the trust essential for effective crisis prevention and management Chair, confidence -building measures must remain closely linked to the other pillars of the UN Framework Implementing them supports the application of agreed norms of responsible state behavior contributes to capacity building and facilitates a common understanding of how international law applies in cyberspace During the discussion on threats and norms Switzerland and many other delegations emphasized the importance of protecting critical infrastructure States therefore are encouraged to continue raising awareness on the importance of critical infrastructure protection when implementing CBMs promoting information sharing among critical infrastructure stakeholders and sharing of good practices and guidance Doing so will help implementing norms 13f, g and h Finally, we are looking forward to the paper announced by the Cross -Regional Council on the Protection of Critical Infrastructure and the International Group on CBMs and thank them for their engagement Chair, Switzerland is committed to constructive cooperation with all delegations to ensure that confidence -building measures are practical, inclusive and oriented towards implementation. Strengthening cooperation at global, regional and national levels can further reinforce trust, stability and security in cyberspace for all. I thank you.
—
Chair Egriselda López
Thank you very much. OK, I’ll take it that we’ve run out of time for this afternoon. I still have 18 requests on my list to take the floor on confidence -building measures on this item. So we’ll hear from all of those delegations tomorrow. And just like I said, once we finish this agenda item, we’ll move on
The knowledge base confirms that Egriselda López of El Salvador serves as Chair of the Global Mechanism on ICTs in the Context of International Security, and that the first substantive plenary session opened at UN Headquarters in New York [S129]. Her role as Chair is also confirmed in the organisational session records [S2].
2
The knowledge base references dedicated stakeholder sessions with accredited organisations participating [S19] and [S63], and confirms the existence of a stakeholder segment within these plenary meetings, though the specific figure of fourteen organisations and the four-minute allocation are not directly corroborated or contradicted.
3
The knowledge base notes concerns about the lack of transparency and clarity in the process for non-state actors to contribute, and identifies this as a barrier to meaningful engagement [S202]. This provides supporting context for the report’s claim that stakeholders raised objections to exclusion from formal participation.
4
The knowledge base references the UN Major Group for Children and Youth as a recognised constituency giving statements at UN forums [S234], but does not provide the specific figure of 20,000 distinct youth organisations, so this statistic cannot be confirmed or corrected from the available sources.
5
The knowledge base does not directly reference General Comment No. 25 of the Committee on the Rights of the Child. No confirmation or contradiction is available from the provided sources.
6
The knowledge base does not contain specific information about the UNIDIR Women in International Security and Cyberspace Fellowship. The United Nations Youth Delegate Programme, which facilitates youth representation in Member State delegations, is referenced as a related mechanism [S232], providing some contextual parallel but not direct confirmation.
7
The knowledge base references the importance of youth engagement in policy and decision-making processes [S232] and [S233], and notes the Summit of the Future process as an opportunity to involve youth voices [S135]. However, Security Council Resolution 2250 and the Youth Peace and Security Agenda are not directly referenced in the knowledge base sources.
8
The knowledge base confirms that CBM discussions were a substantive agenda item in these plenary sessions [S131] and [S157], and a similar procedural situation – where the Chair noted a large number of delegations remaining on the speakers’ list with limited time – is documented in the 2nd meeting of the plenary session [S156], providing contextual parallel for this type of procedural outcome.
Adoption of the agenda and organization of work— In summary, the Republic of Korea emerges as a supportive and engaged advocate for regulations that align closely with international human rights standards and the objectives of SDG 16, underscoring the importance of lea…
Closing Ceremony and Orientation for WAIGF 2025— – Kinyo Sawaboke: Communications Officer at National Information Technology Development Agency Audience: Good evening everyone. I am Abdul Idris, a Nigerian. I’m a program analyst from National Assembly Service. Thank y…
4th meeting – Plenary Session— Civil society actors such as the Kenya ICT Action Network urged ‘meaningful multi-stakeholder participation, because civil society acts as frontline defenders who monitor local harms and support victims on the ground’. T…
Adoption of the agenda and organization of work— Japan has actively engaged in the convention negotiation process, demonstrating a steadfast commitment to fostering an inclusive, transparent, and fair environment. This positive approach is reflected in Japan’s recent a…
Ad Hoc Consultation: Wednesday 31st January, Afternoon session— Overall, Japan appears to be a supportive and cooperative entity in international policy discussions, engaging constructively with various international proposals. Lack of specifics about the proposals, Japan’s reasons f…
Ad Hoc Consultation: Monday 5th February, Afternoon session— This careful attention to detail ensures a balance between national caution and international cooperation, reflecting Japan’s role as a conscientious and considered actor on the world stage. The summary accurately reflec…
Framework Agreement of the Pacific Alliance— (4) Value Added Services are not those services in which for their establishment, operation or exploitation use is made of transmission infrastructure owned by the service provider, unless the service provider has the co…
The New Public Diplomacy— ‘to promote Canada as a good neighbor and reliable partner of the United States’. 22 Are there structural factors at work to support the role of Norway in such a ‘humanitarian superpower’ niche? Phrasing the …
What is the Foreign Ministry?— | | Foreign and Commonwealth Office (UK) Adaptive Diplomacy (2006) | Department of Foreign Affairs and International Trade (Canada) Int…
INTERNATIONAL CIIP HANDBOOK 2008 / 2009— F IRST is the global Forum for Incident Response and Security Teams. The organization is widely recognized as a global leader in incident response and brings together a variety of Computer Security Incident Response Team…
Conversation: 01— -Paula Bogantes Zamora- Area of expertise: Science, innovation, technology and telecommunications policy. Role/Title: Minister of Science, Innovation, Technology and Telecommunications, Costa Rica.[S12] Additional conte…
Ad Hoc Consultation: Tuesday 30th January, Morning session— The United Kingdom’s engagement with international legal discussions presents a distinctly positive alignment with global objectives and the detailed provisions of specific articles, highlighting its and collabora…
Government of the United Kingdom— The Government of the United Kingdom, domestically referred to as Her Majesty’s Government, is the central government of the United Kingdom of Great Britain and Northern Ireland.
Capacity Development— A multistakeholder approachinvolving governments, civil society, business, academia, and other actors. Adaptive capacities: Ability to analyse and adapt,change readiness and management, confidence Although there is no …
DiploNews – Issue 386 – 9 January 2020— A capacity development practitioner or researcher A diplomat responsible for development co-operation Capacity development is central to aid effectiveness. Yet, many practitioners are unsure about what capacity develop…
Advocacy to Action: Engaging Policymakers on Digital Rights | IGF 2023— Connecting international, national, and local levels in the regulation of internet governance is both challenging and necessary. Internet Lab has been actively working towards this goal. By working in conjunction with di…
Ad Hoc Consultation: Tuesday 6th February, Morning session— The country’s affirmative stance highlights its commitment to established technological frameworks and could signal its vision for the nation’s ICT future. Nicaragua’s proactive approach may play a significant role in se…
Opening of the session— Nicaragua has taken a pivotal role in representing a diverse group of nations, advocating for the creation of a comprehensive international treaty aimed at ICT crimes. The coalition includes Belarus, Burundi, Burkina Fas…
Ad Hoc Consultation: Thursday 8th February, Morning session— In summary, Nicaragua’s diplomatic activities exemplify a genuine commitment to collaboration, equitable technology exchange, and constructive dialogue in international forums. They favour a supportive and affirmative ou…
Dedicated stakeholder session— This convergence suggests a recalibration of established international law to incorporate digital statecraft and state interactions in the cyber domain. The African Union (AU) is a key regional player in broadening the d…
African Union— The Union was officially launched in 2002, when the first Assembly of the Heads of States was convened. The process for creating the African Union (AU) was initiated in September 1999, when the Heads of State and Govern…
About the ICRC— The International Committee of the Red Cross (ICRC) is an impartial, neutral and independent organisation whose exclusively humanitarian mission is to protect the lives and dignity of victims of armed conflict and other …
Open Forum #8 Modern Warfare Timeless Emblems— Samit D’Chuna: Tejas, thank you so much for that wonderful introduction. Good morning, everyone. Thank you to the IGF for hosting us for this very important topic, and thank you to all of you. I know there’s some really …
SUMMARY OF THE GENEVA CONVENTIONS OF 12 AUGUST 1949 AND THEIR— The International Committee of the Red Cross (ICRC) is an impartial, neutral and independent organization whose exclusively humanitarian mission is to protect the lives and dignity of victims of armed conflict and o…
Multistakeholder Partnerships for Thriving AI Ecosystems— – Role/Title: Audience participant (part of a German group; specific affiliation not specified)[S1][S2][S3] – Role/Title: Chairperson and CEO, Salesforce South Asia; Former Chairperson, State Bank of India[S16][S17] – …
Building Climate-Resilient Systems with AI— – Affiliation: Google – Role/Title: Director for Sustainability – Role/Title: Founding Partner, Climate Collective – Role/Title: Global Director of Climate Operations – Role/Title: Speaker / Representative, Universit…
Indias Roadmap to an AGI-Enabled Future— -Closing remarks (Suvrat Bhoosha)- Suvrat reiterated the need for an integrated ecosystem that couples energy, compute, talent and data-sovereignty to build indigenous frontier models. He thanked the pa…
Centre for Humanitarian Dialogue— For this, HD uses the tools of private diplomacy to expand the space for the nonviolent resolution of armed conflict. They aim to open channels of communication and mediate between parties in conflict, facilitate dialogu…
INTRODUCTION— A fundamental goal of scientific research is to improve the quality of life of people and the social context in which they live. In the near future, Artificial Intelligence (AI) will offer increasingly effective too…
Stefano Baldi Pasquale Baldocci— As for Italian history in general, Sergio Romano has written several titles in the area. Particularly important is his History of Italy from the Risorgimento to Today . Originally published in French in 1977 , it…
On the origins of World War I— Italy’s role in destroying the Congress of Berlin balance of power seems beyond dispute. The authors also blame Italy for being thefirst European power to use war as a means of reducing social tension at home. Indeed, Gi…
Research Collection— 19 Based on the title of David D. Newsom’s article on the Swiss role in the hostage crisis, which was first published in a commemorative publication for Ambassador Probst: David D. Newsom, ‘The Sensiti…
UN: Summit of the Future Global Call— The analysis reveals Switzerland’s role as a proponent of international cooperation and dialogue. By supporting initiatives like the Summit of the Future and the Pact for the Future, Switzerland positions itself as a fac…
Panel Discussion AI in Healthcare India AI Impact Summit— -Affiliation:Invalude, Canton Broad, Switzerland[S4] -Affiliation:Not specified in transcript (moderator role)[S2] -Role/Title:India Relations Advisor at Invalude (innovation and investment promotion agency of Canton B…
5th meeting Plenary Session— Tonga, speaking on behalf of the Pacific Islands Forum (PIF) – comprising Australia, the Cook Islands, Fiji, Kiribati, the Federated States of Micronesia, the Republic of the Marshall Islands, Nauru, New Zealand, Palau, …
Agenda item 6: other matters/OEWG 2025— – Pacific Islands Forum – Tonga: Speaking on behalf of Pacific Islands Forum member states – The Pacific Islands Forum, represented by Tonga, emphasised the need for a limited number of thematic groups to enable partici…
Multistakeholder Partnerships for Thriving AI Ecosystems— – Role/Title: Audience participant (part of a German group; specific affiliation not specified)[S1][S2][S3] – Role/Title: Parliamentary State Secretary at Germany’s Federal Ministry for Economic Cooperation and Developm…
By the Same Author— Germany is the world’s most decentralized large country, in political and socioeconomic structure. Its nearest comparison is the US, a continental landmass nation of a different order, and possibl…
UNITED NATIONS HANDBOOK 2019-20— * Original members, that is, those that participated in the UN Conference on International Organisation at San Francisco or had previously signed the UN Declaration of 1 January 1942, and that signed and ratified the Cha…
AN INTRODUCTION TO— ICANN is a multistakeholder institution involving a wide variety of actors in different capacities and roles. They fall into four main groups. The first group consists of actors that have been involved since the days whe…
Introducción a la Internet gobernanza DE— – Las comunidades técnica y comercial, cuyo rol dentro de ICANN es el de desarrollar recomendaciones para la Junta de ICANN sobre políticas que cubren las áreas relacionadas con la misión de la organización (por ejemplo,…
By the Same Author— Algeria was relatively unknown in India. Under President Houari Boumediene, it strode tall on the international stage. It had hosted the 1973 Non-Aligned Summit, and showed itself adept at socialist rhetoric, which was t…
(Day 1) General Debate – General Assembly, 79th session: morning session— Cyril Ramaphosa – South Africa: Thank you, Your Excellency, the Chair of the Assembly. We take this opportunity to thank the United Nations Assembly to give us a chance to speak. Thirty years ago, South Africa was bor…
Ad Hoc Consultation: Thursday 8th February, Morning session— Speaking from a national perspective, the representatives communicated that they could fully endorse the Article. This strong endorsement indicates compatibility with national policies or a strategic international stance…
Adoption of the agenda and organization of work— Australia’s position suggests that safeguarding human rights is both a moral and a legal necessity, vital for maintaining treaty credibility and global trust. In cyber security deliberations, particularly concerning draf…
Conversation: 01— – President Donald Trump – Role/Title: Former President of the United States. (mentioned in transcript) -Omar Al Olama- Area of expertise: Artificial Intelligence policy and governance. Role/Title: Minister of State for…
DISCUSSION PAPERS IN DIPLOMACY— Prior to these issuances, the United States denied visas to all persons who were terrorists or had any affiliation with terrorist groups. Gerry Adams, as the leader of the Sinn Fein, the political arm of the Ir…
US diplomacy— Global leadership and multilateral engagement: The United States has historically positioned itself as a global leader and has actively engaged in multilateral institutions and initiatives. It often seeks to shape global…
AN INTRODUCTION TO— In the context of international relations, the Internet community is an epistemic commu- Other terms are used interchangeably with ‘Internet community,’ such as ‘Internet developers,’ ‘Internet founders,’ ‘Intern…
Internet Society— The Internet Society (ISOC) is a global organisation dedicated to keeping the Internet open, transparent, and user-defined. ISOC’s mission is to promote the open development, evolution, and use of the Internet for the be…
Opening of the session— European Union: Thank you, Mr. Chair. I have the honor to speak on behalf of the European Union and its member states. The candidate countries North Macedonia, Montenegro, Serbia, Albania, Ukraine, the Republic of Mo…
Opening of the session— European Union: Good morning Chair, good morning colleagues. I have the honour to speak on behalf of the European Union and its member states, as well as the candidate countries North Macedonia, Montenegro, Serbia, Alban…
UNSC meeting: Strengthening UN peacekeeping— Serbia:Thank you, Mr. President. Thank you very much for convening this important meeting. Mr. President, distinguished members of Security Council, ladies and gentlemen, Serbia is a strong supporter of multilateralism a…
UNSC meeting: Multilateral cooperation for peace and security— Serbia:Mr. President, the world of today is faced with numerous and serious challenges that necessitate close cooperation by us all, as well as responsibility in quest for proper and applicable answers. Serbia considers …
(Day 1) General Debate – General Assembly, 79th session: morning session— Aleksandar VuÄiÄ – Serbia: Madam President, Excellencies, ladies and gentlemen, Mahatma Gandhi said, there is no path to peace. Peace is the path. In the same spirit of fraternal love and open heart, I address you …
Scoping Civil Society engagement in Digital Cooperation | IGF 2023— Audience:Hi, everyone. I’m Ayden Férdeline, fellow of the Alfred Landecker Foundation. Hi, everyone. I’m Laura O’Brien, Senior UN Advocacy Officer at Access Now. Hi there. I’m Jutta Croll from the German Digital Opportun…
Access Now— Advocacy. Through its advocacy campaigns, the organisation promotes its policy positions within public entities and private corporations, and mobilizes global Internet users to stand for their rights. Business and human…
WS #69 Beyond Tokenism Disability Inclusive Leadership in Ig— Audience: All right. Thank you. My name is Francis Akwa Amini. Looks like I’m very tall. All right. Comfortable now. All right. So my name is Francis from Ghana. I’ve been an executive member of ISO Ghana chapter for the…
Moscow State Institute of International Relations (MGIMO-University)— Moscow State Institute of International Relations is an institute of higher education, which is widely considered as the most elite university in Russia. It is one of the top universities in Russia, Central and Eastern E…
Andrei Mikheyev— Dr Andrei Mikheyev is the internet projects manager for Yandex, Russia’s biggest internet company. Prior to going into the private sector, he worked as Director of the Internet Politics Centre and lecturer at Moscow Stat…
Is private public diplomacy a thing?— Michal Brichta is a final-year graduate student in international politics and transnational business at Moscow State Institute of International Relations. He has recently finished an exchange program at Lee Kuan Yew Scho…
How Trust and Safety Drive Innovation and Sustainable Growth— and then we’re going to dive right into my immediate left. I have Alex Reed -Gibbons, who is the CEO of the Center for Democracy and Technology, one of the leading advocacy organizations in the world, working on civil ri…
Ad Hoc Consultation: Friday 9th February, Morning session— Singapore is actively engaged in the sphere of international law, particularly with regard to the treaty ratification process outlined in Article 64. The country has expressed a positive stance on the idea of raising the…
Multistakeholder Partnerships for Thriving AI Ecosystems— – Role/Title: Audience participant (part of a German group; specific affiliation not specified)[S1][S2][S3] – Role/Title: Chairperson and CEO, Salesforce South Asia; Former Chairperson, State Bank of India[S16][S17] I …
Building Climate-Resilient Systems with AI— – Affiliation: Google – Role/Title: Director for Sustainability – Role/Title: Founding Partner, Climate Collective – Role/Title: Global Director of Climate Operations – Role/Title: Speaker / Representative, Universit…
Ad Hoc Consultation: Thursday 8th February, Afternoon session— Indeed, they contend that the incorporation of such equivocal language compromises legal clarity—a cornerstone of International Law that could potentially lead to interpretive conflicts and discord. Moreover, Kiribati ha…
Ad Hoc Consultation: Wednesday 7th February, Afternoon session— Albania’s efforts epitomize its role as a collaborator and mediator in shaping progressive and inclusive legislative outcomes in international relations. In its role within the international community, Albania has adopt…
Ad Hoc Consultation: Friday 9th February, Morning session— These efforts reflect Albania’s dedication to upholding international standards and fostering effective partnerships that advance shared goals, highlighting its role as a cooperative and consistent participant in the rea…
Ad Hoc Consultation: Monday 5th February, Morning session— Albania has demonstrated a clear alignment with the United States on a variety of issues relating to the document under discussion during the chairing session. Notably, Albania concurs with the US regarding the document’…
International Chamber of Commerce— A Commission on Digital Economy was established within ICC, with the aim to promote the global development of the digital economy and stable growth of information and communication technology, through advocacy, promotion…
Business Engagement Session— Maria Fernanda Garza, Honorary Chair of the International Chamber of Commerce (ICC), emphasized the role of digital transformation as a powerful catalyst for sustainability efforts. As the first woman elected to chair th…
AN INTRODUCTION TO— The International Chamber of Commerce (ICC), well known as the main association representing business across sectors and geographic borders, positioned itself as one of the main representatives of the business sector in …
Centre on Global HealtH SeCurity WorkinG GrouP PaPerS— Chatham House 10 St James’s Square London SW1Y 4LE T: +44 (0) 20 7957 5700 F: + 44 (0) 20 7957 5710 www.chathamhouse.org The views expressed in this document are the sole responsibility of the author(s) and…
ACKNOWLEDGEMENT— Chatham House, home of the Royal Institute for International Affairs UK, has been playing a significant role in contributing independent ideas and perspectives for the benefit of the global community. It played a signifi…
Smart Regulation Rightsizing Governance for the AI Revolution— -Affiliation:Chatham House But we do have… What I start with, just next to me here, Bella Wilkinson, who’s a research fellow on the Digital Society Program. with the Chatham House. Next to her is Rafik Rikorian. I hop…
Association for Progressive Communications— The Association for Progressive Communications is an international network of organizations that was founded in 1990 to provide communication infrastructure, including Internet-based applications, to groups and individua…
Open Forum #33 Open Consultation Process Meeting for WSIS Forum 2025— – Anriette Esterhuysen – Association for Progressive Communications Anriette Esterhuysen: Over to you, Anne-Marie. Thank you very much, Gitanjali. Association for Progressive Communications is an international network…
Agents of inclusion: Community networks & media meet-up | IGF 2023— Carlos Baca:Thank you. Thank you. Thank you. Carlos. Our next speaker is Nwendoa Kiibuba from Kenya. And he is one of the board members of the KIKTA-NET, that is the Kenyan ICT Action Network. And he’s also one of the de…
Parliamentary diplomacy and Internet policy making— Grace Mutung’u is an associate at the Kenya ICT Action Network (KICTANet) and an affiliate at the Berkman Klein Center for Internet and Society. She is also an assistant curator for the GIP Digital Watch observatory, and…
Webinar – session 1— David Ndeje, the Communications Officer for the Kenya ICT Action Network (KIKTANET), detailed the organisation’s crucial role in creating a cohesive force among different stakeholders in Kenya’s ICT policy sphere. KIKTAN…
Ad Hoc Consultation: Wednesday 7th February, Morning session— Their emphasis on both consensus and human rights protection showcases a comprehensive approach to cybercrime; one firmly grounded in the rule of law, individual liberties, and international partnerships. In summary, Chi…
Open Forum #40 Building a Child Rights Respecting Inclusive Digital Future— High level of consensus with complementary rather than conflicting viewpoints. This suggests a mature understanding of the challenges and potential solutions in digital child rights and gender inclusion. The agreement ac…
UN OEWG 2021-2025 10th substantive session— During the 10th substantive session of the UN OEWG 2025, various aspects of thecapacity-building landscapewere discussed across multiple sessions. The discussions highlighted both successful initiatives and existing gaps…
Agenda item 6— Finally, Fiji supported the call for gender-sensitive capacity-building initiatives and endorsed statements by Canada and other nations on this requirement. They praised the UN Singapore Fellowship and the Women in Cyber…
TOWARDS A SECURE CYBERSPACE VIA REGIONAL CO-OPERATION— – Capacity building should reflect local cyber dynamics, taking into consideration local political, social, cultural, and other spe cific conditions in developing and implementing capacity-development pro…
Youth diplomacy— A more structured and rights-based approach began to take shape in the 1990s. The UnitedNations’adoption of theWorld Programme of Action for Youth in 1995marked a significant turning point, formally recognising young peo…
How to believe in the future?— In conclusion, the global call for more young people in decision-making spaces highlights the need for institutions to adapt and reflect the voices and opinions of young people. The establishment of a youth office within…
UNSC meeting: Conflict prevention: women and youth— Armenia reaffirms its commitment to the implementation of the UN Security Council Resolution 1325 on Women, Peace, and Security and Resolution 2250 on Youth, Peace, and Security In this speech, Colombia’s representative…
Interim Report:— 27. Other risks are more a product of humans than AI. Deep fakes and hostile information campaigns are merely the l atest example of technologies being deployed for malevolent ends. They can pose serious risks to societa…
Emerging Shadows: Unmasking Cyber Threats of Generative AI— Kevin Brown:What generative AI has introduced is a far low barrier of entry into criminal activity. Before, perhaps, you had to have the technical background, the tooling, and the motivation. And now we’re seeing generat…
2021: The emergence of digital foreign policy— A new ‘hybrid’ governance approach has developed. In ICANN, a multistakeholder space, there is a Government Advisory Committee that brings together national governments.
Internet Governance in Times of Conflict | IGF 2023 Open Forum #152— Audience:So I do want to contribute something very important to the discussion, which I think has been overlooked. And it really relates to this business of why aren’t governments who shut down things sanctioned? And tha…
Closing the Governance Gaps: New Paradigms for a Safer DNS— In addition to its efforts in addressing DNS abuse, ICANN contributes to capacity building for law enforcement agencies, helping them enhance their understanding and implementation of DNS security measures. This collabor…
I NTRODUCTION— – Implementing shared services where demand has already been identified, such as the Unified Government Resource Planning (UGRP) system. – Establishing business-as-usual (BAU) capabilities to maintain ongoing strategic…
Agenda item 6: other matters— Islamic Republic of Iran: Thank you, Mr. Chair, for the floor. I will be quick, as I have to take the â to reach the airplane, a real one. With regard to the remaining issues and related established permanent mechan…
Introduction— Navigating the double-edged sword of digital transformation, managing digital risks and digital harms and leveraging the potential of technologies, requires investing in inclusive and accessible digital infrastructure to…
Quantum technologies tested to strengthen energy systems— Energy systems are undergrowing pressurefrom rising demand, geopolitical volatility and increasingly complex grid operations. Electrification, renewable integration and digital infrastructure growth are making power syst…
Agenda item 5: Day 2 Afternoon session— Furthermore, Mexico reconfirms its participation in the National Survey for Implementation put forth by the United Nations Institute for Disarmament Research (UNIDIR), an initiative recommended in the 2021 Open-Ended Wor…
Closure of the session— Czechia: Thank you, Mr. Chair, for giving me the floor. Czechia aligns itself with the statement of the European Union and would like to make a few additional remarks in its national capacity. Since many of the key i…
WS #110 AI Innovation Responsible Development Ethical Imperatives— Ricardo Israel Robles Pelayo: Thank you very much. Good afternoon, everyone. It is an honor to be here and share a reflection on a topic that is crucial to our present and above all. Our future. Artificial intelligence s…
WSIS women and girls trendsetters and action plan— This tension has clear policy background. WSIS and digital cooperation traditions emphasise multistakeholder collaboration, capacity development and practical exchange across actors[S104][S105]. At the same time, UN Wome…
Media Remuneration Policy Analysis Mitchell began by establishing her background and the context for CNTI’s work. Coming from 25 years at the Pew Research Center where she helped l…
A Clash of Professional Cultures: The David Kelly Affair— Finally, the following two quotes provide further background context in support of the policy-promoting rather than intelligence-sharing aims of the dossier. The first comes from an email from Danny Pruce (a Foreign Offi…
2nd meeting – Plenary Session— The European Union added a specific and politically charged dimension to the stakeholder debate by noting that Estonia had objected to the stakeholder JSC Positive Technologies on the grounds that it was already known to…
UN OEWG 2021-2025 9th substantive session— DuringAgenda Item 5 discussions, Czechia and Chile stressed the need for the involvement of multi-stakeholder communities and expressed regret over the veto of some stakeholders. They underscored the necessity for partic…
Webinar session— This comment prompted a more honest discussion about the limitations of stakeholder participation and influenced other speakers to acknowledge the ongoing challenges. It shifted the conversation from celebrating inclusiv…
Cybersecurity, cybercrime, and online safety— Lastly, the forum stressed the need for a secure cyber space for youth, women, and children. An audience member representing the Bangladesh Youth IGF advocated for a cyber space that prioritizes the safety of these speci…
CLOSING CEREMONY | IGF 2023— She links addressing climate change as vital to protecting vulnerable communities. Especially children and youth in the Global South. She underlines how climate change directly impacts vulnerable communities, particular…
Cyberconflict and warfare— This draft recommends the establishment of an international body named the Agency for Information Infrastructure Protection (AIIP). The UN Governmental Group of Experts in its latest 2021 report, as well as all UN Member…
A. Overview— The following is an initial, non-exhaustive list of voluntary global Confidence-Building Measures. These global CBMs are drawn from the Final Report of the 2021 Open-ended Working Group and the first and second APRs of t…
Opening Session | Seventh OEWG Session on ICT Security — 4. Confidence-Building Measures (CBMs): – The Chair underscored the importance of the OEWG as a CBM and the need to expand the initial list of global CBMs. Suggestions for additional CBMs included cert-to-cert coo…
Agenda item 5 : Day 4 Morning session— Argentina:Thank you, Mr. Chairman. My delegation joins in the statement made by the distinguished delegation of Chile yesterday on behalf of a group of 17 countries, and I would like to add the following comments in my n…
Welcome to the IGF2021 Final report!— It was noted thatcyber norms should continue to be developed at the UNwith more systemic involvement of other stakeholders as they can help build and implement the framework. It is especially crucial forunderrepresented …
Dedicated stakeholder session— The establishment of the global POC directory was recognized as a key confidence-building measure at the global scale. The directory is expected to facilitate the application of other global CBMs, promote resilient and p…
Agenda item 5 : Day 4 Morning session— By fostering policy exchanges and international cooperation on cybersecurity, the POC directory is seen as instrumental in enhancing practical state-to-state communication and cooperation in the cyber domain. In summary,…
Cybersecurity, cybercrime, and online safety— By prioritising these aspects, they can build resilience against cyber threats. Culturally relevant approaches that take into account the specific socio-cultural contexts of these countries can be highly effective in enc…
Women, peace and security— – Canada emphasised the need to protect women human rights defenders 4. Enhance protection mechanisms for women human rights defenders and peacebuilders Costa Rica: Madam President, this year’s annual debate offers us…
5th meeting Plenary Session— Austria believes that discussions on international law in the DTGs should be scenario-based and practice-oriented. They suggest that interstate discussions could be preceded by expert panels, and that meetings should be …
4th meeting – Plenary Session— A broad consensus emerged that the DTGs should serve as practical, action-oriented forums for advancing implementation of the normative framework. Romania stated that ‘the DTGs could play an important role in this respec…
Agenda item 6: other matters/OEWG 2025— Islamic Republic of Iran: Thank you, Mr. Chair. My delegation fully aligns itself with the statement made by Nicaragua on behalf of like-minded countries and wishes to offer the following comments in its national capa…
WS #226 Strengthening Multistakeholder Participation— High level of consensus with significant implications for internet governance reform. The agreement suggests a shared understanding that current approaches are insufficient and that fundamental changes are needed in how …
3rd meeting – Plenary Session— The Bahamas highlighted that cyber threats disproportionately affect women and girls through technology-facilitated gender-based violence. This area requires dedicated attention within the mechanism’s threat discussions …
How Can Cyber Defenders Win?— Creating a secure architecture requires collaboration between the public and private sectors at national, regional, and global levels. Singapore’s anti-scam center serves as a prime example, enabling real-time informatio…
The History of Cyber Diplomacy Future— The panelists agreed on the importance of building trust and confidence among nations in the cyber domain. H.E. Adel al-Jubeir highlighted Saudi Arabia’s initiatives on child protection and women’s empowerment in cybersp…
Successes & challenges: cyber capacity building coordination | IGF 2023— Another key point raised is the need to break down cyber capacity building into more specific categories. The analysis suggests that traditional cyber capacity building, capacity building for crisis response, and capacit…
WS #344 Multistakeholder Perspectives WSis+20 the Technical Layer— Chapman noted the challenge of “rising regulatory pressures from multiple digital media regulators worldwide making decisions without understanding technical implications.” Sorensen reinforced this concern, arguing that …
UN OEWG 2021-2025 10th substantive session— During the 10th substantive session of the UN OEWG 2025, various aspects of thecapacity-building landscapewere discussed across multiple sessions. The discussions highlighted both successful initiatives and existing gaps…
Agenda item 6: other matters— Mozambique: Thank you, Chair. Mozambique will speak out for national capacity. Mozambique delegation recognize that capacity building is essential to promote a secure and inclusive cyberspace. As a developing nation…
UN OEWG 2021-2025 9th substantive session— DuringAgenda Item 5 discussions, Czechia and Chile stressed the need for the involvement of multi-stakeholder communities and expressed regret over the veto of some stakeholders. They underscored the necessity for partic…
5th meeting Plenary Session— Austria expresses frustration with the lack of consensus on stakeholder participation, sharing concerns raised by the multi-stakeholder community. They emphasise that while states will always make the decisions, non-gove…
Cybersecurity, cybercrime, and online safety— Lastly, the forum stressed the need for a secure cyber space for youth, women, and children. An audience member representing the Bangladesh Youth IGF advocated for a cyber space that prioritizes the safety of these speci…
CLOSING CEREMONY | IGF 2023— Another critical aspect discussed by Brito is the urgent need to address climate change for a free, open, and inclusive internet. She underlines how climate change directly impacts vulnerable communities, particularly ch…
Cyberconflict and warfare— This draft recommends the establishment of an international body named the Agency for Information Infrastructure Protection (AIIP). The UN Governmental Group of Experts in its latest 2021 report, as well as all UN Member…
WS #395 Applying International Law Principles in the Digital Space— International law applies to cyberspace but practical implementation remains fragmented across different legal frameworks (international human rights law, international humanitarian law, international criminal law)
UN OEWG 2021-2025 10th substantive session— The discussions within theOEWG 2025 sessionssignificantly highlighted the importance of capacity building and international cooperation as fundamental components in supporting the full operationalisation of the eight agr…
Agenda item 5 : Day 4 Morning session— Argentina:Thank you, Mr. Chairman. My delegation joins in the statement made by the distinguished delegation of Chile yesterday on behalf of a group of 17 countries, and I would like to add the following comments in my n…
PERMANENT MISSION OF THE REPUBLIC OF' SINGAPORE— 37. During the fourth, fifth as well as informal sessions of the OEWG, States continued discussions on confidence-building measures (CBMs). States, reaffirming the cumulative and evolving framework for responsible Stat…
2nd meeting – Plenary Session— Capacity building as a strategic priority, particularly for developing and small island states.Multiple delegations, especially from the African Group, the Pacific Islands Forum, and small island developing states, empha…
Opening plenary session and adoption of the agenda— Chair:Thank you. We now continue with the list of speakers as proposed. Team Purple has the floor. You have the floor. Chair:Today we’re entering a multi-polar world with several actors who can influence the internation…
UN-WSIS Regional Commissions— Speaker 4 introduced an important observation about the absence of key stakeholders from the discussion, noting that people from ECOSOC and New York-based regional formations – which are formally supposed to be under ECO…
WSIS Action Line C5 Building confidence and security in the use of ICTs— Bueermann explained that the foundational questions for the session came from a joint research initiative between GCF, George Washington University’s Space Policy Institute, and ITU, working to examine the main cyber thr…
Pre 12: Resilience of IoT Ecosystems: Preparing for the Future— This question became a recurring theme that multiple speakers addressed throughout the session. It led to detailed explanations about scale, attention gaps, machine-to-machine communication, and the ‘fabric’ nature of Io…
'Our Common Agenda' | Report of the UN Secretary-General— 45. Some countries have created opportunities for younger generations to have a voice in decisions that affect them, through youth councils, parliaments and ministries. However, these solutions have not always avoided to…
WSIS 2018 – Closing ceremony— Zhao opened the floor for open discussion. A representative of the UN Major Group for Children and Youth gave a brief statement on behalf of the children and youth. Dr Reha, the director of the National Centre of Data in…
137
WPM
523
Words
4 min
Time
Youth and children's rights must be fully recognised in the digital environment, and objections to stakeholder accreditation without stated basis undermine the inclusivity principle agreed by consensus – Demand for transparent, criteria-based accreditation
Arg. 1
Explanation
The Discover MUN Foundation, speaking on behalf of the Major Group for Children and Youth, argued that children's rights apply fully in the digital environment and that the mechanism must adopt transparent, criteria-based accreditation practices. They noted that objections lodged against more than 60 stakeholder entities without any stated basis cannot be considered consistent with the inclusivity principle agreed by consensus. They called on member states to honour multi-stakeholder principles affirmed in the Global Digital Compact and WSIS+20 review.
Evidence
The speaker cited General Comment No. 25 of the Committee on Rights of the Child, which establishes that rights of children apply fully and equally in the digital environment . They noted that objections had been lodged against more than 60 stakeholder entities, including NGOs, universities, and technical bodies, without any stated basis . They thanked the EU and its member states for acting as a leading example of transparency pertaining to stakeholder participation .
Major Discussion Point
Stakeholder Participation and Accreditation in the Global Mechanism
Agreed with
ICANNForum of Incident Response and Security TeamsInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAccess NowCanadaJapanMexicoEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoChileGermanyInternational Chamber of CommerceChair Egriselda López
on: Meaningful and inclusive multi-stakeholder participation is essential to the global mechanism's success, not merely desirable
Disagreed with
Forum of Incident Response and Security TeamsInternet SocietyAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeCanadaChileGermanyJapanEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoMexicoInternational Chamber of Commerce
on: Whether stakeholder accreditation objections without stated basis are consistent with the agreed inclusivity principle, and whether the current level of stakeholder participation is acceptable
A dedicated children and youth track within the mechanism's capacity-building activities should be modelled on successful examples such as the UNIDIR Women in International Security and Cyberspace Fellowship
Arg. 2
Explanation
The Discover MUN Foundation called for the establishment of a dedicated children and youth track within the mechanism's sponsorship and capacity-building activities. They argued that such activities must be modelled on successful examples that effectively integrate young technical experts in national delegations. This would ensure that capacity building reaches marginalised stakeholders including youth.
Evidence
The speaker specifically referenced the Women in International Security and Cyberspace Fellowship organised by the UN Institute for Disarmament Research as a successful model that effectively integrates young technical experts in national delegations .
Major Discussion Point
Cybersecurity Capacity Building
Agreed with
ICANNForum of Incident Response and Security TeamsDeveloping Capacity LTDInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAfrican UnionNicaraguaAlgeriaTonga on behalf of the Forum of Pacific IslandsPapua New GuineaSouth AfricaSwitzerlandAustralia
on: Cybersecurity capacity building must be demand-driven, inclusive, and practically oriented, with particular attention to the needs of developing countries and small island developing states
Meaningful engagement with children and youth should be recognised as a confidence-building measure in its own right, consistent with the Youth Peace and Security Agenda under Security Council Resolution 2250
Arg. 3
Explanation
The Discover MUN Foundation argued that meaningful engagement with children and youth should be formally recognised by the mechanism as a confidence-building measure in its own right. This call was grounded in the existing Youth Peace and Security Agenda established under Security Council Resolution 2250. Recognising such engagement as a CBM would give it institutional weight within the framework.
Evidence
The speaker explicitly cited Security Council Resolution 2250 and the Youth Peace and Security Agenda as the basis for this demand .
Major Discussion Point
Protection of Vulnerable and Marginalised Communities in Cyberspace
Dual-use technologies including AI-driven malware and deepfake social engineering are being weaponised against digital spaces, with children and young people facing immediate attacks to their digital safety and rights
Arg. 4
Explanation
The Discover MUN Foundation highlighted that cyber security risks and automated exploits are escalating at unprecedented speed, with dual-use technologies being weaponised to target digital spaces. They argued that when everyday ICT tools are repurposed for malicious activities, it is young people and children who face the most immediate attacks to their digital safety and rights. They called on member states to consider age-related disaggregated data on malicious ICT activity in their submissions.
Evidence
The speaker described dual-use technologies such as AI-driven malware and deepfake social engineering as being weaponised to target digital spaces , and called on delegations to consider age-related disaggregated data on malicious ICT activity in their submissions under this pillar .
Major Discussion Point
Emerging Technologies, AI, and Evolving Cyber Threats
Agreed with
Association for Progressive CommunicationsInternetLabAccess NowKenya ICT Action Network
on: Protecting vulnerable and marginalised communities, including women, children, and human rights defenders, from cyber threats must be a priority for the mechanism
The Women in International Security and Cyberspace Fellowship is an effective model for integrating young technical experts in national delegations and should inform the mechanism's capacity-building activities
Arg. 5
Explanation
The Discover MUN Foundation pointed to the UNIDIR Women in International Security and Cyberspace Fellowship as a proven model for integrating young technical experts into national delegations. They argued that the mechanism's capacity-building activities should be modelled on such successful examples. This would help ensure that marginalised stakeholders, including youth, are meaningfully included in the mechanism's work.
Evidence
The speaker referenced the Women in International Security and Cyberspace Fellowship organised by the UN Institute for Disarmament Research as an example of capacity building for marginalised stakeholders that effectively integrates young technical experts in national delegations .
Major Discussion Point
Protection of Vulnerable and Marginalised Communities in Cyberspace
108
WPM
383
Words
4 min
Time
ICANN's multi-stakeholder model, including the Government Advisory Committee, provides a proven framework for inclusive Internet governance that member states should actively engage with
Arg. 1
Explanation
ICANN argued that its multi-stakeholder model, which brings together registries, registrars, governments, law enforcement, technical experts, civil society, and the private sector, provides an effective framework for addressing Internet governance challenges. The Government Advisory Committee (GAC) gives governments a unique and essential role within this model, advising the ICANN board on public policy issues related to its mission. ICANN encouraged all member states to actively participate in the GAC to ensure the DNS functions flawlessly.
Evidence
ICANN cited the Coalition for Digital Africa as an example of multi-stakeholder collaboration that brings together African governments, regional organisations, academia, the private sector, and the technical community to strengthen DNS security and resilience . The speaker noted that ICANN has staff in New York available to provide information to member states wishing to engage with the GAC , and invited delegates to a briefing on collaborative security approaches co-organised with the Internet Society and ITU .
Major Discussion Point
Stakeholder Participation and Accreditation in the Global Mechanism
Agreed with
Discover MUN FoundationForum of Incident Response and Security TeamsInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAccess NowCanadaJapanMexicoEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoChileGermanyInternational Chamber of CommerceChair Egriselda López
on: Meaningful and inclusive multi-stakeholder participation is essential to the global mechanism's success, not merely desirable
The Coalition for Digital Africa demonstrates how capacity building through multi-stakeholder collaboration can strengthen DNS security, build local technical expertise, and expand Internet governance participation
Arg. 2
Explanation
ICANN highlighted the Coalition for Digital Africa as a concrete example of how multi-stakeholder capacity-building efforts can deliver tangible results. The coalition brings together African governments, regional organisations, academia, the private sector, and the technical community to strengthen DNS security and resilience, build local technical expertise, and expand opportunities for participation in Internet governance. This model demonstrates the value of inclusive, collaborative approaches to capacity building.
Evidence
The speaker described the Coalition for Digital Africa as bringing together African governments, regional organisations, academia, the private sector, and the technical community to strengthen DNS security and resilience, build local technical expertise, and expand opportunities for participation in Internet governance .
Major Discussion Point
Cybersecurity Capacity Building
Agreed with
Discover MUN FoundationForum of Incident Response and Security TeamsDeveloping Capacity LTDInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAfrican UnionNicaraguaAlgeriaTonga on behalf of the Forum of Pacific IslandsPapua New GuineaSouth AfricaSwitzerlandAustralia
on: Cybersecurity capacity building must be demand-driven, inclusive, and practically oriented, with particular attention to the needs of developing countries and small island developing states
Enterprise architecture can bridge policy intent and operational systems, strengthening the mechanism without altering negotiated outcomes, and independent stakeholders bring unique value to implementation
Arg. 1
Explanation
FutureEarth Systems argued that enterprise architecture—which maps how policy intent, legal frameworks, capabilities, processes, data, and technical systems align—can bridge the gap between policy and operational implementation. The speaker used the analogy of a city plan to explain how this approach ensures that different elements work together efficiently and can adapt as conditions change. Crucially, they emphasised that this approach would not alter negotiated outcomes but would strengthen the mechanism and improve capacity building.
Evidence
The speaker used the analogy of a city plan to illustrate enterprise architecture, explaining that it ensures roads, utilities, and buildings work together efficiently and can adapt as the city grows . They noted that industry is already innovating at this level, visible in both regulated and unregulated global trade including cybercrime , and offered to meet with the Mexican delegation to explore how enterprise architecture can assist states with implementation of the norms .
Major Discussion Point
Stakeholder Participation and Accreditation in the Global Mechanism
Enterprise architecture can help harness the positive opportunities of ICTs including AI and quantum, forming blueprints for real-time adaptive systems that enable human society to operate at the next level of complexity
Arg. 2
Explanation
FutureEarth Systems argued that enterprise architecture can serve as the blueprint for real-time sensory systems that adapt dynamically to changing conditions and challenges, including those posed by AI and quantum technologies. These new-generation systems would enable human society to operate at the next level of complexity with peace and security for all. The speaker positioned this approach as essential for cyber defence to become a globally interconnected ecosystem.
Evidence
The speaker argued that an architectural approach forms the blueprints for real-time sensory systems which can adapt themselves much more dynamically to changing conditions and challenges , and that cyber defence needs to be a globally interconnected ecosystem with more effective collaborative systems and shared data between state and regional and global institutions .
Major Discussion Point
Emerging Technologies, AI, and Evolving Cyber Threats
FutureEarth Systems offers to meet directly with the Mexican delegation to explore how enterprise architecture can assist states with implementation of the norms, demonstrating the practical availability of independent stakeholders for bilateral engagement
Arg. 3
Explanation
Rather than taking up session time to answer Mexico's question in plenary, FutureEarth Systems offered to meet directly with the Mexican delegation as a follow-up to explore how enterprise architecture can assist states with implementation of the norms. This reflects the speaker's view that independent accredited stakeholders can provide tailored, practical support to individual member states outside of formal sessions.
Evidence
The speaker stated that rather than taking time up during the session, they would be happy to meet with the Honourable Representatives from Mexico as a follow-up to explore how enterprise architecture can assist states with implementation of the norms . They also thanked representatives for their positive feedback to the organisation’s participation .
Major Discussion Point
Cybersecurity Capacity Building
Cyber defence must become a globally interconnected ecosystem with effective collaborative systems and shared data between state, regional, and global institutions to strengthen collective capabilities and enable every community to operate in peace and security
Arg. 4
Explanation
FutureEarth Systems argued that industry is already innovating at the level of interconnected, adaptive systems, visible in both regulated and unregulated global trade including cybercrime. Cyber defence must therefore match this by becoming a globally interconnected ecosystem itself, with much more effective collaborative systems and shared data between state institutions and regional and global institutions. This would enable collective and continuous strengthening of capabilities so that every community can operate in peace and security.
Evidence
The speaker noted that industry is already innovating at this level, visible in both regulated and unregulated global trade including cybercrime , and argued that cyber defence needs to be a globally interconnected ecosystem itself, with much more effective collaborative systems and shared data between state institutions and regional and global institutions so as to strengthen capabilities collectively and continuously, enabling every community to operate in peace and security .
Major Discussion Point
Confidence-Building Measures (CBMs) and the Global Points of Contact Directory
118
WPM
633
Words
5 min
Time
Incident response and security professionals provide indispensable operational expertise on cyber norms and CBM implementation; stakeholder participation must remain open, transparent, and non-politicised
Arg. 1
Explanation
FIRST argued that stakeholders from industry, academia, and professional and technical organisations play indispensable roles in supporting the implementation of cyber norms and confidence-building measures, providing timely operational responses to emerging threats, facilitating responsible vulnerability disclosure, and strengthening capacity building. They supported the joint multi-stakeholder statement on objections to stakeholder participation, emphasising that such participation must remain open, transparent, and non-politicised. They called on states to support international collaboration among incident responders and ensure it remains non-politicised.
Evidence
FIRST noted that its members have participated in the UNGGE process since 2012 and supported the OEWG since 2019 , and that its membership currently includes 874 incident response and security teams across 118 countries . The speaker cited the OEWG Global Roundtable on Cybersecurity Capacity Building held two years ago as a positive example of open, transparent, inclusive consultation , and referenced the UNGGE 2021 report in calling for non-politicised cooperation .
Major Discussion Point
Stakeholder Participation and Accreditation in the Global Mechanism
Agreed with
Discover MUN FoundationICANNInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAccess NowCanadaJapanMexicoEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoChileGermanyInternational Chamber of CommerceChair Egriselda López
on: Meaningful and inclusive multi-stakeholder participation is essential to the global mechanism's success, not merely desirable
Disagreed with
Discover MUN FoundationInternet SocietyAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeCanadaChileGermanyJapanEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoMexicoInternational Chamber of Commerce
on: Whether stakeholder accreditation objections without stated basis are consistent with the agreed inclusivity principle, and whether the current level of stakeholder participation is acceptable
FIRST has 31 member teams in Mexico and an upcoming Mexico City Technical Colloquium; it stands ready to support states in implementing responsible behaviour frameworks through its global membership network
Arg. 2
Explanation
In response to Mexico's question about practical tools and resources for implementing the responsible state behaviour framework, FIRST highlighted that it already has 31 member teams in Mexico, providing a strong foundation for further cooperation. They noted an upcoming Mexico City Technical Colloquium as a concrete opportunity for engagement. FIRST offered to share experiences from other parts of the world and to provide support in different shapes and forms depending on the situation.
Evidence
The speaker noted that FIRST already has 31 team members from Mexico, described as a sizable number , and highlighted an upcoming Mexico City Technical Colloquium taking place the following month as an opportunity for cooperation .
Major Discussion Point
Cybersecurity Capacity Building
Agreed with
Discover MUN FoundationICANNDeveloping Capacity LTDInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAfrican UnionNicaraguaAlgeriaTonga on behalf of the Forum of Pacific IslandsPapua New GuineaSouth AfricaSwitzerlandAustralia
on: Cybersecurity capacity building must be demand-driven, inclusive, and practically oriented, with particular attention to the needs of developing countries and small island developing states
130
WPM
355
Words
3 min
Time
The Centre for Humanitarian Dialogue urges the global mechanism to develop confidence-building measures specifically for the cyber and information domain in post-conflict situations, where malware's indestructibility and invisibility pose unique risks
Arg. 1
Explanation
The Centre for Humanitarian Dialogue argued that the global mechanism has not yet fully explored confidence building in the cyber and information domain after armed conflict, a gap that has become increasingly timely. They noted that traditional post-conflict stabilisation mechanisms focus on physical domains—land, sea, and air—and that no ceasefire or peace agreement in history has addressed the cyber and information domain. The unique characteristics of cyberspace, including the indestructibility and invisibility of malware, make designing CBMs for this domain particularly challenging but essential.
Evidence
The speaker noted that malware can be developed anywhere, transported on a chip, deployed from any point on earth, and is effectively indestructible . They observed that since cyber operations are often used in hybrid campaigns or to prepare a kinetic battlefield, ICT incidents can raise suspicion in a no-trust security environment such as shortly after a war . The Centre for Humanitarian Dialogue offered its expertise in mediating for peace to assist the mechanism in developing such CBMs .
Major Discussion Point
Application of International Law to Cyberspace
123
WPM
437
Words
4 min
Time
Capacity-building practitioners have published practical suggestions for the mechanism and recommend prioritising quick wins through matchmaking and funding coordination, addressing strategic resource gaps, and improving quality and demand-driven delivery
Arg. 1
Explanation
Developing Capacity LTD argued that the mechanism should prioritise three areas in structuring the work of DTG2: first, achieving quick wins by coordinating, matchmaking, and mobilising funding for capacity-building activities that directly support the mechanism; second, addressing the deeper strategic challenge of increasing resources available for cyber capacity building both internationally and domestically; and third, improving the quality, efficiency, and demand-driven nature of cyber capacity building. The speaker noted that several capacity-building practitioners had recently published articles with practical suggestions for the mechanism.
Evidence
The speaker referenced a series of tabletop exercises on the principles agreed by the OEWG, culminating in a Chatham House report on how they might be applied in practice . They noted that several capacity-building practitioners, including themselves, had recently published articles with practical suggestions for the mechanism to be submitted to the document repository , and highlighted more than two decades of research, conference outcomes, and lessons available to draw upon .
Major Discussion Point
Cybersecurity Capacity Building
Agreed with
Discover MUN FoundationICANNForum of Incident Response and Security TeamsInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAfrican UnionNicaraguaAlgeriaTonga on behalf of the Forum of Pacific IslandsPapua New GuineaSouth AfricaSwitzerlandAustralia
on: Cybersecurity capacity building must be demand-driven, inclusive, and practically oriented, with particular attention to the needs of developing countries and small island developing states
The Sybil Portal, with 74 documents and information on 100 past cyber capacity-building projects, stands ready to serve as a state and stakeholder platform for hosting capacity-building resources
Arg. 2
Explanation
In response to Mexico's question about practical tools and resources for implementing the responsible state behaviour framework, Developing Capacity LTD highlighted the Sybil Portal as an existing repository built by the international community of stakeholders and governments. The portal contains 74 documents on relevant thematic areas and information on 100 past cyber capacity-building projects. The speaker noted it is currently undergoing renewal and stands ready to serve as a platform for hosting such resources going forward.
Evidence
The speaker described the Sybil Portal as having 74 documents on the thematic area of interest and information on 100 past cyber capacity-building projects . They noted it has received support from the Dutch government in the past and is currently going through a period of renewal .
Major Discussion Point
Cybersecurity Capacity Building
118
WPM
392
Words
3 min
Time
Realistic attack simulations reveal systemic interdependencies and cascading effects; responsible preparation requires understanding complexity and challenging assumptions before adversaries do, not merely deploying technologies
Arg. 1
Explanation
IMQ Intuity SPA argued that cyber risks rarely emerge from a single vulnerability but from the interaction between technology, people, processes, suppliers, physical infrastructure, and the decisions connecting them. Based on hundreds of realistic attack simulations, they found that resilience is limited not by technology alone but by assumptions that have never been challenged. They argued that responsible state behaviour requires responsible preparation, meaning understanding complexity, recognising interdependencies, and challenging assumptions before they become vulnerabilities.
Evidence
The speaker drew on experience from hundreds of realistic attack simulations conducted by IMQ Intuity, which revealed the same pattern: cyber risks emerge from interactions between technology, people, processes, suppliers, and physical infrastructure . They described their methodology of turning the map around-asking where an attacker would begin rather than how to defend-as revealing dependencies and challenging assumptions .
Major Discussion Point
Cybersecurity Capacity Building
Cyber risks emerge from the interaction between technology, people, processes, suppliers, and physical infrastructure; resilience requires understanding complexity and interdependencies, not just protecting against known vulnerabilities
Arg. 2
Explanation
IMQ Intuity SPA argued that as societies become increasingly interconnected, cyber incidents no longer remain confined to technology but rapidly become operational, economic, and societal in their consequences. The growing challenge is not the number of vulnerabilities but the growing number of interdependencies. Resilience therefore requires understanding what is truly critical before a crisis occurs, rather than attempting to protect everything equally.
Evidence
The speaker noted that across hundreds of realistic attack simulations, they rapidly observed that cyber risks emerge from the interaction between technology, people, processes, suppliers, physical infrastructure, and the decisions that connect them . They argued that a technical compromise can rapidly become operational, disrupting economic impact and ultimately societal consequences .
Major Discussion Point
Emerging Technologies, AI, and Evolving Cyber Threats
129
WPM
394
Words
3 min
Time
MGIMO University's IDENTITY project, recognised at WSIS, offers free digital education courses for non-technical students including future diplomats, and stands ready to share its curriculum with interested member states
Arg. 1
Explanation
The Moscow State Institute of International Relations (MGIMO) described its IDENTITY project—ICT Digital Related Education for Non-Technical and International Affairs Talented Youth—as a capacity-building initiative offering free, short-term, open-enrolment distance education courses called Digital Weeks. The project was recognised at the World Summit on Information Society in Geneva as a champion in the e-learning category. MGIMO offered to share its curriculum details and competence framework with other universities and training centres in interested member states.
Evidence
The speaker noted that more than 2,300 students had completed the digital skills training programme launched in 2023 . The IDENTITY project was recognised at the World Summit on Information Society in Geneva as a champion in the e-learning category , and the speaker offered to share curriculum details and competence frameworks with other universities and training centres in interested member states .
Major Discussion Point
Cybersecurity Capacity Building
LLM neutrality with regard to international affairs is a concern; MGIMO is developing reproducible benchmark tests to identify anomalies in LLM responses and proposes this as a basis for standardisation of LLM evaluation
Arg. 2
Explanation
MGIMO called for recognition of the importance of neutrality of large language models with regard to international affairs, the everyday work of diplomats, and media coverage of world events. They noted that they have been able to identify profound inconsistencies, irregularities, and sentiment shifts in LLM responses on international affairs issues, as well as a lack of language and cultural diversity in LLM outputs. They are developing a set of reproducible benchmark tests to identify these anomalies, which they believe could form the basis for standardisation of LLM evaluation.
Evidence
The speaker stated that MGIMO has been able to identify profound inconsistencies, irregularities, and sentiment shifts in large language model responses on international affairs issues and problems , and noted that lack of language and cultural diversity in LLM outputs is also an area of concern . They described developing a set of reproducible tests and benchmark designs to identify these anomalies .
Major Discussion Point
Emerging Technologies, AI, and Evolving Cyber Threats
Meaningful stakeholder engagement is not a courtesy but essential, as the Internet is run by a distributed ecosystem; accreditation modalities must be implemented in a predictable and transparent manner
Arg. 1
Explanation
The Internet Society argued that the mechanism's long-term success depends on meaningful and sustained engagement of non-governmental stakeholders, because the Internet is not solely run by governments but by a distributed ecosystem of network operators, standards bodies, and technical experts. They warned that if decisions on cyber norms, international law, and confidence-building measures do not prioritise input from those who build and secure Internet infrastructure, the mechanism risks being disconnected from operational reality. They called on member states to ensure stakeholder accreditation and participation modalities are implemented in a predictable, transparent, and non-reactive manner.
Evidence
The speaker noted that the Internet Society has been promoting the development of the Internet as a global technical infrastructure since 1992, with community members, special interest groups, and over 130 chapters worldwide . They cited the IETF’s open bottom-up process as proof that effective multi-stakeholder collaboration can deliver , and highlighted initiatives such as MANRS for routing security and the Global Common Goods Cyber Initiative .
Major Discussion Point
Stakeholder Participation and Accreditation in the Global Mechanism
Agreed with
Discover MUN FoundationICANNForum of Incident Response and Security TeamsKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAccess NowCanadaJapanMexicoEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoChileGermanyInternational Chamber of CommerceChair Egriselda López
on: Meaningful and inclusive multi-stakeholder participation is essential to the global mechanism's success, not merely desirable
Disagreed with
Discover MUN FoundationForum of Incident Response and Security TeamsAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeCanadaChileGermanyJapanEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoMexicoInternational Chamber of Commerce
on: Whether stakeholder accreditation objections without stated basis are consistent with the agreed inclusivity principle, and whether the current level of stakeholder participation is acceptable
The Internet Society's policymaker programme helps diplomats understand how the Internet works and how standards are developed, enabling better-informed cyber policy
Arg. 2
Explanation
In response to Mexico's question about practical tools and resources, the Internet Society highlighted its policymaker programme as a concrete capacity-building offering. The programme is specifically designed for policymakers and covers how the Internet works, provides visibility on Internet standards development processes, and aims to help diplomats understand how the Internet evolves and the standards that underpin it. The goal is to enable collectively better-developed and implemented policies.
Evidence
The speaker described the Internet Society’s policymaker programme as going over how the Internet works, providing visibility on Internet standards development processes, and working with diplomats to understand how the Internet works, how it evolves, and the standards that underpin it . They offered to connect after the session to provide more information to the Mexican delegate .
Major Discussion Point
Cybersecurity Capacity Building
Agreed with
Discover MUN FoundationICANNForum of Incident Response and Security TeamsDeveloping Capacity LTDKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAfrican UnionNicaraguaAlgeriaTonga on behalf of the Forum of Pacific IslandsPapua New GuineaSouth AfricaSwitzerlandAustralia
on: Cybersecurity capacity building must be demand-driven, inclusive, and practically oriented, with particular attention to the needs of developing countries and small island developing states
112
WPM
408
Words
4 min
Time
Multi-stakeholder expertise must be systematically integrated into informal consultations, technical drafting, and policy implementation, with formal channels for grassroots data from developing nations
Arg. 1
Explanation
KICTANET called for structural integration of multi-stakeholder approaches, arguing that non-static expertise should be systematically woven into informal consultations, technical drafting, and policy implementation. They proposed that the DTGs be prioritised as actionable vehicles for problem-solving, with civil society and governments co-designing workable responses to critical infrastructure vulnerabilities and AI-amplified harms. They also called for formal channels to ingest grassroots data, particularly from developing nations, to ensure internal norms respond to real-world harms.
Evidence
The speaker noted that their statement reflects outcomes from consultations with a broader multi-stakeholder community conducted in preparation for the week . They proposed that DTGs be prioritised as vehicles for civil society and governments to co-design workable responses to critical infrastructure vulnerabilities and AI-amplified harms , and called for formal channels to ingest grassroots data particularly from developing nations .
Major Discussion Point
Stakeholder Participation and Accreditation in the Global Mechanism
Agreed with
Discover MUN FoundationICANNForum of Incident Response and Security TeamsInternet SocietyAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAccess NowCanadaJapanMexicoEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoChileGermanyInternational Chamber of CommerceChair Egriselda López
on: Meaningful and inclusive multi-stakeholder participation is essential to the global mechanism's success, not merely desirable
Capacity building must be human-centric and demand-driven, moving beyond high-level legal meetings to strengthen local incident response teams, defend civic space, and protect vulnerable communities
Arg. 2
Explanation
KICTANET argued that digital security is fundamentally about human safety, and therefore resources need to move beyond high-level legal meetings towards strengthening local incident response teams, defending civic space, and protecting vulnerable communities from technology-facilitated abuse. They called for delivery of human-centric, demand-driven capacity building as one of their key priorities for the mechanism. They also requested virtual meetings on a quarterly or half-yearly basis to make engagement real and ongoing.
Evidence
The speaker called for resources to move beyond high-level legal meetings towards strengthening local incident response teams, defending civic space, and protecting vulnerable communities from technology-facilitated abuse . They also requested that the Chair set up virtual meetings either quarterly or half-yearly to make engagement real .
Major Discussion Point
Cybersecurity Capacity Building
Agreed with
Discover MUN FoundationAssociation for Progressive CommunicationsInternetLabAccess Now
on: Protecting vulnerable and marginalised communities, including women, children, and human rights defenders, from cyber threats must be a priority for the mechanism
Civil society and technical organisations document empirical evidence of cyber harms, including those affecting vulnerable communities; locking out stakeholders injures the mechanism's effectiveness
Arg. 1
Explanation
The Association for Progressive Communications argued that it has often been civil society and academic research that has documented empirical evidence of cyber harms such as ransomware and other threats. They contended that the mechanism inflicted an injury on itself by initially locking out many stakeholders who are needed to contribute this evidence. They urged the mechanism to be both enabling and a safe space so that civil society, vulnerable communities, and security researchers can actively participate.
Evidence
The speaker noted that APC and its members have been organising training activities to equip stakeholders with the capacities needed to engage in global cybersecurity policy discussions . They cited APC network members’ documentation of how digital surveillance is used to intimidate, silence, and restrict women’s participation in civic and political life, based on interviews and testimonies from women in public-facing roles .
Major Discussion Point
Stakeholder Participation and Accreditation in the Global Mechanism
Agreed with
Discover MUN FoundationICANNForum of Incident Response and Security TeamsInternet SocietyKenya ICT Action NetworkRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAccess NowCanadaJapanMexicoEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoChileGermanyInternational Chamber of CommerceChair Egriselda López
on: Meaningful and inclusive multi-stakeholder participation is essential to the global mechanism's success, not merely desirable
Disagreed with
Discover MUN FoundationForum of Incident Response and Security TeamsInternet SocietyRoyal Institute of International Affairs (Chatham House) RepresentativeCanadaChileGermanyJapanEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoMexicoInternational Chamber of Commerce
on: Whether stakeholder accreditation objections without stated basis are consistent with the agreed inclusivity principle, and whether the current level of stakeholder participation is acceptable
State-led capacity-building programmes must address the disproportionate impact of cyber threats on vulnerable communities including women, LGBTQI+ people, and human rights defenders, whose unique threats are often unrecognised or unrecorded
Arg. 2
Explanation
APC argued that state-led and multilateral system capacity-building programmes must address the disproportionate impact of cyber threats faced by vulnerable communities including women, LGBTQI+ people, and human rights defenders. They noted that the unique threats faced by different communities in the Global South are often unrecognised or unrecorded and therefore not catered for in these discussions. Civil society can support this by providing evidence to better understand and mitigate these differentiated effects.
Evidence
The speaker noted that APC network members have documented, based on interviews and testimonies from women in public-facing roles, how digital surveillance is used to intimidate, silence, and restrict women’s participation in civic and political life . They called for gender-sensitive cybersecurity laws that holistically address digital violence and build appropriate rapid response mechanisms .
Major Discussion Point
Protection of Vulnerable and Marginalised Communities in Cyberspace
Agreed with
Discover MUN FoundationInternetLabAccess NowKenya ICT Action Network
on: Protecting vulnerable and marginalised communities, including women, children, and human rights defenders, from cyber threats must be a priority for the mechanism
The global mechanism should build on recognition of harms posed by the cyber mercenary hack-for-hire spyware sector and further examine the gendered impact of these actors on human rights defenders, journalists, and activists
Arg. 3
Explanation
APC called on the global mechanism to build on the recognition documented by the second OEWG of the harms posed by the global growth of the cyber mercenary hack-for-hire spyware sector. They specifically called for further work on the gendered impact of these efforts and how vulnerable communities are impacted by cyber mercenary actors. This was framed as essential to ensuring the mechanism addresses real-world harms affecting human rights defenders, journalists, and activists working on women and LGBTQI issues.
Evidence
The speaker referenced the second OEWG’s recognition of the harms posed by the global growth of the cyber mercenary hack-for-hire spyware sector and the harms it unleashes on human rights defenders, journalists, and activists working on women and LGBTQI issues . They called for further work on the gendered impact of these efforts .
Major Discussion Point
Protection of Vulnerable and Marginalised Communities in Cyberspace
The race for AI deployment in the public sector is impacting security vulnerabilities and affecting vulnerable communities; the mechanism should ensure that feminist and human rights approaches to technology inform AI and cybersecurity discussions
Arg. 4
Explanation
APC urged the mechanism and its DTGs to focus on how the current race for AI deployment, particularly in the public sector, is impacting security vulnerabilities and in turn affecting vulnerable communities. They argued that the mechanism should ensure that the lessons of the last two decades of human rights and feminist approaches to technology serve as a foundation for AI and cybersecurity discussions. They called on the mechanism to pay attention to how the race for AI development impacts the global majority, particularly in an information security context.
Evidence
The speaker urged attention to how the race for AI development impacts the global majority, particularly in an information security context , and called for the mechanism and DTGs to focus on how the current race for AI deployment in the public sector is impacting security vulnerabilities and affecting vulnerable communities . They argued that the lessons of the last two decades of human rights and feminist approaches to technology should be a foundation .
Major Discussion Point
Emerging Technologies, AI, and Evolving Cyber Threats
The mechanism risks being disconnected from operational reality if non-governmental stakeholders are excluded; states should draw more deliberately on multi-stakeholder expertise both within and beyond official sessions
Arg. 1
Explanation
Chatham House argued that the multi-stakeholder community is not a bystander but a partner in implementation, with industry, technical organisations, academia, and civil society already helping translate the framework into operational guidance, often in direct partnership with states. The challenge is not whether this expertise exists but whether it can be implemented and whether states will make full use of it. They encouraged states to draw more deliberately on that expertise, especially given that many stakeholders actively working on these issues have had their accreditation denied.
Evidence
The speaker noted that many stakeholders actively working on these issues have had their accreditation to the official meetings denied . They cited the Chatham House report on operationalisation of cyber capacity-building principles as an example of practical resources developed by the multi-stakeholder community , and noted that the existence of resources is not the same as the capacity to use them .
Major Discussion Point
Stakeholder Participation and Accreditation in the Global Mechanism
Agreed with
Discover MUN FoundationICANNForum of Incident Response and Security TeamsInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsInternetLabAccess NowCanadaJapanMexicoEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoChileGermanyInternational Chamber of CommerceChair Egriselda López
on: Meaningful and inclusive multi-stakeholder participation is essential to the global mechanism's success, not merely desirable
Disagreed with
Discover MUN FoundationForum of Incident Response and Security TeamsInternet SocietyAssociation for Progressive CommunicationsCanadaChileGermanyJapanEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoMexicoInternational Chamber of Commerce
on: Whether stakeholder accreditation objections without stated basis are consistent with the agreed inclusivity principle, and whether the current level of stakeholder participation is acceptable
The growing use of proxy actors, frontier AI models and their cybersecurity implications, and the wider availability of sophisticated cyber intrusion tools are changing the operational landscape; the mechanism must build shared understanding as technology evolves
Arg. 2
Explanation
Chatham House argued that while implementation is rightly the priority for this phase of the mechanism, the environment the framework is intended to govern continues to evolve. More states are adopting offensive cyber postures, proxy actors are increasingly used, frontier AI models have cybersecurity implications, and sophisticated cyber intrusion tools are more widely available. The mechanism therefore has an important role not only in supporting implementation of existing commitments but in continuing to build shared understanding of what responsible behaviour means as technology and state practice evolve.
Evidence
The speaker identified specific trends changing the operational landscape: more states adopting offensive cyber postures, the growing use of proxy actors, the emergence of frontier AI models and their implications for cybersecurity, and the wider availability of sophisticated cyber intrusion tools .
Major Discussion Point
Emerging Technologies, AI, and Evolving Cyber Threats
The Chatham House report on operationalising cyber capacity-building principles, the Geneva Dialogues manual, and sector-specific guidance from organisations like Cyber Peace Institute provide a meaningful body of practical resources for states
Arg. 3
Explanation
In response to Mexico's question about practical tools and resources, Chatham House highlighted several existing resources that states can draw upon. These include the Chatham House report providing concrete recommendations for operationalising cyber capacity-building principles, the Geneva Dialogues manual offering concrete guidance on implementing specific norms such as supply chain security and responsible vulnerability disclosure, and the Paris Call for Trust and Security in Cyberspace. The speaker noted that the multi-stakeholder community has been discussing mapping these resources and making them available to states.
Evidence
The speaker mentioned the Chatham House report on operationalisation of cyber capacity-building principles as highly relevant to DTG2 . They also cited the Geneva Dialogues manual offering concrete guidance on implementing specific norms like supply chain security and responsible vulnerability disclosure , the Paris Call for Trust and Security in Cyberspace , and sector-specific guidance from the Cyber Peace Institute (now called Protect NGO) on protecting the healthcare sector from cyber harm .
Major Discussion Point
Cybersecurity Capacity Building
Agreed with
Discover MUN FoundationICANNForum of Incident Response and Security TeamsDeveloping Capacity LTDInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsInternetLabAfrican UnionNicaraguaAlgeriaTonga on behalf of the Forum of Pacific IslandsPapua New GuineaSouth AfricaSwitzerlandAustralia
on: Cybersecurity capacity building must be demand-driven, inclusive, and practically oriented, with particular attention to the needs of developing countries and small island developing states
122
WPM
507
Words
4 min
Time
Capacity building must be sustainable, demand-driven, and inclusive, with better coordination among existing initiatives, support for states with limited resources, and cooperation on secure open-source cybersecurity tools
Arg. 1
Explanation
InternetLab called for discussions on sustainable, demand-driven, and inclusive cyber capacity building for DTG2, building on progress achieved in the OEWG and focusing on implementation. They identified three priorities: better coordination among existing initiatives, support for states with limited resources, and cooperation for secure open-source cybersecurity tools. They emphasised that effective capacity building requires meaningful engagement with the priorities of global majority states while drawing on the expertise of civil society, academia, the technical community, and the private sector.
Evidence
The speaker called for capacity-building initiatives to be accessible, context-sensitive, and responsive to those most affected by cyber threats . They emphasised that effective capacity building requires meaningful engagement with priorities of the global majority states, while drawing on the expertise of civil society, academia, the technical community, and the private sector .
Major Discussion Point
Cybersecurity Capacity Building
Agreed with
United StatesSwitzerlandTonga on behalf of the Forum of Pacific IslandsThe Dominican RepublicRepublic of KoreaSingaporeAustralia
on: The mechanism should focus on implementing the existing agreed framework and CBMs rather than creating new normative processes or relitigating settled ground
Research on online gender-based political violence against women politicians in Brazil documents how coordinated attacks disproportionately target women and historically marginalised communities, with clear implications for democratic participation and cybersecurity policy design
Arg. 2
Explanation
InternetLab argued that it is essential to examine how the use and misuse of ICTs affect individuals and communities differently, including specific risks faced by women and other historically marginalised groups. They presented their own research on online gender-based political violence against women politicians in Brazil as evidence of how coordinated attacks disproportionately target women and members of historically marginalised communities. They argued that an inclusive and evidence-based understanding of these differentiated impacts is necessary to ensure cybersecurity responses are both effective and rights-respecting.
Evidence
The speaker cited InternetLab’s own research on online gender-based political violence against women politicians in Brazil, which documented how coordinated attacks disproportionately target women and members of other historically marginalised communities, with clear implications for democratic participation and the design of effective rights-respecting cybersecurity responses .
Major Discussion Point
Protection of Vulnerable and Marginalised Communities in Cyberspace
Agreed with
Discover MUN FoundationAssociation for Progressive CommunicationsAccess NowKenya ICT Action Network
on: Protecting vulnerable and marginalised communities, including women, children, and human rights defenders, from cyber threats must be a priority for the mechanism
144
WPM
598
Words
4 min
Time
Out of 313 Internet shutdowns documented in 2025, 125 occurred in conflict situations; DTGs must make the human cost of critical infrastructure attacks visible and foreground the role of civil society in its defence
Arg. 1
Explanation
Access Now argued that DTGs must make the human cost of critical infrastructure attacks visible and foreground the role of civil society in its defence. They called for direct engagement with and protection of the human beings who make cybersecurity possible, including those who provide research and handle incident response, especially regarding digital security threats against the most vulnerable. They emphasised that this cannot remain an aspiration and that states must ensure national critical infrastructure protection frameworks give real operational effect to their human rights obligations.
Evidence
Access Now cited data from their documentation of 313 Internet shutdowns in 2025, of which 125 occurred in situations of conflict, impeding access to essential services and communication . They also aligned with the statement made by ICRC regarding the alarming range of ICT operations that have disabled the provision of essential services for civilian populations .
Major Discussion Point
Protection of Vulnerable and Marginalised Communities in Cyberspace
Agreed with
Discover MUN FoundationAssociation for Progressive CommunicationsInternetLabKenya ICT Action Network
on: Protecting vulnerable and marginalised communities, including women, children, and human rights defenders, from cyber threats must be a priority for the mechanism
States must ensure national critical infrastructure protection frameworks give real operational effect to human rights obligations while protecting tools like strong encryption and independent research capabilities that enable civil society to contribute
Arg. 2
Explanation
Access Now argued that states must ensure their national critical infrastructure protection frameworks give real operational effect to their human rights obligations. They specifically called for the protection of tools like strong encryption and independent research capabilities that enable civil society to contribute to cybersecurity. This was framed as a necessary condition for civil society to play its role in defending critical infrastructure.
Evidence
The speaker called for states to ensure that national critical infrastructure protection frameworks give real operational effect to their human rights obligations while protecting tools like strong encryption and independent research capabilities that enable civil society to contribute .
Major Discussion Point
Protection of Vulnerable and Marginalised Communities in Cyberspace
AI tools are beset by security vulnerabilities with grave consequences for data confidentiality, information integrity, and system availability; a human rights-respecting approach and recognition of AI's specific security risks must be central to DTG discussions
Arg. 3
Explanation
Access Now called for specific recognition of how AI tools are beset by glaring security vulnerabilities that have grave consequences for the confidentiality of data, information integrity, and access to and availability of systems. They argued that a human rights-respecting approach can help solve these problems, and that when human rights are successfully placed at the centre of discussions on AI, the outcomes shift to concrete and enforceable protections for those most at risk. They also called for DTG discussions not to duplicate existing UN processes on AI but to build on them with a focus on the unique value of the global mechanism.
Evidence
The speaker cited the experience of other UN processes where placing human rights at the centre of AI discussions resulted in concrete and forcible protections for those most at risk . They called for specific recognition of how AI tools are beset by glaring security vulnerabilities with grave consequences for data confidentiality, information integrity, and system availability .
Major Discussion Point
Emerging Technologies, AI, and Evolving Cyber Threats
139
WPM
615
Words
4 min
Time
The number of objections to stakeholder accreditation, including organisations from Latin America, Africa, and other regions, deprives the mechanism of critical cross-regional expertise and must be addressed
Arg. 1
Explanation
Canada welcomed the interventions by accredited stakeholders but noted that they were too few, and that the mechanism would have benefited from much more robust cross-regional representation if stakeholders had not been vetoed. They specifically named stakeholders from Mexico, Brazil, Peru, Panama, Ghana, Nigeria, and South Africa as having been excluded. Canada expressed hope for more meaningful and inclusive opportunities for all stakeholders to engage in December.
Evidence
The speaker specifically named stakeholders from Mexico, Brazil, Peru, Panama, Ghana, Nigeria, and South Africa as having been vetoed from participation . They noted that a number of interventions delivered demonstrated the readiness and willingness of the multi-stakeholder community to contribute further on practical matters in the context of the DTGs .
Major Discussion Point
Stakeholder Participation and Accreditation in the Global Mechanism
Agreed with
Discover MUN FoundationICANNForum of Incident Response and Security TeamsInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAccess NowJapanMexicoEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoChileGermanyInternational Chamber of CommerceChair Egriselda López
on: Meaningful and inclusive multi-stakeholder participation is essential to the global mechanism's success, not merely desirable
Disagreed with
Discover MUN FoundationForum of Incident Response and Security TeamsInternet SocietyAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeChileGermanyJapanEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoMexicoInternational Chamber of Commerce
on: Whether stakeholder accreditation objections without stated basis are consistent with the agreed inclusivity principle, and whether the current level of stakeholder participation is acceptable
Canada's participation in tabletop exercises during FIFA World Cup preparations, coordinating with Mexico, CISA, and US CERTs, illustrates how CBM operationalisation through simulation exercises can build practical cooperation
Arg. 2
Explanation
Canada provided a concrete example of CBM operationalisation through its experience as a host country of the FIFA World Cup, where it organised tabletop exercises with cities hosting matches and critical infrastructure operators. They also collaborated with Mexico, CISA, and US CERTs by helping to coordinate relevant information sharing. Canada used this example to illustrate how simulation exercises can build practical cooperation and serve as a model for discussions in the December DTGs.
Evidence
The speaker described organising tabletop exercises with cities hosting FIFA World Cup matches as well as critical infrastructure operators, and collaborating with Mexico, CISA, and US CERTs by helping to coordinate relevant information sharing . They also noted Canada’s recent publication of responses to the UNIDIR survey on implementation of norms, international law, CBMs, and capacity building as an example of CBM-3 on information sharing .
Major Discussion Point
Confidence-Building Measures (CBMs) and the Global Points of Contact Directory
Agreed with
Tonga on behalf of the Forum of Pacific IslandsEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoRepublic of KoreaCosta RicaAlbaniaItalyKiribatiUnited KingdomSerbiaSouth AfricaSingaporeNaoeroPapua New Guinea
on: The Global Points of Contact (POC) Directory is a significant and practical confidence-building measure that must be actively maintained, exercised, and used in good faith
110
WPM
115
Words
1 min
Time
Japan strongly values the multi-stakeholder approach and hopes to further strengthen public-private collaboration within the UN framework through expert briefings and interactive discussions
Arg. 1
Explanation
Japan argued that as cyber threats become increasingly sophisticated and complex, it is critical to draw on the private sector's expertise for recognising threats and implementing concrete countermeasures. Japan attaches great importance to a multi-stakeholder approach in the global mechanism and highly values the session with stakeholders. They expressed hope to further strengthen public-private collaboration within the UN framework through expert briefings and interactive discussions, especially including the DTGs.
Evidence
The speaker noted that Japan attaches great importance to a multi-stakeholder approach in the global mechanism and highly values the session . They expressed hope that with a wide range of stakeholders’ participation, member states’ awareness and understanding of cybersecurity will deepen further .
Major Discussion Point
Stakeholder Participation and Accreditation in the Global Mechanism
Agreed with
Discover MUN FoundationICANNForum of Incident Response and Security TeamsInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAccess NowCanadaMexicoEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoChileGermanyInternational Chamber of CommerceChair Egriselda López
on: Meaningful and inclusive multi-stakeholder participation is essential to the global mechanism's success, not merely desirable
Disagreed with
Discover MUN FoundationForum of Incident Response and Security TeamsInternet SocietyAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeCanadaChileGermanyEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoMexicoInternational Chamber of Commerce
on: Whether stakeholder accreditation objections without stated basis are consistent with the agreed inclusivity principle, and whether the current level of stakeholder participation is acceptable
131
WPM
303
Words
2 min
Time
Stakeholder participation is fundamental; Mexico urges stakeholders to draft specific inputs for DTG discussions and share examples of tools, guides, and methodologies to support framework implementation
Arg. 1
Explanation
Mexico welcomed the stakeholder segment and noted that the practice of displaying organisations' names on screens gives visibility to their valuable contributions and reflects the importance the mechanism attaches to meaningful participation. They urged stakeholders to consider drafting specific inputs for the issues under discussion in the December DTG meetings, so these can be used not only in meetings but also for technical analyses in member states' capitals. Mexico also posed a question asking stakeholders to share examples of ongoing work, guides, methodologies, models, or good practices to support states in implementing the responsible behaviour framework, particularly those that could benefit developing countries.
Evidence
The speaker welcomed the practice of displaying organisations’ names on screens as reflecting the importance of meaningful stakeholder participation . They urged stakeholders to draft specific inputs for DTG discussions and asked for examples of work that could benefit a developing country like Mexico and that takes account of their perspectives .
Major Discussion Point
Stakeholder Participation and Accreditation in the Global Mechanism
Agreed with
Discover MUN FoundationICANNForum of Incident Response and Security TeamsInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAccess NowCanadaJapanEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoChileGermanyInternational Chamber of CommerceChair Egriselda López
on: Meaningful and inclusive multi-stakeholder participation is essential to the global mechanism's success, not merely desirable
Disagreed with
Discover MUN FoundationForum of Incident Response and Security TeamsInternet SocietyAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeCanadaChileGermanyJapanEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoInternational Chamber of Commerce
on: Whether stakeholder accreditation objections without stated basis are consistent with the agreed inclusivity principle, and whether the current level of stakeholder participation is acceptable
157
WPM
1043
Words
7 min
Time
The EU welcomes stakeholder contributions and encourages continued cooperation with states on capacity building, research, and implementation of the UN Framework of Responsible State Behaviour
Arg. 1
Explanation
The EU thanked stakeholders for participating despite a challenging environment and expressed strong interest in their contributions, both in statements made during the session and in the run-up to it. They encouraged stakeholders to continue contributing by enhancing cooperation with states, working together on the ground, building capacities, and implementing the UN Framework of Responsible State Behaviour through research, training, and dedicated activities. The EU also noted the value of having stakeholders contribute to specific challenges to be discussed in the dedicated thematic groups.
Evidence
The speaker noted that having stakeholders dedicate their interventions to the topic being discussed at that moment is very useful to bring stakeholders and states closer to each other . They encouraged stakeholders to continue contributing through enhancing cooperation with states, building capacities, and implementing the UN Framework through research, training, and dedicated activities .
Major Discussion Point
Stakeholder Participation and Accreditation in the Global Mechanism
Agreed with
Discover MUN FoundationICANNForum of Incident Response and Security TeamsInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAccess NowCanadaJapanMexicoChileGermanyInternational Chamber of CommerceChair Egriselda López
on: Meaningful and inclusive multi-stakeholder participation is essential to the global mechanism's success, not merely desirable
Disagreed with
Discover MUN FoundationForum of Incident Response and Security TeamsInternet SocietyAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeCanadaChileGermanyJapanMexicoInternational Chamber of Commerce
on: Whether stakeholder accreditation objections without stated basis are consistent with the agreed inclusivity principle, and whether the current level of stakeholder participation is acceptable
The EU supports operationalising the eight agreed CBMs, including integrating the POC directory into the global mechanism's portal, organising seminars and workshops, and promoting information exchange on cooperation and partnerships
Arg. 2
Explanation
The EU argued that the work on confidence-building measures under the global mechanism should focus as a priority on the operationalisation of the voluntary non-exhaustive list of CBMs agreed under the OEWG. They supported integrating the POC directory into the global mechanism's portal and exploring its further development based on lessons learned. They also outlined specific ways to operationalise other CBMs, including sharing national ICT strategies and policies, promoting information exchange on cooperation and partnerships, and organising regular seminars, workshops, and training programmes.
Evidence
The speaker outlined specific CBM operationalisation activities, including sharing national ICT strategies, policies, legislation, and best practices on a voluntary basis under DTG1 in line with CBM-3 , promoting information exchange on cooperation and partnerships in line with CBM-5 , and organising regular seminars, workshops, and training programmes on ICT security in line with CBM-6 . They also supported integrating the POC directory into the global mechanism’s portal .
Major Discussion Point
Confidence-Building Measures (CBMs) and the Global Points of Contact Directory
Agreed with
SwitzerlandAlbaniaItalyKiribatiTonga on behalf of the Forum of Pacific IslandsRepublic of KoreaSingaporeNaoeroThe Dominican Republic
on: Regional organisations play a vital complementary role in implementing CBMs and international law frameworks, and their experiences should inform global-level discussions
136
WPM
139
Words
1 min
Time
Chile rejects the volume of objections to stakeholder participation, including from organisations in its own region, and affirms that diverse stakeholder voices are essential to reflect ground-level realities
Arg. 1
Explanation
Chile expressed thanks to stakeholders for their participation and affirmed that their participation is fundamental, bringing practical experience, specialised knowledge, and concrete challenges that can help support effective implementation of the mechanism. Chile explicitly rejected the amount of objections voiced against stakeholder participation, including from institutions in its own region. They emphasised that diverse stakeholder voices are essential to reflect the reality on the ground.
Evidence
The speaker stated that Chile rejects the amount of objections voiced on stakeholder participation, including from institutions from their own region . They affirmed that stakeholders bring practical experience, specialised knowledge, and concrete challenges that can help support effective implementation of the mechanism .
Major Discussion Point
Stakeholder Participation and Accreditation in the Global Mechanism
Agreed with
Discover MUN FoundationICANNForum of Incident Response and Security TeamsInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAccess NowCanadaJapanMexicoEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoGermanyInternational Chamber of CommerceChair Egriselda López
on: Meaningful and inclusive multi-stakeholder participation is essential to the global mechanism's success, not merely desirable
Disagreed with
Discover MUN FoundationForum of Incident Response and Security TeamsInternet SocietyAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeCanadaGermanyJapanEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoMexicoInternational Chamber of Commerce
on: Whether stakeholder accreditation objections without stated basis are consistent with the agreed inclusivity principle, and whether the current level of stakeholder participation is acceptable
179
WPM
146
Words
48 s
Time
Germany highlights that organisations blocked from participation, such as Interface with its CBM implementation survey, have produced work directly relevant to the mechanism's discussions
Arg. 1
Explanation
Germany echoed colleagues from the EU, Canada, Mexico, and Chile in valuing the interactive exchange with stakeholders and regretting the limited number of participants. They specifically highlighted a piece of work presented by an organisation that was not allowed to attend—Interface—which produced a study and survey comparing the global state of CBM implementation. Germany considered this survey and analysis quite useful for the interactions and engagement taking place in the mechanism.
Evidence
The speaker specifically named the organisation Interface and its study and survey comparing the global state of CBM implementation as an example of relevant work produced by an organisation that was not allowed to participate . They noted this as illustrating the cost of excluding stakeholders from the mechanism’s formal sessions .
Major Discussion Point
Stakeholder Participation and Accreditation in the Global Mechanism
Agreed with
Discover MUN FoundationICANNForum of Incident Response and Security TeamsInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAccess NowCanadaJapanMexicoEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoChileInternational Chamber of CommerceChair Egriselda López
on: Meaningful and inclusive multi-stakeholder participation is essential to the global mechanism's success, not merely desirable
Disagreed with
Discover MUN FoundationForum of Incident Response and Security TeamsInternet SocietyAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeCanadaChileJapanEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoMexicoInternational Chamber of Commerce
on: Whether stakeholder accreditation objections without stated basis are consistent with the agreed inclusivity principle, and whether the current level of stakeholder participation is acceptable
154
WPM
222
Words
1 min
Time
Existing international law applies to activities in cyberspace and is fit for purpose; further discussion should be anchored in concrete threats and practical tools, not used as a vehicle for treaty-making or relitigating settled ground
Arg. 1
Explanation
The United States reiterated its view that existing international law applies to activities in cyberspace and remains fit for purpose, and stated it will not support language suggesting new binding obligations are required or that existing legal obligations are insufficient. They argued that any proposal to use DTG1 to relitigate international law as a vehicle for treaty-making duplicates work already done and keeps discussions stagnant. They called for further discussion of international law to be anchored in concrete threats and practical tools for addressing them, and emphasised that the mechanism should focus on implementing the 11 norms states have already committed to.
Evidence
The speaker stated that the United States has shown extreme flexibility over the course of discussions in the OEWG but will not agree to a discussion topic that will be hijacked for treaty-making purposes . They argued that previous discussions on international law have demonstrated that existing legal obligations remain fit for purpose .
Major Discussion Point
Application of International Law to Cyberspace
Agreed with
SwitzerlandTonga on behalf of the Forum of Pacific IslandsThe Dominican RepublicRepublic of KoreaSingaporeAustraliaInternetLab
on: The mechanism should focus on implementing the existing agreed framework and CBMs rather than creating new normative processes or relitigating settled ground
Disagreed with
AustraliaSwitzerlandNicaraguaAlgeria
on: Whether the scope of international law discussions in the DTGs should be broad and exploratory or narrowly anchored in concrete threats and practical implementation tools
108
WPM
667
Words
6 min
Time
IHL applies to ICT activities in armed conflict; states should focus discussions on how IHL limits ICT operations causing non-physical damage and on protecting civilian ICT infrastructure and data
Arg. 1
Explanation
The ICRC argued that when ICT capabilities are used for military purposes in situations of armed conflict, their use must comply with existing rules of IHL. They called on states to focus especially on the limits that IHL imposes on ICT activities that result in non-physical damage, noting that in today's ICT-reliant societies it is critical to protect ICT systems that underpin civilian life and digital data against damage and destruction. They also called on states to consider whether existing international law provides sufficient safeguards against harm from increasingly autonomous ICT capabilities.
Evidence
The speaker cited the October 2024 resolution of the 34th International Conference of the Red Cross and Red Crescent, which affirmed that in situations of armed conflict, IHL rules and principles serve to protect civilian populations and other protected persons and objects, including against risks arising from ICT activities . They also invited states to build on in-depth discussions held by over 100 states and other stakeholders under the ICT mainstream of the Global Initiative on IHL .
on: Existing international law, including IHL and international human rights law, applies to state conduct in cyberspace and discussions should continue to build common understanding of how it applies in practice
ICRC calls on states to consider whether existing international law provides sufficient safeguards against harm from increasingly autonomous ICT capabilities, or whether additional limits are needed
Arg. 2
Explanation
The ICRC noted that with conflict dynamics and technology evolving at great speed, states should focus parts of the dedicated thematic groups on how international law addresses new developments and technologies. They specifically called on member states to consider whether existing international law provides sufficient safeguards against the harm that increasingly autonomous ICT capabilities can cause, or whether additional limits are needed. This was framed as a question requiring careful consideration given that IHL applies to ICT operations in armed conflict including those involving AI.
Evidence
The speaker noted that the use of artificial intelligence in ICT activities may increase their speed, scale, and potential for harm . They called on member states to consider whether existing international law provides sufficient safeguards against the harm that increasingly autonomous ICT capabilities can cause or whether additional limits are needed .
Major Discussion Point
Emerging Technologies, AI, and Evolving Cyber Threats
Disagreed with
United StatesAlgeriaNicaragua
on: Whether existing international law is sufficient or whether new legally binding instruments are needed to govern state behaviour in cyberspace
164
WPM
1409
Words
9 min
Time
Switzerland supports concrete discussions on real-world scenarios, particularly on protecting critical infrastructure such as hospitals and water systems, and highlights the ICT work stream under the Global IHL Initiative as a valuable complementary platform
Arg. 1
Explanation
Switzerland argued that the new mechanism offers the opportunity to turn statements and written positions on international law into lively and substantial discussions based on real-world scenarios in the DTGs, which would be an innovative step forward. They specifically supported concrete discussions on the protection of critical infrastructure such as hospitals, water systems, and energy networks from malicious ICT operations, both in times of peace and in armed conflict. They highlighted the ICT work stream under the Global Initiative to Galvanise Political Commitment to IHL as a valuable complementary platform for substantive discussions.
Evidence
The speaker noted that more than 40 states have issued positions on international law in cyberspace and more than 36 national and two regional positions have been published . They highlighted Switzerland’s co-chairmanship, together with Ghana, Luxembourg, and Mexico, of the ICT work stream of the Global IHL Initiative , and described a meeting of a cross-regional group on Mount Rigi in Switzerland where 15 states discussed the concrete application of international law and IHL in cyberspace using real-world scenarios .
on: Existing international law, including IHL and international human rights law, applies to state conduct in cyberspace and discussions should continue to build common understanding of how it applies in practice
Disagreed with
United StatesAustraliaNicaraguaAlgeria
on: Whether the scope of international law discussions in the DTGs should be broad and exploratory or narrowly anchored in concrete threats and practical implementation tools
More than 40 states have issued positions on international law in cyberspace and more than 36 national positions have been published, demonstrating broad appetite for substantive discussions grounded in real-world scenarios in the DTGs
Arg. 2
Explanation
Switzerland used the large number of states that have issued positions on international law in cyberspace as evidence of broad appetite for continuing and deepening these discussions. They argued that this demonstrates great interest in continuing discussions, but not in any manner—the mechanism should enable innovative, scenario-based discussions in the DTGs. They also invited states to use the ICRC's working paper on preventing ICT threats to the civilian population as a basis for focused discussions on IHL.
Evidence
The speaker noted that more than 40 states have issued positions on the applicability of international law in cyberspace, and that more than 36 national and two regional positions have been published . They invited states to use the ICRC’s working paper entitled ‘Preventing ICT Threats to the Civilian Population in Times of Armed Conflict: Six Humanitarian and Legal Priorities’ as a basis for focused discussions on IHL .
Major Discussion Point
Application of International Law to Cyberspace
Switzerland emphasises that the challenge is not to develop new CBMs but to implement those already agreed; regional and sub-regional organisations play a key role and a structured exchange between the global mechanism and regional organisations should be established
Arg. 3
Explanation
Switzerland argued that the challenge is not to develop new confidence-building measures but to implement those already agreed effectively, with efforts focusing on translating commitments into practice, sharing experiences, and identifying implementation gaps and good practices. They emphasised that regional and sub-regional organisations play a particularly important role in promoting dialogue, facilitating capacity building, and adapting CBMs to regional contexts. They called for the establishment of a structured exchange between the global mechanism and regional and sub-regional organisations.
Evidence
The speaker referenced a non-paper submitted to the OEWG in June 2025 on the role of regional organisations in implementing the UN Framework for Responsible State Behaviour and Cybersecurity, one of whose key recommendations is the establishment of a structured exchange between the global mechanism and regional and sub-regional organisations . They also cited a June 2026 meeting organised by the OSCE with German support as demonstrating the added value of such exchanges between regional organisations .
Major Discussion Point
Confidence-Building Measures (CBMs) and the Global Points of Contact Directory
Agreed with
European Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAlbaniaItalyKiribatiTonga on behalf of the Forum of Pacific IslandsRepublic of KoreaSingaporeNaoeroThe Dominican Republic
on: Regional organisations play a vital complementary role in implementing CBMs and international law frameworks, and their experiences should inform global-level discussions
152
WPM
553
Words
4 min
Time
Australia supports consolidating common understandings on how international human rights law, the law of state responsibility, and IHL apply in cyberspace, using concrete incident scenarios to build confidence and shared understanding
Arg. 1
Explanation
Australia argued that while the OEWG's 2025 final report provides a strong foundation, it did not reflect areas in which states had worked hard to identify common ground, including on the application of international human rights law, the law of state responsibility, and IHL. They called for the mechanism to take up the opportunity to consolidate common understandings between states to actionable effect, leveraging the integrated and inclusive platform of the DTGs. Australia's experience has shown that applying international law to concrete cyber incident scenarios helps build confidence and shared understanding.
Evidence
The speaker noted that the two cross-regional groups of states on international law made significant contributions to advance and document discussions in the OEWG, and that the number and diversity of states joining their statements demonstrates broad appetite to prioritise international law in this mechanism . They cited Australia’s own experience showing that applying international law to concrete cyber incident scenarios helps build confidence and shared understanding and demonstrates the practical value of the existing legal framework .
on: Existing international law, including IHL and international human rights law, applies to state conduct in cyberspace and discussions should continue to build common understanding of how it applies in practice
Disagreed with
United StatesSwitzerlandNicaraguaAlgeria
on: Whether the scope of international law discussions in the DTGs should be broad and exploratory or narrowly anchored in concrete threats and practical implementation tools
130
WPM
225
Words
2 min
Time
Nicaragua calls for continued careful, inclusive, intergovernmental debate on international law in cyberspace, keeping open the possibility of legally binding instruments and coupling discussions with effective capacity building and technology transfer
Arg. 1
Explanation
Nicaragua argued that the particularities of cyberspace require the debate on the application of international law to continue in a careful, inclusive, and intergovernmental manner, building a common understanding while avoiding interpretations that could favour the militarisation of cyberspace. They cited the UN Convention against Cybercrime as evidence that the international community can make headway through dialogue and consensus towards multilateral instruments. They called for this process to be coupled with effective international cooperation, capacity building, and technology transfer.
Evidence
The speaker cited the UN Convention against Cybercrime as demonstrating that against new challenges derived from the use of ICTs, the international community can make headway through dialogue and consensus towards multilateral instruments . They noted that for developing countries, this process must be coupled with effective international cooperation, capacity building, and technology transfer .
on: Existing international law, including IHL and international human rights law, applies to state conduct in cyberspace and discussions should continue to build common understanding of how it applies in practice
Disagreed with
United StatesAustraliaSwitzerlandAlgeria
on: Whether the scope of international law discussions in the DTGs should be broad and exploratory or narrowly anchored in concrete threats and practical implementation tools
Algeria supports the elaboration of a legally binding international instrument on state behaviour in cyberspace, arguing that the unique attributes of cyberspace demand legal clarity rather than interpretative ambiguity
Arg. 1
Explanation
Algeria argued that while discussions on how existing international law applies to cyberspace remain important, the international community should now move towards a more focused and practical stage of collectively negotiating how states must behave in cyberspace. They argued that the unique attributes of cyberspace—including the speed and sophistication of attacks, difficulty of attribution, vulnerability of critical infrastructure, and evolving nature of threats—demand legal clarity and certainty rather than interpretative ambiguity. They noted that since the international community has successfully agreed on 11 non-binding norms, it should certainly be able to elaborate legally binding rules.
Evidence
The speaker endorsed the Common African Position on the Application of International Law to the Use of ICTs as the basis for Algeria’s engagement . They argued that since the international community has successfully and collectively agreed on 11 non-binding norms, it should certainly be able to elaborate legally binding rules , and that a legally binding instrument would provide the global mechanism with institutional vitality and the ability to translate decades of productive discussions into meaningful outcomes .
on: Existing international law, including IHL and international human rights law, applies to state conduct in cyberspace and discussions should continue to build common understanding of how it applies in practice
Disagreed with
United StatesAustraliaSwitzerlandNicaragua
on: Whether the scope of international law discussions in the DTGs should be broad and exploratory or narrowly anchored in concrete threats and practical implementation tools
104
WPM
414
Words
4 min
Time
The African Union's Common African Position provides a shared foundation for AU member states to engage in global cyber law discussions, and capacity building on the applicability of international law is an important area for the global mechanism
Arg. 1
Explanation
The African Union highlighted its Common African Position on the Application of International Law to the Use of ICTs in Cyberspace as an important milestone in strengthening Africa's collective voice on international cyber policy. They noted that some AU member states are already starting to develop their own national positions, demonstrating meaningful contributions to the evolution of state practice. The AU considered capacity building on the applicability of international law to be an important area of work for the global mechanism, including within the dedicated thematic groups.
Evidence
The speaker noted that the AU Commission convened a workshop from 1st to 3rd June 2026 in Addis Ababa to strengthen the capacity of AU member states to develop national positions on the application of international law to cyberspace . They described the workshop as reflecting the growing demand among AU member states for practical support for capacity building .
on: Existing international law, including IHL and international human rights law, applies to state conduct in cyberspace and discussions should continue to build common understanding of how it applies in practice
Capacity building for international law in cyberspace is an important area for the global mechanism; the AU Commission convened a workshop to strengthen member states' capacity to develop national positions on the application of international law
Arg. 2
Explanation
The African Union argued that capacity building is not only about strengthening technical capacity but also includes building legal, diplomatic, and institutional expertise to enable all member states to participate effectively and on an equal footing in the development and implementation of international law in cyberspace. The AU Commission convened a workshop in Addis Ababa in June 2026 specifically to strengthen AU member states' capacity to develop national positions on the application of international law to cyberspace. The AU considered this an important area of work for the global mechanism.
Evidence
The speaker described the AU Commission’s workshop from 1st to 3rd June 2026 in Addis Ababa as aimed at strengthening the capacity of AU member states to develop national positions on the application of international law to cyberspace . They noted the workshop reflected growing demand among AU member states for practical support .
Major Discussion Point
Cybersecurity Capacity Building
Agreed with
Discover MUN FoundationICANNForum of Incident Response and Security TeamsDeveloping Capacity LTDInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabNicaraguaAlgeriaTonga on behalf of the Forum of Pacific IslandsPapua New GuineaSouth AfricaSwitzerlandAustralia
on: Cybersecurity capacity building must be demand-driven, inclusive, and practically oriented, with particular attention to the needs of developing countries and small island developing states
143
WPM
488
Words
3 min
Time
The eight voluntary global CBMs adopted by the OEWG constitute a fundamental pillar of the responsible state behaviour framework; the mechanism should now focus on their practical and inclusive operationalisation, supported by a working paper from the cross-regional Confidence Builders group
Arg. 1
Explanation
The Dominican Republic, speaking on behalf of the cross-regional Global Mechanism Confidence Builders group, reaffirmed commitment to the eight voluntary global CBMs adopted by the previous OEWG and argued that the establishment of the global mechanism provides an important opportunity to move progressively from their endorsement towards practical and inclusive operationalisation. They noted that CBMs support implementation of the different pillars of the framework by strengthening communication, facilitating cooperation, increasing transparency, and helping states prevent and manage risks. The group announced it is preparing a working paper ahead of the December session presenting best practices and a comparative perspective on how CBMs are operationalised in practice.
Evidence
The speaker listed the 17 states comprising the cross-regional Confidence Builders group . They announced that the group is preparing a working paper ahead of the December session that will highlight the practical value of CBMs, present best practices, and offer a comparative perspective of how CBMs are operationalised in practice , with the paper expected to be ready ahead of the December session and uploaded to the website .
Major Discussion Point
Confidence-Building Measures (CBMs) and the Global Points of Contact Directory
Agreed with
SwitzerlandEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAlbaniaItalyKiribatiTonga on behalf of the Forum of Pacific IslandsRepublic of KoreaSingaporeNaoero
on: Regional organisations play a vital complementary role in implementing CBMs and international law frameworks, and their experiences should inform global-level discussions
113
WPM
340
Words
3 min
Time
For Pacific small island developing states, CBMs are among the most immediately practical elements of the framework; the Global POC Directory must be actively maintained and used in good faith, with due regard for the capacity constraints of smaller states
Arg. 1
Explanation
Tonga, speaking on behalf of the Pacific Islands Forum, argued that CBMs are particularly important for regions and states with limited capacity, helping build trust, reduce the risk of misperception and escalation, and create channels for communication before, during, and after cyber incidents. They emphasised that the focus at this stage should be on implementing existing CBMs, requiring capacity building, technical assistance, guidance, exercises, and sustained engagement. They called for the Global POC Directory to be actively maintained and used in good faith, with due regard for the capacity constraints of smaller states.
Evidence
The speaker cited the Pacific Cybersecurity Operational Network as an example of a regional CBM that is especially valuable, including through third-to-third cooperation, national and regional exercises, practical incident communication procedures, and opportunities for officials and technical experts to build relationships before a crisis occurs . They called for a shared understanding that the POC network be used proportionately, purposefully, and with due regard for the capacity constraints of smaller states .
Major Discussion Point
Confidence-Building Measures (CBMs) and the Global Points of Contact Directory
Agreed with
SwitzerlandEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAlbaniaItalyKiribatiRepublic of KoreaSingaporeNaoeroThe Dominican Republic
on: Regional organisations play a vital complementary role in implementing CBMs and international law frameworks, and their experiences should inform global-level discussions
Disagreed with
Republic of KoreaUnited KingdomKiribatiSingapore
on: Whether the Global POC Directory should be used flexibly and broadly or strictly in accordance with its original mandate, and whether its use should be constrained to avoid misuse
The UN POC directory is one of the most significant OEWG achievements; it must be used responsibly and in good faith, and should not be misused for purposes inconsistent with its original intent of facilitating cooperative communication
Arg. 1
Explanation
The Republic of Korea argued that the establishment of the UN Global Mechanism Point of Contact Directory is one of the most significant achievements of the OEWG, with the potential to strengthen confidence among states by facilitating timely and effective communication during cyber incidents and crises. They called for the continued operation of the POC directory, including regular exercises and capacity-building activities. However, they also emphasised that the directory must be used responsibly and in good faith, consistent with its purpose, and should not be misused or exploited for purposes inconsistent with its original intent.
Evidence
The speaker stated that the Republic of Korea believes the establishment of the UN Global Mechanism Point of Contact Directory to be one of the most significant achievements of the OEWG . They emphasised that the POC directory should be used responsibly and in good faith, consistent with its purpose of facilitating cooperation and effective communication among member states .
Major Discussion Point
Confidence-Building Measures (CBMs) and the Global Points of Contact Directory
Agreed with
SwitzerlandEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAlbaniaItalyKiribatiTonga on behalf of the Forum of Pacific IslandsSingaporeNaoeroThe Dominican Republic
on: Regional organisations play a vital complementary role in implementing CBMs and international law frameworks, and their experiences should inform global-level discussions
Disagreed with
United KingdomTonga on behalf of the Forum of Pacific IslandsKiribatiSingapore
on: Whether the Global POC Directory should be used flexibly and broadly or strictly in accordance with its original mandate, and whether its use should be constrained to avoid misuse
164
WPM
450
Words
3 min
Time
Costa Rica supports the Global POC Directory as a valuable operational tool for managing cross-border incidents and reducing misunderstandings, and emphasises that legal transparency through publishing national positions on international law also serves as a CBM
Arg. 1
Explanation
Costa Rica argued that confidence-building measures should be understood as practical preventive tools achieved through the creation of known, accessible, and functional communication channels prior to the onset of a crisis. They highlighted the utility of the Global Directory of Points of Contact as a valuable operational tool for facilitating urgent communication, managing cross-border incidents, reducing misunderstandings, and preventing escalation. They also argued that legal transparency—specifically, publishing national positions on the application of international law in cyberspace—serves as a confidence-building measure in its own right.
Evidence
The speaker noted that Costa Rica has published its national position on the application of international law in cyberspace, stating its conviction that this type of transparency helps reduce uncertainty, strengthen shared expectations, and facilitate dialogue among states . They called for the POC Directory to be kept up-to-date, tested periodically, and integrated with actual national capabilities including computer security incident response .
Major Discussion Point
Confidence-Building Measures (CBMs) and the Global Points of Contact Directory
Agreed with
Tonga on behalf of the Forum of Pacific IslandsEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoRepublic of KoreaAlbaniaItalyKiribatiUnited KingdomSerbiaSouth AfricaSingaporeNaoeroPapua New GuineaCanada
on: The Global Points of Contact (POC) Directory is a significant and practical confidence-building measure that must be actively maintained, exercised, and used in good faith
124
WPM
786
Words
6 min
Time
Albania's experience shows that CBMs work through layered cooperation—political, diplomatic, and technical—across the UN, EU, OSCE, ITU, and bilateral relations, with each layer reinforcing the others and building capacity that in turn builds trust
Arg. 1
Explanation
Albania argued that as a country facing persistent malicious cyber activities against its critical infrastructure, it knows firsthand that trust built through practical cooperation determines how quickly and effectively states can respond when an incident occurs. Albania's approach to CBMs rests on cooperation across several layers—political, diplomatic, and technical—through the UN, EU, OSCE, ITU, Western Balkans, and bilateral relations, with each reinforcing the others. They described this as a virtuous cycle: cooperation builds capacity, capacity builds trust, and trust builds still more cooperation.
Evidence
The speaker described Albania’s participation in the UN Global POC Directory, the Women in Cyber Fellowship, OSCE informal working group on cyber CBMs, ITU joint projects, and numerous regional initiatives including the Adriatic Five meetings, Western Balkan Policy Roundtable, and Western Balkan Cyber Dialogue . They noted that Albania became the newest member of the International Coalition on Cybersecurity Workforce the previous day, joining the UK, Canada, UAE, Ghana, Japan, Singapore, and Nigeria .
Major Discussion Point
Confidence-Building Measures (CBMs) and the Global Points of Contact Directory
Agreed with
SwitzerlandEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoItalyKiribatiTonga on behalf of the Forum of Pacific IslandsRepublic of KoreaSingaporeNaoeroThe Dominican Republic
on: Regional organisations play a vital complementary role in implementing CBMs and international law frameworks, and their experiences should inform global-level discussions
126
WPM
502
Words
4 min
Time
Italy emphasises the importance of regional CBMs, particularly those developed by the OSCE, and highlights the value of multinational cyber exercises, cyber ranges, and structured information-sharing mechanisms involving governments, industry, and academia
Arg. 1
Explanation
Italy argued that regional confidence-building measures, particularly those developed by the OSCE, are highly effective and should be given particular importance. They highlighted the value of multinational cyber exercises, cyber ranges, crisis management simulations, and structured information-sharing mechanisms involving governments, critical infrastructure operators, industry, academia, and research organisations. They argued that developing common operational playbooks and trusted networks before crises occur can strengthen collective preparedness and coordinated response capabilities.
Evidence
The speaker noted that Italy actively contributes to OSCE CBM-8 on points of contact and CBM-14 fostering public-private partnerships to address shared cybersecurity challenges . They described Italy’s implementation of CBMs including nominating POCs for the global directory, exchanging views on ICT matters at bilateral and multilateral levels, sharing national strategies and policies, promoting capacity-building projects, and organising workshops and seminars with a whole-society approach .
Major Discussion Point
Confidence-Building Measures (CBMs) and the Global Points of Contact Directory
Agreed with
SwitzerlandEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAlbaniaKiribatiTonga on behalf of the Forum of Pacific IslandsRepublic of KoreaSingaporeNaoeroThe Dominican Republic
on: Regional organisations play a vital complementary role in implementing CBMs and international law frameworks, and their experiences should inform global-level discussions
115
WPM
618
Words
5 min
Time
For Kiribati, the Global POC Directory is the difference between facing a cyber incident alone and facing it with help; CBMs succeed when they are simple, sustained, and relationship-based, and regional organisations are laboratories for global CBMs
Arg. 1
Explanation
Kiribati argued that for small island developing states, the Global POC Directory is not a convenience but the difference between facing an incident alone and facing it with help, as they do not maintain extensive networks of bilateral channels or cyber attachés. They drew two lessons from the Pacific experience: first, that CBMs succeed when they are simple, sustained, and relationship-based, with ambition measured in reliability rather than the number of measures adopted; and second, that regional organisations are not merely implementers of globally agreed CBMs but laboratories for them. They called for the mechanism to keep its work on CBMs firmly practical.
Evidence
The speaker described Kiribati’s experience hosting a recent PACSON gathering, bringing the region’s cybersecurity professionals together to train, share, and strengthen relationships . They cited the Pacific Cybersecurity Operational Network, Cyber Safety Pacifica, and the Boyer Declaration as examples of regional CBMs that have built practical cooperation and trust . They noted that Kiribati is working to finalise its own participation in the Global POC Directory .
Major Discussion Point
Confidence-Building Measures (CBMs) and the Global Points of Contact Directory
Agreed with
SwitzerlandEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAlbaniaItalyTonga on behalf of the Forum of Pacific IslandsRepublic of KoreaSingaporeNaoeroThe Dominican Republic
on: Regional organisations play a vital complementary role in implementing CBMs and international law frameworks, and their experiences should inform global-level discussions
Disagreed with
Republic of KoreaUnited KingdomTonga on behalf of the Forum of Pacific IslandsSingapore
on: Whether the Global POC Directory should be used flexibly and broadly or strictly in accordance with its original mandate, and whether its use should be constrained to avoid misuse
138
WPM
236
Words
2 min
Time
The POC directory complements existing formal and informal networks; its existence does not alter a state's right to attribute irresponsible cyber behaviour, and states may choose whether using it is appropriate in any given incident
Arg. 1
Explanation
The United Kingdom argued that the UN POC directory is a positive practical example of a CBM emerging from the OEWG, designed to provide a way to facilitate secure and direct communications between states to prevent and address serious ICT incidents. They emphasised that the directory complements a range of formal and informal networks that exist to share information on cyber incidents, and that states may choose whether using it is appropriate in any given situation. Crucially, they noted that the existence of the POC directory does not alter a state's right to attribute irresponsible cyber behaviour to another state.
Evidence
The speaker described the POC directory’s purpose as providing a way to facilitate secure and direct communications between states to prevent and address serious ICT incidents through a network of points of contact that could be reached in times of urgency . They noted that if a state detects malicious cyber activity emerging from another state, they may choose to use the POC directory or other cert-to-cert networks if they feel this will help address the incident, or may decide it is not appropriate if the activity is part of a deliberate state-sponsored campaign .
Major Discussion Point
Confidence-Building Measures (CBMs) and the Global Points of Contact Directory
Agreed with
Tonga on behalf of the Forum of Pacific IslandsEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoRepublic of KoreaCosta RicaAlbaniaItalyKiribatiSerbiaSouth AfricaSingaporeNaoeroPapua New GuineaCanada
on: The Global Points of Contact (POC) Directory is a significant and practical confidence-building measure that must be actively maintained, exercised, and used in good faith
Disagreed with
Republic of KoreaTonga on behalf of the Forum of Pacific IslandsKiribatiSingapore
on: Whether the Global POC Directory should be used flexibly and broadly or strictly in accordance with its original mandate, and whether its use should be constrained to avoid misuse
123
WPM
212
Words
2 min
Time
Serbia supports the Global POC Directory and draws on its OSCE experience, including sponsoring CBM-9 on national terminologies, to demonstrate the value of practical cooperation in improving mutual understanding
Arg. 1
Explanation
Serbia argued that in an environment of heightened tension, confidence-building measures are among the most valuable instruments available—practical, voluntary, non-politicised tools that enhance transparency and predictability and reduce the risk that an ICT incident is misperceived and escalates. They welcomed the operationalisation of the Global Points of Contact Directory and designated both diplomatic and technical points of contact. Serbia also drew on its OSCE experience, including sponsoring CBM-9 on national terminologies and definitions in the field of information security, as evidence of the value of practical cooperation.
Evidence
The speaker noted that Serbia designated both diplomatic and technical points of contact for the Global POC Directory . They cited their contribution to OSCE CBM-9 on national terminologies and definitions in the field of information security as an example of practical cooperation aimed at improving mutual understanding and reducing the risk of misperception .
Major Discussion Point
Confidence-Building Measures (CBMs) and the Global Points of Contact Directory
Agreed with
Tonga on behalf of the Forum of Pacific IslandsEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoRepublic of KoreaCosta RicaAlbaniaItalyKiribatiUnited KingdomSouth AfricaSingaporeNaoeroPapua New GuineaCanada
on: The Global Points of Contact (POC) Directory is a significant and practical confidence-building measure that must be actively maintained, exercised, and used in good faith
189
WPM
591
Words
3 min
Time
South Africa regards the POC Directory as a first step to greater cooperation and supports the proposed global cybersecurity cooperation and capacity-building portal as a further CBM to be elaborated in the DTGs
Arg. 1
Explanation
South Africa argued that member states can support and facilitate full operationalisation of the eight global CBMs through international cooperation at UN, regional, and sub-regional levels, including through workshops and roundtable discussions. They regarded the POC Directory as a first step to greater cooperation between states on identifying and responding to threats to ICT security, and encouraged member states to share success stories from assistance received through interaction with Global POCs during a cyber incident. They also supported the proposed global cybersecurity cooperation and capacity-building portal as a further CBM to be elaborated in the DTGs.
Evidence
The speaker noted that the increasing participation by member states in the Global Points of Contact Directory is itself a CBM , and called for narrowing the capacity gap through capacity-building programmes to achieve maximum participation in the Global POC Directory . They supported the continuation of the UNIDIR Women in International Security and Cyberspace Fellowship and the proposed voluntary fund to support participation of developing countries in the global mechanism .
Major Discussion Point
Confidence-Building Measures (CBMs) and the Global Points of Contact Directory
Agreed with
Tonga on behalf of the Forum of Pacific IslandsEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoRepublic of KoreaCosta RicaAlbaniaItalyKiribatiUnited KingdomSerbiaSingaporeNaoeroPapua New GuineaCanada
on: The Global Points of Contact (POC) Directory is a significant and practical confidence-building measure that must be actively maintained, exercised, and used in good faith
South Africa supports the continuation of the UNIDIR Women in International Security and Cyberspace Fellowship and the proposed voluntary fund to support developing countries' participation in the global mechanism
Arg. 2
Explanation
South Africa argued that capacity-building initiatives have brought member states together at the UN and achieved consensus in a difficult geopolitical context. They specifically supported the continuation of the UNIDIR Women in International Security and Cyberspace Fellowship, which has created a support system for delegations regardless of their affiliations with the Global North or Global South. They also supported the proposed voluntary fund to support participation of developing countries in the global mechanism as itself a confidence-building measure.
Evidence
The speaker supported the continuation of the UNIDIR Women in International Security and Cyberspace Fellowship, noting it has created a support system for delegations regardless of their affiliations with the Global North or the Global South . They also supported the proposed voluntary fund to support participation of developing countries in the global mechanism and capacity building as a CBM .
Major Discussion Point
Cybersecurity Capacity Building
Agreed with
Discover MUN FoundationICANNForum of Incident Response and Security TeamsDeveloping Capacity LTDInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAfrican UnionNicaraguaAlgeriaTonga on behalf of the Forum of Pacific IslandsPapua New GuineaSwitzerlandAustralia
on: Cybersecurity capacity building must be demand-driven, inclusive, and practically oriented, with particular attention to the needs of developing countries and small island developing states
Singapore emphasises that CBMs are a team effort requiring states to share best practices and implementation lessons; the POC directory should be used flexibly before standard templates and procedures are developed
Arg. 1
Explanation
Singapore argued that one of the key needs in the global mechanism is for states already implementing CBMs to share best practices, potential pitfalls in implementation, and ways around them. They emphasised that CBMs are a team effort that cannot be practised in isolation by one state alone, and that regional organisations are very important to this cause, with different regions having different ways of implementing CBMs. They supported the POC directory being used in a flexible way before more standard templates and procedures are developed, and noted Singapore's own participation in PING tests to ensure the directory remains a practical tool.
Evidence
The speaker noted that Singapore has participated in the PING tests conducted and will continue to do so to ensure that the directory remains a practical tool and relevant initiative for continued cooperation . They supported UNODA’s ongoing efforts to operationalise the use of the POC directory through capacity-building initiatives, simulation exercises, and engagement with regional mechanisms to promote interoperability and the sharing of best practices .
Major Discussion Point
Confidence-Building Measures (CBMs) and the Global Points of Contact Directory
Agreed with
SwitzerlandEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAlbaniaItalyKiribatiTonga on behalf of the Forum of Pacific IslandsRepublic of KoreaNaoeroThe Dominican Republic
on: Regional organisations play a vital complementary role in implementing CBMs and international law frameworks, and their experiences should inform global-level discussions
Disagreed with
Republic of KoreaUnited KingdomTonga on behalf of the Forum of Pacific IslandsKiribati
on: Whether the Global POC Directory should be used flexibly and broadly or strictly in accordance with its original mandate, and whether its use should be constrained to avoid misuse
127
WPM
446
Words
4 min
Time
Nauru, as incoming chair of PACSON, intends to strengthen the connection between the Pacific's operational cooperation and the global mechanism's CBMs, and calls for the directory to remain practical, exercised, and supported by training of designated officials
Arg. 1
Explanation
Nauru argued that for small states like itself, where the people responsible for cybersecurity, diplomacy, and digital policy are often one and the same, CBMs must be inclusive by design and assume both large and small bureaucracies. They emphasised that the Global POC Directory exists to answer the critical question of who to call in a serious ICT incident, and committed to registering to the POC. As incoming chair of PACSON, Nauru announced its intention to strengthen the connection between the Pacific's operational cooperation and the global mechanism's CBMs, and invited other regions and the mechanism to engage with them in that spirit.
Evidence
The speaker noted that Nauru will assume the chairmanship of the Pacific Cyber Security Operational Network (PACSON) for the coming year , and described PACSON as connecting incident responders of the region in working-level cooperation, week in and week out, showing that trust between technical teams is built through routine contact long before a crisis makes it necessary . They outlined priorities including keeping the directory practical and exercised, investing in training of designated officials, and drawing deliberately on regional networks as sources of tested practice .
Major Discussion Point
Confidence-Building Measures (CBMs) and the Global Points of Contact Directory
Agreed with
SwitzerlandEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAlbaniaItalyKiribatiTonga on behalf of the Forum of Pacific IslandsRepublic of KoreaSingaporeThe Dominican Republic
on: Regional organisations play a vital complementary role in implementing CBMs and international law frameworks, and their experiences should inform global-level discussions
131
WPM
864
Words
7 min
Time
Papua New Guinea emphasises that capacity building must be demand-driven, nationally owned, and responsive to each country's level of digital maturity, particularly for small island developing states
Arg. 1
Explanation
Papua New Guinea argued that the global mechanism should help countries strengthen the core capabilities needed to manage cyber risk, including cyber hygiene, national incident response, legal and regulatory frameworks, and the skills required by officials, technical experts, regulators, law enforcement agencies, and critical infrastructure operators. They emphasised that capacity building must be demand-driven, nationally owned, and responsive to each country's level of digital maturity. For developing countries and small island developing states, strengthening institutional and technical capacities remains pivotal to implementing the agreed framework.
Evidence
The speaker noted that ICT is one of the 12 core national development strategic priorities under Papua New Guinea’s current medium-term development plan 4 . They acknowledged the support of development partners such as UNIDIR and Australia for gender-sensitive capacity-building support including participation in the meeting for female representatives from the Pacific region .
Major Discussion Point
Cybersecurity Capacity Building
Agreed with
Discover MUN FoundationICANNForum of Incident Response and Security TeamsDeveloping Capacity LTDInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAfrican UnionNicaraguaAlgeriaTonga on behalf of the Forum of Pacific IslandsSouth AfricaSwitzerlandAustralia
on: Cybersecurity capacity building must be demand-driven, inclusive, and practically oriented, with particular attention to the needs of developing countries and small island developing states
Papua New Guinea believes the global mechanism should help countries strengthen core capabilities including cyber hygiene, national incident response, and legal frameworks, with CBMs producing practical outcomes through regular communication, joint exercises, and lessons-learned exchanges
Arg. 2
Explanation
Papua New Guinea argued that confidence-building measures should produce practical outcomes, including regular communication between national points of contact, timely information sharing, joint cyber exercises, technical cooperation, and the exchange of lessons learned. They noted that digital transformation can only succeed when people, governments, businesses, and other stakeholders have confidence and trust that the digital environment is safe, secure, and reliable. They also emphasised that the rapid advancement of emerging technologies including AI further reinforces the importance of a resilient cyber ecosystem and international cooperation.
Evidence
The speaker described the Pacific Regional Digital Transformation Summit and Pacific Cyber Week taking place in Papua New Guinea that week as demonstrating that digital transformation can only succeed when stakeholders have confidence and trust in the digital environment . They noted that cybersecurity is not only a technical matter but a foundation for economic growth, digital trade, investment, innovation, and public confidence in digital services .
Major Discussion Point
Confidence-Building Measures (CBMs) and the Global Points of Contact Directory
Agreed with
Tonga on behalf of the Forum of Pacific IslandsEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoRepublic of KoreaCosta RicaAlbaniaItalyKiribatiUnited KingdomSerbiaSouth AfricaSingaporeNaoeroCanada
on: The Global Points of Contact (POC) Directory is a significant and practical confidence-building measure that must be actively maintained, exercised, and used in good faith
143
WPM
597
Words
4 min
Time
The private sector possesses real-time threat visibility and operational experience that is essential to the mechanism's success; meaningful, structured, and predictable stakeholder participation must be ensured across all areas of work
Arg. 1
Explanation
The International Chamber of Commerce argued that the success of the mechanism depends not only on the quality of intergovernmental dialogue but also on its ability to draw on the expertise, experience, and capabilities of the broader cybersecurity community. The private sector is often the first to identify, analyse, and respond to new cyber risks, possessing real-time visibility into threat trends across networks, sectors, and geographies. They argued that meaningful stakeholder participation is not merely desirable but essential to the success of the global mechanism, as much of the world's digital infrastructure is designed, operated, and maintained by the private sector.
Evidence
The speaker noted that ICC is the institutional representative of more than 45 million companies in over 170 countries and an observer to the UN General Assembly . They described the private sector’s real-time visibility into threat trends across networks, sectors, and geographies, as well as practical experience in mitigating attacks and strengthening resilience . They outlined specific areas where industry expertise can support DTG discussions, including protecting critical infrastructure, strengthening cyber resilience, improving coordinated vulnerability disclosure, facilitating threat information sharing, and promoting secure-by-design approaches .
Major Discussion Point
Stakeholder Participation and Accreditation in the Global Mechanism
Agreed with
Discover MUN FoundationICANNForum of Incident Response and Security TeamsInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAccess NowCanadaJapanMexicoEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoChileGermanyChair Egriselda López
on: Meaningful and inclusive multi-stakeholder participation is essential to the global mechanism's success, not merely desirable
Disagreed with
Discover MUN FoundationForum of Incident Response and Security TeamsInternet SocietyAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeCanadaChileGermanyJapanEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoMexico
on: Whether stakeholder accreditation objections without stated basis are consistent with the agreed inclusivity principle, and whether the current level of stakeholder participation is acceptable
125
WPM
2290
Words
18 min
Time
The stakeholder community is a fundamental part of the mechanism's work and their contributions, invitations, and calls to action have been duly noted; stakeholders are encouraged to share their statements with the Chair's team
Arg. 1
Explanation
Chair López affirmed that the community of stakeholders is without doubt a fundamental part of the mechanism's work, possessing considerable experience and knowledge. She committed to working closely with stakeholders to achieve meaningful progress and requested that all statements be shared not only with the Secretariat but also with the Chair's team directly.
Evidence
The Chair stated that the community of stakeholders is a fundamental part of the work and that they have a lot of experience and considerable knowledge, and that the mechanism will continue to work closely with them to achieve meaningful progress . She specifically requested that stakeholders share their statements with the Chair’s team as well as the Secretariat .
Major Discussion Point
Stakeholder Participation and Accreditation in the Global Mechanism
Agreed with
Discover MUN FoundationICANNForum of Incident Response and Security TeamsInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAccess NowCanadaJapanMexicoEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoChileGermanyInternational Chamber of Commerce
on: Meaningful and inclusive multi-stakeholder participation is essential to the global mechanism's success, not merely desirable
The majority of delegations underscored that the global mechanism must continue discussions on the applicability of international law to ICTs, with a common understanding being fundamental to establishing a safe, stable, and predictable digital environment
Arg. 2
Explanation
In her summary of the international law agenda item, Chair López noted that the majority of delegations reaffirmed the need to continue discussions begun during the first OEWG on how international law applies to ICTs. She highlighted that developing a common understanding was identified as fundamental to establishing a safe, stable, and predictable digital environment, and that legal debates must be accessible to all states through capacity building and technical cooperation.
Evidence
The Chair summarised that the majority of delegations underscored that the global mechanism must continue to encourage discussions begun during the first OEWG on the way international law is applicable to ICTs , and that the development of a common understanding is fundamental to establishing a safe, stable, and predictable digital environment . She also noted that delegations underscored that legal debates must be accessible to all states and that capacity building and technical cooperation based on scenarios are fundamental .
on: Existing international law, including IHL and international human rights law, applies to state conduct in cyberspace and discussions should continue to build common understanding of how it applies in practice
Delegations should continue efforts to support capacity building, facilitate regional exchanges, and promote dialogue between legal and technical communities to foster an exchange of specialised knowledge on international law in cyberspace
Arg. 3
Explanation
Chair López encouraged delegations to continue their efforts to support capacity building to facilitate regional exchanges and to promote dialogue between different legal and technical communities. She framed this as essential to fostering an exchange of specialised knowledge and to supporting states in developing national perspectives on the applicability of international law in cyberspace without losing sight of regional efforts.
Evidence
The Chair encouraged delegations to continue their efforts to support capacity building to facilitate regional exchanges and to promote dialogue between the different legal and technical communities to foster an exchange of specialised knowledge . She also noted that delegations shared good practices on the elaboration of national positions on the way to interpret the applicability of international law in cyberspace, as well as updates on previously updated positions .
Major Discussion Point
Application of International Law to Cyberspace
Cross-regional joint statements should be encouraged as they support small delegations with limited capacity to participate meaningfully across the process
Arg. 4
Explanation
Chair López explicitly encouraged delegations to engage in interregional efforts when discussing international law, noting the particular value of joint statements for small delegations who find it difficult to participate across the full process due to limited capacity. This framing positions cross-regional collaboration as a practical tool for inclusive participation rather than merely a diplomatic courtesy.
Evidence
The Chair stated that she encourages delegations to engage in interregional efforts as they engage in these discussions, especially given the limited capacity of small delegations who find it difficult to participate across the process .
Major Discussion Point
Cybersecurity Capacity Building
The mechanism's plenary sessions should be conducted with transparency and inclusivity as the norm, consistent with the consensus-based modalities document, and the Chair is committed to upholding these principles
Arg. 5
Explanation
Chair López opened the stakeholder segment by expressing gratitude to all accredited organisations for participating, acknowledging that many are not based in New York and have made a special effort to contribute. Her framing of the session and her letter dated 1st June, referenced by the Discover MUN Foundation, reflect her commitment to upholding the transparency required by the modalities document and to treating inclusivity as the norm rather than the exception.
Evidence
The Chair expressed thanks to all organisations for participating in the first plenary session of the mechanism, noting that many are not based in New York and thanking them for their interest, time, and contributions . The Discover MUN Foundation thanked the Chair for her letter dated 1st June and for her tireless efforts to uphold the transparency required by the modalities document in A-80-257 .
Major Discussion Point
Stakeholder Participation and Accreditation in the Global Mechanism
Session Knowledge Graph
Speakers · Topics · Arguments · Relationships
Interactive graph · embed active
Agreed Points
Meaningful and inclusive multi-stakeholder participation is essential to the global mechanism's success, not merely desirable
There was near-universal agreement across stakeholder organisations and state delegations that meaningful multi-stakeholder participation is essential to the global mechanism’s effectiveness. The Discover MUN Foundation noted that objections lodged against more than 60 stakeholder entities without any stated basis cannot be considered consistent with the inclusivity principle . The Internet Society argued that the mechanism risks being disconnected from operational reality if non-governmental stakeholders are excluded , while FIRST supported the joint multi-stakeholder statement on objections to participation . Canada specifically named stakeholders from Mexico, Brazil, Peru, Panama, Ghana, Nigeria, and South Africa as having been vetoed , and Chile explicitly rejected the volume of objections including from institutions in its own region . Germany highlighted that the blocked organisation Interface had produced a CBM implementation survey directly relevant to the mechanism’s discussions . The Chair affirmed that the stakeholder community is a fundamental part of the mechanism’s work .
Youth and children's rights must be fully recognised in the digital environment, and objections to stakeholder accreditation without stated basis undermine the inclusivity principle agreed by consensus – Demand for transparent, criteria-based accreditation
ICANN's multi-stakeholder model, including the Government Advisory Committee, provides a proven framework for inclusive Internet governance that member states should actively engage with
Incident response and security professionals provide indispensable operational expertise on cyber norms and CBM implementation; stakeholder participation must remain open, transparent, and non-politicised
Meaningful stakeholder engagement is not a courtesy but essential, as the Internet is run by a distributed ecosystem; accreditation modalities must be implemented in a predictable and transparent manner
Multi-stakeholder expertise must be systematically integrated into informal consultations, technical drafting, and policy implementation, with formal channels for grassroots data from developing nations
Civil society and technical organisations document empirical evidence of cyber harms, including those affecting vulnerable communities; locking out stakeholders injures the mechanism's effectiveness
The mechanism risks being disconnected from operational reality if non-governmental stakeholders are excluded; states should draw more deliberately on multi-stakeholder expertise both within and beyond official sessions
The number of objections to stakeholder accreditation, including organisations from Latin America, Africa, and other regions, deprives the mechanism of critical cross-regional expertise and must be addressed
Japan strongly values the multi-stakeholder approach and hopes to further strengthen public-private collaboration within the UN framework through expert briefings and interactive discussions
Stakeholder participation is fundamental; Mexico urges stakeholders to draft specific inputs for DTG discussions and share examples of tools, guides, and methodologies to support framework implementation
The EU welcomes stakeholder contributions and encourages continued cooperation with states on capacity building, research, and implementation of the UN Framework of Responsible State Behaviour
Chile rejects the volume of objections to stakeholder participation, including from organisations in its own region, and affirms that diverse stakeholder voices are essential to reflect ground-level realities
Germany highlights that organisations blocked from participation, such as Interface with its CBM implementation survey, have produced work directly relevant to the mechanism's discussions
The private sector possesses real-time threat visibility and operational experience that is essential to the mechanism's success; meaningful, structured, and predictable stakeholder participation must be ensured across all areas of work
The stakeholder community is a fundamental part of the mechanism's work and their contributions, invitations, and calls to action have been duly noted; stakeholders are encouraged to share their statements with the Chair's team
Policy Context (Knowledge Base)
This reflects a broad consensus documented across multiple UN forums that multi-stakeholder participation must be substantively strengthened, not merely acknowledged [S185]. The IGF 2021 final report similarly noted that cyber norms should be developed at the UN with more systemic involvement of stakeholders, particularly underrepresented states [S172]. Concerns about the technical community’s exclusion from governance processes have also been raised as a fragmentation risk [S192][S193].
Discover MUN FoundationICANNForum of Incident Response and Security TeamsInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAccess NowCanadaJapanMexicoEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoChileGermanyInternational Chamber of CommerceChair Egriselda López
The Global Points of Contact (POC) Directory is a significant and practical confidence-building measure that must be actively maintained, exercised, and used in good faith
There was broad agreement that the Global POC Directory represents one of the most significant practical achievements of the OEWG and must be actively maintained and used responsibly. The Republic of Korea described it as one of the most significant OEWG achievements , while Kiribati noted it is the difference between facing an incident alone and facing it with help . Tonga called for it to be used proportionately and with due regard for the capacity constraints of smaller states . The EU supported integrating the directory into the global mechanism’s portal , while the United Kingdom clarified that the directory’s existence does not alter a state’s right to attribute irresponsible cyber behaviour . Singapore supported using the directory flexibly before standard templates are developed , and Nauru committed to registering and strengthening the connection between PACSON and the global mechanism .
For Pacific small island developing states, CBMs are among the most immediately practical elements of the framework; the Global POC Directory must be actively maintained and used in good faith, with due regard for the capacity constraints of smaller states
The EU supports operationalising the eight agreed CBMs, including integrating the POC directory into the global mechanism's portal, organising seminars and workshops, and promoting information exchange on cooperation and partnerships
The UN POC directory is one of the most significant OEWG achievements; it must be used responsibly and in good faith, and should not be misused for purposes inconsistent with its original intent of facilitating cooperative communication
Costa Rica supports the Global POC Directory as a valuable operational tool for managing cross-border incidents and reducing misunderstandings, and emphasises that legal transparency through publishing national positions on international law also serves as a CBM
Albania's experience shows that CBMs work through layered cooperation—political, diplomatic, and technical—across the UN, EU, OSCE, ITU, and bilateral relations, with each layer reinforcing the others and building capacity that in turn builds trust
Italy emphasises the importance of regional CBMs, particularly those developed by the OSCE, and highlights the value of multinational cyber exercises, cyber ranges, and structured information-sharing mechanisms involving governments, industry, and academia
For Kiribati, the Global POC Directory is the difference between facing a cyber incident alone and facing it with help; CBMs succeed when they are simple, sustained, and relationship-based, and regional organisations are laboratories for global CBMs
The POC directory complements existing formal and informal networks; its existence does not alter a state's right to attribute irresponsible cyber behaviour, and states may choose whether using it is appropriate in any given incident
Serbia supports the Global POC Directory and draws on its OSCE experience, including sponsoring CBM-9 on national terminologies, to demonstrate the value of practical cooperation in improving mutual understanding
South Africa regards the POC Directory as a first step to greater cooperation and supports the proposed global cybersecurity cooperation and capacity-building portal as a further CBM to be elaborated in the DTGs
Singapore emphasises that CBMs are a team effort requiring states to share best practices and implementation lessons; the POC directory should be used flexibly before standard templates and procedures are developed
Nauru, as incoming chair of PACSON, intends to strengthen the connection between the Pacific's operational cooperation and the global mechanism's CBMs, and calls for the directory to remain practical, exercised, and supported by training of designated officials
Papua New Guinea believes the global mechanism should help countries strengthen core capabilities including cyber hygiene, national incident response, and legal frameworks, with CBMs producing practical outcomes through regular communication, joint exercises, and lessons-learned exchanges
Canada's participation in tabletop exercises during FIFA World Cup preparations, coordinating with Mexico, CISA, and US CERTs, illustrates how CBM operationalisation through simulation exercises can build practical cooperation
Policy Context (Knowledge Base)
The Global POC Directory has been consistently recognised as a landmark CBM achievement. Two ping tests were conducted to verify its functionality [S173], and 109 countries have joined the directory, with calls for regular testing [S174]. Multiple sources confirm its role in facilitating state-to-state communication, crisis management, and trust-building [S175][S176]. Russia has also highlighted its importance as a confidence-building tool [S174].
Tonga on behalf of the Forum of Pacific IslandsEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoRepublic of KoreaCosta RicaAlbaniaItalyKiribatiUnited KingdomSerbiaSouth AfricaSingaporeNaoeroPapua New GuineaCanada
Cybersecurity capacity building must be demand-driven, inclusive, and practically oriented, with particular attention to the needs of developing countries and small island developing states
Across stakeholder organisations and state delegations, there was strong agreement that capacity building must be demand-driven, inclusive, and practically oriented. Developing Capacity LTD recommended prioritising quick wins through matchmaking and funding coordination , while KICTANET called for resources to move beyond high-level legal meetings towards strengthening local incident response teams . InternetLab emphasised that effective capacity building requires meaningful engagement with priorities of global majority states . Papua New Guinea stressed that capacity building must be demand-driven, nationally owned, and responsive to each country’s level of digital maturity . The African Union described a workshop convened in Addis Ababa to strengthen AU member states’ capacity to develop national positions on international law , and Nicaragua called for capacity building to be coupled with technology transfer . South Africa supported the continuation of the UNIDIR Women in International Security and Cyberspace Fellowship .
A dedicated children and youth track within the mechanism's capacity-building activities should be modelled on successful examples such as the UNIDIR Women in International Security and Cyberspace Fellowship
The Coalition for Digital Africa demonstrates how capacity building through multi-stakeholder collaboration can strengthen DNS security, build local technical expertise, and expand Internet governance participation
FIRST has 31 member teams in Mexico and an upcoming Mexico City Technical Colloquium; it stands ready to support states in implementing responsible behaviour frameworks through its global membership network
Capacity-building practitioners have published practical suggestions for the mechanism and recommend prioritising quick wins through matchmaking and funding coordination, addressing strategic resource gaps, and improving quality and demand-driven delivery
The Internet Society's policymaker programme helps diplomats understand how the Internet works and how standards are developed, enabling better-informed cyber policy
Capacity building must be human-centric and demand-driven, moving beyond high-level legal meetings to strengthen local incident response teams, defend civic space, and protect vulnerable communities
State-led capacity-building programmes must address the disproportionate impact of cyber threats on vulnerable communities including women, LGBTQI+ people, and human rights defenders, whose unique threats are often unrecognised or unrecorded
The Chatham House report on operationalising cyber capacity-building principles, the Geneva Dialogues manual, and sector-specific guidance from organisations like Cyber Peace Institute provide a meaningful body of practical resources for states
Capacity building must be sustainable, demand-driven, and inclusive, with better coordination among existing initiatives, support for states with limited resources, and cooperation on secure open-source cybersecurity tools
Capacity building for international law in cyberspace is an important area for the global mechanism; the AU Commission convened a workshop to strengthen member states' capacity to develop national positions on the application of international law
Nicaragua calls for continued careful, inclusive, intergovernmental debate on international law in cyberspace, keeping open the possibility of legally binding instruments and coupling discussions with effective capacity building and technology transfer
Algeria emphasises that developing countries face unique challenges in meeting their obligations in the applicability of international law due to resource constraints and technical gaps
For Pacific small island developing states, CBMs are among the most immediately practical elements of the framework; the Global POC Directory must be actively maintained and used in good faith, with due regard for the capacity constraints of smaller states
Papua New Guinea emphasises that capacity building must be demand-driven, nationally owned, and responsive to each country's level of digital maturity, particularly for small island developing states
South Africa supports the continuation of the UNIDIR Women in International Security and Cyberspace Fellowship and the proposed voluntary fund to support developing countries' participation in the global mechanism
Switzerland emphasises that the challenge is not to develop new CBMs but to implement those already agreed; regional and sub-regional organisations play a key role and a structured exchange between the global mechanism and regional organisations should be established
Australia supports consolidating common understandings on how international human rights law, the law of state responsibility, and IHL apply in cyberspace, using concrete incident scenarios to build confidence and shared understanding
Policy Context (Knowledge Base)
The 10th substantive session of the UN OEWG 2021-2025 extensively discussed capacity-building gaps, particularly for developing nations [S194]. Mozambique and the Democratic Republic of the Congo have both emphasised the critical need for inclusive capacity building to address disparities [S195][S196]. Culturally relevant approaches tailored to specific socio-cultural contexts have also been identified as essential for effectiveness [S178].
Discover MUN FoundationICANNForum of Incident Response and Security TeamsDeveloping Capacity LTDInternet SocietyKenya ICT Action NetworkAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeInternetLabAfrican UnionNicaraguaAlgeriaTonga on behalf of the Forum of Pacific IslandsPapua New GuineaSouth AfricaSwitzerlandAustralia
The mechanism should focus on implementing the existing agreed framework and CBMs rather than creating new normative processes or relitigating settled ground
Multiple speakers agreed that the mechanism’s primary focus should be on implementing existing commitments rather than creating new normative frameworks. The United States stated that the mechanism should focus on implementing the 11 norms states have already committed to and not relitigate settled ground . Switzerland argued that the challenge is not to develop new CBMs but to implement those already agreed . Tonga emphasised that the focus at this stage is the implementation of existing CBMs . The Dominican Republic reaffirmed commitment to the eight voluntary global CBMs and called for their practical operationalisation . InternetLab encouraged discussions that examine how emerging developments affect implementation of the existing UN framework rather than creating parallel normative processes .
Existing international law applies to activities in cyberspace and is fit for purpose; further discussion should be anchored in concrete threats and practical tools, not used as a vehicle for treaty-making or relitigating settled ground
Switzerland emphasises that the challenge is not to develop new CBMs but to implement those already agreed; regional and sub-regional organisations play a key role and a structured exchange between the global mechanism and regional organisations should be established
For Pacific small island developing states, CBMs are among the most immediately practical elements of the framework; the Global POC Directory must be actively maintained and used in good faith, with due regard for the capacity constraints of smaller states
The eight voluntary global CBMs adopted by the OEWG constitute a fundamental pillar of the responsible state behaviour framework; the mechanism should now focus on their practical and inclusive operationalisation, supported by a working paper from the cross-regional Confidence Builders group
The UN POC directory is one of the most significant OEWG achievements; it must be used responsibly and in good faith, and should not be misused for purposes inconsistent with its original intent of facilitating cooperative communication
Singapore emphasises that CBMs are a team effort requiring states to share best practices and implementation lessons; the POC directory should be used flexibly before standard templates and procedures are developed
Australia supports consolidating common understandings on how international human rights law, the law of state responsibility, and IHL apply in cyberspace, using concrete incident scenarios to build confidence and shared understanding
Capacity building must be sustainable, demand-driven, and inclusive, with better coordination among existing initiatives, support for states with limited resources, and cooperation on secure open-source cybersecurity tools
Policy Context (Knowledge Base)
This position is explicitly reflected in the 2nd meeting of the organisational session of the Global Mechanism, where delegations called for priority to be given to translating agreed frameworks into concrete implementation rather than reopening normative debates [S182]. The 4th meeting plenary similarly recorded broad consensus that DTGs should serve as practical, action-oriented forums for advancing implementation [S181].
United StatesSwitzerlandTonga on behalf of the Forum of Pacific IslandsThe Dominican RepublicRepublic of KoreaSingaporeAustraliaInternetLab
Regional organisations play a vital complementary role in implementing CBMs and international law frameworks, and their experiences should inform global-level discussions
There was broad agreement that regional organisations are not merely implementers of globally agreed CBMs but valuable laboratories and partners. Switzerland called for a structured exchange between the global mechanism and regional and sub-regional organisations , citing a June 2026 OSCE meeting as demonstrating the added value of such exchanges . Kiribati argued that regional organisations are laboratories for CBMs and that the mechanism should draw systematically on regional experience . Albania described its layered cooperation across the UN, EU, OSCE, ITU, and bilateral relations as a virtuous cycle where cooperation builds capacity, capacity builds trust, and trust builds more cooperation . The EU called for efforts to complement the work of regional organisations including the OSCE, OAS, ARF, and ECOWAS . Singapore emphasised that different regions have different ways of implementing CBMs and that DTG1 should consider how to involve regional organisations .
Switzerland emphasises that the challenge is not to develop new CBMs but to implement those already agreed; regional and sub-regional organisations play a key role and a structured exchange between the global mechanism and regional organisations should be established
The EU supports operationalising the eight agreed CBMs, including integrating the POC directory into the global mechanism's portal, organising seminars and workshops, and promoting information exchange on cooperation and partnerships
Albania's experience shows that CBMs work through layered cooperation—political, diplomatic, and technical—across the UN, EU, OSCE, ITU, and bilateral relations, with each layer reinforcing the others and building capacity that in turn builds trust
Italy emphasises the importance of regional CBMs, particularly those developed by the OSCE, and highlights the value of multinational cyber exercises, cyber ranges, and structured information-sharing mechanisms involving governments, industry, and academia
For Kiribati, the Global POC Directory is the difference between facing a cyber incident alone and facing it with help; CBMs succeed when they are simple, sustained, and relationship-based, and regional organisations are laboratories for global CBMs
For Pacific small island developing states, CBMs are among the most immediately practical elements of the framework; the Global POC Directory must be actively maintained and used in good faith, with due regard for the capacity constraints of smaller states
The UN POC directory is one of the most significant OEWG achievements; it must be used responsibly and in good faith, and should not be misused for purposes inconsistent with its original intent of facilitating cooperative communication
Singapore emphasises that CBMs are a team effort requiring states to share best practices and implementation lessons; the POC directory should be used flexibly before standard templates and procedures are developed
Nauru, as incoming chair of PACSON, intends to strengthen the connection between the Pacific's operational cooperation and the global mechanism's CBMs, and calls for the directory to remain practical, exercised, and supported by training of designated officials
The eight voluntary global CBMs adopted by the OEWG constitute a fundamental pillar of the responsible state behaviour framework; the mechanism should now focus on their practical and inclusive operationalisation, supported by a working paper from the cross-regional Confidence Builders group
Policy Context (Knowledge Base)
The OEWG 2021-2025 fourth substantive session documented multiple states highlighting the role of regional organisations such as the OSCE, OAS, and ASEAN in operationalising CBMs and enhancing information sharing [S170]. The OSCE itself has argued that regional experiences are invaluable for operationalising CBMs in the future mechanism [S171]. The IGF 2021 report also noted the importance of regional organisations in building and implementing the normative framework [S172].
SwitzerlandEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAlbaniaItalyKiribatiTonga on behalf of the Forum of Pacific IslandsRepublic of KoreaSingaporeNaoeroThe Dominican Republic
Existing international law, including IHL and international human rights law, applies to state conduct in cyberspace and discussions should continue to build common understanding of how it applies in practice
Despite differences on whether new binding instruments are needed, there was broad agreement that existing international law applies to cyberspace and that discussions on how it applies must continue. The Chair summarised that the majority of delegations underscored that the global mechanism must continue to encourage discussions on the way international law is applicable to ICTs . Switzerland noted that more than 40 states have issued positions on international law in cyberspace . The ICRC cited the October 2024 resolution of the 34th International Conference of the Red Cross and Red Crescent affirming that IHL rules and principles serve to protect civilian populations against risks arising from ICT activities . Australia noted that the OEWG saw states solidify and add granularity to several specific areas of convergence on how international law applies . Algeria reaffirmed that international law, including sovereignty, non-interference, prohibition of the use of force, IHL, and international human rights law, fully applies in cyberspace .
Switzerland supports concrete discussions on real-world scenarios, particularly on protecting critical infrastructure such as hospitals and water systems, and highlights the ICT work stream under the Global IHL Initiative as a valuable complementary platform
Australia supports consolidating common understandings on how international human rights law, the law of state responsibility, and IHL apply in cyberspace, using concrete incident scenarios to build confidence and shared understanding
IHL applies to ICT activities in armed conflict; states should focus discussions on how IHL limits ICT operations causing non-physical damage and on protecting civilian ICT infrastructure and data
Algeria supports the elaboration of a legally binding international instrument on state behaviour in cyberspace, arguing that the unique attributes of cyberspace demand legal clarity rather than interpretative ambiguity
The African Union's Common African Position provides a shared foundation for AU member states to engage in global cyber law discussions, and capacity building on the applicability of international law is an important area for the global mechanism
Nicaragua calls for continued careful, inclusive, intergovernmental debate on international law in cyberspace, keeping open the possibility of legally binding instruments and coupling discussions with effective capacity building and technology transfer
The majority of delegations underscored that the global mechanism must continue discussions on the applicability of international law to ICTs, with a common understanding being fundamental to establishing a safe, stable, and predictable digital environment
Protecting vulnerable and marginalised communities, including women, children, and human rights defenders, from cyber threats must be a priority for the mechanism
Civil society organisations consistently agreed that the mechanism must prioritise the protection of vulnerable and marginalised communities. The Discover MUN Foundation highlighted that when everyday ICT tools are repurposed for malicious activities, it is young people and children who face the most immediate attacks . APC documented how digital surveillance is used to intimidate, silence, and restrict women’s participation in civic and political life , and called for gender-sensitive cybersecurity laws . InternetLab cited its own research on online gender-based political violence against women politicians in Brazil as evidence of disproportionate targeting . Access Now documented 313 Internet shutdowns in 2025, of which 125 occurred in conflict situations . KICTANET called for resources to move beyond high-level legal meetings towards protecting vulnerable communities from technology-facilitated abuse .
Dual-use technologies including AI-driven malware and deepfake social engineering are being weaponised against digital spaces, with children and young people facing immediate attacks to their digital safety and rights
State-led capacity-building programmes must address the disproportionate impact of cyber threats on vulnerable communities including women, LGBTQI+ people, and human rights defenders, whose unique threats are often unrecognised or unrecorded
Research on online gender-based political violence against women politicians in Brazil documents how coordinated attacks disproportionately target women and historically marginalised communities, with clear implications for democratic participation and cybersecurity policy design
Out of 313 Internet shutdowns documented in 2025, 125 occurred in conflict situations; DTGs must make the human cost of critical infrastructure attacks visible and foreground the role of civil society in its defence
Capacity building must be human-centric and demand-driven, moving beyond high-level legal meetings to strengthen local incident response teams, defend civic space, and protect vulnerable communities
Policy Context (Knowledge Base)
The Bahamas highlighted that cyber threats disproportionately affect women and girls through technology-facilitated gender-based violence, identifying this as an underexplored area within the mechanism [S186]. Canada has emphasised the need to protect women human rights defenders in the context of women, peace and security discussions [S179]. Saudi Arabia has also cited child protection and women’s empowerment in cyberspace as universally agreeable issues for building inter-state trust [S188].
Discover MUN FoundationAssociation for Progressive CommunicationsInternetLabAccess NowKenya ICT Action Network
Similar Viewpoints
These stakeholder organisations shared the view that their exclusion from the mechanism through opaque objection processes directly undermines the mechanism’s operational effectiveness. The Internet Society warned that the mechanism risks being disconnected from operational reality , while FIRST supported the joint multi-stakeholder statement on objections to participation . The Discover MUN Foundation noted that objections against more than 60 entities without any stated basis cannot be considered consistent with inclusivity . APC argued that the mechanism inflicted an injury on itself by initially locking out many stakeholders . Chatham House noted that many stakeholders actively working on these issues have had their accreditation denied . The ICC argued that meaningful stakeholder participation is not merely desirable but essential .
Pacific Island states consistently emphasised that CBMs and the POC Directory are not abstract diplomatic tools but practical necessities for small states with limited resources. Kiribati noted that predictable, trusted mechanisms for communication are the difference between facing an incident alone and facing it with help . Tonga called for the POC Directory to be used proportionately and with due regard for the capacity constraints of smaller states . Nauru described PACSON as connecting incident responders in working-level cooperation week in and week out, showing that trust is built through routine contact . Papua New Guinea stressed that capacity building must be demand-driven, nationally owned, and responsive to each country’s level of digital maturity .
Algeria, Nicaragua, and the African Union shared the view that the international community should keep open the possibility of developing legally binding instruments for cyberspace, while also emphasising the need for capacity building to accompany legal discussions. Algeria argued that the unique attributes of cyberspace demand legal clarity and certainty rather than interpretative ambiguity , and that since the international community has agreed on 11 non-binding norms, it should be able to elaborate legally binding rules . Nicaragua cited the UN Convention against Cybercrime as evidence that the international community can make headway through dialogue and consensus towards multilateral instruments . The African Union emphasised that capacity building on the applicability of international law is an important area of work for the global mechanism .
These stakeholder organisations responded to Mexico’s question about practical tools by highlighting existing resources and programmes that states can draw upon immediately. Chatham House mentioned the Chatham House report on operationalising cyber capacity-building principles, the Geneva Dialogues manual, and sector-specific guidance from the Cyber Peace Institute . Developing Capacity LTD highlighted the Sybil Portal with 74 documents and information on 100 past cyber capacity-building projects . FIRST noted its 31 member teams in Mexico and an upcoming Mexico City Technical Colloquium . The Internet Society described its policymaker programme for diplomats . ICANN cited the Coalition for Digital Africa as a model of multi-stakeholder capacity building .
Civil society organisations shared a common perspective that human rights must be central to cybersecurity discussions, with particular attention to the gendered and community-specific impacts of cyber threats. APC called for further work on the gendered impact of cyber mercenary actors on human rights defenders, journalists, and activists . InternetLab cited research documenting how coordinated attacks disproportionately target women politicians in Brazil . Access Now called for states to protect tools like strong encryption and independent research capabilities that enable civil society to contribute . The Discover MUN Foundation highlighted that children and young people face immediate attacks to their digital safety and rights when ICT tools are repurposed for malicious activities .
State delegations from diverse regions shared the view that broader and more inclusive stakeholder participation is essential and that the current pattern of objections is counterproductive. Canada named specific stakeholders from Mexico, Brazil, Peru, Panama, Ghana, Nigeria, and South Africa as having been vetoed . Chile explicitly rejected the amount of objections including from institutions in its own region . Germany highlighted that the blocked organisation Interface had produced a CBM implementation survey directly relevant to the mechanism’s discussions . The EU encouraged stakeholders to continue contributing through cooperation with states, research, training, and dedicated activities . Mexico welcomed the practice of displaying organisations’ names on screens as reflecting the importance of meaningful participation .
Multiple speakers agreed that AI and emerging technologies present significant and evolving cybersecurity challenges that the mechanism must address, though they approached this from different angles. Chatham House identified the emergence of frontier AI models and their cybersecurity implications as changing the operational landscape . APC urged attention to how the race for AI deployment in the public sector is impacting security vulnerabilities and affecting vulnerable communities . MGIMO called for recognition of the importance of neutrality of large language models with regard to international affairs . Access Now called for specific recognition of how AI tools are beset by glaring security vulnerabilities with grave consequences for data confidentiality, information integrity, and system availability .
Unexpected Consensus
It is somewhat unexpected that the Women in International Security and Cyberspace Fellowship emerged as a point of consensus across speakers from very different contexts-a youth-focused civil society organisation, a European candidate country for EU membership, and a Global South state. The Discover MUN Foundation cited the Fellowship as a model for integrating young technical experts in national delegations . Albania described it as a confidence-building measure in itself, having brought valuable perspectives and a more resilient cyberspace . South Africa explicitly supported its continuation, noting it has created a support system for delegations regardless of their affiliations with the Global North or Global South . This cross-cutting consensus on a specific programme is notable given the broader disagreements on stakeholder participation.
It is notable that organisations as different as a global business association (ICC), a technical coordination body (Internet Society), a think tank (Chatham House), and a professional security community (FIRST) converged on the same fundamental argument: that excluding technical and civil society stakeholders creates an operational disconnect that undermines the mechanism’s core purpose. The Internet Society warned that decisions on cyber norms should prioritise input from those who build and secure Internet infrastructure, otherwise the mechanism risks being disconnected from operational reality . Chatham House noted that the challenge is not whether expertise exists but whether states will make full use of it . The ICC argued that cybersecurity discussions cannot be separated from the systems, services, and infrastructure they seek to secure . FIRST emphasised that during cyber incidents, security professionals routinely exchange threat intelligence through trusted channels .
It is unexpected that both a private diplomacy organisation focused on humanitarian mediation and the ICRC converged on the need to address the specific challenges of cyber operations in and after armed conflict, an area that had not been prominently featured in previous OEWG discussions. The Centre for Humanitarian Dialogue noted that no ceasefire, armistice, or peace agreement in history has ever had to pay heed to the cyber and information domain , and highlighted the unique challenges posed by malware’s indestructibility and invisibility . The ICRC called on states to focus especially on the limits that IHL imposes on ICT activities that result in non-physical damage , and to consider whether existing international law provides sufficient safeguards against harm from increasingly autonomous ICT capabilities . Both organisations approached this from different angles-humanitarian mediation and international humanitarian law-but reached similar conclusions about the gap in existing frameworks.
It is somewhat unexpected that states from different geopolitical groupings-Switzerland, Australia, Canada, Italy, and Serbia-converged on the practical value of scenario-based exercises and simulations as a tool for building shared understanding, both on international law and on CBMs. Switzerland described the mechanism’s opportunity to turn statements into lively discussions based on real-world scenarios as an innovative step forward . Australia cited its own experience showing that applying international law to concrete cyber incident scenarios helps build confidence and shared understanding . Canada described organising tabletop exercises with FIFA World Cup host cities and collaborating with Mexico, CISA, and US CERTs . Italy highlighted the value of multinational cyber exercises, cyber ranges, and crisis management simulations . Serbia supported regular communication checks, PING exercises, and scenario-based simulation exercises .
It is unexpected that two independent stakeholder organisations-one focused on enterprise architecture and one on realistic attack simulations-converged on the same fundamental insight: that cybersecurity challenges are fundamentally about understanding systemic complexity and interdependencies rather than deploying technologies. FutureEarth Systems argued that enterprise architecture maps how policy intent, legal frameworks, capabilities, processes, data, and technical systems align, using the analogy of a city plan . IMQ Intuity SPA argued from operational experience that cyber risks emerge from the interaction between technology, people, processes, suppliers, and physical infrastructure , and that resilience is limited not by technology alone but by assumptions that have never been challenged . Both organisations positioned their respective approaches as tools for revealing dependencies and strengthening collective preparedness.
Overall Assessment
The discussion revealed strong consensus on several foundational issues: the essential role of multi-stakeholder participation in the mechanism's work; the practical importance of the Global POC Directory as a confidence-building measure; the need for demand-driven, inclusive, and practically oriented capacity building; the applicability of existing international law to cyberspace; and the importance of protecting vulnerable and marginalised communities from cyber threats. There was also broad agreement that the mechanism should focus on implementing existing commitments rather than creating new normative frameworks, and that regional organisations play a vital complementary role. Key areas of divergence included whether new legally binding instruments are needed (with the United States opposing and Algeria, Nicaragua, and others supporting this possibility), and the extent to which stakeholder accreditation objections are legitimate (with most Western and Latin American states opposing the volume of objections while the objecting states were not represented in the discussion). The practical tools and resources available to states for implementing the framework—including the Sybil Portal, Chatham House reports, Geneva Dialogues manual, FIRST membership networks, and the Internet Society's policymaker programme—were highlighted as an area of unexpected richness and readiness.
Points of Difference
Whether existing international law is sufficient or whether new legally binding instruments are needed to govern state behaviour in cyberspace
The United States firmly stated it will not support language suggesting new binding obligations are required or that existing legal obligations are insufficient , arguing that any proposal to use DTG1 to relitigate international law as a vehicle for treaty-making duplicates work already done and keeps discussions stagnant . Algeria took the opposite position, arguing that the unique attributes of cyberspace – including the speed and sophistication of attacks, difficulty of attribution, and vulnerability of critical infrastructure – demand legal clarity and certainty rather than interpretative ambiguity , and that since the international community has agreed on 11 non-binding norms, it should be able to elaborate legally binding rules . Nicaragua similarly called for keeping open the debate on the progressive development of the international legal framework, including the possibility of drafting legally binding instruments . The ICRC raised a more cautious but related question, calling on member states to consider whether existing international law provides sufficient safeguards against harm from increasingly autonomous ICT capabilities or whether additional limits are needed .
Existing international law applies to activities in cyberspace and is fit for purpose; further discussion should be anchored in concrete threats and practical tools, not used as a vehicle for treaty-making or relitigating settled ground
Algeria supports the elaboration of a legally binding international instrument on state behaviour in cyberspace, arguing that the unique attributes of cyberspace demand legal clarity rather than interpretative ambiguity
Nicaragua calls for continued careful, inclusive, intergovernmental debate on international law in cyberspace, keeping open the possibility of legally binding instruments and coupling discussions with effective capacity building and technology transfer
ICRC calls on states to consider whether existing international law provides sufficient safeguards against harm from increasingly autonomous ICT capabilities, or whether additional limits are needed
United StatesAlgeriaNicaraguaICRC
Whether stakeholder accreditation objections without stated basis are consistent with the agreed inclusivity principle, and whether the current level of stakeholder participation is acceptable
A clear fault line emerged between those states and stakeholders who objected to the exclusion of over 60 stakeholder entities and those (unnamed in the transcript but implicitly responsible for the objections) who lodged those objections. The Discover MUN Foundation noted that objections lodged against more than 60 stakeholder entities, including NGOs, universities, and technical bodies, without any stated basis whatsoever, cannot be considered as inclusivity , and called for transparent, criteria-based accreditation practices . Canada specifically named stakeholders from Mexico, Brazil, Peru, Panama, Ghana, Nigeria, and South Africa as having been vetoed , while Germany highlighted that the organisation Interface, which produced a directly relevant CBM implementation survey, was not allowed to attend . The Association for Progressive Communications argued that the mechanism inflicted an injury on itself by initially locking out many stakeholders . No delegation in the transcript explicitly defended the objections, but their existence – implicitly attributed to certain member states – created a significant structural disagreement about the nature and scope of stakeholder participation.
Youth and children's rights must be fully recognised in the digital environment, and objections to stakeholder accreditation without stated basis undermine the inclusivity principle agreed by consensus – Demand for transparent, criteria-based accreditation
Incident response and security professionals provide indispensable operational expertise on cyber norms and CBM implementation; stakeholder participation must remain open, transparent, and non-politicised
Meaningful stakeholder engagement is not a courtesy but essential, as the Internet is run by a distributed ecosystem; accreditation modalities must be implemented in a predictable and transparent manner
Civil society and technical organisations document empirical evidence of cyber harms, including those affecting vulnerable communities; locking out stakeholders injures the mechanism's effectiveness
The mechanism risks being disconnected from operational reality if non-governmental stakeholders are excluded; states should draw more deliberately on multi-stakeholder expertise both within and beyond official sessions
The number of objections to stakeholder accreditation, including organisations from Latin America, Africa, and other regions, deprives the mechanism of critical cross-regional expertise and must be addressed
Chile rejects the volume of objections to stakeholder participation, including from organisations in its own region, and affirms that diverse stakeholder voices are essential to reflect ground-level realities
Germany highlights that organisations blocked from participation, such as Interface with its CBM implementation survey, have produced work directly relevant to the mechanism's discussions
Japan strongly values the multi-stakeholder approach and hopes to further strengthen public-private collaboration within the UN framework through expert briefings and interactive discussions
The EU welcomes stakeholder contributions and encourages continued cooperation with states on capacity building, research, and implementation of the UN Framework of Responsible State Behaviour
Stakeholder participation is fundamental; Mexico urges stakeholders to draft specific inputs for DTG discussions and share examples of tools, guides, and methodologies to support framework implementation
The private sector possesses real-time threat visibility and operational experience that is essential to the mechanism's success; meaningful, structured, and predictable stakeholder participation must be ensured across all areas of work
Policy Context (Knowledge Base)
The 1st meeting plenary of the Global Mechanism documented outstanding objections to stakeholder accreditation that the Chair was unable to resolve through informal consultations, with smaller and developing states highlighting the impact of mass objections [S184]. This tension between the agreed inclusivity principle and accreditation practice has been a persistent fault line in the process [S185].
Discover MUN FoundationForum of Incident Response and Security TeamsInternet SocietyAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeCanadaChileGermanyJapanEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoMexicoInternational Chamber of Commerce
Whether the scope of international law discussions in the DTGs should be broad and exploratory or narrowly anchored in concrete threats and practical implementation tools
The United States argued that further discussion of international law in the mechanism should be anchored in concrete threats and practical tools for addressing them, and that the mechanism should focus on implementing the 11 norms states have already committed to rather than relitigating settled ground . Australia and Switzerland, while also supporting scenario-based and practical discussions , went further in calling for consolidation of common understandings on areas not yet reflected in the OEWG final report, including international human rights law, the law of state responsibility, and IHL . Nicaragua and Algeria pushed for an even broader scope, with Nicaragua calling for continued debate on the progressive development of the international legal framework including the possibility of legally binding instruments , and Algeria arguing the international community should move towards collectively negotiating how states must behave in cyberspace .
Existing international law applies to activities in cyberspace and is fit for purpose; further discussion should be anchored in concrete threats and practical tools, not used as a vehicle for treaty-making or relitigating settled ground
Australia supports consolidating common understandings on how international human rights law, the law of state responsibility, and IHL apply in cyberspace, using concrete incident scenarios to build confidence and shared understanding
Switzerland supports concrete discussions on real-world scenarios, particularly on protecting critical infrastructure such as hospitals and water systems, and highlights the ICT work stream under the Global IHL Initiative as a valuable complementary platform
Nicaragua calls for continued careful, inclusive, intergovernmental debate on international law in cyberspace, keeping open the possibility of legally binding instruments and coupling discussions with effective capacity building and technology transfer
Algeria supports the elaboration of a legally binding international instrument on state behaviour in cyberspace, arguing that the unique attributes of cyberspace demand legal clarity rather than interpretative ambiguity
Policy Context (Knowledge Base)
Austria’s position in favour of scenario-based, practice-oriented DTG discussions [S180] contrasts with other delegations’ preferences for broader normative exploration. The 4th meeting plenary recorded a broad consensus for practical, action-oriented DTG forums [S181], though the 2nd organisational session noted that priority should remain on a limited number of key implementation priorities [S182], suggesting ongoing tension about scope.
United StatesAustraliaSwitzerlandNicaraguaAlgeria
Whether the Global POC Directory should be used flexibly and broadly or strictly in accordance with its original mandate, and whether its use should be constrained to avoid misuse
While all speakers supported the POC Directory in principle, a nuanced disagreement emerged about its appropriate use. The Republic of Korea explicitly stated that the directory must not be misused or exploited for purposes inconsistent with its original intent , and the United Kingdom noted that the existence of the POC directory does not alter a state’s right to attribute irresponsible cyber behaviour and that states may decide using it is not appropriate if malicious activity is part of a deliberate state-sponsored campaign . By contrast, Tonga called for the directory to be used proportionately, purposefully, and with due regard for the capacity constraints of smaller states , while Kiribati emphasised that for small states the directory is the difference between facing an incident alone and facing it with help . Singapore advocated for flexible use before standard templates and procedures are developed , suggesting a more permissive approach than the Republic of Korea and the United Kingdom.
The UN POC directory is one of the most significant OEWG achievements; it must be used responsibly and in good faith, and should not be misused for purposes inconsistent with its original intent of facilitating cooperative communication
The POC directory complements existing formal and informal networks; its existence does not alter a state's right to attribute irresponsible cyber behaviour, and states may choose whether using it is appropriate in any given incident
For Pacific small island developing states, CBMs are among the most immediately practical elements of the framework; the Global POC Directory must be actively maintained and used in good faith, with due regard for the capacity constraints of smaller states
For Kiribati, the Global POC Directory is the difference between facing a cyber incident alone and facing it with help; CBMs succeed when they are simple, sustained, and relationship-based, and regional organisations are laboratories for global CBMs
Singapore emphasises that CBMs are a team effort requiring states to share best practices and implementation lessons; the POC directory should be used flexibly before standard templates and procedures are developed
Policy Context (Knowledge Base)
Russia has highlighted the importance of the Global POC Directory as a confidence-building tool [S174], while its original mandate focused on facilitating communication and crisis management [S175]. China has supported its role in enhancing practical state-to-state communication [S176]. The tension between flexible use and strict mandate adherence reflects broader debates about the directory’s scope documented across multiple OEWG sessions [S173][S175].
Republic of KoreaUnited KingdomTonga on behalf of the Forum of Pacific IslandsKiribatiSingapore
Unexpected Differences
It was unexpected that a disagreement would emerge around the POC Directory, which was widely celebrated as one of the OEWG’s most significant achievements. The Republic of Korea explicitly warned that the directory must not be misused or exploited for purposes inconsistent with its original intent , and the United Kingdom noted that states may decide using it is not appropriate if malicious activity is part of a deliberate state-sponsored campaign . This implicit concern – that the directory could be used to send political messages or to contact states in ways that go beyond its cooperative incident-response mandate – was entirely absent from the statements of Pacific small island states, for whom the directory represents a fundamental lifeline . Tonga called for the directory to be used with due regard for the capacity constraints of smaller states , suggesting a concern that larger states might overwhelm small administrations with messages, while the Republic of Korea and the United Kingdom were concerned about a different form of misuse. This revealed an unexpected asymmetry in how states of different sizes and geopolitical positions perceive the same instrument.
MGIMO raised the issue of the neutrality of large language models with regard to international affairs, the everyday work of diplomats, and media coverage of world events, noting that they have identified profound inconsistencies, irregularities, and sentiment shifts in LLM responses on international affairs issues , as well as a lack of language and cultural diversity in LLM outputs . This was an unexpected contribution because no other speaker addressed this specific dimension of AI governance in the context of cybersecurity and international security. While other speakers discussed AI in terms of security vulnerabilities , offensive capabilities , and deployment risks , MGIMO’s focus on LLM bias and neutrality as a diplomatic and security concern was distinctive and went uncontested, leaving it as an isolated argument without any counterpoint or corroboration from other participants.
The Centre for Humanitarian Dialogue raised the specific and novel issue of confidence building in the cyber and information domain after armed conflict, noting that no ceasefire, armistice, or peace agreement in history has ever had to pay heed to the cyber and information domain . They highlighted the unique characteristics of malware – its indestructibility, invisibility, and ability to be deployed from anywhere – as making this domain particularly challenging for post-conflict stabilisation. This was an unexpected area of disagreement by omission: despite the Centre’s offer to assist the mechanism in developing such CBMs , no state delegation engaged with or responded to this specific proposal during the subsequent CBM discussions. States focused on the POC Directory, regional CBMs, and operationalisation of the eight existing measures, leaving the post-conflict cyber CBM gap entirely unaddressed in the state-level discussion.
Overall Assessment
The discussion revealed three principal areas of disagreement: (1) a fundamental divide between states favouring new legally binding instruments for cyberspace governance and those insisting existing international law is sufficient and fit for purpose; (2) a structural conflict between the broad coalition of stakeholders and supportive states who argued that the exclusion of over 60 stakeholder entities without stated basis violates the agreed inclusivity principle, and the unnamed states responsible for those objections; and (3) nuanced differences about the appropriate use and scope of the Global POC Directory, particularly between larger states concerned about misuse and small island developing states for whom the directory is a critical lifeline. Partial agreements were found on the need for demand-driven capacity building, the value of the eight existing CBMs, and the importance of scenario-based discussions on international law, though the depth and direction of these discussions remained contested.
All speakers agreed that international law applies to cyberspace and that discussions on its application should continue within the global mechanism . The United States, Australia, Switzerland, and others agreed that discussions should be grounded in concrete scenarios and real-world application . However, they diverged sharply on whether this should lead to new legally binding instruments or remain focused on implementing existing commitments . The ICRC's call to consider whether existing law provides sufficient safeguards represents a middle position that acknowledges the question without prejudging the answer.
Agreed
United StatesAustraliaSwitzerlandAlgeriaNicaraguaICRCDiscover MUN Foundation
Contested
Existing international law applies to activities in cyberspace and is fit for purpose; further discussion should be anchored in concrete threats and practical tools, not used as a vehicle for treaty-making or relitigating settled ground Australia supports consolidating common understandings on how international human rights law, the law of state responsibility, and IHL apply in cyberspace, using concrete incident scenarios to build confidence and shared understanding More than 40 states have issued positions on international law in cyberspace and more than 36 national positions have been published, demonstrating broad appetite for substantive discussions grounded in real-world scenarios in the DTGs Algeria supports the elaboration of a legally binding international instrument on state behaviour in cyberspace, arguing that the unique attributes of cyberspace demand legal clarity rather than interpretative ambiguity Nicaragua calls for continued careful, inclusive, intergovernmental debate on international law in cyberspace, keeping open the possibility of legally binding instruments and coupling discussions with effective capacity building and technology transfer IHL applies to ICT activities in armed conflict; states should focus discussions on how IHL limits ICT operations causing non-physical damage and on protecting civilian ICT infrastructure and data Youth and children’s rights must be fully recognised in the digital environment, and objections to stakeholder accreditation without stated basis undermine the inclusivity principle agreed by consensus – Demand for transparent, criteria-based accreditation
All stakeholder organisations and the majority of state delegations that spoke agreed that meaningful multi-stakeholder participation is essential to the mechanism's success . They agreed that the current level of participation is insufficient due to objections lodged against over 60 entities . However, they differed in emphasis: some focused on the procedural problem of objections without stated basis , others on the operational cost of exclusion , and others on the positive case for inclusion . The mechanism's modalities document was cited as the agreed basis for inclusivity , but its implementation remained contested in practice.
Agreed
Discover MUN FoundationForum of Incident Response and Security TeamsInternet SocietyAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeKenya ICT Action NetworkInternetLabAccess NowCanadaChileGermanyJapanEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoMexicoInternational Chamber of Commerce
Contested
Youth and children’s rights must be fully recognised in the digital environment, and objections to stakeholder accreditation without stated basis undermine the inclusivity principle agreed by consensus – Demand for transparent, criteria-based accreditation Incident response and security professionals provide indispensable operational expertise on cyber norms and CBM implementation; stakeholder participation must remain open, transparent, and non-politicised Meaningful stakeholder engagement is not a courtesy but essential, as the Internet is run by a distributed ecosystem; accreditation modalities must be implemented in a predictable and transparent manner Civil society and technical organisations document empirical evidence of cyber harms, including those affecting vulnerable communities; locking out stakeholders injures the mechanism’s effectiveness The mechanism risks being disconnected from operational reality if non-governmental stakeholders are excluded; states should draw more deliberately on multi-stakeholder expertise both within and beyond official sessions Multi-stakeholder expertise must be systematically integrated into informal consultations, technical drafting, and policy implementation, with formal channels for grassroots data from developing nations Capacity building must be sustainable, demand-driven, and inclusive, with better coordination among existing initiatives, support for states with limited resources, and cooperation on secure open-source cybersecurity tools Out of 313 Internet shutdowns documented in 2025, 125 occurred in conflict situations; DTGs must make the human cost of critical infrastructure attacks visible and foreground the role of civil society in its defence The number of objections to stakeholder accreditation, including organisations from Latin America, Africa, and other regions, deprives the mechanism of critical cross-regional expertise and must be addressed Chile rejects the volume of objections to stakeholder participation, including from organisations in its own region, and affirms that diverse stakeholder voices are essential to reflect ground-level realities Germany highlights that organisations blocked from participation, such as Interface with its CBM implementation survey, have produced work directly relevant to the mechanism’s discussions Japan strongly values the multi-stakeholder approach and hopes to further strengthen public-private collaboration within the UN framework through expert briefings and interactive discussions The EU welcomes stakeholder contributions and encourages continued cooperation with states on capacity building, research, and implementation of the UN Framework of Responsible State Behaviour Stakeholder participation is fundamental; Mexico urges stakeholders to draft specific inputs for DTG discussions and share examples of tools, guides, and methodologies to support framework implementation The private sector possesses real-time threat visibility and operational experience that is essential to the mechanism’s success; meaningful, structured, and predictable stakeholder participation must be ensured across all areas of work
All speakers on CBMs agreed that the focus should be on implementing the eight existing voluntary CBMs rather than developing new ones . They agreed on the value of the Global POC Directory . However, they diverged on the appropriate pace and scope of operationalisation: Switzerland and others emphasised that the challenge is not to develop new CBMs but to implement those already agreed , while South Africa supported elaborating a new global cybersecurity cooperation and capacity-building portal . The Republic of Korea and the United Kingdom added caveats about responsible use and non-misuse of the POC Directory , which were not emphasised by Pacific small island states who focused on the directory's life-saving potential for small states .
Agreed
The Dominican RepublicTonga on behalf of the Forum of Pacific IslandsEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoRepublic of KoreaCosta RicaAlbaniaItalyKiribatiUnited KingdomSerbiaSouth AfricaSingaporeNaoeroSwitzerlandCanadaPapua New Guinea
Contested
The eight voluntary global CBMs adopted by the OEWG constitute a fundamental pillar of the responsible state behaviour framework; the mechanism should now focus on their practical and inclusive operationalisation, supported by a working paper from the cross-regional Confidence Builders group For Pacific small island developing states, CBMs are among the most immediately practical elements of the framework; the Global POC Directory must be actively maintained and used in good faith, with due regard for the capacity constraints of smaller states The EU supports operationalising the eight agreed CBMs, including integrating the POC directory into the global mechanism’s portal, organising seminars and workshops, and promoting information exchange on cooperation and partnerships The UN POC directory is one of the most significant OEWG achievements; it must be used responsibly and in good faith, and should not be misused for purposes inconsistent with its original intent of facilitating cooperative communication Costa Rica supports the Global POC Directory as a valuable operational tool for managing cross-border incidents and reducing misunderstandings, and emphasises that legal transparency through publishing national positions on international law also serves as a CBM Albania’s experience shows that CBMs work through layered cooperation—political, diplomatic, and technical—across the UN, EU, OSCE, ITU, and bilateral relations, with each layer reinforcing the others and building capacity that in turn builds trust Italy emphasises the importance of regional CBMs, particularly those developed by the OSCE, and highlights the value of multinational cyber exercises, cyber ranges, and structured information-sharing mechanisms involving governments, industry, and academia For Kiribati, the Global POC Directory is the difference between facing a cyber incident alone and facing it with help; CBMs succeed when they are simple, sustained, and relationship-based, and regional organisations are laboratories for global CBMs The POC directory complements existing formal and informal networks; its existence does not alter a state’s right to attribute irresponsible cyber behaviour, and states may choose whether using it is appropriate in any given incident Serbia supports the Global POC Directory and draws on its OSCE experience, including sponsoring CBM-9 on national terminologies, to demonstrate the value of practical cooperation in improving mutual understanding South Africa regards the POC Directory as a first step to greater cooperation and supports the proposed global cybersecurity cooperation and capacity-building portal as a further CBM to be elaborated in the DTGs Singapore emphasises that CBMs are a team effort requiring states to share best practices and implementation lessons; the POC directory should be used flexibly before standard templates and procedures are developed Nauru, as incoming chair of PACSON, intends to strengthen the connection between the Pacific’s operational cooperation and the global mechanism’s CBMs, and calls for the directory to remain practical, exercised, and supported by training of designated officials Switzerland emphasises that the challenge is not to develop new CBMs but to implement those already agreed; regional and sub-regional organisations play a key role and a structured exchange between the global mechanism and regional organisations should be established Canada’s participation in tabletop exercises during FIFA World Cup preparations, coordinating with Mexico, CISA, and US CERTs, illustrates how CBM operationalisation through simulation exercises can build practical cooperation Papua New Guinea believes the global mechanism should help countries strengthen core capabilities including cyber hygiene, national incident response, and legal frameworks, with CBMs producing practical outcomes through regular communication, joint exercises, and lessons-learned exchanges
All speakers agreed that capacity building must be demand-driven and responsive to the needs of developing countries and vulnerable communities . They agreed that existing resources and initiatives should be better coordinated rather than duplicated . However, they differed in emphasis: some focused on technical capacity building , others on legal and diplomatic capacity , and others on human-centric and gender-sensitive approaches . The African Union specifically highlighted legal and institutional capacity building as an important area , while KICTANET emphasised moving resources beyond high-level legal meetings towards local incident response teams .
Agreed
Developing Capacity LTDKenya ICT Action NetworkInternetLabAssociation for Progressive CommunicationsRoyal Institute of International Affairs (Chatham House) RepresentativeAfrican UnionPapua New GuineaTonga on behalf of the Forum of Pacific Islands
Contested
Capacity-building practitioners have published practical suggestions for the mechanism and recommend prioritising quick wins through matchmaking and funding coordination, addressing strategic resource gaps, and improving quality and demand-driven delivery Capacity building must be human-centric and demand-driven, moving beyond high-level legal meetings to strengthen local incident response teams, defend civic space, and protect vulnerable communities Capacity building must be sustainable, demand-driven, and inclusive, with better coordination among existing initiatives, support for states with limited resources, and cooperation on secure open-source cybersecurity tools State-led capacity-building programmes must address the disproportionate impact of cyber threats on vulnerable communities including women, LGBTQI+ people, and human rights defenders, whose unique threats are often unrecognised or unrecorded The mechanism risks being disconnected from operational reality if non-governmental stakeholders are excluded; states should draw more deliberately on multi-stakeholder expertise both within and beyond official sessions Capacity building for international law in cyberspace is an important area for the global mechanism; the AU Commission convened a workshop to strengthen member states’ capacity to develop national positions on the application of international law Papua New Guinea emphasises that capacity building must be demand-driven, nationally owned, and responsive to each country’s level of digital maturity, particularly for small island developing states For Pacific small island developing states, CBMs are among the most immediately practical elements of the framework; the Global POC Directory must be actively maintained and used in good faith, with due regard for the capacity constraints of smaller states
Key Takeaways
Stakeholder participation is widely regarded as essential to the global mechanism’s effectiveness, not merely a courtesy; the large number of objections to accreditation without stated basis was condemned by multiple delegations and stakeholder organisations as undermining the inclusivity principle agreed by consensus.
The mechanism must move from endorsement of agreed frameworks to practical operationalisation and implementation, with the Dedicated Thematic Groups (DTGs) identified as the primary vehicle for translating dialogue into concrete action.
Existing international law, including international humanitarian law (IHL) and international human rights law, applies to state conduct in cyberspace; the majority of delegations support deepening common understanding of how these bodies of law apply in practice, particularly through real-world scenarios and case studies.
A minority of states, notably Algeria and Nicaragua, called for the elaboration of a legally binding international instrument on state behaviour in cyberspace, arguing that the unique attributes of cyberspace demand legal clarity beyond voluntary norms; the United States firmly opposed any such approach.
The eight voluntary global confidence-building measures (CBMs) adopted by the previous Open-Ended Working Group (OEWG) are widely supported; the priority now is their practical operationalisation rather than the development of new measures.
The Global Points of Contact (POC) Directory is regarded as one of the most significant achievements of the OEWG and a critical practical tool, particularly for small and developing states; it must be actively maintained, regularly exercised, and used in good faith and proportionately.
Capacity building must be demand-driven, nationally owned, inclusive, and responsive to each country’s level of digital maturity, with particular attention to the needs of developing countries, small island developing states, and marginalised communities.
Emerging technologies, particularly artificial intelligence, are changing the cyber threat landscape at speed; the mechanism must build shared understanding of their implications for cybersecurity, including whether existing international law provides sufficient safeguards for increasingly autonomous ICT capabilities.
Vulnerable and marginalised communities, including women, children, LGBTQI+ people, and human rights defenders, face disproportionate and often undocumented cyber threats; the mechanism and its DTGs must ensure these differentiated impacts are recognised and addressed.
Regional organisations are not merely implementers of globally agreed CBMs but laboratories for them; a structured exchange between the global mechanism and regional and sub-regional organisations is needed to share lessons learned and avoid duplication.
The multi-stakeholder community, including the private sector, technical community, civil society, and academia, already contributes substantially to implementing the framework for responsible state behaviour; states should draw more deliberately on this expertise both within and beyond official sessions.
Transparency measures, including publishing national positions on the application of international law in cyberspace and sharing information on CBM implementation, are themselves confidence-building measures that reduce uncertainty and facilitate dialogue.
Resolutions & Action Items
The cross-regional Confidence Builders group (led by the Dominican Republic) announced it is preparing a working paper ahead of the December session highlighting the practical value of CBMs and best practices from regional and sub-regional implementation, to be uploaded to the mechanism’s website.
The Chair requested all stakeholder organisations to share their written statements with both the Secretariat and the Chair’s team.
Canada announced it has published its responses to the UNIDIR survey on the implementation of norms, international law, CBMs, and capacity building, as a concrete practice of CBM-3 on information sharing.
Canada expressed support for holding a second simulation exercise on the Global POC Directory in the autumn to reduce the risk of misunderstanding or escalation during significant or urgent incidents.
The African Union Commission announced it convened a workshop from 1–3 June 2026 in Addis Ababa to strengthen AU member states’ capacity to develop national positions on the application of international law to cyberspace.
Nauru announced it will assume the chairmanship of the Pacific Cybersecurity Operational Network (PACSON) and intends to strengthen the connection between the Pacific’s operational cooperation and the global mechanism’s CBMs during its chairmanship.
ICANN, the Internet Society, and the ITU announced a briefing entitled ‘Demystifying the Internet: Collaborative Security Approaches’ to be held the following day in Conference Room 8 during the lunch break, co-organised with the Permanent Missions of Kenya and Bulgaria.
Developing Capacity LTD highlighted the Sybil Portal as a ready platform for hosting capacity-building resources and noted it is undergoing renewal to serve as a state and stakeholder platform going forward.
The Royal Institute of International Affairs (Chatham House) indicated that the multi-stakeholder community is discussing mapping existing practical resources and making them available to states, and welcomed views on the most useful format for doing so.
FutureEarth Systems offered to meet with representatives from Mexico to explore how enterprise architecture can assist states with implementation of the norms.
FIRST noted it has 31 member teams in Mexico and an upcoming Mexico City Technical Colloquium, and offered to support Mexico and other interested states in implementing responsible behaviour frameworks.
The Internet Society offered to connect the Mexican delegation with information about its policymaker programme on how the Internet works and how standards are developed.
Switzerland highlighted the non-paper submitted to the OEWG in June 2025 on the role of regional organisations in implementing the UN Framework, recommending the establishment of a structured exchange between the global mechanism and regional and sub-regional organisations.
The Chair confirmed that discussions on confidence-building measures would continue the following morning, with 18 delegations remaining on the speakers’ list.
The Chair encouraged delegations to send statements to eStatement.com before delivering them on the floor, to assist interpreters.
Unresolved Issues
The accreditation and participation of more than 60 stakeholder entities, including non-governmental organisations, universities, and technical bodies, remains blocked by objections from certain member states without any stated basis; no resolution was reached during the session.
The question of whether existing international law is sufficient to govern state behaviour in cyberspace, or whether a new legally binding international instrument is needed, remains deeply contested, with no convergence between states supporting the status quo and those calling for a treaty.
The precise modalities for meaningful stakeholder participation in the Dedicated Thematic Groups (DTGs), including the participation of non-accredited stakeholders, have not been finalised.
The structure, mandate, and working methods of the DTGs have not been fully agreed; multiple delegations and stakeholders called for them to be actionable and problem-solving vehicles, but the details remain to be determined.
The question of how IHL applies to ICT operations causing non-physical damage, including to civilian data and ICT systems underpinning civilian life, remains an area requiring further discussion among states.
Whether existing international law provides sufficient safeguards against harm from increasingly autonomous ICT capabilities, or whether additional limits are needed, has not been resolved.
The operationalisation of the proposed global cybersecurity cooperation and capacity-building portal linked to the global mechanism has not been finalised and is to be further elaborated in the DTGs.
The proposed voluntary fund to support participation of developing countries in the global mechanism has not been agreed or operationalised.
The question of how to ensure the Global POC Directory is used proportionately and in good faith, with due regard for the capacity constraints of smaller states, has been raised but not formally addressed.
Cross-regional representation of stakeholders remains inadequate, with organisations from Mexico, Brazil, Peru, Panama, Ghana, Nigeria, and South Africa among those whose accreditation was blocked; no mechanism to remedy this was agreed.
The development of confidence-building measures specifically for the cyber and information domain in post-conflict situations, as proposed by the Centre for Humanitarian Dialogue, has not been taken up formally.
The neutrality of large language models with regard to international affairs, raised by MGIMO University, has not been addressed by the mechanism.
Discussions on confidence-building measures were not completed during the session, with 18 delegations still to speak when time ran out.
Suggested Compromises
Several delegations and stakeholders suggested that the DTGs could serve as a space where non-accredited stakeholders participate in line with established UN informal working methods, as a practical middle ground between full accreditation and exclusion.
The multi-stakeholder community proposed mapping existing practical resources—such as the Chatham House report, the Geneva Dialogues manual, the Paris Call commitments, and sector-specific guidance—and making them available to states in a format useful for DTG discussions, as a way to bridge the gap between existing expertise and state implementation needs.
Switzerland and others suggested that rather than developing new CBMs, the mechanism should focus on implementing the eight already agreed, using the DTGs to share experiences and identify implementation gaps, thereby avoiding contentious negotiations over new measures.
The EU proposed integrating the Global POC Directory into the global mechanism’s portal as an initial step, while remaining open to exploring further development based on lessons learned from its use, balancing ambition with practicality.
Singapore suggested allowing the POC directory to be used flexibly before developing standard templates and procedures, so that states can adapt its use to their needs while the mechanism learns from experience.
The Dominican Republic’s cross-regional Confidence Builders group proposed a working paper drawing on regional and sub-regional implementation experiences to provide comparative guidance on how CBMs can be integrated into DTG discussions, offering a practical, evidence-based foundation for further negotiations.
Australia and others suggested using concrete cyber incident scenarios in the DTGs to build shared understanding of how international law applies, as a way to make progress on legal questions without requiring states to agree on abstract principles first.
Kenya ICT Action Network proposed establishing virtual quarterly or half-yearly meetings to maintain ongoing stakeholder engagement between formal sessions, as a lower-threshold alternative to full in-person participation.
The Royal Institute of International Affairs suggested that the multi-stakeholder community coordinate to provide expertise through all available channels, including outside official sessions, as a practical workaround while accreditation disputes remain unresolved.
“An open, secure, stable, accessible ICT environment cannot and will never be built behind closed doors. We note that these modalities were agreed by consensus on the understanding that inclusivity would be the norm and objection be the exception. But objections that are lodged against more than 60 stakeholder entities, including non-governmental organisations, universities and technical bodies, without any stated basis whatsoever, cannot be considered as inclusivity.”
“Designing confidence-building measures for the non-physical cyber and information domain is a struggle. It is possible to follow troop deployments, to count guns, to observe ships and aircraft, but it is not possible to watch computer code, nor can algorithms be conveniently corralled, assembled in one place, or disabled. Malware can be developed anywhere, transported on a chip, deployed from any point on earth. It is effectively indestructible. I encourage the global mechanism to consider and develop ideas for confidence building in the cyber and information domain after armed conflict.”
“Enterprise architecture maps out how policy intent, legal and regulatory frameworks, capabilities and processes, data and technical systems all align. Think of it like a city plan. It ensures that roads, utilities and buildings work together efficiently and can adapt as the city grows. Using architecture practice in this way can bridge from policy and guidance to implemented operational systems, ensuring optimal alignment of resources and a clearer focus on achieving measurable strategic outcomes.”
“Cyber risks rarely emerge from a single vulnerability. More often, it emerges from the interaction between technology, people, processes, suppliers, physical infrastructure, and the decisions that connect them. The challenge is no longer the number of vulnerabilities. It is the growing number of interdependencies. Rather than asking how we defend ourselves, we ask different questions: if we were the attacker, where would we begin? Looking at ourselves through the eyes of those who seek to exploit us reveals dependencies, challenges assumptions, and helps us understand what truly matters before a crisis occurs.”
“The existence of resources is not the same as the capacity to use them. Guidance cannot implement itself. Many states are committed to implementing the framework but continue to face technical, institutional, or financial constraints as well as competing priorities that make doing so difficult even when practical guidance is readily available. The challenge is not whether this expertise exists but whether it can be implemented and whether states will make full use of it.”
“We have moved beyond the question of whether IHL applies to ICT activities in armed conflict to the more practical and pressing question of how it applies. The discussions have reaffirmed that reliable ICT infrastructure and services are indispensable for successful IHL compliance. Civilians and other protected persons and objects must be safeguarded against the dangers arising from ICT activities during armed conflict.”
“We will not agree to a discussion topic that will be hijacked for that purpose. Our previous discussions on international law have demonstrated that existing legal obligations remain fit for purpose. So further discussion of international law in this mechanism should be anchored in concrete threats and practical tools for addressing them. The United States believes that we should use our time in this GPM to implement the 11 norms states have already committed to and not to relitigate settled ground to manufacture the appearance of a gap that does not already exist.”
“For small island developing states like Kiribati, CBMs are among the most immediately practical elements of the framework of responsible state behavior. We do not maintain extensive networks of bilateral channels or cyber attachés. Predictable, trusted mechanisms for communication between states are, for us, not a convenience. They are the difference between facing an incident alone and facing it with help. This plenary is not only where we discuss confidence building in the abstract. It is where confidence is built.”
“Resonance matters as much as resourcing. The norms will only shape behavior if they are understood beyond this room, not as lists of letters, but as the practical expectations that sit behind them — expectations such as protecting critical infrastructure, cooperating in responding to cyber incidents, or taking reasonable steps to ensure that a state’s territory is not used for internationally wrongful ICT activity. Connecting those expectations to real incidents and real operational challenges helps make the framework something people can recognise, relate to, and ultimately implement. Making it tangible is in itself a form of implementation.”
“CBMs succeed when they are simple, sustained, and relationship-based. Their ambition should be measured in reliability, not in the number of measures adopted. Regional organisations are not merely implementers of globally agreed CBMs. They are laboratories for them. These mechanisms should draw systematically on regional experience, including through regular exchanges with regional parties, and should help connect regional networks, such as PAXON, with their counterparts in other regions, so that what works in one part of the world does not have to be discovered anew in every other.”
How can age-disaggregated data on malicious ICT activity be systematically incorporated into Member States’ submissions under the relevant pillar?
Discover MUN Foundation (on behalf of Major Group for Children and Youth)
Understanding the specific impact of cyber threats on children and youth requires dedicated data collection. Without disaggregated data, policies risk being blind to the disproportionate harms faced by younger populations in digital environments.
What criteria-based, transparent, and principled accreditation practices should be established to ensure predictable and objective procedures for stakeholder and rightholder participation in the global mechanism?
Discover MUN Foundation (on behalf of Major Group for Children and Youth), Association for Progressive Communications, InternetLab, Access Now, Canada, Chile, Germany
Over 60 stakeholder entities, including NGOs, universities, and technical bodies, faced objections to their participation without stated justification. Establishing clear, transparent criteria is essential to uphold the multi-stakeholder principles affirmed in the Global Digital Compact and WSIS+20 review, and to ensure the mechanism is not built behind closed doors.
How can the multi-stakeholder model, including governments, the technical community, civil society, and the private sector, be more effectively and structurally integrated into the work of the Dedicated Thematic Groups (DTGs)?
ICANN, Forum of Incident Response and Security Teams (FIRST), Internet Society, Kenya ICT Action Network, Association for Progressive Communications, Royal Institute of International Affairs (Chatham House), InternetLab, Access Now, International Chamber of Commerce, Canada, Japan, European Union, Chile
Multiple stakeholders and state delegations emphasised that cybersecurity cannot be governed effectively without the operational expertise of non-governmental actors. Structural integration into DTGs would ensure that norms and capacity-building efforts are grounded in operational reality.
What specific guides, guidelines, methodologies, models, or good practices exist to support states, particularly developing countries, in implementing the Framework on Responsible State Behaviour in cyberspace?
Mexico
Mexico explicitly posed this question to stakeholders, seeking practical implementation tools tailored to the needs and perspectives of developing countries. This is critical for closing the gap between agreed norms and their real-world application.
How can enterprise architecture be applied to bridge the gap between policy intent and operational ICT systems, and what would this look like in practice for the global mechanism?
FutureEarth Systems (Chris Sampson)
Enterprise architecture offers a systematic approach to aligning policy, legal frameworks, capabilities, and technical systems. Exploring its application could improve the coherence and measurability of the mechanism’s outcomes and support implementation across diverse national contexts.
How can confidence-building measures be specifically designed for the cyber and information domain in post-conflict or ceasefire situations, where trust is absent and small ICT incidents could trigger renewed hostilities?
Centre for Humanitarian Dialogue
No historical ceasefire or peace agreement has addressed the cyber domain. Given that malware is effectively indestructible and cyber operations are used in hybrid campaigns, the absence of post-conflict cyber CBMs represents a significant and underexplored gap in international peace and security frameworks.
How can the Sybil Portal and similar repositories of cyber capacity-building resources be further developed and sustained as a shared platform for states and stakeholders?
Developing Capacity LTD (Robert Collett)
A centralised, well-maintained repository of capacity-building resources and past projects could significantly improve coordination and efficiency. The portal currently holds 74 documents and information on 100 past projects but is undergoing renewal, raising questions about its long-term governance and funding.
How can realistic attack simulations and adversarial thinking be incorporated into state-level cybersecurity preparedness frameworks to reveal interdependencies and systemic vulnerabilities?
IMQ Intuity SPA (Matteo Tomiazzo)
Operational experience from hundreds of simulations shows that cyber risks emerge from complex interdependencies rather than single vulnerabilities. Integrating this approach into national and international frameworks could fundamentally improve how states understand and prepare for cyber threats.
How can the neutrality of large language models (LLMs) with respect to international affairs, diplomatic language, and media coverage be standardised and evaluated, particularly given observed inconsistencies and lack of linguistic and cultural diversity?
Moscow State Institute of International Relations (MGIMO)
LLMs are increasingly used by diplomats and in media. Identified irregularities and sentiment shifts in LLM outputs on international affairs issues could distort diplomatic processes and public understanding. Developing reproducible benchmarks for LLM evaluation is a nascent but important area of research.
How can the global mechanism ensure that cybersecurity norms and capacity-building efforts address the disproportionate and differentiated impacts of cyber threats on vulnerable communities, including women, LGBTQI+ people, human rights defenders, and communities in the Global South?
Association for Progressive Communications, InternetLab, Access Now, Kenya ICT Action Network
Evidence from civil society research shows that cyber threats, including surveillance, spyware, and coordinated online attacks, affect different communities in fundamentally different ways. Without evidence-based, differentiated analysis, cybersecurity responses risk being ineffective and rights-violating for the most vulnerable.
How can the global mechanism build on existing work in other UN processes regarding AI governance to specifically address the security vulnerabilities introduced by AI deployment, particularly in the public sector and for vulnerable communities?
Association for Progressive Communications, Access Now, Royal Institute of International Affairs (Chatham House), ICRC
The rapid deployment of AI introduces new and poorly understood security vulnerabilities with grave consequences for data confidentiality, information integrity, and system availability. The mechanism needs to determine how to engage with AI-related security risks without duplicating other UN processes.
How can the global mechanism develop a structured exchange with regional and sub-regional organisations to share lessons learned, promote coherence, and avoid duplication in implementing confidence-building measures?
Switzerland, European Union, Singapore, Kiribati, Nauru, Dominican Republic (on behalf of the Cross-Regional Group on CBMs)
Regional organisations such as the OSCE, OAS, ARF, ECOWAS, and PACSON have developed practical CBM experience. A formal mechanism for connecting regional implementation efforts with the global framework could accelerate operationalisation and ensure that successful regional practices are not reinvented elsewhere.
How should the Global Point of Contact (POC) Directory be further developed, maintained, and exercised to ensure it functions as a genuinely useful tool during real cyber incidents, particularly for small states with limited administrative capacity?
Tonga (on behalf of Pacific Islands Forum), Kiribati, Nauru, Republic of Korea, Costa Rica, Singapore, European Union, United Kingdom, South Africa, Canada
The POC Directory is widely recognised as a significant CBM achievement, but concerns were raised about its practical utility, the risk of misuse, the capacity constraints of small states, and the need for regular communication checks and simulation exercises to keep it operational and trusted.
What formal channels should be established to systematically ingest grassroots data on cyber threats, particularly from developing nations and non-state actors operating on the front lines of threat detection and human rights monitoring?
Kenya ICT Action Network
Non-state actors and civil society often have the most granular, real-world data on cyber threats and their human impact. Without formal channels to incorporate this data, international norms risk being disconnected from the actual harms experienced at the community level, especially in developing countries.
How can the mechanism ensure that national cybersecurity laws and policies are developed and implemented consistently with international human rights law and international humanitarian law obligations, and what role should the DTGs play in this?
Access Now, Association for Progressive Communications, InternetLab, Australia, Switzerland
There is a recognised gap between states’ international human rights and IHL obligations and their domestic cybersecurity legislation. Bridging this gap requires both normative clarity and practical capacity-building support, particularly for states that may lack the legal expertise to align national frameworks with international obligations.
Should the global mechanism pursue the elaboration of a legally binding international instrument on state behaviour in cyberspace, and if so, what form should it take and how should it build on existing voluntary norms?
Nicaragua, Algeria, Moscow State Institute of International Relations (MGIMO)
Several delegations argued that the unique characteristics of cyberspace—speed of attacks, difficulty of attribution, vulnerability of critical infrastructure—demand legal certainty beyond voluntary norms. This is a fundamental and contested question about the future direction of the mechanism that requires further deliberation.
How does international humanitarian law apply specifically to ICT operations that result in non-physical damage, such as disruption of civilian data or digital infrastructure, and what additional legal clarity or safeguards may be needed?
ICRC, Switzerland, Australia
Contemporary armed conflicts increasingly involve ICT operations that cause harm without physical destruction. The legal framework for non-physical damage in cyberspace remains underdeveloped, and there is a recognised need for shared understanding on how IHL principles such as distinction, proportionality, and precaution apply in this context.
What practical measures should states take to prevent civilian hackers from committing IHL violations through ICT activities, and how should civilian ICT infrastructure used for military purposes be protected?
ICRC
The blurring of civilian and military roles in cyber operations creates significant IHL compliance challenges. Identifying concrete preventive measures is essential to protect civilian populations and uphold the protective purpose of IHL in the digital domain.
Does existing international law provide sufficient safeguards against the harm that increasingly autonomous ICT capabilities, including AI-enabled systems, can cause, or are additional legal limits needed?
ICRC
The use of AI in ICT operations during armed conflict may increase the speed, scale, and potential for harm of such operations in ways that existing legal frameworks were not designed to address. This is an emerging and urgent question for both the legal and technical communities.
How can capacity-building efforts on the application of international law to cyberspace be made more accessible and demand-driven for developing countries, including through scenario-based training and support for developing national legal positions?
Many developing states lack the technical, legal, and institutional capacity to engage meaningfully in international law discussions or to develop national positions on how international law applies in cyberspace. Without targeted capacity-building, the global discussion will remain unrepresentative and implementation will be uneven.
How can the mechanism map and make accessible the existing body of practical resources—such as the Geneva Dialogue manual, Paris Call commitments, Chatham House reports, and sector-specific guidance—so that states can more easily draw on them for implementation?
Royal Institute of International Affairs (Chatham House), Developing Capacity LTD
A significant body of practical guidance already exists but is fragmented and not easily discoverable by states, particularly those with limited capacity. A systematic mapping and dissemination effort could significantly accelerate implementation without requiring new normative work.
How can the mechanism establish regular virtual or hybrid engagement opportunities—such as quarterly or half-yearly meetings—to maintain meaningful stakeholder participation between formal sessions?
Kenya ICT Action Network
Formal plenary sessions are infrequent and geographically inaccessible for many stakeholders. Regular virtual touchpoints would help sustain engagement, ensure continuity of expertise, and make participation more equitable for organisations not based in New York.
How can the mechanism ensure that the proliferation of commercial spyware, surveillance tools, and cyber mercenary ‘hack-for-hire’ actors is addressed, including their gendered and community-specific impacts on journalists, human rights defenders, and activists?
Access Now, Association for Progressive Communications
The unchecked proliferation of commercial spyware has been documented as causing serious harm to civil society, journalists, and political dissidents. The mechanism needs to determine how to build on the OEWG’s recognition of these harms and develop concrete responses, including addressing the gendered dimensions of these threats.
How can the mechanism address the impact of Internet shutdowns, particularly those occurring in conflict situations, on civilian access to essential services and communication?
Access Now
Access Now documented 313 Internet shutdowns in 2025, of which 125 occurred in conflict situations. This represents a significant and recurring harm to civilian populations that intersects with both IHL obligations and the norms on critical infrastructure protection, yet it remains underaddressed in the mechanism’s framework.
How can the mechanism promote the development of gender-sensitive cybersecurity laws and rapid response mechanisms that holistically address digital violence, including online gender-based political violence?
Association for Progressive Communications, InternetLab
Research from Brazil and other countries has documented how coordinated cyber attacks disproportionately target women politicians and members of marginalised communities, with direct implications for democratic participation. Existing cybersecurity frameworks rarely incorporate gender-sensitive design, leaving these harms unaddressed.
How can the mechanism ensure that technological progress, including AI and digital transformation, narrows rather than widens the digital divide, enabling all states—particularly small island developing states—to participate safely and meaningfully in the global digital economy?
Papua New Guinea, Kiribati, Nauru
Small island developing states face compounded vulnerabilities: limited administrative capacity, geographic isolation, and rapid technological change. Without deliberate efforts to ensure that emerging technologies are accessible and that capacity-building is demand-driven and nationally owned, the digital divide risks deepening existing inequalities in cybersecurity.
Disclaimer: This is not an official session record. DiploAI generates these resources from audiovisual recordings, and they are presented as-is, including potential errors. Due to logistical challenges, such as discrepancies in audio/video or transcripts, names may be misspelled. We strive for accuracy to the best of our ability.
The fifth substantive plenary session of the 2026 Global Mechanism on Development focused on the applicability of international law to the use of ICTs in the context of international security. A broad cross-regional group, speaking through Switzerland, reaffirmed that international law applies to cyberspace and called for deeper discussions on sovereignty, state responsibility, the prohibition of the use of force, international humanitarian law (IHL), and international human rights law, urging that IHL feature prominently in the mechanism’s work . The Pacific Islands Forum, speaking through Tonga, similarly reaffirmed these principles while cautioning against moving prematurely towards new legally binding obligations before states have the capacity to engage with existing law .
The European Union, Australia’s cross-regional group, and numerous individual states including Uruguay, Costa Rica, Ireland, Estonia, and the United Kingdom emphasised that the task before the mechanism is not to relitigate whether international law applies, but to deepen practical understanding of how it applies, including through scenario-based discussions in the Dedicated Thematic Groups (DTGs) . Many delegations stressed that affirming IHL’s applicability to cyberspace does not legitimise or encourage the militarisation of cyberspace, but rather ensures civilian protection during armed conflict .
A recurring theme was the significant capacity gap facing smaller and developing states. Kiribati offered a particularly candid account of the resource constraints faced by small delegations, arguing that legal capacity building is not a footnote to this pillar but its essential precondition . Mauritius, Malawi, and the African Group echoed this, calling for tailored capacity-building initiatives and exchanges of national and regional experiences to enable all states to participate meaningfully .
A notable point of divergence concerned the need for new legally binding instruments. Cuba, Iran, China, Venezuela, and Russia argued that the unique characteristics of cyberspace necessitate new binding rules, with Russia and China endorsing a proposed UN Convention on International Information Security . By contrast, the majority of delegations, including New Zealand, the Republic of Korea, France, and Ireland, opposed new legally binding obligations at this stage, arguing that existing international law is sufficient and that efforts should focus on implementation and common understanding .
Overall, the discussion reflected broad consensus that international law applies to cyberspace, with the mechanism’s primary challenge being to translate that consensus into practical, inclusive, and scenario-based dialogue that strengthens implementation, builds legal capacity across all states, and carries forward the substantive progress achieved in preceding UN processes .
Keypoints
Overall Purpose
The discussion is a formal UN plenary session focused on the applicability of international law to state conduct in cyberspace, held under the framework of the newly established Global Mechanism on Development in the field of information and communication technologies (ICTs) and international security. Delegations sought to build on prior work from the GGEs and OEWGs, deepen common understandings of how existing international law applies in cyberspace, and determine whether additional legally binding obligations are necessary.
—
Major Discussion Points
Broad consensus that international law applies to cyberspace, with debate over how it applies in practice. Nearly all delegations reaffirmed that international law, including the UN Charter, applies to state conduct in cyberspace . However, many noted that the more pressing challenge is moving beyond this general affirmation towards concrete, practical understandings of how specific rules – such as sovereignty, non-intervention, state responsibility, and the prohibition on the use of force – operate in the digital domain . Some states, including Cuba and Venezuela, expressed caution about “automatic” applicability, arguing that the unique characteristics of cyberspace require careful, tailored legal analysis .
The applicability of International Humanitarian Law (IHL) to cyber operations was a significant and contested point. A large cross-regional group, led by Switzerland, strongly advocated for IHL to feature prominently in the mechanism’s work, arguing that applying IHL does not encourage militarisation but rather protects civilians . The EU, Australia, Brazil, Ireland, and others echoed this position . China urged greater prudence, citing unresolved legal and technical difficulties, particularly regarding the involvement of private tech companies in conflicts . Cuba explicitly rejected automatic IHL applicability, warning it could equate cyber attacks with military attacks .
Capacity building was identified as an essential prerequisite for meaningful participation in international law discussions. Kiribati delivered a particularly powerful statement highlighting the resource constraints of small states, noting that international law is their primary defence and that legal capacity building is “the condition of this pillar being real” . The Pacific Islands Forum , African Group , Malawi , Mauritius , and many others stressed that developing countries need tailored support to develop national positions and engage substantively . Scenario-based training and regional workshops were widely proposed as practical tools .
There was a significant divide over whether new legally binding instruments are needed. Cuba, Iran, Russia, China, and Venezuela called for the development of new binding international legal frameworks, arguing that existing law is insufficient to address the unique challenges of cyberspace . Russia specifically promoted its proposed UN Convention on International Information Security . In contrast, the majority of Western and cross-regional states – including the EU, Australia, Switzerland, Republic of Korea, New Zealand, and Ireland – argued that existing international law is fit for purpose and that efforts should focus on clarifying and implementing it rather than negotiating new treaties .
The role of the Dedicated Thematic Groups (DTGs) and the importance of scenario-based, practical legal discussions. Multiple delegations emphasised that the DTGs – particularly DTG1 – should serve as a platform for concrete, scenario-based discussions on how international law applies to real-world cyber challenges, such as attacks on hospitals, energy infrastructure, and critical systems . Austria, Italy, New Zealand, and Canada called for expert briefings, interactive exchanges, and the inclusion of government lawyers and non-governmental stakeholders to enrich these discussions . Ukraine specifically proposed in-depth discussions on protecting healthcare and energy infrastructure .
—
Overall Tone
The overall tone of the discussion was formal, constructive, and largely cooperative, reflecting the diplomatic setting of a UN plenary. Most delegations expressed a genuine commitment to advancing common understandings and building on prior work. However, notable tensions were present throughout. Ukraine’s right-of-reply statement at the outset was sharply adversarial, directly accusing Russia of deliberate disinformation , setting a combative note early in the session. France similarly referenced Russia’s “war of aggression” against Ukraine . Russia’s intervention later in the session was notably assertive, promoting new binding instruments and criticising voluntary norms frameworks . As the session progressed, the tone became more measured and technical, with smaller and developing states – particularly Kiribati , Vanuatu , and Malawi – introducing a more candid and humanising register, emphasising the real-world stakes of legal clarity for vulnerable nations. By the session’s close, the dominant tone was one of cautious optimism, with broad agreement on the need for continued dialogue, even amid unresolved disagreements on the path forward.
Speakers Overview
SO
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, Sweden
114 wpm · 7 min
TO
Tonga on behalf of the Pacific Islands Forum
115 wpm · 4 min
EU
European Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San Marino
157 wpm · 5 min
AO
Australia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and Vietnam
134 wpm · 5 min
SA
South Africa
132 wpm · 4 min
U
Uruguay
130 wpm · 2 min
CR
Costa Rica Delegate
136 wpm · 3 min
I
Italy
149 wpm · 3 min
P
Portugal
139 wpm · 3 min
C
Cameroon
101 wpm · 5 min
K
Kiribati
132 wpm · 6 min
A
Austria
200 wpm · 4 min
M
Malawi
124 wpm · 5 min
S
Singapore
158 wpm · 2 min
C
Colombia
114 wpm · 5 min
RO
Republic of Korea
129 wpm · 2 min
NZ
New Zealand
139 wpm · 4 min
I
Israel
125 wpm · 4 min
E
Estonia
113 wpm · 5 min
UK
United Kingdom
149 wpm · 4 min
A
Armenia
133 wpm · 2 min
M
Mexico
97 wpm · 2 min
C
Cuba
125 wpm · 5 min
IR
Islamic Republic of Iran
127 wpm · 4 min
NN
Nigeria Nigeria on behalf of the Africa Group
113 wpm · 2 min
N
Netherlands
140 wpm · 2 min
B
Brazil
129 wpm · 5 min
G
Germany
167 wpm · 3 min
M
Mauritius
121 wpm · 5 min
V
Venezuela
125 wpm · 2 min
V
Vanuatu
128 wpm · 3 min
C
China
142 wpm · 3 min
F
France
134 wpm · 3 min
J
Japan
103 wpm · 1 min
C
Canada
105 wpm · 4 min
I
Ireland
132 wpm · 4 min
T
Turkey
124 wpm · 2 min
U
Ukraine
134 wpm · 8 min
T
Thailand
110 wpm · 4 min
A
Albania
112 wpm · 4 min
RF
Russian Federation
104 wpm · 5 min
I
Indonesia
146 wpm · 2 min
G
Ghana
110 wpm · 2 min
P
Philippines
119 wpm · 4 min
B
Botswana
144 wpm · 2 min
CE
Chair Egriselda López
141 wpm · 10 min
Expanded Summary: Fifth Substantive Plenary Session of the 2026 Global Mechanism on ICT Security – Applicability of International Law
#
Opening and Ukraine’s Right of Reply
The fifth meeting of the substantive plenary session of the 2026 Global Mechanism on Development in the field of information and communication technologies (ICTs) in the context of international security was called to order by Chair Egriselda López . Before proceeding to the main agenda item, the Chair gave the floor to Ukraine to exercise a right of reply in relation to an intervention made the previous day by the Russian Federation .
Ukraine’s right of reply was sharply adversarial in tone and set a politically charged atmosphere for the session. The delegation characterised Russia’s previous intervention as “an act of intentional disinformation and information manipulation,” noting that it had been “over-exaggeratedly emotional, with elaborated epithets and lack of factual reference” . Ukraine applied criteria suggested by AI for evaluating disinformation – including excessive emotional appeal and absence of factual reference – directly to Russia’s speech, framing the exercise as a live “situational tabletop exercise on a practical case of a disinformation attempt happening right here in this room” . Ukraine cited specific facts omitted from Russia’s intervention: the International Criminal Court’s issuance of arrest warrants for Russian officials including President Putin for the crime of aggression; Russia’s temporary occupation of under 20 per cent of Ukrainian territory, recognised as Ukrainian by numerous General Assembly resolutions; and the permissive environment for criminal cyber ecosystems maintained by Russian occupational administrations on temporarily occupied Ukrainian territories . Ukraine concluded by formally “reporting” Russia’s intervention so that it would “not be disseminated,” signing off with “Hashtag stop fake” . This framing – turning a procedural right of reply into a demonstration of the forum’s own subject matter – established a combative geopolitical undercurrent that persisted throughout the session.
#
Transition to the International Law Agenda Item
Following Ukraine’s right of reply, the Chair moved the session to the next agenda item: the continued study of the applicability of international law in the use of ICTs, including consideration of whether any gaps exist and possible future elaboration of additional legally binding obligations if appropriate . The Chair encouraged delegations to deliver abridged versions of their statements and to submit full texts to eStatements, noting that a timer would be displayed on screen . Group statements were given priority, with the Chair inviting those wishing to speak on behalf of a group to approach the secretariat .
#
The Cross-Regional Group Statement: Five Priority Areas
Switzerland delivered the first and most structurally significant statement of the session, speaking on behalf of a large cross-regional group spanning all UN regional groups – including Austria, Belgium, Brazil, Bulgaria, Canada, Chile, Colombia, Croatia, Czechia, Egypt, Estonia, Finland, France, Germany, Ghana, Hungary, Italy, Ireland, Latvia, Lithuania, Luxembourg, Mexico, the Kingdom of the Netherlands, Norway, Poland, Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, Sweden, and Switzerland itself . The group articulated a clear collective conviction: “clarifying the concrete application of international law to conduct in cyberspace will be central to the work of this global mechanism” . Building on the consensus reports of the GGEs of 2010, 2013, 2015, and 2021, and the final reports of the 2019-2021 and 2021-2025 OEWGs, the group reaffirmed that “international law applies to the use of ICTs” and that “the task before us is to deepen our common understanding of how exactly it applies” [S184][S185].
The group expressed particular regret that the final OEWG report had not retained explicit language on international humanitarian law (IHL), describing this as “especially regrettable” and identifying IHL as “a priority for the mechanism” . It pointed to two cross-regional working papers submitted during the OEWG in July 2025 as a solid basis for future work: one on the application of international law to ICTs, identifying areas of emerging convergence on state responsibility, human rights obligations, peaceful settlement of disputes, and IHL; and another specifically elaborating the rules and principles of IHL applicable to cyber operations . The group also highlighted the resolution adopted at the 34th International Conference of the Red Cross and Red Crescent in 2024 and the ICT work stream under the Global Initiative to Galvanise Political Commitment to IHL as complementary processes providing an invaluable basis for the mechanism’s work .
On the contested question of IHL applicability, the group was unequivocal: “Applying IHL does not increase the risk of armed conflict in cyberspace. Failing to apply it leaves that risk unaddressed and civilians and other protected persons and objects less protected” . The group proposed that the mechanism address five priority areas of international law in a structured and inclusive manner: (1) sovereignty and the prohibition of intervention; (2) state responsibility and due diligence; (3) the prohibition of the use of force and the right of self-defence under Article 51 of the UN Charter; (4) IHL as it applies to cyber operations in situations of armed conflict, including the principles of distinction, proportionality, precaution, necessity, and humanity; and (5) the application of international human rights law (IHRL) to state conduct in cyberspace . The group encouraged the co-facilitators of Dedicated Thematic Group 1 (DTG1) to ensure that international law, including IHL, features prominently in its substantive work, and called for dedicated, scenario-based discussions on the application of these rules to real-world situations, including the protection of critical infrastructure such as hospitals, water systems, and energy networks .
#
Pacific Islands Forum: Principled Approach and Caution on New Obligations
Tonga, speaking on behalf of the Pacific Islands Forum (PIF) – comprising Australia, the Cook Islands, Fiji, Kiribati, the Federated States of Micronesia, the Republic of the Marshall Islands, Nauru, New Zealand, Palau, Papua New Guinea, Samoa, Solomon Islands, Tuvalu, Vanuatu, and Tonga – reaffirmed that international law applies to state conduct in cyberspace, including IHL and human rights law . The PIF called on the global mechanism to build on OEWG progress and to acknowledge areas of broad convergence while providing space for states to continue developing common understandings .
A distinctive element of the PIF’s statement was its caution about moving prematurely towards new legally binding obligations. The Forum argued that “before we can have a meaningful discussion on whether there are gaps, we need the legal capacity to understand and apply the existing framework” . It emphasised that legal capacity building should be “a practical and cross-cutting priority of the global mechanism,” proposing scenario-based training, regional workshops, peer exchanges, and accessible expert briefings as practical tools . The PIF also noted the value of the DTGs in creating “a less formal and more practical environment for legal dialogue among states” [S195].
#
European Union and Australia’s Cross-Regional Group
The European Union, speaking on behalf of its member states and a wide group of candidate and associated countries including North Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia-Herzegovina, Georgia, Norway, and San Marino, reaffirmed full commitment to the application of international law in cyberspace, including the UN Charter, IHRL, IHL, and the law on state responsibility . The EU stressed that “a better global common understanding of how international law applies to cyberspace is necessary to contribute to global cyber resilience and further transparency, predictability, and accountability for states’ conduct in cyberspace” . It noted that over 100 states had now published national or regional positions on international law – including the EU’s own common understanding presented in 2024 and the African Union’s common position, both of which had served as catalysts for this achievement – describing this as “a real achievement” . The EU explicitly stated that “recognising the application of IHL in cyberspace does not lead to nor encourage the militarisation of cyberspace, nor does it legitimise cyber warfare” , and called for the global mechanism and its DTGs to serve as a new opportunity to reflect on practical application in real-world scenarios [S191].
Australia, speaking on behalf of a cross-regional group including Chile, Colombia, the Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, the Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu, and Vietnam, similarly reaffirmed that international law is “a key pillar of the framework for responsible state behaviour” . The group called for detailed and substantive discussions on the application of international law in DTG1, and for DTG2 to better enable states to develop national positions and enhance implementation . It specifically called on the mechanism to draw on the cross-regional working papers on international law and IHL produced in the OEWG context, and emphasised that “emerging common understandings reached during these discussions must be reflected in the reporting of this mechanism” [S202].
#
Individual State Contributions: Deepening Practical Understanding
A succession of individual state delegations elaborated on the theme of deepening practical understanding of how international law applies. South Africa noted that the lived experience and practice of member states in applying international law to cyberspace is “a practical resource,” and suggested that broadening understanding could be achieved by allowing presentations by legal experts from civil society and academia . It affirmed that a cyber operation constitutes an internationally wrongful act when attributable to a state and involving a breach of an international obligation, and that states must take reasonable steps to address harmful activity emanating from their territory when notified . South Africa also highlighted the particular vulnerability of women and marginalised groups to ICT security breaches and disinformation campaigns .
Uruguay reaffirmed that international law is “the foundation for preserving international peace, security and stability, including in the use of ICTs,” and recognised the contributions of the inter-regional group on international law, particularly regarding IHRL, IHL, and state responsibility . It described the global mechanism as “an opportunity to continue with this progress and to consolidate an inclusive forum where we can further develop common understandings” .
Costa Rica offered three substantive reflections. First, it argued that the added value of the global mechanism lies in “moving beyond a general affirmation of applicability towards a more concrete, technical, and inclusive understanding as to how these legal concepts apply to specific situations,” including operations involving proxies, digital coercion, attribution, response measures, and operations below the threshold of the use of force . Second, it noted that certain cyber operations can be legally significant when they cause physical damage, loss of functionality, or interference with inherently governmental functions, and that coercive operations targeting electoral processes or essential services may raise issues under the principle of non-intervention . Third, Costa Rica called for addressing attribution “with rigour and prudence,” promoting good practices and confidence-building measures to distinguish between technical, political, and legal attribution – a conceptual disaggregation not made by most other delegations .
Italy aligned with the EU statement and added national considerations, reaffirming that international law is “fully applicable and relevant in the digital age” . It noted that it had published its national position in 2021 and was planning an update, and encouraged other states to do the same . Italy argued that promoting transparency through national and regional positions “reduces uncertainty and the risk of miscalculation in interstate relations” and “establishes a global baseline for the application of international law in cyberspace” . It also greatly valued the Common African Position on the application of international law to ICTs . Italy proposed that DTG1 facilitate scenario-based discussions to help states understand the impact of threats on international law, while DTG2 could elaborate tailored capacity-building projects .
Portugal made a distinctive contribution by emphasising the centrality of freedom of expression to stability in cyberspace. Citing Article 19 of the Universal Declaration of Human Rights and Article 19 of the International Covenant on Civil and Political Rights, Portugal argued that states have a binding duty to protect freedom of digital expression across borders, including anonymous expression . While acknowledging that state action to combat disinformation based on artificial behaviour is justified, Portugal called for scenario-based discussions in the DTGs to give adequate attention to this duty .
Cameroon framed international law as “the indispensable framework of trust that enables us to harness its benefits” rather than a constraint on technological progress . It supported the progressive development and codification of international law for ICTs but cautioned that this must be conducted “with caution, objectivity, and legal rigor,” grounded in state practice and operational realities, and only where states through a consensus-based process conclude that existing law is insufficient . Cameroon closed with an African proverb – “the strength of a river comes from the meeting of its tributaries” – to underscore the importance of collective action .
#
Kiribati: The Most Impactful Individual Statement
Kiribati’s intervention was widely regarded as the most powerful and candid statement of the session. Aligning with the PIF and Australia’s cross-regional group, Kiribati began by explaining why the international law pillar matters most to states like itself: “Kiribati is a large ocean state of small highlands, a nation of 120,000 people spread across an ocean the size of a continent. We have no capacity to deter and no capacity to retaliate” . The delegation stated plainly: “When we ask ourselves what actually protects Kiribati, the honest answer is this. International law protects Kiribati… They are in truth the only defences we have” .
Kiribati then challenged a assumption in the forum’s discussions: “there is an assumption running quietly beneath our discussions of international law, that every state arrives here with a settled national position, drafted by its own international lawyers, refined across its own governments. For much of this membership, that assumption does not hold” . The delegation noted that its entire delegation comprised three people, covering the national cybersecurity mandate, incident response function, and legal and regulatory work, and that the officer who would draft Kiribati’s national position on international law was present in the room that week while also performing all other functions . This was described not as a complaint but as “the arithmetic of a small state, and the arithmetic behind a great many of the empty chairs in this discussion” .
Kiribati concluded that “legal capacity building is therefore not a footnote to this pillar. It is the condition of this pillar being real” . It reiterated its proposal for scenario-based exercises on international law within the DTGs, arguing that “working through realistic scenarios is how legal principle becomes operational understanding, and it is at the same time one of the most effective forms of legal capacity building available to states like ours” . On new legally binding obligations, Kiribati counselled patience, recalling that three years of negotiating the UN Convention Against Cybercrime in the HADOC committee had “consumed very nearly everything we had to give” and that “at the end of those three years, our network at home were not one day better defended” . The delegation concluded: “for the powerful international law is a constraint they accept; for the small it is the protection they depend on” .
#
Austria, Malawi, Singapore, Colombia, and the Republic of Korea
Austria aligned with the EU and Switzerland’s joint statement, reaffirming that international law as a whole, including IHL and IHRL, applies to state cyber activities . It emphasised that “affirming the applicability of IHL to cyber activities in connection with an armed conflict does not encourage or legitimize cyber warfare” but “aims to provide clarity and affirm the global consensus that armed conflicts are subject to rules and limitations, irrespective of the means of warfare being employed” . Austria called for scenario-based, practice-oriented discussions in the DTGs, preceded by expert panels, and focused on specific sub-areas one at a time . It also expressed frustration at the lack of consensus on stakeholder participation, emphasising that “the expertise provided by non-governmental stakeholders is crucial” to grounding decisions in a sound factual basis, and specifically referencing the joint multi-stakeholder statement submitted that week objecting to restrictions on stakeholder participation .
Malawi reaffirmed the UN Charter as its principal reference point, supporting the recognition that IHL applies where ICTs are used in situations of armed conflict . It argued that questions about legal gaps and new legally binding obligations “should be approached carefully, inclusively and on the basis of evidence,” asking first whether the challenge lies in the law itself or in the collective ability to understand and implement it . Malawi’s most striking formulation was its reframing of the central challenge: “The most significant gap before us today is not a gap on international law. It is the gap between legal consensus and practical implementation. Closing that gap would do more to strengthen international peace and security than debating obligations that many states are not yet equipped to operationalize” .
Singapore affirmed that fostering common understanding on the application of international law to ICTs “will contribute to greater peace, security and trust among states,” and saw considerable value in states issuing national or regional statements . It emphasised that capacity building in international law is “an essential part of fostering common understanding” and specifically noted that this is where the role and work of DTG2 becomes crucial, calling for continued efforts to ensure every state can participate on an equal footing .
Colombia aligned with Australia and Switzerland, proposing three areas where DTG1 could provide significant added value: deepening analysis of IHL application to cyber operations in armed conflict, including how customary international law has been consolidated in cyberspace; examining how IHL principles apply given the transformations introduced by digital technologies, including the use of digital platforms for the forced recruitment of children by armed groups; and studying malicious cyber actions by non-state actors operating from within a state’s territory . Colombia argued that developing a common understanding of the application of international law is “absolutely crucial for consolidating a safe, stable and predictable digital environment” .
The Republic of Korea published its national position on the application of international law to cyberspace in July 2025, contributing to the ongoing international discussion . It argued that “existing international law already provides a sufficient legal foundation for governing state conduct in cyberspace” and that efforts should focus on “clarifying and operationalizing existing international law while strengthening mechanisms for its effective implementation” rather than pursuing new legally binding instruments . It also emphasised that recognising IHL’s applicability “neither legitimizes nor encourages armed conflict” but “seeks to ensure that if an armed conflict occurs, the protections afforded under IHL continue to apply in order to reduce human suffering and protect civilians” [S193].
#
New Zealand, Israel, Estonia, and the United Kingdom
New Zealand aligned with the PIF and Australia’s cross-regional group, and invited states to keep three questions in mind: why are we discussing international law; what issues should we focus on; and who should be in the room . On the first question, New Zealand argued that the answer is not to create new legally binding obligations, “not until all states have the capacity to engage with the existing legal framework” . On the second, it called for the mechanism to enable sharing of practical experiences and best practices, identify capacity-building needs, and discuss areas where understandings remain less settled, noting that the threshold at which cyber operations become coercive under the rule of non-intervention is one such area . On the third, New Zealand maintained that meaningful participation by relevant stakeholders, including legal experts and government lawyers from all states, is essential, and that “lawyers should be in the room with policy colleagues when developing case studies and scenarios” .
Israel reiterated its longstanding position that existing international law applies to cyberspace and that there is no need for a new legally binding instrument . It made a methodological argument: the unique characteristics of the cyber domain – including data lacking physical manifestation, being highly dynamic, and relying on privately owned international infrastructure – require “meticulous evaluation rather than automatic transpositions” . Drawing an analogy to the development of maritime law, aviation law, and space law, Israel argued that “the cyber domain is similarly unique and we should learn from our predecessors by investing sufficient time to exploring the unique characteristics of the cyber domain before reaching premature conclusions” . It proposed that the DTGs play a role in identifying the unique factual characteristics of cyberspace most relevant to the interpretation and application of existing international law, with input from technical experts and academia .
Estonia aligned with the EU and affirmed that “previous UN processes have clearly confirmed that existing international law applies in cyberspace,” with the task now being to “strengthen its implementation, deepen common understanding, and promote transparency” . It strongly believed IHL should be among the topics addressed by the global mechanism, with discussions moving beyond questioning its applicability to focus on concrete legal questions already emerging in practice . Estonia noted that it had set out its first national position in 2019 and was currently in its third review process, encouraging other states to articulate, share, and regularly update their national views . It called for the mechanism to facilitate exchanges on how international law is applied in practice, including assessing the legality of contemplated cyber activities, responding to unlawful operations, and pursuing accountability for violations .
The United Kingdom welcomed the global mechanism as a forum for continued consideration of how international law applies in cyberspace, noting that “the breadth and depth of those exchanges and the extent of our agreement was not fully reflected in the final report of the OEWG, but we must not lose sight of them” . The UK affirmed that “all states have agreed by consensus that international law applies to state conduct in cyberspace” and that “cyberspace is not lawless,” calling for states to move beyond this basic premise and “grapple with the more challenging questions of how existing rules apply in cyberspace” . It encouraged states that had not yet done so to set out their positions publicly, and noted a practical handbook published by scholars from the University of Exeter in collaboration with Estonia, Japan, and the NATO Cooperative Cyber Defence Centre of Excellence – published in 2025 and placed on the Global Mechanism webpage earlier that week – as a useful resource . The UK also regretted that “stakeholders with genuine expertise including those from the University of Exeter were blocked from participating in this plenary session” .
#
Armenia, Mexico, and Cuba
Armenia reaffirmed that international law, including the UN Charter, is applicable in cyberspace and essential to maintaining international peace and security . It underscored the importance of promoting a shared understanding of the application of international law while recognising that capacity building is essential to enable all states to participate effectively . It emphasised that future work should build upon the agreed outcomes of the GGE and OEWG, ensuring continuity and avoiding duplication of efforts .
Mexico reaffirmed that international law, including the UN Charter, IHRL, and IHL, applies to the use of ICTs by states, and that “the applicability of IHL does not legitimise the militarisation of cyberspace nor that of armed conflict” but “imposes limits on the conduct of parties and protects civilian populations” . It appreciated the progress made in the publication of national positions, welcomed the UNIDIR compendium and the Common African Position, and invited more states and regions to publish their positions as a transparency and trust-building measure . Mexico supported deepening exchanges on how specific principles such as distinction, proportionality, precaution, due diligence, and state responsibility are to be applied .
Cuba’s intervention represented one of the most substantive challenges to the dominant consensus. Cuba affirmed that the use of ICTs must be compatible with the UN Charter and international law, particularly sovereignty, territorial integrity, and non-intervention . However, it argued that “automatic applicability of international law and international humanitarian law to cyberspace is not acceptable insofar as this supplies a step towards militarization of cyberspace,” warning that it could make a cyber attack equivalent to a military attack and legitimise the invocation of self-defence under Article 51 . Cuba also raised the structural problem of attribution in the absence of a multilateral mechanism to impartially determine the origin of cyber incidents, arguing that without such a mechanism “this can be easily manipulated today” . Cuba called for a legally binding instrument negotiated multilaterally under the UN framework, arguing that voluntary norms are insufficient and that “the idea that voluntary norms are sufficient would lead to an avoidance of international responsibility” [S198][S200].
#
Iran, the African Group, the Netherlands, Brazil, and Germany
The Islamic Republic of Iran recognised that the purposes and principles of the UN Charter and generally accepted principles of international law apply to the use of ICTs . However, it argued that “the unique characteristics of ICTs, including their cross-border nature, the anonymity of malicious activities, the complexity of attribution, and the increasing involvement of private sector actors create legal and practical challenges that require additional legal rules” . Iran pointed to the successful negotiation of the UN Convention Against Cybercrime as evidence that states have already recognised the need for new legally binding international rules, and argued that “the question of additional legally binding obligations cannot be deferred indefinitely” . It took note of the updated concept of the Russian Federation’s proposed Convention on International Information Security as a possible contribution to discussions [S199].
Nigeria, speaking on behalf of the African Group, reaffirmed that international law, including the UN Charter, applies to the use of ICTs and remains essential to maintaining international peace, security, and stability . It noted that African member states had advanced a common understanding through the adoption of the Common African Position on the Application of International Law to the Use of ICT in Cyberspace . The African Group encouraged the global mechanism to support capacity building for legal, diplomatic, and technical experts; facilitate exchanges of national and regional experiences; promote dialogue among legal, diplomatic, and technical communities; and strengthen cooperation with regional and sub-regional organisations .
The Netherlands aligned with the EU, Switzerland, and Australia’s groups, and called for the mechanism to build on the existing acquis, including the common understanding that international law applies to cyberspace in its entirety . It argued that rather than revisiting areas where consensus has already been reached, the mechanism should focus on “the practical application and the tools that international law provides us to deal with the real-world threats,” including malicious cyber activities targeting critical infrastructure, ransomware, and attacks on medical facilities and humanitarian organisations . It specifically highlighted yesterday’s side event on international law hosted by Egypt as an example of how discussions can benefit from legal experts and other relevant stakeholders, and echoed calls for capacity building to bridge the gap between technical, policy, and legal experts .
Brazil aligned with Switzerland’s group and reaffirmed that international law, including the UN Charter, IHRL, and IHL, is fully applicable to states’ use of ICTs . It noted that “among all the pillars of the mandate, international law is the one in which consensus reports least reflect the richness of our debates” , and welcomed the increasing number of national positions published, noting the importance of a broad and diverse range of state views for the development of customary international law . Brazil made a technically sophisticated point: “the mere fact that a certain state behavior or position has not been formally protested against cannot be interpreted as acquiescence” – a reference to the doctrine of opinio juris . On IHL, Brazil argued that it “applies to situations amounting to armed conflict independently of its classification as such by the parties” and that “the recognition that IHL applies to cyberspace does not in any way endorse its militarization or legitimize cyber warfare” . Brazil also acknowledged that as debates evolve, there may be a need to discuss specific legally binding obligations, seeing no contradiction between existing law and eventual lex specialis .
Germany aligned with the EU, Switzerland, and Australia’s groups, and noted that “we do not begin our discussion on this agenda point from scratch” as successive consensus reports have confirmed that international law applies to cyberspace . It agreed with Brazil that the final OEWG report “did not fully reflect the breadth and depth of those discussions, especially when it comes to international humanitarian law” . Germany highlighted three priorities: capacity building on international law, which it described as a priority for its own cyber capacity-building engagement; the important role of regional organisations such as the AU, OAS, and EU in fostering discussions; and the need for international law to be integrated holistically into the work of the DTGs .
#
Mauritius, Venezuela, Vanuatu, and China
Mauritius committed to promoting a common understanding of how international law applies in cyberspace, noting that it had undertaken the development of its national position – currently undergoing approval processes prior to publication – with the invaluable support of UNIDIR . It described the process of developing a national position as “not merely a legal drafting exercise” but “a valuable capacity building process that strengthens institutional knowledge promotes dialogue among legal, technical, diplomatic and policy communities” . Mauritius aligned with Italy, New Zealand, Germany, and others in affirming that capacity building is a key enabler for advancing discussions on international law in cyberspace, and called for tailored, demand-driven capacity-building initiatives to empower states to develop their own national positions and participate more effectively in international processes .
Venezuela questioned “the full and automatic applicability of international norms to the use of ICTs,” arguing that international law needs to be carefully adjusted and adapted to the specific characteristics of ICT technology . It called for the creation of a legally binding framework of comprehensive scope, which it believed was part of the mandate of the former OEWG, and reiterated the importance of preserving the principle of consensus in all decisions and activities of the global mechanism .
Vanuatu grounded its commitment to international law in demonstrated national action, referencing its role in bringing the question of states’ climate obligations to the International Court of Justice: “We bring the same conviction to this pillar. For states without armies of scale or arsenals of deterrence, the rule of law is not one security strategy among several. It is the security strategy” . Vanuatu reaffirmed that international law, with the UN Charter at its core, applies in full to state conduct in cyberspace, including IHL and IHRL . It described the OEWG’s final report as “the floor for the mechanism’s legal discussions, not their ceiling” , and called for structured time in the mechanism to work through how the law applies in concrete situations, “so that legal discussion becomes a shared capability, rather than a specialist preserve” .
China elaborated three points. First, it underscored the role of the UN Charter and its principles as the cornerstone of cyberspace governance, calling on all countries to “explicitly oppose the use of cyber means to carry out acts of aggression” and on major countries to “use cyber technologies during armed conflicts with caution” and to take the lead in observing international rules in cyberspace instead of engaging in exceptionalism or selective application . Second, it argued that “the application of IHL in cyberspace must be handled with greater prudence,” citing unresolved legal and technical difficulties and the involvement of large technology companies from certain countries in geopolitical conflicts, which it argued makes the distinction between civilians and combatants even harder . Third, China called for the development of a new international legal instrument, supporting Russia’s Convention on International Information Security as “a very good basis for discussion” .
#
France, Japan, Canada, Ireland, Turkey, and Ukraine
France aligned with the EU and reaffirmed commitment to international law and the UN Charter as “a cornerstone of the complex architecture that we’re building here to regulate relations between states” . It noted that “weakening the Charter threatens us all, as Russia is notably doing, waging a war of aggression against Ukraine with devastating effects, both in the kinetic and cyber domains” . France considered the debate on new binding standards to be “of secondary importance,” and expressed regret that “the most fervent defenders of a new treaty are precisely those who are today trampling existing international law underfoot” . It supported the statement by Switzerland on IHL and called for the forthcoming findings of the ICRC global initiative on IHL and ICTs to be taken into account in the mechanism’s work .
Japan affirmed the consensus that existing international law applies in cyberspace and called for “practical and concrete discussions on how existing international law applies with a focus on responding to specific incidents such as cyber attacks on critical infrastructure” . It specifically highlighted the application of the responsibility of states for internationally wrongful acts as a fruitful area for deeper discussion, and hoped that through expert briefings and interactive discussions in DTG1, member states’ awareness and understanding of the specific application of existing international law would be deepened .
Canada firmly committed to ensuring the global mechanism builds on the important acquis developed through previous GGEs and OEWGs, noting that “the challenge before us is therefore no longer whether international law applies in cyberspace” but how to deepen common understanding of its practical application . It recalled that at the March 2026 organisational meeting, the vast majority of member states had expressed willingness to engage constructively on this basis. Canada called for substantive discussions and implementation through integrated discussions on real-world cyber challenges, including ransomware attacks affecting hospitals and malicious cyber activities targeting critical infrastructure . It affirmed that capacity building should remain “a central and necessary element for the success of this pillar” and that “continued dialogue on international law is itself an important confidence-building measure” .
Ireland aligned with the EU and co-sponsored both the Switzerland and Australia cross-regional group statements . It called for international law, including IHL, to feature prominently in the substantive work of the DTGs, and welcomed the use of guiding questions, structured discussions, and scenario-based exercises . Ireland expressed particular support for Kiribati’s intervention on capacity building . It affirmed that “the application of international law in cyberspace, in particular the UN Charter, IHRL, IHL and the Law on State Responsibility is an objective legal fact” and “strongly disagrees with any suggestion that affirming the application of IHL to cyberspace encourages or legitimises the militarisation of cyberspace” . Ireland considered that “any cause for new legally binding rules would be premature” as “it is not evident at this stage that there are significant gaps in the law itself,” and called for outcomes to focus not just on identifying areas of consensus but also areas of convergence .
Turkey reaffirmed that existing international law applies to state conduct in the ICT environment, with the UN Charter as the cornerstone, and that its purposes and principles – including sovereignty, sovereign equality, non-intervention, the prohibition of the use of force, and the protection of public order – are equally relevant in the ICT context . It called for the application of international law to ICTs to be addressed “in a careful, inclusive, and consensus-oriented manner,” taking into account differences in national legal systems, levels of technological capacity, and security concerns .
Ukraine aligned with the EU and reaffirmed its “unwavering support for the cumulative framework developed within the United Nations, under which international law, in particular the Charter of the United Nations in its entirety, is applicable to the use of the ICTs by states” . It stated that it does not support efforts aimed at developing new legally binding or non-binding international rules governing state behaviour in cyberspace at this stage, arguing that “our collective priority should be to deepen the common understanding of how international law that exists, how it applies in practice and to strengthen its faithful implementation” . Ukraine specifically proposed in-depth discussions on protecting healthcare and energy infrastructure from cyberattacks, noting the cross-cutting relevance of these issues to international law, IHL, and the framework of responsible state behaviour . It also called for accountability for violations of international law committed through ICTs, including strengthening international cooperation on attribution and ensuring that violations do not become normalised, referencing “systematic malicious cyber activities conducted as part of the war of aggression waged against Ukraine by a certain P5 member state” .
#
Thailand, Albania, and the Russian Federation
Thailand reaffirmed its longstanding position that international law, in particular the UN Charter, applies to the use of ICTs, and noted the publication of its first-ever National Position on the Application of International Law in Cyberspace the previous year . It attached importance to fostering common understanding through regular sharing of national views and positions to reduce the risk of misunderstandings and escalation . Thailand also highlighted a workshop it had co-hosted with UNIDIR on the implementation of the UN norms of responsible state behaviour in Bangkok earlier that month, and noted that the current arrangement – with international law addressed within DTG1 alongside other topics – may not be the separate dedicated thematic group that Thailand and a number of other member states had proposed .
Albania aligned with the EU and reaffirmed that international law, including the UN Charter, IHRL, and IHL, fully applies to cyberspace . It reiterated that IHL applies to cyber operations in armed conflict and that this “neither encourages the militarisation of cyberspace nor legitimises cyber warfare” . Albania called for the global mechanism to provide an inclusive and action-oriented forum for advancing discussions, with the DTGs facilitating focused exchanges on concrete legal questions .
The Russian Federation’s intervention was notably assertive and diverged sharply from the dominant consensus. Russia highlighted the UN Convention Against Cybercrime, developed on its initiative and signed by 78 countries, as “indisputable evidence of the demand for global treaties to regulate the digital space, whose unique technical and legal characteristics do not allow automatic and full application of existing norms of international law” . It called for the development of similar international legal instruments for other aspects of international information security, and promoted its proposed Convention on International Information Security as a basis for discussion . Russia called on the Chair to organise relevant discussions, citing the mandatory nature of the mechanism’s mandate under UN General Assembly Resolutions 79-237 and 80-16 – emphasising that these resolutions are mandatory obligations – as its legal basis for demanding such discussions . On voluntary norms, Russia objected to what it characterised as a “checklist” approach to implementing norms, rejecting it as “inconsistent with the fundamental principles of the UN Charter,” and specifically demanded that any such checklist be expanded to include additional rules from UNGA Resolution 73-27, including the norm requiring the provision of evidence when attributing responsibility to states for carrying out cyber attacks . It concluded with the argument that “voluntary rules of responsible state behavior can be observed, but only obligations under international treaties can be implemented” [S190].
#
Indonesia, Ghana, the Philippines, and Botswana
Indonesia reaffirmed that international law, including the UN Charter, applies to cyberspace and that existing principles remain fully applicable to states’ conduct in the ICT environment . It underscored the need for the global mechanism to address attribution “in an objective, transparent and based on technical standards and methodologies” manner, emphasising that “attribution must never be used as political instruments” . Indonesia called for cooperative capacity building, including training on the application of international law in cyberspace, to ensure its application remains “fair, non-discriminatory, non-prescriptive, non-hierarchical, and respectful of differing legal traditions,” with exchanges on national positions, case studies, and legal methodologies conducted on that same basis .
Ghana aligned with the African Group and reaffirmed that international law, particularly the UN Charter, remains applicable and essential to maintaining international peace, security, and stability in the use of ICTs . It welcomed the establishment of a dedicated thematic working group on international law as an important platform for inclusive and constructive discussions, and reaffirmed the importance of Article 2(3) of the UN Charter on the peaceful settlement of disputes .
The Philippines reaffirmed the consensus that international law, in particular the UN Charter, applies to the use of ICTs by states, and called for discussions to prioritise practical exchanges on the implementation of international law at the national level, including sharing national legislation, policies, institutional arrangements, and operational experiences . As ASEAN Chair in 2026, the Philippines noted its efforts to advance regional implementation of the agreed framework through the ASEAN Cybersecurity Cooperation Strategy 2026-2030 .
Botswana aligned with the African Group and emphasised that capacity building is “indispensable” to ensuring all states can meaningfully interpret and apply international law to state practice . It highlighted the vital importance of the DTGs in bridging the gap between legal principles and technical realities, and commended UNIDIR, the African Union, and SADC for their capacity-building contributions . Botswana noted that it is in the process of refining its national position on international law and intends to publish it to contribute to the ongoing discussion .
#
Closing Arrangements and Afternoon Programme
The Chair closed the morning session by noting that four speakers remained on the list under the international law agenda item – Switzerland (in national capacity), the United States, Australia, and the International Committee of the Red Cross – and that these interventions would be heard in the afternoon following a dedicated stakeholder session scheduled for 3pm . After concluding the international law agenda item, the session would move to the next agenda item on developing and applying confidence-building measures .
#
Overall Assessment
The session revealed a high degree of consensus on the foundational proposition that international law, including the UN Charter in its entirety, applies to state conduct in cyberspace – a consensus affirmed by virtually every delegation, including those with significant reservations about the scope and manner of application [S184][S186][S187]. The central challenge identified by the vast majority of delegations is not whether international law applies but how to deepen practical, concrete, and inclusive understanding of how it applies, particularly through scenario-based discussions in the DTGs .
A large cross-regional majority firmly affirmed the applicability of IHL to cyber operations in armed conflict, consistently rebutting the argument that this encourages militarisation by inverting the logic: it is the absence of IHL, not its presence, that leaves civilians less protected . A minority of states – notably Cuba, Venezuela, and China – resisted automatic or full IHL applicability, raising concerns about militarisation and the unique characteristics of cyberspace .
The most significant structural divide concerned the need for new legally binding instruments. A large majority, including the EU, Switzerland’s group, Australia’s group, the Pacific Islands Forum, and many individual states, argued that existing international law is sufficient and that the priority should be deepening understanding and implementation . A smaller but vocal minority – Russia, China, Cuba, Iran, and Venezuela – argued that the unique characteristics of cyberspace necessitate new binding instruments and that voluntary norms are insufficient [S199].
Legal capacity building emerged as a near-universal priority, with Kiribati’s intervention transforming it from a procedural footnote into a fundamental question of whether the forum’s discussions are genuinely inclusive . Malawi’s reframing of the central gap – from a gap in the law to a gap between legal consensus and practical implementation – provided a sharp analytical lens that resonated across the session . The publication of national and regional positions was widely encouraged as a transparency and confidence-building measure, with over 100 states having now published such positions . Scenario-based discussions and exercises were endorsed across political groupings as the most effective modality for translating legal principles into operational understanding .
—
Chair Egriselda López
We’re about to begin. The fifth meeting of the substantive plenary session of the 2026 Global Mechanism on Development in the field of information and communication technologies in the context of international security and advancing responsible state behavior in the use of ICTs is called to order. I would like once again to thank all delegations for their very substantive contributions under the topic of voluntary norms. As you will recall, under this same agenda item, there was a request for a right of reply, and so I will give the floor to the delegation of Ukraine. Thank you.
—
Ukraine
Good morning, everyone. Madam Chair, I would like to take the floor for exercising the right of reply in relation to yesterday’s intervention by the representative of the Russian Federation. Madam Chair, distinguished delegates, yesterday and the day before, we had a profound discussion on the existing and potential threats, where many delegations expressed their concerns about the growing threat of disinformation and information manipulation. It is ironic that right after that, the Russian Federation intervenes with a speech that qualifies for an act of intentional disinformation and information manipulation. Let’s see why. Even the AI suggests that in the process of countering disinformation, every piece of information should be evaluated for excessive appeal to emotions, fact -checked, and, if inconsistent, reported and not disseminated. Russia’s yesterday’s intervention is a very important step in the development of the Russian Federation. The intervention was over -exaggeratedly emotional, with elaborated epithets and lack of factual reference, a clear sign of potential disinformation attempt. Now to the fact -checking. the international criminal court has issued a number of warrants of arrest for russian top officials inclusive of putin for the crime of aggression that’s the fact currently russia temporarily occupies under 20 percent of ukrainian territory that’s another fact that these territories are recognized by the international community as ukrainian is also the fact stated in numerous general assembly resolutions which i shall not list here for the sake of the precious time although ukraine temporarily cannot exercise the effective governance on the on these territories also the fact regretfully unlike the occupational administrations of the russian federation who act as they please on the temporarily occupied territories of ukraine thus maintaining the permissive environment for the criminal cyber ecosystems to flourish. Yet another fact. These facts are well known, but were not mentioned in Russia’s intervention of yesterday, which is another clear sign of a disinformation and information manipulation attempt. Distinguished delegates, it looks like we have just had a quick situational tabletop exercise on a practical case of a disinformation attempt happening right here in this room. We looked into it together, and now we all know how it works. Madam Chair, I would like to report the case of attempted disinformation, namely Russia’s intervention of yesterday, so it will not be disseminated. Hashtag stop fake. Thank you.
—
Chair Egriselda López
Thank you. We will now move to the next item. We will now move on to the next item. item which is the continued study of the applicability of international law in the use of ICTs including consideration of whether any gaps exist and possible future elaboration of additional legally binding obligations if appropriate. As I mentioned we don’t have a predetermined time limit for interventions but it would be greatly appreciated if you would consider delivering an abridged version of your statement and sending the full version to eStatements and to the chairs team so that we can hear from all delegations. Also for your reference a timer will be displayed on the screen. I will now invite delegations to indicate their interest in taking the floor under this agenda item. as we did for the other agenda items I would be grateful if you could indicate your desire to speak now so that we can see who wishes to take the floor on behalf of their national delegation and if we could ask those wishing to take the floor on behalf of a group if they could approach the secretariat so that we can give them priority I would now give the floor to Switzerland who will be speaking on behalf of a group of states.
—
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, Sweden
Thank you Madam Chair I have the honor to deliver this statement on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, Sweden, and my own delegation. Our states, spanning all regional groups represented in this room, share a common conviction. Clarifying the concrete application of international law to conduct in cyberspace will be central to the work of this global mechanism. We must continue building on the common understandings established by previous GGEs and the OEWGs. There are key builds in the consensus reports of the GGEs of 2010, 2013, 2015, and 2021, and the final reports of the 2019 to 2021 and the 2021 to 2025 OEWGs is clear. International law applies to the use of ICTs. The task before us is to deepen our common understanding of how exactly it applies. Rich and substantive discussions on the application of international law, including IHL, took place in the GGEs, OEWG, and other forum. These discussions were facilitated by numerous capacity -building initiatives that enabled a growing number of states to contribute. Further, numerous regional and national positions on international law, including IHL, were published in the course of the OEWG. Yet, the final report of the OEWG did not complete. What does not fully reflect all of these, especially regrettable, is that the final report did not retain explicit language on IHL, which should now be a priority for the mechanism. Two working papers submitted by the OEWG in July 2025 provide a solid basis for the work ahead. The cross -regional working paper on the application of international law in the use of ICTs identified areas of emerging convergence on state responsibility, human rights obligations, peaceful settlement of disputes, and the application of IHL in armed conflict. The cross -regional working paper on the application of international humanitarian law to ICT operations elaborated the specific rules and principles of IHL applicable to cyber operations and identified measures to ensure respect for IHL. Important work has also taken place outside the OEWG, reflecting the importance attached to the application of IHL in cyberspace by a great majority of states. The resolution adopted at the 34th International Conference of the Red Cross and Red Crescent in 2024 and the ICT work stream under the Global Initiative to Galvanize Political Commitment to International Humanitarian Law are prominent examples. These complementary processes reinforce our understandings and can provide an invaluable basis for the work of this mechanism. We wish to be clear on one point. Applying IHL does not increase the risk of armed conflict in cyberspace. Failing to apply it leaves that risk unaddressed and civilians and other protected persons and objects less protected. Building on this bedrock, we are committed to advancing focused discussions on international law, including IHL. Indeed, important questions on the concrete. The IHL and the IHL -application remain open and need to be discussed. We therefore propose addressing, among others, the following five areas of international law in a structured and inclusive manner by the mechanism. First, sovereignty and the prohibition of intervention. Second, state responsibility and due diligence. Third, the prohibition of the use of force and the right of self -defense recognized under Article 51 of the UN Charter. Fourth, IHL as it applies to cyber operations in situations of armed conflict, including the principles of distinction, proportionality, precaution, necessity, and humanity, as well as the protection of protected persons and objects. And fifth, sovereignty. Fourth, the application of international human rights law to state conduct in cyberspace, including privacy, freedom of expression, non -discrimination, and the freedom of association. Madam Chair, we welcome the integrated, policy -oriented and cross -cutting nature of DTG1, which draws on the five pillars of the framework, including international law. This approach offers a valuable opportunity to examine specific challenges in ICT security. We encourage the co -facilitators of DTG1 to ensure that international law, including IHL, features prominently in the substantive work of DTG1. This mechanism was created to continue and deepen the work of its predecessors. Continuity on international law, including IHL, is not optional, and we stand ready to support you in your endeavors to do so. For that purpose, we encourage you, Madam Chair, in coordination with the co -facilitators of DTG1, to initiate dedicated discussions on… on the application of the aforementioned rules of international law in real -world scenarios, including the protection of critical infrastructure, such as hospitals, water systems, and energy networks from malicious ICT operations, both in times of peace and in armed conflict. I thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Tonga speaking on behalf of the Pacific Islands Forum.
—
Tonga on behalf of the Pacific Islands Forum
Thank you, Chair. I have the honor to deliver this statement on behalf of the members of the Pacific Islands Forum with a presence of the United Nations, namely Australia, the Cook Islands, Fiji, Kiribati, the Federated States of Micronesia, the Republic of the Marshall Islands, Nauru, New Zealand, Palau, Papua New Guinea, Samoa, Solomon Islands, Tuvalu, Vanuatu, and my own country, Tonga. Chair, on international law, The Pacific Islands Forum continues to support a principled approach grounded in the Charter of the United Nations and other relevant obligations under international law. We reaffirm that international law applies to state conduct in cyberspace. We also reaffirm the applicability of international humanitarian law to cyber activities in situations of armed conflict and the importance of protecting human rights which apply online as they do offline. The global mechanism should build on the progress made in the OEWG and reflect the depth of legal discussions that have already taken place. It should acknowledge the areas where there is a broad convergence while also providing space for states to continue building common understandings on how international law works. International law applies. For the Pacific, further discussion of state responsibility and the peaceful settlement of disputes remains important to our understanding of responsible state behavior in cyberspace and to preventing escalation. At the same time, legal discussions must be accessible to all states. Many countries require support to build the legal capacity needed to engage meaningfully in these conversations, including support for officials who are not specialist international lawyers. Legal capacity building should therefore be a practical and cross -cutting priority of the global mechanism. Scenario -based training. Regional workshops, peer exchanges, and accessible expert briefings can help states develop national views and participate on a more equal footing. The Pacific also continues to caution against moving too quickly towards discussions of additional legally binding obligations before states have had the capacity and opportunity to engage with how existing international law applies. Before we can have a meaningful discussion on whether there are gaps, we need the legal capacity to understand and apply the existing framework. In this regard, the DTGs can contribute by creating a less formal and more practical environment for legal dialogue among states and supporting broader capacity -building efforts. Exchanges among states on experiences, challenges, gaps, and capacity needs regarding the implementation of existing legal obligations in cyberspace, supported by appropriate expert guidance, and the implementation of the DTGs, would be valuable, particularly when they help translate legal principles into realistic scenarios and practical policy choices for states. Thank you, Chair.
—
Chair Egriselda López
Thank you very much. I now give the floor to the European Union to be followed by Australia, South Africa, Uruguay, Costa Rica, and Italy, and then Portugal and Cameroon.
—
European Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San Marino
Chair, colleagues, I have the honor to speak on behalf of the EU and its member states. The candidate countries North Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area, as well as San Marino, align themselves with this statement. As outlined also during our statement on threats, malicious behavior in cyberspace from both state and non -state actors is increasing in scale, severity, sophistication, and impact. The increasing number of cyber threats poses a major challenge to the functioning of our societies, our economies, and our way of life. Cyber threat actors target our curricular infrastructure and attempt to hamper the efforts of states to fully grasp the economic and social benefits of digitalization. With cyber tools also increasingly playing a central role in conflicts, respect for and adherence to the UN framework of responsible state behavior in cyberspace is essential to maintaining international security and stability. The EU and its member states reaffirm their full commitment to the application of international law, in particular the UN Charter, international human rights law, international humanitarian law, and the law on state responsibility in cyberspace. We underscore that respect for international law should be at the core of the efforts of the international community. And to this end, we should continue to work, including in the DTGs, to further enhance our common understanding on how international law applies and build also global capacities to this end. A better global common understanding of how international law applies to cyberspace is necessary to contribute to global cyber resilience and further transparency, transparency, predictability, and accountability for states’ conduct in cyberspace. Thank you. In that vein, the EU and its member states continue to support third countries through training and capacity building on the implementation of the UN framework, including on how to develop a national position on the application of international law in cyberspace. And we acknowledge that an increasing number of states have already developed and put forward their national and regional positions on this issue. To support finding further common understanding, we have in 2024 ourselves presented our common understanding on a non -exhausted set of legal elements on the application of international law. And in conjunction with our declaration, as well as the African Union’s common position, over 100 states have now either individually or collectively published their positions on international law, which is a real achievement. This increasing understanding shows that international law is fit for purpose in this digital age, and that the application of international law is a real achievement. The application of and compliance with fundamental principles of international law and rules of international law to cyberspace, such as state sovereignty, the principle of non -intervention, the prohibition of the threat or use of force, due diligence, as well as international human rights law and international humanitarian law, are essential to ensure security and stability. Areas to be also further discussed, as just outlined in the statement by Switzerland on behalf of a large cross -regional group of states. We also underscore that recognizing the application of international humanitarian law in cyberspace does not lead to nor encourage the militarization of cyberspace, nor does it legitimize cyber warfare. Actually, to the contrary. The EU and its member states will continue to further develop, extend, update, and share our understanding on the application of international law at national, regional, and international level, and we encourage all EU and member states to do the same. The Open Ended Working Group confirmed this common understanding even through the result of hard work of cross -regional groups and a reference to the resolution of the International Conference of the Red Cross and Red Crescent were not included in the final Open Ended Working Group report. And we note that further efforts of the global mechanism should build on previous discussions and achievements and include them in their results. States have recognized that the application of the law of state responsibility, international human rights law, and in situations of armed conflict, international humanitarian law. And we see the global mechanism and its DTGs as a new opportunity to reflect and articulate clearly the progress made and continue to make progress on our common understanding, particularly by reflecting on its practical application in real world scenarios. We also welcome the continued… We also welcome the continued efforts by the cross -regional groups on this issue and look forward to incorporating this work in our discussions under the global mechanism, including in the dedicated thematic groups. Thank you very much.
—
Australia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and Vietnam
Thank you very much. Thailand, Uruguay, Vanuatu and Vietnam. International law is a key pillar of the framework for responsible state behaviour. All states have reaffirmed that international law is applicable and essential to maintaining peace and stability and promoting an open, secure, stable, accessible and peaceful ICT environment. In their use of ICTs, states have reaffirmed the application of the principles of state sovereignty, sovereign equality and the international norms and principles that flow from sovereignty. non -intervention in the internal affairs of another state the prohibition on the use of force and the peaceful settlement of disputes. States have had increasingly rich discussions over time and reached more common understandings on how international law applies in the use of ICTs including in the GGEs and OEWGs that preceded this forum as well as the 34th International Conference of the Red Cross and Red Crescent and the ICT work stream of the Global Initiative to Galvanise Political Commitment to IHL. States from all regions have engaged in discussions, drafted working papers, delivered statements and published national positions that have helped reinforce capacity, build confidence and deepen our common understandings on how international law applies in the use of ICTs. These outcomes demonstrate the value of regular, continuing discussions on these topics and offer ground for carving out additional areas of emerging convergence. This permanent global mechanism represents a valuable opportunity to build on these strong foundations and continue these critical discussions in a structured and inclusive setting It is important that this includes detailed and substantive discussions among states on the application of international law to the use of ICTs by states in an integrated, policy -oriented and cross -cutting manner in the first dedicated thematic group Consideration should also be given to how capacity -building efforts including those advanced through the second dedicated thematic group can better enable states to meaningfully participate in these conversations develop their own national positions and enhance the implementation of international law The cross -regional group on behalf of which I speak today comprising states of various sizes from all regions calls in particular for this mechanism to draw on work such as the cross -regional working paper on the application of international law in the use of ICTs and the working paper on the application of international humanitarian law to ICT operations that were produced in the context of the OEWG 2021 -2025. The first of these working papers, produced by many members of this group, reflected emerging common understandings on the application of international law to cyber activities in a few areas, including in relation to state responsibility, human rights obligations and the application of IHL to states’ use of ICTs in the context of armed conflict, which were reached through rich and substantive dialogue between states throughout the OEWG. We consider this global mechanism must further these discussions on the application of international law in the use of ICTs and that emerging common understandings reached during these discussions must be reflected in the reporting of this mechanism. We express our shared conviction that the substantive work of states on international law from preceding fora remain valuable and highly relevant. reaching more common understandings on how international law applies to states use of icts is critical to maintaining peace and stability including by increasing the predictability of state behavior lowering the risk of miscalculation and clarifying the consequences of unlawful state behavior it is crucial that we build upon upon the sound foundation laid by the OEWG, including the papers and statements of this group and of others, to realise this vision and the mechanism’s full potential. Thank you.
—
Chair Egriselda López
thank you very much I now give the floor to the delegation of South Africa who will be followed by Uruguay
—
South Africa
Thank You chairperson the dedicated thematic groups provide us with an opportunity to reflect further on how international law applies to cyber space the previous open -ended working group on security of and in the use of information and communications technologies benefited from states sharing their national views on how international law applies in cyberspace While regional papers provide valuable references, they are non -exhaustive. The lived experience and practice of member states in the context of applying international law to cyberspace is also a practical resource. We could also broaden our understanding by allowing for presentations by legal experts, including those in civil society and academia. Member states have agreed, for example, that international law, in particular the Charter of the United Nations in its entirety, is applicable and essential to maintaining peace, security, stability, and promoting an open, secure, accessible, and peaceful ICT environment. Chairperson, with regards to breaches of sovereignty, South Africa understands that a cyber operation is deemed internationally, an internationally wrongful act, when it is attributable to a state under international law. and involves a breach of an international obligation of the state. States should not knowingly allow their territory to be used for intentionally wrongful acts, internationally wrongful acts using ICTs. It follows that if a state is notified of harmful activity emanating from its territory, it must take reasonable steps to address such activity. Chairperson, the implementation of the UN Charter includes reference in Article 1 to international human rights law. One of the stated purposes of the UN stated in its Charter is to encourage respect for human rights and for fundamental freedoms for all, without distinction as to race, gender, language or religion. There is no doubt that… …women and vulnerable groups… such as the disabled and the LGBTQI plus community are particularly affected by breaches of ICT security as well as online misinformation and disinformation campaigns led by state and non -state actors. Member states disagree on how the applicability of international law should be treated over the longer term. The global mechanism should therefore engage in a good faith discussion in the DTGs on how the applicability of international law including international humanitarian law could be strengthened. These discussions held informally with experts from civil society and academia in DTG 1 could identify the capacity building needs of member states which could be addressed in the discussions of DTG 2. The GM is an action -oriented mechanism and we should use it to build consensus in areas where this is possible. Chairperson. South Africa’s national position on how international law applies to cyberspace. is still developing as we consider the fast -paced developments of malicious actors using new and emerging technologies to spread divisive information that is contrary to the UN Charter itself. Our collective gaps as an international community should first be ventilated by member states in the context of the global mechanism and then we we could chart a way forward if needed. I thank you.
—
Chair Egriselda López
Muchísimas gracias. Thank you very much. I now give the floor to Uruguay, who will be followed by Costa Rica and then Italy.
—
Uruguay
Thank you very much, Madam Chair. As this is the first time that I’m taking the floor, I’d like to begin by congratulating you on your stewardship of this process and I’d like to express our appreciation for your dedication and also for the tireless work of your team. You can count on us to work constructively. Uruguay reaffirms that international law is the foundation for preserving international peace security and stability, including in the use of ICTs. We value the significant progress made in the OEWG and the GGE and also in other relevant processes. These have made it possible to deepen our common understandings on the application of international law to the use of ICTs and has helped to strengthen trust between states. In this context, we especially recognize the confidence and contributions of the inter -regional group on international law, especially as regards the application of international human rights law. international humanitarian law and the international responsibility of states. The new permanent global mechanism represents an opportunity to continue with this progress and to consolidate an inclusive forum where we can further develop common understandings, strengthen state capacities and take stock of advancements reflected in the periodic reports. Deepening consensus on the application of international law in the use of ICTs will help to strengthen the predictability of state behavior, to reduce the risk of miscalculations and promote cyberspace that is open, stable, secure, peaceful and accessible to all. I thank you.
—
Costa Rica Delegate
Madam Chair, Costa Rica is grateful for this opportunity to speak on this pillar relating to the application of international law to the use of ICTs, which is used by states. One of the major contributions of the previous working groups is the recognition that cyberspace is not a legal vacuum. International law, including the Charter of the United Nations, applies fully to the use of ICTs by states. This encompasses, as appropriate, the principle of sovereign equality, the peaceful settlement of disputes, the prohibition of the threat or use of force, non -intervention, due diligence, the law of international responsibility, international humanitarian law, and international human rights law. In this regard, allow us to share with you three reflections. First, Costa Rica believes that the added value of this global mechanism lies in moving beyond a general affirmation of applicability towards a more concrete, technical, and inclusive understanding as to how these legal concepts apply to specific situations. This includes operations involving the use of proxies. Digital coercion, attribution, response measures, and operations below the threshold of the use of force. Under this framework, sovereignty and non -intervention continue to be central principles. Certain cyber operations can be legally significant when they cause physical damage, loss of functionality or interference with inherently governmental functions. Likewise, coercive operations targeting electoral processes, essential services, public administration or sovereign decisions may raise questions or issues under the principle of non -intervention depending on the circumstances of each case. Finally, Costa Rica also believes it is essential that we address the issue of attribution with rigour and prudence. Although rules of attribution in international law are not new, the digital environment presents unique technical and evidentiary challenges. Therefore, we should promote good practices, voluntary transparency, capacity building and confidence building measures that help to distinguish between technical, political and legal attribution. Madam Chair, legal clarity strengthens trust and protects civilian populations. Costa Rica hopes that this mechanism will foster common understandings without weakening existing norms and reaffirm the fact that security in cyberspace must always advance in accordance with international law, the Charter of the United Nations, human rights and international humanitarian law. I thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Italy.
—
Italy
Good morning, Madam Chair. Thank you for giving me the floor. Italy fully aligns itself with the statement delivered by the European Union and wishes to add a few considerations from its national perspective, also including some contributions of the four stakeholders objected by the Russian Federation. We emphasize the importance of deepening our collective understanding of how international law applies to cyberspace. As noted by you and other delegations before me, international law is fully applicable and relevant in the digital age. International law includes the UN Charter and the UN Charter of the United Nations. the law of state responsibility, international human rights law, and international humanitarian law. Italy publicly shared its national position on this matter in 2021, and we encourage other states to continue to do the same. This year, we are also planning an update of our national position paper, and we look forward to the outcomes of this global mechanism as valuable inputs to our work. Promoting transparency by publishing national and regional positions is in the collective interest, as it reduces uncertainty and the risk of miscalculation in interstate relations. Furthermore, it establishes a global baseline for the application of international law in cyberspace. The EU common understanding of the application of international law to cyberspace demonstrates that it is possible to agree on principles such as state sovereignty, the principle of non -intervention, the prohibition on the use of force, and compliance. This is in accordance with international humanitarian law, international human rights law, and state responsibility law. In this regard, we also greatly value the common African position on the application of international law to ICTs and would welcome the recognition of the importance of regional perspectives by this global mechanism. Italy would also like to stress the importance of supporting capacity -building efforts, including with the aim of ensuring that all states are able to participate on an equal footing on the development of common understandings of how international law applies in the use of ICTs. With this regard, we particularly appreciate the precious work done by organizations like UNIDIR. Based on the UAWG recommendations, it is now important to continue discussions at the global mechanism on how international law applies in the use of ICTs. Such discussions would greatly benefit from briefings of experts, for instance from the International Commission on International Law, the International Law Commission, and academia. That is why we believe that DTG1 can play a significant role in helping all of us understand the impact of certain threats and situations on international law, particularly thanks to scenario -based discussions and similar activities. DTG2, then, could elaborate tailored projects to assist countries in building capacities in the field of international law. Italy stands ready to contribute to these collective
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Portugal. They will be followed by Cameroon, Kiribati and Austria.
—
Portugal
Madam Chair, Portugal aligns with you and the Switzerland’s statements, but would like to emphasize once more the centrality to stability in cyberspace of the binding duty to protect the right to freedom of expression. It is worth remembering in this regard that Article 19 of the European Convention on the Rights of the Persons with Disabilities, which is the right to freedom of expression, is not the right to freedom of expression. The Constitution of the Universal Declaration asserts the fundamental right to hold opinions without interference from any authority and to seek, receive and impart information and ideas through any media, regardless of frontiers. And that Article 19 of the UN International Covenant on Civil and Political Rights asserts that this personal right shall include freedom to seek, receive and impart information and ideas of all kinds, regardless of frontiers, either orally, in writing or in print, in the form of art or through any other media of choice. Of course, the international right to freedom of expression across borders has been at times violated by states that sponsor campaigns of online disinformation with the aim of discrediting the institutions of countries whose freedoms they fear. Those online campaigns are a dangerous hybrid threat to national security. And therefore, the role of the state in combating them based on the identification of artificial behavior is justified. However, when we reaffirm the applicability of international law in cyberspace, we also mean the binding state duty to protect freedom of digital expression of their citizens across borders, including anonymous expression. State responsibility, sovereignty, peaceful settlement of disputes, non -intervention, and the right of self -defense are, of course, pillars of international peace and security, also in cyberspace. But states, according to precedent and jurisprudence, must also uphold and protect the freedom of expression across borders of their citizens, including anonymous expression, because that is part of their binding obligations under international law. therefore in our view scenario based discussions by the two cross -cutting dedicated thematic groups of the global mechanism namely on how binding state obligations apply to particular situations in cyberspace should give adequate attention to the duty to protect freedom of expression including anonymous expression and regardless of borders. Thank you Madam Chairman
—
Chair Egriselda López
Thank you very much I now give the floor to the delegation Cameroun Madam
—
Cameroon
President Madam Chair The history of international law is one of a constant search for balance between the enduring principles that underpin the international legal order and the need to accompany the profound transformations of international society and in every period of major change law has been called upon not only to regulate new realities but also to preserve the of the fundamental values that make peaceful coexistence among nations possible. Cyberspace is today one of such major transformations. It has become an essential space for cooperation, innovation, economic development, and social progress. However, it has also become a domain in which complex challenges to international peace and security, the stability of states, and trust among nations are manifested. And in light of this reality, our collective responsibility is to ensure that the digital revolution remains a force -serving humanity, rather than an additional source of instability. And that is why international law must remain our common reference point, not as a constraint opposed to technological progress, but as the indispensable framework of trust that enables us to harness its benefits -prevented risks, Madam Chair, for Cameroon International Law. is a basis for peaceful coexistence and a way to resolve differences. It remains a normative reference and remains an indispensable foundation of peaceful coexistence. Thank you very much. Thank you. We have always supported the progressive development and codification of international law, including the ICT, because we think that it helps improve legal certainty and the implementation of relevant obligations. However, this reflection must be conducted with caution, objectivity, and legal rigor. It cannot proceed from the assumption that the existing international legal framework is insufficient, nor presume that there are normative gaps that exist. Rather, it should be based on a mythological analysis grounded in state practices, applicable principles of international law, and operational realities associated with digital technologies. In this regard, we remain open to continuing discussions. Thank you. consensus -based process. States conclude that certain situations are not sufficiently covered by existing law. They may then consider, where appropriate, the development of new legally binding obligations. Such development should aim to strengthen the existing international legal order and ensure universal application of law rather than selective application of rules. This also depends on the capacity of states to implement them effectively. And in this regard, capacity building, technical assistance, the sharing of best practices, knowledge and expertise, as well as strengthened and inclusive international cooperation remain indispensable to enable all states, particularly developing countries, to participate fully and effectively in international cyberspace governance in a digital environment where vulnerabilities of state and we are all interdependent. work not just an expression of international community, but an expression of joint will. Madam Chair, allow me to conclude by recalling an African proverb which says that the strength of a river comes from the meeting of its tributaries. And this recalls a fundamental reality that a state alone cannot meet the complex challenges on their own. I thank you.
—
Chair Egriselda López
Thank you. I now give the floor to the delegation of Kiribati to be followed by Austria.
—
Kiribati
Madam Chair, Kiribati aligns itself with the statement delivered by the Kingdom of Tonga on behalf of the Pacific Island Forum members and with the cross -regional statements on the application of international law delivered by Australia. We speak now in our national capacity. Madam Chair, let me begin with the reason this pillar matters most to all states like mine. Kiribati is a large ocean state of small highlands, a nation of 120 ,000 people spread across an ocean the size of a continent. We have no harmony to speak of. We have no capacity to deter and no capacity to retaliate. If a state chose to act against us in cyberspace tomorrow, we could not answer it, and we could not prevent it. When we ask ourselves what actually protects Kiribati, the honest answer is this. International law protects Kiribati. Sovereign equality, the prohibition of fear threat and use of force, non -intervention, the peace settlement of this field. These are not matters of legal theory. They are our defenses. They are in truth the only defenses we have. So when this mechanism affirms that international law, including the Charter of the United Nations in its entirety, applies to state conduct in cyberspace, Kiribati does not hear a technical proposition. We hear our security being spoken aloud. In the previous open -ended working group, Kiribati joined a cross -regional group of states from the Pacific, Asia, Europe, and Latin America in presenting convergence language on international law. Those understandings must be carried forward and reflected in this mechanism’s reporting. Madam Chair, permit me now to be candid about something rarely said. Plainly in this room, there is an assumption running quietly beneath our discussions of international law, that every state arrives here with a settled national position. drafted by its own international lawyers, refined across its own governments. For much of this membership, that assumption does not hold. And so a discussion that is being woven in principle becomes, in practice, a conversation among those who already have the capacity to hold it. Kiribati’s delegation to this session is three people. Between us, we hold our national cybersecurity mandate, our incident response function, and our legal and regulatory work. The officer who would draft Kiribati’s national position on international law is in this room this week, and is also the officer who must do everything else. That is not a complaint. It is the arithmetic of a small state, and it is the arithmetic, and the arithmetic behind a great many of the empty chairs in this discussion. Legal capacity building is therefore not a footnote to this pillar. It is the condition of this pillar being real. Kiribati reiterates the proposal we co -sponsored in this OEWG, that scenario -based exercises on international law be taken up within the dedicated thematic groups. Working through realistic scenarios is how legal principle becomes operational understanding, and it is at the same time one of the most effective forms of legal capacity building available to states like ours. That is what turns a legal debate into a legal conversation that includes us and allows every state to participate not as an observer but as a contributor. This is also why Kiribati councils are pertinent. We have patience about new legally binding obligations. Our position is not opposition. It is sequenced, and it comes from recent experience. Kiribati sat through three years in the HADOC committee, negotiating the United Nations Convention Against Cybercrime. For the largest delegations, that was a demanding process. For a delegation the size of ours, it consumed very nearly everything we had to give. And Madam Chair, at the end of those three years, our network at home were not one day better defended. I say not that as a criticism of that convention, but as a plain statement of what such an undertaking costs a state like mine. Before we can say responsibly whether there are gaps in existing law, we must first be equipped to understand and apply the law we already have. We would rather build that capacity first, and then speak with the voice of the people, a voice that is genuinely our own. Madam Chair, in closing for the powerful international law is a constraint they accept for the small it is the protection they depend on in this room Kiribati’s vote counts the same as any other that equality is not a courtesy extended to us it is a legal principle and it is the most valuable thing we possess international law protects the small Kiribati will continue to work with all all partners, to ensure it protects them in cyberspace, too. I thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much for that Kiribati I now give the floor to the delegation of Austria
—
Austria
Madam Chair Austria fully aligns itself with the statement delivered by the EU and the joint statement delivered by Switzerland and would like to make some additional remarks in its national capacity As this is the first time our delegation is taking the floor, we would like to take this opportunity to congratulate you on your election. We trust in your continued excellent stewardship of this global mechanism. Let me start by recalling the open -ended working group’s conclusion that international law as a whole, including the UN Charter, applies to state cyber activities, and by reaffirming Austria’s firm view that there can be no doubt that such a finding encompasses international human rights law and international humanitarian law. While the global mechanism is new, the issues on its agenda are not being discussed in the UN framework for the first time. It is thus important to build on the achievements of the last decade. This includes, in particular, the most recent open -ended working group on security of and in the use of information and communications technologies, which concluded its mandate. This is the first time that the UN Charter has been held in a state -of -the -art way. This is the first time that the UN Charter has been held in a state -of -the -art way. This is the first time that the UN Charter has been held in a state -of -the -art way. This is the first time that the UN Charter has been held in a state -of -the -art way. We believe that this OEWG has achieved great progress, particularly on international humanitarian law. Affirming the applicability of IHL to cyber activities in connection with an armed conflict does not encourage or legitimize cyber warfare. It aims to provide clarity and affirm the global consensus that armed conflicts are subject to rules and limitations, irrespective of the means of warfare being employed. The existing legal framework must form the basis for any and all cyber activities conducted by both states and non -state actors. Non -legally binding norms can be a helpful tool to implement these legal obligations and to support the development of a common international standard for best practices. In this respect, we wish to highlight the initial overview of the EU’s efforts to implement the norms of responsible state behavior, which the EU and its member states presented ahead of time. The EU has also presented its own policy and recommendations for the implementation of the new rules of cyber warfare. The EU has also presented its own policy and recommendations for the implementation of the new rules of cyber warfare. The EU has also presented its own policy and recommendations for the implementation of the new rules of cyber warfare. The EU has also presented its own policy and recommendations for the implementation of the new rules of cyber warfare. The EU has also presented its own policy and recommendations for the implementation of the new rules of cyber warfare. to the work of the DTGs, Austria considers further, more detailed discussions on how existing international law applies to cyber activities as a priority. We firmly believe that discussions on international law should be scenario -based and practice -oriented. With regard to the working methods of the DTGs, we should look to best practices from other bodies which are dealing with similarly complex technical issues. For example, interstate discussions could be preceded by expert panels that would also provide delegations with sufficient time to ask questions and engage in a meaningful exchange with the experts. The meetings of the DTGs should be focused on specific sub-areas, one at a time, to allow for in-depth discussions. Madam Chair, allow me to also briefly react to the discussion on stakeholder participation and express my delegation’s frustration with the lack of consensus in that regard. We share the concerns raised by the multi-stakeholder community in this week’s joint multi-stakeholder statement on the objections to the participation of stakeholders. I want to emphasize that it always will be states making the decisions in this forum, but for these decisions to be effective, they must be grounded in a sound and comprehensive factual basis. The expertise provided by non-governmental stakeholders is crucial to that. In the spirit of the UN80 process, we cannot afford for this new global mechanism to become a forum that is not a forum that is not a forum that is not a forum. It is out of touch with reality. my delegation remains committed to this issue and thanks you again for the opportunity to share our views on these important matters. Thank you
—
Chair Egriselda López
Thank you. I now give the floor to Malawi, who will be followed by Singapore.
—
Malawi
Madam Chair, Excellencies, Distinguished Delegates, international law remains a cornerstone of the cumulative and evolving framework for responsible state behavior in cyberspace. Successive consensus reports of the United Nations GGEs and the OEWG have affirmed that international law, and in particular the Charter of the United Nations, applies to the use of ICTs by states. This shared understanding provides the foundation upon which we should continue to build. Just like the Pacific Islands Forum and Kiribati, my delegation believes the Charter remains our principal point of reference. Specifically, its principles of sovereign equality of states under Article 2, Paragraph 1, the peaceful settlement of disputes under Articles 2, Paragraph 3 and 33. the prohibition of the threat or use of force against the territorial integrity or political independence of any state under Article 2, Paragraph 4 and the obligation to cooperate in maintaining international peace and security are no less relevant in cyberspace than the physical world. The Republic of Malawi is in support of statements shared by the European Union, Italy and Switzerland on behalf of a group of member states recognizing that where ICTs are used in situations of armed conflict international humanitarian law applies. Respect for the principles of humanity, distinction, proportionality, necessity and precaution remains essential to protecting civilians and civilian infrastructure. Equally, the principles of sovereignty, jurisdiction and state responsibility continue to guide responsible state conduct in cyberspace. Jurisdiction enables states to investigate and prosecute cybercrime while respecting the sovereign rights of other states Likewise, while technical analysis may identify the source of malicious ICT activity attribution to a state remains a legal determination that must be based on international law and credible evidence Responsible attribution is therefore essential to maintaining international peace, security and stability Madam Chair, today’s agenda also invites us to consider whether gaps in international law and whether additional legally binding obligations may, if appropriate, be elaborated in the future My delegation believes these questions should be approached carefully, inclusively and on the basis of evidence Before concluding that legal gaps exist we should first ask whether the greater challenge lies in the law itself or in our collective ability to understand implement as well as operationalize the law that we have already agreed applies. For many developing countries, including the Republic of Malawi, strengthening implementation remains the immediate priority nationally. We continue to strengthen our legal and institutional framework through the development of new national cybersecurity policy, our cybersecurity bill, complementary cybercrime legislation, legislation, and implementation of our Data Protection Act, as well as the work of the Malawi Computer Emergency Response Team and our Data Protection Authority. Should future discussions demonstrate that genuine legal gaps exist and that additional legally binding obligations are both necessary and capable of attracting broad international consensus, the Republic of Malawi stands ready to participate constructively in those discussions. Madam Chair, allow me to conclude with an observation. The most significant gap before us today is not a gap on international law. It is the gap between legal consensus and practical implementation. Closing that gap would do more to strengthen international peace and security than debating obligations that many states are not yet equipped to operationalize. As this global mechanism enters its implementation phase, let us continue to advance our work through dialogue rather than division, cooperation rather than confrontation, and implementation guided by the principles of international law. The Republic of Malawi stands ready to contribute the shared intervoir. I thank you.
—
Chair Egriselda López
Thank you very much. Before I give the floor to the next speaker, let me tell you who’s next. We’ve got Singapore, Colombia, Republic of Korea, New Zealand. I would like to thank the members of the European Commission for their support. be grateful if those delegations who haven’t yet done so, please submit their statement to eStatements and you can also hand it to the Chair’s team in the room. Thank you very, very much for all of your interventions so far. They have been very enriching. We’re very grateful for them and I’ll now give the floor to Singapore.
—
Singapore
Thank you, Madam Chair. Singapore sees international law as a crucial component of the mechanism’s work. As a firm believer in a rules -based international order, Singapore’s view is that fostering common understanding among states in the application of international law to the ICT context will contribute to greater peace, security and trust among states. In this regard, we also see considerable value in states issuing national statements or regional ones such as what the African Union and the European Union have done previously. Such statements would contribute to the key of states’ understanding of how international law applies in cyberspace that assist our work in this permanent mechanism. Singapore remains open to engaging and participating in discussions on the application of international law as a concrete first step needed before we can go on to discussing the identification of gaps in existing international law in the context of cyberspace. At a concluded OEWG, states have made progress in discussions on international law topics such as sovereignty, principle of non -intervention, peaceful settlement of disputes and prohibition against the use of force, and we look forward to states taking the discussions further and deeper. Madam Chair, this is where the role and work of DTG2 becomes crucial. Capacity building in international law is an essential part of fostering common understanding on how international law applies in the use of ICTs. We need to continue capacity building efforts with the aim of ensuring that every state acquires the necessary expertise and capacity to participate on an equal footing. and contribute meaningfully to discussions on international law. This remains a crucial undertaking for all Member States, especially in the context of the fast -evolving ICT landscape and the threats outlined by states in the earlier session. Thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much. I now give the floor to Colombia.
—
Colombia
Madam Chair, Colombia aligns with the statements delivered by Australia and Switzerland on this topic in our national capacity. We wish to share the following observations. The outcome of the deliberations under the framework of the GGE and the OEWG, there is today broad consensus on the applicability of international law to the use of ICTs by states. In this context, Colombia reaffirms that international law and especially the Charter of the United Nations apply to cyberspace and they are essential for maintaining international peace, security and stability. Therefore, the challenge that we face today consists in moving towards a more practical and broadly shared understanding of the idea that international law will apply to activities in cyberspace, including international humanitarian law and international human rights law. So in this regard, my delegation wishes to indicate three spheres where the first thematic group can provide significant added value by developing concrete outputs that will allow us to move legal arguments into practical guidance for states. Firstly, Colombia. believes it is relevant to go deeper in our analysis on the application of international humanitarian law to cybernetic operations in situations of armed conflict and especially we consider it to be useful to analyse how international humanitarian law and customary international law have been consolidated on cyberspace including the for those states while they may not have offensive cybernetic capability they may have legal and humanitarian interest in the development of such norms secondly Colombia has reiterated that international humanitarian law applies fully to the use of ICTs during armed conflict both international and non -international armed conflicts and that the fundamental principles of these continue to underpin the behaviour of parties in this context and so we believe that it is necessary to continue examining how these principles apply given the transformations that digital technologies have introduced into the nature and impact of armed conflicts including the use of digital platforms and social networks for the forced recruitment of boys, girls and adolescents by illicit or illegal armed groups. Finally, my delegation believes it is relevant to go deeper in the study of malicious cybernetic actions carried out by non -state actors in the territory of a state. This obligation should apply to all states equally regardless of their level of technological development. In this context, we believe it is also relevant to advise towards identifying means that will allow us to strengthen the effective implementation of this including the establishment of disclosure mechanisms of vulnerability, technical cooperation, so that those states with reduced capabilities can detect malicious use in their territory, as well as elaborating guidelines that can clarify the actions that states could take in order to ensure compliance with these principles. Madam Chair, Colombia believes that the development of a common understanding on the application of international law to cyberspace is absolutely crucial for consolidating a safe, stable and predictable digital environment. These efforts will allow us to reduce the legal uncertainty, promote responsible behavior by states, and mitigate the risks emanating from confusion as to the applicable international norms. We invite states to actively participate in this dialogue, and we are convinced this will control, contribute to, strengthen, trust between states, preventing conflict, and consolidate a more secure, stable, peaceful, and resilient cyberspace for all. I thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of the Republic of Korea to be followed by New Zealand.
—
Republic of Korea
Thank you, Madam Chair. The Republic of Korea would like to reiterate that existing international law, including the entirety of the UN Charter, international humanitarian law, and international human rights law, applies to cyberspace. Building upon this shared understanding, my government published its national position on the application of international law to cyberspace in July 2025 last year, with a view to contributing constructively to the ongoing discussion in the international community. Existing international law already provides a sufficient legal foundation for governing state conduct in cyberspace. Rather than pursuing the negotiation of new legally binding instruments, our efforts should focus on clarifying and operationalizing existing international law while strengthening mechanisms for its effective implementation through international cooperation. At the same time, we wish to emphasize that recognizing the applicability of international humanitarian law to cyberspace neither legitimizes nor encourages armed conflict. Rather, it seeks to ensure that if an armed conflict occurs, the protections afforded under international humanitarian law continue to apply in order to reduce human suffering and protect civilians. Discussions on the application of international law must also take account of the unique characteristics of cyberspace. In particular, we should recognize the challenges arising from the significant role of non -state actors as well as the anonymity, speed, and technical complexity of cyber operations, all of which make attribution and response more difficult. The global mechanism should therefore continue to serve as a platform for deepening our understanding of the realities of cyberspace and for progressively developing our common understanding of how existing international law applies in this domain. I thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of New Zealand to be followed by Israel, Estonia, United Kingdom, Armenia, Mexico, and Cuba. New Zealand, you have the floor.
—
New Zealand
Thank you, Chair. New Zealand aligns itself with the statement delivered by the Kingdom of Tonga on behalf of the Pacific Islands Forum and the statement delivered by Australia on behalf of the Cross -Regional Group of States. These statements reaffirm our shared understanding that international law applies to state conduct in cyberspace. This includes the UN Charter in its entirety, the law on state responsibility, international humanitarian law, and international human rights law. These statements also recall that our role in this process is to build on these common understandings. But as we begin to consider how international law applies, we invite states to keep three questions in mind. First. Why are we discussing international law? Second. What issues should we be focusing on? And third. Who should be in the room? On the first question, why are we discussing international law? New Zealand acknowledges that developments in cyber capabilities raise novel questions about how international law applies in cyberspace. The global mechanism presents a unique opportunity to work together to answer these questions. However, we do not consider the answer is to create new legally binding obligations. Not until all states have the capacity to engage with the existing legal framework. Our aim when discussing international law should be to work together to apply and implement this existing legal framework. Which leads me to the second question. What issues should we focus on? The global mechanism, including the DTGs, should not just prompt states to recite well -established positions. It should enable us to share. It should enable us to share practical experiences and best practices. on the application of international law when assessing or responding to common challenges, to identify international law capacity -building needs, to discuss areas of international law where our understandings remain less settled. Like Italy, we see value in the common African position on the application of international law, which identifies a helpful example of one area that could benefit from further discussion between states, namely the rule of non -intervention. While states share a common understanding that coercive cyber operations are inconsistent with the rule of non -intervention, the threshold at which such operations become coercive is less settled. Other national position statements on the application of international law to cyberspace, including New Zealand’s national position statement, signpost additional areas where our agreement on the application of international law converges, but our understandings of how international law applies can be strengthened. These discussions should continue here. in the global mechanism. On the third and final question, who should be in the room, New Zealand maintains that meaningful participation by relevant stakeholders, both in the plenary and the DTGs, is essential. This includes legal experts whose positions broadly support the need to continue building an understanding of how international law applies in cyberspace. Equally important is the direct participation of government lawyers from all states. As powerfully put by my colleague from Kiribati and many others in this room, legal capacity building is central to this. Lawyers should be in the room with policy colleagues when developing case studies and scenarios which integrate international law issues and perspectives. Lawyers can help turn legal principles into practical examples and contribute to drafting recommendations on possible action -oriented measures. We therefore continue… to support capacity -building efforts and measures that enable and justify
—
Chair Egriselda López
Thank you very much. I now give the floor to the Delegation of Israel.
—
Israel
Good morning, and thank you, Chair. Israel reiterates its consistent and longstanding position that the existing international law applies to cyberspace, including the UN Charter and the law of armed conflict. For this reason, among other reasons, we have mentioned yesterday, we are of the firm position that there is no need for a new legally binding instrument. Our discussion under the pillar of international law should be focused elsewhere. Traditional international legal principles were established in physical domain, specific context, their application to unique and decentralized features of the cyber domain requires a new legal framework. meticulous evaluation rather than automatic transpositions. To offer but unique example of the unique characteristics of the cyber domain that have meaningful ramifications for interpreting and applying international law to cyber activities, we should recall that data lacks a meaningful physical manifestation. It is highly dynamic as it can travel globally across multiple jurisdictions instantly. And relies heavily on privately owned international infrastructure. This example highlights another methodological insight we must bear in mind. International legal frameworks that were developed for domains with particularly unique characteristics such as maritime domain, international aviation, and space law were done so after comprehensive considerations and cautious deliberation. The cyber domain is similarly unique and we should learn from our predecessors by investing sufficient time to exploring the unique characteristics of the cyber domain before reaching premature conclusions Rules developed in physical domains should not be presumed ipso facto to apply similarly to the cyber domain particularly where the relevant practice or opinion use relate to domain -specific state activity The wide divergence in views held by states on key legal issues in the cyber context also militates we exercise care before asserting that a certain position reflects the lex lata The DTGs could play a role in identifying the unique factual characteristics of cyberspace that are most relevant to the interpretation and application of existing information in international law As part of the cross -cutting, multi -pillar discussions this approach will make sure that we do not prematurely advance our discussion on international law without proper understanding of the relevant technical and factual aspects, aspects that could and should be illuminated by appropriate technical experts from the tech community and academia. Finally, Madam Chair, Israel takes note of the numerous state positions that have been published over the last few years. Against the background of the open -ended working processes, Israel, for its part, has formally submitted its comprehensive legal position paper to the UNODA Secretariat. To conclude, Madam Chair, the global mechanism can contribute to this positive trend by exploring the intersection between the two. The gap between capacity building and international law. In our view, there is much value in using the DTGs as a vehicle for capacity building with an aim to help states in crafting, refining, and publishing
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Estonia to be followed by the United Kingdom.
—
Estonia
Thank you, Madam Chair. Estonia aligns itself with the statement by the European Union, and that’s the following in its national capacity. Previous UN processes have clearly confirmed that existing international law applies in cyberspace. The task before us now is to strengthen its implementation, deepen common understanding, and promote transparency in how states interpret and apply their international legal obligations in the ICT environment. Estonia strongly believes that international humanitarian law should be among the international law topics addressed by the global mechanism. Our discussion should move beyond questioning it. It should focus on its applicability and instead focus on the concrete legal questions. already emerging in practice, including those usefully identified by the ICRC in its working paper. Other international law topics the global mechanism should address include the Charter of the United Nations in its entirety, state sovereignty, the obligation of due diligence, the principle of non -intervention, the law of state responsibility, and international human rights law. I would also like to point out the important role national and regional positions on international law play in promoting clarity, predictability, and transparency in cyberspace. Earlier UN processes demonstrated how these positions usefully informed intergovernmental deliberations on the international law applicable in cyberspace. Estonia set out its first national position already in 2019 To ensure our position reflects current state practice, technological developments and our involving national interest the position is currently in its third review process We encourage other states to articulate, share and, where appropriate, regularly update their national views Looking ahead, the global mechanism should facilitate the exchange of national experiences on how international law is applied in practice This includes, first, assessing the legality of contemplated cyber activities second, responding to unlawful cyber operations and third, pursuing accountability for violations of international law committed in cyberspace Such exchanges can help identify effective approaches develop best practices and strengthen consistency in the application of international law in cyberspace. Chair, the predecessors of the global mechanism have since 2012 agreed and reaffirmed that existing international law applies in cyberspace. Moreover, over 100 countries, a majority of the international community representatives of all geographical regions, through national and regional positions, have already articulated their views on how international law applies in cyberspace. Those positions confirm that a substantial body of international law already applies in cyberspace, that various rules of international law restrict malicious cyber activities, and that international law provides numerous measures of redress to state subject to or affected by malicious cyber activity. International peace and security would now benefit most from investing the global mechanism’s limited resources in advancing a consistent application of existing law. Chair, international law is a cross -cutting theme. It must inform all areas of the global mechanism’s work, including discussions on threats, norms of responsible state behavior, confidence -building measures, capacity building, cooperation, and accountability. Legal considerations should therefore be addressed consistently across all thematic discussions. In this regard, Estonia welcomes the integrated, policy -orientated, and cross -cutting nature of dedicated thematic relations. The framework is the framework of the International Law Group, which draws on the five pillars of the framework, including international law. As also underlined in the joint statement of the cross -regional group, this approach allows us to examine specific ICT security challenges in a holistic manner, while ensuring that legal considerations remain fully integrated across our work. In closing, the global mechanism should keep international law at the center of cybersecurity discussions by supporting implementation, transparency, and practical cooperation within the existing framework of responsible state behavior. Estonia stands ready to contribute constructively to this work. Thank you.
—
Chair Egriselda López
Muchísimas gracias. Thank you very much for that statement. I now give the floor to the delegation of the United Kingdom.
—
United Kingdom
Chair, the United Kingdom is pleased that the global mechanism will continue to provide a forum for consideration of how international law applies in cyberspace, following on from the important work of the OEWG. Through the rich and deep discussions there and in other fora. we found areas of convergence in our collective understanding of the rules and principles that govern the state’s cyber activity. The breadth and depth of those exchanges and the extent of our agreement was not fully reflected in the final report of the OEWG, but we must not lose sight of them. Indeed, those discussions must continue in line with recommendations 44, 45 and 46 of the final report. Not only among states, but also with other stakeholders, including industry, academia and national and international organizations. Each have an important contribution to make in moving us beyond theoretical questions to help define what responsible cyber behavior means in practice. All states have agreed by consensus that international law applies to state conduct in cyberspace. In short, cyberspace is not law. Lawless. The UK’s position is clear. States have the right to exercise cyber capabilities, subject to the restrictions imposed by international law, just as they do in other domains. But we cannot settle on that basic premise. We must move beyond the fact that international law applies, and grapple with the more challenging questions of how existing rules apply in cyberspace. That is one important contribution a global mechanism should strive to make, both in these plenary sessions and through the work of the dedicated thematic groups. But this means turning our minds again in detail to relevant rules and principles, including of the ways in which state responsibility, IHL and IHRL apply in cyberspace. The UK has been at the forefront of states and international organisations impressing these issues, including through our detailed public statements on prohibited interventions, countermeasures, the use of force and the use of cyber means in furtherance of armed conflict. The UK’s position is clear. States have the right to exercise cyber capabilities, countermeasures, the use of force and the use of force in furtherance of armed conflict. where other states have not done so or have not done so in detail we encourage them to set out their positions in a similarly public way including in this forum states developing or reviewing their positions may find assistance in the practical handbook published by scholars from the University of Exeter developed in collaboration with the Ministry of Foreign Affairs of Estonia Ministry of Foreign Affairs of Japan and the NATO Cooperative Cyber Defence Centre of Excellence published in 2025 but placed on the Global Mechanism webpage earlier this week like others in the room we regret that stakeholders with genuine expertise including those from the University of Exeter were blocked from participating in this plenary session Chair, the greater the clarity on the boundaries of lawful behaviour the lower the risk of miscalculation and the clearer the question what consequences can be for those who transgress them The momentum that we built through the OEWG must not be lost. We must ensure that our exchanges help us all to realize a cyberspace that’s free, open, peaceful, and secure. I thank
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Armenia. They will be followed by Mexico and then Cuba.
—
Armenia
Thank you, Madam Chair. Armenia reaffirms its position that international law, including the UN Charter, is applicable in cyberspace as well. We underscore that respectful and faithful implementation of international law is essential to maintaining international peace and security, promoting stability and predictability in cyberspace, and fostering an open, secure, stable, accessible, and peaceful ICT environment. We support the continued discussions on the application of international law. We encourage international law to the use of ICT. including through the exchange of national views and practices in order to enhance clarity, transparency, and legal certainty. We underscore the importance of promoting a shared understanding of the application of international law in cyberspace, while recognizing that capacity building is essential to enable all states to participate effectively. We emphasize that the consensus reports of the GGE and OEWG provide a solid foundation for advancing discussions on the application of international law to the use of ICTs. Future work should build upon these agreed outcomes, ensuring continuity, avoiding duplication of efforts, and further developing a common understanding among states. We highlight the importance of ensuring that future discussions on the application of international law, take into account the needs and perspectives of developing and capacity -constrained states, so that all states can effectively participate in shaping a common understanding of how international law applies to the use of ICTs. I thank you.
—
Chair Egriselda López
Thank you very much I now give the floor to the delegation of Mexico
—
Mexico
Thank you very much, Madam Chair. Mexico reaffirms that international law, including the Charter of the United Nations, international human rights law and international humanitarian law, all apply to the use of ICTs by states. This applicability of international humanitarian law does not legitimise the militarisation of cyberspace nor that of armed conflict. On the contrary, it imposes limits on the conduct of parties and protects civilian populations. Mexico appreciates the progress made in the publication of national positions and welcomes inter -regional contributions on the implementation of international law, including the UNIDIR compendium and the recently published Common African Position. We would invite… more states and regions to publish their positions as a measure of transparency and trust -building. we cannot fail to point out that our country is continuing to work on consolidating its national position. Mexico supports the deepening exchanges within the mechanism as to how specific principles such as distinction, proportionality, precaution, due diligence and state responsibility are to be applied. Making the most of inputs from initiatives such as the Global Initiative on IHL and ICTs of the ICRC, I thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to the next delegations, which are Cuba, the Islamic Republic of Iran, the Kingdom of the Netherlands, Brazil, Germany, Mauritius and Venezuela. Cuba, you have the floor.
—
Cuba
Thank you Madam Chair the use of ICTs must be fully compatible with the purposes and principles of the Charter of the United Nations and international law especially governing sovereignty, territorial integrity and the non -intervention in the internal affairs of states they should be a tool for peace and development not a means of war that encourages a theatre of military operations security of cyberspace while this involves other actors is a responsibility of states like other states we also have presented and published a working document with our national position under the framework of the mechanism. Under Article 4 of the United Nations, cybernetic action does not constitute an armed attack insofar as it lacks the physical characteristics and other requirements that define military attacks, their impacts and their legal consequences. We are not disputing in this forum whether international law applies or not. Rather, we are discussing how it applies. For Cuba, automatic applicability of international law and international humanitarian law to cyberspace is not acceptable insofar as this supplies a step towards militarization of cyberspace. This would lead to making a cyber attack the equivalent of a military attack, and so legitimate defense could be invoked under Article 4. Under Article 4 .1 of the Charter corresponding to the use of force, amongst other difficulties is the broad range of actors that interact in cyberspace. negative impacts, cross -border impacts of this in the absence of a multilateral mechanism that would impartially and unequivocally determine the origin of cybernetic incidents, this can be easily manipulated today. These are all challenges and they cannot be tackled with the fractured and fragmented norms across different jurisdictional areas and many of these norms being flouted with any kind of legal consequences. The idea that voluntary norms are sufficient would enable legal uncertainty and would lead to an avoidance of international responsibility that falls to states and falls upon them when they commit internationally illicit acts. The idea that voluntary norms are sufficient would lead to an avoidance of international responsibility that falls to states and falls upon them when they commit internationally illicit acts. The idea that voluntary norms are sufficient would lead to an avoidance of international responsibility that falls to states and falls upon them when they commit internationally illicit acts. there is a need for a legally binding instrument that would be negotiated multilaterally under the framework of the United Nations. Unlike other fora for cyberspace, there are no primal norms that would regulate the conduct or due diligence of states or other private interests that have a significant control over this. In certain contexts, there may be very different actors involved. There is also capacity to generate international friction, so this continues to be a pending issue. We need to define common terminology that would allow us to define consensus. and understanding of concepts such as cyber incidents, information sharing, or what the different types of improper use of ICTs might be, we believe that this is essential. It is also necessary for us to establish a real commitment to the the elimination of the vast technological gap and all of the obstacles placed on developing countries in terms of investing in their ICT infrastructure, including unilateral coercive measures that limit the ability of these states to tackle existing and potential threats. We should focus on the key purpose, which is preserving ICTs for exclusively peaceful use aimed at development. I thank you.
—
Chair Egriselda López
Thank you very much. I will now tell you who is on the list next. First, the Islamic Republic of Iran, followed by Nigeria, who has a little… I just know they will be speaking on behalf of the African group. Then Netherlands, Brazil, and then Germany. Iran, you have the floor.
—
Islamic Republic of Iran
Thank you, Madam Chair. My delegation fully recognizes that the purposes and principles of the United Nations Charter, as well as the generally accepted principles of international law, apply to the use of ICTs by states. The OEWG process has reaffirmed proud agreement on this fundamental point, including with respect to the principles of sovereignty, sovereign equality, the prohibition of the threat or use of force, territorial integrity, the peaceful settlement of disputes, non -intervention in the internal affairs of states, and the good faith fulfillment of obligations under international law. However, recognizing that generally accepted principles of international law apply does not by itself resolve all legal questions arising in ICT environment. The unique characteristics of ICTs, including their cross -border, nature, the anonymity of malicious activities, the complexity of attribution, and the increasing involvement of private sector actors create legal and practical challenges that require additional legal rules. Madam Chair, the evolution of both domestic and international practice demonstrates that existing legal frameworks alone are not always sufficient to address the unique challenges arising from the use of ICTs. At the national level, an increasing number of states have enacted new legislation or substantially revised their legal frameworks to regulate various aspects of the ICT environment, including cybersecurity, data governance, digital platforms, the protection of critical infrastructure, and cyber security. A similar trend can be observed at the international level. The successful negotiation of the United Nations Convention Against Cybercrime demonstrates that states have already recognized the need to develop new legally binding international rules to address certain challenges arising from the use of ICTs. Had existing international law been considered sufficient to address all such challenges, there would have been no need to negotiate a new international convention in this field. These developments confirm an important reality. Technological developments give rise to new legal challenges requiring further legal regulation. This is fully consistent with the agreed mandate of the global mechanism, which explicitly states that the international law must be adopted to address all such challenges arising from the use of ICTs. This explicitly envisages the development of additional legally binding obligations. The question of additional legally binding obligations cannot be deferred indefinitely. Member states deliberately preserve this issue within the mandate of the global mechanism. and discussion on it should therefore continue in both the plenary sessions and the first dedicated thematic group. Voluntary non -binding norms should not be regarded as a substitute for the elaboration of additional legally binding obligations. In this regard, we take note of the updated concept of the Convention of the United Nations on Ensuring International Information Security, submitted by the Russian Federation and co -sponsored by a number of Member States as a possible contribution to discussions on this issue. I thank you, Madam Chair.
—
Chair Egriselda López
Muchisima gracias. I now give the floor to Nigeria on behalf of the Africa Group.
—
Nigeria Nigeria on behalf of the Africa Group
Thank you, Madam Chair. I have the honor to speak on behalf of the African Group. The Group reaffirmed that international law, including the Charter of the United Nations, applies to the use of ICT by States and remains essential. to maintaining international peace, security, and stability in cyberspace. African member states have advanced a common understanding through the adoption of the Common African Position on the Application of International Law to the Use of ICT in Cyberspace, which reflects Africa’s collective perspective while recognizing that the articulation of legal positions remains the sovereign prerogative of each state. The group believes that regional and continental perspectives enrich global discussions on the application of international law and underscore the importance of strengthening legal capacity, particularly in developing countries, to enable informed participation and effective implementation. In this regard, the African group encourages the global mechanism to 1. Support capacity building for legal, diplomatic, and technical espaces. Two, facilitate exchanges of national and regional experiences and practice. Three, promote dialogue among legal, diplomatic, and technical communities. And finally, strengthen cooperation with the regional and sub -regional organizations to enhance expertise and knowledge sharing. Many thanks, Madam
—
Chair Egriselda López
Chavos. Muchísimas gracias. Ahora doy la palabra a la directora. Thank you very much. I now give the floor to the Kingdom of the Netherlands, after which Brazil.
—
Netherlands
Madam Chair, the Kingdom of the Netherlands aligns itself with the statement delivered by the European Union, and we have also supported joint statements read out by Switzerland and Australia. And for the sake of time, I will deliver a short version of our national statement. The Kingdom of the Netherlands considers that this mechanism should build on the existing acquis, including the common understanding. The Kingdom of the Netherlands considers that this mechanism should build on the existing acquis, including the common understanding that international law applies to cyberspace in its entirety. Rather than revisiting areas where consensus has already been reached, we should turn our attention to the practical application and the tools that international law provides us to deal with the real -world threats. The integrated, policy -oriented, and cross -cutting nature of DGT -1 lends itself to such discussions. For instance, malicious cyber activities targeting critical infrastructure can be addressed through rules and principles, such as sovereignty and non -intervention, as well as international humanitarian law during armed conflict. Other threats that could benefit from further analysis are ransomware and malicious cyber activities targeting or impacting medical facilities and humanitarian and international organizations. The law of state responsibility can provide states with options to respond to such threats. As apparent from yesterday’s side event on international law hosted by Egypt, such discussion could benefit enormously from the views of legal experts and other relevant stakeholders. Discussions could also draw from work taking place outside this forum, for instance by the ICRC, on the implication of international humanitarian law in cyberspace. Finally, my delegation would like to echo the many states that have stressed the continued importance of capacity building on international law. Capacity building is vital to allow for the participation of all states and are needed to bridge the gap between technical, policy and legal experts. As mentioned by the European Union, the Kingdom of the Netherlands stands ready to share its own experiences in developing a national position on the application of international law in cyberspace. Thank you.
—
Chair Egriselda López
Thank you. Now I give the floor to the delegation of Brazil to be followed by Germany.
—
Brazil
My delegation lies itself with the statement made by Switzerland on behalf of a number of like -minded countries and would like to make additional remarks in its national capacity. International law is an essential part of the maintenance of an open, secure, stable, peaceful, accessible, and interoperable ICT environment. The General Assembly rightfully recognized over a decade ago that international law, including the United Nations Charter, international human rights law, and international humanitarian law, is fully applicable to states’ use of ICTs. That, of course, was only the beginning of our work on this issue. Since then, subsequent GGEs and both OEWGs extensively debate how to apply existing rules of interoperability. International law to cyberspace. Though we have made significant progress, the complexity of this endeavor will require further in -depth discussions to reach additional common understandings in this regard. This is likely the reason why, among all the pillars of the mandate, international law is the one in which consensus reports least reflect the richness of our debates. One important step in this process is, as recognized in OEWG reports, having a wide and diverse range of national views on how international law applies to the use of ICTs. As one of the first countries to publish its national position on the applicability of international and cyberspace, Brazil welcomes the increasing number of national positions that have been published and hope to see many more in the near future, especially from the international community. A plethora of national perspectives would enrich our collective understanding in this field. Having a broad and diverse range of states’ views is particularly important when thinking of possible customary law rules, which, as we all know, require both opinion ures and state practice. And as we have expressed in the National Opposition, the mere fact that a certain state behavior or position has not been formally protested against cannot be interpreted as acquiescence. The capacity -building initiatives that have been taking place in this area have been particularly important. We have both benefited from and contributed to those initiatives by sharing our experience with the development of our National Opposition. This global mechanism could make fostering the publication of these positions one focus of its work, including within DTG2. Madam Chair, the application of international humanitarian law to cyberspace is perhaps the issue in which the OEWG reports have been most lacking. As we have repeatedly stated, IHL applies to situations amounting to armed conflict independently of its classification as such by the parties. It does not matter whether the armed conflict is lawful or not, because it is the objective, because its objective is to minimize human suffering and provide a minimum level of protection to civilians in any scenario of hostilities. Therefore, the recognition that IHL applies to cyberspace does not in any way endorse its militarization or legitimize cyber warfare. If that were the case, the very existence, the existence of IHL itself would legitimize the use of force. We hope that relevant recent developments, such as the resolution protecting civilians and other protected persons and objects against the potential human cost of ICT activities during armed conflict, adopted by the 34th International Conference of the Red Cross and Red Crescent, and the work of the ICT Workstream of the Global Initiative to Galvanize Political Commitment to IHL, can help us make the required progress on the subject within this global mechanism. Madam Chair, even though we must continue to make progress in finding common understandings on how existing rules of international law apply to ICTs, we recognize that, as our debates evolve, we might find the need to specifically discuss four specific legally binding obligations to bring greater clarity to all states on international law application to cyberspace. As we have repeatedly stated, there is no contradiction between the applicability of currently internationalized cyberspace and the eventual ex specialis on the subject, or between binding obligations and voluntary norms, which are complementary and mutually reinforcing. We should not let this
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Germany.
—
Germany
Thank you, Madam Chair. Germany aligns itself with the statement of the European Union, as well with the statements by the cross -region groups delivered by Switzerland and by Australia. We will deliver the following additional remarks in our national capacity. Dear colleagues, it is important to note once more that we do not begin our discussion on this agenda point from scratch. Successive consensus reports of the GGEs and open -ended working groups and the General Assembly have affirmed and consistently reaffirmed that international law applies to cyberspace. Our common task for the global mechanism is therefore rather to deepen our common understanding how it applies in practice. The previous open -ended working group provided a great forum for the increasingly rich and focused exchanges on international law. States discussed substantive issues ranging from sovereignty, international human rights, to international humanitarian law. Working papers supported by a diverse group of states were shared and showed room for emerging conversions in states’ opinions on the issues. At the same time, Germany, in line with the observation of Brazil presented just before us, is of the opinion that the final report of the OEWG did not fully reflect the breadth and depth of those discussions, especially when it comes to international humanitarian law. This should not bar us, however, from continuing our good work, building on this foundation and the momentum that has continued to build since then. A growing number of states from all regions have published national or regional positions on their interpretation of international law and cyberspace, and we are hearing from more in other states that they are preparing to voice their opinion as well. At the same time, work on international law and cyberspace is also taking place outside of New York. Here I just want to mention the resolution adopted at the 34th International Conference of the Red Cross and Red Crescent and the ICT work stream under the Global Initiative to Galvanize Political Commitment to International Humanitarian Law, as also already highlighted by colleagues. Conscious of time, we won’t repeat the shared understanding expressed in the joint statements, but would like to highlight the following three points. First, capacity and the need for capacity building on international law, as highlighted by many colleagues. From our own experience, we know that drafting a national position can be demanding, time -consuming, and requires a lot of coordination. This is why international law is a priority for Germany’s partnerships and cyber capacity building engagement. As pointed out by Singapore, it is important that all states can participate on an equal footing at our discussions. Second, we believe that regional organizations have an important role to play. Many regional organizations were key to foster discussions in their respective regions, such as the AU, OAS, and the EU, or included international law and capacity -building activities, as for example the OECD Secretariat. Their deliberations and the outcome of their work then feed back into our work here at the Global Mechanism. And finally, looking ahead to the DTGs, we hope that international law will be integrated holistically into the work of the DTGs. When examining concrete challenges and activities in cyberspace, we also need to consider how international law applies to them. This would provide a solid foundation enabling us to move forward in an action -oriented, practical way to address the challenges we face. We face collectively in line with the
—
Chair Egriselda López
Thank you very much I now give the floor to the delegations of Mauritius to be followed by Venezuela Vanuatu, China, France and then Japan. Mauritius you have the floor
—
Mauritius
Thank you for giving me the floor Chair, distinguished delegates and colleagues Mauritius remains committed to the continued exchange of national views and practices to promote a common understanding of how international law applies in cyberspace The experience of Mauritius demonstrates the importance of translating international principles into effective national implementation Through our Cybersecurity and Cybercrime Act 2021 and related institutional mechanisms, Mauritius continues to strengthen our ability to prevent, investigate and respond to cybercrime threats while ensuring that cybersecurity measures remain consistent with the rule of law and respect for fundamental rights For Mauritius, developing a national position on the application of international law in cyberspace represents an important step towards strengthening legal certainty, enhancing transparency and contributing to international dialogue It also enables us to better understand our rights and obligations under existing international law while informing national policy and decision making In this regard and taking into consideration the common African position Mauritius has undertaken the development of its national position on the application of international law in cyberspace which is currently undergoing the necessary approval processes prior to its publication Our national position reflects our specific national context and priorities as a small island developing state For Mauritius, the following principles provide an essential foundation for addressing current cyber challenges First, sovereignty is closely linked to our ability to protect our critical infrastructure and essential services. Second and third, due diligence and state responsibility support responsible behavior and effective responses to malicious cyber activities. Fourth, respect for human rights ensures that cybersecurity efforts remain people -centered. And fifth, peaceful settlement of disputes reinforces the importance of dialogue and cooperation in addressing the cross -border nature of ICT threats. Given the rapidly evolving nature of the digital environment, Mauritius considers this position as a living document, which may continue to evolve in light of technological developments, emerging challenges, international discussions, and lessons learned from national implementation. Thank you for your attention. Allow me to highlight that this achievement was made possible through the invaluable support of UNIDER whose technical expertise, guidance and capacity building support enable an inclusive national process involving relevant government and multi -stakeholders In partnership with UNIDER, Mauritius also had the privilege of co -organizing a side event on Monday as a pre -launch of our national position The process of developing our national position has demonstrated that this is not merely a legal drafting exercise It is a valuable capacity building process that strengthens institutional knowledge promotes dialogue among legal, technical, diplomatic and policy communities and builds a common national understanding of the legal issues arising from the use of ICTs We share the views of Italy, New Zealand, Germany and Mauritius and many others in that capacity building is a key enabler for advancing discussions on international law in cyberspace Many developing countries possess the willingness to engage substantively in these discussions, but continue to face constraints in terms of specialized expertise, institutional capacity, and resources. Tailored, demand -driven capacity -building initiatives empower states to develop their own national positions, participate more effectively in international processes, and contribute meaningfully to the development of shared understandings on the application of international law in cyberspace. In this context, Mauritius welcomes the continued efforts of the global mechanism and the DGGs to facilitate practical cooperation and support capacity building. This is one of the many capacity -building initiatives that respond to the needs and priorities identified by states. Mauritius remains available to share its experience and lessons learned from the development of our national position with other interested states. We hope that our experience will encourage more states to embark on similar processes, thereby contributing to greater transparency, confidence, and a deeper common understanding of the application of international law
—
Chair Egriselda López
Thank you very much. I now give the floor to Venezuela to be followed by Vanuatu.
—
Venezuela
opinion on the applicability of international law and international humanitarian law to cyberspace. We question the full and automatic applicability of international norms to the use of ICTs, by virtue of which we gradually need to adjust and adapt international law to this sphere as a result of the specific characteristics of this technology and its functioning. Venezuela believes that international law and international humanitarian law are not automatically applicable to cyberspace or virtual space. We need to continue assessing how exactly it should apply. We’re not saying that it doesn’t apply altogether, but rather we’re saying there is a need to critically explore how such law applies to this sphere in particular. We believe that the creation of a… a legally binding framework of comprehensive spoke is not only necessary, but also we believe this is part of the mandate of the former working group. former OEWG. In this regard we also believe that this legally binding framework should be based on the five pillars of the permanent mechanism as set out in the last annual report. Finally we reiterate as we have indicated previously that it is of the utmost importance that we preserve the principle of consensus in all decisions and activities of the global mechanism including those undertaken under the thematic groups. I thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Vanuatu followed by China, France and then Japan.
—
Vanuatu
Madam Chair, Vanuatu aligns itself with the statement delivered by Tonga on behalf of the Pacific Islands Forum members, support the cross -regional group statement delivered by Australia and offers the following remarks in its national capacity. Vanuatu believes in international law not rhetorically, but as a matter of demonstrated national conviction. When our people faced the gravest threat to their future, we took the question of states’ climate obligations to the International Court of Justice, and the world followed. We bring the same conviction to this pillar. For states without armies of scale or arsenals of deterrence, the rule of law is not one security strategy among several. It is the security strategy. Vanuatu therefore reaffirms, as we did through the OEWG, that international law, with the Charter of the United Nations at its core, applies in full to state conduct in cyberspace. The obligations that follow are not obstructions. Respect for sovereignty and the sovereign equality of states, the peaceful settlement of disputes, refraining from the threat or use of force and non -intervention in matters within domestic jurisdiction. We further reaffirm the applicability of international human rights law to the online sphere and of international humanitarian law to cyber activities in armed conflict, a body of law whose purpose is humanitarian protection and whose affirmation makes conflict less cruel, not more likely. Vanuatu attaches particular importance to the law of state responsibility and to the due diligence expectations that accompany sovereignty over ICT infrastructure. For states like ours, clarity on these questions determines whether accountability for malicious activity is a realistic prospect or a theoretical one. We were encouraged that the OEWG’s final report captured convergence in these areas and we consider that record… the floor for the mechanism’s legal discussions, not their ceiling. Madam Chair, Vanuatu has been engaged in sustained national work to deepen and articulate our own understanding of how these rules apply, and we look forward to contributing the fruits of that work to this mechanism at the appropriate time. We commend the states, including in our own region, whose published positions have enriched the collective picture, and we underline that developing such positions is itself a demanding legal exercise for a small foreign ministry, which is why legal capacity building must remain inseparable from this pillar. Vanuatu supports dedicating structured time in this mechanism, including within the thematic groups, to working through how the law applies in concrete situations, so that legal discussion becomes a shared capability, rather than a specialist preserve. Law serves those who can invoke it. Van Watten’s aim in this pillar is a cyberspace in which every state, whatever its size, can.
—
Chair Egriselda López
Thank you very much. I now give the floor to China.
—
China
Thank you, Madam Chair. On the issue of international law, China wishes to further elaborate on the following three points. First, we must further underscore the role of the UN Charter and its purposes and principles as the cornerstone, especially the principles of sovereign equality, the prohibition of the use or threat of force, peaceful settlement of international disputes, and non -interference in the internal affairs of states. With taboo on cyber warfare blatantly breached now and cyber peace and security faced with unprecedented challenges, we must more than ever uphold. A cyberspace order based on the purposes and principles of the UN Charter. All countries should explicitly oppose the use of cyber means to carry out acts of aggression. Major countries in particular should use cyber technologies during armed conflicts with caution. All countries should uphold strategic communication to enhance mutual trust, resolve differences through consultation and dialogue, and prevent and avoid state -to -state cyber conflicts. Major countries in particular should show that their responsibilities take the lead in observing international rules in cyberspace instead of engaging in exceptionalism or selective application. Second, the application of international humanitarian law in cyberspace must be handled with greater prudence. The inherent legal and technical difficulties in applying the international humanitarian law in cyberspace remain unresolved. Furthermore, large tech companies from certain countries are deeply involved in geopolitical conflicts, posing new challenges to the application of international humanitarian law in cyberspace. and of IHL in cyberspace. In cyber conflicts, it is already hard to distinguish between peace and war as well as between civilians and combatants. The involvement of tech companies makes such a distinction even harder. Whether their participation in armed conflicts complies with the principles of distinction and military necessity warrants close attention of all parties. Third, we must more seriously discuss the issue of formulating new legal instruments. To maintain lasting peace and stability in cyberspace and prove and build a shared cyber order. We should, in view of the characteristics of ICT and evolving landscape and based on broad participation from our parties, we should discuss and conclude a new international legal instrument. China believes that the Convention on International Information Security proposed by Russia can serve as a very good basis for discussion. Madam Chair. China hopes that. the DTGs under the global mechanism should take into full consideration concerns of parties. An advanced discussion international in a balanced manner, China is willing to adopt a constructive attitude to participate in relevant
—
Chair Egriselda López
Thank you very much. I now give the floor to France to be followed by Japan.
—
France
Thank you, Madam Chair. My delegation aligns itself with this statement delivered by the European Union and would like to make the following remarks in its national capacity. Let me first recall that this is the first plenary mission of the global mechanism, the importance of discussions on the applicability of international law in all of its aspects, including, naturally, international humanitarian law. France remains very committed to international law, international law, and at its heart, the Charter of the United Nations. And this is a cornerstone of the complex architecture that we’re building here to regulate relations between states and to maintain international security and stability in cyberspace. Weakening the Charter threatens us all, as Russia is notably doing, waging a war of aggression against Ukraine with devastating effects, both in the kinetic and cyber domains. I would like to briefly highlight three points before concluding. First, France advocates the implementation of the existing regulatory framework, of which international law, of course, is a pillar of this framework. We face collectively a major task within the mechanism, which is to develop a common understanding of key concepts of international law, and there are others, such as state responsibility and due diligence. And France is ready to do so. Second, the debate on new binding standards is for us of secondary importance. And we understand very well, having listened to the room, that just a few member states think that this is a priority. But here again, we regret that the most fervent defenders of a new treaty are precisely those who are to today trampling existing international law underfoot. Third, my delegation supports the statement made by Switzerland on international humanitarian law. In particular, we call for the forthcoming findings of the global initiative launched by the International Committee of the Red Cross, which, as you know, has devoted part of its consideration to international law and humanitarian law and the use of information and communication technologies to be taken into account. in our work, and we thank them for this work. I thank
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Japan to be followed by Canada and then Ireland.
—
Japan
Thank you, Madam Chair. Through discussions in the OEWG, we understand that there is a consensus among all UN member states that existing international law applies in cyberspace. In the global mechanism, based on this consensus, it is important to facilitate practical and concrete discussions on how existing international law applies with a focus on responding to specific incidents such as cyber attacks on critical infrastructure. In this regard, from the perspective of complying with existing international law, we consider it an option to deepen discussions. in light of application of responsibility of states for internationally wrongful acts. In DTG 1, we hope that through expert briefings and interactive, practical, and concrete discussions, member states’ awareness and understandings of the specific application of existing international law will be deepened further. Thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much. I now give the floor to Canada.
—
Canada
Canada associates itself with the cross -regional joint statement on the application of international law delivered by Switzerland. Canada wishes to make the following statement in its national capacity. Madam Chair, Canada is firmly committed to ensuring that this new global mechanism, builds on the important acquis developed through the success of UN groups of government experts and… open -ended working groups. We are committed to ensuring that the mechanism advances the existing accomplishments on international law. Thanks to several years of sustained engagement, states have moved well beyond the initial debates. The challenge before us is therefore no longer whether international law applies in cyberspace. There is now a widely recognized consensus on this point. Rather, our task is to continue deepening our common understanding of its practical application. During the March 2026 organizational meeting and in the course of the last two days of the plenary, the vast majority of member states expressed their willingness to pursue down this path and to engage in the work of the mechanism in a constructive, exclusive, and good -faith manner. Canada therefore believes that the global mechanism should focus on substantive discussions and implementation including through integrated discussions on real world cyber challenges All states may face ransomware attacks affecting hospitals as well as malicious cyber activities targeting critical infrastructures such as healthcare, energy and transport Discussions of this nature provide unique opportunities to examine the practical application of international law The dedicated thematic groups provide here an ideal platform for informal exchanges on such concrete cases including through encouraging the participation of both government and non -governmental legal experts Such exchanges could continue to contribute to strengthening common understandings of the practical application of international law and to further develop those understanding in specific areas such as international human rights law and international humanitarian law. Capacity building should remain a central and necessary element for the success of this pillar. Efforts in this area should be needs -based and should continue to assist states in developing national positions, strengthening participation in discussions, and improving practical implementation. The continued publication of national positions and regional approaches have already contributed significantly to building common understandings. Open and inclusive dialogue should continue in this regard. Thank you very much. Madam Chair, international law remains an essential element of our collective efforts. Continued dialogue on international law is itself an important confidence -building measure. By reinforcing existing consensus, deepening common understandings, strengthening capacity, and focusing on practical implementation, the global mechanism can make a meaningful contribution to stability, predictability, and security in cyberspace. Canada looks forward to working with all delegations
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Ireland to be followed by Turkey and Ukraine.
—
Ireland
Thank you, Madam Chair. Ireland aligns with the… …the intervention of the European Union and wishes to make a number of remarks in our national capacity. At the outset, we wish to note that Ireland is pleased to have co -sponsored the joint statement on the application of international law in the use of ICTs submitted by Switzerland and others, and the cross -regional group statement submitted by Australia and others. The global mechanism provides an opportunity to advance our shared understanding on how international law applies in cyberspace and to build on the work of the GGEs and the OEWG. We should make full use of the mechanism structures to advance this work, including the DTGs and the plenary. In particular, we call for international law, including IHL, to feature prominently in the substantive work. We would welcome the use of appropriate working modalities to facilitate a more dynamic exchange of views on international law in the DTGs and plenary as appropriate. Such modalities may include guiding questions, structured discussions and scenario -based exercises We agree with the list of five priority topics identified in the joint statement on the application of international law in the use of ICTs submitted by Switzerland and others We also support calls to use capacity -building discussions in DGG2 to better enable states to develop their own national positions on the application of international law in cyberspace We are particularly supportive of the intervention of Kiribati in that regard The application of international law in cyberspace, in particular the UN Charter, International Human Rights Law, International Humanitarian Law and the Law on State Responsibility is an objective legal fact Ireland strongly disagrees with any suggestion that affirming the application of IHL to cyberspace encourages or legitimizes the militarization of cyberspace IHL is concerned with limiting the suffering caused by armed conflict and mitigating its effects rather than with the justifiability of the initiation of the conflict The application of IHL in cyberspace ensures that we minimise any gaps in legal protection when it comes to armed conflict in cyberspace especially the protection of civilians and civilian objects Madam Chair, we note that there is now real momentum in states developing national positions Over 100 states have now published, either individually or as part of a regional group their positions on international law The experience of developing our own national position, which we published in 2023 was a valuable one and we encourage all states to consider developing a position either individually or collectively Ireland Ireland is willing to engage informally with any states in order to share our national experience in preparing a national position The more national positions that are developed and published, the closer we come to bridging gaps in our shared understanding of how international law applies in cyberspace. Whilst there may be gaps in our shared understanding of the law, it is not evident at this stage that there are significant gaps in the law itself. Accordingly, we consider that any cause for new legally binding rules would be premature, and our priority should instead be to consolidate our shared understanding. Finally, as we consistently submitted in our statements during the OEWG process, we believe that any outcomes of the global mechanism should focus not just on identifying areas of consensus, but also areas of convergence in order to accurately compare. We look forward to contributing positively to further discussions on international law within the global
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Turkey.
—
Turkey
Thank you, Madam Chair. Turkey considers it essential to preserve a rules -based, open, secure, stable, accessible, and peaceful ICT environment. In our view, cyberspace cannot be regarded as a legal vacuum. Although rules and understandings specific to cyberspace are still emerging and continue to be discussed by member states, it may be reaffirmed that existing international law applies to state conduct in the ICT environment. In this regard, UN Charter remains the cornerstone of the international legal order. Its purposes? And principles are equally relevant in the ICT context. These include, in particular, the principles of sovereignty, sovereign equality of states, non -intervention in internal affairs, and prohibition of the threat of use of force, and the obligation to settle international disputes by peaceful means. Türkiye believes that these principles provide the necessary foundation for responsible state behavior in cyberspace. Activities in the ICT environment should not be used to undermine the sovereignty, security, or public order of other states, nor should they be used in a manner inconsistent with the purposes of the principles of the Charter. At the same time, the application of the international law to the use of ICTs should be addressed in a careful, inclusive, and consensus -oriented manner. Differences in national legal systems, levels of technological capacity, and security concerns should be duly taken into account. In this respect, continued dialogue within the UN along with the mechanism is essential for developing common understandings among member states. I
—
Chair Egriselda López
Thank you. I now give the floor to the delegation of Ukraine to be followed by Thailand and Albania.
—
Ukraine
Thank you, Chair. Ukraine aligns itself with the statement delivered by the European Union and would like to add some considerations in our national capacity. Ukraine reaffirms its unwavering support for the cumulative framework developed within the United Nations, under which international law, in particular the Charter of the United Nations in its entirety, is applicable to the use of the ICTs by states. The international community has repeatedly reaffirmed that existing international law provides a comprehensive legal framework governing state conduct in the ICT. environment and remains essential for maintaining international peace and security. Accordingly, Ukraine does not support efforts aimed at developing new legally binding or non -binding international rules governing state behavior in the cyberspace. At this stage, our collective priority should be to deepen the common understanding of how international law that exists, how it applies in practice and to strengthen its faithful implementation. Chair, respect for international law is not optional. It is the foundation of stability, predictability and accountability in international relations, including in cyberspace. The principles of sovereignty, sovereign equality, non -intervention in the internal affairs of states, the peaceful settlement of disputes and the prohibition of the threat or use of force remain fully applicable when states use ICDs. Likewise, Article 51. of the Charter, which recognizes the inherent right of individual and collective self -defense, applies irrespective of the means by which an armed attack is conducted. Chair, Ukraine believes that discussions within the global mechanism should therefore focus on improving states’ common understanding of the application of existing international law, exchanging national views and practices, and strengthening legal capacity across all regions. To our understanding, the work of the DTG -1 could significantly contribute to that, also taking into account that the international law is complemented by the 11 voluntary norms of the responsible state behavior. In this respect, we support the in -depth discussion on the cybersecurity of the healthcare infrastructure, whilst also suggesting the in -depth discussion of the issues relevant to protecting the objects of energy infrastructure against the cyberattacks, the importance of which, to our understanding, is determined by the fact that in the digital age, the internet coverage, data accessibility, access to the transport and banking services, even the house heating, and literally any kind of online activity is dependent on the availability of the stable access to the electricity. To our understanding, this is cross -cutting both in terms of the application of international law and international humanitarian law, also in reference to the joint statement earlier delivered by the Swiss delegation, and operationalization of the framework of the responsible state behavior. As well as potentially determining the approaches and good practices towards balancing the scopes of responsibilities of the stakeholders within the public -private partnerships. Chair, the effectiveness of international law ultimately depends on its observance. States cannot selectively invoke international law while simultaneously violating its fundamental principles through malicious ICT activities directed against other states. international stability and erodes confidence in the rules -based international order. Ukraine believes that accountability must remain an integral element of the rules -based international order in cyberspace. International law cannot effectively contribute to stability if its violations remain without consequences. States responsible for internationally wrongful acts conducting through ICTs must be held accountable in accordance with international law. This includes strengthening international cooperation on attribution, promoting transparency regarding malicious cyber activities, and ensuring that violations of international law do not become normalized. In this regard, systematic malicious cyber activities conducted as part of the war of aggression waged against Ukraine by a certain P5 member state clearly demonstrate the importance of ensuring ensuring accountability for violations of international law committed in and through cyberspace. Impunity only encourages malicious behavior and undermines confidence in the international legal order. Ukraine remains firmly committed to promoting the full implementation of existing international law in cyberspace and looks forward to working with all delegations to strengthen peace, security, and stability in the ICT environment. Thank you. Muchas gracias.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Thailand to be followed by Albania.
—
Thailand
Madam Chair, Thailand aligns itself with the statement delivered by Australia on behalf of the cross-regional group of states. The transition from the UNGCE and the UNOEWG on this global mechanism marks an important milestone in our collective efforts to advance our common understanding of the application of international law in cyberspace. On this agenda item, Thailand wishes to make three points. First, Thailand reaffirms its long-standing position that international law, in particular the UN Charter, applies to the use of ICTs. We remain firmly committed to an international order that is robust, grounded in international law. as the most effective means of safeguarding the sovereignty, security, and interests of all states. The publication of our first ever National Position on the Application of International Law in Cyberspace last year stands as a clear demonstration of this position. We welcome the continuation of discussions on international law under this global mechanism. While this may not be the separate dedicated thematic group that Thailand and a number of other member states have proposed, we believe it nevertheless provides a valuable opportunity to further deepen our common understanding of how international law applies in cyberspace. Thailand also believes that reflecting the common understandings we reached during the session in November. This report would be valuable. Such a record would enable us to identify the progress we have made in narrowing our differences while also highlighting the areas where further dialogue and work remain necessary. Second, Thailand attaches great importance to fostering common understanding on lawful and responsible state behavior in cyberspace to enhance international dialogue and the regular sharing of national views and positions. This helps reduce the risk of misunderstandings and exploration among states while also contributing to progressive development of internationally accepted rules and principles governing state behavior in cyberspace. Thailand has consistently shared its interests, national views throughout the OEWG progress. and looks forward to continuing to do so actively and constructively within this global mechanism. Third, promoting a common understanding of international law in cyberspace also requires bridging the gap between the legal and ICT communities and addressing remaining capacity gaps among states. In this regard, Thailand co -hosted with Junidia the workshop on the implementation of the UN norms of responsible state behavior in cyberspace in Bangkok earlier this month. Such initiatives also strengthen misunderstanding of how international law applies in cyberspace, while also serving as confidence -building and capacity -building measures. The other two important pillars, we stand ready to engage in further discussions on those issues. Thank you. In closing, Thailand reaffirms its unwavering commitment to contributing to the continued development of international law in cyberspace. We stand ready to work with all partners to advance the objective of this global mechanism. Thank you,
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Albania. They will be followed by the Russian Federation.
—
Albania
Thank you, Madam Chair. Albania supports and aligns with the European Union position for fully implementation of the United Nations Framework of Responsible State Behavior in Cyberspace, as well as remains committed to a rules -based, open, secure, and stable cyberspace. We believe that existing international law remains fit for purpose in the digital and cyber domain. Malicious cyber activities are increasing. Increasing in scale, sophistication, and impact. affecting societies, economies, and critical infrastructure and may threaten international peace and security. Albania reaffirms the international law, in particular the Charter of the UN International Human Rights Law and International Humanitarian Law, fully applies to cyberspace. A better global understanding of its application contributes to greater transparency, predictability, and accountability in states’ conduct. In line with the EU Declaration on a Common Understanding of International Law in Cyberspace, Albania supports international law application in the cyber context of state sovereignty, the principles of non -intervention, due diligence, the prohibition of the threat or use of force, the peaceful settlement of disputes, the law of state responsibility and lawful state responses. States must conduct their activities consistently with their international obligations, and internationally wrongful cyber operations entail states’ responsibility when the relevant requirements are met. Albania reiterates that international humanitarian law applies to cyber operations conducted in the context of armed conflict, and recognizes this neither encourages the militarization of cyberspace nor legitimizes cyber warfare. The principles of distinction, proportionality, and precaution remain essential, and civilians and civilian objects must receive, the protection under international humanitarian law. International human rights law likewise applies online as it does offline. Albania attaches particular importance to cooperation and capacity building. training, exchanges of national and regional positions, scenario -based exercises, and the support for developing national positions can help create shared understanding on how international law applies to cyberspace. The global mechanism should provide an inclusive and action -oriented forum for advancing these discussions. Its plenary session and dedicated thematic groups should facilitate focus exchanges on concrete legal questions, draw on national and regional practice, identify capacity needs, and promote practical recommendations. Differences of interpretation should not be treated as issue, but should encourage deeper dialogue to reach a common understanding on the application of UN framework already in place. Albania remains committed to upholding and promoting international law in cyberspace, and stands ready to work with all partners to strengthen a peaceful, secure, stable, and rule -based ICT environment. Thank you, Madam Chair.
—
Russian Federation
Thank you, Madam Chair. In this sphere, the UN Convention against Cybercrime developed on Russia’s initiative was opened for signature. The document has already been signed by 78 countries. I would like to take this opportunity and call upon all states to join this important instrument in the fight against hackers and online fraudsters. The adoption of the convention has become indisputable evidence of the demand for global treaties to regulate the digital space, whose unique technical and legal characteristics do not allow automatic and full application of existing norms of international law. The next logical step, in our view, should be to develop similar international legal instruments for other aspects of international information security, above all, with a view to preventing and peacefully resolving interstate conflicts in the information. Thank you. note that specific proposals on this matter already exist. They were presented within the OEWG and the General Assembly in the form of a concept of UN Convention on International Information Security. This document reflects an understanding of how universally recognized principles of international law apply to ICT and insurates provisions based on the recommendations of the annual UN General Assembly resolutions under the agenda item, developments in the field of information and telecommunications in the context of international security. We believe it is important to continue substantive discussions on this matter, and this is provided for by the mandate of the global mechanism which was established by a consensus, a UN General Resolution 79 -237 and 80 -16, and they are mandatory. In this regard, we call upon the Chair to organize relevant discussions. Thank you. Thank you. I would like to address separately the concept which is promoted by some delegations, namely reporting on implementing voluntary non -binding norms of responsible state behavior. States here are being offered to adopt a supposedly voluntary checklist of practical actions to implement the norms. We do not refuse to discuss the document, but only on the understanding that it will indeed in practice be voluntary and will not become, as openly stated by a number of delegations, a form of reporting by some states to others. We reject such an approach as inconsistent with the fundamental principles of the UN Charter. At the same time, in our view, even in its current form, the above -mentioned checklist is inadequate. It must be expanded primarily. through additional rules contained in UNGA Resolution 73 -27, including the norms that requires the provision of evidence when attributing responsibility to states for carrying out cyber attacks. This so -called framework for responsible behavior should take into account all relevant General Assembly decisions. In conclusion, I would like to reiterate voluntary rules of responsible state behavior can be observed, but only obligations under international treaties can be implemented. Therefore, we believe that the concept of implementing rules of behavior could be possible only after these voluntary rules
—
Chair Egriselda López
Muchas gracias. Thank you very much. I now give the floor to the delegation of Indonesia to be followed by Ghana and then the Philippines.
—
Indonesia
Thank you, Madam Chair. International law provides the essential framework for ensuring stability, predictability, and responsible behavior in the use of ICTs. Indonesia reaffirms that international law, in particular the UN Charter, applies to cyberspace and that existing international law principles, including sovereignty, non -interventions, the prohibitions of the use of force, and peaceful settlement of dispute, remain fully applicable to states’ conduct in the ICT environment. The OEWG has made clear that while the existing body of international law applies, the shared understanding of how these rules operate in practice remains uneven. This gap risks fragmentations, misinterpretations, and inconsistent implementations. Therefore, the global mechanism provides an inclusive platform for the continued dialogue needed to deepen shared understanding and strengthen the practical applications of international law, ensuring that all states can meet. This is a way for the OEWG to meaningfully interpret and apply international law in cyberspace. In a more practical approach, we underscore the need for the global mechanisms to address the issue of attributions on objective, transparent, and based on technical standards and methodologies. Attribution must never be used as political instruments. Such an approach is essential to maintaining trust, preventing miscalculations, and ensuring that the applications of international law in cyberspace remain fair, non -discriminatory, and respectful of differing capacities of states. In this regard, exchanges on national positions, case studies, and legal methodologies are essentials. Indonesia underscores that such exchanges must be non -prescriptive, non -hierarchical, and respectful of differing legal traditions. Madam Chair, as the global mechanism advances its work, Indonesia believes that priorities should be placed on cooperative capacity building, including training on the applications of international law in cyberspace, and strengthening these areas will help ensure that the applications of international law remain fair, non -discriminatory, and respectful of differing legal traditions. International law in cyberspace is inclusive, consistent, and reflective of the needs and realities of all member states, particularly developing countries.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Ghana.
—
Ghana
Chair, distinguished delegates, Ghana aligns itself with the position of the African group delivered by the distinguished delegates of Nigeria and wishes to deliver the statement in its national capacity. Ghana reaffirms that international law, particularly the Charter of the United Nations, remains applicable and is essential to maintaining international peace, security and stability in the use of ICTs. This includes the principles of sovereignty, sovereign equality, peaceful settlement of disputes, and non -intervention in the internal affairs of states, as well as the applicability of international human rights law and international humanitarian law where applicable. This position is consistent with a common African position on the application of international law in the use of ICTs. Ghana believes that continued dialogue on the application of international law is essential to promoting a common understanding among states and reducing the risk of misunderstanding and conflict in cyberspace. In this regard, we welcome the establishment of a dedicated thematic working group on international law as an important platform for inclusive and constructive discussions. Ghana also reaffirms the importance… of Article 2 .3 of the UN Charter, which calls upon states to settle international disputes by peaceful means in a manner that does not endanger international peace, security or justice. This principle remains relevant in the context of ICT -related activities. Madam Chair, Ghana remains committed to working with member states and all relevant stakeholders to advance a shared understanding of the application of international law in the use of ICTs. We look forward to continuing these discussions under the global mechanism in the spirit of cooperation, consensus and mutual respect. Thank
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of the Philippines.
—
Philippines
Thank you, Madam Chair. International law remains a cornerstone of the UN framework of responsible state behavior in the use of ICTs. The Philippines reaffirms the consensus reflected in successive reports of the UN groups of government experts and the OEWG that international law, in particular the Charter of the United Nations, applies to the use of ICTs by states and contributes to maintaining international peace, security, and stability in cyberspace. As the global mechanism advances from dialogue to implementation, our collective work under this pillar should focus on strengthening understanding of and practical implementation of this established consensus. In this regard, we are aligned with the other member states that emphasize practical implementation, continued dialogue, and voluntary exchanges of national experiences and the use of ICTs in the use of ICTs. While recognizing differing legal systems, national circumstances, levels of technological development. The Philippines believes that discussions under this mechanism should prioritize practical exchanges on the implementation of international law at the national level, sharing national legislation policies, institutional arrangements, administrative and judicial practices, and operational experiences can promote transparency, enhance mutual understanding, and assist member states in strengthening their domestic legal and policy frameworks in accordance with their respective legal systems and international obligations. Such exchanges are particularly valuable for developing countries seeking to strengthen national cyber resilience while keeping pace with rapid technological developments. We also recognize that member states continue to hold different legal views on certain aspects of the application of international law in cybersecurity. The global mechanism provides an appropriate platform for continued dialogue and the voluntary exchange of national perspectives, practices, and experiences. These discussions can contribute to greater clarity and a shared understanding of how existing international law is applied in practice Madam Chair, the Philippines continues to strengthen its domestic, legal, and institutional frameworks to support the implementation of international law in the use of ICTs The proposed Cybersecurity and Critical Information Infrastructure Protection Bill which remains part of the country’s priority legislative agenda reflects our continuing efforts to strengthen the protection of critical information infrastructure enhance institutional coordination, and reinforce national cyber resilience We have likewise continued to update our regulatory and government’s frameworks to support secure digital transformation, strengthen government data governance protect sensitive information, and ensure that our domestic legalization and policy frameworks remain responsive to emerging technologies As ASEAN Chair in 2026, the Philippines also continues to advance regional implementation of the agreed framework through the ASEAN Cybersecurity Cooperation Strategy 2026 -2030. Cyber exercises, trusted information sharing, operational collaboration among competent authorities, and the exchange of best practices complement national implementation efforts and contribute to regional stability and resilience. Madam Chair, the Philippines believes that practical implementation should remain the foundation of our work under this pillar. As member states continue to exchange experiences and deepen their understanding, of how international law applies in the use of ICTs, these discussions will contribute to the continued development of our collective understanding. Any such discussion should remain inclusive, transparent, consensus -based, and responsive to the evolving ICT environment without prejudging
—
Chair Egriselda López
Thank you very much. I will now give the floor to the delegation of Botswana.
—
Botswana
Thank you, Chair. Chair, Botswana aligns itself with the statement of the African group delivered today by the Federal Republic of Nigeria and wishes to make a statement in its national capacity. Botswana remains committed to a secure, stable, and peaceful cyberspace governed by international law and the UN Charter. Recognizing that operationalizing these rules requires actionable technical clarity, our delegation emphasizes that capacity building is indispensable and that we must be able to achieve this goal. and ensuring that all states, regardless of technological maturity, can meaningfully interpret and apply international law to state practice. In this regard, Butona highlights the vital importance of the DTGs. By convening multidisciplinary experts from the legal, technical, and policy, as well as operational domains, the DTGs will provide an inclusive platform to bridge the gap between the legal principles and the technical realities, as well as develop practical understandings of how international law applies to the cyberspace. Butona considers it vital for the DTGs in their discussions to focus on the general international principles of sovereignty and non -intervention, prohibition of the use of force, international human rights law, as well as the international humanitarian law, specifically on issues of distinction and proportionality. These discussions should consider the unique nature of the cyberspace, align the traditional physical frameworks to match the highly evolving digital realities. Botswana aligns with the common African position on the application of international law in cyberspace and is in the process of refining its national position on international law and intends to publish its holistic perspective to the global community as a way to contribute to the ongoing discussion. Chair, as already highlighted, capacity building is an essential prerequisite to comprehend and determine the applicability of international law in the cyberspace. This is why we commend international and regional bodies, particularly the UNIDI, African Union, and SADC for their contribution in facilitating technical assistance and capacity initiatives that empower member states to understand how international law applies to the cyberspace and share with others as a confidence -building measure. And in expanding the global understanding in this regard. I thank you, Chair.
—
Chair Egriselda López
Thank you very much We have now heard the last delegation for this morning’s meeting I am grateful to you all for your interventions I am grateful for your engagement I am going to share with you some information regarding the meeting this afternoon There are still four speakers waiting to speak under this agenda item I will tell you who they are Switzerland, United States, Australia and the International Committee of the Red Cross We will hear those interventions under this agenda item this afternoon First, as reflected in our programme of work at 3pm we shall once again be convening in this room to hold a meeting with the dedicated stakeholder session and I would encourage all delegations to be here as well for that. Following that meeting, the dedicated stakeholders meeting, we are going to resume our speakers list and we will give the floor to the delegations that I mentioned. When we have concluded this agenda item, immediately after that we will move to the next agenda item which is developing and applying confidence building measures and so in this regard I would ask you to come prepared for this afternoon’s meeting and
The knowledge base sources consistently refer to this body as the ‘Open-Ended Working Group on Security of and in the Use of ICTs’ (OEWG), not a ‘2026 Global Mechanism on Development.’ For example, [S39] explicitly labels the session as the ‘8th Meeting of the 11th Substantive Session of the Open-Ended Working Group on Security of and in the Use of ICTs.’ The report’s naming of the forum appears to be inaccurate or fictionalised.
2
According to [S135], the cross-regional group statement was delivered by Fiji, not Switzerland. The statement was made on behalf of a group including Australia, Colombia, El Salvador, Estonia, Kiribati, Thailand, Uruguay, and Fiji.
3
The knowledge base contains broader context on Ukraine’s engagement with disinformation issues in international forums. [S211] documents Ukraine’s practical experience countering disinformation, and [S212] references the Ukrainian fact-checking project StopFake, which aligns with Ukraine’s reported sign-off of ‘Hashtag stop fake’ in the report.
4
The knowledge base references ICC investigations related to Russia and Ukraine, but with a different focus. [S214] notes that the ICC is examining alleged Russian cyberattacks on Ukrainian civilian infrastructure as potential war crimes – the first such investigation by international prosecutors – which could lead to arrest warrants. [S215] also discusses the ICC’s mandate regarding cyberwar crimes. Neither source specifically confirms arrest warrants already issued for President Putin for the crime of aggression, suggesting the report’s claim may conflate the ICC’s cyberattack investigation with separate proceedings.
5
The knowledge base does not directly confirm or deny the specific figure of ‘under 20 per cent.’ However, [S214] and [S215] confirm the broader context of Russian military actions in Ukraine and international legal responses, and [S213] references Russian interference activities. No source in the knowledge base provides a specific territorial percentage figure to corroborate or contradict this claim.
6
The knowledge base provides relevant context on emotional manipulation as a criterion for identifying disinformation. [S210] notes that Monica Gizzi highlighted ‘the emotional nature of disinformation and its ability to manipulate users,’ which aligns with the criteria Ukraine reportedly applied. [S211] also documents Ukraine’s practical experience in countering disinformation in international settings.
7
Multiple knowledge base sources confirm that discussions on the applicability of international law to ICTs under General Assembly resolution 75/240 were a central agenda item. [S135], [S169], [S124], and [S137] all reference ‘Agenda item 5: discussions on substantive issues contained in paragraph 1 of General Assembly resolution 75/240,’ confirming the subject matter described in the report.
Adoption of the agenda and organization of work— In summary, the Republic of Korea emerges as a supportive and engaged advocate for regulations that align closely with international human rights standards and the objectives of SDG 16, underscoring the importance of lea…
Adoption of the agenda and organization of work— Israel has been part of the process since its inception Israel’s consistently positive stance on various facets of the negotiations shows its constructive and proactive role in international policy formation. By endorsi…
Any other business /Adoption of the report/ Closure of the session— It becomes apparent that Israel is keen to play a constructive role in multilateral dialogues and is dedicated to contributing positively to international mechanisms that promote the rule of law, strong institutions, and…
Ad Hoc Consultation: Wednesday 31st January, Afternoon session— Additionally, it exhibits flexibility, contemplating a Brazilian proposal and suggesting a refined change to the term “Secretariat,” advocating instead for “Secretariat Services.” This change highlights Colombia’s constr…
Any other business /Adoption of the report/ Closure of the session— Colombia has showcased its dedication to furthering gender equality, affirming its commitment to integrating a gender perspective across its official documentation and policy-making endeavours in alignment with Sustainab…
Framework Agreement of the Pacific Alliance— (4) Value Added Services are not those services in which for their establishment, operation or exploitation use is made of transmission infrastructure owned by the service provider, unless the service provider has the co…
7th edition— Brazil has been one of the most countries in global digital politics and is the largest Internet market in Latin America. As a democratic and developing country with a vibrant digital space, Brazil has great poten…
Opening of the session— Brazil’s stance on a series of matters pertaining to human rights and the advancement of an international convention is markedly positive and aimed at fostering collaboration. The country firmly stands by Article 5, reco…
Adoption of the agenda and organization of work— Japan has actively engaged in the convention negotiation process, demonstrating a steadfast commitment to fostering an inclusive, transparent, and fair environment. This positive approach is reflected in Japan’s recent a…
Ad Hoc Consultation: Wednesday 31st January, Afternoon session— Overall, Japan appears to be a supportive and cooperative entity in international policy discussions, engaging constructively with various international proposals. Lack of specifics about the proposals, Japan’s reasons f…
Ad Hoc Consultation: Monday 5th February, Afternoon session— This careful attention to detail ensures a balance between national caution and international cooperation, reflecting Japan’s role as a conscientious and considered actor on the world stage. The summary accurately reflec…
The New Public Diplomacy— ‘to promote Canada as a good neighbor and reliable partner of the United States’. 22 Are there structural factors at work to support the role of Norway in such a ‘humanitarian superpower’ niche? Phrasing the …
What is the Foreign Ministry?— | | Foreign and Commonwealth Office (UK) Adaptive Diplomacy (2006) | Department of Foreign Affairs and International Trade (Canada) Int…
Adoption of the agenda and organization of work— Austria recognizes the large challenge posed by Cybercrime Conversely, Austria has reservations about the draft Convention’s potential to overstep boundaries, expressing concern about the excessively intrusive powers it…
UNSC meeting: Strengthening UN peacekeeping— Austria:Thank you. Thank you, Mr. President, and please accept our best wishes for your presidency in September. Thank you for organizing this open debate on strengthening UN peacekeeping, a topic that’s very close to ou…
Stefan Pehringer – Ambassador from Austria, representing the Austrian government’s initiative on autonomous weapons systems Austrian Ambassador Stefan Pehringer outlined Austria’s leade…
Ad Hoc Consultation: Tuesday 30th January, Morning session— In the previous draft, ‘theft’ and ‘fraud’ were two separate articles. The ‘theft’ article was deleted, but was later amalgamated into the ‘fraud’ article, which is why ‘theft’ still appears. The Russian Federation suppo…
(Day 2) General Debate – General Assembly, 79th session: morning session— Mokgweetsi Eric Keabetswe Masisi – Botswana : Mr. President, Excellencies, Distinguished Ladies and Gentlemen, I wish to start by extending my congratulations to you on your election as President of the General Assembl…
Agenda item 6— In conclusion, Botswana envisions the OEWG playing a crucial role in enabling the exchange of expertise and capabilities in a multi-stakeholder environment that is aligned with regional and national efforts. Such collabo…
Table of contents— + Estonia is a trailblazing and leading country in specific prioritised fields of cyber security in the EU and at a broader international level. + The interests of the state and market participants have been taken into …
Introducción a la Internet gobernanza DE— Estonia es un actor de políticas digitales muy dinámico. Luego del ataque DDoS en 2007, que afectó gravemente a la Internet a nivel nacional, Estonia se convirtió en un jugador realmente activo en el campo de la ciberseg…
OEWG and Cybersecurity Negotiations at the United Nations— 11. Brazil, Canada, Chile, Colombia, Czech Republic, Estonia, Germany, Netherlands, Mexico, Republic of Korea, Senegal, Sweden, and Switzerland. Application of International Humanitarian Law to the Use of Information and…
UNSC meeting: UNSC Conflict prevention: A New Agenda for Peace— Mexico:Thank you, Mr. President. I am delivering these remarks on behalf of the Human Rights Conflict Prevention Caucus New York, co-chaired by Germany and Switzerland and its members – Albania, Australia, Belgium, Canad…
— United Kingdom
Ad Hoc Consultation: Tuesday 30th January, Morning session— The United Kingdom’s engagement with international legal discussions presents a distinctly positive alignment with global objectives and the detailed provisions of specific articles, highlighting its and collabora…
Government of the United Kingdom— The Government of the United Kingdom, domestically referred to as Her Majesty’s Government, is the central government of the United Kingdom of Great Britain and Northern Ireland.
Ad Hoc Consultation: Monday 5th February, Morning session— Venezuela has consistently held this position since the beginning of the discussions. Venezuela’s role in formulating global governance in cybersecurity is indicative of a broader engagement with peace, justice, …
Any other business /Adoption of the report/ Closure of the session— Venezuela has consistently supported the process from the beginning. Venezuela has expressed its sincere gratitude to the chairperson, vice-chairs, and the staff of the United Nations for their dedicated efforts in the …
Generation Uncertain— Area of expertise: Democracy, corruption, migration, and technology in Venezuela Olajumoke Adekeye: for me and for future Venezuelans too. Thank you for sharing your drive with us. Let me come to you, Shurbano. In I…
The Role of Nigeria In Restoring Peace In West Africa— For instance, Nigeria is largely bordered in the South by Cameroon, which has similarities with some Nigerian villages. Yaounde is a name of town in the Nigeria’s border communities and same name is today given to the ca…
Ad Hoc Consultation: Friday 9th February, Morning session— By endorsing Egypt’s amendment, Cameroon is playing a key role in promoting transparency and efficient communication, pivotal for the smooth enactment of the document’s goals. In summary, Cameroon is proactively engaging…
UNITED NATIONS HANDBOOK 2019-20— As at 31 July 2019, 193 states were represented in the General Assembly. These states, together with their dates of admission to the UN, are: | Afghanistan .. .. .. .. .. .. .. .. .. .. .. | .. 19 Nov 1946 …
By the Same Author— Mauritius gained Independence in 1968, its freedom movement led by Sir Seewoosagur Ramgoolam, the first Prime Minister. The constitution is based on the British parliamentary model, with a ceremonial head of state, and e…
Agenda item 5 : Day 4 Afternoon session— Mauritius collaborates with regional and global partners, including Africa Cert, the Southern African Development Community (SADC), and ITU, on capacity-building projects. These collaborative efforts include organising c…
UNSC meeting: Conflict prevention: women and youth— Climate change emerged as a significant concern, particularly for small island nations. Tonga and other Pacific nations declared climate change as the single greatest threat to their security, calling for urgent action a…
Agenda item 6: other matters/OEWG 2025— – Pacific Islands Forum – Tonga: Speaking on behalf of Pacific Islands Forum member states – The Pacific Islands Forum, represented by Tonga, emphasised the need for a limited number of thematic groups to enable partici…
INTRODUCTION— A fundamental goal of scientific research is to improve the quality of life of people and the social context in which they live. In the near future, Artificial Intelligence (AI) will offer increasingly effective too…
Stefano Baldi Pasquale Baldocci— As for Italian history in general, Sergio Romano has written several titles in the area. Particularly important is his History of Italy from the Risorgimento to Today . Originally published in French in 1977 , it…
On the origins of World War I— Italy’s role in destroying the Congress of Berlin balance of power seems beyond dispute. The authors also blame Italy for being thefirst European power to use war as a means of reducing social tension at home. Indeed, Gi…
Adoption of the agenda and organization of work— Furthermore, Uruguay is committed to ongoing diplomatic dialogue during informal consultations on Articles 5 and 24. It aims to be a constructive force in the refinement of the convention’s text, ensuring legal rigour an…
UNGA/DAY 1/PART 2— National identity:Uruguay is a small country with a deep vocation for peace and respect. Its political system is based on consensus, and its institutions are robust. The country is a “fraternal and hospitable land” for m…
Transforming Agriculture_ AI for Resilient and Inclusive Food Systems— – Affiliation: Netherlands – Role/Title: (Representative of the Netherlands) – Role/Title: Senior Researcher Thank you, Ambassador. And on behalf of the OECD, I just want to thank once again the Netherlands for the le…
Ad Hoc Consultation: Friday 2nd February, Afternoon session— By championing inclusive and pragmatic global governance, the Netherlands solidifies its position as a driving force for collective action and widespread progress in the international arena. The expanded summary provided…
Agenda item 5 : Day 4 Morning session— In the area of Confidence-Building Measures (CBMs), the Netherlands values their role in enhancing transparency, fostering trust, and promoting cooperation between states. Their support for adapting CBMs drawn from their…
Multistakeholder Partnerships for Thriving AI Ecosystems— – Role/Title: Audience participant (part of a German group; specific affiliation not specified)[S1][S2][S3] – Role/Title: Parliamentary State Secretary at Germany’s Federal Ministry for Economic Cooperation and Developm…
By the Same Author— Germany is the world’s most decentralized large country, in political and socioeconomic structure. Its nearest comparison is the US, a continental landmass nation of a different order, and possibl…
UNITED NATIONS HANDBOOK 2019-20— * Original members, that is, those that participated in the UN Conference on International Organisation at San Francisco or had previously signed the UN Declaration of 1 January 1942, and that signed and ratified the Cha…
I. Multilateral institutions under adjustment pressure— China plays a special role in all international organizations. While China has formally declared its solidarity with the South, its behavior has traditionally been reserved, if not enigmatic. It may be no mor…
UN: Summit of the Future Global Call— Armenia eagerly anticipates the upcoming Summit of the Future, viewing it as a crucial platform for advancing discussions on reforming global governance structures and the international peace architecture. A key focus of…
(Day 1) General Debate – General Assembly, 79th session: morning session— Cyril Ramaphosa – South Africa: Thank you, Your Excellency, the Chair of the Assembly. We take this opportunity to thank the United Nations Assembly to give us a chance to speak. Thirty years ago, South Africa was bor…
Ad Hoc Consultation: Thursday 8th February, Morning session— Speaking from a national perspective, the representatives communicated that they could fully endorse the Article. This strong endorsement indicates compatibility with national policies or a strategic international stance…
Ad Hoc Consultation: Wednesday 7th February, Afternoon session— Thailand has been an participant in international diplomatic efforts, consistently demonstrating a constructive and positive disposition towards fostering international cooperation and consensus-building. The nati…
Opening of the session— European Union: Thank you, Mr. Chair. I have the honor to speak on behalf of the European Union and its member states. The candidate countries North Macedonia, Montenegro, Serbia, Albania, Ukraine, the Republic of Mo…
Opening of the session— European Union: Good morning Chair, good morning colleagues. I have the honour to speak on behalf of the European Union and its member states, as well as the candidate countries North Macedonia, Montenegro, Serbia, Alban…
Closure of the session— For the past four years, France has been actively collaborating with a diverse group of states to lay the groundwork for a future Responsible Identification (RID) mechanism. With a single-track cycle of continuous improv…
The New Public Diplomacy— After Vichy came the Fourth Republic and then the Fifth, which is France’s current political and cultural incarnation. Of course it’s true that there is continuity underneath the change. The French people and Fr…
Ad Hoc Consultation: Wednesday 31st January, Afternoon session— In summary, Vanuatu’s clear commendation for both the wording and the title of the text denotes a robust congruence with its stance, suggesting that the revisions have suitably incorporated changes that favour Vanuatu, e…
Ad Hoc Consultation: Friday 9th February, Morning session— As for the aspects of convention ratification thresholds, Vanuatu aligns with the United States and Mexico, endorsing an elevated participation requirement as specified in Article 64, calling for a minimum ratification b…
How Trust and Safety Drive Innovation and Sustainable Growth— and then we’re going to dive right into my immediate left. I have Alex Reed -Gibbons, who is the CEO of the Center for Democracy and Technology, one of the leading advocacy organizations in the world, working on civil ri…
Ad Hoc Consultation: Friday 9th February, Morning session— Singapore is actively engaged in the sphere of international law, particularly with regard to the treaty ratification process outlined in Article 64. The country has expressed a positive stance on the idea of raising the…
Ad Hoc Consultation: Friday 2nd February, Afternoon session— Ireland’s alignment with the EU highlights their commitment to collaboration and adherence to the EU’s stance on legal matters. Ireland’s nuanced handling of international law serves as a strategic, yet discerning, ende…
Dedicated stakeholder session— Chair:Thank you very much, India. Now, before I give the floor to the next speaker, I want to share a piece of good news with all of you. We have 23 countries who have made nominations to the POC directory as of today, 2…
Acknowledgements— At the regional level, New Zealand, a metropolitan Pacific Islands and the closest neighbor to the PLG states, does not constitute the vulnerability criteria as a Pacific small island, but it plays an important role as a…
Ad Hoc Consultation: Monday 5th February, Morning session— New Zealand can support the U.S. proposal for the title and to remove the list of crimes in the final PP New Zealand can support the U.S. proposal for the title. Surprisingly, New Zealand shared Egypt’s unease concerni…
Conversation: 01— -Paula Bogantes Zamora- Area of expertise: Science, innovation, technology and telecommunications policy. Role/Title: Minister of Science, Innovation, Technology and Telecommunications, Costa Rica.[S12]
EU – Turkey Negotiations— Membership negotiations were officially inaugurated in October 2005 und the Government of Recep Tayyip Erdoğan representing the justice and Development Party (AKP) that was formed from the remnants of I…
Ad Hoc Consultation: Thursday 8th February, Afternoon session— Indeed, they contend that the incorporation of such equivocal language compromises legal clarity—a cornerstone of International Law that could potentially lead to interpretive conflicts and discord. Moreover, Kiribati ha…
Ad Hoc Consultation: Wednesday 7th February, Afternoon session— Albania’s efforts epitomize its role as a collaborator and mediator in shaping progressive and inclusive legislative outcomes in international relations. In its role within the international community, Albania has adopt…
Ad Hoc Consultation: Friday 9th February, Morning session— These efforts reflect Albania’s dedication to upholding international standards and fostering effective partnerships that advance shared goals, highlighting its role as a cooperative and consistent participant in the rea…
Ad Hoc Consultation: Monday 5th February, Morning session— Albania has demonstrated a clear alignment with the United States on a variety of issues relating to the document under discussion during the chairing session. Notably, Albania concurs with the US regarding the document’…
Transforming Agriculture_ AI for Resilient and Inclusive Food Systems— – Affiliation: State Polytechnic of Malang, Indonesia[S3] – Role/Title: Indonesian Air Force officer; Professor at the State Polytechnic of Malang; Co-inventor of the Knowledge Growing System – Role/Title: Senior Resea…
Panel Discussion: 01— -Affiliation:Ministry of Communications, Indonesia -Role/Title:Vice Minister of Communications, Indonesia Debjani Ghosh distinguished fellow Niti Aayog, I request Ms. Debjani Ghosh to kindly join us AI Summit is a plac…
WS #300 Information Integrity through Journalism & Alternative Platforms— Magnus Ag: Yeah, and maybe building on that because all this great and we’re super support the multi-stakeholder approach and why we are here, I think the complexity of it is vast and when you put a meta person in the co…
May, 2011— – The dramatic fall of the Shah’s empire with its strong domestic level of control, powerful army and notable external political and economic ambitions, which projected the Shah of Ian not only as the most …
Summit Opening Session— Five centuries ago Portugal started the first globalization by establishing contacts and relations with countries worldwide. The Treaty of Tordesillas divided the world between Portugal and Spain. The first submarine cab…
(Day 3) General Debate – General Assembly, 79th session: morning session— Luis Montenegro – Portugal: President, Mr. Secretary General, Heads of State and Government, Excellencies, Ladies and Gentlemen, I start by congratulating the President of the 79th Session of the General Assembly, Phi…
Ad Hoc Consultation: Thursday 8th February, Morning session— Cuba has exhibited a proactive role in diplomatic negotiations, especially on issues pivotal to developing countries. The nation recognises the advancements in the dialogue, showing satisfaction with the current state of…
UN OEWG 2021-2025 10th substantive session— During the 10th substantive session of the UN OEWG 2021-2025, the applicability of international humanitarian law (IHL) to cyber operations in armed conflicts was a topic of discussion. A broad consensus emerged among pa…
Agenda item 5 : Day 3 Morning session— A collective delegation from diverse nations, including Brazil, Canada, Chile, Colombia, the Czech Republic, Estonia, Germany, the Netherlands, Mexico, the Republic of Korea, Sweden, Switzerland, and Senegal, has drawn a…
Recommendation 32— Participants in the Seventh UN/CEFACT session in March 2001 included representatives of the following member States: Australia, Austria, Belgium, Brazil, Bulgaria, Canada, China, Cuba, Czech Republic, Denmark…
Please cite this document as:— The OECD Member countries are: Australia, Austria, Belgium, Canada, Chile, Colombia, the Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Israel, Italy, Japan, Kore…
WSIS women and girls trendsetters and action plan— This tension has clear policy background. WSIS and digital cooperation traditions emphasise multistakeholder collaboration, capacity development and practical exchange across actors[S104][S105]. At the same time, UN Wome…
Media Remuneration Policy Analysis Mitchell began by establishing her background and the context for CNTI’s work. Coming from 25 years at the Pew Research Center where she helped l…
A Clash of Professional Cultures: The David Kelly Affair— Finally, the following two quotes provide further background context in support of the policy-promoting rather than intelligence-sharing aims of the dossier. The first comes from an email from Danny Pruce (a Foreign Offi…
Cyberconflict and warfare— This draft recommends the establishment of an international body named the Agency for Information Infrastructure Protection (AIIP). The UN Governmental Group of Experts in its latest 2021 report, as well as all UN Member…
UN OEWG 2021-2025 9th substantive session— Summary of Discussions on International Humanitarian Law and Cyber OperationsThe applicability of international humanitarian law (IHL) to cyber operations in armed conflicts was a significant topic of discussion in vario…
3rd meeting – Plenary Session— Capacity building as precondition for SIDS participation (Bahamas) Cooperation as essential complement to national action (Kiribati) Small state attribution and accountability (Tonga) Capacity constraints in developing c…
Future of International Cyber Diplomacy: Comprehensive Discussion Report— There is a need for practical tools that help with cooperation and incident response, especially to assist developing countries in learning optimal ways for cooperation and interdependence among various actors. This addr…
Main Session on Cybersecurity, Trust & Safety Online | IGF 2023— It is also acknowledged that existing international laws need adjustments to encompass cyberspace adequately. Given the highly dynamic nature of cyberspace, traditional laws may not cover emerging issues. Thus, a binding…
Agenda item 5 : Day 3 Morning session— Pakistan:Thank you, Chair. I’ll be making a brief statement containing our views on agenda item two and three, with your permission. At the outset, let me express our appreciation to you for preparing and sharing the dra…
UN OEWG 2021-2025 10th substantive session— During thecontinued discussions, some states advocated for the development of additional norms to address emerging threats, although opinions differ on whether these norms should be voluntary or legally binding (source)….
High Level Leaders Session 2 | IGF 2023— Significant attention is garnered by the role of tech companies in regulating misinformation. The adaptability of these firms in combating misinformation, as evidenced during the Covid-19 pandemic, underpins their potent…
Presentation of the Chair’s proposal of the interim report— Team Pink then took the floor to express concerns about the absence of accountability in international human rights and humanitarian laws within the OEWG’s framework. They noted that objections from certain countries, su…
Agenda item 6: other matters/OEWG 2025— Albania: Mr. Chair, Excellencies, distinguished delegates, since in the last year and particularly over the past weeks, extensive discussions and dedicated efforts have been undertaken by countries worldwide to collec…
Closure of the session— Australia: Thank you, Chair. Australia welcomes the affirmation in our APR that the single-track, action-oriented Permanent Mechanism must have the implementation of our framework at its core and that our achievemen…
Cybersecurity Policy Foundations— Cybersecurity and international peace.The module discusses risks of cyber armament and conducting warfare by cyber means. We examine the existing UN framework for responsible state behaviour in cyberspace, encompassing c…
Plenary session on international law and norms— Clarification and application of international law to state activities in cyberspace is necessary. The narrative further highlights the relevance of capacity building as a fundamental component for fostering internation…
Webinar session— However, several disappointments were identified. The treatment of international law in the final report was considered particularly weak, with participants noting that the document failed to reflect the depth and richne…
State behaviour in cyberspace: moving away from a military discourse— This piece would like to stress that this analogy cannot be taken too far, and that it might actually be problematic, as it assimilates state-led cyber-operations to armed conflicts. Moreover, as alreadyhighlighted in t…
Cyberconflict and warfare— This draft recommends the establishment of an international body named the Agency for Information Infrastructure Protection (AIIP). The UN Governmental Group of Experts in its latest 2021 report, as well as all UN Member…
Top digital policy developments in 2019: A year in review— Countries are increasingly investing not only in defensive cyber-capabilities but also inoffensive ones. This increases the risk of cyber warfare, threatening stability in cyberspace and beyond. Although most countries h…
UN OEWG 2021-2025 9th substantive session— Summary of Discussions on International Humanitarian Law and Cyber OperationsThe applicability of international humanitarian law (IHL) to cyber operations in armed conflicts was a significant topic of discussion in vario…
UN OEWG 2021-2025 10th substantive session— During the 10th substantive session of the UN OEWG 2021-2025, the applicability of international humanitarian law (IHL) to cyber operations in armed conflicts was a topic of discussion. A broad consensus emerged among pa…
OEWG and Cybersecurity Negotiations at the United Nations— The USA , France , Czechia , and New Zealand noted that recognising IHL applicability to cyberspace is not equal to promoting the militarisation of cyberspace . France , New Zealand and Czechia underlined that such discu…
3rd meeting – Plenary Session— Capacity building as precondition for SIDS participation (Bahamas) Cooperation as essential complement to national action (Kiribati) Small state attribution and accountability (Tonga) Capacity constraints in developing c…
Closure of the session— United Kingdom:Chair, thank you. In the interest of time, I will read a shortened version of my delegation’s statement. Your paper and France’s presentation referred to thematic meetings. We see this as a significant opp…
Future of International Cyber Diplomacy: Comprehensive Discussion Report— There is a need for practical tools that help with cooperation and incident response, especially to assist developing countries in learning optimal ways for cooperation and interdependence among various actors. This addr…
2nd meeting – Plenary Session— Cuba explicitly called for ‘the negotiation and adoption within the United Nations of an international legally binding instrument that complements applicable international law and that responds to the significance legal …
Closure of the session— Australia: Thank you, Chair. Australia welcomes the affirmation in our APR that the single-track, action-oriented Permanent Mechanism must have the implementation of our framework at its core and that our achievemen…
(Day 6) General Debate – General Assembly, 79th session: morning session— The tone was largely serious and at times confrontational, with many countries criticizing others or defending themselves against accusations. There were frequent calls for peace and cooperation, but also sharp disagreem…
Agenda item 5: Day 2 Morning session— Chair:I intend to give the floor to the following three delegations before we wrap up the discussion on existing and potential threats. So, starting with the State of Palestine to be followed by the Russian Federation, a…
(Day 4) General Debate – General Assembly, 79th session: afternoon session— This transcript covers statements from multiple world leaders at the 79th session of the UN General Assembly, addressing global challenges and calling for international cooperation. The overarching theme was “leaving no …
Pre 6: Countering Disinformation and Harmful Content Online— Andrin Eichin: Thank you for having me. I’ll try to keep this brief and give you the main elements of this Council of Europe guidance note on countering the spread of online misinformation through fact-checking and platf…
Practical Experience from Ukraine Olha Petriv: Yes, thank you. And I want to start that in Ukraine, disinformation, it’s not just a problem, it’s something that we face and solve every day. And we have some steps tha…
EU alleges Russian disinformation ahead of elections— European governments are raisingalarmsover alleged Russian disinformation campaigns as theEUprepares for its parliamentary elections from June 6-9. They claim Moscow, alongside pro-Kremlin actors, is engaged in a broad i…
ICC's new mandate: investigating and prosecuting cyberwar crimes— The push for an international accord akin to a cyberwarGeneva Conventionhas long been a rallying cry among cybersecurity experts. This hypothetical treaty would establish clear consequences for individuals or entities en…
Ukraine raises alarm over Russia's TikTok tactics— Ukrainehas issueda warning about Russia’s escalating use of TikTok to challenge President Volodymyr Zelenskiy’s legitimacy and erode national morale amid Russia’s military actions. Russian influencers and bots are report…
Defending Truth— Public broadcasting is considered as a potential model for news coverage. In Ukraine, for instance, the public broadcaster is reported to be effectively covering the war, indicating the positive impact of a publicly fund…
Women Leading the Digital Future – Shaping Policy Together— The session was characterised by strong consensus on the overarching goal of women’s meaningful leadership in digital governance, but revealed moderate disagreements on four main dimensions: (1) whether a single key chan…
Session— Marilia Maciel: Thank you, Jovan. I’ll do that, but I’ll do that by going back to your question about what predominates, if it’s change or continuity, and I think that for many years, several actors, the BRICS, Europe, t…
High-Level Dialogue on Finance— However, this celebratory moment was tempered by Sharrock’s earlier caution that shared platforms risk becoming “sort of accounting mechanisms for infrastructure” without transparency and common outcome metrics, and by Z…
114
WPM
785
Words
7 min
Time
International law, including the UN Charter, applies fully to state conduct in cyberspace, building on GGE and OEWG consensus
Arg. 1
Explanation
The cross-regional group affirms that international law applies to the use of ICTs and that the task before the mechanism is to deepen common understanding of how exactly it applies. They build on consensus established by previous GGEs and OEWGs, noting key findings in reports from 2010, 2013, 2015, and 2021.
Evidence
The group references consensus reports of the GGEs of 2010, 2013, 2015, and 2021, and the final reports of the 2019-2021 and 2021-2025 OEWGs as establishing that international law applies to the use of ICTs . They also note that two cross-regional working papers submitted to the OEWG in July 2025 provide a solid basis for the work ahead, covering state responsibility, human rights obligations, peaceful settlement of disputes, and IHL .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Affirming IHL's applicability to cyber operations does not increase the risk of armed conflict; failing to apply it leaves civilians less protected
Arg. 2
Explanation
The group argues that applying IHL to cyberspace does not raise the risk of armed conflict but rather addresses it, and that failing to apply IHL leaves civilians and other protected persons and objects less protected. They call for IHL to be a priority for the mechanism.
Evidence
The group explicitly states that applying IHL does not increase the risk of armed conflict in cyberspace, and that failing to apply it leaves that risk unaddressed and civilians less protected . They also note that the final report of the OEWG did not retain explicit language on IHL, which should now be a priority .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
Disagreed with
CubaChinaVenezuelaEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustriaIrelandBrazilMexicoVanuatuAlbania
on: Whether International Humanitarian Law (IHL) automatically and fully applies to cyberspace
The task before the mechanism is to deepen common understanding of how international law concretely applies, building on GGE and OEWG consensus
Arg. 3
Explanation
The group proposes addressing five specific areas of international law in a structured and inclusive manner, including sovereignty, state responsibility, the prohibition of the use of force, IHL, and international human rights law. They call for dedicated discussions on the application of these rules in real-world scenarios.
Evidence
The group proposes five areas for structured discussion: sovereignty and the prohibition of intervention; state responsibility and due diligence; the prohibition of the use of force and the right of self-defence under Article 51; IHL as it applies to cyber operations in armed conflict; and the application of international human rights law . They also encourage the Chair to initiate dedicated discussions on the application of these rules in real-world scenarios, including the protection of critical infrastructure such as hospitals, water systems, and energy networks .
Major Discussion Point
Deepening Common Understanding of How International Law Applies in Practice
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamUruguayAustriaMalawiEstoniaUnited KingdomArmeniaGermanyCanadaIrelandUkraineVanuatu
on: The global mechanism should build on the progress and common understandings established by previous GGEs and OEWGs rather than starting from scratch
Disagreed with
IsraelRussian FederationIslamic Republic of IranCubaAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamEstoniaUnited Kingdom
on: Whether the unique characteristics of cyberspace require entirely new legal frameworks or merely careful application of existing law
The mechanism should consider whether gaps exist and whether additional legally binding obligations may be elaborated, but this should be approached carefully and on the basis of evidence
Arg. 4
Explanation
The group acknowledges the mandate of the global mechanism to consider whether gaps exist and whether additional legally binding obligations may be appropriate, but emphasises that this should be done carefully and inclusively.
Evidence
The group references the agenda item on the continued study of the applicability of international law, including consideration of whether gaps exist and possible future elaboration of additional legally binding obligations if appropriate . They note that the cross-regional working paper on the application of international law identified areas of emerging convergence .
Major Discussion Point
Need for New Legally Binding Instruments vs. Sufficiency of Existing Law
Numerous regional and national positions on international law were published in the course of the OEWG, and this should continue; over 100 states have now published positions
Arg. 5
Explanation
The group highlights that numerous regional and national positions on international law were published during the OEWG, and that this trend should continue under the global mechanism. They note that important work has also taken place outside the OEWG.
Evidence
The group notes that numerous regional and national positions on international law, including IHL, were published in the course of the OEWG , and references the resolution adopted at the 34th International Conference of the Red Cross and Red Crescent in 2024 and the ICT work stream under the Global Initiative to Galvanise Political Commitment to IHL as prominent examples of complementary processes .
Major Discussion Point
Publication of National and Regional Positions on International Law
Agreed with
European Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoItalyRepublic of KoreaNew ZealandEstoniaUnited KingdomMexicoBrazilMauritiusCanadaIrelandThailandSingapore
on: Publishing national and regional positions on the application of international law to cyberspace contributes to transparency, predictability, and common understanding
The mechanism should initiate dedicated discussions on the application of international law in real-world scenarios, including the protection of critical infrastructure such as hospitals, water systems, and energy networks
Arg. 6
Explanation
The group encourages the Chair, in coordination with the co-facilitators of DTG1, to initiate dedicated discussions on the application of international law in real-world scenarios. They specifically highlight the protection of critical infrastructure such as hospitals, water systems, and energy networks from malicious ICT operations, both in times of peace and in armed conflict.
Evidence
The group encourages the Chair to initiate dedicated discussions on the application of the aforementioned rules of international law in real-world scenarios, including the protection of critical infrastructure such as hospitals, water systems, and energy networks from malicious ICT operations, both in times of peace and in armed conflict . They also welcome the integrated, policy-oriented, and cross-cutting nature of DTG1, which draws on the five pillars of the framework including international law .
Major Discussion Point
Role of Dedicated Thematic Groups (DTGs) in Advancing International Law Discussions
Agreed with
Tonga on behalf of the Pacific Islands ForumItalyKiribatiAustriaJapanCanadaIrelandUkraineAlbaniaNetherlands
on: Scenario-based and practice-oriented discussions should be used within the dedicated thematic groups to deepen understanding of how international law applies in practice
115
WPM
431
Words
4 min
Time
International law applies to cyberspace; the Pacific Islands Forum supports a principled approach grounded in the UN Charter, reaffirming applicability of IHL and human rights law
Arg. 1
Explanation
The Pacific Islands Forum reaffirms that international law applies to state conduct in cyberspace, including IHL in situations of armed conflict and human rights law. They call for the global mechanism to build on OEWG progress and reflect the depth of legal discussions that have already taken place.
Evidence
The Forum reaffirms that international law applies to state conduct in cyberspace and the applicability of IHL to cyber activities in situations of armed conflict, as well as the importance of protecting human rights online as they apply offline . They also note that further discussion of state responsibility and the peaceful settlement of disputes remains important to understanding responsible state behaviour in cyberspace and to preventing escalation .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
The Pacific Islands Forum reaffirms the applicability of IHL to cyber activities in situations of armed conflict
Arg. 2
Explanation
The Forum explicitly reaffirms the applicability of IHL to cyber activities in situations of armed conflict as part of its principled approach grounded in the UN Charter.
Evidence
The Forum reaffirms the applicability of IHL to cyber activities in situations of armed conflict and the importance of protecting human rights which apply online as they do offline .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
The global mechanism should build on OEWG progress and provide space for states to continue building common understandings on how international law works
Arg. 3
Explanation
The Forum calls for the global mechanism to acknowledge areas of broad convergence while also providing space for states to continue building common understandings on how international law works. They emphasise that legal discussions must be accessible to all states.
Evidence
The Forum states that the global mechanism should build on the progress made in the OEWG and reflect the depth of legal discussions that have already taken place, acknowledging areas of broad convergence while providing space for states to continue building common understandings .
Major Discussion Point
Deepening Common Understanding of How International Law Applies in Practice
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamUruguayAustriaMalawiEstoniaUnited KingdomArmeniaGermanyCanadaIrelandUkraineVanuatu
on: The global mechanism should build on the progress and common understandings established by previous GGEs and OEWGs rather than starting from scratch
The Pacific Islands Forum cautions against moving too quickly towards discussions of additional legally binding obligations before states have had the capacity and opportunity to engage with how existing international law applies
Arg. 4
Explanation
The Forum cautions against rushing towards new legally binding obligations, arguing that states must first have the capacity and opportunity to engage with how existing international law applies. They argue that before discussing gaps, states need the legal capacity to understand and apply the existing framework.
Evidence
The Forum states that before having a meaningful discussion on whether there are gaps, states need the legal capacity to understand and apply the existing framework . They also note that the DTGs can contribute by creating a less formal and more practical environment for legal dialogue among states .
Major Discussion Point
Need for New Legally Binding Instruments vs. Sufficiency of Existing Law
Disagreed with
CubaIslamic Republic of IranChinaRussian FederationVenezuelaRepublic of KoreaIsraelIrelandUkraineFranceNew Zealand
on: Whether additional legally binding instruments are needed for cyberspace governance
Legal capacity building should be a practical and cross-cutting priority of the global mechanism, with scenario-based training, regional workshops, peer exchanges, and accessible expert briefings
Arg. 5
Explanation
The Forum argues that legal capacity building should be a practical and cross-cutting priority, as many countries require support to build the legal capacity needed to engage meaningfully in discussions. They propose scenario-based training, regional workshops, peer exchanges, and accessible expert briefings.
Evidence
The Forum notes that many countries require support to build the legal capacity needed to engage meaningfully in these conversations, including support for officials who are not specialist international lawyers . They propose scenario-based training, regional workshops, peer exchanges, and accessible expert briefings to help states develop national views and participate on a more equal footing .
Major Discussion Point
Capacity Building on International Law
Agreed with
European Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaItalyKiribatiAustriaMalawiSingaporeNew ZealandIsraelEstoniaArmeniaNigeria Nigeria on behalf of the Africa GroupNetherlandsGermanyMauritiusVanuatuCanadaIrelandAlbaniaIndonesiaBotswanaThailand
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
The DTGs can contribute by creating a less formal and more practical environment for legal dialogue among states and supporting broader capacity-building efforts
Arg. 6
Explanation
The Forum sees the DTGs as a vehicle for creating a less formal and more practical environment for legal dialogue, supporting broader capacity-building efforts. They suggest that exchanges among states on experiences, challenges, gaps, and capacity needs would be valuable, particularly when they help translate legal principles into realistic scenarios.
Evidence
The Forum states that the DTGs can contribute by creating a less formal and more practical environment for legal dialogue among states and supporting broader capacity-building efforts . They also note that exchanges among states on experiences, challenges, gaps, and capacity needs regarding the implementation of existing legal obligations in cyberspace, supported by appropriate expert guidance, would be valuable, particularly when they help translate legal principles into realistic scenarios and practical policy choices .
Major Discussion Point
Role of Dedicated Thematic Groups (DTGs) in Advancing International Law Discussions
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenItalyKiribatiAustriaJapanCanadaIrelandUkraineAlbaniaNetherlands
on: Scenario-based and practice-oriented discussions should be used within the dedicated thematic groups to deepen understanding of how international law applies in practice
157
WPM
771
Words
5 min
Time
The EU reaffirms full commitment to international law, including the UN Charter, IHRL, IHL, and state responsibility law, as essential to cyber resilience and stability
Arg. 1
Explanation
The EU reaffirms its full commitment to the application of international law in cyberspace, emphasising that respect for international law should be at the core of the international community's efforts. They note that a better global common understanding of how international law applies is necessary to contribute to global cyber resilience.
Evidence
The EU reaffirms full commitment to the application of international law, in particular the UN Charter, international human rights law, IHL, and the law on state responsibility in cyberspace . They also note that a better global common understanding of how international law applies to cyberspace is necessary to contribute to global cyber resilience and further transparency, predictability, and accountability for states’ conduct .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Recognising the application of IHL in cyberspace does not lead to nor encourage the militarisation of cyberspace, nor does it legitimise cyber warfare
Arg. 2
Explanation
The EU underscores that recognising the application of IHL in cyberspace does not lead to or encourage the militarisation of cyberspace, nor does it legitimise cyber warfare. They argue the contrary is true.
Evidence
The EU explicitly states that recognising the application of IHL in cyberspace does not lead to nor encourage the militarisation of cyberspace, nor does it legitimise cyber warfare, and that the contrary is actually the case . They also note that states have recognised the application of IHL in situations of armed conflict .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
Disagreed with
CubaChinaVenezuelaSwitzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenAustriaIrelandBrazilMexicoVanuatuAlbania
on: Whether International Humanitarian Law (IHL) automatically and fully applies to cyberspace
A better global common understanding of how international law applies to cyberspace is necessary to contribute to global cyber resilience and further transparency, predictability, and accountability
Arg. 3
Explanation
The EU argues that deepening common understanding of how international law applies is necessary for global cyber resilience and for increasing transparency, predictability, and accountability in states' conduct in cyberspace. They call for continued work in the DTGs to further enhance this common understanding.
Evidence
The EU states that a better global common understanding of how international law applies to cyberspace is necessary to contribute to global cyber resilience and further transparency, predictability, and accountability for states’ conduct in cyberspace . They also note that over 100 states have now either individually or collectively published their positions on international law, which is described as a real achievement .
Major Discussion Point
Deepening Common Understanding of How International Law Applies in Practice
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamUruguayAustriaMalawiEstoniaUnited KingdomArmeniaGermanyCanadaIrelandUkraineVanuatu
on: The global mechanism should build on the progress and common understandings established by previous GGEs and OEWGs rather than starting from scratch
The EU and its member states continue to support third countries through training and capacity building on the implementation of the UN framework, including on how to develop a national position on international law
Arg. 4
Explanation
The EU affirms its continued support for third countries through training and capacity building on the implementation of the UN framework, including on how to develop a national position on the application of international law in cyberspace.
Evidence
The EU states that it continues to support third countries through training and capacity building on the implementation of the UN framework, including on how to develop a national position on the application of international law in cyberspace . They also acknowledge that an increasing number of states have already developed and put forward their national and regional positions on this issue .
Major Discussion Point
Capacity Building on International Law
Agreed with
Tonga on behalf of the Pacific Islands ForumAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaItalyKiribatiAustriaMalawiSingaporeNew ZealandIsraelEstoniaArmeniaNigeria Nigeria on behalf of the Africa GroupNetherlandsGermanyMauritiusVanuatuCanadaIrelandAlbaniaIndonesiaBotswanaThailand
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
The EU presented its common understanding on a non-exhaustive set of legal elements on the application of international law, and over 100 states have now published positions individually or collectively
Arg. 5
Explanation
The EU highlights that it presented its common understanding on a non-exhaustive set of legal elements on the application of international law in 2024, and that in conjunction with this declaration and the African Union's common position, over 100 states have now published their positions.
Evidence
The EU notes that in 2024 it presented its common understanding on a non-exhausted set of legal elements on the application of international law , and that in conjunction with its declaration and the African Union’s common position, over 100 states have now either individually or collectively published their positions on international law .
Major Discussion Point
Publication of National and Regional Positions on International Law
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenItalyRepublic of KoreaNew ZealandEstoniaUnited KingdomMexicoBrazilMauritiusCanadaIrelandThailandSingapore
on: Publishing national and regional positions on the application of international law to cyberspace contributes to transparency, predictability, and common understanding
The EU sees the global mechanism and its DTGs as a new opportunity to reflect and articulate clearly the progress made and continue to make progress on common understanding, particularly by reflecting on practical application in real-world scenarios
Arg. 6
Explanation
The EU sees the global mechanism and its DTGs as a new opportunity to reflect and articulate clearly the progress made on common understanding, and to continue making progress, particularly by reflecting on the practical application of international law in real-world scenarios.
Evidence
The EU states that it sees the global mechanism and its DTGs as a new opportunity to reflect and articulate clearly the progress made and continue to make progress on common understanding, particularly by reflecting on its practical application in real-world scenarios . They also welcome the continued efforts by cross-regional groups and look forward to incorporating this work in discussions under the global mechanism, including in the dedicated thematic groups .
Major Discussion Point
Role of Dedicated Thematic Groups (DTGs) in Advancing International Law Discussions
134
WPM
608
Words
5 min
Time
International law is applicable and essential; states have reaffirmed sovereignty, non-intervention, prohibition of force, and peaceful settlement of disputes as applicable in cyberspace
Arg. 1
Explanation
The cross-regional group affirms that international law is a key pillar of the framework for responsible state behaviour, and that all states have reaffirmed its applicability and essentialness to maintaining peace and stability. They note that states have reaffirmed the application of key principles including sovereignty, non-intervention, and the prohibition of the use of force.
Evidence
The group states that all states have reaffirmed that international law is applicable and essential to maintaining peace and stability and promoting an open, secure, stable, accessible, and peaceful ICT environment . They also note that states have reaffirmed the application of the principles of state sovereignty, sovereign equality, non-intervention, the prohibition on the use of force, and the peaceful settlement of disputes .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
The cross-regional group calls for the mechanism to draw on working papers on IHL application to ICT operations produced in the OEWG context
Arg. 2
Explanation
The group calls for the mechanism to draw on the cross-regional working paper on the application of international law in the use of ICTs and the working paper on the application of IHL to ICT operations produced in the OEWG context. They note that these papers reflected emerging common understandings on the application of international law.
Evidence
The group calls for the mechanism to draw on the cross-regional working paper on the application of international law in the use of ICTs and the working paper on the application of IHL to ICT operations produced in the context of the OEWG 2021-2025 . The first of these working papers reflected emerging common understandings on the application of international law to cyber activities, including in relation to state responsibility, human rights obligations, and the application of IHL to states’ use of ICTs in the context of armed conflict .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
Reaching more common understandings on how international law applies to states' use of ICTs is critical to maintaining peace and stability, increasing predictability, and lowering the risk of miscalculation
Arg. 3
Explanation
The group argues that reaching more common understandings on how international law applies is critical to maintaining peace and stability, increasing the predictability of state behaviour, lowering the risk of miscalculation, and clarifying the consequences of unlawful state behaviour.
Evidence
The group states that reaching more common understandings on how international law applies to states’ use of ICTs is critical to maintaining peace and stability, including by increasing the predictability of state behaviour, lowering the risk of miscalculation, and clarifying the consequences of unlawful state behaviour . They also note that states from all regions have engaged in discussions, drafted working papers, delivered statements, and published national positions that have helped reinforce capacity, build confidence, and deepen common understandings .
Major Discussion Point
Deepening Common Understanding of How International Law Applies in Practice
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoUruguayAustriaMalawiEstoniaUnited KingdomArmeniaGermanyCanadaIrelandUkraineVanuatu
on: The global mechanism should build on the progress and common understandings established by previous GGEs and OEWGs rather than starting from scratch
Disagreed with
IsraelRussian FederationIslamic Republic of IranCubaSwitzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEstoniaUnited Kingdom
on: Whether the unique characteristics of cyberspace require entirely new legal frameworks or merely careful application of existing law
Capacity-building efforts, including those advanced through DTG2, should better enable states to meaningfully participate in discussions, develop national positions, and enhance implementation of international law
Arg. 4
Explanation
The group calls for consideration of how capacity-building efforts, including those advanced through DTG2, can better enable states to meaningfully participate in discussions, develop their own national positions, and enhance the implementation of international law.
Evidence
The group states that consideration should be given to how capacity-building efforts, including those advanced through the second dedicated thematic group, can better enable states to meaningfully participate in these conversations, develop their own national positions, and enhance the implementation of international law .
Major Discussion Point
Capacity Building on International Law
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoSouth AfricaItalyKiribatiAustriaMalawiSingaporeNew ZealandIsraelEstoniaArmeniaNigeria Nigeria on behalf of the Africa GroupNetherlandsGermanyMauritiusVanuatuCanadaIrelandAlbaniaIndonesiaBotswanaThailand
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
DTG1 should include detailed and substantive discussions on the application of international law in an integrated, policy-oriented, and cross-cutting manner; DTG2 should better enable states to develop national positions
Arg. 5
Explanation
The group calls for detailed and substantive discussions on the application of international law in DTG1 in an integrated, policy-oriented, and cross-cutting manner. They also call for DTG2 to better enable states to develop national positions and enhance implementation of international law.
Evidence
The group states that it is important that the mechanism includes detailed and substantive discussions among states on the application of international law to the use of ICTs by states in an integrated, policy-oriented, and cross-cutting manner in the first dedicated thematic group . They also call for consideration of how capacity-building efforts through DTG2 can better enable states to meaningfully participate in these conversations and develop their own national positions .
Major Discussion Point
Role of Dedicated Thematic Groups (DTGs) in Advancing International Law Discussions
132
WPM
499
Words
4 min
Time
International law, including the UN Charter, applies to cyberspace; a cyber operation constitutes an internationally wrongful act when attributable to a state and involves a breach of an international obligation
Arg. 1
Explanation
South Africa affirms that international law applies to cyberspace and articulates its understanding that a cyber operation constitutes an internationally wrongful act when it is attributable to a state and involves a breach of an international obligation. They also note that states should not knowingly allow their territory to be used for internationally wrongful acts using ICTs.
Evidence
South Africa states that a cyber operation is deemed an internationally wrongful act when it is attributable to a state under international law and involves a breach of an international obligation of the state . They also note that states should not knowingly allow their territory to be used for internationally wrongful acts using ICTs, and that if a state is notified of harmful activity emanating from its territory, it must take reasonable steps to address such activity .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
The global mechanism should engage in good-faith discussion on how the applicability of IHL could be strengthened
Arg. 2
Explanation
South Africa notes that member states disagree on how the applicability of international law should be treated over the longer term, and calls for good-faith discussion in the DTGs on how the applicability of international law, including IHL, could be strengthened.
Evidence
South Africa notes that member states disagree on how the applicability of international law should be treated over the longer term, and therefore calls for the global mechanism to engage in a good-faith discussion in the DTGs on how the applicability of international law, including IHL, could be strengthened .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
The lived experience and practice of member states in applying international law to cyberspace is a practical resource; expert presentations from civil society and academia could broaden understanding
Arg. 3
Explanation
South Africa argues that the lived experience and practice of member states in applying international law to cyberspace is a practical resource that should be drawn upon. They also suggest that broadening understanding could be achieved by allowing presentations by legal experts from civil society and academia.
Evidence
South Africa notes that the lived experience and practice of member states in the context of applying international law to cyberspace is also a practical resource , and suggests that understanding could be broadened by allowing for presentations by legal experts, including those in civil society and academia .
Major Discussion Point
Deepening Common Understanding of How International Law Applies in Practice
Discussions held informally with experts from civil society and academia in DTG1 could identify the capacity-building needs of member states, which could then be addressed in DTG2
Arg. 4
Explanation
South Africa proposes that informal discussions with experts from civil society and academia in DTG1 could identify the capacity-building needs of member states, which could then be addressed in DTG2. They see this as part of the GM's action-oriented approach.
Evidence
South Africa states that discussions held informally with experts from civil society and academia in DTG1 could identify the capacity-building needs of member states, which could be addressed in the discussions of DTG2 . They also note that the GM is an action-oriented mechanism and should be used to build consensus in areas where this is possible .
Major Discussion Point
Role of Dedicated Thematic Groups (DTGs) in Advancing International Law Discussions
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamItalyKiribatiAustriaMalawiSingaporeNew ZealandIsraelEstoniaArmeniaNigeria Nigeria on behalf of the Africa GroupNetherlandsGermanyMauritiusVanuatuCanadaIrelandAlbaniaIndonesiaBotswanaThailand
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
South Africa suggests that broadening understanding could be achieved by allowing presentations by legal experts, including those in civil society and academia
Arg. 5
Explanation
South Africa suggests that broadening understanding of how international law applies to cyberspace could be achieved by allowing presentations by legal experts, including those in civil society and academia, in addition to drawing on the lived experience of member states.
Evidence
South Africa suggests that understanding could be broadened by allowing for presentations by legal experts, including those in civil society and academia .
on: The role and legitimacy of stakeholder participation in the global mechanism
130
WPM
245
Words
2 min
Time
International law is the foundation for preserving international peace, security, and stability, including in the use of ICTs
Arg. 1
Explanation
Uruguay reaffirms that international law is the foundation for preserving international peace, security, and stability, including in the use of ICTs. They value the significant progress made in the OEWG and GGE and in other relevant processes.
Evidence
Uruguay reaffirms that international law is the foundation for preserving international peace, security, and stability, including in the use of ICTs . They also value the significant progress made in the OEWG and the GGE and in other relevant processes, which have deepened common understandings on the application of international law to the use of ICTs and helped to strengthen trust between states .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Deepening consensus on the application of international law will strengthen predictability of state behaviour, reduce the risk of miscalculations, and promote an open, stable, secure, peaceful, and accessible cyberspace
Arg. 2
Explanation
Uruguay argues that deepening consensus on the application of international law in the use of ICTs will help to strengthen the predictability of state behaviour, reduce the risk of miscalculations, and promote a cyberspace that is open, stable, secure, peaceful, and accessible to all.
Evidence
Uruguay states that deepening consensus on the application of international law in the use of ICTs will help to strengthen the predictability of state behaviour, to reduce the risk of miscalculations, and promote a cyberspace that is open, stable, secure, peaceful, and accessible to all .
Major Discussion Point
Deepening Common Understanding of How International Law Applies in Practice
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamAustriaMalawiEstoniaUnited KingdomArmeniaGermanyCanadaIrelandUkraineVanuatu
on: The global mechanism should build on the progress and common understandings established by previous GGEs and OEWGs rather than starting from scratch
136
WPM
363
Words
3 min
Time
Cyberspace is not a legal vacuum; international law, including the UN Charter, applies fully to state use of ICTs, encompassing sovereignty, non-intervention, due diligence, IHL, and IHRL
Arg. 1
Explanation
Costa Rica affirms that one of the major contributions of previous working groups is the recognition that cyberspace is not a legal vacuum, and that international law applies fully to the use of ICTs by states. This encompasses a broad range of principles including sovereignty, non-intervention, due diligence, IHL, and IHRL.
Evidence
Costa Rica states that one of the major contributions of the previous working groups is the recognition that cyberspace is not a legal vacuum and that international law, including the Charter of the United Nations, applies fully to the use of ICTs by states . This encompasses the principle of sovereign equality, the peaceful settlement of disputes, the prohibition of the threat or use of force, non-intervention, due diligence, the law of international responsibility, IHL, and IHRL .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
The added value of the global mechanism lies in moving beyond general affirmation of applicability towards more concrete, technical, and inclusive understanding of how legal concepts apply to specific situations
Arg. 2
Explanation
Costa Rica believes the added value of the global mechanism lies in moving beyond a general affirmation of applicability towards a more concrete, technical, and inclusive understanding of how legal concepts apply to specific situations. They highlight specific areas including operations involving proxies, digital coercion, attribution, response measures, and operations below the threshold of the use of force.
Evidence
Costa Rica states that the added value of the global mechanism lies in moving beyond a general affirmation of applicability towards a more concrete, technical, and inclusive understanding as to how legal concepts apply to specific situations, including operations involving the use of proxies, digital coercion, attribution, response measures, and operations below the threshold of the use of force . They also note that certain cyber operations can be legally significant when they cause physical damage, loss of functionality, or interference with inherently governmental functions .
Major Discussion Point
Deepening Common Understanding of How International Law Applies in Practice
Costa Rica believes it is essential to address attribution with rigour and prudence, promoting good practices, voluntary transparency, capacity building, and confidence-building measures to distinguish between technical, political, and legal attribution
Arg. 3
Explanation
Costa Rica argues that attribution must be addressed with rigour and prudence, as the digital environment presents unique technical and evidentiary challenges. They call for promoting good practices, voluntary transparency, capacity building, and confidence-building measures to distinguish between technical, political, and legal attribution.
Evidence
Costa Rica notes that although rules of attribution in international law are not new, the digital environment presents unique technical and evidentiary challenges . They therefore call for promoting good practices, voluntary transparency, capacity building, and confidence-building measures that help to distinguish between technical, political, and legal attribution .
Major Discussion Point
Attribution of Malicious Cyber Activities
Disagreed with
CubaIndonesiaIslamic Republic of IranIsraelMalawi
on: Whether attribution of malicious cyber activities should be addressed through multilateral mechanisms or existing state practice
149
WPM
463
Words
3 min
Time
Italy reaffirms that international law, including the UN Charter, state responsibility law, IHRL, and IHL, is fully applicable and relevant in the digital age
Arg. 1
Explanation
Italy fully aligns with the EU statement and reaffirms that international law is fully applicable and relevant in the digital age. They emphasise the importance of deepening collective understanding of how international law applies to cyberspace.
Evidence
Italy emphasises the importance of deepening collective understanding of how international law applies to cyberspace, noting that international law is fully applicable and relevant in the digital age . Italy publicly shared its national position on this matter in 2021 and is planning an update .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegatePortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Promoting transparency by publishing national and regional positions reduces uncertainty and the risk of miscalculation, establishing a global baseline for the application of international law
Arg. 2
Explanation
Italy argues that promoting transparency by publishing national and regional positions is in the collective interest, as it reduces uncertainty and the risk of miscalculation in interstate relations and establishes a global baseline for the application of international law in cyberspace.
Evidence
Italy states that promoting transparency by publishing national and regional positions is in the collective interest, as it reduces uncertainty and the risk of miscalculation in interstate relations . They also note that it establishes a global baseline for the application of international law in cyberspace , and greatly values the common African position on the application of international law to ICTs .
Major Discussion Point
Publication of National and Regional Positions on International Law
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoRepublic of KoreaNew ZealandEstoniaUnited KingdomMexicoBrazilMauritiusCanadaIrelandThailandSingapore
on: Publishing national and regional positions on the application of international law to cyberspace contributes to transparency, predictability, and common understanding
Italy stresses the importance of supporting capacity-building efforts to ensure all states can participate on an equal footing in developing common understandings of how international law applies
Arg. 3
Explanation
Italy stresses the importance of supporting capacity-building efforts, including with the aim of ensuring that all states are able to participate on an equal footing in the development of common understandings of how international law applies in the use of ICTs. They particularly appreciate the work done by UNIDIR.
Evidence
Italy stresses the importance of supporting capacity-building efforts, including with the aim of ensuring that all states are able to participate on an equal footing on the development of common understandings of how international law applies in the use of ICTs . They particularly appreciate the precious work done by organisations like UNIDIR .
Major Discussion Point
Capacity Building on International Law
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaKiribatiAustriaMalawiSingaporeNew ZealandIsraelEstoniaArmeniaNigeria Nigeria on behalf of the Africa GroupNetherlandsGermanyMauritiusVanuatuCanadaIrelandAlbaniaIndonesiaBotswanaThailand
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
Italy believes DTG1 can play a significant role in helping all states understand the impact of certain threats on international law through scenario-based discussions, while DTG2 could elaborate tailored projects to assist countries in building capacities
Arg. 4
Explanation
Italy believes DTG1 can play a significant role in helping all states understand the impact of certain threats and situations on international law, particularly through scenario-based discussions. DTG2 could then elaborate tailored projects to assist countries in building capacities in the field of international law.
Evidence
Italy states that DTG1 can play a significant role in helping all states understand the impact of certain threats and situations on international law, particularly thanks to scenario-based discussions and similar activities . DTG2 could then elaborate tailored projects to assist countries in building capacities in the field of international law .
Major Discussion Point
Role of Dedicated Thematic Groups (DTGs) in Advancing International Law Discussions
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumKiribatiAustriaJapanCanadaIrelandUkraineAlbaniaNetherlands
on: Scenario-based and practice-oriented discussions should be used within the dedicated thematic groups to deepen understanding of how international law applies in practice
139
WPM
376
Words
3 min
Time
The binding duty to protect freedom of expression is central to stability in cyberspace; states must uphold freedom of digital expression, including anonymous expression, across borders
Arg. 1
Explanation
Portugal emphasises the centrality of the binding duty to protect freedom of expression to stability in cyberspace. They argue that when states reaffirm the applicability of international law in cyberspace, this includes the binding state duty to protect freedom of digital expression of their citizens across borders, including anonymous expression.
Evidence
Portugal references Article 19 of the Universal Declaration of Human Rights, which asserts the fundamental right to hold opinions without interference and to seek, receive, and impart information through any media, regardless of frontiers . They also reference Article 19 of the UN International Covenant on Civil and Political Rights, which asserts that this personal right shall include freedom to seek, receive, and impart information and ideas of all kinds, regardless of frontiers . Portugal notes that online disinformation campaigns sponsored by states are a dangerous hybrid threat to national security , but that states must also uphold and protect the freedom of expression across borders of their citizens, including anonymous expression .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
101
WPM
500
Words
5 min
Time
International law must remain the common reference point for cyberspace governance, serving as an indispensable framework of trust rather than a constraint on technological progress
Arg. 1
Explanation
Cameroon argues that international law must remain the common reference point for cyberspace governance, serving as an indispensable framework of trust that enables states to harness the benefits of digital technologies while preventing risks. They see cyberspace as a major transformation requiring law to both regulate new realities and preserve fundamental values.
Evidence
Cameroon states that international law must remain the common reference point, not as a constraint opposed to technological progress, but as the indispensable framework of trust that enables states to harness its benefits and prevent risks . They also note that cyberspace has become an essential space for cooperation, innovation, economic development, and social progress, but also a domain in which complex challenges to international peace and security are manifested .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Cameroon supports the progressive development and codification of international law, including for ICTs, but argues this must be conducted with caution, objectivity, and legal rigour, and only where states conclude existing law is insufficient
Arg. 2
Explanation
Cameroon supports the progressive development and codification of international law, including for ICTs, as it helps improve legal certainty and the implementation of relevant obligations. However, they argue this reflection must be conducted with caution, objectivity, and legal rigour, and cannot proceed from the assumption that the existing framework is insufficient.
Evidence
Cameroon states that it has always supported the progressive development and codification of international law, including for ICTs, because it helps improve legal certainty and the implementation of relevant obligations . However, they argue this reflection must be conducted with caution, objectivity, and legal rigour, and cannot proceed from the assumption that the existing international legal framework is insufficient, nor presume that normative gaps exist . They note that if states conclude certain situations are not sufficiently covered by existing law, they may then consider the development of new legally binding obligations .
Major Discussion Point
Need for New Legally Binding Instruments vs. Sufficiency of Existing Law
132
WPM
786
Words
6 min
Time
International law, including the UN Charter, applies to cyberspace; sovereign equality, prohibition of force, non-intervention, and peaceful settlement of disputes are Kiribati's only real defences
Arg. 1
Explanation
Kiribati argues that for small states without the capacity to deter or retaliate, international law is not a matter of legal theory but their only real defence. They emphasise that when the mechanism affirms that international law applies to state conduct in cyberspace, Kiribati hears its security being spoken aloud.
Evidence
Kiribati explains that as a large ocean state of 120,000 people with no capacity to deter or retaliate, if a state chose to act against it in cyberspace, it could not answer or prevent it . They state that international law – sovereign equality, the prohibition of the threat and use of force, non-intervention, and the peaceful settlement of disputes – are not matters of legal theory but their defences, and in truth the only defences they have .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Legal capacity building is the condition of the international law pillar being real; Kiribati reiterates the proposal for scenario-based exercises on international law within the dedicated thematic groups
Arg. 2
Explanation
Kiribati argues that legal capacity building is not a footnote to the international law pillar but the condition of it being real. They reiterate the proposal for scenario-based exercises on international law within the dedicated thematic groups, arguing that working through realistic scenarios is how legal principle becomes operational understanding.
Evidence
Kiribati notes that its delegation to the session is three people, and that the officer who would draft Kiribati’s national position on international law is in the room that week and is also the officer who must do everything else . They state that legal capacity building is therefore not a footnote to this pillar but the condition of this pillar being real . Kiribati reiterates the proposal for scenario-based exercises on international law within the dedicated thematic groups, noting that working through realistic scenarios is how legal principle becomes operational understanding and one of the most effective forms of legal capacity building .
Major Discussion Point
Capacity Building on International Law
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumItalyAustriaJapanCanadaIrelandUkraineAlbaniaNetherlands
on: Scenario-based and practice-oriented discussions should be used within the dedicated thematic groups to deepen understanding of how international law applies in practice
Kiribati supports dedicating structured time in the mechanism, including within the thematic groups, to working through how the law applies in concrete situations, turning legal discussion into a shared capability
Arg. 3
Explanation
Kiribati supports dedicating structured time in the mechanism, including within the thematic groups, to working through how the law applies in concrete situations. They argue this turns legal discussion into a shared capability rather than a specialist preserve, and allows every state to participate as a contributor rather than an observer.
Evidence
Kiribati reiterates the proposal for scenario-based exercises on international law within the dedicated thematic groups, stating that working through realistic scenarios is how legal principle becomes operational understanding and one of the most effective forms of legal capacity building available to states like theirs . They argue this turns a legal debate into a legal conversation that includes all states and allows every state to participate not as an observer but as a contributor .
Major Discussion Point
Role of Dedicated Thematic Groups (DTGs) in Advancing International Law Discussions
200
WPM
776
Words
4 min
Time
Austria reaffirms that international law as a whole, including the UN Charter, IHRL, and IHL, applies to state cyber activities
Arg. 1
Explanation
Austria reaffirms the OEWG's conclusion that international law as a whole, including the UN Charter, applies to state cyber activities, and affirms that this encompasses IHRL and IHL. They stress the importance of building on the achievements of the last decade.
Evidence
Austria recalls the OEWG’s conclusion that international law as a whole, including the UN Charter, applies to state cyber activities, and reaffirms its firm view that there can be no doubt that such a finding encompasses IHRL and IHL . They also note that it is important to build on the achievements of the last decade, including the most recent OEWG .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamUruguayMalawiEstoniaUnited KingdomArmeniaGermanyCanadaIrelandUkraineVanuatu
on: The global mechanism should build on the progress and common understandings established by previous GGEs and OEWGs rather than starting from scratch
Affirming IHL's applicability to cyber activities in connection with armed conflict does not encourage or legitimise cyber warfare; it affirms that armed conflicts are subject to rules regardless of the means of warfare employed
Arg. 2
Explanation
Austria affirms that affirming the applicability of IHL to cyber activities in connection with an armed conflict does not encourage or legitimise cyber warfare. Rather, it aims to provide clarity and affirm the global consensus that armed conflicts are subject to rules and limitations, irrespective of the means of warfare being employed.
Evidence
Austria states that affirming the applicability of IHL to cyber activities in connection with an armed conflict does not encourage or legitimise cyber warfare, but aims to provide clarity and affirm the global consensus that armed conflicts are subject to rules and limitations, irrespective of the means of warfare being employed .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
Disagreed with
CubaChinaVenezuelaSwitzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoIrelandBrazilMexicoVanuatuAlbania
on: Whether International Humanitarian Law (IHL) automatically and fully applies to cyberspace
Austria considers further, more detailed discussions on how existing international law applies to cyber activities as a priority, and believes discussions should be scenario-based and practice-oriented
Arg. 3
Explanation
Austria considers further, more detailed discussions on how existing international law applies to cyber activities as a priority for the work of the DTGs. They firmly believe that discussions on international law should be scenario-based and practice-oriented.
Evidence
Austria considers further, more detailed discussions on how existing international law applies to cyber activities as a priority . They firmly believe that discussions on international law should be scenario-based and practice-oriented , and suggest that interstate discussions could be preceded by expert panels that would also provide delegations with sufficient time to ask questions and engage in a meaningful exchange with the experts .
Major Discussion Point
Capacity Building on International Law
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaItalyKiribatiMalawiSingaporeNew ZealandIsraelEstoniaArmeniaNigeria Nigeria on behalf of the Africa GroupNetherlandsGermanyMauritiusVanuatuCanadaIrelandAlbaniaIndonesiaBotswanaThailand
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
Austria expresses frustration with the lack of consensus on stakeholder participation, emphasising that non-governmental expertise is crucial to grounding decisions in a sound and comprehensive factual basis
Arg. 4
Explanation
Austria expresses frustration with the lack of consensus on stakeholder participation, sharing concerns raised by the multi-stakeholder community. They emphasise that while states will always make the decisions, non-governmental expertise is crucial to grounding those decisions in a sound and comprehensive factual basis.
Evidence
Austria shares the concerns raised by the multi-stakeholder community in the week’s joint multi-stakeholder statement on the objections to the participation of stakeholders . They emphasise that it will always be states making the decisions in this forum, but that for these decisions to be effective, they must be grounded in a sound and comprehensive factual basis, and that the expertise provided by non-governmental stakeholders is crucial to that .
Major Discussion Point
Stakeholder Participation in the Global Mechanism
Disagreed with
United KingdomNew ZealandSouth AfricaRussian Federation
on: The role and legitimacy of stakeholder participation in the global mechanism
Austria believes DTG discussions should be scenario-based and practice-oriented, preceded by expert panels, and focused on specific sub-areas one at a time to allow for in-depth discussions
Arg. 5
Explanation
Austria believes that discussions on international law in the DTGs should be scenario-based and practice-oriented. They suggest that interstate discussions could be preceded by expert panels, and that meetings should be focused on specific sub-areas one at a time to allow for in-depth discussions.
Evidence
Austria firmly believes that discussions on international law should be scenario-based and practice-oriented . They suggest that interstate discussions could be preceded by expert panels that would also provide delegations with sufficient time to ask questions and engage in a meaningful exchange with the experts , and that meetings of the DTGs should be focused on specific sub-areas, one at a time, to allow for in-depth discussions .
Major Discussion Point
Role of Dedicated Thematic Groups (DTGs) in Advancing International Law Discussions
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumItalyKiribatiJapanCanadaIrelandUkraineAlbaniaNetherlands
on: Scenario-based and practice-oriented discussions should be used within the dedicated thematic groups to deepen understanding of how international law applies in practice
124
WPM
579
Words
5 min
Time
International law remains a cornerstone of responsible state behaviour in cyberspace, with the UN Charter as the principal reference
Arg. 1
Explanation
Malawi affirms that international law remains a cornerstone of the cumulative and evolving framework for responsible state behaviour in cyberspace, with the UN Charter as the principal reference. They note that the Charter's principles are no less relevant in cyberspace than in the physical world.
Evidence
Malawi states that international law remains a cornerstone of the cumulative and evolving framework for responsible state behaviour in cyberspace, and that successive consensus reports of the UN GGEs and the OEWG have affirmed that international law, in particular the Charter of the United Nations, applies to the use of ICTs by states . They specifically reference the Charter’s principles of sovereign equality, peaceful settlement of disputes, the prohibition of the threat or use of force, and the obligation to cooperate in maintaining international peace and security as no less relevant in cyberspace than the physical world .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamUruguayAustriaEstoniaUnited KingdomArmeniaGermanyCanadaIrelandUkraineVanuatu
on: The global mechanism should build on the progress and common understandings established by previous GGEs and OEWGs rather than starting from scratch
Malawi supports the recognition that where ICTs are used in situations of armed conflict, IHL applies, with principles of humanity, distinction, proportionality, necessity, and precaution remaining essential
Arg. 2
Explanation
Malawi supports the statements by the EU, Italy, and Switzerland recognising that where ICTs are used in situations of armed conflict, IHL applies. They affirm that the principles of humanity, distinction, proportionality, necessity, and precaution remain essential to protecting civilians and civilian infrastructure.
Evidence
Malawi states that it is in support of statements shared by the EU, Italy, and Switzerland recognising that where ICTs are used in situations of armed conflict, IHL applies . They affirm that respect for the principles of humanity, distinction, proportionality, necessity, and precaution remains essential to protecting civilians and civilian infrastructure .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
Attribution to a state remains a legal determination that must be based on international law and credible evidence; responsible attribution is essential to maintaining international peace, security, and stability
Arg. 3
Explanation
Malawi affirms that while technical analysis may identify the source of malicious ICT activity, attribution to a state remains a legal determination that must be based on international law and credible evidence. They argue that responsible attribution is therefore essential to maintaining international peace, security, and stability.
Evidence
Malawi states that while technical analysis may identify the source of malicious ICT activity, attribution to a state remains a legal determination that must be based on international law and credible evidence . They therefore affirm that responsible attribution is essential to maintaining international peace, security, and stability .
Major Discussion Point
Attribution of Malicious Cyber Activities
Disagreed with
CubaIndonesiaCosta Rica DelegateIslamic Republic of IranIsrael
on: Whether attribution of malicious cyber activities should be addressed through multilateral mechanisms or existing state practice
Malawi believes questions about gaps and additional legally binding obligations should be approached carefully, inclusively, and on the basis of evidence, asking first whether the challenge lies in the law or in the ability to implement it
Arg. 4
Explanation
Malawi believes that questions about gaps in international law and whether additional legally binding obligations may be appropriate should be approached carefully, inclusively, and on the basis of evidence. They argue that before concluding that legal gaps exist, states should first ask whether the greater challenge lies in the law itself or in the collective ability to understand, implement, and operationalise the law that already applies.
Evidence
Malawi states that questions about gaps in international law and whether additional legally binding obligations may be appropriate should be approached carefully, inclusively, and on the basis of evidence . They argue that before concluding that legal gaps exist, states should first ask whether the greater challenge lies in the law itself or in the collective ability to understand, implement, and operationalise the law that has already been agreed to apply .
Major Discussion Point
Need for New Legally Binding Instruments vs. Sufficiency of Existing Law
Malawi affirms that the most significant gap is not in international law itself but between legal consensus and practical implementation, and that closing this gap should be the priority
Arg. 5
Explanation
Malawi concludes that the most significant gap before the mechanism is not a gap in international law but the gap between legal consensus and practical implementation. They argue that closing this gap would do more to strengthen international peace and security than debating obligations that many states are not yet equipped to operationalise.
Evidence
Malawi states that the most significant gap before the mechanism today is not a gap in international law but the gap between legal consensus and practical implementation . They argue that closing that gap would do more to strengthen international peace and security than debating obligations that many states are not yet equipped to operationalise .
Major Discussion Point
Capacity Building on International Law
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaItalyKiribatiAustriaSingaporeNew ZealandIsraelEstoniaArmeniaNigeria Nigeria on behalf of the Africa GroupNetherlandsGermanyMauritiusVanuatuCanadaIrelandAlbaniaIndonesiaBotswanaThailand
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
Singapore affirms that fostering common understanding on the application of international law to ICTs contributes to peace, security, and trust among states
Arg. 1
Explanation
Singapore sees international law as a crucial component of the mechanism's work and affirms that fostering common understanding among states in the application of international law to the ICT context will contribute to greater peace, security, and trust among states.
Evidence
Singapore states that fostering common understanding among states in the application of international law to the ICT context will contribute to greater peace, security, and trust among states . They also see considerable value in states issuing national statements or regional ones, such as what the African Union and the European Union have done previously .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoItalyRepublic of KoreaNew ZealandEstoniaUnited KingdomMexicoBrazilMauritiusCanadaIrelandThailand
on: Publishing national and regional positions on the application of international law to cyberspace contributes to transparency, predictability, and common understanding
Singapore affirms that capacity building in international law is an essential part of fostering common understanding on how international law applies in the use of ICTs
Arg. 2
Explanation
Singapore affirms that capacity building in international law is an essential part of fostering common understanding on how international law applies in the use of ICTs. They call for continued capacity-building efforts to ensure that every state acquires the necessary expertise and capacity to participate on an equal footing.
Evidence
Singapore states that capacity building in international law is an essential part of fostering common understanding on how international law applies in the use of ICTs . They note the need to continue capacity-building efforts with the aim of ensuring that every state acquires the necessary expertise and capacity to participate on an equal footing and contribute meaningfully to discussions on international law .
Major Discussion Point
Capacity Building on International Law
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaItalyKiribatiAustriaMalawiNew ZealandIsraelEstoniaArmeniaNigeria Nigeria on behalf of the Africa GroupNetherlandsGermanyMauritiusVanuatuCanadaIrelandAlbaniaIndonesiaBotswanaThailand
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
114
WPM
551
Words
5 min
Time
Colombia reaffirms that international law, especially the UN Charter, applies to cyberspace and is essential for maintaining international peace, security, and stability
Arg. 1
Explanation
Colombia reaffirms that international law and especially the Charter of the United Nations apply to cyberspace and are essential for maintaining international peace, security, and stability. They note that there is today broad consensus on the applicability of international law to the use of ICTs by states.
Evidence
Colombia reaffirms that international law and especially the Charter of the United Nations apply to cyberspace and are essential for maintaining international peace, security, and stability . They note that as a result of deliberations under the GGE and OEWG frameworks, there is today broad consensus on the applicability of international law to the use of ICTs by states .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Colombia believes it is relevant to deepen analysis of IHL application to cyber operations in armed conflict, including how customary international law has been consolidated in cyberspace
Arg. 2
Explanation
Colombia believes it is relevant to deepen analysis of the application of IHL to cyber operations in situations of armed conflict. They also consider it useful to analyse how IHL and customary international law have been consolidated in cyberspace, including for states that may not have offensive cyber capability but have legal and humanitarian interests.
Evidence
Colombia states that it believes it is relevant to go deeper in the analysis of the application of IHL to cybernetic operations in situations of armed conflict, and considers it useful to analyse how IHL and customary international law have been consolidated in cyberspace . They also note that IHL applies fully to the use of ICTs during armed conflict, both international and non-international, and that it is necessary to continue examining how these principles apply given the transformations that digital technologies have introduced, including the use of digital platforms for the forced recruitment of children by illegal armed groups .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
Colombia believes the first thematic group can provide significant added value by developing concrete outputs that move legal arguments into practical guidance for states
Arg. 3
Explanation
Colombia believes the first thematic group can provide significant added value by developing concrete outputs that allow legal arguments to be translated into practical guidance for states. They identify three spheres where DTG1 can contribute, including deepening analysis of IHL, examining how principles apply in digital conflicts, and studying malicious cyber actions by non-state actors.
Evidence
Colombia indicates three spheres where the first thematic group can provide significant added value by developing concrete outputs that will allow legal arguments to be moved into practical guidance for states . These include deepening analysis of IHL application to cyber operations in armed conflict , examining how IHL principles apply given digital transformations , and deepening the study of malicious cybernetic actions carried out by non-state actors in the territory of a state .
Major Discussion Point
Deepening Common Understanding of How International Law Applies in Practice
Colombia believes the first thematic group can provide significant added value by developing concrete outputs that allow legal arguments to be translated into practical guidance for states
Arg. 4
Explanation
Colombia calls for DTG1 to develop concrete outputs that translate legal arguments into practical guidance for states, including on the application of IHL, the examination of how principles apply in digital conflicts, and the study of malicious cyber actions by non-state actors.
Evidence
Colombia indicates three spheres where the first thematic group can provide significant added value by developing concrete outputs that will allow legal arguments to be moved into practical guidance for states .
Major Discussion Point
Role of Dedicated Thematic Groups (DTGs) in Advancing International Law Discussions
129
WPM
267
Words
2 min
Time
Existing international law, including the UN Charter, IHL, and IHRL, applies to cyberspace and provides a sufficient legal foundation for governing state conduct
Arg. 1
Explanation
The Republic of Korea reiterates that existing international law, including the entirety of the UN Charter, IHL, and IHRL, applies to cyberspace. They argue that existing international law already provides a sufficient legal foundation for governing state conduct in cyberspace.
Evidence
The Republic of Korea reiterates that existing international law, including the entirety of the UN Charter, IHL, and IHRL, applies to cyberspace . They state that existing international law already provides a sufficient legal foundation for governing state conduct in cyberspace, and that rather than pursuing new legally binding instruments, efforts should focus on clarifying and operationalising existing international law .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Recognising the applicability of IHL to cyberspace neither legitimises nor encourages armed conflict; it ensures protections continue to apply to reduce human suffering
Arg. 2
Explanation
The Republic of Korea emphasises that recognising the applicability of IHL to cyberspace neither legitimises nor encourages armed conflict. Rather, it seeks to ensure that if an armed conflict occurs, the protections afforded under IHL continue to apply in order to reduce human suffering and protect civilians.
Evidence
The Republic of Korea states that recognising the applicability of IHL to cyberspace neither legitimises nor encourages armed conflict, but rather seeks to ensure that if an armed conflict occurs, the protections afforded under IHL continue to apply in order to reduce human suffering and protect civilians .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
The global mechanism should continue to serve as a platform for deepening understanding of the realities of cyberspace and progressively developing common understanding of how existing international law applies
Arg. 3
Explanation
The Republic of Korea argues that the global mechanism should continue to serve as a platform for deepening understanding of the realities of cyberspace and for progressively developing common understanding of how existing international law applies in this domain. They note the challenges arising from the significant role of non-state actors and the anonymity, speed, and technical complexity of cyber operations.
Evidence
The Republic of Korea notes that discussions on the application of international law must take account of the unique characteristics of cyberspace, including the challenges arising from the significant role of non-state actors and the anonymity, speed, and technical complexity of cyber operations . They state that the global mechanism should therefore continue to serve as a platform for deepening understanding of the realities of cyberspace and for progressively developing common understanding of how existing international law applies .
Major Discussion Point
Deepening Common Understanding of How International Law Applies in Practice
Existing international law already provides a sufficient legal foundation; efforts should focus on clarifying and operationalising existing law rather than pursuing new legally binding instruments
Arg. 4
Explanation
The Republic of Korea argues that existing international law already provides a sufficient legal foundation for governing state conduct in cyberspace. Rather than pursuing the negotiation of new legally binding instruments, efforts should focus on clarifying and operationalising existing international law while strengthening mechanisms for its effective implementation.
Evidence
The Republic of Korea states that existing international law already provides a sufficient legal foundation for governing state conduct in cyberspace, and that rather than pursuing the negotiation of new legally binding instruments, efforts should focus on clarifying and operationalising existing international law while strengthening mechanisms for its effective implementation through international cooperation .
Major Discussion Point
Need for New Legally Binding Instruments vs. Sufficiency of Existing Law
Disagreed with
CubaIslamic Republic of IranChinaRussian FederationVenezuelaIsraelIrelandUkraineFranceNew ZealandTonga on behalf of the Pacific Islands Forum
on: Whether additional legally binding instruments are needed for cyberspace governance
Republic of Korea published its national position on the application of international law to cyberspace in July 2025, contributing constructively to the ongoing international discussion
Arg. 5
Explanation
The Republic of Korea notes that it published its national position on the application of international law to cyberspace in July 2025, with a view to contributing constructively to the ongoing discussion in the international community.
Evidence
The Republic of Korea states that its government published its national position on the application of international law to cyberspace in July 2025, with a view to contributing constructively to the ongoing discussion in the international community .
Major Discussion Point
Publication of National and Regional Positions on International Law
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoItalyNew ZealandEstoniaUnited KingdomMexicoBrazilMauritiusCanadaIrelandThailandSingapore
on: Publishing national and regional positions on the application of international law to cyberspace contributes to transparency, predictability, and common understanding
The unique characteristics of cyberspace, including anonymity, speed, and technical complexity, make attribution and response more difficult and must be accounted for in discussions
Arg. 6
Explanation
The Republic of Korea argues that discussions on the application of international law must take account of the unique characteristics of cyberspace, including the challenges arising from the significant role of non-state actors and the anonymity, speed, and technical complexity of cyber operations, all of which make attribution and response more difficult.
Evidence
The Republic of Korea notes that discussions on the application of international law must take account of the unique characteristics of cyberspace, in particular the challenges arising from the significant role of non-state actors as well as the anonymity, speed, and technical complexity of cyber operations, all of which make attribution and response more difficult .
Major Discussion Point
Attribution of Malicious Cyber Activities
139
WPM
558
Words
4 min
Time
New Zealand reaffirms that international law applies to state conduct in cyberspace, including the UN Charter, state responsibility law, IHL, and IHRL
Arg. 1
Explanation
New Zealand reaffirms its shared understanding that international law applies to state conduct in cyberspace, including the UN Charter in its entirety, the law on state responsibility, IHL, and IHRL. They align with the statements delivered by the Pacific Islands Forum and the cross-regional group.
Evidence
New Zealand aligns itself with the statement delivered by the Kingdom of Tonga on behalf of the Pacific Islands Forum and the statement delivered by Australia on behalf of the cross-regional group of states, reaffirming the shared understanding that international law applies to state conduct in cyberspace, including the UN Charter in its entirety, the law on state responsibility, IHL, and IHRL .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
New Zealand calls for the mechanism to enable sharing of practical experiences and best practices on the application of international law when assessing or responding to common challenges
Arg. 2
Explanation
New Zealand calls for the global mechanism, including the DTGs, to enable states to share practical experiences and best practices on the application of international law when assessing or responding to common challenges. They also call for identifying international law capacity-building needs and discussing areas where understandings remain less settled.
Evidence
New Zealand states that the global mechanism, including the DTGs, should enable states to share practical experiences and best practices on the application of international law when assessing or responding to common challenges, to identify international law capacity-building needs, and to discuss areas of international law where understandings remain less settled . They also note that the common African position on the application of international law identifies a helpful example of one area that could benefit from further discussion, namely the rule of non-intervention .
Major Discussion Point
Deepening Common Understanding of How International Law Applies in Practice
New Zealand maintains that meaningful participation by relevant stakeholders, both in the plenary and the DTGs, is essential, and supports capacity-building measures
Arg. 3
Explanation
New Zealand maintains that meaningful participation by relevant stakeholders, both in the plenary and the DTGs, is essential. This includes legal experts and government lawyers from all states, and New Zealand continues to support capacity-building efforts and measures that enable all states to participate.
Evidence
New Zealand maintains that meaningful participation by relevant stakeholders, both in the plenary and the DTGs, is essential, including legal experts whose positions broadly support the need to continue building an understanding of how international law applies in cyberspace . They also note the importance of direct participation of government lawyers from all states, and that lawyers should be in the room with policy colleagues when developing case studies and scenarios which integrate international law issues .
on: The role and legitimacy of stakeholder participation in the global mechanism
New Zealand maintains that meaningful participation by relevant stakeholders, including legal experts and government lawyers from all states, is essential, and supports capacity-building measures
Arg. 4
Explanation
New Zealand argues that legal capacity building is central to ensuring meaningful participation, and supports capacity-building efforts and measures that enable and justify participation by all states. They note that lawyers should be in the room with policy colleagues when developing case studies and scenarios.
Evidence
New Zealand notes that as powerfully put by the colleague from Kiribati and many others in the room, legal capacity building is central to this . They state that lawyers should be in the room with policy colleagues when developing case studies and scenarios which integrate international law issues and perspectives, and can help turn legal principles into practical examples .
Major Discussion Point
Capacity Building on International Law
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaItalyKiribatiAustriaMalawiSingaporeIsraelEstoniaArmeniaNigeria Nigeria on behalf of the Africa GroupNetherlandsGermanyMauritiusVanuatuCanadaIrelandAlbaniaIndonesiaBotswanaThailand
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
New Zealand notes that national position statements signpost areas where agreement on the application of international law converges but understandings can be strengthened
Arg. 5
Explanation
New Zealand notes that national position statements on the application of international law to cyberspace, including New Zealand's own, signpost additional areas where agreement on the application of international law converges but understandings of how international law applies can be strengthened.
Evidence
New Zealand notes that other national position statements on the application of international law to cyberspace, including New Zealand’s national position statement, signpost additional areas where agreement on the application of international law converges, but understandings of how international law applies can be strengthened . They state that these discussions should continue in the global mechanism .
Major Discussion Point
Publication of National and Regional Positions on International Law
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoItalyRepublic of KoreaEstoniaUnited KingdomMexicoBrazilMauritiusCanadaIrelandThailandSingapore
on: Publishing national and regional positions on the application of international law to cyberspace contributes to transparency, predictability, and common understanding
125
WPM
476
Words
4 min
Time
Israel reiterates its longstanding position that existing international law, including the UN Charter and the law of armed conflict, applies to cyberspace
Arg. 1
Explanation
Israel reiterates its consistent and longstanding position that existing international law applies to cyberspace, including the UN Charter and the law of armed conflict. They are therefore of the firm position that there is no need for a new legally binding instrument.
Evidence
Israel reiterates its consistent and longstanding position that existing international law applies to cyberspace, including the UN Charter and the law of armed conflict . They state that for this reason, among others, they are of the firm position that there is no need for a new legally binding instrument .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Israel is firmly of the position that there is no need for a new legally binding instrument; discussion should focus on meticulous evaluation of how existing law applies to the unique characteristics of the cyber domain
Arg. 2
Explanation
Israel argues that traditional international legal principles were established in physical domain contexts, and their application to the unique and decentralised features of the cyber domain requires meticulous evaluation rather than automatic transposition. They argue that rules developed in physical domains should not be presumed to apply similarly to the cyber domain.
Evidence
Israel notes that traditional international legal principles were established in physical domain contexts, and their application to the unique and decentralised features of the cyber domain requires meticulous evaluation rather than automatic transpositions . They give the example that data lacks a meaningful physical manifestation, is highly dynamic, and relies heavily on privately owned international infrastructure . They also note that international legal frameworks developed for domains with unique characteristics, such as maritime, aviation, and space law, were done so after comprehensive considerations and cautious deliberation .
Major Discussion Point
Need for New Legally Binding Instruments vs. Sufficiency of Existing Law
Disagreed with
Russian FederationIslamic Republic of IranCubaSwitzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamEstoniaUnited Kingdom
on: Whether the unique characteristics of cyberspace require entirely new legal frameworks or merely careful application of existing law
Israel sees value in using the DTGs as a vehicle for capacity building to help states craft, refine, and publish their legal positions
Arg. 3
Explanation
Israel sees value in using the DTGs as a vehicle for capacity building with the aim of helping states craft, refine, and publish their legal positions. They also note the value in exploring the intersection between capacity building and international law.
Evidence
Israel states that the global mechanism can contribute to the positive trend of states publishing positions by exploring the intersection between capacity building and international law . They see much value in using the DTGs as a vehicle for capacity building with an aim to help states in crafting, refining, and publishing their legal positions .
Major Discussion Point
Capacity Building on International Law
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaItalyKiribatiAustriaMalawiSingaporeNew ZealandEstoniaArmeniaNigeria Nigeria on behalf of the Africa GroupNetherlandsGermanyMauritiusVanuatuCanadaIrelandAlbaniaIndonesiaBotswanaThailand
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
Israel notes that data lacks a meaningful physical manifestation, is highly dynamic, and relies on privately owned international infrastructure, highlighting unique characteristics of the cyber domain relevant to attribution
Arg. 4
Explanation
Israel highlights the unique characteristics of the cyber domain that have meaningful ramifications for interpreting and applying international law to cyber activities, including that data lacks a meaningful physical manifestation, is highly dynamic, and relies heavily on privately owned international infrastructure.
Evidence
Israel notes that data lacks a meaningful physical manifestation, is highly dynamic as it can travel globally across multiple jurisdictions instantly, and relies heavily on privately owned international infrastructure . They argue this highlights a methodological insight that international legal frameworks developed for domains with unique characteristics were done so after comprehensive considerations and cautious deliberation, and that the cyber domain is similarly unique .
Major Discussion Point
Attribution of Malicious Cyber Activities
Disagreed with
CubaIndonesiaCosta Rica DelegateIslamic Republic of IranMalawi
on: Whether attribution of malicious cyber activities should be addressed through multilateral mechanisms or existing state practice
113
WPM
604
Words
5 min
Time
Estonia affirms that previous UN processes have clearly confirmed that existing international law applies in cyberspace
Arg. 1
Explanation
Estonia affirms that previous UN processes have clearly confirmed that existing international law applies in cyberspace, and that the task before the mechanism is to strengthen its implementation, deepen common understanding, and promote transparency in how states interpret and apply their international legal obligations.
Evidence
Estonia states that previous UN processes have clearly confirmed that existing international law applies in cyberspace, and that the task before the mechanism is to strengthen its implementation, deepen common understanding, and promote transparency in how states interpret and apply their international legal obligations in the ICT environment .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamUruguayAustriaMalawiUnited KingdomArmeniaGermanyCanadaIrelandUkraineVanuatu
on: The global mechanism should build on the progress and common understandings established by previous GGEs and OEWGs rather than starting from scratch
Disagreed with
IsraelRussian FederationIslamic Republic of IranCubaSwitzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamUnited Kingdom
on: Whether the unique characteristics of cyberspace require entirely new legal frameworks or merely careful application of existing law
Estonia strongly believes IHL should be among the international law topics addressed by the global mechanism, moving beyond questioning its applicability to concrete legal questions
Arg. 2
Explanation
Estonia strongly believes that IHL should be among the international law topics addressed by the global mechanism. They argue that discussion should move beyond questioning its applicability and instead focus on the concrete legal questions already emerging in practice.
Evidence
Estonia strongly believes that IHL should be among the international law topics addressed by the global mechanism, and that discussion should move beyond questioning its applicability and instead focus on the concrete legal questions already emerging in practice, including those usefully identified by the ICRC in its working paper .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
The global mechanism should facilitate the exchange of national experiences on how international law is applied in practice, including assessing the legality of contemplated cyber activities, responding to unlawful operations, and pursuing accountability
Arg. 3
Explanation
Estonia calls for the global mechanism to facilitate the exchange of national experiences on how international law is applied in practice. This includes assessing the legality of contemplated cyber activities, responding to unlawful cyber operations, and pursuing accountability for violations of international law committed in cyberspace.
Evidence
Estonia states that the global mechanism should facilitate the exchange of national experiences on how international law is applied in practice, including assessing the legality of contemplated cyber activities, responding to unlawful cyber operations, and pursuing accountability for violations of international law committed in cyberspace . They note that such exchanges can help identify effective approaches, develop best practices, and strengthen consistency in the application of international law in cyberspace .
Major Discussion Point
Deepening Common Understanding of How International Law Applies in Practice
Estonia set out its first national position in 2019 and encourages other states to articulate, share, and regularly update their national views
Arg. 4
Explanation
Estonia highlights the important role that national and regional positions on international law play in promoting clarity, predictability, and transparency in cyberspace. They note that Estonia set out its first national position in 2019 and is currently in its third review process, and encourages other states to articulate, share, and regularly update their national views.
Evidence
Estonia notes that it set out its first national position already in 2019, and that to ensure its position reflects current state practice, technological developments, and its evolving national interest, the position is currently in its third review process . They encourage other states to articulate, share, and where appropriate, regularly update their national views .
Major Discussion Point
Publication of National and Regional Positions on International Law
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoItalyRepublic of KoreaNew ZealandUnited KingdomMexicoBrazilMauritiusCanadaIrelandThailandSingapore
on: Publishing national and regional positions on the application of international law to cyberspace contributes to transparency, predictability, and common understanding
Estonia welcomes the integrated, policy-oriented, and cross-cutting nature of DTG1, which allows examination of specific ICT security challenges in a holistic manner while ensuring legal considerations remain fully integrated
Arg. 5
Explanation
Estonia welcomes the integrated, policy-oriented, and cross-cutting nature of DTG1, which draws on the five pillars of the framework including international law. They argue this approach allows examination of specific ICT security challenges in a holistic manner while ensuring that legal considerations remain fully integrated across the mechanism's work.
Evidence
Estonia welcomes the integrated, policy-oriented, and cross-cutting nature of dedicated thematic relations, noting that this approach allows examination of specific ICT security challenges in a holistic manner while ensuring that legal considerations remain fully integrated across the mechanism’s work . They also note that international law is a cross-cutting theme that must inform all areas of the global mechanism’s work, including discussions on threats, norms, confidence-building measures, capacity building, cooperation, and accountability .
Major Discussion Point
Role of Dedicated Thematic Groups (DTGs) in Advancing International Law Discussions
149
WPM
540
Words
4 min
Time
The UK affirms that all states have agreed by consensus that international law applies to state conduct in cyberspace; cyberspace is not lawless
Arg. 1
Explanation
The UK affirms that all states have agreed by consensus that international law applies to state conduct in cyberspace, and that cyberspace is not lawless. They note that states have the right to exercise cyber capabilities, subject to the restrictions imposed by international law.
Evidence
The UK states that all states have agreed by consensus that international law applies to state conduct in cyberspace, and that cyberspace is not lawless . They note that the UK’s position is clear: states have the right to exercise cyber capabilities, subject to the restrictions imposed by international law, just as they do in other domains .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamUruguayAustriaMalawiEstoniaArmeniaGermanyCanadaIrelandUkraineVanuatu
on: The global mechanism should build on the progress and common understandings established by previous GGEs and OEWGs rather than starting from scratch
Disagreed with
IsraelRussian FederationIslamic Republic of IranCubaSwitzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamEstonia
on: Whether the unique characteristics of cyberspace require entirely new legal frameworks or merely careful application of existing law
The UK calls for grappling with how IHL applies in cyberspace, including through detailed public statements on the use of cyber means in furtherance of armed conflict
Arg. 2
Explanation
The UK calls for moving beyond the basic premise that international law applies and grappling with the more challenging questions of how existing rules apply in cyberspace, including IHL. They note that the UK has been at the forefront of states addressing these issues through detailed public statements.
Evidence
The UK states that it must move beyond the fact that international law applies and grapple with the more challenging questions of how existing rules apply in cyberspace, including of the ways in which state responsibility, IHL, and IHRL apply . They note that the UK has been at the forefront of states and international organisations addressing these issues, including through detailed public statements on prohibited interventions, countermeasures, the use of force, and the use of cyber means in furtherance of armed conflict .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
The UK calls for moving beyond the basic premise that international law applies and grappling with the more challenging questions of how existing rules apply in cyberspace
Arg. 3
Explanation
The UK argues that the mechanism cannot settle on the basic premise that international law applies, but must move beyond it and grapple with the more challenging questions of how existing rules apply in cyberspace. They call for this to be done both in plenary sessions and through the work of the dedicated thematic groups.
Evidence
The UK states that it cannot settle on the basic premise that international law applies, and must move beyond the fact that international law applies and grapple with the more challenging questions of how existing rules apply in cyberspace . They note that this is one important contribution the global mechanism should strive to make, both in plenary sessions and through the work of the dedicated thematic groups .
Major Discussion Point
Deepening Common Understanding of How International Law Applies in Practice
The UK encourages states that have not yet done so to set out their positions in a similarly public and detailed way
Arg. 4
Explanation
The UK encourages states that have not yet set out their positions on international law in cyberspace, or have not done so in detail, to do so in a similarly public way. They also reference a practical handbook published by scholars from the University of Exeter as a resource for states developing or reviewing their positions.
Evidence
The UK states that where other states have not done so or have not done so in detail, it encourages them to set out their positions in a similarly public way, including in this forum . They also reference a practical handbook published by scholars from the University of Exeter, developed in collaboration with the Ministry of Foreign Affairs of Estonia, the Ministry of Foreign Affairs of Japan, and the NATO Cooperative Cyber Defence Centre of Excellence, published in 2025 .
Major Discussion Point
Publication of National and Regional Positions on International Law
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoItalyRepublic of KoreaNew ZealandEstoniaMexicoBrazilMauritiusCanadaIrelandThailandSingapore
on: Publishing national and regional positions on the application of international law to cyberspace contributes to transparency, predictability, and common understanding
The UK regrets that stakeholders with genuine expertise, including those from the University of Exeter, were blocked from participating in the plenary session
Arg. 5
Explanation
The UK regrets that stakeholders with genuine expertise, including those from the University of Exeter, were blocked from participating in the plenary session. They argue that such expertise is important for moving beyond theoretical questions to help define what responsible cyber behaviour means in practice.
Evidence
The UK states that it regrets that stakeholders with genuine expertise, including those from the University of Exeter, were blocked from participating in the plenary session . They also note that not only states but also other stakeholders, including industry, academia, and national and international organisations, each have an important contribution to make in moving beyond theoretical questions to help define what responsible cyber behaviour means in practice .
Major Discussion Point
Stakeholder Participation in the Global Mechanism
Disagreed with
AustriaNew ZealandSouth AfricaRussian Federation
on: The role and legitimacy of stakeholder participation in the global mechanism
133
WPM
229
Words
2 min
Time
Armenia reaffirms that international law, including the UN Charter, is applicable in cyberspace and essential to maintaining international peace and security
Arg. 1
Explanation
Armenia reaffirms its position that international law, including the UN Charter, is applicable in cyberspace. They underscore that respectful and faithful implementation of international law is essential to maintaining international peace and security, promoting stability and predictability in cyberspace, and fostering an open, secure, stable, accessible, and peaceful ICT environment.
Evidence
Armenia reaffirms its position that international law, including the UN Charter, is applicable in cyberspace . They underscore that respectful and faithful implementation of international law is essential to maintaining international peace and security, promoting stability and predictability in cyberspace, and fostering an open, secure, stable, accessible, and peaceful ICT environment .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Armenia underscores the importance of promoting a shared understanding of the application of international law in cyberspace, while recognising that capacity building is essential to enable all states to participate effectively
Arg. 2
Explanation
Armenia underscores the importance of promoting a shared understanding of the application of international law in cyberspace, while recognising that capacity building is essential to enable all states to participate effectively. They also emphasise that future discussions should take into account the needs and perspectives of developing and capacity-constrained states.
Evidence
Armenia underscores the importance of promoting a shared understanding of the application of international law in cyberspace, while recognising that capacity building is essential to enable all states to participate effectively . They also highlight the importance of ensuring that future discussions on the application of international law take into account the needs and perspectives of developing and capacity-constrained states, so that all states can effectively participate in shaping a common understanding .
Major Discussion Point
Capacity Building on International Law
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaItalyKiribatiAustriaMalawiSingaporeNew ZealandIsraelEstoniaNigeria Nigeria on behalf of the Africa GroupNetherlandsGermanyMauritiusVanuatuCanadaIrelandAlbaniaIndonesiaBotswanaThailand
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
97
WPM
187
Words
2 min
Time
Mexico reaffirms that international law, including the UN Charter, IHRL, and IHL, applies to the use of ICTs by states
Arg. 1
Explanation
Mexico reaffirms that international law, including the Charter of the United Nations, IHRL, and IHL, all apply to the use of ICTs by states. They also note that the applicability of IHL does not legitimise the militarisation of cyberspace.
Evidence
Mexico reaffirms that international law, including the Charter of the United Nations, IHRL, and IHL, all apply to the use of ICTs by states . They also note that the applicability of IHL does not legitimise the militarisation of cyberspace nor that of armed conflict, but on the contrary imposes limits on the conduct of parties and protects civilian populations .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Mexico affirms that the applicability of IHL does not legitimise the militarisation of cyberspace; on the contrary, it imposes limits on the conduct of parties and protects civilian populations
Arg. 2
Explanation
Mexico affirms that the applicability of IHL does not legitimise the militarisation of cyberspace nor that of armed conflict. On the contrary, it imposes limits on the conduct of parties and protects civilian populations.
Evidence
Mexico states that the applicability of IHL does not legitimise the militarisation of cyberspace nor that of armed conflict, and that on the contrary, it imposes limits on the conduct of parties and protects civilian populations .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
Disagreed with
CubaChinaVenezuelaSwitzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustriaIrelandBrazilVanuatuAlbania
on: Whether International Humanitarian Law (IHL) automatically and fully applies to cyberspace
Mexico appreciates the progress made in the publication of national positions and welcomes inter-regional contributions, inviting more states and regions to publish their positions as a transparency and trust-building measure
Arg. 3
Explanation
Mexico appreciates the progress made in the publication of national positions and welcomes inter-regional contributions on the implementation of international law. They invite more states and regions to publish their positions as a measure of transparency and trust-building.
Evidence
Mexico appreciates the progress made in the publication of national positions and welcomes inter-regional contributions on the implementation of international law, including the UNIDIR compendium and the recently published Common African Position . They invite more states and regions to publish their positions as a measure of transparency and trust-building .
Major Discussion Point
Publication of National and Regional Positions on International Law
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoItalyRepublic of KoreaNew ZealandEstoniaUnited KingdomBrazilMauritiusCanadaIrelandThailandSingapore
on: Publishing national and regional positions on the application of international law to cyberspace contributes to transparency, predictability, and common understanding
Cuba affirms that the use of ICTs must be fully compatible with the UN Charter and international law, especially sovereignty, territorial integrity, and non-intervention
Arg. 1
Explanation
Cuba affirms that the use of ICTs must be fully compatible with the purposes and principles of the Charter of the United Nations and international law, especially governing sovereignty, territorial integrity, and non-intervention in the internal affairs of states. They argue that ICTs should be a tool for peace and development, not a means of war.
Evidence
Cuba states that the use of ICTs must be fully compatible with the purposes and principles of the Charter of the United Nations and international law, especially governing sovereignty, territorial integrity, and the non-intervention in the internal affairs of states, and that they should be a tool for peace and development, not a means of war .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Cuba argues that automatic applicability of IHL to cyberspace is not acceptable as it implies a step towards militarisation and could make a cyber attack equivalent to a military attack
Arg. 2
Explanation
Cuba argues that automatic applicability of international law and IHL to cyberspace is not acceptable insofar as it implies a step towards the militarisation of cyberspace. They argue this would lead to making a cyber attack the equivalent of a military attack, allowing legitimate defence to be invoked.
Evidence
Cuba states that automatic applicability of international law and IHL to cyberspace is not acceptable insofar as this supplies a step towards militarisation of cyberspace . They argue this would lead to making a cyber attack the equivalent of a military attack, so that legitimate defence could be invoked under Article 4.1 of the Charter corresponding to the use of force .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
Disagreed with
ChinaVenezuelaSwitzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustriaIrelandBrazilMexicoVanuatuAlbania
on: Whether International Humanitarian Law (IHL) automatically and fully applies to cyberspace
Cuba argues that automatic applicability of international law to cyberspace is not acceptable and that there is a need for a legally binding instrument negotiated multilaterally under the UN framework
Arg. 3
Explanation
Cuba argues that there is a need for a legally binding instrument that would be negotiated multilaterally under the framework of the United Nations. They argue that voluntary norms are insufficient and would lead to an avoidance of international responsibility.
Evidence
Cuba argues that the idea that voluntary norms are sufficient would lead to an avoidance of international responsibility that falls upon states when they commit internationally wrongful acts . They state there is a need for a legally binding instrument that would be negotiated multilaterally under the framework of the United Nations .
Major Discussion Point
Need for New Legally Binding Instruments vs. Sufficiency of Existing Law
Disagreed with
IsraelRussian FederationIslamic Republic of IranSwitzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamEstoniaUnited Kingdom
on: Whether the unique characteristics of cyberspace require entirely new legal frameworks or merely careful application of existing law
Cuba argues that in the absence of a multilateral mechanism that would impartially determine the origin of cybernetic incidents, attribution can be easily manipulated
Arg. 4
Explanation
Cuba argues that in the absence of a multilateral mechanism that would impartially and unequivocally determine the origin of cybernetic incidents, attribution can be easily manipulated. They see this as one of the challenges that cannot be tackled with fragmented norms across different jurisdictional areas.
Evidence
Cuba states that in the absence of a multilateral mechanism that would impartially and unequivocally determine the origin of cybernetic incidents, attribution can be easily manipulated today . They argue that these are all challenges that cannot be tackled with fractured and fragmented norms across different jurisdictional areas, many of which are being flouted without any kind of legal consequences .
Major Discussion Point
Attribution of Malicious Cyber Activities
Disagreed with
IndonesiaCosta Rica DelegateIslamic Republic of IranIsraelMalawi
on: Whether attribution of malicious cyber activities should be addressed through multilateral mechanisms or existing state practice
127
WPM
466
Words
4 min
Time
Iran recognises that the purposes and principles of the UN Charter and generally accepted principles of international law apply to the use of ICTs by states
Arg. 1
Explanation
Iran fully recognises that the purposes and principles of the UN Charter, as well as the generally accepted principles of international law, apply to the use of ICTs by states. They note that the OEWG process has reaffirmed broad agreement on this fundamental point.
Evidence
Iran states that its delegation fully recognises that the purposes and principles of the UN Charter, as well as the generally accepted principles of international law, apply to the use of ICTs by states . They note that the OEWG process has reaffirmed broad agreement on this fundamental point, including with respect to the principles of sovereignty, sovereign equality, the prohibition of the threat or use of force, territorial integrity, the peaceful settlement of disputes, non-intervention, and the good faith fulfilment of obligations under international law .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Iran argues that the question of additional legally binding obligations cannot be deferred indefinitely, as the mandate of the global mechanism explicitly envisages their development
Arg. 2
Explanation
Iran argues that the unique characteristics of ICTs create legal and practical challenges that require additional legal rules, and that the question of additional legally binding obligations cannot be deferred indefinitely. They note that the mandate of the global mechanism explicitly envisages the development of additional legally binding obligations.
Evidence
Iran argues that the unique characteristics of ICTs, including their cross-border nature, the anonymity of malicious activities, the complexity of attribution, and the increasing involvement of private sector actors, create legal and practical challenges that require additional legal rules . They also note that the successful negotiation of the UN Convention Against Cybercrime demonstrates that states have already recognised the need to develop new legally binding international rules , and that the mandate of the global mechanism explicitly envisages the development of additional legally binding obligations .
Major Discussion Point
Need for New Legally Binding Instruments vs. Sufficiency of Existing Law
Disagreed with
IsraelRussian FederationCubaSwitzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamEstoniaUnited Kingdom
on: Whether the unique characteristics of cyberspace require entirely new legal frameworks or merely careful application of existing law
Iran notes that the anonymity of malicious activities and the complexity of attribution create legal and practical challenges that require additional legal rules
Arg. 3
Explanation
Iran argues that recognising that generally accepted principles of international law apply does not by itself resolve all legal questions arising in the ICT environment. The unique characteristics of ICTs, including anonymity and the complexity of attribution, create legal and practical challenges that require additional legal rules.
Evidence
Iran states that recognising that generally accepted principles of international law apply does not by itself resolve all legal questions arising in the ICT environment . The unique characteristics of ICTs, including their cross-border nature, the anonymity of malicious activities, the complexity of attribution, and the increasing involvement of private sector actors, create legal and practical challenges that require additional legal rules .
Major Discussion Point
Attribution of Malicious Cyber Activities
113
WPM
194
Words
2 min
Time
The African Group reaffirms that international law, including the UN Charter, applies to the use of ICTs and remains essential to maintaining international peace, security, and stability
Arg. 1
Explanation
The African Group reaffirms that international law, including the UN Charter, applies to the use of ICTs by states and remains essential to maintaining international peace, security, and stability in cyberspace. They note that African member states have advanced a common understanding through the adoption of the Common African Position.
Evidence
The African Group reaffirms that international law, including the Charter of the United Nations, applies to the use of ICTs by states and remains essential to maintaining international peace, security, and stability in cyberspace . They note that African member states have advanced a common understanding through the adoption of the Common African Position on the Application of International Law to the Use of ICT in Cyberspace .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
The African Group encourages the global mechanism to support capacity building for legal, diplomatic, and technical experts, and to facilitate exchanges of national and regional experiences
Arg. 2
Explanation
The African Group believes that regional and continental perspectives enrich global discussions on the application of international law and underscores the importance of strengthening legal capacity, particularly in developing countries. They encourage the global mechanism to support capacity building and facilitate exchanges of national and regional experiences.
Evidence
The African Group states that regional and continental perspectives enrich global discussions on the application of international law and underscore the importance of strengthening legal capacity, particularly in developing countries, to enable informed participation and effective implementation . They encourage the global mechanism to support capacity building for legal, diplomatic, and technical experts, facilitate exchanges of national and regional experiences and practice, promote dialogue among legal, diplomatic, and technical communities, and strengthen cooperation with regional and sub-regional organisations .
Major Discussion Point
Capacity Building on International Law
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaItalyKiribatiAustriaMalawiSingaporeNew ZealandIsraelEstoniaArmeniaNetherlandsGermanyMauritiusVanuatuCanadaIrelandAlbaniaIndonesiaBotswanaThailand
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
The Netherlands affirms that the mechanism should build on the common understanding that international law applies to cyberspace in its entirety
Arg. 1
Explanation
The Netherlands affirms that the mechanism should build on the existing acquis, including the common understanding that international law applies to cyberspace in its entirety. Rather than revisiting areas where consensus has already been reached, they call for attention to the practical application of international law and the tools it provides to deal with real-world threats.
Evidence
The Netherlands states that the mechanism should build on the existing acquis, including the common understanding that international law applies to cyberspace in its entirety . Rather than revisiting areas where consensus has already been reached, they call for attention to the practical application and the tools that international law provides to deal with real-world threats .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
The Netherlands supports further analysis of IHL application to malicious cyber activities targeting critical infrastructure, medical facilities, and humanitarian organisations
Arg. 2
Explanation
The Netherlands supports further analysis of IHL application to malicious cyber activities targeting critical infrastructure, medical facilities, and humanitarian and international organisations. They note that the law of state responsibility can provide states with options to respond to such threats.
Evidence
The Netherlands notes that malicious cyber activities targeting critical infrastructure can be addressed through rules and principles such as sovereignty and non-intervention, as well as IHL during armed conflict . They also note that other threats that could benefit from further analysis are ransomware and malicious cyber activities targeting or impacting medical facilities and humanitarian and international organisations, and that the law of state responsibility can provide states with options to respond to such threats .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
The Netherlands affirms that the integrated, policy-oriented, and cross-cutting nature of DTG1 lends itself to discussions on the practical application of international law to real-world threats
Arg. 3
Explanation
The Netherlands affirms that the integrated, policy-oriented, and cross-cutting nature of DTG1 lends itself to discussions on the practical application of international law to real-world threats. They also note that discussions could draw from work taking place outside the forum, for instance by the ICRC.
Evidence
The Netherlands states that the integrated, policy-oriented, and cross-cutting nature of DGT-1 lends itself to discussions on the practical application of international law to real-world threats . They also note that discussions could draw from work taking place outside the forum, for instance by the ICRC on the implication of IHL in cyberspace .
Major Discussion Point
Role of Dedicated Thematic Groups (DTGs) in Advancing International Law Discussions
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumItalyKiribatiAustriaJapanCanadaIrelandUkraineAlbania
on: Scenario-based and practice-oriented discussions should be used within the dedicated thematic groups to deepen understanding of how international law applies in practice
Capacity building is vital to allow for the participation of all states and to bridge the gap between technical, policy, and legal experts
Arg. 4
Explanation
The Netherlands echoes many states that have stressed the continued importance of capacity building on international law. They affirm that capacity building is vital to allow for the participation of all states and to bridge the gap between technical, policy, and legal experts.
Evidence
The Netherlands echoes the many states that have stressed the continued importance of capacity building on international law, stating that capacity building is vital to allow for the participation of all states and is needed to bridge the gap between technical, policy, and legal experts . They also note that the Kingdom of the Netherlands stands ready to share its own experiences in developing a national position on the application of international law in cyberspace .
Major Discussion Point
Capacity Building on International Law
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaItalyKiribatiAustriaMalawiSingaporeNew ZealandIsraelEstoniaArmeniaNigeria Nigeria on behalf of the Africa GroupGermanyMauritiusVanuatuCanadaIrelandAlbaniaIndonesiaBotswanaThailand
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
129
WPM
671
Words
5 min
Time
Brazil affirms that international law, including the UN Charter, IHRL, and IHL, is fully applicable to states' use of ICTs
Arg. 1
Explanation
Brazil affirms that international law is an essential part of the maintenance of an open, secure, stable, peaceful, accessible, and interoperable ICT environment. They note that the General Assembly recognised over a decade ago that international law, including the UN Charter, IHRL, and IHL, is fully applicable to states' use of ICTs.
Evidence
Brazil states that international law is an essential part of the maintenance of an open, secure, stable, peaceful, accessible, and interoperable ICT environment . They note that the General Assembly rightfully recognised over a decade ago that international law, including the UN Charter, IHRL, and IHL, is fully applicable to states’ use of ICTs .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Brazil affirms that IHL applies to situations amounting to armed conflict independently of its classification; recognising this does not endorse militarisation or legitimise cyber warfare
Arg. 2
Explanation
Brazil affirms that IHL applies to situations amounting to armed conflict independently of its classification as such by the parties. They argue that recognising IHL applies to cyberspace does not in any way endorse its militarisation or legitimise cyber warfare, as the objective of IHL is to minimise human suffering.
Evidence
Brazil states that IHL applies to situations amounting to armed conflict independently of its classification as such by the parties, because its objective is to minimise human suffering and provide a minimum level of protection to civilians in any scenario of hostilities . They argue that the recognition that IHL applies to cyberspace does not in any way endorse its militarisation or legitimise cyber warfare, and that if that were the case, the very existence of IHL itself would legitimise the use of force .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
Disagreed with
CubaChinaVenezuelaSwitzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustriaIrelandMexicoVanuatuAlbania
on: Whether International Humanitarian Law (IHL) automatically and fully applies to cyberspace
Brazil recognises that as debates evolve, there may be a need to discuss specific legally binding obligations to bring greater clarity, and sees no contradiction between existing law and eventual lex specialis
Arg. 3
Explanation
Brazil recognises that as debates evolve, there may be a need to specifically discuss legally binding obligations to bring greater clarity to all states on international law application to cyberspace. They argue there is no contradiction between the applicability of existing international law and the eventual development of lex specialis, or between binding obligations and voluntary norms.
Evidence
Brazil states that as debates evolve, there may be a need to specifically discuss legally binding obligations to bring greater clarity to all states on international law application to cyberspace . They argue that there is no contradiction between the applicability of currently internationalised cyberspace and the eventual lex specialis on the subject, or between binding obligations and voluntary norms, which are complementary and mutually reinforcing .
Major Discussion Point
Need for New Legally Binding Instruments vs. Sufficiency of Existing Law
Brazil, as one of the first countries to publish its national position, welcomes the increasing number of national positions and hopes to see many more, especially from developing countries
Arg. 4
Explanation
Brazil, as one of the first countries to publish its national position on the applicability of international law in cyberspace, welcomes the increasing number of national positions that have been published and hopes to see many more, especially from the international community. They note that a plethora of national perspectives would enrich collective understanding.
Evidence
Brazil states that as one of the first countries to publish its national position on the applicability of international law in cyberspace, it welcomes the increasing number of national positions that have been published and hopes to see many more in the near future, especially from the international community . They note that a plethora of national perspectives would enrich collective understanding in this field .
Major Discussion Point
Publication of National and Regional Positions on International Law
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoItalyRepublic of KoreaNew ZealandEstoniaUnited KingdomMexicoMauritiusCanadaIrelandThailandSingapore
on: Publishing national and regional positions on the application of international law to cyberspace contributes to transparency, predictability, and common understanding
Germany reaffirms that successive consensus reports of GGEs and OEWGs have confirmed that international law applies to cyberspace
Arg. 1
Explanation
Germany reaffirms that successive consensus reports of the GGEs and open-ended working groups and the General Assembly have affirmed and consistently reaffirmed that international law applies to cyberspace. They note that the common task for the global mechanism is to deepen common understanding of how it applies in practice.
Evidence
Germany states that successive consensus reports of the GGEs and open-ended working groups and the General Assembly have affirmed and consistently reaffirmed that international law applies to cyberspace . They note that the common task for the global mechanism is therefore to deepen common understanding of how it applies in practice .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamUruguayAustriaMalawiEstoniaUnited KingdomArmeniaCanadaIrelandUkraineVanuatu
on: The global mechanism should build on the progress and common understandings established by previous GGEs and OEWGs rather than starting from scratch
Germany affirms that international law is a priority for its cyber capacity-building engagement, and that all states should be able to participate on an equal footing
Arg. 2
Explanation
Germany highlights the need for capacity building on international law, noting from its own experience that drafting a national position can be demanding, time-consuming, and requires a lot of coordination. They affirm that international law is a priority for Germany's partnerships and cyber capacity-building engagement.
Evidence
Germany notes from its own experience that drafting a national position can be demanding, time-consuming, and requires a lot of coordination . They state that this is why international law is a priority for Germany’s partnerships and cyber capacity-building engagement, and that it is important that all states can participate on an equal footing at discussions .
Major Discussion Point
Capacity Building on International Law
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaItalyKiribatiAustriaMalawiSingaporeNew ZealandIsraelEstoniaArmeniaNigeria Nigeria on behalf of the Africa GroupNetherlandsMauritiusVanuatuCanadaIrelandAlbaniaIndonesiaBotswanaThailand
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
121
WPM
625
Words
5 min
Time
Mauritius remains committed to promoting a common understanding of how international law applies in cyberspace
Arg. 1
Explanation
Mauritius remains committed to the continued exchange of national views and practices to promote a common understanding of how international law applies in cyberspace. They note that developing a national position on the application of international law in cyberspace represents an important step towards strengthening legal certainty and enhancing transparency.
Evidence
Mauritius states that it remains committed to the continued exchange of national views and practices to promote a common understanding of how international law applies in cyberspace . They note that developing a national position on the application of international law in cyberspace represents an important step towards strengthening legal certainty, enhancing transparency, and contributing to international dialogue .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Mauritius affirms that developing a national position on international law is itself a valuable capacity-building process, strengthening institutional knowledge and promoting dialogue among legal, technical, diplomatic, and policy communities
Arg. 2
Explanation
Mauritius affirms that developing a national position on international law is not merely a legal drafting exercise but a valuable capacity-building process. It strengthens institutional knowledge, promotes dialogue among legal, technical, diplomatic, and policy communities, and builds a common national understanding of the legal issues arising from the use of ICTs.
Evidence
Mauritius states that the process of developing its national position has demonstrated that this is not merely a legal drafting exercise but a valuable capacity-building process that strengthens institutional knowledge, promotes dialogue among legal, technical, diplomatic, and policy communities, and builds a common national understanding of the legal issues arising from the use of ICTs . They also note that this achievement was made possible through the invaluable support of UNIDIR, whose technical expertise, guidance, and capacity-building support enabled an inclusive national process .
Major Discussion Point
Capacity Building on International Law
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaItalyKiribatiAustriaMalawiSingaporeNew ZealandIsraelEstoniaArmeniaNigeria Nigeria on behalf of the Africa GroupNetherlandsGermanyVanuatuCanadaIrelandAlbaniaIndonesiaBotswanaThailand
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
Mauritius has undertaken the development of its national position on the application of international law in cyberspace, currently undergoing approval processes prior to publication
Arg. 3
Explanation
Mauritius has undertaken the development of its national position on the application of international law in cyberspace, which is currently undergoing the necessary approval processes prior to its publication. They note that their national position reflects their specific national context and priorities as a small island developing state.
Evidence
Mauritius states that it has undertaken the development of its national position on the application of international law in cyberspace, which is currently undergoing the necessary approval processes prior to its publication . They note that their national position reflects their specific national context and priorities as a small island developing state .
Major Discussion Point
Publication of National and Regional Positions on International Law
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoItalyRepublic of KoreaNew ZealandEstoniaUnited KingdomMexicoBrazilCanadaIrelandThailandSingapore
on: Publishing national and regional positions on the application of international law to cyberspace contributes to transparency, predictability, and common understanding
125
WPM
219
Words
2 min
Time
Venezuela questions the full and automatic applicability of international norms to cyberspace, arguing that international law needs to be carefully adapted to the specific characteristics of ICTs
Arg. 1
Explanation
Venezuela questions the full and automatic applicability of international norms to the use of ICTs, arguing that international law and IHL are not automatically applicable to cyberspace. They argue there is a need to critically explore how such law applies to this sphere in particular, given the specific characteristics of this technology.
Evidence
Venezuela states that it questions the full and automatic applicability of international norms to the use of ICTs, and that international law and IHL are not automatically applicable to cyberspace or virtual space . They argue there is a need to continue assessing how exactly it should apply, and that there is a need to critically explore how such law applies to this sphere in particular .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Disagreed with
CubaChinaSwitzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustriaIrelandBrazilMexicoVanuatuAlbania
on: Whether International Humanitarian Law (IHL) automatically and fully applies to cyberspace
Venezuela believes the creation of a legally binding comprehensive framework is not only necessary but also part of the mandate of the former OEWG
Arg. 2
Explanation
Venezuela believes that the creation of a legally binding comprehensive framework is not only necessary but also part of the mandate of the former OEWG. They also argue that this legally binding framework should be based on the five pillars of the permanent mechanism.
Evidence
Venezuela states that it believes the creation of a legally binding framework of comprehensive scope is not only necessary, but also part of the mandate of the former OEWG . They also believe that this legally binding framework should be based on the five pillars of the permanent mechanism as set out in the last annual report .
Major Discussion Point
Need for New Legally Binding Instruments vs. Sufficiency of Existing Law
Disagreed with
CubaIslamic Republic of IranChinaRussian FederationRepublic of KoreaIsraelIrelandUkraineFranceNew ZealandTonga on behalf of the Pacific Islands Forum
on: Whether additional legally binding instruments are needed for cyberspace governance
128
WPM
444
Words
3 min
Time
Vanuatu reaffirms that international law, with the UN Charter at its core, applies in full to state conduct in cyberspace
Arg. 1
Explanation
Vanuatu reaffirms that international law, with the Charter of the United Nations at its core, applies in full to state conduct in cyberspace. They argue that for states without armies of scale or arsenals of deterrence, the rule of law is not one security strategy among several but the security strategy.
Evidence
Vanuatu states that for states without armies of scale or arsenals of deterrence, the rule of law is not one security strategy among several but the security strategy . They reaffirm that international law, with the Charter of the United Nations at its core, applies in full to state conduct in cyberspace, including the obligations of respect for sovereignty, the peaceful settlement of disputes, refraining from the threat or use of force, and non-intervention .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamUruguayAustriaMalawiEstoniaUnited KingdomArmeniaGermanyCanadaIrelandUkraine
on: The global mechanism should build on the progress and common understandings established by previous GGEs and OEWGs rather than starting from scratch
Vanuatu reaffirms the applicability of IHL to cyber activities in armed conflict, noting its purpose is humanitarian protection and its affirmation makes conflict less cruel, not more likely
Arg. 2
Explanation
Vanuatu reaffirms the applicability of IHL to cyber activities in armed conflict, noting that IHL's purpose is humanitarian protection and that its affirmation makes conflict less cruel, not more likely. They also reaffirm the applicability of IHRL to the online sphere.
Evidence
Vanuatu reaffirms the applicability of IHRL to the online sphere and of IHL to cyber activities in armed conflict, noting that IHL is a body of law whose purpose is humanitarian protection and whose affirmation makes conflict less cruel, not more likely .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
Disagreed with
CubaChinaVenezuelaSwitzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustriaIrelandBrazilMexicoAlbania
on: Whether International Humanitarian Law (IHL) automatically and fully applies to cyberspace
Vanuatu underlines that developing national positions is a demanding legal exercise for a small foreign ministry, and that legal capacity building must remain inseparable from this pillar
Arg. 3
Explanation
Vanuatu underlines that developing national positions is itself a demanding legal exercise for a small foreign ministry, and that legal capacity building must therefore remain inseparable from the international law pillar. They support dedicating structured time in the mechanism to working through how the law applies in concrete situations.
Evidence
Vanuatu states that developing national positions is itself a demanding legal exercise for a small foreign ministry, which is why legal capacity building must remain inseparable from this pillar . They support dedicating structured time in the mechanism, including within the thematic groups, to working through how the law applies in concrete situations, so that legal discussion becomes a shared capability rather than a specialist preserve .
Major Discussion Point
Capacity Building on International Law
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaItalyKiribatiAustriaMalawiSingaporeNew ZealandIsraelEstoniaArmeniaNigeria Nigeria on behalf of the Africa GroupNetherlandsGermanyMauritiusCanadaIrelandAlbaniaIndonesiaBotswanaThailand
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
China underscores the role of the UN Charter and its principles as the cornerstone of cyberspace governance, calling on all countries to oppose the use of cyber means for aggression
Arg. 1
Explanation
China underscores the role of the UN Charter and its purposes and principles as the cornerstone of cyberspace governance, especially the principles of sovereign equality, the prohibition of the use or threat of force, peaceful settlement of disputes, and non-interference. They call on all countries to explicitly oppose the use of cyber means to carry out acts of aggression.
Evidence
China states that it must further underscore the role of the UN Charter and its purposes and principles as the cornerstone, especially the principles of sovereign equality, the prohibition of the use or threat of force, peaceful settlement of international disputes, and non-interference in the internal affairs of states . They call on all countries to explicitly oppose the use of cyber means to carry out acts of aggression, and on major countries in particular to use cyber technologies during armed conflicts with caution .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
China argues that the application of IHL in cyberspace must be handled with greater prudence, given inherent legal and technical difficulties and the involvement of large tech companies in geopolitical conflicts
Arg. 2
Explanation
China argues that the application of IHL in cyberspace must be handled with greater prudence, as the inherent legal and technical difficulties in applying IHL in cyberspace remain unresolved. They also note that large tech companies from certain countries are deeply involved in geopolitical conflicts, posing new challenges to the application of IHL.
Evidence
China states that the inherent legal and technical difficulties in applying IHL in cyberspace remain unresolved . They also note that large tech companies from certain countries are deeply involved in geopolitical conflicts, posing new challenges to the application of IHL in cyberspace . China argues that in cyber conflicts, it is already hard to distinguish between peace and war as well as between civilians and combatants, and that the involvement of tech companies makes such a distinction even harder .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
Disagreed with
CubaVenezuelaSwitzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustriaIrelandBrazilMexicoVanuatuAlbania
on: Whether International Humanitarian Law (IHL) automatically and fully applies to cyberspace
China argues that states should discuss and conclude a new international legal instrument to maintain lasting peace and stability in cyberspace, and supports Russia's Convention on International Information Security as a basis for discussion
Arg. 3
Explanation
China argues that states should, in view of the characteristics of ICTs and the evolving landscape, discuss and conclude a new international legal instrument to maintain lasting peace and stability in cyberspace. They support Russia's Convention on International Information Security as a very good basis for discussion.
Evidence
China states that states should, in view of the characteristics of ICTs and the evolving landscape and based on broad participation, discuss and conclude a new international legal instrument . They state that China believes the Convention on International Information Security proposed by Russia can serve as a very good basis for discussion .
Major Discussion Point
Need for New Legally Binding Instruments vs. Sufficiency of Existing Law
Disagreed with
CubaIslamic Republic of IranRussian FederationVenezuelaRepublic of KoreaIsraelIrelandUkraineFranceNew ZealandTonga on behalf of the Pacific Islands Forum
on: Whether additional legally binding instruments are needed for cyberspace governance
134
WPM
345
Words
3 min
Time
France reaffirms commitment to international law and the UN Charter as a cornerstone of the architecture regulating relations between states in cyberspace
Arg. 1
Explanation
France reaffirms its commitment to international law and the UN Charter as a cornerstone of the complex architecture being built to regulate relations between states and to maintain international security and stability in cyberspace. They note that weakening the Charter threatens all states.
Evidence
France states that it remains very committed to international law and the UN Charter, which is a cornerstone of the complex architecture being built to regulate relations between states and to maintain international security and stability in cyberspace . They note that weakening the Charter threatens all states, as Russia is notably doing by waging a war of aggression against Ukraine with devastating effects in both the kinetic and cyber domains .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
France supports the statement by Switzerland on IHL and calls for the forthcoming findings of the ICRC global initiative on IHL and ICTs to be taken into account
Arg. 2
Explanation
France supports the statement made by Switzerland on IHL and calls for the forthcoming findings of the global initiative launched by the ICRC, which has devoted part of its consideration to IHL and the use of ICTs, to be taken into account in the mechanism's work.
Evidence
France states that it supports the statement made by Switzerland on IHL , and calls for the forthcoming findings of the global initiative launched by the ICRC, which has devoted part of its consideration to international law and humanitarian law and the use of ICTs, to be taken into account in the mechanism’s work .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
France considers the debate on new binding standards to be of secondary importance, and regrets that the most fervent defenders of a new treaty are those currently violating existing international law
Arg. 3
Explanation
France considers the debate on new binding standards to be of secondary importance, noting that only a few member states think this is a priority. They also regret that the most fervent defenders of a new treaty are precisely those who are today trampling existing international law underfoot.
Evidence
France states that the debate on new binding standards is for it of secondary importance, and that it understands that just a few member states think this is a priority . They also regret that the most fervent defenders of a new treaty are precisely those who are today trampling existing international law underfoot .
Major Discussion Point
Need for New Legally Binding Instruments vs. Sufficiency of Existing Law
Disagreed with
CubaIslamic Republic of IranChinaRussian FederationVenezuelaRepublic of KoreaIsraelIrelandUkraineNew ZealandTonga on behalf of the Pacific Islands Forum
on: Whether additional legally binding instruments are needed for cyberspace governance
103
WPM
134
Words
1 min
Time
Japan affirms the consensus that existing international law applies in cyberspace, based on OEWG discussions
Arg. 1
Explanation
Japan affirms that through discussions in the OEWG, there is a consensus among all UN member states that existing international law applies in cyberspace. They call for practical and concrete discussions on how existing international law applies, with a focus on responding to specific incidents.
Evidence
Japan states that through discussions in the OEWG, there is a consensus among all UN member states that existing international law applies in cyberspace . They note that in the global mechanism, based on this consensus, it is important to facilitate practical and concrete discussions on how existing international law applies, with a focus on responding to specific incidents such as cyber attacks on critical infrastructure .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Japan considers it important to facilitate practical and concrete discussions on how existing international law applies, with a focus on responding to specific incidents such as cyber attacks on critical infrastructure
Arg. 2
Explanation
Japan considers it important to facilitate practical and concrete discussions on how existing international law applies, with a focus on responding to specific incidents such as cyber attacks on critical infrastructure. They also consider it an option to deepen discussions in light of the application of responsibility of states for internationally wrongful acts.
Evidence
Japan states that it is important to facilitate practical and concrete discussions on how existing international law applies, with a focus on responding to specific incidents such as cyber attacks on critical infrastructure . They consider it an option to deepen discussions in light of the application of responsibility of states for internationally wrongful acts .
Major Discussion Point
Deepening Common Understanding of How International Law Applies in Practice
Japan hopes that through expert briefings and interactive, practical discussions in DTG1, member states' awareness and understanding of the specific application of existing international law will be deepened
Arg. 3
Explanation
Japan hopes that through expert briefings and interactive, practical, and concrete discussions in DTG1, member states' awareness and understanding of the specific application of existing international law will be deepened further.
Evidence
Japan states that in DTG1, it hopes that through expert briefings and interactive, practical, and concrete discussions, member states’ awareness and understandings of the specific application of existing international law will be deepened further .
Major Discussion Point
Role of Dedicated Thematic Groups (DTGs) in Advancing International Law Discussions
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumItalyKiribatiAustriaCanadaIrelandUkraineAlbaniaNetherlands
on: Scenario-based and practice-oriented discussions should be used within the dedicated thematic groups to deepen understanding of how international law applies in practice
105
WPM
437
Words
4 min
Time
Canada affirms that the challenge is no longer whether international law applies in cyberspace, but how to deepen common understanding of its practical application
Arg. 1
Explanation
Canada affirms that thanks to several years of sustained engagement, states have moved well beyond the initial debates, and the challenge is no longer whether international law applies in cyberspace. Rather, the task is to continue deepening common understanding of its practical application.
Evidence
Canada states that thanks to several years of sustained engagement, states have moved well beyond the initial debates, and the challenge before them is therefore no longer whether international law applies in cyberspace, as there is now a widely recognised consensus on this point . Rather, the task is to continue deepening common understanding of its practical application .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamUruguayAustriaMalawiEstoniaUnited KingdomArmeniaGermanyIrelandUkraineVanuatu
on: The global mechanism should build on the progress and common understandings established by previous GGEs and OEWGs rather than starting from scratch
Canada affirms that capacity building should remain a central and necessary element for the success of the international law pillar, assisting states in developing national positions and improving practical implementation
Arg. 2
Explanation
Canada affirms that capacity building should remain a central and necessary element for the success of the international law pillar. Efforts in this area should be needs-based and should continue to assist states in developing national positions, strengthening participation in discussions, and improving practical implementation.
Evidence
Canada states that capacity building should remain a central and necessary element for the success of this pillar, and that efforts in this area should be needs-based and should continue to assist states in developing national positions, strengthening participation in discussions, and improving practical implementation .
Major Discussion Point
Capacity Building on International Law
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaItalyKiribatiAustriaMalawiSingaporeNew ZealandIsraelEstoniaArmeniaNigeria Nigeria on behalf of the Africa GroupNetherlandsGermanyMauritiusVanuatuIrelandAlbaniaIndonesiaBotswanaThailand
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
Canada affirms that the continued publication of national positions and regional approaches has contributed significantly to building common understandings
Arg. 3
Explanation
Canada affirms that the continued publication of national positions and regional approaches has already contributed significantly to building common understandings. They call for open and inclusive dialogue to continue in this regard.
Evidence
Canada states that the continued publication of national positions and regional approaches have already contributed significantly to building common understandings, and that open and inclusive dialogue should continue in this regard .
Major Discussion Point
Publication of National and Regional Positions on International Law
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoItalyRepublic of KoreaNew ZealandEstoniaUnited KingdomMexicoBrazilMauritiusIrelandThailandSingapore
on: Publishing national and regional positions on the application of international law to cyberspace contributes to transparency, predictability, and common understanding
Canada believes the dedicated thematic groups provide an ideal platform for informal exchanges on concrete cases, including through encouraging participation of both government and non-governmental legal experts
Arg. 4
Explanation
Canada believes the global mechanism should focus on substantive discussions and implementation, including through integrated discussions on real-world cyber challenges. The dedicated thematic groups provide an ideal platform for informal exchanges on concrete cases, including through encouraging the participation of both government and non-governmental legal experts.
Evidence
Canada states that the global mechanism should focus on substantive discussions and implementation, including through integrated discussions on real-world cyber challenges such as ransomware attacks affecting hospitals and malicious cyber activities targeting critical infrastructure . They note that the dedicated thematic groups provide an ideal platform for informal exchanges on such concrete cases, including through encouraging the participation of both government and non-governmental legal experts .
Major Discussion Point
Role of Dedicated Thematic Groups (DTGs) in Advancing International Law Discussions
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumItalyKiribatiAustriaJapanIrelandUkraineAlbaniaNetherlands
on: Scenario-based and practice-oriented discussions should be used within the dedicated thematic groups to deepen understanding of how international law applies in practice
132
WPM
577
Words
4 min
Time
Ireland affirms that the application of international law in cyberspace, including the UN Charter, IHRL, IHL, and state responsibility law, is an objective legal fact
Arg. 1
Explanation
Ireland affirms that the application of international law in cyberspace, in particular the UN Charter, IHRL, IHL, and the law on state responsibility, is an objective legal fact. They strongly disagree with any suggestion that affirming the application of IHL to cyberspace encourages or legitimises the militarisation of cyberspace.
Evidence
Ireland states that the application of international law in cyberspace, in particular the UN Charter, IHRL, IHL, and the law on state responsibility, is an objective legal fact . They strongly disagree with any suggestion that affirming the application of IHL to cyberspace encourages or legitimises the militarisation of cyberspace, noting that IHL is concerned with limiting the suffering caused by armed conflict rather than with the justifiability of the initiation of the conflict .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamUruguayAustriaMalawiEstoniaUnited KingdomArmeniaGermanyCanadaUkraineVanuatu
on: The global mechanism should build on the progress and common understandings established by previous GGEs and OEWGs rather than starting from scratch
Ireland strongly disagrees with any suggestion that affirming the application of IHL to cyberspace encourages or legitimises the militarisation of cyberspace
Arg. 2
Explanation
Ireland strongly disagrees with any suggestion that affirming the application of IHL to cyberspace encourages or legitimises the militarisation of cyberspace. They argue that IHL is concerned with limiting the suffering caused by armed conflict and mitigating its effects, rather than with the justifiability of the initiation of the conflict.
Evidence
Ireland states that it strongly disagrees with any suggestion that affirming the application of IHL to cyberspace encourages or legitimises the militarisation of cyberspace . They note that IHL is concerned with limiting the suffering caused by armed conflict and mitigating its effects rather than with the justifiability of the initiation of the conflict, and that the application of IHL in cyberspace ensures that gaps in legal protection are minimised, especially the protection of civilians and civilian objects .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
Disagreed with
CubaChinaVenezuelaSwitzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustriaBrazilMexicoVanuatuAlbania
on: Whether International Humanitarian Law (IHL) automatically and fully applies to cyberspace
Ireland considers that any call for new legally binding rules would be premature; the priority should be to consolidate shared understanding, as it is not evident that there are significant gaps in the law itself
Arg. 3
Explanation
Ireland considers that any call for new legally binding rules would be premature, and that the priority should instead be to consolidate shared understanding. They note that whilst there may be gaps in shared understanding of the law, it is not evident at this stage that there are significant gaps in the law itself.
Evidence
Ireland states that whilst there may be gaps in shared understanding of the law, it is not evident at this stage that there are significant gaps in the law itself . They therefore consider that any call for new legally binding rules would be premature, and that the priority should instead be to consolidate shared understanding .
Major Discussion Point
Need for New Legally Binding Instruments vs. Sufficiency of Existing Law
Disagreed with
CubaIslamic Republic of IranChinaRussian FederationVenezuelaRepublic of KoreaIsraelUkraineFranceNew ZealandTonga on behalf of the Pacific Islands Forum
on: Whether additional legally binding instruments are needed for cyberspace governance
Ireland notes that over 100 states have now published positions and encourages all states to consider developing a position, either individually or collectively
Arg. 4
Explanation
Ireland notes that there is now real momentum in states developing national positions, with over 100 states having now published positions either individually or as part of a regional group. They encourage all states to consider developing a position, either individually or collectively, and offer to engage informally with any states to share their national experience.
Evidence
Ireland notes that there is now real momentum in states developing national positions, with over 100 states having now published, either individually or as part of a regional group, their positions on international law . They state that the experience of developing their own national position, published in 2023, was a valuable one, and encourage all states to consider developing a position either individually or collectively . Ireland is willing to engage informally with any states in order to share its national experience in preparing a national position .
Major Discussion Point
Publication of National and Regional Positions on International Law
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoItalyRepublic of KoreaNew ZealandEstoniaUnited KingdomMexicoBrazilMauritiusCanadaThailandSingapore
on: Publishing national and regional positions on the application of international law to cyberspace contributes to transparency, predictability, and common understanding
Ireland calls for the mechanism to focus not just on identifying areas of consensus but also areas of convergence to accurately capture progress
Arg. 5
Explanation
Ireland calls for the mechanism to focus not just on identifying areas of consensus but also areas of convergence in order to accurately capture progress. They argue that outcomes of the global mechanism should reflect both areas of consensus and areas of convergence.
Evidence
Ireland states that as it consistently submitted in its statements during the OEWG process, it believes that any outcomes of the global mechanism should focus not just on identifying areas of consensus, but also areas of convergence in order to accurately compare and capture progress .
Major Discussion Point
Deepening Common Understanding of How International Law Applies in Practice
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaItalyKiribatiAustriaMalawiSingaporeNew ZealandIsraelEstoniaArmeniaNigeria Nigeria on behalf of the Africa GroupNetherlandsGermanyMauritiusVanuatuCanadaAlbaniaIndonesiaBotswanaThailand
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
Ireland calls for international law, including IHL, to feature prominently in the substantive work of the DTGs, and welcomes the use of guiding questions, structured discussions, and scenario-based exercises
Arg. 6
Explanation
Ireland calls for international law, including IHL, to feature prominently in the substantive work of the DTGs and plenary. They welcome the use of appropriate working modalities to facilitate a more dynamic exchange of views, including guiding questions, structured discussions, and scenario-based exercises.
Evidence
Ireland calls for international law, including IHL, to feature prominently in the substantive work of the DTGs . They would welcome the use of appropriate working modalities to facilitate a more dynamic exchange of views on international law in the DTGs and plenary, including guiding questions, structured discussions, and scenario-based exercises .
Major Discussion Point
Role of Dedicated Thematic Groups (DTGs) in Advancing International Law Discussions
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumItalyKiribatiAustriaJapanCanadaUkraineAlbaniaNetherlands
on: Scenario-based and practice-oriented discussions should be used within the dedicated thematic groups to deepen understanding of how international law applies in practice
124
WPM
245
Words
2 min
Time
Turkey reaffirms that existing international law applies to state conduct in the ICT environment, with the UN Charter as the cornerstone
Arg. 1
Explanation
Turkey considers it essential to preserve a rules-based, open, secure, stable, accessible, and peaceful ICT environment, and reaffirms that existing international law applies to state conduct in the ICT environment. They note that the UN Charter remains the cornerstone of the international legal order.
Evidence
Turkey states that cyberspace cannot be regarded as a legal vacuum, and that although rules and understandings specific to cyberspace are still emerging, it may be reaffirmed that existing international law applies to state conduct in the ICT environment . They note that the UN Charter remains the cornerstone of the international legal order, with its purposes and principles equally relevant in the ICT context .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
134
WPM
1055
Words
8 min
Time
Russia's intervention qualifies as an act of intentional disinformation and information manipulation, being over-exaggeratedly emotional with a lack of factual reference; Ukraine calls for it to be reported and not disseminated
Arg. 1
Explanation
Ukraine argues that Russia's intervention the previous day qualifies as an act of intentional disinformation and information manipulation, being over-exaggeratedly emotional with elaborated epithets and a lack of factual reference. Ukraine calls for the case of attempted disinformation to be reported so it will not be disseminated.
Evidence
Ukraine states that Russia’s intervention was over-exaggeratedly emotional, with elaborated epithets and lack of factual reference, which is a clear sign of a potential disinformation attempt . Ukraine calls for the case of attempted disinformation, namely Russia’s intervention of yesterday, to be reported so it will not be disseminated .
Major Discussion Point
Disinformation and Information Manipulation as a Cyber Threat
The international criminal court has issued warrants of arrest for Russian top officials including Putin for the crime of aggression; Russia temporarily occupies under 20% of Ukrainian territory, recognised as Ukrainian by numerous General Assembly resolutions
Arg. 2
Explanation
Ukraine presents a series of facts as part of its fact-checking of Russia's intervention, including that the ICC has issued warrants of arrest for Russian top officials including Putin for the crime of aggression, and that Russia temporarily occupies under 20% of Ukrainian territory, recognised as Ukrainian by numerous General Assembly resolutions.
Evidence
Ukraine states that the ICC has issued a number of warrants of arrest for Russian top officials inclusive of Putin for the crime of aggression . Ukraine also notes that Russia temporarily occupies under 20% of Ukrainian territory, and that these territories are recognised by the international community as Ukrainian, as stated in numerous General Assembly resolutions .
Major Discussion Point
Disinformation and Information Manipulation as a Cyber Threat
Russia maintains a permissive environment for criminal cyber ecosystems to flourish on temporarily occupied territories of Ukraine
Arg. 3
Explanation
Ukraine argues that unlike the occupational administrations of the Russian Federation, which act as they please on the temporarily occupied territories of Ukraine, this maintains a permissive environment for criminal cyber ecosystems to flourish.
Evidence
Ukraine states that unlike the occupational administrations of the Russian Federation, which act as they please on the temporarily occupied territories of Ukraine, this maintains a permissive environment for criminal cyber ecosystems to flourish .
Major Discussion Point
Disinformation and Information Manipulation as a Cyber Threat
Ukraine reaffirms its support for the framework under which international law, in particular the UN Charter in its entirety, is applicable to the use of ICTs by states
Arg. 4
Explanation
Ukraine reaffirms its unwavering support for the cumulative framework developed within the United Nations, under which international law, in particular the UN Charter in its entirety, is applicable to the use of ICTs by states. They note that the international community has repeatedly reaffirmed that existing international law provides a comprehensive legal framework governing state conduct in the ICT environment.
Evidence
Ukraine reaffirms its unwavering support for the cumulative framework developed within the United Nations, under which international law, in particular the Charter of the United Nations in its entirety, is applicable to the use of ICTs by states . They note that the international community has repeatedly reaffirmed that existing international law provides a comprehensive legal framework governing state conduct in the ICT environment and remains essential for maintaining international peace and security .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamUruguayAustriaMalawiEstoniaUnited KingdomArmeniaGermanyCanadaIrelandVanuatu
on: The global mechanism should build on the progress and common understandings established by previous GGEs and OEWGs rather than starting from scratch
Disagreed with
Russian Federation
on: Whether Russia's intervention constituted disinformation and information manipulation
Ukraine does not support efforts aimed at developing new legally binding or non-binding international rules governing state behaviour in cyberspace at this stage
Arg. 5
Explanation
Ukraine does not support efforts aimed at developing new legally binding or non-binding international rules governing state behaviour in cyberspace at this stage. They argue that the collective priority should be to deepen common understanding of how existing international law applies in practice and to strengthen its faithful implementation.
Evidence
Ukraine states that it does not support efforts aimed at developing new legally binding or non-binding international rules governing state behaviour in cyberspace . They argue that at this stage, the collective priority should be to deepen the common understanding of how international law that exists applies in practice and to strengthen its faithful implementation .
Major Discussion Point
Need for New Legally Binding Instruments vs. Sufficiency of Existing Law
Disagreed with
CubaIslamic Republic of IranChinaRussian FederationVenezuelaRepublic of KoreaIsraelIrelandFranceNew ZealandTonga on behalf of the Pacific Islands Forum
on: Whether additional legally binding instruments are needed for cyberspace governance
Ukraine affirms that accountability must remain an integral element of the rules-based international order in cyberspace, and calls for strengthening international cooperation on attribution and promoting transparency regarding malicious cyber activities
Arg. 6
Explanation
Ukraine affirms that accountability must remain an integral element of the rules-based international order in cyberspace, and that international law cannot effectively contribute to stability if its violations remain without consequences. They call for strengthening international cooperation on attribution and promoting transparency regarding malicious cyber activities.
Evidence
Ukraine states that accountability must remain an integral element of the rules-based international order in cyberspace, and that international law cannot effectively contribute to stability if its violations remain without consequences . They call for strengthening international cooperation on attribution, promoting transparency regarding malicious cyber activities, and ensuring that violations of international law do not become normalised . They also note that systematic malicious cyber activities conducted as part of the war of aggression waged against Ukraine by a certain P5 member state clearly demonstrate the importance of ensuring accountability for violations of international law committed in and through cyberspace .
Major Discussion Point
Attribution of Malicious Cyber Activities
Ukraine believes discussions within the global mechanism should focus on improving states' common understanding of the application of existing international law, exchanging national views and practices
Arg. 7
Explanation
Ukraine believes that discussions within the global mechanism should focus on improving states' common understanding of the application of existing international law, exchanging national views and practices, and strengthening legal capacity across all regions. They also suggest in-depth discussions on the cybersecurity of healthcare and energy infrastructure.
Evidence
Ukraine states that discussions within the global mechanism should focus on improving states’ common understanding of the application of existing international law, exchanging national views and practices, and strengthening legal capacity across all regions . They suggest in-depth discussions on the cybersecurity of healthcare infrastructure and energy infrastructure against cyber attacks, noting that in the digital age, internet coverage, data accessibility, and access to transport and banking services are dependent on stable access to electricity .
Major Discussion Point
Deepening Common Understanding of How International Law Applies in Practice
Ukraine believes the work of DTG1 could significantly contribute to improving states' common understanding of the application of existing international law
Arg. 8
Explanation
Ukraine believes the work of DTG1 could significantly contribute to improving states' common understanding of the application of existing international law, also taking into account that international law is complemented by the 11 voluntary norms of responsible state behaviour.
Evidence
Ukraine states that the work of DTG1 could significantly contribute to improving states’ common understanding of the application of existing international law, also taking into account that international law is complemented by the 11 voluntary norms of responsible state behaviour . They support in-depth discussions on the cybersecurity of healthcare infrastructure and energy infrastructure, noting this is cross-cutting in terms of the application of international law and IHL .
Major Discussion Point
Role of Dedicated Thematic Groups (DTGs) in Advancing International Law Discussions
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumItalyKiribatiAustriaJapanCanadaIrelandAlbaniaNetherlands
on: Scenario-based and practice-oriented discussions should be used within the dedicated thematic groups to deepen understanding of how international law applies in practice
110
WPM
459
Words
4 min
Time
Thailand reaffirms its longstanding position that international law, in particular the UN Charter, applies to the use of ICTs
Arg. 1
Explanation
Thailand reaffirms its longstanding position that international law, in particular the UN Charter, applies to the use of ICTs. They remain firmly committed to an international order that is robust and grounded in international law as the most effective means of safeguarding the sovereignty, security, and interests of all states.
Evidence
Thailand reaffirms its longstanding position that international law, in particular the UN Charter, applies to the use of ICTs . They note that the publication of their first-ever National Position on the Application of International Law in Cyberspace last year stands as a clear demonstration of this position .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Thailand published its first-ever National Position on the Application of International Law in Cyberspace last year as a clear demonstration of its commitment
Arg. 2
Explanation
Thailand notes that the publication of its first-ever National Position on the Application of International Law in Cyberspace last year stands as a clear demonstration of its commitment to international law in cyberspace.
Evidence
Thailand states that the publication of its first-ever National Position on the Application of International Law in Cyberspace last year stands as a clear demonstration of its position .
Major Discussion Point
Publication of National and Regional Positions on International Law
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoItalyRepublic of KoreaNew ZealandEstoniaUnited KingdomMexicoBrazilMauritiusCanadaIrelandSingapore
on: Publishing national and regional positions on the application of international law to cyberspace contributes to transparency, predictability, and common understanding
Thailand affirms that promoting a common understanding of international law in cyberspace requires bridging the gap between the legal and ICT communities and addressing remaining capacity gaps among states
Arg. 3
Explanation
Thailand affirms that promoting a common understanding of international law in cyberspace requires bridging the gap between the legal and ICT communities and addressing remaining capacity gaps among states. They note that Thailand co-hosted with UNIDIR a workshop on the implementation of the UN norms of responsible state behaviour in cyberspace.
Evidence
Thailand states that promoting a common understanding of international law in cyberspace also requires bridging the gap between the legal and ICT communities and addressing remaining capacity gaps among states . They note that Thailand co-hosted with UNIDIR a workshop on the implementation of the UN norms of responsible state behaviour in cyberspace in Bangkok earlier that month, which strengthens understanding of how international law applies in cyberspace while also serving as confidence-building and capacity-building measures .
Major Discussion Point
Capacity Building on International Law
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaItalyKiribatiAustriaMalawiSingaporeNew ZealandIsraelEstoniaArmeniaNigeria Nigeria on behalf of the Africa GroupNetherlandsGermanyMauritiusVanuatuCanadaIrelandAlbaniaIndonesiaBotswana
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
Albania reaffirms that international law, including the UN Charter, IHRL, and IHL, fully applies to cyberspace
Arg. 1
Explanation
Albania reaffirms that international law, in particular the UN Charter, IHRL, and IHL, fully applies to cyberspace. They note that a better global understanding of its application contributes to greater transparency, predictability, and accountability in states' conduct.
Evidence
Albania reaffirms that international law, in particular the Charter of the UN, IHRL, and IHL, fully applies to cyberspace . They note that a better global understanding of its application contributes to greater transparency, predictability, and accountability in states’ conduct .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandRussian FederationIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Albania reiterates that IHL applies to cyber operations conducted in the context of armed conflict, and recognises this neither encourages militarisation nor legitimises cyber warfare
Arg. 2
Explanation
Albania reiterates that IHL applies to cyber operations conducted in the context of armed conflict, and recognises that this neither encourages the militarisation of cyberspace nor legitimises cyber warfare. They affirm that the principles of distinction, proportionality, and precaution remain essential.
Evidence
Albania reiterates that IHL applies to cyber operations conducted in the context of armed conflict, and recognises this neither encourages the militarisation of cyberspace nor legitimises cyber warfare . They affirm that the principles of distinction, proportionality, and precaution remain essential, and that civilians and civilian objects must receive the protection under IHL .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
Disagreed with
CubaChinaVenezuelaSwitzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustriaIrelandBrazilMexicoVanuatu
on: Whether International Humanitarian Law (IHL) automatically and fully applies to cyberspace
Albania affirms that differences of interpretation should encourage deeper dialogue to reach common understanding on the application of the UN framework
Arg. 3
Explanation
Albania affirms that differences of interpretation should not be treated as an issue but should encourage deeper dialogue to reach a common understanding on the application of the UN framework already in place. They call for the global mechanism to provide an inclusive and action-oriented forum for advancing these discussions.
Evidence
Albania states that differences of interpretation should not be treated as an issue, but should encourage deeper dialogue to reach a common understanding on the application of the UN framework already in place . They call for the global mechanism to provide an inclusive and action-oriented forum for advancing these discussions, with its plenary session and dedicated thematic groups facilitating focused exchanges on concrete legal questions .
Major Discussion Point
Deepening Common Understanding of How International Law Applies in Practice
Albania supports training, exchanges of national and regional positions, scenario-based exercises, and support for developing national positions as means to create shared understanding
Arg. 4
Explanation
Albania attaches particular importance to cooperation and capacity building, supporting training, exchanges of national and regional positions, scenario-based exercises, and support for developing national positions as means to create shared understanding on how international law applies to cyberspace.
Evidence
Albania states that it attaches particular importance to cooperation and capacity building, and that training, exchanges of national and regional positions, scenario-based exercises, and support for developing national positions can help create shared understanding on how international law applies to cyberspace .
Major Discussion Point
Capacity Building on International Law
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumItalyKiribatiAustriaJapanCanadaIrelandUkraineNetherlands
on: Scenario-based and practice-oriented discussions should be used within the dedicated thematic groups to deepen understanding of how international law applies in practice
104
WPM
483
Words
5 min
Time
Russia affirms that universally recognised principles of international law apply to ICTs, but argues that the unique technical and legal characteristics of cyberspace do not allow automatic and full application of existing norms
Arg. 1
Explanation
Russia affirms that universally recognised principles of international law apply to ICTs, but argues that the unique technical and legal characteristics of cyberspace do not allow automatic and full application of existing norms of international law. They argue that the next logical step should be to develop new international legal instruments.
Evidence
Russia states that the adoption of the UN Convention Against Cybercrime has become indisputable evidence of the demand for global treaties to regulate the digital space, whose unique technical and legal characteristics do not allow automatic and full application of existing norms of international law . They argue that the next logical step should be to develop similar international legal instruments for other aspects of international information security, above all with a view to preventing and peacefully resolving interstate conflicts in the information domain .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaIndonesiaGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Disagreed with
IsraelIslamic Republic of IranCubaSwitzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamEstoniaUnited Kingdom
on: Whether the unique characteristics of cyberspace require entirely new legal frameworks or merely careful application of existing law
Voluntary norms are not a substitute for legally binding obligations; a new international legal instrument is needed to address the unique challenges of the ICT environment
Arg. 2
Explanation
Russia argues that voluntary rules of responsible state behaviour can be observed, but only obligations under international treaties can be implemented. They argue that the concept of implementing rules of behaviour could only be possible after these voluntary rules are transformed into legally binding obligations.
Evidence
Russia states that voluntary rules of responsible state behaviour can be observed, but only obligations under international treaties can be implemented, and therefore the concept of implementing rules of behaviour could only be possible after these voluntary rules are transformed into legally binding obligations . They also note that specific proposals on this matter already exist, presented within the OEWG and the General Assembly in the form of a concept of a UN Convention on International Information Security .
Major Discussion Point
Need for New Legally Binding Instruments vs. Sufficiency of Existing Law
Disagreed with
AustriaUnited KingdomNew ZealandSouth Africa
on: The role and legitimacy of stakeholder participation in the global mechanism
146
WPM
321
Words
2 min
Time
Indonesia reaffirms that international law, including the UN Charter, applies to cyberspace and that existing principles remain fully applicable to states' conduct in the ICT environment
Arg. 1
Explanation
Indonesia reaffirms that international law, in particular the UN Charter, applies to cyberspace and that existing international law principles, including sovereignty, non-intervention, the prohibition of the use of force, and peaceful settlement of disputes, remain fully applicable to states' conduct in the ICT environment.
Evidence
Indonesia reaffirms that international law, in particular the UN Charter, applies to cyberspace and that existing international law principles, including sovereignty, non-intervention, the prohibition of the use of force, and peaceful settlement of disputes, remain fully applicable to states’ conduct in the ICT environment .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationGhanaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Indonesia underscores the need for the global mechanism to address attribution in an objective, transparent manner based on technical standards, ensuring it is never used as a political instrument
Arg. 2
Explanation
Indonesia underscores the need for the global mechanism to address the issue of attribution in an objective, transparent manner based on technical standards and methodologies. They argue that attribution must never be used as a political instrument, as such an approach is essential to maintaining trust and preventing miscalculations.
Evidence
Indonesia underscores the need for the global mechanism to address the issue of attribution in an objective, transparent manner based on technical standards and methodologies . They state that attribution must never be used as a political instrument, and that such an approach is essential to maintaining trust, preventing miscalculations, and ensuring that the application of international law in cyberspace remains fair, non-discriminatory, and respectful of differing capacities of states .
Major Discussion Point
Attribution of Malicious Cyber Activities
Disagreed with
CubaCosta Rica DelegateIslamic Republic of IranIsraelMalawi
on: Whether attribution of malicious cyber activities should be addressed through multilateral mechanisms or existing state practice
Indonesia underscores the need for cooperative capacity building, including training on the application of international law in cyberspace, to ensure its application remains fair, non-discriminatory, and reflective of the needs of all member states
Arg. 3
Explanation
Indonesia underscores the need for cooperative capacity building, including training on the application of international law in cyberspace, to ensure that the application of international law remains fair, non-discriminatory, and reflective of the needs and realities of all member states, particularly developing countries.
Evidence
Indonesia underscores that priorities should be placed on cooperative capacity building, including training on the application of international law in cyberspace, and that strengthening these areas will help ensure that the application of international law remains fair, non-discriminatory, and respectful of differing legal traditions . They note that such exchanges must be non-prescriptive, non-hierarchical, and respectful of differing legal traditions .
Major Discussion Point
Capacity Building on International Law
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaItalyKiribatiAustriaMalawiSingaporeNew ZealandIsraelEstoniaArmeniaNigeria Nigeria on behalf of the Africa GroupNetherlandsGermanyMauritiusVanuatuCanadaIrelandAlbaniaBotswanaThailand
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
110
WPM
269
Words
2 min
Time
Ghana reaffirms that international law, particularly the UN Charter, remains applicable and essential to maintaining international peace, security, and stability in the use of ICTs
Arg. 1
Explanation
Ghana reaffirms that international law, particularly the Charter of the United Nations, remains applicable and essential to maintaining international peace, security, and stability in the use of ICTs. They note that this position is consistent with the Common African Position on the application of international law in the use of ICTs.
Evidence
Ghana reaffirms that international law, particularly the Charter of the United Nations, remains applicable and essential to maintaining international peace, security, and stability in the use of ICTs . They note that this position is consistent with the Common African Position on the application of international law in the use of ICTs .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaPhilippinesBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
Ghana affirms the applicability of IHRL and IHL where applicable, consistent with the Common African Position
Arg. 2
Explanation
Ghana affirms the applicability of IHRL and IHL where applicable, consistent with the Common African Position on the application of international law in the use of ICTs.
Evidence
Ghana affirms the applicability of IHRL and IHL where applicable, noting that this is consistent with the Common African Position on the application of international law in the use of ICTs .
Major Discussion Point
Application of International Humanitarian Law (IHL) to Cyberspace
119
WPM
511
Words
4 min
Time
The Philippines reaffirms the consensus that international law, in particular the UN Charter, applies to the use of ICTs by states
Arg. 1
Explanation
The Philippines reaffirms the consensus reflected in successive reports of the UN GGEs and the OEWG that international law, in particular the UN Charter, applies to the use of ICTs by states and contributes to maintaining international peace, security, and stability in cyberspace.
Evidence
The Philippines reaffirms the consensus reflected in successive reports of the UN GGEs and the OEWG that international law, in particular the Charter of the United Nations, applies to the use of ICTs by states and contributes to maintaining international peace, security, and stability in cyberspace .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaBotswana
on: International law, including the UN Charter, applies to state conduct in cyberspace
The Philippines believes discussions should prioritise practical exchanges on the implementation of international law at the national level, sharing legislation, policies, and operational experiences
Arg. 2
Explanation
The Philippines believes that discussions under the mechanism should prioritise practical exchanges on the implementation of international law at the national level. Sharing national legislation, policies, institutional arrangements, and operational experiences can promote transparency, enhance mutual understanding, and assist member states in strengthening their domestic legal and policy frameworks.
Evidence
The Philippines states that discussions under the mechanism should prioritise practical exchanges on the implementation of international law at the national level, and that sharing national legislation, policies, institutional arrangements, administrative and judicial practices, and operational experiences can promote transparency, enhance mutual understanding, and assist member states in strengthening their domestic legal and policy frameworks . They note that such exchanges are particularly valuable for developing countries seeking to strengthen national cyber resilience .
Major Discussion Point
Deepening Common Understanding of How International Law Applies in Practice
144
WPM
354
Words
2 min
Time
Botswana remains committed to a secure, stable, and peaceful cyberspace governed by international law and the UN Charter
Arg. 1
Explanation
Botswana remains committed to a secure, stable, and peaceful cyberspace governed by international law and the UN Charter. They emphasise that capacity building is indispensable to ensuring that all states, regardless of technological maturity, can meaningfully interpret and apply international law to state practice.
Evidence
Botswana states that it remains committed to a secure, stable, and peaceful cyberspace governed by international law and the UN Charter . They emphasise that capacity building is indispensable to ensuring that all states, regardless of technological maturity, can meaningfully interpret and apply international law to state practice .
Major Discussion Point
Applicability of International Law to Cyberspace
Agreed with
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippines
on: International law, including the UN Charter, applies to state conduct in cyberspace
Botswana highlights the vital importance of the DTGs in bridging the gap between legal principles and technical realities, and commends UNIDIR, the African Union, and SADC for their capacity-building contributions
Arg. 2
Explanation
Botswana highlights the vital importance of the DTGs in bridging the gap between legal principles and technical realities, and in developing practical understandings of how international law applies to cyberspace. They commend UNIDIR, the African Union, and SADC for their contributions in facilitating technical assistance and capacity initiatives.
Evidence
Botswana highlights the vital importance of the DTGs, noting that by convening multidisciplinary experts from the legal, technical, and policy domains, the DTGs will provide an inclusive platform to bridge the gap between legal principles and technical realities . They commend UNIDIR, the African Union, and SADC for their contribution in facilitating technical assistance and capacity initiatives that empower member states to understand how international law applies to cyberspace .
Major Discussion Point
Capacity Building on International Law
Agreed with
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaItalyKiribatiAustriaMalawiSingaporeNew ZealandIsraelEstoniaArmeniaNigeria Nigeria on behalf of the Africa GroupNetherlandsGermanyMauritiusVanuatuCanadaIrelandAlbaniaIndonesiaThailand
on: Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
141
WPM
1424
Words
10 min
Time
The Chair calls for delegations to deliver abridged versions of their statements and submit full versions to eStatements, in order to allow all delegations to be heard
Arg. 1
Explanation
The Chair requests that delegations consider delivering shorter versions of their statements and sending the full version to eStatements and the Chair's team. This is to ensure that all delegations have the opportunity to take the floor under the agenda item on the applicability of international law.
Evidence
The Chair states that there is no predetermined time limit for interventions but that it would be greatly appreciated if delegations would consider delivering an abridged version of their statement and sending the full version to eStatements and to the Chair’s team so that all delegations can be heard .
Major Discussion Point
Meeting Management and Procedure
The Chair announces the agenda item on the continued study of the applicability of international law in the use of ICTs, including consideration of whether gaps exist and possible future elaboration of additional legally binding obligations
Arg. 2
Explanation
The Chair formally introduces the next agenda item, which concerns the continued study of the applicability of international law in the use of ICTs. This includes consideration of whether any gaps exist and whether additional legally binding obligations may be appropriate in the future.
Evidence
The Chair announces that the meeting will move on to the next item, which is the continued study of the applicability of international law in the use of ICTs, including consideration of whether any gaps exist and possible future elaboration of additional legally binding obligations if appropriate .
Major Discussion Point
Applicability of International Law to Cyberspace
The Chair gives the floor to Ukraine for a right of reply in relation to the Russian Federation's intervention from the previous day
Arg. 3
Explanation
The Chair acknowledges a request for a right of reply that was made under the agenda item on voluntary norms, and grants the floor to Ukraine to exercise this right in response to the Russian Federation's intervention from the previous day.
Evidence
The Chair recalls that under the agenda item on voluntary norms there was a request for a right of reply, and gives the floor to the delegation of Ukraine .
Major Discussion Point
Disinformation and Information Manipulation as a Cyber Threat
The Chair informs delegations of the afternoon programme, including a dedicated stakeholder session and the continuation of the speakers list on international law, followed by the agenda item on confidence-building measures
Arg. 4
Explanation
The Chair outlines the afternoon programme, noting that there are still four speakers waiting to speak under the international law agenda item. The afternoon will begin with a dedicated stakeholder session, after which the remaining speakers on international law will be heard, followed by the agenda item on confidence-building measures.
Evidence
The Chair informs delegations that there are still four speakers waiting to speak under the international law agenda item, namely Switzerland, the United States, Australia, and the International Committee of the Red Cross . The Chair notes that at 3pm a dedicated stakeholder session will be convened, after which the speakers list will resume, and when the international law agenda item is concluded, the meeting will move to the next agenda item on developing and applying confidence-building measures .
Major Discussion Point
Meeting Management and Procedure
Session Knowledge Graph
Speakers · Topics · Arguments · Relationships
Interactive graph · embed active
Agreed Points
International law, including the UN Charter, applies to state conduct in cyberspace
Virtually all delegations agreed that international law, including the UN Charter, applies to state conduct in cyberspace. This was the most broadly shared position across the entire discussion. Switzerland stated that ‘international law applies to the use of ICTs’ and that ‘the task before us is to deepen our common understanding of how exactly it applies’ . The UK affirmed that ‘all states have agreed by consensus that international law applies to state conduct in cyberspace’ and that ‘cyberspace is not lawless’ . Canada noted that ‘the challenge before us is therefore no longer whether international law applies in cyberspace’ as ‘there is now a widely recognized consensus on this point’ . Even states with reservations about automatic applicability, such as Russia, Cuba, and Venezuela, acknowledged that principles of international law apply to ICTs, though they differed on the extent and manner of application .
International law, including the UN Charter, applies fully to state conduct in cyberspace, building on GGE and OEWG consensus
International law applies to cyberspace; the Pacific Islands Forum supports a principled approach grounded in the UN Charter, reaffirming applicability of IHL and human rights law
The EU reaffirms full commitment to international law, including the UN Charter, IHRL, IHL, and state responsibility law, as essential to cyber resilience and stability
International law is applicable and essential; states have reaffirmed sovereignty, non-intervention, prohibition of force, and peaceful settlement of disputes as applicable in cyberspace
International law, including the UN Charter, applies to cyberspace; a cyber operation constitutes an internationally wrongful act when attributable to a state and involves a breach of an international obligation
International law is the foundation for preserving international peace, security, and stability, including in the use of ICTs
Cyberspace is not a legal vacuum; international law, including the UN Charter, applies fully to state use of ICTs, encompassing sovereignty, non-intervention, due diligence, IHL, and IHRL
Italy reaffirms that international law, including the UN Charter, state responsibility law, IHRL, and IHL, is fully applicable and relevant in the digital age
The binding duty to protect freedom of expression is central to stability in cyberspace; states must uphold freedom of digital expression, including anonymous expression, across borders
International law must remain the common reference point for cyberspace governance, serving as an indispensable framework of trust rather than a constraint on technological progress
International law, including the UN Charter, applies to cyberspace; sovereign equality, prohibition of force, non-intervention, and peaceful settlement of disputes are Kiribati's only real defences
Austria reaffirms that international law as a whole, including the UN Charter, IHRL, and IHL, applies to state cyber activities
International law remains a cornerstone of responsible state behaviour in cyberspace, with the UN Charter as the principal reference
Singapore affirms that fostering common understanding on the application of international law to ICTs contributes to peace, security, and trust among states
Colombia reaffirms that international law, especially the UN Charter, applies to cyberspace and is essential for maintaining international peace, security, and stability
Existing international law, including the UN Charter, IHL, and IHRL, applies to cyberspace and provides a sufficient legal foundation for governing state conduct
New Zealand reaffirms that international law applies to state conduct in cyberspace, including the UN Charter, state responsibility law, IHL, and IHRL
Israel reiterates its longstanding position that existing international law, including the UN Charter and the law of armed conflict, applies to cyberspace
Estonia affirms that previous UN processes have clearly confirmed that existing international law applies in cyberspace
The UK affirms that all states have agreed by consensus that international law applies to state conduct in cyberspace; cyberspace is not lawless
Armenia reaffirms that international law, including the UN Charter, is applicable in cyberspace and essential to maintaining international peace and security
Mexico reaffirms that international law, including the UN Charter, IHRL, and IHL, applies to the use of ICTs by states
Cuba affirms that the use of ICTs must be fully compatible with the UN Charter and international law, especially sovereignty, territorial integrity, and non-intervention
Iran recognises that the purposes and principles of the UN Charter and generally accepted principles of international law apply to the use of ICTs by states
The African Group reaffirms that international law, including the UN Charter, applies to the use of ICTs and remains essential to maintaining international peace, security, and stability
The Netherlands affirms that the mechanism should build on the common understanding that international law applies to cyberspace in its entirety
Brazil affirms that international law, including the UN Charter, IHRL, and IHL, is fully applicable to states' use of ICTs
Germany reaffirms that successive consensus reports of GGEs and OEWGs have confirmed that international law applies to cyberspace
Mauritius remains committed to promoting a common understanding of how international law applies in cyberspace
Venezuela questions the full and automatic applicability of international norms to cyberspace, arguing that international law needs to be carefully adapted to the specific characteristics of ICTs
Vanuatu reaffirms that international law, with the UN Charter at its core, applies in full to state conduct in cyberspace
China underscores the role of the UN Charter and its principles as the cornerstone of cyberspace governance, calling on all countries to oppose the use of cyber means for aggression
France reaffirms commitment to international law and the UN Charter as a cornerstone of the architecture regulating relations between states in cyberspace
Japan affirms the consensus that existing international law applies in cyberspace, based on OEWG discussions
Canada affirms that the challenge is no longer whether international law applies in cyberspace, but how to deepen common understanding of its practical application
Ireland affirms that the application of international law in cyberspace, including the UN Charter, IHRL, IHL, and state responsibility law, is an objective legal fact
Turkey reaffirms that existing international law applies to state conduct in the ICT environment, with the UN Charter as the cornerstone
Ukraine reaffirms its support for the framework under which international law, in particular the UN Charter in its entirety, is applicable to the use of ICTs by states
Thailand reaffirms its longstanding position that international law, in particular the UN Charter, applies to the use of ICTs
Albania reaffirms that international law, including the UN Charter, IHRL, and IHL, fully applies to cyberspace
Russia affirms that universally recognised principles of international law apply to ICTs, but argues that the unique technical and legal characteristics of cyberspace do not allow automatic and full application of existing norms
Indonesia reaffirms that international law, including the UN Charter, applies to cyberspace and that existing principles remain fully applicable to states' conduct in the ICT environment
Ghana reaffirms that international law, particularly the UN Charter, remains applicable and essential to maintaining international peace, security, and stability in the use of ICTs
The Philippines reaffirms the consensus that international law, in particular the UN Charter, applies to the use of ICTs by states
Botswana remains committed to a secure, stable, and peaceful cyberspace governed by international law and the UN Charter
Policy Context (Knowledge Base)
This consensus is well-established across multiple UN processes. The OEWG 2021-2025 sessions consistently affirmed the applicability of existing international law to cyberspace [S174], and IGF 2023 discussions similarly acknowledged the need to clarify how existing international laws apply to cyberspace [S159]. The UN cybersecurity framework, encompassing norms, confidence-building measures, and capacity development, underpins this position [S173].
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaUruguayCosta Rica DelegateItalyPortugalCameroonKiribatiAustriaMalawiSingaporeColombiaRepublic of KoreaNew ZealandIsraelEstoniaUnited KingdomArmeniaMexicoCubaIslamic Republic of IranNigeria Nigeria on behalf of the Africa GroupNetherlandsBrazilGermanyMauritiusVenezuelaVanuatuChinaFranceJapanCanadaIrelandTurkeyUkraineThailandAlbaniaRussian FederationIndonesiaGhanaPhilippinesBotswana
Legal capacity building is essential to enable all states to participate meaningfully in discussions on the application of international law to cyberspace
There was near-universal agreement that legal capacity building is essential for enabling all states, particularly developing countries and small states, to participate meaningfully in discussions on the application of international law to cyberspace. The Pacific Islands Forum noted that ‘many countries require support to build the legal capacity needed to engage meaningfully in these conversations’ . Kiribati powerfully illustrated this point by noting that its delegation of three people must cover all functions, and that ‘legal capacity building is therefore not a footnote to this pillar but the condition of this pillar being real’ . Malawi argued that ‘the most significant gap before us today is not a gap on international law’ but ‘the gap between legal consensus and practical implementation’ . Germany, Italy, Singapore, the Netherlands, Canada, and many others echoed this call, with Mauritius noting that developing a national position is itself ‘a valuable capacity building process’ .
Legal capacity building should be a practical and cross-cutting priority of the global mechanism, with scenario-based training, regional workshops, peer exchanges, and accessible expert briefings
The EU and its member states continue to support third countries through training and capacity building on the implementation of the UN framework, including on how to develop a national position on international law
Capacity-building efforts, including those advanced through DTG2, should better enable states to meaningfully participate in discussions, develop national positions, and enhance implementation of international law
Discussions held informally with experts from civil society and academia in DTG1 could identify the capacity-building needs of member states, which could then be addressed in DTG2
Italy stresses the importance of supporting capacity-building efforts to ensure all states can participate on an equal footing in developing common understandings of how international law applies
Legal capacity building is the condition of the international law pillar being real; Kiribati reiterates the proposal for scenario-based exercises on international law within the dedicated thematic groups
Austria considers further, more detailed discussions on how existing international law applies to cyber activities as a priority, and believes discussions should be scenario-based and practice-oriented
Malawi affirms that the most significant gap is not in international law itself but between legal consensus and practical implementation, and that closing this gap should be the priority
Singapore affirms that capacity building in international law is an essential part of fostering common understanding on how international law applies in the use of ICTs
New Zealand maintains that meaningful participation by relevant stakeholders, including legal experts and government lawyers from all states, is essential, and supports capacity-building measures
Israel sees value in using the DTGs as a vehicle for capacity building to help states craft, refine, and publish their legal positions
Estonia set out its first national position in 2019 and encourages other states to articulate, share, and regularly update their national views
Armenia underscores the importance of promoting a shared understanding of the application of international law in cyberspace, while recognising that capacity building is essential to enable all states to participate effectively
The African Group encourages the global mechanism to support capacity building for legal, diplomatic, and technical experts, and to facilitate exchanges of national and regional experiences
Capacity building is vital to allow for the participation of all states and to bridge the gap between technical, policy, and legal experts
Germany affirms that international law is a priority for its cyber capacity-building engagement, and that all states should be able to participate on an equal footing
Mauritius affirms that developing a national position on international law is itself a valuable capacity-building process, strengthening institutional knowledge and promoting dialogue among legal, technical, diplomatic, and policy communities
Vanuatu underlines that developing national positions is a demanding legal exercise for a small foreign ministry, and that legal capacity building must remain inseparable from this pillar
Canada affirms that capacity building should remain a central and necessary element for the success of the international law pillar, assisting states in developing national positions and improving practical implementation
Ireland calls for the mechanism to focus not just on identifying areas of consensus but also areas of convergence to accurately capture progress
Albania supports training, exchanges of national and regional positions, scenario-based exercises, and support for developing national positions as means to create shared understanding
Indonesia underscores the need for cooperative capacity building, including training on the application of international law in cyberspace, to ensure its application remains fair, non-discriminatory, and reflective of the needs of all member states
Botswana highlights the vital importance of the DTGs in bridging the gap between legal principles and technical realities, and commends UNIDIR, the African Union, and SADC for their capacity-building contributions
Thailand affirms that promoting a common understanding of international law in cyberspace requires bridging the gap between the legal and ICT communities and addressing remaining capacity gaps among states
Policy Context (Knowledge Base)
Capacity building as a foundational component of international cooperation on cybersecurity has been universally recognised across OEWG sessions and IGF discussions [S174]. The OEWG 2021-2025 informal consultations specifically highlighted capacity building as integral to enabling broader state participation in legal discussions [S177].
Tonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamSouth AfricaItalyKiribatiAustriaMalawiSingaporeNew ZealandIsraelEstoniaArmeniaNigeria Nigeria on behalf of the Africa GroupNetherlandsGermanyMauritiusVanuatuCanadaIrelandAlbaniaIndonesiaBotswanaThailand
The global mechanism should build on the progress and common understandings established by previous GGEs and OEWGs rather than starting from scratch
There was broad agreement that the global mechanism should build on the achievements of previous GGEs and OEWGs rather than revisiting settled questions. Switzerland called for continuing to build on ‘the common understandings established by previous GGEs and the OEWGs’ . The EU noted that ‘further efforts of the global mechanism should build on previous discussions and achievements and include them in their results’ . Germany stated that ‘we do not begin our discussion on this agenda point from scratch’ as ‘successive consensus reports of the GGEs and open-ended working groups and the General Assembly have affirmed and consistently reaffirmed that international law applies to cyberspace’ . Canada similarly noted that ‘states have moved well beyond the initial debates’ . Austria emphasised that ‘it is important to build on the achievements of the last decade’ . Vanuatu described the OEWG’s final report as ‘the floor for the mechanism’s legal discussions, not their ceiling’ .
The task before the mechanism is to deepen common understanding of how international law concretely applies, building on GGE and OEWG consensus
The global mechanism should build on OEWG progress and provide space for states to continue building common understandings on how international law works
A better global common understanding of how international law applies to cyberspace is necessary to contribute to global cyber resilience and further transparency, predictability, and accountability
Reaching more common understandings on how international law applies to states' use of ICTs is critical to maintaining peace and stability, increasing predictability, and lowering the risk of miscalculation
Deepening consensus on the application of international law will strengthen predictability of state behaviour, reduce the risk of miscalculations, and promote an open, stable, secure, peaceful, and accessible cyberspace
Austria reaffirms that international law as a whole, including the UN Charter, IHRL, and IHL, applies to state cyber activities
International law remains a cornerstone of responsible state behaviour in cyberspace, with the UN Charter as the principal reference
Estonia affirms that previous UN processes have clearly confirmed that existing international law applies in cyberspace
The UK affirms that all states have agreed by consensus that international law applies to state conduct in cyberspace; cyberspace is not lawless
Armenia emphasises that the consensus reports of the GGE and OEWG provide a solid foundation for advancing discussions on the application of international law to the use of ICTs
Germany reaffirms that successive consensus reports of GGEs and OEWGs have confirmed that international law applies to cyberspace
Canada affirms that the challenge is no longer whether international law applies in cyberspace, but how to deepen common understanding of its practical application
Ireland affirms that the application of international law in cyberspace, including the UN Charter, IHRL, IHL, and state responsibility law, is an objective legal fact
Ukraine reaffirms its support for the framework under which international law, in particular the UN Charter in its entirety, is applicable to the use of ICTs by states
Vanuatu reaffirms that international law, with the UN Charter at its core, applies in full to state conduct in cyberspace
Policy Context (Knowledge Base)
Australia’s statement at the closure of the OEWG session explicitly welcomed the affirmation that the permanent mechanism must carry forward achievements to date, reflecting broad consensus that prior GGE and OEWG outputs should form the foundation of any successor mechanism [S172]. The OEWG 2021-2025 tenth substantive session similarly emphasised continuity in norm development [S165].
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamUruguayAustriaMalawiEstoniaUnited KingdomArmeniaGermanyCanadaIrelandUkraineVanuatu
Scenario-based and practice-oriented discussions should be used within the dedicated thematic groups to deepen understanding of how international law applies in practice
Multiple delegations agreed that the dedicated thematic groups (DTGs) should use scenario-based and practice-oriented approaches to deepen understanding of how international law applies. Switzerland encouraged the Chair ‘to initiate dedicated discussions on the application of the aforementioned rules of international law in real-world scenarios, including the protection of critical infrastructure such as hospitals, water systems, and energy networks’ . Kiribati argued that ‘working through realistic scenarios is how legal principle becomes operational understanding, and it is at the same time one of the most effective forms of legal capacity building available to states like ours’ . Austria firmly believed that ‘discussions on international law should be scenario-based and practice-oriented’ and suggested that ‘interstate discussions could be preceded by expert panels’ . Ireland welcomed ‘the use of appropriate working modalities to facilitate a more dynamic exchange of views on international law in the DTGs and plenary’ including ‘scenario-based exercises’ .
The mechanism should initiate dedicated discussions on the application of international law in real-world scenarios, including the protection of critical infrastructure such as hospitals, water systems, and energy networks
The DTGs can contribute by creating a less formal and more practical environment for legal dialogue among states and supporting broader capacity-building efforts
Italy believes DTG1 can play a significant role in helping all states understand the impact of certain threats on international law through scenario-based discussions, while DTG2 could elaborate tailored projects to assist countries in building capacities
Legal capacity building is the condition of the international law pillar being real; Kiribati reiterates the proposal for scenario-based exercises on international law within the dedicated thematic groups
Austria believes DTG discussions should be scenario-based and practice-oriented, preceded by expert panels, and focused on specific sub-areas one at a time to allow for in-depth discussions
Japan hopes that through expert briefings and interactive, practical discussions in DTG1, member states' awareness and understanding of the specific application of existing international law will be deepened
Canada believes the dedicated thematic groups provide an ideal platform for informal exchanges on concrete cases, including through encouraging participation of both government and non-governmental legal experts
Ireland calls for international law, including IHL, to feature prominently in the substantive work of the DTGs, and welcomes the use of guiding questions, structured discussions, and scenario-based exercises
Ukraine believes the work of DTG1 could significantly contribute to improving states' common understanding of the application of existing international law
Albania supports training, exchanges of national and regional positions, scenario-based exercises, and support for developing national positions as means to create shared understanding
The Netherlands affirms that the integrated, policy-oriented, and cross-cutting nature of DTG1 lends itself to discussions on the practical application of international law to real-world threats
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumItalyKiribatiAustriaJapanCanadaIrelandUkraineAlbaniaNetherlands
Publishing national and regional positions on the application of international law to cyberspace contributes to transparency, predictability, and common understanding
There was strong agreement across delegations that the publication of national and regional positions on the application of international law to cyberspace is a valuable transparency and confidence-building measure. The EU noted that ‘over 100 states have now either individually or collectively published their positions on international law, which is a real achievement’ . Italy argued that ‘promoting transparency by publishing national and regional positions is in the collective interest, as it reduces uncertainty and the risk of miscalculation in interstate relations’ . Estonia noted that it set out its first national position in 2019 and is currently in its third review process, encouraging other states to ‘articulate, share and, where appropriate, regularly update their national views’ . Ireland noted ‘there is now real momentum in states developing national positions’ with ‘over 100 states’ having published positions . Brazil, as ‘one of the first countries to publish its national position’, welcomed the increasing number and hoped to see many more .
Numerous regional and national positions on international law were published in the course of the OEWG, and this should continue; over 100 states have now published positions
The EU presented its common understanding on a non-exhaustive set of legal elements on the application of international law, and over 100 states have now published positions individually or collectively
Promoting transparency by publishing national and regional positions reduces uncertainty and the risk of miscalculation, establishing a global baseline for the application of international law
Republic of Korea published its national position on the application of international law to cyberspace in July 2025, contributing constructively to the ongoing international discussion
New Zealand notes that national position statements signpost areas where agreement on the application of international law converges but understandings can be strengthened
Estonia set out its first national position in 2019 and encourages other states to articulate, share, and regularly update their national views
The UK encourages states that have not yet done so to set out their positions in a similarly public and detailed way
Mexico appreciates the progress made in the publication of national positions and welcomes inter-regional contributions, inviting more states and regions to publish their positions as a transparency and trust-building measure
Brazil, as one of the first countries to publish its national position, welcomes the increasing number of national positions and hopes to see many more, especially from developing countries
Mauritius has undertaken the development of its national position on the application of international law in cyberspace, currently undergoing approval processes prior to publication
Canada affirms that the continued publication of national positions and regional approaches has contributed significantly to building common understandings
Ireland notes that over 100 states have now published positions and encourages all states to consider developing a position, either individually or collectively
Thailand published its first-ever National Position on the Application of International Law in Cyberspace last year as a clear demonstration of its commitment
Singapore affirms that fostering common understanding on the application of international law to ICTs contributes to peace, security, and trust among states
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoItalyRepublic of KoreaNew ZealandEstoniaUnited KingdomMexicoBrazilMauritiusCanadaIrelandThailandSingapore
Similar Viewpoints
A large cross-regional group of states shared the view that affirming the applicability of IHL to cyber operations in armed conflict does not encourage or legitimise the militarisation of cyberspace, but rather serves a humanitarian protection purpose. Switzerland stated explicitly that ‘applying IHL does not increase the risk of armed conflict in cyberspace’ and that ‘failing to apply it leaves that risk unaddressed and civilians and other protected persons and objects less protected’ . The EU similarly stated that ‘recognising the application of IHL in cyberspace does not lead to nor encourage the militarisation of cyberspace, nor does it legitimise cyber warfare’ . Brazil argued that ‘the recognition that IHL applies to cyberspace does not in any way endorse its militarisation or legitimise cyber warfare’ and that ‘if that were the case, the very existence of IHL itself would legitimise the use of force’ . Ireland ‘strongly disagrees with any suggestion that affirming the application of IHL to cyberspace encourages or legitimises the militarisation of cyberspace’ noting that ‘IHL is concerned with limiting the suffering caused by armed conflict’ . This shared viewpoint was expressed in direct response to concerns raised by Cuba and China about the militarisation risk.
Several delegations, particularly smaller states and those from the Pacific region, shared the view that discussions on new legally binding obligations are premature and that the priority should be to first build capacity to understand and implement existing international law. The Pacific Islands Forum ‘cautions against moving too quickly towards discussions of additional legally binding obligations before states have had the capacity and opportunity to engage with how existing international law applies’ . Kiribati explained from personal experience that negotiating the UN Convention Against Cybercrime ‘consumed very nearly everything we had to give’ and that ‘at the end of those three years, our network at home were not one day better defended’ . Ireland stated that ‘it is not evident at this stage that there are significant gaps in the law itself’ and therefore ‘any cause for new legally binding rules would be premature’ . The Republic of Korea argued that ‘existing international law already provides a sufficient legal foundation’ and that ‘rather than pursuing the negotiation of new legally binding instruments, our efforts should focus on clarifying and operationalising existing international law’ .
A distinct group of states — Cuba, Iran, China, Russia, and Venezuela — shared the view that new legally binding instruments are necessary to govern state conduct in cyberspace, and that voluntary norms are insufficient. Russia argued that ‘voluntary rules of responsible state behaviour can be observed, but only obligations under international treaties can be implemented’ . Cuba stated that ‘there is a need for a legally binding instrument that would be negotiated multilaterally under the framework of the United Nations’ . Iran argued that ‘the question of additional legally binding obligations cannot be deferred indefinitely’ and that the mandate of the global mechanism ‘explicitly envisages the development of additional legally binding obligations’ . China called for states to ‘discuss and conclude a new international legal instrument’ and supported Russia’s Convention on International Information Security as ‘a very good basis for discussion’ . Venezuela similarly believed ‘the creation of a legally binding framework of comprehensive scope is not only necessary’ .
Several delegations expressed concern about the exclusion of non-governmental stakeholders and called for their meaningful participation in the mechanism’s work. Austria shared ‘concerns raised by the multi-stakeholder community’ and emphasised that ‘for these decisions to be effective, they must be grounded in a sound and comprehensive factual basis’ and that ‘the expertise provided by non-governmental stakeholders is crucial to that’ . The UK regretted ‘that stakeholders with genuine expertise including those from the University of Exeter were blocked from participating in this plenary session’ . New Zealand maintained that ‘meaningful participation by relevant stakeholders, both in the plenary and the DTGs, is essential’ including ‘legal experts whose positions broadly support the need to continue building an understanding of how international law applies in cyberspace’ . South Africa suggested ‘broadening our understanding by allowing for presentations by legal experts, including those in civil society and academia’ .
Several delegations, from different political groupings, agreed that attribution of malicious cyber activities presents unique challenges in the cyber domain and must be handled carefully. Costa Rica noted that ‘the digital environment presents unique technical and evidentiary challenges’ and called for ‘promoting good practices, voluntary transparency, capacity building and confidence building measures that help to distinguish between technical, political and legal attribution’ . Malawi affirmed that ‘attribution to a state remains a legal determination that must be based on international law and credible evidence’ . The Republic of Korea noted ‘the challenges arising from the significant role of non-state actors as well as the anonymity, speed, and technical complexity of cyber operations, all of which make attribution and response more difficult’ . Indonesia stressed that ‘attribution must never be used as political instruments’ . Cuba argued that ‘in the absence of a multilateral mechanism that would impartially and unequivocally determine the origin of cybernetic incidents, this can be easily manipulated today’ .
Small and developing states from the Pacific and Africa shared a particularly strong conviction that international law is not merely a technical matter but their primary security guarantee in cyberspace. Kiribati stated that ‘international law protects Kiribati’ and that sovereign equality, the prohibition of force, non-intervention, and peaceful settlement of disputes ‘are not matters of legal theory’ but ‘our defences’ and ‘in truth the only defences we have’ . Vanuatu similarly argued that ‘for states without armies of scale or arsenals of deterrence, the rule of law is not one security strategy among several’ but ‘the security strategy’ . Kiribati concluded that ‘for the powerful international law is a constraint they accept for the small it is the protection they depend on’ . These states also emphasised that legal capacity building is essential precisely because they lack the resources to engage fully without support .
Unexpected Consensus
It was somewhat unexpected that states from very different political groupings – including large developed states (Austria, UK, Japan, Canada), developing states (Colombia, Albania), and small island states (Kiribati, Tonga) – all converged on the specific methodology of scenario-based exercises as the preferred approach for advancing legal discussions. This consensus cut across the usual North-South and East-West divides. Kiribati argued that ‘working through realistic scenarios is how legal principle becomes operational understanding, and it is at the same time one of the most effective forms of legal capacity building available to states like ours’ . Austria firmly believed that ‘discussions on international law should be scenario-based and practice-oriented’ . Switzerland encouraged ‘dedicated discussions on the application of the aforementioned rules of international law in real-world scenarios, including the protection of critical infrastructure such as hospitals, water systems, and energy networks’ . This methodological consensus is notable because it bridges the gap between states that want to advance IHL discussions and those that prioritise capacity building, as scenario-based exercises serve both purposes simultaneously.
It was notable that multiple delegations from the same broad coalition explicitly acknowledged that the OEWG final report was inadequate in capturing the depth of legal discussions, particularly on IHL. Switzerland noted that ‘the final report of the OEWG did not retain explicit language on IHL, which should now be a priority for the mechanism’ . The EU stated that ‘even through the result of hard work of cross-regional groups and a reference to the resolution of the International Conference of the Red Cross and Red Crescent were not included in the final Open Ended Working Group report’ . The UK noted that ‘the breadth and depth of those exchanges and the extent of our agreement was not fully reflected in the final report of the OEWG, but we must not lose sight of them’ . Germany similarly observed that ‘the final report of the OEWG did not fully reflect the breadth and depth of those discussions, especially when it comes to international humanitarian law’ . Brazil noted that ‘international law is the one in which consensus reports least reflect the richness of our debates’ . This shared acknowledgement of the OEWG’s shortcomings was unexpected in its directness and breadth.
It was somewhat unexpected that developing and small states from Africa, the Pacific, Asia, and Latin America converged so strongly on the view that the implementation gap – rather than gaps in the law itself – is the primary challenge. Malawi stated plainly that ‘the most significant gap before us today is not a gap on international law’ but ‘the gap between legal consensus and practical implementation’ and that ‘closing that gap would do more to strengthen international peace and security than debating obligations that many states are not yet equipped to operationalize’ . The Pacific Islands Forum argued that ‘before we can have a meaningful discussion on whether there are gaps, we need the legal capacity to understand and apply the existing framework’ . This consensus among developing states was notable because it effectively reframed the debate away from the question of new legally binding instruments – which divides states – towards the shared challenge of implementation, which unites them. It also implicitly aligned these states more closely with those opposing new legally binding instruments, even if they did not explicitly take that position.
Overall Assessment
The discussion revealed a very high level of consensus on the fundamental proposition that international law, including the UN Charter, applies to state conduct in cyberspace. This was affirmed by virtually every delegation, including those with significant reservations about the scope and manner of application. There was also strong consensus on the need for legal capacity building, the value of publishing national and regional positions, and the importance of building on OEWG achievements. A clear majority supported the view that IHL applies to cyber operations in armed conflict and that this does not encourage militarisation. The mechanism's dedicated thematic groups (DTGs) were broadly welcomed as a vehicle for advancing practical, scenario-based discussions. The main area of disagreement concerned whether new legally binding instruments are needed: a large majority of states argued that existing law is sufficient and that the priority should be deepening understanding and implementation, while a smaller group — notably Russia, China, Cuba, Iran, and Venezuela — argued that new legally binding instruments are necessary. There was also a notable divide on stakeholder participation, with some states expressing frustration at the exclusion of non-governmental experts.
Points of Difference
Whether additional legally binding instruments are needed for cyberspace governance
This is the most fundamental disagreement in the session. Cuba , Iran , China , Russia , and Venezuela argue that new legally binding instruments are necessary because existing international law cannot be automatically or fully applied to the unique characteristics of cyberspace. In contrast, the Republic of Korea , Israel , Ireland , Ukraine , France , and the Pacific Islands Forum argue that existing international law is sufficient and that new legally binding obligations are premature, with the priority being to deepen understanding and implementation of existing law.
Cuba argues that automatic applicability of international law to cyberspace is not acceptable and that there is a need for a legally binding instrument negotiated multilaterally under the UN framework
Iran argues that the question of additional legally binding obligations cannot be deferred indefinitely, as the mandate of the global mechanism explicitly envisages their development
China argues that states should discuss and conclude a new international legal instrument to maintain lasting peace and stability in cyberspace, and supports Russia's Convention on International Information Security as a basis for discussion
Voluntary norms are not a substitute for legally binding obligations; a new international legal instrument is needed to address the unique challenges of the ICT environment
Venezuela believes the creation of a legally binding comprehensive framework is not only necessary but also part of the mandate of the former OEWG
Existing international law already provides a sufficient legal foundation; efforts should focus on clarifying and operationalising existing law rather than pursuing new legally binding instruments
Israel is firmly of the position that there is no need for a new legally binding instrument; discussion should focus on meticulous evaluation of how existing law applies to the unique characteristics of the cyber domain
Ireland considers that any call for new legally binding rules would be premature; the priority should be to consolidate shared understanding, as it is not evident that there are significant gaps in the law itself
Ukraine does not support efforts aimed at developing new legally binding or non-binding international rules governing state behaviour in cyberspace at this stage
France considers the debate on new binding standards to be of secondary importance, and regrets that the most fervent defenders of a new treaty are those currently violating existing international law
The Pacific Islands Forum cautions against moving too quickly towards discussions of additional legally binding obligations before states have had the capacity and opportunity to engage with how existing international law applies
Policy Context (Knowledge Base)
This is one of the most persistent and well-documented disagreements in UN cyberspace governance. OEWG sessions recorded significant disagreement between states arguing existing laws are sufficient and those calling for new binding frameworks [S160][S163][S165]. IGF 2023 discussions also reflected this divide, with some participants arguing that a binding regulatory framework is needed to establish clear standards [S159], while others maintained existing law suffices [S160].
CubaIslamic Republic of IranChinaRussian FederationVenezuelaRepublic of KoreaIsraelIrelandUkraineFranceNew ZealandTonga on behalf of the Pacific Islands Forum
Whether International Humanitarian Law (IHL) automatically and fully applies to cyberspace
A significant bloc of states including Cuba , Venezuela , and China argue that IHL cannot be automatically applied to cyberspace, with Cuba explicitly stating this would lead to the militarisation of cyberspace and equate cyber attacks with military attacks. In sharp contrast, a large cross-regional group including Switzerland , the EU , Austria , Ireland , Brazil , Mexico , Vanuatu , and Albania strongly affirm that IHL applies to cyber operations in armed conflict and that this recognition does not encourage militarisation but rather provides humanitarian protection.
Cuba argues that automatic applicability of IHL to cyberspace is not acceptable as it implies a step towards militarisation and could make a cyber attack equivalent to a military attack
China argues that the application of IHL in cyberspace must be handled with greater prudence, given inherent legal and technical difficulties and the involvement of large tech companies in geopolitical conflicts
Venezuela questions the full and automatic applicability of international norms to cyberspace, arguing that international law needs to be carefully adapted to the specific characteristics of ICTs
Affirming IHL's applicability to cyber operations does not increase the risk of armed conflict; failing to apply it leaves civilians less protected
Recognising the application of IHL in cyberspace does not lead to nor encourage the militarisation of cyberspace, nor does it legitimise cyber warfare
Affirming IHL's applicability to cyber activities in connection with armed conflict does not encourage or legitimise cyber warfare; it affirms that armed conflicts are subject to rules regardless of the means of warfare employed
Ireland strongly disagrees with any suggestion that affirming the application of IHL to cyberspace encourages or legitimises the militarisation of cyberspace
Brazil affirms that IHL applies to situations amounting to armed conflict independently of its classification; recognising this does not endorse militarisation or legitimise cyber warfare
Mexico affirms that the applicability of IHL does not legitimise the militarisation of cyberspace; on the contrary, it imposes limits on the conduct of parties and protects civilian populations
Vanuatu reaffirms the applicability of IHL to cyber activities in armed conflict, noting its purpose is humanitarian protection and its affirmation makes conflict less cruel, not more likely
Albania reiterates that IHL applies to cyber operations conducted in the context of armed conflict, and recognises this neither encourages militarisation nor legitimises cyber warfare
Policy Context (Knowledge Base)
IHL applicability in cyberspace has been a central and persistent point of friction across multiple OEWG sessions. While a majority of states, including sixteen countries in a joint statement led by Switzerland, affirmed IHL’s applicability to cyber operations in armed conflict [S178], Russia has firmly insisted that existing IHL is insufficient and potentially legitimises cyber warfare [S177]. The OEWG fourth substantive session saw the majority confirm IHL principles of necessity, humanity, proportionality, and distinction apply in cyberspace [S179], while fundamental disagreement persisted over characterising ICTs as exclusively for peaceful purposes [S169].
CubaChinaVenezuelaSwitzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustriaIrelandBrazilMexicoVanuatuAlbania
Whether the unique characteristics of cyberspace require entirely new legal frameworks or merely careful application of existing law
Israel argues that the unique characteristics of cyberspace, such as data lacking physical manifestation and relying on privately owned infrastructure, require meticulous evaluation rather than automatic transposition of existing rules, but stops short of calling for new instruments. Russia and Iran go further, arguing that these unique characteristics mean existing norms cannot be automatically applied and new legally binding instruments are needed. In contrast, Switzerland , Australia , Estonia , and the UK argue that existing international law clearly applies and the task is to deepen understanding of how it applies in practice.
Israel is firmly of the position that there is no need for a new legally binding instrument; discussion should focus on meticulous evaluation of how existing law applies to the unique characteristics of the cyber domain
Russia affirms that universally recognised principles of international law apply to ICTs, but argues that the unique technical and legal characteristics of cyberspace do not allow automatic and full application of existing norms
Iran argues that the question of additional legally binding obligations cannot be deferred indefinitely, as the mandate of the global mechanism explicitly envisages their development
Cuba argues that automatic applicability of international law to cyberspace is not acceptable and that there is a need for a legally binding instrument negotiated multilaterally under the UN framework
The task before the mechanism is to deepen common understanding of how international law concretely applies, building on GGE and OEWG consensus
Reaching more common understandings on how international law applies to states' use of ICTs is critical to maintaining peace and stability, increasing predictability, and lowering the risk of miscalculation
Estonia affirms that previous UN processes have clearly confirmed that existing international law applies in cyberspace
The UK affirms that all states have agreed by consensus that international law applies to state conduct in cyberspace; cyberspace is not lawless
Policy Context (Knowledge Base)
IGF 2023 discussions acknowledged that existing international laws may need adjustments given the highly dynamic nature of cyberspace [S159], while OEWG sessions reflected divergent views on whether new norms or careful application of existing frameworks is the appropriate response [S163][S164]. This tension between adaptation and new framework creation has been a recurring theme across UN cybersecurity negotiations [S165].
IsraelRussian FederationIslamic Republic of IranCubaSwitzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamEstoniaUnited Kingdom
The role and legitimacy of stakeholder participation in the global mechanism
Austria and the UK express frustration that stakeholders with genuine expertise were blocked from participating in the plenary session, arguing that non-governmental expertise is crucial for grounding decisions in a sound factual basis. New Zealand similarly calls for meaningful stakeholder participation. South Africa supports expert presentations from civil society and academia. The Russian Federation , by contrast, objects to what it characterises as a reporting mechanism and rejects approaches it sees as inconsistent with UN Charter principles, implying resistance to certain forms of stakeholder engagement.
Austria expresses frustration with the lack of consensus on stakeholder participation, emphasising that non-governmental expertise is crucial to grounding decisions in a sound and comprehensive factual basis
The UK regrets that stakeholders with genuine expertise, including those from the University of Exeter, were blocked from participating in the plenary session
New Zealand maintains that meaningful participation by relevant stakeholders, both in the plenary and the DTGs, is essential, and supports capacity-building measures
South Africa suggests that broadening understanding could be achieved by allowing presentations by legal experts, including those in civil society and academia
Voluntary norms are not a substitute for legally binding obligations; a new international legal instrument is needed to address the unique challenges of the ICT environment
Policy Context (Knowledge Base)
Malawi’s statement at the first plenary of the Global Mechanism on ICTs explicitly addressed this tension, arguing that meaningful stakeholder participation is indispensable and that the broadest possible engagement strengthens the mechanism [S182]. Broader IGF discussions have also examined the legitimacy of multistakeholder approaches, noting that public reasoning and authority are foundational for authentic democratic participation [S183], while cooperation must be crafted into legislation to ensure effectiveness and legitimacy [S181].
Whether attribution of malicious cyber activities should be addressed through multilateral mechanisms or existing state practice
Cuba argues that without a multilateral mechanism to impartially determine the origin of cyber incidents, attribution can be easily manipulated, implying a need for a new institutional mechanism. Iran similarly argues that the complexity of attribution requires additional legal rules. Indonesia calls for objective, transparent attribution based on technical standards that is never used as a political instrument. Costa Rica and Malawi take a more cautious approach, calling for rigour, prudence, and evidence-based legal determinations within existing frameworks, without necessarily requiring new institutions.
Cuba argues that in the absence of a multilateral mechanism that would impartially determine the origin of cybernetic incidents, attribution can be easily manipulated
Indonesia underscores the need for the global mechanism to address attribution in an objective, transparent manner based on technical standards, ensuring it is never used as a political instrument
Costa Rica believes it is essential to address attribution with rigour and prudence, promoting good practices, voluntary transparency, capacity building, and confidence-building measures to distinguish between technical, political, and legal attribution
Iran argues that the anonymity of malicious activities and the complexity of attribution create legal and practical challenges that require additional legal rules
Israel notes that data lacks a meaningful physical manifestation, is highly dynamic, and relies on privately owned international infrastructure, highlighting unique characteristics of the cyber domain relevant to attribution
Attribution to a state remains a legal determination that must be based on international law and credible evidence; responsible attribution is essential to maintaining international peace, security, and stability
Policy Context (Knowledge Base)
OEWG discussions reflected divergent approaches to attribution, with Iran calling for technical mechanisms to address politically motivated attributions and the United States emphasising state responsibility under existing frameworks [S167]. This disagreement reflects broader tensions between multilateral institutionalisation of attribution and reliance on individual state practice.
CubaIndonesiaCosta Rica DelegateIslamic Republic of IranIsraelMalawi
Whether Russia's intervention constituted disinformation and information manipulation
Ukraine explicitly characterised Russia’s previous day’s intervention as an act of intentional disinformation and information manipulation, citing its over-emotional nature, lack of factual reference, and omission of key facts such as ICC arrest warrants for Russian officials and the occupation of Ukrainian territory. Ukraine called for the intervention to be reported so it would not be disseminated . Russia , in its subsequent intervention, did not directly respond to Ukraine’s characterisation but continued to advocate for new legally binding instruments and criticised the voluntary norms framework, implicitly rejecting Ukraine’s framing.
Russia's yesterday's intervention is a very important step in the development of the Russian Federation.
Ukraine reaffirms its support for the framework under which international law, in particular the UN Charter in its entirety, is applicable to the use of ICTs by states
Policy Context (Knowledge Base)
The United States explicitly addressed Russian interventions at the closure of the OEWG session, characterising them as efforts to distract from the work and undermine good-faith endeavours to produce a meaningful consensus report [S176]. This reflects a broader pattern of procedural and substantive disputes between Western states and Russia throughout the OEWG process.
UkraineRussian Federation
Unexpected Differences
An unexpected semantic and conceptual disagreement emerged over the nature of voluntary norms. Russia made the surprising argument that voluntary rules of responsible state behaviour can only be ‘observed’ but not ‘implemented’, and that implementation is only possible once voluntary rules are transformed into legally binding obligations. Russia also objected to what it characterised as a ‘checklist’ approach to implementing voluntary norms , calling it inconsistent with UN Charter principles. This distinction between ‘observing’ and ‘implementing’ norms was not directly addressed by other delegations but represents a fundamental conceptual disagreement about the nature of the normative framework that was not anticipated as a major point of contention in the session.
An unexpected area of concern emerged regarding the adequacy of the OEWG’s final report. Switzerland , the EU , Brazil , Germany , and the UK all expressed regret or concern that the final OEWG report did not fully reflect the breadth and depth of discussions that had taken place, particularly on IHL. This was unexpected because the OEWG process was generally presented as a success, yet multiple delegations felt its final report was inadequate – suggesting that the consensus-building process itself may have resulted in a document that understated the degree of agreement actually reached, creating a gap between the richness of discussions and their formal documentation.
China raised an unexpected argument that large technology companies from certain countries are deeply involved in geopolitical conflicts, posing new challenges to the application of IHL in cyberspace, and questioning whether their participation in armed conflicts complies with the principles of distinction and military necessity. This introduced the role of private sector actors as a complicating factor in IHL application – a dimension not prominently addressed by most other delegations. Colombia touched on related issues regarding non-state actors, and Austria argued for stakeholder participation from a different angle. This created an unexpected three-way tension around the role of non-state actors in the IHL framework.
Portugal made an unexpected and distinctive argument that the binding state duty to protect freedom of digital expression, including anonymous expression across borders, should be a central focus of scenario-based discussions in the DTGs. This framing – emphasising the duty to protect rather than merely respect freedom of expression, and specifically including anonymous expression across borders – was not echoed by other delegations and stands in implicit tension with Cuba’s emphasis on sovereignty and non-intervention, and Russia’s argument that existing norms cannot be automatically applied. Portugal’s specific focus on anonymous expression as a binding obligation was particularly unexpected in this context.
Overall Assessment
The session revealed a deep structural divide between two broad camps. A large cross-regional majority – including the EU, Switzerland’s group, Australia’s group, Pacific Islands Forum, and many individual states – affirms that existing international law, including IHL and IHRL, applies fully to cyberspace and that the priority is deepening common understanding and implementation through the DTGs, scenario-based exercises, and capacity building . A smaller but significant minority – including Cuba, Iran, China, Russia, and Venezuela – argues that the unique characteristics of cyberspace prevent automatic application of existing norms and that new legally binding instruments are necessary . The most contentious specific issue is the applicability of IHL, with the majority firmly affirming it applies and rejecting the militarisation argument , while Cuba, China, and Venezuela resist automatic IHL application . There is near-universal agreement on the value of capacity building and the need for scenario-based discussions in the DTGs, though disagreement persists on sequencing and content. The inadequacy of the OEWG final report in capturing IHL discussions was an unexpected area of shared concern among otherwise aligned states.
All speakers agree that the UN Charter and its core principles — including sovereignty, sovereign equality, non-intervention, prohibition of the use of force, and peaceful settlement of disputes — apply to state conduct in cyberspace . This represents a foundational consensus. However, they sharply disagree on whether this means existing international law is sufficient and whether additional legally binding instruments are needed .
Agreed
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamCubaIslamic Republic of IranRussian FederationChinaVenezuela
Contested
International law, including the UN Charter, applies fully to state conduct in cyberspace, building on GGE and OEWG consensus International law applies to cyberspace; the Pacific Islands Forum supports a principled approach grounded in the UN Charter, reaffirming applicability of IHL and human rights law The EU reaffirms full commitment to international law, including the UN Charter, IHRL, IHL, and state responsibility law, as essential to cyber resilience and stability International law is applicable and essential; states have reaffirmed sovereignty, non-intervention, prohibition of force, and peaceful settlement of disputes as applicable in cyberspace Cuba affirms that the use of ICTs must be fully compatible with the UN Charter and international law, especially sovereignty, territorial integrity, and non-intervention Iran recognises that the purposes and principles of the UN Charter and generally accepted principles of international law apply to the use of ICTs by states Russia affirms that universally recognised principles of international law apply to ICTs, but argues that the unique technical and legal characteristics of cyberspace do not allow automatic and full application of existing norms China underscores the role of the UN Charter and its principles as the cornerstone of cyberspace governance, calling on all countries to oppose the use of cyber means for aggression Venezuela questions the full and automatic applicability of international norms to cyberspace, arguing that international law needs to be carefully adapted to the specific characteristics of ICTs
There is broad agreement across virtually all delegations that capacity building on international law is essential and must be a priority of the global mechanism . All agree that many states, particularly developing countries and small island states, lack the legal expertise to fully engage with these discussions. However, they disagree on the sequencing: some states like the Pacific Islands Forum and Kiribati argue capacity building must come before discussions of new obligations, while others like Iran argue that the question of new legally binding obligations cannot be deferred indefinitely regardless of capacity gaps.
Agreed
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenTonga on behalf of the Pacific Islands ForumKiribatiMalawiAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamNigeria Nigeria on behalf of the Africa GroupGermanyCanadaSingaporeArmenia
Contested
The mechanism should initiate dedicated discussions on the application of international law in real-world scenarios, including the protection of critical infrastructure such as hospitals, water systems, and energy networks Legal capacity building should be a practical and cross-cutting priority of the global mechanism, with scenario-based training, regional workshops, peer exchanges, and accessible expert briefings Legal capacity building is the condition of the international law pillar being real; Kiribati reiterates the proposal for scenario-based exercises on international law within the dedicated thematic groups Malawi affirms that the most significant gap is not in international law itself but between legal consensus and practical implementation, and that closing this gap should be the priority Capacity-building efforts, including those advanced through DTG2, should better enable states to meaningfully participate in discussions, develop national positions, and enhance implementation of international law The African Group encourages the global mechanism to support capacity building for legal, diplomatic, and technical experts, and to facilitate exchanges of national and regional experiences Germany affirms that international law is a priority for its cyber capacity-building engagement, and that all states should be able to participate on an equal footing Canada affirms that capacity building should remain a central and necessary element for the success of the international law pillar, assisting states in developing national positions and improving practical implementation Singapore affirms that capacity building in international law is an essential part of fostering common understanding on how international law applies in the use of ICTs Armenia underscores the importance of promoting a shared understanding of the application of international law in cyberspace, while recognising that capacity building is essential to enable all states to participate effectively
A large majority of states agree that publishing national and regional positions on the application of international law to cyberspace is valuable for transparency, predictability, and building common understanding . They share the goal of encouraging more states to publish positions. However, they disagree on what these positions should say — particularly regarding IHL applicability — and on whether the accumulation of national positions is sufficient or whether a new binding instrument is ultimately needed .
Agreed
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenEuropean Union on behalf of the EU and Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia -Herzegovina, and Georgia, and the EFTA country Norway, member of the European Economic Area and San MarinoItalyBrazilEstoniaRepublic of KoreaIrelandMexicoCanadaMauritius
Contested
Numerous regional and national positions on international law were published in the course of the OEWG, and this should continue; over 100 states have now published positions The EU presented its common understanding on a non-exhaustive set of legal elements on the application of international law, and over 100 states have now published positions individually or collectively Promoting transparency by publishing national and regional positions reduces uncertainty and the risk of miscalculation, establishing a global baseline for the application of international law Brazil, as one of the first countries to publish its national position, welcomes the increasing number of national positions and hopes to see many more, especially from developing countries Estonia set out its first national position in 2019 and encourages other states to articulate, share, and regularly update their national views Republic of Korea published its national position on the application of international law to cyberspace in July 2025, contributing constructively to the ongoing international discussion Ireland notes that over 100 states have now published positions and encourages all states to consider developing a position, either individually or collectively Mexico appreciates the progress made in the publication of national positions and welcomes inter-regional contributions, inviting more states and regions to publish their positions as a transparency and trust-building measure Canada affirms that the continued publication of national positions and regional approaches has contributed significantly to building common understandings Mauritius has undertaken the development of its national position on the application of international law in cyberspace, currently undergoing approval processes prior to publication
There is broad agreement that the Dedicated Thematic Groups (DTGs), particularly DTG1, should serve as a platform for practical, scenario-based discussions on the application of international law . States agree on the value of scenario-based exercises and expert briefings. However, they disagree on what content these discussions should cover — particularly whether IHL should feature prominently versus being handled with greater prudence — and whether discussions should aim to identify gaps for new binding obligations or focus solely on deepening understanding of existing law .
Agreed
Switzerland on behalf of Austria, Belgium, Brazil Bulgaria, Canada Chile, Colombia Croatia, Czechia Egypt, Estonia Finland, France Germany, Ghana Hungary, Italy, Ireland Latvia, Lithuania Luxembourg, Mexico Kingdom of the Netherlands, Norway, Poland Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, SwedenAustralia on behalf of Chile, Colombia, The Dominican Republic, Ecuador, Egypt, Estonia, Kiribati, Moldova, Netherlands, New Zealand, Poland, Romania, Thailand, Uruguay, Vanuatu and VietnamAustriaItalyKiribatiJapanCanadaIrelandColombiaUkraine
Contested
The mechanism should initiate dedicated discussions on the application of international law in real-world scenarios, including the protection of critical infrastructure such as hospitals, water systems, and energy networks DTG1 should include detailed and substantive discussions on the application of international law in an integrated, policy-oriented, and cross-cutting manner; DTG2 should better enable states to develop national positions Austria believes DTG discussions should be scenario-based and practice-oriented, preceded by expert panels, and focused on specific sub-areas one at a time to allow for in-depth discussions Italy believes DTG1 can play a significant role in helping all states understand the impact of certain threats on international law through scenario-based discussions, while DTG2 could elaborate tailored projects to assist countries in building capacities Kiribati supports dedicating structured time in the mechanism, including within the thematic groups, to working through how the law applies in concrete situations, turning legal discussion into a shared capability Japan hopes that through expert briefings and interactive, practical discussions in DTG1, member states’ awareness and understanding of the specific application of existing international law will be deepened Canada believes the dedicated thematic groups provide an ideal platform for informal exchanges on concrete cases, including through encouraging participation of both government and non-governmental legal experts Ireland calls for international law, including IHL, to feature prominently in the substantive work of the DTGs, and welcomes the use of guiding questions, structured discussions, and scenario-based exercises Colombia believes the first thematic group can provide significant added value by developing concrete outputs that allow legal arguments to be translated into practical guidance for states Ukraine believes the work of DTG1 could significantly contribute to improving states’ common understanding of the application of existing international law
Key Takeaways
There is broad, near-universal consensus that international law, including the UN Charter in its entirety, applies to state conduct in cyberspace, building on successive GGE and OEWG consensus reports. This is no longer a contested premise for the vast majority of delegations.
The central task before the Global Mechanism is not to re-litigate whether international law applies, but to deepen common understanding of how it applies in practice, particularly in relation to sovereignty, non-intervention, prohibition of the use of force, state responsibility, due diligence, international human rights law (IHRL), and international humanitarian law (IHL).
The application of IHL to cyber operations in situations of armed conflict is affirmed by a large cross-regional majority of states. These delegations consistently emphasised that affirming IHL’s applicability does not encourage or legitimise the militarisation of cyberspace; rather, it provides essential protections for civilians and civilian objects. A minority of states, including Cuba, Venezuela, and China, expressed caution or opposition to the automatic or full application of IHL to cyberspace.
A significant divide exists between states that consider existing international law sufficient (requiring only clarification and implementation) and those, notably Russia, China, Cuba, Iran, and Venezuela, that argue for the negotiation of new legally binding international instruments to govern cyberspace. The majority of delegations opposed or deprioritised the creation of new legally binding obligations at this stage.
Legal capacity building is identified as a critical and cross-cutting priority, particularly for small island developing states, developing countries, and states with limited legal expertise. Kiribati’s intervention powerfully illustrated the practical constraints faced by small delegations and the existential importance of international law as their primary security guarantee.
The publication of national and regional positions on the application of international law to cyberspace is widely encouraged as a transparency and confidence-building measure. Over 100 states have now published such positions individually or collectively, which is regarded as a significant achievement.
The Dedicated Thematic Groups (DTGs), particularly DTG1, are seen as the primary vehicle for advancing practical, scenario-based, and cross-cutting discussions on the application of international law. DTG2 is identified as the appropriate forum for addressing capacity-building needs arising from those discussions.
Scenario-based discussions and exercises are widely supported as the most effective modality for translating legal principles into operational understanding, particularly for states with limited legal capacity.
The final report of the OEWG 2021–2025 was widely criticised for not fully reflecting the depth and breadth of discussions on international law, particularly on IHL. Delegations called for the Global Mechanism to ensure that progress made in preceding fora is not lost and is properly reflected in its own reporting.
Attribution of malicious cyber activities remains a complex and sensitive issue. States emphasised that attribution must be based on international law and credible evidence, must never be used as a political instrument, and must account for the unique technical challenges of the cyber domain.
Stakeholder participation remains a contentious issue. Several delegations, including Austria, the UK, and New Zealand, expressed frustration that non-governmental experts, including academics and legal scholars, were blocked from participating in the plenary session, arguing that their expertise is essential to grounding state decisions in a sound factual basis.
Ukraine exercised a right of reply to characterise Russia’s previous intervention as an act of intentional disinformation and information manipulation, citing the ICC arrest warrants for Russian officials and the occupation of Ukrainian territory as facts omitted from Russia’s statement.
Resolutions & Action Items
The Chair indicated that discussions on the applicability of international law would continue in the afternoon session, with remaining speakers including Switzerland, the United States, Australia, and the International Committee of the Red Cross (ICRC).
Following the international law agenda item, the meeting would move to the next agenda item on developing and applying confidence-building measures.
A dedicated stakeholder session was scheduled for 3pm on the same day, with delegations encouraged to attend.
Multiple delegations called on the co-facilitators of DTG1 to ensure that international law, including IHL, features prominently in the substantive work of DTG1, and to initiate dedicated, scenario-based discussions on the application of specific rules of international law to real-world situations such as attacks on hospitals, water systems, and energy networks.
Delegations were encouraged to submit full written statements to eStatements and to the Chair’s team.
Switzerland, on behalf of a large cross-regional group, proposed that the mechanism address five priority areas of international law in a structured and inclusive manner: (1) sovereignty and the prohibition of intervention; (2) state responsibility and due diligence; (3) the prohibition of the use of force and the right of self-defence under Article 51; (4) IHL as it applies to cyber operations in armed conflict; and (5) the application of IHRL to state conduct in cyberspace.
Kiribati and others called for scenario-based exercises on international law to be taken up within the dedicated thematic groups as a form of legal capacity building.
Multiple delegations, including Italy, Germany, Austria, and Canada, called for expert briefings, including from bodies such as the International Law Commission, the ICRC, and academia, to precede or inform DTG discussions.
The African Group encouraged the global mechanism to support capacity building for legal, diplomatic, and technical experts; facilitate exchanges of national and regional experiences; promote dialogue among legal, diplomatic, and technical communities; and strengthen cooperation with regional and sub-regional organisations.
Several delegations, including Ireland, the Netherlands, and Mauritius, indicated willingness to share their national experience in developing national positions on international law with other interested states.
Russia called on the Chair to organise substantive discussions on the development of new legally binding instruments, citing the mandate of the Global Mechanism under UN General Assembly Resolutions 79-237 and 80-16.
Russia called on all states to join the UN Convention Against Cybercrime, which it noted had already been signed by 78 countries.
Unresolved Issues
Whether additional legally binding international instruments are necessary or desirable to govern state conduct in cyberspace remains deeply contested. A majority of states favour working within the existing legal framework, while Russia, China, Cuba, Iran, and Venezuela advocate for new binding instruments.
The precise application of IHL to cyber operations, including the principles of distinction, proportionality, precaution, necessity, and humanity in the cyber context, remains unsettled and requires further substantive discussion. The involvement of large technology companies in armed conflicts adds further complexity.
The threshold at which cyber operations become coercive and thus inconsistent with the rule of non-intervention remains less settled, as noted by New Zealand and others.
The question of whether there are genuine gaps in existing international law as applied to cyberspace, or whether the primary challenge is one of implementation and capacity, has not been resolved.
Attribution of malicious cyber activities to states remains technically, legally, and politically complex. No agreed multilateral mechanism for impartial attribution exists, and the appropriate standards and processes for attribution remain contested.
The extent to which non-state actors, including large technology companies, are subject to or implicated in international law obligations in cyberspace is not fully addressed.
Stakeholder participation in the Global Mechanism, including in plenary sessions and DTGs, remains unresolved. Several delegations expressed frustration at the blocking of non-governmental experts, but no consensus on participation modalities was reached.
How the Global Mechanism’s reporting will reflect the depth of discussions on international law, particularly on IHL, given that the OEWG final report was widely criticised for failing to do so, remains to be determined.
The specific working modalities of the DTGs, including the format of expert briefings, the use of guiding questions, and the structure of scenario-based exercises, have not yet been agreed.
The question of how to ensure that capacity-constrained and small states can participate on an equal footing in legal discussions, given the resource and expertise disparities highlighted by Kiribati and others, remains a practical challenge without a fully agreed solution.
The applicability of international law to cyber operations below the threshold of armed conflict, including digital coercion, operations involving proxies, and activities below the threshold of the use of force, requires further discussion.
Venezuela and Cuba’s position that the automatic applicability of international law and IHL to cyberspace is not acceptable, and their call for a comprehensive legally binding framework, remains at odds with the majority view and unresolved within the forum.
Suggested Compromises
Several delegations, including the Pacific Islands Forum, Kiribati, Malawi, and New Zealand, suggested a sequenced approach: states should first build legal capacity and deepen understanding of existing international law before engaging in discussions on whether gaps exist or whether new legally binding obligations are needed. This was offered as a middle ground between those seeking immediate new instruments and those opposing any such discussion.
South Africa suggested that informal discussions in DTG1 with experts from civil society and academia could serve as a practical way to identify capacity-building needs, which could then be addressed in DTG2, thereby bridging the gap between legal discussion and practical implementation without prejudging outcomes.
Brazil suggested that there is no contradiction between the applicability of existing international law and the eventual development of lex specialis, or between binding obligations and voluntary norms, framing these as complementary and mutually reinforcing rather than mutually exclusive. This was offered as a conceptual bridge between those favouring new instruments and those opposing them.
Cameroon suggested that the progressive development and codification of international law for ICTs should proceed with caution, objectivity, and legal rigour, and only where states, through a consensus-based process, conclude that existing law is insufficient. This framing was offered as a way to keep the door open to new instruments without prejudging their necessity.
Multiple delegations supported the use of scenario-based discussions and real-world case studies within the DTGs as a practical compromise between abstract legal debate and operational implementation, allowing states of varying capacity to engage meaningfully without requiring settled national positions.
Russia indicated it would not refuse to discuss the proposed checklist for implementing voluntary norms of responsible state behaviour, but only on the understanding that it would genuinely be voluntary and not become a form of reporting by some states to others, suggesting a conditional openness to engagement on implementation frameworks.
The integrated, policy-oriented, and cross-cutting nature of DTG1 was widely endorsed as a structural compromise that allows international law to be discussed in conjunction with other pillars (threats, norms, confidence-building measures, and capacity building) rather than in isolation, making it more accessible to states without specialist legal capacity.
“Ukraine’s right of reply framing Russia’s intervention as a ‘practical tabletop exercise on disinformation’: ‘Distinguished delegates, it looks like we have just had a quick situational tabletop exercise on a practical case of a disinformation attempt happening right here in this room. We looked into it together, and now we all know how it works… I would like to report the case of attempted disinformation, namely Russia’s intervention of yesterday, so it will not be disseminated. Hashtag stop fake.’”
“Kiribati’s candid exposition of the reality of small state participation: ‘When we ask ourselves what actually protects Kiribati, the honest answer is this. International law protects Kiribati… They are in truth the only defences we have… there is an assumption running quietly beneath our discussions of international law, that every state arrives here with a settled national position, drafted by its own international lawyers, refined across its own governments. For much of this membership, that assumption does not hold… Kiribati’s delegation to this session is three people… The officer who would draft Kiribati’s national position on international law is in this room this week, and is also the officer who must do everything else.’”
“Switzerland (on behalf of a large cross-regional group) on IHL: ‘We wish to be clear on one point. Applying IHL does not increase the risk of armed conflict in cyberspace. Failing to apply it leaves that risk unaddressed and civilians and other protected persons and objects less protected.’”
“Costa Rica on attribution: ‘Although rules of attribution in international law are not new, the digital environment presents unique technical and evidentiary challenges. Therefore, we should promote good practices, voluntary transparency, capacity building and confidence building measures that help to distinguish between technical, political and legal attribution.’”
“Cameroon’s invocation of an African proverb to frame multilateral interdependence: ‘Allow me to conclude by recalling an African proverb which says that the strength of a river comes from the meeting of its tributaries. And this recalls a fundamental reality that a state alone cannot meet the complex challenges on their own.’”
“Cuba’s challenge to automatic IHL applicability: ‘Under Article 4 of the United Nations, cybernetic action does not constitute an armed attack insofar as it lacks the physical characteristics and other requirements that define military attacks, their impacts and their legal consequences… automatic applicability of international law and international humanitarian law to cyberspace is not acceptable insofar as this supplies a step towards militarization of cyberspace.’”
“Malawi’s reframing of the central gap: ‘The most significant gap before us today is not a gap in international law. It is the gap between legal consensus and practical implementation. Closing that gap would do more to strengthen international peace and security than debating obligations that many states are not yet equipped to operationalize.’”
“Vanuatu connecting its ICJ climate advisory opinion to its commitment to international law in cyberspace: ‘When our people faced the gravest threat to their future, we took the question of states’ climate obligations to the International Court of Justice, and the world followed. We bring the same conviction to this pillar. For states without armies of scale or arsenals of deterrence, the rule of law is not one security strategy among several. It is the security strategy.’”
“Israel’s methodological caution: ‘International legal frameworks that were developed for domains with particularly unique characteristics such as maritime domain, international aviation, and space law were done so after comprehensive considerations and cautious deliberation. The cyber domain is similarly unique and we should learn from our predecessors by investing sufficient time to exploring the unique characteristics of the cyber domain before reaching premature conclusions.’”
“Brazil on customary international law and state practice: ‘Having a broad and diverse range of states’ views is particularly important when thinking of possible customary law rules, which, as we all know, require both opinion juris and state practice. And as we have expressed in the National Position, the mere fact that a certain state behavior or position has not been formally protested against cannot be interpreted as acquiescence.’”
How exactly does international law, including IHL, apply to specific cyber operations in practice, particularly in real-world scenarios such as attacks on critical infrastructure like hospitals, water systems, and energy networks?
Switzerland (on behalf of Austria, Belgium, Brazil, Bulgaria, Canada, Chile, Colombia, Croatia, Czechia, Egypt, Estonia, Finland, France, Germany, Ghana, Hungary, Italy, Ireland, Latvia, Lithuania, Luxembourg, Mexico, Kingdom of the Netherlands, Norway, Poland, Portugal, Romania, Senegal, Slovakia, Slovenia, Spain, Sweden)
Moving beyond the general affirmation that international law applies to cyberspace towards concrete, scenario-based understanding is essential for states to operationalise legal principles and protect civilians and civilian infrastructure both in peacetime and armed conflict.
How should state responsibility and due diligence obligations be applied in the context of malicious ICT activities emanating from a state’s territory, particularly when that state has been notified of such activity?
South Africa, Vanuatu, Colombia, Netherlands
Clarifying the precise obligations of states under due diligence and state responsibility is critical for establishing accountability and preventing the use of state territory as a permissive environment for malicious cyber operations.
What is the threshold at which a cyber operation becomes coercive and thus inconsistent with the rule of non-intervention?
New Zealand, Costa Rica
While there is broad convergence that coercive cyber operations violate the principle of non-intervention, the specific threshold remains unsettled and requires further dialogue to provide legal clarity and reduce the risk of miscalculation between states.
How should attribution of malicious cyber activities be handled, given the unique technical and evidentiary challenges of the digital environment, and what good practices, voluntary transparency measures, and capacity-building efforts can help distinguish between technical, political, and legal attribution?
Costa Rica, Indonesia, Malawi, Russian Federation
Attribution is a foundational challenge in applying international law to cyberspace. Without agreed methodologies and standards, attribution risks being used as a political instrument, undermining trust and the integrity of the international legal order.
How do the principles of distinction, proportionality, precaution, necessity, and humanity under IHL apply to cyber operations conducted in situations of armed conflict, including the involvement of large technology companies in geopolitical conflicts?
The application of IHL principles to cyber operations remains one of the most contested and underdeveloped areas of international law in cyberspace. The involvement of private tech companies further complicates the distinction between civilians and combatants, making this an urgent area for further research and dialogue.
How does international human rights law, including the rights to privacy, freedom of expression, non-discrimination, and freedom of association, apply to state conduct in cyberspace, including the binding duty to protect freedom of digital expression across borders and anonymous expression?
Portugal, South Africa, Switzerland (cross-regional group), Estonia
Human rights obligations apply online as they do offline, but the specific application to state conduct in cyberspace, including cross-border dimensions and anonymous expression, requires further elaboration to ensure that cybersecurity measures do not undermine fundamental rights.
Are there genuine gaps in existing international law as it applies to cyberspace, or is the primary challenge one of implementation, capacity, and common understanding of existing rules?
Malawi, Pacific Islands Forum (Tonga), Kiribati, Ireland, Republic of Korea, Singapore, Canada
Before pursuing new legally binding obligations, states need to determine whether the challenge lies in the law itself or in the capacity to understand and implement it. This question is central to the mandate of the global mechanism and has significant implications for the direction of future work.
Should additional legally binding obligations be developed to govern state conduct in cyberspace, and if so, what form should they take and how should they be negotiated?
A significant division exists among member states on whether voluntary norms are sufficient or whether new binding instruments are needed. Resolving this question is fundamental to the long-term direction of the global mechanism and international cyber governance.
How can scenario-based exercises and practical case studies be used within the Dedicated Thematic Groups (DTGs) to translate legal principles into operational understanding for states, particularly those with limited legal capacity?
Kiribati, Pacific Islands Forum (Tonga), Austria, Italy, New Zealand, Ireland, Albania, Botswana
Scenario-based training is identified as one of the most effective methods for building legal capacity and turning abstract legal principles into practical policy choices, particularly for small and developing states that lack specialist international lawyers.
How can legal capacity-building efforts be better tailored to the needs of developing and small island states to enable them to develop national positions on international law and participate meaningfully in global discussions?
Kiribati, Pacific Islands Forum (Tonga), African Group (Nigeria), Germany, Singapore, Mauritius, Armenia, Botswana, Malawi
Many states, particularly small island developing states and developing countries, lack the specialised legal expertise and institutional capacity to engage substantively in international law discussions. Addressing this gap is a prerequisite for inclusive and equitable participation in the global mechanism.
How should the unique technical characteristics of cyberspace — including the cross-border nature of data, anonymity, speed, the significant role of non-state actors, and reliance on privately owned infrastructure — affect the interpretation and application of existing rules of international law developed for physical domains?
Israel, Republic of Korea, Iran, Cuba, Turkey
International legal frameworks developed for physical domains such as maritime, aviation, and space law were crafted after careful consideration of domain-specific characteristics. A similar methodological rigour is needed for cyberspace to avoid premature or inappropriate transposition of rules.
How should the involvement of non-state actors, including large technology companies, in cyber operations and armed conflicts be addressed under international law, particularly with respect to the principles of distinction and military necessity?
China, Colombia, Republic of Korea, Cuba
The growing role of private sector actors in cyber operations, including their participation in armed conflicts, raises novel legal questions about responsibility, distinction, and compliance with IHL that are not adequately addressed by existing frameworks.
How can the global mechanism ensure that the breadth and depth of discussions on international law, particularly on IHL, are accurately reflected in its reporting and outcomes, given that the final OEWG report did not fully capture these discussions?
Switzerland (cross-regional group), Australia (cross-regional group), Germany, Brazil, United Kingdom, Thailand
The failure of the OEWG final report to reflect the richness of legal discussions, especially on IHL, risks losing hard-won progress. Ensuring accurate and comprehensive reporting is essential for continuity and for building on previous achievements.
How can the DTGs facilitate expert briefings from bodies such as the International Law Commission, the ICRC, academia, and civil society to inform states’ understanding of how international law applies in cyberspace?
Italy, Austria, Netherlands, South Africa, United Kingdom
Expert input from legal scholars, international organisations, and civil society is essential for grounding intergovernmental discussions in sound legal analysis and ensuring that policy decisions are informed by the best available expertise.
How should the global mechanism address malicious cyber activities by non-state actors operating from within a state’s territory, and what obligations does this place on the host state?
Colombia, South Africa, Ukraine
The question of state responsibility for cyber operations conducted by non-state actors from their territory is a significant legal gap in practice. Clarifying these obligations is essential for preventing states from serving as permissive environments for criminal cyber ecosystems.
How can the global mechanism promote the publication of national and regional positions on the application of international law in cyberspace, and how can these positions contribute to the development of customary international law?
National and regional positions are a key tool for building common understanding and contributing to the development of customary international law. Encouraging their publication and ensuring they are reflected in the mechanism’s work is important for transparency and legal certainty.
How does Article 51 of the UN Charter, recognising the inherent right of individual and collective self-defence, apply when an armed attack is conducted through cyber means, and what threshold must be met for a cyber operation to constitute an armed attack?
Switzerland (cross-regional group), Ukraine, Cuba
The question of whether and when a cyber operation constitutes an armed attack triggering the right of self-defence under Article 51 is one of the most consequential and contested issues in international cyber law, with direct implications for international peace and security.
How should the global mechanism handle the use of digital platforms and social networks for the forced recruitment of children by armed groups, and how does IHL apply to such activities?
Colombia
The use of digital technologies for the recruitment of minors by illicit armed groups represents a novel and serious humanitarian challenge that sits at the intersection of IHL, human rights law, and cybersecurity, requiring dedicated analysis and practical guidance.
How can the global mechanism address ransomware attacks and malicious cyber activities targeting medical facilities and humanitarian organisations, and what rules of international law apply to such threats?
Netherlands, Canada, Ukraine
Ransomware and attacks on healthcare and humanitarian infrastructure represent some of the most pressing real-world cyber threats. Examining how international law applies to these specific scenarios would provide practical guidance for states and strengthen the protection of civilians.
How should the global mechanism approach the question of accountability for violations of international law committed through ICTs, including strengthening international cooperation on attribution and ensuring that violations do not go without consequences?
Ukraine, Estonia, Malawi
Accountability is a critical element of the rules-based international order in cyberspace. Without effective mechanisms for holding states responsible for internationally wrongful cyber acts, impunity is normalised and confidence in the international legal order is undermined.
How can regional organisations such as the African Union, the EU, the OAS, and ASEAN contribute to advancing discussions on the application of international law in cyberspace and feeding their deliberations into the work of the global mechanism?
Germany, African Group (Nigeria), Philippines, Italy
Regional organisations play an important role in fostering legal discussions and capacity building within their respective regions. Understanding how their work can be integrated into the global mechanism would strengthen the inclusivity and effectiveness of international cyber governance.
How should the global mechanism balance the need to deepen common understanding of existing international law with the question of whether new legally binding obligations are necessary, and how can this discussion be sequenced in a way that is inclusive and evidence-based?
Cameroon, Pacific Islands Forum (Tonga), Kiribati, Singapore, Ireland
The sequencing of discussions on existing law versus new obligations is a fundamental methodological question for the global mechanism. Rushing to new binding instruments before states have the capacity to engage with existing law risks producing instruments that are neither effective nor universally implemented.
How can the global mechanism ensure meaningful participation by relevant stakeholders, including industry, academia, civil society, and legal experts, in discussions on the application of international law in cyberspace?
Austria, United Kingdom, New Zealand, South Africa
Non-governmental stakeholders possess expertise that is essential for grounding legal discussions in technical and operational realities. Ensuring their participation is critical for the quality and legitimacy of the mechanism’s outputs, yet consensus on stakeholder participation remains elusive.
How should the global mechanism address the protection of energy infrastructure from cyberattacks, given its cross-cutting relevance to international law, IHL, and the framework of responsible state behaviour?
Ukraine
Energy infrastructure is foundational to modern society, and its protection from cyberattacks has implications across multiple pillars of the UN framework, including international law, IHL, and voluntary norms. Dedicated discussion of this issue would provide practical guidance for states.
How can the global mechanism develop common terminology and definitions for key concepts such as cyber incidents, information sharing, and types of improper use of ICTs, to enable meaningful consensus and shared understanding?
Cuba
The absence of agreed definitions for fundamental concepts in cyberspace governance creates ambiguity and hinders the development of effective legal frameworks. Establishing common terminology is a prerequisite for substantive progress on international law and other pillars of the mechanism’s work.
Disclaimer: This is not an official session record. DiploAI generates these resources from audiovisual recordings, and they are presented as-is, including potential errors. Due to logistical challenges, such as discrepancies in audio/video or transcripts, names may be misspelled. We strive for accuracy to the best of our ability.
This discussion took place during the fourth meeting of the substantive plenary session of the Global Mechanism on ICT security, covering two main agenda items: existing and emerging ICT threats, and voluntary non-binding norms of responsible state behaviour .
On the threats agenda item, multiple delegations highlighted the growing severity and complexity of the cyber threat landscape. Ghana emphasised the importance of protecting critical information infrastructure, noting the 2024 damage to submarine cable 7-Gamma and describing its national response architecture including 13 identified critical infrastructure sectors and a 24/7 incident response capability . Pakistan warned that threats have evolved into major geopolitical tools, highlighting the militarisation of cyberspace, AI-accelerated cyber warfare, and the destabilising role of disinformation in armed conflict . Romania condemned hostile cyber activities attributed to groups controlled by the Russian Federation, noting a blurring of lines between state and non-state actors . The ICRC drew attention to the use of ICTs in armed conflicts, including attacks on civilian infrastructure, medical facilities, and the recruitment of children, as well as the growing role of civilian hackers and AI in amplifying harm .
On voluntary non-binding norms, a broad consensus emerged around prioritising implementation of the existing 11 agreed norms over developing new ones, though some delegations called for both tracks to proceed in parallel. The Pacific Islands Forum, represented by Tonga, stressed that many states, particularly small island developing states, are still building the capacity needed to operationalise existing commitments . The EU shared a detailed non-paper on its own norms implementation efforts and encouraged other states to do likewise . China, Iran, Cuba, and Morocco argued that additional norms are necessary, particularly regarding AI, data security, and the use of ICTs as instruments of coercive measures . Several delegations, including Israel and the Republic of Korea, opposed developing new norms before existing ones are adequately implemented .
The session was also marked by exchanges under the right of reply, with Israel and Iran trading accusations regarding unlawful cyber operations and military aggression, and Russia responding to Ukraine’s statements on critical infrastructure attacks . The Chair repeatedly urged delegations to remain focused on the agenda and avoid politicisation .
The Chair concluded by noting broad common sentiment around shifting to implementation, the role of dedicated thematic groups in facilitating practical exchanges, and the interconnection of norms with capacity building, signalling that these themes would continue to shape the mechanism’s work going forward .
Keypoints
Overall Purpose
The discussion took place during the fourth meeting of the substantive plenary session of the Global Mechanism on Developments in the Field of Information Communication Technologies (ICTs) in the Context of International Security. The overarching goal was to advance international dialogue on two primary agenda items: (1) existing and emerging ICT threats, and (2) voluntary and non-binding norms of responsible state behaviour in cyberspace. Delegations aimed to identify common priorities, share national experiences, and chart a path toward practical implementation of the agreed normative framework through the newly established Dedicated Thematic Groups (DTGs).
—
Major Discussion Points
The evolving ICT threat landscape and the need for collective response. Multiple delegations highlighted the growing sophistication and scale of cyber threats, including attacks on critical infrastructure, ransomware, disinformation, and AI-enabled cyber operations. Ghana drew attention to the disruption caused by damage to submarine cables and outlined its 13 identified critical information infrastructure sectors . Pakistan warned that threats had evolved from localised IT risks into “major geopolitical tools” and raised concerns about the militarisation of cyberspace and the use of commercial spyware . The ICRC documented how ICT operations in armed conflicts were disabling essential civilian services, targeting medical facilities, and facilitating the recruitment of children . Interpol noted that cybercrime had become “one of the world’s most significant illicit economies” and that AI was “supercharging” criminal supply chains .
The primacy of implementing existing voluntary norms over developing new ones. A significant number of delegations, particularly from the Pacific Islands Forum, the EU, and African states, stressed that the priority should be the full and effective implementation of the 11 voluntary non-binding norms agreed in the 2015 GGE report, rather than negotiating new ones. Tonga, speaking on behalf of the Pacific Islands Forum, stated that “many states, including small island developing states, are still building the capacity needed to operationalise these commitments” . The Republic of Korea affirmed that “our priority of global mechanism should be the effective implementation of existing commitments rather than the development of new norms at this stage” . Vanuatu succinctly captured this position: “The task before us is observance, not expansion” .
Calls for new or legally binding norms, particularly from developing and Global South states. In contrast to the above, Cuba, China, Iran, and others argued that voluntary norms were insufficient given the scale of ongoing violations. Cuba stated that “non-binding voluntary norms therefore only constitute an intermediary step” and called for a “broad, legally binding instrument” . China proposed developing new norms in areas such as AI’s impact on cybersecurity, data security, and supply chain integrity . Iran argued that recent cyber operations had “revealed important gaps in the existing normative framework” and called for a structured process to elaborate additional norms in parallel with implementation efforts .
Capacity building and the digital divide as central concerns, especially for developing nations. Numerous delegations emphasised that developing countries face structural disadvantages in implementing cybersecurity norms due to limited technical and institutional capacity. Nicaragua highlighted that “unilateral coercive measures” directly impacted developing countries’ ability to access technology, software, and digital services, deepening the digital divide . The African Union Commission stressed that “capacity building must remain at the heart of this mechanism” and called for gender mainstreaming and youth inclusion . Botswana noted that developing countries “cannot effectively protect critical infrastructure, prevent cross-border cybercrime, or guarantee the integrity of their supply chains if they lack the underlying technical and institutional capacity to do so” .
Geopolitical tensions and rights of reply disrupting proceedings. The session was periodically interrupted by sharp exchanges between Israel, Iran, Ukraine, and Russia, reflecting broader geopolitical conflicts playing out within the forum. Israel accused Iran of “stunning hypocrisy” regarding international law , while Iran characterised Israeli actions as “unlawful acts of aggression” that struck “at the very foundation of every pillar of the global mechanism” . Ukraine cited Russia’s cyber attacks on its energy and telecommunications infrastructure as a direct violation of the norm protecting critical infrastructure , to which Russia responded by accusing Ukraine of being “the largest haven for online fraudsters in the world” . The Chair repeatedly urged delegations to remain focused on the agenda and avoid politicisation .
—
Overall Tone
The discussion began in a constructive and cooperative tone, with delegations sharing national experiences, expressing support for the new Global Mechanism, and engaging substantively on threats and norms. Most states demonstrated a genuine commitment to multilateral dialogue and practical outcomes, with many offering concrete examples of domestic cybersecurity legislation and capacity-building initiatives.
However, the tone shifted noticeably during the rights-of-reply exchanges between Israel and Iran, and later between Ukraine and Russia. These interjections introduced a confrontational and politically charged atmosphere that the Chair visibly struggled to manage, repeatedly calling for restraint and reminding delegations of time constraints . Despite these disruptions, the majority of delegations maintained a professional and solution-oriented posture throughout. By the close of the session, the Chair’s summary remarks helped restore a sense of shared purpose, noting broad common sentiment around the shift toward implementation .
Speakers Overview
G
Ghana
94 wpm · 4 min
P
Pakistan
142 wpm · 4 min
R
Romania
107 wpm · 4 min
N
Nicaragua
131 wpm · 3 min
A
Armenia
122 wpm · 4 min
B
Bangladesh
139 wpm · 2 min
IC
International Committee of the Red Cross
127 wpm · 5 min
I
Interpol
153 wpm · 3 min
AU
African Union Commission
101 wpm · 4 min
KI
Kenya ICT Action Network
108 wpm · 3 min
DM
Discover MUN Foundation
164 wpm · 3 min
TO
Tonga on behalf of the Pacific Island Forum
123 wpm · 3 min
EU
European Union
157 wpm · 6 min
CR
Costa Rica
137 wpm · 3 min
C
Colombia
117 wpm · 3 min
B
Brazil
126 wpm · 3 min
I
Italy
131 wpm · 4 min
M
Morocco
151 wpm · 2 min
C
Cuba
156 wpm · 3 min
P
Portugal
128 wpm · 3 min
RO
Republic of Korea
131 wpm · 1 min
V
Vanuatu
129 wpm · 3 min
N
Nigeria
98 wpm · 5 min
C
China
118 wpm · 3 min
B
Botswana
140 wpm · 3 min
T
Thailand
134 wpm · 3 min
N
Netherlands
107 wpm · 5 min
NZ
New Zealand
164 wpm · 2 min
IR
Islamic Republic of Iran
137 wpm · 7 min
I
Ireland
150 wpm · 2 min
NM
North Macedonia
130 wpm · 2 min
S
Switzerland
187 wpm · 1 min
A
Albania
114 wpm · 6 min
SA
South Africa
105 wpm · 3 min
M
Malawi
121 wpm · 4 min
U
Ukraine
121 wpm · 5 min
I
Israel
130 wpm · 5 min
RF
Russian Federation
139 wpm · 2 min
CE
Chair Egriselda López
118 wpm · 17 min
Expanded Summary: Fourth Meeting of the Substantive Plenary Session of the Global Mechanism on ICT Security
#
Session Overview and Opening
The fourth meeting of the substantive plenary session of the Global Mechanism on Developments in the Field of Information Communication Technologies in the Context of International Security convened to address two primary agenda items: existing and emerging ICT threats, and voluntary and non-binding norms of responsible state behaviour in cyberspace . The session continued a list of speakers on the threats topic before transitioning to the norms discussion, with delegations from member states, regional organisations, and accredited civil society stakeholders all contributing . The overarching aim was to advance international dialogue, share national experiences, and chart a path toward practical implementation of the agreed normative framework through the newly established Dedicated Thematic Groups (DTGs).
Before giving the floor to civil society speakers, the Chair made an important procedural statement citing Annex 1 of A-80-257, clarifying that accredited interested parties may attend substantive plenary sessions and make oral statements during sessions dedicated to interested parties, and may also deliver interventions after states subject to the Chair’s discretion and availability of time. The Chair indicated she would give the floor to duly accredited entities for three minutes, strictly enforced.
—
#
Existing and Emerging ICT Threats: National Perspectives
Ghana opened the threats discussion by emphasising the growing impact of cyber threats on critical information infrastructure, warning that disruption to such systems can have significant consequences for national security, economic stability, and public confidence . Ghana drew particular attention to the damage sustained by submarine cable 7-Gamma in 2024 and the resulting disruption to digital services, using this as a concrete illustration of the strategic importance of protecting such infrastructure . At the national level, Ghana reported having identified 13 critical information infrastructure sectors under its Cybersecurity Act, which provides for registration, operator obligations, and regular compliance audits . Ghana also described its strengthening national incident response architecture, including four operational sectoral computer emergency response teams (CERTs) and plans to extend coverage to health, energy, utilities, transportation, military, and academic sectors . A 24/7 national incident response capability has been established – designated the national CERT (referred to in the transcript as “SET-TH”) – enabling the public to report cyber incidents directly . Ghana welcomed the Global Point of Contact Directory as a voluntary mechanism to facilitate timely communication among states for incident response , and called for enhanced international cooperation and capacity building to help developing countries address risks associated with artificial intelligence and other emerging technologies .
Pakistan offered a broader geopolitical framing, warning that threats have evolved from localised IT risks into major geopolitical tools capable of disrupting global stability . Pakistan highlighted the increasing number, sophistication, and severity of attacks targeting critical infrastructure, noting that cyber operations routinely paralyse public administration and essential services across borders . The militarisation of cyberspace was described as well underway, with states increasingly deploying cyber instruments for espionage, sabotage, and political influence, often leveraging private proxy groups, criminal syndicates, or commercial spyware vendors . Pakistan also raised concerns about AI-accelerated cyber warfare and the sale of sophisticated surveillance tools to state and non-state actors without adequate safeguards . Disinformation and misinformation were identified as potent threats, with Pakistan arguing that such operations contribute to the outbreak and escalation of violence, obscure violations of international law, and can overwhelm information ecosystems when combined with cyber capabilities . Pakistan’s three coherent proposals were: first, democratising global cyber diplomacy with a focus on ransomware mitigation, critical infrastructure protection, and de-escalation channels; second, establishing international consensus and regulatory guardrails on commercial surveillance tools; and third, examining how disinformation contributes to the outbreak, escalation, and prolongation of armed conflict .
Romania stated that it fully aligns with the statement made by the EU before making its national remarks. Romania reported a significant increase in the number, complexity, impact, and persistence of cyber attacks in recent years, including phishing, social engineering, ransomware, and data exfiltration, all amplified by the rapid development of AI . Romania expressed particular concern about the blurring of lines between state and non-state actors in conducting coordinated attacks, and about attacks targeting critical national infrastructure, democratic institutions, and democratic processes . Notably, Romania, together with other EU member states and allies, had condemned hostile cyber activities conducted by groups controlled by the Russian Federation on 13 July, describing a well-established pattern characterised by a complex cyber ecosystem comprising both state institutions and non-state entities .
Nicaragua recognised that ICT threats are developing swiftly and can impact national security, critical infrastructure, essential services, and the well-being of peoples . Nicaragua highlighted its efforts to strengthen its legal and institutional framework and promote a culture of cybersecurity , while also underscoring that the application of unilateral coercive measures has a direct impact on developing countries’ ability to access technology, software, digital services, financing, and knowledge transfer . These measures were described as deepening the digital divide, weakening national capacity, and making it difficult to protect critical infrastructure, with Nicaragua calling for an end to what it characterised as illegal measures in breach of the UN Charter .
Armenia noted that ICT-related threats continue to evolve in scale, sophistication, and frequency, posing risks to states, critical infrastructure, and international stability, and emphasised that given the transboundary nature of cyberspace, no state can effectively address these challenges alone . Armenia explicitly stated it would intervene under both items of the day’s agenda to save time – a procedural choice that explains why Armenia’s statement covered both threats and norms. Bangladesh expressed particular concern about ransomware and denial-of-service attacks against government services and the financial sector, and called for a comprehensive, cooperative international approach to ransomware, including cooperation on tracing illicit finance . Bangladesh specifically called for dedicating confidence-building measures to submarine cable protection – a concrete proposal distinct from merely expressing concern about such infrastructure. Bangladesh also noted growing concern about AI-enabled threats and disinformation generated through advanced technologies . It should be noted that Bangladesh’s statement was cut off mid-sentence in the transcript (“Bangladesh shall remain constructively engaged in this global”), indicating the full statement was not captured.
—
#
The ICRC, Interpol, and the African Union: Institutional Perspectives on Threats
The International Committee of the Red Cross (ICRC) provided one of the most substantively distinctive contributions of the session, grounding the threats discussion in direct field observation from armed conflicts. The ICRC noted that the number of armed conflicts had risen to alarming levels, with over 150 armed conflicts recorded in 2025, and observed an increasing use of ICT capabilities for military operations by state and non-state actors . The ICRC noted it had submitted its observations in a working paper to the Global Mechanism. The ICRC identified four key trends: first, ICT operations are disabling essential civilian services, including power, transport, banking, water supply, and food production, even without causing physical damage ; second, medical facilities and humanitarian organisations are being targeted, with intrusions into systems and exfiltration of sensitive data threatening the safety and dignity of those served ; third, ICTs are being used to recruit children into armed forces via social media and messaging apps, with recruiters now able to contact more children more quickly through online communities – the ICRC emphasised that the involvement of children in armed conflict is unlawful and harms them ; and fourth, civilian hackers and hacktivists are operating in several armed conflicts, often ignoring the limits that international humanitarian law imposes on ICT operations . The ICRC also warned that the growing use of AI in ICT activities will increase their speed, scale, and potential for harm, raising risks of indiscriminate attacks, incidental civilian harm, and uncontrolled escalation . The ICRC called upon member states to reflect the realities of today’s armed conflicts in their discussions and to identify practical measures to mitigate harm to affected populations .
Interpol reframed the cybercrime discussion by characterising it as one of the world’s most significant illicit economies, generating trillions of dollars and affecting governments, businesses, and citizens across every region . Interpol described cybercrime as increasingly industrialised, with specialised actors offering malware as a service, renting malicious infrastructure, and providing services supporting every stage of the criminal lifecycle . The rapid development of AI was described as supercharging this criminal supply chain, increasing the volume, speed, scale, and accessibility of cyberattacks – and even creating new targets . Interpol highlighted that tools and infrastructure developed within criminal ecosystems can also be exploited by a broader range of malicious actors, including state-sponsored actors . Interpol reported on Operation Synergy F3, which brought together more than 70 countries, resulting in close to 100 arrests and the takedown of some 45,000 malicious infrastructure . Interpol expressed readiness to contribute its operational expertise to the work of the global mechanism .
The African Union Commission noted that Africa continues to face an evolving ICT threat landscape, including malicious cyber activities targeting critical infrastructure, ransomware, online fraud, supply chain vulnerabilities, and growing AI security challenges . The Commission described continental initiatives including the initiation of a Continual Declaration on Peace and Security in Cyberspace. The Commission encouraged DTG1 to prioritise practical progress in areas including the implementation of international law in cyberspace, critical infrastructure protection, and AI-related threats . The Commission also welcomed the establishment of DTG2 and called for early progress toward a global ICT security cooperation and capacity-building portal, emphasising that capacity building must remain at the heart of the mechanism and should ensure gender mainstreaming and youth employment .
—
#
Civil Society Perspectives on Threats
The Kenya ICT Action Network argued that for civil society, cybersecurity is not an abstract geopolitical exercise but a matter of human safety, fundamental rights, and democratic survival . The Network highlighted the unchecked proliferation of commercial spyware and state-sponsored cyber harassment used to monitor, intimidate, and silence journalists, human rights defenders, and political dissenters . It also raised concerns about AI-driven automated surveillance and deepfakes weaponising digital spaces to erode electoral integrity and supercharge gender-based violence, with these tools disproportionately targeting women, persons with disabilities, minorities, and other vulnerable groups . The Network called on member states to ground all cyber norms in human rights, protect civic space, end intrusive surveillance, and ensure meaningful multi-stakeholder participation .
The Discover MUN Foundation, speaking on behalf of the Youth Publications and Socioeconomic Forum, emphasised that ICT security depends not only on technologies and institutions but also on human capacity, particularly among young people . Drawing on preliminary research findings from a study of over 700 secondary school students, the Foundation noted that students in non-STEM disciplines expressed significantly greater concern about AI-related job displacement than their STEM peers, even after accounting for AI use and skill . This finding was presented as a broader lesson for cyber capacity building: mere exposure to technology does not necessarily create understanding, preparedness, or resilience . The Foundation called for youth-serving organisations and capacity-building practitioners to be recognised as important stakeholders in the global mechanism and for member states to nominate qualified youth practitioners to the DTGs .
—
#
Chair’s Synthesis of the Threats Discussion
Following the threats discussion, the Chair provided a synthesis of common themes, noting the complexity of the threat landscape, the range of actors and tools involved, the impact of emerging technologies such as AI, the continued relevance of ransomware, the specific vulnerabilities of critical infrastructure in areas such as health, education, public administration, and financial services, and the importance of protecting critical information infrastructure such as submarine cables . The Chair also noted calls for supply chain protection and highlighted that the discussion would inform the development of the pillars of the framework for responsible behaviour . The Chair observed concrete calls to action from many delegations, including for exchange of information on threats, cooperation, capacity building, incident response, recovery, and the creation of resilience .
—
#
Voluntary and Non-Binding Norms: The Implementation-First Consensus
The session’s second major agenda item – voluntary and non-binding norms of responsible state behaviour – generated the most substantive and wide-ranging debate. A broad coalition of states converged on the view that the primary task of the global mechanism should be implementing the existing 11 voluntary non-binding norms agreed in the 2015 GGE report, rather than developing new ones.
Tonga, speaking on behalf of 15 Pacific Islands Forum members – Australia, the Cook Islands, Fiji, Kiribati, the Federated States of Micronesia, the Republic of the Marshall Islands, Nauru, New Zealand, Palau, Papua New Guinea, Samoa, Solomon Islands, Tuvalu, Vanuatu, and Tonga itself – reiterated the Forum’s longstanding position that the priority must remain the implementation of the existing voluntary non-binding norms . The Forum noted that member states are at varying stages of operationalising these norms, including identifying critical infrastructure, strengthening incident response capacity, and building technical and policy foundations . Many states, including small island developing states, are still building the capacity needed to operationalise existing commitments . The Forum described the Voluntary Norms Implementation Checklist as a helpful step towards mainstreaming implementation but noted the need for consolidated guidance, capacity support, and peer exchanges . The Forum called for the mechanism to take the checklist forward in a concrete, action-oriented fashion through the DTGs, and highlighted the potential for technical experts, regional organisations, the private sector, academia, and civil society to contribute to this work .
The European Union reaffirmed its strong commitment to the full and effective implementation of the UN Framework of Responsible State Behaviour in Cyberspace, describing the 11 non-binding voluntary norms as a central pillar whose practical implementation contributes to enhanced transparency, predictability, and accountability . The EU published an initial overview of its member states’ implementation efforts, using the 2021 GGE norms guidance and detailing legislation, policies, structures, mechanisms, and networks put in place to implement the norms . The EU provided an example of how it approaches norm 13b on ICT incident response, describing the coordinated roles of national cyber agencies and relevant EU bodies . The EU encouraged other states to share their implementation experiences and described the DTGs as best placed to elaborate on norms implementation connected to specific cybersecurity challenges . The EU also described the draft voluntary norms checklist as a valuable tool and called for it to be treated as a living document .
Costa Rica emphasised that the global mechanism must build on the accumulated body of work of the GGEs and OEWGs, with the goal not of reopening previously reached consensuses but of consolidating them and translating them into national practices, institutional capacities, and concrete cooperation . Costa Rica stressed that voluntary norms complement international law by offering practical guidance to foster transparency, predictability, restraint, and trust , and called for practical implementation of norms particularly relevant to the protection of critical infrastructure, essential services, and government functions . Costa Rica specifically called for recognition of CERTs as trusted technical actors distinct from offensive intelligence or law enforcement functions – a substantive policy position. Costa Rica also argued that due diligence should be approached as both a responsibility and an agenda for cooperation, technical assistance, and institutional capacity building .
Colombia identified the principal challenge as not the absence of norms but effective implementation, noting that questions remain about how states interpret and apply agreed norms and what challenges limit cooperation and timely exchange of information . Colombia invited states to consider voluntarily publishing their national positions on the interpretation and application of specific norms, arguing this would promote mutual understanding and facilitate the exchange of best practices .
South Africa proposed that DTG1 prioritise focused deliberations on norms F, G, and H regarding the safeguarding of critical infrastructure and critical information infrastructure, as a practical step for sharing knowledge, lessons learned, and expertise . South Africa described its Critical Infrastructure Protection Act of 2019, which mandates the identification and implementation of appropriate measures to safeguard infrastructure vital for public safety, national security, and essential services .
Malawi offered one of the session’s most philosophically precise articulations of the rationale for voluntary norms, arguing that norms do not exist because cyberspace is predictable but precisely because it is not, providing predictability, confidence, and a shared understanding of responsible behaviour even when laws differ . Malawi similarly called for close attention to norms F, G, and H, noting that destruction of critical information infrastructure often leads to breach of international humanitarian law . Malawi described its national implementation efforts, including its Computer Emergency Response Team, Data Protection Authority, national cyber drills, and multi-stakeholder engagements . Malawi concluded with the observation that the strength of the framework will not be measured by the number of additional norms developed but by collective commitment to uphold those already agreed, calling for implementation to become the framework’s legacy .
Brazil affirmed its support for the key outputs of previous UN processes, noting that the continued relevance of the norms after a decade of technological change is a testament to how well they were drafted by focusing on actions rather than specific technologies . Brazil welcomed efforts to facilitate norms implementation, including the voluntary checklist, and highlighted regional cooperation through the OAS CISERT Americas and the Mercosur Cybersecurity Commission as particularly relevant . Brazil also emphasised that the promotion of gender equality is a key component of adequate norms implementation . Brazil offered a bridging position, arguing that advancing implementation of existing norms and adopting new ones are not mutually exclusive, and that the global mechanism can accommodate both as long as there is consensus . Brazil also warned that many initiatives currently underway outside the multilateral process aim to shape state behaviour in areas that fall within the mechanism’s purview, implicitly cautioning against the mechanism becoming irrelevant if it does not act .
Italy called for priority to be given to supporting states in translating agreed norms into national policies, institutional procedures, and operational practices . Italy described its implementation of norm I on supply chain security through the National Cyber Security Agency, and highlighted the importance of integrating IT and OT security requirements, coordinated vulnerability disclosure procedures, and multi-stakeholder partnerships . Italy expressed strong belief that DTG1 can play a key role in facilitating thorough discussion across the five pillars, while DTG2 can produce tailored capacity-building projects .
Morocco argued that the list of norms should not be set in stone given the rapid evolution of threats and the emergence of new technologies including AI, and that the framework must be able to evolve . Morocco called for action focused on effectively implementing existing norms, emphasising that a norm only maintains its value if implemented coherently by all states, and stressed the importance of technical capacity building for developing states . Morocco further called for the DTGs to examine this topic and present concrete proposals for enriching the normative framework. This position bridges the implementation-first and new-norms camps, placing Morocco alongside Brazil, Armenia, and Thailand as a delegation open to normative evolution while prioritising implementation.
Portugal argued that the permanent mechanism was deliberately designed to be more stable than its predecessors and more oriented towards implementation of the 11 voluntary norms and applicable international law than towards discussion of more norms or binding instruments . Portugal expressed strong belief that the two DTGs have the potential to lead towards action-oriented results to be debated during the next plenary session .
The Republic of Korea affirmed that the global mechanism should build upon the consensus achieved through the GGE and OEWG processes and focus on identifying practical ways to effectively implement the 11 voluntary non-binding norms . The Republic of Korea called for the voluntary checklist to continue to serve as a living document, with the global mechanism continuing discussions with a view to its eventual finalisation . The Republic of Korea stated clearly that the priority of the global mechanism should be the effective implementation of existing commitments rather than the development of new norms at this stage .
Vanuatu grounded its intervention in its national circumstances, noting that the norms concerning critical infrastructure carry particular weight for a country whose survival infrastructure is digital, including its multi-hazard early warning network, emergency broadcast capability, and systems for coordinating relief across 83 islands . Vanuatu invited states to affirm through their conduct that infrastructure enabling disaster preparedness and response falls squarely within the protection these norms describe, arguing that there could be no clearer test of responsible behaviour than restraint towards systems that keep vulnerable populations alive . Vanuatu stated plainly that the task before states is observance, not expansion, and that existing commitments have not yet been implemented by all states to a standard that would reveal any genuine gap . Vanuatu expressed readiness to share its own experience candidly, including where its implementation remains work in progress, and encouraged others to do the same .
Nigeria reaffirmed its commitment to preserving the state-led, single-track, inclusive, transparent, and consensus-based nature of the mechanism, noting that consensus has consistently enabled progress . Nigeria called for the mechanism to translate agreed commitments into practical measures that strengthen national capacities, enhance resilience, and deliver tangible benefits for all member states, particularly developing countries . Nigeria welcomed the DTGs and supported scenario-based discussions as an effective means of strengthening implementation, improving collective preparedness, and facilitating practical cooperation .
Botswana emphasised that the 11 voluntary norms are sufficient to govern state conduct and that the DTGs should formulate concrete strategies for effective implementation using the UN Cyber Norms National Implementation Checklist .
Thailand noted that ASEAN, as the first regional organisation to adopt these norms in principle, has finalised its Norm Implementation Checklist, and that Thailand has integrated the norms into its National Policy and Action Plan on Cybersecurity 2022-2027 . Thailand remained open to discussions on the possible development of additional norms, particularly in response to emerging threats, provided they do not impose obligations beyond states’ capacities or serve as a means of technological exclusion .
The Netherlands described the 11 norms as conferring a degree of mutual expectations on states to behave responsibly in cyberspace, and called for the DTGs to discuss norms not in isolation but in a cross-cutting manner with other pillars of the normative framework when addressing specific cyber threats . The Netherlands proposed using guiding questions to prompt member states to discuss norms in conjunction with international law, confidence-building measures, and capacity building, rather than tackling each pillar sequentially . The Netherlands also called for the voluntary checklist to be strengthened and operationalised as a voluntary instrument for self-reporting on the implementation of the 11 norms .
New Zealand reiterated the Pacific Islands Forum’s message that the regional priority is fully implementing the existing norms, and called for the global mechanism to provide further guidance and capacity-building coordination to support implementation at the national level . New Zealand highlighted the value of the EU’s non-paper on norms implementation and the ASEAN Norms Implementation Checklist as practical references for all states .
Ireland affirmed that the 11 voluntary non-binding norms are central to maintaining international security and stability, and called for states to show how they are seeking to implement the norms, citing the EU’s implementation paper as an example . Ireland supported the voluntary checklist as a valuable reference and called for capacity-building programmes to assist with implementation, particularly on the applicability of international law in cyberspace .
Ukraine described the 11 voluntary norms as remaining as relevant today as when first agreed, and emphasised that their effective implementation is essential for reducing risks, strengthening resilience, and preventing conflict . Ukraine focused on two norms of particular importance in light of the current security environment: the protection of critical infrastructure, and the responsibility of states not to knowingly allow their territory to be used for internationally wrongful ICT acts . Ukraine described Russia’s cyber attacks as targeting the energy sector, telecommunications, public administration, and transport infrastructure, with the purpose of undermining state resilience and amplifying the effects of missile and drone attacks . Ukraine also observed the growing convergence between state-sponsored cyber operations and cybercriminal ecosystems, noting that malicious actors operating from Russian territory have repeatedly targeted Ukraine and partner states while benefiting from a permissive environment . Ukraine countered arguments for legally binding instruments by noting that the UN Charter is already legally binding and has not prevented Russia from acting in breach of its provisions . Ukraine also called for thematic discussions to address risks to critical infrastructure from the malicious use of AI by states, state-sponsored actors, and criminals, as well as risks from supply chain vulnerabilities, data poisoning, and manipulation of AI systems .
Switzerland highlighted the Geneva Dialogue and the Geneva Manual – described as a living document with its first two chapters focusing on supply chain security, vulnerability reporting, and critical infrastructure protection – as products of multi-stakeholder engagement that map roles and responsibilities in implementing voluntary norms . Switzerland argued that broad and meaningful participation of stakeholders in the DTGs is not only necessary but advantageous to all states .
Armenia recognised that the framework is dynamic and evolving, and that additional voluntary non-binding norms could be developed over time in response to emerging challenges, guided by inclusiveness, transparency, and consensus .
North Macedonia, Albania, Botswana, and Thailand all affirmed their commitment to implementing the existing norms and described national legislative and institutional measures taken to give effect to them . Albania provided a particularly detailed account of its Law on Cybersecurity, which transposes the EU NIS2 Directive, and described how its national cybersecurity structures, including a National SOC and CERT, give concrete effect to agreed UN norms .
Israel stated that there is no need to develop or elaborate upon any new norms before adequately addressing the compliance gap with the current framework, arguing that the reality of the current landscape demonstrates that the existing norms are being flouted by certain states . Israel argued that pursuing a legally binding instrument without broad agreement on key concepts would waste the considerable diplomatic capital invested in the global mechanism and would be both premature and counterproductive . Israel suggested that the DTGs could serve as a practical forum for sharing national best practices and evaluating whether and how existing norms are understood and applied, and could also revisit the implementation checklist in a more granular and cautious way .
—
#
Calls for New or Legally Binding Norms
In contrast to the implementation-first consensus, a number of delegations argued that the existing voluntary framework is insufficient and that new or legally binding norms are necessary. These positions fall into three broad sub-groups.
Calling for legally binding instruments, Cuba explicitly reaffirmed its position in favour of developing legally binding norms under the auspices of the United Nations, arguing that non-binding voluntary norms only constitute an intermediary step towards achieving the goal of a secure cyberspace . Cuba pointed to the annual increase in cyber attacks as empirical evidence that voluntary norms on their own are not enough, and described the growing militarisation of cyberspace and politically motivated false attributions as further evidence of the framework’s limitations . Cuba called for a broad, legally binding instrument establishing obligations with permanent monitoring, and suggested that the ITU’s Global Cybersecurity Index could provide a starting point for developing a roadmap .
Calling for additional voluntary norms, China argued that the global mechanism should develop new norms in several areas: AI’s impact on cybersecurity, including establishing barriers for frontier AI models; data security, including universal, non-discriminatory international norms on cross-border data flows; critical infrastructure protection, including prohibitions on using cyber means to damage other countries’ key information infrastructure; and supply chain security, including globally interoperable common rules and standards . China called for DTG1 to give serious consideration to these proposals .
Iran argued that the global mechanism has an explicit mandate to elaborate additional rules, norms, and principles of responsible state behaviour, citing paragraph 36D of the OEWG final report and paragraph 9 of Annex C . Iran contended that recent developments – including alleged unlawful cyber operations targeting Iranian critical infrastructure, exploiting ICT supply chains, and integrating cyber capabilities with conventional military operations – have revealed important gaps in the existing normative framework . Iran called for further normative development in areas including data security, accountability of private sector entities, and the use of ICTs for unilateral coercive measures . Iran argued that the balance between developing new norms and implementing existing ones has not been maintained, and proposed that the Chair prepare an initial consolidated draft compiling proposals for additional norms submitted by member states .
Taking a bridging position open to new norms under certain conditions, Brazil, Armenia, Thailand, and Morocco all acknowledged that the framework is dynamic and that additional norms could be considered in response to emerging challenges, provided any such development is guided by inclusiveness, transparency, and consensus, and does not impose obligations beyond states’ capacities .
—
#
Geopolitical Tensions and Rights of Reply
The session was periodically disrupted by sharp exchanges between delegations reflecting broader geopolitical conflicts. Israel requested the floor to respond to what it characterised as the stunning hypocrisy of the Iranian regime’s statements about international law and aggression . Israel argued that Iran has no moral standing to invoke international law and specifically requested the Chair to “exercise your leadership,” stating that Iran cannot be allowed to continue to derail discussions and waste precious time .
Iran responded by accusing Israel of two unlawful acts of aggression against Iran over the past year, arguing that these actions strike at the very foundation of every pillar of the global mechanism . Iran made specific allegations including reference to schoolgirls killed in an attack on an elementary school in Minob, characterised resistance groups in the region as legitimate resistance movements under UN General Assembly Resolution 46-51, and described those who bomb hospitals and schools as the real terrorists . Iran argued that referring to these actions neither politicises nor derails discussions but constitutes a clear illustration of the malicious ICT activities that the process seeks to prevent .
Ukraine cited Russia’s cyber attacks on its energy, telecommunications, and public administration infrastructure as a direct violation of the norm protecting critical infrastructure , prompting Russia to use its right of reply to accuse Ukraine of being the largest haven for online fraudsters in the world and a hub for hackers acting with government support to damage Russian civilian infrastructure . Russia made specific reference to call centres which defraud retirees, blackmail and extort people, and encourage young people to carry out terrorist attacks in Russia, and characterised Ukraine as the most brazen violator of the framework of responsible behaviour .
The Chair intervened on multiple occasions to urge delegations to remain focused on the agenda, noting that there are ways of better using limited time and that these political exchanges should not consume the session . The Chair reminded delegations that the mechanism has a great deal to tackle and that it was already late in the afternoon . The Chair also offered Ukraine the option to use its right of reply immediately, noting that interpreters had provided an additional ten minutes, but Ukraine chose to defer its right of reply to the following day .
—
#
Chair’s Synthesis of the Norms Discussion
Concluding the norms discussion, the Chair provided general reflections, noting a broad emphasis on shifting to implementation as a matter of major significance for all states, particularly small ones . The Chair observed calls to continue discussions on common understandings of how norms will be applied in practice, with the DTGs serving as the main forum for these exchanges . The Chair noted that a number of delegations had mentioned the checklist for implementation, that some had emphasised that additional norms could be considered given the evolving digital environment, and that many had highlighted the interconnection of norms with capacity building and development . The Chair described a great deal of common sentiment as regards implementation and indicated that the global mechanism would meet again the following morning to begin the agenda item on the continued study of how international law applies to the use of ICTs – specifically, including consideration of whether gaps exist and the possible future elaboration of additional legally binding obligations if appropriate . The Chair also reminded delegations of the dedicated stakeholder segment scheduled for the following afternoon and encouraged participation .
—
#
Unresolved Issues and Structural Tensions
The session left several significant issues unresolved. The central normative disagreement – whether to develop new or legally binding norms alongside implementing existing ones – remained a persistent fault line, with Cuba calling for a legally binding instrument; China and Iran calling for additional voluntary norms; Israel, Portugal, the Republic of Korea, and Vanuatu firmly in the implementation-first camp; and Brazil, Armenia, Thailand, and Morocco occupying a bridging position . The modalities for meaningful multi-stakeholder participation in the DTGs also remain an outstanding issue, with the Chair noting that consultations towards a pragmatic solution are ongoing . The extent to which disinformation, the accountability of private sector entities, and the impact of unilateral coercive measures should be addressed within the normative framework has not been resolved . The finalisation and operationalisation of the Voluntary Norms Implementation Checklist, including whether it should serve as a self-reporting instrument, also requires further negotiation .
Despite these tensions, the session demonstrated a solid foundation of shared purpose: broad agreement on the importance of implementing existing norms, the value of the DTGs as practical forums, the centrality of capacity building for developing countries, and the critical importance of protecting critical infrastructure from ICT threats. The Chair’s synthesis reflected this moderate consensus, providing a basis for the mechanism’s continued work in the months ahead.
—
Chair Egriselda López
The fourth meeting of the substantive plenary session of 2026 of the Global Mechanism on Developments in the Field of Information Communication Technologies in the Context of International Security and Advancing Responsible State Behaviour in the Use of ICTs. As I indicated prior to lunch, we’re going to continue with our list of speakers under the topic of threats. And so we are going to hear first from the representative of Ghana, who will conclude her intervention. I would ask her to begin where she left off. And then we will continue with Pakistan, Romania, Nicaragua. And Armenia. Ghana, you have the floor.
—
Ghana
Thank you, Chair. Madam Chair, Ghana remains committed to working with member states, regional organizations, and other stakeholders to address both existing and emerging ICT threats. We are particularly concerned by the growing impact of cyber threats on critical information infrastructure whose disruption can have significant consequences for national security, economic stability, and public confidence. The damage to submarine cable 7 -Gamma in 2024 and the resulting disruption to digital services reinforce the importance of protecting such infrastructure as a strategic national asset. At the national level, Ghana has identified 13 critical information infrastructure sectors under the Cybersecurity Act. which provides for the registration of critical information infrastructure, establishes obligations for operators, and requires regular compliance audits. Ghana is also strengthening its national incident response architecture through national and sectoral computer emergency response teams. Currently, four sectoral sets are operational, and plans are underway to operationalize additional sets for health, energy, utilities, transportation, military, and academic sectors. Ghana has also established a 24 -7 national incident response capability, enabling the public to report cyber incidents directly to the national set, that’s a SET -TH. This has significantly strengthened our ability to respond to cyber incidents and support affected individuals and organizations. In this regard, Ghana welcomes the establishment of the Global Point of Contact Directory as an important voluntary mechanism to facilitate timely communication and cooperation among states for incident response. Like many countries, Ghana continues to confront threats such as business email compromise, online fraud, scams, and other forms of cyber -enabled crime. Emerging technologies, including artificial intelligence and quantum computing, present both significant opportunities and new security challenges. Ghana’s National Artificial Intelligence Strategy seeks to harness artificial intelligence to promote inclusive development while ensuring that its adoption is secure, responsible, and resilient. We therefore support enhanced international cooperation and capacity building to help developing countries address the evolving risks associated with AI and other emerging technologies. As we move forward, Ghana believes that no country can address these challenges alone. We remain committed to working with member states and all relevant stakeholders to strengthen international cooperation, address existing and emerging ICT threats, and contribute to a secure and resilient cyberspace for all. Thank you, Madam Chair.
—
Chair Egriselda López
Thank you. I give the floor next to the delegation of Pakistan.
—
Pakistan
Thank you, Madam Chair. I congratulate you on assumption of your responsibilities as well as your able and dynamic team. As we begin substantive work of the global mechanism, the ICT threat landscape continues to evolve. Threats have evolved from localized IT risks into major geopolitical tools capable of disrupting global stability. Attacks targeting critical infrastructure have increased in number, sophistication, and severity, threatening human life and national stability. Cyber operations routinely paralyze public administration and essential services across borders. Militarization of cyberspace is well underway. States increasingly deploy cyber instruments for espionage, sabotage, or political influence, often leveraging private proxy groups, criminal syndicates, or commercial spyware vendors. Commercial hardware, cloud infrastructure, and software tools have been repurposed for military or intelligence operations making non -proliferation and oversight exceptionally challenging. In addition, the AI -accelerated cyber warfare poses new challenges to international peace and security. Sophisticated surveillance tools sold to state and non -state actors are frequently used without safeguards or oversight. Amongst potent threats affecting international ICT security environments, are misinformation and disinformation, both by states and non -state actors. This information contributes to the outbreak and escalation of violence by manipulating threat perceptions, deepening identity -based visions, and mobilizing populations toward confrontation. It obscures violations of international law, including international humanitarian law and international human rights law, distorts humanitarian realities, and sustains military operations through narrative control. When combined with cyber capabilities, coordinated campaigns can overwhelm information ecosystems, disrupt decision -making, and accelerate conflict dynamics. Madam Chair, Member States must commit to voluntary norms of responsible state behavior alongside international law, including the UN Charter. In addition, we need to establish clear international commitments. that critical infrastructure, especially healthcare, energy and water, must remain strictly off -limits during peace and conflict. In this challenging environment, implementing confidence -building measures assumes greater importance. Operational coordination of cybersecurity authorities is critical to facilitate rapid communication during crisis events and to avoid accidental conflict. In this respect, we suggest three points. Global mechanism is an important opportunity to democratize global cyber diplomacy. We should focus our dialogues on practical issues affecting all regions, such as ransomware mitigation, critical infrastructure protection and de -escalation channels. 2. Establish international consensus and regulatory guardrails. 3. Establish a comprehensive and comprehensive framework for the implementation of the new cyber security system. 4. Establish a comprehensive and comprehensive framework for the implementation of the new cyber security system. 5. Establish a comprehensive and comprehensive framework for the implementation of the new cyber security system. 6. Establish a comprehensive and comprehensive framework for the implementation of the new cyber security system. 10. Establish a comprehensive and comprehensive framework for the implementation of the new cyber security system. 12. Establish a comprehensive and comprehensive framework for the implementation of the new cyber security system. and the misuse of commercial surveillance tools. Three, examine how disinformation, including as part of cyber and hybrid warfare, contributes to the outbreak, escalation, and prolongation of armed conflict, and seek to address this critical issue. Madam Chair, cybersecurity, especially for developing nations, is not merely an IT challenge. It is an economic, sovereign, and human security issue. Maintaining international cyber stability requires moving from passive agreements on norms to implementation, combining clear legal guardrails with operational communication channels, targeted capacity building, and working on practical confidence -building ways. I thank you.
—
Chair Egriselda López
Muchísimas gracias. Thank you very much. I now give the floor to the delegation of Romania.
—
Romania
Thank you, Madam Chair. Romania fully aligns with the statement made by the EU and makes the following remarks in its national capacity As it is the first time I’m taking the floor I would like to thank you Madam Chair and your team for all the work in order to ensure a fruitful session of the global mechanism Romania expressed its interest to contribute constructively to the work of this new global mechanism Madam Chair A clear understanding of the threats and challenges in the cyber domain is of high importance for our future activity within the GMAC framework and for enduring meaningful results This is as important as ever nowadays given the fact that cyber threats are more and more prominent They continue to target our societies, economies and are having increasingly negative effects on our societies and our citizens In the last years, Romania witnessed a significant increase in number, complexity impact and persistence of cyber attacks Thank you Phishing, social engineering, ransomware, cyber frauds, attacks against informatic networks, as we have recently seen, for data exfiltration continue to represent persistent threats amplified by the rapid development of AI models. At the same time, we have been exposed to cyber attacks as part of sophisticated hybrid and interference campaigns. As malicious behavior in cyberspace is intensifying, we are concerned by the blurring lines between non -state and state actors in conducting coordinated attacks. We are particularly concerned of the attacks targeting critical national infrastructure, democratic institutions, and democratic processes. On the 13th of July, Romania, together with other EU member states and allies, had condemned hostile cyber activities, conducted by groups controlled by the Russian Federation. These activities form a part of a well -established pattern characterized by the use of a complex cyber ecosystem comprises both state institutions and non-state entities. Madam Chair, raising awareness on cyber threats is essential for ensuring international security and stability. We remain committed to continue to contribute to the international efforts meant to prevent, deter, and counter such destabilizing actions. The DTGs could play an important role in this respect, as the right venues for exchanging views and formulating recommendations on better implementing the existing normative framework. As well, our focus should be on applying the international law and international humanitarian law in cyberspace and build capacities looking at critical infrastructure and critical information infrastructure. Thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Nicaragua. Thank you. They will be followed by Armenia and Bangladesh.
—
Nicaragua
Thank you, Madam Chair. Nicaragua welcomes the convening of this first substantive session of the Global Mechanism and we reaffirm our readiness to participate constructively in this work. The creation of the mechanism represents an opportunity for consolidating a permanent and transparent inclusive space where all can participate under conditions of equality and contribute to building common understandings. Our work should be focused on promoting an environment for ICTs that is secure, safe, stable, accessible, peaceful and interoperable based on the principles of the Charter of the United Nations including the sovereign equality of states, non -interference in internal affairs and the peaceful settlement of disputes. Madam Chair. Nicaragua recognizes that the existing and emerging threats in the area of ICTs is developing swiftly and can impact the security of states, the functioning critical infrastructure, the provision of essential services and the well -being of our peoples amongst them. For this reason, we have been strengthening our legal and institutional framework by adopting laws with the aim of strengthening the protection of telecommunication systems and infrastructure to promote a more secure and resilient digital environment, broadening access to ICTs and consolidating national capacity for tackling threats derived from their malicious use. Similarly, our country is driving initiatives aimed at promoting a culture of cybersecurity to strengthen digital security and to broaden technical capacity to tackle with cybernetic threats. While we recognize that no, countries, especially in developing countries, can… tackle these challenges in isolation. In this context, international cooperation and exchange of experiences, technical support and capacity building should be the basic building blocks for all countries to tackle the threats resulting from malicious use of ICTs while fully respecting the national sovereignty and their priorities. Similarly, NICRA underscores that the application of unilateral coercive measures has a direct impact on developing ICTs and also in terms of response to attacks, access to technology, to software, digital services and financing and knowledge transfer also impacts. These measures deepen the digital divide, they weaken national capacity, they make it difficult to protect critical infrastructure and they are an impediment to the right to development of our people. This is why, we call for an end to these illegal measures. that are in breach of the principles of the Charter of the United Nations. Madam Chair, Nicaragua will continue contributing to an inclusive, transparent and balanced mechanism aimed at concrete results that promote the peaceful use of information and telecommunications technologies and to strengthen international cooperation and contribute to the development and well -being of all of our peoples.
—
Chair Egriselda López
Thank you very much. I now give the floor to the Delegation of Armenia.
—
Armenia
Thank you, Madam Chair. As this is the first intervention by this delegation, we would like to join others in congratulating you on your election as the first chair of the global mechanism. You can count on our constructive engagement. Taking into account your request to limit our interventions, I will now intervene under both items of today’s agenda. Information and communications technologies, have become an integral component of international peace and security. As digitalization advances, ICT -related threats continue to evolve in scale, sophistication, and frequency, posing risks to states, critical infrastructure, and international stability. The evolving ICT threat landscape underscores the importance of the international cooperation. Given the transboundary nature of cyberspace, no state can effectively address these challenges alone. Collective efforts are therefore essential to strengthen resilience, promote responsible state behavior, and ensure global peace and security. We are confident that the global mechanism will provide an effective and inclusive platform for addressing ICT threats. fostering dialogue and strengthening international cooperation. The dedicated thematic groups will facilitate focused and action -oriented discussions, while DTG2, dedicated to accelerating ICT security capacity building, will play a vital role in identifying needs, facilitating partnerships, and strengthening the capacities of all states to effectively implement the agreed UN framework. We recognize the importance of the voluntary, non -binding norms of responsible state behavior in the use of ICTs, as set out in the 2015 GGE report, which established a common understanding of responsible state conduct. We further acknowledge that the 2021 GGE report provided an additional layer of understanding regarding the interpretation, application, and implementation of these norms. We support efforts to advance responsible state behavior and the further development of the framework over time We recognize that states have different levels of capacity and resources to implement the framework of responsible state behavior in the use of ICTs We emphasize the importance of capacity building, international cooperation, and support to enable all states to effectively implement these norms Furthermore, we recognize that the framework for responsible state behavior in cyberspace is dynamic and evolving And that additional voluntary non -binding norms could be developed over time Where appropriate, in response to emerging challenges and developments in ICTs We emphasize that any further development of norms should continue to contribute to international peace and security And that additional voluntary non -binding norms should continue to contribute to international peace and security And be guided by inclusiveness, transparency, and consensus among states We support continued exchange of views and best practices among states to enhance common understanding and promote the practical implementation of the framework for responsible state behavior. Thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to Bangladesh to be followed by the International Committee of the Red Cross.
—
Bangladesh
Madam Chair, Excellencies, Distinguished Delegates, At the outset, my delegation congratulates you on becoming the Chair of this Global Mechanism and pledges its full and constructive support to your stewardship of this mechanism. We also thank the Secretariat for its work in preparing the first substantive plenary. Bangladesh warmly welcomes the launch of this Global Mechanism as the achievement of five years of work by the open -ended working group. Madam Chair, As a country whose international connectivity depends heavily on a limited number of submarine cables, Bangladesh attaches particular priority to the protection of submarine cables and other cross -border critical information infrastructure. and sees its merit in dedicating confidence -building measures on this issue. We also note with concern that the rising incidence of ransomware and denial of service attacks against government in services and platforms and the financial sector and support a comprehensive, cooperative international approach to ransomware, including cooperation on tracing illicit finance. Like many delegations, we are increasingly concerned by AI -enabled threats and by disinformation and defects generated through advanced technologies, which carry implications for both international security and social stability. Madam Chair, for Bangladesh, confidence -building remains the pillar that makes every other pillar meaningful. In closing, Bangladesh remains committed to working with every delegation towards an open, secure, stable, accessible and peaceful ICT environment. Bangladesh shall remain constructively engaged in this global
—
Chair Egriselda López
Thank you very much I now give the floor to the International Committee of the Red Cross to be followed by Interpol and then the African Union
—
International Committee of the Red Cross
Thank you Ambassador Lopez Distinguished Delegates The International Committee of the Red Cross is grateful for the opportunity to take part in the first substantive plenary session of the Global Mechanism The ICRC commends the important progress achieved by states throughout the work of the Open -Ended Working Group including in identifying threats posed by the use of ICTs during armed conflict Building such shared understanding is a key step towards developing measures to address these threats collectively Over the past year the number of armed conflict has risen to alarming levels with over 130 armed conflict victims and over 150 armed conflicts in 2025 The ICRC observed an increasing use of ICT capabilities for military operations by state and non -state actors and we are concerned about the risks that this poses to the civilian population The ICRC therefore wishes to highlight some of the trends it observes in today’s armed conflicts We have submitted these observations in a working paper to the Global Mechanism First, ICT operations disable the provision of essential services for civilian populations Recent uses of ICTs have shown that even in the absence of physical damage ICT operations can severely disable civilian infrastructure damage or destroy civilian data and disrupt the delivery of essential services The consequences of these operations include power outages disruption of the civilian population disruption to transport systems, banking, water supply and food production They also lead to the denial of contact with loved ones and of access to life -saving information Second, ICT operations do not spare medical facilities, aggravating the hardships suffered by affected populations In addition, humanitarian organizations, including the ICRC, continue to be targeted or affected by ICT activities From the intrusion of their systems and exfiltration of sensitive data to the disabling of computer systems aimed at disrupting humanitarian operations The targeting of humanitarian organizations causes them harm and most importantly, threatens the safety and dignity of the people they serve Third, recent armed conflicts have revealed how ICTs are used to harm children Social media and messaging apps are used by parties to arm conflicts to recruit children into ICTs or to use them in hostilities children no longer need to be physically close to an armed force or armed group to be drawn into their operation recruiters now contact more children more quickly via online communities the involvement of children in armed conflict is unlawful and harms them fourth as the use of ICTs in armed conflicts evolve rapidly new actors are playing increasingly significant role on the one hand while technology companies provide much of the ICT infrastructure assets and services to civilian populations these companies also provide similar assets and services to parties to armed conflicts in times of armed conflict this exposes company infrastructure to real risks with potentially wide -ranging effects on civilian populations who rely on the very same infrastructure and services in their daily lives on the other hand civilian hackers or hacktivists are now operating in several armed conflicts. Too often, they do not know or ignore the limits that IHL imposes on ICT operations. In practice, many of these actors have directed their operations against civilian infrastructure and services. Finally, the growing use of artificial intelligence in ICT activities will increase their speed, scale, and potential for harm. With states and non -state actors integrating AI into their cyber operations, the ICRC is concerned about risks of indiscriminate attacks, incidental civilian harm, damage to critical civilian infrastructure, and uncontrolled escalation, particularly in complex and interconnected digital environments. Madam Chair, as the global mechanism assumes its critical role in advancing the research and development of ICT, the responsible behavior of states in the use of ICTs The ICRC calls upon member states to work together towards reflecting the realities of today’s armed conflicts in their discussions and to identify practical measures to mitigate harm to affected
—
Chair Egriselda López
Thank you. I now give the floor to Interpol.
—
Interpol
Thank you, Madam Chair. As this is the first time that Interpol takes the floor, we congratulate you on your appointment and wish you every success in guiding this important process. In the interest of time, I will deliver an abridged version of our statement. As many of the distinguished delegates have shared over the past two days, the nature and volume of cyber threats we face continues to grow rapidly, from ransomware attacks against critical infrastructure to supply chain vulnerabilities and now increasingly risks associated with artificial intelligence. Thank you. From Interpol’s global perspective, one reality is clear. An open, secure, and stable cyberspace cannot be achieved without addressing one of the principal drivers of insecurity, that is the criminal misuse of ICTs. Cybercrime has become one of the world’s most significant illicit economies, generating trillions of dollars and affecting governments, businesses, and citizens across every region. And cybercrime is becoming increasingly industrialized. Specialized actors offer malware as a service, rent malicious infrastructure, and provide services supporting every stage of the criminal lifecycle. The rapid development of AI is only supercharging this criminal supply chain, increasing the volume, speed, scale, and accessibility of cyberattacks, and even creating new targets. Importantly, the tools and infrastructure developed within criminal ecosystems are now available to the public. can also be exploited by a broader range of malicious actors. Combating cybercrime is therefore not only a law enforcement imperative, it is essential to advancing a safer and more resilient cyberspace. And this is where Interpol provides a distinctive contribution. Through our secure communications network, cyber threat intelligence capabilities, operational coordination, and specialized capacity building activities, Interpol supports police cooperation worldwide. These efforts deliver tangible results. Earlier this year, Interpol’s Operation Synergy F3 brought together more than 70 countries, many of which are represented in this room here today, against phishing, ransomware, and other forms of malware. The operation resulted in close to 100 arrests and took down some 45 ,000 malicious infrastructure. And looking ahead, Interpol is also working with its member countries and partners to address key challenges. Interpol has been working with the United States to address the challenges of cybercrime in the United States. Interpol has been working with the United States to address the challenges of cybercrime Interpol has been working with the United States to address the challenges of cybercrime in the United States. Interpol has been working with the United States to address the challenges of cybercrime in the like residential proxies and bulletproof hosting, to responding to both the challenges and the opportunities presented by the rapid evolution of AI. To conclude, Interpol remains committed to supporting UN member states to strengthen international cooperation, to combat cyber threats, and to enhance collaboration. cyber resilience and we stand ready to contribute our operational expertise to the work of this global mechanism including through its future thematic discussions so that together we can build a safer digital future I thank you.
—
Chair Egriselda López
thank you very much I now give the floor to the delegation of the African Union
—
African Union Commission
Madam Chair the African Union Commission congratulates you on your leadership in convening this first substantive session of the global mechanism and in guiding the operationalization of the dedicated thematic groups the Commission reaffirms its full support of the African Union Commission’s commitment to the global mechanism for this important process The Commission aligns itself with the statement delivered by the Afghan group and wishes to provide complementary observations based on the Afghan Union’s continental mandates. Madam Chair, the establishment of this global mechanism represents an important opportunity to build on the progress achieved through the Open Energy Working Group. At this stage, our collective focus should be on translating agreed commitments into action and delivering outcomes that respond to the realities and priorities of all Afghan Union member states across all regions. The Afghan Union has established a strong continental foundation to support this process through the development of the African Union Convention on Cybersecurity and Personal Data Protection and the Common African Position on the Application of International Law to the Use of ICTs in Cyberspace. Furthermore, the ongoing development of the AU Guidelines for the Implementation of the Norms of Responsible State Behavior in Cyberspace and the initiation of a Continual Declaration on Peace and Security in Cyberspace demonstrate Africa’s commitment to translating global commitment into practical regional actions. Madam Chair, Africa continues to face an evolving ICT threat landscape, including malicious cyber activities targeting critical infrastructures, ransomware, online fraud, supply chain vulnerabilities, and the growing challenges of artificial intelligence for security. The Commission encourages the dedicated thematic group 1 to prioritize areas of practical progress, including the implementation of international law in cyberspace, critical infrastructure protection, artificial intelligence, and other emerging threats affecting peace and security. In this regard, the Afghan Union Continental Artificial Intelligence Strategy and the advisory group on artificial intelligence that was nominated or appointed to support the AU Peace and Security Council can contribute to this discussion. For Africa, practical implementation begins with capacity. Capacity building must remain at the heart of this mechanism and should ensure gender mainstreaming and youth employment to promote innovation on the continent. The Afghan Union Commission welcomes the establishment of the dedicated DEMATIC Group 2 and will encourage early progress toward the global ICT security cooperation and capacity building portal. Madam Chair, we continue to encourage the work of those two groups and we wish also that they will be aligned and mutually reinforcing. Madam Chair, I thank you and I submit.
—
Chair Egriselda López
Muchisima grazie. Thank you very much. We have now exhausted the list of speakers under this agenda item. I have none. Nonetheless, I received another request for the floor under the right of reply and so I give the floor to Israel.
—
Israel
Thank you, Madam Chair. I regret we must ask for the floor again to respond to the stunning hypocrisy of the Iranian regime’s statements about international law and aggression. For years, Iran has constantly and systematically violated every possible international obligation and norm, including by slaughtering tens of thousands of its own people, by intentionally attacking civilian centers in Israel and in other states across the Middle East, and by intentionally holding international maritime and navigation hostage at the expense of all member states. This malicious and rogue Iranian regime has also continued financing, training, and arming its non -state proxies, including Hezbollah, Hamas, and the Houthis, spreading death and destruction all across the Middle East. If only the Iranian people could enjoy, enjoy the benefits of the vast Iranian resources. devoted to ongoing brutal aggression against other member states, so many innocent lives could have been spared. Let me remind this chamber that the Iranian regime openly calls for the annihilation of Israel. The situation of a member state of the UN actively and publicly pursuing the annihilation of another member state is unacceptable. This regime has no moral standing whatsoever to preach against others, nor to lay false and outrageous claims while hypocritically invoking international law. This is a farce that we should not and will not tolerate. Madam Chair, we request that you exercise your leadership. Iran cannot be allowed to continue and derail our discussions and waste our precious times.
—
Chair Egriselda López
Thank you. Muchas gracias. Thank you very much. I hope that… all delegations will bear in mind that we have a very limited amount of time and that we should be focused on covering the agenda item before us. And I think that there are ways of better using our time and not entering into these discussions. And I would ask all delegations just to bear in mind that we have a lot to tackle and it is already 3 .40 p .m. I have been informed that the delegation of Iran has requested the floor. I imagine that this is your second and last intervention under the right of the reply. I will give the floor to you and I would ask you to be very brief.
—
Islamic Republic of Iran
Thank you. Thank you, Madam Chair. I have already addressed absurd allegations made by the representative of the Israeli regime I don’t intend to take up any more of the global mechanism valuable time and I will not take up any more of the global mechanism valuable time and I will not take up any more of the global mechanism valuable time and I will not take up any more of the global mechanism valuable time and I will not take up any more of the global mechanism valuable time and I will not take up any more of the global mechanism valuable time and I will not take up any more of the global mechanism valuable time and I will not take up any more of the global mechanism valuable time or that of other delegations by responding to a repetition of those faceless claims. They don’t warrant any further response, and I don’t intend to dignify them with one. I would, however, like to briefly react to one point in his intervention. Nothing is more astonishing than hearing the representative of the Israeli regime speak about Iranian people and the protection of civilians. The people of Iran don’t need crocodile tears from those responsible for the deaths of thousands of Iranians, including 168 schoolgirls killed in the attack on an elementary school in Minob, the assassinations of our senior officials, and the widespread destruction of civilian infrastructure across my country. It is difficult to reconcile such rhetoric with the well -doctrinated and well -respected and well -documented consequences of the actions of the Israeli regime. Those responsible for such atrocities in our region, including in my country, are in no position to lecture others on international law. Madam Chair, the Israeli regime has consistently sought to mislabel legitimate resistance groups in the region as terrorists or proxies. Let us be clear. According to United Nations General Assembly Resolution 46 -51, these groups are not terrorists. They are legitimate resistance movements fighting against occupation, apartheid, aggression and genocide in the Palestinian and other occupied territories. International law explicitly recognizes the right of peoples to resist foreign occupation and defend themselves against aggression. The real terrorists are those who bomb hospitals and schools. massacre civilians, strike an elementary school in Minak killing 168 schoolgirls and violate international law with impunity. I thank you, Madam Chair. Gracias. Thank you.
—
Chair Egriselda López
Distinguished delegates, before we begin the next topic, I would like to recall the following, which is set out in Annex 1 of A -80 -257. And I quote, the accredited interested parties may attend the substantive plenary sessions and the review conferences of the global mechanism and make oral statements during the… sessions dedicated to interested parties. It will also be possible to deliver interventions after states according to the availability of time and subject to the discretion of the Chair at the standard plenary sessions and the review conferences. According to these modalities and in the spirit of cooperation with the community of stakeholders, as indeed you have delegations, I intend to give the floor to those entities that are duly accredited to the global mechanism. And so in this regard and specifically to provide information on this topic, which is existing and emerging threats near and by CTE, I will be giving the floor for three minutes. This will will be strictly enforced. And so I now give the floor to Kenya ICT Action Network. Can you press the mic?
—
Kenya ICT Action Network
Thank you so much, Chair, for this opportunity and for demonstrating your commitment to engaging stakeholders. You have demonstrated that by engaging us even before the session started. So we are really grateful. I think the other thing I need to note is that I have seen more women from the delegations making their statements, and that is really commendable because in the previous session, you know, we didn’t see that. So that demonstrates the training. So I just want to make a short statement on behalf of different civil society organizations working to protect digital rights, human security, and peace. For civil society… Cyber security is not an abstract exercise in navigating geopolitics, but a matter of human safety, fundamental rights, and democratic survival. Today, the existing threats that alarm us most are those that directly strike citizens. We are witnessing unchecked proliferation of commercial spyware, surveillance, and state -sponsored cyber harassment used to monitor, intimidate, and silence journalists, bloggers, human rights defenders, and political dissenters. Simultaneously emerging threats fueled by artificial intelligence -driven automated surveillance and deepfakes are weaponizing digital spaces to erode electoral integrity and supercharge tech facilitators and counteract gender -based violence. These tools disproportionately target women, persons with disabilities, minorities, and vulnerable groups forcibly out of public and civic life. National security cannot exist without human security. If global mechanism is to build genuine digital peace, we urge member states to prioritize three critical demands. One, ground all cyber norms in human rights, and this calls for measuring to secure cyberspace. That must never be used for censorship, Internet shutdowns, or criminalization of privacy and secure encryption. We need states to also protect civic space and end intrusive surveillance, as well as ensure meaningful multi -stakeholder participation, because civil society acts as frontline defenders who monitor local harms and support victims on the ground. A secure digital world is
—
Chair Egriselda López
Thank you very much for that intervention. Now I give the floor to Discover MUN Foundation.
—
Discover MUN Foundation
Thank you, Madam Chair. My name is Edward Yonko. I take the floor on behalf of the Youth Publications and Socioeconomic Forum, a subsidiary program of the DMUN Foundation. The threats discussed this week demonstrate that ICT security depends on technologies and institutions. It is important to note that they are also reliant on human capacity as well. In that regard, I would like to emphasize one central message. Invest in people, especially in young people. Young people are the next generation of cybersecurity professionals, but we are already participants in the digital ecosystem. We are students, developers, researchers, and innovators. The question, then, is how should we make that investment? I would like to briefly share preliminary findings from a study I was part of involving more than 700 secondary school students at a New York City public high school with specialized academic majors. Because students select their disciplines, we could compare perceptions of artificial intelligence among the demographics. We could compare perceptions of artificial intelligence among a diverse group of STEM -oriented and non -STEM -oriented students. We observed that students in non -STEM disciplines expressed significantly greater concern about AI -related job displacement than their STEM peers. This gap persisted even after accounting for self -reported AI use and skill. In other words, more frequent and more proficient use of AI did not necessarily translate into greater confidence about broader consequences. This finding could suggest a broader lesson for cyber capacity building. Mere exposure to technology does not necessarily create understanding, preparedness, or most importantly, resilience. We want to be precise about what this data does and does not show. The study examined attitudes toward AI and employment, not cybersecurity knowledge or threat recognition. Nevertheless, the findings offer a takeaway relevant to this discussion. Access to an emerging technology and familiarity with it should not be treated as evidence that young people understand its broader consequences or feel prepared to address them. As AI -enabled capabilities become increasingly relevant to ICT security, young people should be resilient. The youth should be equipped to use these technologies responsibly and also be equipped to recognize AI -enabled threats such as phishing and malicious deepfakes. Concretely, we ask that youth -serving organizations and youth capacity -building practitioners be recognized as important stakeholders set out for the global mechanism. Furthermore, we demand member states to nominate qualified youth capacity -building practitioners to the DTGs. Excellencies, we must invest in technology, but we must also remember the importance of an investment in people, and that investment must include young people. Thank you very much.
—
Chair Egriselda López
Muchísimas gracias. Thank you very much. So, distinguished delegates, I thank all of the delegations for this substantive discussion. My team and I. have taken due note of all of your statements and I believe we can identify some common themes that have emerged over the course of our discussion and so what I’m going to now list is not intended by way of any kind of hierarchy or intended to prejudge what is going to be discussed in these specific thematic groups rather rather I’m just providing some feedback as the chair to explain what I’ve heard yesterday and today first of all the threat landscape including complexity the number of actors but also the range of tools that are being used the impact of emerging technologies such as artificial intelligence and other technologies also impacting the security of ICTs and these offer opportunities but they also give challenges. The continued relevance of threats such as ransomware, the specific vulnerabilities of critical infrastructure mainly in areas such as health, education, public administration, financial services and also the critical information infrastructure such as subsidy cables. You also indicated that there is a need to protect the supply chains for ICT services and there were also many other topics that you delved into with a degree of technical detail. We will take this into account with other things as well. All of this will inform the remainder of our programme because it provides the context or the background that we need in order to develop the pillars. of the framework for responsible behaviour. I have also heard concrete calls to action and for concrete solutions. Many delegations emphasise the need for the mechanism to make progress and move to action -oriented decisions, exchange of information on threats, cooperation, capacity building, incident response, recovery and the creation of resilience, implementation of the responsible use framework. As I indicated at the beginning, this does not in any way prejudice or prejudge the discussions that we will be having over the next couple of months as we prepare for the thematic groups. Now, based on the programme of work, we are going to begin the second substantive topic, which is Voluntary and Non -Binding Norms. Voluntary and Non -Binding Norms states and the ways of their implementation, recognising that over time additional norms may be developed. And I would be grateful if at this time you could indicate whether you’re interested in taking the floor so that together with the Secretariat we may have some clarity as to the amount of time that will be required to cover this agenda item. As I said yesterday, there is no established time limit for you to deliver your statements. However, as Chair, I would respectfully ask you to consider delivering an abridged version of your statement and send the whole complete version of this statement to the Secretariat, to the Chair, and once again you will also have a timer available for you on screen to help you manage your time. I will now give the floor to Tonga on behalf of the Pacific Island Forum.
—
Tonga on behalf of the Pacific Island Forum
Thank you, Chair. I have the honor to deliver this statement on behalf of the members of the Pacific Islands Forum with a presence at the United Nations, namely Australia, the Cook Islands, Fiji, Kiribati, the Federated States of Micronesia, the Republic of the Marshall Islands, Nairo, New Zealand, Palau, Papua New Guinea, Samoa, Solomon Islands, Tuvalu, Vanuatu, and my own country, Tonga. Chair, on norms, the Pacific Islands Forum reiterates its longstanding position that the priority must remain the implementation of the existing voluntary non -binding norms of responsible state behavior. Our member states are at varying stages of operationalizing these norms, including identifying national critical infrastructure and critical information infrastructure, strengthening incident response capacity, developing whole -of -government approaches, and building the technical and policy foundations needed for implementation. Our priority at this stage is the full implementation of the 11 agreed norms. Many states, including small island developing states, are still building the capacity needed to operationalize these commitments. And we see considerable value in the global mechanism supporting this work, including through a shared understanding of where implementation gaps remain and how capacity building can be done. And we see considerable value in the global mechanism supporting this work, including through a shared understanding of where implementation gaps remain and how capacity building can be done. and how capacity building efforts can best be targeted. A strong and demonstrable record of implementation across all states will strengthen the framework of responsible state behavior as a whole. The Voluntary Norms Implementation Checklist is a helpful step towards mainstreaming implementation. To realize its potential, however, we also need consolidated guidance, capacity support, and peer exchanges. We would welcome the mechanism taking the checklist forward in a concrete, action -oriented fashion, and we see this as precisely the kind of practical task that dedicated thematic groups are well -placed to advance. This is also an area where stakeholders can make a meaningful contribution. Technical experts, regional organizations, the private sector, academia, and civil society can help to make the checklist forward. It can help states understand how norms translate into practical steps. For instance, expert briefings in the DTGs can provide practical input on implementation without changing the intergovernmental nature of decision-making. The global mechanism should therefore be a place where norms are made operational. Its work should help states move from endorsement to implementation and from implementation in principle to implementation in practice. Thank you, Chair. Muchísimas gracias.
—
Chair Egriselda López
Thank you very much for that statement. I now give the floor to the European Union. They will be followed by Pakistan, Costa Rica, Colombia, and then South Africa.
—
European Union
Thank you very much, Chair, and bear with me. I tried to trim to the extent I’m able to on behalf of the EU and its member states. Also, candidate countries, North Macedonia, Montenegro, Serbia, Albania, Ukraine, the Republic of Moldova, Bosnia-Herzegovina, and Georgia, and the EFTA country, Norway, member of the European Economic Area, as well as San Marino, align themselves with this statement. The EU and its member states reaffirm their strong commitment to the full and effective implementation of the UN Framework of Responsible State Behavior in Cyberspace. As part of the framework, the 11 non-binding voluntary norms of responsible state behavior constitute a central pillar, and the practical implementation of the norms contributes to enhanced transparency, predictability, and accountability of states in cyberspace. It reduces also the risk of misperception and escalation and strengthens trust, and it supports the secure and resilient functioning of critical infrastructure and digital services upon which our modern societies depend. The norms first agreed upon in the 2015 UN Group of Governmental Experts have been reconfirmed and reaffirmed at the Open Ended Working Group and are the basis of our future efforts. In view of the actionable work by the UN on the implementation under the Global Mechanism, the UNS Member States presented ahead of the plenary session an initial overview of our efforts to implement the norms of responsible state behavior. For this contribution, which is published on the website of the Global Mechanism, we used the consensus norms guidance included in the 2021 report of the UN Groups of Governmental Experts, and we detailed our mission. The main pieces of legislation, our policies, our structures, mechanisms, and our policies are the main pieces of legislation that we have developed. and networks that we have put in place in order to implement the UN norms of responsible state behavior. For instance, as regards norm 13b, that in case of ICT incidents, states should consider all relevant information, including the nature and the extent of the impact, as well as in the event of a needed response, included attribution, we have outlined our approach. At union level, the most relevant EU-level actors that contribute to shared situational awareness are the EU member states and their national cyber agencies. The European Commission, the External Action Service, include its intelligence and analysis capacity, the EU Agency for Cyber Security, INISA, and the Cyber Security Service for the Union’s institutions, as well as Europol’s Cyber Crime Center. Under the framework of the Network and Information Security Directive, our cybersecurity legislation, the member states and EU actors cooperate at a strategic, operational, and strategic level. They are at a operational and technical level and have created structures to cooperate at each level, such as the NIS cooperation group, the CERT network of all EU member states, CERTs, as well as Cyclone that compiles all EU cyber agencies. Based on their shared situational awareness, these EU actors work together to consider all relevant information and provide a comprehensive assessment. To further enhance our situational awareness, we have also put in place cooperative mechanisms with the multi-stakeholder community, including through ENISA’s partnership program. Based on this shared situational awareness, the EU and its 27 member states could decide upon an appropriate response, including diplomatic measures under a cyber diplomacy toolbox that also includes the option of attribution. The agreed principles for such… response include, for instance, the need for it to be based on shared situation awareness among all 27 member states, and for the response to be proportionate to the scope, skill, duration, intensity, complexity, and sophistication of the impact of the cyber activity. In other words, for us to consider all relevant information. Like this, we have elaborated on each norm using the UNGGE norms guidance and detailing our main efforts. And we aim to further work on detailing our efforts, including providing more insights in the efforts by individual member states in the implementation at national level, notably also in the fields of capacity building assistance and mitigation and recovery after incidents. This EU contribution complements the 2024 declaration by the EU and its member states on the application of international law in cyberspace, as we should not forget that voluntary norms do not exist in isolation, but they sit alone in international law. While norms are voluntary non -binding, international law itself is binding. And to take one example, international law prohibits the use of ICTs, including ransomware, to interfere coercively in the internal or external affairs of other states. The norms make it clear that states should not use ICT tools such as ransomware to disrupt critical infrastructure. To further build our common understanding on the ways and means to implement the norms of responsible state behavior, we encourage also other states in sharing their experiences in implementing the norms, which will help to enhance our implementation efforts. In addition to such written contributions that some regions already made, the DGGs are best placed to elaborate on the implementation of the norms, connected also to a specific cybersecurity challenge, such as the protection of critical infrastructure or ransomware, and to exchange best practices between states that could feed into concrete recommendations on how to enhance nationalization. In this context, we also see the draft voluntary norms checklist as a valuable tool to take our work forward. The checklist could be treated as a living document and serves as the primary reference as states continue to implement the framework. We could use the checklist as a reference document facilitating the discussions in our DTGs to which we look forward. Thank you very much, Chair.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Costa Rica to be followed by Colombia.
—
Costa Rica
Madam Chair, Costa Rica appreciates the opportunity to speak on this pillar relating to the norms, rules and principles of responsible state behavior in cyberspace. For Costa Rica, the global mechanism must build on the accumulated body of work of the groups of governmental experts in the open -ended working groups. The goal is not to reopen previously reached consensuses, but rather to consolidate them and transform them into a more inclusive and inclusive system. Translate them into national practices, institutional capacities and concrete cooperation. In particular, the voluntary norms of responsible behavior agreed upon in 2015. and the 2024 Voluntary List of Practical Actions continue to provide a foundation for guiding state conduct, reducing risks and promoting international stability and security. Costa Rica emphasises that these voluntary norms do not replace international law that is applicable to cyberspace. Rather, they complement it by offering practical guidance to foster transparency, predictability, restraint and trust. The strength of this framework lies precisely in its ability to link general principles with concrete measures for prevention, cooperation and resilience. In this regard, we consider it important to move towards practical implementation of norms that are particularly relevant to the protection of critical infrastructure, essential services and government functions, areas that states must refrain from targeting. The… … … …recognition of… trusted technical actors, CERTs and CSERTs, distinct from offensive intelligence or other law enforcement functions, and a good faith response to request for assistance must be central to our discussions. Furthermore, Costa Rica believes that due diligence actions should be approached in a balanced manner, both as a responsibility to adopt reasonable measures commensurate with national capabilities to prevent a state’s territory or infrastructure from being used for harmful cyber acts against other states, and also as an agenda for cooperation, technical assistance and institutional capacity building. Madam Chair, responsible state behavior must not remain merely at the level of declarations. It must be translated into public policies, communication channels, responsible vulnerability disclosure, multi -stakeholder cooperation and measures that contribute to the development of a sustainable future. It can reduce the risk of escalation in the event of conflict. Costa Rica hopes that this mechanism will contribute to transforming the existing consensus into concrete, inclusive and results -oriented action.
—
Chair Egriselda López
Thank you very much. I now give the floor to Colombia to be followed by South Africa. Microphone, please. Microphone for Colombia, please.
—
Colombia
Madam Chair, under this item, Colombia highlights the importance and the practical approach of the norms, rules and principles of the Framework for Responsible Behavior of States. In complement to other pillars, it helps to strengthen internal digital resilience. My delegation believes that the existing norms have breadth and flexibility to address an environment that is constantly changing. without prejudice to the idea that other principles may be considered to address the challenges from emerging technologies, especially those linked to the differentiated impact on individuals and communities in situations of vulnerability. However, the principal challenge that we’re facing today is not the absence of norms, but rather effective implementation. There are still questions as to how states will interpret and apply the norms that have been agreed and also as to the understanding of challenges that limit cooperation, timely exchange of information, and participation in trust -building or competence -building mechanisms such as the global directory points of contact. And this is why Colombia considers that the initiatives to address the problems of the global territory points of contact to strengthen capacity that will be taking place under the second semester. groups should be focused prioritarily as operationalising the norms, sharing national experiences, developing practical tools and strengthening institutional capacities. This will allow us to translate our decisions into concrete actions. In this regard, we invite states to consider voluntary publication of their national positions on interpretation and application of specific norms. This exercise would contribute to promoting greater mutual understanding. It would facilitate the exchange of best practices and help us identify common areas and move towards more coherent and effective implementation of the existing framework. Madam Chair, in a geopolitical context where a growing part of interactions between states are taking place in cyberspace, the norms represent a common language that will allow us to reduce uncertainty. guide expected behaviour and reinforce trust between states through dialogue and transparency. The global mechanism provides a unique opportunity for translating this common language into practical tools to guide action by states and strengthen international cooperation. I would like to take this opportunity to say this will be one of the major contributions this process can offer to international stability and security. Colombia reiterates its readiness to continue working with all delegations to achieve this goal. I thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of South Africa. And I will… I will just tell you the next five speakers. Malawi, Brazil, Italy, Morocco and Cuba. South Africa, you have the floor.
—
South Africa
Thank you, Chair. There is no doubt that as the world’s reliance on ICTs continues to grow, the responsible conduct of states in the use of ICTs has become crucial for the preservation of international peace and security. When discussing norms for responsible state behavior, it is essential to maintain a balance in keeping the cumulative normative framework current while transitioning from a conceptual discussion to an action -oriented approach facilitated through the DTGs. South Africa considers the further development of norms as a systematic evaluation, updating where required, and enhancement of the framework, which can be achieved through the implementation of voluntary non -binding norms which will reveal both effective practices, and potential gaps, thereby enriching the discussions. As indicated in the African Group Statement, States will require effective tools and guidelines to implement the UN normative framework for responsible state behavior. In this context, the efforts of the DTGs should focus on finalizing the voluntary checklist in accordance with paragraph 38 of the OEWG 2021 -2025 final report. Furthermore, given the surge of attacks targeted at critical infrastructure and critical information infrastructure, South Africa proposes a discussion on norms F, G, and H regarding the safeguarding of critical infrastructure and critical information infrastructure under DTG 1 as a practical step for focused deliberations, sharing of knowledge, lessons learned, exchange of expertise, and efficient use of time allocated to the DDGs. DTGs in December. Madam Chair, South Africa’s Critical Infrastructure Protection Act of 2019 recognizes that specific infrastructure is essential for public safety, national security and the continuous delivery of vital public services. Accordingly, this act mandates the identification and implementation of appropriate measures to safeguard and ensure the security of critical infrastructure. It defines infrastructure as critical infrastructure if its operation is vital for the economy, national security, public safety and uninterrupted provision of essential public services. Any loss, damage, disruption or immobilization of such infrastructure could significantly impact our country’s functioning or stability, the public interest in terms of safety and the maintenance of law and order. We look forward to hearing about others’ approaches and experiences at the DTG’s
—
Chair Egriselda López
Thank you very much. I now give the floor to the Delegation of Malawi.
—
Malawi
Madam Chair, the Republic of Malawi thanks you for giving us the floor. Before turning to the substance of our intervention, the Republic of Malawi wishes to underscore one important consideration. Norms do not exist because cyberspace is predictable. They exist precisely because it is not. In an environment where technologies evolve rapidly and misunderstandings can have far -reaching consequences, voluntary, non -binding norms provide something invaluable. Predictability, confidence, and a shared understanding of responsible stability and behavior, even when our laws differ. Through the work of the GGEs and OEWG and now this global mechanism, member states have progressively built a cumulative and evolving framework on consensus. This demonstrates that even in a rapidly changing technological landscape, cooperation remains possible. The Republic of Malawi, just like South Africa, acknowledges that the DTG has to pay close attention to norms F, G, and H, noting that destruction of critical information infrastructure does in most cases lead to the breach of international humanitarian law, because data is usually involved. We have prioritized the implementation of norms relating to the protection of critical information infrastructure. We have prioritized the implementation of norms relating to the protection of critical information infrastructure. We have prioritized international cooperation and capacity building through the Malawi Computer Emergency Response Team and our Data Protection Authority, regularly engaging with the national and international community to conduct cybersecurity awareness. child online protection initiatives, threat intelligence sharing, and vulnerability management, support to critical information infrastructure operators, national cyber drills, and multi -state quota engagements, which normally involve government, the private sector, academia, and civil society through established sector certs. These practical measures strengthen resilience while fostering trust and confidence among stakeholders at both the national and international levels. For us, the value of these norms lies not in what they encourage states to do, but in the confidence they foster among states. Promoting restraint, transparency, and cooperation, reducing the risks of misunderstanding and miscalculation. My delegation, therefore, welcomes the emphasis on practical and technical discussions within the dedicated thematic groups, recognizing their role in advancing inclusive, action -oriented recommendations and strengthening the implementation of the framework. As recognized in previous consensus reports, this framework is cumulative and evolving However, its strength will not be measured by the number of additional norms we develop but by our collective commitment to uphold those we have already agreed Looking ahead, my delegation considers the dedicated thematic groups an important opportunity for member states to exchange practical experiences, share lessons learned and identify good practices that strengthen confidence and support the effective implementation of the framework Finally, Madam Chair, consensus has been the strength of this framework Let implementation become legacy.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Brazil.
—
Brazil
Madam Chair Brazil is a staunch supporter of the key of previous UN processes on ICTs and international security, particularly the voluntary norms of responsible state behavior. Their continued relevance after a decade of exponentially accelerating technological innovations is a testament to how well they were drafted by focusing on actions rather than on specific technologies. The norms have guided us on the establishing and updating of our national norms and policies to secure our critical infrastructures and critical information infrastructures against cyber threats, including our most recent national cybersecurity strategy adopted last year. In this regard, we welcome efforts to facilitate norms implementation, including the voluntary checklist of practical actions drafted within the OEWG which could be further developed in the context of this global mechanism. We also recognize the importance of international cooperation efforts in promoting the national implementation of norms. We have greatly benefited from the national experiences of other countries and therefore fully welcome continued knowledge sharing in this area, which is something that this global mechanism could promote. Regional cooperation has also been particularly relevant in this area. Brazil has been engaged in multiple initiatives in this regard, such as the OAS CISERT Americas, which has been instrumental in advancing the norms related to information sharing on threats and vulnerabilities. Mercosur Cybersecurity Commission has also fostered national implementation of these norms through information exchange on cybersecurity institutional and legal frameworks, as well as the ongoing development of a common regional taxonomy. The promotion of gender equality is a key component to the adequate implementation of the norms. Promoting the inclusion of women to the cybersecurity workforce, as well as having policies that address the differentiated impact of cyber threats to women and other vulnerable groups in our society, is an important component of our new national cybersecurity strategy. Madam Chair, we have heard throughout our debates arguments for advancing the implementation of the existing norms and for the adoption of new ones. In our view, these positions are not in any way mutually exclusive, and this global mechanism can have room for both, as long as there is consensus. In any efforts aimed at eventually developing new norms, we have seen the emergence of new forms of behavior, in the cyber domain must be inclusive and therefore take place within this mechanism where the needs of all countries are duly taken into account. The truth of the matter is that there are many initiatives currently underway outside of our multilateral process that aim to shape state behavior in areas that clearly fall within our purview. I thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to Italy to be followed by Morocco.
—
Italy
Good afternoon, Madam Chair. Thank you for giving me the floor. Italy fully aligns itself with the statement delivered by the European Union and wishes to add a few considerations in its national capacity, also benefiting from contributions of the four stakeholders objected by the Russian Federation. Madam Chair, the framework of responsible states and state behavior developed through the GGE and the OEWG provides a solid foundation for the international community that requires systematic and continuous implementation. Priority should be given to supporting states in translating agreed norms into national policies, institutional procedures, and operational practices. In our view, being responsible in the use of ICTs means to understand the duties that each country has to contribute to international peace and stability, as well as to be accountable for its actions and non -actions. In light of the many challenges and possible difficulties in implementing the 11 norms, we believe that the voluntary checklist adopted by the third APR was a very precious tool for all member states, and thus we hope that the global mechanism can take advantage of it, promoting a discussion on its finalization. Italy continues to align to the 11 norms building on strong normative foundations domestically thanks to EU directives, regulations and national law while adapting to technological evolution and maintaining a strong commitment to international cooperation for stability and security in cyberspace A few examples Italy keeps implementing a range of measures to ensure the integrity of supply chain as in norm I through the National Cyber Security Agency which implements and oversees the national cyber security perimeter acts as the national evaluation and certification center and is responsible for the implementation of the EU NISTU directive strengthening ICT supply chain security and trusted procurement The National Cyber Security Agency serving as the national cryptographic center also promotes the use of cryptography as well as the use of cryptography as one of the cyber security tools to ensure the security of the cyber security environment for guaranteeing an effective resilience and long -lasting level of protection of critical infrastructures from ICT threats as in norm F. Particular attention should be also given to the integration of IT and OT security requirements, which are still too often addressed separately despite their increasing convergence. It could be interesting to exchange views on possible common baseline security principles secure by design approaches throughout the life cycle of digital industrial systems and internationally recognized methodologies for cyber maturity assessment. Academia should be actively involved in such exchanges. States should also promote coordinated vulnerability disclosure procedures and clear legal safeguards for good faith security researchers. Multi -stakeholder partnerships are essential in this regard. allowing governments to leverage technical expertise, operational experience and innovation capabilities developed by competence centres, research organisations and the private sector. That is why we firmly believe that DTG1 can play a key role in facilitating a thorough discussion across the five pillars helping deepen the practical implementation of norms. DTG2 then can produce tailored CCB projects that will also contribute to a more responsible behaviour of states in the use of ICTs. Thank you very much.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Morocco.
—
Morocco
Madame la Présidente. Madame Chair, Voluntary and Non-Binding Norms. remain one of the key pillars of the framework of responsible behavior by states. Their goal is clear, to reduce the risk of conflict and escalation in cyberspace by governing the way in which member states conduct their cyber activities. They aim to protect critical infrastructure as well as emergency response teams and promote information exchange and mutual assistance between states in the event of an incident. The goal is to establish a climate of trust between state actors. In this regard, Benelgeshin would like to highlight two observations. First of all, the list of norms should not be set in stone given the rapid evolution of threats and emergence of new technologies and modes of operation, including AI. In light of this, our framework must be able to evolve The 11 Voluntary Non -Binding Norms of the GGA Report 2015 serve as our foundation, and all of us should maintain the ability to enrich or clarify them if necessary. The role of future dedicated nomadic groups in this regard is invaluable. We encourage these groups to, when the time comes, examine this topic and present concrete proposals for enriching them. Secondly, action must be focused on effectively implementing existing norms, and norm only maintains its value if it is implemented coherently by all states. To ensure that the patient is effective, it is important to intensify our actions when it comes to technical capacity building. We place great importance on the fact that states, especially developing states, should be supported. We are committed to ensuring that the GGA is a place where we can continue to improve our services and services for all. We are committed to ensuring that the GGA is a place where we can continue to improve our services and services for all. ownership of these norms through tools, information and necessary resources. Thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Cuba to be followed by the next five speakers which are Portugal, Republic of Korea, Vanuatu, Nigeria and China. Cuba, you have the floor.
—
Cuba
Thank you very much, Madam Chair. We reaffirm our position in favour of developing legally binding norms under the auspices of the United Nations that would complement the applicable principles of international law, respond to legal gaps in the area of cyber security and facilitate impartial handling of the growing challenges and threats faced by states in this area. Non-binding norms are limited by their voluntary nature as their implementation depends on the political will of states. Non-binding voluntary norms therefore only constitute an intermediary step towards achieving our goal. The alarming statistics reveal that voluntary norms on their own are not enough. This is demonstrated by the annual increase in cyber attacks with ever greater speed, scale and sophistication. This is also demonstrated by the growing militarisation of cyberspace with an increase in the development of cyber offensive capabilities A considerable proportion of these attacks are based on politically motivated false attributions and the eagerness to justify hostile actions against states. We recall that the norms, rules and principles… elaborated by the GGE in the past where not all member states participated do not enjoy universal acceptance. The mandate of this global mechanism recognizes that additional norms may be developed over time. We see a need to strengthen the regulatory framework to address matters in the field of security and the use of ICTs in a context of growing threats. The development and implementation of norms for responsible behavior of states in cyberspace should be grounded in respect for the principles of sovereignty, sovereign equality, political independence and territorial integrity. The work should also promote peaceful coexistence and international cooperation for mutual benefit and interest. developing countries stand at a disadvantage in developing technical, technological and regulatory capacities and this disadvantage is further exacerbated when such countries suffer the impact of unilateral coercive measures the lack of conditions in developing countries to determine when they are used for attacks on others has even become an industry with really quite considerable dividends the countries of the south, even though we have common responsibilities these must be differentiated from those for literally developed countries standards are needed for example in relation to prevention and militarisation of cyberspace promotion of cooperation to close the digital divide and matching capacities to respond to the threats faced by states as well as to the peaceful settlement of potential disputes the urgency required to jointly confront the growing threat means that we cannot be left at the mercy of the people or at the mercy of the world based on voluntary norms of supposedly good behaviour this is a notion that can be manipulated according to political interests and context A broad, legally binding instrument that establishes obligations with permanent monitoring would be, in our view, the most effective contribution to establishing a law. a model of responsible behavior by states. One could start, for instance, by considering the development of a roadmap. A global cybersecurity index established by the ITU includes a set of indicators that could be a starting point. Thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Portugal.
—
Portugal
Thank you, Madam Chair. We align with the intervention of the EU, but would like to add a very brief comment in our national capacity. The mandate of this permanent mechanism to promote responsible state behavior in cyberspace in the context of international security provides for regular institutional dialogue focused on the implementation of the consensually agreed framework endorsed by the UN General Assembly since 2015. As we have often emphasized, this dialogue is meant to contribute to upgrade national cyber capabilities across divides. and thus enabling us to move on to a formal system of mutual accountability that levels up all member states’ contributions to peace and security in the digital space so that all of them can peacefully and securely benefit from the digital transition. For more than five years, it has been clear that the majority of the membership is in favor of prioritizing an exchange of lessons learned in combating the increasing degree of insecurity which has been documented year after year and again yesterday and today. The plurality of member states which patiently negotiated the mandate of an action -oriented permanent mechanism within the framework of the Open -Ended Working Group and with the constant support of the overwhelming majority that voted in favor of its establishment have demonstrated the strength of our consensus. Therefore, Portugal strongly believes that the two dedicated thematic groups, designed to address specific security challenges and to accelerate cybersecurity capacity building to confront them, have the potential to lead us towards action -oriented results to be debated during our next plenary session on the basis of their recommendations, which you, Madam Chair, will then convey to us. It was that ambition that led us to establish a permanent mechanism of regular institutional dialogue with its present architecture, deliberately meant to be more stable than its predecessors and more oriented towards implementation of the 11 voluntary norms of responsible state behavior already endorsed and of the applicable international law, than towards the discussion of even more norms or even more binding instruments. Thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of the Republic of Korea to be followed by Vanuatu.
—
Republic of Korea
Thank you, Madam Chair. As noted earlier, the work of the global mechanism should build upon the consensus achieved through the GGE and the OEWG process. In this regard, we should focus on identifying practical ways to effectively implement the 11 voluntary non -binding norms of responsible state behavior that were agreed by the GGE and subsequently endorsed by the United Nations General Assembly. In particular, we believe that the voluntary checklist of practical actions for the implementation of voluntary non -binding norms of responsible state behavior in the OECD should continue to serve as a living document The global mechanism should continue discussions on the checklist with a view to its eventual finalization while ensuring that it remains practical, relevant, and responsive to evolving needs. The global mechanism should continue to strengthen efforts to support and facilitate the implementation of the loans that have been agreed. Therefore, our priority of global mechanism should be the effective implementation of existing commitments rather than the development of new norms at this stage. I thank
—
Chair Egriselda López
you. Muchísimas gracias. Doy ahora la palabra. Thank you very much. And now I give the floor to Vanuatu.
—
Vanuatu
Madam Chair, Vanuatu aligns itself with the statement delivered by Tonga on behalf of the Pacific Islands Forum members. The 11 norms of responsible state behavior were agreed by every state in this room. Vanuatuís interest now lies in a single question. What do those commitments require of states in practice and how do we know they are being met? Vanuatu wishes to offer a perspective on that question that comes directly from our national circumstances. The norms concerning critical infrastructure, the commitment not to conduct or knowingly support ICT activity that damages it, the commitment to protect one’s own, and the commitment to respond to requests for assistance when it is attacked, carry particular weight for a country whose survival infrastructure is digital. Our multi -hazard early warning network, our emergency broadcast capability, our systems for coordinating relief across 83 islands, these are the assets that stand between a natural hazard and a humanitarian catastrophe. Vanuatu invites states to affirm through their conduct and their statements in this mechanism that infrastructure enabling disaster preparedness and response falls squarely within the protection these norms describe. There could be no clearer test of responsible behavior than restraint towards the systems that keep vulnerable populations alive. We also underline the norm -relevant duty of states not to allow their territory to be used for international wrongful acts using ICTs. For small states on the receiving end of transnational malicious activity, this expectation of diligence is among the most consequential elements of the framework, and we encourage continued exchange in this mechanism on what reasonable capacity approach diligence looks like for states at different levels of development. Vanuatu’s product position on this pillar has been consistent across the OEWG, and remains so. The task before us is observance, not expansion. The existing commitments have not yet been implemented by all states to a standard that would refill any genuine gap. We support using this mechanism, including the cross -cutting dedicated thematic group in December, to examine implementation in operational detail, what national arrangements give effect to each norm, what evidence of implementation looks like, and where support is required. Vanuatu is prepared to share its own experience candidly, including where our implementation remains work in progress, and we encourage others, large and small, to do the same. Honesty about implementation is itself a contribution to accountability. The norms where the international communities answer to the question of how to implement the norm, and how states should behave towards one another in cyberspace. Van Matus’ answer to the question of what comes next is simple. Show it in practice. I thank you
—
Chair Egriselda López
Muchisimas gracias. Thank you. I give the floor to Nigeria.
—
Nigeria
Madam Chair. Nigeria once again congratulates you on your sterling leadership. You can count on my delegation’s full support and constructive engagement as you lead this important process. Nigeria aligns itself with the statements delivered by the African group and wishes to make the following remarks in our national capacity. Nigeria remains firmly committed to preserving the state -led, single -track, inclusive, transparent and consensus -based nature of this mechanism. Consensus has consistently enabled progress in this process and should continue to guide our collective efforts. Distinguished delegates, as we embark on this new phase, our priority should be implementation. The extensive body of recommendations developed by the group of governmental experts and the open -ended working groups have provided a comprehensive normative framework for responsible state behavior in cyberspace. The task before us is, therefore, to translate these agreed commitments into practical measures that strengthen national capacities, enhance resilience, and deliver tangible benefits for all member states, particularly developing countries. Nigeria welcomes the establishment of the dedicated thematic groups and support scenario -based discussions as an effective means of strengthening implementation, improving collective preparedness, and facilitating practical cooperation. Such exchanges provide valuable opportunities to share national experiences, strengthen incident response capabilities, and deepen our collective understanding of evolving cyber threats. The rapidly evolving cyber threat landscape demands our urgent attention. Attacks on critical infrastructure and critical information infrastructure, ransomware, ICT supply chain vulnerabilities, threats to undersea cables, electoral process, disinformation, and the malicious use of artificial intelligence pose significant risks. To international peace and security. These threats disproportionately affect developing countries, widening digital divides, and undermining sustainable development. Madam Chair, Nigeria affirms that international law, including the Charter of the United Nations, applies to the use of ICTs. We underscore the principles of sovereignty, sovereign equality, non -intervention, and due diligence, as well as the applicability of international humanitarian law and international human rights law as essential to maintaining international peace and security in cyberspace. Capacity building remains indispensable to the effective implementation of the agreed framework. It is central to reducing vulnerabilities, narrowing the digital divide, and enabling all states to participate meaningfully. in promoting international ICT security. Madam Chair, Nigeria recognizes the valuable contributions of relevant stakeholders, including civil society, academia, and the private sector, in support of this state -led and intergovernmental mechanism. We encourage the Chair’s continued consultations towards a pragmatic solution of the outstanding stakeholder participation issues. In conclusion, Madam Chair, the success of this global mechanism will ultimately be measured not by the number of meetings we convene, but by the practical outcomes we deliver. Stronger national capacities, effective implementation mechanisms, enhanced confidence among states, and a more resilient global ICT environment. Nigeria remains committed to working together. We are working constructively. with all member states to ensure that this mechanism delivers meaningful results and contributes to an open, secure, stable, accessible, peaceful, and interoperable cyberspace for the benefit of all. I thank you, Madam Chair.
—
Chair Egriselda López
Muchísimas gracias. Thank you very much. And I’ll give the floor to China, followed by the following five.
—
China
Thank you, Madam Chair. Confronted with a new landscape and new danger in cyberspace, we must uphold multilateralism to effectively respond to risks, develop and draft the framework for responsible state behavior to make sure the framework can evolve with the times, and can also be cumulative and progressive. China believes that… we should develop new norms regarding the following issues. First, AI’s impact on cybersecurity. AI defensively and obsessively has a profound impact on global cybersecurity. We should establish a barrier for the frontier AI models and to guard against possible security risks and geopolitical risks due to the convergence of cyber technologies with AI. Second, the importance of data security has been increasingly prominent. At present, data security is increasingly prominent. Global mechanisms should discuss developing a universal, non -discriminatory international norms on data security to provide effective institutional guarantee for the protection of data security across the world that we need to strengthen the protection of critical resources and critical infrastructure. Safeguarding critical infrastructure security is a shared concern of our countries Global mechanisms should improve and develop norms for responsible state behaviour Regarding the protection and promotion of critical infrastructure security States should not use cyber means to damage other countries’ critical infrastructure especially key information infrastructure concerning national economy, livelihoods and public interests such as energy, transportation, water conservancy, finance, public services, e -government and other key information infrastructure not to damage or steal key data from other countries’ critical infrastructure Fourth, maintaining open, secure and stable global digital, intelligent, industrial and supply chains is also important Building upon existing consensus, we should further refine and specify the effort to develop and develop new technologies to implement globally interoperable common rules and standards for supply chain security and oppose the man -made fragmentation of supply chains driven by political motives Madam Chair, China hopes that the DTG1 of the global mechanism can give serious consideration to China’s proposal. China stands ready to adopt a constructive attitude to work together to make sure our global mechanism achieves new progress in developing and improving the norms regarding responsible state behavior. Thank you.
—
Botswana
Thank you, Chair. Chair, Botswana reaffirms her steadfast commitment to the UN cyber framework and emphasizes that the 11 voluntary norms reinforced by the UN Charter and the existing international law are sufficient to govern state conduct in the cyberspace. For developing states such as Botswana, the debate initiated at the OEWG regarding the implementation of the existing norms against the formulation of new norms is secondary to the immediate reality of the digital divide. Developing countries cannot effectively protect critical infrastructure, prevent cross -border cybercrime, or guarantee the integrity of their supply chains if they lack the underlying technical and institutional capacity to do so. We emphasize the role of the DTGs in formulating concrete and action -oriented strategies to effectively implement the existing norms. These will provide a structured and predictable avenue for the private sector, civil society, and academia to contribute technical expertise in norm implementation and targeted capacity building in that regard. The UN Cyber Survey and the UN Cyber Norms National Implementation Checklist serve as baseline instruments for the global mechanism and its DTGs by providing clear and actionable tracking where UN member states systematically develop and implement the new norms. The UN Cyber Survey and the UN Cyber Norms National Implementation Checklist serve as baseline instruments for the global mechanism and its DTGs The UN Cyber Survey and the UN Cyber Norms National Implementation Checklist serve as baseline instruments for the global mechanism and its DTGs in executing the 11 voluntary norms. These tools provide practical framework for identifying national and regional capacity gaps to make the work of the DTGs targeted and actionable. Domestically, Botswana, through its national cybersecurity strategy and its progressive legislative tools, such as the Cybersecurity Act, has advanced to safeguard its critical national infrastructure. Our national search further acts as an operational engine responsible for implementing the voluntary norms of responsible state behavior. Their work also involves the response to requests for assistance, sharing of threat intelligence and best practices, coordination of local investigations, as well as mitigation of malicious cyber incidents on Botswana’s networks and to also ensure a secure and stable digital environment. Botswana reiterates its commitment to implement these global norms through a phased approach aligned with its national capacity and available resources. Thank you, Chair.
—
Chair Egriselda López
Thank you. Thank you. And now I give the floor to Thailand.
—
Thailand
Madam Chair, Thailand remains committed to the 11 voluntary non -binding norms of responsible state behavior in cyberspace, recognizing that they complement existing international law applicable to the use of ICTs in cyberspace and should be interpreted in a manner consistent with the purposes and principles of the UN Charter. These norms meaningfully reduce risk to international peace, security, and stability by providing a practical foundation for enhancing transparency, fostering cooperation, and, and promoting predictability in cyberspace. thereby building mutual trust and confidence among states. In addition, Thailand is of the view that the Voluntary Checklist of Practical Actions serves as a useful capacity -building tool that supports states in developing baseline ICT security capacities and resilience. While respecting each state’s prerogative to structure its implementation in accordance with its national circumstances. At the regional level, ASEAN, as the first regional organization to have adopted these cyberspace norms in principle, has finalized its Norm Implementation Checklist to support member states in translating norms into practices. For more information, visit www .aesean .gov .uk At the national level, Thailand has integrated these norms of responsible behavior into our National Policy and Action Plan on Cybersecurity 2022 -2027. The next plan for 2028 -2032 is currently under development, guided by the ASEAN and OEWG checklist. Thailand values and encourages regional organizations and frameworks to adopt and implement these norms, rules, and principles of responsible state behavior as part of the global confidence -building efforts. As we move forward, Thailand supports continued exchanges of views on the rules, norms, and principles of responsible state behavior in the use of cybersecurity. Thailand remains open to discussions on the possible development of additional norms, rules, and principles of responsible state behavior in the use of ICTs, particularly in response to emerging threats. At the same time, such discussions should take into account the diverse contexts, needs, and capacities of states. Any additional frameworks should not impose obligations beyond states’ capacities or serve as a means of technological exclusion. Instead, they should contribute to bridging the digital divide and strengthening the resilience of developing countries against evolving cyber threats. Thank you, Madam Chair.
—
Netherlands
Thank you, Madam Chair. The Kingdom of the Netherlands aligns itself with the statement delivered by the European Union. Please allow me to make some further comments in my national capacity. To the Kingdom of the Netherlands, the 11 non -binding voluntary norms form an integral and essential part of the consensus normative framework for responsible state behavior. We consider it pivotal that while the norms are not in themselves binding, they do confer a degree of mutual expectations on states to behave responsibly in cyberspace. They point towards our collective path forward, and the implementation should be front and center of our work within the UN global mechanism, but also within our national policies. Chair, please allow me to highlight three elements to aid the implementation of the 11 voluntary norms. First, the UN Global Organizing System. Second, the DTGs. should provide the opportunity for states to discuss the norms not in isolation, but in a cross -cutting manner with the other pillars of the normative framework when addressing specific cyber threats and dilemmas. One way to do so is by providing guiding questions that prompt member states to discuss the norms in conjunction with international law, confidence -building measures, and capacity -building, instead of tackling each pillar one by one. The norms are best implemented in the recognition that the normative framework is a unitary framework rather than a collection of parts. Second, the Kingdom of the Netherlands believes that a voluntary checklist for the implementation of norms as developed by the previous Open End Working Group remains a tool of great potential for the implementation of the 11 norms. We should endeavor to strengthen and operationalize the checklist and lay the basis for a voluntary instrument for self -reporting on the implementation of the 11 norms. The EU paper on norms implementation is a perfect example of what such reporting could look like. And finally, in order to ensure that the norms can be implemented by the whole membership of the EU and global mechanism, the Kingdom of the Netherlands believes that our collective efforts at cyber capacity building should be well aligned with the aims and contents of the 11 norms for responsible state behavior. Co-production and demand driven approach to such capacity building efforts remains essential for their success. We would do well not to reinvent the wheel, but to draw upon resources already available. Examples of saturated sources are the norms implementation guide as published by members of the multistate called the community, such as the Geneva dialogue, but also by UN entities such as UNIDIR. And regional groups such as the OAS. Chair, by combining practical DTGs with a well-developed voluntary checklist and effective capacity building the Kingdom of the Netherlands believes that we can collectively make great strides in the implementation of the 11 voluntary non-binding norms for responsible state behavior and we trust in your guidance and assure you of our support in your efforts Thank you
—
Chair Egriselda López
Thank you very much. And I’ll give the floor to New Zealand.
—
New Zealand
Thank you, Chair. We align with the statement by the Kingdom of Tonga on behalf of the Pacific Islands Forum and offer the following in our national capacity. Implementing the norms of responsible state behavior improves stability in cyberspace and strengthens the security of the environment. The resilience of the ICT systems on which our economic and social interests depend. The question is how, in a very practical sense, can we support norms of implementation? On this point, we have been struck by the valuable contributions that regional groups are making We welcome that you use non -paper detailing how it is implementing the norms It’s a practical and substantive demonstration of what implementation can look like Even if implementation may look different in other regions, the paper offers inspiration and useful food for thought Likewise, the ASEAN Norms Implementation Checklist is a valuable point of reference not only for ASEAN, but for all states who want to implement the norms We also look forward to the African Union finalising its guidelines on norms implementation From the Pacific region, we reiterate the message from the Pacific Islands Forum that the regional priority for now is fully implementing the existing norms To this end, the key value that the global mechanism could provide is further guidance and capacity building coordination to support implementation at the national level This is where the data is needed and where the DTGs could prove their worth By considering specific scenarios or specific cyber security challenges experts in the states could share experience on what best practice looks like offer peer learning and identify specific areas where capacity building would support normal implementation This in turn could generate further practical contributions both to address capacity building needs and to develop further guidance such as the volunteer checklist
—
Chair Egriselda López
Thank you very much Indeed I now give the floor to the Islamic Republic of Iran to be followed by the following five speakers, Ireland then Ukraine Canada Japan and then Singapore. Iran you have the floor.
—
Islamic Republic of Iran
Thank you, Madam Chair. Paragraph 36D of the OEWG final report reaffirms that, given the unique attributes of ICTs, additional norms could continue to be developed over time. Accordingly, Paragraph 9 of Annex C explicitly assigns the global mechanism the task of elaborating additional rules, norms, and principles of responsible state behavior. Recent developments further demonstrate why the continued elaboration of additional voluntary norms remains necessary. As my delegation has illustrated under the Agenda Item on Threats, recent unlawful cyber operations carried out by the United States and the Israeli regime in conjunction with their unlawful military attacks against my country have targeted critical infrastructure and essential civilian services, exploited private sector technologies, ICT supply chains, and digital platforms, involved cyber espionage, disinformation, and cognitive operations, and integrated cyber capabilities with conventional military operations, including electronic warfare and interference with communications and satellite navigation systems. These developments revealed important gaps in the existing normative framework and underscored the need for the global mechanism to elaborate additional voluntary norms to promote the exclusively peaceful use of ICTs and contribute to international peace, security, and stability. In light of these developments, my delegation believes that particular attention should now be given to several areas where further normative development is both necessary and timely. These include inter -area data security, including cross -border data flows, the accountability of private sector entities operating in ICT environment and the use of ICTs for unilateral coercive measures. Madam Chair, throughout the OEWG process, many delegations consistently emphasized that the future development of additional norms and the implementation of existing norms are complementary objectives that should proceed in parallel. At present, however, this balance has not been maintained. While work on the implementation of existing voluntary norms has advanced, no comparable process has been established to facilitate the elaboration of additional norms, as envisaged in the agreed mandate of the global mechanism. Accordingly, my delegation considers that negotiations on the proposed voluntary checklist of practical actions for the implementation, of voluntary non -binding norms, should proceed alongside a structured process for the elaboration of additional norms. In this regard, my delegation proposed that the Chair prepare an initial consolidated draft compiling the proposals for additional rules, norms, and principles submitted by Member States deriving from the Annex to the first OEWG Chair Summary. Such a draft would provide a practical basis for structured discussions in both the plenary sessions and the dedicated thematic groups. I thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much. I now give the floor to Ireland.
—
Ireland
Thank you, Madam Chair. To begin, Ireland aligns with the intervention made on behalf of the European Union and makes the following comments in our national capacity. Thank you, Madam Chair. Ireland supported the consensus development of the UN normative framework for responsible state behaviour in cyberspace This was a major achievement in our collective path towards a global, open, secure cyberspace Now we need to focus on its implementation The 11 voluntary non -binding norms of responsible state behaviour are central to maintaining international security and stability and their practical implementation enhances transparency, predictability and accountability of state conduct in cyberspace It is important that states show how they are seeking to implement the norms and I refer to the EU’s paper on implementation as an example of this There is much that we can learn from one another and great value in all states sharing our experiences in implementing the norms It is also important to note that the voluntary norms are 1. complementary to international law which applies in cyberspace Ireland believes that there is a strong role for the DTGs to discuss the implementation of the 11 voluntary norms connected to specific challenges such as the protection of critical infrastructure or ransomware to exchange best practices that could feed into recommendations As others have indicated earlier stakeholders’ expertise can and should play an important role in this Ireland also strongly supports the voluntary checklist of practical actions for the implementation of norms developed in the OEWG which we see as a valuable reference to take states’ implementation of the framework forward and which can be further developed We would also welcome discussion of capacity building programmes to assist with the implementation of existing norms particularly on the applicability of international law and cyberspace at the DTGs Thank you,
—
Ukraine
Thank you, Madam Chair. Ukraine aligns itself with the statement delivered earlier by the European Union and would like to add some considerations in our national capacity. The 11 voluntary norms, together with international law, confidence -building measures, and capacity -building constitute a balanced and comprehensive framework for promoting international peace and security in cyberspace. The cumulative framework already provides a solid foundation. The key challenge before us is not whether the agreed norms remain relevant. They clearly do, but the question is how to ensure their effective implementation in an increasingly complex security environment. The rapidly evolving cyber threat landscape demonstrates the continued relevance of the agreed framework. Against this background, the voluntary norms of responsible state behavior remain as relevant today as when they were first agreed upon. Their effective implementation is essential for reducing risks, strengthening resilience and preventing conflict. Some states insist on the voluntary nature of these norms and suggest that were these norms put into legal framework and had they become legally binding, then states would have adhered to them with more dedication. In this respect, it is necessary to bring to the attention that the UN Charter is an international legally binding document and does not prevent, for example, Russia to act in breach of its provisions. And the International Criminal Court is already taking important steps to hold relevant Russian criminals accountable. At the same time, we think that the states should primarily adhere to the norms for the purpose of progress and development and not due to their fear of persecution. Chair, Ukraine would like to focus on two norms that have already been mentioned by many speakers before and have become particularly important in light of today’s security environment. The first concerns the protection of critical infrastructure. States have agreed that they should not conduct or knowingly support ICT activities that intentionally damage critical infrastructure or otherwise impair its use and operation in providing services to the public. Ukraine’s experience demonstrates why this norm is indispensable. Russia’s cyber attacks have targeted the energy sector, telecommunication networks, public administration systems, transport infrastructure and other essential civilian services. Their purpose has been not merely to disrupt computer systems, but to undermine the resilience of the state, amplify the effects of missile and drone attacks and inflict maximum hardship on the civilian population. The second norm we wish to highlight concerns the responsibility of states not to knowingly allow their territory to be used for intentionally wrongful acts using ICTs. This principle, commonly referred to as due diligence, remains one of the cornerstones of responsible state behavior in cyberspace. No state should knowingly permit malicious cyber infrastructure operating from within its jurisdiction to be used against the rights of other states. At the same time, we observe the growing convergence between state -sponsored cyber operations and cybercriminal ecosystems. Malicious actors operating from Russian territory, including ransomware groups and other cybercriminal entities, have repeatedly targeted Ukraine and partner states while benefiting from a permissive environment. This further underscores the importance of implementing the due diligence norm and ensuring that no state knowingly allows its territory or infrastructure, to be used for malicious ICT activities. Chair, Ukraine believes that the global mechanism provides an important opportunity to move to implementation. Thematic discussions should increasingly focus on practical measures that assist states in implementing the agreed norms.
—
Switzerland
This includes discussions should address the risk to critical infrastructures arising from malicious use of artificial intelligence by states. State -sponsored actors and criminals, as well as risks stemming from vulnerabilities in the supply chain, data poisoning, and the manipulation of AI systems. Chair, Switzerland believes that cooperation with the non -governmental stakeholders is essential for the implementation of the voluntary norms. For that reason, Switzerland has established a genuine dialogue on responsible behavior in cyberspace. The dialogue analyzes and maps the roles and responsibilities of various actors, in implementing voluntary norms and ensuring the security and stability of cyberspace. The Geneva Manual is a product of this dialogue. The manual is a living document. The first two chapters of the manual focus on the norms related to supply chain security, reporting of ICT vulnerabilities, and the protection of critical infrastructure. Based on this experience, we are firmly convinced that broad and meaningful participation of stakeholders in the work of the global mechanism, in particular the DGTs, is not only necessary, but also to the advantage of all states. Finally, we would like to thank the EU for the non -paper on the implementation of voluntary norms. This document, alongside other useful tools, such as the ASEAN Voluntary Implementation Checklist, provides the global mechanisms and state with valuable guidance and resources for putting the voluntary norms into practice. I thank you.
—
Chair Egriselda López
Muchísimas gracias. Thank you very much. I’ll now give the floor to North Macedonia.
—
North Macedonia
Thank you, Madam Chair. As this is the first time my delegation takes the floor, allow us to express our appreciation for your guidance throughout the intersessional period. We would also like to thank you for the efficient appointment of the co -facilitators, which has provided a solid basis for advancing our work. North Macedonia aligns itself with the EU statement delivered by this agenda item, and in our national capacity, we wish to highlight the following brief remarks. As we begin our discussion on norms, rules, and principles, we believe that the global mechanism should remain practical, inclusive, and implementation -oriented. Our efforts should focus on supporting the efficient implementation on the existing framework of responsible state behavior in cyberspace, including the 11 voluntary non -binding norms agreed by all member states. Their effective implementation contributes to greater transparency, privacy, and security. Our efforts should focus on the predictability and accountability of state behavior in cyberspace, while strengthening trust and international security. In this regard, thematic discussions will provide a valuable opportunity to exchange national experiences, share good practices, and identify practical approaches that can support implementation at the national level. We believe that continued exchanges of national experiences and practical approaches will enrich our discussions and support the effective implementation of the agreed norms. We look forward to engaging constructively throughout this process. I thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to Albania.
—
Albania
Thank you, Chair. Albania fully aligns itself with the statement delivered by the European Union and would like to add the following remarks in its national capacity. For Albania, the implementation of agreed UN norms is essential. Their value lies not only in the political commitment, but in their translation into national legislation, institutions, operational procedure, and international cooperation mechanisms. Albania has approved and has enforced the Law on Cybersecurity since May 2022, which fully transposes the EU NISTU Directive. In accordance with the provisions of this directive, all implementing bylaws have now been adopted, providing the necessary legal framework for the operationalization of national cybersecurity structures and the functioning of the national cybersecurity ecosystem. The adopted sub -legal acts regulate, among other matters, the organization, responsibilities, and functioning of the national cybersecurity authority, the Cybersecurity Emergency and Crisis Response Team, the Procedures for Identifying, Classifying, Escalating, and Managing Cyber Crisis and Large -Scale Cybersecurity Incidents, the Identification and Protection of Critical and Important Information Infrastructures, and Assessment and Analysis of Cybersecurity Risks, the National Cybersecurity Certification Scheme and the Registration of Cybersecurity Conformity Assessment Bodies, Organizational, Technical, and Operational Cybersecurity Measures, Coordinated Vulnerability Disclosure, etc. Part of this sub -legal act is also the National Cybersecurity Strategy 2530 and its action plan, and it gives policy goals covering protection and digital infrastructure, online protection of citizens and promotion of cybersecurity culture, strengthening international security, and international cooperation. promotion of innovation and scientific research, and protection against hybrid threats. These acts give concrete effect to the application of the agreed UN norms. Just to provide a few examples, Albania has now fully operational cybersecurity structures such as National SOC and CERT. The establishment of National Cyber Incident Monitoring and Response Structures, together with cybersecurity strategy procedures for cyber incident and crisis management, the identification of critical and important information infrastructure and cybersecurity measures, support several norms such as preventing harmful ICT practices and activities, considering all relevant information in cases of ICT incident, on information exchange to address such threats, and on protection of critical infrastructure from ICT threats. while also strengthening Albanian capacity to cooperate with partners at national and international level. Cybersecurity certification frameworks contribute to supply chain security and assurance, while Albania is currently in the process of harmonizing its legal framework with the EU Cybersecurity Resilience Act, which will further contribute to this norm. Having in place a coordinated vulnerability disclosure policy, the necessary technical capacities to discover and address them, such as national SOC and CERTS, and the mechanisms to share information with critical and important information infrastructures to take the necessary measures, directly support the norm of responsible reporting of ICT vulnerabilities and sharing information to limit and possibly eliminate potential threats. Clearly, Albania is practically implementing UN norms, rules, and principles of responsible state behavior in cyberspace. And we believe that the global mechanism should place practical implementation at the center of its work on norms, rules, and principles. The dedicated thematic groups can provide an inclusive space to share national practices, identify legal, institutional, and capacity gaps, and develop action -oriented recommendations and measures. In this regard, Albania calls upon all states to strengthen their commitment to the vulnerability norms of responsible state behavior. In particular, states should ensure that their territory and ICT infrastructures are not knowingly used for internationally wrongful acts conducted through ICTs against the critical infrastructure and essential services to other states. States should also cooperate in preventing, mitigating and responding to malicious ICT activity and provide assistance where appropriate when critical infrastructure is subjected to malicious cyber operation. Albania further emphasized the importance of protecting the integrity and function of computer emergency response team and computer security incident response teams, whose work is essential for maintaining international cybersecurity and resilience. We also encourage all states to support responsible vulnerability disclosure practices and to promote greater security and integrity throughout the ICT ecosystems. Strengthening those commitments will contribute to reducing opportunities for malicious actors to expose vulnerabilities. and conduct harmful cyber operations. Albania remains committed to the UN framework of responsible state behavior in cyberspace and stands ready to contribute constructively to the work of the global mechanism and its dedicated thematic groups in this regard Thank you, Chair
—
Israel
Thank you, Madam Chair Israel’s position on the framework of responsible state behavior remains firm, consistent, and carefully considered In our view, there is no need to develop or elaborate upon any new norms before we adequately address the gap in compliance to the current framework The reality of the current landscape demonstrates that the voluntary and non -binding norms established in 2015 are currently being floated by certain states As we’ve highlighted when we discussed the existing potential threats militant and non -binding norms malicious actors continue to disregard this framework we all agreed upon against this background we also see no need to develop legally binding instruments pursuing efforts and attempting to develop a legally binding instrument without the underlining of broad agreement on key concepts would waste the considerable diplomatic capital invested in the GMAC as well as its potential such an effort would be both premature and counterproductive this does not mean that we should not celebrate our collective achievements so far and continue to further refine the normative framework we have built together for responsible state behavior this framework including the 2015 GGE norms, rules and principles which are voluntary and non -binding signals the expectations of the international community for state activity in the cyber domain we should focus the efforts on strengthening the implementation of the existing voluntary norms and promoting a broader shared understanding of this framework In our view, the DTGs could provide a practical cross -cutting forum for sharing national best practices and evaluating whether and how the existing norms of responsible state behavior are understood and applied. Furthermore, the DTGs could offer an opportunity to revisit ideas that could not have been adequately discussed in sufficient length and thoroughness in the non -permanent process. For example, the DTGs can serve as a much more appropriate platform to contemplating the implementation checklists explored in APR3 report in a more granular and cautious way. Such checklists provide that they are carefully revisited, considered, and redrafted as necessary, could serve as a voluntary tool for developing activities, common language, and understanding. Finally, Madam Chair, And in response to the Iranian regime’s representative, Israel will not dignify the ridiculous and exaggerated claims the Iranian regime just made with a detailed response. Despite the constructive engagement by a vast majority of delegations, and despite repeated calls by many delegations here to avoid politicization, and despite your chair’s call for the member states to present professional and constructive contribution, Iran seems adamant to impudently waste our time. In doing so, the Iranian delegation continues to show Iran’s determination to disregard the international community and to disrespect other member states, both inside and outside this building, in the cyber domain and in other domains. We invite all delegations here to draw. their own conclusions on
—
Chair Egriselda López
Right. We have concluded the list of speakers under this agenda item. However, a right of reply has been requested, and so I give the floor to the Russian Federation.
—
Russian Federation
Distinguished Chair, my delegation was forced to use its right of reply with regard to the outrageous anti -Russian attacks from the Ukrainian delegation. The accusations leveled against my country are not only false and groundless, but are ridiculous. The irony is that the victims of computer attacks are trying to say they’re victims of cyber attacks, when actually they’re a country that has become a hub for hackers and online fraudsters acting with support of their own government with a single goal, to damage the Russian civilian infrastructure. and to defraud Russian citizens. And in this case, they don’t even need to prove the participation of Kiev in many attacks because the officials of that country themselves have repeatedly acknowledged and even bragged about carrying out these attacks against Russia. It is a well -known fact that Ukraine has become the largest haven for online fraudsters in the world. The number of these so -called call centers which defraud retirees and blackmail and extort people and encourage young people to carry out terrorist attacks in Russia are a number in the thousands. And the victims of these attacks are not only Russians but also Europeans, citizens of those countries that are sponsoring the defrauding of Russians. Chair, it’s difficult for me to call any of this a norm of responsible society or a norm of state behavior in the list laid out by the UNGA. They’ve been violated by Ukraine in the most glaring manner. It’s clear that there is no more brazen violator of the framework of responsibility behavior than
—
Chair Egriselda López
Gracias. Thank you. I give the floor to the delegation of the Islamic Republic of Iran. I take it that is also for a right of reply.
—
Islamic Republic of Iran
Thank you, Madam Chair. In response to the absurd and misleading remarks we have just heard from the representative of the Israeli regime, I wish to make one brief observation. The action of the Israeli regime in our region, particularly its two unlawful acts of aggression against Iran over the past year, strike at the very foundation of every pillar of the global mechanism, just as they strike at the very foundations of international law, and the Charter of the United Nations. Referring to these actions neither politicizes nor derails our discussions or wastes time On the contrary, they constitute a clear illustration of the very malicious ICT activities that these processes seek to prevent and address thereby assisting member states in deepening their discussions and informing the work of the global mechanism I thank you Madam Chair
—
Chair Egriselda López
Thank you I give the floor to the delegation of Ukraine to exercise the right of reply
—
Ukraine
Madam Chair, I would like to exercise the right of reply tomorrow during the session of tomorrow not to keep the delegations over time, please
—
Chair Egriselda López
Thank you. Gracias. Thank you. However, I would like to point out that we have an additional ten minutes, thanks to the interpreters, so if you would like to use your right of reply now, you may do so. Okay. Bueno. All right. Well, we would have preferred to close this item today, but we do note that request. What I’m going to do now is similar to what I did with the former agenda item, which is I’m going to share with you some very general reflections. It is not intended to be any kind of exhaustive summary, but I do want to perhaps touch on some of the questions that we have heard raised by a number of delegations. We have noted that there have been an emphasis on shifting to implementation. This is a is of major significance for all states, but I think especially so for small ones, given their realities and national circumstances. I have also heard calls to continue the discussion on common understandings as to how these norms will be applied in practice and the global mechanism through the DGTs. This will be the main forum for these exchanges. A number of you also mentioned the checklist for implementation. A number of you also emphasized that additional norms could also be considered, given the evolving nature of the digital environment. I’ve also heard a lot of you highlight the interconnection of the norms with some of the pillars, especially capacity building and development. Underscoring that this should be shored up by the various diplomatic and other institutions of state. so it does seem that there is a great deal of common sentiment as regards implementation so thank you very much for that in this regard the global mechanism will meet again tomorrow at 10am in this same room please come prepared to begin with the agenda item on the continued study of how international law applies in the use of ICTs including consideration of whether gaps exist and the possible future elaboration of additional legally binding obligations if appropriate and so before I adjourn the meeting for today I would like to remind you that tomorrow afternoon at 3pm according to our program of work we will be holding the dedicated stakeholder segment under the work of this mechanism. I would encourage delegations also to participate actively in that stakeholder segment. If there is any time remaining, we will continue with… the speaker’s list to try and conclude the morning session. The meeting is adjourned. Thank you.
Ghana’s Cybersecurity Act (Act 1038) is confirmed by [S211], which states that owners of critical information infrastructure must register their systems, report cybersecurity incidents, and undergo periodic security audits, and that the Act allows the designation of critical information infrastructure such as government systems, financial institutions, and telecommunications. The specific number of 13 sectors is not confirmed by the knowledge base, but the registration, obligations, and audit framework are corroborated.
2
The knowledge base does not specifically mention the submarine cable 7-Gamma incident in 2024 in relation to Ghana. However, [S114] notes that submarine cable vulnerability was a notable theme in plenary discussions, with Kiribati describing submarine cable protection as existential and Tonga drawing on its experience of the 2022 volcanic eruption. [S208] also discusses submarine cables as critical infrastructure tied to national security. The specific cable name and 2024 date are not corroborated.
3
The modalities for stakeholder participation are broadly corroborated by [S204], which notes that the OEWG Final Report specifies that accredited stakeholders may attend substantive plenary sessions and review conferences, and that the status of informal DTGs is ambiguous. The specific document reference (Annex 1 of A-80-257) is not directly confirmed, but the substance of the procedural rule is consistent with [S204].
4
The knowledge base does not specify a three-minute limit for civil society speakers in this session. However, [S33] notes that the Chair was vigilant in managing time and strictly enforcing speaking limits in a related consultation context, which is consistent with the report’s description of strict enforcement.
5
The focus on ICT threats and voluntary norms of responsible state behaviour is consistent with the broader OEWG/Global Mechanism agenda as reflected in multiple knowledge base sources, including [S201], which references the 11 responsible norms in cyberspace, and [S175], which discusses existing and potential cyber threats as a key agenda item.
6
The role of Dedicated Thematic Groups (DTGs) in advancing the normative framework is referenced in [S101], where the African Group alludes to the discussion paper on stakeholder modality and dedicated thematic groups for the future permanent mechanism. [S2] also references dedicated thematic groups in the context of the Global Mechanism’s organisational sessions.
7
The knowledge base does not directly mention Ghana’s endorsement of the Global Point of Contact Directory in the sources provided. [S132] references Ghana’s commitment to domestic and international cooperation in addressing cyber threats, which is broadly consistent, but the specific reference to the Global Point of Contact Directory is not corroborated.
Adoption of the agenda and organization of work— In summary, the Republic of Korea emerges as a supportive and engaged advocate for regulations that align closely with international human rights standards and the objectives of SDG 16, underscoring the importance of lea…
Adoption of the agenda and organization of work— Israel has been part of the process since its inception Israel’s consistently positive stance on various facets of the negotiations shows its constructive and proactive role in international policy formation. By endorsi…
Any other business /Adoption of the report/ Closure of the session— It becomes apparent that Israel is keen to play a constructive role in multilateral dialogues and is dedicated to contributing positively to international mechanisms that promote the rule of law, strong institutions, and…
Ad Hoc Consultation: Wednesday 31st January, Afternoon session— Additionally, it exhibits flexibility, contemplating a Brazilian proposal and suggesting a refined change to the term “Secretariat,” advocating instead for “Secretariat Services.” This change highlights Colombia’s constr…
Any other business /Adoption of the report/ Closure of the session— Colombia has showcased its dedication to furthering gender equality, affirming its commitment to integrating a gender perspective across its official documentation and policy-making endeavours in alignment with Sustainab…
7th edition— Brazil has been one of the most countries in global digital politics and is the largest Internet market in Latin America. As a democratic and developing country with a vibrant digital space, Brazil has great poten…
Opening of the session— Brazil’s stance on a series of matters pertaining to human rights and the advancement of an international convention is markedly positive and aimed at fostering collaboration. The country firmly stands by Article 5, reco…
(Day 2) General Debate – General Assembly, 79th session: morning session— Mokgweetsi Eric Keabetswe Masisi – Botswana : Mr. President, Excellencies, Distinguished Ladies and Gentlemen, I wish to start by extending my congratulations to you on your election as President of the General Assembl…
Agenda item 6— In conclusion, Botswana envisions the OEWG playing a crucial role in enabling the exchange of expertise and capabilities in a multi-stakeholder environment that is aligned with regional and national efforts. Such collabo…
Ad Hoc Consultation: Tuesday 30th January, Morning session— In the previous draft, ‘theft’ and ‘fraud’ were two separate articles. The ‘theft’ article was deleted, but was later amalgamated into the ‘fraud’ article, which is why ‘theft’ still appears. The Russian Federation suppo…
About the ICRC— The International Committee of the Red Cross (ICRC) is an impartial, neutral and independent organisation whose exclusively humanitarian mission is to protect the lives and dignity of victims of armed conflict and other …
ICRC EXPERT MEETING 14-16 NOVEMBER 2018 – GENEVA— The International Committee of the Red Cross (ICRC) is an impartial, neutral and independent organization whose exclusively humanitarian mission is to protect the lives and dignity of victims of armed conflict and other …
Internet Governance in Times of Conflict | IGF 2023 Open Forum #152— The International Committee of the Red Cross (ICRC) plays a significant role in conflict management and humanitarian efforts. They work in more than 100 countries and are devoted to upholding International Humanitarian L…
Conversation: 01— -Paula Bogantes Zamora- Area of expertise: Science, innovation, technology and telecommunications policy. Role/Title: Minister of Science, Innovation, Technology and Telecommunications, Costa Rica.[S12] Additional conte…
Public Diplomacy and Nation Brand— Morocco is part of the Maghreb region (Algeria, Tunisia, Libya and Mauritania) and part of Africa, but is not acting in any of their unions because of divisions on the issue of the ‘Western Sahara’. Mor…
Ad Hoc Consultation: Tuesday 6th February, Morning session— During a formal session, the chairperson acknowledged the presence and contributions of various national delegations, with a specific commendation directed towards Morocco for its involvement in an information system. Th…
Ad Hoc Consultation: Tuesday 6th February, Morning session— The country’s affirmative stance highlights its commitment to established technological frameworks and could signal its vision for the nation’s ICT future. Nicaragua’s proactive approach may play a significant role in se…
Opening of the session— Nicaragua has taken a pivotal role in representing a diverse group of nations, advocating for the creation of a comprehensive international treaty aimed at ICT crimes. The coalition includes Belarus, Burundi, Burkina Fas…
Ad Hoc Consultation: Thursday 8th February, Morning session— In summary, Nicaragua’s diplomatic activities exemplify a genuine commitment to collaboration, equitable technology exchange, and constructive dialogue in international forums. They favour a supportive and affirmative ou…
Ad Hoc Consultation: Thursday 8th February, Morning session— In their diplomatic endeavours, Pakistan has portrayed a positive stance on the agreement of the document title, resonating with the positions of Russia and Iran, hence demonstrating unity with these countries on this sp…
Clash of civilisations up close: The case of Pakistan— 1. ThePartition of Indiawas the division of the British Indian Empire that led to the creation of the sovereign states of the Dominion of Pakistan (which later split into Pakistan and Bangladesh) and the Union of India (…
Pakistan’s diplomatic moment: Mediation in an age of geopolitical noise— Too much attention, and the mediator risks becoming a participant. Too little, and its efforts may go unrecognised, unsupported, or misunderstood. Pakistan’s role this week existed in that delicate balance, visible enoug…
INTRODUCTION— A fundamental goal of scientific research is to improve the quality of life of people and the social context in which they live. In the near future, Artificial Intelligence (AI) will offer increasingly effective too…
Stefano Baldi Pasquale Baldocci— As for Italian history in general, Sergio Romano has written several titles in the area. Particularly important is his History of Italy from the Risorgimento to Today . Originally published in French in 1977 , it…
On the origins of World War I— Italy’s role in destroying the Congress of Berlin balance of power seems beyond dispute. The authors also blame Italy for being thefirst European power to use war as a means of reducing social tension at home. Indeed, Gi…
Agenda item 6: other matters/OEWG 2025— – Pacific Islands Forum – Tonga: Speaking on behalf of Pacific Islands Forum member states – The Pacific Islands Forum, represented by Tonga, emphasised the need for a limited number of thematic groups to enable partici…
UNSC meeting: Conflict prevention: women and youth— Climate change emerged as a significant concern, particularly for small island nations. Tonga and other Pacific nations declared climate change as the single greatest threat to their security, calling for urgent action a…
The Role of Nigeria In Restoring Peace In West Africa— For example, the nation’s peace was relatively threatened when the federal government of Nigeria, during General Ibrahim Badamosi Babangida (IBB)’s administration announcement that Nigeria was going …
Research Collection— 19 Based on the title of David D. Newsom’s article on the Swiss role in the hostage crisis, which was first published in a commemorative publication for Ambassador Probst: David D. Newsom, ‘The Sensiti…
UN: Summit of the Future Global Call— The analysis reveals Switzerland’s role as a proponent of international cooperation and dialogue. By supporting initiatives like the Summit of the Future and the Pact for the Future, Switzerland positions itself as a fac…
Panel Discussion AI in Healthcare India AI Impact Summit— -Affiliation:Invalude, Canton Broad, Switzerland[S4] -Affiliation:Not specified in transcript (moderator role)[S2] -Role/Title:India Relations Advisor at Invalude (innovation and investment promotion agency of Canton B…
Transforming Agriculture_ AI for Resilient and Inclusive Food Systems— – Affiliation: Netherlands – Role/Title: (Representative of the Netherlands) – Role/Title: Senior Researcher Thank you, Ambassador. And on behalf of the OECD, I just want to thank once again the Netherlands for the le…
Ad Hoc Consultation: Friday 2nd February, Afternoon session— By championing inclusive and pragmatic global governance, the Netherlands solidifies its position as a driving force for collective action and widespread progress in the international arena. The expanded summary provided…
Agenda item 5 : Day 4 Morning session— In the area of Confidence-Building Measures (CBMs), the Netherlands values their role in enhancing transparency, fostering trust, and promoting cooperation between states. Their support for adapting CBMs drawn from their…
The Role of Government and Innovators in Citizen-Centric AI— – Role/Title: Panel moderator/host; senior role at the European Commission (referred to as “my boss” by Roberto Viola)[S6] precisely this, how do we sort of build capacity in order for this technology to be applied sign…
European Union— The European Union (EU) is a regional intergovernmental organization aimed at enhancing economic and political cooperation among its 28 member states. It operates through various institutions like the European Parliament…
European Union— The EU, through its institutions (such as the European Parliament, the Council of the EU, and the European Commission), works on a wide range of policy areas, from agriculture and competition, to environment and transpor…
The International Criminal Police Organization— The International Criminal Police Organization, commonly known as Interpol, is an international organization that facilitates worldwide police cooperation and crime control.
Webinar – session 1— Jackson Cheboi:Thank you very much, Dr. Arie. Just to mention FASTA-S Interpol is an organization comprising of 196 member countries and each country has at least one node, that’s the NCB, National Central Bureau, which …
I. Multilateral institutions under adjustment pressure— China plays a special role in all international organizations. While China has formally declared its solidarity with the South, its behavior has traditionally been reserved, if not enigmatic. It may be no mor…
UN: Summit of the Future Global Call— Armenia eagerly anticipates the upcoming Summit of the Future, viewing it as a crucial platform for advancing discussions on reforming global governance structures and the international peace architecture. A key focus of…
(Day 1) General Debate – General Assembly, 79th session: morning session— Cyril Ramaphosa – South Africa: Thank you, Your Excellency, the Chair of the Assembly. We take this opportunity to thank the United Nations Assembly to give us a chance to speak. Thirty years ago, South Africa was bor…
Ad Hoc Consultation: Thursday 8th February, Morning session— Speaking from a national perspective, the representatives communicated that they could fully endorse the Article. This strong endorsement indicates compatibility with national policies or a strategic international stance…
Ad Hoc Consultation: Wednesday 7th February, Afternoon session— Thailand has been an participant in international diplomatic efforts, consistently demonstrating a constructive and positive disposition towards fostering international cooperation and consensus-building. The nati…
Ad Hoc Consultation: Wednesday 31st January, Afternoon session— In summary, Vanuatu’s clear commendation for both the wording and the title of the text denotes a robust congruence with its stance, suggesting that the revisions have suitably incorporated changes that favour Vanuatu, e…
Ad Hoc Consultation: Friday 9th February, Morning session— As for the aspects of convention ratification thresholds, Vanuatu aligns with the United States and Mexico, endorsing an elevated participation requirement as specified in Article 64, calling for a minimum ratification b…
Ad Hoc Consultation: Friday 2nd February, Afternoon session— Ireland’s alignment with the EU highlights their commitment to collaboration and adherence to the EU’s stance on legal matters. Ireland’s nuanced handling of international law serves as a strategic, yet discerning, ende…
Closure of the session— – North Macedonia: Representative of North Macedonia Chair: Thank you very much Côte d’Ivoire. Indonesia to be followed by North Macedonia. Chair: Thank you very much, Indonesia. North Macedonia, to be followed by Ar…
UNITED NATIONS HANDBOOK 2019-20— * Original members, that is, those that participated in the UN Conference on International Organisation at San Francisco or had previously signed the UN Declaration of 1 January 1942, and that signed and ratified the Cha…
Acknowledgements— At the regional level, New Zealand, a metropolitan Pacific Islands and the closest neighbor to the PLG states, does not constitute the vulnerability criteria as a Pacific small island, but it plays an important role as a…
Ad Hoc Consultation: Monday 5th February, Morning session— New Zealand can support the U.S. proposal for the title and to remove the list of crimes in the final PP New Zealand can support the U.S. proposal for the title. Surprisingly, New Zealand shared Egypt’s unease concerni…
ISBN:— – H.E. Dr. Amani Abou-Zeid, African Union Commission – H.E. Ms. Aurélie Adam Soulé Zoumarou, Benin – Dr. Ann Aerts, Novartis Foundation – H.E. Dr Mohammed Bin Saud Al Tamimi, Communications and Information Technology…
De-briefing and Next steps— The analysis presents a compelling case for the enhancement of learning initiatives throughout Africa, focusing specifically on the crucial role the African Union Commission (AUC) could play in fostering educational deve…
Ad Hoc Consultation: Wednesday 7th February, Afternoon session— Albania’s efforts epitomize its role as a collaborator and mediator in shaping progressive and inclusive legislative outcomes in international relations. In its role within the international community, Albania has adopt…
Ad Hoc Consultation: Friday 9th February, Morning session— These efforts reflect Albania’s dedication to upholding international standards and fostering effective partnerships that advance shared goals, highlighting its role as a cooperative and consistent participant in the rea…
Ad Hoc Consultation: Monday 5th February, Morning session— Albania has demonstrated a clear alignment with the United States on a variety of issues relating to the document under discussion during the chairing session. Notably, Albania concurs with the US regarding the document’…
(Day 2) General Debate – General Assembly, 79th session: morning session— Klaus Werner Iohannis – Romania: Mr. President of the General Assembly, Mr. Secretary General, Excellencies, we have all gathered here, the world leaders, with the responsibility of a better global vision and the will…
Published by DiploFoundation (2011)— Malta: 4th Floor, Regional Building Regional Rd. Msida, MSD 2033, Malta Switzerland: Rue de Lausanne 56 CH-1202 Genève 21, Switzerland Serbia: Gavrila P. 44A Address Code 112410 11000 Beograd, Serbia E-mail: d…
UNSC meeting: Strengthening UN peacekeeping— Romania has been a committed contributor to peacekeeping since 1991 Romania reaffirmed its strong commitment to UN peacekeeping operations, emphasising their vital role in addressing global conflicts. As a contributor s…
(Day 4) General Debate – General Assembly, 79th session: morning session— Muhammad Yunus – Bangladesh: Bismillahirrahmanirrahim. Mr. President, let me congratulate you on your election as the President of the United Nations General Assembly. I would like to assure you of Bangladesh delegat…
Agenda item 5 : Day 3 Morning session— Bangladesh’s commitment to international cooperation is evident in its role in leading discussions to develop coherent strategies for cyber governance on a global scale. By proposing initiatives that unite states under a…
WS #300 Information Integrity through Journalism & Alternative Platforms— Magnus Ag: Yeah, and maybe building on that because all this great and we’re super support the multi-stakeholder approach and why we are here, I think the complexity of it is vast and when you put a meta person in the co…
May, 2011— – The dramatic fall of the Shah’s empire with its strong domestic level of control, powerful army and notable external political and economic ambitions, which projected the Shah of Ian not only as the most …
Agents of inclusion: Community networks & media meet-up | IGF 2023— Carlos Baca:Thank you. Thank you. Thank you. Carlos. Our next speaker is Nwendoa Kiibuba from Kenya. And he is one of the board members of the KIKTA-NET, that is the Kenyan ICT Action Network. And he’s also one of the de…
Parliamentary diplomacy and Internet policy making— Grace Mutung’u is an associate at the Kenya ICT Action Network (KICTANet) and an affiliate at the Berkman Klein Center for Internet and Society. She is also an assistant curator for the GIP Digital Watch observatory, and…
Webinar – session 1— David Ndeje, the Communications Officer for the Kenya ICT Action Network (KIKTANET), detailed the organisation’s crucial role in creating a cohesive force among different stakeholders in Kenya’s ICT policy sphere. KIKTAN…
Summit Opening Session— Five centuries ago Portugal started the first globalization by establishing contacts and relations with countries worldwide. The Treaty of Tordesillas divided the world between Portugal and Spain. The first submarine cab…
(Day 3) General Debate – General Assembly, 79th session: morning session— Luis Montenegro – Portugal: President, Mr. Secretary General, Heads of State and Government, Excellencies, Ladies and Gentlemen, I start by congratulating the President of the 79th Session of the General Assembly, Phi…
Ad Hoc Consultation: Thursday 8th February, Morning session— Cuba has exhibited a proactive role in diplomatic negotiations, especially on issues pivotal to developing countries. The nation recognises the advancements in the dialogue, showing satisfaction with the current state of…
3rd meeting – Plenary Session— Ghana highlights that the damage to Submarine Cable 7 Ghana in 2024 and the resulting disruption to digital services reinforced the importance of protecting such infrastructure as a strategic national asset. Ghana has id…
Cybersecurity— Nevertheless, the risks are increasingly sophisticated, while the groups interested in exploiting cyberspace vulnerabilities have extended from underground communities of ‘black-hat’ hackers to global and well-organised …
WS #190 Securing critical infrastructure in cyber: Who and how?— Audience: Thank you. I’m assuming here that the hacker and the country that has been hacked are in peace, I mean between their two countries. However, there is a probability that both countries are in war. And I’m be…
The future of global security and why cyber diplomacy matters— In recent years, initiatives such as theUnited Nations Group of Governmental Experts (UN GGE)and theOpen-ended Working Group (OEWG)have been established to reform the use of cyberspace. However, their progress has been c…
AI-driven Cyber Defense: Empowering Developing Nations | IGF 2023— Babu Ram Aryal:Good evening, tech team, it’s okay. Welcome to this workshop number 86 at this hall. It’s very a pleasure to be here discussing about artificial intelligence and cyber defence, especially for developing co…
AI and Cybersecurity — The discourse on cybersecurity is deeply entrenched in concerns regarding the inherent vulnerabilities of digital products, with a particular emphasis on the grave risks associated with autonomous weapons systems. These …
Agenda item 5: Day 2 Morning session— The speaker elaborates on compounding factors, including limited availability of security software or training, which amplify the threat of cyber incursions. The speaker’s country has endured cyber incidents such as malw…
Romanian cybersecurity strategy (2022-2027)— 1.Cyber-enabled crime – activities that involve the use of cyberspace to achieve objectives; 2.Cyber-dependent crimes – activities carried out exclusively in space. Cybercrime groups Regarding the activity of cybercri…
Violent extremism— The terms ‘violent extremism’ and ‘cyberterrorism’ are often used interchangeably. Cyberterrorism is the use of the Internet for conducting cyber-attacks by terrorist groups (such as DoS attacks and hacking attacks), as …
Opening plenary session and adoption of the agenda— Cyber attacks pose significant negative consequences by targeting critical infrastructure and personal data, propagating disinformation campaigns, and utilising deepfake technology. These cyber threats not only compromis…
Opening of the session— Cyber attacks are targeting critical infrastructure, supply chains, intellectual property, and governments.
WSIS women and girls trendsetters and action plan— This tension has clear policy background. WSIS and digital cooperation traditions emphasise multistakeholder collaboration, capacity development and practical exchange across actors[S104][S105]. At the same time, UN Wome…
Media Remuneration Policy Analysis Mitchell began by establishing her background and the context for CNTI’s work. Coming from 25 years at the Pew Research Center where she helped l…
A Clash of Professional Cultures: The David Kelly Affair— Finally, the following two quotes provide further background context in support of the policy-promoting rather than intelligence-sharing aims of the dossier. The first comes from an email from Danny Pruce (a Foreign Offi…
Opening Session | Seventh OEWG Session on ICT Security — 1. Threat Landscape: – The Chair called for objective discussions to understand and respond to the evolving threats in the ICT domain, including ransomware and attacks on critical infrastructure. The potential acc…
Agenda item 5: Day 1 Afternoon session— Albania:Honorable Chair, dear colleagues and stakeholders, in the light of the evolving landscape of threats arising from the use of information and communications, cyber threats often transcend national borders and inte…
Open Forum #53 Safeguarding Critical Infrastructure Beyond Borders— Capacity building is crucial for developing countries to effectively participate in and benefit from cybersecurity initiatives. This helps bridge the gap in capabilities between different nations in addressing cybersecur…
A view on digital divide and economic development— In many developing countries, this synergy is not verified, especially in the context of information and communication technologies (ICTs) as they continue to lack ICT infrastructure, capacities for protection and cybers…
UN OEWG 2021-2025 9th substantive session— During theAgenda Item 5: Part 2, it was noted that some states, including the United Kingdom, suggested the addition of new actions such as addressing the proliferation of commercially available ICT capabilities. Japan a…
Agenda item 5: Day 2 Afternoon session— Chair:Thank you very much, UK. This is turning out to be a very useful discussion and I just wanted to at this point make a brief comment. I still have a good list of speakers and we’ll go through them one by one, but I …
Cybersecurity and cyber diplomacy— Consequently, doubts have been cast over the effectiveness of voluntary, non-binding cyber norms in regulating state behaviour, particularly in the African context, where their adoption appears inconsistent. Reaffirming …
Main Session on Cybersecurity, Trust & Safety Online | IGF 2023— In addition to commitments and cooperation, the development of a legally binding international instrument is necessary to bridge the gaps in cybersecurity. This instrument should complement existing international law and…
Future of International Cyber Diplomacy: Comprehensive Discussion Report— Approach to the 11 established cyber norms – review vs. implementation focus Cyber Norms Implementation and Development Cybersecurity | Legal and regulatory The focus should be on implementing the existing 11 norms ra…
3rd meeting – Plenary Session— Iran alleges that the United States and Israel carried out unlawful military attacks accompanied by extensive malicious cyber operations directed against Iran’s critical infrastructure and civilian services. During the F…
2nd meeting – Plenary Session— The question of whether existing norms are sufficient or new norms are needed has been a central point of contention throughout the OEWG process, with positions ranging from developing new norms, to focusing on implement…
Agenda item 5: Day 2 Morning session— Chair:I have received an additional request, I believe, in the exercise of the right of reply. I give the floor now to the delegation of Israel. Geopolitical tensions were evident during the session, with several delega…
Ad Hoc Consultation: Monday 5th February, Afternoon session— The Chair finds difficulty in accepting one country dictating how others protect their children. The Chair has suggested using the Convention on the Rights of the Child (CRC) as a frame of reference to avoid ambiguity d…
Opening of the session— Kazakhstan:Thank you, Chair, for giving the floor. At the outset, we express our gratitude to you, Chair, and your distinguished team for directing the revised draft of the third annual progress report, which is a good b…
Opening of the session/OEWG 2025— There is a growing need for international cooperation and capacity building, especially to support developing nations in addressing cybersecurity challenges.
Keynotes— No single country can tackle internet governance issues alone – international collaboration across sectors is essential
Opening of the session— The cyber threat landscape is rapidly evolving, with increasing sophistication and complexity of attacks targeting critical infrastructure, international organizations, and emerging technologies.
Agenda item 5: Day 1 Afternoon session— Albania:Honorable Chair, dear colleagues and stakeholders, in the light of the evolving landscape of threats arising from the use of information and communications, cyber threats often transcend national borders and inte…
Cybernorms— Capacity Building:States should consider how best to cooperate to build capacity in developing countries to address ICT security and to develop and implement measures to protect their critical infrastructures.
Open Forum #45 Advancing Cyber Resilience of Critical Infrastructure— This comment challenges the traditional developed/developing country dichotomy in cybersecurity discussions and identifies universal challenges that transcend economic development levels. It reframes capacity building as…
Open Forum #53 Safeguarding Critical Infrastructure Beyond Borders— Capacity building is crucial for developing countries to effectively participate in and benefit from cybersecurity initiatives. This helps bridge the gap in capabilities between different nations in addressing cybersecur…
3rd meeting – Plenary Session— However, the tone shifted markedly when Iran delivered a statement attributing extensive cyber and kinetic attacks to the United States and Israel, prompting sharp responses from the United States, Israel, and Iran’s rig…
Organisational session of the UN Global Mechanism on ICT security— Beyond the organisational session, the Global Mechanism will convene in different formats. It will hold substantive plenary sessions once a year during each biennial cycle, thefirst being scheduled for July 2026. Proce…
First substantive session of the UN Global Mechanism on cybersecurity— Global Mechanism on ICT Security It will hold substantive plenary sessions once a year during each biennial cycle, the first being scheduled for July 2026. The Global Mechanism will convene in different formats. The f…
Ad Hoc Consultation: Friday 2nd February, Morning session— The shared stance on the limitations of Article 12’s application to cybersecurity highlights the pragmatic differentiation between domestic and international law. This dialogue serves as a testament to the overarching ob…
Closure of the session/OEWG 2025— China: Thank you, Chair. Yesterday, towards the end of the meeting, you suggested that we go back home and rewrite our statements. So, following your suggestion, I did exactly so. However, my progress has been slow s…
Summary of 29 February 2024 GDC consultations— Priority will be given to speakers representing groups and coalitions. Interventions will be limited to five (5) minutes for statements on behalf of groups and coalitions. Participants representing individual institution…
Informal multistakeholder session— Chair:This seems acceptable to yellow and gray. I saw that the name plate went down, which means that it is acceptable to you. So what we’re doing is we’re taking what is now paragraph eight. We’re cutting it from here. …
Submarine cables resilience— InPanel 4 – Legal and Regulatory Frameworks for Cable Protection, it was emphasized that submarine cables are considered critical infrastructure, which directly ties them to national security concerns. The panel discusse…
Ghana's Cybersecurity Act 2020 (Act 1038)— Owners of such infrastructure must register their systems, report cybersecurity incidents, and undergo periodic security audits. The Act allows thedesignation of critical information infrastructure, such as government s…
94
WPM
368
Words
4 min
Time
Growing cyber threats to critical information infrastructure, including submarine cables, with 13 CII sectors identified nationally – Critical infrastructure vulnerability (Ghana)
Arg. 1
Explanation
Ghana highlights the growing impact of cyber threats on critical information infrastructure, noting that disruption can have significant consequences for national security, economic stability, and public confidence. Ghana has taken concrete steps by identifying 13 critical information infrastructure sectors under its Cybersecurity Act, which establishes obligations for operators and requires regular compliance audits.
Evidence
The damage to submarine cable 7-Gamma in 2024 and the resulting disruption to digital services reinforced the importance of protecting such infrastructure as a strategic national asset . Ghana has identified 13 critical information infrastructure sectors under the Cybersecurity Act, which provides for registration, operator obligations, and compliance audits .
No country can address cyber challenges alone; international cooperation and capacity building are essential for developing countries to tackle threats from malicious use of ICTs – Collective action necessity (Ghana)
Arg. 2
Explanation
Ghana argues that no single country can address the complex and evolving cyber challenges on its own, making international cooperation and capacity building indispensable. Ghana specifically supports enhanced cooperation to help developing countries address risks associated with AI and other emerging technologies.
Evidence
Ghana’s National Artificial Intelligence Strategy seeks to harness AI for inclusive development while ensuring secure and responsible adoption . Ghana supports enhanced international cooperation and capacity building to help developing countries address evolving risks associated with AI and other emerging technologies .
Cyber threats have evolved from localised IT risks into major geopolitical tools; militarisation of cyberspace is underway with states deploying cyber instruments for espionage and sabotage – Geopolitical cyber threats (Pakistan)
Arg. 1
Explanation
Pakistan argues that cyber threats have transformed from localised IT risks into major geopolitical instruments capable of disrupting global stability. States increasingly deploy cyber tools for espionage, sabotage, and political influence, often leveraging private proxy groups, criminal syndicates, or commercial spyware vendors.
Evidence
Attacks targeting critical infrastructure have increased in number, sophistication, and severity, threatening human life and national stability . States increasingly deploy cyber instruments for espionage, sabotage, or political influence, often leveraging private proxy groups, criminal syndicates, or commercial spyware vendors . Commercial hardware, cloud infrastructure, and software tools have been repurposed for military or intelligence operations, making non-proliferation and oversight exceptionally challenging .
Disinformation and misinformation by state and non-state actors contribute to outbreak and escalation of violence, obscure violations of international law, and overwhelm information ecosystems – Disinformation as a threat (Pakistan)
Arg. 2
Explanation
Pakistan identifies disinformation and misinformation as potent threats to international ICT security, arguing that they manipulate threat perceptions, deepen identity-based divisions, and mobilise populations toward confrontation. When combined with cyber capabilities, coordinated disinformation campaigns can overwhelm information ecosystems and accelerate conflict dynamics.
Evidence
Disinformation contributes to the outbreak and escalation of violence by manipulating threat perceptions, deepening identity-based divisions, and mobilising populations toward confrontation . It obscures violations of international law, including international humanitarian law and human rights law, distorts humanitarian realities, and sustains military operations through narrative control . When combined with cyber capabilities, coordinated campaigns can overwhelm information ecosystems, disrupt decision-making, and accelerate conflict dynamics .
Major Discussion Point
Evolving ICT Threat Landscape
Disagreed with
BangladeshKenya ICT Action NetworkIsrael
on: Whether disinformation and misinformation should be treated as a core ICT security threat within the mechanism's scope
States must commit to keeping critical infrastructure, especially healthcare, energy, and water, strictly off-limits during peace and conflict – Critical infrastructure off-limits norm (Pakistan)
Arg. 3
Explanation
Pakistan calls for clear international commitments that critical infrastructure, particularly healthcare, energy, and water systems, must remain strictly off-limits during both peace and conflict. This is presented as a necessary step in addressing the evolving and dangerous cyber threat landscape.
Evidence
Pakistan calls for establishing clear international commitments that critical infrastructure, especially healthcare, energy, and water, must remain strictly off-limits during peace and conflict .
Cybersecurity for developing nations is an economic, sovereign, and human security issue; implementation requires operational communication channels and targeted capacity building – Capacity building for developing nations (Pakistan)
Arg. 4
Explanation
Pakistan frames cybersecurity not merely as a technical IT challenge but as an economic, sovereign, and human security issue, particularly for developing nations. Maintaining international cyber stability requires moving from passive norm agreements to implementation, combining legal guardrails with operational communication channels and targeted capacity building.
Evidence
Pakistan states that cybersecurity, especially for developing nations, is not merely an IT challenge but an economic, sovereign, and human security issue . Maintaining international cyber stability requires moving from passive agreements on norms to implementation, combining clear legal guardrails with operational communication channels and targeted capacity building .
The global mechanism is an important opportunity to democratise global cyber diplomacy; focus should be on practical issues such as ransomware mitigation and de-escalation channels – Democratising cyber diplomacy (Pakistan)
Arg. 5
Explanation
Pakistan views the global mechanism as a key opportunity to democratise global cyber diplomacy by ensuring that dialogues focus on practical issues affecting all regions. It suggests three priorities: focusing on practical issues like ransomware mitigation and critical infrastructure protection, establishing international consensus and regulatory guardrails, and examining how disinformation contributes to armed conflict.
Evidence
Pakistan suggests that the global mechanism should focus dialogues on practical issues affecting all regions, such as ransomware mitigation, critical infrastructure protection, and de-escalation channels . It also calls for examining how disinformation, including as part of cyber and hybrid warfare, contributes to the outbreak, escalation, and prolongation of armed conflict .
Major Discussion Point
Role of the Global Mechanism and Dedicated Thematic Groups
AI-accelerated cyber warfare poses new challenges; sophisticated surveillance tools sold without safeguards – AI and surveillance risks (Pakistan)
Arg. 6
Explanation
Pakistan highlights that AI-accelerated cyber warfare poses new challenges to international peace and security. Sophisticated surveillance tools are being sold to state and non-state actors and are frequently used without adequate safeguards or oversight.
Evidence
Pakistan notes that AI-accelerated cyber warfare poses new challenges to international peace and security . Sophisticated surveillance tools sold to state and non-state actors are frequently used without safeguards or oversight .
Major Discussion Point
Role of Artificial Intelligence and Emerging Technologies in Cybersecurity
Significant increase in number, complexity, and persistence of cyber attacks, including phishing, ransomware, and hybrid interference campaigns – Rising cyber attack complexity (Romania)
Arg. 1
Explanation
Romania reports a significant increase in the number, complexity, impact, and persistence of cyber attacks in recent years, including phishing, social engineering, ransomware, and data exfiltration. Romania has also been exposed to cyber attacks as part of sophisticated hybrid and interference campaigns.
Evidence
Romania witnessed a significant increase in number, complexity, impact, and persistence of cyber attacks, with phishing, social engineering, ransomware, cyber frauds, and attacks against informatic networks representing persistent threats amplified by the rapid development of AI models . Romania has also been exposed to cyber attacks as part of sophisticated hybrid and interference campaigns .
Attacks targeting critical national infrastructure, democratic institutions, and democratic processes are of particular concern; hostile cyber activities by Russian-controlled groups condemned – Critical infrastructure attacks (Romania)
Arg. 2
Explanation
Romania expresses particular concern about attacks targeting critical national infrastructure, democratic institutions, and democratic processes. Romania, together with other EU member states and allies, condemned hostile cyber activities conducted by groups controlled by the Russian Federation.
Evidence
Romania is particularly concerned about attacks targeting critical national infrastructure, democratic institutions, and democratic processes . On 13 July, Romania, together with other EU member states and allies, condemned hostile cyber activities conducted by groups controlled by the Russian Federation, which form part of a well-established pattern using a complex cyber ecosystem comprising both state institutions and non-state entities .
Major Discussion Point
Protection of Critical Infrastructure
Disagreed with
UkraineIslamic Republic of IranIsraelRussian Federation
on: Attribution of specific hostile cyber activities and geopolitical responsibility for cyber attacks
The DTGs could play an important role as venues for exchanging views and formulating recommendations on better implementing the existing normative framework – DTG role in norm implementation (Romania)
Arg. 3
Explanation
Romania argues that the Dedicated Thematic Groups (DTGs) could serve as important venues for exchanging views and formulating recommendations on better implementing the existing normative framework. The focus should also be on applying international law and international humanitarian law in cyberspace and building capacities for critical infrastructure protection.
Evidence
Romania states that the DTGs could play an important role as the right venues for exchanging views and formulating recommendations on better implementing the existing normative framework . Romania also emphasises that the focus should be on applying international law and international humanitarian law in cyberspace and building capacities looking at critical infrastructure and critical information infrastructure .
Major Discussion Point
Role of the Global Mechanism and Dedicated Thematic Groups
Rapid development of AI amplifies persistent threats such as phishing, ransomware, and cyber fraud – AI amplifying existing threats (Romania)
Arg. 4
Explanation
Romania notes that the rapid development of AI models amplifies persistent cyber threats such as phishing, social engineering, ransomware, and cyber fraud. This technological development compounds existing security challenges facing states.
Evidence
Romania identifies phishing, social engineering, ransomware, cyber frauds, and attacks against informatic networks as persistent threats amplified by the rapid development of AI models .
Major Discussion Point
Role of Artificial Intelligence and Emerging Technologies in Cybersecurity
ICT threats are developing swiftly and can impact national security, critical infrastructure, and essential services; unilateral coercive measures deepen the digital divide and weaken national capacity – Threats and coercive measures (Nicaragua)
Arg. 1
Explanation
Nicaragua recognises that existing and emerging ICT threats are developing swiftly and can impact the security of states, critical infrastructure, and essential services. Nicaragua also highlights that unilateral coercive measures have a direct negative impact on developing countries' ICT capacity, deepening the digital divide and weakening national capacity to protect critical infrastructure.
Evidence
Nicaragua recognises that existing and emerging threats in the area of ICTs are developing swiftly and can impact the security of states, critical infrastructure, essential services, and the well-being of peoples . Nicaragua underscores that the application of unilateral coercive measures has a direct impact on developing ICTs and also impacts access to technology, software, digital services, financing, and knowledge transfer . These measures deepen the digital divide, weaken national capacity, make it difficult to protect critical infrastructure, and impede the right to development .
Unilateral coercive measures have a direct impact on developing countries' ICT capacity, deepen the digital divide, and impede the right to development – Coercive measures harm development (Nicaragua)
Arg. 2
Explanation
Nicaragua argues that unilateral coercive measures directly harm developing countries' ability to develop ICT capacity and respond to cyber attacks. These measures restrict access to technology, software, digital services, financing, and knowledge transfer, ultimately impeding the right to development.
Evidence
Nicaragua underscores that unilateral coercive measures have a direct impact on developing ICTs and also impact access to technology, software, digital services, financing, and knowledge transfer . These measures deepen the digital divide, weaken national capacity, make it difficult to protect critical infrastructure, and are an impediment to the right to development .
Major Discussion Point
International Cooperation and Capacity Building
Disagreed with
CubaIslamic Republic of Iran
on: Whether unilateral coercive measures constitute a legitimate cybersecurity concern within the mechanism
The mechanism represents an opportunity for a permanent, transparent, inclusive space where all can participate under conditions of equality – Inclusive and equal participation (Nicaragua)
Arg. 3
Explanation
Nicaragua welcomes the global mechanism as an opportunity to consolidate a permanent, transparent, and inclusive space where all states can participate under conditions of equality. The work should be focused on promoting a secure, stable, accessible, peaceful, and interoperable ICT environment based on UN Charter principles.
Evidence
Nicaragua states that the creation of the mechanism represents an opportunity for consolidating a permanent and transparent inclusive space where all can participate under conditions of equality and contribute to building common understandings . The work should be focused on promoting an ICT environment that is secure, safe, stable, accessible, peaceful, and interoperable, based on the principles of the UN Charter including sovereign equality of states, non-interference in internal affairs, and peaceful settlement of disputes .
Major Discussion Point
Role of the Global Mechanism and Dedicated Thematic Groups
Disagreed with
Kenya ICT Action NetworkDiscover MUN FoundationSwitzerlandNigeria
on: The role and scope of stakeholder participation in the global mechanism and its DTGs
122
WPM
439
Words
4 min
Time
ICT-related threats continue to evolve in scale, sophistication, and frequency, posing risks to states, critical infrastructure, and international stability – Evolving threat scale (Armenia)
Arg. 1
Explanation
Armenia highlights that as digitalisation advances, ICT-related threats continue to evolve in scale, sophistication, and frequency, posing risks to states, critical infrastructure, and international stability. Given the transboundary nature of cyberspace, no state can effectively address these challenges alone, making collective efforts essential.
Evidence
Armenia notes that ICT-related threats continue to evolve in scale, sophistication, and frequency, posing risks to states, critical infrastructure, and international stability . Given the transboundary nature of cyberspace, no state can effectively address these challenges alone, making collective efforts essential to strengthen resilience and promote responsible state behaviour .
Major Discussion Point
Evolving ICT Threat Landscape
The global mechanism will provide an effective and inclusive platform for addressing ICT threats, fostering dialogue, and strengthening international cooperation – Inclusive platform for cooperation (Armenia)
Arg. 2
Explanation
Armenia expresses confidence that the global mechanism will provide an effective and inclusive platform for addressing ICT threats and fostering dialogue. The dedicated thematic groups, particularly DTG2 dedicated to accelerating ICT security capacity building, will play a vital role in identifying needs and strengthening the capacities of all states.
Evidence
Armenia is confident that the global mechanism will provide an effective and inclusive platform for addressing ICT threats, fostering dialogue, and strengthening international cooperation . The dedicated thematic groups will facilitate focused and action-oriented discussions, while DTG2 will play a vital role in identifying needs, facilitating partnerships, and strengthening the capacities of all states to effectively implement the agreed UN framework .
Major Discussion Point
Role of the Global Mechanism and Dedicated Thematic Groups
The DTG dedicated to accelerating ICT security capacity building will play a vital role in identifying needs, facilitating partnerships, and strengthening capacities of all states – DTG2 for capacity building (Armenia)
Arg. 3
Explanation
Armenia emphasises the importance of DTG2, dedicated to accelerating ICT security capacity building, in identifying needs, facilitating partnerships, and strengthening the capacities of all states to effectively implement the agreed UN framework. Armenia recognises that states have different levels of capacity and resources to implement the framework.
Evidence
Armenia notes that DTG2, dedicated to accelerating ICT security capacity building, will play a vital role in identifying needs, facilitating partnerships, and strengthening the capacities of all states to effectively implement the agreed UN framework . Armenia recognises that states have different levels of capacity and resources to implement the framework of responsible state behaviour in the use of ICTs .
Major Discussion Point
International Cooperation and Capacity Building
The framework is cumulative and evolving; additional voluntary non-binding norms could be developed over time in response to emerging challenges, guided by inclusiveness and consensus – Evolving framework with new norms (Armenia)
Arg. 4
Explanation
Armenia recognises that the framework for responsible state behaviour in cyberspace is dynamic and evolving, and that additional voluntary non-binding norms could be developed over time in response to emerging challenges. Any further development of norms should be guided by inclusiveness, transparency, and consensus among states.
Evidence
Armenia recognises that the framework for responsible state behaviour in cyberspace is dynamic and evolving, and that additional voluntary non-binding norms could be developed over time where appropriate, in response to emerging challenges and developments in ICTs . Armenia emphasises that any further development of norms should continue to contribute to international peace and security and be guided by inclusiveness, transparency, and consensus among states .
Major Discussion Point
Development of Additional or Legally Binding Norms
Disagreed with
CubaChinaIslamic Republic of IranMoroccoBrazilIsraelPortugalRepublic of KoreaVanuatuBotswanaTonga on behalf of the Pacific Island Forum
on: Whether to develop new/additional voluntary norms or focus exclusively on implementing existing ones
139
WPM
230
Words
2 min
Time
Particular concern over ransomware, denial-of-service attacks, and AI-enabled threats with implications for international security and social stability – AI-enabled and ransomware threats (Bangladesh)
Arg. 1
Explanation
Bangladesh notes with concern the rising incidence of ransomware and denial-of-service attacks against government services and the financial sector. Bangladesh is also increasingly concerned by AI-enabled threats and disinformation generated through advanced technologies, which carry implications for both international security and social stability.
Evidence
Bangladesh notes with concern the rising incidence of ransomware and denial-of-service attacks against government services and platforms and the financial sector, and supports a comprehensive, cooperative international approach to ransomware . Bangladesh is increasingly concerned by AI-enabled threats and by disinformation and deepfakes generated through advanced technologies, which carry implications for both international security and social stability .
Major Discussion Point
Evolving ICT Threat Landscape
Submarine cables and cross-border critical information infrastructure deserve particular priority and dedicated confidence-building measures – Submarine cable protection (Bangladesh)
Arg. 2
Explanation
Bangladesh, as a country whose international connectivity depends heavily on a limited number of submarine cables, attaches particular priority to the protection of submarine cables and other cross-border critical information infrastructure. Bangladesh sees merit in dedicating confidence-building measures specifically to this issue.
Evidence
Bangladesh attaches particular priority to the protection of submarine cables and other cross-border critical information infrastructure as a country whose international connectivity depends heavily on a limited number of submarine cables, and sees merit in dedicating confidence-building measures on this issue .
AI-enabled threats and disinformation generated through advanced technologies carry implications for international security and social stability – AI disinformation threats (Bangladesh)
Arg. 3
Explanation
Bangladesh expresses growing concern about AI-enabled threats and disinformation and deepfakes generated through advanced technologies. These developments carry implications for both international security and social stability.
Evidence
Bangladesh is increasingly concerned by AI-enabled threats and by disinformation and deepfakes generated through advanced technologies, which carry implications for both international security and social stability .
Major Discussion Point
Role of Artificial Intelligence and Emerging Technologies in Cybersecurity
Disagreed with
PakistanKenya ICT Action NetworkIsrael
on: Whether disinformation and misinformation should be treated as a core ICT security threat within the mechanism's scope
ICT operations during armed conflict disable essential civilian services, target medical facilities, recruit children, and involve civilian hackers who ignore IHL limits – ICT threats in armed conflict (International Committee of the Red Cross)
Arg. 1
Explanation
The ICRC highlights several concerning trends in the use of ICTs during armed conflict, including the disabling of essential civilian services, targeting of medical facilities, recruitment of children through social media, and the involvement of civilian hackers who often ignore the limits imposed by international humanitarian law. The ICRC observed an increasing use of ICT capabilities for military operations by state and non-state actors.
Evidence
The ICRC observed an increasing use of ICT capabilities for military operations by state and non-state actors, with over 150 armed conflicts in 2025 . ICT operations can severely disable civilian infrastructure even without physical damage, causing power outages, disruption to transport, banking, water supply, and food production . Humanitarian organisations, including the ICRC, continue to be targeted by ICT activities, from intrusion of their systems to disabling of computer systems aimed at disrupting humanitarian operations . Social media and messaging apps are used by parties to armed conflicts to recruit children, with recruiters now able to contact more children more quickly via online communities .
Major Discussion Point
Evolving ICT Threat Landscape
ICT operations can severely disable civilian infrastructure even without physical damage, causing power outages, disruption to transport, banking, water, and food production – Civilian infrastructure disruption (International Committee of the Red Cross)
Arg. 2
Explanation
The ICRC emphasises that ICT operations can severely disable civilian infrastructure and disrupt the delivery of essential services even in the absence of physical damage. The consequences include power outages, disruption to transport systems, banking, water supply, and food production.
Evidence
The ICRC notes that even in the absence of physical damage, ICT operations can severely disable civilian infrastructure, damage or destroy civilian data, and disrupt the delivery of essential services . The consequences include power outages, disruption to transport systems, banking, water supply, and food production, as well as denial of contact with loved ones and access to life-saving information .
Growing use of AI in ICT activities will increase speed, scale, and potential for harm, raising risks of indiscriminate attacks and uncontrolled escalation – AI escalation risks in conflict (International Committee of the Red Cross)
Arg. 3
Explanation
The ICRC warns that the growing use of artificial intelligence in ICT activities will increase their speed, scale, and potential for harm. With states and non-state actors integrating AI into their cyber operations, the ICRC is concerned about risks of indiscriminate attacks, incidental civilian harm, and uncontrolled escalation in complex and interconnected digital environments.
Evidence
The ICRC notes that the growing use of artificial intelligence in ICT activities will increase their speed, scale, and potential for harm . With states and non-state actors integrating AI into their cyber operations, the ICRC is concerned about risks of indiscriminate attacks, incidental civilian harm, damage to critical civilian infrastructure, and uncontrolled escalation, particularly in complex and interconnected digital environments .
Major Discussion Point
Role of Artificial Intelligence and Emerging Technologies in Cybersecurity
Cybercrime has become one of the world's most significant illicit economies, increasingly industrialised, with AI supercharging criminal supply chains – Industrialised cybercrime (Interpol)
Arg. 1
Explanation
Interpol argues that cybercrime has become one of the world's most significant illicit economies, generating trillions of dollars and affecting governments, businesses, and citizens across every region. Cybercrime is becoming increasingly industrialised, with specialised actors offering malware as a service, and AI is supercharging this criminal supply chain.
Evidence
Cybercrime has become one of the world’s most significant illicit economies, generating trillions of dollars and affecting governments, businesses, and citizens across every region . Specialised actors offer malware as a service, rent malicious infrastructure, and provide services supporting every stage of the criminal lifecycle . The rapid development of AI is supercharging this criminal supply chain, increasing the volume, speed, scale, and accessibility of cyberattacks .
AI is supercharging criminal supply chains, increasing volume, speed, scale, and accessibility of cyberattacks – AI and cybercrime (Interpol)
Arg. 2
Explanation
Interpol highlights that the rapid development of AI is supercharging criminal supply chains, increasing the volume, speed, scale, and accessibility of cyberattacks and even creating new targets. The tools and infrastructure developed within criminal ecosystems are now available to a broader range of malicious actors.
Evidence
The rapid development of AI is supercharging the criminal supply chain, increasing the volume, speed, scale, and accessibility of cyberattacks, and even creating new targets . The tools and infrastructure developed within criminal ecosystems can also be exploited by a broader range of malicious actors .
Major Discussion Point
Role of Artificial Intelligence and Emerging Technologies in Cybersecurity
Interpol's operational coordination, cyber threat intelligence, and capacity building activities support police cooperation worldwide; Operation Synergy F3 resulted in nearly 100 arrests – Operational law enforcement cooperation (Interpol)
Arg. 3
Explanation
Interpol highlights its distinctive contribution to combating cybercrime through its secure communications network, cyber threat intelligence capabilities, operational coordination, and specialised capacity building activities. Operation Synergy F3 is cited as a concrete example of successful international law enforcement cooperation.
Evidence
Interpol’s Operation Synergy F3 brought together more than 70 countries against phishing, ransomware, and other forms of malware, resulting in close to 100 arrests and taking down some 45,000 malicious infrastructure .
Africa faces ransomware, online fraud, supply chain vulnerabilities, and growing AI security challenges targeting critical infrastructure – African ICT threat landscape (African Union Commission)
Arg. 1
Explanation
The African Union Commission notes that Africa continues to face an evolving ICT threat landscape, including malicious cyber activities targeting critical infrastructures, ransomware, online fraud, supply chain vulnerabilities, and growing challenges from artificial intelligence for security. The Commission encourages DTG1 to prioritise practical progress in these areas.
Evidence
Africa continues to face an evolving ICT threat landscape, including malicious cyber activities targeting critical infrastructures, ransomware, online fraud, supply chain vulnerabilities, and the growing challenges of artificial intelligence for security . The Commission encourages DTG1 to prioritise areas of practical progress, including the implementation of international law in cyberspace, critical infrastructure protection, artificial intelligence, and other emerging threats affecting peace and security .
Major Discussion Point
Evolving ICT Threat Landscape
Capacity building must remain at the heart of the mechanism and should ensure gender mainstreaming and youth employment to promote innovation – Capacity building with gender focus (African Union Commission)
Arg. 2
Explanation
The African Union Commission argues that capacity building must remain at the heart of the global mechanism and should ensure gender mainstreaming and youth employment to promote innovation on the continent. The Commission welcomes the establishment of DTG2 and encourages early progress toward the global ICT security cooperation and capacity building portal.
Evidence
The African Union Commission states that for Africa, practical implementation begins with capacity, and that capacity building must remain at the heart of this mechanism and should ensure gender mainstreaming and youth employment to promote innovation on the continent . The Commission welcomes the establishment of DTG2 and will encourage early progress toward the global ICT security cooperation and capacity building portal .
The mechanism should translate agreed commitments into action and deliver outcomes responding to the realities and priorities of all member states – Translating commitments to action (African Union Commission)
Arg. 3
Explanation
The African Union Commission argues that the global mechanism represents an important opportunity to build on the progress achieved through the Open-Ended Working Group. The collective focus should be on translating agreed commitments into action and delivering outcomes that respond to the realities and priorities of all African Union member states across all regions.
Evidence
The African Union Commission states that the establishment of the global mechanism represents an important opportunity to build on the progress achieved through the Open-Ended Working Group . The collective focus should be on translating agreed commitments into action and delivering outcomes that respond to the realities and priorities of all African Union member states across all regions . The AU has established a strong continental foundation through the African Union Convention on Cybersecurity and Personal Data Protection and the Common African Position on the Application of International Law to the Use of ICTs in Cyberspace .
Major Discussion Point
Role of the Global Mechanism and Dedicated Thematic Groups
Commercial spyware and state-sponsored cyber harassment are used to monitor and silence journalists, human rights defenders, and political dissenters – Spyware and surveillance threats (Kenya ICT Action Network)
Arg. 1
Explanation
The Kenya ICT Action Network highlights that the most alarming existing threats are those that directly strike citizens, particularly the unchecked proliferation of commercial spyware, surveillance, and state-sponsored cyber harassment. These tools are used to monitor, intimidate, and silence journalists, bloggers, human rights defenders, and political dissenters.
Evidence
The Kenya ICT Action Network notes the unchecked proliferation of commercial spyware, surveillance, and state-sponsored cyber harassment used to monitor, intimidate, and silence journalists, bloggers, human rights defenders, and political dissenters .
AI-driven automated surveillance and deepfakes weaponise digital spaces, eroding electoral integrity and enabling gender-based violence – AI-enabled threats to human rights (Kenya ICT Action Network)
Arg. 2
Explanation
The Kenya ICT Action Network warns that emerging threats fuelled by AI-driven automated surveillance and deepfakes are weaponising digital spaces to erode electoral integrity and supercharge gender-based violence. These tools disproportionately target women, persons with disabilities, minorities, and vulnerable groups.
Evidence
The Kenya ICT Action Network notes that emerging threats fuelled by AI-driven automated surveillance and deepfakes are weaponising digital spaces to erode electoral integrity and supercharge tech-facilitated gender-based violence . These tools disproportionately target women, persons with disabilities, minorities, and vulnerable groups, forcibly pushing them out of public and civic life .
Major Discussion Point
Evolving ICT Threat Landscape
Disagreed with
PakistanBangladeshIsrael
on: Whether disinformation and misinformation should be treated as a core ICT security threat within the mechanism's scope
Civil society acts as frontline defenders monitoring local harms; meaningful multi-stakeholder participation is essential for the global mechanism to build genuine digital peace – Multi-stakeholder participation (Kenya ICT Action Network)
Arg. 3
Explanation
The Kenya ICT Action Network argues that civil society acts as frontline defenders who monitor local harms and support victims on the ground, making their meaningful participation in the global mechanism essential. The organisation urges member states to ground all cyber norms in human rights, protect civic space, and ensure meaningful multi-stakeholder participation.
Evidence
The Kenya ICT Action Network urges member states to ground all cyber norms in human rights, protect civic space and end intrusive surveillance, and ensure meaningful multi-stakeholder participation, because civil society acts as frontline defenders who monitor local harms and support victims on the ground .
Major Discussion Point
Role of the Global Mechanism and Dedicated Thematic Groups
Disagreed with
Discover MUN FoundationSwitzerlandNigeriaNicaragua
on: The role and scope of stakeholder participation in the global mechanism and its DTGs
164
WPM
433
Words
3 min
Time
Mere exposure to technology does not create understanding or resilience; youth must be equipped to recognise AI-enabled threats such as phishing and deepfakes – Youth and AI literacy (Discover MUN Foundation)
Arg. 1
Explanation
The Discover MUN Foundation argues that mere exposure to technology does not necessarily create understanding, preparedness, or resilience, drawing on preliminary research findings. Youth must be specifically equipped to use emerging technologies responsibly and to recognise AI-enabled threats such as phishing and malicious deepfakes.
Evidence
Preliminary findings from a study involving more than 700 secondary school students showed that students in non-STEM disciplines expressed significantly greater concern about AI-related job displacement than their STEM peers, even after accounting for self-reported AI use and skill . This suggests that more frequent and more proficient use of AI did not necessarily translate into greater confidence about broader consequences, indicating that mere exposure to technology does not create understanding, preparedness, or resilience .
Major Discussion Point
Role of Artificial Intelligence and Emerging Technologies in Cybersecurity
Youth-serving organisations and capacity-building practitioners should be recognised as important stakeholders; member states should nominate qualified youth practitioners to DTGs – Youth capacity building (Discover MUN Foundation)
Arg. 2
Explanation
The Discover MUN Foundation calls for youth-serving organisations and youth capacity-building practitioners to be recognised as important stakeholders in the global mechanism. It demands that member states nominate qualified youth capacity-building practitioners to the Dedicated Thematic Groups.
Evidence
The Discover MUN Foundation asks that youth-serving organisations and youth capacity-building practitioners be recognised as important stakeholders set out for the global mechanism . It demands that member states nominate qualified youth capacity-building practitioners to the DTGs .
Major Discussion Point
International Cooperation and Capacity Building
Disagreed with
Kenya ICT Action NetworkSwitzerlandNigeriaNicaragua
on: The role and scope of stakeholder participation in the global mechanism and its DTGs
123
WPM
410
Words
3 min
Time
Priority must remain the full implementation of the 11 agreed norms; the Voluntary Norms Implementation Checklist is a helpful step requiring consolidated guidance and capacity support – Implementation priority (Tonga on behalf of the Pacific Island Forum)
Arg. 1
Explanation
The Pacific Islands Forum reiterates that the priority must remain the full implementation of the existing 11 agreed voluntary non-binding norms of responsible state behaviour. Many states, including small island developing states, are still building the capacity needed to operationalise these commitments, and the Voluntary Norms Implementation Checklist is a helpful step that requires consolidated guidance and capacity support.
Evidence
The Pacific Islands Forum states that the priority must remain the implementation of the existing voluntary non-binding norms of responsible state behaviour, with member states at varying stages of operationalising these norms . The Voluntary Norms Implementation Checklist is described as a helpful step towards mainstreaming implementation, but requires consolidated guidance, capacity support, and peer exchanges to realise its potential .
Major Discussion Point
Implementation of Existing Voluntary Non-Binding Norms
Disagreed with
Islamic Republic of IranIsraelPortugalRepublic of Korea
on: Whether the balance between developing new norms and implementing existing ones has been properly maintained in the mechanism's work
The mechanism should be a place where norms are made operational, helping states move from endorsement to implementation and from implementation in principle to implementation in practice – Norms operationalisation (Tonga on behalf of the Pacific Island Forum)
Arg. 2
Explanation
The Pacific Islands Forum argues that the global mechanism should be a place where norms are made operational, helping states move from endorsement to implementation and from implementation in principle to implementation in practice. Technical experts, regional organisations, the private sector, academia, and civil society can help states understand how norms translate into practical steps.
Evidence
The Pacific Islands Forum states that the global mechanism should be a place where norms are made operational, with its work helping states move from endorsement to implementation and from implementation in principle to implementation in practice . Expert briefings in the DTGs can provide practical input on implementation without changing the intergovernmental nature of decision-making .
Major Discussion Point
Role of the Global Mechanism and Dedicated Thematic Groups
157
WPM
941
Words
6 min
Time
The 11 non-binding voluntary norms constitute a central pillar; the EU published an initial overview of implementation efforts using the 2021 GGE norms guidance – EU norms implementation contribution (European Union)
Arg. 1
Explanation
The EU reaffirms its strong commitment to the full and effective implementation of the UN Framework of Responsible State Behaviour in Cyberspace, with the 11 non-binding voluntary norms constituting a central pillar. The EU and its member states published an initial overview of their implementation efforts using the consensus norms guidance included in the 2021 UN GGE report.
Evidence
The EU and its member states presented ahead of the plenary session an initial overview of their efforts to implement the norms of responsible state behaviour, using the consensus norms guidance included in the 2021 report of the UN Groups of Governmental Experts . The EU detailed its main pieces of legislation, policies, structures, mechanisms, and networks put in place to implement the UN norms, including for norm 13b regarding ICT incidents and attribution .
Major Discussion Point
Implementation of Existing Voluntary Non-Binding Norms
137
WPM
376
Words
3 min
Time
Voluntary norms complement international law by offering practical guidance to foster transparency, predictability, restraint, and trust; implementation must translate into public policies and communication channels – Norms as complement to law (Costa Rica)
Arg. 1
Explanation
Costa Rica emphasises that voluntary norms do not replace international law applicable to cyberspace but rather complement it by offering practical guidance to foster transparency, predictability, restraint, and trust. Responsible state behaviour must be translated into public policies, communication channels, responsible vulnerability disclosure, and multi-stakeholder cooperation.
Evidence
Costa Rica emphasises that voluntary norms do not replace international law applicable to cyberspace but complement it by offering practical guidance to foster transparency, predictability, restraint, and trust . Costa Rica states that responsible state behaviour must not remain merely at the level of declarations but must be translated into public policies, communication channels, responsible vulnerability disclosure, multi-stakeholder cooperation, and measures that contribute to a sustainable future .
Major Discussion Point
Implementation of Existing Voluntary Non-Binding Norms
Due diligence should be approached as both a responsibility and an agenda for cooperation, technical assistance, and institutional capacity building – Due diligence and cooperation (Costa Rica)
Arg. 2
Explanation
Costa Rica argues that due diligence actions should be approached in a balanced manner, both as a responsibility to adopt reasonable measures to prevent harmful cyber acts and as an agenda for cooperation, technical assistance, and institutional capacity building. This framing links the normative framework to practical capacity building needs.
Evidence
Costa Rica believes that due diligence actions should be approached in a balanced manner, both as a responsibility to adopt reasonable measures commensurate with national capabilities to prevent a state’s territory or infrastructure from being used for harmful cyber acts against other states, and also as an agenda for cooperation, technical assistance, and institutional capacity building .
Major Discussion Point
International Cooperation and Capacity Building
117
WPM
389
Words
3 min
Time
The principal challenge is not absence of norms but effective implementation; states should voluntarily publish national positions on interpretation and application of specific norms – Implementation gap challenge (Colombia)
Arg. 1
Explanation
Colombia argues that the principal challenge facing states today is not the absence of norms but rather their effective implementation. Colombia invites states to consider voluntarily publishing their national positions on the interpretation and application of specific norms to promote greater mutual understanding and facilitate the exchange of best practices.
Evidence
Colombia considers that the principal challenge is not the absence of norms but rather effective implementation, with questions remaining about how states will interpret and apply agreed norms and about challenges that limit cooperation and timely exchange of information . Colombia invites states to consider voluntary publication of their national positions on interpretation and application of specific norms, which would contribute to promoting greater mutual understanding and facilitating the exchange of best practices .
Major Discussion Point
Implementation of Existing Voluntary Non-Binding Norms
126
WPM
433
Words
3 min
Time
The existing norms have guided Brazil's national cybersecurity strategy; regional cooperation through OAS and Mercosur has been particularly relevant for norms implementation – Regional cooperation for implementation (Brazil)
Arg. 1
Explanation
Brazil highlights that the voluntary norms of responsible state behaviour have guided the establishment and updating of its national norms and policies, including its most recent national cybersecurity strategy. Regional cooperation through mechanisms such as OAS CISERT Americas and the Mercosur Cybersecurity Commission has been particularly relevant for norms implementation.
Evidence
Brazil notes that the norms have guided the establishment and updating of its national norms and policies to secure critical infrastructure against cyber threats, including its most recent national cybersecurity strategy adopted last year . Brazil has been engaged in multiple regional initiatives, such as the OAS CISERT Americas, which has been instrumental in advancing norms related to information sharing on threats and vulnerabilities, and the Mercosur Cybersecurity Commission, which has fostered national implementation through information exchange and the development of a common regional taxonomy .
Major Discussion Point
Implementation of Existing Voluntary Non-Binding Norms
Promotion of gender equality is a key component of adequate norms implementation; policies addressing differentiated impact of cyber threats on women and vulnerable groups are important – Gender equality in cybersecurity (Brazil)
Arg. 2
Explanation
Brazil argues that the promotion of gender equality is a key component of the adequate implementation of the norms. Promoting the inclusion of women in the cybersecurity workforce and having policies that address the differentiated impact of cyber threats on women and other vulnerable groups is an important component of Brazil's new national cybersecurity strategy.
Evidence
Brazil states that the promotion of gender equality is a key component to the adequate implementation of the norms, including promoting the inclusion of women in the cybersecurity workforce and having policies that address the differentiated impact of cyber threats on women and other vulnerable groups .
Major Discussion Point
International Cooperation and Capacity Building
The global mechanism should promote knowledge sharing and support regional cooperation initiatives such as OAS CISERT Americas and Mercosur Cybersecurity Commission – Regional cooperation mechanisms (Brazil)
Arg. 3
Explanation
Brazil recognises the importance of international cooperation efforts in promoting the national implementation of norms and has greatly benefited from the national experiences of other countries. Brazil fully welcomes continued knowledge sharing and highlights regional cooperation mechanisms as particularly relevant.
Evidence
Brazil recognises the importance of international cooperation efforts in promoting the national implementation of norms and fully welcomes continued knowledge sharing . Brazil highlights regional cooperation through the OAS CISERT Americas and the Mercosur Cybersecurity Commission as particularly relevant examples .
Major Discussion Point
International Cooperation and Capacity Building
Brazil believes that advancing implementation of existing norms and adopting new ones are not mutually exclusive; the global mechanism can accommodate both with consensus – Both implementation and new norms possible (Brazil)
Arg. 4
Explanation
Brazil argues that positions in favour of advancing implementation of existing norms and those in favour of adopting new norms are not mutually exclusive, and that the global mechanism can accommodate both as long as there is consensus. Brazil emphasises that any efforts to develop new norms must be inclusive and take place within the multilateral process.
Evidence
Brazil states that positions in favour of advancing implementation of existing norms and for the adoption of new ones are not mutually exclusive, and that the global mechanism can have room for both, as long as there is consensus . Brazil notes that there are many initiatives currently underway outside the multilateral process that aim to shape state behaviour in areas that clearly fall within the purview of the global mechanism, implying the need for inclusive norm development within the mechanism .
Major Discussion Point
Development of Additional or Legally Binding Norms
Disagreed with
CubaChinaIslamic Republic of IranMoroccoArmeniaIsraelPortugalRepublic of KoreaVanuatuBotswanaTonga on behalf of the Pacific Island Forum
on: Whether to develop new/additional voluntary norms or focus exclusively on implementing existing ones
131
WPM
522
Words
4 min
Time
Priority should be given to supporting states in translating agreed norms into national policies, institutional procedures, and operational practices – Translating norms to practice (Italy)
Arg. 1
Explanation
Italy argues that the framework of responsible state behaviour developed through the GGE and the OEWG provides a solid foundation that requires systematic and continuous implementation. Priority should be given to supporting states in translating agreed norms into national policies, institutional procedures, and operational practices.
Evidence
Italy states that the framework of responsible state behaviour provides a solid foundation for the international community that requires systematic and continuous implementation . Priority should be given to supporting states in translating agreed norms into national policies, institutional procedures, and operational practices . Italy highlights its National Cyber Security Agency, which implements and oversees the national cyber security perimeter and is responsible for the implementation of the EU NISTU directive strengthening ICT supply chain security .
Major Discussion Point
Implementation of Existing Voluntary Non-Binding Norms
The framework of responsible state behavior requires systematic and continuous implementation; the voluntary checklist adopted by the third APR is a precious tool – Systematic implementation needed (Italy)
Arg. 2
Explanation
Italy believes that the voluntary checklist adopted by the third APR is a very precious tool for all member states and hopes that the global mechanism can take advantage of it by promoting a discussion on its finalisation. Italy also highlights the importance of multi-stakeholder partnerships in leveraging technical expertise and innovation capabilities.
Evidence
Italy believes that the voluntary checklist adopted by the third APR was a very precious tool for all member states, and hopes that the global mechanism can take advantage of it, promoting a discussion on its finalisation . Italy also notes that multi-stakeholder partnerships are essential, allowing governments to leverage technical expertise, operational experience, and innovation capabilities developed by competence centres, research organisations, and the private sector .
Major Discussion Point
Implementation of Existing Voluntary Non-Binding Norms
DTG1 can facilitate thorough discussion across the five pillars; DTG2 can produce tailored capacity-building projects contributing to responsible state behaviour – DTG1 and DTG2 roles (Italy)
Arg. 3
Explanation
Italy firmly believes that DTG1 can play a key role in facilitating thorough discussion across the five pillars, helping to deepen the practical implementation of norms. DTG2 can then produce tailored capacity-building projects that will also contribute to more responsible behaviour of states in the use of ICTs.
Evidence
Italy states that DTG1 can play a key role in facilitating a thorough discussion across the five pillars, helping to deepen the practical implementation of norms . DTG2 can produce tailored capacity-building projects that will also contribute to more responsible behaviour of states in the use of ICTs .
Major Discussion Point
Role of the Global Mechanism and Dedicated Thematic Groups
151
WPM
318
Words
2 min
Time
The list of norms should not be set in stone given rapid evolution of threats; the framework must be able to evolve and be enriched or clarified as necessary – Evolving normative framework (Morocco)
Arg. 1
Explanation
Morocco argues that the list of norms should not be set in stone given the rapid evolution of threats and the emergence of new technologies and modes of operation, including AI. The framework must be able to evolve, and the 11 voluntary non-binding norms of the 2015 GGE report serve as a foundation that should be enriched or clarified if necessary.
Evidence
Morocco highlights that the list of norms should not be set in stone given the rapid evolution of threats and emergence of new technologies and modes of operation, including AI . Morocco states that the 11 Voluntary Non-Binding Norms of the GGE Report 2015 serve as a foundation, and all states should maintain the ability to enrich or clarify them if necessary .
Major Discussion Point
Development of Additional or Legally Binding Norms
Disagreed with
CubaChinaIslamic Republic of IranArmeniaBrazilIsraelPortugalRepublic of KoreaVanuatuBotswanaTonga on behalf of the Pacific Island Forum
on: Whether to develop new/additional voluntary norms or focus exclusively on implementing existing ones
156
WPM
509
Words
3 min
Time
Legally binding norms are needed to complement international law, respond to legal gaps, and facilitate impartial handling of cybersecurity challenges; voluntary norms are only an intermediary step – Case for legally binding norms (Cuba)
Arg. 1
Explanation
Cuba reaffirms its position in favour of developing legally binding norms under the auspices of the United Nations to complement applicable principles of international law and respond to legal gaps in cybersecurity. Cuba argues that non-binding voluntary norms are limited by their voluntary nature and only constitute an intermediary step, as demonstrated by the annual increase in cyber attacks.
Evidence
Cuba reaffirms its position in favour of developing legally binding norms under the auspices of the United Nations that would complement applicable principles of international law, respond to legal gaps in cybersecurity, and facilitate impartial handling of growing challenges . Cuba argues that non-binding voluntary norms are limited by their voluntary nature and only constitute an intermediary step, as demonstrated by the annual increase in cyber attacks with ever greater speed, scale, and sophistication .
Major Discussion Point
Development of Additional or Legally Binding Norms
128
WPM
345
Words
3 min
Time
The permanent mechanism was deliberately designed to be more oriented towards implementation of the 11 voluntary norms than towards discussion of more norms or binding instruments – Implementation over new norms (Portugal)
Arg. 1
Explanation
Portugal argues that the permanent mechanism was deliberately designed to be more stable than its predecessors and more oriented towards implementation of the 11 voluntary norms of responsible state behaviour and applicable international law, rather than towards the discussion of even more norms or binding instruments. Portugal strongly believes that the two DTGs have the potential to lead towards action-oriented results.
Evidence
Portugal states that it was the ambition of establishing a permanent mechanism of regular institutional dialogue that led to its present architecture, deliberately meant to be more stable than its predecessors and more oriented towards implementation of the 11 voluntary norms of responsible state behaviour already endorsed and of the applicable international law, than towards the discussion of even more norms or even more binding instruments . Portugal strongly believes that the two DTGs have the potential to lead towards action-oriented results to be debated during the next plenary session .
Major Discussion Point
Development of Additional or Legally Binding Norms
Disagreed with
CubaIsraelUkraine
on: Whether legally binding cybersecurity instruments are desirable or premature
The two DTGs have the potential to lead towards action-oriented results; the mechanism was designed to be more stable and implementation-oriented than its predecessors – Action-oriented DTGs (Portugal)
Arg. 2
Explanation
Portugal strongly believes that the two dedicated thematic groups, designed to address specific security challenges and to accelerate cybersecurity capacity building, have the potential to lead towards action-oriented results. The mechanism was deliberately designed to be more stable and implementation-oriented than its predecessors.
Evidence
Portugal states that the two dedicated thematic groups have the potential to lead towards action-oriented results to be debated during the next plenary session on the basis of their recommendations . The mechanism was deliberately designed to be more stable than its predecessors and more oriented towards implementation .
Major Discussion Point
Role of the Global Mechanism and Dedicated Thematic Groups
131
WPM
173
Words
1 min
Time
The global mechanism should focus on identifying practical ways to effectively implement the 11 voluntary non-binding norms; the voluntary checklist should continue as a living document – Checklist as living document (Republic of Korea)
Arg. 1
Explanation
The Republic of Korea argues that the work of the global mechanism should build upon the consensus achieved through the GGE and OEWG process, focusing on identifying practical ways to effectively implement the 11 voluntary non-binding norms. The voluntary checklist of practical actions should continue to serve as a living document, with the global mechanism continuing discussions on the checklist with a view to its eventual finalisation.
Evidence
The Republic of Korea states that the global mechanism should focus on identifying practical ways to effectively implement the 11 voluntary non-binding norms of responsible state behaviour agreed by the GGE and endorsed by the UN General Assembly . The voluntary checklist of practical actions should continue to serve as a living document, with the global mechanism continuing discussions on the checklist with a view to its eventual finalisation while ensuring it remains practical, relevant, and responsive to evolving needs .
Major Discussion Point
Implementation of Existing Voluntary Non-Binding Norms
Disagreed with
Islamic Republic of IranIsraelPortugalTonga on behalf of the Pacific Island Forum
on: Whether the balance between developing new norms and implementing existing ones has been properly maintained in the mechanism's work
129
WPM
438
Words
3 min
Time
The task before us is observance, not expansion; existing commitments have not yet been implemented by all states to a standard that would reveal any genuine gap – Observance over expansion (Vanuatu)
Arg. 1
Explanation
Vanuatu argues that its position on the norms pillar has been consistent across the OEWG and remains so: the task before states is observance, not expansion. The existing commitments have not yet been implemented by all states to a standard that would reveal any genuine gap requiring new norms.
Evidence
Vanuatu states that its position on this pillar has been consistent across the OEWG and remains so: the task before states is observance, not expansion . Vanuatu notes that the existing commitments have not yet been implemented by all states to a standard that would refill any genuine gap .
Major Discussion Point
Implementation of Existing Voluntary Non-Binding Norms
Disagreed with
CubaChinaIslamic Republic of IranMoroccoArmeniaBrazilIsraelPortugalRepublic of KoreaBotswanaTonga on behalf of the Pacific Island Forum
on: Whether to develop new/additional voluntary norms or focus exclusively on implementing existing ones
Disaster preparedness infrastructure such as early warning networks and emergency broadcast systems falls squarely within the protection these norms describe – Disaster infrastructure protection (Vanuatu)
Arg. 2
Explanation
Vanuatu highlights that norms concerning critical infrastructure carry particular weight for a country whose survival infrastructure is digital, including its multi-hazard early warning network, emergency broadcast capability, and systems for coordinating relief across 83 islands. Vanuatu invites states to affirm that infrastructure enabling disaster preparedness and response falls within the protection these norms describe.
Evidence
Vanuatu notes that its multi-hazard early warning network, emergency broadcast capability, and systems for coordinating relief across 83 islands are the assets that stand between a natural hazard and a humanitarian catastrophe . Vanuatu invites states to affirm through their conduct and statements in this mechanism that infrastructure enabling disaster preparedness and response falls squarely within the protection these norms describe .
Capacity building is indispensable to effective implementation of the agreed framework; it is central to reducing vulnerabilities and narrowing the digital divide – Capacity building centrality (Nigeria)
Arg. 1
Explanation
Nigeria affirms that capacity building remains indispensable to the effective implementation of the agreed framework, as it is central to reducing vulnerabilities, narrowing the digital divide, and enabling all states to participate meaningfully in promoting international ICT security. Nigeria also recognises the valuable contributions of relevant stakeholders, including civil society, academia, and the private sector.
Evidence
Nigeria states that capacity building remains indispensable to the effective implementation of the agreed framework, as it is central to reducing vulnerabilities, narrowing the digital divide, and enabling all states to participate meaningfully in promoting international ICT security . Nigeria recognises the valuable contributions of relevant stakeholders, including civil society, academia, and the private sector, in support of this state-led and intergovernmental mechanism .
Nigeria supports scenario-based discussions as an effective means of strengthening implementation, improving collective preparedness, and facilitating practical cooperation – Scenario-based implementation discussions (Nigeria)
Arg. 2
Explanation
Nigeria welcomes the establishment of the dedicated thematic groups and supports scenario-based discussions as an effective means of strengthening implementation, improving collective preparedness, and facilitating practical cooperation. Such exchanges provide valuable opportunities to share national experiences and strengthen incident response capabilities.
Evidence
Nigeria welcomes the establishment of the dedicated thematic groups and supports scenario-based discussions as an effective means of strengthening implementation, improving collective preparedness, and facilitating practical cooperation . Such exchanges provide valuable opportunities to share national experiences, strengthen incident response capabilities, and deepen collective understanding of evolving cyber threats .
Major Discussion Point
Implementation of Existing Voluntary Non-Binding Norms
The global mechanism should remain state-led, single-track, inclusive, transparent, and consensus-based; consensus should continue to guide collective efforts – State-led consensus mechanism (Nigeria)
Arg. 3
Explanation
Nigeria reaffirms its commitment to preserving the state-led, single-track, inclusive, transparent, and consensus-based nature of the global mechanism. Consensus has consistently enabled progress in this process and should continue to guide collective efforts.
Evidence
Nigeria states that it remains firmly committed to preserving the state-led, single-track, inclusive, transparent, and consensus-based nature of this mechanism . Nigeria notes that consensus has consistently enabled progress in this process and should continue to guide collective efforts .
Major Discussion Point
Role of the Global Mechanism and Dedicated Thematic Groups
Disagreed with
Kenya ICT Action NetworkDiscover MUN FoundationSwitzerlandNicaragua
on: The role and scope of stakeholder participation in the global mechanism and its DTGs
118
WPM
355
Words
3 min
Time
Global mechanism should discuss developing universal, non-discriminatory international norms on data security and establish barriers for frontier AI models – New AI norms needed (China)
Arg. 1
Explanation
China argues that new norms should be developed regarding AI's impact on cybersecurity, including establishing barriers for frontier AI models to guard against security and geopolitical risks from the convergence of cyber technologies with AI. China also calls for developing universal, non-discriminatory international norms on data security.
Evidence
China believes that new norms should be developed regarding AI’s impact on cybersecurity, including establishing barriers for frontier AI models to guard against possible security risks and geopolitical risks due to the convergence of cyber technologies with AI . China calls for global mechanisms to discuss developing universal, non-discriminatory international norms on data security to provide effective institutional guarantees for the protection of data security across the world .
Major Discussion Point
Role of Artificial Intelligence and Emerging Technologies in Cybersecurity
Additional norms should be developed regarding AI's impact on cybersecurity, data security, critical infrastructure protection, and supply chain security – New norms for emerging challenges (China)
Arg. 2
Explanation
China argues that new norms should be developed in several areas: AI's impact on cybersecurity, data security, critical infrastructure protection, and supply chain security. China calls for building upon existing consensus to further refine and develop new technologies to implement globally interoperable common rules and standards for supply chain security.
Evidence
China believes that new norms should be developed regarding AI’s impact on cybersecurity, data security, critical infrastructure protection, and supply chain security . China states that states should not use cyber means to damage other countries’ critical infrastructure, especially key information infrastructure concerning national economy, livelihoods, and public interests such as energy, transportation, water conservancy, finance, and public services . China calls for building upon existing consensus to further refine and develop globally interoperable common rules and standards for supply chain security and opposes the man-made fragmentation of supply chains driven by political motives .
Major Discussion Point
Development of Additional or Legally Binding Norms
Disagreed with
CubaIslamic Republic of IranMoroccoArmeniaBrazilIsraelPortugalRepublic of KoreaVanuatuBotswanaTonga on behalf of the Pacific Island Forum
on: Whether to develop new/additional voluntary norms or focus exclusively on implementing existing ones
140
WPM
380
Words
3 min
Time
The 11 voluntary norms are sufficient to govern state conduct; DTGs should formulate concrete strategies for effective implementation using the UN Cyber Norms National Implementation Checklist – Existing norms sufficiency (Botswana)
Arg. 1
Explanation
Botswana reaffirms its commitment to the UN cyber framework and emphasises that the 11 voluntary norms, reinforced by the UN Charter and existing international law, are sufficient to govern state conduct in cyberspace. Botswana emphasises the role of the DTGs in formulating concrete and action-oriented strategies to effectively implement the existing norms.
Evidence
Botswana reaffirms that the 11 voluntary norms reinforced by the UN Charter and existing international law are sufficient to govern state conduct in cyberspace . Botswana emphasises the role of the DTGs in formulating concrete and action-oriented strategies to effectively implement the existing norms . The UN Cyber Survey and the UN Cyber Norms National Implementation Checklist serve as baseline instruments for the global mechanism and its DTGs by providing clear and actionable tracking of where UN member states systematically develop and implement the norms .
Major Discussion Point
Implementation of Existing Voluntary Non-Binding Norms
Disagreed with
CubaChinaIslamic Republic of IranMoroccoArmeniaBrazilIsraelPortugalRepublic of KoreaVanuatuTonga on behalf of the Pacific Island Forum
on: Whether to develop new/additional voluntary norms or focus exclusively on implementing existing ones
Developing countries cannot effectively protect critical infrastructure or prevent cybercrime without underlying technical and institutional capacity; DTGs should formulate concrete strategies – Capacity gap in developing countries (Botswana)
Arg. 2
Explanation
Botswana argues that for developing states, the debate about implementing existing norms versus formulating new ones is secondary to the immediate reality of the digital divide. Developing countries cannot effectively protect critical infrastructure, prevent cross-border cybercrime, or guarantee the integrity of their supply chains without the underlying technical and institutional capacity to do so.
Evidence
Botswana states that for developing states, the debate about implementing existing norms against formulating new norms is secondary to the immediate reality of the digital divide . Developing countries cannot effectively protect critical infrastructure, prevent cross-border cybercrime, or guarantee the integrity of their supply chains if they lack the underlying technical and institutional capacity to do so .
Thailand has integrated norms into its National Policy and Action Plan on Cybersecurity; ASEAN has finalised its Norm Implementation Checklist to support member states – Regional norm integration (Thailand)
Arg. 1
Explanation
Thailand highlights that it has integrated the norms of responsible behaviour into its National Policy and Action Plan on Cybersecurity 2022-2027, with the next plan currently under development guided by the ASEAN and OEWG checklist. ASEAN, as the first regional organisation to have adopted these cyberspace norms in principle, has finalised its Norm Implementation Checklist.
Evidence
Thailand has integrated the norms of responsible behaviour into its National Policy and Action Plan on Cybersecurity 2022-2027, with the next plan for 2028-2032 currently under development, guided by the ASEAN and OEWG checklist . ASEAN, as the first regional organisation to have adopted these cyberspace norms in principle, has finalised its Norm Implementation Checklist to support member states in translating norms into practices .
Major Discussion Point
Implementation of Existing Voluntary Non-Binding Norms
Thailand remains open to discussions on possible development of additional norms, particularly in response to emerging threats, provided they do not impose obligations beyond states' capacities – Openness to additional norms with conditions (Thailand)
Arg. 2
Explanation
Thailand remains open to discussions on the possible development of additional norms, rules, and principles of responsible state behaviour in the use of ICTs, particularly in response to emerging threats. However, such discussions should take into account the diverse contexts, needs, and capacities of states, and any additional frameworks should not impose obligations beyond states' capacities or serve as a means of technological exclusion.
Evidence
Thailand remains open to discussions on the possible development of additional norms, rules, and principles of responsible state behaviour in the use of ICTs, particularly in response to emerging threats . Thailand states that such discussions should take into account the diverse contexts, needs, and capacities of states, and that any additional frameworks should not impose obligations beyond states’ capacities or serve as a means of technological exclusion .
Major Discussion Point
Development of Additional or Legally Binding Norms
107
WPM
496
Words
5 min
Time
The 11 norms confer mutual expectations on states; the voluntary checklist should be strengthened and operationalised as a voluntary instrument for self-reporting – Mutual expectations and self-reporting (Netherlands)
Arg. 1
Explanation
The Kingdom of the Netherlands considers it pivotal that while the norms are not in themselves binding, they do confer a degree of mutual expectations on states to behave responsibly in cyberspace. The Netherlands believes that the voluntary checklist should be strengthened and operationalised as a voluntary instrument for self-reporting on the implementation of the 11 norms.
Evidence
The Netherlands considers it pivotal that while the norms are not in themselves binding, they do confer a degree of mutual expectations on states to behave responsibly in cyberspace . The Netherlands believes that the voluntary checklist for the implementation of norms remains a tool of great potential and that states should endeavour to strengthen and operationalise the checklist and lay the basis for a voluntary instrument for self-reporting on the implementation of the 11 norms . The EU paper on norms implementation is cited as a perfect example of what such reporting could look like .
Major Discussion Point
Implementation of Existing Voluntary Non-Binding Norms
164
WPM
301
Words
2 min
Time
The global mechanism should support implementation through guidance and capacity building coordination; DTGs could share experience on best practice through specific scenarios – DTG guidance for implementation (New Zealand)
Arg. 1
Explanation
New Zealand argues that the key value the global mechanism could provide is further guidance and capacity building coordination to support implementation at the national level. The DTGs could prove their worth by considering specific scenarios or cybersecurity challenges where experts and states could share experience on best practice and identify specific areas where capacity building would support norm implementation.
Evidence
New Zealand reiterates the message from the Pacific Islands Forum that the regional priority is fully implementing the existing norms, and that the key value the global mechanism could provide is further guidance and capacity building coordination to support implementation at the national level . New Zealand notes that by considering specific scenarios or specific cybersecurity challenges, experts in the states could share experience on what best practice looks like, offer peer learning, and identify specific areas where capacity building would support norm implementation .
Major Discussion Point
Implementation of Existing Voluntary Non-Binding Norms
137
WPM
948
Words
7 min
Time
The global mechanism has a mandate to elaborate additional rules, norms, and principles; recent unlawful cyber operations reveal gaps in the existing normative framework – Mandate for additional norms (Islamic Republic of Iran)
Arg. 1
Explanation
Iran argues that the global mechanism has an explicit mandate to elaborate additional rules, norms, and principles of responsible state behaviour, as set out in the OEWG final report and Annex C. Recent developments, including alleged unlawful cyber operations by the United States and the Israeli regime against Iran, have revealed important gaps in the existing normative framework.
Evidence
Iran cites Paragraph 36D of the OEWG final report, which reaffirms that additional norms could continue to be developed over time, and Paragraph 9 of Annex C, which explicitly assigns the global mechanism the task of elaborating additional rules, norms, and principles of responsible state behaviour . Iran alleges that recent unlawful cyber operations carried out by the United States and the Israeli regime targeted critical infrastructure and essential civilian services, exploited private sector technologies and ICT supply chains, and integrated cyber capabilities with conventional military operations .
Major Discussion Point
Development of Additional or Legally Binding Norms
Developing new norms and implementing existing ones are complementary objectives that should proceed in parallel; a structured process for elaborating additional norms should be established – Parallel norm development and implementation (Islamic Republic of Iran)
Arg. 2
Explanation
Iran argues that throughout the OEWG process, many delegations emphasised that the future development of additional norms and the implementation of existing norms are complementary objectives that should proceed in parallel. Iran proposes that the Chair prepare an initial consolidated draft compiling proposals for additional rules, norms, and principles submitted by member states.
Evidence
Iran states that throughout the OEWG process, many delegations consistently emphasised that the future development of additional norms and the implementation of existing norms are complementary objectives that should proceed in parallel, but that this balance has not been maintained . Iran proposes that the Chair prepare an initial consolidated draft compiling proposals for additional rules, norms, and principles submitted by member states, deriving from the Annex to the first OEWG Chair Summary, to provide a practical basis for structured discussions .
Major Discussion Point
Development of Additional or Legally Binding Norms
Recent unlawful cyber operations by the United States and the Israeli regime targeted Iranian critical infrastructure, exploited ICT supply chains, and integrated cyber capabilities with military operations – Iranian allegations against Israel and US (Islamic Republic of Iran)
Arg. 3
Explanation
Iran alleges that recent unlawful cyber operations carried out by the United States and the Israeli regime, in conjunction with their unlawful military attacks against Iran, targeted critical infrastructure and essential civilian services. These operations exploited private sector technologies, ICT supply chains, and digital platforms, and integrated cyber capabilities with conventional military operations.
Evidence
Iran alleges that recent unlawful cyber operations carried out by the United States and the Israeli regime targeted critical infrastructure and essential civilian services, exploited private sector technologies, ICT supply chains, and digital platforms, involved cyber espionage, disinformation, and cognitive operations, and integrated cyber capabilities with conventional military operations, including electronic warfare and interference with communications and satellite navigation systems .
Major Discussion Point
Geopolitical Tensions and Right of Reply Exchanges
Disagreed with
RomaniaUkraineIsraelRussian Federation
on: Attribution of specific hostile cyber activities and geopolitical responsibility for cyber attacks
Resistance groups in the region are not terrorists but legitimate resistance movements recognised under UN General Assembly Resolution 46-51; those who bomb hospitals are the real terrorists – Iranian characterisation of regional actors (Islamic Republic of Iran)
Arg. 4
Explanation
Iran argues that the Israeli regime has consistently sought to mislabel legitimate resistance groups in the region as terrorists or proxies. Iran contends that according to UN General Assembly Resolution 46-51, these groups are legitimate resistance movements fighting against occupation, apartheid, aggression, and genocide.
Evidence
Iran states that according to United Nations General Assembly Resolution 46-51, groups labelled as terrorists by Israel are not terrorists but legitimate resistance movements fighting against occupation, apartheid, aggression, and genocide in the Palestinian and other occupied territories . Iran argues that international law explicitly recognises the right of peoples to resist foreign occupation and defend themselves against aggression .
Major Discussion Point
Geopolitical Tensions and Right of Reply Exchanges
Israeli actions in the region strike at the very foundation of every pillar of the global mechanism and constitute a clear illustration of the malicious ICT activities these processes seek to prevent – Iranian framing of Israeli actions (Islamic Republic of Iran)
Arg. 5
Explanation
Iran argues that the actions of the Israeli regime in the region, particularly its two alleged unlawful acts of aggression against Iran, strike at the very foundation of every pillar of the global mechanism and of international law and the UN Charter. Iran contends that referring to these actions does not politicise or derail discussions but rather constitutes a clear illustration of the malicious ICT activities these processes seek to prevent.
Evidence
Iran states that the actions of the Israeli regime in the region, particularly its two unlawful acts of aggression against Iran over the past year, strike at the very foundation of every pillar of the global mechanism, just as they strike at the very foundations of international law and the Charter of the United Nations . Iran argues that referring to these actions neither politicises nor derails discussions but constitutes a clear illustration of the very malicious ICT activities that these processes seek to prevent and address .
Major Discussion Point
Geopolitical Tensions and Right of Reply Exchanges
150
WPM
302
Words
2 min
Time
The global mechanism should remain practical and implementation-oriented; thematic discussions provide opportunity to exchange national experiences and good practices – Practical implementation focus (North Macedonia)
Arg. 1
Explanation
Ireland aligns with the EU statement and emphasises that the focus should now be on implementing the 11 voluntary non-binding norms of responsible state behaviour. Ireland believes there is a strong role for the DTGs to discuss the implementation of the norms connected to specific challenges such as the protection of critical infrastructure or ransomware, and to exchange best practices.
Evidence
Ireland states that it is important that states show how they are seeking to implement the norms, referring to the EU’s paper on implementation as an example . Ireland believes there is a strong role for the DTGs to discuss the implementation of the 11 voluntary norms connected to specific challenges such as the protection of critical infrastructure or ransomware, to exchange best practices that could feed into recommendations . Ireland also strongly supports the voluntary checklist of practical actions for the implementation of norms developed in the OEWG .
Major Discussion Point
Implementation of Existing Voluntary Non-Binding Norms
130
WPM
228
Words
2 min
Time
The global mechanism should remain practical, inclusive, and implementation-oriented; thematic discussions provide opportunity to exchange national experiences and good practices – Practical implementation focus (North Macedonia)
Arg. 1
Explanation
North Macedonia believes that the global mechanism should remain practical, inclusive, and implementation-oriented, with efforts focused on supporting the efficient implementation of the existing framework of responsible state behaviour in cyberspace. Thematic discussions will provide a valuable opportunity to exchange national experiences, share good practices, and identify practical approaches that can support implementation at the national level.
Evidence
North Macedonia states that the global mechanism should remain practical, inclusive, and implementation-oriented, with efforts focused on supporting the efficient implementation of the existing framework of responsible state behaviour in cyberspace, including the 11 voluntary non-binding norms agreed by all member states . North Macedonia notes that thematic discussions will provide a valuable opportunity to exchange national experiences, share good practices, and identify practical approaches that can support implementation at the national level .
Major Discussion Point
Implementation of Existing Voluntary Non-Binding Norms
187
WPM
231
Words
1 min
Time
The Geneva Manual, produced through multi-stakeholder dialogue, maps roles and responsibilities in implementing voluntary norms and ensuring security and stability of cyberspace – Multi-stakeholder norms implementation (Switzerland)
Arg. 1
Explanation
Switzerland argues that cooperation with non-governmental stakeholders is essential for the implementation of the voluntary norms. Switzerland has established a genuine dialogue on responsible behaviour in cyberspace, which produced the Geneva Manual, a living document that analyses and maps the roles and responsibilities of various actors in implementing voluntary norms.
Evidence
Switzerland states that it has established a genuine dialogue on responsible behaviour in cyberspace, which analyses and maps the roles and responsibilities of various actors in implementing voluntary norms and ensuring the security and stability of cyberspace . The Geneva Manual is a product of this dialogue, with the first two chapters focusing on norms related to supply chain security, reporting of ICT vulnerabilities, and the protection of critical infrastructure .
Major Discussion Point
Implementation of Existing Voluntary Non-Binding Norms
Thematic discussions should address risks to critical infrastructure from malicious use of AI by states, state-sponsored actors, and criminals – AI risks to infrastructure (Ukraine)
Arg. 2
Explanation
Switzerland argues that thematic discussions should address the risks to critical infrastructures arising from the malicious use of artificial intelligence by states, state-sponsored actors, and criminals. This includes risks stemming from vulnerabilities in the supply chain, data poisoning, and the manipulation of AI systems.
Evidence
Switzerland states that thematic discussions should address the risk to critical infrastructures arising from malicious use of artificial intelligence by states, state-sponsored actors, and criminals, as well as risks stemming from vulnerabilities in the supply chain, data poisoning, and the manipulation of AI systems .
Major Discussion Point
Role of Artificial Intelligence and Emerging Technologies in Cybersecurity
Broad and meaningful participation of stakeholders in the DTGs is not only necessary but advantageous to all states; the Geneva Dialogue demonstrates this – Stakeholder participation in DTGs (Switzerland)
Arg. 3
Explanation
Switzerland is firmly convinced that broad and meaningful participation of stakeholders in the work of the global mechanism, particularly the DTGs, is not only necessary but also to the advantage of all states. Switzerland's experience with the Geneva Dialogue demonstrates the value of multi-stakeholder engagement in implementing voluntary norms.
Evidence
Switzerland states that it is firmly convinced that broad and meaningful participation of stakeholders in the work of the global mechanism, in particular the DTGs, is not only necessary but also to the advantage of all states . Switzerland cites the Geneva Dialogue as an example of how multi-stakeholder engagement can contribute to implementing voluntary norms and ensuring the security and stability of cyberspace .
Major Discussion Point
Role of the Global Mechanism and Dedicated Thematic Groups
Disagreed with
Kenya ICT Action NetworkDiscover MUN FoundationNigeriaNicaragua
on: The role and scope of stakeholder participation in the global mechanism and its DTGs
114
WPM
711
Words
6 min
Time
Implementation of agreed norms is essential; Albania has enacted cybersecurity legislation transposing EU directives and operationalised national cybersecurity structures – National legislative implementation (Albania)
Arg. 1
Explanation
Albania argues that the implementation of agreed UN norms is essential, with their value lying not only in political commitment but in their translation into national legislation, institutions, operational procedures, and international cooperation mechanisms. Albania has approved and enforced a Law on Cybersecurity since May 2022, which fully transposes the EU NISTU Directive.
Evidence
Albania has approved and enforced the Law on Cybersecurity since May 2022, which fully transposes the EU NISTU Directive, with all implementing bylaws now adopted . Albania has now fully operational cybersecurity structures such as National SOC and CERT, and the establishment of national cyber incident monitoring and response structures supports several norms, including preventing harmful ICT practices and protecting critical infrastructure .
Major Discussion Point
Implementation of Existing Voluntary Non-Binding Norms
105
WPM
353
Words
3 min
Time
Critical Infrastructure Protection Act of 2019 mandates identification and safeguarding of infrastructure vital for public safety, national security, and essential services – National critical infrastructure legislation (South Africa)
Arg. 1
Explanation
South Africa highlights its Critical Infrastructure Protection Act of 2019, which recognises that specific infrastructure is essential for public safety, national security, and the continuous delivery of vital public services. The act mandates the identification and implementation of appropriate measures to safeguard and ensure the security of critical infrastructure.
Evidence
South Africa’s Critical Infrastructure Protection Act of 2019 recognises that specific infrastructure is essential for public safety, national security, and the continuous delivery of vital public services . The act mandates the identification and implementation of appropriate measures to safeguard and ensure the security of critical infrastructure, defining infrastructure as critical if its operation is vital for the economy, national security, public safety, and uninterrupted provision of essential public services .
Major Discussion Point
Protection of Critical Infrastructure
Norms F, G, and H regarding safeguarding of critical infrastructure should be prioritised for focused deliberations in DTG1 – Focus on infrastructure norms (South Africa)
Arg. 2
Explanation
South Africa proposes that DTG1 focus its discussions on norms F, G, and H regarding the safeguarding of critical infrastructure and critical information infrastructure. This is presented as a practical step for focused deliberations, sharing of knowledge, lessons learned, and exchange of expertise.
Evidence
South Africa proposes a discussion on norms F, G, and H regarding the safeguarding of critical infrastructure and critical information infrastructure under DTG1 as a practical step for focused deliberations, sharing of knowledge, lessons learned, exchange of expertise, and efficient use of time allocated to the DTGs .
Destruction of critical information infrastructure often leads to breach of international humanitarian law; norms F, G, and H deserve close attention – CII and IHL linkage (Malawi)
Arg. 1
Explanation
Malawi acknowledges that DTG1 must pay close attention to norms F, G, and H, noting that destruction of critical information infrastructure most often leads to a breach of international humanitarian law because data is usually involved. Malawi has prioritised the implementation of norms relating to the protection of critical information infrastructure.
Evidence
Malawi acknowledges that the DTG has to pay close attention to norms F, G, and H, noting that destruction of critical information infrastructure does in most cases lead to the breach of international humanitarian law because data is usually involved . Malawi has prioritised the implementation of norms relating to the protection of critical information infrastructure through its Computer Emergency Response Team and Data Protection Authority .
Consensus has been the strength of the framework; implementation should become its legacy; the DTGs provide an opportunity to exchange practical experiences – Implementation as legacy (Malawi)
Arg. 2
Explanation
Malawi argues that consensus has been the strength of the normative framework and that implementation should become its legacy. The strength of the framework will not be measured by the number of additional norms developed but by the collective commitment to uphold those already agreed.
Evidence
Malawi states that consensus has been the strength of this framework and calls for implementation to become its legacy . Malawi considers the dedicated thematic groups an important opportunity for member states to exchange practical experiences, share lessons learned, and identify good practices that strengthen confidence and support the effective implementation of the framework .
Major Discussion Point
Implementation of Existing Voluntary Non-Binding Norms
121
WPM
586
Words
5 min
Time
Russia's cyber attacks have targeted Ukrainian energy, telecommunications, and public administration to undermine state resilience and amplify the effects of missile and drone attacks – Russian attacks on Ukrainian infrastructure (Ukraine)
Arg. 1
Explanation
Ukraine highlights its experience as a demonstration of why the norm on protection of critical infrastructure is indispensable. Russia's cyber attacks have targeted the energy sector, telecommunication networks, public administration systems, and transport infrastructure, with the purpose of undermining state resilience and amplifying the effects of missile and drone attacks.
Evidence
Ukraine states that Russia’s cyber attacks have targeted the energy sector, telecommunication networks, public administration systems, transport infrastructure, and other essential civilian services . Their purpose has been not merely to disrupt computer systems, but to undermine the resilience of the state, amplify the effects of missile and drone attacks, and inflict maximum hardship on the civilian population .
The UN Charter is legally binding yet does not prevent states from acting in breach; states should adhere to norms for progress, not fear of persecution – Binding law does not guarantee compliance (Ukraine)
Arg. 2
Explanation
Ukraine argues that some states suggest that if norms were legally binding, states would adhere to them with more dedication, but this is not necessarily the case. Ukraine points out that the UN Charter is an international legally binding document and does not prevent Russia from acting in breach of its provisions.
Evidence
Ukraine notes that some states insist on the voluntary nature of norms and suggest that legally binding norms would lead to greater adherence, but points out that the UN Charter is an international legally binding document and does not prevent Russia from acting in breach of its provisions . Ukraine states that the International Criminal Court is already taking important steps to hold relevant Russian criminals accountable, and that states should primarily adhere to norms for the purpose of progress and development, not due to fear of persecution .
Major Discussion Point
Development of Additional or Legally Binding Norms
Disagreed with
CubaIsraelPortugal
on: Whether legally binding cybersecurity instruments are desirable or premature
Thematic discussions should address risks to critical infrastructure from malicious use of AI by states, state-sponsored actors, and criminals – AI risks to infrastructure (Ukraine)
Arg. 3
Explanation
Ukraine believes that the global mechanism provides an important opportunity to move to implementation, and that thematic discussions should increasingly focus on practical measures that assist states in implementing the agreed norms. This includes discussions addressing the risk to critical infrastructures arising from the malicious use of artificial intelligence.
Evidence
Ukraine states that thematic discussions should address the risk to critical infrastructures arising from malicious use of artificial intelligence by states, state-sponsored actors, and criminals, as well as risks stemming from vulnerabilities in the supply chain, data poisoning, and the manipulation of AI systems .
Major Discussion Point
Role of Artificial Intelligence and Emerging Technologies in Cybersecurity
Ukraine alleges that Russia's cyber attacks have targeted Ukrainian critical infrastructure, including energy, telecommunications, public administration, and transport, with the purpose of undermining state resilience and amplifying the effects of conventional military attacks. Ukraine also highlights the growing convergence between state-sponsored cyber operations and cybercriminal ecosystems operating from Russian territory.
Evidence
Ukraine states that Russia’s cyber attacks have targeted the energy sector, telecommunication networks, public administration systems, transport infrastructure, and other essential civilian services, with the purpose of undermining state resilience and amplifying the effects of missile and drone attacks . Ukraine observes the growing convergence between state-sponsored cyber operations and cybercriminal ecosystems, with malicious actors operating from Russian territory, including ransomware groups, repeatedly targeting Ukraine and partner states while benefiting from a permissive environment .
Major Discussion Point
Geopolitical Tensions and Right of Reply Exchanges
Disagreed with
RomaniaIslamic Republic of IranIsraelRussian Federation
on: Attribution of specific hostile cyber activities and geopolitical responsibility for cyber attacks
130
WPM
713
Words
5 min
Time
There is no need to develop new norms before adequately addressing the compliance gap with the current framework; focus should be on strengthening implementation of existing voluntary norms – No new norms before compliance (Israel)
Arg. 1
Explanation
Israel argues that there is no need to develop or elaborate upon any new norms before adequately addressing the gap in compliance with the current framework. The reality of the current landscape demonstrates that the voluntary and non-binding norms established in 2015 are currently being flouted by certain states.
Evidence
Israel states that there is no need to develop or elaborate upon any new norms before adequately addressing the gap in compliance to the current framework, as the reality of the current landscape demonstrates that the voluntary and non-binding norms established in 2015 are currently being flouted by certain states . Israel also sees no need to develop legally binding instruments, arguing that pursuing such efforts without broad agreement on key concepts would waste the considerable diplomatic capital invested in the GMAC .
Major Discussion Point
Development of Additional or Legally Binding Norms
Disagreed with
PakistanBangladeshKenya ICT Action Network
on: Whether disinformation and misinformation should be treated as a core ICT security threat within the mechanism's scope
Pursuing legally binding instruments without broad agreement on key concepts would be premature and counterproductive; focus should remain on strengthening existing voluntary norms – Against premature binding instruments (Israel)
Arg. 2
Explanation
Israel argues that pursuing efforts to develop a legally binding instrument without broad agreement on key concepts would waste the considerable diplomatic capital invested in the GMAC and would be both premature and counterproductive. Israel believes the focus should remain on strengthening the implementation of existing voluntary norms.
Evidence
Israel states that pursuing efforts and attempting to develop a legally binding instrument without the underlining of broad agreement on key concepts would waste the considerable diplomatic capital invested in the GMAC as well as its potential, and that such an effort would be both premature and counterproductive . Israel believes the DTGs could provide a practical cross-cutting forum for sharing national best practices and evaluating whether and how the existing norms of responsible state behaviour are understood and applied .
Major Discussion Point
Development of Additional or Legally Binding Norms
Disagreed with
CubaPortugalUkraine
on: Whether legally binding cybersecurity instruments are desirable or premature
Iran has systematically violated international obligations, financed non-state proxies, and openly calls for the annihilation of Israel; it has no moral standing to invoke international law – Israeli response to Iran (Israel)
Arg. 3
Explanation
Israel argues that Iran has constantly and systematically violated every possible international obligation and norm, including by attacking civilian centres, holding international maritime navigation hostage, and financing non-state proxies. Israel contends that Iran has no moral standing to preach against others or invoke international law.
Evidence
Israel states that Iran has constantly and systematically violated every possible international obligation and norm, including by slaughtering tens of thousands of its own people, intentionally attacking civilian centres in Israel and other states, and intentionally holding international maritime and navigation hostage . Israel notes that the Iranian regime has also continued financing, training, and arming non-state proxies, including Hezbollah, Hamas, and the Houthis, spreading death and destruction across the Middle East . Israel states that the Iranian regime openly calls for the annihilation of Israel, which is unacceptable for a UN member state .
Major Discussion Point
Geopolitical Tensions and Right of Reply Exchanges
Disagreed with
RomaniaUkraineIslamic Republic of IranRussian Federation
on: Attribution of specific hostile cyber activities and geopolitical responsibility for cyber attacks
139
WPM
262
Words
2 min
Time
Ukraine has become a hub for hackers and online fraudsters acting with government support to damage Russian civilian infrastructure; Ukrainian officials have acknowledged carrying out attacks against Russia – Russian counter-allegations against Ukraine (Russian Federation)
Arg. 1
Explanation
The Russian Federation argues that Ukraine has become a hub for hackers and online fraudsters acting with government support, with the single goal of damaging Russian civilian infrastructure and defrauding Russian citizens. Russia contends that Ukrainian officials have repeatedly acknowledged and even bragged about carrying out attacks against Russia.
Evidence
Russia states that Ukraine has become a hub for hackers and online fraudsters acting with support of their own government with a single goal to damage Russian civilian infrastructure and defraud Russian citizens, and that officials of that country have repeatedly acknowledged and even bragged about carrying out these attacks against Russia . Russia also states that Ukraine has become the largest haven for online fraudsters in the world, with thousands of so-called call centres defrauding retirees and encouraging young people to carry out terrorist attacks in Russia .
Major Discussion Point
Geopolitical Tensions and Right of Reply Exchanges
118
WPM
2016
Words
17 min
Time
The threat landscape discussion revealed common themes including complexity, range of actors and tools, impact of emerging technologies, ransomware, critical infrastructure vulnerabilities, and supply chain security – Chair's synthesis of threat discussions
Arg. 1
Explanation
Chair López synthesised the substantive discussions on threats, identifying several recurring themes raised by delegations over two days. These included the evolving threat landscape, the impact of emerging technologies such as AI, the continued relevance of ransomware, specific vulnerabilities of critical infrastructure in sectors such as health and financial services, and the need to protect ICT supply chains.
Evidence
The Chair noted that common themes included the threat landscape including complexity, the number of actors, and the range of tools being used, as well as the impact of emerging technologies such as artificial intelligence . She also highlighted the continued relevance of threats such as ransomware, specific vulnerabilities of critical infrastructure mainly in areas such as health, education, public administration, financial services, and critical information infrastructure such as submarine cables . The Chair further noted that delegations indicated a need to protect supply chains for ICT services .
Delegations made concrete calls to action for the mechanism to move toward action-oriented decisions, including exchange of information on threats, cooperation, capacity building, incident response, and implementation of the responsible use framework – Chair's synthesis of calls to action
Arg. 2
Explanation
Chair López observed that many delegations emphasised the need for the mechanism to make progress and move to action-oriented decisions rather than remaining at the level of discussion. She noted concrete calls for exchange of information on threats, cooperation, capacity building, incident response, recovery, creation of resilience, and implementation of the responsible use framework.
Evidence
The Chair stated that she heard concrete calls to action and for concrete solutions, with many delegations emphasising the need for the mechanism to make progress and move to action-oriented decisions . She noted calls for exchange of information on threats, cooperation, capacity building, incident response, recovery, and the creation of resilience, as well as implementation of the responsible use framework .
Major Discussion Point
Role of the Global Mechanism and Dedicated Thematic Groups
Accredited interested parties may attend plenary sessions and make oral statements during sessions dedicated to interested parties, and may also deliver interventions after states subject to availability of time and Chair's discretion – Stakeholder participation modalities
Arg. 3
Explanation
Chair López clarified the modalities for stakeholder participation in the global mechanism, drawing on Annex 1 of A-80-257. She indicated her intention to give the floor to duly accredited entities to provide information on the agenda topic of existing and emerging threats, with a strict three-minute time limit.
Evidence
The Chair quoted from Annex 1 of A-80-257, stating that accredited interested parties may attend substantive plenary sessions and make oral statements during sessions dedicated to interested parties, and that it will also be possible to deliver interventions after states according to the availability of time and subject to the discretion of the Chair at standard plenary sessions . She indicated her intention to give the floor to duly accredited entities for three minutes, to be strictly enforced .
Major Discussion Point
Role of the Global Mechanism and Dedicated Thematic Groups
There is a great deal of common sentiment among delegations regarding the shift to implementation of norms; additional norms could also be considered given the evolving digital environment, and norms are interconnected with capacity building – Chair's synthesis of norms discussions
Arg. 4
Explanation
Chair López summarised the key themes from the norms discussion, noting a strong emphasis on shifting to implementation as a matter of major significance, particularly for small states. She also acknowledged calls for continued discussion on common understandings of how norms will be applied in practice, the importance of the implementation checklist, the possibility of developing additional norms given the evolving digital environment, and the interconnection of norms with capacity building.
Evidence
The Chair noted that there was an emphasis on shifting to implementation, which is of major significance for all states but especially for small ones given their realities and national circumstances . She also heard calls to continue discussion on common understandings of how norms will be applied in practice through the DTGs . The Chair acknowledged that a number of delegations mentioned the checklist for implementation and emphasised that additional norms could also be considered given the evolving nature of the digital environment . She also noted that many delegations highlighted the interconnection of norms with capacity building and development .
Major Discussion Point
Implementation of Existing Voluntary Non-Binding Norms
Delegations should avoid entering into political exchanges and focus on the agenda items before them, given the limited time available – Call for focused and constructive engagement
Arg. 5
Explanation
Chair López urged all delegations to bear in mind the limited time available and to focus on the agenda items rather than entering into political exchanges. She expressed the view that there are better ways of using the available time than engaging in such discussions.
Evidence
The Chair stated that she hoped all delegations would bear in mind that there is a very limited amount of time and that they should be focused on covering the agenda item before them . She indicated that there are ways of better using the time and not entering into these discussions, and asked all delegations to bear in mind that there is a lot to tackle .
Major Discussion Point
Role of the Global Mechanism and Dedicated Thematic Groups
Session Knowledge Graph
Speakers · Topics · Arguments · Relationships
Interactive graph · embed active
Agreed Points
Priority should be given to implementing the existing 11 voluntary non-binding norms rather than developing new ones at this stage
A broad coalition of states agreed that the primary task of the global mechanism should be implementing the existing 11 voluntary non-binding norms rather than developing new ones. The Pacific Islands Forum stated that ‘the priority must remain the implementation of the existing voluntary non-binding norms of responsible state behavior’ , with many states still building capacity to operationalise these commitments . The Republic of Korea stated that ‘our priority of global mechanism should be the effective implementation of existing commitments rather than the development of new norms at this stage’ . Vanuatu argued that ‘the task before us is observance, not expansion’ and that ‘the existing commitments have not yet been implemented by all states to a standard that would refill any genuine gap’ . Portugal stated that the mechanism was ‘deliberately meant to be more stable than its predecessors and more oriented towards implementation of the 11 voluntary norms’ than towards discussion of more norms or binding instruments . Israel argued there is ‘no need to develop or elaborate upon any new norms before we adequately address the gap in compliance to the current framework’ . Malawi called for ‘consensus has been the strength of this framework. Let implementation become legacy’ .
Implementation priority (Tonga on behalf of the Pacific Island Forum)
EU norms implementation contribution (European Union)
Checklist as living document (Republic of Korea)
Observance over expansion (Vanuatu)
Scenario-based implementation discussions (Nigeria)
Implementation over new norms (Portugal)
No new norms before compliance (Israel)
Existing norms sufficiency (Botswana)
Practical implementation focus (North Macedonia)
DTG guidance for implementation (New Zealand)
Implementation as legacy (Malawi)
Policy Context (Knowledge Base)
This position reflects a dominant strand in OEWG discussions, where multiple states and experts have argued for prioritising implementation of the existing 11 norms before developing new ones [S160][S161][S162]. The OEWG 2021-2025 annual report confirmed this as a central axis of debate [S166], and informal consultations on CBMs similarly identified implementation-first as a key position [S159].
Tonga on behalf of the Pacific Island ForumEuropean UnionRepublic of KoreaVanuatuNigeriaPortugalIsraelBotswanaIrelandNorth MacedoniaNew ZealandMalawi
The Voluntary Norms Implementation Checklist is a valuable tool that should be further developed and operationalised
Multiple delegations agreed that the Voluntary Norms Implementation Checklist developed by the OEWG is a valuable tool that should be further developed within the global mechanism. The Pacific Islands Forum described it as ‘a helpful step towards mainstreaming implementation’ but noted the need for ‘consolidated guidance, capacity support, and peer exchanges’ . The Republic of Korea stated it ‘should continue to serve as a living document’ with the global mechanism continuing discussions ‘with a view to its eventual finalization’ . Italy described the checklist as ‘a very precious tool for all member states’ . The Netherlands called for states to ‘endeavour to strengthen and operationalise the checklist and lay the basis for a voluntary instrument for self-reporting on the implementation of the 11 norms’ . Brazil welcomed ‘efforts to facilitate norms implementation, including the voluntary checklist of practical actions drafted within the OEWG which could be further developed in the context of this global mechanism’ .
Implementation priority (Tonga on behalf of the Pacific Island Forum)
EU norms implementation contribution (European Union)
Checklist as living document (Republic of Korea)
Systematic implementation needed (Italy)
Mutual expectations and self-reporting (Netherlands)
Practical implementation focus (North Macedonia)
Regional cooperation for implementation (Brazil)
Existing norms sufficiency (Botswana)
Policy Context (Knowledge Base)
Colombia explicitly highlighted checklist item 30C as a nationally useful tool for identifying implementation challenges [S154]. Japan and Singapore have advocated treating the checklist as a living document open to further development [S155], reflecting broad support for its operationalisation within the OEWG process [S153].
Tonga on behalf of the Pacific Island ForumEuropean UnionRepublic of KoreaItalyNetherlandsIrelandBrazilBotswanaIsrael
No single country can address cyber challenges alone; international cooperation and capacity building are essential, particularly for developing countries
A wide range of delegations agreed that no single country can address cyber challenges in isolation and that international cooperation and capacity building are essential, particularly for developing countries. Ghana stated that ‘no country can address these challenges alone’ and remained ‘committed to working with member states and all relevant stakeholders to strengthen international cooperation’ . Armenia noted that ‘given the transboundary nature of cyberspace, no state can effectively address these challenges alone’ and that ‘collective efforts are therefore essential’ . Nicaragua recognised that ‘no countries, especially in developing countries, can tackle these challenges in isolation’ . Pakistan framed cybersecurity as ‘not merely an IT challenge’ but ‘an economic, sovereign, and human security issue’ for developing nations . Botswana argued that ‘developing countries cannot effectively protect critical infrastructure, prevent cross-border cybercrime, or guarantee the integrity of their supply chains if they lack the underlying technical and institutional capacity to do so’ .
Collective action necessity (Ghana)
Capacity building for developing nations (Pakistan)
Evolving threat scale (Armenia)
Threats and coercive measures (Nicaragua)
Capacity building with gender focus (African Union Commission)
Capacity building centrality (Nigeria)
Capacity gap in developing countries (Botswana)
Policy Context (Knowledge Base)
This principle is well-established across multiple forums. The OEWG 2025 opening session underscored the growing need for international cooperation and capacity building for developing nations [S175], and IGF 2023 discussions similarly affirmed that no single country can tackle internet governance challenges alone [S176]. Capacity building for developing countries is also highlighted in the context of AI and critical infrastructure [S174].
GhanaPakistanArmeniaNicaraguaAfrican Union CommissionNigeriaBotswanaCosta Rica
The Dedicated Thematic Groups (DTGs) should serve as practical forums for sharing national experiences, exchanging best practices, and advancing implementation of the normative framework
A broad consensus emerged that the DTGs should serve as practical, action-oriented forums for advancing implementation of the normative framework. Romania stated that ‘the DTGs could play an important role in this respect, as the right venues for exchanging views and formulating recommendations on better implementing the existing normative framework’ . Armenia expressed confidence that ‘the dedicated thematic groups will facilitate focused and action-oriented discussions’ . Italy stated that ‘DTG1 can play a key role in facilitating a thorough discussion across the five pillars helping deepen the practical implementation of norms’ . Portugal strongly believed that ‘the two dedicated thematic groups, designed to address specific security challenges and to accelerate cybersecurity capacity building to confront them, have the potential to lead us towards action-oriented results’ . Nigeria welcomed the DTGs and supported ‘scenario-based discussions as an effective means of strengthening implementation, improving collective preparedness, and facilitating practical cooperation’ .
DTG role in norm implementation (Romania)
DTG2 for capacity building (Armenia)
Translating commitments to action (African Union Commission)
DTG1 and DTG2 roles (Italy)
Action-oriented DTGs (Portugal)
Scenario-based implementation discussions (Nigeria)
Mutual expectations and self-reporting (Netherlands)
Focus on infrastructure norms (South Africa)
Stakeholder participation in DTGs (Switzerland)
Policy Context (Knowledge Base)
The OEWG 9th substantive session discussions on Agenda Item 5 reflect the expectation that thematic groupings should facilitate practical norm implementation work, including through tools such as the checklist [S155][S153].
RomaniaArmeniaAfrican Union CommissionItalyPortugalNigeriaNetherlandsSouth AfricaSwitzerlandAlbania
Critical infrastructure, particularly in sectors such as health, energy, water, and financial services, requires special protection from ICT threats
Virtually all delegations agreed that critical infrastructure requires special protection from ICT threats. Ghana highlighted the damage to submarine cable 7-Gamma in 2024 and identified 13 critical information infrastructure sectors under its Cybersecurity Act . Pakistan called for ‘clear international commitments that critical infrastructure, especially healthcare, energy and water, must remain strictly off-limits during peace and conflict’ . Romania expressed ‘particular concern of the attacks targeting critical national infrastructure, democratic institutions, and democratic processes’ . The ICRC noted that ‘ICT operations can severely disable civilian infrastructure’ even without physical damage, causing ‘power outages, disruption to transport systems, banking, water supply and food production’ . Vanuatu highlighted that its ‘multi-hazard early warning network, emergency broadcast capability, systems for coordinating relief across 83 islands’ are assets that ‘stand between a natural hazard and a humanitarian catastrophe’ . Ukraine described Russia’s cyber attacks targeting ‘the energy sector, telecommunication networks, public administration systems, transport infrastructure and other essential civilian services’ .
Growing cyber threats to critical information infrastructure (Ghana)
Critical infrastructure off-limits norm (Pakistan)
Critical infrastructure attacks (Romania)
Submarine cable protection (Bangladesh)
Civilian infrastructure disruption (International Committee of the Red Cross)
African ICT threat landscape (African Union Commission)
National critical infrastructure legislation (South Africa)
CII and IHL linkage (Malawi)
Disaster infrastructure protection (Vanuatu)
Russian attacks on Ukrainian infrastructure (Ukraine)
Policy Context (Knowledge Base)
Protection of critical infrastructure is a core theme across OEWG sessions [S153] and is reinforced by IGF discussions on protecting internet infrastructure during crises [S161]. The Disarmament and International Security Committee has also affirmed that cyber operations against civilian infrastructure have real-world consequences requiring governance [S164].
GhanaPakistanRomaniaBangladeshInternational Committee of the Red CrossAfrican Union CommissionSouth AfricaMalawiVanuatuUkraine
Artificial intelligence presents both opportunities and new security challenges, including amplifying existing cyber threats and creating new risks
A wide range of delegations agreed that AI presents significant new security challenges while also offering opportunities. Ghana’s National Artificial Intelligence Strategy sought to ‘harness artificial intelligence to promote inclusive development while ensuring that its adoption is secure, responsible, and resilient’ . Pakistan noted that ‘AI-accelerated cyber warfare poses new challenges to international peace and security’ . Romania identified threats ‘amplified by the rapid development of AI models’ . The ICRC warned that ‘the growing use of artificial intelligence in ICT activities will increase their speed, scale, and potential for harm’ with risks of ‘indiscriminate attacks, incidental civilian harm, damage to critical civilian infrastructure, and uncontrolled escalation’ . Interpol stated that ‘the rapid development of AI is only supercharging this criminal supply chain, increasing the volume, speed, scale, and accessibility of cyberattacks’ . Switzerland called for thematic discussions to ‘address the risk to critical infrastructures arising from malicious use of artificial intelligence by states, state-sponsored actors and criminals’ .
Collective action necessity (Ghana)
AI and surveillance risks (Pakistan)
AI amplifying existing threats (Romania)
AI-enabled and ransomware threats (Bangladesh)
AI escalation risks in conflict (International Committee of the Red Cross)
AI and cybercrime (Interpol)
African ICT threat landscape (African Union Commission)
AI-enabled threats to human rights (Kenya ICT Action Network)
New AI norms needed (China)
Thematic discussions should address risks to critical infrastructure from malicious use of AI by states, state-sponsored actors, and criminals (Ukraine)
AI risks to infrastructure (Switzerland)
GhanaPakistanRomaniaBangladeshInternational Committee of the Red CrossInterpolAfrican Union CommissionKenya ICT Action NetworkChinaUkraineSwitzerland
The global mechanism should be inclusive, transparent, and consensus-based, building on the work of the GGE and OEWG processes
Multiple delegations agreed that the global mechanism should be inclusive, transparent, and consensus-based, building on prior work. Nicaragua welcomed the mechanism as ‘an opportunity for consolidating a permanent and transparent inclusive space where all can participate under conditions of equality’ . Armenia expressed confidence that ‘the global mechanism will provide an effective and inclusive platform for addressing ICT threats, fostering dialogue and strengthening international cooperation’ . Nigeria reaffirmed its ‘commitment to preserving the state-led, single-track, inclusive, transparent and consensus-based nature of this mechanism’ and noted that ‘consensus has consistently enabled progress in this process’ . Costa Rica stated that ‘the global mechanism must build on the accumulated body of work of the groups of governmental experts in the open-ended working groups’ and that ‘the goal is not to reopen previously reached consensuses’ . Brazil stated that the global mechanism should be ‘inclusive and therefore take place within this mechanism where the needs of all countries are duly taken into account’ .
Inclusive and equal participation (Nicaragua)
Inclusive platform for cooperation (Armenia)
Translating commitments to action (African Union Commission)
State-led consensus mechanism (Nigeria)
Norms operationalisation (Tonga on behalf of the Pacific Island Forum)
Both implementation and new norms possible (Brazil)
Policy Context (Knowledge Base)
The OEWG 2021-2025 process has consistently emphasised consensus-based, inclusive multilateral engagement [S171][S172]. The Chair’s framing of outcomes as ‘finely balanced packages’ reflects the managed consensus approach that has characterised the OEWG [S171].
NicaraguaArmeniaAfrican Union CommissionNigeriaTonga on behalf of the Pacific Island ForumBrazilCosta Rica
Ransomware represents a persistent and significant threat requiring cooperative international responses
Several delegations identified ransomware as a persistent and significant threat requiring cooperative international responses. Pakistan suggested that the global mechanism should focus dialogues on ‘practical issues affecting all regions, such as ransomware mitigation, critical infrastructure protection and de-escalation channels’ . Bangladesh noted ‘with concern the rising incidence of ransomware and denial of service attacks against government in services and platforms and the financial sector’ and supported ‘a comprehensive, cooperative international approach to ransomware’ . Interpol described cybercrime as ‘increasingly industrialized’ with ‘specialized actors offer malware as a service, rent malicious infrastructure’ . The African Union Commission noted that Africa faces ‘ransomware, online fraud, supply chain vulnerabilities’ as part of its evolving ICT threat landscape . The Chair synthesised these discussions, noting ‘the continued relevance of threats such as ransomware’ .
Democratising cyber diplomacy (Pakistan)
Rising cyber attack complexity (Romania)
AI-enabled and ransomware threats (Bangladesh)
Industrialised cybercrime (Interpol)
African ICT threat landscape (African Union Commission)
Chair's synthesis of threat discussions
PakistanRomaniaBangladeshInterpolAfrican Union CommissionChair Egriselda López
Similar Viewpoints
These three delegations shared a viewpoint that the current voluntary, non-binding normative framework is insufficient and that stronger, more binding obligations are needed, while also highlighting the negative impact of unilateral coercive measures on developing countries. Cuba reaffirmed its ‘position in favour of developing legally binding norms under the auspices of the United Nations’ and argued that ‘non-binding voluntary norms therefore only constitute an intermediary step towards achieving our goal’ . Iran argued that ‘recent developments further demonstrate why the continued elaboration of additional voluntary norms remains necessary’ and that ‘important gaps in the existing normative framework’ have been revealed . Nicaragua called for ‘an end to these illegal measures that are in breach of the principles of the Charter of the United Nations’ regarding unilateral coercive measures that ‘deepen the digital divide, weaken national capacity, make it difficult to protect critical infrastructure’ . Cuba similarly noted that ‘developing countries stand at a disadvantage in developing technical, technological and regulatory capacities and this disadvantage is further exacerbated when such countries suffer the impact of unilateral coercive measures’ .
EU member states and aligned countries shared a consistent viewpoint that the focus should be on implementing the existing 11 voluntary norms, with the DTGs serving as practical forums for this work, and that developing new binding instruments would be counterproductive. The EU reaffirmed ‘strong commitment to the full and effective implementation of the UN Framework of Responsible State Behaviour in Cyberspace’ and published an initial overview of implementation efforts . Romania stated that ‘the DTGs could play an important role in this respect, as the right venues for exchanging views and formulating recommendations on better implementing the existing normative framework’ . Ukraine argued that ‘the UN Charter is an international legally binding document and does not prevent, for example, Russia to act in breach of its provisions’ , countering arguments for binding instruments. Albania demonstrated how it has ‘practically implementing UN norms, rules, and principles of responsible state behavior in cyberspace’ through its Law on Cybersecurity . The Netherlands called for the checklist to be operationalised as ‘a voluntary instrument for self-reporting on the implementation of the 11 norms’ .
Pacific Island states shared a consistent viewpoint emphasising full implementation of existing norms as the priority, with particular attention to the specific vulnerabilities of small island developing states. The Pacific Islands Forum stated that ‘the priority must remain the implementation of the existing voluntary non-binding norms’ and that ‘many states, including small island developing states, are still building the capacity needed to operationalize these commitments’ . Vanuatu argued that ‘the task before us is observance, not expansion’ and highlighted that its ‘multi-hazard early warning network, emergency broadcast capability, systems for coordinating relief across 83 islands’ are critical assets . New Zealand reiterated ‘the message from the Pacific Islands Forum that the regional priority for now is fully implementing the existing norms’ and called for ‘further guidance and capacity building coordination to support implementation at the national level’ .
African states shared a consistent viewpoint that the focus should be on implementing existing norms, with capacity building as a central priority, and that the DTGs should focus on practical, action-oriented strategies. South Africa proposed ‘a discussion on norms F, G, and H regarding the safeguarding of critical infrastructure and critical information infrastructure under DTG1 as a practical step for focused deliberations’ . Malawi similarly acknowledged that ‘the DTG has to pay close attention to norms F, G, and H, noting that destruction of critical information infrastructure does in most cases lead to the breach of international humanitarian law’ . Nigeria stated that ‘capacity building remains indispensable to the effective implementation of the agreed framework’ and is ‘central to reducing vulnerabilities, narrowing the digital divide’ . The African Union Commission stated that ‘for Africa, practical implementation begins with capacity’ and that ‘capacity building must remain at the heart of this mechanism’ . Botswana emphasised that ‘developing countries cannot effectively protect critical infrastructure, prevent cross-border cybercrime, or guarantee the integrity of their supply chains if they lack the underlying technical and institutional capacity’ .
These delegations shared a viewpoint that while implementation of existing norms is important, the framework should remain open to developing additional norms over time in response to emerging challenges, particularly those related to AI and other new technologies. Brazil stated that ‘positions in favour of advancing the implementation of the existing norms and for the adoption of new ones are not in any way mutually exclusive’ . Morocco argued that ‘the list of norms should not be set in stone given the rapid evolution of threats and emergence of new technologies’ and that ‘our framework must be able to evolve’ . Armenia recognised that ‘the framework for responsible state behavior in cyberspace is dynamic and evolving’ and that ‘additional voluntary non-binding norms could be developed over time where appropriate, in response to emerging challenges’ . Thailand remained ‘open to discussions on the possible development of additional norms, rules, and principles of responsible state behavior in the use of ICTs, particularly in response to emerging threats’ . China argued that ‘we should develop new norms regarding’ AI’s impact on cybersecurity, data security, critical infrastructure protection, and supply chain security .
Non-state stakeholders shared a viewpoint emphasising the human dimension of cybersecurity, including the need for meaningful stakeholder participation, protection of vulnerable groups, and attention to the real-world impacts of ICT threats on civilians and communities. The Kenya ICT Action Network argued that ‘civil society acts as frontline defenders who monitor local harms and support victims on the ground’ and called for ‘meaningful multi-stakeholder participation’ . The Discover MUN Foundation called for ‘youth-serving organizations and youth capacity-building practitioners be recognized as important stakeholders’ and demanded that ‘member states nominate qualified youth capacity-building practitioners to the DTGs’ . The ICRC called upon member states to ‘work together towards reflecting the realities of today’s armed conflicts in their discussions and to identify practical measures to mitigate harm to affected’ populations .
These delegations shared a strong viewpoint that the global mechanism should focus exclusively on implementing existing norms rather than developing new or binding instruments, arguing that the current framework is sufficient and that compliance gaps must be addressed first. Israel stated there is ‘no need to develop or elaborate upon any new norms before we adequately address the gap in compliance to the current framework’ and that pursuing a legally binding instrument ‘would be both premature and counterproductive’ . Portugal argued that the mechanism was ‘deliberately meant to be more stable than its predecessors and more oriented towards implementation of the 11 voluntary norms of responsible state behavior already endorsed and of the applicable international law, than towards the discussion of even more norms or even more binding instruments’ . The Republic of Korea stated that ‘our priority of global mechanism should be the effective implementation of existing commitments rather than the development of new norms at this stage’ .
Unexpected Consensus
Despite significant disagreements about whether new norms should be developed, states from very different geopolitical positions converged on the value of the voluntary norms implementation checklist as a practical tool. Even Israel, which strongly opposed developing new norms, acknowledged that ‘such checklists provide that they are carefully revisited, considered, and redrafted as necessary, could serve as a voluntary tool for developing activities, common language, and understanding’ . The Republic of Korea called for it to ‘continue to serve as a living document’ , while the Netherlands called for it to be operationalised as ‘a voluntary instrument for self-reporting’ . This consensus is unexpected because it bridges the divide between states focused purely on implementation and those open to developing new frameworks, finding common ground in a practical tool that can evolve without requiring formal new norm development.
Both Ghana and Bangladesh, as developing countries from different regions with different geopolitical positions, converged on the specific vulnerability of submarine cables as deserving dedicated attention. Ghana highlighted ‘the damage to submarine cable 7-Gamma in 2024 and the resulting disruption to digital services’ as reinforcing ‘the importance of protecting such infrastructure as a strategic national asset’ . Bangladesh, ‘as a country whose international connectivity depends heavily on a limited number of submarine cables,’ attached ‘particular priority to the protection of submarine cables and other cross-border critical information infrastructure’ and saw ‘merit in dedicating confidence-building measures on this issue’ . The Chair also noted this in her synthesis, highlighting ‘critical information infrastructure such as subsidy cables’ . This specific convergence on submarine cable protection as a distinct priority is notable given the breadth of cybersecurity issues discussed.
States from diverse regions unexpectedly converged on the value of regional organisations’ norm implementation frameworks as models for the global mechanism. Thailand highlighted that ‘ASEAN, as the first regional organization to have adopted these cyberspace norms in principle, has finalized its Norm Implementation Checklist to support member states in translating norms into practices’ . New Zealand welcomed the ASEAN Norms Implementation Checklist as ‘a valuable point of reference not only for ASEAN, but for all states who want to implement the norms’ and looked ‘forward to the African Union finalising its guidelines on norms implementation’ . Brazil highlighted regional cooperation through ‘the OAS CISERT Americas, which has been instrumental in advancing the norms related to information sharing on threats and vulnerabilities’ and the ‘Mercosur Cybersecurity Commission’ . The African Union Commission noted the development of ‘AU Guidelines for the Implementation of the Norms of Responsible State Behavior in Cyberspace’ . The Netherlands cited ‘the ASEAN Voluntary Implementation Checklist’ as providing ‘the global mechanisms and state with valuable guidance and resources for putting the voluntary norms into practice’ . This cross-regional appreciation for each other’s implementation frameworks was an unexpected area of convergence.
States and civil society from different perspectives converged on disinformation as a significant ICT threat, which is somewhat unexpected given that this topic is often contested in UN cybersecurity forums. Pakistan argued that ‘disinformation and misinformation, both by states and non-state actors’ are among ‘potent threats affecting international ICT security environments’ and called for examining ‘how disinformation, including as part of cyber and hybrid warfare, contributes to the outbreak, escalation, and prolongation of armed conflict’ . Bangladesh expressed growing concern about ‘disinformation and defects generated through advanced technologies, which carry implications for both international security and social stability’ . Romania noted exposure to ‘cyber attacks as part of sophisticated hybrid and interference campaigns’ . The Kenya ICT Action Network highlighted that ‘AI-driven automated surveillance and deepfakes are weaponizing digital spaces to erode electoral integrity’ . This convergence across state and non-state actors on disinformation as a cybersecurity issue is notable given the sensitivity of this topic.
States and civil society from different regions unexpectedly converged on the importance of integrating gender equality and attention to vulnerable groups into cybersecurity frameworks. Brazil stated that ‘the promotion of gender equality is a key component to the adequate implementation of the norms’ and highlighted ‘policies that address the differentiated impact of cyber threats to women and other vulnerable groups’ as an important component of its national cybersecurity strategy . The African Union Commission called for capacity building to ‘ensure gender mainstreaming and youth employment to promote innovation on the continent’ . The Kenya ICT Action Network highlighted that AI-driven threats ‘disproportionately target women, persons with disabilities, minorities, and vulnerable groups forcibly out of public and civic life’ . This convergence across a state from the Global South, a regional organisation, and civil society on gender mainstreaming in cybersecurity is an unexpected area of consensus in what is typically a state-security-focused forum.
Overall Assessment
The discussions revealed a strong and broad consensus on several key issues: the need to prioritise implementation of the existing 11 voluntary non-binding norms over developing new ones; the value of the Voluntary Norms Implementation Checklist as a practical tool to be further developed; the importance of the DTGs as action-oriented forums for sharing best practices; the necessity of international cooperation and capacity building, particularly for developing countries; the critical importance of protecting critical infrastructure from ICT threats; and the significant security challenges posed by AI and other emerging technologies. There was also notable agreement on the value of regional organisations' norm implementation frameworks as models for the global mechanism. Areas of divergence included: whether new norms should be developed alongside implementation efforts (with Cuba, Iran, China, and others favouring new norm development while Israel, Portugal, Republic of Korea, and others opposed); whether legally binding instruments are needed (with Cuba strongly in favour and most Western states opposed); and the role of unilateral coercive measures in hindering developing countries' cybersecurity capacity (raised by Nicaragua and Cuba but not widely endorsed). Geopolitical tensions between Israel and Iran, and between Ukraine and Russia, also surfaced in right-of-reply exchanges, though these were largely kept separate from the substantive discussions.
Points of Difference
Whether to develop new/additional voluntary norms or focus exclusively on implementing existing ones
This is the central normative disagreement of the session. Cuba explicitly called for legally binding norms, arguing that voluntary norms ‘only constitute an intermediary step’ and that ‘the alarming statistics reveal that voluntary norms on their own are not enough’ . China called for new norms on AI, data security, critical infrastructure, and supply chain security . Iran argued the global mechanism has an explicit mandate to elaborate additional norms and that ‘recent developments further demonstrate why the continued elaboration of additional voluntary norms remains necessary’ , citing alleged unlawful cyber operations . Morocco argued the list of norms ‘should not be set in stone’ . In contrast, Israel stated there is ‘no need to develop or elaborate upon any new norms before we adequately address the gap in compliance to the current framework’ , and that pursuing legally binding instruments ‘would be both premature and counterproductive’ . Portugal argued the mechanism was ‘deliberately meant to be more stable than its predecessors and more oriented towards implementation of the 11 voluntary norms… than towards the discussion of even more norms or even more binding instruments’ . Vanuatu stated plainly that ‘the task before us is observance, not expansion’ . Brazil offered a middle position, arguing these are ‘not in any way mutually exclusive’ .
Case for legally binding norms (Cuba)
Additional norms should be developed regarding AI's impact on cybersecurity, data security, critical infrastructure protection, and supply chain security – New norms for emerging challenges (China)
Mandate for additional norms (Islamic Republic of Iran)
The list of norms should not be set in stone given rapid evolution of threats; the framework must be able to evolve and be enriched or clarified as necessary – Evolving normative framework (Morocco)
The framework is cumulative and evolving; additional voluntary non-binding norms could be developed over time in response to emerging challenges, guided by inclusiveness and consensus – Evolving framework with new norms (Armenia)
Brazil believes that advancing implementation of existing norms and adopting new ones are not mutually exclusive; the global mechanism can accommodate both with consensus – Both implementation and new norms possible (Brazil)
There is no need to develop new norms before adequately addressing the compliance gap with the current framework; focus should be on strengthening implementation of existing voluntary norms – No new norms before compliance (Israel)
The permanent mechanism was deliberately designed to be more oriented towards implementation of the 11 voluntary norms than towards discussion of more norms or binding instruments – Implementation over new norms (Portugal)
The global mechanism should focus on identifying practical ways to effectively implement the 11 voluntary non-binding norms; the voluntary checklist should continue as a living document – Checklist as living document (Republic of Korea)
The task before us is observance, not expansion; existing commitments have not yet been implemented by all states to a standard that would reveal any genuine gap – Observance over expansion (Vanuatu)
The 11 voluntary norms are sufficient to govern state conduct; DTGs should formulate concrete strategies for effective implementation using the UN Cyber Norms National Implementation Checklist – Existing norms sufficiency (Botswana)
Priority must remain the full implementation of the 11 agreed norms; the Voluntary Norms Implementation Checklist is a helpful step requiring consolidated guidance and capacity support – Implementation priority (Tonga on behalf of the Pacific Island Forum)
Policy Context (Knowledge Base)
This is identified as the central point of contention in OEWG norm discussions, with positions ranging from developing new norms, to implementing existing ones first, to pursuing both in parallel [S159][S166][S167]. The OEWG 2021-2025 annual report confirmed this division persists across sessions [S166].
CubaChinaIslamic Republic of IranMoroccoArmeniaBrazilIsraelPortugalRepublic of KoreaVanuatuBotswanaTonga on behalf of the Pacific Island Forum
Whether legally binding cybersecurity instruments are desirable or premature
Cuba explicitly advocated for ‘developing legally binding norms under the auspices of the United Nations’ , arguing that ‘a broad, legally binding instrument that establishes obligations with permanent monitoring would be, in our view, the most effective contribution’ . Israel countered that pursuing a legally binding instrument ‘without the underlining of broad agreement on key concepts would waste the considerable diplomatic capital invested in the GMAC’ and would be ‘both premature and counterproductive’ . Ukraine offered a pragmatic counter-argument, noting that ‘the UN Charter is an international legally binding document and does not prevent, for example, Russia to act in breach of its provisions’ , suggesting binding instruments do not guarantee compliance. Portugal reinforced this by noting the mechanism was deliberately designed to be implementation-oriented rather than focused on ‘even more binding instruments’ .
Case for legally binding norms (Cuba)
Pursuing legally binding instruments without broad agreement on key concepts would be premature and counterproductive; focus should remain on strengthening existing voluntary norms – Against premature binding instruments (Israel)
The permanent mechanism was deliberately designed to be more oriented towards implementation of the 11 voluntary norms than towards discussion of more norms or binding instruments – Implementation over new norms (Portugal)
The UN Charter is legally binding yet does not prevent states from acting in breach; states should adhere to norms for progress, not fear of persecution – Binding law does not guarantee compliance (Ukraine)
Policy Context (Knowledge Base)
IGF 2023 discussions included calls for a legally binding international cybersecurity instrument to complement existing international law [S158]. Academic analysis using a maturity model approach has examined the feasibility of binding instruments on cyberweapons, noting the inherently political nature of cyber statecraft [S165]. Doubts about the effectiveness of voluntary non-binding norms, particularly in the African context, have also fuelled this debate [S157].
CubaIsraelPortugalUkraine
Whether disinformation and misinformation should be treated as a core ICT security threat within the mechanism's scope
Pakistan argued strongly that disinformation and misinformation are ‘potent threats affecting international ICT security environments’ , contributing to ‘the outbreak and escalation of violence’ and obscuring ‘violations of international law, including international humanitarian law’ . Pakistan called for the mechanism to ‘examine how disinformation, including as part of cyber and hybrid warfare, contributes to the outbreak, escalation, and prolongation of armed conflict’ . Bangladesh similarly expressed concern about ‘disinformation and deepfakes generated through advanced technologies’ . The Kenya ICT Action Network highlighted AI-driven deepfakes ‘weaponizing digital spaces to erode electoral integrity’ . However, Israel’s position implicitly resisted expanding the scope of the mechanism beyond existing norms , and the right-of-reply exchanges between Israel and Iran illustrated how disinformation allegations can themselves become politically charged within the forum .
Disinformation and misinformation by state and non-state actors contribute to outbreak and escalation of violence, obscure violations of international law, and overwhelm information ecosystems – Disinformation as a threat (Pakistan)
AI-enabled threats and disinformation generated through advanced technologies carry implications for international security and social stability – AI disinformation threats (Bangladesh)
AI-driven automated surveillance and deepfakes weaponise digital spaces, eroding electoral integrity and enabling gender-based violence – AI-enabled threats to human rights (Kenya ICT Action Network)
There is no need to develop new norms before adequately addressing the compliance gap with the current framework; focus should be on strengthening implementation of existing voluntary norms – No new norms before compliance (Israel)
Policy Context (Knowledge Base)
The scope of the OEWG mandate under GA resolution 75/240 is the backdrop for this debate [S153][S156], with some states seeking to broaden the mechanism’s remit to include information influence operations while others resist expanding beyond traditional ICT security threats.
PakistanBangladeshKenya ICT Action NetworkIsrael
The role and scope of stakeholder participation in the global mechanism and its DTGs
Civil society actors such as the Kenya ICT Action Network urged ‘meaningful multi-stakeholder participation, because civil society acts as frontline defenders who monitor local harms and support victims on the ground’ . The Discover MUN Foundation demanded that ‘member states nominate qualified youth capacity-building practitioners to the DTGs’ . Switzerland argued that ‘broad and meaningful participation of stakeholders in the work of the global mechanism, in particular the DGTs, is not only necessary, but also to the advantage of all states’ . However, Nigeria reaffirmed its commitment to ‘preserving the state-led, single-track, inclusive, transparent and consensus-based nature of this mechanism’ , implicitly limiting the role of non-state actors. The Chair herself noted the modalities for stakeholder participation are governed by Annex 1 of A-80-257, with interventions by interested parties subject to availability of time and her discretion , and she encouraged delegations to participate in the dedicated stakeholder segment .
Civil society acts as frontline defenders monitoring local harms; meaningful multi-stakeholder participation is essential for the global mechanism to build genuine digital peace – Multi-stakeholder participation (Kenya ICT Action Network)
Youth-serving organisations and capacity-building practitioners should be recognised as important stakeholders; member states should nominate qualified youth practitioners to DTGs – Youth capacity building (Discover MUN Foundation)
Broad and meaningful participation of stakeholders in the DTGs is not only necessary but advantageous to all states; the Geneva Dialogue demonstrates this – Stakeholder participation in DTGs (Switzerland)
The global mechanism should remain state-led, single-track, inclusive, transparent, and consensus-based; consensus should continue to guide collective efforts – State-led consensus mechanism (Nigeria)
The mechanism represents an opportunity for a permanent, transparent, inclusive space where all can participate under conditions of equality – Inclusive and equal participation (Nicaragua)
Kenya ICT Action NetworkDiscover MUN FoundationSwitzerlandNigeriaNicaragua
Whether unilateral coercive measures constitute a legitimate cybersecurity concern within the mechanism
Nicaragua argued that ‘the application of unilateral coercive measures has a direct impact on developing ICTs’ , that ‘these measures deepen the digital divide, they weaken national capacity, they make it difficult to protect critical infrastructure’ , and called for ‘an end to these illegal measures that are in breach of the principles of the Charter of the United Nations’ . Cuba similarly noted that ‘developing countries stand at a disadvantage in developing technical, technological and regulatory capacities and this disadvantage is further exacerbated when such countries suffer the impact of unilateral coercive measures’ . Iran referenced ‘the use of ICTs for unilateral coercive measures’ as an area requiring further normative development . These positions were not directly rebutted in the session but implicitly contested by Western states that focused exclusively on state-sponsored cyber attacks and norm implementation without acknowledging sanctions as a cybersecurity issue.
Unilateral coercive measures have a direct impact on developing countries' ICT capacity, deepen the digital divide, and impede the right to development – Coercive measures harm development (Nicaragua)
Case for legally binding norms (Cuba)
Parallel norm development and implementation (Islamic Republic of Iran)
NicaraguaCubaIslamic Republic of Iran
Attribution of specific hostile cyber activities and geopolitical responsibility for cyber attacks
Romania condemned ‘hostile cyber activities, conducted by groups controlled by the Russian Federation’ , describing ‘a well-established pattern characterized by the use of a complex cyber ecosystem comprises both state institutions and non-state entities’ . Ukraine detailed how ‘Russia’s cyber attacks have targeted the energy sector, telecommunication networks, public administration systems, transport infrastructure’ to ‘undermine the resilience of the state, amplify the effects of missile and drone attacks’ . Russia countered that ‘Ukraine has become a hub for hackers and online fraudsters acting with support of their own government’ and that Ukrainian officials ‘have repeatedly acknowledged and even bragged about carrying out these attacks against Russia’ . Iran alleged that ‘recent unlawful cyber operations carried out by the United States and the Israeli regime… targeted critical infrastructure and essential civilian services’ . Israel responded by accusing Iran of ‘constantly and systematically violat[ing] every possible international obligation and norm’ and having ‘no moral standing whatsoever to preach against others’ . These exchanges prompted the Chair to urge delegations to ‘be focused on covering the agenda item before us’ .
Attacks targeting critical national infrastructure, democratic institutions, and democratic processes are of particular concern; hostile cyber activities by Russian-controlled groups condemned – Critical infrastructure attacks (Romania)
Russian attacks on Ukrainian infrastructure (Ukraine)
Ukrainian allegations against Russia (Ukraine)
Recent unlawful cyber operations by the United States and the Israeli regime targeted Iranian critical infrastructure, exploited ICT supply chains, and integrated cyber capabilities with military operations – Iranian allegations against Israel and US (Islamic Republic of Iran)
Iran has systematically violated international obligations, financed non-state proxies, and openly calls for the annihilation of Israel; it has no moral standing to invoke international law – Israeli response to Iran (Israel)
Russian counter-allegations against Ukraine (Russian Federation)
Policy Context (Knowledge Base)
Iran’s plenary statement alleging that the United States and Israel conducted unlawful cyber operations against its critical infrastructure, including over 100 attacks during a single period of aggression, illustrates the acute geopolitical dimension of attribution disputes within the OEWG [S163]. The Disarmament and International Security Committee has affirmed that cyber operations are real acts with real consequences that must be governed [S164].
RomaniaUkraineIslamic Republic of IranIsraelRussian Federation
Whether the balance between developing new norms and implementing existing ones has been properly maintained in the mechanism's work
Iran argued that ‘throughout the OEWG process, many delegations consistently emphasized that the future development of additional norms and the implementation of existing norms are complementary objectives that should proceed in parallel’ but that ‘this balance has not been maintained’ . Iran proposed that ‘negotiations on the proposed voluntary checklist of practical actions for the implementation of voluntary non-binding norms should proceed alongside a structured process for the elaboration of additional norms’ . In contrast, Israel, Portugal, the Pacific Islands Forum, and the Republic of Korea all emphasised that the priority should be implementation of existing norms, with Portugal noting the mechanism was ‘deliberately meant to be more stable than its predecessors and more oriented towards implementation’ , and the Republic of Korea stating that ‘our priority of global mechanism should be the effective implementation of existing commitments rather than the development of new norms at this stage’ .
Parallel norm development and implementation (Islamic Republic of Iran)
No new norms before compliance (Israel)
Implementation over new norms (Portugal)
Priority must remain the full implementation of the 11 agreed norms; the Voluntary Norms Implementation Checklist is a helpful step requiring consolidated guidance and capacity support – Implementation priority (Tonga on behalf of the Pacific Island Forum)
The global mechanism should focus on identifying practical ways to effectively implement the 11 voluntary non-binding norms; the voluntary checklist should continue as a living document – Checklist as living document (Republic of Korea)
Policy Context (Knowledge Base)
The OEWG 2021-2025 process has consistently grappled with this balance, with the annual report and informal consultations both identifying it as unresolved [S166][S159]. The EU and other delegations have raised concerns about this balance in plenary [S167].
Islamic Republic of IranIsraelPortugalTonga on behalf of the Pacific Island ForumRepublic of Korea
Unexpected Differences
While geopolitical tensions are not unexpected in UN forums, the degree to which right-of-reply exchanges between Israel and Iran, and between Russia and Ukraine, consumed time in a technical cybersecurity session was notable. Israel requested the floor to respond to ‘the stunning hypocrisy of the Iranian regime’s statements about international law and aggression’ , making allegations about Iran’s conduct that went well beyond ICT security . Iran responded by accusing Israel of ‘two unlawful acts of aggression against Iran’ and characterising resistance groups as ‘legitimate resistance movements’ under UN General Assembly Resolution 46-51 . Russia used its right of reply to accuse Ukraine of being ‘a hub for hackers and online fraudsters acting with support of their own government’ . The Chair was forced to intervene twice, noting ‘we have a very limited amount of time and that we should be focused on covering the agenda item before us’ and that ‘there are ways of better using our time and not entering into these discussions’ . This was unexpected in a session ostensibly focused on technical cybersecurity norms and threat discussions, and the Chair’s visible difficulty in containing these exchanges highlighted a structural tension in the mechanism between geopolitical disputes and technical norm-setting.
Iran made an unexpected argument that its references to alleged Israeli and US cyber operations against Iran were not politicising the discussion but were ‘a clear illustration of the very malicious ICT activities that these processes seek to prevent and address, thereby assisting member states in deepening their discussions and informing the work of the global mechanism’ . This reframing attempted to legitimise geopolitical allegations as substantive contributions to the norm-development discussion. Iran used these alleged operations to argue for gaps in the existing normative framework and to call for new norms on data security, accountability of private sector entities, and the use of ICTs for unilateral coercive measures . Israel characterised this as Iran being ‘adamant to impudently waste our time’ and showing ‘Iran’s determination to disregard the international community’ . The Chair’s response was to urge brevity and focus , without explicitly ruling on whether such references were in or out of scope, creating an unresolved procedural ambiguity.
While most speakers agreed the checklist is valuable, an unexpected nuance emerged regarding its status and future. The Republic of Korea called for it to ‘continue to serve as a living document’ with discussions continuing ‘with a view to its eventual finalization’ , suggesting it is not yet finalised. South Africa called for ‘finalizing the voluntary checklist in accordance with paragraph 38 of the OEWG 2021-2025 final report’ , implying a specific mandate to complete it. Italy described it as ‘a very precious tool’ and hoped the mechanism could promote ‘a discussion on its finalization’ . The Netherlands called for it to be ‘strengthened and operationalised’ as ‘a voluntary instrument for self-reporting’ , suggesting a more ambitious evolution. Iran, however, argued that ‘negotiations on the proposed voluntary checklist… should proceed alongside a structured process for the elaboration of additional norms’ , effectively conditioning checklist work on parallel new norm development. This created an unexpected procedural disagreement about whether checklist finalisation is a standalone priority or must be linked to new norm elaboration.
An unexpected area of implicit disagreement emerged around the accountability of private sector entities in the ICT environment. Iran explicitly called for new norms on ‘the accountability of private sector entities operating in ICT environment’ . The ICRC highlighted that ‘technology companies provide much of the ICT infrastructure assets and services to civilian populations’ but ‘also provide similar assets and services to parties to armed conflicts’ , raising questions about their responsibilities under IHL. Pakistan noted that ‘commercial hardware, cloud infrastructure, and software tools have been repurposed for military or intelligence operations making non-proliferation and oversight exceptionally challenging’ and that ‘sophisticated surveillance tools sold to state and non-state actors are frequently used without safeguards or oversight’ . Switzerland argued for meaningful stakeholder participation including the private sector , but framed this as a contribution to implementation rather than as a subject of accountability norms. Most other delegations did not address private sector accountability directly, leaving this as an emerging but unresolved tension in the normative framework.
Overall Assessment
The session revealed a moderate-to-high level of disagreement on several fundamental questions, despite broad surface-level consensus on the importance of cybersecurity and the value of the existing normative framework. The primary fault lines were: (1) whether to develop new or legally binding norms versus focusing exclusively on implementing existing ones ; (2) attribution of specific hostile cyber activities and the geopolitical exchanges this generated ; (3) the role of unilateral coercive measures as a cybersecurity concern ; (4) the scope and depth of stakeholder participation ; and (5) the status and future of the Voluntary Norms Implementation Checklist . There was genuine consensus on the evolving threat landscape , the importance of capacity building for developing countries , the value of the DTGs as implementation forums , and the centrality of critical infrastructure protection . The Chair’s synthesis noted ‘a great deal of common sentiment as regards implementation’ but acknowledged the divergence on additional norms .
All speakers agreed that the ICT threat landscape is evolving rapidly and poses serious risks to states, critical infrastructure, and international stability . They shared concern about ransomware, AI-enabled threats, attacks on critical infrastructure, and the growing sophistication of malicious actors. However, they disagreed on the causes, attribution, and appropriate responses. Nicaragua and Cuba linked threats to unilateral coercive measures , while Western states focused on state-sponsored attacks by specific actors such as Russia . The ICRC focused on the humanitarian dimension of ICT threats in armed conflict , while Interpol emphasised the criminal dimension . Pakistan highlighted disinformation as a core threat , while others focused more narrowly on technical cyber attacks.
Agreed
GhanaPakistanRomaniaArmeniaBangladeshInternational Committee of the Red CrossInterpolAfrican Union CommissionNicaragua
Contested
Growing cyber threats to critical information infrastructure, including submarine cables, with 13 CII sectors identified nationally – Critical infrastructure vulnerability (Ghana) Cyber threats have evolved from localised IT risks into major geopolitical tools; militarisation of cyberspace is underway with states deploying cyber instruments for espionage and sabotage – Geopolitical cyber threats (Pakistan) Significant increase in number, complexity, and persistence of cyber attacks, including phishing, ransomware, and hybrid interference campaigns – Rising cyber attack complexity (Romania) ICT-related threats continue to evolve in scale, sophistication, and frequency, posing risks to states, critical infrastructure, and international stability – Evolving threat scale (Armenia) Particular concern over ransomware, denial-of-service attacks, and AI-enabled threats with implications for international security and social stability – AI-enabled and ransomware threats (Bangladesh) ICT operations during armed conflict disable essential civilian services, target medical facilities, recruit children, and involve civilian hackers who ignore IHL limits – ICT threats in armed conflict (International Committee of the Red Cross) Cybercrime has become one of the world’s most significant illicit economies, increasingly industrialised, with AI supercharging criminal supply chains – Industrialised cybercrime (Interpol) Africa faces ransomware, online fraud, supply chain vulnerabilities, and growing AI security challenges targeting critical infrastructure – African ICT threat landscape (African Union Commission) ICT threats are developing swiftly and can impact national security, critical infrastructure, and essential services; unilateral coercive measures deepen the digital divide and weaken national capacity – Threats and coercive measures (Nicaragua)
All speakers agreed that international cooperation and capacity building are essential, particularly for developing countries . They shared the view that the digital divide creates asymmetries in cybersecurity capacity that must be addressed. However, they disagreed on the mechanisms and priorities: some emphasised technical capacity building through DTG2 , others stressed the need to address unilateral coercive measures that impede capacity development , and others focused on gender mainstreaming and youth inclusion . The African Union Commission and Botswana emphasised that for developing countries, capacity building is the prerequisite for any norm implementation , while Western states tended to frame capacity building as complementary to norm implementation rather than as its precondition.
Agreed
GhanaPakistanArmeniaBangladeshAfrican Union CommissionBotswanaNigeriaCosta RicaTonga on behalf of the Pacific Island Forum
Contested
No country can address cyber challenges alone; international cooperation and capacity building are essential for developing countries to tackle threats from malicious use of ICTs – Collective action necessity (Ghana) Cybersecurity for developing nations is an economic, sovereign, and human security issue; implementation requires operational communication channels and targeted capacity building – Capacity building for developing nations (Pakistan) The DTG dedicated to accelerating ICT security capacity building will play a vital role in identifying needs, facilitating partnerships, and strengthening capacities of all states – DTG2 for capacity building (Armenia) Submarine cables and cross-border critical information infrastructure deserve particular priority and dedicated confidence-building measures – Submarine cable protection (Bangladesh) Capacity building must remain at the heart of the mechanism and should ensure gender mainstreaming and youth employment to promote innovation – Capacity building with gender focus (African Union Commission) Developing countries cannot effectively protect critical infrastructure or prevent cybercrime without underlying technical and institutional capacity; DTGs should formulate concrete strategies – Capacity gap in developing countries (Botswana) Capacity building is indispensable to effective implementation of the agreed framework; it is central to reducing vulnerabilities and narrowing the digital divide – Capacity building centrality (Nigeria) Due diligence should be approached as both a responsibility and an agenda for cooperation, technical assistance, and institutional capacity building – Due diligence and cooperation (Costa Rica) Priority must remain the full implementation of the 11 agreed norms; the Voluntary Norms Implementation Checklist is a helpful step requiring consolidated guidance and capacity support – Implementation priority (Tonga on behalf of the Pacific Island Forum)
The large majority of speakers agreed that implementing the existing 11 voluntary non-binding norms should be the primary focus of the global mechanism . They agreed that the voluntary checklist is a useful tool and that the DTGs provide the right forum for practical implementation discussions . However, they disagreed on whether this focus on implementation should preclude or delay the development of additional norms, with some states (Cuba, China, Iran, Morocco, Armenia, Brazil) leaving open the possibility of new norms , while others (Israel, Portugal, Vanuatu, Republic of Korea) argued implementation should come first and exclusively .
Agreed
Tonga on behalf of the Pacific Island ForumEuropean UnionCosta RicaColombiaSouth AfricaMalawiBrazilItalyRepublic of KoreaVanuatuNigeriaNetherlandsNew ZealandIrelandNorth MacedoniaAlbaniaBotswanaThailandSwitzerland
Contested
Priority must remain the full implementation of the 11 agreed norms; the Voluntary Norms Implementation Checklist is a helpful step requiring consolidated guidance and capacity support – Implementation priority (Tonga on behalf of the Pacific Island Forum) The 11 non-binding voluntary norms constitute a central pillar; the EU published an initial overview of implementation efforts using the 2021 GGE norms guidance – EU norms implementation contribution (European Union) Voluntary norms complement international law by offering practical guidance to foster transparency, predictability, restraint, and trust; implementation must translate into public policies and communication channels – Norms as complement to law (Costa Rica) The principal challenge is not absence of norms but effective implementation; states should voluntarily publish national positions on interpretation and application of specific norms – Implementation gap challenge (Colombia) Norms F, G, and H regarding safeguarding of critical infrastructure should be prioritised for focused deliberations in DTG1 – Focus on infrastructure norms (South Africa) Consensus has been the strength of the framework; implementation should become its legacy; the DTGs provide an opportunity to exchange practical experiences – Implementation as legacy (Malawi) The existing norms have guided Brazil’s national cybersecurity strategy; regional cooperation through OAS and Mercosur has been particularly relevant for norms implementation – Regional cooperation for implementation (Brazil) Priority should be given to supporting states in translating agreed norms into national policies, institutional procedures, and operational practices – Translating norms to practice (Italy) The global mechanism should focus on identifying practical ways to effectively implement the 11 voluntary non-binding norms; the voluntary checklist should continue as a living document – Checklist as living document (Republic of Korea) The task before us is observance, not expansion; existing commitments have not yet been implemented by all states to a standard that would reveal any genuine gap – Observance over expansion (Vanuatu) Nigeria supports scenario-based discussions as an effective means of strengthening implementation, improving collective preparedness, and facilitating practical cooperation – Scenario-based implementation discussions (Nigeria) The 11 norms confer mutual expectations on states; the voluntary checklist should be strengthened and operationalised as a voluntary instrument for self-reporting – Mutual expectations and self-reporting (Netherlands) The global mechanism should support implementation through guidance and capacity building coordination; DTGs could share experience on best practice through specific scenarios – DTG guidance for implementation (New Zealand) The global mechanism should remain practical and implementation-oriented; thematic discussions provide opportunity to exchange national experiences and good practices – Practical implementation focus (North Macedonia) Implementation of agreed norms is essential; Albania has enacted cybersecurity legislation transposing EU directives and operationalised national cybersecurity structures – National legislative implementation (Albania) The 11 voluntary norms are sufficient to govern state conduct; DTGs should formulate concrete strategies for effective implementation using the UN Cyber Norms National Implementation Checklist – Existing norms sufficiency (Botswana) Thailand has integrated norms into its National Policy and Action Plan on Cybersecurity; ASEAN has finalised its Norm Implementation Checklist to support member states – Regional norm integration (Thailand) The Geneva Manual, produced through multi-stakeholder dialogue, maps roles and responsibilities in implementing voluntary norms and ensuring security and stability of cyberspace – Multi-stakeholder norms implementation (Switzerland)
All these speakers agreed that critical infrastructure protection is a priority concern and that norms protecting critical infrastructure must be strengthened and implemented . They agreed on the goal of protecting critical infrastructure but disagreed on the scope and framing: Pakistan called for critical infrastructure to be 'strictly off-limits during peace and conflict' , the ICRC emphasised the humanitarian law dimension , Ukraine focused on Russian attacks as a concrete example , South Africa and Malawi proposed focusing specifically on norms F, G, and H , and Vanuatu uniquely highlighted disaster preparedness infrastructure as falling within the norms' protection .
Agreed
International Committee of the Red CrossPakistanRomaniaUkraineSouth AfricaMalawiVanuatu
Contested
ICT operations can severely disable civilian infrastructure even without physical damage, causing power outages, disruption to transport, banking, water, and food production – Civilian infrastructure disruption (International Committee of the Red Cross) States must commit to keeping critical infrastructure, especially healthcare, energy, and water, strictly off-limits during peace and conflict – Critical infrastructure off-limits norm (Pakistan) Attacks targeting critical national infrastructure, democratic institutions, and democratic processes are of particular concern; hostile cyber activities by Russian-controlled groups condemned – Critical infrastructure attacks (Romania) Russia’s cyber attacks have targeted Ukrainian energy, telecommunications, and public administration to undermine state resilience and amplify the effects of missile and drone attacks – Russian attacks on Ukrainian infrastructure (Ukraine) Norms F, G, and H regarding safeguarding of critical infrastructure should be prioritised for focused deliberations in DTG1 – Focus on infrastructure norms (South Africa) Destruction of critical information infrastructure often leads to breach of international humanitarian law; norms F, G, and H deserve close attention – CII and IHL linkage (Malawi) Disaster preparedness infrastructure such as early warning networks and emergency broadcast systems falls squarely within the protection these norms describe – Disaster infrastructure protection (Vanuatu)
All speakers agreed that AI poses significant and growing risks to cybersecurity . They shared concern about AI amplifying existing threats, enabling new attack vectors, and creating risks of escalation. However, they disagreed on the appropriate response: China called for new norms specifically on AI , the ICRC focused on AI's implications for IHL compliance in armed conflict , Interpol emphasised AI's role in supercharging criminal supply chains , Pakistan highlighted AI-accelerated cyber warfare and surveillance tools , and Ukraine and Switzerland called for thematic discussions on AI risks to critical infrastructure . The Discover MUN Foundation uniquely focused on AI literacy and youth preparedness .
Agreed
GhanaRomaniaPakistanBangladeshInternational Committee of the Red CrossInterpolAfrican Union CommissionUkraineSwitzerland
Contested
Growing cyber threats to critical information infrastructure, including submarine cables, with 13 CII sectors identified nationally – Critical infrastructure vulnerability (Ghana) Rapid development of AI amplifies persistent threats such as phishing, ransomware, and cyber fraud – AI amplifying existing threats (Romania) AI-accelerated cyber warfare poses new challenges; sophisticated surveillance tools sold without safeguards – AI and surveillance risks (Pakistan) AI-enabled threats and disinformation generated through advanced technologies carry implications for international security and social stability – AI disinformation threats (Bangladesh) Growing use of AI in ICT activities will increase speed, scale, and potential for harm, raising risks of indiscriminate attacks and uncontrolled escalation – AI escalation risks in conflict (International Committee of the Red Cross) AI is supercharging criminal supply chains, increasing volume, speed, scale, and accessibility of cyberattacks – AI and cybercrime (Interpol) Africa faces ransomware, online fraud, supply chain vulnerabilities, and growing AI security challenges targeting critical infrastructure – African ICT threat landscape (African Union Commission) Thematic discussions should address risks to critical infrastructure from malicious use of AI by states, state-sponsored actors, and criminals – AI risks to infrastructure (Ukraine) Thematic discussions should address risks to critical infrastructure from malicious use of AI by states, state-sponsored actors, and criminals – AI risks to infrastructure (Ukraine)
Key Takeaways
The ICT threat landscape is rapidly evolving, with cyber threats having transformed from localised IT risks into major geopolitical tools capable of disrupting global stability, targeting critical infrastructure, and being integrated with conventional military operations.
There is broad consensus that the 11 voluntary non-binding norms of responsible state behaviour, first agreed in the 2015 GGE report, remain the foundational framework for international cyber stability, and that the primary challenge is effective implementation rather than the absence of norms.
Critical information infrastructure — including energy, health, water, transport, financial services, and submarine cables — is a priority area of concern, with many delegations calling for these assets to be strictly off-limits from malicious ICT activity during both peace and conflict.
Artificial intelligence and other emerging technologies present both significant opportunities and serious security challenges, amplifying existing threats such as phishing and ransomware, enabling disinformation and deepfakes, and raising risks of indiscriminate attacks and uncontrolled escalation in armed conflict.
Cybercrime has become one of the world’s most significant illicit economies, increasingly industrialised, with criminal ecosystems now providing malware-as-a-service and other tools that can be exploited by a broad range of malicious actors, including state-sponsored actors.
Capacity building is widely regarded as indispensable to the effective implementation of the agreed normative framework, particularly for developing countries, which face structural disadvantages in technical, technological, and regulatory capacity.
The Dedicated Thematic Groups (DTGs) are seen as the primary vehicles for translating agreed commitments into practical, action-oriented outcomes, with DTG1 focusing on specific security challenges and DTG2 on accelerating ICT security capacity building.
The Voluntary Norms Implementation Checklist, developed during the OEWG process, is broadly welcomed as a useful living document and practical tool, with many delegations calling for its further development and operationalisation within the global mechanism.
There is a significant divide between states that consider the existing 11 voluntary norms sufficient and those that argue for the development of additional norms or legally binding instruments, though some delegations suggest these objectives are not mutually exclusive.
Geopolitical tensions — particularly between Israel and Iran, and between Russia and Ukraine — were explicitly raised during the session, with right-of-reply exchanges reflecting deep disagreements over alleged malicious ICT activities and violations of international law.
Disinformation and misinformation, including as components of hybrid warfare, are recognised as serious threats that contribute to the outbreak and escalation of armed conflict and undermine international humanitarian law.
The protection of humanitarian organisations, medical facilities, and civilian populations from ICT operations during armed conflict is a pressing concern, with the ICRC highlighting the growing involvement of civilian hackers and the recruitment of children through digital platforms.
Multi-stakeholder participation — including civil society, the private sector, academia, and international organisations such as Interpol and the ICRC — is considered essential to the effective functioning of the global mechanism, though the modalities of such participation remain subject to ongoing discussion.
Regional organisations, including the African Union, ASEAN, the Pacific Islands Forum, and the OAS, are playing an increasingly important role in supporting norms implementation and capacity building at the continental and regional levels.
Gender equality, youth inclusion, and the differentiated impact of cyber threats on vulnerable groups are identified as important cross-cutting considerations for the implementation of the normative framework.
Resolutions & Action Items
The Chair summarised common themes from the threats discussion, noting the complexity of the threat landscape, the impact of emerging technologies, the continued relevance of ransomware, the specific vulnerabilities of critical infrastructure, and the need for supply chain protection, to inform the development of the framework pillars.
The Chair indicated that the global mechanism would proceed to the next agenda item — the continued study of how international law applies to the use of ICTs, including consideration of whether gaps exist and the possible future elaboration of additional legally binding obligations — at the following day’s session at 10:00.
The Chair confirmed that a dedicated stakeholder segment would be held the following afternoon at 15:00, and encouraged delegations to participate actively.
The EU published a non-paper detailing its member states’ implementation of the 11 voluntary norms using the 2021 GGE norms guidance, which was cited by multiple delegations as a model for how states could share implementation experiences.
South Africa proposed that DTG1 prioritise focused deliberations on norms F, G, and H regarding the safeguarding of critical infrastructure and critical information infrastructure, as a practical step for knowledge sharing and efficient use of DTG time.
Multiple delegations, including the Republic of Korea, the Netherlands, Italy, Ireland, and New Zealand, called for the Voluntary Norms Implementation Checklist to be treated as a living document and further developed within the global mechanism.
Iran proposed that the Chair prepare an initial consolidated draft compiling proposals for additional rules, norms, and principles submitted by member states, drawing from the Annex to the first OEWG Chair Summary, to provide a basis for structured discussions in plenary and DTGs.
Interpol reported on Operation Synergy F3, which brought together more than 70 countries, resulting in close to 100 arrests and the takedown of approximately 45,000 malicious infrastructure items, as an example of operational international cooperation.
Ukraine indicated it would exercise its right of reply at the following day’s session rather than extending the current meeting.
The Chair reminded delegations that the global mechanism would reconvene the following morning at 10:00 in the same room.
Unresolved Issues
Whether the global mechanism should prioritise the implementation of existing voluntary non-binding norms or proceed in parallel with the elaboration of additional norms, as envisaged in the mechanism’s mandate, remains a significant point of contention among member states.
The question of whether legally binding instruments should eventually be developed to complement or replace voluntary norms is unresolved, with Cuba and others advocating for binding obligations while many Western and Pacific states argue this would be premature or counterproductive.
The modalities for meaningful multi-stakeholder participation in the global mechanism, including the DTGs, remain an outstanding issue, with the Chair noting that consultations towards a pragmatic solution are ongoing.
The extent to which disinformation and misinformation — including as components of hybrid and cyber warfare — should be addressed within the normative framework of the global mechanism has not been resolved.
How the due diligence norm should be interpreted and applied in practice, particularly for states at different levels of development and capacity, remains a subject requiring further elaboration.
The development of new norms specifically addressing AI’s impact on cybersecurity, data security, and supply chain integrity — as proposed by China and others — has not been agreed upon and requires further discussion.
The question of how to address the accountability of private sector entities operating in the ICT environment, including commercial spyware vendors and technology companies providing services to parties in armed conflict, remains unresolved.
The application of international humanitarian law to ICT operations during armed conflict, including the conduct of civilian hackers and hacktivists, requires further normative clarification.
How the global mechanism should address the use of unilateral coercive measures and their impact on developing countries’ ICT capacity and digital sovereignty remains contested.
The geopolitical disputes between Israel and Iran, and between Russia and Ukraine, regarding alleged malicious ICT activities and violations of international law, remain deeply unresolved and risk disrupting the substantive work of the mechanism.
The finalisation and operationalisation of the Voluntary Norms Implementation Checklist, including whether it should serve as a self-reporting instrument and how it should be updated over time, requires further negotiation.
How to ensure that capacity building efforts are adequately targeted, demand-driven, and aligned with the specific needs of developing countries, small island developing states, and other vulnerable groups, including women and youth, remains to be worked out in detail.
Suggested Compromises
Several delegations, including Brazil and Thailand, suggested that advancing the implementation of existing norms and developing additional norms are not mutually exclusive objectives, and that the global mechanism could accommodate both provided there is consensus, offering a potential middle ground between states focused solely on implementation and those seeking new normative development.
The Netherlands proposed that the DTGs discuss norms not in isolation but in a cross-cutting manner with other pillars — international law, confidence-building measures, and capacity building — when addressing specific cyber threats, rather than tackling each pillar sequentially, as a way to make discussions more practical and integrated.
Multiple delegations, including the Pacific Islands Forum and New Zealand, suggested that the DTGs use specific scenarios or cybersecurity challenges as the basis for discussions, allowing states to share best practices and identify capacity building needs in a concrete and action-oriented way, rather than engaging in abstract normative debates.
South Africa and Malawi proposed focusing DTG1 discussions specifically on norms F, G, and H regarding critical infrastructure protection, as a practical and bounded starting point for deliberations that could generate concrete recommendations without requiring agreement on broader normative questions.
Iran proposed that negotiations on the Voluntary Norms Implementation Checklist proceed alongside a structured process for elaborating additional norms, suggesting a parallel-track approach as a compromise between states focused on implementation and those seeking new normative development.
Switzerland highlighted the Geneva Dialogue and the Geneva Manual as examples of multi-stakeholder processes that map roles and responsibilities in implementing voluntary norms, suggesting that such inclusive approaches could serve as a model for the DTGs and help bridge the gap between state-led intergovernmental processes and broader stakeholder engagement.
The Chair’s summary approach — identifying common themes from state statements without prejudging DTG discussions or establishing a hierarchy of issues — was implicitly presented as a procedural compromise to allow the mechanism to move forward despite divergent national positions.
“Cybercrime has become one of the world’s most significant illicit economies, generating trillions of dollars and affecting governments, businesses, and citizens across every region. And cybercrime is becoming increasingly industrialized. Specialized actors offer malware as a service, rent malicious infrastructure, and provide services supporting every stage of the criminal lifecycle. The rapid development of AI is only supercharging this criminal supply chain… Importantly, the tools and infrastructure developed within criminal ecosystems can also be exploited by a broader range of malicious actors. Combating cybercrime is therefore not only a law enforcement imperative, it is essential to advancing a safer and more resilient cyberspace.”
“ICT operations disable the provision of essential services for civilian populations… ICT operations do not spare medical facilities… ICTs are used to harm children… civilian hackers or hacktivists are now operating in several armed conflicts. Too often, they do not know or ignore the limits that IHL imposes on ICT operations… The growing use of artificial intelligence in ICT activities will increase their speed, scale, and potential for harm.”
“Norms do not exist because cyberspace is predictable. They exist precisely because it is not. In an environment where technologies evolve rapidly and misunderstandings can have far-reaching consequences, voluntary, non-binding norms provide something invaluable. Predictability, confidence, and a shared understanding of responsible stability and behaviour, even when our laws differ.”
“Vanuatu invites states to affirm through their conduct and their statements in this mechanism that infrastructure enabling disaster preparedness and response falls squarely within the protection these norms describe. There could be no clearer test of responsible behaviour than restraint towards the systems that keep vulnerable populations alive.”
“The alarming statistics reveal that voluntary norms on their own are not enough. This is demonstrated by the annual increase in cyber attacks with ever greater speed, scale and sophistication. This is also demonstrated by the growing militarisation of cyberspace… Non-binding voluntary norms therefore only constitute an intermediary step towards achieving our goal… A broad, legally binding instrument that establishes obligations with permanent monitoring would be, in our view, the most effective contribution to establishing a model of responsible behaviour by states.”
“Ukraine’s experience demonstrates why this norm is indispensable. Russia’s cyber attacks have targeted the energy sector, telecommunication networks, public administration systems, transport infrastructure and other essential civilian services. Their purpose has been not merely to disrupt computer systems, but to undermine the resilience of the state, amplify the effects of missile and drone attacks and inflict maximum hardship on the civilian population.”
“We have heard throughout our debates arguments for advancing the implementation of the existing norms and for the adoption of new ones. In our view, these positions are not in any way mutually exclusive, and this global mechanism can have room for both, as long as there is consensus. In any efforts aimed at eventually developing new norms, we have seen the emergence of new forms of behaviour in the cyber domain must be inclusive and therefore take place within this mechanism where the needs of all countries are duly taken into account.”
“Mere exposure to technology does not necessarily create understanding, preparedness, or most importantly, resilience… Access to an emerging technology and familiarity with it should not be treated as evidence that young people understand its broader consequences or feel prepared to address them.”
“The application of unilateral coercive measures has a direct impact on developing ICTs and also in terms of response to attacks, access to technology, to software, digital services and financing and knowledge transfer also impacts. These measures deepen the digital divide, they weaken national capacity, they make it difficult to protect critical infrastructure and they are an impediment to the right to development of our people.”
“The DTGs should provide the opportunity for states to discuss the norms not in isolation, but in a cross-cutting manner with the other pillars of the normative framework when addressing specific cyber threats and dilemmas. One way to do so is by providing guiding questions that prompt member states to discuss the norms in conjunction with international law, confidence-building measures, and capacity-building, instead of tackling each pillar one by one. The norms are best implemented in the recognition that the normative framework is a unitary framework rather than a collection of parts.”
How can states effectively implement the 11 voluntary non-binding norms of responsible state behaviour, and what does implementation look like in practice for states at different levels of development?
Tonga (on behalf of Pacific Islands Forum), Vanuatu, Republic of Korea, Nigeria, South Africa, Malawi, Botswana, New Zealand, Ireland, Netherlands, Portugal, Ukraine, North Macedonia, Albania
Multiple delegations emphasised that the primary challenge is not the absence of norms but their effective implementation. There is a need to understand what implementation looks like operationally, particularly for small island developing states and developing countries with limited capacity, and how the global mechanism can support this transition from endorsement to practice.
How should the Voluntary Checklist of Practical Actions for the implementation of norms be finalised and operationalised, and how can it serve as a living document responsive to evolving threats?
Tonga (on behalf of Pacific Islands Forum), European Union, Republic of Korea, Italy, Ireland, Netherlands, South Africa, Brazil, Switzerland, Israel
Several delegations highlighted the checklist as a valuable tool but noted it requires further development, finalisation, and operationalisation. There are open questions about how it should be structured, how it can remain practical and relevant, and how it can serve as a basis for voluntary self-reporting by states.
Should additional voluntary non-binding norms be developed, and if so, in which areas and through what process?
There is an unresolved tension between states prioritising implementation of existing norms and those calling for the elaboration of additional norms, particularly in areas such as AI and cybersecurity, data security, supply chain security, and the use of ICTs in armed conflict. The process and criteria for developing new norms remain unclear.
What normative framework, if any, should govern the use of artificial intelligence in cyber operations, and how should existing norms be interpreted in light of AI-enabled threats?
AI is identified as both an opportunity and a significant security challenge, with concerns about AI-accelerated cyber warfare, AI-enabled surveillance, deepfakes, and indiscriminate attacks. There is a need to examine whether existing norms adequately address AI-related risks or whether new normative guidance is required.
How should the protection of critical infrastructure, particularly health, energy, water, and submarine cables, be operationalised under norms F, G, and H, and what constitutes responsible state behaviour in this regard?
Ghana, Pakistan, Bangladesh, South Africa, Malawi, Vanuatu, Ukraine, Romania, Nigeria
Multiple delegations called for focused discussions on norms F, G, and H regarding critical infrastructure protection. There are open questions about how these norms apply to specific sectors, what obligations states have, and how to ensure that critical infrastructure enabling disaster preparedness and essential services is protected.
How can the due diligence norm be effectively implemented by states at different levels of development, and what does ‘reasonable capacity’ look like for smaller or less-resourced states?
Vanuatu, Costa Rica, Ukraine, Albania
The due diligence norm requires states not to knowingly allow their territory to be used for internationally wrongful ICT acts. There are unresolved questions about what constitutes reasonable diligence for states with limited technical and institutional capacity, and how international cooperation can support compliance.
How should the global mechanism address the role of non-state actors, including private sector entities, hacktivists, and criminal groups, within the normative framework for responsible state behaviour?
Pakistan, Romania, ICRC, Interpol, Switzerland
The blurring lines between state and non-state actors in cyber operations, including the use of proxy groups, commercial spyware vendors, and civilian hackers in armed conflicts, raises questions about accountability and the extent to which existing norms can address the conduct of non-state actors and the responsibilities of states that use or tolerate them.
How should disinformation and information operations, particularly when combined with cyber capabilities, be addressed within the existing normative framework or through new norms?
Pakistan, Romania, Bangladesh, Kenya ICT Action Network
Several delegations raised concerns about disinformation as a tool of hybrid warfare that contributes to conflict escalation and undermines democratic processes. There is a question of whether existing norms adequately address this threat or whether new normative guidance is needed, and how to balance this with freedom of expression.
What role should the Dedicated Thematic Groups (DTGs) play in advancing norms implementation, and how should their work be structured to produce action-oriented recommendations?
South Africa, Netherlands, Italy, Ireland, Nigeria, Portugal, New Zealand, Armenia, Botswana
Multiple delegations expressed support for the DTGs but raised questions about how they should be organised, what specific topics they should address, how they should integrate the different pillars of the normative framework, and how their outputs should feed into plenary recommendations.
Should the global mechanism develop legally binding instruments to complement or replace voluntary non-binding norms, and what would a roadmap for such development look like?
Cuba, Portugal, Ukraine, Israel
Cuba explicitly called for legally binding norms, arguing that voluntary norms are insufficient given the scale of cyber threats. Other delegations, including Portugal and Israel, argued against this approach at the current stage. The question of whether and when legally binding obligations should be pursued remains open and contested.
How can capacity building be better aligned with norms implementation to ensure that developing countries can meaningfully participate in and benefit from the normative framework?
African Union Commission, Morocco, Botswana, Nigeria, Thailand, Colombia, Brazil, Armenia
There is a recognised gap between the normative commitments agreed at the international level and the capacity of developing states to implement them. Questions remain about how capacity building efforts should be targeted, coordinated, and resourced to close this gap and reduce the digital divide.
How should the global mechanism address the use of ICTs in armed conflict, including the targeting of civilian infrastructure, recruitment of children, and the role of technology companies providing services to parties in conflict?
ICRC
The ICRC highlighted several trends in the use of ICTs during armed conflicts that are not fully addressed by existing norms, including the disabling of essential civilian services, targeting of medical facilities, recruitment of children via social media, and the dual-use nature of technology company infrastructure. These raise questions about how international humanitarian law and existing cyber norms apply in practice.
How should the global mechanism handle the proliferation of commercial surveillance tools and spyware, and what regulatory guardrails or norms are needed to prevent their misuse?
Pakistan, Kenya ICT Action Network
The misuse of commercial spyware and surveillance tools against journalists, human rights defenders, and political dissidents was raised as a significant threat. There are open questions about what norms or regulatory frameworks should govern the sale and use of such tools, and how states can be held accountable for their deployment.
What data security norms are needed to address cross-border data flows and the growing importance of data as a strategic asset?
China, Iran
Both China and Iran highlighted data security as an area requiring new normative development. Questions remain about what principles should govern cross-border data flows, how to prevent discriminatory or politically motivated restrictions, and how to balance national security interests with the free flow of information.
How can supply chain security norms be refined and made more specific, and how should the global mechanism address politically motivated fragmentation of ICT supply chains?
China, Italy, Nigeria
Supply chain vulnerabilities were identified as a significant and growing threat. There are questions about how existing norms on supply chain security can be made more operational, what internationally interoperable standards should look like, and how to prevent the use of supply chain restrictions as a geopolitical tool.
How should the global mechanism address the impact of unilateral coercive measures on developing countries’ ability to implement cybersecurity norms and protect their critical infrastructure?
Nicaragua, Cuba
Nicaragua and Cuba raised concerns that unilateral coercive measures deepen the digital divide, weaken national cybersecurity capacity, and impede access to technology and knowledge transfer. There is a question of how the global mechanism should address this structural barrier to norms implementation.
How can meaningful multi-stakeholder participation, including civil society, academia, and the private sector, be integrated into the work of the global mechanism and its DTGs without undermining the intergovernmental nature of decision-making?
Kenya ICT Action Network, Discover MUN Foundation, Switzerland, Italy, Tonga (on behalf of Pacific Islands Forum), Nigeria, Netherlands
Several delegations and civil society representatives called for meaningful stakeholder participation, while the Chair noted that participation is subject to specific modalities. There are unresolved questions about how to structure stakeholder engagement so that it adds value to technical discussions without compromising the state-led nature of the process.
How should youth and youth-serving organisations be recognised and engaged as stakeholders in the global mechanism, and what role should youth capacity-building practitioners play in the DTGs?
Discover MUN Foundation
The Discover MUN Foundation presented research suggesting that exposure to technology does not automatically translate into understanding of its broader consequences or cybersecurity resilience. They called for youth-serving organisations to be recognised as important stakeholders and for qualified youth capacity-building practitioners to be nominated to the DTGs.
What does responsible behaviour look like for technology companies that provide ICT infrastructure and services to both civilian populations and parties to armed conflicts, and how should this be reflected in the normative framework?
ICRC
The ICRC highlighted that technology companies providing infrastructure to parties in armed conflict expose civilian populations who rely on the same infrastructure to significant risks. There is a question of what obligations or expectations should apply to private sector entities in conflict settings and how this should be addressed in the normative framework.
How should the global mechanism address the growing convergence between state-sponsored cyber operations and cybercriminal ecosystems, including ransomware groups operating with state tolerance?
Ukraine, Interpol
Ukraine and Interpol both highlighted the blurring boundaries between state-sponsored actors and criminal groups, with ransomware and other cybercriminal infrastructure being used in ways that benefit state interests. There are open questions about how the due diligence norm and other norms apply to this convergence and what cooperative measures are needed.
How should the global mechanism structure a process for the elaboration of additional norms in parallel with implementation of existing norms, as envisaged in its mandate?
Iran, Brazil, Armenia, Morocco
Iran argued that the mandate of the global mechanism explicitly requires elaboration of additional norms and proposed that the Chair compile a consolidated draft of proposals submitted by member states. There is an unresolved question about how to establish a structured process for this work alongside the implementation agenda.
How can the global mechanism promote voluntary sharing of national positions on the interpretation and application of specific norms to build common understanding and identify areas of convergence?
Colombia, European Union, New Zealand, Ireland
Colombia invited states to voluntarily publish their national positions on specific norms, and the EU provided an example of such reporting. There are questions about how to encourage broader participation in this kind of transparency exercise and how the global mechanism can facilitate and build on such contributions.
What practical measures can states take to protect computer emergency response teams (CERTs) and computer security incident response teams (CSIRTs) from targeting, and how should their distinct role be recognised in the normative framework?
Costa Rica, Albania
Costa Rica emphasised the importance of recognising trusted technical actors such as CERTs as distinct from offensive or law enforcement functions, and Albania highlighted the essential role of CERTs in maintaining cybersecurity resilience. There are questions about what specific protections and norms should apply to these entities.
How should coordinated vulnerability disclosure procedures be developed and standardised internationally, and what legal safeguards are needed for good-faith security researchers?
Italy, Albania
Italy and Albania both highlighted the importance of coordinated vulnerability disclosure as a component of responsible state behaviour. There are open questions about what international standards or norms should govern this practice and how to ensure that security researchers are protected when acting in good faith.
How should the global mechanism address the specific cybersecurity vulnerabilities of small island developing states, particularly regarding disaster preparedness infrastructure and transnational malicious activity?
Vanuatu, Bangladesh, Tonga (on behalf of Pacific Islands Forum)
Vanuatu highlighted that its survival infrastructure, including early warning networks and emergency broadcast systems, is digital and particularly vulnerable. Bangladesh noted its dependence on a limited number of submarine cables. There are questions about what specific protections and capacity-building support are needed for small and geographically vulnerable states.
How should the integration of IT and OT (operational technology) security requirements be addressed within the normative framework, given their increasing convergence and the risks this poses to critical infrastructure?
Italy
Italy noted that IT and OT security are still too often addressed separately despite their increasing convergence, and suggested that common baseline security principles and internationally recognised methodologies for cyber maturity assessment could be developed. This represents an area where further technical and normative work is needed.
How can gender equality and the differentiated impact of cyber threats on women and other vulnerable groups be integrated into the implementation of norms and the work of the global mechanism?
Brazil, Kenya ICT Action Network, African Union Commission
Brazil highlighted gender equality as a key component of norms implementation, Kenya ICT Action Network raised concerns about AI-driven tools being used to perpetrate gender-based violence, and the African Union Commission called for gender mainstreaming in capacity building. There are questions about how these considerations should be systematically integrated into the normative framework and the DTGs’ work.
Disclaimer: This is not an official session record. DiploAI generates these resources from audiovisual recordings, and they are presented as-is, including potential errors. Due to logistical challenges, such as discrepancies in audio/video or transcripts, names may be misspelled. We strive for accuracy to the best of our ability.
This discussion took place during the third meeting of the substantive plenary session of the Global Mechanism on Developments in the Field of Information and Communication Technologies (ICTs) and Advanced Responsible State Behaviour, focusing on existing and potential ICT threats in the context of international security . The Chair noted 30 remaining speakers on the list and requested delegations to deliver abridged statements to allow all parties to be heard .
Several small island developing states, particularly from the Pacific, offered vivid accounts of the real-world consequences of cyber threats. Kiribati described how its first submarine cable connection simultaneously increased its exposure, warning that damage to undersea infrastructure would not merely degrade services but “sever them” . Tonga recounted how the 2022 volcanic eruption severed its single submarine cable, drawing a direct parallel to the potential impact of deliberate sabotage, and described a 2023 ransomware attack on its national health information system . These delegations called for threat discussions to be matched by practical cooperation and concrete steps .
A broad range of delegations identified ransomware, state-sponsored cyber operations, and the malicious use of artificial intelligence as the most pressing threats. The Netherlands highlighted the blurring of lines between state and non-state actors and the use of proxies to maintain plausible deniability . Germany reported estimated annual cyber attack damages of approximately 230 billion US dollars and condemned specific Russian state-sponsored activities targeting EU critical infrastructure . France, Poland, Latvia, and Albania similarly attributed sustained malicious cyber campaigns to Russian actors, citing specific incidents against government institutions and critical infrastructure .
Iran delivered a lengthy statement alleging that the United States and Israel conducted over 100 cyber attacks per day against Iranian critical infrastructure during February 2026, targeting banking, telecommunications, energy, and civilian institutions . Israel and the United States both rejected these characterisations, with the US warning that it would hold malicious actors accountable and that “the cyber domain is about to change” . Ukraine described cyberspace as “one of the principal theatres of Russia’s ongoing war of aggression,” noting that Russian operations had evolved into sophisticated campaigns combining espionage, supply chain compromise, and information manipulation .
Across delegations, there was broad convergence on the need for the global mechanism to move beyond identifying threats towards practical implementation, capacity building, and structured information sharing, particularly for developing countries with limited resources . Delegations including Egypt, Japan, and Chile emphasised the importance of engaging qualified experts and evidence-based discussions within the dedicated thematic groups . The overall significance of the session lay in establishing that the new permanent mechanism must translate shared threat awareness into concrete, cooperative, and action-oriented outcomes for all states, regardless of size or capacity .
Keypoints
Overall Purpose
The discussion takes place during the third meeting of the substantive plenary session of the Global Mechanism on Developments in the Field of Information and Communication Technologies (ICTs) and Advanced Responsible State Behaviour. The primary goal is for member states to identify and discuss existing and potential ICT threats in the context of international security, with a view to informing the work of dedicated thematic groups (DTGs) and advancing the implementation of the UN framework for responsible state behaviour in cyberspace.
—
Major Discussion Points
Critical infrastructure protection, particularly submarine cables and undersea connectivity, as an existential threat for small island developing states (SIDS). Multiple Pacific Island nations emphasised that the disruption of submarine cables – whether through natural disaster, accident, or deliberate malicious action – poses an existential rather than merely significant risk. Tonga recounted how the 2022 Hunga Tonga-Hunga Ha’apai volcanic eruption severed its only submarine cable, leaving the country isolated during a crisis, and warned that a malicious actor could replicate this deliberately. Kiribati similarly noted that damage to its limited cable infrastructure would not degrade services but sever them entirely. Australia and Tuvalu reinforced the importance of undersea cable resilience for economic and social connectivity across the region.
Ransomware as a pervasive and escalating threat to critical infrastructure and essential services. Numerous delegations identified ransomware as one of the most destructive and widespread cyber threats, affecting healthcare, government, energy, and other critical sectors. Tonga described a ransomware attack that encrypted its national health information system and forced hospitals back to pen and paper. Japan stated that ransomware targeting critical infrastructure such as hospitals and power plants could constitute a direct threat to international peace and security. Germany reported a 230 billion USD annual damage estimate from cyber attacks, with ransomware particularly targeting critical infrastructure providers and municipal services. Latvia, the Philippines, Malaysia, and others echoed these concerns.
The role of artificial intelligence in amplifying cyber threats and transforming the threat landscape. A broad consensus emerged that AI is lowering the barrier to entry for malicious actors, enabling more sophisticated phishing, autonomous vulnerability discovery, and large-scale social engineering. New Zealand welcomed discussion on how AI affects cyber security risks and noted the importance of avoiding duplication with other UN processes. The Netherlands highlighted that generative AI and large language models can assist in zero-day vulnerability discovery and exploitation. Australia warned that AI is making it easier for malicious actors to generate propaganda and support target selection for physical strikes. France noted that frontier AI models are increasing the speed of offensive operations and risk creating a new digital divide between those with and without access to such models. The Republic of Korea called for deepened discussions on AI-enabled cyber threats within the global mechanism. – State-sponsored malicious cyber activity, attribution, and accountability. Several Western and allied delegations made explicit attributions of malicious cyber operations to state actors, particularly Russia, while Russia and Iran rejected these accusations and made counter-allegations. France announced it had been the target of persistent cyber attacks by Russia’s FSB for over a decade. Germany, together with EU partners, exposed and condemned malicious cyber activities by Russian state actors targeting government entities and critical infrastructure, including energy systems with potential for catastrophic damage. Ukraine described Russia’s cyber operations as an integral component of its broader war of aggression, combining cyber attacks with kinetic strikes and disinformation. Iran detailed extensive cyber attacks it attributed to the United States and Israel during military operations in February 2026. Russia rejected all accusations as fabricated and without evidence, and counter-accused NATO states of building offensive cyber capabilities. The United States warned that it would identify and hold accountable states conducting malicious cyber activities against others in the room. – Capacity building, international cooperation, and the need to ensure developing countries are not left behind. A recurring theme across delegations from Africa, the Pacific, Latin America, and Asia was that the global mechanism must translate threat discussions into practical, demand-driven capacity building tailored to the needs of developing and small island states. The Bahamas stressed that capacity building is a precondition for meaningful participation for SIDS. Malawi highlighted that many developing countries struggle to respond even to a single cyber incident, let alone sustained campaigns. Cameroon called for the establishment of a dedicated voluntary fund to support national cybersecurity institution building and participation in DTG meetings. Egypt argued that threat discussions in thematic groups must be dynamic, scenario-based, and supported by an agreed pool of relevant experts rather than replicating plenary discussions. —
Overall Tone
The discussion began in a broadly constructive and cooperative tone, with delegations welcoming the establishment of the permanent global mechanism and expressing commitment to practical, action-oriented outcomes. Small island states delivered particularly earnest and personal statements, grounding the discussion in lived national experience rather than abstract policy.
However, the tone shifted markedly when Iran delivered a statement attributing extensive cyber and kinetic attacks to the United States and Israel , prompting sharp responses from the United States , Israel , and Iran’s right of reply . These exchanges introduced a confrontational and politically charged atmosphere, with accusations of bad faith, disinformation, and violations of international law traded between delegations. Russia’s statement similarly escalated tensions by rejecting attribution claims from multiple Western states and accusing NATO of hypocrisy and Russophobia. The Chair intervened to manage procedural order, reminding delegations that rights of reply should be reserved for the end of the speakers’ list and urging all parties to remain focused on the substantive agenda. Despite these disruptions, the majority of delegations maintained a professional and solution-oriented tone throughout, consistently returning to themes of cooperation, capacity building, and the importance of the mechanism delivering tangible outcomes for all states.
Speakers Overview
E
Egypt
155 wpm · 2 min
K
Kiribati
125 wpm · 4 min
NZ
New Zealand
172 wpm · 2 min
T
Tonga
147 wpm · 3 min
N
Netherlands
123 wpm · 4 min
B
Bahamas
112 wpm · 5 min
IR
Islamic Republic of Iran
141 wpm · 8 min
A
Australia
139 wpm · 4 min
J
Japan
114 wpm · 2 min
G
Guyana
140 wpm · 2 min
G
Greece
142 wpm · 2 min
US
United States
137 wpm · 4 min
T
Tuvalu
143 wpm · 3 min
Z
Zimbabwe
123 wpm · 4 min
A
Albania
140 wpm · 6 min
RF
Russian Federation
138 wpm · 6 min
P
Philippines
121 wpm · 4 min
U
Ukraine
131 wpm · 4 min
C
Chile
125 wpm · 5 min
M
Malawi
107 wpm · 5 min
F
France
133 wpm · 5 min
G
Germany
155 wpm · 5 min
L
Latvia
134 wpm · 4 min
I
Israel
137 wpm · 8 min
C
Canada
126 wpm · 4 min
I
Indonesia
126 wpm · 3 min
T
Thailand
100 wpm · 3 min
M
Morocco
116 wpm · 2 min
M
Micronesia
117 wpm · 4 min
M
Malaysia
148 wpm · 3 min
C
Cameroon
143 wpm · 5 min
C
China
111 wpm · 8 min
O
Oman
106 wpm · 6 min
M
Mauritius
112 wpm · 5 min
RO
Republic of Korea
125 wpm · 3 min
G
Ghana
82 wpm · 4 min
I
Iraq
162 wpm · 3 min
P
Poland
118 wpm · 4 min
M
Mozambique
96 wpm · 4 min
CE
Chair Egriselda López
124 wpm · 13 min
Expanded Summary: Third Meeting of the Substantive Plenary Session – Global Mechanism on ICTs and Advanced Responsible State Behaviour
#
Session Overview and Procedural Context
The third meeting of the substantive plenary session of the Global Mechanism on Developments in the Field of Information and Communication Technologies (ICTs) and Advanced Responsible State Behaviour convened under the chairmanship of Ambassador Egriselda López. The primary agenda item was the completion of statements under the pillar on existing and potential ICT threats in the context of international security. With 30 remaining speakers on the list at the outset, the Chair requested that delegations deliver abridged versions of their statements and submit full texts to eStatements, noting that a timer would be projected on screen to assist with time management. This first substantive session of a permanent mechanism was widely acknowledged as historically significant, marking the transition from the time-limited Open-Ended Working Group (OEWG) process to a standing forum for international cyber security dialogue.
#
Calls for Action-Orientation: Setting the Tone for the Mechanism
One of the most consequential early interventions came from Kiribati, which framed the session’s purpose in terms that resonated throughout the entire discussion. Kiribati observed that for years, collective work on ICT security had moved from one limited-time process to the next, while threats had never paused between them, and welcomed the permanence of the new mechanism. Crucially, Kiribati insisted that “discussion of threats must not end as descriptions of threats” and that each threat identified should connect to a concrete step enabling all states, including the smallest, to prevent, detect, and respond. This call for action-orientation – rather than mere cataloguing – was adopted, explicitly or implicitly, by the majority of subsequent speakers, including Malawi, Mozambique, Cameroon, and Morocco, and effectively established a normative standard against which the mechanism’s first session would be judged.
Cameroon reinforced this collective spirit by invoking the African proverb “If you want to go fast, go alone. If you want to go far, go together,” encapsulating its call for shared responsibility and multilateral cooperation in addressing cyber threats. Morocco similarly called for the first Dedicated Thematic Group (DTG1) to be “strongly turned toward action,” emphasising the need to move beyond descriptive threat cataloguing towards concrete, implementable outcomes.
#
Critical Infrastructure and the Existential Vulnerability of Small Island States
The vulnerability of submarine cable infrastructure emerged as one of the session’s most vivid and consistently reinforced themes, driven primarily by Pacific Island Forum member states. Kiribati described how the landing of the East Micronesian Cable at Tarawa – the first submarine cable ever to reach its capital – was transformative for its Digital Government Master Plan and service delivery across dispersed islands, but that “every step forward in connectivity is also a step forward in exposure.” For a nation served by a small number of cables, landing stations, and satellite links, Kiribati stated that critical infrastructure protection is not one threat among many but “existential,” and that damage to or disruption of its submarine cable “will not degrade our services, it will sever them” [S185].
Tonga offered perhaps the most powerful illustration of this vulnerability. Recounting the January 2022 eruption of Hunga Tonga-Hunga Ha’apai, which severed the single submarine cable connecting the kingdom to the world, Tonga described weeks of silence – cut off at the very moment it most needed to call for help, coordinate relief, and reassure families abroad. Tonga then drew a direct and sobering parallel: “everything a volcano did to Tonga by accident, a malicious act could choose to do deliberately.” This framing transformed an abstract geopolitical threat into a visceral, lived experience, and Tonga called on the room to treat the sabotage of submarine cables and other critical infrastructure as one of the gravest threats before the mechanism. Australia reinforced this regional perspective, stating that for many countries in the region, the resilience of undersea cable infrastructure is fundamental to economic and social connectivity and to access to the global internet, and called for critical infrastructure protection to be an early focus for the mechanism through DTG1. Tuvalu similarly highlighted the importance of the Aotevaca Cable and other subsea infrastructure to its connectivity, grounding its cybersecurity concerns in the concrete realities of Pacific island geography.
Ghana noted that damage to Submarine Cable 7 Ghana in 2024 reinforced the importance of protecting such infrastructure as a strategic national asset [S185][S186]. Guyana announced plans to establish a national cyber emergency response system operating on a 24/7 basis, reflecting the growing recognition among developing states that continuous operational capacity is essential for effective incident response.
Beyond submarine cables, the broader theme of critical infrastructure protection attracted broad agreement. The Netherlands highlighted a troubling shift towards the targeting of means of communication such as messaging services, noting that compromises can enable large-scale espionage, manipulation of communications, or disruptions with cascading effects far beyond the specific target. Chile stated that the protection of critical infrastructure represents a national priority and an essential component of international security, with the gradual digitisation and interconnection of critical sectors increasing the risk of systemic effects. Zimbabwe, as a land-linked developing country relying on interconnected regional telecommunications networks, recognised that vulnerabilities within shared digital infrastructure can have cross-border consequences.
The Bahamas drew particular attention to the nexus between cyber threats and natural disasters as a specific and compounding vulnerability for small island developing states, noting that the simultaneous occurrence of a cyber incident and a natural disaster could overwhelm national response capacity at the most critical moment.
#
Ransomware: A Pervasive and Escalating Threat
Ransomware was identified by a remarkably broad coalition of delegations as one of the most destructive and widespread cyber threats, with real-world impacts documented across healthcare, government, energy, and financial services [S191][S192]. Tonga described a ransomware attack in June of the previous year that encrypted its national health information system, holding the medical records of its entire population to ransom and forcing hospitals back to pen and paper. Tonga also noted that its state-owned telecommunications provider was attacked in 2023, and that these incidents against the essential services of a small state demonstrated that no country is too small or too remote to be targeted. Significantly, Tonga, together with Australia and New Zealand, jointly attributed the attack on its Ministry of Health to an affiliate of a known ransomware group, demonstrating that even the smallest states acting with partners can pursue accountability for malicious cyber activities.
Japan stated explicitly that ransomware targeting critical infrastructure such as hospitals and power plants “could certainly pose direct threats to international peace and security,” citing its statement at the Security Council briefing on ransomware in November 2024. Germany reported that the leading German digital business group estimated annual damage from cyber attacks at approximately 230 billion US dollars, with ransomware particularly targeting critical infrastructure providers, municipal and government services, and not-for-profit organisations. Germany also described a ransomware attack that paralysed a leading humanitarian organisation providing food relief in conflict regions, putting lives abroad at risk. Latvia noted that criminal groups have developed industrial-scale ransomware operations, leveraging encryption, infostealer malware, data theft, and extortion to generate enormous profits. The Philippines called for timely information sharing, strengthened incident response capabilities, public-private partnerships, and sustainable capacity building to address ransomware [S187][S188][S189][S190].
#
Artificial Intelligence: Amplifying Threats and Transforming the Landscape
Artificial intelligence was consistently highlighted across delegations as a dual-use technology that is both amplifying offensive cyber capabilities and offering significant defensive opportunities [S154][S155]. The Netherlands stated that generative AI and large language models can lower the barrier for conducting sophisticated operations, from writing convincing phishing messages to assisting in the discovery of zero-day vulnerabilities and their exploitation, and noted that the development of such threats continues to accelerate with the rise of agentic AI. Australia warned that AI is being used to scale social engineering, create more convincing phishing content, analyse stolen data, and lower the cost and skill barriers required to cause harm, and expressed particular concern that AI is making it easier for malicious actors to generate and spread propaganda and to support planning and target selection for physical strikes.
Germany observed that the advent of advanced AI facilitates large-scale attacks including language-agnostic phishing, voice phishing, and social engineering attacks, continuously lowering the barrier for opportunistic malicious actors and creating an increasing strain on defenders’ resources, with particular impact on less-resourced and small countries. Latvia noted that AI-enabled tools can automate reconnaissance, accelerate and scale vulnerability discovery, and generate highly convincing phishing campaigns, with the potential to overwhelm cyber defenders’ capacity to respond. Canada noted that frontier AI models have displayed unprecedented capabilities in autonomous vulnerability discovery, zero-day vulnerability exploit generation, and multi-stage orchestration of malicious cyber activity.
France introduced a particularly significant analytical dimension, observing that the rapid increase in frontier AI model capabilities carries the risk of a new digital divide – between those who have access to these models and those who do not, and between those who can independently assess the risks associated with these models and those who cannot. China stated that “in the past, the risk posed by AI was merely theoretical, but now we see firsthand the real threats AI poses,” and called for the establishment of global standards and systems for testing and assessing the risk of large AI models, to ensure that AI serves as a shield for cybersecurity rather than a tool for unilateral pursuit of hegemony. The Republic of Korea called for the mechanism to deepen discussions on AI-enabled cyber threats and ensure that international dialogue remains timely and responsive to the rapidly changing technological environment.
New Zealand offered a note of caution, arguing that the global mechanism should not duplicate other UN processes actively grappling with AI governance issues, and should focus only on issues where it is uniquely well placed to add value – namely, building shared understanding of the implications of AI for cybersecurity. This position was not widely shared, with most delegations calling for substantive AI discussions within the mechanism itself.
#
State-Sponsored Cyber Activities, Attribution, and Accountability
The session was marked by sharp and explicit attributions of malicious cyber activities to state actors, generating some of the most politically charged exchanges of the meeting. France announced that it had been the target for more than ten years of persistent cyber attacks carried out by Russia’s Federal Security Service (FSB), and stated that this attribution process was conducted in accordance with the norms for responsible state behaviour and following the exhaustion of appropriate channels. France also noted that on the 13th of July, the European Union adopted new sanctions against actors from the Russian cyber threat ecosystem. Germany stated that last week, together with the European Union and its member states and the North Atlantic Council, it had exposed and condemned a series of malicious cyber activities conducted by Russian state actors, including its intelligence service FSB and state-supported cyber criminal and hacktivist groups, targeting government entities and critical infrastructure in several EU member states and Ukraine, some of which had the potential for catastrophic damage to civilian energy infrastructure such as electricity networks or hydroelectric dams. Germany also stated it had communicated the unacceptability of these activities via appropriate direct bilateral channels.
Poland reported a sustained pattern of malicious cyber activity by Russian actors since at least 2010, including strategic reconnaissance, prepositioning, and disruptive sabotage operations targeting Polish critical infrastructure including water treatment plants and the energy sector. Albania documented 51 cyber incidents with significant impact in 2025, rising to more than 17 million attempted cyber attacks in 2026, with four incidents in March 2026 alone targeting the Albanian parliament, post office, office of the general prosecutor, and directorate of prisons, supported by state-sponsored cyber operations. Ukraine described cyberspace as “one of the principal theatres of Russia’s ongoing war of aggression against Ukraine,” noting that Russian malicious ICT activities form part of a broader strategy combining cyber attacks with kinetic strikes, disinformation campaigns, and other hybrid warfare tools, and that over time these operations have evolved from destructive attacks into sophisticated campaigns involving cyber espionage, long-term network persistence, supply chain compromise, and information manipulation [S156][S196].
The Russian Federation categorically rejected all these accusations, arguing that accusations of organising and implementing wrongful acts against states should be substantiated and that no evidence had been provided through existing channels, including the UN Points of Contact Directory. Russia concluded that “either no evidence exists or the incidents never happened at all,” and characterised the accusations as “blatant disinformation” serving Russophobic policies. Russia counter-accused NATO states of building up offensive digital capabilities and conducting computer operations against Russian critical information infrastructure, and accused NATO member states of turning a blind eye to crimes committed by Ukrainian hackers against Russian citizens and civilian critical information infrastructure [S157][S197]. Russia also called on the Chair to prevent the discussions within the global mechanism from turning into a political crisis.
#
The Iran-Israel-United States Exchange
The most politically disruptive episode of the session arose from Iran’s detailed account of cyber attacks it attributed to the United States and Israel. Iran alleged that during the February 2026 aggression alone, more than 100 cyber attacks were launched every day against Iran’s critical and civilian infrastructure. These operations were described as including coordinated cyber and kinetic attacks targeting critical ICT infrastructure including telecommunications facilities, data centres, and AI infrastructure; attacks against civilian institutions including schools, universities, and media; exploitation of private sector technologies and ICT supply chains including products from Cisco and HP and the misuse of Starlink satellite communication services; cyber espionage and information operations including the manipulation of digital platforms such as Instagram, X, and Telegram to incite violence and spread hatred; and electronic warfare and hybrid operations. Iran called on states that advocate respect for international law to apply those principles consistently and condemn such activities.
Israel responded by asserting that its actions during operations Rising Lion and Roaring Lion were conducted in accordance with international law, including the UN Charter and the laws of armed conflict, in the context of an ongoing armed conflict with Iran. Israel accused Iran of waging hostility across all domains of warfare, including the cyber domain, and of specifically targeting critical civilian infrastructure including hospitals with complete disregard for international humanitarian law.
Iran’s right of reply characterised both the US and Israeli statements as “a desperate attempt to distort facts through disinformation and misleading narratives,” and reiterated that the Islamic Republic of Iran has long been one of the principal targets and victims of malicious cyber activities, invoking the historical pattern of such activities – including what it described as the first non-cyber weapon deployed against critical infrastructure – as evidence of a sustained campaign against it. The Chair intervened to clarify that rights of reply should be made at the end of the speakers’ list, indicating that the level of political confrontation had not been anticipated in the procedural design of the session.
#
The United States: Deterrence, Accountability, and Implementation
The United States framed its engagement with the mechanism in terms of practical implementation of the 11 consensus norms, explicitly stating that the mechanism should not be “a vehicle for new legally binding agreements” and arguing that as long as some members are maliciously conducting cyber actions against other members, a legally binding agreement is impossible. The United States stated that the mechanism was established to do real work – to implement the commitments states have already made and to confront actual threats hitting critical infrastructure every single day. The United States further stated that it would demand adherence to the consensus norms and the five pillars to ensure the cyber domain remains a secure and safe space for everyone.
In a notably direct passage, the United States warned that it would specifically identify states and non-state actors perpetuating malicious cyber activities against others in the room, and that President Trump had been clear: “if a country is utilizing the cyber domain to hurt others, in this chamber, the United States will make them pay a heavy price.” The United States also expressed solidarity with Pacific Island states, directly addressing Tonga and Kiribati and pledging to help protect them. In a pointed postscript to its national statement, the United States stated that President Trump “is not going to stand idly by while the oppressive Iranian regime seeks to destroy regional stability and the inalienable right of all Iranians.”
#
Russia and China: Alternative Threat Framings
The Russian Federation introduced a set of threat categories that diverged significantly from the Western-dominated discourse. Russia highlighted the “monetisation of the private sector,” arguing that major ICT developers make no secret of how deeply they are embedded in the military-industrial complexes of the countries where they are registered and often act as contractors for intelligence agencies. Russia also raised the issue of undeclared malicious capabilities – backdoors embedded by developers in the interests of intelligence agencies without notifying end users – noting that as demonstrated by the “infamous Pager incident in Lebanon in 2024,” such tools can be used for causing physical damage. Russia further raised concerns about low-orbit satellite communication systems being used for military-political objectives and interference in the internal affairs of states.
China identified three major threats: the risk of conflicts and unrest in cyberspace, driven by a “certain country” that aggressively develops offensive cyber military capabilities and integrates AI into offensive national cyber strategies; the challenge to the principle of sovereignty, with states being coerced into taking sides under the guise of cybersecurity and global digital industrial chains being deliberately severed; and the risk of marginalisation of global cyberspace governance through small-circle approaches that cannot solve the big challenges facing the world. China formally submitted a position paper on global cyber governance in the digital intelligence age to the Secretariat and requested its circulation to all member states as an official document.
#
Blurring of State and Non-State Actor Boundaries
Multiple delegations identified the blurring of boundaries between state-sponsored actors and non-state proxies as one of the most problematic and growing trends in the threat landscape. The Netherlands described this as a “worrying trend of state actors hiding behind state proxies to maintain plausible deniability,” noting that different types of actors increasingly use similar tools, target similar systems, and sometimes operate in concert. France observed that “the boundaries between state-sponsored acts and cyber criminals are blurring, and the use of proxies by nation-states is spreading,” and noted that behind various disguises, the intention to destabilise remains the same. Israel highlighted the clandestine direction, control, or support of non-state actors as a core threat, and raised the issue of states granting absolute impunity to criminal syndicates and terrorist proxies offering hacking as a service from state-sanctioned safe havens. Israel also drew attention to the illicit financing of such operations via digital assets, calling for international cooperation on tracking, freezing, and seizing cryptocurrencies used for illicit activities.
Iraq raised a distinctive concern not widely echoed by other delegations: the exploitation of ICTs by terrorist groups, including the use of cyberspace for recruitment, dissemination of extremist ideology, financing, planning, and coordination of terrorist operations, as well as the targeting of critical infrastructure by such groups. Iraq affirmed the importance of strengthening the security of ICT supply chains and exchanging international best practices and standards as an important element in reducing cross-border cyber risks.
#
Disinformation, Hybrid Threats, and Influence Operations
The combination of cyber operations with disinformation and information manipulation was identified as an increasingly significant dimension of the threat landscape. Albania described a “particularly concerning trend” in which cyber incidents were followed by attempts to spread disinformation and manipulate public perception through social media platforms, specifically via Telegram, seeking to amplify the psychological impact of cyber incidents, generate public uncertainty, and erode trust in public institutions. Albania concluded that “contemporary cyber threats are no longer limited to technical intrusions, but increasingly combine cyber operations, disinformation, and influence activities.” Ukraine similarly highlighted hybrid campaigns combining cyber operations, disinformation, and economic coercion as seeking to undermine international peace and security.
Mauritius noted the growing risks posed by the malicious use of AI to generate convincing deepfakes, clone voices, spread disinformation, and enable sophisticated forms of fraud, including cryptocurrency-related scams, with the potential to undermine public trust and disproportionately impact vulnerable groups including children and older persons. Micronesia offered a cautionary counterpoint, warning that vague approaches to disinformation can suppress dissent and independent media, erode human rights, politicise enforcement, and disproportionately harm marginalised and remote communities, and urging states to adopt precise, time-bound, and rights-based definitions of disinformation.
#
Supply Chain Security and Emerging Technology Risks
Several delegations raised concerns about the security of ICT supply chains and the risks posed by emerging technologies beyond AI. Iran described attacks exploiting private sector technologies and ICT supply chains, including commercial products and services, software, hardware, and digital supply chains, as well as the misuse of Starlink satellite communication services. Thailand noted that ICT supply chain disruptions, including the deliberate insertion of vulnerabilities, backdoors, or other forms of interference, undermine economic and digital development, particularly in developing countries. Thailand’s national assessment also indicated a continued rise in cyber incidents involving information content security, cyber fraud, and intrusion attempts.
Malaysia noted that it is preparing for the security implications of quantum computing, especially regarding current encryption systems, and is developing a national post-quantum cryptography migration plan focused on safeguarding critical information infrastructure. Chile similarly identified future risks related to quantum computing, alongside ransomware, exploitation of digital supply chains, and cloud-connected software, as topics requiring continued attention. Greece raised concerns about the proliferation of commercial cyber tools and capabilities, welcoming the Pall Mall Process as an initiative seeking to build international consensus on the responsible development, distribution, and use of commercial cyber intrusion capabilities. France described the uncontrolled proliferation of commercial cyber intrusion capabilities as “a veritable ticking time bomb,” and announced the launch of negotiations on guidelines for the cyber intrusion industry under the Pall Mall Process, building on the April 2025 Code of Good Practices for States.
#
Capacity Building and the Needs of Developing Countries
A recurring and strongly felt theme across delegations from Africa, the Pacific, Latin America, and Asia was that the global mechanism must translate threat discussions into practical, demand-driven capacity building tailored to the needs of developing and small island states [S198][S199][S200]. The Bahamas stated that for small island developing states, “capacity building is a precondition for participation,” and called for it to be sustained, tailored to national circumstances, and directed towards durable institutions and a trained workforce. The Bahamas also highlighted three specific priorities: cyber threats to youth, cyber threats to women including technology-facilitated gender-based violence, and the need for women to be at the table in delegation, technical decision-making, and national ICT policy design.
Malawi introduced a particularly precise analytical point, arguing that it is not only the emergence of threats that should concern the mechanism, but their persistence: “persistent and covert malicious ICT activities can remain undetected for extended periods of time, gradually undermining public trust, disrupting essential services, weakening national resilience, and causing significant economic and societal harm.” Malawi noted that for many developing countries, responding to one cyber incident is already difficult, and responding to sustained campaigns is an even greater challenge. Cameroon called for the establishment of a Dedicated Voluntary Fund under the Global Mechanism as an essential instrument to support national cybersecurity institution building, provide resources for training and skills development, and facilitate participation in DTG meetings and capacity-building programmes. Mozambique called for capacity building that is predictable, sustainable, demand-driven, and accompanied by technology transfer, institutional strengthening, and equitable access to knowledge and expertise.
Australia acknowledged that cyber threats are shared but their impacts are not experienced equally, with differences in national capacity affecting vulnerability to malicious cyber activity and the ability to recover when incidents occur. Zimbabwe noted that capacity constraints and uneven cyber resilience increase vulnerability and limit the ability to effectively respond to cyber incidents, risking progress towards digital transformation and sustainable development. Indonesia called for the mechanism and its DTGs to foster cooperation in threat analysis, shared early warning arrangements, and structured exchange on incident trends to ensure that developing countries are not left behind. Indonesia also highlighted its participation in ASEAN, OIC, and Asia-Pacific mechanisms for technical information sharing, coordinated incident response, and joint capacity building as models for the kind of regional cooperation the global mechanism should support and complement.
The Philippines, noting its role as ASEAN Chair in 2026, reaffirmed its commitment to advancing regional cybersecurity cooperation through cyber exercises and operational collaboration, and called for timely information sharing, strengthened incident response capabilities, public-private partnerships, and sustainable capacity building to address threats including ransomware.
#
The Role of the Dedicated Thematic Groups
There was broad consensus that the Dedicated Thematic Groups (DTGs) represent the primary vehicle for translating high-level threat discussions into practical, action-oriented outcomes. Egypt argued that discussions in the DTGs should not replicate plenary discussions but should be dynamic, based on real case scenarios, and supported by a consensus-based pool of relevant experts accepted by delegations – noting that “having discussions on threats without a professional, experienced, and relevant pool of experts is, again, a waste of time.” Japan placed great importance on holding expert briefings and interactive public-private discussions in the substantive plenary sessions and DTGs. Chile argued that the first DTG provides a particularly valuable opportunity for regular, structured, evidence-based dialogue on the evolution of threats, with a forward-looking approach and the participation of experts, regional organisations, the scientific community, and the private sector.
Latvia stated that the DTGs should focus on specific ICT security challenges, enabling states to examine threats, share experience, and develop practical approaches, and should also help turbocharge capacity-building efforts, recognising that global cyber resilience depends on ensuring that all states can protect their digital infrastructure. Oman called for DTG1 to focus on the practical implementation of norms 13i and 13j regarding the protection of critical infrastructure and supply chains, and norm 13c regarding states not allowing their territory to be used for malicious cyber activities, and argued that the mechanism should develop tools to assess whether states are abiding by these norms. France suggested that the first DTG could focus on one or two major trends in cyber threats with an impact on international peace and security, rather than attempting to address all threats simultaneously.
#
International Law and the Framework of Responsible State Behaviour
The vast majority of delegations reaffirmed that international law, including the UN Charter, applies in cyberspace and provides the foundation for responsible state behaviour. The Bahamas stated that international law is “the foundation of a secure and peaceful ICT environment” and “the guarantee of this process, not a constraint to it,” and that voluntary norms and confidence-building measures operate in service of binding legal obligations, not in place of them. Australia stated that state responses, including the development and use of cyber capabilities, must be consistent with international law including the UN Charter in its entirety, international human rights law, and international humanitarian law. Micronesia affirmed that international law applies in cyberspace and that respect for sovereignty, the prohibition on the threat or use of force, and human rights obligations must guide state conduct online as they do offline. Malawi reaffirmed that as recognised in successive UN GGE and OEWG reports, international law including the UN Charter applies to the use of ICTs by states.
The Netherlands argued that adequate implementation of the consensus UN framework is the appropriate response to the growing complexity of the threat landscape, as it can inject a degree of predictability into global affairs. Albania emphasised that ensuring states act responsibly in cyberspace, refrain from supporting malicious activities, and cooperate in addressing threats is essential for preserving international peace, security, and stability in an increasingly interconnected world. The Republic of Korea noted that cryptocurrency theft has become a major source of financing for illicit activities and called for reaffirmation that such activities threaten international peace and security, especially when linked to illicit arms trafficking or the development of weapons of mass destruction, recalling that the final reports of the OEWG recognised cryptocurrency theft as a threat with implications for international peace and security.
#
National Experiences and Legislative Developments
Several delegations shared detailed accounts of their national cyber security postures and legislative frameworks. Kiribati described its Cybercrime Act 2021, Digital Government Act 2023, Data Protection Act 2025, and new Cybersecurity Act 2026 as forming the legislative backbone of its response. The Bahamas noted the launch of its National Computer Incident Response Team in December 2023, the adoption of a national cybersecurity strategy, a Data Protection Act in 2025, and the advancement of a national cybersecurity bill and child online protection strategy. Australia reported that its Cyber Security Centre responded to over 1,200 cyber security incidents and received more than 84,700 cybercrime reports in the previous year – roughly one report every six minutes. Albania documented more than 17 million attempted cyber attacks against Albanian systems in 2026, with four significant incidents in March 2026 alone targeting public institutions. Oman described its Electronic Defense Center, which since 2024 has addressed many cyber threats targeting national and governmental institutions, and announced a new national cybersecurity strategy for 2026-2030 placing cyber resilience at its heart. Oman also noted that it has adopted the 11 responsible behaviour norms for states and incorporated these into all its cyber policies, reflecting a commitment to translating international consensus into domestic practice. Mauritius highlighted the work of CERT-MU, its national Computer Emergency Response Team, in coordinating national incident response and building cyber resilience.
#
Procedural Developments and Closing Arrangements
As the session progressed, the Chair noted that the list of speakers had grown longer than predicted, potentially impacting the ability to address other agenda items, and closed the list of speakers for inscriptions. The Chair reminded delegations of the request to limit statements and noted that 21 speakers remained on the list with approximately one hour and 45 minutes remaining. The session was adjourned with the remaining speakers – Pakistan, Romania, Nicaragua, Armenia, the African Union, ICRC, and Interpol – to continue at 3 p.m., after which the mechanism would immediately proceed to the agenda item on voluntary norms for responsible state behaviour in cyberspace. Several side events were announced, including a joint event by Germany, the Dominican Republic, and Ghana on best practices for the operationalisation of confidence-building measures for the protection of critical infrastructure, and a co-hosted briefing by Latvia, Estonia, and Australia on Frontier AI and the Cyber Threat Landscape.
#
Overall Assessment
The session demonstrated both the promise and the challenges of the new permanent mechanism. There was genuine and broad convergence on the nature and severity of key threats – particularly ransomware, AI-enabled malicious activity, and critical infrastructure vulnerabilities – and on the need for the mechanism to be action-oriented, inclusive, and practically focused. The Pacific Island Forum states made a particularly substantive contribution, grounding abstract security concepts in lived national experience and consistently advocating for practical, cooperative outcomes. The strong alignment between small island developing states and major powers on the importance of submarine cable protection offered a potentially productive area for early concrete action [S149][S150].
At the same time, deep geopolitical divisions – most visibly between Western states and Russia on attribution, and between Iran, Israel, and the United States on the characterisation of recent military and cyber operations – introduced a confrontational dynamic that consumed significant time and risked overshadowing substantive progress. The Chair’s procedural interventions reflected the difficulty of managing these tensions within the constraints of a first substantive session. The mechanism’s success will ultimately depend on whether the areas of genuine consensus – on threats, on the need for capacity building, and on the action-oriented purpose of the DTGs – can be channelled into practical outcomes that deliver real security for all states, regardless of size or geopolitical alignment.
—
Chair Egriselda López
We are about to begin. So please take your seats. The third meeting of the substantive plenary session of 2026 is the Global Mechanism on Developments in the Field of Information and Communication Technologies and Advanced Responsible State Behaviour. Good morning, delegates. As I announced yesterday, we first of all need to complete the list under current and potential threats. We need to complete the list under current and potential threats. We have 30 remaining requests on this list. So, as I indicated yesterday… while there is no established limit for delivering statements it would be appreciated if you could deliver an abridged version and submit the full statement to eStatements and also to the chair’s team this would help us hear all delegations and also just for reference we are going to be projecting a timer on the screen let us proceed then with the list of speakers as it stood yesterday and so I am going to give the floor to the first five speakers, they are Egypt, Kiribati, New Zealand Tonga and Kingdom of the Netherlands Egypt, you have the floor
—
Egypt
Thank you Madam Chair, good morning to all colleagues first allow us to congratulate you on the smooth moderation and sharing of the session and as the topic we are discussing I have a few points to share first, each views threats that they are not specific to certain regions or countries all countries and regions have equal rights to see the challenges and threats they deem as national priorities to be reflected and discussed equally in the plenary and in the thematic groups for the second point, discussions of those threats in the dedicated thematic groups cannot go business as usual and cannot be a replica or mirror the discussions of those threats in the plenary because this will not only be a waste of time but it will also be a missed or very useful opportunity for all delegations for this to happen Egypt is of the view that we need to focus on two main aspects on how we discuss threats first, the discussions should be dynamic based on real case scenarios where we discuss a threat from all aspects first by analyzing it and then seeing how to deal with it in coordination with the national authorities regional authorities and even seeking help for international cooperation And the second aspect, and we deem this aspect as the most important factor in discussing those threats, is that we have to compile and agree on a pool of experts that will help us in those discussions. Having discussions on threats without a professional, experienced, and relevant pool of experts is, again, a waste of time. So it’s our view, again, that discussions on threats in the dedicated thematic groups should be based on a proper and accepted pool of experts by delegations. This is not to say that we will use certain tactics to block certain experts we don’t want to see. Consensus is the key. That’s true. We should put in our minds that the bigger picture is to have a relevant pool of experts to help us, as diplomats, understand the threats, and produce tangible outcomes. Thank you, Chair.
—
Chair Egriselda López
Muchisimas gracias. Thank you very much. I now give the floor to Kiribati.
—
Kiribati
Madam Chair, I will be very brief. Kiribati aligns itself with the statement delivered by the Kingdom of Tonga on behalf of the Pacific Island Forum members and offer the following remarks in its national capacity. Madam Chair, this is the first substantive session of a permanent mechanism and this is no small thing. For years, our collective work on ICT security has moved from one limited time process to the next, while the threats we face have never bossed between them. This mechanism gives us, at last, a standing omen for this work. Kiribati welcomes that permanence and we encourage that this mechanism encourage that this mechanism was designed to be action -oriented. We intend to hold it and ourselves to that standard, beginning with how we treat the threats before us. Madam Chair, the threat landscape is not abstract for Kiribati. Last year, the East Micronesian Cable landed at Tarawa, the first submarine cable ever to reach our capital, connecting Nairo and the Federated State of Micronesia. This connectivity is transformative. It underpins our Digital Government Master Plan and our delivery of services across some of the most dispersed highlands on Earth. But we are clear that every step forward in connectivity is also a step forward in exposure. For a nation served by a small number of cables, landing stations and satellite links, critical infrastructure protection is not one threat among many. It is excessive. Existential. damage to or disruption of our submarine cable whether by malicious cyber activity or otherwise will not degrade our services it will sever them we are equally concerned by the threat that arrives first for our newly connected communities cyber enabled fraud and scams phishing, ransomware against government system and online harm directed at our children these threat to not distinguish between large and small states but they impact for others on those with the least redundancy and the thinnest technical workforce Kiribati is not standing still our cyber crime act 2021 our digital government act 2023 which established our national cert and cyber security mandate of our digital transformation office Our Data Protection Act 2025 and our new Cybersecurity Act 2026 form the legislative backbone of our response, building on our national cybersecurity strategy. This is what a small state can do with its own hand. But national action has limits that only cooperation can overcome. And cooperation is the very reason these mechanisms exist. Madam Chair, our ask is simple. We make it in the spirit of a first session that should set the tone for all that follow. Discussion of threats must not end as descriptions of threats. Each threat identified in this room should connect to a concrete step. Through this plenary and through the dedicated thematic groups or DGGs in December, that leaves every state, including, the smallest that are able to prevent, detect, and respond. If this mechanism can do that from its very first session, it would have proven its worth not only to the state in this room but to every community that depends on
—
Chair Egriselda López
Muchisimas gracias. Thank you. I now give the floor to New Zealand.
—
New Zealand
Thank you Chair. We support the statement by the Kingdom of Tonga on behalf of the Pacific Islands Forum and offer some additional remarks in our national capacity on three aspects of the threat environment. First, as elsewhere, ransomware continues to have serious consequences as New Zealand with opportunistic actors impacting organisations in all sectors of the economy. We have spoken out publicly on some ransomware incidents as have others in the Pacific who have also been affected by ransomware affecting the healthcare sector. Second, we have heard many delegations speak on the need to protect the cyber security of critical infrastructure. This is something we are working to address domestically at the moment In doing so, we are studying closely the steps that others in this room have taken as we look to learn lessons that we can apply in our own context This is an example of why we continue to value exchanging information on threats and best practice in addressing them We hope that discussions in the DTGs can also serve this function Finally, artificial intelligence is rapidly transforming the cyber security landscape We welcome the opportunity to hear how others are seeing AI affect cyber security risks and what they are learning about how this powerful technology can support cyber security defence We also note that there are a variety of other UN processes that are actively grappling with questions related to artificial intelligence including governance issues It’s important that the global mechanism does not duplicate those processes Instead, it should only focus on the issues that it is uniquely well placed to add value and not on the issues that it is not focused on namely in building shared understanding of the implications of AI for cyber security Thank you.
—
Chair Egriselda López
Thank you very much. Thank you very much. I now give the floor to Tonga to be followed by Netherlands, Bahamas, Iran and Australia.
—
Tonga
Thank you, Madam Chair. Tonga aligns itself with the statement delivered by my colleague on behalf of the Pacific Islands Forum members and offers the following remarks in its national capacity. Madam Chair. Chair, when the mechanism discusses threats, Tonga does not speak abstractly. We speak from memory. In January 2022, the eruption of Hunga Tonga Hunga Haapai severed the single submarine cable connecting our kingdom to the world. For weeks, Tonga was silent. Cut off at the very moment we most needed to call for help, coordinate relief, and reassure families abroad that their loved ones were safe. Our other islands waited far longer still. This was nature’s work, but we asked this room to consider that we learned what we learned, everything a volcano did to Tonga by accident, a malicious act it could choose to do deliberately. This is why Tonga regards the sabotage of submarine cables and other critical infrastructure not as a distant scenario, but as one of the gravest threats before this mechanism. It is why we joined the 2024 Joint Statement on the Security and Resilience of Undersea Cables and why we urge all states to treat the protection of this infrastructure against intentional and unintentional damage alike as a shared responsibility under the framework of responsible state behavior. Our concern with man -made disaster is that it is a problem that we cannot solve. This is why we are not confined to the seabed. In June last year, a ransomware attack encrypted our national health information system, holding the medical records of our entire population to ransom, and forcing our hospitals back to pen and paper. Our state -owned telecommunications provider was attacked in 2023. These incidents against the essential services of a small state show that no country is too small or too remote to be targeted. But Tonga’s experience also shows what cooperation can achieve. With the support of partners, our health systems were restored and services maintained. And this year, together with Australia and New Zealand, Tonga jointly attributed the attack on our Ministry of Health to an affiliate of a known ransomware group, demonstrating that even the smallest states acting with partners can pursue accountability for malicious cyber activities. Madam Chair, Tonga’s message on FREX is therefore simple. we have lived the disconnection others theorize about and we have endured the attacks others read about we ask that this mechanism honor that experience by ensuring that every threat discussed here is matched by practical cooperation to prevent it withstand it and respond to it for all states of every
—
Chair Egriselda López
thank you very much I now give the floor to the Netherlands
—
Netherlands
thank you Madam Chair the Kingdom of the Netherlands aligns itself with the statement delivered by the European Union and please allow me to make some further comments in my national capacity over the course of last year the Kingdom of the Netherlands has observed a steady increase in the scale sophistication and diversity of cyber incidents affecting our society Attacks range from ransomware to disruptive DDoS campaigns and exploitation of vulnerabilities in edge devices and widely used software. These incidents impact our society at large, having implications for vital sectors like public administration, healthcare, education, transport and financial services, as well as for the many international organizations based in the Netherlands. Madam Chair, we would like to highlight three emerging threats. First, the Kingdom of the Netherlands considers the observed blurring of lines between state actors and non -state actors, such as activist groups, as one of the most problematic trends in the current threat landscape. Different types of actors increasingly use similar tools, target similar systems and sometimes operate in concert. This blurs the traditional distinctions between motives and methods and constitutes a worrying trend of state actors hiding behind state proxies to maintain plausible deniability. Second, in the last year, critical infrastructure has been repeatedly targeted and continues to face persistent risks. Especially the recent shift towards the targeting of means of communication, such as messaging services, is troublesome. As such, infrastructure underpins the functioning of almost all critical sectors. Compromises can enable large -scale espionage, manipulation of communications or disruptions with cascading effects far beyond the specific target itself. This underlines the need for continuous investment in resilience and secure architecture across all critical sectors, as well as structured dialogues in this context. Global mechanism and how to best protect our critical infrastructure from malicious cyber actors. The Netherlands is keen to engage with UN members to exchange best practices on the protection of critical infrastructure from a policy and operational perspective. And third, generative artificial intelligence amplifies existing cyber threats. Large language models and other AI systems can lower the barrier for conducting sophisticated operations. From writing convincing phishing messages to assisting in the discovery of zero -days, vulnerabilities, and their exploitations. With the use of agentic AI on the rise, the development of such threats continues to accelerate, making the threat landscape more complex by the day. These same tools can and should be harnessed defensively, for example, to improve detection, analysis, and response. Madam Chair, as the threat landscape that we collectively face continues to grow ever more complex it is through the adequate implementation of the consensus UN framework that we can try and we should try to inject a degree of predictability in global affairs Thank you very
—
Chair Egriselda López
Muchisimas gracias Thank you I now give the floor to the Distinguished Representative of the Bahamas to be followed by the Islamic Republic of Iran and then Australia Microphone for the Bahamas please Madam Chair Go ahead
—
Bahamas
Madam Chair As this is the first time I am taking the floor the Commonwealth of the Bahamas congratulates you UN Convention on the Rights of the People and the Rights of the People of the United States of America on your assumption of the chair of the inaugural global mechanism and offers its full support for your role, mandate, and vision. We look forward to working with you and alongside fellow delegates. The establishment of this global mechanism is a milestone. Built on years of work in the open -ended working group, and the Bahamas is committed to building on that foundation and to ensuring it delivers real security for those most exposed by digital risk. As a small island developing state, the Bahamas knows that cyber resilience is built through collaboration, cooperation, and coordination, but also through public -private partnership. But above all, it’s built, by people, and for people. It’s against this backdrop that we underscore three priorities. First, cyber threats to youth. Young people are the fastest adopters of digital technology and will live with the consequences of decisions made in this room. The Bahamas supports deliberate efforts to engage youth in capacity building, training, and dialogue on ICT security. Second, cyber threat to women. We call for concrete attention to technology -facilitated gender -based violence, including online harassment and image -based abuse, which disproportionately target women and girls and threaten both their safety and their participation. Therefore, participation for women is not complete unless women are at the table, in delegation, in technical decision -making, and in the design of national ICT policies. We support continued effort to close the gender digital divide. Third, capacity building. For small island developing states, capacity building is a precondition for participation. It must be sustained, tailored to national circumstances, and directed towards durable institution and a trained workforce, so that developing states can be genuine contributors to global ICT security, not just recipients of it. Madam Chair, the Bahamas welcomes this. We have dedicated thematic groups as a platform for translating dialogue and practical outcomes, including identifying capacity building needs and ensuring developing countries participate meaningfully. In the threat landscape, the threat landscape is a pressing concern for us. Our economy depends on digital -enabled sectors, for example, tourism, financial services, port, and maritime logistics. So we’re faced with ransomware, cybercrime as a service, attacks on our critical infrastructure, AI -enabled fraud, the mis – and disinformation, and very importantly, the nexus between cyber threat and natural disaster. They all carry consequences for small island states that are disproportionate to our size. In response, we have launched the National Computer Incident Response Team in December 2023, adopted a national cybersecurity strategy, and in 2024, our Data Protection Act in 2025, and we are advancing a national cybersecurity bill and a child online protection strategy. We recommend that cyber threat discussions remain grounded in the operational experience of national CERTs and C -CERT networks, that cyber threat information sharing be genuinely accessible to small island states, and that this work stay connected to capacity building. Finally, Madam Chair, international law, including the UN Charter, is the foundation of a secure and peaceful ICT environment. It is the guarantee of this process, not a constraint to it. Voluntary norms and confidence -building measures operate in service of a binding legal obligation, not in place In closing, the Bahamas calls on the global mechanism to keep international law meaningful, inclusion, and sustainable capacity building at its center to advance a secure and stable ICT environment for all. I thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much for that statement We will now hear from the representative of the Islamic Republic of Iran You have the floor
—
Islamic Republic of Iran
Madam Chair, distinguished colleagues Over the past year, the United States and the Israeli regime have carried out unlawful military attacks against the Islamic Republic of Iran These acts of aggression resulted in the loss of thousands of innocent lives including hundreds of women and children and caused widespread destruction of civilian infrastructure These unlawful attacks were accompanied by extensive malicious cyber operations directed against Iran’s critical infrastructure and civilian services disrupting the daily lives of our people and the functioning of essential services While my delegation has addressed the kinetic dimension of these attacks in other relevant international issues and international forums This forum provides the appropriate platform to address their cyber dimension. During the February 2026 aggression alone, more than 100 cyber attacks were launched every day against Iran’s critical and civilian infrastructure. These operations include, in their inter -area, first, coordinated cyber and kinetic attacks targeting critical ICT infrastructure, including telecommunications facilities, data centers, artificial intelligence infrastructure and private sector electronics and ICT manufacturing plants. Critical sectors affected included the banking and financial system, telecommunications networks, energy facilities, fuel distribution systems, industrial control systems and other infrastructure providing essential public services. Second, cyber attacks against civilian institutions and essential… services, including schools, universities, media, and broadcasting infrastructure, and digital platforms supporting education and public communications, with the aim of disrupting public services and the daily lives of ordinary civilians. Third, attacks exploiting private sector technologies and ICT supply chains, including commercial ICT products and services, software, hardware, and digital supply chains, as well as the misuse of Starlink satellite communication services to facilitate hostile operations. My delegation is also concerned by cyber operations exploiting commercial technologies, including products and services supplied by companies such as Cisco and HP, to undermine the security and resilience of national ICT infrastructure. Fourth, cyber espionage and information operations, including attacks against telecommunication networks. a long time. I’ve been in the United States for a long time. the unlawful use of mobile interception technologies, cyber -enabled surveillance, disinformation and cognitive operations, and the manipulation of digital platforms, including Instagram, X, and Telegram, to incite violence, spread hatred, deepen social divisions, and arbitrarily restrict or remove accounts associated with the Islamic Republic of Iran. Fifth, electronic warfare and hybrid operations, including cyber -enabled support for military operations, interference with communications and satellite navigation systems through jamming and GPS spoofing, and the integration of cyber capabilities with conventional military attacks. States that consistently advocate respect for the Charter of the United Nations include international law and the Framework for Responsible Security. The State’s behavior in ICTs should apply those principles consistently and condemn such kinetic and malicious cyber activities directed against the Islamic Republic of Iran. The United States and the Israeli regime must be held accountable for these violations Madam Chair, the experiences of my country particularly those arising from the unlawful cyber and kinetic attacks carried out by the U .S. and the Israeli regime underscore the need for a more comprehensive and shared understanding of existing and emerging threats While the OEWG made important progress there is still no common understanding that fully reflects the security concerns and experience of all member states From the outset of the OEWG process a number of states, including my own identified specific ICT -related threats that were ultimately not reflected in the consensus reports Addressing these gaps should therefore be a priority for the global mechanism In our view, the global mechanism should first give view attention to the threats already identified by member states before expanding discussions on new threat areas We therefore support the preparation under your authority of a consolidated compilation of the threats identified by Member States and reflected in the first OEWG Chair Summary. As the basis for discussions in both the plenary and the dedicated thematic groups, we debut to develop practical cooperative measures to prevent and address such threats. In this regard, my delegation wishes once again to draw attention to a number of threats previously identified by Iran, including the weaponization of the ICT environment, monopoly in Internet governance, false flag operations and fabricated attribution, the use of ICTs for for disinformation and cognitive operations, unilateral coercive measures in the ICT domain, and the responsibilities of private sector entities and digital platforms whose activities have extraterritorial impacts. I thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much I now give the floor to the delegation of Australia to be followed by Japan, Guyana, Greece, the United States and Tuvalu Australia you have the floor
—
Australia
Thank you, Chair. Australia aligns itself with the statement delivered on behalf of the Pacific Islands Forum and would like to make a few comments in our national capacity. As we begin the work of the global mechanism, our discussions on threats should… current, evidence -based and connected to practical implementation of the framework of responsible state behaviour in cyberspace. The cyber threat environment continues to intensify. Individuals, businesses and governments continue to be adversely affected. Those threats can expose sensitive information, disrupt essential services, undermine trust and economic prosperity and contribute to the risks to international peace and security. These threats are real. Last year the Australian Cyber Security Centre responded to over 1 ,200 cyber security incidents and received more than 84 ,700 cybercrime reports, roughly one report every six minutes. No country is immune to persistent threats. These include state -sponsored activity targeting government, critical infrastructure and businesses, ransomware and cybercrime as a service. business email compromise, identity fraud and exploitation of edge devices and systems. This mechanism should help states understand how these threats affect us, the practical steps that reduce risks and how international cooperation can support mitigation, preparedness and response. The tools already available to us, international law, the norms of responsible state behaviour, confidence building measures and effective capacity building are well placed to help states meet these threats in a practical and coordinated way. Critical infrastructure and critical information infrastructure protection should be an early focus for this mechanism, including through DTG1. For many countries, including our own in the region, the resilience of undersea cable infrastructure is fundamental to economic and social connectivity and to access to the global environment. Global Internet. The mechanism should also help states understand and respond to the ways emerging technologies are changing the scale, speed and character of malicious activity. Artificial intelligence is being used to scale social engineering, create more convincing phishing content, analyse stolen data and lower the cost and skill barriers required to cause harm. Australia is particularly concerned that AI is making it easier for malicious actors to generate and spread propaganda and to prepare to carry out physical strikes by supporting planning and target selection. As capabilities advance, AI may also enhance the ability for malicious actors to coordinate complex activities that combine physical and digital elements. Australia underlines the importance of responding to these threats in line with the agreed norms of responsible state behaviour. State responses, including the development and use of cyber capabilities, must be consistent with international law, including the UN Charter in its entirety, international human rights law and international humanitarian law. All states must be supported to build capacity to implement the framework and respond to the threats they are facing. Cyber threats are shared, but their impacts are not experienced equally. Differences in national capacity can affect vulnerability to malicious cyber activity and the ability to recover when incidents occur. Australia looks forward to working with all states, as well as you, Chair, to ensure that our discussions on threats, particularly within the DTGs, remain current, practical and
—
Chair Egriselda López
Thank you very much. Japan, you have the floor.
—
Japan
Thank you, Madam Chair. As cyber threats have continued to grow due to increasingly sophisticated and complex methods of cyber attacks, ensuring a free, fair and secure cyberspace, based on the rural roles has become indispensable for all member states. In addition, with the advancement of frontier AI models responding to malicious cyber activities, that leverage AI is also an urgent challenge, while AI models also provide opportunities for cyber defense. In cyberspace, attackers hold an overwhelming advantage. It is important to have broad discussions on a wide range of approaches, from efforts to create an environment where attackers find it more difficult to operate, to efforts by defenders to rise the cost of cyber attacks through improved security. Focusing on critical infrastructure, Japan recognizes that cyber attacks using ransomware, particularly when they impact, the operations of critical infrastructure, such as hospitals and power plants, can pose a threat to international peace and security. For example, at the Security Council briefing on ransomware on November 8, 2024, Japan stated that, quote, ransomware is one of the most destructive cyber threats undermining the operations of critical infrastructure in society, including hospitals and power plants. Given the overall impacts and ramifications, ransomware could certainly pose direct threats to international peace and security, quote. Japan would like to foster this kind of common understanding on existing and potential cyber threats in the UN global mechanism. Lastly, in conducting such discussions, it is essential to draw on the expertise of a wide range of stakeholders, including the private sector. Japan also places great importance on holding expert briefings and interactive public -private discussions in the substantive plenary sessions and DTGs. I thank you,
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Guyana.
—
Guyana
Thank you, Madam Chair. At the outset, Guyana congratulates you on your appointment as Chair of the Global Mechanism and ICTs and assures you of our full support. Guyana believes that discussions on existing and potential ICT threats in the context of international security are critical as we advance the framework for responsible state behavior in the use of information and communications technologies. The ICT threat landscape is evolving rapidly due to growing developments in ICT capabilities. Without concomitant oversight and governance structures. Effectively addressing existing and potential threats requires integration of security considerations. across the lifecycle of ICT products. While acknowledging the benefits of using ICTs for development, Guyana is concerned about the malicious use of ICTs, which can undermine peace and security, erode trust among states, and constitute a violation of international law. We are particularly concerned about the malicious use of ICTs against critical infrastructure and critical information infrastructure and the use of this technology by non -state actors to exacerbate conflicts, including through attacks targeting civilian and civilian objects. A holistic approach is therefore required to address ICT threats, considering the multifaceted challenges and transboundary nature of these threats. Awareness, capacity building, international cooperation, public -private partnerships, and continued dialogue among relevant stakeholders are essential for detecting, defending, and responding to these threats. These efforts must be made at the national, regional, and international levels. At the national level, Guyana is building its ICT infrastructure, and we are strengthening our digital resilience and cybersecurity capabilities. In this regard, we have enacted legislation on data protection and cybercrime and have developed a cybersecurity policy framework. Ghana is also looking at establishing a cyber emergency response system to respond to cyber threats on a 24 -7 basis. And moving forward, Ghana recognizes the urgency of stronger cooperation and collaboration among states as we seek to address ICT threats in the context of international security. Ghana also stresses for continued multilateral engagement to generate awareness and address ICT threats towards promoting a safe ICT environment. I thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much. I now give the floor to Greece.
—
Greece
Madam Chair, first of all, I would like to thank you and your team for all your efforts so far facilitating a smooth transition. from the OEWG to the global mechanism. Once again, you have our full support in your endeavor to reach concrete outcomes. On the topic at hand, Greece aligns with a statement made by the European Union, and please allow me to make the following remarks in my national capacity. Distinguished delegates, we are witnessing a rapid evolving threat landscape where the misuse of emerging new technologies such as artificial intelligence, the growing prevalence of ransomware, and the proliferation of sophisticated cyber tools pose significant risks to international peace, security, and human rights. These emerging threats increasingly target critical infrastructure, public institutions, businesses, and individuals, often with cross -border consequences. While AI offers great potential for innovation and global progress, its misuse, such as through autonomous cyber tools and the recent advancement of frontier models, can amplify existing vulnerabilities and undermine democratic processes and human rights. These capabilities are expected to soon become widely available, and they significantly lower the entry barrier for actors to perform sophisticated attacks. In this context, last year, Greece, as an non -permanent member of the Security Council, organized an area formula meeting on harnessing a safe, inclusive, trustworthy AI for the maintenance of international peace and security. Another important topic relates to the proliferation of commercial cyber tools and capabilities. The commercial distribution of these capabilities has the potential to undermine privacy, human rights, democratic institutions, and international security when deployed without adequate safeguards. In this regard, we welcome initiatives such as the Paul Moll process, which seek to build international consensus on the responsible development, distribution, and use of commercial cyber intrusion capabilities. It is our view that the continued dialogue and cooperation of this topic can help strengthen accountability, transparency, and the development of shared principles that reduce the risk of misuse of these technologies. I thank you,
—
Chair Egriselda López
Thank you very much I now give the floor to the delegation of the United States to be followed by Tuvalu Zimbabwe, Albania and the Russian Federation United States you have the floor
—
United States
Thank you Madam Chair I would like to present now the national statement of the United States of America The United States is grateful for your leadership since the March organizational session and looks forward to the mechanism’s first substantive work under your stewardship As the global mechanism begins to move from procedure to substance the United States continues to approach it with the same objective we have carried since the OEWG grounded in practical implementation of the 11 consensus norms not a vehicle for new legally binding agreements As long as some members in this hall are maliciously conducting cyber actions against other members a legally binding agreement is impossible This mechanism is the successor to a working group in which the United States invested real effort to secure a non -binding, action -oriented outcome. This mechanism was established to do real work, to implement the commitments states have already made to confront the actual threats hitting our critical infrastructure every single day. Chair, states should not conduct or knowingly support malicious cyber activity targeting critical infrastructure. However, there are members in this chamber right now who are planning and conducting malicious cyber actions against other members’ critical infrastructure. Thank you, EU, Poland, Estonia, France, for pointing out these malicious actions. To Tonga and Kiribati, the United States hears you, and we thank you for your strong statements. While others in this chamber are planning and targeting you, The United States will be there to help protect you. The United States remains focused on the implementation of the consensus framework, holding states accountable to their consensus norms, strengthening resilience, and advancing concrete confidence -building measures. This is where we are directing our energy, and we invite every delegation to do the same. The United States sees DTG2’s work in particular as an opportunity for practical discussion of gaps in cyber capacity and how U .S. industry expertise can help close them, work that builds real security outcomes. Also, the United States is going to work to specifically identify the states and non -state actors who are perpetuating malicious cyber activities against others in this room. President Trump has been clear. If a country is utilizing the cyber domain to hurt others, in this chamber, the United States will make them pay a heavy price. our message is consistent and clear this mechanism succeeds by building on the consensus we already have not by searching for gaps that do not exist the United States will demand adherence to the consensus norms and the five pillars to ensure the cyber domain remains a secure and safe space for everyone freedom is not a characteristic but is an essential part of this mechanism finally, President Trump’s mandate is clear for those in this chamber who think the cyber domain is a venue to abuse and exploit others be warned the cyber domain is about to change and one last postscript to my Iranian colleague thanks for illustrating my point I’m glad you noticed the cyber domain is changing and like I said, President Trump is not going to stand idly by while the oppressive the oppressive Iranian regime seeks to destroy regional stability and the inalienable right of all Iranians
—
Chair Egriselda López
Thank you. Tuvalu, you have the floor.
—
Tuvalu
Madam Chair, allow me to begin by congratulating you and your team for your dedicated efforts in successfully conveying this first substantive session of the Global Mechanism on ICTs. Tuvalu aligns itself with the statement delivered by the Kingdom of Tonga on behalf of the Pacific Islands Forum State. Madam Chair, for Tuvalu, the United UN Framework for Responsive State Behavior in Cyberspace is not merely a diplomatic exercise. It is a fundamental statement. To our national security and local government, stability. As we finalize our national security policy and advance our digital nation initiative, ensuring sovereign continuity in the digital age, cybersecurity has become the cornerstone of our statehood’s resilience. Our approach is anchored in our core values. Through KITASI, our principle of communal stewardship, we recognize that safeguarding cyberspace is a shared responsibility. Complementing this, our practice of falafel or good neighbor lines drives us to uphold these norms as vital contributions to the peace and prosperity of our Blue Pacific continent. Madam Chair, cybersecurity isn’t just a technical safeguard. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development of security. It is a development that digital transformation governance and community outreach can thrive without disruption. However, policy commitments require operational execution to be substantive. Our engagement with regional partners, including the Pacific Security Operations Network, the Australian Cyber Security Centre, as well as the New Zealand and other partners supported Women in International Security and Cyberspace Fellowship, demonstrates that practical operational cooperation is the pathway to robust resilience. In line with the integrated approach of A-79-214 and A-80-257, Tuvalu emphasises that norms, international law and capacity building cannot be treated as separate silos. We urge this global mechanism to focus on the tangible, shared threat intelligence, clear protocols for protecting subsea infrastructure like Aotevaca Cable and the development of local expertise. Tuvalu stands ready to engage constructively to ensure that this mechanism serves as a driver of meaningful action that truly leaves no one behind. I thank you, Madam Chair. Thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Zimbabwe.
—
Zimbabwe
Madam Chair, Zimbabwe aligns itself with the statement delivered by the African group and wishes to make the following remarks in a national capacity. Zimbabwe congratulates you, Ambassador Lopez, on assuming the chair of the inaugural biennium meeting of the global mechanism. We assure you of Zimbabwe’s full support. Madam Chair, Zimbabwe welcomes the discussions under this pillar on existing and potential ICT threats in the context of international security. These deliberations, which are being conducted in the integrated, policy -driven and cross -cutting spirit envisioned under the five pillars of the Framework for Responsible State Behaviour, are essential reference points for our collective efforts. The threat landscape, as we observe it, is anything but static. Malicious ICT activity continues to grow both in scale and sophistication, evolving from isolated incidents into persistent and layered challenges that carry implications for international peace and security, sustainable development and the resilience of nations. My delegation is concerned by the rising frequency of ransomware attacks targeting critical infrastructure, interference with electoral processes, and the unchecked security of the international security system. We are concerned by the spread of disinformation and misinformation through digital platforms. We are equally concerned by the rapid advancement and malicious use of artificial intelligence, which is reshaping the cyber threat landscape, enabling more convincing deception and introducing fresh complexities for cybersecurity resilience and response. For developing countries, these threats are particularly acute. Capacity constraints and uneven cyber resilience increase our vulnerability and limit our ability to effectively respond to cyber incidents, risking progress towards digital transformation and sustainable development. We cannot afford to be left exposed, nor can we afford to be left behind. Madam Chair, Zimbabwe’s National Development Strategy 2 and National AI Strategy place digital transformation at the centre of our socio -economic development. As we continue to expand e -government, digital financial services and digital connectivity, protecting critical ICT infrastructure and strengthening cybersecurity resilience become national priorities. As a land -linked developing country that relies on interconnected regional telecommunications networks for connectivity, trade, and essential services, we recognize that vulnerabilities within shared digital infrastructure can have cross -border consequences. This reinforces the importance of enhancing regional cooperation and building the technical capacity of developing countries to prevent, detect, and respond to malicious ICT activity. We therefore support continued information sharing on emerging threats, the exchange of national experiences and best practices, and strengthened international cooperation to enhance collective resilience. Zimbabwe remains steadfast in its commitment to work constructively with all member states to promote an open, secure, and sustainable development of secure, stable, accessible, and peaceful ICT environment consistent with the purposes and principles of the Charter of the United Nations. Thank you.
—
Chair Egriselda López
Thank you very much. Now we will hear from the representative of Albania. You have the floor.
—
Albania
Thank you, Madam Chair, Excellencies, distinguished colleagues. Albania aligns itself with the statement delivered by the European Union and wishes to make the following remarks in its national capacity. Albania remains deeply concerned by the evolving threat landscape in the sphere of information and communication technologies. The current environment is characterized by increasingly sophisticated, persistent and coordinated malicious cyber activities targeting us, public institutions, critical infrastructure and citizens. As a country that has been directly affected by such activities, Albania attaches particular importance to the discussion on existing and potential threats to international peace and security. The scale and persistence of these activities are reflected in the recent national statistics. During 2025, Albania registered 51 cyber incidents with significant impact. In 2026, the volume of malicious activity and their sophistication has increased substantially. More than 17 million attempt cyber attacks recorded against Albanian system, critical infrastructure, public and private. While only nine incidents were ultimately classified as confirmed cyber security incident, the sheer volume of attempt attacks illustrate the intensity and the threat environment and the continued interest of malicious actor in targeting Albanian institution and critical infrastructure. Recent incidents, four of them only in March 2026, to the public institution, including Albanian parliament, Albanian post office, the office of the general prosecutor and the general director, the director of prisons, were supported by state -sponsored cyber operation on which we have always spoken publicly. A particularly concerned trend is the continued combination of cyber operations with information manipulation activities. Following above -mentioned incident, Albania observed attempt to spread disinformation and manipulate public perception through social media and communication platforms, specifically via Telegram. These activities sought to amplify the psychological impact of cyber incidents, generate public uncertainty, and erode trust in public institutions. They demonstrate that contemporary cyber threats are no longer limited to technical instructions, but increasingly combine cyber operations, disinformation, and influence activities. Other incidents recorded during 2026 include phishing, sphere phishing, and cyber attacks. These are the first of many incidents where cyber attacks are not only used to spread disinformation, but also to spread disinformation. These are the first of many incidents where cyber attacks are not only used to spread disinformation, but also to spread disinformation. These are the first of many incidents where cyber attacks are not only used to spread disinformation, but also to spread disinformation. These are the first of many incidents where cyber attacks are not only used to spread disinformation, but also to spread disinformation. These are the first of many incidents where cyber attacks are not only used to spread disinformation, but also to spread disinformation. These are the first of many incidents where cyber attacks are not only used to spread disinformation, but also to spread disinformation. These are the first of many incidents where cyber attacks are not only used to spread disinformation, but also to spread disinformation. These are the first of many incidents where cyber attacks are not only used to spread disinformation, but also to spread disinformation. Phishing and smission campaigns remain among the most widespread threats affecting both institutions and citizens directly and forming part of broader campaign targeting user and organization across multiple countries. A further area of growing concern for Albania is the impact of militant online activity on young people. The rapid spread of disinformation, manipulation of online content, and cyberbullying through social media and digital platforms possess increasingly risk to the safety, well -being, and resilience of younger generation. The use of AI has made the ecosystem even more insecure and greater the exposure of the risk of young people who are more easily manipulated online. These phenomenon have the potential… to undermine trust in public information, fuel social polarization, and expose children and youth to psychological harm. As digital technologies become even more integrated into everyday life, addressing cyberbullying and the deliberate disinformation of false and misleading information targeting young people should should be considered an important element of our collective effort to promote security and stability in the cyberspace. In Albania’s view, these challenges represent not only a social issue, but also an emerging security concern that deserves greater international attention in the years ahead, but which should be addressed today. The threat faced by Albania, the region, and beyond reflect a wider international challenge. Malicious ICT activities are becoming more complex, increasingly combining technical compromise, theft of information, disruption attempts, and coordinated influence operation. These developments underscore the importance of ensuring the full implementation of the framework of responsible state behavior in cyberspace agreed by the United Nations. Ensuring the State Act responsibility in cyberspace, refrain from supporting malicious activities, and the cooperation in addressing threats is essential for preserving international peace, security, and stability in an increasing interconnected world. Albania remains fully committed to working constructively with the global mechanism and with all partners to strengthen the international cooperation, build trust and advance the implementation of UN framework for responsible state behavior in the cyberspace Thank you Madam Chair
—
Chair Egriselda López
Thank you very much. I now give the floor to the Russian Federation to be followed by the Philippines, France, Ukraine, Chile and Malawi.
—
Russian Federation
Madam Chair, with the rapid development of information communication technologies, including artificial intelligence, threats to international information security are growing in scale and becoming more acute. The greatest danger lies in the use of ICTs for purposes that contradict the UN Charter to undermine the sovereignty of states, violate their territorial integrity, and interfere in their internal affairs. In concrete terms, I propose discussing the following threats within the framework of the global mechanism at its plenary meetings and in the first dedicated thematic group. Monetization of the private sector. In recent years, the world has witnessed this dangerous trend in which major ICT developers, which supply their products throughout the world, including AI, present themselves as neutral, client-oriented, transnational corporations. Now, make no secret of how deeply they are embedded in the military-industrial complexes of the countries where they are registered. They often act as contractors for intelligence agencies and military departments, providing their developments for use in intelligence. and espionage activities. This situation predictably undermines trust in the products of these companies, but more importantly creates serious risks for international stability and security. The use of ICTs for offensive purposes. For many years there was a consensus within the UN that ICTs should not be used for purposes incompatible with the maintenance of peace and security. However, in recent years we’ve seen this consensus collapsing. A number of states are openly declaring and enshrining in their doctrinal documents a shift from purely defensive operations in the information space to offensive ones. This is a threat to global security and to the national security of developing states in particular. The issue of undeclared malicious capabilities. Unfortunately, the international community is increasingly confronting the problem of so -called backdoors. At the software and hardware levels embedded by developers in the interests of intelligence agencies without notifying end users. Such tools are used for intelligence, espionage, interception of personal data and private correspondence. And as shown by the infamous Pager incident in Lebanon in 2024, they’re used for causing physical damage. Low -orbit satellite communication systems created under the pretext of providing reliable Internet connectivity for civilian purposes. These technologies are, in fact, used for military -political objectives in the interests of certain countries. We’re well aware of cases in which such systems have been used to interfere in the internal affairs of states by inciting protests, as well as their use in armed conflicts. This topic, that is, the risk of uncontrollability. The risk of uncontrolled use of low -orbit satellite communication systems was discussed at an informal U .S. Security Council Area Formula meeting in December 2025. We are convinced that to address this problem, low -orbit satellite communication systems operators must act in strict accordance with the national legislation of the countries in which they provide their services. Madam Chair, now I’d like to make a statement as invited reply. During the discussion of this agenda item, a number of delegations made outrageous anti -Russian remarks. We strongly reject these false and fabricated accusations against my country. Let me recall that in accordance with UNGA Resolution 73 27, both accusations of organizing and implementing wrongful acts brought against states should be substantiated. Of course, as in all family cases in the past, no evidence has been provided. Thank you. neither in public nor bilaterally, nor have the existing channels for identifying the true sources of malicious activity been used. And this includes the UN Points of Contact Directory, to which all countries that have joined this campaign of accusations are parties. There is only one conclusion to be drawn. Either no evidence exists or the incidents never happened at all. The purpose of such blatant disinformation is to portray Russia as a threat in the information space in order to serve the Russophobic policies of the governments of these states. The real threat to international information security comes from the West. Let me recall that it is NATO countries that have recognized cyberspace as a theater of military operations. It is NATO and its members that are building up offensive digital capabilities and conducting computer operations against Russian critical information infrastructure in regular drills. I also note the hypocrisy of NATO’s member states which not only turn a blind eye to numerous crimes committed by the Ukrainian hackers against Russian citizens and Russian civilian critical information infrastructure, but also provide them with all possible assistance. In closing, Madam Chair, I would like to mention your call to shorten the duration of statements. We fully understand the reason behind this. You’d like to ensure that all delegations willing to speak have the floor. Unfortunately, this is largely due to the irresponsible behavior of certain delegations who are wasting our precious time on politicizing the discussions. We consider such an approach to be unacceptable and call upon you, Madam Chair, to prevent the discussions within the global mechanism from turning into a political crisis. Thank you.
—
Chair Egriselda López
Thank you also to all of you for cooperating as regards the very limited time that we have for these interventions. I thank you also for a very productive meeting today. We have taken note of the reply, but we would indicate that this should be done at the end of the meeting so that every delegation wishing to speak in their national capacity may be able to do so. And then if any delegation wishes to speak under the right of reply, they should make the request to the Secretariat so that this speaking time can be requested at the end of the list of the speaker as was done in prior meetings of this group. So now we will continue with the list. I will just read out who the next speakers are. Philippines, Ukraine, Chile, and Malawi. Philippines, you have the floor
—
Philippines
Thank you again Madam Chair As the Philippines noted during the organizational session last March implementation remains central to the success of this mechanism As we commence its substantive work we remain committed to working constructively with all member states and encourage the same spirit of cooperation from all The cyber threat landscape continues to evolve in skill and sophistication. Ransomware attacks against critical information infrastructure, cyber espionage, cyber -enabled criminal activities, and the malicious use of emerging technologies continue to challenge national resilience and international security The Philippines believes that the value of the agreed framework lies in its effective implementation At the national level, we continue to strengthen our cyber security posture through enhanced coordination across government, cyber threat information sharing, incident response, and partnerships with the private sector private sector, academia, civil society, and international partners. The National Cyber Intelligence Network serves as the country’s cyber intelligence center, enabling trusted information sharing, coordinated situational awareness, and collaborative response, while contributing to regional and international cybersecurity cooperation. In addition, the proposed Cybersecurity and Critical Information Infrastructure Protection Bill, which remains part of the country’s priority legislative agenda, reflects our continuing efforts to strengthen national resilience. The Philippines recognizes that existing international law provides an important framework for responsible state behavior in cyberspace. Continued dialogue under this mechanism should promote practical exchanges on national implementation while respecting differing legal systems, levels of technological maturity, and national circumstances. Confidence -building and capacity -building remains a priority. remain essential to translating our commitments into practice. As a CN chair in 2026, the Philippines remains committed to advancing regional cybersecurity cooperation through cyber exercises, operational collaboration, and the exchange of best practices. We likewise support capacity building that is demand -driven, nationally owned, sustainable, and responsive to the differing needs of member states. In this regard, we appreciate the continued support of international partners, including UNIDIR, whose technical engagements have strengthened national expertise and participation in the evolving UN cyber dialogue. We also welcome initiatives such as the ITU Academy’s H .E .R. CyberTrack program, which helps strengthen technical expertise, promote inclusivity in international cybersecurity discussions, and contribute to sustainable national capacity. The Philippines has benefited immensely from their technical assistance. Madam Chair, among the evolving cyber threats confronting all member states, the Philippines wishes to highlight ransomware as an area where practical implementation and international cooperation can deliver immediate benefits. Addressing ransomware requires timely information sharing, strengthened incident response capabilities, public -private partnerships, technical assistance, and sustainable capacity building. As we continue to enhance our national legal, policy, and institutional frameworks, we recognize the value of cooperation that is demand -driven, respects national ownership and sovereignty, and responds to the priorities of member states. Given the transnational nature of ransomware, continued cooperation among member states remains essential to strengthening collective resilience. The Philippines remains committed to practical implementation, inclusive dialogue, and consistent space outcomes. We look forward to working with all member states to ensure that this mechanism delivers meaningful, practical results that
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Ukraine to be followed by Chile.
—
Ukraine
Thank you, Madam Chair. Ukraine aligns itself with the statement delivered by the European Union and would like to add some points in our national capacity. We continue to witness an increasingly complex and dangerous cyber threat landscape. Malicious ICT activities have become more frequent, more sophisticated, and more destructive. They increasingly target critical infrastructure, public institutions, and essential services and democratic processes, while highlighting the importance of the ICT environment. We continue to witness hybrid campaigns combining cyber operations, disinformation, and cyber security. and economic coercion seek to undermine international peace and security. At the same time, rapid technological developments, including artificial intelligence, quantum technologies, and increasingly interconnected digital ecosystems, create unprecedented opportunities for innovation, while simultaneously expanding the attack surface available to malicious actors. As cyber threats do not respect national borders, no state is immune from their consequences. These developments underscore the need for the international community to strengthen cooperation, improve resilience, and ensure the effective implementation of the cumulative framework developed through previous UN processes. Chair, Ukraine experience clearly demonstrates that malicious ICT activities are not just theoretical risks. Besides the threats that were broadly described in the interventions by the distinguished representatives of Nigeria, Portugal, Italy, Karabakh, Turkey, Switzerland, Albania, and many others, our threat landscape continues to be determined also by an actor that has a malicious intention as the essence of its attitude towards my country and its partners. For over a decade now, cyberspace remains one of the principal theatres of Russia’s ongoing war of aggression against Ukraine. Russian malicious ICT activities are not isolated incidents, but form part of the broader strategy that combines cyberattacks with kinetic strikes, disinformation campaigns, and other hybrid warfare tools. Since the beginning of its full -scale invasion, Russia has deliberately targeted public authorities, critical infrastructure and energy sector, telecommunications networks, state registries, and private businesses in Ukraine and beyond. Thus attempting to undermine the very idea of the current global mechanism. Over time, its cyber operations have evolved from destructive attacks into sophisticated campaigns involving attempts for cyber espionage, long -term network persistence, supply chain compromise and information manipulation. This activity forced the international community to impose the restrictive measures, sanctions against the individuals and entities as a manifest of protest against their malicious behavior that undermines the security in the use of ICTs and on the global scale. Ukraine’s experience of being a target of long -lasting, unprovoked and unjustified aggression by a neighbor state clearly demonstrates that cyber operations have become an integral component of modern warfare, producing tangible humanitarian, economic and security consequences. And it is only a matter of time that this strategy can be used against any member of the international community. Chair, despite systematic cyber attacks, Ukraine has preserved its functioning. of its digital state while continuously strengthening its national cyber resilience. Still, we believe that acts of deliberate cyber aggression should not be tolerated by the international community. In this respect, it is important that responsible states would join and coordinate their efforts to modernize instruments for countering hybrid threats, strengthening strategic communication, improve cyber threat intelligence sharing, reinforce international deterrence mechanisms, and ensure that malicious actors are held accountable for violations of the international law and the agreed framework of the responsible state behavior in cyberspace. Ukraine remains fully committed to constructive engagement with the global mechanism and looks forward to working with other delegations to ensure that this process delivers practical and meaningful outcomes that enhance international peacekeeping. Security and stability in
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Chile.
—
Chile
Thank you very much, Madam Chair, for our country. This pillar is an area of priority in the global mechanism. Adequate understanding of the threats is an indispensable prerequisite in order to join forces to ensure the responsible behavior of states. Chile believes that malicious threats in cyberspace can constitute a series of threats to international peace and security. Their effects can vary considerably between states depending on their institutional capacity and on the security and resilience of their infrastructure and services. We know with concern that the threat landscape continues to evolve in terms of scale, velocity, sophistication and capacity to generate cross -border impacts through malicious activity aimed at infrastructure and essential services. For this reason, for Chile, the protection of critical infrastructure represents a national priority and an essential component of international security in the use of ICTs. The gradual digitization and interconnection of critical sectors increases the possibility of attacks and the risk of cybernetic incidents having systemic effects in this way impacting the provision of services that are essential for the population. In certain cases, this can have direct consequences on economic stability and on the functioning of our societies. And this is why… …the strengthening of… of the resilience of critical infrastructure must continue to be a priority for this global mechanism. Chile also has noted with attention how emerging technologies continue to generate new vectors and vulnerabilities that can be exploited for malicious ends. In particular, AI is changing the reach of malicious cybernetic attacks and making it easier for them to adapt without prejudice to the important benefits of these technology offices for development. It’s important for us to have a better understanding of its implications for international security and to strengthen cooperation between states in order to tackle with the results of malicious use of AI. They are also contributing to the expansion of phishing attacks, malicious software and increasing the sophistication of cybernetic attacks and also fostering the dissemination of manipulated contact. AI must be understood in this context as having the potential to multiply existing threats and also as a source of new risk factors and vectors. We also believe it is necessary, Chair, to keep attention on ransomware and other destructive forms of malicious software, the exploitation of the digital supply chain, cloud -connected software and future risks related to quantum computing, amongst others. These topics have already been identified by my country as topics requiring continued attention. Chile believes that… I think it is necessary to dedicate to the message. group number one, aimed at policies and cross -cutting issues, gives us a particularly valuable opportunity for driving a regular, structured dialogue that is evidence based on the evolution of threats and their implications for international peace and security. This work should have a forward -looking approach as regards threats, with a view to identifying concrete areas for international cooperation in the area of cybersecurity. And to do this it will be essential to have the participation of experts, regional organizations, the scientific community, the private sector, as well as other interested parties. A substantive discussion on emerging threats requires us to incorporate evidence and information that very often lies outside of government. We unfortunately feel that the response to this continues to be uneven, and so the response must be closely linked to capacity building and the exchange of timely information and strengthening national response services to instance and development of effective mechanisms for technical and diplomatic cooperation. In this regard, Chile looks forward to actively contributing to the work of the dedicated thematic group and to a discussion that will allow us to need to a better understanding of the threats with a view to strengthening security, stability and international resilience. I thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Malawi to be followed by France.
—
Malawi
Madam Chair, Excellencies and distinguished delegates, the Republic of Malawi aligns itself with the statement delivered by Nigeria on behalf of the African group and thanks you and the co -facilitators for guiding our work. We also align ourselves with the interventions by the European Union, Portugal, South Africa, Saudi Arabia, Turkey, Singapore, Switzerland, Botswana, and Vanuatu. Particularly on the growing sophistication of cyber threats, the importance of capacity building, the protection of critical infrastructure, and the need for strengthened international cooperation. We have carefully listened to member states and not a broad convergence of views regarding the growing threats. Malicious ICT activities are becoming increasingly sophisticated, persistent, and transnational. The growing misuse of artificial intelligence, ransomware, supply chain compromises, attacks on critical infrastructure, computer emergency response teams, undersea cables, and cloud services, demonstrates that no state is immune. However, Chair, The Republic of Malawi wishes to emphasize one additional concern. It is not only the emergence of these threats that should concern us, but their persistence. Persistent and covert malicious ICT activities can remain undetected for extended periods of time, gradually undermining public trust, disrupting essential services, weakening national resilience, and causing significant economic and societal harm. For many developing countries, just like Malawi, responding to one cyber incident is already difficult. Responding to sustained campaigns is an even greater challenge. As reaffirmed in successive reports of the UN GGEs and the Open Ended Working Group, international law, including the Charter of the United Nations, applies to the use of ICTs by states. We also reaffirm the voluntary norm that states should not knowingly allow their territory to be used for internationally wrong acts using ICTs. Madam Chair, we therefore cannot discuss these threats without discussing our collective ability to respond to them. National capacities remain uneven. Many developing countries continue to face shortages of skilled professionals, digital forensic capabilities, sustainable financing, and technical resources. In this regard, the Republic of Malawi believes that strengthening national computer emergency response teams, enhancing cyber threat intelligence, promoting early warning mechanisms, and improving trusted information sharing should feature prominently in the work of the development of a comprehensive and dedicated thematic group. resilient response capabilities are just as important as resilient infrastructure. On artificial intelligence, my delegation recognizes both its opportunities and its risks. Artificial intelligence can significantly strengthen cyber defense through automation, vulnerability management, and threat detection. At the same time, it is lowering the barriers for malicious actors to conduct phishing, malware development, fraud and disinformation at unprecedented speeds and scale. Our discussions should therefore focus on enabling responsible innovation while preventing malicious use. Finally, Madam Chair, as recognized in the 2025 OEWG Final Report, capacity building must remain sustainable, demand -driven, and tailored to the needs of state. If this global mechanism is to be implementation -oriented, our discussions should move beyond identifying threats and more towards strengthening the capacities, institutions, and
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of France to be followed by Germany and Latvia.
—
France
Madam Chair. Madam Chair, colleagues, my delegation aligns itself with the statement delivered by the European Union, which is to add the following remarks to its national capacity. We have noticed three trends directly impacting our work in the global mechanism. First, the first trend is the gradual blurring of boundaries between state and non-state actors in cyberspace. Throughout 2025, the threat to landscape and affiliations became increasingly difficult to discern. The boundaries between state-sponsored acts and cyber criminals are blurring, and the use of proxies by nation-states is spreading. Certainly, the threats posed by state-sponsored actors remain significant. They continue their efforts in espionage and destabilization within a context of escalating global geopolitical tensions. On the 13th of July, France announced that it had been the target for more than 10 years of persistent cyber attacks carried out by the Russian Federal Security Service, the FSB. Contrary to what the Russian Federation has stated, this attribution process was conducted in accordance with the norms for responsible state behavior and following having exhausted appropriate channels. Beyond purely state-sponsored activities, the threat is becoming increasingly widespread, originating from commercial activities on scrupulous individuals or individuals claiming ideological motivations. Naturally, no one is fooled. Behind these disguises, the intention to destabilize remains the same. This is why on the 13th of July, the EU adopted new sanctions against actors from the Russian cyber threat ecosystem, whose activities… Russia either uses or actively tolerates from its territory in violation of the framework for responsible state behavior in cyberspace. the second trend relates to the opportunities and concerns raised by the increasing capabilities of AI models in the field of cyber security while not yet fundamentally altering the nature of attacks AI is increasing the speed at which malicious actors can conduct offensive operations it also enables the scaling up of existing practices such as seeking vulnerabilities as is well known but more importantly the rapid increase in cyber capabilities of the AI frontier models carries the risk of a new digital divide the divide between those who have access to these models and everybody else between those who are able to independently assess the risks associated with these models and those who are not as recognized in the final report of the OEWG this perspective on risks associated with AI should not overshadow the opportunities that this technology offers to cyber security professionals as we have seen that we can collectively organise ourselves effectively. The mechanism must address these two aspects and delve deeper into how the framework for responsible behaviour applies to these issues and especially the voluntary norms. The thematic groups will provide a suitable platform for going deeper in our discussions, drawing on the relevant expertise of stakeholders including non-state actors. France will actively contribute to feeding into discussions on this topic within the DTGs. And finally, the third trend relates to the uncontrolled proliferation of cyber intrusion capabilities available on the market. This third trend, fuelled by the first two, is now a veritable ticking time bomb. Without minimal overhaul oversight and accountability measures, the number of actors, including non-state actors, capable of acquiring advanced capabilities will continue to grow. And in this way, it will multiply the risks to the stability of cyberspace. because of the urgency of the issue I would like to share with the members of the United Nations present here the progress that has been made with the United Kingdom as part of the Pall Mall process following the adoption in April 2025 of the Code of Good Practices for States this week we are launching negotiations on the guidelines for the cyber intrusion industry these voluntary documents aim to contribute to the implementation of a framework for responsible behaviour and especially Standard 13 Colleagues, Madam Chair the discussions on cyber threats targeting our states and societies are rightly at the heart of our UN discussions on cyber security they remind us of the often harsh realities that exist outside of these walls if it is to remain a… relevant tool, the new mechanism must be able to identify the evolving nature of these threats. The first thematic group can fulfill this role by focusing on one or two major trends in cyber threats that have an impact on international peace and security and by guiding our collective action to address them. I thank you.
—
Chair Egriselda López
Thank you. I now give the floor to the delegation of Germany to be followed by Latvia.
—
Germany
Thank you, Madam Chair. Germany aligns itself with the statement of the European Union and we will deliver the following remarks in our national capacity. Chair, we commence our discussion in the first binary of the global mechanism against the backdrop of a high level of global cyber threats which have been even further spurred by the rapid evolution of artificial intelligence and geopolitical tensions. The leading German digital business group estimates last year’s total damage of cyber attacks in Germany to be around 230 billion US dollars. dollars. This comprises state -sponsored cyber activities, economic espionage and cyber criminal activities. The severe impact makes clear why cybersecurity is a core element of Germany’s national security. Over the past year, Germany has experienced a continuously high level of ransomware attacks targeted especially at critical infrastructure providers, municipal and government services, but also not -for -profit organizations. For example, a ransomware attack paralyzed a leading humanitarian organization that provides food relief in conflict regions with risks of famine, putting people’s lives abroad at risk. In addition, Germany notes with concern the virulence of politically motivated hacktivist activities both in Germany and abroad. Over the past year, Germany also observed a 25 % increase in DDoS attacks, especially against government entities, public administration, the transportation sector and logistics companies. Attacks against industrial control systems and OT and critical infrastructures by politically motivated activist groups have the potential to threaten the stability of public safety, public order and human security. Such activities are also often aimed at attracting public attention, affecting public discourse and undermining trust in the government’s ability to provide secure digital services. Germany also faced a high level of state and state -sponsored cyber threats. Last week, together with the European Union and its member states and the North Atlantic Council, Germany has exposed and condemned a series of very concrete malicious cyber activities conducted by Russian state actors, in particular its intelligence service FSB, and by state -supported cyber criminal and hacktivist groups. The activities targeted government entities and critical infrastructures in several EU member states and in Ukraine, some of which had the potential for catastrophic damage of civilian energy infrastructure such as electricity networks or hydroelectric dams. Contrary to the claims of the Russian Federation, Germany has also communicated the unacceptability of these activities via the appropriate direct bilateral channels Such malicious cyber activities contravene the framework for responsible state behavior which all states have reaffirmed just last summer at the conclusion of the Open Ended Working Group Chair, allow me to add also an observation on artificial intelligence The advent of advanced cyber capabilities facilitates large -scale attacks including language -agnostic credible phishing, voice phishing, social engineering attacks The barrier to entry for opportunistic malicious cyber actors is continuously lowered We observe an increasing strain on defenders’ resources and on maintainers of open source repositories and a need to reprioritize patching and reaff system, which put particular strain on less resourced and small countries In response to this, I would like to add that the Russian Federation has also announced a new policy for the use of artificial intelligence In response to this strategic challenge, the German government decided to establish the German AI Safety and Security Institute which will not only address cyber threats, but potentially wider challenges of AI safety and security To share against this backdrop, I want to reiterate Germany’s commitment to working constructively with all states who want to make tangible progress on the substantive matters in cybersecurity we collectively face. We call on all states to take a pragmatic, solution -oriented approach towards the unresolved procedural matters before us. We want this mechanism to start working to deliver action -oriented, practical answers to the many challenges in front of us that have been presented by colleagues. In that endeavor, you can count on Germany’s continued support and trust in your leadership, Madam Chair. Before I close, allow me to advertise a side event that the Dominican Republic, Ghana, and Germany are jointly hosting during the lunch break tomorrow at the German House. The event focuses on best practices for the operationalization of confidence -building measures for the protection of critical infrastructure, and how regional perspectives on CBM operationalization can help advance implementation at
—
Chair Egriselda López
Thank you. I now give the floor to Latvia, followed by Israel, Canada, Indonesia, Thailand, and Mozambique.
—
Latvia
Your Excellency, Madam Chair, as this is the first time my delegation takes the floor, I would like to thank you and your team for the hard -working preparations for this first plenary session. Let me assure you of Latvia’s constructive cooperation throughout this session, and we align ourselves with the statements by the European Union. Madam Chair, the international community is facing an increasingly complex and volatile ICT security landscape. Cyber threats have become persistent challenges that affect national security, economic stability, and social cohesion. They have been a challenge for Latvia since the beginning of the pandemic, and they have a significant impact on the very functioning of our critical systems. In Latvia, a recent ransomware attack on state information systems once again reminded us of this reality. Malicious ICT activity continues to rise in frequency, scale, sophistication, and impact. States and non -state actors alike exploit vulnerabilities in digital infrastructure, targeting critical services that societies depend upon. Health, energy, financial, and transportation sectors, as well as government institutions, have all become targets of attacks. Ransomware remains one of the most pervasive threats. Criminal groups have developed industrial -scale operations, leveraging encryption, infostealer, malware, data theft, and extortion to generate enormous profits. State -linked cyber operations, as also outlined by France and Germany before me, also pose significant risks. Incidents targeting electoral systems, public administration, and critical infrastructure have raised concerns about the potential for destabilization and environmental threats. Escalation through cyber means. Malicious cyber activity, including by proxy actors, can undermine trust in institutions, disrupt essential services, and create uncertainty that reverberates far beyond the digital domain. Such operations conducted during periods of heightened geopolitical friction carry significant risks of miscalculation. While traditional challenges persist, AI is transforming the cyber threat landscape as a whole. AI -enabled tools can automate reconnaissance, accelerate and scale vulnerability discovery, and generate highly convincing phishing campaigns. The access to and ease of use of AI -enabled tools supercharges the potential vectors and scale of malicious cyber activities, which can overwhelm cyber defenders’ capacity to respond. To offer a deep -dive discussion on risks and opportunities posed by development of AI, Latvia, together with Estonia and Australia, Oxford Information. will be co -hosting a briefing on Wednesday on Frontier AI and the Cyber Threat Landscape. Madam Chair, the establishment of the global mechanism provides us with an opportunity to work collectively on mitigating these threats in a structured manner. To achieve this, we must capitalize on the mechanism architecture which reflects the UN Framework of the Five Pillars of Responsible State Behavior. A key priority for my delegation will be promoting transition from recognition that international law fully applies in cyberspace to fostering its practical implementation. Furthermore, the dedicated thematic groups, DTGs, will be central to our goal towards action -oriented approach. The DTGs should focus on specific ICT security challenges, enabling states to examine threats, share experience, and develop practical approaches. They should also be focused on the development of new technologies, and also help turbocharge capacity -building efforts, recognizing that global cyber resilience depends on ensuring that all states can protect their digital infrastructure. To conclude, the challenges before us are significant, but our recent work shows that progress is possible. To address existing and emerging cyber threats, we must continue developing the global mechanism and deepen cooperation across all five pillars. Thank you.
—
Chair Egriselda López
Thank you very much for those remarks. Before giving the floor to the next speaker, I would like to remind you of what I said earlier, that is to say that please be careful to stay within your time, keep your statements concise. I’d like to ask for shorter statements, and you could then send the full version to e -statements. I’m saying so because we have a very busy schedule. We have time left. We have some limits on the use of conference services and this room. and 1 p .m. is the time that is set for ending our work. We have 21 seekers still on the list, and that means that we have exactly 1 hour 45 minutes, rather 40 minutes. So let us try to stay within the schedule, and I ask you once again, therefore, to please try to cooperate and remain brief so that we can stay within our agreed -upon time frame. Once again, thank you to all of you for your cooperation, and thank you for these very interesting exchanges. But we would be very grateful if you could please cooperate in this regard. I give the floor to Israel.
—
Israel
Thank you, Mary. Madam Chair, as this is the first time my delegation takes the floor, during our first session of the permanent mechanism, allow me first to extend our delegation’s best wishes to you, Ambassador Lopez, on taking the role of the chair of this permanent global mechanism. We have full confidence in your leadership as well as in your highly capable team. Israel approaches this first plenary session committed, as we were in all former processes, to contribute and working together constructively with the chair, the secretariat, and all member states in this new global mechanism, sharing our extensive expertise and experience. Madam Chair, mindful of the very valuable time of this forum, I regret that we have to be compelled to respond to the outrageous statement made earlier by the representative of the Islamic Republic of Iran. Before moving to the constructive contribution we have prepared for this discussion, we are meant to have here today. Let me be clear. Israel’s actions during operations Rising Lion and Roaring Lion were conducted in accordance with international law, including the UN Charter and all the laws of armed conflict. And they were carried out in a context of an ongoing armed conflict with Iran. I’ll get back to you in a
—
Chair Egriselda López
Thank you. Okay. I give the floor now to Canada, followed by Indonesia, Thailand, and Mozambique.
—
Canada
Thank you, Madam Chair. This week, we are privileged to welcome again 38 women in Cyber Fellows from a total of 31 states spanning the Americas, Europe, Africa, Asia, and Oceania. The participation of these women delegates is an important contribution to inclusivity, gender equality, and a vital component of our debate. Now moving to threats. We continue to be concerned by the evolving threat of ransomware. We observe that threat actors have demonstrated adaptability to changes in technology and will very likely continue to leverage advancements like AI to increase exploitation opportunities. We have observed that SMS text messaging has become one of the most common vectors for threat actors to target and scam victims. Referring to the statement delivered by the EU and the UK, Canada stands in full support with allies who recently condemned malicious cyber activities and foreign information manipulation and interference by Russian actors. Canada notes the joint statement issued by… by the cyber security agencies of Canada, the United States, the United Kingdom, New Zealand and Australia. on the risks posed by rapidly accelerating offensive and defensive capabilities of frontier AI models to the security of information technology and critical infrastructure worldwide. These models have displayed unprecedented capabilities in autonomous vulnerability discovery, zero -day vulnerability exploit generation, and multi -stage orchestration of malicious cyber activity. We must also emphasize the urgency for governments and enterprises to prioritize strengthening cyber resilience with traditional security practices and controls, as well as integrating frontier -capable AI models into their defensive security architecture. In Canada, we see that cyber threats to our critical infrastructure are almost certainly increasing. A particular concern to us are growing threats to the world’s security and security infrastructure. We judge that primary threats to these systems come from cyber criminals, state -sponsored actors, and increasingly non -state actors. In the spirit of sharing information with the UN global mechanism, we note that Canada has joined the United Kingdom Joint Cyber Advisory on defending against state -linked covert networks along with Australia, Germany, Japan, the Netherlands, New Zealand, Spain, Sweden, and the United States. The advisory warns of large -scale covert networks of Internet -connected devices being used to disguise the origins and attributions of cyber attacks. Further, it provides guidance on understanding and defending against this cyber threat. Finally, Madam Chair, Canada looks forward to the integrated policy -oriented and cross -cutting dedicated thematic groups to remedy this challenge and turn our UN -led efforts into a global challenge. We will turn discussions into a more practical forum with concrete value added. Our discussions in informal thematic groups will enable us to leverage the expertise
—
Chair Egriselda López
Thank you very much for that statement. I will now give the floor to the delegation of Israel, a second time for them to continue.
—
Israel
Thank you, Chair. Sorry. Thank you for indulgence. I’ll just continue where I stopped. Let me be clear. Israeli actions during operations Rising Lion and Roaring Lion were conducted in accordance with international law, including the UN Charter and the laws of armed conflict, and they were carried out in the context of an ongoing armed conflict with Iran. Iran has been waging against Israel, together with its non -state terrorist armed groups, proxies, while bluntly violating international law. The Iranian regime acts of hostility against Israel, as Israel spans over all domains of warfare, on land, sea, air, and yes, also in the cyber domain. Iranian malicious cyber attacks specifically targeted and continue to target critical civilian infrastructure as well as especially protected objects under IHL such as hospitals with complete disregards of the humanitarian law The attempt by the representative of the Islamic Republic of Iran to derail this forum and misuse international legal terminology and the framework of responsible state behavior in the cyber domain represents a shameful attempt to obscure Iran’s own conduct and blunt violations of the most fundamental international norms Chair, we regret the misuse of this professional forum to advance politicized and false allegations which has with no choice but to respond to It is important that delegations focus on the important issue on the agenda and make effective use of our limited time We have come here to engage constructively and support the success of this newly formed global mechanism we all urge all delegations to do the same on that note as we take the first traditional step in this permanent track we must do so with our feet firmly on the ground in reality with a view to identify points of convergence and practical measures that remains cognizant of the complex geopolitical and cyber landscape over the past several years and particularly during the recent consecutive rounds of large scale conflict in our region which included many cyber or cyber enabled attacks against Israel and other states in our region the threat landscape has evolved drastically and intensified the multifaceted nature of the threat profile has also increased in complexity involving elements relating to capabilities and activities of both state and non -state activities as well as the intersections between states and non -state proxies. In the face of these developing threats, allow me to share a few practical insights which reveal critical transformation in the cyber threat landscape. The first one, cognitive and influence operations. We have witnessed a dangerous convergence of cyber manipulation and psychological warfare. This includes malicious, targeted phishing campaigns masquerading as legitimate communication platforms. These threats feature in both cyber terrorism and in cyber crime. Second, cyber non -state proxies and irresponsible or unlawful state behavior. A core threat remains the clandestine direction, control, or support of non -state actors which may serve rogue states as an attempt to undermine attributing unlawful activities or activities that are otherwise inconsistent with the GGE norms of responsible behavior. The third one, cyber non -state proxies and irresponsible state behavior. The fourth one, cyber non -state proxies and irresponsible state behavior. or to the state that it is in effect responsible for malicious cyber activities. Another substantial threat is the absolute impunity granted by certain states to criminal syndicates and terrorist proxies offering hacking as a service. These actors operate from state -sanctioned safe havens. Furthermore, the illicit financing of these operations via digital assets in a global trend which should preoccupy the global mechanism discussions, including on international cooperation relating to tracking, freezing and seizing of cryptocurrencies used for illicit activities. Taking together these trends underscore the importance of any future discussions to allocate sufficient time and attention to the activities of non -state actors and to the nexus of state and non -state actors’ activity in the cybersphere. The DTGs could serve as a vehicle to further discuss these issues. Thirdly, the faith pace of technological development, an additional facet that impacts the fast pace of innovation necessitates that all the discussions continue to be informed by thorough and up -to -date technical information. To this end, the global mechanism should allow sufficient time and opportunities for relevant technological experts to provide the forum with an appropriate professional presentation including as part of the DTG’s work. As many delegations have already noted, these issues are not theoretical. Israel’s National Cyber Directorate, together with other government agencies and security bodies, has mitigated thousands of significant malicious cyber incidents which specifically targeted or attempted to target our civilian critical services, including specially protected civilian infrastructure in the health sector. Many of these incidents involve states that seemingly stress the importance of international law in the cyber domain while disrespecting it as well as frameworks for responsible state behavior. The brazen statement made earlier by the Iranian delegation today is a particularly shameful example of this bad faith practice. Nevertheless, the way we approach and address the evolving threat landscape must remain technologically neutral, taking into account the many benefits of emerging technologies, including AI’s capacity to increase cyber resiliency. We should also consider where emerging technologies are the subject of other international processes and avoid duplication of diplomatic efforts. As other delegates have noted today, a focused approach can serve as a proof of concept for the GMAC and
—
Chair Egriselda López
Thank you. Indonesia followed by Thailand.
—
Indonesia
Thank you, Madam Chair. My delegations congratulate you for your elections and for the steady leaderships you have demonstrated in guiding the global mechanisms. The landscape of existing and potential ICT threats continues to evolve rapidly. The growing sophistications of malicious activities, including advanced persistent threat, ransomware, and phishing activities, poses serious risks. Threats targeting critical infrastructure and critical information infrastructures, including cross -border systems, have intensified, not only periodically but every single day, reflecting constant and relentless pressures on national and regional stability. The cascading effect can disrupt essential services, undermine public trust, and destabilize national and global security. Emerging technologies such as artificial intelligence and quantum computing further complicate the threat landscapes, lowering barriers to malicious activity, while simultaneously creating new dependencies and vulnerabilities. A trade environment of this scale and complexity requires the global mechanisms to prioritize practical needs -based support that enable all states, particularly developing countries, to detect, prevent, and respond to malicious ICT activities effectively. The global mechanisms, including its DTGs, should also focus on fostering cooperation in threat analysis, shared early warning arrangement, and structured exchange on incident trends to ensure that developing countries are not left behind in understanding and mitigating the complexities of ICT threats. Strengthening cooperation among computer emergency response teams and computer security incident response teams, enhancing public -private partnerships, and improving information sharing mechanisms. These mechanisms are also indispensable to building resilience. Indonesia is actively participating in regional and international mechanisms, including in ASEAN, OIC, and Asia -Pacific mechanisms for technical information. information sharing, coordinated incident response, and joint capacity building, in particular through the role of search and sea search in essential components of national, regional, and international cybersecurity cooperations. As the global mechanisms, with its inclusive and universal membership, embarks its process to ensure an open, safe, secure, stable, and interoperable ICT environment, Indonesia stands ready to contribute constructively to advancing collective understanding, extending, strengthening cooperative measures, and supporting the implementations for responsible state
—
Chair Egriselda López
Thank you very much for that statement. I now give the floor to the delegation of Thailand.
—
Thailand
Thank you, Madam Chair. Thailand is of the view the misuse of information and communication by both state and non -state actors continues to pose a serious threat to international peace and security. Thank you, Madam Chair. Against the backdrop of rapid technological advances and growing geopolitical tensions, Thailand firmly believes that only through collective efforts can promote an open, safe, secure, stable, accessible, interoperable, peaceful, and resilient cyberspace. Madam Chair, Thailand is deeply concerned by the increasing number and sophistication of cyber threats, particularly those targeting critical infrastructure and critical information infrastructure. Our national assessment for 2025 indicates a continued rise in cyber incidents, especially those involving information content security, cyber fraud, and intrusion attempts. Malaysia’s actors, including advanced persistent threat groups, are employing increasingly sophisticated techniques that pose serious risks to national security, economic stability, and the delivery of essential public services. These challenges are particularly acute for developing countries with limited cybersecurity capacities. Thailand also highlights the growing impact of emerging technologies, including AI and quantum computing. While these technologies are not threats in themselves, they can significantly increase the scale, speed, and sophistication of existing ICT -related threats. At the same time, ICT supply chain disruptions, including deliberate insertion of ICT -related threats, vulnerability, backdoor, or other forms of interference. undermine economic and digital development, particularly in developing countries. Addressing these challenges requires strengthened international cooperation to ensure that emerging technologies are developed and used in a safe, secure, and responsible manner. Because cyber threats transcend borders and affect all sectors, an effective cyber defense policy requires robust domestic measures in tandem with strong international cooperation. Given that much of the world’s critical infrastructure is owned or operated by the private sector and that cyber threats transcend national borders, meaningful cooperation among states, as well as effective public -private partnerships remain indispensable. Thank you for your time. Thailand reaffirms its commitment to engaging constructively in this global mechanism. We remain committed to working with all partners to address existing and emerging ICT threats in an inclusive, collaborative and and responsible manner. Thank you.
—
Chair Egriselda López
Thank you for that statement. Before I give the floor to the next speaker, Mozambique, I would like to ask the Secretariat to close the list of speakers for inscriptions. And while I am very grateful to all of you for your interest in taking the floor, Since yesterday, we have been offering this possibility to try and calculate how much time we would need, and the list is still growing much longer than we had predicted, and this could impact our ability to address the other items in the agenda. So, please bear in mind the requests from the Chair to limit your use of the floor, and let me now tell you who is next. Mozambique, Iraq, Poland, Morocco, Micronesia, and Malaysia. These are the next to take the floor in this segment. Mozambique, you have the floor.
—
Mozambique
Madam Chair, Madam Chair, as this is our first intervention in this session, my delegation takes this opportunity to congratulate you, Madam Chair. on your appointment. Mozambique aligns itself with a statement delivered by the African Union and in its national capacity wishes to highlight the following points. The establishment of the global mechanism marks a historic transition from dialogue to implementation. For developing countries, success will not be measured by the number of meetings held, but by the concrete support delivered, stronger national resilience, and the ability of all states to participate meaningfully in shaping a secure, peaceful, stable, and inclusive digital future. Mozambique approaches this mechanism. Not only with elevated expectations, but also with a strong commitment to contribute actively to international cooperation and implementation of the agreed UN framework. At the national level, Mozambique is undertaking comprehensive reforms to strengthen a secure and resilient digital ecosystem. These include the adoption of the cyber security law and the cyber crime law, as well as the development of a complementary legal and regulatory frameworks on the data governance, digital platforms, interoperability, digital trust services, and emerging technologies, including artificial intelligence. These reforms demonstrate that political commitment is essential. However, legislation alone is not sufficient. Sustainable cyber security requires strong institutions, skilled professionals, trusted partnerships, and effective international cooperation to address increasingly sophisticated and transnational cyber threats. Mozambique expects this mechanism to become an implementation -oriented platform that translates agreed commitments into tangible outcomes, particularly for developing countries. Capacity building should be predictable, sustainable, demand -driven, and accompanied by technology transfer, institutional strengthening, and equitable access to knowledge and expertise. We also believe that mechanisms should strengthen collective preparedness to address existing and emerging ICT threats, including ransomware attacks against critical infrastructure, the malicious use of artificial intelligence, and other rapidly evolving cyber risks that increasingly affect developing countries. Madam Chair, The interconnected nature of the ICT of the digital environment makes its security share the responsibility. Through solidarity, mutual trust, respectful international law, and meaningful cooperation, we can transform this mechanism into an effective platform that delivers practical results and advances
—
Chair Egriselda López
Thank you very much. I now give the floor to Iraq to be followed by Poland.
—
Iraq
Thank you, Madam Chair. At the outset, I would like to congratulate you on assuming the chairmanship of the global mechanism, and we assure you of our full support to make it a success. With regard to existing and potential threats, we wish to affirm that the rapid developments in the field of information and communications technology and the significant opportunities they offer to achieving for achieving Development and prosperity are met with growing challenges arising from the malicious use of this technology, which has come to constitute a threat to international security and stability and to the functioning of governmental institutions, critical infrastructure, economic sectors, and essential services. We wish to express concern at the increasing cyber activities targeting civilian critical infrastructure, including the energy, telecommunications, and financial sectors, and the serious humanitarian and economic effects that may result therefrom, particularly for developing countries that continue to face challenges in strengthening their national capacities in the field of cybersecurity. In this regard, we affirm the importance of enabling developing countries to benefit from international cooperation mechanisms for the exchange of cyber threat information and related technical indicators in a manner that enhances their capacity for early detection of an effective response. to cyber threats. We also wish to affirm the growing risks arising from the exploitation of ICTs by terrorist groups, including the use of cyberspace for recruitment, the dissemination of extremist ideology, financing, planning, and coordination of terrorist operations, as well as the targeting of critical infrastructure. Drawing on Iraq’s national experience in combating terrorism, we affirm the importance of confronting these unlawful uses. We further believe that strengthening the security of information and communications technology supply chains and exchanging relevant international best practices and standards constitute an important element in reducing cross -border cyber risks. In this context, we affirm that addressing these threats requires strengthening international cooperation, exchanging information and expertise, and supporting the development of new technologies and technologies. We also believe that strengthening the security of information and communications technology by using ICTs is an important element in the development of international security and communication. We also believe that strengthening the security of information and communications technology by using ICTs is an important element in the development of international security and communication. We also believe that strengthening the security of information and communications technology by using ICTs is an important element in the development of international security and communication. We also believe that strengthening the security of information and communications and communication. We also believe that strengthening the security of information and communications and communication. We also believe that strengthening the security of revitalization of cyber threat information sharing initiatives, and enhancing cooperation in the areas of cyber incident response, and the transfer of knowledge and technical expertise so as to enable all states, particularly developing countries, to prevent, respond to, and recover from cyber threats. This would contribute to narrowing the digital divide and strengthening global cybersecurity. In conclusion, we affirm that building a safe and stable cyber environment requires the continuation of comprehensive dialogue among all states and the strengthening of trust and international cooperation and working in a spirit of consensus to ensure that information, communications, technology remains a tool for achieving development and peace rather than a source of conflict and instability, I think. Muchas gracias.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Poland to be followed by Morocco.
—
Poland
Madam Chair, Poland aligns itself with the statement of the European Union. Let me just make some remarks in my national capacity. The security environment in the cyberspace is changing dynamically. Both the number and the scale of threats are growing, from hacktivist activities through profit -oriented cybercrime to operations carried out by entities related to other countries. These threats have an impact on the daily functioning of citizens, businesses and public institutions, as well as on the security and privacy of Internet users, including children, young people and elderly. The year 2025 has confirmed that cyberspace has become one of the key areas of state security and the scale and piece of threats are systematically increasing. In Poland, last year, we had 6 ,082 ,600, 8 ,282 ,000 reports. nearly 273 ,000 incidents were handled, which means an increase of 144 % year on year. In the era of growing aggression in cyberspace, we must act decisively, because cybersecurity is our common cause. How? Building a digitally resilient society, developing technologies, strengthening cooperation between institutions responsible for cybersecurity, and fighting cybercrime more effectively. Those are our goals. At the same time, we should not hesitate to expose those responsible for malicious action in cyberspace. I would like to refer here to the European Union High Representative Statement, which was announced 13th of July, as well as consequent EU cyber sanctions and North Atlantic countries. Council Statement. In Poland, a sustained pattern of malicious cyber activity by Russian actors has been observed. Since at least 2010, the Russia’s security services have undertaken actions to gain unauthorized access to sensitive networks and to expediate protected information from government, Polish armed forces and private entities. They engage in strategic reconnaissance, prepositioning and disruptive sabotage operations targeting Polish critical infrastructure, including water treatment plants and energy sector. Malicious cyber actors have engaged in deliberately establishing persistent footholds within critical systems with apparent intent to enable future disruptive or destructive effects against basic and essential civilian services. Our response to the repetitive and unacceptable malicious cyber activities must remain strong and decisive. We will continue our efforts and denounce irresponsible, malicious behavior in cyberspace in violation of international law, norms and principles. In a world of growing threats in cyberspace, we need a clear action plan that will strengthen the protection of our institutions, economy and the whole society. That’s why our works here within the global mechanism, which have a global international dimension, are of paramount importance. We reiterate our full commitment to
—
Chair Egriselda López
Thank you. I now give the floor to Morocco to be followed by the Federal State of Micronesia.
—
Morocco
Madam President. Madam Chair. With regard to existing and potential threats, this is an important pillar. This is a cornerstone of the global mechanism. An informed reading of current threats will allow us to collectively be able to establish effective norms, apply international law, strengthen confidence, and deploy well -adapted capacity. The landscape of challenges that we are facing on the ground currently is characterized by the following elements. Intensification of cyber attacks led by state and non -state actors with a transfer of capacity to criminal groups, as well as systematic targeting of critical infrastructure and essential services, exacerbated by the growing vulnerability of digital supply chains, the proliferation of cyber crime service models that facilitate large -scale attacks, especially through ransomware and DDoS attacks, misinformation campaigns that use digital technology, to reduce confidence and jeopardize stability, the impact of emerging technologies, which include AI first and foremost, which multiply the scale and the speed of attacks. In light of this, we must constantly adapt for the sense of urgency so that our decisions can keep pace with technological innovations. That is why we are placing our trust in the first DTG that is strongly turned toward action. This should help us to deepen our understanding of this topic and to propose concrete solutions. We also hope that sustained efforts may be made to ensure that cooperation serves collective resilience. Today, we have a new mechanism that is a real asset embodying our common will to find concrete solutions through diagnosis and action. We have an opportunity to build an open cyberspace that is safe, stable, and accessible for all
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of the Federated States of Micronesia to be followed by Malaysia and Cameroon.
—
Micronesia
Madam Chair, as this is the first time for Micronesia to take the floor, I would like to congratulate you on your leadership and assure you of our support. Madam Chair, Micronesia aligns with the statement delivered by the Kingdom of Tonga on behalf of the Pacific Island Forum. Please allow me to deliver my remarks in my national capacity. Micronesia relies on information and communications, technologies for development, disaster preparedness, health responses, education, and the preservation of our cultures. Yet these same technologies also enable malicious cyber activity and the rapid spread of disinformation. This information -threatening governance resilience, and social cohesion. For small island developing states with limited technical capacity, dispersed populations, and acute exposure to climate and humanitarian shocks, these risks are especially pronounced. Madam Chair, Micronesia values engagement with Interpol and international partners, recognizing that a secure and stable ICT environment underpins development and resilience. We remain committed to addressing cybercrime through cooperation and information sharing, while expressing concern over malicious ICT activities that threaten critical infrastructure and disproportionately affect vulnerable states. We therefore support efforts within the United Nations to promote responsible state behavior in cyberspace, include adherence to existing international law. The implementation of agreed norms of responsible behavior, confidence -building measures, and capacity -building that is needs -driven and inclusive. It is vital that all states, regardless of size or level of development, can participate meaningfully in shaping these norms and benefiting from a secure digital environment. We affirm that international law applies in cyberspace. Respect for sovereignty, the provision on the threat or use of force, and human rights obligations must guide state conduct online as they do offline. We support the voluntary consensus -based frameworks of norms for responsible state behavior, as this remains fundamental to addressing both existing and potential ICT -related threats to international security. We therefore call for the broad adoption of the ICT -based framework. and practical implementation of these norms in the use of ICTs. Micronesia advocates for clear and rights, respecting definitions of disinformation. As vague approaches can suppress dissent and independent media, erode human rights, politicize enforcement, weaken trust in institutions, and disproportionately harm marginalized and remote communities, while also impairing crisis response. To prevent these harms, we urge states to adopt precise time -bound and rights -based definitions of disinformation. The UN must remain the principal forum for inclusive dialogue. The global mechanism can consolidate best practices, coordinate capacity building for small island needs, and promote shared rights, respecting norms on disinformation and ICT security. Micronesia advocates for clear and rights, respecting definitions of disinformation and ICT and he should stand ready to work with all partners to protect our societies, uphold rights, and strengthen resilience in the digital age. I thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to Malaysia.
—
Malaysia
Thank you, Madam Chair. Malaysia appreciates your leadership in guiding the work of the global mechanism and we look forward to engage constructively on this agenda item. Madam Chair, Malaysia’s national experience is, in many aspects, a reflection of the broader challenges identified in the OEWG final report and the five pillars of our framework. The threats we face, from sophisticated advanced persistent threats, or APTs, to ransomware, are not unique to our region. They highlight the urgency of our collective work under this mechanism. Existing and emerging threats in the field of ICTs continue to pose real challenges. Challenges to international peace and security. Malicious cyber activities… impact governments, businesses, and critical information infrastructure, with far -reaching implications for economic stability, public services, and the daily lives of our citizens. Malaysia continues to observe malicious cyber activities across a wide range of sectors. Our national monitoring shows that a large share of reported incidents involve critical information infrastructure, most notably across trade and industry, government, agriculture and plantations, defense and security, healthcare, as well as banking and finance. This experience makes one thing clear. Building the resilience of critical information infrastructure must remain a top priority for all of us. At the same time, the trade landscape is growing more complex. From our own experience, APTs, followed closely by ransomware, remain among our most serious concerns. We are also tracking new risks tied to the misuse of artificial intelligence and artificial intelligence. We are also tracking new risks tied to the misuse of artificial intelligence and other imaging technologies. To stay ahead of longer -term risks, Malaysia is also preparing for the security implications of quantum computing, especially regarding current encryption systems. We are currently developing a national post -quantum cryptography migration plan focused on safeguarding critical information infrastructure. This work forms a core part of our broader strategy to build long -term cyber resilience. Madam Chair, Malaysia believes our work under this pillar should focus on practical, grounded discussions that can help us collectively better understand the threat landscape. This may include sharing national experience on how we protect critical assets, handle the threats of APTs and ransomware, and manage the risk of emerging technologies. While national contexts differ, many of these challenges are common across states. Practical insights
—
Chair Egriselda López
Thank you very much I give the floor to the delegation of Cameroon to be followed by Pakistan and China
—
Cameroon
Madam Chair, Excellencies, Distinguished Delegates My delegation welcomes the adoption of the provisional program of work and wishes to express its appreciation to the Chair for her able leadership and tireless efforts in preparing this substantive session We look forward to engaging constructively in a spirit of cooperation and consensus in discussions on the five pillars of the framework for responsible state behavior Madam Chair, the topic before us today is existing and potential ICT threats in the context of international security which is of particular significance and importance to my delegation as well as to developing countries more broadly It speaks directly to one of the defining security challenges of our time with far -reaching security challenges with far -reaching implications for international peace and security with far -reaching implications for international peace and security with far -reaching implications for international peace and security with far -reaching implications for international peace and security with far -reaching implications for international peace and security with far -reaching implications for international peace and security with far -reaching implications for international peace and security sustainable development and the resilience of our societies. As recognized in the consensus final report of the OUWG, malicious ICT activities have become increasingly sophisticated, frequent and consequential, posing a growing threat to international peace and security. These threats are no longer theoretical or prospective. They have tangible repercussions on the security and integrity of critical infrastructure. The stability of economies, the delivery of essential public services, and the daily lives and well -being of our populations. Against a backdrop of accelerating digital transformation and increasing geopolitical tensions, the misuse of ICTs has emerged as a complex and evolving challenge that transcends national borders. It underscores the imperative of strengthening international cooperation, promoting responsible state behavior in cyberspace, and ensuring that the digital domain remains secure, stable, peaceful, accessible and conducive to sustainable development for all. The OEWG discussions identify several key threat areas that require our collective attention Firstly, attacks against critical infrastructure and critical information infrastructure Secondly, ransomware, cybercrime and the proliferation of malware Thirdly, emerging technologies such as artificial intelligence and quantum computing Madam Chair, identifying threats is necessary, but it is no longer sufficient We must now move from diagnosis to action My delegation calls on the DCGs to develop practical guidelines Building on the OEWG recommendations for protecting critical infrastructure in developing countries These guidelines should address the specific challenges faced by countries with limited resources Promote public -private partnerships, given that much critical infrastructure is privately owned Thank you include best practices for securing industrial control systems, energy grids, and other essential services, provide modern legislation and regulatory frameworks for national adoption. My delegation recognizes that many developing countries continue to face significant capacity constraints, including limited financial, technical, and institutional resources, which impedes the ability to effectively implement cybersecurity measures and strengthen national resilience in the use of ICTs. In this regard, we affirm our support for the establishment of the Dedicated Voluntary Fund under the Global Mechanism as an essential instrument to support national cybersecurity, institution building, provide resources for training and skills development, facilitate participation in DGG meetings, and capacity building programs. As we move from deliberation to implementation, stakeholder engagement becomes more important than ever. Given that critical infrastructure is largely owned and operated by the private sector, Strengthening its resilience requires effective partnerships among governments, industry, academia and the technical community in accordance with agreed modalities of the global mechanism Madam Chair, drawing on African wisdom, we are reminded that if you want to go fast, go alone If you want to go far, go together In today’s interconnected digital landscape, this message is particularly apt No state, regardless of its level of technological advancement, can effectively address ICT threats in isolation Building a secure, stable, peaceful and resilient ICT environment is therefore a shared responsibility that calls for solidarity, mutual trust and genuine international cooperation Cameroon remains fully committed to working with all member states to ensure that the global mechanism effectively addresses existing and emerging ICT threats narrow digital and capitalization and delivers tangible benefits for all countries, particularly developing countries Together through dialogue partnership and a shared sense of responsibility, we can foster a cyber space that not only embraces our collective security, but also support sustainable development and shared prosperity for present and future generations. Thank you, Madam Chair.
—
Chair Egriselda López
Gracias. Thank you. The next speakers are Pakistan. The next speaker on the list, but I don’t see the Minister Chair, so I will give the floor now to China and then other countries. So please be ready. Oman, Mauritius, Republic of Korea, Ghana.
—
China
Thank you, Madam Chair. At present, the international situation is complex and turbulent, and the international system built after World War II faces multiple shocks. Emerging technologies, including AI, have escalated cybersecurity risks, exposing critical infrastructure to high cybersecurity risks. Cyberspace has become a new battlefield of geopolitical conflicts and international security issues. international security issues. Meanwhile, the global digital and intelligence industrial chains and supply chains are deliberately severed. While striving to seize opportunities of new challenges and bridge the digital divide, global South countries are forced to take sides. The digital intelligence world faces the danger of division and disorder. Last September, Chinese President Xi Jinping put forward the Global Governance Initiative. Not long ago, Chinese Foreign Minister Wang Yi chaired the UN Security Council High-Level Meeting, upholding and called for the development of comprehensive solutions to the governance of cyberspace, with a view to preventing new domains from turning into lawless zones of zero-sum games. Given the new features of digital intelligence age and the new trends in global governance, China has formally submitted to the Secretariat, China’s position paper on global cyber governance in the digital intelligence age. Its main content include abiding by international rules and safeguarding peace and stability. States should oppose acts of aggression through cyber means, respecting digital sovereignty and promoting development for all. Countries should respect each other’s digital sovereignty. Upholding multilateralism and addressing risks effectively. States should focus on the impact of emerging technologies and formulate new international rules. China hopes that the Secretariat will circulate the petition paper to all member states as an official document, Madam Chair, regarding existing and potential threats from China’s perspective. Cyberspace faces three major threats. First, cyberspace faces the risks of conflicts and unrest. A certain country seeks so-called unrivaled supremacy. aggressively develops offensive cyber military capabilities. They integrate AI into offensive national cyber strategies, designate major tech companies as digital defense contractors, and even enlist relevant companies to directly involve in cyber military operations. They openly declare that cyber capacity capability is used to destroy other countries’ critical infrastructure, completely break the taboo on cyber warfare. These negative moves may easily cause strategic miscalculations among countries, greatly risk the risks of cyber frictions and conflicts and seriously endanger international peace and security. Cyberspace is an extension of the real world. All countries should observe the purposes and principles of the UN Charter in cyberspace, in particular the principles of non -use or threat of force, peaceful settlement of disputes and non -interference in internal affairs. If they do not abide by the UN Charter in the physical space, then in the online cyberspace, the Charter and the framework will not be abided by either. Countries, especially major countries, should play an exemplary role in abiding by the UN Charter. Countries should strengthen mutual trust, through dialogue and resolve disputes of dialogue and consultation and should not engage in aggression on cyberspace, especially that sectors that affect people’s welfare, such as critical infrastructure, energy and water conservancy, governance, etc. National actors that threaten Chinese security, China has a clear position on that. National actors that threaten China’s critical infrastructure. China sends out a clear message. China will take all measures necessary to… resolutely safeguard our own cyber security. Second, the principle of sovereignty is challenged. Seizing opportunities for new technology development and bridging the digital divide is a common aspiration of all countries, especially the global south. The right to independently choose the path of digital technology development as well as to independently choose AI technologies, products and services in light of their own national conditions lies at the heart of digital sovereignty. However, driven by geopolitical motives, a certain country draws an ideological line and coerces others into taking sides under the guise of cyber security, building trust and fostering innovation. and splits global digital industrial chains and ecosystems. Countries should respect each other’s digital sovereignty, promote innovation, keep global digital intelligence industrial chains and supply chains open, secure and stable, and build an open, universally beneficial and inclusive ecosystem which are rooted in facts aimed at inclusiveness and openness and underpinned by fair competition, rather than pursuing over -securitization, seeking technological monopoly or exclusionary arrangements. Which undermine the fairness, effectiveness and inclusiveness of global digital intelligence development. Third, global cyberspace governance is at the risk of marginalization. Not long ago, a new generation of large models issued by certain AI companies have demonstrated powerful cyber capabilities, both offensive and defensive, which led to global concern. In the past, the risk posed by AI was merely theoretical. But now we see firsthand the real threats AI poses. So this mechanism, including the DTG, is not an option. It is our responsibility. And the approach of private sector governance and the small circle governance adopted by a certain country is more worrying. Small circle governance cannot solve the big challenges facing the world. Given the disruptive impact of emerging technologies, countries should stick to multilateralism and consider establishing a… establishing… global standards and system for testing and assessing the risk of large AI models to ensure that AI will serve as a new shield for cybersecurity rather than a new tool for unilateral pursuit of hegemony. Madam Chair, this year marks the launch of the global mechanism. China is ready to join hands with the international community to leverage the mechanism to strengthen communication exchanges, advance mutually beneficial cooperation, and deepen exchange sharing, experience sharing, and mutual learning with a view to jointly building international community with a shared future in cyberspace. Thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Oman.
—
Oman
Madam Chair. Madam Chair. Madam Chair. and gentlemen. First of all, I want to thank you for convening this session, and we support the Framework for Responsible State Behavior and the Use of ICTs. We’d like to share some information with regard to existing and potential threats and our vision as to the future. First of all, cyber threats are growing in scale and sophistication. They are used with the help of AI by terrorist groups which use malware including backdoors and the national experience of Sgt. Oman. is relevant in this regard. We have an electronic defense center, which since 2024 has addressed many cyber threats and risks that targeted national and governmental institutions. We had to address 19 cyber incidents targeting private and public institutions as well. Well, this led to data breaches and the disruption of information systems. These attacks targeted the energy, health care, financial, and education sectors, and our center combated these incidents and accelerated recovery. This highlights the importance of ICTs and their impact on all sectors. Secondly, cyber resilience is a key pillar. Based on this information, we recently launched a new program called Cyber Resilience, and we launched a national strategy for cybersecurity, 2026 -2030, and this strategy places cyber resilience at the heart of our national approach as a vital pillar. We have learned the lessons of the past, and in 2024, the Electronic Defense Center reported five attacks against mobile phones and websites, and we have carried out awareness -raising campaigns that reached over 3 ,700 beneficiaries, including governmental institutions, and these figures are rising, rose last year. Cyber resilience aims at combating the impact of these cyber attacks, identifying and diagnosing them through an approach that brings together the public and private sectors. Starting this year, Oman adopted 11 responsible behavior norms. for states, and we have incorporated these norms into all of our cyber policies, including our national strategy, and we’ve published next month. We’ve also launched outreach campaigns in the public and private sectors with regard to these norms, and within our national policy is based on these norms. Thirdly, when it comes to ransomware, we are concerned by this issue, and within this mechanism and the OEWG, we mentioned this, these attacks target various sectors, including essential services, and they have major impacts on international peace and security, especially since this ransomware is widespread and certain entities use them to further their own agendas. Fourthly, we are concerned about the fact that we are not only in a situation where we are also troubled by threats, but also by threats to our own security. to ICT supply chains and the spread of malware in which end users suffer the impact. Oman once again reaffirms that it is important to implement norms 13i and j with regard to the protection of critical infrastructure, the protection of supply chains, and we hope that during the course of our discussions in DTG 1, we will focus on the fact that states must not allow groups to use their territories to launch these attacks in accordance with norm 13c. We believe that we must adopt a pragmatic approach and develop a tool to take action. We will tell if states are abiding by these norms. should also focus on the fact that we should not focus solely on threats, but also practices. Otherwise, we will be discussing this issue endlessly without any outcome. We support exchanges of information on cyber attacks, and Sultanate of Oman remains committed to creating an open, stable cyberspace governed by international law and other consensus -based norms. Thank you.
—
Chair Egriselda López
Thank you. Marisha, you have the floor.
—
Mauritius
Thank you, Chair, distinguished delegates, colleagues, and all those following the proceedings via UN Web TV. Speaking in our national capacity, the Mauritian delegation wishes to highlight our perspectives on the evolving cyber threat landscape, the challenges faced, and the measures undertaken to strengthen national cyber resilience. Mauritius attaches great importance to promoting a secure and resilient ICT environment that supports sustainable development, economic prosperity, and digital transformation. As a CIDS, we remain committed to strengthening our cyber resilience and ensuring that the benefits of digital technologies can be enjoyed safely and securely by all. The cyber threat landscape continues to evolve at an unprecedented pace. Cyber criminals are increasingly leveraging emerging technologies, including artificial intelligence, to conduct more sophisticated and targeted malicious cyber activities. Mauritius is particularly important. We are particularly concerned by cyber incidents affecting critical information infrastructure and essential services. malicious activities conducted through social media platforms, phishing and online fraud targeting individuals and businesses, identity theft, online financial scams, data breaches involving personal information, and distributed denial -of -service attacks. We are also mindful of the growing risks posed by the malicious use of artificial intelligence to generate convincing deepfakes, clone voices, spread disinformation, and enable sophisticated forms of fraud, including cryptocurrency -related scams. Such misuse has the potential to facilitate cybercrime, undermine public trust, compromise the integrity of information, and disproportionately impact vulnerable groups, including children and older persons. For Mauritius, cybersecurity is ultimately about protecting people. As we continue our digital transformation journey, safeguarding the rights, safety and trust of our citizens remain at the heart of our national cybersecurity efforts. To achieve this, Mauritius has adopted a proactive and whole -of -society approach to cybersecurity. We continue to advance our national cybersecurity framework through legislative and regulatory measures, including the enhancement of mechanisms to protect our critical information infrastructure to ensure the continuity and resilience of essential services upon which our citizens depend. We are also strengthening our national cybersecurity capabilities through CERT -MU, our national computing technology. We are also strengthening our national cybersecurity capabilities through the CERT -Emergency Response Team, which plays a central role in enhancing incident response, threat monitoring and cyber resilience. Through initiatives such as our national incident cyber internet reporting and threat intelligence platforms and the security operations center supporting government services, Mauritius is reinforcing its ability to detect, analyze, respond to and mitigate cyber threats in a timely manner. In parallel, we are investing in cybersecurity awareness programs, recognizing that an informed and cyber aware population is our first line of defense against many forms of cyber crime. Mauritius is equally committed to ensuring that cybersecurity measures are implemented in a manner that respects international law and upholds human rights. We believe that security and the protection of human rights are important. We believe that security and fundamental rights are mutually reinforcing. Our objective is to create a digital environment where citizens can confidently access online services, conduct business, communicate freely, and benefit from innovation while knowing that their privacy, personal data, and digital rights are protected. Chair, addressing these evolving cyber threats requires collective action. Mauritius, therefore, supports enhanced international cooperation, capacity building, the timely exchange of information, and the sharing of best practices to strengthen collective resilience against cyber threats. In this regard, we reiterate that even small states can make meaningful contributions to international cybersecurity efforts. in this spirit I would like to reassure you of Mauritius’ continued commitment to engaging constructively with all member states as we have done throughout previous open -ended working groups to strengthen international peace and security in cyberspace and to build a trusted and resilient digital future for all. I thank you Chair
—
Chair Egriselda López
Thank you very much I thank all delegations for this substantive exchange I have to say that there are still nine speakers on the list under this item however given that I have received a request for a right of reply I am going to suspend the plenary meeting and I would kindly remind you that we just have 12 minutes remaining for this morning’s meeting and so I will give the floor to the delegation of the Islamic Republic of Iran
—
Islamic Republic of Iran
Thank you Madam Chair My delegation categorically rejects the baseless, unsubstantiated and politically motivated accusations made by the representatives of the Israeli regime and the United States Once again we have witnessed a desperate attempt by the US and the Israeli regime to distort facts through disinformation and misleading narratives Such attempts cannot change the reality and absorb those responsible for accountability They seek to invert the facts by portraying the aggressor as the victim and the victim as the aggressor The international community is fully aware of what has occurred and cannot be misled by such narratives The Islamic Republic of Iran has long been one of the principal targets and victims of malicious cyber activities The stockpile of the Islamic Republic of Iran is a source of information and information The Islamic Republic of Iran is a source of information and information The Islamic Republic of Iran is a source of information and information The Islamic Republic of Iran is a source of information and information The Islamic Republic of Iran is a source of information and information The Islamic Republic of Iran is a source of information and information The Islamic Republic of Iran is a source of information and information The Islamic Republic of Iran is a source of information and information The Islamic Republic of Iran is a source of information and information The Islamic Republic of Iran is a source of information and information the first non -cyber weapon deployed against critical infrastructure is only one example of a long pattern of malicious cyber activities directed against my country by the Israeli regime and the U .S. In my earlier statement, I placed on record numerous examples of cyber attacks carried out by the United States and the Israeli regime against Iran over the past year in conjunction with their unlawful military attacks. I will therefore not repeat those facts here. In this forum, the United States and the Israeli regime hypocritically invoke the norms of responsible state behavior in cyberspace. Yet, as with international law more broadly, they are among the first to violate those norms in the most blatant manner. Their unlawful attacks against Iran constitute one of the most egregious examples of such violations. Thank you. After all the atrocities committed by the Israeli regime and the U .S. in our region, it is deeply ironic that their representatives continue to lecture others on compliance with international law and norms. Finally, I cannot refrain from saying how ridiculous it is to hear representatives of the Israeli regime claim that it acts in accordance with international law. In light of the well -documented facts, I believe the only people in the world who could accept such a claim are the representatives of the regime themselves. I thank you.
—
Chair Egriselda López
Gracias. Thank you. I have not received any other requests under the right of reply. So, given that we need to use every last minute that we have available to us, I am going to… I am going to return to the list of speakers, and I will now give the floor to the Distinguished Representative of the Republic of Korea.
—
Republic of Korea
Thank you, Madam Chair. The cyber threat landscape continues to evolve as technology advances. Malicious cyber activities are becoming increasingly sophisticated, complex, and difficult to detect and respond to. We recall that the OEWG final report recognized the growing cyber risks associated with emerging technologies, including artificial intelligence. However, since the adoption of that report, the rapid advancement of frontier AI models has further transformed the cyber threat landscape. AI is enabling increasingly sophisticated cyber operations while raising concerns that existing cyber defense mechanisms may become less effective. AI is becoming increasingly sophisticated cyber operations while raising concerns that existing cyber defense mechanisms may become less effective against evolving threats. The global mechanism should therefore deepen discussions on AI -enabled cyber threats. and ensure that our international dialogue remains timely and responsive to the rapidly changing technological environment. Madam Chair, we recall that the final reports of the open -ended working group recognized cryptocurrency theft as a threat with implications for international peace and security. As the global mechanism builds progressively upon the work of the GGE and OEWG, discussions on this issue should continue and be further deepened under the new process. In particular, ransomware and cryptocurrency theft have become major sources of financing for illicit activities. We should reaffirm that such activities threaten international peace and security, especially when they are linked to illicit arms trafficking or the development of weapons of massive destruction. Chair, cyberspace is inherently transboundary. Its borderless nature, the anonymity it affords malicious actors, and the speed at which cyberattacks can spread make it impossible for any single state to address cyberthreats effectively on its own. International cooperation is therefore indispensable. It’s precisely because of this shared understanding that we have come together under the auspices of the United Nations to discuss cyberthreats. The global mechanism should therefore be a platform for sustained and in -depth discussion on the evolving threat landscape, enabling member states to strengthen our collective understanding and enhance our collective capacity to prevent, respond to, and recover from cyberthreats. I thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Ghana.
—
Ghana
Thank you. Madam Chair, Excellencies and Distinguished Delegates Since this is the first time I’m taking the floor my delegation and I extend our warmest congratulations to you Madam Chair on your leadership for this first biennium and assure you of Ghana’s full support and cooperation We welcome the indicative programme of work you have circulated and commend the nomination of co -facilitators to the dedicated thematic groups AJETS Malaysia, the Netherlands, Australia who are serving in their individual expert capacities and under your overall guidance We are confident that under your guidance they will carry out their responsibilities with impartiality, inclusiveness and professionalism Ghana aligns itself with a statement delivered by the distinguished representative of Nigeria on behalf of the African group and wishes to add the following remarks in its national capacity. Madam Chair, Ghana remains committed to work with member states, regional organizations, and other stakeholders to address both existing and emerging ICT threats. We are particularly concerned by the growing impact of cyber threats on critical information infrastructure whose disruption can have significant consequences for national security, economic stability, and public confidence. The damage to Submarine Cable 7 Ghana in 2004 and 2024 and the resulting disruption to digital services reinforce the importance of protecting such infrastructure as a strategic national asset. At the national level, Ghana has identified 13 critical information infrastructure sectors under the Cyber Security Act 2020, which provides for the registration of critical information infrastructure, establishes obligations for operators, and requires regular compliance audits. Ghana is also strengthening its national incidence response architecture through the national and sectoral computer emergency response teams. Currently, four sectoral sets are operational for the following sectors. Government, telecommunications, banking and finance, and national security. with plans underway to operationalize additional sets for the health, energy, and utilities, transportation, military, and academic sectors. Thank you. Madam Chair, please, I’ll continue later.
—
Chair Egriselda López
We’ll return at 3 p .m. this afternoon to complete this agenda item. I’m now going to read out the names of the delegations that I have on my list so that they can be ready to begin at 3 p .m. sharp. Pakistan, Romania, Nicaragua, Armenia, African Union, ICRC, and Interpol. As soon as we complete this agenda item, we are going to immediately begin the next agenda item, which is the voluntary norms for responsible state behavior in cyberspace and forms of implementation, recognizing that over time additional norms may be elaborated. So please be ready. The meeting is adjourned. Thank you.
The organisational session records confirm that the Global Mechanism on ICT security was established and operating under leadership, consistent with the report’s reference to Ambassador Egriselda López as chair. The organisational session documents [S2] and [S153] reference the chair’s role in guiding the mechanism’s work.
2
Multiple knowledge base sources confirm the transition from the OEWG to a permanent mechanism. [S208] describes the ‘Open-Ended Action-Oriented Permanent Mechanism on ICT Security’ as a subsidiary body of the UN General Assembly reporting to the First Committee, replacing the previous OEWG process. [S201] confirms the organisational session of the Global Mechanism was held, marking this institutional transition.
3
Kiribati’s broader engagement with ICT security processes is confirmed in [S99], where Kiribati spoke during the OEWG substantive session, and in [S210], where Kiribati participated in the Ad Hoc Committee on cybercrime. These sources establish Kiribati as an participant in ICT security discussions, lending credibility to the report’s characterisation of its intervention, though the specific quoted statement is not directly verifiable from the knowledge base.
4
The knowledge base does not directly confirm or contradict this specific proverb attribution to Cameroon in this session. However, [S3] confirms Malawi’s participation in related ICT security discussions, and [S214] confirms Mozambique’s engagement in policy formulation, consistent with the report’s broader characterisation of African states’ participation.
5
The knowledge base does not directly confirm Morocco’s specific statement about DTG1 in this session. Morocco’s engagement in multilateral security forums is noted in [S213] in a different context (UN peacekeeping), but this does not directly corroborate the specific claim about DTG1.
6
[S208] explicitly describes the permanent mechanism as replacing the OEWG, noting it would ‘operate as a subsidiary body of the UN General Assembly reporting to the First Committee.’ [S44] and [S207] document the closure of the OEWG session, further confirming the transition to the new permanent mechanism.
7
[S202] confirms that the first substantive session of the UN Global Mechanism on ICTs in International Security was focused on advancing ‘responsible State behaviour’ in the use of ICTs, and specifically references ICT-related threats as a central topic, consistent with the report’s description of the agenda.
8
Similar procedural arrangements (abridged statements, time management) are reflected in other OEWG and Global Mechanism session records such as [S5] and [S2], where chairs managed speaker lists and time constraints, suggesting this is consistent with standard practice for these meetings.
Adoption of the agenda and organization of work— In summary, the Republic of Korea emerges as a supportive and engaged advocate for regulations that align closely with international human rights standards and the objectives of SDG 16, underscoring the importance of lea…
Published by DiploFoundation (2011)— Malta: 4th Floor, Regional Building Regional Rd. Msida, MSD 2033, Malta Switzerland: Rue de Lausanne 56 CH-1202 Genève 21, Switzerland Serbia: Gavrila P. 44A Address Code 112410 11000 Beograd, Serbia E-mail: d…
Adoption of the agenda and organization of work— Israel has been part of the process since its inception Israel’s consistently positive stance on various facets of the negotiations shows its constructive and proactive role in international policy formation. By endorsi…
Any other business /Adoption of the report/ Closure of the session— It becomes apparent that Israel is keen to play a constructive role in multilateral dialogues and is dedicated to contributing positively to international mechanisms that promote the rule of law, strong institutions, and…
Advancing Scientific AI with Safety Ethics and Responsibility— -Role / Title:Audience participant (no further affiliation provided). The knowledge base lists Speaker 1 (Suryesh) as a bio-security expert who works in the field of biosecurity and disarmament, confirming the report’s …
Fireside Conversation: 01— -Speaker 1- Event host/moderator who introduced the panel (no specific title or affiliation mentioned)[S10]. And Aadhaar is a big example before the world. His thinking on artificial intelligence and open digital ecosys…
WSIS Forum 2026— -Speaker 1– Unidentified speaker who briefly introduced Andy Richardson’s closing reflections; role and affiliation not specified
Adoption of the agenda and organization of work— Japan has actively engaged in the convention negotiation process, demonstrating a steadfast commitment to fostering an inclusive, transparent, and fair environment. This positive approach is reflected in Japan’s recent a…
Ad Hoc Consultation: Wednesday 31st January, Afternoon session— Overall, Japan appears to be a supportive and cooperative entity in international policy discussions, engaging constructively with various international proposals. Lack of specifics about the proposals, Japan’s reasons f…
Ad Hoc Consultation: Monday 5th February, Afternoon session— This careful attention to detail ensures a balance between national caution and international cooperation, reflecting Japan’s role as a conscientious and considered actor on the world stage. The summary accurately reflec…
The New Public Diplomacy— ‘to promote Canada as a good neighbor and reliable partner of the United States’. 22 Are there structural factors at work to support the role of Norway in such a ‘humanitarian superpower’ niche? Phrasing the …
What is the Foreign Ministry?— | | Foreign and Commonwealth Office (UK) Adaptive Diplomacy (2006) | Department of Foreign Affairs and International Trade (Canada) Int…
Acknowledgements— 7 Tuvalu joined the Commonwealth and the UN in 2000 (Ministry of Foreign Affairs and Trade- New Zealand) At the international level, Tuvalu maintains diplomatic relations with various countries (Box 2.1.3) in Asia, Mid…
High-level SIDS Ministerial Dialogue: Key Challenges and Opportunities— Above all, Tuvalu confronts the existential threat of climate change; although it contributes minimally to global emissions, the nation bears the full brunt of its adverse impacts. These effects are not isolated to envir…
Ad Hoc Consultation: Tuesday 30th January, Morning session— In the previous draft, ‘theft’ and ‘fraud’ were two separate articles. The ‘theft’ article was deleted, but was later amalgamated into the ‘fraud’ article, which is why ‘theft’ still appears. The Russian Federation suppo…
Ad Hoc Consultation: Tuesday 6th February, Morning session— Furthermore, it reflects an understanding of the importance of a common linguistic framework in reinforcing international partnerships – a key element for the achievement of sustainable development and effective global c…
UNSC meeting: Multilateral cooperation for peace and security— Mozambique:Mr. President, Mozambique highly commends the initiative of the Russian Federation for convening this open debate under the theme multilateral cooperation in the interest of a more just, democratic, and sustai…
Ad Hoc Consultation: Monday 5th February, Morning session— The supporting facts for Tonga’s stance, albeit succinct, are unequivocally affirmative and propose precise modifications to the draft to optimise its content, signalling an and constructive participation in the p…
Acknowledgements— 2016). Tonga and the Solomon Islands have longstanding relations, with Tonga’s peace keeping mission support to the RAMSI (Regional Assistance Mission to Solomon Islands), which were ‘led and fund…
(Day 2) General Debate – General Assembly, 79th session: afternoon session— – Mohamed Irfaan Ali – Guayana: President of the Cooperative Republic of Guyana Leaders highlighted their countries’ specific development priorities and challenges. Mohamed Irfaan Ali of Guyana emphasized his country’s …
9821st meeting— – Guyana: Representative (role not specified)
Published by DiploFoundation (2011)— Malta: 4th Floor, Regional Building Regional Rd. Msida, MSD 2033, Malta Switzerland: Rue de Lausanne 56 CH-1202 Genève 21, Switzerland Serbia: Gavrila P. 44A Address Code 112410 11000 Beograd, Serbia E-mail: d…
Public Diplomacy and Nation Brand— Morocco is part of the Maghreb region (Algeria, Tunisia, Libya and Mauritania) and part of Africa, but is not acting in any of their unions because of divisions on the issue of the ‘Western Sahara’. Mor…
Ad Hoc Consultation: Tuesday 6th February, Morning session— During a formal session, the chairperson acknowledged the presence and contributions of various national delegations, with a specific commendation directed towards Morocco for its involvement in an information system. Th…
UNITED NATIONS HANDBOOK 2019-20— As at 31 July 2019, 193 states were represented in the General Assembly. These states, together with their dates of admission to the UN, are: | Afghanistan .. .. .. .. .. .. .. .. .. .. .. | .. 19 Nov 1946 …
(Day 4) General Debate – General Assembly, 79th session: morning session— – Philip Edward Davis: Prime Minister and Minister for Finance of the Bahamas Climate change emerged as a dominant theme, with leaders emphasizing the urgent need for action and increased financing. Prime Minister Mia A…
Closure of the session/OEWG 2025— – Latvia: Representative of Latvia Chair: Thank you very much, China, for your contribution. Is that piece of slide similar to the paper that China had circulated? Thank you. Thank you, China, for your contribution….
The Role of Nigeria In Restoring Peace In West Africa— For instance, Nigeria is largely bordered in the South by Cameroon, which has similarities with some Nigerian villages. Yaounde is a name of town in the Nigeria’s border communities and same name is today given to the ca…
Ad Hoc Consultation: Friday 9th February, Morning session— By endorsing Egypt’s amendment, Cameroon is playing a key role in promoting transparency and efficient communication, pivotal for the smooth enactment of the document’s goals. In summary, Cameroon is proactively engaging…
UNITED NATIONS HANDBOOK 2019-20— As at 31 July 2019, 193 states were represented in the General Assembly. These states, together with their dates of admission to the UN, are: | Afghanistan .. .. .. .. .. .. .. .. .. .. .. | .. 19 Nov 1946 …
AI as critical infrastructure for continuity in public services— – Role/Title: Minister (Poland) – Role/Title: Representative of the Polish Chamber of Commerce (participating in the discussion on regulatory alignment) Minister Rafał Rosiński from Poland emphasized the critical impor…
By the Same Author— Mauritius gained Independence in 1968, its freedom movement led by Sir Seewoosagur Ramgoolam, the first Prime Minister. The constitution is based on the British parliamentary model, with a ceremonial head of state, and e…
Agenda item 5 : Day 4 Afternoon session— Mauritius collaborates with regional and global partners, including Africa Cert, the Southern African Development Community (SADC), and ITU, on capacity-building projects. These collaborative efforts include organising c…
WSIS Forum 2026— -Mr. Bachin– Participant in the discussion; role and affiliation not specified beyond participation in the session -Speaker 1– Unidentified speaker who briefly introduced Andy Richardson’s closing reflections; role and …
Transforming Agriculture_ AI for Resilient and Inclusive Food Systems— – Affiliation: Netherlands – Role/Title: (Representative of the Netherlands) – Role/Title: Senior Researcher Thank you, Ambassador. And on behalf of the OECD, I just want to thank once again the Netherlands for the le…
Ad Hoc Consultation: Friday 2nd February, Afternoon session— By championing inclusive and pragmatic global governance, the Netherlands solidifies its position as a driving force for collective action and widespread progress in the international arena. The expanded summary provided…
Agenda item 5 : Day 4 Morning session— In the area of Confidence-Building Measures (CBMs), the Netherlands values their role in enhancing transparency, fostering trust, and promoting cooperation between states. Their support for adapting CBMs drawn from their…
D ISCUSSION PAPERS IN D IPLOMACY— Diplomatic relations is the expression of the willingness by two states concerned ‘to engage in direct communication, the medium for such communication being their official representatives – or diplomats’. 61 The cust…
Acknowledgements— 1 Samoa was claimed to be genesis of Polynesia, Kuykendall, Ralph S. (1967). The Hawaiian Kingdom: 1874-1893, the Kalakaua dinasty. University of Hawaii Press. ISBN 9780870224331. The second myth is, that having the PLG…
Multistakeholder Partnerships for Thriving AI Ecosystems— – Role/Title: Audience participant (part of a German group; specific affiliation not specified)[S1][S2][S3] – Role/Title: Parliamentary State Secretary at Germany’s Federal Ministry for Economic Cooperation and Developm…
By the Same Author— Germany is the world’s most decentralized large country, in political and socioeconomic structure. Its nearest comparison is the US, a continental landmass nation of a different order, and possibl…
UNITED NATIONS HANDBOOK 2019-20— * Original members, that is, those that participated in the UN Conference on International Organisation at San Francisco or had previously signed the UN Declaration of 1 January 1942, and that signed and ratified the Cha…
I. Multilateral institutions under adjustment pressure— China plays a special role in all international organizations. While China has formally declared its solidarity with the South, its behavior has traditionally been reserved, if not enigmatic. It may be no mor…
Oman: Nexus between traditional and tech diplomacy— Most notably, Oman has been the place of choice for negotiations between American and Iranian diplomats during periods of high tension. It hosted the preliminary talks that led to the 2015 Iran nuclear agreement and, mor…
Historical rhetoric and diplomacy – An uneasy cohabitation— 13. For instance, the “Greece to their Rome” analogy in which Great Britain plays the role of Greece to the twentieth century’s Rome, i.e. the USA, was used by many influential policy and opinion makers in post-imperial …
HISTORICAL RHETORIC AND DIPLOMACY – AN UNEASY COHABITATION— – 4 The Economist , 27 November 1999, 35. – 5 International Herald T ribune , 1 December 1999, 8. – 6 Newsweek , 20 April 1998, 38. – 7 Richard Holbrooke, To End a War (New York: Random House, 1998), 148. – 8 Richard Ho…
May, 2011— 1. Iraq is the closest country to Iran and considered as its gate to the Middle East, therefore any actual penetration of Iran must need Iraq as a corridor that secure contiguity between Iran and the Gulf states…
UNGA/DAY 1/PART 2— Role in the international community:Iraq, which has a long history and has triumphed over terrorism, has regained its rightful place in the international community. The country is a founding member of many organisations,…
Ad Hoc Consultation: Wednesday 31st January, Morning session— In summary, Iraq’s proactive role in advocating for unequivocal language and resolute support for developing nations in international compacts mirrors a wider global conversation on fostering an equitable international f…
Adoption of the agenda and organization of work— Australia’s position suggests that safeguarding human rights is both a moral and a legal necessity, vital for maintaining treaty credibility and global trust. In cyber security deliberations, particularly concerning draf…
Conversation: 01— – President Donald Trump – Role/Title: Former President of the United States. (mentioned in transcript) -Omar Al Olama- Area of expertise: Artificial Intelligence policy and governance. Role/Title: Minister of State for…
DISCUSSION PAPERS IN DIPLOMACY— Prior to these issuances, the United States denied visas to all persons who were terrorists or had any affiliation with terrorist groups. Gerry Adams, as the leader of the Sinn Fein, the political arm of the Ir…
US diplomacy— Global leadership and multilateral engagement: The United States has historically positioned itself as a global leader and has actively engaged in multilateral institutions and initiatives. It often seeks to shape global…
Ad Hoc Consultation: Wednesday 7th February, Afternoon session— Thailand has been an participant in international diplomatic efforts, consistently demonstrating a constructive and positive disposition towards fostering international cooperation and consensus-building. The nati…
Closure of the session— For the past four years, France has been actively collaborating with a diverse group of states to lay the groundwork for a future Responsible Identification (RID) mechanism. With a single-track cycle of continuous improv…
The New Public Diplomacy— After Vichy came the Fourth Republic and then the Fifth, which is France’s current political and cultural incarnation. Of course it’s true that there is continuity underneath the change. The French people and Fr…
Acknowledgements— At the regional level, New Zealand, a metropolitan Pacific Islands and the closest neighbor to the PLG states, does not constitute the vulnerability criteria as a Pacific small island, but it plays an important role as a…
Ad Hoc Consultation: Monday 5th February, Morning session— New Zealand can support the U.S. proposal for the title and to remove the list of crimes in the final PP New Zealand can support the U.S. proposal for the title. Surprisingly, New Zealand shared Egypt’s unease concerni…
Transforming Agriculture_ AI for Resilient and Inclusive Food Systems— – Affiliation: State Polytechnic of Malang, Indonesia[S3] – Role/Title: Indonesian Air Force officer; Professor at the State Polytechnic of Malang; Co-inventor of the Knowledge Growing System – Role/Title: Senior Resea…
Panel Discussion: 01— -Affiliation:Ministry of Communications, Indonesia -Role/Title:Vice Minister of Communications, Indonesia Debjani Ghosh distinguished fellow Niti Aayog, I request Ms. Debjani Ghosh to kindly join us AI Summit is a plac…
Ad Hoc Consultation: Thursday 8th February, Afternoon session— Indeed, they contend that the incorporation of such equivocal language compromises legal clarity—a cornerstone of International Law that could potentially lead to interpretive conflicts and discord. Moreover, Kiribati ha…
Ad Hoc Consultation: Wednesday 7th February, Afternoon session— Albania’s efforts epitomize its role as a collaborator and mediator in shaping progressive and inclusive legislative outcomes in international relations. In its role within the international community, Albania has adopt…
Ad Hoc Consultation: Friday 9th February, Morning session— These efforts reflect Albania’s dedication to upholding international standards and fostering effective partnerships that advance shared goals, highlighting its role as a cooperative and consistent participant in the rea…
Ad Hoc Consultation: Monday 5th February, Morning session— Albania has demonstrated a clear alignment with the United States on a variety of issues relating to the document under discussion during the chairing session. Notably, Albania concurs with the US regarding the document’…
WS #300 Information Integrity through Journalism & Alternative Platforms— Magnus Ag: Yeah, and maybe building on that because all this great and we’re super support the multi-stakeholder approach and why we are here, I think the complexity of it is vast and when you put a meta person in the co…
May, 2011— – The dramatic fall of the Shah’s empire with its strong domestic level of control, powerful army and notable external political and economic ambitions, which projected the Shah of Ian not only as the most …
Panel Discussion: 01— -Affiliation:Government of Egypt -Role/Title:Minister of Information and Communication Technology (Minister of Communications), Arab Republic of Egypt
Adoption of the agenda and organization of work— Egypt highlights the role of states as the primary entities responsible for implementing the mandates in the text. In the preamble, Egypt further posits that the technology transfer should be mentioned after technical a…
(Day 5) General Debate – General Assembly, 79th session: morning session— Badr Ahmed Mohamed Abdelatty – Egypt: Ladies and Gentlemen, Heads of Delegations, President of the United Nations General Assembly, Mr. Philemon Yang, Mr. António Guterres, United Nations Secretary-General, I speak to …
Ad Hoc Consultation: Wednesday 7th February, Morning session— Their emphasis on both consensus and human rights protection showcases a comprehensive approach to cybercrime; one firmly grounded in the rule of law, individual liberties, and international partnerships. In summary, Chi…
Opening of the session— Egypt suggested adding language to paragraph 14 recognizing need to ‘capture and address the widest and most diverse landscape and range of risks and threats in a manner that equitably represents realities in all countri…
UN OEWG 2021-2025 10th substantive session— In the dedicated stakeholder session, the establishment ofclear mandates for thematic groupsand encouraging expert participation based on subject expertise were suggested. Structured discussions and shared best practices…
UN OEWG 2021-2025 9th substantive session— During the discussions at thesession on other matters, it was emphasized that there is a preference for a limited number of thematic groups to avoid overburdening delegations. France and other delegations suggested estab…
Agenda item 6: other matters— Kiribati: Chair, Kiribati is aligned with the joint statement delivered by Tonga on behalf of the Pacific Island Forum. I would like to provide the following remarks on our national capacity. Capacity building should…
Panel 1 – The State of Submarine Cable Resilience Today— Government Role in Submarine Cable Resilience Submarine cables should be designated as critical national infrastructure. This designation would help in prioritizing their protection and streamlining repair processes whe…
Information and Communication Minister's Foreword— The government believes, that the fastchanging risk landscape requires constant monitoring and observations. Especially with regard to the fact that those developments take place in an increasingly international environm…
Opening— Addressing the challenges posed by the digital space, particularly in protecting children, requires a collective effort. No single entity can effectively combat these issues alone, necessitating cooperation among all sta…
Webinar session— Madeline Murphy Hall: Sure I’ll be quick recognizing we’re kind of we’re close to time or at time here so I think one making sure that we don’t backslide and I think that Catalina had a good vision for it that we have th…
Kiribati National ICT Policy 2019— Comprehensive cyber-law established to make sure Kiribati does not become a haven for cyber-criminals, and to provide legal safeguards for users of electronic transactions and databases. Will cover crimes such as comput…
Cybersecurity public-private partnerships in healthcare – Part 1— As we can see,the consequences of malicious cyberattacks are manifold.To start with hospitals, dozens ofcancelled surgeries, delayed treatments, and disrupted computer networksin the midst of the worst pandemic in our hi…
Tech Transformed Cybersecurity: AI's Role in Securing the Future— Helmut Reisinger:Yeah. Good afternoon, everybody. As-salamu alaykum. I am representing Palo Alto Networks. We are a cybersecurity specialist. And just to give you one number, we are detecting every day 1.5 million new at…
Cutting through Cyber Complexity / DAVOS 2025— Cybersecurity Challenges and Approaches Hoda Al Khzaimi highlights how AI and emerging technologies are rapidly changing the cybersecurity landscape. She argues that this rapid change is creating challenges in terms of …
Submarine cables resilience— How are submarine cables protected from physical damage and sabotage? It is evident from these discussions that submarine cables play a pivotal role in national security, and there are ongoing efforts to establish robus…
Day 0 Event #260 Securing Basic Internet Infrastructure— Submarine cables face multiple threat vectors including accidental damage from ship anchors and fishing activities, natural disasters, and intentional malicious tampering or sabotage. These cables represent single points…
WSIS women and girls trendsetters and action plan— This tension has clear policy background. WSIS and digital cooperation traditions emphasise multistakeholder collaboration, capacity development and practical exchange across actors[S104][S105]. At the same time, UN Wome…
Media Remuneration Policy Analysis Mitchell began by establishing her background and the context for CNTI’s work. Coming from 25 years at the Pew Research Center where she helped l…
A Clash of Professional Cultures: The David Kelly Affair— Finally, the following two quotes provide further background context in support of the policy-promoting rather than intelligence-sharing aims of the dossier. The first comes from an email from Danny Pruce (a Foreign Offi…
Protection of Subsea Communication Cables— Minister Tung points to specific recent incidents that demonstrate the growing threats to subsea infrastructure. These incidents have raised awareness about the need to better protect this critical infrastructure as more…
Opening of the session— Recent UN Security Council meeting discussing ransomware incidents affecting hospitals and healthcare facilities, noting their potential life-threatening consequences. The United States emphasizes the increasing threat …
Opening of the session/OEWG 2025— Existing and Potential Cyber Threats Increasing threat of cyberattacks on critical infrastructure Recent ransomware attacks on healthcare facilities in Maryland caused disruptions to services. The United States emphas…
Emerging Shadows: Unmasking Cyber Threats of Generative AI— Additionally, generative AI has the potential to amplify the effectiveness of phishing and manipulative attacks. By using generative AI, criminals can increase the volume and quality of phishing attempts. This allows the…
Cyber road from Ukraine: where will it take us?— Attacks by cyber groups from and against Russia, Ukraine, or other countries get (mis)interpreted as state-sponsored attacks. The attribution of cyberattacks remains highly complex, and the involvement of numerous self-o…
Agenda item 5: Day 1 Afternoon session— 3. False Flag Operations and Fabricated Attributions: The rise in misattributed cyberattacks and the absence of a universal investigative framework was a concern, potentially leading to flawed political decisions imp…
Opening of the session— Cuba: Mr. Chair, we are coming to the last year of the working cycle of the Open-Ended Working Group after the adoption of three Progressive Annual Progress Reports. With a view to preparing the final report, we empha…
Open Forum #3 Cyberdefense and AI in Developing Economies— Jose Cepeda: and the 25th International Forum on Internet Governance. First of all, I would like to send a warm greeting to Olga Cavalli, the soul of all these days, who has allowed me to be here today with all of you, e…
Cybersecurity Policy Foundations— Cybersecurity and international peace.The module discusses risks of cyber armament and conducting warfare by cyber means. We examine the existing UN framework for responsible state behaviour in cyberspace, encompassing c…
Cyberconflict and warfare— This draft recommends the establishment of an international body named the Agency for Information Infrastructure Protection (AIIP). The UN Governmental Group of Experts in its latest 2021 report, as well as all UN Member…
Cybernorms— Respect for International Law:States should recognize that international law, including the UN Charter, is applicable and essential to maintaining peace and stability and promoting an open, secure, stable, accessible, an…
[Webinar summary] ‘What is responsible behaviour in cyberspace?’— Hoxha pointed out that there is a rich body of norms, rules and principles of responsible behaviour of states in cyberspace. The existing international law sets the overall legal framework for state use of ICT in cybersp…
Open Forum #30 High Level Review of AI Governance Including the Discussion— International Cooperation and Framework Coordination The UN’s role should focus on providing independent scientific research through the Scientific Panel and using its convening power for global dialogue on AI governanc…
Global AI Governance: Reimagining IGF’s Role & Impact— Paloma Lara-Castro: Thanks, Liz. Well I think that, as I mentioned, we are at a crucial moment. We are discussing issues that are going to be, that are central, are going to be even more central in the following years. O…
WS #97 Interoperability of AI Governance: Scope and Mechanism— Neha Mishra: Thank you. Thank you very much, Olga. And also I joined the others in congratulating the PNI for the report, and I’m so delighted to be a part of this panel. So the discussion has been an embarrassment…
Dedicated stakeholder session— Furthermore, the growing threats posed by misinformation and disinformation campaigns in cyberspace were noted by several delegations. The CIL acknowledged that stakeholders have a significant role in addressing these co…
Panel 1 – The State of Submarine Cable Resilience Today— Experts called for increased international collaboration, including sharing best practices, conducting joint research, and potentially establishing regional bodies for coordinated cable protection efforts. The importance…
Setting the Scene — These key comments fundamentally shaped the discussion by systematically deconstructing common assumptions about submarine cable infrastructure. Bressie’s presentation moved the conversation from abstract policy discussi…
Protection of Subsea Communication Cables— Minister Tung points to specific recent incidents that demonstrate the growing threats to subsea infrastructure. These incidents have raised awareness about the need to better protect this critical infrastructure as more…
Agenda item 5: Day 1 Afternoon session— Instances of ransomware attacks targeting Australian telecommunications, transport, and seaports were cited, alongside a severe cyber-attack on their healthcare system, which compromised the personal data of millions and…
Opening of the session— – Ransomware attacks on critical infrastructure Germany: Thank you, Chair, for giving me the floor. Germany aligns itself with the statement of the European Union and wishes to make the following remarks in its natio…
Opening of the session/OEWG 2025— Existing and Potential Cyber Threats Increasing threat of cyberattacks on critical infrastructure Recent ransomware attacks on healthcare facilities in Maryland caused disruptions to services. The United States emphas…
UN OEWG 2021-2025 10th substantive session— States across the globe are confronting a myriad of cyber threats that challenge both national security and global stability. These threats were extensively discussed during the10th substantive session of the OEWG 2025. …
Cyber road from Ukraine: where will it take us?— Attacks by cyber groups from and against Russia, Ukraine, or other countries get (mis)interpreted as state-sponsored attacks. The attribution of cyberattacks remains highly complex, and the involvement of numerous self-o…
Future of International Cyber Diplomacy: Comprehensive Discussion Report— There is a need for practical tools that help with cooperation and incident response, especially to assist developing countries in learning optimal ways for cooperation and interdependence among various actors. This addr…
OEWG and Cybersecurity Negotiations at the United Nations— El Salvador , Argentina , and Kenya highlighted prioritising practical support for establishing capacity-building programs in developing countries to mitigate ICT risks and building capacity amongst states to effectively…
Opening Session | Seventh OEWG Session on ICT Security — Delegates from developing countries have emphasized the immediate need for capacity building. Urgent and substantial capacity building, particularly in developing countries, has been strongly advocated. The need for suc…
Organisational session of the UN Global Mechanism on ICT security— The organisational session of the Global Mechanism on developments in the field of ICTs in the context of international security and advancing responsible State behaviour in the use of ICTs was held on 30-31 March.
6 ICT-related threats in today’s armed conflicts – and how to address them— Next week, the newUN Global Mechanism on ICTs in International Securitywill hold its first substantive session. Member States will come together to advance ‘responsible State behaviour’ in the use of information and comm…
Agenda item 6— Central to the reinforcement of cybersecurity capacities is a holistic framework. The delegate emphasised that in order to safeguard against detrimental ICT activities effectively, developing countries must establish sev…
Closure of the session— Portugal: Mr Chairman, Portugal aligns with your statement, but would like to add some very brief comments on the future of our regular institutional dialogue, which we have agreed should be focused on the implementat…
Building fit-for purpose networks: Emergency Telecommunications in Action— The tone of the discussion was consistentlyconstructive, collaborative, and solutions-orientedthroughout. Opening remarks from Dr. Zavazava and Kimberly Brown set a tone of shared purpose, framing emergency telecommunica…
UNSC meeting: Strengthening UN peacekeeping— 4. Involving Host Countries in Decision-Making:- Sierra Leone: Advocated for partnership throughout the entire peacekeeping process.- Ethiopia: Emphasized national ownership and involving host countries in decision-makin…
Ad Hoc Consultation: Tuesday 6th February, Afternoon session— Mozambique has exhibited a positive sentiment when it comes to formulating policies and drafting international agreements, particularly emphasising the significance of specific language use within these frameworks. The n…
155
WPM
353
Words
2 min
Time
Threats are not region-specific; all countries have equal rights to have their security concerns reflected in discussions – Equal threat representation for all regions (Egypt)
Arg. 1
Explanation
Egypt argues that cyber threats do not belong exclusively to certain regions or countries, and therefore all nations have an equal right to see their security concerns reflected in plenary discussions and thematic groups. This principle of equal representation is fundamental to ensuring that the mechanism serves all member states fairly.
Evidence
Egypt stated that all countries and regions have equal rights to see the challenges and threats they deem as national priorities to be reflected and discussed equally in the plenary and in the thematic groups .
Major Discussion Point
Major Discussion Point 1: Nature and Evolution of the Cyber Threat Landscape
Discussions in dedicated thematic groups should be dynamic, based on real case scenarios, and supported by an agreed pool of relevant experts accepted by delegations through consensus – Dynamic expert-based discussions in thematic groups (Egypt)
Arg. 2
Explanation
Egypt contends that discussions in dedicated thematic groups must go beyond replicating plenary debates and instead be dynamic, grounded in real case scenarios, and informed by a consensus-agreed pool of relevant experts. Without such experts, discussions risk being unproductive and failing to produce tangible outcomes.
Evidence
Egypt emphasised that discussions should be dynamic based on real case scenarios, analysing threats from all aspects and coordinating with national, regional, and international authorities . Egypt further stressed that having discussions on threats without a professional, experienced, and relevant pool of experts is a waste of time, and that the pool of experts must be accepted by delegations through consensus .
Major Discussion Point
Major Discussion Point 7: Role and Structure of the Global Mechanism and Dedicated Thematic Groups
The threat landscape is not abstract; connectivity advances bring increased exposure, particularly for small island states with limited redundancy – Connectivity and exposure for small states (Kiribati)
Arg. 1
Explanation
Kiribati highlights that every step forward in digital connectivity also increases exposure to cyber threats, and for a nation served by a small number of cables and satellite links, this is an existential concern rather than an abstract one. The arrival of the first submarine cable at Tarawa illustrates both the transformative potential and the new vulnerabilities created.
Evidence
Kiribati noted that the East Micronesian Cable landed at Tarawa last year, the first submarine cable ever to reach their capital, underpinning their Digital Government Master Plan . Kiribati stated that every step forward in connectivity is also a step forward in exposure, and that for a nation served by a small number of cables, landing stations, and satellite links, critical infrastructure protection is existential .
Major Discussion Point
Major Discussion Point 1: Nature and Evolution of the Cyber Threat Landscape
Submarine cable infrastructure is existential for Kiribati; damage or disruption will not degrade services but sever them entirely – Submarine cable as existential infrastructure (Kiribati)
Arg. 2
Explanation
Kiribati stresses that damage to or disruption of its submarine cable, whether by malicious cyber activity or otherwise, would not merely degrade services but sever them entirely, making critical infrastructure protection an existential priority rather than one concern among many.
Evidence
Kiribati stated that damage to or disruption of their submarine cable will not degrade their services but will sever them, and that they are equally concerned by cyber-enabled fraud, phishing, ransomware against government systems, and online harm directed at children . Kiribati also cited their legislative backbone including the Cybercrime Act 2021, Digital Government Act 2023, Data Protection Act 2025, and Cybersecurity Act 2026 .
Major Discussion Point
Major Discussion Point 2: Critical Infrastructure Protection
National action has limits that only cooperation can overcome; each threat identified should connect to a concrete step enabling all states, including the smallest, to prevent, detect, and respond – Cooperation as essential complement to national action (Kiribati)
Arg. 3
Explanation
Kiribati argues that while national legislative and institutional action is important, it has inherent limits that only international cooperation can overcome, and this is the very reason the mechanism exists. The mechanism should ensure that every threat discussed connects to a concrete step that leaves every state able to prevent, detect, and respond.
Evidence
Kiribati stated that national action has limits that only cooperation can overcome, and that cooperation is the very reason these mechanisms exist . Kiribati called for discussion of threats to connect to concrete steps through the plenary and dedicated thematic groups, leaving every state, including the smallest, able to prevent, detect, and respond .
Major Discussion Point
Major Discussion Point 6: Capacity Building and International Cooperation
The mechanism was designed to be action-oriented; discussion of threats must not end as descriptions but must connect to concrete steps for all states – Action-oriented mechanism with concrete outcomes (Kiribati)
Arg. 4
Explanation
Kiribati emphasises that the global mechanism was designed to be action-oriented and that this standard must be upheld from the very first session. Discussions on threats must not merely describe those threats but must translate into concrete, practical steps for all states.
Evidence
Kiribati welcomed that the mechanism was designed to be action-oriented and stated their intention to hold it and themselves to that standard . Kiribati called for discussion of threats to not end as descriptions but to connect to concrete steps that leave every state able to prevent, detect, and respond .
Major Discussion Point
Major Discussion Point 7: Role and Structure of the Global Mechanism and Dedicated Thematic Groups
Cyber-enabled fraud and scams, phishing, ransomware against government systems, and online harm directed at children do not distinguish between large and small states but impact those with least redundancy – Online harms affecting all states disproportionately (Kiribati)
Arg. 5
Explanation
Kiribati points out that cyber threats such as fraud, phishing, ransomware, and online harm to children do not discriminate between large and small states, but their impact falls disproportionately on those with the least redundancy and the thinnest technical workforce.
Evidence
Kiribati stated that cyber-enabled fraud and scams, phishing, ransomware against government systems, and online harm directed at children do not distinguish between large and small states, but their impact falls hardest on those with the least redundancy and the thinnest technical workforce .
Major Discussion Point
Major Discussion Point 9: Disinformation, Influence Operations, and Hybrid Threats
Ransomware continues to have serious consequences across all sectors, including healthcare, and AI is rapidly transforming the cybersecurity landscape – Ransomware and AI threats (New Zealand)
Arg. 1
Explanation
New Zealand highlights that ransomware continues to cause serious consequences across all sectors of the economy, with opportunistic actors affecting organisations including in the healthcare sector across the Pacific. Additionally, AI is rapidly transforming the cybersecurity landscape, creating both new risks and defensive opportunities.
Evidence
New Zealand noted that ransomware continues to have serious consequences, with opportunistic actors impacting organisations in all sectors of the economy, and that others in the Pacific have also been affected by ransomware in the healthcare sector . New Zealand welcomed the opportunity to hear how others are seeing AI affect cybersecurity risks and what they are learning about how AI can support cyber defence .
Major Discussion Point
Major Discussion Point 1: Nature and Evolution of the Cyber Threat Landscape
AI is rapidly transforming the cybersecurity landscape; the mechanism should focus on building shared understanding of AI's implications for cybersecurity without duplicating other UN processes – AI's impact on cybersecurity and avoiding duplication (New Zealand)
Arg. 2
Explanation
New Zealand argues that while AI is rapidly transforming the cybersecurity landscape, the global mechanism should focus specifically on building shared understanding of AI's implications for cybersecurity rather than duplicating the work of other UN processes that are already addressing AI governance issues.
Evidence
New Zealand noted that there are a variety of other UN processes actively grappling with questions related to artificial intelligence, including governance issues, and that it is important that the global mechanism does not duplicate those processes . New Zealand stated that the mechanism should focus only on issues where it is uniquely well placed to add value, namely building shared understanding of the implications of AI for cybersecurity .
Major Discussion Point
Major Discussion Point 7: Role and Structure of the Global Mechanism and Dedicated Thematic Groups
The sabotage of submarine cables is one of the gravest threats; Tonga's experience with the Hunga Tonga eruption demonstrated what a malicious act could deliberately replicate – Submarine cable sabotage as a grave threat (Tonga)
Arg. 1
Explanation
Tonga draws on its direct experience of the 2022 Hunga Tonga-Hunga Ha'apai volcanic eruption, which severed the single submarine cable connecting the kingdom to the world, to illustrate the catastrophic consequences of connectivity loss. Tonga argues that what nature did by accident, a malicious actor could choose to do deliberately, making submarine cable sabotage one of the gravest threats before the mechanism.
Evidence
Tonga described how in January 2022, the eruption of Hunga Tonga-Hunga Ha’apai severed the single submarine cable connecting the kingdom to the world, leaving Tonga silent for weeks and cut off at the very moment it most needed to call for help and coordinate relief . Tonga stated that everything a volcano did by accident, a malicious act could choose to do deliberately, and that this is why Tonga regards submarine cable sabotage as one of the gravest threats before the mechanism .
Major Discussion Point
Major Discussion Point 2: Critical Infrastructure Protection
A ransomware attack encrypted Tonga's national health information system, holding medical records to ransom and forcing hospitals back to pen and paper – Ransomware attack on national health system (Tonga)
Arg. 2
Explanation
Tonga provides a concrete example of the devastating impact of ransomware on essential services, describing how an attack encrypted the national health information system, holding the medical records of the entire population to ransom and forcing hospitals to revert to manual processes.
Evidence
Tonga described that in June of the previous year, a ransomware attack encrypted their national health information system, holding the medical records of their entire population to ransom and forcing hospitals back to pen and paper . Tonga also noted that their state-owned telecommunications provider was attacked in 2023, demonstrating that no country is too small or too remote to be targeted .
Major Discussion Point
Major Discussion Point 2: Critical Infrastructure Protection
Tonga jointly attributed a ransomware attack on its Ministry of Health to an affiliate of a known ransomware group, demonstrating that small states acting with partners can pursue accountability – Small state attribution and accountability (Tonga)
Arg. 3
Explanation
Tonga highlights that even the smallest states can pursue accountability for malicious cyber activities when acting with partners, as demonstrated by the joint attribution of the ransomware attack on its Ministry of Health to an affiliate of a known ransomware group together with Australia and New Zealand.
Evidence
Tonga stated that together with Australia and New Zealand, it jointly attributed the attack on its Ministry of Health to an affiliate of a known ransomware group, demonstrating that even the smallest states acting with partners can pursue accountability for malicious cyber activities .
Major Discussion Point
Major Discussion Point 4: State-Sponsored Cyber Activities and Attribution
123
WPM
457
Words
4 min
Time
Malicious cyber activities targeting critical infrastructure have grown in scale, sophistication, and diversity, affecting vital sectors including public administration, healthcare, and financial services – Escalating cyber incidents across sectors (Netherlands)
Arg. 1
Explanation
The Netherlands reports a steady increase in the scale, sophistication, and diversity of cyber incidents affecting society, ranging from ransomware to DDoS campaigns and exploitation of vulnerabilities in edge devices. These incidents impact vital sectors including public administration, healthcare, education, transport, and financial services.
Evidence
The Netherlands observed a steady increase in the scale, sophistication, and diversity of cyber incidents, with attacks ranging from ransomware to disruptive DDoS campaigns and exploitation of vulnerabilities in edge devices and widely used software . These incidents impact vital sectors like public administration, healthcare, education, transport, and financial services, as well as international organisations based in the Netherlands .
Major Discussion Point
Major Discussion Point 1: Nature and Evolution of the Cyber Threat Landscape
The blurring of lines between state actors and non-state actors, including activist groups, is one of the most problematic trends, with states hiding behind proxies to maintain plausible deniability – State-proxy blurring and plausible deniability (Netherlands)
Arg. 2
Explanation
The Netherlands identifies the blurring of boundaries between state and non-state actors as one of the most problematic trends in the current threat landscape, with different types of actors increasingly using similar tools and sometimes operating in concert. This creates a worrying trend of state actors hiding behind proxies to maintain plausible deniability.
Evidence
The Netherlands stated that different types of actors increasingly use similar tools, target similar systems, and sometimes operate in concert, blurring traditional distinctions between motives and methods . The Netherlands described this as a worrying trend of state actors hiding behind state proxies to maintain plausible deniability .
Major Discussion Point
Major Discussion Point 4: State-Sponsored Cyber Activities and Attribution
Critical infrastructure has been repeatedly targeted, with a recent shift towards targeting means of communication such as messaging services, enabling large-scale espionage and cascading disruptions – Targeting of communications infrastructure (Netherlands)
Arg. 3
Explanation
The Netherlands highlights that critical infrastructure continues to face persistent risks, with a particularly troublesome recent shift towards targeting means of communication such as messaging services. Compromises of such infrastructure can enable large-scale espionage, manipulation of communications, or disruptions with cascading effects far beyond the specific target.
Evidence
The Netherlands noted that critical infrastructure has been repeatedly targeted and continues to face persistent risks, with a recent shift towards targeting means of communication such as messaging services . The Netherlands stated that compromises can enable large-scale espionage, manipulation of communications, or disruptions with cascading effects far beyond the specific target .
Major Discussion Point
Major Discussion Point 2: Critical Infrastructure Protection
Generative AI amplifies existing cyber threats by lowering barriers for sophisticated operations, from phishing to zero-day vulnerability discovery, while also offering defensive opportunities – Generative AI as a threat amplifier (Netherlands)
Arg. 4
Explanation
The Netherlands argues that generative AI amplifies existing cyber threats by lowering the barrier for conducting sophisticated operations, from writing convincing phishing messages to assisting in the discovery and exploitation of zero-day vulnerabilities. At the same time, these tools can and should be harnessed defensively to improve detection, analysis, and response.
Evidence
The Netherlands stated that large language models and other AI systems can lower the barrier for conducting sophisticated operations, from writing convincing phishing messages to assisting in the discovery of zero-day vulnerabilities and their exploitation . The Netherlands noted that with the use of agentic AI on the rise, the development of such threats continues to accelerate, making the threat landscape more complex by the day .
Major Discussion Point
Major Discussion Point 3: Artificial Intelligence and Emerging Technologies as Cyber Threats
The consensus UN framework injects a degree of predictability into global affairs; adequate implementation is the appropriate response to the growing complexity of the threat landscape – Implementing the consensus framework for predictability (Netherlands)
Arg. 5
Explanation
The Netherlands argues that as the threat landscape grows ever more complex, it is through the adequate implementation of the consensus UN framework that states can inject a degree of predictability into global affairs. This implementation-focused approach is the appropriate collective response to the challenges identified.
Evidence
The Netherlands stated that as the threat landscape continues to grow ever more complex, it is through the adequate implementation of the consensus UN framework that states can try to inject a degree of predictability in global affairs .
Major Discussion Point
Major Discussion Point 8: International Law and the Framework for Responsible State Behaviour
112
WPM
601
Words
5 min
Time
Cyber threats disproportionately affect small island developing states, including ransomware, cybercrime-as-a-service, attacks on critical infrastructure, AI-enabled fraud, and the nexus between cyber threats and natural disasters – Disproportionate impact on small island states (Bahamas)
Arg. 1
Explanation
The Bahamas highlights that its economy depends on digital-enabled sectors such as tourism, financial services, and maritime logistics, making it particularly vulnerable to a range of cyber threats. These threats carry consequences for small island states that are disproportionate to their size.
Evidence
The Bahamas noted that its economy depends on digital-enabled sectors including tourism, financial services, port, and maritime logistics, and that it faces ransomware, cybercrime as a service, attacks on critical infrastructure, AI-enabled fraud, mis- and disinformation, and the nexus between cyber threats and natural disasters . The Bahamas stated that all these threats carry consequences for small island states that are disproportionate to their size .
Major Discussion Point
Major Discussion Point 1: Nature and Evolution of the Cyber Threat Landscape
Capacity building is a precondition for participation for small island developing states; it must be sustained, tailored, and directed towards durable institutions and a trained workforce – Capacity building as precondition for SIDS participation (Bahamas)
Arg. 2
Explanation
The Bahamas argues that for small island developing states, capacity building is not merely beneficial but a precondition for meaningful participation in global ICT security discussions and implementation. Such capacity building must be sustained, tailored to national circumstances, and directed towards building durable institutions and a trained workforce.
Evidence
The Bahamas stated that for small island developing states, capacity building is a precondition for participation, and that it must be sustained, tailored to national circumstances, and directed towards durable institutions and a trained workforce so that developing states can be genuine contributors to global ICT security, not just recipients of it .
Major Discussion Point
Major Discussion Point 6: Capacity Building and International Cooperation
International law, including the UN Charter, is the foundation of a secure and peaceful ICT environment; voluntary norms and confidence-building measures operate in service of binding legal obligations – International law as foundation, not constraint (Bahamas)
Arg. 3
Explanation
The Bahamas asserts that international law, including the UN Charter, is the foundation of a secure and peaceful ICT environment and is a guarantee of the process rather than a constraint on it. Voluntary norms and confidence-building measures operate in service of binding legal obligations, not in place of them.
Evidence
The Bahamas stated that international law, including the UN Charter, is the foundation of a secure and peaceful ICT environment and is the guarantee of this process, not a constraint to it . The Bahamas further stated that voluntary norms and confidence-building measures operate in service of a binding legal obligation, not in place of it .
Major Discussion Point
Major Discussion Point 8: International Law and the Framework for Responsible State Behaviour
Cyber threat information sharing should be genuinely accessible to small island states, and work should stay connected to capacity building – Accessible information sharing for small states (Bahamas)
Arg. 4
Explanation
The Bahamas recommends that cyber threat discussions remain grounded in the operational experience of national CERTs and C-CERT networks, and that cyber threat information sharing be genuinely accessible to small island states. This work should remain connected to capacity building to ensure meaningful participation.
Evidence
The Bahamas recommended that cyber threat discussions remain grounded in the operational experience of national CERTs and C-CERT networks, that cyber threat information sharing be genuinely accessible to small island states, and that this work stay connected to capacity building .
Major Discussion Point
Major Discussion Point 6: Capacity Building and International Cooperation
Ransomware and cybercrime-as-a-service, attacks on critical infrastructure, AI-enabled fraud, and the nexus between cyber threats and natural disasters carry disproportionate consequences for small island states – Cybercrime disproportionately affecting small island states (Bahamas)
Arg. 5
Explanation
The Bahamas highlights that the full range of cyber threats, including ransomware, cybercrime-as-a-service, infrastructure attacks, AI-enabled fraud, and the intersection of cyber threats with natural disasters, all carry consequences for small island states that are disproportionate to their size due to limited redundancy and resources.
Evidence
The Bahamas listed ransomware, cybercrime as a service, attacks on critical infrastructure, AI-enabled fraud, mis- and disinformation, and the nexus between cyber threats and natural disasters as threats that carry consequences for small island states disproportionate to their size .
Major Discussion Point
Major Discussion Point 5: Non-State Actors and Cybercrime
141
WPM
1192
Words
8 min
Time
The United States and Israel carried out extensive malicious cyber operations against Iran's critical infrastructure and civilian services during military attacks, including over 100 cyber attacks per day – US and Israeli cyber attacks against Iran (Islamic Republic of Iran)
Arg. 1
Explanation
Iran alleges that the United States and Israel carried out unlawful military attacks accompanied by extensive malicious cyber operations directed against Iran's critical infrastructure and civilian services. During the February 2026 aggression alone, more than 100 cyber attacks were launched every day against Iran's critical and civilian infrastructure.
Evidence
Iran stated that during the February 2026 aggression alone, more than 100 cyber attacks were launched every day against Iran’s critical and civilian infrastructure . Iran described coordinated cyber and kinetic attacks targeting critical ICT infrastructure including telecommunications facilities, data centres, AI infrastructure, and private sector electronics , as well as attacks against civilian institutions including schools, universities, and media , and attacks exploiting private sector technologies and ICT supply chains including Starlink satellite communication services .
Major Discussion Point
Major Discussion Point 4: State-Sponsored Cyber Activities and Attribution
The global mechanism should give priority attention to threats already identified by member states before expanding to new threat areas, using a consolidated compilation as the basis for discussions – Prioritising previously identified threats (Islamic Republic of Iran)
Arg. 2
Explanation
Iran argues that the global mechanism should first give attention to threats already identified by member states in previous processes before expanding to new threat areas. Iran supports the preparation of a consolidated compilation of threats identified by member states as the basis for discussions in both the plenary and dedicated thematic groups.
Evidence
Iran stated that from the outset of the OEWG process, a number of states including Iran identified specific ICT-related threats that were ultimately not reflected in consensus reports, and that addressing these gaps should be a priority for the global mechanism . Iran supported the preparation of a consolidated compilation of threats identified by member states and reflected in the first OEWG Chair Summary as the basis for discussions .
Major Discussion Point
Major Discussion Point 7: Role and Structure of the Global Mechanism and Dedicated Thematic Groups
The use of ICTs for disinformation and cognitive operations, including manipulation of digital platforms to incite violence and spread hatred, represents a significant threat – Disinformation and cognitive operations as ICT threats (Islamic Republic of Iran)
Arg. 3
Explanation
Iran identifies the use of ICTs for disinformation and cognitive operations as a significant threat, including the unlawful use of mobile interception technologies, cyber-enabled surveillance, and the manipulation of digital platforms to incite violence, spread hatred, and deepen social divisions.
Evidence
Iran described cyber espionage and information operations including the unlawful use of mobile interception technologies, cyber-enabled surveillance, disinformation and cognitive operations, and the manipulation of digital platforms including Instagram, X, and Telegram to incite violence, spread hatred, deepen social divisions, and arbitrarily restrict or remove accounts associated with Iran .
Major Discussion Point
Major Discussion Point 9: Disinformation, Influence Operations, and Hybrid Threats
The framework for responsible state behaviour must be implemented consistently; states that advocate respect for international law should apply those principles consistently – Consistent application of responsible state behaviour norms (Islamic Republic of Iran)
Arg. 4
Explanation
Iran argues that states which consistently advocate respect for the UN Charter, international law, and the framework for responsible state behaviour in ICTs should apply those principles consistently and condemn malicious cyber activities directed against Iran. Selective application of these norms undermines their legitimacy.
Evidence
Iran stated that states which consistently advocate respect for the Charter of the United Nations, international law, and the framework for responsible state behaviour in ICTs should apply those principles consistently and condemn kinetic and malicious cyber activities directed against Iran .
Major Discussion Point
Major Discussion Point 8: International Law and the Framework for Responsible State Behaviour
Attacks exploiting private sector technologies and ICT supply chains, including commercial products and services, software, hardware, and digital supply chains, undermine national ICT infrastructure security – Supply chain exploitation as a cyber threat (Islamic Republic of Iran)
Arg. 5
Explanation
Iran highlights attacks that exploit private sector technologies and ICT supply chains, including commercial products and services, software, hardware, and digital supply chains, as well as the misuse of satellite communication services to facilitate hostile operations. Iran is also concerned by cyber operations exploiting commercial technologies from companies such as Cisco and HP.
Evidence
Iran described attacks exploiting private sector technologies and ICT supply chains, including commercial ICT products and services, software, hardware, and digital supply chains, as well as the misuse of Starlink satellite communication services to facilitate hostile operations . Iran also expressed concern about cyber operations exploiting commercial technologies including products and services supplied by companies such as Cisco and HP to undermine the security and resilience of national ICT infrastructure .
Major Discussion Point
Major Discussion Point 10: Supply Chain Security and Emerging Technology Risks
139
WPM
515
Words
4 min
Time
The cyber threat environment continues to intensify, with state-sponsored activity, ransomware, business email compromise, and exploitation of edge devices affecting individuals, businesses, and governments – Intensifying cyber threat environment (Australia)
Arg. 1
Explanation
Australia reports that the cyber threat environment continues to intensify, with individuals, businesses, and governments adversely affected by threats that expose sensitive information, disrupt essential services, undermine trust and economic prosperity, and contribute to risks to international peace and security.
Evidence
Australia stated that the Australian Cyber Security Centre responded to over 1,200 cybersecurity incidents and received more than 84,700 cybercrime reports in the previous year, roughly one report every six minutes . Australia identified persistent threats including state-sponsored activity targeting government, critical infrastructure and businesses, ransomware and cybercrime as a service, business email compromise, identity fraud, and exploitation of edge devices .
Major Discussion Point
Major Discussion Point 1: Nature and Evolution of the Cyber Threat Landscape
Critical infrastructure and critical information infrastructure protection should be an early focus for the mechanism, including the resilience of undersea cable infrastructure – Undersea cable resilience as a priority (Australia)
Arg. 2
Explanation
Australia argues that critical infrastructure and critical information infrastructure protection should be an early focus for the global mechanism, including through DTG1. For many countries, including Australia and others in the region, the resilience of undersea cable infrastructure is fundamental to economic and social connectivity.
Evidence
Australia stated that critical infrastructure and critical information infrastructure protection should be an early focus for the mechanism, including through DTG1 . Australia noted that for many countries, including their own in the region, the resilience of undersea cable infrastructure is fundamental to economic and social connectivity and to access to the global internet .
Major Discussion Point
Major Discussion Point 2: Critical Infrastructure Protection
AI is being used to scale social engineering, create convincing phishing content, and lower cost and skill barriers for malicious actors, including for propaganda and physical strike planning – AI enabling malicious actors at scale (Australia)
Arg. 3
Explanation
Australia highlights that AI is being used by malicious actors to scale social engineering, create more convincing phishing content, analyse stolen data, and lower the cost and skill barriers required to cause harm. Australia is particularly concerned that AI is making it easier for malicious actors to generate and spread propaganda and to prepare physical strikes.
Evidence
Australia stated that artificial intelligence is being used to scale social engineering, create more convincing phishing content, analyse stolen data, and lower the cost and skill barriers required to cause harm . Australia expressed particular concern that AI is making it easier for malicious actors to generate and spread propaganda and to prepare to carry out physical strikes by supporting planning and target selection .
Major Discussion Point
Major Discussion Point 3: Artificial Intelligence and Emerging Technologies as Cyber Threats
State responses, including development and use of cyber capabilities, must be consistent with international law, including the UN Charter, international human rights law, and international humanitarian law – State cyber capabilities must comply with international law (Australia)
Arg. 4
Explanation
Australia underlines the importance of responding to cyber threats in line with the agreed norms of responsible state behaviour, and that state responses, including the development and use of cyber capabilities, must be consistent with international law including the UN Charter, international human rights law, and international humanitarian law.
Evidence
Australia stated that state responses, including the development and use of cyber capabilities, must be consistent with international law, including the UN Charter in its entirety, international human rights law, and international humanitarian law .
Major Discussion Point
Major Discussion Point 8: International Law and the Framework for Responsible State Behaviour
Differences in national capacity affect vulnerability to malicious cyber activity and the ability to recover; cyber threats are shared but their impacts are not experienced equally – Unequal impact of cyber threats and capacity gaps (Australia)
Arg. 5
Explanation
Australia acknowledges that while cyber threats are shared across all states, their impacts are not experienced equally. Differences in national capacity can affect vulnerability to malicious cyber activity and the ability to recover when incidents occur, making capacity building an essential component of the mechanism's work.
Evidence
Australia stated that cyber threats are shared, but their impacts are not experienced equally, and that differences in national capacity can affect vulnerability to malicious cyber activity and the ability to recover when incidents occur .
Major Discussion Point
Major Discussion Point 6: Capacity Building and International Cooperation
114
WPM
279
Words
2 min
Time
Cyber attacks using ransomware targeting critical infrastructure such as hospitals and power plants can pose a threat to international peace and security – Ransomware as a threat to international peace and security (Japan)
Arg. 1
Explanation
Japan argues that ransomware attacks, particularly when they impact the operations of critical infrastructure such as hospitals and power plants, can pose a direct threat to international peace and security. Japan seeks to foster this common understanding within the UN global mechanism.
Evidence
Japan referenced its statement at the Security Council briefing on ransomware on 8 November 2024, where it stated that ransomware is one of the most destructive cyber threats undermining the operations of critical infrastructure including hospitals and power plants, and that given the overall impacts and ramifications, ransomware could certainly pose direct threats to international peace and security .
Major Discussion Point
Major Discussion Point 1: Nature and Evolution of the Cyber Threat Landscape
It is important to foster common understanding on existing and potential cyber threats in the UN global mechanism, drawing on expertise from a wide range of stakeholders including the private sector – Common understanding through multi-stakeholder engagement (Japan)
Arg. 2
Explanation
Japan emphasises the importance of fostering common understanding on existing and potential cyber threats within the UN global mechanism, and argues that this requires drawing on the expertise of a wide range of stakeholders including the private sector. Japan places great importance on expert briefings and interactive public-private discussions.
Evidence
Japan stated that it is essential to draw on the expertise of a wide range of stakeholders, including the private sector, in conducting discussions on cyber threats . Japan also stated that it places great importance on holding expert briefings and interactive public-private discussions in the substantive plenary sessions and DTGs .
Major Discussion Point
Major Discussion Point 8: International Law and the Framework for Responsible State Behaviour
The mechanism should allow sufficient time and opportunities for relevant technological experts to provide professional presentations, including as part of DTG work – Expert briefings within the mechanism (Japan)
Arg. 3
Explanation
Japan argues that the fast pace of technological development necessitates that discussions within the global mechanism be informed by thorough and up-to-date technical information. The mechanism should therefore allow sufficient time and opportunities for relevant technological experts to provide professional presentations.
Evidence
Japan stated that it is essential to draw on the expertise of a wide range of stakeholders, including the private sector, and that Japan places great importance on holding expert briefings and interactive public-private discussions in the substantive plenary sessions and DTGs .
Major Discussion Point
Major Discussion Point 7: Role and Structure of the Global Mechanism and Dedicated Thematic Groups
140
WPM
341
Words
2 min
Time
The threat landscape is evolving rapidly due to growing ICT capabilities without concomitant oversight and governance structures – Governance gap in ICT development (Guyana)
Arg. 1
Explanation
Guyana argues that the ICT threat landscape is evolving rapidly due to growing developments in ICT capabilities without corresponding oversight and governance structures. Effectively addressing existing and potential threats requires the integration of security considerations across the lifecycle of ICT products.
Evidence
Guyana stated that the ICT threat landscape is evolving rapidly due to growing developments in ICT capabilities without concomitant oversight and governance structures, and that effectively addressing existing and potential threats requires integration of security considerations across the lifecycle of ICT products .
Major Discussion Point
Major Discussion Point 1: Nature and Evolution of the Cyber Threat Landscape
The use of ICTs by non-state actors to exacerbate conflicts, including attacks targeting civilian objects, requires a holistic approach considering the transboundary nature of threats – Non-state actor exploitation of ICTs in conflicts (Guyana)
Arg. 2
Explanation
Guyana expresses particular concern about the malicious use of ICTs against critical infrastructure and the use of this technology by non-state actors to exacerbate conflicts, including through attacks targeting civilian objects. A holistic approach is required to address these threats given their multifaceted and transboundary nature.
Evidence
Guyana stated that it is particularly concerned about the malicious use of ICTs against critical infrastructure and critical information infrastructure, and the use of this technology by non-state actors to exacerbate conflicts, including through attacks targeting civilian and civilian objects . Guyana called for a holistic approach considering the multifaceted challenges and transboundary nature of these threats .
Major Discussion Point
Major Discussion Point 5: Non-State Actors and Cybercrime
Awareness, capacity building, international cooperation, and public-private partnerships are essential for detecting, defending, and responding to threats at national, regional, and international levels – Multi-level approach to threat response (Guyana)
Arg. 3
Explanation
Guyana argues that a comprehensive multi-level approach is required to address ICT threats, encompassing awareness, capacity building, international cooperation, public-private partnerships, and continued dialogue among relevant stakeholders at national, regional, and international levels.
Evidence
Guyana stated that awareness, capacity building, international cooperation, public-private partnerships, and continued dialogue among relevant stakeholders are essential for detecting, defending, and responding to threats, and that these efforts must be made at the national, regional, and international levels .
Major Discussion Point
Major Discussion Point 6: Capacity Building and International Cooperation
142
WPM
329
Words
2 min
Time
The misuse of AI, including through autonomous cyber tools and frontier models, can amplify existing vulnerabilities and undermine democratic processes and human rights – AI misuse undermining democratic processes (Greece)
Arg. 1
Explanation
Greece highlights that while AI offers great potential for innovation and global progress, its misuse through autonomous cyber tools and the advancement of frontier models can amplify existing vulnerabilities and undermine democratic processes and human rights. These capabilities are expected to soon become widely available, significantly lowering the entry barrier for sophisticated attacks.
Evidence
Greece stated that the misuse of AI, such as through autonomous cyber tools and the recent advancement of frontier models, can amplify existing vulnerabilities and undermine democratic processes and human rights . Greece noted that these capabilities are expected to soon become widely available and significantly lower the entry barrier for actors to perform sophisticated attacks .
Major Discussion Point
Major Discussion Point 3: Artificial Intelligence and Emerging Technologies as Cyber Threats
The commercial distribution of cyber capabilities has the potential to undermine privacy, human rights, and democratic institutions when deployed without adequate safeguards – Commercial cyber tools undermining human rights (Greece)
Arg. 2
Explanation
Greece identifies the proliferation of commercial cyber tools and capabilities as an important concern, noting that their commercial distribution has the potential to undermine privacy, human rights, democratic institutions, and international security when deployed without adequate safeguards. Greece welcomes initiatives such as the Pall Mall process to build international consensus on responsible use.
Evidence
Greece stated that the commercial distribution of cyber capabilities has the potential to undermine privacy, human rights, democratic institutions, and international security when deployed without adequate safeguards . Greece welcomed initiatives such as the Pall Mall process, which seeks to build international consensus on the responsible development, distribution, and use of commercial cyber intrusion capabilities .
Major Discussion Point
Major Discussion Point 5: Non-State Actors and Cybercrime
137
WPM
538
Words
4 min
Time
This mechanism succeeds by building on the consensus already achieved, not by searching for gaps; it should focus on practical implementation of the 11 consensus norms – Building on existing consensus rather than new agreements (United States)
Arg. 1
Explanation
The United States argues that the global mechanism should be grounded in practical implementation of the 11 consensus norms rather than serving as a vehicle for new legally binding agreements. The mechanism was established to do real work implementing commitments states have already made, not to search for gaps that do not exist.
Evidence
The United States stated that it continues to approach the mechanism with the objective of grounded practical implementation of the 11 consensus norms, not as a vehicle for new legally binding agreements, noting that as long as some members are maliciously conducting cyber actions against other members, a legally binding agreement is impossible . The United States stated that this mechanism succeeds by building on the consensus already achieved, not by searching for gaps that do not exist .
Major Discussion Point
Major Discussion Point 7: Role and Structure of the Global Mechanism and Dedicated Thematic Groups
States should not conduct or knowingly support malicious cyber activity targeting critical infrastructure; some members in this chamber are planning and conducting such actions – Condemnation of malicious cyber activities by member states (United States)
Arg. 2
Explanation
The United States asserts that states should not conduct or knowingly support malicious cyber activity targeting critical infrastructure, yet alleges that some members in the chamber are currently planning and conducting such actions against other members' critical infrastructure. The United States commits to identifying and holding accountable those perpetrating such activities.
Evidence
The United States stated that states should not conduct or knowingly support malicious cyber activity targeting critical infrastructure, but that there are members in the chamber right now who are planning and conducting malicious cyber actions against other members’ critical infrastructure . The United States stated it would work to specifically identify the states and non-state actors who are perpetuating malicious cyber activities against others in the room .
Major Discussion Point
Major Discussion Point 4: State-Sponsored Cyber Activities and Attribution
143
WPM
469
Words
3 min
Time
The mechanism should focus on tangible outcomes including shared threat intelligence, clear protocols for protecting subsea infrastructure, and the development of local expertise – Action-oriented mechanism with concrete outcomes (Tuvalu)
Arg. 1
Explanation
Tuvalu emphasises that norms, international law, and capacity building cannot be treated as separate silos, and urges the global mechanism to focus on tangible outcomes including shared threat intelligence, clear protocols for protecting subsea infrastructure, and the development of local expertise. Tuvalu stands ready to engage constructively to ensure the mechanism serves as a driver of meaningful action.
Evidence
Tuvalu urged the global mechanism to focus on tangible outcomes including shared threat intelligence, clear protocols for protecting subsea infrastructure like the Aotevaca Cable, and the development of local expertise . Tuvalu emphasised that norms, international law, and capacity building cannot be treated as separate silos, in line with the integrated approach of A-79-214 and A-80-257 .
Major Discussion Point
Major Discussion Point 7: Role and Structure of the Global Mechanism and Dedicated Thematic Groups
123
WPM
447
Words
4 min
Time
For developing countries, capacity constraints and uneven cyber resilience increase vulnerability and limit the ability to respond effectively to cyber incidents – Capacity constraints in developing countries (Zimbabwe)
Arg. 1
Explanation
Zimbabwe highlights that for developing countries, capacity constraints and uneven cyber resilience increase vulnerability and limit the ability to respond effectively to cyber incidents, risking progress towards digital transformation and sustainable development. Developing countries cannot afford to be left exposed or left behind.
Evidence
Zimbabwe stated that for developing countries, capacity constraints and uneven cyber resilience increase vulnerability and limit the ability to effectively respond to cyber incidents, risking progress towards digital transformation and sustainable development . Zimbabwe stated that they cannot afford to be left exposed, nor can they afford to be left behind .
Major Discussion Point
Major Discussion Point 6: Capacity Building and International Cooperation
Protecting critical ICT infrastructure and strengthening cybersecurity resilience are national priorities, particularly as a land-linked developing country relying on interconnected regional networks – Cross-border infrastructure vulnerabilities for developing countries (Zimbabwe)
Arg. 2
Explanation
Zimbabwe emphasises that as a land-linked developing country relying on interconnected regional telecommunications networks for connectivity, trade, and essential services, protecting critical ICT infrastructure and strengthening cybersecurity resilience are national priorities. Vulnerabilities within shared digital infrastructure can have cross-border consequences.
Evidence
Zimbabwe stated that as a land-linked developing country that relies on interconnected regional telecommunications networks for connectivity, trade, and essential services, vulnerabilities within shared digital infrastructure can have cross-border consequences . Zimbabwe noted that this reinforces the importance of enhancing regional cooperation and building the technical capacity of developing countries to prevent, detect, and respond to malicious ICT activity .
Major Discussion Point
Major Discussion Point 2: Critical Infrastructure Protection
The spread of disinformation and misinformation through digital platforms, and the rapid advancement and malicious use of AI reshaping the cyber threat landscape, are of growing concern – Disinformation and AI-enabled deception (Zimbabwe)
Arg. 3
Explanation
Zimbabwe expresses concern about the spread of disinformation and misinformation through digital platforms, as well as the rapid advancement and malicious use of artificial intelligence, which is reshaping the cyber threat landscape by enabling more convincing deception and introducing fresh complexities for cybersecurity resilience and response.
Evidence
Zimbabwe stated that it is concerned by the spread of disinformation and misinformation through digital platforms . Zimbabwe also stated that it is equally concerned by the rapid advancement and malicious use of artificial intelligence, which is reshaping the cyber threat landscape, enabling more convincing deception, and introducing fresh complexities for cybersecurity resilience and response .
Major Discussion Point
Major Discussion Point 9: Disinformation, Influence Operations, and Hybrid Threats
140
WPM
834
Words
6 min
Time
Albania observed state-sponsored cyber operations against public institutions, combined with disinformation campaigns via Telegram to amplify psychological impact and erode public trust – State-sponsored attacks combined with disinformation (Albania)
Arg. 1
Explanation
Albania reports that recent cyber incidents against public institutions were supported by state-sponsored cyber operations, and were followed by attempts to spread disinformation and manipulate public perception through social media platforms, specifically via Telegram. These activities sought to amplify the psychological impact of cyber incidents and erode trust in public institutions.
Evidence
Albania stated that recent incidents, four of them only in March 2026, targeted public institutions including the Albanian parliament, Albanian post office, the office of the general prosecutor, and the director of prisons, and were supported by state-sponsored cyber operations . Albania observed attempts to spread disinformation and manipulate public perception through social media and communication platforms, specifically via Telegram, following these incidents .
Major Discussion Point
Major Discussion Point 4: State-Sponsored Cyber Activities and Attribution
Contemporary cyber threats increasingly combine cyber operations with information manipulation activities, seeking to amplify psychological impact and erode trust in public institutions – Combination of cyber operations and disinformation (Albania)
Arg. 2
Explanation
Albania argues that contemporary cyber threats are no longer limited to technical intrusions but increasingly combine cyber operations with disinformation and influence activities. This combination seeks to amplify the psychological impact of cyber incidents, generate public uncertainty, and erode trust in public institutions.
Evidence
Albania stated that a particularly concerning trend is the continued combination of cyber operations with information manipulation activities, and that following cyber incidents, Albania observed attempts to spread disinformation and manipulate public perception through social media and communication platforms, specifically via Telegram . Albania stated that these activities demonstrate that contemporary cyber threats are no longer limited to technical intrusions but increasingly combine cyber operations, disinformation, and influence activities .
Major Discussion Point
Major Discussion Point 9: Disinformation, Influence Operations, and Hybrid Threats
The impact of militant online activity on young people, including cyberbullying and deliberate spread of disinformation, represents an emerging security concern deserving greater international attention – Online harms to youth as an emerging security concern (Albania)
Arg. 3
Explanation
Albania highlights the growing impact of militant online activity on young people, including the rapid spread of disinformation, manipulation of online content, and cyberbullying through social media and digital platforms. Albania argues that these phenomena represent not only a social issue but an emerging security concern that deserves greater international attention.
Evidence
Albania stated that the rapid spread of disinformation, manipulation of online content, and cyberbullying through social media and digital platforms pose increasingly serious risks to the safety, well-being, and resilience of younger generations . Albania stated that the use of AI has made the ecosystem even more insecure and has increased the exposure of young people who are more easily manipulated online .
Major Discussion Point
Major Discussion Point 9: Disinformation, Influence Operations, and Hybrid Threats
Ensuring states act responsibly in cyberspace, refrain from supporting malicious activities, and cooperate in addressing threats is essential for preserving international peace and security – State responsibility and cooperation for peace (Albania)
Arg. 4
Explanation
Albania argues that ensuring states act responsibly in cyberspace, refrain from supporting malicious activities, and cooperate in addressing threats is essential for preserving international peace, security, and stability in an increasingly interconnected world. Albania remains fully committed to working constructively with the global mechanism and all partners.
Evidence
Albania stated that ensuring states act responsibly in cyberspace, refrain from supporting malicious activities, and cooperate in addressing threats is essential for preserving international peace, security, and stability in an increasingly interconnected world .
Major Discussion Point
Major Discussion Point 8: International Law and the Framework for Responsible State Behaviour
138
WPM
826
Words
6 min
Time
The use of ICTs for purposes contradicting the UN Charter, including undermining sovereignty and interfering in internal affairs, represents the greatest danger in the current threat landscape – ICT misuse against UN Charter principles (Russian Federation)
Arg. 1
Explanation
The Russian Federation argues that the greatest danger in the current threat landscape lies in the use of ICTs for purposes that contradict the UN Charter, specifically to undermine the sovereignty of states, violate their territorial integrity, and interfere in their internal affairs. This represents the core threat that the global mechanism should address.
Evidence
The Russian Federation stated that the greatest danger lies in the use of ICTs for purposes that contradict the UN Charter to undermine the sovereignty of states, violate their territorial integrity, and interfere in their internal affairs .
Major Discussion Point
Major Discussion Point 8: International Law and the Framework for Responsible State Behaviour
The monetisation of the private sector, with major ICT developers embedded in military-industrial complexes and acting as contractors for intelligence agencies, creates serious risks for international stability – Militarisation of private ICT sector (Russian Federation)
Arg. 2
Explanation
The Russian Federation highlights a dangerous trend in which major ICT developers, including AI companies, are deeply embedded in the military-industrial complexes of the countries where they are registered and act as contractors for intelligence agencies and military departments. This undermines trust in their products and creates serious risks for international stability and security.
Evidence
The Russian Federation stated that major ICT developers which supply their products throughout the world, including AI, now make no secret of how deeply they are embedded in the military-industrial complexes of the countries where they are registered, and often act as contractors for intelligence agencies and military departments . The Russian Federation stated that this situation predictably undermines trust in the products of these companies and creates serious risks for international stability and security .
Major Discussion Point
Major Discussion Point 5: Non-State Actors and Cybercrime
Accusations against states should be substantiated with evidence; no evidence has been provided through existing channels including the UN Points of Contact Directory – Requirement for substantiated evidence in attributions (Russian Federation)
Arg. 3
Explanation
The Russian Federation argues that accusations of organising and implementing wrongful acts brought against states should be substantiated with evidence, as required by UNGA Resolution 73/27. The Russian Federation contends that no evidence has been provided either publicly or bilaterally, nor have existing channels for identifying the true sources of malicious activity been used.
Evidence
The Russian Federation stated that in accordance with UNGA Resolution 73/27, accusations of organising and implementing wrongful acts brought against states should be substantiated, and that no evidence has been provided neither in public nor bilaterally, nor have the existing channels for identifying the true sources of malicious activity been used, including the UN Points of Contact Directory .
Major Discussion Point
Major Discussion Point 4: State-Sponsored Cyber Activities and Attribution
Disagreed with
FranceGermanyUkraineUnited StatesAlbaniaPoland
on: Attribution of state-sponsored cyber attacks and the evidentiary standard required
The issue of undeclared malicious capabilities, including backdoors embedded by developers for intelligence agencies without notifying end users, is used for espionage and physical damage – Backdoors and undeclared malicious capabilities (Russian Federation)
Arg. 4
Explanation
The Russian Federation highlights the growing problem of undeclared malicious capabilities, including backdoors embedded at the software and hardware levels by developers in the interests of intelligence agencies without notifying end users. Such tools are used for intelligence, espionage, interception of personal data, and as demonstrated by the Pager incident in Lebanon in 2024, for causing physical damage.
Evidence
The Russian Federation stated that the international community is increasingly confronting the problem of so-called backdoors at the software and hardware levels embedded by developers in the interests of intelligence agencies without notifying end users . The Russian Federation cited the Pager incident in Lebanon in 2024 as an example of such tools being used for causing physical damage .
Major Discussion Point
Major Discussion Point 10: Supply Chain Security and Emerging Technology Risks
Low-orbit satellite communication systems created under the pretext of civilian connectivity are used for military-political objectives and interference in internal affairs of states – Militarisation of low-orbit satellite systems (Russian Federation)
Arg. 5
Explanation
The Russian Federation argues that low-orbit satellite communication systems, created under the pretext of providing reliable internet connectivity for civilian purposes, are in fact used for military-political objectives and to interfere in the internal affairs of states. The Russian Federation calls for operators of such systems to act in strict accordance with the national legislation of the countries in which they provide services.
Evidence
The Russian Federation stated that low-orbit satellite communication systems are in fact used for military-political objectives in the interests of certain countries, and cited cases in which such systems have been used to interfere in the internal affairs of states by inciting protests, as well as their use in armed conflicts . The Russian Federation noted that this topic was discussed at an informal UN Security Council meeting in December 2025 .
Major Discussion Point
Major Discussion Point 10: Supply Chain Security and Emerging Technology Risks
121
WPM
502
Words
4 min
Time
Addressing ransomware requires timely information sharing, strengthened incident response capabilities, public-private partnerships, technical assistance, and sustainable capacity building – Practical cooperation to address ransomware (Philippines)
Arg. 1
Explanation
The Philippines highlights ransomware as an area where practical implementation and international cooperation can deliver immediate benefits. Addressing ransomware requires a comprehensive approach including timely information sharing, strengthened incident response capabilities, public-private partnerships, technical assistance, and sustainable capacity building.
Evidence
The Philippines stated that addressing ransomware requires timely information sharing, strengthened incident response capabilities, public-private partnerships, technical assistance, and sustainable capacity building . The Philippines noted that given the transnational nature of ransomware, continued cooperation among member states remains essential to strengthening collective resilience .
Major Discussion Point
Major Discussion Point 6: Capacity Building and International Cooperation
131
WPM
586
Words
4 min
Time
Russia's ongoing war of aggression against Ukraine includes deliberate targeting of critical infrastructure, telecommunications, and state registries as part of a broader hybrid warfare strategy – Russian cyber aggression as part of hybrid warfare (Ukraine)
Arg. 1
Explanation
Ukraine argues that for over a decade, cyberspace has been one of the principal theatres of Russia's ongoing war of aggression against Ukraine, with Russian malicious ICT activities forming part of a broader strategy combining cyberattacks with kinetic strikes, disinformation campaigns, and other hybrid warfare tools. Since the full-scale invasion, Russia has deliberately targeted public authorities, critical infrastructure, and private businesses in Ukraine and beyond.
Evidence
Ukraine stated that for over a decade, cyberspace remains one of the principal theatres of Russia’s ongoing war of aggression against Ukraine, and that Russian malicious ICT activities are not isolated incidents but form part of a broader strategy combining cyberattacks with kinetic strikes, disinformation campaigns, and other hybrid warfare tools . Ukraine stated that since the beginning of the full-scale invasion, Russia has deliberately targeted public authorities, critical infrastructure, energy sector, telecommunications networks, state registries, and private businesses in Ukraine and beyond .
Major Discussion Point
Major Discussion Point 4: State-Sponsored Cyber Activities and Attribution
Hybrid campaigns combining cyber operations, disinformation, and economic coercion seek to undermine international peace and security – Hybrid campaigns as a systemic threat (Ukraine)
Arg. 2
Explanation
Ukraine highlights that it continues to witness hybrid campaigns combining cyber operations, disinformation, and economic coercion that seek to undermine international peace and security. These campaigns, combined with rapid technological developments including AI and quantum technologies, create unprecedented challenges for the international community.
Evidence
Ukraine stated that it continues to witness hybrid campaigns combining cyber operations, disinformation, and economic coercion that seek to undermine international peace and security . Ukraine noted that rapid technological developments including artificial intelligence, quantum technologies, and increasingly interconnected digital ecosystems create unprecedented opportunities for innovation while simultaneously expanding the attack surface available to malicious actors .
Major Discussion Point
Major Discussion Point 9: Disinformation, Influence Operations, and Hybrid Threats
Malicious ICT activities are not isolated incidents but form part of broader strategies combining cyberattacks with kinetic strikes, disinformation, and hybrid warfare tools – Hybrid warfare combining cyber and kinetic operations (Ukraine)
Arg. 3
Explanation
Ukraine argues that malicious ICT activities are not isolated incidents but form part of broader strategies that combine cyberattacks with kinetic strikes, disinformation campaigns, and other hybrid warfare tools. Over time, Russia's cyber operations have evolved from destructive attacks into sophisticated campaigns involving cyber espionage, long-term network persistence, supply chain compromise, and information manipulation.
Evidence
Ukraine stated that Russian malicious ICT activities are not isolated incidents but form part of a broader strategy that combines cyberattacks with kinetic strikes, disinformation campaigns, and other hybrid warfare tools . Ukraine noted that over time, Russia’s cyber operations have evolved from destructive attacks into sophisticated campaigns involving attempts for cyber espionage, long-term network persistence, supply chain compromise, and information manipulation .
Major Discussion Point
Major Discussion Point 8: International Law and the Framework for Responsible State Behaviour
125
WPM
629
Words
5 min
Time
Critical infrastructure protection represents a national priority and an essential component of international security, with digitisation increasing the risk of systemic effects – Critical infrastructure as a national and international security priority (Chile)
Arg. 1
Explanation
Chile argues that the protection of critical infrastructure represents both a national priority and an essential component of international security in the use of ICTs. The gradual digitisation and interconnection of critical sectors increases the possibility of attacks and the risk of cyber incidents having systemic effects, impacting the provision of essential services.
Evidence
Chile stated that for Chile, the protection of critical infrastructure represents a national priority and an essential component of international security in the use of ICTs . Chile noted that the gradual digitisation and interconnection of critical sectors increases the possibility of attacks and the risk of cybernetic incidents having systemic effects, impacting the provision of services that are essential for the population .
Major Discussion Point
Major Discussion Point 2: Critical Infrastructure Protection
AI is changing the reach of malicious cyber attacks, contributing to phishing, malicious software, and sophisticated attacks, and must be understood as multiplying existing threats – AI as a multiplier of existing threats (Chile)
Arg. 2
Explanation
Chile notes that AI is changing the reach of malicious cyber attacks and making it easier for them to adapt, contributing to the expansion of phishing attacks, malicious software, and increasing the sophistication of cyber attacks. AI must be understood as having the potential to multiply existing threats and as a source of new risk factors and vectors.
Evidence
Chile stated that AI is changing the reach of malicious cybernetic attacks and making it easier for them to adapt, and that AI is contributing to the expansion of phishing attacks, malicious software, and increasing the sophistication of cybernetic attacks, as well as fostering the dissemination of manipulated content . Chile stated that AI must be understood as having the potential to multiply existing threats and also as a source of new risk factors and vectors .
Major Discussion Point
Major Discussion Point 3: Artificial Intelligence and Emerging Technologies as Cyber Threats
Future risks related to quantum computing, alongside ransomware, exploitation of digital supply chains, and cloud-connected software, require continued attention – Quantum computing as a future risk factor (Chile)
Arg. 3
Explanation
Chile argues that it is necessary to keep attention on ransomware and other destructive forms of malicious software, the exploitation of the digital supply chain, cloud-connected software, and future risks related to quantum computing. These topics have already been identified by Chile as requiring continued attention.
Evidence
Chile stated that it is necessary to dedicate attention to ransomware and other destructive forms of malicious software, the exploitation of the digital supply chain, cloud-connected software, and future risks related to quantum computing, amongst others, and that these topics have already been identified by Chile as requiring continued attention .
Major Discussion Point
Major Discussion Point 10: Supply Chain Security and Emerging Technology Risks
The first DTG provides a particularly valuable opportunity for regular, structured, evidence-based dialogue on the evolution of threats, with a forward-looking approach and expert participation – Evidence-based forward-looking dialogue in DTG1 (Chile)
Arg. 4
Explanation
Chile argues that the dedicated thematic group focused on policies and cross-cutting issues provides a particularly valuable opportunity for driving regular, structured, evidence-based dialogue on the evolution of threats and their implications for international peace and security. This work should have a forward-looking approach and incorporate evidence and information from experts, regional organisations, the scientific community, and the private sector.
Evidence
Chile stated that the dedicated thematic group number one gives a particularly valuable opportunity for driving regular, structured dialogue that is evidence-based on the evolution of threats and their implications for international peace and security . Chile stated that a substantive discussion on emerging threats requires incorporating evidence and information that very often lies outside of government, and that the participation of experts, regional organisations, the scientific community, the private sector, and other interested parties is essential .
Major Discussion Point
Major Discussion Point 7: Role and Structure of the Global Mechanism and Dedicated Thematic Groups
Malicious ICT activities are becoming increasingly sophisticated, persistent, and transnational, with growing misuse of AI, ransomware, and supply chain compromises – Growing sophistication and persistence of threats (Malawi)
Arg. 1
Explanation
Malawi highlights that malicious ICT activities are becoming increasingly sophisticated, persistent, and transnational, with the growing misuse of AI, ransomware, supply chain compromises, attacks on critical infrastructure, and attacks on undersea cables and cloud services demonstrating that no state is immune.
Evidence
Malawi stated that malicious ICT activities are becoming increasingly sophisticated, persistent, and transnational, and that the growing misuse of artificial intelligence, ransomware, supply chain compromises, attacks on critical infrastructure, computer emergency response teams, undersea cables, and cloud services demonstrates that no state is immune .
Major Discussion Point
Major Discussion Point 1: Nature and Evolution of the Cyber Threat Landscape
Strengthening national CERTs, enhancing cyber threat intelligence, promoting early warning mechanisms, and improving trusted information sharing should feature prominently in the mechanism's work – Strengthening national response capabilities (Malawi)
Arg. 2
Explanation
Malawi argues that the global mechanism's work should prominently feature the strengthening of national computer emergency response teams, enhancing cyber threat intelligence, promoting early warning mechanisms, and improving trusted information sharing. Resilient response capabilities are just as important as resilient infrastructure.
Evidence
Malawi stated that strengthening national computer emergency response teams, enhancing cyber threat intelligence, promoting early warning mechanisms, and improving trusted information sharing should feature prominently in the work of the dedicated thematic group . Malawi stated that resilient response capabilities are just as important as resilient infrastructure .
Major Discussion Point
Major Discussion Point 6: Capacity Building and International Cooperation
AI is lowering barriers for malicious actors to conduct phishing, malware development, fraud, and disinformation at unprecedented speeds and scale – AI enabling malicious activities at unprecedented scale (Malawi)
Arg. 3
Explanation
Malawi recognises both the opportunities and risks of AI, noting that while AI can significantly strengthen cyber defence, it is also lowering the barriers for malicious actors to conduct phishing, malware development, fraud, and disinformation at unprecedented speeds and scale. Discussions should focus on enabling responsible innovation while preventing malicious use.
Evidence
Malawi stated that AI is lowering the barriers for malicious actors to conduct phishing, malware development, fraud, and disinformation at unprecedented speeds and scale . Malawi stated that discussions should focus on enabling responsible innovation while preventing malicious use .
Major Discussion Point
Major Discussion Point 3: Artificial Intelligence and Emerging Technologies as Cyber Threats
133
WPM
731
Words
5 min
Time
France has been the target of persistent cyber attacks by Russia's FSB for over ten years; attribution was conducted in accordance with responsible state behaviour norms – Attribution of Russian FSB cyber attacks against France (France)
Arg. 1
Explanation
France reports that on 13 July it announced it had been the target for more than ten years of persistent cyber attacks carried out by Russia's Federal Security Service (FSB). France emphasises that this attribution process was conducted in accordance with the norms for responsible state behaviour and following having exhausted appropriate channels.
Evidence
France announced that on 13 July, France announced that it had been the target for more than 10 years of persistent cyber attacks carried out by the Russian Federal Security Service, the FSB . France stated that contrary to what the Russian Federation has stated, this attribution process was conducted in accordance with the norms for responsible state behaviour and following having exhausted appropriate channels .
Major Discussion Point
Major Discussion Point 4: State-Sponsored Cyber Activities and Attribution
AI is increasing the speed of offensive operations and enabling scaling of existing practices, while the rapid increase in frontier model capabilities risks creating a new digital divide – AI acceleration of offensive operations and digital divide (France)
Arg. 2
Explanation
France identifies AI as increasing the speed at which malicious actors can conduct offensive operations and enabling the scaling up of existing practices such as seeking vulnerabilities. More importantly, the rapid increase in cyber capabilities of AI frontier models carries the risk of creating a new digital divide between those who have access to these models and those who do not.
Evidence
France stated that while AI is not yet fundamentally altering the nature of attacks, it is increasing the speed at which malicious actors can conduct offensive operations and enabling the scaling up of existing practices such as seeking vulnerabilities . France stated that the rapid increase in cyber capabilities of AI frontier models carries the risk of a new digital divide between those who have access to these models and those who are able to independently assess the risks associated with them .
Major Discussion Point
Major Discussion Point 3: Artificial Intelligence and Emerging Technologies as Cyber Threats
The uncontrolled proliferation of commercial cyber intrusion capabilities without adequate oversight and accountability measures multiplies risks to the stability of cyberspace – Uncontrolled proliferation of commercial cyber tools (France)
Arg. 3
Explanation
France identifies the uncontrolled proliferation of cyber intrusion capabilities available on the market as a veritable ticking time bomb. Without minimal oversight and accountability measures, the number of actors, including non-state actors, capable of acquiring advanced capabilities will continue to grow, multiplying risks to the stability of cyberspace.
Evidence
France stated that without minimal oversight and accountability measures, the number of actors, including non-state actors, capable of acquiring advanced capabilities will continue to grow, multiplying the risks to the stability of cyberspace . France shared progress made with the United Kingdom as part of the Pall Mall process, including the launch of negotiations on guidelines for the cyber intrusion industry .
Major Discussion Point
Major Discussion Point 5: Non-State Actors and Cybercrime
155
WPM
713
Words
5 min
Time
Ransomware paralysing humanitarian and critical services – Ransomware paralysing humanitarian and critical services (Germany)
Arg. 1
Explanation
Germany highlights that ransomware attacks have paralysed not only government and critical infrastructure providers but also not-for-profit organisations, including a leading humanitarian organisation providing food relief in conflict regions, putting people's lives abroad at risk.
Evidence
Germany stated that over the past year, it has experienced a continuously high level of ransomware attacks targeted especially at critical infrastructure providers, municipal and government services, and not-for-profit organisations . Germany cited a specific example of a ransomware attack that paralysed a leading humanitarian organisation providing food relief in conflict regions, with risks of famine and putting people’s lives abroad at risk .
Major Discussion Point
Major Discussion Point 2: Critical Infrastructure Protection
Russian state-sponsored attacks on EU and Ukraine – Russian state-sponsored attacks on EU and Ukraine (Germany)
Arg. 2
Explanation
Germany reports that together with the European Union and its member states and the North Atlantic Council, it has exposed and condemned a series of malicious cyber activities conducted by Russian state actors, in particular the FSB, and by state-supported cyber criminal and hacktivist groups. These activities targeted government entities and critical infrastructure in several EU member states and in Ukraine.
Evidence
Germany stated that together with the European Union and its member states and the North Atlantic Council, Germany exposed and condemned a series of malicious cyber activities conducted by Russian state actors, in particular the FSB, and by state-supported cyber criminal and hacktivist groups . Germany noted that these activities targeted government entities and critical infrastructure in several EU member states and in Ukraine, some of which had the potential for catastrophic damage of civilian energy infrastructure such as electricity networks or hydroelectric dams .
Major Discussion Point
Major Discussion Point 4: State-Sponsored Cyber Activities and Attribution
AI lowering barriers for malicious actors (Germany)
Arg. 3
Explanation
Germany observes that the advent of advanced AI facilitates large-scale attacks including language-agnostic credible phishing, voice phishing, and social engineering attacks, continuously lowering the barrier to entry for opportunistic malicious cyber actors. This creates an increasing strain on defenders' resources and puts particular strain on less resourced and small countries.
Evidence
Germany stated that the advent of advanced cyber capabilities facilitates large-scale attacks including language-agnostic credible phishing, voice phishing, and social engineering attacks, and that the barrier to entry for opportunistic malicious cyber actors is continuously lowered . Germany noted an increasing strain on defenders’ resources and on maintainers of open source repositories, which puts particular strain on less resourced and small countries .
Major Discussion Point
Major Discussion Point 3: Artificial Intelligence and Emerging Technologies as Cyber Threats
Agreed with
New ZealandNetherlandsAustraliaJapanGreeceLatviaChileMalawiFranceCanadaIndonesiaChinaRepublic of KoreaMauritiusZimbabwe
on: Artificial intelligence is transforming the cyber threat landscape by lowering barriers for malicious actors and amplifying existing threats, while also offering defensive opportunities
134
WPM
564
Words
4 min
Time
Cyber threats have become persistent challenges affecting national security, economic stability, and social cohesion, with ransomware remaining one of the most pervasive threats – Persistent and pervasive cyber threats (Latvia)
Arg. 1
Explanation
Latvia reports that cyber threats have become persistent challenges affecting national security, economic stability, and social cohesion, with a recent ransomware attack on state information systems serving as a reminder of this reality. Ransomware remains one of the most pervasive threats, with criminal groups having developed industrial-scale operations.
Evidence
Latvia stated that in Latvia, a recent ransomware attack on state information systems once again reminded them of the reality of cyber threats . Latvia stated that ransomware remains one of the most pervasive threats, with criminal groups having developed industrial-scale operations leveraging encryption, infostealer malware, data theft, and extortion to generate enormous profits .
Major Discussion Point
Major Discussion Point 1: Nature and Evolution of the Cyber Threat Landscape
Criminal groups have developed industrial-scale ransomware operations leveraging encryption, infostealer malware, data theft, and extortion to generate enormous profits – Industrial-scale ransomware criminal operations (Latvia)
Arg. 2
Explanation
Latvia highlights that criminal groups have developed industrial-scale ransomware operations, leveraging encryption, infostealer malware, data theft, and extortion to generate enormous profits. State-linked cyber operations also pose significant risks, with incidents targeting electoral systems, public administration, and critical infrastructure.
Evidence
Latvia stated that criminal groups have developed industrial-scale operations, leveraging encryption, infostealer malware, data theft, and extortion to generate enormous profits . Latvia also noted that state-linked cyber operations pose significant risks, with incidents targeting electoral systems, public administration, and critical infrastructure raising concerns about the potential for destabilisation .
Major Discussion Point
Major Discussion Point 5: Non-State Actors and Cybercrime
AI-enabled tools can automate reconnaissance, accelerate vulnerability discovery, and generate highly convincing phishing campaigns, overwhelming cyber defenders' capacity to respond – AI supercharging malicious cyber activities (Latvia)
Arg. 3
Explanation
Latvia highlights that AI is transforming the cyber threat landscape as a whole, with AI-enabled tools capable of automating reconnaissance, accelerating and scaling vulnerability discovery, and generating highly convincing phishing campaigns. The access to and ease of use of AI-enabled tools supercharges the potential vectors and scale of malicious cyber activities, which can overwhelm cyber defenders' capacity to respond.
Evidence
Latvia stated that AI-enabled tools can automate reconnaissance, accelerate and scale vulnerability discovery, and generate highly convincing phishing campaigns . Latvia stated that the access to and ease of use of AI-enabled tools supercharges the potential vectors and scale of malicious cyber activities, which can overwhelm cyber defenders’ capacity to respond .
Major Discussion Point
Major Discussion Point 3: Artificial Intelligence and Emerging Technologies as Cyber Threats
The DTGs should focus on specific ICT security challenges, enabling states to examine threats, share experience, develop practical approaches, and turbocharge capacity-building efforts – DTGs as vehicles for practical action (Latvia)
Arg. 4
Explanation
Latvia argues that the dedicated thematic groups should be central to achieving an action-oriented approach, focusing on specific ICT security challenges and enabling states to examine threats, share experience, and develop practical approaches. The DTGs should also help turbocharge capacity-building efforts, recognising that global cyber resilience depends on ensuring all states can protect their digital infrastructure.
Evidence
Latvia stated that the DTGs should focus on specific ICT security challenges, enabling states to examine threats, share experience, and develop practical approaches . Latvia stated that the DTGs should also be focused on the development of new technologies and help turbocharge capacity-building efforts, recognising that global cyber resilience depends on ensuring that all states can protect their digital infrastructure .
Major Discussion Point
Major Discussion Point 7: Role and Structure of the Global Mechanism and Dedicated Thematic Groups
137
WPM
1103
Words
8 min
Time
Israel's actions were conducted in accordance with international law in the context of an ongoing armed conflict with Iran, which has been waging hostility across all domains including cyber – Israeli actions conducted within international law (Israel)
Arg. 1
Explanation
Israel asserts that its actions during operations Rising Lion and Roaring Lion were conducted in accordance with international law, including the UN Charter and the laws of armed conflict, in the context of an ongoing armed conflict with Iran. Israel argues that Iran has been waging hostility against Israel across all domains of warfare, including the cyber domain.
Evidence
Israel stated that its actions during operations Rising Lion and Roaring Lion were conducted in accordance with international law, including the UN Charter and the laws of armed conflict, and were carried out in the context of an ongoing armed conflict with Iran . Israel stated that Iran has been waging against Israel, together with its non-state terrorist armed groups and proxies, while bluntly violating international law .
Major Discussion Point
Major Discussion Point 4: State-Sponsored Cyber Activities and Attribution
Certain states grant absolute impunity to criminal syndicates and terrorist proxies offering hacking as a service, operating from state-sanctioned safe havens – State-sanctioned safe havens for cybercriminals (Israel)
Arg. 2
Explanation
Israel identifies as a substantial threat the absolute impunity granted by certain states to criminal syndicates and terrorist proxies offering hacking as a service, which operate from state-sanctioned safe havens. Israel also highlights the illicit financing of these operations via digital assets as a global trend that should preoccupy the global mechanism's discussions.
Evidence
Israel stated that another substantial threat is the absolute impunity granted by certain states to criminal syndicates and terrorist proxies offering hacking as a service, which operate from state-sanctioned safe havens . Israel noted that the illicit financing of these operations via digital assets is a global trend which should preoccupy the global mechanism discussions, including on international cooperation relating to tracking, freezing, and seizing of cryptocurrencies used for illicit activities .
Major Discussion Point
Major Discussion Point 5: Non-State Actors and Cybercrime
126
WPM
442
Words
4 min
Time
Frontier AI capabilities as a security risk (Canada)
Arg. 1
Explanation
Canada highlights that frontier AI models have displayed unprecedented capabilities in autonomous vulnerability discovery, zero-day vulnerability exploit generation, and multi-stage orchestration of malicious cyber activity. Canada notes a joint statement issued by cybersecurity agencies of Canada, the United States, the United Kingdom, New Zealand, and Australia on the risks posed by rapidly accelerating offensive and defensive capabilities of frontier AI models.
Evidence
Canada noted the joint statement issued by the cybersecurity agencies of Canada, the United States, the United Kingdom, New Zealand, and Australia on the risks posed by rapidly accelerating offensive and defensive capabilities of frontier AI models to the security of information technology and critical infrastructure worldwide . Canada stated that these models have displayed unprecedented capabilities in autonomous vulnerability discovery, zero-day vulnerability exploit generation, and multi-stage orchestration of malicious cyber activity .
Major Discussion Point
Major Discussion Point 3: Artificial Intelligence and Emerging Technologies as Cyber Threats
Agreed with
New ZealandNetherlandsAustraliaJapanGreeceGermanyLatviaChileMalawiFranceIndonesiaChinaRepublic of KoreaMauritiusZimbabwe
on: Artificial intelligence is transforming the cyber threat landscape by lowering barriers for malicious actors and amplifying existing threats, while also offering defensive opportunities
Growing threats to critical infrastructure (Canada)
Arg. 2
Explanation
Canada observes that cyber threats to its critical infrastructure are almost certainly increasing, with primary threats coming from cyber criminals, state-sponsored actors, and increasingly non-state actors. Canada also notes the growing threat from large-scale covert networks of internet-connected devices used to disguise the origins and attributions of cyber attacks.
Evidence
Canada stated that in Canada, cyber threats to critical infrastructure are almost certainly increasing, and that primary threats to these systems come from cyber criminals, state-sponsored actors, and increasingly non-state actors . Canada noted that it has joined the United Kingdom Joint Cyber Advisory on defending against state-linked covert networks, which warns of large-scale covert networks of internet-connected devices being used to disguise the origins and attributions of cyber attacks .
Major Discussion Point
Major Discussion Point 2: Critical Infrastructure Protection
on: The blurring of lines between state and non-state actors, including the use of proxies, is a growing and concerning trend in the cyber threat landscape
126
WPM
328
Words
3 min
Time
The cyber threat landscape is characterised by increasingly sophisticated attacks, including APTs, ransomware, and phishing, posing serious risks to critical infrastructure and essential services – Sophisticated threats to critical infrastructure (Indonesia)
Arg. 1
Explanation
Indonesia reports that the landscape of existing and potential ICT threats continues to evolve rapidly, with growing sophistication of malicious activities including advanced persistent threats, ransomware, and phishing posing serious risks. Threats targeting critical infrastructure and critical information infrastructure have intensified, reflecting constant and relentless pressures on national and regional stability.
Evidence
Indonesia stated that the growing sophistication of malicious activities, including advanced persistent threats, ransomware, and phishing activities, poses serious risks . Indonesia noted that threats targeting critical infrastructure and critical information infrastructure, including cross-border systems, have intensified, not only periodically but every single day, reflecting constant and relentless pressures on national and regional stability .
Major Discussion Point
Major Discussion Point 1: Nature and Evolution of the Cyber Threat Landscape
AI and quantum computing complicating threats (Indonesia)
Arg. 2
Explanation
Indonesia highlights that emerging technologies such as artificial intelligence and quantum computing further complicate the threat landscape by lowering barriers to malicious activity while simultaneously creating new dependencies and vulnerabilities. A threat environment of this scale and complexity requires the global mechanism to prioritise practical, needs-based support.
Evidence
Indonesia stated that emerging technologies such as artificial intelligence and quantum computing further complicate the threat landscape, lowering barriers to malicious activity while simultaneously creating new dependencies and vulnerabilities .
Major Discussion Point
Major Discussion Point 3: Artificial Intelligence and Emerging Technologies as Cyber Threats
Agreed with
New ZealandNetherlandsAustraliaJapanGreeceGermanyLatviaChileMalawiFranceCanadaChinaRepublic of KoreaMauritiusZimbabwe
on: Artificial intelligence is transforming the cyber threat landscape by lowering barriers for malicious actors and amplifying existing threats, while also offering defensive opportunities
Regional cooperation for resilience building (Indonesia)
Arg. 3
Explanation
Indonesia argues that cooperation among states, including through ASEAN, OIC, and Asia-Pacific mechanisms, is indispensable for building resilience through threat analysis, shared early warning arrangements, and structured exchange on incident trends. Strengthening cooperation among CERTs and improving information sharing mechanisms are essential to building resilience.
Evidence
Indonesia stated that the global mechanism, including its DTGs, should focus on fostering cooperation in threat analysis, shared early warning arrangements, and structured exchange on incident trends to ensure that developing countries are not left behind . Indonesia noted that it is actively participating in regional and international mechanisms including ASEAN, OIC, and Asia-Pacific mechanisms for technical information sharing, coordinated incident response, and joint capacity building .
Major Discussion Point
Major Discussion Point 6: Capacity Building and International Cooperation
on: Capacity building is essential for developing countries and small island developing states to meaningfully participate in and benefit from the global mechanism
100
WPM
347
Words
3 min
Time
The misuse of ICTs by both state and non-state actors continues to pose serious threats, with increasing sophistication particularly targeting critical infrastructure – State and non-state actor misuse of ICTs (Thailand)
Arg. 1
Explanation
Thailand is deeply concerned by the increasing number and sophistication of cyber threats, particularly those targeting critical infrastructure and critical information infrastructure. Malicious actors, including advanced persistent threat groups, are employing increasingly sophisticated techniques that pose serious risks to national security, economic stability, and the delivery of essential public services.
Evidence
Thailand stated that its national assessment for 2025 indicates a continued rise in cyber incidents, especially those involving information content security, cyber fraud, and intrusion attempts . Thailand noted that malicious actors, including advanced persistent threat groups, are employing increasingly sophisticated techniques that pose serious risks to national security, economic stability, and the delivery of essential public services .
Major Discussion Point
Major Discussion Point 1: Nature and Evolution of the Cyber Threat Landscape
Supply chain vulnerabilities harming developing countries (Thailand)
Arg. 2
Explanation
Thailand highlights that ICT supply chain disruptions, including the deliberate insertion of vulnerabilities, backdoors, or other forms of interference, undermine economic and digital development, particularly in developing countries. Addressing these challenges requires strengthened international cooperation to ensure that emerging technologies are developed and used in a safe, secure, and responsible manner.
Evidence
Thailand stated that ICT supply chain disruptions, including deliberate insertion of ICT-related threats, vulnerabilities, backdoors, or other forms of interference, undermine economic and digital development, particularly in developing countries . Thailand stated that addressing these challenges requires strengthened international cooperation to ensure that emerging technologies are developed and used in a safe, secure, and responsible manner .
Major Discussion Point
Major Discussion Point 10: Supply Chain Security and Emerging Technology Risks
116
WPM
271
Words
2 min
Time
The threat landscape is characterised by intensification of cyber attacks, systematic targeting of critical infrastructure, proliferation of cybercrime service models, and misinformation campaigns – Multi-dimensional threat landscape (Morocco)
Arg. 1
Explanation
Morocco describes the current threat landscape as characterised by the intensification of cyber attacks led by state and non-state actors, systematic targeting of critical infrastructure and essential services, proliferation of cybercrime service models facilitating large-scale attacks, misinformation campaigns, and the impact of emerging technologies including AI.
Evidence
Morocco described the threat landscape as characterised by intensification of cyber attacks led by state and non-state actors with a transfer of capacity to criminal groups, systematic targeting of critical infrastructure, proliferation of cybercrime service models including ransomware and DDoS attacks, misinformation campaigns, and the impact of emerging technologies including AI .
Major Discussion Point
Major Discussion Point 1: Nature and Evolution of the Cyber Threat Landscape
117
WPM
461
Words
4 min
Time
International law applies fully in cyberspace (Micronesia)
Arg. 1
Explanation
Micronesia affirms that international law applies in cyberspace, and that respect for sovereignty, the prohibition on the threat or use of force, and human rights obligations must guide state conduct online as they do offline. Micronesia supports the voluntary consensus-based framework of norms for responsible state behaviour as fundamental to addressing both existing and potential ICT-related threats.
Evidence
Micronesia affirmed that international law applies in cyberspace, and that respect for sovereignty, the provision on the threat or use of force, and human rights obligations must guide state conduct online as they do offline . Micronesia supported the voluntary consensus-based frameworks of norms for responsible state behaviour as fundamental to addressing both existing and potential ICT-related threats to international security .
Major Discussion Point
Major Discussion Point 8: International Law and the Framework for Responsible State Behaviour
on: International law, including the UN Charter, applies in cyberspace and provides the foundation for responsible state behaviour
Rights-respecting definitions of disinformation (Micronesia)
Arg. 2
Explanation
Micronesia advocates for clear and rights-respecting definitions of disinformation, warning that vague approaches can suppress dissent and independent media, erode human rights, politicise enforcement, weaken trust in institutions, and disproportionately harm marginalised and remote communities. Micronesia urges states to adopt precise, time-bound, and rights-based definitions of disinformation.
Evidence
Micronesia stated that vague approaches to disinformation can suppress dissent and independent media, erode human rights, politicise enforcement, weaken trust in institutions, and disproportionately harm marginalised and remote communities, while also impairing crisis response . Micronesia urged states to adopt precise, time-bound, and rights-based definitions of disinformation .
Major Discussion Point
Major Discussion Point 9: Disinformation, Influence Operations, and Hybrid Threats
Agreed with
Islamic Republic of IranAlbaniaZimbabweUkraineMauritiusAustraliaRussia
on: Disinformation and information manipulation, increasingly combined with cyber operations, represent a growing and serious threat
Disagreed with
Islamic Republic of IranRussian FederationAlbaniaZimbabwe
on: Whether the mechanism should address disinformation and cognitive operations as ICT threats
Malicious cyber activities impact governments, businesses, and critical information infrastructure, with APTs and ransomware among the most serious concerns – APTs and ransomware as primary concerns (Malaysia)
Arg. 1
Explanation
Malaysia reports that malicious cyber activities continue to impact governments, businesses, and critical information infrastructure across a wide range of sectors, with advanced persistent threats and ransomware remaining among the most serious concerns. Malaysia's national monitoring shows that a large share of reported incidents involve critical information infrastructure.
Evidence
Malaysia stated that its national monitoring shows that a large share of reported incidents involve critical information infrastructure, most notably across trade and industry, government, agriculture and plantations, defence and security, healthcare, as well as banking and finance . Malaysia stated that APTs, followed closely by ransomware, remain among its most serious concerns .
Major Discussion Point
Major Discussion Point 1: Nature and Evolution of the Cyber Threat Landscape
Quantum computing and post-quantum cryptography (Malaysia)
Arg. 2
Explanation
Malaysia highlights that it is preparing for the security implications of quantum computing, especially regarding current encryption systems, and is developing a national post-quantum cryptography migration plan focused on safeguarding critical information infrastructure. This work forms a core part of Malaysia's broader strategy to build long-term cyber resilience.
Evidence
Malaysia stated that it is preparing for the security implications of quantum computing, especially regarding current encryption systems, and is currently developing a national post-quantum cryptography migration plan focused on safeguarding critical information infrastructure . Malaysia stated that this work forms a core part of its broader strategy to build long-term cyber resilience .
Major Discussion Point
Major Discussion Point 10: Supply Chain Security and Emerging Technology Risks
Practical national experience sharing (Malaysia)
Arg. 3
Explanation
Malaysia argues that the mechanism's work under the threats pillar should focus on practical, grounded discussions that help states collectively better understand the threat landscape. This may include sharing national experiences on how states protect critical assets, handle APTs and ransomware, and manage the risks of emerging technologies.
Evidence
Malaysia stated that its work under this pillar should focus on practical, grounded discussions that can help states collectively better understand the threat landscape, including sharing national experience on how states protect critical assets, handle the threats of APTs and ransomware, and manage the risk of emerging technologies .
Major Discussion Point
Major Discussion Point 7: Role and Structure of the Global Mechanism and Dedicated Thematic Groups
143
WPM
735
Words
5 min
Time
Malicious ICT activities have become increasingly sophisticated, frequent, and consequential, posing a growing threat to international peace and security – Growing frequency and consequences of malicious ICT activities (Cameroon)
Arg. 1
Explanation
Cameroon recognises that malicious ICT activities have become increasingly sophisticated, frequent, and consequential, posing a growing threat to international peace and security. These threats have tangible repercussions on the security and integrity of critical infrastructure, the stability of economies, and the delivery of essential public services.
Evidence
Cameroon stated that as recognised in the consensus final report of the OEWG, malicious ICT activities have become increasingly sophisticated, frequent, and consequential, posing a growing threat to international peace and security . Cameroon noted that these threats have tangible repercussions on the security and integrity of critical infrastructure, the stability of economies, the delivery of essential public services, and the daily lives and well-being of populations .
Major Discussion Point
Major Discussion Point 1: Nature and Evolution of the Cyber Threat Landscape
The establishment of a Dedicated Voluntary Fund under the Global Mechanism is essential to support national cybersecurity institution building and facilitate participation in DTG meetings – Dedicated Voluntary Fund for developing countries (Cameroon)
Arg. 2
Explanation
Cameroon affirms support for the establishment of a Dedicated Voluntary Fund under the Global Mechanism as an essential instrument to support national cybersecurity institution building, provide resources for training and skills development, and facilitate participation in DTG meetings and capacity building programmes.
Evidence
Cameroon affirmed support for the establishment of the Dedicated Voluntary Fund under the Global Mechanism as an essential instrument to support national cybersecurity institution building, provide resources for training and skills development, facilitate participation in DTG meetings, and capacity building programmes .
Major Discussion Point
Major Discussion Point 6: Capacity Building and International Cooperation
111
WPM
933
Words
8 min
Time
States should oppose acts of aggression through cyber means, respect digital sovereignty, and uphold multilateralism to address risks effectively, including formulating new international rules – Multilateralism and digital sovereignty in cyber governance (China)
Arg. 1
Explanation
China argues that states should oppose acts of aggression through cyber means, respect each other's digital sovereignty, and uphold multilateralism to address risks effectively. China calls for the formulation of new international rules to address the impact of emerging technologies and prevent new domains from turning into lawless zones of zero-sum games.
Evidence
China stated that states should oppose acts of aggression through cyber means, respect digital sovereignty, and promote development for all . China called for countries to respect each other’s digital sovereignty, uphold multilateralism, and consider establishing global standards and systems for testing and assessing the risk of large AI models .
Major Discussion Point
Major Discussion Point 8: International Law and the Framework for Responsible State Behaviour
New generation large AI models have demonstrated powerful offensive and defensive cyber capabilities, making the risk posed by AI no longer merely theoretical – AI posing real and immediate threats (China)
Arg. 2
Explanation
China highlights that a new generation of large AI models has demonstrated powerful cyber capabilities, both offensive and defensive, leading to global concern. China argues that the risk posed by AI is no longer merely theoretical but is now a real and immediate threat, making the work of the mechanism and its DTGs not optional but a responsibility.
Evidence
China stated that not long ago, a new generation of large models issued by certain AI companies demonstrated powerful cyber capabilities, both offensive and defensive, which led to global concern . China stated that in the past, the risk posed by AI was merely theoretical, but now the real threats AI poses can be seen firsthand, making the mechanism including the DTG not an option but a responsibility .
Major Discussion Point
Major Discussion Point 3: Artificial Intelligence and Emerging Technologies as Cyber Threats
106
WPM
604
Words
6 min
Time
Cyber threats are growing in scale and sophistication, with AI being leveraged by terrorist groups and malicious actors targeting national and governmental institutions – AI-enabled threats and national experience (Oman)
Arg. 1
Explanation
Oman reports that cyber threats are growing in scale and sophistication, with AI being leveraged by terrorist groups which use malware including backdoors. Oman's Electronic Defence Centre has addressed many cyber threats and risks targeting national and governmental institutions, including 19 cyber incidents targeting private and public institutions.
Evidence
Oman stated that cyber threats are growing in scale and sophistication and are used with the help of AI by terrorist groups which use malware including backdoors . Oman noted that its Electronic Defence Centre has addressed many cyber threats and risks targeting national and governmental institutions, and had to address 19 cyber incidents targeting private and public institutions, leading to data breaches and disruption of information systems .
Major Discussion Point
Major Discussion Point 1: Nature and Evolution of the Cyber Threat Landscape
112
WPM
616
Words
5 min
Time
Cyber criminals are increasingly leveraging emerging technologies, including AI, to conduct more sophisticated and targeted malicious cyber activities – AI-driven cybercrime evolution (Mauritius)
Arg. 1
Explanation
Mauritius reports that the cyber threat landscape continues to evolve at an unprecedented pace, with cyber criminals increasingly leveraging emerging technologies including AI to conduct more sophisticated and targeted malicious cyber activities. Mauritius is particularly concerned by cyber incidents affecting critical information infrastructure and essential services.
Evidence
Mauritius stated that cyber criminals are increasingly leveraging emerging technologies, including artificial intelligence, to conduct more sophisticated and targeted malicious cyber activities . Mauritius stated that it is particularly concerned by cyber incidents affecting critical information infrastructure and essential services, malicious activities conducted through social media platforms, phishing and online fraud targeting individuals and businesses, identity theft, online financial scams, data breaches, and DDoS attacks .
Major Discussion Point
Major Discussion Point 1: Nature and Evolution of the Cyber Threat Landscape
AI-generated disinformation undermining public trust (Mauritius)
Arg. 2
Explanation
Mauritius is concerned about the growing risks posed by the malicious use of AI to generate convincing deepfakes, clone voices, spread disinformation, and enable sophisticated forms of fraud including cryptocurrency-related scams. Such misuse has the potential to facilitate cybercrime, undermine public trust, compromise the integrity of information, and disproportionately impact vulnerable groups.
Evidence
Mauritius stated that it is mindful of the growing risks posed by the malicious use of artificial intelligence to generate convincing deepfakes, clone voices, spread disinformation, and enable sophisticated forms of fraud, including cryptocurrency-related scams . Mauritius stated that such misuse has the potential to facilitate cybercrime, undermine public trust, compromise the integrity of information, and disproportionately impact vulnerable groups, including children and older persons .
Major Discussion Point
Major Discussion Point 9: Disinformation, Influence Operations, and Hybrid Threats
Agreed with
Islamic Republic of IranAlbaniaZimbabweUkraineMicronesiaAustraliaRussia
on: Disinformation and information manipulation, increasingly combined with cyber operations, represent a growing and serious threat
AI-enabled fraud and disinformation targeting vulnerable groups (Mauritius)
Arg. 3
Explanation
Mauritius highlights that the malicious use of AI to generate deepfakes, clone voices, spread disinformation, and enable sophisticated fraud disproportionately impacts vulnerable groups including children and older persons. This misuse has the potential to facilitate cybercrime and undermine public trust.
Evidence
Mauritius stated that the malicious use of artificial intelligence to generate convincing deepfakes, clone voices, spread disinformation, and enable sophisticated forms of fraud, including cryptocurrency-related scams, has the potential to facilitate cybercrime, undermine public trust, compromise the integrity of information, and disproportionately impact vulnerable groups, including children and older persons .
Major Discussion Point
Major Discussion Point 3: Artificial Intelligence and Emerging Technologies as Cyber Threats
125
WPM
342
Words
3 min
Time
Malicious cyber activities are becoming increasingly sophisticated, complex, and difficult to detect, with frontier AI models further transforming the threat landscape – Evolving sophistication and AI impact (Republic of Korea)
Arg. 1
Explanation
The Republic of Korea reports that malicious cyber activities are becoming increasingly sophisticated, complex, and difficult to detect and respond to. The rapid advancement of frontier AI models has further transformed the cyber threat landscape, enabling increasingly sophisticated cyber operations while raising concerns that existing cyber defence mechanisms may become less effective.
Evidence
The Republic of Korea stated that malicious cyber activities are becoming increasingly sophisticated, complex, and difficult to detect and respond to . The Republic of Korea noted that since the adoption of the OEWG final report, the rapid advancement of frontier AI models has further transformed the cyber threat landscape, enabling increasingly sophisticated cyber operations while raising concerns that existing cyber defence mechanisms may become less effective .
Major Discussion Point
Major Discussion Point 1: Nature and Evolution of the Cyber Threat Landscape
Frontier AI transforming the threat landscape (Republic of Korea)
Arg. 2
Explanation
The Republic of Korea argues that the global mechanism should deepen discussions on AI-enabled cyber threats and ensure that international dialogue remains timely and responsive to the rapidly changing technological environment. The rapid advancement of frontier AI models has further transformed the cyber threat landscape beyond what was recognised in the OEWG final report.
Evidence
The Republic of Korea stated that the global mechanism should deepen discussions on AI-enabled cyber threats and ensure that international dialogue remains timely and responsive to the rapidly changing technological environment .
Major Discussion Point
Major Discussion Point 3: Artificial Intelligence and Emerging Technologies as Cyber Threats
Agreed with
New ZealandNetherlandsAustraliaJapanGreeceGermanyLatviaChileMalawiFranceCanadaIndonesiaChinaMauritiusZimbabwe
on: Artificial intelligence is transforming the cyber threat landscape by lowering barriers for malicious actors and amplifying existing threats, while also offering defensive opportunities
Cryptocurrency theft financing illicit activities (Republic of Korea)
Arg. 3
Explanation
The Republic of Korea highlights that ransomware and cryptocurrency theft have become major sources of financing for illicit activities, including illicit arms trafficking and the development of weapons of mass destruction. The global mechanism should continue and deepen discussions on this issue, reaffirming that such activities threaten international peace and security.
Evidence
The Republic of Korea recalled that the final reports of the OEWG recognised cryptocurrency theft as a threat with implications for international peace and security . The Republic of Korea stated that ransomware and cryptocurrency theft have become major sources of financing for illicit activities, and that states should reaffirm that such activities threaten international peace and security, especially when linked to illicit arms trafficking or the development of weapons of mass destruction .
Major Discussion Point
Major Discussion Point 5: Non-State Actors and Cybercrime
Deepening AI threat discussions in the mechanism (Republic of Korea)
Arg. 4
Explanation
The Republic of Korea argues that the global mechanism should deepen discussions on AI-enabled cyber threats and ensure that international dialogue remains timely and responsive to the rapidly changing technological environment. The mechanism should serve as a platform for sustained and in-depth discussion on the evolving threat landscape.
Evidence
The Republic of Korea stated that the global mechanism should deepen discussions on AI-enabled cyber threats and ensure that international dialogue remains timely and responsive to the rapidly changing technological environment . The Republic of Korea stated that the global mechanism should be a platform for sustained and in-depth discussion on the evolving threat landscape, enabling member states to strengthen collective understanding and enhance collective capacity to prevent, respond to, and recover from cyber threats .
Major Discussion Point
Major Discussion Point 7: Role and Structure of the Global Mechanism and Dedicated Thematic Groups
82
WPM
314
Words
4 min
Time
Protecting submarine cables as strategic assets (Ghana)
Arg. 1
Explanation
Ghana highlights that the damage to Submarine Cable 7 Ghana in 2024 and the resulting disruption to digital services reinforced the importance of protecting such infrastructure as a strategic national asset. Ghana has identified 13 critical information infrastructure sectors under its Cybersecurity Act 2020 and is strengthening its national incident response architecture.
Evidence
Ghana stated that the damage to Submarine Cable 7 Ghana in 2024 and the resulting disruption to digital services reinforce the importance of protecting such infrastructure as a strategic national asset . Ghana noted that it has identified 13 critical information infrastructure sectors under the Cyber Security Act 2020, which provides for the registration of critical information infrastructure, establishes obligations for operators, and requires regular compliance audits .
Major Discussion Point
Major Discussion Point 2: Critical Infrastructure Protection
on: Critical infrastructure protection, including submarine cables and undersea infrastructure, must be a priority for the global mechanism
162
WPM
556
Words
3 min
Time
Humanitarian and economic effects of infrastructure attacks (Iraq)
Arg. 1
Explanation
Iraq expresses concern at the increasing cyber activities targeting civilian critical infrastructure, including the energy, telecommunications, and financial sectors, and the serious humanitarian and economic effects that may result, particularly for developing countries that continue to face challenges in strengthening their national cybersecurity capacities.
Evidence
Iraq stated that it wishes to express concern at the increasing cyber activities targeting civilian critical infrastructure, including the energy, telecommunications, and financial sectors, and the serious humanitarian and economic effects that may result therefrom, particularly for developing countries that continue to face challenges in strengthening their national capacities in the field of cybersecurity .
Major Discussion Point
Major Discussion Point 2: Critical Infrastructure Protection
on: Critical infrastructure protection, including submarine cables and undersea infrastructure, must be a priority for the global mechanism
Terrorist exploitation of ICTs and infrastructure attacks (Iraq)
Arg. 2
Explanation
Iraq highlights the growing risks arising from the exploitation of ICTs by terrorist groups, including the use of cyberspace for recruitment, dissemination of extremist ideology, financing, planning, and coordination of terrorist operations, as well as the targeting of critical infrastructure. Drawing on Iraq's national experience in combating terrorism, Iraq affirms the importance of confronting these unlawful uses.
Evidence
Iraq stated that it wishes to affirm the growing risks arising from the exploitation of ICTs by terrorist groups, including the use of cyberspace for recruitment, the dissemination of extremist ideology, financing, planning, and coordination of terrorist operations, as well as the targeting of critical infrastructure . Iraq stated that drawing on its national experience in combating terrorism, it affirms the importance of confronting these unlawful uses .
Major Discussion Point
Major Discussion Point 2: Critical Infrastructure Protection
ICT supply chain security as a cross-border priority (Iraq)
Arg. 3
Explanation
Iraq argues that strengthening the security of ICT supply chains and exchanging relevant international best practices and standards constitute an important element in reducing cross-border cyber risks. Addressing these threats requires strengthening international cooperation, exchanging information and expertise, and supporting the development of new technologies.
Evidence
Iraq stated that strengthening the security of information and communications technology supply chains and exchanging relevant international best practices and standards constitute an important element in reducing cross-border cyber risks . Iraq affirmed that addressing these threats requires strengthening international cooperation, exchanging information and expertise, and supporting the development of new technologies .
Major Discussion Point
Major Discussion Point 10: Supply Chain Security and Emerging Technology Risks
on: International law, including the UN Charter, applies in cyberspace and provides the foundation for responsible state behaviour
118
WPM
420
Words
4 min
Time
Russian malicious cyber activities against Poland (Poland)
Arg. 1
Explanation
Poland reports that a sustained pattern of malicious cyber activity by Russian actors has been observed in Poland since at least 2010, with Russia's security services undertaking actions to gain unauthorised access to sensitive networks and exfiltrate protected information from government, armed forces, and private entities. These activities include strategic reconnaissance, prepositioning, and disruptive sabotage operations targeting Polish critical infrastructure.
Evidence
Poland stated that since at least 2010, Russia’s security services have undertaken actions to gain unauthorised access to sensitive networks and to exfiltrate protected information from government, Polish armed forces, and private entities . Poland noted that malicious cyber actors have engaged in deliberately establishing persistent footholds within critical systems with apparent intent to enable future disruptive or destructive effects against basic and essential civilian services .
Major Discussion Point
Major Discussion Point 4: State-Sponsored Cyber Activities and Attribution
on: Attribution of state-sponsored cyber attacks and the evidentiary standard required
96
WPM
352
Words
4 min
Time
Capacity building must be predictable, sustainable, demand-driven, and accompanied by technology transfer, institutional strengthening, and equitable access to knowledge – Sustainable and equitable capacity building (Mozambique)
Arg. 1
Explanation
Mozambique argues that sustainable cybersecurity requires strong institutions, skilled professionals, trusted partnerships, and effective international cooperation. Capacity building should be predictable, sustainable, demand-driven, and accompanied by technology transfer, institutional strengthening, and equitable access to knowledge and expertise.
Evidence
Mozambique stated that sustainable cybersecurity requires strong institutions, skilled professionals, trusted partnerships, and effective international cooperation to address increasingly sophisticated and transnational cyber threats . Mozambique stated that capacity building should be predictable, sustainable, demand-driven, and accompanied by technology transfer, institutional strengthening, and equitable access to knowledge and expertise .
Major Discussion Point
Major Discussion Point 6: Capacity Building and International Cooperation
Collective preparedness through the mechanism (Mozambique)
Arg. 2
Explanation
Mozambique expects the global mechanism to become an implementation-oriented platform that translates agreed commitments into tangible outcomes, particularly for developing countries. The mechanism should strengthen collective preparedness to address existing and emerging ICT threats, including ransomware attacks against critical infrastructure and the malicious use of AI.
Evidence
Mozambique stated that it expects the mechanism to become an implementation-oriented platform that translates agreed commitments into tangible outcomes, particularly for developing countries . Mozambique stated that the mechanism should strengthen collective preparedness to address existing and emerging ICT threats, including ransomware attacks against critical infrastructure, the malicious use of artificial intelligence, and other rapidly evolving cyber risks that increasingly affect developing countries .
Major Discussion Point
Major Discussion Point 7: Role and Structure of the Global Mechanism and Dedicated Thematic Groups
on: International law, including the UN Charter, applies in cyberspace and provides the foundation for responsible state behaviour
124
WPM
1555
Words
13 min
Time
Delegations should deliver abridged statements and submit full versions to eStatements to ensure all delegations can be heard within the available time – Managing speaking time to ensure inclusive participation (Chair)
Arg. 1
Explanation
The Chair requests that delegations keep their statements concise and submit full versions electronically, in order to ensure that all 30 remaining speakers on the list can be heard. This procedural guidance is aimed at balancing inclusivity with the practical constraints of conference time.
Evidence
The Chair indicated that while there is no established limit for delivering statements, it would be appreciated if delegations could deliver an abridged version and submit the full statement to eStatements and to the chair’s team, as this would help ensure all delegations are heard . The Chair also noted that a timer would be projected on the screen .
Major Discussion Point
Major Discussion Point 7: Role and Structure of the Global Mechanism and Dedicated Thematic Groups
Rights of reply should be exercised at the end of the speakers' list, not during the substantive discussion, to allow all delegations to make their national capacity statements first – Procedural guidance on rights of reply (Chair)
Arg. 2
Explanation
The Chair clarifies that delegations wishing to exercise a right of reply should make their request to the Secretariat so that speaking time can be allocated at the end of the list of speakers, as was done in prior meetings. This ensures that the substantive discussion is not interrupted by political exchanges.
Evidence
The Chair noted that the right of reply should be done at the end of the meeting, and that any delegation wishing to speak under the right of reply should make the request to the Secretariat so that speaking time can be requested at the end of the list of speakers, as was done in prior meetings of this group .
Major Discussion Point
Major Discussion Point 7: Role and Structure of the Global Mechanism and Dedicated Thematic Groups
The list of speakers for inscriptions should be closed to manage the agenda and ensure other items can be addressed within the available time – Closing the speakers' list to protect the agenda (Chair)
Arg. 3
Explanation
The Chair announces the closure of the speakers' list for new inscriptions, noting that the list has grown longer than predicted and risks preventing the meeting from addressing other agenda items. This decision is taken to protect the integrity of the overall programme of work.
Evidence
The Chair asked the Secretariat to close the list of speakers for inscriptions, noting that since the previous day the list had continued to grow much longer than predicted, which could impact the ability to address other items on the agenda . The Chair noted that there were 21 speakers still on the list with only one hour and forty minutes remaining .
Major Discussion Point
Major Discussion Point 7: Role and Structure of the Global Mechanism and Dedicated Thematic Groups
Upon completion of the threats agenda item, the meeting will immediately proceed to the agenda item on voluntary norms for responsible state behaviour – Sequencing of agenda items (Chair)
Arg. 4
Explanation
The Chair announces that as soon as the current agenda item on existing and potential threats is completed, the meeting will immediately move to the next agenda item on voluntary norms for responsible state behaviour in cyberspace. This signals the Chair's intention to maintain momentum and cover all substantive items.
Evidence
The Chair stated that as soon as the threats agenda item is completed, the meeting will immediately begin the next agenda item, which is the voluntary norms for responsible state behaviour in cyberspace and forms of implementation, recognising that over time additional norms may be elaborated . The Chair asked delegations to be ready .
Major Discussion Point
Major Discussion Point 7: Role and Structure of the Global Mechanism and Dedicated Thematic Groups
Session Knowledge Graph
Speakers · Topics · Arguments · Relationships
Interactive graph · embed active
Agreed Points
Ransomware poses a serious and growing threat to critical infrastructure, including healthcare, and represents a threat to international peace and security
A broad coalition of states agreed that ransomware represents one of the most serious and pervasive cyber threats. Tonga described a ransomware attack that encrypted its national health information system, forcing hospitals back to pen and paper . Japan explicitly stated at the Security Council that ransomware ‘could certainly pose direct threats to international peace and security’ . Germany cited a ransomware attack that paralysed a humanitarian organisation providing food relief in conflict regions . Latvia noted that criminal groups have developed industrial-scale ransomware operations . The Philippines called for timely information sharing and public-private partnerships to address ransomware . This near-universal agreement on ransomware as a critical threat was one of the strongest consensus points in the discussion.
Ransomware and AI threats (New Zealand)
Ransomware attack on national health system (Tonga)
Ransomware as a threat to international peace and security (Japan)
Escalating cyber incidents across sectors (Netherlands)
Intensifying cyber threat environment (Australia)
Ransomware paralysing humanitarian and critical services (Germany)
Industrial-scale ransomware criminal operations (Latvia)
Practical cooperation to address ransomware (Philippines)
Critical infrastructure as a national and international security priority (Chile)
Growing sophistication and persistence of threats (Malawi)
AI-enabled threats and national experience (Oman)
APTs and ransomware as primary concerns (Malaysia)
Growing frequency and consequences of malicious ICT activities (Cameroon)
Multi-dimensional threat landscape (Morocco)
Policy Context (Knowledge Base)
This assessment is corroborated by Australia’s statement at the organisational session of the Global Mechanism, which explicitly noted that ‘ransomware, phishing, distributed denial of service attacks are becoming more frequent, coordinated and disruptive’ [S163]. The link between ICT threats and international peace and security is also embedded in the foundational cybersecurity policy framework discussed in UN contexts [S164].
Artificial intelligence is transforming the cyber threat landscape by lowering barriers for malicious actors and amplifying existing threats, while also offering defensive opportunities
There was near-universal agreement that AI is fundamentally changing the cyber threat landscape. The Netherlands noted that large language models can lower the barrier for conducting sophisticated operations, from phishing to zero-day vulnerability discovery . Australia stated that AI is being used to scale social engineering and lower cost and skill barriers for malicious actors . Germany observed that AI facilitates large-scale attacks including language-agnostic phishing and social engineering . Latvia noted that AI-enabled tools can automate reconnaissance and generate highly convincing phishing campaigns, potentially overwhelming defenders . France highlighted that the rapid increase in frontier AI model capabilities carries the risk of a new digital divide . Canada noted that frontier AI models have displayed unprecedented capabilities in autonomous vulnerability discovery and multi-stage orchestration of malicious activity . Virtually all speakers agreed that while AI poses threats, it also offers defensive opportunities.
Ransomware and AI threats (New Zealand)
Generative AI as a threat amplifier (Netherlands)
AI enabling malicious actors at scale (Australia)
Common understanding through multi-stakeholder engagement (Japan)
AI misuse undermining democratic processes (Greece)
AI lowering barriers for malicious actors (Germany)
AI-enabled tools supercharging malicious cyber activities (Latvia)
AI as a multiplier of existing threats (Chile)
AI enabling malicious activities at unprecedented scale (Malawi)
AI acceleration of offensive operations and digital divide (France)
Frontier AI capabilities as a security risk (Canada)
AI and quantum computing complicating threats (Indonesia)
AI posing real and immediate threats (China)
Frontier AI transforming the threat landscape (Republic of Korea)
AI-driven cybercrime evolution (Mauritius)
Disinformation and AI-enabled deception (Zimbabwe)
Policy Context (Knowledge Base)
Australia’s statement at the Global Mechanism organisational session directly referenced AI as amplifying cyber risks [S163]. The UN First Committee discussion on cybersecurity and AI similarly highlighted the misuse of AI and emerging technologies as a key concern for ICT infrastructure protection [S160]. This reflects a broader consensus emerging across multiple UN forums on AI’s dual-use nature in the cyber domain.
New ZealandNetherlandsAustraliaJapanGreeceGermanyLatviaChileMalawiFranceCanadaIndonesiaChinaRepublic of KoreaMauritiusZimbabwe
Critical infrastructure protection, including submarine cables and undersea infrastructure, must be a priority for the global mechanism
There was broad consensus that critical infrastructure protection must be a central focus of the global mechanism. Kiribati stated that for a nation served by a small number of cables, critical infrastructure protection is ‘existential’ . Tonga described how the severing of its submarine cable during the 2022 volcanic eruption left the kingdom silent for weeks , and argued that a malicious actor could deliberately replicate this . Australia called for critical infrastructure and critical information infrastructure protection to be an early focus for the mechanism, including through DTG1 . The Netherlands highlighted a troubling shift towards targeting means of communication such as messaging services . Ghana noted that damage to Submarine Cable 7 Ghana in 2024 reinforced the importance of protecting such infrastructure as a strategic national asset .
Submarine cable as existential infrastructure (Kiribati)
Submarine cable sabotage as a grave threat (Tonga)
Ransomware and AI threats (New Zealand)
Targeting of communications infrastructure (Netherlands)
Undersea cable resilience as a priority (Australia)
Ransomware as a threat to international peace and security (Japan)
Critical infrastructure as a national and international security priority (Chile)
Cross-border infrastructure vulnerabilities for developing countries (Zimbabwe)
Growing threats to critical infrastructure (Canada)
Protecting submarine cables as strategic assets (Ghana)
Humanitarian and economic effects of infrastructure attacks (Iraq)
AI-enabled threats and national experience (Oman)
APTs and ransomware as primary concerns (Malaysia)
Growing frequency and consequences of malicious ICT activities (Cameroon)
Multi-dimensional threat landscape (Morocco)
Sophisticated threats to critical infrastructure (Indonesia)
State and non-state actor misuse of ICTs (Thailand)
Policy Context (Knowledge Base)
The UN First Committee discussion explicitly listed undersea cables among ICT infrastructure threats requiring cooperative measures [S160]. Expert panels have emphasised the importance of designating submarine cables as critical infrastructure and called for increased international collaboration and potentially regional bodies for coordinated protection [S178]. Regulators have also highlighted the need for public protection policies given submarine cables’ essential role in global traffic [S179].
Capacity building is essential for developing countries and small island developing states to meaningfully participate in and benefit from the global mechanism
There was strong consensus that capacity building is not merely beneficial but essential, particularly for developing countries and small island developing states. The Bahamas stated that for small island developing states, capacity building is ‘a precondition for participation’ . Australia acknowledged that cyber threats are shared but their impacts are not experienced equally, with differences in national capacity affecting vulnerability and recovery . Zimbabwe noted that capacity constraints and uneven cyber resilience increase vulnerability and limit the ability to respond effectively . Malawi argued that for developing countries, responding to one cyber incident is already difficult, and responding to sustained campaigns is an even greater challenge . Cameroon supported the establishment of a Dedicated Voluntary Fund under the Global Mechanism as an essential instrument to support national cybersecurity institution building .
National action has limits that only cooperation can overcome; each threat identified should connect to a concrete step enabling all states, including the smallest, to prevent, detect, and respond (Kiribati)
Capacity building as precondition for SIDS participation (Bahamas)
Unequal impact of cyber threats and capacity gaps (Australia)
Multi-level approach to threat response (Guyana)
Capacity constraints in developing countries (Zimbabwe)
Strengthening national response capabilities (Malawi)
Practical cooperation to address ransomware (Philippines)
Evidence-based forward-looking dialogue in DTG1 (Chile)
Regional cooperation for resilience building (Indonesia)
Dedicated Voluntary Fund for developing countries (Cameroon)
Sustainable and equitable capacity building (Mozambique)
Action-oriented mechanism with concrete outcomes (Tuvalu)
Policy Context (Knowledge Base)
Pakistan’s statement at the signature panel on cyber resilience for sustainable development underscored the importance of bridging the global capacity gap [S168]. The Open Forum on cyberdefence and AI in developing economies further contextualises the structural disadvantage faced by developing states [S161]. The consensus nature of the global mechanism’s foundational elements was noted as giving every state a stake in its success [S181], making capacity building essential for equitable participation.
The global mechanism should be action-oriented, moving from description of threats to concrete, practical steps and outcomes
There was widespread agreement that the global mechanism must be action-oriented and produce concrete outcomes rather than merely describing threats. Kiribati stated that ‘discussion of threats must not end as descriptions of threats’ and that each threat identified should connect to a concrete step . Tonga called for the mechanism to honour its experience by ensuring every threat discussed is matched by practical cooperation . The United States stated that the mechanism ‘was established to do real work, to implement the commitments states have already made’ . Latvia argued that the DTGs should focus on specific ICT security challenges, enabling states to examine threats, share experience, and develop practical approaches . Mozambique expected the mechanism to become an implementation-oriented platform that translates agreed commitments into tangible outcomes .
The mechanism was designed to be action-oriented; discussion of threats must not end as descriptions but must connect to concrete steps for all states (Kiribati)
Tonga's message on practical cooperation to prevent, withstand, and respond to threats (Tonga)
Cyber threat information sharing should be genuinely accessible to small island states (Bahamas)
Intensifying cyber threat environment (Australia)
Building on existing consensus rather than new agreements (United States)
Action-oriented mechanism with concrete outcomes (Tuvalu)
Evidence-based forward-looking dialogue in DTG1 (Chile)
DTGs as vehicles for practical action (Latvia)
Collective preparedness through the mechanism (Mozambique)
Growing sophistication and persistence of threats (Malawi)
Multi-dimensional threat landscape (Morocco)
Growing frequency and consequences of malicious ICT activities (Cameroon)
Policy Context (Knowledge Base)
Cuba’s statement at the opening of the session emphasised the need to give due attention to cyber threats with social and political dimensions as the working group approached its final report [S159]. The comprehensive report on the 18th meeting of the Disarmament and International Security Committee noted that the global mechanism’s elements were negotiated and agreed by all states in a consensus process, underscoring the expectation of tangible outcomes [S181].
International law, including the UN Charter, applies in cyberspace and provides the foundation for responsible state behaviour
There was broad consensus that international law applies in cyberspace and provides the foundation for responsible state behaviour. The Bahamas stated that international law, including the UN Charter, is ‘the foundation of a secure and peaceful ICT environment’ and ‘the guarantee of this process, not a constraint to it’ . Australia stated that state responses, including the development and use of cyber capabilities, must be consistent with international law including the UN Charter, international human rights law, and international humanitarian law . Micronesia affirmed that international law applies in cyberspace and that respect for sovereignty and human rights obligations must guide state conduct online as they do offline . Malawi reaffirmed that as recognised in successive UN GGE and OEWG reports, international law including the UN Charter applies to the use of ICTs by states .
International law as foundation, not constraint (Bahamas)
State cyber capabilities must comply with international law (Australia)
Action-oriented mechanism with concrete outcomes (Tuvalu)
International law applies fully in cyberspace (Micronesia)
Ensuring states act responsibly in cyberspace, refrain from supporting malicious activities, and cooperate in addressing threats is essential for preserving international peace and security (Albania)
Malicious ICT activities are not isolated incidents but form part of broader strategies combining cyberattacks with kinetic strikes, disinformation, and hybrid warfare tools (Ukraine)
Growing sophistication and persistence of threats (Malawi)
Addressing ransomware requires timely information sharing, strengthened incident response capabilities, public-private partnerships, technical assistance, and sustainable capacity building (Philippines)
Collective preparedness through the mechanism (Mozambique)
Multi-level approach to threat response (Guyana)
ICT supply chain security as a cross-border priority (Iraq)
AI-enabled threats and national experience (Oman)
Policy Context (Knowledge Base)
This is a well-established norm explicitly articulated in the UN cybernorms framework: ‘States should recognize that international law, including the UN Charter, is applicable and essential to maintaining peace and stability and promoting an open, secure, stable, accessible, and peaceful ICT environment’ [S166]. Albania’s statement at the OEWG similarly affirmed the UN as the guardian of international law as the foundation for global peace and security [S169]. Authoritative commentary confirms that existing international law sets the overall legal framework for state use of ICT [S167].
The blurring of lines between state and non-state actors, including the use of proxies, is a growing and concerning trend in the cyber threat landscape
Multiple states agreed that the blurring of boundaries between state and non-state actors represents one of the most problematic trends in the current threat landscape. The Netherlands described this as a ‘worrying trend of state actors hiding behind state proxies to maintain plausible deniability’ . France noted that ‘the boundaries between state-sponsored acts and cyber criminals are blurring, and the use of proxies by nation-states is spreading’ . Germany noted with concern the virulence of politically motivated hacktivist activities . Latvia noted that state-linked cyber operations pose significant risks, with incidents targeting electoral systems and critical infrastructure . Israel highlighted the clandestine direction, control, or support of non-state actors as a core threat .
State-proxy blurring and plausible deniability (Netherlands)
Attribution of Russian FSB cyber attacks against France (France)
Russian state-sponsored attacks on EU and Ukraine (Germany)
Persistent and pervasive cyber threats (Latvia)
Israeli actions conducted within international law (Israel)
State-sponsored attacks combined with disinformation (Albania)
Russian cyber aggression as part of hybrid warfare (Ukraine)
Growing threats to critical infrastructure (Canada)
Policy Context (Knowledge Base)
The UK’s statement at the OEWG described ‘an expanding and evolving threat landscape and an emerging contest between those who use technology to improve our lives’ [S162], implicitly referencing the complexity of actor attribution. The rise of false flag operations and misattributed cyberattacks was also flagged as a concern in the agenda item 5 discussions, with the absence of a universal investigative framework noted as potentially leading to flawed political decisions [S158].
Disinformation and information manipulation, increasingly combined with cyber operations, represent a growing and serious threat
Multiple states agreed that disinformation and information manipulation, particularly when combined with cyber operations, represent a serious and growing threat. Albania described a ‘particularly concerning trend’ of combining cyber operations with information manipulation activities, noting that following cyber incidents, attempts were made to spread disinformation via Telegram to amplify psychological impact and erode trust in public institutions . Zimbabwe expressed concern about the spread of disinformation and misinformation through digital platforms . Ukraine highlighted hybrid campaigns combining cyber operations, disinformation, and economic coercion . Mauritius noted the growing risks posed by the malicious use of AI to generate deepfakes, clone voices, and spread disinformation . Micronesia called for precise, time-bound, and rights-based definitions of disinformation .
Disinformation and cognitive operations as ICT threats (Islamic Republic of Iran)
Combination of cyber operations and disinformation (Albania)
Disinformation and AI-enabled deception (Zimbabwe)
Hybrid campaigns as a systemic threat (Ukraine)
AI-generated disinformation undermining public trust (Mauritius)
Rights-respecting definitions of disinformation (Micronesia)
AI enabling malicious actors at scale (Australia)
The use of ICTs for purposes contradicting the UN Charter (Russian Federation)
Policy Context (Knowledge Base)
The dedicated stakeholder session noted that ‘growing threats posed by misinformation and disinformation campaigns in cyberspace were noted by several delegations’ [S174]. The agenda item 5 discussions specifically flagged ‘ICT in Disinformation Campaigns and Cognitive Operations’ as a distinct threat category [S158]. Disinformation in the political landscape is widely recognised as a serious threat to democratic processes [S176], and the malicious use of AI and deepfakes is identified as further deteriorating the informational ecosystem [S175].
Islamic Republic of IranAlbaniaZimbabweUkraineMauritiusMicronesiaAustraliaRussia
Similar Viewpoints
Pacific Island Forum members consistently emphasised the existential nature of cyber threats to small island developing states, particularly the vulnerability of submarine cable infrastructure. Kiribati stated that damage to or disruption of its submarine cable ‘will not degrade our services, it will sever them’ . Tonga described how the 2022 volcanic eruption severed its single submarine cable, leaving the kingdom silent for weeks , and argued that a malicious actor could deliberately replicate this . Australia noted that for many countries in the region, the resilience of undersea cable infrastructure is fundamental to economic and social connectivity . Tuvalu called for clear protocols for protecting subsea infrastructure like the Aotevaca Cable . All Pacific Island Forum members aligned with Tonga’s statement on behalf of the group .
European states, particularly those aligned with the EU and NATO, shared a consistent viewpoint attributing malicious cyber activities to Russian state actors. France announced that it had been the target for more than ten years of persistent cyber attacks carried out by Russia’s FSB . Germany, together with the EU and North Atlantic Council, exposed and condemned malicious cyber activities conducted by Russian state actors targeting government entities and critical infrastructure in several EU member states and Ukraine . Poland reported that since at least 2010, Russia’s security services have undertaken actions to gain unauthorised access to sensitive networks . Ukraine stated that for over a decade, cyberspace has been one of the principal theatres of Russia’s ongoing war of aggression against Ukraine . All these states aligned with the EU statement and condemned Russian malicious cyber activities.
Developing countries and small island developing states consistently emphasised that capacity constraints make them disproportionately vulnerable to cyber threats and that capacity building must be a central feature of the global mechanism. The Bahamas stated that capacity building is ‘a precondition for participation’ for small island developing states . Zimbabwe noted that capacity constraints and uneven cyber resilience increase vulnerability and limit the ability to respond effectively . Malawi argued that for developing countries, responding to one cyber incident is already difficult, and responding to sustained campaigns is an even greater challenge . Cameroon supported the establishment of a Dedicated Voluntary Fund as an essential instrument to support national cybersecurity institution building . Mozambique called for capacity building that is predictable, sustainable, demand-driven, and accompanied by technology transfer .
Western European states shared a nuanced view of AI as both a threat amplifier and a potential defensive tool, while also highlighting the risk of a new digital divide. The Netherlands noted that generative AI amplifies existing cyber threats by lowering barriers for sophisticated operations, while also noting these tools can and should be harnessed defensively . France highlighted that the rapid increase in frontier AI model capabilities carries the risk of a new digital divide between those who have access to these models and those who do not . Greece noted that AI capabilities are expected to soon become widely available, significantly lowering the entry barrier for sophisticated attacks . Germany observed that AI facilitates large-scale attacks and creates an increasing strain on defenders’ resources, putting particular strain on less resourced and small countries .
Several states from different regional groups agreed that discussions within the global mechanism and its dedicated thematic groups should be informed by expert knowledge and practical experience, rather than remaining at a purely diplomatic level. Egypt argued that discussions should be dynamic, based on real case scenarios, and supported by a consensus-agreed pool of relevant experts . Japan placed great importance on holding expert briefings and interactive public-private discussions in the substantive plenary sessions and DTGs . Chile argued that a substantive discussion on emerging threats requires incorporating evidence and information that very often lies outside of government . Israel called for the mechanism to allow sufficient time and opportunities for relevant technological experts to provide professional presentations .
Iran, Russia, and China shared a broadly similar viewpoint emphasising digital sovereignty, the dangers of Western states using ICTs for offensive purposes, and the need for multilateral governance rather than small-circle approaches. Iran argued that states which advocate respect for international law should apply those principles consistently and condemn malicious cyber activities directed against Iran . Russia argued that the greatest danger lies in the use of ICTs for purposes that contradict the UN Charter, including undermining sovereignty and interfering in internal affairs . China called for states to respect each other’s digital sovereignty and uphold multilateralism, arguing that small circle governance cannot solve the big challenges facing the world . All three states expressed concern about the militarisation of ICTs by Western powers.
Tonga, Australia, and New Zealand shared a particularly close viewpoint, having cooperated directly on the attribution of the ransomware attack on Tonga’s Ministry of Health. Tonga stated that together with Australia and New Zealand, it jointly attributed the attack on its Ministry of Health to an affiliate of a known ransomware group, demonstrating that even the smallest states acting with partners can pursue accountability . Australia aligned with the Pacific Islands Forum statement and highlighted the importance of undersea cable resilience for the region . New Zealand noted that others in the Pacific have also been affected by ransomware affecting the healthcare sector . This practical cooperation between a major power and a small island state was highlighted as a model for the mechanism.
Unexpected Consensus
Despite deep geopolitical divisions evident throughout the discussion, states from opposing blocs converged on the view that the mechanism should produce practical, concrete outcomes. The United States stated that the mechanism ‘was established to do real work, to implement the commitments states have already made’ . Iran supported the preparation of a consolidated compilation of threats as the basis for practical cooperative measures . Russia proposed discussing specific concrete threats within the framework of the global mechanism . China stated that the mechanism ‘is not an option, it is our responsibility’ . Kiribati called for discussion of threats to connect to concrete steps . While the motivations and preferred approaches differed significantly, the surface-level agreement on the need for practical action was notable given the otherwise sharp divisions in the room.
Unusually, states from very different geopolitical positions and levels of development converged on the view that AI now poses real and immediate, rather than merely theoretical, threats to cybersecurity. China stated that ‘in the past, the risk posed by AI was merely theoretical, but now we see firsthand the real threats AI poses’ . The Republic of Korea noted that the rapid advancement of frontier AI models has further transformed the cyber threat landscape beyond what was recognised in the OEWG final report . Canada noted that frontier AI models have displayed unprecedented capabilities in autonomous vulnerability discovery and multi-stage orchestration of malicious cyber activity . Malawi noted that AI is lowering the barriers for malicious actors to conduct phishing, malware development, fraud, and disinformation at unprecedented speeds and scale . This consensus across the Global North-South divide on the immediacy of AI threats was notable.
It was perhaps expected that small island developing states would emphasise submarine cable vulnerability, but the convergence of major powers on this issue was notable. Kiribati described submarine cable protection as existential . Tonga drew on its direct experience of the 2022 volcanic eruption to illustrate the catastrophic consequences of connectivity loss . Australia explicitly called for undersea cable resilience to be an early focus for the mechanism . The Netherlands highlighted the troubling shift towards targeting means of communication . Ghana noted that damage to Submarine Cable 7 Ghana in 2024 reinforced the importance of protecting such infrastructure . This convergence between small island states and major powers on a specific infrastructure protection priority was unexpected and potentially significant for the mechanism’s work programme.
Despite sharp disagreements about who is responsible for such activities, states from opposing geopolitical blocs agreed that the combination of cyber operations with disinformation and influence activities represents a distinct and growing threat. Albania described the combination of cyber operations with information manipulation activities as a ‘particularly concerning trend’ . Ukraine highlighted hybrid campaigns combining cyber operations, disinformation, and economic coercion . Iran described cyber espionage and information operations including the manipulation of digital platforms to incite violence and spread hatred . Zimbabwe expressed concern about the spread of disinformation through digital platforms . Mauritius highlighted the growing risks posed by AI-generated deepfakes and disinformation . While these states disagreed sharply about attribution, they converged on the characterisation of hybrid cyber-disinformation campaigns as a serious threat.
Overall Assessment
The discussion revealed a high degree of consensus on the nature and severity of cyber threats, particularly ransomware, AI-enabled threats, critical infrastructure vulnerabilities, and the growing combination of cyber operations with disinformation. There was also strong agreement on the need for the global mechanism to be action-oriented, produce practical outcomes, and prioritise capacity building for developing countries. However, deep divisions remained on questions of attribution, with Western states attributing malicious activities to Russia and, to a lesser extent, other state actors, while Russia, China, and Iran contested these attributions and offered alternative framings of the threat landscape. The Pacific Island Forum states presented a particularly coherent and compelling bloc, emphasising the existential nature of cyber threats for small island developing states and the critical importance of submarine cable infrastructure. The discussion also revealed an emerging consensus on the immediacy of AI threats to cybersecurity, with states from across the geopolitical spectrum acknowledging that AI has moved from a theoretical to a real and present danger.
Points of Difference
Whether the global mechanism should pursue new legally binding agreements or focus solely on implementing existing consensus norms
The United States explicitly stated that the mechanism should be ‘grounded in practical implementation of the 11 consensus norms not a vehicle for new legally binding agreements’ , arguing that as long as some members are conducting malicious cyber actions, a legally binding agreement is impossible . The Bahamas, by contrast, stated that ‘voluntary norms and confidence-building measures operate in service of a binding legal obligation, not in place of it’ , implying a stronger role for binding law. China called for ‘establishing global standards and system for testing and assessing the risk of large AI models’ and for states to ‘formulate new international rules’ , suggesting openness to new normative frameworks. The Russian Federation emphasised that the greatest danger lies in ICT use contradicting the UN Charter , implying a need for stronger legal frameworks, while Iran argued that states advocating respect for international law should apply those principles consistently , suggesting existing law is sufficient but unevenly applied.
Building on existing consensus rather than new agreements (United States)
International law as foundation, not constraint (Bahamas)
Consistent application of responsible state behaviour norms (Islamic Republic of Iran)
Multilateralism and digital sovereignty in cyber governance (China)
ICT misuse against UN Charter principles (Russian Federation)
Policy Context (Knowledge Base)
This tension is longstanding in UN cybersecurity processes. The existing framework of norms, rules and principles of responsible state behaviour in cyberspace, grounded in customary international law, is well-established [S167][S166], and the OEWG’s progressive annual progress reports have built on this foundation [S159]. The consensus-based nature of the global mechanism’s elements [S181] suggests a preference among many states for implementation over new treaty-making, though this remains contested.
United StatesBahamasIslamic Republic of IranChinaRussian Federation
Attribution of state-sponsored cyber attacks and the evidentiary standard required
The Russian Federation strongly rejected accusations of malicious cyber activity, arguing that ‘accusations of organizing and implementing wrongful acts brought against states should be substantiated’ and that ‘no evidence has been provided neither in public nor bilaterally, nor have the existing channels for identifying the true sources of malicious activity been used’ . Russia concluded that ‘either no evidence exists or the incidents never happened at all’ . In direct contrast, France stated that it had been the target of persistent cyber attacks by Russia’s FSB for over ten years and that ‘this attribution process was conducted in accordance with the norms for responsible state behaviour and following having exhausted appropriate channels’ . Germany stated it had ‘communicated the unacceptability of these activities via the appropriate direct bilateral channels’ . Ukraine described Russian malicious ICT activities as ‘not isolated incidents, but form part of the broader strategy that combines cyberattacks with kinetic strikes, disinformation campaigns, and other hybrid warfare tools’ . Poland reported a ‘sustained pattern of malicious cyber activity by Russian actors’ since at least 2010 . The United States committed to ‘specifically identify the states and non-state actors who are perpetuating malicious cyber activities against others in this room’ .
Accusations against states should be substantiated with evidence; no evidence has been provided through existing channels including the UN Points of Contact Directory – Requirement for substantiated evidence in attributions (Russian Federation)
Attribution of Russian FSB cyber attacks against France (France)
Russian state-sponsored attacks on EU and Ukraine (Germany)
Russian cyber aggression as part of hybrid warfare (Ukraine)
Condemnation of malicious cyber activities by member states (United States)
State-sponsored attacks combined with disinformation (Albania)
Russian malicious cyber activities against Poland (Poland)
Policy Context (Knowledge Base)
The rise of false flag operations and fabricated attributions was explicitly identified as a concern in the agenda item 5 discussions, with the absence of a universal investigative framework noted as a key gap that could lead to flawed political decisions impacting international peace [S158]. This reflects a persistent structural disagreement in UN cybersecurity forums about who can attribute, on what evidence, and with what consequences.
Responsibility for cyber attacks between Iran and Israel/United States
Iran alleged that ‘the United States and the Israeli regime have carried out unlawful military attacks against the Islamic Republic of Iran’ accompanied by ‘extensive malicious cyber operations directed against Iran’s critical infrastructure and civilian services’ , claiming ‘more than 100 cyber attacks were launched every day against Iran’s critical and civilian infrastructure’ during February 2026 . Israel directly rejected these claims, asserting that ‘Israeli actions during operations Rising Lion and Roaring Lion were conducted in accordance with international law, including the UN Charter and the laws of armed conflict’ , and accused Iran of ‘waging against Israel, together with its non-state terrorist armed groups, proxies, while bluntly violating international law’ . The United States added a ‘postscript’ to the Iranian statement, stating that ‘President Trump is not going to stand idly by while the oppressive Iranian regime seeks to destroy regional stability’ , and Iran’s right of reply characterised both the US and Israeli statements as ‘a desperate attempt to distort facts through disinformation and misleading narratives’ .
US and Israeli cyber attacks against Iran (Islamic Republic of Iran)
Israeli actions conducted within international law (Israel)
Condemnation of malicious cyber activities by member states (United States)
Islamic Republic of IranIsraelUnited States
The role of the private sector and commercial technology companies in the cyber threat landscape
The Russian Federation characterised major ICT developers as threats in themselves, arguing they ‘make no secret of how deeply they are embedded in the military-industrial complexes of the countries where they are registered’ and ‘often act as contractors for intelligence agencies and military departments’ , framing private sector involvement as a source of instability. Japan, by contrast, argued that ‘it is essential to draw on the expertise of a wide range of stakeholders, including the private sector’ and placed ‘great importance on holding expert briefings and interactive public-private discussions’ . Chile similarly called for ‘the participation of experts, regional organisations, the scientific community, the private sector, as well as other interested parties’ . France and Greece focused on the proliferation of commercial cyber intrusion tools as a concern requiring oversight, with France warning that ‘without minimal oversight and accountability measures, the number of actors, including non-state actors, capable of acquiring advanced capabilities will continue to grow’ , and Greece welcoming the Pall Mall process to build consensus on responsible use .
Monetisation of the private sector (Russian Federation)
Common understanding through multi-stakeholder engagement (Japan)
Evidence-based forward-looking dialogue in DTG1 (Chile)
Commercial cyber tools undermining human rights (Greece)
Uncontrolled proliferation of commercial cyber tools (France)
Policy Context (Knowledge Base)
The dedicated stakeholder session acknowledged that ‘stakeholders have a significant role in addressing contemporary issues’ in cyberspace [S174], reflecting the multi-stakeholder dimension of this debate. The characterisation of private sector actors as either partners or threats varies significantly across state groupings, a tension visible in broader UN ICT governance discussions.
Russian FederationJapanChileGreeceFrance
Whether the mechanism should address disinformation and cognitive operations as ICT threats
Iran identified ‘disinformation and cognitive operations’ and ‘the manipulation of digital platforms including Instagram, X, and Telegram to incite violence, spread hatred, deepen social divisions’ as significant threats , and listed ‘the use of ICTs for disinformation and cognitive operations’ among threats previously identified by Iran that should be prioritised . Russia similarly highlighted the use of ICTs to ‘undermine the sovereignty of states’ and ‘interfere in their internal affairs’ . Albania and Zimbabwe supported treating disinformation as a security concern, with Albania noting that cyber incidents were combined with ‘attempts to spread disinformation and manipulate public perception through social media’ . However, Micronesia offered a cautionary counterpoint, warning that ‘vague approaches can suppress dissent and independent media, erode human rights, politicise enforcement, weaken trust in institutions, and disproportionately harm marginalised and remote communities’ , and urging states to ‘adopt precise time-bound and rights-based definitions of disinformation’ .
Disinformation and cognitive operations as ICT threats (Islamic Republic of Iran)
ICT misuse against UN Charter principles (Russian Federation)
Rights-respecting definitions of disinformation (Micronesia)
Combination of cyber operations and disinformation (Albania)
Disinformation and AI-enabled deception (Zimbabwe)
Policy Context (Knowledge Base)
The agenda item 5 discussions flagged ‘ICT in Disinformation Campaigns and Cognitive Operations’ as a distinct and contested threat category [S158]. Cuba’s opening statement emphasised the need to address cyber threats with social and political dimensions [S159], while other states have resisted expanding the mechanism’s mandate to cover information content. The appropriate scope of disinformation within ICT security frameworks remains a live debate across multiple UN forums [S174][S176].
Islamic Republic of IranRussian FederationMicronesiaAlbaniaZimbabwe
How the mechanism should handle the use of offensive cyber capabilities by states
The Russian Federation argued that ‘a number of states are openly declaring and enshrining in their doctrinal documents a shift from purely defensive operations in the information space to offensive ones’ and characterised this as ‘a threat to global security’ . China similarly stated that ‘a certain country seeks so-called unrivaled supremacy, aggressively develops offensive cyber military capabilities’ and ‘openly declares that cyber capability is used to destroy other countries’ critical infrastructure, completely break the taboo on cyber warfare’ . The United States, by contrast, stated it would ‘specifically identify the states and non-state actors who are perpetuating malicious cyber activities against others in this room’ and that ‘President Trump has been clear. If a country is utilizing the cyber domain to hurt others, in this chamber, the United States will make them pay a heavy price’ , implying a willingness to use offensive capabilities as deterrence. Australia took a more measured position, stating that ‘state responses, including the development and use of cyber capabilities, must be consistent with international law, including the UN Charter in its entirety, international human rights law and international humanitarian law’ .
The use of ICTs for offensive purposes (Russian Federation)
Condemnation of malicious cyber activities by member states (United States)
State cyber capabilities must comply with international law (Australia)
Multilateralism and digital sovereignty in cyber governance (China)
Russian FederationUnited StatesAustraliaChina
Whether low-orbit satellite communication systems represent a security threat requiring regulation
The Russian Federation argued that ‘low-orbit satellite communication systems created under the pretext of providing reliable Internet connectivity for civilian purposes’ are ‘in fact used for military-political objectives in the interests of certain countries’ , citing cases where such systems were used ‘to interfere in the internal affairs of states by inciting protests, as well as their use in armed conflicts’ . Russia called for operators to ‘act in strict accordance with the national legislation of the countries in which they provide their services’ . Iran similarly described ‘the misuse of Starlink satellite communication services to facilitate hostile operations’ as part of attacks against Iran . These positions were not directly addressed or contested by Western states in the transcript, though the United States’ broader framing of the mechanism as focused on implementing existing norms rather than creating new regulatory frameworks implicitly conflicts with calls for new satellite regulation.
Militarisation of low-orbit satellite systems (Russian Federation)
Supply chain exploitation as a cyber threat (Islamic Republic of Iran)
Russian FederationIslamic Republic of Iran
Unexpected Differences
It was unexpected that Micronesia, a small Pacific Island state generally aligned with Western positions on cybersecurity, offered a cautionary note on disinformation that implicitly challenged the positions of both Western states (who raised disinformation as a Russian threat) and non-Western states (who raised it as a tool of interference). Micronesia warned that ‘vague approaches can suppress dissent and independent media, erode human rights, politicise enforcement, weaken trust in institutions, and disproportionately harm marginalised and remote communities, while also impairing crisis response’ , and called for ‘precise time-bound and rights-based definitions of disinformation’ . This created an unexpected three-way tension: Iran and Russia framing disinformation as a tool used against them , Albania and Zimbabwe treating it as a security threat to be addressed , and Micronesia warning that addressing it without rights-based definitions could itself become a threat to human rights .
It was unexpected that the very first substantive session of the new permanent global mechanism became a venue for sharp bilateral political exchanges, with Iran making extensive allegations against the US and Israel , Israel responding with a right of reply , the United States making pointed remarks about Iran and about unnamed states conducting malicious activities , and Russia accusing Western states of ‘outrageous anti-Russian remarks’ and ‘blatant disinformation’ . The Russian Federation even called upon the Chair ‘to prevent the discussions within the global mechanism from turning into a political crisis’ , while itself making politically charged statements. The Chair had to intervene to clarify that rights of reply should be made at the end of the meeting , indicating that the level of political confrontation was not anticipated in the procedural design of the session.
New Zealand’s explicit call for the mechanism to avoid duplicating other UN processes on AI was unexpected given the broad consensus among other states that AI threats should be deeply discussed within this mechanism. New Zealand stated that ‘there are a variety of other UN processes that are actively grappling with questions related to artificial intelligence including governance issues’ and that ‘the global mechanism does not duplicate those processes’ . This contrasted with China’s call for ‘establishing global standards and system for testing and assessing the risk of large AI models’ within this mechanism , the Republic of Korea’s call for the mechanism to ‘deepen discussions on AI-enabled cyber threats’ , and France’s detailed discussion of how the mechanism ‘must address these two aspects and delve deeper into how the framework for responsible behaviour applies to these issues’ . The disagreement over the appropriate scope of AI discussions within this specific mechanism versus other UN bodies was not widely anticipated.
The Russian Federation’s characterisation of major ICT developers as embedded in ‘military-industrial complexes’ and acting as ‘contractors for intelligence agencies and military departments’ , Iran’s specific naming of Cisco, HP, and Starlink as tools used in attacks against Iran , and China’s reference to ‘a certain country’ that ‘draws an ideological line and coerces others into taking sides under the guise of cyber security’ represented an unexpected framing of Western technology companies as threats rather than partners. This directly contradicted the positions of Japan, Chile, and others who called for greater private sector involvement in the mechanism’s work . The depth of this disagreement about the role of private technology companies was more pronounced than might have been anticipated in a forum ostensibly focused on state behaviour.
Overall Assessment
The discussion revealed deep and multifaceted disagreements across several dimensions. The most fundamental disagreement concerned the attribution of state-sponsored cyber attacks, with Western states (France, Germany, UK allies, Ukraine, Poland, Albania) making specific attributions against Russia , while Russia categorically rejected these as ‘false and fabricated accusations’ without evidence . A parallel dispute between Iran and Israel/United States dominated a significant portion of the session . Beyond these bilateral disputes, there were structural disagreements about the mechanism’s purpose: the United States insisted on implementation of existing norms rather than new agreements , while China and others called for new international rules . There was also disagreement about the scope of threats to be addressed, with some states seeking to include disinformation, cognitive operations, and satellite systems , while others focused on more traditional cybersecurity threats. The role of the private sector was contested, with Russia and China viewing Western tech companies with suspicion , while Japan, Chile, and others sought to incorporate them as partners . Procedurally, the session was marked by unexpected political confrontations that the Chair had to manage , with Russia explicitly calling for the Chair to prevent the mechanism from ‘turning into a political crisis’ .
All Pacific Island Forum members and Australia agreed that submarine cable infrastructure is critically important and requires protection, with Tonga describing how the 2022 volcanic eruption demonstrated the catastrophic consequences of connectivity loss and Kiribati stating that 'damage to or disruption of our submarine cable whether by malicious cyber activity or otherwise will not degrade our services it will sever them' . Australia stated that 'the resilience of undersea cable infrastructure is fundamental to economic and social connectivity' , and Ghana highlighted the damage to Submarine Cable 7 Ghana in 2024 . However, they differed on emphasis: Pacific Island states framed this as an existential threat requiring immediate practical cooperation , while Australia focused on it as an 'early focus' for the mechanism through DTG1 , and Tuvalu called for 'clear protocols for protecting subsea infrastructure' . The disagreement lies in the urgency and the specific mechanisms needed to address this shared concern.
Submarine cable as existential infrastructure (Kiribati) Submarine cable sabotage as a grave threat (Tonga) Undersea cable resilience as a priority (Australia) Ransomware and AI threats (New Zealand) Action-oriented mechanism with concrete outcomes (Tuvalu) Protecting submarine cables as strategic assets (Ghana) Growing threats to critical infrastructure (Canada)
There was broad agreement that AI is transforming the cyber threat landscape and lowering barriers for malicious actors. The Netherlands stated that 'large language models and other AI systems can lower the barrier for conducting sophisticated operations' , Germany noted that 'the advent of advanced cyber capabilities facilitates large-scale attacks including language-agnostic credible phishing' , and Latvia stated that 'AI-enabled tools can automate reconnaissance, accelerate and scale vulnerability discovery, and generate highly convincing phishing campaigns' . China agreed that 'a new generation of large models issued by certain AI companies have demonstrated powerful cyber capabilities, both offensive and defensive' . However, speakers disagreed on governance responses: New Zealand argued the mechanism should avoid duplicating other UN processes and focus only on 'building shared understanding of the implications of AI for cybersecurity' , while China called for 'establishing global standards and system for testing and assessing the risk of large AI models' , and France highlighted the risk of a 'new digital divide' between those with and without access to frontier AI models .
Agreed
NetherlandsFranceGermanyLatviaAustraliaNew ZealandJapanRepublic of KoreaChinaMalawi
Contested
Generative AI as a threat amplifier (Netherlands) AI acceleration of offensive operations and digital divide (France) AI lowering barriers for malicious actors (Germany) AI-enabled tools supercharging malicious cyber activities (Latvia) AI enabling malicious actors at scale (Australia) Ransomware and AI threats (New Zealand) Common understanding through multi-stakeholder engagement (Japan) Frontier AI transforming the threat landscape (Republic of Korea) New generation large AI models posing real and immediate threats (China) AI enabling malicious activities at unprecedented scale (Malawi)
All speakers agreed that capacity building is essential and that developing countries face disproportionate challenges. The Bahamas stated that 'for small island developing states, capacity building is a precondition for participation' , Zimbabwe noted that 'capacity constraints and uneven cyber resilience increase our vulnerability and limit our ability to effectively respond to cyber incidents' , and Australia acknowledged that 'cyber threats are shared, but their impacts are not experienced equally' . However, they differed on mechanisms: Cameroon specifically called for 'the establishment of the Dedicated Voluntary Fund under the Global Mechanism' , while Mozambique emphasised that capacity building must be 'accompanied by technology transfer, institutional strengthening, and equitable access to knowledge and expertise' . The Bahamas focused on ensuring information sharing is 'genuinely accessible to small island states' , while Malawi emphasised strengthening national CERTs and early warning mechanisms .
Capacity building as precondition for SIDS participation (Bahamas) Cooperation as essential complement to national action (Kiribati) Small state attribution and accountability (Tonga) Capacity constraints in developing countries (Zimbabwe) Strengthening national response capabilities (Malawi) Dedicated Voluntary Fund for developing countries (Cameroon) Sustainable and equitable capacity building (Mozambique) Regional cooperation for resilience building (Indonesia) Unequal impact of cyber threats and capacity gaps (Australia)
Multiple speakers agreed that the dedicated thematic groups should be action-oriented and informed by expert knowledge, but differed on how to achieve this. Egypt argued for 'a pool of experts that will help us in those discussions' accepted by delegations through consensus . Japan placed 'great importance on holding expert briefings and interactive public-private discussions in the substantive plenary sessions and DTGs' . Chile called for 'the participation of experts, regional organisations, the scientific community, the private sector, as well as other interested parties' . Latvia stated that DTGs should 'focus on specific ICT security challenges, enabling states to examine threats, share experience, and develop practical approaches' . The key difference is Egypt's emphasis on a pre-agreed, consensus-based pool of experts , which could be seen as more restrictive than the broader multi-stakeholder approach advocated by Japan and Chile.
Agreed
EgyptJapanChileKiribatiLatvia
Contested
Dynamic expert-based discussions in thematic groups (Egypt) Expert briefings within the mechanism (Japan) Evidence-based forward-looking dialogue in DTG1 (Chile) Action-oriented mechanism with concrete outcomes (Kiribati) DTGs as vehicles for practical action (Latvia)
The United States expressed solidarity with Pacific Island states, stating 'To Tonga and Kiribati, the United States hears you, and we thank you for your strong statements. While others in this chamber are planning and targeting you, The United States will be there to help protect you' . Tonga and Kiribati welcomed practical cooperation, with Tonga noting that 'with the support of partners, our health systems were restored and services maintained' and that joint attribution with Australia and New Zealand demonstrated 'that even the smallest states acting with partners can pursue accountability' . However, the Pacific Island states focused on practical cooperation and concrete outcomes , while the United States framed its engagement more in terms of accountability and deterrence, warning that 'if a country is utilizing the cyber domain to hurt others, in this chamber, the United States will make them pay a heavy price' , a more confrontational framing than the cooperative approach emphasised by Pacific states.
Agreed
United StatesKiribatiTongaAustraliaNew Zealand
Contested
Condemnation of malicious cyber activities by member states (United States) Action-oriented mechanism with concrete outcomes (Kiribati) Small state attribution and accountability (Tonga) Intensifying cyber threat environment (Australia) Ransomware and AI threats (New Zealand)
Key Takeaways
The Global Mechanism on Developments in the Field of Information and Communication Technologies and Advanced Responsible State Behaviour held its first substantive plenary session, marking a historic transition from the Open-Ended Working Group (OEWG) to a permanent mechanism.
The cyber threat landscape is universally acknowledged as intensifying in scale, sophistication, and transnational reach, affecting critical infrastructure, essential services, governments, businesses, and individuals across all regions.
Ransomware was identified by numerous delegations as one of the most pervasive and destructive cyber threats, with real-world impacts on healthcare, energy, financial services, and public administration, including specific incidents in Tonga, Latvia, and Germany.
Artificial intelligence was consistently highlighted as a dual-use technology that is both amplifying offensive cyber capabilities (lowering barriers for malicious actors, enabling sophisticated phishing, autonomous vulnerability discovery) and offering significant defensive opportunities.
Small island developing states (SIDS), including Kiribati, Tonga, Tuvalu, Bahamas, and Micronesia, emphasised that their limited redundancy, dispersed populations, and reliance on submarine cable infrastructure make them disproportionately vulnerable to cyber threats, with disruptions being existential rather than merely disruptive.
The protection of critical infrastructure, particularly submarine cables and undersea communications infrastructure, was identified as a shared international responsibility and a priority for the mechanism’s first Dedicated Thematic Group (DTG1).
There is broad consensus that the mechanism must be action-oriented, moving beyond the identification and description of threats towards concrete, practical steps that enable all states to prevent, detect, and respond to malicious ICT activities.
The blurring of boundaries between state-sponsored actors and non-state proxies, including hacktivist groups and criminal syndicates operating from state-sanctioned safe havens, was identified as one of the most problematic and growing trends in the threat landscape.
Multiple delegations, including France, Germany, Poland, Estonia, and Ukraine, publicly attributed sustained malicious cyber activities to Russian state actors, including the FSB, targeting government entities, critical infrastructure, and democratic processes in EU member states and Ukraine.
Iran detailed extensive cyber attacks it attributed to the United States and Israel during military operations in 2026, while Israel and the United States rejected these characterisations and offered counter-narratives, reflecting deep geopolitical divisions within the mechanism.
Capacity building was consistently identified as a precondition for meaningful participation by developing countries, with calls for it to be sustainable, demand-driven, tailored to national circumstances, and accompanied by technology transfer and institutional strengthening.
International law, including the UN Charter, was reaffirmed by the vast majority of delegations as the foundation for responsible state behaviour in cyberspace, with voluntary norms and confidence-building measures seen as complementary rather than substitutes for binding legal obligations.
The Dedicated Thematic Groups (DTGs) were widely seen as the primary vehicle for translating high-level threat discussions into practical, action-oriented outcomes, with calls for expert briefings, evidence-based dialogue, and multi-stakeholder participation.
Disinformation, influence operations, and hybrid threats combining cyber operations with information manipulation were identified as an increasingly significant and complex dimension of the threat landscape.
Supply chain security, including the risks posed by backdoors, undeclared malicious capabilities, and the deliberate insertion of vulnerabilities into ICT products, was raised as a growing concern, particularly for developing countries.
The proliferation of commercial cyber intrusion capabilities without adequate oversight was identified as a significant risk multiplier, with France and the United Kingdom highlighting the Pall Mall Process as a relevant initiative.
Quantum computing was noted by several delegations, including Malaysia and Chile, as an emerging future risk requiring proactive attention, particularly regarding the security of current encryption systems.
Resolutions & Action Items
The Chair directed that delegations wishing to exercise a right of reply should make requests to the Secretariat so that speaking time can be allocated at the end of the speaker list, establishing a procedural norm for the mechanism.
The Chair requested that delegations deliver abridged statements and submit full versions to eStatements and the Chair’s team, in order to accommodate all speakers within the available conference time.
The Chair closed the list of speakers for inscriptions under the agenda item on existing and potential threats, to manage the schedule and ensure other agenda items could be addressed.
The session was adjourned with the remaining speakers (Pakistan, Romania, Nicaragua, Armenia, African Union, ICRC, and Interpol) to continue at 3 p.m., after which the mechanism would immediately proceed to the agenda item on voluntary norms for responsible state behaviour.
Germany, the Dominican Republic, and Ghana announced a joint side event during the lunch break on best practices for the operationalisation of confidence-building measures for the protection of critical infrastructure.
Latvia, Estonia, and Australia announced a co-hosted briefing on Wednesday on Frontier AI and the Cyber Threat Landscape.
China announced the formal submission to the Secretariat of a position paper on global cyber governance in the digital intelligence age, requesting its circulation to all member states as an official document.
France and the United Kingdom announced the launch of negotiations on guidelines for the cyber intrusion industry as part of the Pall Mall Process, following the adoption of a Code of Good Practices for States in April 2025.
Multiple delegations called for the preparation of a consolidated compilation of threats already identified by member states in the first OEWG Chair Summary, to serve as the basis for discussions in the plenary and DTGs.
Several delegations, including Egypt and Japan, called for the establishment of an agreed pool of relevant experts to support discussions in the dedicated thematic groups, to be accepted by delegations through consensus.
Tonga, Kiribati, and other Pacific Island Forum members called for the mechanism to ensure that every threat discussed is matched by practical cooperation to prevent, withstand, and respond to it for all states.
Oman called for DTG1 to focus on the practical implementation of norms 13i and 13j regarding the protection of critical infrastructure and supply chains, and norm 13c regarding states not allowing their territory to be used for malicious cyber activities.
Cameroon called for the establishment of a Dedicated Voluntary Fund under the Global Mechanism to support national cybersecurity institution building, training, and participation in DTG meetings by developing countries.
Unresolved Issues
Deep geopolitical divisions remain unresolved, particularly regarding the attribution of malicious cyber activities between Iran, Israel, and the United States, with each party rejecting the other’s characterisations and no common factual basis established.
The question of whether the mechanism should pursue new legally binding agreements or focus exclusively on implementing existing consensus norms remains contested, with the United States explicitly opposing new legally binding instruments while other delegations implicitly or explicitly favour stronger legal frameworks.
The appropriate scope and methodology for expert participation in the DTGs has not been agreed upon; Egypt called for a consensus-based pool of experts, but no process for establishing this has been determined.
The extent to which the mechanism should address threats already identified in previous OEWG processes versus expanding to new threat areas (such as frontier AI, quantum computing, and low-orbit satellite systems) remains unresolved.
The question of how to address the activities of non-state actors, including criminal syndicates, hacktivist groups, and terrorist organisations, within a state-centric framework of responsible behaviour has not been resolved.
The governance of artificial intelligence in the context of cybersecurity, including whether and how the mechanism should engage with AI-specific risks without duplicating other UN processes, remains to be worked out.
The issue of how to make cyber threat information sharing genuinely accessible to small island developing states and other developing countries with limited technical capacity has not been operationally resolved.
The proliferation of commercial cyber intrusion capabilities and the appropriate international oversight mechanisms remain subjects of ongoing discussion without agreed outcomes within the mechanism.
The risks posed by low-orbit satellite communication systems, including their potential use for military-political objectives and interference in internal affairs, were raised by Russia but not addressed by other delegations.
The nexus between cyber threats and natural disasters, particularly for SIDS, was identified as a concern but no concrete cooperative framework to address it was proposed.
The question of how to ensure that capacity building is sustainable, predictable, and demand-driven rather than donor-driven remains unresolved, with developing countries expressing concern about the adequacy of existing arrangements.
The issue of how to address the digital divide created by unequal access to frontier AI models, raised by France, has not been addressed within the mechanism’s framework.
The modalities for the Dedicated Thematic Groups, including their format, frequency, expert participation, and relationship to the plenary, remain to be fully elaborated.
The question of accountability and consequences for states that violate the consensus framework of responsible state behaviour, beyond public attribution, has not been resolved.
The treatment of disinformation and influence operations within the mechanism’s mandate, including the tension between security concerns and human rights protections, remains contested, as highlighted by Micronesia’s call for rights-respecting definitions.
Suggested Compromises
Egypt suggested that discussions in dedicated thematic groups should be based on real case scenarios and supported by a consensus-based pool of experts, implying a compromise between open expert participation and state control over who contributes to discussions.
Iran suggested that the mechanism should prioritise threats already identified by member states in the first OEWG Chair Summary before expanding to new areas, which could serve as a sequencing compromise between states wishing to address established threats and those wishing to address emerging ones.
New Zealand suggested that the mechanism should focus on AI’s implications for cybersecurity specifically, rather than AI governance broadly, as a way of carving out a distinct and non-duplicative role for the mechanism alongside other UN AI processes.
France suggested that the first DTG could focus on one or two major trends in cyber threats with an impact on international peace and security, rather than attempting to address all threats simultaneously, implying a prioritisation compromise.
Multiple delegations, including Australia and Chile, implicitly suggested that the DTGs should draw on expertise from outside government, including the private sector, academia, and civil society, as a compromise between state-centric discussions and broader multi-stakeholder engagement.
Oman suggested that discussions should not focus solely on threats but also on practices and tools to assess whether states are abiding by agreed norms, implying a compromise between descriptive threat analysis and normative accountability.
The Chair’s procedural suggestion that delegations deliver abridged statements and submit full versions to eStatements represents a practical compromise between the desire of all delegations to speak at length and the constraints of available conference time.
Several delegations, including the Philippines and Malaysia, suggested that discussions should promote practical exchanges on national implementation while respecting differing legal systems, levels of technological maturity, and national circumstances, implying a compromise between universal standards and national flexibility.
“Tonga’s delegation drew a direct parallel between the 2022 Hunga Tonga-Hunga Ha’apai volcanic eruption severing their submarine cable and the potential for deliberate malicious acts: ‘We learned everything a volcano did to Tonga by accident, a malicious act could choose to do deliberately.’ They also noted their joint attribution of a ransomware attack on their Ministry of Health with Australia and New Zealand, demonstrating that ‘even the smallest states acting with partners can pursue accountability for malicious cyber activities.’”
“Kiribati stated: ‘Discussion of threats must not end as descriptions of threats. Each threat identified in this room should connect to a concrete step… that leaves every state, including the smallest, able to prevent, detect, and respond. If this mechanism can do that from its very first session, it would have proven its worth not only to the states in this room but to every community that depends on it.’”
“Egypt proposed that discussions in dedicated thematic groups should be ‘dynamic, based on real case scenarios’ and, crucially, that they must be supported by ‘a proper and accepted pool of experts by delegations,’ adding: ‘Having discussions on threats without a professional, experienced, and relevant pool of experts is, again, a waste of time.’ Egypt was careful to note this was not about blocking experts but about achieving consensus on relevance.”
“The Islamic Republic of Iran delivered a detailed account of over 100 cyber attacks per day during the February 2026 aggression, cataloguing coordinated cyber and kinetic attacks, attacks on civilian institutions, exploitation of commercial technologies including Cisco and HP products, misuse of Starlink, and cognitive operations via Instagram, X, and Telegram. Iran also called for attention to threats ‘previously identified by Iran’ including ‘weaponisation of the ICT environment, monopoly in Internet governance, false flag operations and fabricated attribution, and unilateral coercive measures in the ICT domain.’”
“The United States stated: ‘As long as some members in this hall are maliciously conducting cyber actions against other members, a legally binding agreement is impossible… There are members in this chamber right now who are planning and conducting malicious cyber actions against other members’ critical infrastructure… President Trump has been clear. If a country is utilizing the cyber domain to hurt others, in this chamber, the United States will make them pay a heavy price.’”
“France identified three trends: the blurring of state and non-state actor boundaries, AI’s impact on cyber capabilities, and the ‘uncontrolled proliferation of cyber intrusion capabilities available on the market,’ which France described as ‘a veritable ticking time bomb.’ France also announced the launch of negotiations on guidelines for the cyber intrusion industry under the Pall Mall Process, building on the April 2025 Code of Good Practices for States.”
“The Russian Federation raised four specific threats: the ‘monetisation of the private sector’ (major ICT companies embedded in military-industrial complexes), the shift from defensive to offensive ICT operations by certain states, ‘undeclared malicious capabilities’ (backdoors embedded by developers for intelligence agencies), and the military use of low-orbit satellite communication systems. Russia stated: ‘Such tools are used for intelligence, espionage, interception of personal data and private correspondence. And as shown by the infamous Pager incident in Lebanon in 2024, they’re used for causing physical damage.’”
“The Bahamas highlighted three priorities that were distinct from the dominant infrastructure-focused discourse: cyber threats to youth, cyber threats to women (specifically technology-facilitated gender-based violence), and the principle that ‘participation for women is not complete unless women are at the table, in delegation, in technical decision-making, and in the design of national ICT policies.’ The Bahamas also emphasised the ‘nexus between cyber threat and natural disaster’ as a specific concern for small island states.”
“China stated: ‘In the past, the risk posed by AI was merely theoretical. But now we see firsthand the real threats AI poses. So this mechanism, including the DTG, is not an option. It is our responsibility.’ China also called for ‘establishing global standards and system for testing and assessing the risk of large AI models to ensure that AI will serve as a new shield for cybersecurity rather than a new tool for unilateral pursuit of hegemony,’ and criticised ‘small circle governance’ as unable to solve global challenges.”
“Malawi emphasised: ‘It is not only the emergence of these threats that should concern us, but their persistence. Persistent and covert malicious ICT activities can remain undetected for extended periods of time, gradually undermining public trust, disrupting essential services, weakening national resilience, and causing significant economic and societal harm. For many developing countries, just like Malawi, responding to one cyber incident is already difficult. Responding to sustained campaigns is an even greater challenge.’”
How should the dedicated thematic groups (DTGs) structure their discussions on threats to avoid simply replicating plenary discussions, and what format would make them most effective?
Egypt
Egypt raised the concern that DTG discussions risk becoming a mirror of plenary discussions, which would waste time and miss opportunities. Determining an effective, dynamic format based on real case scenarios is critical to producing tangible outcomes from the mechanism.
What criteria and process should be used to compile and agree upon a pool of experts to inform threat discussions in the dedicated thematic groups?
Egypt, Japan, Chile, Israel
Multiple delegations stressed the need for relevant, experienced experts to guide threat discussions. Without a consensus-based, professionally credible pool of experts, discussions risk being uninformed. The process for selecting and agreeing on such experts requires further elaboration.
How can the global mechanism ensure that each identified threat is matched with a concrete, actionable step for prevention, detection, and response, particularly for small island developing states?
Kiribati, Tuvalu, Tonga, Bahamas
Small island developing states emphasised that threat discussions must not end as mere descriptions. Translating identified threats into practical cooperative measures is essential for the mechanism to prove its worth, especially for the most vulnerable states.
What practical measures and international cooperation frameworks can be developed to protect submarine cable infrastructure from both malicious cyber activity and physical sabotage?
Kiribati, Tonga, Australia, Tuvalu, Ghana
Several Pacific island states and Australia highlighted that submarine cable disruption is an existential threat for some nations. Further research is needed on international legal frameworks, technical standards, and cooperative response protocols specifically for undersea cable protection.
How is artificial intelligence transforming the cyber threat landscape, and what specific implications does this have for existing cyber defence mechanisms and the framework of responsible state behaviour?
New Zealand, Netherlands, Australia, Japan, Greece, France, Germany, Latvia, Republic of Korea, Chile, Malawi, Canada, Malaysia
Numerous delegations noted that AI is rapidly changing the scale, speed, and sophistication of cyber threats while also offering defensive opportunities. A deeper, structured discussion is needed on how AI affects existing norms, what new vulnerabilities it creates, and how states can harness it defensively without duplicating other UN processes.
How should the global mechanism address the blurring of lines between state and non-state actors, including the use of proxies, hacktivist groups, and criminal syndicates by states to maintain plausible deniability?
Netherlands, France, Latvia, Israel, Albania
The convergence of state-sponsored and non-state malicious cyber activity complicates attribution and accountability. Further research is needed on how existing norms and international law apply to proxy actors and how states can be held responsible for activities they tolerate or direct.
What governance frameworks or international standards should be developed to oversee the proliferation of commercial cyber intrusion capabilities and prevent their misuse?
Greece, France, Netherlands
The uncontrolled proliferation of commercial cyber tools poses risks to privacy, human rights, and international security. The Pall Mall process was cited as a relevant initiative, but further international dialogue and research are needed to build consensus on accountability and oversight mechanisms.
How can cyber threat information sharing be made genuinely accessible to small island developing states and other developing countries with limited technical capacity?
Bahamas, Kiribati, Indonesia, Malawi, Mozambique, Iraq
Developing countries, particularly small island states, face significant barriers to accessing timely threat intelligence. Research is needed on how to design information-sharing mechanisms that are inclusive, accessible, and practically useful for states with thin technical workforces and limited resources.
What concrete capacity-building measures, tailored to the specific needs of developing countries, should be prioritised under the global mechanism to ensure meaningful participation and resilience?
Bahamas, Cameroon, Malawi, Mozambique, Indonesia, Iraq, Zimbabwe
Capacity building was identified as a precondition for participation by many developing states. Further work is needed to define what sustainable, demand-driven, and nationally owned capacity building looks like in practice, including financing mechanisms such as the proposed Dedicated Voluntary Fund.
How should the global mechanism address technology-facilitated gender-based violence, including online harassment and image-based abuse, as a distinct cyber security concern?
Bahamas
The Bahamas highlighted that cyber threats disproportionately affect women and girls through technology-facilitated gender-based violence. This area requires dedicated attention within the mechanism’s threat discussions and capacity-building efforts, yet it remains underexplored in current frameworks.
How can the global mechanism address the nexus between cyber threats and natural disasters, particularly for small island developing states vulnerable to both?
Bahamas, Tonga
The intersection of cyber threats and natural disaster scenarios (e.g., a malicious actor exploiting the same vulnerabilities exposed by a natural disaster) represents a distinct and underexplored risk. Further research is needed on how to build resilience that addresses both simultaneously.
What practical steps can states take to implement the voluntary norm that states should not knowingly allow their territory to be used for internationally wrongful acts using ICTs, and how can compliance be assessed?
Oman, Malawi, Micronesia
Several delegations reaffirmed this norm but noted the lack of practical tools to verify or encourage compliance. Research is needed on monitoring mechanisms, confidence-building measures, and diplomatic channels that can operationalise this norm effectively.
How should the global mechanism deepen discussions on ransomware, including its use as a financing mechanism for illicit activities such as arms trafficking and weapons development, and what cooperative measures can be developed?
Japan, Tonga, Philippines, Republic of Korea, Latvia, Germany, Oman
Ransomware was identified by many delegations as one of the most pervasive and destructive threats, with links to broader illicit financing. Further structured discussion is needed on practical international cooperation measures, including information sharing, attribution, and accountability for ransomware actors.
How should the global mechanism address cryptocurrency theft and its role in financing illicit activities, including the development of weapons of mass destruction?
Republic of Korea
The Republic of Korea noted that cryptocurrency theft has become a major source of illicit financing and that this issue was recognised in the OEWG final report. Further in-depth discussion is needed to develop concrete cooperative measures to address this threat under the new mechanism.
What international frameworks or norms should govern the use of low-orbit satellite communication systems to prevent their misuse for military-political objectives or interference in the internal affairs of states?
Russian Federation
The Russian Federation raised concerns about the dual-use nature of low-orbit satellite systems such as Starlink. This area requires further research on applicable international law, governance frameworks, and the responsibilities of operators under national and international law.
How should the global mechanism address the issue of undeclared malicious capabilities, including hardware and software backdoors embedded by developers at the behest of intelligence agencies?
Russian Federation, Thailand
The existence of backdoors in widely used ICT products poses significant risks to national security and supply chain integrity. Further research is needed on international standards, transparency requirements, and accountability mechanisms for ICT developers and states that mandate such capabilities.
How should the global mechanism handle the militarisation of the private ICT sector, including the integration of major technology companies into national military-industrial complexes and intelligence operations?
Russian Federation, China
Both the Russian Federation and China raised concerns about the blurring of lines between commercial ICT companies and state military or intelligence activities. This raises questions about the applicability of existing norms to private sector actors and the risks to international stability.
What mechanisms can be developed to ensure that discussions on AI-related cyber threats within the global mechanism complement rather than duplicate existing UN processes on AI governance?
New Zealand, Israel
New Zealand and Israel both cautioned against duplicating other UN processes on AI. Further clarity is needed on the specific added value of the global mechanism in addressing AI-cyber security intersections, and how it should coordinate with other relevant forums.
How can the global mechanism develop a consolidated, agreed compilation of threats identified by member states, building on the OEWG Chair Summary, to serve as a practical basis for DTG discussions?
Islamic Republic of Iran
Iran proposed that the mechanism prioritise threats already identified by member states before expanding to new areas, and called for a consolidated compilation under the Chair’s authority. This raises questions about methodology, inclusivity, and how to ensure all states’ security concerns are reflected.
How should the global mechanism address the use of ICTs for disinformation, cognitive operations, and information manipulation, including the exploitation of social media platforms, as a distinct threat to international security?
Islamic Republic of Iran, Albania, Zimbabwe, Mauritius, Micronesia
Multiple delegations raised concerns about disinformation and cognitive operations as a growing component of hybrid cyber threats. Further research is needed on how existing norms apply, what rights-respecting definitions of disinformation should look like, and what cooperative measures can be developed.
How can the global mechanism address the security implications of quantum computing, particularly regarding the vulnerability of current encryption systems, and what cooperative measures should be developed?
Chile, Malaysia
Chile and Malaysia both identified quantum computing as an emerging threat to existing cryptographic infrastructure. Further research is needed on timelines, the scope of vulnerability, and international cooperation on post-quantum cryptography migration, particularly for developing countries.
How should the global mechanism address the exploitation of digital supply chains, including cloud-connected software and ICT hardware, as a vector for malicious cyber activity?
Chile, Guyana, Thailand, Iraq, Oman
Supply chain vulnerabilities were identified as a significant and growing threat. Further research is needed on international standards, best practices, and cooperative frameworks for securing ICT supply chains, particularly given their cross-border nature and the involvement of private sector actors.
What practical guidelines should the DTGs develop for protecting critical infrastructure in developing countries, including securing industrial control systems, energy grids, and essential services?
Cameroon, Australia, Chile
Developing countries face specific challenges in protecting critical infrastructure due to limited resources. Further work is needed to translate general norms into practical, context-specific guidelines that address the needs of less-resourced states, including through public-private partnerships.
How can the global mechanism strengthen national computer emergency response teams (CERTs) and enhance cyber threat intelligence sharing, including early warning mechanisms, particularly for developing countries?
Malawi, Indonesia, Bahamas, Iraq
Many delegations highlighted the importance of CERTs and threat intelligence sharing for resilience, but noted that developing countries face significant capacity constraints. Further research is needed on how to build sustainable, interoperable CERT networks and accessible intelligence-sharing platforms.
How should the global mechanism address the growing impact of cyber threats on youth, including cyberbullying, online manipulation, and exposure to disinformation, as an emerging security concern?
Bahamas, Albania
Both the Bahamas and Albania highlighted the specific vulnerabilities of young people to cyber threats, including AI-enabled manipulation and disinformation. This area requires dedicated attention within the mechanism’s threat discussions and may warrant specific cooperative measures.
What role should non-state actors, including the private sector, academia, civil society, and technical experts, play in the DTGs and plenary discussions, and how should their participation be structured?
Japan, Chile, France, Cameroon, Israel
Multiple delegations stressed the importance of drawing on expertise beyond government, including from the private sector and technical community. Further clarity is needed on the modalities for stakeholder engagement within the global mechanism’s architecture.
How should the global mechanism address the use of ICTs by terrorist groups, including for recruitment, financing, planning, and targeting of critical infrastructure?
Iraq, Oman
Iraq and Oman raised the specific threat of terrorist exploitation of ICTs, drawing on national experience. Further research is needed on how existing counter-terrorism frameworks intersect with the cyber security norms framework and what cooperative measures can be developed.
How can the global mechanism develop practical tools to assess whether states are abiding by agreed norms, moving beyond threat identification to monitoring and accountability?
Oman
Oman stressed the need to move from discussing threats to developing practical tools for assessing norm compliance. This raises important questions about verification, transparency, and the role of confidence-building measures in holding states accountable.
What international standards and risk assessment systems should be developed for frontier AI models to prevent their use as tools for offensive cyber operations or unilateral pursuit of hegemony?
China, Canada, Latvia
China, Canada, and Latvia all raised concerns about the unprecedented offensive and defensive capabilities of frontier AI models. Further research is needed on how to establish globally agreed standards for testing and assessing the risks of large AI models within a multilateral framework.
How should the global mechanism address the illicit financing of malicious cyber operations through digital assets and cryptocurrencies, including tracking, freezing, and seizing such assets?
Israel
Israel highlighted the use of digital assets to finance cyber criminal syndicates and terrorist proxies operating from state-sanctioned safe havens. Further research is needed on international cooperation mechanisms for tracking and disrupting illicit cryptocurrency flows linked to malicious cyber activity.
How can the global mechanism ensure that its discussions on AI and emerging technologies remain forward-looking and responsive to the rapidly changing technological environment, given the pace of development since the OEWG final report?
Republic of Korea, France, Germany
The Republic of Korea and others noted that the threat landscape has evolved significantly even since the OEWG final report. The mechanism needs to develop processes for keeping its threat assessments current and technically informed, which may require regular expert briefings and structured updates.
What measures can be taken to address the growing threat of large-scale covert networks of internet-connected devices (botnets) being used to disguise the origins and attribution of cyber attacks?
Canada
Canada highlighted a joint advisory on defending against state-linked covert networks used to obscure attribution. Further research and cooperative measures are needed to address this specific threat, including technical standards, information sharing, and attribution methodologies.
How should the global mechanism address the specific cyber security challenges faced by land-locked developing countries that rely on interconnected regional telecommunications networks, given the cross-border consequences of vulnerabilities in shared digital infrastructure?
Zimbabwe
Zimbabwe highlighted the specific vulnerabilities of land-locked states dependent on regional telecommunications networks. This represents an underexplored dimension of critical infrastructure protection that requires tailored research and cooperative frameworks.
Disclaimer: This is not an official session record. DiploAI generates these resources from audiovisual recordings, and they are presented as-is, including potential errors. Due to logistical challenges, such as discrepancies in audio/video or transcripts, names may be misspelled. We strive for accuracy to the best of our ability.
This discussion took place during the second meeting of the 2026 substantive plenary session of the Global Mechanism on ICTs in the context of international security, covering both organisational matters related to the Dedicated Thematic Groups (DTGs) and substantive discussions on the evolving cyber threat landscape .
On the question of DTG organisation, several delegations welcomed the Chair’s appointment of co-facilitators , whilst others, notably China and Belarus, raised procedural concerns, arguing that the appointment deviated from the consensus-based decision-making principles established by General Assembly resolutions . Brazil, Kiribati, and New Zealand emphasised that the DTGs should focus on a limited number of priority topics, avoid duplicating plenary discussions, and produce action-oriented recommendations . Multiple delegations, including Germany, Argentina, and Oman, stressed the importance of stakeholder participation – including the private sector, academia, and civil society – to ensure practical and implementable outcomes .
Regarding the substantive threat pillar, delegations identified ransomware targeting critical infrastructure and essential services as one of the most pressing concerns , with the healthcare sector highlighted as a particularly vulnerable target . The malicious use of artificial intelligence – including AI-enabled phishing, deepfakes, disinformation campaigns, and automated vulnerability exploitation – was widely cited as a rapidly escalating threat . The growing use of state-sponsored proxy actors to conduct malicious cyber operations whilst maintaining plausible deniability was also flagged as a serious concern by the EU, Estonia, Portugal, and the United Kingdom .
Developing countries and small island states, including Kiribati, Vanuatu, and Nauru, underscored the disproportionate impact of cyber threats on states with limited capacities, particularly where digital infrastructure is fragile or newly established . The African Group called for DTG2 on capacity building to be allocated adequate time and resources, and for early operationalisation of practical tools such as the global ICT security cooperation portal and the point-of-contact directory .
Overall, the session reflected broad agreement on the urgency of transitioning from normative consensus to practical implementation, whilst procedural disagreements over DTG governance and stakeholder participation remained unresolved, with the Chair committing to continued intersessional consultations to address outstanding issues .
Keypoints
Overall Purpose
The discussion takes place during the first substantive plenary session of the UN Global Mechanism on ICTs in the context of international security. The primary goals are to organise the work of the newly established Dedicated Thematic Groups (DTGs), agree on their topics and working methods, and begin substantive exchanges on the existing and evolving cyber threat landscape facing member states.
—
Major Discussion Points
Governance and procedural legitimacy of the DTGs, particularly the appointment of co-facilitators. A significant portion of the session was consumed by disagreement over whether the Chair’s unilateral appointment of co-facilitators was consistent with the consensus-based decision-making principles established by UN General Assembly resolutions. China argued that the practice of appointing facilitators without consensus had no precedent in the history of cyber discussions at the UN and that informal meetings could not be used as a “blank check” to abandon consensus . Belarus, aligning with a joint statement delivered by Nicaragua, stated that deviating from the consensus principle was unacceptable for both states and the Chair, and acknowledged that “an entire group of states distanced itself from the procedure” . By contrast, Germany, Chile, New Zealand, and others welcomed the appointments as the Chair’s prerogative and urged the mechanism to move forward .
Structure, mandate, and working methods of the DTGs. Delegations debated how the two DTGs should operate, what topics they should prioritise, and how their outputs should feed back into the plenary. Brazil stressed that DTG2 on capacity building should be autonomous and not subordinate to DTG1 , while Argentina and Chile emphasised that the groups should be horizontal and complementary to the plenary rather than duplicating it . Kiribati and New Zealand both advocated a “less is more” approach, urging the DTGs to focus on a small number of concrete deliverables with broad support rather than attempting to cover everything at once . Germany proposed that the DTGs focus on thematically coherent topics such as critical infrastructure protection and ransomware targeting essential services, and suggested that co-facilitators provide oral updates to the plenary alongside written consensus recommendations . The Netherlands cautioned that negotiating written recommendations would place a heavy burden on smaller delegations and reduce time for substantive work .
Participation of non-state stakeholders in the DTGs. Several delegations strongly advocated for the inclusion of technical experts, civil society, academia, and the private sector in DTG discussions, arguing that their expertise is indispensable for practical implementation. Oman argued that without private sector and academic participation, the mechanism would lack access to critical threat intelligence and real-world experience . France went so far as to say that including non-state stakeholders would actually enable states to retain their central role, “otherwise they will be marginal” . Argentina called for transparent, neutral, and geographically diverse accreditation criteria, suggesting the use of existing UN institutional accreditation systems . China, however, cautioned against introducing NGO participation practices from other forums into this mechanism, arguing that the key question was what practice was appropriate specifically for this global mechanism given its 20-30 year history .
The evolving cyber threat landscape, with particular focus on ransomware, critical infrastructure, and AI-enabled threats. During the substantive agenda item on existing and potential threats, delegations from across all regions described a rapidly deteriorating threat environment. Ransomware was consistently identified as one of the most acute and pervasive threats, with Costa Rica citing its own 2022 experience , Ireland referencing its 2021 health service attack , and Singapore reporting close to 8,000 ransomware cases worldwide in 2025 . The malicious use of artificial intelligence was highlighted by numerous delegations – including Turkey, Estonia, South Africa, Brazil, and Switzerland – as fundamentally reshaping the threat landscape by lowering barriers to entry, accelerating attack timelines, and enabling large-scale disinformation and deepfakes . The protection of critical infrastructure, including undersea cables, healthcare systems, and electoral processes, was identified as a cross-cutting priority .
Capacity building as a strategic priority, particularly for developing and small island states. Multiple delegations, especially from the African Group, the Pacific Islands Forum, and small island developing states, emphasised that capacity building must be treated as a substantive and cross-cutting pillar rather than an afterthought. The African Group called for early operationalisation of the global ICT security cooperation portal, a UN Voluntary Fund for ICT Security Capacity Building, and a UN ICT Security Fellowship Programme . Saudi Arabia announced a Global Initiative for Capacity Building in Cyberspace launched at the Global Cybersecurity Forum, which had already benefited cybersecurity experts from more than 80 states . Nauru and Vanuatu illustrated the acute vulnerability of newly connected small states, with Nauru noting that “a country that connects late meets the full threat landscape on day one” and Vanuatu describing how cyber risk and climate risk compound each other into a single existential threat .
—
Overall Tone
The tone of the discussion was largely formal and diplomatic, as is typical of UN plenary proceedings, but it was notably tense during the organisational segment. The procedural dispute over the appointment of co-facilitators introduced an undercurrent of division, with China and Belarus expressing pointed criticism of the Chair’s approach , while a broad coalition of Western and developing states offered explicit support . The Chair herself acknowledged the difficulty of the situation and accepted personal responsibility for her decision .
As the session transitioned to the substantive agenda item on cyber threats, the tone shifted considerably – becoming more collaborative, technically detailed, and at times urgent. Delegations from small island states such as Kiribati, Nauru, and Vanuatu introduced a notably human and vulnerable dimension to the discussion , which contrasted with the more geopolitically charged contributions from the EU, UK, and Estonia regarding Russian proxy activity and cyber sanctions . By the close of the session, the Chair was appealing for brevity given that 29 delegations remained on the speakers’ list , reflecting both the breadth of engagement and the practical constraints under which the mechanism operates.
Speakers Overview
B
Brazil
128 wpm · 8 min
C
China
85 wpm · 9 min
K
Kiribati
116 wpm · 6 min
RO
Republic of Korea
139 wpm · 2 min
NZ
New Zealand
153 wpm · 2 min
G
Germany
162 wpm · 3 min
C
Croatia
193 wpm · 1 min
A
Argentina
139 wpm · 5 min
C
Chile
128 wpm · 4 min
S
Singapore
144 wpm · 8 min
B
Belarus
176 wpm · 2 min
NI
Nigeria in behalf of the African group
106 wpm · 7 min
N
Netherlands
129 wpm · 3 min
TO
Tonga on behalf of the Pacific Islands Forum
116 wpm · 3 min
I
Italy
135 wpm · 4 min
N
Nigeria
135 wpm · 4 min
S
Switzerland
126 wpm · 6 min
EU
European Union
151 wpm · 6 min
S
Sweden
150 wpm · 3 min
E
Estonia
141 wpm · 4 min
F
France
160 wpm · 3 min
P
Portugal
138 wpm · 7 min
UK
United Kingdom
112 wpm · 3 min
C
Cuba
126 wpm · 4 min
A
Algeria
129 wpm · 4 min
SA
South Africa
111 wpm · 4 min
S
Serbia
121 wpm · 3 min
V
Vanuatu
121 wpm · 3 min
N
Nauru
132 wpm · 3 min
B
Botswana
155 wpm · 5 min
CR
Costa Rica
126 wpm · 3 min
M
Mexico
109 wpm · 3 min
C
Colombia
120 wpm · 3 min
I
Ireland
140 wpm · 1 min
T
Turkey
117 wpm · 3 min
K
Kazakhstan
135 wpm · 3 min
O
Oman
97 wpm · 4 min
SA
Saudi Arabia
126 wpm · 5 min
B-
Bosnia -Herzegovina
122 wpm · 3 min
V
Vietnam
97 wpm · 2 min
CE
Chair Egriselda López
121 wpm · 15 min
Expanded Summary: Second Meeting Within the First Substantive Plenary Session – UN Global Mechanism on ICTs in the Context of International Security
#
Overview and Session Structure
This document summarises the second meeting within the first substantive plenary session of the UN Global Mechanism on progress in ICTs in the context of international security and fostering responsible state behaviour on the use of ICTs, which convened under the chairship of Ambassador Egriselda López . Multiple delegations, including Croatia, Argentina, Bosnia-Herzegovina, Serbia, and Botswana, referred to this as “the first substantive session of the Global Mechanism,” with the current meeting being the second within that session. The session addressed two principal areas of business: first, the completion of the list of speakers under the organisational item concerning the work of the Dedicated Thematic Groups (DTGs), and second, the commencement of substantive discussions on existing and potential threats arising from the use of ICTs in the context of international security . The session represented a critical juncture for the newly established mechanism, which had been created to succeed the Open-Ended Working Group (OEWG) and to translate years of normative consensus into practical implementation.
—
#
Organisational Matters: Structure and Functioning of the DTGs
The opening segment of the session was dominated by debate over the structure, mandate, and working methods of the two DTGs – DTG 1, focused on ICT security challenges, and DTG 2, focused on capacity building. Brazil opened the discussion by welcoming the Chair’s designation of co-facilitators for both DTGs and expressing readiness to cooperate with them . Brazil argued that the DTGs should focus their discussions on a limited number of priority topics per cycle and draw on expertise from a wide variety of sources, including stakeholders, with due regard for geographic balance . On the specific agenda for DTG 1, Brazil proposed topics including more in-depth discussions of the voluntary checklist on norms implementation, the continued operationalisation of the points of contact directory, and further discussion on the application of international law in cyberspace, noting the growing number of national positions that had been published . Brazil also acknowledged that the protection of critical infrastructure, raised by other delegations, was a topic of utmost relevance .
On DTG 2, Brazil emphasised the strategic importance of capacity building, arguing that the interconnected nature of cyberspace means that security is a collective endeavour and that no country can be safe from threats in isolation . Brazil proposed that DTG 2 commence its work with a diagnostic assessment of the current capacity-building landscape, identifying existing initiatives, evaluating their strengths and weaknesses, and making recommendations for optimisation . Crucially, Brazil stressed that while synergy between the two DTGs was important, they are each autonomous bodies and DTG 2’s mandate should not in any way be tied to DTG 1’s . Brazil also called for a clear procedure to elevate DTG reports and negotiate recommendations to the plenary so that they may be formally adopted .
The Republic of Korea welcomed the appointment of co-facilitators and expressed confidence that through their efforts and continued engagement with member states, the global mechanism would make meaningful progress . On the substantive agenda for DTG 1, Korea proposed that ransomware and the protection of critical infrastructure could serve as important agenda topics, particularly in light of their growing significance . Korea also indicated readiness to support the Chair’s proposals where they are based on broad consultations with member states, acknowledging that a multilateral process cannot fully reflect every individual preference .
—
#
The Consensus Dispute: China and Belarus
China’s intervention introduced the most significant procedural tension of the session. China argued that DTG 1’s broad mandate – a product of the inability to reach consensus on its mandate during the OEWG negotiations – meant that either consensus must be reached on specific topics or countries must retain the right to propose topics they believe need to be raised . China explicitly objected to any procedure by which the Chair or certain individuals decide that certain topics seem to have received more support and therefore deserve discussion, calling such a practice a deviation from consensus equivalent to a form of voting . China further argued that informal meetings are not a “blank check” to abandon consensus .
On the selection of experts, China argued that the selection should be closely tied to the topics decided upon, rather than having experts determine what topics should be discussed . China also challenged the invocation of “UN practice” as a justification for the co-facilitator appointment, drawing a specific distinction between the First Committee and General Assembly – where resolutions are voted on if consensus cannot be reached – and the Second and Third Committees – where the approach is to reach consensus on all resolutions – noting that both are “UN practices” and that the relevant question is what practice is appropriate specifically for this global mechanism . China stated that over the 20-30 year history of cyber discussions at the UN, facilitators had never been appointed without consensus, and questioned whether the DTGs’ innovation was genuinely improving discussions or increasing divisions . On stakeholder participation, China cautioned against introducing NGO participation practices from other forums, arguing that the mechanism’s conclusions must be accepted by all countries to be globally significant, and that countries can learn from NGO discussions and bring useful practices back as national policy without formally integrating NGOs into the mechanism .
Belarus aligned itself with the joint statement delivered by the delegation of Nicaragua on behalf of a group of like-minded states . Belarus stated that General Assembly Resolutions 79/237 and 80/16 establish consensus as the fundamental principle for decision-making, and that deviating from this principle is unacceptable for both states and the Chair . Belarus acknowledged the Chair’s acceptance of responsibility for her decision on the appointment of co-facilitators but noted that an entire group of states had distanced itself from the procedure used . Despite these concerns, Belarus expressed readiness to work constructively with all states in a spirit of mutual respect, dialogue, and consensus .
—
#
Support for the Chair’s Approach: Germany, Chile, New Zealand, and Others
In contrast to China and Belarus, a broad coalition of delegations welcomed the appointment of co-facilitators as the Chair’s prerogative. Germany stated that it continues to view the appointment of co-facilitators as the prerogative of the Chair and that the working paper on the DTGs provided valuable clarity on roles and responsibilities . Germany identified several open points requiring specification, including the programme of work, topics, reporting from DTGs to the plenary, practical arrangements for stakeholder participation, and the selection of experts from the proposed pool . Germany proposed that the DTGs focus on thematically coherent topics, with both groups taking the same challenge as a starting point, proposed by the Chair and co-facilitators after consultation with states . Germany identified protection of critical infrastructure and ransomware attacks targeting essential services such as the healthcare sector as the two topics with the broadest support from numerous delegations . On reporting, Germany suggested that co-facilitators provide an oral update at the next plenary on preceding DTG discussions, with written action-oriented consensus recommendations also transmitted in writing for consideration .
Chile expressed full support for the nomination of co-facilitators as inclusive, well-balanced, and in line with UN practice . Chile described the DTGs as one of the most significant institutional innovations of the global mechanism and emphasised that their deliberations must prioritise dialogue and the search for consensus without reproducing formal negotiations or the adoption of decisions by consensus at each step of their work . Chile called for a clear and predictable programme of work for the biennium, drafted through consultations, with guiding questions or specific themes prepared by co-facilitators for each session . Chile also stressed the importance of adequate coordination between the different DTGs to avoid duplication and ensure a coherent approach to the implementation of the five pillars of the framework .
New Zealand reframed the informality of DTG meetings as “a feature not a bug,” arguing that informality provides space for inclusive, detailed discussions on novel or complex subjects in a way that is not possible during formal meetings . New Zealand endorsed a “less is more” approach, warning that trying to do too much at once in the DTGs risks doing nothing at all, and that focusing initially on a narrow set of issues with broad support would be more productive and serve as a proof of concept . New Zealand also stressed the importance of avoiding duplication of the plenary’s pillar-by-pillar discussion and expressed openness on the specific topics, hoping only to see issues that enjoy broad support and enable the DTGs to deliver practical value .
Croatia aligned with the EU statement and called for the plenary, DTGs, and intersessional activities to remain coherent, mutually reinforcing, transparent, and focused on practical outcomes while avoiding duplication and preserving the ability of all delegations to participate meaningfully . Argentina described the DTGs as one of the most important opportunities the global mechanism provides to move from normative consensus to practical implementation, arguing that their success should be measured not by the volume of documents produced but by their capacity to contribute to effective implementation . Argentina also stressed the importance of technical community participation, including experts from academia, the private sector, and institutions with recognised experience in the subjects under review . Argentina proposed using existing UN institutional accreditation systems for civil society organisations as a transparent, neutral, and predictable basis for stakeholder participation .
—
#
Kiribati: A Strategic Vision for Small States
Kiribati’s intervention was among the most strategically coherent of the session. Kiribati stated its firm conviction that the DTGs’ purpose is to build on what has already been agreed, not to reopen it, and that the cumulative framework for responsible state behaviour – adopted by consensus through successive OEWG reports – should serve as the common foundation . Kiribati did not seek to reopen the co-facilitator dispute but urged that however the matter is resolved, it should be resolved swiftly and in a spirit of consensus so that the DTGs can begin substantive work in December as planned . Kiribati warned that for a small state that has placed its hopes in the promise that this mechanism will act, the outcome most to be avoided is one in which the intersessional period is lost to procedure .
Kiribati made a substantive strategic argument that the mechanism operates in five-year cycles with a review conference at which states will collectively take stock, and that this gives space to sequence work sensibly – acting first on what is agreed and impactful, learning from the first biennium, and considering new questions in due course on the basis of evidence. Kiribati called for the DTGs to prioritise a small number of concrete deliverables with broad support so that their outputs are substantial enough to matter and focused enough to survive in the plenary . Kiribati also stressed the need for a clear and predictable way for DTG recommendations to be brought back to and taken up by the plenary, warning that without this link, the groups risk becoming discussions that lead nowhere . Kiribati identified two non-negotiable conditions: that DTG meetings must be conducted in a genuinely hybrid format – describing hybrid participation as “the difference between contributing and being absent” for a state as far from New York as Kiribati – and that the DTGs should draw on the expertise of stakeholders in line with agreed modalities .
—
#
Stakeholder Participation: A Contested but Broadly Supported Principle
The question of stakeholder participation generated significant debate. Oman argued that private sector and academic participation is essential because these parties can identify cyber threats and provide information not always available to governments, and that without their involvement the mechanism cannot access their experience . Oman also stressed that capacity building requires experience not only from governments but also from the private sector and other parties, particularly in developing countries .
France drew a memorable analogy to the FIFA World Cup – noting that the previous day’s final had been watched by many and congratulating Spain on their victory – before observing that “like in football, cyber diplomacy is a team sport, and non-state stakeholders also have a role to play if we want the mechanism to be relevant” . France went further, arguing that including non-state stakeholders would actually enable states to retain their central role, whereas excluding them risks making states marginal . The Netherlands proposed structuring DTG discussions around concrete, action-oriented work items including fictional scenarios pertaining to specific cyber threats or dilemmas, with guiding questions prompting states to consider what responsible state behaviour looks like in a given context . The Netherlands cautioned that negotiating written recommendations would place a heavy burden on delegation resources and significantly reduce the time available for substantive work, particularly affecting smaller delegations . The Netherlands also suggested that the intersessional period could be used to consult with delegations on the co-facilitators’ verbal reporting, to ensure the spirit of consensus is reflected in the process.
Singapore called for comprehensive discussions during the DTGs where countries could express a wide range of views, with focused topics enabling small states to better prepare given limited resources . Singapore recalled the relevant provisions of the final OEWG report on facilitators transmitting action-oriented draft recommendations for consideration by states . The African Group, speaking through Nigeria, affirmed that the mechanism must remain state-led, single-track, and consensus-based, with consensus serving as a driver of progress rather than an obstacle . The African Group also recognised the valuable contribution of relevant stakeholders, including civil society, academia, and the private sector, whose expertise complements the intergovernmental and state-led nature of the mechanism .
The European Union added a specific and politically charged dimension to the stakeholder debate by noting that Estonia had objected to the stakeholder JSC Positive Technologies on the grounds that it was already known to be supporting Russian cyber operations, and that its participation contradicts the ambitions of the global mechanism . This illustrated that even among those broadly supporting stakeholder participation, significant disagreements exist about which specific entities should be admitted.
—
#
The African Group’s Priorities
Nigeria, speaking on behalf of the African Group, outlined three mutually reinforcing priorities for the mechanism: strengthening implementation through capacity building and operational cooperation; leveraging regional and continental frameworks as implementation pathways; and understanding the evolving ICT threat landscape presented by emerging technologies and possible cooperative measures to address them . The African Group called for DTG 2 to be allocated adequate time to contribute to concrete and measurable outcomes, including early operationalisation of the global ICT security cooperation and capacity building portal, the point of contact directory, a UN Voluntary Fund for ICT Security Capacity Building, and a UN ICT Security Fellowship Programme .
On regional frameworks, the African Group highlighted Africa’s existing instruments, including the Malabo Convention and the Common African Position on the Application of International Law in Cyberspace, as a solid basis for the continent’s contribution to the global framework . The African Union was described as being at an advanced stage of validating AU guidelines for the implementation of norms of responsible state behaviour in cyberspace and the Declaration on Peace and Security in Cyberspace . The African Group also supported the continued use and further development of voluntary checklists of practical action as a tool to assist member states in implementing agreed norms . The African Group reaffirmed that international law, including the UN Charter, applies fully to the use of ICTs and remains fundamental to maintaining international peace, security, and stability .
—
#
Chair’s Mid-Session Appeal for Brevity
A notable procedural moment occurred during the transition from organisational to substantive discussions, when the Chair intervened to note that approximately 40 delegations had requested the floor under the threats agenda item with only one hour and fifteen minutes remaining in the session. The Chair appealed for shorter, more succinct statements, drawing attention to the countdown clock projected on the screen. This intervention illustrated the practical constraints under which the session operated and the challenge of accommodating a large number of delegations within the available time.
—
#
Substantive Discussions: The Evolving Cyber Threat Landscape
As the session transitioned to the substantive agenda item on existing and potential threats, the tone shifted from procedural tension to a more collaborative and technically detailed exchange. Tonga, speaking on behalf of the Pacific Islands Forum, identified ransomware as a severe and growing concern for Pacific states and called for the protection of critical infrastructure and critical information infrastructure to be taken up as an early focus topic for DTG 1 . Tonga highlighted the integrity of undersea cable infrastructure as not an abstract vulnerability but a lifeline, increasingly at risk from natural hazards, man-made disasters, and malicious activity . Tonga also identified AI-related cybersecurity threats as a potential area for practical discussion, noting that AI may increase the speed, scale, and accessibility of malicious cyber activity, including through more convincing social engineering, automated vulnerability discovery, and disinformation . Tonga called for DTG discussions to focus on practical outputs including accessible threat briefings, shared risk typologies, lessons from national and regional incidents, and best practice guidance, and for these discussions to be clearly connected with exchanges on cyber capacity building in DTG 2 .
Nigeria, speaking in its national capacity, described a broad spectrum of cyber threats confronting the country, including ransomware, malware, phishing, business email compromise, supply chain attacks, data breaches, and attacks on cloud infrastructure, critical information infrastructure, and Internet of Things systems . Nigeria noted that the malicious use of AI has further amplified risks through deepfakes, synthetic media, identity theft, online fraud, and disinformation . Nigeria described its national response, including the designation of certain sectors as national critical information infrastructure, the establishment of a National Cyber Security Coordination Centre, and the strengthening of its legal and institutional framework through cybercrime prevention legislation . Nigeria expressed support for scenario-based discussions under the DTGs as a way to enhance collective understanding of evolving threats .
—
#
State-Sponsored Activity, Proxy Actors, and Accountability: EU, UK, and Allied Positions
The European Union’s intervention was among the most politically charged of the session. The EU described a threat landscape in which malicious actors continue to target government services, critical infrastructure including hospitals, financial institutions, and energy grids, and in which cyber tools are being used as fully integrated instruments of war, even against international humanitarian organisations . The EU highlighted the growing use of AI models to exploit zero-day vulnerabilities nearly instantly upon their discovery .
The EU drew particular attention to the growing use of non-state actors as proxies by states, arguing that non-state actors tolerated by, linked to, or controlled by a state function as highly effective and deniable proxies, and that actively using or encouraging proxies is irresponsible behaviour contrary to UN norms . The EU explicitly named Russia, stating that the EU and its member states, alongside the United Kingdom, had exposed and condemned the misuse by Russia of an ecosystem of actors – including a government agency, private sector entities, hacktivists, and criminals – to target the EU, its member states, and its partners . The EU announced that it had imposed sanctions on individuals and entities supporting Russia’s malicious behaviour .
Portugal aligned with the EU statement and provided a detailed overview of its national threat landscape, noting a marked intensification and diversification of malicious cyber activity spanning the full spectrum of threat actors, from sophisticated state and state-sponsored operations to increasingly professionalised non-state criminal enterprises . Portugal expressed concern about the persistence of malicious cyber activity attributable to state actors and networks operating under their direction, sponsorship, or tolerance through proxy actors, criminal affiliates, and self-styled activist collectives . Portugal also raised the use by certain states of offensive and intrusive cyber capabilities to monitor, harass, and repress dissidents and diaspora communities, calling such practices fundamentally incompatible with respect for human rights and fundamental freedoms .
Estonia argued that the global mechanism occupies a distinct place within the UN architecture as the only universal forum entrusted with examining cyber threats that affect international peace and security . Estonia stated that artificial intelligence is fundamentally reshaping the cybersecurity landscape and that the global mechanism should address AI’s impact within its mandate, noting that AI is increasing the scale, speed, and sophistication of malicious cyber activity, from AI-enabled phishing and ransomware to attacks on AI systems themselves through manipulation or poisoning . Estonia highlighted the growing use of proxy actors as a trend deserving particular attention, noting that such proxy models undermine international security and stability and are inconsistent with agreed UN norms . Estonia announced a technical briefing titled “Frontier AI and the Cyber Threat Landscape” to be held during the session, co-hosted with Latvia and Oxford Information Labs .
Sweden identified the evolving nexus between state and non-state actors as an increasing concern, raising questions regarding state responsibility particularly where non-state actors act with varying degrees of state support . Sweden welcomed the latest EU cyber sanctions package and called on all states to use cyber capabilities in accordance with international law and to take necessary measures to stop malicious actors operating within their jurisdictions . The United Kingdom described a threat landscape in which states, their proxies, and cyber criminal networks increasingly run coordinated campaigns alongside information, economic, and other hybrid operations . The UK announced its first joint cyber sanctions package with the EU, targeting Russian state actors including senior intelligence officers and closely associated criminal and proxy networks responsible for orchestrating destructive cyberattacks across Europe .
—
#
Ransomware and Critical Infrastructure: Cross-Regional Consensus
Across the substantive threat discussion, ransomware and the protection of critical infrastructure emerged as the most widely supported priority topics, with delegations from all regions sharing direct national experiences. Costa Rica cited its own 2022 cyber attacks as demonstrating that ransomware and malicious operations can impact state functions, public services, institutional continuity, and public trust . Costa Rica called for the protection of critical infrastructure and essential services to be central to discussions, listing hospitals, financial systems, energy networks, water, telecommunications, transport, education systems, emergency services, and state digital platforms as indispensable components of human well-being .
Ireland drew on its 2021 experience of a hugely disruptive criminal ransomware attack on its health service, calling for the protection of the healthcare sector against malicious cyber activity to be a focus topic for the DTGs . Colombia identified ransomware attacks against critical infrastructure and state institutions as a priority, noting that this threat is aggravated by the use of AI to engage in more sophisticated and precise campaigns that are more difficult to detect . Colombia also raised the risks associated with attacks against AI systems themselves and the need for effective measures for their protection. Singapore reported close to 8,000 ransomware cases worldwide in 2025 based on data leak site postings, and noted that the ransomware ecosystem has continued to evolve and fragment . Singapore described international cooperation as essential to countering ransomware as an inherently transnational threat, referencing the Counter Ransomware Initiative as a multilateral platform working with industry partners to strengthen collective resilience . Singapore also addressed quantum computing in its substantive statement, highlighting the threat posed to existing cryptographic systems and the need for states to migrate to quantum-safe cryptography before quantum computers become powerful enough to break current systems.
Italy reported a 38% increase in cyber events in the previous year and a 68% increase in incidents targeting the public sector, with 75% of attacks directed towards local and central administrations . Italy described ransomware as one of the most impactful cyber threats, mainly affecting small manufacturing companies with limited capacity and often causing prolonged service disruption . South Africa expressed deep concern about the significant increase in the frequency and devastating impact of cyber attacks on critical infrastructure, proposing the inclusion of these threats in the priorities for DTG 1 in December .
Brazil, in the substantive segment, made a pointed argument that discussions currently underway in ad hoc processes outside the UN on issues such as ransomware, AI implications to cybersecurity, and intrusive tools must be integrated into the global mechanism . Brazil argued that the borderless nature of these threats means that the engagement of all nations is needed to adequately tackle them, and that “keeping discussions within the echo chambers of our like-minded groups will reduce their reach, effectiveness, and legitimacy” . This implicitly challenged the Counter Ransomware Initiative and similar coalitions, and reinforced Brazil’s earlier call for the DTGs to draw on a wide variety of sources with due regard for geographic balance . Brazil also called for the creation of a threat repository, the adoption of common terminology, and the sharing of good practices in threat mitigation as concrete tools to improve cybersecurity resilience . Brazil expressed particular concern about the use of generative AI in misinformation and disinformation campaigns, including deepfakes, noting that in the context of an armed conflict this could cause grave harm to civilians and constitute a violation of international humanitarian law . Brazil called for deeper discussions on AI and quantum computing, particularly post-quantum cryptography, within the mechanism .
—
#
Artificial Intelligence: A Near-Universal Concern
The malicious use of artificial intelligence was raised by virtually every delegation that took the floor during the substantive threat discussion, reflecting near-universal recognition of AI as a transformative and urgent challenge. Turkey highlighted the evolving security implications of advanced AI models, noting that their capabilities in code generation, vulnerability discovery, automation, and large-scale social engineering may increase the speed, scale, sophistication, and effectiveness of malicious cyber operations . Turkey expressed particular concern that the widespread availability of such capabilities may lower the barrier to entry for less-resourced actors, including criminal networks and terrorist organisations . Turkey proposed that the mechanism consider sharing risk assessments on AI-enabled ICT threats, developing voluntary norms and safeguards for responsible development and deployment of high-capacity AI models, and establishing structured information sharing on AI-enabled incidents .
Switzerland reported that according to its national cyber security centre, the frequency, sophistication, and strategic significance of malicious cyber activities are increasing, a trend accelerated by the rapid development of large language models . Switzerland noted that current AI models overwhelm many software providers, particularly open-source maintainers, jeopardising the ability to fix vulnerabilities in a timely manner . However, Switzerland argued that there is no need to adopt new voluntary norms or specific confidence-building measures for AI, as existing ones are generally broad enough to address the challenges posed by AI and cybersecurity . Switzerland also cautioned against conducting discussions on AI in isolation from other ongoing processes, such as the global dialogue on AI governance . Switzerland specifically offered to share its experience on mandatory incident reporting and public-private information sharing as a concrete contribution to the capacity-building work of the mechanism.
Algeria warned that if advanced AI-enabled cyber capabilities remain concentrated in the hands of a few actors while many countries lack the infrastructure, expertise, and access to secure technologies needed to detect, defend against, or respond to malicious ICT activities, the digital divide risks becoming a security divide, thereby undermining sovereignty, resilience, and collective stability . Algeria stressed that the proliferation and misuse of spyware and intrusive cyber capabilities constitutes a serious violation of fundamental human rights, international law, state sovereignty, diplomatic inviolability, and the principle of non-interference in internal affairs, with direct consequences for regional stability and international peace and security . Algeria called for this threat to be explicitly included in the reports of the global mechanism, with clear recommendations for stronger international norms and effective accountability mechanisms .
Vietnam specifically mentioned the illicit trade in user information and personal data, phishing and other online fraud schemes, and the use of ICTs to facilitate trafficking in persons as specific cybercrime concerns, in addition to threats posed by AI and quantum computing. Serbia raised concerns about the growing availability of commercial intrusive tools and the misuse of AI and cryptocurrencies for cybercrime as specific threats warranting attention within the mechanism.
—
#
Small Island Developing States: Compounding Vulnerabilities
Several of the most distinctive and humanising contributions to the threat discussion came from small island developing states, which framed cyber threats not as abstract geopolitical concerns but as immediate existential risks. Vanuatu, consistently assessed as the most disaster-exposed nation on Earth, described how twin cyclones in 2023 and an earthquake in December 2024 had each destroyed the digital systems on which modern crisis response depends . Vanuatu argued that for its context, cyber risk and climate risk are not parallel concerns but a single compounding one, and that a malicious ICT incident during a disaster window would not be an inconvenience but would cost lives . Vanuatu called for early warning systems, emergency communications, and disaster coordination platforms to be recognised at the top of the critical infrastructure catalogue . Vanuatu also highlighted the risk that AI-generated synthetic content – such as a fabricated evacuation notice or falsified weather warning – could send communities towards danger rather than away from it, describing this as a safety-of-life issue rather than merely an information one .
Nauru, which had only recently received its first international submarine cable, offered a candid perspective on the experience of late-connecting states: “A country that connects late meets the full threat landscape on day one that others encounter gradually” . Nauru described its people encountering online fraud and scams engineered against those newest to the Internet, and its government systems joining a region in which health systems and telecommunications operators have been held to ransom by criminal groups . Nauru is finalising what it described as the most comprehensive digital reform programme in its history, encompassing a cybersecurity bill establishing a framework for critical information infrastructure protection including a national CERT and incident reporting obligations, a data protection bill, revisions to its cybercrime bill, a national cybersecurity strategy, and a national child online protection strategy. Nauru called on the mechanism to make its outputs usable, producing shared assessments in plain terms, early warning that reaches small administrations, and guidance that helps states act on what they learn .
Kiribati, in the substantive segment, reiterated that for a small state that has placed its hopes in the promise that this mechanism will act, the outcome most to be avoided is one in which the intersessional period is lost to procedure .
—
#
Capacity Building: A Strategic and Cross-Cutting Priority
Multiple delegations emphasised that capacity building must be treated as a substantive and cross-cutting pillar rather than an afterthought. Saudi Arabia announced the launch of the Global Initiative for Capacity Building in Cyberspace with the UN and its specialised agencies at the Global Cybersecurity Forum in October 2025, aimed at supporting international efforts for capacity building and ensuring cyber readiness at the global level . Saudi Arabia also launched a Capacity Building Programme for representatives of member states participating in the global mechanism, in partnership between the GCF and UNODA, which had already benefited cybersecurity experts from more than 80 states . Kazakhstan emphasised that for Central Asia and as a landlocked country, key areas include strengthening national and regional capacities, developing human resources, and increasing the resilience of critical infrastructure . Kazakhstan highlighted the importance of cyber hygiene and noted that it had amended its labour code to establish responsibilities for employers to promote cyber culture within organisations . Kazakhstan also noted that following a national referendum, its new constitution highlights the right to protection of personal data in the digital environment, and that a digital code and a law on AI had been adopted.
Bosnia-Herzegovina expressed deep concern about the growing number of cyber activities targeting democratic institutions and electoral processes, noting the particular vulnerability of states with limited capacities, including those in post-war countries . Bosnia-Herzegovina also thanked Germany for supporting its participation through the “Project Partnership for Strengthening Cybersecurity” and GIZ for facilitation – a concrete example of capacity building in practice. Botswana described the risks inherent in transitioning to a fully interconnected society, including AI-driven manipulation, deepfakes, mass disinformation campaigns, data protection risks, and the weaponisation of malware . Botswana called on member states to prioritise regional and international cooperation in sharing threat intelligence, capacity building, and adherence to the normative framework of responsible state behaviour .
—
#
Human Dimensions of Cyber Threats
Several delegations called for threat analysis to incorporate a human dimension and consider the differentiated nature of harm caused by cyber incidents. Costa Rica argued that women and girls, the elderly, persons with disabilities, migrants and refugees, journalists, human rights defenders, and other groups may face specific risks such as undue surveillance, digital harassment, fraud, information manipulation, or exclusion from digital services . Mexico underscored the gender dimensions of cyber threats, noting that digital violence in its various forms disproportionately affects women and girls and can limit their participation in public, economic, and social life, and called for sex-disaggregated data to enable the design of more effective policy responses . Mexico also highlighted the cybernetic dimension of major international events, citing the 2026 FIFA World Cup as an example of the importance of close coordination between Mexico, Canada, and the United States to protect critical infrastructure during large-scale events .
—
#
International Law and the Normative Framework
Several delegations reaffirmed the applicability of existing international law to cyberspace and the sufficiency of the existing normative framework. France reaffirmed its historic commitment to existing international law and the UN Charter, expressing regret that those promoting an alternative treaty are also the first to violate this foundational text . France identified three main priorities for the coming year: making progress in implementing the regulatory framework through the thematic groups; continuing work on the application of existing international law to cyberspace; and keeping pace with technological advances including artificial intelligence . The African Group reaffirmed that international law, including the UN Charter, applies fully to the use of ICTs and remains fundamental to maintaining international peace, security, and stability . Switzerland argued that existing voluntary norms are generally broad enough to address the challenges posed by AI and cybersecurity without the need for new instruments .
Cuba, by contrast, called for the negotiation and adoption within the UN of an international legally binding instrument that complements applicable international law and responds to significant legal loopholes in cybersecurity , a position that France implicitly countered. Algeria stressed that the proliferation and misuse of spyware and intrusive cyber capabilities constitutes a serious violation of fundamental human rights, international law, state sovereignty, diplomatic inviolability, and the principle of non-interference in internal affairs , and called for stronger international norms and effective accountability mechanisms .
—
#
Chair’s Closing Remarks and Next Steps
As the session drew to a close, the Chair noted that 29 delegations remained on the list of speakers under the threats agenda item and that the session would reconvene the following morning at 10 a.m., with Egypt, Kiribati, New Zealand, Tonga, and the Kingdom of the Netherlands named as the first five speakers . The Chair confirmed that she would continue working with delegations during the intersessional period on the programme of work and other organisational aspects of the DTGs, and would organise consultations in coordination with the co-facilitators to address remaining open modality questions . The Chair indicated that after concluding the discussion on existing and potential threats, the session would proceed to voluntary non-binding norms on responsible state behaviour and ways for their implementation .
The session thus concluded with a complex picture: deep procedural divisions over the appointment of co-facilitators, the consensus principle, and stakeholder participation remained unresolved, while a remarkably broad substantive convergence had emerged across geopolitical lines on the key threats facing states – ransomware, attacks on critical infrastructure, AI-enabled malicious activity, and the growing use of proxy actors. The challenge for the mechanism in the intersessional period would be to translate this substantive convergence into an agreed programme of work for the DTGs, while managing the procedural tensions that had characterised the opening of the session.
—
Chair Egriselda López
the second meeting of the 2026 substantive plenary session of the global mechanism on progress in ITC in the context of international security and fostering responsible state behavior on the use of ICTs. Distinguished delegates, as I announced this morning, we will begin by finishing our list of speakers under the item organization of work. As stated before, we already have a list of speakers and I’m just going to read out the list as I have it right now. Brazil, Republic of Korea, China, Kiribati, Oman, Brazil, Korea, China, New Zealand, Germany, Croatia, Argentina, Chile, France, the Democratic Republic of Congo, Singapore and Belarus.
—
Brazil
and Belarus. I give the floor then to the Distinguished Delegation of Brazil. Muchas gracias, Senhora Presidenta. Madam Chair, my delegation would like to thank you and your team for the efforts you have been undertaking since your election to lay out the foundations for the work of this mechanism. We welcome your designation of co -facilitators for both DDGs and stand ready to cooperate with them in their discharging of their duties. For the DDGs to perform their functions most effectively, they should focus their discussion on a limited number of priority topics on each cycle. They should also feed on the expertise of a wide variety of sources, including stakeholders. with due regard for geographic balance. Madam Chair, my delegation presented some options in March for topics for DDG 1, such as more in -depth discussions of the voluntary checklist on norms implementation, the continued operationalization of the points of contact directory, or further discussion on the application of international law in cyberspace, taking into account the growing number of national positions that have been published. Other delegations have mentioned the protection of critical infrastructures, which is also a topic of utmost relevance. We remain ready to engage constructively with other delegations in order to reach agreement on DDG’s agenda, DDG’s 1 agenda. The creation of DDG on ICT security capacity building was of particular importance to me. The interconnected and transactional nature of cyberspace means that security is even more a collective endeavor than in other arenas. No country can be safe from threats in the digital domain in isolation. We are only as strong as our weakest link. My country, along with many others, has advocated for greater United Nations involvement in this domain. Centralizing the many existing capacity -building initiatives under the UN umbrella would facilitate access by those who need them and ensure a closer alignment with priority issues identified by the OEWG and the GMAC plenary and better compliance with the capacity -building principles adopted by the OEWG. In this regard, it would be beneficial for the DTG on capacity -building to commence its work with a diagnostic assessment of the current landscape and the landscape in the field, identifying existing initiatives, evaluating their strengths and weaknesses, and making recommendations for its optimization. While it will be important to ensure synergy between both DTGs, they are each autonomous bodies, and DTG2’s mandate should not in any way be tied to DTG1’s. Madam Chair, it will be key to ensure that discussions within the DTGs adequately fit the work of the plenary. For that to happen, we must establish a clear procedure to elevate DTG’s report and negotiate the recommendations to the plenary so that they may be formally adopted. My delegation looks forward to continuing working with you and your team and to engage constructively with all delegations as we embark on this new chapter in the pursuit
—
Chair Egriselda López
Thank you very much. I give the floor now to the Republic of Korea.
—
Republic of Korea
Thank you, Madam Chair. We welcome you, Chair’s appointment of the co -facilitator, and express our appreciation for their willingness to undertake this important responsibility. We look forward to working closely with the co -facilitators under your leadership, and we’re confident that through their efforts and continued engagement with member states, the global mechanism will make meaningful progress in advancing this substantive work. With regard to work of DTG -1, we believe that ransomware and the protection of critical infrastructure could serve as important agenda topics, particularly in light of their growing significance and potential for the future. We look forward to working closely with the Republic of Korea and the broad support they have received from member states. Chair, we recognize that the previous OEWG report may not explicitly address every procedural issue that may arise during the work of the global mechanism. By its very nature, a multilateral process inevitably cannot fully reflect every individual preference of all member states. In such cases, we are prepared to support the Chair’s proposals where they are based on broad consultations with and due considerations of the views of member states. Because we believe it is very important that the global mechanism now move forward with substantive discussions in order to achieve our shared objective, which is to promote a cyberspace that is secure, stable, open, and peaceful.
—
Chair Egriselda López
Thank you very much. Now I give the floor to the delegation of China.
—
China
Thank you, Chair. with regard to the future DTGs. It is a very important question. About DTG 2, we seem to have a rather clear consensus on that. But as for DTG 1, relatively speaking, its mandate is broad. That is because when we were negotiating the final document of the OEWG, we couldn’t reach a consensus on the mandate of DTG 1. Countries all have their preferences and priorities. Based on the discussions, we can see that DTG 1 is a very important document and the divisions remain. therefore with regard to the topics of DTG1 either we reach consensus on certain specific topics or countries have the right to propose those important questions that they believe need to be raised in DTG1 there shouldn’t be such a procedure by which the chair or certain people will decide that certain topics seem to have received more support and therefore they deserve our discussions such a practice is to turn consensus into certain kind of voting Thank you we can all agree that for substantive, major substantive and procedural issues of the global mechanism, we need to reach consensus. Well, that practice is a deviation from the consensus. I don’t believe it should be any kind of UN practice. Therefore, informal meeting is not a blank check. In other words, you can just abandon consensus. Second, about the selection of experts for DTGs. I’d like to remind all the colleagues that we invite experts to our discussions. Thank you very much. for the purpose to better our understandings about certain topics or certain backgrounds. Therefore, the selection of experts should be closely tied to the topics we discuss. The topics we decide on discussing will decide what kind of experts we should invite. Instead of having experts telling us what topics we should discuss. Third, a point on UN practice, because many countries mention UN practice. In the UN system, there are many practices. In the First Committee of the UN, there are many practices. In the General Assembly, all resolutions are voted on. if consensus cannot be reached. But in the second or third committees, their approach is to reach consensus on all resolutions. There is no such an option or vote. So both of these are UN practices. So when we talk about UN practice, it doesn’t make this word any more authoritative because the key to this question is in this global mechanism, in this context of DTG, what kind of UN practice should we adopt here? that is the question that we should really pay attention to the the DTGs have its own rules of procedure rules of procedures of other bodies or other committees will not automatically apply here I hope in our future discussions let’s talk about what kind of rules we should use here instead of talking about UN practice because I don’t really know what kind of UN practice you’re talking about cyber issue became a UN topic in 1998 it’s been 20 -30 years and over this history We never saw the appointment of facilitators without consensus. So this is not a practice of the global mechanism. I do understand that many countries regard DTGs as an innovation or an experiment. But the purpose of innovation is to make our discussions better instead of increasing our divisions. Many countries hope that NGOs can join the discussions without any limitation. They could totally go to a conference room in a building. And all the interested countries can join voluntarily. they can talk about anything many countries all said that they want to learn from the experiences of these NGOs if you find this experience is useful you can really bring them back and make them your national practice no one will be stopping you from doing that why do we have to introduce this practice into this global mechanism with this mechanism we hope that the conclusions that we reach here can be accepted by all countries only when all countries can accept this will the they become important to global rule so the key is whether the NGO’s participation is useful or not, or whether you can actually learn from discussions. The crux is whether we respect an important practice of this global mechanism, which has been developed over the last 20 or 30 years. There is an old Chinese saying which means to the effect of trying to take practice from faraway places instead of close by. We hope that in our future discussions, we can look at what is a practice that has emerged over the past 20 or 30 years here. In a few days, there will be a side event by UNIDEA where the history of OEWG will be be shared. I hope that Unity will share what is our practice
—
Chair Egriselda López
Thank you. Now I give the floor to the delegation of Kiribati, followed by Oman and New Zealand.
—
Kiribati
Madam Chair, we thank you for your dedication in bringing us to the point where we can now turn our minds to the dedicated thematic groups. Madam Chair, Kiribati approaches the DGGs with one clear conviction. Their purpose is to build on what we have already agreed not to reopen it. The cumulative and evolving framework for responsible state behavior reaffirmed through the successive reports. of the open -ended working group and carry it into this mechanism through Annex 1 of A -80 -257 and Annex C of A -79 -214 is our common foundation. It was adorned by consensus. Kiribati’s firm will is that the DTGs should take that consensus as their starting point and devote their energy to implementation rather than relitigating questions that the membership has already settled. Madam Chair, we have listened carefully to the concerns some delegations have raised regarding the establishment of the co -facilitators of the dedicated diplomatic groups. Kiribati does not seek to reopen that discussion here. Our concern is a practical one, that however this matter is resolved, it is resolved swiftly and in a spirit of consensus, so that the dedicated thematic groups can begin their substantive work in December as planned. For a small state that has placed its hopes in the promise that this mechanism will act, the outcome we most wish to avoid is one in which the intersessional period is lost to procedure. We say this deliberately. This mechanism was established to be action -oriented. The DDGs are the instrument through which that ambition is meant to become real. The space, in the words of the framework we adopted, for focused and practical exchanges, that produce action -oriented recommendations. If the groups spend their first binomial reoccurring settled ground, they will squander the very feature that distinguishes this mechanism from what came before, and they will do so at the expense of the states that can least afford lost time. Kiribati’s message is therefore simple. We should consolidate before we expand. We already have a framework, 11 agreed norms, and a body of confidence -building and capacity -building commitments. The immediate task is to make this operational, to move from what states have agreed to do to how they will actually do it. That is a full agenda in itself, and it should come first. Within that agenda, the DDGs cannot do everything at once and delegations like ours cannot follow an endless list of subtopics. We would encourage the groups to prioritize a small number of concrete deliverables with broad support so that their outputs are substantial enough to matter and focused enough to survive in this plenary. And for the work of the groups that carry away, there must be a clear and predictable way for the recommendations to be brought back to and taken up by this plenary. Without that link, the group risks becoming discussions to lead nowhere. And Kitty Best would welcome clarity on this point during this session. Madam Chair, we also recall that this mechanism operates in five -year cycles. With a review conference at what will collectively take stock. that gives us the space to sequence our work sensibly, to act first on what is agreed and impactful, to learn the experience of this first binomial, to consider new questions in due course on the basis of evidence rather than a session. Two final points that are, for GDBES non -negotiable, the DDGs must be conducted in a genuinely hybrid format for a dedication based as far from New York as our capital. Hybrid participation is the difference between contributing and being absent. And an implementation party that cannot hear from the state most in need of implementation will defeat its own purpose. And the DDGs should draw on the expertise of stakeholders. in line with the modalities we have agreed because practical implementation is precisely where the technical knowledge is most valuable. Kiribati stands ready to engage constructively and to help this mechanism improve in December and beyond that it can convert where we have agreed into what state can actually do. I thank you, Madam Chair.
—
Chair Egriselda López
Muchísimas gracias. Thank you very much. Now I give the floor to Oman, followed by New Zealand and Germany.
—
Oman
Madam Chair, the Sultanate of Oman congratulates you for taking up the role of Chair during this cycle of the global mechanism on development in the field of ICTs. We… congratulate you and we wish you every success in your work to strengthen the work of this mechanism for advancing responsible state behaviour in the use of ICTs. This is something that must be protected and safeguarded in developments in the private sector and in academia are things that must be taken into account and they must be able to participate in this endeavour. The conclusion of this mechanism must be realistic and it must be implementable, the outcomes of it. As for the parties who have a lot of experience they need to be mentioned First of all if we leave these parties to one side, well we might not have a proper understanding of certain challenges if they’re not involved. So they need to be consulted on databases and other topics and these parties can identify cyber threats, they can help us to counter these threats and this information is not always available to governments. So if these parties are not involved then we can’t access their experience and we need their experience in our discussions. Secondly, capacity building is a pillar of the work of this mechanism, of its programs including the global manual. And we need experience, not only government experience but also from the private sector and other parties. in order for us to be able to implement the principles of the manual. And this is particularly the case in developing countries. Thirdly, we need to review the recommendations. Practical experience in management helps us to implement recommendations. If we can’t access all of these different contributions, then it will have an impact on the final outcome. So what we need are policies that are in step with reality. And this in line with the third. report of the group of experts. We need to listen to the experts and all of the different parties, otherwise the mechanism won’t be able to strengthen trust in the field of ICTs in particular when it comes to responsible state behaviour. Madam Chair, the recommendations must be applicable they must be implementable and in order to achieve this we need participation from
—
Chair Egriselda López
Thank you very much. Now I give the floor to New Zealand.
—
New Zealand
Thank you Chair. As has been noted already, the DTGs are a key innovation of this process and we appreciate your work to set them up for success. We know that in accordance with Annex 1 of the final OEWG report DTG meetings are informal This is a feature not a bug Informality provides space for inclusive, detailed discussions on novel or complex subjects in a way that is not possible during formal meetings The informal dynamic will support the development of practical action -oriented initiatives And when it comes to what the DTG should focus on in December, we support the views shared by Kiribati just now Less is more Trying to do too much at once in the DTGs risks doing nothing at all Focusing initially on a narrow set of issues that are of widespread interest and enjoy broad support will be more productive and serve as a proof of concept for the DTGs It’s also consistent with what we agreed in Annex 1 that the DTGs should avoid duplicating the discussions of the plenary and instead be more action -oriented. Avoiding duplication of the plenary’s pillar -by -pillar discussion is critical to ensuring good participation in the DTGs and demonstrating the value of the global mechanism. We are open -minded as to what particular topics the DTGs focus on. We only hope to see topics that enjoy broad support and enable the DTGs to deliver practical value for members. We also think it makes sense to seek some kind of coherence between the work of the two DTGs. Thank you.
—
Chair Egriselda López
Muchas gracias. Thank you very much. I now give the floor to the delegation of Germany, followed by Croatia, Argentina, and Chile.
—
Germany
Thank you very much, Chair. Germany aligns itself with the statement of the European Union and delivers the following remarks in a national capacity. Germany welcomes the appointment of co-facilitators of the dedicated thematic working groups, which we continue to view as the prerogative of the Chair. Your working paper on the DTGs provided valuable clarity on the roles and responsibilities of co-facilitators and how you intend to work with them under your leadership. Germany views this week’s plenary meeting as an important opportunity to engage with all member states on remaining open modality questions to ensure that the first meeting of the dedicated thematic working groups in December can create meaningful, action-oriented and substantive discussions. We see some open points that require specification, in particular the program of work of the DTGs, their topics, the reporting from the DTGs to the plenary, and the practical arrangements of the stakeholders’ legislation, and the selection from the pool of experts that you have proposed in your working paper. In our view, DTGs, the plenary meetings, and the global roundtable on capacity building play distinct roles. The plenary will discuss each pillar of the framework separately and provide guidance to the DTGs. DTGs will provide a forum for cross -cutting discussions on specific issues. Thereby, they can generate concrete, actionable recommendations and identify best practices to address these issues using all elements of the framework in a balanced way. We have already mentioned the crucial importance of the participation of stakeholders in this regard earlier today. Having them and their expertise at the discussion at UN level would benefit all of us, not only the organization they happen to be part of or the country they happen to stem from. This would also contribute to enhancing the common understanding of challenges. Germany sees value in thematic cohesion between the meetings of DTG 1 and DTG 2, meaning that they should take the same challenge as a starting point. This challenge should be proposed by the Chair and the co -facilitators after consultation with States. Two topics with numerous delegations echoed over the course of consultation so far were the protection of critical infrastructure as well as addressing ransomware attacks targeted at essential services such as the healthcare sector. Lastly, as regards reporting, Germany believes that the co -facilitators and or you, Madam Chair, could provide an oral update at the next plenary meeting on the discussions that we had at the preceding DTG meeting. Additionally, written action -oriented consensus recommendations could be transmitted in writing to the plenary for consideration, provided that they were agreed by states in the spirit of consensus and intersessional period between DTG meetings and the plenary meeting. A neutral summary of proceedings report by the Secretariat could also be issued. Thank you, Chair.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Croatia.
—
Croatia
Thank you, Madam Chair and dear colleagues. It is a privilege to address you on behalf of the Republic of Croatia. During this first substantive session of the UN Global Mechanism. I would like to first join in expressing my gratitude to you, Madam Chair, and to your team. for everything done in the lead -up to this first session of the Global Mechanism. We would like to fully align with the EU statement, especially on the work on the DTGs, but also on the need to ensure the participation of relevant stakeholders in the work of the Global Mechanism. Furthermore, we welcome the appointment of the co -facilitators of the DTGs, with whom we look forward to further engage with. The plenary, the dedicated thematic groups, and intersessional activities should remain coherent and mutually reinforcing, transparent, and focused on practical outcomes, while avoiding duplication and preserving the ability of all delegations to participate meaningfully. The Republic of Croatia is committed to strengthening the framework of responsible state behavior in cyberspace, and we are eager to work with you and member states in a constructive and action -orientated manner to achieve concrete and tangible results in implementing the framework. In this sense, we look forward to fruitful and constructive discussions during the next week in order to provide guidance to the work of the DTGs in December. Thank you.
—
Chair Egriselda López
Thank you. Muchas gracias. Thank you very much. I now give the floor to… Argentina.
—
Argentina
Madam Chair, my delegation wishes to begin by congratulating you for assuming this very important responsibility of presiding over this first substantive session of the global mechanism and we’re so aware of how important this moment is. The setting forth of this mechanism is a milestone for the United Nations and will require leadership, capacity for dialogue and constant efforts to build consensus. In this regard, please allow us to express our conviction that this process is in the right hands and we wish to reiterate the fact that my delegation stands fully ready to work constructively with you and alongside other delegations. Madam Chair, we believe that the dedicated thematic groups constitute one of the most important opportunities that the global mechanism provides in order to make progress from a normative point of view to the practical and the practical. Practical implementation of the global mechanism. on responsible state behaviour. We believe that this group can provide particularly important added value through discussions focused on concrete issues and focused on identifying practical solutions that would strengthen cooperation between states. In our judgment, the success of the thematic groups should not be measured by the amount of documents they produce, but rather by their capacity to contribute to the effective implementation of the consensus already reached. On this, please allow me an opportunity to refer to the agendas of the different groups. We believe that the work of each and every one of these dedicated groups must be horizontal in their nature. So this means that it should not be subordinate to the discussions of another dedicated group. We believe that the DTGs have an essentially complementary nature vis -à -vis the plenary and their role should be to consist in going into depth on the technical analysis of particular thematics and to facilitate the identification of possible courses of action that could subsequently be considered by the plenary. Preserving this body as the ultimate and one in the natural environment for making decisions based on census the outcomes that could come out of the DTGs will be all the more useful when they can contribute to the deliberations between states and facilitate the identification of areas of convergence for the consideration of the plenary. Madam Chair, my delegation attaches particular importance to the participation of the technical community in these DTGs. We’re convinced that our deliberations will be significantly more fruitful if we have experts from academia, the private sector and the DTGs. The tech community, the group on responding to incidents, critical infrastructure and other institutions with recognised experience in the subjects under review. The experience of those who develop, operate and protect the digital ecosystem is an essential input for us to be able to make headway towards technically robust and operationally useful solutions At the same time, we understand that the participation of other interested parties will be strengthened if we continue to develop it on transparent, neutral and predictable criteria that enable us to consider the technical nature of contributions with adequate geographical diversity in full respect for the intergovernmental nature of the mechanism When it comes to civil society organisations, we believe that it would be beneficial to use already consolidated institutional accreditation systems within the UN system and this is already a robust and predictable process, so we would suggest using that We believe that the credibility of the… global mechanism will largely depend on our ability to strike the right balance between openness to specialised technical knowledge, the preservation of the intergovernmental nature of the mechanism and constant focus on concrete and tangible results for states. We’re convinced that these three elements are fully compatible with one another and constitute the best guarantee possible for these DTGs to be successful. Finally, Madam Chair, we wish to reiterate our support to your work and the work of your team and the fact that we stand ready to continue to work with flexibility and a constructive spirit to ensure that this new mechanism can yield concrete results that will strengthen the security
—
Chair Egriselda López
Thank you very much. I now give the floor to Chile, followed by the Democratic Republic of the Congo, then Singapore, Belarus, the Netherlands, and the Kingdom of the Netherlands, and France.
—
Chile
Thank you very much, Madam Chair. Chile is grateful for the leadership that you’ve shown organizing this work, and we express our full support to the nomination of the co -facilitators of the DTGs. For us, it’s inclusive and well -balanced and in line with UN practice, and that’s why we will actively support the work that they engage in. In our view, the dedicated thematic groups are one of the most significant institutional inventions of the global mechanisms, and they will contribute to the debates of the plenary, providing spaces to engage in more specialized, in -depth, continuous discussions focused on the implementation of the commitments already acquired. Chile wishes to particularly underscore the creation of DTG2 on capacity building. For us, this is recognition of the strategic importance of this pillar. to strengthen the implementation of the framework for responsible state behaviour and to be able to respond to the needs and priorities of all states, in particular the priorities and needs of developing states. In this context, we believe that the groups must focus on a practical approach based on the sharing of national experiences, identifying common challenges and extending recommendations that can enrich the discussion of the plenary and implementing effective recommendations for advancing responsible state behaviour. We believe that the mandate for these groups contains informal working methods that were designed to facilitate open and substantive exchanges between member states. And for this reason, we believe that their deliberations must prioritise dialogue and the search for consensus without reproducing formal negotiations or the adoption of decisions by consensus in each step of their work. Furthermore, for us, it’s important for each DTG to have a clear and predictable program of work for the biennium drafted through consultations with the states participating in them that’s sufficiently flexible to be able to respond to the changes in the ICT sector. On DTG 1, given the breadth of its mandate, we believe that its work could benefit from progressive limits on the themes that will be addressed in each meeting that would facilitate substantive results -focused discussions. They could use guiding questions or specific themes prepared by the co -facilitators for each session, and this would involve consultations with states. Chile also believes that the participation of technical experts and other stakeholders could bring significant added value to these discussions, strengthening the exchange of specialized knowledge and practical experience. we therefore align ourselves with Colombia’s approach to use multilingualism to facilitate the broad participation of experts. Given the cross -cutting nature of so many of the current challenges for Chile we should promote adequate coordination between the different DTGs avoiding duplication and focusing on a coherent approach to the implementation of the five pillars of the manual we believe that these groups will be a dynamic space for dialogue, cooperation and strengthening practical knowledge significantly contributing to the success of the global
—
Chair Egriselda López
Thank you very much. I now give the floor to the Democratic Republic of the Congo to be followed by Singapore and Belarus Democratic Republic of the Congo Okay, we go with Singapore then
—
Singapore
So thank you Madam Chair and your team firstly for all the hard work done in preparing for this meeting Allow me at the outset to extend my delegation’s appreciation to you for your steadfast leadership and dedication in moving the discussions forward We welcome your appointment of the co -facilitators and will support their work Thank you Madam Chair, it would be productive for a comprehensive discussion during the DTGs where countries could express a wide range of views on key topics of interest to states expressed during plenary meetings, which could then be reported to the plenary in their totality. This will allow small states to prepare. Having focused discussions will allow small states to better prepare, given limited resources for discussions at the DTGs. In our estimation, this would allow the DTGs to best serve their purpose, which is to add perspectives and enhance the depth of our discussions at the plenary. We encourage the co -facilitators to provide a robust and comprehensive report on the DTGs’ work to the plenary. Recalling Para 12 of Annex 1 and the final report of the OECD, we note that the DTGs would report to their substantive plenary sessions with updates and recommendations. It reads further that the facilitators of the DTGs will provide updates to the global mechanism at its substantive plenary sessions on the work of their respective DTG. We note that the facilitators of the DTGs in consultation with states could also transmit action -oriented draft recommendations for consideration by states. We hope for inclusive discussions where the voices of all states, large and small, are heard and considered. We may not agree on everything, but this should not stop us from listening to each other and making progress on areas we agree on. Madam Chair, we therefore see value in allowing in -depth discussions on selected and focused topics with guiding questions by the Chair on issues of clear relevance and importance to all states, linking to how the Cyber Stability Framework can be strengthened to better help all states meet these issues of concern to all of us. And for these discussions in DTG 1 to be linked for discussions in DTG 2 on capacity building to ensure coherence. To better support these discussions, it may be in our interest to invite non -government experts to contribute. to our understanding of these issues where needed. Madam Chair, we support the co -facilitators raising the key recommendations and issues from DTG discussions in the plenary for further discussions and consensus decisions. Thank you, Madam Chair.
—
Chair Egriselda López
Muchas gracias. Thank you very much. I now give the floor to the delegation of Belarus, followed by the Kingdom of the Netherlands and France, who is the last speaker for this segment.
—
Belarus
Thank you very much, Madam Chair. The delegation of Belarus welcomes the launch of the work of the Global Mechanism and wishes all delegations and states success in their work. We also wish you success, Madam Chair. You’re taking on this work in a very challenging context, which we’re seeing from the very outset of our work, and we hope that the outcome of the work of our Global Mechanism will live up to its name. and can become something tangible and concrete for the whole world. The delegation of Belarus fully endorses the approach of the group of light -minded states set out in the joint statement delivered by the delegation of Nicaragua. I won’t waste time reiterating the argumentation there. I think everyone understands perfectly well what I’m referring to. I will just touch on one point in particular. If we are prepared from the very outset to spend time criticizing states that act in accordance with the rules on some issues, while at the same time we allow ourselves to break the rules on other issues, it will be very difficult to expect an overall positive outcome in that context. General Assembly Resolutions 79, 237, and 80 -16 have already set out the fundamental principle for decision -making by our body, and that is consensus. Deviating from that view, from that consensus principle, in our view is something that is not acceptable, neither for states nor for the chair. In your statement, Madam Chair, we understand that you fully appreciate the consequences of your decision on the appointment of the co -facilitators, and your words about accepting responsibility command our sincere respect. It was indeed a challenging situation. An entire group of states distanced itself from the procedure used to appoint coordinators for the DTGs, and we hope that the current situation will not harm our work on the important area of ensuring information security. We also can’t say that the situation we’re facing is unique. It’s just another testament to the profound crisis of multilateralism that our organization is going through. Despite all this, we express our readiness to work constructively with all states, with all exception, in a spirit of mutual respect, dialogue, and consensus. Thank you.
—
Chair Egriselda López
Thank you very much, and I now give the word to the Kingdom of the Netherlands.
—
Netherlands
Thank you, Madam Chair. And the Kingdom of the Netherlands aligns itself with a statement delivered by the European Union this morning. And please allow me to make some further comments in my national capacity. During the previous Open Ended Working Group, all states in this room worked together to establish a global mechanism capable of delivering practical results. Now, having arrived at this first plenary session of this mechanism, we share a responsibility to ensure it delivers on its promise. For the Kingdom of the Netherlands, this means a smoothly functioning mechanism in which all elements fulfill their role. The plenary should serve as a formal space to take stock of our collective efforts to implement the agreed normative framework, while the DTGs should serve to substantiate the process we collectively seek. The Kingdom of the Netherlands appreciates your efforts to come to a workable solution for the programme of work. We believe it to be important that a careful balance struck in the Open End Working Group’s consensus report remains respected in its entirety. The found compromise reflects this adequately. Allow me to underline two elements next to the multistakeholder participation which we discussed earlier that deserve specific consideration within the mechanisms programme to work to ensure that it can deliver. First, regarding the functionings of the DTGs, the Netherlands’ position on how the DTGs are best set up to address cyber threats from a practical angle aligns well with your vision. Concretely, we believe that structuring the DTGs along the lines of concrete and action -oriented work is a necessary step forward. items, including fictional scenarios pertaining to a specific cyber threat or dilemma will help considerably to make the DDGs more effective. Guiding questions can then prompt states to answer for themselves what responsible state behavior, in line with the normative framework, looks like within a given context, and can help states structure their suggested recommendation on how to implement the normative framework accordingly. Second, regarding the reporting between the DDGs and the plenary sessions, we believe it’s the most effective if co -facilitated report firmly to the plenary on the results of the DDGs. Negotiating language on written recommendations would place a heavy burden on delegation resources and significantly reduce the time available within the DDGs for substantive work. which especially affects smaller delegations. To ensure co -facilitators reflect the spirit of consensus in their verbal reporting to the plenary, the intersessional period could be used to consult with delegations on
—
Chair Egriselda López
Thank you very much. I now give the floor to the Delegation of France.
—
France
Thank you, Madam Chair. Madam Chair, my delegation aligns itself with the statement made by the EU and would like to add a few remarks in its national capacity. Allow me first of all to thank you, Madam Chair, and your team as well as the Secretariat for the work carried out during the intersessional period, including the adoption of an agenda program of work and the appointment of five co -facilitators for the DTGs. France once again reaffirms its support to you, reflecting the importance my country attaches to the success of the global mechanism. In a context of increasing cyber threats. Dear colleagues, during the March session, a majority of states emphasized the need to produce tangible results. Otherwise, the mechanism would not be worthy of the precious diplomatic resources devoted to it. This will require tangible progress in the implementation of the accrued -upon framework for responsible state behavior in cyberspace. However, this goal cannot be achieved if states and their diplomats become inward -looking and work in isolation. The responses to the challenges we face require the participation of all stakeholders, each of whom holds a part of the solution. In that regard, yesterday we watched the final of the World Cup, and we would like to congratulate our Spanish colleagues on their victory, because like in football, cyber diplomacy is a team sport, and non -state stakeholders also have a role to play if we want the mechanism to be relevant. I would even go so far that including them will enable states to retain the central role that they currently play, otherwise they will be marginal. Thank you. As Italy recalled, the time for procedural discussions is now behind us. That is why I would like to present the three main priorities for France for the coming year. We need to make progress in implementing the regulatory framework, building on in -depth work and the expertise of specialists within the two thematic groups. In this regard, Madam Chair, I commend the paper you circulated on this topic. Second, we must continue our work on the application of existing international law to cyberspace. France reaffirms its historic commitment to existing international law and, in particular, to the UN Charter. My delegation regrets that those promoting an alternative treaty are also the first to violate this foundational text. Third, we must continue our efforts to keep pace with the technological advances we are witnessing, and this, of course, includes artificial intelligence. Yet the rhythm of diplomacy cannot always match the speed of technological progress, but this should not prevent us from collectively improving our understanding of challenges and opportunities that AI presents in cyberspace. We must also fully assess the consequences of significant disparities in capabilities between states and how this impacts international security and stability. I thank you.
—
Chair Egriselda López
Thank you very much. We have heard the last delegation that has requested to take the floor under this item. I reiterate my gratitude to all of you on your statements on this topic and your vision on how we can organize the work of the dedicated thematic groups. I will continue working with delegations during the intersessional period during the program. and other organizational aspects of the work of the DTGs. You can rest assured that I will continue dedicating efforts to this matter, and I will organize consultations in coordination with the co -facilitators to that end. Now that we have concluded our organization of work, we may proceed to the substantive discussions under Agenda Item 5, as contained in Document A -AC .304 -2026 -CRP .2. We will begin with the topic Existing and Potential Threats Arising from the Use of Information and Communications Technologies in the Context of International Security. I look forward to a very robust exchange. As previously indicated, there is no pre -established list of speakers. Delegations may request the floor by pressing the button. And if you could please indicate right now all delegations that are interested in making a statement so that together with the Secretariat we can be clear on the amount of time that will be necessary to dedicate to this agenda item. While there is no pre -established time limit for statements, I would be enormously grateful if you could consider delivering a shorter version of your statement and sending in the full text of your statement to eStatements as well as our chair’s text. This will allow us to ensure that all delegations can be heard given that we have limited resources. for the reference of all delegations. Further on, the Secretariat will project a countdown clock on the screen. This will make it easier for you to refer to exercise the necessary discipline in that regard. Thank you for already having indicated your interest. And speaking of already having a rather lengthy list of speakers, I will read the first three, Tonga, Nigeria, and the European Union.
—
Tonga on behalf of the Pacific Islands Forum
Thank you, Chair. I have the honor to deliver this statement on behalf of the members of the Pacific Islands Forum with a presence at the United Nations, namely Australia, the Cook Islands, Fiji, Kiribati, the Federated States of Micronesia, the Republic of the Marshall Islands, Nauru, New Zealand, Palau, Papua New Guinea, Samoa, Somon Islands, Tuvalu, Vanuatu, and my own country, Tonga. Chair, our region continues to be affected by malicious activity in the use of ICTs. Ransomware remains a severe and growing concern for Pacific states. As to threats to critical infrastructure and critical information, I can’t say for sure that the United Nations will be able to respond to these threats. The protection of critical infrastructure and critical information infrastructure is a core priority for the Pacific, and one we would encourage this mechanism, and dedicated the Medic Group 1 in particular, to take up as an early focus topic. Many of our essential services, from health to finance to government administration, now depend on a small number of systems whose disruption would be felt immediately and across the whole of society. The integrity of our undersea cable infrastructure, vital to our economic and social resilience, and in many cases our only link to the global Internet, is increasingly at risk from both natural hazards, man-made disasters, and malicious activity. For the Pacific, this is not an abstract vulnerability, but a lifeline. We also see AI -related cybersecurity threats as another potential area for practical discussion as part of the threat pillar of this work. AI may increase the speed, scale, and accessibility of malicious cyberactivity, including through more convincing social engineering, automated vulnerability discovery, disinformation, and the abuse of AI -enabled tools by criminal and other malicious actors. When it comes to the DTGs, we think discussions should focus on practical outputs. In DTG 1, these could include accessible threat briefings, shared risk typologies, lessons from national and regional incidents, or best practice guidance. We also see value in clearly connecting these discussions with exchanges on cybercapacity building. including in DTG2, so that identifying threats is directly linked to support for mitigation, preparedness, and response. We do not need the global mechanism to simply restate that threats are growing. We need it to help states understand how those threats affect them, what practical steps can reduce risk, and how international cooperation can support national and regional resilience. Thank you, Chair.
—
Chair Egriselda López
Thank you very much to the distinguished representative of Tonga. Thank you for that statement on behalf of the Pacific Island Forum. I now give the floor to the representative of Nigeria, speaking on behalf of the African Commission.
—
Nigeria
Thank you, Chair. Madam Chair, I’m delivering the statement in a national capacity, not representing the African Union. The national statement.
—
Chair Egriselda López
Go ahead. Very well. Go ahead.
—
Nigeria
I’d like to commend your sterling leadership in guiding our discussions towards practical and forward -looking outcomes. you may count on Nigeria’s continued commitment to working constructively with all member states to promote an open, secure, stable, accessible, peaceful, and interpretable ICT environment. The rapid advancement of technology has transformed societies, accelerated economic growth, and expanded opportunities for innovation and sustainable development. Yet, this same technology has also created an increasingly complex cyber threat landscape. Malicious cyber activities are growing in scale, sophistication, and impact, undermining national security, economic stability, public trust, and well -being of individuals. Nigeria continues to confront a broad spectrum of cyber threats, including ransomware, malware, phishing, business email consumption, compromised supply chain attacks, data breaches, attacks on cloud infrastructure, critical information infrastructure and Internet of Things systems. The malicious use of artificial intelligence has further amplified further risks through deepfakes, synthetic media, identity theft, online fraud, disinformation, and other forms of cyber -enabled crime. These threats increasingly target critical sectors such as finance, energy, telecommunications, transportation, healthcare, electoral systems, and other essential public services with significant economic and social consequences. In response, the government of Nigeria has placed cybersecurity at the center of its national security and digital transformation agenda. Through the implementation of the national security policy and strategy, Nigeria has designated certain sectors as national critical information infrastructure and continues to do so. Nigeria continues to strengthen its protection through risk -based and all -off government approaches. The National Cyber Security Coordination Center leads national efforts to enhance cyber resilience by coordinating threat monitoring, incident response, cyber threat intelligence, vulnerability assessment, and digital forensic capabilities, cyber exercises, and capacity building programs. Nigeria has also strengthened its legal and institutional framework through cyber crimes and cyber crimes and prevention acts, wide deepening partnership with the private sector, academia, regional organizations, and international partners to improve preparedness against both existing and emerging threats. Recognizing that cyber threat knows no border, Nigeria remains committed to strengthening national security. Nigeria is committed to strengthening national security. Nigeria is committed to strengthening national security. Nigeria is committed to strengthening national security. Nigeria is committed to strengthening national security. Nigeria is committed to strengthening national security. Nigeria is committed to strengthening national security. Nigeria is committed to strengthening national security. Nigeria is committed to strengthening national security. Nigeria is committed to strengthening national security. Nigeria is committed to strengthening national security. Nigeria is committed to strengthening national security. Nigeria is committed to strengthening national security. Nigeria is committed to strengthening national security. Nigeria is committed to strengthening national security. through information sharing, confidence -building measures, capacity building, and closer collaboration among computer emergency response teams. We believe that timely exchange of technical information, best practices, and strength intelligence is indispensable to building collective cyber resilience. Nigeria also supports scenario -based discussion under the dedicated thematic groups of this global mechanism. Such practical exchanges enhance our collective understanding of evolving threats, strengthening preparedness, and continue to the effective implementation of the UN framework for responsible state behavior in the cyber space. Madam Chair, the effectiveness of this global mechanism will ultimately be measured by its ability to strengthen national capacities, foster practical cooperation, and improve our collective resilience against an evolving cyber threat landscape. Nigeria remains committed to working with all member states and stakeholders to ensure that cyber space remains secure, stable, peaceful, and conducive to sustainable development for the benefit of present and future generations. I thank you.
—
Chair Egriselda López
Thank you very much. I’m now going to read the next few delegations on our list of speakers who have requested the floor. We have the European Union, Portugal, Saudi Arabia, Costa Rica, Mexico, South Africa and Algeria.
—
European Union
Thank you, Chair. Colleagues, it’s my honour to deliver this statement on behalf of the EU and its member states. The candidate countries North Macedonia, Montenegro, Albania, Ukraine, the Republic of Moldova, Bosnia -Herzegovina and Serbia, and the EFTA country Norway, members of the European Economic Area, as well as San Marino, align themselves with this statement. The start of our discussions under the UNGGEs and the Open End Working Groups has always been and should also continue to be under the global mechanism to enhance our common understanding of the cyber threat landscape. Understanding cyber threats and challenges allows us to exchange upon the best practices to tackle them and can help us to identify also the topics that we need to address in more detail as a matter of priority during our work in the dedicated thematic groups. The continued proliferation of new threats in the cyber domain, paired with a more hostile geopolitical context, continue to be of concern to the EU and its member states. To enhance our collective resilience against such threats, discussions like today remain ever more relevant. Developments in the threat landscape are many -fold. Malicious actors continue to target our government services, our critical infrastructure, such as hospitals, financial institutions, and energy grids. We see cyber tools being used as fully integrated instruments of war, even being used against international humanitarian organizations. And we see how new AI models are used to exploit zero -days vulnerabilities nearly instantly upon their discovery. Cyber threats continue to target our societies, economies, and democracies, having a profound effect, causing disruptions in essential services and directly affecting our citizens. Particularly, for instance, the healthcare sector has become a prime target for ransomware actors due to the vast amount of sensitive data it holds and the criticality of its operations. Discussing this issue could be one of the topics to be discussed under the DTGs in December. The EU would, for instance, be keen to share its experiences gained through the implementation of its action plan to protect the healthcare sector from cyber attacks. We could share our experiences on enhancing cyber threat detection, reinforce crisis preparedness, and fostering closer coordination. Furthermore, we are increasingly seeing non -state actors supporting the conduct of malicious cyber activities. Non -state actors that are tolerated by, linked to, or controlled by a state, that function and are leveraged as highly effective and deniable proxies. The tolerance or even the incentivation of such actors increases the threat of attacks against third parties, as well as the risk of uncontrolled spillover effects globally. This evolving threat represents a maturation of the proxy model, where a state keeps its distance in order to claim plausible deniability and thus avoid complying with the obligations arising from its responsibility. And it’s a concerning trend that we should not avoid. It’s not allowed to develop further. Actively using or encouraging proxies is irresponsible behavior contrary to the UN norms of responsible state behavior to not allow your territory to be used for malicious cyber activities and to not target the critical infrastructure of others It is important that states take responsibility and are held to account for their deliberate activities including if they are using proxies to execute them in line with the law of state responsibility Therefore, last week, the EU and its member states alongside the United Kingdom exposed and condemned the misuse by Russia of an ecosystem of Russian actors including a government agency, private sector, hacktivists and criminals to target the EU, its member states and its partners consistently through cyber attacks Its security services are using private companies and individuals to conduct malicious activities for them They contract such companies and individuals to secure technical infrastructure, vulnerability research, malware development, specific hardware and any other relevant enabling activities that allow to target us. The EU has therefore imposed sanctions on those individuals and entities that support Russia and their malicious behavior. And it is for this reason also that Estonia, supported by the EU and all member states, objected to the stakeholder JSC Positive Technologies, who we already knew was supporting Russian cyber operations. Behavior that again contradicts the ambition of this global mechanism. I refer to further details to the letter published by Estonia, giving transparency to the objection provided. The EU member states see a need to ensure international security and stability by raising awareness on the most pertinent issues. The trends of malicious behavior that pose risk to the security and stability of us all should be known. So we are able to uphold responsible state behavior and exchange on the best practices to prevent, mitigate and respond to these type of threats. To this end, we will continue to raise awareness about cyber threats, including through threat advisories such as by our cybersecurity agency, INISA, and our CERT for the institutions, agencies, and bodies, CERT -EU. We will raise attention on particular advanced persistent threats that continue to conduct malicious cyber activities against our businesses, our citizens, and our governments, and likely target also other governments around the world. We will continue also to cooperate with partners to promote an open, free, stable, and secure cyberspace, and also support states in the understanding and their response to cyber threats. The DDGs could support this work, allowing us to formulate concrete recommendations as to how to enhance national resilience and how to enforce responsible state behavior by advancing the implementation of the framework. We look
—
Chair Egriselda López
Thank you very much. For all of the delegations who have requested the floor, if you would like to take the floor on behalf of a group of states, then please approach the Secretariat for the necessary arrangements to be made. I’m informed that Nigeria wishes to take the floor again, this time on behalf of the African group. I therefore give Nigeria the floor right now for that statement, and I’ll also read the list as it stands right now. However, I would be grateful if you could all express your interest to take the floor if you’re going to. And just like I said, please say if you will be speaking on behalf of a group of states for the rules. So Nigeria, please, on behalf of the African group.
—
Nigeria in behalf of the African group
Thank you, Madam Chair. At the onset, the group warmly congratulates you, Madam Chair, on your leadership of the first Bahamian meeting. The group encourages the indicative program of work circulated by the Excellency. The African group commends the nomination of Egypt, Malaysia, Netherlands, and Australia as co -facilitators of the dedicated thematic group, who will serve in their individual expert capacities and under the chairs of our raw guidance. In streets, observance of neutrality, impartiality, and inclusivity, and look forward to their work benefiting all delegations. The group highlights that the mechanism must remain state -led, single -track, and conscious -based, with consensus serving as a driver of progress rather than an obstacle to hate. Madam Chair, African engagement in this first substantive plenary will focus on three mutually reinforcing priorities. One, strengthening implementation through capacity building and operational cooperation. Two, leveraging regional and continental framework as implementation pathways. And three, understanding the involving ICT threat landscape presented by emerging technologies and possible cooperative measures to address them. Let me stress on the first one, strengthening implementation through capacity building and operational cooperation. Capacity building is a strategic cross -cutting priority requiring sustainable need -based support, particularly for developing countries. In this regard, the African group considers DDG2 a key platform for advancing practical cooperation, confidence -building measures, and capacity building. DDG2 should be allocated adequate time that will effectively contribute to concrete and measurable outcomes that will include early operationalization of the global ICT security cooperation and capacity building portal. The point of contact directory. Sabah SSI Stronger National sets a United Nations Voluntary Fund for ICT Security Capacity Building designed to ensure efficiency, transparency, and equitable access and a United Nations ICT Security Fellowship Program. Encouraging voluntary reporting on the implementation of voluntary norm -binding norms of responsible state behavior in the use of ICT, recognizing that it is the prerogative of member states to structure their implementation efforts in accordance with national policy and capacities. Strengthening regional and continental framework as implementation pathways. The group considers regional and continental framework to be essential foundation for translating global commitment. Into practical implementation. In this regard, Africa’s existing instruments, including the Malabo Convention and the Common African Position on the Application of International Law in Cyberspace, provide solid basis for the continent’s contribution to the global framework. To this end, the African Union is at an advanced stage of validating the AU guidelines for the implementation of norms of responsible state behavior in cyberspace and the Declaration on Peace and Security in Cyberspace. These instruments will provide practical guidance to member states on implementing the UN Framework for Responsible State Behavior while reflecting African peace and security priorities. The group supports the continued use and further development of voluntary checklists of practical action as a practical tool to assist member states in implementing their agreed norms while recognizing that national approaches should remain flexible and adapted to national circumstances and priorities. On the understanding the involving ICT trade landscape presented by emerging technologies and possible cooperative measures to address them, the group remained deeply concerned by the growing scale and sophistication of cyber threat targeting critical infrastructure and critical information infrastructure. These include ransomware attack, vulnerability in supply chains, threat to undersea cables and electoral processes, the spread of disinformation and misinformation, and the malicious use of artificial intelligence, all of which have a disproportionate, disproportionate, disproportionate impact on developing countries. On this, DTJ1 should advance focused discussions on critical infrastructural protection, evolving threat, responsible approaches to emerging technologies, norm implementation, and practical cooperation among member states. The African group reaffirmed that international law, including the Charter of the United Nations, applies fully to the use of ICT and remains fundamental to maintaining international peace, security, and stability. Consistent with the Common African Position, the African group underscores the principle of sovereignty, due diligence, and non -intervention, as well as the applicability of international norms. The group recognizes the valuable contribution of relevant stakeholders, including civil society, academia, and the private sector, whose expertise complements the intergovernmental and state -led nature of the mechanism. We encourage the Chair to continue consultation toward a pragmatic resolution of the outstanding participation issues. For the African group, the global mechanism must become a platform that delivers practical outcomes, strengthen global cooperation, support implementation, and enable all member states to safely, securely, and meaningfully benefit from digital technologies. The group, therefore, looks forward to the intersectional consultation and the first DTG meeting in December
—
Chair Egriselda López
Muchas gracias. Thank you very much. I now give the floor to Portugal, followed by Saudi Arabia.
—
Portugal
Thank you very much. Madam Chair, we align with the intervention of the European Union but would like to complement it with an overview of our national threat landscape. Portugal continues to observe a marked intensification and diversification of malicious cyber activity directed at its national cyberspace. These activities span the full spectrum of threat actors from sophisticated state and state -sponsored operations to increasingly professionalized non -state criminal enterprises and loosely organized collectives of younger digitally native offenders. Critical infrastructure operators, namely in the energy, transport, financial, health and telecommunication sectors as well as public administration networks and operations, other sensitive systems have all registered a sustained increase in reconnaissance, intrusion attempts and disruptive or destructive incidents. This convergence of threat vectors represents a growing risk, not only to the confidentiality, integrity and availability of national networks, but by extension to the continuity of essential services and the trust of citizens in the digital domain. Portugal would like to take this opportunity to note with concern the persistence and evolution of malicious cyberactivity attributable to state actors and to networks operating under their direction, sponsorship or tolerance. This activity is conducted through an ecosystem of proxy actors, criminal affiliates and self -styled activist collectives that operate with the questions, encouragement or resistance. This activity is conducted through an ecosystem of proxy actors, criminal affiliates and self -styled activists that operate with the questions, encouragement or resistance. This activity is conducted through an ecosystem of proxy actors, criminal affiliates and self -styled activists that operate with the questions, encouragement or resistance. This activity is conducted through an ecosystem of proxy actors, criminal affiliates and self -styled activists that operate with the questions, encouragement or resistance. This activity is conducted through an ecosystem of proxy actors, criminal affiliates and self -styled activists that operate with the questions, encouragement or resistance. This activity is conducted through an ecosystem of proxy actors, criminal affiliates and self -styled activists that operate with the questions, encouragement or resistance. This activity is conducted through an ecosystem of proxy actors, criminal affiliates and self -styled activists that operate with the questions, encouragement or resistance. conducted by other actors oriented principally towards the large -scale and systematic collection of private and commercially sensitive data, including personal data of citizens, intellectual property and strategic technological know -how. This activity is frequently associated with efforts to advance geopolitical and economical objectives, including the shaping of technical standards, supply chains and digital dependencies in a manner favorable to the interests of the sponsoring state. Such conduct raises serious concerns about the compliance to the norms of responsible state behavior in cyberspace repeatedly endorsed by the UN General Assembly, in particular those relating to the protection of critical infrastructure and the due regard owed to the sovereignty and the security of the infrastructure. and economic interests of other states. A further pattern of concern involves the use by certain states of offensive and intrusive cyber capabilities to monitor, harass, and repress dissidents and diaspora communities present within or connected to Portuguese territory. Portugal considers such practices to be fundamentally incompatible with respect for human rights and fundamental freedoms in the digital environment and calls upon all states to refrain from the extraterritorial use of cyber tools for purposes of transnational repression. Beyond the state dimension, Portugal’s national cyberspace, together with that of numerous partner states, is increasingly affected by two factors. Distinct categories of non -state threat actors. The first category comprises organized criminal networks operating from jurisdictions that function, whether by design or by omission. as areas of relative impunity. These networks have professionalized their operations to an industrial scale, running ransomware -as -a -service enterprises and large -scale scam and fraud hubs that target victims across Portugal and across the wider international community, including through so -called pig butchering and investment fraud schemes, business email compromise and extortion campaigns directed at hospitals, municipalities and small and medium enterprises. The transnational and highly monetized nature of this criminal economy demands reinforced international judicial and law enforcement cooperation, robust mutual legal assistance mechanisms and sustained pressure on jurisdictions that host or tolerate such infrastructure. The second category. The third category of growing concern to my government consists of loosely structured transnational collectives composed predominantly of minors and young adults whose activity blurs the line between the digital and physical domains. These groups engage in intrusion, extortion, swatting, and coordinated harassment campaigns, often motivated less by financial gain than by the pursuit of online notoriety and media exposure. Their operations have, on occasion, escalated into real -world harm, including through the incitement of physical violence or intimidation against targeted individuals. Portugal considers that this phenomenon requires a response that combines criminal justice measures with preventive, educational and safeguarding approaches in view of the age profile of many of those involved. Taken together, the cumulative effect of these state and non-state threats is a heightened risk of service disruption, data compromise and erosion of public trust in digital systems that underpin daily life and economic activity. Portugal underscores that the protection of critical infrastructure as recognized in the norms of responsible state behavior is not merely a national imperative, but a shared international interest given the interconnected and borderless nature of cyberspace. In light of the foregoing, Portugal reaffirms its full commitment to the framework of responsible state behavior in cyberspace, including the applicability of international law, the voluntary norms endorsed by the General Assembly, and the confidence-building measures developed within these and other relevant fora. Thank you, Madam Chair.
—
Chair Egriselda López
Thank you very much. I give the floor now to Saudi Arabia followed by Costa Rica and Mexico.
—
Saudi Arabia
We are confident that your chairmanship will steer our work towards success and further cooperation and consensus amongst member states. We wish to also congratulate the co-facilitators. of the United States of America, President Trump, and the President of the United States of America, President Trump, and the President of the United States of America, President Trump, and the President of the United States of America, President Trump, and the President of the United States of America, President Trump, and the President of the United States of America, President Trump, and the President of the United States of America, President Trump, and the President of the United States of America, President Trump, and the President of the United States of America, President Trump, and the President of the United States of America, President Trump, and the President of the United States of America, President Trump, and the President of the United States of America, President Trump, and the President of the United States of America, President Trump, and the President of the United States of America, President Trump, and the President of the United States of America, President Trump, and the President of the United States of America, President Trump, and the President of the United States of America, President Trump, and the President Chair, while cybersecurity remains one of the most important pillars of the maintenance of international peace and security, our world today faces a mounting challenge, namely a lack of experts in cybersecurity. This demonstrates the need for capacity building at all levels. The Kingdom of Saudi Arabia last October, during the Global Cybersecurity Forum in 2025, launched the Global Initiative for Capacity Building in Cyberspace with the United Nations and its specialized agencies in order to support international efforts for capacity building. and ensuring cyber readiness at the global level. His Excellency, Secretary General of the United Nations, Antonio Guterres, in his statement during the GCF in 2020, 2025, and upon the launching of the initiative, reiterated the importance of collective action to ensure that cyberspace remains a global public good through further investments in human capacities, upskilling, and inclusivity. The Kingdom of Saudi Arabia, in order to implement this initiative, launched the Capacity Building Program for representatives of member states participating in the global mechanism in partnership between the GCF and the UNODA. The launching of this initiative demonstrated the commitment of the Kingdom to promoting international cooperation in cybersecurity and ensuring capacity building to contribute to a safe and secure cyberspace, one that enables growth and prosperity for all peoples of the world. This program includes a full cycle that ensures capacity building, one that was designed to support the representatives of member states during their participation in the global mechanism and before this participation as an important platform at the United Nations to strengthen collaboration on ICT in the context of international security. And this program was a continuation of a series of capacity building initiatives launched by the GCF to contribute to resilience and stability in the cyber space. The various programs launched by the GCF has benefited more or the experts or the cybersecurity experts of more than 80 states. Madam Chair. As we kick -start the work of the first substantive session of the global mechanism, we reiterate our readiness to cooperate with member states to find an inclusive mechanism, one that ensures a consensus and one that furthers international cooperation for a more resilient cyberspace for the benefit of all of humanity. I thank you, Madam Chair.
—
Chair Egriselda López
Thank you. I now give the floor to Costa Rica.
—
Costa Rica
Madam Chair, as this is the first time we take the floor, Costa Rica would like to congratulate you on your election, and we commend the intense, committed work that you and your team have carried out in preparing and convening this first substantive meeting of the global mechanism on ICTs in the context of international security. This new space will allow us to, build on the knowledge accumulated in previous working groups, and to build on the knowledge accumulated in previous working groups, and to build on the knowledge accumulated in previous working groups, to respond with greater clarity, inclusivity, and practicality to the evolving nature of threats in cyberspace. For Costa Rica, cyber threats are not abstract. Our own experience with the 2022 cyber attacks demonstrated that ransomware and other malicious operations can impact state functions, public services, institutional continuity, and public trust. Therefore, this mechanism must contribute to strengthening the resilience of states and their capacity to prevent, respond to, and recover from incidents that directly affect their populations. Secondly, the protection of critical infrastructure and essential services, as defined by each state, must be central to our discussions. Assets such as hospitals, financial, energy, work, and social security must be important. Water, telecommunications, transport, and education systems, emergency services, State digital platforms and public databases are indispensable components of human well -being and the democratic functioning of our societies. Third, threat analysis must always incorporate a human dimension and consider the differentiated nature of harm caused. Women and girls, the elderly, persons with disabilities, migrants and refugees, journalists, human rights defenders and other groups may face specific risks such as undue surveillance, digital harassment, fraud, information manipulation or exclusion from digital services. Finally, Costa Rica considers it important to address emerging and systemic threats such as attacks on ICT supply chains, the growing use of artificial intelligence in criminal activities, and the actions of transnational criminal actors. These challenges require international cooperation responsible disclosure regarding capabilities and vulnerabilities and the exchange of information and technical assistance to effectively build capacity. Madam Chair, Costa Rica hopes that this global mechanism will be an inclusive, technical, and action -oriented forum. The identification of threats must translate into practical cooperation, greater resilience, and the effective protection of people, essential services, and through that public trust. Thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Mexico, followed by South Africa, Algeria, Turkey, and Italy.
—
Mexico
Thank you very much, Chair. Mexico recognizes that the threat landscape is evolving rapidly and identifies applications. As a priority, ransomware directed against critical infrastructure and essential services, risks to ICT supply chain change, chains and the activity of organized criminal groups that employ increasingly sophisticated techniques, tactics, and methods. When it comes to artificial intelligence, the concerns are not limited to its malicious use. They include risks associated with the lifecycle of AI systems themselves. These include model security, data integrity, the IAEA supply chain, and incident response capacities, insofar as artificial intelligence is becoming a cross -cutting layer on which critical infrastructure depends. Mexico also underscores the cybernetic dimension of major international events. The recently concluded 2026 FIFA World Cup, is an example of the importance of close coordination between Mexico, Canada, and the United States. to protect critical infrastructure during large -scale events. That experience constitutes a valuable experience of sub -regional cooperation, exchange of information, and joint preparation that could contribute to strengthening resilience to cross -border threats. Mexico underscores the human and social impact of cyber incidents, particularly those directed against critical infrastructure and critical information infrastructure on which essential services depend. Attacks on hospitals and health care services illustrate how cybernetic operations go beyond merely technical damage and directly affect people. This reinforces the relevance of evaluating threats from a civilian protection perspective. We must also recognize the gender dimensions of this issue. digital violence and its various forms disproportionately affect women and girls and can limit their participation in public, economic, and social life. These consequences must be reflected both in the analysis of threats as well as in public policy responses through information and desegregated data that will enable the design of more effective responses. Finally, Mexico favors linking the identification of threats to a comprehensive and cross -cutting approach that takes into account the five pillars of responsible behavior. Thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to South Africa, followed by Algeria and Turkey.
—
South Africa
Chairperson, South Africa aligns with the statement delivered by the United Nations and delivered by Nigeria on behalf of the African group. South Africa would like to join others. in expressing its appreciation to you, your team, and the Secretariat for the preparations leading up to the convening of this inaugural substantive session of the global mechanism. You have our full support and commitment to continuing the achievement of consensus in moving this process forward. Regarding the participation of other stakeholders, South Africa supports the proposal for the Chair to maintain engagement and urge for the speedy resolution of this issue to enable the global mechanism to focus on its core mandate given the limited time available. With only four substantive plenary sessions and dedicated thematic groups meetings before the review conference, we must swiftly and smoothly transition into substantive. substantive discussions. The global mechanism with a universal membership and operating on the basis of consensus, is well equipped to analyze the evolving cyber threat landscape and formulate cooperative measures to address it. We underscore the importance of the global mechanism and the DTGs building upon the achievements of the previous two OEWGs and GGEs in order to advance towards the establishment of an open, safe, secure, stable, accessible, peaceful, and interoperable ICT environment. We must be concerned about the significant increase in recent years in the frequency and devastating impact of cyber attacks on critical infrastructure and critical information infrastructure. Technological innovations, particularly in AI, have dramatically increased the scale, frequency, and sophistication of cyber attacks, posing a significant threat to national development agendas. We are confronted with a plethora of AI -driven threats, ransomware, phishing, distributed denial -of -service attacks, the theft of personal credentials, extortion, misinformation, disinformation, and malinformation. These incidents are eroding trust and confidence in the use of ICTs. Chair, in this regard, my delegation proposes the inclusion of these threats in the priorities for the meeting of GTG1 in December, in order to collectively identify collaborative measures to address them. As emerging technologies amplify systems exposure to exploits, and to address the inevitable vulnerabilities of cyber attacks, Their secure deployment is crucial to prevent further digital divides and ensure that AI -driven growth benefits everyone. The same AI technologies that empower attackers also offer defenders powerful tools to strengthen their cybersecurity defense strategies. It will be equally important to identify practical ways to address these challenges through capacity building. This, in our view, should be the DTG’s preoccupation. My delegation believes that this new process presents an opportunity to consolidate our efforts building on the previous processes to achieve significant and meaningful process in the years ahead. I thank you, Chair.
—
Chair Egriselda López
Muchisimas gracias. Thank you very much. I wish to indicate the following. We have… one hour and 15 minutes remaining in the meeting today. And we currently have 40 delegations that have requested the floor just under this agenda item. This means that we will certainly not conclude the list of speakers today. And this will also delay us when it comes to the consideration of other agenda items. And it is important that you recall that we need to finalize by 6 p .m. today, but also throughout the whole plenary session needs to be finished by 1 p .m. on Friday. You’re all aware of the limitations the UN is currently under right now. Therefore… I appeal to you for your cooperation so that we can, if you could possibly reduce your statements and deliver them more succinctly. And as I also indicated at the beginning, there are various tools that you all have available that will allow you to share your positions in greater detail. Therefore, please, from the very beginning, do take this into consideration so that all of those who have requested the floor will be able to make their statements. Now, as you can see, we have the clock on the screen. Again, it is indicative. It can help you because… We know sometimes that when the microphone is blinking, it’s difficult to see it when one is speaking, and that is the entire purpose of having the clock on the screen. Thank you very much. And I now give the floor to Algeria, followed by Turkey, Italy, Kazakhstan,
—
Algeria
Thank you, Madam Chair. Algeria welcomes the convening of the first substantive session of the Global Mechanism on ICT Security and congratulates you on your election as chair of its first biennial cycle. The establishment of the Global Mechanism represents a significant achievement for multilateral diplomacy. It provides an inclusive, action -oriented, and permanent forum for dialogue and cooperation on the security, often in the use of ICTs under United Nations auspices. At a time when this field has become central to international cooperation, international peace, and security on sustainable development. Madam Chair, cyber threats are not abstract risks They affect public institutions, essential services, social cohesion and the trust among states upon which peaceful international relations depend Building on the cumulative and evolving framework developed through more than three decades of UN discussions and reaffirmed in the final report of the OEWG Algeria underlines that existing and emerging threats in cyberspace continue to intensify and evolve in scale, sophistication and impact Against this backdrop, I would like to highlight the following points First, Algeria stresses the attacks against critical infrastructure and critical information infrastructure ransomware, supply chain compromises ICT -enabled disinformation and propaganda campaigns and the malicious use of intrusion campaigns Disappabilities remain among the most pressing threats Within this broader threat landscape, the proliferation and misuse of spyware and intrusive cyber capabilities represent a particularly serious concern. Recent investigations by credible international media and human rights organizations have provided evidence that such tools have been systematically abused to target state officials, diplomats, journalists, lawyers, human rights defenders, and civil society actors. Such unlawful conduct constitutes a serious violation of fundamental human rights, international law, state sovereignty, diplomatic inviolability, and the well -established principle of non -interference in internal affairs and good neighborliness, with direct consequences for regional stability and international peace and security. Algeria, therefore, stresses that its threat should be explicitly included in the reports of the global mechanism. A combined biosecurity and international peace are the key factors that should be considered. This is provided by a clear recommendation for stronger international norms and effective accountability mechanisms. Second, the current cyber threat landscape is being amplified by the rapid evolution of emerging technologies particularly artificial intelligence AI offers significant opportunities but also serious risk and is becoming increasingly connected to cyber security It can strengthen cyber defense by improving detection, threat analysis and incident response However, without appropriate safeguards, it can also be misused to identify vulnerabilities automate attacks, enhance malware, scale disinformation campaigns and conduct cyber operations beyond existing defensive capacities Third, this evolution raises particular concerns for developing countries If advanced AI enables cyber capabilities remain concentrated in the hands of few actors while many countries which lack the infrastructure, expertise and access to secure technologies needed to detect, defend against or respond to malicious ICT activities, the digital divide risk becoming a security divide, thereby undermining sovereignty, resilience and collective stability. In conclusion, Madam Chair, as emerging technologies continue to develop at a pace that exceeds the capacity of our existing governance framework to adapt and respond, the challenge before us is whether we can collectively, within this global mechanism, keep our discussion focused on the most pressing issues and translate them into concrete and coordinated actions that strengthen international cooperation, preserve the sovereignty of states and protect regional stability and international peace and security. Thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Turkey.
—
Turkey
Thank you, Madam Chair. Turkey wishes to underline the growing threat posed to critical infrastructure and critical information infrastructure, including energy, finance, health, transport, telecommunications and undersea cable systems, as well as the increasing frequency of ransomware attacks, supply chain compromises, and attacks targeting national computer emergency response teams. Türkiye wishes to highlight the evolving security implications of emerging technologies, including advanced AI models, quantum computing, and proliferation of insecure connected devices. These developments have the potential to significantly alter the cyber threat landscape and may warrant consideration as standing items under this pillar. In particular, the deployment of advanced general -purpose AI models raises specific concerns from an international security perspective. The capabilities of such models in areas such as code generation, vulnerability discovery, automation, and large -scale social engineering may increase the speed, scale, sophistication, and effectiveness of malicious cyber operations. A key concern is the widespread availability of such capabilities may lower the barrier for entry for less resourced actors, including criminal networks and terrorist organizations. Capabilities that were previously accessible to only a limited number of highly capable actors may now become increasingly available, creating risks that extend beyond individual incidents and potentially affecting international peace and security. In this context, within the mechanism’s mandate, and while avoiding the duplication of existing UN processes, Turkey proposes to the mechanism to consider exploring the following approaches. First, share risk assessments concerning AI -enabled ICT threats. Second, volunteer norms and safeguards for responsible development and deployment of high -capacity AI models. Third, responsible access considerations. Fourth, the most sensitive capabilities. Fourth, structured information sharing on AI -enabled incidents And fifth, enhanced coherence with international efforts on AI governance Türkiye believes that any such measures should remain balanced, technology neutral and designed in a manner that preserves the legitimate and beneficial civilian uses of emerging technologies while addressing potential
—
Chair Egriselda López
Thank you very much and I’ll give the floor to Italy Italy fully aligns itself with the statement delivered by the European Union and wishes to add a few slightly shorter, as per your request, considerations from its national perspective also benefiting from contributions of the four stakeholders objected by the Russian Federation Italy follows with great attention and concern and I thank you very much and I’ll give the floor to Italy
—
Italy
The developments in cyberspace as regards existing and potential threats in fact, not only do we witness an increasing number and sophistication of malicious cyber activities, but the latter are also part of broader hybrid campaigns aimed at destabilizing our national political, economic, and social life. Indeed, the cyber threat landscape continues to evolve in both scale and complexity, with malicious cyber activities increasingly targeting critical infrastructure, public services, democratic institutions, and digital supply chains. Italy has seen last year an increase of cyber events by 38%, and incidents targeting the public sector by 68%. And in the public sector, 75 % of attacks were directed towards local and central administrations. Ransomware remains one of the most impactful cyber threats, and attacks by ransomware actors mainly affect small manufacturing companies with limited capacity, often causing prolonged service disruption. At the same time, rapid advances in artificial intelligence are reshaping the threat environment. In the past, the threat environment has been a threat to the public sector, AI is taking cybersecurity risks and threats to the next levels. AI -powered attacks are speeding up. Defense mechanisms struggle to keep up. AI discovers vulnerabilities and generates exploits at a pace that is incompatible with traditional cyber response. We need a new way of working, and also we need a new way of co -working vis -à -vis these threats. In parallel, the prospective impact of quantum computing also requires governments and organizations to begin a timely transition towards post -quantum cryptography to safeguard long -term confidentiality and integrity of sensitive information. Addressing these evolving challenges requires stronger cyber resilience, secure by design approaches, but also enhanced cooperation among governments, industry, academia, and the experts community. In fact, cyber incidents can simultaneously affect government bodies, critical infrastructure, private companies. No single affected party has complete visibility of the threat landscape, and more so with artificial intelligence. Hence, cyber resilience depends less on the strength of individual organizations and more on the ability of institutions and companies to act as a coordinated ecosystem. We have practices that we can share from Italy, including our experience coordinating with various national administrations through our cybersecurity cell, our public -private partnership model, which allows us to pool information and resources to contrast malicious cyber activities to the benefit of shielding not only critical infrastructure, but also SMEs who represent the backbone of our national ecosystem. And also, we are updating our national cybersecurity strategy so that our country can be equipped even better from an organizational and technical point of view, leveraging a whole -society approach to prepare society for future challenges. We’ll be happy to share that. And to conclude, Italy would like to highlight the importance of concrete exchanges we can have in DTG1 to deepen the understanding of specific threats, benefiting from the contribution of technical experts and other stakeholders. I would like to mention in particular the topics of ransomware, the nexus between AI and cybersecurity, and the role of non -state actors in Mauritius’ cyber activities, and cyber -resilient digital transformation as possible topics for discussion. We stand ready to provide contribution through governmental bodies as well as through relevant stakeholders. Thanks a lot.
—
Chair Egriselda López
Muchísimas gracias. Thank you very much. I now give the floor to the delegation of Kazakhstan. Followed by Colombia. Estonia and Bosnia and Herzegovina.
—
Kazakhstan
Thank you, Chair, for giving the floor. At the outset, Kazakhstan would like to thank you, your team, and the Secretariat for the dedicated efforts and work throughout the process. We advocate maintaining the consensual nature of the global mechanism’s work and convince that its activities should remain action -oriented and address all five main pillars of the OEWG. As noted earlier, the implementation of the global agenda must take into account the needs and priorities of different regions. For Central Asia and as a landlocked country, the key areas are strengthening the national and regional capacities, developing human resources, as well as increasing the resilience of critical infrastructure. Today, states face a growing range of cyber threats, which include data breaches, ransomware, DDoS attacks, online fraud. Misinformation, risks associated with the rapid development of AI, supply chain threats, and the shortage of qualified cyber professionals. As technologies evolve and threats become more complex, legal and policy frameworks must keep pace, including the cloud technologies. They are intended not to limit innovation, but to ensure that technological progress contributes to sustainable development. On that, following the outcomes of the national referendum marched this year, Kazakhstan’s new constitution highlights the right to protection of personal data, including in the digital environment. In addition, the digital code and the law on AI adopted, and the law on cybersecurity has been updated within the principles of the privacy by design and the security by default. The low level of cyber hygiene remains one of the main factors contributing to the occurrence of the cyber incidents. In this regard, Kazakhstan has amended the labor code, establishing the responsibilities of employers to promote the cyber culture and ensure the compliance with the cybersecurity requirements within organizations. As cyber threats continue to evolve, our focus should extend beyond responding to threats. Greater emphasis should be placed on the prevention and the capacity building as essential pillars of effective international cooperation and mutual trust, including the work of the Global POC Directory. On that, Kazakhstan will continue to work constructively with all member states and stakeholders to promote an open, secure, stable, accessible, and peaceful ICT environment. I thank you.
—
Chair Egriselda López
Thank you very much for your statements and for being so brief. Thank you. I now give the floor to the Delegate of Colombia.
—
Colombia
Madam Chair, like we said during the organizational meeting, Colombia identifies two priority issues that stand out in the pillar under existing and potential threats, and that we believe must be addressed swiftly. First of all, for my delegation, it’s important to delve into understanding of the risks that new and emerging technologies such as AI pose to the safe and responsible use of ICTs. While it is important to recognize the potential of these technologies in strengthening society, it is also important to recognize the potential of the future reducing the impact of cyber incidents. It is also necessary to recognise the risks that derive from their undue use. We can cite automatised phishing, the creation and diffusion of artificial content, disinformation campaigns, scanning for critical vulnerabilities and other modalities of malicious use that can undermine security and trust in the digital environment. In this regard, having said that, in addition to considering the undue use of this type of technologies, it’s relevant to think about the risks associated with attacks against artificial intelligence systems themselves, as well as the adoption of effective measures for their protection. Secondly, Columbia wishes to underscore as a priority ransomware attacks, levied against critical infrastructure and state institutions. which compromise the continuity and stability of essential services. This threat is aggravated by the use of artificial intelligence to engage in more sophisticated, precise campaigns that are more difficult to detect, which makes it essential to strengthen cybersecurity capacities and to strengthen the resilience of critical infrastructure. Madam Chair, against this backdrop, trust is a fundamental asset for the digital environment in an increasingly complex geopolitical environment. We have a responsibility to build bridges that enable us to make progress in understanding these shared challenges and to build innovative solutions to respond to these pressing threats. Colombia launches an appeal to make the most of this space and use it as a space of focus in the thematic, on strengthening interceptual dialogue and identifying practical tools that will enable us to move towards a safer, more resilient and more reliable cyberspace. Thank you very much.
—
Chair Egriselda López
thank you very much. I now give the floor to Estonia.
—
Estonia
Thank you, Chair. Estonia aligns itself with the statement by the European Union, and that’s the following in its national capacity. The global mechanism occupies a distinct place within the United Nations architecture. It is the only universal forum entrusted with examining cyber threats that affect international peace and security. Our responsibility is therefore not simply to catalog malicious cyber activity, but to focus on those incidents and trends whose scale, sophistication, or consequences have the potential to destabilize states, heighten tensions, and increase the risk of conflict. This shared understanding of the threat environment is the foundation upon which all other aspects of our work must rest. While we have made important progress, the cyber threat landscape continues to evolve at an unprecedented pace. Artificial intelligence is fundamentally reshaping the cybersecurity landscape. The global mechanism is, of course, not intended to serve as a forum for negotiating international rules on AI governance. These important discussions are taking place in other dedicated processes. That said, the global mechanism should not ignore the impact of AI on the cyber threat landscape, but address it where it clearly falls within our mandate. Under the first pillar of existing and emerging ICT threats, the dedicated thematic group should take into account that AI is increasing the scale, speed, and sophistication of malicious cyber activity. From AI -enabled phishing, ransomware, and virtualization. The global mechanism is, of course, not intended to serve as a forum for negotiating international rules on AI governance. The global mechanism should not ignore the impact of AI on the cyber threat landscape. From AI -enabled phishing, ransomware, and virtualization. The global mechanism should not ignore the impact of AI on the cyber threat landscape. AI systems through manipulation or poisoning. As AI becomes increasingly integrated into government services, financial systems, and critical infrastructure, it also expands that tech surface, creating new vulnerabilities and attractive targets for malicious cyber activity. These developments have direct implications for the resilience of critical infrastructure and the implementation of the frameworks for responsible state behavior in cyberspace. On Wednesday, Estonia and Latvia, together with Oxford Information Labs, will host a technical briefing titled Frontier AI and the Cyber Threat Landscape. The briefing will provide practical insight into how frontier AI is transforming cyber threats and what governments should understand as we design a future mechanism capable of responding to rapidly evolving technological developments. We invite all delegations to participate. A trend deserving of particular attention is the growing use of proxy actors, as also highlighted by their Open Union. Such proxy models undermine international security and stability, are inconsistent with the agreed UN norms that states should not knowingly allow their territory or infrastructure to be used for internationally wrongful cyber activities, or target the critical infrastructure of other states. And may give rise to the international legal responsibility of the states engaging the proxy actors. Ensuring states’ fair responsibility for using proxies to engage in malicious cyber activity is an important element of strengthening responsible behavior in cyberspace. Finally, integrating legal considerations and capacity building across the dedicated thematic groups is essential to facilitate practical discussions. on how specific rules and principles of international law apply while identifying concrete capacity building gaps and ensuring that all states are better equipped to implement the agreed framework for responsible state behavior in cyberspace. Thank you.
—
Chair Egriselda López
Muchísimas gracias. Thank you very much. I now give the floor to the delegation of Bosnia -Herzegovina who will be followed by Vanuatu, Botswana, and Cuba.
—
Bosnia -Herzegovina
Madam Chair, while we align ourselves with the statements of the European Union, I would like to add some remarks in my national capacity. Since this is the first time I am taking the floor, allow me to congratulate you, Ambassador Lopez, on your election as the first chair of the global mechanism. I would also like to thank you and your team, as well as the Secretariat, for the efforts invested in preparing this plenary session. It is a great pleasure to participate in the work of the European Union and the European Union. Thank you. On that note, I would like to thank the government of the Federal Republic of Germany for supporting my participation in this session through the Project Partnership for Strengthening Cybersecurity. I also wish to thank GIZ for its facilitation. Madam Chair, information and communication technologies continue to transform our societies and economies, bringing significant opportunities but also increasing our exposure to cyber threats. At the same time, new technologies are enhancing resilience while creating new risks when misused for malicious purposes. In this regard, we wish to emphasize two points. First, we are deeply concerned by the growing number of cyber activities targeting democratic institutions and electoral processes. We are increasingly alarmed about the impact of such activities on the states with limited capacities, including those in post -war countries. Second, we are deeply concerned about the impact of such activities on the states with limited capacities, which may be especially vulnerable to these threats. Second, we also remain concerned by the way ICTs are being misused by both state and non -state actors, particularly when such activities begin to affect supply chains, critical infrastructure, and the delivery of essential services. Addressing these challenges requires a collective response based on greater awareness, timely information sharing, and cooperation to maintain stability and security in cyberspace. From our perspective, it is essential that mechanisms support all states, regardless of their size or level of capacity, so that they engage meaningfully and benefit from these discussions. Finally, Madam Chair, Bosnia and Herzegovina remains committed to contributing within its capacities and fully support the success of this important process. I thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to Vanuatu.
—
Vanuatu
Madam Chair, Vanuatu aligns itself with the statement delivered by Tonga on behalf of the Pacific Islands Forum members and speaks now on its national capacity. Vanuatu is consistently assessed as the most disaster -exposed nation on Earth. In 2023, the twin cyclones, Judy and Kevin, struck us within 72 hours of each other. In December 2024, an earthquake devastated Port Vila. Each time, alongside homes and roads, we lost the digital systems on which modern crisis response depends. At the very hour, we depended on them most. In the context in which Vanuatu reached the threat landscape, for us, cyber risk and climate risk are not parallel concerns. but a single compounding one. A malicious ICT incident during a disaster window would not be an inconvenience. It would cost lives. When this mechanism catalogs threats to critical infrastructure, Vanuatu asks it to recognize that early warning systems, emergency communications, and disaster coordination platforms belong at the top of that catalog. At the same time, the threats themselves are changing shape. When we addressed the organizational session in March, we highlighted the shift from ransomware towards AI -enabled risks. Four months on, the trajectory has only steepened. Artificial intelligence is lowering the cost of convincing deception, and in a country where fabricated evacuation notice or a falsified weather warning could send a threat to the country, and communities towards danger rather than away from it, synthetic content is a safety -of -life issue. not merely an information one. Madam Chair, Fanuatu’s response to this environment is ambition, not retreat. We are pursuing one of the most forward -leaning digital agendas among small island developing states, building towards cloud -based continuity of government so that our services and records survive even when our buildings do not, expanding secure digital public services and assessing emerging technologies deliberately so that we adopt them on our terms. But ambition, sorry, we do this because for a country like ours, the riskiest technology strategy is to have none at all. But ambition of this kind is only sustainable in a digital ecosystem that is trustworthy, and ours is both fragile and exposed. Throughout the OEWG, Vanuatu and our Pacific partners argued that the resilience of digitalizing states depends on the restraint and responsibility of all states. We carry that argument into this mechanism, and we ask that its thread discussions keep the connection between technological opportunity and state behavior firmly in view. I thank you, Chair.
—
Chair Egriselda López
Thank you very much for your statement. I now give the floor to Botswana.
—
Botswana
Thank you, Chair. Chair, the Republic of Botswana congratulates you on convening the first substantive session of this global mechanism. We are confident that under your leadership, this body will successfully transition our shared commitments from normative consensus into actionable global resilience, and we remain ready to assist you in the future. Thank you. The Republic of Botswana aligns itself with the statement of the African Group as delivered by the Federal Republic of Nigeria. Chair Botswana knows the rapid evolution of the cyber threat landscape As Botswana drives its national agenda towards a digitalized and knowledge -based economy we recognize that international security in the cyber space is not solely focused on protecting just the physical borders but on preserving human dignity, protecting citizen data and ensuring that emerging technologies do not become tools of oppression or destabilization but of drivers of economies Chair, transitioning into a fully interconnected society presents a huge benefit for economic growth for us but we are also aware that this comes with significant challenges Botswana knows with concern the rising threat of AI -driven manipulation and the integration of AI to produce highly sophisticated deepfakes, phishing and mass disinformation campaigns posing a direct risk to social security and the development of a global system of cyber security and the development of a global system of cyber security and the development of a global system of cyber security and the development of a global system of cyber security and the development of a global system of cyber security and the development of a global system of cyber security and the development of a global system of cyber security and the development of a global system of cyber security and the development of a global system of cyber security and the development of a global system of cyber security When weaponized across borders, these technologies can manipulate public discourse and destabilize societies. Furthermore, algorithmic biases embedded within AI systems risk automating discrimination, not only at national level in a developing country like Botswana, but also on a global scale, threatening fundamental human rights and economic development. Chair, the borderless nature of cyberspace has amplified data protection risks. As governments and corporations accumulate unprecedented volumes of sensitive personal data, Botswana anticipates an escalating threat for both state and non -state actors targeting these repositories. Large -scale data breaches, unauthorized cross -border data tracking, and data exfiltration undermine the state’s sovereignty and violate individuals’ rights to privacy. Without robust protections, massive centralized data stores become soft targets for malicious cyber operations. We are deeply concerned by the risk inherent… in unregulated surveillance technologies and intrusive digital tools. ICTs are misused to conduct unauthorized mass surveillance and restrict multiple human rights. The cyberspace must remain an enabler of human potential, not an instrument for human rights violations. The Republic of Botswana knows that malicious ICT activity threatens physical disruption to its critical infrastructure and critical information infrastructure where access to critical services are under threat. Disruption to these systems carries severe consequences on our economy. Further, the weaponization of malware, often driven by AI -assisted capabilities, allows malicious actors to bypass traditional protocols with the potential to cause cross -border failures. The Internet of Things proliferation in Botswana, as in the rest of the world, has caused massive security vulnerabilities, as malicious actors are being used to control the internet. These devices are perfecting the skill of hijacking these devices to launch novel DDoS attacks against digital infrastructure. Additionally, while cloud migration offers scalability on a massive level, the potential risks that come with it cannot be avoided. as just one misconfiguration or targeted cyber attack within a major cloud provider can instantly compromise entities and cut off access to essential public services. We also note the increase in ransomware in its magnitude and complexity to counteract these threats and ensure a human -centric approach to digital security. Botswana has actively implemented progressive interventions at national level. This is through, among other things, the enactment of legislation such as the Data Protection Act, which enforces mandatory data protection impact assessments for high-risk processing operations, specifically including the deployment of AI systems. We have fully operationalized the Information and Data Protection Commission to serve as an independent watchdog, ensuring that state and private data controllers are held accountable. We have also enacted the Cybersecurity Act, which establishes clear and enforceable standards for risk management, mandatory risk reporting, and security by design principles for manufacturers, service providers, and operators of critical infrastructure. Botswana calls to member states to prioritize regional and international cooperation in sharing threat intelligence, capacity building, and adherence to the normative framework of responsible state behavior in the cyberspace. Thank you, Chair.
—
Chair Egriselda López
Thank you. I now give the floor to the delegation of Cuba, who will be followed by the United Kingdom, Singapore, Vietnam and Serbia. Cuba, please.
—
Cuba
Thank you, Madam Chair. The trend of deregularizing and the complication of the different threats we face as member states make it more necessary than ever to become more aware of them and to demand us having better detection, response and resilience capacities. In this regard, we underscore threats such as the growing development of cyber offensive capacities and the inclusion. in national security strategies of some states, the use of offensive cyber weapons and the carrying out of cyber offensive operations by those states. The possibility to engage in cyber attacks that are supposedly preventive to dissuade adversaries, the proliferation of doctrines that consider the use of force as a legitimate response to a cyber attack, and the covert and illegal use of the information systems of other nations by individuals, organizations and states to engage in IT attacks against third countries, as well as the false and politically motivated use of cyber attacks to justify hostile actions against other states. The undue use of ICTs and media platforms, including social networks and radio and electronic transmissions as tools for the interference in the internal affairs of states through the promotion of hate speech, incitation of violence and terrorist acts subversion, destabilization the dissemination of fake news and distorting of reality against any state for political purposes and as a pretext for the threat or the use of force this is called fourth generation warfare that seeks to use the information stored and processed in violation of personal data rights and often this model of action becomes a business so we underscore the need to continue to develop and to apply cooperation measures in order to confront existing and potential threats in cyberspace in order to counter threats to security and the use of ICTs we require on a global level to prioritise the following issues, striking a global compromise and commitment for the use of ICTs for exclusively peaceful purposes to benefit the development of peoples, the prohibition of the use of ICTs as a pretext to start wars or to threaten to use or use force, and the militarisation of cyberspace, dealing with the digital gap and the lack of capacity of certain developing countries to invest in ICT development and the use of unilateral coercive measures such as the embargo against my country, given these measures limit our capacities to deal with existing and potential threats. The negotiation and adoption within the United Nations of an international legally binding instrument that is the ICTs and ICTs are the most important and the most important that complements applicable international law and that responds to the significance legal loopholes that currently exist in the area of cyber security. Other measures that could be adopted to counter threats in cyber security and in the use of ICT such as increasing cooperation in order to deal with cyber events by exchanging information that does not compromise the privacy of states with respect to their capacities or being against national legislation, implementing technical cooperation mechanisms to increase capacities including to improve the protection of critical infrastructure based on the respect of the national legislation of states, standardizing as much as possible responses to cyber attacks, having common terminology and using the multilateral system to determine in an unequivocal and unbiased way
—
Chair Egriselda López
The chair thanks Cuba and gives the floor to the United Kingdom.
—
United Kingdom
Thank you, Chair. The cyber threat landscape continues to evolve in both scale and complexity. States, their proxies, and cyber criminal networks increasingly run coordinated campaigns, often alongside information, economic, and other hybrid operations, to erode trust in institutions, threaten economic and national security, and shape geopolitical outcomes. Cyber threats are no longer isolated incidents, but are part of persistent, ongoing, malicious campaigns. These campaigns of malicious cyber activity cause financial loss, psychological distress to victims, disruption to services and risks to critical national infrastructure, democratic institutions, and media. The cyber criminal ecosystem remains highly adaptive. Ransomware continues to be one of the most acute and pervasive threats. The threat from ransomware has been resilient, in spite of sustained international action to counter this phenomenon. Meanwhile, artificial intelligence is transforming cyber activity by increasing the sophistication, scale and pace of operations, whilst at the same time lowering barriers to entry. This differentiated and evolving threat landscape reinforces the importance and the challenge for the UN global mechanism to promote strategic stability through responsible state behaviour in cyberspace. In response to malicious state activity, the UK works with international partners to hold malicious actors to account and raise the cost of such activity through coordinated attribution, sanctions, diplomacy and the like. Last week, the UK issued our first joint cyber sanctions package with the European Union. These sanctions target the Russian state, including senior Russian intelligence officers, and closely associated criminal and proxy networks responsible for orchestrating reckless and destructive cyberattacks across Europe. We also supported the attribution of a recent attempted attack on Poland’s energy infrastructure by Russian intelligence services. The attack failed, but could have left up to 500 ,000 people without electricity during winter. We condemn this malicious cyberactivity. Thank you, Chair.
—
Chair Egriselda López
Thank you very much. I give the floor to Singapore.
—
Singapore
Thank you Madam Chair. Cyberspace has become an indispensable pillar of our global economy, governance and daily lives. While cyber security is the key enabler of a thriving digital economy it is also an imperative for security and resilience. Digital technologies have indeed created unprecedented opportunities for innovation and prosperity but they have also introduced new vulnerabilities that transcend national borders. The rise in cyber threats including attacks by APTs or advanced persistent threats the increase in ransomware as well as threats to emerging technology continue to threaten not just national security but also the economic well-being and ability of many states. First I’d like to turn to the increased malicious cyber activity from APT groups, cyber criminals and hacktivist groups These sophisticated campaigns often conducted by highly capable and well-resourced actors are characterized by stealth, persistence and strategic intent. Rather than seeking immediate financial gains, APT actors frequently target government institutions, critical information infrastructure, or pre-position themselves for future disruptive activities. The increasing complexity of these operations and their ability to remain undetected for extended periods poses serious risks to national security, economic resilience, and international stability. It is in all our interests as an international community to discuss how we can better implement the cyber stability framework and foster international understanding and cooperation to counter the threats posed by APTs, including in the protection of CII’s. Madam Chair, the APT threat is most acutely pertinent to the protection of critical information infrastructure, or CII. The protection of critical information infrastructures is not a technical task. It is a collective. It is a national and global responsibility. Our essential services, from telecommunications and energy to health care, transport, water, and finance, are the systems that keep our nations running every day. They support our economy, safeguard our security, and preserve trust in our institutions. Globally, ransomware activity has continued to surge. In 2025, cybersecurity researchers have reported close to 8,000 cases worldwide based on data leak site postings. The ransomware ecosystem has also continued to evolve and fragment, shaped in part by intensifying law enforcement pressure, internal competition, and weak affiliate loyalty. International cooperation is essential to countering ransomware, which is inherently a transnational threat. Through the Counter Ransomware Initiative, a multilateral platform that forces international cooperation against ransomware, a group of states have been working together with industry partners to strengthen collective resilience by sharing best practices, exchanging information, and developing practical guidance that countries and organizations can adapt to their own context. Madam Chair, the next developments in quantum technologies and AI present both remarkable opportunities and security risks. While quantum computing has the potential to transform fields like scientific research, medicine, logistics and communications, it also threatens the existing cryptographic systems that secure our digital infrastructure today. Threat actors are expected to exploit quantum computing to break encryption, putting sensitive data and digital trust at risk, therefore necessitating migration to quantum-safe cryptography before quantum computers become powerful enough to break today’s system. We’ve heard many delegations speak about nexus between AI and cybersecurity. AI is not just improving existing attacks, it is fundamentally changing cyber operations. AI accelerates attacks in three ways. On speed, it compresses vulnerability discovery and exploitation timelines. On scale, AI enables thousands of attacks to be conducted simultaneously at a low cost. On accessibility, AI lowers the barrier to entry for phishing, malware and reconnaissance. Therefore, Madam Chair, at this global mechanism, we need to build a common understanding of AI cyber risks and a sharing of best practices on how states may better prepare themselves to address AI as a threat and to work with AI as a tool and to defend AI as a target. We welcome the integrated policy -oriented and cross -cutting nature of DTG 1, which draws on the five pillars in the framework. We encourage DTG 1 to ensure that the areas we’ve highlighted here feature prominently in our discussions. DTG 2 could then look at the capacity building required to support our efforts in these domains. I thank you, Madam Chair.
—
Chair Egriselda López
Muchísimas gracias. Many thanks. I now give the floor to Vietnam, followed by Serbia, Brazil, and Ireland.
—
Vietnam
Thank you, Madam Chair. Since this is our first intervention in the meeting, we wish to express our sincere appreciation to you and your team for your continued engagement with Member States. Chair, Vietnam is facing increasing malicious ICT activities, particularly larger -scale advanced persistence, and threat campaigns. targeting critical national information infrastructure and information technology platforms, as well as ransomware attacks directed against data servers of government and private sectors. Nowadays, emerging technologies, including artificial intelligence and quantum computing, enable sophisticated cyber attacks with broader and more far -reaching impacts. The determination of false and misleading information in cyberspace continues to contribute to information disorder, undermining credibility and reputation of states, organizations, and individuals, adversely affecting national security and public order. Cybercrimes, continues to evolve in both scale and sophistication. posing significant challenges to law enforcement. This includes the illicit trade in user information and personal data, phishing and other online fraud schemes, as well as the use of ICTs to facilitate trafficking in persons. We believe DTGIs should focus on the challenges to the international community and make workable recommendations to the plenary. I thank you, Chair.
—
Chair Egriselda López
Thank you very much. I now give the floor to Serbia.
—
Serbia
Thank you, Madam Chair. Dear colleagues, I am truly pleased to take the floor for the first time on behalf of the Republic of Serbia in the Global Mechanism. It is a privilege to join this important forum, and I welcome the opportunity to contribute. To our shared efforts to further strengthen international cooperation on ICT -related issues. The Republic of Serbia warmly congratulates Ambassador Lopez on your appointment as Chair of the Global Mechanism and expresses its confidence that, under your leadership, the mechanism will foster inclusive dialogue, effective cooperation, and achieve meaningful outcomes. The cyber threat landscape continues to become more challenging, and Serbia’s experience reflects this reality. Our national data shows that a steady increase in malicious ICT activity targeting systems of special importance, including government networks and critical infrastructure. What we observe at the national level is consistent with the findings of the final report of the OEWG. Malicious ICT activity by both state and non -state actors continues to increase in volume and complexity. while some non -state actors now possess capabilities that were once available only to states. These activities strike beyond national borders, affecting our citizens’ daily life. This underlines a simple reality. No state is immune to these threats, and no state can address them alone. Serbia is paying close attention to the risk arising from the malicious use of the new and emerging technologies. Artificial intelligence is already changing the nature of cyber threats, making malicious ICT activities more sophisticated and more difficult to prevent and mitigate. Our national experience reflects this wider trend. We are also concerned by the growing availability of commercial, artificial intrusion tools. The misuse of the AI and cryptocurrencies for cybercrime and the security of ICT supply chains, globally speaking, the changing DNA of cybercrime. These developments reinforce the importance of discussing threats on the basis of facts, technical expertise, and shared evidence. This is fully consistent with the agreed UN framework, which calls on states to consider all relevant information and the broader context when assessing cyber incidents. For Serbia, this is not only a matter of principle, but also of practice. We systematically monitor and analyze incidents affecting our critical systems and believe that sharing such experience can strengthen our collective understanding of the evolving threat landscape. We, therefore, support… regular expert exchanges, especially within the dedicated thematic groups, and stand ready to make our national experience available. Thank you for your attention.
—
Chair Egriselda López
Thank you very much. I now give the floor to the delegation of Brazil, followed by Ireland, Nauru, Sweden, and Switzerland.
—
Brazil
Madam Chair, the pervasive use of ICTs and the exponential increase they have brought to our vulnerability to malicious cyber operations continue to be one of the most complex challenges to international peace and security and to the development of our societies. Rapidly evolving technologies continue to bring new threats to critical infrastructure and other essential services. We have done important work throughout the GGEs and the OEWGs in developing common understanding on many of those threats and on recommendations to address them. and this global mechanism should build upon that previous work. We will need to continue to strive to have our recommendations to be as technology -neutral as possible to avoid having their reach limited to specific technologies, with the recognition that some specific technologies or acts can have particularly strong implications to national and international security. Of particular concern to my delegation are the impacts of artificial intelligence and quantum computing, particularly post -quantum cryptography. While we welcome the inclusion of references to them in the OEWG reports, we believe there can still be deeper discussions on those issues within this mechanism. We are weakly concerned by the uses of generative AI in misinformation, and disinformation campaigns, particularly, but not limited to, the use of so -called deepfakes. In the context of an armed conflict, this could cause grave harm to civilians and would constitute a violation of international humanitarian law. The use of AI for misinformation and disinformation purposes is also of particular concern in electoral processes, where it poses a significant threat to states’ political stability. The global mechanism must allow room for, through one or more of its DDGs, in -depth discussions with a view to reach consensus recommendations on how to collectively address new threats and challenges. Discussions currently underway in ad hoc processes outside the UN on issues such as ransomware, AI implications to cybersecurity or intrusive tools, must be, integrated to the global mechanism. Their borderless nature means that we need the engagement of all nations to adequately tackle them. Keeping discussions within the echo chambers of our like -minded groups will reduce their reach, effectiveness, and legitimacy. Madam Chair, Cooperation and capacity building, which has been rightfully recognized by the WEWG as a cross -cutting element to all issues under its mandate, will continue to play a key role in countering threats. Narrowing the digital divide is essential to promote broad cybersecurity. Furthermore, we must not forget that the ultimate objective of our efforts in countering threats is to build resilience to ensure the maximum benefit from digital technologies to promote the development of societies. In this regard, we continue to support discussions of proposals that can help us build their potential for the future. We will continue to work to improve cybersecurity resilience, such as the creation of a threat repository, the adoption of common terminology, and the sharing of good practices in threat mitigation. I thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to Ireland.
—
Ireland
Thank you, Madam Chair. Ireland aligns itself fully with the intervention of the European Union and makes the following comments in our national capacity. Malicious actors continue to target our government and public services, our democratic processes, our private institutions, and our critical infrastructure, including undersea infrastructure. Understanding the cyber threats that we face allows us to identify the topics that we need to prioritise for deeper examination during the DTGs in December. The protection of the healthcare sector against malicious cyber activity is a topic that we need to focus on. It is a topic that we would like to see discussed under the DTGs. Ireland has direct and recent experience of this threat Our health service was targeted by a hugely disruptive criminal ransomware attack in 2021 The DTGs should provide a forum for exchanges on the evolving cyber threats that we all face and facilitate discussion on reinforcing responsible state behaviour and our collective resilience Thank you Madam Chair
—
Chair Egriselda López
Many thanks. I now give the floor to Nauru, followed by Sweden Switzerland, Egypt and Kiribati Nauru, you have the floor
—
Nauru
Thank you Madam Chair Nauru aligns itself with the statement delivered on behalf of the Pacific Island Forum members and makes the following remarks in its national capacity Nauru Nauru is one of the smallest members of this organization and until recently we were also one of its least connected. That has changed. Last year, the East Micronesian Cable came ashore at Yarin, the first international submarine cable in our history, ending the case of dependence on the satellite links alone. For Daynauras, this is a special opportunity, this is a welcome opportunity to expand possibilities for our students and our businesses, our government services, and our place in the digital world. Nauru is candid about what else it brings. A country that connects late meets the full threat landscape on day one that others encounter gradually. Our people are encountering online fraud and scams engineered against those newest to the Internet. Our government systems join a region in which the essential services of small states are being used to create a better future. health systems, telecommunication operators have been held to ransom by criminal groups operating from the other side of the world. And the cable itself, our single fiscal link, concentrates our national connectivity in one piece of infrastructure. We cannot take for granted its protection. NARO’s answer is to build our defenses at the same speed as our connectivity. Our government is finalizing the most comprehensive digital reform program in our history, a cybersecurity bill establishing a framework for critical information infrastructure protection, which includes a national cert and incident reporting, and a data protection bill to follow. There are also considerations of revising the cybercrime bill modernizing our criminal law for the digital age. Simultaneously, our national cybersecurity system and our national child online protection strategy are both under development. This is what taking threats seriously looks like for a state of our size. Madam Chair, Nauru asked one thing of these mechanisms works on threats. Make it usable. Threat discussion serves the smaller states when they produce shared assessments in plain terms. Early warning that reaches small administrations and corporations that help us act what we learn. Nauru has shown what a small state is prepared to do at home. We look to this mechanism to match that effort internationally. Thank you.
—
Chair Egriselda López
Thank you very much. I now give the floor to Sweden.
—
Sweden
Thank you, Madam Chair. This is the first time I’m taking the floor, so I would like to begin by commending you for your strong leadership in preparing for this inaugural plenary session of the Global Networks, a mechanism you can count on the full support from my delegation. Sweden fully aligns itself with the statement delivered by the EU, and I would like to highlight three points in the national capacity. Firstly, it is evident that the worrying context of this meeting is an increasingly complex and challenging cyber threat landscape which affects large parts of societies. The backdrop is a geopolitical environment which continues to deteriorate. In my country, cyber threats involve critical infrastructure, public institutions and services at national, regional and municipal levels, businesses and private citizens, potentially endangering national security as well as economic prosperity. To successfully deal with such extensive challenges, a whole -society approach is necessary to build resilience. In particular, effective public -private partnership is indispensable. In Sweden, a reinforced national cybersecurity center sits at the core of our cybersecurity ecosystem but interacts with a wide range of public and private actors. By the same token, for the global mechanism to be able to achieve this goal, we need to be able to address these threats effectively. It will be crucial to draw on the expertise of the international community. which resides uniquely within the multi -stakeholder community. Secondly, the evolving nexus between state and non -state actors is an increasing concern. It raises questions regarding the responsibility of non -state actors and the relationship between malicious cyber activities conducted by non -state actors and state responsibility, particularly in situations where non -state actors act with varying degrees of state support. We expect all states to use cyber capabilities in accordance with international law and in line with the UN norms of responsible state behavior in cyberspace and to take necessary measures to stop malicious actors operating within their jurisdictions. In this connection, Sweden welcomes the latest EU cyber sanctions package adopted last week. And thirdly, the potentially far -reaching implications of emerging technology for cybersecurity. Cyber threat operations. State actors continuously develop new techniques and rapidly adopt technological developments. To be clear, artificial intelligence offers tremendous opportunities. At the same time, it can dramatically lower barriers for malicious actors, enabling cyber operations of a heretofore unimaginable scale and speed. Harnessing the promises of AI while preventing that it’s being weaponized to exploit vulnerabilities will be an essential task going forward. Thank you, Madam Chair.
—
Chair Egriselda López
Muchísimas gracias. Thank you. I now give the floor to Switzerland, followed by Egypt.
—
Switzerland
Thank you, Madam Chair. The cyber threat landscape continues to deteriorate. According to the latest assessment by the Swiss National Cyber Security Center, the frequency, sophistication, and strategic significance of malicious cyber activities are increasing, a trend accelerated by the rapid development of large language models. While financially motivated cyber crime remains prevalent, a significant threat to Switzerland comes from state and state -sponsored actors. These actors conduct cyber espionage against governments, international and humanitarian organizations, research institutions and industry, seek persistent access to critical infrastructure, exploit supply chains, including through managed service providers and telecommunications operators, and increasingly integrate cyber operations into broader geopolitical strategies. The use of proxies and the growing conversions between state interests and cyber criminal ecosystems poses an additional accountability challenge and increases risk to international peace and security. Malicious cyber operations are commonly routed through infrastructure -inferred countries, including rented servers and compromised consumer devices, to obfuscate their origin. Consistent with the agreed norm that states should not knowingly allow their territory to be used for internationally wrongful acts using ICTs, Switzerland actively has… works to prevent the misuse of infrastructure on its territory and stands ready to share its experience in this regard. Switzerland also continues to observe a high level of hacktivist activity. Motivated by geopolitical developments, these groups and individuals have demonstrated the ability to rapidly mobilize and carry out disruptive campaigns, including distributed denial -of -service attacks, website defacements, and data leaks. While these operations often have limited technical impact, they contribute to instability, amplify political narratives, increasing the risk of escalation of existing conflicts. Such activities are criminal offenses under Swiss law, as in most states. Irrespective of whether civilians act alone or collectively, act out of political motives or in the interest or on behalf of another state. Switzerland recalls that, in line with norm 13c, states should not knowingly allow their territory to be used for internationally wrongful acts using ICTs and shenanigans. It should take appropriate measures to prevent non -state actors on their territory from conducting such activities. Recent armed conflicts have demonstrated that cyber operations are now an integral part of modern warfare. Cyber activities are employed alongside conventional military operations for purposes such as gathering intelligence, disrupting communications, targeting critical infrastructure, and influencing public perception. In that regard, Switzerland is concerned about the heightened threat to the technical infrastructure essential to the general availability and integrity of the Internet, including submarine cables, orbital communication networks, and data centers. These developments highlight the importance of minimizing the risk of escalation, safeguarding civilian infrastructure, ensuring respect of existing international law, in particular international humanitarian law, and that the agreed framework of responsible state behavior continues to inform state conduct in cyberspace. Switzerland continues to strengthen its national resilience. The introduction of mandatory reporting of cyber incidents affecting critical infrastructures has improved situational awareness and reinforced cooperation between public authorities and private operators. Experience confirms that timely information sharing is an essential element of effective cyber resilience. Switzerland stands ready to share this experience, including on mandatory incident reporting and public -private information sharing as a concrete contribution to the capacity -building work of this mechanism. Chair, artificial intelligence is transforming cybersecurity. Every new generation of AI models offers significant new opportunities to strengthen cybersecurity by improving vulnerability detection, incident response and threat analysis. However, they are also used by malicious actors to conduct sophisticated or even autonomous cyber operations with greater speed, scale and sophistication. thereby lowering the barriers to advanced attacks, social engineering, and creating new vulnerability sets associated with the AI systems themselves. Current AI models furthermore overwhelm many software providers, in particular open -source maintainers, jeopardizing the ability to fix vulnerabilities in a timely manner. Switzerland believes that these developments deserve increased international attention. Discussions within this mechanism should help shaping a common understanding of AI risks. Consider how states can use AI responsibly whilst respecting and implementing existing international law, voluntary norms, and CBMs, and contributing to capacity building. In our view, there is no need to adopt new voluntary norms or specific CBMs for AI. The existing ones were not created for any particular technology and are generally broad enough to enable us to address the challenges posed by AI and cybersecurity as well. It is also important to keep in mind the mandate of the global mechanism and that we do not conduct this discussion in isolation from other ongoing processes or duplicate work being carried out within them, such as in the global dialogue on AI governance. Madam Chair, given your involvement in both processes, I am confident that you
—
Chair Egriselda López
Thank you very much. We have exhausted the amount of time available to us this afternoon. We still have 29 delegations on the list of speakers under this item, and I will read out the first five who will be the first to speak tomorrow. Egypt, Kiribati, New Zealand. Tonga and the Kingdom of the Netherlands these are the first five speakers for tomorrow morning we will reconvene in this room at 10 a .m. tomorrow to continue the consideration of this agenda item and according to the program of work as I indicated after this discussion on threats we will begin with voluntary non -binding norms on responsible state behavior and ways for their implementation recognizing that additional norms could be developed over time as I mentioned this morning as we complete each item in the program I will immediately move on to the next item that is to say we will continue with the agenda of the session thank you very much and see you all tomorrow
The knowledge base confirms that Chair Egriselda López presided over meetings of the Global Mechanism on ICT security [S120].
2
The knowledge base source [S120] describes this meeting as the ‘2nd meeting of the organisational session’ of the Global Mechanism, not the second meeting within the first substantive plenary session. This is a potentially significant distinction between an organisational session and a substantive plenary session. Additionally, [S177] indicates the first substantive session is scheduled for July 2026, suggesting the current meeting may still be part of the organisational phase rather than a substantive session.
3
The knowledge base references the OEWG 2021-2025 and the future permanent mechanism, consistent with the Global Mechanism succeeding the OEWG [S184] and [S179].
4
The knowledge base confirms that the 1st meeting of the plenary session addressed the role and working methods of the DTGs, and references discussions on ICT security challenges and capacity building as distinct thematic areas [S116].
5
The knowledge base confirms that the voluntary checklist for norms implementation was a significant agenda item in prior OEWG sessions [S152] and [S185], providing context for Brazil’s proposal to continue this work in DTG 1.
6
The knowledge base confirms that the EU, Canada, Switzerland, Mexico, and Japan advocated for focused, scenario-based discussions drawing on expert briefings and guiding questions in the context of DTG working methods [S116].
7
According to [S177], the first substantive plenary session of the Global Mechanism is scheduled for July 2026, and the body will hold substantive plenary sessions once a year during each biennial cycle. This adds important context to the report’s characterisation of the current meeting as part of the ‘first substantive plenary session.’
Adoption of the agenda and organization of work— In summary, the Republic of Korea emerges as a supportive and engaged advocate for regulations that align closely with international human rights standards and the objectives of SDG 16, underscoring the importance of lea…
7th edition— Brazil has been one of the most countries in global digital politics and is the largest Internet market in Latin America. As a democratic and developing country with a vibrant digital space, Brazil has great poten…
Opening of the session— Brazil’s stance on a series of matters pertaining to human rights and the advancement of an international convention is markedly positive and aimed at fostering collaboration. The country firmly stands by Article 5, reco…
Framework Agreement of the Pacific Alliance— (4) Value Added Services are not those services in which for their establishment, operation or exploitation use is made of transmission infrastructure owned by the service provider, unless the service provider has the co…
Ad Hoc Consultation: Wednesday 31st January, Afternoon session— Additionally, it exhibits flexibility, contemplating a Brazilian proposal and suggesting a refined change to the term “Secretariat,” advocating instead for “Secretariat Services.” This change highlights Colombia’s constr…
Any other business /Adoption of the report/ Closure of the session— Colombia has showcased its dedication to furthering gender equality, affirming its commitment to integrating a gender perspective across its official documentation and policy-making endeavours in alignment with Sustainab…
(Day 2) General Debate – General Assembly, 79th session: morning session— Mokgweetsi Eric Keabetswe Masisi – Botswana : Mr. President, Excellencies, Distinguished Ladies and Gentlemen, I wish to start by extending my congratulations to you on your election as President of the General Assembl…
Agenda item 6— In conclusion, Botswana envisions the OEWG playing a crucial role in enabling the exchange of expertise and capabilities in a multi-stakeholder environment that is aligned with regional and national efforts. Such collabo…
Conversation: 01— -Paula Bogantes Zamora- Area of expertise: Science, innovation, technology and telecommunications policy. Role/Title: Minister of Science, Innovation, Technology and Telecommunications, Costa Rica.[S12] Additional conte…
Table of contents— + Estonia is a trailblazing and leading country in specific prioritised fields of cyber security in the EU and at a broader international level. + The interests of the state and market participants have been taken into …
Introducción a la Internet gobernanza DE— Estonia es un actor de políticas digitales muy dinámico. Luego del ataque DDoS en 2007, que afectó gravemente a la Internet a nivel nacional, Estonia se convirtió en un jugador realmente activo en el campo de la ciberseg…
The art of bending without breaking: Vietnam's quiet power play — Even before China’s rise in economic and technological avenues, China had regarded Vietnamese-style communism as troublesome and could never compel Hanoi to pursue its interests. After Vietnam had invaded Cambodia to ove…
Balancing act: advocacy with big tech in restrictive regimes | IGF 2023— Trinh Huu Long:Yeah, thank you very much for having me. I have a presentation. May I share my screen or? Yeah, I think so. Great. I’m finding my screen. Please bear with me. Super. Yeah, we can see it now. Thank you very…
— United Kingdom
Ad Hoc Consultation: Tuesday 30th January, Morning session— The United Kingdom’s engagement with international legal discussions presents a distinctly positive alignment with global objectives and the detailed provisions of specific articles, highlighting its and collabora…
Government of the United Kingdom— The Government of the United Kingdom, domestically referred to as Her Majesty’s Government, is the central government of the United Kingdom of Great Britain and Northern Ireland.
Agenda item 5 : Day 3 Morning session— Belarus is recognized for taking a leading role in this field, advocating for the formulation of new, binding international agreements to effectively manage information security. Belarus’ support for the preliminary conc…
Pre 6: Countering Disinformation and Harmful Content Online— Alina Koushyk, director of Belsat TV, a Belarusian media outlet operating in exile, provided a harrowing account of the challenges faced by independent media under authoritarian regimes. She revealed that 88% of Belarusi…
Opening of the session— – Nigeria – Speaking on behalf of the African Group Chair: Thank you very much, European Union. Could you kindly share the statement with us, please? Thank you very much. Nigeria for African Group to be followed by Fiji…
UNSC meeting: Regional arrangements for peace— Kazakhstan:Thank you, Mr. Chair. I thank the Brazilian Presidency for convening today’s open debate. The urgency of today’s global problems threatens all of us and our civilizations, and so we need to create conditions f…
UNSC meeting: Conflict prevention: women and youth— Climate change emerged as a significant concern, particularly for small island nations. Tonga and other Pacific nations declared climate change as the single greatest threat to their security, calling for urgent action a…
Agenda item 6: other matters/OEWG 2025— – Pacific Islands Forum – Tonga: Speaking on behalf of Pacific Islands Forum member states – The Pacific Islands Forum, represented by Tonga, emphasised the need for a limited number of thematic groups to enable partici…
INTRODUCTION— A fundamental goal of scientific research is to improve the quality of life of people and the social context in which they live. In the near future, Artificial Intelligence (AI) will offer increasingly effective too…
Stefano Baldi Pasquale Baldocci— As for Italian history in general, Sergio Romano has written several titles in the area. Particularly important is his History of Italy from the Risorgimento to Today . Originally published in French in 1977 , it…
On the origins of World War I— Italy’s role in destroying the Congress of Berlin balance of power seems beyond dispute. The authors also blame Italy for being thefirst European power to use war as a means of reducing social tension at home. Indeed, Gi…
(Day 4) General Debate – General Assembly, 79th session: morning session— Andrej Plenkovic – Croatia: Mr. President, Excellencies, distinguished ladies and gentlemen, today we should stand united in the face of unprecedented global challenges. From the proliferation of conflicts and deterio…
The Role of Nigeria In Restoring Peace In West Africa— For example, the nation’s peace was relatively threatened when the federal government of Nigeria, during General Ibrahim Badamosi Babangida (IBB)’s administration announcement that Nigeria was going …
Research Collection— 19 Based on the title of David D. Newsom’s article on the Swiss role in the hostage crisis, which was first published in a commemorative publication for Ambassador Probst: David D. Newsom, ‘The Sensiti…
UN: Summit of the Future Global Call— The analysis reveals Switzerland’s role as a proponent of international cooperation and dialogue. By supporting initiatives like the Summit of the Future and the Pact for the Future, Switzerland positions itself as a fac…
Panel Discussion AI in Healthcare India AI Impact Summit— -Affiliation:Invalude, Canton Broad, Switzerland[S4] -Affiliation:Not specified in transcript (moderator role)[S2] -Role/Title:India Relations Advisor at Invalude (innovation and investment promotion agency of Canton B…
Transforming Agriculture_ AI for Resilient and Inclusive Food Systems— – Affiliation: Netherlands – Role/Title: (Representative of the Netherlands) – Role/Title: Senior Researcher Thank you, Ambassador. And on behalf of the OECD, I just want to thank once again the Netherlands for the le…
Ad Hoc Consultation: Friday 2nd February, Afternoon session— By championing inclusive and pragmatic global governance, the Netherlands solidifies its position as a driving force for collective action and widespread progress in the international arena. The expanded summary provided…
Agenda item 5 : Day 4 Morning session— In the area of Confidence-Building Measures (CBMs), the Netherlands values their role in enhancing transparency, fostering trust, and promoting cooperation between states. Their support for adapting CBMs drawn from their…
The Role of Government and Innovators in Citizen-Centric AI— – Role/Title: Panel moderator/host; senior role at the European Commission (referred to as “my boss” by Roberto Viola)[S6] precisely this, how do we sort of build capacity in order for this technology to be applied sign…
European Union— The European Union (EU) is a regional intergovernmental organization aimed at enhancing economic and political cooperation among its 28 member states. It operates through various institutions like the European Parliament…
European Union— The EU, through its institutions (such as the European Parliament, the Council of the EU, and the European Commission), works on a wide range of policy areas, from agriculture and competition, to environment and transpor…
Multistakeholder Partnerships for Thriving AI Ecosystems— – Role/Title: Audience participant (part of a German group; specific affiliation not specified)[S1][S2][S3] – Role/Title: Parliamentary State Secretary at Germany’s Federal Ministry for Economic Cooperation and Developm…
By the Same Author— Germany is the world’s most decentralized large country, in political and socioeconomic structure. Its nearest comparison is the US, a continental landmass nation of a different order, and possibl…
UNITED NATIONS HANDBOOK 2019-20— * Original members, that is, those that participated in the UN Conference on International Organisation at San Francisco or had previously signed the UN Declaration of 1 January 1942, and that signed and ratified the Cha…
Ad Hoc Consultation: Friday 2nd February, Afternoon session— In addition, Sweden’s membership within the EU reflects its conviction in the efficacy of supranational entities to initiate transformative change and engender stability. The country’s eagerness to foster dialogue and en…
I. Multilateral institutions under adjustment pressure— China plays a special role in all international organizations. While China has formally declared its solidarity with the South, its behavior has traditionally been reserved, if not enigmatic. It may be no mor…
Oman: Nexus between traditional and tech diplomacy— Most notably, Oman has been the place of choice for negotiations between American and Iranian diplomats during periods of high tension. It hosted the preliminary talks that led to the 2015 Iran nuclear agreement and, mor…
By the Same Author— Algeria was relatively unknown in India. Under President Houari Boumediene, it strode tall on the international stage. It had hosted the 1973 Non-Aligned Summit, and showed itself adept at socialist rhetoric, which was t…
(Day 1) General Debate – General Assembly, 79th session: morning session— Cyril Ramaphosa – South Africa: Thank you, Your Excellency, the Chair of the Assembly. We take this opportunity to thank the United Nations Assembly to give us a chance to speak. Thirty years ago, South Africa was bor…
Ad Hoc Consultation: Thursday 8th February, Morning session— Speaking from a national perspective, the representatives communicated that they could fully endorse the Article. This strong endorsement indicates compatibility with national policies or a strategic international stance…
Closure of the session— For the past four years, France has been actively collaborating with a diverse group of states to lay the groundwork for a future Responsible Identification (RID) mechanism. With a single-track cycle of continuous improv…
The New Public Diplomacy— After Vichy came the Fourth Republic and then the Fifth, which is France’s current political and cultural incarnation. Of course it’s true that there is continuity underneath the change. The French people and Fr…
UNSC meeting: Strengthening UN peacekeeping— Serbia:Thank you, Mr. President. Thank you very much for convening this important meeting. Mr. President, distinguished members of Security Council, ladies and gentlemen, Serbia is a strong supporter of multilateralism a…
UNSC meeting: Multilateral cooperation for peace and security— Serbia:Mr. President, the world of today is faced with numerous and serious challenges that necessitate close cooperation by us all, as well as responsibility in quest for proper and applicable answers. Serbia considers …
(Day 1) General Debate – General Assembly, 79th session: morning session— Aleksandar VuÄiÄ – Serbia: Madam President, Excellencies, ladies and gentlemen, Mahatma Gandhi said, there is no path to peace. Peace is the path. In the same spirit of fraternal love and open heart, I address you …
Ad Hoc Consultation: Wednesday 31st January, Afternoon session— In summary, Vanuatu’s clear commendation for both the wording and the title of the text denotes a robust congruence with its stance, suggesting that the revisions have suitably incorporated changes that favour Vanuatu, e…
Ad Hoc Consultation: Friday 9th February, Morning session— As for the aspects of convention ratification thresholds, Vanuatu aligns with the United States and Mexico, endorsing an elevated participation requirement as specified in Article 64, calling for a minimum ratification b…
How Trust and Safety Drive Innovation and Sustainable Growth— and then we’re going to dive right into my immediate left. I have Alex Reed -Gibbons, who is the CEO of the Center for Democracy and Technology, one of the leading advocacy organizations in the world, working on civil ri…
Ad Hoc Consultation: Friday 9th February, Morning session— Singapore is actively engaged in the sphere of international law, particularly with regard to the treaty ratification process outlined in Article 64. The country has expressed a positive stance on the idea of raising the…
Ad Hoc Consultation: Friday 2nd February, Afternoon session— Ireland’s alignment with the EU highlights their commitment to collaboration and adherence to the EU’s stance on legal matters. Ireland’s nuanced handling of international law serves as a strategic, yet discerning, ende…
Acknowledgements— At the regional level, New Zealand, a metropolitan Pacific Islands and the closest neighbor to the PLG states, does not constitute the vulnerability criteria as a Pacific small island, but it plays an important role as a…
Ad Hoc Consultation: Monday 5th February, Morning session— New Zealand can support the U.S. proposal for the title and to remove the list of crimes in the final PP New Zealand can support the U.S. proposal for the title. Surprisingly, New Zealand shared Egypt’s unease concerni…
UNSC meeting: Strengthening UN peacekeeping— Argentina is one of the vice-chairs of C34 In this speech, Argentina reaffirms its commitment to United Nations peacekeeping operations and emphasises the need for a comprehensive approach to maintaining international p…
Adoption of the agenda and organization of work— Argentina reiterated its willingness to collaborate in consensus building In summary, Argentina’s diplomatic engagement and flexible approach to achieving consensus demonstrate their dedication to fostering cooperative …
EU – Turkey Negotiations— Membership negotiations were officially inaugurated in October 2005 und the Government of Recep Tayyip Erdoğan representing the justice and Development Party (AKP) that was formed from the remnants of I…
Ad Hoc Consultation: Thursday 8th February, Afternoon session— Indeed, they contend that the incorporation of such equivocal language compromises legal clarity—a cornerstone of International Law that could potentially lead to interpretive conflicts and discord. Moreover, Kiribati ha…
Summit Opening Session— Five centuries ago Portugal started the first globalization by establishing contacts and relations with countries worldwide. The Treaty of Tordesillas divided the world between Portugal and Spain. The first submarine cab…
(Day 3) General Debate – General Assembly, 79th session: morning session— Luis Montenegro – Portugal: President, Mr. Secretary General, Heads of State and Government, Excellencies, Ladies and Gentlemen, I start by congratulating the President of the 79th Session of the General Assembly, Phi…
Ad Hoc Consultation: Thursday 8th February, Morning session— Cuba has exhibited a proactive role in diplomatic negotiations, especially on issues pivotal to developing countries. The nation recognises the advancements in the dialogue, showing satisfaction with the current state of…
Multistakeholder Partnerships for Thriving AI Ecosystems— – Role/Title: Audience participant (part of a German group; specific affiliation not specified)[S1][S2][S3] We’re also joined by Nakul Jain, who’s the CEO and managing director of Wadwani AI Global. Nakul is a mission -…
Ad Hoc Consultation: Wednesday 7th February, Morning session— Their emphasis on both consensus and human rights protection showcases a comprehensive approach to cybercrime; one firmly grounded in the rule of law, individual liberties, and international partnerships. In summary, Chi…
Agenda item 5 : Day 4 Afternoon session— Brazil envisages a centralized portal, ideally on the UN’s website, as a vessel for streamlining cooperation information exchange, including capacity building data. Advocating for increased UN involvement in cyber capaci…
Agenda item 5: Day 2 Morning session— Brazil remains resolute in its pledge to advance these discussions and ensure that cybersecurity protocols evolve in step with technological progress and the dynamic landscape of cyber threats, thereby safeguarding inter…
9821st meeting— I also reiterate my call for banning lethal autonomous weapons. We must establish new prohibitions and restrictions on autonomous weapon systems by 2026. No country should design, develop, deploy, or use military applica…
Agenda item 5: Day 2 Afternoon session— Furthermore, given the pace of technological advancements and the dynamic nature of the cyber domain, Brazil understands the need for the establishment of new norms. However, Brazil insists that any endeavour to craft su…
The Challenges of Data Governance in a Multilateral World— Moreover, it is crucial that interoperable mechanisms for international data transfers prioritize the fundamental right to data protection. Brazil, for instance, is currently engaged in discussions regarding regulations …
Closure of the session— China: Thank you, Chair. At present, the ICT security process of the United Nations has entered a critical transitional juncture. How to promote discussions of the future mechanism and reach more consensus has become…
WSIS women and girls trendsetters and action plan— This tension has clear policy background. WSIS and digital cooperation traditions emphasise multistakeholder collaboration, capacity development and practical exchange across actors[S104][S105]. At the same time, UN Wome…
Media Remuneration Policy Analysis Mitchell began by establishing her background and the context for CNTI’s work. Coming from 25 years at the Pew Research Center where she helped l…
A Clash of Professional Cultures: The David Kelly Affair— Finally, the following two quotes provide further background context in support of the policy-promoting rather than intelligence-sharing aims of the dossier. The first comes from an email from Danny Pruce (a Foreign Offi…
UN Global Mechanism on ICT security— How will DTGs feed into the plenary? Iran and Russia emphasised that topics must be determined by consensus among all member states. Argentina argued that the plenary should maintain control over the agenda rather than …
Effective Governance for Open Digital Ecosystems | IGF 2023 Open Forum #65— The risk of inadvertently developing into surveillance states through digitisation must be carefully mitigated. Furthermore, the analysis underlines the importance of a global multi-stakeholder approach, where government…
Future of International Cyber Diplomacy: Comprehensive Discussion Report— -Multi-stakeholder Participation and Modalities: A significant focus was placed on how to meaningfully integrate non-state actors (private sector, civil society, academia) into the future mechanism while maintaining the …
Opening Session | Seventh OEWG Session on ICT Security — 1. Threat Landscape: – The Chair called for objective discussions to understand and respond to the evolving threats in the ICT domain, including ransomware and attacks on critical infrastructure. The potential acc…
UN OEWG 2021-2025 10th substantive session— States across the globe are confronting a myriad of cyber threats that challenge both national security and global stability. These threats were extensively discussed during the10th substantive session of the OEWG 2025. …
Digital divides & Inclusion— In conclusion, the digital divide between the developed and developing world is a significant issue that requires attention. Factors such as the lack of policy coordination, government censorship, cybersecurity concerns,…
DIPLOFOUNDATION UNIVERSITY OF MALTA— The most significant concern about the so-called digital divide is that Internet resources and access be best utilised to decrease the digital and other divides. New Internet resources must offer opportunities and suppor…
Day 0 Event #258 Nowhere to Hide Accountability to Fight Global Ransomware— Low to moderate disagreement level. The speakers demonstrated strong alignment on threat assessment and the need for collaborative responses, with differences mainly in tactical approaches and stakeholder inclusion. This…
Open Forum #48 The International Counter Ransomware Initiative— Low level of disagreement. The speakers presented complementary information and perspectives, reinforcing each other’s points rather than contradicting them. This alignment suggests a unified approach to addressing ranso…
WS #260 The paradox of inclusion in Internet governance— Hurel Louise Marie: inclusion of minoritized identities and communities. Louise, would you like to go first? Sure, happy. do so, and thank you for that question, Sasha. I think from where I’m standing, and from the, …
Informal Stakeholder Consultation Session— We must also confront new challenges, from artificial intelligence to deepening digital divides, with the same spirit of multistakeholder solidarity that defined WSIS. To ensure a focused and productive review, we unders…
New Year’s in New York: A Crowded Cyber-Norms Playground (Part 2)— All of the currently established norms and CBMs are of voluntary nature, thus states should adhere to them, but are not bound. Some states, in particular the EU, Australia, the US, and their other western allies (althoug…
WSIS ActionLine C6 Enabling Environment— The Digital Readiness Framework identifies gaps across 117 indicators, but not every gap necessarily requires action. Policymakers must prioritise based on what is most relevant in their context, what is feasible, and wh…
UN Global Mechanism on ICT security— Another issue discussed was how DGT work feeds into plenary work. Brazil made it clear that without a defined protocol for elevating DTG reports to the plenary and formally accepting their recommendations, the groups ris…
Future of International Cyber Diplomacy: Comprehensive Discussion Report— -Multi-stakeholder Participation and Modalities: A significant focus was placed on how to meaningfully integrate non-state actors (private sector, civil society, academia) into the future mechanism while maintaining the …
Opening Session | Seventh OEWG Session on ICT Security — 1. Threat Landscape: – The Chair called for objective discussions to understand and respond to the evolving threats in the ICT domain, including ransomware and attacks on critical infrastructure. The potential acc…
UN OEWG 2021-2025 10th substantive session— States across the globe are confronting a myriad of cyber threats that challenge both national security and global stability. These threats were extensively discussed during the10th substantive session of the OEWG 2025. …
UN General Assembly 66th Plenary Meeting – WSIS Plus 20 High-Level Review— The Pacific Island Forum calls for enhanced technical cooperation and capacity building specifically designed for small island developing states. Many Pacific countries face constraints in deploying emerging technologies…
OEWG and Cybersecurity Negotiations at the United Nations— Capacity building remained a priority for developing nations. Mauritius and Malawi stressed the urgent need for technical assistance, funding, and training to strengthen cybersecurity frameworks in regions facing resourc…
First substantive session of the UN Global Mechanism on cybersecurity— Global Mechanism on ICT Security It will hold substantive plenary sessions once a year during each biennial cycle, the first being scheduled for July 2026. The Global Mechanism will convene in different formats. The f…
Agenda item 6: other matters— France: Thank you, Mr Chairman. My delegation thanks you for the opportunity to share with the VOEWG a presentation on concrete proposals and avenues of reflection for the future mechanism of regular institutional di…
Closure of the session/OEWG 2025— Chair: Thank you very much, Djibouti, for your contribution. Is there anyone else who wishes to speak or who wishes to come back and respond to any comments that have been made? Either you have exhausted the topic or…
Women, peace and security— Brazil: Thank you, Madam President, Madam President, distinguished colleagues. Britsland would like to applaud Switzerland for the topic of this year’s open debate on peace and security and the briefers for their edif…
UN OEWG 2021-2025 9th substantive session— The discussions on managing the number of thematic groups in the future permanent mechanism were not extensively covered in most sessions of theUN OEWG 2021-2025 9th Substantive Session. However, in theAgenda Item 6: Oth…
DTGs should focus on a limited number of priority topics per cycle and draw on expertise from diverse sources including stakeholders, with geographic balance
Arg. 1
Explanation
Brazil argues that for DTGs to be most effective, they should concentrate on a limited number of priority topics each cycle rather than attempting to cover everything. They should also incorporate expertise from a wide variety of sources, including stakeholders, while ensuring geographic balance in representation.
Evidence
Brazil presented specific options for DTG 1 topics in March, including more in-depth discussions of the voluntary checklist on norms implementation, the continued operationalisation of the points of contact directory, and further discussion on the application of international law in cyberspace . Brazil also noted that other delegations had mentioned the protection of critical infrastructures as a topic of utmost relevance .
Major Discussion Point
Structure and Functioning of Dedicated Thematic Groups (DTGs)
Agreed with
KiribatiGermanyArgentinaChileOmanFranceNigeria in behalf of the African groupSingapore
on: Stakeholder participation, including from the private sector, academia, and technical community, adds significant value to DTG discussions
Disagreed with
ChinaKiribatiNew ZealandGermanyChile
on: Decision-making process for selecting DTG 1 topics
The creation of DTG 2 on ICT security capacity building is of particular importance; centralising capacity-building initiatives under the UN umbrella would facilitate access and ensure alignment with priority issues
Arg. 2
Explanation
Brazil emphasises that the interconnected nature of cyberspace makes security a collective endeavour, and no country can be safe in isolation. Centralising the many existing capacity-building initiatives under the UN umbrella would facilitate access for those who need them and ensure closer alignment with priority issues identified by the OEWG and GMAC plenary.
Evidence
Brazil stated that no country can be safe from threats in the digital domain in isolation and that ‘we are only as strong as our weakest link’ . Brazil noted that its country, along with many others, has advocated for greater United Nations involvement in this domain , and that centralising capacity-building initiatives under the UN umbrella would facilitate access and ensure better compliance with capacity-building principles adopted by the OEWG .
Major Discussion Point
Capacity Building as a Priority (DTG 2)
Agreed with
ChileNigeria in behalf of the African groupSingaporeSaudi ArabiaKazakhstan
on: Capacity building is a strategic cross-cutting priority, and DTG 2 is a key platform for advancing practical cooperation and concrete outcomes
DTG 2 should commence with a diagnostic assessment of the current landscape, identifying existing initiatives, evaluating their strengths and weaknesses, and making recommendations for optimisation
Arg. 3
Explanation
Brazil recommends that DTG 2 begin its work with a comprehensive diagnostic assessment of the current capacity-building landscape. This would involve identifying existing initiatives, evaluating their strengths and weaknesses, and making recommendations for optimisation.
Evidence
Brazil explicitly stated that it would be beneficial for DTG 2 on capacity-building to commence its work with a diagnostic assessment of the current landscape in the field, identifying existing initiatives, evaluating their strengths and weaknesses, and making recommendations for its optimisation .
A clear procedure must be established to elevate DTG reports and negotiate recommendations to the plenary so they may be formally adopted
Arg. 4
Explanation
Brazil stresses the importance of ensuring that DTG discussions adequately feed into the work of the plenary. To achieve this, a clear procedure must be established to elevate DTG reports and negotiate recommendations so that they can be formally adopted by the plenary.
Evidence
Brazil stated that it will be key to ensure that discussions within the DTGs adequately fit the work of the plenary, and that a clear procedure must be established to elevate DTG reports and negotiate the recommendations to the plenary so that they may be formally adopted .
Major Discussion Point
Reporting from DTGs to the Plenary
Agreed with
KiribatiGermanySingaporeNetherlandsChile
on: There must be a clear and predictable mechanism for DTG recommendations to be brought back to and taken up by the plenary
More in-depth discussions of the voluntary checklist on norms implementation, operationalisation of the points of contact directory, and application of international law in cyberspace are proposed topics for DTG 1
Arg. 5
Explanation
Brazil proposes specific topics for DTG 1 that build on existing frameworks and agreements. These include deeper engagement with the voluntary checklist on norms implementation, continued operationalisation of the points of contact directory, and further discussion on the application of international law in cyberspace.
Evidence
Brazil presented these options in March for topics for DTG 1, noting the growing number of national positions that have been published on the application of international law in cyberspace .
Major Discussion Point
Priority Topics for DTG 1
Agreed with
Republic of KoreaGermanyTonga on behalf of the Pacific Islands ForumItalyNigeria in behalf of the African groupMexicoColombiaIrelandCosta RicaSingapore
on: Protection of critical infrastructure and ransomware are priority topics for DTG 1 with broad support
The interconnected nature of cyberspace means security is a collective endeavour; no country can be safe from threats in isolation and we are only as strong as our weakest link
Arg. 6
Explanation
Brazil argues that the interconnected and transactional nature of cyberspace makes security fundamentally a collective endeavour, more so than in other domains. This means that no country can achieve safety from cyber threats by acting alone, and the overall security level is determined by the weakest link in the chain.
Evidence
Brazil stated that ‘the interconnected and transactional nature of cyberspace means that security is even more a collective endeavour than in other arenas’ and that ‘no country can be safe from threats in the digital domain in isolation’ and ‘we are only as strong as our weakest link’ .
Major Discussion Point
Digital Divide and Developing Countries’ Cyber Challenges
Generative AI use in misinformation and disinformation campaigns, including deepfakes, is of particular concern; in armed conflict contexts this could violate international humanitarian law
Arg. 7
Explanation
Brazil expresses particular concern about the use of generative AI in misinformation and disinformation campaigns, especially the use of deepfakes. In the context of armed conflict, such use could cause grave harm to civilians and would constitute a violation of international humanitarian law.
Evidence
Brazil stated it is ‘weakly concerned by the uses of generative AI in misinformation, and disinformation campaigns, particularly, but not limited to, the use of so-called deepfakes’ and that ‘in the context of an armed conflict, this could cause grave harm to civilians and would constitute a violation of international humanitarian law’ . Brazil also noted concern about AI use in electoral processes, where it poses a significant threat to states’ political stability .
Major Discussion Point
Cyber Threat Landscape – Artificial Intelligence and Emerging Technologies
Agreed with
Tonga on behalf of the Pacific Islands ForumNigeriaEstoniaTurkeyItalySwitzerlandUnited KingdomAlgeriaSerbiaVietnamSingaporeSouth AfricaMexico
on: AI is fundamentally reshaping the cyber threat landscape, increasing the scale, speed, and sophistication of malicious cyber activities
Disagreed with
SwitzerlandTurkeyEstonia
on: Whether existing voluntary norms and CBMs are sufficient to address AI-related cyber challenges, or whether new norms are needed
Discussions currently underway in ad hoc processes outside the UN on ransomware, AI implications, and intrusive tools must be integrated into the global mechanism; keeping discussions within like-minded groups reduces their reach and legitimacy
Arg. 8
Explanation
Brazil argues that discussions on key cyber issues such as ransomware, AI implications for cybersecurity, and intrusive tools that are currently taking place in ad hoc processes outside the UN must be integrated into the global mechanism. The borderless nature of these threats requires the engagement of all nations, and keeping discussions within like-minded groups reduces their reach, effectiveness, and legitimacy.
Evidence
Brazil stated that ‘discussions currently underway in ad hoc processes outside the UN on issues such as ransomware, AI implications to cybersecurity or intrusive tools, must be integrated to the global mechanism’ and that ‘keeping discussions within the echo chambers of our like-minded groups will reduce their reach, effectiveness, and legitimacy’ .
DTG 1's broad mandate requires either consensus on specific topics or the right of countries to propose topics; decisions on topics should not be made by the Chair or select individuals without consensus
Arg. 1
Explanation
China argues that because DTG 1 has a broad mandate on which consensus could not be reached during OEWG negotiations, the selection of topics must either be agreed by consensus or allow all countries to propose topics they consider important. The Chair or select individuals should not unilaterally decide which topics have received sufficient support for discussion.
Evidence
China noted that ‘when we were negotiating the final document of the OEWG, we couldn’t reach a consensus on the mandate of DTG 1’ and that ‘countries all have their preferences and priorities’ . China explicitly stated that ‘there shouldn’t be such a procedure by which the chair or certain people will decide that certain topics seem to have received more support and therefore they deserve our discussions’ as ‘such a practice is to turn consensus into certain kind of voting’ .
Major Discussion Point
Structure and Functioning of Dedicated Thematic Groups (DTGs)
Disagreed with
BrazilKiribatiNew ZealandGermanyChile
on: Decision-making process for selecting DTG 1 topics
The appointment of co-facilitators without consensus deviates from established UN practice in this domain; over 20-30 years, facilitators were never appointed without consensus in cyber discussions
Arg. 2
Explanation
China argues that the appointment of co-facilitators without consensus is not consistent with the established practice of this global mechanism. Over the 20-30 year history of cyber issues at the UN, facilitators were never appointed without consensus, making this a deviation from established practice.
Evidence
China stated that ‘cyber issue became a UN topic in 1998, it’s been 20-30 years and over this history we never saw the appointment of facilitators without consensus’ and therefore ‘this is not a practice of the global mechanism’ .
Major Discussion Point
Appointment of Co-facilitators and Consensus Principle
Disagreed with
BelarusRepublic of KoreaGermanyChileKiribati
on: Appointment of co-facilitators and the consensus principle
NGO participation should not be introduced into the global mechanism without consensus; the mechanism's conclusions must be accepted by all countries to be globally significant
Arg. 3
Explanation
China argues that while NGOs can hold their own discussions and countries can learn from their experiences, introducing NGO participation into the global mechanism without consensus is problematic. The mechanism's conclusions need to be accepted by all countries to carry global significance.
Evidence
China noted that many countries hope NGOs can join discussions, and that interested countries can voluntarily attend NGO conferences and bring back useful experiences as national practice . However, China questioned why this practice must be introduced into the global mechanism, stating that ‘the key is whether the NGO’s participation is useful or not’ and whether it respects ‘an important practice of this global mechanism, which has been developed over the last 20 or 30 years’ .
Major Discussion Point
Stakeholder Participation in the Global Mechanism
Disagreed with
KiribatiGermanyArgentinaFranceOmanEuropean Union
on: Stakeholder and NGO participation in the global mechanism
DTGs should build on already agreed frameworks rather than relitigating settled questions, focusing on implementation rather than reopening consensus
Arg. 1
Explanation
Kiribati argues that the DTGs should take the existing consensus framework as their starting point and devote their energy to implementation rather than reopening questions that have already been settled. The cumulative and evolving framework for responsible state behaviour, reaffirmed through successive OEWG reports, is the common foundation.
Evidence
Kiribati stated that ‘the DTGs should take that consensus as their starting point and devote their energy to implementation rather than relitigating questions that the membership has already settled’ . Kiribati referenced the framework reaffirmed through successive OEWG reports and carried into the mechanism through Annex 1 of A-80-257 and Annex C of A-79-214 .
Major Discussion Point
Structure and Functioning of Dedicated Thematic Groups (DTGs)
Agreed with
ArgentinaNew ZealandCroatiaNigeria in behalf of the African group
on: DTGs should build on existing agreed frameworks and focus on implementation rather than relitigating settled questions
The current situation regarding co-facilitator appointment should be resolved swiftly and in a spirit of consensus so that DTGs can begin substantive work in December as planned
Arg. 2
Explanation
Kiribati acknowledges the concerns raised by some delegations regarding the establishment of co-facilitators but does not seek to reopen that discussion. Its concern is practical: the matter should be resolved swiftly and in a spirit of consensus so that the DTGs can begin their substantive work in December as planned.
Evidence
Kiribati stated that ‘however this matter is resolved, it is resolved swiftly and in a spirit of consensus, so that the dedicated thematic groups can begin their substantive work in December as planned’ . Kiribati noted that ‘for a small state that has placed its hopes in the promise that this mechanism will act, the outcome we most wish to avoid is one in which the intersessional period is lost to procedure’ .
Major Discussion Point
Appointment of Co-facilitators and Consensus Principle
Disagreed with
ChinaBelarusRepublic of KoreaGermanyChile
on: Appointment of co-facilitators and the consensus principle
DTG 1 should focus on a small number of concrete deliverables with broad support so that outputs are substantial enough to matter and focused enough to survive in the plenary
Arg. 3
Explanation
Kiribati argues that the DTGs cannot do everything at once, and delegations like theirs cannot follow an endless list of subtopics. The groups should prioritise a small number of concrete deliverables with broad support so that their outputs are both substantial enough to matter and focused enough to survive in the plenary.
Evidence
Kiribati stated that ‘the DDGs cannot do everything at once and delegations like ours cannot follow an endless list of subtopics’ and encouraged ‘the groups to prioritise a small number of concrete deliverables with broad support so that their outputs are substantial enough to matter and focused enough to survive in this plenary’ .
Major Discussion Point
Priority Topics for DTG 1
Agreed with
BrazilNew ZealandChileSingaporeTonga on behalf of the Pacific Islands ForumVietnam
on: DTGs should focus on a limited number of priority topics rather than attempting to cover everything at once
Disagreed with
ChinaBrazilNew ZealandGermanyChile
on: Decision-making process for selecting DTG 1 topics
There must be a clear and predictable way for DTG recommendations to be brought back to and taken up by the plenary; without this link, groups risk becoming discussions that lead nowhere
Arg. 4
Explanation
Kiribati stresses that for the work of the DTGs to carry weight, there must be a clear and predictable mechanism for their recommendations to be brought back to and taken up by the plenary. Without this link, the groups risk becoming discussions that lead nowhere.
Evidence
Kiribati stated that ‘for the work of the groups that carry away, there must be a clear and predictable way for the recommendations to be brought back to and taken up by this plenary’ and that ‘without that link, the group risks becoming discussions to lead nowhere’ . Kiribati also welcomed clarity on this point during the session .
Major Discussion Point
Reporting from DTGs to the Plenary
Agreed with
BrazilGermanySingaporeNetherlandsChile
on: There must be a clear and predictable mechanism for DTG recommendations to be brought back to and taken up by the plenary
Disagreed with
BrazilGermanySingaporeNetherlands
on: Reporting mechanism from DTGs to the plenary
The global mechanism should draw on expertise of stakeholders in line with agreed modalities, as practical implementation is where technical knowledge is most valuable
Arg. 5
Explanation
Kiribati argues that the DTGs should draw on the expertise of stakeholders in line with the modalities that have been agreed. This is particularly important because practical implementation is precisely where technical knowledge is most valuable.
Evidence
Kiribati stated that ‘the DDGs should draw on the expertise of stakeholders in line with the modalities we have agreed because practical implementation is precisely where the technical knowledge is most valuable’ .
Major Discussion Point
Stakeholder Participation in the Global Mechanism
Agreed with
BrazilGermanyArgentinaChileOmanFranceNigeria in behalf of the African groupSingapore
on: Stakeholder participation, including from the private sector, academia, and technical community, adds significant value to DTG discussions
Disagreed with
ChinaGermanyArgentinaFranceOmanEuropean Union
on: Stakeholder and NGO participation in the global mechanism
Protection of critical infrastructure and critical information infrastructure is a core priority for the Pacific, including the integrity of undersea cable infrastructure
Arg. 6
Explanation
Kiribati, speaking on behalf of Pacific states, highlights that the protection of critical infrastructure and critical information infrastructure is a core priority for the region. The integrity of undersea cable infrastructure is particularly vital as it represents the only link to the global internet for many Pacific states.
Evidence
Kiribati referenced the mechanism’s need to consolidate before expanding, noting that ‘we already have a framework, 11 agreed norms, and a body of confidence-building and capacity-building commitments’ and that ‘the immediate task is to make this operational’ .
Major Discussion Point
Priority Topics for DTG 1
139
WPM
227
Words
2 min
Time
Ransomware and the protection of critical infrastructure could serve as important agenda topics for DTG 1, given their growing significance
Arg. 1
Explanation
The Republic of Korea suggests that ransomware and the protection of critical infrastructure are particularly important topics for DTG 1 to address, given their growing significance and potential for the future. These topics have received broad support from member states.
Evidence
The Republic of Korea stated that ‘ransomware and the protection of critical infrastructure could serve as important agenda topics, particularly in light of their growing significance and potential for the future’ .
Major Discussion Point
Priority Topics for DTG 1
Agreed with
BrazilGermanyTonga on behalf of the Pacific Islands ForumItalyNigeria in behalf of the African groupMexicoColombiaIrelandCosta RicaSingapore
on: Protection of critical infrastructure and ransomware are priority topics for DTG 1 with broad support
The Republic of Korea is prepared to support the Chair's proposals where they are based on broad consultations with member states, recognising that multilateral processes cannot fully reflect every individual preference
Arg. 2
Explanation
The Republic of Korea acknowledges that the previous OEWG report may not explicitly address every procedural issue that may arise. It recognises that multilateral processes cannot fully reflect every individual preference and is therefore prepared to support the Chair's proposals where they are based on broad consultations with member states.
Evidence
The Republic of Korea stated that ‘we recognize that the previous OEWG report may not explicitly address every procedural issue that may arise during the work of the global mechanism’ and that ‘by its very nature, a multilateral process inevitably cannot fully reflect every individual preference of all member states’ . It expressed readiness to ‘support the Chair’s proposals where they are based on broad consultations with and due considerations of the views of member states’ .
Major Discussion Point
Appointment of Co-facilitators and Consensus Principle
Disagreed with
ChinaBelarusGermanyChileKiribati
on: Appointment of co-facilitators and the consensus principle
153
WPM
264
Words
2 min
Time
DTG meetings are informal by design, which provides space for inclusive and detailed discussions on novel or complex subjects not possible in formal meetings
Arg. 1
Explanation
New Zealand argues that the informality of DTG meetings is a deliberate feature, not a flaw. This informality provides space for inclusive and detailed discussions on novel or complex subjects in a way that is not possible during formal meetings, and will support the development of practical, action-oriented initiatives.
Evidence
New Zealand stated that ‘in accordance with Annex 1 of the final OEWG report DTG meetings are informal’ and that ‘this is a feature not a bug’ as ‘informality provides space for inclusive, detailed discussions on novel or complex subjects in a way that is not possible during formal meetings’ .
Major Discussion Point
Structure and Functioning of Dedicated Thematic Groups (DTGs)
Agreed with
KiribatiArgentinaCroatiaNigeria in behalf of the African group
on: DTGs should build on existing agreed frameworks and focus on implementation rather than relitigating settled questions
Disagreed with
ChinaBrazilKiribatiGermanyChile
on: Decision-making process for selecting DTG 1 topics
162
WPM
466
Words
3 min
Time
The appointment of co-facilitators is welcomed as the prerogative of the Chair; the working paper on DTGs provided valuable clarity on roles and responsibilities
Arg. 1
Explanation
Germany welcomes the appointment of co-facilitators of the dedicated thematic working groups, viewing it as the prerogative of the Chair. The working paper on DTGs provided valuable clarity on the roles and responsibilities of co-facilitators and how the Chair intends to work with them.
Evidence
Germany stated that it ‘welcomes the appointment of co-facilitators of the dedicated thematic working groups, which we continue to view as the prerogative of the Chair’ and that ‘your working paper on the DTGs provided valuable clarity on the roles and responsibilities of co-facilitators and how you intend to work with them under your leadership’ .
Major Discussion Point
Appointment of Co-facilitators and Consensus Principle
Disagreed with
ChinaBelarusRepublic of KoreaChileKiribati
on: Appointment of co-facilitators and the consensus principle
DTGs should have thematic cohesion, with both groups taking the same challenge as a starting point, proposed by the Chair and co-facilitators after consultation with states
Arg. 2
Explanation
Germany sees value in thematic cohesion between the meetings of DTG 1 and DTG 2, meaning that both groups should take the same challenge as a starting point. This challenge should be proposed by the Chair and co-facilitators after consultation with states.
Evidence
Germany stated that it ‘sees value in thematic cohesion between the meetings of DTG 1 and DTG 2, meaning that they should take the same challenge as a starting point’ and that ‘this challenge should be proposed by the Chair and the co-facilitators after consultation with States’ . Germany noted that two topics with broad support were the protection of critical infrastructure and addressing ransomware attacks targeting essential services such as the healthcare sector .
Major Discussion Point
Structure and Functioning of Dedicated Thematic Groups (DTGs)
Disagreed with
BrazilSingaporeChile
on: The autonomy and relationship between DTG 1 and DTG 2
Having stakeholders and their expertise at UN-level discussions benefits all, not only the organisations they belong to or the countries they come from; it enhances common understanding of challenges
Arg. 3
Explanation
Germany argues that having stakeholders and their expertise participate in discussions at the UN level would benefit all member states, not just the organisations they belong to or the countries they come from. This participation would also contribute to enhancing the common understanding of challenges.
Evidence
Germany stated that ‘having them and their expertise at the discussion at UN level would benefit all of us, not only the organization they happen to be part of or the country they happen to stem from’ and that ‘this would also contribute to enhancing the common understanding of challenges’ .
Major Discussion Point
Stakeholder Participation in the Global Mechanism
Agreed with
BrazilKiribatiArgentinaChileOmanFranceNigeria in behalf of the African groupSingapore
on: Stakeholder participation, including from the private sector, academia, and technical community, adds significant value to DTG discussions
Disagreed with
ChinaKiribatiArgentinaFranceOmanEuropean Union
on: Stakeholder and NGO participation in the global mechanism
Co-facilitators could provide an oral update at the next plenary on preceding DTG discussions; written action-oriented consensus recommendations could also be transmitted in writing for consideration
Arg. 4
Explanation
Germany proposes a dual reporting mechanism from DTGs to the plenary. Co-facilitators could provide an oral update at the next plenary meeting on the discussions that took place at the preceding DTG meeting, while written action-oriented consensus recommendations could also be transmitted in writing for consideration.
Evidence
Germany stated that ‘co-facilitators and or you, Madam Chair, could provide an oral update at the next plenary meeting on the discussions that we had at the preceding DTG meeting’ and that ‘written action-oriented consensus recommendations could be transmitted in writing to the plenary for consideration, provided that they were agreed by states in the spirit of consensus’ . Germany also suggested that ‘a neutral summary of proceedings report by the Secretariat could also be issued’ .
Major Discussion Point
Reporting from DTGs to the Plenary
Agreed with
BrazilKiribatiSingaporeNetherlandsChile
on: There must be a clear and predictable mechanism for DTG recommendations to be brought back to and taken up by the plenary
Disagreed with
BrazilSingaporeNetherlandsKiribati
on: Reporting mechanism from DTGs to the plenary
Protection of critical infrastructure and addressing ransomware attacks targeting essential services such as healthcare are topics with broad support from numerous delegations
Arg. 5
Explanation
Germany identifies two topics that have received broad support from numerous delegations during consultations: the protection of critical infrastructure and addressing ransomware attacks targeted at essential services such as the healthcare sector. These are proposed as priority topics for the DTGs.
Evidence
Germany stated that ‘two topics with numerous delegations echoed over the course of consultation so far were the protection of critical infrastructure as well as addressing ransomware attacks targeted at essential services such as the healthcare sector’ .
Major Discussion Point
Priority Topics for DTG 1
Agreed with
BrazilRepublic of KoreaTonga on behalf of the Pacific Islands ForumItalyNigeria in behalf of the African groupMexicoColombiaIrelandCosta RicaSingapore
on: Protection of critical infrastructure and ransomware are priority topics for DTG 1 with broad support
The plenary, DTGs, and intersessional activities should remain coherent, mutually reinforcing, transparent, and focused on practical outcomes while avoiding duplication
Arg. 1
Explanation
Croatia argues that the plenary, dedicated thematic groups, and intersessional activities should work together in a coherent and mutually reinforcing manner. They should be transparent and focused on practical outcomes, while avoiding duplication and preserving the ability of all delegations to participate meaningfully.
Evidence
Croatia stated that ‘the plenary, the dedicated thematic groups, and intersessional activities should remain coherent and mutually reinforcing, transparent, and focused on practical outcomes, while avoiding duplication and preserving the ability of all delegations to participate meaningfully’ .
Major Discussion Point
Structure and Functioning of Dedicated Thematic Groups (DTGs)
Agreed with
KiribatiArgentinaNew ZealandNigeria in behalf of the African group
on: DTGs should build on existing agreed frameworks and focus on implementation rather than relitigating settled questions
139
WPM
678
Words
5 min
Time
DTGs constitute the most important opportunity to move from normative consensus to practical implementation; their success should be measured by contribution to effective implementation, not volume of documents produced
Arg. 1
Explanation
Argentina believes that the dedicated thematic groups represent one of the most important opportunities the global mechanism provides to move from normative consensus to practical implementation. The success of these groups should not be measured by the amount of documents they produce, but by their capacity to contribute to the effective implementation of the consensus already reached.
Evidence
Argentina stated that ‘the dedicated thematic groups constitute one of the most important opportunities that the global mechanism provides in order to make progress from a normative point of view to the practical implementation of the global mechanism on responsible state behaviour’ . Argentina further stated that ‘the success of the thematic groups should not be measured by the amount of documents they produce, but rather by their capacity to contribute to the effective implementation of the consensus already reached’ .
Major Discussion Point
Structure and Functioning of Dedicated Thematic Groups (DTGs)
Agreed with
KiribatiNew ZealandCroatiaNigeria in behalf of the African group
on: DTGs should build on existing agreed frameworks and focus on implementation rather than relitigating settled questions
Participation of technical experts from academia, private sector, and technical community would make deliberations more fruitful; accreditation should use existing UN institutional systems
Arg. 2
Explanation
Argentina attaches particular importance to the participation of the technical community in the DTGs, arguing that deliberations will be significantly more fruitful with experts from academia, the private sector, and technical institutions. For civil society organisations, Argentina suggests using already consolidated institutional accreditation systems within the UN system.
Evidence
Argentina stated that it is ‘convinced that our deliberations will be significantly more fruitful if we have experts from academia, the private sector and the DTGs’ and that ‘the experience of those who develop, operate and protect the digital ecosystem is an essential input for us to be able to make headway towards technically robust and operationally useful solutions’ . Argentina suggested ‘using already consolidated institutional accreditation systems within the UN system’ for civil society organisations .
Major Discussion Point
Stakeholder Participation in the Global Mechanism
Agreed with
BrazilKiribatiGermanyChileOmanFranceNigeria in behalf of the African groupSingapore
on: Stakeholder participation, including from the private sector, academia, and technical community, adds significant value to DTG discussions
Disagreed with
ChinaKiribatiGermanyFranceOmanEuropean Union
on: Stakeholder and NGO participation in the global mechanism
Stakeholder participation should be developed on transparent, neutral, and predictable criteria ensuring technical contributions with adequate geographical diversity
Arg. 3
Explanation
Argentina argues that while stakeholder participation is important, it should be strengthened through transparent, neutral, and predictable criteria. These criteria should enable consideration of the technical nature of contributions while ensuring adequate geographical diversity and full respect for the intergovernmental nature of the mechanism.
Evidence
Argentina stated that ‘the participation of other interested parties will be strengthened if we continue to develop it on transparent, neutral and predictable criteria that enable us to consider the technical nature of contributions with adequate geographical diversity in full respect for the intergovernmental nature of the mechanism’ .
Major Discussion Point
Stakeholder Participation in the Global Mechanism
Agreed with
BrazilKiribatiGermanyChileOmanFranceNigeria in behalf of the African groupSingapore
on: Stakeholder participation, including from the private sector, academia, and technical community, adds significant value to DTG discussions
128
WPM
484
Words
4 min
Time
Chile fully supports the nomination of co-facilitators as inclusive, well-balanced, and in line with UN practice
Arg. 1
Explanation
Chile expresses full support for the nomination of co-facilitators of the DTGs, viewing it as inclusive, well-balanced, and in line with UN practice. Chile commits to actively supporting the work that the co-facilitators will engage in.
Evidence
Chile stated that ‘for us, it’s inclusive and well-balanced and in line with UN practice, and that’s why we will actively support the work that they engage in’ .
Major Discussion Point
Appointment of Co-facilitators and Consensus Principle
Disagreed with
ChinaBelarusRepublic of KoreaGermanyKiribati
on: Appointment of co-facilitators and the consensus principle
DTGs should have a clear and predictable programme of work for the biennium, drafted through consultations, with guiding questions or specific themes prepared by co-facilitators for each session
Arg. 2
Explanation
Chile argues that each DTG should have a clear and predictable programme of work for the biennium, drafted through consultations with participating states. For DTG 1, given the breadth of its mandate, the work could benefit from progressive limits on themes addressed in each meeting, with guiding questions or specific themes prepared by co-facilitators.
Evidence
Chile stated that ‘it’s important for each DTG to have a clear and predictable program of work for the biennium drafted through consultations with the states participating in them that’s sufficiently flexible to be able to respond to the changes in the ICT sector’ . Chile also noted that DTG 1 ‘could use guiding questions or specific themes prepared by the co-facilitators for each session, and this would involve consultations with states’ .
Major Discussion Point
Structure and Functioning of Dedicated Thematic Groups (DTGs)
Agreed with
BrazilKiribatiGermanySingaporeNetherlands
on: There must be a clear and predictable mechanism for DTG recommendations to be brought back to and taken up by the plenary
Disagreed with
ChinaBrazilKiribatiNew ZealandGermany
on: Decision-making process for selecting DTG 1 topics
The creation of DTG 2 recognises the strategic importance of capacity building to strengthen implementation of the framework for responsible state behaviour and respond to needs of developing states
Arg. 3
Explanation
Chile particularly underscores the creation of DTG 2 on capacity building, viewing it as recognition of the strategic importance of this pillar. DTG 2 is seen as essential to strengthening the implementation of the framework for responsible state behaviour and responding to the needs and priorities of all states, particularly developing states.
Evidence
Chile stated that ‘the creation of DTG2 on capacity building’ is ‘recognition of the strategic importance of this pillar to strengthen the implementation of the framework for responsible state behaviour and to be able to respond to the needs and priorities of all states, in particular the priorities and needs of developing states’ .
Major Discussion Point
Capacity Building as a Priority (DTG 2)
Agreed with
BrazilNigeria in behalf of the African groupSingaporeSaudi ArabiaKazakhstan
on: Capacity building is a strategic cross-cutting priority, and DTG 2 is a key platform for advancing practical cooperation and concrete outcomes
Stakeholder participation should be developed on transparent, neutral, and predictable criteria ensuring technical contributions with adequate geographical diversity
Arg. 4
Explanation
Chile believes that the participation of technical experts and other stakeholders could bring significant added value to DTG discussions, strengthening the exchange of specialised knowledge and practical experience. Chile aligns with Colombia's approach to use multilingualism to facilitate broad participation of experts.
Evidence
Chile stated that ‘the participation of technical experts and other stakeholders could bring significant added value to these discussions, strengthening the exchange of specialized knowledge and practical experience’ and aligned ‘with Colombia’s approach to use multilingualism to facilitate the broad participation of experts’ .
Major Discussion Point
Stakeholder Participation in the Global Mechanism
Agreed with
BrazilKiribatiGermanyArgentinaOmanFranceNigeria in behalf of the African groupSingapore
on: Stakeholder participation, including from the private sector, academia, and technical community, adds significant value to DTG discussions
144
WPM
1105
Words
8 min
Time
DTGs should allow comprehensive discussion where countries can express a wide range of views, with focused topics enabling small states to better prepare given limited resources
Arg. 1
Explanation
Singapore argues that it would be productive for DTGs to allow comprehensive discussion where countries can express a wide range of views on key topics of interest. Having focused discussions would allow small states to better prepare, given their limited resources, and would allow the DTGs to best serve their purpose of adding perspectives and enhancing the depth of plenary discussions.
Evidence
Singapore stated that ‘it would be productive for a comprehensive discussion during the DTGs where countries could express a wide range of views on key topics of interest to states expressed during plenary meetings, which could then be reported to the plenary in their totality’ . Singapore noted that ‘having focused discussions will allow small states to better prepare, given limited resources for discussions at the DTGs’ .
Major Discussion Point
Structure and Functioning of Dedicated Thematic Groups (DTGs)
Agreed with
BrazilKiribatiNew ZealandChileTonga on behalf of the Pacific Islands ForumVietnam
on: DTGs should focus on a limited number of priority topics rather than attempting to cover everything at once
Co-facilitators should provide a robust and comprehensive report on DTGs' work to the plenary; facilitators in consultation with states could transmit action-oriented draft recommendations
Arg. 2
Explanation
Singapore encourages co-facilitators to provide a robust and comprehensive report on the DTGs' work to the plenary. Recalling the relevant provisions of the final OEWG report, Singapore notes that facilitators in consultation with states could also transmit action-oriented draft recommendations for consideration by states.
Evidence
Singapore recalled ‘Para 12 of Annex 1 and the final report of the OECD’ noting that ‘the DTGs would report to their substantive plenary sessions with updates and recommendations’ and that ‘the facilitators of the DTGs in consultation with states could also transmit action-oriented draft recommendations for consideration by states’ .
Major Discussion Point
Reporting from DTGs to the Plenary
Agreed with
BrazilKiribatiGermanyNetherlandsChile
on: There must be a clear and predictable mechanism for DTG recommendations to be brought back to and taken up by the plenary
Disagreed with
BrazilGermanyNetherlandsKiribati
on: Reporting mechanism from DTGs to the plenary
Ransomware continues to be one of the most acute and pervasive threats; the ransomware ecosystem has evolved and fragmented, shaped by law enforcement pressure and internal competition
Arg. 3
Explanation
Singapore highlights that ransomware activity has continued to surge globally, with cybersecurity researchers reporting close to 8,000 cases worldwide in 2025. The ransomware ecosystem has evolved and fragmented, shaped by intensifying law enforcement pressure, internal competition, and weak affiliate loyalty.
Evidence
Singapore stated that ‘globally, ransomware activity has continued to surge’ with ‘cybersecurity researchers have reported close to 8,000 cases worldwide based on data leak site postings’ in 2025 . Singapore noted that ‘the ransomware ecosystem has also continued to evolve and fragment, shaped in part by intensifying law enforcement pressure, internal competition, and weak affiliate loyalty’ .
Major Discussion Point
Cyber Threat Landscape – Ransomware and Critical Infrastructure
Agreed with
BrazilRepublic of KoreaGermanyTonga on behalf of the Pacific Islands ForumItalyNigeria in behalf of the African groupMexicoColombiaIrelandCosta Rica
on: Protection of critical infrastructure and ransomware are priority topics for DTG 1 with broad support
Quantum computing threatens existing cryptographic systems; threat actors are expected to exploit quantum computing to break encryption, necessitating migration to quantum-safe cryptography
Arg. 4
Explanation
Singapore highlights that quantum computing presents both remarkable opportunities and significant security risks. Threat actors are expected to exploit quantum computing to break encryption, putting sensitive data and digital trust at risk, necessitating migration to quantum-safe cryptography before quantum computers become powerful enough to break current systems.
Evidence
Singapore stated that ‘quantum computing has the potential to transform fields like scientific research, medicine, logistics and communications, it also threatens the existing cryptographic systems that secure our digital infrastructure today’ . Singapore noted that ‘threat actors are expected to exploit quantum computing to break encryption, putting sensitive data and digital trust at risk, therefore necessitating migration to quantum-safe cryptography before quantum computers become powerful enough to break today’s system’ .
Major Discussion Point
Cyber Threat Landscape – Artificial Intelligence and Emerging Technologies
Agreed with
BrazilTonga on behalf of the Pacific Islands ForumNigeriaEstoniaTurkeyItalySwitzerlandUnited KingdomAlgeriaSerbiaVietnamSouth AfricaMexico
on: AI is fundamentally reshaping the cyber threat landscape, increasing the scale, speed, and sophistication of malicious cyber activities
Cyber threats affect not only national security but also the economic well-being and ability of many states; attacks on hospitals illustrate how cyber operations go beyond technical damage and directly affect people
Arg. 5
Explanation
Singapore emphasises that cyber threats, including attacks by APTs, ransomware, and threats to emerging technology, threaten not just national security but also the economic well-being and ability of many states. The protection of critical information infrastructure is described as a national and global responsibility.
Evidence
Singapore stated that ‘the rise in cyber threats including attacks by APTs or advanced persistent threats the increase in ransomware as well as threats to emerging technology continue to threaten not just national security but also the economic well-being and ability of many states’ . Singapore described the protection of critical information infrastructure as ‘not a technical task’ but ‘a national and global responsibility’ .
Major Discussion Point
Human Dimension of Cyber Threats
DTG 2 should look at the capacity building required to support efforts in addressing AI cyber risks, ransomware, and protection of critical information infrastructure
Arg. 6
Explanation
Singapore argues that DTG 2 should focus on the capacity building required to support member states' efforts in addressing key cyber challenges. These include AI cyber risks, ransomware, and the protection of critical information infrastructure, ensuring coherence between the work of the two DTGs.
Evidence
Singapore stated that ‘DTG 2 could then look at the capacity building required to support our efforts in these domains’ after encouraging DTG 1 to ensure that areas including AI cyber risks, ransomware, and protection of critical information infrastructure feature prominently in discussions .
Major Discussion Point
Capacity Building as a Priority (DTG 2)
Agreed with
BrazilChileNigeria in behalf of the African groupSaudi ArabiaKazakhstan
on: Capacity building is a strategic cross-cutting priority, and DTG 2 is a key platform for advancing practical cooperation and concrete outcomes
Disagreed with
BrazilGermanyChile
on: The autonomy and relationship between DTG 1 and DTG 2
176
WPM
372
Words
2 min
Time
General Assembly Resolutions 79/237 and 80/16 establish consensus as the fundamental principle for decision-making; deviating from this is unacceptable for states or the Chair
Arg. 1
Explanation
Belarus argues that General Assembly Resolutions 79/237 and 80/16 have already set out the fundamental principle for decision-making by the global mechanism, which is consensus. Deviating from this consensus principle is unacceptable, whether by states or by the Chair.
Evidence
Belarus stated that ‘General Assembly Resolutions 79, 237, and 80-16 have already set out the fundamental principle for decision-making by our body, and that is consensus’ and that ‘deviating from that view, from that consensus principle, in our view is something that is not acceptable, neither for states nor for the chair’ . Belarus also noted that ‘an entire group of states distanced itself from the procedure used to appoint coordinators for the DTGs’ .
Major Discussion Point
Appointment of Co-facilitators and Consensus Principle
Disagreed with
ChinaRepublic of KoreaGermanyChileKiribati
on: Appointment of co-facilitators and the consensus principle
106
WPM
752
Words
7 min
Time
The global mechanism must remain state-led, single-track, and consensus-based, with consensus serving as a driver of progress
Arg. 1
Explanation
The African group emphasises that the global mechanism must remain state-led, single-track, and consensus-based. Consensus should serve as a driver of progress rather than an obstacle, ensuring that the mechanism advances in a manner acceptable to all member states.
Evidence
The African group stated that ‘the mechanism must remain state-led, single-track, and conscious-based, with consensus serving as a driver of progress rather than an obstacle to hate’ .
Major Discussion Point
Structure and Functioning of Dedicated Thematic Groups (DTGs)
Agreed with
KiribatiArgentinaNew ZealandCroatia
on: DTGs should build on existing agreed frameworks and focus on implementation rather than relitigating settled questions
DTG 2 is a key platform for advancing practical cooperation, confidence-building measures, and capacity building, and should be allocated adequate time to contribute to concrete and measurable outcomes
Arg. 2
Explanation
The African group considers DTG 2 a key platform for advancing practical cooperation, confidence-building measures, and capacity building. DTG 2 should be allocated adequate time to effectively contribute to concrete and measurable outcomes.
Evidence
The African group stated that ‘DDG2 should be allocated adequate time that will effectively contribute to concrete and measurable outcomes’ including ‘early operationalization of the global ICT security cooperation and capacity building portal’ and ‘the point of contact directory’ .
Capacity building is a strategic cross-cutting priority requiring sustainable, need-based support particularly for developing countries
Arg. 3
Explanation
The African group identifies capacity building as a strategic cross-cutting priority that requires sustainable, need-based support, particularly for developing countries. This is seen as essential for enabling all states to safely and securely benefit from digital technologies.
Evidence
The African group stated that ‘capacity building is a strategic cross-cutting priority requiring sustainable need-based support, particularly for developing countries’ .
Major Discussion Point
Capacity Building as a Priority (DTG 2)
Agreed with
BrazilChileSingaporeSaudi ArabiaKazakhstan
on: Capacity building is a strategic cross-cutting priority, and DTG 2 is a key platform for advancing practical cooperation and concrete outcomes
DTG 1 should advance focused discussions on critical infrastructure protection, evolving threats, responsible approaches to emerging technologies, norm implementation, and practical cooperation
Arg. 4
Explanation
The African group argues that DTG 1 should advance focused discussions on several key areas, including critical infrastructure protection, evolving threats, responsible approaches to emerging technologies, norm implementation, and practical cooperation among member states.
Evidence
The African group stated that ‘DTJ1 should advance focused discussions on critical infrastructural protection, evolving threat, responsible approaches to emerging technologies, norm implementation, and practical cooperation among member states’ .
Major Discussion Point
Priority Topics for DTG 1
Agreed with
BrazilRepublic of KoreaGermanyTonga on behalf of the Pacific Islands ForumItalyMexicoColombiaIrelandCosta RicaSingapore
on: Protection of critical infrastructure and ransomware are priority topics for DTG 1 with broad support
International law, including the UN Charter, applies fully to the use of ICTs and remains fundamental to maintaining international peace, security, and stability
Arg. 5
Explanation
The African group reaffirms that international law, including the Charter of the United Nations, applies fully to the use of ICTs and remains fundamental to maintaining international peace, security, and stability. The group underscores the principles of sovereignty, due diligence, and non-intervention.
Evidence
The African group stated that ‘international law, including the Charter of the United Nations, applies fully to the use of ICT and remains fundamental to maintaining international peace, security, and stability’ . The group also underscored ‘the principle of sovereignty, due diligence, and non-intervention, as well as the applicability of international norms’ .
Major Discussion Point
Application of International Law in Cyberspace
Agreed with
FrancePortugalAlgeriaSwitzerland
on: International law, including the UN Charter, applies fully to the use of ICTs and is fundamental to maintaining international peace and security
Disagreed with
CubaFrancePortugalAfrican group (Nigeria)
on: Whether new legally binding instruments are needed to address cyber threats
Africa's existing instruments including the Malabo Convention and the Common African Position on the Application of International Law in Cyberspace provide a solid basis for the continent's contribution to the global framework
Arg. 6
Explanation
The African group highlights that Africa's existing instruments, including the Malabo Convention and the Common African Position on the Application of International Law in Cyberspace, provide a solid basis for the continent's contribution to the global framework. The African Union is also at an advanced stage of validating AU guidelines for the implementation of norms of responsible state behaviour.
Evidence
The African group stated that ‘Africa’s existing instruments, including the Malabo Convention and the Common African Position on the Application of International Law in Cyberspace, provide solid basis for the continent’s contribution to the global framework’ . The group noted that ‘the African Union is at an advanced stage of validating the AU guidelines for the implementation of norms of responsible state behavior in cyberspace and the Declaration on Peace and Security in Cyberspace’ .
Major Discussion Point
Regional Frameworks and International Cooperation
The African Union is at an advanced stage of validating AU guidelines for the implementation of norms of responsible state behaviour in cyberspace and the Declaration on Peace and Security in Cyberspace
Arg. 7
Explanation
The African group notes that the African Union is at an advanced stage of validating AU guidelines for the implementation of norms of responsible state behaviour in cyberspace and the Declaration on Peace and Security in Cyberspace. These instruments will provide practical guidance to member states on implementing the UN Framework for Responsible State Behaviour.
Evidence
The African group stated that ‘the African Union is at an advanced stage of validating the AU guidelines for the implementation of norms of responsible state behavior in cyberspace and the Declaration on Peace and Security in Cyberspace’ and that ‘these instruments will provide practical guidance to member states on implementing the UN Framework for Responsible State Behavior while reflecting African peace and security priorities’ .
Major Discussion Point
Regional Frameworks and International Cooperation
129
WPM
416
Words
3 min
Time
DTGs should be structured around concrete, action-oriented work items including fictional scenarios pertaining to specific cyber threats, with guiding questions prompting states to consider responsible state behaviour
Arg. 1
Explanation
The Netherlands argues that structuring DTGs along the lines of concrete and action-oriented work items, including fictional scenarios pertaining to specific cyber threats or dilemmas, will help make the DTGs more effective. Guiding questions can then prompt states to consider what responsible state behaviour looks like within a given context.
Evidence
The Netherlands stated that ‘structuring the DTGs along the lines of concrete and action-oriented work items, including fictional scenarios pertaining to a specific cyber threat or dilemma will help considerably to make the DDGs more effective’ . The Netherlands noted that ‘guiding questions can then prompt states to answer for themselves what responsible state behavior, in line with the normative framework, looks like within a given context’ .
Major Discussion Point
Structure and Functioning of Dedicated Thematic Groups (DTGs)
Co-facilitators should report firmly to the plenary on DTG results; negotiating written recommendations would place a heavy burden on delegations and reduce time for substantive work
Arg. 2
Explanation
The Netherlands argues that it is most effective for co-facilitators to report firmly to the plenary on the results of the DTGs. Negotiating language on written recommendations would place a heavy burden on delegation resources and significantly reduce the time available within the DTGs for substantive work, especially affecting smaller delegations.
Evidence
The Netherlands stated that ‘it’s the most effective if co-facilitated report firmly to the plenary on the results of the DDGs’ and that ‘negotiating language on written recommendations would place a heavy burden on delegation resources and significantly reduce the time available within the DDGs for substantive work, which especially affects smaller delegations’ .
Major Discussion Point
Reporting from DTGs to the Plenary
Agreed with
BrazilKiribatiGermanySingaporeChile
on: There must be a clear and predictable mechanism for DTG recommendations to be brought back to and taken up by the plenary
Disagreed with
BrazilGermanySingaporeKiribati
on: Reporting mechanism from DTGs to the plenary
116
WPM
404
Words
3 min
Time
Ransomware remains a severe and growing concern for Pacific states; protection of critical infrastructure and critical information infrastructure is a core priority
Arg. 1
Explanation
Tonga, speaking on behalf of the Pacific Islands Forum, highlights that ransomware remains a severe and growing concern for Pacific states. The protection of critical infrastructure and critical information infrastructure is a core priority for the Pacific, and the mechanism's DTG 1 should take this up as an early focus topic.
Evidence
Tonga stated that ‘ransomware remains a severe and growing concern for Pacific states’ and that ‘the protection of critical infrastructure and critical information infrastructure is a core priority for the Pacific, and one we would encourage this mechanism, and dedicated the Medic Group 1 in particular, to take up as an early focus topic’ . Tonga noted that ‘many of our essential services, from health to finance to government administration, now depend on a small number of systems whose disruption would be felt immediately and across the whole of society’ .
Major Discussion Point
Cyber Threat Landscape – Ransomware and Critical Infrastructure
AI-related cybersecurity threats are a potential area for practical discussion; AI may increase the speed, scale, and accessibility of malicious cyber activity including social engineering and automated vulnerability discovery
Arg. 2
Explanation
Tonga identifies AI-related cybersecurity threats as another potential area for practical discussion as part of the threat pillar of the mechanism's work. AI may increase the speed, scale, and accessibility of malicious cyber activity, including through more convincing social engineering, automated vulnerability discovery, disinformation, and the abuse of AI-enabled tools.
Evidence
Tonga stated that ‘AI may increase the speed, scale, and accessibility of malicious cyberactivity, including through more convincing social engineering, automated vulnerability discovery, disinformation, and the abuse of AI-enabled tools by criminal and other malicious actors’ .
Major Discussion Point
Cyber Threat Landscape – Artificial Intelligence and Emerging Technologies
on: AI is fundamentally reshaping the cyber threat landscape, increasing the scale, speed, and sophistication of malicious cyber activities
DTGs should focus on practical outputs such as accessible threat briefings, shared risk typologies, lessons from national and regional incidents, and best practice guidance
Arg. 3
Explanation
Tonga argues that DTG discussions should focus on practical outputs rather than simply restating that threats are growing. These outputs could include accessible threat briefings, shared risk typologies, lessons from national and regional incidents, or best practice guidance.
Evidence
Tonga stated that ‘in DTG 1, these could include accessible threat briefings, shared risk typologies, lessons from national and regional incidents, or best practice guidance’ . Tonga emphasised that ‘we do not need the global mechanism to simply restate that threats are growing’ but rather ‘to help states understand how those threats affect them, what practical steps can reduce risk, and how international cooperation can support national and regional resilience’ .
Major Discussion Point
Structure and Functioning of Dedicated Thematic Groups (DTGs)
Agreed with
BrazilKiribatiNew ZealandChileSingaporeVietnam
on: DTGs should focus on a limited number of priority topics rather than attempting to cover everything at once
Protection of critical infrastructure and critical information infrastructure is a core priority for the Pacific, including the integrity of undersea cable infrastructure
Arg. 4
Explanation
Tonga highlights that the integrity of undersea cable infrastructure is vital to the Pacific's economic and social resilience, and in many cases represents the only link to the global internet. This infrastructure is increasingly at risk from natural hazards, man-made disasters, and malicious activity.
Evidence
Tonga stated that ‘the integrity of our undersea cable infrastructure, vital to our economic and social resilience, and in many cases our only link to the global Internet, is increasingly at risk from both natural hazards, man-made disasters, and malicious activity’ and that ‘for the Pacific, this is not an abstract vulnerability, but a lifeline’ .
Major Discussion Point
Priority Topics for DTG 1
135
WPM
532
Words
4 min
Time
Ransomware remains one of the most impactful cyber threats, mainly affecting small manufacturing companies with limited capacity, often causing prolonged service disruption
Arg. 1
Explanation
Italy highlights that ransomware remains one of the most impactful cyber threats, with attacks mainly affecting small manufacturing companies with limited capacity and often causing prolonged service disruption. Italy has seen a significant increase in cyber events and incidents targeting the public sector.
Evidence
Italy stated that ‘Italy has seen last year an increase of cyber events by 38%, and incidents targeting the public sector by 68%’ and that ‘in the public sector, 75% of attacks were directed towards local and central administrations’ . Italy noted that ‘ransomware remains one of the most impactful cyber threats, and attacks by ransomware actors mainly affect small manufacturing companies with limited capacity, often causing prolonged service disruption’ .
Major Discussion Point
Cyber Threat Landscape – Ransomware and Critical Infrastructure
Agreed with
BrazilRepublic of KoreaGermanyTonga on behalf of the Pacific Islands ForumNigeria in behalf of the African groupMexicoColombiaIrelandCosta RicaSingapore
on: Protection of critical infrastructure and ransomware are priority topics for DTG 1 with broad support
Ransomware, the nexus between AI and cybersecurity, the role of non-state actors in malicious cyber activities, and cyber-resilient digital transformation are proposed topics for DTG 1
Arg. 2
Explanation
Italy proposes specific topics for discussion in DTG 1, including ransomware, the nexus between AI and cybersecurity, the role of non-state actors in malicious cyber activities, and cyber-resilient digital transformation. Italy stands ready to provide contributions through governmental bodies as well as through relevant stakeholders.
Evidence
Italy stated that it would ‘like to mention in particular the topics of ransomware, the nexus between AI and cybersecurity, and the role of non-state actors in Mauritius’ cyber activities, and cyber-resilient digital transformation as possible topics for discussion’ . Italy also highlighted the importance of ‘concrete exchanges we can have in DTG1 to deepen the understanding of specific threats, benefiting from the contribution of technical experts and other stakeholders’ .
Major Discussion Point
Priority Topics for DTG 1
Agreed with
BrazilTonga on behalf of the Pacific Islands ForumNigeriaEstoniaTurkeySwitzerlandUnited KingdomAlgeriaSerbiaVietnamSingaporeSouth AfricaMexico
on: AI is fundamentally reshaping the cyber threat landscape, increasing the scale, speed, and sophistication of malicious cyber activities
135
WPM
601
Words
4 min
Time
Nigeria confronts a broad spectrum of cyber threats including ransomware, malware, phishing, supply chain attacks, and attacks on critical information infrastructure and IoT systems
Arg. 1
Explanation
Nigeria highlights that it confronts a broad spectrum of cyber threats, including ransomware, malware, phishing, business email compromise, supply chain attacks, data breaches, and attacks on cloud infrastructure, critical information infrastructure, and Internet of Things systems. The malicious use of AI has further amplified these risks.
Evidence
Nigeria stated that it ‘continues to confront a broad spectrum of cyber threats, including ransomware, malware, phishing, business email consumption, compromised supply chain attacks, data breaches, attacks on cloud infrastructure, critical information infrastructure and Internet of Things systems’ . Nigeria noted that ‘the malicious use of artificial intelligence has further amplified further risks through deepfakes, synthetic media, identity theft, online fraud, disinformation, and other forms of cyber-enabled crime’ .
Major Discussion Point
Cyber Threat Landscape – Ransomware and Critical Infrastructure
The malicious use of AI has amplified risks through deepfakes, synthetic media, identity theft, online fraud, and disinformation
Arg. 2
Explanation
Nigeria highlights that the malicious use of artificial intelligence has further amplified cyber risks through deepfakes, synthetic media, identity theft, online fraud, disinformation, and other forms of cyber-enabled crime. These threats increasingly target critical sectors with significant economic and social consequences.
Evidence
Nigeria stated that ‘the malicious use of artificial intelligence has further amplified further risks through deepfakes, synthetic media, identity theft, online fraud, disinformation, and other forms of cyber-enabled crime’ . Nigeria noted that ‘these threats increasingly target critical sectors such as finance, energy, telecommunications, transportation, healthcare, electoral systems, and other essential public services with significant economic and social consequences’ .
Major Discussion Point
Cyber Threat Landscape – Artificial Intelligence and Emerging Technologies
Agreed with
BrazilTonga on behalf of the Pacific Islands ForumEstoniaTurkeyItalySwitzerlandUnited KingdomAlgeriaSerbiaVietnamSingaporeSouth AfricaMexico
on: AI is fundamentally reshaping the cyber threat landscape, increasing the scale, speed, and sophistication of malicious cyber activities
126
WPM
772
Words
6 min
Time
AI is increasing the frequency, sophistication, and strategic significance of malicious cyber activities; current AI models overwhelm many software providers, jeopardising timely vulnerability fixes
Arg. 1
Explanation
Switzerland reports that according to its national cyber security centre, the frequency, sophistication, and strategic significance of malicious cyber activities are increasing, a trend accelerated by the rapid development of large language models. Current AI models overwhelm many software providers, particularly open-source maintainers, jeopardising the ability to fix vulnerabilities in a timely manner.
Evidence
Switzerland stated that ‘according to the latest assessment by the Swiss National Cyber Security Center, the frequency, sophistication, and strategic significance of malicious cyber activities are increasing, a trend accelerated by the rapid development of large language models’ . Switzerland noted that ‘current AI models furthermore overwhelm many software providers, in particular open-source maintainers, jeopardizing the ability to fix vulnerabilities in a timely manner’ .
Major Discussion Point
Cyber Threat Landscape – Artificial Intelligence and Emerging Technologies
Agreed with
BrazilTonga on behalf of the Pacific Islands ForumNigeriaEstoniaTurkeyItalyUnited KingdomAlgeriaSerbiaVietnamSingaporeSouth AfricaMexico
on: AI is fundamentally reshaping the cyber threat landscape, increasing the scale, speed, and sophistication of malicious cyber activities
The use of proxies and the growing convergence between state interests and cyber criminal ecosystems poses an additional accountability challenge and increases risk to international peace and security
Arg. 2
Explanation
Switzerland highlights that the use of proxies and the growing convergence between state interests and cyber criminal ecosystems poses an additional accountability challenge. Malicious cyber operations are commonly routed through infrastructure in third countries to obfuscate their origin.
Evidence
Switzerland stated that ‘the use of proxies and the growing conversions between state interests and cyber criminal ecosystems poses an additional accountability challenge and increases risk to international peace and security’ . Switzerland noted that ‘malicious cyber operations are commonly routed through infrastructure-inferred countries, including rented servers and compromised consumer devices, to obfuscate their origin’ .
Major Discussion Point
State-Sponsored Cyber Activities and Use of Proxy Actors
Agreed with
European UnionEstoniaSwedenPortugalUnited Kingdom
on: The use of proxy actors by states undermines international security and is inconsistent with agreed UN norms of responsible state behaviour
Switzerland believes existing voluntary norms and CBMs are broad enough to address challenges posed by AI and cybersecurity; there is no need to adopt new voluntary norms or specific CBMs for AI
Arg. 3
Explanation
Switzerland argues that existing voluntary norms and confidence-building measures are broad enough to enable addressing the challenges posed by AI and cybersecurity. There is therefore no need to adopt new voluntary norms or specific CBMs specifically for AI.
Evidence
Switzerland stated that ‘in our view, there is no need to adopt new voluntary norms or specific CBMs for AI’ as ‘the existing ones were not created for any particular technology and are generally broad enough to enable us to address the challenges posed by AI and cybersecurity as well’ .
Major Discussion Point
Application of International Law in Cyberspace
Agreed with
Nigeria in behalf of the African groupFrancePortugalAlgeria
on: International law, including the UN Charter, applies fully to the use of ICTs and is fundamental to maintaining international peace and security
Disagreed with
TurkeyEstoniaBrazil
on: Whether existing voluntary norms and CBMs are sufficient to address AI-related cyber challenges, or whether new norms are needed
Switzerland actively works to prevent the misuse of infrastructure on its territory and stands ready to share its experience, consistent with the agreed norm that states should not knowingly allow their territory to be used for internationally wrongful acts
Arg. 4
Explanation
Switzerland highlights that it actively works to prevent the misuse of infrastructure on its territory, consistent with the agreed norm that states should not knowingly allow their territory to be used for internationally wrongful acts using ICTs. Switzerland stands ready to share its experience in this regard.
Evidence
Switzerland stated that ‘consistent with the agreed norm that states should not knowingly allow their territory to be used for internationally wrongful acts using ICTs, Switzerland actively has works to prevent the misuse of infrastructure on its territory and stands ready to share its experience in this regard’ . Switzerland also noted its experience with mandatory incident reporting and public-private information sharing as a concrete contribution to the capacity-building work of the mechanism .
Major Discussion Point
Regional Frameworks and International Cooperation
151
WPM
917
Words
6 min
Time
Non-state actors tolerated by, linked to, or controlled by states function as highly effective and deniable proxies; actively using or encouraging proxies is irresponsible behaviour contrary to UN norms
Arg. 1
Explanation
The EU highlights the growing trend of non-state actors being used as proxies by states, where the state keeps its distance to claim plausible deniability. Actively using or encouraging such proxies is irresponsible behaviour contrary to UN norms of responsible state behaviour, including the norm not to allow territory to be used for malicious cyber activities.
Evidence
The EU stated that ‘non-state actors that are tolerated by, linked to, or controlled by a state, that function and are leveraged as highly effective and deniable proxies’ and that ‘actively using or encouraging proxies is irresponsible behavior contrary to the UN norms of responsible state behavior to not allow your territory to be used for malicious cyber activities and to not target the critical infrastructure of others’ .
Major Discussion Point
State-Sponsored Cyber Activities and Use of Proxy Actors
Agreed with
EstoniaSwedenSwitzerlandPortugalUnited Kingdom
on: The use of proxy actors by states undermines international security and is inconsistent with agreed UN norms of responsible state behaviour
The EU and member states exposed and condemned Russia's use of an ecosystem including a government agency, private sector, hacktivists, and criminals to target the EU and its partners
Arg. 2
Explanation
The EU and its member states, alongside the United Kingdom, exposed and condemned Russia's use of an ecosystem of actors including a government agency, private sector entities, hacktivists, and criminals to target the EU, its member states, and partners through cyber attacks. The EU has imposed sanctions on individuals and entities supporting Russia's malicious behaviour.
Evidence
The EU stated that ‘last week, the EU and its member states alongside the United Kingdom exposed and condemned the misuse by Russia of an ecosystem of Russian actors including a government agency, private sector, hacktivists and criminals to target the EU, its member states and its partners consistently through cyber attacks’ . The EU noted that it ‘has therefore imposed sanctions on those individuals and entities that support Russia and their malicious behavior’ .
Major Discussion Point
State-Sponsored Cyber Activities and Use of Proxy Actors
Estonia objected to the stakeholder JSC Positive Technologies, known to support Russian cyber operations, as its participation contradicts the ambitions of the global mechanism
Arg. 3
Explanation
The EU references Estonia's objection to the stakeholder JSC Positive Technologies, which is already known to support Russian cyber operations. The EU argues that such participation contradicts the ambition of the global mechanism, and refers to Estonia's published letter giving transparency to the objection.
Evidence
The EU stated that ‘Estonia, supported by the EU and all member states, objected to the stakeholder JSC Positive Technologies, who we already knew was supporting Russian cyber operations’ and that this is ‘behavior that again contradicts the ambition of this global mechanism’ . The EU referred to ‘the letter published by Estonia, giving transparency to the objection provided’ .
Major Discussion Point
Stakeholder Participation in the Global Mechanism
Disagreed with
ChinaKiribatiGermanyArgentinaFranceOman
on: Stakeholder and NGO participation in the global mechanism
150
WPM
422
Words
3 min
Time
The evolving nexus between state and non-state actors raises questions regarding state responsibility, particularly where non-state actors act with varying degrees of state support
Arg. 1
Explanation
Sweden identifies the evolving nexus between state and non-state actors as an increasing concern. This raises questions regarding the responsibility of non-state actors and the relationship between malicious cyber activities conducted by non-state actors and state responsibility, particularly in situations where non-state actors act with varying degrees of state support.
Evidence
Sweden stated that ‘the evolving nexus between state and non-state actors is an increasing concern’ and that ‘it raises questions regarding the responsibility of non-state actors and the relationship between malicious cyber activities conducted by non-state actors and state responsibility, particularly in situations where non-state actors act with varying degrees of state support’ . Sweden welcomed ‘the latest EU cyber sanctions package adopted last week’ .
Major Discussion Point
State-Sponsored Cyber Activities and Use of Proxy Actors
Agreed with
European UnionEstoniaSwitzerlandPortugalUnited Kingdom
on: The use of proxy actors by states undermines international security and is inconsistent with agreed UN norms of responsible state behaviour
141
WPM
560
Words
4 min
Time
AI is fundamentally reshaping the cybersecurity landscape by increasing the scale, speed, and sophistication of malicious cyber activity; the global mechanism should address AI's impact within its mandate
Arg. 1
Explanation
Estonia argues that artificial intelligence is fundamentally reshaping the cybersecurity landscape and that the global mechanism should not ignore this impact. While the mechanism is not intended to negotiate international rules on AI governance, it should address AI's impact on the cyber threat landscape where it clearly falls within its mandate.
Evidence
Estonia stated that ‘artificial intelligence is fundamentally reshaping the cybersecurity landscape’ and that ‘the global mechanism should not ignore the impact of AI on the cyber threat landscape, but address it where it clearly falls within our mandate’ . Estonia noted that ‘under the first pillar of existing and emerging ICT threats, the dedicated thematic group should take into account that AI is increasing the scale, speed, and sophistication of malicious cyber activity’ .
Major Discussion Point
Cyber Threat Landscape – Artificial Intelligence and Emerging Technologies
Agreed with
BrazilTonga on behalf of the Pacific Islands ForumNigeriaTurkeyItalySwitzerlandUnited KingdomAlgeriaSerbiaVietnamSingaporeSouth AfricaMexico
on: AI is fundamentally reshaping the cyber threat landscape, increasing the scale, speed, and sophistication of malicious cyber activities
Disagreed with
SwitzerlandTurkeyBrazil
on: Whether existing voluntary norms and CBMs are sufficient to address AI-related cyber challenges, or whether new norms are needed
The growing use of proxy actors undermines international security and stability and is inconsistent with agreed UN norms that states should not knowingly allow their territory to be used for internationally wrongful cyber activities
Arg. 2
Explanation
Estonia highlights the growing use of proxy actors as a trend deserving particular attention. Such proxy models undermine international security and stability and are inconsistent with the agreed UN norms that states should not knowingly allow their territory or infrastructure to be used for internationally wrongful cyber activities.
Evidence
Estonia stated that ‘such proxy models undermine international security and stability, are inconsistent with the agreed UN norms that states should not knowingly allow their territory or infrastructure to be used for internationally wrongful cyber activities, or target the critical infrastructure of other states’ . Estonia noted that ‘ensuring states’ fair responsibility for using proxies to engage in malicious cyber activity is an important element of strengthening responsible behavior in cyberspace’ .
Major Discussion Point
State-Sponsored Cyber Activities and Use of Proxy Actors
Agreed with
European UnionSwedenSwitzerlandPortugalUnited Kingdom
on: The use of proxy actors by states undermines international security and is inconsistent with agreed UN norms of responsible state behaviour
160
WPM
473
Words
3 min
Time
Including non-state stakeholders will enable states to retain the central role that they currently play; excluding them risks making states marginal
Arg. 1
Explanation
France argues that including non-state stakeholders in the mechanism's work is essential for states to retain their central role. France goes so far as to suggest that excluding stakeholders would risk making states marginal in addressing cyber challenges, comparing cyber diplomacy to a team sport.
Evidence
France stated that ‘like in football, cyber diplomacy is a team sport, and non-state stakeholders also have a role to play if we want the mechanism to be relevant’ . France stated that ‘including them will enable states to retain the central role that they currently play, otherwise they will be marginal’ .
Major Discussion Point
Stakeholder Participation in the Global Mechanism
Agreed with
BrazilKiribatiGermanyArgentinaChileOmanNigeria in behalf of the African groupSingapore
on: Stakeholder participation, including from the private sector, academia, and technical community, adds significant value to DTG discussions
Disagreed with
ChinaKiribatiGermanyArgentinaOmanEuropean Union
on: Stakeholder and NGO participation in the global mechanism
France reaffirms its commitment to existing international law and the UN Charter; it regrets that those promoting an alternative treaty are also the first to violate this foundational text
Arg. 2
Explanation
France reaffirms its historic commitment to existing international law and the UN Charter as the foundation for responsible state behaviour in cyberspace. France expresses regret that those promoting an alternative treaty are also the first to violate this foundational text.
Evidence
France stated that it ‘reaffirms its historic commitment to existing international law and, in particular, to the UN Charter’ and that ‘my delegation regrets that those promoting an alternative treaty are also the first to violate this foundational text’ .
Major Discussion Point
Application of International Law in Cyberspace
Agreed with
Nigeria in behalf of the African groupPortugalAlgeriaSwitzerland
on: International law, including the UN Charter, applies fully to the use of ICTs and is fundamental to maintaining international peace and security
Disagreed with
CubaPortugalAfrican group (Nigeria)
on: Whether new legally binding instruments are needed to address cyber threats
138
WPM
926
Words
7 min
Time
Portugal notes with concern the persistence of malicious cyber activity attributable to state actors and networks operating under their direction, sponsorship, or tolerance through proxy actors and criminal affiliates
Arg. 1
Explanation
Portugal expresses concern about the persistence and evolution of malicious cyber activity attributable to state actors and networks operating under their direction, sponsorship, or tolerance. This activity is conducted through an ecosystem of proxy actors, criminal affiliates, and self-styled activist collectives.
Evidence
Portugal stated that it ‘would like to take this opportunity to note with concern the persistence and evolution of malicious cyberactivity attributable to state actors and to networks operating under their direction, sponsorship or tolerance’ . Portugal described this activity as being ‘conducted through an ecosystem of proxy actors, criminal affiliates and self-styled activist collectives’ .
Major Discussion Point
State-Sponsored Cyber Activities and Use of Proxy Actors
Agreed with
European UnionEstoniaSwedenSwitzerlandUnited Kingdom
on: The use of proxy actors by states undermines international security and is inconsistent with agreed UN norms of responsible state behaviour
The framework of responsible state behaviour in cyberspace, including the applicability of international law and voluntary norms endorsed by the General Assembly, must be reaffirmed
Arg. 2
Explanation
Portugal reaffirms its full commitment to the framework of responsible state behaviour in cyberspace, including the applicability of international law, the voluntary norms endorsed by the General Assembly, and the confidence-building measures developed within relevant fora. Portugal underscores that the protection of critical infrastructure is not merely a national imperative but a shared international interest.
Evidence
Portugal stated that it ‘reaffirms its full commitment to the framework of responsible state behaviour in cyberspace, including the applicability of international law, the voluntary norms endorsed by the General Assembly, and the confidence-building measures developed within these and other relevant fora’ . Portugal underscored that ‘the protection of critical infrastructure as recognized in the norms of responsible state behavior is not merely a national imperative, but a shared international interest given the interconnected and borderless nature of cyberspace’ .
Major Discussion Point
Application of International Law in Cyberspace
Agreed with
Nigeria in behalf of the African groupFranceAlgeriaSwitzerland
on: International law, including the UN Charter, applies fully to the use of ICTs and is fundamental to maintaining international peace and security
Disagreed with
CubaFranceAfrican group (Nigeria)
on: Whether new legally binding instruments are needed to address cyber threats
112
WPM
294
Words
3 min
Time
AI is transforming cyber activity by increasing sophistication, scale, and pace of operations whilst lowering barriers to entry; this reinforces the importance of promoting responsible state behaviour
Arg. 1
Explanation
The United Kingdom highlights that artificial intelligence is transforming cyber activity by increasing the sophistication, scale, and pace of operations, whilst at the same time lowering barriers to entry. This differentiated and evolving threat landscape reinforces the importance and challenge for the UN global mechanism to promote strategic stability through responsible state behaviour.
Evidence
The UK stated that ‘artificial intelligence is transforming cyber activity by increasing the sophistication, scale and pace of operations, whilst at the same time lowering barriers to entry’ . The UK noted that ‘this differentiated and evolving threat landscape reinforces the importance and the challenge for the UN global mechanism to promote strategic stability through responsible state behaviour in cyberspace’ .
Major Discussion Point
Cyber Threat Landscape – Artificial Intelligence and Emerging Technologies
Agreed with
BrazilTonga on behalf of the Pacific Islands ForumNigeriaEstoniaTurkeyItalySwitzerlandAlgeriaSerbiaVietnamSingaporeSouth AfricaMexico
on: AI is fundamentally reshaping the cyber threat landscape, increasing the scale, speed, and sophistication of malicious cyber activities
The UK works with international partners to hold malicious actors to account through coordinated attribution, sanctions, and diplomacy; the UK issued its first joint cyber sanctions package with the EU targeting Russian state actors
Arg. 2
Explanation
The United Kingdom describes its approach to responding to malicious state cyber activity, which involves working with international partners to hold malicious actors to account through coordinated attribution, sanctions, and diplomacy. The UK issued its first joint cyber sanctions package with the EU, targeting Russian state actors and associated criminal and proxy networks.
Evidence
The UK stated that ‘last week, the UK issued our first joint cyber sanctions package with the European Union’ and that ‘these sanctions target the Russian state, including senior Russian intelligence officers, and closely associated criminal and proxy networks responsible for orchestrating reckless and destructive cyberattacks across Europe’ . The UK also noted that it ‘supported the attribution of a recent attempted attack on Poland’s energy infrastructure by Russian intelligence services’ which ‘could have left up to 500,000 people without electricity during winter’ .
Major Discussion Point
State-Sponsored Cyber Activities and Use of Proxy Actors
Agreed with
European UnionEstoniaSwedenSwitzerlandPortugal
on: The use of proxy actors by states undermines international security and is inconsistent with agreed UN norms of responsible state behaviour
126
WPM
550
Words
4 min
Time
Cuba underscores the covert and illegal use of information systems of other nations by individuals, organisations, and states to engage in IT attacks against third countries, and the false and politically motivated attribution of cyber attacks
Arg. 1
Explanation
Cuba highlights several threats including the covert and illegal use of information systems of other nations to engage in IT attacks against third countries. Cuba also underscores the false and politically motivated use of cyber attacks to justify hostile actions against other states, which it describes as fourth generation warfare.
Evidence
Cuba underscored ‘the covert and illegal use of the information systems of other nations by individuals, organizations and states to engage in IT attacks against third countries, as well as the false and politically motivated use of cyber attacks to justify hostile actions against other states’ . Cuba described this as ‘fourth generation warfare that seeks to use the information stored and processed in violation of personal data rights’ .
Major Discussion Point
State-Sponsored Cyber Activities and Use of Proxy Actors
Cuba calls for the negotiation and adoption within the UN of an international legally binding instrument that complements applicable international law and responds to significant legal loopholes in cybersecurity
Arg. 2
Explanation
Cuba calls for the negotiation and adoption within the United Nations of an international legally binding instrument on ICTs. This instrument should complement applicable international law and respond to the significant legal loopholes that currently exist in the area of cybersecurity.
Evidence
Cuba stated that it supports ‘the negotiation and adoption within the United Nations of an international legally binding instrument that complements applicable international law and that responds to the significance legal loopholes that currently exist in the area of cyber security’ .
Major Discussion Point
Application of International Law in Cyberspace
Disagreed with
FrancePortugalAfrican group (Nigeria)
on: Whether new legally binding instruments are needed to address cyber threats
129
WPM
564
Words
4 min
Time
AI offers significant opportunities but also serious risks; without appropriate safeguards it can be misused to identify vulnerabilities, automate attacks, and scale disinformation campaigns
Arg. 1
Explanation
Algeria acknowledges that AI offers significant opportunities but also poses serious risks. Without appropriate safeguards, AI can be misused to identify vulnerabilities, automate attacks, enhance malware, scale disinformation campaigns, and conduct cyber operations beyond existing defensive capacities.
Evidence
Algeria stated that ‘AI offers significant opportunities but also serious risk and is becoming increasingly connected to cyber security’ and that ‘without appropriate safeguards, it can also be misused to identify vulnerabilities automate attacks, enhance malware, scale disinformation campaigns and conduct cyber operations beyond existing defensive capacities’ .
Major Discussion Point
Cyber Threat Landscape – Artificial Intelligence and Emerging Technologies
Agreed with
BrazilTonga on behalf of the Pacific Islands ForumNigeriaEstoniaTurkeyItalySwitzerlandUnited KingdomSerbiaVietnamSingaporeSouth AfricaMexico
on: AI is fundamentally reshaping the cyber threat landscape, increasing the scale, speed, and sophistication of malicious cyber activities
If advanced AI-enabled cyber capabilities remain concentrated in the hands of few actors while many countries lack infrastructure and expertise, the digital divide risks becoming a security divide
Arg. 2
Explanation
Algeria expresses concern that if advanced AI-enabled cyber capabilities remain concentrated in the hands of a few actors while many countries lack the infrastructure, expertise, and access to secure technologies needed to detect, defend against, or respond to malicious ICT activities, the digital divide risks becoming a security divide.
Evidence
Algeria stated that ‘if advanced AI enables cyber capabilities remain concentrated in the hands of few actors while many countries which lack the infrastructure, expertise and access to secure technologies needed to detect, defend against or respond to malicious ICT activities, the digital divide risk becoming a security divide, thereby undermining sovereignty, resilience and collective stability’ .
Major Discussion Point
Digital Divide and Developing Countries’ Cyber Challenges
Algeria stresses that the proliferation and misuse of spyware and intrusive cyber capabilities constitutes a serious violation of fundamental human rights, international law, state sovereignty, and diplomatic inviolability
Arg. 3
Explanation
Algeria highlights the proliferation and misuse of spyware and intrusive cyber capabilities as a particularly serious concern. Evidence from credible international media and human rights organisations shows that such tools have been systematically abused to target state officials, diplomats, journalists, lawyers, human rights defenders, and civil society actors.
Evidence
Algeria stated that ‘recent investigations by credible international media and human rights organizations have provided evidence that such tools have been systematically abused to target state officials, diplomats, journalists, lawyers, human rights defenders, and civil society actors’ . Algeria stated that ‘such unlawful conduct constitutes a serious violation of fundamental human rights, international law, state sovereignty, diplomatic inviolability, and the well-established principle of non-interference in internal affairs’ .
Major Discussion Point
Application of International Law in Cyberspace
Agreed with
Nigeria in behalf of the African groupFrancePortugalSwitzerland
on: International law, including the UN Charter, applies fully to the use of ICTs and is fundamental to maintaining international peace and security
111
WPM
447
Words
4 min
Time
South Africa is concerned about the significant increase in frequency and devastating impact of cyber attacks on critical infrastructure, with AI dramatically increasing the scale, frequency, and sophistication of attacks
Arg. 1
Explanation
South Africa expresses concern about the significant increase in recent years in the frequency and devastating impact of cyber attacks on critical infrastructure and critical information infrastructure. Technological innovations, particularly in AI, have dramatically increased the scale, frequency, and sophistication of cyber attacks.
Evidence
South Africa stated that it is ‘concerned about the significant increase in recent years in the frequency and devastating impact of cyber attacks on critical infrastructure and critical information infrastructure’ . South Africa noted that ‘technological innovations, particularly in AI, have dramatically increased the scale, frequency, and sophistication of cyber attacks, posing a significant threat to national development agendas’ .
Major Discussion Point
Human Dimension of Cyber Threats
Agreed with
BrazilTonga on behalf of the Pacific Islands ForumNigeriaEstoniaTurkeyItalySwitzerlandUnited KingdomAlgeriaSerbiaVietnamSingaporeMexico
on: AI is fundamentally reshaping the cyber threat landscape, increasing the scale, speed, and sophistication of malicious cyber activities
121
WPM
409
Words
3 min
Time
AI is already changing the nature of cyber threats, making malicious ICT activities more sophisticated and more difficult to prevent and mitigate
Arg. 1
Explanation
Serbia highlights that artificial intelligence is already changing the nature of cyber threats, making malicious ICT activities more sophisticated and more difficult to prevent and mitigate. Serbia's national experience reflects this wider trend.
Evidence
Serbia stated that ‘artificial intelligence is already changing the nature of cyber threats, making malicious ICT activities more sophisticated and more difficult to prevent and mitigate’ and that ‘our national experience reflects this wider trend’ . Serbia also noted concern about ‘the growing availability of commercial, artificial intrusion tools’ and ‘the misuse of the AI and cryptocurrencies for cybercrime’ .
Major Discussion Point
Cyber Threat Landscape – Artificial Intelligence and Emerging Technologies
Agreed with
BrazilTonga on behalf of the Pacific Islands ForumNigeriaEstoniaTurkeyItalySwitzerlandUnited KingdomAlgeriaVietnamSingaporeSouth AfricaMexico
on: AI is fundamentally reshaping the cyber threat landscape, increasing the scale, speed, and sophistication of malicious cyber activities
121
WPM
411
Words
3 min
Time
Vanuatu faces compounding cyber and climate risks; a malicious ICT incident during a disaster window would not be an inconvenience but would cost lives; early warning systems and emergency communications must be prioritised
Arg. 1
Explanation
Vanuatu argues that for its country, cyber risk and climate risk are not parallel concerns but a single compounding one. A malicious ICT incident during a disaster window would cost lives, and therefore early warning systems, emergency communications, and disaster coordination platforms must be prioritised in the mechanism's catalog of threats to critical infrastructure.
Evidence
Vanuatu described its experience with twin cyclones in 2023 and an earthquake in December 2024, noting that ‘each time, alongside homes and roads, we lost the digital systems on which modern crisis response depends’ . Vanuatu stated that ‘a malicious ICT incident during a disaster window would not be an inconvenience. It would cost lives’ .
Major Discussion Point
Digital Divide and Developing Countries’ Cyber Challenges
For a small island developing state, the riskiest technology strategy is to have none at all; ambition in digital development is only sustainable in a digital ecosystem that is trustworthy
Arg. 2
Explanation
Vanuatu argues that despite the risks, it is pursuing an ambitious digital agenda because for a country like theirs, the riskiest technology strategy is to have none at all. However, this ambition is only sustainable in a digital ecosystem that is trustworthy, and Vanuatu's ecosystem is both fragile and exposed.
Evidence
Vanuatu stated that it is ‘pursuing one of the most forward-leaning digital agendas among small island developing states’ including ‘building towards cloud-based continuity of government so that our services and records survive even when our buildings do not’ . Vanuatu stated that ‘for a country like ours, the riskiest technology strategy is to have none at all’ but that ‘ambition of this kind is only sustainable in a digital ecosystem that is trustworthy, and ours is both fragile and exposed’ .
Major Discussion Point
Digital Divide and Developing Countries’ Cyber Challenges
132
WPM
388
Words
3 min
Time
Nauru, newly connected via its first international submarine cable, encounters the full threat landscape immediately; the mechanism's work on threats must produce shared assessments in plain terms usable by small states
Arg. 1
Explanation
Nauru highlights that as a newly connected country, it encounters the full cyber threat landscape immediately rather than gradually. The mechanism's work on threats must produce shared assessments in plain terms, early warning that reaches small administrations, and guidance that helps small states act on what they learn.
Evidence
Nauru stated that ‘last year, the East Micronesian Cable came ashore at Yarin, the first international submarine cable in our history’ . Nauru noted that ‘a country that connects late meets the full threat landscape on day one that others encounter gradually’ and that its government systems are encountering threats including ransomware from ‘criminal groups operating from the other side of the world’ .
Major Discussion Point
Digital Divide and Developing Countries’ Cyber Challenges
155
WPM
785
Words
5 min
Time
Botswana recognises that transitioning to a fully interconnected society brings significant benefits for economic growth but also significant challenges including AI-driven manipulation and data protection risks
Arg. 1
Explanation
Botswana acknowledges that transitioning to a fully interconnected society presents huge benefits for economic growth but also comes with significant challenges. These include the rising threat of AI-driven manipulation, deepfakes, phishing, mass disinformation campaigns, and data protection risks.
Evidence
Botswana stated that ‘transitioning into a fully interconnected society presents a huge benefit for economic growth for us but we are also aware that this comes with significant challenges’ . Botswana noted concern about ‘the rising threat of AI-driven manipulation and the integration of AI to produce highly sophisticated deepfakes, phishing and mass disinformation campaigns posing a direct risk to social security’ .
Major Discussion Point
Digital Divide and Developing Countries’ Cyber Challenges
Botswana notes that ICTs are misused to conduct unauthorised mass surveillance and restrict multiple human rights; cyberspace must remain an enabler of human potential, not an instrument for human rights violations
Arg. 2
Explanation
Botswana expresses deep concern about the risk inherent in unregulated surveillance technologies and intrusive digital tools. ICTs are being misused to conduct unauthorised mass surveillance and restrict multiple human rights, and cyberspace must remain an enabler of human potential rather than an instrument for human rights violations.
Evidence
Botswana stated that it is ‘deeply concerned by the risk inherent in unregulated surveillance technologies and intrusive digital tools’ and that ‘ICTs are misused to conduct unauthorized mass surveillance and restrict multiple human rights’ . Botswana stated that ‘the cyberspace must remain an enabler of human potential, not an instrument for human rights violations’ .
Major Discussion Point
Application of International Law in Cyberspace
126
WPM
388
Words
3 min
Time
Costa Rica's 2022 cyber attacks demonstrated that ransomware and malicious operations can impact state functions, public services, institutional continuity, and public trust
Arg. 1
Explanation
Costa Rica draws on its own experience with the 2022 cyber attacks to demonstrate that ransomware and other malicious operations can have severe impacts on state functions, public services, institutional continuity, and public trust. This reinforces the need for the mechanism to contribute to strengthening the resilience of states.
Evidence
Costa Rica stated that ‘our own experience with the 2022 cyber attacks demonstrated that ransomware and other malicious operations can impact state functions, public services, institutional continuity, and public trust’ . Costa Rica stated that ‘this mechanism must contribute to strengthening the resilience of states and their capacity to prevent, respond to, and recover from incidents that directly affect their populations’ .
Major Discussion Point
Cyber Threat Landscape – Ransomware and Critical Infrastructure
Agreed with
BrazilRepublic of KoreaGermanyTonga on behalf of the Pacific Islands ForumItalyNigeria in behalf of the African groupMexicoColombiaIrelandSingapore
on: Protection of critical infrastructure and ransomware are priority topics for DTG 1 with broad support
Threat analysis must incorporate a human dimension and consider the differentiated nature of harm; women, girls, the elderly, persons with disabilities, migrants, journalists, and human rights defenders face specific risks
Arg. 2
Explanation
Costa Rica argues that threat analysis must always incorporate a human dimension and consider the differentiated nature of harm caused. Specific groups including women and girls, the elderly, persons with disabilities, migrants and refugees, journalists, and human rights defenders may face particular risks such as undue surveillance, digital harassment, fraud, and information manipulation.
Evidence
Costa Rica stated that ‘threat analysis must always incorporate a human dimension and consider the differentiated nature of harm caused’ and that ‘women and girls, the elderly, persons with disabilities, migrants and refugees, journalists, human rights defenders and other groups may face specific risks such as undue surveillance, digital harassment, fraud, information manipulation or exclusion from digital services’ .
Major Discussion Point
Human Dimension of Cyber Threats
109
WPM
320
Words
3 min
Time
Ransomware directed against critical infrastructure, risks to ICT supply chains, and activity of organised criminal groups are priority areas for DTG 1
Arg. 1
Explanation
Mexico identifies ransomware directed against critical infrastructure and essential services, risks to ICT supply chains, and the activity of organised criminal groups employing increasingly sophisticated techniques as priority areas for the mechanism's work. Mexico also highlights the cybernetic dimension of major international events.
Evidence
Mexico stated that it ‘identifies applications as a priority, ransomware directed against critical infrastructure and essential services, risks to ICT supply chain change, chains and the activity of organized criminal groups that employ increasingly sophisticated techniques, tactics, and methods’ . Mexico referenced the 2026 FIFA World Cup as ‘an example of the importance of close coordination between Mexico, Canada, and the United States to protect critical infrastructure during large-scale events’ .
Major Discussion Point
Priority Topics for DTG 1
Agreed with
BrazilRepublic of KoreaGermanyTonga on behalf of the Pacific Islands ForumItalyNigeria in behalf of the African groupColombiaIrelandCosta RicaSingapore
on: Protection of critical infrastructure and ransomware are priority topics for DTG 1 with broad support
Concerns about AI are not limited to malicious use but include risks associated with the lifecycle of AI systems themselves, including model security, data integrity, and AI supply chains
Arg. 2
Explanation
Mexico argues that concerns about AI in the cybersecurity context are not limited to its malicious use but also include risks associated with the lifecycle of AI systems themselves. These include model security, data integrity, the AI supply chain, and incident response capacities, insofar as AI is becoming a cross-cutting layer on which critical infrastructure depends.
Evidence
Mexico stated that ‘when it comes to artificial intelligence, the concerns are not limited to its malicious use’ and that ‘they include risks associated with the lifecycle of AI systems themselves’ including ‘model security, data integrity, the IAEA supply chain, and incident response capacities, insofar as artificial intelligence is becoming a cross-cutting layer on which critical infrastructure depends’ .
Major Discussion Point
Cyber Threat Landscape – Artificial Intelligence and Emerging Technologies
Agreed with
BrazilTonga on behalf of the Pacific Islands ForumNigeriaEstoniaTurkeyItalySwitzerlandUnited KingdomAlgeriaSerbiaVietnamSingaporeSouth Africa
on: AI is fundamentally reshaping the cyber threat landscape, increasing the scale, speed, and sophistication of malicious cyber activities
Digital violence disproportionately affects women and girls and can limit their participation in public, economic, and social life; gender dimensions must be reflected in threat analysis and public policy responses
Arg. 3
Explanation
Mexico underscores the gender dimensions of cyber threats, noting that digital violence in its various forms disproportionately affects women and girls and can limit their participation in public, economic, and social life. These consequences must be reflected in both threat analysis and public policy responses.
Evidence
Mexico stated that ‘we must also recognize the gender dimensions of this issue’ and that ‘digital violence and its various forms disproportionately affect women and girls and can limit their participation in public, economic, and social life’ . Mexico noted that ‘these consequences must be reflected both in the analysis of threats as well as in public policy responses through information and desegregated data that will enable the design of more effective responses’ .
Major Discussion Point
Human Dimension of Cyber Threats
The 2026 FIFA World Cup demonstrated the importance of close coordination between Mexico, Canada, and the United States to protect critical infrastructure during large-scale events, constituting a valuable example of sub-regional cooperation
Arg. 4
Explanation
Mexico highlights the cybernetic dimension of major international events, using the recently concluded 2026 FIFA World Cup as an example. The experience of close coordination between Mexico, Canada, and the United States to protect critical infrastructure during this large-scale event constitutes a valuable example of sub-regional cooperation and information exchange.
Evidence
Mexico stated that ‘the recently concluded 2026 FIFA World Cup, is an example of the importance of close coordination between Mexico, Canada, and the United States to protect critical infrastructure during large-scale events’ . Mexico noted that ‘that experience constitutes a valuable experience of sub-regional cooperation, exchange of information, and joint preparation that could contribute to strengthening resilience to cross-border threats’ .
Major Discussion Point
Regional Frameworks and International Cooperation
120
WPM
351
Words
3 min
Time
Ransomware attacks against critical infrastructure and state institutions compromise the continuity and stability of essential services, aggravated by the use of AI for more sophisticated campaigns
Arg. 1
Explanation
Colombia identifies ransomware attacks against critical infrastructure and state institutions as a priority issue, noting that they compromise the continuity and stability of essential services. This threat is aggravated by the use of artificial intelligence to engage in more sophisticated, precise campaigns that are more difficult to detect.
Evidence
Colombia stated that it ‘wishes to underscore as a priority ransomware attacks, levied against critical infrastructure and state institutions, which compromise the continuity and stability of essential services’ . Colombia noted that ‘this threat is aggravated by the use of artificial intelligence to engage in more sophisticated, precise campaigns that are more difficult to detect, which makes it essential to strengthen cybersecurity capacities and to strengthen the resilience of critical infrastructure’ .
Major Discussion Point
Cyber Threat Landscape – Ransomware and Critical Infrastructure
Agreed with
BrazilRepublic of KoreaGermanyTonga on behalf of the Pacific Islands ForumItalyNigeria in behalf of the African groupMexicoIrelandCosta RicaSingapore
on: Protection of critical infrastructure and ransomware are priority topics for DTG 1 with broad support
140
WPM
162
Words
1 min
Time
Ireland has direct experience of ransomware targeting its health service in 2021, causing huge disruption; protection of the healthcare sector against malicious cyber activity must be a focus
Arg. 1
Explanation
Ireland highlights its direct and recent experience of a criminal ransomware attack targeting its health service in 2021, which caused huge disruption. Ireland argues that the protection of the healthcare sector against malicious cyber activity is a topic that must be focused on and discussed under the DTGs.
Evidence
Ireland stated that ‘Ireland has direct and recent experience of this threat’ as ‘our health service was targeted by a hugely disruptive criminal ransomware attack in 2021’ . Ireland stated that ‘the protection of the healthcare sector against malicious cyber activity is a topic that we need to focus on’ and ‘a topic that we would like to see discussed under the DTGs’ .
Major Discussion Point
Cyber Threat Landscape – Ransomware and Critical Infrastructure
Agreed with
BrazilRepublic of KoreaGermanyTonga on behalf of the Pacific Islands ForumItalyNigeria in behalf of the African groupMexicoColombiaCosta RicaSingapore
on: Protection of critical infrastructure and ransomware are priority topics for DTG 1 with broad support
117
WPM
310
Words
3 min
Time
Advanced AI models raise specific concerns regarding code generation, vulnerability discovery, automation, and large-scale social engineering, potentially lowering barriers for criminal networks and terrorist organisations
Arg. 1
Explanation
Turkey highlights that the deployment of advanced general-purpose AI models raises specific concerns from an international security perspective. The capabilities of such models in areas such as code generation, vulnerability discovery, automation, and large-scale social engineering may increase the speed, scale, sophistication, and effectiveness of malicious cyber operations, potentially lowering barriers for criminal networks and terrorist organisations.
Evidence
Turkey stated that ‘the capabilities of such models in areas such as code generation, vulnerability discovery, automation, and large-scale social engineering may increase the speed, scale, sophistication, and effectiveness of malicious cyber operations’ . Turkey noted that ‘a key concern is the widespread availability of such capabilities may lower the barrier for entry for less resourced actors, including criminal networks and terrorist organizations’ .
Major Discussion Point
Cyber Threat Landscape – Artificial Intelligence and Emerging Technologies
Agreed with
BrazilTonga on behalf of the Pacific Islands ForumNigeriaEstoniaItalySwitzerlandUnited KingdomAlgeriaSerbiaVietnamSingaporeSouth AfricaMexico
on: AI is fundamentally reshaping the cyber threat landscape, increasing the scale, speed, and sophistication of malicious cyber activities
Disagreed with
SwitzerlandEstoniaBrazil
on: Whether existing voluntary norms and CBMs are sufficient to address AI-related cyber challenges, or whether new norms are needed
135
WPM
363
Words
3 min
Time
For Central Asia and as a landlocked country, key areas are strengthening national and regional capacities, developing human resources, and increasing the resilience of critical infrastructure
Arg. 1
Explanation
Kazakhstan highlights that for Central Asia and as a landlocked country, the key areas of focus are strengthening national and regional capacities, developing human resources, and increasing the resilience of critical infrastructure. Kazakhstan advocates maintaining the consensual nature of the global mechanism's work.
Evidence
Kazakhstan stated that ‘for Central Asia and as a landlocked country, the key areas are strengthening the national and regional capacities, developing human resources, as well as increasing the resilience of critical infrastructure’ . Kazakhstan noted that states face ‘a growing range of cyber threats, which include data breaches, ransomware, DDoS attacks, online fraud, misinformation, risks associated with the rapid development of AI, supply chain threats, and the shortage of qualified cyber professionals’ .
Major Discussion Point
Digital Divide and Developing Countries’ Cyber Challenges
Agreed with
BrazilChileNigeria in behalf of the African groupSingaporeSaudi Arabia
on: Capacity building is a strategic cross-cutting priority, and DTG 2 is a key platform for advancing practical cooperation and concrete outcomes
Kazakhstan advocates maintaining the consensual nature of the global mechanism's work and ensuring activities address all five main pillars of the OEWG, taking into account the needs and priorities of different regions
Arg. 2
Explanation
Kazakhstan advocates for maintaining the consensual nature of the global mechanism's work and is convinced that its activities should remain action-oriented and address all five main pillars of the OEWG. The implementation of the global agenda must take into account the needs and priorities of different regions.
Evidence
Kazakhstan stated that it ‘advocates maintaining the consensual nature of the global mechanism’s work and convince that its activities should remain action-oriented and address all five main pillars of the OEWG’ . Kazakhstan noted that ‘the implementation of the global agenda must take into account the needs and priorities of different regions’ .
Major Discussion Point
Regional Frameworks and International Cooperation
97
WPM
384
Words
4 min
Time
Private sector and academia must participate as their experience is essential; they can identify cyber threats and provide information not always available to governments
Arg. 1
Explanation
Oman argues that parties with a lot of experience, such as the private sector and academia, must be involved in the mechanism's work. These parties can identify cyber threats and help counter them, providing information that is not always available to governments, and their exclusion would limit the mechanism's effectiveness.
Evidence
Oman stated that ‘if we leave these parties to one side, well we might not have a proper understanding of certain challenges if they’re not involved’ and that ‘they need to be consulted on databases and other topics and these parties can identify cyber threats, they can help us to counter these threats and this information is not always available to governments’ . Oman noted that ‘if these parties are not involved then we can’t access their experience and we need their experience in our discussions’ .
Major Discussion Point
Stakeholder Participation in the Global Mechanism
Agreed with
BrazilKiribatiGermanyArgentinaChileFranceNigeria in behalf of the African groupSingapore
on: Stakeholder participation, including from the private sector, academia, and technical community, adds significant value to DTG discussions
Disagreed with
ChinaKiribatiGermanyArgentinaFranceEuropean Union
on: Stakeholder and NGO participation in the global mechanism
126
WPM
588
Words
5 min
Time
Saudi Arabia launched the Global Initiative for Capacity Building in Cyberspace with the UN and a Capacity Building Programme for member state representatives participating in the global mechanism
Arg. 1
Explanation
Saudi Arabia highlights its commitment to international cooperation in cybersecurity through the launch of the Global Initiative for Capacity Building in Cyberspace with the UN and its specialised agencies. Saudi Arabia also launched a Capacity Building Programme for representatives of member states participating in the global mechanism, in partnership between the GCF and UNODA.
Evidence
Saudi Arabia stated that it ‘last October, during the Global Cybersecurity Forum in 2025, launched the Global Initiative for Capacity Building in Cyberspace with the United Nations and its specialized agencies in order to support international efforts for capacity building and ensuring cyber readiness at the global level’ . Saudi Arabia noted that it ‘launched the Capacity Building Program for representatives of member states participating in the global mechanism in partnership between the GCF and the UNODA’ .
Major Discussion Point
Capacity Building as a Priority (DTG 2)
Agreed with
BrazilChileNigeria in behalf of the African groupSingaporeKazakhstan
on: Capacity building is a strategic cross-cutting priority, and DTG 2 is a key platform for advancing practical cooperation and concrete outcomes
122
WPM
365
Words
3 min
Time
Bosnia-Herzegovina is deeply concerned by growing cyber activities targeting democratic institutions and electoral processes, particularly affecting states with limited capacities including post-war countries
Arg. 1
Explanation
Bosnia-Herzegovina expresses deep concern about the growing number of cyber activities targeting democratic institutions and electoral processes. It is particularly alarmed about the impact of such activities on states with limited capacities, including those in post-war countries, which may be especially vulnerable to these threats.
Evidence
Bosnia-Herzegovina stated that it is ‘deeply concerned by the growing number of cyber activities targeting democratic institutions and electoral processes’ and is ‘increasingly alarmed about the impact of such activities on the states with limited capacities, including those in post-war countries’ . Bosnia-Herzegovina also expressed concern about ‘the way ICTs are being misused by both state and non-state actors, particularly when such activities begin to affect supply chains, critical infrastructure, and the delivery of essential services’ .
Major Discussion Point
Human Dimension of Cyber Threats
97
WPM
189
Words
2 min
Time
Vietnam faces increasing malicious ICT activities including large-scale APT campaigns targeting critical national information infrastructure and ransomware attacks against government and private sector data servers
Arg. 1
Explanation
Vietnam highlights that it is confronting a growing range of serious cyber threats, particularly advanced persistent threat campaigns targeting critical national information infrastructure and IT platforms. Ransomware attacks directed against data servers of both government and private sectors are also a significant concern.
Evidence
Vietnam stated that it is ‘facing increasing malicious ICT activities, particularly larger-scale advanced persistence, and threat campaigns targeting critical national information infrastructure and information technology platforms, as well as ransomware attacks directed against data servers of government and private sectors’ .
Major Discussion Point
Cyber Threat Landscape – Ransomware and Critical Infrastructure
Emerging technologies including AI and quantum computing enable sophisticated cyber attacks with broader and more far-reaching impacts; disinformation in cyberspace undermines credibility of states, organisations, and individuals
Arg. 2
Explanation
Vietnam notes that emerging technologies such as artificial intelligence and quantum computing are enabling increasingly sophisticated cyber attacks with wider impacts. The spread of false and misleading information in cyberspace contributes to information disorder, undermining the credibility and reputation of states, organisations, and individuals, and adversely affecting national security and public order.
Evidence
Vietnam stated that ’emerging technologies, including artificial intelligence and quantum computing, enable sophisticated cyber attacks with broader and more far-reaching impacts’ and that ‘the determination of false and misleading information in cyberspace continues to contribute to information disorder, undermining credibility and reputation of states, organizations, and individuals, adversely affecting national security and public order’ .
Major Discussion Point
Cyber Threat Landscape – Artificial Intelligence and Emerging Technologies
Agreed with
BrazilTonga on behalf of the Pacific Islands ForumNigeriaEstoniaTurkeyItalySwitzerlandUnited KingdomAlgeriaSerbiaSingaporeSouth AfricaMexico
on: AI is fundamentally reshaping the cyber threat landscape, increasing the scale, speed, and sophistication of malicious cyber activities
Cybercrime continues to evolve in scale and sophistication, including illicit trade in user information, phishing, online fraud, and the use of ICTs to facilitate trafficking in persons
Arg. 3
Explanation
Vietnam highlights that cybercrime is evolving in both scale and sophistication, posing significant challenges to law enforcement. This includes the illicit trade in user information and personal data, phishing and other online fraud schemes, as well as the use of ICTs to facilitate trafficking in persons.
Evidence
Vietnam stated that ‘cybercrimes, continues to evolve in both scale and sophistication, posing significant challenges to law enforcement’ and that ‘this includes the illicit trade in user information and personal data, phishing and other online fraud schemes, as well as the use of ICTs to facilitate trafficking in persons’ .
Major Discussion Point
Cyber Threat Landscape – Ransomware and Critical Infrastructure
DTG 1 should focus on challenges to the international community and make workable recommendations to the plenary
Arg. 4
Explanation
Vietnam argues that the dedicated thematic groups should concentrate on the key challenges facing the international community rather than attempting to cover all issues. The groups should produce workable, practical recommendations that can be brought back to the plenary for consideration.
Evidence
Vietnam stated that ‘we believe DTGIs should focus on the challenges to the international community and make workable recommendations to the plenary’ .
Major Discussion Point
Structure and Functioning of Dedicated Thematic Groups (DTGs)
Agreed with
BrazilKiribatiNew ZealandChileSingaporeTonga on behalf of the Pacific Islands Forum
on: DTGs should focus on a limited number of priority topics rather than attempting to cover everything at once
121
WPM
1798
Words
15 min
Time
The Chair will continue working with delegations during the intersessional period on the programme and other organisational aspects of the DTGs, organising consultations in coordination with co-facilitators
Arg. 1
Explanation
The Chair commits to continuing engagement with delegations during the intersessional period to address remaining questions about the programme and organisational aspects of the DTGs. She will organise consultations in coordination with the co-facilitators to that end.
Evidence
The Chair stated that she would ‘continue working with delegations during the intersessional period during the program and other organizational aspects of the work of the DTGs’ and that she would ‘organize consultations in coordination with the co-facilitators to that end’ .
Major Discussion Point
Structure and Functioning of Dedicated Thematic Groups (DTGs)
The plenary session must conclude by 1 p.m. on Friday and delegations are urged to deliver shorter, more succinct statements to allow all delegations to be heard given limited time and resources
Arg. 2
Explanation
The Chair draws attention to the significant time constraints facing the session, noting that 40 delegations have requested the floor under a single agenda item and that the plenary must conclude by 1 p.m. on Friday. She appeals to delegations to reduce the length of their statements and to use available tools to share their positions in greater detail outside the formal meeting.
Evidence
The Chair noted that there were ’40 delegations that have requested the floor just under this agenda item’ and that ‘we will certainly not conclude the list of speakers today’ . She appealed for cooperation so that ‘if you could possibly reduce your statements and deliver them more succinctly’ and reminded delegations that ‘we need to finalize by 6 p.m. today, but also throughout the whole plenary session needs to be finished by 1 p.m. on Friday’ .
Major Discussion Point
Structure and Functioning of Dedicated Thematic Groups (DTGs)
After concluding the organisation of work, the plenary will proceed to substantive discussions beginning with existing and potential threats arising from the use of ICTs in the context of international security
Arg. 3
Explanation
The Chair announces the transition from organisational matters to substantive discussions, indicating that the first substantive agenda item will be existing and potential threats arising from the use of ICTs in the context of international security. She notes that there is no pre-established list of speakers for this item and that delegations may request the floor by pressing the button.
Evidence
The Chair stated that ‘now that we have concluded our organization of work, we may proceed to the substantive discussions under Agenda Item 5’ and that ‘we will begin with the topic Existing and Potential Threats Arising from the Use of Information and Communications Technologies in the Context of International Security’ . She also noted that ‘there is no pre-established list of speakers’ and that ‘delegations may request the floor by pressing the button’ .
Major Discussion Point
Priority Topics for DTG 1
Session Knowledge Graph
Speakers · Topics · Arguments · Relationships
Interactive graph · embed active
Agreed Points
DTGs should focus on a limited number of priority topics rather than attempting to cover everything at once
Multiple delegations converged on the view that DTGs must concentrate on a limited number of focused topics rather than attempting to address everything simultaneously. Brazil argued that DTGs should focus on a limited number of priority topics each cycle , Kiribati warned that ‘the DDGs cannot do everything at once and delegations like ours cannot follow an endless list of subtopics’ , New Zealand stated that ‘less is more’ and that ‘trying to do too much at once in the DTGs risks doing nothing at all’ , Chile called for ‘progressive limits on the themes that will be addressed in each meeting’ , Singapore noted that focused discussions would allow small states to better prepare given limited resources , Tonga emphasised the need for practical outputs rather than restating that threats are growing , and Vietnam called for DTGs to focus on key challenges and make workable recommendations .
DTGs should focus on a limited number of priority topics per cycle and draw on expertise from diverse sources including stakeholders, with geographic balance
DTG 1 should focus on a small number of concrete deliverables with broad support so that outputs are substantial enough to matter and focused enough to survive in the plenary
DTG meetings are informal by design, which provides space for inclusive and detailed discussions on novel or complex subjects not possible in formal meetings
DTGs should have a clear and predictable programme of work for the biennium, drafted through consultations, with guiding questions or specific themes prepared by co-facilitators for each session
DTGs should allow comprehensive discussion where countries can express a wide range of views, with focused topics enabling small states to better prepare given limited resources
DTGs should focus on practical outputs such as accessible threat briefings, shared risk typologies, lessons from national and regional incidents, and best practice guidance
DTG 1 should focus on challenges to the international community and make workable recommendations to the plenary
Policy Context (Knowledge Base)
This principle reflects broader governance best practice, as noted in trade and digital policy forums where policymakers are advised against attempting to achieve everything at once and instead focus on what is most relevant and feasible [S158]. The Digital Readiness Framework similarly emphasises prioritisation based on relevance and political momentum to create actionable roadmaps [S159].
BrazilKiribatiNew ZealandChileSingaporeTonga on behalf of the Pacific Islands ForumVietnam
Protection of critical infrastructure and ransomware are priority topics for DTG 1 with broad support
There was remarkably broad agreement across delegations from all regions that protection of critical infrastructure and ransomware should be priority topics for DTG 1. Brazil mentioned protection of critical infrastructures as a topic of utmost relevance , the Republic of Korea explicitly proposed ransomware and protection of critical infrastructure as important agenda topics , Germany identified these as the two topics with the most support from numerous delegations during consultations , Italy reported a 38% increase in cyber events and highlighted ransomware as one of the most impactful threats , the African group called for focused discussions on critical infrastructure protection , Mexico identified ransomware against critical infrastructure as a priority , Colombia underscored ransomware attacks against critical infrastructure as a priority issue , Ireland drew on its 2021 health service ransomware attack experience , Costa Rica referenced its 2022 cyber attacks , and Singapore reported close to 8,000 ransomware cases worldwide in 2025 .
More in-depth discussions of the voluntary checklist on norms implementation, operationalisation of the points of contact directory, and application of international law in cyberspace are proposed topics for DTG 1
Ransomware and the protection of critical infrastructure could serve as important agenda topics for DTG 1, given their growing significance
Protection of critical infrastructure and addressing ransomware attacks targeting essential services such as healthcare are topics with broad support from numerous delegations
Ransomware remains one of the most impactful cyber threats, mainly affecting small manufacturing companies with limited capacity, often causing prolonged service disruption
DTG 1 should advance focused discussions on critical infrastructure protection, evolving threats, responsible approaches to emerging technologies, norm implementation, and practical cooperation
Ransomware directed against critical infrastructure, risks to ICT supply chains, and activity of organised criminal groups are priority areas for DTG 1
Ransomware attacks against critical infrastructure and state institutions compromise the continuity and stability of essential services, aggravated by the use of AI for more sophisticated campaigns
Ireland has direct experience of ransomware targeting its health service in 2021, causing huge disruption; protection of the healthcare sector against malicious cyber activity must be a focus
Costa Rica's 2022 cyber attacks demonstrated that ransomware and malicious operations can impact state functions, public services, institutional continuity, and public trust
Ransomware continues to be one of the most acute and pervasive threats; the ransomware ecosystem has evolved and fragmented, shaped by law enforcement pressure and internal competition
Policy Context (Knowledge Base)
Ransomware has been a subject of dedicated international discussion, including through the Counter Ransomware Initiative, where speakers demonstrated strong alignment on threat assessment and the need for collaborative responses [S144][S145]. The broad support across geopolitical divides reflects the maturity of this policy discussion.
BrazilRepublic of KoreaGermanyTonga on behalf of the Pacific Islands ForumItalyNigeria in behalf of the African groupMexicoColombiaIrelandCosta RicaSingapore
There must be a clear and predictable mechanism for DTG recommendations to be brought back to and taken up by the plenary
All delegations addressing the reporting question agreed that a clear link between DTG work and the plenary is essential. Brazil called for ‘a clear procedure to elevate DTG’s report and negotiate the recommendations to the plenary so that they may be formally adopted’ , Kiribati warned that ‘without that link, the group risks becoming discussions to lead nowhere’ , Germany proposed that co-facilitators provide an oral update at the next plenary and that written action-oriented consensus recommendations could be transmitted in writing , Singapore recalled the relevant provisions of the final OEWG report on facilitators transmitting action-oriented draft recommendations , and the Netherlands argued for co-facilitators to report firmly to the plenary while cautioning that negotiating written recommendations would burden delegations and reduce time for substantive work .
A clear procedure must be established to elevate DTG reports and negotiate recommendations to the plenary so they may be formally adopted
There must be a clear and predictable way for DTG recommendations to be brought back to and taken up by the plenary; without this link, groups risk becoming discussions that lead nowhere
Co-facilitators could provide an oral update at the next plenary on preceding DTG discussions; written action-oriented consensus recommendations could also be transmitted in writing for consideration
Co-facilitators should provide a robust and comprehensive report on DTGs' work to the plenary; facilitators in consultation with states could transmit action-oriented draft recommendations
Co-facilitators should report firmly to the plenary on DTG results; negotiating written recommendations would place a heavy burden on delegations and reduce time for substantive work
DTGs should have a clear and predictable programme of work for the biennium, drafted through consultations, with guiding questions or specific themes prepared by co-facilitators for each session
Policy Context (Knowledge Base)
The 3rd meeting of the organisational session of the Global Mechanism on ICT security explicitly discussed mechanisms for DTGs to produce updates and draft recommendations on possible action-oriented measures for the plenary [S155]. China also highlighted the importance of clear role definition between plenaries and DTGs [S160].
BrazilKiribatiGermanySingaporeNetherlandsChile
Capacity building is a strategic cross-cutting priority, and DTG 2 is a key platform for advancing practical cooperation and concrete outcomes
Multiple delegations emphasised the strategic importance of capacity building and the role of DTG 2. Brazil argued that no country can be safe in isolation and that centralising capacity-building initiatives under the UN umbrella would facilitate access , Chile described DTG 2 as ‘recognition of the strategic importance of this pillar’ for developing states , the African group stated that ‘capacity building is a strategic cross-cutting priority requiring sustainable need-based support, particularly for developing countries’ and that DTG 2 should be allocated adequate time for concrete outcomes , Singapore called for DTG 2 to address capacity building required for AI cyber risks, ransomware, and critical infrastructure protection , Saudi Arabia highlighted its Global Initiative for Capacity Building in Cyberspace launched with the UN , and Kazakhstan emphasised strengthening national and regional capacities as a key area for landlocked countries .
The creation of DTG 2 on ICT security capacity building is of particular importance; centralising capacity-building initiatives under the UN umbrella would facilitate access and ensure alignment with priority issues
The creation of DTG 2 recognises the strategic importance of capacity building to strengthen implementation of the framework for responsible state behaviour and respond to needs of developing states
Capacity building is a strategic cross-cutting priority requiring sustainable, need-based support particularly for developing countries
DTG 2 should look at the capacity building required to support efforts in addressing AI cyber risks, ransomware, and protection of critical information infrastructure
Saudi Arabia launched the Global Initiative for Capacity Building in Cyberspace with the UN and a Capacity Building Programme for member state representatives participating in the global mechanism
For Central Asia and as a landlocked country, key areas are strengthening national and regional capacities, developing human resources, and increasing the resilience of critical infrastructure
BrazilChileNigeria in behalf of the African groupSingaporeSaudi ArabiaKazakhstan
AI is fundamentally reshaping the cyber threat landscape, increasing the scale, speed, and sophistication of malicious cyber activities
There was near-universal agreement that AI is fundamentally transforming the cyber threat landscape. Brazil expressed concern about generative AI in misinformation campaigns and deepfakes , Tonga noted AI may increase the speed, scale, and accessibility of malicious cyber activity , Nigeria highlighted AI amplifying risks through deepfakes and disinformation , Estonia stated that ‘artificial intelligence is fundamentally reshaping the cybersecurity landscape’ , Turkey raised concerns about AI models lowering barriers for criminal networks , Italy noted AI is ‘taking cybersecurity risks and threats to the next levels’ , Switzerland reported AI accelerating the frequency and sophistication of malicious activities , the UK stated AI is ‘transforming cyber activity by increasing the sophistication, scale and pace of operations’ , Algeria warned of AI being misused to automate attacks and scale disinformation , Serbia noted AI is making malicious activities ‘more sophisticated and more difficult to prevent and mitigate’ , Vietnam highlighted AI enabling sophisticated attacks with broader impacts , Singapore described AI accelerating attacks on speed, scale, and accessibility , South Africa noted AI dramatically increasing the scale and sophistication of attacks , and Mexico highlighted risks associated with the lifecycle of AI systems themselves .
Generative AI use in misinformation and disinformation campaigns, including deepfakes, is of particular concern; in armed conflict contexts this could violate international humanitarian law
AI-related cybersecurity threats are a potential area for practical discussion; AI may increase the speed, scale, and accessibility of malicious cyber activity including social engineering and automated vulnerability discovery
The malicious use of AI has amplified risks through deepfakes, synthetic media, identity theft, online fraud, and disinformation
AI is fundamentally reshaping the cybersecurity landscape by increasing the scale, speed, and sophistication of malicious cyber activity; the global mechanism should address AI's impact within its mandate
Advanced AI models raise specific concerns regarding code generation, vulnerability discovery, automation, and large-scale social engineering, potentially lowering barriers for criminal networks and terrorist organisations
Ransomware, the nexus between AI and cybersecurity, the role of non-state actors in malicious cyber activities, and cyber-resilient digital transformation are proposed topics for DTG 1
AI is increasing the frequency, sophistication, and strategic significance of malicious cyber activities; current AI models overwhelm many software providers, jeopardising timely vulnerability fixes
AI is transforming cyber activity by increasing sophistication, scale, and pace of operations whilst lowering barriers to entry; this reinforces the importance of promoting responsible state behaviour
AI offers significant opportunities but also serious risks; without appropriate safeguards it can be misused to identify vulnerabilities, automate attacks, and scale disinformation campaigns
AI is already changing the nature of cyber threats, making malicious ICT activities more sophisticated and more difficult to prevent and mitigate
Emerging technologies including AI and quantum computing enable sophisticated cyber attacks with broader and more far-reaching impacts; disinformation in cyberspace undermines credibility of states, organisations, and individuals
Quantum computing threatens existing cryptographic systems; threat actors are expected to exploit quantum computing to break encryption, necessitating migration to quantum-safe cryptography
South Africa is concerned about the significant increase in frequency and devastating impact of cyber attacks on critical infrastructure, with AI dramatically increasing the scale, frequency, and sophistication of attacks
Concerns about AI are not limited to malicious use but include risks associated with the lifecycle of AI systems themselves, including model security, data integrity, and AI supply chains
BrazilTonga on behalf of the Pacific Islands ForumNigeriaEstoniaTurkeyItalySwitzerlandUnited KingdomAlgeriaSerbiaVietnamSingaporeSouth AfricaMexico
DTGs should build on existing agreed frameworks and focus on implementation rather than relitigating settled questions
Several delegations agreed that DTGs should take the existing consensus as their starting point and focus on practical implementation. Kiribati stated that ‘the DTGs should take that consensus as their starting point and devote their energy to implementation rather than relitigating questions that the membership has already settled’ , Argentina argued that ‘the success of the thematic groups should not be measured by the amount of documents they produce, but rather by their capacity to contribute to the effective implementation of the consensus already reached’ , New Zealand noted that DTGs should ‘avoid duplicating the discussions of the plenary and instead be more action-oriented’ , Croatia called for the plenary and DTGs to remain ‘coherent and mutually reinforcing, transparent, and focused on practical outcomes, while avoiding duplication’ , and the African group emphasised that the mechanism must remain ‘state-led, single-track, and conscious-based, with consensus serving as a driver of progress’ .
DTGs should build on already agreed frameworks rather than relitigating settled questions, focusing on implementation rather than reopening consensus
DTGs constitute the most important opportunity to move from normative consensus to practical implementation; their success should be measured by contribution to effective implementation, not volume of documents produced
DTG meetings are informal by design, which provides space for inclusive and detailed discussions on novel or complex subjects not possible in formal meetings
The plenary, DTGs, and intersessional activities should remain coherent, mutually reinforcing, transparent, and focused on practical outcomes while avoiding duplication
The global mechanism must remain state-led, single-track, and consensus-based, with consensus serving as a driver of progress
Policy Context (Knowledge Base)
This principle is consistent with positions expressed at the WSIS+20 review process, which stressed the importance of building on established consensus rather than relitigating agreed frameworks [S149]. It also aligns with the focus on implementing existing agreed frameworks rather than renegotiating new ones, as noted in multistakeholder engagement discussions [S147].
KiribatiArgentinaNew ZealandCroatiaNigeria in behalf of the African group
The use of proxy actors by states undermines international security and is inconsistent with agreed UN norms of responsible state behaviour
Western and like-minded delegations strongly agreed that the use of proxy actors by states is a serious and growing concern inconsistent with agreed UN norms. The EU stated that ‘actively using or encouraging proxies is irresponsible behavior contrary to the UN norms of responsible state behavior’ and exposed Russia’s use of an ecosystem of actors including government agencies, private sector, hacktivists, and criminals , Estonia noted that ‘such proxy models undermine international security and stability’ and are ‘inconsistent with the agreed UN norms’ , Sweden identified the ‘evolving nexus between state and non-state actors’ as ‘an increasing concern’ raising questions about state responsibility , Switzerland highlighted that ‘the use of proxies and the growing conversions between state interests and cyber criminal ecosystems poses an additional accountability challenge’ , Portugal expressed concern about ‘malicious cyberactivity attributable to state actors and to networks operating under their direction, sponsorship or tolerance’ , and the UK announced its first joint cyber sanctions package with the EU targeting Russian state actors and associated criminal networks .
Non-state actors tolerated by, linked to, or controlled by states function as highly effective and deniable proxies; actively using or encouraging proxies is irresponsible behaviour contrary to UN norms
The growing use of proxy actors undermines international security and stability and is inconsistent with agreed UN norms that states should not knowingly allow their territory to be used for internationally wrongful cyber activities
The evolving nexus between state and non-state actors raises questions regarding state responsibility, particularly where non-state actors act with varying degrees of state support
The use of proxies and the growing convergence between state interests and cyber criminal ecosystems poses an additional accountability challenge and increases risk to international peace and security
Portugal notes with concern the persistence of malicious cyber activity attributable to state actors and networks operating under their direction, sponsorship, or tolerance through proxy actors and criminal affiliates
The UK works with international partners to hold malicious actors to account through coordinated attribution, sanctions, and diplomacy; the UK issued its first joint cyber sanctions package with the EU targeting Russian state actors
European UnionEstoniaSwedenSwitzerlandPortugalUnited Kingdom
Stakeholder participation, including from the private sector, academia, and technical community, adds significant value to DTG discussions
A broad coalition of delegations agreed that stakeholder participation adds value to DTG discussions, though with varying degrees of emphasis and different views on modalities. Brazil called for DTGs to draw on expertise from diverse sources including stakeholders with geographic balance , Kiribati stated that ‘the DDGs should draw on the expertise of stakeholders in line with the modalities we have agreed because practical implementation is precisely where the technical knowledge is most valuable’ , Germany argued that having stakeholders at UN-level discussions ‘would benefit all of us’ and ‘contribute to enhancing the common understanding of challenges’ , Argentina stressed that deliberations would be ‘significantly more fruitful’ with experts from academia and the private sector , Chile noted stakeholder participation ‘could bring significant added value’ , Oman argued that without private sector and academia involvement ‘we can’t access their experience’ , France compared cyber diplomacy to a team sport requiring non-state stakeholders , the African group recognised ‘the valuable contribution of relevant stakeholders’ , and Singapore saw value in inviting non-government experts where needed .
DTGs should focus on a limited number of priority topics per cycle and draw on expertise from diverse sources including stakeholders, with geographic balance
The global mechanism should draw on expertise of stakeholders in line with agreed modalities, as practical implementation is where technical knowledge is most valuable
Having stakeholders and their expertise at UN-level discussions benefits all, not only the organisations they belong to or the countries they come from; it enhances common understanding of challenges
Participation of technical experts from academia, private sector, and technical community would make deliberations more fruitful; accreditation should use existing UN institutional systems
Stakeholder participation should be developed on transparent, neutral, and predictable criteria ensuring technical contributions with adequate geographical diversity
Private sector and academia must participate as their experience is essential; they can identify cyber threats and provide information not always available to governments
Including non-state stakeholders will enable states to retain the central role that they currently play; excluding them risks making states marginal
The group recognises the valuable contribution of relevant stakeholders, including civil society, academia, and the private sector, whose expertise complements the intergovernmental and state-led nature of the mechanism
To better support these discussions, it may be in our interest to invite non-government experts to contribute to our understanding of these issues where needed
Policy Context (Knowledge Base)
Multistakeholder engagement has been a persistent theme across UN and IGF processes. The 1st meeting of the Global Mechanism on ICT security underscored the importance of inclusive rules of procedure that enable meaningful participation [S161]. The IGF 2023 Open Forum on SDGs and cybersecurity similarly highlighted the value of engaging stakeholders from different sectors to foster collaboration [S141].
BrazilKiribatiGermanyArgentinaChileOmanFranceNigeria in behalf of the African groupSingapore
International law, including the UN Charter, applies fully to the use of ICTs and is fundamental to maintaining international peace and security
Several delegations reaffirmed that existing international law applies to cyberspace and provides the foundation for responsible state behaviour. The African group stated that ‘international law, including the Charter of the United Nations, applies fully to the use of ICT and remains fundamental to maintaining international peace, security, and stability’ , France reaffirmed its ‘historic commitment to existing international law and, in particular, to the UN Charter’ , Portugal reaffirmed its ‘full commitment to the framework of responsible state behaviour in cyberspace, including the applicability of international law’ , Algeria stressed that misuse of spyware constitutes ‘a serious violation of fundamental human rights, international law, state sovereignty, diplomatic inviolability’ , and Switzerland argued that existing voluntary norms are ‘generally broad enough to enable us to address the challenges posed by AI and cybersecurity’ without needing new norms .
International law, including the UN Charter, applies fully to the use of ICTs and remains fundamental to maintaining international peace, security, and stability
France reaffirms its commitment to existing international law and the UN Charter; it regrets that those promoting an alternative treaty are also the first to violate this foundational text
The framework of responsible state behaviour in cyberspace, including the applicability of international law and voluntary norms endorsed by the General Assembly, must be reaffirmed
Algeria stresses that the proliferation and misuse of spyware and intrusive cyber capabilities constitutes a serious violation of fundamental human rights, international law, state sovereignty, and diplomatic inviolability
Switzerland believes existing voluntary norms and CBMs are broad enough to address challenges posed by AI and cybersecurity; there is no need to adopt new voluntary norms or specific CBMs for AI
Policy Context (Knowledge Base)
This is a long-standing position in UN cyber negotiations. The OEWG 2021-2025 process has consistently affirmed the applicability of international law to cyberspace, though debates continue over whether existing frameworks are sufficient or whether new legally binding instruments are needed [S152][S153].
Nigeria in behalf of the African groupFrancePortugalAlgeriaSwitzerland
Similar Viewpoints
Pacific Island Forum members and New Zealand shared a particularly strong alignment on the need for focused, practical DTG work that serves small states. Kiribati warned that ‘delegations like ours cannot follow an endless list of subtopics’ and called for ‘a small number of concrete deliverables with broad support’ , New Zealand echoed that ‘less is more’ and that ‘focusing initially on a narrow set of issues that are of widespread interest and enjoy broad support will be more productive’ , Singapore noted that ‘having focused discussions will allow small states to better prepare, given limited resources’ , and Tonga called for practical outputs including ‘accessible threat briefings, shared risk typologies, lessons from national and regional incidents, or best practice guidance’ . All four delegations emphasised the particular challenges faced by small states with limited resources.
EU member states and close partners shared a strongly aligned position on state-sponsored cyber activities and the use of proxy actors, with several explicitly referencing Russia. The EU exposed Russia’s use of ‘an ecosystem of Russian actors including a government agency, private sector, hacktivists and criminals’ and announced sanctions , the UK announced its ‘first joint cyber sanctions package with the European Union’ targeting Russian state actors , Estonia highlighted that proxy models ‘undermine international security and stability’ and are ‘inconsistent with the agreed UN norms’ , Sweden welcomed ‘the latest EU cyber sanctions package adopted last week’ , and Portugal expressed concern about activity ‘attributable to state actors and to networks operating under their direction, sponsorship or tolerance’ . This group presented a coordinated front on accountability for state-sponsored malicious cyber activity.
China, Belarus, and Cuba shared a strong alignment on the primacy of consensus in all aspects of the global mechanism’s work, and expressed concern about procedural deviations. China argued that the Chair should not decide which topics have received more support as ‘such a practice is to turn consensus into certain kind of voting’ and that ‘over this history we never saw the appointment of facilitators without consensus’ , Belarus stated that ‘deviating from that view, from that consensus principle, in our view is something that is not acceptable, neither for states nor for the chair’ and noted that ‘an entire group of states distanced itself from the procedure used to appoint coordinators for the DTGs’ , and Cuba called for the negotiation of ‘an international legally binding instrument’ within the UN and highlighted the ‘false and politically motivated use of cyber attacks to justify hostile actions against other states’ . These delegations consistently emphasised the need for strict consensus-based decision-making.
Latin American delegations and Singapore shared a strong emphasis on the importance of DTG 2 for capacity building and the need to move from normative consensus to practical implementation. Brazil argued for centralising capacity-building initiatives under the UN umbrella and proposed DTG 2 begin with a diagnostic assessment of the current landscape , Chile described DTG 2 as recognition of the ‘strategic importance of this pillar’ for developing states , Argentina argued that success should be measured by ‘capacity to contribute to the effective implementation of the consensus already reached’ rather than documents produced , and Singapore called for DTG 2 to address capacity building required for AI cyber risks, ransomware, and critical infrastructure protection . All four emphasised practical, implementation-focused outcomes.
Pacific Island states shared a distinctive perspective on cyber threats as existential and compounding risks for small, vulnerable states. Vanuatu described how cyber risk and climate risk are ‘not parallel concerns but a single compounding one’ and that ‘a malicious ICT incident during a disaster window would not be an inconvenience. It would cost lives’ , Nauru highlighted that ‘a country that connects late meets the full threat landscape on day one’ and called for threat discussions to produce shared assessments ‘in plain terms’ usable by small states , Kiribati emphasised that ‘for a small state that has placed its hopes in the promise that this mechanism will act, the outcome we most wish to avoid is one in which the intersessional period is lost to procedure’ , and Tonga highlighted the integrity of undersea cable infrastructure as ‘not an abstract vulnerability, but a lifeline’ . These delegations consistently framed cyber threats in terms of their disproportionate impact on small island developing states.
Germany, the Netherlands, Chile, and Singapore shared a similar vision for how DTGs should be structured, emphasising guiding questions, thematic coherence, and action-oriented work. Germany called for thematic cohesion between DTG 1 and DTG 2 with challenges proposed by the Chair after consultation , the Netherlands proposed structuring DTGs around ‘concrete and action-oriented work items, including fictional scenarios pertaining to a specific cyber threat or dilemma’ with guiding questions , Chile called for ‘guiding questions or specific themes prepared by the co-facilitators for each session’ , and Singapore supported ‘in-depth discussions on selected and focused topics with guiding questions by the Chair’ . All four delegations envisioned a structured, question-driven approach to DTG work.
Costa Rica, Mexico, and Bosnia-Herzegovina shared a focus on the human dimension of cyber threats, emphasising that analysis must go beyond technical impacts to consider effects on vulnerable groups and democratic institutions. Costa Rica argued that ‘threat analysis must always incorporate a human dimension and consider the differentiated nature of harm caused’ and listed specific vulnerable groups , Mexico underscored that ‘digital violence and its various forms disproportionately affect women and girls’ and called for gender-disaggregated data in policy responses , and Bosnia-Herzegovina expressed deep concern about ‘cyber activities targeting democratic institutions and electoral processes’ and their impact on ‘states with limited capacities, including those in post-war countries’ . All three delegations called for a more human-centred approach to cyber threat analysis.
Unexpected Consensus
Despite significant disagreements on procedural matters such as the appointment of co-facilitators, delegations from very different geopolitical groupings agreed that DTGs should avoid duplicating the plenary’s work and should be genuinely action-oriented. New Zealand explicitly stated that DTG informality ‘is a feature not a bug’ and that DTGs should ‘avoid duplicating the discussions of the plenary’ , Kiribati called for DTGs to focus on implementation rather than ‘relitigating questions that the membership has already settled’ , Chile stated that DTG ‘deliberations must prioritise dialogue and the search for consensus without reproducing formal negotiations or the adoption of decisions by consensus in each step of their work’ , Croatia called for avoiding duplication while preserving meaningful participation , the African group emphasised that consensus should be ‘a driver of progress rather than an obstacle’ , and Singapore called for focused topics that allow the DTGs to ‘best serve their purpose, which is to add perspectives and enhance the depth of our discussions at the plenary’ . This consensus cut across the deep procedural divisions evident in the session.
Despite the deep divisions over procedural matters and the appointment of co-facilitators, delegations from developed and developing countries, from all regions, and from opposing geopolitical blocs converged on ransomware and critical infrastructure protection as priority topics. This is notable because it represents one of the few areas where substantive agreement emerged across the dividing lines of the session. The Republic of Korea proposed these topics , Germany identified them as having the broadest support from numerous delegations , the African group called for focused discussions on critical infrastructure protection , Pacific Island states highlighted ransomware as a severe concern , Italy shared national statistics on ransomware impacts , Colombia , Ireland , and Costa Rica all drew on direct national experiences with ransomware, and Singapore provided global statistics on the scale of the problem . This cross-regional, cross-bloc consensus on substantive topics stands in contrast to the procedural disagreements that dominated much of the session.
While not all delegations explicitly addressed hybrid participation, Kiribati made it a non-negotiable condition, stating that ‘the DDGs must be conducted in a genuinely hybrid format for a dedication based as far from New York as our capital’ and that ‘hybrid participation is the difference between contributing and being absent’ . This concern about geographic inclusion was echoed implicitly by multiple small state delegations emphasising the need for focused topics that allow states with limited resources to prepare adequately. The unexpected element is that this practical concern about physical accessibility, rather than just substantive or procedural issues, emerged as a firm condition from a small island developing state, highlighting a dimension of inclusion that larger delegations may not have considered as central.
Delegations from Africa, the Pacific, and Central Asia converged on a concern that is rarely articulated so clearly in cybersecurity discussions: that the concentration of advanced AI-enabled cyber capabilities in the hands of a few actors could transform the existing digital divide into a security divide. Algeria explicitly stated that ‘the digital divide risk becoming a security divide, thereby undermining sovereignty, resilience and collective stability’ , Vanuatu described how its fragile digital ecosystem makes it particularly exposed , Nauru highlighted that newly connected states ‘meet the full threat landscape on day one’ , Botswana noted that ‘when weaponized across borders, these technologies can manipulate public discourse and destabilize societies’ , and Kazakhstan emphasised the need for strengthening national and regional capacities as a landlocked country . This convergence across very different developing country contexts on the security implications of the digital divide represents an unexpected area of consensus.
Overall Assessment
The session revealed a complex landscape of agreements and disagreements. On substantive cyber threat issues, there was remarkably broad consensus across geopolitical divides: virtually all delegations agreed that ransomware and critical infrastructure protection should be priority topics for DTG 1 , that AI is fundamentally reshaping the cyber threat landscape , and that capacity building through DTG 2 is a strategic priority . On structural matters, there was broad agreement that DTGs should focus on a limited number of topics , avoid duplicating the plenary , and have clear reporting mechanisms to the plenary . However, deep divisions remained on procedural questions, particularly the appointment of co-facilitators without consensus , the role of NGOs and stakeholders , and the fundamental question of whether consensus is required for all decisions or whether the Chair has discretion to act on the basis of broad consultations . The use of proxy actors by states was another area of strong agreement among Western and like-minded delegations but was contested by others who raised concerns about false attribution and politically motivated cyber accusations .
Points of Difference
Appointment of co-facilitators and the consensus principle
This was the most fundamental disagreement in the session. China argued that ‘cyber issue became a UN topic in 1998, it’s been 20-30 years and over this history we never saw the appointment of facilitators without consensus’ , making the co-facilitator appointment a deviation from established practice. Belarus reinforced this, stating that ‘General Assembly Resolutions 79, 237, and 80-16 have already set out the fundamental principle for decision-making by our body, and that is consensus’ and that deviating from this ‘is something that is not acceptable, neither for states nor for the chair’ , noting that ‘an entire group of states distanced itself from the procedure used to appoint coordinators for the DTGs’ . In contrast, Germany ‘welcomes the appointment of co-facilitators of the dedicated thematic working groups, which we continue to view as the prerogative of the Chair’ , Chile stated it is ‘inclusive and well-balanced and in line with UN practice’ , and the Republic of Korea expressed readiness to ‘support the Chair’s proposals where they are based on broad consultations with and due considerations of the views of member states’ . Kiribati took a pragmatic middle position, not seeking to reopen the discussion but urging that ‘however this matter is resolved, it is resolved swiftly and in a spirit of consensus’ .
The appointment of co-facilitators without consensus deviates from established UN practice in this domain; over 20-30 years, facilitators were never appointed without consensus in cyber discussions
General Assembly Resolutions 79/237 and 80/16 establish consensus as the fundamental principle for decision-making; deviating from this is unacceptable for states or the Chair
The Republic of Korea is prepared to support the Chair's proposals where they are based on broad consultations with member states, recognising that multilateral processes cannot fully reflect every individual preference
The appointment of co-facilitators is welcomed as the prerogative of the Chair; the working paper on DTGs provided valuable clarity on roles and responsibilities
Chile fully supports the nomination of co-facilitators as inclusive, well-balanced, and in line with UN practice
The current situation regarding co-facilitator appointment should be resolved swiftly and in a spirit of consensus so that DTGs can begin substantive work in December as planned
ChinaBelarusRepublic of KoreaGermanyChileKiribati
Stakeholder and NGO participation in the global mechanism
China questioned why NGO participation must be introduced into the global mechanism, arguing that ‘the key is whether the NGO’s participation is useful or not’ and whether it respects ‘an important practice of this global mechanism, which has been developed over the last 20 or 30 years’ , suggesting that countries can learn from NGO discussions and bring back useful practices as national policy without formally integrating NGOs into the mechanism . By contrast, Germany argued that ‘having them and their expertise at the discussion at UN level would benefit all of us, not only the organization they happen to be part of or the country they happen to stem from’ . France went further, stating that ‘like in football, cyber diplomacy is a team sport, and non-state stakeholders also have a role to play if we want the mechanism to be relevant’ and that ‘including them will enable states to retain the central role that they currently play, otherwise they will be marginal’ . The EU added a specific dimension by noting that Estonia ‘objected to the stakeholder JSC Positive Technologies, who we already knew was supporting Russian cyber operations’ as ‘behavior that again contradicts the ambition of this global mechanism’ , illustrating that even among those supporting stakeholder participation, there are disagreements about which stakeholders should be admitted.
NGO participation should not be introduced into the global mechanism without consensus; the mechanism's conclusions must be accepted by all countries to be globally significant
The global mechanism should draw on expertise of stakeholders in line with agreed modalities, as practical implementation is where technical knowledge is most valuable
Having stakeholders and their expertise at UN-level discussions benefits all, not only the organisations they belong to or the countries they come from; it enhances common understanding of challenges
Participation of technical experts from academia, private sector, and technical community would make deliberations more fruitful; accreditation should use existing UN institutional systems
Including non-state stakeholders will enable states to retain the central role that they currently play; excluding them risks making states marginal
Private sector and academia must participate as their experience is essential; they can identify cyber threats and provide information not always available to governments
Estonia objected to the stakeholder JSC Positive Technologies, known to support Russian cyber operations, as its participation contradicts the ambitions of the global mechanism
Policy Context (Knowledge Base)
This is a contested issue within the Global Mechanism itself. Iran argued at the 1st meeting of the organisational session that the OEWG adopted specific modalities governing stakeholder participation across the global mechanism as a whole, including DTGs, with no distinction drawn between plenary and DTG meetings for stakeholder participation purposes [S154]. This reflects a broader tension in UN processes between inclusive multistakeholder models and state-centric intergovernmental approaches [S146].
ChinaKiribatiGermanyArgentinaFranceOmanEuropean Union
Decision-making process for selecting DTG 1 topics
China explicitly objected to any procedure ‘by which the chair or certain people will decide that certain topics seem to have received more support and therefore they deserve our discussions’, calling such a practice ‘to turn consensus into certain kind of voting’ . China insisted that ‘either we reach consensus on certain specific topics or countries have the right to propose those important questions that they believe need to be raised in DTG1’ . In contrast, Germany proposed that the challenge for both DTGs ‘should be proposed by the Chair and the co-facilitators after consultation with States’ , and Chile suggested that DTG 1 ‘could use guiding questions or specific themes prepared by the co-facilitators for each session’ . New Zealand argued that informality is ‘a feature not a bug’ that enables flexible discussion, while Kiribati urged the groups to ‘prioritise a small number of concrete deliverables with broad support’ without specifying a consensus requirement for topic selection.
DTG 1's broad mandate requires either consensus on specific topics or the right of countries to propose topics; decisions on topics should not be made by the Chair or select individuals without consensus
DTGs should focus on a limited number of priority topics per cycle and draw on expertise from diverse sources including stakeholders, with geographic balance
DTG 1 should focus on a small number of concrete deliverables with broad support so that outputs are substantial enough to matter and focused enough to survive in the plenary
DTG meetings are informal by design, which provides space for inclusive and detailed discussions on novel or complex subjects not possible in formal meetings
DTGs should have thematic cohesion, with both groups taking the same challenge as a starting point, proposed by the Chair and co-facilitators after consultation with states
DTGs should have a clear and predictable programme of work for the biennium, drafted through consultations, with guiding questions or specific themes prepared by co-facilitators for each session
ChinaBrazilKiribatiNew ZealandGermanyChile
Reporting mechanism from DTGs to the plenary
While all speakers agreed that DTG outputs must feed into the plenary, they disagreed on the form this should take. Brazil stressed that ‘a clear procedure must be established to elevate DTG’s report and negotiate the recommendations to the plenary so that they may be formally adopted’ , implying a formal negotiation process. Germany proposed a dual approach: oral updates from co-facilitators plus ‘written action-oriented consensus recommendations could be transmitted in writing to the plenary for consideration, provided that they were agreed by states in the spirit of consensus’ . Singapore recalled that ‘the facilitators of the DTGs in consultation with states could also transmit action-oriented draft recommendations for consideration by states’ . The Netherlands, however, cautioned that ‘negotiating language on written recommendations would place a heavy burden on delegation resources and significantly reduce the time available within the DDGs for substantive work, which especially affects smaller delegations’ , favouring instead that ‘co-facilitated report firmly to the plenary on the results of the DDGs’ without formal negotiation of written text.
A clear procedure must be established to elevate DTG reports and negotiate recommendations to the plenary so they may be formally adopted
Co-facilitators could provide an oral update at the next plenary on preceding DTG discussions; written action-oriented consensus recommendations could also be transmitted in writing for consideration
Co-facilitators should provide a robust and comprehensive report on DTGs' work to the plenary; facilitators in consultation with states could transmit action-oriented draft recommendations
Co-facilitators should report firmly to the plenary on DTG results; negotiating written recommendations would place a heavy burden on delegations and reduce time for substantive work
There must be a clear and predictable way for DTG recommendations to be brought back to and taken up by the plenary; without this link, groups risk becoming discussions that lead nowhere
BrazilGermanySingaporeNetherlandsKiribati
Whether new legally binding instruments are needed to address cyber threats
Cuba explicitly called for ‘the negotiation and adoption within the United Nations of an international legally binding instrument that complements applicable international law and that responds to the significance legal loopholes that currently exist in the area of cyber security’ . France directly countered this position, stating that it ‘reaffirms its historic commitment to existing international law and, in particular, to the UN Charter’ and that ‘my delegation regrets that those promoting an alternative treaty are also the first to violate this foundational text’ . Portugal and the African group similarly reaffirmed commitment to the existing framework of voluntary norms and international law without calling for new binding instruments , reflecting a broader divide between states seeking new binding rules and those insisting the existing framework is sufficient.
Cuba calls for the negotiation and adoption within the UN of an international legally binding instrument that complements applicable international law and responds to significant legal loopholes in cybersecurity
France reaffirms its commitment to existing international law and the UN Charter; it regrets that those promoting an alternative treaty are also the first to violate this foundational text
The framework of responsible state behaviour in cyberspace, including the applicability of international law and voluntary norms endorsed by the General Assembly, must be reaffirmed
International law, including the UN Charter, applies fully to the use of ICTs and remains fundamental to maintaining international peace, security, and stability
Policy Context (Knowledge Base)
This is one of the most persistent and unresolved debates in UN cyber negotiations. The OEWG 2021-2025 process repeatedly debated whether voluntary norms are sufficient or whether new legally binding obligations are needed, with Pakistan, Russia, Iran, Egypt and others calling for continued discussion on legally binding instruments, while Western states generally favour implementation of existing voluntary norms [S153]. The OEWG annual report and session documents confirm this as a significant divide [S152][S151].
CubaFrancePortugalAfrican group (Nigeria)
Whether existing voluntary norms and CBMs are sufficient to address AI-related cyber challenges, or whether new norms are needed
Switzerland explicitly stated that ‘there is no need to adopt new voluntary norms or specific CBMs for AI’ because ‘the existing ones were not created for any particular technology and are generally broad enough to enable us to address the challenges posed by AI and cybersecurity as well’ . Turkey, however, proposed that the mechanism consider ‘volunteer norms and safeguards for responsible development and deployment of high-capacity AI models’ , suggesting new norm development may be warranted. Estonia argued that the global mechanism ‘should not ignore the impact of AI on the cyber threat landscape, but address it where it clearly falls within our mandate’ , while Brazil expressed particular concern about generative AI in misinformation campaigns, noting that ‘in the context of an armed conflict, this could cause grave harm to civilians and would constitute a violation of international humanitarian law’ , implying existing law may need clearer application or elaboration.
Switzerland believes existing voluntary norms and CBMs are broad enough to address challenges posed by AI and cybersecurity; there is no need to adopt new voluntary norms or specific CBMs for AI
Advanced AI models raise specific concerns regarding code generation, vulnerability discovery, automation, and large-scale social engineering, potentially lowering barriers for criminal networks and terrorist organisations
AI is fundamentally reshaping the cybersecurity landscape by increasing the scale, speed, and sophistication of malicious cyber activity; the global mechanism should address AI's impact within its mandate
Generative AI use in misinformation and disinformation campaigns, including deepfakes, is of particular concern; in armed conflict contexts this could violate international humanitarian law
Policy Context (Knowledge Base)
The question of whether existing norms are sufficient or new norms are needed has been a central point of contention throughout the OEWG process, with positions ranging from developing new norms, to focusing on implementation of existing norms first, to developing new norms in parallel [S151]. The EU, Australia, and the US have generally held that existing norms are adaptable, while other states advocate for new frameworks [S150][S152].
SwitzerlandTurkeyEstoniaBrazil
The autonomy and relationship between DTG 1 and DTG 2
Brazil explicitly stated that ‘while it will be important to ensure synergy between both DTGs, they are each autonomous bodies, and DTG2’s mandate should not in any way be tied to DTG1’s’ , emphasising independence. Germany, by contrast, ‘sees value in thematic cohesion between the meetings of DTG 1 and DTG 2, meaning that they should take the same challenge as a starting point’ , proposing that both groups begin from the same thematic challenge. Singapore suggested that ‘DTG 2 could then look at the capacity building required to support our efforts in these domains’ , implying a sequential and linked relationship where DTG 2 follows from DTG 1’s work. Chile similarly promoted ‘adequate coordination between the different DTGs avoiding duplication and focusing on a coherent approach’ , suggesting coordination without full subordination.
While it will be important to ensure synergy between both DTGs, they are each autonomous bodies, and DTG2's mandate should not in any way be tied to DTG1's
DTGs should have thematic cohesion, with both groups taking the same challenge as a starting point, proposed by the Chair and co-facilitators after consultation with states
DTG 2 should look at the capacity building required to support efforts in addressing AI cyber risks, ransomware, and protection of critical information infrastructure
Chile also believes that the participation of technical experts and other stakeholders could bring significant added value to these discussions, strengthening the exchange of specialized knowledge and practical experience
Policy Context (Knowledge Base)
The 2nd meeting of the organisational session of the Global Mechanism on ICT security highlighted the importance of clear role definition between plenaries and DTGs, with China noting that DTGs should focus on specific outcomes while plenaries maintain balanced discussions across all five pillars [S160]. The 3rd meeting further elaborated the distinct functions envisioned for DTGs [S155].
BrazilGermanySingaporeChile
Unexpected Differences
An unexpected dimension of the procedural disagreement was the dispute over what ‘UN practice’ actually means in this context. China pointed out that ‘in the UN system, there are many practices’ and that ‘in the General Assembly, all resolutions are voted on if consensus cannot be reached’ while ‘in the second or third committees, their approach is to reach consensus on all resolutions’ . China then asked ‘in this global mechanism, in this context of DTG, what kind of UN practice should we adopt here?’ , arguing that the DTGs ‘have its own rules of procedure’ and that ‘rules of procedures of other bodies or other committees will not automatically apply here’ . This was unexpected because Chile and Germany both cited ‘UN practice’ to justify the co-facilitator appointment , while China used the same concept of ‘UN practice’ to argue the opposite conclusion – that the appointment was illegitimate. The disagreement was thus not merely about the substance of the decision but about the very framework of reference used to evaluate it.
China raised an unexpected procedural point about the sequencing of expert selection and topic selection, arguing that ‘the selection of experts should be closely tied to the topics we discuss’ and that ‘the topics we decide on discussing will decide what kind of experts we should invite, instead of having experts telling us what topics we should discuss’ . This inverted the logic assumed by many other delegations – Germany, Argentina, and Oman all argued for bringing in expert knowledge to enrich discussions without addressing this sequencing concern. The disagreement was unexpected because it revealed a deeper philosophical divide: China viewed expert participation as a tool to illuminate pre-agreed topics, while others viewed expert participation as integral to shaping the agenda itself.
While most delegations treated the digital divide as a capacity-building challenge to be addressed through DTG 2, Algeria unexpectedly reframed it as a security threat in itself, warning that ‘if advanced AI enables cyber capabilities remain concentrated in the hands of few actors while many countries which lack the infrastructure, expertise and access to secure technologies needed to detect, defend against or respond to malicious ICT activities, the digital divide risk becoming a security divide, thereby undermining sovereignty, resilience and collective stability’ . Vanuatu and Nauru similarly described their connectivity vulnerabilities as immediate security risks rather than merely development gaps . This reframing was unexpected because it challenged the implicit assumption in the session’s structure that threats and capacity building are separate pillars, suggesting instead that for the most vulnerable states, they are inseparable.
Brazil made the unexpected argument that ‘discussions currently underway in ad hoc processes outside the UN on issues such as ransomware, AI implications to cybersecurity or intrusive tools, must be integrated to the global mechanism’ and that ‘keeping discussions within the echo chambers of our like-minded groups will reduce their reach, effectiveness, and legitimacy’ . This implicitly criticised initiatives like the Counter Ransomware Initiative, which Singapore referenced positively as ‘a multilateral platform that forces international cooperation against ransomware’ . China’s insistence on consensus for all decisions would make integrating outputs from non-consensus external processes particularly difficult. This created an unexpected three-way tension between Brazil’s universalist integration argument, Singapore’s pragmatic endorsement of existing coalitions, and China’s procedural insistence on consensus.
Overall Assessment
The session revealed deep and multi-layered disagreements operating at two distinct levels: procedural and substantive. At the procedural level, the most fundamental disagreement concerned the appointment of co-facilitators without consensus, with China and Belarus leading a group of states that viewed this as a violation of established practice and the consensus principle enshrined in General Assembly resolutions , while Germany, Chile, the Republic of Korea, and many others supported the appointment as the Chair’s prerogative and consistent with UN practice . This procedural divide mapped onto a broader disagreement about stakeholder participation, with China arguing against introducing NGO participation without consensus and a large majority of states – including Germany, France, Argentina, Oman, and Kiribati – arguing that stakeholder expertise is essential for effective implementation . At the substantive level, there was surprisingly broad convergence on the key threats facing states – ransomware, attacks on critical infrastructure, AI-enabled malicious activity, and the use of proxy actors – with delegations from all regions sharing national experiences and identifying similar priorities . However, even within this substantive convergence, significant disagreements emerged: over whether existing norms are sufficient to address AI challenges or new ones are needed , over whether the digital divide constitutes a security threat in itself , over whether external processes should be integrated into the mechanism , and over the specific attribution of malicious cyber activity and the appropriateness of sanctions . The reporting mechanism from DTGs to the plenary also generated disagreement, with states divided between those favouring formal negotiation of written recommendations and those warning this would burden small delegations and reduce substantive discussion time .
There was broad agreement that DTGs should focus on a limited number of topics rather than attempting to cover everything. New Zealand stated that 'less is more' and that 'trying to do too much at once in the DTGs risks doing nothing at all' . Kiribati similarly urged groups to 'prioritise a small number of concrete deliverables with broad support' . Tonga argued that DTG discussions should focus on 'practical outputs' . However, speakers disagreed on who should determine which topics are selected and by what process — whether through consensus among all states , through Chair and co-facilitator proposals after consultation , or through some other mechanism — reflecting agreement on the principle of focus but disagreement on the procedure for achieving it.
Agreed
BrazilKiribatiNew ZealandGermanyChileSingaporeNetherlandsTonga on behalf of the Pacific Islands Forum
Contested
DTGs should focus on a limited number of priority topics per cycle and draw on expertise from diverse sources including stakeholders, with geographic balance DTG 1 should focus on a small number of concrete deliverables with broad support so that outputs are substantial enough to matter and focused enough to survive in the plenary DTG meetings are informal by design, which provides space for inclusive and detailed discussions on novel or complex subjects not possible in formal meetings DTGs should have thematic cohesion, with both groups taking the same challenge as a starting point, proposed by the Chair and co-facilitators after consultation with states DTGs should have a clear and predictable programme of work for the biennium, drafted through consultations, with guiding questions or specific themes prepared by co-facilitators for each session DTGs should allow comprehensive discussion where countries can express a wide range of views, with focused discussions enabling small states to better prepare given limited resources Co-facilitators should report firmly to the plenary on DTG results; negotiating written recommendations would place a heavy burden on delegations and reduce time for substantive work DTGs should focus on practical outputs such as accessible threat briefings, shared risk typologies, lessons from national and regional incidents, and best practice guidance
All speakers agreed that DTG outputs must feed back into the plenary in some form, and that a clear linkage is essential. Kiribati warned that 'without that link, the group risks becoming discussions to lead nowhere' , and Germany, Singapore, and the Netherlands all proposed reporting mechanisms. However, they disagreed on the form: Brazil favoured formal negotiation of recommendations , Germany proposed both oral updates and written consensus recommendations , Singapore recalled the provision for action-oriented draft recommendations transmitted in consultation with states , and the Netherlands cautioned against negotiating written text as it would burden delegations and reduce substantive discussion time .
A clear procedure must be established to elevate DTG reports and negotiate recommendations to the plenary so they may be formally adopted There must be a clear and predictable way for DTG recommendations to be brought back to and taken up by the plenary; without this link, groups risk becoming discussions that lead nowhere Co-facilitators could provide an oral update at the next plenary on preceding DTG discussions; written action-oriented consensus recommendations could also be transmitted in writing for consideration Co-facilitators should provide a robust and comprehensive report on DTGs’ work to the plenary; facilitators in consultation with states could transmit action-oriented draft recommendations Co-facilitators should report firmly to the plenary on DTG results; negotiating written recommendations would place a heavy burden on delegations and reduce time for substantive work DTGs should have a clear and predictable programme of work for the biennium, drafted through consultations, with guiding questions or specific themes prepared by co-facilitators for each session DTGs constitute the most important opportunity to move from normative consensus to practical implementation; their success should be measured by contribution to effective implementation, not volume of documents produced
There was very broad agreement across diverse regional groupings that ransomware and protection of critical infrastructure should be priority topics for DTG 1. Germany noted these as 'two topics with numerous delegations echoed over the course of consultation so far' , the Republic of Korea proposed them as 'important agenda topics' , and Tonga described ransomware as 'a severe and growing concern for Pacific states' . Ireland, Colombia, Italy, Singapore, Nigeria, and Costa Rica all shared direct national experiences with ransomware. However, the agreement on the topic did not resolve the underlying procedural disagreement about how topics would be formally selected for the DTG agenda, particularly given China's objection to any process that did not require full consensus .
Agreed
GermanyRepublic of KoreaTonga on behalf of the Pacific Islands ForumItalyIrelandColombiaSingaporeNigeriaCosta Rica
Contested
Protection of critical infrastructure and addressing ransomware attacks targeting essential services such as healthcare are topics with broad support from numerous delegations Ransomware and the protection of critical infrastructure could serve as important agenda topics for DTG 1, given their growing significance Ransomware remains a severe and growing concern for Pacific states; protection of critical infrastructure and critical information infrastructure is a core priority Ransomware remains one of the most impactful cyber threats, mainly affecting small manufacturing companies with limited capacity, often causing prolonged service disruption Ireland has direct experience of ransomware targeting its health service in 2021, causing huge disruption; protection of the healthcare sector against malicious cyber activity must be a focus Ransomware attacks against critical infrastructure and state institutions compromise the continuity and stability of essential services, aggravated by the use of AI for more sophisticated campaigns Ransomware continues to be one of the most acute and pervasive threats; the ransomware ecosystem has evolved and fragmented, shaped by law enforcement pressure and internal competition Nigeria confronts a broad spectrum of cyber threats including ransomware, malware, phishing, supply chain attacks, and attacks on critical information infrastructure and IoT systems Costa Rica’s 2022 cyber attacks demonstrated that ransomware and malicious operations can impact state functions, public services, institutional continuity, and public trust
There was broad agreement on the strategic importance of DTG 2 on capacity building, with Brazil, Chile, Argentina, the African group, Kiribati, and Singapore all welcoming its creation and emphasising its importance for developing countries. Brazil stated that 'no country can be safe from threats in the digital domain in isolation' and that 'we are only as strong as our weakest link' . The African group called capacity building 'a strategic cross-cutting priority requiring sustainable need-based support, particularly for developing countries' . However, disagreement emerged on whether DTG 2 should be autonomous from DTG 1 or whether the two should be thematically linked , and on the specific mandate and starting point for DTG 2's work.
Agreed
BrazilChileArgentinaNigeria in behalf of the African groupKiribatiSingapore
Contested
The creation of DTG 2 on ICT security capacity building is of particular importance; centralising capacity-building initiatives under the UN umbrella would facilitate access and ensure alignment with priority issues The creation of DTG 2 recognises the strategic importance of capacity building to strengthen implementation of the framework for responsible state behaviour and respond to needs of developing states DTGs constitute the most important opportunity to move from normative consensus to practical implementation; their success should be measured by contribution to effective implementation, not volume of documents produced DTG 2 is a key platform for advancing practical cooperation, confidence-building measures, and capacity building, and should be allocated adequate time to contribute to concrete and measurable outcomes DTGs should build on already agreed frameworks rather than relitigating settled questions, focusing on implementation rather than reopening consensus DTG 2 should look at the capacity building required to support efforts in addressing AI cyber risks, ransomware, and protection of critical information infrastructure
There was broad agreement that the use of proxy actors in cyberspace is a serious concern, with the EU , Estonia , Sweden , Switzerland , and the UK all highlighting this trend. However, the speakers disagreed sharply on who the responsible actors are and what the appropriate response should be. The EU and UK specifically named Russia and imposed sanctions , while Cuba countered by highlighting 'the false and politically motivated use of cyber attacks to justify hostile actions against other states' and warning against politically motivated attribution. China's emphasis on consensus and established practice implicitly resisted the attribution-and-sanctions approach favoured by Western states.
Agreed
European UnionEstoniaSwedenSwitzerlandUnited KingdomPortugalChinaCuba
Contested
Non-state actors tolerated by, linked to, or controlled by states function as highly effective and deniable proxies; actively using or encouraging proxies is irresponsible behaviour contrary to UN norms The growing use of proxy actors undermines international security and stability and is inconsistent with agreed UN norms that states should not knowingly allow their territory to be used for internationally wrongful cyber activities The evolving nexus between state and non-state actors raises questions regarding state responsibility, particularly where non-state actors act with varying degrees of state support The use of proxies and the growing convergence between state interests and cyber criminal ecosystems poses an additional accountability challenge and increases risk to international peace and security The UK works with international partners to hold malicious actors to account through coordinated attribution, sanctions, and diplomacy; the UK issued its first joint cyber sanctions package with the EU targeting Russian state actors The framework of responsible state behaviour in cyberspace, including the applicability of international law and voluntary norms endorsed by the General Assembly, must be reaffirmed DTG 1’s broad mandate requires either consensus on specific topics or the right of countries to propose topics; decisions on topics should not be made by the Chair or select individuals without consensus Cuba underscores the covert and illegal use of information systems of other nations by individuals, organisations, and states to engage in IT attacks against third countries, and the false and politically motivated attribution of cyber attacks
Key Takeaways
The first substantive plenary session of the UN Global Mechanism on ICTs in the context of international security marked a significant milestone, with discussions centred on the structure and functioning of Dedicated Thematic Groups (DTGs), the appointment of co-facilitators, stakeholder participation, and the evolving cyber threat landscape.
There is broad agreement that DTGs should focus on a limited number of priority topics per cycle, be action-oriented, and build upon the already agreed normative framework rather than relitigating settled questions, with implementation being the primary focus.
A clear divide exists between delegations that welcome the Chair’s appointment of co-facilitators as her prerogative and those (notably China, Belarus, and a group of like-minded states) who consider the appointment a deviation from the consensus principle established over 20–30 years of UN cyber discussions.
The consensus principle is widely affirmed as the fundamental decision-making basis for the global mechanism, though interpretations differ on how it applies to procedural matters such as the appointment of co-facilitators.
There is strong and widespread support for stakeholder participation, including from the private sector, academia, and civil society, though China maintains that introducing NGO participation without consensus contradicts established practice of the global mechanism.
The cyber threat landscape is universally acknowledged as evolving rapidly, with ransomware, attacks on critical infrastructure, AI-enabled threats, state-sponsored proxy activities, and supply chain compromises identified as the most pressing concerns.
Artificial intelligence is recognised as both a tool for strengthening cyber defence and a vector for increasingly sophisticated malicious cyber activity, lowering barriers to entry for malicious actors and amplifying the scale and speed of attacks.
The use of proxy actors by states to conduct malicious cyber activities is identified as a growing and deeply concerning trend that undermines accountability and contradicts agreed UN norms on responsible state behaviour.
Capacity building, particularly for developing countries and small island developing states, is affirmed as a cross-cutting strategic priority, with DTG 2 seen as the key platform for advancing practical cooperation and measurable outcomes in this area.
There is broad support for thematic coherence between DTG 1 and DTG 2, with many delegations suggesting that the same challenge or threat should serve as the starting point for both groups to ensure a linked and coherent approach.
A clear and predictable reporting mechanism from DTGs to the plenary is considered essential by multiple delegations to ensure that DTG outputs translate into formally adopted recommendations and do not become discussions that lead nowhere.
The protection of critical infrastructure, including healthcare systems, undersea cables, and essential public services, emerged as the most widely supported priority topic for DTG 1, alongside ransomware and AI-related cybersecurity threats.
Small island developing states and developing countries emphasised the disproportionate impact of cyber threats on their populations and the importance of the mechanism producing practical, usable outputs accessible to states with limited resources.
The human dimension of cyber threats, including the gendered impact of digital violence and the targeting of vulnerable groups, was raised by several delegations as a necessary consideration in threat analysis and policy responses.
Regional frameworks, such as the African Union’s Malabo Convention and the Common African Position on the Application of International Law in Cyberspace, are recognised as important implementation pathways that complement the global framework.
Resolutions & Action Items
The Chair confirmed that co-facilitators have been appointed for both DTGs and that she will continue working with delegations during the intersessional period on the programme of work and other organisational aspects of the DTGs.
The Chair will organise consultations in coordination with the co-facilitators during the intersessional period to address remaining open modality questions, including the programme of work, topics, reporting procedures, stakeholder participation arrangements, and the selection of experts from the proposed pool.
The first meeting of the DTGs is planned for December, and delegations are expected to engage constructively during the intersessional period to ensure the December meeting can proceed with substantive discussions.
Estonia and Latvia, together with Oxford Information Labs, announced a technical briefing titled ‘Frontier AI and the Cyber Threat Landscape’ to be held on Wednesday during the session, open to all delegations.
Saudi Arabia announced the launch of the Global Initiative for Capacity Building in Cyberspace with the UN and a Capacity Building Programme for member state representatives participating in the global mechanism, in partnership between the GCF and UNODA.
The African Union confirmed it is at an advanced stage of validating AU guidelines for the implementation of norms of responsible state behaviour in cyberspace and the Declaration on Peace and Security in Cyberspace.
The EU and member states, alongside the United Kingdom, issued a joint cyber sanctions package targeting Russian state actors, senior intelligence officers, and associated criminal and proxy networks responsible for malicious cyberattacks across Europe.
The Chair indicated that after concluding the discussion on existing and potential threats, the session will proceed to voluntary non-binding norms on responsible state behaviour and ways for their implementation, continuing through the programme of work.
The list of speakers for the following morning was confirmed as Egypt, Kiribati, New Zealand, Tonga, and the Kingdom of the Netherlands, with the session to reconvene at 10 a.m.
Unresolved Issues
The legitimacy and procedural basis for the appointment of co-facilitators without explicit consensus remains contested, with a group of like-minded states having distanced themselves from the procedure, and no resolution having been reached during the session.
The specific topics for DTG 1’s agenda have not been agreed upon; while protection of critical infrastructure, ransomware, and AI-related threats received broad support, no formal consensus on the programme of work was reached.
The modalities for stakeholder participation in the DTGs, including which entities may participate, under what conditions, and how objections to specific stakeholders are handled, remain unresolved, as illustrated by Estonia’s objection to JSC Positive Technologies.
The precise reporting mechanism from DTGs to the plenary, including whether recommendations should be transmitted orally or in writing, and whether they require consensus agreement during the intersessional period before being presented to the plenary, has not been determined.
The question of whether DTG 2’s mandate should be tied to or independent of DTG 1’s work remains a point of divergence, with Brazil explicitly stating DTG 2 should be autonomous, while others advocate for thematic coherence between the two groups.
The extent to which discussions on AI governance and AI-related cyber threats should be conducted within this mechanism versus other dedicated UN processes has not been resolved, with delegations holding differing views on the appropriate scope.
The role and weight of existing regional frameworks, such as the African Union instruments, in relation to the global mechanism’s framework has not been formally addressed.
Cuba’s call for the negotiation of an international legally binding instrument on cybersecurity to complement existing international law was raised but not addressed or responded to by other delegations or the Chair.
The question of how to ensure hybrid participation for delegations geographically distant from New York, raised by Kiribati as non-negotiable, has not been formally resolved in terms of practical arrangements.
The 29 remaining delegations on the list of speakers under the threats agenda item had not yet had the opportunity to make their statements by the close of the session, leaving the discussion on existing and potential threats incomplete.
The procedure for selecting experts from the proposed pool to contribute to DTG discussions, and the criteria for ensuring geographic balance and technical relevance, has not been finalised.
Suggested Compromises
Several delegations, including New Zealand, Kiribati, Singapore, and Chile, suggested that DTGs should focus on a small number of concrete, widely supported topics rather than attempting to address a broad agenda, as a pragmatic way to ensure meaningful outputs and broad participation.
Germany and the Netherlands proposed that co-facilitators provide oral updates to the plenary on DTG discussions, rather than requiring formal negotiation of written recommendations, as a way to reduce the burden on delegations while maintaining accountability and the spirit of consensus.
Chile suggested that DTG 1 could use guiding questions or specific themes prepared by co-facilitators for each session, developed through consultations with states, as a flexible mechanism to structure discussions without requiring full consensus on a fixed agenda in advance.
Argentina proposed using existing UN institutional accreditation systems for civil society organisations as a transparent, neutral, and predictable basis for stakeholder participation, rather than creating new ad hoc criteria, as a way to balance openness with the intergovernmental nature of the mechanism.
The Netherlands proposed structuring DTG discussions around fictional scenarios pertaining to specific cyber threats or dilemmas, with guiding questions prompting states to consider what responsible state behaviour looks like in a given context, as a practical way to make DTGs more effective and action-oriented.
Brazil suggested that discussions currently underway in ad hoc processes outside the UN, such as on ransomware and AI implications, should be integrated into the global mechanism, implicitly proposing that the mechanism serve as the consolidating forum to bridge like-minded group discussions with universal membership.
Kiribati implicitly suggested sequencing the mechanism’s work by first consolidating and operationalising what has already been agreed before expanding to new questions, as a way to manage the workload and ensure the mechanism delivers on its core mandate within the five-year cycle.
Switzerland suggested that existing voluntary norms and confidence-building measures are broad enough to address AI-related cybersecurity challenges without the need for new specific norms, offering a compromise position between those calling for new AI-specific rules and those wishing to avoid expanding the normative agenda.
The Republic of Korea indicated readiness to support the Chair’s proposals where they are based on broad consultations with member states, implicitly suggesting that the Chair’s procedural decisions could gain broader acceptance if accompanied by demonstrably inclusive consultation processes.
“China challenged the practice of the Chair or certain individuals deciding which topics ‘seem to have received more support’ and therefore deserve discussion, calling this a deviation from consensus. China stated: ‘there shouldn’t be such a procedure by which the chair or certain people will decide that certain topics seem to have received more support and therefore they deserve our discussions such a practice is to turn consensus into certain kind of voting.’ China also argued that the selection of experts should follow topic decisions, not precede them, and questioned the legitimacy of appointing co-facilitators without consensus, noting: ‘over this history We never saw the appointment of facilitators without consensus.’”
“Kiribati articulated a clear strategic vision: ‘The purpose is to build on what we have already agreed not to reopen it… The immediate task is to make this operational, to move from what states have agreed to do to how they will actually do it. That is a full agenda in itself, and it should come first.’ Kiribati also warned that if the DTGs spend their first biennium ‘relitigating settled ground, they will squander the very feature that distinguishes this mechanism from what came before, and they will do so at the expense of the states that can least afford lost time.’”
“New Zealand stated: ‘Informality provides space for inclusive, detailed discussions on novel or complex subjects in a way that is not possible during formal meetings. The informal dynamic will support the development of practical action-oriented initiatives… Less is more. Trying to do too much at once in the DTGs risks doing nothing at all.’”
“France’s delegate drew an analogy to the FIFA World Cup: ‘like in football, cyber diplomacy is a team sport, and non-state stakeholders also have a role to play if we want the mechanism to be relevant. I would even go so far that including them will enable states to retain the central role that they currently play, otherwise they will be marginal.’”
“Vanuatu connected cyber risk directly to climate and disaster risk: ‘In the context in which Vanuatu reached the threat landscape, for us, cyber risk and climate risk are not parallel concerns, but a single compounding one. A malicious ICT incident during a disaster window would not be an inconvenience. It would cost lives.’ Vanuatu also noted that ‘synthetic content is a safety-of-life issue, not merely an information one’ in the context of fabricated evacuation notices or falsified weather warnings.”
“Brazil argued that ‘discussions currently underway in ad hoc processes outside the UN on issues such as ransomware, AI implications to cybersecurity or intrusive tools, must be integrated to the global mechanism. Their borderless nature means that we need the engagement of all nations to adequately tackle them. Keeping discussions within the echo chambers of our like-minded groups will reduce their reach, effectiveness, and legitimacy.’”
“The European Union explicitly named and condemned Russia’s use of ‘an ecosystem of Russian actors including a government agency, private sector, hacktivists and criminals to target the EU, its member states and its partners.’ The EU also noted that Estonia had objected to the stakeholder JSC Positive Technologies ‘who we already knew was supporting Russian cyber operations,’ and referenced the EU-UK joint cyber sanctions package targeting Russian intelligence officers.”
“Nauru, speaking as a newly connected small island state, offered a candid and practical perspective: ‘A country that connects late meets the full threat landscape on day one that others encounter gradually.’ Nauru asked the mechanism to ‘make it usable’ and produce ‘shared assessments in plain terms, early warning that reaches small administrations, and guidance that helps us act on what we learn.’”
“China argued: ‘The crux is whether we respect an important practice of this global mechanism, which has been developed over the last 20 or 30 years… There is an old Chinese saying which means to the effect of trying to take practice from faraway places instead of close by. We hope that in our future discussions, we can look at what is a practice that has emerged over the past 20 or 30 years here.’”
“Costa Rica stated: ‘For Costa Rica, cyber threats are not abstract. Our own experience with the 2022 cyber attacks demonstrated that ransomware and other malicious operations can impact state functions, public services, institutional continuity, and public trust.’ Costa Rica also called for threat analysis to ‘always incorporate a human dimension and consider the differentiated nature of harm caused,’ specifically naming women and girls, the elderly, persons with disabilities, migrants, refugees, journalists, and human rights defenders.”
What specific topics should DTG 1 focus on, and how should consensus be reached on those topics?
Brazil, China, Republic of Korea, Germany, New Zealand, Kiribati, Chile, Singapore, Argentina
Multiple delegations raised the question of how to determine the agenda for DTG 1 given its broad mandate and the lack of consensus from the OEWG negotiations. China specifically questioned whether the Chair or co-facilitators should have the authority to determine which topics have received sufficient support, arguing this would deviate from consensus principles. This is critical to the functioning of the entire mechanism.
How should the DTGs report their findings and recommendations back to the plenary, and what procedure should be used to formally adopt those recommendations?
Several delegations highlighted the absence of a clear and predictable procedure for elevating DTG reports and negotiating recommendations to the plenary for formal adoption. Without this link, DTG discussions risk leading nowhere. Germany suggested oral updates and written consensus recommendations, while the Netherlands cautioned against placing heavy burdens on delegations through negotiating written language.
What UN practices and rules of procedure should govern the global mechanism and its DTGs, particularly regarding consensus and decision-making?
China, Belarus, Kiribati, Chile
China questioned what specific UN practices should apply to the global mechanism, noting that different UN bodies operate under different rules. Belarus and China both raised concerns about deviations from consensus principles. This question is fundamental to the legitimacy and functioning of the mechanism and remains unresolved.
How should stakeholders, including civil society, the private sector, and academia, participate in the DTGs, and what criteria should govern their selection and involvement?
Oman, Argentina, Germany, Sweden, New Zealand, China, Kiribati, Chile, South Africa
The modalities for stakeholder participation remain contested. China argued against unrestricted NGO participation, while many other delegations stressed the essential value of private sector and technical expertise. Argentina suggested using existing UN accreditation systems. This unresolved issue could significantly affect the quality and legitimacy of DTG outputs.
How should the appointment of co-facilitators for the DTGs be handled, and was the current appointment process consistent with consensus principles?
China, Belarus, Chile, Republic of Korea
China stated that the appointment of facilitators without consensus is not a practice of the global mechanism, while Belarus noted that an entire group of states distanced itself from the procedure used. Chile and Korea supported the Chair’s appointment. This procedural dispute risks undermining the legitimacy of the DTGs and needs resolution.
How should the work of DTG 1 and DTG 2 be coordinated to ensure coherence without making one subordinate to the other?
Brazil, Germany, Argentina, Singapore, New Zealand, Chile
Multiple delegations raised the need for thematic coherence between DTG 1 and DTG 2 while also insisting on their autonomy. Brazil explicitly stated that DTG 2’s mandate should not be tied to DTG 1’s. Germany and Singapore suggested structuring both DTGs around the same challenge as a starting point. This coordination question is important for avoiding duplication and ensuring practical outcomes.
How should the global mechanism address the growing use of proxy actors by states to conduct malicious cyber activities, and how should state responsibility be attributed in such cases?
European Union, Portugal, Sweden, Switzerland, Estonia, United Kingdom
Multiple delegations highlighted the increasing use of criminal networks, hacktivists, and private companies as proxies for state-sponsored cyber operations. The question of how to hold states accountable for proxy activities and how international law on state responsibility applies in these cases remains an important area for further research and discussion within the mechanism.
How should the global mechanism address the cybersecurity implications of artificial intelligence, including both its malicious use and the security of AI systems themselves?
AI was identified by a large number of delegations as a transformative and urgent threat. Questions remain about whether existing norms are sufficient to address AI-related threats, how to share risk assessments on AI-enabled incidents, and whether new voluntary norms are needed. Switzerland argued existing norms are sufficient, while others called for deeper discussion. This is a critical area requiring further research.
How should the global mechanism address the security implications of quantum computing, particularly the need for post-quantum cryptography?
Brazil, Singapore, Italy
Brazil, Singapore, and Italy raised concerns about the implications of quantum computing for existing cryptographic systems. The question of how and when states should begin transitioning to post-quantum cryptography, and how this mechanism can support that transition, requires further research and practical guidance.
How should ransomware attacks targeting critical infrastructure and essential services, particularly the healthcare sector, be addressed through the global mechanism?
Tonga (Pacific Islands Forum), Republic of Korea, Germany, European Union, Ireland, Colombia, Singapore, United Kingdom, Italy, South Africa
Ransomware was identified as one of the most acute and pervasive threats by numerous delegations. The question of what concrete, actionable recommendations the mechanism can produce to address ransomware, and whether it should be a priority topic for DTG 1 in December, remains open and requires further focused discussion.
How should the global mechanism address threats to undersea cable infrastructure, given its critical importance particularly for small island developing states?
Several delegations, particularly from the Pacific, highlighted the unique vulnerability of undersea cables as the sole link to the global Internet for many small states. The question of how international norms and cooperative measures can better protect this infrastructure requires further research and practical recommendations.
How should the global mechanism incorporate a human rights and gender dimension into its analysis of cyber threats?
Costa Rica, Mexico, Botswana, Algeria
Costa Rica and Mexico highlighted that cyber threats disproportionately affect women, girls, the elderly, persons with disabilities, and other vulnerable groups. Mexico called for sex-disaggregated data to enable more effective policy responses. This dimension is often absent from technical cybersecurity discussions and requires further research to integrate meaningfully into the mechanism’s work.
How should the global mechanism address the malicious use of ICTs for disinformation, misinformation, and interference in electoral processes?
Multiple delegations raised concerns about the use of ICTs for disinformation campaigns, deepfakes, and interference in democratic processes. Brazil specifically noted the implications under international humanitarian law during armed conflict. The question of how the mechanism should address these threats, which intersect with freedom of expression concerns, requires further research.
How should the global mechanism address the security of ICT supply chains, including risks from managed service providers and telecommunications operators?
Supply chain vulnerabilities were identified as a growing threat by multiple delegations. The question of what norms, best practices, and cooperative measures can address supply chain risks, including those introduced by AI systems themselves, requires further focused research and discussion within the mechanism.
How should the global mechanism ensure that its threat discussions and outputs are accessible and usable for small states with limited resources and capacity?
Small states repeatedly emphasised that threat discussions must produce practical, plain-language outputs that small administrations can actually use. Nauru specifically asked the mechanism to produce shared assessments in plain terms and early warning systems that reach small administrations. This raises important questions about the format and accessibility of mechanism outputs.
How should the global mechanism address the intersection of cyber risk and climate-related disasters, particularly for small island developing states?
Vanuatu
Vanuatu raised the novel point that for disaster-exposed nations, cyber risk and climate risk are compounding rather than parallel concerns. A malicious ICT incident during a disaster window could cost lives. This intersection is an underexplored area that warrants further research and consideration in the mechanism’s threat analysis.
How should the global mechanism address the use of commercial spyware and intrusive cyber tools against state officials, diplomats, journalists, and human rights defenders?
Algeria, Portugal, Botswana
Algeria highlighted evidence of systematic abuse of spyware against state officials and civil society actors, calling for explicit inclusion of this threat in mechanism reports and stronger international norms. Portugal raised concerns about the use of offensive cyber capabilities for transnational repression of diaspora communities. This area requires further research into accountability mechanisms and applicable international law.
How should the global mechanism integrate discussions currently taking place in external processes, such as the Counter Ransomware Initiative and AI governance forums, to avoid duplication while ensuring universal engagement?
Brazil, Switzerland, Estonia, Turkey
Brazil argued that discussions on ransomware, AI implications, and intrusive tools happening in ad hoc processes outside the UN must be integrated into the global mechanism to ensure universal legitimacy. Switzerland and Estonia cautioned against duplicating work in other processes. The question of how to achieve coherence across multiple international forums requires further consideration.
How should the global mechanism address the growing threat posed by loosely organised transnational collectives, including those composed predominantly of minors, whose activities blur the line between digital and physical harm?
Portugal
Portugal identified a distinct and underexplored category of threat actors: loosely structured transnational collectives, often composed of young people, engaging in intrusion, extortion, swatting, and harassment that can escalate to real-world harm. Portugal called for a response combining criminal justice with preventive and educational approaches. This phenomenon requires further research into appropriate governance and response frameworks.
How should the global mechanism address the security implications of the Internet of Things proliferation and cloud migration for critical infrastructure?
Botswana, Nigeria
Botswana and Nigeria highlighted the growing security vulnerabilities introduced by IoT devices and cloud infrastructure, including the risk that a single misconfiguration or attack on a major cloud provider could compromise essential public services. Further research is needed on how international norms and cooperative measures can address these systemic risks.
What diagnostic assessment of the existing capacity-building landscape should DTG 2 undertake, and how should it identify gaps and make recommendations for optimisation?
Brazil, African Group (Nigeria)
Brazil proposed that DTG 2 commence its work with a diagnostic assessment of existing capacity-building initiatives, evaluating their strengths and weaknesses. The African Group called for early operationalisation of specific tools including the global ICT security cooperation portal and a UN Voluntary Fund. The question of how to conduct such an assessment and what criteria to use requires further research.
How should the global mechanism address the growing shortage of cybersecurity experts globally, and what role should the UN play in coordinating capacity-building efforts?
Saudi Arabia, Brazil, Nigeria (African Group)
Saudi Arabia highlighted the global shortage of cybersecurity experts as a mounting challenge and described its Global Initiative for Capacity Building in Cyberspace. The question of how the UN can coordinate and centralise the many existing capacity-building initiatives to ensure equitable access and alignment with mechanism priorities requires further research and practical planning.
How should the global mechanism ensure that hybrid participation arrangements are genuinely functional for small and geographically distant states?
Kiribati
Kiribati stated that hybrid participation is non-negotiable and represents the difference between contributing and being absent for states far from New York. The question of what technical and procedural arrangements are needed to make hybrid participation genuinely effective, rather than nominal, requires further practical research and planning.
How should the global mechanism address the use of ICTs to facilitate trafficking in persons and other transnational crimes?
Vietnam
Vietnam raised the use of ICTs to facilitate trafficking in persons alongside other cybercrimes. This intersection between cybersecurity and transnational organised crime is an underexplored area within the mechanism’s mandate that warrants further research into appropriate cooperative measures.
How should the global mechanism address the cybersecurity risks associated with major international events, and what lessons can be drawn from recent experiences?
Mexico
Mexico highlighted the 2026 FIFA World Cup as an example of close sub-regional cooperation to protect critical infrastructure during large-scale events, describing it as a valuable experience of information sharing and joint preparation. The question of how such experiences can be systematised and shared through the mechanism to strengthen collective resilience requires further research.
How should the global mechanism address the risk of the digital divide becoming a security divide, particularly as advanced AI-enabled cyber capabilities become concentrated among a small number of actors?
Algeria, Brazil, South Africa
Algeria warned that if advanced AI cyber capabilities remain concentrated among few actors while many developing countries lack the infrastructure and expertise to defend themselves, the digital divide risks becoming a security divide. Brazil similarly called for narrowing the digital divide as essential to broad cybersecurity. This structural inequality requires further research into how the mechanism can address it practically.
How should the global mechanism address the security of early warning systems, emergency communications, and disaster coordination platforms as critical infrastructure?
Vanuatu, Tonga (Pacific Islands Forum)
Vanuatu and the Pacific Islands Forum called for early warning systems and disaster coordination platforms to be recognised at the top of the critical infrastructure catalogue. For disaster-prone small states, a cyber incident affecting these systems during a disaster window could cost lives. Further research is needed on how international norms and cooperative measures can specifically protect this category of infrastructure.
How should the global mechanism address the use of AI to generate synthetic content, including fabricated emergency notices or weather warnings, as a safety-of-life issue?
Vanuatu
Vanuatu raised the specific concern that AI-generated synthetic content, such as fabricated evacuation notices or falsified weather warnings, could send communities towards danger rather than away from it. This is framed not merely as an information integrity issue but as a safety-of-life concern. Further research is needed on how this specific threat can be addressed within the mechanism’s framework.
How should the global mechanism address the implications of advanced general-purpose AI models for lowering barriers to entry for less-resourced malicious actors, including criminal networks and terrorist organisations?
Turkey, Singapore, United Kingdom, Italy
Turkey and others raised the concern that widespread availability of advanced AI capabilities may lower the barrier for entry for criminal networks and terrorist organisations, creating risks that extend beyond individual incidents to international peace and security. The question of what voluntary norms, safeguards, and responsible access considerations should apply to high-capacity AI models requires further research.
How should the global mechanism address the need for mandatory cyber incident reporting and public-private information sharing as tools for enhancing collective resilience?
Switzerland, Sweden, Italy, Kazakhstan
Switzerland described its experience with mandatory reporting of cyber incidents affecting critical infrastructure as improving situational awareness and reinforcing public-private cooperation. Sweden highlighted effective public-private partnership as indispensable. The question of how such practices can be shared and potentially standardised through the mechanism requires further research and practical guidance.
Disclaimer: This is not an official session record. DiploAI generates these resources from audiovisual recordings, and they are presented as-is, including potential errors. Due to logistical challenges, such as discrepancies in audio/video or transcripts, names may be misspelled. We strive for accuracy to the best of our ability.