First substantive session of the UN Global Mechanism on cybersecurity
AI-generated report
7th meeting – Plenary Session
The seventh meeting of the substantive plenary session of the Global Mechanism on ICT security focused primarily on two agenda items: confidence-building measures (CBMs) and capacity building . Delegates from numerous states and regional organisations took the floor to share national experiences and recommendations for advancing the practical implementation of the agreed framework for responsible state behaviour in cyberspace.
On confidence-building measures, there was broad consensus that the Global Points of Contact Directory represents a significant achievement of the Open-Ended Working Group and should be further operationalised . Multiple delegations, including Vanuatu, Australia, and Germany, stressed that the directory must complement rather than replace existing diplomatic and regional communication channels, and that it should be used in good faith and with due regard for the capacity constraints of smaller states . Côte d’Ivoire and Cameroon recommended organising regular UN-sponsored simulation exercises and strengthening CBMs at the regional and sub-regional level . The Russian Federation noted that 125 states had joined the directory but highlighted practical challenges, including “dead contacts” and politically motivated non-responses, calling for a standardised communication template and in-person meetings of POC representatives .
Several delegations, including Tonga and the Dominican Republic, emphasised that confidence is built through sustained cooperation before a crisis occurs, citing real-world examples such as Tonga’s joint public attribution following a health system cyberattack . Regional organisations, including the OSCE and the African Union, shared their experiences implementing CBMs and recommended institutionalising dialogue between the global mechanism and regional bodies .
On capacity building, which formed the second major agenda item, the Pacific Islands Forum, the African Group, the European Union, and a Latin American group all underscored that capacity building is a cross-cutting enabler underpinning all pillars of the framework . Delegations called for the Dedicated Thematic Group 2 (DTG2) to serve as a strategic coordination platform that is demand-driven, nationally owned, and avoids duplication of existing initiatives . Practical proposals included a voluntary UN ICT Security Capacity Building Fund, a fellowship programme for developing countries, and the Global ICT Security Cooperation and Capacity Building Portal .
Overall, the discussion reflected strong agreement that the global mechanism must move beyond political commitments towards concrete, inclusive, and operationally effective implementation of both confidence-building measures and capacity-building initiatives, ensuring that no state, particularly small island developing states and least developed countries, is left behind .
-
Overall Purpose
-
The discussion takes place during the seventh meeting of the substantive plenary session of the Global Mechanism on ICT security. Its primary purpose is to advance international dialogue on confidence-building measures (CBMs) and capacity building in cyberspace, with a focus on translating previously agreed frameworks into practical, operational tools that reduce the risk of misunderstanding, escalation, and conflict among states.
-
—
-
Major Discussion Points
-
The Global Points of Contact (POC) Directory as a central confidence-building tool: Multiple delegations welcomed the establishment of the Global Intergovernmental Points of Contact Directory as a flagship practical achievement, while stressing that its value depends on use, regular testing, and good-faith engagement. Concerns were raised about “dead contacts,” low response rates, and misuse of the directory. Russia reported receiving 2,576 inquiries in the past year, with only approximately 48% responded to. Germany noted receiving repetitive, identical messages from a certain state that did not reflect responsible use of the directory. States broadly agreed the directory should complement, not replace, existing diplomatic and technical channels.
-
Operationalising CBMs through the Dedicated Thematic Groups (DTGs): A strong consensus emerged that the DTGs represent a critical opportunity to move beyond abstract political commitments and translate the eight agreed voluntary global CBMs into concrete, practical action. Argentina proposed that DTG1 focus on exchanging national and regional experiences and developing practical guidance, while DTG2 could identify capacity needs and promote voluntary exercises. The Dominican Republic cautioned that a designated contact point on paper is not the same as one capable of responding 24 hours a day, 365 days a year. Several delegations, including Tonga on behalf of the Pacific Islands Forum, urged that DTGs avoid becoming additional negotiating rooms reproducing procedural disagreements. – The role of regional organisations in implementing CBMs: Numerous delegations highlighted the indispensable role of regional bodies – including ECOWAS, the OAS, ASEAN, the African Union, the OSCE, and Pacific regional mechanisms – in developing and implementing CBMs tailored to local realities. The OSCE noted it was the first regional organisation to develop cyber CBMs and has 16 CBMs with years of practical implementation experience, including an “Adopt-a-CBM” initiative. The African Union Commission recommended that the global mechanism institutionalise regular technical dialogue with regional organisations and facilitate integration of regional POC networks with the global directory. Cross-regional learning and avoiding duplication were consistently emphasised.
-
Capacity building as a cross-cutting prerequisite for effective CBM implementation: Delegations from developing countries, particularly from Africa, the Pacific, Latin America, and the Caribbean, stressed that capacity building is not a secondary issue but a strategic enabler underpinning all pillars of the framework. CARICOM identified three regional priorities: cyber law, sustained cyber capacity building, and critical infrastructure protection for small states. The Philippines, Ireland, and Australia all noted that many states face institutional, technical, and resource constraints that prevent meaningful participation in CBMs. Calls were made for demand-driven, nationally owned, sustainable, and inclusive capacity-building initiatives, including a voluntary UN ICT Security Capacity Building Fund and a fellowship programme for developing countries.
-
Coherence, non-duplication, and the voluntary nature of CBMs: A recurring theme was the need to ensure that the expanding architecture of communication channels and CBM initiatives remains coherent and does not create burdens for states – particularly smaller ones – operating multiple channels through the same handful of officials. Vanuatu articulated this concern directly, calling for clear guidance on which channels serve which purpose and consistency in points of contact. Cuba and Iran both emphasised that the voluntary nature of CBMs must be preserved and that measures must respect sovereignty and non-interference in internal affairs. Germany stressed that any CBM, existing or newly proposed, should be concrete, action-oriented, voluntary, and focused on building transparency rather than creating obligations. —
-
Overall Tone
-
The overall tone of the discussion is constructive, cooperative, and pragmatic, with a shared sense of purpose around implementing the agreed framework for responsible state behaviour in cyberspace. Delegations across all regions expressed genuine commitment to advancing CBMs and capacity building, and there was broad convergence on key principles such as voluntariness, inclusivity, and the need to move from political commitments to practical action.
-
The tone remained largely consistent throughout, though it shifted slightly in emphasis as the session progressed. Early interventions from smaller states such as Vanuatu and Tonga introduced a grounded, operational perspective, highlighting the real-world constraints faced by nations with limited diplomatic and technical resources. Later contributions from larger delegations and regional organisations added layers of institutional experience and specific proposals. Germany’s remarks introduced a mildly cautionary note regarding the misuse of the POC directory, reflecting underlying tensions about good-faith engagement. The session on capacity building in the latter portion carried a more urgent and advocacy-driven tone, particularly from African and Latin American group statements, which framed capacity building as a matter of equity and sustainable development rather than merely a technical concern. There were no significant moments of open disagreement, though divergent priorities – particularly between developed and developing states – were evident beneath the surface of diplomatic language.
Expanded Summary: Seventh Meeting of the Substantive Plenary Session of the Global Mechanism on ICT Security
#
Opening and Agenda
The seventh meeting of the substantive plenary session of the Global Mechanism on ICT security was called to order by Chair Egriselda López . In accordance with the programme of work, the session continued with the list of speakers on the agenda item on confidence-building measures (CBMs), with 22 requests for the floor outstanding at the start of proceedings . The session subsequently moved to a second major agenda item on developing and implementing capacity building . Throughout both segments, delegations from all regions, as well as regional organisations and accredited stakeholders, took the floor to share national experiences, highlight operational challenges, and advance proposals for the practical implementation of the agreed framework for responsible state behaviour in cyberspace.
—
#
Confidence-Building Measures: Foundational Principles and Broad Consensus
There was near-universal agreement across the session that CBMs are indispensable practical tools for fostering trust, transparency, predictability, and cooperation among states, contributing to international peace and security in cyberspace . Nigeria, speaking on behalf of the African Group, affirmed that CBMs are essential for reducing the risk of misunderstanding and miscalculation . Israel described CBMs as allowing states to build practical procedures during peacetime that can be directly utilised for de-escalation, communication, and risk reduction during geopolitical crises . Australia characterised CBMs as tools for reducing the risk of misinterpretation, escalation, and conflict, helping states build relationships and establish communication channels before a crisis occurs so that these channels can be used effectively during and after cyber incidents .
Côte d’Ivoire offered a normative framing, observing that in cyberspace, uncertainty about the origin, intention, or scale of an incident can rapidly give rise to misunderstandings and stoke tensions, and that the lack of reliable communication channels can transform a technical incident into a political crisis . The delegation argued that trust is not something that can be declared by fiat but is built by dialogue, transparency, predictability, and results-based cooperation . Cameroon similarly described CBMs as providing one of the most direct avenues for translating political commitments into practical cooperation, contributing to reducing misunderstandings, preventing misperceptions, and lowering the risk of unintended escalations . North Macedonia noted that CBMs are among the most valuable outcomes of the Open-Ended Working Group (OEWG) process, demonstrating that states can agree on practical measures to strengthen trust and improve communication even in a complex and rapidly evolving cyber environment .
Norway outlined three specific points on CBMs: first, that CBMs provide practical tools for implementing agreed commitments through mechanisms such as points of contact, dialogue, sharing of best practices, and information sharing; second, that CBMs enable practical cooperation between states, creating opportunities to exchange experiences, share best practices, and strengthen implementation of the framework including resilience, incident response, and protection of critical infrastructure; and third, that effective implementation requires capacity and broad participation including through the inclusion of women. Norway also noted that capacity building and confidence building are mutually reinforcing.
Several delegations introduced important nuances to this broad consensus. Cuba explicitly stated that CBMs on their own do not guarantee the strictly peaceful use of ICTs and that they are merely complementary to binding norms, emphasising that the voluntary nature of CBMs must prevail and that different phases of confidence building must respect sovereignty and non-interference in internal affairs . Cuba also stressed that the establishment of binding norms within the UN framework is itself one of the pillars for international confidence building . Germany, by contrast, argued that any CBM – existing or newly proposed – should be concrete, action-oriented, and voluntary in nature, and should avoid entering the field of expectations or even obligations , reflecting a preference for keeping CBMs strictly voluntary rather than moving towards binding frameworks.
—
#
The Global Points of Contact Directory: Achievements and Operational Challenges
The Global Intergovernmental Points of Contact (POC) Directory was consistently identified as the flagship practical achievement of the OEWG . Tonga strongly supported the directory as the flagship practical achievement and commended UNODA for its continued operationalisation . Argentina underscored the directory as one of the most relevant milestones achieved in the OEWG . The Russian Federation, which claimed the directory was established on its initiative, described it as enabling the first universal confidence-building measure in the field of international information security, establishing a mechanism for preventing interstate conflicts in the information space . By the time of the session, 125 states had joined the directory .
Despite this broad support, the session surfaced significant operational challenges. The Russian Federation provided detailed statistics, reporting that its POC had received 2,576 inquiries in the previous year, of which only approximately 48% were responded to . Russia attributed this to what it termed “dead contacts” – where organisations or individuals not authorised to engage in specialised cooperation are designated to the directory – as well as the continuous availability problems of technical POCs, and cases where certain capitals simply ignore requests for political reasons . Russia called for the finalisation of a standardised communication template as a priority task, noting that a draft had been presented by UNODA but had not been substantively discussed before the OEWG’s final report was adopted . Russia also called upon the Chair to include a separate agenda item in the Global Mechanism’s programme of work for discussing issues related to supporting and improving the POC directory , and proposed in-person meetings of POC representatives as envisaged in the OEWG final report . Russia additionally announced plans to contribute to the development of the POC directory by practising POC interaction under a Russian Capacity Building Initiative, which it indicated it would introduce under the relevant agenda item.
Germany’s subsequent intervention introduced a notable moment of diplomatic tension. Without naming Russia explicitly, Germany reported that its technical POC had received repetitive, identical messages from a certain state that did not take into account its replies, characterising this as “clearly not in line with the purpose of the UN POC directory” and as not presenting “a responsible or sincere use of the directory” . This exchange revealed that political dynamics were already manifesting within what was designed as a non-politicised, technical communication mechanism . Germany indicated that its Federal Foreign Office serves as the diplomatic POC and its Cyber Security Agency as the technical POC, and that it remains open to engaging in good faith with all interested parties .
Australia reinforced the need for responsible use, calling for requests through the directory to be proportionate, purposeful, and made with due regard to the capacity constraints of smaller states . Australia explicitly warned that the directory should not be treated as a mechanism for overwhelming national points of contact, creating unreasonable expectations of response, or as a substitute for existing procedures where other channels are more appropriate . Thailand supported regular communication checks, simulation exercises, and continued engagement to ensure the directory remains effective when needed most . Thailand also considered the communication template provided by the Secretariat pursuant to A/79/14 as a useful tool and suggested incorporating elements such as urgency and confidentiality to better reflect operational needs, particularly in time-sensitive or critical situations. The African Union Commission recommended facilitating the integration of regional points of contact with the global POC directory , while Cameroon envisioned the directory evolving from a repository of contacts into a dynamic instrument for cooperation with progressively enhanced functionalities .
A recurring theme across multiple delegations – including Ireland, the Netherlands, Germany, Vanuatu, and Australia – was that the POC directory must complement rather than replace existing diplomatic and technical communication channels . Ireland stated it should be used in good faith as a complement to existing channels . The Netherlands argued that its strength and added value lie in establishing lines of contact where these previously were unavailable or unclear, and that it should not replace existing POC networks or other diplomatic channels . Germany similarly argued the directory is not intended to replace established channels such as FIRST, the network of CERTs, CERT-to-CERT cooperation, or law enforcement cooperation . Malaysia mentioned the ASEAN Regional Forum Points of Contact Directory as an example of how regional efforts can complement the implementation of CBMs. Vanuatu articulated this concern most directly from the perspective of small administrations, noting that the international community is multiplying its channels of communication and requesting clear guidance on which channels serve which purpose, consistency in points of contact where national structures allow it, and no duplication of what already functions elsewhere .
—
#
Vanuatu and Tonga: Pacific Perspectives on Practical Confidence Building
Vanuatu offered one of the session’s most conceptually distinctive contributions, reframing the discussion on the POC directory from a quantitative to a qualitative lens. The delegation observed that “confidence is not built by the number of channels that exist, or the volume of requests within them, but by the certainty of what happens when one is used” . Vanuatu also drew a compelling analogy between disaster response and cyber incident cooperation, noting that when disaster strikes its islands, information flows between governments within hours – offers of assistance, coordination of relief, verification of facts on the ground – and that this habit of rapid, trusted state-to-state communication in physical emergencies is precisely the habit the CBM agenda seeks to create for digital ones . The delegation argued that a region accustomed to cooperating through cyclones is well-placed to cooperate through cyber incidents .
Vanuatu further emphasised transparency as a measure available to every state regardless of size, noting its own openness about national arrangements, legislative development including its data protection and privacy bill, and assessments of the threat environment . The delegation called for the structured exchange of such national information within the mechanism, not as a reporting burden, but as routine practice that prevents misreading between states . Vanuatu also supported regular communications exercises for the directory, sustained training for designated officials with attention to continuity as personnel change, and the preservation of hybrid modalities so that distance never determines who participates in building confidence .
Tonga provided the session’s most powerful empirical illustration of CBMs working in practice. The delegation noted that when its health system was attacked the previous year, established relationships with partners enabled rapid assistance and ultimately a joint public attribution with Australia and New Zealand . Tonga characterised this as demonstrating “what confidence building measures look like when they work: relationships built before the crisis, exercised during it and deepened after it” . Tonga’s CERT, established by cabinet decision in 2016 as among the first national CERTs in the Pacific, had worked within the Pacific Cyber Security Operational Network, where incident responders share information and build the personal trust on which crisis cooperation depends . Tonga accordingly urged the mechanism to “keep the CBM agenda modest in rhetoric and ambitious in practice” – a directory that works, points of contact who are trained and exercised, regional experience feeding global learning, and hybrid participation so that officials from Nukuʻalofa can engage .
—
#
CBMs as Preventive Diplomacy: The Dominican Republic’s Regional Lessons
The Dominican Republic offered a particularly candid and analytically rigorous contribution, drawing on its experience as chair of the OAS working group on CBMs in cyberspace during the 2024-2025 session . The delegation argued that the challenge is no longer normative but practical, since global CBMs benefit from broad political backing but what is lacking is translating these CBMs into established capacities . Crucially, the Dominican Republic drew a sharp distinction between CBMs as preventive diplomacy tools and real-time incident response mechanisms, noting from regional experience that when ransomware struck essential public services, “bilateral technical direct cooperation was key” and that CBMs helped to boost confidence and trust in order to engage and host technical assistance and act rapidly – but were not themselves the response mechanism .
The Dominican Republic also called for transparency in POC directory response metrics, arguing that sharing these metrics would reflect both the real results of implementation and the real commitment of each party . The delegation highlighted the OAS’s development of a common severity scale for incidents, which allows all members to understand and recognise how serious an incident affecting another member state is, and noted that measuring severity can help prioritise and scale cooperation between national CERTs . The delegation also emphasised that no CBM can be implemented in a void and that national mechanisms and practical measures are needed to turn these tools into regulations and achieve institutional continuity when staff turnover occurs – a challenge particularly relevant in Latin American countries .
—
#
Operationalising CBMs Through the Dedicated Thematic Groups
A strong consensus emerged that the Dedicated Thematic Groups (DTGs) represent the primary vehicle for translating agreed CBMs into practical action. Israel stated that the DTGs must prioritise further developing and operationalising CBMs, as they hold great potential for immediate positive impact and for generating beneficial momentum for the global mechanism . Chile viewed the DTGs as offering a valuable opportunity to go into further depth on the role of international organisations in effective CBM implementation, exchanging national experiences and good practices . Argentina proposed a division of labour between DTG1, which could examine the operationalisation of CBMs by exchanging national and regional experiences and developing practical guidance, and DTG2, which could identify the capacities required to support this operationalisation effort, including proposals to strengthen national capacities of contact points and promote voluntary exercises .
Argentina further expressed hope that the DTGs would establish themselves as spaces for technical work capable of producing substantive recommendations and decisions on CBMs for consideration by the plenary, and that these recommendations would subsequently be reviewed, fine-tuned, and negotiated by states in plenary deliberations . Cameroon offered a distinctive framing, stating that “the success of the DTGs is a confidence building measure” given its capacity to bring states together to strengthen exchanges and enable a lasting culture of cooperation in cyberspace to emerge. This vision of DTGs as quasi-negotiating spaces producing actionable outputs was not universally shared. The Pacific Islands Forum, speaking through Tonga, explicitly warned that DTGs should not become additional negotiating rooms that reproduce the same procedural disagreements or simply repeat plenary discussions, with their value to be measured by whether they help countries make progress . The Netherlands suggested that simulation exercises within DTGs could demonstrate how public-private partnerships could concretely benefit an open, free, and secure cyberspace . North Macedonia called for CBMs to be reflected in DTG work through sharing of national experience, practical implementation approaches, and good practices, while avoiding duplication of plenary discussions .
—
#
Regional Organisations: Indispensable Partners in CBM Implementation
Delegations from all regions consistently highlighted the indispensable role of regional organisations in developing and implementing CBMs tailored to local realities. The African Group encouraged the global mechanism to strengthen coordination and complementarity between global and regional confidence-building initiatives, promote linkages between regional POC networks and the global directory, support regional cyber exercises and capacity building, and encourage voluntary exchange of national experiences and good practices . Chile argued that the exchange of good practices between regional mechanisms could make meaningful contributions to strengthening CBM implementation globally, avoiding duplications and making the most of lessons learned in different contexts .
Uruguay highlighted the OAS experience as a practical model, noting that since 2018 it has designated and updated its technical contact points in the OAS framework and participates actively in cooperation mechanisms such as CERT Americas, promoting the exchange of technical information including indicators, good practices, and strengthening of state capacities . Ghana pointed to the ECOWAS regional framework on cyber ICT confidence-building measures, which establishes practical mechanisms including national diplomatic and technical points of contact and information-sharing arrangements . The Philippines, as ASEAN Chair in 2026, welcomed progress in operationalising the ASEAN Regional CERT as an important step toward raising the regional cybersecurity posture through timely information sharing and coordinated incident response .
The OSCE described itself as the first regional organisation to develop cyber confidence-building measures and noted it has many years of experience in the practical implementation of its 16 CBMs . The OSCE described its “Adopt-a-CBM” initiative, through which 26 participating states have adopted nine CBMs and significantly contributed to their meaningful implementation . The OSCE also noted that it held its sixth annual meeting of technical and policy points of contact in Vienna the previous month, where the global mechanism was discussed with the aim of raising awareness . The OSCE Secretariat referenced a non-paper on inter-regional cooperation submitted by Switzerland to the second OEWG in June 2024, prepared with contributions from seven regional organisations, which provided recommendations on how regional organisations could contribute to future discussions .
The African Union Commission endorsed the African Group’s statement and provided additional detail on its own work, noting that the common African position on the application of international law to cyberspace reaffirms the importance of the peaceful settlement of disputes in cyberspace . The Commission stated that its ambition is not to reproduce existing models or multiply the number of CBMs, but to set out concrete, adapted measures suited to African realities that can be effectively implemented across the various regions of the continent, drawing on experience from economic and regional committees including ECOWAS . The Commission recommended that the global mechanism institutionalise a technical and regular dialogue with regional organisations, strengthen support to regional organisations for CBM development and implementation, and facilitate the integration of regional points of contact with the global POC directory .
Bosnia and Herzegovina highlighted the launch of the Western Balkans Cyber Diplomacy Network in 2025, supported by the German Federal Foreign Office, as a regional initiative representing the region’s shared commitment to addressing cross-border cyber challenges through dialogue and cooperation . Germany noted its close work with ECOWAS member states and the ECOWAS Commission in their journey towards the adoption of a first set of CBMs in Africa , and co-hosted a side event with Ghana and the Dominican Republic on regional best practices for CBM implementation .
Cuba introduced an important caveat, arguing that each region or sub-region has unique characteristics and that measures implemented at these levels cannot be considered single global models or benchmarks . The African Union Commission similarly stated that its ambition is not to reproduce existing models , reflecting a shared concern that regional approaches should be contextually adapted rather than universally imposed.
—
#
Simulation Exercises, Training, and Practical Cooperation
Multiple delegations emphasised that simulation exercises, regular training, and practical cooperation activities are essential for building confidence before crises occur. Côte d’Ivoire recommended regularly organising under UN auspices simulation exercises that bring together points of contact, national incident response teams, and relevant authorities . Argentina supported continuing voluntary exercises, gradually fine-tuning their modalities and exchanging experiences that encourage practical use of the POC directory . Australia highlighted its Cyber Rapid Assistance for Pacific Incidents and Disasters programme as an example of building trust and habits of trust between states and regions, emphasising that cooperation must be established before it is needed in a crisis . The OSCE described its scenario-based exercises as usually well received by participants, helping them understand the practical application of CBMs . Thailand supported regular communication checks, simulation exercises, and continued engagement to ensure the directory remains effective when needed most .
Botswana provided a detailed account of its national CBM implementation, noting that it has operationalised its national cybersecurity strategy and established the Botswana Computer Incident Response Team under the Botswana Communications Regulatory Authority to coordinate incident management, issue threat advisories, and safeguard national critical infrastructure . Botswana also described its engagement in formal bilateral and sub-regional information-sharing protocols among CERTs within the SADC region, its participation as a continental partner under the African CERT umbrella, and its formal public-private partnerships, threat intelligence sharing, and academic collaboration . Malawi noted its role as Vice Chair of the SADC CICERT working group and its engagement with FIRST, Africa CERT, and the ITU .
—
#
Iran’s Proposals for New Confidence-Building Measures
The Islamic Republic of Iran introduced two substantive proposals that went beyond the consensus positions of most other delegations. First, Iran highlighted a proposal from paragraph 47k of the OEWG final report for a new CBM aimed at facilitating access by all states to ICT security products and tools, arguing that this strengthens national capacities while simultaneously promoting cooperation, trust, and confidence among states . Second, drawing on paragraph 52 of the OEWG final report, Iran proposed that the global mechanism prepare a consolidated list of technical terms used in consensus-based OEWG reports and undertake discussions to develop common understandings of key concepts such as ICTs, ICT infrastructure, ICT environment, and malicious use of ICTs . Iran called for both proposals to be considered by the first DTG and incorporated into the existing set of eight voluntary global CBMs . These proposals touched on politically sensitive issues – including technology transfer, export controls, and definitional disputes – that are likely to resurface in the DTGs.
—
#
Capacity Building: A Cross-Cutting Strategic Priority
The second major agenda item – developing and implementing capacity building – generated an equally extensive discussion, with 43 requests for the floor received . There was strong consensus across all regional groups that capacity building is a cross-cutting enabler underpinning all pillars of the framework for responsible state behaviour, not merely a standalone pillar . The Pacific Islands Forum, speaking through Tonga, described capacity building as “the enabler that underpins all aspects of our work,” foundational to responding to threats, implementing norms, engaging meaningfully in international law discussions, and sustaining CBMs, and argued it should not be siloed . The African Group stated that for African countries, capacity building is not an auxiliary issue but a strategic enabler for achieving a secure, resilient, and inclusive digital future as digital transformation accelerates across the continent .
Costa Rica offered one of the session’s most memorable formulations, warning that “without capacities, we run the risk of building a legally elegant infrastructure that is operationally useless” . The delegation described capacity building as a bridge between consensus and action, arguing that voluntary norms, international law, CBMs, and due diligence can only be turned into policies and practical steps if states have technical, legal, and institutional capacities that are up to the mark . Costa Rica also highlighted that legal interpretation requires specialised institutional capacities, including the ability to evaluate incidents, establish national positions on the application of international law to cyberspace, understand different legal thresholds, and participate responsibly in international debates . Morocco similarly described capacity building as “the guiding thread that runs through all the other pillars of responsible behavior” .
Vietnam stated that capacity building is essential for states to develop common understanding of voluntary non-binding norms of responsible state behaviour, shared experiences, and best practices in applying these norms to protect critical infrastructure and supply chains. Vietnam supported flexible and inclusive capacity building to bridge the digital divide, incorporating gender equality and awareness raising. Vietnam also announced its initiative to establish an Asia-Pacific Regional Cybercrime Center in Hanoi in cooperation with UNODC, as a follow-up to the ratification of the UN Convention against Cybercrime, welcoming participation of other states and stakeholders as sponsors and partners.
—
#
DTG2 as the Main Platform for Capacity Building Dialogue
The Latin American group, with Chile speaking on behalf of Argentina, Brazil, Colombia, Costa Rica, Ecuador, Guatemala, Honduras, Mexico, Paraguay, Peru, the Dominican Republic, and Uruguay, called for DTG2 to be established as the main platform for dialogue on capacity building within the global mechanism, playing a fundamental role as a space for strategic coordination to facilitate information exchange, articulate synergies between existing mechanisms, and identify opportunities for cooperation . The group announced it would soon present a working document with concrete proposals on the future functions, priorities, and modalities of DTG2 . The group also emphasised that both DTGs play different but complementary roles and must be worked on together in a balanced way, with the cross-cutting nature of capacity building reflected throughout .
The African Group called for DTG2 to build upon rather than duplicate the valuable outcomes of the OEWG, and welcomed a proposal for a structured diagnostic assessment of the current capacity-building landscape as a DTG2 deliverable . The group outlined African capacity-building priorities including strengthening national cybersecurity strategies and governance frameworks, developing legislative and regulatory frameworks, enhancing technical and operational capabilities including national and sectoral CERTs, building cyber diplomacy expertise, promoting cyber resilience for critical infrastructure, supporting digital forensics and cybercrime investigation, and fostering regional cooperation and information sharing . The African Group also supported practical initiatives including the Global ICT Security Cooperation and Capacity Building Portal, the Point of Contact Directory, strengthened national CERTs, a Voluntary UN ICT Security Capacity Building Fund and Programme to Develop Cyber Security Professionals, and a United Nations ICT Security Fellowship Programme for developing countries with attention to least developed countries and small island developing states. The European Union highlighted its significant investment of 100 million euros across 27 projects globally and its commitment to continue investing, recognising capacity building as an essential pillar of security and stability in cyberspace . The EU also proposed that the global roundtable on capacity building could play a coordination role, bringing together capacity-building implementers for exchange of information and best practices, feeding into plenary and DTG2 discussions .
CARICOM, with the Bahamas speaking on behalf of the 14-member Caribbean community, specifically welcomed the establishment of DTG2 on capacity building, describing it as “a cornerstone of the evolving framework for responsible state behaviour in cyberspace.” CARICOM identified three regional priorities: cyber law and modern legal and regulatory frameworks, sustained cyber capacity building for resilience and technical expertise, and critical infrastructure protection for small states . CARICOM noted that the 2025 OAS IDB Cybersecurity Report confirmed both progress and persistent gaps in resources, workforce development, and cross-sector coordination across the region , and supported capacity-building initiatives that are voluntary, demand-driven, sustainable, transparent, and based on national ownership .
—
#
Demand-Driven, Nationally Owned, and Sustainable Capacity Building
A strong consensus emerged that capacity building must be demand-driven, nationally owned, sustainable, and tailored to the specific needs and priorities of countries . The African Group underscored that effective capacity building must respect national sovereignty and regional perspectives and realities . Colombia emphasised the value of South-South and triangular cooperation as particularly valuable modalities for capacity building, facilitating the exchange of knowledge and good practices while taking account of local realities and priorities . Colombia also proposed incorporating analysis of specific real case studies and hypothetical scenarios into DTG2 discussions to generate concrete lessons and practical recommendations . Iraq stressed that capacity building should receive financial and technical support so that equal opportunities are available to all states, with special attention to developing countries and countries emerging from conflict . Nigeria called for DTG2 to prioritise strengthening national cybersecurity strategies, legal and governance frameworks, technical capabilities including CERTs, and expertise in cyber diplomacy, digital forensics, and cybercrime investigations . Nigeria also supported practical initiatives including the Global ICT Security Cooperation and Capacity Building Portal, strengthened national CERTs, a Voluntary UN ICT Security Capacity Building Fund, and a UN ICT Security Fellowship Programme for developing countries, particularly least developed countries and small island developing states .
—
#
Small Island Developing States and the Digital Divide
Small island developing states and geographically distant delegations consistently emphasised that their unique circumstances create specific challenges for CBM implementation and that the global mechanism must be designed with these constraints in mind. Tuvalu highlighted its Tuvalu Subsea Cable as a vital digital lifeline and called for clear international guidance for the protection of subsea infrastructure, seeking an explicit CBM commitment from all member states and stakeholders to share best practices to safeguard this essential digital lifeline from both natural hazards and malicious cyber threats . Tuvalu also introduced the concept of “capacity sovereignty,” arguing that international cooperation must shift away from short-term external consulting and towards tangible long-term training of local technical teams, with true confidence established where every state possesses the sovereign ability to manage its own digital systems independently . Tuvalu announced it would host the 19th Asia-Pacific Telecommunication Policy and Regulation Forum from 4 to 6 August, framing it as a practical confidence-building measure in itself .
Botswana argued that global transparency initiatives must be paired with concrete technical assistance to address the digital divide, and that states should leverage regional and sub-regional platforms to strengthen operational mechanisms . The Pacific Islands Forum called for improvements to accreditation and participation modalities so that stakeholder participation is real rather than nominal, and urged that meeting times be rotated so Pacific delegations are not consistently asked to participate in the middle of the night . The Democratic Republic of Congo joined calls from Colombia and Mexico to promote multilingualism as a guarantor of inclusivity in negotiation spaces, ensuring effective participation by everyone .
—
#
Stakeholder Engagement: Private Sector, Civil Society, Academia, and Youth
There was broad agreement on the importance of stakeholder engagement from the private sector, civil society, academia, and the technical community for effective CBM implementation and capacity building. Ireland argued that the expertise and experience of these stakeholders should play a strong role in the process, with practical tools, best practices, and examples feeding engagement and allowing CBMs to be reflected in national and regional structures . Ireland also highlighted specific CBMs to be implemented, including sharing national ICT-related information and actions, exchanging experience on protecting critical infrastructure, promoting information exchange and cooperation and partnerships between states to strengthen ICT security capacity, and organising regular seminars, workshops, and training programmes on ICT security. Australia stated that industry and the technical community, civil society, and academia are often closest to vulnerabilities, incidents, and emerging risks, and that their expertise can help states understand threats, improve prevention and response, strengthen supply chain resilience, and translate CBMs into practical action, while preserving the intergovernmental nature of decision-making . Uruguay highlighted that public-private partnerships are essential given that a significant part of critical information infrastructure is operated by non-governmental actors or is part of the supply chain . The Pacific Islands Forum strongly supported the substantive inclusion of stakeholders in both formal and informal settings and the fullest possible use of expert briefings within the DTGs .
The DMUN Foundation, speaking on behalf of the Youth Publications and Socioeconomic Forum, introduced the novel argument that youth engagement should be considered a practical confidence-building measure in itself, including through structured dialogues between governments and youth, support for youth-led cyber awareness initiatives, and opportunities for young experts to participate in regional and international CBM activities . The Foundation noted that today’s youth are the first generation to grow up in an environment where cyber incidents, online disinformation, and AI-generated content are part of everyday life, yet are rarely included in discussions on how trust and confidence in cyberspace should be built . Nigeria commended initiatives such as the UNODA and donor-sponsored Women in International Security and Cyberspace Fellowship as making valuable contributions to broadening inclusive participation .
—
#
Chair’s Summary and Transition to Capacity Building
Before giving the floor to Botswana, Chair López acknowledged that it was the last day for Ambassador Norman of the Netherlands serving as Special Envoy for Cyber Issues, and called for a round of applause from the room in recognition of his long journey in the mechanism.
In her closing summary of the CBMs agenda item, Chair López noted that delegations had reflected on the eight global measures, including information exchange measures, collaboration between the public and private sectors, and capacity building as a cross-cutting topic . She welcomed state participation in the POC directory and expressed hope that universal participation would eventually be achieved, urging all states that had not yet done so to appoint and nominate diplomatic contact points and engage in verifications to ensure these contacts remain and operational . The Chair noted that all statements had been taken as important inputs for determining how to structure discussions in the DTGs .
Following the conclusion of the CBMs agenda item, the Chair opened the floor to accredited stakeholders in accordance with the modalities established in Annex 1 of A/82/57, allowing them to make oral statements with a strict limit of three minutes each . The session then transitioned to the capacity building agenda item, with 43 requests for the floor received . The meeting was adjourned with 49 requests still outstanding under the capacity building item, with the Chair announcing that the remaining delegations would be heard in the afternoon session at 3 p.m. .
—
#
Overall Assessment
The seventh meeting of the substantive plenary session demonstrated a remarkably high level of consensus across geographically and politically diverse delegations on the fundamental importance of CBMs and capacity building as pillars of the framework for responsible state behaviour in cyberspace. The core principles of CBMs as practical tools, the value of the POC directory, the importance of capacity building, the role of regional organisations, and the need for practical operationalisation through DTGs commanded near-universal support. The most significant areas of tension – the implicit Russia-Germany conflict over good-faith use of the POC directory , Cuba’s distinct position on binding norms , and the burden placed on small island developing states by multiplying communication channels – were present in the discussions, though not always directly contested. Among the most analytically substantive contributions were those that combined concrete evidence or lived experience with normative framing, exemplified by Tonga’s account of its health system attack , the Dominican Republic’s lessons from regional ransomware incidents , and Costa Rica’s formulation about “legally elegant but operationally useless” infrastructure . These contributions deepened the level of analysis and set a practical standard against which the global mechanism’s future work in the DTGs will be measured.
The knowledge base indicates that the Global Mechanism on ICT Security was established with its first substantive plenary session scheduled for July 2026 [S190] [S191]. The report describes a ‘seventh meeting of the substantive plenary session of the Global Mechanism on ICT security,’ which appears inconsistent with the knowledge base timeline. Additionally, [S192] references a ‘Seventh OEWG Session on ICT Security,’ suggesting the session described in the report may actually be the seventh meeting of the OEWG (Open-Ended Working Group), not of the Global Mechanism. The report may be conflating or mislabelling the body in question.
The knowledge base confirms Nigeria spoke on behalf of the African Group in OEWG discussions on agenda item 5 [S68] [S154]. CBMs are also broadly described as serving to reduce misunderstanding and prevent conflict escalation [S88], corroborating the substance of Nigeria’s statement.
The knowledge base confirms that the OEWG process produced agreed voluntary global confidence-building measures, described as helping build trust and foster mutual understanding among states [S195]. This provides context supporting North Macedonia’s characterisation of CBMs as valuable OEWG outcomes, though North Macedonia’s specific statement is not directly corroborated.
The knowledge base confirms that capacity building (agenda item 5 or 6 depending on the session) was a substantive agenda item discussed in OEWG plenary sessions, with multiple delegations taking the floor on this topic [S18] [S23] [S142].
The knowledge base broadly confirms this characterisation of CBMs. [S125] describes CBMs as ‘multifaceted tools essential for fostering transparency, cooperation, and stability while reducing conflicts by preventing misunderstandings and easing tensions.’ [S124] similarly notes CBMs as vital tools for enhancing cyber stability.
The knowledge base does not provide specific figures on the number of speakers queued for the CBMs agenda item. However, multiple sources confirm that CBMs attracted broad participation from delegations across regions in OEWG sessions [S68] [S120] [S154], providing general context for a large speakers’ list.
Background and Research Context
Media Remuneration Policy Analysis Mitchell began by establishing her background and the context for CNTI’s work. Coming from 25 years at the Pew Research Center where she helped l…
CBMs as essential tools for preventing escalation and fostering trust – CBMs are indispensable for fostering trust, transparency, predictability and cooperation among states, contributing to international peace and security in cyberspace (NIgeria on behalf of African Group)
Arg. 1
The African Group affirms that confidence-building measures are indispensable for fostering trust, transparency, predictability and cooperation among states. These measures contribute directly to international peace, security and stability in cyberspace.
The African Group explicitly affirmed that CBMs are indispensable for fostering trust, transparency, predictability and cooperation among states, thereby contributing to international peace, security and stability in cyberspace .
on: CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace
African peace and security architecture as a model for cyber cooperation – African experience in conflict prevention and security cooperation, including through the African peace and security architecture, demonstrates the value of sustained dialogue and cooperative approaches relevant to cyberspace (NIgeria on behalf of African Group)
Arg. 2
The African Group draws on the continent's experience in conflict prevention and security cooperation, including through the African peace and security architecture, as a model for cyber cooperation. The principles of sustained dialogue, effective communication channels and cooperative approaches are equally relevant to reducing the risk of misunderstanding and miscalculation in cyberspace.
The African Group noted that African experience in conflict prevention and security cooperation, including through the African peace and security architecture, demonstrates the value of sustained dialogue, effective communication channels and cooperative approaches to addressing shared security challenges, and that these principles are equally relevant to strengthening confidence and reducing the risk of misunderstanding and miscalculation in cyberspace .
Regional organisations play an important role in advancing CBMs – The global mechanism should strengthen coordination and complementarity between global and regional confidence-building initiatives and promote linkages between regional POC networks and the global directory (NIgeria on behalf of African Group)
Arg. 3
The African Group underscores the important role of regional and sub-regional organisations in advancing confidence-building through dialogue, information sharing, cyber diplomacy and practical cooperation. The group encourages the global mechanism to strengthen coordination between global and regional initiatives and promote linkages between regional POC networks and the global directory.
The African Group encouraged the global mechanism to strengthen coordination and complementarity between global and regional confidence-building initiatives, promote linkages between regional point-of-contact networks and the Global Point of Contact Directory, support regional cyber exercises and capacity building, and encourage the voluntary exchange of national experiences and good practices .
on: Regional organisations play an important role in advancing CBMs and their experiences should inform global implementation
Capacity building as a strategic enabler for African countries – For African countries, capacity building is not an auxiliary issue; it is a strategic enabler for achieving a secure, resilient and inclusive digital future as digital transformation accelerates across the continent (NIgeria on behalf of African Group)
Arg. 4
The African Group views capacity building as a strategic enabler rather than a secondary concern, essential for achieving a secure, resilient and inclusive digital future. As digital transformation accelerates across the continent, strengthening national and regional cyber capacity remains essential for states to prevent, detect, respond to and recover from cyber threats.
The African Group stated that for African countries, capacity building is not an auxiliary issue but a strategic enabler for achieving a secure, resilient and inclusive digital future, and that strengthening national and regional cyber capacity remains essential to enabling states to prevent, detect, respond to and recover from cyber threats while advancing sustainable development in line with African Union Agenda 2063 and the Digital Transformation Strategy for Africa 2020-2030 .
on: Capacity building is a cross-cutting priority and essential enabler for effective CBM implementation
Capacity building must be demand-driven, nationally owned and sustainable – Effective capacity building must be demand-driven, nationally owned, sustainable, and tailored to the specific needs and priorities of countries, respecting national sovereignty (NIgeria on behalf of African Group)
Arg. 5
The African Group emphasises that effective capacity building must be demand-driven, nationally owned, sustainable and tailored to the specific needs and priorities of countries. It must also promote inclusive approaches through the meaningful participation of women, men, youth, academia, the technical community, civil society and the private sector.
The African Group underscored that effective capacity building must be demand-driven, nationally owned, sustainable and tailored to the specific needs and priorities of countries, and must promote inclusive approaches through the meaningful participation of women, men, youth, academia, the technical community, civil society and the private sector, recognising that cybersecurity is a shared responsibility requiring all-of-society approaches .
on: Capacity building must be demand-driven, nationally owned, sustainable and tailored to specific national needs
Need for a voluntary UN ICT Security Capacity Building Fund – The African Group encourages progress on practical initiatives including a Voluntary UN ICT Security Capacity Building Fund and a UN ICT Security Fellowship Programme for developing countries, particularly least developed countries and small island developing states (NIgeria on behalf of African Group)
Arg. 6
The African Group encourages progress on a range of practical initiatives to support capacity building, including a Voluntary UN ICT Security Capacity Building Fund and a UN ICT Security Fellowship Programme. These initiatives should be designed to ensure efficiency, transparency and equitable access, with particular attention to least developed countries and small island developing states.
The African Group encouraged progress on practical initiatives including the Global ICT Security Cooperation and Capacity Building Portal, the Point of Contact Directory, strengthened national CERTs, a Voluntary UN ICT Security Capacity Building Fund, and a UN ICT Security Fellowship Programme for developing countries with attention to least developed countries and small island developing states, designed to ensure efficiency, transparency and equitable access .
Women's meaningful participation in cybersecurity – Effective capacity building must promote inclusive approaches through the meaningful participation of women, men and youth, recognising that cybersecurity is a shared responsibility requiring all-of-society approaches (NIgeria on behalf of African Group)
Arg. 7
The African Group stresses that capacity building must promote inclusive approaches that ensure the meaningful participation of women, men and youth alongside academia, the technical community, civil society and the private sector. Cybersecurity is a shared responsibility requiring all-of-society approaches.
The African Group stated that capacity building should promote inclusive approaches through the meaningful participation of women, men, youth, academia, the technical community, civil society and the private sector, recognising that cybersecurity is a shared responsibility requiring all-of-society approaches .
CBMs as practical tools for de-escalation – CBMs allow states to build practical procedures during peacetime that can be directly utilised for de-escalation, communication and risk reduction during geopolitical crises (Israel)
Arg. 1
Israel argues that CBMs serve as practical tools built during peacetime that can be directly utilised when geopolitical crises arise. They provide established procedures for de-escalation, communication and risk reduction before tensions escalate.
Israel stated that CBMs allow states to build practical procedures during times of peace that can be directly utilised for de-escalation, communication and risk reduction during a geopolitical crisis .
on: CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace
on: Whether CBMs alone are sufficient or must be complemented by binding norms
DTGs should prioritise further developing and operationalising CBMs – The DTGs must prioritise further developing and operationalising CBMs, as they hold great potential for immediate positive impact and for generating beneficial momentum for the global mechanism (Israel)
Arg. 2
Israel believes that CBMs hold great potential for immediate positive impact and for generating beneficial momentum for the global mechanism. Accordingly, the dedicated thematic groups must prioritise further developing and operationalising CBMs, including those highlighted by delegates during the session.
Israel stated that CBMs hold great potential for immediate positive impact and for generating beneficial momentum for the global mechanism, and accordingly that the DTGs must also prioritise further developing and operationalising CBMs including those highlighted by delegates during the week .
on: DTGs should focus on practical, action-oriented work to operationalise CBMs rather than reproducing procedural disagreements
Global mechanism should harmonise with other multilateral and regional forums – The global mechanism's work should prioritise harmonising with other multilateral and regional forums and ensure that all outcomes are mutually reinforcing (Israel)
Arg. 3
Israel emphasises that the global mechanism should prioritise harmonising its work with other multilateral and regional forums to ensure that all outcomes are mutually reinforcing. This includes Israel's own contributions to regional and inter-regional bodies such as the OECD, Council of Europe and Mediterranean Partnerships.
Israel noted that it continues to contribute its national experience to regional and inter-regional bodies including the OECD, Council of Europe and the framework of the Mediterranean Partnerships, and stated that the global mechanism’s work should prioritise harmonising with other multilateral and regional forums to ensure all outcomes are mutually reinforcing .
on: Avoiding duplication across multiple communication channels and mechanisms is essential for coherence and effectiveness
CBMs as cross-cutting elements of the responsible state behaviour framework – CBMs are one of the most operational components of the framework for responsible state behaviour and should constitute a cross-cutting element running through all work of the dedicated thematic groups (Argentina)
Arg. 1
Argentina views CBMs as one of the most operational components of the framework for responsible state behaviour, providing opportunities to respond to different mandates, identify common challenges and compile good practices. CBMs should constitute a cross-cutting element running through all of the work of the two dedicated thematic groups.
Argentina stated that CBMs are one of the most operational components of the framework for responsible state behaviour and that CBMs should constitute a cross-cutting element running through all of the work of the two dedicated thematic groups .
DTG1 for operationalising CBMs and DTG2 for capacity building support – DTG1 could examine operationalisation of CBMs by exchanging national and regional experiences, while DTG2 could identify capacities required to support this operationalisation effort (Argentina)
Arg. 2
Argentina proposes a division of labour between the two DTGs, with DTG1 examining the operationalisation of CBMs through exchanging national and regional experiences and developing practical guidance, while DTG2 identifies the capacities required to support this operationalisation effort. Both groups should work in a complementary manner.
Argentina proposed that DTG1 could be an appropriate framework to examine the operationalisation of CBMs by exchanging national and regional experiences, developing practical guidance, strengthening interoperability between existing mechanisms and drafting recommendations on early warnings on ICT incidents, while DTG2 could contribute to identifying capacities required to support this operationalisation effort, including proposals to strengthen national capacities of contact points and promote voluntary exercises .
on: DTGs should focus on practical, action-oriented work to operationalise CBMs rather than reproducing procedural disagreements
DTGs should lead to practical outcomes and recommendations – Argentina hopes DTGs will establish themselves as spaces for technical work able to establish substantive recommendations and decisions on CBMs for consideration by the plenary, progressively working towards more interactive, results-focused dialogue (Argentina)
Arg. 3
Argentina hopes the DTGs will establish themselves as spaces for technical work capable of producing substantive recommendations and decisions on CBMs for consideration by the plenary. This dynamic would allow plenary meetings to progressively work towards more interactive, results-focused dialogue where states can build consensus on concrete proposals.
Argentina expressed hope that the DTGs would establish themselves as spaces for technical work able to establish substantive recommendations and decisions on CBMs for consideration by the plenary, and that these recommendations would be subsequently reviewed, fine-tuned and negotiated by states in the framework of plenary deliberations, allowing the plenary to progressively work towards more interactive and results-focused dialogue .
on: The role of the dedicated thematic groups (DTGs) — whether they should produce negotiated outcomes or remain technical exchange forums
Voluntary cyber exercises to build confidence and practical skills – Argentina supports continuing voluntary exercises, gradually fine-tuning their modalities and exchanging experiences that encourage practical use of the POC directory and other CBMs (Argentina)
Arg. 4
Argentina supports continuing voluntary exercises to encourage the practical use of the POC directory and other CBMs, gradually fine-tuning their modalities and exchanging experiences. The success of the directory will depend not only on connectivity tests but on states acquiring the confidence required to use it as an effective channel for communication when circumstances require it.
Argentina underscored that the success of the POC directory will not only depend on periodically carrying out connectivity tests or ping tests, but also on states acquiring the confidence required to use it as an effective channel for communication when circumstances require it, and expressed support for continuing voluntary exercises, gradually fine-tuning their modalities and exchanging experiences that encourage practical use .
on: Simulation exercises, regular training and practical cooperation activities are essential for building confidence before crises occur
CBMs as preventive diplomacy tools – CBMs are preventive diplomacy tools, not necessarily mechanisms actionable in real time to respond to incidents; bilateral technical direct cooperation is key during actual crises (Dominican Republic)
Arg. 1
The Dominican Republic draws on regional experience to argue that CBMs are tools of preventive diplomacy rather than mechanisms actionable in real time during incidents. During an actual crisis involving ransomware against essential public services, bilateral technical direct cooperation proved to be the key response mechanism, while CBMs helped boost confidence and trust to engage and host technical assistance.
The Dominican Republic noted that from experience with other directories, a designated contact point on paper is not the same as a focal point able to respond 24 hours a day, 365 days a year, and that when ransomware struck essential public services in the region, CBMs proved to be preventive diplomacy tools rather than real-time response mechanisms, with bilateral technical direct cooperation being key .
on: Whether regional CBM models should inform or be adopted as global benchmarks
CBMs as instruments for inclusive participation – For developing countries, CBMs are not merely diplomatic instruments but practical tools that enable more inclusive participation in the international ICT security framework (Cameroon)
Arg. 1
Cameroon argues that for developing countries, CBMs go beyond diplomatic instruments and serve as practical tools that enable more inclusive participation in the international ICT security framework. They complement capacity-building efforts by creating the trust and predictability necessary for states to cooperate effectively, exchange information and respond collectively to shared challenges.
Cameroon stated that for developing countries, CBMs are not merely diplomatic instruments but practical tools that enable more inclusive participation in the international ICT security framework, and that they complement capacity-building efforts by creating the trust and predictability necessary for states to cooperate effectively, exchange information and respond collectively to shared challenges .
on: CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace
POC Directory as a dynamic instrument for cooperation – The directory should evolve from a repository of contacts into a dynamic instrument for cooperation, with functionalities progressively enhanced to facilitate secure communication and voluntary information exchange (Cameroon)
Arg. 2
Cameroon proposes that the POC directory should evolve beyond a static repository of contacts into a dynamic instrument for cooperation. Its functionalities could be progressively enhanced to facilitate secure communication, voluntary information exchange, consultations among points of contact and the sharing of good practices, ultimately contributing to building a genuine community of practice.
Cameroon proposed that the directory should continue to evolve from a repository of contacts into a dynamic instrument for cooperation, with functionalities progressively enhanced to facilitate secure communication, voluntary information exchange, consultations among points of contacts and the sharing of good practices, and that over time it should contribute to building a genuine community of practice among points of contact .
on: The Global POC Directory is an important achievement that should be actively maintained, regularly tested and used in good faith as a complement to existing channels
on: The appropriate scope and use of the POC Directory — whether it should be used proactively for information exchange or reserved for crisis communication
Avoiding duplication between global and regional mechanisms – The global mechanism should facilitate exchanges of experience among member states and regional organisations through workshops and knowledge-sharing initiatives, avoiding duplication of what already functions elsewhere (Cameroon)
Arg. 3
Cameroon recommends that the global mechanism facilitate exchanges of experience among member states and regional organisations through workshops and knowledge-sharing initiatives. Regional experiences, including those from Africa, can provide valuable lessons and contribute to strengthening global cooperation while avoiding duplication.
Cameroon proposed that the global mechanism should facilitate exchanges of experience among member states and regional organisations through workshops and knowledge-sharing initiatives, noting that regional experiences including those from Africa can provide valuable lessons and contribute to strengthening global cooperation while avoiding duplication .
on: Avoiding duplication across multiple communication channels and mechanisms is essential for coherence and effectiveness
Voluntary exchange of national experiences and good practices – The global mechanism should encourage voluntary implementation guidance, practical communication tools, and capacity-building activities adapted to national circumstances, and continued dialogue on relationships between CBMs, international law and other pillars (Cameroon)
Arg. 4
Cameroon recommends that the global mechanism encourage voluntary implementation guidance, practical communication tools and capacity-building activities adapted to national circumstances. Continued dialogue on the relationships between CBMs, international law and the other pillars of the framework can further enhance transparency and predictability among states.
Cameroon proposed that the global mechanism should encourage voluntary implementation guidance, practical communication tools and capacity-building activities adapted to national circumstances, and that continued dialogue on relationships between CBMs, international law and the other pillars of the framework can further enhance transparency and predictability among states .
CBMs as complementary to binding norms – CBMs on their own do not guarantee the strictly peaceful use of ICTs; they are complementary to binding norms and must respect sovereignty and non-interference in internal affairs (Cuba)
Arg. 1
Cuba argues that CBMs alone do not guarantee the strictly peaceful use of ICTs and are complementary to binding norms established within the UN framework. The voluntary nature of CBMs must prevail, and different phases of confidence building must respect sovereignty and the principle of non-interference in the internal affairs of states.
Cuba stated that CBMs on their own do not guarantee the strictly peaceful use of ICTs and that the different phases for confidence building must respect sovereignty and the non-interference in the internal affairs of states, and that the voluntary nature of confidence-building measures must prevail .
on: Whether CBMs alone are sufficient or must be complemented by binding norms
Regional CBMs should not be treated as single global models – Each region or sub-region has unique characteristics, and measures implemented at these levels cannot be considered single global models or benchmarks (Cuba)
Arg. 2
Cuba emphasises that each region or sub-region has unique characteristics, and therefore measures implemented at these levels cannot be considered single global models or benchmarks. Closing the digital gap and ensuring universal, inclusive and non-discriminatory access to ICTs can also contribute to building confidence.
Cuba stated that each region or sub-region has unique characteristics and that the measures implemented at these levels cannot be considered single global models or benchmarks, and that closing the digital gap and ensuring universal, inclusive and non-discriminatory access to information and knowledge through ICTs can contribute to building confidence .
on: Whether regional CBM models should inform or be adopted as global benchmarks
Substantive dialogue within the mechanism as a CBM in itself – Ensuring information exchange and dialogue on the use of ICTs and international security in the global mechanism is in itself a CBM; these dialogues must be conducted with mutual respect and constructively (Cuba)
Arg. 3
Cuba argues that ensuring information exchange and dialogue on the use of ICTs and international security within the global mechanism is itself a confidence-building measure. These dialogues must be conducted with mutual respect, constructively, and with consideration for the diversity of positions and different understandings of each of the five pillars.
Cuba stated that ensuring information exchange and dialogue on the use of ICTs and international security in the global mechanism is in itself a CBM, and that all delegations should be able to continue to develop these dialogues within this framework with mutual respect, constructively, considering the diversity of positions and different understandings of each of the five pillars .
CBMs as voluntary and action-oriented cyber diplomacy tools – CBMs are action-oriented voluntary cyber diplomacy tools at the discretion of states that can help reduce tensions and the risk of miscalculation (Germany)
Arg. 1
Germany characterises CBMs as action-oriented voluntary cyber diplomacy tools at the discretion of states that can help reduce tensions and the risk of miscalculation. Germany has been a consistent supporter of discussing and adopting CBMs that are concrete, action-oriented and voluntary in nature, building on consensus and focused on transparency, cooperation and stability between states.
Germany stated that CBMs are action-oriented voluntary cyber diplomacy tools at the discretion of states that can help reduce tensions and the risk of miscalculation, and that Germany has been a consistent supporter of discussing and adopting CBMs that are concrete, action-oriented and voluntary in nature, that build on consensus and are focused on building transparency, cooperation and stability between states .
on: Whether CBMs alone are sufficient or must be complemented by binding norms
DTGs as forums for trust-building and learning – The global mechanism, especially the DTGs, provides an opportunity to develop ways to operationalise the CBM pillar in a practical way and can act as a forum for cross-regional learning (Germany)
Arg. 2
Germany views the global mechanism, especially the DTGs, as providing an opportunity to develop ways to operationalise the CBM pillar in a practical way. The DTGs can act as a forum for cross-regional learning, and Germany echoes the value of cross-regional exchanges, partnerships and capacity building for CBM implementation as highlighted at a side event co-hosted with Ghana and the Dominican Republic.
Germany stated that the global mechanism, especially the DTGs, provides an opportunity to develop ways to operationalise the CBM pillar in a practical way and can act as a forum for cross-regional learning, and echoed Ghana’s remarks on the side event co-hosted by Ghana, the Dominican Republic and Germany on regional best practices for the implementation of CBMs, which highlighted the practical, concrete value that CBMs can add in solving real-world policy challenges .
on: DTGs should focus on practical, action-oriented work to operationalise CBMs rather than reproducing procedural disagreements
Concerns about repeated, bad-faith use of the directory – Germany reported receiving repetitive, identical messages from a certain state that did not take into account replies, which is not in line with the purpose of the UN POC Directory and does not represent responsible or sincere use (Germany)
Arg. 3
Germany raised concerns about the misuse of the POC directory, reporting that its Cyber Security Agency received repetitive, identical messages from a certain state that did not take into account Germany's replies or recommended course of action. Germany characterised this as clearly not in line with the purpose of the UN POC directory and not representing responsible or sincere use.
Germany reported that its Federal Foreign Office serves as the diplomatic POC and its Cyber Security Agency as the technical POC, and that despite initially replying in good faith and recommending an appropriate course of action, the technical POC continued receiving repeated identical requests from the same sender whilst not taking into account Germany’s replies, which Germany characterised as clearly not in line with the purpose of the UN POC directory and not representing responsible or sincere use .
on: The appropriate scope and use of the POC Directory — whether it should be used proactively for information exchange or reserved for crisis communication
POC Directory as complementary to, not replacing, existing channels – The strength and added value of the POC Directory are found in establishing lines of contact where these previously were unavailable or unclear; it should be a complementary tool, not a replacement for existing POC networks (Netherlands)
Arg. 4
Germany argues that the POC directory is designed as a voluntary practical tool at the discretion of states, and that in addition to it there are established channels such as FIRST, the network of CERTs, CERT-to-CERT cooperation and law enforcement cooperation, as well as relevant existing regional POC networks. The POC directory should not replace those channels or other diplomatic channels appropriate for addressing strategic security concerns.
Germany stated that the POC directory is designed as a voluntary practical tool at the discretion of states, and that in addition and in complementarity to it there are established channels such as FIRST, the network of CERTs, CERT-to-CERT or law enforcement cooperation, as well as relevant and existing regional POC networks, and that the POC network is not intended to and should not replace those channels or other diplomatic channels appropriate to address strategic security concerns .
on: Avoiding duplication across multiple communication channels and mechanisms is essential for coherence and effectiveness
on: The appropriate role and purpose of the Global POC Directory — whether it is a primary crisis communication tool or strictly a supplementary channel
CBMs built through dialogue and transparency – Trust is not something that can be declared by fiat; it is built by dialogue, transparency, predictability, and results-based cooperation (Côte d'Ivoire)
Arg. 1
Côte d'Ivoire emphasises that trust cannot be declared by fiat but must be built through dialogue, transparency, predictability and results-based cooperation. The global mechanism must become the appropriate forum for this trust-building process.
Côte d’Ivoire stated that trust is not something that can be declared by fiat but is built by dialogue, transparency, predictability and results-based cooperation .
on: CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace
Regular simulation exercises under UN auspices – Côte d'Ivoire recommends regularly organising under UN auspices simulation exercises that bring together points of contact, national incident response teams and relevant authorities (Côte d'Ivoire)
Arg. 2
Côte d'Ivoire recommends that the UN regularly organise simulation exercises that bring together points of contact, national incident response teams and relevant authorities. This is one of three concrete recommendations made by the delegation to strengthen CBM implementation.
Côte d’Ivoire set out three recommendations, the first of which was to regularly organise under the auspices of the UN simulation exercises that bring together points of contact, national teams for responding to incidents and relevant authorities .
on: Simulation exercises, regular training and practical cooperation activities are essential for building confidence before crises occur
Strong support for the POC Directory as a flagship achievement – Tonga strongly supports the Global Points of Contact Directory as the flagship practical achievement of the OEWG and commends UNODA for its continued operationalisation (Tonga)
Arg. 1
Tonga strongly supports the Global Points of Contact Directory as the flagship practical achievement of the OEWG and commends UNODA for its continued operationalisation. Small states like Tonga particularly need trusted, predictable lines of communication between states when an incident strikes, as they do not maintain wide networks of diplomats tasked with cyber-related cooperation.
Tonga stated that small states do not maintain wide networks of diplomats tasked with cyber-related cooperation, and that when an incident strikes, trusted, predictable lines of communication between states are needed, and therefore strongly supports the Global Points of Contact Directory as the flagship practical achievement of the OEWG, commending UNODA for its continued operationalisation .
on: The Global POC Directory is an important achievement that should be actively maintained, regularly tested and used in good faith as a complement to existing channels
Pacific regional cooperation as a model for cyber incident response – CERT Tonga was established in 2016 and has worked within the Pacific Cyber Security Operational Network; when Tonga's health system was attacked, established relationships enabled rapid assistance and joint public attribution with Australia and New Zealand (Tonga)
Arg. 2
Tonga presents its own experience as a concrete example of CBMs working in practice. CERT Tonga was established in 2016 and has worked within the Pacific Cyber Security Operational Network, building personal trust among incident responders. When Tonga's health system was attacked, established relationships enabled rapid assistance and ultimately a joint public attribution with Australia and New Zealand.
Tonga noted that CERT Tonga was established by cabinet decision in 2016 among the first national CERTs in the Pacific and has worked within the Pacific Cyber Security Operational Network where regions’ incident responders share information and build personal trust, and that when its health system was attacked last year, established relationships with partners enabled rapid assistance and ultimately a joint public attribution with Australia and New Zealand .
on: Regional organisations play an important role in advancing CBMs and their experiences should inform global implementation
Tonga's CERT as an example of CBMs working in practice – Tonga's experience with its health system attack demonstrated what CBMs look like when they work: relationships built before the crisis, exercised during it, and deepened after it (Tonga)
Arg. 3
Tonga uses its own experience with a health system attack to illustrate what effective CBMs look like in practice. The key lesson is that relationships must be built before a crisis, exercised during it and deepened after it, rather than being established in the midst of an emergency.
Tonga described its experience when its health system was attacked, noting that established relationships with partners enabled rapid assistance and ultimately a joint public attribution with Australia and New Zealand, and characterised this as what CBMs look like when they work: relationships built before the crisis, exercised during it and deepened after it .
on: Simulation exercises, regular training and practical cooperation activities are essential for building confidence before crises occur
Small states face unique challenges in CBM implementation – Small states do not maintain wide networks of diplomats tasked with cyber-related cooperation; when an incident strikes, trusted, predictable lines of communication between states are needed (Tonga)
Arg. 4
Tonga highlights the unique challenges faced by small states in CBM implementation, noting that they do not maintain wide networks of diplomats tasked with cyber-related cooperation. This makes trusted, predictable lines of communication between states particularly critical when an incident strikes.
Tonga stated that small states do not maintain wide networks of diplomats tasked with cyber-related cooperation, and that when an incident strikes, trusted, predictable lines of communication between states are needed .
DTGs should focus on practical, technical work rather than procedural disagreements – DTGs should be used to identify needs, share practical experience, connect states with relevant expertise, and help match national and regional priorities with appropriate support, not become additional negotiating rooms (Tonga on behalf of Pacific Islands Forum)
Arg. 1
The Pacific Islands Forum, speaking through Tonga, argues that DTGs should be used to identify needs, share practical experience, connect states with relevant expertise and help match national and regional priorities with appropriate support. They should not become additional negotiating rooms that reproduce the same procedural disagreements or simply repeat plenary discussions.
Tonga on behalf of the Pacific Islands Forum stated that the DTGs should be used to identify needs, share practical experience, connect states with relevant expertise and help match national and regional priorities with appropriate support, and that they should not become additional negotiating rooms that reproduce the same procedural disagreements, nor simply repeat plenary discussions, with their value to be measured by whether they help countries make progress .
on: DTGs should focus on practical, action-oriented work to operationalise CBMs rather than reproducing procedural disagreements
on: The role of the dedicated thematic groups (DTGs) — whether they should produce negotiated outcomes or remain technical exchange forums
Capacity building as foundational to all aspects of the mechanism's work – Capacity building is the enabler that underpins all aspects of the work; it is foundational to responding to threats, implementing norms, engaging meaningfully in international law discussions, and sustaining CBMs (Tonga on behalf of Pacific Islands Forum)
Arg. 2
The Pacific Islands Forum argues that capacity building is the enabler that underpins all aspects of the mechanism's work, including responding to threats, implementing norms, engaging meaningfully in discussions of international law and sustaining CBMs. It should not be siloed but should remain a cross-cutting thread through all of the mechanism's work.
Tonga on behalf of the Pacific Islands Forum stated that capacity building is the enabler that underpins all aspects of the work, that it is foundational to responding to threats, implementing norms, engaging meaningfully in the discussion of international law and sustaining confidence-building measures, and that it should not be siloed but should remain a cross-cutting thread through all of the mechanism’s work .
on: Capacity building is a cross-cutting priority and essential enabler for effective CBM implementation
Stakeholder engagement essential for capacity building – Meaningful capacity building depends on access to the expertise of the multi-stakeholder community, academia, civil society, the private sector and the technical community; stakeholders must be substantively included in both formal and informal settings (Tonga on behalf of Pacific Islands Forum)
Arg. 3
The Pacific Islands Forum emphasises that meaningful capacity building depends on access to the expertise of the multi-stakeholder community, including academia, civil society, the private sector and the technical community. The Forum strongly supports the substantive inclusion of stakeholders in both formal and informal settings and supports the fullest possible use of expert briefings within the dedicated thematic groups.
Tonga on behalf of the Pacific Islands Forum stated that member states consistently find the technical expertise of the multi-stakeholder community, academia, civil society, the private sector and the technical community to be of real and practical value, and that meaningful capacity building depends on access to that expertise, strongly supporting the substantive inclusion in both formal and informal settings and the fullest possible use of expert briefings within the dedicated thematic groups .
on: Stakeholder engagement from the private sector, civil society, academia and the technical community is important for effective CBM implementation
Pacific states should not be consistently disadvantaged by meeting times – Meeting times should be rotated so Pacific delegations are not consistently asked to participate in the middle of the night; an inclusive global mechanism must be inclusive not only in principle but in the practical design of its work (Tonga on behalf of Pacific Islands Forum)
Arg. 4
The Pacific Islands Forum raises the practical concern that Pacific delegations are consistently asked to participate in meetings in the middle of the night due to time zone differences. The Forum calls for meeting times to be rotated and for hybrid modalities to be welcomed, arguing that an inclusive global mechanism must be inclusive not only in principle but in the practical design of its work.
Tonga on behalf of the Pacific Islands Forum welcomed hybrid modalities for the DTGs but asked for meeting times to be rotated so Pacific delegations are not consistently asked to participate in the middle of the night, stating that an inclusive global mechanism must be inclusive not only in principle but in the practical design of its work .
POC Directory as a complement, not replacement, to existing channels – The POC Directory should be used as a complement to existing channels of communication between states, not as a replacement or duplication of established diplomatic or technical channels (Ireland)
Arg. 1
Ireland argues that the POC Directory should be used in good faith and as a complement to existing channels of communication between states. Ireland is open to exploring further development of the directory as more is learned from its use.
Ireland stated that the POC Directory should be used in good faith and as a complement to existing channels of communication between states, and that Ireland is open to exploring further development of the POC Directory as more is learned from its use .
on: The POC Directory should complement, not replace, existing diplomatic and technical communication channels
on: The appropriate role and purpose of the Global POC Directory — whether it is a primary crisis communication tool or strictly a supplementary channel
Sharing national ICT-related information and protecting critical infrastructure – States must move forward on implementation of CBMs including by sharing national ICT-related information, exchanging experience on protecting critical infrastructure, and promoting information exchange and cooperation between states (Ireland)
Arg. 2
Ireland argues that in addition to the POC Directory, states must move forward on implementation of other CBMs. This includes sharing national ICT-related information, exchanging experience on protecting critical infrastructure, promoting information exchange and cooperation, and organising regular seminars, workshops and training programmes on ICT security.
Ireland stated that in addition to the POC Directory, states must move forward on implementation of other CBMs including by sharing national ICT-related information, exchanging experience on protecting critical infrastructure, promoting information exchange and cooperation and partnerships between states to strengthen ICT security capacity, and by organising regular seminars, workshops and training programmes on ICT security .
Expertise of stakeholders should play a strong role – The expertise and experience of stakeholders from academia, the technical community, civil society and the private sector should play a strong role in the CBM implementation process, with practical tools and best practices feeding engagement (Ireland)
Arg. 3
Ireland argues that the expertise and experience of stakeholders from academia, the technical community, civil society and the private sector should play a strong role in the CBM implementation process. Practical tools, best practices and examples should feed engagement and allow CBMs to be reflected into national and regional structures.
Ireland stated that the expertise and experience of stakeholders from academia, the technical community, civil society and the private sector should also play a strong role in the CBM implementation process, and that practical tools, best practices and examples should feed engagement and allow CBMs to be reflected into national and regional structures .
on: Stakeholder engagement from the private sector, civil society, academia and the technical community is important for effective CBM implementation
Need for simulation exercises within DTGs – In simulation exercises within DTGs, states could see how public-private partnerships could concretely benefit an open, free and secure cyberspace and help prevent and address incidents (Netherlands)
Arg. 1
The Netherlands proposes that simulation exercises within DTGs could demonstrate how public-private partnerships can concretely benefit an open, free and secure cyberspace and help prevent and address incidents. In this manner, DTGs will offer the opportunity to discuss CBM operationalisation.
The Netherlands stated that in simulation exercises within DTGs, states could see how public-private partnerships could concretely benefit an open, free and secure cyberspace and help prevent and address incidents taking place in cyberspace, and that in this manner DTGs will offer the opportunity to discuss CBM operationalisation .
POC Directory as complementary to, not replacing, existing channels – The strength and added value of the POC Directory are found in establishing lines of contact where these previously were unavailable or unclear; it should be a complementary tool, not a replacement for existing POC networks (Netherlands)
Arg. 2
The Netherlands argues that the strength and added value of the POC Directory lie in establishing lines of contact where these previously were unavailable or unclear. It should be viewed as a complementary tool to existing POC networks and channels of communication that already function appropriately, not as a replacement or duplication.
The Netherlands stated that the strength and added value of the POC Directory are found in establishing lines of contact where these previously were unavailable or unclear, and that it should be looked at as a complementary tool to existing POC networks and channels of communication that already function appropriately, not as a replacement or a duplication .
on: Avoiding duplication across multiple communication channels and mechanisms is essential for coherence and effectiveness
on: The appropriate role and purpose of the Global POC Directory — whether it is a primary crisis communication tool or strictly a supplementary channel
Developing national positions on international law in cyberspace – The Netherlands encourages all member states and regional organisations to continue to develop national positions on how international law applies in cyberspace and make these views available to a wider public, to avoid miscommunication and miscalculation (Netherlands)
Arg. 3
The Netherlands encourages all member states and regional organisations to continue developing national positions on how international law applies in cyberspace and to make these views available to a wider public. By openly and clearly communicating on how international law is interpreted in cyberspace, states can avoid miscommunication and miscalculation, leading to a more solid basis for establishing trust over time.
The Netherlands encouraged all member states and regional organisations to continue to develop national positions on how international law applies in cyberspace and to make these views available to a wider public, stating that by openly and clearly communicating on how international law is interpreted in cyberspace, states avoid miscommunication and miscalculation, leading to a more solid basis to establish trust over time, and that the Netherlands stands ready to share its best practices with all member states in the process of developing their position .
on: Whether CBMs alone are sufficient or must be complemented by binding norms
Need for coherence across multiple communication channels – The international community is multiplying its channels of communication; Vanuatu requests that the directory be developed in deliberate awareness of the wider ecosystem, with clear guidance on which channels serve which purpose (Vanuatu)
Arg. 1
Vanuatu raises the concern that the international community is multiplying its channels of communication, creating a burden for small administrations that must operate all of these channels at once, often through the same handful of officials. Vanuatu requests that the directory be developed in deliberate awareness of the wider ecosystem, with clear guidance on which channels serve which purpose and no duplication of what already functions elsewhere.
Vanuatu noted that the international community is multiplying its channels of communication, including the Global Points of Contact Directory, the 24/7 network under the UN Convention against Cybercrime, bilateral relationships and regional arrangements, and that Vanuatu speaks from the standpoint of administrations that must operate all of these channels at once, often through the same handful of officials, requesting that the directory be developed in deliberate awareness of the wider ecosystem with clear guidance on which channels serve which purpose and no duplication of what already functions elsewhere .
on: Avoiding duplication across multiple communication channels and mechanisms is essential for coherence and effectiveness
on: The appropriate role and purpose of the Global POC Directory — whether it is a primary crisis communication tool or strictly a supplementary channel
Transparency as a measure available to every state regardless of size – Vanuatu emphasises transparency as a measure available to every state regardless of size, encouraging the structured exchange of national information within the mechanism as routine practice that prevents misreading between states (Vanuatu)
Arg. 2
Vanuatu emphasises transparency as a confidence-building measure available to every state regardless of size. Vanuatu has sought to be open about its national arrangements, legislative development and assessments of the threat environment, and encourages the structured exchange of such national information within the mechanism as routine practice that prevents misreading between states.
Vanuatu emphasised transparency as a measure available to every state regardless of size, noting that Vanuatu has sought to be open about its national arrangements, legislative development including its data protection and privacy bill, and assessments of the threat environment, and encouraged the structured exchange of such national information within the mechanism not as a reporting burden but as routine practice that prevents misreading between states .
Importance of training and continuity for designated officials – Vanuatu supports regular communications exercises for the directory, sustained training for designated officials with attention to continuity as personnel change, and preservation of hybrid modalities so that distance never determines who participates (Vanuatu)
Arg. 3
Vanuatu supports regular communications exercises for the directory and sustained training for designated officials, with particular attention to continuity as personnel change. The preservation of hybrid modalities is also important so that distance never determines who participates in building confidence.
Vanuatu stated that measures on paper acquire meaning through practice, and supported regular communications exercises for the directory, sustained training for designated officials with attention to continuity as personnel change, and the preservation of hybrid modalities so that distance never determines who participates in building confidence .
Hybrid modalities essential for inclusive participation – Vanuatu supports the preservation of hybrid modalities so that distance never determines who participates in building confidence; accessibility is also a capacity-building issue (Vanuatu)
Arg. 4
Vanuatu argues that hybrid modalities must be preserved so that distance never determines who participates in building confidence. This is particularly important for small island states whose officials may be unable to travel to participate in person.
Vanuatu supported the preservation of hybrid modalities so that distance never determines who participates in building confidence .
DTGs as platforms for exchanging national experiences and good practices – The dedicated thematic groups offer a valuable opportunity to go into further depth on international relations and the role of international organisations in effective implementation of CBMs, exchanging national experiences and good practices (Chile)
Arg. 1
Chile views the dedicated thematic groups as valuable opportunities to go into further depth on discussions about international relations and the role of international organisations in the effective implementation of CBMs. These groups could be great spaces for exchanging national experiences, good practices and engaging in measures to strengthen cooperation in specific areas such as coordinated responses to cyber incidents.
Chile stated that the dedicated thematic groups offer a valuable opportunity to go into further depth into discussions on the issue of international relations and the role of international organisations in the effective implementation of CBMs, and that these groups could be great spaces for exchanging national experiences and good practices and engaging in measures to work towards cooperation to strengthen these measures in specific areas such as coordinated responses to cyber incidents .
on: DTGs should focus on practical, action-oriented work to operationalise CBMs rather than reproducing procedural disagreements
Cross-regional exchanges to avoid duplication and share lessons learned – The exchange of good practices between regional mechanisms could make meaningful contributions to strengthening CBM implementation globally, avoiding duplications and making the most of lessons learned in different contexts (Chile)
Arg. 2
Chile believes that the exchange of good practices between regional mechanisms could make meaningful contributions to strengthening CBM implementation globally. This approach would avoid duplications and make the most of lessons learned in different contexts.
Chile stated that the exchange of good practices between regional mechanisms could make meaningful contributions to strengthening the implementation of CBMs globally, avoiding duplications and making the most of lessons learned in different contexts .
on: Regional organisations play an important role in advancing CBMs and their experiences should inform global implementation
CBMs must address protection of critical infrastructure – The global mechanism must continue to engage in substantive discussions focused on identifying new opportunities to strengthen CBM implementation, including those geared towards protecting critical infrastructure and essential services (Chile)
Arg. 3
Chile argues that the global mechanism must continue to engage in substantive discussions focused on identifying new opportunities to strengthen CBM implementation, including those geared towards protecting critical infrastructure and essential services. This is particularly important given the growing impact of cyber incidents on societies.
Chile stated that the global mechanism must continue to engage in substantive discussions focused on identifying new opportunities to strengthen the implementation of CBMs, including those geared towards protecting critical infrastructure and essential services, given the growing impact of cyber incidents on societies .
DTG2 as the main platform for capacity building dialogue – The DTG on capacity building must be established as the main platform for dialogue on this issue within the global mechanism, playing a fundamental role as a space for strategic coordination to facilitate information exchange and articulate synergies (Chile Representative on behalf of Latin American group)
Arg. 1
The Latin American group argues that the DTG on capacity building must be established as the main platform for dialogue on this issue within the global mechanism. It should play a fundamental role as a space for strategic coordination to facilitate the exchange of information and experience, articulate synergies between existing mechanisms and identify opportunities for cooperation that respond to the needs expressed by states.
The Latin American group stated that the DTG on capacity building must be established as the main platform for dialogue on this issue within the framework of the global mechanism, playing a fundamental role as a space for strategic coordination to facilitate the exchange of information and experience, to articulate synergies between existing mechanisms and to identify opportunities for cooperation that can respond to the needs expressed by states .
on: Capacity building is a cross-cutting priority and essential enabler for effective CBM implementation
CBMs as valuable outcomes of the OEWG process – CBMs are among the most valuable outcomes of the OEWG process, demonstrating that even in a complex and rapidly evolving cyber environment, states can agree on practical measures to strengthen trust and improve communication (North Macedonia)
Arg. 1
North Macedonia views CBMs as among the most valuable outcomes of the OEWG process, demonstrating that states can agree on practical measures even in a complex and rapidly evolving cyber environment. These measures help reduce misunderstanding, strengthen cooperation and lower the risk of unintended escalation, particularly during significant ICT incidents when timely communication between states is essential.
North Macedonia stated that CBMs are among the most valuable outcomes of the OEWG process, demonstrating that even in a complex and rapidly evolving cyber environment, states can agree on practical measures and strengthen trust, improve communication and contribute to international peace and security, and that from its country, CBMs are practical tools that help reduce misunderstanding, strengthen cooperation and lower the risk of unintended escalation practically during significant ICT incidents when timely communication between states is essential .
on: CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace
CBMs should be reflected in DTG work through sharing of national experiences – CBMs should be reflected in the work of the thematic groups through sharing of national experience, practical implementation approaches and good practices, while avoiding duplication of plenary discussions (North Macedonia)
Arg. 2
North Macedonia looks forward to seeing CBMs reflected in the work of the thematic groups through the sharing of national experience, practical implementation approaches and good practices. This should be done while avoiding duplication of discussions taking place in the plenary session.
North Macedonia stated that it looks forward to seeing CBMs reflected in the work of the thematic groups through the sharing of national experience, practical implementation approaches and good practices, while avoiding duplication of discussions taking place in the plenary session, and that such exchanges can help translate common commitment into effective action .
on: DTGs should focus on practical, action-oriented work to operationalise CBMs rather than reproducing procedural disagreements
Western Balkans Cyber Diplomacy Network as a regional initiative – The launch of the Western Balkans Cyber Diplomacy Network in 2025, supported by the German Federal Foreign Office, represents the region's shared commitment to addressing cross-border cyber challenges through dialogue and cooperation (Bosnia and Herzegovina)
Arg. 1
Bosnia and Herzegovina highlights the launch of the Western Balkans Cyber Diplomacy Network in 2025 as a key milestone in regional cyber cooperation. Supported by the German Federal Foreign Office, the network represents the region's shared commitment to addressing cross-border cyber challenges through dialogue and cooperation.
Bosnia and Herzegovina noted that a key milestone was the launch of the Western Balkans Cyber Diplomacy Network in 2025, an initiative supported by the German Federal Foreign Office, and that the network represents yet another example of the region’s shared commitment to addressing cross-border cyber challenges through dialogue and cooperation .
on: Regional organisations play an important role in advancing CBMs and their experiences should inform global implementation
OSCE as the first regional organisation to develop cyber CBMs – The OSCE was the first regional organisation to develop cyber confidence-building measures and has many years of experience in practical implementation of its 16 CBMs, including through the Adopt-a-CBM initiative (OSCE)
Arg. 1
The OSCE was the first regional organisation to develop cyber confidence-building measures and has many years of experience in their practical implementation. The OSCE's 16 CBMs are implemented through various mechanisms including regular updates from participating states, the Adopt-a-CBM initiative where states champion specific CBMs, and capacity building activities including scenario-based exercises.
The OSCE stated that it was the first regional organisation to develop cyber confidence-building measures and has many years of experience in the practical implementation of its 16 CBMs, and that to date 26 OSCE participating states have adopted nine CBMs through the Adopt-a-CBM initiative, significantly contributing to the meaningful implementation of those CBMs .
on: Regional organisations play an important role in advancing CBMs and their experiences should inform global implementation
on: Whether regional CBM models should inform or be adopted as global benchmarks
OSCE capacity building through scenario-based exercises – The OSCE delivers capacity building activities including trainings and workshops with scenario-based exercises that help participants understand the practical application of CBMs, which is usually well received (OSCE)
Arg. 2
The OSCE delivers capacity building activities including trainings and workshops with scenario-based exercises that help participants understand the practical application of CBMs. These events are usually well received by participants and represent a concrete form of CBM implementation.
The OSCE stated that a third form of implementation is capacity building activities, namely trainings and workshops delivered by the Secretariat, and that these events usually involve a scenario-based exercise which helps understanding the practical application of the CBMs and is usually well received by the participants .
on: Simulation exercises, regular training and practical cooperation activities are essential for building confidence before crises occur
CBMs provide practical tools for implementing agreed commitments – CBMs provide practical tools for implementing agreed commitments; mechanisms such as points of contact, dialogue, sharing of best practices and information sharing help reduce risk, prevent misunderstandings and contribute to stability and security in cyberspace (Norway)
Arg. 1
Norway argues that CBMs provide practical tools for implementing agreed commitments, with mechanisms such as points of contact, dialogue, sharing of best practices and information sharing helping to reduce risk, prevent misunderstandings and contribute to stability and security in cyberspace. Norway's priority is to elaborate and strengthen implementation of the CBMs already agreed upon.
Norway shared three points, the first being that CBMs provide practical tools for implementing agreed commitments, with mechanisms such as points of contact, dialogue, sharing of best practices and information sharing helping to reduce risk, prevent misunderstandings and contribute to stability and security in cyberspace .
on: CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace
OAS regional experience as a model for CBM implementation – Regional experience in the OAS shows the practical value of CBMs; Uruguay has designated and updated its technical contact points in the OAS framework since 2018 and participates in cooperation mechanisms such as CERT Americas (Uruguay)
Arg. 1
Uruguay highlights the practical value of CBMs through its regional experience in the Organisation of American States. Since 2018, Uruguay has designated and updated its technical contact points in the OAS framework and participates actively in cooperation mechanisms such as CERT Americas, promoting the exchange of technical information and strengthening of state capacities.
Uruguay stated that regional experience in the OAS shows the practical value of CBMs, and that since 2018, Uruguay has designated and updated its technical contact points in the framework of the OAS and is participating actively in cooperation mechanisms such as CERT Americas, where it is promoting the exchange of technical information including indicators, good practices and strengthening of capacities of states in the region .
on: Regional organisations play an important role in advancing CBMs and their experiences should inform global implementation
Public-private partnerships essential for critical infrastructure protection – Given that a significant part of critical information infrastructure is operated by non-governmental actors or is part of the supply chain, public-private partnerships are essential to strengthen prevention, early alerts and fighting malicious information (Uruguay)
Arg. 2
Uruguay argues that public-private partnerships are essential to strengthen prevention, early alerts and fighting malicious information, given that a significant part of critical information infrastructure is operated by non-governmental actors or is part of the supply chain. The OAS experience emphasises the importance of combining transparency, communication between contact points, technical cooperation and dialogue with the private sector, academia and civil society.
Uruguay stated that the experience of the OAS emphasises the importance of combining transparency, communication between contact points, technical cooperation and dialogue with the private sector, academia and civil society and the technical community, and that given that a significant part of critical information infrastructure is operated by non-governmental actors or is part of the supply chain, public-private partnerships are essential to strengthen prevention, early alerts, early warnings and fighting malicious information .
on: Stakeholder engagement from the private sector, civil society, academia and the technical community is important for effective CBM implementation
ECOWAS regional framework as a practical example – ECOWAS has developed a regional framework on cyber ICT confidence-building measures with Ghana's participation, establishing practical mechanisms including national diplomatic and technical points of contact (Ghana)
Arg. 1
Ghana highlights the ECOWAS regional framework on cyber ICT confidence-building measures as a practical example of regional CBM implementation. The ECOWAS directive establishes practical mechanisms including national diplomatic and technical points of contact and information-sharing arrangements that strengthen cooperation and contribute to regional resilience.
Ghana stated that drawing on international good practices and adapting them to regional realities, ECOWAS has developed a regional framework on cyber ICT confidence-building measures with the participation of Ghana, and that the ECOWAS directive establishes practical mechanisms including national diplomatic and technical points of contact and information-sharing arrangements that strengthen cooperation and contribute to regional resilience .
on: Regional organisations play an important role in advancing CBMs and their experiences should inform global implementation
on: Whether regional CBM models should inform or be adopted as global benchmarks
CBMs as practical tools reducing misunderstanding – CBMs are practical tools for reducing the risk of misinterpretation, escalation and conflict in cyberspace, helping states build relationships and establish communication channels before a crisis occurs so that these channels can be used effectively during and after cyber incidents (Australia)
Arg. 1
Malawi affirms that CBMs remain among the most practical and effective means of strengthening international peace and security in the use of ICTs. By promoting transparency, predictability and cooperation, they reduce misunderstandings and misperceptions while fostering the trust necessary for timely communication and coordinated responses to cyber incidents.
Malawi stated that confidence-building measures remain among the most practical and effective means of strengthening international peace and security in the use of ICTs, and that by promoting transparency, predictability and cooperation, they reduce misunderstandings and misperceptions while fostering the trust necessary for timely communication and coordinated responses to cyber incidents .
on: CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace
POC Directory requires capacity building to be effective – Many states face institutional, technical and resource constraints affecting their ability to operationalise national points of contact; capacity building is indispensable for effective implementation (Philippines)
Arg. 1
The Philippines emphasises that capacity building is indispensable for the effective implementation of CBMs, as many member states continue to face institutional, technical and resource constraints. These constraints affect their ability to operationalise national points of contact, participate in cyber exercises, exchange technical information and respond effectively to ICT-related incidents.
The Philippines emphasised that capacity building is indispensable for the effective implementation of CBMs, and that many member states continue to face institutional, technical and resource constraints that affect their ability to operationalise national points of contact, participate in cyber exercises, exchange technical information and respond effectively to ICT-related incidents .
on: Capacity building is a cross-cutting priority and essential enabler for effective CBM implementation
ASEAN Regional CERT as a step toward regional cybersecurity posture – As ASEAN Chair in 2026, the Philippines welcomed progress in operationalising the ASEAN Regional CERT, an important step toward raising the regional cybersecurity posture through timely information sharing and coordinated incident response (Philippines)
Arg. 2
The Philippines highlights the progress in operationalising the ASEAN Regional CERT as an important step toward raising the regional cybersecurity posture. Together with the implementation of the ASEAN Cybersecurity Cooperation Strategy 2026–2030, this initiative reinforces trusted relationships among competent authorities, improves regional preparedness and complements the work of the global mechanism.
The Philippines stated that as ASEAN Chair in 2026, it welcomed the progress in operationalising the ASEAN Regional CERT, an important step toward raising the regional cybersecurity posture through timely information sharing, coordinated incident response and exchange of best practices, and that together with the implementation of the ASEAN Cybersecurity Cooperation Strategy 2026-2030, this initiative reinforced trusted relationships among competent authorities and improved regional preparedness .
on: Regional organisations play an important role in advancing CBMs and their experiences should inform global implementation
CARICOM priorities for capacity building – CARICOM highlights three regional priorities: cyber law and modern legal frameworks, sustained cyber capacity building for resilience and technical expertise, and critical infrastructure protection for small states with limited resources (Bahamas on behalf of the CARICOM)
Arg. 1
CARICOM highlights three regional priorities for capacity building: cyber law and modern legal and regulatory frameworks, sustained cyber capacity building that develops resilience, technical expertise and a skilled workforce, and critical infrastructure protection for small states. The challenge for small states begins with the very ability to define, identify and classify critical infrastructure and extends to protecting it with limited resources.
CARICOM highlighted three regional priorities: first, cyber law and modern legal and regulatory frameworks that enable states to address cybercrime, protect data and cooperate across borders; second, sustained cyber capacity building that develops resilience, technical expertise and a skilled workforce; and third, critical infrastructure protection for small states, noting that the challenge begins with the very ability to define, identify and classify critical infrastructure and extends to protecting it with limited resources .
on: Capacity building must be demand-driven, nationally owned, sustainable and tailored to specific national needs
CARICOM faces persistent gaps despite progress – The 2025 OAS IDB Cybersecurity Report confirms both progress and challenges for CARICOM; persistent gaps in resources, workforce development and cross-sector coordination continue to expose the region to an increasingly complex threat environment (Bahamas on behalf of the CARICOM)
Arg. 2
CARICOM acknowledges both progress and persistent challenges in its cybersecurity capacity. The 2025 OAS IDB Cybersecurity Report, based on the Oxford Cybersecurity Capacity Maturity Model, confirms that while the region has improved across all five dimensions since 2020, persistent gaps in resources, workforce development and cross-sector coordination continue to expose it to an increasingly complex threat environment.
CARICOM noted that the 2025 OAS IDB Cybersecurity Report, based on the Oxford Cybersecurity Capacity Maturity Model, confirms both progress and challenges, and that the region has improved across all five dimensions of the model since 2020, yet persistent gaps in resources, workforce development and cross-sector coordination continue to expose it to an increasingly complex threat environment .
Facilitating access to ICT security products and tools as a new CBM – Iran considers the proposal for a new CBM aimed at facilitating access by all states to ICT security products and tools to be particularly valuable, as it strengthens national capacities while simultaneously promoting cooperation, trust and confidence (Islamic Republic of Iran)
Arg. 1
Iran considers the proposal for a new CBM aimed at facilitating access by all states to ICT security products and tools to be particularly valuable. This measure strengthens national capacities while simultaneously promoting cooperation, trust and confidence among states, reflecting the OEWG's recognition that capacity-building programmes are an important confidence-building measure.
Iran noted that paragraph 47k of the OEWG Final Report reaffirms the importance of continuing discussions on the development and implementation of CBMs, and that states took note of a proposal for a new CBM aimed at facilitating access by all states to ICT security products and tools, which Iran considers particularly valuable as it strengthens national capacities while simultaneously promoting cooperation, trust and confidence among states .
Subsea cable infrastructure as a critical asset requiring international guidance – Tuvalu urges the mechanism to establish clear international guidance for the protection of subsea infrastructure, seeking an explicit CBM commitment from all member states to share best practices to safeguard this essential digital lifeline (Tuvalu)
Arg. 1
Tuvalu urges the mechanism to establish clear international guidance for the protection of subsea infrastructure, which it describes as a vital digital artery. Tuvalu seeks an explicit CBM commitment from all member states and stakeholders to share best practices to safeguard this essential digital lifeline from both natural hazards and malicious cyber threats.
Tuvalu noted that its developer subsea cable is a vital digital artery and urged the mechanism to establish clear international guidance for the protection of subsea infrastructure, seeking an explicit CBM commitment from all member states and stakeholders to share best practices to safeguard this essential digital lifeline from both natural hazards and malicious cyber threats .
Capacity building for small island developing states requires long-term investment – International cooperation must shift away from short-term external consulting and towards tangible long-term training of local technical teams; true confidence is established where every state possesses the sovereign ability to manage its own digital systems independently (Tuvalu)
Arg. 2
Tuvalu argues that international cooperation must shift away from short-term external consulting and towards tangible long-term training of local technical teams. True confidence is established where every state, regardless of its size, possesses the sovereign ability to manage its own digital systems independently.
Tuvalu stated that international cooperation must shift away from short-term external consulting and towards tangible long-term training of local technical teams, and that true confidence is established where every state, regardless of its size, possesses the sovereign ability to manage its own digital systems independently .
Botswana's CERT and national cybersecurity strategy for critical infrastructure – Botswana has operationalised its national cybersecurity strategy and established the Botswana Computer Incident Response Team to coordinate incident management, issue threat advisories and safeguard national critical infrastructure (Botswana)
Arg. 1
Botswana has taken steps to implement voluntary CBMs nationally, including operationalising its national cybersecurity strategy and establishing the Botswana Computer Incident Response Team under the Botswana Communications Regulatory Authority. This team coordinates incident management, issues threat advisories and safeguards national critical infrastructure.
Botswana stated that it has operationalised its national cybersecurity strategy and established the Botswana Computer Incident Response Team under the Botswana Communications Regulatory Authority to coordinate incident management, issue threat advisories and safeguard national critical infrastructure, and has undertaken the development of a new system of designation and submission of national POCs across both diplomatic and technical levels to populate the POC directory .
Capacity building must address the digital divide – Global transparency initiatives must be paired with concrete technical assistance to address the digital divide; states should leverage regional and sub-regional platforms to strengthen operational mechanisms (Botswana)
Arg. 2
Botswana argues that global transparency initiatives must be paired with concrete technical assistance to address the digital divide. States should leverage regional and sub-regional platforms to strengthen operational mechanisms, including direct state-to-state cooperation and critical infrastructure protection, as the most effective pathway towards building global trust and incident response readiness.
Botswana stated that global transparency initiatives must be paired with concrete technical assistance to address the digital divide, and that states should be leveraging the regional and sub-regional platforms to strengthen operational mechanisms, including direct state-to-state cooperation and critical infrastructure protection, as this would provide the most effective pathway towards building global trust and incident response readiness .
Botswana's national cybersecurity activities as CBM implementation – Botswana's recent internal cybersecurity activities reflect CBM implementation through formal public-private partnerships, threat intelligence sharing and academic collaboration, focusing on response readiness and workforce upskilling (Botswana)
Arg. 3
Botswana describes its recent internal cybersecurity activities as reflecting CBM implementation through formal public-private partnerships, threat intelligence sharing and academic collaboration. These initiatives focus on response readiness and workforce upskilling to collaboratively ensure the security of Botswana's critical infrastructure.
Botswana stated that recent internal cybersecurity activities reflect the implementation of CBMs through formal public-private partnerships, threat intelligence sharing and academic collaboration, focusing on response readiness and workforce upskilling to collaboratively ensure the security of Botswana’s critical infrastructure, and that the Botswana Communications Regulatory Authority has signed several memoranda of understanding with global cybersecurity firms delivering real-time intelligence on emerging threats and sharing best practices in cyber defence capabilities .
on: Simulation exercises, regular training and practical cooperation activities are essential for building confidence before crises occur
Challenges with dead contacts and misuse of the directory – The directory faces challenges including dead contacts, misinterpretation of objectives of technical POCs, and cases where capitals ignore requests for political reasons; around 48% of Russia's inquiries were responded to (Russian Federation)
Arg. 1
The Russian Federation reports that the POC directory faces a number of challenges in its initial stages. These include dead contacts, misinterpretation of the objectives of technical POCs when designated authorised bodies to the directory, and cases where certain capitals simply ignore requests for political reasons. Russia reports that around 48% of its 2,576 inquiries in the past year were responded to.
The Russian Federation provided statistics showing that there were 2,576 inquiries from Russian POCs in the past year, of which around 48% were responded to, attributing this to dead contacts, misinterpretation of the objectives of technical POCs, and cases where certain capitals simply ignore requests for political reasons, particularly those countries that make unsubstantiated accusations regarding the supposed involvement of other states in computer attacks .
on: The appropriate role and purpose of the Global POC Directory — whether it is a primary crisis communication tool or strictly a supplementary channel
Need for universal participation in the directory – 125 states have joined the directory, which is positive, but all remaining member states should join by designating appropriate diplomatic and technical points of contact (Russian Federation)
Arg. 2
The Russian Federation notes that 125 states have joined the POC directory, which it considers a positive indicator, but urges all remaining member states to join by designating appropriate diplomatic and technical points of contact. Russia credits the establishment of the directory to its own initiative and views it as the main practical outcome of the OEWG.
The Russian Federation stated that 125 states have joined the directory, which is a positive indicator, but urged all remaining member states to join the directory by designating appropriate diplomatic and technical points of contact .
on: The Global POC Directory is an important achievement that should be actively maintained, regularly tested and used in good faith as a complement to existing channels
on: The role of the dedicated thematic groups (DTGs) — whether they should produce negotiated outcomes or remain technical exchange forums
Need for standardised communication templates – A priority task is to finalise a standardised communication template to simplify cooperation between POCs by clearly defining the information needed for analysis of attacks and incidents (Russian Federation)
Arg. 3
The Russian Federation argues that a priority task is to finalise a standardised communication template to simplify cooperation between POCs by clearly defining the information needed for the analysis of attacks and incidents. Russia notes that UNODA presented relevant considerations last year but there was not enough time for substantive discussion, and that Russia has specific drafts to contribute.
The Russian Federation stated that the priority task is to finalise a standardised communication template that will simplify cooperation between POCs by clearly defining the information needed for the analysis of attacks and incidents, noting that UNODA presented relevant considerations last year but there was not enough time for a substantive discussion during the approval process for the OEWG’s final report, and that Russia has specific drafts in this regard .
on: The appropriate scope and use of the POC Directory — whether it should be used proactively for information exchange or reserved for crisis communication
CBMs as practical tools reducing misunderstanding – CBMs are practical tools for reducing the risk of misinterpretation, escalation and conflict in cyberspace, helping states build relationships and establish communication channels before a crisis occurs so that these channels can be used effectively during and after cyber incidents (Australia)
Arg. 1
Australia argues that CBMs are practical tools for reducing the risk of misinterpretation, escalation and conflict in cyberspace. They help states build relationships, establish procedures and create channels of communication before a crisis occurs so that these channels can be used effectively during and after cyber incidents.
Australia stated that CBMs are practical tools for reducing the risk of misinterpretation, escalation and conflict in cyberspace, and that they help states build relationships, establish procedures and create channels of communication before a crisis occurs so that these channels can be used effectively during and after cyber incidents .
on: CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace
Need for the directory to be actively maintained and tested – For the POC Directory to remain useful, it should be actively maintained, regularly tested, and supported by clear expectations of good faith use; requests should be proportionate and purposeful (Australia)
Arg. 2
Australia argues that for the POC Directory to remain useful, it should be actively maintained, regularly tested and supported by clear expectations of good faith use. Requests through the directory should be proportionate, purposeful and made with due regard to the capacity constraints of smaller states.
Australia stated that for the POC Directory to remain useful, it should be actively maintained, regularly tested and supported by clear expectations of good faith use, and that requests through the directory should be proportionate, purposeful and made with due regard to the capacity constraints of smaller states, and should not be treated as a mechanism for overwhelming national points of contact or creating unreasonable expectations of response .
on: The POC Directory should complement, not replace, existing diplomatic and technical communication channels
on: The appropriate scope and use of the POC Directory — whether it should be used proactively for information exchange or reserved for crisis communication
Cyber Rapid Assistance for Pacific Incidents and Disasters as a model – Australia's Cyber Rapid Assistance for Pacific Incidents and Disasters programme has an important role to play in building trust and habits of trust between states and regions; cooperation must be established before it is needed in a crisis (Australia)
Arg. 3
Australia highlights its Cyber Rapid Assistance for Pacific Incidents and Disasters (Cyber Rapid) programme as an example of regional arrangements that play an important role in building trust and habits of trust between states and regions. The key principle is that cooperation must be established before it is needed in a crisis.
Australia stated that regional arrangements including initiatives such as Australia’s Cyber Rapid Assistance for Pacific Incidents and Disasters, or Cyber Rapid, programme have an important role to play in building trust and habits of trust between states and regions, and that there needs to be a process of cooperation before they are needed in a crisis .
on: Simulation exercises, regular training and practical cooperation activities are essential for building confidence before crises occur
Industry and technical community closest to vulnerabilities and risks – Industry and the technical community, civil society and academia are often closest to vulnerabilities, incidents and emerging risks; their expertise can help states understand threats, improve prevention and response, and translate CBMs into practical action (Australia)
Arg. 4
Australia underlines the importance of stakeholder engagement, arguing that industry and the technical community, civil society and academia are often closest to vulnerabilities, incidents and emerging risks. Their expertise can help states understand threats, improve prevention and response, strengthen supply chain resilience and translate CBMs into practical action while preserving the intergovernmental nature of decision-making.
Australia stated that industry and the technical community, civil society and academia are often closest to vulnerabilities, incidents and emerging risks, and that their expertise can help states understand threats, improve prevention and response, strengthen supply chain resilience and translate CBMs into practical action while preserving the intergovernmental nature of decision-making .
on: Stakeholder engagement from the private sector, civil society, academia and the technical community is important for effective CBM implementation
Cooperation on vulnerability disclosure and supply chain integrity – The global mechanism should help states operationalise practical CBMs that reduce risk and build resilience, including cooperation on vulnerability disclosure and mitigation, supply chain integrity and national capacity building (Australia)
Arg. 5
Australia argues that the global mechanism should help states operationalise practical CBMs that reduce risk and build resilience. This includes cooperation on vulnerability disclosure and mitigation, supply chain integrity and national capacity building, recognising that for many states the ability to participate meaningfully in CBMs depends on having the right technical, policy and institutional foundations in place.
Australia stated that the global mechanism should also help states operationalise other practical CBMs that reduce risk and build resilience, including cooperation on vulnerability disclosure and mitigation, supply chain integrity and national capacity building, and that for many states the ability to participate meaningfully in CBMs depends on having the right technical, policy and institutional foundations in place .
Support for communication checks and simulation exercises – Thailand supports regular communication checks, simulation exercises and continued engagement to ensure the directory remains effective when needed most (Thailand)
Arg. 1
Thailand supports regular communication checks, simulation exercises and continued engagement to ensure that the POC directory remains effective when it is needed most. Thailand also considers the Template for Communication provided by the Secretariat as a useful tool to facilitate communication and assistance among POCs.
Thailand stated that it supports regular communication checks, simulation exercises and continued engagement to ensure that the directory remains effective when it is needed the most, and considers the Template for Communication example provided by the Secretariat pursuant to A79-14 as a useful tool to facilitate communication and assistance among POCs .
on: Simulation exercises, regular training and practical cooperation activities are essential for building confidence before crises occur
Dialogue within the OEWG and global mechanism as constructive CBMs – Thailand considers substantive dialogue within the OEWG and the ongoing discussion in the global mechanism to be constructive CBMs in themselves, recognising the vital role of the UN in supporting global implementation (Thailand)
Arg. 2
Thailand considers the substantive dialogue within the OEWG and the ongoing discussion in the global mechanism to be constructive CBMs in themselves. Thailand recognises the vital role of the UN in supporting the global implementation of CBMs.
Thailand stated that it considers the substantive dialogue within the OEWG and the ongoing discussion in the global mechanism to be constructive CBMs in themselves, and recognises the vital role of the UN in supporting the global implementation of CBMs .
DTGs as platforms for exchanging national experiences and good practices – The dedicated thematic groups offer a valuable opportunity to go into further depth on international relations and the role of international organisations in effective implementation of CBMs, exchanging national experiences and good practices (Chile)
Arg. 1
Malaysia sees the DTGs as an important platform for turning agreed CBMs into practical action. By identifying state capacity-building needs and facilitating access to relevant expertise and support, DTGs can help ensure that capacity-building efforts are responsive to national needs and strengthen the implementation of agreed CBMs.
Malaysia stated that it sees the DTG as an important platform for turning agreed confidence-building measures into practical action, and that by identifying state capacity-building needs and facilitating access to relevant expertise and support, DTG can help ensure that capacity-building efforts are responsive to national needs and strengthen the implementation of the agreed CBMs .
on: DTGs should focus on practical, action-oriented work to operationalise CBMs rather than reproducing procedural disagreements
African Union developing adapted CBMs for African realities – The African Union Commission is developing concrete measures adapted to African realities that can be effectively implemented in the various regions of the continent, drawing on experience from economic and regional committees (African Union Commission)
Arg. 1
The African Union Commission is committed to developing concrete measures adapted to African realities that can be effectively implemented in the various regions of the continent. The ambition is not to reproduce existing models or multiply the number of CBMs, but to set out concrete, adapted measures drawing on experience from economic and regional committees such as ECOWAS.
The African Union Commission stated that its ambition is not to reproduce existing models and not to multiply the number of confidence-building measures, but to set out concrete, adapted measures adapted to African realities that can be effectively implemented in the various regions of the continent, drawing on experience gained in economic and regional committees, in particular ECOWAS, and on best practices developed by other international organisations .
on: Regional organisations play an important role in advancing CBMs and their experiences should inform global implementation
on: Whether regional CBM models should inform or be adopted as global benchmarks
Importance of integrating regional POC networks with the global directory – The global mechanism should facilitate the integration of regional points of contact with the global POC directory to strengthen coherence and complementarity (African Union Commission)
Arg. 2
The African Union Commission recommends that the global mechanism facilitate the integration of regional points of contact with the global POC directory. This is one of three recommendations made to allow the global mechanism to support and strengthen the work done by the African Union.
The African Union Commission set out three recommendations for the global mechanism, the third of which was to facilitate the integration of the regional points of contact with the global POC directory .
on: The Global POC Directory is an important achievement that should be actively maintained, regularly tested and used in good faith as a complement to existing channels
Voluntary exchange of national cybersecurity strategies and risk assessments – States should share on a voluntary basis their national experience in terms of cybersecurity strategy, protection of essential infrastructure, risk management and response to incidents, fostering mutual trust and understanding (Democratic Republic of Congo)
Arg. 1
The Democratic Republic of Congo encourages states to share on a voluntary basis their national experience in terms of cybersecurity strategy, protection of essential infrastructure, risk management and response to incidents. This voluntary exchange can foster mutual trust and understanding among states.
The Democratic Republic of Congo encouraged states to share on a voluntary basis their national experience in terms of cybersecurity strategy, the protection of essential infrastructure, risk management and response to incidents, noting that this can foster mutual trust and understanding among states .
Multilingualism as a guarantor of inclusivity – The DRC joins the call to promote multilingualism as a guarantor of inclusivity in negotiation spaces, ensuring effective participation by everyone and the best results in the involvement of everyone (Democratic Republic of Congo)
Arg. 2
The Democratic Republic of Congo joins the call to promote multilingualism as a guarantor of inclusivity in negotiation spaces. Multilingualism ensures the effective participation of everyone and the best results in the involvement of all parties.
The Democratic Republic of Congo joined the call sounded by Colombia and Mexico to promote multilingualism as a guarantor of inclusivity in spaces for negotiation, stating that it has ensured the effective participation by everyone and the best results in the involvement of everyone .
Coordination between global roundtable and DTGs – The global roundtable on capacity building could play a role in ensuring enhanced coordination and cooperation, bringing together capacity building implementers for exchange of information and best practices, feeding into plenary and DTG2 discussions (European Union)
Arg. 1
The European Union proposes that the global roundtable on capacity building could play a role in ensuring enhanced coordination and cooperation by bringing together capacity building implementers for exchange of information and best practices. This would feed into discussions in the plenary and DTG2, with the EU aiming to avoid duplication between these different forums.
The European Union stated that the global roundtable on capacity building could play a role in ensuring enhanced coordination and cooperation, for instance by bringing together capacity building implementers for exchange of information and best practices, feeding into the discussions in the plenary and DTG2, and that the EU and its member states will aim to avoid duplication with discussions between the plenary, DTG2 and the global roundtable and pursue a streamlined approach .
on: Avoiding duplication across multiple communication channels and mechanisms is essential for coherence and effectiveness
EU investment in cybercapacity building globally – The EU is working with partners on 27 projects with a value of 100 million euros and will continue to invest, recognising capacity building as an essential pillar of security and stability in cyberspace (European Union)
Arg. 2
The European Union highlights its significant investment in cybercapacity building, noting that it is currently working with partners on 27 projects with a value of 100 million euros. The EU will continue to invest, recognising capacity building as an essential pillar of security and stability in cyberspace and of its partnerships.
The European Union stated that it has significantly invested in cybercapacity building over recent years and will continue to do so, noting that in addition to EU member states’ individual projects and initiatives such as the Global Gateway, the EU is working with partners on 27 projects with a value of 100 million euros, and will continue to invest, recognising capacity building as an essential pillar of security and stability in cyberspace .
Multi-stakeholder community role in designing and delivering capacity building – The role of the multi-stakeholder community in the design and delivery of cybercapacity building should be further discussed, recognising that industry, civil society and academia contribute meaningfully to effective and sustainable capacity building (European Union)
Arg. 3
The European Union argues that the role of the multi-stakeholder community in the design and delivery of cybercapacity building should be further discussed. The EU and member states will continue to promote coordination and cooperation with international organisations and other stakeholders such as industry, civil society, education and academia to ensure meaningful allocation of scarce resources and deliver capacity building activities in an effective and sustainable manner.
The European Union stated that further discussions could include the role of the multi-stakeholder community in the design and delivery of cybercapacity building, and that the EU and member states will continue to promote coordination and cooperation including with international organisations and other stakeholders such as industry, civil society and academia to ensure meaningful allocation of scarce resources and deliver capacity building activities in an effective and sustainable manner .
on: Stakeholder engagement from the private sector, civil society, academia and the technical community is important for effective CBM implementation
Youth engagement as a practical confidence-building measure – Member states should consider youth engagement as a practical CBM, including structured dialogues between governments and youth, support for youth-led cyber awareness initiatives, and opportunities for young experts to participate in regional and international CBM activities (DMUN Foundation)
Arg. 1
The DMUN Foundation argues that confidence in cyberspace cannot exist solely between governments but must extend to the people who use digital technologies every day, especially young people. Member states should consider youth engagement as a practical CBM, including structured dialogues, support for youth-led cyber awareness initiatives and opportunities for young experts to participate in regional and international CBM activities.
The DMUN Foundation stated that today’s youth are the first generation to grow up in an environment where cyber incidents, online disinformation and AI-generated content are part of everyday life, and despite being among the most affected stakeholders, young people are rarely included in discussions on how trust and confidence in cyberspace should be built, and therefore encouraged member states to consider youth engagement as a practical CBM including structured dialogues between governments and youth, support for youth-led cyber awareness initiatives and opportunities for young experts to participate in regional and international CBM activities .
on: Stakeholder engagement from the private sector, civil society, academia and the technical community is important for effective CBM implementation
Capacity building as a bridge between consensus and action – Capacity building is a bridge between consensus and action; voluntary norms, international law, CBMs and due diligence can only be turned into policies and practical steps if states have technical, legal and institutional capacities (Costa Rica)
Arg. 1
Vietnam strongly believes that capacity building is essential to international cooperation in ICT security. Through capacity building, states may develop common understanding of voluntary norms of responsible state behaviour and shared experiences and best practices in applying these norms to protect critical infrastructure and supply chains.
Vietnam stated that through capacity building, states may develop common understanding of voluntary, non-binding norms of responsible state behaviour, shared experiences and best practices in applying these norms to protect critical infrastructure and supply chains, and to ensure cyber hygiene and security by design .
on: Capacity building is a cross-cutting priority and essential enabler for effective CBM implementation
Capacity building requires financial and technical support for equal opportunities – Capacity building should get financial and technical support so that equal opportunities are available to all states to benefit from international programmes and initiatives, with special attention to developing countries and countries emerging from conflict (Iraq)
Arg. 1
Iraq stresses the importance of providing financial and technical support for capacity building so that equal opportunities are available to all states to benefit from international programmes and initiatives. Special attention should be given to the needs of developing countries and countries emerging from conflict.
Iraq stated that capacity building should get financial and technical support so that equal opportunities be available to all states to benefit from international programmes and initiatives, and that special attention should be given to the needs of developing countries and countries emerging from conflict in a manner that enables such countries to implement the international framework of responsible state behaviour .
on: Capacity building must be demand-driven, nationally owned, sustainable and tailored to specific national needs
Capacity building initiatives should avoid duplication and maximise resources – The mechanism offers the right platform to identify ongoing initiatives, generate complementarity between them, and engage in more effective coordination based on the needs and priorities of different states (Colombia)
Arg. 1
Colombia argues that avoiding duplication of efforts and maximising available resources is a priority. The mechanism offers the right platform to identify initiatives that are currently ongoing, generate complementarity between them and engage in more effective coordination based on the needs and priorities of different states.
Colombia stated that for it, it is a priority to avoid duplication of efforts and to maximise the resources available, and that the mechanism offers the right platform to identify initiatives that are currently ongoing, to generate complementarity between them and to engage in more effective coordination based on the needs and priorities of different states .
on: Avoiding duplication across multiple communication channels and mechanisms is essential for coherence and effectiveness
South-South and triangular cooperation as valuable modalities – Modalities like South-South cooperation and triangular cooperation can play a particularly valuable role in capacity building, facilitating the exchange of knowledge and good practices while taking account of local realities and priorities (Colombia)
Arg. 2
Colombia argues that modalities like South-South cooperation and triangular cooperation can play a particularly valuable role in capacity building, as they facilitate the exchange of knowledge and good practices while taking account of local realities and priorities. These modalities leverage the comparative advantages and specialised experience of some states and regions.
Colombia stated that it is essential to harness the comparative advantages and specialised experience of some states and regions to promote more effective cooperation tailored to the needs of beneficiary countries, and that modalities like South-South cooperation and triangular cooperation can play a particularly valuable role since they facilitate the exchange of knowledge and good practices, taking account of local realities and priorities .
on: Capacity building must be demand-driven, nationally owned, sustainable and tailored to specific national needs
Capacity building as a bridge between consensus and action – Capacity building is a bridge between consensus and action; voluntary norms, international law, CBMs and due diligence can only be turned into policies and practical steps if states have technical, legal and institutional capacities (Costa Rica)
Arg. 1
Costa Rica argues that capacity building is a bridge between consensus and action, as voluntary norms, international law, CBMs and due diligence can only be turned into policies and practical steps if states have the necessary technical, legal and institutional capacities. Without capacities, there is a risk of building a legally elegant infrastructure that is operationally useless.
Costa Rica stated that capacity building is a bridge between consensus and action, and that voluntary norms, international law, confidence-building measures, due diligence and national resilience can only be turned into policies and practical steps if states have technical, legal and institutional capacities that are up to the mark, warning that without capacities there is a risk of building a legally elegant infrastructure that is operationally useless .
on: Capacity building is a cross-cutting priority and essential enabler for effective CBM implementation
Capacity building priorities for developing countries – Nigeria believes DTG2 should prioritise strengthening national cybersecurity strategies, legal and governance frameworks, technical capabilities including CERTs, and expertise in cyber diplomacy, digital forensics and cybercrime investigations (Nigeria)
Arg. 1
Nigeria believes DTG2 should prioritise a range of capacity building areas for developing countries, including strengthening national cybersecurity strategies, legal and governance frameworks, technical capabilities including CERTs, and expertise in cyber diplomacy, digital forensics and cybercrime investigations. Nigeria also attaches particular importance to practical cooperation among governments, regional organisations, academia, the private sector, civil society and the technical community.
Nigeria stated that it believes DTG2 should prioritise strengthening national cybersecurity strategies, legal and governance frameworks, technical capabilities including CERTs, and expertise in cyber diplomacy, digital forensics, cybercrime investigations and the promotion of critical infrastructure and critical information infrastructure, and that as emerging technologies continue to evolve rapidly, capacity-building efforts should equally invest in cybersecurity education, digital skill development, research and innovation .
on: Capacity building must be demand-driven, nationally owned, sustainable and tailored to specific national needs
Capacity building as a bridge between consensus and action – Capacity building is a bridge between consensus and action; voluntary norms, international law, CBMs and due diligence can only be turned into policies and practical steps if states have technical, legal and institutional capacities (Costa Rica)
Arg. 1
Morocco argues that capacity building is not a secondary issue but the guiding thread that runs through all the other pillars of responsible behaviour. The credibility of the global mechanism hinges on the collective capacity to translate ideas into projects and projects into concrete results.
Morocco stated that capacity building is not a secondary issue but the guiding thread that runs through all the other pillars of responsible behaviour, and that the credibility of the global mechanism largely hinges on the collective capacity to translate ideas into projects and projects into concrete results .
on: Capacity building is a cross-cutting priority and essential enabler for effective CBM implementation
CBMs as practical tools reducing misunderstanding – CBMs are practical tools for reducing the risk of misinterpretation, escalation and conflict in cyberspace, helping states build relationships and establish communication channels before a crisis occurs so that these channels can be used effectively during and after cyber incidents (Australia)
Arg. 1
Mozambique considers CBMs to be one of the most practical pillars of the global mechanism. For developing countries, CBMs should move beyond political commitments and translate into concrete mechanisms that strengthen confidence, reduce the risk of misunderstanding and miscalculation, and improve collective resilience against cyber threats.
Mozambique stated that for developing countries, confidence-building measures should move beyond political commitments and translate into concrete mechanisms that strengthen confidence, reduce the risk of misunderstanding and miscalculation, and improve collective resilience against cyber threats .
on: CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace
The eight global CBMs and the POC Directory are important confidence-building tools that can strengthen cooperation and reduce misinterpretation – The Chair summarised that delegations reflected on the eight global measures, including information exchange, public-private collaboration and capacity building, and that the POC Directory is an important voluntary confidence-building tool (Chair Egriselda López)
Arg. 1
The Chair summarised the discussion by noting that delegations had reflected on the eight global measures, which include information exchange measures such as sharing national strategies, legislation and good practices, collaboration between the public and private sector, and capacity building measures. She affirmed that the POC Directory is an important voluntary confidence-building tool that can strengthen cooperation and reduce misinterpretation and instability.
The Chair stated that delegations had reflected on the eight global measures including information exchange measures such as sharing national strategies, legislation and good practices, collaboration between the public and private sector, and capacity building measures, and that the POC Directory is an important confidence-building tool, a voluntary one that can strengthen cooperation and reduce misinterpretation and instability, and that CBMs can strengthen cooperation, reduce risks from errors of calculation and foster stability in the digital sector .
on: CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace
Universal participation in the POC Directory should be achieved – The Chair welcomed state participation in the directory and expressed hope that universal participation would eventually be achieved (Chair Egriselda López)
Arg. 2
The Chair expressed her welcome for state participation in the POC Directory and her hope that universal participation would eventually be achieved. This reflects the broader consensus among delegations that the directory's value depends on the widest possible participation by member states.
The Chair stated that she welcomed state participation in the directory and hoped that eventually universal participation would be achieved .
on: The Global POC Directory is an important achievement that should be actively maintained, regularly tested and used in good faith as a complement to existing channels
Contact points must be and operational to respond in a timely manner to ICT incidents – The Chair urged all states that had not yet done so to appoint and nominate diplomatic contact points and engage in verifications to ensure contact points remain and operational (Chair Egriselda López)
Arg. 3
The Chair urged all states that had not yet done so to appoint and nominate diplomatic contact points and to engage in verification exercises to ensure that these contact points remain and operational. She emphasised that the real value of contact points lies precisely in their ability to respond in a timely manner to ICT incidents.
The Chair urged all those who had not yet done so to appoint and nominate diplomatic contact points and engage in verifications to ensure that these contact points remain and operational, given that the real value of them is precisely their ability to respond in a timely manner to ICT incidents .
CBMs are vital for implementing the framework on responsible state behaviour – The Chair noted that member states attached great value to CBMs as vital for the implementation of the framework on responsible state behaviour (Chair Egriselda López)
Arg. 4
The Chair noted in her summary that member states had expressed the value they attach to CBMs as vital instruments for the implementation of the framework on responsible state behaviour. She indicated that all statements had been taken note of as important inputs for determining the way forward, specifically how discussions in the DTGs would be structured.
The Chair stated that she had heard the value that member states attached to these measures as vital for the implementation of the framework on responsible state behaviour, and that all statements had been taken note of as important inputs for determining the way forward, specifically how discussions in the DTGs would be structured .
Session Knowledge Graph
Speakers · Topics · Arguments · Relationships
There was near-universal agreement that CBMs are essential practical tools for reducing misunderstanding, escalation and conflict in cyberspace. The African Group affirmed that CBMs are indispensable for fostering trust, transparency, predictability and cooperation . Israel stated that CBMs allow states to build practical procedures during peacetime for de-escalation and risk reduction during geopolitical crises . Australia described CBMs as practical tools for reducing the risk of misinterpretation, escalation and conflict . Malawi and Mozambique echoed this view . Norway emphasised that CBMs provide practical tools for implementing agreed commitments . North Macedonia noted that CBMs are among the most valuable outcomes of the OEWG process . Côte d’Ivoire stressed that trust is built by dialogue, transparency, predictability and results-based cooperation . The Chair summarised this broad consensus in her closing remarks .
CBMs as essential tools for preventing escalation and fostering trust – CBMs are indispensable for fostering trust, transparency, predictability and cooperation among states, contributing to international peace and security in cyberspace (NIgeria on behalf of African Group)
CBMs as practical tools for de-escalation – CBMs allow states to build practical procedures during peacetime that can be directly utilised for de-escalation, communication and risk reduction during geopolitical crises (Israel)
CBMs as practical tools reducing misunderstanding – CBMs are practical tools for reducing the risk of misinterpretation, escalation and conflict in cyberspace, helping states build relationships and establish communication channels before a crisis occurs so that these channels can be used effectively during and after cyber incidents (Australia)
CBMs as practical tools reducing misunderstanding – CBMs are practical tools for reducing the risk of misinterpretation, escalation and conflict in cyberspace, helping states build relationships and establish communication channels before a crisis occurs so that these channels can be used effectively during and after cyber incidents (Australia)
CBMs as practical tools reducing misunderstanding – CBMs are practical tools for reducing the risk of misinterpretation, escalation and conflict in cyberspace, helping states build relationships and establish communication channels before a crisis occurs so that these channels can be used effectively during and after cyber incidents (Australia)
CBMs provide practical tools for implementing agreed commitments – CBMs provide practical tools for implementing agreed commitments; mechanisms such as points of contact, dialogue, sharing of best practices and information sharing help reduce risk, prevent misunderstandings and contribute to stability and security in cyberspace (Norway)
CBMs as valuable outcomes of the OEWG process – CBMs are among the most valuable outcomes of the OEWG process, demonstrating that even in a complex and rapidly evolving cyber environment, states can agree on practical measures to strengthen trust and improve communication (North Macedonia)
CBMs as instruments for inclusive participation – For developing countries, CBMs are not merely diplomatic instruments but practical tools that enable more inclusive participation in the international ICT security framework (Cameroon)
CBMs built through dialogue and transparency – Trust is not something that can be declared by fiat; it is built by dialogue, transparency, predictability, and results-based cooperation (Côte d'Ivoire)
The eight global CBMs and the POC Directory are important confidence-building tools that can strengthen cooperation and reduce misinterpretation – The Chair summarised that delegations reflected on the eight global measures, including information exchange, public-private collaboration and capacity building, and that the POC Directory is an important voluntary confidence-building tool (Chair Egriselda López)
This consensus is well-established within the UN OEWG framework, where delegations broadly affirmed that CBMs should be implemented gradually and that the POC directory constitutes a good starting point [S158]. The African Group explicitly called for continued discussion on how CBMs can be effectively operationalised in response to severe incidents [S156], reinforcing their practical utility.
Speakers broadly agreed that the Global POC Directory is a significant achievement that must be actively maintained and used in good faith. Tonga described it as the flagship practical achievement of the OEWG . Ireland and the Netherlands both argued it should be used as a complement to, not a replacement for, existing channels . Australia called for it to be actively maintained, regularly tested and supported by clear expectations of good faith use, with requests being proportionate and purposeful . The Russian Federation urged all remaining states to join . Thailand supported regular communication checks and simulation exercises . The African Union Commission recommended integrating regional POC networks with the global directory . The Chair urged all states to appoint and nominate diplomatic contact points and engage in verifications .
Strong support for the POC Directory as a flagship achievement – Tonga strongly supports the Global Points of Contact Directory as the flagship practical achievement of the OEWG and commends UNODA for its continued operationalisation (Tonga)
POC Directory as a complement, not replacement, to existing channels – The POC Directory should be used as a complement to existing channels of communication between states, not as a replacement or duplication of established diplomatic or technical channels (Ireland)
POC Directory as complementary to, not replacing, existing channels – The strength and added value of the POC Directory are found in establishing lines of contact where these previously were unavailable or unclear; it should be a complementary tool, not a replacement for existing POC networks (Netherlands)
Need for the directory to be actively maintained and tested – For the POC Directory to remain useful, it should be actively maintained, regularly tested, and supported by clear expectations of good faith use; requests should be proportionate and purposeful (Australia)
Need for universal participation in the directory – 125 states have joined the directory, which is positive, but all remaining member states should join by designating appropriate diplomatic and technical points of contact (Russian Federation)
Support for communication checks and simulation exercises – Thailand supports regular communication checks, simulation exercises and continued engagement to ensure the directory remains effective when needed most (Thailand)
Importance of integrating regional POC networks with the global directory – The global mechanism should facilitate the integration of regional points of contact with the global POC directory to strengthen coherence and complementarity (African Union Commission)
Voluntary cyber exercises to build confidence and practical skills – Argentina supports continuing voluntary exercises, gradually fine-tuning their modalities and exchanging experiences that encourage practical use of the POC directory and other CBMs (Argentina)
POC Directory as a dynamic instrument for cooperation – The directory should evolve from a repository of contacts into a dynamic instrument for cooperation, with functionalities progressively enhanced to facilitate secure communication and voluntary information exchange (Cameroon)
Universal participation in the POC Directory should be achieved – The Chair welcomed state participation in the directory and expressed hope that universal participation would eventually be achieved (Chair Egriselda López)
The POC Directory was launched with 109 countries joining within its first six months [S160], and subsequent sessions emphasised expanding participation and building capacity, especially for developing countries [S170]. Discussions at the 9th substantive OEWG session highlighted standardisation, improved communication, and proactive use of the Directory [S168], while Canada welcomed ongoing operationalisation efforts [S166].
Multiple speakers converged on the view that the POC Directory should complement rather than replace existing channels. Ireland stated it should be used in good faith as a complement to existing channels . The Netherlands argued its strength lies in establishing lines of contact where previously unavailable, and should not replace existing POC networks or diplomatic channels . Germany similarly argued the directory is not intended to replace established channels such as FIRST, CERT-to-CERT cooperation or law enforcement cooperation . Australia stated states should always remain free to engage through channels most appropriate to the circumstances . Vanuatu requested clear guidance on which channels serve which purpose and no duplication of what already functions elsewhere .
POC Directory as a complement, not replacement, to existing channels – The POC Directory should be used as a complement to existing channels of communication between states, not as a replacement or duplication of established diplomatic or technical channels (Ireland)
POC Directory as complementary to, not replacing, existing channels – The strength and added value of the POC Directory are found in establishing lines of contact where these previously were unavailable or unclear; it should be a complementary tool, not a replacement for existing POC networks (Netherlands)
POC Directory as complementary to, not replacing, existing channels – The strength and added value of the POC Directory are found in establishing lines of contact where these previously were unavailable or unclear; it should be a complementary tool, not a replacement for existing POC networks (Netherlands)
Need for the directory to be actively maintained and tested – For the POC Directory to remain useful, it should be actively maintained, regularly tested, and supported by clear expectations of good faith use; requests should be proportionate and purposeful (Australia)
Need for coherence across multiple communication channels – The international community is multiplying its channels of communication; Vanuatu requests that the directory be developed in deliberate awareness of the wider ecosystem, with clear guidance on which channels serve which purpose (Vanuatu)
The OEWG framework explicitly envisages differentiated roles for diplomatic and technical POCs, with diplomatic POCs communicating with diplomatic counterparts and technical POCs with technical counterparts [S161]. Delegations also emphasised building on existing POC infrastructures from regional organisations rather than replacing them [S158].
There was strong consensus that capacity building is a cross-cutting priority and essential enabler for effective CBM implementation. The African Group stated that for African countries, capacity building is not an auxiliary issue but a strategic enabler . The Pacific Islands Forum argued it is foundational to all aspects of the mechanism’s work and should not be siloed . Ireland noted that capacity building is an essential prerequisite for successful CBM implementation for many states . The Latin American group called for DTG2 to be established as the main platform for capacity building dialogue . The Philippines emphasised that capacity building is indispensable for effective CBM implementation . Costa Rica described capacity building as a bridge between consensus and action . Morocco called it the guiding thread running through all pillars of responsible behaviour .
Capacity building as a strategic enabler for African countries – For African countries, capacity building is not an auxiliary issue; it is a strategic enabler for achieving a secure, resilient and inclusive digital future as digital transformation accelerates across the continent (NIgeria on behalf of African Group)
Capacity building as foundational to all aspects of the mechanism's work – Capacity building is the enabler that underpins all aspects of the work; it is foundational to responding to threats, implementing norms, engaging meaningfully in international law discussions, and sustaining CBMs (Tonga on behalf of Pacific Islands Forum)
Expertise of stakeholders should play a strong role – The expertise and experience of stakeholders from academia, the technical community, civil society and the private sector should play a strong role in the CBM implementation process, with practical tools and best practices feeding engagement (Ireland)
DTG2 as the main platform for capacity building dialogue – The DTG on capacity building must be established as the main platform for dialogue on this issue within the global mechanism, playing a fundamental role as a space for strategic coordination to facilitate information exchange and articulate synergies (Chile Representative on behalf of Latin American group)
POC Directory requires capacity building to be effective – Many states face institutional, technical and resource constraints affecting their ability to operationalise national points of contact; capacity building is indispensable for effective implementation (Philippines)
CARICOM priorities for capacity building – CARICOM highlights three regional priorities: cyber law and modern legal frameworks, sustained cyber capacity building for resilience and technical expertise, and critical infrastructure protection for small states with limited resources (Bahamas on behalf of the CARICOM)
Capacity building as a bridge between consensus and action – Capacity building is a bridge between consensus and action; voluntary norms, international law, CBMs and due diligence can only be turned into policies and practical steps if states have technical, legal and institutional capacities (Costa Rica)
Capacity building as a bridge between consensus and action – Capacity building is a bridge between consensus and action; voluntary norms, international law, CBMs and due diligence can only be turned into policies and practical steps if states have technical, legal and institutional capacities (Costa Rica)
Capacity building priorities for developing countries – Nigeria believes DTG2 should prioritise strengthening national cybersecurity strategies, legal and governance frameworks, technical capabilities including CERTs, and expertise in cyber diplomacy, digital forensics and cybercrime investigations (Nigeria)
Capacity building as a bridge between consensus and action – Capacity building is a bridge between consensus and action; voluntary norms, international law, CBMs and due diligence can only be turned into policies and practical steps if states have technical, legal and institutional capacities (Costa Rica)
Capacity building was identified as a complementary aspect to CBMs across multiple OEWG sessions, with calls for a coordinated strategy involving regional and sub-regional organisations and multi-stakeholder participation [S167]. Malaysia specifically welcomed provisions on targeted capacity-building to encourage onboarding of states to the POC Directory [S159], and Canada supported work to help developing states participate effectively [S166].
Speakers from all regions agreed that regional organisations play a vital role in advancing CBMs and that their experiences should inform global implementation. The African Group encouraged the global mechanism to strengthen coordination between global and regional initiatives . Chile argued that exchange of good practices between regional mechanisms could strengthen CBM implementation globally . Uruguay highlighted the OAS experience . Ghana pointed to the ECOWAS regional framework . The Philippines highlighted the ASEAN Regional CERT . The African Union Commission described its work developing adapted CBMs for African realities . The OSCE shared its extensive experience as the first regional organisation to develop cyber CBMs . Tonga presented its Pacific cooperation experience as a concrete example of CBMs working in practice .
Regional organisations play an important role in advancing CBMs – The global mechanism should strengthen coordination and complementarity between global and regional confidence-building initiatives and promote linkages between regional POC networks and the global directory (NIgeria on behalf of African Group)
Cross-regional exchanges to avoid duplication and share lessons learned – The exchange of good practices between regional mechanisms could make meaningful contributions to strengthening CBM implementation globally, avoiding duplications and making the most of lessons learned in different contexts (Chile)
OAS regional experience as a model for CBM implementation – Regional experience in the OAS shows the practical value of CBMs; Uruguay has designated and updated its technical contact points in the OAS framework since 2018 and participates in cooperation mechanisms such as CERT Americas (Uruguay)
ECOWAS regional framework as a practical example – ECOWAS has developed a regional framework on cyber ICT confidence-building measures with Ghana's participation, establishing practical mechanisms including national diplomatic and technical points of contact (Ghana)
ASEAN Regional CERT as a step toward regional cybersecurity posture – As ASEAN Chair in 2026, the Philippines welcomed progress in operationalising the ASEAN Regional CERT, an important step toward raising the regional cybersecurity posture through timely information sharing and coordinated incident response (Philippines)
African Union developing adapted CBMs for African realities – The African Union Commission is developing concrete measures adapted to African realities that can be effectively implemented in the various regions of the continent, drawing on experience from economic and regional committees (African Union Commission)
OSCE as the first regional organisation to develop cyber CBMs – The OSCE was the first regional organisation to develop cyber confidence-building measures and has many years of experience in practical implementation of its 16 CBMs, including through the Adopt-a-CBM initiative (OSCE)
Western Balkans Cyber Diplomacy Network as a regional initiative – The launch of the Western Balkans Cyber Diplomacy Network in 2025, supported by the German Federal Foreign Office, represents the region's shared commitment to addressing cross-border cyber challenges through dialogue and cooperation (Bosnia and Herzegovina)
Pacific regional cooperation as a model for cyber incident response – CERT Tonga was established in 2016 and has worked within the Pacific Cyber Security Operational Network; when Tonga's health system was attacked, established relationships enabled rapid assistance and joint public attribution with Australia and New Zealand (Tonga)
DTGs as forums for trust-building and learning – The global mechanism, especially the DTGs, provides an opportunity to develop ways to operationalise the CBM pillar in a practical way and can act as a forum for cross-regional learning (Germany)
Delegations broadly supported building on existing POC infrastructures from regional organisations and integrating them to avoid duplication of effort [S158]. Germany and France specifically suggested learning from regional examples to ensure responsible use of the POC Directory [S170].
Multiple speakers agreed that capacity building must be demand-driven, nationally owned, sustainable and tailored to specific national needs. The African Group underscored that effective capacity building must be demand-driven, nationally owned, sustainable and tailored to the specific needs and priorities of countries . CARICOM supported capacity-building initiatives that are voluntary, demand-driven, sustainable, transparent and based on national ownership . Iraq stressed that capacity building should be anchored in national needs and priorities while respecting sovereignty . Nigeria called for capacity building efforts to be demand-driven, nationally owned, sustainable and tailored to national priorities . Colombia emphasised the value of South-South and triangular cooperation in facilitating knowledge exchange while taking account of local realities .
Capacity building must be demand-driven, nationally owned and sustainable – Effective capacity building must be demand-driven, nationally owned, sustainable, and tailored to the specific needs and priorities of countries, respecting national sovereignty (NIgeria on behalf of African Group)
CARICOM priorities for capacity building – CARICOM highlights three regional priorities: cyber law and modern legal frameworks, sustained cyber capacity building for resilience and technical expertise, and critical infrastructure protection for small states with limited resources (Bahamas on behalf of the CARICOM)
Capacity building requires financial and technical support for equal opportunities – Capacity building should get financial and technical support so that equal opportunities are available to all states to benefit from international programmes and initiatives, with special attention to developing countries and countries emerging from conflict (Iraq)
Capacity building priorities for developing countries – Nigeria believes DTG2 should prioritise strengthening national cybersecurity strategies, legal and governance frameworks, technical capabilities including CERTs, and expertise in cyber diplomacy, digital forensics and cybercrime investigations (Nigeria)
South-South and triangular cooperation as valuable modalities – Modalities like South-South cooperation and triangular cooperation can play a particularly valuable role in capacity building, facilitating the exchange of knowledge and good practices while taking account of local realities and priorities (Colombia)
This principle is reinforced by IGF discussions emphasising the need to reduce duplication, harmonise efforts, and create sustainable outcomes through coordination [S164]. The importance of avoiding one-size-fits-all approaches is particularly salient given the distinct constraints faced by small island developing states and other vulnerable nations [S151][S152].
There was broad agreement that DTGs should focus on practical, action-oriented work to operationalise CBMs. Israel stated that DTGs must prioritise further developing and operationalising CBMs . Argentina proposed a division of labour between DTG1 for CBM operationalisation and DTG2 for capacity building support . The Pacific Islands Forum argued DTGs should not become additional negotiating rooms reproducing procedural disagreements . Chile viewed DTGs as valuable opportunities for exchanging national experiences and good practices . North Macedonia called for CBMs to be reflected in DTG work through sharing of national experience while avoiding duplication of plenary discussions . Germany described the DTGs as providing an opportunity to operationalise the CBM pillar in a practical way and act as a forum for cross-regional learning .
DTGs should prioritise further developing and operationalising CBMs – The DTGs must prioritise further developing and operationalising CBMs, as they hold great potential for immediate positive impact and for generating beneficial momentum for the global mechanism (Israel)
DTG1 for operationalising CBMs and DTG2 for capacity building support – DTG1 could examine operationalisation of CBMs by exchanging national and regional experiences, while DTG2 could identify capacities required to support this operationalisation effort (Argentina)
DTGs should focus on practical, technical work rather than procedural disagreements – DTGs should be used to identify needs, share practical experience, connect states with relevant expertise, and help match national and regional priorities with appropriate support, not become additional negotiating rooms (Tonga on behalf of Pacific Islands Forum)
DTGs as platforms for exchanging national experiences and good practices – The dedicated thematic groups offer a valuable opportunity to go into further depth on international relations and the role of international organisations in effective implementation of CBMs, exchanging national experiences and good practices (Chile)
CBMs should be reflected in DTG work through sharing of national experiences – CBMs should be reflected in the work of the thematic groups through sharing of national experience, practical implementation approaches and good practices, while avoiding duplication of plenary discussions (North Macedonia)
DTGs as platforms for exchanging national experiences and good practices – The dedicated thematic groups offer a valuable opportunity to go into further depth on international relations and the role of international organisations in effective implementation of CBMs, exchanging national experiences and good practices (Chile)
DTGs as forums for trust-building and learning – The global mechanism, especially the DTGs, provides an opportunity to develop ways to operationalise the CBM pillar in a practical way and can act as a forum for cross-regional learning (Germany)
A broad consensus emerged across plenary sessions that DTGs should serve as practical, action-oriented forums for advancing implementation of the normative framework [S155][S157]. Romania explicitly stated that DTGs could play an important role as venues for exchanging views and formulating recommendations [S155].
Speakers widely agreed that simulation exercises, regular training and practical cooperation activities are essential for building confidence before crises occur. Côte d’Ivoire recommended regularly organising UN-auspiced simulation exercises bringing together points of contact, national incident response teams and relevant authorities . Argentina supported continuing voluntary exercises to encourage practical use of the POC directory . Tonga illustrated what CBMs look like when they work through its health system attack experience: relationships built before the crisis, exercised during it and deepened after it . Australia emphasised that cooperation must be established before it is needed in a crisis . The OSCE described its scenario-based exercises as usually well received . Thailand supported regular communication checks and simulation exercises .
Regular simulation exercises under UN auspices – Côte d'Ivoire recommends regularly organising under UN auspices simulation exercises that bring together points of contact, national incident response teams and relevant authorities (Côte d'Ivoire)
Voluntary cyber exercises to build confidence and practical skills – Argentina supports continuing voluntary exercises, gradually fine-tuning their modalities and exchanging experiences that encourage practical use of the POC directory and other CBMs (Argentina)
Tonga's CERT as an example of CBMs working in practice – Tonga's experience with its health system attack demonstrated what CBMs look like when they work: relationships built before the crisis, exercised during it, and deepened after it (Tonga)
Cyber Rapid Assistance for Pacific Incidents and Disasters as a model – Australia's Cyber Rapid Assistance for Pacific Incidents and Disasters programme has an important role to play in building trust and habits of trust between states and regions; cooperation must be established before it is needed in a crisis (Australia)
OSCE capacity building through scenario-based exercises – The OSCE delivers capacity building activities including trainings and workshops with scenario-based exercises that help participants understand the practical application of CBMs, which is usually well received (OSCE)
Botswana's national cybersecurity activities as CBM implementation – Botswana's recent internal cybersecurity activities reflect CBM implementation through formal public-private partnerships, threat intelligence sharing and academic collaboration, focusing on response readiness and workforce upskilling (Botswana)
Support for communication checks and simulation exercises – Thailand supports regular communication checks, simulation exercises and continued engagement to ensure the directory remains effective when needed most (Thailand)
There was broad agreement on the importance of stakeholder engagement for effective CBM implementation. Ireland argued that the expertise and experience of stakeholders from academia, the technical community, civil society and the private sector should play a strong role . Australia stated that industry and the technical community are often closest to vulnerabilities and emerging risks . Uruguay highlighted that public-private partnerships are essential given that significant parts of critical information infrastructure are operated by non-governmental actors . The Pacific Islands Forum strongly supported the substantive inclusion of stakeholders in both formal and informal settings . The EU called for continued promotion of coordination with industry, civil society and academia . The DMUN Foundation called for youth engagement as a practical CBM .
Expertise of stakeholders should play a strong role – The expertise and experience of stakeholders from academia, the technical community, civil society and the private sector should play a strong role in the CBM implementation process, with practical tools and best practices feeding engagement (Ireland)
Industry and technical community closest to vulnerabilities and risks – Industry and the technical community, civil society and academia are often closest to vulnerabilities, incidents and emerging risks; their expertise can help states understand threats, improve prevention and response, and translate CBMs into practical action (Australia)
Public-private partnerships essential for critical infrastructure protection – Given that a significant part of critical information infrastructure is operated by non-governmental actors or is part of the supply chain, public-private partnerships are essential to strengthen prevention, early alerts and fighting malicious information (Uruguay)
Stakeholder engagement essential for capacity building – Meaningful capacity building depends on access to the expertise of the multi-stakeholder community, academia, civil society, the private sector and the technical community; stakeholders must be substantively included in both formal and informal settings (Tonga on behalf of Pacific Islands Forum)
Multi-stakeholder community role in designing and delivering capacity building – The role of the multi-stakeholder community in the design and delivery of cybercapacity building should be further discussed, recognising that industry, civil society and academia contribute meaningfully to effective and sustainable capacity building (European Union)
Youth engagement as a practical confidence-building measure – Member states should consider youth engagement as a practical CBM, including structured dialogues between governments and youth, support for youth-led cyber awareness initiatives, and opportunities for young experts to participate in regional and international CBM activities (DMUN Foundation)
Multi-stakeholder participation was consistently encouraged across OEWG sessions, with academia, the private sector, civil society, and technical communities identified as essential contributors to CBM implementation [S167]. The DTG framework was also designed to incorporate expert briefings and evidence-based dialogue with multi-stakeholder participation [S157].
Multiple speakers agreed on the importance of avoiding duplication across multiple communication channels and mechanisms. Vanuatu, speaking from the perspective of small administrations operating multiple channels through the same handful of officials, requested clear guidance on which channels serve which purpose and no duplication of what already functions elsewhere . Israel called for the global mechanism to prioritise harmonising with other multilateral and regional forums . The Netherlands argued the POC directory should be a complementary tool, not a replacement . Germany similarly argued the directory should not replace established channels . Cameroon recommended avoiding duplication of what already functions elsewhere . Colombia prioritised avoiding duplication of efforts and maximising available resources . The EU aimed to avoid duplication between the plenary, DTG2 and the global roundtable .
Need for coherence across multiple communication channels – The international community is multiplying its channels of communication; Vanuatu requests that the directory be developed in deliberate awareness of the wider ecosystem, with clear guidance on which channels serve which purpose (Vanuatu)
Global mechanism should harmonise with other multilateral and regional forums – The global mechanism's work should prioritise harmonising with other multilateral and regional forums and ensure that all outcomes are mutually reinforcing (Israel)
POC Directory as complementary to, not replacing, existing channels – The strength and added value of the POC Directory are found in establishing lines of contact where these previously were unavailable or unclear; it should be a complementary tool, not a replacement for existing POC networks (Netherlands)
POC Directory as complementary to, not replacing, existing channels – The strength and added value of the POC Directory are found in establishing lines of contact where these previously were unavailable or unclear; it should be a complementary tool, not a replacement for existing POC networks (Netherlands)
Avoiding duplication between global and regional mechanisms – The global mechanism should facilitate exchanges of experience among member states and regional organisations through workshops and knowledge-sharing initiatives, avoiding duplication of what already functions elsewhere (Cameroon)
Capacity building initiatives should avoid duplication and maximise resources – The mechanism offers the right platform to identify ongoing initiatives, generate complementarity between them, and engage in more effective coordination based on the needs and priorities of different states (Colombia)
Coordination between global roundtable and DTGs – The global roundtable on capacity building could play a role in ensuring enhanced coordination and cooperation, bringing together capacity building implementers for exchange of information and best practices, feeding into plenary and DTG2 discussions (European Union)
Policy coherence and avoidance of duplication are recognised priorities across multiple UN digital governance forums [S162][S163]. IGF discussions on cyber capacity building coordination similarly emphasised the need to reduce duplication and harmonise efforts [S164], and delegations in the OEWG context called for integrating regional POC infrastructures to avoid duplicating effort [S158].
Small and developing states share a common perspective that their unique circumstances create specific challenges for CBM implementation and that the global mechanism must be designed with these constraints in mind. Tonga noted that small states do not maintain wide networks of diplomats tasked with cyber-related cooperation . Vanuatu emphasised that distance should never determine who participates in building confidence and supported hybrid modalities . Tuvalu called for a shift from short-term external consulting to long-term training of local technical teams . CARICOM acknowledged persistent gaps in resources, workforce development and cross-sector coordination . Botswana argued that global transparency initiatives must be paired with concrete technical assistance to address the digital divide .
Russia, Germany and Australia all identified practical challenges with the functioning of the POC Directory, though from different perspectives. Russia reported that only around 48% of its 2,576 inquiries were responded to, attributing this to dead contacts and political reasons . Germany reported receiving repetitive, identical messages from a certain state that did not take into account its replies, characterising this as not in line with the purpose of the directory . Australia called for the directory to be actively maintained, regularly tested and supported by clear expectations of good faith use, with requests being proportionate and purposeful . All three implicitly or explicitly called for better norms around responsible use of the directory.
Regional groupings from Africa, the Pacific, Latin America and the EU all converged on the view that capacity building is a central, cross-cutting priority for the global mechanism. The African Group stated that for African countries, capacity building is not an auxiliary issue but a strategic enabler . The Pacific Islands Forum argued it is foundational to all aspects of the mechanism’s work and should not be siloed . The Latin American group called for DTG2 to be established as the main platform for capacity building dialogue . The EU highlighted its significant investment of 100 million euros across 27 projects and its commitment to continue investing .
Pacific Island states and Australia shared a common perspective on the importance of building relationships and cooperation before crises occur, drawing on concrete Pacific regional experience. Tonga described how established relationships enabled rapid assistance when its health system was attacked, characterising this as what CBMs look like when they work . Vanuatu drew on the analogy of rapid state-to-state communication during physical emergencies such as cyclones as a model for digital emergencies . Australia highlighted its Cyber Rapid Assistance for Pacific Incidents and Disasters programme as an example of building trust and habits of trust before a crisis .
Cuba and the Dominican Republic both offered nuanced perspectives on the limitations of CBMs, emphasising that they are not sufficient on their own. Cuba argued that CBMs do not guarantee the strictly peaceful use of ICTs and are complementary to binding norms, with the voluntary nature of CBMs needing to prevail [191, 194, 198-199]. The Dominican Republic drew on regional experience to argue that CBMs are tools of preventive diplomacy rather than real-time response mechanisms, with bilateral technical direct cooperation proving key during an actual ransomware crisis . Both speakers thus cautioned against over-reliance on CBMs as standalone solutions.
Developing countries and small island developing states shared a common view that financial and technical support mechanisms are needed to ensure equitable access to capacity building. The African Group called for a Voluntary UN ICT Security Capacity Building Fund and a UN ICT Security Fellowship Programme with particular attention to least developed countries and small island developing states . CARICOM emphasised that capacity building efforts must remain accessible to all developing countries . Iraq stressed that capacity building should receive financial and technical support so that equal opportunities are available to all states . Tuvalu called for a shift from short-term external consulting to long-term training of local technical teams .
It was somewhat unexpected that Cuba and Thailand, states that might not always be expected to align, both independently argued that the substantive dialogue within the global mechanism itself constitutes a confidence-building measure. Cuba stated that ensuring information exchange and dialogue on the use of ICTs and international security in the global mechanism is in itself a CBM . Thailand similarly considered the substantive dialogue within the OEWG and the ongoing discussion in the global mechanism to be constructive CBMs in themselves . This meta-level argument about the process being part of the outcome represents an interesting area of convergence across different geopolitical perspectives.
It was unexpected that Russia and Germany, states with significant geopolitical tensions, both raised concerns about misuse or ineffective use of the POC Directory, albeit from opposite perspectives. Russia reported that only around 48% of its inquiries were responded to, attributing some of this to political reasons , while Germany reported receiving repetitive, identical messages from a certain state that did not take into account its replies . Although each state was implicitly or explicitly pointing at the other, both agreed that the directory was not being used as intended in some cases. Australia reinforced this by calling for clear expectations of good faith use and proportionate, purposeful requests . This convergence on the need for better norms around directory use, despite coming from very different political positions, represents an unexpected area of agreement.
Both Vanuatu and Tonga drew on their experience with physical disasters as a model for cyber incident cooperation, which was an unexpected and distinctive contribution to the discussion. Vanuatu noted that when disaster strikes its islands, information flows between governments within hours, and that this habit of rapid, trusted state-to-state communication in physical emergencies is precisely the habit the CBM agenda seeks to create for digital ones . Tonga similarly drew on its experience with the Pacific Cyber Security Operational Network, where relationships built through physical emergency cooperation translated into effective cyber incident response . This framing of physical disaster cooperation as a template for cyber cooperation was a distinctive Pacific perspective not raised by other regions.
Cuba and the African Union Commission, from quite different political perspectives, both argued that regional CBMs should not be treated as universal models. Cuba stated that each region or sub-region has unique characteristics and that measures implemented at these levels cannot be considered single global models or benchmarks . The African Union Commission similarly stated that its ambition is not to reproduce existing models but to set out concrete, adapted measures adapted to African realities . This convergence between a state known for its emphasis on sovereignty and non-interference and a regional organisation seeking to develop its own adapted approach represents an unexpected alignment on the importance of contextual adaptation.
The discussion revealed a very high level of consensus across geographically and politically diverse delegations on the fundamental importance of CBMs as practical tools for reducing misunderstanding, escalation and conflict in cyberspace. There was near-universal agreement on the value of the Global POC Directory as a flagship achievement, the need for it to be actively maintained and used in good faith as a complement to existing channels, and the importance of capacity building as a cross-cutting priority. Regional organisations were widely recognised as playing a vital role in advancing CBMs, with their experiences seen as valuable inputs for global implementation. The DTGs were broadly supported as platforms for practical, action-oriented work rather than procedural negotiation. Stakeholder engagement from the private sector, civil society, academia and the technical community was also widely endorsed. Areas of nuance included the limitations of CBMs as standalone tools (Cuba, Dominican Republic), practical challenges with the POC Directory's functioning (Russia, Germany, Australia), and the need to avoid treating regional CBMs as universal models (Cuba, African Union Commission). The distinctive Pacific perspective on physical disaster cooperation as a model for cyber incident cooperation was an unexpected contribution. Developing countries and small island developing states consistently emphasised the need for financial and technical support mechanisms, long-term capacity building investment and hybrid participation modalities to ensure inclusive participation.
The Russian Federation views the POC Directory as the primary practical outcome of the OEWG and reports that around 48% of its 2,576 inquiries were responded to, attributing low response rates to dead contacts and political obstruction . Russia calls for a separate agenda item to discuss directory improvements and urges all states to join . By contrast, Germany explicitly reported receiving repetitive, identical messages from a certain state that did not take into account its replies, characterising this as not in line with the purpose of the directory . The Netherlands and Ireland both emphasised that the directory should be a complementary tool to existing channels, not a replacement . Vanuatu highlighted the burden placed on small administrations that must operate multiple channels at once . Australia stressed that requests must be proportionate and purposeful, and that the directory should not be used to overwhelm national points of contact . These positions reflect a fundamental tension between states that wish to use the directory as a primary communication mechanism and those that insist it must remain strictly supplementary.
Challenges with dead contacts and misuse of the directory – The directory faces challenges including dead contacts, misinterpretation of objectives of technical POCs, and cases where capitals ignore requests for political reasons; around 48% of Russia's inquiries were responded to (Russian Federation)
Concerns about repeated, bad-faith use of the directory – Germany reported receiving repetitive, identical messages from a certain state that did not take into account replies, which is not in line with the purpose of the UN POC Directory and does not represent responsible or sincere use (Germany)
POC Directory as complementary to, not replacing, existing channels – The strength and added value of the POC Directory are found in establishing lines of contact where these previously were unavailable or unclear; it should be a complementary tool, not a replacement for existing POC networks (Netherlands)
POC Directory as a complement, not replacement, to existing channels – The POC Directory should be used as a complement to existing channels of communication between states, not as a replacement or duplication of established diplomatic or technical channels (Ireland)
Need for coherence across multiple communication channels – The international community is multiplying its channels of communication; Vanuatu requests that the directory be developed in deliberate awareness of the wider ecosystem, with clear guidance on which channels serve which purpose (Vanuatu)
Need for the directory to be actively maintained and tested – For the POC Directory to remain useful, it should be actively maintained, regularly tested, and supported by clear expectations of good faith use; requests should be proportionate and purposeful (Australia)
This tension is evident in OEWG records, where some delegations called for proactive use of the Directory for information exchange while others emphasised its supplementary nature [S168]. The formal framework envisages differentiated diplomatic and technical roles [S161], but the boundary between proactive and reactive use remains contested.
Cuba explicitly stated that CBMs on their own do not guarantee the strictly peaceful use of ICTs and that they are merely complementary to binding norms, emphasising that the voluntary nature of CBMs must prevail and that different phases of confidence building must respect sovereignty and non-interference . Cuba also stressed that the establishment of binding norms within the UN framework is one of the pillars for international confidence building . In contrast, Israel, Germany and the Netherlands focused on the value of voluntary CBMs as practical tools for de-escalation and trust-building without explicitly calling for binding norms . Germany specifically stated that any CBM should avoid entering the field of expectations or even obligations , suggesting a preference for keeping CBMs strictly voluntary rather than moving towards binding frameworks.
CBMs as complementary to binding norms – CBMs on their own do not guarantee the strictly peaceful use of ICTs; they are complementary to binding norms and must respect sovereignty and non-interference in internal affairs (Cuba)
CBMs as practical tools for de-escalation – CBMs allow states to build practical procedures during peacetime that can be directly utilised for de-escalation, communication and risk reduction during geopolitical crises (Israel)
CBMs as voluntary and action-oriented cyber diplomacy tools – CBMs are action-oriented voluntary cyber diplomacy tools at the discretion of states that can help reduce tensions and the risk of miscalculation (Germany)
Developing national positions on international law in cyberspace – The Netherlands encourages all member states and regional organisations to continue to develop national positions on how international law applies in cyberspace and make these views available to a wider public, to avoid miscommunication and miscalculation (Netherlands)
Cuba explicitly cautioned that regional or sub-regional CBM measures cannot be considered single global models or benchmarks, given that each region has unique characteristics . The African Union Commission similarly stated that its ambition is not to reproduce existing models but to set out concrete measures adapted to African realities . However, Ghana and the OSCE presented their regional frameworks as practical examples that could inform global implementation , and the Dominican Republic drew on OAS experience to offer lessons for the global mechanism . This creates a tension between those who wish to draw on regional experience as a source of global learning and those who resist the imposition of any regional model as a universal standard.
Regional CBMs should not be treated as single global models – Each region or sub-region has unique characteristics, and measures implemented at these levels cannot be considered single global models or benchmarks (Cuba)
ECOWAS regional framework as a practical example – ECOWAS has developed a regional framework on cyber ICT confidence-building measures with Ghana's participation, establishing practical mechanisms including national diplomatic and technical points of contact (Ghana)
OSCE as the first regional organisation to develop cyber CBMs – The OSCE was the first regional organisation to develop cyber confidence-building measures and has many years of experience in practical implementation of its 16 CBMs, including through the Adopt-a-CBM initiative (OSCE)
African Union developing adapted CBMs for African realities – The African Union Commission is developing concrete measures adapted to African realities that can be effectively implemented in the various regions of the continent, drawing on experience from economic and regional committees (African Union Commission)
CBMs as preventive diplomacy tools – CBMs are preventive diplomacy tools, not necessarily mechanisms actionable in real time to respond to incidents; bilateral technical direct cooperation is key during actual crises (Dominican Republic)
Russia envisions the directory as an tool for professional, non-politicised contacts between specialists, and calls for standardised communication templates and in-person meetings of POC representatives . Cameroon similarly envisions the directory evolving into a dynamic instrument for cooperation with progressively enhanced functionalities . However, Germany’s experience of receiving repetitive, identical messages that were not responsive to its replies illustrates the risk of the directory being used in ways that strain rather than build trust . Australia explicitly warned that the directory should not be treated as a mechanism for overwhelming national points of contact or creating unreasonable expectations of response , suggesting a more cautious and limited scope for its use.
Need for standardised communication templates – A priority task is to finalise a standardised communication template to simplify cooperation between POCs by clearly defining the information needed for analysis of attacks and incidents (Russian Federation)
Need for the directory to be actively maintained and tested – For the POC Directory to remain useful, it should be actively maintained, regularly tested, and supported by clear expectations of good faith use; requests should be proportionate and purposeful (Australia)
Concerns about repeated, bad-faith use of the directory – Germany reported receiving repetitive, identical messages from a certain state that did not take into account replies, which is not in line with the purpose of the UN POC Directory and does not represent responsible or sincere use (Germany)
POC Directory as a dynamic instrument for cooperation – The directory should evolve from a repository of contacts into a dynamic instrument for cooperation, with functionalities progressively enhanced to facilitate secure communication and voluntary information exchange (Cameroon)
Germany and France emphasised responsible use of the POC Directory and learning from regional examples [S170], while the 9th substantive OEWG session discussions reflected calls for more proactive and standardised use [S168]. This divergence reflects an unresolved question about the Directory’s operational mandate.
Argentina expressed hope that the DTGs would establish themselves as spaces for technical work capable of producing substantive recommendations and decisions on CBMs for consideration by the plenary, envisioning a process where recommendations are subsequently reviewed, fine-tuned and negotiated by states . The Pacific Islands Forum, speaking through Tonga, explicitly warned that DTGs should not become additional negotiating rooms that reproduce the same procedural disagreements or simply repeat plenary discussions, with their value to be measured by whether they help countries make progress . Russia called for a separate agenda item in the global mechanism’s programme of work for discussing issues related to supporting and improving the POC directory , suggesting a preference for more formal, structured deliberation. These positions reflect differing visions of whether the DTGs should be action-oriented technical forums or quasi-negotiating spaces.
DTGs should lead to practical outcomes and recommendations – Argentina hopes DTGs will establish themselves as spaces for technical work able to establish substantive recommendations and decisions on CBMs for consideration by the plenary, progressively working towards more interactive, results-focused dialogue (Argentina)
DTGs should focus on practical, technical work rather than procedural disagreements – DTGs should be used to identify needs, share practical experience, connect states with relevant expertise, and help match national and regional priorities with appropriate support, not become additional negotiating rooms (Tonga on behalf of Pacific Islands Forum)
Need for universal participation in the directory – 125 states have joined the directory, which is positive, but all remaining member states should join by designating appropriate diplomatic and technical points of contact (Russian Federation)
Plenary discussions reflected a broad preference for DTGs as practical, action-oriented forums rather than negotiating bodies [S155][S157], yet the tension between producing actionable recommendations and avoiding formal negotiation remains present in the design of the global mechanism [S148].
While the POC Directory was designed as a non-politicised, technical communication tool, the statements of Russia and Germany revealed an unexpected and direct implicit conflict over its use. Russia reported that around 48% of its 2,576 inquiries were responded to, attributing low response rates partly to cases where capitals ignore requests for political reasons, specifically targeting countries that make unsubstantiated accusations regarding computer attacks . Germany, without naming Russia explicitly, reported receiving repetitive, identical messages from a certain state that did not take into account its replies, characterising this as clearly not in line with the purpose of the directory . This exchange was unexpected because the directory was intended to foster professional, non-politicised contacts , yet the statements of both delegations revealed that geopolitical tensions are already manifesting within this supposedly technical mechanism, undermining its foundational premise.
Cuba and Thailand both argued that the substantive dialogue within the global mechanism is itself a confidence-building measure , which was an unexpected framing not shared by most other delegations. Cuba used this argument to emphasise that dialogues must be conducted with mutual respect and consideration for the diversity of positions , which could be read as a caution against pressure to adopt specific CBM frameworks. Israel, by contrast, focused on the need for the DTGs to prioritise further developing and operationalising concrete CBMs , implying that dialogue alone is insufficient and that tangible outputs are needed. This disagreement over whether process itself constitutes a CBM was unexpected and has implications for how the mechanism’s success should be measured.
While there was broad support for the POC Directory, an unexpected tension emerged between small island developing states and larger states over the practical burden the directory places on small administrations. Vanuatu explicitly noted that it speaks from the standpoint of administrations that must operate all channels at once, often through the same handful of officials , and requested clear guidance on which channels serve which purpose to avoid duplication . Tonga similarly noted that small states do not maintain wide networks of diplomats tasked with cyber-related cooperation . Australia acknowledged this by calling for requests to be made with due regard to the capacity constraints of smaller states . However, Russia called for universal participation and urged all remaining states to join the directory , without explicitly addressing the capacity burden this places on small states. This tension was unexpected given the general consensus on the directory’s value.
Iran proposed two new CBMs for consideration by the first DTG: facilitating access by all states to ICT security products and tools, and developing a consolidated list of technical terms used in OEWG reports . This was unexpected because most other delegations, including Germany, Israel and Australia, focused exclusively on implementing the existing eight agreed CBMs rather than expanding the list. Germany explicitly stated that at a minimum, any CBM existing or re-proposed should fulfil criteria of being concrete, action-oriented and voluntary, and should avoid entering the field of expectations or even obligations , which could be read as a cautious response to proposals for new measures. Australia similarly focused on making agreed CBMs operational . This divergence over whether to expand or consolidate the CBM framework was not widely anticipated.
The discussion revealed a broadly cooperative atmosphere with strong consensus on the importance of CBMs and capacity building as pillars of the framework for responsible state behaviour. However, significant disagreements emerged beneath this surface consensus, particularly around: (1) the appropriate use and scope of the POC Directory, with an implicit but pointed conflict between Russia and Germany over good-faith use ; (2) whether CBMs should remain strictly voluntary or be complemented by binding norms, with Cuba taking a distinct position ; (3) the role of regional models in informing global CBM frameworks, with tension between those who see regional experience as universally instructive and those who resist any single model ; (4) the nature and mandate of the DTGs, with disagreement over whether they should produce negotiated outcomes or remain technical exchange forums ; and (5) the burden placed on small island developing states by multiplying communication channels . Capacity building discussions were more consensual in principle but diverged on modalities, funding responsibilities and the role of the multi-stakeholder community .
All these speakers agreed that the POC Directory should not replace existing communication channels and that coherence across multiple mechanisms is essential [13-17, 147-149, 76-77, 471-473, 218-221, 41-42]. However, they disagreed on the implications: Vanuatu focused on the administrative burden on small states operating multiple channels simultaneously , while Germany and Australia raised concerns about misuse and disproportionate use of the directory [473-474, 219-221]. The Netherlands and Ireland framed the issue as one of complementarity and added value [147-149, 76-77], whereas Israel emphasised the need for harmonisation across multilateral forums more broadly .
Need for coherence across multiple communication channels – The international community is multiplying its channels of communication; Vanuatu requests that the directory be developed in deliberate awareness of the wider ecosystem, with clear guidance on which channels serve which purpose (Vanuatu) POC Directory as complementary to, not replacing, existing channels – The strength and added value of the POC Directory are found in establishing lines of contact where these previously were unavailable or unclear; it should be a complementary tool, not a replacement for existing POC networks (Netherlands) POC Directory as a complement, not replacement, to existing channels – The POC Directory should be used as a complement to existing channels of communication between states, not as a replacement or duplication of established diplomatic or technical channels (Ireland) POC Directory as complementary to, not replacing, existing channels – The POC Directory is designed as a voluntary practical tool at the discretion of states; it should not replace established channels such as FIRST, the network of CERTs, or other diplomatic channels (Germany) Need for the directory to be actively maintained and tested – For the POC Directory to remain useful, it should be actively maintained, regularly tested, and supported by clear expectations of good faith use; requests should be proportionate and purposeful (Australia) Global mechanism should harmonise with other multilateral and regional forums – The global mechanism’s work should prioritise harmonising with other multilateral and regional forums and ensure that all outcomes are mutually reinforcing (Israel)
All speakers agreed that capacity building is a cross-cutting priority essential for implementing the framework for responsible state behaviour, and that it must be demand-driven, nationally owned and sustainable [692-694, 609-612, 672, 647-651, 759-760, 747-748]. However, they diverged on emphasis and modality: the African Group and Latin American group stressed the need for a dedicated DTG2 as the main platform [685-687, 672], while the EU highlighted its own significant financial investment and the role of the multi-stakeholder community in design and delivery . Colombia emphasised South-South and triangular cooperation as particularly valuable modalities , while Iraq focused on the need for financial and technical support to ensure equal opportunities . These differences reflect varying perspectives on who should lead and fund capacity building efforts.
Capacity building must be demand-driven, nationally owned and sustainable – Effective capacity building must be demand-driven, nationally owned, sustainable, and tailored to the specific needs and priorities of countries, respecting national sovereignty (NIgeria on behalf of African Group) Capacity building as foundational to all aspects of the mechanism’s work – Capacity building is the enabler that underpins all aspects of the work; it is foundational to responding to threats, implementing norms, engaging meaningfully in international law discussions, and sustaining CBMs (Tonga on behalf of Pacific Islands Forum) DTG2 as the main platform for capacity building dialogue – The DTG on capacity building must be established as the main platform for dialogue on this issue within the global mechanism, playing a fundamental role as a space for strategic coordination to facilitate information exchange and articulate synergies (Chile Representative on behalf of Latin American group) EU investment in cybercapacity building globally – The EU is working with partners on 27 projects with a value of 100 million euros and will continue to invest, recognising capacity building as an essential pillar of security and stability in cyberspace (European Union) South-South and triangular cooperation as valuable modalities – Modalities like South-South cooperation and triangular cooperation can play a particularly valuable role in capacity building, facilitating the exchange of knowledge and good practices while taking account of local realities and priorities (Colombia) Capacity building requires financial and technical support for equal opportunities – Capacity building should get financial and technical support so that equal opportunities are available to all states to benefit from international programmes and initiatives, with special attention to developing countries and countries emerging from conflict (Iraq)
All these speakers agreed that stakeholders from the private sector, civil society, academia and the technical community have an important role to play in CBM implementation and capacity building [82, 229, 621-625, 654, 114-115, 145-146]. However, they differed on the extent and nature of that role: the Pacific Islands Forum called for the fullest possible use of expert briefings within DTGs and improvements to accreditation and participation modalities , while Australia and Ireland emphasised preserving the intergovernmental nature of decision-making [229, 82]. Cuba, though not listed here, implicitly resisted broader stakeholder roles by emphasising state sovereignty and non-interference . The EU focused on coordination and avoiding duplication in stakeholder-delivered capacity building .
Expertise of stakeholders should play a strong role – The expertise and experience of stakeholders from academia, the technical community, civil society and the private sector should play a strong role in the CBM implementation process, with practical tools and best practices feeding engagement (Ireland) Industry and technical community closest to vulnerabilities and risks – Industry and the technical community, civil society and academia are often closest to vulnerabilities, incidents and emerging risks; their expertise can help states understand threats, improve prevention and response, and translate CBMs into practical action (Australia) Stakeholder engagement essential for capacity building – Meaningful capacity building depends on access to the expertise of the multi-stakeholder community, academia, civil society, the private sector and the technical community; stakeholders must be substantively included in both formal and informal settings (Tonga on behalf of Pacific Islands Forum) Multi-stakeholder community role in designing and delivering capacity building – The role of the multi-stakeholder community in the design and delivery of cybercapacity building should be further discussed, recognising that industry, civil society and academia contribute meaningfully to effective and sustainable capacity building (European Union) Public-private partnerships essential for critical infrastructure protection – Given that a significant part of critical information infrastructure is operated by non-governmental actors or is part of the supply chain, public-private partnerships are essential to strengthen prevention, early alerts and fighting malicious information (Uruguay) Need for simulation exercises within DTGs – In simulation exercises within DTGs, states could see how public-private partnerships could concretely benefit an open, free and secure cyberspace and help prevent and address incidents (Netherlands)
African delegations broadly agreed that regional organisations play a decisive role in CBM implementation and that global efforts should strengthen rather than duplicate regional mechanisms [87-93, 236-237, 553-556, 343, 177-178, 480]. However, they differed on the degree of autonomy for regional approaches: the African Union Commission explicitly stated it does not wish to reproduce existing models , while Ghana and the African Group pointed to ECOWAS as a model that could inform global implementation [236-237, 87-93]. Cameroon focused on avoiding duplication , while Botswana and Mozambique emphasised the need for concrete national and regional mechanisms tailored to developing country realities [177-178, 480].
Regional organisations play an important role in advancing CBMs – The global mechanism should strengthen coordination and complementarity between global and regional confidence-building initiatives and promote linkages between regional POC networks and the global directory (NIgeria on behalf of African Group) ECOWAS regional framework as a practical example – ECOWAS has developed a regional framework on cyber ICT confidence-building measures with Ghana’s participation, establishing practical mechanisms including national diplomatic and technical points of contact (Ghana) African Union developing adapted CBMs for African realities – The African Union Commission is developing concrete measures adapted to African realities that can be effectively implemented in the various regions of the continent, drawing on experience from economic and regional committees (African Union Commission) Avoiding duplication between global and regional mechanisms – The global mechanism should facilitate exchanges of experience among member states and regional organisations through workshops and knowledge-sharing initiatives, avoiding duplication of what already functions elsewhere (Cameroon) Botswana’s CERT and national cybersecurity strategy for critical infrastructure – Botswana has operationalised its national cybersecurity strategy and established the Botswana Computer Incident Response Team to coordinate incident management, issue threat advisories and safeguard national critical infrastructure (Botswana) CBMs as practical tools reducing misunderstanding – For developing countries, CBMs should move beyond political commitments and translate into concrete mechanisms that strengthen confidence, reduce the risk of misunderstanding and miscalculation, and improve collective resilience against cyber threats (Mozambique)
Latin American delegations broadly agreed on the value of DTGs for exchanging national and regional experiences and on the importance of building on existing regional mechanisms such as the OAS [123-124, 32-33, 517-523, 112-113]. However, they differed on the nature of CBMs: the Dominican Republic drew a sharp distinction between CBMs as preventive diplomacy tools and real-time crisis response mechanisms, arguing that bilateral technical cooperation was key during actual incidents , while Argentina and Chile focused more on the operationalisation of CBMs through the DTGs without drawing this distinction as sharply [123-124, 32-33]. Uruguay emphasised the OAS experience as a practical model , while the Dominican Republic highlighted lessons learned from ransomware incidents in the region .
DTG1 for operationalising CBMs and DTG2 for capacity building support – DTG1 could examine operationalisation of CBMs by exchanging national and regional experiences, while DTG2 could identify capacities required to support this operationalisation effort (Argentina) DTGs as platforms for exchanging national experiences and good practices – The dedicated thematic groups offer a valuable opportunity to go into further depth on international relations and the role of international organisations in effective implementation of CBMs, exchanging national experiences and good practices (Chile) CBMs as preventive diplomacy tools – CBMs are preventive diplomacy tools, not necessarily mechanisms actionable in real time to respond to incidents; bilateral technical direct cooperation is key during actual crises (Dominican Republic) OAS regional experience as a model for CBM implementation – Regional experience in the OAS shows the practical value of CBMs; Uruguay has designated and updated its technical contact points in the OAS framework since 2018 and participates in cooperation mechanisms such as CERT Americas (Uruguay)
-
Confidence-Building Measures (CBMs) are widely recognised as indispensable tools for fostering trust, transparency, predictability and cooperation among states, contributing to international peace and security in cyberspace. There was broad consensus across all regional groups on their fundamental importance.
-
The Global Points of Contact (POC) Directory was identified as the flagship practical achievement of the Open-Ended Working Group (OEWG), with 125 states having joined. However, delegates acknowledged it faces significant operational challenges including dead contacts, low response rates (Russia reported approximately 48% of its inquiries were responded to), and instances of bad-faith or politically motivated non-responses.
-
There was strong consensus that CBMs are preventive diplomacy tools rather than real-time incident response mechanisms. The Dominican Republic highlighted from regional experience that bilateral technical direct cooperation is key during actual crises, with CBMs serving to build the trust that enables such cooperation.
-
The Dedicated Thematic Groups (DTGs) were broadly supported as the primary vehicles for translating agreed CBMs into practical action, with DTG1 focused on operationalising CBMs and DTG2 focused on capacity building. Multiple delegations emphasised these groups should produce practical, action-oriented outcomes rather than reproducing procedural disagreements from plenary sessions.
-
Regional organisations — including the OSCE, ECOWAS, OAS, ASEAN, African Union, and Pacific Islands Forum mechanisms — were consistently highlighted as valuable repositories of practical experience in CBM implementation that should inform and complement global-level work, with strong calls to avoid duplication.
-
Capacity building was identified as a cross-cutting enabler underpinning all pillars of the framework for responsible state behaviour, not merely a standalone pillar. It was described as the bridge between political commitments and practical implementation, particularly for developing countries, small island developing states, and least developed countries.
-
The POC Directory must be used in good faith and as a complement to — not a replacement for — existing diplomatic channels, regional mechanisms, and state-to-state engagement. Germany explicitly reported instances of repeated, identical, bad-faith requests from a specific state that did not take into account replies, which it characterised as inconsistent with the directory’s purpose.
-
Stakeholder engagement from the private sector, civil society, academia and the technical community was broadly supported as essential to effective CBM implementation and capacity building, while preserving the intergovernmental nature of decision-making.
-
Coherence across the expanding ecosystem of communication channels and mechanisms was identified as a priority concern, particularly for small states with limited officials managing multiple parallel channels simultaneously.
-
Inclusive participation — including through hybrid modalities, equitable meeting scheduling, multilingualism, and meaningful engagement of women and youth — was identified as a structural prerequisite for an effective global mechanism.
“Vanuatu’s observation that ‘confidence is not built by the number of channels that exist, or the volume of requests within them, but by the certainty of what happens when one is used.’ They also drew a compelling analogy between disaster response communication habits and cyber incident response, arguing that ‘a region accustomed to cooperating through cyclones is well-placed to cooperate through cyber incidents.’”
“Tonga’s statement: ‘When our health system was attacked last year, established relationships with partners enabled rapid assistance and ultimately a joint public attribution with Australia and New Zealand. This is what confidence building measures look like when they work. Relationships built before the crisis, exercised during it and deepened after it.’ Tonga also urged the mechanism to ‘keep the CBM agenda modest in rhetoric and ambitious in practice.’”
“The Russian Federation’s detailed statistical disclosure: ‘There were 2,576 inquiries [to Russian POCs last year]. Out of those, around 48% of them were responded to.’ The Russian delegation attributed this to ‘dead contacts,’ misdesignation of technical POCs, and cases where ‘certain capitals simply ignore our requests for political reasons.’ Russia also called for a separate agenda item dedicated to POC directory governance.”
“Germany’s disclosure that its technical POC ‘continued receiving repeated identical requests from the same sender, whilst not taking into account our replies,’ characterising this as ‘clearly not in line with the purpose of the UN POC directory and does not present a responsible or sincere use of the directory.’”
“The Dominican Republic’s frank assessment: ‘CBMs are preventive diplomacy tools, they are not necessarily mechanisms that are actionable in real time to respond to incidents.’ They also called for transparency in POC directory response metrics, arguing this ‘would reflect the real results of implementation and the real commitment of each and every one of the parties.’”
“Côte d’Ivoire’s recommendation to ‘promote a culture of restraint and responsibility,’ specifying that ‘when incidents happen, states must prioritize consultations, the exchange of information, and a rigorous establishment of the facts while avoiding any premature accusations that might fuel escalation.’”
“Australia’s nuanced warning that the POC directory ‘should not be treated as a mechanism for overwhelming national points of contact, creating unreasonable expectations of response, or as a substitute for existing procedures where other channels are more appropriate,’ and that requests ‘should be proportionate, purposeful’ and made ‘with due regard to the capacity constraints of smaller states.’”
“Iran’s proposal that the global mechanism ‘prepare a consolidated list of technical terms used in the consensus-based reports of the OEWG and subsequently undertake discussions to develop common understandings of key concepts such as ICTs, ICT infrastructure, ICT environment and malicious use of ICTs,’ and that access to ICT security products and tools be recognised as a new CBM.”
“Tuvalu’s call for ‘an explicit CBM — a commitment from all member states and stakeholders to share best practice to safeguard [subsea cable] essential digital lifeline from both natural hazard and malicious cyber threats,’ and their framing of ‘capacity sovereignty’ as requiring ‘long-term training of our own local technical teams’ rather than ‘short-term external consulting.’”
“Costa Rica’s warning that ‘without capacities, we run the risk of building a legally elegant infrastructure that is operationally useless,’ and their argument that ‘legal interpretation also requires specialised institutional capacities’ including the ability to ‘evaluate incidents, establish national positions on the application of international law to cyberspace, to understand the different legal thresholds.’”
How can the Global Points of Contact Directory be developed with deliberate awareness of the wider ecosystem of communication channels, including the 24/7 network under the UN Convention against Cybercrime and existing third-party relationships?
Vanuatu raised the concern that small administrations must operate multiple communication channels simultaneously, often through the same handful of officials. Clarifying which channel serves which purpose and avoiding duplication is essential for practical implementation, particularly for smaller states.
How can the habit of rapid, trusted state-to-state communication developed during physical emergencies (e.g., cyclones) be formally connected to and reinforced by cyber incident response frameworks?
Vanuatu observed that Pacific states already cooperate effectively during natural disasters and suggested this existing culture of cooperation could be leveraged for cyber incidents. Further research into how emergency communication habits translate to digital contexts could yield practical CBM models.
What are the most effective modalities for regular communications exercises for the Global POC Directory, and how should training for designated officials be structured to ensure continuity when personnel change?
Multiple delegations highlighted that the directory’s value depends on trained, points of contact. Understanding how to design exercises and training programmes that account for staff turnover and varying national capacities is a key operational gap.
How can the Dedicated Thematic Groups (DTGs) best facilitate the exchange of national experiences and regional good practices on CBM implementation, particularly regarding contact point mechanisms, diplomatic and technical consultations, and voluntary incident information exchange?
Several delegations identified the DTGs as the primary vehicle for operationalising CBMs but noted that their structure and focus need to be clearly defined to avoid duplicating plenary discussions and to produce substantive, actionable recommendations.
How should the Global Mechanism harmonise its CBM work with other multilateral and regional forums (e.g., OECD, Council of Europe, Mediterranean Partnerships) to ensure mutually reinforcing outcomes?
Israel stressed the need for coherence across multilateral and regional bodies. Further research is needed on how to map existing CBM frameworks and identify overlaps, gaps, and opportunities for alignment without creating conflicting obligations.
What practical mechanisms can be established to promote a culture of restraint and responsibility among states when cyber incidents occur, including prioritising consultation and rigorous fact-finding before making public attributions?
Several delegations warned that premature or unsubstantiated political attributions of cyber attacks can escalate tensions. Research into norms and procedures for responsible attribution and restraint is needed to complement existing CBMs.
How can simulation exercises involving points of contact, national CERTs, and relevant authorities be regularly organised under UN auspices, and what format would be most effective for different regional contexts?
Multiple delegations called for regular simulation exercises as a practical CBM, but the design, frequency, and inclusivity of such exercises remain open questions requiring further development and research.
What are the specific metrics and response rates for the Global POC Directory, and should these be made publicly available to improve transparency and accountability?
The Dominican Republic called for sharing response metrics to reflect real implementation results and commitment. The Russian Federation provided statistics showing approximately 48% response rates to its POC inquiries. Understanding the causes of non-response and how to improve them is a critical area for further investigation.
How can ‘dead contacts’ in the Global POC Directory be identified and resolved, and what notification mechanisms should be established to inform states of ping test results?
The Russian Federation identified dead contacts and misdesignation of technical POCs as significant operational problems. Developing a systematic process for identifying, notifying, and resolving inactive or incorrectly designated contacts is essential for the directory’s effectiveness.
What should a standardised communication template for the Global POC Directory contain, particularly to meet the distinct needs of diplomatic versus technical points of contact?
The Russian Federation noted that a draft template was presented by UNODA but not fully discussed before the OEWG’s final report. Thailand suggested incorporating urgency and confidentiality elements. Further deliberation on the template’s content and format is needed.
How can in-person meetings of POC representatives be organised, and what would be the most effective format and frequency for such gatherings?
The OEWG final report envisaged in-person meetings of POC representatives, but the modalities for such meetings have not been determined. Research into how other international POC networks (e.g., OSCE) organise such meetings could inform this process.
How should the Global Mechanism address cases where states ignore POC directory requests for political reasons, and what norms of good faith use should be established?
Both the Russian Federation and Germany reported instances of bad faith or politically motivated non-engagement with the directory. Establishing clear expectations and norms for responsible use of the directory is an unresolved issue requiring further discussion.
Should a new confidence-building measure be developed to facilitate access by all states to ICT security products and tools, and how would this interact with existing CBMs and capacity-building efforts?
Iran highlighted a proposal from the OEWG final report (paragraph 47k) for a new CBM on access to ICT security products and tools. Whether and how to incorporate this into the existing eight voluntary CBMs requires substantive discussion in the DTGs.
Could the Global Mechanism prepare a consolidated list of technical ICT terms and develop common understandings of key concepts such as ‘ICTs’, ‘ICT infrastructure’, ‘ICT environment’, and ‘malicious use of ICTs’?
Iran referenced paragraph 52 of the OEWG final report encouraging voluntary sharing of national views on technical terminology. A lack of common definitions can impede cooperation and mutual understanding; developing shared terminology is a foundational research and policy task.
How can regional CBM frameworks (e.g., ECOWAS, OAS, ASEAN, OSCE, African Union) be better integrated with the Global POC Directory and the global CBM framework to avoid duplication and maximise coherence?
Multiple delegations and regional organisations highlighted the risk of fragmentation and duplication between regional and global CBM mechanisms. Research into how to map, align, and institutionalise linkages between these frameworks is a priority.
How can capacity building and confidence building be better integrated as mutually reinforcing pillars, ensuring that states have the institutional, technical, and human resource foundations needed to implement CBMs effectively?
Several delegations noted that many states cannot implement CBMs without first receiving capacity-building support. Research into how to sequence and link these two pillars in practice, particularly for developing countries, is essential.
What role should academia, the technical community, civil society, and the private sector play in the design and delivery of CBMs and capacity-building activities, and how can their participation be structured within the intergovernmental nature of the mechanism?
Multiple delegations stressed the value of multi-stakeholder expertise but also the need to preserve the state-led nature of the process. Defining appropriate modalities for stakeholder engagement in both DTGs and plenary sessions is an open question.
How can the POC Directory be used to build trust rather than strain it, and what guidelines should govern proportionate and purposeful use of the directory, particularly with regard to the capacity constraints of smaller states?
Australia warned against overwhelming smaller states’ POCs with disproportionate requests, while Germany reported receiving repetitive, identical messages. Developing clear guidelines for responsible and proportionate use of the directory is a pressing operational need.
How can cooperation on vulnerability disclosure, mitigation, and supply chain integrity be operationalised as practical CBMs, and what role can the Global Mechanism play in facilitating this?
Australia highlighted vulnerability disclosure and supply chain integrity as practical CBMs that could reduce risk and build resilience. Further research into how these can be structured as voluntary, implementable measures within the global framework is needed.
How can the Western Balkans Cyber Diplomacy Network and similar sub-regional initiatives serve as models for building cyber confidence in other regions, and what lessons can be drawn for the global mechanism?
Bosnia and Herzegovina highlighted the 2025 launch of the Western Balkans Cyber Diplomacy Network as a regional CBM initiative. Studying its design and early outcomes could provide transferable lessons for other regions and for the global mechanism.
How can the African Union’s continental CBM framework be developed in a way that is adapted to African regional realities rather than reproducing existing models, and how should it be integrated with global efforts?
The African Union Commission stated its ambition to develop concrete, adapted CBMs suited to African realities rather than copying existing frameworks. Research into what specific measures would be most effective and implementable across Africa’s diverse sub-regions is needed.
How should the OSCE’s ‘Adopt-a-CBM’ initiative and its annual meetings of technical and policy points of contact be used as models or inputs for the Global Mechanism’s CBM implementation approach?
The OSCE shared extensive experience with its 16 CBMs and the Adopt-a-CBM initiative, where 26 participating states have adopted nine CBMs. Examining how this model could be adapted for the global mechanism’s broader and more diverse membership is a valuable area for further research.
How can inter-regional cooperation between regional organisations on cyber CBMs be institutionalised, and what role should a formal dialogue mechanism between the Global Mechanism and regional organisations play?
The OSCE referenced a non-paper on inter-regional cooperation submitted by Switzerland in 2024. The African Union Commission called for institutionalised technical dialogue between the global mechanism and regional organisations. Developing a formal framework for this cooperation is an unresolved structural question.
How can youth be meaningfully included in CBM discussions and activities, and what specific mechanisms (e.g., structured dialogues, youth-led initiatives, cross-border exchanges) would be most effective?
The DMUN Foundation highlighted that young people are among the most affected by cyber incidents yet are rarely included in CBM discussions. Research into effective models for youth engagement in international cybersecurity governance is needed.
How can the Global Mechanism ensure that capacity-building efforts are demand-driven, nationally owned, and sustainable rather than supply-driven or short-term, and what assessment tools (e.g., cybersecurity capacity maturity models) should be used to measure progress?
Multiple delegations stressed that capacity building must be tailored to national needs and priorities rather than imposed externally. Research into how to design assessment frameworks and matching mechanisms that connect recipient needs with available expertise and funding is a priority.
How can the DTG2 on capacity building serve as a strategic coordination platform rather than duplicating plenary discussions, and what specific deliverables (e.g., diagnostic assessments, needs mapping, action-oriented recommendations) should it produce?
Several delegations called for DTG2 to be results-focused and action-oriented, but the specific format, deliverables, and relationship to plenary discussions remain to be defined. Clarifying the DTG’s mandate and working methods is essential for its effectiveness.
How can South-South and triangular cooperation modalities be better utilised for cybersecurity capacity building, and what role can regional mechanisms play in facilitating these exchanges?
Colombia and the Latin American group highlighted South-South and triangular cooperation as particularly valuable for sharing contextually relevant knowledge. Research into existing models and how they can be scaled or formalised within the global mechanism is needed.
How can real case studies and hypothetical scenarios be incorporated into DTG2 discussions to generate concrete lessons and practical recommendations on cyber incident response cooperation?
Colombia proposed using specific case studies and simulation exercises within DTG2 to move beyond abstract discussion. Developing a methodology for selecting, presenting, and drawing lessons from such cases is an area requiring further work.
How can the Global ICT Security Cooperation and Capacity Building Portal, the Voluntary UN ICT Security Capacity Building Fund, and the UN ICT Security Fellowship Programme be operationalised and adequately resourced?
The African Group and Nigeria called for progress on these specific initiatives as practical capacity-building tools. The modalities, governance, funding mechanisms, and eligibility criteria for these instruments remain to be developed.
How can the full, equal, and meaningful participation of women and youth in cybersecurity capacity-building programmes be ensured, and what specific initiatives or fellowship programmes have proven effective?
Multiple delegations stressed the importance of gender-inclusive capacity building. Research into effective models, such as the UNODA and donor-sponsored Women in International Security and Cyberspace Fellowship, and how to scale them is needed.
How can the Asia-Pacific Regional Cybercrime Centre being established in Hanoi (in cooperation with UNODC) contribute to regional capacity building and CBM implementation, and how can other states and stakeholders participate?
Vietnam announced the initiative to establish an Asia-Pacific Regional Cybercrime Centre and invited participation from other states and stakeholders. Further research into its mandate, governance, and relationship to the global mechanism is needed.
How can the protection of critical subsea cable infrastructure be addressed through explicit international CBMs, and what guidance should the Global Mechanism develop on this issue?
Tuvalu highlighted its Tuvalu Subsea Cable as a vital digital lifeline and called for explicit CBMs and international guidance on protecting subsea infrastructure from both natural hazards and malicious cyber threats. This is an emerging area with limited existing international guidance.
How can the Global Mechanism support ‘capacity sovereignty’ — the long-term training of local technical teams rather than reliance on short-term external consulting — and what modalities would best achieve this?
Tuvalu called for a shift from short-term external consulting to sustainable, locally owned technical capacity. Research into effective models for building indigenous cybersecurity expertise in small island developing states is a priority area.
How can hybrid participation modalities and time-zone-sensitive scheduling be improved to ensure that small and geographically distant delegations (e.g., Pacific Island states) can participate meaningfully in DTG meetings?
Pacific delegations noted that current meeting times often require them to participate in the middle of the night. Research into how to design inclusive participation modalities that do not systematically disadvantage certain regions is needed.
How can the Global Mechanism’s accreditation and participation modalities for non-state stakeholders be improved to ensure that their engagement is substantive rather than nominal?
The Pacific Islands Forum expressed concern that stakeholder participation is currently more nominal than real. Research into how other UN mechanisms have successfully integrated multi-stakeholder expertise while preserving the intergovernmental nature of decision-making could inform improvements.
How can the severity scale for cyber incidents developed within the OAS framework be adapted or adopted at the global level to help states prioritise and scale cooperation between national CERTs?
The Dominican Republic highlighted the OAS’s common incident severity scale as a practical tool that enables states to understand and respond proportionately to incidents affecting other members. Exploring whether and how this could be adopted globally is a valuable area for further research.
How can institutional continuity for CBM implementation be maintained during staff turnover, particularly in developing countries, and what mechanisms (e.g., documented procedures, institutional memory systems) are most effective?
The Dominican Republic identified staff turnover as a significant challenge for sustaining CBM implementation, particularly in Latin American countries. Research into best practices for institutional continuity in cybersecurity governance is needed.
How can the Cyber Security Centre for Latin America and the Caribbean (headquartered in Santo Domingo) serve as a model for point-to-point cooperation that sustains capacity building, and how can similar regional centres be established in other regions?
The Dominican Republic highlighted this centre as an example of how regional specialised technical assistance can sustain capacity building. Research into its governance model, funding, and outcomes could inform the establishment of similar centres elsewhere.
How can the Global Mechanism facilitate a structured diagnostic assessment of the current global capacity-building landscape to identify gaps, avoid duplication, and match needs with available expertise and resources?
Multiple delegations called for a systematic mapping of existing capacity-building initiatives. The African Group specifically welcomed a proposal for a structured diagnostic assessment as a DTG2 deliverable. Developing the methodology and scope for such an assessment is a priority research task.
How can the Global Roundtable on Capacity Building be used to enhance coordination among capacity-building implementers, and how should its outputs feed into DTG2 and plenary discussions?
The EU suggested the Global Roundtable on Capacity Building could play a coordination role, but its relationship to the DTGs and plenary has not been clearly defined. Research into effective models for such roundtables in other UN contexts could inform its design.
How can the voluntary norms implementation checklist be further developed into a digital tool to support states’ implementation of the UN framework, and what features would make it most useful for diverse national contexts?
The EU proposed building on the voluntary norms implementation checklist to develop a broader digital support tool. Research into user needs, technical requirements, and governance of such a tool is needed before it can be developed.
How can the ICT security capacity-building guidelines adopted in the 2021 OEWG report be mainstreamed into relevant ICT security and cyber capacity-building programming at national and regional levels?
The EU called for mainstreaming the 2021 OEWG capacity-building guidelines into programming. Research into how these guidelines are currently being used, where gaps exist, and how to promote their adoption is needed.
How can the applicability of international law to cyberspace — including sovereignty, non-intervention, international humanitarian law, and the peaceful settlement of disputes — be clarified through capacity-building activities, and what role should the DTGs play in this?
Vietnam and Costa Rica highlighted that states need capacity to understand how international law applies to cyberspace and to develop national positions. Research into effective training and capacity-building modalities for cyber law and diplomacy is needed.
How can the Global Mechanism support the development of cyber diplomacy strategies that integrate legal, technical, and political knowledge, enabling states to coherently represent national interests in international fora?
Costa Rica identified cyber diplomacy as a specialised capacity that many states lack. Research into what constitutes effective cyber diplomacy training and how it can be delivered in a sustainable, regionally adapted manner is a priority.
How can public-private partnerships be structured within the global CBM and capacity-building framework to leverage private sector expertise on vulnerabilities, incidents, and emerging risks while preserving the intergovernmental nature of decision-making?
Multiple delegations highlighted the importance of public-private partnerships but also the need to maintain state leadership. Research into effective governance models for such partnerships in the cybersecurity context is needed.
How can the Global Mechanism develop and promote national positions on how international law applies in cyberspace, and what support can be provided to states that lack the resources to undertake this process independently?
The Netherlands called on all member states to develop and publish national positions on international law in cyberspace and offered to share best practices. Research into what support mechanisms (e.g., model frameworks, technical assistance, peer review) would be most effective for resource-constrained states is needed.







