The UN’s permanent cyber mechanism continued its transition from developing policy frameworks to implementing them, with member states focusing on practical measures to operationalise confidence-building measures (CBMs), strengthen cyber capacity, and ensure agreed commitments can function effectively during real-world cyber incidents.
During the seventh substantive plenary meeting of the Global Mechanism on ICT Security, delegations concentrated on translating previous political agreements into operational tools. Discussions centred on the Global Points of Contact (POC) Directory, the role of the Dedicated Thematic Groups (DTGs), regional cooperation, and capacity development as the foundation for responsible state behaviour in cyberspace.
Across regional groups, delegates broadly agreed that implementation has become the mechanism’s principal challenge, particularly for developing countries and small island developing states with limited technical and institutional resources.
States seek to operationalise cyber confidence-building measures
Delegations reaffirmed that confidence-building measures are intended to reduce misunderstandings, improve communication, and lower the risk of escalation before cyber incidents develop into political crises.
The Global Points of Contact Directory was widely described as the most tangible achievement inherited from the previous Open-ended Working Group (OEWG). However, speakers stressed that its success depends not simply on the number of participating states, but on regular testing, timely responses, and practical use during incidents.
Several delegations emphasised that the directory should complement, not replace, existing diplomatic, technical, and regional communication channels, while remaining proportionate to the capacities of smaller administrations.
Practical experience shapes future cooperation
Rather than proposing new confidence-building measures, many countries shared lessons from real cyber incidents.
Tonga highlighted cooperation following a cyberattack on its national health system, explaining that trusted regional relationships enabled rapid assistance and coordinated public attribution. Vanuatu similarly argued that confidence is built through predictable cooperation and routine communication rather than by creating additional mechanisms or reporting requirements.
The Dominican Republic also distinguished between confidence-building measures and operational incident response, noting that CBMs create the trust necessary for rapid technical cooperation but are not themselves emergency response mechanisms.
Dedicated Thematic Groups become implementation platform
Many delegations identified the Dedicated Thematic Groups as the mechanism’s primary vehicle for turning agreed commitments into practical action.
Countries proposed that the DTGs facilitate exchanges of national experience, scenario-based exercises, practical guidance, and technical recommendations while avoiding duplication of plenary negotiations. Regional organisations were likewise encouraged to share their implementation experience so that successful practices could inform global discussions.
Simulation exercises, regular communication checks, and joint training activities were repeatedly highlighted as practical ways to ensure confidence-building measures function effectively before crises occur.
Capacity development recognised as the foundation
The second half of the session focused on capacity building, which delegations consistently described as underpinning every pillar of the UN cyber framework.
The Pacific Islands Forum, the African Group, the European Union, CARICOM, and a Latin American coalition argued that countries cannot effectively implement voluntary norms, apply international law, or participate in confidence-building measures without sufficient legal, institutional, and technical capacity. Several speakers proposed expanding international support through fellowship programmes, a voluntary UN ICT Security Capacity Building Fund, stronger national computer emergency response teams (CERTs), and a Global ICT Security Cooperation and Capacity Building Portal.
Delegations also stressed that future capacity-building efforts should remain demand-driven, nationally owned, and adapted to local priorities while avoiding duplication of existing initiatives.
Ensuring no country is left behind
Throughout the discussion, developing countries and small island developing states emphasised that practical implementation must take account of widely differing national capacities.
Several delegations called for greater inclusion of regional organisations, civil society, academia, the private sector, and youth in implementation efforts, arguing that broad participation will be essential if the mechanism is to deliver practical improvements in global cybersecurity.
Closing the session, Chair Egriselda LĂłpez noted the broad support for translating agreed confidence-building measures into practical implementation and confirmed that discussions on capacity development would continue during the afternoon session.
Track all key moments from the First substantive session of the UN Global Mechanism on cybersecurity on our dedicated page.
Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!
