3rd meeting - Plenary Session
This discussion took place during the third meeting of the substantive plenary session of the Global Mechanism on Developments in the Field of Information and Communication Technologies (ICTs) and Advanced Responsible State Behaviour, focusing on existing and potential ICT threats in the context of international security . The Chair noted 30 remaining speakers on the list and requested delegations to deliver abridged statements to allow all parties to be heard .
Several small island developing states, particularly from the Pacific, offered vivid accounts of the real-world consequences of cyber threats. Kiribati described how its first submarine cable connection simultaneously increased its exposure, warning that damage to undersea infrastructure would not merely degrade services but "sever them" . Tonga recounted how the 2022 volcanic eruption severed its single submarine cable, drawing a direct parallel to the potential impact of deliberate sabotage, and described a 2023 ransomware attack on its national health information system . These delegations called for threat discussions to be matched by practical cooperation and concrete steps .
A broad range of delegations identified ransomware, state-sponsored cyber operations, and the malicious use of artificial intelligence as the most pressing threats. The Netherlands highlighted the blurring of lines between state and non-state actors and the use of proxies to maintain plausible deniability . Germany reported estimated annual cyber attack damages of approximately 230 billion US dollars and condemned specific Russian state-sponsored activities targeting EU critical infrastructure . France, Poland, Latvia, and Albania similarly attributed sustained malicious cyber campaigns to Russian actors, citing specific incidents against government institutions and critical infrastructure .
Iran delivered a lengthy statement alleging that the United States and Israel conducted over 100 cyber attacks per day against Iranian critical infrastructure during February 2026, targeting banking, telecommunications, energy, and civilian institutions . Israel and the United States both rejected these characterisations, with the US warning that it would hold malicious actors accountable and that "the cyber domain is about to change" . Ukraine described cyberspace as "one of the principal theatres of Russia's ongoing war of aggression," noting that Russian operations had evolved into sophisticated campaigns combining espionage, supply chain compromise, and information manipulation .
Across delegations, there was broad convergence on the need for the global mechanism to move beyond identifying threats towards practical implementation, capacity building, and structured information sharing, particularly for developing countries with limited resources . Delegations including Egypt, Japan, and Chile emphasised the importance of engaging qualified experts and evidence-based discussions within the dedicated thematic groups . The overall significance of the session lay in establishing that the new permanent mechanism must translate shared threat awareness into concrete, cooperative, and action-oriented outcomes for all states, regardless of size or capacity .
Overall Purpose
- The discussion takes place during the third meeting of the substantive plenary session of the Global Mechanism on Developments in the Field of Information and Communication Technologies (ICTs) and Advanced Responsible State Behaviour. The primary goal is for member states to identify and discuss existing and potential ICT threats in the context of international security, with a view to informing the work of dedicated thematic groups (DTGs) and advancing the implementation of the UN framework for responsible state behaviour in cyberspace.
- --
Major Discussion Points
- Critical infrastructure protection, particularly submarine cables and undersea connectivity, as an existential threat for small island developing states (SIDS). Multiple Pacific Island nations emphasised that the disruption of submarine cables - whether through natural disaster, accident, or deliberate malicious action - poses an existential rather than merely significant risk. Tonga recounted how the 2022 Hunga Tonga-Hunga Ha'apai volcanic eruption severed its only submarine cable, leaving the country isolated during a crisis, and warned that a malicious actor could replicate this deliberately. Kiribati similarly noted that damage to its limited cable infrastructure would not degrade services but sever them entirely. Australia and Tuvalu reinforced the importance of undersea cable resilience for economic and social connectivity across the region.
- Ransomware as a pervasive and escalating threat to critical infrastructure and essential services. Numerous delegations identified ransomware as one of the most destructive and widespread cyber threats, affecting healthcare, government, energy, and other critical sectors. Tonga described a ransomware attack that encrypted its national health information system and forced hospitals back to pen and paper. Japan stated that ransomware targeting critical infrastructure such as hospitals and power plants could constitute a direct threat to international peace and security. Germany reported a 230 billion USD annual damage estimate from cyber attacks, with ransomware particularly targeting critical infrastructure providers and municipal services. Latvia, the Philippines, Malaysia, and others echoed these concerns.
- The role of artificial intelligence in amplifying cyber threats and transforming the threat landscape. A broad consensus emerged that AI is lowering the barrier to entry for malicious actors, enabling more sophisticated phishing, autonomous vulnerability discovery, and large-scale social engineering. New Zealand welcomed discussion on how AI affects cyber security risks and noted the importance of avoiding duplication with other UN processes. The Netherlands highlighted that generative AI and large language models can assist in zero-day vulnerability discovery and exploitation. Australia warned that AI is making it easier for malicious actors to generate propaganda and support target selection for physical strikes. France noted that frontier AI models are increasing the speed of offensive operations and risk creating a new digital divide between those with and without access to such models. The Republic of Korea called for deepened discussions on AI-enabled cyber threats within the global mechanism. - State-sponsored malicious cyber activity, attribution, and accountability. Several Western and allied delegations made explicit attributions of malicious cyber operations to state actors, particularly Russia, while Russia and Iran rejected these accusations and made counter-allegations. France announced it had been the target of persistent cyber attacks by Russia's FSB for over a decade. Germany, together with EU partners, exposed and condemned malicious cyber activities by Russian state actors targeting government entities and critical infrastructure, including energy systems with potential for catastrophic damage. Ukraine described Russia's cyber operations as an integral component of its broader war of aggression, combining cyber attacks with kinetic strikes and disinformation. Iran detailed extensive cyber attacks it attributed to the United States and Israel during military operations in February 2026. Russia rejected all accusations as fabricated and without evidence, and counter-accused NATO states of building offensive cyber capabilities. The United States warned that it would identify and hold accountable states conducting malicious cyber activities against others in the room. - Capacity building, international cooperation, and the need to ensure developing countries are not left behind. A recurring theme across delegations from Africa, the Pacific, Latin America, and Asia was that the global mechanism must translate threat discussions into practical, demand-driven capacity building tailored to the needs of developing and small island states. The Bahamas stressed that capacity building is a precondition for meaningful participation for SIDS. Malawi highlighted that many developing countries struggle to respond even to a single cyber incident, let alone sustained campaigns. Cameroon called for the establishment of a dedicated voluntary fund to support national cybersecurity institution building and participation in DTG meetings. Egypt argued that threat discussions in thematic groups must be dynamic, scenario-based, and supported by an agreed pool of relevant experts rather than replicating plenary discussions. ---
Overall Tone
- The discussion began in a broadly constructive and cooperative tone, with delegations welcoming the establishment of the permanent global mechanism and expressing commitment to practical, action-oriented outcomes. Small island states delivered particularly earnest and personal statements, grounding the discussion in lived national experience rather than abstract policy.
- However, the tone shifted markedly when Iran delivered a statement attributing extensive cyber and kinetic attacks to the United States and Israel , prompting sharp responses from the United States , Israel , and Iran's right of reply . These exchanges introduced a confrontational and politically charged atmosphere, with accusations of bad faith, disinformation, and violations of international law traded between delegations. Russia's statement similarly escalated tensions by rejecting attribution claims from multiple Western states and accusing NATO of hypocrisy and Russophobia. The Chair intervened to manage procedural order, reminding delegations that rights of reply should be reserved for the end of the speakers' list and urging all parties to remain focused on the substantive agenda. Despite these disruptions, the majority of delegations maintained a professional and solution-oriented tone throughout, consistently returning to themes of cooperation, capacity building, and the importance of the mechanism delivering tangible outcomes for all states.
Expanded Summary: Third Meeting of the Substantive Plenary Session - Global Mechanism on ICTs and Advanced Responsible State Behaviour
#
Session Overview and Procedural Context
The third meeting of the substantive plenary session of the Global Mechanism on Developments in the Field of Information and Communication Technologies (ICTs) and Advanced Responsible State Behaviour convened under the chairmanship of Ambassador Egriselda López. The primary agenda item was the completion of statements under the pillar on existing and potential ICT threats in the context of international security. With 30 remaining speakers on the list at the outset, the Chair requested that delegations deliver abridged versions of their statements and submit full texts to eStatements, noting that a timer would be projected on screen to assist with time management. This first substantive session of a permanent mechanism was widely acknowledged as historically significant, marking the transition from the time-limited Open-Ended Working Group (OEWG) process to a standing forum for international cyber security dialogue.
#
Calls for Action-Orientation: Setting the Tone for the Mechanism
One of the most consequential early interventions came from Kiribati, which framed the session's purpose in terms that resonated throughout the entire discussion. Kiribati observed that for years, collective work on ICT security had moved from one limited-time process to the next, while threats had never paused between them, and welcomed the permanence of the new mechanism. Crucially, Kiribati insisted that "discussion of threats must not end as descriptions of threats" and that each threat identified should connect to a concrete step enabling all states, including the smallest, to prevent, detect, and respond. This call for action-orientation - rather than mere cataloguing - was adopted, explicitly or implicitly, by the majority of subsequent speakers, including Malawi, Mozambique, Cameroon, and Morocco, and effectively established a normative standard against which the mechanism's first session would be judged.
Cameroon reinforced this collective spirit by invoking the African proverb "If you want to go fast, go alone. If you want to go far, go together," encapsulating its call for shared responsibility and multilateral cooperation in addressing cyber threats. Morocco similarly called for the first Dedicated Thematic Group (DTG1) to be "strongly turned toward action," emphasising the need to move beyond descriptive threat cataloguing towards concrete, implementable outcomes.
#
Critical Infrastructure and the Existential Vulnerability of Small Island States
The vulnerability of submarine cable infrastructure emerged as one of the session's most vivid and consistently reinforced themes, driven primarily by Pacific Island Forum member states. Kiribati described how the landing of the East Micronesian Cable at Tarawa - the first submarine cable ever to reach its capital - was transformative for its Digital Government Master Plan and service delivery across dispersed islands, but that "every step forward in connectivity is also a step forward in exposure." For a nation served by a small number of cables, landing stations, and satellite links, Kiribati stated that critical infrastructure protection is not one threat among many but "existential," and that damage to or disruption of its submarine cable "will not degrade our services, it will sever them" [S185].
Tonga offered perhaps the most powerful illustration of this vulnerability. Recounting the January 2022 eruption of Hunga Tonga-Hunga Ha'apai, which severed the single submarine cable connecting the kingdom to the world, Tonga described weeks of silence - cut off at the very moment it most needed to call for help, coordinate relief, and reassure families abroad. Tonga then drew a direct and sobering parallel: "everything a volcano did to Tonga by accident, a malicious act could choose to do deliberately." This framing transformed an abstract geopolitical threat into a visceral, lived experience, and Tonga called on the room to treat the sabotage of submarine cables and other critical infrastructure as one of the gravest threats before the mechanism. Australia reinforced this regional perspective, stating that for many countries in the region, the resilience of undersea cable infrastructure is fundamental to economic and social connectivity and to access to the global internet, and called for critical infrastructure protection to be an early focus for the mechanism through DTG1. Tuvalu similarly highlighted the importance of the Aotevaca Cable and other subsea infrastructure to its connectivity, grounding its cybersecurity concerns in the concrete realities of Pacific island geography.
Ghana noted that damage to Submarine Cable 7 Ghana in 2024 reinforced the importance of protecting such infrastructure as a strategic national asset [S185][S186]. Guyana announced plans to establish a national cyber emergency response system operating on a 24/7 basis, reflecting the growing recognition among developing states that continuous operational capacity is essential for effective incident response.
Beyond submarine cables, the broader theme of critical infrastructure protection attracted broad agreement. The Netherlands highlighted a troubling shift towards the targeting of means of communication such as messaging services, noting that compromises can enable large-scale espionage, manipulation of communications, or disruptions with cascading effects far beyond the specific target. Chile stated that the protection of critical infrastructure represents a national priority and an essential component of international security, with the gradual digitisation and interconnection of critical sectors increasing the risk of systemic effects. Zimbabwe, as a land-linked developing country relying on interconnected regional telecommunications networks, recognised that vulnerabilities within shared digital infrastructure can have cross-border consequences.
The Bahamas drew particular attention to the nexus between cyber threats and natural disasters as a specific and compounding vulnerability for small island developing states, noting that the simultaneous occurrence of a cyber incident and a natural disaster could overwhelm national response capacity at the most critical moment.
#
Ransomware: A Pervasive and Escalating Threat
Ransomware was identified by a remarkably broad coalition of delegations as one of the most destructive and widespread cyber threats, with real-world impacts documented across healthcare, government, energy, and financial services [S191][S192]. Tonga described a ransomware attack in June of the previous year that encrypted its national health information system, holding the medical records of its entire population to ransom and forcing hospitals back to pen and paper. Tonga also noted that its state-owned telecommunications provider was attacked in 2023, and that these incidents against the essential services of a small state demonstrated that no country is too small or too remote to be targeted. Significantly, Tonga, together with Australia and New Zealand, jointly attributed the attack on its Ministry of Health to an affiliate of a known ransomware group, demonstrating that even the smallest states acting with partners can pursue accountability for malicious cyber activities.
Japan stated explicitly that ransomware targeting critical infrastructure such as hospitals and power plants "could certainly pose direct threats to international peace and security," citing its statement at the Security Council briefing on ransomware in November 2024. Germany reported that the leading German digital business group estimated annual damage from cyber attacks at approximately 230 billion US dollars, with ransomware particularly targeting critical infrastructure providers, municipal and government services, and not-for-profit organisations. Germany also described a ransomware attack that paralysed a leading humanitarian organisation providing food relief in conflict regions, putting lives abroad at risk. Latvia noted that criminal groups have developed industrial-scale ransomware operations, leveraging encryption, infostealer malware, data theft, and extortion to generate enormous profits. The Philippines called for timely information sharing, strengthened incident response capabilities, public-private partnerships, and sustainable capacity building to address ransomware [S187][S188][S189][S190].
#
Artificial Intelligence: Amplifying Threats and Transforming the Landscape
Artificial intelligence was consistently highlighted across delegations as a dual-use technology that is both amplifying offensive cyber capabilities and offering significant defensive opportunities [S154][S155]. The Netherlands stated that generative AI and large language models can lower the barrier for conducting sophisticated operations, from writing convincing phishing messages to assisting in the discovery of zero-day vulnerabilities and their exploitation, and noted that the development of such threats continues to accelerate with the rise of agentic AI. Australia warned that AI is being used to scale social engineering, create more convincing phishing content, analyse stolen data, and lower the cost and skill barriers required to cause harm, and expressed particular concern that AI is making it easier for malicious actors to generate and spread propaganda and to support planning and target selection for physical strikes.
Germany observed that the advent of advanced AI facilitates large-scale attacks including language-agnostic phishing, voice phishing, and social engineering attacks, continuously lowering the barrier for opportunistic malicious actors and creating an increasing strain on defenders' resources, with particular impact on less-resourced and small countries. Latvia noted that AI-enabled tools can automate reconnaissance, accelerate and scale vulnerability discovery, and generate highly convincing phishing campaigns, with the potential to overwhelm cyber defenders' capacity to respond. Canada noted that frontier AI models have displayed unprecedented capabilities in autonomous vulnerability discovery, zero-day vulnerability exploit generation, and multi-stage orchestration of malicious cyber activity.
France introduced a particularly significant analytical dimension, observing that the rapid increase in frontier AI model capabilities carries the risk of a new digital divide - between those who have access to these models and those who do not, and between those who can independently assess the risks associated with these models and those who cannot. China stated that "in the past, the risk posed by AI was merely theoretical, but now we see firsthand the real threats AI poses," and called for the establishment of global standards and systems for testing and assessing the risk of large AI models, to ensure that AI serves as a shield for cybersecurity rather than a tool for unilateral pursuit of hegemony. The Republic of Korea called for the mechanism to deepen discussions on AI-enabled cyber threats and ensure that international dialogue remains timely and responsive to the rapidly changing technological environment.
New Zealand offered a note of caution, arguing that the global mechanism should not duplicate other UN processes actively grappling with AI governance issues, and should focus only on issues where it is uniquely well placed to add value - namely, building shared understanding of the implications of AI for cybersecurity. This position was not widely shared, with most delegations calling for substantive AI discussions within the mechanism itself.
#
State-Sponsored Cyber Activities, Attribution, and Accountability
The session was marked by sharp and explicit attributions of malicious cyber activities to state actors, generating some of the most politically charged exchanges of the meeting. France announced that it had been the target for more than ten years of persistent cyber attacks carried out by Russia's Federal Security Service (FSB), and stated that this attribution process was conducted in accordance with the norms for responsible state behaviour and following the exhaustion of appropriate channels. France also noted that on the 13th of July, the European Union adopted new sanctions against actors from the Russian cyber threat ecosystem. Germany stated that last week, together with the European Union and its member states and the North Atlantic Council, it had exposed and condemned a series of malicious cyber activities conducted by Russian state actors, including its intelligence service FSB and state-supported cyber criminal and hacktivist groups, targeting government entities and critical infrastructure in several EU member states and Ukraine, some of which had the potential for catastrophic damage to civilian energy infrastructure such as electricity networks or hydroelectric dams. Germany also stated it had communicated the unacceptability of these activities via appropriate direct bilateral channels.
Poland reported a sustained pattern of malicious cyber activity by Russian actors since at least 2010, including strategic reconnaissance, prepositioning, and disruptive sabotage operations targeting Polish critical infrastructure including water treatment plants and the energy sector. Albania documented 51 cyber incidents with significant impact in 2025, rising to more than 17 million attempted cyber attacks in 2026, with four incidents in March 2026 alone targeting the Albanian parliament, post office, office of the general prosecutor, and directorate of prisons, supported by state-sponsored cyber operations. Ukraine described cyberspace as "one of the principal theatres of Russia's ongoing war of aggression against Ukraine," noting that Russian malicious ICT activities form part of a broader strategy combining cyber attacks with kinetic strikes, disinformation campaigns, and other hybrid warfare tools, and that over time these operations have evolved from destructive attacks into sophisticated campaigns involving cyber espionage, long-term network persistence, supply chain compromise, and information manipulation [S156][S196].
The Russian Federation categorically rejected all these accusations, arguing that accusations of organising and implementing wrongful acts against states should be substantiated and that no evidence had been provided through existing channels, including the UN Points of Contact Directory. Russia concluded that "either no evidence exists or the incidents never happened at all," and characterised the accusations as "blatant disinformation" serving Russophobic policies. Russia counter-accused NATO states of building up offensive digital capabilities and conducting computer operations against Russian critical information infrastructure, and accused NATO member states of turning a blind eye to crimes committed by Ukrainian hackers against Russian citizens and civilian critical information infrastructure [S157][S197]. Russia also called on the Chair to prevent the discussions within the global mechanism from turning into a political crisis.
#
The Iran-Israel-United States Exchange
The most politically disruptive episode of the session arose from Iran's detailed account of cyber attacks it attributed to the United States and Israel. Iran alleged that during the February 2026 aggression alone, more than 100 cyber attacks were launched every day against Iran's critical and civilian infrastructure. These operations were described as including coordinated cyber and kinetic attacks targeting critical ICT infrastructure including telecommunications facilities, data centres, and AI infrastructure; attacks against civilian institutions including schools, universities, and media; exploitation of private sector technologies and ICT supply chains including products from Cisco and HP and the misuse of Starlink satellite communication services; cyber espionage and information operations including the manipulation of digital platforms such as Instagram, X, and Telegram to incite violence and spread hatred; and electronic warfare and hybrid operations. Iran called on states that advocate respect for international law to apply those principles consistently and condemn such activities.
Israel responded by asserting that its actions during operations Rising Lion and Roaring Lion were conducted in accordance with international law, including the UN Charter and the laws of armed conflict, in the context of an ongoing armed conflict with Iran. Israel accused Iran of waging hostility across all domains of warfare, including the cyber domain, and of specifically targeting critical civilian infrastructure including hospitals with complete disregard for international humanitarian law.
Iran's right of reply characterised both the US and Israeli statements as "a desperate attempt to distort facts through disinformation and misleading narratives," and reiterated that the Islamic Republic of Iran has long been one of the principal targets and victims of malicious cyber activities, invoking the historical pattern of such activities - including what it described as the first non-cyber weapon deployed against critical infrastructure - as evidence of a sustained campaign against it. The Chair intervened to clarify that rights of reply should be made at the end of the speakers' list, indicating that the level of political confrontation had not been anticipated in the procedural design of the session.
#
The United States: Deterrence, Accountability, and Implementation
The United States framed its engagement with the mechanism in terms of practical implementation of the 11 consensus norms, explicitly stating that the mechanism should not be "a vehicle for new legally binding agreements" and arguing that as long as some members are maliciously conducting cyber actions against other members, a legally binding agreement is impossible. The United States stated that the mechanism was established to do real work - to implement the commitments states have already made and to confront actual threats hitting critical infrastructure every single day. The United States further stated that it would demand adherence to the consensus norms and the five pillars to ensure the cyber domain remains a secure and safe space for everyone.
In a notably direct passage, the United States warned that it would specifically identify states and non-state actors perpetuating malicious cyber activities against others in the room, and that President Trump had been clear: "if a country is utilizing the cyber domain to hurt others, in this chamber, the United States will make them pay a heavy price." The United States also expressed solidarity with Pacific Island states, directly addressing Tonga and Kiribati and pledging to help protect them. In a pointed postscript to its national statement, the United States stated that President Trump "is not going to stand idly by while the oppressive Iranian regime seeks to destroy regional stability and the inalienable right of all Iranians."
#
Russia and China: Alternative Threat Framings
The Russian Federation introduced a set of threat categories that diverged significantly from the Western-dominated discourse. Russia highlighted the "monetisation of the private sector," arguing that major ICT developers make no secret of how deeply they are embedded in the military-industrial complexes of the countries where they are registered and often act as contractors for intelligence agencies. Russia also raised the issue of undeclared malicious capabilities - backdoors embedded by developers in the interests of intelligence agencies without notifying end users - noting that as demonstrated by the "infamous Pager incident in Lebanon in 2024," such tools can be used for causing physical damage. Russia further raised concerns about low-orbit satellite communication systems being used for military-political objectives and interference in the internal affairs of states.
China identified three major threats: the risk of conflicts and unrest in cyberspace, driven by a "certain country" that aggressively develops offensive cyber military capabilities and integrates AI into offensive national cyber strategies; the challenge to the principle of sovereignty, with states being coerced into taking sides under the guise of cybersecurity and global digital industrial chains being deliberately severed; and the risk of marginalisation of global cyberspace governance through small-circle approaches that cannot solve the big challenges facing the world. China formally submitted a position paper on global cyber governance in the digital intelligence age to the Secretariat and requested its circulation to all member states as an official document.
#
Blurring of State and Non-State Actor Boundaries
Multiple delegations identified the blurring of boundaries between state-sponsored actors and non-state proxies as one of the most problematic and growing trends in the threat landscape. The Netherlands described this as a "worrying trend of state actors hiding behind state proxies to maintain plausible deniability," noting that different types of actors increasingly use similar tools, target similar systems, and sometimes operate in concert. France observed that "the boundaries between state-sponsored acts and cyber criminals are blurring, and the use of proxies by nation-states is spreading," and noted that behind various disguises, the intention to destabilise remains the same. Israel highlighted the clandestine direction, control, or support of non-state actors as a core threat, and raised the issue of states granting absolute impunity to criminal syndicates and terrorist proxies offering hacking as a service from state-sanctioned safe havens. Israel also drew attention to the illicit financing of such operations via digital assets, calling for international cooperation on tracking, freezing, and seizing cryptocurrencies used for illicit activities.
Iraq raised a distinctive concern not widely echoed by other delegations: the exploitation of ICTs by terrorist groups, including the use of cyberspace for recruitment, dissemination of extremist ideology, financing, planning, and coordination of terrorist operations, as well as the targeting of critical infrastructure by such groups. Iraq affirmed the importance of strengthening the security of ICT supply chains and exchanging international best practices and standards as an important element in reducing cross-border cyber risks.
#
Disinformation, Hybrid Threats, and Influence Operations
The combination of cyber operations with disinformation and information manipulation was identified as an increasingly significant dimension of the threat landscape. Albania described a "particularly concerning trend" in which cyber incidents were followed by attempts to spread disinformation and manipulate public perception through social media platforms, specifically via Telegram, seeking to amplify the psychological impact of cyber incidents, generate public uncertainty, and erode trust in public institutions. Albania concluded that "contemporary cyber threats are no longer limited to technical intrusions, but increasingly combine cyber operations, disinformation, and influence activities." Ukraine similarly highlighted hybrid campaigns combining cyber operations, disinformation, and economic coercion as seeking to undermine international peace and security.
Mauritius noted the growing risks posed by the malicious use of AI to generate convincing deepfakes, clone voices, spread disinformation, and enable sophisticated forms of fraud, including cryptocurrency-related scams, with the potential to undermine public trust and disproportionately impact vulnerable groups including children and older persons. Micronesia offered a cautionary counterpoint, warning that vague approaches to disinformation can suppress dissent and independent media, erode human rights, politicise enforcement, and disproportionately harm marginalised and remote communities, and urging states to adopt precise, time-bound, and rights-based definitions of disinformation.
#
Supply Chain Security and Emerging Technology Risks
Several delegations raised concerns about the security of ICT supply chains and the risks posed by emerging technologies beyond AI. Iran described attacks exploiting private sector technologies and ICT supply chains, including commercial products and services, software, hardware, and digital supply chains, as well as the misuse of Starlink satellite communication services. Thailand noted that ICT supply chain disruptions, including the deliberate insertion of vulnerabilities, backdoors, or other forms of interference, undermine economic and digital development, particularly in developing countries. Thailand's national assessment also indicated a continued rise in cyber incidents involving information content security, cyber fraud, and intrusion attempts.
Malaysia noted that it is preparing for the security implications of quantum computing, especially regarding current encryption systems, and is developing a national post-quantum cryptography migration plan focused on safeguarding critical information infrastructure. Chile similarly identified future risks related to quantum computing, alongside ransomware, exploitation of digital supply chains, and cloud-connected software, as topics requiring continued attention. Greece raised concerns about the proliferation of commercial cyber tools and capabilities, welcoming the Pall Mall Process as an initiative seeking to build international consensus on the responsible development, distribution, and use of commercial cyber intrusion capabilities. France described the uncontrolled proliferation of commercial cyber intrusion capabilities as "a veritable ticking time bomb," and announced the launch of negotiations on guidelines for the cyber intrusion industry under the Pall Mall Process, building on the April 2025 Code of Good Practices for States.
#
Capacity Building and the Needs of Developing Countries
A recurring and strongly felt theme across delegations from Africa, the Pacific, Latin America, and Asia was that the global mechanism must translate threat discussions into practical, demand-driven capacity building tailored to the needs of developing and small island states [S198][S199][S200]. The Bahamas stated that for small island developing states, "capacity building is a precondition for participation," and called for it to be sustained, tailored to national circumstances, and directed towards durable institutions and a trained workforce. The Bahamas also highlighted three specific priorities: cyber threats to youth, cyber threats to women including technology-facilitated gender-based violence, and the need for women to be at the table in delegation, technical decision-making, and national ICT policy design.
Malawi introduced a particularly precise analytical point, arguing that it is not only the emergence of threats that should concern the mechanism, but their persistence: "persistent and covert malicious ICT activities can remain undetected for extended periods of time, gradually undermining public trust, disrupting essential services, weakening national resilience, and causing significant economic and societal harm." Malawi noted that for many developing countries, responding to one cyber incident is already difficult, and responding to sustained campaigns is an even greater challenge. Cameroon called for the establishment of a Dedicated Voluntary Fund under the Global Mechanism as an essential instrument to support national cybersecurity institution building, provide resources for training and skills development, and facilitate participation in DTG meetings and capacity-building programmes. Mozambique called for capacity building that is predictable, sustainable, demand-driven, and accompanied by technology transfer, institutional strengthening, and equitable access to knowledge and expertise.
Australia acknowledged that cyber threats are shared but their impacts are not experienced equally, with differences in national capacity affecting vulnerability to malicious cyber activity and the ability to recover when incidents occur. Zimbabwe noted that capacity constraints and uneven cyber resilience increase vulnerability and limit the ability to effectively respond to cyber incidents, risking progress towards digital transformation and sustainable development. Indonesia called for the mechanism and its DTGs to foster cooperation in threat analysis, shared early warning arrangements, and structured exchange on incident trends to ensure that developing countries are not left behind. Indonesia also highlighted its participation in ASEAN, OIC, and Asia-Pacific mechanisms for technical information sharing, coordinated incident response, and joint capacity building as models for the kind of regional cooperation the global mechanism should support and complement.
The Philippines, noting its role as ASEAN Chair in 2026, reaffirmed its commitment to advancing regional cybersecurity cooperation through cyber exercises and operational collaboration, and called for timely information sharing, strengthened incident response capabilities, public-private partnerships, and sustainable capacity building to address threats including ransomware.
#
The Role of the Dedicated Thematic Groups
There was broad consensus that the Dedicated Thematic Groups (DTGs) represent the primary vehicle for translating high-level threat discussions into practical, action-oriented outcomes. Egypt argued that discussions in the DTGs should not replicate plenary discussions but should be dynamic, based on real case scenarios, and supported by a consensus-based pool of relevant experts accepted by delegations - noting that "having discussions on threats without a professional, experienced, and relevant pool of experts is, again, a waste of time." Japan placed great importance on holding expert briefings and interactive public-private discussions in the substantive plenary sessions and DTGs. Chile argued that the first DTG provides a particularly valuable opportunity for regular, structured, evidence-based dialogue on the evolution of threats, with a forward-looking approach and the participation of experts, regional organisations, the scientific community, and the private sector.
Latvia stated that the DTGs should focus on specific ICT security challenges, enabling states to examine threats, share experience, and develop practical approaches, and should also help turbocharge capacity-building efforts, recognising that global cyber resilience depends on ensuring that all states can protect their digital infrastructure. Oman called for DTG1 to focus on the practical implementation of norms 13i and 13j regarding the protection of critical infrastructure and supply chains, and norm 13c regarding states not allowing their territory to be used for malicious cyber activities, and argued that the mechanism should develop tools to assess whether states are abiding by these norms. France suggested that the first DTG could focus on one or two major trends in cyber threats with an impact on international peace and security, rather than attempting to address all threats simultaneously.
#
International Law and the Framework of Responsible State Behaviour
The vast majority of delegations reaffirmed that international law, including the UN Charter, applies in cyberspace and provides the foundation for responsible state behaviour. The Bahamas stated that international law is "the foundation of a secure and peaceful ICT environment" and "the guarantee of this process, not a constraint to it," and that voluntary norms and confidence-building measures operate in service of binding legal obligations, not in place of them. Australia stated that state responses, including the development and use of cyber capabilities, must be consistent with international law including the UN Charter in its entirety, international human rights law, and international humanitarian law. Micronesia affirmed that international law applies in cyberspace and that respect for sovereignty, the prohibition on the threat or use of force, and human rights obligations must guide state conduct online as they do offline. Malawi reaffirmed that as recognised in successive UN GGE and OEWG reports, international law including the UN Charter applies to the use of ICTs by states.
The Netherlands argued that adequate implementation of the consensus UN framework is the appropriate response to the growing complexity of the threat landscape, as it can inject a degree of predictability into global affairs. Albania emphasised that ensuring states act responsibly in cyberspace, refrain from supporting malicious activities, and cooperate in addressing threats is essential for preserving international peace, security, and stability in an increasingly interconnected world. The Republic of Korea noted that cryptocurrency theft has become a major source of financing for illicit activities and called for reaffirmation that such activities threaten international peace and security, especially when linked to illicit arms trafficking or the development of weapons of mass destruction, recalling that the final reports of the OEWG recognised cryptocurrency theft as a threat with implications for international peace and security.
#
National Experiences and Legislative Developments
Several delegations shared detailed accounts of their national cyber security postures and legislative frameworks. Kiribati described its Cybercrime Act 2021, Digital Government Act 2023, Data Protection Act 2025, and new Cybersecurity Act 2026 as forming the legislative backbone of its response. The Bahamas noted the launch of its National Computer Incident Response Team in December 2023, the adoption of a national cybersecurity strategy, a Data Protection Act in 2025, and the advancement of a national cybersecurity bill and child online protection strategy. Australia reported that its Cyber Security Centre responded to over 1,200 cyber security incidents and received more than 84,700 cybercrime reports in the previous year - roughly one report every six minutes. Albania documented more than 17 million attempted cyber attacks against Albanian systems in 2026, with four significant incidents in March 2026 alone targeting public institutions. Oman described its Electronic Defense Center, which since 2024 has addressed many cyber threats targeting national and governmental institutions, and announced a new national cybersecurity strategy for 2026-2030 placing cyber resilience at its heart. Oman also noted that it has adopted the 11 responsible behaviour norms for states and incorporated these into all its cyber policies, reflecting a commitment to translating international consensus into domestic practice. Mauritius highlighted the work of CERT-MU, its national Computer Emergency Response Team, in coordinating national incident response and building cyber resilience.
#
Procedural Developments and Closing Arrangements
As the session progressed, the Chair noted that the list of speakers had grown longer than predicted, potentially impacting the ability to address other agenda items, and closed the list of speakers for inscriptions. The Chair reminded delegations of the request to limit statements and noted that 21 speakers remained on the list with approximately one hour and 45 minutes remaining. The session was adjourned with the remaining speakers - Pakistan, Romania, Nicaragua, Armenia, the African Union, ICRC, and Interpol - to continue at 3 p.m., after which the mechanism would immediately proceed to the agenda item on voluntary norms for responsible state behaviour in cyberspace. Several side events were announced, including a joint event by Germany, the Dominican Republic, and Ghana on best practices for the operationalisation of confidence-building measures for the protection of critical infrastructure, and a co-hosted briefing by Latvia, Estonia, and Australia on Frontier AI and the Cyber Threat Landscape.
#
Overall Assessment
The session demonstrated both the promise and the challenges of the new permanent mechanism. There was genuine and broad convergence on the nature and severity of key threats - particularly ransomware, AI-enabled malicious activity, and critical infrastructure vulnerabilities - and on the need for the mechanism to be action-oriented, inclusive, and practically focused. The Pacific Island Forum states made a particularly substantive contribution, grounding abstract security concepts in lived national experience and consistently advocating for practical, cooperative outcomes. The strong alignment between small island developing states and major powers on the importance of submarine cable protection offered a potentially productive area for early concrete action [S149][S150].
At the same time, deep geopolitical divisions - most visibly between Western states and Russia on attribution, and between Iran, Israel, and the United States on the characterisation of recent military and cyber operations - introduced a confrontational dynamic that consumed significant time and risked overshadowing substantive progress. The Chair's procedural interventions reflected the difficulty of managing these tensions within the constraints of a first substantive session. The mechanism's success will ultimately depend on whether the areas of genuine consensus - on threats, on the need for capacity building, and on the action-oriented purpose of the DTGs - can be channelled into practical outcomes that deliver real security for all states, regardless of size or geopolitical alignment.
The organisational session records confirm that the Global Mechanism on ICT security was established and operating under leadership, consistent with the report's reference to Ambassador Egriselda López as chair. The organisational session documents [S2] and [S153] reference the chair's role in guiding the mechanism's work.
Multiple knowledge base sources confirm the transition from the OEWG to a permanent mechanism. [S208] describes the 'Open-Ended Action-Oriented Permanent Mechanism on ICT Security' as a subsidiary body of the UN General Assembly reporting to the First Committee, replacing the previous OEWG process. [S201] confirms the organisational session of the Global Mechanism was held, marking this institutional transition.
Kiribati's broader engagement with ICT security processes is confirmed in [S99], where Kiribati spoke during the OEWG substantive session, and in [S210], where Kiribati participated in the Ad Hoc Committee on cybercrime. These sources establish Kiribati as an participant in ICT security discussions, lending credibility to the report's characterisation of its intervention, though the specific quoted statement is not directly verifiable from the knowledge base.
The knowledge base does not directly confirm or contradict this specific proverb attribution to Cameroon in this session. However, [S3] confirms Malawi's participation in related ICT security discussions, and [S214] confirms Mozambique's engagement in policy formulation, consistent with the report's broader characterisation of African states' participation.
The knowledge base does not directly confirm Morocco's specific statement about DTG1 in this session. Morocco's engagement in multilateral security forums is noted in [S213] in a different context (UN peacekeeping), but this does not directly corroborate the specific claim about DTG1.
[S208] explicitly describes the permanent mechanism as replacing the OEWG, noting it would 'operate as a subsidiary body of the UN General Assembly reporting to the First Committee.' [S44] and [S207] document the closure of the OEWG session, further confirming the transition to the new permanent mechanism.
[S202] confirms that the first substantive session of the UN Global Mechanism on ICTs in International Security was focused on advancing 'responsible State behaviour' in the use of ICTs, and specifically references ICT-related threats as a central topic, consistent with the report's description of the agenda.
Background and Research Context Media Remuneration Policy Analysis Mitchell began by establishing her background and the context for CNTI's work. Coming from 25 years at the Pew Research Center where she helped l...
Threats are not region-specific; all countries have equal rights to have their security concerns reflected in discussions - Equal threat representation for all regions (Egypt)
Arg. 1Egypt argues that cyber threats do not belong exclusively to certain regions or countries, and therefore all nations have an equal right to see their security concerns reflected in plenary discussions and thematic groups. This principle of equal representation is fundamental to ensuring that the mechanism serves all member states fairly.
Egypt stated that all countries and regions have equal rights to see the challenges and threats they deem as national priorities to be reflected and discussed equally in the plenary and in the thematic groups .
Discussions in dedicated thematic groups should be dynamic, based on real case scenarios, and supported by an agreed pool of relevant experts accepted by delegations through consensus - Dynamic expert-based discussions in thematic groups (Egypt)
Arg. 2Egypt contends that discussions in dedicated thematic groups must go beyond replicating plenary debates and instead be dynamic, grounded in real case scenarios, and informed by a consensus-agreed pool of relevant experts. Without such experts, discussions risk being unproductive and failing to produce tangible outcomes.
Egypt emphasised that discussions should be dynamic based on real case scenarios, analysing threats from all aspects and coordinating with national, regional, and international authorities . Egypt further stressed that having discussions on threats without a professional, experienced, and relevant pool of experts is a waste of time, and that the pool of experts must be accepted by delegations through consensus .
The threat landscape is not abstract; connectivity advances bring increased exposure, particularly for small island states with limited redundancy - Connectivity and exposure for small states (Kiribati)
Arg. 1Kiribati highlights that every step forward in digital connectivity also increases exposure to cyber threats, and for a nation served by a small number of cables and satellite links, this is an existential concern rather than an abstract one. The arrival of the first submarine cable at Tarawa illustrates both the transformative potential and the new vulnerabilities created.
Kiribati noted that the East Micronesian Cable landed at Tarawa last year, the first submarine cable ever to reach their capital, underpinning their Digital Government Master Plan . Kiribati stated that every step forward in connectivity is also a step forward in exposure, and that for a nation served by a small number of cables, landing stations, and satellite links, critical infrastructure protection is existential .
Submarine cable infrastructure is existential for Kiribati; damage or disruption will not degrade services but sever them entirely - Submarine cable as existential infrastructure (Kiribati)
Arg. 2Kiribati stresses that damage to or disruption of its submarine cable, whether by malicious cyber activity or otherwise, would not merely degrade services but sever them entirely, making critical infrastructure protection an existential priority rather than one concern among many.
Kiribati stated that damage to or disruption of their submarine cable will not degrade their services but will sever them, and that they are equally concerned by cyber-enabled fraud, phishing, ransomware against government systems, and online harm directed at children . Kiribati also cited their legislative backbone including the Cybercrime Act 2021, Digital Government Act 2023, Data Protection Act 2025, and Cybersecurity Act 2026 .
National action has limits that only cooperation can overcome; each threat identified should connect to a concrete step enabling all states, including the smallest, to prevent, detect, and respond - Cooperation as essential complement to national action (Kiribati)
Arg. 3Kiribati argues that while national legislative and institutional action is important, it has inherent limits that only international cooperation can overcome, and this is the very reason the mechanism exists. The mechanism should ensure that every threat discussed connects to a concrete step that leaves every state able to prevent, detect, and respond.
Kiribati stated that national action has limits that only cooperation can overcome, and that cooperation is the very reason these mechanisms exist . Kiribati called for discussion of threats to connect to concrete steps through the plenary and dedicated thematic groups, leaving every state, including the smallest, able to prevent, detect, and respond .
The mechanism was designed to be action-oriented; discussion of threats must not end as descriptions but must connect to concrete steps for all states - Action-oriented mechanism with concrete outcomes (Kiribati)
Arg. 4Kiribati emphasises that the global mechanism was designed to be action-oriented and that this standard must be upheld from the very first session. Discussions on threats must not merely describe those threats but must translate into concrete, practical steps for all states.
Kiribati welcomed that the mechanism was designed to be action-oriented and stated their intention to hold it and themselves to that standard . Kiribati called for discussion of threats to not end as descriptions but to connect to concrete steps that leave every state able to prevent, detect, and respond .
Cyber-enabled fraud and scams, phishing, ransomware against government systems, and online harm directed at children do not distinguish between large and small states but impact those with least redundancy - Online harms affecting all states disproportionately (Kiribati)
Arg. 5Kiribati points out that cyber threats such as fraud, phishing, ransomware, and online harm to children do not discriminate between large and small states, but their impact falls disproportionately on those with the least redundancy and the thinnest technical workforce.
Kiribati stated that cyber-enabled fraud and scams, phishing, ransomware against government systems, and online harm directed at children do not distinguish between large and small states, but their impact falls hardest on those with the least redundancy and the thinnest technical workforce .
Ransomware continues to have serious consequences across all sectors, including healthcare, and AI is rapidly transforming the cybersecurity landscape - Ransomware and AI threats (New Zealand)
Arg. 1New Zealand highlights that ransomware continues to cause serious consequences across all sectors of the economy, with opportunistic actors affecting organisations including in the healthcare sector across the Pacific. Additionally, AI is rapidly transforming the cybersecurity landscape, creating both new risks and defensive opportunities.
New Zealand noted that ransomware continues to have serious consequences, with opportunistic actors impacting organisations in all sectors of the economy, and that others in the Pacific have also been affected by ransomware in the healthcare sector . New Zealand welcomed the opportunity to hear how others are seeing AI affect cybersecurity risks and what they are learning about how AI can support cyber defence .
AI is rapidly transforming the cybersecurity landscape; the mechanism should focus on building shared understanding of AI's implications for cybersecurity without duplicating other UN processes - AI's impact on cybersecurity and avoiding duplication (New Zealand)
Arg. 2New Zealand argues that while AI is rapidly transforming the cybersecurity landscape, the global mechanism should focus specifically on building shared understanding of AI's implications for cybersecurity rather than duplicating the work of other UN processes that are already addressing AI governance issues.
New Zealand noted that there are a variety of other UN processes actively grappling with questions related to artificial intelligence, including governance issues, and that it is important that the global mechanism does not duplicate those processes . New Zealand stated that the mechanism should focus only on issues where it is uniquely well placed to add value, namely building shared understanding of the implications of AI for cybersecurity .
The sabotage of submarine cables is one of the gravest threats; Tonga's experience with the Hunga Tonga eruption demonstrated what a malicious act could deliberately replicate - Submarine cable sabotage as a grave threat (Tonga)
Arg. 1Tonga draws on its direct experience of the 2022 Hunga Tonga-Hunga Ha'apai volcanic eruption, which severed the single submarine cable connecting the kingdom to the world, to illustrate the catastrophic consequences of connectivity loss. Tonga argues that what nature did by accident, a malicious actor could choose to do deliberately, making submarine cable sabotage one of the gravest threats before the mechanism.
Tonga described how in January 2022, the eruption of Hunga Tonga-Hunga Ha'apai severed the single submarine cable connecting the kingdom to the world, leaving Tonga silent for weeks and cut off at the very moment it most needed to call for help and coordinate relief . Tonga stated that everything a volcano did by accident, a malicious act could choose to do deliberately, and that this is why Tonga regards submarine cable sabotage as one of the gravest threats before the mechanism .
A ransomware attack encrypted Tonga's national health information system, holding medical records to ransom and forcing hospitals back to pen and paper - Ransomware attack on national health system (Tonga)
Arg. 2Tonga provides a concrete example of the devastating impact of ransomware on essential services, describing how an attack encrypted the national health information system, holding the medical records of the entire population to ransom and forcing hospitals to revert to manual processes.
Tonga described that in June of the previous year, a ransomware attack encrypted their national health information system, holding the medical records of their entire population to ransom and forcing hospitals back to pen and paper . Tonga also noted that their state-owned telecommunications provider was attacked in 2023, demonstrating that no country is too small or too remote to be targeted .
Tonga jointly attributed a ransomware attack on its Ministry of Health to an affiliate of a known ransomware group, demonstrating that small states acting with partners can pursue accountability - Small state attribution and accountability (Tonga)
Arg. 3Tonga highlights that even the smallest states can pursue accountability for malicious cyber activities when acting with partners, as demonstrated by the joint attribution of the ransomware attack on its Ministry of Health to an affiliate of a known ransomware group together with Australia and New Zealand.
Tonga stated that together with Australia and New Zealand, it jointly attributed the attack on its Ministry of Health to an affiliate of a known ransomware group, demonstrating that even the smallest states acting with partners can pursue accountability for malicious cyber activities .
Malicious cyber activities targeting critical infrastructure have grown in scale, sophistication, and diversity, affecting vital sectors including public administration, healthcare, and financial services - Escalating cyber incidents across sectors (Netherlands)
Arg. 1The Netherlands reports a steady increase in the scale, sophistication, and diversity of cyber incidents affecting society, ranging from ransomware to DDoS campaigns and exploitation of vulnerabilities in edge devices. These incidents impact vital sectors including public administration, healthcare, education, transport, and financial services.
The Netherlands observed a steady increase in the scale, sophistication, and diversity of cyber incidents, with attacks ranging from ransomware to disruptive DDoS campaigns and exploitation of vulnerabilities in edge devices and widely used software . These incidents impact vital sectors like public administration, healthcare, education, transport, and financial services, as well as international organisations based in the Netherlands .
The blurring of lines between state actors and non-state actors, including activist groups, is one of the most problematic trends, with states hiding behind proxies to maintain plausible deniability - State-proxy blurring and plausible deniability (Netherlands)
Arg. 2The Netherlands identifies the blurring of boundaries between state and non-state actors as one of the most problematic trends in the current threat landscape, with different types of actors increasingly using similar tools and sometimes operating in concert. This creates a worrying trend of state actors hiding behind proxies to maintain plausible deniability.
The Netherlands stated that different types of actors increasingly use similar tools, target similar systems, and sometimes operate in concert, blurring traditional distinctions between motives and methods . The Netherlands described this as a worrying trend of state actors hiding behind state proxies to maintain plausible deniability .
Critical infrastructure has been repeatedly targeted, with a recent shift towards targeting means of communication such as messaging services, enabling large-scale espionage and cascading disruptions - Targeting of communications infrastructure (Netherlands)
Arg. 3The Netherlands highlights that critical infrastructure continues to face persistent risks, with a particularly troublesome recent shift towards targeting means of communication such as messaging services. Compromises of such infrastructure can enable large-scale espionage, manipulation of communications, or disruptions with cascading effects far beyond the specific target.
The Netherlands noted that critical infrastructure has been repeatedly targeted and continues to face persistent risks, with a recent shift towards targeting means of communication such as messaging services . The Netherlands stated that compromises can enable large-scale espionage, manipulation of communications, or disruptions with cascading effects far beyond the specific target .
Generative AI amplifies existing cyber threats by lowering barriers for sophisticated operations, from phishing to zero-day vulnerability discovery, while also offering defensive opportunities - Generative AI as a threat amplifier (Netherlands)
Arg. 4The Netherlands argues that generative AI amplifies existing cyber threats by lowering the barrier for conducting sophisticated operations, from writing convincing phishing messages to assisting in the discovery and exploitation of zero-day vulnerabilities. At the same time, these tools can and should be harnessed defensively to improve detection, analysis, and response.
The Netherlands stated that large language models and other AI systems can lower the barrier for conducting sophisticated operations, from writing convincing phishing messages to assisting in the discovery of zero-day vulnerabilities and their exploitation . The Netherlands noted that with the use of agentic AI on the rise, the development of such threats continues to accelerate, making the threat landscape more complex by the day .
The consensus UN framework injects a degree of predictability into global affairs; adequate implementation is the appropriate response to the growing complexity of the threat landscape - Implementing the consensus framework for predictability (Netherlands)
Arg. 5The Netherlands argues that as the threat landscape grows ever more complex, it is through the adequate implementation of the consensus UN framework that states can inject a degree of predictability into global affairs. This implementation-focused approach is the appropriate collective response to the challenges identified.
The Netherlands stated that as the threat landscape continues to grow ever more complex, it is through the adequate implementation of the consensus UN framework that states can try to inject a degree of predictability in global affairs .
Cyber threats disproportionately affect small island developing states, including ransomware, cybercrime-as-a-service, attacks on critical infrastructure, AI-enabled fraud, and the nexus between cyber threats and natural disasters - Disproportionate impact on small island states (Bahamas)
Arg. 1The Bahamas highlights that its economy depends on digital-enabled sectors such as tourism, financial services, and maritime logistics, making it particularly vulnerable to a range of cyber threats. These threats carry consequences for small island states that are disproportionate to their size.
The Bahamas noted that its economy depends on digital-enabled sectors including tourism, financial services, port, and maritime logistics, and that it faces ransomware, cybercrime as a service, attacks on critical infrastructure, AI-enabled fraud, mis- and disinformation, and the nexus between cyber threats and natural disasters . The Bahamas stated that all these threats carry consequences for small island states that are disproportionate to their size .
Capacity building is a precondition for participation for small island developing states; it must be sustained, tailored, and directed towards durable institutions and a trained workforce - Capacity building as precondition for SIDS participation (Bahamas)
Arg. 2The Bahamas argues that for small island developing states, capacity building is not merely beneficial but a precondition for meaningful participation in global ICT security discussions and implementation. Such capacity building must be sustained, tailored to national circumstances, and directed towards building durable institutions and a trained workforce.
The Bahamas stated that for small island developing states, capacity building is a precondition for participation, and that it must be sustained, tailored to national circumstances, and directed towards durable institutions and a trained workforce so that developing states can be genuine contributors to global ICT security, not just recipients of it .
International law, including the UN Charter, is the foundation of a secure and peaceful ICT environment; voluntary norms and confidence-building measures operate in service of binding legal obligations - International law as foundation, not constraint (Bahamas)
Arg. 3The Bahamas asserts that international law, including the UN Charter, is the foundation of a secure and peaceful ICT environment and is a guarantee of the process rather than a constraint on it. Voluntary norms and confidence-building measures operate in service of binding legal obligations, not in place of them.
The Bahamas stated that international law, including the UN Charter, is the foundation of a secure and peaceful ICT environment and is the guarantee of this process, not a constraint to it . The Bahamas further stated that voluntary norms and confidence-building measures operate in service of a binding legal obligation, not in place of it .
Cyber threat information sharing should be genuinely accessible to small island states, and work should stay connected to capacity building - Accessible information sharing for small states (Bahamas)
Arg. 4The Bahamas recommends that cyber threat discussions remain grounded in the operational experience of national CERTs and C-CERT networks, and that cyber threat information sharing be genuinely accessible to small island states. This work should remain connected to capacity building to ensure meaningful participation.
The Bahamas recommended that cyber threat discussions remain grounded in the operational experience of national CERTs and C-CERT networks, that cyber threat information sharing be genuinely accessible to small island states, and that this work stay connected to capacity building .
Ransomware and cybercrime-as-a-service, attacks on critical infrastructure, AI-enabled fraud, and the nexus between cyber threats and natural disasters carry disproportionate consequences for small island states - Cybercrime disproportionately affecting small island states (Bahamas)
Arg. 5The Bahamas highlights that the full range of cyber threats, including ransomware, cybercrime-as-a-service, infrastructure attacks, AI-enabled fraud, and the intersection of cyber threats with natural disasters, all carry consequences for small island states that are disproportionate to their size due to limited redundancy and resources.
The Bahamas listed ransomware, cybercrime as a service, attacks on critical infrastructure, AI-enabled fraud, mis- and disinformation, and the nexus between cyber threats and natural disasters as threats that carry consequences for small island states disproportionate to their size .
The United States and Israel carried out extensive malicious cyber operations against Iran's critical infrastructure and civilian services during military attacks, including over 100 cyber attacks per day - US and Israeli cyber attacks against Iran (Islamic Republic of Iran)
Arg. 1Iran alleges that the United States and Israel carried out unlawful military attacks accompanied by extensive malicious cyber operations directed against Iran's critical infrastructure and civilian services. During the February 2026 aggression alone, more than 100 cyber attacks were launched every day against Iran's critical and civilian infrastructure.
Iran stated that during the February 2026 aggression alone, more than 100 cyber attacks were launched every day against Iran's critical and civilian infrastructure . Iran described coordinated cyber and kinetic attacks targeting critical ICT infrastructure including telecommunications facilities, data centres, AI infrastructure, and private sector electronics , as well as attacks against civilian institutions including schools, universities, and media , and attacks exploiting private sector technologies and ICT supply chains including Starlink satellite communication services .
The global mechanism should give priority attention to threats already identified by member states before expanding to new threat areas, using a consolidated compilation as the basis for discussions - Prioritising previously identified threats (Islamic Republic of Iran)
Arg. 2Iran argues that the global mechanism should first give attention to threats already identified by member states in previous processes before expanding to new threat areas. Iran supports the preparation of a consolidated compilation of threats identified by member states as the basis for discussions in both the plenary and dedicated thematic groups.
Iran stated that from the outset of the OEWG process, a number of states including Iran identified specific ICT-related threats that were ultimately not reflected in consensus reports, and that addressing these gaps should be a priority for the global mechanism . Iran supported the preparation of a consolidated compilation of threats identified by member states and reflected in the first OEWG Chair Summary as the basis for discussions .
The use of ICTs for disinformation and cognitive operations, including manipulation of digital platforms to incite violence and spread hatred, represents a significant threat - Disinformation and cognitive operations as ICT threats (Islamic Republic of Iran)
Arg. 3Iran identifies the use of ICTs for disinformation and cognitive operations as a significant threat, including the unlawful use of mobile interception technologies, cyber-enabled surveillance, and the manipulation of digital platforms to incite violence, spread hatred, and deepen social divisions.
Iran described cyber espionage and information operations including the unlawful use of mobile interception technologies, cyber-enabled surveillance, disinformation and cognitive operations, and the manipulation of digital platforms including Instagram, X, and Telegram to incite violence, spread hatred, deepen social divisions, and arbitrarily restrict or remove accounts associated with Iran .
The framework for responsible state behaviour must be implemented consistently; states that advocate respect for international law should apply those principles consistently - Consistent application of responsible state behaviour norms (Islamic Republic of Iran)
Arg. 4Iran argues that states which consistently advocate respect for the UN Charter, international law, and the framework for responsible state behaviour in ICTs should apply those principles consistently and condemn malicious cyber activities directed against Iran. Selective application of these norms undermines their legitimacy.
Iran stated that states which consistently advocate respect for the Charter of the United Nations, international law, and the framework for responsible state behaviour in ICTs should apply those principles consistently and condemn kinetic and malicious cyber activities directed against Iran .
Attacks exploiting private sector technologies and ICT supply chains, including commercial products and services, software, hardware, and digital supply chains, undermine national ICT infrastructure security - Supply chain exploitation as a cyber threat (Islamic Republic of Iran)
Arg. 5Iran highlights attacks that exploit private sector technologies and ICT supply chains, including commercial products and services, software, hardware, and digital supply chains, as well as the misuse of satellite communication services to facilitate hostile operations. Iran is also concerned by cyber operations exploiting commercial technologies from companies such as Cisco and HP.
Iran described attacks exploiting private sector technologies and ICT supply chains, including commercial ICT products and services, software, hardware, and digital supply chains, as well as the misuse of Starlink satellite communication services to facilitate hostile operations . Iran also expressed concern about cyber operations exploiting commercial technologies including products and services supplied by companies such as Cisco and HP to undermine the security and resilience of national ICT infrastructure .
The cyber threat environment continues to intensify, with state-sponsored activity, ransomware, business email compromise, and exploitation of edge devices affecting individuals, businesses, and governments - Intensifying cyber threat environment (Australia)
Arg. 1Australia reports that the cyber threat environment continues to intensify, with individuals, businesses, and governments adversely affected by threats that expose sensitive information, disrupt essential services, undermine trust and economic prosperity, and contribute to risks to international peace and security.
Australia stated that the Australian Cyber Security Centre responded to over 1,200 cybersecurity incidents and received more than 84,700 cybercrime reports in the previous year, roughly one report every six minutes . Australia identified persistent threats including state-sponsored activity targeting government, critical infrastructure and businesses, ransomware and cybercrime as a service, business email compromise, identity fraud, and exploitation of edge devices .
Critical infrastructure and critical information infrastructure protection should be an early focus for the mechanism, including the resilience of undersea cable infrastructure - Undersea cable resilience as a priority (Australia)
Arg. 2Australia argues that critical infrastructure and critical information infrastructure protection should be an early focus for the global mechanism, including through DTG1. For many countries, including Australia and others in the region, the resilience of undersea cable infrastructure is fundamental to economic and social connectivity.
Australia stated that critical infrastructure and critical information infrastructure protection should be an early focus for the mechanism, including through DTG1 . Australia noted that for many countries, including their own in the region, the resilience of undersea cable infrastructure is fundamental to economic and social connectivity and to access to the global internet .
AI is being used to scale social engineering, create convincing phishing content, and lower cost and skill barriers for malicious actors, including for propaganda and physical strike planning - AI enabling malicious actors at scale (Australia)
Arg. 3Australia highlights that AI is being used by malicious actors to scale social engineering, create more convincing phishing content, analyse stolen data, and lower the cost and skill barriers required to cause harm. Australia is particularly concerned that AI is making it easier for malicious actors to generate and spread propaganda and to prepare physical strikes.
Australia stated that artificial intelligence is being used to scale social engineering, create more convincing phishing content, analyse stolen data, and lower the cost and skill barriers required to cause harm . Australia expressed particular concern that AI is making it easier for malicious actors to generate and spread propaganda and to prepare to carry out physical strikes by supporting planning and target selection .
State responses, including development and use of cyber capabilities, must be consistent with international law, including the UN Charter, international human rights law, and international humanitarian law - State cyber capabilities must comply with international law (Australia)
Arg. 4Australia underlines the importance of responding to cyber threats in line with the agreed norms of responsible state behaviour, and that state responses, including the development and use of cyber capabilities, must be consistent with international law including the UN Charter, international human rights law, and international humanitarian law.
Australia stated that state responses, including the development and use of cyber capabilities, must be consistent with international law, including the UN Charter in its entirety, international human rights law, and international humanitarian law .
Differences in national capacity affect vulnerability to malicious cyber activity and the ability to recover; cyber threats are shared but their impacts are not experienced equally - Unequal impact of cyber threats and capacity gaps (Australia)
Arg. 5Australia acknowledges that while cyber threats are shared across all states, their impacts are not experienced equally. Differences in national capacity can affect vulnerability to malicious cyber activity and the ability to recover when incidents occur, making capacity building an essential component of the mechanism's work.
Australia stated that cyber threats are shared, but their impacts are not experienced equally, and that differences in national capacity can affect vulnerability to malicious cyber activity and the ability to recover when incidents occur .
Cyber attacks using ransomware targeting critical infrastructure such as hospitals and power plants can pose a threat to international peace and security - Ransomware as a threat to international peace and security (Japan)
Arg. 1Japan argues that ransomware attacks, particularly when they impact the operations of critical infrastructure such as hospitals and power plants, can pose a direct threat to international peace and security. Japan seeks to foster this common understanding within the UN global mechanism.
Japan referenced its statement at the Security Council briefing on ransomware on 8 November 2024, where it stated that ransomware is one of the most destructive cyber threats undermining the operations of critical infrastructure including hospitals and power plants, and that given the overall impacts and ramifications, ransomware could certainly pose direct threats to international peace and security .
It is important to foster common understanding on existing and potential cyber threats in the UN global mechanism, drawing on expertise from a wide range of stakeholders including the private sector - Common understanding through multi-stakeholder engagement (Japan)
Arg. 2Japan emphasises the importance of fostering common understanding on existing and potential cyber threats within the UN global mechanism, and argues that this requires drawing on the expertise of a wide range of stakeholders including the private sector. Japan places great importance on expert briefings and interactive public-private discussions.
Japan stated that it is essential to draw on the expertise of a wide range of stakeholders, including the private sector, in conducting discussions on cyber threats . Japan also stated that it places great importance on holding expert briefings and interactive public-private discussions in the substantive plenary sessions and DTGs .
The mechanism should allow sufficient time and opportunities for relevant technological experts to provide professional presentations, including as part of DTG work - Expert briefings within the mechanism (Japan)
Arg. 3Japan argues that the fast pace of technological development necessitates that discussions within the global mechanism be informed by thorough and up-to-date technical information. The mechanism should therefore allow sufficient time and opportunities for relevant technological experts to provide professional presentations.
Japan stated that it is essential to draw on the expertise of a wide range of stakeholders, including the private sector, and that Japan places great importance on holding expert briefings and interactive public-private discussions in the substantive plenary sessions and DTGs .
The threat landscape is evolving rapidly due to growing ICT capabilities without concomitant oversight and governance structures - Governance gap in ICT development (Guyana)
Arg. 1Guyana argues that the ICT threat landscape is evolving rapidly due to growing developments in ICT capabilities without corresponding oversight and governance structures. Effectively addressing existing and potential threats requires the integration of security considerations across the lifecycle of ICT products.
Guyana stated that the ICT threat landscape is evolving rapidly due to growing developments in ICT capabilities without concomitant oversight and governance structures, and that effectively addressing existing and potential threats requires integration of security considerations across the lifecycle of ICT products .
The use of ICTs by non-state actors to exacerbate conflicts, including attacks targeting civilian objects, requires a holistic approach considering the transboundary nature of threats - Non-state actor exploitation of ICTs in conflicts (Guyana)
Arg. 2Guyana expresses particular concern about the malicious use of ICTs against critical infrastructure and the use of this technology by non-state actors to exacerbate conflicts, including through attacks targeting civilian objects. A holistic approach is required to address these threats given their multifaceted and transboundary nature.
Guyana stated that it is particularly concerned about the malicious use of ICTs against critical infrastructure and critical information infrastructure, and the use of this technology by non-state actors to exacerbate conflicts, including through attacks targeting civilian and civilian objects . Guyana called for a holistic approach considering the multifaceted challenges and transboundary nature of these threats .
Awareness, capacity building, international cooperation, and public-private partnerships are essential for detecting, defending, and responding to threats at national, regional, and international levels - Multi-level approach to threat response (Guyana)
Arg. 3Guyana argues that a comprehensive multi-level approach is required to address ICT threats, encompassing awareness, capacity building, international cooperation, public-private partnerships, and continued dialogue among relevant stakeholders at national, regional, and international levels.
Guyana stated that awareness, capacity building, international cooperation, public-private partnerships, and continued dialogue among relevant stakeholders are essential for detecting, defending, and responding to threats, and that these efforts must be made at the national, regional, and international levels .
The misuse of AI, including through autonomous cyber tools and frontier models, can amplify existing vulnerabilities and undermine democratic processes and human rights - AI misuse undermining democratic processes (Greece)
Arg. 1Greece highlights that while AI offers great potential for innovation and global progress, its misuse through autonomous cyber tools and the advancement of frontier models can amplify existing vulnerabilities and undermine democratic processes and human rights. These capabilities are expected to soon become widely available, significantly lowering the entry barrier for sophisticated attacks.
Greece stated that the misuse of AI, such as through autonomous cyber tools and the recent advancement of frontier models, can amplify existing vulnerabilities and undermine democratic processes and human rights . Greece noted that these capabilities are expected to soon become widely available and significantly lower the entry barrier for actors to perform sophisticated attacks .
The commercial distribution of cyber capabilities has the potential to undermine privacy, human rights, and democratic institutions when deployed without adequate safeguards - Commercial cyber tools undermining human rights (Greece)
Arg. 2Greece identifies the proliferation of commercial cyber tools and capabilities as an important concern, noting that their commercial distribution has the potential to undermine privacy, human rights, democratic institutions, and international security when deployed without adequate safeguards. Greece welcomes initiatives such as the Pall Mall process to build international consensus on responsible use.
Greece stated that the commercial distribution of cyber capabilities has the potential to undermine privacy, human rights, democratic institutions, and international security when deployed without adequate safeguards . Greece welcomed initiatives such as the Pall Mall process, which seeks to build international consensus on the responsible development, distribution, and use of commercial cyber intrusion capabilities .
This mechanism succeeds by building on the consensus already achieved, not by searching for gaps; it should focus on practical implementation of the 11 consensus norms - Building on existing consensus rather than new agreements (United States)
Arg. 1The United States argues that the global mechanism should be grounded in practical implementation of the 11 consensus norms rather than serving as a vehicle for new legally binding agreements. The mechanism was established to do real work implementing commitments states have already made, not to search for gaps that do not exist.
The United States stated that it continues to approach the mechanism with the objective of grounded practical implementation of the 11 consensus norms, not as a vehicle for new legally binding agreements, noting that as long as some members are maliciously conducting cyber actions against other members, a legally binding agreement is impossible . The United States stated that this mechanism succeeds by building on the consensus already achieved, not by searching for gaps that do not exist .
States should not conduct or knowingly support malicious cyber activity targeting critical infrastructure; some members in this chamber are planning and conducting such actions - Condemnation of malicious cyber activities by member states (United States)
Arg. 2The United States asserts that states should not conduct or knowingly support malicious cyber activity targeting critical infrastructure, yet alleges that some members in the chamber are currently planning and conducting such actions against other members' critical infrastructure. The United States commits to identifying and holding accountable those perpetrating such activities.
The United States stated that states should not conduct or knowingly support malicious cyber activity targeting critical infrastructure, but that there are members in the chamber right now who are planning and conducting malicious cyber actions against other members' critical infrastructure . The United States stated it would work to specifically identify the states and non-state actors who are perpetuating malicious cyber activities against others in the room .
The mechanism should focus on tangible outcomes including shared threat intelligence, clear protocols for protecting subsea infrastructure, and the development of local expertise - Action-oriented mechanism with concrete outcomes (Tuvalu)
Arg. 1Tuvalu emphasises that norms, international law, and capacity building cannot be treated as separate silos, and urges the global mechanism to focus on tangible outcomes including shared threat intelligence, clear protocols for protecting subsea infrastructure, and the development of local expertise. Tuvalu stands ready to engage constructively to ensure the mechanism serves as a driver of meaningful action.
Tuvalu urged the global mechanism to focus on tangible outcomes including shared threat intelligence, clear protocols for protecting subsea infrastructure like the Aotevaca Cable, and the development of local expertise . Tuvalu emphasised that norms, international law, and capacity building cannot be treated as separate silos, in line with the integrated approach of A-79-214 and A-80-257 .
For developing countries, capacity constraints and uneven cyber resilience increase vulnerability and limit the ability to respond effectively to cyber incidents - Capacity constraints in developing countries (Zimbabwe)
Arg. 1Zimbabwe highlights that for developing countries, capacity constraints and uneven cyber resilience increase vulnerability and limit the ability to respond effectively to cyber incidents, risking progress towards digital transformation and sustainable development. Developing countries cannot afford to be left exposed or left behind.
Zimbabwe stated that for developing countries, capacity constraints and uneven cyber resilience increase vulnerability and limit the ability to effectively respond to cyber incidents, risking progress towards digital transformation and sustainable development . Zimbabwe stated that they cannot afford to be left exposed, nor can they afford to be left behind .
Protecting critical ICT infrastructure and strengthening cybersecurity resilience are national priorities, particularly as a land-linked developing country relying on interconnected regional networks - Cross-border infrastructure vulnerabilities for developing countries (Zimbabwe)
Arg. 2Zimbabwe emphasises that as a land-linked developing country relying on interconnected regional telecommunications networks for connectivity, trade, and essential services, protecting critical ICT infrastructure and strengthening cybersecurity resilience are national priorities. Vulnerabilities within shared digital infrastructure can have cross-border consequences.
Zimbabwe stated that as a land-linked developing country that relies on interconnected regional telecommunications networks for connectivity, trade, and essential services, vulnerabilities within shared digital infrastructure can have cross-border consequences . Zimbabwe noted that this reinforces the importance of enhancing regional cooperation and building the technical capacity of developing countries to prevent, detect, and respond to malicious ICT activity .
The spread of disinformation and misinformation through digital platforms, and the rapid advancement and malicious use of AI reshaping the cyber threat landscape, are of growing concern - Disinformation and AI-enabled deception (Zimbabwe)
Arg. 3Zimbabwe expresses concern about the spread of disinformation and misinformation through digital platforms, as well as the rapid advancement and malicious use of artificial intelligence, which is reshaping the cyber threat landscape by enabling more convincing deception and introducing fresh complexities for cybersecurity resilience and response.
Zimbabwe stated that it is concerned by the spread of disinformation and misinformation through digital platforms . Zimbabwe also stated that it is equally concerned by the rapid advancement and malicious use of artificial intelligence, which is reshaping the cyber threat landscape, enabling more convincing deception, and introducing fresh complexities for cybersecurity resilience and response .
Albania observed state-sponsored cyber operations against public institutions, combined with disinformation campaigns via Telegram to amplify psychological impact and erode public trust - State-sponsored attacks combined with disinformation (Albania)
Arg. 1Albania reports that recent cyber incidents against public institutions were supported by state-sponsored cyber operations, and were followed by attempts to spread disinformation and manipulate public perception through social media platforms, specifically via Telegram. These activities sought to amplify the psychological impact of cyber incidents and erode trust in public institutions.
Albania stated that recent incidents, four of them only in March 2026, targeted public institutions including the Albanian parliament, Albanian post office, the office of the general prosecutor, and the director of prisons, and were supported by state-sponsored cyber operations . Albania observed attempts to spread disinformation and manipulate public perception through social media and communication platforms, specifically via Telegram, following these incidents .
Contemporary cyber threats increasingly combine cyber operations with information manipulation activities, seeking to amplify psychological impact and erode trust in public institutions - Combination of cyber operations and disinformation (Albania)
Arg. 2Albania argues that contemporary cyber threats are no longer limited to technical intrusions but increasingly combine cyber operations with disinformation and influence activities. This combination seeks to amplify the psychological impact of cyber incidents, generate public uncertainty, and erode trust in public institutions.
Albania stated that a particularly concerning trend is the continued combination of cyber operations with information manipulation activities, and that following cyber incidents, Albania observed attempts to spread disinformation and manipulate public perception through social media and communication platforms, specifically via Telegram . Albania stated that these activities demonstrate that contemporary cyber threats are no longer limited to technical intrusions but increasingly combine cyber operations, disinformation, and influence activities .
The impact of militant online activity on young people, including cyberbullying and deliberate spread of disinformation, represents an emerging security concern deserving greater international attention - Online harms to youth as an emerging security concern (Albania)
Arg. 3Albania highlights the growing impact of militant online activity on young people, including the rapid spread of disinformation, manipulation of online content, and cyberbullying through social media and digital platforms. Albania argues that these phenomena represent not only a social issue but an emerging security concern that deserves greater international attention.
Albania stated that the rapid spread of disinformation, manipulation of online content, and cyberbullying through social media and digital platforms pose increasingly serious risks to the safety, well-being, and resilience of younger generations . Albania stated that the use of AI has made the ecosystem even more insecure and has increased the exposure of young people who are more easily manipulated online .
Ensuring states act responsibly in cyberspace, refrain from supporting malicious activities, and cooperate in addressing threats is essential for preserving international peace and security - State responsibility and cooperation for peace (Albania)
Arg. 4Albania argues that ensuring states act responsibly in cyberspace, refrain from supporting malicious activities, and cooperate in addressing threats is essential for preserving international peace, security, and stability in an increasingly interconnected world. Albania remains fully committed to working constructively with the global mechanism and all partners.
Albania stated that ensuring states act responsibly in cyberspace, refrain from supporting malicious activities, and cooperate in addressing threats is essential for preserving international peace, security, and stability in an increasingly interconnected world .
The use of ICTs for purposes contradicting the UN Charter, including undermining sovereignty and interfering in internal affairs, represents the greatest danger in the current threat landscape - ICT misuse against UN Charter principles (Russian Federation)
Arg. 1The Russian Federation argues that the greatest danger in the current threat landscape lies in the use of ICTs for purposes that contradict the UN Charter, specifically to undermine the sovereignty of states, violate their territorial integrity, and interfere in their internal affairs. This represents the core threat that the global mechanism should address.
The Russian Federation stated that the greatest danger lies in the use of ICTs for purposes that contradict the UN Charter to undermine the sovereignty of states, violate their territorial integrity, and interfere in their internal affairs .
The monetisation of the private sector, with major ICT developers embedded in military-industrial complexes and acting as contractors for intelligence agencies, creates serious risks for international stability - Militarisation of private ICT sector (Russian Federation)
Arg. 2The Russian Federation highlights a dangerous trend in which major ICT developers, including AI companies, are deeply embedded in the military-industrial complexes of the countries where they are registered and act as contractors for intelligence agencies and military departments. This undermines trust in their products and creates serious risks for international stability and security.
The Russian Federation stated that major ICT developers which supply their products throughout the world, including AI, now make no secret of how deeply they are embedded in the military-industrial complexes of the countries where they are registered, and often act as contractors for intelligence agencies and military departments . The Russian Federation stated that this situation predictably undermines trust in the products of these companies and creates serious risks for international stability and security .
Accusations against states should be substantiated with evidence; no evidence has been provided through existing channels including the UN Points of Contact Directory - Requirement for substantiated evidence in attributions (Russian Federation)
Arg. 3The Russian Federation argues that accusations of organising and implementing wrongful acts brought against states should be substantiated with evidence, as required by UNGA Resolution 73/27. The Russian Federation contends that no evidence has been provided either publicly or bilaterally, nor have existing channels for identifying the true sources of malicious activity been used.
The Russian Federation stated that in accordance with UNGA Resolution 73/27, accusations of organising and implementing wrongful acts brought against states should be substantiated, and that no evidence has been provided neither in public nor bilaterally, nor have the existing channels for identifying the true sources of malicious activity been used, including the UN Points of Contact Directory .
on: Attribution of state-sponsored cyber attacks and the evidentiary standard required
The issue of undeclared malicious capabilities, including backdoors embedded by developers for intelligence agencies without notifying end users, is used for espionage and physical damage - Backdoors and undeclared malicious capabilities (Russian Federation)
Arg. 4The Russian Federation highlights the growing problem of undeclared malicious capabilities, including backdoors embedded at the software and hardware levels by developers in the interests of intelligence agencies without notifying end users. Such tools are used for intelligence, espionage, interception of personal data, and as demonstrated by the Pager incident in Lebanon in 2024, for causing physical damage.
The Russian Federation stated that the international community is increasingly confronting the problem of so-called backdoors at the software and hardware levels embedded by developers in the interests of intelligence agencies without notifying end users . The Russian Federation cited the Pager incident in Lebanon in 2024 as an example of such tools being used for causing physical damage .
Low-orbit satellite communication systems created under the pretext of civilian connectivity are used for military-political objectives and interference in internal affairs of states - Militarisation of low-orbit satellite systems (Russian Federation)
Arg. 5The Russian Federation argues that low-orbit satellite communication systems, created under the pretext of providing reliable internet connectivity for civilian purposes, are in fact used for military-political objectives and to interfere in the internal affairs of states. The Russian Federation calls for operators of such systems to act in strict accordance with the national legislation of the countries in which they provide services.
The Russian Federation stated that low-orbit satellite communication systems are in fact used for military-political objectives in the interests of certain countries, and cited cases in which such systems have been used to interfere in the internal affairs of states by inciting protests, as well as their use in armed conflicts . The Russian Federation noted that this topic was discussed at an informal UN Security Council meeting in December 2025 .
Addressing ransomware requires timely information sharing, strengthened incident response capabilities, public-private partnerships, technical assistance, and sustainable capacity building - Practical cooperation to address ransomware (Philippines)
Arg. 1The Philippines highlights ransomware as an area where practical implementation and international cooperation can deliver immediate benefits. Addressing ransomware requires a comprehensive approach including timely information sharing, strengthened incident response capabilities, public-private partnerships, technical assistance, and sustainable capacity building.
The Philippines stated that addressing ransomware requires timely information sharing, strengthened incident response capabilities, public-private partnerships, technical assistance, and sustainable capacity building . The Philippines noted that given the transnational nature of ransomware, continued cooperation among member states remains essential to strengthening collective resilience .
Russia's ongoing war of aggression against Ukraine includes deliberate targeting of critical infrastructure, telecommunications, and state registries as part of a broader hybrid warfare strategy - Russian cyber aggression as part of hybrid warfare (Ukraine)
Arg. 1Ukraine argues that for over a decade, cyberspace has been one of the principal theatres of Russia's ongoing war of aggression against Ukraine, with Russian malicious ICT activities forming part of a broader strategy combining cyberattacks with kinetic strikes, disinformation campaigns, and other hybrid warfare tools. Since the full-scale invasion, Russia has deliberately targeted public authorities, critical infrastructure, and private businesses in Ukraine and beyond.
Ukraine stated that for over a decade, cyberspace remains one of the principal theatres of Russia's ongoing war of aggression against Ukraine, and that Russian malicious ICT activities are not isolated incidents but form part of a broader strategy combining cyberattacks with kinetic strikes, disinformation campaigns, and other hybrid warfare tools . Ukraine stated that since the beginning of the full-scale invasion, Russia has deliberately targeted public authorities, critical infrastructure, energy sector, telecommunications networks, state registries, and private businesses in Ukraine and beyond .
Hybrid campaigns combining cyber operations, disinformation, and economic coercion seek to undermine international peace and security - Hybrid campaigns as a systemic threat (Ukraine)
Arg. 2Ukraine highlights that it continues to witness hybrid campaigns combining cyber operations, disinformation, and economic coercion that seek to undermine international peace and security. These campaigns, combined with rapid technological developments including AI and quantum technologies, create unprecedented challenges for the international community.
Ukraine stated that it continues to witness hybrid campaigns combining cyber operations, disinformation, and economic coercion that seek to undermine international peace and security . Ukraine noted that rapid technological developments including artificial intelligence, quantum technologies, and increasingly interconnected digital ecosystems create unprecedented opportunities for innovation while simultaneously expanding the attack surface available to malicious actors .
Malicious ICT activities are not isolated incidents but form part of broader strategies combining cyberattacks with kinetic strikes, disinformation, and hybrid warfare tools - Hybrid warfare combining cyber and kinetic operations (Ukraine)
Arg. 3Ukraine argues that malicious ICT activities are not isolated incidents but form part of broader strategies that combine cyberattacks with kinetic strikes, disinformation campaigns, and other hybrid warfare tools. Over time, Russia's cyber operations have evolved from destructive attacks into sophisticated campaigns involving cyber espionage, long-term network persistence, supply chain compromise, and information manipulation.
Ukraine stated that Russian malicious ICT activities are not isolated incidents but form part of a broader strategy that combines cyberattacks with kinetic strikes, disinformation campaigns, and other hybrid warfare tools . Ukraine noted that over time, Russia's cyber operations have evolved from destructive attacks into sophisticated campaigns involving attempts for cyber espionage, long-term network persistence, supply chain compromise, and information manipulation .
Critical infrastructure protection represents a national priority and an essential component of international security, with digitisation increasing the risk of systemic effects - Critical infrastructure as a national and international security priority (Chile)
Arg. 1Chile argues that the protection of critical infrastructure represents both a national priority and an essential component of international security in the use of ICTs. The gradual digitisation and interconnection of critical sectors increases the possibility of attacks and the risk of cyber incidents having systemic effects, impacting the provision of essential services.
Chile stated that for Chile, the protection of critical infrastructure represents a national priority and an essential component of international security in the use of ICTs . Chile noted that the gradual digitisation and interconnection of critical sectors increases the possibility of attacks and the risk of cybernetic incidents having systemic effects, impacting the provision of services that are essential for the population .
AI is changing the reach of malicious cyber attacks, contributing to phishing, malicious software, and sophisticated attacks, and must be understood as multiplying existing threats - AI as a multiplier of existing threats (Chile)
Arg. 2Chile notes that AI is changing the reach of malicious cyber attacks and making it easier for them to adapt, contributing to the expansion of phishing attacks, malicious software, and increasing the sophistication of cyber attacks. AI must be understood as having the potential to multiply existing threats and as a source of new risk factors and vectors.
Chile stated that AI is changing the reach of malicious cybernetic attacks and making it easier for them to adapt, and that AI is contributing to the expansion of phishing attacks, malicious software, and increasing the sophistication of cybernetic attacks, as well as fostering the dissemination of manipulated content . Chile stated that AI must be understood as having the potential to multiply existing threats and also as a source of new risk factors and vectors .
Future risks related to quantum computing, alongside ransomware, exploitation of digital supply chains, and cloud-connected software, require continued attention - Quantum computing as a future risk factor (Chile)
Arg. 3Chile argues that it is necessary to keep attention on ransomware and other destructive forms of malicious software, the exploitation of the digital supply chain, cloud-connected software, and future risks related to quantum computing. These topics have already been identified by Chile as requiring continued attention.
Chile stated that it is necessary to dedicate attention to ransomware and other destructive forms of malicious software, the exploitation of the digital supply chain, cloud-connected software, and future risks related to quantum computing, amongst others, and that these topics have already been identified by Chile as requiring continued attention .
The first DTG provides a particularly valuable opportunity for regular, structured, evidence-based dialogue on the evolution of threats, with a forward-looking approach and expert participation - Evidence-based forward-looking dialogue in DTG1 (Chile)
Arg. 4Chile argues that the dedicated thematic group focused on policies and cross-cutting issues provides a particularly valuable opportunity for driving regular, structured, evidence-based dialogue on the evolution of threats and their implications for international peace and security. This work should have a forward-looking approach and incorporate evidence and information from experts, regional organisations, the scientific community, and the private sector.
Chile stated that the dedicated thematic group number one gives a particularly valuable opportunity for driving regular, structured dialogue that is evidence-based on the evolution of threats and their implications for international peace and security . Chile stated that a substantive discussion on emerging threats requires incorporating evidence and information that very often lies outside of government, and that the participation of experts, regional organisations, the scientific community, the private sector, and other interested parties is essential .
Malicious ICT activities are becoming increasingly sophisticated, persistent, and transnational, with growing misuse of AI, ransomware, and supply chain compromises - Growing sophistication and persistence of threats (Malawi)
Arg. 1Malawi highlights that malicious ICT activities are becoming increasingly sophisticated, persistent, and transnational, with the growing misuse of AI, ransomware, supply chain compromises, attacks on critical infrastructure, and attacks on undersea cables and cloud services demonstrating that no state is immune.
Malawi stated that malicious ICT activities are becoming increasingly sophisticated, persistent, and transnational, and that the growing misuse of artificial intelligence, ransomware, supply chain compromises, attacks on critical infrastructure, computer emergency response teams, undersea cables, and cloud services demonstrates that no state is immune .
Strengthening national CERTs, enhancing cyber threat intelligence, promoting early warning mechanisms, and improving trusted information sharing should feature prominently in the mechanism's work - Strengthening national response capabilities (Malawi)
Arg. 2Malawi argues that the global mechanism's work should prominently feature the strengthening of national computer emergency response teams, enhancing cyber threat intelligence, promoting early warning mechanisms, and improving trusted information sharing. Resilient response capabilities are just as important as resilient infrastructure.
Malawi stated that strengthening national computer emergency response teams, enhancing cyber threat intelligence, promoting early warning mechanisms, and improving trusted information sharing should feature prominently in the work of the dedicated thematic group . Malawi stated that resilient response capabilities are just as important as resilient infrastructure .
AI is lowering barriers for malicious actors to conduct phishing, malware development, fraud, and disinformation at unprecedented speeds and scale - AI enabling malicious activities at unprecedented scale (Malawi)
Arg. 3Malawi recognises both the opportunities and risks of AI, noting that while AI can significantly strengthen cyber defence, it is also lowering the barriers for malicious actors to conduct phishing, malware development, fraud, and disinformation at unprecedented speeds and scale. Discussions should focus on enabling responsible innovation while preventing malicious use.
Malawi stated that AI is lowering the barriers for malicious actors to conduct phishing, malware development, fraud, and disinformation at unprecedented speeds and scale . Malawi stated that discussions should focus on enabling responsible innovation while preventing malicious use .
France has been the target of persistent cyber attacks by Russia's FSB for over ten years; attribution was conducted in accordance with responsible state behaviour norms - Attribution of Russian FSB cyber attacks against France (France)
Arg. 1France reports that on 13 July it announced it had been the target for more than ten years of persistent cyber attacks carried out by Russia's Federal Security Service (FSB). France emphasises that this attribution process was conducted in accordance with the norms for responsible state behaviour and following having exhausted appropriate channels.
France announced that on 13 July, France announced that it had been the target for more than 10 years of persistent cyber attacks carried out by the Russian Federal Security Service, the FSB . France stated that contrary to what the Russian Federation has stated, this attribution process was conducted in accordance with the norms for responsible state behaviour and following having exhausted appropriate channels .
AI is increasing the speed of offensive operations and enabling scaling of existing practices, while the rapid increase in frontier model capabilities risks creating a new digital divide - AI acceleration of offensive operations and digital divide (France)
Arg. 2France identifies AI as increasing the speed at which malicious actors can conduct offensive operations and enabling the scaling up of existing practices such as seeking vulnerabilities. More importantly, the rapid increase in cyber capabilities of AI frontier models carries the risk of creating a new digital divide between those who have access to these models and those who do not.
France stated that while AI is not yet fundamentally altering the nature of attacks, it is increasing the speed at which malicious actors can conduct offensive operations and enabling the scaling up of existing practices such as seeking vulnerabilities . France stated that the rapid increase in cyber capabilities of AI frontier models carries the risk of a new digital divide between those who have access to these models and those who are able to independently assess the risks associated with them .
The uncontrolled proliferation of commercial cyber intrusion capabilities without adequate oversight and accountability measures multiplies risks to the stability of cyberspace - Uncontrolled proliferation of commercial cyber tools (France)
Arg. 3France identifies the uncontrolled proliferation of cyber intrusion capabilities available on the market as a veritable ticking time bomb. Without minimal oversight and accountability measures, the number of actors, including non-state actors, capable of acquiring advanced capabilities will continue to grow, multiplying risks to the stability of cyberspace.
France stated that without minimal oversight and accountability measures, the number of actors, including non-state actors, capable of acquiring advanced capabilities will continue to grow, multiplying the risks to the stability of cyberspace . France shared progress made with the United Kingdom as part of the Pall Mall process, including the launch of negotiations on guidelines for the cyber intrusion industry .
Ransomware paralysing humanitarian and critical services - Ransomware paralysing humanitarian and critical services (Germany)
Arg. 1Germany highlights that ransomware attacks have paralysed not only government and critical infrastructure providers but also not-for-profit organisations, including a leading humanitarian organisation providing food relief in conflict regions, putting people's lives abroad at risk.
Germany stated that over the past year, it has experienced a continuously high level of ransomware attacks targeted especially at critical infrastructure providers, municipal and government services, and not-for-profit organisations . Germany cited a specific example of a ransomware attack that paralysed a leading humanitarian organisation providing food relief in conflict regions, with risks of famine and putting people's lives abroad at risk .
Russian state-sponsored attacks on EU and Ukraine - Russian state-sponsored attacks on EU and Ukraine (Germany)
Arg. 2Germany reports that together with the European Union and its member states and the North Atlantic Council, it has exposed and condemned a series of malicious cyber activities conducted by Russian state actors, in particular the FSB, and by state-supported cyber criminal and hacktivist groups. These activities targeted government entities and critical infrastructure in several EU member states and in Ukraine.
Germany stated that together with the European Union and its member states and the North Atlantic Council, Germany exposed and condemned a series of malicious cyber activities conducted by Russian state actors, in particular the FSB, and by state-supported cyber criminal and hacktivist groups . Germany noted that these activities targeted government entities and critical infrastructure in several EU member states and in Ukraine, some of which had the potential for catastrophic damage of civilian energy infrastructure such as electricity networks or hydroelectric dams .
AI lowering barriers for malicious actors (Germany)
Arg. 3Germany observes that the advent of advanced AI facilitates large-scale attacks including language-agnostic credible phishing, voice phishing, and social engineering attacks, continuously lowering the barrier to entry for opportunistic malicious cyber actors. This creates an increasing strain on defenders' resources and puts particular strain on less resourced and small countries.
Germany stated that the advent of advanced cyber capabilities facilitates large-scale attacks including language-agnostic credible phishing, voice phishing, and social engineering attacks, and that the barrier to entry for opportunistic malicious cyber actors is continuously lowered . Germany noted an increasing strain on defenders' resources and on maintainers of open source repositories, which puts particular strain on less resourced and small countries .
on: Artificial intelligence is transforming the cyber threat landscape by lowering barriers for malicious actors and amplifying existing threats, while also offering defensive opportunities
Cyber threats have become persistent challenges affecting national security, economic stability, and social cohesion, with ransomware remaining one of the most pervasive threats - Persistent and pervasive cyber threats (Latvia)
Arg. 1Latvia reports that cyber threats have become persistent challenges affecting national security, economic stability, and social cohesion, with a recent ransomware attack on state information systems serving as a reminder of this reality. Ransomware remains one of the most pervasive threats, with criminal groups having developed industrial-scale operations.
Latvia stated that in Latvia, a recent ransomware attack on state information systems once again reminded them of the reality of cyber threats . Latvia stated that ransomware remains one of the most pervasive threats, with criminal groups having developed industrial-scale operations leveraging encryption, infostealer malware, data theft, and extortion to generate enormous profits .
Criminal groups have developed industrial-scale ransomware operations leveraging encryption, infostealer malware, data theft, and extortion to generate enormous profits - Industrial-scale ransomware criminal operations (Latvia)
Arg. 2Latvia highlights that criminal groups have developed industrial-scale ransomware operations, leveraging encryption, infostealer malware, data theft, and extortion to generate enormous profits. State-linked cyber operations also pose significant risks, with incidents targeting electoral systems, public administration, and critical infrastructure.
Latvia stated that criminal groups have developed industrial-scale operations, leveraging encryption, infostealer malware, data theft, and extortion to generate enormous profits . Latvia also noted that state-linked cyber operations pose significant risks, with incidents targeting electoral systems, public administration, and critical infrastructure raising concerns about the potential for destabilisation .
AI-enabled tools can automate reconnaissance, accelerate vulnerability discovery, and generate highly convincing phishing campaigns, overwhelming cyber defenders' capacity to respond - AI supercharging malicious cyber activities (Latvia)
Arg. 3Latvia highlights that AI is transforming the cyber threat landscape as a whole, with AI-enabled tools capable of automating reconnaissance, accelerating and scaling vulnerability discovery, and generating highly convincing phishing campaigns. The access to and ease of use of AI-enabled tools supercharges the potential vectors and scale of malicious cyber activities, which can overwhelm cyber defenders' capacity to respond.
Latvia stated that AI-enabled tools can automate reconnaissance, accelerate and scale vulnerability discovery, and generate highly convincing phishing campaigns . Latvia stated that the access to and ease of use of AI-enabled tools supercharges the potential vectors and scale of malicious cyber activities, which can overwhelm cyber defenders' capacity to respond .
The DTGs should focus on specific ICT security challenges, enabling states to examine threats, share experience, develop practical approaches, and turbocharge capacity-building efforts - DTGs as vehicles for practical action (Latvia)
Arg. 4Latvia argues that the dedicated thematic groups should be central to achieving an action-oriented approach, focusing on specific ICT security challenges and enabling states to examine threats, share experience, and develop practical approaches. The DTGs should also help turbocharge capacity-building efforts, recognising that global cyber resilience depends on ensuring all states can protect their digital infrastructure.
Latvia stated that the DTGs should focus on specific ICT security challenges, enabling states to examine threats, share experience, and develop practical approaches . Latvia stated that the DTGs should also be focused on the development of new technologies and help turbocharge capacity-building efforts, recognising that global cyber resilience depends on ensuring that all states can protect their digital infrastructure .
Israel's actions were conducted in accordance with international law in the context of an ongoing armed conflict with Iran, which has been waging hostility across all domains including cyber - Israeli actions conducted within international law (Israel)
Arg. 1Israel asserts that its actions during operations Rising Lion and Roaring Lion were conducted in accordance with international law, including the UN Charter and the laws of armed conflict, in the context of an ongoing armed conflict with Iran. Israel argues that Iran has been waging hostility against Israel across all domains of warfare, including the cyber domain.
Israel stated that its actions during operations Rising Lion and Roaring Lion were conducted in accordance with international law, including the UN Charter and the laws of armed conflict, and were carried out in the context of an ongoing armed conflict with Iran . Israel stated that Iran has been waging against Israel, together with its non-state terrorist armed groups and proxies, while bluntly violating international law .
Certain states grant absolute impunity to criminal syndicates and terrorist proxies offering hacking as a service, operating from state-sanctioned safe havens - State-sanctioned safe havens for cybercriminals (Israel)
Arg. 2Israel identifies as a substantial threat the absolute impunity granted by certain states to criminal syndicates and terrorist proxies offering hacking as a service, which operate from state-sanctioned safe havens. Israel also highlights the illicit financing of these operations via digital assets as a global trend that should preoccupy the global mechanism's discussions.
Israel stated that another substantial threat is the absolute impunity granted by certain states to criminal syndicates and terrorist proxies offering hacking as a service, which operate from state-sanctioned safe havens . Israel noted that the illicit financing of these operations via digital assets is a global trend which should preoccupy the global mechanism discussions, including on international cooperation relating to tracking, freezing, and seizing of cryptocurrencies used for illicit activities .
Frontier AI capabilities as a security risk (Canada)
Arg. 1Canada highlights that frontier AI models have displayed unprecedented capabilities in autonomous vulnerability discovery, zero-day vulnerability exploit generation, and multi-stage orchestration of malicious cyber activity. Canada notes a joint statement issued by cybersecurity agencies of Canada, the United States, the United Kingdom, New Zealand, and Australia on the risks posed by rapidly accelerating offensive and defensive capabilities of frontier AI models.
Canada noted the joint statement issued by the cybersecurity agencies of Canada, the United States, the United Kingdom, New Zealand, and Australia on the risks posed by rapidly accelerating offensive and defensive capabilities of frontier AI models to the security of information technology and critical infrastructure worldwide . Canada stated that these models have displayed unprecedented capabilities in autonomous vulnerability discovery, zero-day vulnerability exploit generation, and multi-stage orchestration of malicious cyber activity .
on: Artificial intelligence is transforming the cyber threat landscape by lowering barriers for malicious actors and amplifying existing threats, while also offering defensive opportunities
Growing threats to critical infrastructure (Canada)
Arg. 2Canada observes that cyber threats to its critical infrastructure are almost certainly increasing, with primary threats coming from cyber criminals, state-sponsored actors, and increasingly non-state actors. Canada also notes the growing threat from large-scale covert networks of internet-connected devices used to disguise the origins and attributions of cyber attacks.
Canada stated that in Canada, cyber threats to critical infrastructure are almost certainly increasing, and that primary threats to these systems come from cyber criminals, state-sponsored actors, and increasingly non-state actors . Canada noted that it has joined the United Kingdom Joint Cyber Advisory on defending against state-linked covert networks, which warns of large-scale covert networks of internet-connected devices being used to disguise the origins and attributions of cyber attacks .
on: The blurring of lines between state and non-state actors, including the use of proxies, is a growing and concerning trend in the cyber threat landscape
The cyber threat landscape is characterised by increasingly sophisticated attacks, including APTs, ransomware, and phishing, posing serious risks to critical infrastructure and essential services - Sophisticated threats to critical infrastructure (Indonesia)
Arg. 1Indonesia reports that the landscape of existing and potential ICT threats continues to evolve rapidly, with growing sophistication of malicious activities including advanced persistent threats, ransomware, and phishing posing serious risks. Threats targeting critical infrastructure and critical information infrastructure have intensified, reflecting constant and relentless pressures on national and regional stability.
Indonesia stated that the growing sophistication of malicious activities, including advanced persistent threats, ransomware, and phishing activities, poses serious risks . Indonesia noted that threats targeting critical infrastructure and critical information infrastructure, including cross-border systems, have intensified, not only periodically but every single day, reflecting constant and relentless pressures on national and regional stability .
AI and quantum computing complicating threats (Indonesia)
Arg. 2Indonesia highlights that emerging technologies such as artificial intelligence and quantum computing further complicate the threat landscape by lowering barriers to malicious activity while simultaneously creating new dependencies and vulnerabilities. A threat environment of this scale and complexity requires the global mechanism to prioritise practical, needs-based support.
Indonesia stated that emerging technologies such as artificial intelligence and quantum computing further complicate the threat landscape, lowering barriers to malicious activity while simultaneously creating new dependencies and vulnerabilities .
on: Artificial intelligence is transforming the cyber threat landscape by lowering barriers for malicious actors and amplifying existing threats, while also offering defensive opportunities
Regional cooperation for resilience building (Indonesia)
Arg. 3Indonesia argues that cooperation among states, including through ASEAN, OIC, and Asia-Pacific mechanisms, is indispensable for building resilience through threat analysis, shared early warning arrangements, and structured exchange on incident trends. Strengthening cooperation among CERTs and improving information sharing mechanisms are essential to building resilience.
Indonesia stated that the global mechanism, including its DTGs, should focus on fostering cooperation in threat analysis, shared early warning arrangements, and structured exchange on incident trends to ensure that developing countries are not left behind . Indonesia noted that it is actively participating in regional and international mechanisms including ASEAN, OIC, and Asia-Pacific mechanisms for technical information sharing, coordinated incident response, and joint capacity building .
on: Capacity building is essential for developing countries and small island developing states to meaningfully participate in and benefit from the global mechanism
The misuse of ICTs by both state and non-state actors continues to pose serious threats, with increasing sophistication particularly targeting critical infrastructure - State and non-state actor misuse of ICTs (Thailand)
Arg. 1Thailand is deeply concerned by the increasing number and sophistication of cyber threats, particularly those targeting critical infrastructure and critical information infrastructure. Malicious actors, including advanced persistent threat groups, are employing increasingly sophisticated techniques that pose serious risks to national security, economic stability, and the delivery of essential public services.
Thailand stated that its national assessment for 2025 indicates a continued rise in cyber incidents, especially those involving information content security, cyber fraud, and intrusion attempts . Thailand noted that malicious actors, including advanced persistent threat groups, are employing increasingly sophisticated techniques that pose serious risks to national security, economic stability, and the delivery of essential public services .
Supply chain vulnerabilities harming developing countries (Thailand)
Arg. 2Thailand highlights that ICT supply chain disruptions, including the deliberate insertion of vulnerabilities, backdoors, or other forms of interference, undermine economic and digital development, particularly in developing countries. Addressing these challenges requires strengthened international cooperation to ensure that emerging technologies are developed and used in a safe, secure, and responsible manner.
Thailand stated that ICT supply chain disruptions, including deliberate insertion of ICT-related threats, vulnerabilities, backdoors, or other forms of interference, undermine economic and digital development, particularly in developing countries . Thailand stated that addressing these challenges requires strengthened international cooperation to ensure that emerging technologies are developed and used in a safe, secure, and responsible manner .
The threat landscape is characterised by intensification of cyber attacks, systematic targeting of critical infrastructure, proliferation of cybercrime service models, and misinformation campaigns - Multi-dimensional threat landscape (Morocco)
Arg. 1Morocco describes the current threat landscape as characterised by the intensification of cyber attacks led by state and non-state actors, systematic targeting of critical infrastructure and essential services, proliferation of cybercrime service models facilitating large-scale attacks, misinformation campaigns, and the impact of emerging technologies including AI.
Morocco described the threat landscape as characterised by intensification of cyber attacks led by state and non-state actors with a transfer of capacity to criminal groups, systematic targeting of critical infrastructure, proliferation of cybercrime service models including ransomware and DDoS attacks, misinformation campaigns, and the impact of emerging technologies including AI .
International law applies fully in cyberspace (Micronesia)
Arg. 1Micronesia affirms that international law applies in cyberspace, and that respect for sovereignty, the prohibition on the threat or use of force, and human rights obligations must guide state conduct online as they do offline. Micronesia supports the voluntary consensus-based framework of norms for responsible state behaviour as fundamental to addressing both existing and potential ICT-related threats.
Micronesia affirmed that international law applies in cyberspace, and that respect for sovereignty, the provision on the threat or use of force, and human rights obligations must guide state conduct online as they do offline . Micronesia supported the voluntary consensus-based frameworks of norms for responsible state behaviour as fundamental to addressing both existing and potential ICT-related threats to international security .
on: International law, including the UN Charter, applies in cyberspace and provides the foundation for responsible state behaviour
Rights-respecting definitions of disinformation (Micronesia)
Arg. 2Micronesia advocates for clear and rights-respecting definitions of disinformation, warning that vague approaches can suppress dissent and independent media, erode human rights, politicise enforcement, weaken trust in institutions, and disproportionately harm marginalised and remote communities. Micronesia urges states to adopt precise, time-bound, and rights-based definitions of disinformation.
Micronesia stated that vague approaches to disinformation can suppress dissent and independent media, erode human rights, politicise enforcement, weaken trust in institutions, and disproportionately harm marginalised and remote communities, while also impairing crisis response . Micronesia urged states to adopt precise, time-bound, and rights-based definitions of disinformation .
on: Disinformation and information manipulation, increasingly combined with cyber operations, represent a growing and serious threat
on: Whether the mechanism should address disinformation and cognitive operations as ICT threats
Malicious cyber activities impact governments, businesses, and critical information infrastructure, with APTs and ransomware among the most serious concerns - APTs and ransomware as primary concerns (Malaysia)
Arg. 1Malaysia reports that malicious cyber activities continue to impact governments, businesses, and critical information infrastructure across a wide range of sectors, with advanced persistent threats and ransomware remaining among the most serious concerns. Malaysia's national monitoring shows that a large share of reported incidents involve critical information infrastructure.
Malaysia stated that its national monitoring shows that a large share of reported incidents involve critical information infrastructure, most notably across trade and industry, government, agriculture and plantations, defence and security, healthcare, as well as banking and finance . Malaysia stated that APTs, followed closely by ransomware, remain among its most serious concerns .
Quantum computing and post-quantum cryptography (Malaysia)
Arg. 2Malaysia highlights that it is preparing for the security implications of quantum computing, especially regarding current encryption systems, and is developing a national post-quantum cryptography migration plan focused on safeguarding critical information infrastructure. This work forms a core part of Malaysia's broader strategy to build long-term cyber resilience.
Malaysia stated that it is preparing for the security implications of quantum computing, especially regarding current encryption systems, and is currently developing a national post-quantum cryptography migration plan focused on safeguarding critical information infrastructure . Malaysia stated that this work forms a core part of its broader strategy to build long-term cyber resilience .
Practical national experience sharing (Malaysia)
Arg. 3Malaysia argues that the mechanism's work under the threats pillar should focus on practical, grounded discussions that help states collectively better understand the threat landscape. This may include sharing national experiences on how states protect critical assets, handle APTs and ransomware, and manage the risks of emerging technologies.
Malaysia stated that its work under this pillar should focus on practical, grounded discussions that can help states collectively better understand the threat landscape, including sharing national experience on how states protect critical assets, handle the threats of APTs and ransomware, and manage the risk of emerging technologies .
Malicious ICT activities have become increasingly sophisticated, frequent, and consequential, posing a growing threat to international peace and security - Growing frequency and consequences of malicious ICT activities (Cameroon)
Arg. 1Cameroon recognises that malicious ICT activities have become increasingly sophisticated, frequent, and consequential, posing a growing threat to international peace and security. These threats have tangible repercussions on the security and integrity of critical infrastructure, the stability of economies, and the delivery of essential public services.
Cameroon stated that as recognised in the consensus final report of the OEWG, malicious ICT activities have become increasingly sophisticated, frequent, and consequential, posing a growing threat to international peace and security . Cameroon noted that these threats have tangible repercussions on the security and integrity of critical infrastructure, the stability of economies, the delivery of essential public services, and the daily lives and well-being of populations .
The establishment of a Dedicated Voluntary Fund under the Global Mechanism is essential to support national cybersecurity institution building and facilitate participation in DTG meetings - Dedicated Voluntary Fund for developing countries (Cameroon)
Arg. 2Cameroon affirms support for the establishment of a Dedicated Voluntary Fund under the Global Mechanism as an essential instrument to support national cybersecurity institution building, provide resources for training and skills development, and facilitate participation in DTG meetings and capacity building programmes.
Cameroon affirmed support for the establishment of the Dedicated Voluntary Fund under the Global Mechanism as an essential instrument to support national cybersecurity institution building, provide resources for training and skills development, facilitate participation in DTG meetings, and capacity building programmes .
States should oppose acts of aggression through cyber means, respect digital sovereignty, and uphold multilateralism to address risks effectively, including formulating new international rules - Multilateralism and digital sovereignty in cyber governance (China)
Arg. 1China argues that states should oppose acts of aggression through cyber means, respect each other's digital sovereignty, and uphold multilateralism to address risks effectively. China calls for the formulation of new international rules to address the impact of emerging technologies and prevent new domains from turning into lawless zones of zero-sum games.
China stated that states should oppose acts of aggression through cyber means, respect digital sovereignty, and promote development for all . China called for countries to respect each other's digital sovereignty, uphold multilateralism, and consider establishing global standards and systems for testing and assessing the risk of large AI models .
New generation large AI models have demonstrated powerful offensive and defensive cyber capabilities, making the risk posed by AI no longer merely theoretical - AI posing real and immediate threats (China)
Arg. 2China highlights that a new generation of large AI models has demonstrated powerful cyber capabilities, both offensive and defensive, leading to global concern. China argues that the risk posed by AI is no longer merely theoretical but is now a real and immediate threat, making the work of the mechanism and its DTGs not optional but a responsibility.
China stated that not long ago, a new generation of large models issued by certain AI companies demonstrated powerful cyber capabilities, both offensive and defensive, which led to global concern . China stated that in the past, the risk posed by AI was merely theoretical, but now the real threats AI poses can be seen firsthand, making the mechanism including the DTG not an option but a responsibility .
Cyber threats are growing in scale and sophistication, with AI being leveraged by terrorist groups and malicious actors targeting national and governmental institutions - AI-enabled threats and national experience (Oman)
Arg. 1Oman reports that cyber threats are growing in scale and sophistication, with AI being leveraged by terrorist groups which use malware including backdoors. Oman's Electronic Defence Centre has addressed many cyber threats and risks targeting national and governmental institutions, including 19 cyber incidents targeting private and public institutions.
Oman stated that cyber threats are growing in scale and sophistication and are used with the help of AI by terrorist groups which use malware including backdoors . Oman noted that its Electronic Defence Centre has addressed many cyber threats and risks targeting national and governmental institutions, and had to address 19 cyber incidents targeting private and public institutions, leading to data breaches and disruption of information systems .
Cyber criminals are increasingly leveraging emerging technologies, including AI, to conduct more sophisticated and targeted malicious cyber activities - AI-driven cybercrime evolution (Mauritius)
Arg. 1Mauritius reports that the cyber threat landscape continues to evolve at an unprecedented pace, with cyber criminals increasingly leveraging emerging technologies including AI to conduct more sophisticated and targeted malicious cyber activities. Mauritius is particularly concerned by cyber incidents affecting critical information infrastructure and essential services.
Mauritius stated that cyber criminals are increasingly leveraging emerging technologies, including artificial intelligence, to conduct more sophisticated and targeted malicious cyber activities . Mauritius stated that it is particularly concerned by cyber incidents affecting critical information infrastructure and essential services, malicious activities conducted through social media platforms, phishing and online fraud targeting individuals and businesses, identity theft, online financial scams, data breaches, and DDoS attacks .
AI-generated disinformation undermining public trust (Mauritius)
Arg. 2Mauritius is concerned about the growing risks posed by the malicious use of AI to generate convincing deepfakes, clone voices, spread disinformation, and enable sophisticated forms of fraud including cryptocurrency-related scams. Such misuse has the potential to facilitate cybercrime, undermine public trust, compromise the integrity of information, and disproportionately impact vulnerable groups.
Mauritius stated that it is mindful of the growing risks posed by the malicious use of artificial intelligence to generate convincing deepfakes, clone voices, spread disinformation, and enable sophisticated forms of fraud, including cryptocurrency-related scams . Mauritius stated that such misuse has the potential to facilitate cybercrime, undermine public trust, compromise the integrity of information, and disproportionately impact vulnerable groups, including children and older persons .
on: Disinformation and information manipulation, increasingly combined with cyber operations, represent a growing and serious threat
AI-enabled fraud and disinformation targeting vulnerable groups (Mauritius)
Arg. 3Mauritius highlights that the malicious use of AI to generate deepfakes, clone voices, spread disinformation, and enable sophisticated fraud disproportionately impacts vulnerable groups including children and older persons. This misuse has the potential to facilitate cybercrime and undermine public trust.
Mauritius stated that the malicious use of artificial intelligence to generate convincing deepfakes, clone voices, spread disinformation, and enable sophisticated forms of fraud, including cryptocurrency-related scams, has the potential to facilitate cybercrime, undermine public trust, compromise the integrity of information, and disproportionately impact vulnerable groups, including children and older persons .
Malicious cyber activities are becoming increasingly sophisticated, complex, and difficult to detect, with frontier AI models further transforming the threat landscape - Evolving sophistication and AI impact (Republic of Korea)
Arg. 1The Republic of Korea reports that malicious cyber activities are becoming increasingly sophisticated, complex, and difficult to detect and respond to. The rapid advancement of frontier AI models has further transformed the cyber threat landscape, enabling increasingly sophisticated cyber operations while raising concerns that existing cyber defence mechanisms may become less effective.
The Republic of Korea stated that malicious cyber activities are becoming increasingly sophisticated, complex, and difficult to detect and respond to . The Republic of Korea noted that since the adoption of the OEWG final report, the rapid advancement of frontier AI models has further transformed the cyber threat landscape, enabling increasingly sophisticated cyber operations while raising concerns that existing cyber defence mechanisms may become less effective .
Frontier AI transforming the threat landscape (Republic of Korea)
Arg. 2The Republic of Korea argues that the global mechanism should deepen discussions on AI-enabled cyber threats and ensure that international dialogue remains timely and responsive to the rapidly changing technological environment. The rapid advancement of frontier AI models has further transformed the cyber threat landscape beyond what was recognised in the OEWG final report.
The Republic of Korea stated that the global mechanism should deepen discussions on AI-enabled cyber threats and ensure that international dialogue remains timely and responsive to the rapidly changing technological environment .
on: Artificial intelligence is transforming the cyber threat landscape by lowering barriers for malicious actors and amplifying existing threats, while also offering defensive opportunities
Cryptocurrency theft financing illicit activities (Republic of Korea)
Arg. 3The Republic of Korea highlights that ransomware and cryptocurrency theft have become major sources of financing for illicit activities, including illicit arms trafficking and the development of weapons of mass destruction. The global mechanism should continue and deepen discussions on this issue, reaffirming that such activities threaten international peace and security.
The Republic of Korea recalled that the final reports of the OEWG recognised cryptocurrency theft as a threat with implications for international peace and security . The Republic of Korea stated that ransomware and cryptocurrency theft have become major sources of financing for illicit activities, and that states should reaffirm that such activities threaten international peace and security, especially when linked to illicit arms trafficking or the development of weapons of mass destruction .
Deepening AI threat discussions in the mechanism (Republic of Korea)
Arg. 4The Republic of Korea argues that the global mechanism should deepen discussions on AI-enabled cyber threats and ensure that international dialogue remains timely and responsive to the rapidly changing technological environment. The mechanism should serve as a platform for sustained and in-depth discussion on the evolving threat landscape.
The Republic of Korea stated that the global mechanism should deepen discussions on AI-enabled cyber threats and ensure that international dialogue remains timely and responsive to the rapidly changing technological environment . The Republic of Korea stated that the global mechanism should be a platform for sustained and in-depth discussion on the evolving threat landscape, enabling member states to strengthen collective understanding and enhance collective capacity to prevent, respond to, and recover from cyber threats .
Protecting submarine cables as strategic assets (Ghana)
Arg. 1Ghana highlights that the damage to Submarine Cable 7 Ghana in 2024 and the resulting disruption to digital services reinforced the importance of protecting such infrastructure as a strategic national asset. Ghana has identified 13 critical information infrastructure sectors under its Cybersecurity Act 2020 and is strengthening its national incident response architecture.
Ghana stated that the damage to Submarine Cable 7 Ghana in 2024 and the resulting disruption to digital services reinforce the importance of protecting such infrastructure as a strategic national asset . Ghana noted that it has identified 13 critical information infrastructure sectors under the Cyber Security Act 2020, which provides for the registration of critical information infrastructure, establishes obligations for operators, and requires regular compliance audits .
on: Critical infrastructure protection, including submarine cables and undersea infrastructure, must be a priority for the global mechanism
Humanitarian and economic effects of infrastructure attacks (Iraq)
Arg. 1Iraq expresses concern at the increasing cyber activities targeting civilian critical infrastructure, including the energy, telecommunications, and financial sectors, and the serious humanitarian and economic effects that may result, particularly for developing countries that continue to face challenges in strengthening their national cybersecurity capacities.
Iraq stated that it wishes to express concern at the increasing cyber activities targeting civilian critical infrastructure, including the energy, telecommunications, and financial sectors, and the serious humanitarian and economic effects that may result therefrom, particularly for developing countries that continue to face challenges in strengthening their national capacities in the field of cybersecurity .
on: Critical infrastructure protection, including submarine cables and undersea infrastructure, must be a priority for the global mechanism
Terrorist exploitation of ICTs and infrastructure attacks (Iraq)
Arg. 2Iraq highlights the growing risks arising from the exploitation of ICTs by terrorist groups, including the use of cyberspace for recruitment, dissemination of extremist ideology, financing, planning, and coordination of terrorist operations, as well as the targeting of critical infrastructure. Drawing on Iraq's national experience in combating terrorism, Iraq affirms the importance of confronting these unlawful uses.
Iraq stated that it wishes to affirm the growing risks arising from the exploitation of ICTs by terrorist groups, including the use of cyberspace for recruitment, the dissemination of extremist ideology, financing, planning, and coordination of terrorist operations, as well as the targeting of critical infrastructure . Iraq stated that drawing on its national experience in combating terrorism, it affirms the importance of confronting these unlawful uses .
ICT supply chain security as a cross-border priority (Iraq)
Arg. 3Iraq argues that strengthening the security of ICT supply chains and exchanging relevant international best practices and standards constitute an important element in reducing cross-border cyber risks. Addressing these threats requires strengthening international cooperation, exchanging information and expertise, and supporting the development of new technologies.
Iraq stated that strengthening the security of information and communications technology supply chains and exchanging relevant international best practices and standards constitute an important element in reducing cross-border cyber risks . Iraq affirmed that addressing these threats requires strengthening international cooperation, exchanging information and expertise, and supporting the development of new technologies .
on: International law, including the UN Charter, applies in cyberspace and provides the foundation for responsible state behaviour
Russian malicious cyber activities against Poland (Poland)
Arg. 1Poland reports that a sustained pattern of malicious cyber activity by Russian actors has been observed in Poland since at least 2010, with Russia's security services undertaking actions to gain unauthorised access to sensitive networks and exfiltrate protected information from government, armed forces, and private entities. These activities include strategic reconnaissance, prepositioning, and disruptive sabotage operations targeting Polish critical infrastructure.
Poland stated that since at least 2010, Russia's security services have undertaken actions to gain unauthorised access to sensitive networks and to exfiltrate protected information from government, Polish armed forces, and private entities . Poland noted that malicious cyber actors have engaged in deliberately establishing persistent footholds within critical systems with apparent intent to enable future disruptive or destructive effects against basic and essential civilian services .
on: Attribution of state-sponsored cyber attacks and the evidentiary standard required
Capacity building must be predictable, sustainable, demand-driven, and accompanied by technology transfer, institutional strengthening, and equitable access to knowledge - Sustainable and equitable capacity building (Mozambique)
Arg. 1Mozambique argues that sustainable cybersecurity requires strong institutions, skilled professionals, trusted partnerships, and effective international cooperation. Capacity building should be predictable, sustainable, demand-driven, and accompanied by technology transfer, institutional strengthening, and equitable access to knowledge and expertise.
Mozambique stated that sustainable cybersecurity requires strong institutions, skilled professionals, trusted partnerships, and effective international cooperation to address increasingly sophisticated and transnational cyber threats . Mozambique stated that capacity building should be predictable, sustainable, demand-driven, and accompanied by technology transfer, institutional strengthening, and equitable access to knowledge and expertise .
Collective preparedness through the mechanism (Mozambique)
Arg. 2Mozambique expects the global mechanism to become an implementation-oriented platform that translates agreed commitments into tangible outcomes, particularly for developing countries. The mechanism should strengthen collective preparedness to address existing and emerging ICT threats, including ransomware attacks against critical infrastructure and the malicious use of AI.
Mozambique stated that it expects the mechanism to become an implementation-oriented platform that translates agreed commitments into tangible outcomes, particularly for developing countries . Mozambique stated that the mechanism should strengthen collective preparedness to address existing and emerging ICT threats, including ransomware attacks against critical infrastructure, the malicious use of artificial intelligence, and other rapidly evolving cyber risks that increasingly affect developing countries .
on: International law, including the UN Charter, applies in cyberspace and provides the foundation for responsible state behaviour
Delegations should deliver abridged statements and submit full versions to eStatements to ensure all delegations can be heard within the available time - Managing speaking time to ensure inclusive participation (Chair)
Arg. 1The Chair requests that delegations keep their statements concise and submit full versions electronically, in order to ensure that all 30 remaining speakers on the list can be heard. This procedural guidance is aimed at balancing inclusivity with the practical constraints of conference time.
The Chair indicated that while there is no established limit for delivering statements, it would be appreciated if delegations could deliver an abridged version and submit the full statement to eStatements and to the chair's team, as this would help ensure all delegations are heard . The Chair also noted that a timer would be projected on the screen .
Rights of reply should be exercised at the end of the speakers' list, not during the substantive discussion, to allow all delegations to make their national capacity statements first - Procedural guidance on rights of reply (Chair)
Arg. 2The Chair clarifies that delegations wishing to exercise a right of reply should make their request to the Secretariat so that speaking time can be allocated at the end of the list of speakers, as was done in prior meetings. This ensures that the substantive discussion is not interrupted by political exchanges.
The Chair noted that the right of reply should be done at the end of the meeting, and that any delegation wishing to speak under the right of reply should make the request to the Secretariat so that speaking time can be requested at the end of the list of speakers, as was done in prior meetings of this group .
The list of speakers for inscriptions should be closed to manage the agenda and ensure other items can be addressed within the available time - Closing the speakers' list to protect the agenda (Chair)
Arg. 3The Chair announces the closure of the speakers' list for new inscriptions, noting that the list has grown longer than predicted and risks preventing the meeting from addressing other agenda items. This decision is taken to protect the integrity of the overall programme of work.
The Chair asked the Secretariat to close the list of speakers for inscriptions, noting that since the previous day the list had continued to grow much longer than predicted, which could impact the ability to address other items on the agenda . The Chair noted that there were 21 speakers still on the list with only one hour and forty minutes remaining .
Upon completion of the threats agenda item, the meeting will immediately proceed to the agenda item on voluntary norms for responsible state behaviour - Sequencing of agenda items (Chair)
Arg. 4The Chair announces that as soon as the current agenda item on existing and potential threats is completed, the meeting will immediately move to the next agenda item on voluntary norms for responsible state behaviour in cyberspace. This signals the Chair's intention to maintain momentum and cover all substantive items.
The Chair stated that as soon as the threats agenda item is completed, the meeting will immediately begin the next agenda item, which is the voluntary norms for responsible state behaviour in cyberspace and forms of implementation, recognising that over time additional norms may be elaborated . The Chair asked delegations to be ready .
Session Knowledge Graph
Speakers · Topics · Arguments · Relationships
A broad coalition of states agreed that ransomware represents one of the most serious and pervasive cyber threats. Tonga described a ransomware attack that encrypted its national health information system, forcing hospitals back to pen and paper . Japan explicitly stated at the Security Council that ransomware 'could certainly pose direct threats to international peace and security' . Germany cited a ransomware attack that paralysed a humanitarian organisation providing food relief in conflict regions . Latvia noted that criminal groups have developed industrial-scale ransomware operations . The Philippines called for timely information sharing and public-private partnerships to address ransomware . This near-universal agreement on ransomware as a critical threat was one of the strongest consensus points in the discussion.
Ransomware and AI threats (New Zealand)
Ransomware attack on national health system (Tonga)
Ransomware as a threat to international peace and security (Japan)
Escalating cyber incidents across sectors (Netherlands)
Intensifying cyber threat environment (Australia)
Ransomware paralysing humanitarian and critical services (Germany)
Industrial-scale ransomware criminal operations (Latvia)
Practical cooperation to address ransomware (Philippines)
Critical infrastructure as a national and international security priority (Chile)
Growing sophistication and persistence of threats (Malawi)
AI-enabled threats and national experience (Oman)
APTs and ransomware as primary concerns (Malaysia)
Growing frequency and consequences of malicious ICT activities (Cameroon)
Multi-dimensional threat landscape (Morocco)
This assessment is corroborated by Australia's statement at the organisational session of the Global Mechanism, which explicitly noted that 'ransomware, phishing, distributed denial of service attacks are becoming more frequent, coordinated and disruptive' [S163]. The link between ICT threats and international peace and security is also embedded in the foundational cybersecurity policy framework discussed in UN contexts [S164].
There was near-universal agreement that AI is fundamentally changing the cyber threat landscape. The Netherlands noted that large language models can lower the barrier for conducting sophisticated operations, from phishing to zero-day vulnerability discovery . Australia stated that AI is being used to scale social engineering and lower cost and skill barriers for malicious actors . Germany observed that AI facilitates large-scale attacks including language-agnostic phishing and social engineering . Latvia noted that AI-enabled tools can automate reconnaissance and generate highly convincing phishing campaigns, potentially overwhelming defenders . France highlighted that the rapid increase in frontier AI model capabilities carries the risk of a new digital divide . Canada noted that frontier AI models have displayed unprecedented capabilities in autonomous vulnerability discovery and multi-stage orchestration of malicious activity . Virtually all speakers agreed that while AI poses threats, it also offers defensive opportunities.
Ransomware and AI threats (New Zealand)
Generative AI as a threat amplifier (Netherlands)
AI enabling malicious actors at scale (Australia)
Common understanding through multi-stakeholder engagement (Japan)
AI misuse undermining democratic processes (Greece)
AI lowering barriers for malicious actors (Germany)
AI-enabled tools supercharging malicious cyber activities (Latvia)
AI as a multiplier of existing threats (Chile)
AI enabling malicious activities at unprecedented scale (Malawi)
AI acceleration of offensive operations and digital divide (France)
Frontier AI capabilities as a security risk (Canada)
AI and quantum computing complicating threats (Indonesia)
AI posing real and immediate threats (China)
Frontier AI transforming the threat landscape (Republic of Korea)
AI-driven cybercrime evolution (Mauritius)
Disinformation and AI-enabled deception (Zimbabwe)
Australia's statement at the Global Mechanism organisational session directly referenced AI as amplifying cyber risks [S163]. The UN First Committee discussion on cybersecurity and AI similarly highlighted the misuse of AI and emerging technologies as a key concern for ICT infrastructure protection [S160]. This reflects a broader consensus emerging across multiple UN forums on AI's dual-use nature in the cyber domain.
There was broad consensus that critical infrastructure protection must be a central focus of the global mechanism. Kiribati stated that for a nation served by a small number of cables, critical infrastructure protection is 'existential' . Tonga described how the severing of its submarine cable during the 2022 volcanic eruption left the kingdom silent for weeks , and argued that a malicious actor could deliberately replicate this . Australia called for critical infrastructure and critical information infrastructure protection to be an early focus for the mechanism, including through DTG1 . The Netherlands highlighted a troubling shift towards targeting means of communication such as messaging services . Ghana noted that damage to Submarine Cable 7 Ghana in 2024 reinforced the importance of protecting such infrastructure as a strategic national asset .
Submarine cable as existential infrastructure (Kiribati)
Submarine cable sabotage as a grave threat (Tonga)
Ransomware and AI threats (New Zealand)
Targeting of communications infrastructure (Netherlands)
Undersea cable resilience as a priority (Australia)
Ransomware as a threat to international peace and security (Japan)
Critical infrastructure as a national and international security priority (Chile)
Cross-border infrastructure vulnerabilities for developing countries (Zimbabwe)
Growing threats to critical infrastructure (Canada)
Protecting submarine cables as strategic assets (Ghana)
Humanitarian and economic effects of infrastructure attacks (Iraq)
AI-enabled threats and national experience (Oman)
APTs and ransomware as primary concerns (Malaysia)
Growing frequency and consequences of malicious ICT activities (Cameroon)
Multi-dimensional threat landscape (Morocco)
Sophisticated threats to critical infrastructure (Indonesia)
State and non-state actor misuse of ICTs (Thailand)
The UN First Committee discussion explicitly listed undersea cables among ICT infrastructure threats requiring cooperative measures [S160]. Expert panels have emphasised the importance of designating submarine cables as critical infrastructure and called for increased international collaboration and potentially regional bodies for coordinated protection [S178]. Regulators have also highlighted the need for public protection policies given submarine cables' essential role in global traffic [S179].
There was strong consensus that capacity building is not merely beneficial but essential, particularly for developing countries and small island developing states. The Bahamas stated that for small island developing states, capacity building is 'a precondition for participation' . Australia acknowledged that cyber threats are shared but their impacts are not experienced equally, with differences in national capacity affecting vulnerability and recovery . Zimbabwe noted that capacity constraints and uneven cyber resilience increase vulnerability and limit the ability to respond effectively . Malawi argued that for developing countries, responding to one cyber incident is already difficult, and responding to sustained campaigns is an even greater challenge . Cameroon supported the establishment of a Dedicated Voluntary Fund under the Global Mechanism as an essential instrument to support national cybersecurity institution building .
National action has limits that only cooperation can overcome; each threat identified should connect to a concrete step enabling all states, including the smallest, to prevent, detect, and respond (Kiribati)
Capacity building as precondition for SIDS participation (Bahamas)
Unequal impact of cyber threats and capacity gaps (Australia)
Multi-level approach to threat response (Guyana)
Capacity constraints in developing countries (Zimbabwe)
Strengthening national response capabilities (Malawi)
Practical cooperation to address ransomware (Philippines)
Evidence-based forward-looking dialogue in DTG1 (Chile)
Regional cooperation for resilience building (Indonesia)
Dedicated Voluntary Fund for developing countries (Cameroon)
Sustainable and equitable capacity building (Mozambique)
Action-oriented mechanism with concrete outcomes (Tuvalu)
Pakistan's statement at the signature panel on cyber resilience for sustainable development underscored the importance of bridging the global capacity gap [S168]. The Open Forum on cyberdefence and AI in developing economies further contextualises the structural disadvantage faced by developing states [S161]. The consensus nature of the global mechanism's foundational elements was noted as giving every state a stake in its success [S181], making capacity building essential for equitable participation.
There was widespread agreement that the global mechanism must be action-oriented and produce concrete outcomes rather than merely describing threats. Kiribati stated that 'discussion of threats must not end as descriptions of threats' and that each threat identified should connect to a concrete step . Tonga called for the mechanism to honour its experience by ensuring every threat discussed is matched by practical cooperation . The United States stated that the mechanism 'was established to do real work, to implement the commitments states have already made' . Latvia argued that the DTGs should focus on specific ICT security challenges, enabling states to examine threats, share experience, and develop practical approaches . Mozambique expected the mechanism to become an implementation-oriented platform that translates agreed commitments into tangible outcomes .
The mechanism was designed to be action-oriented; discussion of threats must not end as descriptions but must connect to concrete steps for all states (Kiribati)
Tonga's message on practical cooperation to prevent, withstand, and respond to threats (Tonga)
Cyber threat information sharing should be genuinely accessible to small island states (Bahamas)
Intensifying cyber threat environment (Australia)
Building on existing consensus rather than new agreements (United States)
Action-oriented mechanism with concrete outcomes (Tuvalu)
Evidence-based forward-looking dialogue in DTG1 (Chile)
DTGs as vehicles for practical action (Latvia)
Collective preparedness through the mechanism (Mozambique)
Growing sophistication and persistence of threats (Malawi)
Multi-dimensional threat landscape (Morocco)
Growing frequency and consequences of malicious ICT activities (Cameroon)
Cuba's statement at the opening of the session emphasised the need to give due attention to cyber threats with social and political dimensions as the working group approached its final report [S159]. The comprehensive report on the 18th meeting of the Disarmament and International Security Committee noted that the global mechanism's elements were negotiated and agreed by all states in a consensus process, underscoring the expectation of tangible outcomes [S181].
There was broad consensus that international law applies in cyberspace and provides the foundation for responsible state behaviour. The Bahamas stated that international law, including the UN Charter, is 'the foundation of a secure and peaceful ICT environment' and 'the guarantee of this process, not a constraint to it' . Australia stated that state responses, including the development and use of cyber capabilities, must be consistent with international law including the UN Charter, international human rights law, and international humanitarian law . Micronesia affirmed that international law applies in cyberspace and that respect for sovereignty and human rights obligations must guide state conduct online as they do offline . Malawi reaffirmed that as recognised in successive UN GGE and OEWG reports, international law including the UN Charter applies to the use of ICTs by states .
International law as foundation, not constraint (Bahamas)
State cyber capabilities must comply with international law (Australia)
Action-oriented mechanism with concrete outcomes (Tuvalu)
International law applies fully in cyberspace (Micronesia)
Ensuring states act responsibly in cyberspace, refrain from supporting malicious activities, and cooperate in addressing threats is essential for preserving international peace and security (Albania)
Malicious ICT activities are not isolated incidents but form part of broader strategies combining cyberattacks with kinetic strikes, disinformation, and hybrid warfare tools (Ukraine)
Growing sophistication and persistence of threats (Malawi)
Addressing ransomware requires timely information sharing, strengthened incident response capabilities, public-private partnerships, technical assistance, and sustainable capacity building (Philippines)
Collective preparedness through the mechanism (Mozambique)
Multi-level approach to threat response (Guyana)
ICT supply chain security as a cross-border priority (Iraq)
AI-enabled threats and national experience (Oman)
This is a well-established norm explicitly articulated in the UN cybernorms framework: 'States should recognize that international law, including the UN Charter, is applicable and essential to maintaining peace and stability and promoting an open, secure, stable, accessible, and peaceful ICT environment' [S166]. Albania's statement at the OEWG similarly affirmed the UN as the guardian of international law as the foundation for global peace and security [S169]. Authoritative commentary confirms that existing international law sets the overall legal framework for state use of ICT [S167].
Multiple states agreed that the blurring of boundaries between state and non-state actors represents one of the most problematic trends in the current threat landscape. The Netherlands described this as a 'worrying trend of state actors hiding behind state proxies to maintain plausible deniability' . France noted that 'the boundaries between state-sponsored acts and cyber criminals are blurring, and the use of proxies by nation-states is spreading' . Germany noted with concern the virulence of politically motivated hacktivist activities . Latvia noted that state-linked cyber operations pose significant risks, with incidents targeting electoral systems and critical infrastructure . Israel highlighted the clandestine direction, control, or support of non-state actors as a core threat .
State-proxy blurring and plausible deniability (Netherlands)
Attribution of Russian FSB cyber attacks against France (France)
Russian state-sponsored attacks on EU and Ukraine (Germany)
Persistent and pervasive cyber threats (Latvia)
Israeli actions conducted within international law (Israel)
State-sponsored attacks combined with disinformation (Albania)
Russian cyber aggression as part of hybrid warfare (Ukraine)
Growing threats to critical infrastructure (Canada)
The UK's statement at the OEWG described 'an expanding and evolving threat landscape and an emerging contest between those who use technology to improve our lives' [S162], implicitly referencing the complexity of actor attribution. The rise of false flag operations and misattributed cyberattacks was also flagged as a concern in the agenda item 5 discussions, with the absence of a universal investigative framework noted as potentially leading to flawed political decisions [S158].
Multiple states agreed that disinformation and information manipulation, particularly when combined with cyber operations, represent a serious and growing threat. Albania described a 'particularly concerning trend' of combining cyber operations with information manipulation activities, noting that following cyber incidents, attempts were made to spread disinformation via Telegram to amplify psychological impact and erode trust in public institutions . Zimbabwe expressed concern about the spread of disinformation and misinformation through digital platforms . Ukraine highlighted hybrid campaigns combining cyber operations, disinformation, and economic coercion . Mauritius noted the growing risks posed by the malicious use of AI to generate deepfakes, clone voices, and spread disinformation . Micronesia called for precise, time-bound, and rights-based definitions of disinformation .
Disinformation and cognitive operations as ICT threats (Islamic Republic of Iran)
Combination of cyber operations and disinformation (Albania)
Disinformation and AI-enabled deception (Zimbabwe)
Hybrid campaigns as a systemic threat (Ukraine)
AI-generated disinformation undermining public trust (Mauritius)
Rights-respecting definitions of disinformation (Micronesia)
AI enabling malicious actors at scale (Australia)
The use of ICTs for purposes contradicting the UN Charter (Russian Federation)
The dedicated stakeholder session noted that 'growing threats posed by misinformation and disinformation campaigns in cyberspace were noted by several delegations' [S174]. The agenda item 5 discussions specifically flagged 'ICT in Disinformation Campaigns and Cognitive Operations' as a distinct threat category [S158]. Disinformation in the political landscape is widely recognised as a serious threat to democratic processes [S176], and the malicious use of AI and deepfakes is identified as further deteriorating the informational ecosystem [S175].
Pacific Island Forum members consistently emphasised the existential nature of cyber threats to small island developing states, particularly the vulnerability of submarine cable infrastructure. Kiribati stated that damage to or disruption of its submarine cable 'will not degrade our services, it will sever them' . Tonga described how the 2022 volcanic eruption severed its single submarine cable, leaving the kingdom silent for weeks , and argued that a malicious actor could deliberately replicate this . Australia noted that for many countries in the region, the resilience of undersea cable infrastructure is fundamental to economic and social connectivity . Tuvalu called for clear protocols for protecting subsea infrastructure like the Aotevaca Cable . All Pacific Island Forum members aligned with Tonga's statement on behalf of the group . European states, particularly those aligned with the EU and NATO, shared a consistent viewpoint attributing malicious cyber activities to Russian state actors. France announced that it had been the target for more than ten years of persistent cyber attacks carried out by Russia's FSB . Germany, together with the EU and North Atlantic Council, exposed and condemned malicious cyber activities conducted by Russian state actors targeting government entities and critical infrastructure in several EU member states and Ukraine . Poland reported that since at least 2010, Russia's security services have undertaken actions to gain unauthorised access to sensitive networks . Ukraine stated that for over a decade, cyberspace has been one of the principal theatres of Russia's ongoing war of aggression against Ukraine . All these states aligned with the EU statement and condemned Russian malicious cyber activities. Developing countries and small island developing states consistently emphasised that capacity constraints make them disproportionately vulnerable to cyber threats and that capacity building must be a central feature of the global mechanism. The Bahamas stated that capacity building is 'a precondition for participation' for small island developing states . Zimbabwe noted that capacity constraints and uneven cyber resilience increase vulnerability and limit the ability to respond effectively . Malawi argued that for developing countries, responding to one cyber incident is already difficult, and responding to sustained campaigns is an even greater challenge . Cameroon supported the establishment of a Dedicated Voluntary Fund as an essential instrument to support national cybersecurity institution building . Mozambique called for capacity building that is predictable, sustainable, demand-driven, and accompanied by technology transfer . Western European states shared a nuanced view of AI as both a threat amplifier and a potential defensive tool, while also highlighting the risk of a new digital divide. The Netherlands noted that generative AI amplifies existing cyber threats by lowering barriers for sophisticated operations, while also noting these tools can and should be harnessed defensively . France highlighted that the rapid increase in frontier AI model capabilities carries the risk of a new digital divide between those who have access to these models and those who do not . Greece noted that AI capabilities are expected to soon become widely available, significantly lowering the entry barrier for sophisticated attacks . Germany observed that AI facilitates large-scale attacks and creates an increasing strain on defenders' resources, putting particular strain on less resourced and small countries . Several states from different regional groups agreed that discussions within the global mechanism and its dedicated thematic groups should be informed by expert knowledge and practical experience, rather than remaining at a purely diplomatic level. Egypt argued that discussions should be dynamic, based on real case scenarios, and supported by a consensus-agreed pool of relevant experts . Japan placed great importance on holding expert briefings and interactive public-private discussions in the substantive plenary sessions and DTGs . Chile argued that a substantive discussion on emerging threats requires incorporating evidence and information that very often lies outside of government . Israel called for the mechanism to allow sufficient time and opportunities for relevant technological experts to provide professional presentations . Iran, Russia, and China shared a broadly similar viewpoint emphasising digital sovereignty, the dangers of Western states using ICTs for offensive purposes, and the need for multilateral governance rather than small-circle approaches. Iran argued that states which advocate respect for international law should apply those principles consistently and condemn malicious cyber activities directed against Iran . Russia argued that the greatest danger lies in the use of ICTs for purposes that contradict the UN Charter, including undermining sovereignty and interfering in internal affairs . China called for states to respect each other's digital sovereignty and uphold multilateralism, arguing that small circle governance cannot solve the big challenges facing the world . All three states expressed concern about the militarisation of ICTs by Western powers. Tonga, Australia, and New Zealand shared a particularly close viewpoint, having cooperated directly on the attribution of the ransomware attack on Tonga's Ministry of Health. Tonga stated that together with Australia and New Zealand, it jointly attributed the attack on its Ministry of Health to an affiliate of a known ransomware group, demonstrating that even the smallest states acting with partners can pursue accountability . Australia aligned with the Pacific Islands Forum statement and highlighted the importance of undersea cable resilience for the region . New Zealand noted that others in the Pacific have also been affected by ransomware affecting the healthcare sector . This practical cooperation between a major power and a small island state was highlighted as a model for the mechanism.
Despite deep geopolitical divisions evident throughout the discussion, states from opposing blocs converged on the view that the mechanism should produce practical, concrete outcomes. The United States stated that the mechanism 'was established to do real work, to implement the commitments states have already made' . Iran supported the preparation of a consolidated compilation of threats as the basis for practical cooperative measures . Russia proposed discussing specific concrete threats within the framework of the global mechanism . China stated that the mechanism 'is not an option, it is our responsibility' . Kiribati called for discussion of threats to connect to concrete steps . While the motivations and preferred approaches differed significantly, the surface-level agreement on the need for practical action was notable given the otherwise sharp divisions in the room.
Unusually, states from very different geopolitical positions and levels of development converged on the view that AI now poses real and immediate, rather than merely theoretical, threats to cybersecurity. China stated that 'in the past, the risk posed by AI was merely theoretical, but now we see firsthand the real threats AI poses' . The Republic of Korea noted that the rapid advancement of frontier AI models has further transformed the cyber threat landscape beyond what was recognised in the OEWG final report . Canada noted that frontier AI models have displayed unprecedented capabilities in autonomous vulnerability discovery and multi-stage orchestration of malicious cyber activity . Malawi noted that AI is lowering the barriers for malicious actors to conduct phishing, malware development, fraud, and disinformation at unprecedented speeds and scale . This consensus across the Global North-South divide on the immediacy of AI threats was notable.
It was perhaps expected that small island developing states would emphasise submarine cable vulnerability, but the convergence of major powers on this issue was notable. Kiribati described submarine cable protection as existential . Tonga drew on its direct experience of the 2022 volcanic eruption to illustrate the catastrophic consequences of connectivity loss . Australia explicitly called for undersea cable resilience to be an early focus for the mechanism . The Netherlands highlighted the troubling shift towards targeting means of communication . Ghana noted that damage to Submarine Cable 7 Ghana in 2024 reinforced the importance of protecting such infrastructure . This convergence between small island states and major powers on a specific infrastructure protection priority was unexpected and potentially significant for the mechanism's work programme.
Despite sharp disagreements about who is responsible for such activities, states from opposing geopolitical blocs agreed that the combination of cyber operations with disinformation and influence activities represents a distinct and growing threat. Albania described the combination of cyber operations with information manipulation activities as a 'particularly concerning trend' . Ukraine highlighted hybrid campaigns combining cyber operations, disinformation, and economic coercion . Iran described cyber espionage and information operations including the manipulation of digital platforms to incite violence and spread hatred . Zimbabwe expressed concern about the spread of disinformation through digital platforms . Mauritius highlighted the growing risks posed by AI-generated deepfakes and disinformation . While these states disagreed sharply about attribution, they converged on the characterisation of hybrid cyber-disinformation campaigns as a serious threat.
The discussion revealed a high degree of consensus on the nature and severity of cyber threats, particularly ransomware, AI-enabled threats, critical infrastructure vulnerabilities, and the growing combination of cyber operations with disinformation. There was also strong agreement on the need for the global mechanism to be action-oriented, produce practical outcomes, and prioritise capacity building for developing countries. However, deep divisions remained on questions of attribution, with Western states attributing malicious activities to Russia and, to a lesser extent, other state actors, while Russia, China, and Iran contested these attributions and offered alternative framings of the threat landscape. The Pacific Island Forum states presented a particularly coherent and compelling bloc, emphasising the existential nature of cyber threats for small island developing states and the critical importance of submarine cable infrastructure. The discussion also revealed an emerging consensus on the immediacy of AI threats to cybersecurity, with states from across the geopolitical spectrum acknowledging that AI has moved from a theoretical to a real and present danger.
The United States explicitly stated that the mechanism should be 'grounded in practical implementation of the 11 consensus norms not a vehicle for new legally binding agreements' , arguing that as long as some members are conducting malicious cyber actions, a legally binding agreement is impossible . The Bahamas, by contrast, stated that 'voluntary norms and confidence-building measures operate in service of a binding legal obligation, not in place of it' , implying a stronger role for binding law. China called for 'establishing global standards and system for testing and assessing the risk of large AI models' and for states to 'formulate new international rules' , suggesting openness to new normative frameworks. The Russian Federation emphasised that the greatest danger lies in ICT use contradicting the UN Charter , implying a need for stronger legal frameworks, while Iran argued that states advocating respect for international law should apply those principles consistently , suggesting existing law is sufficient but unevenly applied.
Building on existing consensus rather than new agreements (United States)
International law as foundation, not constraint (Bahamas)
Consistent application of responsible state behaviour norms (Islamic Republic of Iran)
Multilateralism and digital sovereignty in cyber governance (China)
ICT misuse against UN Charter principles (Russian Federation)
This tension is longstanding in UN cybersecurity processes. The existing framework of norms, rules and principles of responsible state behaviour in cyberspace, grounded in customary international law, is well-established [S167][S166], and the OEWG's progressive annual progress reports have built on this foundation [S159]. The consensus-based nature of the global mechanism's elements [S181] suggests a preference among many states for implementation over new treaty-making, though this remains contested.
The Russian Federation strongly rejected accusations of malicious cyber activity, arguing that 'accusations of organizing and implementing wrongful acts brought against states should be substantiated' and that 'no evidence has been provided neither in public nor bilaterally, nor have the existing channels for identifying the true sources of malicious activity been used' . Russia concluded that 'either no evidence exists or the incidents never happened at all' . In direct contrast, France stated that it had been the target of persistent cyber attacks by Russia's FSB for over ten years and that 'this attribution process was conducted in accordance with the norms for responsible state behaviour and following having exhausted appropriate channels' . Germany stated it had 'communicated the unacceptability of these activities via the appropriate direct bilateral channels' . Ukraine described Russian malicious ICT activities as 'not isolated incidents, but form part of the broader strategy that combines cyberattacks with kinetic strikes, disinformation campaigns, and other hybrid warfare tools' . Poland reported a 'sustained pattern of malicious cyber activity by Russian actors' since at least 2010 . The United States committed to 'specifically identify the states and non-state actors who are perpetuating malicious cyber activities against others in this room' .
Accusations against states should be substantiated with evidence; no evidence has been provided through existing channels including the UN Points of Contact Directory - Requirement for substantiated evidence in attributions (Russian Federation)
Attribution of Russian FSB cyber attacks against France (France)
Russian state-sponsored attacks on EU and Ukraine (Germany)
Russian cyber aggression as part of hybrid warfare (Ukraine)
Condemnation of malicious cyber activities by member states (United States)
State-sponsored attacks combined with disinformation (Albania)
Russian malicious cyber activities against Poland (Poland)
The rise of false flag operations and fabricated attributions was explicitly identified as a concern in the agenda item 5 discussions, with the absence of a universal investigative framework noted as a key gap that could lead to flawed political decisions impacting international peace [S158]. This reflects a persistent structural disagreement in UN cybersecurity forums about who can attribute, on what evidence, and with what consequences.
Iran alleged that 'the United States and the Israeli regime have carried out unlawful military attacks against the Islamic Republic of Iran' accompanied by 'extensive malicious cyber operations directed against Iran's critical infrastructure and civilian services' , claiming 'more than 100 cyber attacks were launched every day against Iran's critical and civilian infrastructure' during February 2026 . Israel directly rejected these claims, asserting that 'Israeli actions during operations Rising Lion and Roaring Lion were conducted in accordance with international law, including the UN Charter and the laws of armed conflict' , and accused Iran of 'waging against Israel, together with its non-state terrorist armed groups, proxies, while bluntly violating international law' . The United States added a 'postscript' to the Iranian statement, stating that 'President Trump is not going to stand idly by while the oppressive Iranian regime seeks to destroy regional stability' , and Iran's right of reply characterised both the US and Israeli statements as 'a desperate attempt to distort facts through disinformation and misleading narratives' .
US and Israeli cyber attacks against Iran (Islamic Republic of Iran)
Israeli actions conducted within international law (Israel)
Condemnation of malicious cyber activities by member states (United States)
The Russian Federation characterised major ICT developers as threats in themselves, arguing they 'make no secret of how deeply they are embedded in the military-industrial complexes of the countries where they are registered' and 'often act as contractors for intelligence agencies and military departments' , framing private sector involvement as a source of instability. Japan, by contrast, argued that 'it is essential to draw on the expertise of a wide range of stakeholders, including the private sector' and placed 'great importance on holding expert briefings and interactive public-private discussions' . Chile similarly called for 'the participation of experts, regional organisations, the scientific community, the private sector, as well as other interested parties' . France and Greece focused on the proliferation of commercial cyber intrusion tools as a concern requiring oversight, with France warning that 'without minimal oversight and accountability measures, the number of actors, including non-state actors, capable of acquiring advanced capabilities will continue to grow' , and Greece welcoming the Pall Mall process to build consensus on responsible use .
Monetisation of the private sector (Russian Federation)
Common understanding through multi-stakeholder engagement (Japan)
Evidence-based forward-looking dialogue in DTG1 (Chile)
Commercial cyber tools undermining human rights (Greece)
Uncontrolled proliferation of commercial cyber tools (France)
The dedicated stakeholder session acknowledged that 'stakeholders have a significant role in addressing contemporary issues' in cyberspace [S174], reflecting the multi-stakeholder dimension of this debate. The characterisation of private sector actors as either partners or threats varies significantly across state groupings, a tension visible in broader UN ICT governance discussions.
Iran identified 'disinformation and cognitive operations' and 'the manipulation of digital platforms including Instagram, X, and Telegram to incite violence, spread hatred, deepen social divisions' as significant threats , and listed 'the use of ICTs for disinformation and cognitive operations' among threats previously identified by Iran that should be prioritised . Russia similarly highlighted the use of ICTs to 'undermine the sovereignty of states' and 'interfere in their internal affairs' . Albania and Zimbabwe supported treating disinformation as a security concern, with Albania noting that cyber incidents were combined with 'attempts to spread disinformation and manipulate public perception through social media' . However, Micronesia offered a cautionary counterpoint, warning that 'vague approaches can suppress dissent and independent media, erode human rights, politicise enforcement, weaken trust in institutions, and disproportionately harm marginalised and remote communities' , and urging states to 'adopt precise time-bound and rights-based definitions of disinformation' .
Disinformation and cognitive operations as ICT threats (Islamic Republic of Iran)
ICT misuse against UN Charter principles (Russian Federation)
Rights-respecting definitions of disinformation (Micronesia)
Combination of cyber operations and disinformation (Albania)
Disinformation and AI-enabled deception (Zimbabwe)
The agenda item 5 discussions flagged 'ICT in Disinformation Campaigns and Cognitive Operations' as a distinct and contested threat category [S158]. Cuba's opening statement emphasised the need to address cyber threats with social and political dimensions [S159], while other states have resisted expanding the mechanism's mandate to cover information content. The appropriate scope of disinformation within ICT security frameworks remains a live debate across multiple UN forums [S174][S176].
The Russian Federation argued that 'a number of states are openly declaring and enshrining in their doctrinal documents a shift from purely defensive operations in the information space to offensive ones' and characterised this as 'a threat to global security' . China similarly stated that 'a certain country seeks so-called unrivaled supremacy, aggressively develops offensive cyber military capabilities' and 'openly declares that cyber capability is used to destroy other countries' critical infrastructure, completely break the taboo on cyber warfare' . The United States, by contrast, stated it would 'specifically identify the states and non-state actors who are perpetuating malicious cyber activities against others in this room' and that 'President Trump has been clear. If a country is utilizing the cyber domain to hurt others, in this chamber, the United States will make them pay a heavy price' , implying a willingness to use offensive capabilities as deterrence. Australia took a more measured position, stating that 'state responses, including the development and use of cyber capabilities, must be consistent with international law, including the UN Charter in its entirety, international human rights law and international humanitarian law' .
The use of ICTs for offensive purposes (Russian Federation)
Condemnation of malicious cyber activities by member states (United States)
State cyber capabilities must comply with international law (Australia)
Multilateralism and digital sovereignty in cyber governance (China)
The Russian Federation argued that 'low-orbit satellite communication systems created under the pretext of providing reliable Internet connectivity for civilian purposes' are 'in fact used for military-political objectives in the interests of certain countries' , citing cases where such systems were used 'to interfere in the internal affairs of states by inciting protests, as well as their use in armed conflicts' . Russia called for operators to 'act in strict accordance with the national legislation of the countries in which they provide their services' . Iran similarly described 'the misuse of Starlink satellite communication services to facilitate hostile operations' as part of attacks against Iran . These positions were not directly addressed or contested by Western states in the transcript, though the United States' broader framing of the mechanism as focused on implementing existing norms rather than creating new regulatory frameworks implicitly conflicts with calls for new satellite regulation.
Militarisation of low-orbit satellite systems (Russian Federation)
Supply chain exploitation as a cyber threat (Islamic Republic of Iran)
It was unexpected that Micronesia, a small Pacific Island state generally aligned with Western positions on cybersecurity, offered a cautionary note on disinformation that implicitly challenged the positions of both Western states (who raised disinformation as a Russian threat) and non-Western states (who raised it as a tool of interference). Micronesia warned that 'vague approaches can suppress dissent and independent media, erode human rights, politicise enforcement, weaken trust in institutions, and disproportionately harm marginalised and remote communities, while also impairing crisis response' , and called for 'precise time-bound and rights-based definitions of disinformation' . This created an unexpected three-way tension: Iran and Russia framing disinformation as a tool used against them , Albania and Zimbabwe treating it as a security threat to be addressed , and Micronesia warning that addressing it without rights-based definitions could itself become a threat to human rights .
It was unexpected that the very first substantive session of the new permanent global mechanism became a venue for sharp bilateral political exchanges, with Iran making extensive allegations against the US and Israel , Israel responding with a right of reply , the United States making pointed remarks about Iran and about unnamed states conducting malicious activities , and Russia accusing Western states of 'outrageous anti-Russian remarks' and 'blatant disinformation' . The Russian Federation even called upon the Chair 'to prevent the discussions within the global mechanism from turning into a political crisis' , while itself making politically charged statements. The Chair had to intervene to clarify that rights of reply should be made at the end of the meeting , indicating that the level of political confrontation was not anticipated in the procedural design of the session.
New Zealand's explicit call for the mechanism to avoid duplicating other UN processes on AI was unexpected given the broad consensus among other states that AI threats should be deeply discussed within this mechanism. New Zealand stated that 'there are a variety of other UN processes that are actively grappling with questions related to artificial intelligence including governance issues' and that 'the global mechanism does not duplicate those processes' . This contrasted with China's call for 'establishing global standards and system for testing and assessing the risk of large AI models' within this mechanism , the Republic of Korea's call for the mechanism to 'deepen discussions on AI-enabled cyber threats' , and France's detailed discussion of how the mechanism 'must address these two aspects and delve deeper into how the framework for responsible behaviour applies to these issues' . The disagreement over the appropriate scope of AI discussions within this specific mechanism versus other UN bodies was not widely anticipated.
The Russian Federation's characterisation of major ICT developers as embedded in 'military-industrial complexes' and acting as 'contractors for intelligence agencies and military departments' , Iran's specific naming of Cisco, HP, and Starlink as tools used in attacks against Iran , and China's reference to 'a certain country' that 'draws an ideological line and coerces others into taking sides under the guise of cyber security' represented an unexpected framing of Western technology companies as threats rather than partners. This directly contradicted the positions of Japan, Chile, and others who called for greater private sector involvement in the mechanism's work . The depth of this disagreement about the role of private technology companies was more pronounced than might have been anticipated in a forum ostensibly focused on state behaviour.
The discussion revealed deep and multifaceted disagreements across several dimensions. The most fundamental disagreement concerned the attribution of state-sponsored cyber attacks, with Western states (France, Germany, UK allies, Ukraine, Poland, Albania) making specific attributions against Russia , while Russia categorically rejected these as 'false and fabricated accusations' without evidence . A parallel dispute between Iran and Israel/United States dominated a significant portion of the session . Beyond these bilateral disputes, there were structural disagreements about the mechanism's purpose: the United States insisted on implementation of existing norms rather than new agreements , while China and others called for new international rules . There was also disagreement about the scope of threats to be addressed, with some states seeking to include disinformation, cognitive operations, and satellite systems , while others focused on more traditional cybersecurity threats. The role of the private sector was contested, with Russia and China viewing Western tech companies with suspicion , while Japan, Chile, and others sought to incorporate them as partners . Procedurally, the session was marked by unexpected political confrontations that the Chair had to manage , with Russia explicitly calling for the Chair to prevent the mechanism from 'turning into a political crisis' .
All Pacific Island Forum members and Australia agreed that submarine cable infrastructure is critically important and requires protection, with Tonga describing how the 2022 volcanic eruption demonstrated the catastrophic consequences of connectivity loss and Kiribati stating that 'damage to or disruption of our submarine cable whether by malicious cyber activity or otherwise will not degrade our services it will sever them' . Australia stated that 'the resilience of undersea cable infrastructure is fundamental to economic and social connectivity' , and Ghana highlighted the damage to Submarine Cable 7 Ghana in 2024 . However, they differed on emphasis: Pacific Island states framed this as an existential threat requiring immediate practical cooperation , while Australia focused on it as an 'early focus' for the mechanism through DTG1 , and Tuvalu called for 'clear protocols for protecting subsea infrastructure' . The disagreement lies in the urgency and the specific mechanisms needed to address this shared concern.
Submarine cable as existential infrastructure (Kiribati) Submarine cable sabotage as a grave threat (Tonga) Undersea cable resilience as a priority (Australia) Ransomware and AI threats (New Zealand) Action-oriented mechanism with concrete outcomes (Tuvalu) Protecting submarine cables as strategic assets (Ghana) Growing threats to critical infrastructure (Canada)
There was broad agreement that AI is transforming the cyber threat landscape and lowering barriers for malicious actors. The Netherlands stated that 'large language models and other AI systems can lower the barrier for conducting sophisticated operations' , Germany noted that 'the advent of advanced cyber capabilities facilitates large-scale attacks including language-agnostic credible phishing' , and Latvia stated that 'AI-enabled tools can automate reconnaissance, accelerate and scale vulnerability discovery, and generate highly convincing phishing campaigns' . China agreed that 'a new generation of large models issued by certain AI companies have demonstrated powerful cyber capabilities, both offensive and defensive' . However, speakers disagreed on governance responses: New Zealand argued the mechanism should avoid duplicating other UN processes and focus only on 'building shared understanding of the implications of AI for cybersecurity' , while China called for 'establishing global standards and system for testing and assessing the risk of large AI models' , and France highlighted the risk of a 'new digital divide' between those with and without access to frontier AI models .
Generative AI as a threat amplifier (Netherlands) AI acceleration of offensive operations and digital divide (France) AI lowering barriers for malicious actors (Germany) AI-enabled tools supercharging malicious cyber activities (Latvia) AI enabling malicious actors at scale (Australia) Ransomware and AI threats (New Zealand) Common understanding through multi-stakeholder engagement (Japan) Frontier AI transforming the threat landscape (Republic of Korea) New generation large AI models posing real and immediate threats (China) AI enabling malicious activities at unprecedented scale (Malawi)
All speakers agreed that capacity building is essential and that developing countries face disproportionate challenges. The Bahamas stated that 'for small island developing states, capacity building is a precondition for participation' , Zimbabwe noted that 'capacity constraints and uneven cyber resilience increase our vulnerability and limit our ability to effectively respond to cyber incidents' , and Australia acknowledged that 'cyber threats are shared, but their impacts are not experienced equally' . However, they differed on mechanisms: Cameroon specifically called for 'the establishment of the Dedicated Voluntary Fund under the Global Mechanism' , while Mozambique emphasised that capacity building must be 'accompanied by technology transfer, institutional strengthening, and equitable access to knowledge and expertise' . The Bahamas focused on ensuring information sharing is 'genuinely accessible to small island states' , while Malawi emphasised strengthening national CERTs and early warning mechanisms .
Capacity building as precondition for SIDS participation (Bahamas) Cooperation as essential complement to national action (Kiribati) Small state attribution and accountability (Tonga) Capacity constraints in developing countries (Zimbabwe) Strengthening national response capabilities (Malawi) Dedicated Voluntary Fund for developing countries (Cameroon) Sustainable and equitable capacity building (Mozambique) Regional cooperation for resilience building (Indonesia) Unequal impact of cyber threats and capacity gaps (Australia)
Multiple speakers agreed that the dedicated thematic groups should be action-oriented and informed by expert knowledge, but differed on how to achieve this. Egypt argued for 'a pool of experts that will help us in those discussions' accepted by delegations through consensus . Japan placed 'great importance on holding expert briefings and interactive public-private discussions in the substantive plenary sessions and DTGs' . Chile called for 'the participation of experts, regional organisations, the scientific community, the private sector, as well as other interested parties' . Latvia stated that DTGs should 'focus on specific ICT security challenges, enabling states to examine threats, share experience, and develop practical approaches' . The key difference is Egypt's emphasis on a pre-agreed, consensus-based pool of experts , which could be seen as more restrictive than the broader multi-stakeholder approach advocated by Japan and Chile.
Dynamic expert-based discussions in thematic groups (Egypt) Expert briefings within the mechanism (Japan) Evidence-based forward-looking dialogue in DTG1 (Chile) Action-oriented mechanism with concrete outcomes (Kiribati) DTGs as vehicles for practical action (Latvia)
The United States expressed solidarity with Pacific Island states, stating 'To Tonga and Kiribati, the United States hears you, and we thank you for your strong statements. While others in this chamber are planning and targeting you, The United States will be there to help protect you' . Tonga and Kiribati welcomed practical cooperation, with Tonga noting that 'with the support of partners, our health systems were restored and services maintained' and that joint attribution with Australia and New Zealand demonstrated 'that even the smallest states acting with partners can pursue accountability' . However, the Pacific Island states focused on practical cooperation and concrete outcomes , while the United States framed its engagement more in terms of accountability and deterrence, warning that 'if a country is utilizing the cyber domain to hurt others, in this chamber, the United States will make them pay a heavy price' , a more confrontational framing than the cooperative approach emphasised by Pacific states.
Condemnation of malicious cyber activities by member states (United States) Action-oriented mechanism with concrete outcomes (Kiribati) Small state attribution and accountability (Tonga) Intensifying cyber threat environment (Australia) Ransomware and AI threats (New Zealand)
- The Global Mechanism on Developments in the Field of Information and Communication Technologies and Advanced Responsible State Behaviour held its first substantive plenary session, marking a historic transition from the Open-Ended Working Group (OEWG) to a permanent mechanism.
- The cyber threat landscape is universally acknowledged as intensifying in scale, sophistication, and transnational reach, affecting critical infrastructure, essential services, governments, businesses, and individuals across all regions.
- Ransomware was identified by numerous delegations as one of the most pervasive and destructive cyber threats, with real-world impacts on healthcare, energy, financial services, and public administration, including specific incidents in Tonga, Latvia, and Germany.
- Artificial intelligence was consistently highlighted as a dual-use technology that is both amplifying offensive cyber capabilities (lowering barriers for malicious actors, enabling sophisticated phishing, autonomous vulnerability discovery) and offering significant defensive opportunities.
- Small island developing states (SIDS), including Kiribati, Tonga, Tuvalu, Bahamas, and Micronesia, emphasised that their limited redundancy, dispersed populations, and reliance on submarine cable infrastructure make them disproportionately vulnerable to cyber threats, with disruptions being existential rather than merely disruptive.
- The protection of critical infrastructure, particularly submarine cables and undersea communications infrastructure, was identified as a shared international responsibility and a priority for the mechanism's first Dedicated Thematic Group (DTG1).
- There is broad consensus that the mechanism must be action-oriented, moving beyond the identification and description of threats towards concrete, practical steps that enable all states to prevent, detect, and respond to malicious ICT activities.
- The blurring of boundaries between state-sponsored actors and non-state proxies, including hacktivist groups and criminal syndicates operating from state-sanctioned safe havens, was identified as one of the most problematic and growing trends in the threat landscape.
- Multiple delegations, including France, Germany, Poland, Estonia, and Ukraine, publicly attributed sustained malicious cyber activities to Russian state actors, including the FSB, targeting government entities, critical infrastructure, and democratic processes in EU member states and Ukraine.
- Iran detailed extensive cyber attacks it attributed to the United States and Israel during military operations in 2026, while Israel and the United States rejected these characterisations and offered counter-narratives, reflecting deep geopolitical divisions within the mechanism.
- Capacity building was consistently identified as a precondition for meaningful participation by developing countries, with calls for it to be sustainable, demand-driven, tailored to national circumstances, and accompanied by technology transfer and institutional strengthening.
- International law, including the UN Charter, was reaffirmed by the vast majority of delegations as the foundation for responsible state behaviour in cyberspace, with voluntary norms and confidence-building measures seen as complementary rather than substitutes for binding legal obligations.
- The Dedicated Thematic Groups (DTGs) were widely seen as the primary vehicle for translating high-level threat discussions into practical, action-oriented outcomes, with calls for expert briefings, evidence-based dialogue, and multi-stakeholder participation.
- Disinformation, influence operations, and hybrid threats combining cyber operations with information manipulation were identified as an increasingly significant and complex dimension of the threat landscape.
- Supply chain security, including the risks posed by backdoors, undeclared malicious capabilities, and the deliberate insertion of vulnerabilities into ICT products, was raised as a growing concern, particularly for developing countries.
- The proliferation of commercial cyber intrusion capabilities without adequate oversight was identified as a significant risk multiplier, with France and the United Kingdom highlighting the Pall Mall Process as a relevant initiative.
- Quantum computing was noted by several delegations, including Malaysia and Chile, as an emerging future risk requiring proactive attention, particularly regarding the security of current encryption systems.
“Tonga's delegation drew a direct parallel between the 2022 Hunga Tonga-Hunga Ha'apai volcanic eruption severing their submarine cable and the potential for deliberate malicious acts: 'We learned everything a volcano did to Tonga by accident, a malicious act could choose to do deliberately.' They also noted their joint attribution of a ransomware attack on their Ministry of Health with Australia and New Zealand, demonstrating that 'even the smallest states acting with partners can pursue accountability for malicious cyber activities.'”
“Kiribati stated: 'Discussion of threats must not end as descriptions of threats. Each threat identified in this room should connect to a concrete step... that leaves every state, including the smallest, able to prevent, detect, and respond. If this mechanism can do that from its very first session, it would have proven its worth not only to the states in this room but to every community that depends on it.'”
“Egypt proposed that discussions in dedicated thematic groups should be 'dynamic, based on real case scenarios' and, crucially, that they must be supported by 'a proper and accepted pool of experts by delegations,' adding: 'Having discussions on threats without a professional, experienced, and relevant pool of experts is, again, a waste of time.' Egypt was careful to note this was not about blocking experts but about achieving consensus on relevance.”
“The Islamic Republic of Iran delivered a detailed account of over 100 cyber attacks per day during the February 2026 aggression, cataloguing coordinated cyber and kinetic attacks, attacks on civilian institutions, exploitation of commercial technologies including Cisco and HP products, misuse of Starlink, and cognitive operations via Instagram, X, and Telegram. Iran also called for attention to threats 'previously identified by Iran' including 'weaponisation of the ICT environment, monopoly in Internet governance, false flag operations and fabricated attribution, and unilateral coercive measures in the ICT domain.'”
“The United States stated: 'As long as some members in this hall are maliciously conducting cyber actions against other members, a legally binding agreement is impossible... There are members in this chamber right now who are planning and conducting malicious cyber actions against other members' critical infrastructure... President Trump has been clear. If a country is utilizing the cyber domain to hurt others, in this chamber, the United States will make them pay a heavy price.'”
“France identified three trends: the blurring of state and non-state actor boundaries, AI's impact on cyber capabilities, and the 'uncontrolled proliferation of cyber intrusion capabilities available on the market,' which France described as 'a veritable ticking time bomb.' France also announced the launch of negotiations on guidelines for the cyber intrusion industry under the Pall Mall Process, building on the April 2025 Code of Good Practices for States.”
“The Russian Federation raised four specific threats: the 'monetisation of the private sector' (major ICT companies embedded in military-industrial complexes), the shift from defensive to offensive ICT operations by certain states, 'undeclared malicious capabilities' (backdoors embedded by developers for intelligence agencies), and the military use of low-orbit satellite communication systems. Russia stated: 'Such tools are used for intelligence, espionage, interception of personal data and private correspondence. And as shown by the infamous Pager incident in Lebanon in 2024, they're used for causing physical damage.'”
“The Bahamas highlighted three priorities that were distinct from the dominant infrastructure-focused discourse: cyber threats to youth, cyber threats to women (specifically technology-facilitated gender-based violence), and the principle that 'participation for women is not complete unless women are at the table, in delegation, in technical decision-making, and in the design of national ICT policies.' The Bahamas also emphasised the 'nexus between cyber threat and natural disaster' as a specific concern for small island states.”
“China stated: 'In the past, the risk posed by AI was merely theoretical. But now we see firsthand the real threats AI poses. So this mechanism, including the DTG, is not an option. It is our responsibility.' China also called for 'establishing global standards and system for testing and assessing the risk of large AI models to ensure that AI will serve as a new shield for cybersecurity rather than a new tool for unilateral pursuit of hegemony,' and criticised 'small circle governance' as unable to solve global challenges.”
“Malawi emphasised: 'It is not only the emergence of these threats that should concern us, but their persistence. Persistent and covert malicious ICT activities can remain undetected for extended periods of time, gradually undermining public trust, disrupting essential services, weakening national resilience, and causing significant economic and societal harm. For many developing countries, just like Malawi, responding to one cyber incident is already difficult. Responding to sustained campaigns is an even greater challenge.'”
How should the dedicated thematic groups (DTGs) structure their discussions on threats to avoid simply replicating plenary discussions, and what format would make them most effective?
Egypt raised the concern that DTG discussions risk becoming a mirror of plenary discussions, which would waste time and miss opportunities. Determining an effective, dynamic format based on real case scenarios is critical to producing tangible outcomes from the mechanism.
What criteria and process should be used to compile and agree upon a pool of experts to inform threat discussions in the dedicated thematic groups?
Multiple delegations stressed the need for relevant, experienced experts to guide threat discussions. Without a consensus-based, professionally credible pool of experts, discussions risk being uninformed. The process for selecting and agreeing on such experts requires further elaboration.
How can the global mechanism ensure that each identified threat is matched with a concrete, actionable step for prevention, detection, and response, particularly for small island developing states?
Small island developing states emphasised that threat discussions must not end as mere descriptions. Translating identified threats into practical cooperative measures is essential for the mechanism to prove its worth, especially for the most vulnerable states.
What practical measures and international cooperation frameworks can be developed to protect submarine cable infrastructure from both malicious cyber activity and physical sabotage?
Several Pacific island states and Australia highlighted that submarine cable disruption is an existential threat for some nations. Further research is needed on international legal frameworks, technical standards, and cooperative response protocols specifically for undersea cable protection.
How is artificial intelligence transforming the cyber threat landscape, and what specific implications does this have for existing cyber defence mechanisms and the framework of responsible state behaviour?
Numerous delegations noted that AI is rapidly changing the scale, speed, and sophistication of cyber threats while also offering defensive opportunities. A deeper, structured discussion is needed on how AI affects existing norms, what new vulnerabilities it creates, and how states can harness it defensively without duplicating other UN processes.
How should the global mechanism address the blurring of lines between state and non-state actors, including the use of proxies, hacktivist groups, and criminal syndicates by states to maintain plausible deniability?
The convergence of state-sponsored and non-state malicious cyber activity complicates attribution and accountability. Further research is needed on how existing norms and international law apply to proxy actors and how states can be held responsible for activities they tolerate or direct.
What governance frameworks or international standards should be developed to oversee the proliferation of commercial cyber intrusion capabilities and prevent their misuse?
The uncontrolled proliferation of commercial cyber tools poses risks to privacy, human rights, and international security. The Pall Mall process was cited as a relevant initiative, but further international dialogue and research are needed to build consensus on accountability and oversight mechanisms.
How can cyber threat information sharing be made genuinely accessible to small island developing states and other developing countries with limited technical capacity?
Developing countries, particularly small island states, face significant barriers to accessing timely threat intelligence. Research is needed on how to design information-sharing mechanisms that are inclusive, accessible, and practically useful for states with thin technical workforces and limited resources.
What concrete capacity-building measures, tailored to the specific needs of developing countries, should be prioritised under the global mechanism to ensure meaningful participation and resilience?
Capacity building was identified as a precondition for participation by many developing states. Further work is needed to define what sustainable, demand-driven, and nationally owned capacity building looks like in practice, including financing mechanisms such as the proposed Dedicated Voluntary Fund.
How should the global mechanism address technology-facilitated gender-based violence, including online harassment and image-based abuse, as a distinct cyber security concern?
The Bahamas highlighted that cyber threats disproportionately affect women and girls through technology-facilitated gender-based violence. This area requires dedicated attention within the mechanism's threat discussions and capacity-building efforts, yet it remains underexplored in current frameworks.
How can the global mechanism address the nexus between cyber threats and natural disasters, particularly for small island developing states vulnerable to both?
The intersection of cyber threats and natural disaster scenarios (e.g., a malicious actor exploiting the same vulnerabilities exposed by a natural disaster) represents a distinct and underexplored risk. Further research is needed on how to build resilience that addresses both simultaneously.
What practical steps can states take to implement the voluntary norm that states should not knowingly allow their territory to be used for internationally wrongful acts using ICTs, and how can compliance be assessed?
Several delegations reaffirmed this norm but noted the lack of practical tools to verify or encourage compliance. Research is needed on monitoring mechanisms, confidence-building measures, and diplomatic channels that can operationalise this norm effectively.
How should the global mechanism deepen discussions on ransomware, including its use as a financing mechanism for illicit activities such as arms trafficking and weapons development, and what cooperative measures can be developed?
Ransomware was identified by many delegations as one of the most pervasive and destructive threats, with links to broader illicit financing. Further structured discussion is needed on practical international cooperation measures, including information sharing, attribution, and accountability for ransomware actors.
How should the global mechanism address cryptocurrency theft and its role in financing illicit activities, including the development of weapons of mass destruction?
The Republic of Korea noted that cryptocurrency theft has become a major source of illicit financing and that this issue was recognised in the OEWG final report. Further in-depth discussion is needed to develop concrete cooperative measures to address this threat under the new mechanism.
What international frameworks or norms should govern the use of low-orbit satellite communication systems to prevent their misuse for military-political objectives or interference in the internal affairs of states?
The Russian Federation raised concerns about the dual-use nature of low-orbit satellite systems such as Starlink. This area requires further research on applicable international law, governance frameworks, and the responsibilities of operators under national and international law.
How should the global mechanism address the issue of undeclared malicious capabilities, including hardware and software backdoors embedded by developers at the behest of intelligence agencies?
The existence of backdoors in widely used ICT products poses significant risks to national security and supply chain integrity. Further research is needed on international standards, transparency requirements, and accountability mechanisms for ICT developers and states that mandate such capabilities.
How should the global mechanism handle the militarisation of the private ICT sector, including the integration of major technology companies into national military-industrial complexes and intelligence operations?
Both the Russian Federation and China raised concerns about the blurring of lines between commercial ICT companies and state military or intelligence activities. This raises questions about the applicability of existing norms to private sector actors and the risks to international stability.
What mechanisms can be developed to ensure that discussions on AI-related cyber threats within the global mechanism complement rather than duplicate existing UN processes on AI governance?
New Zealand and Israel both cautioned against duplicating other UN processes on AI. Further clarity is needed on the specific added value of the global mechanism in addressing AI-cyber security intersections, and how it should coordinate with other relevant forums.
How can the global mechanism develop a consolidated, agreed compilation of threats identified by member states, building on the OEWG Chair Summary, to serve as a practical basis for DTG discussions?
Iran proposed that the mechanism prioritise threats already identified by member states before expanding to new areas, and called for a consolidated compilation under the Chair's authority. This raises questions about methodology, inclusivity, and how to ensure all states' security concerns are reflected.
How should the global mechanism address the use of ICTs for disinformation, cognitive operations, and information manipulation, including the exploitation of social media platforms, as a distinct threat to international security?
Multiple delegations raised concerns about disinformation and cognitive operations as a growing component of hybrid cyber threats. Further research is needed on how existing norms apply, what rights-respecting definitions of disinformation should look like, and what cooperative measures can be developed.
How can the global mechanism address the security implications of quantum computing, particularly regarding the vulnerability of current encryption systems, and what cooperative measures should be developed?
Chile and Malaysia both identified quantum computing as an emerging threat to existing cryptographic infrastructure. Further research is needed on timelines, the scope of vulnerability, and international cooperation on post-quantum cryptography migration, particularly for developing countries.
How should the global mechanism address the exploitation of digital supply chains, including cloud-connected software and ICT hardware, as a vector for malicious cyber activity?
Supply chain vulnerabilities were identified as a significant and growing threat. Further research is needed on international standards, best practices, and cooperative frameworks for securing ICT supply chains, particularly given their cross-border nature and the involvement of private sector actors.
What practical guidelines should the DTGs develop for protecting critical infrastructure in developing countries, including securing industrial control systems, energy grids, and essential services?
Developing countries face specific challenges in protecting critical infrastructure due to limited resources. Further work is needed to translate general norms into practical, context-specific guidelines that address the needs of less-resourced states, including through public-private partnerships.
How can the global mechanism strengthen national computer emergency response teams (CERTs) and enhance cyber threat intelligence sharing, including early warning mechanisms, particularly for developing countries?
Many delegations highlighted the importance of CERTs and threat intelligence sharing for resilience, but noted that developing countries face significant capacity constraints. Further research is needed on how to build sustainable, interoperable CERT networks and accessible intelligence-sharing platforms.
How should the global mechanism address the growing impact of cyber threats on youth, including cyberbullying, online manipulation, and exposure to disinformation, as an emerging security concern?
Both the Bahamas and Albania highlighted the specific vulnerabilities of young people to cyber threats, including AI-enabled manipulation and disinformation. This area requires dedicated attention within the mechanism's threat discussions and may warrant specific cooperative measures.
What role should non-state actors, including the private sector, academia, civil society, and technical experts, play in the DTGs and plenary discussions, and how should their participation be structured?
Multiple delegations stressed the importance of drawing on expertise beyond government, including from the private sector and technical community. Further clarity is needed on the modalities for stakeholder engagement within the global mechanism's architecture.
How should the global mechanism address the use of ICTs by terrorist groups, including for recruitment, financing, planning, and targeting of critical infrastructure?
Iraq and Oman raised the specific threat of terrorist exploitation of ICTs, drawing on national experience. Further research is needed on how existing counter-terrorism frameworks intersect with the cyber security norms framework and what cooperative measures can be developed.
How can the global mechanism develop practical tools to assess whether states are abiding by agreed norms, moving beyond threat identification to monitoring and accountability?
Oman stressed the need to move from discussing threats to developing practical tools for assessing norm compliance. This raises important questions about verification, transparency, and the role of confidence-building measures in holding states accountable.
What international standards and risk assessment systems should be developed for frontier AI models to prevent their use as tools for offensive cyber operations or unilateral pursuit of hegemony?
China, Canada, and Latvia all raised concerns about the unprecedented offensive and defensive capabilities of frontier AI models. Further research is needed on how to establish globally agreed standards for testing and assessing the risks of large AI models within a multilateral framework.
How should the global mechanism address the illicit financing of malicious cyber operations through digital assets and cryptocurrencies, including tracking, freezing, and seizing such assets?
Israel highlighted the use of digital assets to finance cyber criminal syndicates and terrorist proxies operating from state-sanctioned safe havens. Further research is needed on international cooperation mechanisms for tracking and disrupting illicit cryptocurrency flows linked to malicious cyber activity.
How can the global mechanism ensure that its discussions on AI and emerging technologies remain forward-looking and responsive to the rapidly changing technological environment, given the pace of development since the OEWG final report?
The Republic of Korea and others noted that the threat landscape has evolved significantly even since the OEWG final report. The mechanism needs to develop processes for keeping its threat assessments current and technically informed, which may require regular expert briefings and structured updates.
What measures can be taken to address the growing threat of large-scale covert networks of internet-connected devices (botnets) being used to disguise the origins and attribution of cyber attacks?
Canada highlighted a joint advisory on defending against state-linked covert networks used to obscure attribution. Further research and cooperative measures are needed to address this specific threat, including technical standards, information sharing, and attribution methodologies.
How should the global mechanism address the specific cyber security challenges faced by land-locked developing countries that rely on interconnected regional telecommunications networks, given the cross-border consequences of vulnerabilities in shared digital infrastructure?
Zimbabwe highlighted the specific vulnerabilities of land-locked states dependent on regional telecommunications networks. This represents an underexplored dimension of critical infrastructure protection that requires tailored research and cooperative frameworks.
