WSIS Forum 2026
Rapport généré par l'IA

The Global Shield: Collaborative Cyber Resilience for global e-Commerce and logistics

5 intervenants
Résumé

Résumé

La discussion a porté sur les efforts de l’UPU pour renforcer la cyberrésilience dans l’ensemble de l’écosystème mondial du commerce électronique et de la logistique, en partant du principe que les achats en ligne dépendent d’un vaste réseau de livraison numériquement interconnecté, et non d’un simple site web marchand. La modératrice a fait valoir que, les cybercriminels ciblant désormais des écosystèmes entiers, aucun pays, opérateur postal ou entreprise ne peut se protéger seul, ce qui rend la défense collective essentielle. André Pharand a présenté les conclusions préliminaires d’une enquête de l’UPU sur la cybersécurité menée à la fin de 2024, qui a recueilli 152 réponses sur 192 pays membres, soit un taux de réponse de 76 pour cent. Il a indiqué que les données montraient que seule environ la moitié des opérateurs mettaient en œuvre ou développaient les huit mesures de cyberhygiène, avec des résultats particulièrement faibles en matière de gestion des risques, de réponse aux incidents et de gestion de crise. Pharand a également mis en évidence une pression croissante sur les capacités : les charges de travail augmentent, les budgets ne suivent pas, seuls environ 35 pour cent des opérateurs sont reliés à une équipe nationale de réponse aux incidents, et de nombreux répondants ont demandé des formations, des financements, des orientations et un appui d’experts. Massimiliano Aschi a décrit un paysage de menaces porté par des organisations criminelles opérant à l’échelle industrielle, qui utilisent l’IA pour repérer les vulnérabilités, adapter les attaques et abaisser la barrière technique pour les acteurs malveillants, rendant les attaques plus rapides et plus difficiles à prévenir. Il a soutenu que la collaboration au sein des secteurs et entre eux est désormais inévitable, mais que les progrès ont été limités par le manque de ressources, la méfiance et l’inégalité des capacités ; la résilience doit donc être abordée de manière systémique plutôt que fragmentée. Tracy Hackshaw a expliqué que la proposition de travail 309 de l’UPU vise à créer une base minimale de sécurité pour le secteur postal, à fournir une feuille de route aux opérateurs les moins avancés et à soutenir un accès équitable à la formation, au renforcement des capacités et à d’autres ressources. Elle a également souligné la nécessité d’informer les clients sur les faux messages relatifs aux colis et l’usurpation des identités postales, en notant que les opérateurs n’apprennent souvent l’existence de telles attaques que lorsque les clients les signalent. Les recommandations d’André consistaient à fournir des financements, des formations mutualisées et des équipes d’experts, des guides opérationnels de reprise, un soutien prioritaire aux opérateurs les moins préparés, ainsi que des évaluations pratiques pour vérifier le niveau de préparation. Le panel a présenté Post-ISAC, Trust .post, les domaines .post et Secure .post comme des mécanismes concrets de partage des menaces, d’identité numérique de confiance et d’outils de sécurité destinés au public.

Lors de l’échange avec le public, les intervenants ont indiqué que l’UPU prévoit de travailler avec les autorités nationales compétentes en cybersécurité, les CERT, les CERT sectoriels, d’autres ISAC et FIRST afin de renforcer la résilience aux niveaux national et mondial, tout en mentionnant également la coopération avec l’Organisation mondiale des douanes sur les questions de sécurité et de partage des données.

La session s’est conclue sur le constat que la cyberrésilience dans le commerce électronique et la logistique dépend d’un renforcement de la confiance, de la coordination et du soutien aux opérateurs les plus fragiles tout au long de la chaîne d’approvisionnement.

Points clés

- La session a présenté le commerce électronique comme étant bien plus que des interfaces d’achat en ligne : un clic sur « acheter » un réseau logistique mondial complexe composé de postes, de douanes, de compagnies aériennes, d’entrepôts et de systèmes de transport, ce qui signifie qu’une cyberattaque touchant un nœud peut perturber l’ensemble de l’écosystème. Cela a conduit à l’argument central selon lequel aucun pays ni aucune organisation ne peut se défendre seul et que la défense collective est nécessaire. - Les résultats de l’enquête d’André Pharand ont montré d’importantes lacunes en matière de cybersécurité dans l’ensemble du réseau postal malgré une forte participation des membres de l’UPU. L’enquête de 2024 a recueilli 152 réponses sur 192 membres, a constaté seulement environ 50 % de mise en œuvre/développement des mesures fondamentales de cyberhygiène, et a mis en évidence des faiblesses dans des domaines tels que la gestion des risques, la réponse aux incidents et la gestion de crise, avec des disparités régionales notables. - Un thème majeur a été l’écart entre l’augmentation des exigences en matière de cybersécurité et des capacités limitées. Les répondants ont signalé une hausse des charges de travail liées à la cybersécurité sans augmentation correspondante des budgets ; certains opérateurs ont même vu leurs budgets réduits. De nombreux opérateurs n’avaient pas non plus de liens avec les structures nationales de réponse aux incidents, et les commentaires libres ont souligné les besoins en financement, en formation, en modèles, en orientations et en accès à des experts. - Massimiliano Aschi a souligné que les cybermenaces sont désormais portées par des écosystèmes criminels opérant à l’échelle industrielle, de plus en plus accélérés par l’usage malveillant de l’IA. Il a soutenu que les attaques deviennent plus rapides, plus difficiles à détecter et plus faciles à lancer pour des acteurs moins qualifiés, ce qui rend indispensable - et non facultative - une coopération systémique, intersectorielle et transfrontière. - La discussion s’est fortement concentrée sur la réponse pratique et normative de l’UPU : la proposition de travail 309 vise à établir une base minimale de cybersécurité et un soutien équitable aux pays les moins préparés, tandis que des initiatives telles que Post-ISAC, Trust .post, les domaines .post et Secure .post ont pour objet de transformer les politiques en résilience opérationnelle grâce à des domaines de confiance, au partage du renseignement sur les menaces, à la formation et à des outils de sécurité destinés au public.

L’objectif général de la discussion était d’examiner comment l’Union postale universelle et ses partenaires peuvent renforcer la cyberrésilience dans l’ensemble de l’écosystème mondial postal, logistique et du commerce électronique. Le panel visait à relier politiques publiques, éléments probants tirés de l’enquête et expérience opérationnelle afin d’identifier les vulnérabilités, d’expliquer pourquoi une défense coordonnée est nécessaire et de présenter des mécanismes concrets ainsi que des recommandations pour améliorer la résilience à l’échelle du secteur.

Le ton général était professionnel, collaboratif et empreint d’urgence. Il a commencé de manière accessible et explicative en élargissant la compréhension du public de ce qu’implique réellement le commerce électronique, puis est devenu plus grave et plus prudent à mesure que les intervenants décrivaient des vulnérabilités systémiques, des lacunes de capacités et la menace croissante de la cybercriminalité organisée et des attaques facilitées par l’IA. À la fin, le ton a légèrement évolué vers une résolution constructive des problèmes et un optimisme prudent, en mettant l’accent sur les plateformes partagées, les partenariats et le soutien pratique aux opérateurs les plus fragiles.

Intervenants

- Mayssam Sabra - Modératrice de la session ; de l’Union postale universelle (UPU). - Massimiliano Aschi - Spécialiste principal de la cybersécurité ; président de l’équipe d’experts sur la cyberrésilience de l’UPU ; de Poste Italiane. - Audience - Participants du public posant des questions et faisant de brèves interventions. - Tracy Hackshaw - Responsable de la .post Business Management Unit à l’Union postale universelle ; stratège TIC et économie numérique [S9][S11] - André Pharand - CEO de Pharand Advisors ; expert du secteur du courrier, de l’express, du colis et de l’industrie postale. Intervenants supplémentaires : - Ahmed Omar - Participant du public en ligne ayant posé une question.

Intervenants
MS
Mayssam Sabra
117 wpm · 11 min
AP
André Pharand
143 wpm · 12 min
MA
Massimiliano Aschi
105 wpm · 15 min
TH
Tracy Hackshaw
146 wpm · 14 min
A
Audience
136 wpm · 1 min

Mayssam Sabra a commencé par remettre en question l’association instinctive du public entre le commerce électronique et un site web, un panier d’achat ou une plateforme. Elle a soutenu que le véritable système commence après que le client clique sur « buy now », « purchase now » ou « submit », car cette action déclenche une vaste chaîne logistique internationale de entrepôts, camions, compagnies aériennes et bureaux de poste reliés par des systèmes numériques. Pour cette raison, a-t-elle dit, aucun pays, bureau de poste, organisme ou entreprise ne peut se protéger seul, et la discussion devait se concentrer sur une défense collective à l’échelle d’un écosystème interconnecté. Elle a présenté l’UPU comme l’institution spécialisée des Nations Unies pour le secteur postal et logistique, basée à Berne, en Suisse, reliant 192 pays, cofacilitant la ligne d’action C7 du SMSI, et se trouvant « au cœur même de ce moteur mondial » avec l’engagement de renforcer la cyberrésilience du secteur. Sabra a ensuite présenté les intervenants comme apportant des perspectives différentes mais complémentaires : André Pharand sur les résultats de l’enquête et les politiques, Massimiliano Aschi sur la sécurité opérationnelle, et Tracy Hackshaw sur la politique de l’UPU et la mise en œuvre des plateformes. Elle a indiqué que la session chercherait à regarder derrière le rideau ce que faisait l’UPU pour traduire les grands objectifs en matière de cyberrésilience en actions concrètes. André Pharand a ancré la discussion dans une enquête de cybersécurité de l’UPU menée à la fin de 2024. Il a déclaré que le secteur postal, du courrier, de l’express et des colis est particulièrement exposé parce que les flux transfrontaliers dépendent de systèmes interconnectés couvrant les postes d’origine, les douanes, les postes de destination et les compagnies aériennes, et parce que toute perturbation de la livraison affecte rapidement des clients et des entreprises habitués à une exécution rapide. Il a également noté que les opérateurs diffèrent fortement dans leur forme institutionnelle, certains étant privatisés, d’autres publics, et d’autres encore tenus de s’autofinancer, même s’ils font face à des défis cyber similaires. L’enquête a été envoyée aux 192 membres de l’UPU et a reçu 152 réponses, soit un taux de réponse de 76 %. Pharand a indiqué que cela fournissait une base solide pour une analyse préliminaire couvrant des opérateurs très grands comme très petits. Les résultats ont montré un niveau de départ inégal : pour huit mesures d’hygiène cyber, les taux de mise en œuvre et de développement n’étaient globalement que d’environ 50 %, et certains opérateurs avaient abandonné certaines mesures, décidé de ne pas les adopter ou ne les avaient jamais envisagées. Les domaines les plus faibles étaient la gestion des risques, la réponse aux incidents et la gestion de crise, les pays industrialisés, l’Europe et la région arabe obtenant des résultats relativement meilleurs que les autres régions. Il a souligné que ces lacunes étaient liées non seulement à la technologie, mais aussi aux effectifs, aux équipes et aux ressources. Pharand a déclaré que les charges de travail en cybersécurité augmentaient plus vite que les budgets, en particulier dans certaines régions comme l’Amérique latine, et que dans huit cas, les opérateurs signalaient une hausse de la charge de travail alors même que les budgets de cybersécurité avaient été complètement supprimés. Il a également mis en évidence des liens limités avec les structures nationales de réponse : seuls environ 35 % des opérateurs ont signalé des liens avec un ISIRT national affilié, qu’il a décrit comme une équipe nationale de réponse aux incidents, tandis que 68 % des répondants ont déclaré connaître l’initiative dot-post. Les commentaires libres ont confirmé la même tendance. Pharand a indiqué que 26 % des répondants avaient fourni des commentaires en texte libre, et que 50 % de ces commentaires portaient sur les besoins en capacités et en financement. Les opérateurs ont demandé des modèles, des formations, des orientations, des experts thématiques et un soutien plus large, car ils ne disposaient ni du budget ni de l’expertise nécessaires pour mettre en place eux-mêmes les mesures. Sa conclusion était que la principale lacune relevait des capacités plutôt que de la sensibilisation. Interrogé plus tard sur les recommandations, Pharand a proposé de mettre en place un soutien et de fournir un financement aux postes qui en ont besoin, tout en reconnaissant que tous les opérateurs n’ont pas besoin du même niveau d’appui. Il a également appelé à la formation, au partage d’experts, à un possible soutien de type « SWAT team », à des guides opérationnels de reprise, à une assistance centrale rapide de la part de l’UPU, à la priorisation des postes les moins préparés, et à des évaluations numériques pour vérifier le niveau de préparation et suivre les progrès dans le temps. Massimiliano Aschi a ensuite élargi la discussion à l’environnement de menace plus large. Il a déclaré que les chiffres de l’enquête étaient « vraiment impressionnants » parce qu’ils reflétaient une réalité plus générale : la cybercriminalité fonctionne désormais à travers une chaîne d’approvisionnement criminelle à l’échelle industrielle, avec des organisations structurées, une division du travail et un partage des profits. Selon Aschi, ces acteurs scrutent en permanence l’internet public à la recherche de vulnérabilités et peuvent lancer rapidement des campagnes ciblées ou à grande échelle, ce qui rend les attaques plus difficiles à détecter et à prévenir. Il a mis en garde en particulier contre le mauvais usage de l’intelligence artificielle. Selon lui, l’IA est utilisée pour identifier des vulnérabilités dans les logiciels, les appareils, les réseaux et les infrastructures, et pour générer des outils d’attaque adaptés à ce qui est trouvé. Il a souligné que cela abaisse le seuil de compétence requis pour les attaquants tout en augmentant la vitesse, l’ampleur et la sophistication des menaces. À partir de ce constat, Aschi a soutenu que la collaboration au sein du secteur postal et entre les secteurs n’était plus facultative. Il a déclaré que les efforts internationaux existants avaient donné des résultats limités au regard de l’ampleur et de la rapidité de la cybercriminalité organisée, en raison de contraintes de ressources, de scepticisme, d’un manque de confiance, d’intérêts divergents et de capacités inégales. À ses yeux, les services physiques-numériques et entièrement numériques doivent désormais être protégés comme un seul écosystème interdépendant, en veillant non seulement à la continuité, mais aussi à l’intégrité, à la conformité et à l’éthique. Tracy Hackshaw a ensuite expliqué la réponse politique de l’UPU. Elle a déclaré que la proposition de travail de Dubaï 309 portait spécifiquement sur la cyberrésilience pour le secteur postal. Revenant à l’image d’un colis se déplaçant dans une chaîne de livraison, elle a soutenu qu’une perturbation numérique peut rompre cette chaîne tout comme une perturbation physique, avec des effets en cascade sur les chaînes d’approvisionnement, les paiements, les transports et les infrastructures connexes. Elle a indiqué que l’UPU cherchait à établir une base minimale de sécurité et souhaitait que tous les opérateurs atteignent au moins un niveau « stable » ou « good », en utilisant les données de l’enquête d’André comme point de départ pour progresser. Hackshaw a également mis l’accent sur l’éducation des clients et les questions de confiance vis-à-vis du public. Elle a noté que de nombreuses attaques exploitent l’urgence liée aux colis à travers des messages usurpés et de fausses notifications de livraison, et que les opérateurs ignorent souvent même que ces campagnes circulent, à moins que les clients ne les signalent. Elle a déclaré que l’UPU voulait mutualiser les connaissances et les ressources des opérateurs les plus solides pour aider les plus faibles et utiliser sa position d’organisation des Nations Unies pour instaurer la confiance dans l’ensemble du secteur. Elle a relié cela à Trust.post et au domaine .post. Hackshaw a soutenu que .post constitue un mécanisme de confiance parce qu’il est soutenu par une institution du système des Nations Unies et réservé à des entités vérifiées et authentifiées plutôt qu’à des particuliers, ce qui contribue à réduire les risques d’usurpation dans un environnement de menace où les attaquants peuvent créer des sites web et des noms de domaine trompeusement similaires.

Elle a également indiqué que l’UPU avait procédé au lancement officiel de Secure.post en même temps que l’ISAC à Berne la semaine précédente, le 23 juin. Secure.post, a-t-elle expliqué, fournira des outils et des informations à la fois pour les opérateurs et pour les particuliers, y compris un outil en direct de vérification de liens, des générateurs de mots de passe, des ressources de formation, des tests d’e-mails et de sites web, ainsi qu’un accès aux normes et aux bonnes pratiques. La discussion a également porté sur Post-ISAC en tant que mécanisme concret d’action collective. Aschi l’a décrit comme ayant un « potentiel remarquable » parce qu’il réunit des opérateurs des cinq continents malgré d’importantes différences de maturité et de ressources. Il a indiqué que cela importait parce que les opérateurs sont reliés par des échanges de données, des systèmes de suivi, des procédures douanières et des paiements, et parce que de nombreux postes fournissent aussi des services financiers et peuvent être actifs dans l’assurance, les télécommunications, la logistique et le commerce électronique. Selon lui, Post-ISAC pourrait renforcer les capacités locales en permettant aux participants de partager des informations sur les menaces, les incidents et les bonnes pratiques, créant ainsi un système d’alerte précoce dans lequel une attaque identifiée dans un pays peut aider les autres à se préparer. Il a également suggéré que les opérateurs postaux pourraient agir comme un réseau international distribué de capteurs et qu’un ISAC sectoriel pourrait filtrer de grands volumes de renseignements sur les menaces pour les transformer en informations plus pertinentes et plus exploitables. Hackshaw a donné une illustration concrète du fonctionnement de la plateforme. Si un poste en Asie était attaqué, a-t-elle dit, l’opérateur pourrait partager de manière confidentielle des informations pertinentes sur la menace afin que d’autres puissent se préparer à des attaques similaires. Les opérateurs pourraient partager des indicateurs, expliquer comment ils ont survécu à un incident, ou demander de l’aide pendant qu’ils sont sous attaque. Elle a décrit l’ISAC comme un « bouclier » collaboratif construit grâce à des échanges de confiance et à un soutien mutuel. Les questions du public ont été traitées brièvement. Sur le rôle des CERT et des structures nationales connexes, Hackshaw a indiqué que la feuille de route de l’UPU comprenait un travail avec les autorités nationales de cybersécurité, qui sont généralement liées aux CERT nationaux et sectoriels, et que l’organisation finalisait un accord de coopération avec FIRST, car elle ne pouvait pas fournir seule un soutien efficace. Aschi a ajouté que des initiatives collaboratives telles que Post-ISAC pourraient réduire les coûts d’accès grâce aux économies d’échelle et éloigner la cyberdéfense de modèles isolés. Sur l’usurpation, Hackshaw a indiqué que la partie droite de .post est protégée par des contrôles au niveau du domaine de premier niveau et que des versions trompeusement similaires ne seraient pas autorisées, d’où l’importance du domaine protégé. Sur la coopération avec l’Organisation mondiale des douanes, Sabra a déclaré que l’UPU et l’OMD travaillent à travers un comité de contact couvrant les marchandises illicites, le trafic, la sécurité physique et la cybersécurité, tandis qu’Aschi a ajouté que l’évaluation des risques douaniers en Europe dépend de plus en plus des données échangées, bien que cela demeure à un stade précoce. Dans les remarques de clôture, Pharand est revenu sur la maturité inégale des opérateurs, notant que certains disposent de départements informatiques internes et d’un accès à des consultants, tandis que d’autres ont des capacités informatiques très limitées et peuvent même ne pas intégrer la cybersécurité dans leurs plans pour les services de commerce électronique. Il a déclaré que l’enquête montrait une marge d’amélioration évidente et une possibilité d’aider les postes disposant de moins de ressources à atteindre un niveau acceptable. Aschi a conclu par un avertissement selon lequel les fournisseurs de services basés sur internet font face à un environnement de menace qui se dégrade et pourraient bientôt être confrontés à « une nouvelle épidémie fondée sur le mauvais usage de l’IA ». Il a appelé à une coopération plus stricte, à une confiance renforcée et à un soutien aux pays les plus faibles tant en matière de financement que de capacités. Sabra a ensuite invité les participants à poursuivre la conversation au stand de l’UPU, numéro 14, à Palexpo du mercredi 8 juillet au vendredi 10 juillet. Dans l’ensemble, les intervenants ont largement convenu que le commerce électronique dépend d’un système postal-logistique numérique et physique interconnecté, que le cyberrisque dans ce système est partagé, et que des opérateurs plus faibles peuvent exposer l’ensemble du réseau.

Ils ont également convenu que le principal défi est l’inégalité des capacités, notamment en matière de réponse, de reprise, d’effectifs, de financement et de liens avec les organismes cyber nationaux.

La discussion a dégagé un programme d’action concret centré sur le soutien en financement et en formation, l’expertise partagée, le partage d’informations sur les menaces et les incidents entre opérateurs, une infrastructure numérique de confiance grâce à .post, des outils destinés au public grâce à Secure.post, et un renforcement de la coopération avec les partenaires nationaux et internationaux.

Mayssam Sabra
Good morning, good afternoon, everyone with us here in the room or those who are joining online and welcome to our session, the Global Shield Collaborative Cyber Resilience for E -commerce and Logistics. My name is Mayssam Sabra from the Universal Postal Union and I am the moderator of today's session. So before we deep dive into our discussions, I just wanted to ask the audience who is with us here in the room or the participants who are joining online one question. When you think of e -commerce, what first comes to your mind? Just keep your answer very basic, simple, just give me a quick thought when you think of e -commerce. What comes to mind Okay, could you please use the microphone?
Audience
I said Amazon is what comes to my mind.
Mayssam Sabra
Okay let me see if we have someone answering online.
Audience
Platform, platform.
Mayssam Sabra
Correct actually your answers are correct and make total sense when we usually think of e-commerce we think of a website of a shopping cart of a button that says buy now purchase now or submit but the reality that most people don't know is that e -commerce don't add with when you click by actually this click triggers a massive invisible global engine of logistics airplanes, trucks, warehouses, post offices that are working all together to bring you a package to your doorstep, right? And because this network is digital and interconnected, a cyber attack on one part of its chain can cause the entire ecosystem to collapse. And cyber criminals today, they are not attacking one single target anymore, but they are targeting the entire ecosystem. So that's why today in our session we are going to talk about collective defense. This means no country, no post office, no organization, no business can protect itself alone. We have to work or to shield the network together. So answer UPU. Just for those who are not familiar with the UPU, it's a universal postal union. It's a United Nations agency based in Bern, Switzerland, and specialized for the postal and logistics sector. It sits at the very heart of this global engine as it is committed to enhancing the cyber resilience of the postal and logistics sector. And beyond linking 192 countries, the UPU is also a proud co -facilitator of WSIS Action Line C7, which is dedicated to building a safe and secure digital economy. So in today's session, we are going to look behind the curtain at the UPU cyber resilience and see how global policy translates into real-world defense. And to guide us through this, I am joined with three fantastic intervenants. And so André Pharand is the CEO of Pharand Advisors and expert in the courier, express, parcel, and postal industry. I have also Tracy Heckshaw, the head of the dot -post business management unit of the Universal Postal Union. At the Universal Postal Union, and we have with us on the screen Massimiliano Aschi, senior cybersecurity specialist and the chair of the cyber resilience expert team of the UPU. From Post Italiane. So let's dive straight into our first round of questions, and I start with you, André, to set the stage for us. The UPU recently conducted a comprehensive survey with member countries to diagnose our current strengths and vulnerabilities. Based on this survey data, what is the current state of cybersecurity across the coastal network, and what are the key gaps we need to look out for?
André Pharand
Thank you, Mayssam. What I'll be doing is presenting the results of the cybersecurity survey and the recommendations, some of the key findings and recommendations. These are preliminary. The purpose is to share preliminary information, obtain some feedback, and then develop some final set of recommendations. But I will set the stage with some of the findings. from the survey. First of all, and just to complement what Mayssam mentioned, a tremendous amount of things, goods, especially when you're talking about cross -border, will touch an origin post, customs agency, destination post, an airline. So you have a lot of systems that interconnect all of these players together, and therefore that could create some vulnerability. And as you can see here with some examples at the bottom of the page, there are some logistics companies, whether postal or not, are not immune. And, in fact, I would say logistics companies, along with health care, are typically top targets because of the impact that they can create. Imagine a carrier not being able to deliver for two or three days, especially when people expect parcels to be delivered next day and then, you know, that can be a big problem. fairly traumatic, especially for those companies that do face an attack. And just a bit more, so CEP and logistics, we're talking about everything that's being delivered under, let's say, 70 pounds, just to simplify, so letters and parcels. Parcels dominate nowadays, and so that kind of gives you a bit of the context. And postal operators are part of that, and some are privatized, some are part of the government, some have mandates to essentially be self -funding, if I can put it that way. Anyway, the point is that you have a number of different players and different contexts. The analysis or the survey was done at the end of 2024. It was sent out to over the 192 members of the UPU. We received 152 responses. A good 76 % response rate, pretty good. And the purpose was to measure the eight cyber hygiene measures and also to look at awareness of some of the initiatives and to get some of their feedback as to what some of these postal operators are looking for. So some postal operators are very big, USPS. Some are very small, if you think about Curacao Post, and you have everybody in between. But the challenges are roughly about the same for just about everybody. The survey coverage and response rates by region. So you can see here, overall, very good participation, particularly in Latin America, with the caveat that industrialized countries didn't participate as much, perhaps because they feel they are more, I guess, self -sufficient. Anyway, the point is that we do have a solid base of data to work with. And if I move to the next slide, what we see here are the eight, cyber hygiene measures and their adoption. So you can see from the dark green indicates that they're implementing lighter green underdevelopment and considering which is the even lighter green. But if you look at the first two greens here, we're roughly at about a 50 % rate across the board. But you can see that some of these measures struggle more than others. And you can also see that on the right -hand side, there are some posts that have discontinued, decided against, or never even considered cybersecurity. There's a reason for this. Some posts perhaps are not even there yet. You know, connectivity is probably number one. Then you deal with step number two, but we'll discover that there's maybe a little bit more to that. As I move to the next slide, we then analyzed on a – on a geographic basis using the Universal Postal Union groupings of the different countries. And you can see the cyber hygiene initiatives are at the bottom this time. What we can see here is the first three categories, industrialized countries, Europe and the Arab region, are doing fairly well. The ones that are struggling and particularly the topics where the posts struggle are with risk management, incident response, crisis management. So you can see this is more tied to teams, resources, more so than perhaps a technical component or aspect. As I move on, the other thing that we discovered was that there's a capacity squeeze. As we progress, and the question was asked whether your workload was raised, was going up or not, in relation to cyber security initiatives. And as you can see here, definitely the respondents ranked this very high. So everybody, most everybody believes that or feels that the workload is increasing. However, if you look at the green or the blue bars, you can see here that the budget rising is not keeping up. So you can see here, especially there's a large gap with Latin America where demand is rising, but the budgets are not. And if I kind of zoom in on the bottom statistic here, there are eight operators whose workload did go up, but that for whom their budget was completely cut out outright. So you can see here some of the challenges that we're facing or some of the post operators are facing. Now, if I continue, bear with me, hold on here. And if I continue to go down, I'm going to see that the budget is going to go up. And if I continue to go down, I'm going to see that the budget is going to go up. I seem to be struggling. I'm trying to get back to the screen. Oh, here we are. The next slide shares that demand is rising faster, and also that only about 35 % of the postal operators have any link with an affiliated national ISIRT. This is kind of a response team at the national level. So while they are an entity, typically the stakeholder, the owner of a post is the government, you're not seeing as much alignment or interconnectivity or integration. And then the other component here is that 68 % of all respondents to the survey did mention that they were aware of the dot post initiative. This is a UPU initiative, and Tracy can certainly mention a lot more. But something that can help posts with digital and cybersecurity support. additionally when we look at what operators asked for 26 percent of them actually wrote something where they were compelled enough to write something in a open comment and 50 percent of those responses are tied to the capability and also funding. If we unpack this a little bit more, what they're asking for is more help around training, around funding, and also around guidance and access to subject matter experts and just expertise in general, which is not necessarily always available locally. Most cited focus areas is staff capability, general and all measures, and then thirdly, infrastructure. Just a sample quote here, we need UPU support to implement all of the above. We don't have a budget for this. UPU can support with templates training and subject matter expert support so these are some of the initiatives that or some of the feedback that we obtained from the postal operators so the key takeaways if I can just finalize with this and then we can talk about recommendations afterwards we had broad participation across all regions the response and recovery is really the weak spot it's not about awareness it's more about the capability also of being able to implement some of these controls and some of these crisis management and other initiatives there is a wide regional gap which can be expected you could say it all depends on the availability of resources locally as well and I think that's the key takeaway and I think that's the key takeaway and I think that's the key takeaway And then capacity, as I mentioned, not awareness is the gap. Even though you are also very strongly rated from a ranking or a maturity on all of the hygiene factors, it does not necessarily mean that you're immune to attacks. And so I'll stop right there.
Mayssam Sabra
Thank you very much, André. So we can be clear from the UPU data that the vulnerabilities are clear. Let's see how this translates to the front lines. And I would like to invite Massimiliano Aschi, who is joining us remotely. Massimiliano, you leave this operational reality daily. So from the perspective of a major national operator like Post Italiane, what do these ecosystem threats actually look like day to day? And why? Why do we need a coordinated sector response? Over to you, Massimiliano.
Massimiliano Aschi
Thank you very much, Mayssam. The data that has been just presented are really impressive, and they confirm that for a long time now, cyberattacks have been sustained by a truly industrial-scale supply chain, orchestrated by highly structured criminal organizations that work in close coordination with clear distribution of roles, capabilities, and profits. This illicit ecosystem enables the continuous monitoring of a vast portion of the public Internet in search of vulnerable assets and makes it possible to deploy attack campaigns that are either highly targeted or large-scale. With respect remarkable speed and precision in timing. As a result, the attacks are becoming increasingly difficult to detect, and at the same time more complex to prevent encounter. In recent times, this criminal synergy has found an additional disruptive enabler in the malicious use of artificial intelligence. AI technologies are being used to identify weaknesses more effectively in software, devices, network and technological infrastructures, as well as to develop attack tools tailored to the vulnerabilities detected. A particularly critical aspect is that these capabilities do not necessarily require advanced technical expertise. thereby significantly broadening the pool of potential malicious actors. Thanks to the AI, such activities can now be conducted at extremely high speed and frequency, exposing our digital services to a volume and level of sophistication of threats that is unprecedented. In this context, collaboration among stakeholders within the same sector, as well as cross-sector cooperation, is no longer a matter of choice, but an unavoidable necessity. Yet, despite the efforts made at the international level over the years, the results achieved have unfortunately remained limited when, compared to the scale speeds of impacts generated by organized crime. The reasons are manifold lack of resources, persistent skepticism ,insufficient trust, misalignment of visions, objectives and interests And significant asymmetries in the capacity to detect, respond to and mitigate threats above all what is still missing is a shared strategic vision fully aligned with an increasingly evident reality our hybrid service physical-digital and fully digital services are ever more interconnected and interdependent value creation now depends on complex chains of stakeholders suppliers and service providers which must be realized and regarded as a single ecosystem and the future of the ecosystem when seeking to protect both service delivery and effective service accessibility. In other words, resilience can no longer be approached in a fragmented manner. It requires a systemic perspective. Moreover, if we move beyond a purely business -oriented logic and also consider digital public interest services, including those delivered by public administrations, the discussion necessarily broadens. It must then include issues such as operational continuity, information integrity, regulatory compliance, and ethical responsibility. From this point of view, cooperation should be concretely aimed at strengthening service resilience. including through the introduction of incentive mechanisms and practical operational support for service operators. Within this framework, the operational presence of trusted actors capable of serving as bridges between organizations is an essential precondition. Without such mechanism of coordination and trust, the risk is that we will continue to operate in isolation, thereby exposing ourselves to increasingly severe systemic vulnerabilities. Otherwise, we will continue to move along through an increasingly hostile environment, fully aware that we are visible, vulnerable, and sooner or later, bound to be struck. Thank you very much.
Mayssam Sabra
Thank you very much, Massimiliano, for your insights. Tracy, technical defense requires a strong global policy foundation. How do you think the UPU mandates, especially the Dubai Work Proposal 309, help us build global frameworks that ensure no country, regardless of its development stage, is left digitally vulnerable?
Tracy Hackshaw
Thank you, Mayssam, and welcome to those online and those in the room. Just for those who don't know, the Work Proposal 309 is cyber resilience for the postal sector. That's the name of that proposal. And I want you guys to think about a physical parcel. So the Universal Postal Union has to provide universal service. to everyone. And the postal operators in your countries have to deliver to everyone. But what happens if there's some break in the chain of that delivery? A parcel gets affected, or mail as a case may be. That's in a physical world, a physically connected world. But when we talk about a digitally connected world, what happens if there's a disruption or break in that chain? Because of the connection of all of the elements, we could potentially see ripple effects on other systems that are connected to that larger digital infrastructure. The supply chain, payment systems, transit and transport systems, and so on. so when we talk about trying to protect the sector we are looking at not just the physical but also the digital aspects of it and we titled the session about e -commerce logistics because unless I am mistaken things that are purchased online for the most part are still physical I mean you can purchase music yes you can purchase movies and digital goods but the majority of the things that we purchase online still have to be physically produced and physically delivered to your location wherever you are, business or home so that is important to understand that even though you may want to understand why is the post so involved in the digital world it is because when you buy things online the post and other entities in the sector have to get involved to deliver those things to you so so we are trying to establish a minimum security baseline for this sector as a whole and we're looking to really get to a stage where everybody is at least stable or what we call good and André is sort of giving us a baseline as to where we are and the data doesn't look very promising but again we'll get some recommendations coming in I hope in the next few minutes. Our system provides a standardized roadmap for getting those who are behind from sort of an a to at least a b meaning in the steps in the progress and eventually to the c where we'll hopefully they'll go eventually in addition by embedding the this particular thinking into our work plan we also hope to allow the equitable resource allocation so we want to unlock capacity development training resources, sensitization resources that would allow the operators in the various countries to not only support themselves to become more resilient, but the wider sector and, of course, the customers. Because if you think about it for a second, the majority of the attacks that are happening in the sector, and you know them, you've seen them, you get this message or you get an email saying your parcel is late or something that's fairly urgent. And you do click on those links because, of course, you would like to get your package now. And that's one way of being attacked. So trying to educate customers to where and how those attacks are happening is vitally important because, as we found out, my target of the post, the majority of them don't even know that these customers are getting those messages. It's only if the customer tells the post that this is happening. They will know that their URLs or their email addresses are being spoofed or being abused. And that's something we wanted to fix as well by educating the customer base. We provide technical assistance and try to pool the knowledge and resources of our, as Andrew sort of hinted at, that the ones who didn't respond to a large extent, those who are, although if you look at some of the data, they also can be at risk. Those who are stable and resilient, as according to the data, to help those who are less so. And by our organization being what it is as a UN organization, we believe we can help do that as well. And finally, we would like to build. This concept of trust out of one of our flagship projects called Trust .post, which is based around the .post domain. and if we think about it again if you don't trust your digital infrastructure in your country what happens? You don't trust the digital economy and you don't trust trade to happen and we see that in many of the least developed economies where cash is still king we still prefer to use physical as opposed to digital because the trust is not there so we want to ensure that by enforcing global cyber standards we give every country this trust mark that certifies them as a safe partner in the global supply chain so we would like to ensure that our plan in the next four or five years ensures digital inclusion which is one of the big topics at WSIS and we are building a global frame where cyber resilience is not a luxury for those who have the resources but a standard utility for all because at the end of the day our global network is only as secure as the most vulnerable operator. So what we're trying to do is ensure that at every step of the chain we secure, provide that resilience level and strengthen that supply chain as far as we possibly can. Thank you.
Mayssam Sabra
Thank you, Tracy. Now I go back to you, André, for the recommendations. So in the UPU cybersecurity position paper that you have been working on, what are the primary concrete recommendations that the UPU is proposing to help member countries protect themselves? Please keep your answer short because I still have two questions for Massimiliano and Tracy and we have only 15 minutes left.
André Pharand
I'll keep it short. It addresses some of the fundamental gaps that were identified in the survey. Number one is provide funding, set up and provide funding to posts. Not for all. Some are self -sustaining. Others require support. Number two, training and shared experts, because this is a common problem across many postal operators, so it's something where you have a SWAT team that can go in and help. And in addition, to help with recovery from attacks, not just prevention, so a playbook of some sort, along with some timely support at the centralized level, so the UPU provides that support to the postal operators that do require. In addition to this, prioritize the least prepared posts. They're the ones that are asking for this, and therefore, they will certainly benefit the most out of this. And then finally, verify readiness with practical checks through a proposed digital assessment to monitor how posts are doing and especially improving. So, I'll stop there. Thank you.
Mayssam Sabra
Thank you, André. Actually, turning those recommendations, into real-world action is where platforms come. And now I go back to you, Massimiliano, on screen. How does a tool like the UPU's post -ISAC move threat intelligence from a concept into a live? Practical shield for operators on the ground?
Massimiliano Aschi
Post-ISAC has a remarkable potential, which can be increasingly leveraged in the years ahead. First of all, it is an international community of operators spanning all five continents and reflecting a broad spectrum of cyber maturity levels, threat response capabilities, and resource availability. This makes it possible to bring to the same table needs and realities that may differ significantly from one to another under the coordination of an institution of recognized standing. Such a framework is grounded in the understanding that every operator plays a distinct role in the creation of value for the postal sector and that the vulnerabilities or strengths of one partner may translate into risks or aspects of the business. For the sector as a whole, this is particularly evident in areas such as data exchanges between operators, tracking systems, customs processes, and cross-border payments. Secondly, the cross-sectoral nature of our business creates a unique opportunity to address and integrate vertical needs specific to different sectors. More than 90 % of postal operators provide financial services, and a number of them are also in insurance, telco, logistics, and e -commerce. As a result, the range of perspective and the potential scope of impact are especially significant. Third, Post-ISAC offers a genuine local capacity for action. Cyber threats are global in nature. Frauds, ransomware, phishing. And the attacks on the digital supply chain affect postal operators across the world in very similar ways. Yet, the way these threats are managed, the regulatory context in which they arise, and the defensive capacities available remain profoundly local. In this context, operators can share information on threats, incidents, and best practice, thereby building a collective body of intelligence and knowledge that no single national operator could develop alone. An attack detected in one country can become an early warning for all, strengthening anticipatory response capabilities across the network. In this way, global exchange is transformed into local benefit, which in turn can generate local good practices, capable of evolving into global standards. The extensive territorial presence of postal operators within their respective countries also creates the potential for an integrated international network of sensors. able to relay to the wider community timely information on developments observed at local level, including new fraud patterns, technology abuses, and waves of attacks. At the same time, the sector's deep operational expertise in vertical technologies, such as automated mail and parcel-sorted systems, makes it possible to identify and escalate emerging threat scenarios at ecosystem level with speed and precision. Equally important, a clear understanding of the technologies that are most relevant to the sector allows the community to filter the vast volume of threat intelligence available, producing curated and highly effective intelligence and intelligent feeds focused on the concrete interests of the stakeholders. The floor is again yours, Mayssam.
Mayssam Sabra
Thank you, thank you, Massimiliano. So I go back to you, Tracy, now. You have been working in the last few years on the UPU cyber resilience initiatives. You have developed a number of initiatives like PostISAC, Trust .Post, and Secure .Post. How do you think these platforms practically turn that high-level policy into a live, functioning, secure space for global e-commerce?
Tracy Hackshaw
Thank you very much, Mayssam. And I'm glad you mentioned Post-ISAC, and Massimiliano did as well. So I just want to give, not repeating what he said, so just give like a practical example. Imagine that you have an attack happening in Asia to a particular post. The ISAC allows the post the ability to share the information that would have caused that threat, utilizing our tools that we have. I'm putting a place in the ISAC and share that information securely, confidentially, with other participants in the ISAC to allow them to better prepare themselves for what may be a widespread attack or at the very least to prepare them for an attack that may happen in the future. So something like that is very critical to quick sharing confidential information and also to get learning if you have been attacked, what you did to survive it. Or on the other side, if you are currently under attack, how you can get help to deal with the attack itself. So it's in all different directions. We think the ISAC can help in terms of collaboration, sharing of threat intelligence and moving your organization forward with a secure layer of protection that you can use to protect yourself and your organization. Not just from tools, but also from others. Sort of a shield, as we said, a global shield, a shield that's placed around you in that regard. Moving on to the post top-level domain, which we haven't discussed a lot. It may seem somewhat trivial to talk about a domain name, but think about the majority of the attacks that happen. They come through the domain name system, the DNS, as we say. And when people are looking at links, the intent is to ensure that they understand that a safe link will be one that has a trusted mark, which is .post, the only top-level domain that has a UN system agency behind it. So if your operator is operating one that is, let's say, not trusted, so I don't want to call the other domain names, but you know them, those names. It can be easily purchased by anybody. and spoofed. So for those who don't know much about that, if your name has things like the letter A, the letter I, the letter L, the letter O, those are very, very easily spoofed names because you can just adjust the letters in different characters. So the I can become an L, the L can become an I. And visually, you can't detect it as quickly as you might want to. So if someone is trying to scam you or allow you to go and click that link, with the AI revolution that's happening today, you can spin up a website that looks exactly like your postal website today or your operator, have a dummy domain name that you think is the correct one, or you can just create one that says something tracking, and you go on it because you think it's safe. So what we're trying to advocate is utilizing dot post, which we don't allow anyone. who is not a verified or authenticated entity to access that. We have no individuals accessing that name, that top -level domain, and only authorized verified entities can utilize it. So we are encouraging all members of the sector to access that top -level domain name and provide another level of security. And additionally and finally, we talk about, and to do that you utilize trust Post, as Mayssam would have indicated. That's the gateway to get those top -level domains. And sort of to wrap around this, we have a public-facing environment that we are about to go live with. We've done an official launch along the ISAC last week. Was it last week or the 23rd of June? Maybe that's two weeks now in Bern. And that's secure .post. And in there you'll see a lot of information about our website, and it's tools, things that you can use anyone, you don't have to be an operator you can be just an individual we have one live today so if you go to it right now you'll see checking your link environment that we have and very shortly you'll see password generators tools to get better information on training from your partners and also to do things like testing your email and website alongside best practices and standards with that I think I'll say that's what's happening on the ground and how best we can help everyone in the sector become more resilient. Thank you.
Mayssam Sabra
Thank you Tracy. Now we have four minutes left I would like to open the floor for the audience here in the room or online if you have any questions please feel free to raise them. Yes please.
Audience
Thank you very much for the presentation I have one question your colleague Massimo on the panel mentioned CERT and the critical role CERT play in cyber resilience in the country so what would you say through your work is the one major challenge and one major opportunity how you could help basically CERT's cyber resilience especially on the side of prevention working with corporate partners with supply chain partners as well.
Tracy Hackshaw
Thank you maybe Icould start and hand over to Massimo I will say that the plan that we have is to in fact work with national cyber security authorities in the country that's mapped out in our roadmap it's a KPI so not just doing it ourselves but linking up with the authorities in the various countries and the people of the country and the people of the country And those authorities generally are linked themselves to national certs and C-certs and ideally to sectoral certs within those countries as well. So if the financial sector certs within a country, et cetera. So our goal is to sort of create another chain of resilience within the country as well as a global approach and work in fact with even other ISACs to sort of bring that together. We are currently finalizing a partnership with FIRST. And for those who don't know, FIRST is the forum of incident response teams around the world. We're currently in the middle of a cooperation agreement consummation, working out the final details. And through that, we will intend, our intention is to fully, fully optimize our resources within the UPU and work with FIRST's teams around the world to ensure that we can do this. Because we can't do it ourselves. We do it to help everyone. Maybe Massimiliano can add something from his experience. Massimiliano, would you like to add something?
Massimiliano Aschi
Yes, very, very interesting question. It will take more time to answer, but if we take an example, the postal ecosystem, but this is valid probably for many other kind of ecosystems, the scale and reach of it maximise, could maximise the impact of investments made in preparedness and threat response, for example. And the development of training and awareness initiative, for example, could generate substantial returns. And another thing, for example, is that while the cost of accessing services could be relatively high for many participating countries, this cost may be significantly reduced through economies of scale. And in this case, in this sense, participants, participating in initiatives like the post-ISAC we mentioned, has the potential to be a game changer in the way cyber defense is conceived. This would enable a shift from an isolated, an island -based model to a more collaborative and participatory approach to security. And this would help to break the isolation in which many operators still act and foster the emergence of an ecosystem -wide protective barrier. This is, in my opinion, an effective way of mitigating shared cyber risk. I don't know if this answers a bit.
Mayssam Sabra
Thank you, Massimiliano. I hope this answers your question. Okay, now we have another question from the audience.
Audience
Thank you. I have mine. One goal initiative for governance. Just a simple question, I suppose. How do you deal with the fact that there's an O in the word post? And how does first deal with the fact that there's an I in the word first?
Tracy Hackshaw
Well, we'll get into the technical issues. On the right-hand side of the dot, that is impossible to be spoofed because a top-level domain is issued only by ICANN. Two. Verified entities. So there's no way you can get dot P, another character ST, because it'll be a very complex domain. It'll be confusingly similar. And ICANN would not allow that to happen. In terms of first, good question, but I'm not first. I'm not going to answer on their behalf. But you can also, I know they are set, you can use the number one as well. etc but I believe there are ways that they would monitor that as well but that's a good question in terms of the left side of the dot on the right side of the dot dot whatever it's very difficult to have that spoofed which is the point of the dot post top level domain.
Mayssam Sabra
We have Ahmed Omar online please Ahmed go ahead with your question.
Audience
Thank you for the presentation I have one question how does UPU cooperation with WCO World Customs Organization to enhance risk assessment and data sharing for cross border postal shipments especially in the context of growing e-commerce, thank you.
Mayssam Sabra
Thank you Ahmed for your question I think Tracy would you like to answer this question I don't know if Massimiliano has any thoughts on it but I do know that but the UPU and the WCO works together with what is called a contact committee, and they cover security as a topic generally. So they cover illicit goods, trafficking, physical security issues, and also cybersecurity issues. So with the WCO and the UPU, they do meet regularly via this contact committee to discuss and deal with issues at both a policy level and at an operational level. But again, I'll ask Massimiliano if he has any. I guess he's a practitioner, so maybe he may have some thoughts in terms of customs authorities in -country, as well as the WCO. Massimiliano, maybe?
Massimiliano Aschi
Yes, I can bring you an answer considering just Europe. I'm not informed about other regions. I'm not aware of other countries' realities. But what I can tell you is that we are approaching risk evaluation based on data exchange. So data flows exchanged through networks, international networks, are becoming particularly relevant in evaluating risks, potential risks of shipments, for example. And this helps to address custom controls in a more smarter way, I would say. Still, I believe this is just the beginning, and this way is not probably mature enough to produce relevant results, but it is one way to approach this issue.
Mayssam Sabra
Thank you, Massimiliano. So as we wrap up our today's session and our time is already over but I would like to give our panelists a final word maybe I start with André to give your what is your main takeaway of this session or if you would like to have some few words to conclude
André Pharand
Maybe the only last comment would be that postal operators are in different levels so you have some that have their own IT departments they hire external consultants they're very strong others that barely have their own IT department some don't even are not even aware they just want to get something going to get e-commerce going in their country and they don't even think about cyber securities and afterthought sometimes the IT department and the entity that's responsible is not even part of the post it's still an entity within the government getting these resources is a challenge. I say this because there's an opportunity to improve and that would be and then this survey does display that I think that's a good point there's certainly some room for improvement and to help these, particularly the posts that have less resources, to get up to the right level to minimize the risk, basically.
Mayssam Sabra
Thank you André. Now Massimiliano, what's your main takeaway from today's session? Please.
Massimiliano Aschi
Yes, it was very interesting to hear many things from Tracy and André. I know that there's an increasingly threat scenario that is becoming really dangerous for e -commerce, but also for organizations which are just showing up their services upon Internet. We are going to face a new epidemic based on AI misusage. I don't know how to explain this better. I don't know how to explain this better in just a few seconds, but it is becoming worse, worse and worse. we still have to build trust we are still discussing how to cooperate, we have to cooperate, we have to support weaker countries, we are all part of the same supply chain everything is getting integrated and the weakest part of the chain needs to be supported because they could be part of the real value in delivering our services because they bring up their experiences, they bring up their contacts that are particularly different from one from the other so this is a call for stricter cooperation and UPU and organizations like yours could start building up trust and support member countries not only financially but also by providing the and the people and the people providing them with the capabilities to enforce trust and exchange of useful and actionable information.
Mayssam Sabra
Thank you. Thank you, Massimiliano, and thank you all, and thank you for your time. We are now closing our session. I hope it was insightful and beneficial for all of you, and if you would like to continue conversations with us and to learn more about the UPU Cyber Resilience Initiatives, we will be at PAL Expo from Monday to Friday this week, booth number 14. So you can come visit us, and we can continue our exchanges. Yes, so it's Wednesday, 8 July to Friday, 10 July, booth number 14. Thank you very much. Thank you.
E-commerce and trade
Technology has significantly transformed the world’s economy. The ability to make data flow worldwide, and the digitisation of information have enabled digital business models and spurred the growth of e-commerce. Digit...
UNCTAD eCommerce Week 2019: An overview
In the field of cybercrime, there is a need for stronger public-private partnerships in order to find adequate and scalable solutions. It is also important to provide cyber capacity building for actors who are part of th...
Cybersecurity
Cybersecurity came into sharper focus with the rapid expansion of the Internet's user base. One side effect of the rapid integration of the Internet in almost all aspects of human activity is the increased vulnerability ...
Open Forum #51 Strengthening Cyber Resilience in Global Posts Logistics
Open Forum #51 Strengthening Cyber Resilience in Global Posts Logistics Rapport de session Intervenants Graphe de connaissances Analyse approfondie...
How .POST powered services build Cyber Resilience within the global Postal and Logistics Sector
The tone was collaborative and solution-oriented, with participants sharing both concerning statistics and practical initiatives. While the data presented was "scary" (as noted by intervenants), the overall atmosphere remain...
What’s new with cybersecurity negotiations? OEWG 2021-2025 fourth substantive session
After that, the Chair will prepare a second revision of the PoC elements non-paper. Capacity building El Salvador, Argentina, and Kenya highlighted prioritising practical support for establishing capa...
Cybercrime
https://dig.watch/wp-content/uploads/cybercrime-novi-72-dpi-DORADJEN-FINAL-2021.png AI and cybercrime The AI race between cybercriminals and those who try to protect systems is emerging as one of the most critical for ...
AI and Digital in 2023: From a winter of excitement to an autumn of clarity
Cybersecurity: Preserving the internet in difficult times In 2023, cybersecurity has emerged in a wide range of contexts, from an increasing number of wars and conflicts (Ukraine-Russia, the invasion of Gaza, etc.) ...
The Overlooked Peril: Cyber failures amidst AI hype
Implementing existing and introducing new policies and legal instruments While technical protections are crucial, they alone are insufficient to address the complex landscape of cyber risks. The vulnerability of digita...
1

The knowledge base confirms that the Universal Postal Union is a United Nations specialised agency, headquartered in Berne/Bern, Switzerland, and that it is one of the WSIS Action Line co-facilitators in the area of e-business [S16] and [S65]. It also confirms the figure of 192 UPU members [S64].

2

The knowledge base supports the broader factual premise that cyber resilience requires cooperation across stakeholders and borders. This is echoed in material stressing that industry cannot 'go it alone' and that governments, critical infrastructure owners, providers, and other actors must act collectively [S61]. Related material on regional cyber cooperation also underlines the need for confidence building, capacity building, and coordinated implementation [S68].

3

The knowledge base provides supporting context that cross-border parcel traffic depends heavily on data-rich logistics and customs systems. It notes that parcel tracking uses 'digital wrappers' containing data on products, exporters, importers, and other global tracking information [S25]. It also highlights customs risk assessment and cross-border parcel security dependencies involving postal and other external data sources, including the UPU [S37].

4

The knowledge base confirms that the UPU has 192 members, so a survey sent to all UPU members would indeed have gone to 192 entities [S64].

5

The knowledge base adds context that developing regions and smaller operators face greater cybersecurity challenges and need targeted support. It describes UPU initiatives such as secure.post, starter packages for small island developing states and least developed countries, and partnerships for capacity building, which aligns with the report's emphasis on resource and capability gaps [S3].

6

The knowledge base directly corroborates this figure in discussion of postal integration with national cybersecurity frameworks, stating that only 35% of posts are affiliated with national information security incident response teams [S3].

Maïssa Bahsoun — Maïssa Bahsoun
Salomé Petit Siemens — https://diplo-media.s3.eu-central-1.amazonaws.com/2024/04/Salome-Petit-Siemens.jpeg Ms Salomé Petit Siemens is currently pursuing a dual master's degree in international security between Sciences Po and the London School...
How .POST powered services build Cyber Resilience within the global Postal and Logistics Sector — You can do so by contacting us today at hello at trust.post, or by utilizing this QR code, which you can scan and express interest in participating with us to onboard yourselves into the post-ISAC in a pilot manner. And ...
Massimiliano Fusari — Dr Massimiliano Fusari focuses on assessing, producing, planning, and enhancing sensible and effective strategic campaigns upon the pillars of digital marketing and visual storytelling. Since September 2021, he has been...
Massimiliano Lombardo — Massimiliano Lombardo is Programme Specialist for Natural Sciences at the UNESCO Cluster Office for the Caribbean. He has extensive international professional experience as an environment and sustainable development spec...
European Broadcasting Union — Capacity development Most of the EBU’s activities are aimed at increasing the capacity of its members to address challenges and embrace opportunities brought about by the digital age. To that end, through its Digital T...
EQUAL Global Partnership Research Coalition Annual Meeting | IGF 2023 — Is there any summary from Audience: their discussions? Yeah maybe I can just briefly summarize so thanks to the great tech team we were able to like solve our issues and communicate with each other but...
Tracy Hackshaw — Mr Tracy Hackshaw is an ICT and Digital Economy Strategist possessing close to twenty-five (25) years' experience spanning work in the public and private sectors both locally and internationally, including representing T...
Open Forum #20 CONNECT.POST: Connect communities through the postal network — But a key point to highlight for all you is that making this vision a reality requires collaboration with governments, international organizations, donors, the private sector, civil society, and, of course, designate...
The Postal Network: A Vehicle of Digital Inclusion | IGF 2023 Open Forum #160 — Tracey Hackshaw Speech speed 166 words per minute Speech length 3334 words ...
André Picot — André Picot
Communications and competition law: Key issues in the telecoms, media and technology sectors — district courts and federal appellate courts. In addition to civil litigation, Mr. Lange represents clients in criminal and civil antitrust investigations, and counsels clients on the antitrust implications of business p...
Open Forum #51 Strengthening Cyber Resilience in Global Posts Logistics — The platform enables both checking suspicious links and reporting potential threats. Preuves Secure.post is live today with check URL facility for testing suspicious URLs and reporting scams/malware. Platform will e...
Universal Postal Union — The Universal Postal Union, established by the Treaty of Bern of 1874, is a specialized agency of the United Nations that coordinates postal policies among member nations, in addition to the worldwide postal system.The ...
Cybersecurity — Cybersecurity came into sharper focus with the rapid expansion of the Internet's user base. One side effect of the rapid integration of the Internet in almost all aspects of human activity is the increased vulnerability ...
Cyberattacked: Who do you call? — Almost noone! Or, more accurately, there is no single emergency telephone number where we can call for effective help during or after cyberattacks as we have with physical security. In cyber emergencies, corporate and ...
Crisis management — Crisis management is about anticipating, responding to, and recovering from events that disrupt lives, institutions, or entire societies. From natural disasters to cyberattacks or political upheaval, failure to act quick...
Welcome 2015 ‒ a year of cyber(in)security — Nuclear plant in South Korea hacked... Hackers attack Internet overlord ICANN... US, European police swoop on Tor 'dark markets' ... Cybersecurity units to protect Russia’s nuclear weapons stockpiles... Digital War takes...
What makes up institutional capability for e-diplomacy? — This requires: A 21st Century ICT infrastructure - no more excuses for absence of wifi - and policies to match, covering security for e-tools; cloud and other storage; archiving Acceptance that IT/ICT/IM is not accou...
Successes & challenges: cyber capacity building coordination | IGF 2023 — So from my experience I can definitely say that cyber capacity building coordination is lacking amongst stakeholders, that we face a lot of challenges when attempting to coordinate notably diverging objectives, approache...
Enabling trade inclusion for MSMEs, women and underrepresented communities through the postal network (UPU)- UPU TradePost Forum — Despite the number of packages delivered more than doubling, this growth was mainly driven by big e-commerce services and retailers. The Universal Postal Union (UPU) reported an initial drop of over 20% in postal volumes...
Postal network as enabler for e-commerce and trade facilitation (UPU) -UPU TradePost Forum — This is considered a key element in promoting interoperability. The analysis suggests that by implementing automated APIs based on a library, the process of data exchange and interoperability can be facilitated. In addit...
E-commerce and trade — Technology has significantly transformed the world’s economy. The ability to make data flow worldwide, and the digitisation of information have enabled digital business models and spurred the growth of e-commerce. Digit...
E-commerce in the WTO: the next arena of Internet policy discussions? — E-commerce has been part of the World Trade Organization (WTO) agenda since 1998, following the Ministerial Declaration on Global Electronic Commerce. In the same year, the Organisation for Economic Co-operation and Deve...
What’s new with cybersecurity negotiations? OEWG 2021-2025 fourth substantive session — After that, the Chair will prepare a second revision of the PoC elements non-paper. Capacity building El Salvador, Argentina, and Kenya highlighted prioritising practical support for establishing capa...
AI and Digital in 2023: From a winter of excitement to an autumn of clarity — Cybersecurity: Preserving the internet in difficult times In 2023, cybersecurity has emerged in a wide range of contexts, from an increasing number of wars and conflicts (Ukraine-Russia, the invasion of Gaza, etc.) ...
The Overlooked Peril: Cyber failures amidst AI hype — Implementing existing and introducing new policies and legal instruments While technical protections are crucial, they alone are insufficient to address the complex landscape of cyber risks. The vulnerability of digita...
20 Keywords for the Digital 2020s: A Digital Policy Prediction Dictionary — Yet as questions of trust have become ubiquitous in digital discussions, clarity about what they in fact refer to has been lost. In the 2020s, digital trust debates will be exercised above all by the following questions:...
Online trust: between competences and intentions — This will help users to make more informed decisions on how they want to use Internet services and applications. Second, governments and public authorities should require that terms of service (ToS) are clear, concise, a...
Closing the Governance Gaps: New Paradigms for a Safer DNS — Capacity building is crucial in NSWs discussions, and efforts are being made to include representatives from regions outside the Global North. Additionally, capacity building is being addressed in the context of future i...
WS #280 the DNS Trust Horizon Safeguarding Digital Identity — This scale demonstrates that reactive abuse reporting alone is insufficient and proactive, automated processes are necessary. Preuves NetBeacon Reporter handling 20,000 monthly reports, standardizing and enriching r...
Open Forum #51 Strengthening Cyber Resilience in Global Posts Logistics — national authorities, and international organizations is essential for effective cybersecurity resilience Posts serve as critical infrastructure and trusted community hubs, making them attractive targets for cybercrimi...
How .POST powered services build Cyber Resilience within the global Postal and Logistics Sector — Intervenants - Kevin Hernandez- Esmeralda Kazia Arguments Only 35% of posts are affiliated with National Information Security Incident Response Teams International collaboration is essential for addressing cross-border po...
Cybersecurity — Cybersecurity came into sharper focus with the rapid expansion of the Internet's user base. One side effect of the rapid integration of the Internet in almost all aspects of human activity is the increased vulnerability ...
Leveraging data for securing cross-border e-commerce parcel traffic ( Cross-border Research Association) — By effectively identifying and profiling entities, customs authorities can allocate resources more efficiently and mitigate the risks associated with illicit trade.In conclusion, the discussion highlights the potential v...
E-commerce and trade — Technology has significantly transformed the world’s economy. The ability to make data flow worldwide, and the digitisation of information have enabled digital business models and spurred the growth of e-commerce. Digit...
Diplomatic policy analysis — Overdependence on algorithms without critical human oversight can lead to biased or incomplete conclusions, particularly in complex, nuanced scenarios. Digital divides: Not all countries have equal access to advanced an...
EU cyber defence policy framework — It will aim to improve the resilience of the EEAS CSDP networks, with a focus on prevention, detection, incident response, situational awareness, information exchange and early warning mechanisms. The protection of EEA...
International multistakeholder cyber threat information sharing regimes: Policy considerations for scaling trust and participation — The paper looks at the United States as a model for the development of cybersecurity information sharing policies over time, and establishes a model based on the United States that could be applied in some other jurisdic...
EU cyber defence policy framework (2018 update) — This IT security capability will cover both classified and unclassified systems and will be an integral part of the existing operational entities. There is also a need to streamline the security rules for the informatio...
UN OEWG 2021-2025 - Existing and potential threats in the sphere of international security — Countries have a responsibility to work together in order to reach agreements to secure and stabilise the ICT environment, Costa Rica noted. Botswana suggested the establishment of a permanent forum for exchanging knowl...
Unpacking the High-Level Panel’s Rapport on Digital Cooperation: Geneva policy experts propose action plan — Postal networks can potentially be used for the digital inclusion of not only the ‘next billion’, but also the ‘bottom billion’ of world citizens. Action: Organise an awareness-building event on the role of post offices ...
Enabling trade inclusion for MSMEs, women and underrepresented communities through the postal network (UPU)- UPU TradePost Forum — Despite the number of packages delivered more than doubling, this growth was mainly driven by big e-commerce services and retailers. The Universal Postal Union (UPU) reported an initial drop of over 20% in postal volumes...
E-commerce and trade — Technology has significantly transformed the world’s economy. The ability to make data flow worldwide, and the digitisation of information have enabled digital business models and spurred the growth of e-commerce. Digit...
UNCTAD eCommerce Week 2019: An overview — In the field of cybercrime, there is a need for stronger public-private partnerships in order to find adequate and scalable solutions. It is also important to provide cyber capacity building for actors who are part of th...
Cybersecurity — Cybersecurity came into sharper focus with the rapid expansion of the Internet's user base. One side effect of the rapid integration of the Internet in almost all aspects of human activity is the increased vulnerability ...
Open Forum #51 Strengthening Cyber Resilience in Global Posts Logistics Open Forum #51 Strengthening Cyber Resilience in Global Posts Logistics Rapport de session Intervenants Graphe de connaissances Analyse approfondie...
How .POST powered services build Cyber Resilience within the global Postal and Logistics Sector — The tone was collaborative and solution-oriented, with participants sharing both concerning statistics and practical initiatives. While the data presented was "scary" (as noted by intervenants), the overall atmosphere remain...
What’s new with cybersecurity negotiations? OEWG 2021-2025 fourth substantive session — After that, the Chair will prepare a second revision of the PoC elements non-paper. Capacity building El Salvador, Argentina, and Kenya highlighted prioritising practical support for establishing capa...
Cybercrime — https://dig.watch/wp-content/uploads/cybercrime-novi-72-dpi-DORADJEN-FINAL-2021.png AI and cybercrime The AI race between cybercriminals and those who try to protect systems is emerging as one of the most critical for ...
AI and Digital in 2023: From a winter of excitement to an autumn of clarity — Cybersecurity: Preserving the internet in difficult times In 2023, cybersecurity has emerged in a wide range of contexts, from an increasing number of wars and conflicts (Ukraine-Russia, the invasion of Gaza, etc.) ...
The Overlooked Peril: Cyber failures amidst AI hype — Implementing existing and introducing new policies and legal instruments While technical protections are crucial, they alone are insufficient to address the complex landscape of cyber risks. The vulnerability of digita...
Growing E-commerce Market in China — It became one of the largest messaging apps by the number of monthly users. As of May 2016, there were 700 million users and more than 70 million of those accounts were created outside of China. That is par...
Diplo launches e-commerce portal — Issues related to the digital economy have gained prominance in the last few years. The volume of e-commerce is soaring, and the impact of cross-border data flows on gross domestic product (GDP) growth is now larger than...
The rise of e-commerce initiatives: From expanding access to taxation — Pursuing a similar purpose and in an effort to bridge the rural-urban divide, the international company Alibaba plans to train a million teenagers in rural areas in China to help them start their own online businesses. A...
Embracing the future of e-commerce and AI now (WEF) — However, not all attempts to use AI in logistics have been successful. Graf's company attempted to leverage AI for return logistics, with the aim of automating the process of checking returned items.The AI was intended t...
Connecting the dots and (finally) understanding international security — Amidst the current environmental, socioeconomic, and health crises, a lot has been said in regard to humanity’s existential threats. COVID-19 has exposed us. The pandemic has revealed the fragility of our societies, and ...
Cybersecurity requires governments to step in — This why we need greater transparency and accountability about how vulnerabilities are handled. While companies are currently enhancing software development and implementing secure-by-design practices for reducing vulner...
Main Topic 1 -  One for all, all for one: the role of cooperation in enhancing cyber resilience in Europe  — Topics: Cybersecurity cooperation, International relations Rapport Cyber resilience is increasingly recognised as critical to ensuring the continued operation of essential sectors amidst digital threats. Forgi...
[ConfTech #4 discussion summary] (Cyber)Security and the shift to online — Remote work has also raised privacy concerns on whether corporate security policies can be ensured in homes and whether data that used to be stored on corporate networks can now be secured and insured in terms of integri...
WSIS Action Line C7 E-business: Building an inclusive digital economy — So many So hi everyone. So many So hi everyone. So many So hi everyone. So many So hi everyone. So many My name is Kevin Hernandez and I am a Digital Inclusion Expert at the Universal Postal Union, which is the United Na...
Universal Postal Union — The Universal Postal Union (UPU), a United Nations specialised agency, is the primary forum for cooperation between postal sector players. It aim is to establish international regulations for postal services and to prom...
[WebDebate #20 summary] Strategies for African States in Multilateral Diplomacy — UN Security Council reform and the Ezulwini Consensus Spies stressed that Africa is the only continent that has a unified position regarding the UN Security Council reform, however, the Ezulwini Consensus is not really a...
[WebDebate #17 summary] Humanitarian diplomacy and the influence of new actors and new technology — Ormeno agreed that diplomacy is not exercised only by state representatives and agents, but can also be carried out by communities at the local level, as his examples aptly illustrated. What is the key challenge or key h...
Towards a secure cyberspace via regional cooperation — A draft background study was prepared (the final study will be available soon). Mr Frank Grütter, UN GGE expert and Head of the Security Policy Division of the Swiss Federal Department of Foreign Affairs, opened the sess...
Framework to Develop Gender-responsive Cybersecurity Policy | IGF 2023 WS #477 — However, David also expressed concerns about the potential negative consequences of overemphasizing gender. He cautioned against an excessive focus on gender, highlighting the strategic disadvantages that can arise from ...
Prévisions 2023 : 12 tendances en matière de gouvernance numérique et de diplomatie — Par exemple, nous avons transféré tout et n'importe quoi vers le Cloud, qui autrefois semblait sûr, mais qui l'est de moins en moins (comme le confirment les attaques et les brèches dans les services Cloud de Twitter, Ub...

Avertissement : Il ne s'agit pas d'un compte rendu officiel de la session. DiploAI génère ces ressources à partir d'enregistrements audiovisuels ; elles sont présentées telles quelles, y compris d'éventuelles erreurs. En raison de contraintes logistiques (audio/vidéo ou transcriptions), les noms peuvent être mal orthographiés. Nous nous efforçons d'être aussi précis que possible.