UN OEWG

This page provides detailed and real-time coverage on cybersecurity and peace and security negotiations at the United Nations.

The use of cyberattacks by states – and, more generally, the behaviour of states in cyberspace in relation to maintaining international peace and security – is moving to the top of the international agenda.

Historically, as you can consult further down, the basis for cybersecurity at the UN was laid by the work of the UN Group of Governmental Experts (UN GGE) between 2004 and 2021. Currently, the focus is on the work of the UN Open-Ended Working Group (OEWG) on security of and in the use of information and communications technologies 2021–2025.

In November 2022, the First Committee of the UNGA adopted a resolution on the programme of action (PoA) on cybersecurity, which proposes to establish a PoA as a permanent, inclusive, action-oriented mechanism after the OEWG 2021-2025 ends.

Recent achievements: In July 2023, delegations reached a compromise on the second Annual Progress Report.

Next steps: The OEWG will hold its seventh substantive session on 4-8 March 2024 in New York. In addition, OEWG Chair will convene a dedicated Global Roundtable on ICT security capacity-building on 10 May 2024 in New York in the form of a high-level meeting, open to capacity-building practitioners, State representatives, and interested stakeholders.

For most recent updates, consult the menu to the right.

CYBER DIPLOMACY color 72 dpi

To learn more about risks of cyber conflict, global negotiations on cyber norms and the framework of responsible behaviour, and cyber diplomacy, enrol on our Cybersecurity Diplomacy online course.

The current process - OEWG 2021-2025

In December 2020, the OEWG was renewed for 2021-2025 (A/RES/75/240). The OEWG started its second mandate (2021–2025) with the organisational session held in June 2021. After the three substantive sessions of the OEWG held in December 2021April and July 2022, the main stumbling stone remains the participation of non-state stakeholders in the OEWG process. Despite tensions due to the war in Ukraine, some progress in confidence-building measures and capacity building was made. In July 2022, delegations reached a compromise on the Annual Progress Report. In July 2023, delegations reached a compromise on the second Annual Progress Report. Annual Progress Reports serve as a roadmap for further negotiations. 

 

Timeline
The group started its work on 1 June 2021 with an organisational session. Its first substantive session was scheduled for December 2021, followed by the second substantive session, 28 March-1 April 2022, and the third substantive session, 25-29 July 2022. Its fourth and fifth substantive sessions are scheduled for 6-10 March and 17-21 July 2023, respectively.
Participation
The composition is declared as open, allowing all UN member states that express a desire to participate. In addition, the first OEWG held consultative meetings with interested parties – businesses, non-governmental organisations, and academia. Applications were managed by UNODA and approved on a ‘no objection’ basis (i.e. objections by the governments). It remains to be seen how stakeholders will be included in the discussions of the second OEWG. Ambassador Burhan Gafoor of Singapore was elected, by acclamation, as the Chair of the second OEWG.

Our reports and blogs

A team of GIP rapporteurs followed the discussions at the OEWG and produced detailed reports and blogs from:

See also: Africa's participation in OEWG discussions

 

The future process - PoA

Co-proposed by 40 states, a Programme of Action (PoA) for advancing responsible state behaviour in cyberspace would establish ‘a permanent UN forum to consider the use of ICTs by States in the context of international security’. The proposal suggests the PoA to be in a single, long-term, inclusive, and progress oriented format; its implementation and follow-up measures could be subsequently endorsed by the UN GA. 

In November 2022, the First Committee of the UNGA adopted a resolution on the programme of action (PoA) on cybersecurity.

Framework of responsible behaviour (the acquis)

The term ‘acquis’ (a reference to the EU’s body of laws) which popped up in recent cyber negotiations, refers to the body of existing agreements. While it has quickly been adopted for informal discussions, there is still no clear understanding of everything it encompasses.

It does encompass:

All reports were adopted by respective resolutions of the UNGA by consensus of all states.  

Additionally, other resolutions, such as those that established the GGEs and OEWGs on cybersecurity, also play a role, as states refer to some of them throughout negotiations. This particularly refers to the UNGA resolutions that established the OEWG in 2018 and 2020, since they do not entirely match GGE's reports, but rather reflect on other issues such as propaganda, and have procedural implications.

The timeline below shows when the aforementioned documents were adopted and what their most important points were.

 

  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  • - UN starts addressing cybersecurity issues

    A proposal to address cybersecurity at the United Nations was made by Russia on 30th September 1998. It was formally adopted by the UNGA Resolution A/RES/53/70 on 4th January 1999.

  • - 2010 UN Governmental Group of Experts (GGE) Report on Cybersecurity

    Report of the UN GGE 2009/2010, which includes recommendations for:

    • Further dialogue among States to reduce the risk and protect critical national and international infrastructure
    • Confidence-building, stability and risk reduction measures
    • Information exchanges on national legislation and strategies, and capacity-building measures
    • The elaboration of common terms and definitions related to information security
    • Capacity-building in less developed countries
  • - 2013 UN GGE report recognises that international law applies to digital space

    Report of the UN GGE 2012/2013 (later adopted by the UN General Assembly Resolution A/RES/68/243), which includes:

    • Recognition that international law, and in particular the UN Charter, applies to digital space
    • Norms, rules, and principles on the responsible behaviour of States
    • Reference that state sovereignty applies to the digital field
    • The principle that states must meet their international obligations regarding internationally wrongful acts in cyberspace attributable to them
  • 24/01/2023 - 2015 UN GGE Report: Introduction of 11 Principles on Cybersecurity

    24/01/2023

    The report of the UN Group of Governmental Experts (UN GGE) 2015 encompasses principles of State sovereignty, the settlement of disputes by peaceful means, and non-intervention in the internal affairs of other states, applies to cyberspace; recognition that states must comply with their obligations under international law to respect and protect human rights and fundamental freedoms, the agreement that UN should play a leading role in developing common understandings on the application of international law and norms, rules and principles for responsible State behaviour, other norms, rules, and principles on the responsible behaviour of states, confidence-building measures (CBMs), and an invitation for international cooperation and assistance in ICT security and capacity building.

    The report was later adopted by the UN General Assembly Resolution A/RES/70/174.

  • - Establishment of the UN Open-Ended Working Group (OEWG) on Cybersecurity

    UN GA on OEWG resolution includes:

    • Setting up the OEWG
    • Welcoming a chosen set of norms enshrined in the GGE Reports of 2013 and 2015
  • - Establishment of the Second UN Open-Ended Working Group (OEWG) on Cybersecurity

    Consult UN GA Resolution on Establishment of the Second OEWG that includes:

    • The renewal of the OEWG for a period of five years – 2021 to 2025, with the same mandate
    • The organisational session of the new OEWG be held in 2021 and includes the establishment of thematic subgroups, allowing interaction with other stakeholders.
    • The group is to provide an annual progress report and a final report to the 80th UNGA, starting in autumn 2025.
  • - Report of the First UN OEWG on Cybersecurity

    • Reaffirmation of the results of the previous reports of the Group of Governmental Experts (GGE), as well as that international law, and in particular the Charter of the UN, is applicable to cyberspace
    • Norms do not replace or alter states’ obligations or rights under international law – which are binding – but rather provide additional and specific guidance on what constitutes responsible state behaviour in the use of ICTs
    • Recommendation that states voluntarily identify and consider CBMs
    • Recommends that appropriate to their specific contexts, and cooperate with other states on their implementation
    • Comprehensive capacity building measures in the field of ICT security

    Consult the first OEWG Report (2021)

  • - 2021 UN GGE Final Report

    The UN GGE concluded its work with this Report. Cybersecurity process will shift to the UN OEWG.

    Consult 2021 UN GGE Report

Open issues

Despite long-running discussions and several consensus reports, there are a number of issues that remain open.

Does existing international law apply to cyberspace?
There is a broad consensus that international law applies to cyberspace – this includes the UN Charter as expressed in UN GGE reports, reaffirmed by the final OEWG report and the related UN General Assembly (GA) resolutions. More specifically, there is a general agreement that the states have jurisdiction over information and communications technology (ICT) within their territory, and that states should not conduct internationally wrongful acts nor use proxies for such acts.
How does the UN Charter apply to cyberspace?
There is broad agreement that the UN Charter in its entirety applies to cyberspace, which was confirmed by GGE reports and related UNGA resolutions, as well as by the final OEWG report. However, it gets much more complicated when we look at specific articles of the UN Charter and their interpretations.
How does state sovereignty translate into cyberspace?
One of the principles of the UN Charter is self-determination and the equality of states, reflected in Article 2. The 2021 GGE report and the 2021 OEWG report state that sovereignty applies to ICTs, and that states have jurisdiction over ICTs within their territory. There is a consensus that states have an obligation to respect the sovereignty of other states and to refrain from activities that constitute a violation of other states’ sovereignty, including cyber operations that would violate the sovereignty of another country. The question remains as to what responsibilities (stemming from the principle of sovereignty and sovereign equality) are assumed by states. While some states refer to the right of executing jurisdictional authority within the territorial borders of their country (principle of non-interference), others also attach a responsibility of not allowing other actors to use the territory of any given state to conduct malicious cyber activities (i.e. the principle of due diligence as described later). States also struggle with the global reach of cyber activities that do not fit into the traditional definition of sovereignty (i.e. protecting state authority over property and persons within territorial borders). For example, cyberattacks that target extraterritorial data storage (i.e. assert sovereign power over data) often include proxy servers or other tools that render the attackers untraceable (i.e. mask their geographical origin). This can make it extremely difficult to determine whether they involved a cross-border operation that would violate a state’s sovereignty
Non-interference principle: coercion, use of force, or armed attack?
The non-interference principle, derived from the principle of sovereignty, prohibits interference in the internal or external affairs of another state with the intent to employ coercion against that state. Existing and emerging technologies provide states with more opportunities to influence and interfere in the internal or external affairs of other states. In the context of cyberspace, a question arises: When are cyber operations considered coercion, use of force, or an armed attack given that no weapons in the usual (physical, kinetic) sense are used? Most states at the OEWG assess cyberattacks on an individual basis, after considering their effects and whether they are comparable to those of a conventional and prohibited act of violence. One open issue includes defining the thresholds of interference, i.e. at what point can a targeted state respond or have the right to defend itself. The precise boundaries between coercion, the use of force, and an armed attack have not yet been set. The two main points in this regard are the interpretation of Art. 2 (4) of the UN Charter and Art. 51 of the UN Charter. Coercion as economic, diplomatic, or political pressure is not defined under Art. 2 (4) of the UN Charter. In certain cases, however, when evaluated through its effects, it cannot be ruled out that a cyber operation with serious financial or economic impacts may qualify as the use of force. When interpreting the use of force, as described in Art. 2(4) of the UN Charter, international law does not provide a clear definition. Each case is examined individually to establish whether the ‘scale and effects’ are such that an operation may be deemed a violation of the prohibition of the use of force. That being said, the prohibition of the use of force is acknowledged by states at the OEWG and its implementation is a priority at the OEWG discussions. The majority of states at the OEWG also agree that an armed attack does not necessarily have to be carried out by kinetic means to trigger a state’s right to self-defense.
(How) Does the right to self-defence, enshrined in the UN Charter (Art. 51), apply to cyberattacks?
The UN Charter, as the basis of jus ad bellum, grants in Art. 51 the right to invoke individual or collective self-defence if an armed attack occurs against a member state. Yet, what exactly constitutes an internationally wrongful act, a use of force, or an armed attack in cyberspace? What is the threshold of an armed attack? Is it limited to attacks that cause physical damage and injury, or would other effects (financial, environmental, economic, or political) of a cyberattack also count? Should this determination remain the sole responsibility of states – perhaps by considering certain factors such as context, intent, or the severity of effects, as suggested in the Tallinn Manual 2.0? The major stumbling block, however, is the right to self-defence. In particular, should countries that are subject to a cyberattack be allowed to respond by any means, including all-out military options associated with traditional means of warfare? This question was one of the main reasons why the GGE failed to reach a consensus in 2017. The 2021 GGE report concludes that the ‘affected state’s response to malicious ICT activity attributable to another state should be in accordance with its obligations under the UN Charter and other international law, including those relating to the settlement of disputes by peaceful means and internationally wrongful acts.’ Positions on this issue are openly divergent: NATO has confirmed that Art. 5 of its Treaty allows response by any means (including conventional weapons) in the event of a cyberattack against one of its members. Russia finds that the traditional use of force is not a legitimate response to cyberattacks, at least not without the approval of the UN Security Council and in accordance with the UN Charter, which allows the accused party to defend itself before the Security Council. Russia further requests that the sources of cyberthreats are not identified by (attacked) states independently and arbitrarily, without evidence, particularly if this could lead to devastating counter-strikes. Some small states, like Cuba, believe that a cyberattack is not tantamount to an armed attack, and thus, the right to self-defence should not be used in such cases. An additional gray zone is the right to self-defence against armed attacks conducted by non-state actors or state proxies.
In what other ways can countries respond to cyberattacks?
While the right to self-defence may apply once the attack has occurred, what other options does a state have to respond to cyberattacks and deter counterparties from conducting such attacks? Also, should anticipatory self-defence (to deter imminent threats) or even preemptive strikes be considered? For instance, the USA and the EU consider the following actions to be acceptable: The USA believes in a ‘cyber deterrence menu’ of countermeasures that states can take when an attack occurs and to deter further attacks. It additionally supports accountability measures in relation to attackers: private and public attribution, sanctions, deterrence alliances, and even ‘defense forward’ (or preemptive) cyber strikes. The EU has adopted its cyber-diplomacy toolbox and sanction regime as official options to respond to and deter cyberattacks, as well as its Cybersecurity Strategy for the Digital Decade. EU member states have voiced their opinions in national capacities as well; for example, France believes anticipatory self-defence may be allowed, but not preemptive strikes. It also remains an open question whether states should have the duty to notify the state against which they plan to launch countermeasures.
How should attribution of cyberattacks be conducted?
Discussions often turn to the challenge of enforcing the agreed upon rules, be they binding ones, such as international law, or voluntary, such as norms and CBMs. One of the main challenges with holding states accountable for their operations is the complexity of attribution. As we saw in Module 1, an attack may include many layers of techniques that mask its origins. Even if one could provide technical evidence that connects an attack to a certain hacker group, it is a legal challenge to prove the connection between a particular state and a cyberattack. Therefore, rather than responding to a certain incident with evidence and dialogue, states are turning to campaign-like public attribution against other parties There is no agreed-upon methodology on how to establish attribution to cyberattacks. There are divergent views among experts over how reliable current technical means are for tracing the origins of attacks. Certain aspects of intelligence-gathering – such as conventional intelligence activities and cyberespionage for the collection of digital evidence – are understandably kept secret by parties working on attribution. In addition, the lack of transparency over evidence seen in the recent avalanche of mutual public accusations among states adds to the complexity. While the 2015 GGE report (Art. 28f), the resolution that established the OEWG (Art 1.2), and the final OEWG report confirm that the indication of the origin of the attack might not be enough for attribution and that accusations need to be substantiated, the official positions of the main actors are clearly divergent: The USA, its NATO allies, and some of the large internet industry players engage in collective attribution in the form of a joint public naming and shaming of the suspects. Russia sees such an approach as a pseudo-legal concept where a group of countries accuse a third country without disclosing evidence and demand evidence-based attribution. The 2021 UN GGE report also calls for caution in attribution, as it is a complex exercise and such caution can help avert misunderstandings and the escalation of tension between states.
Should due diligence be an obligation?
Due diligence is an obligation of states to prevent their territory from being used for the launch of cyberattacks against other states by state or non-state actors. The norms set in the 2015 GGE report, and reiterated in the OEWG resolution, as well as the 2021 GGE report request countries not to allow their territory to be used for internationally wrongful acts, and to mitigate cyberattacks against the critical infrastructure (CI) of other countries that originate in their territory. The final OEWG report went on to reaffirm the 2015 GGE norms. The 2021 GGE report added that the invocation of the responsibility of a state for an internationally wrongful act involves complex technical, legal, and political considerations. In practice, aside from the norms being voluntary, there may be a number of reasons why their implementation could be limited. For instance, states may only react to attacks, rather than try to prevent them, or they may claim they didn’t know about the attack at all. The EU and its partners believe that due diligence should be a binding obligation (both in cyberspace and beyond) following the International Court of Justice judgment in the Corfu case (1949), and warn that not adhering to it may result in countermeasures by the attacked country. Russia and its partners, on the other hand, oppose due diligence as an obligation in general, and only approve what has been agreed by the GGE.
Are new norms needed?
Are more norms needed at the moment? Or should the focus be placed on the implementation of existing ones? The 2015 GGE report, the resolution that established the OEWG, and the final OEWG report provide room for the development of additional norms over time. Some of the options raised by different parties – with evident divergence in their positions – include norm proposals by the Global Commission on the Stability of Cyberspace (GCSC) such as protecting the public core of the internet, preventing injury to civilians, mitigating the effects during incidents, and protecting electoral systems, as well as norms related to the effects of artificial intelligence (AI) on security, fake news, and disinformation, the protection of core internet infrastructure as public goods, and cybercrime issues, among others.

Past processes: GGE and OEWG 2019-2021

The Open-Ended Working Group (OEWG) 2019/2020

The OEWG 2019/2020 was established by the UN General Assembly in December 2018 (A/RES/73/27).

The UN Group of Governmental Experts (GGE)

The UN Group of Governmental Experts (GGE) on Advancing responsible State behaviour in cyberspace in the context of international security (formerly: on Developments in the Field of Information and Telecommunications in the Context of International Security) have convened from 2004 until 2021. 

GGE vs OEWG

In 2018, the UNGA adopted two resolutions (one sponsored by the USA (A/RES/73/266), the other by Russia (A/RES/73/27)) which set up the continuation of the GGE in 2019–21 and the UN OEWG. During 2019-2021, the GGE and the OEWG worked in parallel in somewhat different settings. Considerable cooperation between the chairs of the two groups was established, and many countries played an active and constructive role in both.

(Click on the infographic below, or here, for a voice-reader accessible .pdf version.) 

The table compares the membership, issue areas, and reporting objectives of the UN GGE and OEWG, and includes a timeline of their work programmes