UN Global Mechanism on ICT Security highlights growing role of stakeholders

The UN’s permanent cyber mechanism devoted a full session to accredited stakeholders, with technical organisations, civil society groups, humanitarian actors, and youth representatives calling for greater participation in shaping international cybersecurity cooperation and urging member states to make stakeholder engagement a practical part of implementing the UN cyber framework.

The sixth meeting of the first substantive plenary session of the Global Mechanism on ICTs in the Context of International Security combined stakeholder interventions with discussions on international law and confidence-building measures (CBMs). Throughout the day, speakers argued that responsible state behaviour in cyberspace increasingly depends on close cooperation with the technical community, researchers, industry, humanitarian organisations, and civil society.

A recurring concern was the exclusion of more than 60 accredited organisations from formal participation. Multiple stakeholders called on member states to adopt transparent, criteria-based accreditation procedures, arguing that meaningful implementation of the UN cyber framework requires inclusive multistakeholder participation.

Technical community highlights operational expertise

Several organisations emphasised that many of the practical tools needed to strengthen cybersecurity already exist outside governments.

ICANN outlined its work on strengthening the resilience of the internet’s domain name system, while the Internet Society highlighted initiatives supporting routing security, internet exchange points, and critical cybersecurity infrastructure. FIRST, representing hundreds of incident response teams worldwide, stressed the importance of international cooperation among technical responders, responsible vulnerability disclosure, and operational collaboration during cyber incidents.

Other stakeholders focused on implementation challenges. Chatham House argued that practical guidance alone is insufficient unless states also possess the institutional capacity to apply it, while Developing Capacity LTD highlighted existing resources and cyber capacity-building initiatives that could support the work of the Dedicated Thematic Groups (DTGs).

Youth, civil society and humanitarian perspectives

The Discover MUN Foundation, speaking on behalf of the UN Major Group for Children and Youth, called for age-disaggregated data on malicious cyber activity, dedicated youth capacity-building initiatives, and recognition of youth engagement itself as a confidence-building measure.

Human rights organisations drew attention to the disproportionate impact of cyber threats on vulnerable communities, while Access Now highlighted the growing number of internet shutdowns during armed conflicts and called for greater attention to the human consequences of cyber operations. The Centre for Humanitarian Dialogue introduced another emerging issue by encouraging states to begin developing confidence-building measures specifically for post-conflict cyber environments.

States back stronger cooperation with stakeholders

During the interactive dialogue, several member states acknowledged the value of stakeholder expertise.

Canada, the European Union, Japan, Chile, Germany, and Mexico encouraged stronger collaboration with technical organisations, academia, and civil society, particularly within the DTGs. Delegations also criticised the exclusion of numerous accredited organisations, arguing that broader participation would strengthen implementation of the UN framework rather than complicate negotiations.

Stakeholders responded by offering practical implementation resources, including policy guidance, technical expertise, training programmes, capacity-building platforms, and operational tools that could support future work under the Global Mechanism.

International law discussions remain implementation-focused

The session also continued discussions on the application of international law to cyberspace.

Switzerland and Australia argued that the mechanism should build on existing areas of legal convergence by examining practical cyber scenarios through the DTGs. The International Committee of the Red Cross called for greater attention to how international humanitarian law protects civilian infrastructure and addresses emerging technologies such as AI in armed conflict.

While Algeria and Nicaragua continued to support the eventual development of legally binding international instruments, the United States maintained that existing international law remains sufficient and that discussions should focus on implementation rather than negotiating new treaties.

Confidence-building measures move towards implementation

The final part of the session focused on operationalising the confidence-building measures agreed during the previous UN Open-ended Working Group.

Many delegations identified the Global Points of Contact Directory as one of the mechanisms’ most practical achievements, describing it as an important tool for crisis communication and incident response. Small island developing states, including Kiribati and Nauru, emphasised that reliable communication channels are essential for countries with limited diplomatic and technical resources.

Regional initiatives such as the Pacific Cybersecurity Operational Network were repeatedly cited as examples of how regular cooperation, information sharing, and practical exercises can build trust before cyber incidents occur.

Closing the meeting, the Chair thanked both member states and stakeholders for their extensive contributions and noted that discussions on confidence-building measures would continue the following day.

Track all key moments from the First substantive session of the UN Global Mechanism on cybersecurity on our dedicated page.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

UN Global Mechanism on ICT security shifts towards practical cybersecurity cooperation

The UN’s permanent cyber mechanism continued its substantive discussions by identifying shared priorities for international cooperation, with member states highlighting ransomware, AI, critical infrastructure protection, and capacity development as areas requiring practical action.

During the third plenary of the first substantive session of the Global Mechanism on Developments in the Field of ICTs in the Context of International Security, delegations repeatedly stressed that discussions should move beyond mere description of cyber threats to developing practical tools to help states prevent, detect, and respond to them.

The discussion reinforced a trend already visible during earlier meetings, that despite differing national perspectives on specific cyber incidents, broad agreement is emerging on the issues likely to shape the mechanism’s future work.

From identifying threats to supporting implementation

Several delegations argued that the mechanism’s success should be measured by its ability to translate years of international negotiations into practical cooperation.

Kiribati captured this approach by observing that discussions on cyber threats should not end with mere descriptions but lead to concrete measures that enable countries of all sizes to strengthen their cyber resilience. Cameroon and Morocco similarly encouraged the mechanism to prioritise practical implementation through the Dedicated Thematic Groups (DTGs), which are expected to become the forum’s primary venue for detailed technical cooperation.

The emphasis on implementation reflected a broader shift from developing international norms towards helping governments apply them in practice through information sharing, capacity development, and operational cooperation.

Critical infrastructure protection gains momentum

Protection of critical infrastructure emerged as one of the strongest areas of convergence during the session.

Small island developing states offered particularly compelling examples of how digital infrastructure has become essential for national resilience. Kiribati described how its first submarine cable has transformed public services while simultaneously increasing its exposure to cyber risks. Tonga recalled the 2022 volcanic eruption that severed its only submarine cable, leaving the country isolated during a national emergency, and warned that a malicious cyber operation could deliberately produce similar consequences.

Delegations from Australia, Tuvalu, Chile, Ghana, Zimbabwe, and other countries similarly highlighted the growing importance of protecting undersea cables, telecommunications infrastructure, government networks, and other critical systems that underpin economic activity and essential public services.

Rather than treating these as purely national concerns, speakers increasingly framed critical infrastructure resilience as a shared international challenge requiring cooperation across borders.

Ransomware remains a global priority

Ransomware was once again identified as one of the most significant cyber threats facing governments and critical services worldwide.

Delegations described attacks affecting healthcare systems, humanitarian organisations, government institutions, municipalities, telecommunications providers, and energy infrastructure.

National experiences illustrated the scale of the challenge. Tonga described how a ransomware attack encrypted its national health information system, forcing hospitals to return temporarily to paper records. Germany cited estimates placing annual cyber-related economic damage at approximately US$230 billion, while several countries highlighted the growing sophistication and transnational nature of ransomware operations.

Many speakers emphasised that responding effectively will require stronger international information sharing, coordinated incident response, public-private cooperation, and support for countries with more limited cybersecurity capacities.

AI increasingly shapes cybersecurity discussions

AI continued to feature prominently throughout the session as delegations examined its growing influence on the cyber threat landscape.

Countries from different regions observed that AI is lowering barriers to entry for malicious actors while increasing the speed and sophistication of cyber operations. Among the risks identified were AI-generated phishing campaigns, automated vulnerability discovery, deepfakes, large-scale disinformation, and attacks targeting AI systems themselves.

Several delegations also pointed to emerging challenges related to frontier AI models, quantum computing, commercial cyber intrusion capabilities, and digital supply chain security, suggesting these issues should continue to receive attention within the Global Mechanism.

While views differed on how these developments should be governed internationally, there was broad agreement that the mechanism provides an important forum for exchanging experience and improving collective understanding of rapidly evolving technologies.

Capacity development remains central to cyber resilience

Developing countries consistently stressed that discussions on cyber threats should be matched by practical support.

Delegations highlighted the importance of strengthening national institutions, expanding technical expertise, improving incident response capabilities, and ensuring that developing countries can participate fully in the mechanism’s work.

Small island developing states noted that limited resources often magnify the consequences of cyber incidents, while African, Asian, Caribbean, and Pacific countries called for sustainable, demand-driven capacity-building programmes tailored to national priorities. Several speakers also encouraged greater regional cooperation and more structured exchanges of operational experience.

These interventions reinforced the view that improving global cybersecurity depends not only on reducing threats but also on ensuring that all countries have the capabilities needed to address them.

Dedicated Thematic Groups move into focus

Attention also turned to the role of the Dedicated Thematic Groups as the mechanism’s principal vehicle for translating discussions into practical outcomes.

Delegations proposed using the groups for scenario-based discussions, expert briefings, exchanges of operational experience, and the development of practical recommendations on issues such as critical infrastructure protection, supply chain security, ransomware, and implementation of agreed voluntary norms. Several countries argued that the groups should focus on a limited number of concrete priorities that could produce measurable results.

Alongside these substantive discussions, some delegations continued to express differing views regarding state attribution of cyber incidents and recent geopolitical developments. While these exchanges reflected broader international tensions, the majority of interventions remained focused on strengthening cooperation within the Global Mechanism and identifying practical areas where progress can be achieved.

As the session concluded, the Chair confirmed that discussions would continue with the remaining speakers before the mechanism moved to its next agenda item on voluntary norms for responsible state behaviour in cyberspace.

Track all key moments from the First substantive session of the UN Global Mechanism on cybersecurity on our dedicated page.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

UN Global Mechanism on ICT security identifies ransomware and AI among key global cyber threats

The UN’s new permanent mechanism on international cybersecurity shifted from organisational discussions to substantive exchanges on the evolving cyber threat landscape, with member states identifying ransomware, attacks on critical infrastructure, and the malicious use of AI among the most pressing challenges requiring international cooperation.

Meeting during the first substantive plenary session of the Global Mechanism on Developments in the Field of ICTs in the Context of International Security, delegates also continued discussions on the organisation of the mechanism’s Dedicated Thematic Groups (DTGs), which are expected to play a central role in translating years of normative work into practical cooperation.

While delegations expressed different views on some procedural aspects of the DTGs, there was broad agreement that the groups should focus on practical, action-oriented work and avoid duplicating discussions already taking place during the annual plenary sessions.

Dedicated Thematic Groups take shape

Several delegations described the DTGs as one of the Global Mechanism’s most important innovations, providing an opportunity for more detailed discussions than are possible during formal plenary meetings.

Brazil, Argentina, Chile, Kiribati and New Zealand encouraged the groups to concentrate on a limited number of priority topics capable of producing practical recommendations. Germany similarly proposed focusing on thematically coherent issues, including ransomware and the protection of critical infrastructure, while ensuring that discussions ultimately feed back into the plenary through concrete recommendations.

A recurring message throughout the discussion was that the mechanism should now move from establishing common principles towards supporting their implementation. Several delegations cautioned that attempting to address too many issues simultaneously could reduce the effectiveness of the DTGs, advocating a focused approach instead during their first biennium.

Delegations also highlighted the importance of maintaining predictable working methods, ensuring meaningful participation by all regions, and enabling smaller countries to contribute effectively throughout the process.

Broad support for stakeholder expertise

Another recurring theme was the value of involving technical expertise in DTG work.

Countries from different regions highlighted the contributions that academia, the private sector, civil society, and technical organisations can make to understanding rapidly evolving cyber threats and supporting the implementation of agreed commitments.

Oman stressed that governments alone cannot access all relevant technical knowledge, while Argentina called for transparent and predictable arrangements for stakeholder participation. France argued that cybersecurity requires cooperation across different communities, describing cyber diplomacy as a ‘team sport’. The African Group likewise recognised that expertise from non-state actors complements the intergovernmental character of the mechanism.

Many delegations also underlined that meaningful stakeholder engagement would be particularly valuable during the more interactive discussions planned within the thematic groups.

Ransomware and critical infrastructure emerge as shared priorities

As discussions moved to the evolving cyber threat landscape, a strong degree of convergence emerged across regions.

Ransomware was consistently identified as one of the most significant threats facing governments, businesses, and societies. Delegations pointed to attacks affecting healthcare, public administration, financial services, energy systems, telecommunications, and other essential services.

Several countries drew on national experience to illustrate the impact of such incidents. Costa Rica referred to the disruption caused by major ransomware attacks in 2022, while Ireland highlighted the effects of the 2021 cyberattack on its health service. Singapore noted that nearly 8,000 ransomware incidents were publicly reported worldwide during 2025, underlining the increasingly transnational nature of the threat.

The protection of critical infrastructure also emerged as a common concern. Delegations discussed the resilience of healthcare systems, government services, energy networks, transport infrastructure, telecommunications, and undersea cables, with several suggesting these issues should become early priorities for the DTGs.

AI reshapes the cyber threat landscape

The malicious use of AI featured prominently throughout the session, with delegations from all regions describing its growing impact on cybersecurity.

Countries warned that AI is accelerating the speed and sophistication of cyber operations while lowering barriers to entry for malicious actors. Among the concerns raised were AI-enabled phishing campaigns, automated vulnerability discovery, deepfakes, synthetic media, disinformation, and attacks targeting AI systems themselves.

Several delegations also pointed to emerging challenges, including quantum computing, post-quantum cryptography, commercial spyware, and increasingly sophisticated cybercrime ecosystems. While views differed on whether these developments require new international norms, there was broad recognition that the mechanism should continue examining their implications within its existing mandate.

Capacity building remains central for developing countries

Capacity building remained a cross-cutting priority throughout the session, particularly for developing countries and small island developing states.

The African Group called for practical implementation of existing capacity-building initiatives, including the ICT security cooperation portal, fellowship programmes, and the global network of national points of contact. Other delegations highlighted regional initiatives aimed to strengthening resilience, improving cyber hygiene, and supporting national institutions.

Small island developing states added an important practical perspective to the discussion. Vanuatu described how cyber resilience has become closely linked to disaster preparedness, while Nauru observed that countries connecting to the internet today immediately face the full spectrum of contemporary cyber threats rather than encountering them gradually over time.

The session concluded with the Chair confirming that consultations on the DTGs would continue ahead of their first meetings in December. While some organisational questions remain under discussion, the exchanges demonstrated growing convergence on the substantive issues likely to shape the mechanism’s future work, particularly ransomware, critical infrastructure protection, AI-enabled threats, and strengthening cyber capacity across all regions.

Track all key moments from the First substantive session of the UN Global Mechanism on cybersecurity on our dedicated page.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

UNIDIR publishes guidance on gender-responsive cybersecurity

The United Nations Institute for Disarmament Research (UNIDIR) has published a compendium of good practices to help governments integrate gender perspectives into cybersecurity policies and strengthen the implementation of responsible state behaviour in cyberspace.

Drawing on a series of multistakeholder workshops held with the Stimson Center in 2025, the report brings together existing initiatives and practical examples from governments and other stakeholders. It also identifies lessons learned and recommendations for incorporating gender considerations into national ICT architectures and implementing the UN Framework for Responsible State Behaviour in Cyberspace.

The compendium covers four themes: the gendered impacts of ICTs, the application of international law in cyberspace, the integration of gender into national cybersecurity institutions and strategies, and gender-responsive cyber capacity building. It also includes practical recommendations and a toolbox of resources for policymakers and practitioners.

UNIDIR said the compendium is intended to help governments and other stakeholders strengthen cybersecurity governance through more inclusive policy development and implementation.

Why does it matter?

The compendium reflects growing recognition that cybersecurity governance should consider how cyber threats, policies and digital technologies affect different groups of people. Rather than treating gender as a standalone issue, the report presents it as an element of effective, inclusive cybersecurity policymaking.

By collecting practical examples and recommendations from governments and the wider multistakeholder community, the publication also supports international efforts to strengthen responsible state behaviour in cyberspace and build more inclusive national cyber capacity.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

UN Global Mechanism on cybersecurity begins work with focus on participation and consensus

The United Nations’ new permanent mechanism on international cybersecurity has begun its substantive work, opening a new phase of multilateral discussions on responsible state behaviour in cyberspace.

The first substantive session of the Global Mechanism on Developments in the Field of ICTs in the Context of International Security opened on 20 July at UN Headquarters in New York under the chairmanship of Ambassador Egriselda López of El Salvador. The meeting marked the first time member states had convened within a standing UN framework dedicated to ICT security and responsible state behaviour.

The mechanism succeeds years of negotiations under the Open-Ended Working Group and is intended to provide a permanent, single-track forum for discussions across five established pillars, such as existing and potential ICT threats, rules and norms of state behaviour, the application of international law, confidence-building measures, and capacity development.

In a pre-recorded statement, UN Under-Secretary-General and High Representative for Disarmament Affairs Izumi Nakamitsu described the mechanism as holding ‘tremendous promise’. She highlighted its permanent and consensually agreed character and called for stakeholder engagement to take place in a systematic, sustained, and substantive manner.

A permanent forum takes shape

Opening the session, López described the meeting as a historic moment that would help shape not only the first two-year cycle of the mechanism but also the UN’s wider approach to ICT security in the years ahead.

She acknowledged that the forum was beginning its work amid a complex international environment marked by attacks against critical infrastructure, disruptions to digital supply chains, the use of ICTs in conflicts, and the growing interaction between cybersecurity and emerging technologies such as AI.

The Chair also emphasised that agreement would require sustained diplomatic effort.

‘Consensus is not automatic,’ López told delegations, arguing that it must be built through commitment, flexibility, and political will.

She noted that multilateral processes are often advanced through ‘small steps, difficult compromises, and the willingness to keep talking even when there are differences’.

The session achieved an early procedural milestone with the adoption, by consensus, of the provisional agendas for the 2026 and 2027 plenary sessions. The mechanism also noted its provisional programme of work, creating a framework for the substantive discussions scheduled for the week.

The mechanism tests its approach to stakeholder participation

A substantial part of the opening discussion focused on how non-governmental stakeholders should participate in the mechanism.

Under the agreed accreditation procedure, applications are accepted unless a member state submits a written objection. The Chair reported that she had held consultations with states that raised objections, although the positions of the concerned governments remained unchanged.

Several delegations expressed concern that a large proportion of stakeholder applicants had not received accreditation. They argued that technical experts, civil society organisations, industry representatives, and academic institutions can provide knowledge that supports informed negotiations and practical implementation.

The issue was particularly important for smaller and developing states, some of which said they rely heavily on external partners because they have limited domestic technical and diplomatic capacity.

Kiribati emphasised that technical partners and regional organisations had contributed to its national cybersecurity posture and helped shift international discussions from problem identification to solution delivery. It called for greater transparency around objections, arguing that explanations could help states understand and potentially address the concerns raised.

‘Transparency here costs the objecting state little; silence costs the rest of us a great deal,’ the delegation said.

Other delegations placed greater emphasis on ensuring that participating organisations meet the agreed standards of objectivity and impartiality. They maintained that the non-objection procedure was negotiated by consensus and that states retained the right to raise concerns about individual applicants.

The discussion, therefore, reflected a broader institutional question of how the mechanism can preserve state oversight while gaining access to the technical expertise needed for meaningful cybersecurity cooperation.

Participation rules remain important for thematic work

Delegations also considered how stakeholder participation should function in the Dedicated Thematic Groups scheduled to meet from 7 to 11 December.

The mechanism will operate two such groups. One will address general substantive issues, while the other will focus on capacity development. Their purpose is to enable more detailed and interactive discussions that build on the work of the annual plenary.

Some delegations argued that, because the thematic groups are informal, they should be able to include a wide range of experts and stakeholders without requiring the same accreditation process used for formal plenary sessions.

Others maintained that the agreed participation modalities for the mechanism should apply consistently across all its formats. From this perspective, applying different rules to the thematic groups could weaken their intergovernmental character or create uncertainty over the status of their outcomes.

The debate highlighted the need for predictable working methods before the December meetings. Clear guidance on participation, expert briefings, meeting formats, and reporting procedures will be particularly important for delegations with limited resources.

Procedural questions shape preparations for thematic discussions

The Chair also announced the appointment of four co-facilitators for the thematic groups, selected from Australia, Egypt, Malaysia, and the Netherlands.

López said the appointments reflected geographic and gender balance and that the co-facilitators would serve in their personal capacities under the principles of neutrality, impartiality, and inclusion.

Many delegations welcomed the appointments as a practical step towards ensuring that preparations for the December meetings could move forward. They viewed the selection of facilitators as consistent with practices used in other UN processes.

Other delegations preferred the appointments to be formally agreed upon by consensus among all member states. They argued that the mechanism’s state-led character requires collective agreement on both procedural and substantive decisions.

The exchange demonstrated that the meaning of consensus will remain an important issue as the new forum develops its institutional practices. The challenge will be to preserve the confidence of all states while allowing the mechanism to carry out the organisational work needed to function effectively.

From general debate to practical cooperation

Beyond the procedural questions, delegations began outlining how the thematic groups could contribute to the mechanism’s wider objectives.

Several countries supported focused, scenario-based discussions addressing concrete challenges such as ransomware, attacks against critical infrastructure, AI security, operational technology, quantum readiness, and post-quantum cryptography.

Others emphasised that the groups should maintain a balanced approach across all five pillars of the framework and avoid prioritising specific topics without the agreement of member states.

Capacity development emerged as a particularly important theme. Developing and smaller states highlighted the role of partnerships with governments, international organisations, industry, academia, and civil society in strengthening national cyber resilience.

Questions of accessibility were also raised. Colombia and Mexico called for simultaneous interpretation to support participation by experts from different linguistic communities, while Mauritius stressed the need for clear rules, timelines, and coordination between the two thematic groups.

These proposals suggest that the success of the mechanism will depend not only on reaching agreements at the diplomatic level but also on translating them into practical cooperation that responds to national needs.

Building consensus in a permanent mechanism

The opening plenary showed that establishing a permanent international forum involves more than adopting a mandate. Member states must also develop shared expectations about participation, decision-making, working methods, and the relationship between formal negotiations and technical expertise.

Despite differing interpretations of some procedures, delegations broadly reaffirmed their support for the Global Mechanism and its objective of strengthening international cooperation on ICT security.

The consensus adoption of the agenda provided a foundation for the substantive work ahead. The Chair also pledged to continue consultations with states and maintain sustained dialogue with stakeholders.

The mechanism’s first session, therefore, represents both an institutional achievement and an early test of multilateral cooperation. Its ability to deliver practical results will depend on whether member states can balance inclusivity, state leadership, procedural predictability, and the consensus principle on which the forum was founded.

As the mechanism moves towards its first Dedicated Thematic Group meetings in December, the immediate priority will be to turn its permanent mandate into working arrangements capable of supporting trust, resilience, and responsible state behaviour in cyberspace.

Track all key moments from the First substantive session of the UN Global Mechanism on cybersecurity on our dedicated page.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

White House launches GOLD EAGLE cybersecurity initiative

The White House has announced the launch of GOLD EAGLE, a cybersecurity vulnerability coordination initiative established under President Donald Trump’s Executive Order 14410, Promoting Advanced Artificial Intelligence Innovation and Security.

According to the administration, the initiative brings together federal agencies, open-source software partners and operators of critical infrastructure to accelerate the identification and remediation of cybersecurity vulnerabilities using AI.

The initiative is being implemented through collaboration between the White House, the Department of the Treasury, the Department of Homeland Security, including the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of War. The administration said GOLD EAGLE is intended to reduce duplicative vulnerability scanning, improve exploit detection and provide prioritised threat and remediation information to government and private-sector defenders.

According to the announcement, GOLD EAGLE has already begun receiving and prioritising reported cybersecurity vulnerabilities from multiple sectors, coordinating verification efforts and supporting remediation activities. The White House said the initiative represents a new operational model for cyber defence that combines government resources with private-sector capabilities to strengthen the resilience of critical infrastructure and software systems.

Why does it matter?

GOLD EAGLE marks a shift towards more centralised public-private coordination of cybersecurity vulnerability management in the USA. By combining AI-assisted vulnerability prioritisation with information sharing across government agencies and critical infrastructure operators, the initiative aims to accelerate the detection and remediation of cyber threats.

It also reflects the Trump administration’s broader strategy of linking AI innovation with national cybersecurity and critical infrastructure protection.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

Spain promotes national cybersecurity support helpline

Spain’s National Cybersecurity Institute (INCIBE) has highlighted its free and confidential 017 helpline, which provides specialist advice on digital security issues for citizens, businesses, professionals and educational institutions.

The helpline provides guidance on scams, phishing, identity theft, compromised accounts, social media privacy, cyberbullying, device security and protecting personal information. It also advises on parental controls, online child safety, digital identity management and the safe use of apps and social media platforms.

INCIBE stressed that 017 is a cybersecurity advisory service rather than a reporting channel or technical support line. Specialists explain appropriate reporting procedures, direct users to the relevant authorities where necessary and assess each case individually.

The service is available daily from 8:00 to 23:00 via telephone, WhatsApp, Telegram, an online form and, by appointment, in person at INCIBE’s headquarters in León.

Why does it matter?

As cyber threats become more common, many users need trusted advice before or after an incident rather than only technical assistance or law enforcement support. Services such as INCIBE’s 017 helpline can help individuals and organisations respond more effectively while improving awareness of everyday cyber risks.

The initiative also reflects a broader shift towards strengthening national cyber resilience through public support services. By combining technical, legal and practical guidance in a single point of contact, governments can encourage earlier reporting, better cyber hygiene and more effective responses to digital security incidents.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

EU expands cybersecurity and resilience support for Armenia

The Council of the EU has officially launched the EU Partnership Mission in Armenia (EUPM Armenia), a new civilian mission under the Common Security and Defence Policy (CSDP) that will help strengthen the country’s resilience against hybrid threats, including cyberattacks and disinformation.

The advisory mission, established in April 2026 at the request of the Armenian government, will initially operate for two years.

EUPM Armenia will provide strategic advice, technical expertise and institutional capacity-building in areas including cybersecurity, foreign information manipulation and interference (FIMI), and illicit financial flows.

The mission will also establish a dedicated project cell to deliver targeted assistance while promoting a whole-of-government approach to tackling hybrid threats. The Council stressed that the mission is advisory in nature and will not participate in Armenia’s national decision-making.

According to the Council, the mission forms part of the EU’s broader strategy to strengthen Armenia’s resilience, democratic institutions and security capabilities while fully respecting the country’s sovereignty and ownership.

The mission follows the adoption of the EU-Armenia Strategic Agenda in December 2025, which identified countering hybrid threats and disinformation as key priorities for bilateral cooperation. Cosmin George Dinescu has been appointed Head of Mission.

EU High Representative Kaja Kallas described the deployment as part of a broader package of political and economic support for Armenia. She said the mission would help strengthen Armenia’s ability to respond to cyber threats, disinformation and illicit financial flows while increasing its resilience to external pressure.

Why does it matter?

The launch of EUPM Armenia reflects the EU’s growing focus on civilian security and resilience alongside traditional defence cooperation. By providing expertise on cybersecurity, disinformation and institutional resilience rather than military assistance, the mission illustrates how the EU is increasingly addressing hybrid threats through governance, capacity-building and technical cooperation.

The mission also highlights the expanding role of cybersecurity and information resilience in international partnerships. As hybrid threats become more sophisticated, governments are placing greater emphasis on strengthening institutions and public-sector capabilities before crises emerge rather than responding after attacks occur.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

EU unveils AI cybersecurity Action Plan

The European Commission has published an Action Plan to address the cybersecurity risks and opportunities created by advanced AI models. Released on 7 July 2026, the initiative sets out a coordinated approach to strengthening Europe’s cyber resilience as AI capabilities continue to advance.

The Action Plan brings together member states, industry and EU institutions to coordinate responses to AI-related cybersecurity challenges. Rather than introducing new legislation, it builds on the EU’s existing regulatory framework while adapting it to risks posed by increasingly capable AI systems.

The Commission says the plan will strengthen defences against vulnerabilities that AI systems may introduce or exploit. It also promotes closer cooperation between public and private stakeholders, reflecting the view that AI governance and cybersecurity must increasingly be treated as interconnected policy areas.

The Action Plan forms part of the EU’s broader strategy to strengthen digital resilience while maintaining technological competitiveness. Its implementation will depend on cooperation between governments, regulators, businesses and cybersecurity organisations across the Union.

Why does it matter?

The Action Plan reflects growing recognition that advanced AI models are changing the cybersecurity landscape by strengthening defensive capabilities while also creating new opportunities for attackers. As AI systems become more capable and autonomous, policymakers are increasingly treating AI safety and cybersecurity as part of the same strategic challenge.

The initiative also reinforces the EU’s broader digital sovereignty agenda. Rather than creating separate policies for AI and cybersecurity, the Commission is integrating the two into a common governance framework. That approach could influence how organisations deploy AI in critical sectors and provide a model for other jurisdictions developing AI cybersecurity strategies.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

European Commission takes four countries to EU court over NIS2 delays

The European Commission has referred Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union for failing to transpose the NIS2 Directive fully into national law.

The Directive strengthens the EU cybersecurity rules and sets common requirements for organisations operating in critical sectors.

Member states were required to transpose NIS2 by 17 October 2024, but the four countries have not notified the Commission of full implementation.

The referrals follow earlier infringement steps. The Commission sent letters of formal notice on 28 November 2024 and reasoned opinions on 7 May 2025.

The Commission is asking the Court to impose financial sanctions, including a lump sum and daily penalties until the countries notify complete transposition.

NIS2 applies to entities in 18 critical sectors, including health, energy, transport and public administration.

The Directive aims to improve national and EU-wide cyber resilience by strengthening risk management, incident response and security obligations for public and private entities.

The Commission said full implementation is essential for improving the EU’s overall resilience and the incident response capacity of organisations operating in critical sectors.

Why does it matter?

The referral shows that the Commission is prepared to enforce cybersecurity law against member states that fail to meet implementation deadlines. NIS2 is designed to create a more consistent baseline of cyber resilience across the EU, but delays in national transposition can leave organisations facing fragmented obligations and uneven enforcement. For critical sectors, consistent implementation is central to risk management, incident response and cross-border resilience.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!