UN Global Mechanism on ICT security shifts towards practical cybersecurity cooperation

The UN’s permanent cyber mechanism continued its substantive work by identifying ransomware, AI-enabled threats, critical infrastructure protection, and capacity development as shared priorities for strengthening international cybersecurity cooperation.

Global Mechanism on ICT security

The UN’s permanent cyber mechanism continued its substantive discussions by identifying shared priorities for international cooperation, with member states highlighting ransomware, AI, critical infrastructure protection, and capacity development as areas requiring practical action.

During the third plenary of the first substantive session of the Global Mechanism on Developments in the Field of ICTs in the Context of International Security, delegations repeatedly stressed that discussions should move beyond mere description of cyber threats to developing practical tools to help states prevent, detect, and respond to them.

The discussion reinforced a trend already visible during earlier meetings, that despite differing national perspectives on specific cyber incidents, broad agreement is emerging on the issues likely to shape the mechanism’s future work.

From identifying threats to supporting implementation

Several delegations argued that the mechanism’s success should be measured by its ability to translate years of international negotiations into practical cooperation.

Kiribati captured this approach by observing that discussions on cyber threats should not end with mere descriptions but lead to concrete measures that enable countries of all sizes to strengthen their cyber resilience. Cameroon and Morocco similarly encouraged the mechanism to prioritise practical implementation through the Dedicated Thematic Groups (DTGs), which are expected to become the forum’s primary venue for detailed technical cooperation.

The emphasis on implementation reflected a broader shift from developing international norms towards helping governments apply them in practice through information sharing, capacity development, and operational cooperation.

Critical infrastructure protection gains momentum

Protection of critical infrastructure emerged as one of the strongest areas of convergence during the session.

Small island developing states offered particularly compelling examples of how digital infrastructure has become essential for national resilience. Kiribati described how its first submarine cable has transformed public services while simultaneously increasing its exposure to cyber risks. Tonga recalled the 2022 volcanic eruption that severed its only submarine cable, leaving the country isolated during a national emergency, and warned that a malicious cyber operation could deliberately produce similar consequences.

Delegations from Australia, Tuvalu, Chile, Ghana, Zimbabwe, and other countries similarly highlighted the growing importance of protecting undersea cables, telecommunications infrastructure, government networks, and other critical systems that underpin economic activity and essential public services.

Rather than treating these as purely national concerns, speakers increasingly framed critical infrastructure resilience as a shared international challenge requiring cooperation across borders.

Ransomware remains a global priority

Ransomware was once again identified as one of the most significant cyber threats facing governments and critical services worldwide.

Delegations described attacks affecting healthcare systems, humanitarian organisations, government institutions, municipalities, telecommunications providers, and energy infrastructure.

National experiences illustrated the scale of the challenge. Tonga described how a ransomware attack encrypted its national health information system, forcing hospitals to return temporarily to paper records. Germany cited estimates placing annual cyber-related economic damage at approximately US$230 billion, while several countries highlighted the growing sophistication and transnational nature of ransomware operations.

Many speakers emphasised that responding effectively will require stronger international information sharing, coordinated incident response, public-private cooperation, and support for countries with more limited cybersecurity capacities.

AI increasingly shapes cybersecurity discussions

AI continued to feature prominently throughout the session as delegations examined its growing influence on the cyber threat landscape.

Countries from different regions observed that AI is lowering barriers to entry for malicious actors while increasing the speed and sophistication of cyber operations. Among the risks identified were AI-generated phishing campaigns, automated vulnerability discovery, deepfakes, large-scale disinformation, and attacks targeting AI systems themselves.

Several delegations also pointed to emerging challenges related to frontier AI models, quantum computing, commercial cyber intrusion capabilities, and digital supply chain security, suggesting these issues should continue to receive attention within the Global Mechanism.

While views differed on how these developments should be governed internationally, there was broad agreement that the mechanism provides an important forum for exchanging experience and improving collective understanding of rapidly evolving technologies.

Capacity development remains central to cyber resilience

Developing countries consistently stressed that discussions on cyber threats should be matched by practical support.

Delegations highlighted the importance of strengthening national institutions, expanding technical expertise, improving incident response capabilities, and ensuring that developing countries can participate fully in the mechanism’s work.

Small island developing states noted that limited resources often magnify the consequences of cyber incidents, while African, Asian, Caribbean, and Pacific countries called for sustainable, demand-driven capacity-building programmes tailored to national priorities. Several speakers also encouraged greater regional cooperation and more structured exchanges of operational experience.

These interventions reinforced the view that improving global cybersecurity depends not only on reducing threats but also on ensuring that all countries have the capabilities needed to address them.

Dedicated Thematic Groups move into focus

Attention also turned to the role of the Dedicated Thematic Groups as the mechanism’s principal vehicle for translating discussions into practical outcomes.

Delegations proposed using the groups for scenario-based discussions, expert briefings, exchanges of operational experience, and the development of practical recommendations on issues such as critical infrastructure protection, supply chain security, ransomware, and implementation of agreed voluntary norms. Several countries argued that the groups should focus on a limited number of concrete priorities that could produce measurable results.

Alongside these substantive discussions, some delegations continued to express differing views regarding state attribution of cyber incidents and recent geopolitical developments. While these exchanges reflected broader international tensions, the majority of interventions remained focused on strengthening cooperation within the Global Mechanism and identifying practical areas where progress can be achieved.

As the session concluded, the Chair confirmed that discussions would continue with the remaining speakers before the mechanism moved to its next agenda item on voluntary norms for responsible state behaviour in cyberspace.

Track all key moments from the First substantive session of the UN Global Mechanism on cybersecurity on our dedicated page.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!