Ambassador Gafoor (Chair)
Good afternoon, friends. Welcome back. The second meeting of the 11th substantive session of the Open-Ended Working Group on security of and in the use of ICTs is now called to order. I apologize for the delay in beginning this session. I was engaged in some informal consultations which took a little longer than expected. The group will now continue its discussion under agenda item 5. We will continue our reading of REV1, or the final report. This morning we began with sections A and B, and this afternoon we will also start with sections C and D, and therefore sections A, B, C, and D are now open for comments. We will begin with the speakers who remain on the list from this morning. The first speaker on my list is Cameroon, to be followed by the Republic of Korea. I would once again urge all delegations to be as brief as possible. If your points have already been addressed by groups in which you are a member, you could simply align yourself with that statement and make any additional specific points that have not been previously already been mentioned. If you have any very specific proposals, bridging proposals, compromise solutions, or better still, if you have a draft of REV2, make that available to all of us. I think that is the spirit of the discussions, that we are looking for solutions, not necessarily in the mode of restating and reiterating your preferred positions. Thank you very much for your understanding. Cameroon, to be followed by the Republic of Korea.
Cameroon
Thank you, Mr. Chair. Mr. Chair, my delegation aligns itself with a statement delivered by Nigeria on behalf of the African Group and commends your leadership in steering this session towards consensus. My delegation welcomes REV1, drafted and published on the 25th of June 2025, and would like to make the following remarks in its national capacity to bridge the remaining divergences. Under threats to ICT security in Section B, my delegation supports Section B’s focus on ransomware, undersea cables, and critical infrastructure in paragraphs 17 to 19. To strengthen this, my delegation proposes the following amendment. In paragraph 24, we propose the insertion of the following: The future permanent mechanism shall prioritize capacity building programs for least developed countries to enhance their resilience against ransomware attacks, including through dedicated technical assistance via the global ICT cooperation portal, referenced in paragraph 55. Regional cooperation frameworks such as the African Union’s mechanism for police cooperation, AFRIPOL, and finally specialized training for national CSIRTs, building on paragraph 52D of this report. This addition provides concrete implementation pathways for ransomware mitigation, directly responding to the threat landscape described in paragraphs 17 to 19 on critical infrastructure protection. On sovereignty and norms in Section D, paragraph 40E, my delegation suggests reaffirming sovereignty as foundational, while recognizing voluntary norms as complementary. The permanent mechanism should facilitate dialogue on harmonizing sovereign rights with cooperative implementation, particularly for developing states. For norm accountability in Section C, paragraph 34P, my delegation proposes establishing a working group to study gaps in accountability, including the feasibility of binding measures for egregious acts, for example, attacks on healthcare infrastructure, with findings reported to the 2030 review conference. Thank you, Mr. Chair.
Ambassador Gafoor (Chair)
Thank you very much, Cameron, for your contribution. Republic of Korea, to be followed by Malaysia.
South Korea
Thank you, Chair. I would like to thank you and your team for your leadership and efforts in guiding us throughout the process. Regarding the threat section, first, we welcome the revision made to paragraph 24 of the report, which reflects more clearly the risks and seriousness of cryptocurrency heists and ransomware. We strongly urge that this language be maintained in the final report. In this vein, I would like to thank Japan for making these points very clear in the morning session. We also welcome the more concrete reference in paragraph 25 to the use of commercially available ICT intrusion capabilities, which aligns with the developments reflected in the third annual progress report. And third, throughout our discussions, we have recognized the usefulness of AI, but we have also stressed that its malicious use can significantly increase cyber threats. In this regard, we welcome paragraph 27 of the final report, which points out that larger language models can lower the barriers to engage in malicious cyber activities, such as malware development and defects. And lastly, regarding the threat section, we have a concern regarding the specific phrase, which is exclusively peaceful purposes in paragraph 15. This phrase has not been part of our discussions, and it is ambiguous. We suggest reverting to the original language or revising the wording for clarity and consistency. For the rules section, Chair, among the voluntary and non-binding norms currently being discussed, we believe that the 11 existing norms as outlined in the 2015 GGE report and endorsed by the General Assembly already enjoy broad consensus and provide a relevant and effective framework for addressing emerging threats. In this context, we would like to express our concerns regarding paragraphs 34 and 36 of the current draft, which leave open the possibility of proposing or creating new norms. What’s needed now is not more norms, but rather a focus on how to implement and operationalize the ones we already have. In this regard, the Voluntary Checklist of Practical Action, including Annex 1, is a valuable tool to facilitate practical and ongoing discussions among states on norm implementation. Regarding international law, first of all, I am pleased to share that the Government of the Republic of Korea released its official position paper on this matter today. You can find our position paper on the OEWG website or our ministry website. As many other states have already stated, our position also confirms the core principles of the UN Charter, such as state sovereignty and the prohibition on the use of force, along with the obligations under international human rights law and international humanitarian law apply equally in cyberspace. Chair, we believe with the rapid pace of technological advancement and the constantly evolving nature of the cyber environment, it is simply not feasible to create a completely new legal system tailored to cyberspace. Instead, we should base our approach on the application of existing international law and not allow specific practices related to the cyber domain to develop progressively through implementation tools, such as the Voluntary Checklist of Practical Action, as well as through the accumulation of national position papers. Regarding IHL, we would like to emphasize the need for clearer and more detailed language in the final report on the application of international humanitarian law. Given that IHL has been a recurring topic of discussion within the OEWG and is reflected in the position papers of a significant number of member states, we believe it is important for the final report to reflect this explicitly. Lastly, we believe some revisions are needed in paragraph 41. Among the six currently listed, some are outcomes of a formal international meeting, while others are just joint statements from groups of states. It is unclear what criteria were used for their inclusion, so maybe the possible listing of documents can be deleted as well. I will stop here. Thank you for your attention, Chair.
Ambassador Gafoor (Chair)
Thank you, Republic of Korea. Malaysia, to be followed by the Kingdom of the Netherlands.
Malaysia
Mr. Chair, we join others in expressing our appreciation for your continued leadership and tireless efforts, bringing us to this 11th and final substantive session of the OEWG. Malaysia is committed to working together with all Member States in ensuring a smooth transition to the future permanent mechanism in the spirit of constructive dialogue and consensus. We are pleased that the overall structure of the REV1 draft has been drawn from agreed language, found in the 1st, 2nd APR, and 3rd APR, and the activities carried out prior to this substantive session. Recognizing these points, we agree with the proposed text in Section A of the REV1 draft. Moving to Section B, on existing and potential threats, Malaysia appreciates the comprehensive overview of threats in this section, reflecting the depth of discussion we have had on this section. Like Mauritius and Malawi, Malaysia supports paragraph 17 on critical infrastructure and critical information infrastructure. Malaysia further joins Qatar, Japan, and Australia in supporting paragraph 24, which highlights concern on malicious software as well as cryptocurrency, currency theft, and the abuse of cryptocurrency to finance malicious activity, which could potentially impact international peace and security. Malaysia joins Indonesia in supporting paragraph 20 and would like to propose realignment of the language in this paragraph, taking into account technical and policy-oriented audiences. We propose the formulation, I quote, States express concern that industrial control systems, ICS, operational technology, OT, 5G networks, the Internet of Things, IoT, cloud computing services, and technologies at the network perimeter, such as virtual private networks, VPNs, firewalls, and routers, are increasingly vulnerable to malicious ICT activities, which could compromise them and have widespread consequences. End quote. Malaysia is also of the view that paragraphs 20 and 29 may be combined as both paragraphs touch upon vulnerabilities that can be exploited for malicious activities. Malaysia further welcomes paragraphs 26 and 27 on the new and emerging technologies, including artificial intelligence and the need to better understand the associated risks. Further, Malaysia joined Mauritius, Ghana, and Singapore in supporting language on the strengthening of cooperation between CSIRTs, including capacity building and public-private partnership in paragraph 32. Malaysia also recognizes the importance of enhancing dialogue on ICT security between different sectors at the national level, including the technical, diplomatic, and legal sector. Finally, Malaysia looks forward to continued exchange of views under the future permanent mechanism on existing and potential threats to the security of and in the use of ICT in the context of international security, as recommended in paragraph 33. Thank you, Chair.
Ambassador Gafoor (Chair)
Thank you very much, Malaysia, for your contribution. Kingdom of the Netherlands to be followed by the United Kingdom.
The Netherlands
Thank you, Chair, for giving my delegation the floor. The Kingdom of the Netherlands fully aligns itself with the statements of the European Union, and I would like to make the following complimentary remarks in national capacity. At the outset, I want to start by thanking you, Mr. Chair, your team, and UNODA for the preparation of the REV1 report, and we continue to constructively work with you and other delegations towards a consensus outcome at the end of this week. As raised by others, we see a strong need to better reflect the balance between implementing existing consensus agreements on the one hand and new proposals that did not achieve consensus on the other. The content and value of the existing normative framework should be acknowledged in full in the final report. Chair, on the overview section, as this report will be the basis for future discussion, it is essential it is based on consensus agreements. In that regard, we propose to add in the last sentence of paragraph 3 a reference to the GGE reports and the 2021 OEWG report endorsed by the General Assembly. In a similar vein, we agree with other States to remove the language on the Chair’s summary and the proposals in the annex, for example, in paragraph 4, as this was explicitly not a consensus agreement. Chair, turning to threats. In the past reports, we have made clear progress in identifying and articulating the range of threats in the use of ICTs. Specifically, we welcome the references regarding malicious ICT activity targeting international organizations and humanitarian organizations in paragraph 21, and the reflection of the in-depth discussion we had in paragraphs 18 and 19. However, we also see room for further improvement, and we will limit ourselves to three paragraphs. First, on paragraph 15, on the notion that ICTs have already been used in conflicts in different regions, we join other UN member states in the call for deletion of “exclusively peaceful purposes,” and support the proposal for alternative language raised by Australia. Lastly, as was raised by Colombia, the Republic of Korea, and others, we welcome the references in paragraph 24 to the risks of ransomware and the notion for a human-centric approach. Paragraph 24 lists several examples of malicious software and cyber attack techniques. As ransomware was specifically raised by many delegations in past years, we ask to dedicate a separate paragraph to it, starting with “states express particular concern over ransomware attacks targeting CI and CII.” The other examples of malicious software and techniques could be included in the following paragraph. We also support the new proposal for a recommendation, as was done by the EU in a statement on ransomware. Then turning to norms, in line with what the Republic of Korea just said, we welcome the recommendation in paragraph 37 on the voluntary checklist of practical action for the implementation of the 11 norms, as this provides states with clear guidance on implementation while also remaining flexible to tailor implementation to specific needs and realities. Second, while we welcome the addition of paragraph 34n, we propose moving the first two sentences to the chapeau of paragraph 34. The first two sentences of 34n reflect consensus language rather than one of the proposals with varying levels of support. The same argument goes for paragraph 34a. In our view, the sub-paragraphs contain too many references to the Chair’s summary of the 2021 OEWG report, which is not a consensus document, as well as proposals that were supported by only a very limited number of states. In that regard, we specifically propose deleting paragraph 34q. As stated throughout this OEWG, my delegation considers that we still have a lot of work to do on norms implementation, including through capacity building. While this does not exclude the possibility of future discussions on additional norms that could be developed over time as agreed in NXC of the third APR, some of the proposals in this REV1 have hardly been discussed, were proposed by a very limited number of states, or are already captured by existing norms. We therefore strongly urge the deletion of paragraph 34r and paragraph 36 in its entirety. Then lastly, turning to international law, Chair. Throughout this OEWG, we have seen a rise in the number of substantive statements on international law. Moreover, in national and regional positions, in cross-regional papers, and side events, as well as in scenario-based workshops, we have clearly moved from the question of whether international law applies to the question of how it applies. And while my delegation recognizes that we do not yet have all the answers, we believe that the substantial progress made should be reflected in the final report. We therefore urge the inclusion of substantive language on the law of state responsibility, international human rights law, and international humanitarian law, as proposed in the cross-regional paper on convergence language. And then lastly, turning to a few concrete proposals. First, we regret the deletion of the final sentence of paragraph 40c on the question of when an ICT operation may constitute the use of force. This additional layer of understanding is widely reflected in national and regional positions and shows concrete progress. We therefore propose reinstating this final sentence. Second, as underlined in the second sentence of paragraph 41, this paragraph focuses on how international law applies to the use of ICTs. In that context, we propose a reference to discussions on international human rights law. In addition, we ask for the deletion of the references to the possibility of additional binding obligations and the latter supported by a very small number of states on a convention, as they do not relate to the question of how international law applies. Since the resolution of the 34th International Conference of the Red Cross and Red Crescent represents a consensus outcome, we believe it merits a separate paragraph. We also propose adding substantive language on IHL from OP4 of this resolution, in particular that, quote, “states reiterated that in situations of armed conflict, IHL rules and principles serve to protect civilian populations and other protected persons and objects, including against the risks arising from ICT activities,” end of quote. Furthermore, in paragraph 42e on capacity building, we propose adding scenario-based discussions after conferences. And then that’s my final point. Lastly, with regards to paragraph 43, we support states that have proposed placing a full stop after the phrase “in the use of ICTs.” Thank you very much, Chair.
Ambassador Gafoor (Chair)
Thank you very much, Netherlands. UK, followed by Germany.
United Kingdom
Thank you, Chair. As this is the first time we’ve taken the floor, we’d like to begin by thanking you and your team for your work over the last five years. The UK reiterates its commitment to working with you and other delegations here constructively to achieve consensus this week and deliver a seamless transition to a future mechanism in March 2026. At present, however, we believe the current draft requires further refinement to achieve the balance necessary for consensus. In particular, the report should more clearly focus on the constituent parts of the consensus framework on responsible state behavior in cyberspace that we have built collectively over many years. At present, the draft gives disproportionate weight to proposals that remain far from broadly supported. If we do not clearly preserve and highlight this shared foundation, we risk setting the future mechanism on an unstable footing, potentially undermining the hard-won consensus that international law applies to state conduct in cyberspace. This leads my delegation to our first point on the threats section. The last sentence of paragraph 15 should be removed for the reasons outlined by a number of states, including South Korea just now. It introduces novel criteria. In paragraph 16, we support the edit made in REV1 with regard to cryptocurrency. The UK also supports the acknowledgment in this paragraph that serious ICT criminal activity could impact international peace and security, thereby bringing such activity in scope for our discussions. This OEWG recognized this by consensus with respect to ransomware in the third APR. In paragraph 20, we would like to add data centers and managed service providers to the list of technology infrastructures. So the sentence would read, states expressed concern that industrial systems, operational technology, 5G networks, the Internet of Things, cloud computing services, data centers and managed service providers, and then continue as currently drafted. This would make the list more consistent with the scope of CII regulation in many states. We’d also support merging this paragraph with paragraph 29 as Malaysia has suggested. We support the addition to paragraph 23 made by Ghana regarding security by design. In paragraph 24, we would like to insert the words including those to the third sentence, so it reads, states expressed particular concern over ransomware attacks, including those targeting CI and CII. We also support the proposal from the EU to make ransomware a standalone paragraph. We support maintaining the last sentence of paragraph 24. We see paragraph 25 as a reasonable reflection of our discussions that also balances a range of positions. Use of commercially available cyber intrusion capabilities by states is subject to the consensus UN framework, including the voluntary non-binding norms and international law. So we should retain these references. We also support improvements recommended by France to this paragraph. We support the REV1 change to paragraph 26, but this could be further improved by adding, and prepare for the migration to post-quantum cryptography at the end of the last sentence. In the middle of paragraph 27, we would like to replace large language models with simply AI. This is because generative models, reinforcement learning agents, and other AI systems beyond LLMs are relevant in this context. In paragraph 28, we support the additional technologies listed in REV1 and their relevance to the security and protection of data. The UK does not support amendments to paragraph 12, and we emphasize that this paragraph is consensus language from the third APR. On norms, we were pleased to see the use of footnotes to cite the wording of the relevant norm throughout this report. However, in the view of my delegation, the norms section does not sufficiently anchor the final report of this OEWG in the existing consensus framework. With respect to paragraph 34n, we would like this paragraph to be incorporated into the chapeau portion of paragraph 34, as a few other delegations have mentioned. This is because the text in 34n is not simply a proposal but is consensus language. Consensus language from the 2021 GGE report referencing the 11 norms should also be added to the chapeau. The combined text added to 34n would read as follows. States recalled consensus resolution 70/237, in which the General Assembly called upon member states to be guided in their use of ICTs by the 2015 report of the GGE, which included 11 voluntary non-binding norms of responsible state behavior, and further recalled that norms do not seek to limit or prohibit action that is otherwise consistent with international law. They reflect the expectations of the international community and set standards for responsible state behavior. States also acknowledged that the work of the OEWG has contributed to strengthening the cumulative and evolving framework of responsible state behavior, which provides a foundation for the future mechanism. Moving on, the UK supports the existing text in 34b, 34c, 34e, and 34f. In paragraph 34h, we would like to replace lawful purposes with legitimate and necessary purposes and is consistent with international law. In 34l, we regret that our proposals for the voluntary checklist of practical actions have not been incorporated. We nonetheless welcome the adoption of the checklist as a valuable output of the final report of this OEWG. Chair, we now wish to address paragraph 34r and the recommendation in paragraph 36. Through your guiding questions, you provided opportunities for states to present their proposals for possible new norms at the fourth, sixth, ninth substantive sessions and the intersessional meetings of December 2022, May 2023, and May 2024. There have been at least six meetings of this OEWG in which the states advocating for new norms have been invited to build support among UN members for specific proposals. Despite the substantial time this OEWG has dedicated to studying new norms, we find it hard to see that any convincing complementary addition to the 11-2015 norms has emerged. As the Netherlands has just noted, Annex C of the third APR and the recommendation in paragraph 35 already recognize that new norms could be developed over time, including under the future mechanism. This is existing consensus and delegations, including my own, have already demonstrated flexibility in this regard. However, the UK strongly objects to the use of the Secretariat’s time and resources to further an exercise that has failed to generate convincing proposals over the 10-year period since 2015, as is proposed in 34R and 36. Current UN80 reforms are a further argument against this. 34R and 36 should be deleted in order to provide more emphasis on implementing the more practical measures emerging from this OEWG, including those in Annex I. On international law, the UK is disappointed that REV1 does not include new substantive content on the additional areas of convergence in our common understanding of international law that have become apparent over the past year. For example, there is a consensus text on the application of international humanitarian law, thanks to the ICRC’s 34th international conference resolution that could have readily been included in this year’s report. Similarly, we are disappointed that the language in the Zero Draft regarding the use of force at paragraph 40C has been deleted for reasons that are not clear to us. We would like this to be added back into the report. The UK is also deeply concerned with paragraph 41. This paragraph should reflect the rich and deep discussions that we have had in the OEWG on how existing international law applies to the use of ICTs. Instead, paragraph 41 conflates existing law with proposals for new law in a deeply problematic way. The UK considers that new legally binding obligations should not be listed alongside topics such as state responsibility and IHL. This is not an accurate reflection of our discussions. Moreover, the UK cannot accept the inclusion of a controversial proposal for new obligations, which is supported by only five states. We welcome the changes made to paragraph 42B, which we considered prejudged our discussions on international law at the Future Mechanism. Finally, Chair, on paragraph 43, the UK does not support the prejudging of international law topics that we will discuss at the Future Permanent Mechanism. Paragraph 43 should simply recognize that we will continue to engage in focused discussions on how international law applies. We’d also like to agree with the points made by a number of delegations in relation to the 2021 Chair Summary and the importance of recognizing GGE reports throughout this report. Thank you, Chair.
Ambassador Gafoor (Chair)
Thank you UK. Germany, to be followed by Albania.
Germany
Mr. Chair, first, we would like to thank you for your and your team’s efforts to move us toward consensus. We align with the statements of the European Union and would like to address in a national capacity a few points in the four sections that have been raised already by colleagues. On the first two sections, first, in line with the EU and also highlighted inter-area by Canada, El Salvador, and Moldova, we see a need to recall and reaffirm the normative framework and the consensus achieved so far in the overview section. Also, as a solid foundation for our future discussion, the suggestion by one state to delete the commitment to implement the UN framework is not an option for us. Second, the threat section should include key issues we are faced with today, like ransomware or the protection of critical infrastructures, as highlighted, for example, by Nigeria on behalf of the African Group, Mauritius, but also Cameroon and Korea this afternoon. Like Canada and the Netherlands, we believe ransomware would warrant an extra paragraph. We are all affected by its consequences, and we believe it might also be a possible example for a topic for a future cross-cutting action-oriented discussion, questioning how norms in international law relate to it, what cyber capacity building needs and tools are there or need to be developed to better address this threat, also acknowledging the role of the private sector in this regard. Third, like a number of other states, the new last part of paragraph 15 is problematic for us, and we suggest deleting it, but would also be ready to support a proposal made by Australia. More generally, also on sections C and D, Germany, like expressed by many others, believes that a clear distinction between the key of the normative framework that we have built collectively over the years and the areas of consensus that we already agreed on during this open-ended working group on the one side and additional proposals that have been made but have not received universal support on the other side is necessary, also to move us toward consensus. We would be in favor of mainstreaming and organizing the whole sections C and D following this logic, also with regard to the recommendations. Mindful of time, just a few examples that have already been raised by colleagues and there can be proof. First, on paragraph 34n, we believe it’s under the wrong chapeau. For us, it’s clear that the first sentences are not a proposal with varying levels of support, but they are consensus language. Second, the chair summary annexed to the 2021 open-ended working group report that has been mentioned by colleagues and which is not a consensus document. Third, we believe it is up to the future mechanism to decide on whether to take on the potential development of new voluntary non-binding norms, considering the comprehensive set of expectations already in place and therefore ask for a deletion of 34q and r, as well as para 36. Finally, paragraph 41 is a mix of very different papers that was just explained by the UK colleague, national positions, and non-consensual proposals for future formats for discussion. We therefore suggest dividing it and taking out from recommendation para 43, references to non-consensual proposals. A last point on one area where focus has been made and where we also had extensive discussions here with a number of cross-regional working papers. We would very much welcome a clear reference to the applicability of international humanitarian law and an inclusion of relevant language, which would be op4 of the ICRC consensus resolution adopted last year. Thank you, Chair.
Ambassador Gafoor (Chair)
Thank you, Germany, for your statement. Albania, to be followed by Fiji.
Albania
Thank you, Chair, for giving me the floor. As this is Albania’s first intervention, I wish to commend you and your team for your excellent leadership in advancing the work of this Open-Ended Working Group. I am happy to be here as part of the Women in Cyber Fellowship, thanks to the Netherlands. I am happy to be part of a group of women of this fellowship who have a strong voice and give a tremendous contribution to the UN discussions on cybersecurity. Albania supports the EU statement presented at the Open-Ended Working Group and presents this statement in its national capacity. Albania has reviewed the REV1 draft and considers it a good foundation for constructive discussions, keeping in consideration that we should conclude on a report that recognizes the work done by the international community so far. Our aim is to contribute actively to the Open-Ended Working Group mission and advance global peace in cyberspace. We believe this forum is uniquely equipped to reconcile different views and chart a path forward. Albania stands firmly behind efforts to foster a cooperative framework in the cybersecurity dialogue, recognizing that such progress depends on the collective state commitment. We support every effort which leads toward a report that would allow a future permanent mechanism which would face real challenges of cybersecurity in today’s world. We welcome the true reflection of the threat landscape, acknowledging this is the basis of our discussions on responsible state behavior in cyberspace and the implementation of the UN framework in this regard. The threat of misuse of cyber operations, whether by state or non-state actors, is growing more urgent. We would like to highlight a matter of paramount importance, as Albania reiterates its deep concern over the continued pattern of malicious cyber activities attributed to state-sponsored actors which have systematically targeted democratic institutions and civilian infrastructure. A notable escalation occurred in Albania in July 2022 when a destructive cyber attack assessed to have originated from Iranian state-linked actors severely disrupted a wide range of government digital services. This incident was the first of a broader and ongoing campaign followed by subsequent cyber operations, including multiple intrusions throughout this period. The most recent attack happened on June 20, 2025, when the IT systems of the municipality of our capital city were breached and the normal functioning of public services was disrupted. The attackers publicly claimed responsibility. Such coordinated actions, whether conducted by or on behalf of a state, reflect a deliberate strategy to challenge sovereignty, weaken institutional integrity, interfere with the normal functioning of democratic societies, and reflect a persistent and evolving threat landscape. We urge member states to reaffirm their commitment to the principle that no state should itself or should allow its territory to be used for malicious cyber operations. Member states should support the development of a framework that ensures appropriate consequences for those responsible. Albania therefore calls upon the Open-Ended Working Group to allow for a future mechanism which would explicitly recognize the cyber attacks directed at democratic systems and civilian infrastructure to be incompatible with international law and require the establishment of effective accountability mechanisms. In closing, Albania reiterates its strong support for the OEWG’s mandate and underscores its commitment to work constructively to ensure a smooth transition for the future permanent mechanism to advance transparency, stability, and trust in cyberspace, and to strengthen the resilience of democratic institutions against evolving cyber threats. Thank you, Chair. Thank you.
Ambassador Gafoor (Chair)
Thank you very much, Albania. Fiji, to be followed by Israel.
Fiji
Mbule Winaka Chair, dear colleagues, and dear friends. Fiji aligns itself with the Pacific Islands Forum statement and provides the following in our national capacity regarding sections A and B of REV1. Firstly, Chair, Fiji thanks you for your leadership in our OEWG journey, and we’d like to reaffirm our commitment as we lead to the conclusion of this week. With regards to section A, Chair, Fiji welcomes paragraphs 9 and 12 regarding the need for more to be done to bridge the digital divides and the gender digital divide and echoes the statements by Australia, Mauritius, Moldova, and a number of other states and also refers to the working paper on gender and the permanent mechanism which Fiji has co-drafted and which is supported by a large number of states. Fiji also welcomes text recognizing the many cyber threats already impacting member states, especially impacting our critical infrastructure and critical information infrastructure, and the text on the discretion of states to designate their critical infrastructure and critical information infrastructure, which is an area of priority for Fiji, and we welcome collaboration in that regard. With regards to section B, Chair, Fiji welcomes text on new and emerging technologies such as artificial intelligence, 5G, and quantum computing, as there is an urgent need to enhance common understanding amongst all states on the opportunities and the risks of these new and emerging technologies, and this has also been referenced by a number of delegations. Chair, data shows that in our region in the first four months of this year, threat actors have publicly claimed almost one cyber extortion attack per month compared with an average of one every four months over the previous two years, and we note that in reality, this number may be higher. Therefore, we support the calls for a dedicated paragraph on ransomware and welcome the text of the human-centric approach in paragraph 24, as has been echoed by delegations. Fiji also supports proposals by the European Union and the African Union and supported by other delegations regarding subsea cable infrastructure, the text amendment proposed by Malaysia and the UK on paragraph 20, the proposal by Ghana regarding paragraph 23 on incorporating security by design, and the text proposal by France for paragraph 25. Finally, Chair, Fiji welcomes the reference to the need for strengthened cooperation between CSIRTs and private-public partnerships in paragraph 32 to combat these cyber threats that we’re facing, and this has also been echoed by a number of delegations. Thank you, Chair.
Ambassador Gafoor (Chair)
Thank you very much, Fiji. Israel, to be followed by Pakistan.
Israel
Thank you, Chair, for the floor. As this is the first time my delegation takes the floor during the 11th round of the Open-Ended Working Group discussions, Israel wishes to congratulate and thank you and your team for the commendable efforts up to this point, which, if we all do our part during this week, could bring us to a report that will hopefully be adopted by consensus and pave the road for a seamless and smooth transition into the future mechanism in our institutional dialogue. Mr. Chair, in line with your guidance in our agenda, allow me to briefly share a few suggestions we have for the Sections B and C of REV1. There are, however, other very important issues that we intend to address later on in our deliberations. Mr. Chair, in paragraph 15, we would like to support the comments of the EU, made by the EU and the U.S., Australia, and others, that the language of for exclusively peaceful purposes should be omitted. In the spirit of compromise, we suggest replacing the language for purposes exclusively in line with the principle of the UN Charter. This amendment better reflects, in our view, the appropriate scope of purposes that ICT capabilities should be employed for. We could also support the language proposed by Australia to amend this paragraph. In paragraph 16, keeping in line with the new language added at the end of paragraph 16, which refers to the possibility that criminal activities may impact international peace and security, it is important to add identical language to the threat posed by terrorist groups, which undoubtedly reflects an equal, if not greater, risk to global peace and security. In response to comments by other delegations and in the spirit of constructive dialogue, we suggest adding may or potential before making reference to threats to international peace and security where appropriate. As for paragraph 17, in order to keep consistent with agreed language, we suggested adding the word malicious before the words ICT attacks. In paragraph 25, the word particularly suggests that the use of ICT capabilities in a manner that is consistent with the framework for responsible state behavior could, nonetheless, contribute to a threat to the international peace and security. This surely isn’t the notion we are suggesting, and this could be easily amended by deleting the word particularly. Additionally, we request that the word illegitimate be added before dissemination in order to keep the language of this paragraph consistent with paragraph 34H in section C. On a final and more general note, as other delegations have commented, the reference made in section B to emerging technologies, such as AI and quantum computing, is overly detailed and overemphasizes the risks, rather than the opportunities that these technologies may provide. It also gives an incorrect impression that we have thoroughly discussed these issues, an impression we would not carry onto our work in the permanent mechanism. Therefore, we find it appropriate that these areas of text be shortened and recalibrated to reflect the promises these technologies may hold. We will provide these comments in writing to the chair and his team as well. As for section C, Mr. Chair, in the zero draft paragraph 34C included an explicit reference to non-state actors. This reflects the reality that often it is these actors that conduct malicious ICT activities from the territory of one state against a third party. This acknowledgement is important, reflects our discussions previously, and is consistent with other paragraphs that explicitly reference to non-state actors. Therefore, we suggest adding the words including by non-state actors between two commas after the words internationally wrongful acts using ICTs in paragraph 34C. In paragraph 34H, a reference to lawful purposes has been added. This new language may create ambiguity, as the law does not always spell out what purposes are lawful, but rather prescribes rules of conduct. It is true that the former language referred only to international law, yet this could be reminded in the clearer and preferable way by replacing these words with consistent with domestic and international law. As for paragraph 24J that deals with inter alia the sharing of information between the public and private sector as well as between states. Although we fully support the sharing of information between stakeholders, we would also acknowledge the challenges that the states may face in this regard due to a myriad of reasons ranging from domestic law to the lack of technical capacity. Therefore, we suggest adding the words as deemed appropriate after the words as well as with the involvement of relevant stakeholders. I thank you, Mr. Chair.
Ambassador Gafoor (Chair)
Thank you, Israel, for your statement. Pakistan to be followed by Ukraine.
Pakistan
Thank you, Chair. I have asked for the floor to make a few brief points. First, to express our profound appreciation for your dedication and professionalism, which I believe is recognized by everyone. Second, the geopolitical environment in the past five years has discernibly worsened, impacting the ICT landscape and its implications for global peace and security. Despite a shared comprehension of our collective work, global cyberspace continues to evolve as an emerging rather than established arena of conflict. We would have wished these concerns were better reflected in the draft report. Third, the Chair’s revised draft report provides, in our view, a good basis to achieve shared objectives. We, like other delegations, have several proposed amendments in the draft report for it to better reflect our concerns and priorities. However, while doing so, we should remain cognizant of our overarching goal to arrive at a consensus report, which is already the least common denominator of our international understanding. In this spirit, we would strive to make as minimal interventions as possible and allow your efforts to forge consensus and contribute wherever required. Chair, I would like to briefly outline some feedback on the revised text. In para 15, we support the reference to exclusively peaceful purposes. In the same para, we’ll request bringing back the language of the zero draft on ICTs in conflict situations. In para 16, we support the impact on international peace and security reference. In para 25, we support the addition of appropriate safeguards and oversight efforts, but would propose to add “within the United Nations” at the end of it. We also support the reference to cryptocurrency in para 24 and post-quantum cryptographic solutions in para 26. We need to maintain a balance between applications of international law and norms, particularly on the possible new norms, legally binding instruments, or a combination of these approaches. Lastly, we believe that the progress achieved in the OEWG should be preserved and must not be allowed to relapse. Therefore, the only acceptable way forward is to continue future discussions on the security of and in the use of ICTs under the UN auspices. I thank you, Chair.
Ambassador Gafoor (Chair)
Thank you very much, Pakistan, for your contribution. Ukraine, to be followed by Ireland.
Ukraine
Thank you, Chair, and thank you for all the efforts of you personally and your team throughout the process and with compiling a comprehensive final document. As a starting comment on the draft final report, Ukraine stresses the importance of adoption of the report that would not be detrimental to our work in this Open-Ended Working Group. In relation to Sections A and B, Ukraine fully aligns itself with the statement delivered by the European Union. Now our delegation would like to make some additional remarks in our national capacity. In relation to Para 12, we welcome the mention of the increasing level of meaningful participation of women in the work of the OEWG and the related decision-making processes, as we believe it makes the process itself a better balanced one. Our delegation positively notes the inclusion of the UN framework in Para 13, but we would recommend further emphasis on this issue throughout the document, primarily in Paragraphs 7 and 8. We welcome the comprehensive reflection of current cyber threats, which provides an essential basis for advancing responsible behavior in cyberspace. In Para 15, we note that the nature of the ICT determines the possibility of its use for self-defense purposes in accordance with Article 51 of the UN Charter, which does not lift the obligation of the states to protect civilians from the consequences of malicious cyber operations. In this respect, we believe that the compromise line here could be a mention of using the ICT in compliance with international law. Section C and D. In relation to Paragraphs 34R, in line with what was already mentioned by some other countries, Ukraine considers as premature the discussion over the new proposals for norms on top of the 11 voluntary non-binding norms of responsible state behavior in cyberspace that are already in place. We suggest continuing and succeeding with the implementation of the existing 11 norms, and we suggest to put no pressure on the Secretariat regarding the circulation of the list of proposals that is to exclude Para 36. In this respect, we also note that the effective implementation of the norms by the states within the already existing international legal framework should and must precede a possible new international legally binding document in that regard. It is the issue of the will to implement and the responsibility in the first place. A binding document is not the magic pill. We all currently observe the unjustified military aggression against Ukraine lasting for over three years, which was conducted by a UN Security Council member against another UN member state with full disrespect of the provisions of the already existing legally binding multilateral documents. Therefore, in relation to Para 41, we cannot accept any language tasking any kind of group or structure within this final report or the future permanent mechanism for developing a binding multilateral document prior to a successful implementation by the states of the already existing UN framework. Having said that, we suggest revising the language to ensure that discussions should not only focus on cooperation but also on implementing the UN framework. We remain committed to working constructively towards achieving a positive outcome of this session. Thank you, Chair.
Ambassador Gafoor (Chair)
Thank you very much, Ukraine, for your contribution. Thank you very much. Ireland, to be followed by Czechia.
Ireland
Thank you very much, Mr. Chairman. As this is the first time that I have intervened at this session, I would like to, as many others have, thank you for all of your hard work and that of your team over the course of the years of this process. We would align with the intervention of the EU. I thought that your own summary at the start of this meeting was very helpful, particularly your highlighting of the UN Normative Framework and the need to focus on what has been agreed by consensus over the course of the OEWG. In this regard, the UN Framework of Responsible State Behaviour must be at the core of our work in moving forward this process and indeed underpin our future permanent mechanism. As with Argentina, we recognize the importance of capacity building in this process and in the future permanent mechanism. Turning to threats, Ireland welcomes the progress that states have made under the threats pillar, particularly in recognizing the devastating impact of ransomware and spyware on a global level. In this regard, we feel that ransomware can be further strengthened in the text, as has been proposed by the EU and a number of other states already. Regrettably, over the course of the OEWG, we have seen a deteriorating security environment, increasing use of ICTs in armed conflicts, and the breach of the consensus-agreed UN norms of responsible state behaviour. We must acknowledge the proliferation of state and non-state actors using cyber capabilities for disruptive and offensive means. In this regard, in paragraph 15, we would oppose the reference to exclusively peaceful uses, which does not reflect the reality that ICTs are being used in conflicts already. In this regard, we can support the Australian proposal on paragraph 15. Today’s cyber criminals are better organized, have more developed capabilities, and are more sophisticated in their approach than ever before. And we must recognize this. We welcome the language on critical infrastructure and support the mentions in the AU statement and many others, most recently I think Fiji, on the importance of CI and CII in this text. Ireland strongly condemns cyber activities that target healthcare facilities, which is a breach of the UN norms. In paragraph 17, in that regard, we support the highlighting of vulnerable sectors, particularly healthcare and maritime. Turning to the norms of responsible state behaviour, we supported and were encouraged by the consensus development of the UN normative framework for responsible state behaviour in cyberspace. This agreement was a major achievement in our collective path towards a global, open, secure cyberspace. We strongly support the voluntary checklist that has been developed as an effective capacity building tool for states, demonstrating the value of sustainable capacity building initiatives. We also welcome in section C, paragraph N, the clarification on the appropriate role that norms play in the UN framework and the important reiteration that norms do not replace or alter states’ obligations or rights under international law, which are binding. We have, in regards to many of the new norms that have been proposed, as others have previously mentioned, we feel that there has not as yet been sufficient substantive discussion on these, and therefore we would suggest that the emphasis of the four paragraphs on new norms seems out of step with the discussion of the OEWG. We would therefore propose to merge 34O to P and delete 34Q and OR, as all of these paragraphs articulate the same point. This would also help to streamline the document. We would also mention that the recommendation in paragraph 36 on the same lines perhaps might be premature, and so we’d suggest a deletion of that paragraph. On the capacity building, we feel – sorry, apologies. Turning to legal, I think that many very good points have already been made. We could agree with the proposals that were made, particularly by the Dutch, but also some of the ones that were proposed by the Germans and the UK on legal matters. We think that at the moment the balance here is not right. As many others have mentioned, we have had a great deal of discussion on international humanitarian law over the course of the OEWG. We feel that this is not as yet reflected in the text, and we would feel that there is a good deal of change to be made in this section. But in the interests of brevity and the fact that many of these points have already been made, as mentioned by other states previously, I will leave it at that for the moment. Thank you.
Ambassador Gafoor (Chair)
Thank you very much, Ireland, for your contribution. The Czech Republic will be followed by Costa Rica.
Czechia
Thank you, Mr. Chair. The Czech Republic fully aligns itself with the statement delivered by the European Union and wishes to add the following remarks in its national capacity. First of all, let me commend all your and your team’s tireless efforts throughout the entire OEWG process, and now particularly on the final report, driven by a vision to reflect as much as possible the wide range of views expressed by Member States and to find an acceptable balance between them. And that is not easy. As we approach the conclusion of the OEWG’s mandate, the Czech Republic believes that consensus must remain the foundation of our collective work, while preserving the fundamental elements of what the UN is based on, and also while preserving what we have already achieved, as you rightly mentioned, Mr. Chair, in your opening remarks. And we have already achieved a lot. Now let me make a few remarks on the specific parts of the report which we are now discussing, meaning the first four parts. On the overview, we welcome how it covers our previous discussions, mentioning not only the OEWG reports but also the GGE reports, because all of those discussions provided grounds for where we are now, as was mentioned, for example, by Japan and other delegations, and it is important to include that in the report. In the same vein, we would like to support the Netherlands, the United Kingdom, and others who propose to add links to other important GGE documents which are still missing from the report. On Chapter B on threats, we appreciate the inclusion of key concerns, such as cyber operations targeting healthcare in Para 17, or the growing impact of ransomware in Para 24, as highlighted also by Colombia and many other states, and including the emphasis on a human-centric approach to it in Para 24, as mentioned, for example, by Fiji, and also the risks posed by emerging technologies in Para 27. This inclusion is crucial, as we are all struggling with these threats, and that is why we should also focus on capacity building in this respect, as mentioned, for example, in Para 32, which we welcome. And that is also why we should direct our cross-cutting discussions that way in the future permanent mechanism, and why we see a high merit in involving the private sector in such discussions, while not disputing, of course, the intergovernmental character of this process, but the private sector has the expertise which we, as the governments, do not have, obviously, and therefore is irreplaceable and very valuable for us. On the specific wording in this section, we would like to propose just two minor adjustments for clarification purposes in Para 15 and 25. The last sentence of Para 15, in that sentence, we propose to delete the words for exclusively peaceful purposes and replace them with in compliance with international law, as mentioned just a while ago, for example, by Ukraine, and we could also support the proposal by Australia, voiced earlier this morning, which goes in a similar direction. And likewise, in the last sentence of Para 25, we propose replacing the words for lawful purposes with in compliance with international law. On Chapter C, norms, the Czech Republic has consistently emphasized that priority must be placed on the implementation of norms which have already been agreed by consensus, and we would strongly caution against introducing new norms, especially those that have not been thoroughly discussed within the OEWG, as this risks undermining the focus on practical application, which is crucial. In this regard, we note with concern Para 34P of the draft report, which suggests that norm development and implementation can proceed in parallel, and it is precisely because we place such emphasis on implementation, we welcome the inclusion of the voluntary checklist of practical actions, just as it was mentioned by the Republic of Korea and some other states. We fully support this tool as a practical means to guide national efforts and promote shared understanding. While we generally welcome all suggestions for improvements, we do not see the suggestion contained in Para 36 to compile and circulate to delegations a non-exhaustive list of proposals to be based on previous discussions. For this reason, we join numerous other delegations and request its deletion. And in the last sentence of Para 34H, for the same reasons explained, for example, by Israel, we propose replacing the words for lawful purposes with in compliance with international law. And finally, on section D on international law, we would like to thank you for taking into account some of our comments, including in paragraph 39Bii, which in our view has improved. However, the broad substantive discussion on this topic has not yet been adequately reflected, and we would like to see further elaboration on this matter, in particular in relation to international humanitarian law. Similarly, we appreciate the inclusion of additional important documents and initiatives in Para 41. However, due to these additions, the paragraph now appears somewhat difficult to navigate, and we therefore propose splitting it into sub-paragraphs in line with what was suggested by Germany, and grouping the references according to their origin. And speaking about Paragraph 41, we also request the deletion of the notion possibility of additional legally binding obligations, as we do not see there has been consensus on this topic. And for the same reasons, we would also request deleting the reference to the General Assembly document A-77-984. And just like many others, we also regret that the last sentence of Para 40C from the zero draft has been removed, as we believe it constitutes an essential substantive addition, and we therefore request its reinstatement. Mr. Chair, the Czech Republic is fully committed to listening to other states and to reaching consensus by the end of this week. And we would like to conclude with the belief that we are all here to work toward an agreement on a practical, action-oriented, and inclusive future mechanism, with a high focus on capacity building and on putting the existing normative framework into practice, also through international cooperation. And we should all do our best to reach that goal. Thank you.
Ambassador Gafoor (Chair)
Thank you very much Czechia. Costa Rica to be followed by Brazil.
Costa Rica
Thank you, sir. Costa Rica appreciates your leadership in this final stage of the process. We appreciate the inclusiveness and transparency with which you have guided the work of the Working Group, and we recognize the effort reflected in the revised version of the report. Regarding Section A, we highlight the way in which the text recognizes the key role of international cooperation in building an open, secure, stable, accessible, peaceful, and interoperable ICT environment. Capacity building not only complements but also enables the effective implementation of standards, confidence-building measures, and international law, and is a priority for countries facing structural challenges in developing their national capacities. Regarding Section B, we believe it is right that the text identify ransomware as a significant and expanding threat, in line with the concrete experience of countries such as Costa Rica, where this type of attack has seriously affected essential public services. We also welcome the fact that the text recognizes the new risk factors associated with emerging technologies such as generative artificial intelligence and quantum computing. Mr. Chair, we echo, as was mentioned by the delegation of Mauritius in support of El Salvador, Moldova, Colombia, and others, on the equal and meaningful participation of women in decision-making processes related to the use of ICTs in the context of international security. Finally, we join the call expressed in the room to work with flexibility and constructive spirit, with the objective of adopting a consensus report that reflects the collective progress achieved. Multilateralism, as this group has demonstrated, remains the indispensable framework for addressing the global challenges of cyberspace. Thank you very much.
Ambassador Gafoor (Chair)
Thank you very much, Costa Rica, for your contribution. Brazil, to be followed by Cuba.
Brazil
Thank you very much, Mr. Chair. My delegation would like to express its appreciation to you and your team for your work throughout this process, in particular for this REV1, which we believe is a very good basis for our continued discussions, and though of course with some room for improvement, is very successful in balancing some diverging and sometimes conflicting positions on this issue. Turning to the overview, my delegation appreciates the due recognition given to cooperation and capacity building and would like to see that remain. We also would like to see the retention of paragraph 12, language on gender and women, which we highlight is the same wording as the one adopted by consensus in the third APR, so we would like to see that remain. On paragraph 13, we also join other delegations in asking to have the reference to the GGE reports, which are part of the UN, a key on the security of and in the use of ICTs, and as others have mentioned, we highlight that these reports were endorsed by consensus General Assembly resolutions. Our future work should build upon what we have already achieved, and that includes the GGE reports. On threats, we agree with El Salvador on reverting the language on paragraphs 15 and 16 to that of the zero draft, which we believe better reflects the delicate relationship between ICT criminal activities and ICT activities that amount to threats to international peace and security. We support, however, the Swiss proposal to add at the end of paragraph 15, a sentence on the protection of civilian populations and situations of conflict. Furthermore, on paragraph 24, we align with the proposals made to have a separate paragraph specifically on the issue of ransomware, given the prominence of this threat currently, and can support the language that has been put forward by other delegations. We also appreciate the changes made to paragraph 25, particularly regarding the use of the adjective irresponsible, which we believe is better defined in the current wording. We are, of course, willing to work with delegations on further refining the language, as long as we are mindful to keep any references to it within the mandate of this group and what was actually discussed on the issues. Moving on to norms, on paragraph 34, we can support the UK’s proposal on adding more, a stronger, clearer reference to the 11 norms and responsible state behavior on the chapeau of that paragraph, lifted from the previous OEWG’s final report. And moving on to international law, on 40C, we would also support inserting the last phrase from the zero draft on definitions of use of force, and also would like to reiterate a proposal we made in previous town halls to have an additional subparagraph under 40, that is based on the ICRC humanitarian resolution, which would then read, states further recalled that in situations of armed conflict, IHL rules and principles serve to protect civilian populations and other protected persons and objects, including against the risks arising from ICT activities. These are our remarks for now. As you and others have stated, our final week of negotiations takes place in a challenging geopolitical environment. We, however, have succeeded in reaching consensus in other challenging circumstances before, and remain confident that guided by your able leadership and our collective goodwill and flexibility, we can reach a consensus outcome once again. Thank you.
Ambassador Gafoor (Chair)
Thank you very much, Brazil, for your statement. Cuba, to be followed by Vietnam.
Cuba
Thank you very much, sir. I shall refer to Section C and D of the draft report, and here, in addition to what was stated by the delegation in Nicaragua on behalf of the group of countries sharing ideas related to our common view on international norms and law, I should like to propose the following. We support maintaining P, Q, and R of Paragraphs 34 of Section C on norms. In Section D on international law, we like deleting the reference to unacceptable use of force, which was in the zero draft of the report, as there were controversial documents which were not discussed within the context of the OEWG. However, looking at Paragraph 41, we still see references to questions where there is no consensus in the OEWG, such as the references to international law, IHL, international humanitarian law, be that directly or indirectly, by means of the reference to documents that were drawn up beyond the framework of the OEWG and which are not universally accepted. We would like to stress that we want to see the dilution of any reference which could be kindred with the notion defending the applicability of IHL to cyberspace, and therefore, this could lead to unacceptable interpretations seeking to legitimize this sphere as another one of war. We suggest re-wording the second paragraph of Paragraph 42, sub-paragraph D, so that it should exactly reflect what happened in the OEWG, taking into account that not all the national or regional positions distributed to the working group were discussed in this framework. Thank you very much, sir.
Ambassador Gafoor (Chair)
Thank you very much, Cuba. Vietnam to be followed by the European Union.
Vietnam
Mr. Chair, at the outset, Vietnam would like to extend our appreciation for the continued leadership and great efforts of you and your team in preparing the draft of the final report. We also commend the initiative to convene the town hall meetings, which have served as an inclusive platform to exchange views and promote greater understanding among members and stakeholders. Vietnam supports the adoption of the final report by consensus. Despite ongoing differences in perspectives among member states, the OEWG process has seen meaningful progress across various thematic topics. We believe the final report should reflect all these achievements. It should avoid overly detailed and divisive elements that risk undermining consensus, and instead aim to address shared concerns and priorities. The report must clearly outline areas of convergence and consensus, while also comprehensively reflecting the wide range of views expressed during the group’s discussions. In this vein, we would like to make the following comments on the first two sections in the draft 1 of the final draft. Regarding Section A, we echo the emphasis by previous speakers on capacity building, which is essential for countries, especially developing ones. We stress the pressing need to put capacity building initiatives proposed during the OEWG into operation, even as pilot programs, to address the growing needs of developing countries in strengthening resilience and ensuring ICT security. Delaying action until a fully completed framework is in place risks missing critical opportunities to respond to emerging ICT threats. To reflect this view, we would like to make two small amendments to paragraph 8 and paragraph 9, which will be provided to you in writing later. On Section B, we support the current revised draft, which has identified existing and potential ICT threats. We believe this section provides a good basis for discussion in the future permanent mechanism. Mr. Chair, our delegation would now like to turn briefly to Section D on international law. The group discussions on this topic have been significantly enriched by a wide range of national and regional positions on how international law applies in cyberspace. We believe the final report should reflect the areas of convergence among these positions. We would also like to see clear reference to the application of some areas of international law, particularly state responsibility, human rights, and international humanitarian law in the final report. In this regard, we thank you and your team for updating REV1 with the working paper entitled Application of International Law in the Use of ICTs, Areas of Convergence by a Cross-Regional Group of States to which Vietnam is a member. We support the recommendation in the final report to continue the discussion on international law in the future permanent mechanism, where states are encouraged to share their national views and positions. We believe that the mechanism should capitalize upon the convergence among national positions by promoting progressive codification of international cyber law. This could result in a concrete outcome, such as a guideline, declaration, or a set of understandings on the application of international law in cyberspace, which will certainly contribute to the maintenance of international peace and security and promotion of an open, secure, stable, accessible, and peaceful ICT environment. I thank you for your attention.
Ambassador Gafoor (Chair)
Thank you very much, Vietnam, for your statement. European Union to be followed by Côte d’Ivoire.
EU
Thank you, Chair. I have the honour to speak on behalf of the EU and its member states, the Canada countries, North Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia and Herzegovina, and Georgia, and the after country, Norway, member of the European Economic Area, as well as San Marino, align themselves with this statement. That means 37 states, as said before. Please allow me to come back to what I said earlier today. We should not allow this report to lose the progress we made on the UN framework, including the 11 voluntary non-binding norms of responsible state behaviour. We should not lose it by putting an emphasis on new proposals, which have not been properly discussed, rather than focusing on the further implementation of existing norms. Moreover, the Russian intervention earlier today shows that we actually are even at risk of losing our work on the framework altogether, with Russia wanting to just observe it, rather than express its commitment to it. And again, I really ask everyone in this room to think about what that would mean if states would not feel themselves restrained by the UN framework of responsible state behaviour in cyberspace. Particularly on norms, to date, the Open-Ended Working Group discussions on new voluntary non-binding norms have been limited in scope, and the proposals made could be covered by existing norms or would fall outside of the scope of the Open-Ended Working Group mandate. Also, we have not had sufficient substantive discussions on new norms, and therefore the emphasis of four paragraphs on new norms seems out of step with the discussion of the Open-Ended Working Group. We therefore propose to merge 34O to P and delete Q and R, as all of these paragraphs are duplicatory and as these articulate actually the same point. We also call for the deletion of the repeated references to the chair summary annexed in the 2021 Open-Ended Working Group reports, as just this chair summary is not a consensus document. Further, to compile a list of new norms is premature. Not only are most states, including EU member states, still focused on implementing existing norms, which we consider to be a comprehensive set of expectations for responsible state behaviour in cyberspace, the discussion on potential development of new voluntary non-binding norms is something for the future permanent mechanism to decide whether to potentially take on, considering the current level of discussions in this Open-Ended Working Group, the already existing consensus language on these issues, which you can use for the final report, and as we are negotiating this final report right now. We therefore request the deletion of paragraph 36. We stress that, reflecting the overwhelming appetite of states in this process, we need to keep our focus on the implementation of the existing set of norms and provide capacity building to effectively do so, as well as identify on that basis any gaps before considering whether new norms are actually necessary. Regarding the implementation of norms, we welcome the recognition of the value of the whole of government coordination in paragraph 34b. Further, with regard to implementation, we welcome paragraph 37 of the adoption of the voluntary checklist of practical actions for the implementation of norms. It functions as a reference for states working to implement the norms, and we would further support the identification of related cyber capacity building needs in this context. We also look forward to using it ourselves. Let me turn to international law. Over recent years, the international community, repeatedly in the Open-Ended Working Group, as well as in the UNGA, has affirmed that international law applies in cyberspace. This affirmation has allowed us to make progress, detailing how international law applies and furthering international security and stability. The Open-Ended Working Group has taken important steps to clarify how international law applies and to ensure that states uphold their legal obligations in this context. Many working papers have been put forward, including on the application of IHL, such as the cross-regional working paper submitted by Switzerland and 12 other states, presented by Senegal in March 2024 and IHL, and the cross-regional working paper on the application of international law and the use of ICTs, areas of convergence, submitted on behalf of a number of countries across regions from 21st of May 25, also preferred just now by Vietnam. Also, with the declaration of the EU and its member states in 24, on a common understanding of the application of international law to cyberspace, as well as the common position of the African Union in this context, over a hundred member states have now individually or collectively published their position and views on the application of international law. We see this as significant progress by the current Open-Ended Working Group and a milestone, because it has brought not only further clarity on how international law applies, but also enabled us to identify common ground, common ground that we feel needs to be reflected in the final Open-Ended Working Group report. It simply cannot be that all the efforts to further and implement UN consensus on international law is placed at the same level as non-consensual proposals by individual states advocating for a new legally binding instrument, which is not the sole solution to addressing cyber threats, and we all know this. We do not think it’s appropriate to move away from the UN framework for responsible state behaviour and therefore do not see room for the reference to the letter with the Russian proposal in paragraph 41, particularly since this paragraph relates to how international law applies, and even more so as this has not been debated in the Open-Ended Working Group. We therefore ask for deletion of the reference to this letter in its entirety. The possibility of future elaboration of additional legally binding obligations could be discussed, if appropriate, and once gaps may have been identified following our further discussions on how international law applies. We already acknowledge that, and we already made a compromise on this, of which everyone is aware. We have language on this in the consensus reports of last year that can help us to achieve consensus this week. Also paragraph 41, as it stands, is in general quite heavy and it contains documents that are not of the same nature or value. We would suggest dividing the paragraph into parts, and in particular having the landmark ICT resolution adopted at the 34th International Conference of the Red Cross and the Red Crescent recognized on its own. Particularly in this section on international law, we reiterate our strong preference for a structure that shows a clear separation between paragraphs that concern the re-information of the applicability of international law and the consensus interpretations of how it applies gained through this Open-Ended Working Group from new proposals that have not garnered consensus but could be part of future discussions if gaps are found to exist. We should continue to discuss how international law applies to cyberspace and should continue the implementation of rules, norms, and principles supported by cross-cutting discussions in dedicated working groups and by capacity building. Through this, we can see how to best strengthen the UN framework. This can also be done through scenario-based discussions. In order to identify the gaps, the report needs to actually reflect the progress made on the application of international law, and given that all that we have achieved and in the understanding to need to find consensus by the end of this week, the EU requests for the final report to simply acknowledge the progress the Open-Ended Working Group has achieved regarding the application of international law, including on the Charter, on peaceful settlement of disputes, international humanitarian law, international human rights law, and the law of state responsibility. We have language proposals on each of these items that could be reflected to this end, and we will share this with you in writing. But please allow me to highlight just one now, which I know other states have and will continue to address as well. We suggest including a clear reference to the applicability of IHL in cyberspace and the progress made to this end, building on the various cross-regional working papers mentioned, including also the reference to principles of humanity, necessity, proportionality, and distinctions in situations of armed conflict. As others have suggested, we would also welcome the inclusion of language of OP4 of the consensus resolution adopted by the 34th International Conference of the Red Cross and Red Crescent, and this could be included in the new subparagraph 40H. Achieving consensus on language, on state responsibility, human rights law, and IHL have proved to be challenging over the lifetime of the Open-Ended Working Group due to the objections by a small number of states. If the final report does not allow us to identify these areas of consensus, at a minimum they should be acknowledged as areas of convergence, as it’s not acceptable that the view of the vast majority of member states were ignored in the final report on these crucial issues. Furthermore, as regard our discussions on international law, we agree that discussions on how international law applies between legal experts is useful and necessary, and these should continue in the plenary discussions as well as dedicated as one of the pillars on the cross-cutting DTGs. We reiterate that discussions on international law between states should be placed into the context of challenges we face, and should not be treated in just a silo. How international law applies is not just a theoretical debate, nor should the outcome of this debate be predetermined by some states. The debate on international law should most importantly allow states to exchange on practices, seek mutual understanding and common ground, as well as build capacity of states on how specific rules and principles of international law apply. In this regard, Recommendation 43 is pre-empting the discussions under the Future Permanent Mechanism by adding references to a specific draft proposal on the Convention. Annex C of last year notes the possibility of future elaboration of additional binding obligations, if appropriate, and should not be reinterpreted or rewritten. As said, we have accepted this language as a compromise, under the pretext that we continue to work on the implementation, and if any gaps are identified, we could enter in such discussions. We therefore do not consider it necessary or appropriate to mandate the Future Permanent Mechanism to specifically continue the discussions on this specific proposal. We must continue to work on our understanding of how international law applies in line with the fragile consensus achieved in Annex C of last year, and not stretch this fragile consensus by adding references to a draft Convention. We therefore request to put a full stop in the Recommendation 43 after ICTs. We emphasize the need for a smooth transition to ensure a clear mandate for the Permanent Mechanism, one that is grounded in the UN Framework of Responsible State Behavior, one that enables the implementation of the UN Framework through action-oriented discussions, one that facilitates capacity building, and one that, if appropriate, and once gaps have been identified, could look into measures of further discussions. This effort towards a smooth transition becomes challenging if other states continue to insist on adding a detailed proposal to an already fragile compromise we have made over recent years. It is all of the pillars of the UN Framework, including but not just only international law, and their effective implementation that will ensure stability and security in cyberspace. And the effort of implementation will also lead to further discussion on gaps, if they exist, and further measures, if appropriate. We should therefore continue to work on the implementation and not dismiss or rewrite it. Let me also continue with CBMs now, if you indulge me, which is another important tool, in addition and in connection to the other pillars I just discussed, that can help us to advance security and stability in cyberspace. Let me thank you for all your efforts, and we are very supportive of the work you have done in this Open-Ended Working Group. You’ve established eight CBMs, of which we have been able to operationalize one significantly, the POC Directory. While we support these efforts, we also caution against adding too many new elements in the final report. Our collective aim should be to build trust and confidence, which is something that takes time, as we all know, and it requires a strong buy-in and consensus from all UN member states. We therefore suggest being modest in the final report with new commitments, including in general terms, such as stressing the development of additional CBMs twice in paragraph 47, and refrain from proposals that are unlikely to find consensus, such as the development of technical ICT terms and technologies, as well as a template that was actually developed as an example by the Secretariat. We have not discussed it, and adopting it would also go beyond what is common practice on the POC networks, such as in the OSCE and in the CERT networks. Their voluntary nature also reflects the need for operational flexibility to adapt to the different organizations and address the dynamic environments in which they are used. We also caution against including the norm and reporting of ICT vulnerabilities in 46F and present it as a CBM, and we caution against putting in obligations as regard to facilitation of access to ICT security goods and services in 46L. Not only have these proposals not been discussed in detail, including regarding their potential nature as a CBM, they have not garnered broad support, and it’s difficult to see a pathway to consensus with these proposals. Putting them into the final report without an exchange during the Open-Ended Working Group could only undermine the idea that a report will reflect consensus, and in addition is preempting discussions under the future permanent mechanism, while also hampering progress on the implementation of your actual achievements on CBMs today. In this vein, we stress the need to focus on the further development and the implementation of the eight CBMs we already agreed upon, and to just improve the POC directory at this stage. We recognize the value of the directory in enabling communication between states during situations that may threaten international peace and security, but we have also raised our concern about instances of misuse of the directory, an issue that was publicly noted by France and Germany during the February 25 session. We support the Secretary’s efforts to operationalize and maintain the directory, but we believe that the directory as such needs to first function well, and that existing challenges must be addressed before we can consider an expansion. We believe the priority should be to increase participation and enhance states’ capacity to use the directory in accordance with its agreed purposes. Further development should be informed by the practical experience gained through its use. To summarize, while we are very grateful for your effort in developing the CBMs that we have to date, we suggest it should be left to the future permanent mechanism to guide further discussions, and to moreover focus on concrete action to implement the actual achievements of this Open-Ended Working Group. Thank you very much, Chair.
Ambassador Gafoor (Chair)
Thank you, European Union. Côte d’Ivoire, to be followed by Fiji.
Côte d’Ivoire
Mr. Chairman, my delegation aligns itself with the statement delivered by Nigeria on behalf of the African Group, and we wish to duly pay tribute to you for your excellent stewardship of the work over the past five years. We recognize the key role of confidence-building measures in easing tensions as well as improving shared understanding of the Framework for Responsible Conduct of States. We have always supported the various significant measures that we have gradually undertaken over these past few years. These include the initial list of confidence-building measures as well as technical terms for ICT, including the Global Directory for Points of Contact. We recently joined the directory through the nomination of the National Focal Point, and we are also supportive of continuing and deepening the implementation of this framework as part of the Standing Future mechanism. We believe that biannual ping tests and exercises and mock simulations are key for its smooth operations and should be fine-tuned. We also support the communications model that was proposed by the secretariat, as reflected in Annex 2 of the draft report. This is a key tool for facilitating communication, transparency, and confidence among the points of contact. Furthermore, when it comes to extending the open-ended working group, we believe it is wise to stress that the future mechanism should explore to a greater degree the means of encouraging more significant participation in this directory through targeted capacity-building modalities. Moreover, there’s an important need to specify for future consideration the priority that needs to be granted for strategies to ensure universal accession to the directory. I now turn to capacity-building. Due to the significance of this, as reflected in the report, we support a regular convening of these meetings, preferably on an annual basis. We also welcome the updating requested by the secretariat for the establishment and operationalization of the Global Portal before the first substantive session of the Future Standing Mechanism. We hope that this updating exercise will duly reflect the exchanges on the subject during the 10th substantive session of the OEWG, specifically with more information about the modalities for management of the portal. As a beneficiary, we have appreciated the scholarship program for women in international security and cyberspace. We also reiterate our gratitude to the various donors to this program, specifically Germany. We call for sustaining this initiative and strengthening it through adequate and sufficient financing. To conclude, we fully support the OEWG as well as the successful conclusion of the mandate. Thank you.
Ambassador Gafoor (Chair)
Thank you very much, Côte d’Ivoire. Fiji, to be followed by the Islamic Republic of Iran.
Fiji
Thank you, Chair. I have the honour to deliver this statement on behalf of the Pacific Islands Forum, with their presence in the United Nations, namely Australia, the Cook Islands, Fiji, Kiribati, the Federated States of Micronesia, the Republic of the Marshall Islands, Nauru, New Zealand, Palau, Papua New Guinea, Samoa, Solomon Islands, Tonga, Tuvalu, and Vanuatu. On norms, we reiterate our position that the focus must remain on the implementation of existing voluntary non-binding norms. Our members are at varying stages of operationalizing these norms, including identifying national critical infrastructure and critical information infrastructure, developing cyber incident response capacity, and applying whole-of-government approaches. Discussions on new norms, particularly without consensus or a clear gap analysis, are premature. We are not opposed to new norms of responsible state behaviour. However, given our constrained resources, we need time to implement the 11 agreed norms. The voluntary track piece is a helpful step towards mainstreaming norms implementation, but we also need consolidated guidance, capacity support, and peer exchanges to fully realize their potential, which is crucial. On international law, we continue to support a principled approach grounded in the UN Charter and other relevant international legal obligations. We endorse the applicability of international humanitarian law in situations of armed conflict, and we affirm that human rights apply online just as they do offline. While the REV1 text reflects many perspectives, the Pacific shares concerns, also shared by others, that it fails to reflect the depth of legal discussions that have taken place within the OEWG, including the high degree of convergence on areas such as international humanitarian law and human rights. We are of the view that a better balance needs to be struck between acknowledging a diversity of views and faithfully reflecting the views of an overwhelming majority of states. We would like to see our final annual report demonstrate the progress that has been made in the OEWG. We call attention to the need to further references to state responsibility and further detail on the peaceful settlement of disputes, both important to our understanding of responsible behavior. We are concerned by the lack of balance demonstrated by reference to the possibility of developing additional legally binding obligations, noting that many states have expressed a need to build legal capacities first and that this is a necessary step to enable states to engage in discussions on how existing international law already applies before considering whether there are any gaps. Legal capacity building, including scenario-based training and regional workshops, will be essential to ensuring all states can meaningfully engage in these discussions. Chair, Fiji will also be taking the floor later on Sections B and C in our national capacity. Thank you.
Ambassador Gafoor (Chair)
Thank you. Islamic Republic of Iran, followed by Australia.
Iran
Thank you, Mr. Chair. We have the following specific comments on the norms section. As noted in our comments on paragraph 25, the States have identified commercially available ICT inclusion capabilities as a threat, but specific measures to address it have not yet been discussed within the Open-Ended Working Group. Therefore, we cannot support the inclusion of paragraph 34H in the final report at this stage. Paragraph 33 of the third annual progress report explicitly underscores that the voluntary checklist is to be discussed and updated at the forthcoming OEWG sessions. However, it is a fact that the States have not discussed the checklist in any of the meetings held after the eighth substantive session of the OEWG. Therefore, we request the deletion of paragraphs 34L and 37, as well as annex 1. We further propose that consideration of the checklist be deferred to the future permanent mechanism. In this regard, we propose the following language as the recommended next step on the checklist. I quote, States to discuss and update the voluntary checklist within the framework of the future permanent mechanism with a view to its development and finalization, while recognizing that it is the prerogative of each State to structure its implementation efforts in accordance with national policies and circumstances. We appreciate the inclusion of paragraphs 34P, Q, and R, and 36 regarding the development of new norms, and we strongly support their retention in the final version of the report. Any attempt to remove these paragraphs would seriously undermine the overall balance of the section on norms, which would be unacceptable for us. In this context, we are concerned about the reference in paragraph 36 to the inclusion of new norms proposed by stakeholders in a list to be compiled by the Secretariat. This approach is not acceptable, as such proposals have not been subject to intergovernmental discussions. We express our support for the specific language proposal put forward by China during the previous meetings on data security. Mr. Chair, we are surprised by the request from some delegations to remove the reference to the Chair’s summary, given that this document has been referenced repeatedly in previous annual progress reports adopted by consensus. For instance, the Chair’s summary is mentioned seven times in the third annual progress report alone. Therefore, we cannot support the request for deleting references to the Chair’s summary throughout the final report. On international law, we believe that the section on international law lacks overall balance, as it reflects only one existing approach, namely the sufficiency of existing international law and its application to the ICT domain. To ensure a more balanced treatment, the report should also reflect discussions on the potential development of additional legally binding obligations, particularly in paragraphs 38, 41B, and 42. To accurately reflect the discussions held over the past years, we also propose adding the following sentence at the end of paragraph 42F. In this regard, a proposal was made concerning the updated concept of the United Nations Convention on Ensuring International Information Security. We welcome the removal of the reference to the use of force in paragraph 40C, which is a positive development. However, we remain concerned about the reference to article 33, paragraph 1 of the UN Charter in paragraph 40B, which lacks consensus and reflects significant divergence among states and therefore should be deleted. A new paragraph 42B has been introduced, referring to national and regional views on the application of international law. It states that these views were discussed within the OEWG, which does not accurately reflect the proceedings. Given the current lack of clarity regarding the responsibility of the private sector and platforms with extraterritorial impact in the ICT environment, we underscore the importance of in-depth discussions on their obligations within the framework of the future permanent mechanism. We therefore request that the reference to this important issue be retained in paragraph 42B. Mr. Chair, concerning the unsubstantiated political accusation made by the representative of Albania, I would like to bring the following to your attention. First, the Islamic Republic of Iran categorically rejects and denounces any kind of unwarranted attribution for the alleged cyberattack on Albania’s infrastructure. This accusation is completely unfounded and is hereby rejected and condemned. Second, given the nature and technical characteristics of cyberspace and the challenges of attribution in the information communication technologies environment, Iran warns of the negative consequences of falsified and forged attribution to the state. We need to observe the principle enshrined in the UNGA Resolution 73-27, which states that all accusations brought against a state in organizing or committing wrongful acts should be substantiated. Paradoxically, this principle has been ignored by those states that advocate implementing the norms of responsible state behavior in the ICT environment and at the same time make groundless accusations that contradict these norms. Publicly attributing responsibility for incidents in the information space to a specific state without any technical evidence is unacceptable and constitutes irresponsible behavior in the ICT environment. Such behavior clearly underscores the validity of certain states’ concerns that existing norms are insufficient and that new norms must be developed. Third and finally, I would like to underscore that Iran, as the primary target and main victim of cyberattacks against its vital infrastructure, has expressed its readiness for technical cooperation since the very first day these baseless claims were made by Albania. Yet, to date, we have received no response. I thank you, Mr. Chair.
Ambassador Gafoor (Chair)
Thank you, Islamic Republic of Iran, for your statement. Australia, to be followed by China.
Australia
Australia aligns itself with the Pacific Islands Forum Statement delivered by Fiji, and we will now make some additional remarks in our national capacity. Chair, on norms and international law, we appreciate that there have been some positive additions, but we suggest that these sections could be improved considerably to strike a better balance in the text and to more accurately reflect the discussions that have taken place in the OEWG. First, turning to norms, on paragraph 34n, we agree with many others that the new additions should be moved to the chapeau of paragraph 34, and additional consensus language on the 11 voluntary non-binding norms of responsible state behaviour should be recalled. On paragraph 34h, we propose the same change here as in paragraph 25, since these paragraphs are linked, amending for lawful purposes to consistent with international law. On the new paragraph 34r and the recommendation in paragraph 36, we echo others that there is no consensus among states to compile and circulate a list of proposals on norms. Only a small number of states have advocated for new norms, while many more states have pointed out that such proposals may already be addressed by existing norms. We have also heard from many developing states that have raised the need to focus first on building capacity in order to implement existing norms. We therefore request that these paragraphs be deleted. On paragraph 37, we support the adoption of the voluntary checklist of practical actions, and note it could be further enhanced by mainstreaming gender equality actions under relevant norms, as detailed in the cross-regional paper on gender and the future permanent mechanism. Turning now to international law, on paragraph 40c, Australia supports retaining the last sentence from the zero draft on the use of force which has been omitted in REV1. The supplementary detail was a very positive addition that added granularity on common understandings reached. Australia also joins Vietnam in calling for insertion of additional language in line with the cross-regional paper co-sponsored by Australia and a group of 16 other states on the topics of international human rights law, the law of state responsibility, and international humanitarian law. This text could be included in paragraph 40. The proposed language in the paper reflects progress made and emerged common understandings reached on international law in the OEWG. The language draws from agreed language adopted by all states, including the 2021 GGE report, and is supported broadly by states across different regions. On paragraph 41, Australia welcomes the inclusion of references to the two OEWG cross-regional papers on international law, as well as references to the discussions that have taken place on IHL and state responsibility. We consider that a reference to international human rights law should also be included to accurately reflect our discussions. In paragraph 41, we are however concerned with the reference to possible additional legally binding obligations, which is a topic that has received very little support and does not fall within the scope of the topic of how international law applies to the use of ICTs. It duplicates content already elsewhere in the report, including at paragraph 42f, giving it undue prominence in the international law chapter. The letter referring to a convention is also not relevant to the topic of how existing international law applies. These references in paragraph 41 should therefore be deleted. We further suggest placing the reference to the 34 ICT resolution in a separate paragraph to reflect its special status as a consensus document. Noting that we have heard many in the room today call for more substantive content on IHL, including from Brazil and the Republic of Korea, we consider that this paragraph would present a good opportunity to insert agreed 34 IC language on IHL. In paragraph 43, we echo the EU and others in calling for the recommendation to end with the words applies in the use of ICTs, as we should not prejudge the topics to be discussed in the future permanent mechanism. Thank you, Chair.
Ambassador Gafoor (Chair)
Thank you, Australia. China, to be followed by Finland.
China
I would like to thank you, your team, and the Secretariat for your efforts to promote consensus. We would like to align ourselves with Niagara for their statement. On behalf of our delegation, I would like to make the following additions. On Section A and B, I would like to make three points. Considering time constraints, we would like to provide our written recommendations on edits. First, considering the fact that China is not only a target of cyber attack by malicious actors in the cyberspace – by state actors in the cyberspace, China is also the victim of these state actors in spreading misinformation, disinformation on attribution. Given the behalf of China, I would like to ask that we add 17 bits after paragraph 17. I would like to read the addition. States expressed serious concerns regarding the spread of disinformation on attributions of malicious ICT activities. In the norms section, I would like to add relevant wording as well. Point number two, on paragraph 16 and paragraph 24, China believes that cyber criminal activities are different from malicious cyber activities that impact international peace and security. We believe that under the UN framework, there is a specific mechanism that is dealing with the issue. So we should not equal these two things. At the same time, ransomware in essence is a cyber activity – a cyber criminal activity, and it should not be linked to any impact on international peace and security. China would like to propose deletion of relevant wordings. On paragraph 15, the use of ICTs for exclusively peaceful purposes has long been a consensus among us. When ICT is being widely used in conflicts in the current landscape, this shows that we are advocating for the use of ICTs for exclusive peaceful purposes. This shows our foresightedness and the significance of the use of ICTs for peaceful purposes. Because of this, we do need to keep the reference here so that we could send a signal to the international community that we are firmly committed to promoting the use of ICTs for exclusively peaceful purposes. On section C and section D, China has three points to make. First, there should be a balance between norms and international law. Implementing existing rules and creating new rules should also strike a balance. This is why we were able to reach consensus in previous sessions. This is not only included in summaries of our previous discussions. This also is reflected in the wording and the organization or structure of recommendation parts. On the summaries of our discussions, in this OEWG session, many countries, including China, in terms of supplier security, data security, cross-border data sharing, attribution, cooperation mechanisms, gap disclosure, vulnerability disclosure, have made many suggestions and have conducted discussions in these areas. Throughout the whole process, China has always proposed this data security initiative. Considering paragraph 41 has made a detailed summary of our discussions on international law, we would like to put these suggestions and recommendations into the discussions on norms. On paragraph 41, I would like to remind us that under international law, we also talked about UN Charter and the principle of sovereignty as well as other major important topics. We would like to ask that those things could be reflected here in our discussions part. At the same time, we should change our topic directly to international law in order to reflect our discussions in a more accurate manner. Now when it comes to recommendation part, recommendations on norms should be consistent with the part under international law. We would like to ask in terms of paragraph 35, we need to change states to continue exchanging views to states to continue to engage in focused discussions. Paragraph 36, we would like to suggest that we add the following at the beginning of the paragraph. I would like to read the addition. States agree to continue the discussions on the possible development of additional norms as a future permanent mechanism. Point number two, commercially available intrusion capacities, China has always made it clear that the transfer of cyber weapons between governments and the spread of aggressive weapon technologies are something that are more concerning. The current text is far from being balanced. In particular, when it comes to paragraph 34H, it does not consider the major source of threat, which is state actor. It only focuses on commercially available ICT intrusion capacities. It is China’s belief that this is in fact not focusing on what matters and this is not an approach that we should adopt. We would like to suggest deleting H. At the same time, I’ve noted that countries that support the retention of para-H are countries that are opposing the creation of new norms. We hope that these countries should maintain consistency in implementing their own standards. Point number three, on the new paragraph 34N, it seems that based on the wording, it says norms are not binding. China finds this bewildering. Even though this is consensus language, but we have always repeatedly saying that norms are not binding. This might send a message to the international community that we are not willing to follow the norms that we have reached after a very difficult negotiation. And this is not constructive. That is why we would like to suggest the deletion of the first sentence of para-N. These are the main points that we would like to share. Other suggestions and recommendations we will provide in writing. Thank you.
Ambassador Gafoor (Chair)
Thank you, China, for your statement, and could you please share your statement in English with the Chair’s office. Thank you, Finland, to be followed by Ghana.
Finland
Thank you, Chair. I have the honor to deliver this statement on international law on behalf of the Nordic countries, Denmark, Iceland, Norway, Sweden, and my own country, Finland. The Nordic countries fully align themselves with the EU statement. This final year of the OEWG, we also mark the 80th anniversary of the signing of the UN Charter. What better time to reaffirm our steadfast commitment to the rules-based international order with the UN at its core and to upholding international law. As affirmed by the previous OEWG and endorsed by the General Assembly, international law, including the UN Charter, applies in cyberspace. The Nordic countries have consistently emphasized that the applicability of international law does not depend on the technological means employed, but applies across domains. More than half of the UN member states have now elaborated positions and understandings on how international law applies in cyberspace. These have paved the way towards a truly common understanding. This broad support should be reflected in the OEWG final report. In the course of the OEWG, many of the Charter-based obligations have been discussed and referenced in the annual progress reports. We would wish to reiterate that the prohibition of threat or use of force applies to any use of force, regardless of the weapons or means employed. Depending on the scale and effects of the cyber operation in question, it may violate this prohibition. And depending on its gravity, a cyber operation may also constitute an armed attack under international law. Regarding peaceful settlement of disputes, the commitment made by states in the GGE report from 2021 continues to be valid. We also wish to emphasize that the rule of state sovereignty is applicable in cyberspace and that a breach of the rule may amount to an international wrongful act and give rise to state responsibility. We are pleased with the further discussions regarding IHL and ICTs, both in the OEWG and in other fora, and the final report should clearly refer to IHL’s applicability in cyberspace. The report should also explicitly acknowledge that in situations of armed conflicts, IHL rules and principles serve to protect civilian populations and other protected persons and objects, including against the risks arising from ICT activities. The landmark ICT resolution adopted at the 34th International Conference of the Red Cross and Red Crescent merits to be taken into consideration by the OEWG, not merely as a reference, but also regarding its substance and the progress made. The Nordic countries affirm the need for states to respect, protect, and fulfill human rights and fundamental freedoms, both online and offline, in accordance with their respective obligations. This should also be reflected in the final report. How international law applies in cyberspace will continue to be discussed in the future permanent mechanism. The starting point is the established acquis of the successive GGEs and OEWGs that international law applies in cyberspace. Building on the three annual progress reports, the final report should clearly reflect and acknowledge the significantly deepened discussions during the OEWG on how international law applies in cyberspace. We need to look ahead while holding on to the common understanding already developed. We consider that international law is relevant to all thematic discussions, and the suggested dedicated thematic groups should reflect this. International law is also included in the plenary session. In the future mechanism, the focus should be on addressing practical, concrete challenges. Finally, we wish to thank the Chair for all the work and effort in seeking to take into account divergent views and to continue to steer us in the process of making the future permanent mechanism a reality. The longer version of this statement will be shared in writing. I thank you.
Ambassador Gafoor (Chair)
Thank you, Finland, for your statement. Ghana, to be followed by the Russian Federation.
Ghana
My delegation would like to now share views on Section C and D. Mr. Chair, my delegation welcomes Paragraph 34C regarding further discussions to build common understanding on Norm C, which highlights that states should not knowingly allow their territory to be used for internationally wrongful acts using ICTs. In support of the comments delivered by Fiji on behalf of the Pacific Island Forum, my delegation is not opposed to conversations around new norms either. However, we see merit in the need to ensure that member states focus on implementing existing norms nationally and regionally. In line with this, my delegation is in support of Paragraph 34B, which advocates for a whole-of-government coordination on the implementation of the voluntary, non-binding norms and the need to raise awareness of these norms at the national level. Ghana, during previous sections, highlighted the importance of standardized templates, and as such welcomes a reference to a common template in Paragraph 34E for requesting assistance and responding to such requests, which is essential to facilitating effective and timely cooperation. Finally, Ghana supports the adoption of the Voluntary Checklist of Practical Actions for the implementation of voluntary, non-binding norms of responsible states’ behavior in the use of ICTs, as contained in the REV1 draft of the final report, now on international law. On Sections D, Mr. Chair, Ghana welcomes Paragraph 42E of the REV1 draft of the final report and sees merit in the retention of this paragraph, particularly the reference to principles that should underpin capacity-building efforts to develop a common understanding on how international law applies in the use of ICTs, as well as the proposals for such capacity-building initiatives, including workshops, conferences, and best practices exchanges at the international, inter-regional, and sub-regional levels. To further build on this, Ghana supports the inclusion of scenario-based discussions in this paragraph after conferences, as highlighted by the Netherlands. In prioritizing capacity-building, Ghana recently joined the ICT workstream of the ICRC’s Global Initiative to Galvanize Political Commitment to International Humanitarian Law to join other like-minded states and build a shared understanding on the topic. Ghana will be co-chairing this workstream with colleagues from Luxembourg, Mexico, and Switzerland. Additionally, the development of online and in-person training courses, as well as the online resource libraries, will serve as a useful tool for developing countries. To conclude, Ghana supports earlier references that have been made to include previous GGE reports in the existing reports to clearly outline the progress that has been made over the years, as highlighted by the Netherlands and re-echoed by the UK. I thank you, Mr. Chair.
Ambassador Gafoor (Chair)
Thank you, Ghana, for your contribution. Russian Federation, to be followed by Italy.
Russia
Mr. Chairman, distinguished colleagues, we, according to the mandate for the OEWG and strident resolution 75-240, states as a priority need to continue to formulate rules, norms, and principles for responsible conduct of states in the information space. We cannot but note in the current version of the final report of the group, this key premise has been violated. As a whole, the document, and specifically in the rules of conduct, has unjustified distortion in favor merely of implementation of the existing list of voluntary norms I referred to, paragraphs 30B, 30C, 32, and 36. There is a blatant biased reflection of the course of discussions about this aspect of the mandate. Specifically, there is an absence of something that has been repeatedly voiced by a number of delegations, including the Russian delegation. I refer to the premise about the importance of attributing voluntary nonbinding rules of conduct and making this a legally binding status. I refer to paragraph 34. We stress that there is a need to incorporate this language in the section on norms. Furthermore, we propose that paragraph 34N, which stresses a difference in the status and rules of conduct and norms of international law, be brought to the beginning of that paragraph. And to be moved there, we cannot agree with the proposal to approve the control list of practical actions to implement rules of conduct, paragraphs 34L and 37. This initiative was not thoroughly considered during the final negotiations around the OEWG, including – and this – we – Russia has a number of – and a number of delegations have principled objections to this, and we propose a continuation of this under the future permanent standing mechanism. We propose that it remain provisional in nature. Given that the draft list has already been incorporated in Annex A to the third annual report of the OEWG and has not yet been changed, we stress that it be deleted from the list of proposals for the final report and for the relevant adjustment in paragraph 34L and 37 to be made. In order to ensure progress in terms of rules, norms, and principles for the future standing mechanism, we recommend the deletion from the recommendation of paragraph 36B, provisions on the final fine-tuning of existing norms, and to use the term observation instead of implementation vis-a-vis the voluntary rules of conduct for states. I also wish to react in this context to the statement that was delivered by the EU representative. In my language, observe is to adhere to, to abide by, or to comply with, and this presupposes a high level of obligation insofar as my language – my knowledge of English allows me to understand. In English, these are also clear synonyms to the verb observe. Now turning to implementation, this is a matter of domestic policy of states. This is a part of their sovereignty. We cannot dictate to states how they are to implement the norms at the national level. This is only possible in the event of the adoption of a legally binding agreement and the relevant ratification thereof by the relevant states. I now turn to paragraph 34E. We believe there’s an important need to focus on the development through the OEWG to focus on universal templates for data exchange through the UN’s Establishment Global Intergovernmental Register for contact points, and not the templates for delivery of assistance on matters related to malicious impact on critical infrastructure. I am confident that states will be able to deal with this matter bilaterally. We note the unjustified emphasis on something which is not widely supported. I refer to the idea of internal domestic measures for the implementation of voluntary norms, paragraph 34B, and the establishment of some kind of a culture of constant improvement vis-a-vis critical information infrastructure, paragraph 34F. We think it is wise to delete this language in the above-mentioned paragraphs. On the whole, the section on norms could be shortened specifically through paragraph 34F and 34J, as well as for certain provisions of 34M to be brought to the – to be moved to the capacity-building section. I turn to the section on the applicability of international law. In principle, in our view, it is important to incorporate recommendation for – paragraph 43 on the possibility of developing a legally binding agreement, an information space, in accordance with the OEWG report, which was approved last year for the standing mechanism. We also firmly believe that the fact that the question is being set out by – in and of itself by certain delegations about the necessity for legally binding norms is simply not relevant. The international community has already taken a concrete step in that direction, having reached agreement last year on the UN Convention Against Cybercrime. This became the first international treaty in the area of safety and security in the use of ICT. For this reason, in paragraph 41 on the relevant national initiatives, we propose that there be a reference with an up-to-date note of state sponsors of the concept of – directed to the OEWG on providing for international information security. We also insist on the deletion of mention to the non-consensual resolution of the 34th International Red Crescent and Red Cross Conference on the Protection of Civilians in the context of the use of ICT in the light of the centrality of the role of the UN and the OEWG on the question of the applicability of international law vis-a-vis the use of ICT. What is also not feasible, in our view, is to single out certain aspects such as protection of critical infrastructure and data as priorities for the discussion on the matter of the applicability of international law and information space under the future mechanism of paragraph 42B. We believe it is wise to include in the list the relevant proposals on the development of a legally binding – of legally binding agreements in taking into account the specific features of ICT paragraph 42B in order to ensure balanced reflection of the position of states’ parties of the OEWG. Turning to the section on international law, the idea of briefings of experts including the International Law Commission, paragraph 42A is premature for states. What is optimal, in our view, is to have paragraphs shortened on the capacity-building of states on the matter of international law, paragraph 42E and 45 in the section on capacity-building. Mr. Chairman, I also wish to note in response to the statements made by a number of delegations who have been proposing that we revert back – in paragraph 40C to include a highly contentious notion which places cyber operations on equal footing with the use of force in accordance with the Charter of the United Nations. This is an approach which is neither consensus-based nor is it supported by the majority of states, and our objective during this final session is to enshrine in the final report specifically those elements which constitute the fruit of consensus. Thank you.
Ambassador Gafoor (Chair)
Thank you, Russian Federation, for your statement. Italy, please.
Italy
Thank you, Mr. Chair. First of all, I’d like to express our sincere appreciation for your leadership and for preparing the final report. Let me also extend my gratitude to the Secretariat for its invaluable support. Mr. Chair, as you pointed out earlier today, we have almost reached the final goal of the OEWG. We now need to make sure that everyone’s concerns are taken into due consideration for a more balanced, consensus-based report that is firmly anchored to the framework of responsible state behavior. Italy fully aligns itself with the statements delivered by the European Union. I would like just to share a few additional reflections on sections B, C, and D in our national capacity. On section B, we welcome the thorough analysis of the threat landscape, acknowledging this is the basis for the implementation of the UN framework. In this context, we note that ICTs are increasingly being employed in ways that combine different non-conventional instruments of influence, including activities below the threshold of armed conflict. We are thus confident that the final report for Concerns Paragraph 15 will reflect this understanding about the potential hybrid use of ICTs with which the international community is daily confronted. We also welcome the inclusion of a dedicated paragraph on AI. Italy highlights the importance of continuing to better understand the risks associated with emerging technologies, including AI, quantum computing, IoT, and cloud computing, and to dedicate appropriate space in the report to each of them as they do have a direct impact on international security, and we are called to address the risks they pose. As for section C, we strongly believe that states should not knowingly allow their territory to be used for internationally wrongful acts using ICTs, as is rightfully mentioned in paragraph 34C. However, building on that, we underline that all the actors present within a state’s territory, both state and non-state ones, should fall under the application of this rule. As for section D, we would like to see the progress made on international humanitarian law reflected in the final report. In particular, we once again underline the importance of upholding the core principles reaffirmed in the resolution adopted at the 34th International Conference of the Red Cross and Red Crescent, as also recalled a while ago by the Netherlands, the UK, the EU, Finland, and others. In addition, we stress that human rights have to be protected in the digital space inasmuch as they are offline. This is much more evident and undeniable now than it was at the beginning of the OEWG. Furthermore, we share many delegations’ conviction that we should continue to debate on how international law applies to cyberspace and continue to implement existing rules, norms, and principles supported by cross-cutting discussions and by capacity building before introducing new norms or legally binding instruments for which consensus has not been reached. Finally, we regret the omission of previously agreed language on the threshold for an ICT operation to constitute a use of force, and we support its reinsertion in paragraph 40C. Mr. Chair, to conclude, let us not lose sight of the considerable progress already achieved in this OEWG. We encourage a final report that duly reflects this progress and reinforces our collective, shared commitment to implement the UN Framework on Responsible State Behavior in Cyberspace. Thank you, Mr. Chair. Thank you.
Ambassador Gafoor (Chair)
Thank you very much. Now, friends, I think we have about another maybe 15 delegations, so certainly we’ll need to take up the list of speakers and continue our work tomorrow morning. Second, I just wanted to share that tomorrow morning we will shift to, in addition to A, B, C, and D, also to sections E and F. And I will give an opportunity to delegations who are waiting on the list to speak to also make comments on these two additional sections. So we’ll keep, for the moment, regular institutional dialogue apart, and I intend to take that up tomorrow afternoon or hopefully earlier in the morning if we can exhaust the speakers list. Thirdly, now there have been some discussions which are fairly long, and some of you have been speaking for groups. I respect that, I acknowledge that. These are very important inputs, and I’m hoping also that the statements that we have heard today will help to frame the discussions and that those who are speaking tomorrow do not find the need to repeat statements that were already made today, especially if they were part of these groups to which they are aligned. So I seek your indulgence in that. The last comment I wanted to make was that today, or rather this afternoon, we went deeper into the discussions because we were trying to cover four additional, or two additional sections, so covering a chunk of REV1. And so we’ve continued our work, the tone has been constructive, the contributions have been detailed and specific, but there’s also a degree of expressing strong preferences for your own positions while expressing objections and requests for deletions of proposals that are not your positions. And this has been the dynamic to some extent this afternoon, and that is not surprising because this is a negotiation, you obviously are not ready to part with your national positions and your preferred positions, but that too is understandable. But what you need to keep in mind, as we reflect on the day’s work, is that if we put together everyone’s preferences, then that is not going to bring us to convergence. I think we will need some expressions of flexibility, and that will mean that everyone accepting the fact that other delegations who have a different point of view also need to have the opportunity to have their points of view reflected. And that is where the balance needs to be struck. So I appeal to each one of you to keep that in mind, because it’s in some ways easy to take a position that I want the document to be reflected the way it is aligned with my own national position, but anything that is not aligned with my national position, I would like to have it deleted. I mean, that kind of reasoning is not going to get us very far. So please keep this in mind when you come back for your statements tomorrow. Tomorrow, we’ll start with France to be followed by the United States. And to be fair to them, I don’t want to give them the floor at this point, partly because we’re running out of time, partly because the interpreters have worked hard. They’ve also passed me the message that delegations have to speak a bit slower. Obviously, projecting the clock on the screen is stressing quite a number of you and accelerating your statements. So, but if you slow down, we don’t have all the time either. So I really think you need to, this evening, those who are planning to speak tomorrow, to focus on the essential points so that you are communicating your position in terms of what you can live with, what you can accept, what the compromises could be, and, of course, any bridging proposals, if you have any to put forward. The final thing is that since you worked very hard today, I’d like to invite all of you for a drink at the Singapore Mission. This is the traditional start of the meeting reception that I would like to host for all of you this evening at 6:15 p.m. at the Singapore Mission. So please come and have a drink, meet and mingle, get to know people, and if you can also negotiate bridging proposals at the reception over a drink in a neutral territory like the Mission of Singapore, that is also very much welcome. So, friends, thank you very much for a productive day. My thanks to the interpreters for keeping up with the rapid speeches. The meeting is adjourned. We resume tomorrow morning at 10 a.m. Thank you for your attention.
Leave a Reply