Ambassador Gafoor (Chair)
Good morning, distinguished delegates. As indicated in the program of work, this morning we will start with the dedicated stakeholder session. And in keeping with the practice of the Working Group, we will go through each of the stakeholders who are registered to speak. And as I indicated yesterday, before we wrap up, we are operating under intense time pressure. So I’d like to appeal to the stakeholders for their understanding and support. We will have to turn off the microphone at the three-minute point. It’s not something that I enjoy doing, but I’d like to seek your kind understanding. Do circulate the statements to me and to all delegations. We will put that on the website. But I also want to say that this session today is not a one-off session. We have, throughout the five years, been talking to the stakeholder community. At each of the formal sessions, we have given them an opportunity to speak. I also make it a point to convene informal sessions with the stakeholders on a range of topics. They have contributed a lot of ideas. Not all the ideas make it to the formal progress reports or might even make it to the final report. But the point is that they are engaging, participating, contributing ideas, and this enriches our collective conversation here. I think that is the spirit of the United Nations. Let’s get on with the speakers list. The first speaker is Access Now, followed by the German Council on Foreign Relations. Access Now, you have the floor, please.
Access Now
Thank you, Chair. I am Ramanjit Singh Cheema, addressing you on behalf of Access Now, the international civil society organization which focuses on digital security and defending the digital rights of vulnerable individuals and communities. We thank you for the opportunity to address you all today, and in particular, appreciate the comments you made yesterday, Chair. We hope all delegations are here, listening to us and seeking to understand the views of stakeholders. We speak to you from positions of expertise and frontline experience. Our Digital Security Helpline, a proud member of the Forum for Incident Response, and a participant in the Common Good Cyber Initiative, has seen over 1,000 cases each quarter so far this year, showing us just the tip of the cybersecurity crisis we face. Today, we ask you to see yourselves not only as diplomats, but as stewards. The main duty of stewardship is simple, to leave things better than how you found it. Today, we are therefore asking this OEWG to consider the fact that the first OEWG and the Group of Governmental Experts left us with milestone consensus achieved across the UN’s membership on responsible state behavior, despite the odds they faced, a foundation that we could all work with and build on. Right now, we believe you have partly progressed on this foundation, but you still run the risk of jeopardizing a key that states here have achieved through tremendous work. An instance of progress in the current draft is the references to state efforts against the growing market for commercially available ICT intrusion capabilities. We believe international efforts on responsible ICT behavior must recognize the reality that commercial spyware is regularly used to target civilian populations, diplomats, and other stakeholders. In that regard, we believe the REV1 text must be further bolstered by adding specific references in PARA25 that cyber intrusion capabilities must be used in ways consistent with international law, including the standard of necessity, legality, and proportionality as outlined in international human rights law. We welcome the efforts to further implement the norms on human rights and a human-centric approach to cybersecurity through the voluntary norms E and J in the text. OEWG members must promote human rights on the internet and encourage responsible reporting of ICT vulnerabilities, including the critical role of security researchers. But the current text leads us to the less secure foundation in the past OEWG by failing to incorporate explicit references to international human rights law in the main body. This body should also be proud of the increasing number of states who have outlined their position internationally on cyber operations. In that regard, we believe that more needs to be done again to specifically refer to international human rights law and humanitarian law. We urge you lastly to reconsider your approach to the modalities of stakeholders. We’ve joined 24 organizations and experts this week in supporting a joint letter asking for improved stakeholder modalities. Do not lock yourself into politics. Be pragmatic and give yourself all the tools you can achieve. We therefore wish you success in establishing a permanent mechanism that advances the challenges of meaningful rights-respecting cyber dialogue.
Ambassador Gafoor (Chair)
Thank you very much, Access Now, for your contribution. German Council on Foreign Relations, you are the next speaker.
German Council on Foreign Relations
My name is Valentin Weber, and I’m a Senior Research Fellow with DGAP, the German Council on Foreign Relations, and in this capacity, I also signed the joint civil society letter on multistakeholder modalities. Thank you so much for giving me the floor and for your admirable effort to find consensus in a world where it is increasingly rare. For the German Council on Foreign Relations, also known as DGAP, this OEWG has been the first time to engage in a UN cyber dialogue. During the last five years, we thankfully had the opportunity to closely follow how member states have started operationalizing their key of the past 20 plus years. We’re very happy to see that the current version of this report puts an emphasis on critical infrastructures. At DGAP, we have actively supported your and member states’ efforts to strengthen their protection. But our research shows that words alone do not suffice. There is a huge gap in the implementation of the norms and the protection of critical infrastructure. In the policy brief, we have highlighted that half of the countries, that means half of the room here, represented in this room, have not yet designated critical infrastructure sectors within their territories. This makes it difficult to implement norms 13F, G, and H, and in my opinion, requires further attention. My team at DGAP has also taken notice of member states’ concern over the misuse of quantum technology. In this context, we’re happy to see that for the first time, the current version of the final OEWG report contains a reference to states’ intention to deploy post-quantum cryptographic solutions. We don’t think that this is premature. Chair, it is really high time to do so. DGAP research shows that all of us are profoundly vulnerable to quantum computing. Our analysis found that no UN member state has yet accomplished the transition to quantum security. No country in this room. In short, all UN member states are vulnerable for the day when quantum computers reach the capability to break conventional encryption. Some estimate that this might even occur by 2030. This leaves us only four years to get this job done. In short, there has been progress also due to your efforts, Mr. Chair, but the world and in particular its critical infrastructure remains profoundly vulnerable. As Elvis Presley said, a little less conversation, a little more action. A little more bite and a little less bark. A little less fight and a little more spark. In this spirit, we appeal to you and the member states. Thank you for your attention.
Ambassador Gafoor (Chair)
Thank you very much, Chairman, Council for Foreign Relations, and also for introducing some music into our lives. I think we need to have a positive tone and a positive tune in our heads at this point. I give the floor now to SafeBC Solutions.
Safe PC Solutions
Thank you, Chair, for the opportunity for SafeC Solutions to speak today to make a statement for intervention. We welcome zero-draft recognition of the transformative potential and the dual-use nature of emerging technologies, particularly artificial intelligence and quantum computing. As I stated last week in the informal dialogue, we need to include generative AI, a rapidly advancing subset of AI capable of producing synthetic content such as text, images, code, and audio. It has introduced new vectors for disinformation, social engineering, and automated cyber attacks. And also, we encourage the OEWG to consider referencing the governance of generative AI as a distinct area of concern within the broader AI landscape. We also suggest that quantum computing be separated and be defined in the document. Quantum computing presents a foreseeable threat to current cryptographic systems. We urge the OEWG to emphasize the urgent need for the development, standardization, and the global adoption of post-quantum cryptographic solutions. We further emphasize the importance of inclusive cross-sectoral cooperation, engaging governments, industry, academia, and civil society to address the complex risks arising from the convergence of AI, quantum computing, and other advanced technologies. And I do thank you for putting the stakeholders at the forefront of this meeting. We also, SafeC Solutions, we also support the joint stakeholder statement on the zero-draft and REV1 Annex III section on stakeholder modalities. Also concerning capacity building for resilience and sustainable development, SafeC Solutions last month, well, in May, we had the opportunity to present at the Global Conference on Cyber Capacity Building in Geneva. And I met with a lot of the member states from Africa, Latin America, and Pacific Islands. And they were not aware, first of all, that we were a stakeholder in OEWG, let alone that we had built a cybersecurity awareness training on a generative AI platform focusing on people of color. So thank you.
Ambassador Gafoor (Chair)
Thank you very much, Safe PC Solutions. The next speaker is Academia Mexicana de Ciberseguridad y Derecho Digital.
Academia Mexicana
Thank you very much, sir. The Mexican Academy of Cybersecurity and Digital Law welcomes this opportunity to speak, and we pay tribute to what has been done by states in this entire process. We welcome the advances in principles such as making a better, broader, and more peaceful cyberspace. However, things are still lacking to ensure a robust, person-centered cybersecurity panorama. So we would like to see more data, clear data, looking at the future so that we can include emerging technologies and new technologies, generative AI, so that we can be vigilant also in independent decision-making systems, although the draft does recognize quantum computing and generative AI. We feel that we need a specialized thematic group that can bring forward recommendations and look at technicalities based on evidence. Then we need a cross-cutting approach when it comes to human rights in the digital sphere. In the document, we have to respect human rights. That’s mentioned. However, there’s a lack of practical measures to fulfill this. We have voluntary measures as suggested over the last two weeks applicable to AI and cyber technologies by states. Then when we look at the larger scale, we need governance, traceability, accountability, particularly when it comes to decision-making operations for public decisions. This is linked also to products and services. And then fourthly, when we come to IHL in the context of armed conflict in cyberspace, we would suggest that the section here be strengthened with reference to the possibility of enforcement, particularly in sensitive areas. We also underline how important it is to strengthen accountability mechanisms. When it comes here to a voluntary basis, it would be a good idea to provide basic behavioral indices for regions and have voluntary national reports to increase confidence. Then lastly, when it comes to the participation of stakeholders, stakeholders can make relevant contributions only if it’s possible to actually work in the field. The large support expressed in this group for capacity building cannot move forward without contributions from all sectors. Therefore, we support the joint cybersecurity paper submitted last week. Lastly, when it comes to innovation and human dignity under legal provisions, we feel the speaker has been cut off.
Ambassador Gafoor (Chair)
Thank you very much, Academia Mexicana. CREST International, you have the next speaker.
CREST
Thank you for your commitment to ensuring that stakeholders are heard by the OEWG. I speak for CREST International, a non-profit which builds trust in the digital world by raising standards in the cybersecurity industry. The recent Common Good Cyber and EU-ISS paper highlights multiple non-profit-led programs that are relevant to the Zero Drafts initiatives. The practical experience and real-world results of such work uniquely position stakeholders to work with states. Crest therefore supports the Joint Civil Society Statement in calling for meaningful stakeholder engagement and the Canada-Chile-led paper’s proposal to overcome the single-state veto and enable stakeholders to contribute to each agenda item. You invited us, Mr. Chair, to identify where we can work with states on the Zero Drafts initiatives. Crest is specifically well-placed to contribute to global standards for supply chain security and the Standardized Curriculum for Technical Cyber Capacity Building. These are set out in paragraphs 34G and 51C. Crest brings 18 years of experience driving cyber resilience through the supply chain, developing standards for technical cybersecurity services and assessing providers against them. Crest also brings experience as a licensing and certifying body, setting standards for the cybersecurity workforce and developing and assessing professionals on behalf of governments and regulators. Crest’s syllabus defines the knowledge professionals require. Crest’s course material is underpinned by a commercial model that supports capacity building. Crest’s certifications can be taken in 3,500 exam centers in 158 countries. Our standards enable capacity building. Australia, EBRD, and UK-sponsored Crest Camp programs have built service provider maturity in 14 countries, including Indonesia, Ghana, Kenya, Malaysia, Morocco, Thailand, and Vietnam, and supported training centers with trainer training and course material. As we work together to build a safer digital world, internationally recognized and agreed-upon standards must be preferable to variable national standards in guiding states’ due diligence, measuring, verifying compliance in the norms upheld by the international community, and in identifying gaps and measuring progress for capacity building. Together, we can identify and recommend relevant tested standards as the basis for future international standards, for future iterations of the checklist, and as a confidence-building measure. In conclusion, Crest supports OEWG’s aspirations to drive international standards. We bring practical experience and capability to work with states and others to agree, negotiate, and evolve standards and to develop standardized curriculum. We look forward to your continued collaboration with states and stakeholders within the future permanent mechanism. Thank you.
Ambassador Gafoor (Chair)
Thank you very much for your contribution. I give the floor now to the Centre for Humanitarian Dialogue.
Centre for Humanitarian Dialogue
Thank you for giving me the floor, Mr. Chairman. The Center for Humanitarian Dialogue welcomes the opportunity to speak. It is among the numerous stakeholders who have issued a joint statement on stakeholder participation in the Future Permanent Mechanism. On 11 January 2011, the UN General Assembly welcomed the work of a Group of Governmental Experts on developments in the field of information and telecommunications in the context of international security. In their report, the experts, chaired by Russian Ambassador Andrei Krutsky, warned that existing and potential threats in the sphere of information security are among the most serious challenges of the 21st century. They developed a conceptual triangle to address these challenges. And the corners of this triangle are agreeing the rules that govern state use of ICT, both binding international law and non-binding norms of responsible state behavior, building confidence that states will respect these rules, and developing capacities so that all states can behave in a rule-abiding and confidence-inspiring manner. For 15 years, these elements have been guiding the United Nations’ work on the issue, building a cumulative and evolving framework for responsible state behavior. Now, I am worried that the final OEWG report may depart from this successful approach. The draft before delegates, and the proposed setup of the dedicated working groups, represents a shift of focus away from the evolving nature of the threats, and it relegates to second rank the discussions on norms as well as on confidence building. UN efforts have resulted in substantial progress on the rules of state use of ICT. As the Secretary-General wrote in 2023, the rule of law exists in the digital sphere just as it does in the physical world. This progress has been hard-won, and it must serve as a baseline for all future multilateral work in this area. Many argue that the problem is not an absence of rules, but a lack of confidence that states will respect them. Rules are a manifestation of power. They are worth very little without confidence that the rules will enjoy respect. In the words of Russian Tsarina Catherine the Great, power without confidence is nothing. To escape the risk of reducing hard-won progress to nothing, an appropriate emphasis in the Future Permanent Mechanism on confidence building seems advisable. In support of such efforts, including in the dedicated thematic working groups, the Center for Humanitarian Dialogue would be happy to offer insights based on its concrete activities dedicated to ICT confidence building.
Ambassador Gafoor (Chair)
Thank you very much for your contribution. The next speaker is Raylan de Fonca de los Derechos Digitales.
Red en Defensa de los Derechos Digitales (R3D)
Thank you very much, sir. I’m Francia Pietrasanta , and I represent R3D, the Network to Defend Digital Rights. We are a Mexican organization to defend rights in the digital scenario, and we welcome the opportunity to speak here. In a world where states are constantly expanding the use of technologies in some local contexts, such as ours, there are also more and more attributions going to authorities to access, gain, and share data without any effective limits. All this gives rise to serious concern when it comes to the real capacity of infrastructure to ensure the security of computer systems. We can think of the millions of people that are affected when there are cyber attacks or undue use of the information obtained. The development, acquisition, and use of digital systems by states in areas such as intelligence, public security, implementation of law, control of migrants, and the provision of services can only deepen structural gaps, facilitate mass surveillance, exploitation of data, and discrimination when it comes to the provision of public services. As is indicated in paragraph 1727 and others, the protection of critical information structures has to be addressed very seriously. Here, the standing mechanism from this working group and its thematic groups needs to incorporate a perspective of the global majority, in particular Latin America, when it comes to the inter-American system of human rights and the differing interpretations when it comes to freedom of expression and privacy. There are effects here when it comes to these on human rights in accordance with A and what is considered in the voluntary measures for taking steps here. It is important to ensure that the results of these discussions be taken to a regional and national context to ensure real, fair, and effective implementation. So we from R3D have subscribed to the joint statement on the modalities of participation of the stakeholders in order, as is stated in paragraph 17A of Annex 3, to ensure a systematic, sustained, and substantive involvement of all interested stakeholders when it comes to the use and abuse of technologies. Thank you.
Ambassador Gafoor (Chair)
Thank you very much for your contribution. Alliance of NGOs on Crime Prevention and Criminal Justice, you have the floor, please.
Alliance of NGOs on Crime Prevention and Criminal Justice
Thank you, Chair. It’s a privilege to address you today on behalf of the Alliance of NGOs on Crime Prevention and Criminal Justice, an umbrella organization coordinating civil society engagement with the crime and justice mandates of the United Nations. The Alliance has a leading role in supporting civil society participation in multilateral discussions. It has actively engaged in the negotiations of the United Nations Cybercrime Convention and the subsequent discussion on stakeholder participation in the Conference of States Parties. As delegations work towards the consensus adoption of the final report, it’s a critical time to show strong support for stakeholder participation, to ensure that civil society, the private sector, and academia can meaningfully contribute to the future permanent mechanism on cybersecurity. Stakeholders have consistently demonstrated the value of their contributions over the two years of the first OEWG and more than four years of the second OEWG. We have seen more joint organization of side events on the margins of the substantive sessions, as well as state-stakeholder cooperation and initiatives outside of the plenary. These actions show a strong commitment to responsible state behavior in cyberspace. However, concerns remain about the openness and inclusiveness of the OEWG discussions. Many organizations have been vetoed and face concerns to participate in the substantive sessions. Should the final report maintain weak language on stakeholder modalities in the future permanent mechanism, it will further hinder the engagement. The advancement of responsible state behavior in cyberspace will fall short of effectiveness, transparency, and inclusivity if done without the support of civil society. The plenary discussions also show a strong cross-regional support for stakeholders to have a voice in the regular institutional dialogue. We support the proposal led by Canada and Chile and the joint stakeholder position that states can object to specific applicants, but a vote will be requested in plenary to decide on the final accreditation. The future permanent mechanism is a unique opportunity to set the stage for long-term progress on international peace and security. To achieve its full potential, the agreement must not come at the expense of stakeholder participation. We remain committed to engaging throughout the session and supporting an outcome that ensures constructive stakeholder engagement. Thank you for your attention.
Ambassador Gafoor (Chair)
Thank you very much for your contribution. European Union Institute for Security Studies, you have the floor, please.
EU Institute for Security Studies (EUISS)
Thank you, Chair, for giving me the floor. As the Open-Ended Working Group concludes its mandate, we must acknowledge that the decisions taken in this final session will not only shape the final report, but determine whether a decade of international consensus-building anchors its achievements or risks diluting them. One of the most decisive tests would be whether we treat capacity building as a silo or as a strategic lever across all pillars of responsible state behaviour. In this regard, the language on capacity building in REV1 remains too siloed. We believe that cyber capacity building should be strongly recognized as a cross-cutting enabler for norm implementation, confidence building, and the operationalization of international law, and this should be more clearly reflected in the report across pillars. Chair, we urge that the final report emphasizes the cross-cutting foundation of capacity building by considering the following proposals. Reiterate explicitly the link between norm implementation and capacity building. Embed capacity building in the language on CBMs as an enabler for responsible but also accountable state behaviour. And finally, on international law, we should emphasize that capacity building has played a foundational role in advancing states’ understanding of how international law applies in cyberspace within the respective jurisdictions. Capacity building efforts must uphold human rights, promote equity, and include a wide range of actors to ensure meaningful and inclusive participation. These principles must shape program design, monitoring, and evaluation, not serve as a post-hoc consideration. Chair, there is a second cross-cutting observation we must acknowledge in the context of this process and cyberspace, the essential value that stakeholders contribute. Their contribution is grounded in their diversity and complementary expertise, qualities that are often described as welcome yet not always treated as such in practice. Stakeholder inclusion is not optional. Excluding stakeholders from future coordination efforts will weaken the legitimacy of the process but also its outcomes. In these regards, we also express our full support for the working paper on practical modalities for stakeholders’ participation and accreditation in future UN mechanisms on cybersecurity, coordinated by Canada and Chile, and the joint stakeholder statement on the Zero Draft and the REV1 Annex III section on stakeholders’ modality in the future permanent mechanism. Chair, the Open-Ended Working Group cannot conclude with a report that treats the cross-cutting contribution of capacity building and stakeholder engagement in isolation. Both are essential to reflect the reality of the cyber domain’s multi-layered nature and shared ownership. I thank you for your attention.
Ambassador Gafoor (Chair)
Thank you very much for your contribution. Write Pilot, you have the floor, please.
Write Pilot
Honorable Chair, distinguished delegates and stakeholders, my name is Abdullah bin Hussein. Noting your recent exhortation to stakeholders to find partners so that voices from vulnerable areas and underrepresented communities are heard, I am pleased to deliver this statement on behalf of Write Pilot so a young Jordanian voice is heard in this august chamber. Mr. Chair, allow me to express our appreciation for your exceptional leadership and guidance throughout this process. Your patience and understanding have been instrumental in fostering an environment that accommodates diverse perspectives and inclusion. In keeping with your guidance and focusing discussions on ways in which the multistakeholder community can work together with states, Write Pilot is prepared to serve as a co-facilitator in support of civil society’s efforts to structure, organize, and report back to states in the future permanent mechanism. We welcome the statement made by CREST International that internationally recognized standards must be preferred over varied international standards and hence the need to recognize the harmonization of standards as a confidence-building measure. The multi-dimensional use of standards in the zero draft report warrants greater understanding of the diverse frequencies in which standards intend to play as either a technology security issue, a matter of governance, or a matter of capacity building enabler, even as a component of international law with states being obliged to comply under the principle of due diligence. Following your guidance to engage as a network of advocates, Write Pilot is pleased to align itself with CREST International in committing to work with others to reach understanding on how standards in cyberspace can enable and operate under international law. We welcome and support the Canada-Chile-led proposal to support the engagement of the multistakeholder community, the joint civil society statement, and its call for meaningful stakeholder engagement. The Women in Cybersecurity Middle East group, WIXME, we urge the international community to recognize them as a common good cyber initiative and to continue to support the major achievements of women in cybersecurity fellowship programs as a crucial way to enable underrepresented voices to speak and be listened to by states. We stand ready to support you in building a resilient cyberspace. Thank you, Mr. Chair.
Ambassador Gafoor (Chair)
Thank you very much for your contribution. The next speaker is Hitachi America.
Global Partners Digital
Thank you, Mr. Chair, for this dedicated stakeholder session towards the final stage of OEWG consensus. As a private company, we make efforts providing safe, secure, reliable civilian critical infrastructure, including energy, transportation, digital, water, and data for people globally, while applying positive innovations in AI, quantum, and nuclear fusion. Today, let me touch upon REV1 draft final report. First, working together with the States, we can contribute to updating threats, such as the negative use of AI and quantum, and start applying a norm checklist, including FGHIJ, in different designated sectors by state and regions. As a provider of hardware, software, and IoT for the global supply chain in digitized CI, we can work with inclusive stakeholders, NGOs, academia, and states, under all auspices of the UN, sharing best practices, and analyzing gaps for improvements under trust. These are examples of plenary or designated thematic group one. Second, we can contribute active participation in technical and legal simulation scenarios and gap analysis with country advisors. Lessons learned can be reflected in policy improvements, while applying international laws such as the Charter, human rights, and IHL. These are examples of DTG2. Third, capacity building is most we can contribute as a CICII provider, including global round tables, and best practices, such as security by design, zero trust, AI security and ethics, and quantum-safe securities. These are related to DTG3 and relevant to digital compacts and SDGs. Indeed, capacity building is CBM. In conclusion, we can participate practically working together with the states in a permanent mechanism, continuously improving global CI CII for peace, safety, security, and resilience, addressing the cross-cutting nature and gaps in data integrity of physical and virtual in each.
Ambassador Gafoor (Chair)
Thank you very much for your contribution. Arab Association for Cyber Security, you have the floor, please.
Arab Association for Cybersecurity
Honourable Chair, Distinguished Delegates, Esteemed Colleagues and Stakeholders, It is a privilege to address this distinguished working group today on behalf of the Arab Association of Cybersecurity. Allow me first to express our sincere appreciation to you, Mr. Chair, for your unwavering leadership and dedication to ensuring this post remains inclusive, transparent, and loose in dialogue. Your efforts continue to inspire confidence and trust amongst all participants. We welcome the zero-draft plan report as a thoughtful and well-balanced basis for further negotiation. We particularly commend the inclusive spirit of this process, embodied in the citizen-led meetings and consultations over the past four years. The road to consensus requires patience, openness, and a willingness to listen. We remain committed to contributing to this process in that spirit, seeking outcomes that reflect the collective wisdom of the entire international community. We fully support the global points upcoming directory, which holds great promise for building cross-border trust and cooperation. To reach its full potential, we encourage targeted capacity-building efforts, including collaborative training and regional exchange, so that all states, regardless of maturity, can benefit equally. Regional institutions, such as the OIC CERT, offer valuable experience and insights. Indeed, we see great potential in strengthening linkages between such bodies and the UNL process to foster greater cohesion and a more effective implementation of global norms. Mr. Chair, allow me to turn to my colleague. Thank you, Mr. Chair. We welcome the reaffirmation in the Zero Draft that existing international law applies to cyberspace, and we support continued dialogue in this area. Recognizing that dialogue alone is not enough, we must take practical steps to strengthen understanding and, importantly, compliance. That is why we urge states to commit to the formalization of expert briefings that draw on their legal expertise, as well as technical knowledge of international and regional organizations and regional and national cybersecurity agencies. We also welcome the reference to women’s meaningful participation. Here, too, we see an opportunity to lead by example, by promoting gender parity in national delegations and ensuring that women cybersecurity leaders are actively involved in OEWG discussions and consultations. The Arab Association for Cybersecurity stands ready to contribute to regional capacity-building efforts in close collaboration with international partners. Our initiatives include delivering cyber diplomacy trainings aligned with UN frameworks, fostering trilateral partnerships between the UN, Arab cybersecurity centers, and academia, and promoting hands-on workshops tailored to the needs of developing states in our region. We believe that capacity-building is not only a technical goal, but a powerful enabler for mutual trust and understanding. In closing, as the working group moves forward towards finalizing its final report, we reaffirm our commitment towards active and constructive participation. We stand ready to support a smooth transition toward the future permanent mechanism, which will carry forward the inclusive spirit that has defined this process. Thank you.
Ambassador Gafoor (Chair)
Thank you very much for your contribution. S. Walter Redland, School of International Studies, Centre of Excellence for National Security.
Centre of Excellence for National Security (RSIS)
Thank you, Chair, for the floor and for all of your hard work in including stakeholders. We appreciate the references in the draft to the contributions that all interested parties and stakeholders can make to the Future Permanent Mechanism. Now, building on paragraph 17K of Annex 3, we propose the following process to organize hybrid consultative meetings with all interested parties and stakeholders during the inter-sessional period, building on the practice of the previous OEWG and our regional experience in capacity building and confidence-building measures as a think tank. I invite everyone to view our written statement, which is posted on the UN OEWG website, which also includes a graphical representation of our proposal. Point 1, the Chair of the Future Permanent Mechanism or the thematic study groups can appoint a corresponding non-governmental Track 2 counterpart to organize stakeholder study groups of all interested parties and stakeholders to support the respective dedicated thematic groups of States. Point 2, each corresponding stakeholder study group can convene regional, cross-regional, or global meetings in hybrid modalities over the course of the year to enable wider participation, sustainability, and equitable geographic representation, regardless of accreditation, visa status, time zone, or funding. These stakeholder study groups can gather relevant expert analysis, generate actionable ideas, foster dialogue, and develop non-political recommendations to the respective thematic groups. States or other interested organizations can fund the conduct of these study groups as a means of capacity building. Point 3, States participating in the thematic groups can interact on a Track 1.5 level with the stakeholder study groups so that both technical experts and policy experts can have interactive dialogue, as the combined contributions of both are essential. Point 4, the outcomes of the stakeholder study groups can be presented as memoranda to the respective dedicated thematic groups of States. States can identify experts to brief them on the findings of the study groups following the precedent of the Global Roundtable on Capacity Building. Chair, this proposal does not contradict or detract from the existing modalities for the inclusion of all interested parties and stakeholders into the Future Permanent Mechanism or for any proposals to amend the modalities. This is instead a proposal to complement the modalities to ensure stakeholder contributions remain meaningful, relevant, consultative, and non-political in nature. We draw on the precedent of CSCAP, or Council for Security Cooperation in Asia Pacific, which is a non-governmental Track 2 counterpart that carries out the same function in assisting the ASEAN Regional Forum (ARF), which is the official governmental forum for security dialogue. This multinational entity has experts participating from all ASEAN Member States, Australia, Canada, China, Europe, India, Japan, Korea, Mongolia, New Zealand, Papua New Guinea, Russia, the U.S., and the Pacific States. Our Centre stands ready to support, host, or organize.
Ambassador Gafoor (Chair)
Thank you very much for your contribution. I give the floor now to Nuclear Age Peace Foundation.
Nuclear Age Peace Foundation
Chair, Excellencies, distinguished colleagues, ladies and gentlemen. My name is Lydia Peavy and I am a youth activist with the Nuclear Age Peace Foundation and Reverse the Trend, NAPF’s youth initiative. I grew up in Singapore and am proud to be a Singapore permanent resident and appreciate Singapore’s efforts in guiding the OEWG’s process. I would like to recognize that the OEWG has strengthened global norms and opened space for more inclusive dialogue. Chair, I will focus my remarks on the importance of civil society and youth engagement in the OEWG’s process and particularly on the critical role that youth can and must play as we transition to a future permanent mechanism. The draft final report acknowledges that engagement with civil society, NGOs, academia, and youth has strengthened legitimacy, transparency, and effectiveness in the OEWG’s work, but we must go further. In paragraph 52M, the report encourages states to engage other interested parties, stakeholders, and youth in capacity building and training. This is critical, but we urge member states to treat youth not just as recipients of training, but as co-creators of policy. Youth engagement brings community insight and an understanding of how technologies are used, abused, and experienced firsthand. Civil society is not just a supporting actor in global cyber security governance, but comprises implementers, technical experts, educators, and especially in the case of youth, digital natives who understand how these technologies function and how they affect our societies. The report’s recognition of the need for diverse and sustained engagement must be backed by practical steps, including regular consultations, technical cooperation, inclusive cyber capacity building, and clear pathways for stakeholder input in norm development. We are highly concerned about attempts to backtrack and limit the role of stakeholders. Chair, our generation will live with the consequences of today’s decisions on digital security and governance, whether it’s AI-enabled conflict, the misuse of cyber tools against civilians or governmental actors, or attacks on critical infrastructure. The risks are real and youth engagement is crucial in shaping responses. The OEWG has laid a strong foundation, but the future permanent mechanism must go further in embedding civil society, especially youth, as partners in this space. Finally, as someone who grew up in Singapore and now works with young peace builders from around the world, I’ve seen what happens when youth are given the tools and the trust to lead. The future of ICTs depends on us. Let’s build that future together. Thank you.
Ambassador Gafoor (Chair)
Thank you very much for your contribution. I give the floor now to Youth for Privacy.
Youth for Privacy
Thank you, Chair, for giving me the floor. My name is Jaywon Choi, and I am speaking on behalf of Useful Privacy and the DMUN Foundation. I am also a 16-year-old young person, representing the marginalized voices of children in this process. Chair, as we go through the final session of the Working Group, we commend the recognition of several cross-cutting issues and would like to offer our three reflections. First, we demand an open and inclusive future mechanism. As the draft report highlights, the Working Group engaged stakeholders in a systemic, sustained, and substantive manner. We believe that this model of inclusive dialogue must continue further. In particular, the sustained interest of civil society organizations and other stakeholders throughout the sessions is the living evidence for the value of our contributions. Meaningful progress requires diverse voices. Second, we call for somatic flexibility in the works of the permanent mechanism. We strongly support the idea that the future mechanism should be integrated, policy-oriented, and cross-cutting. We also stress that somatic structures must remain adaptable to quickly address emerging risks and new technologies. Finally, and most importantly, youth engagement is never optional. It’s inalienable and is part of our fundamental rights. While the final report affirms the importance of the participation of certain stakeholders, we note a concerning and relative silence regarding the role of children and youth. As previously stated, children and youth possess relevant lived experience that brings valuable contributions to the Working Group and the permanent mechanism. Hence, we urgently demand that children and youth become systemically embedded into the permanent mechanism as valid stakeholders. Distinguished colleagues, Mr. Chair, the success of the permanent mechanism will rely on the openness, agility, and commitment to inclusive stakeholder participation. We, as children and youth of the world, will not allow ourselves to be pushed out to the sidelines in this process. I thank you.
Ambassador Gafoor (Chair)
Thank you very much, Youth for Privacy, for your contribution. I give the floor now to Fundación Karisma.
Fundación Karisma
Mr. Chairman, I should like to thank you for your work at the head of this working group and also for giving us the opportunity to take part in today’s discussion. I belong to a foundation, Charisma. It’s a Colombian organization working for the promotion of digital rights. We have a digital security laboratory, and we look at privacy for civil society. We would like to emphasize the need to redouble endeavors when it comes to discussions and capacities from the OEWG so that they be implemented at a local level too by participating states. We know that some governments, such as the Colombian government, are making real steps forward to improve their policies, protocols, and capacities regarding cyber security. An example is the attempt to update national legislation to create new cyber security bodies, the effective inclusion of human rights in new legislation, and strengthening human and technical capacity to respond to cyber attacks. However, from Charisma’s point of view, we believe that we need to take our discussions further with this. Yet there’s been no consensus when it comes to the regulation of technology for military use, identification of vulnerability, and capacity building in cyber security in a non-centralized fashion. There are still very important barriers here at a national level. We believe that this process is a complex one and requires multisectoral work, time, and resources. Therefore, we would like to emphasize the call that states continue with regard to local implementation. We believe that a standing dialogue mechanism should provide an opportunity for states to present regular reviews on progress in cyber security so that the many stakeholders can also make recommendations and reports in the thematic groups and plenaries. The alignment nationally from the purposes of this group will include transparency and contribute to the construction of confidence amongst the various parties. Thank you.
Ambassador Gafoor (Chair)
Thank you very much for your contribution. I give the floor now to the first incorporator.
Forum of Incident Response Teams (FIRST)
Thank you, Chair, and good morning Excellencies, Distinguished Delegates, Fellow Stakeholders. First, the Forum of Incident Response and Security Teams is just that, a forum, a platform, and a community of incident response practitioners and teams from around the world. We have over 800 members from 113 economies, including national teams, some of whom are here today, as well as teams from government, the private sector, academia, civil society, and more. We are practitioner and practice-driven. Together with the wider community, we come together to build trust, share information, and find ways to do incident response better. Nearly every aspect of the OEWG discussions involves or impacts incident response, and we have direct operational experience on many of the matters discussed throughout the process. We hope to share what works in our community to help improve outcomes for everyone. CSIRTs are central in responding to existing and potential threats, actioning norms, and acting as key actors in confidence-building measures. Driven by peer-to-peer sharing and community building, we also have practical experience in capacity building. This includes supporting the establishment of new teams, facilitating CSIRT-to-CSIRT cooperation, and delivering formal and informal mentorship, measures highlighted in paragraphs 32, 52D, Annex 1, and elsewhere in the draft report. FIRST welcomes the recognition of the importance of capacity building and echoes the need to deliver efforts in a way that is tailored to local context in Section F of the draft. In our experience, the most effective efforts take an ecosystem-wide approach, leverage proactive engagement with stakeholders, are operationally driven, and focus on long-term formal and informal collaboration and community building. With this in mind, we encourage any efforts to action recommendations 54 to 57 to not duplicate what already exists. Many of the most impactful capacity building initiatives are driven by operational communities that work behind the scenes and are unfortunately under-resourced. Duplication diverts resources further away from delivering action and collectively dilutes utility. Leveraging communities and platforms that already exist, like the GFCE, Cybil Portal, FIRST, and others as highlighted in the Common Good Cyber Nonprofit Contributions to Cybersecurity Report, build on what already works, expanding rather than replicating impact and allowing further investment to be directed toward efforts that deliver concrete action. FIRST is here as a resource with expertise to share from the incident response community. This includes developing collaborative bottom-up standards, like the Traffic Light Protocol, Common Vulnerability Scoring System, and the FIRST Point of Contact Directory. These technical standards could offer a starting point to help put OEWG discussions, like on the POC Directory, into action. We are also proud to have worked with the Women in International Security and Cyberspace WIC Fellowship to deliver a series of Toastville tabletop exercises to build awareness of how incident response works in practice and bridge technical and diplomatic perspectives. These types of meaningful contributions require more robust stakeholder modalities than captured in the current draft. We endorse the Joint Stakeholder Statement signed by 24 partners.
Ambassador Gafoor (Chair)
Thank you very much for your contribution. Global Cyber Alliance, you’re next.
Global Cyber Alliance
Chair, Excellencies, Distinguished Delegates, I’m Chris Painter, Strategic Advisor for the Global Cyber Alliance. GCA is a not-for-profit which works internationally to improve the Internet and help people and organizations be more secure online. We thank the Chair for his inclusive approach, and we welcome the emphasis on practical capacity building as a core element of cyber stability. However, we are still concerned that several proposed initiatives in the draft risk duplicating existing and ineffective mechanisms. Here are four examples. The draft calls for a new global ICT security cooperation and capacity building portal, risking duplicating existing platforms, such as the GFCE portal and the UNIDIR’s cyber policy portal, both of which already catalog projects and connect donors with implementers. The creation of a UN-managed sponsorship program would divert from successful initiatives, such as the Women in Cyber Fellowship Program or the France-Irish Sponsorship Program for small islands and developing states. Other states should consider the UN’s additional overhead and costs and decide whether they want fewer beneficiaries for more money. The proposal for standardized training and curriculum at a UN Cyber Resilience Academy risks duplicating the UNIDIR’s Academy and decades of work by civil society organizations, such as FIRST, which has trained national CSIRTs with technical hands-on training, tailored, trusted, and deployed in more than 70 countries, or CREST, working with regulators and building standards and certifications for critical infrastructure protection. Future discussions on the new UN Voluntary Fund should consider the serious risk of diverting funds from existing funding streams, like the World Bank Cybersecurity Multi-Donor Trust Fund and public-private partnerships, like Common Good Cyber Fund, which was recently launched to support nonprofit work protecting vulnerable civil society and digital infrastructure. If established, any UN Voluntary Fund should be limited to helping states participate in UN meetings and activity. These existing efforts are not theoretical. They are functioning, field-tested, and responsive to national priorities. Creating new structures in a state-only context and without integrating stakeholders risks duplication, confusion, and inefficiency. The recent Common Good Cyber report, Nonprofit Contributions to Cybersecurity, commissioned by the EU Institute for Security Studies and funded by Global Gateway, documents 334 nonprofit initiatives, but it also highlights ongoing challenges, such as lack of funding, limited policy access, and weak coordination with multilateral bodies. We need to scale what works, not replace it. For this reason, we very much support the joint civil society statement on meaningful involvement by stakeholders, which still is not reflected in the current draft. And we make a couple of recommendations in that regard. One, assess before you build. Include a commitment for annual mapping exercises in the first report to identify partnerships and existing stakeholders and how they can be integrated. And two, enhance the stakeholder accreditation and participation. To be fully inclusive and participatory, it has to be better than a single state veto, which is –
Ambassador Gafoor (Chair)
Thank you very much for your contribution. I give the floor now to Women in Cyber Security Middle East.
Women in Cyber Security Middle East
Esteemed Members, States, and Colleagues, I speak today as the Chairperson of Women’s Cybersecurity Middle East (WiCSME), a movement born from our region’s legacy of resilience, collective will, and the belief that cybersecurity is not merely a technical domain; it is a human responsibility. Starting with a verse from our Holy Quran that reflects the spirit of our OEWG journey, “Indeed, Allah does not change the condition of a people until they change what is within themselves”. This reminds us that the transformation begins from within, and today, as we all share the higher purpose of guarding our digital realm, it is our collective resolve that can take this OEWG from aspiration to activation. Women are nation-builders, and our Islamic and Arabic culture has proudly empowered women over the 1,400 years, cultivating a supporting environment that continues to produce impactful female role models across various fields. A powerful recent example of resilience was demonstrated by the Palestinian women in Gaza. Their remarkable strength and iron grit resonated globally, reminding everyone of the enduring spirit of our region. Today, WiCSME continues that legacy, uniting over 3,000 women across 22 Arab countries to strengthen cybersecurity, elevate women’s voices, and deliver sustainable impact. WiCSME is not just a network; it is a global strategic blueprint for building inclusive digital futures. Examples of that are launching CyberShe, the regional capacity-building program, with national KPIs alignment, aiming to train up to 1,500 skilled female cyber talents across the region in three years, with the first cohort launched from Kuwait. In partnership with ITU, WiCSME participants form one-third of the global cohort in the Women’s Cyber Mentorship Program. Arabic content and globalized support were introduced for the first time, serving as a global hub by connecting more than 18 women’s cyber groups worldwide to support and amplify impact. These are not just milestones of representation. They are models of regional ownership, strategic execution, and sustained impact. As we approach the finalization of our OEWG work, we respectfully propose acknowledging WiCSME and CyberShe as global blueprints for gender-responsive capacity-building, utilizing civil society as force multipliers and operational partners, and establishing inclusive payment mechanisms for the stakeholders. WiCSME’s journey is a story of our region’s culture-guided, resilience-built, and impact-driven. Let us carry this spirit forward, not as parallel voices, but as partners in progress, and be keen to cooperate in righteousness and piety, as widely advised in our Holy Qur’an. It is when empowerment meets righteousness, guided by a shared higher purpose, that we build not only a safer digital ecosystem but stronger, more compassionate nations. Thank you, Chair.
Ambassador Gafoor (Chair)
Thank you very much for your contribution. Global Partners Digital, you have the floor, please.
Global Partners Digital
Thank you, Chair, for the opportunity to speak on behalf of Global Partners Digital. We’re a human rights organization focusing on the governance of digital technologies, and thank you for your efforts to substantively engage stakeholders over the past years and to all of the states who listened to your encouragement to be here for this stakeholder session. Discussions around major cyber incidents often revolve around the technical, financial, legal, and intergovernmental consequences. However, this group has also unpacked the human impacts of cyber incidents, including at a breakfast meeting hosted by Global Partners Digital alongside the Freedom Online Coalition, Kingdom of the Netherlands, and the Government of Ghana at the group’s 10th session. This event explored how major incidents, and specifically ransomware, have cascading impacts, including on human rights and gender equality. This requires balancing technical measures with a rights-respecting, human-centric framework fostered by multistakeholder collaboration. Discussions on the human impact of cyber incidents could be better reflected in the group’s final APR to provide a clearer starting point for the future mechanism to build on progress made during the OEWG. In addition, greater detail on international humanitarian law would be useful. While recent APRs reaffirm that IHL applies to cyber operations during armed conflict, they stop short of reflecting obligations such as feasible precautions in hostilities. We appreciated Mexico’s intervention yesterday on the need for the APR to include more concrete measures related to IHL. We were also glad to hear so many delegations mention the updated paper on practical modalities for stakeholder participation supported by 42 states. This paper encourages NGOs to foster the diversity of stakeholder participation. This is something that GPD has been doing over the years at the OEWG. Through the support of our funders, we have consistently funded and supported civil society from the global majority to engage in international cyber discussions, and supported their work to translate the global norms to their regional and local contexts through rights-respecting approaches. Without including these voices, discussions in the future mechanism risk missing on-the-ground realities, and proposals risk being impractical or inappropriate for many contexts. We fully support and endorse the joint statement by a group of 24 stakeholders. A few printed copies are available by the door as well as online. We need modalities that allow stakeholder participation to go beyond symbolic consultation for us to be able to effectively support the work of states in the permanent mechanism. Thank you for this opportunity to share our views.
Ambassador Gafoor (Chair)
Thank you very much for your contribution. The last speaker is Stiftung Wissenschaft und Politik. You have the floor, please.
German Institute for International and Security Affairs
Mr. Chair, I’m affiliated with the German Institute for International and Security Affairs, or Stiftung Wissenschaft und Politik in German. We’re a think tank. I strongly support the Joint Stakeholder Statement on Stakeholder Modalities in the Future Permanent Mechanism. The statement is an example of cross-regional coordination among stakeholders, as encouraged by you, Mr. Chair. It provides action-oriented proposals for ensuring meaningful stakeholder contributions to the future permanent mechanism. To quote from the statement, ensuring meaningful stakeholder participation is primarily for the benefit of UN member states, also against the backdrop of limited resources and expertise. Researchers like me have continuously provided evidence-based scientific expertise that is directly relevant to the OEWG discussions. I encourage states to make use of this opportunity by elaborating modalities that allow for substantive stakeholder participation. Finally, as an affiliate of an organization with ECOSOC consultative status, I wish to acknowledge the long-standing practice that the participation of such organizations, which have undergone a rigorous application process, is a cornerstone of stakeholder participation in UN processes. Mr. Chair, I would also like to address the issue of action-oriented dedicated thematic groups of the future permanent mechanism. Faced with the question of how to design these groups, I advocate for a cross-cutting approach that addresses specific issues across all pillars of the framework. One concrete example showcasing the benefit of this cross-cutting approach is the issue of software supply chain security, which several delegations have raised during the sessions. I suggest that one of the dedicated thematic groups to be established tackle this cross-cutting issue as one of its agenda items. Software supply chain security remains a difficult problem, as insecure software products and components and lacking security practices of suppliers and service providers are the root cause of many cybersecurity incidents around the world. It is also a matter for norms implementation, as norm I spells out an obligation for states to take action to strengthen software supply chain security. While this norm to date lacks broad implementation, stakeholders have made meaningful action-oriented suggestions on which policy actions such implementation could entail. Finally, the topic also has implications for international law and capacity building. In such discussions, stakeholders hold crucial expertise and can support states in advancing the debate towards concrete results. This example underscores that stakeholders need to have a voice, particularly in the dedicated thematic groups. Thank you, Mr. Chair.
Ambassador Gafoor (Chair)
Thank you very much for your contribution. Dear friends, that was the last speaker on the list of stakeholders, and I want to take this opportunity to thank all of them, all the stakeholders who spoke this morning, for their very well-prepared, thoughtful contributions. We heard several suggestions and ideas, and I hope that Member States have listened carefully and taken note of these ideas and suggestions. My thanks also to the stakeholders for having been engaged in this process over the last few years. Some of you have been in this process from the beginning, others have joined recently. Your organizations have been engaged consistently, and I thank you for that. I’d like to suggest and request that the stakeholder community, who are represented here in this room, become advocates for this process, become ambassadors for this process, as we make the smooth and seamless transition to the future permanent mechanism. You are familiar with the work and discussions here, you are familiar also with the challenges that we are dealing with, the diversity of views, the deep differences also in positions, but also you are familiar with the progress we have made, the convergence that has emerged on a range of issues, and the work that remains to be done. So be empowered to become our advocates and ambassadors as we make the transition to the future permanent mechanism. The other thing that I want to say is that the group here is, of course, a diverse group, and the group here present in the room is a function of the modalities that we have. That has been the decision, but it is my hope that we can, in the future permanent mechanism, continue to grow this group, expand the circle of participants, but at the same time expand the diversity of representatives, so that we have representatives from different parts of the world, so that we have representatives from different segments of the population. The youth, for example, it’s very heartening to see youth representatives who have taken their time away from their studies to be engaged in this process. I find that very heartening and hopeful for the future permanent mechanism. So we need to do better in terms of expanding the circle of participation and also improving the diversity of representatives who will be able to participate in the future permanent mechanism. Now, I have also taken note of the joint stakeholder statement on modalities. This, of course, as all of you know, is one of the most challenging issues that we have faced in this process right from the beginning, and it is with us even as we near the end of our work. We’ll need to find an equilibrium that is possible within this process, but my message to the stakeholders and also to Member States is this. The modalities are important, and it is important to have as inclusive a modality as possible. But if we are not able to arrive at perfect modalities, then we have to find other ways to continue to widen the circle of participation and enhance the diversity of representatives. For example, the modalities that we have for stakeholder participation do not prevent any Member State or anyone else from convening side events or track 1.5 or track 2 events, and I think there have been some ideas in that regard. So I’d like all of you to think about it. We have within this process under the previous OEWG we have been able to convene OEWG stakeholders for a dialogue here at the UN, so that option and those kinds of possibilities are still open to us regardless of what modalities we arrive at. So I’d like all of you to think very creatively in terms of how we can continue to expand and widen the circle of stakeholder participation. So these are some thoughts that I have, and my thanks once again to the stakeholders. Please stay engaged, please stay in touch, please also wish us luck as we continue our work over the next few days to cross the finish line. And of course, please share your statements in writing with us and with my office so that we’ll put it on the website. I think the views of the stakeholders are an important record and a checking mechanism to what Member States are saying. It’s an alternative point of view, and it’s really important that we hear them and reflect on them. So thank you very much once again to everyone. Now, distinguished delegates, we’ll now, as I said earlier, or rather yesterday, we have about one hour and 40 minutes. I have about 30 delegations, in fact, 35 delegations which have asked to speak. So I have to do what I wasn’t planning to do, which is to put a three-minute time limit and a microphone cutoff. Don’t look at this as the chair being nasty and mean, trying to muzzle you, but look at it as us collectively sharing a limited resource, which is time. And I encourage delegations to stay within the time limit, and we’ll have to refer to all delegations. One option is to let you speak, and then we’ll have to adjourn at 1 p.m., but that will not be fair to delegations which are not able to speak. There’s no easy way out, but I think I’d like to give everyone an equal opportunity so that we collectively share the limited resource of available time, and that collective sense of sharing that limited resource in itself is what this exercise has always been about, about creating a community, creating understanding, and listening to each other as well, listening to everyone, so that we give everyone a chance. So with those remarks, I will now open the floor, not open the floor, I mean rather I will go to the list of speakers that we had left from yesterday morning, which starts with El Salvador and Switzerland. Now, as your name is announced, some of you have also indicated to the secretary that you would like to withdraw your request for the floor. That is appreciated as a way of saving time. As you are given the floor, if you would like to withdraw your request for the floor, that will also be noted, but if you would like to make your intervention, then we will allocate three minutes to your delegation and to all delegations. So El Salvador to be followed by Switzerland, and the speakers list yesterday was from sections A to F, but if you choose to address also the section on RID by all means. And then I also have some remaining speakers from yesterday afternoon on the RID section, about six speakers. So all in all, we have about 30 speakers, about 35 speakers. So let’s listen to everyone this morning. El Salvador to be followed by Switzerland.
El Salvador
Thank you very much, Mr. Chairman. Looking at the remaining sections of the final report, our comments will be very brief. Regarding norms, rules, and principles of responsible behaviour, we welcome the redrafting of paragraph 34C by eliminating the reference to non-state actors, which we believe is consistent with the applicability of the framework for responsible behaviour. We also welcome the rewording of paragraph 34E and the addition of 34N, which recognize the voluntary nature of these norms and how they are complementary with international law. When it comes to international law, as many delegations have stated when they took the floor before me, we believe that this section does not fully reflect the tenor of the discussions over the last few years and would be better if there were more progressive language. In particular, we regret the deletion in the new paragraph 46 of an important reference as to how these references by operations using ICT can mean use of force when comparable with traditional means. Indeed, the previous language of 42B was more accurate, particularly regarding future areas for discussion, such as obligations on territorial integrity, the importance of life, and the protection of critical infrastructure and data under international law. Lastly, we regret that there is no inclusion of any significant reference to the implementation of IHL in cyberspace. In particular here, regarding the limitation of cyber operations in the context of armed conflict, the protection of critical infrastructure against cyber attacks, and also the implementation of IHL doesn’t legitimate cyberspace as an area for conflict. When it comes to confidence-building measures (CBMs), we like the new wording in the new paragraph 46F when it comes to the implementation of J, the provision on responsibilities, and also recommendation 58, looking at the capacity building aligned with the needs of developing countries and their priorities respecting their national sovereignty and approval there. As many countries have said, it is vital to retain focus on national capacity in this final report. This is not just a priority for developing countries; it is essential for the digital ecosystem. We would like to say that we support this capacity building initiative as suggested and the sponsorship program looking at experts being used in capitals.
Ambassador Gafoor (Chair)
Thank you very much, El Salvador, for your contribution. Please send us your statement. Switzerland has asked for the floor, to be followed by Paraguay.
Switzerland
Thank you, Chair, for giving us the floor again. We initially wanted to comment on Chapters C, D, E, and F. However, in the interest of time, I will focus on international law, and we will send our full statement to the Secretariat. However, we strongly regret this unequal treatment and the cut-off. On international law, we would first of all like to congratulate Thailand and the Republic of Korea on the publication of their national positions on the application of international law in cyberspace, and New Zealand on their updated position. Over the last five years, many states and regional organizations published their national positions on how international law applies. They are an invaluable source of clarifying the law, and they draw a clear picture. Cyberspace is not a lawless space, neither in peacetime nor during armed conflicts. Indeed, discussions on international law, particularly IHL, have developed substantially over the past five years. As numerous previous speakers have mentioned, this is particularly evident in the many contributions to the debate, especially across regional working papers, but also in the publication of many national and regional positions on the application of international law. However, this progress is not yet adequately reflected. Chair, we think that you have a unique opportunity to reflect the rich discussions that took place, and we trust you that you will try to do so in REV2 and give the text the necessary balance, as this is not the case yet. Therefore, now in detail to Chapter D. In Para 40C, the sentence, start quote, “an ICT operation may constitute the use of force when its scale and effects are comparable to non-ICT operations, rising to the level of a use of force,” end quote, has been deleted at the end. It needs to be reinstated as requested by Brazil, the UK, and many others. With regards to Para 41, we welcome the mention of state responsibility, due diligence, and international humanitarian law in the list of topics. However, international human rights law should also be included here, as this was discussed and raised by numerous delegations, as well as the cross-regional paper on areas of convergence. We support the good proposition by Poland. We welcome the mentioning of the two procedural working papers on IHL and on areas of convergence. What we can’t understand is why Para 41 refers to the document A-77-984, as this is not a contribution to the substantive discussions of the concrete application of international law in cyberspace, but a proposal on a convention. This reference needs to be deleted. The phrase “and the possibility of additionally legally binding obligations” has nothing to do with the application of existing international law in cyberspace. We propose to delete it. We welcome the positions of the EU and the European Union that are mentioned. The same applies to the resolution of the 34th International Conference. However, since the resolution represents a consensus outcome, we believe it merits a separate paragraph. We support the proposal made by the Netherlands, propose adding substantive language on IHL from OP4 of the resolution. More generally, on IHL, I would like to refer to the joint statement by the co-chairs of the ICT Workstream on Thank you.
Ambassador Gafoor (Chair)
Thank you very much, Switzerland, and thank you for your understanding as well. Paraguay, to be followed by Mauritius.
Paraguay
Yes, thank you. Good morning, sir. I think, looking at what was said yesterday, we still have outstanding applicability of international law to cyberspace, and in particular, the Charter of the UN, which has clear principles and purposes when it comes to sovereign equality of states and when it comes to maintaining peace and security in the international arena, and supporting friendly relations amongst nations. This is especially referred to in the preamble to the Vienna Convention on Diplomatic Relations. Thank you.
Ambassador Gafoor (Chair)
Thank you very much, Paraguay. Mauritius, to be followed by South Africa.
Mauritius
Thank you for giving me the floor, Chair. The Mauritian Delegation would like to reflect on Agenda Items C, D, E, and F. In the interest of time and taking into consideration the Chair’s guidance, we will limit our intervention to the most salient points. In line with Paragraph 34b on Rules, Norms, and Principles of Responsible State Behaviour, we emphasize the importance of a whole-of-government approach in the national implementation of norms. We also wish to highlight that regional organizations can play a critical role in supporting and complementing national implementation efforts. Therefore, we propose that the language be strengthened to read, States emphasize the importance of whole-of-government coordination in the national implementation of voluntary non-binding norms of responsible state behaviour and in raising awareness of these norms across all relevant sectors. In this context, States recognize that regional organizations can serve as vital partners in facilitating the implementation process, particularly by supporting capacity building efforts, promoting regional cooperation, and addressing shared challenges stemming from technical gaps, diverse legal systems, and regional specificities. We further believe that since Paragraphs 34b and K are interrelated, it could be beneficial to integrate the content of the two paragraphs into a single cohesive paragraph, keeping the essence of global, regional, and national aspects. Moving on to Paragraph 34f, we affirm that the designation of CI and CII remains a sovereign prerogative, and we support the development of national risk assessments, training programs, and frameworks to ensure their protection. We believe that for an effective CI or CII framework implementation, the first step is the identification of critical services and owners, and this is often a challenging task for many developing States. We therefore recommend that a comprehensive guideline on the identification of CII be developed as part of the activities of the future permanent mechanism. Now, with regards to confidence building measures, we express our full support for the global POC directory and to ensure meaningful and inclusive participation, we encourage efforts to support POCs from developing countries to participate in person and call for comprehensive capacity building support to empower all States to actively engage with the directory. Now, coming to capacity building, we express support for new initiatives such as the proposed digital tool for norms implementation and the UN Cyber Resilience Academy under UNIDIR. We believe that these tools can provide practical support and long-term resources for States, especially those with limited capacities. I thank you, Chair.
Ambassador Gafoor (Chair)
Thank you, Mauritius. South Africa, to be followed by Australia.
South Africa
Thank you, Chair. The South African delegation agrees with the sections on norms and international law as drafted, and we wish to make a brief remark on the norms section. Paragraph 34E in the norms section clearly outlines the purpose of common templates for requesting assistance and responding to requests. Therefore, we propose renaming Annex Chair 2 to better reflect this purpose. Specifically, we suggest changing the title to Templates for Requests for Assistance, instead of Template for Communication. We consider this common template an essential tool for both requesting assistance and responding to requests, which can be implemented on a voluntary basis. We appreciate the recognition in subparagraph 34M of the value of developing targeted ICT security capacity building programs to address implementation challenges and capacity gaps. Paragraphs 34P and 34Q accurately reflect the group’s discussions over the past four and a half years, and we support their attention. South Africa also supports the inclusion of Annex 1, the voluntary checklist of implementation. Turning to sections E and F, South Africa supports the sections on confidence building measures and capacity building as drafted, with a minor proposal on paragraph 46B to delete part of the sentence after footnote 67. That is the sentence starting with noting also that the principles of the POC directory as encapsulated in Annex A of the second APR should be retained until the POC is fully operational without burdening the directory with additional responsibilities. Thank you, Chair.
Ambassador Gafoor (Chair)
Thank you, South Africa. Australia, to be followed by the Republic of Korea.
Australia
Thank you, Chair. I’m taking the floor on items E and F. Australia aligns itself with the Pacific Islands Forum Statement and makes the following remarks in its national capacity. On confidence-building measures, we welcome many of the amendments that have been made in REV1. On paragraphs 46E and 50, we suggest the template for communications be retitled voluntary template for communications to underscore this point and be consistent with the voluntary checklist of practical actions. On paragraph 45L, we do not consider it appropriate to include a reference to one CBM proposal made by a single state which has not been thoroughly discussed or widely supported and strongly recommend deleting it. On capacity building, which is foundational to developing the capabilities necessary to increase state cyber security and resilience and implementing the framework for responsible state behavior in cyberspace, we must also be conscious of the context of UN80 and we need capacity building that is cost-efficient, leverages existing resources, and avoids duplication. On paragraph 54, while Australia supports the objectives of the Global Roundtable, it is unclear how they would interact with capacity building discussions in the plenary or dedicated thematic groups, when they would be scheduled, or how they would be funded. We therefore support France’s updated proposal to convene the Global Roundtable under DTG1 on resilience. We also support Brazil’s suggestion to delete high level to give more flexibility on the format and level of participation. On paragraph 56, in principle, Australia supports a sponsorship program funded by voluntary contributions to assist LDCs, LLDCs, and SIDS participation and to encourage the full, equal, and meaningful participation of women in future permanent mechanism meetings. In practice, Australia is a proud sponsor of the Women in International Security and Cyberspace Fellowship, which has supported over 120 women from 55 countries to participate in the OEWG and is considered best practice and cost-efficient. We strongly support retaining reference to it in paragraph 52M. We also note the French, Irish, and Singaporean sponsorship programs. On paragraph 57, agreeing to continue discussions on a UN voluntary fund is already covered under paragraph 53. It is premature to prescribe the direction of discussions, especially in the context of major fiscal constraints and many alternative funding instruments available. Thank you, Chair.
Ambassador Gafoor (Chair)
Thank you, Australia. Republic of Korea, to be followed by Latvia.
South Korea
Thank you, Chair. I’m taking the floor to speak on CBMs and capacity building. Chair, on CBMs, we aligned ourselves with the statement by the representative of Ghana yesterday, and we believe that the purpose of CBMs is to reduce misunderstanding, enhance predictability, and prevent the escalation of conflicts. In this regard, we would like to underscore the critical role of information sharing through the Global Point of Contact Network. For the POC network to function effectively as a CBM, it is crucial to ensure broad participation by member states. In this regard, we welcome Paragraph 46E, which encourages the flexible and voluntary use of the POC template developed by the Secretariat. Chair, in line with CBMs 5 and 6, the Republic of Korea has been hosting the World Emerging Security Forum since 2021. At the fourth forum held last December, we brought together a wide range of stakeholders, including government officials, private sector experts, academia, and civil society, to discuss key issues, including AI governance, the risks associated with the AI-WMD nexus, and international cooperation in response to cyber threats. This year, we are pleased to announce that the fifth World Emerging Security Forum will be held on September 8 in Seoul, under the theme, The Evolution of Hybrid Threats and International Security. We sincerely hope to see active participation and interest from fellow member states. On capacity building, Chair, while we welcome international support for capacity building, we believe that the most important factor for its success is establishing a structure that’s both realistic and implementable. In this regard, we are somewhat concerned that the current draft report proposes a rather excessive number of new initiatives. While well-intentioned, this may actually reduce the effectiveness and efficiency of implementation. Creating a new fund or a program does not automatically result in funding or a follow-through. It is essential to assess overlaps with existing systems and explore ways to align and streamline to ensure concrete implementation. In this regard, we do not see the necessity of Paragraph 52J. I’ll stop here. Thank you.
Ambassador Gafoor (Chair)
Thank you, ROK. Latvia, to be followed by Cuba.
Latvia
Thank you, Chair. I will make two short statements, national and joint. Nationally, Latvia aligns itself with the statement by the European Union, and I would like to stress that my delegation fully supports the establishment of cross-cutting, action-oriented thematic groups. We share your view that decisions on the group should not be postponed. We believe that a compromise proposal by France to establish groups drawing on existing formulations from REV1 is the right way to go. In line with the proposal, the groups to increase the resilience and ICT security of states, to enhance concrete actions and cooperative measures to address threats, and to promote an open, secure, stable, accessible, and peaceful ICT environment would provide the future mechanism with the action-oriented tools it requires. It would enable an issue-based approach drawing on all pillars of the framework. Chair, now I would like to switch to a joint statement on behalf of Vietnam and Latvia concerning the specific element in the capacity-building section. We welcome the Para 52i, which refers to the establishment of a UN Cyber Resilience Academy within UNIDIR as proposed by Latvia together with Vietnam and supported by many other member states, including today. That said, we regret that the proposal has not found a place in the recommendation part of the report, which would envisage a clear way forward to its implementation. There is a clear demand for capacity-building in the future permanent mechanism. The report in its current form has identified the issues and proposed a roadmap for the way forward. However, we believe that the implementation modality is still missing. The UN Cyber Resilience Academy within UNIDIR is meant exactly to be this implementation mechanism. Therefore, we would still call on you for adding a sentence in the recommendation part of the capacity-building section that reads, decides to establish a Cyber Resilience Academy hosted within UNIDIR, supported by voluntary contributions to conduct the research and capacity-building activities on cybersecurity and resilience issues under the auspices of the academy. With this, I thank you, Mr. Chair, and wish you all the luck you need to conclude these negotiations in a positive manner.
Ambassador Gafoor (Chair)
Thank you very much, Latvia, for your contribution. Cuba, to be followed by Tunisia, speaking on behalf of the Arab Group.
Cuba
Thank you very much, Mr. Chairman. I would just like to refer briefly to two elements in E on confidence-building measures. We would like to emphasize our support for retaining the reference in paragraph 46L to the new measure proposed in the OEWG on the facilitation of access of all states to the market of security goods and services for ICTs. When it comes to the section on capacity building, we want once again to say how important this is in order to eliminate the deep and increasingly growing digital divide affecting developing countries. We support that language remain robust here with the specific proposals that are reflected in the current section F. Diluting, rendering conditional, or limiting capacity building would only be against a global response that could really counter the threats looming in security and the use of ICTs. Budgetary constraints in the UN, essentially because of the denial of the major contributor, cannot be used as a pretext when it comes to addressing the needs of developing countries. Thank you.
Ambassador Gafoor (Chair)
Thank you, Cuba. Tunisia, to be followed by the Kingdom of the Netherlands.
Tunisia
Thank you, Mr. Chairman, for giving me the floor. The Arab Group would like to refer to the intervention that called for deleting 52A and I, which relates to supporting the implementation of rules and norms under the pretext that this initiative was not addressed in previous discussions, Mr. Chairman. In this context, the Arab Group reiterates that this initiative was formally proposed during the ninth session, and it was supported through a visual presentation that was uploaded to the OEWG website by Kuwait in order to make it accessible to all delegations. The initiative enjoyed the support of a number of states during the ninth and tenth sessions, and the Arab Group reiterated its full support of the initiative in a formal statement during the tenth session, and this is also available on the website. Therefore, we emphasize that we should maintain this paragraph. Thank you, Mr. Chairman.
Ambassador Gafoor (Chair)
Thank you very much, Tunisia. Kingdom of the Netherlands, to be followed by the Dominican Republic.
The Netherlands
Thank you, Chair. We align ourselves with the statements of the EU as well as the statement delivered by Ghana on behalf of the cross-regional group of the Open-Ended Working Group confidence builders and would like to add the additional remarks in our national capacity. Being grateful for all the work this Open-Ended Working Group has put into the development of the eight CBMs, we believe that now is the time to focus on their operationalization, and therefore we join others that the report should not list new proposals that were barely discussed, and we echo the call by others to delete paragraph 46L and annex 2. Moreover, while we agree that the implementation of norm J is important, we are cautious to single out this norm on reporting of ICT vulnerabilities in paragraph 46F under this CBM’s chapter and not the other norms. In paragraph 46J, we ask to explicitly recognize the role of regional organizations and the technical community alongside other stakeholders as they play a critical role in the implementation of CBMs. Lastly, on paragraph 48, as we have encountered obstacles with the practice of the POC directory, we are in favor of first focusing on the effective, inclusive, and constructive operationalization before developing it further. Therefore, we wish to include the language in a step-by-step manner, as also mentioned in paragraph 46C. Chair, allow me to turn now to capacity building. Underlying that capacity building should be an essential element in the future mechanism, we have highlighted the proposal on functions on capacity building in the future mechanism under regular institutional dialogue. So now I will only focus on some additional text proposals. We took note of paragraph 52B on the need to enhance availability of capacity building and leadership programs, and we would be keen to see other active fellowships with a similar objective reflected. For example, the Women in Cyber Fellows. Regarding paragraph 52E and 52F on the ICT security cooperation and capacity building portal, we see merit of the portal serving as an official website in the future permanent mechanism. We do have concerns regarding the other functions and the complementarity with existing initiatives. And then finally, with respect to paragraph 58, we propose replacing while respecting national ownership and sovereignty with while respecting the principles of capacity building. The capacity principles adopted in 2021, the Open-Ended Working Group consensus report, also already encompass national ownership and sovereignty, but also other elements. I thank you, Chair.
Ambassador Gafoor (Chair)
Thank you. Netherlands, Dominican Republic, to be followed by Italy.
Dominican Republic
Thank you, Mr. Chair. I shall just provide you with a very summary version of our full paper, which has been provided both in Spanish and English electronically. We didn’t have the opportunity to speak in any previous session because it doesn’t appear fair to give us only three minutes this morning. Section C, our delegation once again wants to express its support for voluntary norms for responsible behavior in cyberspace. We like the inclusion of practical measures, and we support the existing norms and good practices referred to here, particularly when it comes to critical infrastructure and supply chains. We think it’s appropriate to have references to regional provisions such as those adopted in some South American states in line with the OEWG and also reference to cyber defenders. We recall that recently there’s been adoption of the practices on critical infrastructure, looking at all possible dangers there, and we support national capacity building in order really to look at the threats from ICTs. The international law, particularly the UN Charter, is fully applicable to cyberspace. We welcome the reference to regional positions, and we support the future mechanism to continue to be discussed in the practical implementation of international law in the future. We welcome the reference to voluntary national positions, and we shall be publishing our recommendations shortly. When it comes to critical mechanisms, we would say that we want to consider international law, UNIDIR in particular, in connection with South America when it comes to E and confidence-building measures of the OAS and cyberspace. We support CBMs in order to avoid misunderstanding and to strengthen interstate cooperation. We welcome the establishment of the global POC, and we urge all states to appoint a POC and improve interoperability with existing mechanisms. We hope that it will be possible to connect regional directories so that we’ll be able to improve notification in the case of serious incidents. We support the development of a cyber incident on a global scale or a common scale for requirements here. Then F, we believe that we should cover all pillars of the OEWG, looking at cybernetics and digital rights. And we are proud to note particular initiatives such as that for particularly appreciated by our states. We support the global capacitation or confidence-building portal. We want to see redoubling of forces but not duplication when it comes to cooperation here with developing countries. And the speaker is guillotined.
Ambassador Gafoor (Chair)
Thank you very much, Dominican Republic, and thank you also for your understanding. Please do share with us your full statement. I give the floor now to Italy, to be followed by Sweden.
Italy
Thank you, Mr. Chair, for giving me the floor. Italy fully aligns itself with the statement delivered by the European Union and would like to add the following element on Section F from a national perspective. Italy considers cyber capacity building to be a central and cross-cutting component of the work of the OEWG, as well as of the future permanent mechanism. CCB is also at the core of our national cyber diplomacy. That’s why we sincerely attach a great deal of importance to it. We believe that the draft final report allows for some improvements. In fact, the inclusion of several proposals, such as some of which not properly discussed, risk undermining the overall coherence of the section. See, for example, paragraph 52i. Furthermore, there seems to be an overemphasis on financial instruments at paragraphs 52j, 56, and 57, at the expense of a more integrated policy vision on what CCB is and how it can be carried out in a sustainable and inclusive way. At the same time, we must strive to avoid duplication and fragmentation. Existing tools and mechanisms, including the ongoing efforts of UNODA, UNIDIR, ITU, and the work of multistakeholder platforms such as the GFCE, should be leveraged more systematically. Italy also attaches particular importance to promoting multistakeholder engagement. Effective capacity building cannot happen in silos. That’s why we strongly support an approach that actively involves governments, the private sector, academia, NGOs, and civil society. Governments alone cannot always deliver what is needed. Technical and informed voices are indispensable for a successful and effective CCB. That’s why we believe that the language of paragraph 52m is too weak in this respect. In conclusion, Italy reaffirms its commitment to promoting a constructive and results-oriented dialogue on CCB. The latter is cross-cutting by nature, and therefore we strongly support the structure of DTGs in the future permanent mechanism, as proposed by France with the cyber POA, in order to bridge the various gaps states are confronted with. We trust in your leadership, Mr. Chair, to shape a chapter on CCB that is realistic and implementable. Thank you, Mr. Chair.
Ambassador Gafoor (Chair)
Thank you. Thank you, Italy. Sweden to be followed by Zimbabwe.
Sweden
Thank you, Chair. As previously mentioned, Sweden fully aligns itself with the statement delivered by the European Union, as well as the Nordic statement delivered by Finland. Sweden regrets that the new language in paragraph 15, that is reading, exclusively peaceful purposes. This diverts from previously agreed language and denies both the obligations and the rights given to states under international law, as elaborated on by multiple states, among others by Ukraine. Sweden therefore supports the language proposal put forward by Australia. Sweden also supports Italy’s remark on paragraph 15 regarding the potential hybrid use of ICTs. Sweden regrets that in paragraph 40C, the reference to when an ICT operation may constitute a use of force has been deleted. Sweden requests its reinsertion. Chair, the UN framework of responsible state behavior and the UN acquis is what gives us stability and security in the ICT domain. We cannot risk weakening the framework at this stage. Considering this, in paragraph 33, the UN framework must be given equal weight as the development of cooperative measures to counter threats facing states. And the overall balance in the report must be strengthened to reaffirm the UN framework and the UN acquis. Thank you, Chair. Thank you.
Ambassador Gafoor (Chair)
Thank you, Sweden. Zimbabwe to be followed by the UK.
Zimbabwe
Thank you, Chair. In the interest of time, Zimbabwe would like to focus on Agenda Item 5, Section F of your draft report, and would like to underscore the following in our national capacity. First, Chair, my delegation finds merit in needs-based and sustainable approaches to capacity building. In this regard, we support the call for tailored, gender-responsive capacity building initiatives, referenced in paragraphs 52A and 52B, that address national gaps in ICT security, institutional strengthening, technical skills transfer, and leadership development. Chair, I would also like to proceed and include the points that were raised regarding institutional capacity building, which is important. We stress the importance of South-South and triangular cooperation, as highlighted in paragraph 52C, to complement traditional North-South partnerships, leveraging shared regional experiences in Africa and beyond. Second, my delegation welcomes the proposal under paragraphs 52E to 55 on the global ICT security cooperation portal, which is defined as a neutral, member-state-driven, one-stop shop for capacity building resources. This portal must prioritize accessibility for developing countries and integrate with existing mechanisms to avoid duplication. Third, my delegation recognizes the value of strengthening computer emergency response teams, including computer security incident response teams (CSIRTs), through a structured mentorship program, joint training initiatives, and robust information-sharing mechanisms. As highlighted in paragraph 52D of the report, such efforts are critical for enhancing Africa’s cyber resilience in the face of evolving threats. Zimbabwe, therefore, calls for increased international cooperation and targeted technical assistance aimed at developing and reinforcing regional set capabilities, particularly within the African context. This would bridge the digital divide while contributing meaningfully to building a secure, stable, and resilient cyberspace for all. Chair, we also welcome the inclusion of a regular high-level global roundtable as a means to sustain political momentum on capacity building initiatives. In particular, we support inclusive participation, as outlined in paragraph 52M, notably the involvement of the youth, academia, and the private sector in these dialogues. Such engagement under agreed modalities of participation is essential to ensuring that capacity building efforts are responsive, forward-looking, and reflective of the diverse stakeholders shaping the global digital landscape. Chair, Zimbabwe emphasizes that the future permanent mechanism should prioritize concrete.
Ambassador Gafoor (Chair)
Thank you very much, Zimbabwe. UK to be followed by Colombia.
United Kingdom
Thank you, Chair. On confidence-building measures, we would like to add two additional sentences to 46b, which draws on consensus text of the second annual progress report, highlighting the voluntary, practical, and neutral nature of the POC, as well as taking into account the work of computer emergency response teams and computer security incident response teams. We’ll send our full proposal in writing. We also support paragraph 46d. Regarding paragraphs 46e and 50, we appreciate the improvements in REV1, but note the points raised by others, namely Australia, the US, and France. In the final sentence in paragraphs 46g and 49, we would like to add, “in accordance with the state’s national policies and legislations,” at the end of the last sentence. This language is from Annex A of the second APR. Regarding 46l, we are not comfortable with the elevation of a proposal by a single state in this way. We therefore agree with comments made by many others that this language should be removed. On capacity building, as stated yesterday, we continue to hear the broad consensus that capacity building should be at the heart of the future mechanism. REV2 and particularly Annex 3 could draw more on the proposals that we’ve heard, including the 11 key functions outlined by a group of Latin American states. In this regard, we continue to support further consideration of the proposals put forward by France and the Netherlands. We also agree with a large number of states that have said we should recognize the very difficult fiscal circumstances of the UN, and we therefore caution against initiatives that will increase financial burdens during the ongoing UNAT reforms. In this regard, the first sentence of paragraph 55 should read, “States agree to establish a dedicated global ICT security, cooperation, and capacity building portal within existing resources,” taking into account paragraphs 51e, f, and g. In 52b, we welcome the addition of the words “mutually agreed,” but they should also be included in the first and penultimate sentences of 52d. We will send this amendment in writing. Thank you, Chair.
Ambassador Gafoor (Chair)
Thank you very much, UK. Before I give the floor to Colombia, I have received a request from the Russian Federation to make a procedural point. Russia, you have the floor, please.
Russia
Distinguished Chair, our delegation would like to once again point out that there is a continuing problem with interruption in the webcast of this OEWG meeting in Russia through the UN Web TV website. Our experts have not been able to take part in person in today’s meeting, therefore are essentially being excluded from following our discussions at this very important session of the group. I’d like to once again underscore that this runs counter to the principles of transparency and full participation of states in the activities of the OEWG. We ask you to provide support and to take measures to rectify the situation immediately. Thank you.
Ambassador Gafoor (Chair)
Thank you, Russian Federation. I was not aware of this technical problem with regard to UN Web TV. I think it happened once before during this week, so I kindly ask the Secretary to look into this. I think the point made by the Russian Federation is a fair one. Ultimately, if we have UN Web TV, it should be accessible to all around the world, and this recurring problem does create an issue, a reasonable grounds that Russia has. So can I request that the Secretary address this, and hopefully we’ll get an update at a later stage. Thank you, Russian Federation. We’ll continue with the list of speakers. Colombia, to be followed by Ghana. Colombia, please.
Colombia
Thank you, sir. This is a summarized version of what we have to say. Looking at the paragraph on norms and principles, we support the list of practical actions for the implementation of the norms, including the recommendation included in paragraph 37. On international law, we welcome the inclusion and the reference to the working documents on international law and IHL, as submitted by the regional group of countries, Colombia included therein. However, in order to move towards a broader consensus, we think that this could be dealt with thematically in connection with the content of these documents. We also support the proposal from other delegations on this paragraph. On C and D, on the importance of developing national positions, I’d like to say that in Colombia’s case, it was a determining experience working with other countries in outlining our national position. And here we would like to make the following suggestion on paragraph 42D, as a reaction thereto our positions… applies to the use of ICT, aggregate as well… We’d like to add… practices in the process of their elaboration. On capacity building, for various sessions now, a group of countries from my region and others have submitted working documents and statements on capacity building. These are intended to provide practical considerations here. My delegation believes it’s important to include the reference to these documents and therefore we propose this in paragraph 52, after Chair’s national experience… as views of groups of the states on international cooperation and capacity building. Finalmente… And lastly, on paragraph 55, we support the proposal made recently by the UK. Thank you very much.
Ambassador Gafoor (Chair)
Thank you very much, Colombia. Ghana, to be followed by Uruguay.
New Zealand
Thank you, Chair. Ghana aligns itself with a statement delivered yesterday by the Afghan Group on Capacity Building. We welcome and support Paragraph 52B, which underscores the importance of tailoring capacity-building initiatives to the specific context and priorities of Member States. My delegation also joins others in expressing strong support for the UN Voluntary Fund. In this regard, Ghana welcomes Paragraphs 52J and 57, and we are of the view that these should be retained in the final report. We also support Paragraph 56 on the establishment of a sponsorship program administered by the UN Secretariat. Ghana supports the proposal to establish a dedicated global portal for ICT security cooperation and capacity building, and looks forward to its timely operationalization. We also recognize the importance of existing initiatives such as the High-Level Global Roundtable on ICT Security, as well as fellowships like the Women in International Security and Cyberspace Fellowship and the UN Singapore Cyber Fellowship. In this regard, we express support for the creation of an additional fellowship program under the auspices of the United Nations. Finally, we support the views expressed regarding the vital role of regional organizations in capacity building and the importance of showcasing the impactful initiatives already underway. We likewise welcome the proposal to establish a Cyber Resilience Academy hosted by UNIDIR as a further step towards strengthening global capacity in this area. I thank you.
Ambassador Gafoor (Chair)
Thank you very much. Ghana, Uruguay, to be followed by Ukraine.
Uruguay
Thank you very much, Mr. Chairman. Uruguay has participated in the Group on Confidence-Building Measures together with Germany, Australia, Brazil, Canada, Chile, Colombia, and Ghana, inter alia. This is in line with our working document submitted by our country, believing that this is fundamental for the peaceful use of cyberspace and strengthening capacities here and minimizing conflict. We also appreciate the list of voluntary measures, including implementation of the PACE directory and looking at CBMs under the future standing mechanism. Lastly, we emphasize the work done regionally and sub-regionally to build confidence, such as in the OAS, and we wish to look at specific priorities and context here. We wish to see these organizations connected with the future standing body. Thank you.
Ambassador Gafoor (Chair)
Thank you very much, Uruguay. Ukraine, to be followed by Cameroon.
Ukraine
Thank you, Chair. As we advance in the discussions, Ukraine fully aligns itself with the statements previously delivered by the European Union, and our delegation would like to make some additional remarks in its national capacity on CBMs. At the outset, we cannot but recognize the progress that OEWG has achieved on this issue, which includes the adoption of eight CBMs and the establishment of the POC directory. Returning to the revised draft final report, Ukraine does not support the development of additional CBMs at this stage. We observe that the potential of the CBMs already in place has not been explored to its fullest yet. The example illustrating how CBMs used, particularly CBM-3, can already add to the functioning of the future permanent mechanism was given during yesterday’s intervention by Ukraine. We would also suggest refraining from the inclusion of such proposals as the development of technical ICP terms and terminologies, since such proposals have not been discussed in depth. In general, we emphasize the need to focus on the further development and implementation of the eight agreed CBMs, and further effective functioning of the POC directory. Therefore, at this stage, we should ensure that the POC directory is fully functional before moving to the further development of this mechanism. On capacity building, Ukraine supports the convening of regular global roundtables on ICT security capacity building under the auspices of the future permanent mechanism. However, we would suggest that such roundtables are held at the expert level rather than at the high level. We believe that such meetings could include capacity building practitioners, representatives of states, and other interested parties and stakeholders, including businesses, non-governmental organizations, and others. We also support the establishment of a dedicated global ICT security cooperation capacity building portal as paragraph 55. However, we consider it is important to avoid the duplication with the existing initiatives, such as the cyber policy portal of UNIDIR, and civil portal of the Global Forum on Cyber Expertise. We remain committed to working constructively towards achieving a positive outcome at this session.
Ambassador Gafoor (Chair)
Thank you very much, Ukraine. Cameroon, to be followed by Vietnam.
Cameroon
Thank you, Chair, for giving my delegation the floor once more. My delegation would like to make the following remarks on Section E and Section F. On Section E, which focuses on capacity building measures, and Paragraph 48, which focuses on the global POC directory, Cameroon supports the functioning of the POC directory but proposes amending Paragraph 48 to include that the directory shall integrate regional POC networks to enhance easier response, leveraging the template in Annex 2. This addition reinforces Paragraph 46B on the POC’s contact directory’s purpose and Paragraph 11 on regional organization. On Paragraph 49, which focuses on the simulation exercises, we propose the addition of this statement: exercises should prioritize scenarios affecting least developing countries, with post-exercise reports shared via the Global ICT Security Cooperation Portal. On capacity building in Section F, my delegation emphasizes the critical importance of Section F, particularly Paragraph 57, on the proposed UN Voluntary Fund. To transform this concept into actionable progress, my delegation proposes the following amendment. In Paragraph 57, the current text should be replaced with: the future permanent mechanism shall operationalize a UN Voluntary Fund by 2026 with resources prioritized for least developing countries and African states in accordance with the ICT security capacity building principles in the 2021 OEWG report in Paragraph 56. Thank you, Mr. Chair.
Ambassador Gafoor (Chair)
Thank you very much, Cameron, for your statement. I give the floor now to Vietnam, please.
Vietnam
Thank you, Chair. I’m delivering this statement on behalf of a cross-regional group of States that includes Australia, Chile, Colombia, the Dominican Republic, Ecuador and El Salvador, Estonia, Fiji, Germany, Kiribati, Moldova, the Netherlands, Papua New Guinea, Romania, Thailand, Uruguay, Vanuatu, and Vietnam. We have come a long way. Over the years of this OEWG, States from all regions have engaged in increasingly detailed and substantive discussions on international law. These discussions have helped reinforce capacity, build confidence, and deepen our common understanding of how international law applies in cyberspace. These common understandings on international law are a key output of this OEWG. Our cross-regional group has presented proposals in our paper that represent areas of emerging convergence on international law, based on our discussions, and has also reflected in States’ national positions. Regrettably, the current iteration of the report does not reflect these important understandings that we have reached. We are prepared to be flexible. We are open to compromise. In this spirit, we would therefore like to propose the following streamlined and qualified language for inclusion in the report, under new subparagraphs in this paragraph 40. The language reads as follows. Paragraph 40, at the OEWG’s focused discussion on how international law applies to the use of ICTs, States in the earlier, new paragraph F, discussed the need to respect and protect human rights and fundamental freedoms, both online and offline, in accordance with their respective obligations. G. Discussed how there can be an internationally wrongful act of a State when its use of ICTs is attributable to it and constitutes a breach of an international obligation of the State. H. Discussed how international humanitarian law applies to activities using ICTs within an armed conflict, including, where applicable, the established international legal principles of humanity, necessity, proportionality, and distinction. We hope that the report can, at a minimum, faithfully capture a factual record of our discussion within the OEWG. We look forward to working with all States to ensure that our hard work, rich discussion, and progress are appropriately reflected. Thank you.
Ambassador Gafoor (Chair)
Thank you very much, Vietnam, for the statement. India had asked for the floor. Are you able to take the floor now? Okay, so we’ll come back to India. I give the floor now to the ICRC and Interpol, two intergovernmental organizations which had asked for the floor since Monday, and I apologize to them as well for, first of all, making them wait, and of course for the limited time that is available to them but also to others. So, ICRC followed by Interpol.
ICRC
Excellencies, Ambassador Gafoor, the International Committee of the Red Cross is grateful for the opportunity to participate in this final substantive session of the Open-Ended Working Group. Today, there are over 130 armed conflicts around the world. ICT activities are an integral part of many of these conflicts. You, the delegations in this room, have the important task of building common understandings on the international legal rules that limit malicious ICT activities, prevent escalation in new wars, and protect civilian populations against harm if conflict erupts. This Open-Ended Working Group has done an unprecedented job in setting out today’s ICT threats. The ICRC can attest that many of these exact threats materialize in today’s armed conflicts. Our colleagues in countries affected by armed conflicts have documented cyber operations aimed at disrupting or destroying essential services for civilian populations. These operations put the lives and well-being of civilian populations in danger. Excellencies, in light of these acute threats, the ICRC sees great value in paragraphs 38 to 41 of the draft report, which reference the multiple agreements that states have reached on the application of international law, including international humanitarian law, to the use of ICTs. This Open-Ended Working Group has provided a central platform for such discussions, building on the work of several GGEs and the last Open-Ended Working Group, as well as other important processes such as the International Conference of the Red Cross and Red Crescent. Through global, regional, and cross-regional cooperation, we today have overwhelming agreements to a humanitarian red line in the use of ICTs. IHL prohibits attacking civilian objects, targeting hospitals, and launching indiscriminate or disproportionate attacks, including in the use of ICTs. During this final week of intergovernmental negotiations, the ICRC calls on all delegations to reflect this humanitarian red line in the final report. As said by many delegations in this Working Group, additional discussions are needed to ensure that IHL is effectively applied to the use of ICTs in armed conflicts. Whether this is done by building common understandings on existing law or through an additional legally binding instrument, such negotiations must not cast doubt or undermine the existing legal protection for civilian populations affected by armed conflicts. I thank you.
Ambassador Gafoor (Chair)
Thank you very much, ICRC, for your contribution. INTERPOL, please.
Interpol
Mr. Chair, Excellencies, and colleagues, thank you for this opportunity. Today, ICT security is not just a technical concern. It is a defining issue for global stability, peace, and sustainable development. In this context, Interpol welcomes Member States’ recognition, in paragraph 16 of REV1, of the threats posed by the criminal misuse of ICTs, given its significant potential to disrupt essential services and cause serious harm. And the threat is growing. Interpol’s latest Africa cyber threat assessment reported an alarming increase in cybercrime incidents across the continent. One country saw over 17,000 ransomware detections, while another faced a 3,000 percent rise in scam alerts. These threats are not limited to one region. Across the globe, we’re seeing sophisticated criminal networks using techniques like phishing, malware, and deepfakes to target citizens, governments, and businesses. These threats mirror many of those recognized in Section B of REV1 and underscore the need for collective action. Faced with this rapidly evolving challenge, Interpol welcomes and encourages Member States to continue leveraging our global capabilities and network to address the criminal and terrorist use of ICTs, in line with Norm D of the Framework on Responsible State Behavior. In support of this, we continue to strengthen trust and confidence building between our 196 member countries for practical law enforcement cooperation. Our relaunched cybercrime expert group brings together over 170 experts from around the world to examine the evolving cyber threat landscape, including the implications of emerging technologies like AI. Interpol is also embarking on new initiatives to better support Member States in countering current and emerging cyber threats. These include efforts to respond to cyberattacks targeting critical infrastructure and developing global strategies to combat the misuse of residential proxies, the expansion of IoT malware, and phishing attacks. We welcome interested partners to contribute to these efforts. As States have repeatedly emphasized throughout this OEWG, capacity building is both foundational and cross-cutting. With the support of partners like the European Union, the Council of Europe, and the United Kingdom, Interpol delivers capacity building tailored to the needs of frontline officers across different regions. These efforts are aimed at producing operational outcomes against specific cyber threats, a model that has enabled the dismantling of hundreds of thousands of malicious infrastructures and the arrests of thousands of suspects just over the last year. In closing, these results show what is possible when we work together. In this regard, Interpol is convinced that the future permanent mechanism like the OEWG can play a vital role in strengthening trust and confidence between States, the foundation on which effective international cooperation is built. I thank you.
Ambassador Gafoor (Chair)
Thank you very much, INTERPOL. Friends, we have completed the list of speakers that was outstanding from yesterday morning, and it’s now my intention to move to the other list of outstanding speakers, and there are six of them with regard to the debate yesterday on regular institutional dialogue. The list is as follows: Czechia, Guatemala, Mauritius, Belarus, Costa Rica, and New Zealand, plus India, which had asked for the floor earlier, but I think they are not yet ready to speak. We’ll give them a chance. So we have seven speakers left. I’m planning to take the list remaining as of yesterday, so we’ll start with Czechia, to be followed by Guatemala.
Czechia
Thank you, Mr. Chair. On the RID, we align ourselves with the statement delivered by the EU and add the following in our national capacity. The Czech Republic supports a structure of a future mechanism which will be inclusive, efficient, and action-oriented. That is why we reaffirm our support for the creation of thematic groups, and we stress that they should be cross-cutting, as it was very well described by our French colleague yesterday. A cross-cutting structure will best reflect the interconnected nature of cyber issues and ensure coherence across the mechanism’s work. Within one group, we will be able to discuss all aspects of a specific cyber issue, the related threats, our potential reactions to them, and also the capacity building needs which such threats are linked to. From our experience as a country providing cyber capacity building, we can clearly see that especially such capacity building which derives from specifically articulated needs is the most effective, and the cross-cutting thematic groups which will focus on specific topics under three umbrella themes—stability, resilience, and cooperation—define specific threats and identify specific gaps that need to be addressed would provide a perfect basis for a tailor-made approach to capacity building. The discussions in the cross-cutting groups would be able to cover also all other related issues, including international law, implementation of norms, or anything else that may arise in the specific context. We strongly do not agree with the creation of a specific group on international law, as the discussions on law should not stay alone without being related to specific issues that the law addresses. We consider the format of cross-cutting thematic groups to be the most convenient for efficient and to-the-point discussions which should aim at tackling the specific challenges that we are facing in cyberspace. We would still have the pillar discussions in the plenary, and we would be able to benefit in the plenary from the practical discussions held in the cross-cutting thematic groups and from their potential recommendations under a separate agenda item in the plenary, as suggested, for example, by Mexico, France, or Brazil. We also support the idea of the global roundtable on capacity building as a valuable tool for exchange of views and coordination of capacity building activities, and we agree with Brazil to strike out the high level. Concerning the indicative timeline in Annex 3, while we see merit in having the plenary taking place back-to-back with the thematic groups, at the same time we are a bit concerned about the possible loss of momentum of the discussions with having all the meetings taking place over the course of several days or weeks in July or August with actually no other meetings during the rest of the year. Also, in order to give more time for the preparation of the recommendations to be presented in the plenary, we would suggest distributing the meetings in a more balanced manner throughout the year. Finally, we also underline the importance of meaningful multistakeholder participation. Multistakeholders play an important role in identifying threats, in tackling them, and very importantly also in capacity building. We are truly convinced that while this being an intergovernmental process, the future permanent mechanism must be inclusive in all possible aspects, and that is why we cannot agree with the word…
Ambassador Gafoor (Chair)
Thank you very much, Chair. Guatemala, to be followed by Mauritius.
Guatemala
Thank you, Mr. Chairman. Guatemala would like to thank you for your leadership in this session and during the session of the Working Group, and also for producing the draft final report and the actions moving towards transition towards a permanent mechanism. We once again would like to say that we support the existence of a permanent mechanism to help us to continue with progress in the OEWG. We believe that the transition should be a fluid one and in accordance with the principles upon which we agreed. We emphasize the need to avoid duplication of efforts and processes, particularly in a context where both technical and financial resources are limited. A new sole mechanism should consolidate the existing one, strengthen what’s already worked, and harmonize rather than fragment initiatives. We also support the creation of a moderate number of technical working groups and thematic ones. And we believe it is vital that one of these should focus specifically on the capacity building pillar. This is a priority for developing countries and must be addressed in a structural fashion, looking for specific and sustainable results. We highlight the working documents submitted by a group of countries from my region, seeking to include the various dimensions of capacity building and looking at the various needs there. A specific thematic group will ensure a systematic integrated approach able to coordinate what is already being done. Guatemala also resoundingly supports the participation of relevant stakeholders. Their technical, operational, political contribution is vital to ensure that we have a transparent and inclusive participation strengthening the future mechanism. So here we support Canada and Chile’s proposal. Lastly, Guatemala once again says that we are committed constructively to the process whereby a permanent mechanism will be established and we wish to offer full support to the chair. We’re sure that after the fruitful discussions in the OEWG, we will be able to have an effective, inclusive mechanism, one that is action-oriented. Thank you.
Ambassador Gafoor (Chair)
You’re welcome! If you have any text that needs proofreading, feel free to share it.
Mauritius
Thank you, Chair, for giving us the floor. We take this opportunity to reaffirm our strong commitment to the establishment of a regular institutional dialogue on international ICT security through the operationalization of the future permit mechanism. We support the operationalization of the permit mechanism through thematic working groups as a practical and flexible modality to carry forward discussions and implementation. We believe that such a structure will promote targeted, sustained engagement and provide an opportunity for states and stakeholders to exchange experiences, propose new ideas, and address gaps based on their evolving needs. We believe the following elements must be addressed in the future mechanism. Within DTG1, we recommend the following: A non-attributive threat information exchange platform supported by technical partners, both public and private, should be set up at the level of the UN. Moreover, the existing guidance, toolkits, and repositories should be leveraged by states for the adoption of existing norms. At the same time, the modalities for the creation of new norms could be considered as stated by many other delegations. As regards to CBMHA, we also underscore the importance of ensuring that initiatives developed under the OEWG, such as global POC directory simulation exercises and capacity building roundtables, are sustained and further developed under the future permit mechanism. Their integration into the mechanism’s future work schemes will be critical to operationalizing the framework and building trust. We also emphasize the partnerships with regional organizations that could serve as an implementation bridge for policy alignment and regional implementation, as well as for supporting region-specific CBMs. Coming to DTG2, we propose the following: An inclusive legal forum including technical and legal experts, legal advisors, and other stakeholders to discuss the applicability of international law to state behavior in cyberspace. A voluntary compilation of the states’ national positions on international law could be made available on existing repositories. For the DTG3 on capacity building, we suggest the niche-based catalog as a transition to the future permit mechanism. We also support the idea of convening the global roundtable on ICT security capacity building on a regular basis. We believe the participation of earlier capacity building experts, practitioners, and other stakeholders, such as the regional organizations, technical community, and NGOs, is critical to accelerate the delivery of the capacity building. Regional organizations could act as implementation hubs to coordinate technical assistance, training, and knowledge exchange. They could also serve as the liaison bodies for the future permit mechanism. Furthermore, they could play an important role in facilitating regional dialogues and submit regional reports or positions to the UN. We also propose the setting up of a monitoring and evaluation framework for voluntary state reporting on implementation progress at national, regional, and global levels. Dashboards, as well as regular review forums, could facilitate the monitoring of the progress. In conclusion, Chair, we reaffirm our commitment to the early and effective establishment of the future permit mechanism. Thank you very much.
Ambassador Gafoor (Chair)
Thank you, Mauritius. Belarus, to be followed by Costa Rica.
Belarus
Distinguished Chair, at the outset, allow me to thank you and your team for your hard work over the past five years to ensure the continuation of the negotiation process as part of this working group, which is now in its final phase, as well as for preparing the draft final report on the work of the OEWG. We align ourselves with the opinion of the Nicaraguan on behalf of the like-minded states with regard to the draft final report. We believe that the basic principle underlying decision-making in the future mechanism must be consensus, taking into account the views of all states is crucially important in decision-making for both substantive and procedural issues. In discussing the details of the thematic groups, as we mentioned before, it’s important to find an optimal balance between, on one hand, efforts to cover a large number of issues and, on the other hand, to maintain their unique specialized nature. At the same time, it’s important to note that the establishment of thematic groups is not a prerequisite for the success of this concluding session. The main priority should be having a seamless transition between the current OEWG and the future mechanism without undermining its mandate and taking into account all five pillars. Therefore, we do not support at the current stage the first thematic group in its current proposed format, taking into account the need for a balance between norms and international law as well as the importance of efforts for confidence-building measures and capacity building. We propose creating a separate thematic group on standards and on confidence-building measures. Given the rapid development of technology, the mandate of the future mechanism should include the possibility of developing the standards on important issues such as supply chains and data security. We support the consensus-based approach toward appointing co-chairs of the thematic groups. With regard to persuasion of stakeholders in the work of the future mechanism, we believe that priority should be given to the principles of national sovereignty. We support the current format of work. We are aware of the important contributions made to the work of the OEWG by non-state entities, but we believe that all decisions on the NGO participation in sessions ought to be based on no objection from member states, and this is an intergovernmental process first and foremost. In addition, participation of accredited – ECOSOC accredited NGOs could be helpful for the future permanent mechanism. We believe the terminology of the report ought to be in line with the mandate of the group and previously agreed reports, and we also believe we should separate out the concepts of criminal activities in the area of ICT and harmful cyber activity. We also support including language on potentially developing legally binding norms that would reflect positions of the member states from the outset of the OEWG. We believe that the norms of IHL that are applicable in times of armed conflict should not – are not sufficient for regulating ICT issues.
Ambassador Gafoor (Chair)
Thank you very much, Belarus, for your statement. Costa Rica, to be followed by New Zealand.
Costa Rica
Mr. Chairman, Costa Rica supports a regular institutional dialogue with broad participation of states and stakeholders on security and the use of ICTs. Not just looking at one of the mandates bringing us here, but also we view this as a need in order to achieve global understandings based on consensus on this important matter, which is constantly in development. We wish to respect the principles of inclusivity and transparency and therefore support the documents submitted by Canada and Chile. We also recognize the value of the structure being proposed to us in Annex III on the thematic working groups. For Costa Rica, looking at capacity building, we are with particular interest to the proposal which is aimed at action with clearly identified objectives to facilitate the exchange of experiences, including their experts to promote international cooperation, to provide a platform for implementing the agreed framework, and also to ensure that it be flexible to deal with new threats. So we strongly urge in the final report that there be the inclusion of the working documents submitted by the group of countries from Latin America and the Caribbean entitled Strengthening of the Strategic Dialogue on Capacity Building and its Inclusion in the Future Mechanism. Thank you.
Ambassador Gafoor (Chair)
Thank you, Costa Rica. New Zealand, to be followed by India.
New Zealand
Thank you, Chair. On regular institutional dialogue and with your plea for brevity in mind, we will simply note that, like a great many other delegations, we support the very constructive French compromise proposal for cross-cutting action-oriented thematic groups, and we support the important proposal put forward by Tudor and Canada on stakeholder modalities. We’ve explained our reasoning for supporting these initiatives previously, so given time constraints, I won’t repeat that now. We also want to endorse the helpful reminder from Germany yesterday to take a step back and recall what we’re trying to achieve through establishing the permanent mechanism. We want to promote, protect, and implement the normative framework for responsible state behaviour, and continue to build common understanding of how international law applies in cyberspace. We want cross-cutting issue-oriented discussions to allow for concrete and meaningful exchanges, including to support effective capacity building. And we want to move forward in a single-track format. The measure of success for our work this week will be to reach consensus on establishing, for the first time, a permanent UN forum focused on ICT security in the context of international security. This will be a significant achievement, and it’s the most important signal we can send about our shared commitment to promoting an open, secure, stable, accessible, peaceful, and interoperable cyberspace. Thank you.
Ambassador Gafoor (Chair)
Thank you very much, New Zealand, for your contribution. India, please, to be followed by Nigeria.
India
Thank you, Chair. India is speaking for the first time. We appreciate the Chair’s leadership in guiding us towards consensus. We by and large agree with the REV1 draft, which reflects the consensus we have achieved over the years. We have several technical suggestions related to AI-powered attacks, ransomware as a service, etc., which we are sending to you by email. We would like to highlight some important broad principles, many of which have been highlighted in interventions of many of our Global South partners, like Brazil, South Africa, Thailand, Indonesia, Malawi, and the African Group. Mr. Chair, today a significant portion of global Internet users live in developing countries, and the governments of the Global South are also heavily invested in the ICT domain and digital governance. The Global South today stands at a transformative juncture, where technology and digital innovation are not merely tools, but have become powerful levers and catalysts for economic advancement and the realization of our developmental aspirations. In this regard, India’s own journey with digital public infrastructure, exemplified by the open architecture of India’s stack, demonstrates the profound potential of accessible, secure, and interoperable digital systems to uplift societies and accelerate progress at population scale. Let me add that India’s stack from its inception itself endeavors to implement secure by design, by default, and in deployment. It is in this spirit that we underscore the paramount importance of safeguarding cyberspace, particularly for developing nations, and that is why capacity building is of utmost importance for the Global South. Let me reiterate here that the sentiments of a majority of the states on this topic, particularly the Global Capacity Building Portal, have been aptly captured by the REV1 text. It is in this context of our developmental needs that the OEWG becomes important for us. The most important characteristics of the OEWG that we want to preserve and pass on to RID is that the OEWG is representative, inclusive, and democratic. These also abbreviate as RID. Therefore, we want the RID to be also RID. We believe that the strength of the OEWG platform lies not in the platform but in our own ability to build consensus, which was very beautifully articulated by Egypt. The ICT domain is a borderless domain where coexistence is not an option but an inherent feature of the domain. It goes without saying that harmonious coexistence requires consensus as an essential. On the importance of consensus for coexistence, I am reminded of an ancient Sanskrit verse from Rig Veda, which I will translate. It says, samāniva ākūtiḥ samānā hṛdayānivaḥ samānamastu vamano yathāva su-sahāsati meaning, let your intentions be united, let your hearts be in harmony, let your minds be in congruence, so that you may coexist in harmony. We therefore would like to highlight that we all need to come together and focus on ensuring a seamless transition to a future permanent mechanism rather than focusing on procedural specificities. Thank you, Chair.
Ambassador Gafoor (Chair)
Thank you very much, India, for your statement and your message of harmony, which is what I think we need as we come close to the finish line. Nigeria, please.
Nigeria
Chair, Nigeria aligns itself with the African Group, and I would like to make the following remarks in our national capacity. Nigeria views capacity building as a fundamental pillar of trust to bridge gaps among divergent capacities in the field of human endeavor. In our opinion, it is an upbringer of inclusivity to reduce inequality of requisite knowledge among states. It gives states equal footing in relevant discussion, obliterating a sense of marginalization, while holding up ownership in ensuring documents or outcomes of meetings. It’s a cross-cutting topic embedded in all pillars of the Open-Ended Working Group, in the security of, and in the use of, information and communication technologies, as asserted in paragraph 9 of the report on that reference. Nigeria acknowledges the elaborate consensus theme of capacity building in the report’s overview. I would like to make further suggestions on pragmatic mechanisms to consolidate it as a pillar in the future permanent mechanism. My delegation advocates practical context with actionable support for cybersecurity infrastructure and relevant staff. The transfer of knowledge should be need-based, inclusive, transparent, tailored to us, integrating it with indigenous knowledge for sustainability. The integration of modern technology with indigenous knowledge in recipient countries will facilitate the ability to nurture a diverse and skilled cybersecurity workforce. This enables such states to easily defend their critical infrastructure and critical information infrastructure against cyber threats and contributes to the nation’s digital resilience, as well as create cyber solutions for the future. It will also create a spiral effect on employment in emerging technological fields, improving economic and human developmental indices of developing countries. The gender inclusiveness in cybersecurity is vital to maximize human capacity. Women are famous for their multitasking ability, which is crucial in inculcating relevant knowledge to safeguard the cyberspace. Technology as we know it today has become an indispensable element of human subsistence. It is therefore imperative to prepare the younger generation beyond the use of social media to the complexity of cybersecurity. Teaching them from a young age increases the digital skills of any nation, and it further reduces future digital gaps between the high and low-income countries. Nigeria acknowledges the framework of international law as a second pillar in the future family mechanism, due to its complexity within the cyberspace. The guiding principle of international law is a product of multilateral efforts in ensuring responsible state behavior, and this should be applicable in the cyberspace. Let me conclude by reiterating the importance of inclusivity in global discourse. It should be championed through mutual respect, meaningful engagement, and transparency.
Ambassador Gafoor (Chair)
Thank you very much, Nigeria, for your contribution. Friends, we’ve exhausted the speaker’s list, and it’s almost 12:50, and I wanted to have some time to also share my views on how we move forward from here, so I will need some time as well for that purpose. But I wanted to also explain why we had to do the microphone cut-off. This is the first time I’ve done this in five years, and I did not do it with an easy heart, but perhaps it was not clear to you. I wanted to explain that this is also the very first time that the work of the OEWG has been subjected to cuts in meeting time allocated by the UN Secretariat. These cuts in meeting and conference services are applied across the board to all meetings of the UN. All processes, all chairs, and facilitators of UN processes have been asked to make a 10% cut. So this afternoon, this meeting room is not available, and there are no interpretation services available. I’m ready to meet you anywhere and to listen to you, but if you want to have an open-ended meeting of this nature with interpretation, which is what the UN is all about, multilingualism, multilateral cooperation, this meeting room is not available. And why do we have to cut conference services? Because the UN is in financial crisis. And why are we in a state of financial crisis? Because some members do not pay in full and on time. It’s not a secret. And why do some members not pay in full and on time? Because of a variety of reasons that’s known to them. And a related point which provides the context for our work is that multilateralism is in crisis. I don’t need to belabor that point. But before I elaborate on that, let me come back to why we had to cut the microphone. So I apologize sincerely to those who feel that you were not allowed to express your points of view, that you did not get the time you deserved. There are some, I believe, who have not even spoken. There are some who have only spoken once. And there were some who were subjected to the microphone. So I apologize for that. These were circumstances beyond my control. At the same time, this process has evolved in such a way that there is so much to say. That is a good thing. And it seems to me that we will need a two-week meeting for the future permanent mechanism. Obviously, one week is not enough for everything that needs to be said. But that is another issue. But I once again want to say that, you know, my apologies for cutting you off if you feel that you have been muzzled. Second, I want to ask in the remaining time that we have, I still have a request for a floor that has just come in. Is there anyone else who feels that you have not been heard and you need to put your views on the table? I can only go to 1 p.m. I see Albania, you have asked for the floor. Thank you.
Albania
Thank you, Chair. First, Albania fully aligns with the statement of the European Union on regular institutional dialogue and multistakeholder modalities. We also reaffirm our strong commitment to responsible state behavior in cyberspace and welcome continued progress towards a permanent and effective mechanism in line with the General Assembly’s decision on the Program of Action. We believe this future mechanism must be inclusive, action-oriented, and structured to deliver real-world solutions towards cybersecurity challenges. It should build on the existing UN framework while adapting to evolving threats and technological developments. To effectively secure cyberspace, we must focus on concrete real-world challenges and avoid duplicating efforts. This requires adding a practical dimension to UN discussions so that we can focus on Open-Ended Working Group-style negotiations in the plenary, including on international law, along with dedicated thematic group discussions focused on implementation and capacity building. Cyber threats are rarely confined to a single area. They are interlinked and complex. Therefore, we support a framework where expert-level groups focus on concrete challenges, sharing best practices, and identifying capacity-building needs, while the plenary continues to play its critical role in discussing the essentials. Clear and distinct roles for each format—plenary, DGTs, and capacity-building platforms—will ensure that efforts are streamlined, complementary, and effective. The complexity of cybersecurity demands that we leverage the full breadth of expertise available. The private sector, civil society, academia, and technical experts offer critical insight that states alone cannot provide. Transparency and open dialogue must guide our work, and we support decision-making processes that reflect the will of the majority where necessary. An inclusive mechanism is not only more effective but also legitimate. So regarding modalities, Albania believes we must move past a system in which the objection of a single state can prevent the broader community from benefiting from the expertise of diverse stakeholders. Albania has prepared its position for each of the issues discussed and will send them to the Secretariat. Albania is fully committed to working constructively with all partners to establish a mechanism that reflects our shared goals. Thank you.
Ambassador Gafoor (Chair)
Thank you, Albania. Is there anyone else who has not spoken and feels that it’s important for you to speak and you need to speak now? Djibouti, please.
Djibouti
Thank you, Chair. My delegation commends the adoption of the African Union at the following its national capacity. At the outset, I’d like, on behalf of my delegation, to take the floor for the first time to congratulate you on your leadership throughout the process. We commend your considerable efforts throughout the past five years to arrive at this document that reflects concerns on these very important issues. We also are pleased with the other reports on progress made toward a common understanding of ICT security and its challenges. We are pleased with the strengthening of confidence-building measures despite a difficult situation geopolitically. We welcome the entirety of this report. Establishment of a permanent mechanism represents a natural evolution that is necessary to continue our combined efforts, and we welcome in particular the focus on capacity building. That’s an absolute priority for developing countries. The Global POC Directory is also a promising innovation that we support. The inclusive approach allowing participation of non-state actors corresponds to modern realities in the field of cybersecurity, where the borders between public and private are blurred. We recognize the link between cybersecurity and sustainable development, which is often overlooked but is very important for developing countries. In the interest of time, Mr. Chair, we will send you our contributions in writing, and we hope the work of this 11th and last session will be successful. Thank you.
Ambassador Gafoor (Chair)
Thank you very much, Djibouti. Is there anyone else who would like to make a statement? Good, I see no further requests for the floor. Thank you very much for your cooperation, but friends, you still have the opportunity to send me your inputs and statements in writing. I’d like this process to have the collective sense that you have been heard, and I want to assure you that I and my team have listened very carefully to everything that has been said this week. I’ve taken careful notes myself, and so has my team. I’ve also received many, many of your statements and suggestions and proposals, and I thank you for them, and I will also need to go through them, and for that, I will need some time. Thirdly, I want to say that I have been very encouraged by the discussions so far. We are midway in the week. It’s Wednesday morning, and I am very gratified by the very constructive tone and the manner in which all of you have taken the floor and put forward your ideas. I’m also very encouraged and gratified by the strong commitment you have demonstrated to this process, and more importantly, the commitment that you have demonstrated to reach an outcome this week. That is my strong sense from listening to all the statements, but also that is my strong sense from my various informal meetings and consultations. Everyone I have spoken to informally, but also in the context of your statements here, everyone is committed to reaching a consensus outcome. I think that should give all of us encouragement and hope that an outcome is possible. Second, I want to say that, as I said earlier, the UN is going through a very challenging period, and therefore what we do here will send a very strong signal, positive or negative. A signal will be sent on Friday, and if we are able to reach a consensus outcome on Friday, then I think that will be good, not just for this process and for our ability to make the transition to the next mechanism, but also for the very idea of multilateral cooperation, for the very idea and vision of the United Nations. So in that sense, my dear friends, on your shoulders lies also the burden to show to your capitals, to each other, and to the world, that the spirit of multilateral cooperation is alive and well, and that additional burden arises because of the specific context in which we are doing our work. This additional burden would not normally be on your shoulders, but it is precisely because we are traversing a very difficult period geopolitically, internationally, and in the international security landscape, that each one of us has that additional responsibility to look at the larger picture and do whatever we can to reach that outcome. And as I said, what gives me hope and encouragement is the fact that all of you are committed, all of you have said to me you want an outcome, all of you have said to me you are determined to go back home with a consensus outcome on Friday. So that, I think, is the positive and the plus point. The other point that I would make is that we cannot conceal or hide the fact that there are divergences. We have heard it throughout the week. And often these divergences are expressed with regard to proposals put forward by another group of delegations or another delegation. And that works both ways. If a proposal is put forward by a delegation or a group of delegations, then there is also a counterpoint or a counterproposal or a counter request from another group of delegations. So if we look at all the proposals, there’s usually a counterpoint or a counterproposal. And that makes finding consensus very challenging. Sometimes the proposals are in terms of additional language. Sometimes the proposals are in terms of deletion. So for every proposal for additional language, there are additional proposals for deletion of the additional proposals. Sometimes the proposal is for deletion. The counterpoint is a proposal to retain. So it’s a matrix of divergences. And that is why I think the task for us is challenging. But at the same time, there are also elements of convergence. First, as I said, there is a strong commitment to reach an outcome and make that seamless and smooth transition to a future permanent mechanism. I think that there is a very strong commitment to that. Second, a strong convergence and commitment to build on all that we have achieved over the last three years as a working group, and then consolidate the outcomes, build on it, and then take it to the next process. And then there are many other details in terms of how we reflect the discussions factually, objectively. Even that is challenging because that could also come back to the points and counterpoints. Having said all of that, I want to give you another positive aspect, and that is the fact that I do see a narrow path visible and possible that will take us forward. And that is what I will try and do in preparing REV2. But it is important to keep in mind that the narrow path that is possible and visible to take a step forward is not a path that will go automatically in the direction of your capital’s views and instructions that you have. There’s a narrow path possible, but that narrow path has to be in the middle. In the middle, because we are seeking to put together an outcome that is balanced for everyone, because we are in a consensus process. If it was a question of putting things to a vote, it would be much, much easier. But we are not in that exercise, which is why we have that additional burden also of looking for and walking a tightrope, almost a tightrope, towards consensus. And that tightrope is going to be right in the middle. And therefore, I appeal to each one of you, first of all, to be very clear about your prioritization, because if you want so many things in REV2, it may not be possible to have everything that you hope to see in REV2. You need to be pragmatic, but most of all, you need to be flexible. My intention is to look for solutions that will work for everyone. I will do my best, but in the nature of UN processes, we may not be able to satisfy everyone. And therefore, you need to be very clear about your own priority issues. And then, of course, at the same time, you also need to not just take and take and take, but you also need to give and give and give. That is in the nature of seeking consensus. That is in the nature of what we do at the UN. There has to be give and take. There has to be an open-mindedness. There has to be flexibility. And we need to be pragmatic, because we can’t solve all the issues. Some of the issues will have to be left for the future mechanism. But we need to do what is necessary to ensure a smooth and seamless transition, so that we do not put at risk what we have achieved, so that we do not take a step backwards. We need to take a step forward. So, friends, these are some thoughts I have. In terms of the process, this is what I intend to do. I will, together with my team, we will be working on REV2, and it’s my intention to make that available around 9 p.m. this evening. I’ve said 9 p.m. in the past, and it came much later. Some of you will remember this. So, give me some flexibility on the 9 p.m. So, we will say 9 p.m.-ish. Thank you for your understanding. Second, tomorrow we will meet at 11 a.m., so as to give some time for you and your groups to meet, have a quick meeting in the morning. But at 11 a.m., we will reconvene, and I will present the REV2. And after that, we can have some initial remarks, and you probably will need more time to go through. But we need to look at a conference room paper by the end of Thursday, because delegations will have to seek instructions. So, we need a formal document by the end of Thursday. So, the REV2 is a step that will lead us to a conference room paper at the end of Thursday, which, by the way, is what we have done for the last few years. So, what I’m describing to you is not a novel methodology, but what we have been doing in the group. So, REV2 tonight. Tomorrow morning, we meet at 11 a.m. to allow for me to present the REV2 and to hear initial remarks. And then, we can reconvene at 3 p.m., and CRP to be put forward tomorrow, the formal document, so that you can send it back to capitals and their time zone differences. And then, Friday morning, at 10 a.m., we meet to adopt the conference room paper by consensus. It’s possible. It’s achievable. But we need to go to REV2 first. So, on that note, I want to thank you once again, and I also want to thank our excellent, excellent, excellent bunch of interpreters who are unseen, under-appreciated. So, they are the unsung heroes and the backbone of multilateralism, because they’ve given us another 10 minutes extra for that. So, thank you, dear interpreters, for that. So, friends, the meeting is adjourned. I wish you a pleasant lunch, and see you tomorrow morning. Thank you.
Leave a Reply