Session 3-2 Transcript
(OEWG 2021-25)

Home » Resources » UN Open-ended Working Group (OEWG) transcripts » Session 3-2 Transcript(OEWG 2021-25)
Ambassador Gafoor

The second meeting of the third substantive session of the OEWG on security of and in the use of information and communication technologies 2021-2025, established pursuant to General Assembly resolution 75/240 of 31 December 2020, is now called to order. Distinguished delegates, the group will now continue its discussion under agenda item 5 on the revised draft of the annual progress report on which we had begun discussions this morning. This afternoon, we will continue our discussions on the revised draft annual progress report, focusing on the sections relating to the introduction, existing and potential threats, as well as the section on rules, norms, and principles. When we adjourned this morning, earlier today, there were 26 speakers who had inscribed on the list, and I’d like to invite those speakers who had inscribed to address their comments relating to the revised annual progress report, in particular, the introduction, the existing and potential threats, as well as the section on rules, norms, and principles of responsible state behavior. Once again, I’d like to appeal to delegations to be as succinct as possible, as concrete as possible. This is not really a general debate, but an initial discussion on the revised draft annual progress report. The first speaker for this afternoon is the Islamic Republic of Iran, to be followed by the Russian Federation, Brazil, Cameroon, France, and I’ll go down the speakers’ list in the order in which we had received them this morning. So I give now the floor to the Islamic Republic of Iran. Give the floor, please. Thank you. We’ll give the floor to the Russian Federation. We’ll come back to the Islamic Republic of Iran in a while. All right. We’ll give the floor to the delegation of Brazil, and then we’ll come back to the earlier speakers. Brazil, you have the floor, please.

Brazil

Thank you, Chair. That was a surprise. Thank you, Chair, for the draft report. My delegation welcomes the adoption of modalities and of the program of work, as well as the participation of other stakeholders in this meeting, including from my own country, Brazil. We believe that this broader participation is positive for the work of the group and perfectly compatible with its inter-governmental nature. Speaking of which, we also consider the full participation of all member states to be crucial to the work of this group. Agreeing on a report is important not only because the group was mandated to do so, or even to show progress. It is also important because, despite procedural challenges, member states were able to discuss substantive issues during the first two sessions. This work must be honored and reflected in writing, which will set a direction and also a positive tone for our work ahead. On the introduction of the draft, firstly, the basis of our work is the acquis. Reaffirming the OEWG and all the GGE reports is crucial. We must demonstrate that we can build as member states incrementally, not only on what those reports established already, but also on what they have identified as areas for further study. In other words, the reports already set our roadmap. Secondly, we thank the Chair for refreshing our memory on the group’s mandate, in order to avoid disparate views on what we are here to do. Thirdly, as a priority within that mandate, the implementation of the framework of norms, as per the resolution that established the OEWG, is a priority. And we agree with the US delegation that international security is our focus. How capacity building fits into that is a more challenging topic, because as developing countries we need to build the basis to address implementation of norms, and sometimes this basis will be relevant beyond international security, but we can discuss further in the proper chapter. On gender, we agree with Spain that gender equality is a cross-cutting issue at the UN, already recognized in every multilateral angle that is relevant for this group. The information society angle, gender is one of the expressions of the digital divide that member states agreed to address in the World Summit of Information Society, and also in the international security angle, considering we have an agenda on women, peace, and security already. On the threat session, we welcome the insertion of the item A on diagnostics. We agree with China that the best language to use in this paragraph is “exchanged views on.” We think the threats chapter is more about diagnostics and exchanging views than to be too much closed or normative. We also agree with the EU and others on the importance of referring to the threats themselves. This is consistent with the history of deliberation on that topic, as well as with the general perception in the room last session of a heightened level of risk and alert. This was common for all member states. This was also echoed by Under-Secretary Nakamitsu this morning, when she referred to a steady stream of ICT incidents. We don’t need to negotiate threats, meaning that we want to exclude ones or include others. We don’t need to do attribution or name-shaming. We just need to be consistent with the impression and perception of member states that we are in a higher level of alert. We also are open to consider how emerging technologies fit in that scenario. Finally, one point on interfaces. There is an interface in the report with the internet governance track, when we discuss risks of fragmentation, ensuring availability, and integrity. We welcome this concern in the report, but we would like to be mindful of the proper place to discuss broader internet governance issues. And finally, on the cybercrime track, we believe that ransomware is relevant for the OEWG. When it reaches the level of threat to international security, this may or may not happen. And in most cases, ransomware will be more pertinent to the track of cybercrime. So we need to have a contextual-based approach. And finally, we propose that items six and seven on this part could be deleted because of this overlap with the discussion on cybercrimes. We understand that the Chair tried to fix this overlap, adding the language on coordination, but we believe it didn’t bring the desired clarity. So we would propose it to be deleted. We don’t have any amendment on the norms section. We just would like to highlight the voluntary nature of measures dedicated to support implementation and follow up on them. Thank you, Chair.

Ambassador Gafoor

Thank you very much, Brazil, for your very succinct as well as very concrete comments. I give now the floor to the Islamic Republic of Iran. I see that the delegation is present. Please, you have the floor.

Iran

Okay, thank you so much, Mr. Chairman. My apology for arriving a bit late. Well, actually, with regard to the first reading of the draft annual progress report, before I address the agenda of the threats and norms, I would like to make the following general comment regarding this report. The importance of an all-inclusive approach within the OEWG should not and must not be overlooked. The concrete action-oriented approach which has been taken in preparing all proposals and parts of the first annual report is not, in our view, an all-inclusive and comprehensive approach toward the work of the second OEWG. We note that with the unbalanced approach, the issue of implementation is overemphasized in all six parts of the annual progress report. We are of the view that describing all proposals with the term concrete is subjective judgment. What constitutes a proposal as concrete or non-concrete is a matter of controversy and would not facilitate the consensus agreement. Instead, we have proposed these two contentious terms to be substituted with a neutral term as different proposals made by states. Also, the term action-oriented implicitly prioritizes the sufficiency of implementing voluntary and non-binding norms of responsible state behavior in the use of ICT on the one hand and dismisses the necessity of negotiating a legally binding instrument on the other hand. So, there should be careful balance toward the approach of the report. Adopting a concrete action-oriented approach with the new OEWG basically converts the group into a proposed PoA, in our view, structured to implement the framework for responsible state behavior in the use of ICT, recommended by the 2015 GGE report. This is contrary to the mandate of the OEWG established pursuant to General Assembly Resolution 75/240. We must strive to recognize the concern and interest of all states in a fair, transparent, and balanced manner. To this end, it will be essential to resume the practice of paragraph-by-paragraph negotiation exercise, which will effectively facilitate consensus building on the outcome of the document, including the annual progress report. It is highly expected that the group will start negotiation on the zero draft, actually, to avoid undesirable situations for delegations regarding the final outcome of the third OEWG report. Mr. Chairman, on the introduction part, we believe that the intergovernmental, democratic, all-inclusive, and transparent nature of the OEWG needs to be highlighted in the introduction part of the annual report. Since the chair’s summary attached to the report of the first OEWG is an integral part of the report, any reference to the previous OEWG final report should include a reference to the chair’s summary, which contains diverse perspectives, new ideas, and important proposals that were put forward by states during the 2021 OEWG. According to paragraph 80 of that report, the previous OEWG, these perspectives should be further considered in future UN processes, including in the open-ended working group established pursuant to General Assembly Resolution 75/240. In light of my delegation’s well-known position regarding the Group of Governmental Experts, we cannot support any reference to GGEs in the reports of the OEWG, which was long awaited to involve all state actors in issues with overarching influence on all aspects of human life. We recall that the reports of the 2010, 2013, 2015, and 2021 GGEs are not accepted or affirmed by all member states. They are consensus reports of a maximum of 25 states. In the introduction section, Mr. Chairman, we would like to recall that 13 voluntary non-binding norms of responsible state behavior are presented in the UN General Assembly Resolution 73/27. Even we recall that the list of 13 voluntary non-binding norms is not exhaustive and other new norms have been proposed by these and other delegations to be considered and agreed upon. Also, after reaffirming that international law, in particular, the Charter of the United Nations, is applicable and essential to maintaining peace, security, and stability in the ICT environment, we propose to reaffirm that in view of the specific characteristics of ICTs, the state also recalled the possibility of additional legally binding obligations. In paragraph 2, we welcome the reference to the mandate of the OEWG contained in the GA Resolution 75/240. For the introduction section, we also propose some additional paragraphs which set the context and environment within which the recommendations of the OEWG should be voluntarily applied. These additional paragraphs are included in our written proposals on the zero draft which was sent to the chair as well as to the secretariat. I do not repeat those paragraphs, but those recommended paragraphs deal with the different situations, capabilities, and priorities of different states. Also, this is important to leave no state behind and take into account different national realities. The OEWG also acknowledges the benefits of digital technologies are not evenly distributed and that narrowing the digital divide, including through wider access to ICT and connectivity, remains an urgent priority for the international community. Also, we have addressed some other issues regarding internet access and non-discriminatory state-level arrangements regarding the internet and also technology transfer and the responsibilities of different countries and in particular responsibilities of other stakeholders. On the existing and potential threats section of the annual report, in accordance with my delegation’s general comment delivered on this issue, we suggest that, as we have said, concrete action-oriented proposals be deleted and replaced with different proposals in paragraph 7. In paragraph 7b and roman 9, we welcome the reference to China’s global initiative on data security and we would like also to include reference to data protection and we prefer the change with paragraph 7b as follows: Measures and initiatives to safeguard the general availability and integrity of the ICT resources while also ensuring equal rights and responsibilities of the states in internet governance. During the previous OEWG, as well as the first and second of the current OEWG delegations, discussed the threats of ICT against the sovereignty of states. Therefore, we suggest adding the following paragraph in this regard: Measures, including among others as follows, to prevent the use of ICT against the sovereignty of states and to prevent destabilizing and interfering in their domestic systems and processes and creating conflict among nations, races, and ethnic minorities and also to avoid restrictions, including through unilateral coercive measures against states in the ICT domain and also to address disinformation campaigns, fabricated image building, and xenophobia against states through the use of ICT. Also, to ensure the responsibility of the private sector and platforms with extraterritorial impact in the ICT domain. Interaction with the stakeholders, also including on the protection of CI and CII, is the prerogative right of states. Therefore, we prefer to delete paragraph 7/d, 7 little d, which proposes states consider strengthening interaction with interested stakeholders. On the recommendation part of the existing and potential threats, in paragraph 2, we believe that exchanging technical information related to existing and potential threats should not be limited to the sharing of risk assessment, threat intelligence, best practices, and incident mitigation measures, but should also include all topics stated in paragraph 7 little d. Experts could be invited to make presentations on these topics, but it should be done on a non-objection basis. In paragraph 3, in addition to the protection of CI and CII, we suggest that the prevention of the use of ICT against the sovereignty of a state be added for focused discussion at the fourth and fifth sessions of the OEWG. Mr. Chairman, on the rules, norms, and principles section of the annual report, in line with what we have already mentioned in paragraph 8, we suggest that the phrase concrete action-oriented proposals be deleted and substituted with different proposals. We welcome the reference to developing technical ICT terms in paragraph 8 little a, but we would like it to be replaced with developing universal terminology in the field of ICT security, which has been suggested by some countries during the previous as well as current OEWG. We wish to recall that in accordance with the consensual recommendations of the 2021 OEWG report, we are to continue discussing all the ranges of proposals, including the chair’s summary. Therefore, we suggest modifying paragraph 8 as follows: States reaffirm that additional norms need to be developed, noting that the further development of new norms and the implementation of existing norms were not mutually exclusive, but could take place in parallel. In paragraph 8 little c, we propose best practices be replaced by relevant information and lessons. In this part of the term, vulnerability disclosure needs to be more clarified. We believe that reporting of national implementation is something that could take place within a legally binding instrument, so we propose to delete the reference to reporting national implementation on norms in paragraph 8 little d. In paragraph 8 little e, instead of states take note of the list of non-exhaustive norms, we suggest using the agreed language. States should further consider the list of non-exhaustive norms, which has been used in paragraph 80 of the 2021 OEWG report. Regarding the recommendation next steps for rules, norms, and principles in paragraph 1, we prefer to use the same language from the mandate of the OEWG in UNGA Resolution 75/240. In paragraph 2, again, we suggest using universal terminology in the field of ICT security instead of common understanding on technical ICT terms. We are also of the view that submitting working papers, which has been requested in this part, should not be limited to the existing non-exhaustive list of 13 norms, and instead states or groups of states should also be invited to submit working papers to contribute to the development of additional norms. In paragraph 3, in line with our suggestion regarding paragraph 8 little e above, reference to reporting national implementation of norms also should be deleted. I thank you, Mr. Chairman.

Ambassador Gafoor

Thank you very much, Islamic Republic of Iran, for your statement. I now give the floor to the Russian Federation.

Russia

Chair, dear colleagues, in our view, the area on the existing and potential threats requires substantial reworking. First of all, it needs the inclusion of a current list of threats. It also needs proposals of states to respond to those threats. In accordance with the statement of the Chair, as current threats, we believe we should include the use of ICT for military means and also to undermine the territorial integrity of states and any other acts that undermine international peace, security, and stability. Also, for terrorist purposes, including to carry out terrorist propaganda and to recruit new adherents to terrorist ideology for extremist purposes, and also for the intervention into the internal affairs of sovereign states. To circulate information that harms public, political, and socioeconomic situations, the spiritual, moral, or cultural realms of a state for criminal purposes, including to carry out crimes using computer information, and also for the aim of commission of various forms of fraud. To carry out computerized attacks on information resources of states, including on critical infrastructure (CII), critical information infrastructure. To publish incorrect information, to circulate knowingly false information, to create a risk to life or the safety of citizens, or some act that could have a serious impact. Also, baseless attacks against individuals or states of carrying out crimes or internet attacks, and also the use by certain states of technological domination of the global information space to monopolize ICT, to curtail the access of other states to that ICT, and to increase their technological dependence on the states that dominate in the information realm and informational inequality. Also, free access to instruments, or making available instruments to carry out terrorist computer attacks, and to use such instruments. Coordination and relevant attacks to carry out computerized attacks, a list of potential threats or existing threats, and the circulation of information, falsified messages, and hateful rhetoric. This should be a separate provision on the need to counter the above-mentioned acts in the national information space of states, and also with regard to providing instruments to carry out computerized attacks, and also on the inadmissibility of coercive restrictive measures against other states, including on the free circulation of information in the media and carrying out measures against private companies. We would also propose broadening the list of threats with regard to points seven, eight, 11, and 24 of the Chair’s first open-ended working group, and our proposals have been sent to the Secretariat and to the open-ended working group. It’s important for us to ensure measures to ensure open access, stable functioning of the internet with a focus on the sovereignty of states in their national information space. There’s also a need to ensure the participation on equal footing of all states in carrying out these activities, and there is a need to focus on basic steps that can be taken to protect personal data and to decrease the circulation of falsified information as well. Turning now to the improvement of cooperation with non-state actors when it comes to the security of ICT, we see added value in hearing the opinion of precisely those stakeholders that are directly responsible for the protection of critical information infrastructure. This includes infrastructure and critical information infrastructure. This dialogue should be carried out considering the key role of national governments in this matter. We believe it’s superfluous to mention stepping up the efforts of the international community to build capacity. This is because the draft report has a separate section on this issue. I have some comments now about the rules and norms of responsible behavior of states. The open-ended working group’s mandate is to work in this area. We believe it is of principal importance to carry out joint work on norms and rules. Russia insists on the need to agree on a comprehensive list of such rules. And we’ve seen major progress in ICT, and we’ve seen the unacceptability of current rules in ICT to address this realm. There’s a need to take measures to ensure that such rules are legally binding in nature. As a result, we need to formulate an international legal regime when it comes to the use of ICT, especially because more and more states, especially developing states, have been voicing the need for this to happen. That was clearly shown at the statements in the first and second open-ended working group. The group could take practical steps to agree upon elements of such a document. I’m compelled to note the following. Our comments and proposals about the rules and principles have not been considered. We still think there is an undue accent on voluntary rules of conduct. It’s also unacceptable to impose on participants in the discussion various forms of accountability that have not been agreed upon at the UN. All of this is the effort of certain states that are trying to push through voluntary rules despite the direct impact that ICT has on national security. These states are impeding at every turn binding rules. It’s clear that they want to keep a free hand for themselves in the informational sphere. It’s our conviction that this reporting needs to happen with regard to mandatory rules. We think it’s important to stringently adhere to the mandate of the OEWG. Our task is to further elaborate rules of behavior. We’ve already had two sessions of the open-ended working group, and they should be duly reflected in the draft report. Moreover, we agreed long ago that the group is not starting from square one, but rather it’s basing its work on the outcome of the first OEWG. The national initiatives should be considered in the report that were found in the Chair’s summary of the previous report. Our detailed proposal in this regard is with Mr. Gafoor. He has it. Mr. Chair, Russia was mentioned by the representative of a number of states in the context of our special military operation in Ukraine. Therefore, we would like to point out to the participants in the discussion – we would like to ask for them to stringently adhere to the mandate of the open-ended working group without politicizing our discussion. That said, we also have something to say. It concerns something unleashed against Ukraine. I’m referring to the aggression in cyberspace. With the assistance of the Pentagon and the intelligence services of the U.S., there is a Ukrainian IT army designed to harm Russia’s infrastructure and that of its allies. There are state structures involved in that effort, and also financial institutions, media outlets, and energy producers, transport companies, and all these parties are targeted, rather, and our citizens are also being targeted. There are many attacks. There’s mass theft of personal information and confidential information as well. Russian specialists have said that every week in our informational sphere, hundreds of sabotage activities are carried out. They are from North America and from Ukraine and other states. The most computerized attacks against critical infrastructure of other countries come from the United States. Sometimes IT giants are standing behind these perpetrators, IT giants attempting to ensure their technological dominance. The principle and the scale of these attacks clearly indicate that in addition to preparation by the U.S., NATO, and other countries, informational and technological measures carried out in Ukraine are being carried out, and also anonymous hackers are being used with the connivance of the patrons of the Kiev regime. It’s clear that there’s an army of cyber mercenaries arrayed against us, and they have specific military tasks they’re carrying out, and often this borders on open terrorism. Against that backdrop, it’s clear what the aim of the anti-Russian rhetoric is. The aim is to discredit the Russian Federation and its policy to shore up international information security. There’s an attempt to continue this cyber aggression unleashed against our country. Moreover, official high-placed U.S. officials have not balked at issuing statements, and they have publicly acknowledged that they are engaged in offensive cyber operations against Russia. I wish to note that statements from other states in the context of CERTs have often been evaluated by Russian experts in the context of the insinuations we’ve heard today about Russia’s actions against Ukraine. We inform you that the states have accused us of aggression, but they haven’t given us any notices about that. So again, what this is are baseless, unsubstantiated allegations. I would like to call upon the member states of the OEWG once more to refrain from undue politicized statements in this work and to work on coordinating this entering report. I thank you, Chair.

Ambassador Gafoor

I thank the Russian Federation for its statement. I now give the floor to Cameroon, to be followed by France. Cameroon, please.

Cameroon

Mr. Chairman, allow me at the outset, as it is the first time that my delegation is taking the floor during the meeting of the Open-Ended Working Group on the security of and in the use of information and communication technologies, to join those who have previously taken the floor to express my full gratitude for your remarkable stewardship of our work. Also, my full thanks for all of the efforts that have been made to facilitate our discussions. My delegation reiterates its readiness, support, cooperation, and commitment to contribute fully to achieve the expected results for the mandate granted to this Open-Ended Working Group, which you have the heavy and lofty responsibility of leading. Chairman, ladies and gentlemen, the increasing use of ICTs and their use in criminality is increasing. These are undermining the sovereignty of states and affect the image and protection of institutions, the economy, political freedom, as well as the fundamental rights of peoples and goods in a cross-cutting, and the cross-cutting and cross-border nature of cybercrime also means that we need to pool our efforts, share experiences, and establish international cooperation involving different stakeholders so that we can all contribute to fighting this scourge. There is an opportunity to provide it to all member states here at this meeting in order to discuss drawing up a dashboard to contribute to protecting cyberspace, and these include capacity building. Chairman, in this general debate, on all of the points on our agenda, Cameroon aligns itself with the proposals that have been made with regard to international cooperation in the zero draft of the report, as well as on the implementation of effective international cooperation given the urgent need to establish new digital hygiene for mutual interest, and that’s so as to identify all relevant stakeholders and to assess all needs, as well as to ensure the capacity building and protection of infrastructure. In addition, this involves fighting cybercrime, disinformation, and a lack of skills that is particularly faced by developing countries, and this should be addressed through technical assistance provided to less developed countries, as well as the harnessing of all the knowledge of all states. This would contribute to reducing the digital divide that has been increasing in size given the number of attacks that is just exponentially growing, particularly in developing countries that have been mentioned here. They are the main victims of cyberattacks, and they need access to necessary technology to counter cybercrime. In light of the widespread and indisputable access of women in these negotiations and the drawing up of national strategies, as well as to maintain cyber peace and security, all of this would guarantee sustainable development, capacity building, and responsible behavior. This should take into account climate change for a resistant and resilient environment that would lead to a reduction of the digital divide and would strengthen development and protect sovereignty and international law. This, in turn, would defend human rights as well. Furthermore, we highlight the establishment of national and contact points for the exchange of information. These are specific steps to counter the use of ICTs for criminal means because cyberspace has no borders. In order to operationalize and implement norms urgently and to support states in implementing these, as well as to respond to their particular vulnerabilities of the OEWG and the GGE in order to achieve results. It’s also important to identify threats in cyberspace through synergies and through assessing risks for international security. It’s important to draw up a coordinated Program of Action in order to consolidate mutual commitments to combat the malicious use of ICTs. It’s important to establish regular and periodic meetings to establish a permanent platform for support and discussions on new threats. In terms of general comments, Cameroon reiterates the establishment of confidence-building measures. But we also have a strong commitment to the protection of the ICTs. We also have some regional comments that will be provided by civil society, the academia, etc. These pertain to confidence-building measures, particularly with regard to the problems faced by children and girls in accessing cyberspace. Further, it’s important to ensure confidence-building measures for critical infrastructure. Now, we also would like to underscore the strategic cooperation of governments in the consensus-based implementation of rules, norms, and principles of responsible state behavior. And, of course, their implementation in order to help states to self-assess and to overcome obstacles in the use of ICTs. Furthermore, we believe this is important to ensure security for human beings, but also for the issue of gender. We hope that countries will exchange their good practices in cybersecurity. Continuing along general lines, we support the implementation of capacity-building measures for a peaceful and sustainable cyberspace through financing support measures that are to be established. We believe it’s important to support the strengthening of all of their capacities in order to fill gaps, as well as to address issues with IP addresses. Further, it’s important to develop recommendations for strong national partnerships for capacity building for Africa, as well as to ensure the protection of vulnerable groups and critical infrastructure. We believe it’s important to promote ICTs and grants to be given to women in the use of ICTs to strengthen the understanding of women in ICTs and to include cybersecurity in school curricula. Furthermore, we believe it’s important to work with social and technical partners by establishing several CSIRTs in each country that through cooperation with the United Nations would help developing countries to be better prepared in the case of cyberattacks. Mr. Chairman, under the auspices of the United Nations, Cameroon finally, generally speaking, and subject to the details that will be provided later, proposes assisting the states to focus more on humanitarian law, hence the importance of international law in cyberspace. This obliges states to publish their documents of the implementation of ICT guidelines and to undertake in-depth assessments. This would also favor the establishment of a working group that would look at a regional group, at least on a regional level, and would also foster the exchange of experiences. We should also promote justice and develop legal frameworks and, in particular, fill legal voids to ensure accountability. Finally, we underscore the importance of establishing a regular platform to urgently respond to emergencies, hence the need for a consensus-based regional discussion in order to ensure that we have a peaceful and stable internet that is transparent and that follows regular assessments in order to urgently respond to current needs and to reduce the digital divide. Mr. Chairman, in closing, my delegation hopes to see fruitful discussions that would lead to a consensus on the publication of an annual report, particularly bearing in mind the specific needs of states. We would be honored to take the floor on the specific sections of the report in more detail. Thank you very much.

Ambassador Gafoor

Thank you, Cameron, for your statement. I now give the floor to France.

France

Thank you, Chair. By way of introduction, I assure you of my delegation’s support in the work of our session. In this regard, we hail the approach on all of the dimensions of this group’s mandate to setting forth areas for discussion to have a more detailed debate in the sessions going forward. There are two objectives. First off, the annual report needs to annually reflect the substantive discussions of our first two sessions. Secondly, it needs to be a clear roadmap allowing for the useful structuring of the ongoing discussions in 2023. I turn now to the introduction of this annual report. We have the following remarks and proposals. Paragraph one: we think we should replace “could” with “should” in the second to last – should be built upon. As affirmed by OP5 of the resolution adopted last year, our work not only could but would carry out these efforts. Paragraph two: we think it’s not necessary for the mandates to be duplicated in the – that are duplicated in the OP. We think this could be annexed to the annual report. We support the new paragraph five, which underscores the need to take into account the gender-digital divide in the work of the group. We also wish to highlight new paragraph four, which has to do with the regional list of regional organizations’ contributions. Against that backdrop, we agree with paragraph six, yet we think that it could be reformulated to be more concise. I will be happy to share with you our proposal for that. Turning now, Mr. Chair, to the section of the report on existing and potential threats. The diagnosis of existing and potential threats using ICT as regards international security is an integral part of the mandate of this group. It is of foundational importance for our work because specific proposals discussed in this group will only take on meaning to the extent at which they diagnose clearly identified threats. To arrive at a perception – a common perception and characterization of this threat for this group is very important progress. It’s just as important as the adoption of one provision or another. Hence, we believe that the annual report needs to contain a description, even a summary, of the threats as such. In that regard, we acknowledge that the new version of the draft report that you circulated a few days ago represents an improvement because paragraph 7a recalls the threats that were identified in the report of the previous Open-Ended Working Group. That said, there are some threats that could be recalled more explicitly. This would allow us to reflect the fact that our work fits into a context of increasing concern as regards the malevolent use of ICT. As mentioned in the introduction of the report itself, paragraph a could conclude the following threats. The fact that ICTs – the use of ICTs is not only just probable but is an effective reality. The potentially devastating fallout on the security, social, economic, and humanitarian realms of these malicious activities on critical infrastructure. This refers to paragraph 18 of the previous report of the OEWG. Finally, the vulnerabilities through a lack of adequate capacity to detect and to respond to cyber activities – malevolent cyber activities. In addition, we should note the threats that are largely acknowledged and were discussed during the first two sessions. We could also mention ransomware. Ransomware could have implications beyond national or international security because they target critical infrastructure, as was recalled by the delegate of Costa Rica this morning. The report could also list the risk that has to do with cyber activists that could contribute to heightening tensions or to conflict situations that could have a destabilizing effect on international security. Finally, Chair, I turn now to the section of the report on the rules, norms, and principles of responsible state behavior. This part of the report appears overall satisfactory to my delegation. However, we have a proposal, an amendment – the following amendment and approval. We want to clarify the acquis, which underpins our work. So we think that the 11 norms should be cited in the text. If we want to keep this report concise, then an alternative would be to put those in the annex. The roles of these norms and their precise articulation with international law could be recalled. For example, in paragraph 25 – or using paragraph 25 of the previous OEWG report, we would also have another suggestion reformulating the end of paragraph 9a as well as – OEWG and GGE report, as well as continue developing common understandings on existing norms. Nous proposons – we propose in paragraph 9b – introducing this paragraph by states recalled instead of states proposed to the extent that this paragraph reaffirms a conclusion of the previous OEWG rather than formulating a new proposal. Finally, we have a proposal that we shorten recommendation 2 of this section as follows. States or groups of states are invited to submit working papers to contribute to the development of guidance, checklists, and other tools to assist states in developing common understandings. Je me tiens à disposition. I will convey these suggestions in writing and I thank you.

Ambassador Gafoor

Thank you very much, France, for your statement, and yes, I do look forward to receiving your proposals in writing. I give now the floor to Poland, to be followed by Sri Lanka, Peru, and Egypt. And once again, I’d like to invite colleagues to be as succinct as possible, so that we can give as much opportunity for other delegations to also make their contributions today. I give now the floor to Poland, please.

Poland

Thank you, Mr. Chair. I would like to begin by commending all your efforts, including the informal consultations held in the course of preparations, which brought us to this important session. Mr. Chair, distinguished delegates, Poland aligns itself with the statement delivered earlier by the European Union. I’d like to add a few short remarks in my national capacity. On a general note, Poland condemns in the strongest possible terms Russia’s military aggression against independent and sovereign Ukraine, as well as malicious cyber activities conducted from Russian territory. We call on Russia and other countries which allow the use of their cyberspace for such harmful activities to stop them immediately. Turning to the revised draft of the Annual Progress Report, we recognize that we need it not only because it is in line with the mandate of the group, but it is also in the interest of the group to have a guiding tool for its further work. We all need this guidance, building gradually on the current achievements. From the Polish perspective, there are several issues which we would call landmarks of order in cyberspace. To name them in a random sequence: application of international law, preservation of existing key respect for human rights, participation of multistakeholders, key role of confidence-building measures and capacity building, and progressing on the Program of Action. It is of utmost importance that all these elements are properly addressed in the ultimate outcome of the OEWG process. Mr. Chair, distinguished delegates, our strategic goal should be to build in an incremental manner a permanent platform for debating on international cybersecurity, setting security standards, exchanging information, generating projects and ideas of international cooperation among partners, being at different stages of advancement of cybersecurity. We believe that in order to achieve it, we should not lose any of the aforementioned cybersecurity landmarks, which are our lighthouses indicating a clear path for further development of international cybersecurity. Thank you for your attention.

Ambassador Gafoor

Thank you, Pauline, for your statement. Sri Lanka, you have the floor, please.

Sri Lanka

Ambassador Burhan, may I thank you for your stewardship and efforts in leading this Open-Ended Working Group, and congratulate you on effectively driving it forward to the third substantive session. We were happy to see this morning the High Representative for Disarmament, Madam Nakamitsu. The draft of the Annual Progress Report, Mr. Chairman, I must say, is comprehensive and leaves us much for discussion on seven important aspects. Sri Lanka wishes to bring to focus the following aspects for the purposes of this discourse. Your proposal, Mr. Chair, that we file an Annual Progress Report is most appropriate and timely. There is much support for such an initiative. The draft more than cements the phenomena that cybersecurity is global, that it needs to be dealt with through global collaborative efforts. It seeks to identify gaps that need further attention. It reminds us that there is a need to harness collaborative efforts to consider diverse views to achieve a balanced outcome and build a consensus. Such collaborative efforts will no doubt, Mr. Chairman, address the context-specific challenges and bridge national and global policies in establishing norms and best practices in regulating the environment in the use of information and communication technology. Mr. Chair, the draft looks at the prevalent context-specific threats, need for norms and applicability of international law, critical analysis of law, and encourages the implementation of a multidisciplinary approach. Such multidimensional approaches will not only facilitate, I say, in threat detection, but can give productive pointers to security risk management and impact assessment when norms, principles, and laws are implemented. Sri Lanka believes that collaboration can bring in global efforts closer and hence must focus on taking stakeholders such as industry bodies on board to work in parallel with governments and promote ICT security and continuous innovation in cybersecurity. It is pertinent, I say, Mr. Chairman, that I briefly refer to cyber-specific international legal regimes that deal with the prevention of harm across economic sectors, artificial intelligence-based processing of personal data, and secondly, as a target and tool for crime, which I think needs focus. Artificial intelligence systems, like other information as we know, can be a target or tool for criminal activity. As observed before, both of which are within the scope of the 2001 Budapest Convention on Cybercrime. Also dealt with within the Council of Europe framework with active participation of non-member states from the outside. Now, whilst universal ratification may be possible for political reasons, one of the principal objectives of the treaty is to harmonize domestic substantive and procedural criminal law as a precondition for more effective international cooperation. And I say that’s important. Being the first and most widely ratified multilateral treaty on cybercrime, this treaty can achieve its objectives, we believe, without formal global participation as it simply serves as a model instrument. At just over two decades, Mr. Chairman, at just over two decades old, the international law of cybersecurity remains in a relative state of infancy, I would say. This is despite the fact that the period has seen extraordinary advances in cyber capabilities, the exponential growth of societal cyber dependence, and a corresponding rise in vulnerabilities to hostile cyber operations. Indeed, states continue to struggle with such basic issues as sovereignty in cyberspace, as quite rightly pointed out in the draft. In great part, the challenge is that many states are conflicted over the application and interpretation, as I see today, of key aspects of international law in the cyber context as we observe today. But the tension is, I say, to be encouraged. We need to exploit that tension. After all, although international law can serve as a normative fireball against hostile cyber operations, the principle of sovereign equality must be understood as protective norms and also can act as barriers to a state’s own cyber operations, some of which may be deemed essential to the state, especially with respect to national security. These differences, Mr. Chairman, of normative perspectives often play out domestically in disagreements between ministries with different roles vis-a-vis cyberspace and internationally between states wielding offensive cyber capability and those that see themselves primarily as victims thereof. Paradoxically, the international community today plainly sees hostile cyber operations as a significant threat to their security and their citizens’ welfare. But efforts to legally prohibit or restrict them have borne little fruit. We need to address this issue in all its earnestness. As much as ICT threats are becoming a rising global challenge, innovative research will no doubt develop understanding on the persistent threats in the ICT environment in the current context, and we need to step up our efforts. Sri Lanka wishes to highlight that the current discussions need to specifically look at the challenges in the industrial sector that needs more targeted delivery. In particular, during the last two decades, there have been vulnerabilities shown in critical infrastructure such as financial networks and power grids. These sectors have been prone to cyber attacks. Despite there being initiatives undertaken through sectoral partnerships, still work remains to be done. In particular, as the cyber threat landscape continues to grow and expand, developing countries in particular will require capacity building in the area such as infrastructure, as quite rightly again focused in the draft, and technology, to understand and face the challenges by, again, cybersecurity management capabilities in order to strengthen the resilience and preparedness. Sri Lanka identifies that capacity building in technical support training through cooperation programs can build more collaboration, innovative ideas, in overcoming threats, in particular, in Internet governance and in international law. Sri Lanka, having recognized that equitable global digital transition requires to meet contemporary challenges, inclusive of digital governance, appreciate, we appreciate that developing countries such as Sri Lanka have to face issues such as cybercrime, cybersecurity threats, disinformation, and violence, and that the digitalization must be environmentally friendly. We have also recognized the fact that the multilateral digital collaboration and connection are required if it is to effectively contribute to the green transition. We are also appreciative of the fact that digital technology can be of assistance in dealing with climate change and disaster prevention, and that we cannot have a digital divide that would weaken the whole policy towards digital and resilience to confront criminality in cyberspace and an abuse of technology. I thank you, Mr. Chairman.

Ambassador Gafoor

I thank the Permanent Representative of Sri Lanka for his statement. I now give the floor to Egypt.

Egypt

Mr. Chair, at the outset, we express our deep appreciation to you, Ambassador Gafoor, and your team for your efforts in pushing forward wisely in the work of the OEWG at this critical time, in which building bridges and deepening trust among delegations are highly needed. We also commend the insightful statement of Ms. Izumi Nakamitsu, Under-Secretary for the Armament Affairs, delivered this morning. Mr. Chair, we underscore the importance of the third substantive session of the Group, which focuses on discussing the draft Annual Progress Report with a view to reaching consensus on it. We reiterate the importance of its adoption in line with the mandate of the OEWG reflected in Resolution 75-240. That draft report shouldn’t be a copy-paste of previous relevant final reports, which were different in nature. However, it should reflect, as suggested, the deliberations of the previous substantive sessions of the Group, as well as provide a roadmap of focused discussions within the Group during 2023. We believe that the revised version of the Annual Progress Report of the Group is still quite balanced and represents a good basis for discussions during this week. We encourage all delegations to negotiate the text in a constructive and rational manner, as well as to show maximum flexibility in this regard, taking into consideration the importance of avoiding the politicization or pushing non-consensual language into the text that might have implications for the progress of the Group. Furthermore, we would like to add the following comments with regard to Sections A, B, and C of the report. For Section A, in paragraph 4, we believe that the last sentence of this paragraph is not clear and might not represent the views of all Member States in this regard, and we support the amendments made by the Chinese delegation in this regard. For Section B, we would like to reiterate that there is no disagreement regarding the gravely alarming trends related to the malicious uses of ICTs and the risks they pose to international peace and security, while effective cooperation among States is essential for reducing those risks. We support having the general and comprehensive reference to the agreed discussions under this section as reflected in paragraph 7, which includes the consensual report of the last OEWG on ICT. Perhaps we could also refer to the consensual Resolution 76-19, which supports both consensual reports of the last OEWG and GGE. We also believe it’s not necessary to include an exhaustive list of threats in the spirit of rationalization of the text and also to mitigate the endless discussions on which threats we should focus on and which we should ignore. For Section C, we believe that it is important to include the discussions and comments on the issue of possible elaboration of legally binding rules that should be reflected under this agenda item, also in line with the language agreed in paragraph 18 of the consensual report of the OEWG. These are our comments for the first three sections, and we will provide further comments as we go further in the text. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you very much for your statement, Egypt. Please also make available to us your proposals in writing if it’s possible. Distinguished delegates, I have Germany, Mexico, Netherlands, Portugal, and Singapore as the next speakers. Once again, I’d like to appeal to delegations to be as succinct as possible and to address themselves to sections A, B, and C of the revised annual draft progress report. The more specific your comments are, the more it will be helpful to all of us and also to me in particular to see how we can find formulations that will take us forward and that will find consensus. So I once again would like to encourage you to be as specific as possible in your comments so that every one of us, including myself, will have a good sense of what is a good way forward. Thank you very much. With those comments, I give now the floor to Germany. Peace.

Germany

Thank you, Chair. Germany is fully aligned with the statement of the EU, as well as with the statement of the Czech Republic and Canada on multistakeholder participation. Germany wishes to thank the Chair and his team for compiling the draft progress report, which we see as a sound basis for discussion. We welcome the action-oriented structure, focusing on next steps and concrete initiatives for implementing the existing global framework of responsible state behavior in cyberspace. We have a number of suggestions for the text of the section on existing and potential threats. Germany considers it essential to use the section to describe and raise full awareness about the existing threat landscape and to focus discussions in the Open-Ended Working Group on the most harmful threats to international peace and security, as we see them today. Since the last session, we have seen destabilizing trends in cyberspace continue, most strikingly the use of cyberattacks by Russia in its war of aggression against Ukraine. Reverberating effects of these attacks can be felt in networks all over Europe, including in Germany. Russia’s actions are a flagrant violation of international law and the UN framework of responsible state behavior in cyberspace, which was agreed in this building precisely to ensure that cyberspace is not misused as a domain of warfare. The spillover effects we are seeing as a direct result of Russia’s cyber war against Ukraine have had direct disruptive effects on Germany’s critical infrastructure, namely our renewable energy sector, as well as key distributors of fuel. Another concerning development is the increase in hacktivism in the context of the war in Ukraine. Hacktivists aggravate risks and instability and have added another level of unpredictability to cyberspace. Cybercrime, and in particular ransomware attacks, continue at a level that can pose direct threats to international peace and stability, as was highlighted this morning by Costa Rica and further outlined by Brazil. With regards to the first draft, Germany suggests including direct references to military use of ICTs, hacktivism, and cybercrime in the section summarizing current threats. Germany also supports the proposal by the United States to cover new threats posed by emerging technologies in this section. With regards to the rules, norms, and principles section, Germany supports the proposals in the draft annual report concerning transparency and information sharing regarding national views on specific norms, rules, and principles. Such open discussions should aim at developing a joint understanding of these norms and at protecting international peace and security. As an action point, Germany would like to propose a concrete reference in the report regarding attribution. Jointly with other states, we have pointed out the high value we see in deepening interstate exchange and the sharing of best practices regarding the attribution of cyber incidents. Attribution is not only a key instrument to ensure accountability, but also essential to prevent future malicious cyber activities, as already underlined in the report of the 2021 GGE. As such, Germany would support action-oriented recommendations in Para 8E of this section. In closing, let me assure you that Germany is ready to engage constructively on finalizing a substantive progress report by the end of this week in order to guide the further Open-Ended Working Group process in a transparent and action-oriented manner and to strengthen international peace and stability in cyberspace at a time when we find that both peace and stability are being challenged by the acute security crisis in Europe. Thank you.

Ambassador Gafoor

Thank you, Germany, for your statement and contribution. I now give the floor to Mexico.

Mexico

Thank you, Chairman. Allow me briefly to recognize your efforts to ensure that this session could be held, and also I express my thanks to the work of the secretariat and also the support team. The multilateral discussions on ICTs and international security, on diplomacy and United Nations diplomacy in cyberspace and cybersecurity are more necessary than ever. The second draft of the annual progress report that you have circulated is welcome for the Mexican Government as a substantive proposal that is also balanced, comprehensive, and action-oriented. It’s well known, Chairman, that the comments and inputs put forward during the informal discussions did not go unheeded; rather, they were included in an immense effort to include them all, and we are very grateful for those. We note with satisfaction that from the introduction it is pointed out that there is a very close chain between the recognition of agreements and the framework that has been previously agreed, and also a call for implementation, and therefore an invitation to report on implementation and then to guide new action that might be necessary in the future. We also welcome the fact that in paragraph 2 it is underscored that there is an interrelation between the different topics or sections. The link from threats, existing threats with international law and with rules, norms, and principles, with confidence-building measures and cooperation and capacity-building, this is all seen as a whole and it’s something that we particularly welcome. Chairman, Mexico believes it will be helpful to include something in this introductory section on how the work of the Open-Ended Working Group is being guided by the principles and mandates of the United Nations to prevent conflict, to support the peaceful settlement of disputes, and to promote the peaceful use of cyberspace. We recognize the inclusion of paragraph 4 on the role of regional organizations for the implementation of the United Nations agreed framework. In this paragraph, if you’ll allow me, more than just pointing out that not all countries are members of regional organizations, we could recommend that action should be taken to recognize regional organizations as well as efforts, mechanisms, and other regional and sub-regional discussions. This would be in English as follows: organizations and regional, sub-regional, and inter-regional efforts and mechanisms. Mexico also recognizes the inclusion of paragraph 5 that emphasizes the gender-based discussions, and we particularly support the fact that we have maintained the cross-cutting nature of narrowing the gender-digital divide. Allow me to underscore, Chair, in light of some doubts about this type of inclusion, that the specific reference to gender is crucial for the work from the first committee. It’s not only necessary but actually crucial. We also recognize that we have a women, peace, and security agenda as well as other texts emanating from our very own work in the first committee, none other than that. In paragraph 6, we don’t believe it’s necessary to qualify our working group as one that is in its early stages. It is a fact that there has been – that we do have a timeframe that goes up to 2025. However, the agreements to be reached should not be subject to only being cemented in the subsequent stage of the process but rather from the outset of the whole process. So, to promote peaceful use, this is particularly urgent to address. On this introduction, allow me to return now to paragraph 3 on the agreed modalities, specifically, Chair, on the participation of other non-state actors. Mexico believes that the current drafting should be revised without further wording because the flexibility that we’ve shown shouldn’t have led to a right against plurality in excluding organizations from academia and civil society and even multistakeholder organizations whose participation would have been valuable for our discussions. The result of the implementation of our modalities has not been satisfactory at all. Therefore, Mexico would like to reaffirm its position in addressing modalities in previous sessions on how, for my country, consensus is not a veto. In terms – returning to the section on threats, Mexico believes that this does not contain all threats. However, we are aware that it would be impossible to achieve in an annual progress report an exhaustive list of such threats. This is, therefore, a report that reports on our discussions, not that is listing all of these threats that have been identified throughout the different sessions. Therefore, Mexico is flexible and stands ready to support your work, Chairman, in achieving a better balance that would allow us to reflect the different positions on these paragraphs. The specific reference to continuing to discuss threats, well, we believe that that should, furthermore, include a recognition that states have to continue identifying, mitigating, and recovering from threats and sharing information in a timely manner for those countries for which it might be useful to prevent such threats. Turning now to the next section on rules, norms, and principles, I would like to say, Chair, that Mexico welcomes the text that has been circulated here. However, we believe that it would be appropriate for – from paragraph 8 or in paragraph 8A, we should firstly stress the commitment and the call for implementation of the rules, norms, and principles. This was a call that has been repeatedly put forward in all of the previous sessions of our OEWG. Once we have stressed this call for implementation, we can then include the manifest interest in ensuring that we have additional guidance for that implementation. Mexico recognizes the specific reference in this section to the questionnaire from the National Survey of Implementation. This was mentioned in the Open-Ended Working Group’s report and in previous sessions of our group. We support the language that calls to action in this regard and also the inclusion as a recommendation of sharing experiences in filling out the National Survey, including obstacles that, from an institutional basis or in terms of technical capacities, are identified throughout this process. Finally, Chairman, a specific reference to UNIDIR in the third recommendation from this session. Well, my country believes that that would be helpful given the work that has been generated from this United Nations Institute. Thank you very much, Chair.

Ambassador Gafoor

Thank you, Mexico, for your statement. Netherlands, please.

Netherlands

Mr. Chair, dear colleagues. At the outset, let me thank you, Mr. Chair, and High Representative Nakamitsu for your opening remarks this morning and reiterate our full support to you, Mr. Chair, as you guide us forward this week. I would like to align myself with the EU statement and make some comments in my national capacity. I also align myself with the statement by the Czech Republic on the stakeholder accreditation. When we last met in March, we were meeting in difficult times. Today, it’s been five months since the beginning of the unjustified and unprovoked invasion of Ukraine by the Russian Federation, and we continue to see malicious ICT activities as an integral part of the invasion against Ukraine, but also affecting EU member states as well as other partners. I won’t go into this further, but one thing is clear: our efforts to strengthen the rules-based international order and advance responsible state behavior in cyberspace could not be more urgent. Let me turn to the draft progress report. The Netherlands appreciates the pragmatic and action-oriented approach taken in the zero draft progress report. We welcome the roadmap for further discussion and consider this a useful way to make further progress. We do note the importance of staying within the remit of the First Committee, which deals with matters of international security. Allow me to highlight a few general comments that provide the context for the Netherlands’ engagement over the next few days. Firstly, that we make it crystal clear throughout the report that we take the acquis as our starting point. That means we recall and reaffirm the consensus that was achieved by previous groups. This provides us with a strong basis of common understanding and allows us to show progress in our work. Secondly, as you stated in your letter of the 12th of July, it is important that proposals from different delegations should be reflected in a balanced manner. In bringing this balance, we consider it important to ensure that elements that are part of the acquis, such as the applicability of international law, including the UN Charter in cyberspace, or have garnered broad support, are given appropriate weight and recognition vis-a-vis proposals that have received limited support. Thirdly, we welcome practical proposals that advance the implementation of the normative framework for responsible state behavior. For the Netherlands, it is vitally important that such proposals fall within the scope of our work on international security. They should also take into account existing initiatives and avoid duplication in efforts. And we look forward to working with other delegations to further streamline these proposals and ideas. Let me now share our proposals for amendments to the text. The first paragraph in the introduction and the first sentence. We strongly value the reference to the challenging geopolitical environment. We would like to emphasize the impact of malicious ICT activities, particularly on critical infrastructure and essential services. The latter are important elements of our work. So at the end of the sentence, after “with rising concern over the malicious use of ICTs by state and non-state actors,” we would like to add, “against critical infrastructure and essential services, including in the context of armed conflict.” Still the first paragraph, the second sentence, we would like to propose an edit that would include a reference to the work of the GGE. We believe it is important to highlight the work of both processes in line with resolution 76-19 that endorsed the two consensus reports. So I propose the full sentence to be as follows: “At these sessions, states recalled the contributions by the first open-ended working group established pursuant to General Assembly Resolution 73-27 and the Group of Governmental Experts established pursuant to General Assembly Resolution 73-266, which concluded their work in 2021.” Paragraph, the first paragraph again, the final sentence, we welcome the additional reference in this sentence to the consolidation of an initial framework that the open-ended working group builds upon. We would like to propose a minor edit to underline the fact that we are indeed working on the basis of this framework, as was broadly acknowledged during our previous sessions. This was also done in paragraph eight of the 2021 open-ended working group report. The full sentence would be: “These elements consolidate an initial framework for responsible state behavior in the use of ICTs, providing a foundation upon which the open-ended working group builds its work.” Then I continue to paragraph three, the final sentence. We have had long discussions on the modalities for multistakeholder participation. As the sentence indicates, there were indeed many views expressed, which I think will be difficult to capture in a sentence that all of us can feel comfortable with. We therefore support the proposal to delete this sentence. On paragraph five, we welcome the reference to women’s participation and gender in this new paragraph. Gender is part of our mandate in line with resolution 1325. Then on the threat section, a common understanding of the threats that we are seeking to address is a vital element of our work, and the threat picture has evolved since the adoption of the 2021 open-ended working group and GGE reports. Our concern over the military use of ICTs in the context of an armed conflict has materialized while we increasingly see issues such as ransomware having an impact on critical infrastructure and essential services. The current list of measures to address threats all have a place in other parts of the reports. Like the delegate from China suggested, we also propose to consider and discuss them there. Paragraph 7a, the first sentence. It is important for this group to build its work on a common understanding of the threats to international cybersecurity, so we welcome the addition of this paragraph. When recalling the threats identified previously, we ask that both the 2021 OEWG and GGE reports are referenced. So the beginning of the first sentence would be: “States recalling the threats identified in the 2021 OEWG and GGE reports.” On the list of paragraph 7b, I have three points that I would like to make. First, on item four, instead of using the words “threat intelligence,” we suggest using the wording “threat assessment.” Item six and seven, we consider that item six and seven in this list covering law enforcement and mutual legal assistance are in fact areas related to cybercrime, which are being actively discussed in the Ad Hoc Committee on Cybercrime. So to leave them out here. Then item 10, we welcome the reference to the general availability and integrity of the internet. As an editorial point, I would request for this concept to be reflected in line with the 2021 OEWG and GGE reports. In these reports, the concept is referred to as “the technical infrastructure essential to the general availability or integrity of the internet.” Thank you very much.

Ambassador Gafoor

Thank you very much, Netherlands, for your detailed comments. I give now the floor to Portugal, please.

Portugal

Mr. Chairman, we are very grateful for the inclusive draft proposal that you have circulated, which reflects, in our opinion, accurately all the common understandings that have been achieved since June 2021, in spite of a highly aggravating international peace and security landscape. In this regard, we are, of course, in full alignment with the European Union and other delegates who have underlined the strong impact on peace and security in cyberspace of the inexcusable invasion of Ukraine by Russia in flagrant violation of international law. Indeed, the applicability to the prevention, regulation, and resolution of conflicts in cyberspace of the UN Charter, of the Geneva Conventions, and of the UN Human Rights Conventions has been unambiguously reiterated several times by the UN General Assembly, namely upon the proposal of government experts appointed by the Secretary-General. On the other hand, upon the proposal of the same government experts, the UN General Assembly has also endorsed politically a framework of voluntary norms of responsible state behavior with a view to increase the stability and safety of cyberspace, while upholding its openness, neutrality, and accessibility according to the principles that presided over its creation. That was the outstanding double achievement of the overall work of the First Committee during its initial expert phase in this field. But thanks to a smooth transition under Ambassadors Guilherme Patriota and Jürg Lauber two years ago, we have now moved successfully up to a more participatory five-year phase under your able chairmanship, during which Member States are supposed to discuss and agree on how to ensure across the international divides that international security law and norms of responsible behavior are respected by all States with the concourse of dedicated and sufficient cooperation. The draft report which you have proposed is a mature step forward in that direction. We will be particularly pleased if it acknowledges the work already carried out and encourages its pursuit by the co-sponsors of a future Program of Action so that its suitability as a proper successor to the current open-ended working group gradually becomes consensual in the coming years before we move on to a third and permanent phase of our overall multilateral work on peace and security in cyberspace. Mr. Chairman, due diligence in cyberspace is, in our view, one of the most promising norms of voluntary behavior. The growing use of proxies by hackers, including of official proxies, is very worrying and can precipitate the use of unjustified countermeasures which will be especially dangerous in the context of an armed conflict. Therefore, before resorting to cyber weapons to retaliate against malicious operations apparently originated in another State, this State must be immediately called upon by the victim to confirm swiftly if digital devices on its territory have indeed been manipulated. Though the technical obstacles are many and hard to overcome, we should not desist from agreeing on a set of standards that increase the attractiveness of due diligence as a means to afford a pause before precipitating and aggravating a crisis generated by an attack against a critical infrastructure. Given that the vast majority of critical infrastructures in our societies are privately owned and/or run, some form of due diligence applicable to the private sector should perhaps also be devised. At least the benefit of the doubt should be given to those scholars who have been defending this development, and they should perhaps be invited to make written contributions to this debate. Once their views have been circulated, maybe a small group of Member States should write a foot-for-thought non-paper to foster further debate on the practical viability of a due diligence code of conduct. Thank you, Mr. Chairman.

Ambassador Gafoor

Thank you, Portugal. I now give the floor to Singapore.

Singapore

Thank you, Mr. Chair. I’d like to begin by expressing my delegation’s appreciation for the Chair’s efforts in driving the work of the five-year OEWG, including the mainstreaming of the ECWI, broadening the middle ground in international cyber discussions, despite the challenging geopolitical circumstances. We support the Chair’s vision of the OEWG as an action-oriented and inclusive process, aimed at delivering tangible outcomes and progress. We also welcome the Chair’s goal of using the Annual Progress Report to set out a roadmap for focused discussions on specific topics within the OEWG’s mandate over the course of the next year. On the Introduction section of the Annual Progress Report, Singapore supports the proposed language. I move on now to the section on Existing and Potential Threats. One of Singapore’s key priorities is critical information infrastructure protection, given that these national CIIs play a critical role in delivering essential services to our population and ensuring the effective functioning of the economy and society. On that note, we echo the concern raised by delegates from Canada, Costa Rica, the EU, France, and others that ransomware has become a major threat to the availability of these essential services and hence national security issues, and thus warrants inclusion. Singapore, as a small and highly interconnected country, would also like to draw attention to the idea of cross-border CIIs, which provide services critical to international trade, financial markets, global transport, communications, health, or humanitarian action across several states. Without clear regulatory control on cybersecurity measures for these cross-border CIIs, they become prime targets for cyber-threat actors who seek to exploit vulnerabilities in these CIIs. Similar to the consensus report of the inaugural OEWG, which recognized the need to protect these cross-border CIIs, we propose to incorporate a reference to cross-border CIIs at the end of paragraph 7b, sub-paragraph 2, by tagging on the phrase, including cross-border CIIs at the end. Operational technology (OT) and Internet of Things (IoT) systems are a special class of devices, where a cyber incident may have physical, real-world safety consequences. We would hence like to propose the inclusion of measures to resolve vulnerabilities in OT and IoT technologies amongst the list of proposals under the threat section, by incorporating a reference that reads, Measures and initiatives to resolve vulnerabilities in OT and in the interconnected computing devices, platforms, machines, or objects that constitute the Internet of Things, as a sub-clause under paragraph 7b. We agree with the three recommended steps detailed under the threat sections. These simple but practical proposals would allow us to kick-start closer cooperation as we defend against the growing scale and sophistication of cyber-threats. I move on now to the section on rules, norms, and principles. We agree with the proposals in all the sub-paragraphs, including the inclusion of the National Survey of Implementation in sub-paragraph 8d. As to sub-paragraph 8a, which calls for states to develop additional guidance or checklists on norms implementation, I’d like to give a quick update that Singapore is developing the norms implementation checklist with UNODA. The checklist is envisioned to constitute a simple guide for a set of actions that developing countries can take towards implementing the 11 voluntary, non-binding norms of responsible state behavior in the use of ICTs. This checklist will be developed through a series of workshops, which would gather views from countries from different regions, with the goal to develop an inclusively consulted checklist by 2025, when the OEWG ends. We’ve already concluded the first two workshops of the series with representatives from the ASEAN and Non-Aligned Movement member states, and a group of friends on e-governance and cybersecurity, where we discussed the implementation of norms G, J, and K. Given the rapidly evolving cyber-threat landscape, it is timely that the Annual Progress Report has considered the possibility of developing new norms over time in sub-paragraph B. Some possible areas which could benefit from discussions on new norms or further implementation of existing norms include the protection of electoral infrastructure and the general integrity and availability of the Internet. We agree with the three recommended steps under the norms section. The proposals in the Chair’s Summary of the 2021 OEWG Report would be a good starting point for discussions on norms implementation. Thank you.

Ambassador Gafoor

Thank you, Singapore. I now have the following speakers: Cuba, Austria, Malaysia, United States, and Pakistan. And once again, I invite all delegations to be as succinct as possible and refer their comments to sections A, B, and C of the revised draft annual progress report. Thank you very much. Cuba, you have the floor, please.

Cuba

Chairman, we thank you for your commendable efforts, and we extend our thanks to your whole team. We thank you for the timely publication of the report as a good starting point for our discussions. The positions of our delegation that were set out in the working document, documents that we submitted to the last Open-Ended Working Group (OEWG) session, and that have been developed since the beginning of the process within this second group, continue to be valid. We continue to stand ready to contribute positively and actively to this third substantive session of this working group, and we express our disposal and readiness to work with all delegations here present in order to achieve a progressive report that would be balanced and conserved as a basis for progress in the forthcoming sessions of the group. In line with your request to be specific in my statement, I will now proceed to list and read out my comments on the document. On section A, Introduction, in our view, the first introductory paragraph should not omit a reference to resolution 73-27 of the General Assembly. This contains a set of rules and established the first Open-Ended Working Group. Nor should it omit a reference to resolution 75-240, which established the current Open-Ended Working Group. We reiterate that the report of the Group of Governmental Experts (GGE) from 2021 is not acceptable for our delegation. We do not believe it relevant. We do not believe the applicability of international humanitarian law to be applicable to the use of ICTs in the context of international security. Therefore, this would imply tacit acceptance of the possibility of a scenario in which there is an armed conflict in this context. It would contribute to the militarization of cyberspace, and it would be a first step towards equipping a cyber attack added to an armed attack in which, yes, the rules of international humanitarian law do apply. On section B, Potential and Existing Threats, I will read out the following suggested amendments. We believe it’s important to reflect in the report the development of ICTs capacities for military means as a constant threat to be borne in mind. From our perspective, the exchange of technical information between states and risk assessments should be voluntary. We reiterate our proposal to consider the establishment of a glossary of terms for common use to facilitate the process of identifying and addressing emerging, existing, and potential threats. And we are in favor of the inclusion of a reference to our proposal to begin discussions in the context of the Open-Ended Working Group on the need to have a multilateral mechanism for the attribution of cyber incidents. Turning now to section C, Rules, Norms, and Principles of Responsible State Behavior, I will read out the following proposed amendments, including a reference to the review of the existing norms and the development of additional norms as we’ve proposed in previous substantive sessions of this working group. We are not in favor of excessively stressing rules, norms, and voluntary rules, norms, and principles for responsible state behavior in the area of ICTs. We will continue to support the beginning of a negotiation process in the context and the auspices of the United Nations to adopt an international legally binding instrument that would enable us to effectively respond to this based on multilateral cooperation to respond to considerable legal voids in the context of the use of ICTs. In this context, we believe that we should reflect the need or the possibility of developing legally binding mechanisms in line with the recommendations of the report of the Open-Ended Working Group from 2021. As well, we should also refer to the recommendations from forthcoming steps. Chair, as you have also stated, we have submitted our amendments in writing on behalf of Bolivia, Nicaragua, Venezuela, and our delegation. We will continue to send our views also for the REV1 version of the document. Thank you.

Ambassador Gafoor

Thank you, Cuba, for your statement. I now give the floor to Austria.

Austria

Thank you very much, Mr. Chair, and thank you for guiding us through this third substantive session of the Open-Ended Working Group, as well as for your work done both on the ZERO Draft as well as on the REV1. We look forward to working with you and hopefully to arrive at the progress report that is acceptable to all delegations. Austria aligns with the comments made by the EU on the threats chapter and by Czechia with regards to the participation of stakeholders in our meeting. Before I go on to some specific comments on the threat section, kindly allow me to pose a question for clarification on the draft and especially the recommendations. Are these recommendations meant to pertain to the whole remaining mandate until 2025 or only until the next progress report, so to speak, in 2023? From our view, the recommendations are aimed at the coming year only, and this is what our deliberations will be based on, but we welcome the clarification. Turning now to the threat section, to my delegation, this is a very important section because it should give us a frame of the challenges we’re discussing in the ICT environment. The OEWG has been mandated by the First Committee, which deals with disarmament and international peace and security, and thus this is the frame to which we should regard this threat section. Mr. Chair, you mentioned the OEWG should not be a talking shop but discussed concretely, and therefore we think that a concrete description of threats is key. We see our constituents and we see many stakeholders, both here in the room and both stakeholders that have been vetoed from being in the room watching our deliberations, and they would not be satisfied with an OEWG whose work is out of touch with the realities of the work we’re facing, and the work of the OEWG in such a case would be rendered less credible. Therefore, this section, as well as other sections, should focus on current challenges, and with regards to threats, this includes an overview of the current threat landscape. A case in point is the unacceptable and unjustifiable war waged by Russia against Ukraine, which has starkly brought to light the myriad threats emanating from malicious ICT activity. It goes without saying that Russia needs to stop this war immediately, and Austria continues to stand with Ukraine. As requested, a couple of concrete proposals on the REV1. Paragraph 7a, following my earlier remarks, in our view, this paragraph is too vague and not clear enough about the threats we’re facing, especially considering how the threat landscape has shifted since 2021 when both the Open-Ended Working Group and the GGE reports were adopted. Paragraph 7a should therefore be expanded and be made more specific. A couple of points that have been mentioned today and in past sessions, I would like to point those out explicitly. First, the escalatory potential of ICT operations, especially when their impact transcends national borders. Second, the potentially devastating humanitarian impact of cyber operations. This is, on the one hand, when critical infrastructure is attacked, which is a clear violation of IHL, and which goes counter to Security Council resolutions designed to protect essential civilian infrastructure. On the other hand, also, when cyber operations hinder the safe, swift, and unimpeded access by humanitarian actors to conflict zones. And third, as many delegations have mentioned today, ransomware. And we’ve heard how ransomware can be a threat when it affects international peace and security. Finally, on paragraph 7c, like other member states have pointed out before me, the role of regional and sub-regional organizations should not be diluted. Their value to this process, in our view, is not a proposal by member states, but it’s a fact. Thank you.

Ambassador Gafoor

Thank you, Austria, for your statement. Malaysia, you have the floor, please.

Malaysia

Distinguished Delegates, Malaysia welcomes the zero draft and the subsequent revised draft of the Annual Progress Report circulated by the Chair. Malaysia commends and appreciates the work done by you, Mr. Chair, and the Secretariat in taking an action-oriented approach by developing a substantive and balanced progress report. We share the aims of the Progress Report, namely to capture concrete progress made at the OEWG to date, with a focus on the proposal by States and the next step of the OEWG, as well as to set a roadmap for focused discussions on specific topics within the OEWG mandate. In this regard, Malaysia expresses our support and shared interest in moving forward towards the adoption of the Annual Progress Report by the end of this week with a view to maintaining the momentum and making further progress next year. Referring to the introduction section, Malaysia welcomes the draft Progress Report’s clear reaffirmation of the key consolidated decisions by previous processes. In this regard, Malaysia also welcomes the addition of paragraphs 2, 3, 4, and 5 in the Ref 1. Moving to the Existing and Potential Threats, Malaysia welcomes the recommendations listed in the Existing and Potential Threats chapter. We propose for these sections to raise full awareness about the existing range of threats, as suggested by many delegations, as this will provide important context to the rest of the report. For the section on Existing and Potential Threats, Malaysia would like to propose a paragraph to indicate the current and emerging threats, emphasizing that threats are increasing in frequency and becoming more complex and sophisticated. These include, among others, malicious cyber activities targeting critical infrastructure, ransomware, and state-sponsored malicious cyber activities. Recalling these threats briefly would assist us in setting the scene and provide clarity in our efforts to find consensus within the pillars under the OEWG mandate. Malaysia also supports the proposal by the United States to include threats brought by emerging technology. We take note of the technical and cooperative measures to address existing and potential threats in Para 7B. Malaysia supports the proposal to include the protection of cross-border CII, as well as measures to reduce the vulnerabilities of the OT and the IOT by Singapore. Malaysia welcomes paragraphs 7C and 7D, and Malaysia further welcomes the recommended next step for this particular section. With regards to the section on Rules, Norms, and Principles of Responsible State Behaviour, Malaysia is pleased with the proposal to continue the work to further develop guidance and common understanding concerning the rules, norms, and principles of responsible state behaviour, building upon the conclusions and recommendations agreed to in previous OEWG and GGE reports. Malaysia also welcomes consideration of the recommendations in the 2021 OEWG report for states to take note of the list of non-exhaustive proposals made on the elaborations of rules, norms, and principles of responsible state behaviour indicated in the Chair’s summary in the OEWG report. Malaysia further welcomes steps on surveys of or voluntary reporting on national implementations of rules, norms, and principles of responsible state behaviour, utilizing on a voluntary basis existing tools such as the National Survey of Implementations and reports to the Secretary-General on development in the field of ICT in the context of international security. Malaysia also supports the recommended next steps under the section on Rules, Norms, and Principles of Responsible State Behaviour. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Malaysia, for your statement. I now give the floor to the United States.

United States

Thank you, Chair. My prior remarks were very general, and I would like to take the opportunity, and I thank you for this recognition, to give more specific remarks. As I said in my opening remarks, the threat section needs to describe cyber threats. Others have echoed that point of view. And proposals for how to address threats should be elsewhere in the document. So the Chair’s updated draft may contain a starting point with paragraph 7a pointing to the threats mentioned in the last OEWG report, but this draft needs to acknowledge that the threat landscape has evolved significantly. The introductory section acknowledges that we are witnessing malicious use of ICTs by both state and non-state actors in the current challenging geopolitical environment. The threat section should note that cyber capabilities are being used in the context of an ongoing armed conflict, a new development, and have included disruptive, irresponsible, presumably unintended, disruptive spillover cyber activity. In addition, we believe that the annual report should acknowledge the emerging threat of ransomware, the increased risk of escalatory or uncontrolled cyber activity, and the cyber threats now faced by humanitarian actors. In the midst of the COVID pandemic, we have all become more aware of the cyber risks to the healthcare sector where a relatively minor disruption or manipulation of data can cause loss of life. We have also become more aware of the risks posed by cyber criminals, not the focus of our efforts, but who are allowed by certain states to operate with impunity from their territory. All of these issues are relevant for this group. The laundry list of potential measures laid out in paragraph 7b, however, does not belong in this section. Furthermore, some of these measures seem out of scope for the OEWG altogether, as had been mentioned earlier, such as law enforcement cooperation, best practices, etc., or they’re not going to gain consensus report. Relevant proposals that are likely to gain consensus report should be raised in appropriate sections with sufficient detail to be actionable. Paragraphs 7c and 7d also address issues not relevant to the threat section and should be deleted. In addition, the OEWG should not be treated like a cybersecurity best practices technical forum or as a forum for cyber incident response. That is not the purpose of the OEWG, as I said earlier, nor is it within its mandate. Therefore, paragraphs 2 and 3 of the next steps subsection should be revised or deleted. On the issue of rules, norms, and principles, I would note that the section is robust, but it would benefit from a clear statement in paragraph 8 that states should continue to implement the existing norms that have already been endorsed by consensus at UNGA. In paragraph 8a, the United States does not support proposals for the UN to develop “common understandings of technical ICT terms,” as a general matter, and would certainly not see that as an OEWG responsibility. To improve understanding among states, we support sharing of national definitions of ICT terms where it is feasible so that we do not misunderstand one another. And we have the same comment regarding paragraph 2 in the next step section. 8b does not appear to be an actual concrete proposal. It’s just a quote from the 2021 report, and it should be deleted. If it is retained, the text needs additional balancing language at the beginning that says states proposed prioritizing the implementation of existing norms before states proposed the additional norms, etc., in order to capture the nature of our discussions more accurately. Is 8c supposed to be about best practices and cooperation in the area of norms implementation? It is vague and unclear as written, and the text should be clarified. 8d appears to include the first mention of the Secretary-General’s annual report and should include a citation noting that this report was called for in UNGA Resolution 7619. In the recommended next step section, paragraph 1 should refer specifically to implementing the norms already adopted by consensus at UNGA via its consensus endorsement of the GGE and OEWG reports. Thank you, Chair.

Ambassador Gafoor

Thank you, United States, for your comments and detailed contribution. Pakistan, you have the floor next.

Pakistan

Thank you, Chair, for giving me the floor and the opportunity to present Pakistan’s view on the Annual Progress Report. Taking this opportunity, I would like to express my appreciation for your untiring efforts to steer the work of the OEWG in a steady and balanced manner. Chair, Pakistan attaches great importance to this OEWG, which is a platform represented by all member states and has the potential to make cyberspace secure, stable, and accessible for every country in the world. Coming to the draft Annual Progress Report, Pakistan welcomes it. We believe that it’s a balanced draft that provides a base for further discussion and reaching a draft acceptable to all. To make the report more balanced, Pakistan has the following proposals. We believe that the measures to counter disinformation and fake news and measures for the timely disclosure of vulnerabilities must be added as technical and cooperative measures to address existing and potential threats in Para 7B at numbers 11 and 12, respectively. Moreover, there is a need to define and explain other relevant processes and entities as mentioned in the revised draft in Para 7B at numbers 6 and 7, respectively. Like any other country, Pakistan is confronting a multitude of threats posed by ungoverned cyberspace. Rising cyber attacks against critical infrastructure, distributed denial of service attacks, data theft, and targeted disinformation campaigns are some facets of cyber security challenges faced by my country. Therefore, Pakistan consistently calls for a legally binding instrument to promote responsible states’ behavior in cyberspace. On the militarization of cyberspace, Pakistan’s position is consistent. We consider the internet as a common heritage of mankind and believe that the use of cyberspace for military purposes is gradually converting it into an arena of military confrontation. Therefore, Pakistan calls for an outright ban on the development of offensive cyber weapons. On the development of rules, norms, and principles of responsible states’ behavior, the portion of the report is balanced. In line with the recommendation of the 2021 OEWG report, Pakistan is ready to discuss the proposals put forward by other states on the subject matter. Pakistan proposes the mentioning of 11 norms of responsible state behavior as agreed in the GGE report of 2015 in Para 8 of the Annual Progress Report. I would like to reiterate Pakistan’s position on the further development of the rules, norms, and principles of responsible state behavior in cyberspace. It is quite clear that we do consider the formulation of non-binding voluntary norms important for secure and stable cyberspace. However, these non-binding norms cannot be an alternative to a legally binding instrument. The main difference between non-binding norms and a legally binding instrument is that the latter imposes certain obligations and their violation triggers the law of state responsibility. Moreover, norms are effective during peacetime only and will lose efficacy in the event of conflict. Pakistan believes that there is a need to equip the member states with the required skills and technologies and to clearly define the modalities for the implementation of the agreed norms. I thank you, Chair.

Ambassador Gafoor

Thank you very much, Pakistan, for your succinct and concrete contributions. I now have the delegations of Israel, Argentina, Australia, Czech Republic, and Ghana. Once again, I’d like to invite your delegations to be as succinct as possible and to focus on sections A to C. Thank you. Israel, you have the floor, please.

Israel

Thank you, Mr. Chairperson. At the outset, the Israeli delegation wishes to express our gratitude and appreciation to you, Chair, and your team’s hard work in preparing, organizing, and steering this process. Israel commends the work conducted to present a balanced, zero-draft report. We will now highlight some general thoughts on the text, and as we drill down on the different sections, we will offer additional concrete amendments and language. Mr. Chairperson, like others, Israel believes that the annual report should emphasize that we are building our discussions and the report on the strong foundations laid by previous GGEs and the Open-Ended Working Group consensual reports, as endorsed by the General Assembly. Mr. Chair, with regards to the section in the report relating to threats, since we last convened here in New York, we have unfortunately witnessed another rise in cyber risks and threats. As the world continues to struggle with the COVID-19 pandemic consequences, more interactions and operations moved online, thus blurring boundaries between public and private and expanding attack surfaces. Major geostrategic developments have increased cyber-offensive operations, and they are turning more sophisticated and harmful. Malicious actors are becoming more brazen. Ransomware attacks turn into a real global pandemic that targets governments’ critical infrastructure, as well as essential services, including hospitals and the health system, water infrastructure, and energy supply, while instigating enormous human and economic losses. The technological landscape continues to be more interconnected and embedded in all areas of our lives, while the cyber workforce isn’t growing to supply the growing demand. All these create ever-increasing strategic national and international challenges and threats. Preparing for them and mitigating them will require political will, vision, action, and more cooperation across organizations, sectors, and borders. In light of the above, Israel believes that the text should include specific reference to threats such as cybercrime that crosses the threshold by threatening international security and stability, especially ransomware, also to critical vulnerabilities, as well as threats against operational technologies and SCADAS. Mr. Chair, more than ever, the cyber domain continues to pose global challenges that should be faced with multinational and bilateral efforts. Speedy and effective international engagement and cooperation are essential as well. Israel, as an internationally acclaimed high-tech hub and a leader in cybersecurity, seeks to harness its strengths in cybersecurity to promote global cyber resilience and offer cooperation based on shared values and trust. Israel attaches great importance to global security and stability in cyberspace and continues to support and offer its part to international efforts aimed at enhancing global cyber resilience. We look forward to working with UN member states to identify cyber threats of shared concern to international peace and security and to implement effective measures aimed at diminishing those risks. Mr. Chair, the multistakeholder community plays an integral role in the issues under discussion in this group and can provide perspectives that can help us better understand these issues and assist states in reaching consensus decisions. Israel therefore supports the consultative role of intergovernmental organizations, civil society, industry, and the technical community and academia in our discussions. Finally, Mr. Chair, Israel attaches importance to the work of the Open-Ended Working Group and remains committed to working with you and other delegations to achieve a consensus-based outcome of the open-ended working process. Thank you, Chair.

Ambassador Gafoor

Thank you very much, Israel, for your contribution. I give now the floor to Argentina, please.

Argentina

Mr. Chairman, I’d like to begin by saying that the Argentine delegation supports your view in favor of the adoption of an annual report, which would serve as an input for the final report, which at the end of its mandate, the Open-Ended Working Group should submit to the General Assembly. Argentina would like to thank you for preparing the zero draft and its first revision. This is a balanced document that has managed to capture the spirit of the debates that were held during the first and second substantive sessions. We thank you for swiftly and against the clock reflecting the concerns put forward by states. This represents a good basis for beginning our negotiations. The REV1 is ambitious, and it will take hard work to achieve a consensus. The Argentine delegation invites member countries to maintain a constructive and flexible spirit that we’ve shown during previous meetings in order to facilitate a robust and substantive final document. Maintaining stable and peaceful cyberspace is a complex and sensitive matter that is liable to affect international peace and security. For Argentina, which is a country that supports robust multilateralism, the only way of facing global challenges is by generating collective solutions. In this context, we reiterate the importance of keeping an inclusive forum so that states as well as representatives of civil society, the private sector, academia, and the technology sector can continue to contribute to maintaining, consolidating, and generating understandings, capacities, tools, and norms in favor of the responsible use of ICTs. This should be to achieve greater stability and predictability in cyberspace. These years of work have led to a format of debate that is both valuable and lively on one of the most important topics of the new international agenda. This cyber diplomacy represents a great opportunity to show the international community the results that this type of debate can generate. Argentina reiterates the importance of having a safe, open, free, and interoperable cyberspace for people, companies, societies, governments, and for social, economic, and political development both for the present and the future. In a constantly evolving world, we are witnessing increasing incidents of greater or lesser seriousness that are affecting the security of people, companies, societies, and essential infrastructure of our countries. States, therefore, need to be able to react immediately and with solidarity in order to counter these threats for our societies. We therefore support the initiatives aimed at strengthening cooperation and capacity building. With regard to the text in particular on threats, the Argentine delegation would like to underscore the following points. The development of ICTs is dynamic. As ICTs are being developed and diversified, we see new challenges to our critical infrastructure. Therefore, Argentina believes it’s important to maintain open and applicable debate on this matter. Argentina also believes that it is the power of each state in the context of its own national cybersecurity strategy to define what it considers to be a threat. Therefore, we would thank the chair for including paragraph A, which captures the spirit of this concern. Moreover, Argentina believes that it would like to refer to threat intelligence. This is a point that we believe is necessary and possible. The private sector looks at the operation of malicious software, and this allows it to malware, which allows it to maintain and update its compendia of threats constantly over time. Generating international cooperation with the private sector in this area would represent a tangible, concrete benefit for the whole community. Argentina promotes the strengthening and, as necessary, the generation of CERT networks. These are spaces for the sharing of information, experiences, and also to understand best practices. In this context, the regional cooperation in the OAS represents added value as the CERT Americas network includes countries with similar capacities. Finally, with regard to critical infrastructure, Argentina believes that its classification is the exercise of each state. This should be carried out, and the results should be shared if possible. This delegation understands that there is a broad range for international cooperation in this area, for instance, CII protection mechanisms and methods, and in order to put capacity building. On section C, on the responsible conduct of states, we would like to underscore that while it is important to underscore that achievement up to date is continued up to date, it is important to continue our work in order to better understand its scope. The cybersecurity agenda is a novel agenda and, therefore, affects the international community as a whole, but the synergies of this system mean that we need a robust debate to create consensus on the responsible conduct of states. This should be based – a norms-based order would be beneficial to predictability, transparency, and stability for the whole international community. The national cybersecurity strategy in Argentina promotes the peaceful use of cyberspace and supports any initiative that aims to install values such as justice, respect for international law, balance, and a reduction of the digital divide between nations while also promoting discussion and dialogue. Bearing this in mind, Argentina promotes continuing to support – to work dynamically in this context. Argentina supports the exploration of formats such as the creation of a shared repository which could set out the norms in this area. This could include information on existing and potential threats as well as the exchange of best practices and mitigation measures together with other tools that the community might deem relevant. Thank you very much.

Ambassador Gafoor

Thank you very much, Argentina. Australia, please.

Australia

I want to thank you first for your REV1 proposal. I can see from the hard work that you and your team have done weaving together the various strands of our discussions into a reflection. And I also welcome the ambition and objectives of this report to consolidate practical proposals and identify consensus recommendations, which can provide a roadmap for our future work. Before I start, I wanted to recognize and draw some optimism from our process by the statement that was made by my esteemed colleague from China, that the most important position for this session is to honor our previously made commitments. And to say that Australia’s primary goal for this annual progress report is incredibly similar, to make sure that we respect and uphold and build upon our consensus-agreed commitments and protect that agreed framework of responsible state behavior. Taking on board your request, Chair, to make very specific language proposals, most of the proposals I am making draw upon consensus text that has already been agreed by our predecessors, trying to recognize that we’re not starting from scratch. And if an issue has already been solved in the past, I suggest in the interest of time, it might be easier where appropriate for this group’s purposes that we try and use those existing solutions. So turning to the introduction, regarding paragraph one, Australia can support the proposal by the Netherlands regarding this paragraph, that is to include a reference to the rising concern of malicious use of ICTs by state and non-state actors against critical infrastructure, including in the context of armed conflict. The proposal to include a reference to the GGE report and also the proposal to alter the second last sentence referring to our framework. Turning to paragraph two, I request a small amendment to the very last word of this paragraph. It currently reads agreements. We would like to change this or suggest changing this to the word commitments. That’s because it’s referring to the responsible state behavior framework and encapsulating our entire framework, which includes international law, voluntary norms, CBMs, and capacity building. And this should be reflected here. Turning to paragraph three, Australia welcomes very much the inclusion of this paragraph and recalling the extensive discussions on the role of multistakeholders throughout our first and second sessions. We think that it’s helpful that the progress report reflects those conversations and we welcome how it is reflected here. We suggest the additional sentence which draws from paragraph three of the 2021 GGE report at the end of this sentence. And this would read, the OEWG recalled the importance of engaging other actors, including the private sector, civil society, academia, and the technical community where appropriate in states’ efforts to implement the recommendations of previous OEWG and GGE reports. And I should note that everything that I’m proposing, I will send you in writing. On paragraph four, we also very much welcome the inclusion of this paragraph and support the recognition of the various forum processes across the international multilateral architecture that are very relevant for our discussions. We could support Mexico’s proposal to also reference regional efforts, not just organizations. And we could accommodate China’s proposal for the first part of this paragraph that is saying that in the field of security, the use of ICTs, the regional organizations could play a role in implementing the framework of responsible behavior of states in the use of ICTs. And then we’d request an additional part to the end of that sentence, which is drawn from paragraph four of the 2021 GGE report, which says, and recalled the important role of regional and sub-regional bodies in taking forward the assessments and recommendations of previous GGE and OEWG reports. Turning to paragraph five, we very much also support the inclusion of this paragraph and request a small amendment. The paragraph talks about gender and the meaningful participation and leadership of women. It also asks for the effective participation of women. And we’d like to request that the word effective be changed to the two words full and equal. This is because there is no requirement for men’s participation to be effective, and so this shouldn’t apply to women. Thank you. Turning now to the existing and emerging threats. I align with and reiterate many of the comments that have been made already today. And that is that this group and its predecessors have been discussing the threats to international peace and security posed by states’ use and misuse of ICTs since 2004. And it would be incongruent with the spirit of what this international community has achieved to date to ignore the reality that we face. As Undersecretary-General Nakamitsu made very eloquently this morning, she made points on the current and growing threats faced by us all, and that the use of ICTs to support active hostilities is no longer becoming more likely, but is a reality. We would like to see the threats faced and the threats that have been raised by many countries in our first and second sessions be reflected in this report. As many delegations have said, previous reports have described what the threats are. And these threats provide a context against what the following chapters say and where they flow. And it provides the context through which the work of this group actually becomes meaningful. I have drafted with some others some texts that I was going to propose to be included after paragraph 7A that adds language to characterize the threats that we face and those threats that have been identified. But I would welcome working on this text with those several delegations who have already raised in the room that they would like to work on this text so that might be able to propose some texts which would garner consensus. And if anyone wants to reach out to me to input into that, please come forward. Turning to paragraph 7B. This paragraph, many of the measures here aren’t new and we’re talking about measures, not threats. So my proposal is that we move those sub-paragraphs below in paragraph 7B to the appropriate chapter that the measure belongs to. And to be very clear, measure sub-paragraph I or 1 belongs to the capacity building chapter. It’s referenced similarly in paragraph 61 of the 2021 OEWG report, 89B of the 2021 GGE report, and 20A of the 2015 GGE report. So it’s well and truly covered and talking about the capacity building. Number two, we would suggest moving either to the confidence building chapter as it’s set out in that chapter in the 2021 GGE report at paragraph 85 or it could be moved to the norms chapter. It’s a rewording of norm 13G. And rather than referring to the classification of critical infrastructure, as was put in the text here, I would propose using consensus text that we’ve already agreed. And we have a couple of options. The 2015 GGE report at paragraph 16D refers to the voluntary provision by states of their national views of categories of infrastructure they consider critical and national efforts to protect them. Or we have another option, which is from the 2021 OEWG report, which asks states to voluntarily share national views on the classification of critical national infrastructure and critical infrastructure providing essential services regionally and internationally. So we have a couple of consensus options there. Number three, we’d suggest moving this to the norms chapters. It’s a paraphrasing of norm 13I on paragraph four, suggest moving this to the CBMs chapter as per the transparency measures that are set out in the 2021 OEWG and GGE reports. On paragraph five, this could be moved to the capacity building chapter given the reference to cooperation and assistance. The sentence at number six on training for law enforcement officials corresponds to norm D, which is to assist each other, prosecute terrorists in criminal use of ICT. And here I want to align with Brazil’s point that cyber crime, including ransomware, is relevant to our work, but only relevant when it reaches a threshold through its scale, sophistication, or effects that risks impacting international peace and security. I would not support the inclusion of sentence at number seven regarding mutual legal assistance, given that this is very much in the purview of a third committee process that’s ongoing and will be here in about a month. On number eight, suggest moving this to the capacity building chapter as it’s tailored as a reference from the 2021 OEWG capacity building principles. On number nine regarding measures to enhance data security, this could be addressed under norm A. And finally, 10 regarding the general availability and integrity of the internet. This corresponds to norm F and I’d also agree with the rephrasing proposed by the Netherlands there. Turning to the recommendations, Australia would prefer to keep recommendation one as it is with the reference to security in the use of ICTs, but we’re open to considering China’s proposed additional recommendation one BIS. Turning to chapter B, the rules, norms, and principles chapter. We welcome the proposal made by many to make reference in paragraph eight to the consensus norms that have been endorsed by the General Assembly and the aim of this group to help implement those norms. We would agree with the European Union and also proposed by France on paragraph eight A, which is to delete the last clause of that sentence. We do not agree to the proposal to develop common understandings on technical ICT terms. I note that this is also included in recommendation two of this chapter and also in paragraph 10E of the CBMs chapter. Australia considers that our collective aim should be better to understand each other and thereby build trust and confidence and not to impose a top-down framework. And that this will be any aim at harmonizing terminology will take a significant time investment, but also could be potentially harmful because by necessity, such harmonization has to disregard the particulars of particular cultural contexts and diversity. Turning to paragraph eight C, we suggest amending this to refer to the norms that it is referring to. So it’s referring to norm J on vulnerability discussion and to norm G on the protection of critical infrastructure and then probably deleting the part on cooperation between certs, because this is the CBM and should therefore be reflected in the CBM chapter, not the norms chapter. Turning to paragraph eight D, like Malaysia, we strongly welcome and support this paragraph. Regarding the survey, I’ve heard informally that over 200 of us have started the survey on the UNIDIR cyber policy portal. And I encourage others, including my own team, to persevere. Australia is finding it very useful process across government trying to pull together our input. Finally, turning to recommendation three, again, we strongly support and welcome the inclusion of this paragraph. As Mexico said, it is included in the consensus recommendations of both the 2021 OEWG and GGE reports. As I said, I’ll send all these textual proposals to the secretariat, which you are very welcome to share with others. I note that several in the room have said that you’ve provided textual proposals. I can’t find these on the OEWG website and I encourage those who want us to consider your proposals, please share them with us so that we can. And finally, I would like to briefly align with the statements of the Czech Republic and Brazil today regarding stakeholder participation. Thank you, Chair.

Ambassador Gafoor

Thank you very much, Australia, for your very thoughtful and detailed comments. I am in listening mode, but I just wanted to echo what was just said by our delegate from Australia. I think it’s important that we are in the frame of mind of building consensus and looking for consensus solutions. I did mention in my letter when I circulated the revised draft that I have a good sense of what your preferred positions are. I think I have a good sense of your preferred positions on the various issues, but it’s not a question of how we compile a list of preferences but how we put together a progress report that is able to command a consensus. So, where necessary, we’ll have to resort to referring to previously agreed language, and I think our friend from Australia provided some useful references there. But there will be many other instances where we will have to agree on language proposals for which we may not have references in prior documents, and that too will require that we build consensus. I would encourage, having heard the views of delegations almost throughout the day, that you reach out to others, and where there is a difference of view, perhaps try and find consensual wording or consensual formulation because that will be very helpful to the process and also to me in the chair. Finally, in terms of the various proposals that have been made, I’m very encouraged that there have been a lot of very detailed reflections. Do send them to me, but I would also encourage you, as Australia has suggested, that you circulate it widely and put it on the website. Send them to the secretariat asking that it be put on the website because it’s important that everyone is able to see it, and if there are delegations that disagree with your very detailed comments, then well, at least we know. But if delegations are able to work with your proposals and find possible compromise formulations, then I think we are making a step forward. So do help me find formulations. I’m very happy to be in the position of receiving hundreds of textual formulations, but I can’t possibly put all of them in a blender and extract the juice of it and come up with a smoothie that will find a smooth way forward. So I will need help with textual formulations, and listening very carefully to the discussions today, I am having a bit of mixed emotions because there are many good proposals coming, but there are also many comments and proposals that put forward preferences and preferred outcomes, even if they are not put in such a way. But they’re coming from the perspective of “this is my preferred outcome” or others saying, “well, my preferred outcome is the opposite point of view,” for example. But we need to get into the middle, and that’s where I do encourage each one of you to reach out and talk to each other. If groups of you can gather to help put together compromise formulations, that will be immensely helpful to the process. I hadn’t intended to say this at this point; I was waiting for the end of the discussions, but Australia’s useful comments on previously agreed language prompted me to intervene. So let me continue with the rest of the speakers’ list. We’ll have to press on with the rest of the speakers’ list today and, of course, tomorrow. I give the floor now to the Czech Republic, to be followed by Ghana. Czech Republic, please.

Czechia

Thank you, Mr. Chair. First of all, I would like to thank you and your team for all your work. I can assure you of the continuing support of the Czech Republic. The Czech Republic aligns itself with the EU statement delivered earlier and wishes to emphasize a couple of points in our national capacity. The Czech Republic has been a long-time contributor to the Open-Ended Working Group discussion on current and mentioned threats, so I believe our general position is known. Nevertheless, I would like to underline our key priorities, and I will then turn to specific comments on your draft annual report. In the current international situation, I can hardly begin with any other point than the unprovoked Russian aggression against Ukraine, which represents a flagrant breach of international law and a distortion of the entire rule-based international order. As the EU representative and other colleagues have already clearly described, Russian aggression is also being waged in cyberspace and is having serious spillover effects. Malicious cyber activities related to Russian aggression are a source of instability and pose a serious threat. It’s not about politicization; it’s about seeing the truth. Another major threat is the general expansion of malicious cyber activities. The number of harmful incidents is increasing, and they’ve been getting more and more sophisticated. In particular, harmful activities targeting the critical infrastructure that provides services to the public, domestically, regionally, or globally, represent a serious threat to peace and security. As we have stated repeatedly in previous Open-Ended Working Group meetings, we are seriously concerned about the possible abuse of new technologies to constrain human rights and fundamental freedoms. We have witnessed the assertion of greater control over the internet with the pretext of ensuring national cybersecurity while disregarding international human rights law and principles of an open, free, secure, and interoperable internet. We have also seen unlawful arbitrary surveillance, unlawful arbitrary restriction on encryption and anonymity, and restriction of content of network shutdowns, all of which are inconsistent with international human rights law. We are of the opinion that these practices also represent a threat and should be reflected in the draft annual report. As for the report itself, we will commit as a good basis for our discussion, and we are convinced that we can finalize it in the current meeting of our group. In addition to the recommendations I’ve already made, I would like to add a few suggestions to improve the text. I would like to strongly support those countries that mentioned the increasing intensity of ransomware attacks as another important threat. I would like to stress the word “increasing intensity,” directed to some delegations who cast doubt about including it in our work. I have to admit that in the past, we also considered ransomware attacks as a part of the cybercrime domain, which is being dealt with in another forum, but exactly the increase in their intensity is what makes them a threat to international peace and security, as Australia mentioned just a couple of minutes ago. The Czech Republic has long and repeatedly called for ensuring the security and integrity of supply chains. The draft annual report, in our opinion, doesn’t sufficiently address this issue and mentions only the integrity, but not the security, of the supply chain. Also, this issue is not merely about the prevention of the use of harmful hidden functions, as the draft report states, and it’s also already addressed in the EU contribution. It also includes the malicious exploitation of vulnerabilities, targeted supply chain attacks, and more. According to our view, it’s not desirable to single out only one of those malicious activities, nor try to list all of them, as the list would never be exhausted. We will therefore propose to amend this program. The Czech Republic is not convinced if it’s appropriate for the report to include areas that are currently being discussed in another forum, in particular by the cooperation among legal enforcement officials and the deepening of mutual legal assistance. Whilst undoubtedly an important issue, it is currently being discussed in an ad hoc group under the third committee. We should not interfere with their ongoing work or prejudice their future conclusions. So, as the Netherlands and other states already mentioned, we prefer to delete it. As for norms, principles, and responsible state behavior, section C, the Czech Republic is convinced that adherence to your framework of responsible state behavior in cyberspace is absolutely essential to assure peace, security, and stability. The implementation of the 11 norms of responsible state behavior, unanimously endorsed by the UN General Assembly, is our top priority. For us, this is closely linked to capacity building, because compliance in practice requires a high level of cybersecurity. At the same time, we are persuaded that working with the broadest possible range of stakeholders and experts will enhance the implementation of the norms. The Czech Republic doesn’t just talk about the need to implement responsible behavior norms. We take concrete action, focusing on critical infrastructure over the past year. The government of the Czech Republic, the Cyber Peace Institute, and Microsoft worked together to build a global, multistakeholder community dealing with the protection of the healthcare sector. By drawing on the experiences of hospital staff, IT professionals, capacity building experts, diplomats, national service, and first responders in countries affected by hospital cyber attacks, they put together a compendium of best practices and recommendations to better protect this vital sector from cyber harm. This multistakeholder community has provided constructive, inclusive, and action-oriented contributions that can assist states in implementing cyber norms and protecting one of the most critical infrastructure sectors. We will present our compendium at the launch event on Thursday at midday. I would like to cordially invite all interested parties to this event. As for the annual report, I have only one comment. I would like to support the countries that have expressed concerns about launching an exercise of ICT terminology and the common understanding of ICT terms. Mr. Chair, thank you for your effort. We value your work, and we look forward to completing the annual report this week in the Open-Ended Working Group meeting. Thank you.

Ambassador Gafoor

Thank you very much, Czech Republic. Delegation of Ghana, please.

Ghana

Mr. Chair, thank you for giving me the floor. At the outset, my delegation wishes to assure you of our continuing support and cooperation for your role as the Chair of the Open-Ended Working Group on security of and in the use of information and communication technologies. Ghana welcomes the revised draft of the Annual Progress Report of the OEWG, and we are encouraged that the document reflects most of our proposals from previous sessions of the OEWG. Mr. Chair, concerning the section under discussion, my delegation wishes to indicate that while the text under Section B of the OEWG Zero Drafts Report on existing and potential threats provides an adequate framework under which Member States can dialogue and elaborate on measures aimed at preventing, managing, and responding to cyber security threats and cyber security incidents, there is a need for a further elaboration in the draft report of threats such as ransomware, misinformation, online sexual exploitation, criminal and terrorist use of ICTs, and threats affecting critical infrastructure as identified by my delegation during the second substantive session. We believe that the description of cyber threats in the report will offer Member States specific areas to focus our discussions on. Mr. Chair, Ghana is particularly supportive of the provision made in the draft regarding the development and dissemination of best practices on the classification and protection of critical infrastructure and critical information infrastructure, as this is in line with our submissions during the second session of the OEWG. Furthermore, it is consistent with the objective of Ghana’s Cyber Security Act 2020, CII Directive, and the African Union Convention on Cyber Security and Personal Data Protection. We also agree that strengthening tailored capacity building activities should be prioritized. We believe that mutual agreement to provide legal assistance is critical for the successful prosecution of cyber crimes considering jurisdictional competence for enforcement. Also, working together and providing assistance to create and improve computer emergency response teams is necessary in our objective to ensuring the security of ICTs. Additionally, we are in favor of the suggested course of action for states to participate in focused discussions on the protection of CI and CII at the fourth and fifth OEWG sessions with representatives from the various regions and sub-regions, as well as representatives from interested stakeholders, including businesses, non-governmental organizations, and academia, given the immense value of sharing relevant experiences with these entities at the OEWG. On rules, norms, and principles of responsible states’ behavior under Section C, while we support the need for states to consider surveying or voluntarily reporting on their national implementation of rules, norms, and principles of responsible states’ behavior using existing avenues and tools like the National Survey of Implementation, we wish to reiterate our call for the need to also take into account the 11 voluntary non-binding standards of responsible states’ behavior as they show great potential in reducing risk to global peace, security, and stability. We are also of the view that information exchange between states is essential to ensuring stability and security in the use of ICTs. In light of this, best practices on information exchange and collaboration should be improved and should include the sharing of information on vulnerability disclosure, the protection of CII, and cooperation between states. I thank you.

Ambassador Gafoor

Thank you very much, Ghana, for your very detailed comments. I now give the floor to Kazakhstan.

Kazakhstan

Thank you, Mr. Chair. Kazakhstan has international traits and areas of practical interaction within the framework of the Shanghai Cooperation Organization, the Collective Security Treaty Organization, and the Commonwealth of Independent States, and also actively participates in the discussion of issues related to ICT security within OSCE, the Conference on Interaction and Confidence-Building Measures in Asia, and in particular, within the framework of the Informed Working Group in the field of OSCE and cybersecurity. Kazakhstan, together with Canada, supervises confidence-building measures, within which it is advantageous that participating states will, on a voluntary basis, share information on the measures they have taken to ensure openness, security, and reliability of the Internet. Within the framework of the Conference on Interaction and Confidence-Building Measures in Asia in 2021, new confidence-building measures on the security and use of ICT were approved, which is currently chaired by Kazakhstan. In October 2022, at the next summit of the Conference on Interaction and Confidence-Building Measures in Asia, it is planned to adopt a statement by the heads of state. In view of the foregoing, we note the importance and timeliness of point A in the context of international regional cooperation. Kazakhstan is taking comprehensive measures to counter cybersecurity threats at the national and international levels. The state policies are implemented within the framework of the Kazakhstan Cyber Shield concept, which provides for the qualification and trace and specific measures to level them. Incidents are of a cross-border nature and equally threaten the security and infrastructure of each of the countries. We believe it’s important to support the point on cooperation and staging of computer incident response teams. This is our opinion. We also establish direct contacts between the National Computer Incident Response Service. For its part, the National Computer Incident Response Service of Kazakhstan has already concluded 26 memorandums with international organizations. As an achievement of practical experience, we annually conduct cyber exercises as well as practical conferences. This year, from September 14-16, in Almaty, Kazakhstan, the International Practical Conference Kazakhstan 2022 will be held, which will be devoted to topical issues of cybersecurity. Moreover, within the framework of the conference, the ITU of the United Nations will organize an interregional cybersecurity exercise for the CIS region and the Arab states. We believe that such events will increase practical experience in responding to computer incidents as well as strengthening international cooperation, which generally corresponds to point six of international exercise and technical training. We also want to support point 10, as Kazakhstan pays great attention to creating a safe internet from malware and phishing, in particular in order to protect the Kazakhstan segment of the internet. Together with the provider company of websites with .kz domain names, we’re giving the opportunity to be protected by the web totem systems. In addition, together with a Kazakh company, the bug bounty vulnerability and detection program was launched. We research and receive appropriate rewards for discovering vulnerabilities in systems and websites. More than 1,200 independent cybersecurity experts from around the world have already registered on the bug bounty platform, from which more than 1,200 reports of vulnerabilities have been received, some of which are critical. On the most important issues of global digitalization and information security, to address these issues, the Cyber Shield of Kazakhstan concept is being implemented, within the framework of which a set of measures was taken on cybersecurity issues, which positively reflect in the UN Global Security Ranking. Kazakhstan is ranked 31st. We face the common task of ensuring cybersecurity in a single state, as an able and independent country, modern threats. In this regard, Kazakhstan is ready to participate in the process of exchanging experience in building international cybersecurity systems. Since 2009, the country has been operating the computer incident response service. Along the line, as part of the international exchange of information for the current year, more than 2,060 notifications were sent to 40 states. Today, ICT plays an important role in all spheres of life. In this regard, we consider the proposal to expand the exchange of information between states as a very important initiative. In conclusion, Kazakhstan fully supports the work of the Open-Ended Working Group, aiming at finding consensus on the key international agenda in the field of ICT. We believe that the adoption at the end of the current session of the interim report will fully contribute to this, in accordance with UN General Assembly Resolution 76-19. Thank you for your attention.

Ambassador Gafoor

Thank you, Kazakhstan. Distinguished Delegates, I have 20 delegations which have been inscribed to speak, and I know that there has been some frustration among delegations waiting to speak, but I wanted to assure you that we are following the order in which delegations have been inscribed to speak, as reflected by the system here on the screen. So I wanted to assure you that you will get an opportunity to speak. Tomorrow we will begin at 10, and it is my intention to also add to our discussion the sections relating to international law and confidence-building measures. So for those delegations which are inscribed to speak, I would invite that you comment not only from sections A to C but also address in your comments sections A, B, C, as well as D and E, relating to international law and confidence-building measures. Secondly, I would like to appeal to delegations that in making your comments, please be very specific with reference to the revised draft of the annual progress report, and where it is possible, please refer to comments already made by delegations today and groups of delegations to indicate your support for the positions or otherwise. That will be very useful for everyone here as to whether a proposal that has been made today enjoys the support of other delegations or does not enjoy the support of other delegations. So do come prepared for those delegations that are inscribed to speak, not necessarily to read your prepared statements as they might have been prepared in capitals, very diligently prepared no doubt, but I would urge you to be succinct and summarize them as a way of reacting already to the proposals that have been made. And once again, I have not today interrupted any delegations. Some of the statements were of a general debate nature, others were very, very pointed and detailed, and I do not as a rule like to intervene to stop delegations from making their statements. It is indeed your sovereign right to make a statement, especially in a forum like an open-ended working group, which is inclusive, very transparent, and very democratic. But I think in order to be fair to every delegation, it is really important that we address the issue at hand, which is the draft annual progress report before us that needs to be considered and that needs to be adopted by the end of the week. So tomorrow we will start with the first speaker from the list that we were not able to hear today. The first speaker will be Indonesia, to be followed by El Salvador, India, Japan, and Switzerland. So once again, tomorrow we’ll begin with Indonesia, El Salvador, India, Japan, and Switzerland. And then we have 15 more speakers, and the speakers list will also be open for others who wish to intervene. And we will look at all the sections from sections A to section C, dealing until confidence-building measures. I wish you a pleasant evening, and the meeting is adjourned. Thank you.

Leave a Reply

Your email address will not be published. Required fields are marked *