Ambassador Gafoor
Distinguished Delegates, good afternoon to all of you, and a warm welcome to all the stakeholders represented here. I apologize for beginning this meeting 20 minutes later than scheduled. I was giving delegations and stakeholders the opportunity to come into the meeting, and I also took the opportunity to have some conversations with friends in the room. I now invite the Working Group to begin its dedicated stakeholder session, and this session will be divided into two segments. In the first segment, we will be examining best practices and lessons learned with regard to stakeholder involvement in capacity-building initiatives in the information and communication technologies security sphere. After hearing from stakeholders, there will be an opportunity for an interactive exchange with members of the Working Group, and we will also be looking at the draft annual progress report. I must say that as Chair, I am very happy that we can have this dedicated stakeholder session today. This session represents, in my view, a milestone for our process because this is the first time we have been able to convene such a session within this Open-Ended Working Group, a dedicated stakeholder session. This is possible because Member States have agreed on modalities for the participation of stakeholders in this Working Group. And all of you know that it took some time for us to discuss, negotiate, and agree on the modalities for stakeholder participation. We do have an agreement, and even if it is not the perfect or the most perfect of modalities, I think we have agreement on a set of modalities that I am confident will, over time, allow for the participation of more and more stakeholders in this process. For this session, we have 71 accredited stakeholders, including 54 non-ECOSOC stakeholders. I take this opportunity to formally welcome all stakeholders participating in the Open-Ended Working Group, and I thank you for your interest in contributing to our work. I know that many of the stakeholders present today have been sitting in the room since the beginning of the week, and I know as well that you have been carefully following our discussions. I have had the opportunity to meet several of you in the corridors and to have some quick conversations with some of you. I also know that stakeholders have been meeting actively with government delegations and, of course, also having conversations within the stakeholder community. So I am very pleased that this afternoon we will have a chance to hear directly from stakeholders in this Working Group. I have said many times before that as Chair of this process, I am deeply committed to engaging with the stakeholder community. I said so right at the beginning when I assumed the chairmanship of this Working Group in June last year. I think the convening of this dedicated stakeholder session sends a very strong signal that this Working Group as a whole is committed to engaging with the stakeholder community. I would also like to add that this dedicated stakeholder session builds on the informal dialogues that I have convened in my capacity as Chair. I convened informal sessions in December, March, and also last week here in New York. So the session today is in some ways complementary to the informal dialogue that I had convened last week and in earlier months. The informal dialogue is also a forum for stakeholders to share their views, not only with the Chair but also with each other and with Member States, because the informal dialogue sessions are also open to Member States. The point I am making is that there are multiple opportunities for the stakeholder community as well as delegations to interact and exchange views. I hope that through these interactions, we will get a better understanding, newer ideas, and hopefully, we can make some progress. Now for this session, I had disseminated some guiding questions around the two topics. I hope that those taking the floor will address the questions or the guiding questions. The first topic is focused around the issue of how stakeholders are supporting capacity building and whether there are best practices and lessons that can be shared in this regard. The second topic, as I said earlier, is with regard to the draft annual progress report. For those of you who have been following the discussion so far, you know that we have completed the first reading of the draft annual progress report. I’m on the verge of preparing a revised draft, which I hope to make available this evening. My intention is to listen also to the stakeholder community before I finalize the next revision of the draft annual progress report. Now, much as I would like to allocate as much time as possible, the reality is that we do have a tight schedule. So I do want to limit interventions to three minutes or less. I kindly seek the understanding of all stakeholders to not exceed three minutes. This is to be fair to other stakeholders but also to be fair to delegations, because I too had imposed a time limit on the intervention. So I think the idea of limiting the interventions to three minutes is not intended to in any way muzzle you, but on the contrary, to let a thousand flowers bloom to give as many of you a chance to make an intervention. So that is the spirit of the three-minute time limit, and I really seek your understanding in keeping to the time limit. The Secretariat has prepared a list of stakeholders who had expressed an interest to speak. I have before me the list prepared by the Secretariat. I will go through the list, and I do seek your patience if you are not speaking earlier than you would like, but I do assure you that we will get to you and you will have that opportunity to make your views known. So I’ll start now by giving the floor to Access Now. You have the floor, please, for three minutes. Thank you very much.
Access Now
Thank you, Ambassador Gafoor, Secretariat members, and OEWG delegates joining this discussion. Thank you for this opportunity to speak. As you know, Access Now is an international human rights organization that defends and extends the digital rights of users at risk. We provide direct technical assistance to human rights defenders and journalists through our helpline and engage in key discussions around cybersecurity policy and human rights. First, we see the OEWG itself as a key confidence-building measure. We’ve been glad to see its efforts to find consensus among states on urgent issues impacting human rights, development, and peace and security. However, we’re deeply concerned about the undermining of this way forward. This smoothie lacks key ingredients. Stakeholders from civil society, the corporate sector, and cybersecurity incident response were all prevented from joining our discussions and providing the critical inputs we need. Advancing improved global network security requires the OEWG to recognize the widespread networked nature of different actors who further cybersecurity. Civil society plays a critical role in supporting and growing capacity building. It is civil society researchers who detect the use of spyware and the scale of the global hack-for-hire sector, which proliferates the use of malware and software exploits globally. We document, and our colleagues suffer adverse impacts on human rights and dignity, including from disruptions to connectivity like internet shutdowns. Independent security researchers at the national level detect vulnerabilities in public and private sector systems, filing bug reports and raising public awareness on how to better improve cybersecurity across nations and networks. These reports secure elections and protect policymakers, among other beneficiaries. We engage and build capacity with these communities through many initiatives. Our civil society incident response network, or CIVISERT, Access Now’s global 24/7 digital security helpline, and RightsCon, our global conference summit series on human rights and technology, to name a few. And we welcome discussion with OEWG participants on how these platforms can support this ongoing work. We believe this body would be enriched by asking civil society cybersecurity networks how they seek to better spread digital hygiene, conduct digital security training, and respond to the digital security threats faced by the most vulnerable. As part of this, OEWG should also seek to collect and document what best practices exist at the national level for government and private sector stakeholders to engage with civil society, and on what threats and systemic challenges the civil society information security community faces. We recommend a focused pillar on protecting and encouraging the human beings who make cybersecurity possible, especially for our global civic sphere. Cyber threats to human rights defenders, journalists, and humanitarian actors must be referred to in the report of the OEWG. By doing this, the OEWG would also recognize the extraordinary growth in cybersecurity attacks and efforts to compromise human rights defenders, journalists, and humanitarian actors globally. This work must include a recognition of these attacks and add to the international consensus against allowing state and non-state actors to use cyber means to target humanitarian actors, journalists, and human rights defenders. Our international key on cybersecurity must further consolidate the recognition that international humanitarian law applies to cyberspace, and that international law does apply to cyber offensive activities. In this, we support the joint call by Switzerland on behalf of itself and 16 other states across the global north and south, strongly believing an explicit mention of international humanitarian law and the role of the ICRC must be added to the report. The OEWG must recognize that digital rights violations, including those taking the form of cyber attacks that enable and escalate offline violence, and the calculated attacks targeting digital systems essential to people’s safety, rights, and well-being, are simply unacceptable. Thank you, Chair. I will submit my remarks in writing.
Ambassador Gafoor
Thank you very much, Access Now. I’d also like to point out to speakers that the microphone will start flashing at the 2 minute 30 seconds point. So if your microphone is flashing, it is an indication that you have about 30 seconds to sum up. So that’s the signal that is being sent through the flashing microphone. And thank you for your cooperation once again. I give now the floor to the Association for Progressive Communications.
Association of Progressive Communications
Thank you, distinguished Chair, delegations, and colleagues. We welcome the opportunity to engage in this discussion. In our intervention, we will focus on some aspects of the draft report connected with capacity building and on the guiding question on ways in which civil society organizations such as APC are involved in supporting and delivering capacity building initiatives. Firstly, we welcome the inclusion of language in the draft report connected with narrowing the digital divide. Gaps in terms of access and digital skills should be seen as security concerns, since they are factors that create differential vulnerability to cyber attacks. Secondly, we support the recommendation of mainstreaming the capacity building principles adopted in 2021. In particular, we welcome the recommendation to continue addressing the gender dimensions of ICT security. It has been encouraging to see this week a growing number of states calling for a gender approach to international cybersecurity. We welcome the introduction of the important role of non-governmental stakeholders in capacity building. For example, civil society organizations such as APC play a key role in bringing human rights and gender perspectives to national cybersecurity strategies. APC is now conducting research on how to better incorporate the gender perspective in cybersecurity policies and will soon launch a framework to assist policymakers in doing that. Finally, we welcome the introduction of the APC capacity building initiative. APC is an international organization that has tailored trainings for women’s rights activists so they can use the Internet safely. APC’s feminist tech exchange seeks to be a feminist contribution to the global response to digital security capacity building and also plays a key role in convening stakeholders and designing training that responds to local context.
Ambassador Gafoor
Thank you very much, APC. I now give the floor to the Bangladesh NGOs Network for Radio and Communication. You have the floor, please.
Bangladesh NGOs Network for Radio and Communication
Mr. Chair, we are so grateful for giving us an opportunity to share our experiences and accreditation for joining the third session. We would like to thank you in your capacity as Chair of the OEWG for your commitment and dedication to international peace and security, international law, and human rights in the context of the negative impact of malicious cyber operations and misuse of ICT, and furthering the peaceful use of ICT. Bangladesh and the US network for radio and communication approach to media development and promotion and use of ICT and cyberspace are both knowledge-driven and context-sensitive in line with building confidence and security in the use of ICT, UNWSIS Action Line 5, WGE assessment and recommendations, and third, giving voices to the voiceless for meaningful access to rural communities in cyberspace security through community radio broadcasting. Mr. Chair, Bangladesh Internet Governance Forum has been organizing capacity building-related programs through the Bangladesh Internet Governance Conference, Bangladesh School of Internet Governance, Bangladesh Youth IGF, Bangladesh Women IGF, and Bangladesh Kids IGF. As a result, multistakeholder participation in the process has been oriented. The Bangladesh government has already reviewed its cybersecurity capacity in collaboration with the Global Cyber Security and Capacity Center and the Oxford Martin School at the University of Oxford in line with the CMM model. According to the report, the Bangladesh Cyber Security Strategy 2021 to 2025 has been formulated with four pillars. The four pillars are Digital Bangladesh, human resource development, IT industry promotions, and connectivity and infrastructure. Mr. Chair, Bangladesh Internet Governance Forum, in collaboration with Bangladesh NGOs network for radio and communication, has organized a cyber diplomacy training course for the youth and young women for furthering the peaceful use of ICTs. We are so grateful to the UN Office for Disarmament Affairs, the Government of Singapore, and the Government of Canada for developing the important and useful training course in an online manner. Apart from this, we have been promoting the report of the UN Secretary-General High-Level Panel on Digital Cooperation and Roadmap, the Secretary-General Report of Our Common Agenda 2021, and ongoing work of the Office of the Envoy of Technology in line with promoting trust and security in the digital environment and strengthening digital capacities and skills. Mr. Chair, Bangladesh Internet Governance Forum has created a parliamentary caucus on internet governance, digital economy, and media development in Bangladesh very recently. Through the caucus, we would like to promote security in the use of ICT among the parliamentarians in Bangladesh. In conclusion, Mr. Chair, we thank you and your team, especially Catherine Frisman, for tireless efforts in driving the OEWG forward, especially in this difficult time, and for producing a zero draft that continues to raise the profile of capacity building. We would like to thank the Government of Ireland for its generous financial contribution to stakeholders’ meaningful participation, including me, in the third session of the OEWG. We hope that our intervention is helpful, and we look forward to future cooperation on facilitating meaningful engagement, CSO participation, and strengthening coordination for the capacity building process. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much. I give the floor now to the Centre of Excellence in National Security, S. Rajaratnam School of International Studies, Nanyang Technological University of Singapore. You have the floor, please, three minutes.
Centre of Excelence for National Security (RSIS)
Chair, we thank the Chair for the opportunity to speak to the third substantive session of the Open-Ended Working Group, and we further thank the Chair for your efforts to include non-government stakeholders like us in the formal processes of the OEWG, as well as continuing the conversation in informal sessions where you have been able to include inputs from stakeholders who were not accredited for the formal sessions. We thank you for your guiding questions and wish to respond to the first set of questions on capacity building. Our contribution is based on what we have learned while conducting capacity building efforts in ASEAN and beyond. Our Centre of Excellence for National Security is an independent national security policy research think tank based in Singapore at the RSIS Graduate School. We’ve provided trainers for the UN Singapore Cyber Programme, Capacity Building Programme for ASEAN, as well as other partner initiatives for capacity building there, and including workshops for ASEAN delegates on, among other things, the meaning of the norms, developments of the norms implementation checklist, which we have expanded to other interested states. We also contributed content to the UN Cyber Diplomacy Online Course, which I’m very heartened to hear from our colleague, is being used and is available to all interested states and stakeholders. We share three observations from our experience. Number one, we observed that participants at our workshops have been very eager to engage the topic and to learn. While every state is at a different level of cyber maturity, over the years, many delegates who participated in the programmes have taken back what they learned to their respective states and returned in following years with reports of progress on a personal and institutional level. So we encourage all stakeholders who support capacity building to continue doing so. There is an impact. Number two, one best practice that we observe is that participants benefit from a multistakeholder approach with academia providing frameworks, industry providing technical expertise, civil society providing perspectives, and state participants frankly sharing experiences and challenges. This delivers value and holistic capacity is much better than a siloed approach because in a siloed approach, academic or policy frameworks alone may not be technically feasible, technical proposals alone may be blind to public and private interests. We therefore urge all stakeholders to work across domains when conducting capacity building. Combine academia, civil society, private sector, and public sector. Number three, we observed that participants share the Chair’s desire for sustained and substantive capacity building that’s inclusive and builds confidence. So we look forward to proposals to develop neutral and inclusive capacity buildings that avoid politicization and improve access. In conclusion, we observe a wide range of capacity building aspects that stakeholder groups can contribute to, and we encourage states to continue working with stakeholders, stakeholders to continue working with states, and stakeholders to continue working with other stakeholders on capacity building. This can carry on regardless of whether we are accredited to formal sessions or not. It is in the interest to find ways to cooperate even when it’s inconvenient to do so to deepen capacity building to ensure security and stability. Thank you.
Ambassador Gafoor
Thank you very much. I also wanted to add that all statements from stakeholders submitted to the Secretariat will be put on the website of the Open-Ended Working Group, so that all can have access to the statements. We’ll continue with the speakers list. Can I check if Cyber Justice Watch Institute is present? My understanding is that they are not, so we’ll go on to the next speaker, European Union Institute for Security Studies. You have the floor, please. Thank you.
EU institute for Security Studies
Thank you, Mr. Chair, for the opportunity to contribute to the discussion. Acknowledging that this discussion is already quite advanced regarding the draft and many concrete recommendations and comments were already made by national delegations, I would like to focus on two main points, one general and one substantive. Our substantive point is a recommendation that the Open-Ended Working Group starts working on the list of concrete cyber capacity goals to be achieved by the international community by 2030. Regarding the general point, we share the assessment of those delegations that expressed skepticism about the Secretariat’s operational capacities and the Open-Ended Working Group’s mandate to deliver on the recommendations in the section devoted to capacity building. The report on international cyber capacity building global trends and scenarios that the institution I represent has published last year clearly pointed out the need for all organizations in the cyber capacity building community to prepare for the continued growth of the field. Therefore, in our view, this is not the time for experimentation but rather the time to focus on delivery. As the field continues to grow, coordination will become even more important. Better coordination could be achieved by organizations improving their internal information sharing, supporting processes for international coordination such as the GFCE, and making better use of in-country coordination efforts in partnership with the host government. Now to my substantive point. Given the importance of cyber capacity building for the debate about the design and implementation of norms, confidence-building measures, international law, and societal resilience, we propose that the Open-Ended Working Group put forward a list of concrete cyber capacity building goals to be achieved by the international community by 2030. The starting point for such a list could be the list contained already in the 2015 GGE report and other elements identified by the cyber capacity building community, such as the adoption of national cyber security frameworks or establishing a CERT. Such goals could also help identify which parts of the UN system are best suited to support these objectives, including the role of lending institutions such as the World Bank and development agencies like UNDP. Such an approach would also help to reconcile differences in priorities and needs identified by states and their commitments at the international level. Therefore, we would like to make the following recommendation to be included in the report. States are invited on a voluntary basis to work together with relevant stakeholders, including regional organizations, businesses, non-governmental organizations, and academia, to propose a catalog of concrete cyber capacity goals to be achieved by the international community by 2030 with the aim to support states in meeting their commitments and exercising their rights resulting from the consecutive reports of the GGE or Open-Ended Working Group reports. I understand that this concrete recommendation may be difficult to integrate into this report. Therefore, I would like to request that this topic is addressed during the subsequent substantial sessions of the Open-Ended Working Group. And let me conclude by mentioning two concrete examples of cyber capacity building initiatives that might be relevant for the work of this group. We have recently launched what’s called the EU Cyber Diplomacy Fellowship addressing the needs in cyber diplomacy. For 10 spots, we have received over 500 applications, which suggest that there is a very clear need in the international community to meet that specific need. And finally, we have also hosted today an event on a multistakeholder community’s contribution to the fight against ransomware together with the governments of Costa Rica, Indonesia, Malta, and the European Union on the lessons from the engagement of the multistakeholder community in the fight against ransomware and the lessons for the implementation of the framework of responsible state behavior of states. We will be submitting the report from this meeting for attention. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much. I now give the floor to Fundación Karisma. You have the floor, please.
Fundación Karisma
Thank you, Mr. Chair, for your work during this session and the opportunity to participate in it. I am the Director of Fundación Carisma, a civil society Colombian organization that has worked and participated in debates on digital security for over six years. In addition to supporting the gender focus that has been brought forward in the document we’re discussing, we will present four points that we think civil society can contribute to moving forward in peace and global security. I will focus on the first two points. The first is national coordination for promoting, publishing, or expressing what its weak points are. This is a trust-building measure and requires national coordination for managing weak points that are frequently used and seen within state structures. This requires that we work actively on protecting those who do research in this area. Effective response mechanisms and mechanisms for supervision and monitoring are needed to ensure this is done in alignment with state defense measures. Civil society has expertise and experience to share. We will include in our text how the debate on the National Colombian Strategic Plan went from the Ministry of Defense to the Ministry of ICTs. We will provide experience and research on the cooperation measures of ICTs that we made to contribute to the creation of the National Coordinator for Vulnerabilities in Colombia, something that was recognized by the OECD as a best practice. Second, the debate this week on the inclusion or not of ransomware as a threat means that we have to reflect on how, in this particular case, the weapon that facilitates it is malware and sometimes spyware. This is the opportunist use of vulnerabilities by malicious actors, often backed by states. Seen in this light, this is obviously a digital security matter. These are offensive actions that should not just be seen as a national security issue but as something that directly affects people. Civil society has reported this as a kind of weapon that is used against vulnerable populations. We have seen them spread throughout armed conflict against journalists, environmental activists, and human rights activists. For that reason, we have to analyze it as part of our response. In our text, we will also talk about the importance of protecting encryption and fomenting cooperation processes amongst various stakeholders, especially civil society with the national bodies that are in charge of digital security. We support Switzerland’s initiative concerning international humanitarian law. Thank you very much.
Ambassador Gafoor
Thank you very much. I now give the floor to Global Partners Digital.
Global Partners Digital
Chair, Delegates, when we speak of cyber capacity building and the cyber capacity building landscape and how stakeholders are contributing, we must consider the wide range of capacity building initiatives and activities that are relevant. Although the GGE and OEWG reports don’t present an exhaustive list, they present areas of work that generally fall under five themes: cyber security policy, cyber incident management and critical infrastructure protection, cyber crime capacity, cyber security culture and skills, and cyber security standards. There are numerous examples of how stakeholders contribute to each of these areas, whether through the provision of training, the sharing of expertise, legal and otherwise, the sharing of knowledge and good practice, or the development of resources. But as I do not have much time, I wanted to share examples of how at Global Partners Digital (GPD), we have supported capacity building in relation to cyber security policy, including at the national level. Considering that national cyber security strategies or frameworks are a key instrument for the implementation of the agreed 11 norms, this is particularly relevant. We have worked directly with a range of stakeholders and governments to support inclusive cyber policy development, including by developing practical toolkits on inclusive cyber policy development and others for the assessment of cyber strategies from a human rights perspective. We have engaged in the process of developing the most recent and second edition of the ITU (International Telecommunication Union)’s Guide to Developing National Cyber Security Strategy, and we have worked closely with the Organization of American States (OAS) on a joint publication on national cyber security strategies, which features deep dive cases from the region. GPD is also a partner of the Global Forum on Cyber Expertise (GFCE) and works within the GFCE’s clearinghouse function, which provides a matching service where we have provided our expertise on the development of inclusive and rights-respecting national cyber policies. This month, we participated in the African School of Internet Governance (AFRICIG), which is also being referred to already, and which brought together a diverse group of individuals from governments, law enforcement and security agencies, civil society, digital rights and media groups, and cyber security experts from across the region to identify cyber capacity building priorities and needs, the role of non-state actors in addressing those needs, and concrete proposals for addressing them. Our output document will soon be available. This consultation shows how non-state actors play an important role in convening stakeholders, including governments, providing platforms for discussion, for dialogue, and collaboratively identifying priority actions for cyber capacity building. This is important because whatever aspect of cyber capacity building we are discussing, whether it’s policy, technical skills, diplomacy, or incident response, the strengthening of ties between people is at the heart of strong cyber capacity. We therefore recommend that in the report, the relevant recommendation, which refers to surveying capacity needs nationally, reference the need to engage all stakeholders in such efforts in order to ensure evidence-based, effective, sustainable capacity building initiatives and efforts. Thank you.
Ambassador Gafoor
Thank you, GPD. Thank you very much. Hitachi America, please, you have the floor for three minutes.
Hitachi America
Thank you, Mr. Chair, for this opportunity. First, Hitachi’s businesses are categorized in digital systems, digital services, green energy, and mobility-connected industry, connective automotive businesses. We adopt digital transformation and green transformation in critical infrastructure such as energy, train, water, banking, manufacturing, smart city, and so on. Digital twin towards metaverse is on the horizon. Our aim is to provide safe, secure, resilient products and services for customers and citizens on our planet. Second, working with IT, OT, IoT, as Singapore suggested, recent cyber threats are non-trivial. The risks, particularly in global supply chains, are very complex issues, by product, by product, and each layer and depth of the supply chain. Thus, we need to be more focused on the product-based CSIRT or P-CSIRT, coordinating for supply chain partners and customers. To serve our customers, one thing is still true, an old proverb says, “When in Rome, do as the Romans do,” to serve each of the customers on the planet. To secure the global supply chain, we recognize the great effort already made by states, industry, academia, and the trusted industry groups. Third, our thoughts on short-term, mid-term, and long-term goals. For the short-term, we need to know the facts immediately to coordinate with government and industry partners to address asymmetric vulnerabilities. For the mid-term, we need to strengthen digital trust mechanisms and technology for IT, OT, IoT, particularly with AI. Security and safety in design may be the way to go. Longer-term goals include alignment with the 17 Sustainable Development Goals, SDGs, particularly number nine, industry, innovation, and infrastructure. We committed to number 13, climate action, already. Shifting to a circular economy is the way to go. Finally, trainings and exercises are essential for capacity building, working with governments, other industry partners, and regions or subregions. In conclusion, trusted multistakeholder capacity building is essential for global peaceful ICT. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Hitachi America. ICT for Peace, you have the floor next for three minutes. Thank you.
ICT4Peace
Honorable Chair, Delegates, colleagues, and friends, thank you for the opportunity to speak here today. I’m representing ICT4Peace Foundation, a non-profit organization based in Geneva, Switzerland, which has been working at the intersection of peace, security, and technology in research and capacity building for almost 20 years. First of all, we express our gratitude for the organization of this dedicated stakeholder session and for providing an opportunity for non-state stakeholders to contribute to the discussions of the Open-Ended Working Group (OEWG). Considering the important expertise and areas of influence and control of the multistakeholder community, we consider it essential to achieve the OEWG’s mandate and objectives that all relevant stakeholders are able to contribute to these discussions. In response to the question about the various ways in which we are currently involved in supporting and delivering capacity building initiatives, for more than eight years, ICT for Peace has delivered numerous capacity building courses on various areas related to cyber security. Last year, we launched the ICT for Peace Academy, which offers live, custom-tailored courses on several topics related to cyber security, misinformation and hate speech, cyber diplomacy, application of international law to cyber, and cyber norms. And for those of you from OAS member states, we have developed, in cooperation with the OAS, a live five-day interactive course on cyber diplomacy, law, and norms, in which we take a deep dive into how international law applies to cyberspace. Through the mechanism of case studies, we analyze how international law would apply to cyber incidents according to the leading legal interpretations and through a comparative analysis of different state statements and positions. We also take a close look at the normative framework for responsible state behavior in cyberspace through the lens of how it would apply in realistic hypothetical situations and consider the different roles and contributions of non-state multistakeholder participation. We also look at areas such as cyber crime and other cross-cutting issues such as gender in ICTs. And this course is designed to prepare delegates to participate effectively in meetings such as this, or actually this meeting. We consider capacity building among states and other relevant stakeholders absolutely essential in order to more closely reach the goals of an open, peaceful, and secure cyberspace. Our live interactive courses bring together subject matter experts and practitioners from all relevant stakeholder communities and are specifically tailored to meet the needs of the participants. We take into account their particular national, regional, and institutional contexts as well. And the scenarios we use are realistic and inspired by real-life events and help to prepare representatives so that you are more able to effectively respond to cyber incidents when they do occur because they will. I will end here on this question and look forward to the next round. Thank you.
Ambassador Gafoor
Thank you very much, ICT4Peace. I give the floor now to Igarapé Institute.
Igarapé Institute
Dear Distinguished Chair, Delegates, and colleagues from other non-governmental entities, We thank the Chair and the Member States for the opportunity to be here. I’m speaking on behalf of the Guarape Institute. We are an independent think and do tank dedicated to the areas of public climate and digital security and its consequences for democracy. As an organization that is based in Brazil and works primarily with countries in Latin America and the global South, we see that stakeholders can play an even more important role in filling capacity and capacity building gaps and informing governments in their efforts to implement norms. I highlight three ways. First, stakeholders can help with incident mapping and reporting. From a developed and mostly developing country context, governments face and might face challenges in collating information about incidents, sometimes relying on outsourcing their security and not necessarily developing internal capacities. We believe that civil society organizations and joint efforts with other stakeholders can help map incidents, providing more situational awareness of national and regional contexts through open-source information. We recall, for example, our colleagues from the Cyber Peace Institute on their efforts to track incidents against the healthcare sector. We have also been conducting incident mapping on ransomware attacks and attacks against electoral infrastructure in Brazil in collaboration with other sectors to inform government entities and help develop preventive strategies based on that. This is particularly relevant to the implementation of Norm 13B of the GGE report that calls states to consider all relevant information in the case of an ICT incident, as it could, for example, support public attribution efforts. Second, stakeholders can help identify gaps in cross-government efforts through national mapping of cybersecurity governance. Governments sometimes might not be aware of their counterparts in different government agencies or the norms that each respective department has already developed internally. That is why we launched the first nationally dedicated cybersecurity portal in Latin America, in this case focused on Brazil. The Brazilian cybersecurity portal provides a map of governmental and non-governmental actors nationally and collates all their normative efforts, laws, decrees, white papers, and joint statements. We believe that portals democratize access to the cybersecurity debate for both governmental and non-governmental entities and, in our case, also complement the efforts of our colleagues at the international level, such as the UNIDIR Cyber Policy Portal and, at the regional level, the OAS Observatory. We believe that such efforts could inform the process of filling in the national surveys on norms implementation and capacity development, as well as the identification of points of contact beyond intra-governmental settings. Finally, stakeholders can help to promote inter-agency and multistakeholder best practices exchange. We have developed a multistakeholder agenda for digital security in Brazil based on meetings with stakeholders, which has resulted in the establishment of a multistakeholder platform for dialogue at the national level. We believe this is also in line with the implementation of Norm 13D of the GGE report on information exchange. Thank you, Chair, and we look forward to continuing the dialogue.
Ambassador Gafoor
Thank you very much. I now give the floor to Internet Identity Card for three minutes.
Internet Identity Card
Thank you. Thank you, Mr. Chair. Your Excellency, Mr. Ambassador Burhan Gafoor, Chair of the Open-Ended Working Group on Security of and in the Use of Information and Communication Technologies. Ladies and gentlemen, dear delegates, dear colleagues, and friends, I have the honour of addressing you in my capacity as CEO and founder of HTTPS Card Internet Identity Card Limited, established in the United Kingdom on August 8, 2014. Our goal from the start has been to self-fund our work in order to remain independent and not to be pressured by anyone. Being independent has a price, but from our point of view, the security of your identity and your data on the internet are priceless. We take a lot of pride in what we have been able to achieve since the inception of our organisation, and in the future, we would like to look back at ourselves and be proud of what we have achieved. Your Excellency, in the spirit of emerging technologies, supporting the UN Secretary-General’s strategy on new technologies and the sustainable development goals, and given the urgent cybersecurity threats and needs faced by states, I am both proud and honoured to make disruptive and concrete proposals today at the United Nations Headquarters in New York. These capacity-building proposals will radically renew our operation. First proposal. The governance and the future of the Internet Identity Card will be decided by its community, between governmental organisations and stakeholders, and under the UN framework. This is the world’s first Internet Identity Card that will adopt decentralised voting, and proposals and votes will be immutably recorded on the blockchain. This way, UN member states and stakeholders will decide the future of the Internet Identity Card platform. Second proposal. HTTPS Card Internet Identity Card Limited is willing to share without delay our knowledge and technology, such as decentralised and offline digital identity solutions, blockchain, non-fungible tokens, extended reality, Internet of Things, metaverse, and artificial intelligence, with UN member states and under the UN framework. Beyond the disruption of our business caused by the impacts of malicious cyber operations and the misuse of information and communication technologies, the war in Ukraine, and the pandemic, our shared suffering must inspire us with a firm and common determination to overcome these problems and to rebuild a better digital world. To this end, we must be aware of the opportunities that lie before us in order to seize them. We are all united. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much for the intervention. I now give the floor to the Kenya ICT Action Network. You have the floor, please, for three minutes.
Kenya ICT Action Network
Mr. Chair, the Kenya ICT Action Network, KICTANET, is a multistakeholder platform and think tank that is based in Nairobi. The network provides mechanisms and a framework for continuing cooperation and collaboration in ICT matters among stakeholders. It also encourages synergies for ICT policymaking activities and initiatives through advocacy, capacity building, research, and multistakeholder engagement. We would like to thank you, the Chair, and all member states for their work in advancing the mandate of OEWG and welcome the various proposals made on topics discussed during this third session. In particular, we welcome the measures directed at addressing specific capacity building needs of developing countries, tackling the gender digital divide, promoting confidence building measures, and recognizing the roles of regional and sub-regional institutions. In response to questions provided by you, the Chair, we respond as follows. Question one, KICTANET has and continues to conduct research on existing and potential cybersecurity threats and risks, policy and legislative development, the impact of emerging technologies, and makes proposals for reform of policy, legislative, and institutional mechanisms. It creates awareness on cyber hygiene, digital security, and provides digital resilient support to civil society organizations. We also promote multistakeholder engagement at local and regional levels and, for example, KICTANET convenes the regular topical thought leadership forums and the Kenya Internet Governance Forum, which this year was held in June and attended by over 500 people. We also advocate for greater cooperation and information sharing among stakeholders and for the implementation of human-centric approaches to cybersecurity. We also have developed curricula on cybersecurity and cyber hygiene, targeting the digitally marginalized and excluded populations and vulnerable groups such as children, women, farmers, persons living with disabilities, and youth from informal settlements. KICTANET also hosts the Kenya School of Internet Governance Forum, which has so far trained over 500 students since 2016 on internet governance. We also contribute to the development of a cybersecurity curriculum by the GFCE. On number two, we think that civil society can contribute by conducting capacity building in the use of ICT such as offering digital safety and security training and cyber hygiene awareness programs for the public, conducting evidence-based research on emerging cybersecurity issues of concern, promoting awareness at national, regional, and international levels of cybersecurity and societal security, including the development of knowledge products and tools to promote digital security. On number three, we believe that contributing technical and knowledge resources, including by providing specialized expertise in the development of cyber policies, legislation, and strategies, as well as hosting focused discussions and participating in regular dialogue to enhance coordination and to exchange information, knowledge, and best practices. What has not worked well are cyber processes that are not open, inclusive, and multistakeholder in nature, whether at national, regional, and international levels. While stakeholders such as civil society organizations from the global south do not have significant financial resources, they remain ready and willing to meaningfully engage and effectively participate in key processes and implement targeted programs. Finally, Mr. Chair, we call for financial support to global south civil society organizations to enable them to effectively contribute to the OEWG and deliver useful outcomes in their regions. Thank you.
Ambassador Gafoor
Thank you very much. I give the floor now to Derecho Digital for three minutes, please.
Derechos Digitales
Thank you very much, Mr. Chairman, ladies and gentlemen. Derechos Digitales, Latin America, thanks you for this opportunity to participate in this meeting of the Open-Ended Working Group. On the first group of questions on capacity building, based on our experience as a civil society organization, I can say that we’re actively working on research and information exchange on cyber threats as well as training programs on cybersecurity. We consider collaboration to be an essential element for the promotion of training that would consider the impact of security risks in cyberspace on vulnerable groups. Amongst other groups and other efforts for cybersecurity, we need to extend these protections to those who are often targeted by malware and spyware. This extends to training for audits amongst activist groups, including a gender-focused training for police in Chile. The management and creation of a trust-building network would be useful in Latin America in order to move towards the creation of an observatory for digital threats. Contributions to national policy in the area of cybersecurity in Chile facilitate the integration of human rights considerations as a main part of our multi-sector dialogue. Also, research on the impact of contributions by stakeholders on such national policy. These efforts have in common collaboration and continuous support for capacity building and are added to our participation at various levels of multi-sectoral discussion mentioned in other interventions. We consider all these to be crucial factors both for the formulation and the implementation of cyberspace guidelines focused on individuals and their fundamental rights. We hope to continue contributing to this process. Thank you very much.
Ambassador Gafoor
Thank you very much. I give the floor now to the Paris Peace Forum.
Paris Peace Forum
Thank you, Mr. Chairman, Honorable Delegates. The Paris Peace Forum has been working closely with stakeholders across the ICT value chain and beyond the industry to foster better norms and efficient capacity-building measures to secure a stable cyberspace in the framework of the Paris Call for Trust and Security in Cyberspace. Since 2018, the Paris Call for Trust and Security in Cyberspace has gathered a coalition of 1,200 actors, including 80 governments, 700 companies, and 350 civil society organizations around nine core principles to protect and promote a free, open, secure, and stable cyberspace. As suggested by the Chair, we are happy to address the OEWG on best practices and lessons learned with regard to stakeholders’ involvement in capacity-building initiatives in the ICT security sphere, and more specifically on efficient stakeholders’ involvement in capacity-building initiatives. On this important matter and building on our experience, we would like to draw your attention to two general recommendations. First of all, attention should be given to the clarity of the goals and the limits. Normal stakeholder cooperation, especially related to capacity-building issues, cannot last without a precise definition from the outset of the scope of the cooperation and its intended outputs. This further entails the need to start the cooperation by lifting any possible uncertainty on the limits of each stakeholder’s responsibility, especially when it comes to the distribution of state and corporate responsibility when applicable. This recommendation echoes comments made by several delegations on the importance of sticking to the mandate of the OEWG in New York this week. Such a guideline, which is key to the success of diplomatic negotiations, is also key to the success of any stakeholder involvement in capacity-building initiatives. Second, attention should be given to the persistence of the engagement with stakeholders. By persistence, I mean that stakeholders need to be involved at all steps of the cooperation in a regular and continuous manner from the conception to the implementation phase. Without such a comprehensive view and understanding of the larger process, stakeholders cannot efficiently mobilize their resources and expertise, thus diminishing their capacity to deliver to the best of their ability. This recommendation doesn’t necessarily mean that stakeholders should be involved in every single discussion or step. Some capacity-building issues closely related to international security matters can especially entail matters or steps involving sovereign competence, thus requiring a strictly intergovernmental format. In such cases, persistence means that states should maintain a channel of communication with the larger ecosystem and endeavor to provide them with sufficient information to efficiently support it. We are happy to elaborate on this recommendation with concrete examples of successful stakeholders involved in the ICT-related issue at the request of an interested delegation and especially the example of the Crescent School. Thank you for your attention.
Ambassador Gafoor
Thank you very much. I give the floor now to the Write Pilot.
Write Pilot
Thank you. As a founding partner and board member of Women’s Cybersecurity Middle East Group, presenting under the umbrella of RightPilot, I would like to thank you, Chair, for this valuable opportunity to learn and hear our voice. I hope you find our successful initiatives insightful to learn from, as much as we have learned from your stellar leadership and members of states’ insights and discussions in the past couple of days. Now, in addressing the guided question number one, I would like to state the following. The Women’s Cybersecurity Middle East Group, also short for WiCSME, was formed in 2018 to promote increased women’s participation in cybersecurity. It is a voluntary group with a vision to build a strong, dependable, and growing network of passionate female cybersecurity professionals in the Middle East and North African countries, and eventually increase the percentage of women in the workforce in the field of cybersecurity, and encourage more female leadership in cybersecurity in the region. During these five years, WiCSME has built a strong foundation fully in line with our regional culture, religious, and societal values, and as a result, has grown from nine members to over 1,800 members from 23 countries. We have experienced historical moments where we introduced many initiatives to successfully create a platform for our sisters in the region that is fueled by respect, openness to ideas, constructive feedback, and a strive toward excellence. In this matter, I would like to bring special attention to the key capacity-building initiatives and achievements by WiCSME, all of which were firsts in our Middle East region. We are proud to say that we now have a platform in which women’s cybersecurity, our young rising stars, and experienced professionals have an equal chance to share their knowledge, have their voices heard, and their individual strengths appreciated. We also created opportunities for our women to participate alongside their male peers and build their technical, soft, and collaborative skills as part of our WiCSME Regional Capture the Flag competition. In 2020, 36% of the 600 participants were females. In 2021, we had 63% of female participants. This is a double-digit year-on-year growth, which speaks to the impact we are making while recognizing and managing the changes that we are often faced with in a regional setup. We also introduced a formal way of recognizing, appreciating, and showcasing the unique capabilities and contributions of women in cybersecurity through an annual WiCSME Awards, be it in their capacities as leaders in the field, rising stars, or contributions toward their communities. We do not only celebrate our women but also our male allies whose support is fundamental in steering this movement forward. We have felt a tremendous increase in confidence levels for our members who are now taking on bigger and better challenges in their personal and professional lives. They are now transforming from being followers to leaders, from sitting in the passenger seat to taking the wheel in the driver’s seat. In doing so, they do not only think about themselves but also contribute back as givers to the community in their unique and talented ways and capacities. They now have a network and safety net of like-minded women to feel confident and lean on when facing problems and dilemmas. Looking at this congregation here, I feel that we are very much similar to the UN in terms of capacity and efforts. We are bringing together our WiCSME affiliate countries toward a common goal. Needless to say, we could not achieve all of this without the support from our partners of success. I would like to pay special thanks to the Kuwait Foundation for the Advancement of Science and the UK Gulf Women in Cyber Fellowship who have been with us on this journey since the beginning. While we have achieved so much in voluntary capacity and contributions from our passionate members, we recognize that now we need to build a more formalized structural framework focused on creating a more sustainable organization, which will carry forward the torch of this movement, build the foundation, and breathe life into the organization to flourish and create more historical moments for generations to come. This will require more collaborative efforts and support from various corners of society, including but not limited to private and public organizations, governments, academia, and community programs. It is a moment of pride to be able to state on this global forum and stage that WiCSME has successfully created an avenue for women in cybersecurity in the Middle East that is nurtured by our values and culture, and keen to showcase, foster, and celebrate their talents in and beyond the world of cybersecurity. We are creating leaders who believe in being stronger together and givers who actively contribute to our societies and the global system of cybersecurity. To conclude, we hope that there will be a day where we have a United Nations of Women in Cybersecurity that unites these tremendous efforts of various women cybersecurity groups around the globe to collectively support us in achieving the mission and making a difference for generations over the world. This might sound like a big dream, and perhaps, Mr. Chair, a bit complicated, ingredients for the smoothie metaphor you have referenced. But we believe that with such big dreams, we need to be committed in order to start and consistent in order to finish. Today, we are here. That’s a start. And together, by putting collectively our three H’s in action—our hearts, our heads, and our hands—we will hopefully be able to achieve our goals and finish as we are and will always be stronger together. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Write Pilot. I now give the floor to Youth for Privacy for three minutes.
Youth for Privacy
Thank you, Distinguished Chair. My name is Zidama Izobidum-Chow, Representative for Youth for Privacy. I am a millennial born in the same year the World Wide Web launched into the public domain. Since then, ICTs, including contemporary AI, have grown increasingly embedded in our daily lives, whether we know or consent to its applications. Youth for Privacy is a global group that makes the often-invisible value of privacy visceral within the next generation of privacy-minded youth. Learning from our work in youth advocacy and consensus building, we recommend Member States secure ICT for youth, highlighting three practices. First, amplify youth voices within the cybersphere. We’ve seen how operating in silos creates gaps and redundancy. Shrink the multi-generational divide by supporting our efforts and trust us to speak to our own insights. Commit to a dedicated youth-led session with accessible means of participation in the next substantive working group. Consistent engagement beyond ad hoc events is necessary to sustain meaningful contribution. Secondly, build within an intersectional framework by centering the youth beyond cyberspaces. While Youth for Privacy is primarily made up of people who grew up with relatively easy access to ICTs, we know that this is not the case for 63 percent of young people globally. Understand specific matters concerning young populations who, one, have limited safeguards against public ICTs and, two, do not directly use ICTs but are impacted. Multiply marginalized youth are also often disafforded physical and psychological safeties of privacy autonomy. Trans-disabled black and brown youth especially are more likely to encounter cyberbullying and search for physical and mental health support online compared to their counterparts. Co-create youth education programs on secure internet use to encourage a broad range of youth participants at the systematic level. Education in all technical and non-technical fields must promote privacy education, including awareness of information flows and purpose of data collection across all sectors. Produce these learning materials with standards like that of KnowBe4 and Cyber Collective. Goals should be objective-oriented with associated metrics. Finally, bolster privacy to reduce harm. Endorse negotiations for a comprehensive cybercrime treaty that demands the inclusion of human rights standards to guarantee full protections for youth. Redefine existing goals in your domain to realize the 2030 Agenda for Sustainable Development and other models. This includes technical decision-makers prioritizing student safety over short-term incentives in the long-term adoption of e-learning technologies that have accelerated in the COVID-19 pandemic. Thank you, and we look forward to continued conversations in the next substantive session.
Ambassador Gafoor
Thank you very much, Youth for Privacy, for your statement. We’ve concluded the list of speakers who had wanted to address the first topic with regard to best practices and lessons learned with regard to stakeholder involvement in capacity building initiatives. I’d like to give about 15 minutes to hear any reactions from delegations to the comments heard, and if delegations are taking the floor, I would discourage the reading of prepared statements. I want this to be interactive, so I would like to give each one of you who wish to speak about 60 seconds, one minute, to either raise a point or raise a question, so that we can get to the essential points in a very quick manner. So the floor is now open for any delegations wishing to comment or make any specific point. Brazil, you have the floor, please.
Brazil
Thank you, Chair. We would like to thank all organizations that took the floor today and others that maybe were not able to be here, but we will, of course, submit their contributions. Brazil believes that this kind of participation is really helpful also for member states, and it should be an interaction in which we are able to give you feedback and not only take note. Of course, international security is a matter in which the centrality of the state is very prominent, so not necessarily the model of participation will be the same as in internet governance, for instance. But this doesn’t mean that it’s only a matter for the state to discuss. So we would like to thank in particular the participation of entities from the Global South and in Latin America, my region, and also the participation of Instituto Igarapé. We don’t say Igarapé, we say Igarapé, but I don’t expect you to know Portuguese. But this is really helpful because it shows also the vibrant civil society that we have in Brazil, and we hope that in the next meeting we count also with the presence of our internet steering committee, which is a multistakeholder entity itself, and I’m sure we’ll have other contributions to make. One point, finally, I think the problems and challenges of cyber security for non-government organizations, particularly human rights defenders, the youth, and journalists, while not necessarily reaching every time the threshold of international security, are related to the kind of capacities we need to build at the national level that will benefit not only state resilience but also the resilience of society as a whole. So the things are connected, and we appreciate following up on that in future meetings. Thank you.
Ambassador Gafoor
Thank you very much, Brazil. South Africa, please.
South Africa
I would like to thank the Chairperson for including this interactive session with stakeholders in the program of work. We just have one question. We would like to ask stakeholders if there were models that they found useful for engagement with all national-level stakeholders. Thank you.
Ambassador Gafoor
South Africa, could you repeat the question so that we are all clear?
South Africa
We would like to ask stakeholders if there were models that they found useful for engagement with all national-level stakeholders.
Ambassador Gafoor
Thank you. We’ll come back to the stakeholders at a later point. I’ll give the floor now to the Czech Republic.
Czechia
Thank you, Mr. Chair. I’m not able, of course, in 60 seconds to respond to all points which were raised here, but I would like to assure everybody that I noted very well all that was said here, and we would like to work with it. I would like to welcome and really appreciate that we have this meeting. It’s very important for us. Of course, I regret that there are not all NGOs, but in principle, I really welcome this discussion, and I’m looking forward to other interactions we have together. Thank you.
Ambassador Gafoor
Thank you very much, Czech Republic. Argentina, please.
Argentina
Thank you, Chair. Gracias. Thank you so much, Chair. I get a little bit confused sometimes. I hear so much English, I end up speaking in English. Argentina welcomes the contributions made by the organizations during this session, especially given the importance that they have brought to capacity building. I want to say that Argentina has developed over the last 15 years approximately a great number of capacity building activities within the area of ICTs. Some were initiated by the government, others by academia or civil society, but they were always multi-participatory, multistakeholder events. So we invite all the organizations that are here with us today to work in tandem with our government and, well, on our activities so that they might be further strengthened for our communities. And we hope to count on the participation of all organizations in future sessions. Thank you.
Ambassador Gafoor
Thank you very much, Argentina. Canada, please.
Canada
Thank you, Chair, and thank you to all the stakeholders who came here today and, you know, traveled to New York, took the time to make statements. You know, to me, an event like this really shows the value of what we achieved with the modalities. I do regret, though, of course, that not all were accredited, because I would note that there are other organizations who could have shared views, such as Cyber Peace Institute, Microsoft, Chatham House, and others who unfortunately were not invited. But nonetheless, you know, I’ve learned in six years at the UN that you put water in your wine and you take small victories, and this is one. Listening to this really inspired me. You know, on a very concrete level, Canada probably will update and retable our norms guidance text from the previous OEWG. And if we do, we will definitely do what we did last time, which is to seek the views of stakeholders in addition to the views of states. I heard, for example, I think it was Igor Ape who mentioned, you know, the role of stakeholders in implementing the norms. I think that absolutely has to be part of any guidance and also the follow-up work to implement. I heard others mention the human-centric approach. That is something that we would look to incorporate. And, you know, I’m not an expert on those things. I’m a cyber guy. And, you know, that is exactly the kind of feedback that we’d be wanting to get. So I just wanted to echo my Czech, Argentinian, and other colleagues who expressed their, you know, just like me, that we really heard excellent ideas and that we, Canada, again, plan to incorporate views of stakeholders in any of our major text proposals. And we would encourage others to do the same. Thank you.
Ambassador Gafoor
Thank you very much, Canada. I hope we don’t have too much water in our wines. I give the floor now to Colombia, please.
Colombia
Thank you very much, Mr. Chair. My delegation also welcomes that we might have held this meeting with the participation of various stakeholders. The comments that we have had thus far, all the contributions made, as well as the information delivered on experiences that they’ve had in conjunction with the various institutions and states, show how important their participation is, not only in these discussions but also when it comes to the implementation of responsible behavior by states. The strategies that we might adopt in order to face and overcome challenges before us, and absolutely, strengthening national capacity.
Ambassador Gafoor
Thank you very much, Colombia. U.K., please.
United Kingdom
Thank you, Chair. The UK relies on an active stakeholder community to deliver across our portfolio, from policy to technical capability. We don’t have the capacity or expertise to deliver everything ourselves, and moreover, we can’t match the passion, eloquence, and committed delivery of our stakeholder colleagues, such as Dr. Reem of Wright Pilot. We really welcome the diversity of representation here today, particularly from the Global South, and we’d like to reassure EU-ISS and the ICC that their suggestion of cyber capacity goals is well noted. We’re considering how we might work with them to take some of this forward, as we think that’s a very sensible proposal, and we’ll come back in due course on that. Thank you, Chair.
Ambassador Gafoor
Thank you very much, UK. El Salvador, please.
El Salvador
Thank you very much, Mr. Chair. El Salvador would like to express its gratitude also for the participation by various stakeholders in this process. We applaud your inclusion and have said before how we can benefit from the experience of other actors. In particular, we have benefited from the Cyber Diplomacy Program by ICTs for Peace Foundation. We can talk about how these experiences benefit us when we are able to participate in events like this Working Group. Thank you.
Ambassador Gafoor
Thank you, El Salvador. Australia, please.
Australia
Thank you so much, Chair. I want to say thank you for organizing this part of the formal session, and also thank you for the contributions of our stakeholder community today, last week, and also in writing. I’d like to refer to the cybersecurity threat reports. I know several of our stakeholders here and also other stakeholders and industry entities and national cybersecurity agencies produced a lot of reports and papers. Some of these have been submitted to the OEWG. I find them incredibly valuable in the way that Australia looks at our positions, and I would encourage other countries also to engage with these products, these written products, and I would encourage the stakeholders here and also those perhaps watching at home, online, to share these with the OEWG Secretariat so that they are all in one place for us. And I just also wanted to say I very much appreciate the words of the ICT for Peace, who called us all friends. I see a lot of friends on this part of the room, but also sitting up in the stakeholder area over in civil society, and that’s very warmly welcomed. Thank you.
Ambassador Gafoor
Thank you very much, Australia, for your comments. South Africa had a question about what the stakeholder community or representatives thought about whether there was a model that was applicable across countries. Are there any stakeholder representatives who immediately want to jump in and respond to that? Can you press the button or raise your hands? We may not be able to see you from here. Well, Global Partners did show. Would you like to take the floor?
Global Partners Digital
South Africa, thank you for the question and the engagement. I hope that my response will not be disappointing in the sense that I will say there are no specific models we would recommend or be able to point to, although, as I mentioned, we have developed toolkits in collaboration with other stakeholders on how to conduct inclusive policy development, cyber policy development processes. But what I can say, and what I hope is practical, is that there are some underpinning principles which shape better and good engagement processes, and those are openness, inclusivity, and transparency. There’s no one way or one-size-fits-all way of implementing those principles, so it will depend on the context. But what’s really important is that there is clarity on the way to engage, that there is transparency from the beginning, and, for example, that could mean that engagement and inputs from stakeholders are clearly reflected, or if they are not reflected or integrated into a process or into a final output, it is explained why that is the case. It’s also really important to keep in mind the specific needs of vulnerable groups. So, for example, while an open call for input into a cyber security strategy might be useful to engage some groups, it might not be accessible for others, and so that should be considered from the beginning. And then another point, I think we often hear good examples of engagement, is of developing a sustainable framework so that engagement with stakeholders does not depend on individuals in a government or in a department but rather lasts beyond the particular engagement of a group of people. So these engagement spaces could be anything from forums or advisory groups, and as I said, that will depend on the context. I think some examples have already been referred to in the statements that were provided earlier, but they should be fair and democratic and open and inclusive for all interested stakeholders to engage in. I hope that was helpful and also interested to hear from others. Thanks.
Ambassador Gafoor
Thank you very much, that was very helpful indeed. I think there is Igarapé Institute, did I pronounce it correctly?
Igarapé Institute
Yes, Chair, and I thank the representative of Brazil for calling me out on that. Yes, thank you very much for the question, the delegate from South Africa. I would definitely say that when it comes to thinking about models, especially coming from a developing country, I think models are important, but potentially the most important element is to have a model that’s flexible, that can actually adapt to the realities of developing countries. And of course, this means this could go from more practical elements such as tabletop exercises to trainings, of course, but up until national strategy development, as my colleague from GPD just mentioned. And I think in our case, I think this is also a two-way street, right? On the side of civil society organizations and non-governmental stakeholders, I think there is a possibility for our group to activate these kinds of conversations with different government ministries whenever possible. And also on the other side, for governments to reach out to these different stakeholder groups so that we can find a model that’s also inclusive from both ways. So two-way streets in that sense. And finally, I would also note that from our experience in developing the report, which is an agenda for digital security, we actually started the process and we called to the table different stakeholders. And that was a really good experience in just trying to develop methodologies that come bottom-up, but that also meet the requirements and the interests also of government priorities that are set in our national cybersecurity strategy. So I’d say my key takeaway is the two-way streets and thinking the model, and also from a developing country perspective to always think about how to better adapt. I think that’s the best model.
Ambassador Gafoor
Thank you. That’s also very, very helpful for our work here. RCT for Peace, you wanted to also come in, I think. Please.
ICT4Peace
Okay, thank you very much. I just wanted to come in. I was actually going to talk about this in my second intervention, but I thank both South Africa for the question and also for the opportunity to respond. In terms of models, one area that we have worked very much in is the model of multistakeholder governance. This is based on a theory that, as in international law and international relations, is based on the notion of effective control over a given territory or sphere of influence. In cyber, there are different actors that have different areas of effective control over cyberspace. So you have technical actors and developers who are more competent in dealing with the actual technical aspects and the development of it. You have governments that have their regulatory authorities. You have civil society and different users that can bring the experience of the users on the ground. You have academics and other experts that are working on different theoretical and other aspects that are important toward this. If we are all going to work towards a more safe, peaceful, and secure cyberspace, we have to figure out which of those roles we have as each different kind of stakeholder, whether we are states, technical experts, companies that own large segments or important parts of the internet, or civil society that can actually bring the experiences and work together. We need to craft models based on our independent areas of effective control and expertise so that we can all work towards an effective, peaceful, and secure cyberspace. Thank you very much.
Ambassador Gafoor
Thank you very much, ICT4Peace. I know this is a very interesting discussion, but I’ll give the floor to two more stakeholders before we move on to the next topic. So Access Now, you have the floor, please. Thank you.
Access Now
Indeed, a plus one to what my colleagues in civil society have said. I think we won’t probably hear as much from the companies in this open forum as we would like, but my sense is that they do work closely with governments and a lot of information-sharing initiatives. And that is definitely a two-way street that does have wider benefits for civil society and institutions when governments and companies are able to share threat information. And one clear way for governments to, I would say, do their part is through vulnerabilities equities processes, where they disclose zero days and other emerging threats to those private sector actors who can patch quickly and efficiently in order to prevent larger-scale incidents. And for our part, Access Now, we did join first the Global Forum of Incident Response and Security Teams, which is largely made up of governments and companies. I believe we were the first civil society to join. And so we are trying to open doors to where this sharing of information is actually taking place already. We also host the RightsCon event, which is open to governments and companies as well as civil society. And these topics are discussed likewise at the Internet Governance Forum. Beyond these, there are coalitions like the Freedom Online Coalition of States that are pretty open to multistakeholder governance and policymaking. And we, of course, encourage more states to join that and similar coalitions. I think, above all, we in civil society are often the first to experience new and emerging threats in the cyber security realm. And we are looking to, through CivIssert, build our knowledge base in order to more efficiently and coherently share that. And we do hope that those doors are open when we come. Thanks.
Ambassador Gafoor
Thank you very much. That was also very helpful. The last speaker under this topic from the stakeholder community, Fundación Karisma, please.
Fundación Karisma
Thank you very much. I just wanted to share with you an experience that is probably a bit different from the others, and this is the case. Before a very paternalistic national strategy plan in Colombia, we decided to start an advocacy project that was to show the importance of researchers in this field. We started some tests on very intensive personal data sites in the government that were looking for vulnerabilities. We, of course, found them because digital security is never 100% good. By doing that, we initiated a process with the Ministry of ICT to create a de facto coordination vulnerability response. This has been going on for a few years and has been very useful to create the idea of co-responsibility, or to elaborate on the principle of co-responsibility and trust building. The idea is to make the government understand, or the state, that this is possible and that they need to open it. We are in the process, but it has been a very challenging and yet very important process, I believe, with a different model which is advocacy-oriented. Thank you very much.
Ambassador Gafoor
Thank you, very helpful as well. I understand Saudi Arabia has asked to speak, so we’ll go back to delegations for the last comment from Saudi Arabia before we move on to the next topic.
Saudi Arabia
Thank you, Mr. Chair. Thank you for organizing this formal session. Thank you to all the stakeholders for their enriching contributions. It is a pleasure and an honor to be here with you in the context of the Open-Ended Working Group to discuss this vitally important issue of stakeholder involvement in capacity-building initiatives in the ICT security sphere. Saudi Arabia strongly believes that the contributions of stakeholder groups are of critical importance, and in some cases, this is of value to capacity-building. Our experience in Saudi Arabia has yielded important lessons for us regarding the forms of stakeholder cooperation that are most effective. We believe that a key element of our success has been the development of coordinated frameworks that engage key players in long-term partnerships, and that is through our cybersecurity development strategy. Recognizing stakeholders as essential partners in and enablers of our cyber capacity development, the Kingdom has developed long-term strategic frameworks and platforms for coordinating with ecosystem players on cyber policy areas, including cybersecurity compliance, risk management, and national skill development. This has helped us maximize the value of engagement with stakeholders in our capacity-building efforts. In particular, this systematic approach has helped us to co-develop capacity-building solutions with the private sector. Through industry partnerships, we have co-created innovative cybersecurity toolkits and compliance assessment tools. Saudi Arabia has taken a strategic and deliberate approach to partnering with actors across our ecosystem, including through working with the academic community on the development of our cybersecurity workforce framework and establishing R&D partnerships across the ecosystem along several tracks, including on secure cloud computing technologies, cybersecurity forensics, vulnerability analysis research, and more. The Kingdom’s efforts at the international level also reflect our fundamental belief in the power of multistakeholder partnerships. For example, the Kingdom has established the Global Cyber Security Framework, GCF, not only to convene government cybersecurity leaders but also specifically to bring together the global technical, academic, and private sector communities to advance cybersecurity collaboratively. There are many diverse opportunities for stakeholders to deliver meaningful contributions to capacity-building. One area in which we have seen stakeholders’ involvement be of particularly critical value is in the development and delivery of cyber skills trainings. Our work with academic and private sector partners through the higher education framework and National Cybersecurity Academy has enabled us to develop trainings that evolve at pace with the latest technical developments. In closing, the Kingdom of Saudi Arabia believes that increased coordination and strategic engagement with diverse stakeholders across the international cybersecurity ecosystem is a critical enabler of success in delivering meaningful and sustainable capacity-building outcomes, which in turn is essential to our collective efforts to create a more open, secure, stable, and accessible ICT environment for all. Thank you.
Ambassador Gafoor
Thank you, Saudi Arabia. I think the first segment of this stakeholder session discussion was very useful indeed, and I thank both the stakeholders and delegations which had taken the floor. We’ll go now to the second segment of the session where we had made available guiding questions to look at how stakeholders can work with states to contribute to the implementation of the various concrete proposals made by states at both the first and second substantive sessions and as captured in the draft annual progress report that all of you have seen. So this is in some ways related to the earlier discussion, but it’s slightly an additional discussion, if you like, because we are focusing specifically on the draft annual progress report that looks at the various issues in the report, the specific proposals, and I know some of the stakeholders had already addressed their comments in this regard at the earlier segment. But I’d like to invite now the stakeholders once again to be strictly speaking within three minutes, please, so that we can wrap up in time. So I give the floor now to the European Union Institute for Security Studies. Please, you have the floor.
EU institute for Security Studies
Mr. Chair, it’s a bit difficult to comment on work in progress. We don’t know which of the recommendations will make it through the revision, so I’ll just focus on two main points, one editorial and one substantive. My substantive point will be again a recommendation to include a reference to informal diplomacy under the section devoted to confidence-building measures, and I will come back to this point in a minute. Regarding the editorial comment, there are several references in the text to interested stakeholders. To paraphrase our colleague from Australia, there is no requirement for states to be interested, so we believe that there should be no reference to interested stakeholders either. We would therefore suggest either replacing interested with relevant, but given the discussions of the UN about who defines who is relevant, we simply maybe suggest leaving any notion in front of stakeholders and keeping the term simple. We believe that in line with the whole-of-society approach, states have an active duty to seek out relevant stakeholders and engage them. Moving to the substantive comment, we very much welcome the mention of expertise and calls on several occasions for the involvement of experts on various topics to contribute to the discussion. Evidence-based policymaking grounded in research is an important mechanism to moderate the risk of breakdown of diplomacy, on the one hand, and a mechanism to prevent a stalemate in a highly polarized political environment, on the other hand. Therefore, we regret that many excellent research institutes and non-governmental organizations with whom the UISS has worked for years have seen their requests for accreditation rejected and hence will not be able to contribute. Since our discussion concerns questions of international security, I would like to submit for your consideration, Mr. Chair and dear delegates, the inclusion in the progress report of references to the role of informal diplomacy, often referred to as Track 1.5 and Track 2 dialogues, involving governments and other groups of stakeholders. For instance, the Council for Security Cooperation in the Asia-Pacific, CSCAP, provides an informal mechanism for scholars, officials, and others in their private capacities to discuss political and security issues and challenges facing the region, including for the CSCAP study group on international law and cyberspace. The UISS, together with the Geneva Centre for Security Policy, Xiamen University, and China Institute of Contemporary International Relations, has been involved in the Sino-European Expert Working Group on International Law and Cyberspace, supported by the EU, Switzerland, the Netherlands, and China, which helped to improve our understanding of respective positions. Such meetings provided both policymakers and the research community with an opportunity to quietly engage, raise awareness, and clarify views on issues related to cyberspace, ICTs, and international security with counterparts in other states. Moreover, such engagements reflect the political will on the part of national leaders and research communities to reduce the risks of misunderstanding and potential conflict escalation. In this light, we suggest including in the section devoted to confidence-building measures the following recommendation, and I quote: “States on a voluntary basis are encouraged to promote and support informal diplomacy channels involving relevant stakeholders from non-governmental organizations, research, and academia with the aim to promote dialogue and contribute to reducing the risk of escalation or conflict in cyberspace. States are encouraged to share information about such dialogues.” Again, should there be no consensus regarding this provision at this stage, I would like to request that we come back to this topic during the next substantive sessions. Finally, we will also share with the Secretariat the report on informal diplomacy published by the EU Cyber Diplomacy Initiative, which the UISS coordinates. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, EUISS. More than three minutes, but we take note of your points. I give now the floor to Global Partners Digital.
Global Partners Digital
Thank you, Chair. With regards to these questions, Global Partners Digital is pleased to be able to provide this input to the OEWG, and we appreciate your efforts to engage stakeholders thus far. However, we regret that many stakeholders who would have had many relevant inputs to share on these questions are unable to do so. We hope that this will not remain the case going forward, and that the OEWG will be able to benefit from the rich array of expertise that is available from stakeholders. In terms of contributing to the proposals, we would like to recommend that in developing additional guidance or checklists on norms implementation, states do so in consultation with stakeholders in their countries and regions. I was pleased to hear a commitment to do this already from a delegation in the room earlier. In this way, states can build awareness of the norms, but also ensure practical guidance is developed that is informed by realities on the ground and the needs of those on the ground, and draw on the expertise and the deep knowledge of existing regulatory frameworks that are relevant, standards that are relevant, draw on the expertise of those who respond directly to threats and to cyber incidents, and those who understand how those incidents impact people, communities, and society. GPD has worked with other experts, for example, to develop a series of briefs that unpacks the agreed framework or acquis from a human-centric perspective. When it comes to surveying implementation of the framework, we also urge states to work together with stakeholders and leverage their expertise and understanding of the policy landscape in their country to identify existing modes of implementation and gaps. States should convene inclusive open consultations to gather relevant input from non-state actors throughout the remainder of the OEWG’s mandate on all issues on its agenda, not only on capacity building. Non-stakeholder input can also add value to discussions on issues such as the applicability of international law in cyberspace, the effectiveness of confidence-building measures, and norm development and implementation. Regarding international law, the draft report states that the OEWG could convene discussions on specific topics related to international law and capacity building efforts on international law could be strengthened. Civil society organizations can and should support these efforts, particularly as they can bring legal expertise, including from a human rights perspective, and they can provide necessary evidence, data, and other information relevant to understanding the applicability of international law to cyberspace. We’ll provide a more detailed response in writing, but in the meantime, thank you for your attention.
Ambassador Gafoor
Thank you very much, GPD. The floor is now to ICT4Peace. Three minutes, thank you.
ICT4Peace
Thank you again for the opportunity to speak at this dedicated stakeholder session. Regarding the question on how stakeholders can work with states to contribute to the implementation of concrete action-oriented proposals, I would also just reiterate what I said a few moments ago about the importance of multistakeholder approaches and identifying the different roles and responsibilities that each stakeholder can play in order to contribute to a safe and secure cyberspace. I would also say that by including us and other stakeholders in the room and organizing the session, the Open-Ended Working Group (OEWG) shows great understanding of the nature of the threats that we are all collectively facing in the cybersecurity realm and the need for participation and collaboration of all relevant stakeholders. In addition, we should draw your attention to our proposal to improve transparency and accountability in cyberspace through the development of a peer-review mechanism on the order of the Human Rights Council. This would help to further develop what it means practically for states to behave responsibly in cyberspace and contribute to a growing body of good practices and standards to guide states in their behavior online. It would also provide a measure of transparency and oversight. We also carry out relevant research on ICTs and international security and would highlight a couple of recent research projects that we have carried out. One on neutrality in cyberspace, or what it means to be neutral in cyberspace in the context of conflict, which is not only relevant to neutral countries as such but to all countries who wish to remain neutral in the context of an armed conflict, which involves cyber capabilities. And in September, we will also be publishing a mapping study on the use of ICTs by commercial actors in the provision of private security services, a growing industry and trend that we need to look at. In closing, we thank you very much for this opportunity to speak today and contribute to the Open-Ended Working Group’s discussions and look forward to working with all stakeholders towards practical, effective, and action-oriented responses to the cyber challenges we are all facing. Thank you very much.
Ambassador Gafoor
Thank you very much for that intervention. I give the floor now to the Igarapé Institute.
Igarape Institute
Thank you, Chair. We would like to also thank you again for the opportunity. Given the important task of Member States this week to discuss the report, I would like to use this opportunity itself not to just answer what we could do as stakeholders to implement norms, but to already provide input to the report as future implementation efforts will be guided by it. We will submit our complete comments with detailed recommendations for the Secretariat. However, I would like to take these very brief moments to just highlight four points. On the question of gender, we welcome the reference to it in the Zero Draft Report. We recall the Women in Peace and Security Agenda and note that efforts of the OEWG would benefit from including a reference to it, thus linking cybersecurity to a transversal discussion to which gender is an integral part. And that has already been recognized in different reports, and I mention as an example the UN Women’s recent publication titled Action Brief, Women, Peace and Cybersecurity in Asia and the Pacific, as an example that highlights the need to strengthen, one, women’s participation in policy development and decision-making processes related to cybersecurity, and two, the prevention of online-facilitated violence and conflict risks. Second, on human rights, we believe that human rights should not be restricted to the international law section of the Zero Draft Report, and therefore propose that a mention be added to the introduction, reiterating the commitment of Member States with human rights through a reference to the norm 13D of the GGE 2021 report and paragraphs 1, 2, and 3 of the OEWG 2021 report. Additionally, in the potential threat section, we believe a mention could be added to how the escalatory cyber threat landscape, with the latest being, for example, ransomware, affects disproportionately human rights defenders, civil society organizations, universities, and the whole of society alike, as we’ve been seeing. Third, also on existing and potential threats, it is evident that States agree on the importance of protecting critical infrastructure. We believe that Section B would benefit from the characterization of how incidents against critical infrastructure meet the international peace and security threshold, that is, through their scale, scope, and speed. The inclusion of ransomware attacks against healthcare, for example, would fall under that characterization. And finally, on capacity building, we would recall paragraph 57 of the 2021 OEWG report and recommend the inclusion of a reference to South-South, North-South, and triangular cooperation. We believe this could inform and contribute to the consolidation of a more detailed discussion around capacity building. Thank you, Chair.
Ambassador Gafoor
Thank you very much. I give the floor now to the Paris Peace Forum.
Paris Peace Forum
Thank you, Mr. Chairman, Honorable Delegates. We are happy to address the Open-Ended Working Group with concrete examples on how stakeholders can work with States to contribute to the action-adoption proposals you made and you are working on this week. I would first like to inform Delegations that we can find a developed written contribution from the Paris Peace Forum with more detailed proposals related to our work on the website. I will take this opportunity to highlight three dimensions for a fruitful collaboration from stakeholders to the implementation of the action-adoption proposals. First, stakeholders can efficiently work with States by informing integral discussions held in the framework of this Open-Ended Working Group. Stakeholders can, for instance, efficiently contribute to identifying technical and cooperative measures to address existing and potential threats with regards to security in the use of ICTs, as mentioned in paragraph 7b of the revised draft Annual Progress Report, especially those mentioned in points 2, 3, 4, 5, 8, 9, and 10. Information exchanges and best practices in cooperation, mentioned in paragraph 8c of the draft Annual Progress Report, could in the same way be applied to stakeholders by including them through dual-track approaches within intergovernmental channels, when relevant for international security. Second, stakeholders can efficiently contribute to international norm-setting discussions on securing ICTs, while respecting States’ exclusive prerogative on the matter. Should the Open-Ended Working Group convene discussions on specific topics related to international law, as mentioned in paragraph 9a, the extended inclusion of stakeholders would, for instance, be especially relevant for discussions related to principles of international humanitarian law, as for any discussions involving concrete impacts on individuals’ and non-state actors’ rights and obligations. In the same way, voluntary contributions by States on how international law is applied in the use of ICTs, mentioned in paragraph 9b, could also be requested from stakeholders. Although the development of international law remains the exclusive prerogative of States, such contribution could be rewarded as subsidiary means to inform States’ work in specifying the applicability of international law in cyberspace, building on existing practice in international law, to accept non-state actors’ contributions as subsidiary means for the determination of rules of law, as for instance enshrined in article 38.1d of the Statute of the International Court of Justice. Finally, stakeholders’ involvement could strongly contribute to developing better mutual awareness, trust, and sufficient collaboration internationally. Should the Open-Ended Working Group agree to establish a global, intergovernmental points-of-contact directory on ICTs at the United Nations, as mentioned in paragraph 10a, additional steps could be, for instance, taken to extend such initiatives to stakeholders when relevant to international security in a specific forum. We remind the disposal of the delegation to elaborate this proposal, and once again, thank you for the opportunity to speak. Thank you.
Ambassador Gafoor
Thank you, Paris Peace Forum. I give now the floor to R3D. You have the floor, please.
Red en Defensa de los Derechos Digitales (R3D)
We welcome the consensus reached by delegations of states that have allowed for participation by stakeholders in the work of this OEWG, including civil society. We find that the diverse stakeholders, especially civil society organizations, can contribute in a significant way to the implementation of various proposals that seek to address action that is found in the progress report, including those related to identifying existing and potential threats, the implementation of rules, guidelines, and principles for responsible behavior of states, as well as discussions on specific matters concerning international law like the respect for human rights, due diligence, and the responsibility of states. In that regard, and given the limited amount of time we’ve been given, we will briefly mention some matters that we think are fundamental for this group to take into consideration now and during future sessions. We find, first off, that it’s important to recognize the asymmetry of offensive and defensive capacities that different states have concerning ICT security, which can be resolved not only through the development of capacity-building measures or confidence-building measures, but also by recognizing this asymmetry when it comes to peacekeeping and international security maintenance through ICTs. In that regard, the reduced number of states that historically have concentrated offensive cybernetic capacities assume greater responsibility, for example, when it comes to revealing vulnerabilities. We should also avoid certain states from imposing on manufacturers and developers of ICTs the obligation of establishing backdoors or debilitating the encryption. So it’s important that states guarantee that manufacturers and developers adopt security and privacy principles. States have an important choice to make. They can choose between taking on the joint responsibility of preserving the security and resilience of ICTs for all or remain under the unrealistic notion that they can keep security for themselves and at the same time maintain their ability to violate other people’s ICTs if they’re their adversaries, increasing vulnerability of the infrastructure that our societies and economies depend on more and more, thereby threatening international peace and security. Finally, we think that we need to recognize the growing participation of a mercenary industry in the spread of cyberattacks and the responsibility of those states that promote them. The activities carried out or facilitated by this mercenary group or these mercenary groups increase major risks to ICT security, for example, increasing economic incentives for not revealing vulnerabilities and increasing the number of actors that are able to carry out sophisticated digital attacks, like malicious non-state actors or transnational organized crime. Thank you for your attention.
Ambassador Gafoor
Thank you very much. I give the floor now to Third Eye Legal. You have the floor, please.
Third Eye Legal
Thank you, Chair. My name is Francesca. I am the CEO of the OEWG. I’m a Third Eye Legal representative for the private sector, and I’m grateful to the Chair of the OEWG for granting accreditation. Third Eye Legal Consultancy specializes in cyber aspects of international law and seeks to contribute and collaborate with the U.N. Cyber OEWG on developments in the field of ICT in the context of international security, including key aspects of annual cybersecurity. Third Eye Legal Consultancy specializes in international law and seeks to contribute and collaborate with the U.N. Cyber Security on developments in the field of international security, including key aspects of annual cybersecurity. Third Eye Legal affirms recommendations that help enable states to develop their own understandings of how international law applies to the use of ICTs by states and to contribute to building consensus within the international community. Some states express the view that due to the quickly evolving nature of the threat environment and the severity of the risk, an internationally agreed legally binding framework on ICTs is needed. It was also suggested that such a binding framework may lead to more effective global implementation of commitments to international law. Third Eye Legal Consultancy recommends that states agree to customary international law on cyber, leading to a binding framework. In order for all states to develop their own understandings of how international law applies to the use of ICTs by states and to contribute to building consensus within the international community, states agreed that there was a strong need for additional neutral and objective standards for the use of ICTs by states. To this effect, Third Eye Legal Consultancy seeks to contribute to and collaborate with the U.N. Cyber OEWG. In this regard, the Program of Action should be further elaborated. Multistakeholder initiatives can be instrumental in implementing the Program of Action as iterated in the informal discussions in the U.N. Third Eye Legal Consultancy is a part of the U.N. Cyber Security on cyber, leading to a binding framework of international law, in line with the 2030 Agenda for Sustainable Development. Third Eye Legal Consultancy can assist states in making informed choices in the Voluntary National Implementation Service, which will compensate for the lack of expertise, if any, that may delay the achievement of national, regional, and global implementation goals. Stakeholder capacity can be harnessed by making resources available to states to facilitate the implementation of the Program of Action. The coordination among states and stakeholders should be formulated in an actionable manner, addressing capacity issues and filling the gap where necessary. The POA, as a complementary initiative to the OEWG, will be a key enabler in realizing peaceful, secure, and stable cyberspace. Third Eye Legal Consultancy will assist states in ensuring that international principles and any deliberations of a binding framework are implemented in an actionable manner. Third Eye Legal Consultancy will also facilitate the implementation of cyber policies as suggested in the background of the proposal. Assistance to states shall include advice and recommendations as well as making informed choices in the Voluntary Implementation Service and the U.N. Disarmament Cyber Policy Portal. In order to inform the U.N. Cyber OEWG, Third Eye Legal seeks potential collaboration with relevant stakeholders to develop a comprehensive and effective framework for the implementation of the U.N. Cyber Policy. Third Eye Legal Consultancy will also support the U.N. Cyber Policy and suggest measures to strengthen data security as alluded to in the draft of the annual report. As a stakeholder, we seek to formulate a coordination mechanism within the U.N. framework to achieve those goals. In order to accomplish stated objectives, all necessary sustainable financial support will ensure deliverables meet the agreed-upon criteria. We are committed to working with the U.N. to develop a comprehensive and effective framework to support its successful adoption and to work on future collaborations. Thank you, Chair.
Ambassador Gafoor
Thank you for the statement. I now give the floor to Write Pilot.
Write Pilot
Allow me, Mr. Chair, to first start by thanking the governments of the UK, Ireland, and the Hashemite Kingdom of Jordan for enabling the participation of Middle Eastern women in cybersecurity in the third substantive session of the Open-Ended Working Group. We believe that this level of support testifies to the keen interest and multilateral cooperation and contribution of member states to reducing gender parity in this sphere. Under this guiding question, I would like to draw the Open-Ended Working Group’s attention to the role played by fellowship programs of the sort established and sponsored by the UK government in achieving ground-up practical impact and to encourage this as a model that can both be encouraged and enabled by the Open-Ended Working Group. For example, by making it easier for individuals who are active in such groups to be accredited to attend Open-Ended Working Group sessions. I’m founder of Jordan’s Women in Cybersecurity Middle East Affiliate Group and also the secretariat for the UK government-sponsored UK Gulf Women in Cybersecurity Fellowship. This is a regional program that has so far brought together more than 30 senior women in cybersecurity from across the Gulf. The fellowship provides them with an opportunity to work together as a team on meaningful projects with the underlying intent to deliver national and regional outcomes. These projects have so far achieved publicly available research on the cybersecurity skills shortages gap within the GCC to inform the development of needed capacity building programs and an understanding of the extent and nature of women’s contribution to cybersecurity across the GCC. A. The first Arabic online portal to enhance cybersecurity hygiene practices targeting children, women, and the elderly. B. The promotion and encouragement of fellows as role models within their region and globally through publicizing their achievements and promoting their contribution to international fora, including the participation of Women in Cybersecurity Middle East group at this UN meeting. C. The provision of general support to Women in Cybersecurity Middle East ongoing initiatives and programs to empower and support women through training, mentorships, regional cyber competitions to name just a few. D. Support for the development of an innovation framework for a regionally focused cybersecurity innovation lab and the provision of certified innovation training. This fellowship model of collaboration demonstrates a poignant example of an action-oriented and results-focused initiative to improve gender diversity in the cybersecurity profession that we would like to see replicated across the Middle East and internationally to enhance the contribution of women to national and global development efforts in cybersecurity. In addition, I have seen firsthand how interaction between my Jordan Women in Cyber Middle East affiliate group and the cybersecurity services company within its network was able to provide two female graduates currently studying for their cybersecurity master’s degree with the opportunity to work on a high-profile forensics case to give them the needed experience, exposure, and on-the-job training. We therefore welcome the contribution of large technology companies to offer apprenticeship schemes as part of a broader strategy for capacity building for women to both encourage and increase their number in the cybersecurity workforce and encourage all efforts to identify those willing to offer such schemes and match them with recipients who will benefit, such as my Wixme Jordan affiliate group. And finally, on behalf of Wixme and the UK Gulf Women in Cybersecurity Fellows, I would like to thank the UK government and other member states once again for supporting Wixme and the UK Gulf Fellowship. We ask them to bear witness to the progress made by these women in fulfilling a long-held aspiration of participation in the UN Open-Ended Working Group in the security of and use of ICTs in the context of international security. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much for that statement. I now give the floor to Youth for Privacy.
Youth for Privacy
Thank you, Honorable Chair. Good afternoon, distinguished delegates and stakeholders. My name is Amogh Dimri, and I’m a representative of Youth for Privacy. These past two days of negotiations have made clear that this body believes that cyberterrorism and cyberattacks are central threats in the effort to foster safer ICTs. However, we, the youth, believe that an equally important yet largely overlooked threat to that future is the affront to individuals’ private data occurring every day. In fact, it is the normalized corporate data mining and sale of individual private data without public awareness that we wish to rectify. Youth for Privacy is a collective of youth from around the world advocating for privacy as a human right. Our effort to ensure that the youth voice is heard on the issue of ICTs is not only because users aged 18 to 24 comprise a quarter of global internet usage, but also because today’s youth come from a generation that has grown up with the internet and, more importantly, will see the internet and new technology like artificial intelligence become increasingly pervasive and shape the rest of their lives in an unprecedented manner. We have three recommendations for the progress report. Firstly, section F of the progress report discusses capacity building for future discussions on ICTs as offering cooperation between states and new concerned stakeholders. Moreover, the recommended next steps in section G on regular institutional dialogue call for new mechanisms to advance capacity building. To these ends, we, the youth, assert there is no more pertinent stakeholder perspective and no better way to bolster this working group’s capacity building efforts than to sponsor an international cohort of youth delegates to attend the fourth and fifth sessions of this working group. We seek to have the youth be involved in the decision-making process regarding data privacy, and Youth for Privacy is eager to aid this body in reaching out to passionate youth to attend future sessions and make this group’s discussions robust and rounded. Secondly, we wish to remind states that with respect to section D concerning international law, the right to privacy is enshrined in the Universal Declaration of Human Rights, the International Covenant on Civil and Political Rights, and the Convention on the Rights of the Child. They read, no one shall be subjected to arbitrary or unlawful interference with his or her privacy. So, if privacy is a human right protected by international law, then why do we ignore the routine and normalized breaches of individual data privacy and exclusively highlight cybercrime as our core threat? The right to privacy is an essential and core right for all, especially with regards to women and children’s rights, and going forward, we, the youth, assert that the internet will become the new battleground for our right to privacy. With this in mind, the progress report must be expanded to herald the right to privacy as a core directive for states to uphold online with the same vigor they do in the physical world. We urge this body to highlight the right to privacy under international law in the progress report as a reminder to states that protecting this right is essential for any future discussions on ICTs. Finally, we urge states to expand upon section C on Responsible State Behavior by adding a privacy review stage that comes before implementing cybersecurity responses to ensure individual privacy is not impeded upon by such measures. Privacy is, after all, a human right, and therefore there can be no such thing as responsible state behavior without giving credence to the existing international law regarding privacy. I thank you for your time, and we are eager to collaborate with member states and fellow stakeholders.
Ambassador Gafoor
Thank you very much, Youth for Privacy, for that very helpful statement. There are two further requests for the floor, not from the stakeholder community, but I think from the accredited observer organizations, INTERPOL and the International Chamber of Commerce. I’d like to give them the opportunity as well. So, INTERPOL, you have three minutes, please.
Interpol
Mr. Chair, esteemed delegates, Interpol thanks you for the opportunity to engage with the Open-Ended Working Group and makes this statement in its capacity as permanent observer to the United Nations. Interpol shares the concerns of the OEWG draft progress report that threats in the use of ICTs continue to intensify and evolve as threat actors continue to exploit an increased reliance on the digital environment. Interpol’s mandate covers non-state threat actors and ordinary law crimes. At the same time, the support that Interpol provides to its 195 member countries contributes substantially to the capabilities of these countries and, by extension, their implementation of norms. Interpol emphasizes the importance of optimizing the use of existing mechanisms, platforms, and networks in addressing cybercrime. An example of this is Interpol’s I-247 platform, which facilitates secure information exchange between law enforcement agencies across the globe. Additionally, Interpol maintains a 24-7 cybercrime points of contact list for the law enforcement community to facilitate timely operational responses to cybercrime in joint investigations or during ongoing cyberattacks. This 24-7 points of contact list includes up-to-date information such as the name, phone number, and email address of the head of the cybercrime unit in national law enforcement agencies. Finally, Interpol would like to highlight the importance of ensuring that international cyber-related policy processes have adequate input pertaining to law enforcement cooperation. Interpol stands ready to support the OEWG process, and our written submission is available on the OEWG’s website. I thank you.
Ambassador Gafoor
Thank you, Interpol. International Chamber of Commerce, please.
Internatinal Chamber of Commerce
Many thanks for the opportunity to speak on behalf of the International Chamber of Commerce. The U.S. Council for International Business, as ICC’s affiliate in the United States and an accredited stakeholder to the Open-Ended Working Group, also aligns itself with the statement. As my colleague from Access Now mentioned, we are disappointed that so few voices from the business community were given the opportunity to speak here today, but we wish to take the floor again to highlight their work and contributions, much of which was already highlighted throughout stakeholder consultations and also on the Open-Ended Working Group website. I wish to reiterate my point made earlier today that stakeholders bring significant experience and insight across all elements discussed by the Open-Ended Working Group. Multistakeholder action is critical across rules development, capacity building, and implementation alike. For example, business provides invaluable technical expertise to the expert groups developing policy guidelines and instruments to ensure they are commercially and technically feasible. Multistakeholder forums, such as the Global Forum on Cyber Expertise, act as a resource for states coordinating regional and global cyber capacity projects and initiatives. The important collection of technical standards and good practices provided by organizations such as the ISO, ISA, IEC, NIST, and others are fundamental resources for adequate development of information security, cybersecurity, and privacy management systems. Furthermore, the ICT infrastructure is largely built and maintained by the private sector, so deliberations on peace and security in cyberspace need to be inclusive of non-governmental voices. On capacity building in particular, the examples shared by fellow stakeholders today demonstrate that there are really no limits to the types of projects that stakeholders have proven themselves willing and able to support. Capacity building contributions may vary across stakeholder groups, but they ultimately complement each other and lead to more comprehensive solutions to advance shared goals. As we’ve mentioned on previous occasions, capacity building is an area where further work by the Open-Ended Working Group may have the most important impact in two ways. Firstly, agreeing on a set of cyber development goals so that the international community has a benchmark that can be used to assess what states need in order to reach the level of technical, institutional, and legal development that makes possible the full implementation of the international acquis. And secondly, by leveraging that common set of goals to evaluate what capacity gaps they face and what assistance they might need in order to reach them. Elements of proposals already made by member states, such as the national survey on responsible use of ICTs by states, the voluntary publication of national implementation frameworks of international law, or the points of contact directory, just to name a few, could be proposals considered under the CDGs. I wish to thank the United Kingdom for their support in this proposal of ours, and we are looking forward to working with them as well as all other governmental and non-governmental stakeholders inside and outside this room to bring it to fruition. I thank you.
Ambassador Gafoor
Thank you very much, International Chamber of Commerce, for the statement. I have no other requests for the floor from the stakeholder community. I know the hour is getting late. I would like to nevertheless ask if there are any Member States who wish to quickly respond or comment with regard to the comments you have heard from the stakeholder community. Very good. I do not see any requests for the floor. And I certainly don’t want to summarize the discussions because it has been a very rich and very helpful discussion and an interactive discussion too, I should add. I have frankly found this session to be very energizing and uplifting in many ways to see a diverse range of stakeholder representatives from developed as well as developing countries, the voices of women, the voices of youth representatives, and I think it has also been useful to have a very useful, albeit brief, interactive discussion. Second, I take note of some of the disappointment expressed with regard to the fact that not many organizations are present here because the accreditation was not successful, but I think it is important that we look at the fact that the glass is half full rather than half empty, and I certainly hope that with the modalities we have, we will be able to see more and more accredited representatives participating in the work of the OEWG. Third, it is quite clear to me from this session that there is very strong value and usefulness in having stakeholders present in the midst of this working group, observing our work, and also having the opportunity to comment in a dedicated session. But the stakeholder community should also note that it is not me as the chair that you are communicating with or having a dialogue with. It is ultimately a venue for you to reach out to delegations, and there are 193 of them, and I should say that not all of them are present at this session, and therefore it is important for the stakeholder community to reach out to the delegations, as many as possible, and also demonstrate to delegations that there is value in your presence, that you can bring a value-added contribution to this process. As I said, I have no doubt about the value you bring to the process, but I think it is incumbent on the stakeholder community that you reach out to government delegations and demonstrate the value-added, and how you can help them, the delegations, through your presence and participation. So I think that is important, but I would note also that this is perhaps the beginning of a process, because this is the very first dedicated stakeholder session that we are having, and it is in person, so this gives stakeholders an opportunity to reach out, establish networks, and make friendships, and convey your views, persuade government delegations of your views and ideas. I think one of the stakeholder communities, I think it was the European Union Institute for Security Studies, which spoke about informal diplomacy and informal diplomatic channels. In a sense, being able to participate in the working group, and being present in this working group throughout the week, gives you the opportunity for informal diplomacy, because you have a lot of time here in the working group to reach out to government delegations and engage in informal interactions, and I hope that you will take that opportunity. The point I’m making is that we don’t need to wait to establish a formal Track 1.5 process for informal interactions to begin. While that is useful and always helpful, you can already engage informally in a Track 1.5 at the margins of this working group, and I’m sure all of you are doing precisely that by reaching out to government delegations. Finally, I hope that the ideas that you have contributed will serve to enrich the outcome we have, and I hope that stakeholder representatives who have observed this discussion from Monday, Tuesday, and now Wednesday, will realize that it is not easy to produce outcomes at the United Nations, not just because the issues are complex, but simply the nature of an intergovernmental process in which governments make decisions, in which governments are sovereign, means that we have to listen to every single voice in this process. And this is a process that works on the basis of consensus, which means that we have to patiently listen to every voice and every proposal to see what is the best middle ground, and very often at the United Nations, not just for this process, the middle ground inevitably is narrow, and it’s thin ice, and it’s very fragile. So that’s what we are navigating. While your ideas are very interesting, very helpful, and very bold, I want to say that we need to take a longer-term perspective in terms of making some of these ideas a reality. And not everything can be achieved at this session or overnight. So those are some initial reactions I have, and I wanted to take this opportunity to thank all the stakeholder community, the representatives who are present. I hope that you have found this session in some ways useful for your work, that you can bring back to your communities and organizations back in the countries and cities where you are represented. And this is going to be a two-way process, as one of you had said, and this is the beginning of an interactive dialogue, which I hope will continue to enrich the process and also enrich your work in the stakeholder community. Now, with this, we have concluded the dedicated stakeholder session. It’s my intention to adjourn the meeting very soon. I do need to go back and start working on the revised trial panel progress report. But before I adjourn the meeting, I wanted to say that tomorrow we will resume the discussions on Agenda Item 5 in accordance with the program of work. And I had earlier announced that we will have the thematic discussion on capacity building with presentations from UNIDO, as well as by representatives of regional organizations on best practices and lessons learned with regard to capacity building efforts. And I understand that we will have a good lineup of regional organizations. That is for tomorrow, starting with the African Union, ASEAN, CSTO, Collective Security Treaty Organization, European Union, OSCE, and OAS. So that will be for tomorrow morning’s thematic discussion on capacity building from 10 a.m. to 11 p.m. And after that, we will resume our work on Agenda Item 5 relating to the draft annual progress report. On the draft annual progress report, again, in accordance with what I had said earlier, it’s my intention to make available a revised draft document this evening. And I anticipate that it would be ready around 8 p.m. So I do need to go back and start looking at it. I’ll have a cup of coffee before I do that so that I can look at it with a fresh pair of eyes. I’ve been in the basement with no access to sunlight, so I’m not sure what time it is out there. So wish me luck. I am also encouraged by the statements from the stakeholder community who have all expressed support for the idea of producing and adopting an outcome document by the end of the week. As I told Member States earlier this morning, nothing at the United Nations is given, consensus is never guaranteed, and outcome is never preordained. We have to work for it. And stakeholders also have a role to play in talking to delegations to ensure that we produce an outcome. And as the chair, I will do my best. We have all the ingredients to make a very decent smoothie. I need to switch on the blender this evening. Let’s hope there’s not too much water in the wine, as Canada put it. But I hope that we will be able to have a revised document that will be a step forward in terms of finding a consensus outcome at the end of the week. So with those comments, I thank you for your participation and your patience. The meeting is adjourned. Thank you.
Leave a Reply