Ambassador Gafoor
Good morning, Excellencies, colleagues, friends. The first meeting of the fourth substantive session of the Open-Ended Working Group on Security of and in the Use of Information and Communication Technologies 2021-2025, established pursuant to General Assembly resolution 75-240 of 31 December 2020, is called to order. Distinguished delegates, I extend a very, very warm welcome to all of you this morning. I’m delighted to see so many of you here in person at United Nations Headquarters in New York. I extend a very warm welcome to those who have traveled a long distance to be here in person. I thank you for your participation, and for those representatives who are based in New York, thank you also for your participation. I’m aware that this is a particularly busy week. Today, the United Nations is holding the meeting of the 67th session on the Commission on the Status of Women, and it is in some sense appropriate that we too are holding our meeting at the same time, because the theme for the Commission on the Status of Women is innovation and technological change and education in the digital age for achieving gender equality and the empowerment of all women and girls. So, on this important day, as we begin our deliberations here in this committee of the Open-Ended Working Group, I want to extend a special welcome to the women representatives and delegates. Thank you for your presence here, and in particular, I also acknowledge and welcome the presence of the Women in Cyber Fellows. Distinguished delegates, I would also like to acknowledge the presence of Ms. Izumi Nakamitsu, Under-Secretary-General and High Representative for Disarmament Affairs at the United Nations, and at this point, I’d like to give her the floor to hear her opening remarks. Ms. Nakamitsu, the floor is yours.
Izumi Nakamitsu
Thank you very much, Mr. Chair. Mr. Chair, Excellencies, Distinguished Delegates, Ladies and Gentlemen, I am grateful for another opportunity to address the Open-Ended Working Group on security of and in the use of information and communication technologies. With each session, the issues under the purview of this group become increasingly urgent and higher priority. In other words, the stakes continue to rise. We are witnessing a steady stream of malicious cyber activity around the world. Malicious cyber activity during conflict time, especially activity targeting sectors providing critical services to the public, is a serious concern. Malicious activity in connection with the war in Ukraine is a case in point. Rhetoric around cyberspace as a domain of hostilities is unacceptably commonplace. And scenarios involving direct military confrontation in response to malicious ICT activity are far from abstract. Despite these challenges, there is some reason to feel encouraged. This working group has been able to find areas of convergence and identify topics for further discussion under the very able leadership of Ambassador Gafoor. I thank him for steering the group’s deliberations in a highly practical, action-oriented manner. I also appreciate his convening of constructive informal intersessional meetings in December last year. At a time when consensus agreements seemed elusive, this working group adopted its first annual progress report in July, which marked a critical intermediate step. Through the report, states reaffirmed the agreements reached in the previous Open-Ended Working Group and Groups of Governmental Experts, thus further solidifying commitment to the normative framework for responsible state behavior in the use of ICTs. The report includes a range of other noteworthy achievements. It builds on the work of the previous working group with regard to language related to harmful ICT activity against critical infrastructure. The report is also realistic in its threat assessment as it notes the challenging geopolitical environment and threats posed by malicious use of ICTs by both state and non-state actors. The report also demonstrates good progress on gender. The working group agreed that states could continue to raise awareness of the gender dimensions of ICT security and promote gender-sensitive capacity building at a policy level, as well as the selection and operationalization of projects. As is often said, addressing gender dimensions in all disarmament and international security discussions is not a nice-to-have, but rather a must-have. The progress report recognizes the need for further exchange of views on several of the most challenging topics at hand, from emerging and potential threats to the applicability of international law, including further study on how and when the foundational principles of international humanitarian law apply to the use of ICTs by states. The working group identified other specific topics for discussion, including best practices and lessons learned on topics of public-private partnerships and funding for capacity building efforts. Given this specifically, I would echo the chair’s appeal to delegations to use their interventions throughout this week to address these focused topics. Finally, and perhaps most concretely, the working group agreed to establish a global intergovernmental points of contact directory. Early operationalization of a point of contact directory would not only build confidence between and among states but also serve as a tool to pursue other cooperative measures to address threats arising from malicious use of ICTs. The directory should not be seen as an end in itself, but a critical next step towards a peaceful ICT environment. I hope states will be able to agree to the modalities for its operation this year. Mr. Chair, distinguished delegates, ladies and gentlemen, the adoption of the first annual progress report, while praiseworthy, cannot result in complacency. We need to redouble efforts to build convergence on topics under all of the group’s agenda items, especially on the issues that seem farthest from consensus, like common understanding on the applicability of international law and questions on the sufficiency and implementation of rules, norms, and principles. I hope delegations will not shy away from tackling these most difficult matters. Before concluding, I wish to reiterate that the Secretary-General is fully committed to supporting states in the safeguarding of a peaceful, secure, and stable cyberspace. Concretely addressing the potential for cyberspace to become a domain of conflict and hostilities is a high priority for the Secretary-General and one that will constitute an important part of his proposed new agenda for peace. Multistakeholderism will also feature prominently in this context. I continue to believe that the most effective responses to challenges arising from cyberspace require engagement by a range of actors, including civil society, academia, and the private sector. I take this opportunity to welcome the non-governmental entities here in the room today and those following on webcast. I said at the outset of my remarks that the stakes are high and rising. We must rise to meet them. I wish you all the very best in your deliberations this week. The United Nations remains your steadfast partner. I thank you very much for your attention.
Ambassador Gafoor
Thank you very much, Ms. Izumi Nakamitsu, for your remarks, and thank you also for the support that you and your team have offered this process. And of course, we also value very much the support of the Secretary-General himself. Distinguished delegates, please allow me to make my opening remarks before we proceed with the rest of the agenda items. Today, we are meeting for the fourth substantive session of the Open-Ended Working Group. And as we begin this meeting, I think it is important to reflect on where we are as a process and where we have come from in this process. The Open-Ended Working Group, of which this is the second iteration of such a process, is not starting from scratch. I said this last year, and I think it is worth remembering this. We have a foundation that was built over a period of two decades, during which there have been meetings of six GGEs and also one previous version of the Open-Ended Working Group, which concluded by adopting a consensus report. It is on that foundation that we began our work when we had our first meeting in June 2021. At the first substantive session in 2021, I had said that what we are engaged in is like a marathon. We have a long distance to go. And we can be satisfied that we have traveled some distance, but we are not even at the midpoint of this long process. We have a lot more distance to cover. Last July, we made a very important step by adopting a consensus annual progress report. A journey of a thousand miles begins with a single step, as is often said in various parts of the world, especially a proverb that originated in China. I think there is a lot of truth in that. It is important that we do not stop after the first step. In that regard, I welcome very much the message from the Under-Secretary-General that there is no room for complacency. It is our responsibility to maintain the momentum and deliver concrete results for the international community, for our countries, and for our people. Please allow me to make some additional points. As we are meeting today, the international geopolitical environment remains very challenging. We are faced with multiple crises, natural disasters, wars, and the relationship between major powers continues to be strained, and there continues to be a high level of mistrust. The multilateral system and the United Nations are facing many serious challenges – the global economic crisis, the debt crisis, the energy crisis, the food security crisis, shocks and strains in the supply chain system. And in such a context, the landscape for ICT security has also evolved and in some ways has become even more challenging. The malicious use of ICT has increased, not decreased. In many ways, nations today are more vulnerable to cyber attacks compared to a year ago. It is in that context that we should look at the work that we are doing here in this working group. This leads me to my second point, which is that the work of the Open-Ended Working Group has become more relevant now, not less relevant. Why do I say that the work has become more relevant? Simply because we face increasing risks and multifaceted threats in cyberspace and to ICT security because of the evolving nature of digital technologies, which continue to transform our societies and economies. Artificial intelligence continues to make advances that are both exciting but also worrisome. And it is creating opportunities but also creating new types of threats and risks. The rapid pace of development in digital technologies offers great opportunities to accelerate sustainable development, that is sure. But in order to reap the benefits of these new digital technologies, we have to strengthen the framework of rules, norms, and principles of responsible state behavior. We have to build on this framework to safeguard international peace and security and to allow for greater cooperation at the global level and to create greater levels of trust between member states. In that regard, the work of the Open-Ended Working Group is critical because it is the only inclusive, open-ended, transparent, and democratic platform that we have today to discuss ICT security. It has often been said that the Open-Ended Working Group is a CBM in itself and offers a platform for dialogue among nations. I think the CBM nature of the OEWG process is needed much more now than ever before. At the same time, the OEWG, because it is an inclusive process, has brought so many other nations into the discussions and into the dialogue. And this is evident from the full capacity that we are seeing in this room today. Representatives from developing nations, representatives from small countries are excited and ready and committed to join this global dialogue on ICT security. In that sense, the Open-Ended Working Group process has helped to raise awareness about the importance of ICT security to all countries. It has also raised awareness and underlined the importance of all nations working together to strengthen the framework of rules, norms, and principles of responsible state behavior in the cyber domain. I would say that the Open-Ended Working Group is also an important platform to rebuild levels of trust. Over the last 12 to 18 months, we have, I think, been working hard to rebuild levels of trust and, in some cases, repair the levels of trust that might have shown some cracks. But the task of repairing trust and confidence is not something that can be achieved overnight. This is a work in progress. And I urge all of you to approach the task of rebuilding levels of trust with great care and with great responsibility. The third point that I want to make is that the OEWG must build on the progress that was made last year when we adopted the first annual progress report. Whether it’s in terms of concrete outcomes, for example, it is important that we really reach agreement on the elements of the POC directory in order to operationalize it as soon as possible. At the same time, we should also continue our focused discussion on all pillars under the mandate of the Open-Ended Working Group. It is vitally important that in July this year, we deliver a substantive second annual progress report as a follow-up to the recommendations that were made in the progress report that we adopted last year. And in order to be in a position that we are able to adopt a second progress report in July, we have to start working seriously and in a focused way at this session in order to build convergence. It is my intention to give a fair and balanced consideration of all the items under the mandate of the Open-Ended Working Group. On some topics, convergence might be a little less challenging. But in other areas, convergence and consensus will be more challenging. But whatever it is, it is important that we approach the discussions with an open mind. It is clear that the issues on our agenda are going to be difficult. That is why I have always advocated that we take an incremental approach, a step-by-step approach to building convergence. If we are to build something concrete, we need to build consensus brick by brick, one step at a time, so that over a period of time, we are able to see together and collectively an outcome that we can all embrace and be satisfied with. But even as we are trying to build convergence, we also need to continue the work on implementation. I would also appeal to delegations to approach this session from the perspective of finding consensus, finding solutions, and seeking the middle ground. The OEWG, because it is almost in its second year, is not a place for a general debate. Neither is it a debating club. I think the positions of all delegations are well known, and I recognize that you would need to put your position on record and explain your position. That is important in terms of increasing levels of understanding. But at the same time, if we are to make progress, we need to be focused. We need to be focused on specific actions and concrete outcomes. The good news is that the OEWG has demonstrated that it can deliver results. To put it differently, you have demonstrated that you can deliver results when you work together. That gives me some grounds for optimism that we can, in July, adopt a substantive progress report. My hope and my determination is that we can and we must deliver a substantive second annual progress report in July to build convergence on a range of issues, on a package of issues, building on what we have already achieved last July. I also want to remind delegations that the work that we are doing helps to strengthen the cumulative and evolving framework of rules, norms, and principles of responsible state behavior. As our work continues to be guided by Resolution 75-240, that resolution is our mandate, and it will continue to be the guide for our work. But we must also use the annual progress report adopted last July as a roadmap for our discussions, because that is what we agreed last July, that the annual progress report will provide a roadmap for our focused discussions at the fourth and fifth substantive sessions. It is therefore my hope that members will not reopen or re-litigate issues from previous sessions on which we have reached agreement. Let us respect what we have agreed to do. Let us respect our differences and our positions. But even as we understand each other’s differences, let us work together to find common ground. I want to thank all of you for your support and spirit of cooperation in which you have approached this process. Your support will determine whether we are able to take another step in July. Finally, let me also acknowledge the presence and participation of stakeholders in this process. I have always said that as Chair of this process, I am committed to a systematic, sustained, and substantive engagement with stakeholders. I have continued in that spirit to engage stakeholders in various formats, including at informal, intersessional meetings. I want to acknowledge the work and contribution that stakeholders make to this process by bringing their ideas, by bringing their solutions, but also bringing their knowledge and expertise to this process. And I would encourage all delegations to work with stakeholders and engage them. Likewise, stakeholders, I think, have a responsibility to building convergence in this process. Where there are differences, we need to find solutions, not try and exacerbate these differences, but try and find solutions. So ideas coming from all aspects of the civil society and stakeholder community would be very much welcome. So, Excellencies, Distinguished Delegates, with those opening remarks, I would like to once again thank Ms. Nakamitsu for her presence and for her remarks. And before we continue with the rest of the work, please allow me to confer briefly with Ms. Nakamitsu. Thank you very much. We will now proceed to the Programme of Work. And here we are at the final agenda, guided by the agenda that we adopted in April. In that context, I have prepared a Programme of Work to organize our discussions today. On the 3rd of March, I circulated a revised Programme of Work, which has been circulated in document AAC 292-203-REV1, Provisional Programme of Work. And I wanted to briefly explain to you, first of all, that the Programme of Work is a tool for our discussions. It is intended as a tool to organize our time effectively for the remaining part of the week. I have also prepared guiding questions, and the guiding questions are also intended as a tool to focus our discussions. Let me explain why I have prepared a revised version of the Provisional Programme of Work. I would like to assure you that the revision was intended to simplify the Provisional Programme of Work that needs to be approved by this working group. The guiding questions, on the other hand, are my suggestions to you in order to focus the discussions. The guiding questions do not need your approval, which is the reason why I decided to separate the guiding questions from the Provisional Programme of Work. Secondly, the removal of the guiding questions from the Provisional Programme of Work does not mean that we are not going to have focused discussions. I want to make that very clear. We will continue to have focused discussions, and it is my intention as Chair to have this meeting focus on some of the very specific issues and questions and recommendations that came up from our Annual Progress Report. So the removal of the guiding questions from the Programme of Work is by no means intended to return to a general debate or a general discussion, neither is it intended as a means to avoid a focused discussion. On the contrary, the removal of the guiding questions is intended to avoid a big debate over the Provisional Agenda, because it is not my intention to negotiate or debate the Provisional Agenda. I hope that with that spirit, you will be able to adopt the Provisional Programme of Work as revised, and we will proceed on the understanding that we will continue to be guided by the Annual Progress Report as well as the Agenda, with the guiding questions that I have submitted serving as a guide for discussions. And as always, every delegation has the liberty to raise issues that it thinks are relevant. And if you do not like my guiding questions, please feel free to ignore them, but please do make a focused contribution, and please address issues that you think I have not addressed or you think need to be addressed in order to build convergence. Thank you very much.
Ukraine
Mr. Chair, our delegation would like to, it’s not on the program of work, but rather on the stakeholders’ participation. We are ready to make a statement right now or right after approval. It seems that this agenda item is suitable for raising, to explain our position on the issue of stakeholders’ participation.
Ambassador Gafoor
Thank you very much, Ukraine. May I add that we approved the program of work, and after the approval of the program of work, I’ll give delegations the opportunity to raise other issues, including the issue of stakeholder participation. Can we proceed in that way? So, may I ask if there are any objections to the approval of the program of work? I see Canada and France have asked for the floor. Is this relating to the adoption of the program of work? Canada, please.
Canada
It is on the—thank you, Chair—it’s on the stakeholder issues, so I will wait until after.
Ambassador Gafoor
Thank you very much, Canada, for your understanding. France as well.
France
Mr. Chairman, thank you very much. Thank you for specifying information about the guiding questions, which, as you recalled, is our own responsibility. Of course, we will not oppose adding to the program of work. However, we have also highlighted the fact that the Program of Action had disappeared from the documents that you distributed a few years ago, and that’s although the annual report provides for states to be involved in more specific discussions on that proposal. So we’d just like to underscore in that regard that these are published under the responsibility of the Chair and do not call into question the consensus-based agreement within the group to go into discussions of the Program of Action. As far as we’re concerned, of course, we will use the guidelines to develop our vision of main principles for the Program of Action. Thank you, sir, and I can assure you of our full support of the work of this session.
Ambassador Gafoor
Thank you very much, France. Let me assure you that the Programme of Action has not disappeared. It is on the agenda of the Working Group in accordance with the mandate as outlined in Resolution 75-240. It is also in the Annual Progress Report that we adopted, which will serve as a roadmap for the work of this Working Group, and we will use that as a roadmap for discussion this week. So it’s very much there. Ultimately, not just on the Programme of Action, but on all the agenda items, nothing has disappeared. We need to work on them and find consensus. That’s my understanding. So with those comments, if there are no objections, I’d like to propose that we approve the Programme of Work. I see no objections. It’s so decided. Thank you very much for that. So we will use the Programme of Work as a tool to organize our time, and I want to add that if we exhaust an agenda item earlier than it is scheduled in the Programme of Work, we will go on to the next item in the Programme of Work. And if we complete all the agenda items earlier than Friday, then it is my intention also to use the time available for discussion. On additional issues, we need to address to a better understanding in terms of what might be possible. So we will use the program of work in a very flexible way. It’s not cast in stone. We may switch things up or move things up if unable to complete discussions on a particular agenda item. So with that understanding, I hope I will also have your understanding. We can now proceed to take comments on issues that delegations wish to raise before we proceed on the first agenda item, which is existing and potential threats. Before we do that, I’ll give delegations an opportunity to make comments on the issue of stakeholder participation, which some delegations have indicated an interest to comment on. So we’ll start with Ukraine. Ukraine, you have the floor, please.
Ukraine
Thank you very much, Mr. Chair, for giving the floor to our delegation to explain our position on stakeholder participation. At the outset, the delegation of Ukraine would like to stress that Ukraine has always supported the broad participation of stakeholders in the work of various UN bodies, including the OEWG on cyber. We are of the view that all interested stakeholders can make significant expert contributions to the work of the OEWG, in particular in better understanding all key issues on the agenda item. In addition, Ukraine believes that the full-fledged participation of stakeholders testifies to the inclusiveness, openness, and transparency of our discussions in the working group. Mr. Chair, since the issue of inclusiveness and transparency is also related to the accreditation process within the OEWG, we would like to stress the following. After careful consideration of the list of non-governmental organizations that do not have consultative status within ECOSOC, which submitted applications for accreditation in accordance with agreed modalities, we have concluded that a number of stakeholders do not meet the criteria of independence and impartiality. In particular, we consider that a number of organizations from the Russian Federation are state-affiliated entities, which raises serious doubts about their impartiality and independence. In this regard, we have decided to object to the accreditation of such entities for participation in the fourth session of the OEWG. However, we cannot but mention that Russia again blocked a number of stakeholders, thus preventing them from participating in the work of the OEWG. As a result, the OEWG has been deprived of the opportunity to listen to the views and recommendations of these organizations, some of which are among the world’s most prominent in the field of ICTs. In conclusion, Mr. Chair, Ukraine stands ready to continue actively contributing to the work of the OEWG and to the establishment of an open, secure, stable, and peaceful cyberspace. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Ukraine, for your statement, which is well noted. I now give the floor to Canada.
Canada
Thank you, Chair. I am also taking the floor because I would like to discuss the inclusion of stakeholders in the OEWG process. As we all recall, it took us eight months of rather difficult modalities negotiations to agree on the modalities at the beginning of this Open-Ended Working Group. The modalities that we all agreed on included one main gain, the need for states that use their veto to do so openly and transparently. The idea being that if a state wishes to use its veto right, it must do so openly, not anonymously as was the case at the previous Open-Ended Working Group. In Canada’s view, this principle has been violated in spirit by the unfortunate delays in accrediting stakeholders this time around. We do not know which state requested the two delays in question, which we would argue goes against the spirit of the modalities that we adopted last year. The result of these delays is that newly accredited organizations only found out that they were accredited mid-week last week, giving them only a few days to book their travel to New York. Some recently accredited organizations may not have been able to come because by then flights may have been full or too expensive. These delays are unfortunate in and of themselves as they limit participation of even accredited stakeholders. Worse, we do not know which state or states requested the delays, so there is no transparency or accountability. We therefore condemn these delays. We respectfully urge the Secretariat to in future refuse such repeated requests for delays. We would respectfully submit that any decisions on accreditation should in future be made at least one week before OEWG meetings in order to give stakeholders a minimally acceptable amount of time to plan their travel. Now, let me say a few words about the vetoes themselves. Last year, of the nearly 80 or so organizations who applied for accreditation, about two-thirds were accredited and one-third or so were vetoed. This was notable progress compared to the previous OEWG, which had a zero for 18 record. Just recently, organizations were allowed to apply for accreditation again. We were very pleased that 77 organizations were accredited this time, which is almost 25 more than a year ago. This is solid progress by UN standards. However, we were disappointed that nearly 30 organizations were vetoed by five states. These vetoes are most unfortunate as they deprive the OEWG of benefiting from the full participation of reputable organizations such as Microsoft, the Cyber Peace Institute, and the Australian Strategic Policy Institute, among many others. Canada would encourage states to explain their use of vetoes. We thank Ukraine for doing so and urge others to do the same thing. While we recognize that such an explanation is optional, Canada believes that all states in this room should understand the nature of opposition to the presence of these vetoed stakeholders. We hereby respectfully request that the states that used their veto explain why they did so. I want to say that despite these unfortunate delays and vetoes, Canada remains committed to taking into account the view of all relevant stakeholders as we develop our positions and text proposals. We did so at the last OEWG, where despite the unfortunate veto of all 18 organizations who applied, we developed, for example, our norms guidance text in consultation with over a dozen non-state organizations. They provided extremely useful proposals and comments, many of which were included into our text. We plan on following this approach of consulting all relevant stakeholders, including ones who were just vetoed, again at this Open-Ended Working Group. We encourage other states to consider taking this approach as well. I would like to conclude by saying that I really welcome the participation of Women in Cyber Fellows in the room who contribute to gender balance and the quality of interventions at every session. Thank you, Chair.
Ambassador Gafoor
Thank you very much, Canada. Your comments are very well noted. I give now the floor to the European Union, to be followed by the Russian Federation. EU, please.
EU
Thank you, Chair. I would first like to echo the statement made by Canada and add that we really regret that there have been so many organizations vetoed yet again, that have crucial expertise that we want to benefit from. We believe that failure to do so will contribute to the substance of the Open-Ended Working Group discussions, eventually decreasing the relevance of the discussions in the global era. Let me, on behalf of the EU and its member states, express our full commitment to continue working with the multistakeholder community to advance the objectives of a global, open, free, stable, and secure cyberspace, including through the discussions in the UN Open-Ended Working Group. Thank you.
Ambassador Gafoor
Thank you, European Union. Your comments are very much well noted. I now give the floor to the Russian Federation, please.
Russia
Distinguished Chair, distinguished colleagues, we welcome all participants to the fourth session of the Open-Ended Working Group on security of and in the use of ICTs. The rise of threats and instability in the global information sphere underscores as never before the need for joint work of states to bolster security in the field of ICTs. To this end, the professional expert dialogue of this group was established. During the first year of the OEWG’s work, we already have been able to achieve important outcomes that are enshrined in the consensus-based progress report of July 29, 2022. This document’s recommendations allow us to make progress for the strategic goal of crafting an international legal regime in the information sphere and developing tangible measures for confidence-building and cooperation. However, one gets the impression that not all participants of this negotiation process understand the importance of these efforts. Once again, the U.S., without justification and in a provocative manner, has refused to issue visas to certain members of the Russian interagency delegation. The same measure was earlier used against the head of the delegation. This is an egregious violation of Washington’s obligations to host and facilitate the work of the UN headquarters. Our representatives in the OEWG are known as competent, results-oriented negotiators. They enjoy the trust of their colleagues and the chair of the group. It is no secret that Russia initiated the establishment of the OEWG and contributes constructively to its work. Hampering the participation of delegations in the group’s work essentially undermines the principle of sovereign equality of states, one of the key principles of the UN Charter. As far as we know, the practice of non-issuance of U.S. visas has been used against other delegations as well. As a result, member states of the UN are on an unequal footing in this process of negotiations. The U.S. essentially is affecting the composition of national delegations. Despite these obstacles they’ve created, we are certain that all participants of the OEWG can see who truly wishes to develop universal solutions and who is prioritizing participation in the process and dirty tricks. The problem of non-issuance of visas is also being encountered by members of OEWG-accredited Russian NGOs. They are being prevented from taking part in person in the specialized NGO session. I’d like to ask the U.S. representative, what are they afraid of? What is the government afraid of when they deny visas to participants with consultative status? Are these actions really the norm for the so-called civilized world? In this regard, I’d like to turn to the chair and the secretariat of the UN and urgently request that they take measures to end this harmful practice. Our priority is to ensure true equality among the OEWG’s participants. In the context of the statement of Ms. Nakamitsu, I’d like to recall it’s unacceptable to politicize the discussions within the OEWG, especially on the part of such a high-ranking international civil servant. The group has a clear mandate enshrined in G-Resolution 75-240 and the proposed agenda and program of work put forward by the chair, which we just supported. Based on this, we believe that the OEWG should continue its important work in a professional and non-politicized tone. As for the statement of Canada, Ukraine, and the EU on the participation of the NGOs in the work of the OEWG, the decision of participation of non-state entities in the group is the sovereign right of states. Russia has carefully examined all applications for accreditation by other interested parties and will continue to carefully study them in the future. Our position for every candidacy was put forward after a careful analysis of evidence about the activities of these non-state entities. We base ourselves first and foremost on the criteria of professionalism, technical expertise, willingness to engage in non-politicized dialogue, compliance with the mandate of the OEWG, and the added value for interstate discussions. Unfortunately, many so-called independent representatives of non-state entities often distort the facts and arrive at convenient conclusions. In other words, they are carrying out political commissions. We believe that these pseudo-experts are not appropriate to have in the OEWG. Taking part in this negotiation process within the UN and other international bodies should be prevented in the future as well. We note that before the fourth session of the OEWG, the applications of all Russian organizations were denied without explanation of any reason. In addition, the host country of the UN headquarters once again refused denied visas to already accredited experts under Russian NGOs. We view this as an appalling attempt to cut off our country’s scientific and academic community from discussions of the OEWG. This is a community that needs the necessary expertise in the area of international patient security. We urge the chair and secretariat of the UN to take the necessary measures to end this wrongful discrimination from the U.S. Thank you. Thank you.
Ambassador Gafoor
Thank you, Russian Federation, for your comments, and your comments are well noted. I see Belarus has asked for the floor. You have the floor, please.
Belarus
Thank you so much, Distinguished Chairperson. Just to make a brief remark, ladies and gentlemen, distinguished colleagues, the global discussions on international information security are growing in importance. The report of the OEWG demonstrates the effectiveness of negotiations on the issue of cyber threats and shows the interest of the vast majority of parties in dialogue and compromise. However, the real picture of the discussions demonstrates major divergences in viewpoints, as we see in this room today. We are forced to note the lack of consensus between key actors when it comes to the use of cyberspace and information security in the world as a whole. We ought to note that the open nature of the OEWG does not in and of itself guarantee the speedy resolution of global ICT threats. There are remaining disagreements with regard to how international law ought to be applied to cyberspace. Unfortunately, new restrictive measures are not being proposed for cyber information carried out beyond state borders. There is a lack of progress in adoption and implementation of rules, norms, and principles of responsible behavior of states or on controversial issues such as the applicability of international law to ICTs. We also are concerned that for sensitive issues, these will be discussed in a narrow circle and the dialogue on these issues will remain fragmented. We believe that the experience of regional associations is not being used efficiently. And we’re making a statement on behalf of the presidency of the CSTO. Discussions on the topic of information security have become more complex and multilayered, and yet cyber diplomacy over the past few years has shown a positive trend. There have been successes of the OEWG through its reports, which demonstrate the understanding of all stakeholders of the great need for this kind of compromise. Therefore, we support the Russian Federation’s conceptual note. Certainly, the advantage of the OEWG is the broad support for its mandate as laid out in the G resolution. However, the current environment will require more tangible results from the OEWG, the importance of a comprehensive solution, and consensus through country negotiations. Belarus highlights the importance of two aspects: capacity building in the sphere of ICTs and full coverage of legal regulations for gray areas in international law that should be applied to ICTs. And secondly, we should not allow the automatic application of international humanitarian law to ICTs in times of peace because ICTs do not fall under the definition of weapons.
Ambassador Gafoor
I think we are not yet in the substantive agenda items. We are still on the issue of stakeholder participation and other issues. So, can I invite you to revisit your statement? That was the end of my statements, Mr. Chairperson. Thank you so much for the attention. Thank you very much, Pilares, for your statement. It is also very much well noted. I don’t have any other requests for the floor, and I certainly am not going to make a summary. But I do want to say that I have taken careful note of the remarks and comments that have been made, and so has the Secretariat. But just to offer some reflections. First, it is quite clear that on the issue of stakeholder participation, this has been one of the most challenging issues that we have dealt with in this Open-Ended Working Group. But the good news is that we have made some progress. There is a long way ahead and more progress that needs to be done, but we have made some progress, even if the progress we have made is not entirely sufficient for where we need to go. Second, it is quite clear that this is an area where we need to continue our bridge building and confidence building and trust building. Therefore, I would like to invite all of you, all representatives of delegations, but also all representatives of the stakeholder community and the NGOs who are present here, but also those who might be following the discussion virtually, to continue your contacts and engagement with a view to building trust, building confidence, as well as building convergence in this Working Group. I also want to remind delegations that this Working Group operates under agreed modalities for the participation of stakeholders, and we have a set of modalities which does envisage the use of the non-objection procedure. But the modalities also encourage Member States to utilize the non-objection mechanism judiciously, bearing in mind the spirit of inclusivity. So I encourage all delegations that might have availed themselves of the non-objection procedure to reflect carefully on how such a modality can be used in future, bearing in mind the need to have inclusivity in the process. Finally, let me also say that the issue of visa remains an important one. It is an issue that does come up, not just in this Working Group, but it is an issue that comes up in various different UN meetings. And as the Chair, it is also my expression of hope that this issue can be addressed and visas can be issued in a timely manner, because if we really, truly want to engage in this spirit of inclusivity, it is important that we have all representatives at the table present. Even if the representatives at the table may have a different view, it is important that we engage and talk with them, which is what the United Nations is about, engaging and talking, dialoguing and discussing, in order to build trust, confidence, not to mention confidence. Now, on that note, I’d like to now ask, or rather draw your attention, to document the list of non-governmental entities which has been updated. There are 77 non-governmental entities who have received approval to participate in the current session, and that updated list has been made available to all of you, and may I take it that the Open-Ended Working Group approves the attendance of the non-governmental entities contained in Document A/AC.292/2023/INF.1, with the list of 77 non-governmental entities having received approval to participate. I see no objection. It is so decided. Distinguished Delegates, we have completed the initial aspects of the program of work. Now it is time to go into Agenda Item 5, which is the discussion on substantive issues. And looking at the clock, I do want to give a little coffee break, also in the spirit of allowing each one of you to reconnect and build confidence, and each one of you should go up to someone you have never met before, introduce yourself, and say that you look forward to working with them, and that includes the NGO community as well. So on that basis, coffee break for 10 minutes, we resume at 11:30. Thank you.
Sri Lanka
Thank you, Mr. Chairman. Like many technologies at our disposal, ICTs are dual-use technologies, but with the capacity to affect positively or negatively all three pillars of the United Nations and thereby all walks of life, so to speak. Therefore, building digital trust and security lies, in our view, at the core, as you quite rightly observed, of the efforts to reap the benefits of the digital domain and utilize it for development gains, including the 2030 Agenda. Mr. Chairman, since the last session of the OEWG, the destabilizing trends in cyberspace have seen no mitigation or signs of abatement. The increased digitalization and reliance on the digital sphere for the delivery of services and connectivity due to restrictions of COVID-19 in all countries, including ourselves, Sri Lanka, have resulted in the rise in the threat volume and high-profile cyber attacks. The cyber dimension of gender-based violence, I must mention it, is evolving worldwide and obstructing few affirmative actions being taken to bring together the gender question, the question of equality with regard to gender. The most severe form of gender-based discrimination now employs technology to inflict harassment and prejudice, and this must be addressed. Such activities disproportionately against women, based on their gender, are detrimental to establishing gender equality in society. State governments have therefore policies to address gender-based violence and maintain gender equality, but they are not applicable to gender-based cyber violence. Even the developed nations, we see, have failed, some of the developed nations, have failed to address online gender-based violence on a legislative level. It is expected, Mr. Chairman, that cyber security threats will continue to grow and evolve in frequency and complexity. In promoting a common understanding of existing and potential cyber threats, Mr. Chairman, there is a need, I say, to bring national and global policies in the regulatory environment in the use of information and communications technology. Sri Lanka emphasizes, therefore, the need for proactive, cooperative measures on cyber security risk mitigation to face these evolving challenges. Domestically, we have launched capacity-building programs, systems for early identification, and resolving attempts at hacking, improving cyber emergency response teams, the CERT functions within the country, and implementing cyber security frameworks. Finally, in collaboration with our international partners in combating threats, we are pleased, Mr. Chairman, to be part of the Budapest Convention on Cybercrime, which allows for information sharing and sharing experiences. It is important, I say, that we continue to strengthen stakeholder cooperation globally to enhance sharing of information among states on security incidents for timely response, recovery, and mitigation actions, including through the exchange of information through the national CERTs. We believe that the proposed global point of contact directory will be yet another step in the right direction, although the exact modalities are yet to be worked out, and I believe that that will be addressed sooner than later. I thank you, Mr. Chairman.
Ambassador Gafoor
Thank you very much, Sri Lanka, for that statement to get us going. I now give the floor to the Russian Federation, to be followed by Portugal. Russian Federation, please.
Russia
Mr. Chair, distinguished colleagues, for most countries in the world, the security of information resources is of critical importance. In this regard, the use of ICTs for purposes that run counter to the UN Charter may cause interstate conflicts. This is due, first and foremost, to the possibility of disproportionate use of response measures to threats. The situation is aggravated by the possible use of computer attacks under a false flag to hold another state responsible. In the absence of a universal methodology for identifying perpetrators, as well as criteria for classifying computer attacks as an armed attack, and principles for investigating computer incidents, the adoption of any political decisions on the security of ICTs may pose additional risks to international peace and security. The international community needs to conduct an in-depth discussion and analysis of the entire set of factors that contribute to the escalation of threats, including the anonymity of actions in information space. The Russian Federation believes there is a need to develop within the OEWG measures to counter the following threats to information security and factors that affect it. First of all, using ICTs by states in military and political, as well as other spheres, to undermine or infringe upon the sovereignty of—violate the territorial integrity, social and economic stability of sovereign states, to interfere in their internal affairs, as well as to commit other acts in global information space that impede the maintenance of international peace and security. Secondly, carrying out computer attacks on the information processes of states, including critical information infrastructure. Third, monopolizing the ICT market—this is done by individual states and/or with their assistance by private companies by restricting access to advanced ICTs to other states, and increasing their technological dependence on states that dominate in the field of informatization, as well as expanding the digital divide. Fourth, the unsubstantiated accusations leveled by some states against others with regard to organizing and carrying out wrongful acts using ICTs, including computer attacks. Fifth, the use of information resources under another state’s jurisdiction without the approval of the competent bodies of that state. Sixth, placing in the information space of states free, accessible tools for computer attacks, instructions on methods of their organization, coordination, and development of practical skills to use these tools in order to carry out computer attacks. Seventh, using ICTs to the detriment of fundamental human rights and freedoms in information space, especially the right to privacy. Eighth, integrating undeclared capabilities in ICTs and the concealing by manufacturers of information on vulnerabilities in their products. Ninth, the use by states of their own information infrastructure to commit internationally wrongful acts, as well as using proxies by states, including non-state actors, to commit such acts. Tenth, disseminating information through ICTs that is detrimental to the socio-political and socio-economic foundations, the spiritual, moral, and cultural environment of states, and information that threatens the lives and safety of citizens. Eleventh, the inability to precisely and accurately identify the source of computer attacks aimed at committing wrongful acts caused by the specificities of ICTs and the lack of institutional mechanisms to ensure de-anonymization in information space. To counter these threats, it is important to work toward developing a global information security system under UN auspices in accordance with the provisions of GA Resolution 77-36. Such a system should be built on the basis of respect for the principle of equal security of parties and peaceful settlement of interstate disputes arising from the use of ICTs. Among the individual topics that deserve attention, we would like to focus on the protection of personal and other data. The definition and subsequent approval of the principles for processing personal data that would be the only one used for all UN member states will increase the level of protection of personal data in cross-border exchanges. It will also contribute to the development of legislation in the field of personal data protection in states where such legislation is not yet sufficiently developed or is completely absent. Thank you.
Ambassador Gafoor
Thank you very much, Russian Federation. I would also invite those delegations that speak to send my team your text of your remarks so that we can study them closely. I would now like to give the floor to the European Union before Portugal, if Portugal doesn’t mind, because I understand the EU is making a statement on behalf of a group of states. So, European Union, please, you have the floor.
EU
Thank you, Mr. Chairman. I have the honour to speak on behalf of the EU and its Member States. North Macedonia, Montenegro, Albania, Republic of Moldova, Georgia, Bosnia and Herzegovina, Iceland, as well as Monaco aligned themselves with this statement. Previous UNGGE reports, as well as the previous Open-Ended Working Group reports, made useful descriptions of the ICT threat environment. However, the ICT threat landscape continues to evolve rapidly, and malicious behaviour in cyberspace increases at a speed that we, in this format, find difficult to keep up with. It is increasingly difficult to demarcate civilian and military dimensions of cyberspace, as seen in the recent attacks on energy networks, transport infrastructure, and space assets that also have a military function. This increases the escalatory potential of malicious cyber activities. The fact that there are countries that are willing to act in violation of the Normandy framework constitutes a threat in itself, just as the differentiation in capacities to counter cyber threats between Member States. More needs to be done to address cyber threats, which is why we must, first of all, start with the threat section that adequately reflects the current threats in cyberspace. We cannot deny that some state actors continue to undermine the international rule-based order in cyberspace. By conducting malicious cyber activities, as well as using proxies, and contrary to the norms of responsible state behaviour, they allow criminal groups to further destabilize cyberspace. Ransomware continues to be one of the top cyber threats, not only for Europe but for all, costing the world around 20 billion euros in damages globally. The destructive nature, financial viability, and ease of deniability of ransomware make it an attractive tool for the whole range of threat actors to utilize. Finance, education, industrial, and even the healthcare sector, as shown by their remorseless targeting in the EU and partners during the pandemic, tend to be ransomware attackers’ primary targets. And the EU is not alone, as shown by last year’s ransomware attacks experienced by Costa Rica. After a month of crippling ransomware attacks, Costa Rica declared a state of national emergency to respond to these criminal acts. Conventional security threats like ransomware, phishing, supply chain attacks, and even deliberate cyber attacks against humanitarian organizations or food and agriculture cooperatives that have become prime targets during the critical planting and harvest season will continue to exist as cyber criminals become more prolific. All countries will need to be on alert to address this ever-evolving landscape. The work of the International Counter-Ransomware Initiative supports the implementation of the agreed-upon UN normative framework for responsible state behavior in cyberspace, specifically the norm that states should cooperate to exchange information, assist each other, prosecute terrorist and criminal use of ICTs, and implement other cooperative measures to address such threats. The joint efforts of the Counter-Ransomware Initiative partners are also directly contributing to the implementation of the consensus conclusions and recommendations of the UN expert group to conduct a comprehensive study on cybercrime. The EU and its Member States see an opportunity for the Open-Ended Working Group to take stock of this work and formulate our common position. We also welcome states to join the cooperation against ransomware. Secondly, the EU and its Member States are concerned about the increased use of so-called wiper attacks. The North Korea attack in 2017, which devastated Ukrainian businesses, was in the end a wiper attack that encrypted computers irreparably and spilled over into other countries, causing 10 billion in damages worldwide. We see an increased willingness to destroy systems, which is a worrying trend in malicious behavior. Analysis of the Russian cyber warfare tactics used in Ukraine over the past year has identified links between conventional and cyber operations. Russia’s digital assault against the Viasat network was carried out an hour before the invasion of Ukraine to pave the way for its assaults. One year on, it is no longer possible to always separate cyber attacks from the conventional aspects of Russian aggression. Since the attacks have failed to deal a critical blow to Ukraine’s digital infrastructure and its cyber resilience, Ukrainian experience in countering these cyber threats can provide valuable lessons for the international community while offering a glimpse into a future where wars will be waged both by conventional means and increasingly in cyberspace. While we agree that it could also be useful to discuss potential future cyber threats that might affect the threat landscape and relations between states in the coming years, it is crucial to try to reach a common understanding of the current cybersecurity threat landscape. With the cyber landscape in constant evolution, the need for updated and accurate information on the current situation is growing. The Open-Ended Working Group is well positioned to help and support countries and stakeholders with timely information for policy creation, decision making, and applying security measures, as well as in increasing understanding, knowledge, and information of the cybersecurity challenges related to new technologies. Thank you.
Ambassador Gafoor
Thank you, European Union. Portugal, to be followed by Kenya. Portugal, please.
Portugal
Mr. Chairman, the insecurity in cyberspace has increased once again in 2022, in spite of international and national efforts to render critical infrastructure more resilient and to advance a framework for responsible state behavior on the one hand, and an international regime against cybercrime on the other hand. Last year, Portugal registered very serious incidents, either from hackers who apparently just wanted to compete among each other in exposing vulnerabilities, from criminals who wanted to collect ransom from flagship companies, or from state-sponsored actors who wanted to extract data from government institutions. We are therefore very grateful for your personal efforts to bring us together once again to cover as much ground as the international situation affords in order to reach common understandings about the application of relevant international law and norms to cyberspace in order to decrease insecurity. In this respect, we are of course in full alignment with the European Union about the strong impact on peace and security in cyberspace of the callous and inexcusable invasion of Ukraine by Russia in flagrant violation of international law. The approval end of last year by an impressively qualified majority of a resolution asking the Secretary-General to submit a report on a Program of Action to eventually succeed the current Open-Ended Working Group after 2025 has made it fully clear that the First Committee wants our work to be fully anchored on implementation. We hope that the regional consultations that have already been scheduled by UNODA in that regard will be participated at the highest level of all interested parties, as happened with the regional consultations that led to the very fruitful work of the sixth GGE and the first Open-Ended Working Group. Indeed, the wide interest raised by the initiative to create a global directory of political and expert national points of contact as a basic prerequisite for comprehensive international cooperation on capacity building is in itself a very promising signal that the time is ripe for moving on resolutely to implementation of the framework for responsible state behavior. At the same time, we hope as well that the current negotiations on a legal framework to combat cybercrime will be successful already this year, because so many times criminal entities have links with official entities which must be weakened and eventually severed through a concerted international effort. Exponential digitalization of national critical infrastructure and exciting technological developments and their fast dissemination in all directions of collective and personal life, like artificial intelligence and quantum computing applications, demand from us a steady work on countering insecurity through further codification and cooperation, which I’m sure this group will continue to achieve under your chairmanship. Thank you, Chair.
Ambassador Gafoor
Thank you, Portugal. I now give the floor to Kenya, to be followed by the Philippines.
Kenya
Thank you, Chair, for giving me the floor. Excellencies, dear colleagues, capacity building, including trainings on risks associated with ICT and how to mitigate them, must remain a central component in our discussions on the specific objectives of the POC Directory, in alignment with the mandate of the OEWG and the Consensual First Annual Progress Report. Once the envisioned POC is agreed upon and operationalized, it will serve as a confidence-building measure and an essential platform for cooperation and risk management. The POC would also serve to reduce tensions, misunderstandings, and misperceptions arising from ICT incidents, including the misuse of emerging technologies such as artificial intelligence, AI-enabled technologies like drones and robots, and cloud-based infrastructure. Malicious cyber-threat actors exploit these technologies using malware, ransomware, distributed denial-of-service, and crypto-jacking attacks, which compromise container-based cloud systems, restrict access to services, expose restricted data, and enhance backdoor attacks. We are currently seeing an increase in the exploitation of threat vectors related to information, including misinformation, disinformation, and malinformation, and their implications for national, regional, and international peace and security. We appreciate the efforts of the international community to cooperate and collaborate in addressing existing and potential threats to information and data security. To deepen our understanding of the potential risks, the international community should consider establishing a repository of common threats, vectors, and actors that members can regularly update in the face of new and emerging threats. Within the framework of the OEWG, the international community can further support states to mitigate against new and emerging ICT threats by enhancing broad multistakeholder conversations and forge partnerships with technology providers to have a security design that factors in geocultures whose preservation is important in maintaining regional security. In its quest to secure its digital space, Kenya has, amongst others, established the National Kenya Computer Incident Response Team, implemented the National Public Key Infrastructure, and recently inaugurated the National Computer and Cybercrime Coordination Committee, comprising relevant ministries and agencies with a fully-fledged secretariat to ensure effective implementation of decisions. Colleagues, the nature of emerging technologies, including their ubiquity, programmability, and data-driven nature has also opened the door for misuse by cyber threat actors, including armed groups and terrorists. Kenya strongly urges global collaborative efforts in combating violent extremism and terrorist activities in the ICT ecosystem. More must also be done to assist states in their efforts to deal with the challenges associated with the increased levels of digitization, use of cryptocurrencies, and miniaturization of devices that have led to increased anonymity in Internet and network accessibility, especially with unregulated technologies. Additionally, adequate resource allocation and recognition of cybersecurity as a key pillar to economic development will ensure that security threats are addressed adequately and comprehensively. Noting that most countries are technology consumers, we urge enhanced global collaboration to ensure that the media platforms, especially the social media, remain safe for our children and vulnerable groups. I conclude by reiterating our call for practical support for efforts to establish programs and mobilize resources to unlock greater access for developing countries to ensure that no state is left behind. One such initiative is the UN Women in Cyber Fellowship, of which Kenya is a beneficiary. I thank you.
Ambassador Gafoor
Thank you very much, Kenya, for your statement. I now give the floor to the Philippines, to be followed by Denmark. Philippines, please.
Philippines
Thank you for giving me the floor, Mr. Chair. Thank you again for your leadership and for steering us in the work of this OEWG. We thank your team and the Secretariat as well for their hard work. For my delegation, the guiding questions you sent in advance have helped my delegation be more focused on the specific issues and concerns to put forth under each of the agenda items we’re discussing this week. On existing and potential threats, the Philippines, like many developing countries, is still struggling to develop greater cyber defense capabilities. We suffer from a low number of cybersecurity professionals, leaving the nation vulnerable to attack. If attacked, we need to enhance and expand our pool of information and communications technology experts, especially in the law enforcement and defense sectors. We could also benefit more from greater collaborative efforts with academia and the business community to achieve cyber resiliency, effective law enforcement, and a cybersecurity-educated society. For these reasons, it is a challenge to map out existing cybersecurity threats across our sectors, be it government, business, or at the individual level, and single out which threats are the most frequent, which threats have the most impact, and in turn, which threats need to be immediately addressed or potential threats that we should be most wary of. My delegation thus appreciates the conduct of stakeholder engagement last week and looks forward to our engagement with the stakeholders on Thursday. The Philippines listened carefully to the informal dialogue with interested stakeholders last week regarding this very topic we are discussing now, and we find the engagement extremely helpful. Some of the emerging threats that were raised during the discussion with stakeholders were artificial intelligence-powered cyber attacks, supply chain attacks, and the rise of cyber mercenaries, among others. We find these threats seriously alarming and thus relevant to our discussions in the OEWG. We wish to know more and appreciate the Chair’s efforts to bridge and create platforms for exchange between stakeholders and member states. We look forward to more similar engagements so that we can keep abreast of emerging threats, their evolving application, and the magnitude of these emerging threats. For my delegation, our primary concern is ensuring the security of critical ICT infrastructures, including information assets of the government, individuals, and businesses. The Philippines, like many others, is of the view that the cyber threat landscape is continuously evolving, and it is useful that the United Nations, as the universal and global intergovernmental organization, will take the lead in the discussions pertaining to cybersecurity that affects international peace and security. Mr. Chair, for my delegation, a cybersecurity repository under the UN auspices, which could include all relevant information we are discussing today and beyond, would help states in deepening their knowledge and provide up-to-date and readily available information on cybersecurity affecting international security. I just heard our distinguished colleague from Kenya mentioning the need for a repository of common threats. For instance, this repository could include cybersecurity incident reports from member states submitted on a voluntary basis that may have an impact on international peace and security. These reports possibly could capture existing and potential threats. The data that will be accumulated could serve as the primary basis, including the results of the National Survey of Implementation of UN Recommendations on Responsible Use of ICT in the Context of International Security, for creating capacity-building programs to be facilitated by the UN. We note that the survey already encompasses four elements – international law, norms, rules, and principles for responsible behavior of states, CBMs, and capacity building. Taking all these things together, this would be a rich, one-stop shop for all things under the umbrella of cybersecurity. The repository may also include the Global Points of Contact Directory, or a gateway or link to the POC Directory, which, for security reasons, could be designed for member states only. Or it could be the General Information Purpose Public Page, providing an overview of the POC Directory’s mandate as captured in the Chair’s revised elements paper. In addition, this OEWG could learn from existing repositories, such as the Cybercrime Repository under the UN Office on Drugs and Crime, which even features a lessons learned database containing national practices and strategies in preventing and combating cybercrime. Depending on our needs, we can explore developing something similar. We could also explore the possibility of taking advantage of the already existing cyber policy portal of the UN Institute for Disarmament Research, UNIDIR, expand and/or rationalize it, and help build this portal in a way that could serve the purpose of the OEWG. Mr. Chair, we are of the view that continued exchanges with stakeholders in the form of dialogue, roundtable discussions, briefings, and research projects, among others, would help member states be well informed of the discussions happening on cybersecurity matters in the context of international security. We again express appreciation for the Chair’s efforts in creating more opportunities for such exchanges. You can count on the Philippines’ participation and engagement on this front as we contribute to this process to the fullest. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Philippines, for your very detailed and focused statement. I also welcome the fact that you had responded to an idea that was previously proposed by Kenya with regard to the idea of a repository of common threats. I would encourage delegations to respond and react to other ideas or suggestions that other speakers might have made, so that way we begin to get a sense of at least initial views on some of the ideas that are already emerging, and I’m very satisfied with the discussions so far. So let’s continue with the speakers list. I have Denmark to be followed by Argentina. Denmark, please.
Denmark
Thank you, Chair. I have the honor of speaking on behalf of the Nordic countries: Finland, Iceland, Norway, Sweden, and my own country, Denmark. We fully align ourselves with the statement delivered earlier by the European Union, and in my national capacity, I would also like to align myself with the statement made earlier by Canada in relation to the openness of the blocking of multistakeholders. I wish to start by thanking the Chair for expertly facilitating discussions in this Working Group with a view to also producing concrete results. Our delegations remain ready to constructively engage in the Working Group to ensure its continued success and promote a free, open, and secure cyberspace. An accurate description of the threat picture that we are faced with in cyberspace is a prerequisite for our work. We must know the threats to counter them. While it is useful to look ahead and discuss potential threats based on new and emerging technologies that we may face in the future, our first priority must be to address the threats that we know. Moreover, while significant progress has been made in the UN and in other multilateral fora, it should be clear to all that malicious cyber activity continues to increase in scope and complexity. Russia’s illegal invasion of Ukraine illustrates this in real time. Russia’s cyber capabilities have been weaponized in Ukraine in an attempt to undermine trust in authorities and to destroy critical functionalities. We commend Ukraine on its digital resilience that has withstood Russia’s malicious cyber operations. The Viasat case set cyber attack by Russia only hours before the start of the full-scale invasion of Ukraine showed how cyber attacks in a war zone can have spillover effects in other countries. The attack had a significant impact on the critical infrastructure of several EU member states and affected both the internet connectivity of citizens and the energy sector. We condemn Russia’s illegal invasion of Ukraine, and we condemn Russia’s irresponsible use of cyber attacks that destabilize cyberspace to the detriment of us all. Ransomware is a major threat to both private businesses and governments. Ransomware costs the world billions of euros each year and is a major threat to the provision of public goods. We have in past months seen major ransomware attacks in critical infrastructure that have highlighted how this type of cyber attack has the potential to carry grave consequences for the access to, for example, clean water, electricity, and basic government services. Furthermore, developments in the past few years have shown that global value chains can be fragile. The breakdown of certain supply chains to the health sector impeded our efforts to battle the COVID-19 epidemic and showed how disruptions of global supply chains can directly affect the health of our citizens. It should be clear that cyber attacks have the potential to disrupt global value chains, which can carry great consequences for the health and security of our citizens. Finally, we would also like to highlight cyber attacks targeting democratic institutions and, in particular, elections infrastructure. The digital infrastructure that underpins democratic processes is essential to the functioning of democratic society and is thus critical to our security. Thank you, Chair.
Ambassador Gafoor
Thank you, Denmark. I give the floor now to Argentina, to be followed by Greece. Argentina, please.
Argentina
Thank you very much, sir. As this is the first time that the Argentine delegation is speaking during this debate, we would like to thank you for your dedication to the work that we’ve been doing since 2021 in fulfilling the mandate of the Open-Ended Working Group (OEWG). The Argentine delegation supports your commitment to achieve tangible results in the context of this working group, and we agree with your vision that the directory for focal points could be helpful in that regard. We look forward to an enriching debate on Wednesday that might help us with setting up that directory. Argentina attaches importance to having a free, global, open, stable, and secure cyberspace, and it should also contribute to the social, economic, and political development of our countries. Moreover, working towards a resilient cyberspace is important given the threats to international peace and security we are currently facing. For Argentina, which is a country that promotes the idea of robust multilateralism, the only way to achieve this goal is through collective solutions. In that context, we reiterate the importance of maintaining an inclusive forum for states and representatives of civil society, academia, the technical sector, and the private sector in order to work together to consolidate and come to agreements, tools, and capacity for the responsible use of ICTs and to have greater predictability and stability of cyberspace. To answer your questions with regard to the guide, sir, we’d like to work with more direction with the private sector with the corresponding modalities that might help to evaluate the impact of new technologies and new threats in cyberspace. A specific example of that might be cooperation relating to intelligence on threats. We think it would be necessary to have more cooperation among states. Generally speaking, countries should reach out to the private sector to have more information about upcoming threats and to ensure their commitment to assisting us. Also, they have worthwhile contributions to make in terms of updating the compendium on threats over time. Creating international cooperation and greater interaction with the private sector in this area would be a tangible and concrete benefit for all. Moreover, with regard to your question on the specific needs that member states might be able to identify for the implementation of the framework and development of the infrastructure to that end, we believe that for developing countries it’s key to develop capacity in the technical area and in cybersecurity. And here I’d like to open a parenthesis to say that in a few days we’ll be celebrating the International Day of Women. In that context, we have the legal framework for women that’s being examined at the United Nations right now. I should like to refer to access to ICTs for women more specifically. The National Institute of Statistics in my country has seen that 90 percent of those applying have access to the internet and 64 percent of Argentine families have a computer at home. However, women account for only 30 percent of the development of software and information services and programming. At the same time, of the few women that start their studies in careers related to science and technology or communications, only a small percentage finish their studies and very few come out with a degree. Our investigations show on a preliminary basis that women leave university usually in the third year of their studies. With that, sir, we’d like to reaffirm that closing the digital divide both for the use and access and production of ICTs will further develop human resources in the public and private sectors and will help to develop policies and infrastructure for cyberspace to have an open cyberspace that’s secure. Especially, it will contribute to improving the economic empowerment of women. In that context, I’d like to take this opportunity to thank the Women in Cyber Fellowship and all the donors who help promote greater participation in these debates. That initiative is very important for us. Finally, sir, Argentina believes that the main threats that we need to grapple with in our country are not necessarily about what’s happening in the rest of the world. There’s a global nature to cyberspace and there’s a transnational reach to all the threats. So we think that’s one of the main issues we need to address. Working with the European Union, Kenya, and other countries, we think like them that ransomware is a huge threat and we need to address that, especially the use of extortion in this regard. We need to be building capacity amongst states in order to have the ability to respond to these threats and help our societies respond to them. We need to strengthen international cooperation inter-regionally and within regions to that end to develop capacity and build confidence measures in these areas in order to address the various threats mentioned by Kenya, which Argentina supports. Thank you.
Ambassador Gafoor
Thank you, Argentina. Greece to be followed by the United States. Greece, please. Microphone for Greece, please.
Greece
Yes, thank you very much, Mr. Chairman. Greece fully aligns itself with the statement made by the EU delegation and wishes to make the following additional comments in a national capacity. First of all, I would like to thank you and your team for all your efforts supporting this group and becoming a catalyst for discussion to move forward. The guided questions were really a point of useful reflection for all of us. We also welcome the work done so far in order for the newly agreed-upon group and points of contact directory to materialize. As we all know, security and stability in cyberspace is a global challenge that requires international engagement, collaboration, and coordination among all stakeholders in order to preserve a functioning and stable cyberspace, foster open societies, and enable economic growth and social development globally. With this in mind, Greece is highly committed to further discussion in the UN on the issues of security and the use of ICTs, and we affirm our willingness to engage positively in an effort to make constructive progress. Such progress includes not only moving forward in the discussion of new norms, rules, principles, and CBMs but also continuing to implement the already agreed-upon framework of responsible, safe behavior and expanding capacity-building efforts. We believe that the future Program of Action will also play an extremely important role in this regard as an action-oriented mechanism monitoring the implementation of agreed-upon norms as well as supporting states’ international implementation efforts. These efforts are imperative considering that there is a continuous rise in the malicious use of ICTs, especially after Russia’s unprovoked aggression against Ukraine, increasing the risk posed to international security, stability, human rights, freedom, democracy, and sustainable development. From our side, this past year was highly constructive as we have been actively contributing to a variety of cyber capacity-building efforts both bilaterally and multilaterally. These efforts include cooperation with the Western Balkan partners, the European Union, our partners in the Eastern Mediterranean region, and across the Atlantic in the development of legislation, third-to-third cooperation, the exchange of best practices, cooperation during cyber incidents, and further development and resilience in sectoral infrastructures such as the energy and maritime sectors. Finally, I would like to reiterate that Greece is working towards a global, peaceful, secure, open, and independent cyberspace governed by international law where human rights and fundamental freedoms and the rule of law fully apply with a view to the well-being, economic growth, prosperity, and the integrity of free and democratic societies. Thank you so much.
Ambassador Gafoor
Thank you very much, Greece. Ambassador, for your presence and statement. I now give the floor to the United States, to be followed by Slovenia. U.S., please.
United States
Thank you, Chair. Last year’s APR highlighted that cyber threats continue to intensify. We believe the OEWG needs to delve deeper into this topic, as there are a number of emerging cyber threats that warrant our attention. Foremost among those threats is the fact that we are currently witnessing the reckless use of cyber capabilities in the context of an ongoing armed conflict. The deployment of cyber operations that produce disruptive effects in third countries that are costly to remediate is not responsible state behavior. In the early months of Russia’s premeditated, unprovoked, and unjustified war against Ukraine, Russian state-affiliated cyber actors launched numerous offensive cyber effects operations to destabilize the Ukrainian state and military, targeting the Ukrainian power grid and satellite communications. As the further invasion continued throughout the summer and autumn, Russian and Russia-aligned cyber actors continued to target Ukraine with DDoS attacks against the public and private sectors, disinformation and online influence operations, and attempts to divert and censor Ukraine’s access to the internet. Separately, last year we witnessed one of the most damaging peacetime cyber attacks in recent memory, when the government of Iran conducted a reckless and irresponsible cyber attack on Albania that destroyed government data and disrupted government services to the public. Separately, the DPRK has engaged for years in malicious cyber activity to advance its unlawful weapons of mass destruction and ballistic missile programs. As the 1718 Committee Panel of Experts reported in its 2022 midterm report, this includes theft of both cryptocurrency assets as a source of funding and information and materials of value for advancing its unlawful military program. These behaviors disregard the framework member states have worked to uphold. This type of activity can have cascading domestic, regional, and global effects and pose an elevated risk of harm to the population. We also continue to believe the annual report should acknowledge the rising threat of ransomware, the increased risk of escalatory or uncontrolled cyber activity, the cyber threats now faced by humanitarian actors, and the risks posed by cyber criminals who are allowed by certain states to operate with impunity from their territory. It is vital that our group address these current and emerging threats. Finally, we recognize that non-state stakeholders, including vetted entities, some of whom are leaders in their fields, can have important expertise that could help the OEWG in its work. We agree with the Philippines, Argentina, and others that member states can gain valuable insights from these stakeholders, particularly in the area of emerging threats, and those interactions should be enhanced. Thank you, Chair.
Ambassador Gafoor
Thank you, United States, for your statement. I give the floor now to Slovenia, to be followed by El Salvador. Slovenia, please.
Slovenia
Thank you, Chair. Slovenia aligns itself with the statement of the EU, and I would like to make some additional points in my national capacity. Chair, I will focus on the question of what concrete specific initiatives states and other interested parties can undertake within the framework of the Open-Ended Working Group (OEWG) to mitigate the impact of new and emerging ICT threats on international security. Chair, Slovenia is promoting the development of mutual understanding of existing and potential threats in the sphere of information security, with a focus on new vectors and vulnerabilities that can be exploited for malicious ICT activity. Slovenia is encouraged and motivated to contribute to finding ways to mitigate new and emerging threats. To mitigate the impact of new and emerging ICT threats on international security, Slovenia calls for consideration of building models of an adaptive regulatory framework, which can be based on knowledge sharing of existing, potential, and evolving security risks in ICT with cutting-edge companies. The proposed models, such as the one of adaptive regulatory governance that integrates the benefits of centralized risk regulatory frameworks with operational knowledge and mitigation mechanisms developed by epistemic involving cognitive communities that manage day-to-day ICT security, can be put into practice. In other words, the idea is to combine the advantage of centralized risk regulation with the knowledge and mitigation strategies developed by various communities involved in managing daily ICT security. This approach is known as the adaptive regulatory governance model. To place it into practice, cognitive communities would be formed to manage ICT security on a daily basis. Furthermore, the standards and requirements of the existing regulatory framework should be dynamically updated to include the possible threats and potential risks of malicious ICT activity when new emerging technologies are being developed and even before their general use. Slovenia considers enhanced multistakeholder interaction and cooperation between the states as paramount to promoting international peace and security as we observe the increasing evolution of conflicts and incidents in ICTs. Multistakeholder communities are often placed in a unique position to aggregate security data to understand the scope, scale, and possibilities of ICT incidents around the globe. This allows multistakeholders, in turn, to share their unique insights on how the ICT threat landscape is evolving and what crucial actions can be taken to manage the risks. It is equally necessary to increase transparency and predictability to reduce tensions when it comes to ICT incidents. States and the international community have to build on commitments to apply rules to prevent emerging threats and the risk of new ICT activities. Chair, Slovenia believes that we can collectively develop a deeper understanding of new and emerging risks. To conclude, allow me to say that although the statement may be complex and challenging to comprehend, it underscores the significance of assembling a diverse group of individuals with diverse backgrounds and expertise to accomplish the objectives of the Open-Ended Working Group. Chair, I thank you, and you can count on our support.
Ambassador Gafoor
Thank you. Slovenia, El Salvador, please.
El Salvador
Thank you, sir. El Salvador is pleased to be participating in this fourth session of the Open-Ended Working Group in follow-up to the current threats and potential threats that are in the Annual Progress Report for 2022 and the discussions for the intersessional period which took place in December of 2022. And if I may, I would now like to address the following issues. As addressed in the report adopted by consensus, the threats and the use of ICTs and international security mentioned by the earlier working group and the Group of Governmental Experts continue to intensify, and they’re evolving quickly. In that regard, we agree with the statement that emerging technologies might in and of themselves represent new vectors of attacks and create new vulnerabilities. In keeping with this, deepening what’s been said by the Philippines with regard to emerging threats, we have all seen the qualitative leap of chatbots and artificial intelligence in recent months. For instance, conversations with AI that stem from language models based on automatic learning are considered an innovative form of AI, which is generative. And it’s interacting with this kind of chatbot, and we’ve seen the capacity they have to interrelate in a conversational manner with users and generate responses that are similar to those of humans to questions or indications in a variety of different formats. It’s also been noted that different industries are already starting to use AI operations that are generative for these tasks, simplifying and improving processes thereby and generating immeasurable benefits. However, as has been observed earlier with other emerging technologies, the possible harmful use of these or sophistication of them to create attacks are a source of concern. Cyber attacks have a tendency to increase in volume and complexity with artificial intelligence, which can also help to mitigate threats through the use of tools such as automatic learning and natural language processing, helping thereby to reduce response time, which is especially beneficial for small cybersecurity teams. Cognitive computation can strengthen AI and the use of human intelligence in order to make systems more intelligent in a gradual manner. This emerging technology is still learning and still enhancing its interaction with the world. The design will improve, and the responses will be increasingly accurate. As these become disseminated and used on a wide basis by the masses, we will have to make efforts to regulate some of their uses with a risk-based approach, as has been indicated in other spaces. It’s time to understand all of the impact of AI in the context of international security. But my country calls for greater analysis of regulation and prohibition of some of the risks specifically attached to AI capacity, as those that are also geared to the military and weaponry, which reduce, limit, or eliminate human intervention or control. In addition, as was addressed in earlier sessions, El Salvador would appreciate the upcoming report created by this group reflecting a specific mention of ransomware, which continues to be one of the greatest threats to the security of information and data, as was mentioned by the European Union, Kenya, Denmark, Argentina, and the United States, who spoke before me. The year 2022 was a year that was particularly challenging for Latin America because a number of critical infrastructures in the region were attacked by ransomware. To conclude, sir, my delegation would highlight the importance of continuing with these discussions on the threats that we face, taking into account the evolution of technology and ICTs. Thank you.
Ambassador Gafoor
Thank you very much, El Salvador. I give the floor now to Chile, to be followed by Germany.
Chile
Thank you very much, sir. For Chile, illicit activities in cyberspace are a clear threat to international peace and security. Chile believes that these threats can affect states in different ways, depending on the level of digitalization, capacity, security, and resiliency of ICTs in a given state, and depending on the infrastructure and development of that state as well. Threats can also affect other groups and entities in different ways, especially women and girls. That is why we believe it’s relevant to have states work together and exchange experiences, which help to reduce the digital divide and to grapple successfully with real and potential threats and make progress in terms of the correct use of cyberspace. As mentioned by the annual progress report, the properties and characteristics of new and emerging technologies also broaden the scope of attack, create new vectors for attack, and new vulnerabilities that can be used for harmful, malicious activities in cyberspace. In that regard, we can highlight here the use of artificial intelligence and machine learning, blockchain, the Internet of Things, virtual reality, cloud computing, and quantum computing, amongst other technologies. The extraordinary characteristics of these emerging technologies have broadened the scope of cyberspace, along with providing it with greater capacity. However, the expanded infrastructure of networks and the greater number of connected devices also mean greater vulnerability for illicit activities and intrusions. And in a similar way, the enormous volume of data which is processed and shared then becomes a more probable subject to attack and exploitation. In this regard, it’s key that states be able to create frameworks for cooperation and the exchange of information, meetings of technical bodies at the bilateral, multilateral, and regional levels. This needs to go hand-in-hand with work in a coordinated manner with the private sector and other interested parties. It’s also important to build greater capacity in the area of cyber intelligence and to create efficient mechanisms for the exchange of information, as well as for regulatory frameworks at the national level which are adequate to the job. Likewise, it’s key that states be able to have ongoing programs for training and building capacity for governmental issues. In this regard, we need to have ongoing programs. We especially need to do so for government entities. We must create coordination structures and plans for coordination, but not just at the government level. We also need to do so with civil society, the private sector, and academia, with whom we should develop effective partnerships. Thank you.
Ambassador Gafoor
Thank you, Chile. Germany, please.
Germany
Thank you, Mr. Chair, for convening us, and thanks to you and your whole team for the excellent preparation of this session. Germany is fully aligned with the statement of the EU and wishes to make the following remarks in a national capacity. Germany wishes to stress the central importance of today’s agenda item. The analysis of the existing threat landscape, as well as of emerging threats ahead of us, should be the anchoring point for the discussion in the Open-Ended Working Group, and the way we approach all other agenda items should be based on the understanding of the cyber threats the world community is facing. Germany would welcome seeing a much substantiated chapter on threats in the upcoming Annual Progress Report. For the present session, Germany would like to draw our attention to three kinds of cyber-related threats with a strong relevance for international peace and security: ransomware attacks against state institutions, spillover effects from international conflict, and risks associated with IT supply chains. In 2022, Europe experienced a number of grave incidents of ransomware attacks against state institutions, which have proven that actors using ransomware have the means to paralyze core functions of government at any level—local, regional, and national. In some instances, the ability of national institutions to perform key tasks was effectively paralyzed for weeks. In these extreme cases, cybercrime has a devastating impact on the functioning of states. These cases also have the potential to impact negatively on international peace and stability. While Germany acknowledges the progress made in the Ad Hoc Committee on Cybercrime in the preparation of a UN Convention, this Convention, if it can be agreed upon, would not be dealing with the impact of cybercrime on international peace and stability. This is an aspect that will need to be under consideration in the Open-Ended Working Group. Recent cyberattacks compromising global software supply chains, like the SolarWinds attack or Log4J incident, have exposed the high risks associated with the dynamic nature and complexity of these supply chains, which for any single software consist of a multitude of suppliers, often contributing from different states and regulatory environments. The 2015 GGE already acknowledged that states should take reasonable steps to ensure the integrity of the supply chain. How these reasonable steps could look in light of today’s challenges and which room there is for international cooperation and coordination is now being highlighted by an independent expert study prepared by a highly regarded German think tank, Stiftung Neue Verantwortung, whose participation in this Open-Ended Working Group has been vetoed. The preparation of the study has been supported with funds from the German Federal Foreign Office and went online last week. The study includes recommendations for multistakeholder dialogue on international standards setting and for international best practices for coordinated vulnerability disclosure. Germany is very concerned with Russia’s cyberwar against Ukraine, in particular its effects on the civilian population and the functioning of critical infrastructure. This is the first international conflict that is fought in a significant way by cyber means. The cyberattacks committed by the Russian Federation in its war of aggression against Ukraine misuse cyberspace in blatant violation of international law and the agreed UN framework of responsible state behavior to inflict damage on Ukraine’s population. It therefore appears completely unreal and absurd to hear the Russian delegation here today proposing to work out a global UN system for the peaceful settlement of cyber conflicts. It is difficult to imagine any UN member state with less credibility to bring forward such an initiative. Spillover effects from Russia’s war reverberate through German networks and continue to negatively impact IT infrastructure, including critical infrastructure in Germany. In addition to the concrete incidents that Germany had to deal with, we are seeing a considerably heightened level of volatility throughout German networks as a result of Russia’s malicious use of cyber instruments against Ukraine, with all the associated costs of keeping national cybersecurity at considerably heightened levels of alert. These spillover effects contribute to aggravating the existing tensions in Europe’s regional security environment. Best practices for mitigating these effects and for de-escalation and confidence building should be under consideration of this group. In addition to these already existing threats, Germany wishes to draw the attention of this group to the potentially adverse effects of the use of AI-powered cyber instruments on international peace, security, and stability, as has just been outlined by the delegation of El Salvador. AI has the potential to considerably accelerate machine functions, including the functions of ICTs. AI may also enable autonomous decision-making by machines. The algorithms at the base of such decision-making may draw on data sets that have been selected and trained in intransparent and biased ways. Both the acceleration in the use of ICTs and the intransparency of algorithms may cause lower levels of human control and oversight of ICTs. The risks associated with this in the security domain should be under the consideration of this group. Allow me to add, Mr. Chair, that Germany is fully aligned with the statements of the EU and Canada on multistakeholder participation. Thank you.
Ambassador Gafoor
Thank you very much, Germany. I give the floor now to Czechia, please.
Czech Republic
Thank you. Mr. Chair, I would like to thank you for all your effort. I really appreciate it. First of all, I would like to briefly, but very strongly, support Canada’s position on multistakeholder participation, echoed by the European Union, both considering delays and the transparency of the process. I’ve already mentioned a couple of times that we need stakeholders in the room, rather than waiting at the door; otherwise, we risk losing the available insight and technical support. The Czech Republic has long considered the chapter of current and emerging threats to be one of the most important. The Czech Republic aligns itself with the EU statement delivered earlier and wishes to emphasize a couple of points in its national capacity. As it has been mentioned many times also, the development of new technologies improves our lives, provides unprecedented opportunities for economic growth, and constitutes the backbone of our society. At the same time, it’s the source of serious risks and threats. I would like to focus on four most important risks and threats from the perspective of the Czech Republic. If we have to talk about threats in cyberspace in general, I cannot start other than to say that the Czech Republic considers as the greatest threat of our time the aggressive behavior of Russia. It strongly condemned the Russian unprovoked aggression against Ukraine, accompanied by cyber attacks, which represents a flagrant violation of international law, the UN Charter, and disruption of the overall rules-based international order. There are negative impacts throughout the world. In this context, I would like to particularly emphasize the EU position and positions of others, that it’s not possible to separate cyber attacks from other aspects of Russian aggression. We are witnessing the enormous reach and impact of cyber operations in warfare, with their spillover effects. It clearly shows that these are the threats that we need to talk about in the Open-Ended Working Group as well. Second point, recently we have seen a huge increase in ransomware attacks, as mentioned by a couple of delegations already. They can no longer be considered as individual actions with limited impact. On the contrary, they have a significant impact on states. In 2022, we saw ransomware attacks causing significant damage to the critical infrastructure of states, as was already mentioned by the U.S. statement. We have also noted a case when a state has even been forced to resort to declaring a state of crisis. This phenomenon must be therefore addressed not only in the context of cyber crime but also from the perspective of international security and peace. Third point, the Czech Republic welcomes the development of new technologies, such as artificial intelligence and quantum computers. At the same time, we are aware of the risks and threats posed by the deployment of those technologies. Here, I would like to especially appreciate a very complex and comprehensive description of the actual state by our colleague from El Salvador. Thank you, Julia. Elements of automation, acceleration, and scalability, exactly those three points, bring new dynamics and deepen the opacity of current processes and overall uncertainty. The Open-Ended Working Group should develop a more detailed discussion on responsible state behavior in developing new technologies. Last point, the Czech Republic is primarily concerned about the misuse of new technologies for human rights abuses. This includes using technologies as weapons and for committing crimes, blocking political content, shutting down the Internet, massive data collection of its citizens, partial or total censorship, surveillance of political opponents and all citizens, etc. Cyber security must not be used as a tool to suppress human rights. In this context, we are concerned about the growing trend whereby the introduction of apparently technical measures concerning new technologies or the adoption of new standards and norms concerning new technologies is in fact a means of suppressing human rights, such as freedom of expression, protection of privacy, and the right of nonviolent association. This is a relevant topic for discussion in the Open-Ended Working Group. We advocate a human-centered approach and a human-based approach and human-centric approach in cyberspace, where the individual has the same human rights in the online environment as in the offline world. We are fundamentally opposed to the misuse of technology to disrupt the current multilateral rules-based order. Mr. Chair, I would like to appreciate your effort, and I would like to offer on behalf of the Czech Republic maximum support and cooperation in our discussion. Thank you.
Ambassador Gafoor
Thank you very much, Chair, for your statement. It’s five to six minutes past one o’clock, and I’m conscious that we’ll have to break soon. First, I want to say that we are off to a good start. The statements that we’ve heard, 15 statements on the agenda item relating to existing and potential threats, have been fairly detailed and focused, with some new proposals and ideas coming up. So that is a good start. Second, I would encourage you, as we resume in the afternoon, to try and make your statements more succinct, if possible, and highlight, where possible, very specific ideas, proposals, or suggestions. We have about nearly 40 additional speakers. Fourteen delegations have spoken on this agenda item, but 40 additional speakers have indicated interest. So if we devoted about three minutes for each delegation, then there’s a good chance that we might be able to complete the list of speakers. But I’m also conscious that, because this is the first substantive agenda item, some of the statements are also touching on other agenda items. So in that sense, that’s fine, because all the different elements are related, whether it’s threats, international law, CBMs, and of course, capacity building or the PoA directory. So I can be a little indulgent, but I would still like delegations to be prepared to make very succinct statements this afternoon when we resume at 3 p.m. So I thank you once again, and I wish you a pleasant lunch break, and the meeting will resume at 3 p.m. Thank you.
Leave a Reply