Ambassador Gafoor
Good morning, distinguished delegates. The third meeting of the fourth substantive session of the Open-Ended Working Group on security of and in the use of ICT, established pursuant to General Assembly resolution 75/240, is now called to order. I apologize for beginning the meeting late, as I was involved in a side event on gender issues in the context of the Commission on the Status of Women, and I apologize for the delay. But in some ways, the coffee break has been front-loaded, and I was happy to see that many of you were talking to each other, which is also an important part of our work, to have these informal conversations. We will now continue with the speakers list on the first agenda item, relating to existing and potential threats. We have about a dozen speakers, and we will continue with the list that we had from yesterday, starting with Vietnam, to be followed by Egypt. Vietnam, you have the floor, please. Thank you.
Vietnam
Thank you, Mr. Chair, for giving us the floor this morning. In our first intervention this week, we would like to reaffirm our strong support for the work of this working group under your effective and efficient leadership. Mr. Chair, international cyberspace has become more interrelated and interdependent than ever. Next-generation technologies are evolving at an unprecedented pace, creating new opportunities for developments and collaboration, while at the same time presenting an ever-growing threat to global peace and security, as well as national security and public order. In general, Vietnam fully supports the use of cyberspace or ICT environments in compliance with international and United Nations Charters. It is imperative that the States should work together to prevent cyberspace from turning into a threat to military natures or even conflict killers. Indeed, the peaceful use of cyberspace should be guaranteed and protected for the social and economic development of nations. Mr. Chair, before discussing your guiding questions, let me briefly mention the approach of Vietnam towards national cyberspace. For us, cyberspace or the ICT environment is an essential condition for national development. Indeed, Vietnam is hoping to seize the opportunities that the Fourth Industrial Revolution has promised by building up the nationwide ICT infrastructure for the digital transformation and the operation of e-government services. This will help us achieve our goals of economic prosperity and social security by taking advantage of the rapidly advancing ICT landscape. Mr. Chair, regarding the first question about new vectors and vulnerabilities, in recent years we have witnessed increasing widespread and systematic PT activities and ransomware attacks targeting national critical infrastructure for essential services and ICT infrastructure that serve digital transformation, information sharing systems and databases, as well as industrial operating systems. The spreading of fake news and the use of ICT for criminal purposes are also reaching an accelerating pace, creating adverse impacts on the protection of interests of the states, their citizens, and enterprises. The reasons for these phenomena are multi-faceted. First, we do not have fully realized or universal technical standards and requirements for the R&D of new ICT products and services. This discrepancy creates potential cybersecurity risks, especially for those countries that do not have efficient or independent cyber capabilities. In addition, the ineffective public-private engagement, as well as incomplete state regulatory frameworks, also undermine our efforts in reducing cyber threats. For the question about how to develop a deeper understanding of these threats, we share the aspiration of many delegations that the POC network may serve as a repository or a compendium for analysis of malicious ICT activities, as well as proven cyber policies. For the question about what initiatives they can do, we call on our countries to respect and uphold their commitments to existing international laws and norms of responsible state behaviors which apply in the ICT environment. As a co-sponsor of the UNSC Resolution 2573 in 2021 on the protection of objects indispensable for the survival of the civilian population in conflict areas, we encourage states to uphold full compliance with this resolution and are looking forward to working with other states to expand this resolution to the ICT-dependent and ICT-enabled objects. In addition, we also welcome more coordinated initiatives to advance, first, confidence-building to test the global POC directories, including a repository’s function as previously mentioned, and second, capacity-building to handle the growing threat of ransomware to build a resilient, stable, safe, and secure global digital ecosystem. We look forward to continuing the important discussion throughout the week. I thank you, Mr. Chair, for your kind attention.
Ambassador Gafoor
Thank you very much, Vietnam. I give the floor now to Egypt, to be followed by the Netherlands.
Egypt
Thank you, Mr. Chair. Since it’s our first time to take the floor, we would like to express our gratitude to you, Mr. Chair, and your team, as well as the Secretariat, for your efforts throughout this process. Rest assured of Egypt’s support to you, your team, and the process itself. I would like to highlight the following remarks in Arabic with regards to our position on the existing and potential threats. Mr. Chairman, as far as the use of ICTs and new emerging threats in this context, we would like to insist on the following. First of all, threats linked to the use by states, terrorists, or criminal groups of ICTs in order to threaten critical infrastructure of states that depend on ICTs, or to conduct other acts of sabotage or illicit acts, especially in light of difficulties in determining who is responsible for such actions. Secondly, threats linked to undermining the supply chains that have a negative impact on economies of countries, especially developing countries. In this context, we’d like to mention threats related to digital identity, theft of personal data, propaganda campaigns, and disinformation campaigns against individuals or states. Of course, this has a negative impact on the economies of countries. Thirdly, the ease with which malware is spreading and which is used by certain states against other states. This represents a threat for everyone, including for the very states that have developed this technology initially. In this context, Egypt shares the concerns expressed by several other delegations, in particular about the use of artificial intelligence that could be used to target states. This is why we need to continue working in order to avoid duplication in our discussions. We need to develop a new concept regarding existing threats and emerging threats. Bearing that in mind, we support, as a matter of principle, the proposal made by other delegations to create a repertory of common threats, a repertory that is inclusive, can evolve, and can adapt to accelerating changes in ICTs. Perhaps also to include an annex with terms and general definitions related to cybersecurity. We are ready to engage in discussions with relevant delegations in order to further this proposal, and we are also aware of the scale and scope of the challenges related to attribution. This is why we need to engage in discussions among states in order to develop an international consensual mechanism, an impartial mechanism, in the framework of the United Nations, to combat the malicious use of ICTs. In conclusion, and in order to confront existing threats and future threats, it’s essential to join our efforts to strengthen our capacities at the national, regional, and international levels by sharing our experiences, good practices, and technologies in order to raise awareness among states and encourage them to adhere to responsible behavior with regard to ICTs. Also, we need to ensure to avoid any restriction on the rights of states to use ICTs for peaceful purposes. We will continue our discussions on this point in the framework of the item on international cooperation. Thank you very much, Mr. Chairman.
Ambassador Gafoor
Thank you very much, Egypt, for your statement. I now give the floor to the Netherlands, to be followed by Italy. Netherlands, please.
The Netherlands
Thank you, Chair. The Netherlands aligns itself with the statement delivered by the European Union. I will make some additional remarks in my national capacity. I’m also aligning myself with others who expressed regret over the objections raised to the participation of a large number of stakeholders. Their insights are uniquely valuable to the discussions on ICT security. Let me therefore begin by echoing the many stakeholders that during last Wednesday’s multistakeholder informal highlighted the growing threat to critical infrastructure, including the technical infrastructure essential to the general availability or integrity of the internet. In the 2022 Annual Progress Report, we noted that threats have continued to intensify and have evolved significantly in the current challenging geopolitical environment. It would be an understatement to say that the geopolitical environment has only deteriorated further, and the use of ICTs in the context of an armed conflict is now a reality. A key pillar of the mandate of this group is to identify these threats and achieve a common understanding of how they affect international security. We therefore propose the 2023 APR could reflect several key threats associated with the use of ICTs in the context of armed conflict. First, the serious risk of ICT activities affecting civilian objects, infrastructure, and services, including humanitarian organizations and healthcare, which may violate the rules of international humanitarian law. Second, the increased risk of ICT activities causing spillover effects in states not party to the conflict, potentially affecting, among others, food and energy supplies, as well as ICT products and services, and this is a global risk. Third, the risk of escalation stemming from such spillover effects. Chair, let me zoom out and address other threats that the Netherlands believes could be reflected in the report. Firstly, many states have raised the risk of ransomware. I would like to thank in particular Costa Rica for sharing their experiences on how they dealt with this threat. We also recognize the increasing risk of ransomware that rises to the level of international security. Let us do more work on thinking through this relationship between ransomware and international security. For example, in many instances, we see that the kill chain of a ransomware attack begins with early infiltration in systems, including, for example, in critical infrastructures and essential services. Depending on their scale and severity, such activities can pose a significant risk of instability, mistrust, and escalation between states. Secondly, like El Salvador, Chile, Canada, Malaysia, Singapore, South Africa, India, and many others, the Netherlands draws attention to new technologies. The Netherlands believes that it would be important to further our understanding, as an open-ended working group, of how new technologies, such as AI and quantum, may affect the risks posed by the use of ICTs to international security. Thirdly, like Germany, Singapore, and Israel, we would like to see the risk of cyber activities affecting the supply chains of ICT products and services reflected in the report. The EU has been developing regulations to bolster cybersecurity rules to ensure more secure hardware and software products, and many other states are doing the same. Fourthly, we are also concerned about the risk posed by the indiscriminate or reckless use of ICTs that causes harmful spillover effects on critical infrastructure and essential services. When the use of ICT capabilities is designed in such a manner that their deployment allows no or limited meaningful control by the initiators, this is likely to diminish the means of a state to ensure adherence to the framework for responsible state behavior, including international law. As such, the effects of such uses carry with them an additional risk of causing harm to citizens, institutions, and economies. They also increase the likelihood of destabilizing misperceptions and might therefore lead to unintended escalation between states. While a wide range of technical properties have been known to cause such uncontrolled cascading effects in past incidents, the use of automation, as well as new and emerging technologies such as artificial intelligence, may exacerbate their probability in the future. We will soon circulate a working paper on this topic and would welcome feedback from other delegations. Further, I would like to support the points made by Israel and Greece on maritime security. I would like to echo the points made by Argentina, the Philippines, the United States, Chile, Bangladesh, and others on the importance of working with the private sector and other stakeholders in assessing threats and understanding the evolving threat landscape. I support the UK on the points they made on the risks of widespread sale and use of high-end capabilities in ways that undermine human rights. I support the points raised by Chile on threats to women and girls and the points by Costa Rica. …of involving …unwarranted …the Netherlands and the Ukrainian people. Lastly, I would like to recall captured in previous reports that the use of ICTs by states is inconsistent with their obligations under the framework undermining peace and security, trust, and stability between states. This is the starting point of our discussions. The framework took years of intensive negotiations and the consensus we achieved. It’s up to states to live up to those agreements. Thank you, Chair.
Ambassador Gafoor
Thank you, Netherlands, for your statement. I give the floor now to Italy, to be followed by Ecuador, please.
Italy
Chair, good morning, and thank you for bringing us together again for this fourth substantive session of the OEWG. We very much align with your opening remarks yesterday, especially the ones related to the fact that this group is not starting from scratch, that issues should not be reopened, and that we need to find convergence. As well as the remarks from S.G. Nakamitsu, notably the references to the war which is raging on European soil, waged by the Russian Federation, and which is providing us with a very worrying first example of weaponization of cyber and the dangerous spillover effects that this can have. We also share Ms. Nakamitsu’s worries related to the pace at which technology is evolving and on the need to redouble our efforts to discuss issues that still divide us. Many thanks also for clarifying your position on the guiding questions and the spirit in which these have been formulated and are being addressed during this session, as well as for organizing the intersessional meetings, notably the ones which have brought together different stakeholders. Their involvement remains key; it’s inspiring. As mentioned yesterday by the Philippines and many others, the issues which emerged last Wednesday are very relevant. Proof is that they have been taken into account by many delegations during their interventions. We have also heard your appeal yesterday afternoon on this issue and look forward to sharing ideas on how the collaboration with stakeholders might shape, notably by discussing the value-added of public-private partnerships mentioned also by India and Vietnam this morning. Regarding the issue of transparency of stakeholders’ participation in the OEWG, please count us amongst those who align with the statement made by Canada yesterday morning. Let me now turn to your recommendation to be focused and action-oriented. I shall stick to your advice and be telegraphic in communicating what existing and potential threats we feel should be discussed and included in this year’s annual progress report. In aligning with the EU statement, we wish to underscore the increasing worry we share with many others regarding ransomware. For the reasons mentioned by many before me, also in previous sessions, notably by Costa Rica and my partners who have joined the counter-ransomware initiative like Italy has, we believe that this phenomenon should be inserted in the APR, especially in relation to attacks on critical infrastructure. In line with our national cyber strategy, we believe that greater attention should also be given to vulnerabilities, very eloquently explained by Switzerland yesterday, on the development of mechanisms which facilitate coordinated disclosure, as well as an analysis leading to a common understanding of the market which is growing around these. There is also a fast and growing concern about the impact of emerging technologies. We share those mentioned by many in a very eloquent manner by colleagues from El Salvador, Chile, Malaysia, and others related to artificial intelligence, notably when used for malicious purposes, cloud and quantum computing, and IoT devices. Chair, the surface of attacks is rapidly expanding exponentially, and the sheer amount of issues that have emerged yesterday and this morning should give us all an idea of the magnitude of the task before us. More than 60 delegations have taken the floor. It looks like your guiding questions have led the genie out of the lamp. We might need to reflect on how to multiply the occasions to have discussions on this founding block of the OEWG agenda. As an initial co-sponsor of the EPA, Italy has a pretty good idea about where these could be pursued and deepened, hopefully sooner rather than later. In the meantime, we heard your invitation to listen to each other’s proposals. We don’t have immediate responses yet. We’ll be looking into the different suggestions made, notably on the use or development of possible repositories of cyber incidents. Going forward, we trust that together with the Secretariat, you will craftily collect proposals in the upcoming APR, focusing on the most credible proposals, to paraphrase my German colleagues’ intervention yesterday morning, those which are bound to find convergence amongst all delegations. Thank you, Chair, for your unwavering efforts.
Ambassador Gafoor
Thank you very much, Italy, for your statement. I give now the floor to Ecuador, to be followed by Uruguay.
Ecuador
Thank you, Mr. Chairman. I’ll be brief, given that we’ve already exceeded the time allocated for this item. Since this is the first time that my delegation is taking the floor, I’d like to congratulate you and thank you for your efforts that have facilitated the preparation of this fourth session and the work of the Open-Ended Working Group, including the revised version of the non-paper on the essential elements to make operational the global directory of contact points that will serve as a basis for our deliberations tomorrow. I’m also grateful to the Secretariat for its work. Cyberattacks are a clear threat to international peace and security. This is why Ecuador is convinced that multilateralism, international cooperation, and such mechanisms as capacity building are effective tools to confront cyber threats and make cyberspace a safe environment benefiting everyone, because these tools make it possible to overcome existing imbalances in this area. This is why we’d like to highlight and support the proposal of Kenya that was seconded by the Philippines and other delegations regarding promoting the repository of threats as long as we are trying to achieve this goal. Also, Ecuador would like to highlight the significant, meaningful participation of women in this forum, and we hail and are grateful for initiatives such as Women in Cyber Fellows that have enabled many women to participate in this forum of discussion. Along the same order of ideas, my delegation would like to express their hope that the role of women in the area of cybersecurity is strengthened and is increasingly substantial and sustained so that the gender gap that exists in this area is significantly reduced. Lastly, Mr. Chairman, you can count on the support of Ecuador in this process, and we would like to wish you a productive session. Thank you.
Ambassador Gafoor
Thank you very much, Ecuador. Uruguay, to be followed by the Dominican Republic. Uruguay, please.
Uruguay
Good morning, Mr. Chairman. Thank you very much for giving me the opportunity to greet you and the Secretariat and wish you success in the new session of the Open-Ended Working Group. As my country stated, we have previously attached particular interest to this topic, and we value the work in the framework of the mandate of this group. You can count on the support of my delegation, Uruguay, in terms of various member states regarding vulnerability, and countries regarding critical infrastructure such as sanitary, security, and other infrastructure regarding the use of ICTs. This malicious use of ICTs is a real threat and requires greater cooperation between the states, the private and public sectors to protect their functioning and availability. In Uruguay, we are making progress in strengthening the National Centre of Response to ICT Incidents, strengthening its capacities for monitoring in order to minimize the time for detection and response to incidents, and reducing risks. This leads to significant savings for the country. Last year, my country suffered a series of ransomware attacks in the public sector. This is why we believe, and we agree with Ecuador and other states, that we support the repository of threats. Mr. Chairman, to confront these potential threats, Uruguay considers it very important to promote existing trends to strengthen cooperation and capacity building, taking into account differences between each country to confront these malicious actors. Uruguay reaffirms, as we have stated in previous sessions, the importance of having an exchange of good practices at the national level in confronting these threats. The Open-Ended Working Group is the ideal forum so that states in a position to do so can share their experience with the rest of the membership. Also, we believe that we must make progress in standardizing norms for a regulatory framework. We also hope to make progress in actions in the framework of the Program of Action, and we’d like to also reiterate the importance of gender issues in cybersecurity, especially bearing in mind this week and the topic of the Commission on the Status of Women. Thank you very much, Mr. Chairman.
Ambassador Gafoor
Thank you very much, Uruguay. Dominican Republic to be followed by Mauritius. Dominican Republic, please.
Dominican Republic
Thank you, Chairman. Good morning. This is the first time that we’re taking the floor. Allow us to begin our intervention by congratulating you for your leadership and your efforts, as well as the Secretariat in this group of work. The Dominican Republic reiterates its commitment to contribute constructively in achieving the goals of this Open-Ended Working Group (OEWG). As we see it, among the risks associated with emerging technologies, or rather significant risks implied with these technologies that are common to all states, we’d like to mention the deployment of 5G networks, with which current crimes and threats will have a greater capacity to be implemented, such as DDoS, botnets, and ransomware attacks. Also, we have risks associated with quantum computing, which in practice would make it necessary to update and develop new cryptographic algorithms, because the current ones would be easily vulnerable through quantum computing. Additionally, artificial intelligence implies new modalities of attacks and a greater capacity to carry these out. Artificial intelligence could be used by malicious actors and cybercriminals as a method to avoid existing technical mechanisms, for example, to conduct ransomware. Now, raising awareness and the visibility of these risks is the first step to identify potential mechanisms for their mitigation, perhaps through regulation of their use and implementation. Capacity building is becoming more important, especially for developing countries in the face of these growing risks, for example, the investigation and monitoring of cryptoassets. We agree with the proposal of Bangladesh on the importance of cooperating with the private sector in order to find solutions together. Also, regarding the value of the contribution of various stakeholders, it’s very important, as was mentioned yesterday. Regarding your question on the repository of threats, we believe that this would be a good idea, because even though we have visibility of the threats on a daily basis through the response team to incidents, certainly to have a consolidated repository would be very useful. This could be implemented through a secure portal, which could also be a directory of points of contact. Thank you very much.
Ambassador Gafoor
Thank you very much, Dominican Republic. Mauritius to be followed by Albania. Mauritius, please.
Mauritius
Thank you for giving me the floor, Chair. Chair, distinguished delegates, good morning. The Republic of Mauritius would like to extend its thanks to you, Chair, and your team for your efforts in putting together a set of guiding questions, as always, that pave the way for delegations to provide meaningful contributions towards the OEWG. Mauritius would like to submit its contributions on existing and potential threats as follows. While recent technologies employing artificial intelligence, such as Chat-GPT, can streamline and automate business processes, they also account for emerging and sophisticated security risks. For example, the ease, the proliferation of convincing-sounding phishing emails and the like, and have the potential to be utilized in crafting misinformation and propagating hate speech at relentless speed, in particular on social media. Mauritius aligns itself with the statements made by Singapore, France, and other delegations with regards to potential threats posed by the adoption of artificial intelligence. Further, Mauritius strongly believes that the existing normative framework could be molded in order to better deal with such pertinent issues. Similar to Canada, Malaysia, Bangladesh, and others, Mauritius firmly believes that the growing power of quantum computing will bring along unprecedented threats. Such a powerful technology can render modern cryptographic methods useless. For example, by causing more and more encrypted data to be harvested for later exploitation and compromising blockchain technology. This is a potential threat that companies and consumers investing in such technologies can expect in not a too distant future. Additionally, Mauritius underlines that the increasing use of open-source software that comes with no claims or legal obligations accounts for the high exploitation of vulnerabilities. It is no secret that the black-box nature of such software makes it complex and time-consuming to identify and address any prevailing vulnerabilities. However, the sharing of information on risks and vulnerabilities posed by open-source software can help avoid pitfalls associated with them. In the same vein, allow me to highlight, Chair, that Mauritius has established an information-sharing platform known as MoShield that through membership enables organizations at national, regional, and international levels to share threat intelligence and hence stay ahead of potential threats. Allow me to also mention, Chair, that this project was a runner-up in the ITU-WSIS Forum 2023, and we stand ready to welcome on board any member states wishing to take advantage of this endeavor. To conclude, I would like to take this opportunity to assure you that you can count on my delegation’s full support and cooperation in the OEWG. Thank you, Chair.
Ambassador Gafoor
Thank you very much, Mauritius. Albania, to be followed by Poland, please. Albania.
Albania
Thank you, Mr. Chair, dear colleagues. At the outset, allow me to extend our appreciation and support to you, Ambassador Gafoor, as Chair of this group, and to your team for your efforts in facilitating a focused discussion guided by the first annual progress report addressing issues that concern each of us today at national, regional, and international levels. Albania aligns with the statements delivered by the EU delegation on multistakeholder participation, as well as on the issue of threats in cyberspace, for which I’d like to make the following statement on our national capacity. Mr. Chair, technological advances are dramatically impacting international peace and security. The potential for misuse by states or non-state actors is significantly growing. Some countries are continuously trying to deliberately mislead information, distort facts, interfere in the democratic processes of others, spread hatred, discrimination, and incite violence or conflicts by misusing digital technologies. In the same vein, we see with concern unlawful internet shutdowns, restrictions, or denial of human rights and freedoms in using them. Allow me to recall that our region is systematically targeted by campaigns of interference and manipulation of information, which aim to create political instability and hinder peace, development, and stability. Cyberattacks have tried to suspend the online work of public institutions in these countries. We are deeply concerned by the malicious information and communications technology activities aimed at critical infrastructure and critical information infrastructure facilities affecting essential services to the public. As rightfully recalled by previous speakers, Albania’s critical infrastructure underwent two massive cyberattacks last year of a complex nature in an unsuccessful attempt by one state to inflict damage to the critical infrastructure, erase digital systems, steal data, and try to paralyze online public services that constitute 95 percent of all public services in Albania, trying to paralyze the whole country to create chaos and insecurity. It was a blatant breach of norms of responsible state behavior in cyberspace in violation of the principles of the UN Charter and international laws. Albania recognizes cybersecurity as a top priority. We will bring this issue to the attention of the Security Council during this year. In this regard, we are taking the appropriate actions to protect ourselves from potential cyberthreats based on cooperation with strategic national and international partners by implementing security measures in critical information infrastructure and, more concretely, by building the National Security Operations Center to effectively respond against cyberthreats. Cyberattacks and cyberthreats are unlawful acts, must be condemned, and must be treated accordingly. Impunity for these illegal activities by state or non-state actors should be properly addressed in our discussion. In this sense, Albania believes in the imperative of defining rules that ensure security and stability in cyberspace within the framework of the United Nations, grounded in the UN Charter and existing international laws, international humanitarian law, and international human rights law. In July 2022, member states recalled that the Program of Action should be further elaborated, including at the 2021-2025 open-ended working group process. We look forward to and encourage member states to further elaborate during this session the proposal put forward by France and Egypt for the Program of Action to advance responsible state behavior in cyberspace. This permanent mechanism could be very instrumental in bringing resilience and stability in cyberspace. Finally, Mr. Chair, allow me to reiterate Albania’s firm position for a global, open, free, stable, and secure cyberspace, where international law, including respect for human rights and fundamental freedoms, fully apply, supporting social, political, and economic development. We believe that multilateral efforts and the United Nations play an important role in continuing the dialogue between member states. Thank you.
Ambassador Gafoor
Thank you very much, Albania. Poland to be followed by Timor-Leste. Poland, please.
Poland
Thank you. Mr. Chair, distinguished delegates, Poland fully aligns itself with the statement delivered yesterday by the European Union. We would also like to express our support for Canada and its statement on stakeholders’ participation, as well as the statement delivered by France with regard to the programme of work. Allow me to provide a few remarks in my national capacity. From our national perspective, one of the biggest threats we continue to face comes from Russia and its malicious activities in cyberspace. More than a year ago, Moscow started a full-scale war against sovereign and peaceful Ukraine. Its aggression is unjustified and unlawful. Whatever Moscow chooses to call its actions, it is a war, with killing of civilians, Ukrainian infrastructure, including critical infrastructure, being continuously destroyed, and malicious attacks in cyberspace being conducted on a daily basis. Russia’s disregard for international law, including the foundation of this very organization, the UN Charter, as well as principles of international humanitarian law, is simply horrifying. Let me stress one crucial thing. Our discussions within the OEWG do not happen in a vacuum. Looking away from some real-life developments, like the war waged by Russia, will not make them go away. In order to ensure responsible use of cyberspace, we need to approach the discussion in a responsible manner. Therefore, we call on Russia to stop the aggression, withdraw from Ukraine immediately, and stop malicious activities in cyberspace, also those conducted against other countries, like my own Poland. Mr. Chair, as for the specific questions relating to threats and the next APR, we would definitely like to see the threats section being strengthened. In our view, we need a well-defined set of cyber threats. We support those countries speaking before us, asking to address, among others, the issue of ransomware. The example of the ransomware attack against Costa Rica in 2022 provides a clear argument as for why we urgently need to address this threat. We do not intend to elaborate on other agenda items at this stage, but since all of them are interlinked, we would like to stress the importance of real progress in capacity building, which is crucial for strengthening resilience. What is more, we want to thank you, Chair, and your team, and the Secretariat, for the papers and your efforts with regard to the POC directory. We look forward to further discussions on this valuable initiative. We also believe that it is necessary to have a permanent platform offering concrete cooperation projects. The Program of Action, which establishment was supported by the vast majority of UN members during last year’s vote in the UN General Assembly, aims at achieving concrete results. Building a sustainable platform covering all important aspects of responsible behavior in cyberspace, setting security standards, exchanging information and best practices, generating projects and ideas for international cooperation. Thank you for your attention.
Ambassador Gafoor
Thank you, Poland. I now give the floor to Timor-Leste, to be followed by Venezuela. Timor-Leste, please.
Timor Leste
Thank you, Chair. At the outset, I wish to join others in congratulating you on your success in steering this Working Group to the fourth substantive session. I can assure you of Timor-Leste’s full support and cooperation. Chair, as mentioned over the course of this Working Group, cyber security threats are now a current and constant risk to the well-being and prosperity of all nations and people. The role of ICT in areas of society is a clear example of how security has become a fundamental requirement for all aspects of society. The potential of cyber crimes and threats implies that cyber security is and will continue to be a complex issue, especially for developing countries such as Timor-Leste, and thus it requires significant resources to be allocated to address the threats. Issues such as hacks, data breaches, and theft of personal information have become a constant security concern for all nations. For many developing countries, the introduction and use of ICT to generate direct and indirect economic growth has become an additional variable to promote and diversify the national economy. Some of the factors contributing to fragile cyber security are poor secure networks, lack of cyber laws, and a shortage of well-trained IT security experts from both private and government agencies. The environment of cyber security should include effective laws and regulations, cyber security awareness, national and international collaboration, organizational structure, as well as protection for women and children. Considering that conventional methods are not always reliable for controlling cyber threats, a multi-layered approach that will focus on the core elements of the cyber security environment is an essential part of addressing cyber security. Chair, the government of Timor-Leste is increasingly focused on developing and adopting information communication technology as a cornerstone of communication, commerce, and governance. The pace of transition to the digital economy has been accelerated by the COVID-19 pandemic as well as ongoing rapid innovation in the ICT sector, factors that call for effective safeguards and appropriate security measures to ensure the well-being and functioning of the state and its citizens in cyberspace. Recently, the government of Timor-Leste established its first national cyber security strategy, which lays down priorities, objectives, and lines of action that constitute a path to the establishment of strong legal and policy frameworks that are necessary to enable effective crisis management, coordination of operational responses to cyber attacks, workforce development, and coordination of national capabilities. This strategy seeks to provide incentives to build cyber security capabilities needed to increase international investments in commerce for Timor-Leste as a safe place to do business. One of the most vital yet prevalent threats is data and information theft and ransomware, as mentioned by many delegations. For countries that are still in the process of establishing and implementing their cyber laws, controlling this will prove to be a challenge as national authorities are still not fully equipped to address the matter. My delegation takes note of the initiative raised by several delegations on the establishment of a repository of cyber threats, and we look forward to more detailed discussions on this matter as this may provide a good basis for the implementation of our national policy. Chair, lastly, as we have reiterated in previous sessions, Timor-Leste views cooperation with key domestic stakeholders as important to undertake necessary improvements to the country’s digital ecosystem. Given the quick development of the technology and communication industry and the digital divide between countries, a collaborative partnership between states, the private sector, and academic institutions at national and regional levels should be encouraged to address the issue as a whole. Thank you, Chair.
Ambassador Gafoor
Thank you very much, Timor-Leste. Venezuela, to be followed by Slovakia.
Venezuela
Good morning, Mr. Chairman. Thank you for giving me the opportunity to speak. My delegation is grateful for your efforts and for your leadership in guiding the work of the Open-Ended Working Group. In confronting current threats and future threats in the area of information and communication security, we should acknowledge certain aspects that are of crucial importance. First of all, the fact that in the face of these phenomena, even though to different degrees, all states are vulnerable. Secondly, there are technological gaps between states. This is a reality that, in fact, deepens even more the vulnerabilities of developing countries. These issues, in addition to the growing monopolized character of the communication industry, only deepen the imbalances and threaten the pluralist and democratic character of the processes of communication, as has been denounced and condemned previously. The political infrastructure of Venezuela has been the target of cyberattacks by state actors and non-state actors. These attacks have affected the national banking sector, the food supply chains, telecommunications systems, the national electricity generating system, and the oil industry of my country. These premeditated attacks that have been used in the framework of a failed policy of regime change have affected the national economy and have forced us to strengthen our efforts to ensure a broad range of social, economic, and cultural rights. This is why, in my country, we reject the militarization of cyberspace and the use of information and communication technologies to interfere in the internal affairs of states or to generate processes of political, economic, and social destabilization or to disrupt communications by government institutions of any state. Mr. Chairman, the rapid technological evolution in a context where various actors intervene clearly points to the scope and complexity of the existing threats in the area of the use of ICTs. Computer piracy in all its forms, the propaganda generated by artificial intelligence, cyber spying, the theft of information, cyberattacks against critical infrastructure, the alteration of computer data, dissemination of false information, and the blocking of communications. These are just some of the emerging threats that affect the security, sovereignty, and economic development and well-being. In the development of norms by the working group, any discussion of real and potential threats must be compatible with the principles and purposes of the United Nations Charter and international law and, in particular, the principle of sovereign equality, respect for the sovereignty of states, the peaceful resolution of disputes, the non-use in international relations of the threat of the use of force against the territorial integrity or political independence of any state, and the non-intervention in the internal affairs of any state. And while we are working to approve a legally binding instrument, the disputes derived from the use of ICTs should be resolved through peaceful means in the framework of international law. Mr. Chairman, now heeding your appeal to contribute to our debates, one aspect that has not been discussed and that we hope will be reflected in the future report of the working group has to do with the unilateral coercive regimes called cyber sanctions, which are beginning to proliferate around the world. Today, we’re increasingly concerned by the extended use of unilateral coercive measures that undermine the trust in a peaceful international administration of cyberspace. Without internationally accepted regulation in this area, the efforts of the Open-Ended Working Group might become inadequate. In the face of such varying and changing phenomena, I think it would be a good idea under the auspices of the United Nations to draw up a compendium of existing threats accompanied by the best practices in addressing these threats. International cooperation that is free of any conditionality, that is shared in a voluntary way where information strategies and technologies are shared to improve the protection of critical infrastructure should serve the international goal of minimizing and neutralizing the threats derived from the malicious use of information and communication technologies. Thank you very much, Mr. Chairman.
Ambassador Gafoor
Thank you Venezuela. Slovakia please.
Slovakia
Thank you, Mr. Chair. Slovakia associates itself with the statement delivered by the European Union. I would like to stress the following points from our national perspective. Slovakia supports the development of human-centric tech that doesn’t undermine but rather strengthens human rights, dignity, and democratic values. The new and emerging technologies need to be clearly tied to the existing normative framework, with the possibility of expanding these norms if required. To achieve that, we need clear rules that promote innovation and a human rights-based approach related to EDTs. An adequate security infrastructure is one that encourages effective communication, situational awareness, and offers ways of assistance to mitigate systemic vulnerabilities. To mitigate issues referenced by the OEWG Annual Progress Report, such as possession of offensive cyber capabilities or frequent use of ransomware, transparency should be our main focus. We think that key to supporting implementation of the framework for responsible state behavior is a thorough assessment of the degree of cyber resilience of developing countries, also in cooperation with relevant regional organizations and multistakeholders. Thank you.
Ambassador Gafoor
Thank you very much, Slovakia. I’ll now give the floor to observers. Two of them have requested to speak. We’ll start with the ICRC, to be followed by the International Chamber of Commerce. ICRC, please, you have the floor.
ICRC
Excellencies, dear colleagues, the International Committee of the Red Cross is grateful for the opportunity to participate in the fourth session of the Open-Ended Working Group. As a neutral, impartial, and independent humanitarian organization, we have been closely monitoring the use of information and communication technologies in armed conflict. Today, we would like to bring to your attention two trends in existing and emerging threats that we believe are important for this working group. The first trend has existed for several years, namely cyber operations against civilian infrastructure, such as power plants, medical facilities, civilian e-governance systems, and private companies. As the OEWG expressed in its 2021 report, these operations risk having potentially devastating security, economic, social, and humanitarian consequences. We would like to reiterate the threat that such operations pose to humans. The more societies use and rely on digital apps, devices, industrial control systems, and networks, the more vulnerabilities exist and risk being targeted and disrupted. The second trend concerns the growing involvement of civilians in digital operations during armed conflict and the use of digital civilian infrastructure for military purposes. This trend manifests in several ways. For civilians, digital technology has seemingly lowered the threshold for engaging in digital operations in support of warring parties. While people may be physically remote from the theater of hostilities, they are only one click away from the digital battlefield. In several conflicts, civilians have decided or been encouraged to use ICT devices to take part in cyber operations that rely on mass participation, and seemingly private hacker groups have been instructed or tolerated to conduct operations linked to ongoing armed conflict. These operations have two growing commonalities. One, when civilians conduct cyber operations in relation to an armed conflict, there is a real risk that they get caught in digital and physical hostilities and suffer harm. States need to be conscious of this risk, especially when asking civilians to support digital operations during armed conflict. And two, on many occasions, civilians have been targeted in their ICT operations against civilian objects. States have an obligation to ensure that even civilians respect IHL, in particular that they do not conduct cyber operations against civilians. Moreover, providing digital tools to civilians or tolerating hacking groups to conduct their operations risks long-term destabilization. When conflicts between regular armies stop, who will control the non-state actors that are increasingly equipped and able to conduct harmful operations? The ICRC is also concerned about a growing threat of damage to digital civilian infrastructure and services that are used for military purposes. The more the military is relying on cables, satellites, or cloud that are otherwise civilian, the more likely it becomes that such infrastructure is being targeted in times of armed conflict with adverse consequences for civilians. It does not matter whether infrastructure or services are publicly or privately owned, whether they are used in offense or in defense, the harm to civilians will be similar. One way to halt this growing development could be to increasingly separate international infrastructure used by the military from civilian infrastructure and to refrain from using civilian infrastructure and services for military purposes. Separation will not be absolute, but technically, stronger separation is feasible. It’s a political choice to move in this direction. Thank you.
Ambassador Gafoor
Thank you, ICRC. International Chamber of Commerce, please.
International Chamber of Commerce
Thank you, Chair, and good morning, colleagues. Many thanks for the opportunity to share a few thoughts with regards to existing and potential threats on behalf of the International Chamber of Commerce, the institutional representative of 45 million companies across more than 100 countries. Chair, digitization is now a key part of every country’s sustainable economic and social development, as many delegations have highlighted yesterday and today. At the same time, with accelerating digital transformation, protecting cyberspace is becoming increasingly harder to achieve as more and more of our lives become connected. Cyber threats take many forms. Malicious cyber activity affecting businesses continues to rise in scale, frequency, and complexity. We continue to see wide-scale exploitation of personal technology and information focusing on data theft and alteration, phishing, and ransomware, with threats on critical infrastructure alarmingly becoming a sort of new normal across sectors as essential as energy, healthcare, utilities, and transportation, affecting industries, communities, or even entire cities and countries. Botnets are constantly evolving and becoming more sophisticated. Hundreds of thousands of new malware variants are emerging. We are also seeing an increase in cyber-offensive capabilities. The increase in ransomware incidents is further exacerbating a model known as ransomware as a service, where sophisticated cyber criminals provide easy access to ransomware tools to any individual or group at a low cost. Furthermore, threat actors are leveraging the growing complexity of the cyber domain to operate with almost complete deniability. Proliferation of threats is combined with the lack of clear and effective legal and policy countermeasures against malicious actors, combined with the lack of capacity that governments, law enforcement agencies, and justice administration organizations have on cybersecurity issues. Such evolving threats can only be countered by equally dynamic and flexible policy solutions rather than prescriptive, compliance-focused regulatory requirements. As seen with other global measures, they must also be met with strong international cooperation and deterrent and punitive measures against malicious actors. Collaboration between governments and all relevant industry sectors is also key to counter the significant sophistication of these new types of threats. We know that we are not starting from scratch. International law and globally agreed norms exist. However, at the present time, there is little or no agreement on what technical, legal, and policy frameworks each country should have in place to meaningfully act on their implementation, what are the potential gaps in capacity, and how to bridge them. This is where the Open-Ended Working Group (OEWG) can bring particular value. It is imperative that through our work here we put cybersecurity efforts in perspective and recognize as the international community that cybersecurity is the prerequisite for digital transformation that fuels economic growth and social development and commit to mainstreaming cybersecurity into the broader development agenda. This will help identify and address challenges in implementation or gaps in capacity and direct resources to build targeted programs in response. It will also help identify with a more comprehensive lens which technical, legal, and policy frameworks, what capacity building initiatives, and what governance and support actions are needed, both in the context of international cooperation and at the national level to secure the digital economy. Thank you, Chair.
Ambassador Gafoor
Thank you very much, International Chamber of Commerce. We’ve exhausted the speaker’s list, and it is my intention to move to the next item on our agenda, which is rules, norms, and principles of responsible state behavior. But before we do that, I just wanted to share some initial reflections. It is not a summary, certainly premature to come to any conclusions after discussing just one agenda item, so we’ll see how the rest of the discussion evolves. But I wanted to share with you that, first of all, we heard from 60 delegations, 61 to be precise, and of course, two observers as well made their contributions. I think this is probably the largest number of interventions we’ve had on this topic, at least since this working group began its work. And I see that as a very good sign because that is an indication of not only interest but also commitment and engagement. And I was also very gratified to hear contributions from many small delegations. And this is also a sign that they are interested, they are committed, and engaged in this process. Now, the second thing which struck me was that all the interventions were very thoughtful, very detailed, and very focused. I’m not sure if I should take credit for these comments, which were focused, perhaps because the guiding questions had helped you in some way, but I will not take credit for that because these interventions are your interventions, your contributions. And therefore, I give credit to you, to all of you who made your views known. In some ways, this demonstrates also the value of this working group because it does provide a forum for all countries, large and small, to express their views and propose very specific ideas. So, I could not have asked for a better beginning for our work this week. Now, this discussion took a little longer than I had expected, but I think it was a good investment in time because I think we can catch up with the other agenda items as we move along. It was a good investment in time because, in many ways, the discussion on this first item on existing and potential threats does help us understand what we need to do as an international community in terms of rules, in terms of confidence-building measures, in terms of international law, and of course, in terms of capacity building, not to mention regular institutional dialogue in the future. So, the usefulness of this discussion is that it provides a good frame. Now, in capturing elements for our second annual progress report, I think we need to keep in mind a few things. First, the discussion on emerging and potential threats has happened for some time. So, this is not the first time we’ve had such a discussion. This has happened over the last 20 years, the previous OEWG, and now. But the reality also is that the threat landscape is evolving. So, this discussion is very useful because it gives us a sense of the evolving nature and some of the emerging threats, and also a greater sense of urgency that I sense from the discussion with regard to some of the threats that have been identified. So, that, in that sense, is very useful for us to note. The second point we need to keep in mind is that even as we try and capture the common elements, and there were many common elements with regard to the threats because many of you were echoing each other, which I think is very, very useful. And so, I think that there are some common elements that we can capture as elements to be put into the annual progress report. But we do need to keep in mind that whatever we agree on in this particular section, again, has to be based on consensus. My own sense is that if we focus on this section, existing and potential threats, in a very objective way, and try and identify the threats in an objective way, without finger-pointing, then I think there is value in identifying a range of the emerging threats because that has relevance for the work that we do in our working group. So, this is a section that will need careful drafting. I also think that – I know quite a number of you made specific references to specific contexts or countries. Some countries also shared their own experiences with some of the threats. So, all these are relevant, and of course, all this is also overlaid with that very challenging geopolitical context that we face. But it’s also important to keep in mind that we are not the General Assembly, we are not the Security Council, we are the working group on ICT security. So, we need to describe the threats in a way that is objective, that is not finger-pointing, but that is relevant to our work. And that will require very careful drafting at some point. So, these are some things that I wanted to share. The last point that I wanted to make is that there were some very specific ideas put across. I think that’s useful. I welcome the spirit in which these ideas are being put across. For example, the idea of a repository has been put forward, and it’s received echoes and endorsements. I would like to encourage those who have put forward this idea to reach out to others who have echoed, supported, or endorsed it, and to try and create a cross-regional coalition, for want of a better word. Maybe coalition is not a good word because it has a connotation, just let’s say a cross-regional group, to further discuss the idea, and then share your submission with me. Because based on this discussion, it is clear that this is an idea that will need further discussion. So, I’m asking you to help me. Those of you who think that this is an idea that is worth pursuing, of discussing further, please get together in a cross-regional group setting, and then elaborate the ideas, and then put forward a paper, and give that paper to me. And then we can then see how we can have further discussions, if needed, to see what exactly we are talking about, and how we can build a convergence. So, distinguished delegates, very, very good discussion, very good start. So, let’s move on to the next item on our agenda, which is rules, norms, and principles of responsible state behavior. And I’ll open the floor now to delegations. Yeah. Thank you. Now, Russian Federation, is it on the next item, rules, norms, and principles? Can I confirm that? Okay, good. So, we are moving to the next item on the agenda, rules, norms, and principles of responsible state behavior. So, we’ll start with the Russian Federation, to be followed by Sri Lanka, please.
Russia
Mr. Chairman, distinguished colleagues, UNGA Resolution No. 75-240 requires that the OEWG continue the development of rules, norms, and principles for the responsible behavior of states in cyberspace as a priority. Work in this direction has been carried out under the UN’s auspices at the initiative of the Russian Federation for nearly 25 years. However, as demonstrated during the discussions in the group, challenges and threats in the cyber field continue to increase. A number of states are still developing military, including offensive, ICT capabilities. It’s obvious that the existing voluntary and non-binding rules of behavior are not enough to effectively regulate the use of ICTs. The solution to this problem lies in the creation of an international legal regime regulating cyberspace. It would be through the development of a legally binding multilateral international treaty under the UN’s auspices. Such a document should provide a solution to the issue of preventing and settling interstate conflicts, promoting the entirely peaceful use of ICTs, and providing a framework for cooperation amongst states for these purposes. We know that a number of states fear such initiatives like the plague. They are torpedoing the relevant discussion on international platforms and trying to maintain the purely voluntary nature of the rules above mentioned. Obviously, they want to keep their hands free in cyberspace. However, statements from delegations at the OEWG sessions clearly show that most countries are advocating for the need to develop a legally binding instrument. We have already dealt with a similar situation with the topic of combating cybercrime. At first, a narrow group of states was strongly against the Russian proposal to develop a universal convention in this area. And now, under the UN’s auspices, a relevant ad hoc committee is up and running where all member states are negotiating the text of a future international treaty. We are sure that the situation will develop in a similar manner with regards to the security of the use of ICTs. In this regard, the Russian Federation requests that the chair of the Open-Ended Working Group disseminate the concept of a UN convention on ensuring international cybersecurity within the group. We would like to submit this document to the secretariat of the Open-Ended Working Group after our statement. Our initiative is a practical development in the long-term discussion on the creation of a regulatory regime in the ICT field. It is based on the recommendations of the annual UNGA resolutions entitled Developments in the Field of Information and Telecommunications in the Context of International Security, as well as the consensus reports of the Open-Ended Working Group in 2021 and the GGE, which completed work in 2010, 2013, 2015, and 2021. The document takes into account the initiatives of states outlined in the summary by the chair of the first Open-Ended Working Group and is structured for drafting a future convention. We would like to emphasize that Russia presents this proposal as food for thought as well as a conceptual basis for further work. We are open to discussion and to taking into account constructive suggestions and comments. In our view, the draft convention should be developed under the UN’s auspices, bearing in mind the views of all member states within the negotiating format that should be established for these purposes. A future treaty should provide mechanisms for monitoring the fulfillment of its provisions by participants, for making amendments and additions, for exchanging views on the implementation of the document, and on the settlement and peaceful resolution of disputes. Only after the adoption of such a universal, legally binding agreement can we talk about countries’ accountability for compliance with its provisions. Thank you for your attention.
Ambassador Gafoor
Thank you, Russian Federation, for your statement. I look forward to receiving your statement, which I will study carefully, and it will also be put on the website of the Working Group. I now give the floor to Sri Lanka, please.
Sri Lanka
Thank you, Mr. Chairman, for giving me the floor. Mr. Chairman, if we look around the world, we will soon appreciate that rules, norms, and principles can be no more than a facilitator to achieving the goal of responsible behavior in cyberspace. I’m simply saying that we therefore need to go beyond just a set of rules to make a real difference. I say this because responsible behavior entails self-motivation and self-guidance by Member States in their best interest and in the interest of the international community, and not for reasons of pursuing a common cause of some fashionable political alliance. We know that the Program of Action represents an opportunity to put forward an alternative approach to state behavior in cyberspace, based on multistakeholder capacity building and democratic norms in a bid to take it beyond the realms of the law. We must also remind ourselves of the normative framework developed by the GGEs to promote responsible state behavior in cyberspace, which is based on the four pillars of international law, the 11 voluntary norms setting out what states should do and should not do in the digital space, various confidence-building measures, in particular to strengthen transparency, predictability, and stability, and finally, of course, capacity building. Now, in order to successfully achieve these initiatives, we need to have trust in technology, because trust is a fundamental aspect of building confidence in an interconnected, digitalized world. In the absence of an internationally legally binding instrument structured upon the foundation of trust and values that governs the digital space, the development of effective rules, norms, and principles of responsible state behavior becomes that much more difficult. However, while the development of rules, norms, and principles of responsible state behavior in this sector may be a positive step, Sri Lanka’s position has remained steadfast that any protocol of rules developed cannot be the alternative to working towards a legally binding instrument. Mr. Chairman, it is our position that before we can develop new rules, we need to have a clear understanding of how existing rules and laws are applied in the digital space. We have accepted the position that international law also applies in the digital space. In the case of certain rules, such as the prohibition of violence in cyberspace, it is relatively straightforward to understand. However, in the case of such rules as the rules of international humanitarian law, this application needs greater study, I say, as to its implementation. In other words, we require greater study on what states can and can’t do in the event of cyber warfare. Mr. Chairman, it is only once we have clarified these issues that we will be able to evaluate whether new rules are necessary. So, as far as Sri Lanka is concerned, with the adoption of the Data Protection Act and the Cybersecurity Bill, Sri Lanka is focusing on creating a rules-based order, setting the minimum standards to protect our digital infrastructure and cyber use and engagement. Sri Lanka takes cognizance of the fact that the framework is primarily about promoting interstate cooperation, respecting human rights and privacy, protecting critical infrastructure, safeguarding global supply chains, providing assistance when required, and preventing the malicious use of digital technologies on states’ national territories. Mr. Chairman, we believe that we must work towards upholding and strengthening international law. Secondly, that Member States must clarify the way in which international law should be applied in concrete terms in the digital space by examining where they stand on these issues. Mr. Chairman, by setting out and promoting its individual position, Member States can help to bring greater consistency and predictability. In this way, it can also shape the international position on the digital space to reflect our individual interests. And finally, I say that it can make a tangible contribution to promoting clarity and a shared understanding of the application of international law by a regular dialogue between states. Mr. Chairman, I must mention the fact that the rule of law, just as much as it prevails in ordinary circumstances, must also prevail in the digital space. It cannot be rules of law. It must be the rule of law and nothing short of the rule of law. Thank you.
Ambassador Gafoor
Thank you, Ambassador, for your statement. I have a list of speakers who have indicated interest. Let me at this point take the opportunity to draw your attention to the guiding questions which I have made available, so that will also be useful that I get your response to that. The questions under this section relate also to whether there are any suggestions for updates or elaboration to the non-exhaustive list of proposals that was annexed to the Chair’s summary in the 2021 OEWG report. And so please look at these guiding questions. And then I’d also ask for a guiding question on the development of guidance checklists and the sharing of national views on technical ICT terms. Which of these topics should be most urgently examined in the context of developing guidance or checklists in order to build common understandings on rules, norms, and principles of responsible state behaviour? So quite some big issues under this cluster of items, and we’ll continue with the speakers list now. Starting now with the European Union to be followed by Portugal. EU, please.
EU
Thank you, Mr. Chairman. I have the honour to speak on behalf of the EU and its Member States. North Macedonia, Montenegro, Albania, Ukraine, the Republic of Moldova, Bosnia and Herzegovina, Georgia, Iceland, Norway, Monaco, and San Marino align themselves with this statement. Norms of responsible state behaviour are a key element of the normative framework for responsible state behaviour and are complementary to international law as applicable to cyberspace. In this regard, the first Open-Ended Working Group has elaborated on and strengthened the 11 norms of responsible state behaviour, in particular by enhancing the understanding of the implications of these norms of responsible state behaviour. The 2021 UNGGE and Open-Ended Working Group reports both also note a persisting divide in states’ capacities to implement the agreed-on norms and recommendations effectively. The latter case provides an entry point for cyber capacity-building activities that could help broaden and deepen awareness and common understanding of the norms. According to a model developed by the Australian Strategic Policy Institute, cyber norm implementation can be understood as a six-step process: awareness, recognition, assessment, understanding, plan and act, and implementation. That means that for states to engage meaningfully in the cyber norms debate and to be able to implement cyber norms, specific capacities are required. They include activities aimed at national awareness, policies and strategies, international cooperation and coordination, national laws and regulations, national institutions and resources, and public-private partnership and cooperation. Therefore, the reference to the layers of norms includes a common understanding of the tasks necessary to adhere to norms. We need to continue working within the UN on deepening our common understanding of these tasks. This supports the implementation of norms in cyberspace as well as contributes to cyber capacity-building efforts. Through its cyber capacity-building projects, the EU aims to support the implementation of one or more of the norms, inter alia awareness raising, establishing information-sharing pathways, conducting training exercises, etc. Similarly, the EU will actively promote universal human rights and fundamental freedoms, the rule of law, and democratic principles in the digital space and advance a human-centric approach to digital technologies in relevant multilateral fora and other platforms. Already in 2014, the EU adopted the EU human rights guidelines on freedom of expression online and offline, which state clearly that all human rights that exist offline must also be protected online, in particular the right to freedom of opinion and expression and the right to privacy, which also includes the protection of personal data. One vehicle for promoting capacity-building aiming explicitly at cyber norm implementation was proposed in October 2020 when a cross-regional group of member states led by Egypt and France put forward a proposal for a United Nations Program of Action. This proposal aims to set up a permanent, inclusive, and action-oriented mechanism at the United Nations to monitor the implementation of agreed cyber norms and recommendations and to support states in their national implementation efforts, mainly through capacity-building. These exchanges should build upon the discussion on norms implementation and the identification of gaps, also taking into consideration the subject of gender-sensitive capacity-building, and could further feed into the work under the POA, noting that capacity-building constitutes the practical foundation to implement the UN framework for responsible state behaviour in cyberspace. I thank you for your time.
Ambassador Gafoor
Thank you very much, European Union. I now give the floor to Portugal, to be followed by Canada. Portugal, please.
Portugal
Mr. Chairman, due diligence is, in our view, one of the most promising tools in the framework for responsible state behavior comprised by international law and norms applicable to the prevention and regulation of conflicts among states in cyberspace. The growing use of proxies by hackers, including official proxies, is very worrying and can precipitate the use of unjustified countermeasures, which will be especially dangerous in the context of an armed conflict, such as the invasion by Russia already one year ago. Therefore, before resorting to cyber weapons to retaliate against malicious operations apparently originating in another state, this state must be immediately called upon by the victim to confirm swiftly if digital devices on its territory have indeed been manipulated. Though the technical and management obstacles are many and hard to overcome, we should not desist from agreeing on a set of standards that increase the attractiveness of due diligence as a means to afford a pause before precipitating a crisis generated by an attack against critical infrastructure. Given that the vast majority of critical infrastructures in our societies are privately owned and/or managed, some form of due diligence applicable to the private sector should perhaps also be devised. At least, the benefit of the doubt should be given to those scholars who have been defending this development, and they should perhaps be invited to make contributions to this debate. When their views have been heard, maybe a small group of member states should write a food-for-thought non-paper to foster further debates on the practical viability of a comprehensive due diligence code of conduct, which, in our view, should be one of the main priorities as soon as we move on to a Program of Action to advance responsible state behavior in cyberspace. Thank you, Mr. Chairman.
Ambassador Gafoor
Thank you very much, Portugal. I think all contributions which are food for thought are very much welcome from all delegations or groups of delegations. That’s what we need to do in this working group: put ideas on the table but also work across groups to discuss these ideas and see how we can proceed and how we can build convergence. Now the list is growing. I certainly don’t want to discourage you, but if we had 60 speakers for each agenda item, we’ll need to extend the session by another week, which I’m happy to do because I’m based in New York. Perhaps some of you might be happy to stay in New York as well for another week. But I do urge you to be succinct and also please help to respond to some of my guiding questions. But if you don’t want to respond to them, that’s perfectly fine too, because that in itself is a signal and a response of some sort from you. So I’m not forcing you to look at my guiding questions, but I just wanted you to be aware that they are on the table for you to respond. Canada to be followed by Cuba. Canada, please.
Canada
Merci, Monsieur le Président. Canada believes that we don’t need any new norms at this time. From our point of view, the 11 current norms and international law are enough to guide the behavior of states. In our view, now is not the time to develop a new legal instrument. We should continue to develop the texts that we have been working on for the past 10 years. We agree with Sri Lanka on the idea of continuing to develop international law, and my colleague will speak about this in greater detail on the law section. We would suggest that Russia should respect the norms and rights before proposing any further legal obligations. Chairman, you also asked if additional guidelines could be provided on the norms, and my answer to this question is definitely. In previous sessions, many states proposed the fact that the norms were too abstract and that they needed guidance and explanations, as well as examples of what states can do to implement them. We should recall the previous work done on this subject. Canada’s work on the guidance for norms took place at the last OEWG. This text garnered the support of 40 states in 2021. Also, the GGE text from 2021 included a guidance text on these norms, and we think that we can use this text and complete it by adding elements, for example, on gender and the role of actors in the implementation of the norms, as well as issues of human rights and a human-centered approach. If we move on to the plan for this OEWG, we will update the text for the norms in 2021 that we proposed. We will ask stakeholders and states to propose new ideas so as to be able to include them in the text. We have had excellent bilateral discussions and small groups with some parties in December and this week. If you have any ideas, don’t hesitate to come see me or my team this week. So the goal here is to present a part of this text in 2023, focusing initially on the norms based on critical infrastructure, and then we would propose the entire text in 2024 or 2025. I’m eager to continue this conversation with all states in the weeks and months to come, so as to be able to add layers of understanding to the existing norms and to promote their implementation. This leads me to my last point on the key role of stakeholders in the implementation of the norms and in the elaboration of the guidance on the norms in particular. As I mentioned earlier, an informal consultative group made up of key stakeholders would give us new interesting ideas to include in the guidance. I wish to thank the individuals and organizations that have already worked with us on this subject. Regarding the next steps, we will submit our draft text to a larger group of stakeholders after having carried out internal consultations and consultations with states on the text. This is a true model of multistakeholder collaboration. This is independent from the modalities relative to this group. Each state is free to consult the stakeholders as they wish on the proposals on the states. We did this during the last open-ended working group, and we will do it this time, and we would recommend that other states do the same in the elaboration of their text. Thank you.
Ambassador Gafoor
Thank you, Canada. Cuba, to be followed by France. Cuba, please.
Cuba
Mr. Chairman, Cuba would like to reiterate the need to strengthen the normative framework to regulate issues in the area of security and the use of information and communication technologies. Bearing this in mind, we reaffirm the need to have a legally binding international instrument that encompasses in a comprehensive manner issues related to cybersecurity and the use of ICTs and regulates the behavior of states in cyberspace. This is our ultimate aspiration because we consider this would be the most effective contribution to establish a model of behavior for member states with permanent monitoring, also with the possibility of confronting the diversity and variety of the threats that we have referred to previously. Based on the fact that binding norms are an intermediate step in achieving this goal, we’d like to recall the priority character that resolution 75/240 of the General Assembly stressed on the need for this group to develop norms, rules, and principles for the responsible behavior of states, as well as the corresponding modalities of application, and if necessary, the introduction of amendments or the elaboration of additional rules of behavior. Consequently, we advocate for the discussions of this group to be based initially on the proposals of new norms presented by states that are in the annex to the reform of the GTCA of 2019-2021. The norms, rules, and principles elaborated by the GGEs previously, where all the states did not participate, do not have universal acceptance. Mr. Chairman, norms must be elaborated and implemented on the basis of the respect for the principle of sovereignty and sovereign equality, political independence, and the territorial integrity of states. They should also promote peaceful coexistence and international cooperation for mutual benefit and interest. Also, what is required are norms that refer to the prevention of militarizing cyberspace and the non-imposition of unilateral coercive measures. We do not favor norms that make recommendations on the internal behavior of states or international control mechanisms or relationships with other actors or any other action that undermines the sovereign right of any state to decide on the internal procedures to ensure cybersecurity. At the same time, we have maintained a consistent position against the creation of unique recipes or unique approaches to these issues. We would like to stress that each country has its own specificity. And generally speaking, developing countries do not – we do not have the same technical and technological possibilities as developed countries, which is why – [inaudible]
Ambassador Gafoor (PROBLEM)
Thank you Cuba. France please.
France
Thank you, Chair. Through preliminary remarks on the matter, we understand the norms of behavior before entering into the subject. It is key, first and foremost, to recall that these norms do not prevail over international law. It remains essential for maintaining international peace and security in cyberspace. Norms are therefore not aimed at prohibiting actions that would be in accordance with international law. Nonetheless, these norms are valuable as to establishing standards of behavior that are commonly recognized in the use of ICTs. These norms allow for an increase in the predictability and in facilitating cooperation in cyberspace. Therefore, we welcome Sri Lanka, who in their statement noted that the elaboration of voluntary norms for behavior is a precondition for any other normative discussion, including those on a treaty. Therefore, it is essential to pursue our efforts, firstly, to bolster the common understanding of the modalities for the implementation of these norms through, as you proposed, the improvement of checklists or guidance, and to continue, where possible, to deepen and enrich the content of these norms. Allow me now to detail two goals which, according to France, should guide the implementation of the norms we have agreed upon. The first is the cooperative management of cyber incidents, and the second is the regulation of private sector activities. The first goal is the cooperative management of cyber incidents. This approach, that we sometimes refer to as due diligence, is based on two norms in particular in the 2015 GGE report, 13C and 13H. Firstly, France believes that these norms are based on a principle under the sovereignty of states. States are carrying out their competencies with regards to infrastructure which is based on their territories. Therefore, they are responsible for taking adequate and reasonable measures to respond to malicious activities which originate on their territory. This does not mean that states control or monitor all activities over their territory. This is an obligation of means and not results. If a state is notified in good faith of a malicious cyber activity that originates in their territory, they must take reasonable measures to address it. Notifying a state of the fact that a malicious activity is being carried out from their territory in no case constitutes an implicit or indirect form of attribution. This, to the contrary, is a request for cooperation based on the postulate that each state must exercise its sovereignty over its territory. Assistance and capacity building have an essential role to play to bolster the implementation of this norm by assisting states in the development of resources and institutional structures which would allow them to effectively undertake the inherent responsibilities of their sovereignty. This should be one of the objectives of the future Program of Action. Further, we would like to propose that this group elaborate a practical guide that would facilitate the implementation of these two norms, 13C and 13H. Both contribute to a goal of cooperative management of cyber incidents. France will propose with other partners a non-paper on the subject. Second goal, the regulation of private actors. Mr. Chair, France aligns itself with these statements made yesterday. We are not justifying the presence of businesses in our work. In addition, we stress that what justifies the presence of businesses in this group is indeed their right to have their voice heard, but also the responsibility that they have in the implementation of our normative framework. The responsibility is based in three areas. First, the uncontrolled development of cyber by the private sector, which is extremely worrying. It could lead to a risk and escalations in cyberspace. France, during the last open-ended working group, proposed some language which we will circulate through the secretariat once again. The challenge is the unregulated production and commercialization of other tools by the private sector. We believe that in accordance with norm 13I, the states must combat this proliferation, thus the importance of establishing robust export regimes such as that proposed under the Wassenaar Arrangement. And third, and I will conclude with this, the third issue is one I referred to yesterday regarding the quality and security of digital services and products put on the market by businesses. In accordance with norms 13I and J of the previous – the GGE report, states must ensure the development of software, hardware, or the Internet of Things by the private sector takes into account a security goal by design and by default. These goals must be established so that the commercialization of these products does not contribute through their vulnerabilities to extending the scope of attack that is already far too large. This is the goal of the work carried out by the OECD over the past few years and which has led to the publication of recommendations in December 2022 on digital security of products and services. Although this work was under the OECD framework, this work could be useful in creating a UN framework. This is also the goal of a unique regulation being carried out in the European Union called the Cyber Resilience Act, which we hope will allow us to set the global level of ambition for this issue. Thank you.
Ambassador Gafoor
Thank you very much, France, for your statement. I’d like to also ask delegations to please send us your interventions, your text. There are very detailed proposals coming and comments, so we certainly would like to look at them. I would like to look at them carefully, inviting as well. And the interpreters have kindly asked that delegations email their statements to them at estatements@un.org. Estatements, one word, at un.org. Please be kind to the interpreters; they are trying to keep up with your rapid pace of interventions, and if you can, please email the statements in advance. Thank you very much for your cooperation. I give now the floor to Iran, to be followed by South Africa. Iran, please.
Iran
Thank you very much for giving me the floor. Mr. Chair, Resolution 75-240 entrusts the OEWG to prioritize the further development of rules, norms, and principles for the responsible behavior of states and to introduce changes or additional rules if necessary. We note that the norms in the 2015 GGE report are insufficient for regulating the ICT environment comprehensively. Therefore, it is crucial to continue developing a universal, comprehensive list of rules, norms, and principles. The first OEWG Chair Summary Annex proposes additional norms, which highlights the incomplete work on the norms in the past, as recognized in paragraph 80 of the previous OEWG’s final report. We believe that implementing rules of behavior prematurely will not have the expected effect unless they have a universal and obligatory character. In response to your guiding questions, Mr. Chair, we believe that a comprehensive and conflict-free cyberspace requires a set of universal binding norms, and we are persistently supportive of the idea of a legally binding instrument at the global level. The sooner, the better. And in this vein, before any discussion on operationalizing the norms, the OEWG needs to agree on the final and comprehensive list of them. The OEWG should also elaborate on ways to regulate IT companies in the digital sphere and formulate rules for responsible behavior on digital platforms, social media, and networks, as well as the stakeholders. The private sector and social media platforms should observe the rules, norms, and principles of the countries where they operate. States should consider ways to hold them responsible. In addition to our submissions in 2020 during the previous OEWG and echoing some other delegations, we propose the following norms: 1. Enhance the role of states in governing the ICT environment, including policy and decision-making at the global level, while maintaining state sovereignty and respecting states’ rights to make decisions for the development, governance, and legislation models in the ICT environment. 2. Prohibit states from intervening through cyber means directly or indirectly in the internal or external affairs of other states. 3. Condemn and prevent all forms of interventions, interference, or attempted threats against political, economic, social, and cultural systems, as well as the cyber-related critical infrastructure of the states. 4. Prohibit states from using ICT advances as a tool for economic, political, or coercive measures, including limiting and blocking measures against targeted states. 5. Ensure that the private sector, with extraterritorial impacts, including platforms, is held accountable for their behavior in the ICT environment. 6. Hold states responsible for knowingly intervening in the national sovereignty, security, and public order of other states if they fail to exercise due control over their companies and platforms under their jurisdiction and control. 7. Refrain from and prevent the abuse of ICT supply chains developed under their jurisdiction and control to create or assist in the development of vulnerabilities in products and services and maintain compromising sovereignty and data protection of the target states. We need the OEWG to discuss these proposed norms, address any ambiguities in terminology, and make necessary changes while also introducing additional norms to ensure a comprehensive list. I thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Islamic Republic of Iran. South Africa, to be followed by Peru. South Africa, please.
South Africa
Thank you, Chairperson. South Africa believes that maintaining international peace and security in cyberspace is a collective responsibility. We believe that states should use the existing 11 rules, norms, and principles of responsible state behavior in cyberspace in their current incarnation while we consider the possibility of a broader Program of Action. We agree with the first OEWG Chair’s summary, which was included in the 2021 OEWG report, that there is a need to promote awareness of the existing norms and to support their operationalization. This is one aspect that, in our view, can help move our work a step forward through socialization of the voluntary norms for more states to partake in their implementation, thus making the framework universal. We should pursue regular information sharing between states on their experiences in implementing the rules, norms, and principles of responsible state behavior in cyberspace. As a practical step, states that are already at advanced stages of implementation can be encouraged on a voluntary basis to document and share lessons learned to assist those who are yet to commence with implementation to avoid pitfalls and speed up the process. Chairperson, the proposal for an implementation roadmap developed by states could be beneficial in guiding those who are considering implementation on where to start. Without a roadmap, the task can be daunting and slow in progress. As mentioned earlier, the idea of a voluntary survey for the sharing of lessons and good practices can be pursued in an endeavor to assist states who are willing to implement the norms but find the task overwhelming in the absence of guidance and the necessary capacity. The development of new norms should not detract from the implementation of existing norms. The further development of norms, rules, and principles should be understood as a process of evaluating, updating where necessary, and refining rather than seeking to develop a completely new set of norms. Thank you.
Ambassador Gafoor
Thank you, South Africa, for your statement. Peru to be followed by Argentina.
Peru
Thank you, Chairman. Since this is the first time I’m taking the floor, I’d like to thank you and express the support of Peru for the way in which you’ve been conducting the work of this Open-Ended Working Group, both in the official meetings and during the intersessional periods. In particular, we’d like to highlight the advances towards the establishment and functioning of a global directory of points of contact as a way of promoting confidence that will also serve as a framework for the implementation of other measures. The directory of points of contact is a clear demonstration of how the Open-Ended Working Group is geared towards action. Action towards promoting an open, stable, secure, accessible, and peaceful environment for technologies, information, and communication, and to promote responsible behavior by states. Mr. Chairman, we have no doubt that the development of rules, norms, and principles of responsible behavior by states is essential. This is recommended in the reports of the Open-Ended Working Group of 2021 and in the reports of the Groups of Governmental Experts. But their voluntary, non-binding character makes it necessary that they should be compatible with international law and with the purposes and principles of the UN Charter, including the maintenance of international peace and security and the promotion of human rights and international humanitarian law. Now, international law, in effect, in addition to the voluntary norms that reflect the will of states, could be sufficient in addressing the challenges related to ICTs. However, due to the rapid evolution of threats and risks, we believe that it’s important to have a legally binding international legal framework that makes it possible to more effectively implement international obligations, and that is a stronger basis for accountability. Mr. Chairman, until we achieve a legally binding framework in the voluntary phase, Peru thinks that it’s necessary to develop additional norms. The development of these norms and the implementation of existing norms could take place simultaneously. Also, we believe that it’s important for states to conduct voluntarily a study or report on the implementation of voluntary norms, principles, and rules on responsible behavior as well as a report on implementation. Also, states should examine the best way to cooperate to exchange information, provide mutual assistance, and implement additional cooperation measures to confront existing threats and to confront vulnerabilities related to ICTs. The elaboration of new measures on this point is essential. States must take appropriate measures to protect critical infrastructure in the face of threats related to ICTs. Also, states should not carry out or support any ICT activity that damages or undermines intentionally the use or functioning of critical infrastructure of other member states, thus contravening international law. Mr. Chairman, lastly, I’d like to highlight the important role that regional and subregional organizations can continue to play in implementing the norms of responsible behavior by states with regard to ICTs. Furthermore, regional and interregional exchanges could open up new ways of cooperation and mutual learning to avoid conflicts and to contribute to the peaceful use of cyberspace. Thank you very much.
Ambassador Gafoor
Thank you very much, Peru. Argentina, to be followed by Egypt. Argentina, please.
Argentina
Thank you very much, Mr. President, for giving us the floor again. We will be brief. Of the framework on regional cooperation, and this is a vital aspect for generating trust, transparency, and inclusion among member states that share, in most cases, similar levels of digital development. In this context, the imbalance in the international sphere requires a robust debate on the creation of consensus on responsible behavior by states. A rules-based order has a systemic benefit because it increases stability and transparency for the whole international community. This is why Argentina bears in mind that while each state belongs to a different region characterized by different threats, we all share similar threats and risks that impact all of us due to the global and transnational character of cyberspace. Therefore, and due to the rapid development of cyberspace, the delegation of Argentina considered it necessary to continue discussing and exchanging ideas on possible new norms of responsible behavior. Argentina would consider it valuable to hear the vision of various international organizations and other stakeholders on emerging technologies, on the threats that could appear in cyberspace, and options for responses to these threats. We’d like to express – examine the possibilities of including this in the intersessional agenda of the Open-Ended Working Group. Regarding your question on the capacities required for the implementation of the framework, Argentina is a developing country. We’d like to highlight the importance of the pillar on capacity building that we will debate in the next few days. The creation of capacity is a broad topic that includes infrastructure and other aspects. This is why we must identify specific areas, which of course depend on the specificities of each state. Now regarding this pillar and answering one of your questions, Argentina considers that training for decision-makers for the creation of effective public policies and raising awareness of the population and governmental action with regard to protection and mitigation is very important. Both – these are essential for effective implementation. For example, I’d like to highlight that Argentina is in the process of updating its national strategy of cybersecurity that we submitted for a public consultation that we have concluded, and we hope to be able to approve it soon. In this context, we are examining this. Bearing in mind everything I’ve said, Mr. Chairman, the delegation of Argentina continues to promote work on the development of a normative framework, of course updating it with the necessary inputs and evaluating the creation of new norms that are in line with the development of new technologies. These are very challenging and could be threatening for international peace and security. On this point, my delegation promotes the participation of experts in the Open-Ended Working Group as well as the exchange of experiences with the purpose of sharing a practical vision on certain topics, especially such complex topics as artificial intelligence and others. The speaker read her text at top speed without providing it to the interpreters.
Ambassador Gafoor
Thank you very much, Argentina. I think the interpreters are once again making an appeal for you to share your statements with them because many of you read your statements very rapidly. Let’s be kind to our interpreters. At the UN, they play a crucial role. We can’t build bridges without interpretation, so I also thank the interpreters once again for their work. Let’s continue with the speakers list. Egypt to be followed by Singapore. Egypt, please.
Egypt
Thank you, Mr. Chairman. Mr. Chairman, with regard to rules, norms, and principles of responsible state behavior by states for the use of ICT in the context of international security, Egypt would like to point to the following. First, we understand relevant challenges with regard to developing new norms, rules, and principles, and we recall that developing the normative framework of responsible behavior in the use of ICT does not run counter to developing new principles and norms to bridge the current gaps at the international level. We also believe that we need to raise the level of these norms from recommendations that countries can adopt voluntarily to a higher level of international political commitment, and therefore, in view of the new and fast developments of the use of ICT as well as the different nature of various regions in the world, the purpose is to prompt states to commit to these rules. Egypt believes that we can actually promote the two tracks simultaneously, the first with regard to application and the second track is the development of rules and norms. Egypt believes in the usefulness of putting norms and systems on the non-use of ICT in violating the security of other states. Egypt stresses the importance of heeding the non-restriction of any legitimate activities of states in line with international law or to obstruct the state’s roles in the peaceful uses of ICT, or the use of international cooperation and transfer of technology, or prescribing that certain technologies are a threat to international rules. This is while we are in the process of developing the new norms. With regard to developing an international legally binding agreement on the use of ICT, Egypt would like to support in principle drafting a convention in this regard, provided that such a convention be comprehensive, balanced, and effective, and provided that it enjoys the support of all states, particularly influential states in the field of cybersecurity. Egypt is flexible with regard to negotiating and consulting member states on this proposal. Thank you, sir. Thank you, Egypt. Singapore to be followed by the Netherlands. Singapore, please. Thank you, Mr. Chair. We recall that the Annex of the Chair Summary of the 2021 Open-Ended Working Group Report contains proposals by many states on strengthening the protection of critical infrastructure and welcome the opportunity to address your guiding questions on this topic. One area of critical infrastructure protection that Singapore believes requires further attention is the protection of cross-border CIIs that provide services across borders or jurisdictions, such as the SWIFT financial system and the Amadeus flight booking system. These CIIs are critical to international trade, financial markets, global transport, communications, health, or humanitarian action. Disrupting or undermining the operations of these CIIs is likely to impair the delivery of critical services to populations and may have serious implications for international peace and security. We look forward to having further discussions within the OEWG on possible proposals to improve cooperation between states on strengthening the protection of these cross-border CIIs. We also recall the proposals in the Annex of the Chair Summary on protecting the technical infrastructure essential to the general availability or integrity of the Internet. Such technical infrastructure, such as DNS, the Domain Name System, or Internet Exchange Points, are important for developed and developing states alike, given the increasing reliance of all states on ICT-based technologies. We support further discussion within the OEWG on possible measures that can be taken to ensure the general availability or integrity of the Internet. Turning now to the development of guidance and checklists, my delegation would like to underscore the importance of linking the implementation of each norm to specific capacity-building initiatives and activities that facilitate its implementation. Such tagging would provide a useful reference to small and developing states in prioritizing the norms to focus on first, and clearly mark out the capacity-building activities that states would need to identify and participate in while managing limited resources, time, and talents. The ASEAN region has embarked on this initiative to identify and tag capacity-building initiatives to specific norms following guidance from Cybersecurity and Digital Ministers who met at the 7th Annual ASEAN Ministerial Conference on Cybersecurity held in Singapore last year. This effort to tag capacity-building initiatives to specific norms will build on the ongoing work at the ASEAN Regional Action Plan Matrix on the implementation of norms, which was co-developed by Singapore and our colleagues in Malaysia in 2021 to guide the regional implementation of the 11 voluntary non-binding norms of responsible state behavior in the use of ICTs. Since then, the Regional Action Plan has been endorsed at the 2nd ASEAN Cybersecurity Coordinating Committee in November 2021 and remains a living document that can be reviewed and updated when required. Singapore believes that it would be useful to have a similar norms implementation checklist at the international level endorsed at the UN to serve as a guide for all countries. Such a norms implementation checklist, listing out the policy, operational, technical, and diplomatic actions that states can take to concretely implement these norms, would be a significant milestone and achievement in helping move forward norm implementation. This is in line with paragraph 23 of the Chair’s Summary in the 2021 OEWG Report, which proposed a roadmap developed by states to assist in norm implementation efforts. Singapore is working with UNODA under the United Nations Singapore Cyber Programme to develop such a global norms implementation checklist. The checklist is envisioned to constitute a simple guide for a set of actions that developing countries could take towards implementing the 11 voluntary non-binding norms. Singapore plans to develop this global norms implementation checklist through a series of cross-regional workshops. Two of these workshops have already been conducted on the sidelines of the OEWG substantive sessions in March and July 2022 to explore norms G, J, and K. We look forward to continuing organizing these workshops to explore the other norms of responsible behavior and to include other regional perspectives in these workshops. Singapore looks forward to the support and collaboration with international partners on the development of this norms implementation checklist, which could establish a strong foundation in the norms implementation work stream at international cyber disciplines.
Ambassador Gafoor
Thank you very much, Singapore, for your statement. Netherlands, to be followed by Costa Rica.
The Netherlands
Thank you, Chair. The Netherlands aligns itself with the statement to be delivered by the European Union, and I would like to add some additional remarks in a national capacity. The 11 norms for responsible state behavior promote predictability and reduce risks of misperceptions between states. At the same time, and this is of vital importance to the Netherlands, the norms also help to protect citizens, particularly those in vulnerable situations. In exchanging views on rules, norms, and principles of responsible state behavior in cyberspace, it is important to note that we are building on previous work on this topic, endorsed by the General Assembly by consensus. The Netherlands considers norms to be complementary to international law. Norms do not replace or alter states’ obligations or rights under international law, which are binding, but rather provide additional specific guidance on what constitutes responsible state behavior in the use of ICTs. The 2021 GGE report provided an additional layer of understanding to the 11 voluntary non-binding norms of responsible state behavior. This underscored the value of expected responsible state behavior and provided practical measures for their implementation. In this context, let me reiterate the importance of capacity building to enable all states to implement the norms in their national context. We see this as one of the main purposes of the Program of Action and believe the Program of Action could build on existing work being done to operationalize the normative framework, including the 11 norms, making use of the UNIDIR survey of national implementation and the Singapore UNODA norms implementation checklist. Chair, the Netherlands has consistently emphasized the importance of norms for the protection of critical infrastructure. That is why the Netherlands has actively contributed to developing an additional layer of understanding to the norms, including the norms related to critical infrastructure. While it remains up to states to determine which infrastructure is critical, previous OEWG and GGE consensus reports made reference to the healthcare sector, the technical infrastructure essential to the general availability or integrity of the internet, and electoral processes as examples of critical infrastructure. From the Netherlands’ perspective, it was important to highlight these sectors in response to the evolving threat landscape and the strong dependency on these infrastructures for states, economies, development, political and social functioning, and national security. Chair, in my intervention under threats, I highlighted the growing threat posed by the indiscriminate or reckless use of ICTs that causes harmful spillover effects on the critical infrastructure and essential services. To address this threat, the Netherlands would like to put forward proposals for additional guidance on norm F, which sets out that states should not conduct or knowingly support ICT activities on critical infrastructure. Firstly, the open-ended working group should call on states to actively consider the potential risk of indiscriminate uses of ICTs and the potential harmful spillover effects that such uses may have on critical infrastructure and essential services of another state. Secondly, building on paragraph 46 of the GGE report, the OEWG could also encourage states to take appropriate steps to incorporate such considerations in institutional arrangements and national decision-making processes in the development and use of ICTs as part of their commitment to be guided by the emerging and evolving framework for responsible state behavior endorsed by all UN member states. As I mentioned in my intervention on threats, we will share a working paper on this topic in due course. I would also like to draw the attention of the group to the norm stating that states should not knowingly allow their territory to be used for internationally wrongful acts against another state. The 2021 GGE report set out that this norm raises the expectation that a state will take reasonable steps within its capacity to end ongoing activity in its territory through means that are proportionate, appropriate, and effective in a manner consistent with international and domestic law. At the same time, and I would like to stress this point, the GGE agreed that it is not expected that states could or should monitor all activities within their territory. The 2021 GGE provided further guidance on this norm that is of particular relevance to our work on confidence-building measures, that an affected state should notify the state from which the activity is emanating. The notified state should acknowledge receipt of the notification to facilitate cooperation and clarification and make every reasonable effort to assist. In our view, the APR could recommend the establishment of effective channels, allowing states to communicate requests for assistance or ask for clarification in case of a significant cyber incident. The POC directory could be an effective tool in this regard. Also, the exchange of best practices regarding national approaches for responding to such requests for assistance would further contribute to a better implementation of the norm. This all enhances confidence building and could therefore be reflected in the APR. Thank you, Chair.
Ambassador Gafoor
Thank you, Netherlands. Costa Rica, to be followed by the Syrian Arab Republic. Costa Rica, please.
Costa Rica
Thank you, Mr. Chairman. On the need for implementation of existing norms, Costa Rica considers that we should focus on implementing the agreed 11 norms. In addition, the development of any new norms must be inclusive of all stakeholders and should respect all rights. This should be done in an open and inclusive way. It should be human-centric and should be respectful of rights, including by mainstreaming a gender approach. For example, in developing policies to implement the agreed norms, governments should integrate gender perspectives at all stages of the policy-making process. Another important point that I’d like to emphasize is the role of all relevant stakeholders, including civil society, in supporting states’ efforts to implement the agreed norms. Civil society plays a key role in the implementation of cyber norms by producing research, developing cyber capacity building, and monitoring their implementation. States should refer to the norms adopted when they perceive that they have been undermined or violated in order to strengthen the understanding of these norms. There must be an open and transparent process with the affected parties to repair the damage and to guarantee that there will be no repetition of these illegal acts. For instance, the use of spyware by state actors against human rights defenders and journalists violates the agreed norms, including the human rights norm. This is why Costa Rica has called for a moratorium on spyware technology, as have UN human rights experts. To implement the norms, states should also work together to provide mutual guidance on the norms, on how they are interpreted, and how they can be implemented. For example, relating to the norms on critical infrastructure, states can share how they define or what they designate as critical infrastructure. States should also share how they’re implementing the norms, including efforts to mainstream gender perspective in their implementation. Costa Rica also supports the proposal related to states conducting surveys or voluntarily reporting on their national implementation of rules, norms, and principles of responsible state behavior, utilizing existing avenues and tools, such as the National Survey of Implementation, as contained in the recommendations of the 2021 Open-Ended Working Group Report. Thank you.
Ambassador Gafoor
Thank you, Ambassador, for your statement. I now give the floor to the Syrian Arab Republic, to be followed by Germany. Syria, please.
Syria
Thank you, Mr. Chairman. Mr. Chairman, my delegation believes that the current context for principles and norms of responsible states’ behavior can contribute to limiting the risks of harming peace and security at the international level. However, given the unique characteristics of the ICT environment and the quick development of the threats in that field and the risks it entails, we believe that there is a need to develop more cooperative measures in this field while keeping open the possibility of developing a binding international instrument to challenge and face up to the illegal uses of ICT. First, we believe that the normative framework of states’ conduct is not comprehensive and fails to address all aspects that would challenge the effective use of ICT for illegal purposes. Therefore, this is more of a political instrument than a legal one. The two processes of developing additional criteria and the implementation of existing ones while introducing some changes do not represent two separate processes that are mutually exclusive. They can happen simultaneously, and they could constitute a full checklist of criteria that would contribute to a binding international agreement in the field of ICT. Three, there is a difference in points of view even among parties that support the current framework of responsible behavior by states on the way of implementing criteria included in such a list and the impact of their implementation. Fourth, the checklist of responsible behavior does not provide a clear vision on the threshold of use of force and the legal description of the use of force in cyberspace. Finally, given their voluntary nature, member states implement the norms of responsible states according to their national priorities and their capabilities, making this not sufficient for commitment, and therefore they are not an alternative to commitments by states under international law that guarantees alone the international and effective implementation worldwide and that builds a more firm accountability framework. Therefore, my delegation believes that an effective and comprehensive approach to challenges in cyberspace requires that we work on an internationally binding instrument. Thank you for your attention, sir.
Ambassador Gafoor
Thank you, Syria, for your statement. I now give the floor to Germany, please.
Germany
Thank you, Mr. Chair. Germany is fully aligned with the statement of the European Union and wishes to make a couple of remarks in a national capacity. It is Germany’s position that the focus of the Open-Ended Working Group on rules, norms, and principles should be on ways to advance the implementation of the already existing international framework of responsible state behavior. Germany is taking this line because of the significant gaps and deficits we are seeing with implementation, both with regard to international law and UN norms, and with UN confidence-building measures being at an advanced but early stage of elaboration. Germany welcomes opportunities for further dialogue on the implementation of existing rules, norms, and principles, but sees little merit in formalizing this with the development of additional guidance or checklists. The already existing mechanisms for checking and reporting implementation, such as the UN ODA Norm Implementation Checklist and the National Survey of Implementation hosted by UNIDIR, provide well-designed and transparent tools open to all UN member states. Germany is happy to make active use of them and encourages all members of this working group to do so as well. Germany is concerned to hear that a possible treaty process is mentioned at this stage of discussions by the Russian Federation. As stated before, we have already reached a common understanding that international law is fully applicable in cyberspace. We are currently in the second phase of discussions on how international law is applied in cyberspace. Germany is convinced that continued focused discussions on the modalities of the application of international law in cyberspace would clarify that there are no substantial legal gaps that would justify a treaty process or render such a process necessary. Nor can we agree with the position of the Russian Federation that state accountability depends on agreeing on a new treaty. This statement is dangerous. It creates the impression that today’s cyber operations by states take place in a legal void. This is not true. International law as it stands provides a robust and comprehensive framework, and this clearly includes the customary law rules on state responsibility. The Russian Federation must expect to be held accountable for the extensive military use of cyber instruments in its war against Ukraine, which have caused massive damages to the civilian population, an unclear breach of international law, and the existing framework of responsible state behavior. Thank you.
Ambassador Gafoor
Thank you for your statement. I give the floor now to China.
China
Thank you, Chair. China is of the view that under the current situation, the issue of norms is the most important and urgent one. All countries should step up their efforts to stabilize the stock and promote incrementality. As far as the stock is concerned, the normative framework of responsible state behavior represents a hard-won major consensus achieved during the UN process and should be implemented in a comprehensive, complete, and accurate manner. We regret to see that even before the ink dried on the 2021 GGE and OEWG consensus report, a certain country chose to disregard the consensus on developing and implementing globally interoperable common rules and standards for supply chain security. Driven by natural geopolitical interests, this country deliberately created an exclusive clique to discuss supply chain issues to defend its hegemonic monopoly, thereby depriving other countries of their right to development, all in the name of democracy. Therefore, during the third session last year, China took the lead in proposing that all parties should abide by, rather than merely implement, the framework of responsible state behavior and such language be included in the annual progress report, hoping that all countries, especially major countries, would take concrete actions to earnestly safeguard the framework of responsible state behavior. As far as incrementality is concerned, in light of the evolving cyberspace landscape and technological development, new rules should be made on an ongoing basis. The relevant G-resolution has mandated this group to continue discussing risks and challenges related to inter-area data security and measures. Yesterday, we heard Iran, the Russian Federation, Chile, Sudan, Syria, and Timor-Leste; these colleagues all referred to the current flaring up of data security risks. Issues such as cross-border data flows and personal information protection have triggered widespread concern in the international community. Countries urgently need to strengthen dialogue and exchanges and develop global rules on data security. Based on the discussions at multilateral forums, including the UN, and practices of various countries in the area of governance, China took the lead in proposing the Global Data Security Initiative and concluded with the Arab League and five Central Asian countries, the China-Arab League Cooperation Initiative on Data Security and China-Central Asia Cooperation Initiative on Data Security, respectively. We uphold openness, inclusivity, and mutual learning, welcome all parties putting forward useful proposals on these initiatives, and jointly promote global rules of digital governance that reflect the wishes and respect the interests of all parties on the basis of these aforementioned initiatives. Second, a plethora of complex factors has undermined security and stability. As Egypt and Iran have mentioned, the security and stability of the global supply chain have been undermined by these factors. According to a consensus as contained in the 2021 GGE report, the current OEWG should discuss the development of global interoperable common rules and standards for supply chain security so as to effectively safeguard the common interests of all countries. Third, all countries should explicitly commit to nonproliferation of offensive cyber technology and develop relevant rules and norms on this matter.
Ambassador Gafoor
Thank you, China, for your statement. Distinguished delegates, we have about 13 other speakers who have registered, so we will have to continue our discussions this afternoon. I know we are a little behind schedule, but given the fact that this particular item of the agenda on norms, rules, and principles of responsible behaviour, this discussion has already in some ways touched on some aspects of international law, so the subsequent agenda item is also embraced to some extent. So hopefully we can catch up by the end of the day with our programme of work. On that note, we’ll adjourn the meeting now and we will resume at 3 p.m. to continue discussions on this item. Have a pleasant lunch. Thank you.
Leave a Reply