Session 4-9 Transcript
(OEWG 2021-25)

Home » Resources » UN Open-ended Working Group (OEWG) transcripts » Session 4-9 Transcript(OEWG 2021-25)
Ambassador Gafoor

Delegates, good morning. The ninth meeting of the fourth substantive session of the Open-Ended Working Group on ICT Security, established pursuant to General Assembly resolution 75-240, is called to order. Mr. Miss Delegates, I wanted to give an update as to where we are on the program of work. We have one day left, and it’s my intention to use every available time today to finish all the work that we need to do and to give everyone an opportunity to make their contributions today. If you look at the program of work, it’s clear that we are in some ways behind schedule, but at the same time, in the program of work, the last session, which is 3 p.m. to 6 p.m., is designated for the closing of the session, which in essence is concluding remarks by the Chair. So in effect, we have the entire afternoon as well. So I intend to use this meeting till 6 p.m. this evening, if needed, in order to allow everyone the opportunity to make their contributions. I do not want any of you to leave with the sense that you had wanted to say something and make a contribution, but you were not able to do so because of time constraints. So I want to first of all assure you that we will have the time to go through the issues, and we are not, in that sense, behind schedule. Second, I did say yesterday that we would start with the revised POC directory, and I was reflecting on the question yesterday evening. I would suggest that we start with a discussion on regular institutional dialogue this morning, as this is an issue on which we have not yet had any discussion. So it is my intention this morning to proceed straight into regular institutional dialogue, which in a sense means we catch up with the program of work, because we are scheduled to discuss regular institutional dialogue this morning. And after the discussion on regular institutional dialogue, we will go through a few issues that I would like to raise, and we will also go through the revised POC directory. For the revised POC directory, I am not looking for a repetition of the comments I heard last week. I would like very precise, specific comments that add to the value of the revised paper. So that is the program of work, if you like, for this morning and today. And so before we begin with the discussion on regular institutional dialogue, I want to say a few things. Firstly, regular institutional dialogue is part of the agenda and mandate of this working group under Resolution 75-240. So it is an important part of our work. Secondly, I would like to draw your attention to the questions that I had circulated, and please look at the questions that I circulated not only as part of the revised program of work, in which there are two questions, but also the questions on the POA, which were circulated in November as part of the consolidated list of questions, in which I had also asked questions relating to the POA Program of Action. I don’t need to read the questions to you. So in the questions I had circulated on the 22nd of November, there was a specific question. There are two specific questions. How do we ensure that discussions on ICT security continue in an inclusive manner with the broad participation of all member states? And second, in considering the proposal for a Program of Action with a view towards its possible establishment as a mechanism, how do states understand its relationship with the OEWG? And in what specific ways can the POA complement the ongoing work of the OEWG? So I draw your attention to those two questions, plus the two questions that were circulated on the 3rd of March with regard to regular institutional dialogue. I would like your response to that. The other thing I would draw your attention to is the annual progress report. In the recommendation on regular institutional dialogue, we all agreed that we will continue exchanging views on regular institutional dialogue and that we will continue to engage in focused discussions within the framework of the OEWG to further elaborate the POA with a view towards its possible establishment as a mechanism to advance responsible state behavior in the use of ICTs, inter alia to support the capacities, etc. And states will also engage in focused discussions on the relationship between the POA and the OEWG and on the scope, content, and structure of a POA. So distinguished delegates, these are the points that I wanted to remind you of and refer you to as we begin these discussions. The last point I wanted to make as Chair of the OEWG is that it is my hope and my determination that we reach convergence not only on all the other issues, but also on the issue of regular institutional dialogue. It is also my hope and determination that we reach convergence on the specific issue of how the POA relates to the discussions in the OEWG on regular institutional dialogue. So I look at this issue as a very important issue, and as Chair of the OEWG, I will do my very best, like in any other issue, to find convergence on regular institutional dialogue and in that context the proposal that has been put forward on the idea of a Program of Action. So I wanted to make that very clear, but ultimately not just on this issue, regular institutional dialogue, but on the other issues, convergence is not something that can be imposed from the podium. It’s in your hands. So on that note, I open the floor now to have this discussion on regular institutional dialogue. And I’m all ears, so the floor is open. European Union, you have the floor, please. Thank you.

Thank you very much. I have the honor to speak on behalf of the European Union and its member states. North Macedonia, Montenegro, Serbia, Albania, Ukraine, the Republic of Moldova, Bosnia and Herzegovina, Georgia, Iceland, Norway, Monaco, and San Marino aligned themselves with this statement. The EU and its member states are committed to advancing the discussion on the regular institutional dialogue and stand ready to engage with a positive approach in an effort to make constructive progress, which builds on the existing UN consensus grounded in the application of existing international law and norms of responsible state behavior in cyberspace. The Open-Ended Working Group provides the opportunity to benefit from the multilayered expertise and experience of states and stakeholders interested in contributing to the discussions. However, it should be acknowledged that efforts to limit the participation of non-state stakeholders may affect the stakeholders’ future contributions to the implementation of the agreements put forward by the Open-Ended Working Group. The private sector, academia, and NGOs are crucial for following through with the agreements and their implementation on the national, regional, and international levels. In particular, the 2019-2021 Open-Ended Working Group concluded that any future regular institutional dialogue should be an action-oriented process with specific objectives, building on previous outcomes and being inclusive, transparent, consensus-driven, and result-based. Multistakeholders have a key role to play in this. In this vein, the EU supports the proposal to establish a Program of Action to advance responsible state behavior in cyberspace, which will allow us to, in complementarity to the Open-Ended Working Group, advance the practical work on implementing the UN framework. Let me recall once again that one of the main objectives of the POA is to enhance multistakeholder engagement that would allow for regular consultations with relevant stakeholders, including the private sector, academia, and civil society, to consider and provide their unique perspectives on relevant issues. Enhancing multistakeholder engagement would also be relevant insofar as non-governmental actors, including the private sector, have a responsibility to contribute to the effective implementation of some aspects of the framework. We also believe the POA could provide a permanent, inclusive structure to support states in their efforts to implement the framework. To that end, it would encourage voluntary reporting by states on their national implementation efforts to map the needs and challenges they face. The POA would foster exchanges of best practices and expertise on the identified challenges. On this basis, the POA would aim to provide support for tailored capacity-building activities to address the needs and challenges identified by states in their efforts to implement the framework. To that end, it would seek to leverage relevant existing initiatives and build on existing capacity-building structures and platforms. It would also seek better coordination, for example, via regular briefings with capacity-building activities carried out in other institutions, each within the scope of the mandate. The POA should also be flexible enough to allow states to address new threats and further develop the normative framework on the basis of consensus, if appropriate. Many delegations have recalled this week that while support for the implementation of the existing framework is urgently needed, new norms may also be developed over time, if needed. The POA could hold regular meetings or review conferences to update the framework as appropriate. In the same vein, we would also like to encourage states to submit their national contributions to the UN Secretary-General’s report with the proposals regarding the POA’s possible structure and content and probable way forward for its preparatory work and establishment. Furthermore, a dedicated session on the POA in 2024 would give all states the opportunity to engage in focused, inclusive discussions on the further elaboration of a POA, including by voicing their expectations and potential concerns. Thank you for the consideration.

Ambassador Gafoor

Thank you, European Union. CĂ´te d’Ivoire, followed by Pakistan. CĂ´te d’Ivoire, please.

CĂ´te d’Ivoire

Thank you, Chair. As this is the first time that my delegation is speaking since the start of this session, allow me to express my gratitude to you for your exemplary organization of our work and for all of the efforts that have been made to effectively implement the mandate of this working group. The importance placed by my country on cybersecurity has been reflected for over a decade in our various national measures. It has culminated in the adoption on December 22, 2021, of a National Cybersecurity Strategy 2021-2025. CĂ´te d’Ivoire’s international commitment on the issue at the United Nations, and in particular as part of the Open-Ended Working Group on cybersecurity and its use, is clearly reflected in this strategy. It was adopted just after our first substantive session, and its implementation period is aligned with the duration of this group’s mandate. The symbolic timing of these events is a clear reflection of our unwavering commitment to the OEWG and of the interest of my country in discussions as part of this group. This is also attested to by our full support of the first annual report in 2022. Distinguished Chair, in December 2022, CĂ´te d’Ivoire co-sponsored Resolution 77-37 on the Program of Action to Advance Responsible State Behavior in the Use of Information and Communications Technologies in the Context of International Security. This new international commitment of my country can be explained first and foremost by the fact that we certainly do not view this Program of Action as a contradictory mechanism that duplicates the work of the OEWG. Rather, for us, it is part of the continuity and complementarity of the OEWG’s discussions, which grant it its legitimacy and its basis. The second reason for which my delegation supports the implementation of the POA is our belief that, together with the OEWG, it will help strengthen the driving force, the role of the United Nations in security, and the use of ICTs, which is a necessary precondition to promote this priority. Moreover, the POA is an additional response to continuing and deepening regular institutional dialogue. As part of this group, we have already recognized and promoted the need for this dialogue in our work. Moreover, in the face of increasing security challenges related to the changing properties and characteristics of digital technology, the establishment of a permanent, inclusive, action-oriented mechanism could only help strengthen the existing framework developed to be able to adapt and change with respect to our responses over the course of time. This is why we believe that the POA should be supported in defining its objectives and the specific results which we wish to achieve, as well as in its operations, its monitoring mechanism, and it can be modeled on the POA on small arms and light weapons. Distinguished Chair, my delegation is particularly supportive of including capacity building for developing countries as a key pillar of the POA. The goal would be to foster a better understanding of their needs, to enhance their ability to respond to cybersecurity incidents, and finally, to strengthen their capacity, the capacity of all states, to engage in responsible state behavior, which is our ultimate goal. In conclusion, my country would like to reaffirm its lasting commitment as part of the OEWG on security of and in the use of ICTs and calls for discussions moving towards a collective shared vision based on the POA and the modalities for its implementation. Thank you.

Ambassador Gafoor

Thank you very much, CĂ´te d’Ivoire. Pakistan, to be followed by the Islamic Republic of Iran.

Pakistan

Thank you, Chair. Pakistan maintains a consistent and clear position on the topic of regular institutional dialogue. We propose that the key principles that should be considered in the formulation of future platforms for discussions on ICTs must include inclusivity, consensus-driven decision-making, multistakeholder participation, global collaboration, and sustainability. Pakistan believes that the future institutional dialogue must also include in its mandate the topics of capacity building, norms building, and discussions on the application of international law in cyberspace. Furthermore, we hold the view that this dialogue should take place under the auspices of the UN. It is essential to emphasize here that at this stage, there is no need to create any parallel structure to the existing OEWG. We firmly believe that the existing OEWG is the most appropriate forum for all discussions related to the TORs and mandate areas of any future platform, including the Program of Action (POA). Pakistan’s decision to abstain from the resolution on the POA is driven by our belief that any mechanism or structure created after the existing OEWG in 2025 must be built on sustainable foundations and developed through a consensual process. Therefore, the existing OEWG provides an ideal platform for such discussions. We advocate for a collaborative and all-inclusive approach for the POA, which would ensure its effectiveness and long-term sustainability. Taking this opportunity, I would like to renew, Chair, Pakistan’s support for this intergovernmental process for a safe, secure, and stable cyberspace. We believe that the success of the OEWG process depends upon equal and all-inclusive participation of all member states. I thank you, Chair.

Ambassador Gafoor

Thank you, Pakistan, for your contribution. The Islamic Republic of Iran to be followed by the Russian Federation. Iran, please. Thank you, Mr. Chair.

Iran

Mr. Chair, according to Resolution 75-240, which was acknowledged by Consensus Resolution 76-19, establishing a regular institutional dialogue with the broad participation of States under the auspices of the United Nations is one of the key mandates of the current OEWG. Paragraph 77 of the 2021 OEWG and Paragraph 18B of the ATR acknowledge that a variety of proposals for advancing responsible State behavior in the use of ICTs were put forward. According to the first annual progress report recommendation, States should continue exchanging views at the OEWG on regular institutional dialogue and on the proposals by States to facilitate regular institutional dialogue on the security in the use of ICTs. Therefore, the Program of Action should be discussed within the OEWG on an equal footing with other States’ proposals. Mr. Chair, it is our well-known position that replacing the model of the UN POA on small arms and light weapons, which has not yet proven its effective value in preventing, combating, and eradicating illicit trade of arms, does not serve the purpose of ICT security. Procedural approaches such as POA are inherently challenging and, instead, we should move towards legally binding instruments on cyber security. Such a legally binding framework would lead to more effective and global implementation of commitments and a strong basis for holding actors accountable for their actions. Mr. Chair, in response to your guiding question, we believe that any future mechanism for regular institutional dialogue on ICT security within the UN should be intergovernmental, consensus-based, democratic, transparent, and non-political, and should take into account the concerns and interests of all States through equal State participation in a fair and balanced manner. It would also be essential to resume the practice of paragraph-by-paragraph negotiation exercise on any outcome document on the regular institutional dialogue in the field of ICT security. Interaction with non-State actors within the future body should be consultative and informal. Only accredited non-State actors will be able to participate upon invitation and without the right to vote in formal sessions as observers. I thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Islamic Republic of Iran, for your contribution. Russian Federation, to be followed by Denmark. Russian Federation, please.

Russia

Mr. Chair, distinguished colleagues, UN Resolution 77/36 highlights the importance of continuing democratic, comprehensive, transparent, and result-oriented discussions as part of the OEWG. It recognizes the central role of the OEWG as a body operating under the UN, a mechanism for supporting intergovernmental dialogue on international information security. Most countries have voted in favor of this document because their interests are aligned with the idea of consensus in decision-making. It helps us promote the information sovereignty of all member states and to stop decisions from being made that would contradict their national interests. In line with item 5 in the resolution, the Russian Federation would like to submit a proposal on regular institutional dialogue on ICT security, which will be launched upon the completion of the work of this OEWG. We will provide the corresponding conceptual note to the group’s secretariat with the request for it to be published on the OEWG website. We are basing this on the idea that the foundation of future dialogue will be based on the following principles: 1. The leading role of the UN in promoting dialogue on ICT security. 2. Alignment with the principles enshrined in the UN Charter – that is, sovereign equality among states, not using force, and the peaceful resolution of international disputes. 3. Decision-making on the basis of consensus only by states. 4. Avoiding duplication of international efforts aiming to ensure ICT security on several negotiating platforms. 5. Continuity with respect to updates and recommendations of previous expert groups and OEWG. Given the need in the international community for creating a permanent mechanism on ICT security within the UN framework, the new body could work as part of the GA in the format of an open-ended working group, a commission, a committee, or a review conference. It would be useful to consider future changes that may be made to it in the future based on the changing needs of states and the appearance of new challenges in ICT security. The mandate of the future body should include the entire spectrum of issues related to ICT, and it should be oriented towards the practical implementation of agreements reached at the OEWG related to all aspects of this agenda. Specifically, the mandate can include the following powers: 1. The practical implementation of rules, standards, and principles for responsible state behavior developed by the OEWG by developing a draft of a legally binding international instrument, ensuring international information security, aiming to eliminate gaps in international law that prevent us from regulating the activities of states in the global information space. Also, it needs to enshrine the need to improve standards in international law while accounting for the specific qualities of ICTs. 2. Implementing confidence-building measures by creating mechanisms for practical cooperation between states, including through established channels for dialogue of authorized bodies or structures in order to combat threats to ICT security and to prevent intergovernmental conflict in the international information space. Creating mechanisms for supporting states and increasing their ability to protect their national information resources while accounting for their specific needs. It would be helpful in the future body to consider how decisions will be implemented as they are agreed upon in the format of independent reports without there being a specific requirement for their adoption in terms of timeline. We need to take specific measures to continue to promote a permanent information exchange among states through the corresponding electronic portal. It would also be useful to arrange for the cooperation between this body and regional organizations and structures in the format of consultations between the chairman of the body and groups of countries and also as part of inter-sessional sessions organized annually with the representatives of regional organizations. As part of the work of the future body, the role of non-state actors should be consultative and informal. For example, in the format of inter-sessional meetings conducted once a year, the right to participate in official events as an observer can only be granted to accredited organizations, accredited non-governmental organizations. That means they must be approved by the states. The need for this kind of dialogue is particularly relevant given the attempt made by some states to replace the OEWG, the OEWG POA, in accordance with Item 1 of Resolution 75/240 and Item 4 in Resolution 77/36. One of the missions of the OEWG is to consider the initiatives of states to improve ICT security. This is why the POA should be discussed at the same level as other state initiatives at the OEWG on the basis of consensus. We believe that it would be optimal at the UN to maintain a single mechanism for negotiation which would also consider various national initiatives in a transparent manner on an equal footing. Thank you.

Ambassador Gafoor

Thank you, Russian Federation. Denmark, to be followed by France.

Denmark

Mr. Chair, I have the honor of speaking on behalf of the Nordic countries: Finland, Iceland, Norway, Sweden, and my own country, Denmark. We fully align ourselves with the statement delivered by the European Union. This week, many states have voiced the need to combine a focus on the potential development of new voluntary non-binding norms with an emphasis on the implementation of the already agreed framework. We need to implement the agreed 11 norms of responsible state behavior in cyberspace. We need to implement best practices on cybersecurity. We need to see strengthened compliance with international law, as well as further develop common understandings on important aspects of how international law applies in cyberspace. On this note, we have heard many calls for capacity-building efforts, and surely implementation of the above-mentioned points is a capacity-building effort. But we also need to make sure that no state is left behind in meeting the challenges that continued digitalization entails, including future threats that may follow the adoption of new technology. And finally, we have heard many states underline how the input from academia, civil society, and the private sector is of great value for capacity-building, as well as their input being an important contribution in its own right in maintaining a free, open, and secure cyberspace. The insightful statements from the stakeholders yesterday surely bear witness to this. A future regular institutional dialogue should be action-oriented, have specific objectives, and be inclusive, transparent, and consensus-driven, as well as results-based, as this was also agreed in the previous iteration of the OEWG. We regret to have been denied the possibility to draw on valuable and insightful expertise from some relevant stakeholders this week, as their participation has been blocked. This runs counter to our joint efforts to enhance security in cyberspace. This bears witness that current modalities do not entail the optimal structure for enabling stakeholder participation. As such, it is our view that in order to be legitimately inclusive, any future regular institutional dialogue must provide for the participation of all interested stakeholders. The Nordic countries believe that the proposal of a Program of Action would ensure the invaluable participation of stakeholders, as well as provide the permanent platform that we need to allow for action-oriented implementation, tailored capacity-building, and continued discussions on the potential development of new norms. The PUA will provide a focused structure to support the exchange of knowledge, best practices, and expertise, to assist states in their efforts to maintain a free, open, and secure cyberspace. Furthermore, the PUA should be flexible and adaptable to future threats and technologies by regularly convening states to review the framework as necessary and appropriate. Going forward, we should continue to have adequate time allocated for discussion on the PUA in this format. At the same time, we encourage all states to submit national contributions to the UN Secretary-General report on the possible structure and preparatory work on the PUA. The Nordic countries call for a dedicated session in 2024 to provide all states with the opportunity to have comprehensive discussions on the structure, content, and objectives of the PUA. The calls for this session could be reflected and answered in the annual progress report. Thank you, Chair.

Ambassador Gafoor

Thank you very much, Denmark, for your contribution. I think the Nordic Statement referred to the need for dedicated discussions in 2024 in order to have a comprehensive discussion. My intention is to have comprehensive discussions in 2023. We don’t need to wait for 2024. We have enough time, not only today, but the rest of the weeks and months before July, and let’s have that comprehensive discussion now, not in 2024, on regular institutional dialogue, including the Program of Action. So let’s continue with the speaker’s list. France, to be followed by Egypt. France, please.

France

Good morning, Mr. Chairman. At a time when we are reaching the end of our fourth formal session, my delegation would like to welcome the very rich exchanges that it has made possible among the current delegations. I’d like to thank you for the way in which you have conducted our work. These exchanges give us confidence that we will achieve concrete progress under your leadership in the upcoming sessions. But it also includes different lessons, useful lessons, for ideas on a future regular institutional dialogue. As you know, Mr. Chairman, my delegation, as many other states, supports the idea of setting up a Program of Action as a future forum for regular institutional dialogue for many reasons, and mostly because we believe that the United Nations must have a tool which would make it possible to effectively guarantee the stability and security in cyberspace. I will therefore deal with the questions that you pose to us and point out the elements that could be part of a future Program of Action. The first key principle is that the Program of Action would provide a permanent and unique structure to deal with cyber challenges in the First Committee. Cyber issues are no longer an emerging issue. It’s now a daily reality, and the dimensions are very well established in the work of the First Committee. The development of this permanent framework would provide increasingly necessary institutional stability, and this would spare the General Assembly from having periodic discussions on the launching of limited working groups. It would make it possible to focus on the adoption of substantive deliverables that the POA would transmit in its approval. As a permanent structure, the Program of Action could have regular review conferences and meetings according to a frequency which will be defined, bearing in mind the capacity of states. The second principle would be inclusiveness. Very broad participation on the part of states and that of non-government entities who have been accredited in the work of our formal session reflects a willingness to build collective solutions within the framework of an open and transparent framework when it comes to challenges linked to cyberspace security. The POA should take into account this aspiration and give it the means to be fully achieved. First of all, the principle of inclusiveness also applies to states. The future PA should make it possible for all states to be able to take part in all of its meetings and work. Secondly, the principle also applies to non-government entities. Of course, the POA – no one questions the prerogative of states when it comes to international cybersecurity. But a broad participation of these non-government actors we feel is necessary in our work. It’s not simply a case of defending the right of these organizations to have their voice heard, but it’s also a matter of benefiting from the expertise and resources that they could provide to our discussion. And above all, it’s a question of underlining the responsibility that these actors have, especially in the private sector. They should contribute to the establishment of certain aspects of the normative framework, for example, by contributing ideas to the security of products. We should therefore favor accreditation modalities which would allow the participation of these actors in formal sessions of the POA. And we could also base ourselves on precedents used in different processes of the First Committee, such as the GGE on autonomous lethal weapons. The third key principle is that the POA should clearly reaffirm the cumulative and evolving framework of responsible state behavior as its basis for work. In the course of the session, many delegations have reminded us that we are not starting from scratch. A POA should thus be able to build on the gains of successive processes, including the consensual results that the current process will have produced during its mandate, such as the eventual intergovernmental POC directory. We welcome the other proposals that were made this week, and we will examine them attentively when it comes to inscribing them in a future POA, such as the Directory of Threats proposed by Kenya or the Global Portal on Cooperation, which was suggested by India. The fourth key principle is that the POA should strongly stress support for the efforts to implement a normative framework. In the course of this week, several delegations rightly recalled that new norms and standards could be developed in the future. But almost all of the delegations have also stressed that this possibility to negotiate new norms should not be a reason to delay the efforts to implement the currently agreed framework. The POA would favor voluntary reporting of states, namely through instruments such as the National Implementation Survey of States in UNIDIR, in order to identify the challenges and needs encountered by states in implementing the framework. It would favor the exchange of good practices and expertise on these matters. A fifth key principle is that the POA would support capacity building, promoting relevant activities to support states in implementing the normative framework of responsible behavior. Support for capacity building within the framework of the POA should take into account existing initiatives in this area and should favor better coordination among them. Regular briefings could be organized with other organizations, such as the World Bank or the ITU, to take into account activities carried out by those organizations within the framework of their mandate. A sixth and last key principle is flexibility. The POA should make it possible to continue discussions on the eventual development of a normative framework. We have collectively acknowledged that additional norms could be developed in the future. Future meetings or review conferences of the POA should make it possible to update the normative framework on the basis of consensus, if necessary. This flexibility would make it possible to establish the POA as an instrument which could deal both with the implementation of a normative framework as well as its potential development. Chairman, these are the key principles that, in our opinion, should structure the continuing discussions of this group on the establishment of the POA. These principles also inspired the national contribution to the report that the Secretary-General was requested to prepare through Resolution 77-37. We would submit this contribution in the upcoming days, and we will disseminate it on the portal of the OEWG, in keeping with our commitment to use this group as a forum to develop this proposal in an inclusive and transparent fashion. With respect to the modalities to establish this POA, we will continue our efforts, working with you, Mr. Chairman, to consolidate a consensus in favor of this proposal and to move towards the establishment of the POA when this OEWG will have concluded its work in 2025. In order to continue to elaborate this proposal and to further discussion on the key principles, we attach the utmost importance to the 2023 report of the group, calling for a specific session in 2024, or an international meeting of the group, in order to deepen our discussions on the development of this project. Thank you very much.

Ambassador Gafoor

Thank you, France, for your intervention. Please feel free to share your interventions with the Secretariat so we can put them on the website. Egypt to be followed by China, please.

Egypt

Thank you, Mr. Chair. At the outset, I’d like to highlight that Egypt has been working with France along with a group of co-sponsors on the POA for almost three years. Egypt has submitted its detailed working paper on the Cyber Programme of Action proposal, which is available on the website of the OEWG, to conduct focused discussion on it, in line with the Consensual First APR of the group, focusing on the POA’s scope, objectives, structure, and possible modalities. Moreover, we believe that POA would be a UN permanent, action-oriented, and flexible cyber process as follows. One, permanent, which means that we will get to the table to discuss the POA’s mandate, scope, and modalities once for a lifetime, to avoid the periodic discussions taking place every few years to establish a new UN cyber process. Every so often, we have a unified process if we are lucky enough, while other times there could be parallel processes, depending on the geopolitical situation. Second, action-oriented. One of the major challenges against the previously established cyber processes is the problems that they are facing while adopting concrete proposals, in particular those related to capacity building. POA would allow a regular dialogue and follow-up on the implementation while providing related international cooperation and assistance to states. Third, flexible. POA could be updated regularly through its regular meetings and review conferences, identifying possible gaps and challenges, consistently with the evolving nature of the ICTs. And POA would be consensus-based to accommodate concerns of all participating states and to make sure of the inclusivity of participation of all states. Fourth, a hub for capacity building. In light of the growing technological gap among developing and developed states, the capacity building pillar becomes more essential and timely as an enabler for the effective implementation of the agreed normative framework. In this vein, we believe that POA would be a venue to oversee capacity building tailored programs based on the recipient state’s assessments and needs, consistently with the assistance principles adopted in the 2019-21 cyber OEWG. Fifth, non-duplicating. We share the view that POA should be focusing on the implementation of the agreed normative framework. At the same time, discussions should be taking place on the outstanding issues that would require further deliberations within the OEWG or other processes to be established after 2025. Hence, we would achieve the required harmonization of work of both processes, not only on the substantive issues but also while scheduled meetings. For the proposals announced today by the Russian Federation delegation under the regular institutional dialogue, we will send it to Cairo for consideration. However, preliminarily, we believe that there is an agreement in principle for the dire need of the implementation of agreed existing acquis, while diversions of views might still exist on the process. Therefore, we believe further efforts need to be exerted to find a common ground forward. Additionally, we encourage all member states to contribute to the IG report on the POA to accommodate their concerns and reflect their related priorities. That report will be discussed at the OEWG in line with Resolution 77-37. Finally, we look forward to further discussing the POA proposal within the OEWG and listening to states’ positions and reactions to the aforementioned working paper, as well as engaging with all interested states with the aim of reaching consensus on it. In this context, we reiterate our proposal to convene dedicated sessions on the different elements of the POA, for example, to discuss the scope, mandate, and establishment in specific sessions, and the modalities and structure in other sessions. This also goes along with the proposals that have been tabled today by several delegations. I thank you, Mr. Chair.

Ambassador Gafoor

Thank you very much, Egypt. I would invite all delegations to share their interventions with the Secretary-General so that we can put them on the website. Everyone can see the views expressed, and I think that will be very useful for all of us. China to be followed by Romania. China, please.

Unknown Speaker

Thank you, Mr. Chair. China believes that cyberspace bears on the future of humanity, and its future should be shaped by all countries together. From the previous GGEs to the current OEWG, it is the general consensus of the countries that there should be only one UN process, an inclusive process that all countries can take part in, against the background of geopolitical tensions. And with the concerted efforts of the chair and all parties, last year’s third session produced the first annual progress report, once again showing the international community’s trust and confidence in the OEWG and multilateralism. China supports the OEWG in having in-depth discussions about future institutional dialogue. At the same time, China would like to reiterate three concerns. First, the discussions of future institutions should not be considered the same as discussions of the POA. The relevant discussion should be open to avoid predetermination of results. Second, last year, relevant countries submitted a resolution to the GA attempting to set up a parallel POA preparation mechanism outside the OEWG. It will gravely undermine the status of the working group and fragment the UN process. China was open to discussing all types of institutional dialogue, including the POA, under the OEWG framework. But now things have changed. The main proponents of the POA should clarify whether they can rule out the possibility of starting something different outside the OEWG. It is perplexing to see that they have one foot here and the other one outside. It is a belief of China that the discussions of the working group should by no means be used to fragment or undermine the status of the OEWG. Third, the OEWG should make it clear that there should be only one process in the UN, an inclusive process that all countries can take part in. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you, China. Romania to be followed by El Salvador. Romania, please.

Romania

Mr. Chair, as my distinguished colleagues from France and Egypt have so eloquently illustrated, some of the principles defining the proposal of a Program of Action (POA) are its permanent nature, its inclusivity of states and of multistakeholders, its affirmation of the cumulative and evolving nature of the Framework for Responsible State Conduct in cyberspace, its strong emphasis on support for efforts to implement it, the accent it places on capacity building in the service of responsible state conduct, and its flexibility. This final principle is quite important, as the POA is conceptualized as able to deal with both supporting implementation and norm development as appropriate. The POA is, by its nature and evolution, the closest thing possible to a grassroots initiative of the members of this Assembly. It is also conceptualized and structured in a way based on precedent, tried and proven approaches, and is strongly focused on needs. With this in mind, we support calls and emphasize the importance of maintaining a dedicated dialogue on the POA within the present Open-Ended Working Group (OEWG) through the use of dedicated inter-sessional meetings. In support also of the position expressed by Egypt, we also encourage colleagues to contribute to the Secretary-General’s report on the Program of Action. Thank you.

Ambassador Gafoor

Thank you, Romania. El Salvador to be followed by Croatia. El Salvador, please.

El Salvador

Thank you, Chairman. With respect to the regular institutional dialogue and in response to your questions, El Salvador believes that proposals which are directed to action are the best way in which we can operationalize the exchange among states. And in that respect, Salvador can imagine a permanent, inclusive, and transparent mechanism to discuss real and potential threats in the area of information security, supporting states in the implementation of the normative framework of responsible behavior, promoting capacities and assistance, and also to generate a platform of convergence for the implementation of confidence-building measures. As has already been said earlier, this mechanism should be built on the basis of the accumulation of knowledge generated by the Group of Governmental Experts, the former working group of the OEWG, and the result of the consensus of this working group following the finalization of its work. And this with a view to avoiding duplication of processes, which would be highly discouraged by my country due to the challenge that it represents for these small delegations to be able to cover several processes at the same time under the same general system. And an idea that El Salvador has been supporting since 2019 is the Program of Action, and we are pleased to see the adoption of the resolution that mandates this mechanism. However, considering that this is a process that we are going to build in a collaborative fashion, we hope to be able to share in the relative spaces, to be able to share specific opinions on its scope, on its structure and content, as well as on the preparatory work, as well as modalities with a view to its establishment. And we will listen to the visions of other states with respect to what I’ve said. My country is open and will continue to exchange opinions on facilitating the regular institutional dialogue with – related to the use of ICTs in the area of international security. Thank you.

Ambassador Gafoor

Thank you, El Salvador. Croatia, to be followed by Canada. Croatia, please.

Croatia

Thank you, Chair, and the Republic of Croatia aligns itself with the intervention given by the European Union. As one of the many sponsors of the Program of Action, Croatia strongly believes that the POA will prove to be a stable, inclusive, flexible, and efficient platform for collective decision-making and action-oriented results. It will offer practical steps towards confidence-building and resilient trust by structured cooperation, enabling human-centric digital transformation and accountability. While the final responsibility, as well as decision-making ability, should rest exclusively in the hands of States, it would be a lost opportunity not to involve and learn from other stakeholders. The future work of the POA can be infused by topics that were mentioned earlier this week, like discussions on existing challenges and threats to the maintenance of international peace and security, sharing of experience and expertise, promoting CBMs, managing capacity-building efforts, mapping of needs and donors’ available projects, exploring and developing new standards and norms, defining the voluntary national reporting schemes and avoiding any duplication of similar existing work, sharing information on national governing structures, policies, legislations, and measures, enabling public-private interaction and partnerships, resilience and recovery, and exchanges with the multistakeholder community, and supporting preventive efforts to avoid cyber conflicts. There were many good proposals on repositories, platforms, and similar exchanges this week, and we should explore how to make synergy between those proposals and the POA. We agree with our distinguished neighbor, CĂ´te d’Ivoire, on the continuity of the open-ended working group through the POA, and we also believe that the POA is an additional response to deepen and continue regular institutional dialogue. We can also support proposals from France and Egypt on holding dedicated sessions to further discuss the POA. The compelling support that the UNGA Resolution 77-37 received from the UN members also gives us hope that such an important outcome and establishment of the POA should be feasible in the timeframe. The said resolution also clearly indicates the prerequisites and organizational path towards this goal. Thank you, Chair.

Ambassador Gafoor

Thank you very much, Croatia. Canada, to be followed by Brazil.

Canada

Thank you, Mr. Chair. As you stated this morning at the opening of our session, it inspired me to say that the elements of the Working Group, the POA, and other factors are taken into account in our discussions. The annual report, the report of the Chair of the Working Group, which we have all approved, as well as the internal discussions on the mechanism for dialogue, for regular institutional dialogue, are all conveying this message, especially as part of the last OEWG mechanism report, which states that all future mechanisms of regular institutional dialogue should be action-oriented and aim to achieve concrete goals. It needs to be based on past goals, it needs to be inclusive, transparent, consensual, and results-oriented. This is a common shared principle which Canada has always promoted in order to reach agreement. The process for developing the POA has the potential to become a bridge between countries in the OEWG context. As a participant of this forum, states can directly participate in the process in order to achieve compromise when a legal instrument is not feasible or desirable. I will conclude in English. Chair, we mentioned capacity building yesterday and how the POA can also be a factor in this regard. Yet, there are other questions to consider, and many conversations have happened this week on this. For instance, what commitments would such a future instrument include? What kind of accountability and monitoring mechanisms could it establish? What does politically binding mean? What is the role of non-governmental stakeholders? What are the practical implications of fulfilling the cyber POA? And how can we build awareness of and, again, on capacity to implement the cyber POA commitments? These questions could be, in addition to others that you have presented as well, questions that could be a basis for a future focused discussion about the POA as well as dedicated sessions within this year, as you mentioned. There is an ongoing collective effort by states to work towards having the cyber POA include action points relevant to all these areas that I just mentioned. This is being done while keeping the overarching objective to contribute to the maintenance of international peace and security by preserving an open, stable, secure, accessible, and peaceful ICT environment. And in that vein, Canada would encourage states to submit their views to the UN Secretary-General on how they see the POA being developed further. States have also observed that the normative framework itself is cumulative and evolving in nature. Two objectives should be kept in mind in this regard. Efforts ought to continue to support the implementation of the existing agreed framework, and a future POA should thus allow for the potential further development of said framework, especially as new threats and challenges may arise. The framework is not a static one. Technology advances. Threats evolve and proliferate. Challenges to the implementation remain. The POA could provide vehicles to increase relevance and agility in the face of such change. We would also like to align ourselves with the statement from France and Egypt and associate with the number of key elements presented. For Canada, the POA should, in particular, ensure inclusivity, both for states and for the stakeholder community. In regard to stakeholders, the POA should clearly reaffirm that states bear primary responsibility in matters of international security and therefore should retain the decision-making power, but its modalities should allow stakeholders to attend formal meetings, make statements, and submit written inputs. The inclusion of relevant stakeholders during the next phase of the process lends legitimacy and can shape an instrument that will affect lived realities and real threats. We would also encourage states to consult with stakeholders in this process of submitting views to the UNSG, and that stakeholders be part of the regional consults named in the POA resolution. Moreover, given the nature of the cybersecurity field and ownership of key infrastructure and services, many different stakeholders will have an important role to play in implementing a cyber POA. Canada will continue to advocate for the creation of an inclusive, action-oriented POA. It will help states implement the acquis, coordinate capacity-building efforts, and better integrate the voices of non-state stakeholders. In line with our objective for stakeholder participation in the OEWG process, Canada believes that constructive participation of non-state stakeholders in an eventual POA could provide insightful and valuable input into this group’s work. Thank you.

Ambassador Gafoor

Thank you, Canada. Brazil, to be followed by the Netherlands. Brazil, please.

Brazil

Thank you, Chair. Brazil favors a regular, open, and inclusive dialogue on international security related to ICTs. The proposals put forward should be considered on their own merits, regardless of the format in which they are presented. We are not in a position to prejudge the result of our talks on regular institutional dialogue. To Brazil, it is essential to maintain the unity of our discussions. Anything short of a single track will duplicate and complicate delegations’ efforts, proving to be a burden, especially to developing countries, as highlighted by El Salvador. In addition, it would be detrimental to multilateralism, as well as to our common goal of promoting transparency, trust, and stability among states in cyberspace. We should avoid creating echo chambers when dealing with security related to ICTs. Confidence building is only useful when aimed at building bridges between those who disagree. In the same vein, discussions on regular institutional dialogue should not lose sight of complementarity with our work in this OEWG. On the substance of such a dialogue, for Brazil, it is fundamental that the initiative be supportive of cooperation and capacity building, as well as preserve the integrity of the current acquis on responsible state behavior in the use of ICTs and on the application of internationalized cyberspace. In order to preserve the acquis, it is not enough to maintain the framework, but we must keep developing it. Any proposal on regular institutional dialogue should aim at creating a dynamic for the gradual and incremental advance of our common understanding on the norms of responsible behavior and on the application of international law. Yet, we highlight that the normative role should continue to be performed by the UN General Assembly, as it has up to today, by adopting the reports of the GGEs and of the first OEWG. It is our hope that the Secretary-General’s report, requested in paragraph 3 of the UN General Assembly Resolution 77-37, covers lessons learned from other UN mechanisms of regular institutional dialogue. Thank you, Chair.

Ambassador Gafoor

Thank you, Brazil, for your statement. Netherlands, to be followed by Japan. Netherlands, please.

The Netherlands

Thank you, Chair. The Netherlands aligns itself with the statement delivered by the European Union and some remarks in a national capacity. We appreciate the rich discussions we’ve had this week, which conveyed the shared sense of urgency of the international community around the issue of cyber security. We believe this naturally brings us to the agenda item on future regular institutional dialogue. The Netherlands supports the Program of Action (POA) initiative, and we welcome the resolution adopted by the General Assembly last fall, which articulates the general objectives of the POA and provides guidance on how it can be further developed. We welcome discussions on the POA within the Open-Ended Working Group (OEWG) with a view to finding common ground on the scope, structure, and content through focused discussions. As others before me have highlighted, we also support the idea of having a dedicated session on the POA. The Netherlands sees a need to establish a permanent, inclusive, transparent, and action-oriented mechanism to address the evolving threats to international peace and security posed by the use of ICTs. Building on the long history of progress we’ve made in this regard on this platform, we believe such a mechanism should be inclusive, anchored in the normative framework agreed by all states, provide a platform for technical discussions and exchanges, facilitate capacity building, and allow for the further development of the normative framework and updating it based on the ongoing developments in the ICT environment based on consensus. It should also allow for the participation of relevant stakeholders. Chair, we would like to use this opportunity to zoom in on our thinking of the element of implementation for the Program of Action. Our idea is based on a four-step cycle, and I will briefly elaborate on it. First, states could develop a set of POA-endorsed areas of capacity building that are instrumental to the implementation of the normative framework for responsible state behaviors. These areas would provide a common framework that translates the consensus outcomes to capacities on, for example, critical infrastructure protection, incident response, policies and strategies, CSIRTs, etc. They should be flexible to ensure they can be adapted to the diverse context and priorities of each state. In identifying these areas, states can draw from the work undertaken by UNIDIR on unpacking cyber capacity needs. To help identify needs and priorities for all states, states would self-report on the implementation of the framework based on the areas of capacity building and using available tools such as the UNIDIR survey of national reporting or the Singapore UNODA norms implementation checklist. The POA, based on needs identified by states themselves, would then serve as a convening platform—or perhaps even the word “hub” that my Egyptian colleague used is relevant here—to match capacity building needs and resources. As already highlighted by my distinguished colleague from Egypt, on the principles for capacity building agreed in the 2021 report, this function could also integrate existing tools such as the UNIDIR Cyber Policy Portal. After capacity building needs have been identified and successfully matched with resources and capacity building, the POA would facilitate a feedback loop to share best practices in implementation and further inform the work to develop the normative framework. Similar to Croatia, we believe that these activities can already take off before the establishment of the POA, particularly because our ideas build on existing tools and initiatives. In addition, we would also like to explore the synergies with highly relevant proposals that have been made this week, such as those put forward by Kenya, India, and others. We decided to raise our thinking here because we believe the POA could help anchor and institutionalize these sorts of implementation efforts in a permanent mechanism beyond 2025. Chair, it would be important to maintain the scope of implementation efforts under the POA on the normative framework, as you’ve also highlighted yesterday. We also believe that the POA could provide a practical way to help connect with capacity building in distinct but interlinked areas such as increasing connectivity, digital transformation, countering cybercrime, as well as broader efforts to narrow the digital divide. In closing, we welcome the views of other delegations on these ideas and encourage all delegations to submit their national views to the Secretary-General’s report. Thank you, Chair.

Ambassador Gafoor

Thank you, Netherlands. Japan to be followed by Argentina, please.

Japan

Thank you, Chair. We are of the view that regular institutional dialogue should be action-oriented and provide concrete support for the effective implementation of the Framework for Responsible State Behaviour. As a mechanism to advance responsible state behaviour, Japan supports, as co-sponsor, the POA resolutions adopted by the UN General Assembly. In our view, four points are important in elaborating the scope, structure, and content of the POA. First, the POA should provide recommendations to guide national efforts to implement the Framework for Responsible State Behaviour. Second, the POA should encourage voluntary reporting on national practices in order to identify the needs and challenges of each member state. Thirdly, the POA should support capacity building tailored to the needs and challenges of recipient countries. The idea of tagged checklists proposed by Singapore would help this function. Fourthly, the POA should be inclusive, ensuring broad participation of member states and non-governmental stakeholders. As the EU, France, Egypt, and other delegations stated, we would also like to highlight the importance of the concept of multistakeholders. Various international organizations, regional organizations, and states have been providing capacity building programs in collaboration with non-governmental stakeholders. In this context, we think it would be useful if the POA would leverage these existing initiatives and help coordinate the needs of recipient member states with various multistakeholder capacity building programs. Japan would like to make utmost contributions to discussions at the OEWG, bearing in mind that the POA will serve as a hopeful format for the actual implementation of the agreed norms and principles of responsible state behaviours. Thank you, Chair.

Ambassador Gafoor

Thank you. Japan, Argentina, to be followed by Cuba, please.

Argentina

Thank you, Chairman. Several years ago, a group of countries began to think about how an institutional dialogue would look at the end of the mandate of the current OEWG 2045, and we felt that it was the time to establish a mechanism of continued dialogue, given the growing and dynamic nature of the use of ICTs in the sphere of cybersecurity. This platform, the POA, was finally adopted by the General Assembly through Resolution A-77-37 last year. The Delegation of Argentina supports the POA being set up as a permanent platform to install definitively in the United Nations the debate on cybersecurity and its implications for international peace and security, and to adopt operative recommendations to promote international cooperation and also to promote programs of assistance adapted to the needs of states. Likewise, we believe that it could be a platform to continue discussions on the agenda of the ICTs with a view to achieving greater understandings on the responsible use of the ICTs in cyberspace and to promote greater resilience and stability. With respect to the principles which it should be based on, we do agree with the comments made by France, Egypt, and other delegations. And today, we believe that we should adopt a permanent, universal, open, inclusive, and pragmatic framework which should take as its main axis the peaceful use of ICTs to generate an open, free, and interoperable cyberspace. In this respect, the Delegation of Argentina agrees with your comments from yesterday, Mr. Chairman, that the focus should be on guaranteeing international peace and security. And so we believe that deliberations on the design of the POA should be directed towards this mandate without duplicating other processes which are taking place here in the United Nations or in other fora where they also deal with issues related to ICTs. Secondly, my delegation believes that the POA should be strongly oriented towards the implementation of the framework. However, the POA should not set aside the dynamic and evolving nature of the ICTs, and as a result, it should have enough space to continue to discuss the new items that are emerging and taking their place on the agenda, as we saw in the session on threats last Monday. The agenda’s perspective should also be included in any future Program of Action. Thirdly, capacity building should be guided by the principles agreed to in the final report of the first OEWG in 2021, as well as on the conclusions of the first progress report agreed in July of 2022. The objective of the POA should be to coordinate training requests and supply with respect to what we said yesterday, since the majority of countries will need to develop capabilities to be able to implement it and to assimilate the norms and understandings that will be reached. Furthermore, we do agree with Denmark on the multistakeholder approach that the future POA would adopt, and we hope to be able to discuss its modalities within the framework of the discussion of the new permanent framework. Argentina hopes that in the coming months we will have an open and transparent discussion, and its design to sync to the visions of all countries with a view to convergence. And if we decide to continue the work in an intersessional fashion, we promote the incorporation of this item on the working agenda. Thank you very much.

Ambassador Gafoor

Thank you very much, Argentina, for your statement. Cuba, to be followed by Vietnam. Cuba, please.

Cuba

Thank you, Mr. Chairman. The United Nations, a multilateral forum par excellence, should be the main platform in order to tackle the concerns of its member states with respect to security and the use of ICTs. In that respect, we reaffirm that the United Nations must play a guiding role in the promotion of a regular dialogue among states with a view to achieving an open, safe, stable, accessible, and peaceful environment. We place great importance on the format of the OEWG as an inclusive, democratic, and transparent mechanism, the unique space for all states to be able to make contributions to the discussion on the use of ICTs within the context of international security. The OEWG has proven its value in this sense. We support its central role as a mechanism for regular institutional dialogue until 2025. We reiterate the importance of consensus in any mechanism for regular institutional dialogue that will be adopted both for substantive issues as well as organizational issues. In this area, we do not favor methods of decision-making of the main committees of the General Assembly. We insist on the intergovernmental nature of the cybersecurity processes within the United Nations. We agree with Russia that a future regular institutional dialogue should be focused on the practical implementation of the recommendations of the OEWG and consider comprehensively all of the items in this area. We would not be in favor of forced links of the future mechanism with initiatives of regional organizations that aim to establish themselves as interlocutors. The mandate of the OEWG includes the review of states’ proposals. All of the proposals must be discussed on an equal footing within this framework and must be recommended with the consensus of all the members of the group. The scope and content of an eventual Program of Action should be well-defined. They cannot include elements that are not agreed to by consensus. We are not in favor of focusing only on matters of international law, which has been the most controversial within the OEWG. Its basis cannot be the reports of the Groups of Governmental Experts, which were not negotiated by all of the member states. It should contain practical measures for international cooperation, assistance, as well as technology transfer to developing countries. Every discussion on this program must take place within the framework of the OEWG. The voluntary standards should be an intermediate step towards the adoption of a future instrument – an international legally binding instrument that would regulate the behavior of states in this area. It should be duly reflected within the recommendations of the OEWG or in the document that we manage to achieve. The governments are responsible for implementing any initiative at the national level. It is up to the OEWG to recommend the future courses of action which are most appropriate on the basis of consensus achieved by the member states. We don’t support the establishment of parallel mechanisms which would duplicate or replace those of the group if they didn’t result from the group. We reiterate our willingness to contribute to the discussion. Thank you very much.

Ambassador Gafoor

Thank you very much, Cuba, for your statement. I have some good news to share. We have a long list of speakers, and it’s been an excellent, excellent discussion. I have the sense that we might all benefit from a coffee break at this point. So let’s do a 10-minute break, and then we will come back and continue with the list of speakers. Thank you very much. See you in 10 minutes. [Break].

Thank you very much. We will resume our meeting. And we will continue with the speakers list. I have Vietnam, Begium, United States, Portugal, Kenya. Five speakers. So starting with Vietnam now. Vietnam you have the floor.

Vietnam

Mr. Chair, we hold the view that the establishment of any permanent dialogue mechanism on ICT security should be discussed within the framework of the OEWG, based on consensus and equal participation of all member states. Our delegation would like to briefly introduce our position on principles of the future dialogues on cybersecurity as follows. First, the dialogue process must be state-led. Second, the dialogue decision-making must be consensus-based. Third, the process must ensure inclusivity and transparency through the participation of stakeholders, including NGOs, enterprises, and academia. Fourth, the dialogue process should be placed within the First Committee of the General Assembly. I thank you, Mr. Chair, for your kind attention.

Ambassador Gafoor

Thank you very much, Vietnam, for your brief and succinct remarks. Belgium to be followed by the United States. Belgium, please.

Belgium

Mr. Chair, my country aligns with the statement delivered by the EU and wishes to make the following remarks in its national capacity. Over the past decade, the international community has made it clear that the international rules-based order should guide state behavior in the use of ICTs. Reaffirming the cumulative and evolving framework for responsible state behavior, states have made various proposals on the means to facilitate regular institutional dialogue on security in the use of ICTs. We therefore welcome today’s focused discussion on the principles that should guide the design of this regular institutional dialogue, i.e., RID. In our view, four principles should guide the design of RID. The principle of rationalization first. The forum for RID should represent a rationalization of time and effort, uniting participants in a comprehensive process. We also stress the need for inclusiveness of the format in relation to stakeholders in particular. Second, the principle of preservation. The forum for RID should be based on the normative acquis. Third, the principle of cooperation and empowerment. The forum should foster cooperation in implementing the acquis, be result-oriented, and attentive to capacity-building needs. The principle of flexibility. The forum should be future-oriented and have the necessary flexibility to allow reviews of the acquis and the potential development of new norms. We also support the CQ principle presented by France pertaining to this regular institutional dialogue, and we value the statement made by Egypt. Mr. Chair, we believe that the establishment of a Program of Action, POA, to advance responsible state behavior in cyberspace is the best means to materialize this regular institutional dialogue with broad participation under the auspices of the United Nations. The four principles stressed earlier are also best realized through a POA. As a permanent and inclusive mechanism building on a framework for responsible state behavior, the POA indeed represents an ideal need to A, increase security-inspired cyberspace, B, operationalize the agreed norm for responsible state behavior, C, support the national implementation of these norms, D, support tailored capacity-building efforts to address the specific needs and challenges identified by states, foster the exchange of practices, and transfer of expertise, and E, strengthen the engagement with the multistakeholder community. The POA will also be flexible in the work to address new threats. We see the POA process as complementary to the work of the OEWG. We encourage all states to actively engage in the debate towards the establishment of a POA due to the UNHCR report by submitting their national views on the scope, structure, and objectives of a future POA. Finally, my delegation supports the EU and others to organize a dedicated session on the POA within the framework of this open-ended working group. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Chair. Belgium, for your statement. United States, followed by Portugal. U.S., please.

United States

Thank you, Chair. Member states have repeatedly called for a more permanent UN system on cyber issues in the context of international security. Member states have been clear that this future institutional dialogue must be normative and consensus-based, expert-driven, cumulative in nature, inclusive of all UN member states, and also inclusive of relevant non-state stakeholders. In 2022, the GA passed a resolution with overwhelming support from member states that welcomed the proposal for a new Program of Action as a future permanent mechanism on cyber issues in the context of international security. The resolution took an incremental and inclusive approach towards the POA’s launch, including by acknowledging the role of the current OEWG and considering how a future POA could advance our work. UN staff are tasked with drafting a report this year based on member state input, including views expressed here, on how a POA could be established. We encourage states to submit their views. It is up to all of us to shape the POA’s future. We are currently developing the U.S. written input to the SG’s report and would like to use this opportunity to offer some preliminary views. First and perhaps foremost, the consensus framework articulated in the GGE and OEWG reports and repeatedly affirmed by the GA must be the POA’s foundation. The resolution, we feel, was very strong on this mandate. Also, the POA should be conceived as a permanent body dedicated to the international security dimensions of cyber issues. Member states would set the POA’s direction and update it over time, maintaining a priority focus on practical implementation and capacity-building work dedicated to implementation of the framework. The POA would serve as a durable resource for states in these efforts. As a permanent mechanism, the POA must have the flexibility to address future threats and the agility to assess states’ evolving needs and best practices to address these threats. States would also be able to consider within the POA whether and how the consensus framework should evolve over time. Non-state stakeholders must be an integral part of the POA process. The POA needs to have modalities for stakeholder participation that are as inclusive as possible to fully leverage their expertise. As we develop our submission, we are reviewing other UN models for similar permanent action-oriented mechanisms. We have taken note of mechanisms that have annual or biannual practical meetings focused on national implementation and a review process held every few years to assess the mechanism’s work and prioritize its future direction. These implementation meetings should focus on country experiences and best practices in implementing the framework, possibly leveraging national survey submissions and relevant capacity-building needs and resources. Implementation meetings could prioritize key areas of interest, such as critical infrastructure protection, state-to-state cooperation, cooperation with the private sector, and assessments of the current cyber threat landscape. We appreciate France, Egypt, and others for bringing forward this POA proposal several years ago. Interest has grown steadily since then and reached a new high point with the overwhelming support seen at last year’s UNGA. We have an opportunity as member states and as the OEWG to work together to address these issues. Thank you, Chair.

Portugal

Portugal aligns itself with the statement already delivered by the European Union. Last November, the Secretary-General was tasked to submit a report of a Program of Action to advance responsible state behavior in cyberspace. This permanent track is meant to enable us all to concentrate from the 80th session of the UN’s General Assembly onwards, only matching demand and supply of national capacity building and time to continue together annually to monitor and improve the application of the normative framework. This Open-Ended Working Group, under your able guidance, Mr. Chairman, has reached unparalleled degrees of commitment from a growing number of Member States from all regions in identifying needs and means for general compliance with the framework, including the most basic ones, such as a universal directory of national contact points and repositories of national experience in threats, in policies, and in legal and technical capacity building. They are critical preconditions for the future Program of Action, and thus this Open-Ended Working Group should, as proposed by Egypt, France, and other Member States, have a session entirely dedicated to the discussion of the recommendations which the Secretary-General will make in his report. Thank you, Mr. Chairman.

Ambassador Gafoor

Thank you, Portugal. Kenya, please.

Kenya

Thank you, Chair. The Open-Ended Working Group has continued to offer states an unprecedented opportunity to meet and exchange views on security of and in the use of ICTs. In response to your questions, Chair, on key principles that need to be considered in the design of regular institutional dialogue, Kenya underscores that equitable and inclusive participation and efficiency of work must remain important in building confidence among states. As often said, we are only as strong as the weakest link, and as such, the ability of all members to not only participate but also initiate processes that prioritize an integrated OEWG is another key consideration and principle. On how to ensure discussions on ICT security at the UN continue in an inclusive manner, it is useful to focus on areas of shared commonalities where members are able to engage and take action. Care should be taken to ensure that whatever form of institutional dialogue takes, it does not result in fragmentation of efforts by states, particularly when it comes to a critical issue such as security in and use of ICTs. Inclusivity must also factor in partnerships with the public, private sector, and sub-regional and regional bodies. All these are critical in enhancing awareness and contextualized understanding within our regular institutional dialogues here in New York. I conclude by thanking you, Chair, your team, and all participants in yet another productive OEWG session. I affirm Kenya’s continued constructive engagement to contribute to enhanced global efforts, the goals, frameworks, and norms that will promote a free, peaceful, and stable cyber domain and at the same time cooperatively work to mitigate the existing and potential threats in the ICT domain. I thank you, Chair.

Ambassador Gafoor

Thank you very much, Kenya. Ireland to be followed by the Republic of Korea. Ireland, please.

Ireland

Thank you, Chair. Ireland fully aligns itself with the comments made earlier by the EU. Ireland is committed to advancing the discussions on regular institutional dialogue. In this context, we were a co-sponsor last year of the French-Egypt proposal to establish a Program of Action to advance responsible state behavior in cyberspace. We continue to support the establishment of the POA, which will provide a useful platform to advance practical work in this area. In this context, I am delighted to say that Ireland will provide €25,000 to the UNODA to support collaboration with relevant regional organizations and to convene a series of consultations to share views on the POA, as directed by General Assembly Resolution 7737. Chair, there are points we would like to make in response to your questions for this session. In this, we would support in particular the earlier statements by France and Egypt and many of the key principles set out therein. Firstly, it is clear from the sheer scale of malicious cyber activity, the increased digitization of our societies, the relative and increasing importance of cyber issues, and the potential impact on our citizenry and our societies, that it is incumbent on us to ensure that there is a clear roadmap on how we consider cyber into the future within the UN framework. The POA would provide a single, permanent, inclusive, and action-oriented structure for dealing with cyber issues. It would provide the necessary sustained focus, building on existing UN consensus grounded in the application of existing international law and norms of responsible state behavior in cyberspace. Second, Ireland is committed to supporting sustainable capacity building. The scale of the challenges facing us requires international cooperation, and we must ensure that states receive the necessary tailored supports to enable them to implement the normative framework for responsible behavior. Ireland has expertise in designing and implementing national strategies, encouraging greater participation of women in cyber roles, and the application of international law in cyberspace, among other areas where we can make our contribution. We believe that the POA would be the optimum platform for this, in establishing a clear sense of the needs and challenges through voluntary reporting, to build on enhanced engagement with and coordinate on existing capacity building structures, and to provide the necessary flexibility to be able to pivot as and when the threat landscape evolves. Third, the POA, as proposed, would also underpin broad participation of states, regional organizations, and, of course, non-governmental actors such as civil society, industry, and academia. The scale of the challenge is such that it is only by harnessing the totality of this knowledge, expertise, and energy available that we will be able to ensure a safe and secure cyberspace for all. Finally, Chair, Ireland supports calls for a dedicated session on the POA to engage in focused, conclusive discussions on the further elaboration of the POA, and we welcome your indication today that that would be possible this year. This would provide an opportunity to build a consensus view on the expectations for the POA and to take stock and seek to address any potential concerns. Thank you.

Ambassador Gafoor

Thank you, Ireland. Republic of Korea, please.

South Korea

Thank you, Chair. As a co-sponsor of the resolution 77-37 on the Program of Action, the ROK shares the position that has been stated by many other co-sponsors such as France, Egypt, and others. Having said that, my delegation believes that building a constructive and complementary relationship between this working group and the POA is important. We believe that the POA, as a permanent and organized mechanism, can serve as a practical platform for operationalizing the various agreed outcomes put forward at the OEWG. Also, while the overarching mandate of the OEWG comprehensively deals with the six pillars, the POA could provide a setting for discussing the modalities on how to reflect the discussions made at this working group into actual state practices. The General Assembly resolution on the establishment of the POA was supported by a vast majority of votes. So we believe that it is important that the POA should operate in an inclusive manner, effectively engaging all member states. In this regard, we encourage member states to take part in submitting national reports which will contribute to the Secretary-General’s report and share their views on how the POA can operate as an effective institution. For the meantime, we believe that the POA should be flexible to accommodate various views and needs of member states and adapt to the evolving ICT environment. We also share the view of previous speakers that capacity building is core to inclusiveness and therefore should be an integral part of the POA. My delegation also underlines the importance of engaging the multistakeholders in a more meaningful and substantial manner so that we can incorporate the valuable and varied expertise and experience in operating the POA. Thank you, Chair.

Ambassador Gafoor

Thank you. Republic of Korea, Colombia, please.

Colombia

Thank you, Mr. Chairman. Colombia believes that the mechanism for regular institutional dialogue should promote the framework of responsible state behavior in the use of ICTs, as well as the follow-up and cooperation for its collective implementation, which would be both a space for dialogue on the achievements and challenges of the implementation, as well as to promote new developments. For Colombia, the ideal mechanism for this purpose would be the Program of Action, which should be established as a permanent, inclusive, transparent, and action-oriented mechanism, with a view to furthering cooperation, concrete cooperation, to make the framework operational, and at the same time as a platform to continue to discuss its development in the light of growing threats and challenges, bearing in mind the evolving nature of cyberspace and the development of ICTs. And so our answer to the question of what would be the key principles that should be considered in the design of a regular institutional dialogue when it comes to security and ICTs, they should follow the same path that I mentioned, as pointed out in Resolution 7737 of the General Assembly. Any future mechanism of regular institutional dialogue under the auspices of the United Nations should be action-oriented and have specific objectives based on previous results and must also be inclusive, transparent, consensus-based, and result-based. Mr. Chairman, the POA could also be a platform to share best practices and recommendations for its application at the national and/or regional level. Undoubtedly, it would play a key role when it comes to capacity building and cooperation in this area, and this should be a fundamental pillar of the Program of Action, and other speakers have mentioned that this morning. In this respect, we are grateful for the proposals made by the Netherlands as well as some other opinions we have heard this morning, which would certainly encourage our discussion in this area. And clearly, this would be a process driven by states, but it could also be a platform to hold regular meetings among the different interested parties, including the private sector, academia, and civil society, to review relevant issues. With respect to your question on how we see the relationship between the proposal of the POA and the current OEWG, as recommended in the annual progress report, we could devote time in the OEWG. And here we estimate by France and Egypt to have a session devoted to that this year. And Mr. Chairman, we shouldn’t forget that, in any case, within the mandate that we have, both in the creation of this working group as well as in the later one adopted with respect to the POA, the results of discussions that we have here should feed the subsequent process of the POA. There is the connection between one and the other, and it should follow the same line of the accumulated work of the step-by-step approach that we’ve had within the framework of our actions. The POA must continue to be based on previous work done by the GGEs and their recommendations approved by the General Assembly, as well as that done by the previous OEWG and by the current one. As was pointed out by Brazil, we must preserve the integrity of the framework of responsible state behavior that exists. And likewise, the POA should be space-aware to its implementation to provide a follow-up of it and to continue our dialogue on the details, such that it would be, as we’ve said, as it would be a space of dialogue and the achievements and challenges of the collected application of the framework of responsible behavior. At the same time, it would be a platform to continue to discuss its subsequent development in the light of growing threats and challenges. As was stipulated in the APR and reiterated by most of the delegations during our discussions now and also last December and in the previous session, in the previous OEWG, our work is based on the path already traveled and on the work already done. This is, as I said, a gradual effort which is based on consensus-based results and approved results, and the Program of Action will follow the same line. We see this as an ongoing continuity of what we’ve already done. Mr. Chairman, I’d like to point out that drawing up the Program of Action as a mechanism of regular institutional dialogue must be a task involving all of the states. It’s a collective effort. The discussions in this group, in this OEWG, are part of that task, which will continue in 2025. Thank you very much.

Ambassador Gafoor

Thank you, Colombia. Switzerland, to be followed by South Africa. Switzerland, please.

Switzerland

Thank you, Mr. Chair. Switzerland supports the ongoing discussions on the establishment of a UN Programme of Action on Cybersecurity. We believe that it is time to establish at the UN level a regular institutional dialogue aimed at supporting the implementation of an agreed framework for responsible behavior of states in cyberspace. Switzerland believes that the dialogue on international cybersecurity at the UN level should be held in a format that is long-term and permanent to ensure its sustainability. We are pleased to see that the concept of the POA has gained broad support with the adoption of resolution 77-37. In line with this resolution, Switzerland intends to submit its national views on the scope, structure, content, preparatory work, and modalities for the establishment of a possible POA. We encourage all states to do the same so that we can better understand their views, proposals, and concerns and have substantive discussions. In this regard, Switzerland’s submission will be guided by a number of key elements. Allow me to mention three of them. The future POA must be firmly based on the framework for responsible state behavior, including the application of international law in cyberspace. It must respect the acquis that was reached in 2021 both through the GGE and the Open-Ended Working Group reports and use it as a basis for its work and take into account the consensus outcomes of this Open-Ended Working Group. The POA should be action-oriented. It should place a strong focus on support for national efforts to implement the framework for responsible behavior of states in cyberspace. This could include the exchange of best practices and support for relevant capacity-building initiatives. In this regard, the POA should support building on existing capacity-building initiatives and creating and using synergies. We welcome the ideas and proposals shared by the Netherlands in this regard and the proposal by Singapore for checklists. The POA should be inclusive. This means that all states should be able to participate in the POA. In addition, the POA should allow for meaningful and broad multistakeholder engagement. This is important as the multistakeholder community has a crucial role to play when it comes to supporting states’ efforts in implementing the framework and securing cyberspace. It is now up to all members of this Open-Ended Working Group to discuss the details of the POA, including its focus. We agree with you, Chair, that we should have comprehensive discussions already this year and continue them next year. We support the proposal of France and Egypt to hold a dedicated session for this purpose. Thank you.

Ambassador Gafoor

Thank you, Switzerland. South Africa to be followed by Israel. South Africa, please.

South Africa

Thank you, Chairperson. South Africa thanks you and your team for your hard work and dedication in moving forward on issues where there is convergence between states in the Open-Ended Working Group. We believe that discussions in the OEWG should have the broadest possible support for it to have an effective outcome. If we are to agree on a Program of Action or a legally binding instrument, it will require the acceptance of all member states. South Africa supports discussion on a Program of Action; however, we are open to listening to the views of all states. We believe that an exchange of views will allow us to reach an understanding of the needs of all states present in this meeting. Several states have stated preferences for one or the other; therefore, we agree that we should reach convergence on regular institutional dialogue, whether or not it is linked to a specific agreement. With regards to the principles of regular institutional dialogue, we should operate with inclusivity, transparency, sustainability, and in an objective-driven and results-based manner, as agreed in the final report of the first OEWG. We should not underestimate the importance of an open and democratic process. Again, we are open to hearing views of all states and believe that we should not prejudge the outcomes of this OEWG. South Africa supports a single-track approach on regular institutional dialogue. We believe that efforts to introduce a dual track will complicate the core process and become a burden on states that have limited ability to follow two or more sets of discussions on the same issue. As our colleague from Brazil stated, this would also be detrimental to our efforts to build mutual trust between states that is needed to support a multilateral process aimed at keeping cyberspace stable and secure. Our current mode of work facilitates inclusivity of all stakeholders in their respective roles and responsibilities. Meetings where member states engage with other stakeholders are a very efficient way of taking into consideration the views and voices of other role players, and we welcome the various contributions from civil society, particularly on the applicability of international law to cyberspace. Thank you.

Ambassador Gafoor

Thank you, South Africa. Israel, to be followed by India. Israel, please.

Israel

Thank you, Chair, for giving us the floor. We wish to join this constructive conversation and share our positions on the topic of regular institutional dialogue, including our remarks on the Program of Action. Mr. Chair, Israel holds the position that it is important to continue conducting an inclusive and transparent global discussion on matters pertaining to the security in ICTs and their use. The framework and mechanism of such a regular institutional dialogue are directly related to its possible mandate, modalities, and characteristics. Israel is of the view that for the sake of inclusiveness and effectiveness of such a dialogue, the framework for such a dialogue on ICT security should be of a voluntary and non-legally binding nature. In this context, Israel also believes that as cybersecurity and cyber-resilience are key elements of states’ national security, it is essential that any future framework will be consensus-based. Like many of our distinguished colleagues that have stressed before and today, any chosen institutional dialogue should avoid any duplications or fora fragmentations, as well as maximize the use of resources and maintain a practical and focused process. Like many other member states, we also anticipate that we might encounter some difficulties equally contributing and fully engaging with parallel and multiple processes. Mr. Chair, as for the issue of the proposed Program of Action, Israel voted in support of Resolution 7737 on the recreation of a Program of Action to continue the international discussions regarding the use of information and communication technologies in the context of international security. While having some reservations, Israel recognizes the aim of this initiative in creating an important, inclusive, and permanent venue for discussing cybersecurity issues. Israel believes that there are several potential advantages to the idea of creating a POA as the sole UN mechanism for discussing cybersecurity issues on a global level. At the same time, we still have some reservations. We have persistently made clear that it is imperative that all decisions in the new POA be made based on the principle of consensus, applied both to the negotiation processes leading to the creation of the POA as well as to the decision-making process within it. In our view, it should be clearly reflected in the POA’s modalities, as cybersecurity issues may affect the fundamental national security interests of all states. It is our expectation that this essential and widely observed principle be maintained and safeguarded in the text and put into practice in the next phase of deliberations on the creation of any future POA. Finally, going forward in our opinion, it will be important for the POA to be objective and neutral. As past experience demonstrates, its credibility will depend in large part on ensuring that it will follow the principles of non-politicization and non-contextualization. Thank you, Chair.

Ambassador Gafoor

Thank you, Israel. India, to be followed by Australia. India, please.

India

Mr. Chair, as we have heard from multiple Member States and a common understanding that has been evolving in this Working Group, the ICT landscape is an interplay of multiple elements such as threats, normative framework, how international law applies to States’ use of ICTs, CBMs, and capacity building initiatives. The pillars of security of and the use of ICTs are integrated and evolve continuously. The number of statements and focused interventions on the OEWG mandate in this session underlies a comprehensive process. The inclusive, open, and consensus in the Working Group provide the Member States the necessary trust and confidence. India supports a single-track ICT process, as do Brazil, South Africa, and Israel. The Working Group must be used to discuss the modalities and practical cooperation aspects of the regular institutional dialogue, thus avoiding duplication of the existing mandate of the Group. The regular institutional dialogue mechanism on international cooperation on ICTs in the context of international security should integrate various key aspects of the ICT environment, such as raising awareness, building trust and confidence, and encouraging deeper study and discussion of areas where no common understanding has yet emerged. India believes that any future regular institutional dialogue, including the Program of Action (POA), must be open, inclusive, consensus-based, transparent, and action-oriented with specific objectives, building on the concrete outcomes of the Working Group. I thank you, Mr. Chair.

Ambassador Gafoor

Thank you, dear. Australia, to be followed by the United Kingdom. Australia, please.

Australia

Thank you, Chair. I want to thank you for the reminder this morning that you gave us of the attention which was paid to regular institutional dialogue and to the Program of Action on cyber in our annual progress report last year. And I add to that the recommendations of our predecessor Open-Ended Working Group, which in 2021 also recommended that states consider proposals to advance practical work to implement our existing commitments, specifically the POA, and to further elaborate that POA, including within this OEWG. Australia has been a long-standing advocate for the establishment of an institutionalized UN mechanism that is permanent, inclusive, transparent, democratic, and consensus-based to consider and address responsible state behavior in cyberspace. And it sounds like this is an almost universal wish from this group. We bear a responsibility to work together to manage the complex international security challenges that face us in cyberspace and to focus our efforts on promoting peace and avoiding conflict. And key to this is having a permanent and inclusive venue within which we can do just that. Indeed, in the geopolitical context as such, it is perhaps more important now than ever before. Ultimately, Australia wants a forum where all of us can meaningfully engage on a regular and ongoing basis to discuss and advance these issues, a forum for discussion and action that builds on the hard-fought consensus gains that we have made in the GGEs and the OEWGs alike, something that meets all of our needs, and one that can grow, pivot, and develop as our understandings and needs dictate. Like many countries, we consider these issues as simply too important to be split across multiple fronts. Australia stresses that any new permanent mechanism is not intended to compete with what has come before it or what currently exists, but rather represents the next evolution in UN cyber discussions, building upon consensus agreements to date. Since the Russian Federation first introduced a resolution on these issues back in 1998 and then subsequently led the establishment of the first GGE in 2004, the mode and structure of UN cyber discussions has developed considerably. In GGEs, we saw nascent discussions begin and progress under the guidance of a small clutch of states’ experts behind closed doors, first 15 people in 2004-05, 2009-10, and 2012-13, then 20 experts in 2014-15, and eventually 25 in 2016-17 and 2019-21. And discussions then progressed further with the ad hoc creation of the first and now second all-193 UN member state Open-Ended Working Group with multistakeholder participation. A permanent mechanism simply represents the next phase or evolution in UN cyber architecture that builds upon what has come before and guarantees that these issues are accorded the attention and importance that they merit going forward. Moreover, Brazil helpfully made clear some practical considerations, that anything more than a single track would be a burden, particularly for smaller states. The establishment of a permanent mechanism ensures that our precious time is spent focusing on the issues that really matter, rather than debating the pros and cons of one ad hoc forum over another and then spending considerable time on the logistics and modalities over and over again. Australia welcomes the chance to continue this discussion on the POA in this Open-Ended Working Group, not only because we have been having some discussions since the POA was first raised in this room in 2020, February 2020, but because the opportunity we have in this forum here is unique, bringing together experts from capital and from New York to make sure that the POA, the next step in our evolution, truly serves the needs of all states. Australia welcomes learning from you all within this room and the OEWG and through our submissions to the UN Secretary-General’s report on how to shape the collective vision for the POA. We are also supportive of preparing for the regional consultations planned for later this year and look forward to discussing and considering the results of those consultations and hope we can do so within this Open-Ended Working Group. For our part, Australia would like to see a POA which will consolidate and leverage the growing political awareness and the growing political commitment to advance responsible state behavior in cyberspace, to preempt and respond to threats, providing all states the ability to use cyberspace for peaceful and prosperous purposes and safeguarding the benefits for a free, open, secure, stable, accessible, and peaceful cyber environment for our future generations. We hope that we can design a POA which will promote, refine, and implement common understandings and cooperative measures to respond to current and emerging threats, including how international law applies to the use of ICTs by states, norms of responsible state behavior, confidence-building measures, and all of this supported by targeted, coordinated, practical, needs-based capacity building to implement these commitments and to do so flexibly and in a dynamic way, exploring and addressing key themes as they arise, for example, the protection of critical infrastructure from malicious cyber activity, best practice incident response, and requests for assistance in the face of a malicious cyber incident. And we see the strength of the POA being in also providing a periodic opportunity to review and assess whether additional actions are necessary to respond to the rapidly evolving cyber environment. Because as Brazil said, it’s not enough to maintain the framework, we must keep developing it. Because as Canada said, this framework and its evolution must work for us all to address the emerging and future threats. So in closing, we believe that we have talked long enough about the establishment of such a mechanism and that now is the time to take the initial steps in bringing forward that vision into fruition. We welcome this discussion and your proposal, Chair, to continue substantive discussions on this topic in 2023. Thank you.

Ambassador Gafoor

Thank you, Australia. United Kingdom, please, to be followed by Malaysia. UK.

United Kingdom

Thank you, Chair. The United Kingdom supports continued regular institutional dialogue to build on our long history of international cooperation on this topic. Focusing on the implementation and development of the agreed framework for responsible state behaviour in cyberspace is crucial if we are to fulfil our duty and protect all states from the risks of malicious cyber activity. On how we do this, we are here to listen. The United Kingdom was a co-sponsor of last year’s resolution on the Program of Action, and we believe in its potential to deliver the practical action we need to implement the framework. We will draft our return for the Secretary-General’s report once we have fully heard and considered the ideas of colleagues here today, and we support Egypt’s suggestion of more focused discussions on specific elements of a POA in the future. But I will share two of the United Kingdom’s priorities for the future of regular institutional dialogue. First, it should have the normative framework at its core. The UN framework provides a consensus basis for all states to demonstrate responsible behaviour in cyberspace, and we believe that we have further to go on implementation. There are valuable initiatives underway to deliver such implementation, development by Canada, the Netherlands, and others to provide guidance for the implementation of agreed norms, and research by UNIDIR to identify capacity gaps in the implementation of the norms needed to tackle specific threats. We believe a POA will be able to provide a permanent home for these initiatives, which are already underway. Second, we see that a Program of Action could play a significant role in shaping cyber capacity building. The United Kingdom spoke yesterday about our support for a broad-based approach to the coordination and delivery of cyber capacity building. We’ve heard from India this week regarding a UN portal for such activity, and from a number of states seeking greater access to reporting on threats. We should start to explore such ideas now, but we can clearly envisage them being supported by a permanent UN forum on cyber issues. And finally, we agree with France that a Program of Action could facilitate briefings from the World Bank, the ITU, or others, and that this could help facilitate the mainstreaming of cyber in other development assistance and better use of development banks. Chair, I’ll pick up my pen to draft the United Kingdom’s response to the Secretary-General’s report when I return to London. We encourage all states to do so too, and we note that the extended deadline of the 14th of April might allow us a moment of well-deserved rest. Thank you.

Ambassador Gafoor

Thank you very much, UK. I think there is no rest for the wicked, so we have to keep at it. I hope you won’t rest too long, UK. We need you and your inputs. Thank you very much for that statement. Malaysia to be followed by Indonesia.

Malaysia

Thank you, Mr. Chair. Our deliberations during the present sessions are a testament to the value of this OEWG in enabling comprehensive considerations of various issues relevant to ICT security. Mr. Chair, cybersecurity encompasses the elements of people, process, and technology. We have had continuous discussions on threats originating from the continuous exploitation of current technologies, vulnerabilities, and also the potential threats that originate from new emerging technologies. The threat will continue to evolve, and we need to have an institutionalized platform. Secondly, people. People are all the stakeholders that exist in the cyber ecosystem. And thirdly, the process, which covers the development and maintenance of procedures and, in this regard, the normative framework of responsible state behavior. We heard the presentations of various proposals within this OEWG on how member states can best sustain and advance regular institutional dialogue. This is indeed welcome, allowing for discussions to proceed in an open and transparent manner. As we consider the format and modalities of dialogue best suited to advancing the normative framework of responsible state behavior in cyberspace, including in the post-2025 period, it is imperative to ensure that we build on the important work being undertaken by this OEWG. Elements of principle and practical practicality require careful assessment as we move forward. Optimizing the use of scarce resources, preventing duplications, and ensuring broad and inclusive participation by the UN membership as a whole should remain at the forefront of our efforts. Malaysia will continue to engage constructively with all delegations with a view to achieving the full and effective operationalization of member states’ commitments relating to cybersecurity. Thank you.

Ambassador Gafoor

Thank you. Malaysia, Indonesia, to be followed by Germany, please. Indonesia.

Indonesia

Mr. Chair, on the issue of regular institutional dialogue, Indonesia wishes to reiterate its position. First, Indonesia reiterates its support for a multilateral, inclusive, and consensus process that belongs to and is driven by all UN member states. Second, we believe in the importance of maintaining a single and consensus process. We therefore need to acknowledge and consider that many countries, especially smaller delegations, have limited capacity to participate in various processes. Third, Indonesia opens and stands ready to partake in the discussion related to the proposal of the Program of Action to advance responsible state behavior in cyberspace. We hope that discussion can address the issue of modalities, relationship with ongoing UN processes, and a clear timeline for implementation. Finally, we remain convinced that discussion related to the POA initiative should take place within the OEWG, and we need to avoid possible overlap or duplication. We understand that the A/RES/77/37 related to the POA initiative outlines mandates for the POA which are cross-cutting with the current mandate of the OEWG, as outlined in the GA Resolution 75/240, such as to discuss existing and potential threats, implementation of the existing voluntary norms and international law, as well as capacity building and confidence-building measures. However, there are elements of the mandate from the current OEWG that are not included in the POA. For example, the important work of the OEWG to further develop the rules, norms, and principles of responsible behavior of states as mandated by Operative Paragraph 1 of GA Resolution 75/240. Finally, Mr. Chair, we look forward to the discussion and stand ready to work together to reach a consensus outcome. I thank you.

Ambassador Gafoor

Thank you, Indonesia. Germany, to be followed by the Syrian Arab Republic.

Germany

Thank you, Mr. Chair. Previous speakers have spoken very eloquently on the goals and substance of the future Program of Action, including Egypt and France, the two UN member states which have led this initiative from the start. So let me just comment on three points briefly that have come up during the discussion today. The first one is that there has been a concern of a parallel process raised by El Salvador and Brazil, or a fragmentation of efforts as Kenya put it. And let me just comment on this notion that this POA is actually being advanced here inside the Open-Ended Working Group, and the proponents of the POA are committed to taking the POA forward as part of the work of this Open-Ended Working Group, both inside the informal sessions but hopefully also as part of an informal session, possibly next year. Then we have this whole element of the national submissions, which again is designed to try and avoid duplication of efforts. This is also part of the Open-Ended Working Group work. If you’re invited to make your national submissions, all of us are invited to make these submissions and to have an impact on the future of the POA. So this is again another element that I’d like to stress that is designed to keep us together. Then there’s this whole second element of the regional consultations where UNODA is actually coming to all of our regions to take in the comments, the ideas, the visions of all UN member states at the regional level. We’re looking forward to UNODA joining us in Vienna in June, and I know that UNODA is going to also come to all the other regions. So this again is designed to really be very economical about our capacities and to help us avoid any kind of duplication of efforts. Then there’s an additional element to deconflict efforts, and that’s the time element. As we work on this POA, we make sure that there’s no time conflict with the work of this Open-Ended Working Group because the way that it’s being taken forward, the way that it’s being designed, is that this is something that can take off once the Open-Ended Working Group comes to the end of its mandate in 2025. So the POA should be ready to start after that. But again, no conflict with the work of this Open-Ended Working Group. In fact, we are here on a single track, just to use a term that was coined by South Africa and was also mentioned by India just now. Then there was a question raised by China: could the suggestion or the project of a POA actually undermine the Open-Ended Working Group? And I’d like to invite China and in fact all of us to look at this from a completely different angle. In Germany’s view, taking forward the POA as part of the Open-Ended Working Group really adds very important substance to the work of this group. Advancing the permanent mechanism of cybersecurity in the United Nations here as part of the Open-Ended Working Group makes our work much more meaningful. So I’m convinced that this POA will in fact one day be part of the legacy of this group, possibly one of the most, if not the most important legacy points of this Open-Ended Working Group. A colleague from the UK has talked about giving cybersecurity a permanent home, and I’m sure that many of you are looking forward to going home soon. Cybersecurity does not have a home so far, and cybersecurity is not a diplomat changing homes every couple of years. We need to find and build this permanent institutional home for cybersecurity, and this will not be a home to rest; this will be the home of future action. It is important to have this permanent home because, one, the discussion on cybersecurity has matured over many years here inside the United Nations, and our colleague from Australia has just said that having a permanent institutional mechanism is just the logical next phase. So let’s tackle this and build this institutional home for cybersecurity inside this Open-Ended Working Group, a home that will serve the interests of all states. Then my last point, the distinguished delegate from the Islamic Republic of Iran has mentioned the other or the first already existing Program of Action inside the United Nations, which is the Program of Action on small arms and light weapons. Let me just say that in Germany’s view, this is actually a model to take encouragement from. In our view, this is a very robust framework for small arms and light weapons. It provides a very good basis for capacity building. Germany provides a lot of capacity building on small arms and light weapons control through that mechanism. This includes training, but also provision of hardware. And actually, there’s also a funding mechanism linked to that small arms and light weapons program, the Salient Fund. And just one last point, talking about capacity building, allow me to remind you all of the side event taking place in just about 15 minutes with the ITU, where the ITU will actually be presenting its work on capacity building, and we’ll be able to present some of the links to the work of this group. Thank you, Mr. Chairman.

Ambassador Gafoor

Thank you, Germany, for your statement and also for your commercial. I hope you have sandwiches for everyone. But I want to say, as an itinerant diplomat, home is where everyone feels at home. Home is a place where we have a sense of belonging. And that is the beauty of the United Nations. 193 sovereign, independent countries feel at home at the United Nations. And therefore, the debate about the future institutional dialogue and the discussion about the Program of Action or other ideas and proposals put forward is indeed a discussion about creating this collective home. So you’re right, cyber does not have a permanent home. But it is a home that has a roof over all of us, where we can all feel at home. So before you go home, think about how we create that home collectively, brick by brick, if needed. Now, I won’t flog this imagery any further because I might make you homesick. We have six more speakers. We’ll see how far we can go. And then we’ll certainly have to continue this afternoon. So Syrian Arab Republic, followed by Nicaragua. Syria, please.

Syria

Thank you, Mr. Chairman. Syria emphasizes the need for the United Nations to undertake a central role in strengthening dialogue through the OEWG, with its modus operandi governed by transparency and inclusivity. This gives it a unique character to find common ground among states with regard to the global threats emanating from the abuse of ICT. The participation of activist states in the work of the working group is indicative of the pressing need to discuss the matters before it. It also shows the pressing need to arrive at unanimous solutions to the use of ICT and combating their abuse. General Assembly resolution 36/77 stresses the need to continue a democratic, inclusive consultation process focusing on achieving results within the OEWG. It acknowledges the pivotal role of the working group under the aegis of the United Nations to continue dialogue on these matters. General Assembly resolution 240/77 entrusts the working group to look into the different initiatives of states to secure safety in the use of ICT. Hence, the Program of Action must be discussed within the framework of the OEWG on par with the other initiatives and on the basis of consensus. My delegation is of the view that the following points must be taken into consideration when it comes to regular institutional dialogue: 1. Taking decisions relating to the work of the OEWG in an inclusive and transparent manner. 2. Emphasizing the pioneering role of the United Nations and avoiding duplication of efforts. Any dialogue must be inclusive, take decisions by consensus, and deal with all aspects of ICT. 3. Dialogue is a governmental process that should take decisions. Active stakeholders’ views should be taken in a non-official and voluntary manner, with the participation of accredited parties. In conclusion, we are ready to participate with you and engage in achieving results that maintain a sustainable, safe cyberspace. Thank you, Mr. Chairman.

Ambassador Gafoor

Thank you, Syrian Arab Republic. It’s one o’clock, and there are three more speakers. I think it would not be fair to rush the remaining speakers this afternoon. So, I intend to continue with the three remaining speakers—Nicaragua, Ghana, and Czechia—this afternoon. If others wish to speak, you’re welcome to do so. We are happy to hear your views, and I’m sure others would be happy to hear your views as well. Now is the time to press your button if you wish to speak, and we will take note of it. We’ll resume the meeting at three o’clock sharp. The meeting is adjourned. Enjoy your lunch break.

Leave a Reply

Your email address will not be published. Required fields are marked *