Ambassador Gafoor
Excellencies, Distinguished Delegates, and France. The first meeting of the Fifth Substantive Session of the Open-Ended Working Group on Security of, and in the Use of Information and Communication Technologies 2021-2025, established pursuant to General Assembly resolution 75-240 of 31st December 2020, is now called to order. Distinguished Delegates, I apologize that we have begun a little later than 10 a.m., but I could sense that many of you were catching up and having very meaningful conversations, so I thought I would give you all a little bit of time to catch up with each other, and myself included, to greet as many of you as possible, which I will continue to do so throughout this week. Let me at the beginning extend a very, very warm welcome to all delegations attending the meeting here in person. I’m so encouraged, energized, and very happy to see so many of you attending this meeting. Also particularly happy to see so many familiar faces of France who have joined the meeting in New York, and I know that quite a number of you will also be following the proceedings through UN Web TV, and I thank you for following the discussions. I’d like to begin by acknowledging the presence of Mr. Adedeji Ebo, Director and Deputy to the Under-Secretary-General and High Representative for Disarmament Affairs at the United Nations, Ms. Izumi Nakamitsu, that all of you would know, and he is representing the Under-Secretary-General, and I’d like to give him the floor to make some opening remarks. Mr. Ebo, the floor is yours.
Adedeji Ebo (Director and Deputy to the High Representative for Disarmament Affairs)
Thank you, thank you very much. Mr. Chair, distinguished delegates, ladies and gentlemen, good morning. I am delighted to address the Open-Ended Working Group on security of and in the use of information and communication technologies. The High Representative, Ms. Izumi Nakamitsu, regrets that she cannot be here. She is not in the country, and she sends her very warm regards to all of you. This substantive session marks the halfway point of the Working Group’s mandate. Much has been achieved so far. Progress has been evident from the first session in December 2021 through to the current discussions on the second annual progress report to be considered at this session. Exchanges have been rich. Proposals have been action-oriented. Last year’s first annual progress report represented a significant intermediate step. The report crystallized several interim achievements of the group. The Working Group agreed to establish an intergovernmental point of contact directory and is currently finalizing modalities for its functioning. States decided to hold a focused intersessional meeting on the issue of confidence building, as trust is an essential ingredient to a secure and peaceful cyberspace. The Working Group also identified specific discussion points like funding for capacity building efforts, best practices in public-private partnerships, and the gender dimensions of ICT security. The first progress report also recognized the need for further exchanges on several critical questions. How does international law apply to states’ use of ICTs? What cooperative measures could be pursued to address existing and potential threats to ICT security? How can states reach common understanding on rules, norms, and principles of responsible state behavior? These exchanges have been held in a highly constructive atmosphere, in large part thanks to the work of the Chair. I take this opportunity to express deep appreciation to Ambassador Burhan Gafoor for his outstanding stewardship of the Working Group. The commitment he has shown, I think, is plain to all of us. So, we have looked back, but we must also look ahead. Time is moving quickly. Before we know it, the Working Group will be discussing its final report for transmittal to the 8th session of the General Assembly in 2025. Now is the moment to redouble efforts, not just because of the quick passage of time, but because of the circumstances in which we find ourselves. Just last week, the Secretary-General released his policy brief on a new agenda for peace. The Secretary-General does not sugarcoat the peace and security challenges that we face. He calls the stakes to address them not only high, but existential. High among these risks are new weapons of war and potential domains of conflict. The extension of conflict and hostilities to cyberspace is among the most salient of these risks. The Secretary-General offers specific recommendations to protect the safety and security of cyberspace. First, he recommends concrete steps to protect human life from malicious cyber activity. He calls upon states to commit to refrain from targeting infrastructure essential for public services and to the functioning of society. The particular vulnerability of critical infrastructure, from water and sanitation to energy, is undeniable. The particular vulnerability of critical infrastructure, from water and sanitation to energy, is undeniable, worth repeating. Second, the Secretary-General concludes that there is scope to enhance accountability for malicious use of cyberspace. He recommends an independent, multilateral accountability mechanism that could support implementation of agreed norms of responsible state behavior. Through this Working Group and its predecessor, states have made tremendous progress in developing a normative framework of responsible state behavior and affirmed the applicability of international law to state use of ICTs. States have endorsed three norms that specifically address threats to critical infrastructure and one norm that seeks to prevent escalation as a result of misattribution of responsibility for an ICT incident. In this way, states possess tools that can and should underpin further steps to protect human life from malicious activity and prevent further escalation in this domain. The Secretary-General acknowledges this significant and concrete step. At the same time, he does not shy away from calling for further action. This Working Group will play an essential role in considering any such future action. Mr. Chair, distinguished delegates, ladies and gentlemen, the time has come to consider the Working Group’s second annual progress report. I commend the delegations for the very constructive exchanges already held on the draft. But the hard work of reaching a final consensus still remains. I welcome that the draft report contains a number of elements that encapsulate clear progress forward, including elements for the operationalization of the Point of Contact Directory and an initial set of voluntary confidence-building measures. But I also acknowledge that there are a number of outstanding issues that require further discussion to bridge differences, such as how to capture the divergence of views on the format and structure of a future regular institutional dialogue. These multilateral processes are anything but easy, but they remain absolutely vital. There is broad agreement that, in the light of the scope of threats emanating from cyberspace, there is an urgent need to enhance common understanding, build confidence, and intensify cooperation. On this basis, I, along with the High Representative, continue to believe there is scope for progress and will remain committed to supporting delegations to this end. I wish you well in your deliberations this week, and I thank you for your attention.
Ambassador Gafoor
Thank you very much, Director Adedeji Ebo, for your remarks, as well as conveying the remarks of the High Representative for Disarmament. Distinguished Delegates, we will now hear a statement that I wish to make in my capacity as Chair of the process. First of all, once again, please allow me to welcome all of you to this fifth substantive session in New York. And as I said earlier, it is good to see so many of you attending this meeting and so many familiar faces, as well as new faces. I want to also extend a special welcome to the Women in Cyber Fellows and say that I’m very gratified to see that so many delegations here are represented by women representatives. And I want to say that your presence and contribution is very much appreciated and will be very much needed throughout the rest of the week. I also acknowledge the presence of representatives from the stakeholder community here in the room and also those who might be following the discussions through UN Web TV. Distinguished Delegates and friends, I’d like to share with you some general remarks just before we begin our substantive work. Firstly, it is important that we recognize the important progress we have made as a working group over the past two and a half years. We are exactly at the midpoint of what is intended to be a five-year process. And we are not building from scratch. We have taken small steps forward. The progress that we need to make this week will also represent another small step in the long journey that we have taken as a working group. And the progress we have made is not just in terms of the discussions we have had, but also in terms of the very concrete proposals and initiatives that are on the table for adoption. And these proposals will contribute to the strengthening of the cumulative and evolving framework of rules, norms, and principles for responsible behavior in the domain of ICT security. Last year, we made an important first step by adopting the first annual progress report by consensus. And that report gave us also a roadmap for our work this year. And based on that roadmap and based on that first annual progress report, we were able to engage in very concrete, focused, and meaningful discussions over the past 12 months. We have had three weeks of deep, substantive discussions in New York. We had a hybrid intersessional discussion in December and also another hybrid intersessional meeting in May 2023. We also met for a formal substantive session here in New York in March 2023, which was the fourth substantive session. And throughout all these meetings, both intersessional as well as the formal sessions, we have been engaged in very focused and detailed discussions in a balanced way across all pillars of the OEWG’s mandate by looking for areas for potential convergence. I should add that we have also, over the past 12 months, engaged in very important and substantive discussions with the stakeholder community. As part of my commitment to have sustained systematic and substantive discussions with the stakeholder community, I’ve organized virtual stakeholder sessions on our modalities in April last year. And also, most recently, I held informal virtual consultations on the Zero Draft in my own capacity as chair on the 11th of July. All in all, we have had thorough consultations with all delegations, and I have also been meeting many of you virtually, individually, and bilaterally throughout the last 12 months. And therefore, I can say with confidence that the second annual progress report, REV2, that is before you, and the Zero Draft prior to that, captures the substance and spirit of our substantive discussions over the last 12 months. It was not a document that emanated from thin air, but it was rooted in the very specific and focused discussions we’ve been having over the last 12 months. That is the first point that I’d like all of you to keep in mind. Secondly, I want to say that one of the most tangible outcomes that is in the second annual progress report that is before you will be the establishment of a global POC directory. Now, the latest version of the POC elements paper is contained in the annual progress report in the annex. This paper is once again the result of very focused, detailed, and rich discussions that we have had over the last 12 months. And I think that it is going to be an immense contribution if we are able to agree to operationalize the POC directory, because it will be the first such universal mechanism that we have had, a global points of contact directory. But success is not a given, because whether it’s the POC directory or all the other specific proposals mentioned in the annual progress report, we need to have it adopted. This leads me to my next point, which is that if we are to move forward as a working group, we need to make small steps with each passing cycle. So here now in July, it is important that we continue to move forward and adopt the second annual progress report, which will help to strengthen the framework of the cumulative and evolving framework of rules, norms, and principles. And I also want to say that the second annual progress report builds on the first annual progress report by respecting the pillars of the mandate of the OEWG. In other words, the second annual progress report attaches the greatest importance to achieving balance across all aspects of the OEWG’s mandate. My next point is that the second annual progress report will also serve as a roadmap for our work over the next year. That is why it is important that we conclude our work this week on Friday by adopting the second annual progress report that will also outline areas for our focused discussions next year. The last thing I would say is that I have been really encouraged by the progress that we have made this year. I have sensed that there is willingness and commitment to make progress in this working group. When we began our work almost two years ago, many of you will recall how challenging it was to get started in this working group, how difficult it was for us to get into a discussion on substance because there were so many differences of views on procedure and on technical issues and on the issue of the participation of stakeholders. We can really be proud that over the last two and a half years we have come far, we have made progress. And this is the result of what you have achieved collectively because each one of you have reached out to others, have built confidence, have built relationships of trust, have had conversations with each other. And all this has allowed us to make progress forward last year in July and I am hoping and I am counting that this week we can make another step forward. But I also want to say that the document that is before you certainly will require further improvement. What you have before you is a revised version of the second annual progress report. It is not close to perfection but it brings us closer and closer to the potential adoption by consensus at the end of the week. But if we are to adopt this report at the end of the week, it will require all of us or should I say all of you to listen to each other, understand what each one of you needs in order to have the report adopted by consensus. And it is also my hope that each one of you will demonstrate understanding and flexibility because ultimately it is not for me as the chair to impose a consensus from the podium. It is not for me as the chair to make minor changes here and there behind closed doors. It is for each one of you to explain to each other what you need in order to achieve consensus. What your concerns are and that needs to be addressed in order to achieve consensus. So I would like, as always, to be firmly committed to an inclusive, open, and transparent process. Because fundamentally it is not about you persuading me about what amendments need to be made. It is about you persuading each other that what will be required in order to achieve consensus. And that is why we will begin with the first reading later this morning of the second annual progress report. The first reading is intended to give each one of you the opportunity to put forward your views or your concerns, if any, with regard to the adoption by consensus of the second annual progress report. The very last thing I would say is that it is really important that we demonstrate to ourselves and to the international community that this working group is able to continue the path of consensus. We made that step forward in July last year by adopting a first annual progress report by consensus. And it is important that we demonstrate once again that we are capable as a working group, as members of the international community, to reach agreement, to reach consensus by adopting the second annual progress report. And adopting the second annual progress report by consensus will itself be a very powerful demonstration and exercise in building confidence, in building trust. And in some cases, in rebuilding confidence, rebuilding trust. Because the reality is that the United Nations has 193 members, sovereign, equal, and independent. And we are all here in that capacity. And we need to respect each other. We cannot wish away that the views of one delegation will be made to disappear. Because every one of you are here representing the right of your delegation to put forward your views. But even as you exercise your right to make amendments, to put forward your concerns, I also ask each one of you to also exercise your responsibility to see how we can all move forward collectively. Exercise your responsibility as well, I hope, by listening to each other, by understanding each other. Because that is how we make progress at the United Nations. Well, friends, I think I’ve said enough. Once again, I want to thank each one of you for your very constructive commitment and engagement in this process. I look forward to working with each one of you during this week, using every hour possible, in order to listen to your concerns, in order to build the consensus that we need in order to adopt the second annual progress report. I thank you very much for your attention. Thank you. Thank you very much. We’ll now move to agenda item three, which is organization of work. The group will now consider its organization of work, and delegations are reminded that the group will continue to conduct its work in accordance with the decision taken at its organizational session held on the 1st of June 2021. And these decisions include adoption of the agenda of the working group, as contained in document A/AC.292/2021/1, an agreement that the work of the group will be conducted in accordance with the rules of procedure of the main committees of the General Assembly, while acting on a consensus basis. So please allow me now to draw your attention to the provisional program of work of the fifth substantive session, as contained in document A/AC.292/2023/3, which has been structured in accordance with the agenda of the working group. May I take it that the working group wishes to proceed in accordance with the provisional program of work of the fifth substantive session of the working group, as contained in document A/AC.292/2023/3? Russian Federation, you have the floor.
Russia
Distinguished Chair, distinguished colleagues, I’d like to express my doubt about the utility of, in the morning of July 26th, holding the informal segment for non-governmental actors. We believe that the primary task for states at this fifth session of the OEWG is to agree upon and adopt by consensus its second interim report. Under our estimates, the delegates are facing a very difficult task that comes forth on the text. To optimize this negotiation process, it would be wiser to postpone the meeting with the NGOs to July 28th. As a gesture of goodwill, we will not stand in the way of the adoption of the Chair’s proposed program of work. At the same time, we propose giving Mr. Gafoor flexibility in terms of potentially postponing this segment for NGOs as a function of the dynamics of negotiations on the document. Thank you.
Ambassador Gafoor
Thank you very much, Russian Federation, for your remarks and also for giving me, as the Chair, the flexibility to organize the work of this session. Dear friends, I want to say that this week is going to be very important for the substance of our discussions and for the substance of the Second Annual Progress Report. And I see the program of work as a tool to organize our work in such a way that we get to the substance. So it is, first of all, my hope and request to all of you that let’s not make the program of work itself the subject of discussions because that will take up time and that will prevent us from getting to the substance of our discussions. Second, Russian Federation, I take note of your point with regard to the stakeholder discussions which are scheduled on the 26th of July. And I want to make two specific points with regard to that. First, last July we had a similar arrangement where right in the middle of the week, on a Wednesday, we had a discussion with stakeholders scheduled as part of the program of work. And second, I also want to say that as part of the agreed modalities of the Open-Ended Working Group, we did indeed agree to a dedicated session with stakeholders. In that sense, the meeting scheduled on the 26th of July is an important one. But there’s also another practical reason why I have scheduled that meeting on a Wednesday morning because it is my intention to use that morning to prepare another revision of the Annual Progress Report. So to recap, we hope to start with the first reading this morning and all of tomorrow we will continue with the first reading. And while we are having the session with stakeholders on Wednesday morning, my team will be working on a revision. And so the purpose of scheduling that stakeholder session that morning is also to give some time to me and my team to focus on working on the revision. Having explained the reasoning for scheduling the stakeholder session, I also want to acknowledge and thank the Russian Federation for showing us flexibility, for entrusting me as the Chair to exercise the flexibility that will be needed. And the program of work, as I said, is an instrument to organize our work so that we get to substance. And I will, as Chair, organize our work in the best way possible in order for us to get to substance and in order for us to get to consensus. So with those comments, I would like to close the speaker’s list. I want to assure delegations that may have concerns about the program of work. I want to give you my assurance that it will be carried out in a way that will focus on the substance of our delegation while exercising flexibility as Chair. With those comments, I’d like to ask that we proceed to the adoption of the program of work. Venezuela, you have asked for the floor. Can I please request that you be brief and succinct? Thank you. Thank you.
Venezuela
Mr. Chairman, the Bolivarian Republic of Venezuela wishes to state that it is happy to see the beginning of this fifth substantive session of our Working Group. Our delegation, sir, would like to thank you and the Secretariat for the work that has been carried out to lead us to this meeting. The OEWG is the principal and sole intergovernmental forum of the UN, which is inclusive, in order to establish a framework where technological advances in ICTs are not used to obstruct peacekeeping and international security. This framework must be compatible with the principles and purposes of the UN Charter, international law, and in particular with the principles of sovereign equality, the respect of sovereignty of states, the peaceful settlement of international disputes, abstaining in international relations from the use or threat of the use of force against the territorial integrity or political independence of any state, and non-intervention in the internal affairs of other states. The mandate of the General Assembly, set forth in Resolution 75-240, establishes the role of this OEWG as continuing its task of developing rules, standards, and principles for responsible behavior of states, as well as the implementation of such rules. It is crucial to remain aware of the difference of both processes and to maintain a balance between development and implementation. The mandate of the GA also clearly sets forth the spirit of cooperation, consent, and debate as having to prevail in all meetings and discussions. So we would issue an appeal to respect the differences, diversity of opinions from all sides, and the imperative need to depoliticize debates. We assess all the proposals in the OEWG, considering that all should receive the same attention in accordance with the equality of all those participating in this forum, and the added value that can come from different ideas. So we trust that the Chair’s report will reflect the great diversity of ideas and contributions here. We’d like to take advantage of this meeting, referring to paragraphs 8 and 9 of Resolution 76-122 of the 17th of December 2021, whereby inter alia, the General Assembly expressed its serious concern for the failure to issue entry visas to representatives of certain member states. Here, we would urge the host country in a timely fashion to issue these visas for all member states in accordance with Article 4, Sections 11 and 13 of the Headquarters Agreement. Mr. Chairman, as I conclude, allow me to assert once again my delegation’s desire to move positively forward in this group. You can rely on us in your task.
Ambassador Gafoor
Thank you very much, Venezuela, for your statement and also for your commitment to engage in this working group in a very positive and constructive way, and I thank you very much for that. Distinguished delegates, I do not intend to turn this into a general debate segment of our work. We are here to have that program of work adopted, and as some of you have said, Venezuela and the Russian Federation, this is indeed an intergovernmental process. All views will be respected, but the schedule as I have put forward is intended to organize our work. The dedicated stakeholder session was put in accordance with the consensus agreement we had reached, and as Chair, it is my intention in any event to implement the program of work in a way that is flexible in order for us to focus on substance, in order for me to hear all your views, in order for me to manage the diversity of positions so that we arrive at a substantive conclusion and a consensus conclusion. So with those remarks, I would like to proceed to the adoption of the program of work, and I see no other speakers. The program of work is thus adopted. I thank you very much for your cooperation and also for the trust that you have placed in me as Chair to organize our discussions this week. We will now move on to the next item. I now would like to address the question of the attendance of stakeholders at this fifth substantive session, and delegates would recall that the working group adopted the modalities for the participation of stakeholders. The work of the working group at the first meeting of its third substantive session, and in accordance with that decision, an updated list of non-governmental entities which submitted applications to participate in the current session is contained in document A-AC.292-2023-INF-3. May I take it that the Open-Ended Working Group approves the attendance of the non-governmental entities as contained in document A-AC.292-2023-INF-3?
Ukraine
Thank you, Mr. Chair. Ukraine does not object to the list of stakeholders shared by you and the Secretariat, and we would like to make a statement. However, we would like to make a statement to explain our position on the objection against the participation of a number of stakeholders. With your permission, Mr. Chair, I will make… Ukraine…
Ambassador Gafoor
Would you be able to make that statement of explanation after the adoption? Would you consider that? Absolutely, Mr. Chair. Thank you. Thank you very much, Ukraine, for your flexibility. So may I take it that the Open-Ended Working Group approves the attendance of the non-governmental entities as contained in the document that is before you? I hear no objections; it is so decided. I thank you very much, all of you, for your collaboration and support for the adoption of this list of non-governmental entities, and I’ll give the floor to Ukraine for its statement of explanation. Ukraine, you have the floor, please.
Ukraine
Thank you, Mr. Chair. The Delegation of Ukraine would like to make a brief statement on the issue of stakeholder participation in the work of the OEWG. At the outset, our Delegation would like to stress that Ukraine has always been supporting the broad participation of stakeholders in the work of various UN bodies, including the OEWG. We proceed from the fact that all interested stakeholders of the cyber security community can make significant expert contributions to our work, which would allow us to better understand all key issues of the agenda of the Working Group. In addition, Ukraine believes that the full-fledged participation of stakeholders testifies to the inclusiveness, openness, and transparency of our discussions in the Working Group. Mr. Chair, since the issue of inclusiveness and transparency is also related to the accreditation process within the OEWG, we would like to stress the following. After careful consideration of the list of non-governmental organizations without consultative status within ECOSOC, who submitted their applications for accreditation in accordance with the agreed modalities of the OEWG, we have concluded that a number of stakeholders do not meet the criteria of independence and impartiality. In particular, we consider a few organizations from the Russian Federation and state-affiliated entities. In this regard, we have decided to object to the accreditation of such entities for participation in the fifth session of the OEWG. I cannot also but mention that Russia has been systematically blocking a large number of non-governmental organizations from participation in the work of the group. As a result, the OEWG has been deprived of the opportunity to listen to the views and recommendations of many leaders in the field of ICTs and all agenda items of these important UNGA subsidiary bodies. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Ukraine. I take note of your statement. I see no other requests for the floor, and therefore we are ready to move to agenda item 5, which is discussions on substantive issues contained in paragraph 1 of General Assembly resolution 75/240. In this regard, I want to inform delegations that the draft procedural report of the Working Group outlining all the organizational matters relating to the Working Group has been issued as document A/AC/292/2023/L1. This draft report, which is a procedural report, will be considered by the Working Group at our final meeting on Friday. I therefore draw your attention to this particular document. Second, we will now go on to the consideration of agenda item 5 and the discussions on substantive issues as contained in paragraph 1 of GA resolution 75/240 of our mandating resolution. In that context, we will do a first reading of the draft second annual progress report. I wanted to say a few brief words with regard to the annual progress report, the second or the revised second annual progress report that is before you. First, for this week, we are working on the basis of REV1, which is issued with my letter dated 12 July. I want to make that clear. There was a zero draft, and now there is a REV1 of 12 July 2023. This REV1 was prepared taking into consideration the range of views and inputs that were put forward by states in response to the zero draft, including the views expressed by many of you at the town hall on the 27th of June, as well as the written inputs submitted by many of you, including the many different informal bilateral consultations that several of you had sought with me. So please look at REV1 as an attempt on the part of the chair to make some improvements to the zero draft, which was circulated prior to that. Secondly, I’ve circulated REV1 with tracked changes in order to make your work easier. I hope that good intention has not led to confusion, and I hope that the tracked changes are clear and self-explanatory. The new additions are in bold, underlined, and italicized, so you have a sense of what the new additions are. The deletions are in strikethrough. Again, I hope delegations find that useful as a way to compare what the changes are that have been made. Now, fundamentally, REV1 is still a work in progress, which is why it is my hope to begin a discussion of the first reading of the REV1 document this morning. As you look at the first REV1 of the annual progress report, I would also want to say that I hope you will not be in the mindset of making general statements because this week we have to be very focused and specific in terms of how we can improve the REV1 draft of the annual progress report. We are not in a frame of mind for a general debate because it was all those general discussions and focused discussions that have led us to this week, which is to look in a focused way at the first revision or the REV1 of the draft annual progress report. So that is the plea that I would make to you. We will be looking at the first reading in a way that will consider all the comments you might have on that first draft with the REV1 document. I would also urge you to be as succinct as possible when making those comments. Now, I’m looking at the board. I propose that since this is the first day and all of you have been very nice and very constructive, I propose to give you all a coffee break of 15 minutes. We will come back here at 11:30 so that you can continue some of your informal conversations and greet each other. We will begin the first reading of the REV1 of the second annual draft, second annual progress report. The meeting is adjourned. Thank you.
Silence
[Break]
Ambassador Gafoor
I begin consideration of agenda item 5, relating to the first reading of the negotiations on the draft second annual progress report. I’ve been thinking about how best we can structure our discussions of the draft annual progress report, and I think it’s best that we cluster them into sections at a time. Therefore, I propose that this morning we begin with sections A and B, the section on overview as well as existing and potential threats, which will take us to paragraph 21 of the report. The overview is essentially similar to the overview of the first annual progress report, except for paragraph 8. Therefore, I’d like to think it’s a fairly straightforward overview, intended to build confidence and ease all of you into the rest of the document. The section B, on existing and potential threats, has a fair bit of additions and deletions, and I’m sure there will be views on how we can further improve this section. So my intention is to begin with that this morning, section A and section B to paragraph 21. The second thing, as we are just beginning the first reading, is that I would strongly like to urge and appeal to all delegations to avoid general statement-like interventions. I’m sure that each one of you has come prepared with very detailed statements, and that would be appreciated. But if there is any way you can present them in a succinct and summarized way, with a view to focusing on what are the additions, suggestions, proposals, or requests that you are making as a delegation, or as a group of delegations. So my attention will be focused on what proposals you are making, as opposed to a general statement on your position on the topic under discussion. With those comments, I’d like to open the floor, and I see some delegations have requested the floor. So we’ll start with the European Union. European Union, you have the floor, please, to be followed by Nicaragua. EU, please.
EU
Thank you, Mr. Chair. Let me start by thanking you for all your hard work and the progress made over the last 12 months. I really commend you and your team for all of this. And it’s necessary indeed to make such progress. Malicious behavior in cyberspace from both state and non-state actors has intensified in recent years, including a sharp and constant surge in malicious activities targeting our critical infrastructure, supply chains, intellectual property, as well as a rise in ransomware attacks against our businesses, organizations, and citizens. Cyberattacks are a threat to peace and security and can significantly impact conflicts and the conduct of war. Well-targeted attacks have increasingly harmful social and economic effects. Continuous attacks against Ukraine over the last years, attacks against Montenegro, Albania, EU candidate countries, or the ransomware attacks affecting Costa Rica, as well as the recent cyberattacks against Norway that we learned about this morning, are just mere examples of recent activities. Now more than ever, it’s imperative for the OEWG to focus on strengthening the rule of law, the implementation of the UN Framework for Responsible State Behaviour, and the promotion and protection of human rights. States need to take responsibility in maintaining peace and security in cyberspace, as in other domains, and they need to work together with other relevant stakeholders. We therefore welcome the interaction with the stakeholders during this week. Allow me to make a few general remarks, and then I will continue with some specific remarks, also including the threat section. We are appreciative of the report in its REF1 version, which we consider an improvement of the previous version. We like the action-oriented nature of these reports, the language on gender, updates on existing and potential threats, and the international law chapters, to name a few. However, we see still room for improvement in various areas of the text, including related to the references to human rights, state responsibilities in international law, appropriate reflection of the implementation of norms of responsible state behaviour as a priority, as well as some elements of the regular institutional dialogue. As agreed from the start, it’s important that our discussion builds upon our consensus agreements, and it’s also important that our work continues to improve and build upon the previous Open-Ended Working Group and GGE reports. The draft in front of us demonstrates different opinions voiced in the valuable discussions we had through the past years, and it also lists proposals, and proposals for interesting informal inter-sessional meetings, such as a dedicated global roundtable meeting on ICT security capacity building during the inter-sessional period. It would, however, be helpful if we could put forward a potential timetable to make sure that we all have time to sufficiently prepare and provide valuable contributions to those discussions. It would allow everyone around the table to make the necessary travel arrangements and have the relevant input and engagement of all of our experts. We also have to consider the budgetary implications of all of these proposals. Chair, we continue to be committed to the Open-Ended Working Group, and over the recent year, we’ve worked hard, and we hope that by the end of the week we will manage to agree on a balanced and concrete annual progress report. But before I go into the threat section, let me express my solidarity with Ukraine and the Ukrainian people. With the discussion on the use of ICTs in the context of international security as we have them today, we cannot ignore the fact that unjustified cyber operations by Russia in Ukraine are an ongoing threat to Ukraine, as well as to all of us, our international peace and security. It’s the largest military conflict of the cyber age, and the first to incorporate such significant levels of cyber operations. Our discussions, therefore, continue to be of immediate relevance. We welcome, therefore, our discussions to exchange views on existing and potential threats to international peace and security, and would like to thank the Chair for the draft report, as well as the suggestion for continued exchanges. We acknowledge the work that has gone into producing this draft. The existing and potential threat section forms the foundation of our work. We share our threat perceptions, and this is key to identifying common threats and finding convergences. It also serves as a basis to find solutions to the threats that we face. We appreciate, therefore, the reference to ransomware, as well as the language on the increase in malicious activities impacting critical infrastructure, and the threat posed by malicious ICT activities targeting supply chains. We have been developing a regulation to bolster cybersecurity rules to ensure more secure hardware and software products, and many other states are doing the same, and it’s useful to exchange on these types of products. Similarly, we appreciate the reference to malicious cyber activities that could undermine trust and confidence in political and electoral processes and public institutions, as well as the reference to humanitarian organizations and health care. Attacks against humanitarian organizations are not an act that the international community can take lightly, and the proposal that was put forward by Switzerland about the need to safeguard digital assets merits further consideration by this Open-Ended Working Group in the future. I would also like to emphasize again the need to create a clear linkage between the existing and emerging threats we identify and deepening the implementation and discussing recommendations and proposals for the responsible use of ICTs should be reflected in the report through the various chapters. We appreciate the recognition in this regard that ICTs have already been used in conflicts in different regions. Since the use of operations as a means, methods, or warfare in armed conflicts poses a real threat of harm to civilians, we would like to suggest including direct references to concrete threats and to the military use of ICTs in the section summarizing threats, and to reflect the norms of responsible state behavior that adhere to them. ICTs are not a threat in themselves. It’s only when they’re used inconsistently with international peace and security that they may pose a threat. It’s the responsibility of the international community to ensure that those capabilities are used on the battlefield and that they are used in a manner that complies with long-standing rules of warfare and in a way that minimizes human suffering. In order to further our understanding of how new technologies such as AI and quantum computing may affect the risk posed by the use of ICTs to international security, we recommend having more focused discussions on the potential impact of these technologies on the use of ICTs and to also include the multistakeholder community in this context. We recognize that these are key drivers of economic progress, and we will continue to promote a human-centric and balanced approach to AI in the EU and globally. Let me thank you again, Chair, and express our commitment to making this week a success. And note that, as in paragraph six said, the EU will continue to play a role in the implementation of the framework of responsible state behavior in cyberspace. Thank you very much.
Ambassador Gafoor
Thank you very much, EU, and welcome back to the process after some time. I give the floor now to Nicaragua, to be followed by Brunei. Nicaragua, please.
Nicaragua
Thank you very much, Mr. Chair. We, the Republic of Belarus, the Republic of Burundi, the People’s Republic of China, the Republic of Cuba, the Democratic People’s Republic of Korea, the Islamic Republic of Iran, the Republic of Nicaragua, the Russian Federation, the Syrian Arab Republic, and the Bolivian Republic of Venezuela, express our full support to the Open-Ended Working Group on security of and in the use of ICTs 2021-2025, and look forward to ensuring tangible results of the second year of the group’s activities. We know that the revised draft of the second APR, REV-1, has a number of crucial drawbacks that raise significant concerns about the text. Thus, we believe that this draft is yet to be balanced and factual by incorporating the views and concerns of all member states so as to reach a consensus. It is our firm belief that the following changes need to be made to the document. Number one, the draft report should go strictly in line with the mandate of the OEWG as enshrined in the UNGA Resolution 75-240, which tasks the group to continue as a priority to further develop the rules, norms, and principles of responsible behavior of states and ways for their implementation. It is crucial to restore the necessary balance between the development and implementation of norms instead of laying excessive emphasis on the latter. Of significant importance is the elaboration of legally binding obligations as suggested by a number of states and reflected in the UNGA Resolutions. Number two, the draft report should treat equally the variety of national proposals put forward by states within the OEWG. It should not lay excessive emphasis on some of them, including through dedicated sessions and intersessional meetings, while neglecting the others. To prove equal treatment of all national initiatives, the document should therefore reflect the concept of a UN Convention on International Information Security co-sponsored by Belarus, DPRK, Nicaragua, Russia, Syria, and Venezuela, submitted as an official document of the 77th UNGA session. Three, the draft report should not predetermine a future decision of states in the format of regular institutional dialogue on security in the use of ICTs under the UN auspices. Such a decision should be made by consensus and within the OEWG, not imposed by a group of states. Evident bias in favor of the Program of Action (POA) to advance responsible behavior of states in the use of ICTs is unacceptable. It is worth noting that the POA is only one of the proposals on the table, which is not supported by all states. Its substance remains unclear. Its proposed structure, mandate, scope, and method of work are subject to continuous change and impartial approaches. Four, the OEWG draft report should not include proposals which may be exploited for further politicization of ICT security issues, like a voluntary repository of threats to ICT security. Five, the OEWG should further discuss initiatives stated within the mandate of the group for possible consideration and reflection in its future reports to ensure their objective and politically neutral nature. Issues that fall out of the scope of the OEWG’s mandate should be deleted from the APR. Six, the role of the private sector as well as the so-called other interested parties in ensuring information security should not be overestimated. While the proposal to hold private actors accountable is yet to be reflected in the APR, it is unacceptable to highlight one specific organization, namely the GFCE, as the main capacity-building initiative. The OEWG is an intergovernmental process in which negotiation and decision-making are exclusive prerogatives of the member states. Mr. Chair, we reiterate our deep disappointment on the host country’s failure to issue visas for a number of delegates. Those colleagues’ absence will hinder our delegation’s ability to fully participate in the session and will result in losing their valuable and essential contributions. We would like to kindly request you, Mr. Chair, to find a suitable solution for this matter and urge the host country to uphold its legally binding obligations. We remain committed to engaging constructively in negotiations on the annual progress report and look forward to crafting its language in a balanced and factual manner at the fifth session of the OEWG. We wish that the second APR could satisfy all member states to feel the ownership and garner an unquestionable consensus through a meaningful and interactive approach, which in turn can avoid an undecidable situation for the delegations to take it or leave it on the last day of the substantive session. Having said that, and along with these points, we will reiterate in due course our proposals aiming at materializing such a goal. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Nicaragua, for your statement on behalf of a group of states. I give the floor now to Brunei Darussalam, to be followed by the United States. Brunei, please.
Brunei
Thank you, Mr. Chair. I have the honour to deliver this statement on behalf of the Association of Southeast Asian Nations, ASEAN. ASEAN is pleased with the strong engagement demonstrated in this Open-Ended Working Group, which continues to serve as a confidence-building measure towards building an open, safe, secure, stable, accessible, interoperable, peaceful, and resilient cyberspace. ASEAN remains actively engaged in discussions on cybersecurity through relevant ASEAN-led mechanisms, and we are pleased that this OEWG has allowed us to share our original experiences with the rest of the world. We are also encouraged by the rich debates and focused exchange of views in this forum, which has paved the way for realizing points of convergence among Member States. Therefore, Mr. Chair, we believe that a second Annual Progress Report, APR, is necessary to capture the constructive momentum that this OEWG has posted. It is important for the APR to be substantive and adopted by consensus at the end of this week. Accordingly, the second APR should build on the first APR in order to continue the progress that has been made under all items within the mandate of the OEWG. In terms of concrete outcomes, ASEAN looks forward to reaching an agreement on the key elements for the development and operationalization of a Global Intergovernmental Points of Contact Directory. We hope ASEAN’s original experience on the POC Directory on Security of and in the use of ICTs within the ASEAN Regional Forum that has previously been presented to this Working Group could serve as a point of reference in our deliberation. Overall, Mr. Chair, we are confident that through our collective diplomacy, we will continue to generate ideas and workable solutions based on equal and full participation of all Member States. We look forward to contributing constructively to the OEWG alongside the international community in enhancing cybersecurity, which remains crucial for the overall maintenance of international peace and security. I thank you.
Ambassador Gafoor
Thank you very much, Ambassador, for that statement on behalf of the ASEAN countries. I give the floor now to the United States, to be followed by India. U.S., please.
United States
Thank you, Chair, and greetings to you and my fellow delegates. First, thank you, Chair, for your work and the work of your team on this draft APR. It provides a good basis for our conversations this week. While we have no specific language suggestions for the introductory section, I want to take this opportunity to provide some overall comments on the latest draft. We appreciate the Chair’s action-oriented and forward-looking approach to the draft annual report. This report should serve as guidance for the OEWG’s work over the next year, and we think the current draft is a good starting point. Our comments this week will be aligned with the view expressed in paragraph 8, that this APR is intended to capture concrete progress made at the OEWG to date, and is not intended to be a comprehensive summary of discussions, which I think we would all recognize would be very difficult given the robust discussions we’ve had within this forum this year. One issue I wanted to raise as a general matter is a concern that the draft may not accurately reflect the current capabilities and roles of the OEWG and the UN Secretariat, and that some elements of it could have budgetary implications. Expansions of these roles will likely have these implications and need to be carefully considered. There are existing mechanisms both within the UN and outside of it, in regional organizations and other groups, that we should leverage to the extent possible. One example of this is the many recommendations for dedicated intersessional meetings or global roundtables. We appreciate the Chair’s ambition but are reluctant to support these proposals without a better understanding of their budgetary implications. Finally, in a few places, the draft appears to stray a bit beyond the remit of the First Committee and the mandate of this group. The OEWG’s scope is security of and in the use of ICTs in the context of international security, in furtherance of the UN’s mission to maintain international peace and security. We must stay focused on that mission and approach all issues, including capacity building, through that lens. Turning to the threat section, the Chair’s updated draft is a general improvement over last year’s threat section and provides a good starting point for our discussions. With paragraph nine, both recalling threats we discussed last year and recognizing that the threat landscape continues to evolve, including via increasing cyber threats to critical infrastructure that can have cascading effects. We believe the annual report should acknowledge the increased risk of escalatory or uncontrolled cyber activity and the cyber threats faced by humanitarian actors. We have also become more aware of the risks posed by cyber criminals who are allowed by certain states to operate with impunity from their territory. All these issues are relevant for the group and we welcome their addition to the draft APR. In paragraph 10, we do not support the inclusion of references to dis- and misinformation or deep fakes, which are topics outside the OEWG remit and have not been addressed in prior OEWG and GGE reports. Also, we do not understand the reference to data security here in the list of activities of concern, given that the security and confidentiality of information is a priority for many states. The term should be removed or edited. Paragraph 10 should begin with “states express concern regarding the exploitation of ICT product vulnerabilities.” In paragraph 14, we recommend reverting to the phrasing of last year’s APR, paragraph 11, which speaks about potential development opportunities of emerging technologies, not just their neutrality, and acknowledges that their evolving properties could expose new vulnerabilities and vectors for ICT exploit. We do not support framing this text in the context of attack vectors, which makes this paragraph unacceptably narrow, given that the term attack is not used to describe most malicious cyber activities. Also, in paragraph 14, we reject the inclusion of cloud technology in this context. Within cybersecurity communities, it is generally understood that cloud technology can be much more secure than other on-premises service solutions. This OEWG will do a disservice to cybersecurity if it asserts otherwise. Paragraph 15 discusses a proposal for a voluntary threat repository. We recommend referencing this proposal in the CBM section, given that this section of the text should be used to describe threats, while measures to address those threats should be elsewhere in the document. Regarding the text itself, we are interested in discussing this idea further and are, of course, supportive of information sharing on cyber threats. That said, there are numerous technical forums that already share cyber threat and vulnerability information among practitioners. To effectively consider whether a new repository is necessary, states need to discuss existing information sharing methods, including cert-to-cert channels and the release of public threat advisories among many options. Relatedly, in paragraphs 15 and 20, the word neutral should be removed. In forums where states discuss threats, states are expected to share factual information about what they perceive as threats or what they see as constituting a significant cyber incident, and the term neutral to us does not make sense in that context. Therefore, we propose the following revisions to the text. For paragraph 15, we propose, “states discuss the proposal for a new voluntary threat repository, including how such a repository could take into account and complement existing threat information sharing mechanisms, such as cert-to-cert channels.” For paragraph 20, we propose “states recognize the need to share information on ICT threats in the context of international security in an inclusive and accessible manner. In this regard, states should engage in focused discussions on existing methods to share ICT threat information and consider whether and how to enhance such information sharing.” Finally, regarding paragraph 21’s proposal for an intersessional meeting on emerging technologies, I would like to highlight that there are several UN initiatives on emerging technologies, including a GGE on lethal autonomous weapon systems. So any OEWG discussions should be carefully scoped to avoid duplicating that work. Thank you, Chair.
Ambassador Gafoor
Thank you, United States, for your focused contribution. India to be followed by Kenya. India, please.
India
Mr. Chair, dear colleagues, a very good morning to all of you. Rarely do we see such a sight of a house full meeting. And this is, Mr. Chair, not only just because of the topic of the meeting, but also the way this Open-Ended Working Group on ICT security has been ably led by you, supported by your very dedicated and hard-working team. So, Mr. Chair, first of all, let me thank you for your continued leadership of the OEWG, your step-by-step approach and a consensus-driven approach, your focused attention in resolving the modalities matters, and last but not least, your conscious efforts and initiatives to make the functioning of this working group more open, transparent, and inclusive. We commend you for your efforts in drafting the GERO draft and subsequently the REV1 of the second annual progress report of this OEWG, which reflects the wide range of views expressed by Member States during the previous substantive sessions as well as inter-sessional sessions. We commend your approach of bringing such a comprehensive draft. Mr. Chair, now paying heed to your request, I will cease the temptation of making a general comment. And with your permission, I would like to suggest an edit to point 10 under section B, existing and potential threats in the draft EPR. It is the last sentence of point 10. The sentence currently reads as, “some non-State actors have demonstrated ICT capabilities previously only available to States.” India requests the addition of quasi-State actors in the line, and with that added, the revised sentence would read as, “some non-State and quasi-State actors have demonstrated ICT capabilities previously only available to States.” And I would like to present the rationale behind this edit. Today, there are actors and entities that straddle the line between Statehood and private existence, borrowing characteristics from both without fitting neatly into either designation. These quasi-State actors have access to ICT capabilities that otherwise should only be available to States. These QSAs tend to exploit a legal loophole that allows them some of the advantages of sovereignty without corresponding obligations and hence pose a serious threat to international security. And we believe that the inclusion of quasi-State actors in point 10 under section B, as proposed just now, would help in addressing the lack of accountability of QSAs for behaving responsibly in cyberspace. My delegation is available to provide further information and justification if needed and would be sharing further details during the course of our discussion on the draft report. We reserve our right to provide further comments if necessary during the course of our discussion. Mr. Chair, I would like to stop here and before handing over the floor back to you, let me reiterate the support of my delegation in making this session productive and action and outcome-oriented. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, India, for your contribution. Kenya to be followed by Côte d’Ivoire. Kenya, please.
Kenya
Thank you, Chair, Excellencies, dear colleagues. Kenya commends you, Chair, and your team for your continued efforts in providing us with an action-oriented program of work as we put our efforts together to engage in the Second Annual Progress Report for a consensual outcome for this session. You can count on Kenya’s support. It is our position that the revised draft of the second APR reflects the actual discussions tabled and therefore a good starting point for discussion and negotiations. We commend the efforts you have taken long before the beginning of this session to consult and try and find a middle ground on the issues. Chair, on existing and potential threats, the concerns reflected in paragraph 10 and the subsequent sections, particularly 10-B, 10-[unclear], and 10-[unclear], are reflective of the broad implications that existing threats continue to pose to our ICT ecosystems, including critical infrastructure and critical information infrastructure, not to mention the urgency to address them. Colleagues, the nature of emerging technologies, including their ubiquity, programmability, and data-driven nature, has also opened a door for misuse by cyber threat actors. The increasing malicious use of ICTs by terrorist and criminal groups continues to hamper developing nations’ efforts in the delivery of essential services to its citizens and subsequently stalling efforts to bridge the digital gap. It is therefore our hope that highlighting this issue in paragraph 10 will lead to enhanced global collaborative efforts in combating violent extremism and terrorist activities in the ICT ecosystem. Mr. Chair, in relation to AI and quantum computing, and specifically AI and its use in deep tech, we support the language of paragraph 14, including the emphasis that despite the neutrality of the technology, it has the potential of being used for high-stake national misinformation, disinformation, and malinformation with capabilities of destabilizing a state’s peace and national, regional, and international security, given the increasing exploitation of threat vectors related to information systems. One of the challenges Kenya has experienced is with malinformation or defects, where mimicking of high-level representatives contributes to fanning hostilities and divisions. Consideration of possible interventions and mitigation measures must remain a priority. Malicious cyber threat actors exploit these technologies using malware, ransomware, distributed denial of service, and crypto-jacking attacks, which compromise container-based cloud systems, restrict access to services, expose restricted data, and enhance backdoor attacks. Mr. Chair, in relation to paragraph 15, we appreciate the inclusion and the retention of this paragraph as an implementation and capacity-building measure. Its reflection here is a non-politicized urge for the international community to enhance its cooperation in addressing existing and potential threats to information and data security while leveraging accessibility to the threat landscape for all. To deepen our understanding of potential risks, the international community should consider establishing a UN-run repository of common threats that members can regularly update in the face of new and emerging threats. The language of paragraph 15, as it stands, allows for a voluntary, practical, and neutral platform that Kenya believes will be critical once operationalized. Based on discussions in the fourth substantive session, my delegation has since circulated a revised draft working paper that further emphasizes the non-attribution and non-duplicatory nature of this proposal for our further consideration. My delegation looks forward to your views, including an engagement on the modalities of the platform within the OEWG. Chair, we all agree that technology transcends international borders and such an effort is in the spirit of the mandate and building blocks of the OEWG. We therefore wish to request that the power remains as is and we retain the words are stricken out, that is, and facilitate a discussion on cooperative measures to address them. Additionally, paragraph 15 lends credence to paragraph 18. As such, a repository would be an ideal resource of information in addressing the lack of awareness of existing and potential threats, including the lack of adequate capacities to detect, defend against, or respond to malicious activities. Paragraph 16, Chair, articulates the need for a gender perspective in addressing ICT threats, including specific risks faced by vulnerable groups. Kenya supports this power, considering the important role of ICTs and the role they play in socioeconomic development that encompasses even the most vulnerable members of our society, the underserved, marginalized, and people with disabilities. As a country, we have embarked on an ambitious project which has borne fruit in the inclusive digitization of 5,068 citizen services. This is against the reality of how irresponsible acts from both state and non-state actors can have a significant impact on the delivery of citizenry services and even a potential threat to stability. On recommendations and next steps, Kenya supports the recommendation as outlined in paragraphs 19 and 21, as spelled out in the APR, but with a more approach that includes quantum computing, artificial intelligence, and all other emerging technologies. We also, however, wish to request that the language in paragraph 20 remains as was initially worded for the reasons we have outlined. On our part, we have sought initiatives to mitigate against new and emerging ICT threats by enhancing broad multistakeholder conversations and forging partnerships with technology providers to have security by design that factors in geocultures whose preservation is important in maintaining regional security. In its quest to secure its digital space, Kenya has, among others, established the National Kenya Computer Incident Response Team, implemented the national public key infrastructure, and recently inaugurated the National Computer and Cybercrimes Coordination Committee, which comprises relevant ministries and agencies with a fully-fledged secretariat. Let me conclude, Chair, by reiterating our call for practical support for efforts to establish programs and mobilize resources to unlock greater access for developing countries to ensure that no state is left behind. I thank you.
Ambassador Gafoor
Thank you very much, Kenya. Côte d’Ivoire to be followed by Colombia. Côte d’Ivoire, please.
Russia
Thank you, Chair. The delegation would like to express gratitude for this excellent draft 2023 APR under consideration at this session, which reflects in a balanced manner the viewpoints expressed during our previous sessions. ForCôte d’Ivoire, it is an excellent document that ought to foster discussions in order to arrive at a consensus-based halfway progress report. As Chair, we are also very pleased that this document uses the same structure and approaches of the first annual report, which is based on concrete action, including for future work. This methodology is very helpful because it allows us to accurately reflect our deliberations and their changes over time. With regard to the section on existing potential threats, Côte d’Ivoire is pleased with the large section that is devoted to identifying actual current and potential threats as well as their consequences. Understanding the complexity of security challenges and their changes is indeed crucial for the utility of the working group and for the appropriate responses that it could provide. Here, in order to better protect and conserve this action, my country would like to see more attention paid to means of preventing cyberattacks on critical infrastructure, including critical information infrastructure. When it comes to optional and non-binding norms of responsible behavior by states, Côte d’Ivoire welcomes and supports the drafting of a glossary of technical terminology which would contribute to a better understanding of these norms and would also facilitate their adoption and implementation. As for the applicability of international law to cyberspace, an in-depth reflection on the modalities of this application, especially when it comes to the UN Charter, is something my delegation is very satisfied with. My country also supports the establishment of various measures to strengthen the role of international law in order to build a safe, stable cyberspace. Côte d’Ivoire also welcomes the focus placed on competence and transparency-building measures to improve mutual understanding between cyberspace actors, which is a key prerequisite for establishing a peaceful digital environment. It therefore fully supports the establishment of the POC’s directory and calls for its adoption at the present session in order to be operationalized in the near future. Chair, the reaffirmation in this report of the cross-cutting nature of capacity building and the fact that it serves as a common thread running through all of the actions proposed for other pillars is something the delegation welcomes. For us, that reflects the reality of the importance of this pillar of our collective efforts to attain lasting stability in global cyberspace. It deserves greater attention as we continue our work to consolidate its effectiveness with the goal of developing response measures for cybersecurity incidents. This could improve the implementation by all states of the Responsible Conduct Framework. Lastly, when it comes to regular institutional dialogue, Côte d’Ivoire favors the establishment of a permanent inclusive mechanism that aims to promote action within the extended working group and is pleased with possibilities in this regard during our upcoming discussions. Chair, in conclusion, we would like to reaffirm our commitment within this working group and also reiterate our support for the 2023 Annual Progress Report and its consistent adoption. Thank you.
Ambassador Gafoor
Thank you,Côte d’Ivoire. Colombia, to be followed by Germany. Colombia, please.
Colombia
Thank you, Mr. Chairman. We are grateful for your stewardship of this working group and particularly the transparency with which you’ve displayed in our discussions in this working group, in the inter-sessional meeting in May, the draft of the second annual progress report, and then the revised version, and also the informal meeting on the 27th of June. We also welcome the valuable commentaries from Mr. Adedjigebu and the work of the secretariat. Sir, we believe that the draft of the second annual progress report is a balanced text. It, in general, reflects the discussions which were held in this group since the third session. It develops the roadmap shaped in the first annual report and outlines the necessary work for future sessions. We welcome the fact that in each theme in the group’s mandate, there is inclusion of practical steps to be taken which are different and complementary, involving all states, civil society, academia, the regional organizations, and the OEWG. We welcome the fact that both the importance of developing future agreements as well as driving forward existing agreements are included. We believe that the adoption of, in this fifth session, the second report together with its annexes and the development and authorization of the global directory of POCs and the listing of CBMs will contribute indeed to the purpose of strengthening cooperation, transparency, and predictability among states with the aim of promoting a cyberspace which is open, safe, stable, accessible, peaceful, and interoperable. We have the firm belief that the development of our discussions on these various aspects in the mandate of the group will contribute to reassert, clarify, and indeed solidify the responsible behavior of states in the use and security of ICTs. Mr. Chairman, my delegation does have comments and proposals which are specific on the report draft, and we shall at present just refer to the overview, general description. On particular aspects, we refer to paragraphs two and three, and we remember that groups agreed on ICTs regarding OEWG and looking at the general development of responsible behavior of states. This is the bedrock for the work of this group, and here we certainly emphasize the reassertment session that international cooperation with the UN is essential to maintain peace, security, and stability in ICTs. Regarding three, we suggest the inclusion of international humanitarian law. We believe that UN – that this should be applied only in aspects of armed conflict and should in no way affect the prohibition of the use of ICTs in a grifted manner. We believe that responsible behavior in the use of ICTs and in accordance with international humanitarian law should be included. When it comes to paragraphs five, six, and seven referring to the commitment, we believe that in a substantive and systematic way we should look at the sharing of responsibilities which are regional, inter-regional, and at responsible behavior and also the importance of closing the digital divide, gender gaps, and ensuring a significant participation of women in decision-making processes related to this. When it comes to potential and existing threats, we emphasize that there is inclusion of the principal ones identified within this group such as the use of malware affecting critical infrastructure and essential information, supply chains, internet availability, and humanitarian actions. We emphasize the use of ransomware and technological development, particularly artificial intelligence and quantum computing, which can have an effect on vulnerability. On this last, we refer to the need for there to be a constructive dialogue regarding how it is possible to address these and at the same time avail of the potential of these technologies. In particular, AI is important. It has to be remembered that information here has to be shared in a way that is relevant in order to look at the data supplied particularly by states. And here, Mr. Chairman, the distinguished delegate of the US referred to the processes which have been carried out in Geneva regarding autonomous and independent and lethal weapons systems. I think it’s important to emphasize the lessons learned from this process which is being completed at present, and I just wish to emphasize the fact that in this case, as in all other cases pertaining to cyber security and other use of other armaments, international law applies and must be the basis and bedrock of the use of any new technology. Regarding paragraph 18, we support the need to become more aware of understanding of threats in order to develop the joint responses by means of cooperative measures. And here, referring to paragraphs 15 and 20 on the proposal to develop voluntary POR on threats, we reiterate again our support for this. We believe that a directory of threats, common threats administered by the UN, would help states to arrive at a deeper understanding of the potential risks here given the resilience of information systems and the threat from cyberspace. This would lead to a greater strengthening of interstate relations. And then we refer to the dialogue of the 11th of July. We believe that the contributions here could prove to realistically understanding threats. So we would like to see paragraph 20 included in the proposals to be explored looking at the establishment of the directory, and we believe that stakeholders should be included in discussions when they come to this. Regarding paragraph 21, we support the proposal that there be an interstitial meeting on the development of new technologies and their possible impact on cyber security. We suggest that in this session we provide room for the states which have been victims of cyber attacks and wish to participate on a voluntary basis should share their experiences, including lessons learned, good practices, and protocols for protection, response, and cooperation which have emerged as a result of these attacks. We would emphasize again the relevance of the inclusion of civil society, including the private sector and academia, in discussions on how it is possible to address future attacks, taking into account the knowledge and the role of these in developing ICTs as well as the fact that in practice, cyber attacks do have impacts on different stakeholders. With these comments, we wish again to express Colombia’s support for your chairing of this meeting and to say that we continue to participate in this working group in order to contribute to the adoption by consensus of the second annual report. Thank you.
Ambassador Gafoor
Thank you very much, Colombia, for your contribution. Germany, to be followed by the Republic of Korea.
Germany
Germany wishes to thank you, Honourable Chair, and your team for compiling a very substantial and ambitious draft of the Annual Progress Report, which is a good basis for building consensus. The report demonstrates how much dedicated work from delegations has been accomplished and how far we have progressed in our discussions as a group. There is a clear dynamic away from solely engaging in an exchange of views towards achieving tangible results with the potential for real cyber world impact. And the draft API in front of us reflects that positive trajectory most clearly in its actions on confidence-building measures and on capacity building, which have both seen significant progress. However, the report also requires substantial further work in order to fully and accurately reflect the proposals that have been brought forward by delegations over the past year. This particularly concerns the sections on rules, norms and principles, international law, and regular institutional dialogue. Germany welcomes the substantially expanded section on existing and potential threats. In Germany’s view, the draft of this section for the first time attempts to mention the full range of security challenges that this open-ended working group is dealing with. Germany in particular welcomes the focus on the security challenges associated with political and electoral processes as these touch the core of state sovereignty and the democratic right of citizens to freely choose those who govern. The draft for the first time acknowledges that ICTs have already been used in conflicts in different regions. This is an important step forward since this reflects the reality of modern-day conflict across the globe. Germany proposes making the following addition in paragraph 10, which would read in sentence 2, and express concern that ICTs have already been used in conflicts in different regions, and add, also causing significant cross-border spillover effects for states not involved in conflict. Germany and other countries have extensively described the risks associated with spillover effects, which are a characteristic feature of conflict in the cyber domain, and therefore need to be reflected in this report. Germany also proposes to make mention of ransomware attacks in this section, paragraph 10, noting that this is a growing trend with the potential to destabilize states and to have a harmful impact on international peace and stability. Germany can support the existing language in paragraphs 15 and 20, summarizing Kenya’s proposal on a repository of threats. This is a proposal that merits further discussion in this group. As the issue of threats is really at the heart of the work of this group, in many ways the starting point of our discussions under all agenda items, Germany supports the draft of this section as a strong opening chapter of the API. Germany also looks forward to participating in the dedicated inter-sessional meeting on threats, with the participation of expert speakers to collect independent expert input for further work of this group. The draft in front of us contains proposals for five different meetings to be held outside the formal session of the open-ended working group, as well as a sixth meeting focusing on the review of the POC directory. Germany would welcome guidance from the Chair at some point during this session on how this sequence of meetings can be held in a way that allows for the broadest and also most meaningful participation of all UN Member States. Please also allow me to add, Mr. Chair, that in responding to the strong interest expressed by this group in advancing our discussions on cyber capacity building, Germany has partnered with Japan and the World Bank to host a side event to present the work of the World Bank’s multi-donor trust fund. This will be right after the session at German House, and lunch will be served. Thank you.
Ambassador Gafoor
Thank you very much, Germany, for the free lunch. Lunch is always a good confidence-building measure, not to mention that it also builds some capacity. So I think there are quite a number of side events this week, and I certainly would encourage delegations to participate in as many of them as possible. I know there have been some questions relating to the timeline as well as budgetary implications of some of the additional intersessional meetings that have been proposed, and I’ll address these questions at a later stage. Right now, I’ll continue to go through the speaker’s list. Republic of Korea, to be followed by Pakistan. All okay, please.
Korea
Thank you. Thank you, Chair. I’d like to start by expressing my delegation’s gratitude to you and the Secretariat for organizing the fifth substantive session of the OEWG, and for all the preparatory work, including the drafting of the second annual progress report. We believe the revised draft of the second APR provides a sound basis for the discussion to follow this week. The revised draft captures detailed progress made at the OEWG during this year’s discussions, and we believe that further elaboration compared to the first APR signifies the progress at the OEWG. My delegation believes that the fifth substantive session should not merely be a venue for revisiting the previous discussions at the OEWG, but also an opportunity to make further progress with consensus. This year’s APR should aim to capture further developments and provide a window towards broad consensus. To this end, my delegation hopes that the OEWG will expand consensus, especially with regard to the operationalization of the Global Point of Contact Directory, specifying how international law applies to cyberspace and the implementation of the existing norms, and the establishment and the working method for the Program of Action. In the overview part, we welcome the 11 norms of responsible behavior and the Charter of the United Nations as applicable to international law being mentioned in this report. However, to be precise, we reiterate our position that the Charter of the United Nations in its entirety is applicable in cyberspace. My delegation welcomes Paragraph 5 in mentioning again that the OEWG is committed to engaging stakeholders in a systemic, sustained, and substantive manner. Once again, we reiterate our view that the multistakeholder approach needs to be upheld in the OEWG process. We also welcome and support Paragraph 7 on the participation of women, delegates, and gender perspectives in the OEWG process. The message in this particular paragraph is an important one that my government supports across the board. We appreciate the APR duly reflects this important message. With respect to the existing and potential threats, my delegation supports Paragraph 10b, which mentions malicious activities impacting critical infrastructure and critical information infrastructure. We believe attacks against CI and CII have substantial security and humanitarian implications. We’d just like to suggest here in this part adding energy alongside healthcare, maritime, and aviation. Since the energy sector also has a huge impact on the lives of people, economy, and security of a country. For this reason, it’s becoming a potential target of malicious activities. We commend the chair’s efforts in specifying malicious ICT tools and recent technological developments that have contributed to the disturbing trend of aggravating cyber threats. We especially support the mention of ransomware in Paragraph 10 quarter as malicious ICT tools and techniques. Ransomware has exploited the vulnerabilities of our ICT-reliant daily lives during the pandemic and as a result, the damage caused by ransomware has tripled between 2019 and 2022. My delegation also welcomes Paragraph 18. Inadequacy of awareness and capacity certainly makes a state vulnerable to malicious ICT activities. As malicious actors increasingly search for vulnerabilities, this ultimately causes detrimental effects, especially to states lacking capacities. This calls for strengthened international cooperative measures, especially capacity-building efforts for these states. Regarding Paragraphs 15 and 20, which elaborate on the suggestion of establishing a threat repository, we acknowledge the potential benefits of its establishment and we can support it being included in our annual progress report. Having said that, it would be preferable that such a repository be established with minimum additional administrative and financial burdens. So we hope that we continue our discussion on this issue with more information on the possible options on how financially and administratively this idea can be supported. Mr. Chair, my delegation recalls that during the previous session and following intersessional discussions, several delegations, including my delegation, expressed concern over increasing cases of cryptocurrency theft. Cryptocurrency theft is often used to finance illegal activities, including the development of weapons of mass destruction, posing a threat to peace and security of the international community. Therefore, we would like to suggest adding cryptocurrency theft in the first sentence of Paragraph 10 quarter. With this suggestion, thank you very much.
Ambassador Gafoor
Thank you, ROK. Pakistan, to be followed by the Russian Federation. Pakistan, please.
Pakistan
At the onset, Pakistan would like to express its utmost appreciation for the remarkable efforts made by you and your team in compiling the second annual progress report, especially its revised version 1, in a balanced manner. The sections related to the CBMs and capacity building rightly capture the views and comments of the member states. However, Pakistan believes that still there is room for further improvement in the APR to make it more balanced by incorporating the views of all member states on critical issues pertaining to the use of ICTs and their impact on global security. Chair, I am also aware that the primary goal of the first substantive session of the OEWG is the adoption of the second APR. Therefore, my intervention will be succinct. Chair, coming to the overview section of the APR, Pakistan agrees with the language, except for one amendment that I would like to propose at line 11 of paragraph 3, which could be read as, “and call for discussions on the formulation of a legally binding instrument to ensure the responsible uses of ICTs.” This amendment is in line with Pakistan’s consistent position that the formulation of a legally binding instrument is essential to ensure responsible uses of ICT for safe, secure, and stable cyberspace. Chair, coming to the threats portion of the APR, which rightly takes stock of the existing and potential threats posed by the malicious uses of ICTs by both states and non-state actors, Pakistan agrees with the assertion given in the APR that the military applications of ICTs have significantly accentuated the threats to international and regional security in recent times. Pakistan endorses the incorporation of language expressing concerns over the rising trends of the use of ICTs for attacks on critical infrastructure, misinformation and disinformation campaigns, the exploitation of vulnerabilities, and supply chain-related attacks. However, we have a proposal for amendments as well. In paragraph 10, quarter, we would like to propose an amendment in the first line, which could be read as, “states express concerns regarding misinformation, fake news, and disinformation.” Pakistan proposes the addition of the word “fake news” in the first line because Pakistan believes that the malicious uses of ICTs, especially for spreading disinformation, misinformation, and fake news by both states and non-state actors, not only jeopardize regional and global peace and security but also give rise to social unrest in certain countries as well. In paragraph 11, Pakistan would like to propose the addition of the language in the fourth line, which could be read as, “the growth of illegal markets in dark web and open source offering access to inter-area software vulnerabilities.” We believe that states must discuss means and methods to curb the illegal activities in dark web. Chair, in the end, I would like to reiterate Pakistan’s full support for the consensus adoption of the second APR. I thank you, Chair. Thank you.
Ambassador Gafoor
Thank you, Pakistan, for your contribution. Russian Federation to be followed by Malaysia. Russian Federation, please.
Russia
Distinguished Chair, distinguished colleagues, I am forced to respond to certain statements heard during the morning session, that is, unfounded anti-Russian statements. This is yet another attempt to disrupt and politicize the work of the OEWG. We believe that these tricks are outrageous and disrespectful to all participants in the negotiation process. Distinguished Chair, I am appealing to you. The Russian delegation is prepared to give a detailed response to the insinuations that have been made against us. I assure you that we have many more reasons for accusatory rhetoric. Nevertheless, we respect you, Mr. Chair, and the participants of this negotiation process as well as our joint work. Therefore, at this stage, we will not allow ourselves to be drawn into a politicized debate. We call on all delegates to maintain a professional and constructive approach for the benefit of successful and efficient work by the OEWG. Distinguished Chair, if such anti-Russian rhetoric is repeated, the Russian delegation reserves the right to reply. Distinguished Chair, before making concrete comments by the Russian Federation on the text of the draft annual report, I’d like to make a statement on behalf of the head of the Russian delegation at the OEWG, the director of the Department of International Information Security of the Russian Ministry of Foreign Affairs, Artur Lukmanov, who unfortunately is unable to take part in in-person meetings of the OEWG due to systematic refusals by the U.S. Government to issue him a visa. I’d like to make greetings to all participants of the fifth session of the OEWG on the security of and the use of ICTs, 2021-2025. This group is approaching the halfway point of its activity. It is crucial that by this milestone, thanks to the efforts of the majority of states and the distinguished Chair, Mr. Gafoor, and the UN Secretariat, we have nearly managed to achieve the first practical outcome. I’m referring to the establishment of an intergovernmental directory of points of contact. The launch of this mechanism under UN auspices will for the first time in history allow the competent authorities of all countries to cooperate in order to prevent computer attacks and incidents and to mitigate their consequences, as well as to share experience and strengthen mutual trust, as well as cultivate expertise. This last is especially important for developing countries that are facing a shortage of experts in ICT security. We are convinced that if established, the POC’s directory will become a cornerstone for future agreements on all aspects of the mandate. Russia believes that the main efforts should be directed at developing a universal, legally binding instrument in the field of ICTs and their use. At the OEWG meeting in March, we presented to UN member states a prototype of this document in the form of a concept of a convention on international information security. In May, together with Belarus, DPRK, Venezuela, Nicaragua, and Syria, we submitted it as an official document of the 77th session of the UN General Assembly. This concept aims mainly to ensure the prevention and peaceful resolution of conflicts in cyberspace, creating conditions for the protection of all countries from modern threats to information security, as well as to build up the capacity of developing countries. Our initiative is based on the principles of the sovereign equality of states and non-interference in their internal affairs. A number of states deeply fear the development of a binding treaty on international information security. They advocate for the exclusively voluntary nature of rules, norms, and principles of responsible behavior of states. Against these non-binding norms, they are hoping to take on the role of arbiters. And in the finest traditions of the Orwellian ministries of truth and peace, to designate those responsible for the illegal use of ICTs based on what they claim to be highly likely. This in spite of the fact that it is these pseudo-defenders of order that are actively militarizing cyberspace and using ICTs for offensive purposes. Against this backdrop, the true intentions of the authors of the Program of Action on advancing responsible behavior in the field of ICTs are clear, namely to create under the pretext of implementing norms a tribunal to prosecute undesirable states. It is no accident that since the idea of this Program of Action emerged, no practical proposals have been made on its actual content, including for capacity building and modalities of work and procedures. It is also obvious that this initiative is being promoted to undermine the OEWG, bypassing the preferences of the majority of UN member states regarding a universal negotiation format for international information security. In conclusion, I would like to draw your attention to a flagrant violation by the United States of its obligations to host UN headquarters. The Biden administration has once again, brusquely, without any explanation, refused to issue visas to members of the Russian delegation from the competent agencies of our country. A similar situation took place as well with regard to heads of the delegations, representatives of the Russian NGOs accredited to the OEWG. We believe this policy lacks common sense and is hostile not only to Russia but also to all members of the OEWG as well as to the chair of the group. By blocking the participation of certain negotiators in the meetings in New York, the U.S. further discredits itself, showing that it is a country that abuses its status as host to the UN headquarters. Thank you for your attention. Mr. Chair, the Russian delegation fully supports, as a co-sponsor, the statement made by a group of like-minded countries, which was delivered by the distinguished delegate of Nicaragua. During discussions of the draft annual report of the OEWG, I’d like to make a general comment. We’re forced to note that the updated document as circulated by the chair on July 13th is significantly worse compared to the previous version. Our specific concerns on the text of the draft report were explained in detail by the joint statement that I just mentioned by the like-minded countries. We call on the chair to rework this draft report and to ensure a balanced reflection of the interests of all participants of the process. The current version of the document will not garner consensus. For our part, we continue to be prepared to work constructively on the text. With regard to specific comments on the introduction, section 8, we insist on the need to bring that section of the report in line with the mandate of the OEWG. Paragraph 4. It is unacceptable to reduce the group’s priority of developing rules, norms, and principles for responsible behavior of states to the mere idea of developing some kind of common understanding of security in the use of ICTs. Paragraph 5. The language of the draft should be brought in line with the UNGGE resolution 75-240. The term stakeholders, here and further in the text, should be replaced by other interested parties. Paragraph 6. We consider the implementation of the rules of responsible behavior to be the prerogative of states. Regional organizations could play a role in discussing the full range of ICT security issues. Paragraph 7. The mandate of the OEWG does not include a discussion on gender issues. In this paragraph, it is more appropriate to reflect the more pressing organizational aspects of the group’s work – that is to say, the urgent need to ensure the in-person participation of all representatives of national delegations as well as other interested parties accredited to the OEWG in its official sessions and intersessional meetings held at UN headquarters through the timely issuance of visas. Separately, I’d like to speak on paragraph 3. The statement that international law – in particular, the UN Charter – applies to the field of ICTs omits an essential element of the long-standing compromise. I’m referring to the need for progressive development of international law, including the development of new norms of a legally binding nature. Relevant wording is enshrined in the reports of the Groups of Governmental Experts and resolutions of the UN General Assembly and should be reflected in our document. We will submit detailed proposals on the draft – that is, section A – to the secretariat separately. Mr. Chair, I’d like to ask you to again give the floor to the Russian Federation to make comments on section B later. Thank you.
Ambassador Gafoor
Thank you, Russian Federation. We are looking at Section B now, so I would invite those comments at this point, and I would invite all delegations to be succinct. Russian Federation, do you want to come back now?
Russia
Thank you, Chair. In our opinion, the section of the Draft Report on Existing and Potential Threats in the use of ICTs requires significant improvement. In paragraph 10, we consider a threat to the information security of States to be the use of ICTs for purposes inconsistent with the objective of maintaining international peace and security. And this can happen both during and outside of conflicts. In addition, the meaning of the term “conflict” in this case is not clear to us. Paragraph 10bis. We must exclude any mention of certain humanitarian organizations that are not part of the critical infrastructure of States. In addition, we believe that selective references to certain types of CI, for example, marine or aviation infrastructure, are unreasonable. To avoid listing all areas that States consider critical, it’s advisable to limit ourselves to mentioning the threat of computer attacks against information resources of States, including CII. Paragraph 10ter. We propose removing references to electoral processes, which are a part of political processes, which were already mentioned in this paragraph. We ought to add to this paragraph the threat of interference in the internal affairs of States. Paragraph 10quarter. Mentioning the impact of vulnerabilities and harmful hidden functions on international peace and security is redundant because this contradicts the understanding enshrined in Norms I and J of the 2015 GGE report. In addition, it would be advisable to break this paragraph down into several semantic blocks. The first, on the issue of data security and disinformation. The second, on harmful hidden functions and threats to supply chains. And the third would be on the threat of the use of ICTs for criminal purposes, including specific instruments. Paragraphs 14 and 21. The issues of artificial intelligence and quantum computing do not fall under the mandate of the OEWG. They are discussed at other specialized platforms, under the aegis of the UN and beyond. Paragraph 15. As we mentioned before, gender issues also are not within the scope of the OEWG’s mandate and do not have a significant impact on international information security. As a compromise, a single mention of the participation of women delegates in the sessions of the OEWG in the preamble could be retained. Paragraph 17. This needs significant revision. The obligations of States can be based solely on the norms of international law. They cannot be based on voluntary rules of behavior and even less so on confidence-building measures. Therefore, this paragraph should be supplemented with a reference to possible future legally binding norms. In addition, given the high degree of politicization of information security issues by certain States and their inclination to subjectively interpret the rules of responsible behavior to impose sanctions for alleged noncompliance, we suggest emphasizing in this paragraph that the application of the rules of behavior should not lead to any escalation of tensions in cyberspace. From the very beginning of the work of the OEWG, Russia has repeatedly proposed reflecting an updated list of threats in the documents of the group. Unfortunately, in practice, many of our proposals are still not reflected. These include the use of information resources under the jurisdiction of another State without the consent of the competent authorities of that State, unsubstantiated accusations by some States against other States of organizing and committing wrongful acts using ICTs, including computer attacks, unreasonable and deliberate inclusion of undeclared capabilities by ICT developers, as well as concealment by manufacturers of information about vulnerabilities in their products, which are used by certain States, as we know quite well, to conduct covert intelligence and total surveillance of users around the world. Monopolization by individual States and/or with their assistance by private companies of the ICT market by limiting the access of other States to advanced ICTs and by increasing the technological dependence on the States that dominate the field of information technology, thus increasing the digital divide. The use of ICTs as a coercive measure, including by limiting the access of developing States to technology. Moreover, the current version of this report does not include any measures, almost any measures, to respond to existing and potential threats. We consider it necessary to supplement this section with proposals made by States on preventing the manipulation of information flows and the spread of hate speech, countering the deployment of tools for conducting computer attacks that are freely accessible, and preventing unlawful restrictive measures against certain States, including against the freedom of information and the media, as well as discriminatory policies against private companies. We could also include other measures as contained in the Chair’s summary of the first OEWG of March 12, 2021. Thank you for your attention.
Ambassador Gafoor
Thank you very much once again, Russian Federation, I was looking at the time, I think we can take one more intervention from Malaysia. You have the floor please.
Malaysia
Thank you, Mr. Chair. Malaysia associates ourselves with the ASEAN statement delivered by Brunei Darussalam. At the outset, my delegation would like to express its appreciation to you, Mr. Chair, and your dedicated team for your steadfast commitment and tireless effort in advancing the work of this OEWG. We commend the further improved versions of the 2nd Annual Progress Report, Ref 1, particularly as we gather for the 5th substantive OEWG session with the important objective of adopting the 2nd Annual Progress Report by consensus. We welcome the approach taken by you, Mr. Chair, in seeking to build on the existing acquis of responsible state behaviour in cyberspace. The inclusions of agreed language indeed reflect the incremental and cumulative nature of the OEWG process. We are pleased that the overall structure and preambular paragraphs, along with the chapeau paragraphs for each section, have been incorporated from the agreed language found in the 1st Annual Progress Report and the activities that have been carried out prior to this substantive session. Recognising these points, we agree with the proposed text in Section A of the Ref 1 of 2nd APR. Moving to Section B on existing and potential threats, Malaysia is pleased with the substantive enhancement of this section as compared to the 1st APR. With the aim of strengthening this report, Malaysia would like to present our suggestions as follows. First, Malaysia proposes to reword the last sentence in paragraph 10B to: The vulnerabilities in multiple sectors, including the healthcare, maritime, and aviation sectors, were particularly noted. The revised sentence is proposed to provide a more holistic reflection of critical infrastructure (CI) and critical information infrastructure (CII) sectors. It will also encompass the ICT sector, which may be categorised as CII in certain states, although this may not have been explicitly mentioned directly in our discussions and is fundamental to core discussions in the OEWG. The proposed text also, in our view, will address the proposal from the Republic of Korea to add energy as one of the sectors, as well as the comment from the Russian Federation on not limiting the language to CI or CII sectors. In addition to that, Malaysia supports the proposed addition of spillover effect to this paragraph as proposed by Germany. Second, Malaysia proposes to reword paragraph 10.4 to: States also express concern regarding the exploitations of ICT product vulnerabilities and the use of harmful hidden functions, in particular where these issues impact international peace and security. In this regard, states also noted the significant threat posed by malicious ICT activities targeting supply chains. States also highlighted the risk posed by malicious software (malware), ranging from ransomware, wiper malware, and trojans. Social engineering techniques, such as phishing, are being used by malicious actors as a point of entry to ICT applications, systems, and infrastructure. A separate paragraph is suggested for threats of misinformation and disinformation as follows: States also expressed concern regarding misinformation and disinformation, including where propagated through the use of deepfake technology. Third, Malaysia suggests that data security be placed in paragraph 14 as follows: States noted that development in technology, such as quantum computing and artificial intelligence, and the increasing reliance on cloud technology, while neutral in and of themselves, could potentially have impacts for data security and the use of ICT in the context of international security, including by increasing vulnerabilities and expanding ICT attack vectors if security hardening is not properly implemented. Fourthly, Malaysia proposes the deletion of the phrase “and open sources” in paragraph 11, as well as the replacement of the phrase “hacker for hire services” with “crime as a service (CaaS).” And finally, Malaysia would like to propose the addition of the sentence: Recognizing the requirements for security protection, detection, and response are pivotal to the safety and resiliency of new and emerging technology as an extension to paragraph 21. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Malaysia, for your contribution. It’s almost time for us to adjourn for lunch, and I want to first of all thank the interpreters for their indulgence. But before you break for lunch, I want to share two quick comments. First, there are about 30 speakers who have inscribed to speak on Section A and B. And if you might have noticed, you will note that I did not cut off anyone, and I did not impose a time limit either. Now, if we continue in this trajectory, we may have to go into the weekend. I have no plans for the weekend. I live in New York, but some of you will have to travel. So I’d like to really urge you, over lunchtime, to come back with more succinct comments as you prepare to make them. Second, I draw your attention to my letter of 12 July, the second last paragraph. I had mentioned that it is not about stating the preference of your delegation in terms of the amendments you would like to see, but also do keep in mind what might command consensus. Another point, many of you have said what you like about the draft. I’ll take it that you love the draft, and you might even like me as the chair. But all expressions of love and liking can be assumed. What I’d like to hear from you is what specific comments or amendments you wish to propose to improve the draft. Again, it’s not an expression of preference, but an expression that you think is a flaw that needs to be addressed from your delegation’s point of view, but also suggestions that could command a consensus. So I’m trying to narrow the range of your comments such that this afternoon, the remaining speakers will come prepared to address not only the comments from a very focused perspective, but also to prioritize your additions or suggestions so that we can go through the speakers’ list in a much faster way. Otherwise, I’m concerned that we may not be able to give everyone a chance to comment on the REV1, and that’s really important that we hear everyone to express their views. So I may also have to start imposing some kind of time limit, but I hope I don’t have to get there. But I do urge you to come prepared this afternoon to be able to make more focused and very succinct comments in terms of what you really need in order for the draft to be acceptable, not just to you but for everyone. On that note, the meeting is adjourned. Enjoy your free lunch with Germany, and I’ll see you at 3 p.m. Thank you.
Leave a Reply