Session 5-2 Transcript
(OEWG 2021-25)

Home » Resources » UN Open-ended Working Group (OEWG) transcripts » Session 5-2 Transcript(OEWG 2021-25)
Ambassador Gafoor

The second meeting of the fifth substantive session of the Open-Ended Working Group on security of and in the use of ICT is now called to order. Distinguished delegates, we’ll now continue our discussion under agenda item five on sections A and B of the draft Second Annual Progress Report, namely the sections on overview as well as existing and potential threats. I have about 30 speakers who have inscribed to speak, and I’d like very much to complete this list of speakers on section A and section B, and I’d like to get to the subsequent sections in the draft Annual Progress Report, section C as well as section D, relating to rules, norms, and principles as well as international law today. Now, if we are to get to section C and section D today, I’d like very much that the speakers who are speaking on section A and section B to be as succinct as possible, and therefore I’ve asked the Secretariat to put a little clock on the screen, and I’m recommending that each of you try your best to keep within a three-minute timeline. Now, I’m not going to cut off microphones after the three minutes, but it’s a way of encouraging you to be succinct because it’s important that we continue our work in a way that will allow us to finish the first reading by the end of tomorrow. It is my intention also to produce a REV2 in the middle of the week, and it is therefore important that I at least have an initial reaction from all of you on the entirety of the document. That is the reason why I welcome very much your very succinct interventions. I’ll assume that you love the draft and you like it very much, so if you like something, there’s no reason to specifically outline the elements you like very much. What I will be looking for are areas for improvement that are important for your delegation, not areas for improvement that are your preference or that reflect your wish, but areas for improvement that you think are important from the point of view of your delegation. In putting forward those suggestions, please also keep in mind that what you are asking for has to also be something that persuades other delegations because ultimately we are not compiling your different preferences, but we are trying to build a common document that will command a consensus. So friends, that’s where we are, and this afternoon we will continue with the speakers list starting with Argentina, to be followed by Uruguay. I’ve used the speakers list as I have received the indications of interest to speak earlier in the morning, so we’ve kept a list. We’ll follow that list, we’ll go through the list, and once again, I urge all of you to be as succinct as possible. Thank you very much. The floor is now to Argentina.

Argentina

Thank you very much, Mr. Chairman. Since this is the first time that the Argentinian delegation is taking the floor during this debate, we’d like to thank you for the dedication to our work that we’ve been doing since 2021, when the current mandate of the OEWG began. The Argentinian delegation supports your commitment to achieving consensus on a progress report for this year, which sets out tangible results that could be achieved, even in this very complicated time that we live in. Argentina welcomes Draft No. 1, a document that has reflected the ideas that have been discussed over the past sessions and has come up with very concrete ideas oriented towards action, taking a step further compared to last year’s report. Argentina would like to share its ideas with regard to Sections A and B of the draft. With regard to Section A, overview, we consider it timely, just as in the annual report of 2022, to provide the text with a general framework to indicate from where we started, so that we understand where we are for each pillar of work. Argentina supports the inclusion of language that reflects previous resolutions and reports on which we’ve built our work. Also, the mention of multiple stakeholders interested in the work of regional and sub-regional bodies, and an inclusion of a paragraph on the gender perspective. All these elements contribute to the ultimate goal, which is agreed on concrete actions to promote an open, safe, and stable cyberspace that is accessible and peaceful. This is where we support the language contained in paragraph 8. Furthermore, my delegation believes that the overview lacks mention of an important element to achieve this goal, and that is the central importance that capacity building has. Mr. Chairman, the working draft has recognized the value of capacity building. It doesn’t only indicate it as a confidence-building measure, but looks at it in a holistic and cross-cutting way. This is why we believe that this principle deserves a separate mention in the overview. Also, in paragraph 8, in relating this concept to the goal of the report and the mandate of the group in general, because we think that a safe and interoperable cyberspace is possible to the extent that all states are ensured participation in it. With regard to Section B, threats, in the annual report – progress report of last year, the states reiterated that threats in the context of international security have become more intense. The number of incidents that involve the malicious use of information is growing, and this is concerning. Argentina stresses that global challenges should be based on collective solutions and should involve not only member states but other actors that could contribute with their experience on the impact that information technologies could have on cyberspace. Argentina is convinced that the main threats that we are confronting are connected to what is going on around the world, given the transnational and interconnected aspect of cyberspace. This is why we believe it’s important to have a report that goes further than last year and explicitly mentions threats on which we have been working over the past few sessions, such as ransomware and phishing, and which were mentioned by the United States, Colombia, Korea, and other delegations. We’re also grateful for the inclusion of this language in Section B. For Argentina, threats to cybersecurity are those that could threaten international peace and security through attacks against critical infrastructures and other essential services for the functioning of a country. We support paragraph 10bis. However, on paragraph 10quater, as we indicated earlier, while we support the general idea, we consider together with the United States that disinformation is more in the area of cybercrime rather than here. Furthermore, Argentina, as has already been stated in the informal session in May, supports inclusion in the – quantum computing and other aspects. We also support the comments made by Colombia and Malaysia and others. We believe it’s important that we begin discussing these topics in order to generate consensus on public policies and norms to protect the interests of our societies and allow our countries to continue moving forward in the military sphere. Artificial intelligence should meet the guiding principles of human rights as the main normative framework. And bearing this in mind, AI systems should be put at the service of people and not vice versa. Lastly, taking into account the existing digital divide between countries and with the goal of building a resilient digital architecture, we’d like to highlight the importance of capacity building in the area of threats. This is why we believe we should strengthen initiatives such as dialogue with interested parties, with experts, and regional organizations that could contribute to better cooperation. We support the language proposed for paragraph 21. And this takes into account equitable geographical representation, which I think sets out the various challenges represented around the world. Unfortunately, the speaker did not provide this text to the interpreters.

Ambassador Gafoor

Thank you, Argentina. Uruguay, to be followed by the Philippines. Uruguay, please.

Uruguay

Thank you very much, Mr. Chairman. For me, it’s a pleasure to see you chairing our session once again. I would like to thank the Secretary for his participation in this morning’s meeting and for the information we exchanged in line with what has been our national position. Since this item, ICT security, is part of the agenda of the UN as well as the processes of Open-Ended Working Groups and GGE, your way reaffirms the importance of the document, that is the outcome of this document, and that it is based on consensus, and this has been reflected in the negotiation process. So we would also be grateful to delegations, well, to show flexibility to continue moving forward and thus facilitate your difficult task. Now, generally speaking, we agree with this document. This is an ambitious outcome following various debates and exchanges of views during informal meetings. We’re also grateful for your transparency in this process and your concern about conducting inter-sessional meetings. We know that fine-tuning the work of delegates for the formal sessions seeks to facilitate that work. Now, regarding the paragraphs proposed that set out the resolutions and decisions of the General Assembly on the topic, as well as the final reports adopted previously by OEWG, these are very important, as well as the cross-cutting topics that my country supports, such as the gender perspective, human rights, etc. Now, we must continue seeking common understandings on the conduct of states with regard to ICTs in the context of international security. I will now make a few general comments. Regarding the existing threats and potential threats in the area of cybersecurity, Uruguay sees with concern, as other countries have mentioned, the fact that malicious activities have an impact on the infrastructure of states with great destabilizing potential and could trigger conflicts. Bearing that in mind, the priority is to find responses and solutions to these types of malicious activities, especially through cooperation, transfer of technologies, and promotion of confidence-building measures. And while we all have different national realities, we have to take into account that we’re all targets of these kinds of attacks and we need to work together, even though we’re at different levels of development. We’ve been measuring national tactics in dealing with this. The document includes references to recent developments such as artificial intelligence and quantum computing, and we value the inclusion of these, given, as has been mentioned in other fora and has also been part of the UN agenda regarding digital aspects, that we are probably a step behind. And so we need to move forward in line with the development of technology. And so we need international regulation on these very important topics. We’d like to take this opportunity to reiterate the importance of promoting cooperation for developing countries. Not all countries and regions are at the same level. And here we agree with paragraph 40C, which seeks to improve coordination of efforts in the area of capacity building, and in particular, the particular role of the UN that could play in this area, for example, by mapping the needs of states and unifying different proposals and opportunities for cooperation offered by various entities of this organization, but also by other relevant actors that are participating and following these processes. And I think that’s very important. In line with this position, we strongly support the proposal of the Program of Action contained in paragraph 43. In particular, I’d like to thank the various institutes and organizations that cooperate with delegations such as mine in building capacities and strengthening national frameworks, which make it possible to move forward. Also, regional organizations such as the Organization of American States, which is working closely with our country and our region. We also support the language proposed by the chair to promote exchanges between states. International law should also apply to the use of ICTs. We’d also like to take this opportunity to mention that we intend to hold a side event on this topic this week. And I would just like to make a request, Mr. Chairman, which I already made in the past, and that is to ensure better coordination as far as the agenda, because these topics are of great use in all missions, especially for smaller missions, making it very difficult to be in different events at the same time. As far as organizing the thematic roundtables, these are important on how to apply international law to cyberspace. It’s very important to reach agreement on this point, given different interpretations and different positions, which will be on the work of OEWG. And Uruguay has always defended the maintenance of international peace and security. We believe that cybersecurity is an essential element in preventing conflicts. I’d like to stress the word prevention because we need to focus on this, bearing in mind the guiding principles of our foreign policy. We believe it’s important to apply international law and international human rights law. The sovereignty of every state and the decisions that will be taken and implemented in the future will be very important. Also, discussions in the area of security must include a human rights perspective and a gender perspective, as others have said. We believe that the forums for discussion on cyberspace and cybercrime should be in constant dialogue. It’s important to reach consensus that makes it possible to guide the action of states in accordance with international public law. This is why Uruguay supports transparency in discussions and the involvement of various relevant actors in addition to member states to cover this topic in a holistic way. We also need to promote at the level of the region the participation of civil society stakeholders, which up to now has been less than we’d like to see, and we hope for greater participation of civil society in the future. As far as the work that remains ahead of us this week, we have hard work ahead of us, and I simply would like to reiterate once again that my delegation is ready to work with you and support you to make progress in these discussions and to find common ground with different delegations, which, based on what we heard today, is not going to be an easy task for you. I’d also like to refer to the capacities and threats, especially capacity building that Argentina mentioned earlier. My delegation also would like to see it incorporated in paragraph 8, with a separate mention of this. Thank you very much, Mr. Chairman, and I’m sorry that I spoke for so long. Thank you.

Ambassador Gafoor

Thank you, Uruguay, for your statement. Philippines to be followed by Austria. Philippines, please.

Philippines

Thank you, Mr. Chair, and distinguished colleagues and delegates. Good afternoon. The Philippines aligns itself with the statement delivered by Brunei Darussalam on behalf of ASEAN. Since this is the first time that the Philippines is taking the floor, we would like to recognize and appreciate the Chair’s effort and his team on the revised draft of the 2nd Annual Progress Report. We commend you for your transparent and very balanced approach in producing your 2nd APR, taking into consideration all comments and inputs of Member States, including their various proposals. The draft that we have today is a solid basis for a consensus outcome document and a pragmatic roadmap of our future work. On our part, the Philippines is currently reviewing its National Cyber Security Plan 2023-2028 to provide a safe and reliable cyberspace for all Filipinos. We therefore look forward to the adoption of the 2nd APR, which could feed into the drafting of our National Cyber Security Plan, which is scheduled to be released before the end of the year. Taking into consideration the Chair’s request for a succinct intervention, I go straight to the point. On the matter of existing and potential threats, we observe that the proposal to develop a repository of threats to ICT security in paragraph 20 has been watered down. It may be recalled that the Philippines also recommended having a cybersecurity repository under the auspices of the UN, which could include cybersecurity incident reports from Member States that may have an impact on international peace and security. We believe that these reports could capture existing and potential security threats and could serve as a primary basis for creating capacity-building programs to be facilitated later on by the UN. While we would have preferred to retain the previous language, we understand that some Member States would like to take an incremental approach in this matter, and we can therefore support this proposal as long as Member States can further explore this proposal in the near future. Thank you very much.

Ambassador Gafoor

Thank you very much, Philippines, for keeping within the time limit. It’s very much appreciated. Austria, to be followed by Australia. Austria, please.

Austria

Thank you very much, Mr. Chair, and good afternoon. At the outset, please accept my thanks for the hard work you and your team have put into the REF1, which we see as a step forward compared to the zero draft, albeit with one where there’s still some room for improvement. We fully align with the statement delivered this morning by the European Union and the proposals contained therein. I’ll just add some brief points in my national capacity. On the introduction in paragraph three, we would have the suggestion to rephrase the second sentence because the way it reads currently, I think it skews the balance between the existing 11 voluntary non-binding norms and additional norms. So we suggest separating those existing norms and additional norms in the following way, so that the second sentence in paragraph three would read: “States recalled and reaffirmed the 11 voluntary non-binding norms of responsible state behavior recommended in the report of these groups.” Furthermore, states recognized, and then it continues. I think this gives a little bit more logic and chronology to the text and makes it clearer as to what has been agreed and endorsed by states on several occasions and what are potential new developments. In that regard, we also heard the proposal by the delegation of Pakistan on paragraph three. With the addition at the end, we don’t think it’s quite suitable here. On paragraphs seven and 16, I would just react to what we’ve heard. Other proposals for us, the reflection of gender perspective and the participation of women in our process is essential. So the paragraph as it is here is a starting point. It should be much stronger, and we would not be in a position to accept any reframing of this paragraph towards issues that do not belong in the purview of the discussions we’re having here. On the threat section overall, we think it’s quite good. We would like to support the proposals made by Germany and the Republic of Korea, among others, to insert language regarding ransomware. The language of Germany was, I think, very suitable in that regard. As a final point I wanted to make on paragraph 21 regarding quantum and AI, we took note of the concerns with several delegations. We also would be of the view that maybe a dedicated intersessional meeting would be a little bit much and that focused discussions on how quantum and AI affect cyber specifically would be more suitable than a dedicated intersessional meeting. I thank you.

Ambassador Gafoor

Thank you, Austria, for your contribution and for keeping within the time limit. Australia to be followed by New Zealand. Australia, please.

Australia

Thank you very much, Chair, and please take my thanks and my delight as read. We are very pleased that this draft report intends to reflect the group’s discussions and our progress over the last year, and we hope that we can focus in this report on our progress rather than falling back on our positions, because important work has been done over the past year and there have been many ideas put forward. Some of these have been discussed with very significant interest, and this should be reflected in our progress report, and it should be reflected appropriately, realistically, and concretely. I suggest that we pay close attention and are very careful about how we reflect the ideas and the proposals that we’ve put forward over the past year, and suggest that perhaps we could better delineate through the structure of this report, between first reflecting what has already been agreed and our key, and then talking about what has been discussed in the past year and some of the proposals that have been put forward, and finally reflecting on what this group decides we want to focus our limited time on in our future discussions. This is our progress and our roadmap, including what is required and what requires a formal recommendation from this group at this stage of the process. In particular, I think this year we need to look at the point of contacts directory because the work of getting from an idea on a page or a suggestion from a group to an up-and-running operational resource initiative cannot be underestimated. The point of contact directory is a great example here. It seemed very simple when a year ago a cross-regional group of confidence builders proposed taking this idea forward, but in reality, it has taken eight years since a global point of contact directory was first proposed in the 2015 GGE report, and it has taken a lot of time and learning from long-standing and functioning versions of this directory at a regional level to turn that one sentence of a proposal into something real. In particular, it has required significant work and effort, which we can only thank you for, Chair, by the Chair and your team and the Secretariat to realize the ambition of this proposal over the past year. So I suggest we use this as a template, and with everything going to plan this week, successfully operationalizing the first global UN cyber point of contact directory, this can be a way that we can operationalize some of the proposals that we have put forward in the past year in this open-ended working group, and really focus on making sure that our time, efforts, and resources are put towards those proposals that have piqued our interest, garnered our support, and most importantly, have a realistic chance of consensus adoption. This is the framing over which I will be talking about the proposals and the chapters over the next few days. Very briefly on the overview chapter, I want to join Australia’s voice with Colombia’s support for paragraphs five on stakeholder participation, six on the role of regional organizations, and seven on the importance of reflecting a gender dimension. I also add Australia’s voice to the proposal by the Republic of Korea to reflect our full acquis in paragraph three, by referring to the application of the UN Charter in its entirety to state behavior in cyberspace, and also the proposal by my esteemed neighbor to split the references to our agreed norms and references to possible future work. Turning to the threats chapter, I’m very encouraged to see a really rich reflection of our discussions since our first progress report last year, and very much welcome the references to many issues we have discussed and threats identified, including, as mentioned by Deputy to the High Representative for Disarmament Affairs Adedeji Ebo this morning, the gender dimensions. We have a couple of proposals very specifically for this chapter. First, we have a proposal on how the chapter is structured, and the aim of these suggestions is to bring consistency to the way that all threats are identified, because as currently drafted, some of the threats here are linked to a threshold, which overtly brings them into this group’s mandate, and that is when the threat rises to a level that has the potential to impact international peace and security, while others do not have that core link set out in the text. Similarly, some parts of the chapter identify specific technology as concerning, while other parts of the chapter provide the additional nuance that it is the use of technology irresponsibly which is a concern, and not the technology itself, because the work of this group is focused on delineating responsible behavior and use of cyberspace by states. We’re not here to pass judgment on technologies, nor are we here to duplicate the work of technical standard-setting bodies. We therefore propose that all of these qualifications that currently frame some of the threats discussed in the chapter are applied to and equally frame all of the threats in the chapter. In addition to this structural shift, we propose a few specific textual amendments. First, in paragraph 10, we would replace the reference in line 3 to expressing concern, and we will replace this with noted. Secondly, in paragraph 10bis, we support Malaysia’s proposed amendment to the last sentence to be more inclusive of the reference to critical sectors, and we can support the proposal from the Republic of Korea to include a reference to the energy sector here. On paragraph 10 quarter, there’s a reference here to misinformation and disinformation, and while colloquially we do use these terms, we think that there is a risk that they might be misunderstood and misinterpreted in this report, and suggest that we use a descriptor that we have used already via consensus for this type of conduct. I’m referring here, and I quote from paragraph 9 of the 2021 GGE report, which quotes, “the worrying increase in states’ malicious use of ICT-enabled covert information campaigns to influence the processes, systems, and overall stability of another state.” I also note the proposal from Malaysia on paragraph 10 quarter around making a distinction between the tools that can be used for malicious cyber activity, like malware and ransomware, and the techniques employed by malicious actors when they put these tools into effect, such as phishing. I think this approach is quite logical in setting out the threats based on whether they’re a vector, or a tool, or a technique, or an effect, and somehow grouping it that way, and I look forward to looking at that proposal a little bit more. Malaysia also proposed to move the reference to data from paragraph 10 to paragraph 14, and we think that this could be quite logical, and we’ll look closely at this proposal and the text there, but I think we would prefer to see the reference to data to be included in the first half of the sentence in paragraph 14, rather than in the second half. Also, in paragraph 14, we would like to replace at the end of the sentence, it currently reads, expanding ICT attack vectors, and we would replace this with expanding malicious threat vectors. On paragraph 15, we’re supportive of the way that this provides a way forward to explore proposals, but we also agree with some others that this may be more appropriately considered as a transparency measure, or a way to address threats identified in this chapter, given that it is very similar to and builds upon some of the recommendations to share information, as a way to build trust and confidence, which were adopted in the 2015 and 2021 GGE reports. We would also, in paragraph 16, replace vulnerable groups with a reference to groups in vulnerable situations, and prefer to revert to gender dimensions in this paragraph. One final point on paragraph 21, we would like to call for consistency across the way this recommendation has been set out in all of the chapters. So we have, in paragraph 21, threats in 27 norms, in 33 law, 39 CBMs, 45 capacity building, and 52 regular institutional dialogue. All of these are calling for more discussions and an informal process, but we think that we need to be treating these equally. Some of the inconsistencies we’ve identified across these recommendations, the way these intersessional meetings are described or titled, some are called roundtables, some are called intersessionals, some are called informals. There’s also some inconsistency in the choice of the specific topics under discussion, and in the proposed participants. So we would call for consistency across these recommendations. We will be sharing all of these changes with the Secretariat and the Chair. Finally, Germany is not the only country that has cornered the market on a free lunch. Tomorrow, Australia, Bulgaria, and the Internet Corporation for Assigned Names and Numbers, ICANN, will be hosting a side event to discuss internet governance issues in conference room 11. Lunch will be provided, so I hope to see some of you there. Thank you.

Ambassador Gafoor

Thank you, Australia. New Zealand to be followed by Bangladesh. New Zealand, please.

New Zealand

Kia ora koutou. Chair, we thank you and your team for your hard work bringing us the REV1 text. Despite divergent views in some areas, we believe it is within reach to achieve a consensus report that reflects the weight of discussions held over the past year and captures progress made. As paragraph 3 in the overview section notes, states have reaffirmed that international law, in particular the Charter of the United Nations, is applicable and essential to maintaining peace, security, and stability in cyberspace, as well as the 11 norms of responsible state behaviour. This is the cornerstone of the work of the OEWG, and we strongly support these elements as the basis for further discussions. We appreciate the efforts of Australia, Colombia, El Salvador, Estonia, and Uruguay to elaborate areas of convergence in this area. We recall and endorse the mandate of the OEWG to focus on ways for implementing the rules, norms, and principles of responsible state behaviour. We welcome the report emphasizing the high-level participation of women delegates and the prominence of gender perspectives in discussions and agree that this accurately reflects discussions held over the past year. We reiterate the importance of multistakeholderism and the vital perspective and expertise that non-government stakeholders bring to these discussions. Chair, turning to section B, existing and potential threats. In discussions of current and emerging threats over the past year, states including Aotearoa New Zealand expressed ongoing concern about the current threat landscape, including deployment of ransomware, targeting of critical infrastructure, and that the malicious use of cyber activity is now occurring in the context of an international armed conflict. In our view, these discussion points are important developments to capture in the APR. We join others who have called for giving more prominence to ransomware and malicious ICT activities against critical infrastructure in paragraph 10b. With respect to paragraph 10 quarter, in our view, proposed text regarding misinformation and disinformation and data security remain outside the mandate of the OEWG and the scope of cyber security threats and should be removed or, as Australia has suggested, revert to language in the 2021 report. We support language in paragraph 16 and the importance of taking a gender perspective and addressing ICT threats and the specific risks faced by persons in vulnerable situations. We take note of the proposal for a voluntary repository of threats raised in the fourth substantive session of the OEWG and would welcome a recommendation that states engage in further exchanges to better understand this proposal. As others have said, this recommendation could be shifted to the section on confidence-building measures. Finally, noting that neutrality is not a principle under the UN Charter, we do not believe it is relevant in the context of discussion of state or state-linked threats and recommend deleting reference to it in paragraph 20. Thank you.

Ambassador Gafoor

Thank you very much. New Zealand. Bangladesh to be followed by Indonesia. Bangladesh, please.

Bangladesh

Mr. Chair, please allow me to begin by expressing my delegation’s sincere thanks to you and your team for the immense dedication and hard work in presenting the zero draft of the second APR and subsequent REV1 version, engaging states and stakeholders through town hall meetings and informal engagement with delegations. In our view, the REV1 is a very balanced draft and an excellent basis for discussions. My delegation supports the overview section, which gives a certain level of confidence and comfort to the delegations and your approach that this APR intends to capture concrete progress made at the OEWG to date as outlined in paragraph 8. Under section B1, Existing and Potential Threats, we are happy to see the reference to the use of ICTs in conflicts in different regions in paragraph 10. In paragraph 10b, in the fourth line, we would propose to replace the word “domestic” with “national.” While we appreciate the inclusion of the vulnerability of critical infrastructure and critical information infrastructure (CII), we, however, highlight the critical importance of protecting financial institutions and systems from malicious ICT activities that aim to disrupt financial services or undermine the stability of financial markets. Therefore, in addition to the vulnerability of healthcare, maritime, and aviation, my delegation proposes the inclusion of the financial sector as a critical sector. In paragraph 10 quarter, we are happy to see the inclusion of misinformation and disinformation, including through the use of defects, as a threat to international peace and security. My delegation proposed the same during the last substantive sessions and town hall meetings. In paragraph 14, we support the inclusion of quantum computing and artificial intelligence and the increasing reliance on cloud technology as new vectors for the malicious use of ICT. In paragraph 15, we support the idea of having a voluntary repository of threats. In paragraph 16, we appreciate the inclusion of a gender perspective in addressing ICT threats to the specific risks faced by vulnerable groups. We, however, propose an edit at the beginning of the sentence, which would read “States also stress the need for” then the continuation of the sentence instead of “drew attention.” In paragraph 17, my delegation proposes to add “act” in the last line after the word “between,” resulting in the wording “between and among the states.” Mr. Chair, we support the proposed recommended steps, including having a dedicated intersessional meeting on developments in new technologies such as quantum computing and artificial intelligence to develop and deepen our common understanding of the potential risks and challenges these technologies may pose to the use of ICT in international security. In paragraph 20, in the second line, we propose to add “transparent” after the word “accessible.” As you mentioned, the above is not our preference, but rather our effort to improve the draft. Finally, Mr. Chair, we firmly believe that under your able and skillful leadership, we can reach a consensus and successfully adopt the second APR. You can rest assured of my delegation’s unwavering support throughout this endeavor. Thank you.

Ambassador Gafoor

Thank you, Bangladesh. Indonesia, to be followed by South Africa. Indonesia, please.

Indonesia

Thank you, Mr. Chair. Allow me to first express our appreciation to you, Mr. Chair, for your leadership in steering the OEWG into its fifth substantive session. We thank the Chair, his team, and the Secretary for preparing the draft of the Second Annual Progress Report. We welcome the draft as a solid foundation for our deliberation this week. My delegation aligns itself with the statement made by Brunei on behalf of ASEAN, and in this regard, we have a few additional points to make. On the draft of the second APR, we are of the view that the draft report has included concrete elements that reflect the progress of our deliberation within the OEWG over the past year, including reflecting our consultations to establish the Global Points of Contact Directory, as well as the possibility to further explore other proposals. This will be another important step forward for us to achieve concrete outcomes of this OEWG, which will hopefully lead to reducing the security risk of the use of ICT and, at the same time, increasing the capacity of developing countries in addressing ICT security issues. Mr. Chair, specifically on Section B, we are pleased to see that the APR has recognized the growing threats in cyberspace. No countries are indeed immune from such threats. It is important for us to keep abreast of these threats and increase our capability to respond to them. We recognize that the current threat landscape continues to undermine the security of our cyberspace. Such malicious cyber activities also attack sectors that are vital to our nation. In the first semester of this year alone, Indonesia has experienced ransomware attacks surpassing the total number of incidents throughout last year. Therefore, we welcome the recognition of these threats in Paragraph 10 Quarter. In this regard, we also believe that strengthening comprehensive regulatory and policy responses will be crucial to increase our capability to detect and respond to these growing threats. Thus, we welcome the proposal in Paragraphs 15 and 20 on the development of the Voluntary Repository of Threats, as this is an important first step to acknowledge the emerging threat landscape. My delegation remains open to discuss how Paragraphs 15 and 20 should be worded. In addition, in these paragraphs, they must also be followed with guidance as to the best practices in addressing them. We believe that such a repository would serve as a good addition to our step forward. Finally, Mr. Chair, let me reiterate Indonesia’s readiness to support you throughout the OEWG process and will work constructively towards the consensual adoption of the Draft Second Annual Progress Report. I thank you.

Ambassador Gafoor

Thank you very much, Indonesia. South Africa, to be followed by Costa Rica. South Africa, please.

South Africa

Thank you, Chairperson. We thank you and your team for the revised draft of the Annual Progress Report. We will comment on the overview and existing and potential threat sections. The overview is a good assessment of where states are in terms of engagement at the multilateral level. We are also glad to see mention of the high level of engagement of women delegates in the Working Group. We prefer to retain the agreed language on gender perspectives and the gender-digital divide in paragraph 7. The overview draws largely from agreed language in the previous APR, which remains a strong consensual basis that we must retain. Therefore, we would prefer to retain such agreed language, having considered some proposals today to change this. We also strongly support the retention of the structure of the report, which builds on the consensual basis we have already achieved in the previous APR. South Africa believes that we must continue to be ambitious about how all delegations can benefit in a practical way throughout the five-year process of this Working Group. Chairperson, with regards to the many threats faced by states, South Africa believes that cooperative measures are needed to address the threats against ICT infrastructure. In this regard, we support the recommendation for states to continue exchanging views in the OEWG on existing and potential threats. We underline the central role of the UN as a forum for an exchange of views on existing and potential threats in cyberspace. In addition to continuing exchanging views in the OEWG, the proposal for the establishment of a voluntary repository for information on threats to ICT security is a constructive approach. Any repository should prioritize objective information in an inclusive, neutral, accessible, and universal manner. Our goal is not only to continue discussions in the OEWG, but to assist states by providing them with relevant information on emerging technologies that will come to dominate our lives and assess any possible threats to ICT security. The proposal for intersessional meetings to discuss threats related to new technologies, such as artificial intelligence and quantum computing, would be useful. As some developing countries are also in the process of trying to understand these technologies, expert briefings to the OEWG during intersessional meetings would be of assistance. Thank you.

Ambassador Gafoor

Thank you very much, South Africa. Costa Rica to be followed by the Netherlands. Costa Rica, please.

Costa Rica

Thank you, Chair. Costa Rica would like to thank you for the work carried out in preparing this second annual progress report. This is a mechanism we think that allows us to take stock of progress made as we continue to build on our work in this and future sessions. On overview, paragraph 5, we appreciate the specific emphasis on engaging stakeholders in a systemic, sustained, and substantive manner, particularly the inclusion of businesses, NGOs, and academia. This is an inclusive approach and is vital for comprehensive and effective global cooperation. On paragraph 6, we commend the importance of recognizing the crucial role of regional and sub-regional organizations in implementing the framework for responsible state behavior. These organizations contribute through their unique insights and context-specific solutions. They are valuable partners, therefore, in promoting peace and security. We also think it’s crucial in paragraph 7 to refer to the meaningful participation and leadership of women in decision-making processes in a full, equitable manner. In the use of ICTs in the context of international security, it’s crucial to close the digital and technological gaps between women and men from childhood to the elderly. This also includes gaps in access, use, and knowledge on existing and potential threats. We support the call to establish a repository of ICT threats, recognizing the role of experts, businesses, NGOs, and academia in detecting and monitoring these threats. We recommend that the report reflects the importance of the participation of non-governmental stakeholders, receiving information on states’ contributions to the repository, ensuring objectivity and evidence-based assessments. The greatest cyber threat is ransomware. This is a threat to national and economic security for all states. These ransomware attacks target critical infrastructure and essential services such as public health, schools, finance, insurance, or government functions. Therefore, we think it’s crucial to reflect this threat in the report in a sufficient manner. So, we propose, after paragraph 10, adding the following paragraph. I’ll read it in English: …concern regarding ransomware attacks with a disruptive impact on individuals, economies, and societies at large. In this regard, states noted the growing risk of the impact of such threats to rise to the level of national and international security. In this working group, we must discuss not only current threats but also potential threats. Malicious behavior in cyberspace is increasing, and it’s difficult to predict it. It has an impact on human rights, particularly on freedom of expression and privacy, in a way that disproportionately impacts vulnerable groups. The report must explicitly acknowledge the increased risk faced by vulnerable professions, such as illegal surveillance, spyware, OSINT software, malware, and attacks on critical electoral infrastructure. Thank you.

Ambassador Gafoor

Thank you, Costa Rica. Netherlands to be followed by Kyrgyzstan. Netherlands, please.

Netherlands

Thank you, Chair. Colleagues, I had prepared words of appreciation, but at your request, Chair, I move straight into the substance. Allow me to share two remarks of a more general nature. Firstly, Chair, our understanding is that this draft follows a similar structure to the previous APR. It reflects views expressed by States in the narrative of each chapter, followed by consensus recommendations. Like last year, we will continue to carefully reflect on the overall balance that the report strikes. Of particular importance to the Netherlands is to ensure, where necessary, that the findings of this report are placed in the context of previous consensus reports. Secondly, the Netherlands is supportive of the action-oriented approach of this report. In considering the different recommendations for further work, we would like to make sure the actions and taskings coming out of this document are feasible, coherent, and take into account resource and capacity constraints, both on the side of Member States as well as at the UN level. In addition, in further operationalization of the new practical ideas, we consider it of key importance to complement and build on existing efforts, both inside and outside of the UN. Then on existing and potential threats, 10bis. The Netherlands welcomes paragraph 10bis on threats to critical infrastructure, including the reference to cascading effects, electoral processes, and the general integrity or availability of the Internet. With regard to the healthcare, maritime, and aviation sectors, we would like to avoid describing them as inherently vulnerable, but rather by expressing concern regarding the potential impact caused by malicious ICT activities targeting these sectors. We agree with Malaysia that this is not an exhaustive list of critical sectors, but rather a set of sectors of particular concern. In paragraph 10bis, the concepts of misinformation and disinformation could be reflected in a more specific manner, placing it within the scope of the work of the First Committee. This could be addressed with consensus language from the 2021 GGE report on ICT-enabled covert information campaigns to influence processes, systems, and overall stability of another state. Similarly, we have concerns regarding the reference to data security. It is not clear how this impacts international security, and we consider this an issue that requires much more elaboration. We therefore propose to reflect data in paragraph 14, where we consider the potential impact of new technologies on the use of ICTs in international security. Still on paragraph 10.4, with regards to ransomware, this is an issue that has been raised by many states as a global challenge with broad impacts, posing increasing risk to national and international security. The Netherlands is of the view that this threat could be further elaborated on. We therefore support the proposal made by Costa Rica with a minor tweak, namely to refer to incidents instead of attacks, since attacks have a specific legal meaning in the context of our work. We consider other specific techniques highlighted in the report, such as wiper malware, phishing, and trojans to be of a more technical nature and prefer to leave them out. With regards to paragraph 11 on commercially available ICT capabilities, we would like to focus the text on the misuse of such capabilities by the state. The illegality of specific markets and sources is highly complex, and in many cases subject to national laws and regulations. In paragraph 14, we propose to replace attack factors with malicious threat factors, since the use of the word attack has a particular legal meaning. As mentioned before, we would find data more appropriate to move to this paragraph 14, and we also want to make sure that the positives of new technologies are also reflected here, and that we focus our attention on studying the potential implication of these new technologies for the use of ICTs in the context of international security. So the paragraph would read as follows, quote, states noted that developments in technology, such as quantum computing and artificial intelligence, and the increased reliance on data while expanding development opportunities could potentially also expand the attack surface, creating new factors and vulnerabilities that can be exploited for malicious ICT activity, unquote. In paragraph 16, the Netherlands does propose to replace the specific risks faced by vulnerable groups with the specific risks faced by persons in vulnerable situations. In paragraph 21, we would like to streamline this paragraph to focus it on studying the potential impacts or the use of ICTs in the context of international security. We therefore propose to rephrase the second part of the sentence as follows, quote, the OEWG to convene a dedicated intersessional meeting focused discussions with the participation of relevant experts invited by the OEWG chair and with due consideration given to equitable geographical representation to exchange views on the potential impact of developments in new technologies, such as quantum computing and artificial intelligence on the use of ICTs in the context of international security, unquote. Thank you, Chair.

Ambassador Gafoor

Thank you. Netherlands. Kyrgyzstan, followed by the Islamic Republic of Iran. Kyrgyzstan, you have the floor, please.

Kyrgyzstan

Thank you, Mr. Chair. Let me also join in thanking you and your team for these tireless efforts, as well as your leadership in finding solutions. Let me also thank you for the submission of the second draft of the second report of the OEWG, which we hope will be adopted at the end of this substantive session. Mr. Chair, General Assembly resolution 75/240 indicates the OEWG should submit annual progress reports to the General Assembly for adoption by consensus. In this regard, let me recall the first annual progress report of the OEWG, which was consensually adopted last year and was subsequently endorsed by the General Assembly. We hope that the zero-draft second APR of the OEWG will serve as a starting point for our discussions in the coming days, with a view to adopting it by consensus. Mr. Chair, I also echo other speakers in stating that the second APR should be balanced, based on the progress made in the first annual report, and reflect progress in discussions on the main areas of the OEWG’s mandate, as well as reflect the ideas and proposals, including the initiative on the draft concept of the UN Convention on Ensuring International Information Security, as well as establishing under the auspices of the UN a regular institutional dialogue with the participation of all UN member states on the security issues in the use of ICT. Mr. Chair, I agree that the work over the past year has been focused and productive and has provided concrete elements that we can reflect as progress in our report. In this regard, I join the other speakers and invite all the delegations to demonstrate flexibility and understanding in order to achieve the final results and adopt the report. I thank you, Mr. Chair.

Ambassador Gafoor

Thank you very much. Kyrgyzstan, Islamic Republic of Iran, to be followed by Canada. Iran, please.

Iran

Thank you. Mr. Chair, we extend our sincere appreciation to you and your team for the commendable efforts in organizing the meetings and developing the draft annual progress report. We also acknowledge your dedicated attempts to facilitate the issuance of visas for the capital delegates, despite the unfortunate situation where the host country could not fulfill its legal obligations in this regard. Furthermore, we express our gratitude for the continuous support provided by the Secretariat, which has been instrumental in facilitating the smooth functioning of the proceedings. In alignment with the statement delivered by Nicaragua on behalf of a group of like-minded countries, we recognize the progress that has been made thus far in the draft report. However, like several other delegations, we believe that there is room for further improvement in the draft to ensure its accuracy and balance. We have thoroughly explained the rationale behind our textual proposals, and we strongly emphasize the importance of incorporating the proposals into the final text of the annual progress report. Now, with your indulgence, Mr. Chair, I’m going to raise our concrete proposals, not just preferences, though, throughout the draft APR, and we will share them in writing at the end of the first reading of the draft. So, Mr. Chair, on paragraph 10-quarter, we would like to suggest the addition of “inciting violence” after the parenthesis in the second line. And we have a suggestion to add another paragraph as 10-quinquies, which will be as follows: States further express concern regarding unsubstantiated accusations and attributions, inequitable role and responsibility of states in Internet governance, and lack of responsibility of the private sector and platforms with extraterritorial impact. And at the end of paragraph 11, we would like to propose the following addition: In this regard, states underscore the need to take steps to avoid and refrain from taking any measures that impede legitimate ICT security and law enforcement activities of states and that hinder international cooperation and technology transfer in the field of ICT security, as well as digital development of states in a fair and non-discriminatory environment. And also, we have another paragraph to be added as 14-bis, which will read: States also stress the importance of ensuring states’ rights of peaceful use and development of ICTs and emerging technologies so that all states can share digital benefits. In this regard, states express concern regarding unilateral coercive measures against other states in the use of ICTs. On paragraph 15, we would like to suggest replacing the word “practical” in the middle of the paragraph and replacing it with the following phrases: “reliable, technical.” On paragraph 16, we would like to suggest the deletion of the newly added phrases in the first and second lines and also to replace the word “vulnerable groups” at the end of the first sentence and replace it with the phrase “men and women.” In the second sentence of the same paragraph, in the last line, we would like to suggest the addition of the phrase “international and national” after the word “implementation of the,” so it will read “implementation of the international and national sustainable development goals.” And also, another addition at the end of the paragraph, which reads: “while respecting cultural diversity and national needs and priorities of states.” On paragraph 18, we would like to suggest in the second line from the bottom to add the phrase “and capacity building activities” before the word “under the cumulative and evolving framework.” And for paragraph 19 also, we’d like to propose the addition of “any capacity building” in the third line after the phrase “possible cooperative.” And finally, Mr. Chair, for paragraph 20, again, we’d like to suggest replacing the word “practical” with “reliable and technical.” In conclusion, Mr. Chair, together, let us work collaboratively and enhance the needed quality of the report and contribute to the success of our collective efforts. I thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Iran, for your statement. Canada, to be followed by Mexico.

Canada

Thank you, Mr. Chair. Please take our thanks as given. As you noted, it will be very important to capture the spirit and substance of our discussions in the APR. In this regard, the revised draft is a solid step in the direction of accurately reflecting the nature and weight of our discussions. There is, of course, always room for improvement, and I will outline a number of areas where Canada believes further adjustments could be made as we address each chapter of the text. In terms of general comments, Canada supports Australia’s proposed way forward in terms of shaping the document clearly between what has been agreed, what has been discussed, and where recommendations are needed, as a solid option for the structure of the document going forward. Canada also has questions as to the roadmap and budgetary implications of the proposals in the text, and we look forward to the additional details you have promised in this regard. The ongoing deepening of our work is, of course, welcome. However, we must also be realistic in terms of the capacity of the Secretariat and, indeed, of the budget allocated to this group. We also note there appears to be a lack of consistency in the nature of the description of the participants in some of these meetings, with references in the threat section to relevant experts, whereas in the norms section, the nature of these experts is laid out in greater detail. We would recommend consideration of greater consistency in this regard, while stressing the importance that Canada places on including all relevant stakeholders in these discussions. Within the overview overall, I would like to reinforce Canada’s strong support for language highlighting the importance of the role of stakeholders in our work, and also the value of taking a gendered and informed approach to our work. Weakening this language would be very problematic for us. Mr. Chair, with respect to the text on threats, this section is very important. It lays foundations for the rest of the report. Therefore, we’re pleased to note that the annual report for this year contains a section on threats, and that’s a substantial section. We’re also very satisfied that issues that Canada and other states mentioned last year are in the text, namely ransomware, emerging technologies, and cyber threats. These are essential, and we also include critical infrastructure and CII. On emerging technology, we note, however, that the use of certain expressions loses an important element of the discussion, namely that technologies provide us with both advantages and risks. Therefore, we’d like to revert to wording similar to that used in last year’s annual report, which underscored both the possibilities for development and the risks and potential implications that these technologies could lead to. We also note that it would be important to reflect risks for criminals and other stakeholders operating in all impunity in states. This is a threat and an increasing concern for Canada. We support the proposal by India to include the term quasi-state actors in paragraph 10. We also support the proposal by the Republic of Korea to include cryptocurrency in paragraph 10. Chair, Canada was very interested in the updated working document of Kenya on threats. We are very pleased to discuss how states can share as best possible information on threats related to ICT while we think that proposals need further discussions. Thank you, Chair.

Ambassador Gafoor

Thank you, Canada. Mexico to be followed by China. Mexico, please.

Mexico

Thank you, Mr. Chair. Mexico considers that this second annual progress report is an ambitious and positive document geared towards action, and that it is based on an evolving framework and builds on previous inputs, the implementation of the norms and principles for the responsible conduct of states in cyberspace. We believe it’s a solid basis to reach consensus and move forward toward this common goal. Mexico appreciates that this language broadly reflects the rich and diverse contributions of all delegations on key elements such as existing and potential threats. This is proof of a recurring reality that many delegations have stated earlier, and that is the evolving nature of cyberspace and technologies requires a flexible approach based on reaffirming the fact that international law is applicable to cyberspace, as well as the need to develop confidence-building measures that are adapted to our own contexts, and the importance of international cooperation to build capacity and resilience, as well as the need to maintain a balance between, on the one hand, the peaceful use of cyberspace and technologies for common good and the implementation of SDGs, and on the other hand, prevention, control, and mitigation of malicious activities that could threaten international security. As far as the two first sections that you requested that we comment on, my country values the references to previous reports that were adopted, as well as the principles of the responsible and peaceful use of cyberspace adopted by the Group of Governmental Experts and the OEWG. Mexico also would like to express its support for the proposal made by Argentina regarding the mention of capacity building. In the overview section, just as Canada, we align ourselves with the Australian proposal on the importance – on how important it is for the structure of the annual report to reflect the progress achieved in this group. As far as the repository of threats, my delegation agrees with comments made by Kenya on paragraphs 15 and 20, as well as what other delegations have said. We believe that this proposal would be better situated in the confidence-building measures section in order to continue exchanging views on this. My country also values the references to the gender perspective that are included throughout the text. And as we have seen, the participation of women has had a very positive effect on our negotiations. However, these references could be strengthened, as well as the need to address the growing digital divide that impacts women and other historically discriminated groups. Bearing this in mind, we support the proposed language made by the Netherlands just a few moments ago on paragraph 16. Lastly, I would like to reiterate the support of my country to make a positive contribution in this working group, and we’d like to express a hope to see the adoption of the second annual progress report. Thank you very much.

Ambassador Gafoor

Thank you, Mexico, for your statement. China to be followed by Japan. China, please.

China

Thank you, Mr. President. First and foremost, China thanks the President and his team, as well as the Secretariat, for everything you’ve done for making this meeting successful. China stands ready to play a positive role and make sure this meeting turns out to be a success. For the overview section, paragraph 1, malicious use of ICT, China prefers to use the 2022 annual report’s consensus language to highlight the impact on the critical infrastructure. Regarding paragraph 3, we’d like to reaffirm our established consensus, and on the basis of that, we believe that our landing point should be on the adherence to and implementation of the responsible state behavior framework, and hope it can be reflected in the current report. Regarding paragraph 7, relevant countries’ concern on visas, this should be properly reflected. Regarding the existing and potential threats section, with regard to paragraph 10, categories of critical infrastructure, humanitarian organization, this concept is not clear enough. We hope we can reference the OEWG 2021 report and say this is transportation. And China supports South Korea, among others, in adding the energy sector, among others. As for 10.4, with regard to the security of the supply chain, we prefer to use the GGE report of 2021, integrity of supply chains, because risks to a supply chain not only come from malicious Internet activities. As for 14 and 21, emerging threats, China believes countries, in order to maintain their hegemony, abuse this threat, and they’re using electoral coercive measures and deprive others of the right to use ICT technologies. They widen the digital gap and undermine international cooperation. This dangerous trend should be reflected in this section. China supports countries’ proposal that in our discussion of emerging technologies, we focus on data security, which is not only a common issue, it is also within the mandate of OEWG. China proposes that in our forthcoming discussions, we focus our discussion on digital security. For paragraph 15 and paragraph 20, China would like to highlight that before our tracing is fully addressed, under the current politicization trend, talking about establishing such a database will be counterproductive. It will not add to improved awareness of Internet security. It will be used as a platform to spread disinformation. To avoid such things from happening, we should first talk about establishing an interstate tracing mechanism, making sure that information is verified first, and before that mechanism is established, countries can use the CERT mechanism and the global points of contact directory that is about to be established to share threat information. The written statement will be submitted to the chairman. Thank you.

Ambassador Gafoor

Thank you, China. I give the floor now to Japan, to be followed by Cuba. Japan, please.

Japan

Please allow me, at the outset, to express my delegation’s appreciation for the patient manner with which you continue to guide us in our effort to further advance the objective of the OEWG. I would also like to commend all the efforts you and your team have made to come up with a zero draft and a subsequent Rev. 1 draft of the annual progress report of the OEWG. This is a good basis for further discussion in the meeting, and Japan is generally supportive of the draft report. Compared to the previous year’s report, the contents of the report have been materialized considerably. As Australia and Canada have stated, we sincerely hope that the final outcome of the report will well reflect the discussion in the previous substantive sessions of the current OEWG and will provide the basis for future discussions. As Mr. Ebo, Director of the UNODA, has stated at the outset, we must look ahead. Regarding existing and potential threats, as many delegations have already noted, our discussion cannot be separated from events in the real world. Malicious cyber operations have been conducted, including those against critical infrastructure, those intended to interfere in following elections, demand ransoms, and steal sensitive information, even in the form of state-sponsored cyber attacks. The reports of malicious use of ICTs against critical infrastructures are particularly troubling. Regarding paragraph 10bis, we would like to support a Netherlands comment to mention the importance of protection of critical infrastructure, including these sectors, rather than mentioning these sectors as vulnerable sectors. Mr. Chair, Japan would like to continue to work with other delegations constructively to reach consensus on this annual report. I thank you, Chair.

Ambassador Gafoor

Thank you, Japan. Cuba, please, to be followed by Czechia. Cuba.

Cuba

Thank you, Mr. Chairman. We would align ourselves with a statement made by Nicaragua on behalf of a group of countries. We’d like to stress the need for the report to be adopted to reflect in a factual and balanced way the discussions that have taken place in the framework of the OEWG during the period that we have covered. In response to the request of Ambassador Gafoor, we will focus our comments and proposals on specific issues that are important to our delegation. In section A, on general vision, we would like to say that regarding the role of regional organizations in cooperation in the area of security and the use of ICTs, we suggest adding at the end of paragraph 6 that regional efforts to this end should be inclusive and in no way discriminatory. In section B, on existing potential threats, we suggest the following: to add a reference to the primary responsibility of states in maintaining an ICT environment that’s open, safe, stable, accessible, and peaceful. Also, it’s important to eliminate reference to malicious activities, ICT activities, against humanitarian organizations. We think that this is a strained and overdone reference in paragraph 10bis. We believe that we should maintain a general reference to concern about the increase in malicious ICT activities that affect critical infrastructure and critical information infrastructures. It’s important also to factually mention other threats that have been expressed by various delegations during the OEWG discussions. This would ensure a balanced character to the debates. At this point, we would suggest paragraph 10.4 to begin as follows, and I will read: “States also express their concern about the malicious use of ICT platforms, including social media.” We also propose adding, after deepfakes, the following phrase: “for political ends or to interfere in the internal affairs of states, incitement to violence.” And then we would continue as is. Everything seems to point to the fact that states need more time to study and discuss the initiative mentioned in paragraph 15 and 20 regarding sharing information on threats, including through a possible repository. This has been a recent initiative within the OEWG, and there’s a concern that it could be used for false attributions or accusations for political ends. Any definition of threats should be assessed within the OEWG and approved by consensus. Thank you very much.

Ambassador Gafoor

Thank you, Cuba. Czechia to be followed by Ireland. Czechia, please.

Czechia

Thank you, Mr. Chair. I would like to address directly Section B, existing and potential threats. Our approach is constant. We have been drawing attention for a long time to several main areas of threats that need to be addressed in the Open-Ended Working Group format, and we appreciate that EPR covers many of them. I would like to highlight the main ones. The importance of ensuring supply chain security and highlighting the significant threat of cyberattacks in this context, especially in relation to critical infrastructure. Then, rising the amount of ransomware attacks. Last month, we have observed increased activities of malicious actors against the Czech Republic using ransomware techniques. These attacks have had serious effects. This is why we consider the inclusion of ransomware cyberattacks in the threat chapter as more urgent than ever. And it’s precisely the reason we fully support the proposals of Germany, the Republic of Korea, Austria, Costa Rica, and others to strengthen the language on this issue. Then, I would like to highlight malicious ICT activities impacting critical infrastructure and critical information infrastructure. In the previous Open-Ended Working Group session, Czechia systematically drew attention, for example, to attacks against the healthcare sector. To have the text more balanced, we support a proposal of Malaysia, supported by the Netherlands and other countries. We are also pleased that EPR is putting emphasis on threats arising from new technologies, such as quantum computing and artificial intelligence. We are of the opinion that elements of automatization, acceleration, and scalability, which those technologies are characterized by, bring new dynamics and deepen the opacity of current processes. In principle, we support the effort to convene dedicated interstitial meetings on the development of new technologies. This includes the participation of relevant experts, provided budgetary issues are resolved. We can support a Dutch proposal for rewriting the text as well. Last but not least, we appreciate that EPR is not afraid to say that ICT has already been used in conflicts. We are concerned that some states do not hesitate to use ICT capabilities for military purposes in violation of international law and norms. In addition to this, we welcome that EPR mentions the Kenyan proposal to develop a voluntary repository of threats to ICT security in the context of international security. We are looking forward to further discussing and elaborating on it, including also in which section to incorporate it, but we believe that it could enhance information sharing among states. Unfortunately, there is one element we are sorely missing in the EPR. We are convinced that the misuse of ICT to suppress human rights represents also a significant threat. It includes the massive collection of data on one’s own citizens, partial or complete censorship, blocking of internet monitoring, political opponents, and so on. We strongly encourage including it in the text of EPR. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Chair. Ireland to be followed by Israel. Ireland, please.

Ireland

Chair, thank you to you and your team for your work on the APR. We look forward to actively participating in the discussions this week. To begin, Ireland aligns itself with the statement made by our EU colleague earlier today. On the current draft, Ireland would like to make the following points. Chair, we consider the language on the current draft represents a baseline in detailing the importance of the gender dimension and gender perspectives to the issues being discussed with the group. Diversity is security, and it is important, recognizing the comments in this group, that the gender references throughout the REV1 are retained. We echo the comments of Austria and Canada in this regard. Chair, the proliferation of cybercriminality, ransomware, innovations such as ransomware as a service, and the indiscriminate use of ransomware by cybercriminals, particularly where critical infrastructure and national healthcare systems are targeted, has elevated this threat to the point where they merit inclusion in this text. In that context, we welcome the references to ransomware in paragraph 10, Carther, and believe it is important to include the additional language proposed by Costa Rica and the Netherlands. Chair, we support the removal of the reference to misinformation in paragraph 10, Carther. We see value in retaining the language to the text and the threat of disinformation, and making clear that this refers to where disinformation is enabled by malicious cyber activity, such as in hack and leak campaigns. These campaigns, particularly where they occur in an election context, can be enormously damaging to the integrity of government procedures and political processes. We support the Netherlands’ proposals on this. Chair, we support more focused discussions to consider developments in new technologies, as referenced in paragraph 21. The focus on artificial intelligence is of particular importance, given the degree to which threat actors are increasingly deploying more sophisticated and complex AI-powered tools to scale and power malicious cyber behavior. More focused discussions will be a good opportunity to consider these challenges in greater detail. It is important, as Colombia mentioned, that there is participation of industry, civil society, and other stakeholders in this discussion, and this should be elaborated in the next version of the text. Chair, attacks against humanitarian organizations are of the utmost concern to the international community and demand serious consideration. In this context, Ireland supports further consideration by the OEWG of the Swiss proposal on the need to safeguard digital assets. Finally, I wish to echo the comments of my Czechia colleague on the Kenyan proposal. Thank you very much.

Ambassador Gafoor

Thank you, Ireland. Israel, to be followed by El Salvador. Israel, please.

Israel

Thank you, Mr. Chairperson. As per your request, please take as given our thanks to you, your team, and the UN ODA Secretariat. Mr. Chairperson, as our common practice, the annual report should be based on the solid foundation laid out by the reports of the previous GGEs and Open-Ended Working Groups, the relevant General Assembly resolutions, and the extensive discussions we have conducted throughout the year. The principle of consensus is an integral part of our work and should continue to guide us through this session. Mr. Chair, the cyber-threat landscape has continued to expand steeply during this passing year. This is linked first and foremost to the increase in cyber-attacks carried out by malicious states, state-sponsored actors, and non-state actors. We have witnessed attacks on critical infrastructure, ransomware, malware, cyber-crime, and DDoS attempts to disrupt and block services and access to data. Cyber-crime, including ransomware, has grown to become the world’s third-largest economy after the U.S. and China, according to the World Economic Forum, and is projected to cost the world $8 trillion in 2023 and $10.5 trillion by 2025, or 1 percent of global GDP. Ransomware increasingly crosses the threshold of impacting international peace and security. In that regard, Israel is taking an active role as part of the counter-ransomware initiative led by the U.S. As the world continues to witness growing attack surfaces, a phenomenon linked inter alia to the ever-developing technological landscape and its interconnectivity, as well as to changes brought about by the COVID-19 pandemic, threats in cyberspace have the potential to become even more harmful than before. Attacks on critical infrastructure, including essential critical information technology, as well as essential services such as hospitals, water infrastructure, and energy supply, are more prevalent and create a growing risk to human lives and enormous economic losses when they are not properly secured. Building resilience to thwart them and mitigate their effects requires stronger political will, clear vision, concrete action, and increased cooperation across organizations, sectors, and borders. Considering these threats and challenges, Israel welcomes the reference in the text to the malicious use of ICTs by terrorists and criminal groups in paragraph 10. We are witnessing an intensifying threat posed not only from terror-sponsoring states but also directly by terrorists, proxy organizations, and other malicious users. The spectrum of malicious actors in this respect has increased significantly. Israel also welcomes the reference made to ransomware, wiper malware, phishing, and trojan in paragraph 10.4 of the APR draft. Israel supports further expansion of these threats in the text to accurately represent the discussion that has taken place in the room, as well as the prominence of these threats, in particular ransomware that crosses the threshold and becomes a threat to national security. In addition, we remain convinced that the existing and potential threat section would benefit from a specific reference to attacks against infrastructure that exploit critical vulnerabilities, as well as threats to operational technologies and SCADA. Mr. Chair, still on the issue of threats, we would like to highlight an erroneous conflation that has been made in the drafting of paragraph 11 of the draft APR between two separate issues. Israel strongly supports the inclusion of an expression of concern regarding irresponsible and malicious use of ICT capabilities. Software vulnerabilities, spyware, sophisticated high-end offensive ICT tools, and hacker-for-hire services are used by malicious users to carry out their nefarious activities. This is a serious threat that needs to be recognized in our report and is reflective of the discussion we’ve had during this past year. At the same time, the inclusion of a reference to states in the second line conflates the problem of irresponsible and malicious use in users with normative aspects of transfers by states. Transfer of ICT tools by states is in essence a fundamentally different subject matter, which is addressed in other specialized fora, as they require specific expertise and a different set of considerations. In addition, it should be recognized that open sources in and of themselves are not illegitimate and are used legitimately by state and private actors alike. It is important that we do not curtail them because of the abuse carried out by malicious actors. Mr. Chairperson, with regard to paragraph 15, like Germany and Canada, we would be happy to reflect in the text the need for further discussion of this suggestion. An additional issue we have with the context of threats refers to paragraph 17. Israel would like to repeat its position expressed in previous meetings that voluntary norms, international law, and CBMs cannot all be characterized uniformly as obligations. Voluntary norms, by their very definition and nature, are not obligatory. CBMs, in the context of the open-ended working group, are also voluntary. We therefore suggest a tweaking of the text that would differentiate between voluntary norms and CBMs on the one hand and obligations under international law on the other. Finally, Mr. Chairperson, I would like to support the comment made by the Delegation of Australia that we are not here to pass judgment on technology but rather address its misuse. I thank you.

Ambassador Gafoor

Thank you very much, Israel, for your statement. El Salvador to be followed by Estonia.

El Salvador

Mr. Chairman, I’d like to thank you and your team for elaborating an annual progress report, which we believe is an improved version compared to draft zero. We don’t have a comment on the overview, which is made up mostly of previously agreed language. Regarding existing and potential threats, El Salvador in previous sessions explained how emerging technology could represent new vectors of attack and create new vulnerabilities, which is why, generally speaking, we appreciate the language of this section. We attach great importance to the need for protection of critical infrastructure and critical information infrastructure from malicious attacks, especially those that affect essential services and that are key to the functioning of society, or guarantee the integrity and operation of the internet, which is why we would like to preserve paragraph 10b in its current form. Along these lines, we applaud the specific mention of some of these threats in 10-quarter through the use of techniques such as ransomware, exploitation of software vulnerabilities, and attacks against supply chains. These are threats which we have discussed in previous sessions and explained their disruptive character regarding national and international security. We, in particular, attach great value to the proposal of Costa Rica on this point, which has been approved by other delegations. Also, we acknowledge the recent developments regarding artificial intelligence and its intersection with quantum technology as very important. We hope to develop this in future sessions. We think it’s important to further work on this topic, especially when we speak of certain uses and abuses of artificial intelligence. Since this is a very vague term to be used in discussing technology and its implications, particularly regarding such topics as peace and security, we hope that this reference is maintained in the future report, although we are flexible regarding the language. The goal is to keep building common understandings on potential threats, as proposed in paragraph 21. Mr. Chairman, the mention of a gender perspective throughout the report is essential and is an element that we think is a cross-cutting one and a holistic one in our discussions, which is why we believe it should be retained. Thank you very much.

Ambassador Gafoor

Thank you, Salvador. Estonia, to be followed by Brazil. Estonia, please.

Estonia

Thank you, Mr. Chair, for giving me the floor. I would like to start by expressing my sincere appreciation for the hard work of you, Chair, and your team in preparing the draft of the Annual Progress Report that captures the discussions we have held during recent OEWG formal and informal meetings. I believe that this draft report is a good basis for fine-tuning the convergence language and for successfully delivering the 2023 APR. The Soviet alliance itself, with the statements delivered by the European Union, including the points made on Russia’s operation against Ukraine. We would also like to use this opportunity to add some points in our national capacity regarding the sections of the revised draft report under discussion so far. On the existing and potential threat section of the revised draft report, Estonia welcomes the language on the ongoing use of ICTs in conflicts in paragraph 10. We see it as very relevant to objectively reflect the threat landscape and the severity and multitude of various threats. In this regard, the protection of critical infrastructure and essential services, as well as safeguarding the security of democratic processes such as elections, is vital for the functioning of our societies. We also underline the increasing number of ransomware attacks which, when targeted against, for example, critical infrastructure providers, may bring along devastating effects. We therefore support the language proposal highlighted by Costa Rica. Estonia hosted this afternoon a roundtable to exchange experiences on counter-ransomware challenges with the Russia Institute and Costa Rica and Vanuatu as co-sponsors. The discussions underlined the relevance of the threat of ransomware worldwide in the context of international peace and security. And, if I may add, we did have sandwiches. In addition to the vulnerability of healthcare, maritime, and aviation sectors mentioned in paragraph 10bis, we would propose to add the energy sector to the list as proposed also by the Republic of Korea and some other countries. We would also like to underline the key principle reiterated in paragraph 17, emphasizing that any use of ICTs by states in a manner inconsistent with their obligations under the Framework of Responsible State Behavior and the use of ICTs, which includes voluntary norms, international law, and CBMs, undermines international peace and security, trust, and stability between states. In addition, I would like to react to the suggestion of the countries that supported initiating the negotiations of the Legal Abiding Treaty that, in our view, it would be premature and unnecessary at this time. The notion that existing international law and, in particular, the UN Charter applies to cyberspace has been confirmed by all the UN Member States numerous times. The State must now engage in productive discussions of further clarifying how existing international law applies in the context of cyberspace. Finally, the idea expressed by Colombia on giving space for countries that have suffered under cyberattacks to share their experiences on a voluntary basis is a good one and deserves our attention.

Ambassador Gafoor

Thank you, Estonia. Brazil to be followed by Croatia. Brazil, please. Thank you.

Brazil

Thank you, Mr. Chair. Thank you and your team for your hard work this past year. In the interest of time, we will go straight to substance, as you have requested. Brazil welcomes your second revision of the APR. On overview, we support the suggestion made by Argentina of mentioning capacity building efforts, which is not only cross-cutting but also essential for other pillars of the mandate of this OEWG. On Section B, Existing Implementation Threats, my delegation would like to highlight a few passages. Paragraph 10 mentions military purposes, use of ICTs in future conflict between States, and in this context, “concern that ICTs have already been used in conflict in different regions.” When addressing this issue, this group must refrain from going beyond its mandate, in particular regarding making attributions of malicious uses of ICTs. In paragraph 10 quarter, while recognizing international threats of specific ICT tools and techniques, we should keep in mind the difference between the adequate global institutional responses. In other words, whether these issues belong to this OEWG, or for instance, to the UN Ad-Hoc Committee on Cybercrime Convention. Some delegations mentioned this issue and suggested wording that could commend consensus. In the same sense, in paragraph 11, we need to consider whether challenges stemming from “growth of illegal markets and open sources” are an issue for this OEWG, or if this belongs to the framework on cybercrimes. Also in paragraph 11, my delegation is concerned about language to the effect that “proliferation, including by States, of ICT capabilities can be utilized by malicious actors.” This passage could generate imprecisions or confusion, especially given the nature of ICT capabilities. We are concerned about the consequences this notion could entail, especially to developing countries, for example, regarding States’ efforts to develop legitimate capabilities in order to close the digital divide. Brazil, therefore, requests that the words “including by States” be deleted. On paragraph 16, my delegation prefers to align language with consensual one agreed in the last commission on the status of women’s session, where it reads “specific risks faced by vulnerable groups,” we suggest to replace by “specific risks faced by persons in vulnerable situations.” On paragraph 20, we request to add back the language on “further developing the proposal for a repository of threats to ICT securities” in order to guide our future focused discussions on this, taking into account concerns raised by delegations on this issue. I thank you.

Ambassador Gafoor

Thank you, Brazil, for your contribution. Croatia, to be followed by Singapore. Croatia, please.

Croatia

Thank you, Chair, and also many thanks to your whole team for the zero-draft report, and even more for the revised, much-improved version of the annual progress report, which quite well reflects our discussions from the last 12 months. Let me begin by stating that Croatia aligns itself with the intervention of the European Union, and in national capacity, we would also like to stress the importance of acknowledging previous UNGGE and Open-Ended Working Group reports, which were endorsed by the consensus of all states in the General Assembly, and which represent a great framework and baseline for our discussions. Therefore, we are grateful that those founding elements are mentioned in the overview. The Secretary-General, in his new Agenda for Peace brief, has emphasized, amongst other things, the need to invest in prevention, support regional cooperation, and to put women and girls at the center. We are glad that these horizontal topics are also addressed in our annual progress report, although the role of regional organizations could be better mentioned throughout the text. We especially welcome the emphasis on the empowerment of women in the ICT domain, mentioned in PARIS 7. This is needed because roughly 17 percent of technology companies currently have a woman serving as a CEO, and the survey from last year shows that a staggering 91 percent of software developers are men. So the high participation and engagement of female delegates in this working group serve not just as an excellent example and role model for the private sector, but also wider. And therefore, we advocate to keep wording both in PARIS 7 and PARIS 16, which is already supported by the majority of states today. No survey is needed to demonstrate how new threats are influencing our everyday life, especially the life of civilians in Ukraine, where Russian military aggression is not just violating international law, but also damaging all our work and efforts we all have invested in the last several years to achieve security of the ICT domain. We welcome that many of the new threats, such as unlawful usage of ICTs in armed conflicts, malicious cyber activities against critical infrastructures, supply chains, and political and electoral processes, as well as ransomware, are rightfully mentioned in this year’s text, and we can support the German proposal to mention also the spillover effect and the proposal from Costa Rica to strengthen the ransomware wording. We would be equally grateful if DDoS attacks could be mentioned in PARIS 10 quarter, especially those DDoS attacks directed against public services that are necessary for the undisrupted functioning of society, having in mind that in the last year alone, DDoS attacks globally increased by 109 percent. Also, having in mind the recent briefing on AI in the Security Council, we further agree that we should also closely follow developments of new technologies, such as AI and quantum, which could have an impact on cybersecurity, and therefore, we welcome PARIS 21 and the dedicated intersessional meeting on the cyber angle of new technologies, while not duplicating work in other formats. On the other hand, in PARIS 10 quarter, we would like to remove misinformation, since it is not deliberate behavior like disinformation, which is, on the other hand, purposefully false or inaccurate information sharing. And having in mind the UN Universal Declaration of Human Rights, and therein mentioned freedoms of opinion and expression, we would like to clarify in the text that cyber-enabled dissemination of disinformation should be addressed, or we can use agreed language from our previous report, as Australia suggested. We can also support member states who pointed out that mentioning data could be better positioned in PARIS 14. Lack of trust and cooperation creates a fertile ground for all kinds of cyber-related threats, new and emerging, and therefore, the input of all stakeholders is invaluable. So we need to work closely with the private sector in order to create a robust foundation for security and sustainable development. And here, we can support Kenya’s intervention on the need for more security by design. Some new initiatives, such as repositories and a dedicated portal, were proposed in the text as well. And we believe that it would be beneficial for us all to hear more information about them and also to identify whether we can achieve synergies with existing mechanisms. So we could support a dedicated informal meeting, and having in mind budgetary implications, we can support the virtual form of that meeting. We should aim for simple solutions, which will bring added value while avoiding unnecessary burden for the secretariat. And of course, we would like to encourage the involvement of all stakeholders. The POC directory is a good example of how, through valuable exchanges with regional organizations and member states, we can reach tangible and sustained results, which would serve as a role model for future initiatives. And we know that it’s almost a mission impossible to accommodate all requests from member states and still have a well-balanced text, but we have confidence and trust that on Friday, we will be able to agree on a new annual progress report with clear guidelines for our future work. Thank you, Chair, and sorry for being a little bit longer.

Ambassador Gafoor

Thank you very much, Chair, for your statement. Singapore, to be followed by France. Singapore, please.

Singapore

Thank you, Chair. Firstly, I would like to express my delegation’s appreciation for the work done by you and your team in sharing the work of the OEWG in developing the draft Second Annual Progress Report. Singapore aligns itself with the statement made by Brunei on behalf of ASEAN earlier. Singapore notes that the revised draft APR has captured the key points and a broad range of proposals raised at past sessions. This reflects the breadth and depth of interests of States and is important, especially given the transboundary nature of cybersecurity. The second APR draft thus forms a good basis as a roadmap for both immediate action and to inform future OEWG discussions over the next year and beyond. We look forward to the draft being adopted by consensus as an affirmation of Member States coming together on this important issue of cybersecurity. Chair, the section on existing and potential threats is especially important as without a clear threat picture, the various pillars under the OEWG mandate will not be holistically informed, causing us to navigate blindfolded through the ever-changing landscape of cybersecurity risks, and our efforts will be akin to shooting arrows in the dark. To effectively defend, we must first understand the nature and scope of the threats. It is therefore important that this segment represents the breadth of cyber threats faced by States, and we are glad that the APR has captured a variety of emerging and potential cyber threats which we see in our region as well. For example, paragraph 10bis mentions concerns over malicious ICT activities impacting critical infrastructure and critical information infrastructure. Paragraph 14 mentions that developments in technologies such as quantum computing, artificial intelligence, and the increasing reliance on cloud technology could potentially have implications for the use of ICTs, including by increasing vulnerabilities and expanding ICT attack vectors. Recognition of these threats will help States better formulate stronger, more effective defense measures against the threats. We further welcome the dedicated international meeting with relevant experts mentioned in paragraph 21 to help us better comprehend the wide range of challenges and threats faced. Through these discussions, we hope that we can collectively develop insights into the dynamic cyber threat landscape to better inform our discussions at the OEWG. Thank you, Chair.

Ambassador Gafoor

Thank you, Singapore, for your statement. France to be followed by the United Kingdom. France, please.

France

Thank you very much, Chair. As I know we’re short on time, I’ll go straight into the substantive comments that I have on this text. First of all, I’d like to thank you and your team for your leadership and your unwavering search for consensus. Rest assured you have the constructive support of my delegation to enable this group to, at the end of the week, adopt a robust, balanced report. We’re sure that this is possible. On B, the section on existing and potential threats, my delegation thinks that, on the whole, we have seen significant progress with respect to the 2022 section of this report. However, we have some comments on certain paragraphs of this section as follows. On 10, we welcome the introduction of language on the use of ICT in conflict. We think it’s crucial for the relevance and very credibility of our work to note that this scenario is no longer a probability, but rather a reality. In order to further clarify on language, we’d like to support the proposal of Germany on the threat of the spillover effect of such actions. On 10-quarter, my delegation would like to delete the mention of disinformation, which is a legitimate and natural concern, but we think that it doesn’t fall under the mandate of this group. It could be better dealt with in other fora. On paragraph 11, my delegation supports the inclusion in this section of the irresponsible and potentially malicious use of commercially available ICT capabilities. On 14 and 21, we commend the introduction of a reference to technologies such as AI and quantum computing. We can also support the addition of language that notes that these technologies could have implications on cyber security, and that is what this group is interested in. Finally, on paragraph 20, my delegation can support the new addition and we’re open to proposals such as on the repository of threats. We think these discussions above all must seek to explore the objectives and potential modalities of these proposals. Thank you.

Ambassador Gafoor

Thank you very much, France, for your statement. The UK to be followed by Switzerland. UK, please.

United Kingdom

Thank you, Chair. We are grateful for your efforts and the efforts of your team. We feel that this draft does go a good way to achieving balance, reflecting both the depth of our discussions this year and the practical proposals by Member States to, as you said in your introductory remarks, take small steps with each passing cycle in support of our mandate. We are mindful too, as has already been suggested by others, of budgetary and resource restraints, both the Secretariat’s and our own as Member States, when we are considering a future roadmap for this group. We look forward to participating constructively this week in support of a consensus report. On the threats section, we welcome the proposed language from Costa Rica for further language on ransomware. This subject has been a source of significant discussion and increasing concern in this group over the past year. Like the Netherlands, our preference would be to retain the reference to ransomware incidents for consistency across the report. Regarding references to disinformation, misinformation, and deep fakes in paragraph 10 Quater, and the suggestion to include fake news and further such activities, we agree with Australia’s proposal to use umbrella language from the 2021 GGE report. We also support the proposal from Malaysia, Croatia, and others that data security would be more suitably listed in paragraph 14. We support the inclusion of paragraph 11. The United Kingdom is concerned by the risk posed by the misuse of commercially available cyber capabilities. Increasingly, these capabilities will come in more advanced forms and from a wide variety of sources, legitimate and otherwise. We therefore suggest that the emphasis of this paragraph should be on responsible use. And so rather than referring to illegal markets, which could be read ambiguously, it could instead conclude with reference to the misuse of commercially available ICT capabilities in a manner inconsistent with international law, including international human rights law, and the framework for responsible behavior in the use of ICTs. There’s been a lot of interest in discussing emerging and potential threats, including today. We thank Kenya for sharing an updated paper on their proposed threats repository. We are ready to discuss this further, to consider ways to increase threat information sharing and to draw links with existing initiatives. We support suggestions from others that we could consider this repository as a potential CBM and potentially reference it in that section of the report. Finally, we would like to support reference to groups in vulnerable situations rather than vulnerable groups and to emphasize the importance of reference to gender perspectives throughout this report. We should not be less ambitious on this issue than in previous reports when we rightly celebrate the improvements in representation in this working group. Thank you, Chair.

Ambassador Gafoor

Thank you very much, UK. Switzerland to be followed by the Syrian Arab Republic. Switzerland, please.

Switzerland

Thank you, Mr. Chair. Thank you and your team for all the efforts and the zero draft. The REV1 version is a step forward compared with the first draft and a good basis for our discussions. We agree with you, Mr. Chair, that we have made important progress in our work, and it is important that this is reflected in the report. The report reflects this progress quite well and would benefit from Australia’s proposal of restructuring. Moreover, in our view, there is still a certain imbalance between proposals and positions that have received broad support, like the POA, and those that have been suggested by some states. We support the action-oriented approach of the draft. The report contains many proposals for future work. As others have said, we think that we have to set priorities in order to be able to plan and prepare for our work accordingly, taking into account the resources of delegations. Stakeholders have a role to play in all six pillars and can make valuable contributions to our discussions. This should be adequately reflected in all sections of the report, which in our view is not yet the case, for example, in the chapter on international law or in the chapter on regular institutional dialogue. On the introduction section, paragraph 3 contains the important reaffirmation of the UNGGE consensus reports of 2010, 2013, 2015, and 2021, and the Open-Ended Working Group consensus report of 2021. We support Australia’s proposal for the rewording of the second sentence of paragraph 3. In the last sentence, we would like to replace “a foundation” with “the foundation.” International law, in particular the Charter of the United Nations, is applicable and essential to maintaining peace, security, and stability in the ICT environment. It is important to state this in the introduction. As the Republic of Korea and Australia, we would like to emphasize that the UN Charter is applicable in its entirety and that this should be reflected in this report. We welcome paragraph 6, highlighting the important role of regional organizations, but would like to suggest deleting the “could” in the first sentence. Regional organizations already play an important role, and we should recognize that. Both the Open-Ended Working Group and regional organizations can benefit from each other. We also welcome paragraph 5 on the role of stakeholders and paragraph 7 on the participation of women delegates and would find leaking of the text difficult to accept. On the threat section, we welcome the change in paragraph 10, which points out that ICTs are already used in conflicts in different regions. That’s a reality which we need to reflect and report. States’ use of cyber operations and malicious activities of non-state actors may have harmful spillover effects. We therefore support Germany’s proposal for the addition of spillover effects in this paragraph. We welcome the new paragraph 10b. It is important to mention potential cascading effects malicious cyber activities against critical infrastructure can have, and we especially welcome the mention of humanitarian actors in this paragraph. Switzerland believes that it is critical to have a firm consensus among states that humanitarian actors and their data must never be subject to malicious cyber activity or misuse. We invite all states to continue discussions on this and work together to affirm this consensus. We support the mention of ransomware in paragraph 10.25 and support Costa Rica’s drafting proposal to expand the wording. We also support the proposal by Australia to redraft this paragraph with regard to misinformation and disinformation. And we share the concerns stated by the Netherlands on data security and the concrete drafting proposal in this regard. We welcome the inclusion of paragraph 11, but would also like to change the language and support the proposal just made by the UK. We welcome the reference to emerging technologies in paragraph 14, such as quantum computing and AI. We would like to suggest also mentioning IoT devices here, as well as in paragraph 21. The Netherlands has made a proposal on how to address data security in this paragraph 14, and we could imagine a similar wording for IoT devices referring to their increased use and proliferation and potential for misuse. Finally, in paragraph 15, the proposal for a threat overview is a valuable proposal from our point of view and deserves to be discussed further. As others have already mentioned, we should take into account existing formats for sharing threat information and assessments. And we could also imagine discussing this in the sections on CBMs. Thank you.

Ambassador Gafoor

Thank you. Switzerland, Syrian Arab Republic, to be followed by Kazakhstan. Syria, please.

Syria

Thank you, Mr. President. At the outset, I would like to thank you and your group for your efforts to prepare the first revised draft of this report. We also value your leadership, which represents a key factor in the progress made by this group. We would like to join the group given by Nicaragua on behalf of the like-minded – the group of like-minded states – and we would like to add the following comments in our national capacity. First of all, with regards to the standards of responsible behavior, the report focuses on standards that are already pre-existing with no attention to developing new standards. This is despite the fact that the development of such new standards is part of the mandate of the group. The United States have also clearly expressed their support for the development of new standards in order to keep up with the rapid developments in the changing landscape of threats. In that context, we would like to affirm the reference to the need for a legally binding instrument that clearly outlines the duties of all parties in a balanced manner and deals with the use of ICT in a comprehensive manner that is consistent with the unique nature of cyberspace. We also welcome the keenness on the implementation of pre-existing instruments, but this is not enough. Secondly, we emphasize that the Open-Ended Working Group (OEWG), because of its comprehensive, inclusive, and democratic nature, is considered the best platform to find effective and consensus solutions in the field of ICT. And the program for responsible behavior implies that all states have already agreed that this is the best platform in order to delineate how ICT should be used. And this is not the case, because discussions have made it clear that different states have not agreed to implement this program. Many have considered it a program that should be considered within the group on equal footing with other programs so that its effectiveness can be assessed before it is agreed. As for international law, the report focuses on how international law can be applied to ICT without giving enough attention to the possibility of working on data security in internationally binding instruments. This is something that several delegations, including ours, have emphasized in order to fill any gaps in terms of the implementation of international law in cyberspace, which has a very different nature from the material space. As for capacity building, no capacity building process can be effective and credible in light of the restrictions enforced by unilateral coercive measures. Therefore, it’s important to outline in the draft report the negative impact of such measures. They need to be lifted, and they cannot be reinstated because of how negatively they impact the access of the countries that suffer them to technology and preparations needed in order to participate in enforcing peace and security in the use of ICT in an effective and equal manner. And as for the section under review on existing and potential threats, we believe that the draft report has neglected to mention a number of threats outlined by a number of delegations, including ours, key among which was the use of encryption technology on the internet by terrorist organizations in order to coordinate and communicate. They use the dark web and encryption and private networks and hacking in order to recruit soldiers and deceive youths and spread hate and increase radicalization and hatred. Social media and digital platforms are also used to spread misinformation and disinformation in order to interfere in states’ affairs and destabilize them in order to achieve political ends, and this all threatens international peace and security. Developed services such as cloud services that are provided by some technology companies in states without their consent must also be considered an attack upon these states’ cyberspace. In order to face these threats, we believe in the importance of adding a recommendation that highlights the importance of reaching rules that are abiding these companies that provide services that rely on encryption so that they cannot provide these services without the explicit consent of the countries in which these services are provided, and the violation of such rules should be considered an attack upon these countries’ cyberspace. Thank you, Mr. President, and sorry for taking so long.

Ambassador Gafoor

Thank you very much, Syrian Arab Republic, for your statement. I now give the floor to Kazakhstan, to be followed by Ecuador. Kazakhstan, please.

Kazakhstan

Thank you, Mr. Chair. Kazakhstan fully supports the work of the Open-Ended Working Group aimed at finding consensus on the key international agenda in the field of ICT. In March 2023, we adopted the concept of digital transformation as a development of the ICT industry and cybersecurity, which noted the UN documents in the field of cybersecurity. On the presented report, our delegation expresses the following opinion. On paragraph 10b, we believe that there is no need to list all sectors of critical institutions, since the list can be endless. We propose to remove all threats of activity and replace them with the following words: “that provide a threat to the state and the provision of public life.” On paragraphs 14 and 21, given the rapid development of technology, we consider it right to mention AI. This technology could potentially have applications for the safe use of ICT. In this regard, Kazakhstan has begun work on implementing a strategy for the development of AI. Finally, on paragraphs 15 and 20, our delegation supports the agreement of three directories that will allow all countries to use said information at the same level. Mr. Chair, the statement will be sent to the Secretary. Thank you.

Ambassador Gafoor

Thank you very much, Kazakhstan, for your statement. Slovakia to be followed by Vietnam. Slovakia, please. Sorry, Ecuador. My apologies to Ecuador. You have the floor, please. Could you restart, Ecuador? Thank you.

Ecuador

Thank you, Chairman. My delegation would like to congratulate your efforts that have facilitated the preparation of this fifth session and the work of the Open-Ended Working Group. Ecuador is grateful for the revised version of the Second Annual Progress Report, which inter alia has a set of essential aspects for the operation of the global repository of contact points. We believe that this report should be adopted at this session without delay. I would like to reiterate that Ecuador would like to insist that international law, including international humanitarian law, applies to cyberspace. Ecuador defends its exclusively peaceful use. The UN Charter prohibits the use of force, so any conflict or dispute should be dealt with through peaceful means, including with regard to cyberspace. Therefore, we support the reference to this as is mentioned in the overview of the document in question. Ecuador values the efforts to incorporate into this document the points reached by consensus last year and the different proposals of various negotiations. This is an excellent basis for negotiation for this session. As mentioned in previous meetings, in our opinion, capacity building should be a robust section of the report oriented towards action and with a gender perspective that makes it possible for us to make progress in eliminating digital and gender divides, taking into account that each country has its own situation. Ecuador is grateful that Argentina has made a specific proposal on capacity building in the overview. We’d like to also highlight the importance of a broad and coordinated participation of the various actors involved in cyberspace activities and the importance of public-private partnership in this area. Ecuador values the inclusion of initiatives such as the Repository of Threats that we believe is a concrete example of confidence-building measures among states. With regard to paragraph 10-TER, Ecuador supports the mention of malicious activities that undermine trust in electoral processes and democratic systems. Also, in paragraph 10-QUARTER, we support the mention of malicious risks and activities such as ransomware, and we also support the proposal made by Costa Rica. As for paragraphs 6 and 16, we’d like to highlight the need for a gender perspective that specifically envisions risks for groups in vulnerable situations and also speaks of efforts to reduce the digital divide. On paragraph 21, Ecuador supports the organization of an upcoming meeting with the participation of experts to discuss the development of new technologies, in particular, technologies pertaining to artificial intelligence and the impact of this technology on international peace and security. Mr. Chairman, Ecuador trusts that dialogue and a commitment to a safe cyberspace for the benefit of everyone will be the main premise, the main starting point for these negotiations and future negotiations. It will allow us to continue to take positive steps based on our mandate, and you can count on the support of this delegation to continue working constructively under your leadership. We wish you success in the work in conducting this session and the adoption by consensus of our Second Annual Progress Report. Thank you very much.

Ambassador Gafoor

Thank you. Ecuador. Slovakia, to be followed by Vietnam. Slovakia, please.

Slovakia

Thank you, Mr. Chair. Slovakia aligned itself with the statement delivered by the European Union. Still, allow me to make some further remarks in my national capacity. Slovakia welcomes the proposal to adopt the annual progress report of the second OEWG. We thank you, Mr. Chair, and your team’s efforts for drafting the report and for endeavoring to reach a consensus and set a roadmap for the next discussions in this process. The ICT threat landscape continues to evolve rapidly, and malicious behavior in cyberspace increases with a speed that we in this format find difficult to keep up with. This is one of the reasons why Slovakia greatly appreciates the expanded and improved section on existing and potential threats. Slovakia considers it essential to use this section to describe and raise full awareness about the existing threat landscape and to focus discussions in the OEWG on the most harmful threats to international peace and security today. Especially as technology becomes interlinked with the physical world, cyberattacks can put the lives and the well-being of those in vulnerable situations at risk and could as well cause undesirable misunderstanding and escalation. Over the course of the past few years, we have witnessed the effects of malicious use of ICTs in connection to networks all over the globe, particularly with regard to Russia’s use of ICTs as part of its war of aggression against Ukraine. With the Russian invasion on February 24, 2022, the Age of Vipers seems to have arrived as a growing number of destructive malware variants try to rip through Ukrainian systems. While such attacks weren’t unheard of in the years preceding the Russian invasion, the rise of viper incidents detected in various sectors and later also in countries reached an unprecedented pace. The countries that support Ukraine have, unfortunately, also become targets. We have also seen a rise in the use of cyberattacks involving destructive instruments, not only vipers for system breakdown but also service disruptions, intrusion attempts, and DDoS attacks targeting Ukraine with the potential for spillover into other countries. Importantly, the ever-increasing use of ransomware poses threats to systems worldwide. We therefore commend the reference to risks posed by malicious ICT tools, such as ransomware and phishing, among others, in paragraph 10.4, but would nonetheless welcome a stronger emphasis on the threats posed by ransomware attacks, such as the text amendment suggested by Costa Rica and supported by multiple other countries. Still on the topic of threats, Slovakia supports the inclusion of the acknowledgment of the malicious use of ICTs in the context of armed conflicts. This acknowledgment clearly mirrors the level of urgency we all share to address this matter. We therefore support Germany’s suggested addition to the text in connection to this specific threat. Lessons from history and recent attacks on critical infrastructure throw into sharp relief the need to better safeguard our essential services. In this vein, we would like to emphasize the vulnerability of sectors such as healthcare to malicious cyber activities in paragraph 10bis. We also appreciate the mention of the potential for trust and confidence in political and electoral processes and public institutions being undermined as a result of malicious use of ICTs in paragraph 10ter. And finally, I would like to express our support for the statement delivered by the Czech Republic, as we would also like to draw attention to the lack of reference to the misuse of new technologies and in turn potential for human rights abuses in the threat section. While new technologies offer countless opportunities for societal development, they cannot be used to repress human rights in any shape or form. The annual progress report should therefore reflect this. Mr. Chair, without a doubt, the cyber threat landscape continues to evolve and we are oftentimes getting the short end of the stick. As such, I would like to once again appreciate your effort and would like to offer on behalf of the Slovak Republic our maximum support and cooperation moving forward. Thank you.

Ambassador Gafoor

Thank you, Slovakia, for your statement. I give the floor to Vietnam.

Vietnam

Thank you, Mr. Chair. Mr. Chair, at the outset, the Vietnamese delegation would like to express our full support for the leadership of this working group. We associate ourselves with the statement delivered by Brunei on behalf of ASEAN in our national capacities. We welcome the first revision of the draft report, which has considered thoughtfully and decisively inputs from the informal meetings on June 27th, and will serve as a strong foundation for future discussion on ICT security and the identification of confidence-building and capacity-building measures. Mr. Chair, we share the vision of a peaceful ICT environment based on international law, equal and full participation of states, cooperation with private and international partners responsible for state behaviors, and confidence-building measures. We acknowledge the importance of the OEWG processes in realizing these visions and emphasize the need for consensus in this annual progress report. We also share the sentiments with many delegations that the Intergovernmental Points of Contact directories will be the first major achievement of this working group, and even though some fine-tuning is required, it is our hope that the POC will be finalized by the end of this week. Mr. Chair, turning to Section B on threats, we support the view expressed by previous speakers that the draft report should go further than a mere summary of the March session discussion and continue to update on the new and emerging trends and threats that members did have as sharing to the group. Along this line, this delegation hopes to see references to the dark web, cryptocurrency, and ransomware as pointed out by previous speakers, and will lend its support to the suggestion of the repository of threats as mentioned in paragraph 15. Regarding paragraph 10bis, we support the Korean and Chinese suggestion to add energy among vulnerable sectors, and propose the addition to the civilian population after the phrase essential services, so that it would reach essential services to the civilian population as already mentioned in the UN Security Council Resolution 2573-2021. Regarding paragraph 10 quarters, we support the Cuban proposal to put a threshold on misinformation and disinformation, including defects that may come under the purview of this working group. Therefore, these activities should be violating the principles of non-interference in domestic affairs. We also recall that in March, many delegations mentioned the need for a gender perspective in addressing the ICT threats. Therefore, we are pleased to see this mentioned in paragraph 16. Regarding paragraph 17, this delegation would like to register its understanding that the phrase their obligation only refers to international law obligations duly assumed by the state. And the phrase framework of responsible state behaviors refers to an evolving and ever-changing framework that may cover emerging technologies and includes all legally binding instruments in addition to the United Nations Charter. Regarding the next steps in paragraphs 19 to 21, this delegation supports the proposal to convene a dedicated in-person inter-sessional meeting on the development of new and emerging information technologies such as artificial intelligence and quantum computing and their potential impact in the context of international security as mentioned in paragraph 21. We believe that the session will not only provide us with more understanding of these technologies but will also enlighten us with possible regulatory responses at both state and international levels. In paragraph 20, we share the view expressed by several delegations that the addition of neutralities in the second and fourth lines brings more ambiguities as it is unclear to us whether the paragraph seeks to speak of the neutralities of the technologies or of the information shared. Therefore, we suggest the deletion of the word neutralities in this paragraph. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Vietnam. Belgium, to be followed by Fiji. Belgium, please.

Belgium

Mr. Chair, let me first thank you and your team for drafting and updating this APR REV.1. My country aligns with the statement delivered by the EU. We wish to stress the following elements in our national capacity. We share the view that this draft is a good basis for our negotiation, but it needs further improvement. We appreciate the approach you took in building upon and ensuring continuity with previous APRs, and the balance you have sought to reach between the various views expressed this year. First, we would like to make some transversal comments. We support the language on gender, which would be stronger in PARA 7 and 16. We also support PARA 5 on stakeholders. The REV.1 lists many proposals for informal inter-sessional meetings. With those extra inter-sessional meetings, it would be helpful if you could put forward a potential timetable and agenda of the inter-sessionals in order to better organize ourselves. My delegation proposed that the APR.2 set clear priorities for our upcoming works next year. The aim of the 6th and 7th sessions should give Member States a greater level of granularity on threats, international law, and RID. With such a roadmap, we believe that we could make greater progress in our common understanding. On the threat section, cyber threats have intensified and evolved significantly since last year. In the context of the use of ICT in conflicts, in contradiction with the framework of responsible behavior in cyberspace, we reaffirm our solidarity with Ukraine and the Ukrainian people. Keeping in mind the evolving nature of cyber threat and the rapidly evolving threat landscape, we cannot stress enough the fundamental character of the threat pillar of our group work. In this respect, we welcome the updates in the threat section. In PARA 10, my delegation supports strongly the reference to ransomware, the emphasis on threat to critical infrastructure. On PARA 10 base, we support the Dutch proposal on sectors and the need for further work on new technologies, AI, and quantum computing in PARA 14 and 21. We particularly find important the inclusion of language on the threats to political and electoral processes, as well as language on the evolving context, such as increasing use of ICTs in armed conflict and against humanitarian organizations. We believe that they must remain in the report. We also support the proposal of Germany on spillover effects and on ransomware, also proposed by the Republic of Korea. However, we have reservations on the formulation of PARA 10 quarter, especially regarding misinformation and data security. In that respect, we support the proposal made by Croatia and Australia. We also welcome in PARA 15 the proposal to continue our discussion and understanding on a repository of threat on ICT security, which should remain in the draft and could be envisaged as a CBM. We count, Mr. Chair, on your able leadership to lead us further in this important section of our work. We must build greater convergence and move towards a greater level of granularity next year in our approach to cyber threats. In this respect, we welcome your proposal to discuss possible cooperative measures and to convene a dedicated experts meeting on the development in new technologies. Thank you.

Ambassador Gafoor

Thank you, Belgium, for your statement. Fiji to be followed by Chile. Fiji, please.

Fiji

Good afternoon, Chair and colleagues. Chair, please accept Fiji’s deepest thanks and appreciation for your decisive leadership and the hard work of your team. Fiji supports your call in ensuring that we make the necessary small steps this week and to assist the Secretariat in its efforts for another revised draft this Wednesday. To demonstrate our support, Fiji would like to add its voice regarding the provisions that are currently being discussed. Firstly, Fiji, like other delegations, reaffirms and supports the text amendment to Paragraph 3 to state that with regards to the UN Charter being applicable in its entirety. We support existing language regarding Paragraph 7 on the participation of women and the gender perspectives in Paragraph 16. With regards to Paragraph 10, Fiji welcomes the amendment by Germany on the cross-border spillover effect. Regarding Paragraph 10bis, Fiji supports the amendment proposed by Malaysia, which we agree will facilitate the energy and financial sector as proposed by the Republic of Korea and Bangladesh respectively. The importance of protection of critical infrastructure as proposed by the Netherlands is also supported. With regards to Paragraph 10.4, we support the recommendation by the Netherlands and Australia and also supported by other states regarding the consensus language to be adopted. Chair, we support the existing language on Paragraphs 15 and 17, and we welcome further focused discussions to ensure that all states are on an equal footing. Finally, Chair, with regards to Paragraph 21, we welcome such meetings to build further common understanding, including in the highlighted areas. We support the recommendation by Colombia for the intersessional meeting, whereby states who have been impacted by cyber attacks can share their experiences. We also support the recommendation by the EU for the timetable with regards to the scheduled date so that we can prepare for the same. And we support the recommendation by Australia for the standardization of references and the scope of reference to these meetings throughout the document. Finally, Chair, as always, Fiji is eager to work with all states and stakeholders throughout the week to ensure that we all adopt a consensus document with tangible and action-oriented outcomes, including the Program of Action. Thank you.

Ambassador Gafoor

Thank you, Fiji. Chile, you have the floor, please.

Chile

Mr. Chairman, as this is the first time that we’re taking the floor, my delegation would like to express our gratitude and appreciation for your work, the work of your team, and the Secretariat of the Office on Disarmament Affairs, the UN, as well as for the version, this draft of the second annual report. Generally speaking, Mr. Chairman, this document appears to be a good text. It’s well-balanced, geared towards action, and includes important elements such as, for example, the gender perspective, human rights, and participation of multiple stakeholders, inter alia. We believe this is a good starting point for our discussions, and we share the hope that this text can be approved by consensus at the end of this week. To be brief, we’ll just make a couple of specific comments. As far as the overview, we support the proposal of Colombia to include a reference in paragraph 3 on international humanitarian law, which could mention the report of the Group of Governmental Experts of 2021. International humanitarian law is part of international law, which is why its mention is justified and necessary. We also appreciate the contents of paragraphs 5, 6, and 7 with regard to the inclusion of multiple stakeholders, the role of regional and sub-regional organizations, and the participation of women in decision-making processes that various delegations have referred to. With regard to the section on threats, we appreciate the inclusion of ransomware, since this is a real and concrete current threat and it affects all regions, including Latin America and the Caribbean. It puts at risk the security of people and countries. Bearing that in mind, we support the proposal of Costa Rica on this point. We also appreciate and would like to highlight the references made regarding malicious activities in the framework of ICTs that target and impact critical infrastructure – critical information infrastructure and the supply chains. However, the mention of supply chains, phishing, ransomware, and others should not be in paragraph 10-4, since this refers more to the topic of disinformation. On this topic, its inclusion might not have a direct relationship to the subject that we’re dealing with in that paragraph, which is why we doubt that it should be included there. We support Germany’s proposal in paragraph 10 regarding the indirect cross-border effects on states that are not involved in conflict. This reference is important, since it precisely reflects the impact and threat of malicious activities in cyberspace as far as international security is concerned. As far as paragraph 15, we support the idea of developing a voluntary repository on threats. However, we would like to highlight the importance of also considering already existing mechanisms at the global level on this topic. With this in mind, we would like to highlight the important and valuable work carried out by multiple stakeholders, including the private sector, academia, and civil society, in evaluating the panorama of both current and future threats. Lastly, we agree that we need to have an intersessional meeting mentioned in paragraph 21, and we hope that at that session there could be an important participation of all stakeholders. Thank you very much, Mr. Chairman.

Ambassador Gafoor

Thank you very much, Chile, for your statement. There are two other speakers, and we are getting close to six o’clock. I’ve also received an indication that there is a request for a right of reply. So, in accordance with the rules of procedure of the main committees of the General Assembly, I’d like to now call upon the Russian Federation to make its right of reply at this point. Russia, you have the floor, please.

Russia

Mr. Chairman, colleagues, the Russian Federation is forced to once again take the floor to react to the anti-Russian statements that we heard today by various delegations. As I have already noted, such pathetic attempts to politicize our discussion are a manifestation of the lack of respect for the work of this group, for its mandate, and for the participants of the negotiating process. In fact, those who make such statements are stealing valuable time from us. The Russian Federation categorically rejects the insinuations against it on the Ukrainian topic. We recommend NATO member states and all those who dutifully follow the ideological mandates of Washington and Brussels to think about their role in what is taking place. You have abetted the criminal Kiev regime. Your hands are covered in blood, the blood of peaceful citizens who die every day from NATO’s shells. My colleagues in the specialized platforms of the United Nations will provide a more detailed answer to you. As far as the use of ICTs, well, to describe Ukraine as a victim of cyber aggression is hypocritical. Russia has systematically been the target of ICT attacks from the territory of that state. And we’re talking about DDoS attacks, theft of personal data, replacement and substitution of media content. It’s quite indicative that covered by the Russophobic rhetoric of the Zelensky regime, who’s operating behind that cover, are mainly criminals who are acting in their narrow interests. According to the statistics of one of the largest Russian banks, 80 out of 100 cases of phone machinations or phone illegal activity originate in Ukraine. We also have to mention here the support provided by NATO countries to Ukraine on the pretext of strengthening its cyber security. A whole section, a whole unit, is sent to that country to coordinate and train hackers who attack the Russian information infrastructure. It’s ironic, but in the near future, the cyber criminals who will return to Europe or to the United States will then start to steal money from their own taxpayers and will engage in criminal activity. We’re already seeing this kind of trend. In particular, I’d like to highlight something in connection with the official statements of NATO leaders in favor of protecting the freedom of cyberspace. Your words have nothing to do with the real situation as usual. Just a month ago, legislators of the House of Representatives in the United States once again accused the FBI of actually blocking, using Meta and Google and others in limiting certain accounts and in limiting their freedom of expression, and in fact, in violating the First Amendment of the Constitution. Just to sum up, I would like to recommend to countries whose delegations have made Russophobic statements to very carefully examine from a legal and ethical point of view their policies in cyberspace before expressing opinions on the activity of other states. Mr. Chairman, my statement also applies to possible future anti-Russian statements during this session of OEWG on the Ukrainian topic. Thank you for your attention.

Ambassador Gafoor

Russian Federation, your right of reply is well noted. France, it’s almost six o’clock, and I have two more speakers. As much as I would like to give the two remaining speakers the floor today, I’m afraid that we’ll have to wrap up for today. But before we do so, I wanted to say that what we have done today, of course, is to launch into a discussion on the first two sections of the draft annual progress report. But we have quite a few more sections left, and tomorrow morning it is my intention that we begin with section C and section D relating to rules, norms, and principles, as well as international law. So it’s my intention tomorrow to hear discussions on these two sections, and it is also my hope that in the afternoon we will take up section E on confidence-building measures and section F on capacity building. So that is my plan and hope for tomorrow. Now, this very much depends on delegations being as succinct as possible, and I really count on you to be as brief as possible in making your interventions. If everyone were to keep to three minutes or around three minutes, then I think it’s possible for us to get through the different sections by the end of tomorrow. Since today was the first day, I haven’t been very strict with the timing of your statements, and I do recognize that you also have some general comments to make. So in that sense, the discussions today have been very, very useful. But tomorrow we have to be very, very focused, and I hope that you will help me in that regard. Second, I don’t want to make any summary for today, but I want to say that I was very encouraged by the fact that all of you have said that you do want to work towards the adoption of our second annual progress report and have it adopted by consensus. That is very encouraging, and of course, in order to have that report adopted, we’ll need to find agreement on a range of issues. So we have just begun the first two sections, so there’s much more work to do. But I would like you to keep in mind that stating and perhaps articulating your own position and hoping for that to be included in a way that excludes the preferred position of other delegations is not the best route to go to consensus. I think there was some degree of restating of positions and preferences on a range of issues by a range of delegations, and that still means that there is a gap in how we may have to address the issues in the overview as well as in the threat section. But what is clear to me is that the structure of the report, of the second annual progress report, is something that has to be maintained because it’s a structure that follows the structure of the first annual progress report, and I’m not sure that at this stage of our discussions we can radically revise the structure. So I would also advise delegations to focus on how we can improve the draft annual progress report without altering the structure of the report. So I welcome very much the different suggestions that have been put forward today, and I will do my best to see how we can reflect as many of them as possible in order to take another step forward. But there are also those of you who have said that this draft is a good step forward towards achieving balance, but at the same time, there were also those of you who have said that it’s a good step forward but it’s not as balanced until some of your own views are reflected. So that’s my predicament. I don’t have any solutions at this point. We’ll have to go through the whole draft, a first reading of the whole draft, and we’ll have greater clarity hopefully at the end. And since all of you have been very good and very nice and very constructive, I’d like to invite all of you to a drink. I am hosting a reception this evening at the Singapore Mission, and all of you are invited to the reception at 6:30 at the Permanent Mission of Singapore, 318 East 48th Street. It’s also a chance for each one of you to interact with each other. You’re welcome to the reception, have a drink, and have something to eat. But do make an effort to reach out and talk to other people rather than talk to members of your own regional group. I know you love each other very much. You give each other great comfort. You echo each other. You are so like-minded with each other, and that is the value of regional groups. But I would also urge each one of you to step out of your comfort zone, step out of your bubble of regular interactions, and talk to people in order to reach out and understand what others want out of this process because ultimately it is not your own position or the position of your own group that will determine consensus, but it’s how we bring together a diverse range of views and positions and how we can find that balance that will determine whether we have an outcome at the end of the week. So with those comments, thank you very much. My thanks to the interpreters for giving me some additional time, and see you at the reception. The meeting is adjourned. Thank you.

Leave a Reply

Your email address will not be published. Required fields are marked *