Ambassador Gafoor
Excellencies, distinguished delegates, the first meeting of the sixth substantive session of the Open-Ended Working Group on security of and in the use of information and communication technologies, established pursuant to General Assembly resolution 75/240, is called to order. Distinguished delegates, I extend a very warm welcome to all of you attending this meeting in person, as well as those who might be following this online. I’m very energized by the palpable sense of enthusiasm and excitement prevalent in this room this morning, as many of you have traveled back to New York from your capitals. Also, experts in New York are back in the meeting room, and I can sense that many of you are reconnecting with new friends and old friends. I think this bodes very well for our work this week. I’d like to begin by acknowledging the presence of Mr. Adedeji Ebo, Director and Deputy to the Under-Secretary-General and High Representative for Disarmament Affairs at the United Nations, and I propose that we begin by giving him the floor to hear some opening remarks. Mr. Ebo, the floor is yours.
Adedeji Ebo (Director and Deputy to the High Representative for Disarmament Affairs)
Thank you. Mr. Chair, distinguished delegates, ladies and gentlemen, good morning. I am pleased to address the Open-Ended Working Group on security of and in the use of information and communication technologies. The High Representative for Disarmament Affairs, Izumi Nakamitsu, regrets that she cannot be here and sends her best wishes for a productive session. She is actually traveling at the moment. In July of this year, I had the privilege of offering remarks to this group at its fifth session. I reflected on the progress achieved by the group since its inception in 2021. I acknowledged the many rich exchanges, action-oriented proposals, and constructive engagement that have defined its success. Since then, the consensus adoption in July of a second annual progress report further crystallized the achievements of this group. Allow me to highlight a few aspects of the report that are especially noteworthy. First, the second progress report includes a clear roadmap for discussions over the next year, including dedicated intersessional meetings on capacity building and on strengthening measures to protect critical infrastructure and to ensure the integrity of the supply chain. Second, the group adopted clear modalities for the operation of a global point of contact directory to facilitate communication between diplomatic and technical authorities, including in the event of a significant ICT incident. Third, the report lists an initial set of confidence-building measures, such as those related to information sharing, which represent a solid basis for further consideration and elaboration, including at the regional and sub-regional levels. Fourth, in support of states, the Secretariat was called upon to undertake various tasks, including preparation of a mapping exercise on the landscape of ICT security capacity building at the global, regional, and sub-regional levels. UNODA looks forward to publishing this report ahead of the next session of the working group in March 2024. We hope it will serve as a useful resource for states and other stakeholders in formulating capacity building activities that are more effective, efficient, and sustainable. Fifth, and equally important, is the report’s sober assessment of the ICT environment. States acknowledged that not only is the use of information and communication technologies in future conflicts becoming more likely, but such technologies have already been used in this context. I also welcome states’ recognition of the increase in malicious ICT activities impacting on critical infrastructure that provides essential services across borders and jurisdictions, such as the healthcare, maritime, aviation, and energy sectors. Sixth, this recognition is very much in line with the Secretary-General’s prioritization of protecting human life from malicious cyber activity. In this context, I take the opportunity to recall that in his policy brief on a new agenda for peace, the Secretary-General encourages states to refrain from targeting infrastructure essential for public services and to the functioning of society. The particular vulnerability of such infrastructure, from water to energy to sanitation, is indisputable. And finally, I commend the progressive language contained in the report on the need to integrate a gender perspective into efforts tackling cyber security threats. Such an inclusive approach increases the chances of reaching transformative and effective solutions. All this is to say, there is much to applaud and much for which we can indeed be proud. But let us not underestimate the work that still lies ahead. At a time when multilateral consensus is more often the exception than the norm, maintaining positive momentum is anything but guaranteed. Mr. Chair, distinguished delegates, the sixth substantive session marks the midpoint of the group’s mandate. With five sessions behind you, and another six, including this one, to go, the stakes will surely continue to rise. The peace and security challenges we face will not diminish, so neither must our resolve to address them. In particular, I would encourage delegations to redouble efforts to build convergence on the issues that seem farthest from consensus. I would highlight two areas in this regard: building common understandings on the applicability of international law, and unpacking questions on the sufficiency and implementation of rules, norms, and principles. First, on international law, as is often repeated, there is no longer any doubt that it is applicable and essential to a secure, stable, and peaceful ICT environment. Focused discussions on applicability of legal principles, such as sovereignty and sovereign equality, the peaceful settlement of disputes, and non-intervention, among others, to the ICT domain have proven invaluable. Moreover, there have been consistent calls for the sharing of national views on applicability of international law, and for additional capacity-building activities in this area to ensure all states can participate on an equal footing. Building on this progress, further clarification of the application of international law, including international humanitarian law, to the use of ICT by states would go a long way in supporting a peaceful ICT domain. Second, on norms. States have made tremendous progress in developing a normative framework of responsible state behavior, but there is scope to make further strides. Commitment to implementation of this framework by all states is clear. To take forward this commitment, there have been many proposals, including voluntary surveying of national implementation and development of additional guidance, such as checklists. These and other proposals are worthy of enhanced pursuit so that the norms are not just commitments in theory, but also in practice. In tackling implementation of existing norms, states may also consider the question of the need for additional norms, rules, and principles. Taken together, these efforts will undoubtedly bring us all closer to the goal of safeguarding the peace and security of the ICT environment. The UN Office for Disarmament Affairs remains your steadfast partner in these endeavors and looks forward to working closely with all delegations. Thank you for your attention, and I wish you a productive session. Thank you.
Ambassador Gafoor
Thank you very much, Mr. Abel, for your statement. At this stage, I’d like to offer some remarks of my own as Chair of the process. Let me say that I’m very happy to be here this morning, and once again, I extend a very warm welcome to all of you. It’s really good to see so many familiar faces in the room and also some new faces or new friends who have just been appointed or who have just joined the process. For those of you who are new, congratulations. This process is a challenging one, but I think a very meaningful one as well, and I look forward to working with you, the newly arrived ones, but also those who have been involved in this process for some time. Today marks the start of the third annual cycle of the OEWG, and as Mr. Abel said earlier, we are exactly at the midway point of our mandate, and in that sense, we are entering the second half of the OEWG’s work. As we are at a midway point, I think it’s important for us to reflect on where we are as a process and what is it that we can achieve over the next two years. Now, over the last two years, I think we have taken some very important steps forward by adopting our first and second annual progress reports in July 2022 and this year, July 2023, and these reports were adopted by consensus. Now, these annual progress reports have, in my view, advanced meaningful cooperation and outcomes with tangible benefits and implications for international peace and security in the ICT domain. When we first began our work two years ago, some of us who have been involved right from the beginning, as we look back, perhaps we might think that we did not expect to have come this far, but we have, and this is the result of your commitment individually and your commitment collectively to travel the distance. The outcomes we have achieved include the decision to establish the global points of contact directory, which I hope will soon become a reality by the middle of 2024. Even as we speak, I think the Fifth Committee is looking at the budgetary implications of the decisions we have made. Overall, what we have been able to achieve so far as a working group has been significant and meaningful, but apart from the very concrete decisions we have taken and the steps we have taken, my sense also is that the OEWG has built a sense of camaraderie, a sense of community, and through this process, I’d like to think that we have also helped to build or rebuild some level of confidence and trust among our delegation. As in any UN process, and there are so many at the UN, I can tell you, there will bound to be differences of views, deep divisions, and geopolitical tensions, but the idea of a UN process and the idea of this OEWG is to provide a platform for dialogue, discussions in order to arrive at common ground. And in that sense, the real value of the OEWG, looking over the last two years, is that it has itself performed, I think, fairly well as a confidence-building measure. And this is something that we have all acknowledged and even reflected in the annual progress report in the sense that we recognize the value of the OEWG itself performing the functions of a CBM. But the process, as well as the outcome from this process, have been possible because of the very active engagement by all of you, the sense of purpose and sense of dedication that each one of you have brought to the process, but also the flexibility shown by all delegations. So as we begin the third cycle, I am not taking anything for granted. I want to express my gratitude to you and your delegation for your role, for your contribution, and for your constructive engagement to this process. Given that we have about two years left, our work in this process is far from complete, and from my informal consultations with delegations, I understand that you continue to have many priorities and ideas and proposals that you want to bring into the OEWG. The ICT domain is a rapidly changing domain, and technology continues to advance, and we therefore, in this working group, cannot sit still. It is my duty to all delegations and to the international community to ensure that we continue to make progress on the outstanding issues across all areas of our mandate. So now is not the time to sit back and be satisfied with our achievements. We have not reached cruising altitude. We need to gain elevation. We need to gain further altitude before we prepare for descent in July 2025. So this is not the time to take the easy way out by repeating well-known debates, well-known positions, or insisting on a particular point of view. If we want to make progress, all of us have to be ready to engage and demonstrate flexibility. I’ve said before that the OEWG is not a debating club. I think there’s a certain value in debates, especially when we have deeply different views, but we also have to ensure that the debates we have lead to some understandings and some decisions. Over the past two years, I think we have collectively built up a baseline of trust and confidence, and I think there is a good, constructive, and positive working dynamic within this working group. And I can tell you that as the PR of my country at the UN, who spent some years in New York, I’ve been part of many, many UN processes, and I sincerely believe that the atmosphere and the working dynamic within this working group is a positive one. And so we need to build on the momentum, and we need to seize the opportunity to make progress this year. I now would like to take some time to go section by section to share some of my personal experiences and take stock of where we are in our work on each of the pillars of our mandate. And these are just my personal views, and of course, I will be guided by your views as I listen to your discussions later this week. First, on existing and potential threats. I think we need to continue our work studying the threat landscape. Our discussions in this chapter have been very productive so far, including by identifying some new threats in our second annual progress report, which is the first time that we have been able to identify some very concrete emerging threats in a UN report. And so the work under this chapter is important because our understanding of the threat landscape informs the rest of our work, because it is precisely because of the threat landscape that we need to do certain things collectively as an international community to respond to that threat landscape. And in that context, given the changing technology, the discussions under this pillar will have to be a continuous one because the threat landscape also evolves continuously. And I should say that in discussing the threat section, the idea is not to point fingers at anyone as being a source of the threat. I think we should put aside those concerns and anxieties as to whether the threat section could lead to a finger-pointing exercise. The idea of a discussion on existing and potential threats is to raise awareness of the international community as to the challenges and the threats facing us collectively, and therefore, what is it that we need to do collectively to respond to these threats, to manage these threats, to build awareness, and build capacity to deal with those threats. I think it is in that context that we should look at the discussions in this section. Second, on rules, norms, and principles for responsible state behavior. There are two main areas where we could focus on. First, we need to intensify our efforts to implement the agreed norms of responsible state behavior. And the agreed norms are a central component of the cumulative and evolving framework, and they will contribute certainly to international peace and security if we are able to implement them. We have them, the agreed norms, and we need to implement them. Now, in this regard, I want to draw attention to the recommendation in the second annual progress report for states to elaborate additional guidance, including a checklist on the implementation of norms, taking into account previous agreements, and for the chair to produce an initial draft of such a checklist. And to facilitate my drafting of this checklist, I would welcome input from delegations in your statements when we get to the discussions later, as well as written inputs on what elements should be included in such a checklist. I’m aware that various states, regional groups, and stakeholders have also produced versions of such implementation checklists for your own use. And if you wish to share these checklists with the chair as your contribution to our global effort, that was also much appreciated. And based on the input I received, I hope to be able to share an initial draft with delegations for consideration early next year before the next substantive session. Now, at the same time, we must also redouble our efforts to develop our common understandings related to rules, norms, and principles. I’ll be candid and say that we have made little progress in this respect so far. I think our discussions in this area have been dominated by perhaps an abstract debate between those states that want to develop new norms and those states that want to focus on existing norms but elaborate existing understandings and guidance within these norms. Now, if we continue with this debate in this fashion, there’s a good chance that we will not be able to make any progress. And this debate does not need to be an ideological one. We need to take a pragmatic approach because at its core, what all states do appear to agree on is the need to elaborate on what responsible state behavior means to the international community. In this regard, I call on all states with ideas, whether they come in the form of new norms or as elaborations of existing norms, to put forward your ideas, to put concrete and specific language suggestions on the table for discussions. And this will help move our discussions forward and give us an opportunity to build additional common understandings that hopefully will strengthen our cumulative and evolving framework. Thirdly, on international law, there are very strongly held views on all sides, particularly on the question of the need for additional legally binding obligations. However, it is important to remember that in a consensus process, and that is what we are engaged in in the OEWG, if delegations simply reiterate their well-known positions, it is not going to be possible to make progress. In other words, if you state your preference and your desired outcomes, we will end up repeating well-known positions again and again. But if we want to make some progress, we need to start thinking about what is the best way we can reach some common ground on this difficult issue over the next two years. And regardless of where you stand on the substantive questions relating to international law, my sense is that there is generally a willingness to engage constructively in this discussion. This is what we have seen over the last two years. My sense is that every state or every delegation wants to have greater clarity and better understanding about how international law applies in the ICT environment, even if we may disagree on what form these understandings should take. So I call on all delegations to consider what progress in our understandings we can make that would be equally useful, regardless of whether we are working towards a legally binding instrument or whether we are aiming to apply existing law. Additionally, we should make it a key priority to ensure that participation in our discussions on international law is as universal as possible, so that all states have an opportunity to make their views heard and play a meaningful part in the discussions. A clear understanding on how international law applies, whether in the form of additional binding obligations or on the basis of existing international law obligations, will only have credibility and legitimacy if all states have a sense of ownership in its development. Now, in this regard, I reiterate the call in the Second Annual Progress Report for all states in a position to do so, in particular those who have been advocates of this particular issue, to consider how you can share your expertise with others that want to participate more actively but are perhaps unable to do so because of a lack of capacity, and what can we do here in the OEWG to facilitate capacity building in the domain of international law? To put it simply, I think we need to start debating and discussing what progress could look like in this very sensitive and difficult issue of how international law applies in the ICT domain. Fourthly, with regard to confidence-building measures, I think we can all agree that we have made good progress over the past two years. In addition to the creation of the global POC directory, we were also able to agree on an initial list of voluntary global CBMs. And these are very significant achievements, and we can take some pride in having decided on them. Our task now is to ensure the effective implementation of these initiatives so that what we have agreed is not just words on a page, not just annex to a report, but they are operationalized and they become alive in the national and regional context, and that they make a contribution in some way to international peace and security. With regard to the global POC directory, we have a lot more work to do, and in the second annual progress report, we agreed that we would continue discussions on, firstly, initiatives to encourage or expand participation in the global POC directory, and B, we also agreed that we would continue discussions on developing communication protocols, and C, ideas to enhance the effective functioning of the directory, and D, capacity building efforts aimed at enabling full participation in the directory. This last point is particularly important, because even if the global POC directory is to be operationalized, we want it to be operationalized in a way that is universal and inclusive, so that the directory does not just bring together a few countries with well-developed expertise in this field, but somehow does not include or, worse still, excludes many other countries who may not have the requisite capacity to participate meaningfully in this directory. So, there are a lot of areas in which we need to have further discussions in order to ensure the effective implementation and successful functioning of the POC directory, and I look forward to hearing your ideas later this week. The fifth point is on capacity building, and here we have a broad recognition that capacity building is an important confidence-building measure, and is a cross-cutting topic that connects all the pillars of the OEWG’s work, and I think this was an important outcome from our discussions over the last two years, that capacity building itself is a CBM. Given the transboundary nature of ICTs, our efforts to ensure international peace and security are only as strong as the weakest link, and even as we continue to make progress on developing the cumulative and evolving framework, we need to ensure that every state has the capacity to implement what we have already agreed, and we need to consider what can be done at the global level to facilitate these efforts and to consider concrete proposals in this regard. And here, delegations will recall that the Second Annual Progress Report called on states to continue to discuss the proposal for a global cybersecurity cooperation portal, and here I want to thank India once again for the initiative in putting forward this proposal, and I also call on all other delegations with concrete ideas to put them on the table, but also to engage in discussions such that we can build common ground, we can maximize synergies and leverage on existing initiatives, but at the same time find a way to build common ground here at the UN so that the UN too can play a role to get us to where we need to go in the area of capacity building. I also draw your attention to the request in the Second Annual Progress Report for the chair to convene a global roundtable meeting on capacity building, and in line with the request in the Second Annual Progress Report, my intention is for the global roundtable to take the form of a high-level meeting bringing together state representatives, capacity building practitioners, and stakeholders, of course, for a deep conversation on what needs to be done at the international level to ensure that every state is able to build the capacity it needs. I had previously informed delegations in a letter that the global roundtable would take place on the 10th of May 2024, and I will provide delegations with further details earlier next year, but I would also like to hear your views this week on how we can best organize this global roundtable to attain our objectives. And here I want to stress with regard to capacity building that it is important that we attach urgency and priority to this issue, and the global roundtable is one platform for us to have a very deep and dedicated discussion. And we need urgency and priority in our discussions on capacity building for a simple reason, which is that capacity building cannot wait. We have spent the last two years discussing a range of issues. I think there is enough common ground on capacity building that allows us, and in fact that requires us, to start moving to implementation. So, we need to make capacity building happen right away, and we need to take advantage of the global roundtable by making it action-oriented, practitioner-oriented, stakeholder-inclusive. To put it simply, we need to stop talking about capacity building. We need to start making it happen. Now, let me move on to the next issue, which is regular institutional dialogue. In the second annual progress report, we took a small step forward with the adoption of some common elements for the future mechanism. At the same time, delegations also continue to develop and advance different proposals with regard to regular institutional dialogue. I’ve said before that I’m committed to ensuring that all delegations with proposals have as much time as required to develop the ideas within the OEWG, including during the two dedicated intersessional meetings which are mandated in the second annual progress report, in order to discuss proposals from regular institutional dialogue, including the POA, Program of Action. In this regard, I encourage delegations with proposals to see how you can take on board a green common element in your proposals. And at the same time, we should draw on ideas from delegations’ proposals to elaborate additional consensus common elements. And it is my hope that through this iterative two-way process of discussion and evolution that we will be able to find consensus on the question of regular institutional dialogue and the form of the future mechanism. It is really important, I think, that all delegations use the OEWG as a platform to build common ground on this very, very difficult issue of regular institutional dialogue and the shape of the future mechanism. My own sense is that a consensus is possible. A common ground is possible with regard to establishing the future mechanism. There are ideas on the table. We need to discuss how we can bring the different ideas together and find a way forward. And it is best that we do it in the open-ended working group, because that would enable us to build consensus. Excellencies, dear friends, let me end by calling on you to make full use of this opportunity to have a productive week. I look forward to working with all of you, but also meeting with all of you as well informally, either bilaterally or in different groups over the next few days. And as we begin this third cycle, once again, I’m full of appreciation for the very positive and constructive tone that prevails in this working group. Now, let me also take this opportunity to remind you that this evening I’ll be hosting a welcome reception at the Singapore Mission, the details of which have been made available in a letter that I sent to all of you. And all of you present in this room are invited. It will not just be a confidence-building measure, but it will also be an occasion to have something to drink and eat in a relaxing atmosphere. Let me stop there, and I apologize that the remarks have been longish, but I wanted to share with you my own thoughts right at the beginning of the third cycle. And of course, these are my personal views as chair of the process. You don’t have to agree with any of them or all of them, but I hope that this would have inspired you to reflect on your own positions. And I look forward to hearing from all of you as we go through the work program this week.
Colombia
Mr. Chairman, we are grateful for your efforts and leadership in conducting the work of our working group on our schedule of meetings and also on the informal dialogue by stakeholders and for preparing this meeting. We’re also grateful for the valuable comments of Mr. Adegeyebo and the work of the Secretariat. Excellency, we reiterate Colombia’s support for your work, and we are ready to continue to participate constructively in the process of this working group. Mr. Chairman, we begin by highlighting the adoption by consensus of the second annual report, and we are convinced that the implementation of its recommendations is a collective task which benefits from the support and contribution of many stakeholders. We highlight the contributions made during the informal dialogue of the 6th of December. We have taken note of your proposals and comments, and we will take the opportunity of this meeting to echo them. Mr. Chairman, in response to your question as to whether there are new developments or trends in terms of existing or potential threats, we have the following comments to make. Number one, new and emerging technologies, in particular artificial intelligence and quantum computing, are expanding opportunities for development. However, their properties and characteristics are constantly evolving, and this creates new vectors and vulnerabilities which can be exploited for malicious activities and the use of ICTs and possibly affect international security. Thus, we consider it important to discuss these two matters in more depth. We think it would be useful to hear the experience of states which have done risk assessments of these technologies and on best practices on the development of artificial intelligence systems which allow it to be designed and deployed in a secure manner. Number two, as mentioned in the second annual progress report, the APR, there are concerning trends, in particular ransomware, which continues to be the most disruptive and common form of these uses. On the 12th of September, several Colombian state institutions suffered the consequences of a cyber incident aimed at the IFX network, a company which offers communications and digital platform services in various countries. There are other incidents. We increasingly see that states are constantly exposed to existing and potential threats which can have an impact on critical information infrastructure, on supply chains, and on the general availability of integrity for the internet. Capacity building is a fundamental aspect of the work of this working group. The capacities of states will determine the way in which they can implement responsible norms of behavior on the use of ICTs that we have agreed on to meet current and future challenges in this domain through a robust and institutional framework as well as CBMs. Mr. Chair, I will refer to your question about some of the potential initiatives that could be developed globally in order to increase awareness and to deepen understanding of existing and potential threats and later on to develop and implement cooperative measures to meet those threats. On this subject, I’d like to reiterate our support for Kenya’s proposal to develop a repository to include voluntary information from states with regard to threats and vectors in the use of ICTs in the context of international security. The repository would contribute to a deeper understanding of potential risks and their impact to improving the resilience of security and information systems and of the data in view of cyber threats. Colombia believes that the contributions of civil society, academia, and the private sector for the repository are key to a holistic understanding of the threats. This repository should also have factual and descriptive information, so it would not be for purposes of attribution but rather for the exchange of updated information on threats, taking into account the evolving nature of the ICT landscape. This repository would scale up the development and implementation of cooperative measures to meet the threats. Taking into account that there’s no consensus yet on creating this, Colombia believes that by implementing CBMs contained in the second APR, in particular numbers two and three, it would be possible to move forward on exchanging voluntary information on the subject. Mr. Chair, a deeper discussion on potential new and existing threats is intrinsically linked to the establishment and capacity building for states. The establishment of a permanent capacity building mechanism would be an essential measure to address the threats. You have very wisely said so this morning. Capacity building cannot wait. The contribution and support of the many stakeholders is valuable and can be leveraged in order to maintain a free, open, secure, technologically neutral, interoperable, and peaceful cyber digital domain is a common objective and a shared commitment. Thank you.
Ambassador Gafoor
Thank you very much, Colombia. Russian Federation, to be followed by Uruguay. Russia, please.
Russia
Mr. Chair, colleagues. Amid growing geopolitical tensions, the risk of interstate conflicts stemming from the use of information and communication technologies for purposes contrary to the UN Charter is coming to the fore. This is mainly due to the possibility of a disproportionate use of measures of response to threats. In view of the anonymity of the information space, false flag computer attacks aimed at holding other states responsible also pose a serious danger. In the absence of a universal methodology for identifying perpetrators, criteria for classifying computer attacks as armed attacks, and principles for studying computer incidents, making any political decisions in the domain of ICT use may pose additional risks to international peace and security. We believe that the global community needs to carry out an in-depth discussion and analysis of all the factors contributing to the escalation of threats and measures to counter those threats. As a basis for such a discussion, we propose that the following list of threats be considered in the information security domain and factors influencing them. Based on the concept of the UN Convention on International Information Security submitted by Belarus, the DPRK, Nicaragua, the Russian Federation, Syria, and Venezuela as an official document of the 77th session of the UN General Assembly. First, the use of ICTs by states in the military, political, and other spheres in order to undermine or infringe upon sovereignty, violate territorial integrity, and social and economic stability of sovereign states, interfere in the internal affairs, as well as to commit other acts in the global information space which impede the maintenance of international peace and security. Second, carrying out computer attacks against the information resources of states, including critical information infrastructure. Third, monopolization of the ICT market by individual states and/or with the assistance of private companies through restricting access for other states to advanced ICTs and increasing those states’ technological dependence on states that dominate in the field of information, thus increasing the digital divide. Fourth, unsubstantiated accusations brought by some states against others as to organizing or carrying out wrongful acts with the use of ICTs, including computer attacks. Fifth, the use of information resources under the jurisdiction of another state without the approval of the competent bodies of that state. Sixth, placement of free-to-access tools for computer attacks, instructions on methods of their organization, and development of practical skills for the use of such tools in information spaces of other states. Seventh, the use of ICTs to the detriment of the fundamental human rights and freedoms in the information space, primarily the right to respect for private life. Eighth, integration of undeclared capabilities in ICTs and the concealment by manufacturers of information regarding the vulnerabilities of their products. Ninth, use by states of their information infrastructure to commit internationally illegal acts or the use of proxies, including non-state actors, to commit such acts. Tenth, disseminating information through ICTs, which is detrimental to the socio-political and socio-economic foundations, spiritual, moral, and cultural environment in states or threatening the lives and safety of citizens. Eleventh, challenges in identifying the source of computer attacks with precision due to the technological specificities of ICTs and the absence of institutional mechanisms ensuring de-anonymization of the information space. To counter these threats, it is necessary to work toward creating a global information security system under the auspices of the United Nations in accordance with the provisions of the UN General Assembly Resolution 77-36 and Draft GA Resolution on International Information Security, contained in A/C.1/78/L.11, adopted on November 2nd in the First Committee of the 78th session of the General Assembly. Such a system should be based on compliance with the principles of prevention and peaceful settlement of international disputes, sovereign equality of states, and indivisible security. For it to function effectively, it is necessary to develop an appropriate international legal regime. Special attention should be given to the issue of protecting personal and other data. In our view, it makes sense to identify and approve the principles for obtaining, storing, and processing personal data for all UN member states. This step will significantly increase the level of protection of personal data in the relevant cross-border exchanges and will contribute to the development of national legislation on personal data protection. Thank you very much.
Ambassador Gafoor
Thank you, Russian Federation. Uruguay, to be followed by the United Kingdom. Uruguay, please.
Uruguay
Thank you very much, Mr. Chairman. Since this is the first time that I take the floor at this meeting, at this session, I take the opportunity to greet you and your team, and we wish you every success in the work of this substantive session. My country also recognizes the excellent work of support undertaken by the Secretariat at this time and at previous sessions. Chair, as has been stated previously, Uruguay grants special interest to the topics discussed in this group, and thus we value the work which has been done to carry forward its mandate. You have the support of my delegation. Malicious cyber activities undermine peace and security and international trust. They weaken development, in particular that of the Global South countries, and they reduce prosperity. Although digital transformation and the use of ICTs open up limitless opportunities for social and economic development, they also introduce new threats, vectors of attack, and vulnerabilities. Malicious cyber actions all over the world by state and non-state actors alike are increasingly sophisticated. Uruguay shares the concern expressed by several member states with regard to the vulnerability of sectors having to do with critical health infrastructure, security, and defense infrastructure given malicious activities and threats. In this case, we also consider it relevant to emphasize that artificial intelligence and its undue uses to develop attacks or to develop malicious tools is a growing threat, and it must be met decisively by members. Mr. Chairman, with regard to the main questions you have raised, my country views carefully the development of threats which have to do with ransomware. This criminal activity endangers the information security of our countries since it constantly blocks sensitive information for the exchange of the payment of a ransom, which in the case of developing countries is economically not viable. Cases increase by the day, and no country is free from an attack of this type. Thus, we must make progress in a joint defense in order to prevent and counter these threats. In this regard, Uruguay believes that through international cooperation we can meet ransomware more efficiently, and for that reason, capacity building, the transfer of technologies from countries which have better know-how to those which don’t have it, the exchange of best practices, and a robust set of confidence-building measures can offer the solution we so dearly wish. Mr. Chairman, as possible initiatives to meet the ICT initiatives, we value the progress that has been made with regard to the mapping exercise and the point of contact directory. We have cooperated with this in our region, Latin America and the Caribbean. However, these measures need to be strengthened through initiatives which place us all on an equal footing given the malicious use of ICTs. The international community needs to use available tools at the regional and multilateral levels in order to succeed. We value the efforts of the UN and the OAS. Governments must supplement our efforts with civil society and have a united front, a dynamic and multi-sectoral front. Mr. Chairman, finally, we must pay attention to the need to educate on prevention with regard to cyber security. The United Nations has a singular opportunity to offer a capacity to its member states on these capacities of prevention. Institutions such as UNIDIR must deepen their work, and we urge states in a position to do so to increase their voluntary contributions which are necessary for this purpose. Thank you.
Ambassador Gafoor
Thank you, Uruguay. United Kingdom, followed by Kenya. UK, please.
United Kingdom
Chair, we are all aware that artificial intelligence will touch all aspects of modern life and is already subject to a wide range of important national and international initiatives, including here at the United Nations. It has been only a few weeks since the United Kingdom hosted an AI Safety Summit, which recognized the importance of the safe development of artificial intelligence systems to deliver AI’s transformative opportunities. The summit recognized the need for collaborative, constructive action to address AI risk, including cybersecurity risk. This is a shared responsibility between states and stakeholders, particularly the private sector. AI has implications beyond international peace and security. When considering AI in this Open-Ended Working Group, we should remain within our mandate of security of and in the use of ICTs. We believe this means focusing on the cybersecurity of AI systems and AI’s impact on cyber capabilities. Cybersecurity is an essential precondition for the safety of AI systems and is required to ensure privacy, fairness, reliability, and predictability. As the use of AI systems in our societies grows, national cyber resilience will require good cybersecurity of AI systems. AI systems themselves are subject to novel cybersecurity vulnerabilities that can be exploited by malicious actors to induce specific behavior in the AI or manipulate its decision-making. The potential impact of malicious exploitation of such vulnerabilities will increase as AI is used in more and more critical applications. The UK advocates a secure by design approach to AI systems, where security is integrated into the development of the AI from the start and throughout the lifecycle of the system. This means AI developers in the private sector should consider the secure design, secure development, secure deployment, and secure maintenance of AI systems. These points are elaborated further in a recent publication produced by the United Kingdom and the United States with the support of a cross-regional group of national agencies from 18 states and the multistakeholder community entitled Guidelines for Secure AI System Development. Chair, my delegation will use the remainder of this statement to update the OEWG on the unacceptable attempts to use cyber operations to interfere in our democratic institutions and processes. These cyber threats are growing in depth, complexity, and speed. Last week, on 7th December, the United Kingdom and our international partners exposed a series of attempts by the Russian intelligence services to target high-profile individuals and entities involved in the UK’s political, democratic, and civil society institutions through cyber operations. This has been a sustained pattern of behavior over an extended period of time. The UK government judges that these operations were undertaken with the intent to use the information obtained to interfere in our political and democratic processes. We have identified a campaign operated under the direction of the Russian FSB targeting politicians, civil servants, journalists, non-governmental organizations, and other civil society organizations. We have identified activity ranging from spear phishing campaigns against high-profile parliamentarians, the hacking of governmental trade documents leaked ahead of the United Kingdom’s 2019 general election, the 2018 hack and leak of the UK-based think tank Institute for Statecraft, and the recent hack of the organization’s founder. Chair, unjustified and irresponsible attempts such as these to interfere with and to influence political and democratic processes are of significant concern. We urge vigilance and increased awareness of these threats as the United Kingdom is not alone in being exposed to such campaigns. We are grateful for the support from international partners who have stood with us in solidarity, and we urge all states to abide by and to practice the norms of responsible state behavior adopted by consensus at the General Assembly. Thank you, Chair.
Ambassador Gafoor
Thank you, UK. Kenya to be followed by the Islamic Republic of Iran. Kenya, please.
Kenya
Thank you, Chair. My delegation commends you, Chair, and your team for your continued efforts in providing the OEWG with an action-oriented program of work. Emerging technologies have opened a door for misuse of cyberspace by malicious actors as a result of their ambiguity, programmability, and data-driven nature. The increased adoption of Internet of Things devices has enabled a seamless, interconnected digital ecosystem, and as a result, the attack surface possibility has extended further. The use of malware, ransomware, distributed denial of services, and crypto-jacking attacks, which compromise container-based cloud systems, restrict access to services, expose restricted data, and enhance backdoor attacks, also pose increased risks and threats in cyberspace. The use of machine learning and robotics resulting in anonymity in cyberspace is an additional challenge. Misinformation, disinformation, and malinformation are among the greatest challenges that we are witnessing today as digital platforms have enabled rapid sharing of information. With the wide adoption and use of mobile money in Kenya, we have also observed an increase in financial phishing targeted at e-commerce and e-payment platforms for purposes of fraudulently obtaining user credentials and data. AI as a technology is being used in the proliferation of potent and complex weapons, which pose a major risk to civilians. Global collaborative efforts are necessary in addressing these threats, and the Open-Ended Working Group offers an opportunity for discussion on what platforms such efforts should take. The proposed Global Cyber Security Cooperation Portal could serve as a source of information, raising awareness, and deepening understanding of existing threats among states.
Ambassador Gafoor
Thank you, Kenya. Islamic Republic of Iran, to be followed by the Republic of Korea.
Iran
Thank you. We extend our sincere appreciation to the Chair, his team, and the Secretariat for their efforts in orchestrating the sixth substantive session of the OEWG on ICTs. As emphasized previously, a fundamental element in substantiating the fair and effective implementation of the OEWG’s consensus-based approach is the meticulous consideration of the perspectives put forth by Member States. It is imperative that these inputs are accurately and comprehensively reflected in the annual reports, a critical aspect that remains to be fully realized in a satisfactory manner. We trust and expect that moving forward, the Chair and the Secretariat will redouble their commitment to ensuring the thorough and faithful representation of Member States’ contributions, thus fortifying the credibility and inclusivity of the consensual working method within the OEWG. With that being stated, I am presenting the distinct perspectives of my delegation on the threat landscape concerning ICTs. A peaceful ICT environment plays a crucial role in promoting international security and stability. Achieving this goal demands a more holistic approach to addressing threats in the realm of information security, encompassing not just digital infrastructure but also the content and information itself. Some pressing and formidable challenges faced by Member States include: 1. Monopoly and hegemony in Internet governance. 2. Actions within the ICT environment aimed at violating national sovereignty, interfering in internal affairs, and undermining the political, economic, and social systems of other States, including through disinformation. 3. Threats or use of force against the sovereignty, territorial integrity, or political independence of any State within and through the ICT environment. 4. Unilateral coercive measures, including limitations and blocking in the ICT environment. 5. Excessive and politically motivated publication of attribution of attacks in the ICT environment. 6. Lack of responsibility among private companies and platforms. 7. Application of double standards in safeguarding cyber security. 8. Manipulation of ICT supply chains, including the implementation of backdoors to create vulnerabilities in products, services, and maintenance, compromising the sovereignty, data protection, and data security of target States. 9. Absence of a legally binding international instrument to regulate the behavior of States and other stakeholders in the ICT environment. 10. Imbalanced development of different areas of international law in the ICT environment, such as governance, cyber crimes, data protection, and data security. Lastly, Mr. Chair, in light of the ongoing failure of the host country to fulfill its legally binding obligations in promptly issuing visas for the representatives of Member States, it is crucial to acknowledge this shortcoming as a collateral threat to the OEWG in general and the concerned Member States in particular. Your intervention, coupled with the support of the Secretariat, is earnestly sought to address and resolve this issue conclusively. Your efforts in rectifying this matter are highly needed and deeply appreciated. I thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Iran. Republic of Korea, please.
South Korea
Thank you. I’d like to start by expressing my gratitude to the Chair for organizing the sixth substantive session of the Open-Ended Working Group. Korea hosted the third World Emerging Security Forum last week with an emphasis on cyber threat and artificial intelligence. As a multistakeholder platform, the forum aims to raise awareness of emerging threats and facilitate partnerships to address the new challenges. Given the multifaceted nature of cyber threats, my delegation believes that it is necessary to invite all relevant stakeholders to collectively understand and explore ways to address the threat. I thank Mr. Chair, Your Excellency Ambassador Kapur, for sharing your expertise with the forum. My delegation welcomes the second APR to include malicious software and ransomware as critical cyber threats. The Korean government is participating in the Counter-Ransomware Initiative to enhance global awareness and build collective resilience against ransomware. We also note with concern the recent cases of cyberspace being misused to interfere with democracy and democratic institutions. Meanwhile, emerging technologies can create new areas and vulnerabilities that can be exploited in malicious ICT activities. Cryptocurrency is an example. Cryptocurrency theft is often used to finance illegal activities, such as the development of WMD, which is prohibited and sanctioned by the UN Security Council. We would like to underline that cryptocurrency theft should be addressed as one of the cyber threats that can adversely affect international peace and security. The Korean government initiated a capacity building program for ASEAN countries to enhance awareness of cryptocurrency theft and assist them in responding more effectively. Artificial intelligence is another example. My delegation is of the view that AI and cybersecurity are inseparable, with AI having positive and negative impacts on cybersecurity. In this regard, there is a need to study the implications of AI development for cybersecurity and to discuss how we can manage the risks. Looking forward, Korea will convene a series of conferences on AI next year. Together with the UK, we will host a virtual global AI summit. We will also organize the second summit on responsible artificial intelligence in the military domain, RE-AIM, in partnership with the Netherlands. Lastly, the lack of awareness and the lack of capacity itself poses a threat by allowing attacks from malicious actors in cyberspace, highlighting the need for inclusive capacity building for the weakening countries. As my president emphasized in his UN General Assembly speech, the Korean government remains committed to strengthening its efforts to narrow the digital divide in developing countries. We welcome the recommendations to conduct a mapping exercise, which could be the groundwork for the UN to play a coordinating role, ensuring synergy and avoiding duplications in capacity building initiatives. Thank you.
Ambassador Gafoor
Thank you, Korea. Kazakhstan to be followed by El Salvador. Kazakhstan, please.
Kazakhstan
Thank you, Chair, for giving the floor. We would like to express our gratitude to you, Chair, and your distinguished team for your active and productive work at the midway point of the OEWG. In this case, Kazakhstan fully supports the work of the Open-Ended Working Group aimed at finding consensus on the key international agenda in the field of ICTs. As for the section on existing and potential threats, as mentioned before by the States, in a rapidly advancing world, nations are actively embracing and deeply delving into the realm of artificial intelligence. Without a doubt, AI showcases best practices, yet it brings a new set of challenges. In turn, Kazakhstan has started developing an AI strategy which will allow regulation at the government level. In this context, in this section, it is recommended to address the significance of issues related to existing threats by the use of AI for cyber resilience. This will allow a deeper understanding of the nature of challenges and the effective development of strategies to counter the growing cybersecurity concerns. So it is proposed as follows: States expressed concerns about the potential risks associated with the use of artificial intelligence in the field of ICT, especially in ensuring cyber resilience. Furthermore, it is essential to emphasize in this section the risks associated with data collecting and processing, including personal data, considering the surge in leaks of confidential information that span the entire global landscape. Additionally, we consider it necessary to include in this section the issues of threats that might be linked to the use of cloud technologies. As the number of cloud migrations increases each year and the functionality of such solutions continues to improve, security concerns remain quite acute. So it is proposed as follows: States have noted the growing importance of data protection, including personal data, in the context of international security, while also recognizing the need to address potential threats associated with the use of cloud technologies in the field of ICT. Thank you once again, Chair, for your work and your distinguished team for your work. We believe that discussing issues of existing and potential threats can be an excellent example of working in the field of ICT to ensure international information security.
Ambassador Gafoor
Thank you. Thank you very much, Kazakhstan. El Salvador to be followed by the United States.
El Salvador
Thank you, Mr. Chairman. I would like to convey my gratitude for the convening of this sixth session of the OEWG. On the subject of present and potential threats, El Salvador wishes to address the questions in your questions and in the second APR. As we have said in various fora, the threats with regard to ICTs in the context of security continue to evolve in scale and in intensity. To a large extent, these threats are associated with emerging technologies which include new areas of attack and which create vulnerabilities in the systems. Chairman, in your guiding questions, you mentioned threats to the ICTs and the matters which the Working Group should address. We have discussed artificial intelligence and quantum computing in previous sessions. The APR does not detail the challenges which have to do with technological developments such as rapid advances in generative AI, language models based on automatic learning, or the use of large volumes of data which create risks for international security, which derive from escalation of hostilities, calculation mistakes, progression in armaments, including WMDs. Despite the fact that artificial intelligence is discussed in different fora of the United Nations, we must address its implications from the perspective of security, especially when the disruptive effects go beyond the international threshold of peace and security. We must continue discussing other emerging technologies, for example, quantum computing and its application for mapping. In the area of information security, cryptography has a fundamental role to play. It offers confidentiality, integrity, and authenticity to our operations through ICTs. However, with quantum computing, which is imminent, the security of current standards will be compromised, which seriously threatens confidentiality and the integrity of digital communications through the Internet. The transition toward quantum cryptography will require efforts at the private and governmental levels through major investments and considerable time for its implementation. States must be prepared for this. El Salvador is committed to these discussions in this forum in order to create an awareness of the impact of emerging technologies for international security. We look for practical ideas as to how states can prepare for these challenges and how the Working Group can contribute to these efforts. Thank you.
Ambassador Gafoor
Thank you very much, El Salvador. United States to be followed by India. U.S., please.
United States
Thank you, Chair. The OEWG’s discussion on threats has been one of the most substantive and robust elements of our sessions, and we look forward to continued information sharing on our assessments of the cyber threat landscape. The United States continues to be concerned by a range of cyber threats, such as ransomware and other malicious cyber activities targeting critical infrastructure, cyber-enabled targeting of humanitarian actors, and cyber-enabled interference in democratic processes. We also take note of states’ growing appreciation of the cybersecurity implications of emerging technologies, such as AI. In the current geopolitical environment, we see an increased risk of escalation from uncontrolled cyber activity. Among the most prominent threats we continue to observe is the reckless use of cyber capabilities by nation-state actors during peacetime. And of course, we continue to see cyber tools used in the context of ongoing armed conflict, as the 2023 APR importantly acknowledged, and the risk of spillover effects. We remain concerned about cyber targeting of critical infrastructure. Last week, the United States issued a warning about Iran-affiliated actors’ continued malicious cyber activity against operational technology devices. These actors are actively targeting and compromising tools used in critical infrastructure sectors, including the water and wastewater system sector. In addition, we also underscore the statements in the second APR, noting a worrying increase in states’ malicious use of ICT-enabled covert information campaigns to influence the processes, systems, and overall stability of another state. The APR emphasized that malicious ICT activities that undermine trust and confidence in a political process are a real and growing concern. The United States will soon be in a presidential election year, and we note with concern the United Kingdom’s recent announcement of cyber actors affiliated with the Russian intelligence services targeting its political and democratic processes. We call on all states to refrain from malicious cyber activity designed to destabilize and undermine democratic processes and societies. These behaviors disregard the framework member states have worked and have committed to uphold. This type of activity can have cascading domestic, regional, and global effects and pose an elevated risk of harm to populations. In addition, we continue to see ransomware attacks increase at a troubling pace. This trend is due in part to some states allowing ransomware criminal actors to operate with impunity from their territories. The United States takes this issue of ransomware very seriously, as evidenced by our efforts to establish the Counter-Ransomware Initiative, or CRI. The CRI recently held its third annual summit, where its 50 member states met to discuss cooperation in the global fight against ransomware. At the summit, states agreed to establish a range of information-sharing mechanisms and technical training programs. CRI members also recommended against paying ransomware demands in an effort to undermine the extortive ransomware business model. Over the course of the year, we have also seen an explosion of interest in conversation around new and emerging technologies like artificial intelligence. As each of us study new and emerging technologies like AI, and as emerging technology issues get raised in various UN debates, we should remember the mandate of this group, which is concerned with ICT security in the context of international peace and security. Therefore, our unique remit is to study how emerging technologies could impact the cyber-threat landscape. At the same time, we need to understand how emerging technologies could impact the cyber-threat landscape. At the same time, we recognize that the framework of responsible behavior in cyberspace was designed to be technology-neutral and focused on effects, and therefore provides us with a solid basis to consider how to mitigate risks of emerging technologies in cyberspace. I think we can all imagine how AI could enable faster and more efficient malicious cyber-targeting, undermining the confidence we have worked toward together. While a lot of the conversation on AI has focused on risks, AI can also have a significant positive impact on cybersecurity. It could lead to a more secure cyberspace with increased resilience, improved cyber response time, and stronger networks. Finally, we recognize that non-state stakeholders, including some vetted entities, some of which are leaders in their fields, can have important expertise that could help the OEWG in its work. Member states can gain valuable insights from these stakeholders, particularly in the area of emerging threats, and those interactions in the OEWG should be enhanced. Thank you, Chair.
Ambassador Gafoor
Thank you, United States. India, to be followed by Canada. India, please.
India
Thank you, Mr. Chair. Mr. Chair, the threat to nations at large and to people in general has increased many folds over the years in the sphere of information security. The interconnected nature of our digital world has given rise to both existing and potential threats, necessitating a proactive and comprehensive approach to safeguarding our national interests. State and non-state entities deploy APTs to gain unauthorized access to networks and systems over an extended period. APTs are characterized by their sophistication, often targeting governmental, military, or industrial entities. The mostly unregulated cryptocurrency and digital currency markets have posed challenges for a parallel economy, which many nations are finding hard to fight. And this has also been pointed out by our South Korean colleague. Unregulated growth in this sector has been one of the biggest sources of channeling funds for hosting evasive attack infrastructure used by cybercriminals. There’s an increased reliance on cloud infrastructure and security of data centers housing the data of individuals and organizations. The sheer number of cyber attacks on companies, government, and individuals and the sophistication of these threats has increased due to the application of emerging technologies and also greater tactical cooperation among non-state and state actors. The surge in ransomware incidents has become a pressing concern, with attackers encrypting critical data and demanding ransom payments. This not only poses financial risks but also disrupts essential services, impacting national resilience. There’s also an immense need to protect critical information infrastructure systems from cyber attacks by adversaries. There is an increasing phenomenon of using social media platforms to spread misinformation and disinformation, leading to the disturbance of law and order, peace, and security of member states. The spread of false narratives can destabilize nations and undermine trust in democratic institutions. Mr. Chair, India takes this opportunity to thank you for your able leadership and sincere efforts in taking forward the mandate of this working group. We deeply appreciate your action-oriented approach and your efforts in taking forward various initiatives identified in the second annual progress report, wherein it was recommended that the OEWG convene a dedicated intersessional meeting with the participation of relevant experts invited by the OEWG chair and with due consideration given to equitable geographical representation on existing and potential threats to security in the use of ICTs. India appreciates this recommendation, and we are glad that the progress so far has been in the right direction. And we assure you of our constructive engagement and cooperation. Mr. Chair, as referred to in paragraph 17 of the second annual progress report, new and emerging technologies, while on one hand expand development opportunities for member states, on the other hand create new vectors and vulnerabilities that can be exploited for malicious ICT activity. These technologies are multifaceted and transcend physical boundaries of countries. The working group may need to underline a point that technological development, often referred to as disruptive innovations in the field of ICTs, is taking place beyond the horizon of the governments. In the forms of steps that member states can take to manage emerging threats and risks to international security, we would like to enumerate the following points that we believe would help in bridging the existing gap between potential threats posed by the latest technologies and the capacities of member states to address these threats. Firstly, multiple cross-regional dialogues with the involvement of all relevant stakeholders sharing the latest technological trends, discovered threats, and the scope of impact to individuals, organizations, and countries would build a deeper understanding of the latest technology and associated risks with such technology. The accountability aspect of new and emerging technologies to help member states better use and manage it may also be explored as a part of cross-regional dialogues. Secondly, to discourage potential threats from becoming threats of large-scale implications, it is important to encourage information exchange on discovered vulnerabilities and emerging threat scenarios to the ICT environment through a 24/7 contact point with the involvement of national CERTs or CSIRTs. In this regard, the intergovernmental points of contact directory would play a significant role. Thirdly, facilitating regular interaction between competent authorities or POCs to share methods of response to a particular threat or cyber incident along with established cyber hygiene practices would assist member states to work together and share best practices. Fourthly, sharing the model governance frameworks at national, regional, and multilateral levels that put in place necessary recommendations to the developments of emerging technologies and check threats posed by these technologies may help member states promote international cooperation and ensure cybersecurity and resilience of ICT systems and networks that are in place at the national level. India’s proposal on a global cybersecurity cooperation portal, which has been earmarked for discussions in this sixth substantive session, if implemented, would provide an integrated platform for all of the measures suggested, avoiding a multiplicity of platforms, channels, and portals, for the attainment of shared objectives. I thank our colleagues from Kenya for their support. Mr. Chair, new and emerging technologies are progressing at an agile pace. While governments prepare to address existing challenges, a new range of challenges is already evolving due to the continuously evolving nature of technological developments. As we navigate the evolving landscape of cybersecurity, our commitment to staying informed, adaptive, and collaborative will be instrumental in mitigating risks and ensuring a secure digital future. I thank you, Mr. Chair.
Ambassador Gafoor
Thank you, India. Canada to be followed by Moldova. Canada, please.
Canada
Thank you, Mr. Chair. Before speaking to threats, I’d like to take the opportunity to welcome 34 Women in Cyber Fellows from 28 countries attending this week’s OEWG meeting. The presence of these women delegates is an important contribution to gender equity and a vital component of our debate. We also welcome the presence of many stakeholders and regret, as the U.S. just indicated, that some of these non-state actors who could provide significant and substantive contributions on threats have been vetoed and are unable to join us. Canada hopes that this OEWG session allows us to further engage constructively on our collective objective to shape a stable cyberspace where responsible state behavior is ensured. A fundamental component of a stable cyberspace is ensuring that states understand the threats they face. A second is that states themselves do not act as threats to others. We note with grave concern in this regard U.S. statements regarding the targeting of their water supply. We also continue to be concerned by ongoing state-based crypto theft. From a thematic perspective for Canada, ransomware is one of the top disruptive threats. It is pervasive and can seriously impact an organization’s ability to function. Critical infrastructure is a particularly attractive target for malicious cyber actors. Cybercriminal activity against critical infrastructure can interrupt operations that support essential services, utilities, and the production of important goods, including food, fuel, and medical equipment. In terms of initiatives to tackle this type of threat, Canada actively participates in the U.S.-led counter-ransomware initiative, as well as various other multipartite counter-ransomware efforts. Our Canadian Centre for Cyber Security also works to minimize the threat by providing guidance and technical services to critical infrastructure and key supply chains to improve their cyber resiliency, whilst working to streamline cyber incident reporting and to discourage ransom payments. But we note that some states are very likely acting as safe havens from which these cyber criminals based within their borders can operate against targets located elsewhere, and they do so with near impunity. State-sponsored malicious cyber activity against Canada is a constant threat that is often a subset of larger global campaigns. State-sponsored threat actors are exploiting commonly used software platforms to target thousands and even hundreds of thousands of victims across the globe. They do so for a variety of purposes, such as stealing intellectual property and acquiring personal information. State-sponsored cyber actors are also targeting critical infrastructure to collect information through espionage, preposition in the case of future hostilities, and as a form of power projection and intimidation. They sometimes work with non-state cyber groups as a force multiplier to enhance their capabilities and avoid direct attribution. State actors have also been increasingly using cyber capabilities to target democratic processes around the world. The recent report of the Canadian Security Establishment on Cyber Threats to Canadian Democracy found that disinformation has become ubiquitous in national elections, and states are now using generative artificial intelligence to create and spread fake content. The report found that in 2022, slightly over a quarter of all national elections globally had at least one reported cyber incident. Of those countries whose national elections were targeted by cyber activity from 2015 to 2022, approximately 25% were NATO countries and 35% were OECD countries. Such behavior is unacceptable. This is why Canada joined with the UK and other allies to condemn Russian actors targeting the UK through cyber means as an attempt to interfere in electoral and political affairs. More generally on trends of threats, Mr. Chair, we believe there is value in examining the role of AI in terms of its impact on cyber security and the cyber security of AI. This highlights the importance of working together with partners for secure AI development, and Canada was pleased to sign on to the guidelines along with 18 partners aimed at helping AI developers to consider the risks from a cyber security perspective. Mr. Chair, as a responsible state actor in cyberspace, Canada looks forward to working with all other states that share our commitment to a stable, rules-based cyberspace to tackle these threats. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Canada. Moldova, to be followed by the European Union. Moldova, please.
Moldova
Thank you, Mr. Chair. Since this is the first time a delegation has taken the floor, please allow me to congratulate you for chairing this OEWG in a transparent and inclusive manner, aiming at achieving our shared objective to promote a free and secure cyberspace. Mr. Chair, the Republic of Moldova considers the field of cybersecurity as an extremely important dimension of its national security, assuming both the commitment to ensure the normative framework in the field and to meet international requirements and to facilitate bilateral cooperation in the prompt and efficient exchange of information between the competent authorities with responsibilities in combating the use of ICT for malicious purposes, as well as the international promotion of a global free and secure Internet, in which human rights, fundamental freedoms, and the rule of law are fully applied, but also of the responsible behavior of states in cyberspace. Moldova recalls with appreciation the consensus of states towards the adoption of the first and second annual progress reports of the OEWG, as well as your efforts in this process. We entirely support the expressed concern that a lack of awareness of existing and potential threats and a lack of adequate capacities to detect, defend against, or respond to malicious ICT can make them more vulnerable. States should be aware of the existing risks and threats they might be exposed to whilst feeling confident sharing them on the multilateral fora. We regret to note countless efforts by state and non-state actors aimed at destabilizing countries in order to draw them into new or existing conflicts. Cyberattacks are constantly on the rise in our region, becoming more extensive in terms of domains and target entities, and have an increased level of complexity which entails serious consequences for states, both financially and in terms of national security systems. Given the need for a well-defined and focused collective approach to responding to the crisis, the course and intensity of discussions on strengthening government and national cybersecurity capabilities changed dramatically. In 2022 alone, there were 10 DDoS attacks of major intensity in the Republic of Moldova which aimed to break down our governmental websites. One of the biggest security attacks took place between August 23 to 30, when several state information resources were subjected to massive cyberattacks with the aim of making them unavailable. Although these attacks are of medium complexity, characterized by overloading the internet network, they have a high intensity as the goal is the isolation of the government network from the global internet network. The attackers use various assailing methods, cyberattacks of level 7, implementation of intelligent mechanisms, simulation of the behavior of real users which greatly impede their identification and corresponding seclusion. In addition to DDoS attacks, new types of cyberattacks are observed which aim to obtain unauthorized access to information, steal information, and/or alter it like intrusions and brute force attacks. The most common types of intrusions are those that allow remote access to compromised systems to be exploited in the future, such as backdoor. At the same time, there are also attempts to break the passwords of systems that are not protected. The visible effects of these attacks resulted in the reduced speed of access to some websites; some resources were unavailable for short periods of time. Practically all the telecommunications infrastructure of the state has been operating at the limit during this whole period and at some moments even in extreme conditions. In the context of the intensification of attacks on the ICT infrastructures and their happening all the time with different intensity and complexity, ensuring risk prevention and countering threats to state security in the field of ICT is one of the main tasks of the state. Therefore, we support the idea of continuing the exchange of up-to-date views at the OEWG regarding the impact of existing and potential threats in the use of ICTs on international security and peace, as well as the cooperation in countering cyber threats related to ICTs. In this regard, we underline the state should consider how such a platform can be aligned with the envisaged exchange of information between technical contact points as well as with other relevant and appropriate information exchange and capacity building initiatives in place. In closing, I should highlight Moldova’s full alignment, full commitment to further work closely with all the delegations in this OEWG in order to ensure secure use of ICTs and promote responsible state behavior in cyberspace. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Republic of Moldova. European Union to be followed by Germany. EU, please.
EU
Thank you, Chair. Yes, thank you, Chair. I have the honour to speak on behalf of the European Union and its 27 Member States. The candidate countries, North Macedonia, Montenegro, Albania, Ukraine, the Republic of Moldova, and Bosnia and Herzegovina, the potential candidate countries, Georgia, and the EFTA countries, Iceland and Norway, members of the European Economic Area, as well as San Marino, align themselves with this statement. Chair, allow me to start by saying that the European Union and its Member States strongly condemn malicious cyber activities targeting democratic institutions and electoral processes. We closely monitor any attempts of cyber attacks on our democratic processes, especially in the context of the upcoming European elections. As pressure is mounting on democracy globally, we continue assisting and working with partners against these ongoing cyber threats. In this vein, the European Union and its Member States share the serious concern of the United Kingdom and other partners as stated in their declaration on December 7th, and express our full solidarity. Activities that seek to threaten our integrity and security, democratic values and principles, and the core functioning of democracies are unacceptable. Those activities are contrary to the norms of responsible state behavior in cyberspace, as endorsed by all UN members. We continue to promote due diligence and responsible state behavior in cyberspace, and call upon all states to comply with these norms and principles. Allow me to now turn to the EU statement under this agenda point. Technological and political changes are reshaping cyberspace as the ways that people interact with it. Working together to understand the evolving nature of the threat of malicious cyber activity is crucial to setting the context in which we develop practical measures for international cooperation. In 2022, the number of software supply chain attacks tripled. Every day, small businesses and critical institutions, including hospitals, are being targeted by cybercriminals. Every 11 seconds, an organization is hit by a ransomware attack, with an estimated cost of 20 billion euros annually. The increasing scale and severity of ransomware attacks is one element which heightens the risk to essential services and critical national infrastructure, and may therefore rise to the level of national and international security. In the longer term, we anticipate witnessing more complex and high-profile malicious cyber activities driven by AI-powered software. There is little doubt that humankind is on the verge of an era of exponential technological advancement, and AI is leading the way in the emerging digital world. For cybersecurity, this trend has comprehensive implications. In simple terms, artificial intelligence acts as a powerful catalyst and enabler for cybersecurity in our connected ecosystem. Chair, Russia’s aggression against Ukraine shows that ICTs are an integral part of modern warfare. In this context, malicious cyber activities are capable of causing excessive harm to civilian infrastructure and critical energy infrastructure. As reported by Ukrainian authorities, the overall number of campaigns originating from Russia-aligned threat groups against Ukraine doubled in the last six months. It is important to note that while the threats that we face are evolving and increasing, we have a framework which we have all agreed to as our collective starting point to address these threats. The threats just mentioned, as well as the threats that will be raised by our colleagues here today and in the past sessions, provide the context against which the following discussions under our mandate flow, and the context through which the work of this group becomes meaningful. Just as creating a clear link between the existing and emerging threats we identify and the reminder of our work discussing recommendations and proposals for responsible use of technology through the application of international law, norms, CBMs, and capacity building. We look forward to further advancing discussions, including experts’ briefings with a deep dive into this important topic in the open-ended working group in the years to come. Thank you.
Ambassador Gafoor
Thank you, European Union. Germany, to be followed by Italy (sic). Germany, please.
Germany
Thank you, Honourable Chair, for calling this meeting and for setting us all up for action and results-oriented discussions during the sixth session of this working group. Since this is the first time that Germany is taking the floor, let me reiterate Germany’s concern at the treatment of multistakeholders in this forum. Once again, two of Germany’s most respected think tanks, the German Council on Foreign Relations and the Stiftung Neue Verantwortung, which focuses specifically on the challenges of modern digital societies, have been vetoed from participating in the deliberations of this group. The vetoing of these two think tanks and a whole range of independent expert institutions from other UN member states has now become routine practice by some states. This is not acceptable. Vetoing participation of these stakeholders does not serve the interests of this group, which has the ambition to be an inclusive platform for developing solutions to the international cybersecurity challenges we are all facing. Excluding qualified voices from this process undermines the legitimacy of this working group. It will also impact negatively on our ability to accomplish the tasks in front of us. On the issue of threats more specifically, Germany would like to highlight three trends amid the rapidly evolving threat landscape in cyberspace. One, threats against democratic processes. Germany has seen serious interference by malicious cyber actors in the run-up to the federal elections in 2021, targeting a large set of our leading politicians. Germany is concerned that such malicious activities continue to be carried out against politicians and their parties even two years onwards. Germany will join hands with its EU partners to shore up cyber resilience and public awareness ahead of the European elections in 2024. Germany is in full solidarity with the United Kingdom after the UK attribution of a very serious cyber incident directed against their key democratic institutions. Two, cybercrime rising to the level of a threat to international peace and security. Cybercrime continues to be the most immediate and far-reaching threat to Germany’s IT infrastructure. However, cybercrime is not only crime. When crossing a certain threshold of severity, in particular when public authorities or critical infrastructure is targeted, cybercrime can pose a threat to national and international security. Last year’s major cyberattacks against Albania, Costa Rica, and Montenegro fall into that category, and this is the category that should be addressed by this open-ended working group. Three, spillover effects from international conflict. Today’s international conflicts play out in the cyber domain as they play out in the physical world. As Europe is going through a painful time of war, we are seeing direct spillover effects and heightened instability in German networks caused by Russia’s illegal war of aggression against Ukraine. Germany has activated the communication network of the OSCE multiple times over the past two years to inform OSCE participating states about major cyber incidents using the platform provided by the OSCE’s CBMs. In view of cooperative measures at the UN level, Germany hopes to be able to communicate via the UN Global POC Directory in similar instances from as early as next year. The idea of a repository of cyber threats, as advanced by Kenya, is an initiative of the OSCE that merits further discussion by this group. Germany also recognizes the particular challenges posed by AI-driven applications and supports previous speakers who have been calling for a more in-depth discussion of these challenges where they have a direct impact on cybersecurity, for instance, on the ability to effectively protect IT systems against attacks. Thank you.
Ambassador Gafoor
Thank you very much, Germany. Netherlands to be followed by Malaysia. Netherlands, please.
Netherlands
Thank you, Chair. I would like to start by thanking you, Chair, as well as Deputy High Representative Abel for your opening remarks. The Netherlands looks back on a successful Open-Ended Working Group cycle. Under your able leadership and with the excellent support of your team as well as the Secretariat, we have been able to make incremental and meaningful progress. I would also like to acknowledge the contribution of stakeholders to our work by supporting Member States with their expertise. In this regard, I echo the points of my colleagues from the United States and Canada on stakeholders’ accreditation. I wish to express my delegation’s appreciation to you, Chair, for continuing to facilitate exchanges with stakeholders in this process. Chair, let me now turn to the issues of threats. The Netherlands aligns itself with the statement delivered by the European Union, and I will make some additional remarks in my national capacity. Our previous meetings have seen a rich and detailed exchange on the threat landscape. Many countries face challenges stemming from the use of ICTs in the context of international security. In the second APR, we made important steps by acknowledging some of these existing and future threats and the need for a gender perspective in addressing them. The report also notes that ICTs are being used during armed conflict in different regions and expresses concern over the impact of ICT threats on the healthcare, maritime, aviation, and energy sectors. Chair, allow me to raise three types of existing and potential threats that we believe the Open-Ended Working Group could do further work on. Firstly, the interconnectedness of our digital world comes with a risk of severe spillover or cascading effects of cyber incidents on a regional and global scale. In particular, the Netherlands sees a risk for cascading effects when the use of ICT capabilities allows no or limited meaningful control by their initiators. The reckless use of ICTs makes the effects of these activities highly unpredictable. This carries an additional risk of causing harm to citizens, institutions, and economies and increases the likelihood of destabilizing misperceptions and unintended escalation between states. The use of automation as well as new and emerging technologies such as AI may exacerbate those risks. Secondly, we have heard many delegations raise the issue of ransomware. We therefore welcome the reference made to ransomware in the APR and hope we can further expand on this in our next report. In different parts of the world, we have seen ransomware incidents with a disruptive impact on individuals, economies, and societies at large. The impact of such incidents rose to the level of a threat to national and international security. Thirdly, the Netherlands is concerned about malicious cyber activities targeting international organizations. Such organizations are key to multilateralism and the rules-based international order. It is of vital importance that international organizations are able to fulfill their respective mandates in a safe, secure, and independent manner. We also support the points raised by the Republic of Korea on the threats of crypto theft, and we echo the Republic of Korea, Kazakhstan, and the United States on AI and its role in cybersecurity. Chair, my delegation would also like to take this opportunity to recall that we have collectively recognized electoral processes as a possible example of critical infrastructure. As 2024 features many elections worldwide, the Netherlands is concerned by threats of malicious cyber activities undermining the integrity and security of electoral processes and other core state functions. The Netherlands would also like to reiterate the recent statement of the EU High Representative condemning malicious cyber activities targeting democratic institutions and electoral processes and expressing the EU’s solidarity with the United Kingdom in light of its recent statement on this issue. Finally, Chair, the Netherlands attaches great value to the agreed normative framework of responsible state behavior. I therefore want to stress the notion reiterated in the second annual progress report that observation and implementation of the framework remain fundamental to addressing existing and potential ICT-related threats to international security. The large majority of states are adhering to the framework, and continued international cooperation is essential in ensuring all states have the capacities they need to further advance its implementation. Thank you, Chair.
Ambassador Gafoor
Thank you, Netherlands. Malaysia, to be followed by Italy. Malaysia, please.
Malaysia
For your continued leadership in our efforts to advance the work of this OEWG. We also thank the Director and Deputy to the Under-Secretary-General and High Representative for Disarmament Affairs for his opening remarks. We have collectively come as far as the six substantive sessions of the OEWG with the adoption of two annual progress reports. This is a testament to the indispensable value of multilateralism and the OEWG itself as a critical confidence-building measure. Mr. Chair, the guiding questions you asked us to share on any new developments or trends in existing and potential ICT threats, which the OEWG should discuss in depth. Recent developments have shown a significant surge in sophisticated cyber attacks, which exploit new and emerging technologies that can adapt, learn from, and autonomously manipulate ICT systems and infrastructure. This poses an increasing risk to cybersecurity. The proliferation of ICT devices also amplifies the attack surface, introducing more entry points for malicious actors to infiltrate networks and compromise data. Mr. Chair, Malaysia shares the concern on the threat brought by AI, quantum computing, and ransomware raised by many states earlier. Malaysia also appreciates and supports the point made by Germany on how cybercrime has escalated to a level impacting national and international security in certain cases. It is also worth noting that threats posed by new and emerging technologies, including AI, quantum computing, the IoTs, 5Gs, and others, become increasingly complex when these technologies are used in tandem to execute malicious activities. In-depth scenario-building discussions on this matter with expert stakeholder representatives will be beneficial in identifying the risks and impacts associated with these technologies when used together. Additionally, we should also focus on further studying how these technologies can be optimized for cybersecurity protection and response. In this regard, Malaysia believes that deliberations and input today and in the past substantive sessions of the OEWG, including the informal sessions with stakeholders, are of great relevance and will continue to deepen collective understanding of the challenges at hand. Hence, it is imperative for the OEWG to work together in ensuring that recommendations and proposals concerning the responsible use of cyberspace are prioritized and that identified threats are effectively addressed with risk-based approaches. In prioritizing our action items, Malaysia would like to highlight and reiterate several key points that, in our view, should be at the center of our discussion on this agenda item. First, both new and conventional technologies are subject to rapid innovation and advancement and must be continuously monitored. Second, security requirements are pivotal to the safety and resilience of new and emerging technologies. Third, privacy and cybersecurity risk management considerations and approaches are applicable in the design, development, and deployment of these technologies. Fourth, balancing security and privacy aspects without impeding usability or compromising safety requires participation from cross-disciplinary experts and stakeholders. Fifth, often cybersecurity incidents happen as a result of unresolved or ineffective security controls. Cybersecurity baselining is therefore crucial in ensuring hardening and secure usage of systems and technologies. Mr. Chair, with regard to the guiding questions on potential initiatives that can be undertaken at the global level to develop and implement cooperative measures to tackle the threat that we have discussed, Malaysia underscores the importance of embedding security and privacy by design at the early stage of development of any system and solutions. Malaysia is of the view that there should be a convergent discussion among UN bodies that focus on digital transformations and development to examine the imperative of prioritizing cybersecurity and implementing security by design. This should include the causes as well as the economic and other impacts of failing to pursue such prioritizations and implementations. The OEWG can play a vital role in facilitating discussion and bringing together all relevant stakeholders. This analysis is essential in order for us to understand the necessity of robust cybersecurity measures and potential repercussions in their absence. It will also clearly reflect the importance of cybersecurity as a fabric of digital transformation and the need to incorporate it at the initiation stage. This exercise could further assist in the prioritization of capacity building requirements and needs for states vis-a-vis implementations of the framework of responsible state behavior. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Malaysia. Italy, please.
Italy
Good morning, Chair. It’s nice to see you again after some months, I must say. And it was because of my fault, of course. Since it is the first time that I take the floor, I’d like to greet you all and thank the Chair, the supporting team, and the Secretary-General for their work and for having convened this session. Our work begins today, building on the success of the previous session of the OEWG when the second APR was adopted, and I am convinced that this is very promising, also for our work in the next few days. Let me first of all recall that Italy fully aligns itself with the statement earlier delivered by the European Union, and I will open our remarks in our national capacity, recalling also in the last APR, when it says that it is of the utmost importance to continue deepening the understanding of existing and potential threats, raise awareness, and further develop and implement cooperative measures to tackle such threats to states. So in this framework, we are particularly concerned by the global increase of malicious cyber campaigns which deploy much sophisticated and advanced technologies and are mainly carried out by cyber criminals, state actors, and activists, but also state actors. Many of these campaigns target European and national organizations, governments, companies, and civil society, often undermining our democratic values and security. Among all of the phenomena, ransomware continues to be one of the top cyber issues, not only for Europe but for all, costing the world around 20 billion euros in damages globally. The destructive nature, financial viability, and ease of deniability of ransomware make it an attractive tool for the whole range of threat actors. Finance, construction, education, industrial, and even the healthcare sector, as shown by their remorseless targeting in the EU and partners during the pandemic, tend to be ransomware attackers’ primary targets. So Italy remains committed to taking actions to combat this phenomenon, which requires international cooperation to be disrupted. We support and encourage existing initiatives, such as the Counter-Ransomware Initiative, which is tackling ransomware through a collective, coordinated, and comprehensive approach to ransomware resilience, disruption, illicit finance, public-private partnerships, and diplomacy. And I would like to echo our American colleagues by recalling that in the last summit in Washington, members of the Counter-Ransomware Initiative, including of course Italy, approved a joint declaration committing the relevant national authorities not to pay ransoms to cyber criminals. Phishing and the spread of malware via email are also among the most frequently encountered vectors, and with the advent of AI-based tools, we expect increasingly credible phishing emails, especially considering the ability of these systems to generate text corrected in various languages. More generally, while we are aware of the opportunities offered by technologies like artificial intelligence, AI tools that could be used to power malicious cyber activities or provoke serious social harm deserve our utmost attention. And even more than in any other field, the constructive relationship and involvement of the private sector in any discussion on cybersecurity aspects of AI is crucial to make sure that AI is designed and deployed in a way that it does not constitute a threat to international stability and security. In this framework, the Italian Cyber Security Agency has recently adhered to the guidelines for the safe development of artificial intelligence earlier mentioned by the United Kingdom. The guidelines, I’m sure, will help developers to create responsible, ethical, and safe AI. Cyber attacks against critical infrastructure are increasing in scale and geopolitical implication. The spreading of disinformation and foreign information manipulation and interference threaten the democratic values and policymaking processes of modern societies. Such activities have the potential to negatively impact peace and stability in cyberspace and may cause public harm. Finally, discussions regarding detection/identification of existing and potential threats should consider the involvement of providers, tech companies, operators of critical infrastructures, and end users like civil society of essential services, thus enhancing national capabilities in protecting vital sectors and preventing domestic, regional, and global effects. We welcome and we strongly encourage stakeholders’ participation in such discussions. Mr. Chair, as you said this morning while opening the sessions, the discussion on threats is very important per se, but is even more so if they are able to increase our awareness and if they are conducive to renewing our impetus for the consolidation and better implementation of international law and of the norms that we are all committed to. In this spirit, we look with interest at the proposal of Kenya for a repository of threats and look forward to the proposed international meetings with the presence of selected experts, equitable geographical representation, and dedicated time to make the discussion as substantial as possible. I thank you.
Ambassador Gafoor
Thank you very much, Italy, for your remarks. In fact, I would say that the discussions this morning have turned out to be very substantial indeed, and that’s a very, very good start to our work this week. It’s five minutes past one, so we’ll have to stop here. We have had about almost 20 speakers this morning and another 25 who have inscribed to speak on this item. We will continue with that list this afternoon and then proceed to the next agenda item if we are able to exhaust the speaker’s list. So I wish you a pleasant lunch and see you at 3 p.m. The meeting is adjourned.
Leave a Reply