Session 6-2 Transcript
(OEWG 2021-25)

Home » Resources » UN Open-ended Working Group (OEWG) transcripts » Session 6-2 Transcript(OEWG 2021-25)
Ambassador Gafoor

The second meeting of the sixth substantive session of the Open-Ended Working Group on Security of and in the Use of Information and Communication Technologies, established pursuant to General Assembly resolution 75-240 of 31st December 2020, is now called to order. Distinguished delegates, before we resume with the list of remaining speakers under the first cluster of items as indicated in the Programme of Work, I would like to give members an update on the participation of stakeholders under the agenda item Organisation of Work. I wanted to highlight that delegates would know that the Working Group had adopted the modalities for the participation of stakeholders in the OEWG at the very first meeting of the third substantive session, and in accordance with that decision, a list of non-governmental entities which submitted applications to participate in the current session was made available, together with accompanying relevant information to all delegations before the session. That updated list of non-governmental entities is contained in document AC-292-2023-INF-6. May I take it that the Open-Ended Working Group approves the attendance of the non-governmental entities contained in the aforementioned document? Hearing no objections, it is so decided. I also wanted to draw the attention of members of the Working Group to the informal engagement with stakeholders that I had convened last week on Wednesday, the 6th of December, which turned out to be a very fruitful and productive session with the participation of more than 100 representatives from the stakeholder community. And I look at this informal engagement with stakeholders as complementing the engagement of stakeholders in the Working Group through the accreditation modalities as was decided within this Working Group. I have always said at the beginning of the Working Group that the work of the Working Group or rather right from the outset when I assumed the post that I am committed to a systematic, sustained, and substantive engagement with the stakeholder community. And I believe that this is an effort that I continue to undertake. And the informal consultations with the stakeholder community last week were organized in that respect. Later this week, as part of the program of work, we will have a dedicated stakeholder session to again engage with the stakeholder community. And I wanted to take this opportunity to thank the representatives from the stakeholder community who are present here as well as those who might be following the discussions virtually. I wanted to thank them for their presence and contribution to the process because I see all ideas coming from the stakeholder community as enriching our discussions and as contributing to our efforts to find common ground. So with those comments, I’d like to now move to the program of work in relation to Agenda Item 5, Cluster 1, Existing and Potential Threats, on which we had a good start this morning. We have about 25 remaining speakers and I intend to proceed with the remaining speakers list. And we will continue with the list as it was registered in our system before the lunch break. And I see that the green lights are still switched on from your nameplates, which means that your names are reflected on the list. So we’ll go through that list one at a time. And if you have been left out, please press the button again, and we’ll get to you. We’ll start with… Yeah, New Zealand to be followed by France. You have the floor, please, New Zealand.

New Zealand

Thank you, Chair. New Zealand is pleased to join this session of the OEWG, where we once again have the opportunity to reflect on our collective progress implementing the agreed framework of responsible state behaviour online, and we thank you and your team for your continued efforts. Chair, a report card has mixed results. The fact that the OEWG was able to agree on a consensus annual progress report in July is commendable. However, we see a small group of states continue to use cyber technologies in an irresponsible manner, showing disregard for the agreed framework. New Zealand’s latest cyber threat report shows that 23% of nationally significant incidents over the 2022-2023 year had indications of a connection to state-sponsored actors. Malicious cyber activity carried out by state-linked actors has the potential to undermine stability and threaten international peace and security. This is why New Zealand has joined the UK and other partners in condemning malicious cyber activity conducted by the Russian government. We do not tolerate attempts to undermine the integrity of democratic institutions through cyber or any other means. By providing examples of malicious cyber activity in public, we aim to raise awareness of the threat, signal to all states what we view as irresponsible behaviour, and call on all states to behave responsibly online. Overall, the number of incidents linked to state actors has decreased, but we experienced a record high proportion of links to financially motivated groups or malicious cyber actors exhibiting financially motivated behaviours. Our National Cyber Security Centre observed malicious cyber actors increasingly taking advantage of exfiltrated data to extort payment from their victims. The theft of data combined with encryption of the victim’s copy is double extortion, as a malicious cyber actor now has two opportunities to leverage payment from the victim, increasing the potential harm an organisation experiences during these breaches. Finally, as we have said in previous sessions, we remain concerned at the use of malicious cyber operations in international armed conflict, particularly reports of cyber operations being used to target civilian infrastructure. I thank you.

Ambassador Gafoor

Thank you, New Zealand. France, to be followed by the Syrian Arab Republic. France, please.

France

Thank you, Mr. Chair. My delegation aligns itself with the statement made by the European Union, including the support expressed by the UK, and we have the following comments to make in our national capacity. Let me share three comments that France has on the issue of cyber threats. During 2023, we observed, on the one hand, that the overall number of threats globally was elevated, and also a tendency to target the most vulnerable or least protected entities. Ransom software, mentioned by many delegations here today, ransomware attacks were very numerous in France, particularly with regard to local government and health institutions, with serious consequences. These entities have a variable level of maturity in terms of cyber security, and therefore they’re the chosen targets which suffer from the most sophisticated attacks. On the other hand, the level of protection of the critical infrastructure has been effectively raised, and that’s good news. This is due to the measures taken as part of the NIS European regulation, and with regard to the normative framework which stipulates that states must protect their essential infrastructure. This better protection has caused attackers to look for more vulnerable targets, and that is why we decided to radically increase the number of entities that are part of this regulation framework under NIS2, and this is now being adopted as part of our national legislature in France. The second comment I had to make has to do with the growing commercialization by private companies of intrusive cyber tools that can be used for malicious purposes. Some of the use is legitimate, such as fighting terrorism or providing information security, data security. The companies that have these tools remain responsible for them, and France is taking all necessary measures to mobilize us collectively, as we did in 2015 when we adopted the normative framework. We will continue to actively participate in discussing collective and national responses to these threats. My third comment has to do with the links between cyber security and artificial intelligence. Cyber security is the dominant trend in terms of our further development because of its double nature. It can enhance existing capabilities, but also can give rise to destructive technologies, including malicious use on the global scale. Malicious use of generative AI can allow non-state actors to carry out increasingly sophisticated attacks. Furthermore, artificial intelligence systems themselves offer specific vulnerabilities which have to be taken into account parallel to the classic threats that have existed for some time. Cyber security for AI systems is a sine qua non condition for ensuring secure use of these sophisticated technologies, and also for promoting international security, because these technologies are being integrated in an increasing number of critical information systems. We believe that our group should mention that in our annual report. Thank you very much.

Ambassador Gafoor

Thank you, France, for your statement. Syrian Arab Republic, to be followed by Cuba. Syria, please.

Syria

Thank you, Mr. Chair. My delegation would like, at the outset, to thank you and your team, as well as the Secretariat, for your efforts in preparing and convening this session. We appreciate your able leadership, which constitutes a very important factor in the progress of the work of this group. Mr. Chair, the delegation of my country strongly believes in the value of the OEWG being the only platform which could guarantee an equal participation of all states in discussing the issues related to the security of ICT. This group has proven its worth through the very large and efficient participation, as well as the issuing of two annual progress reports. We need to keep this group and not replace it with any other mechanism, and to also hold on to the consensus within the group. Mr. Chair, when it comes to existing and potential threats, my delegation would like to stress the following points: First of all, the dangers of misuse of a digital platform, including social media, in order to spread misleading information for political reasons or in order to interfere in the domestic affairs of countries, incitement to violence, which would fuel social instabilities. Secondly, to use the data on the lands of other countries or to provide access, very developed access of satellite internet access, on the lands of other countries without their approval and with no commitments from the provider companies. This is an interference in the affairs of states and an attack on their sovereignty over their cyberspace. Thirdly, the producing companies might also hide important information on vulnerabilities in their projects. Fourthly, the increasing growth of illegal markets on the dark web and the possibility those markets offer in accessing equipment and resources to non-state actors, which might use them for malicious targets, especially by terrorist groups, which could coordinate and communicate using VPNs and encrypted messages in order to enroll fighters and mislead the youth, fueling extremism and incitement to violence. Mr. Chair, any capacity building process, in order to be credible and efficient, cannot work under the UCMs. These are illegal measures. Therefore, we could not ignore the threat posed by those UCMs. We should call to lift them and stop and refrain from imposing them, as they are impeding and hindering the capacity building process. In conclusion, Mr. Chair, we believe that under the absence of clear norms and standards about responsibility in cyberspace and fears and concerns over auto evaluations when it comes to the incidents of ICTs, especially that it is very difficult to know specifically which is the source of these malicious cyber activities and the tracking is very complicated. My delegation does not support establishing a list or a registry or a global cybersecurity portal of those threats, which could hinder the process and have an opposite effect. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you very much, Syrian Arab Republic. Cuba, to be followed by Poland. Please, Cuba.

Cuba

Mr. Chairman, we reiterate our gratitude to you and to your team in coordinating this group. Taking into account what is stated in the second APR on the urgency of deepening awareness of existing and potential threats in the area of information security, and on the basis of your guiding questions for this segment of our debate, we wish to emphasize the following: Number one, the need to be aware of the various threats faced by member states, which, although they are no longer new, seem to become more regular and complex. In this regard, we emphasize the following: 1. The growing cyber offensive capacity development and their inclusion in the national strategies of some states which use offensive cyber weapons and undertake cyber offensive operations. 2. The possibility of undertaking cyber attacks against adversaries. 3. The proliferation of doctrines which consider the use of force as a legitimate response to a cyber attack. 4. The covert and illegal use of the informatic systems of other nations by individuals, organizations, and states to conduct information attacks against third countries, and for the false and politically motivated attribution of cyber attacks to justify hostile actions against other states. 5. The undue use of ICTs and of communication platforms, including social media and radio and electronic broadcasts, as a tool to interfere in the internal affairs of states by promoting hate speech, incitement to violence and terrorist acts, subversion, destabilization, false news, and the distortion of reality against any state for political purposes and as a pretext for the threat or use of force as part of the so-called fourth generation warfare which manipulates emotions through the use of information which has been stored and processed in violation of the protection of personal data. This with the participation of companies which turn this model into a business. The Non-Aligned Movement has alerted to this in the framework of the previous context. The second APR also underscores the need to continue to apply measures of cooperation to face existing and potential threats in cyberspace. In order to counter threats to security and to the use of ICTs, we need to prioritize the following issues globally: 1. A global commitment on the use of ICTs for exclusively peaceful purposes to the benefit of cooperation and the development of peoples. 2. The prohibition of the use of ICTs as a pretext to unleash war, threat, or use of force. 3. The prohibition of the militarization of cyberspace. 4. The elimination of the enormous technological divide and what has been imposed on developing countries to invest in their ICT structures, including unilateral coercive measures, since they limit their capacities to address existing and potential threats. 5. The negotiation and adoption in the framework of the United Nations of an international legally binding instrument which supplements applicable international law and responds to the significant vacuums in the area of cyber security. Other actions – global actions which could address these threats are: 1. To increase cooperation to address cyber incidents by means of an exchange of information which would not compromise the privacy of states with regard to their capacities nor contravene national laws. 2. To implement mechanisms of technical assistance for capacity building, including those which perfect critical infrastructure based on respect for the national laws of states. 3. To standardize, if possible, the terminology of cyber incidents, trying to find a common terminology. 4. To establish a multilateral mechanism to determine impartially and unequivocally the origin of incidents which involve the use of ICTs. Mr. Chairman, every state has the right and the duty to promote, as part of its constitutional prerogatives, the security and the use of ICTs for peace, development, cooperation, and friendly relations among states and nations. Cuba is firmly committed to this. Thank you.

Ambassador Gafoor

Thank you, Cuba, for your statement. Poland to be followed by Bangladesh. Poland, please.

Poland

Thank you very much, Chair. I would like to welcome everyone. Thank you for inviting us. And I want to thank you and your team for your tireless efforts to move our work forward towards achieving some sustainable results, which we could take with us further to any platform to be established within the United Nations to continue the work for a safer cyberspace for all of us and for more responsible states’ behavior in this respect. It’s a very hard task. I will continue to support you. Poland aligns itself, of course, with the statement of the European Union. In our national capacity, I would like to share a few elements. The maps of threats coming from or enabled by cyberspace are constantly expanding and the patterns are becoming more and more complex. Therefore, we cannot list or eliminate all of them, but we rather should focus on two elements. First is to have the international law and norms implemented on the global level, and B, to develop and share effectively within the UN family member states effective tools to combat such threats. This is where we see the substance of our work here within the Open-Ended Working Group and beyond, within the future permanent UN structure dedicated to cybersecurity issues. So I’m not going into details of AI and other technologies as they were covered eloquently by a number of previous speakers. However, also in the context of approaching the complexity of threats related to the development of new technologies, it is even more difficult to understand why certain states constantly block participation of a growing number of representatives from the private sector or think tanks who often possess knowledge and analysis from which we, representatives of governments, could benefit in our discussions here. Finally, I would like to note that our work here is and will continuously be difficult because while we’re discussing responsible states’ behavior in cyberspace, some of the states present here undermine it constantly. They undermine the international applicability to cyberspace and the norms we all agreed upon. Poland, like many other countries, has associated with the concerns expressed by the UK, pointing out that Russian cyberattacks are directed against democratic institutions’ electoral processes. We strongly condemn all forms of malicious cyber activities aimed at destabilizing democratic institutions, public administration, or social life. We firmly advocate that states, the private sector, and individuals adhere to the principles of responsible behavior in cyberspace as endorsed by the UN in the form of the 11 norms and international law. I was a guest at the opening panel at the Singapore International Cyber Week earlier this year, and we discussed the UN framework for our work. And then I said that the UN framework, UN platform, is not ideal to deal with the problems of cyberspace and the challenges. But this is the only one we have at the global level. Therefore, Poland will not cease from our efforts to come to concrete results that can be endorsed and implemented by all UN states. Thank you, Chair.

Ambassador Gafoor

Thank you, Poland, for your statement. I give the floor to Bangladesh, to be followed by Singapore. Bangladesh, please.

Bangladesh

Thank you, Mr. Chair. Very good to see you at the sixth substantive session of the Open-Ended Working Group on security of and in the use of ICT. My delegation expresses its sincere appreciation to you and your able team for guiding this group in an excellent manner. You can count on my delegation’s full support in your endeavors. Mr. Chair, to answer the guiding questions on new developments or trends in existing and potential ICT threats, let me highlight the following: First, my delegation believes that deepfakes are becoming increasingly sophisticated and realistic, which poses significant risk for disinformation campaigns, identity theft, and erosion of trust in media. Disinformation campaigns through deepfakes have the potential to erode trust in public information and institutions, create confusion, and undermine the credibility of both states and institutions. In our view, the potential for deepfakes to be used in cyberbullying, propaganda, and criminal activities warrants in-depth discussion and potential policy intervention. Second, we identify quantum computing as an emerging threat as it could render current encryption systems obsolete. The geopolitical landscape surrounding quantum technology poses challenges that could impede its maximum utilization and advancement. Therefore, we want to have an in-depth discussion on the consequences of the malicious use of quantum computing to broaden our common understanding. Third, AI-powered hacking is another area of growing concern. AI can be used to automate hacking tasks, such as finding vulnerabilities and exploiting them. AI-powered hacking can be used to attack a wide range of targets, including businesses, governments, and individuals. It is imperative to have thorough discussions to pinpoint risks and formulate agile strategies for effective mitigation. Fourth, supply chain attacks are becoming increasingly common, targeting critical infrastructures through vulnerabilities in software and hardware components. The growing complexity of software and the reliance on open-source libraries further increase the attack surface and the potential for vulnerabilities. The Open-Ended Working Group should consider potential strategies for enhancing software supply chain security and promoting responsible vulnerability disclosure practices. Finally, Mr. Chair, my delegation highlights that given the interdependent nature of ICT, no government or organization is able to address these challenges alone. International cooperation and information sharing are the most viable ways to tackle these issues. In this regard, bridging the digital divide, raising awareness, and capacity building are paramount to effectively address these challenges. I thank you.

Ambassador Gafoor

Thank you, Bangladesh, for your statement. Singapore, to be followed by Ireland. Singapore, please.

Singapore

Thank you, Mr. Chair. We’d like to first express our thanks to you and to your team for the work done in convening this meeting. My delegation would like to share two key trends from our observations of the ICT threat landscape. First, as noted by our colleagues from the Republic of Korea delegation, as well as Colombia, Uruguay, and many others, ransomware remains a serious threat, as reflected in the second annual progress report. Its operations are continuing at a high tempo worldwide, resulting in the disruption of operations and services. An upward trend in cyberattacks impacting CIIs by cybercriminals such as ransomware groups has been observed this year. Ransomware groups were seen targeting organizations that provide critical services, such as healthcare providers. In some of the widely reported cases, the ransomware attacks impacted operations of many clinics and hospitals within the same healthcare group, due to the interconnectivity of their IT systems. Second, Mr. Chair, as noted by many other delegations here, in fact, AI-enabled ICT threats have emerged as a key area of concern. The potential of AI to turbocharge the speed, scale, and sophistication of ICT threats can facilitate a variety of malicious activities. Beyond AI-enabled ICT attacks, the security of AI itself is crucial. AI risks such as model manipulation and prompt injection attacks can allow malicious actors to bypass security safeguards and gain unauthorized access to sensitive information. It is useful for us to continue building greater understanding of the global cybersecurity threats, including the two that I’ve highlighted above, through discussions at the OEWG. Having a timely and clear understanding of the rapidly evolving ICT threat landscape can help states better build resilience, both nationally and in cooperation with others. Such understanding can also be instrumental in guiding global ICT capacity building efforts on the types of capacity building that need to be developed in order to address these threats. In this regard, it would be useful for ongoing capacity building efforts to take into account many of the threats being discussed here today. I’ll speak more on this in the section on capacity building. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Singapore. Ireland to be followed by Australia. Ireland, please.

Ireland

Chair, thank you. To begin, I want to align with the EU statement delivered by my colleagues here earlier in this session. Chair, I want to thank you and your team for your helpful questions to guide our discussions today. There is scope to build on the text agreed to in the second annual progress report, agreed here in July, and as you said, we are halfway through and there is a real opportunity to make tangible progress building on these substantive exchanges. I’m already heartened by what we’ve heard this morning. Chair, there are three areas where Ireland believes it is important to focus discussions at the UN OEWG on existing and potential threats. Firstly, artificial intelligence. It is reshaping cyber security and while it does offer enhanced threat detection and automated responses, technology is also enabling more potent adversarial attacks and introducing new attack vectors such as training data poisoning, model inversion, and manipulation. More broadly, we are concerned about the vulnerability of new technologies, the ongoing adoption of 5G technology, and the rise of the Internet of Things. The connection of previously isolated real-world devices will vastly increase the attack surface, leading to new risks not previously associated with the cyber domain. Chair, ransomware continues to be an issue of serious concern and the dynamic evolution of criminal groups and their operations. Cybercrime as a service, where experienced cybercriminals offer services like malware and ransomware to the highest bidder, is on the rise, lowering the barrier to entry for cyber attacks. Ireland remains concerned about the threat posed by state actors, their proxies, and aligned hacktivist groups targeting critical infrastructure with the potential for cross-border cascading effects to the point of impacting international peace and security. We are also concerned about efforts to use malicious cyber activity to undermine trust and confidence in political electoral processes. These threats remain, as evidenced by the statement by our UK colleague earlier today, and Ireland wishes to express solidarity with the UK in that regard. Next year, an estimated 4 billion people will take part in democratic processes, and it is of the highest importance that there is confidence and trust in the integrity of the electoral system. We urge states to abide by the norms of responsible state behavior in cyberspace in this regard as endorsed by all UN member states. Chair, as we look to potential initiatives to raise awareness and to deepen our understanding of the existing and potential threats, we see this as an obvious place to underline the importance of the multistakeholder approach. Strong collaboration between governments and the private sector will be critical to advance cyber security technologies and practices. We support the development of platforms that bring together industry, academia, and government to discuss these issues. We need all the skills available to us. We are also supportive of further consideration of global threat intelligence sharing platforms such as that in the Kenyan proposal. The challenge of ransomware is so complex it can only be tackled by strong international collaboration focused on disrupting cyber criminals, building national resilience, and working collaboratively with the private sector. The counter ransomware initiative is an increasingly important framework for this work. Ireland is also taking measures domestically and recently established a new national counter ransomware task force, and we’re happy to share our experience of that with other countries. Finally, I want to join my EU colleagues in underlining the importance that women and girls have full access to digital information and media education and to be protected from technology-facilitated gender-based violence online. This area should also be a priority for the OEWG.

Ambassador Gafoor

Thank you very much, Chair. Thank you, Ireland. Australia to be followed by Czechia. Australia, please.

Australia

Thank you very much, Chair. I want to thank you first for providing your perspective this morning on the topics that we have to discuss this week, and Australia would agree with you that recognizing new emerging threats in our 2023 progress report should be commended. Australia is optimistic that we can continue to build upon this essential work by sharing views and experiences both here between states and also by fostering dialogue with the technical community, industry, civil society, and academia because states can’t solve this issue alone. Often the first affected by cyber incidents, the protectors of critical infrastructure, the benefactor and beneficiary of two-way expertise, cooperation with the multistakeholder community is absolutely essential for security and for lifting our capacity collectively. We all know that cyber threats are growing in number, speed, and sophistication. Every threat report published by a national cyber security agency from around the world has been confirming this trend. The stakes are higher than ever before, and our most sensitive data and most vulnerable members of the community are at risk. Some statistics, for example, from Australia’s Cyber Security Centre 2023 threat report, which was published a couple of weeks ago, show that malicious domain requests went up 176 percent this year compared to last year, and attacks against servers went up 336 percent. Ten percent of all cyber incidents in Australia this year involved ransomware, and we responded to 143 different cyber security incidents that targeted Australian critical infrastructure. We also had a program that assisted recovery from several significant critical infrastructure attacks in other countries in our region. This group’s recent focus on critical infrastructure is welcome, and Australia supports continuing to work on the protection of critical infrastructure from cyber threats because this targeting is increasing as operational technology networks grow in size and complexity. We’re seeing an interconnected nature more and more of critical infrastructure networks with a number of growing third parties involved in technology supply chains and increased reliance on remote access and management solutions, and this all increases the attack surface. We’re seeing networks and infrastructure regularly targeted by both opportunistic and also more deliberate malicious cyber activity. Understanding the specifics and the vectors of cyber threats posed to critical infrastructure remains key to our ability to address and mitigate these threats, including through implementing and adhering to our agreed norms. The three critical infrastructure norms are very important here, and also through a renewed global focus on security by design and security by default policy, which was also mentioned by Malaysia. Since our last substantial session in July, Australia experienced a major cyber incident impacting an operator of our ports, container terminals, and provider of supply chain logistics, which involved a lot of exfiltration of data by the threat actor. As an island country, interference in the operation and logistics of ports poses a fundamental risk, but we’re not the only ones. This morning, we’ve heard Colombia speak about a recent significant cyber attack on their critical infrastructure, the US spoke about cyber tools targeting water system supply, and the United Kingdom explained that last week it attributed sustained unsuccessful attempts to interfere in UK politics and democratic processes to Russian state cyber actors. Attempts to use cyberspace to interfere in elections and democratic processes are unacceptable and must stop. Australia joins the UK and other partners in expressing serious concerns about attempts to use cyber operations to interfere with democratic processes, and we call on all countries to act responsibly in cyberspace, continuing to promote the implementation of and adherence to international law and norms, and hold states to account if they act contrary to these international obligations and expectations. There is a real and growing concern regarding the use of cyber operations to undermine trust and confidence in political and electoral processes and also in public institutions. We’d like to reiterate our concern regarding the increase in cyber operations targeting humanitarian organizations and international organizations. Last year, we spoke in detail about attacks targeting the data of the ICRC. More recently, we have seen an unprecedented, sophisticated, and serious cyber incident impacting the International Criminal Court. This incident has been interpreted as a serious attempt to undermine the court’s mandate, and Australia condemns this activity. Others have spoken this morning about potential threats posed by emerging technologies, including AI, quantum computing, and cloud services, and Australia joins these voices in reiterating that this group should examine the way emerging technologies can impact international peace and security in cyberspace, both by creating new vectors for threats and also in providing innovative ways to address these threats. Finally, I would like to conclude by mentioning something from a slightly different perspective. The value of the rules-based cyberspace is in providing stability and independence for all countries, large and small, developed and developing, to determine their own digital future and economic development. A rules-based cyberspace mirrors the rules-based international order, which is enshrined in the fundamental instruments of the United Nations. Yesterday marks the 75th anniversary of the Universal Declaration of Human Rights. Although crafted in a very different era, the Universal Declaration of Human Rights has an enduring power and has enduring relevance, including in our work in this forum. All countries have agreed that rights apply online just as they do offline, and the principles of universality, indivisibility, non-discrimination, and all rights applying to all humans without distinction of any kind remain at the foundation of international engagement on human rights in the real world and the digital one. The passage of 75 years hasn’t changed this. Thank you, Chair.

Ambassador Gafoor

Thank you, Australia. Czechia, to be followed by Finland. Czechia, please.

Czechia

Mr. Chair, first of all, I would like to thank you for your excellent leadership of our Working Group, and I wish you all the best for the next annual cycle of our discussions. At the outset, I would like to use this opportunity to join the EU and others in expressing solidarity and strongly condemning malicious cyber activities targeting democratic institutions and electoral processes, as also stated in the Public Declaration of the United Kingdom and other partners on December 7th, 2023. Czechia has long strongly supported the full involvement of multistakeholders in the Open-Ended Working Group. I would like to thank you, Mr. Chair, for all of your efforts. I really highly appreciate it. But still, Czechia fully subscribes to the statement of Germany, Poland, Australia, and others, regretting that some NGOs, including those with high expertise, were again denied access to our meeting. During the Open-Ended Working Group meetings, Czechia has constantly drawn attention to several categories of threats that have the potential to impact international peace and security. We observe that some of these threats have intensified and evolved significantly in the current challenging geopolitical environment. Mr. Chair, reacting to your guiding questions and consistent with the intervention of many delegations, including the Republic of Korea, India, Colombia, El Salvador, Uruguay, Kenya, Canada, Singapore, and Ireland, Czechia would like to pay more attention to ransomware attacks. Czechia welcomes incorporating ransomware into the second APR, as we have been highlighting its importance repeatedly. In June 2023, our National Cyber Security Agency issued an announcement to inform about the increased risk of ransomware attacks against Czechia. On a national level, we detected elevated activity of cybercrime groups using these techniques in the past months. When speaking about ransomware, we would like to point out a new rapidly developing trend of ransomware as a service. This threat is unique for its use of manifold extortion and begins to prevail. We also see that ransomware groups are targeting smaller and smaller companies that previously might have been thought of as uninteresting to hackers. This is due to the growing number of ransomware groups that often operate as high-end technology companies with their own developers, sales departments, negotiation teams, and marketing. For all the above-mentioned reasons, Czechia became part of the International Counter-Ransomware Initiative. During the third Counter-Ransomware Initiative gathering, Czechia, together with more than 40 other countries, joined the collective statement against ransomware payments. Our National Cyber Security Agency discouraged paying ransomware demands in recent analysis and recommendations on ransomware. In addition to the ransomware attacks, Czechia also supports more focused discussion on threats posed by the deployment of new and emerging technologies, especially artificial intelligence and quantum computers. Elements of automation, acceleration, and scalability bring new dynamics and deepen the opacity of the current processes. Finally, yet importantly, Czechia’s long-term stand is for a human rights-based and human-centric approach in cyberspace. In this context, we would like to welcome a discussion within the Open-Ended Working Group on threats related to the misuse of technologies to suppress human rights. Here we mean, for example, the massive collection of data on one’s own citizens, partial or complete censorship or blocking of the Internet, monitoring of political opponents, and so on. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Czechia. Finland, to be followed by Egypt. Finland, please.

Finland

Thank you, Chair. Since I take the floor for the first time in this session, Mr. Chair, I wish to thank you and the secretariat for the work carried out in preparing this session. Finland aligns with the statement made by the European Union. In addition, I would like to make a few remarks in my national capacity. I would like to join those delegations, including the EU, Costa Rica, Uruguay, Kenya, the UK, South Korea, El Salvador, the USA, India, Canada, Malaysia, Italy, France, Bangladesh, Singapore, Australia, and Chechnya, that have raised the concern of the threats posed by emerging technologies. Artificial intelligence and quantum technology pose both opportunities and risks for the international community. Artificial intelligence, being relevant in multiple domains, is covered by other UN processes. However, we should take a closer look at it in the framework of cyberspace from the perspective of international peace and security. Artificial intelligence can enhance malicious cyber actor capabilities to conduct cyber operations and perform disinformation operations. Artificial intelligence will multiply actors and impact. Although with artificial intelligence we can better detect malicious cyber operations, there is a risk that cyber detection and prevention do not develop at the same pace. Quantum technology, like artificial intelligence, contains possible threats in the cyber domain. It has been clear for a long time that once quantum computers develop far enough, all currently used methods of data encryption can be broken. Expert estimates of when this will happen vary between five and 30 years. However, it is worth paying attention to this threat already. Even if the quantum threat does not materialize for years or even in this or the next decade, we should already be aware of it now and start preparing for this transition. Finland shares the serious concern expressed by the United Kingdom and other delegations about malicious cyber activities targeting democratic institutions and electoral processes. I thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Finland. Egypt, to be followed by Brazil. Egypt, please.

Egypt

Mr. President, at the outset, please allow me to extend my appreciation to you and to your team. I also thank the Secretariat for its efforts over the past two years in order to advance the Open-Ended Working Group’s work. We also commend the adoption of the second APR. This report is a roadmap for the period to come. In addition, we commend you and the Under-Secretary-General for Disarmament. We thank you for your opening statements. On existing and potential threats, we would like to note the following: One, the threats resulting from states and the criminal and terrorist groups that exploit ICTs to carry out attacks against the critical infrastructure and ICT-dependent infrastructure or to carry out any other sabotage or illegitimate act, particularly given the attribution-related difficulties. Two, the threats resulting from supply chain attacks. These have negative repercussions on economies, mainly the economies of developing countries. We would also like to note the threats related to digital identity, personal data theft, privacy breach, and misinformation campaigns that target individuals or countries, and these could also affect countries and their national security. Three, the transfer of malicious technologies and software to other countries or to non-state actors, including to terrorist groups. This transfer poses a threat to all, including the very countries that have developed these technologies. In this context, Egypt shares the concerns of many delegations on the fast-paced developments related to artificial intelligence users. We underline the importance of avoiding duplication and multiple tracks. The Open-Ended Working Group mandate should be respected. The group, if consensus is reached, can address AI exclusively from an international security perspective. Five, on a related note, it’s important to reach a common understanding of existing and emerging threats. In principle, we support the proposal for a repository of common threats. This proposal can be further developed and can help address the evolving uses of ICT. If agreement is reached, the repository could also contain a pillar on terminologies and common definitions of cybersecurity. This can bring opinions closer and can help reach a common understanding. Finally, also under the potential and existing threats, it’s important to support capacity-building efforts at the national, regional, and international levels by sharing expertise, best practices, and relevant technologies in order to raise awareness and encourage states to implement the existing consensus framework on the ICT use from an international security perspective. In this context, we would like to underline the positive role of the proposed National Point of Contact Directory. Thank you, Mr. President.

Ambassador Gafoor

Thank you. Egypt. Brazil to be followed by Croatia. Brazil, please.

Brazil

Thank you very much, Mr. Chair. Mr. Chair, at the outset, I would like to express my delegation’s appreciation for your work since the beginning of the mandate of this OEWG, and in particular for your tireless efforts to ensure the consensus adoption of our second annual progress report this past July. Rest assured of my delegation’s continued unwavering support to the OEWG and to you and your team in the discharging of your duties in this forum, which is of invaluable importance to Brazil. The malicious use of ICTs is one of the most complex challenges to international peace and security of our times. The pervasive use of these technologies, now present in nearly all dimensions of our lives and societies, has proportionally increased our vulnerability to malicious cyber operations. Specifically on the subject of existing and potential threats, the GGEs, the previous OEWG, and the current one have made important progress in the discussion of the most pressing threats posed by ICTs to our critical infrastructures and critical information infrastructures. We also appreciate the second APR’s inclusion of ransomware for the first time in this section. It is essential, given the great implications from many ransomware attacks to the security and stability of states, that the OEWG engage in deeper discussions on this issue, with a view to eventually making concrete recommendations to address this threat. While we welcome the discussion of this important issue in the Cybercrime Forum and are members of the Counter-Ransomware Initiative, this OEWG, as the UN forum with a mandate from the General Assembly to discuss threats and which congregates the entire UN membership, is the body with the legitimacy to establish universal guidelines on this subject. Similarly, we join other delegations which have raised the importance of the discussion under the OEWG of challenges to international peace and security presented by other emerging technologies, namely artificial intelligence and quantum computing. The international community is clearly concerned by these technologies, as evidenced by the many initiatives at the national and international levels that many countries have recently taken on both subjects. As with ransomware, we will have taken part in some of these processes due to the intrinsically multidisciplinary nature of artificial intelligence. Our international discussions of it should remain open and inclusive. This group, with its universal UN membership composition, is the forum best suited to a structured, long-term discussion on the security aspects of artificial intelligence, including those related to its military applications. In the cyber realm, which has been transnational since its inception, international cooperation is even more important to countering threats. This includes capacity building, which we will specifically discuss later this week, but which has also been recognized in the second APR as a cross-cutting element to all issues under the OEWG’s mandate. CBMs, such as the establishment of the Global Directory of Points of Contact, as well as those taken in regional contexts, are yet another powerful tool. We also positively view some proposals made by other delegations within the group, such as the creation of a threat repository and the adoption of a common terminology, and are open to further discussing those proposals. Thank you very much.

Ambassador Gafoor

Thank you very much. Brazil, Croatia, to be followed by Argentina.

Croatia

Thank you, Chair, and also many thanks to your team for dedicated and tireless work, which once again has resulted in the smooth and consensual adoption of this year’s Annual Progress Report. Now it is on all of us to implement what we have agreed. Croatia aligns itself with the intervention of the European Union, and in national capacity, we would like to emphasize several points. We welcome that many of the new threats, such as the unlawful usage of ICTs in armed conflicts, malicious cyber activities against critical infrastructure, supply chains, and political and electoral processes, as well as ransomware and DDoS attacks, are rightfully mentioned in this year’s Annual Progress Report. As many colleagues have already pointed out, the threat landscape is evolving rapidly in sophistication, scope, and numbers. Additionally, geopolitics continue to have a strong impact on cyber operations. Destructive cyber attacks are a prominent component of the operations by state and non-state actors, with often cascading and spillover effects. We have also observed a rise in hacktivism, as well as in using disinformation as a tool in cyber warfare. Another growing concern is related to a growing market of malicious tools and services for hire, and we agree with Ireland that cybercrime as a service is on the rise and we need to discuss it. As many countries already mentioned, ransomware is becoming a major challenge for the whole society, since it targets more and more national security interests, such as critical infrastructure and public bodies and services, having no regard for how impactful its disruption of essential social or economic processes or the trust in government institutions is. DDoS attacks are also getting larger and more complex, and they are as well being used in the context of cyber warfare. Their cascading effect can jeopardize the functioning of society and disable key processes. They are also detrimental to innovation and the development of new technologies. Furthermore, data breaches are increasing every year, and machine learning models, which are at the core of modern systems, are increasingly becoming a target of cyber attacks. These are just a few of the many new threats that are influencing our everyday life and significantly disrupting the normal functioning of our institutions and businesses, affecting also our citizens, and every year we are faced with new ones. In this regard, we cannot forget the potential impact of new and emerging technologies, such as AI, quantum, and blockchain, which are bringing new opportunities but also challenges for cybersecurity. If we want to address those challenges in the right way, close collaboration between the public and private sectors, research and technical community, and civil sector in this area is key, as well as establishing universally acceptable international standards and rules. Last week, the EU accomplished a historical milestone by agreeing on the AI Act, the first-ever set of rules on artificial intelligence, which will ensure that AI will be developed in a human-centric, transparent, and responsible way. Security by design is important, not just for AI systems, but also for IT devices. More cyber-secure products, as well as increasing cyber hygiene of our citizens and organizations, are a good path towards more resilience. Although some of the new technologies are discussed in other forums, we agree with El Salvador and Egypt that we need to address emerging technologies from aspects of international security also within this working group. And as Moldova, we also believe that a lack of awareness makes us more vulnerable, and through sharing national experience with different threats, we will be able to improve our own understanding and awareness. This working group, as well as the POC directory, are good platforms to exchange such information and lessons learned on existing and potential future threats. Many countries face cyber-attacks on institutions and democratic processes, which is especially sensitive during the election period. We would like to express full solidarity with the UK and stress once more that activities seeking to threaten the integrity and security, democratic values and principles, and the core functioning of democracies are unacceptable. All states should respect their obligations in implementing norms and principles of responsible state behavior in cyberspace. We need to invest joint efforts to reshape the landscape of cyberspace and to bring more security and stability through facilitating collaboration and the sharing of expertise, knowledge, and capacities among all relevant stakeholders. We agree with Colombia on the need to raise awareness and deepen understanding of existing and potential threats, and Kenya’s proposal on a non-contributional cyber threat repository is worth considering in this regard. Thank you very much.

Ambassador Gafoor

Thank you, Croatia. Argentina, to be followed by Ghana. Argentina, please.

Argentina

Thank you, Mr. Chairman. Since this is the first time that my delegation takes the floor, Argentina would like to greet you and your team and wish you every success during this week of work. We also wish to thank the program Women in Cyber Fellows and its donors. We believe that the successful promotion of the gender perspective in recent years has meant that this now has an important place in the Open-Ended Working Group. Mr. Chairman, in this year’s APR, the states reiterated their concern over the increase in incidents related to the malicious use of information technologies. My delegation wishes to emphasize the following points in response to your questions. With regard to your first question, Argentina believes that the main threats which we must address in our country are not separate from what happens in the rest of the world, mainly because of the global nature of cyberspace and the transnational nature of cyber incidents in all their forms. Threats to cyber security have affected not only public institutions and the private sector but also our citizens. This increase is seen in the number of recorded attacks and also in terms of their intensity and sophistication. In this context, the ecosystem of vulnerabilities of critical infrastructures has been considerably expanded, and this is a concern which is shared by the state and also the private sector and civil society. The cyber security divide is an obstacle to the delivery of essential services to our citizens in energy, communications, health, transport, financial services, security, among others. In this regard, experts have said that Latin America suffers more than 1,600 cyber attacks per second, and approximately 14 percent of ransomware attacks in 2022 took place in our region. Phishing attacks, ransomware, and zero-day attacks are some of the most common ones. The Argentine delegation is pleased to see that these threats have been included in the last APR. On the other hand, the existence of new technologies and their applications such as AI, big data, cloud computing, the Internet of Things, and quantum computing offer enormous opportunities for innovation, but they also amplify the possibilities for attacks and can still create unknown risks. Governments and stakeholders must work together to develop a solid understanding of emerging risks in terms of cyber security. Argentina believes it important to create synergies and points of convergence to move forward on public policy and regulations so that our countries may continue to make progress in technological development. My delegation believes that the point of departure for this convergence should be human rights. Technological development must be placed at the service of individuals and not the other way around. The intrinsically complex nature of the digital ecosystem, together with the many dimensions of public cyber policy, have contributed to a defying architecture of stakeholders. This cooperation means that we have to think outside the traditional boxes. Cooperation with the many stakeholders must be inclusive and multi-sectoral. Furthermore, taking into account the digital divide which exists among our countries, and in order to build a resilient digital architecture, technical assistance for capacity building in the area of threats is also needed. Our country understands that capacity building is a confidence measure among states. It contributes to consensus building, and we believe that actions such as exchanges of experiences, dialogue with other stakeholders by way of panels of experts, or as indicated in the APR, the repository of threats which has been proposed by Kenya – all of these can work toward a better understanding of the impact of new technologies on cyberspace. Thank you.

Ambassador Gafoor

Thank you, Argentina. Ghana, to be followed by China. Ghana, please.

Ghana

Mr. Chair, thank you for giving me the floor. My delegation appreciates your steadfast leadership and guidance of the Open-Ended Working Group throughout the year and towards the adoption of the Second Annual Progress Report, which marks a significant achievement of this OEWG. Ghana remains committed to fostering consensus during this substantive session and actively contributing to the discussions of this working group. Mr. Chair, Ghana is of the view that the set of guiding questions you have provided serves as a good basis for our discussions in this substantive session. We are therefore prepared to carefully consider the perspectives of our delegation on these matters. In response to the guiding questions on new developments or trends in existing and potential threats, Ghana continues to recognize that the advent of the Fourth Industrial Revolution and the increasing use of technology, specifically AI, Internet of Things, ubiquitous connectivity, blockchain technology, among others, continue to pose risks to international security, despite the significant benefits they offer, which has been mentioned in earlier submissions. Additionally, my delegation underscores a growing concern related to deep fakes. These deceptive practices utilize AI and deep learning techniques to manipulate content such as images, videos, or audio recordings, presenting them in a manner that seems genuine. The inherent risk lies in their potential to escalate conflicts by disseminating information and disinformation. It is therefore important to have comprehensive discussions on effective strategies to address these issues during the substantive sessions of this OEWG. Additionally, my delegation stresses the need for relevant experts invited by the OEWG chair to engage in focused discussions on advancements in new technologies such as quantum computing and artificial intelligence. We believe the exchange of views would enhance our understanding of the potential impact. We also wish to reiterate our support for Kenya’s proposal to establish a threat repository within the United Nations as it would contribute to global awareness of existing threats and a deep understanding of potential risks. Furthermore, we believe the other initiatives that could be explored at a global level to tackle cyber threats include the development of international guidelines for the design and deployment of ICTs. These guidelines should promote security by design and address issues such as privacy, security, and accountability. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you very much, Ghana. China to be followed by Chile.

China

Thank you, Mr. Chair. First of all, China is willing to take this opportunity to thank Mr. Chair for your very rich opening speech this morning. And also, I thank you for leading OEWG in reaching two annual progress reports. China will continuously support the work of OEWG and Mr. Chair, and also we want to be constructive and proactive in promoting the work of OEWG in the new year to reach consensus. Combining the guiding question number one proposed by Mr. Chair, in terms of emerging threats, China believes that global cyberspace is faced with militarization, fragmentation, and many other threats. The current international order in terms of cyberspace is at the risk of breaking down. A handful of countries are upholding the Cold War mentality and also expanding the concept of political security and using the pretext of competition to achieve the purpose of monopoly. But actually, they are conducting digital monopoly and also blockading the development of technologies of other countries. They are fragmenting the supply chain and industrial chain of the international digital industry. The global cyberspace is facing difficulties and challenges in terms of dividing into different camps. A handful of countries are blatantly developing attacking forces or technologies. As a non-party to the conflicts, they openly claim that in armed conflicts they have aggression against nuclear countries, and also openly declare and claim offensive cyber attacks, and also openly claim that critical infrastructure can be considered a target of a tactical attack. Military alliances have been introduced into cyberspace, exacerbating the risk of further escalating the situation and threatening international peace and security. Some countries are enthusiastic about establishing small circles while excluding some other countries. Even in terms of a global challenge like ransomware, some countries are still trying to do the same. Some countries are still excluding certain countries in establishing small circles. At the same time, some countries, in terms of the responsible behavior of cyberspace, choose whatever fits and is beneficial for them. They take the lead in not upholding the consensus of the UN, and they are compromising the current order in terms of international cyberspace. Some countries are using ICT technologies to spread misinformation and interfere in the internal affairs of other countries, affecting the political stability of other countries. I want to emphasize that spreading misinformation, interfering in the internal affairs of other countries, and even subverting other governments are not something new. These countries previously used shortwave radios or newspapers, which were traditional media, to achieve this purpose. But currently, they are using cyberspace and social media to achieve the same purpose. Combining the guiding question number two proposed by Mr. Chair in terms of new measures and recommendations to address the challenges, China recommends that, first of all, we have to comprehensively observe and follow the international orders in the sphere of cyberspace, observe and implement the current rules, and also follow the international orders in the current order. The responsible behavior framework for cyberspace is something that doesn’t come by easily in the past 25 years, and it is the solemn political commitment made by member states of the UN. It is not voluntary recommendations. It is not just a guiding principle. It is not just a guideline. China was among the first group in proposing that we have to follow the responsible behavior framework. We need to observe and implement this and also promote the inclusion of this into the two annual progress reports of OEWG. On top of that, China recommends that OEWG adopts new measures to convert the political commitments into legally binding rules or forms so as to better safeguard the current international order and authorities of international orders in the space of cyberspace. Secondly, we have to voluntarily adapt to the situation and improve international rules and norms. OEWG’s second annual progress report pointed out that given the increasing amount of data as well as the development of new technologies, data protection and data security become ever more important. China in 2020 proposed the International Data Security Initiative, and also with the AU and five Central Asian countries, we have reached initiatives in terms of cooperation in this area. We hope that OEWG can consider the recommendation and initiative proposed by China as a blueprint in terms of how to address the challenges so as to kick off a substantive discussion in this regard. At the same time, OEWG should clearly oppose the establishment of different small circles and different standards beyond the scope of the UN. Lastly, in terms of emerging risks and threats, China believes that what is outstanding is the development and peaceful use of technologies. Some countries are abusing the pretext of national security in coming up with discriminatory standards as well as export control measures to interfere with the development of other countries’ enterprises. At the same time, data security is about the security – this is a good example – of the security of data. This is a common and fundamental issue when it comes to the development of emerging technologies, including artificial intelligence. Also, this is an important topic within the mandate of OEWG. If we’re going to discuss the threats of emerging technologies, we should first of all discuss in terms of public interest and data security, what are the implications on these different areas. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you, China, for your statement. Chile to be followed by Belgium. Chile, please.

Chile

Thank you, Mr. Chairman. My cordial greetings to you and all those present, and our best wishes for a good negotiating session. I take this opportunity to thank the Secretariat for its work in preparing for this session. Chile reiterates its view that illicit activities in cyberspace are a clear threat to international peace and security. They can affect all states depending on their levels of security and resilience with regard to their technology’s structure and development. We underscore that these threats can also affect different groups and entities differently, with special consideration given to women, girls, and adolescents. We therefore consider it relevant to work jointly among states to exchange experiences in order to reduce digital divides so as to address emerging, present, and potential threats. The properties and characteristics of new and emerging technologies also expand the areas for attack, and they create new vulnerabilities which can be used maliciously in cyberspace. The extraordinary characteristics of these emerging technologies have expanded the scope of cyberspace, and there are greater capacities. However, the expanded infrastructure of the networks also entails greater vulnerability for illicit activities. In the same way, the enormous amount of data becomes increasingly the object of attack and exploitation. Following your guiding question, sir, in terms of new trends and developments with regard to threats which the group could discuss in depth, as other delegations have mentioned previously, I would mention the advanced use of artificial intelligence, which is making progress in the development of intelligent malware and attacks to elude security protocols. The increasingly sophisticated and sustained attacks on supply chains are of particular relevance in guaranteeing the capacity for resilience of our states since they themselves are the object of attacks during areas of vulnerability, for example, after an internal crisis or at the time of a climate change disaster, something we have felt in my country. Social engineering such as phishing and other personalized attacks, the continued and sustained use of ransomware including malware wiper, malicious activities and attacks by states, especially those which affect the critical infrastructure and humanitarian institutions. Malicious and cyber attacks against space, technical structures which may be essential to the integrity of the internet. Quantum attacks and the need for new algorithms should be resistant to these attacks. Malicious attacks which exploit the internet of things and cloud computing, among others. Threats to democracy, as was stated by the European Union, its member countries, and other delegations during electoral processes. The integrity of government institutions and the use of artificial intelligence to disseminate confidential information and/or false information. As democracies, we need transparency, security, and trust at all stages. This is fundamental to state guarantees toward our citizens. We would also like to echo what was mentioned by Australia on the recent 75th anniversary of the Universal Declaration of Human Rights, its full existence, and the need to bear in mind and orient it to results. With regard to the implementation of cooperation measures to address these threats and potential initiatives which could be taken globally, we would like to mention the following. States can generate frameworks for cooperation to exchange information, bilateral, multilateral, and above all regional meetings, technical meetings, together with coordinated work with the private sector and other stakeholders to use national points of contact networks. Also, we need to generate greater capacities on cyber intelligence together with efficient mechanisms for the exchange of information and adapting this to regulatory national frameworks when appropriate. States should also have permanent programs of training, especially for government entities. There should be coordination plans and structures not only at the government level but also to develop effective partnerships with civil society, academia, and the private sector. Our country supports the convening of a specific meeting on current and potential threats intersessionally with the participation of all stakeholders. Thank you.

Ambassador Gafoor

Thank you, Chile. Belgium, to be followed by Denmark. Belgium, please.

Belgium

Mr. Chair, my country aligns with the statement delivered by the EU. We wish to stress the following elements in our national capacity. Cyber threats have intensified and evolved significantly this last year, in the context of the use of ICT in conflicts in contradiction with the framework of responsible state behavior in cyberspace. Keeping in mind the evolving nature of cyber threats and the rapidly growing threat landscape, we cannot stress enough the fundamental character of the threat pillar of our group’s work. As cyber incidents are still taking place at a rapid pace in different regions of the world for political reasons, there is often a link to the war of aggression against Ukraine. For criminal reasons, we are deeply convinced that the work of the Open-Ended Working Group on Responsible State Behavior in ICT is absolutely meaningful. On the other hand, time is flying, and the need for a new formula is critical. We reiterate, therefore, our support for a Program of Action dealing with implementing the framework for responsible state behavior in cyberspace. I take this opportunity to congratulate the 158 countries which voted for the resolution, showing an overwhelming desire to make concrete progress in order to have a cyberspace that is safer and more secure. My delegation also stresses the importance of ransomware, the emphasis on threats to critical infrastructure, and the need for further work on new technologies, AI, and quantum computing. We find particularly important the threats to political and electoral processes, as well as the spatial evolving context such as the increasing use of ICTs in armed conflicts and against humanitarian organizations. We believe that our work should also take into account a victim-based approach. People and individuals are suffering from cyberattacks. People die in hospitals because of ransomware or cyberattacks. People are deprived of basic services because of cyberattacks on critical infrastructures. We should also put the victims of cyberattacks, human sufferings, and their humanitarian impact at the center of our attention. Therefore, we recommend envisaging a victim-based approach in our works. Interested delegations can reach out to our Belgian desk. The growing risk linked to a possible technical internet fragmentation also constitutes a potential threat to the implementation of the Framework for Responsible State Behavior in Cyberspace and International Peace and Security, which should be examined by this group. Fragmentation also raises cybersecurity risks as it creates vulnerabilities in the global internet infrastructure, making it more difficult to address the threat collectively. The preservation of an open, interconnected, and secure internet is key to fostering trust, cooperation, and accountability among states. We find particularly important the threats to political and electoral processes. Together with the EU, Belgium strongly condemns malicious cyber activities targeting democratic institutions and electoral processes. We closely monitor any attempt of cyberattacks on our democratic processes, especially in the context of the upcoming European and national elections. As pressure is mounting on democracy globally, we continue assisting and working with partners against these ongoing cyber threats. In this vein, the European Union and its member states share the serious concern of the United Kingdom and other partners, as stated in their declaration on December 7. We hereby express our full solidarity. Activities that seek to threaten our integrity and security, democratic values and principles, and the core functioning of democracies are unacceptable. Accountability is key. Those activities are contrary to the norms of responsible state behavior in cyberspace, as endorsed by all UN member states. We continue to promote due diligence and responsible state behavior in cyberspace and call upon all states to comply with these norms and principles. We have called out against those activities before. For instance, in 2020, the EU imposed sanctions on those responsible for the act of the Bundestag. In 2021, the EU made a declaration strongly denouncing malicious cyber activities collectively designated as ghostwriters, targeting numerous electoral processes in different EU member states. The European Union and its member states have the responsibility for and are determined to protect and defend our electoral and political processes. We remain vigilant and ready to undertake any action necessary from the EU cyber diplomacy toolbox, including sanctions to prevent and respond to unacceptable cyberattacks. Belgium will chair the Council of Ministers of the European Union for the first six months of 2024 until the 30th of June 2024. Belgium expresses its stance to the outgoing Spanish presidency. Building on the recent achievements, the Belgian presidency is dedicated to enhancing the EU’s cyber posture, aiming for an open, free, global, stable, and secure cyberspace by mainstreaming cyber diplomacy objectives throughout the overall foreign policy, defense, and development agenda. The presidency aims to further the EU collective capacity to prevent, defend against, and respond to malicious activities. As part of this commitment, the presidency intends to promote closer cooperation with NATO. It will also aim to facilitate the development of an adequate framework for engaging with the private sector in cyber-related matters. The Belgian presidency will also promote EU digital and cyber diplomacy through dialogues, partnerships, and capacity building within EU countries with a particular emphasis on Africa. It will strive for a strong European commitment to effective multilateral cooperation in relevant organizations and fora, such as the UN, the ITU, and the UN Summit of the Future. Lastly, the Belgian presidency will support strengthening the EU digital and cyber cooperation with the United States, the United Kingdom, and other close partners. This will be facilitated through mechanisms such as the Trade and Technology Council and cyber dialogues. Finally, I would like to underline that cyberspace is not a lawless space. We affirm firmly our position that international law, human rights law, and humanitarian rights law apply in cyberspace. Belgium is currently preparing its national position on the application of international law to cyberspace and intends to present it to the Open-Ended Working Group at our next session in March 2024. I thank you for your attention.

Ambassador Gafoor

Thank you, Belgium. Denmark, to be followed by Ukraine. Denmark, please.

Denmark

Mr. Chair, thank you. Esteemed colleagues, I would like to start by underlining that Denmark, of course, fully aligns itself with the statement previously delivered by the EU. Hence, what will follow will be in national capacity. Generally, we must know the threats in order to counter them, and we must find a common understanding of the threats we face in order to jointly improve security and stability in cyberspace. Malicious cyber activity continues to increase in scope and complexity, which has been pointed out by a number of colleagues here today. Russia’s illegal and unprovoked invasion of Ukraine illustrates this in real time. Russia’s cyber capabilities have been weaponized in Ukraine in an attempt to undermine trust in authorities and to destroy critical infrastructure in clear violation of international law and the framework for responsible state behavior in cyberspace. Let me use this opportunity to highlight cyber attacks targeting democratic institutions and electoral processes as well. 2024 has been announced as perhaps the biggest elections year in history. Elections to the European Parliament lie ahead, among many others. As such, I think it’s pertinent for us to discuss the malicious cyber activity that may threaten these elections. Recently, we’ve seen the UK attribute several cyber attacks on democratic processes to Russia. Along with our EU partners, Denmark strongly condemns malicious cyber activity targeting democratic electoral processes. It is a clear violation of the framework for responsible state behavior endorsed by all UN member states. We call on all states to comply with the framework and their due diligence obligations. The infrastructure that underpins electoral processes is essential to the functioning of democratic societies and, as such, critical to our security. Finally, I’d like to stress the threat from new technologies, not least AI. While AI will help us improve cyber security, it will by all accounts also enable more advanced cyber attacks in much greater numbers. Thank you, Chair.

Ambassador Gafoor

Thank you very much, Denmark. I give the floor now to Ukraine, to be followed by Guatemala. Ukraine, please.

Ukraine

Thank you, Mr. Chair. Ukraine aligns itself with the statement delivered by the European Union, and now we would like to make a statement in our national capacity. Ukraine fully supports the framework for responsible state behavior in the use of ICTs elaborated through the consensus reports of the UN Group of Governmental Experts and Open-Ended Working Group, as well as the Open-Ended Working Group’s 2022 and 2023 annual progress reports. It is important to stress that according to the agreements reached, all states are required to uphold and implement the framework for responsible state behavior in cyberspace, including international law, which is applicable to the cyber domain. Despite the existing commitments and significant work undertaken at the international level to advance a free, open, peaceful, and secure cyberspace, we are witnessing an increased number of incidents involving the malicious use of ICTs, such as malware attacks, as well as cyber operations against critical infrastructure. Throughout the last decade, cyber attacks have evolved significantly as a means in armed conflict, becoming one of the most serious threats to international peace and security. In addition, the continuing increase in incidents involving the malicious use of ICTs by non-state actors, including terrorists and criminal groups, is another disturbing trend which testifies to the need to properly address all these challenges to cyberspace. Mr. Chair, Ukraine strongly condemns malicious cyber operations targeting democratic institutions and electoral processes. In this regard, we express our full solidarity with the United Kingdom in light of the most recent cyber attack conducted by Russia. The ongoing aggression of the Russian Federation against Ukraine is accompanied by large-scale cyber attacks. State and local authorities’ information resources of the security and defense sectors, the energy, financial, and commercial sectors, as well as the IT infrastructure and the transport industry, are the main targets of Russian hackers. Throughout the first half of 2023, the media sector of Ukraine has also been subjected to persistent attacks. The goal behind those cyber operations is to gain control over media resources and accounts, intending to employ them for disinformation campaigns and influence operations. In October-November 2023, with the beginning of the new heating season and the absence of success in open military actions against the defense forces of Ukraine, the Special Services of the Russian Federation have intensified cyber attacks against critical infrastructure of Ukraine, primarily objects indispensable for the survival of the population. Russian actors use a variety of methods to gain initial access to their targets. These can be phishing campaigns, the use of unpatched vulnerabilities, and supply chain attacks. The main purposes of these malicious actions are to conduct intelligence operations, long-term espionage, and destroy data. Analysis of cyber incidents recorded by the Computer Emergency Response Team of Ukraine in 2023 suggests that the most serious and destructive attacks are waged by the groups belonging to the main directorate of the General Staff of the Armed Forces of the Russian Federation. In addition, targeted cyber attacks are carried out by groups associated with the FSB of Russia, in particular Gamaredon Group, which carries out espionage for the purpose of gathering intelligence data. Thanks to the efforts undertaken by Ukrainian governmental agencies in response to Russia’s cyber attacks and ongoing cooperation of our country with other states, a significant number of cyber attacks have been managed to be mitigated in time at the stage of initial access. Mr. Chair, touching upon the potential threats in cyberspace, we would like to stress that the dynamics of the developments in cyberspace indicate that in the future, cyber attacks against critically important systems of Ukraine will only intensify. Moreover, we may expect a significant rise in sophisticated cyber attacks by Russia, including with the use of artificial intelligence. Based on the existing context, observations, and lessons learned by Ukraine, we may also expect that the companies developing software for critical infrastructure and the military sector will be actively targeted in the long-term perspective. At the same time, hackers are also intensifying the complexity of their attack chains. They are leveraging advanced techniques to create more intricate attack scenarios, which includes the development and deployment of highly sophisticated malware. In addition, malicious actors are becoming increasingly cautious and therefore trying to avoid detection, in particular by refraining from deploying custom malware that could raise alarms. To conclude, Mr. Chair, Ukraine strongly believes that the OEWG should pay more attention to the malicious use of ICTs in the context of armed conflict. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you. Ukraine. Guatemala, to be followed by Greece. Guatemala, please.

Guatemala

Thank you, Mr. Chairman. Permit me to begin by thanking you and your team for coordinating this sixth substantive session of the OEWG. The development of information technologies is growing, importantly with the need to deepen the knowledge and strengthen national capacities and cooperation on cyber security. Cyberspace has become a central area essential to global activity because of its civil and dual-use possibilities. It has been used by criminal groups, interconnected networks, and the digitalization of the global economy has opened up spaces for violations of cyber security to present significant threats in the area of security and the economy. There are existing and potential threats. While in the second APR work areas were described, we must continue with plans to counter the most pressing challenges. My country views with concern the problems with the ICT networks which can be exploited by malicious actors to negate services or to undertake illicit activities. The lack of updated software and the lack of implementation of adequate protection measures exponentially increase the risk. Mr. Chairman, we have witnessed cyber attacks which go from phishing and identity theft all the way to ransomware. All of these crimes can affect individuals as well as companies, generating significant impacts for the economy and national security. We see the need to redouble our efforts to protect critical infrastructure such as electricity networks, transport systems, and others which seem to be attractive targets of malicious attacks. No doubt these attacks have a high impact on society. They interrupt essential services and cause important damages. For my country, it’s extremely important to strengthen public and private cooperation so that together we may prepare norms and methodologies necessary for capacity building given these threats. This is imperative to have better responses for these incidents. Lastly, sir, we remind all states that ICTs must be used peacefully and for the common good of mankind, promoting the sustainable development of all countries irrespective of their scientific and technological development level. Thank you.

Ambassador Gafoor

Thank you, Guatemala. Greece, to be followed by Costa Rica. Greece, please. Mr. Chair.

Greece

Next speaker, please, to be followed by France. Next speaker, please, to be followed by France. Next speaker, please, to be followed by France. Next speaker, please, to be followed by France. Next speaker, please, to be followed by France. To conclude, let me assure you that Greece remains highly committed to this process and to our common goal for an open, secure, peaceful, and accessible cyberspace governed by national law, where human rights, fundamental freedoms, and the rule of law fully apply. I thank you.

Ambassador Gafoor

Thank you. Greece, Costa Rica, to be followed by Qatar. Costa Rica, please.

Costa Rica

Thank you, Mr. Chair. I would like to highlight three areas in which the Working Group can deepen its understanding of the threats, as decided in the second annual report. One, as we have expressed in previous sessions, Costa Rica experienced ransomware attacks that paralyzed essential services and significantly affected our population. These incidents have also happened in other countries in recent years, which shows us the urgency of addressing this threat in depth. Costa Rica considers it essential to include ransomware as the biggest current global cyber threat in order to develop prevention and response strategies at a global level. For this reason, we emphasize that ransomware should be included in the intersessional meeting dedicated to threats which we have decided to organize in the second annual report. Two, we recognize that threats in cyberspace have direct consequences for human rights, especially privacy and freedom of expression. Costa Rica advocates close collaboration with stakeholders to understand how these threats disproportionately affect vulnerable groups and women. Policies and measures designed to address these threats must be inclusive and evidence-based. It is crucial that we view human rights violations as a threat in and of themselves. The panel should work with stakeholders to better understand how various existing and emerging threats can affect human security, with a particular focus on groups that experience disproportionate impact. Three, in this Working Group, it is essential not to limit ourselves to considering current threats, but also to anticipate and address those that may emerge in the future. Technology is advancing at a rapid pace, and we must anticipate emerging threats with a proactive approach. For example, we must study the potential effects of artificial intelligence on cyber security. Fortunately, applications of AI and machine learning are already being developed to prevent cyber attacks, but we must also understand the threats that can arise from malicious uses. Mr. Chair, let us continue to use this OEWG to share timely information for policy formulation, decision making, and implementation of security measures, as well as to increase understanding, knowledge, and information about cyber security challenges associated with new technologies. Only through global collaboration and the implementation of proactive measures can we strengthen cyber security and safeguard fundamental rights in cyberspace. Thank you.

Ambassador Gafoor

Thank you very much, Costa Rica. Qatar, followed by Japan. Qatar, please.

Qatar

Mr. Chairman, as my delegation is speaking for the first time at this meeting, allow me to express our thanks to you, Mr. Chairman, for your chairmanship of the 2021-2025 UN Open-Ended Working Group on developments in the field of information and telecommunications. We shall continue to cooperate with you towards the desired results. There is a need, Mr. Chairman, to discuss the threats—security threats that come through the increasing use of AI and emerging technologies in the Open-Ended Working Group, particularly concerning the changes of threats related to ICT and its secure use. We must also mention that modern technologies and AI may be an opportunity to solve some of these challenges in cyberspace. Mr. Chairman, this working group has an important rostrum for multilateral solutions on the threats and opportunities that come from the development of AI and emerging technologies. States have stressed the urgent need to increase awareness and deepen understanding of current and potential threats. This was also mentioned in the second APR. There is also the need to continue developing collaborative measures to confront these threats. There are many opportunities as examples—awareness campaigns, workshops, conferences, as well as multilateral cooperation in building capacities. In conclusion, these threats, whether current or potential, through the use of modern technologies, are interconnected and complicated. We must have a unified approach. Our collaborative efforts must stress the exchange of knowledge and development of modern technologies in cybersecurity. Thank you, sir.

Ambassador Gafoor

Thank you, Qatar. To be followed by Japan and then Venezuela. Japan, you have the floor, please.

Japan

Mr. Chair, since this is the first time that my delegation is taking the floor, Japan would like to express our appreciation for all the efforts you and your team have made to convene the sixth substantive session of the Open-Ended Working Group. Cyberattacks have been used constantly to disable or destroy critical infrastructure, interfere in foreign elections, demand ransoms, and steal sensitive information, even in the form of state-sponsored cyberattacks. In this context, as other delegations mentioned, cyberattacks against democracy are totally unacceptable. We would also like to reiterate that in the second annual progress report, we are particularly concerned about the increase in malicious ICT activities impacting critical infrastructure, including the healthcare, maritime, aviation, and energy sectors. In order to ensure secure and stable use of cyberspace, especially the security of government systems and critical infrastructure, our cybersecurity response capabilities should be strengthened. Mr. Chair, ransomware is one of the most serious cyber threats disrupting the operations of hospitals and businesses in almost every sector of economies around the world. The scale of the attacks is global, and it is growing. In Japan, the reported cases of ransomware incidents have increased by 58 percent from 2021 to 2022. We need to fight together against ransomware actors, including through the International Counter-Ransomware Initiative and other efforts. As other delegations pointed out, we would also like to raise emerging challenges to address attacks targeting cryptocurrency markets and cryptocurrency theft by threat actors. Mr. Chair, a preventive measure we can take is to emphasize to all states the importance of adhering to the framework of responsible state behavior in cyberspace. Giving the public information about the existing risks is an important preventive measure as well. In this context, Japan has also issued alerts to the public that there is an increased risk of cyberattacks. However, cybersecurity cannot be ensured by a single country alone, nor can it be sufficiently ensured by government efforts alone. States can work together with other states and the various stakeholders to share threat awareness to protect against malicious cyber activities. This can also be done through regional frameworks, such as the ASEAN Regional Forum, and globally utilizing the Open Networking Group. In addition, networks among CSIRTs and CSARTs are important to share threat information in real time. Japan will continue to make efforts to fight against cyber threats and to pursue a free, open, and secure cyberspace with other states and the various stakeholders. I thank you, Mr. Chair.

Ambassador Gafoor

Thank you. Japan, Venezuela, to be followed by South Africa. Venezuela, please.

Venezuela

Thank you, Mr. Chairman. We refer to ICTs. These are a source of threats which can be large-scale nationally and internationally. They have the potential of thwarting peace, international peace and security, and sustainable development. Rapid technological evolution and actors’ use of ICTs show the complexity of existing threats. Informatics in all its forms, cyber-espionage, cyber-attacks on critical infrastructure and cyber-data, false information, large-scale and communication blocks, are some of the threats that affect sovereignty, economic development, and place risks on international peace and security. The Bolivarian Republic of Venezuela firmly shares with other delegations the idea that any approach to present and potential threats must be compatible with the purposes and principles of the UN Charter and international law, in particular with the principles of sovereign equality, respect for the sovereignty of states, the peaceful settlement of international disputes, international relations with regard to acts against territorial integrity or the political independence of any state, and non-interference in the internal affairs of states. My delegation believes that disputes which derive from the use of ICTs must be resolved by peaceful means in the framework of international law. Venezuela continues to reaffirm the concept according to which states bear the primary responsibility of maintaining a secure and peaceful domain in the area of ICTs in accordance with their national laws, their policies, plans, and programs, and in order to safeguard the interests of their sovereignty, their security, sustainable development, and the common good of their citizens. At the same time, we reject the proliferation of doctrines and national security policies which militarize cyberspace and which legitimate the use of force even by invoking self-defense with regard to cyber-attacks. In dealing with threats in cyberspace, states must have common terminology which standardizes an understanding of the phenomena being referred to, and they must consider matters of crucial importance. Firstly, the fact that faced with these phenomena, all states are vulnerable. Secondly, the existence of asymmetries and technological divides between states which are deepened by the implementation of unilateral coercive measures and flagrant violation of international law. For these reasons, as identified in the second APR of the working group, international cooperation and technical assistance can serve the international objectives of minimizing and neutralizing threats. However, addressing threats and their consequences will require a global framework to guide the actions of states and which would be a legally binding instrument increasing confidence among all states of the organization. Thank you.

Ambassador Gafoor

Thank you very much, Venezuela. South Africa to be followed by Israel. South Africa, please.

South Africa

Chairperson, as we embark on the second half of the OEWG process, we would like to take this opportunity to commend you and your team for the outstanding manner you have been steering this working group. The two consensus progress reports are a testament to the effectiveness of your chairing and the potential of the Forum to yield positive and practical results to address the global challenges to international peace and security in the cyber realm. We agree with the delegations of India and Brazil that we have made good progress on the discussion on existing and potential threats to information and communications technologies, and we encourage the group to maintain the momentum. Chairperson, we have agreed in the OEWG on the need to protect all critical infrastructure and critical information infrastructure, supporting essential services to the public along with endeavoring to ensure the general availability and integrity of the Internet. South Africa has committed to the continued exchange of views and information on evolving threats to security in the use of ICTs at the OEWG, including cooperative ways of addressing them as Kenya has proposed. With growing connected Internet of Things devices globally with inadequate security infrastructure, the attack surface has grown exponentially. Governments and healthcare are deploying these systems, and without adequate security, attacks against these systems can lead to widespread disruption, panic, and put human life at risk. We share the view expressed by many delegations on the threat posed by the exploitation of technologies such as AI, quantum computing, and machine learning for malicious purposes with potential harmful impact on international peace and security. Chairperson, South Africa supports the recommendation of the second APR that the OEWG should convene a dedicated intersessional meeting with the participation of relevant experts invited by the OEWG chair and with due consideration given to equitable geographical representation on existing and potential threats to security in the use of ICTs. We thus propose the inclusion of IoT and AI threats and their possible impact on human life as an area of focus during the dedicated intersessional meeting. Thank you.

Ambassador Gafoor

Thank you, South Africa. Israel, to be followed by Mauritius. Israel, please.

Israel

Thank you, Chair, for giving me the floor. As it’s the first time that my delegation takes the floor during this round of OEWG deliberations, we wish to thank you and your team, as well as the UNODA, for their tireless efforts and dedication leading us through this process. We’d like now to present the Israel perspective on existing potential threats. Chair, on Saturday, October 7th, thousands of Hamas terrorists penetrated the southern border of Israel and massacred, burned, raped, stabbed, beheaded, and mutilated more than 1,200 innocent people – women, men, elderly, children, and babies. Entire families were slaughtered just because they were Jews. In addition, thousands more were injured and more than 240 innocent citizens were abducted and taken hostage by these terrorists. Israel has experienced cyber terror well before October 7th. However, after this heinous terror attack, rogue states and cyber terrorist attack groups like Hezbollah, Hamas, and other adversaries have intensified their attempts to launch cyber attacks against targets in the Israeli public, private, and government sectors. The attackers’ goal, as any other terrorist organization, is to spread terror by harming civilians and causing real damage. They’re using cyberspace to damage, among other things, our critical civil infrastructures to target energy installations, water systems, and even hospitals. Their terror actions should be condemned uniformly, also in this forum. As part of the effort to confront these attempts to spread terror, Israel has thwarted many attempts to penetrate cameras and billboards in the public domain, to gather information and influence, and to damage essential services, as well as numerous attempts to deny service or deface government and commercial websites and harm private sector entities and services. These actions and attempts violate the basic norms of responsible state behavior in cyberspace. Nations that are advocating and call for the implementation of these norms should all stand together today with Israel in condemning these harmful, malicious cyber attacks. An additional threat is the one posed by malicious actors using cyberspace to spread misinformation and fake news and engage in sophisticated phishing campaigns aiming to spread malware. This is particularly serious as it can directly threaten national security. Just like the campaigns perpetrated by Hamas cyber terrorists using cyberspace cynically and mercilessly to hurt the families of the victims in the most degraded and despicable form while trying to spread fear and stealing the hostages’ digital assets, we should work together to improve our capabilities to fight these and similar threats. Mr. Chair, the introduction and use of AI, and recently with the development of frontier AI, a new challenge emerges also to cybersecurity. The attack surfaces have increased significantly. AI models and data sets used by these models present new opportunities to adversaries. Publicly available generative AI enhances attackers’ capabilities. We will need to address the challenge of how to better secure AI models throughout their lifespan. This includes the need to secure AI development and data sets and safeguard the use of AI models. It should be mentioned that AI also holds great positive potential for cybersecurity, and we should work together to harness AI technologies for better cybersecurity and for building our collective resilience. We wish to highlight our basic premise that technology is neutral. There is no bad technology or good technology. Technology is, in and of itself, neither legitimate nor illegitimate. The emergence of new and very advanced technologies carries also many new opportunities and benefits, and the international community will need to find ways to balance the need of securing an open and free development of EDTs while mitigating the potential new threats that they pose. As for ransomware, we agree with many member states flagging that this is a very serious and growing threat. Israel is a founding member and takes an active role in the U.S.-led CRI, a multinational cross-regional coalition aiming to combat ransomware and cybercrime. We are very encouraged to see the active and leading role that the ICRTF, led by Australia, is taking in the joint efforts to enlarge the CRI membership. Diplomatic engagement together with professional cooperation continues to be essential tools for the international community’s fight against ransomware attacks. Israel is committed to continue work together not only with the CRI members but also with other partners committed to fighting the scourge of ransomware. Under this umbrella effort, Israel is leading together with the UAE and other states the development of a novel information-sharing platform called the Crystal Ball. Information sharing is at the heart of building cybersecurity and speed is of crucial importance. The goal of this system is to enable relevant and timely information sharing of data related to cyberattacks between countries in near real-time, connecting professionals and decision-makers, allowing many-to-many timely sharing of relevant operational information. The platform is designed to connect to other relevant platforms and databases to allow for better multinational interconnectivity and inter-proliferate. Another phenomenon which we should take into consideration is the cooperation between rogue states, criminal actors, and terrorist organizations and proxies. Too often, criminals and cyber terrorists providing hacking as a service receive a type of safe haven which enables them to pursue their malicious activities with impunity. In this context, illicit financing of cyberattacks using cryptocurrency is a growing threat. This is an area where countries could collaborate to break this kill chain and block funding for malicious cyber activities. We believe that if we could develop an efficient mechanism to freeze and seize cryptocurrencies on a global scale, we could drastically prevent many of these cyberattacks. To conclude, Mr. Chair, Israel is looking to cooperate with other states on the prevention and mitigation of risks and threats in cyberspace, aiming at building together a stronger global resilience. I thank you, Mr. Chair.

Ambassador Gafoor

Thank you very much, Israel. Mauritius to be followed by Vietnam. Mauritius, please.

Mauritius

Chair, good afternoon, and thank you for giving me the floor. The Republic of Mauritius would like to extend its gratitude to you and your dedicated team for your efforts in formulating a set of guiding questions that indicate how delegations could provide meaningful contributions to each agenda item of this meeting. Mauritius commenced the adoption of the second APR in July and would like to submit its remarks on existing and potential threats as follows. Cyber security has always been a cat-and-mouse game, but the mice keep getting smarter and are becoming progressively harder to hunt, especially with the advent of technologies such as artificial intelligence and quantum computing. Paradoxically, cyber criminals do not always need to discover new vulnerabilities or sophisticated methods of penetrating our networks. The traditional low-skill tactics, common tools, and the use of social engineering generally suffice to launch an attack. In this day and age, cyber attacks on systems that run utility plants, hospitals, financial services, transportation networks, and other essential services are persistent, and successful attacks often result in the disruption of economies. We are of the opinion that the protection of critical information infrastructure and preservation of the confidentiality, integrity, and availability of information in cyberspace are the essence of a secure cyberspace. Chair, we all strive to enjoy a resilient infrastructure and trusted cyber environment that provides cost-effective business, service continuity, sustained revenue, and uninterrupted delivery of critical services. Against this backdrop, various national and regional measures could be implemented, in particular at the level of small island developing states and African countries, in order to address cyber threats ranging from ransomware to AI-based attacks. Allow me to enumerate four of these achievable measures. Number one, the enforcement of a national critical information infrastructure protection policy that elucidates the cyber security responsibilities and accountability of critical sectors. Number two, the setting up of a national cyber attack early warning system that allows for timely detection and response to incidents. Number three, cyber security capacity building through training programs, tabletop exercises, and live simulations to help organizations prevent and respond to cyber threats, reduce vulnerabilities, and minimize the impact of incidents. And finally, number four, the establishment of or participation in information sharing and analysis centers, also known as ISACs, that allow two-way sharing of information between public and private sectors about root causes, incidents, and threats. In conclusion, I would like to take this opportunity to assure you of my delegation’s full support in current and future deliberations. I thank you very much, Chair.

Ambassador Gafoor

Thank you very much, Mauritius. Vietnam to be followed by Switzerland.

Vietnam

Mr. Chair, upon the first intervention this week, I would like to express my delegation’s gratitude to you and your team for the dedicated efforts throughout this process. I also wish to reiterate Vietnam’s full support for the work of the OEWG on ICTs. Mr. Chair, the rapid development of new technologies, from the inception in research laboratories to daily life applications, offers unprecedented opportunities for development and collaboration. Yet, it also brings forth new challenges to global peace and security. While we contend with our established cybersecurity concerns, the growing impact of emerging technologies, including artificial intelligence (AI) and quantum computing, cannot be overstated. The surge in interest in AI represents a momentous shift. AI has the capability to revolutionize our lives in ways that we have yet to fully comprehend. Recognizing these potential opportunities, Vietnam has been proactively enhancing policy frameworks and infrastructures to promote international collaborations in this domain. At the same time, we are acutely aware and concerned about the risks that these technologies carry. AI allows malicious actors to fine-tune ransomware and phishing tactics. It adds fuel to the proliferation and distribution of myths and disinformation in cyberspace. The fact that AI is being used in the military and security industries is no longer a possibility but is a reality. With that in mind, Vietnam would like to stress that the evolutions of AI must comply with international law, uphold the principles of UN Charters, and adhere to norms of responsible state conduct within cyberspace. Apart from security, the adoption of AI poses the risk of widening the development and digital gaps among countries. Therefore, the United Nations needs to play an essential role in shaping an AI governance framework that harnesses its potential to accelerate progress towards sustainable development goals while mitigating the risks it poses to sovereignty, national security, and human rights. Vietnam stands ready to be an active and constructive partner in the formation of a global framework that ensures member states’ equal access to AI benefits and share responsibility to address its challenges. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Vietnam. I give the floor now to Switzerland, to be followed by the Russian Federation. Switzerland, please.

Switzerland

Thank you, Mr. Chair. I would like to start by thanking you for your commitment and your guidance during these very important discussions, and your team for all the hard work in preparing this session. The last months have shown some incidents with severe impacts, namely attacks by criminal ransomware groups targeting critical infrastructure and suppliers, among them many hospitals or humanitarian actors, and publishing sensitive information, which in some cases might amount to a national security issue. In this regard, we also observe some criminal attack actors, which do offer and sell stolen data directly to underground marketplaces, inviting all interested parties to join the bidding. This development is of concern as it has the potential to further blur the lines between state and non-state actors. To tackle such risk, Switzerland is participating in the Counter-Ransomware Initiative, among others. Switzerland welcomes the fact that the APR mentions for the first time that ICTs have already been used in conflicts in various regions. This is a reality, particularly true in the war against Ukraine, and needed to be reflected in the report. Switzerland believes that the existing and potential threats to international peace and security that may arise from such use, as well as their compatibility with international law, in particular international humanitarian law, should be discussed further in depth in the Open-Ended Working Group. Still lasting are minimal impact attacks on websites in the context of the war against Ukraine executed by self-proclaimed patriots. While these attacks usually do not cause any worrisome impact, Switzerland would like to underline the fact that some of these attacks were also aimed at critical infrastructure providers and national CSIRTs. While coming from non-state actors, these attacks are still claimed to be done within the context of the war against Ukraine and in support of the warring parties. In this context, we do take note of increasing intensity regarding certain attacks, as well as a continuation of attacks potentially causing spillover effects, and by that having the potential of misinterpretation and heightened tension. The APR highlighted the risk posed by distributed denial-of-service attacks, and we have heard from other states, like Moldova, about their effects. This year, Switzerland was twice the victim of politically motivated DDoS attacks carried out by a self-declared pro-Russian hacktivist group. The actor primarily targeted authorities and organizations close to the federal administration and held in high esteem by the public, like the Swiss Parliament, the Swiss Post Office, and the Swiss Federal Railways, but also airports. Our National Cyber Security Center published a detailed analysis report on these DDoS attacks earlier in November. The report shows how these DDoS attacks were carried out and gives advice on how such attacks can be prevented or how their effects can be limited. Switzerland welcomes the fact that the second APR mentioned the challenges related to the Internet of Things. Most IoT devices are not designed with security in mind. Malicious actors can target IoT devices more easily and use them either to cause harm to the operator of the device or use them for malicious activities against states, companies, and citizens. To meet these challenges, we need to work together with other stakeholders. Like other countries, we therefore regret that some stakeholders were prevented from participating in this session again. As many other states, Switzerland is of the view that we should address the potential threat artificial intelligence can pose to cybersecurity and international peace and security. An exchange with other stakeholders is also important in this area, and we support the proposal to organize expert briefings during a dedicated session on emerging technologies to help us better understand the developments in the different areas, their opportunities, but also the risk or potential threats. Mr. Chair, Switzerland is concerned about malicious cyber activities targeting democratic institutions and electoral processes, and we share the concerns expressed by the UK and other states in this regard. Finally, Switzerland supports the Netherlands and Australia’s comments on the risks of malicious use of ICTs for international organizations. All states must help ensure that they can fulfill their role unhindered by such activities. Thank you.

Ambassador Gafoor

Thank you very much. It’s the Russian Federation, to be followed by Pakistan. Russia, please.

Russia

Mr. Chair, our delegation is compelled to take the floor to respond to unsubstantiated political attacks against Russia made by Western delegations. First, those who allow themselves such insinuations show disrespect for the chair of the group and all its participants. They waste the time that is meant to be used discussing the mandate of the OEWG. As a result, we have time pressure which forces the chair to speed up the statements of other delegates. This happens because of individual states that seek to turn discussions in the OEWG into a political fuss. Secondly, as was mentioned in our previous statement, any accusations leveled against states for malicious use of ICTs should be substantiated. Russia has not been provided with such facts. Specialized channels for the exchange of information between competent agencies have not been used either bilaterally or within the OSCE, as mentioned by the representative of Germany. Thirdly, NATO countries quite simply do not have the moral right to level any accusations against Russia. It’s your governments that develop doctrinal documents justifying offensive use of ICTs, practice scenarios of attacks against undesirable regimes, provide perpetrators with detailed instructions for computer attacks, and carry out or encourage electronic surveillance and interception of individuals’ data around the world. All that in violation of their false statements as to commitment to non-interference in internal affairs, defending democracy, human rights, and fundamental freedoms. It’s high time for NATO members to stop portraying Ukraine as a victim of aggression in the information space. We are well aware of their support to the Zelensky regime in terms of carrying systematic cyber attacks against the critical infrastructure of Russia. These are not groundless accusations. Our competent agencies record all such facts. Furthermore, the Ukrainian authorities themselves acknowledge the acts of sabotage committed by their country with the use of ICTs. Just last month, the State Intelligence Directorate of Ukraine’s Ministry of Defense claimed responsibility for cyber attacks against information resources of the Federal Air Transport Agency of the Russian Federation and the Russian Ministry of Labor aimed at stealing confidential data. There are many cases of the malicious activities using ICTs perpetrated by the so-called IT Army, a gang of cyber criminals and phone scammers controlled by Ukraine’s Ministry of Defense and supervised by Western countries led by the United States. We have warned on many occasions that this creature of Washington and its allies will turn against ordinary Europeans, and this is what happened in the end. In November 2023, the Hungarian authorities reported that most of the funds stolen in their country through ICT crimes, including telephone fraud, ended up in Ukraine. States should search for ways of settling contradictions and mutual claims by peaceful means. That would serve true interests of strengthening peace and security in the information space. There are communication channels between competent authorities, including Computer Security Incident Response Teams, CSIRTs, for that purpose. We hope that establishing a global intergovernmental points of contact directory will facilitate professional and depoliticized interaction among authorized agencies in terms of ICT security. Thank you.

Ambassador Gafoor

Thank you, Russian Federation. Pakistan to be followed by Estonia. Pakistan, please.

Pakistan

Thank you so much, Chair. Thank you for the opportunity to share our views on the critical issue of existing and potential threats in international information security. At the outset, let me express our deep appreciation to you for leading this group in an able and transparent manner, and to your team for the hard work. Pakistan attaches great importance to this OEWG, which is a platform represented by all member states and has the potential to make cyberspace secure, stable, and accessible for every country in the world. Chair, the second annual progress report has rightly taken stock of the existing and potential threats posed by the malicious use of ICTs by both states and non-state actors. Pakistan believes that the military application of ICTs has significantly accentuated the threats to international and regional security in recent times. We express concern over the rising trends of the use of ICTs to attack critical infrastructure, critical information infrastructure, exploitation of vulnerabilities, and supply chain-related attacks. We are particularly concerned about misinformation, fake news, and disinformation campaigns by states and non-state actors, which not only jeopardize regional and global peace and security but also give rise to social unrest. Chair, we also underscore the importance of discussing the growth of illegal markets on the dark web and open sources offering access to inter-area software vulnerabilities. We believe that states must discuss means and methods to curb the illegal activities on the dark web that have become a haven for cyber criminals. While appreciating the focus on critical infrastructure, we suggest a more balanced approach considering issues like global internet regulation, the digital divide, software piracy, cross-border data security, family vulnerability disclosure, and IT supply chain security. Chair, Pakistan is also confronting a multitude of threats posed by ungoverned cyberspace. Rising cyber attacks against critical infrastructure, distributed denial of service, data theft, and targeted disinformation campaigns are some facets of cyber security challenges that we face. Therefore, Pakistan consistently calls for a legally binding instrument to promote responsible behaviors in cyberspace. We also underline the challenge of preventing the exploitation of vulnerabilities in operational technology and interconnected devices within the Internet of Things for malicious purposes. Pakistan emphasizes the need to implement capacity building initiatives, which are key for developing countries. On the militarization of cyberspace, Pakistan’s position is consistent. We consider the internet as a common heritage of mankind, and the use of cyberspace must not be converted for military purposes. In conclusion, Pakistan reaffirms its readiness for enhancing interstate cooperation to effectively counter the threats posed by ungoverned global cyberspace. I thank you, Mr. Chair.

Ambassador Gafoor

Thank you. Pakistan, Estonia, please.

Estonia

Thank you, Mr. Chair, for giving me the floor. Dear colleagues, the cyber threat landscape has become more complex and challenging. In addition to financially motivated cyber criminals, state-sponsored cyber operations are on the rise. Several countries, including Estonia, are witnessing a steady rise in malicious cyber operations targeting public and private targets alike. Additionally, we can observe the increasing occurrence of ideological hacktivism as a global phenomenon. This has an effect on national security and international stability, as well as the way our societies operate. We are reminded that an open, secure, stable, accessible, and peaceful ICT environment cannot be taken for granted, and we must work on bolstering cyber resilience on domestic, regional, and global levels. Estonia is carefully monitoring the threat landscape, and we welcome an open exchange of views on the existing and potential threats and possible cooperative measures to prevent and counter such threats. We continue to be concerned by advanced persistent threats, ransomware, and supply chain attacks, among others. In the aftermath of Russia’s ongoing illegal aggression in Ukraine, the protection of critical infrastructure and services, as well as safeguarding the security of democratic processes, such as elections, is our utmost priority. On the 7th of December 2023, we, among many others, supported the United Kingdom in condemning Russia for their attacks against the UK’s democratic processes. The international community must not accept behavior breaching the obligations stemming from international law and norms of responsible state behavior. Part of the open-ended working group discussions focuses on how to prevent and counter cyber threats. Estonia believes that these discussions are increasingly relevant for all the countries in the world. Based on our own experience, we have learned that effective prevention and mitigation of cyber threats cannot be founded merely on one-off campaigns and trainings. Instead, this effort must be systematic and persistent. In order to enhance cyber resilience, we need to adopt a holistic view of cyber threats and keep in mind that the effective response depends on multiple aspects, such as policy frameworks, crisis management mechanisms, international cooperation, organizational aspects, legal frameworks, education, and general awareness, etc. Cyber security implications must be kept in mind when building information systems, establishing organizations, and designing domestic processes. One of our priorities is also to conduct trainings and exercises for the providers of essential services and critical infrastructure, as well as gather these providers for the exchange of information and best practices. Our National Cyber Security Centre focuses on enhancing cyber security of the public sector and protecting critical infrastructure, as well as being the competent authority and contact point for cyber security for the purposes of the EU Directive on Network and Information Security. We see that in today’s volatile security environment, we must all prepare for being a target of malicious cyber operations, and investing in prevention is more reasonable than having to deal with the costly consequences. Finally, I would like to underline that enhancing cyber security across society is a long-term project, which depends on the participation of different actors, such as the public and private sector, academia, and civil society. It is essential to nurture good cooperation and trusted partnerships within the domestic environment, as well as with our international counterparts. In addition, we underline the value of training, cyber hygiene, and awareness of the everyday user, as well as the education of younger generations. Thank you, Mr. Chair.

Unknown Speaker

Thank you very much. Estonia. I give the floor now to Sudan.

Sudan

Thank you, Chair, for giving me the floor and allowing me, at the beginning, to express my delegation’s support and appreciation for the constructive and action-oriented manner you have been following throughout the work of this Open-Ended Working Group. In response to your guiding questions regarding existing and potential threats, I’d like to share and agree with views expressed that similar threats seem to be targeting countries around the world at different speeds and scales. Let me now share some of the information and reports provided by the Ministry of Information and Telecommunication in Sudan. My country has faced well-organized crimes against the government and private sector, targeting the telecommunication and control infrastructure. These types of attacks focus mainly on DDoS, especially in banking and customer-related services. Moreover, with increased dependency on online payment services in the country, new types of money theft crimes have emerged, including phishing. What is really alarming is the use of ICTs for human trafficking and even terrorism by state and non-state actors. Recent reports show an unprecedented increase in the number of attacks, and this includes APT (Advanced Persistent Threat), denial-of-service attack, zero-day exploit, man-in-the-middle attack, botnet used to perform distributed denial-of-service attacks, in addition to spyware, ransomware, and social engineering. Although the national cyber policies included the ITU framework on cybersecurity, cyber crime fighting procedures, and the ITU impact global cyber approach, the mitigation of threats in cyber and ICTs requires more comprehensive and inclusive intergovernmental platforms to exchange information and best practices in a transparent manner. In this regard, we would like to support the proposal of dedicating an intersessional meeting for further exploring the way forward regarding existing and potential threats. Thank you, Chair.

Ambassador Gafoor

Thank you very much Sudan. I give the floor now to Mexico. You have the floor, please.

Mexico

Mr. Chairman, my country joins delegations which have thanked you for convening this sixth session of the OEWG. In your initial statement, you urged us to build on the basis of points of convergence among our positions in order to promote progress in our deliberations. The OEWG fully supports this approach and advocates for it being through collaboration that we organize our activities this week. Having listened to other delegations on current and emergent threats in the area of information security, including data protection and possible cooperation strategies to prevent and mitigate these threats, we reaffirm that the concerns we have identified and discussed previously continue to exist. Questions such as the use of malware, ransomware, data theft, in particular the protection of personal information, as well as the use of ICTs to interfere in national processes, including elections, the prevention of attacks, must continue to be priorities among our efforts. We also agree that the specter of threats is expanding, and we share the concern expressed by other delegations on how to address the challenges of emerging technological developments, such as artificial intelligence, generative artificial intelligence, quantum computing, cloud services, among others. It is imperative to deepen our understanding of these fields. Mexico believes it relevant to continue to explore the proposal of having a repository of cyber incidents as a way to understand common threats which touch on other processes underway within our organization and which are interconnected and mutually reinforce each other. This integrated perspective is key to avoid duplication of efforts. Mr. Chairman, cybersecurity should not continue to be an isolated topic, but rather part of an integrated dialogue which addresses aspects of cyberspace, cybercrime, and questions pertaining to foreign space, to outer space, and the development of autonomous lethal weapons. We believe that this space can benefit from the tasks and concerns discussed in other forums which are intrinsically related to cyberspace and which can enrich and complement our debates in this regard. We join the appeals of Chile and South Africa to convene a specific intersessional meeting with the participation of relevant experts invited by the presidency. As established in the second APR, we believe that such a meeting could benefit from expert voices from other forums which are taking place now. In conclusion, I wish to underscore the importance for Mexico of including in our deliberations all stakeholders, including civil society organizations, academia, private sector, among others.

Ambassador Gafoor

Thank you very much, Mexico. Thank you very much, distinguished delegates. I certainly do not intend to provide a summary. We have had, I think, nearly 55 delegations which have made statements. And obviously, this is also, in some ways, the first statement for many delegations. So I think quite a number of you addressed quite a few issues in addition to existing and potential threats and were connecting the dots with different aspects of the mandate of the Working Group. I’ve got two more speakers left. In fact, it looks like it’s three more speakers. But I’ve got a request for a right of reply, so I’m going to accommodate, I would have to accommodate that, in accordance with the rules of procedure of the Working Group. So I propose to take the remaining speakers tomorrow morning, and then we proceed with the next agenda, or rather the next item in the program of work, which would be rules, norms, and principles of responsible behavior of states. So we will start that tomorrow morning after we have completed the three remaining speakers. And I see that one of the three remaining speakers is a speaker who has already spoken this afternoon. So it is a speaker who wishes to speak again, I presume, on the same topic of existing and emerging threats. So we will hear the three speakers tomorrow, and I shall now call on those who have requested the right of reply. And in this connection, I would like to remind all delegations that the first intervention in exercising the right of reply is limited to 10 minutes, and the second intervention is limited to five minutes. So I give the floor now to the representative of Egypt. You have the floor, please.

Egypt

Thank you, Mr. President. I had to take the floor to exercise my right of reply on behalf of the Arab Group. We would like to comment and to respond to Israel’s delegate. Mr. President, it’s no secret that the Israeli occupation forces are perpetrating – have been perpetrating massacres and genocide against Palestinians over the past two months in flagrant violation of international law and international humanitarian law. This has led to humanitarian consequences that are beyond the imagination. More than 18,000 Palestinians were killed, including 70 percent of whom are children and women. In this context, I reiterate 70 percent of women and children. In addition, the Israeli aggression on Gaza has led to the displacement of more than 1.5 million Palestinians, i.e., around 85 percent of the population of the Gaza Strip. More than 60 percent of infrastructure and residential complexes were destroyed. This includes vital critical infrastructure as well as schools, hospitals, and UN facilities. It’s surprising that the Israeli delegation called today on the international community to condemn attacks on civilian infrastructure, while figures and facts that I have listed show that Israel, in fact, should be condemned. On a related note, and as part of the collective punishment policy perpetrated by Israel against the Palestinians, Israel has been violating the human right to life. Israel, too, and over the past two months has cut off water, energy, and telecommunication from Gaza. As a result, more than 1 million Palestinians were disconnected from telecommunications and internet networks. As a result also, the humanitarian catastrophe of the civilians in Gaza has worsened, and civilians now have difficulties in seeking help and treatment because of the ongoing Israeli assault. This is another flagrant violation of international law in this context. And as mentioned by delegations including Egypt, the dissemination of misinformation and the fabricated false propaganda campaigns are threats linked to the use of ICTs. In this context, we mention that Israel continues to disseminate disinformation about its attack on Gaza. Israel seeks to falsify facts and to mislead public opinion. Israel also shouldn’t forget that history will unveil the truth. The international community has known on several occasions that Israeli claims are not substantiated. In conclusion, the Arab Group calls on the Israeli delegation to stop spreading disinformation within and outside the United Nations. We call on Israel not to waste the time of delegations. We call on Israel to focus on substantive negotiations pertaining to the mandate of the OEWG. The group will continue to respond to Israel and will continue to raise the Israeli aggression on Gaza in suitable formats. Thank you.

Ambassador Gafoor

I now give the floor to the representative of Israel.

Israel

Thank you, Chair, for giving me the opportunity to respond to the statement given by the representative of Egypt on behalf of the Arab Group. This was a very lengthy statement by the representative of Egypt, and I do not intend to spend any more of this precious time by this forum. I will just say very briefly that October 7th is a fact. Nothing is invented. Nothing was manipulated. It’s all out there. Truths are known to the entire world, and this statement that was just given here was very lengthy, but it did not mention one word, which is Hamas. It’s not surprising, because October 7th was 66 days ago, and for 66 days, the Arab Group has not found the opportunity for once to condemn this attack by Hamas, which was unprovoked on October 7th. This is all I’m going to say. Thank you.

Ambassador Gafoor

I now give the floor to the representative of Germany, also in exercise of the right of reply.

Germany

Thank you. This is just a very short response to the most recent statement delivered by Russia. It is unacceptable to talk about the support of Germany and other states to what Russia is calling a regime. Germany and its allies are cooperating with President Zelensky as a legitimate and democratically elected head of government and with Ukraine as a sovereign state that has fallen victim to Russia’s illegal war of aggression. Russia’s attack on Ukraine’s sovereignty through its illegal war of aggression must not be repeated by any statements that put the sovereign legitimacy of the state of Ukraine, or in fact of any other state, into question. Thank you.

Ambassador Gafoor

I see no further requests for the floor from representatives seeking to exercise their right of reply. It’s exactly six o’clock. The meeting is adjourned, and we will resume tomorrow. But we will see you before that at the reception for all delegates.

Leave a Reply

Your email address will not be published. Required fields are marked *