Ambassador Gafoor
Good afternoon, everyone. Welcome back to the meeting of the OEWG, and in accordance with the program of work, we are having the dedicated session with stakeholders, which is organized in accordance with the agreed modalities for the participation of stakeholders, and it is also in accordance with the program of work that we adopted earlier this week. I want to thank all the stakeholders who are here present, as well as delegations who are here, and I want to take this opportunity to thank stakeholders for joining us today in this session, and for your participation, both physically and virtually, throughout the OEWG process. The objective today is to hear from stakeholders, but before I give the floor to the list of speakers who have been inscribed, I want to say that this dialogue builds on the previous stakeholder sessions held in July 2022 and also earlier in the year, March 2023 and July 2023. And I also organized last week an informal engagement session with stakeholders, where I was able to hear a range of participants, not all of whom are here present today. I want to express my appreciation to the stakeholders who are here today, but also those who participated last week and those who might be following the proceedings online. I want to thank you for your participation, your contribution, and as I said last week to some of you, the OEWG process is midway through its mandate. The discussions are getting deeper into details. The level of understanding has increased. I would also say that the level of trust and confidence between delegations has also increased. So overall, I think we are moving in the right direction. We have adopted two annual progress reports by consensus. But as we stand on the midway mark of our process, we also need to keep in mind that we have two remaining years where a lot needs to be done. A lot of follow-up and implementation and building convergence on a range of issues needs to be done. So it is in this context that I would like to invite stakeholders to make their contributions in a way that is relevant and related to the work we are engaged in and the stage of the process we are in. In this OEWG. Now, before we begin, let me give the floor to the Secretariat. I think they have kept a list of speakers and they might have some logistical arrangements. Catherine?
OEWG Secretariat
Thank you very much, Mr. Chair, for giving me the floor, and thank you very much to the stakeholders who have registered to make an intervention here today. In order to ensure the most productive use of our meeting time, we would kindly request that you keep your speaking to three minutes. We will have to enforce that. And I understand that there is a pre-established list of speakers, so we will be giving you the floor in the order in which you inscribed. So, thank you very much.
Ambassador Gafoor
All right, thank you, Catherine. We’ll start with the EU Institute for Security Studies, to be followed by Wright Pilot. So, the EU Institute, please.
EU Institute for Security Studies
Distinguished Chair, Excellencies, thanks for this opportunity. Echoing the EU, there is no silver bullet against cyber threats. The threat landscape is ever-changing, and we have witnessed unprecedented deployment of cyber capabilities along the lines of geopolitical conflicts and sub-threshold tensions. We know too well the harm that malicious cyber activities can cause. They can target core entities of states’ functioning, including civilian infrastructure, critical infrastructures, and democratic processes. Malicious operations pose a concrete risk not only for the logical layer of cyberspace but also to societal resilience, to the so-called human domain, and to individual rights. This landscape demands a collective, multi-actor, and proactive approach. The latter should encompass diplomatic, policy, academic, and technical efforts aimed at promoting adherence to the norms and existing international law. With the sixth substantive session, we are entering the second half of the OEWG mandate. The UISS has had the honor of being in the group of accredited stakeholders from the inception of this forum. We have been following the process closely, and we have been working with member states and partner organizations toward regular exchanges inside and outside of this room. Through the EU Cyber Diplomacy Initiative, we continue to facilitate gatherings, research, and knowledge management on the substantive agenda items of the OEWG. As an example, with our partners at Leiden University, we recently published an edited volume on Responsible Behavior in Cyberspace, Global Narratives and Practice. The book explores whether and how global, regional, and national narratives on responsible state behavior have translated into practice. Furthermore, in early December, we partnered with the Dutch Foreign Ministry to organize the third edition of the Closing the Gap Conference, exploring regional perspectives on emerging and disruptive technologies. Moreover, we partnered with the Stimson Center on several research activities and scoping exercises on accountability in cyberspace. As for exchanges with partners in the context of the EU Cyber Diplomacy Fellowship last July, we funded and facilitated the participation of 15 representatives and stakeholders in the OEWG. Furthermore, through horizontal multistakeholder platforms such as the European Cyber Agora, we strive to create fruitful spaces for multifaceted discussion involving governments, research communities, civil society, and the private sector. Certainly, numerous guidance texts and input papers have been produced by states. It is important to draw from the knowledge generated by the multistakeholder community. Such contributions are instrumental to fuel a productive dialogue around the promotion and implementation of norms. We do not have a silver bullet, but a broader, values-driven multistakeholder cooperation can be a silver lining.
Ambassador Gafoor
Thank you very much, EU Institute. Write Pilot please.
Write Pilot
Thank you, Mr. Chair, for this opportunity to speak, the Secretariat for organizing this session, and to the British Government for enabling my participation. From the outset, I would like to give praise, Mr. Chair, to your ground-breaking efforts in promoting gender parity within the United Nations Open-Ended Working Group. Your commitment to supporting this cause has paved the way for a more inclusive and equitable governance process on cyber, which will forever be remembered and celebrated as one of this Committee’s hallmark and momentous achievements. Under the guiding question on tools to incorporate a gender perspective in capacity building, we align ourselves with the commentary delivered by Chatham House in 2022 on gender mainstreaming for the proposed Cybercrime Convention. In it, Chatham House called for an intersectional approach to gender mainstreaming, which takes into account multiple forms of social power relating to class, race, nationality, ethnicity, ability, etc. By implication, women in underrepresented geographic regions to the UN, such as the Middle East and North Africa regions, including the Gulf, where they largely represent 50% of STEM graduates but only 25% of the workforce, form an integral part of this approach. We would therefore like to take this opportunity, Mr. Chair, and ask you to leverage existing UN instruments, such as the UN Women, Peace and Security Initiative, to increase the international engagements of Arab women in the work of the OEWG, where they are largely underrepresented, as well as to strengthen their capacities for international engagements by extending fellowship programs of the sort that enhance understanding and knowledge of the work undertaken by the First and Third Committees. The second is the multi-track approach, which acknowledges the need to incorporate gender into all aspects of policymaking and program design as a distinct and standalone goal. We believe, Mr. Chair, that this approach would benefit from a provision to incorporate a gender dimension into decision-making roles. States, for example, can engender on a voluntary basis a cyber diplomacy role within their diplomatic corps to facilitate international cooperation on cyber resilience development and the operationalization of the Program of Action at the GCC level and the Arab League. With these two approaches, Arab women can be better placed to support the implementation of norms for responsible state behavior and, in the future, the adoption and ratification of the Convention on Cybercrime as two mutually reinforcing mechanisms on cyber governance and cyber resilience development. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Write Pilot, for your statement. Hitachi Limited, please.
Hitachi
Thank you, Mr. Chair. As a private company, Hitachi provides critical infrastructure in such sectors as energy, train, smart city, water, digital, and IT services, adopting digital innovation with SDGs, keeping peace, safety, security, and resilience. In this dedicated stakeholder session, let me shed light on the recommended next step sections shared in the informal session about the second APR to work together. First, to implement rules, norms, and principles, we need to prepare the deployment plans with the best practice with the national CI, CIR, and global supply chain, and most importantly, for safe and secure operations. The industry can standardize and tailor the requirements with the checklist, if you will, for regions, states including developing countries and small states. Second, for the capacity building, the industries can implement the framework considering resilience, security by design and default, and safe operations to address human mistakes, mechanical failures, and AI misbehavior and potential harms. We need multilateral collaboration to ensure safety, security, and data integrity for ICT environment with a trusted human-to-human communication. Third, about mapping exercise, we can work on global landscape together. Great examples are UNIDIR, cyber and AI portal policy, and proposed global cyber security cooperation portal with the existing best and recognized portals so that we can accomplish a one-stop shop created under the auspices of the United Nations. For practical implementation purposes further, product-level supply chain mapping can address such potential threats identified as healthcare, maritime, aviation, and energy sectors. Fourth, global roundtable is a great idea for multilateral collaborations keeping equitable representations, adapting some impactful cases such as Paris Call, Accra Call in Ghana, a great example for convergence. Finally, regular institutional dialogue including POA is encouraging for multilateral public-private partnerships addressing the continuous technological innovations for cyber and the digital civilization, enhancing the confidence in building major. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Hitachi. I give the floor now to the Centre for International Law, National University of Singapore.
Center for International Law
Thank you, Chair. On behalf of the Centre for International Law, National University of Singapore, we thank the Chair for convening this dedicated stakeholder segment and according non-government stakeholders an opportunity to engage in the discussions. As this is the first time that CIR is participating in OEWG meetings, please allow me to briefly introduce our Centre. The CIR is a university-level research institute, founded in 2009, in response to the growing need for international law thought leadership and capacity building in the Asia-Pacific region. The focus areas of research include a public international law program that seeks to promote a diversified approach and understanding of international law among a global audience. We thank the Chair for his guiding questions. I wish to address the topic of international law. Several delegations have stated that international law applies to cyberspace and that efforts are needed to clarify how that applies. In this regard, stakeholders have an important role in building capacity in a manner suited to the national needs and circumstances and forging national common understandings. For instance, the CIR provided trainers for the UN Singapore Cyber Fellowship and engaged in a high-level dialogue during the Singapore International Cyber Week. Furthermore, in line with Paragraph 36 of the Second APR, which speaks to building capacity in the areas of international law in a neutral and objective manner, we wish to flag two recent CIR initiatives. First, in April of this year, CIR collaborated with Chatham House to convene a regional workshop and dialogue on international law in cyberspace, Asian perspectives, and current trends. Conducted in Singapore under Chatham House rules, the dialogue sought to foster understanding and networks around the application of international law in the use of ICTs among diplomats, government-given advisors, the tech sector, and civil society in the Asian region. Structured around a set of guiding questions, participants engaged in a wide-ranging, in-depth discussion on some of the most pressing emerging issues, as well as other issues where there is a wide spectrum of views. This includes the principles and methods of interpretation and identification in applying international law to cyberspace, the theory and practice of cyber due diligence, the role of non-state actors in cyberspace, countermeasures and the rules of state responsibility, information operations and international law, emerging technologies and international law, among others. More recently, in September, during the second annual symposium on cyber and international law, we convened a cross-regional panel of experts in moderated discussion that saw a spotlight on regional perspectives. We offer some observations on these engagements. The full details are in the full statement. For example, for your appropriate, the convening of small, closed-door discussions can offer a trusted space for frank, robust discussions. Engaging with experts and stakeholders across different disciplines in a cohesive manner can be very helpful as well, particularly when you engage experts and officials from different political and legal systems to facilitate understanding and demystify different understandings of similar terminology. Chair, we stand ready to contribute to future dedicated sessions. Thank you.
Ambassador Gafoor
Thank you very much, Center for International Law. I give the floor now to Youth for Privacy. You have the floor, please.
Youth for Privacy
Thank you, Mr. Chair. I’m Shivani Sundaresan, and I’m a representative of Youth for Privacy. With most Internet users under the age of 30, it’s clear that the future of ICTs is in the hands of the younger generation. We wish to address two thematic topics: capacity building and regular institutional dialogue. First, regarding capacity building, we believe that checklists to assist states should contain the following. First, privacy and data protection protocols. In addition to the current focus on confidentiality, these checklists should include guidelines on implementing strong privacy and data protection measures in line with international standards. Next, mobilizing a diverse range of resources. Instead of focusing on ICTs from a purely technical standpoint, we must shift the perspective towards those who are most affected by ICTs. That is, we must implement a socially engaged design framework to include the end user in these discussions as well. Finally, the inclusion of youth language in final documents. It is vital that the final document and deliverables of the OEWG should include specific language that addresses the youth. This ensures that the concerns and perspectives of young people are not only recognized but also acted upon. Next, regarding regular institutional dialogue, we’ve previously brought up a proposal to start a youth advisory board for ICTs. The UN has already created a youth advisory board in the fight against climate change, recognizing that youth lack the access to the political, legal, and voting power necessary to help shape our futures. We propose that a youth advisory board will contribute the following to security in ICTs. First, providing educational content to promote digital literacy. Today, many states have discussed the implications of misinformation on the Internet, which has led to an overall mistrust in governments per the Global Sustainability Development Report. To restore overall trust in government, we need targeted education, collaborative partnerships, inclusive policymaking, and an investment in digital literacy. In the past, Youth for Privacy has hosted workshops with other nonprofit organizations, such as the Data Values Bootcamp, to educate the youth on issues related to privacy. And we encourage similar initiatives for both youth and policymakers by a potential youth advisory board for ICTs. Currently, there are numerous challenges in the cyberspace uniquely affecting young individuals, such as online harassment, the manipulation of digital content through deepfakes, and the emerging complexities associated with the widespread use of generative AI in many different fields. These issues are often overlooked in global discussions and have profound implications on the well-being and digital rights of the youth. Implementing a global youth advisory board would help bring these issues to life, and having a group of youth experts will bring a unique perspective on how to solve these issues. In conclusion, our discussions and decisions at this session must be informed by the perspectives and experiences of young people. Our involvement is not just beneficial, but essential for creating robust, effective, and inclusive policies for the future of ICTs. Thank you so much for your time.
Ambassador Gafoor
Thank you very much, Youth for Privacy, and thank you for bringing the perspective of young people into these hallowed halls of the imagination. I think it’s a voice that we need to listen to very carefully. I give the floor now to Third Eye Legal. Please, take the floor.
Third Eye Legal
Thank you, Chair, for the opportunity to contribute to the formal stakeholder session. Cyber threat actors have modified their tools, tactics, and procedures in accordance with the evolving landscape and have incorporated AI, IoT, and neurotech into their cyber attack arsenal. The impact of such attacks on states and their citizens is manifold. From attacks on critical infrastructure, vital to the functioning of states, to attacks on human rights defenders, private sector organizations, government officials, military personnel, critical service providers, and innocent civilians, the attack vector has widened, and the goalposts to protect states, their vital assets, and civilians keep shifting. In the not-too-distant future, ICTs will usher in the quantum era, and the risks will continue to evolve and morph into potentially dangerous territory in combination with AI. Additionally, the sale of surveillance technology and spyware has enabled belligerent states to increase their ability to conduct cyber espionage that can detect and destroy their targets indiscriminately and covertly, especially attacks on industrial control systems. Such technology is also used by malicious sectors to spread myths and disinformation, to change public perception and opinion, including interference in the democratic processes of states, to achieve their intended result, which is a key tool of an autocratic belligerent state. Third Eye Legal has, in almost all of its proposals, urged states to come to a common understanding on the implementation of international law, in addition to adhering to voluntary norms. With the emergence of hybrid conflicts across different regions, the disastrous impact has been felt in real and human terms. States in previous sessions have not recognized the importance of building consensus on a legally binding treaty that respects the UN Charter, international humanitarian law, and international human rights law, and have termed the dire need for it as premature. Third Eye Legal urges states to reconsider their respective positions and include international law consensus building in the program of work as an essential priority. To achieve such a consensus, Third Eye Legal suggests a few focus areas of work, particularly on how international law and the framework of responsible state behavior apply to cyber-led intelligence operations based on specific case studies, the relationship between the rule of law, intelligence contents, and the stability of cyberspace, and the technical, legal, and policy implications of generative AI, large language models, IoT, neurotech, 6G, and possibly quantum tech. To this effect, Third Eye Legal has proposed contributing to tabletop exercises, especially cyber-conflict gaming, and how and when scale, scope, and effects might be reached such that a cyber attack constitutes a belligerent act and therefore would invoke states’ obligations under international law. Cyber security exercises are conducted on national and international levels and contribute to the strengthening of cyberspace by testing measures to be taken against potential cyber threats. Such efforts are limited to national and regional alliances, and broader cooperation is needed among states on a global level that can be achieved under the UN Cyber OEWG, ensuring inclusivity of all states. Finally, Third Eye Legal reiterates its willingness to work with all states and interested stakeholders in joining efforts to combat the malicious use of ICTs and ensure peace and stability for our common future. Thank you.
Ambassador Gafoor
Thank you very much, Third Eye Legal. Global Partners Digital, you have the floor, please.
Global Partners Digital
Distinguished colleagues, Chair, thank you for this opportunity to share the views of Global Partners Digital, or GPD. I will focus my contribution on threats and international law, with reference to the recommendations in the second APR. GPD welcomes the increasingly detailed discussion of threats, including emerging technologies such as quantum computing, IoT, and AI, and encourages further discussion on this topic to advance understanding of the negative and positive impacts of these technologies on the cyber landscape. Discussion of different types of cyber operations and the targets of attacks, including CI, CII, humanitarian organizations, and democratic processes, have enabled our group to develop a fuller picture of threats. Yet, this picture will remain only partial if it is not also complemented by efforts to assess their human rights impacts and ability to jeopardize security. Stakeholders can provide vital knowledge, which should be leveraged to inform the group’s understanding of threats and the proposed threat repository. Regarding international law, while cyberspace is often referred to as a domain, it does not, in fact, constitute a new legal area or domain, and thus international law applies in its entirety. This does not mean that there are not unique features relating to the use of ICTs, which require additional attention, and we welcome the proposal for a dedicated intersessional to further discuss these areas. This should reflect areas of additional convergence, such as on the application of international humanitarian and international human rights law, and should focus on what is needed to ensure their protective value. We also support the recommendation to build capacity on international law to enable states to provide their own views. The task of developing positions is a challenging one, requiring coordination from multiple agencies, significant financial resources, and expert knowledge. Capacity building should thus aim to mitigate these challenges and to support the adoption of national positions, which are instrumental to arriving at common understandings. It is also a team effort and should involve the participation of different stakeholders. GPD remains available to participate and appreciates the work of UNIDIR and others on this front. Finally, in going forward with its work, we urge the group to effectively leverage the vital contributions of stakeholders, including in the further elaboration of the POA. To highlight just one example, GPD recently published case studies with Directos Digitales, Fundacion Carisma, and R3D to illustrate the work of civil society in supporting inclusive implementation of the norms through national policy and regulatory processes. To fully enable insights like these to be captured, this group should prioritize open and meaningful dialogue, including on the POA’s design. Thank you for your attention.
Ambassador Gafoor
Thank you very much, Global Partners Digital, for your statement. I give the floor now to Safe PC Solutions. You have the floor, please.
Safe PC Solutions
Thank you. Thank you, Mr. Chairman, for the opportunity as a stakeholder to give a perspective from the private sector. Safe PC Solutions, in collaboration with Praxis AI, has developed a cybersecurity awareness training program and toolkit utilizing a learning experience platform, which is virtual and hybrid training around building the operational capabilities of PLCs in cybersecurity. The training program and toolkit will further benefit from a deepening understanding of member states’ capacity-building requirements on the various issues addressed by this committee, including international law, to be able to help participants learn how to defend themselves and their organizations from cyber threats, and to promote regional, cross-regional, and inter-organizational collaboration and skilling. I suggest that we review the training program during the mapping exercise and collect feedback from member states and stakeholders, officially pulling together both the public and private sectors on how we can overall improve the effectiveness of training to build capacity. Furthermore, this will address the main challenges in the ICT industry, which is the lack of cybersecurity skills, which further impacts capacity building, again, not only in developing countries but also in developed societies in which women and minorities continue to be marginalized. Mr. Chairman, this will be introduced as a measure by the private sector to build the capacities and capabilities of PLCs and can be extended to subjects such as international law, confidence-building measures, cyber threats, and reporting vulnerabilities. Thank you so much.
Ambassador Gafoor
Thank you very much Safe PC Solutions, for your statement. I give the floor now to DiploFoundation.
Diplo Foundation
Mr. Chair, Distinguished Delegates, and Colleagues, my name is Vladimir Radunovic. I represent Diplo Foundation, a non-profit educational organization supporting small and developing countries as well as various stakeholders in industry and civil society with capacity building in cyber diplomacy, cyber security, and internet governance topics for over 20 years. Mr. Chair, we would like to express our further support to the work of the Open-Ended Working Group (OEWG) and address some of the guiding questions for the sixth substantive session. Regarding the specific ways to strengthen cooperation to ensure the integrity of the supply chain and prevent the use of harmful hidden functions, Diplo Foundation is happy to share the results achieved this year by the Geneva Dialogue on Responsible Behavior in Cyberspace, established by Switzerland and led by Diplo. In 2023, over 50 representatives and independent experts from the private sector, civil society, academia, and technical community contributed to the development of the Geneva Manual, a comprehensive guide on the implementation of the agreed cyber norms by relevant stakeholders. The first edition of the manual was launched last week in Geneva and focused on the implementation of the two UNGGE norms related to the ICT supply chain security and responsible reporting of ICT vulnerabilities. The manual addresses the implementation gap and serves as an important contribution to the Open-Ended Working Group, highlighting the roles for various stakeholders in implementing the norms and the related challenges. The Geneva Manual is published on the Geneva Dialogue website but is also published at the Open-Ended Working Group website. We invite all interested stakeholders to join this multistakeholder work to further discuss the roles and responsibilities in the implementation of the agreed framework. Mr. Chair, regarding capacity building, Diplo strongly supports the mapping exercise we have submitted as a contribution to our footprint and experience in cyber capacity building in the last two decades of our work and are committed to actively assisting the UN Secretariat and the States in this regard. With regard to the possible Global Cyber Security Cooperation Portal, Diplo will be happy to contribute with its experiences of operating the Geneva Internet Platform (GIP) and the Digital Watch Observatory as examples of neutral and inclusive well-recognized online resources and comprehensive mappings in cyber diplomacy and digital policy field. It is important that the future portal builds on existing experiences and incorporates specialized existing tools for diplomatic use cases. We remain committed to supporting the future capacity building efforts. Thank you for this opportunity, Mr. Chair.
Ambassador Gafoor
Thank you very much, Diplo Foundation, for your contribution. I’ve had a request from the interpreters. We’ve asked that the stakeholders speak a little slower. Obviously, I think the pace is a little too rapid, and we have to be fair to the interpreters as well. So let’s go through the list. I give the floor now to the Centre of Excellence for National Security, Nanyang Technological University of Singapore.
RSIS
Thank you, Mr. Chair, for the opportunity to speak at the 6th substantive meeting, and we further thank you, Mr. Chair, for providing guiding questions and for your efforts to engage stakeholders. I speak for the Centre of Excellence for National Security, or CENS, a policy research think tank based at RSIS, the Rajaratnam School of International Studies in Singapore. We seek to answer your guiding questions and note the concerns that states have raised in this substantive meeting, so we are proposing two ways that stakeholders like us can help states with implementing the agreements in the 2nd Annual Progress Report. Firstly, protection of critical infrastructure. We note that many states in the meeting yesterday raised concerns about the protection of critical infrastructure. We believe that more can be done to bring together states, critical infrastructure operators, cybersecurity professionals, civil society, and academia to better protect national, international, and supranational critical infrastructure. We believe this is relevant to the 2nd Annual Progress Report, paragraphs 12, 13, 17, and 23. We are therefore planning a series of multistakeholder, multi-region roundtables on protecting critical infrastructure. The roundtables will seek to exchange views on existing and potential threats to operational technology (OT), Internet of Things (IOT), understand challenges, share best practices and frameworks, discuss regional and global cooperation, and create learning opportunities. We will draw on our own experience and networks built while developing and assisting in the review of Singapore’s Operational Technology Cybersecurity Master Plan. We welcome states and regional organizations to partner with us in this effort. Number two, implementation of rules, norms, and principles. We note the concerns of states that there is still a gap in the understanding of the 11 norms of responsible state behavior and the urgency to create a checklist of how states can implement these norms. Therefore, we encourage states to engage relevant stakeholders, academic institutions like our think tank, to facilitate workshops on implementation of rules, norms, and principles, and to help develop checklists for implementation. We draw on our experience in conducting workshops for capacity building, norms, and international law in the ASEAN region and for the UN Singapore Cyber Programme. We can share that the in-depth conversations at these workshops do help states. We also encourage states to engage operators of critical infrastructure and critical information infrastructure to identify how to implement the norms for protection of critical infrastructure. And we encourage states to share their experiences and best practices. We believe this will help the 2nd APR paragraphs 24, 25, 26, and 27. We look forward to collaborating with states and stakeholders in upcoming activities for protection of critical infrastructure and implementation of rules, norms, and international law. Thank you, Chair.
Ambassador Gafoor
Thank you very much, Centre for Excellence. I give the floor now to Derechos Digitales.
Derechos Digitales
Thank you, Mr. Chair. Mr. Chair, distinguished delegations, Derechos Digitales is pleased to participate in this meeting of the Working Group. We are a civil society organization based in Santiago, Chile, that works all over Latin America. We are dedicated to the advocacy of human rights given the regulation, the deployment, and the abuse of digital technologies. We will base this statement on two points. Number one, we welcome the recommendations of next steps in paragraphs 21 and 22 of the second APR with regard to identifying current and potential threats with express mention to cooperative measures. Derechos Digitales works together with independent and civil society experts in Latin America, which include the launching of the program La Red. This is a Latin American program on resilience and digital defense. With this program, we try to implement preventive actions and responses on the detection and study of cyber attacks. We also facilitate a network of experts throughout Latin America for an exchange of information on threats by building an observatory of digital threats for the region. We thus emphasize the value of cooperation for the effective threat detection through direct contact and with trusting affected persons and groups by identifying patterns, trends, and new forms of attack, including technologies mentioned by many delegations, thus improving available information on threats. A repository on threats as that proposed by several delegations could thus be complemented by the work of stakeholders. Number two, Derechos Digitales welcomes the steps that have been recommended on international law, including the convening of an intersessional meeting and capacity building. Stakeholders, such as civil society organizations and others, can compile and analyze national positions and also contribute to their development, in particular by bridging knowledge gaps. We recall that progress on international law standards, such as those shown in the resolutions of the Human Rights Council, have enjoyed the contribution of stakeholders, the civil society of the whole world, which have frequent experiences in the application of international law. We remain alert and will continue contributing to this process. Thank you.
Ambassador Gafoor
Thank you very much for your contribution. I give the floor now to Red en Defensa de los Derechos Digitales.
Red en Defensa de los Derechos Digitales
Thank you, Mr. Chair. I’m Francia Pietrasanta, and I represent R3D, the Network for the Defense of Digital Rights. This is a Mexican NGO dedicated to the defense of human rights in the digital domain. The use of spyware for malicious intent is a threat that weakens information security and is a growing risk for international security, the sovereignty of states, freedom, and the dignity of individuals. In this context, the increase in the use of these tools is a matter of concern not only for states but also stakeholders such as civil society, the technical sector, academia, and the private sector. Any initiative to address ICT threats must incorporate technical experience and a human rights perspective. While it is crucial to counter emerging threats in the digital environment, they must also be addressed from the standpoint of prevention. So we welcome the support of Kenya, Mexico, Colombia, Brazil, Ghana, among other delegations, for a repository of threats. The establishment of that repository must have the participation of all stakeholders so that we may effectively contribute to preventing these threats. We also welcome the proposal of organizing an intersessional on threats. This has been supported by some states. As recognized in the second APR, vulnerable persons face specific risks. We believe that including these groups, who include activists, journalists, women, and members of the LGBTQI community, can be reached with the support of civil society. We have investigated the threats to those groups, and as part of this process, we have understood their specific needs. It is important for states to recognize the asymmetry of responsibilities derived from an asymmetry of capabilities. For example, with regard to information about vulnerabilities, we need to have information on situations such as the weakening of encryption and also the establishment of backdoors. Cybersecurity should not be thought of as a dispute among states. It must place protecting individuals at its center. We hope to continue participating in this process to contribute to the action of this working group. Thank you, sir.
Ambassador Gafoor
Thank you very much for your contribution. International Chamber of Commerce, you have the floor next.
International Chamber of Commerce
Thank you, Mr. Chair, and good afternoon, colleagues. Thank you, Mr. Chair, for the opportunity to share a few thoughts on behalf of the International Chamber of Commerce. Following our intervention during the stakeholder consultation last week, we would like to share further details on our input to the continued discussions of the Working Group with respect to the existing and potential threats. We have taken note of previous discussions of the group that emphasized how the rising threat of ransomware is a serious concern for Member States. This is also clearly noted in the Annual Progress Report, and this is why at ICC, together with our member companies from across sectors and geographies, we developed a dedicated report entitled “A Global Business Perspective on Fostering Ransomware Resilience.” The report outlines the ways in which business is addressing the ransomware challenge and highlights proactive measures taken by companies in preventing, detecting, and addressing the rising frequency of ransomware threats. It also calls for strengthened collective action, emphasizing the importance of international cooperation, information sharing, and multistakeholder efforts to combat the multifaceted nature of ransomware. Let me share here just a few takeaways from the paper. Especially noteworthy is the evolution of ransomware incidents propelled to new heights by a disruptive professionalized structure known as ransomware as a service. In this model, malware developers lease out both the ransomware itself and its control infrastructure to other malicious actors, broadening access to a lucrative criminal domain. This has transformed ransomware, once a fringe activity, into a well-organized and profitable enterprise with substantial profit margins affecting critical infrastructure, businesses of all sizes, and governments worldwide. In addition, companies are not only the target of attacks but also at the forefront of detecting threats and creating innovative approaches to resilience and response. Based on case studies and examples shared by ICC member companies, the paper outlines how businesses are proactively fortifying their resilience against ransomware through incident response plans, robust asset inventories, secure data backups, and up-to-date systems with the latest security patches. Cybersecurity training and innovative technical strategies are also integral components of the resilient efforts. Furthermore, businesses are offering counter-ransomware tools and strategies to help other organizations prevent, mitigate, and recover from such incidents. They also focus on collaborative approaches with national and international organizations and contribute to coordinated efforts, sharing their resources to effectively combat ransomware. The paper takes stock of these and other efforts, sharing learnings and good practices. In closing, the private sector has a wide range of on-the-ground experience and up-to-date information on the types, targets, and impact of cyber threats. It is imperative that the discussions in this working group include private sector experts, not only to ensure that conversations reflect the realities of today but also to proactively seek collaborative policy solutions that support business efforts. I would invite all of you to visit the working group website and read through the paper as it has been kindly uploaded by the secretariat, and please don’t hesitate to reach out to us should you have any questions. We wish to work with you further. Thank you for your attention.
Ambassador Gafoor
Thank you very much for your contribution, International Chamber of Commerce. I give the floor now to Fundación Karisma. Please.
Fundacion Karisma
Thank you, Mr. Chair. Mr. Chairman, I thank you for your work as the leader of this working group. Fundación Karisma is a Colombian organization that works on digital rights and has a laboratory on digital security and privacy. At this meeting, we wish to refer to the need to have a human rights perspective in cybersecurity policies. Infrastructure and information are assets when we speak of cybersecurity, but we must not forget that it is individuals who suffer the consequences of attacks. An example of this is the recent investigation of Fundación Carisma on differential impacts of cyberattacks against Colombia suffered there in November 2022. A company, Carolty, suffered a ransomware attack which affected the systems used to deliver health services to 5 million people in Colombia. We interviewed women who were caregivers for people who suffered the cybersecurity incident. We also requested information through information requests. Also, we saw that these women of low income suffered from these attacks, and these were services which used to be given virtually now require them to travel at additional cost, and furthermore, in-person dynamics also meant that they had additional expenses for having access to the health services. There was a suspension of subsidized prescriptions, and there were delays or interruptions in medical treatment since clinical records were not available. These were the problems with regard to health delivery services. The findings of our investigation are an example of the consequences of a cyberattack for vulnerable groups. We must have responses to ransomware, but we must not overlook the impact that these have on individuals. For example, contingency acts to guarantee the attention of the more vulnerable groups are important to have good response times, and in case of data breaches, we must inform the affected individuals so that they may implement self-protection measures. In the next few months, Fundación Carisma will publish a complete investigation and will have a brief manual on this. These documents will be a civil society contribution to capacity building and to confidence building from a human rights perspective. Thank you.
Ambassador Gafoor
Thank you very much, Fundación Karisma. I give the floor now to Chatham House.
Chatham House
Thank you, Chair. I speak today in my capacity as an Associated Fellow with Chatham House. We would like to directly respond to two of the Chair’s questions and highlight how research and convening that Chatham House is doing can complement the efforts of Member States and other stakeholders in advancing critical elements in cyber capacity building. First, in relation to developing checklists and tools to assist States in mainstreaming cyber capacity building principles, Chatham House would like to draw attention to research and guidance we are producing and operationalizing the cyber capacity building principles. As Member States and stakeholders know well, the cyber capacity building principles outlined in the 2021 OEWG report draw on a long-established history of principles from the international development community. This means that the ideas and essence of these principles are well-recognized, well-known, and well-applied. A principles-based approach to cyber capacity building will simply be building upon that work with the ultimate aim of contributing to making capacity building more efficient, more ethical and valuable, and more conducive to facilitating an open, secure, and peaceful cyberspace. These principles can also help protect against harms and risks that might emanate from capacity building, whether intentional or unintentional. As part of a project supported by the Netherlands, we are in the process of developing further guidance on how the principles should be applied and how they can contribute to advancing the three elements of the framework on responsible state behavior in cyberspace. This guidance will seek to explore the principles on a more granular level, looking at what exactly they mean and how principles might work in tandem with each other. It will offer guidance on the operationalization of the principles. Ultimately, our research and work will seek to assist states in mainstreaming the principles in their cyber capacity building activities. We welcome the continued focus on these principles. Secondly, in relation to states encouraging states to develop and share tools that would assist in incorporating gender perspective into capacity building activities, we would like to draw attention to the toolkit Chatham House has produced on integrating gender into cybercrime capacity building. While the focus of the toolkit is cybercrime, it contains lots of valuable transferable guidance in this form, and we’d also like to take the opportunity to draw attention to important research on gender and cyber that Chatham House and other organizations are undertaking. As we emphasized in previous statements, gender security is an international security matter, and gendered issues occupy a very particular position in cyberspace. An incomplete understanding of the threat landscape is not conducive to adequate solutions. Applying an intersessional gender approach to our understanding of security risks in cyberspace will lead to a more comprehensive understanding of how cyberspace tools can be weaponized and against whom and how they can be put in place and protections for those threats. Chatham House will be publishing two papers in this regard. Finally, Chatham House also is an active participant in the GFCE, and to supplement the mapping exercise, we’d like to call your attention to the recent global conference on cyber capacity building held in Ghana and the resulting Accra Call for Cyber-Resilient Development that is a national plan for advancing cybersecurity foundation for development agenda. The Accra Call has been endorsed by many states and other stakeholders and remains open for endorsement by everyone here. And finally, on the capacity-building tools, we recommend the linking of the GFCE, CBL, and UNIDIR portals, which is a great collaborative effort to help all states achieve capacity building. Thank you.
Ambassador Gafoor
Thank you very much, Chatham House, for your contribution. I give the floor now to the last speaker, Centre for Humanitarian Dialogue.
Centre for Humanitarian Dialogue
Thank you very much, Mr. Chair, for giving me the floor. I am speaking on behalf of the Center for Humanitarian Dialogue, a non-profit organization acting from principles of humanity, impartiality, neutrality, and independence. In our cyber mediation program, we are engaging with countries that possess ICT capabilities to develop confidence-building measures. All GGE and OEWG reports have called for cyber confidence-building. However, serious concerns persist about a lack of implementation of long-agreed cyber confidence-building measures, at least in some parts of the world. This problem is particularly pronounced in parts or in regions where there are no organizations, regional organizations, or where regional organizations have not yet advanced to cooperation in this field, and is also pronounced among countries that have adversarial or competitive bilateral relations, where official channels for cyber diplomacy do not exist or face secure constraints. The Center for Humanitarian Dialogue is engaging various actors to complement existing regional CBMs with bilateral arrangements and to build new arrangements where they are non-existent. This is taking up a recommendation in the 2021 OEWG report that states continue to consider CBMs at the bilateral, regional, and multilateral levels. I would like to offer four observations. First, cyber confidence-building is about establishing political trust in an environment of distrust. Hence, it is not enough simply to exchange names and telephone numbers. The contact points, cyber contact points, need to have political backing to engage, and their conclusions and their agreements need feedback to political decision-makers. Second, we are observing increasing activities by non-state actors, also in the context of armed conflicts between states. This raises risks of misperception, and it renders trust and confidence-building measures ever more important. Third, there is a lot of expertise in the IT industry among scientists and in the user community, and it may be wise to design cyber confidence-building measures in a way that allows engaging industry, civil society, and the science community as well. Could technical scientific advisory bodies that are standing and feed into the deliberations of political decision-makers be a solution? Finally, let me point out that cyber confidence-building is difficult. It requires time, resources, and effort. Destroying trust, on the other hand, takes only one abuse of capabilities, one bad move. The question arises, what happens then? So I’ll end with a quote from Russia’s Tsarina Catherine II, Catherine the Great: “Power without confidence means nothing.” Thank you.
Ambassador Gafoor
Thank you very much, Centre for Humanitarian Dialogue, which was the last inscribed speaker. Let me take this opportunity to thank all the stakeholders for having come here with very prepared and substantive contributions. I’m very happy to see that so many delegations are in the room and they are also listening very carefully, as I did. Second, it’s very clear that the stakeholders have been following our work closely, because they have obviously looked through all our reports, including the last annual progress report, and I think that their contributions were directly related and relevant to the work that we are actually doing at this very point. Third, this is going to be a process. This is going to be a process where stakeholders will continue to contribute, I hope, and at the same time, this is also a process where delegations will, I hope, reach out to stakeholders and engage in discussions, because ultimately, the work that we are doing here collectively is about building trust, is about building confidence, and it is about building convergence. And it’s all iterative, because with trust, we might find it easier to build convergence, and when there’s convergence, it reinforces the trust that is there, which then allows for even greater convergence, as we take a step-by-step and incremental approach. So to the stakeholders here today, thank you very much. Please stay engaged. We’ll continue to hear from you, but your contribution does not end with the statements you have made here. I do encourage you to reach out and stay in touch with the different delegations. But most importantly, delegations arrive here with instructions to, of course, advance a certain point of view. Delegations also have an obligation to look for common ground and convergence, and I hope that you, the stakeholder community, will encourage them to go in the direction of convergence, to encourage them as well, to encourage delegations to demonstrate flexibility when the time comes. So I look to the stakeholders, in a sense, to talk to delegations to show flexibility, so that we can build convergence as we take a step-by-step approach. Once again, thank you very much for the stakeholders who are present here, and also those who might be following the discussions virtually. I’d like to now suggest that we move on to continue our earlier discussions on international law. So we’ll continue with the earlier speakers list, and let me look for that speakers list now. So we are going back to the last few remaining speakers on international law, and I’d like to close the speakers list for international law, so that we can, after hearing the remaining speakers, make the next transition, or make the transition to the next cluster, which is confidence-building measures. So I give the floor now to Chile, followed by Ukraine. Chile, please.
Chile
Thank you, Mr. Chair. My delegation thanks you for the period we had to listen to the stakeholders. We were able to prepare a shorter version of my statement. Chile believes that international law, and in particular the UN Charter, provides a normative framework which is applicable and should regulate the work of states in cyberspace, including humanitarian law, human rights law, and those laws which regulate the international responsibilities of states. They are essential to maintain the essential peace and stability to have a secure and peaceful environment with regard to ICTs. In like manner, states using ICTs must observe the Charter, apply the principles and obligations contained therein, such as sovereign equality of states, peaceful settlement of disputes, so that peace, security, and international justice are not endangered, refrain from the use of threats or use of force against the territorial integrity or the political independence of any state, respect for human rights and fundamental freedoms, and non-interference in the internal affairs of other states. This is our basis, our baseline, and this will help us reach common understandings on how to protect the civilian population and have clarity as to what actions are prohibited or which ones are allowed in situations of conflict. International humanitarian law applies to cyberspace, and the application of how it can be deployed in cyber operations in armed conflict is a priority for future debates. In order to continue developing and studying the application of international law to cyberspace, as I have, other delegations have said, and also some stakeholders have said, we need to continue promoting cooperation on these matters through an inter-sessional meeting, a dedicated one, which would make it possible to exchange regional particular characteristics and also exchange views internationally. We wish to recognize the basic role in our region of the cybersecurity program of the OAS, which since 2017 has developed very good work in training officials on the application of international law to cyberspace. Thank you.
Ambassador Gafoor
Thank you very much. Ukraine, please.
Ukraine
Mr. Chair, Ukraine aligns itself with the statement delivered by the European Union under the agenda item on international law. Our delegation would like to make a statement in our national capacity. The international community has consistently affirmed that international law, including the UN Charter in its entirety, applies in cyberspace, including recently through its adoption of the 2021 GGE report, as well as 2022 and 2023 OEWG reports. In accordance with international law, each state is obliged to respect the sovereignty of other states and the sovereign equality between states. This is one of the fundamental principles of international law stipulated in the UN Charter. In addition, Article 2, Paragraph 4 of the United Nations Charter states that all members shall refrain in their international relations from the threat or use of force against the territorial integrity or political independence of any state. As reiterated by the UN member states earlier and most recently in the OEWG annual progress report of 2022, international humanitarian law applies in situations of armed conflict. We recognize the importance of further study on how existing international law applies to state behavior in cyberspace. A better understanding of how international law applies in cyberspace will contribute to the strengthening of an open, secure, stable, and peaceful cyber domain. In this regard, Ukraine welcomes the recommendations of the annual progress report to convene a dedicated international meeting on how international law applies in cyberspace. Mr. Chair, today’s cyberattacks take place alongside conventional warfare. In this regard, we believe that it is crucial to advance the work of the OEWG on the applicability of international humanitarian law in cyberspace, especially in the context of a growing number of cyberattacks against critical infrastructure, including but not limited to hospitals, humanitarian organizations, transport, energy, financial, and commercial sectors. We strongly believe that states must be held accountable for violations of international humanitarian law by cyber means. In addition, Ukraine reaffirms the importance of further discussion on the issue of due diligence obligations, which calls on states to take practical steps to ensure that their territory is not being used for malicious cyber activities. Mr. Chair, as our delegation stated during the OEWG’s deliberations on norms, rules, and principles of responsible behavior yesterday on the 12th of December, the Ukrainian national telecommunication operator Kyivstar became the target of a cyberattack. In this way, we believe it is important to continue to inform UN member states of the ongoing efforts undertaken by Ukraine’s authorities in response to this malicious cyberattack. As of today, cyber specialists of the Security Service of Ukraine and Kyivstar specialists, in cooperation with other state bodies, continue to restore the network following a cyberattack. According to the preliminary estimates, Ukraine’s authorities concerned expect to restore fixed Internet for households by the end of December 13, by the end of the day, as well as to launch mobile communication and Internet services. It is important to stress that the digital infrastructure of Kyivstar has been critically damaged. Thus, the restoration of all services in compliance with the necessary security protocols is a time-consuming procedure. Finally, one of the Russian pseudo-hacker groups has already claimed responsibility for this attack. This group belongs to the main directorate of the General Staff of the Armed Forces of the Russian Federation, which is yet another evidence that Russia has been using cyberspace as one of the means of its aggression against Ukraine.
Ambassador Gafoor
Thank you, Ukraine, for your statement. Uganda, please.
Uganda
Thank you very much, Mr. Chair. This is my first time to take the floor. I wanted this opportunity, Mr. Chair. My delegation appreciates your leadership. I would like to give you an A-plus for steering our meeting thus far, and we are very confident we shall be supporting you all the way to the finish line. Uganda believes that capacity building at the local level is of paramount importance in contributing to our participation at the international stage. Mr. Chair, we look at the current cyberspace more like a jungle, ruled by survival of the fittest and the strongest, making most of us in the developing world vulnerable to cyber attacks, threats, and risks. We lack adequate capacity and means to effectively deal with non-state and even state actors beyond our borders who possess the means and the capacity to cause significant disruption to our economies and critical infrastructure. For us in Uganda, we are still in the process of developing the necessary regulations to address this critical area of cyber security. However, because of our limited resources, cyber security doesn’t get the adequate priority and the urgency it deserves. That’s why my delegation calls for international support to increase awareness and capacity at the local level, more so targeting the key policymakers like members of parliament and government departments so that they can take decisions to elaborate cyber security as a key component of our national security strategy. In this regard, we would like to thank the offer from Ireland to help developing countries develop their national positions. We shall be looking into that. Mr. Chair, it will be extremely difficult for our countries to be equal partners and effectively participate at the international level if we lack local expertise and capacity to engage in this very technical field of cyber security, which keeps changing very rapidly. We cannot afford to be bystanders when it comes to cyberspace. That’s why I want to call for international support to help developing countries develop local capacities to be able to engage in a meaningful way in these meetings. Mr. Chair, in conclusion, I would like to express appreciation for the continued support from the UK, Canada, Australia, the US, New Zealand, and other countries which have enabled participation of more women from the developing world in these meetings. I’m one of those proud beneficiaries, and I hope that I’ll continue to come and participate in these meetings. Their support has enabled our voices as women to be heard at such an international forum. Mr. Chairman, with those few words, Uganda’s position is that we need to first look at developing local capacities in our countries to enable us to have a critical mass that can engage meaningfully at the international forum. I thank you, Chair.
Ambassador Gafoor
Thank you very much, Uganda, for your contributions, and also thank you for giving me a good grade. I think my final exam is next year in July, so you might want to hold on to giving me any grade. But I think what you have said in many ways represents the views and sentiments of many, many representatives here and also representatives who may not be here for a variety of reasons. Because as we are midway in this process, we also have to think about what is success for the OEWG and for our work. If we define our success in a New York-centric way, then I think we would not have succeeded at all. Our success as a working group will depend on whether we are able to make a difference to the situation on the ground, in capitals, in different countries, small countries, developing countries, countries that need help to deal with the challenge of ICT security. I mean, there’s no doubt that there are many countries in the room who have the frontier technologies and the capacities to deal with threats and new kinds of emerging threats. But I think it’s important that we leave no one behind, which is in some ways the motto of this house, the motto of the United Nations, not just for this process, but across the board, leave no one behind. That’s the motto of the Sustainable Development Goals. That’s what we try to do in whatever different processes we have at the UN. That means being inclusive, role of women in peace and security, role of young people. All these are very important. So while I’m very heartened by the discussions on international law, and Uganda was the last speaker from delegations, I have two other requests for the floor from NGOs, and I’ll give them the floor in a while. While we had a very, very good discussion on international law, and I think that the discussions on international law fit into a pattern that I have observed from the podium since Monday, which is that our discussions are getting deeper, the tone is constructive, and my sense is also that people are keeping, I think, an open mind on a range of issues. So even in this area of international law, which is one of the most challenging ones where there are very diverse views, I think we are beginning to see an opening of minds, a willingness to listen, and I think that bodes well for the process, and for all of you, and for all of us here. So I was very encouraged by that, by the discussions we have had on international law. Many elements of convergence, convergence on the core principles, convergence on the core principles of the UN Charter, some of which were captured in the Second Annual Progress Report, a convergence also on a sense that we must go deeper into the discussion on how international law applies. Of course, there’s a difference of view as to whether the ICT domain is so unique as to warrant a different treatment. Quite a number of you have said that there’s nothing unique about it because technology does not determine the application of international law. Whatever the technology, international law applies in its entirety. But there were others who said that this was a domain that was sufficiently unique or had specificities which therefore required a different approach. But even those who said that this domain was not unique also said that it is a question of interpretation, and the interpretation was about nuances of understanding this particular domain, which also suggests that this domain requires a certain way of looking at it as opposed to looking at other domains like outer space or oceans. So of course, the larger debate under international law, the elephant in the room is this discussion about whether we need a new treaty, new binding norms, or no treaty, no new binding norms. It’s a question of interpretation and understanding. Now, if we leave aside the large elephant in the room, which is about the question of a new binding instrument, I think there is a lot of work we can do in a productive way by having a deeper conversation about what is it exactly we mean when we say it’s about interpretation in terms of how the law applies. Are there any specificities in the context of technology or in the context of the ICT domain that may require us to look at it in a slightly different way? So this is an ongoing discussion. I’m certainly not going to provide a summary because each one of you will be able to bring back things for your own reflection. But another area of convergence was about capacity building, which our colleague from Uganda just mentioned. Because capacity building keeps coming up in every domain. And I think that when we first began the OEWG exercise, this second OEWG, I think the understanding about the importance and the strategic nature of capacity building was perhaps not as well understood as it is now. Because everything comes down to capacity building. If you want your norms to be implemented, you need capacity building. If you want international law to be applied, you need capacity building. If you want to build confidence through CBMs, you need capacity building. So it has become very foundational, the whole question of capacity building. We are not discussing that now. We’ll come to it later. But that was a convergent element in the context of international law as well. And in that context, I think the Unity Workshop was referred to by many of you. And I thought that the fact that this Unity Workshop was supported by a cross-regional group in itself was significant, which would have been unthinkable maybe even a year ago or two years ago. This is a workshop that was organized by a cross-regional group. And there was also, I think, a convergence that we should continue that exercise, but not just that specific exercise, but continue exercises which involve discussions and widen the conversation and look at scenario-based discussions as a way of understanding how international law applies, what are we talking about when we say it’s a question of interpretation and understanding and nuances of how they are applied. And so I think this is an area where a lot more meaningful work can be done and must be done. Now, the conversations and work that we do on international law is not going to be immediately translated into a piece of paper. But I think these kinds of deeper conversations are very important. And I think it’s also important to bring in legal experts into the conversation and there to the question of legal capacity comes in, because not everyone has a legal team back home or even at the missions here in New York. So for those of you who attach a lot of importance to this particular cluster, you also need to keep in mind that we need to bring everyone into the conversation. So we need to go deeper, but we also need to go wider in terms of widening the participation and the number of countries, because we don’t want to have a very deep conversation among a handful of countries, because that is not going to be helpful in producing an agreement at the UN level. If you want to have a convergence, we need to go wider. And then over time, expand the areas of understanding. And then there were also many other areas, law of state responsibility, principle of due diligence, international humanitarian law, international human rights law. These are areas on which there’s no immediate convergence, but I think definitely areas where we need to have more conversations. And our colleague from Bangladesh is not here, but he drafted a very good statement without the aid of any lawyer or legal team. So I think these are principles, and some of the principles like due diligence or international humanitarian law, at some point we need to involve legal experts. And the final point I would make is that many of you said that you look forward to the dedicated intersessional meeting. That will be also an opportunity to go deeper, and bring legal experts from outside who can then facilitate and help to moderate the discussion. So all in all, once again, an A plus for all of you. You have answered all the four questions. Many of you had to abbreviate your presentation at my request, but I thank you for submitting your inputs to the Secretariat. Yes, so we’ll now take the two last statements from on this item of international law. I give the floor to the ICRC. And then, yeah, ICRC, please. And then the OAS, ICRC.
ICRC
Good afternoon, Mr. Chair, dear colleagues. The International Committee of the Red Cross is grateful for the opportunity to address the succession of the OEWG. We commend States for adopting an annual progress report earlier this year, which recommends States to continue to engage in focused discussion on how international law applies in the use of ICTs. This includes international humanitarian law. The ICRC shares the concern of States about the continuing increase in incidents involving the malicious use of ICTs by States and non-State actors, in particular during armed conflict. In our view, focused exchange among States on the limits that IHL imposes on such operations is urgently needed. We would therefore like to highlight two issues that we believe require particular attention by States in this Working Group. First, we are concerned with belligerents that they are using cyber operations not only against their adversaries but also to target civilians. As a result, new risks arise for populations already enduring the horrors of war. This means that life-saving hardware in hospitals is becoming inoperable, power grids on which civilian lives depend are disabled, and data collected by humanitarian organizations and used exclusively for humanitarian ends may become lost or unavailable. In many instances, cyber operations do not result in physical damage but in disrupting or disabling digital infrastructure and services. This new digital dimension can be addressed through existing rules of international humanitarian law. This requires, however, that the long-standing rule of IHL be interpreted and applied in ways that ensure adequate protection for civilian infrastructure and civilian data in our increasingly digital societies. Interpretations of IHL that focus solely on the protection of civilian objects against physical damage are insufficient. In our view, exchanges among States on this issue are of great importance and urgency. The second matter of serious concern for the ICRC, and which we believe this Working Group should focus on, is the growing involvement of civilians, individuals, hacker groups, and companies in the digital operations related to armed conflicts. The more civilians take part in military operations and the more civilian infrastructure, such as civilian satellite communication or cloud infrastructure, is used for military purposes, the greater the risk of civilian and civilian infrastructure being targeted. This trend risks undermining the universally supported principle of distinction and must be reversed. To this end, we call on States to stop turning a blind eye to the participation of civilian hackers in armed conflicts. In addition, States and the tech sector should consider the potential risks that arise when civilian digital infrastructure is used for military purposes and work towards a common understanding of the limits of the military use of civilian digital infrastructure during armed conflicts. In October this year, the ICRC Global Advisory Board on Digital Threats during Armed Conflicts released its final report, which outlined four guiding principles and 25 recommendations to protect civilians against such threats. These principles and recommendations were developed jointly with a group of high-level leaders and experts from the legal, military, policy, technological, and security fields. We would like to draw attention to delegates to this report, and some of these recommendations can also inform the work of this group. During the March session of next year, the ICRC will co-organize a side event to discuss these guiding principles and recommendations. Thank you.
Ambassador Gafoor
Thank you very much, ICRC, for your statement. I give the floor now to the Organization of American States.
Organization of American States
Chair, thank you. I would like to specifically address the question on what specific capacities are most urgently needed and what existing initiatives and programs targeting these specific concerns exist. Chairing the Americas, not many of our states have adopted a robust position on the main issues of international law and cyberspace, whose scope is being debated. The efforts made by the OAS through CICTE and the Inter-American Juridical Committee (CJI) have made a positive contribution to deepening dialogue and exchanges for state positions on the matter, fostering more transparency among the OAS member states. For instance, in 2020, CJI adopted a report entitled “International Law and State Cyber Operations, Improving Transparency,” which provides parameters on the application of international law inside of cyberspace and points of convergence and divergence about the understanding of these international rules within OAS member states. This document provides transparency and improves subject matter knowledge in order to limit the risk of escalation or conflict. Further, in 2022, that committee also adopted a similar report on international law applicability to cyberspace, which provided an analysis on major issues of international law, including attribution, breach of international obligations, and responses available to states that have been a victim of a malicious cyber operation. It also integrated the official positions of OAS member states since 2019. In the case of specific capacity building programs, Chair, we would like to share that as a part of supporting the OAS’s already agreed CBMs in cyberspace, we have been assisting member states by doing cyber diplomacy courses and helping them to understand international law’s applicability. We wanted to cite two examples, so at least member states here could be very clear on how this could be applied. With the support of the Government of Canada, the OAS member states have been benefiting from the International Law of Cyberspace Operations courses delivered by Cyber Law International. Additionally, with the support of the Government of the United Kingdom, the CICTE cybersecurity program has staged two master classes that specifically address state responsibilities and response options, and another one on the application of international humanitarian law in cyber operations. Chair, CICTE continues to use practical methods to help our member states derive their national positions, and we will be working with Chatham House in the next coming year to deliver two national dialogues on international law and cyberspace as a pilot program within our member states. This initiative, we believe, will help our member states to identify gaps on international law and on IHL in cyberspace, as well as support them in developing national state positions. One last point we would like to mention is, as it relates to international humanitarian law, our Department of International Law within the OAS continues to play an active role in advancing the dissemination of IHL in the Americas. They work very closely with the ICRC in the development of courses related to IHL, and we are aware that the ICRC, since 2015, continues to urge states to establish internationally agreed limits, as well as on autonomous weapon systems to ensure civilian protection. Chair, I wanted to just close by sincerely addressing you as well. I believe your sincerity in the approaches that member states should take to capacity building is received. As a technical secretariat for an international governmental organization, we believe that member states here within the UN cannot only hear what the OAS is doing in this area, but we are pretty open to be consulted, discussed with, or accessed to be able to give other regions ideas on how they can approach cybersecurity capacity building. Chair, on that note, thank you for your leadership, and we look forward to the further deliberations for the rest of the week.
Ambassador Gafoor
Thank you very much, OAS, for your contribution. Your role is very much appreciated, and please do remain engaged in our process because we need all the help we can get. So, that was the last speaker on international law. We’ll now move to the next item on the agenda, or rather the next topic under agenda item five, relating to confidence-building measures. The floor is open for those who would like to kick off the discussions on CBMs. It’s another big topic. Yep, I see delegations are pressing the button, so we’ll go through the speaker’s list today as much as we can. Starting with the Russian Federation, followed by Australia. Russia, please.
Russia
Mr. Chair, we welcome the recommendation of the OEWG’s second annual report to approve elements of a global intergovernmental points of contact directory for the exchange of information on computer attacks. As a first confidence-building measure in the field of information security, we consider the establishment of the POC directory as an important practical outcome of the group’s work and a milestone in the negotiation process. This is clear evidence of the effectiveness of the OEWG format and its ability to make important decisions. We thank the Chair, Mr. Gafoor, for his skillful leadership of the group’s tireless efforts. We believe that the global intergovernmental POC directory should become a central link in organizing the interaction between countries in responding to computer incidents. It’s important that all states, with no exception, should use this tool in good faith to develop depoliticized cooperation with a view to reducing tensions and preventing misperceptions of ICT incidents. This, in turn, would significantly reduce the risk of a direct interstate confrontation in cyberspace. There’s a demand for specific steps toward an early launch of the POC directory. We believe it would be reasonable to start by forming a list of available points of contact at the technical and diplomatic levels. We assume that diplomatic points of contact can be an authorized national agency responsible for international cooperation, the Ministry of Foreign Affairs, and the technical POC could be an authorized national organization responsible for preventing, detecting, and responding to and mitigating the consequences of ICT incidents. Once we’ve actually created the global directory, it would be possible to move on to practical POC activities in 2024, including the organization of regular in-person and virtual meetings, communication checks, and the form of ping tests. Parallel to that, there’s a need to continue within the framework of OEWG, discussing possible ways for further stepwise improvement of the directory, according to Annex A to the second annual report, including communications protocols and the necessary capacity building measures. Thus, in order to optimize interaction within the POC directory, it’s appropriate to develop standardized message transmission templates. Such templates could include the type of information requested, including technical data and the nature of the request. As for extending assistance in responding to computer incidents, in our opinion, at the initial stage, it is necessary to formulate the specific list of the needs of each state. We also welcome OEWG’s approved initial non-exhaustive list of voluntary global confidence-building measures, as contained in Annex B, based on the confidence-building measures that were agreed by consensus in the OEWG reports for 2021, 22, and 23. This work must continue. It would also be helpful to consider, in particular, holding consultations, including through competent agencies, on activities in the information space that might raise states’ concern with a view to preventing and settling conflicts by peaceful means. A fundamental point here is that confidence-building measures must not be used as a tool for interfering in countries’ internal affairs, for a biased political assessment of states’ actions and intentions in the information sphere, and a subsequent adoption of various types of penalties, such as sanctions and other response measures. Mr. Chair, let me also make a brief statement in furtherance of the discussion with stakeholders. I would like to draw your attention, and the attention of the UN Secretariat and member states, to the fact that the host country of UN headquarters has once again denied entry visas to an expert of a Russian non-governmental organization, already accredited under the group. This is an attempt to cut the scientific and research community of our country, which has the right expertise, off of discussions within the group. This undermines confidence-building, which we are discussing at this very moment. We call on the Chair and the UN Secretariat to take possible measures to stop this wrongful, discriminatory practice by the United States. Thank you.
Ambassador Gafoor
Thank you very much, Russian Federation, for your statement. Your comments are noted. I give the floor now to Australia, to be followed by India. Australia, please.
Australia
Thank you very much, Chair. But before I make my intervention on CBMs, I really wanted to take the opportunity first to thank everyone at the back of the room. I found that really helpful in such a short period of time. I wrote down so many notes, but just the way that this interacted with our discussions so far, there was discussion about default security, security by design for IoT and for operational technologies in AI and in critical infrastructure, which are things that we’re thinking about so much and were part of our threats discussion on Monday. I liked hearing from Chatham House about the operationalisation of our capacity building principles, and we heard from quite a few people on international law and how we can continue those discussions. And in particular, I was very pleased to hear about the focus on mainstreaming gender in these discussions and also the ideas about supporting other communities like youth and young people to support them to bring them into this community in this discussion. So thank you everyone up the back. That was wonderful. Turning now to confidence building measures, I really want to recognise the progress that we made in July to agree in our 2023 APR this initial list of voluntary global CBMs. Building on the progress of that July session, the cross-regional group of confidence builders yesterday published a joint paper, which is now available on the OEWG website. Australia is very pleased to be part of this group and a contributor to this paper with Argentina, Brazil, Canada, Chile, Colombia, Czechia, Fiji, Germany, Israel, Republic of Korea, Mexico, the Netherlands, Singapore, and Uruguay. It’s a mouthful. This group’s newly published joint paper strives to further advance the elaboration of the initial list of global CBMs by drawing on and providing some examples of existing national and regional practice in the implementation of the APRs for CBMs. We’re hoping that by providing a more practical angle to our discussion on CBMs, this paper aims to encourage states that may be a little bit less familiar with implementation of CBMs to consider some specific examples from our group’s collective experiences. We also hope that this paper proves a method of responding to your guiding question, Chair, on how we can accelerate universal implementation of the initial list of global CBMs by transparently sharing best practice and these examples. In Australia’s contribution to this paper, we provided some examples of transparency measures that we have undertaken to share information on a voluntary basis, including concept papers, national strategies, policies, and programs, and information on these transparency measures under CBM3. Turning to the Global Point of Contacts Directory, Australia is committed to working with all of us to breathe life into this very important initiative. We think that the time is now ripe to operationalise the directory. In our previous interventions, we have said that Australia is supportive of taking an incremental approach to the POC directory and this operationalisation. And once the UN administration is in place, we know that that takes time, those states that are in a position to nominate their diplomatic and technical POCs should do so in a timely manner, if possible, so that we can get the POC directory up and running. But we also recognise that not all states will be in a position to nominate POCs immediately. And states or groups of states in a position to do so should consider supporting outreach, awareness raising, and capacity building with regards to this POC directory, including on participating in the directory and understanding the roles of diplomatic and technical POCs. Finally, Chair, you asked us to consider whether there are any additional CBMs to be added to our initial list. I’m afraid I haven’t done my homework yet to answer this question. But Australia is in principle a strong supporter of this endeavour. We will listen very closely to other ideas that are put forward. And we hope that this is a project we can make progress on and do our homework on over our new cycle. We look forward to the dedicated international meetings as an opportunity to get down to work in adding to our list. Thank you, Chair.
Ambassador Gafoor
Thank you very much, Australia. No, I was just talking to the Secretariat in terms of when the budget is going to be approved. I think it is going to be approved at the end of the month. The Fifth Committee is meeting, and once that budget hurdle is passed, then I think we enter the domain of finding a person, and the recruitment process is run by the UN Secretariat. But in any event, it is my hope to organize very early in the year an information session on the POC directory after having heard from the Secretariat on what exactly is the status, maybe in a month or two from now. And that way, we can go through the different elements that will be related to the implementation and operationalization of the POC directory. Some of these administrative parts relate to the Secretariat, and so I’m not in a position to commit the Secretariat because they have their own rules, regulations, and requirements as well. So I will need to sit down with Catherine, but also with the Under-Secretary-General. My intention is to organize an information session early in the year. It won’t be January, certainly. In January, maybe in February or March, as soon as I have enough information as to where we are on the administrative establishment of the POC directory. Meanwhile, I think we should work on the assumption that it is important and possible to have an operationalization of the POC directory in the first half of the year. In fact, well before the first half of the year, I hope, so that it is ready to do some of the things that it needs to do. But the exact timing is not something that I can commit to because the budget has not even been approved. It’s being discussed now, right now, even as we speak this week. So that’s just by way of background because the first two speakers, Russian Federation and Australia, both referred to the operationalization, and so I thought I would make that brief remark. The next speaker is India, followed by Egypt.
India
Thank you. Mr. Chair, the essence of CBMs lies in creating a framework that encourages open dialogue and cooperation among States, reducing the likelihood of misunderstandings and the unintended consequences of cyber activities. These measures can take various forms, including information exchange, joint capacity building efforts, and the establishment of communication channels to address cyber incidents promptly. Our delegation would like to emphasize that with the necessary resources, capacities, and engagements, CBMs can strengthen the overall security, resilience, and peaceful use of ICTs. CPMs can also enable the implementation of norms of responsible State behavior in cyberspace, in that they foster trust and ensure greater clarity, predictability, and stability in the use of ICTs by States. Our delegation believes that there is a broader requirement to understand and define foundational values to build confidence among Nations that are demarcated with clear physical boundaries but overlapping virtual boundaries in cyberspace. CBMs, like norms, may have relevance at the global level, while propagation and implementation could continue to happen at the regional level. It may be kept in mind that regional measures may vary when compared with each other, and to that effect, harmonization of regional CBMs is the key to developing a common action by the international community. Another crucial aspect of CBMs is the establishment of communication channels and mechanisms for incident response. Rapid and reliable communication can prevent misunderstandings and de-escalate tensions in the event of a cyber incident. India’s proposal for a global cybersecurity cooperation portal is one such mechanism that would create a UN-based repository, and such a repository would enable timely information exchange. Cyberspace is being widely used for the proliferation of misinformation, smear campaigns, and terror propaganda. An obligation of the States to cooperate on countering terror propaganda on the Internet by actions such as removing harmful content, alerting other Member States of cyber activities of concern, and cooperation in investigating terrorist attacks mounted through ICTs could build robust trust and confidence between Member States. Such practices also help in bringing Member States together. Apart from it, differentiating between cyber terrorism and other cyber incidents needs to be given due priority. States should consider ways by which data residing within their own territorial jurisdiction is not seen as exclusively their own and must take into account factors such as data ownership and data subjects in determining jurisdiction owing to the unique situation that prevails in cyberspace. In refraining from attacking or targeting critical infrastructure, States must recognize critical transnational networks and respect the designation of critical infrastructure and transnational infrastructures by other States and be guided by what Member States consider as critical infrastructure within their own territories. Mr. Chair, emphasis should be given to conducting joint drills and tabletop exercises involving national computer emergency response teams at regional levels. The OEWG mandate, during its mandate till 2025, may focus on building mechanisms for States to consider how best to cooperate on investigating cyber crimes and sharing digital forensics data with other States so that forensic evidence could mitigate cyber crime and malicious activity. The OEWG should attempt to develop innovative frameworks to deal with the emerging challenges in cyberspace based on a common understanding of all Member States. India’s engagement with various countries through bilateral, regional, and multilateral platforms is based on practical cooperation and concrete action plans. In this regard, the OEWG may explore the potential of developing effective mechanisms for swift information exchange and response between law enforcement agencies and governments for facilitating cross-border coordination and cooperation between concerned authorities to counter terrorist and criminal use of ICTs. Our delegation proposes that as a way forward for the OEWG during its mandate, the Member States may come together to create an indicative list of agreed CBMs, though not an exhaustive one, that could be implemented on a voluntary basis on similar lines of the norms, principles, and rules of responsible behavior of States. Thank you.
Ambassador Gafoor
Thank you very much India. Egypt, followed by Thailand, please.
Egypt
Thank you, Mr. Chairman. I should like to make the following statement on behalf of the Group of Arab States. The Arab Group first and foremost expresses appreciation to you and to the Secretariat for all the efforts that have been made over the last two years to push our work forward. Mr. Chairman, the Group stresses the need to include CBMs under cybersecurity. This would allow effective communication among states, bringing viewpoints closer, avoiding escalation, and avoiding armed conflict among states in cyberspace. We welcome the consensual agreement on national CBMs – POCs, I apologize, for cybersecurity, and we look forward to authorizing this list as soon as possible, and we believe that an incremental approach must be taken in developing it. The Group believes that we must begin for the list to start working without beginning to develop it. We believe that this would give states the opportunity to identify gaps and relevant challenges, taking into consideration the relation between this list of POCs to take up cybersecurity under the umbrella of the United Nations. As for national capacities and their building, the Group points to the valuable measures in the annex, and we look forward to their rapid implementation. This includes measures through the Secretariat of the United Nations as well as the Open-Ended Working Group, including, one, having a digital approach to the online tutorial, 101-2, as well as digital decisions on e-modules, as well as simulation tabletop exercises for experts in order to share best practices and expertise. We should like to point out the importance of committing to this list at the United Nations because we believe it is the link that brings all these measures together – including the holding of meetings to national POCs. In a related field, the Arab Group welcomes or stresses the importance of cooperating and collaborating with the standing regional mechanisms on cybersecurity, and we – our states, rather – through the Arab League have promoted CBMs among them, as well as – and we have also developed national response teams, CSIRTs. We have also participated in informal consultations held by the Secretariat of the United Nations with the Group in Cairo in September 2023 concerning the future mechanism for cybersecurity and the POA established in accordance with Resolution 37-77 of the General Assembly. We have taken note of the lists of CBMs in the second APR of the Working Group, which fundamentally is based on the final report of the Working Group in 2021 and the measures referred to in the first annual report of this year. We stress the need for cooperation and dialogue at all levels – bilateral, sub-regional, regional, and multilateral – as well as workshops among the POCs of member states. This would ensure sharing best practices and expertise. That would also be beneficial at the international level to build CBMs that would be drafted sub-regionally and regionally if agreement is reached on them within the United Nations, having decided whether such measures are useful or not. In conclusion, the Arab Group expresses its confidence in this Working Group as it allows dialogue and consultation among states, which is one of the best means of building CBMs. We continue to support the chair of the Working Group, and we shall continue working positively within it. Thank you, sir.
Ambassador Gafoor
Thank you very much Egypt. Thailand, to be followed by Cuba.
Thailand
Thank you, Mr. Chair, for giving me the floor. On CBMs, Thailand wishes to make the following points. First, Thailand welcomes the establishment of the Global POC Directory, which is one of the concrete contributions by the OEWG to building trust and confidence among states and serves as a tool for mitigating threats in cyberspace. Therefore, as mentioned earlier by many states, we support its operationalization at the earliest opportunities. In this regard, Thailand wishes to reiterate that capacity building and international cooperation to equip states and relevant stakeholders with necessary tools and skills remain crucial to ensuring the effective functioning of the Global POC. Second, Thailand believes that CBMs can be strengthened at the regional level to facilitate the acceleration of the CBM between regions and at the global level. We support the involvement of the regional body as they play a crucial role in fostering trust, enhancing cross-sectoral, cross-pillar coordination, broadening networks, and promoting confidence among states within and between regions, as well as their external partners. Within ASEAN, we have put in our concerted effort to strengthen cybersecurity through several platforms and mechanisms, such as, to name a few, the ASEAN Cybersecurity Coordinating Committee, ASEAN Regional Forum Inter-Sessional Meeting on Security of and in the Use of Information and Communication Technologies, and ASEAN Regional Forum Points of Contact Directories. We believe that our undertakings at the regional level help facilitate the implementation of the CBM at the global level. Third, looking ahead, as previously mentioned by Indonesia and Tonga, we believe that third-to-third cooperation at the global level represents a possible area of our collective efforts in strengthening CBMs, complementing the establishment of the POC Directory. We believe that third-to-third cooperation has the potential to facilitate collective responses and enhance readiness against cyber threats. In implementing a global third-to-third cooperation, we can learn from efforts at the regional level, including ASEAN’s third-to-third cooperation among ASEAN members and COMPASS, among other things, information sharing, and cyber threat assessment that help foster regional preparedness, operational readiness in responding to cyber incidents, as well as the protection of CI and CII. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Thailand. Cuba, to be followed by European Union.
Cuba
Thank you, Mr. Chair. One of the results of the previous session of this Open-Ended Working Group was the adoption of elements to prepare and implement a global intergovernmental directory of points of contact as a confidence-building measure. With a view to the development and the operationalization of the global directory, we insist that we should guarantee the adequate treatment of the information to be exchanged and the expeditious coordination given cyber incidents among the national points of contact designated by states at the technical and/or political level. In that regard, we underscore that a clear protocol should be established to define the contents of information to be exchanged, circumstances, and equality of conditions in which that exchange would take place. The measures mentioned in paragraph 37C of the second APR could contribute to that. We need to strengthen capacity in developing countries so that we can adequately implement the directory of points of contact. In this regard, it is imperative for developing countries to receive training and transfers of technology. We agree that we cannot neglect the experiences of existing international and regional mechanisms which have the participation of all states since they have POC directories such as the ILO. However, we are not in favor of trying to impose the recognition of specific organizations as regional interlocutors on this subject when they do not include the participation of all member states of the region in question. Confidence-building measures implemented at the regional or sub-regional level cannot be considered global models since every region has its particular characteristics. A global POC directory and the CBMs included in the initial and not exhaustive list in annex B of the second APR are not the only actions on which we should focus our efforts. As recommended in the APR itself, states should continue to exchange points of view in the Open-Ended Working Group with regard to the elaboration and implementation of CBMs, including the possible preparation of additional measures. In that regard, our delegation emphasizes the need to have measures that favor cooperation and capacity building to close the digital divide and to guarantee universal, inclusive, and non-discriminatory access to information and knowledge through ICTs. It is not possible to develop confidence in a context in which there are obstacles and unilateral coercive measures against developing countries that limit their capacities in contravening international law. The initial list of CBMs in annex B does not include capacity building yet and minimally refers to cooperation among states when such cooperation can be seen as a confidence-building measure in itself. At the same time, it is clear that CBMs as a complement to the improvement of cooperation and transparency do not replace the norms, rules, and principles of responsible state behavior which should be established to guarantee the peaceful uses of cyberspace. We insist that we need binding norms. Thank you.
Ambassador Gafoor
Thank you, Cuba, for your statement. European Union, to be followed by Pakistan.
European Union
Thank you, Chair. Excellencies, I have the honour to speak on behalf of the European Union and its 27 Member States, the candidate countries North Macedonia, Serbia, Montenegro, Ukraine, Albania, the Republic of Moldova, and Bosnia and Herzegovina, the potential candidate country Georgia, and the EFTA countries Iceland and Norway, members of the European Economic Area, align themselves with this statement. Under the current circumstances, building mutual trust between countries remains more important than ever. As one key element of the framework for responsible state behaviour in cyberspace, confidence-building measures are an essential tool in mitigating the risk of misperception, miscalculations, and unintended escalation. Recent years have seen significant steps by several regional organisations in developing and implementing confidence-building measures. They have acted as an incubator for national implementation of UNGGE and OEWG confidence-building measures, and additionally have developed their own initiatives. The European Union is working closely with three regional organisations with cyber-CBMs programmes: the Organisation for Security and Co-operation in Europe, the ASEAN Regional Forum, and the Organisation of American States. Each organisation is unique, but some elements of success get across the regions. Last month, with the aim of learning from regional experiences and looking for cross-regional synergies, we organised together with UNODA and UNIDIR an event at the OSCE that brought together all above-mentioned organisations. All regional organisations agreed that CBMs are recognised as pivotal diplomatic tools, serving not only as goals but also as guidance in diplomatic initiatives. The mutual benefit of CBMs underscores their strategic significance in fostering international cooperation and addressing cybersecurity challenges. But CBMs also take months, if not years, to become operational, and they need a permanent structure around them. For example, the OSCE developed and adopted a CBM initiative, where individual states or a group of states are in charge of putting a CBM into action. Through such initiatives, regional organisations can play a crucial role in facilitating mutual understanding between countries, acting as a platform to form consensus around interpretation and implementation. After the adoption of CBMs, the OSCE has been focusing more than ever on operationalisation of CBMs through increased targeted support and capacity building for OSCE-participating states. This takes place in the format of scenario-based discussions, where government officials are exposed to the practical application of CBMs and norms of responsible state behaviour and sub-regional training for policymakers, technical experts, and private sector representatives. The OSCE has also developed virtual capacity building tools, such as e-learnings and good practice reports, which aim to further implement CBMs in the OSCE area, as well as raise awareness of OSCE cybersecurity efforts globally. A good example of such an implementation is the EU-run annual tabletop exercise for cyber attachés and capital experts of EU member states within the framework of the Horizontal Working Party on Cyber Issues. The exercise focuses on how to respond to malicious cyber activities with diplomatic measures and to support the crisis management decision-making process. This activity corresponds with OSCE CBM 5, use of OSCE as a platform for dialogue, exchange of best practices, awareness raising, and information on capacity building. During the event, participants also emphasised the merits of holistic approaches to CBM implementation. In particular, they highlighted the importance of prioritisation, sustainable development, and regional collaboration. Strategies such as mapping projects to identify relevant organisations and initiatives, regional dialogue, and the creation of points of contact demonstrate a comprehensive effort towards this direction. In addition, states may consider establishing or identifying appropriate points of contact within the private sector. Challenges in CBM development and implementation are the lack of immediate metric of success, reluctance to share information, and the complexity of fitting CBMs to diverse national contexts, taking into account local idiosyncrasies. Although such information sharing can be valuable, there are also limits to that value. Replicating what works in one region will not ensure success in another. Thus, there is a need for regional adaptation and ownership. Simultaneously, the potential for regional collaboration and the importance of understanding national perspectives on assistance highlight the opportunities for effective cooperation on CBM development and implementation. In this context, CBMs are crucially enabling measures for implementation of CBMs and provide concrete support to overcome the aforementioned challenges. The EU continues to believe that cyber confidence-building measures are best implemented by regional organisations with the capacity and regional expertise to take on such programmes and adapt them to the regional context. But we need to keep in mind that although nearly half of the world has pursued a regional cyber CBM framework, still not all UN member states are members of multilateral or regional organisations with cyber CBMs programmes. Therefore, the initial list of voluntary CBMs at the global level is a useful step. We believe that the UN’s primary role on cyber CBMs should be to develop global recommendations and encourage cross-regional dialogue and exchanges while taking into account and complementing existing activities in regional organisations. I thank you, Chair.
Ambassador Gafoor
Thank you very much, European Union. We give the floor now to Pakistan, followed by Kazakhstan.
Pakistan
Thank you, Chair. Pakistan considers cyber CBMs extremely important for fostering trust, cooperation, transparency, and predictability among the member states, and to avert misunderstanding and escalations of conflict. It was quite encouraging to see, as outlined in the Second Annual Progress Report, a general consensus among the states on the establishment and operationalization of the Global Point of Contact Directory. Pakistan, from the beginning, has been calling for the establishment of a platform like the POC Directory at the global level that could help to promote an open, secure, stable, accessible, and peaceful ICT environment. Therefore, Pakistan calls for an early operationalization of the POC Directory and stands ready to engage in technical discussions. In this regard, we appreciate your explanation and look forward to further details early next year. The need for a platform like the POC Directory becomes more critical in view of rising trends of cyberattacks on critical infrastructure, which are getting more complex and sophisticated. Moreover, the emergence of AI-assisted cyberattacks, such as DeepFakes, have added a non-linear path to escalations. Other than the POC Directory, Pakistan stresses the importance of increasing cooperation among the respective computer emergency response teams of member states to address investigation, trust-back requests of cyberattacks. However, limitations on the technical capacities of developing countries to address such requests may be taken into account. Appointment of focal personnel at the national level and the establishment of outlines will help in averting confusion and prompt exchange of information in case of major cyberattacks against critical infrastructure. Voluntary and timely disclosure of hardware or software vulnerabilities by member states and sharing it with others is also crucial. Finally, Mr. Chair, joint research, investment in cybersecurity-related projects, and exchange of best practices could be of help as well. I thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Pakistan. Kazakhstan to be followed by Sri Lanka.
Kazakhstan
Thank you, Chair, for giving the floor. Kazakhstan fully supports the implementation of confidence-building measures as they play a crucial role in ensuring responsible state behavior and the use of ICT. In this section, it is proposed to apply the importance of considering issues related to public-private partnerships in the field of ICT as a confidence-building measure. This is relevant in the context of managing cyber risks at the national level, where the establishment of effective public-private partnerships can serve as a means of combating threats in the ICT sector. We recognize the significance of PPPs in the use of ICT, as they can serve as a tool in facilitating the effective detection, prevention, and response to cyber security threats. In our case, within the framework of PPPs, Kazakhstan is actively operating with the private sector, including in the usage of the platform for vulnerability detection. Also, it is important to note that this week in Kazakhstan, a new package of amendments to legislation on information security was signed, aimed at strengthening the protection of personal data and introducing legal regulation of the institution of white hat hackers. Additionally, legal mechanisms for ensuring information security are being introduced through the creation of a program for collaboration with cyber security researchers. We support enhancing mechanisms for the exchange of information on cyber threats and incidents between states in the field of ICT within the framework of the OEWG. These steps aim at strengthening international coordination for the effective counteraction of cyber threats. Sharing vulnerability information is crucial for states, as it is integral to fostering responsible behavior in the use of ICT. Also, as a confidence-building measure, the implementation of cyber security capacity-building platforms might be considered, fostering the development of highly skilled professionals, strengthening defenses against cyber threats, and cultivating public trust in the digital environment. Additionally, as one of the confidence-building measures, it is important to highlight that states recognize the importance of critical infrastructure protection from cyber threats and challenges. Given its important mentioning across all sections of the project report, underscoring the importance of protecting critical infrastructure is vital in the establishment of cyber resilience. Thank you.
Ambassador Gafoor
Thank you, Kazakhstan. Sri Lanka to be followed by the United States.
Sri Lanka
Thank you, Mr. Chairman, for giving me the floor. Mr. Chairman, we have given careful consideration to the guiding questions that have been provided to us before we engaged in this discourse. Sri Lanka, Mr. Chairman, underscores the profound importance of cybersecurity for social and economic development. We acknowledge the critical role of cybersecurity and infrastructure protection in fostering social and economic development for states. We support any action-oriented proposals on confidence-building measures to address the evolving challenges in the use of information and communications technologies through practical and action-oriented proposals that are essential to bridge the trust deficit in the field, promoting international cooperation and collective security. Mr. Chairman, recognizing the link between ICT access and UN Sustainable Development Goals, Sri Lanka emphasizes the significance of expanded ICT access for achieving the SDGs, particularly Goal 9. Security and trust in ICTs are integral to building resilient infrastructure, promoting sustainable industrialization, and fostering innovation, contributing to the overall success of the SDGs. We express our support for the Global Point of Contact Directory, seeing it as a significant step towards building confidence. The sharing of lessons learned between countries through this directory is crucial for assisting those with less capacity, contributing to the implementation of the Global POCs. Sri Lanka aligns itself, therefore, with the Chair’s emphasis on achieving a milestone in confidence-building measures through the establishment of a Global Point of Contact Directory. Operating the directory comprehensively, considering competencies, information types, and interaction modalities, is vital, and we fully appreciate that aspect of the matter. Mr. Chairman, we advocate for simplicity, broad participation, and prevention of duplication, endorsing both single, national, and separate discipline-specific contacts to ensure compatibility with domestic structures. This nuanced strategy fosters, we say, a secure digital landscape and effective harmonization with diverse national frameworks for enhanced global cybersecurity cooperation. In our pursuit of confidence-building measures, Sri Lanka actively enhances its capabilities through the Computer Emergency Readiness Team. Our focus on investigating cyberattacks, maintaining confidentiality, and globally sharing threat intelligence underscores our commitment to preventing ICT misuse and safeguarding critical information infrastructure. Cybersecurity and protection of infrastructure, as I said, are essential for the social and economic development of any state. So in view of the need for an evolving framework for responsible state behavior in the use of ICTs and to service, as I said, the trust deficit in this field, expanded access based on security and trust is therefore recognized as essential to accelerate progress on all 17 SDGs. In this regard, we welcome the non-exhaustive list of proposals mentioned in the Second Annual Progress Report of the OEWG. To universally implement these CBMs, Mr. Chairman, it is crucial that states are provided with the required capacity-building measures. Developing countries, such as Sri Lanka, are not often best positioned to address cybersecurity challenges due to a lack of local capacity, resources, policy framework, and research ecosystems, even though they may have the required political will. Permit me to refer briefly to the alarming rise in ransomware attacks, which poses severe threats to critical infrastructure and global supply chains, making it a focal point for confidence-building measures. We therefore welcome Canada’s active engagement in initiatives like the Counter-Ransomware Initiative. For this purpose, Sri Lanka recognizes the establishment and operationalization of the Global Point of Contact Directory, which we say is a significant step towards building confidence. Mr. Chair, Sri Lanka has taken steps to improve CBMs in terms of providing assistance by CERT in investigating cyberattacks and maintaining confidentiality of investigations. Moreover, Sri Lanka has strictly adhered to data protection through the data protection provisions in the law and developed and implemented a guideline on cyber hygiene and minimum baseline standards. We further highlight the need for enhanced training and awareness programs on cybersecurity. You would appreciate that confidence-building in the sphere of ICT is a gradual process, which requires the sustained and honest engagement of the member states, regional bodies, the private sector, the technical community, academia, and civil society. Strengthening, therefore, confidence and trust necessitates progress in other areas, such as clarity on implementing norms and applying international law. The framework of responsible state behavior in cyberspace, Mr. Chairman, must, therefore, be approached in its entirety in order to allow for an effective operationalization of CBMs as essential tools for enabling cyberspace. I thank you, Mr. Chairman.
Ambassador Gafoor
I thank the Ambassador of Sri Lanka for the statement, and I give the floor now to the United States, followed by Canada.
United States
Thank you, Chair. The United States has been supportive of the OEWG’s work on confidence-building measures and is pleased the group was able to reach an agreement in July to establish the global POC directory. We appreciate the update on timing among the POC directory’s establishment, and we look forward to hearing more in the new year. In pursuit of these efforts, we encourage the OEWG to collaborate closely with organizations like the OAS, OSCE, and ARF, who have existing directories, to ensure cohesion and leverage synergies where possible. POC directories can assist in conflict prevention in times of urgency and are relevant for our work within the UNGA First Committee. We were pleased to see this fact reflected in paragraph 5D of Annex A in this year’s APR. As this group begins the work of operationalizing the POC directory, it will be useful to look to the work done in regional organizations where POC directories have been built, maintained, exercised, and used by states to share urgent information. For example, the OSCE Cyber Informal Working Group has conducted communication tests and other exercises to ensure the proper functioning of its POC directory, and participation in the OSCE CBMs remains quite active. As an example, this morning the United States used three of the OSCE cyber CBMs to share technical information on malicious Iran-affiliated cyber activity targeting U.S. water systems. We believe that by sharing information through these channels, we can both facilitate mitigation of the threat as well as indicate the seriousness with which we view the activity. CBMs such as these create transparency by enabling information sharing through both technical and diplomatic channels that can help de-escalate in times of crisis and ensure countries are aware of timely threat information. Finally, I want to highlight that CBMs such as POC directories underpin some of our work on norms, as we emphasized during our remarks on the norms agenda item. One example is norm 13d on cooperation between states. This norm encourages states to strengthen and further develop mechanisms that can facilitate exchanges of information and assistance between relevant national, regional, and international organizations. The OEWG is well placed to dig into how states should go about such efforts, which would help turn these recommendations into reality. Thank you.
Ambassador Gafoor
Thank you very much, United States, for your statement. Canada, to be followed by Japan.
Canada
Thank you, Mr. President. Canada is pleased with the accomplishments achieved by adopting the decision proposed by you, Mr. President, this fall, so that the global directory of points of contact is realized. To answer your first guided question, one of the ways to support the implementation of the initial list of CBMs is to promote the sharing of experience at the regional and national level. The inter-regional group, Confidence Builders, circulated earlier this week a working document expounding good practices and regional experiences. Canada will be in a position to share experience acquired in that regard in the area of CBMs within the OAS and OSCE. We will continue working with this inter-regional group and call the attention of other members to the working document, which we hope could be helpful in implementing CBMs globally. Furthermore, CBMs are part of a process of targeted capacity building, which helps its operationalization. Paragraph 14 of Annex A of the second report makes it imperative that we encourage states to participate in the directory, working with GFCE and other stakeholders. An additional way of supporting participation in the directory is discussing the benefits of this directory in our conversations at the bilateral and regional levels. Finally, the development of protocols and other tools could also help promote this process in the regional and inter-regional context. Supporting responsible state behavior in cyberspace. Thank you very much.
Ambassador Gafoor
Thank you very much, Canada. Japan, to be followed by Switzerland.
Japan
Thank you, Mr. Chair. We would like to reiterate the importance of confidence-building measures, including the sharing of cyber threat awareness, strategies, policies, and best practices with other states. Through dialogues at all levels, including among leaders, we aim to foster trust, reduce threats, and most importantly, reduce miscalculations. In this context, Japan conducts various dialogues. Bilateral dialogues provide an opportunity to explain each other’s cyber policies and exchange views on threats and issues of concern. Japan also participates in cyber discussions at the regional level, such as the ASEAN Regional Forum. We believe these serve as important confidence-building measures. Mr. Chair, the establishment of the Global POC Directory is one of the achievements of this Open-Ended Working Group. Japan would like to take this opportunity to once again appreciate the efforts of the Chair and your team. The establishment of this Global POC Directory is not a goal, and the operationalization will show improvements and the next steps. In this regard, it is better to operationalize with simple functions, rather than to pursue many functions from the beginning. As there are existing networks between threats, it is also important to operate it without duplication. In addition, the initial list of voluntary global confidence-building measures would be a big step forward if states accelerate the implementation based on the list together with the Global POC Directory. In this regard, it is important to share best practices of confidence-building measures with each other. Mr. Chair, Japan will continue to place great importance on and promote confidence-building measures in pursuit of a free, fair, and secure cyberspace. I thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Japan, for your statement. Switzerland will be followed by Germany.
Switzerland
Mr. Chair, Switzerland is of the view that the first step to accelerate the implementation of the CBMs listed in the Initial List of Voluntary Global CBMs is the nomination of national policy/diplomatic and technical POCs by participating States on a voluntary basis. The existence of the POC network and national POCs will facilitate the implementation of all further CBMs. Based on the experience of creating the POC network in the OSCE, we recommend starting out with a basic structure containing contact details of the political/diplomatic and technical POCs, beginning to enter the data, and then evaluate the functioning of the database after a certain period of time, and, if necessary, make modifications to ensure it serves the purpose States intended. Overloading the elements will most probably have the result that it will take more time to establish the network and fewer States participating from the beginning. Equally, with regard to communication protocols and templates, we would like to recommend that they should remain voluntary and flexible to allow for exchanges and cooperation even if some information is unavailable. Switzerland will constructively engage in its establishment but would also like to recall its position that the POC directory should not duplicate the work of computer emergency response teams and computer security incident response teams. Mr. Chair, we welcome your intention to hold an information meeting early next year and think that the timely development of an online tutorial will benefit the operationalization of the POC network. We would like to thank the cross-regional group of open-ended working group confidence builders for their very useful working paper. The paper contains valuable examples of regional practice in the implementation of the four CBMs included in NXP of the second annual progress report. Switzerland supports the approach of learning and benefiting from experience at the regional level. We therefore welcome the presence of representatives of regional organizations here in the room who can make a valuable contribution to our discussion. The continued exchange between different regional organizations but also between regional organizations and the open-ended working group is important. Promoting such exchanges is one of the aims of the OSCE CBM 12, of which Switzerland is a co-adopter. The side event that took place at the OSCE in Vienna in November and about which the e-delegation informed us earlier is a concrete action in this context. Mr. Chair, Switzerland proposes to adopt a step-by-step approach. We see merit in focusing on the implementation of the first set of CBMs we have agreed on. As mentioned, the establishment of a POC network and nomination of national POCs is a first step. Such a network will help to implement the second and third CBMs on our list, exchanging good practices for responsible behavior in cyberspace, national views and practices on ICT security incidents and other related threats or vulnerabilities, ICT security advice, guidance, national strategies, or national and regional approaches to risk management and conflict prevention, including national approaches to classifying ICT incidents in terms of the scale and seriousness of the incident. Exchange on such topics will lead to better cooperation and dialogue as well as transparency. Mr. Chair, during the discussion on threats and norms, Switzerland and many other delegations emphasized the importance of protecting critical infrastructure. States, therefore, are encouraged to continue raising awareness on the importance of critical infrastructure protection when implementing CBMs, promoting information sharing among critical infrastructure stakeholders, and sharing of good practices and guidance. Doing so will help implement norms for the F, G, and H. The focus on an initial set of global CBMs does, of course, not preclude states from continuing to work towards the implementation of other CBMs, in particular at the regional level. Working at regional and bilateral levels will allow us to benefit from this experience and synergies when developing further global CBMs. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you. Switzerland, Germany, to be followed by Singapore.
Germany
Thank you, Mr. Chair. Building on the statement of fellow members of the Group of Confidence Builders, Germany would like to share the following experience with the implementation of a regional CBM focusing on voluntary information sharing, including in the event of an urgent or significant ICT incident, facilitated through the Global POC Directory, as mentioned in CBM 1C of Annex B of the Annual Progress Report. Starting in May 2022, Germany has shared information on major cyber incidents with participating states of the Organization for Security and Cooperation in Europe (OSCE). Based on CBM 8 of the OSCE, nomination of national focal points to raise concerns and communicate through. CBM 8 is the most widely accepted CBM of the OSCE, having been adopted by 56 out of 57 OSCE participating states. Germany chose to share information via this platform in order to contribute to the implementation of related OSCE CBMs, namely CBM 2 on facilitating cooperation, CBM 5 on using the OSCE as a platform for dialogue, CBM 7 on information exchange on national updates, CBM 15 on enhancing protection of critical infrastructure, and CBM 16 on reporting vulnerabilities. The overarching objective of sharing information via the OSCE CBM platform was to activate a channel for information sharing on major cyber incidents at a time of heightened geopolitical tensions in the OSCE area. A channel which might contribute to de-escalation in the event of significant malicious cross-border cyber activity. Germany has repeatedly informed OSCE participating states about major cyber incidents since, also using the confidential designated OSCE communication network based on OSCE CBM 13. Germany has also used this network to inform about mitigation measures put in place in response to the respective cyber incidents. Most recently, Germany used this network Friday last week to let OSCE participating states know about a cyber attack on a municipal IT service provider called Südwestfahnen IT and the federal state North Rhine-Westphalia. Germany decided to inform all OSCE participating states about this incident and the mitigation measures because it had a direct impact on the delivery of public services with the potential to undermine trust in the functioning of state authorities. More than 1.7 million citizens were affected with their ability to access digital public services when the attack happened on 30th October. This practical example taken from Germany’s regional practice illustrates how the Global POC Directory can be actively used once it has become operational, hopefully in early 2024. The Group of Confidence Builders will continue to work on further advancing the existing set of initial CBMs included in Annex B. Following the side event hosted by the group yesterday at the Chilean mission, which explored the nexus between CBMs and cyber capacity building, one option is to elaborate an additional CBM that could serve to inform about available cyber capacity building programs and to share national needs and requests for such capacity building. Such a CBM might also speak to the concern voiced earlier in this session by Cuba. However, the more immediate concern over the next few months will be to operationalize the Global POC Directory. All members of the Open-Ended Working Group (OEWG) should start identifying their national POCs now in order to be ready to build the global directory from 2024. The Group of Confidence Builders is ready to assist your member states who are not participating in existing regional CBM frameworks in their preparation for joining the global directory. Thank you.
Ambassador Gafoor
Thank you very much, Chairman, for your statement as well as for your suggestions. I give the floor now to Singapore, to be followed by Italy.
Singapore
Thank you, Chair. As part of the informal cross-regional confluence of this group and its working paper, Singapore would like to share some of our experiences in implementing CBMs within the ASEAN region, in addition to those shared by my colleague from Thailand earlier, which have taken into account differences in regional context and the structures of relevant organizations, as mentioned in CBM 2B of Annex B of the Annual Progress Report 2023. From our perspective, CBMs are important to build trust and confidence, to maintain channels of communication, and to foster mutual understanding. ASEAN sees CSIRT-to-CSIRT cooperation exchanges as an important confidence-building measure in the region. It is taking steps to strengthen regional CSIRT-to-CSIRT cooperation and capacity-building initiatives to enhance the region’s collective cybersecurity. In this regard, Singapore is working with other ASEAN Member States in a proposal to establish an ASEAN Regional CSIRT, which aims to promote and facilitate information sharing related to cyber incident response, to complement the operational mandate exercised by individual national CSIRTs in each ASEAN Member State. The CSIRT-to-CSIRT exchanges will further complement and be complemented by the ASEAN Cyber POCs Directory, established in 2020 through a proposal spearheaded by Malaysia and Australia as part of the CBMs’ effort in the ASEAN Regional Forum. Nomination of POCs to the Directory occurs on a voluntary basis and is updated and ping-tested biannually. Identifying ways to link the work of the ASEAN Regional CSIRT with the Regional POCs Directory can concretely contribute towards our regional efforts to strengthen engagement and build capacity among our regional POCs, thus also enhancing mutual exchanges, fostering greater cooperation, and building trust and confidence. Besides CSIRT-to-CSIRT cooperation, there is also regular dialogue among ASEAN Member States on cybersecurity issues through a variety of platforms, including the ASEAN Cyber Coordinating Committee, the annual ASEAN Ministerial Conference on Cybersecurity, and the ASEAN Network Security Action Council. These platforms and peer learning opportunities, which are built into cyber capacity-building programs delivered at the ASEAN-Singapore Cybersecurity Centre of Excellence, allow ASEAN Members to exchange perspectives on rapidly changing cyber landscapes and threats, as well as discuss newly evolving threats, including continuing the coordinated ASEAN approach to address common threats. Such efforts help to foster regular exchange of lessons and good practices at the regional level while taking into account differences in national contexts. Further, the inclusion of policy, operational, technical, and diplomatic representatives in capacity-building activities involving aspects of cyber outside their own area of expertise can also lend a more holistic perspective to these exchanges, thus contributing to greater understanding among participating States. Identifying opportunities to build in CBMs within our regional CSIRT-to-CSIRT activities and capacity building has mutually enriched both the substance of these activities, as well as strengthened the implementation of CBMs within the region. We trust that some of the best practices from our experience could be potentially useful to the OEWG’s work as we consider how best we could continue strengthening the implementation of CBMs at the global level. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Singapore. Italy, please.
Italy
Thank you, Chair. Italy aligns itself with the statement of the EU, and I also want to congratulate you and the group for agreeing on establishing the POC Directory. I can assure you of our commitment to its operationalization. As a member of the OSCE, Italy has adopted CBM number 14 together with Austria, Belgium, Estonia, Finland, and Sweden, and I have the honour to speak also on behalf of them. CBM 14 focuses on public-private partnerships. Together, we have supported a study that has been published in March this year on the OSCE website. The report highlights the implementation of the measure, which encourages states to establish public-private partnerships to respond to common security challenges stemming from the use of ICTs. It provides examples of existing practice from the OSCE region as well as baseline recommendations to support future efforts. We’re convinced that this work can be meaningful for the OEWG too, not only because it provides best practices and suggestions but also for the different and more operational perspective on PPC, PPPs that it brings with it. It is a perspective on the necessary and inextricable relation of cooperation between the public and the private sectors that could be very useful here, where opinions can be quite distant on this specific aspect. More generally, being able to draw upon regional organizations’ work is very beneficial for the OEWG. Finally, the work on CBM 14 could greatly contribute to the proposed POA mechanism. I invite, therefore, all colleagues to check the report, which is also available in the Arabic language, and to give some consideration to a possible similar CBM in the near future. We’ll also formally submit the report to the Secretariat. I thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much. We have about 10 delegations wishing to make statements. I think it’s best that we continue tomorrow, and I wanted to give the floor to the Secretary if they have anything to say.
OEWG Secretariat
Thank you, Chair. Delegations are reminded to get registered for the list of speakers on the Delegate Portal. Only 44 delegations have been registered so far, while the attendance is much, much higher. So please go to the Delegate Portal and get registered for the list of participants. Thank you, Chair.
Ambassador Gafoor
Thank you very much. I think it’s important that your participation is officially registered because, obviously, the room has been quite full for the last few days, so I am very happy to see the good turnout. Tomorrow, we will take the 10 speakers, and then we will transition to capacity building, which is just as well because I think the question of our CBMs and the POC directory leads us naturally into capacity building. Then we will take it from there. This has been an excellent start to the discussions on confidence-building measures as well as the POC directory, so there’s a lot to unpack and listen to each other. I thank you very much for all your contributions, and I look forward to continuing our discussions tomorrow. The meeting is adjourned, and I wish you a pleasant evening.
Leave a Reply