Session 6-8 Transcript
(OEWG 2021-25)

Home » Resources » UN Open-ended Working Group (OEWG) transcripts » Session 6-8 Transcript(OEWG 2021-25)
Ambassador Gafoor

Distinguished delegates, the eighth meeting of the sixth substantive session of the Open-ended Working Group is now called to order. We’ll now continue consideration of Agenda Item five, on the topic of capacity building, and we will continue with the speaker’s list. I think I have about 50 delegations who have inscribed to speak. This is going to be a very important discussion so I look forward to hearing your views. We’ll start with Cuba to be followed by Bangladesh. Cuba please.

Cuba

Chair, the changing nature of information and communication technology is evolving rapidly. This, combined with the current asymettries between states in this sphere has a negative impact on the security of nations with less technology.] Mr. Chairman, we’re considering two basic needs on capacity building for states to defend themselves or respond to the malicious use of ICTs. And in the first place, these are universal, inclusive and non discriminatory access of all states to information and to knowledge related to ICTs. And secondly, training and the development of human resources for which it is also imperative to have universal access. Activities on capacity building recommended by this Open-ended Working Group must be aimed at making that access possible, and to bridging the digital divide to have an adequate response by stage to the threats identified by the group and thus contribute to sustainable development in particular of developing countries. We cannot say that the few activities that take place today under the auspices of the United Nations on capacity building are enough to change the digital divide into digital opportunities. Nor can we claim that the bilateral and regional efforts on capacity development could replace multilateral mechanisms that may be created to that end, since their scope would be global and in tune with the common promise of not leaving anyone behind and achieving sustainable development. Thus we insist that bilateral and regional initiatives must complement global efforts on capacity development. We reaffirm the positions of the Non-Aligned Movement on capacity development, as well as the appeal to developed countries and to relevant international agencies to provide developing countries so requesting assistance and cooperation, including financial resources and transfer of technologies, bearing in mind the specific needs and the characteristics of each recipient state. International cooperation for capacity development must be politically neutral, transparent, responsible and unconditional. It must follow the principle of shared but differentiated responsibilities. We demand the lifting of any unilateral coercive measure which prevent universal access to the benefits of ICTs or which limits or denies in any way to developing countries, technical knowledge, technologies or services related with it in all their aspects for exclusively peaceful purposes. In addition to these basic issues, which are necessary for capacity building, we reiterate that other measures which the OEWG could provoke could promote would be the following. – Establishing a common terminology to facilitate an exchange of information and responses to cyber incidents. Increasing cooperation to address cyber incidents. – Exchanging information which does not compromise the privacy or sovereignty of states, nor counter any national laws. To this end, we can make use of the computer emergency response teams and the global POC directory. – Implementing certification programs with financing facilities for experts, especially from developing countries on items relating to ICT security. A listing of needs and priorities in this regard could be channeled through this group. – Offering updated periodic courses, which allow developing countries to follow incident management processes. – Facilitating technology transfers, including specialized tools and hardware to developing countries to increase their operational capacity on cyber incident management. – Publishing results of studies on vulnerabilities and hidden functions of ICT platforms without compromising the infrastructure or services of states. – Implementing technical assistance mechanisms upon the request of recipient states, and based on respect for national laws. – Exchanging methodologies, best practices and procedures on protecting critical infrastructure on the basis of mutual respect and confidentiality bearing in mind national legislations. The United Nations through specialized agencies, like for example the International Telecommunications Union, should play a central role and be a permanent forum for dialogue, consultation and cooperation and coordination among member states, including capacity building and technical assistance in the area of ICT security. We are grateful for India’s detailed presentation.Thank you.

Ambassador Gafoor

Thank you very much, Cuba. Bangladesh to be followed by Belgium.

Bangladesh

Thank you, Mr. Chair. Bangladesh believes that capacity building is at the core of the success of the work of this group. As you mentioned, Chair, in your opening remarks of this session, we are only as strong as our weakest link. There is a resounding call that the developing countries are in critical need of robust capacity building to develop the knowledge, skills, and resources necessary to effectively implement responsible state behavior in the use of ICTs. We acknowledge the ongoing efforts of the Secretariat as it undertakes a mapping exercise to survey the landscape of capacity building programs and initiatives within and outside the United Nations, as well as those at the global and regional levels. Building on the ongoing mapping exercise, we believe that a comprehensive capacity assessment, including the National Survey of Implementation of the United Nations Recommendations on the Responsible Use of ICTs by States in the context of international security, is equally important. Offering a comprehensive and a global array of both capacity assessment tools and capacity building programs would be an important first step towards the concrete and tangible implementation of national capacity building initiatives. Chair, capacity building requirements vary from country to country, and there is no one-size-fits-all solution. Therefore, my delegation highlights the importance of a needs-based approach for capacity building. The pivotal question then becomes how do we effectively assess the specific needs of countries for capacity building and what are the available programs we have? In order to answer these questions, we propose exploring the possibility of creating a comprehensive matrix encompassing capacity building needs, possible capacity building programs to meet those needs, and a list of existing capacity building programs and initiatives. These dynamic metrics should be updated regularly to incorporate new programs and needs as they emerge. In our view, it would facilitate a nuanced understanding of diverse capacity building needs, enable self-assessment against industry benchmarks, and offer a thoughtfully curated selection of existing capacity building programs customized to meet the specific requirements of each member state. The matrix could also function as a comprehensive inventory of capacity building programs, potentially shedding light on areas where support is lacking or needed. The Global Cyber Security Cooperation Portal, as presented by India, could be the possible host of such metrics. We thank India for their comprehensive presentation on this portal, and we support the establishment of this portal. The roundtable discussion on capacity building scheduled for next May could provide a valuable opportunity to delve deeper into this matter. Mr. Chair, we believe that for a capacity building program to be successful, it is imperative to involve the industry. Without enhanced collaboration between states and industry, we may not be able to achieve the desired results that we all aspire to attain. Finally, a gender-sensitive approach to capacity building is critical. We should consider the gender impacts and implications of cyber threats and address the needs, priorities, and capacities of women and girls. Additionally, it is crucial for states to actively engage with youth activists and young professionals in the field of ICTs as they are driving innovation and making remarkable contributions to the field of technology. I thank you.

Ambassador Gafoor

Thank you, Bangladesh. Belgium to be followed by Slovenia.

Belgium

Mr. Chair, my country aligns with the statement delivered by the EU. We wish to stress the following elements in our national capacity. Considerable attention on capacity building in cyber has recently been drawn, thanks to the conference G3CB held in Accra on November 29 and 30 this year. We congratulate the organizers on this occasion. Through many panels, different regions were put at the forefront, as well as different teams. In that vein, we would like to say that Belgium considers being more involved and is joining some working groups of the European T4D program. Moreover, as Presidency of the EU from January 1, 2024, until June, we mentioned that in our earlier statement, we seriously envisage an encounter between the EU cyber ambassador with African peers. One of the topics of that gathering would be to exchange views on UN processes and other topics that we would agree on, such as regional cooperation. For the EU side, on regional cooperation, we could expand on the cyclone mechanism, ENISA, or the Cyber Solidarity Act. Additional topics could be cyber criminality and/or connectivity. Prior to that, Belgium has sent to UNODA a list of projects that it has undertaken relating to capacity building in cyber. Lastly, I would like to share with you a principle that could be examined in our works. Cooperation and capacity building should not imply access and transfer of data to the country that is offering aid and capacity building. I hope that this principle could resonate in the open-ended working group. We ask that we thank India for the interesting presentation on the new parcel. Thank you for your attention.

Ambassador Gafoor

Thank you very much, Belgium, for your contribution and for your suggestion. Slovenia, to be followed by Slovakia.

Slovenia

Thank you, Mr. Chair. Mr. Chair, Excellencies, Slovenia aligns itself with the statement delivered on behalf of the European Union and its member states and would like to deliver the following statement in its national capacity. Mr. Chair, as pointed out in the second OEWG annual progress report, states can use the OEWG as a platform to continue exchanging views and ideas related to ICT security capacity building efforts. In this sense, Slovenia wishes to share its experience in the regional capacity building efforts. Within the shared efforts for cyber capacity building, Slovenia and its partners established a regional cyber capacity center in the Western Balkans, abbreviated WB3C. With the WB3C, Slovenia and France, together with Montenegro, developed a strategic long-term project aimed at exchanging information, good practices, and training courses, as well as strengthening the cyber culture and developing the expertise of active practitioners. The goal of the center, based in Podgorica, Montenegro, is to educate the educators in national administrations on cutting-edge policies and practices in cyber security and combating cyber crime. Furthermore, the center is actively contributing to the enhancement of the cyber security system of the Western Balkans region through various international and inter-regional cooperation initiatives, as well as through fostering cooperation between academia developing cyber curricula. The WB3C designed an array of diverse trainings in 2023, such as a trainer session on cyber hygiene for public administrations, a mentoring program supporting women engaged in cyber security policymaking and international negotiations, a cyber crime course for judicial academies, a cyber crime course for police academies, and a course for chief information security officers in critical infrastructures across six Western Balkans countries. An additional 12 trainings, lasting from one to two weeks, are scheduled to take place in 2024. Mr. Chair, Slovenia believes that regional centers such as the WB3C should strive to be sustainable in the way they operate. They should create a training ecosystem where experts pass their knowledge on to beneficiaries who, in turn, become the next generation of experts and trainers. By fostering this self-renewing cycle, centers ensure a continuous pool of skilled regional professionals. This approach empowers the local community and contributes to the organic growth of cyber security expertise, creating a self-sustaining network of knowledge that evolves and adapts over time. Mr. Chair, recalling your opening remarks, we agree that capacity building is a topic that connects all of the pillars of the OEWG’s work. It is proving to be an especially important topic in states where cyber infrastructure is not yet present. As a member of several cyber initiatives and with the presented activities in the region, which we importantly see going hand-in-hand with the work of the OEWG, Slovenia is therefore reaffirming its commitment to cyber capacity building. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you very much, Slovenia. I give the floor now to Slovakia, to be followed by Germany.

Slovakia

Thank you, Mr. Chair. The Slovak Republic recognizes the pivotal role of trust in fostering efficient cooperation amongst various units in the domain of ICT. This trust is cultivated through multi-phased channels, ranging from shared membership in common organizations to the personal experience of individuals. Our commitment to this principle is solid, and we believe it forms the cornerstone of any successful collaborative efforts. When discussing capacity-building measures, specifically in the CSIRT area, it is imperative to highlight existing successful frameworks. The CSIRT network within the European Union serves as a notable example of efficient regional collaboration in cybersecurity. This model demonstrates the importance and impact of coordinated trust-based efforts in enhancing cybersecurity on multiple levels. The Slovak Republic is a strong proponent of establishing and nurturing CSIRT units. Our national cybersecurity center is not only mandated to support the development of CSIRTs within Slovakia but also to extend its expertise and assistance internationally upon request. This support is not limited to the inception of these units but also encompasses their evolution. We aid in elevating the maturity level of CSIRTs, facilitating their integration into prestigious groups such as FIRST and Trusted Introducer. This approach not only strengthens individual units but also contributes to the robustness of the global cybersecurity framework. At the global level, the existing World Forum FIRST for CSIRT units exemplifies the potential and efficiency of international cooperation. The global network also acts as a dynamic and comprehensive point of contact list, connecting a vast array of CSIRTs across the world. Notably, this network includes the majority of national CSIRTs, illustrating its extensive reach and impact. Mr. Chair, we believe it is essential to consider the necessity of duplicating existing well-functioning structures in our capacity-building efforts. Instead, we should contemplate varying degrees of involvement and support by the OEWG in these activities. Building upon established successes allows us to maximize resources, share best practices, and foster a more cohesive and resilient global cybersecurity infrastructure. One of the tasks of the Program of Action should also be to foster capacities in those states that are in need of increasing their overall cybersecurity level, also in cooperation with relevant stakeholders. Mr. Chair, to conclude my contribution, allow me to make a brief comment on the point of contact topic. The Slovak Republic strongly supports the consideration of the development of different types of points of contact in the database. We believe that a single contact can complicate the situation if it is necessary to solve an urgent problem, not on a technical or diplomatic level. We see contacts for diplomacy, problems of national cooperation at the legislative level, and technical contacts of various types. In alignment with these principles, the Slovak Republic remains committed to contributing constructively to the OEWG’s initiatives promoting trust-based cooperation and leveraging existing successful structures in our collective journey towards enhanced global cybersecurity capacity. Thank you.

Ambassador Gafoor

Thank you very much, Mr. Machia. Germany, to be followed by Kuwait.

Germany

Honorable Chair, thank you very much for giving me the floor. Germany is fully aligned with the statement of the European Union and makes the following statement in its national capacity. Before responding directly to your questions, Germany would like to commend you, Mr. Chair, for encouraging this working group to attach urgency and priority to capacity building, which itself is part of building confidence and a cross-cutting issue. Indeed, as we have seen throughout this week, all other agenda items come down to capacity building, and it has become a foundational issue for our discussions. You have rightly stated that capacity building cannot wait, and Germany has heard your call for action through a multitude of already existing cyber capacity building programs with different priority areas and a particular regional focus on Africa, the Western Balkans, and the Eastern Partnership countries, including Ukraine. Just last month, Germany held a cyber diplomacy training for the ECOWAS region in Togo, two study trips to Germany’s cyber institutions for officials from Ukraine, as well as policy and technical cyber experts from the Western Balkans, and multiple peer-to-peer exchanges for heads of Western Balkan CSIRTs in Latvia and Luxembourg. All of our CCB work is following a partnership-based approach and seeks to enhance regional cooperation, which we deem a key requirement for states to effectively detect, defend against, or respond to malicious ICT activities. We would also like to draw the attention of this group to the recent Global Conference on Cyber Capacity Building, GC3B, hosted by the Digital Ministry and Cybersecurity Authority of Ghana in Accra, and jointly organized by the Cyber Peace Institute, the Global Forum on Cyber Expertise, the World Bank, and the World Economic Forum. During the conference, which for the first time managed to bring together leaders of the cyber and development community, Germany organized a session to explore the cybersecurity dimension of the principle, leave no country behind. Without excessively diving into the details, let me briefly share some of the key findings from our discussion in Accra for our working group. First, the international community should work together by promoting regular collaboration and information sharing to avoid gaps and asymmetries in cyber capacity building, which includes sharing best practices, identifying and addressing vulnerabilities, as well as identifying and adopting common frameworks and standards. Examples include continuous cyber excellence centers and cyber dialogues among each other to encourage this kind of cooperation. Second, sharing the same objectives is key for effective coordination of capacity building initiatives, and to avoid duplication of efforts while a demand-driven approach with local ownership is vital to make cyber capacity building engagement the two-way street it is essentially supposed to be. Thirdly, sometimes it is time to go back to basics. Another capacity building training won’t be effective if basic hardware and software is outdated. Therefore, capacity building should never lose sight of the technical foundations. Finally, the GC3B was a great reminder that we need to get all stakeholders from different sectors and fields into the same room if we want to take on a comprehensive and holistic approach to cyber capacity building. To now come back to your guiding questions, Mr. Chair, Germany believes that work here at the UN should contribute to ensuring everyone has a seat at the table in the facilitation of capacity building efforts to complement the extensive amount of already existing offers in this regard, such as coordination efforts undertaken by the Global Forum on Cyber Expertise, GFCE. Bearing this in mind, Germany sees merit in further considering India’s proposal of a one-stop platform for enabling global cooperation and coordination between member states on matters related to ICT security. One agenda point for the upcoming roundtable in May could be, after today’s presentation, to further consolidate with already existing portals such as the GFCE Cyber Portal, EU Cybernet, and the UNIDIR Policy Portal to see how a joint portal could look like. Building on this, Germany is convinced that the envisaged UN Program of Action would serve as a powerful practical mechanism to facilitate access to cyber capacity building solutions for UN member states while respecting the already agreed-upon UN principles. Germany fully echoes the elaborate contributions by other member states within this regard. Moreover, our delegation is strongly convinced that incorporating more women into cyber can only be done via mainstreaming gender activities into all cyber capacity building efforts. The OEWG already serves as a powerful example of how targeted training for women can make a difference. Germany, therefore, advocates for streamlining similar programs into all cyber-related fields. Last but not least, Germany fully echoes the sentiment that all capacity building activities should be action and practitioner-oriented as well as inclusive of all stakeholders. We firmly believe that there are plenty of beneficial resources, proposals, and tools available already, and it is now time to find ways of bringing these together to enter the next phase and make capacity building happen for all UN member states, ensuring that we leave no country behind. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you very much, Germany, for your statement. Kuwait to be followed by Japan.

Kuwait

Distinguished Chairperson, distinguished delegates, In alignment with the guiding questions and aiming to facilitate in-depth discussions on capacity building within the OEWG’s mandate, Kuwait believes that in order to strengthen the resilience of developing countries and secure its ICT environment as part of capacity building, it is important to develop foundational capacities required for states to detect, defend against, or respond to malicious ICT activities. Thus, incorporating and focusing on the right tools and solutions is crucial for effective capacity building in any state, especially for small and under-resourced developing countries. Therefore, Kuwait proposes to establish standardized security guidelines, starting from acquiring an essential list of 10 security tools and solutions, categorized by their primary function as follows: 1. Identity and access management 2. Firewalls and intrusion prevention systems 3. Endpoint protection and response 4. Data encryption 5. Email security 6. Patch management 7. Vulnerability management 8. Backup and recovery 9. Secure remote access 10. Security information and event management To effectively acquire and implement these essential tools and solutions, particularly in resource-limited states, a structured approach is required. The paramount objective of this plan should be to prepare and align the people, processes, and technology aspects essential for ICT security. This requires a multifaceted strategy that not only concentrates on the procurement of necessary tools and solutions but also emphasizes the requisite skills, knowledge, and infrastructure. This comprehensive approach ensures these tools are used and maintained effectively as follows: 1. Assessment of current capabilities and needs. Conduct a baseline assessment by evaluating the current state of ICT security, including infrastructure, existing tools, skills, and processes. Identify gaps by determining the tools, skills, and infrastructure that are missing or need improvement. 2. Strategic planning. Define objectives by establishing clear, achievable goals for capacity building based on the identified gaps. Develop a roadmap. Create a phased plan—short, medium, long—for acquiring tools, developing infrastructure, and training personnel. 3. Budgeting and resource allocation. Secure funding by identifying sources of funding, which could include government budgets, grants, or partnerships. Allocate resources wisely. Prioritize spending based on the most critical needs and the greatest impact. 4. Financial assistance. Coordinate with donor countries and organizations to mobilize resources and funding for ICT security initiatives in developing states. 5. Technology transfer. Assist in the transfer of technology and knowledge to states that lack advanced ICT infrastructure or capabilities. 6. Workforce development and training. Build local expertise by investing in training for local personnel to manage and operate security solutions effectively. 7. Establish partnerships. Collaborate with educational institutions, international organizations, and the private sector for knowledge transfer and training. 8. Expertise sharing. Facilitate the sharing of expertise and best practices among member states. 9. Policy development and legal framework. Develop a legal and regulatory framework that aligns with international standards like the NIST cybersecurity framework and ISO 27001 while adapting to local legal requirements. 10. Monitoring and evaluation. Continuous monitoring by regularly monitoring the implementation process and the effectiveness of implemented security solutions and training. Feedback mechanism by establishing mechanisms for feedback and continuous improvement, which involve periodic reviews and assessments to ensure that the strategy remains relevant. 11. Community engagement and awareness. Raise awareness by conducting awareness campaigns to educate the public and stakeholders about ICT security. Engage stakeholders. Involve a wide range of stakeholders, including government departments, the private sector, civil society, and academia, in the planning and implementation process. 12. Public-private partnership. Engage with the private sector. Foster partnerships between government and private sector entities to leverage their expertise, technology, and resources. Incentivize collaboration. Create incentives for private companies to invest in and support ICT security initiatives in developing states. 13. Sustainability and scalability. Plan for sustainability to ensure that the capacity-building initiatives are sustainable in the long term. Design initiatives that can be scaled up or adapted as technology and threats evolve. Mr. Chairperson and distinguished delegates, capacity building requires a strategic and sustainable approach focusing on both the acquisition of technology and the development of human capacity. Partnership, careful planning, and phased implementation are key to successfully enhancing the state’s ICT security capabilities. This is an invitation to not only align national strategies with these capacity-building initiatives but also to dedicate necessary resources toward the enhancement of ICT security capabilities. Embrace the exchange of knowledge and expertise, fostering a community of shared learning and mutual support. Let us make a shared commitment to advance toward a future where a robust cybersecurity environment is a reality for all, regardless of resource limitations. By fostering capacity building across nations, we lay the foundation for a secure, resilient, and prosperous digital future for every member state. Thank you.

Ambassador Gafoor

Thank you very much, Kuwait. Japan, to be followed by El Salvador.

Japan

Mr. Chair, Japan strongly believes that capacity building is essential for maintaining peace and stability and promoting a free, fair, and secure cyberspace. As for the area of capacity building, the UN should focus its efforts especially in the area of implementation of the framework of responsible state behavior. In our efforts to advance capacity building, we should promote a multistakeholder approach as we believe capacity building is not only the matter of state but also of non-state stakeholders such as businesses and academia. Coordinating and collaborating with the efforts by non-state stakeholders is crucially important. We believe that the OEWG has an advantage to advance this multistakeholder approach with its non-state stakeholders’ participation as observers. Mr. Chair, Japan is also of the view that regional and sub-regional organizations play an important role in capacity building. Compiling and sharing information related to the existing programs and experiences of these organizations are beneficial to all Member States. In this regard, the idea of a voluntary checklist proposed by Singapore is interesting. We should use the checklist to ensure the implementation of the framework of responsible state behavior as well as to identify the gaps where capacity building is needed. It would be interesting to learn from the experiences of ASEAN in this regard. Japan is also willing to share its own experiences in supporting capacity building projects in ASEAN and other regions. To ASEAN, we are providing capacity building programs through AJCCBC, ASEAN-Japan Cyber Capacity Building Centre in Bangkok. Since its launching five years ago, the centre has provided training programs to more than 1,600 ASEAN Member States’ government officials and those who are working for critical infrastructure. Japan has been contributing to the World Bank Cyber Security Multidonor Trust Fund, a new fund launched in 2021 that is dedicated to cyber security. This trust fund has also supported such initiatives as the recent GC3B meeting in Accra, whose success we would like to welcome together with the EU, Belgium, Germany, and other delegations. Mr. Chair, the UN is in a good position to compile and share information and experiences related to existing capacity building efforts, as well as to identify the gaps where capacity building is needed for the implementation of the framework of responsible state behavior. In this regard, we would like to support convening a dedicated global roundtable on ICT security capacity building and provide constructive inputs based on our experience. In the same spirit, we think India’s proposal for GCSCP, Global Cyber Security Cooperation Portal, is an interesting idea which merits further discussion. We should discuss the concrete concept and clarify what kind of added values we can expect from the GCSCP, as Germany stated. Japan is of the view that this function of identifying gaps and coordinating capacity building efforts would be one of the major functions of the future POA, which my delegation would like to elaborate on in the next agenda item. I thank you, Mr. Chair.

Ambassador Gafoor

Thank you very much, Japan. El Salvador, to be followed by Portugal.

El Salvador

Thank you, Chair. I would like to begin by thanking India for presenting its proposal on the portal. El Salvador aligns with Argentina, who spoke on behalf of some countries of Latin America and the Caribbean, and says the following in a national capacity. On capacity building and in response to your guiding questions, we would like to focus on two specific areas within the global cyber capacities: cyber security and digital issues. In an environment where interdependence intensifies, cybernetics has evolved from technical to social and economic aspects and requires a comprehensive approach. With regard to cyber security, we specifically refer to the integration and security of the infrastructure networks. This entails a security mentality and requires designs that go from prevention to resistance, recovery, and resilience for the purpose of guaranteeing the availability, authenticity, integrity, and confidentiality of data and services accessible through information systems. With regard to digital and diplomatic cybernetics, we want to mention the work that we are all carrying out in this group. We are deepening the importance of capacities in cyber diplomacy. This will allow for active participation in multilateral regional forums on topics relating to cyberspace. We also promote confidence-building measures, responsible state behavior, international standards, and strengthening regulatory frameworks in order to consolidate cyber security, cyber resilience, and to strengthen international cooperation in the cyber landscape. We agree with recommendations 45 and 46 in the APR to work through the United Nations Secretariat to establish capacities, aligning these efforts with the responsible state behavior concept. El Salvador, with a group of Latin American countries, has submitted a non-exhaustive list of capacity development programs at the regional level, in particular actions undertaken by the Organization of American States, the OAS, through the cyber security program of the Inter-American Counterterrorism Committee, including gender perspectives in accordance with that call in capacity building. In conclusion, we appeal to a multistakeholder approach in order to contribute to our discussions. We recognize that experience in the cyber field comes from various sources, and given the nature of the digital domain, the views of other stakeholders are key. Thank you, Chair, for this opportunity, so that various actors can conduct these discussions. Thank you.

Ambassador Gafoor

Thank you very much, El Salvador. Portugal, followed by Ecuador.

Portugal

Thank you, Mr. Chairman. Capacity building is a truly cross-cutting topic for this OEWG, as it allows countries to better identify and address threats, to better implement international law and norms for responsible behavior in cyberspace, and as it constitutes in itself a CBM. The United Nations has a crucial role to play in the provision, coordination, and facilitation of capacity building efforts. There is no better way of promoting capacity building than through a permanent institutional mechanism for international cooperation on cybersecurity, the Programme of Action. In this connection, the proposal for a Global Cybersecurity Cooperation Portal (GCSCP), that was so eloquently presented by India this morning, merits consideration in the current OEWG and could later be integrated into the upcoming POA. We look forward to the mapping exercise of capacity building activities to be published by UNODA before the next substantive session in March 2024. This mapping exercise will identify gaps and challenges, thus serving as a tool to enhance our capacity building efforts moving forward. We also look forward to the roundtable to be convened in May 2024. Mr. Chair, as you mentioned in your opening remarks for this session, and as many have echoed today, capacity building cannot wait. We urgently need to break silos in our work at the national level and here at the UN. In this regard, we take due note of the ACRA call for cyber-resilient development, and we concur that cyber-resilience is an important enabler for sustainable development. For that to happen, we need to engage with the development community and show that by promoting cybersecurity, we can actively contribute to the implementation of the SDGs and to their future-proofing. In the framework of its strategic cooperation programs with partner countries and following a needs-based approach, Portugal is seeking to address cybersecurity in various sectors of intervention. Our aim is to foster digitalization in an integrated manner that includes protective mechanisms against both cybercrime and cybersecurity threats. In our joint work with Mozambique, for instance, planned initiatives aim at building a better understanding of the cybersecurity landscape, with a focus on identifying specific areas of interest, as well as training activities and technical support for security forces and the Ministry of Defense. With São Tomé and Príncipe, the strategic cooperation program includes actions to raise awareness and provide training to develop general and specific skills in the safe use of technologies and protection of cyberspace, to establish close cooperation and knowledge sharing in responding to incidents in cyberspace, and to build the capacity of São Tomé and Príncipe security forces and services. Lastly, with Timor-Leste, within the framework of the strategic cooperation program 2019-2023, Portugal promoted a training and technical assistance program, including training in information security, cybersecurity, and information protection. More detail was submitted to the Secretariat in the context of the mapping exercise on capacity building activities. I will stop here. Thank you very much.

Ambassador Gafoor

Thank you, Particle. Ecuador, to be followed by Israel.

Ecuador

Thank you, Mr. Chair. Ecuador aligns itself with the statement made by Argentina on behalf of a group of Latin American countries. This room has witnessed consensus in the group with regard to the urgent and priority need to build and strengthen capacities globally so that we are able to counter cyber security threats and promote an open, stable, secure, accessible, and peaceful environment for the benefit of all. And that is following international law, the international law of human rights, and international humanitarian law. Mr. Chair, my country, seeking better tools with which to meet the challenges of evolving existing and emerging technologies and to be able to prioritize strategically the review and update of its cyber security policy as well as its national strategy, in 2022 conducted a multistakeholder evaluation of the level of its cyber security capacities with the support of the World Bank. This evaluation had five dimensions in it: cyber security policy and strategy, cyber culture and society, the development of knowledge and cyber security capabilities, legal and regulatory frameworks, and standards and technologies. We are implementing now the 2022-2025 national strategy on cyber security, and we have identified some priority training areas, among them regular and sustained capacity for ECUCERT, cyber incidents management by public and private institutions with respective protocols on the identification, containment, and resolution of these incidents, and finally, the monitoring and protection of critical digital infrastructure and essential services. I can also state that Ecuador has joined the Global Forum on Cyber Expertise. I also state that a group of countries from Latin America, including my own, submitted a vision on capacity building and capacity strengthening, as requested by UNODA, with a view to the report to be submitted at the next substantive session of the group. My delegation would also like to highlight and to thank the Women in Cyber program and donor states, among them Canada. That initiative allows us to land and to add to global efforts in order to ensure a fair, full, and effective participation of women in cyber security negotiations, which contribute to eliminating the gender gap. My delegation therefore expresses the wish that these initiatives multiply and be part of a substantive and standing capacity building mechanism. Finally, we value the proposal made by India and we will place it before our technical entities for their consideration. Thank you.

Ambassador Gafoor

Thank you very much. Ecuador. Israel, to be followed by the Republic of Moldova. Israel, please.

Israel

Thank you, Chair, for giving us the floor to share our national perspectives on the very timely and important topic of capacity building. As many Member States have alluded, cybersecurity is an urgent issue. Currently, the growth of risk far outpaces defensive capacities and capacity building. The global community needs to do more and to do it much faster. Developing countries struggling to bridge the digital divide seek to leapfrog their digital economies and do so securely. Capacity building in this context, in Israel’s perception, refers to the family of efforts conducted to empower partner countries so they can achieve this objective. Specifically, capacity building can also serve as an important measure in building trust, as well as promoting a stable and resilient global cyberspace and facilitating continued human prosperity and progress in the information age. Israel’s capacity building efforts are aimed at improving global resilience on a potentially neutral basis, thus adopting a constructive and cooperative approach while encouraging innovation. Israel published its International Cyber Cooperation Strategy and continues to contribute to raising the cybersecurity of foreign markets by donating funds through the Inter-American Development Bank and the World Bank, assisting countries to build their strategies and establish their national cybersecurity mechanisms. At the government’s initiative, all public universities in Israel now have their own R&D centers for cybersecurity and offer extensive courses and training facilities, managing to more than quintuple our amount of cyber-related research. Leading Israeli researchers in academia have developed a sectorial survey which allows sector regulators and decision-makers to get a holistic view over their sector’s cyber posture. Israeli experts have worked successfully together with some countries to use this novel methodology and assist them in assessing and improving the cybersecurity maturity of some of their most critical sectors. We stand ready to cooperate with interested parties and share this know-how and experience. Mr. Chair, Israel is actively sharing best practices with many countries and organizations who wish to build their own national cybersecurity capacities, and we are ready to collaborate with other states and organizations on this important matter. Less than a year ago, the Permanent Mission of Israel to the UN here in New York, in cooperation with Israel’s National Cyber Directorate, hosted a special event at the UN headquarters named Stronger Together – Collaborations for a Cyber-Safe World, a special summit featuring some of Israel’s top experts discussing how nations can stay safe in a world full of existing and new threats. That event featured the case study of Israel while sharing ideas for pursuing global action in the UN fora and discussing the interaction between public and private sectors and possible collaborations in this field. As mentioned earlier this week, Israel is leading together with the UAE an initiative that includes the presentation of the Crystal Ball system that will allow the easy sharing of information between countries on cyber attacks. This is done under the leadership of the USA, with dozens of partners including very fruitful cooperation with the private sector, and once ready will serve as a tool to prevent attacks on the go. Cybersecurity is a cutting-edge field, and the gaps in skilled cyber professionals are huge on a global scale. The need to have skilled hands-on and updated training is crucial in order to establish and sustain an effective cyber-defending force. Israel is a hub for online hands-on, updated simulation scenarios that may serve many other nations to build their national cyber capacities. Its experience has shown that cyber can also serve as a means to improve social mobility and economic growth. We have therefore continued to invest in capacity building programs to reach out to citizens living in the socio-economic periphery with inclusive training and educational programs aimed at underrepresented sectors, especially relevant for young girls and women. The cyber domain is not just one of threats. It holds possibilities and opportunities. Israel continues to build its cyber ecosystem while reinforcing its periphery, bringing together government, academia, and the private sector. We’re gladly sharing experience in this field. Cyber has created novel policy and regulatory challenges due to, among other things, the involvement of the private sector. So it merits a broad discussion that requires thinking out of the box, breaking existing silos, and strengthening multinational cooperation together with broadening the participation of all stakeholders. Finally, Mr. Chair, however we tend to speak in the context of cybersecurity building about technology, it is indeed mostly people-driven and it should be treated as such, starting from education at a young age and working rapidly to minimize any existing gaps. I thank you.

Ambassador Gafoor

Thank you very much, Israel.

Moldova

Mr. Chair, the context of activities and discussions held within this group has undergone major transformations, substantially redefining and completing the concept of international security. A significant aspect of such changes is the geopolitical impact on the nature and extent of confrontations in cyberspace, as the war in its classical sense has currently changed into a threatening hybrid along with cyber and information warfare. These changes require a new, much more complex, differentiated, and responsible approach from all stakeholders involved in the ICT field, eminently the state actors, as many countries, Mr. Chair, realize they are not ready to face all these threats on their own for various reasons. The ever-increasing number of attacks aimed at the critical infrastructure of countries and/or the infrastructure of their government, cybercrime and online fraud, phishing, ransomware attacks, and other such activities have made countries focus more on strengthening the rule of law and on identifying sources and ways of enhancing their capacities needed so much to respond to such threats. I would like to underline that the Republic of Moldova aligns with the EU statements and would like to make some remarks in its national capacity as follows. The dramatic deterioration of the cyber threat environment in our region highlighted the need for enhanced international cooperation and coordination to prevent, detect, and respond to malicious cyber activities. Furthermore, recent incidents in our region highlighted the urgent need to ensure that critical infrastructure is secure and resilient. Strengthening cyber capabilities became a priority for my country following the adoption of its first law on cyber security in March 2023, which establishes the primary regulatory framework in the field of cyber security. Our government issued a decision on professional development in the field of cyber security, according to which a public university is to ensure the professional development of public employees as well as other interested persons from the private sector by organizing training programs, courses, and training exercises in this field. Besides developing the professional skills of staff from public authorities and advancing research and innovation programs in cyber security, this university will establish partnerships with international profile organizations for the development of joint trainings, innovation programs, as well as the implementation of cross-border research and innovation projects. Accordingly, we welcome the international meetings aimed at discussing ways of cooperation on enhancing capacities, awareness, and exchanging information on addressing the crisis at a technical, operational, and political level. We emphasize the need to organize regional and international sessions on lessons learned following coordination on support for these developing countries. During a regional cyber symposium hosted in my country last November, it was highlighted that countries in our region, particularized by a fragile security, need enhanced support in strengthening government structures to address cyber incidents, monitoring the threat landscape, detecting and mitigating cyber attacks, crisis management, and cyber resilience. The parties confirmed the continuous need for efforts to organize meetings on regional levels, at multilateral forums, or engaging dialogues on a bilateral level in order to discuss current and future cyber security strategies, norms, as well as cyber diplomacy policies. At the same time, we are pleased to highlight that a series of initiatives aimed to build cyber security skills and trust among nations sponsored by a single or a group of countries are very welcomed. These initiatives have a substantial role in reducing the risk of misinterpretation and unintended escalation of cyber incidents, as they seek to listen to all sides as well as integrating all perspectives, opinions, and visions in a transparent and inclusive manner. For this reason, I would like to underline the importance of the Women in Cyber program supported by the Global Forum on Cyber Expertise and the role of its six sponsoring countries in advancing gender parity, thus enabling greater participation by women in the cyber negotiations, their robust contribution, and unique perspectives to the debates held within this OEWG process. Concurrently, we are aware of the fact that there are many more initiatives known and unknown to all of us here, which support states to build their national cyber capabilities. We hereby encourage all the states and organizations that contributed with their efforts and resources to the development of the capacity building measures of third countries by organizing workshops, fellowships, seminars, etc., to voice in this group their experiences and the impact of their support towards building capacity, as we witnessed, for example, on November 8, 2023, during the reunion of the OSCE Informal Working Group on CBMs in Vienna, where participating states reported about their actions aimed at building confidence in this field. Informing about these initiatives will not only seek to further deepen cooperation, but as some previous speakers mentioned, will also facilitate the coordination and harmonization of this support on capacity building measures and cyber crisis management provided to these countries. I thank you, Mr. Chair.

Ambassador Gafoor

Give the floor now to Pakistan, followed by Côte d’Ivoire.

Pakistan

Thank you, Chair. Capacity building has a crucial role to play in effectively responding to the current and potential cyber threats. The need for capacity building becomes more important due to the large gap in terms of capacities and skills between states to deal with the threats emanating from cyberspace. Pakistan appreciates the focus of the second annual progress report on the area of capacity building, especially the need to narrow the gap between countries. Pakistan is in agreement with the principles of capacity building outlined in Act C of the APR. We underscore capacity building proposals such as short-term and long-term programs to address urgent threats, structural requirements, and to ensure sustainability through South-North cooperation. The international cooperation in the area of capacity building on equal footing is a key measure to secure and establish cyberspace. We also support the idea of a permanent capacity building mechanism under the United Nations with a specific focus on the needs of developing countries, especially taking into account the ongoing mapping exercise. The principles of capacity building should be demand-driven, taking into account the specific needs and context of member states with sustainable impacts. It should ensure fair, unconditional, and equitable access to related technologies, products, and services without any restriction on technology transfer. The states must be provided with the necessary technical support and resources for the establishment and effective utilization of CSIRTs, securing critical infrastructure, and the training of crisis management. We support the provision of fellowships and training for cybersecurity professionals in the area of critical infrastructure security, cyber policy making, and the application of international law in cyberspace. In this regard, we appreciate the UN Singapore Cyber Fellowship Program. Pakistani experts have benefited from this program. Mindful of the interlinkage between confidence building and capacity building, it is essential to ensure that ICT-related capacity building is seen as a trust-building measure and that it remains transparent, accountable, and non-discriminatory. Finally, Mr. Chair, we also support the idea presented by Egypt regarding the establishment of a fund to support the capacity building project in developing countries. We are looking forward to the UN Global Roundtable next year and hope that it would result in some concrete proposals and their implementation under the United Nations auspices for capacity building. I thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Pakistan. Cote d’Ivoire to be followed by Kazakhstan.

Cote dIvoire

Thank you, Chair. Chair, this is the first time that we are speaking since the beginning of this session. So we would like to commend your sacrifice and commitment to move forward with this important process, as well as the skill with which you fulfill your role. We fully support and are prepared to work for the success of your mission and the mandate that has been entrusted to us collectively. Chair, Côte d’Ivoire, since the beginning of this group’s work, has focused on the priority given to capacity building, which is the crucial solution for the development of all states and their ability to respond to threats when it comes to cyberspace security. We are very pleased today with the existence of a general consensus on the crucial role of this area of action and the cross-cutting nature of all of our discussions of the questions examined today. We are talking about innovative ways of coming up with concrete modalities and implementation to help contribute to our goals, that is, establishing a stable and peaceful cyberspace as an important issue at hand. It’s important to fully take stock of this challenge and work to promote the achievements of this group. And therefore, we support the Program of Action, which aims to promote responsible state behavior when it comes to using cyberspace in the context of international security. Chair, the variety of tools and methods, their coordination, and a flexible approach that would be adaptable and long-term are important, we believe, to take into account as we try to rethink our action for capacity building. And that is why my delegation favors exploring all dimensions of expanded cooperation in this area, including north-south cooperation, as well as south-south and triangular cooperation, and regional cooperation. Here, recent attacks on critical infrastructure and critical information infrastructure, as well as the international scope of their impacts, which has been spoken about often at this session, means that these various forms of cooperation must further develop tools to amend the vulnerabilities of states and allow them to defend themselves. It’s especially important to support and encourage regional and sub-regional initiatives that are relevant in this regard, such as the Cyber Africa Forum, which prioritizes, during its recent summit in Côte d’Ivoire, the protection of critical infrastructure against cyber threats through information sharing and sharing of best practices. In addition, the development of technical skills and human resources staff in states with lower digital resources, as well as courses in cyber diplomacy, could have a positive role to play. Côte d’Ivoire, like other member states of ECOWAS, took part in December 2022 in a seminar on international cyberspace security, which was jointly organized by the George C. Marshall Center, the U.S., and Germany, and we have found it very useful. In addition, renewed capacity building oriented toward achieving results requires adequate and sufficient financing. Therefore, it is crucial to find complementary options for financial aid and assistance, which would meet growing needs. Establishing a special fund with voluntary contributions could be an interesting avenue to explore. Thank you very much, Chair.

Ambassador Gafoor

Thank you very much, Gurdjieff, for your statement and suggestions. I give the floor now to Kazakhstan, followed by Saudi Arabia.

Kazakhstan

Thank you, Chair, for giving the floor. Capacity building in the secure use of ICT refers to the process of developing and enhancing the knowledge, skills, resources, and capabilities of individuals, organizations, and states to effectively understand, prevent, detect, respond to, and recover from cyber threats and attacks. It involves a comprehensive approach to strengthen the overall cyber security posture by addressing various aspects. Indeed, it should be noted that capacity building is relevant to all sections of the project report and plays an inclusive role in the safe use of ICT. We consider it essential to note in the draft report the importance of mentioning capacity building in national cyber security strategies as it enhances states’ resilience to emerging cyber threats and ensures the continuous evolution of their cyber security capabilities. In turn, Kazakhstan outlines in its national cyber security strategy prioritizing the establishment of necessary conditions for raising awareness of threats, developing capacity building, and enhancing the domestic ICT industry’s potential in creating cyber security software. These efforts are directed toward countering malicious software as well as ensuring secure telecommunications equipment. We also find it important to emphasize the significance of the regional and sub-regional cyber security training initiatives, including practical exercises and the use of ICT in fostering capacity building. Such events provide states with a valuable opportunity to enhance their cyber security capabilities, promoting collaborative learning and information exchange, thereby contributing to collective cyber security resilience. Thus, Kazakhstan actively engages as a participant in international and regional organizations, hosting regional training events as part of its commitment to collaborative efforts in enhancing cyber security capabilities. As an example, Kazakhstan conducted inter-regional cyber security exercises for the Commonwealth of Independent States and the Arab States region in cooperation with the UN International Telecommunication Union, using practical tasks that included scenario-based discussions. Besides, as part of the OSCE, Kazakhstan hosted sub-regional trainings for the representatives of the OSCE and participating states and demonstrated the work of the Security Operations Center and the work of domestic companies in the field of ICT, which gave a broader idea of capacity building. In addition, as a part of the capacity building, we consider it important to take into account creating recommendations for ensuring cyber security regarding critical infrastructure and data protection of countries, which could serve as a general guide for raising awareness and would contain basic norms for ensuring responsible behavior by states. Also, we consider it essential to note in the draft report the public awareness; raising awareness among the public and private sectors on cyber security best practices contributes to creating a more resilient overall ecosystem on capacity building. Additionally, Kazakhstan expresses gratitude to be a fellow of the Women in International Security and Cyberspace Fellowship Program, jointly sponsored by the Netherlands, Australia, Canada, New Zealand, the United Kingdom, and the United States. Effective capacity building is crucial for addressing the dynamic and complex nature of cyber security challenges. It aims to create a resilient environment that can withstand, adapt to, and recover from cyber threats, ultimately contributing to a more secure ICT ecosystem. Thank you, Chair.

Ambassador Gafoor

Thank you, Kazakhstan, for your statement. Saudi Arabia, followed by Malaysia.

Saudi Arabia

Mr. President, we align ourselves with the statement delivered by Egypt on behalf of the Arab Group. We deliver this statement in our national capacity. We commend your efforts, Mr. Chair, in facilitating our deliberations as part of the OEWG. The Kingdom of Saudi Arabia believes in the importance of capacity-building measures. They are important in achieving common objectives. We commend the voluntary checklist proposed to build confidence. This is a good starting point. On this basis, we can take effective measures in order to achieve progress. On the way forward and on how best to implement the aforementioned CBMs, we believe that there are several promising opportunities that can expand dialogue and that can help reach implementable steps. In particular, we would like to focus on the second point. We should continue to hold debates and bilateral workshops. And also, we focus on the fourth point, which is to promote opportunities to cooperate and to implement CBMs. We would like to shed light on the effective establishment of ministerial councils or boards on cyber security, boards that would address current topics. Cyber security is comprehensive and is of importance to several sectors. The ministerial committee on cyber security as part of the GCC is one such example. This committee was established to complement cooperation that already exists among GCC countries. The Kingdom believes that this approach is effective in promoting cooperation to achieve results. This is why we put forward a proposal to establish an Arab ministerial cyber security council affiliated with the Arab League. This proposal won the support of member states and it was eventually established. On additional CBMs that could be added to the voluntary checklist to build international confidence, we believe in highlighting the importance of existing efforts as part of the OEWG. Dialogues among multistakeholders are also important. At the same time, we should establish other avenues for comprehensive dialogue in order to build confidence. All stakeholders should be engaged, including the private sector and non-profit organizations, as well as academics and NGOs. The aim is to broaden dialogue to be more comprehensive and inclusive. This year, because we believe in the importance of broadening dialogue on cyber security, we hosted an international cyber security forum under the theme of common cyberspace priorities. The forum attracted international participation from NGOs, academics, and businesses inter alia. Participants came from more than 220 countries across the world. The forum also hosted 35 panel discussions with the participation of more than 150 speakers. In addition, we launched an international institution for cyber security. This is a legal personality and it’s financially and administratively independent and it is not a non-profit organization. It aims to maintain cyber security globally. It also aims to promote global cooperation and to achieve social and economic development. It also seeks to align relevant global efforts on cyber security. The institution will launch several initiatives and projects in order to build trust among different stakeholders. In conclusion, Mr. Chair, the Kingdom of Saudi Arabia reiterates support for efforts aimed to build trust among stakeholders. We will continue to support these efforts in order to promote interactive exchange among states for an open, secure, stable, and peaceful ICT environment. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you very much, Saudi Arabia. Malaysia to be followed by North Macedonia.

Malaysia

Mr. Chair, allow me to respond to your question on some of the foundational capacity required for states to detect, defend against, or respond to malicious cyber activities. Malaysia had earlier emphasized, in our intervention on existing and potential threats, the importance of cybersecurity as a fabric of digital transformation, and the need to incorporate it at the initiation stage, or in other words, to ensure security by design. This means that consideration of security elements has to be shifted to the earliest possible stage of any technology or ICT development so as to reduce exploitable flaws. Creating secure products should be prioritized, rather than simply adding security features on an ad hoc basis. This is where states require appropriate skills and abilities, which can only be achieved through effective capacity building. Capacity building will help foster and sustain a culture of security. With the right culture, security will be requested and demanded by all relevant stakeholders, and thereby become a prerequisite in technological development and acquisition. Mr. Chair, in order for a state to identify foundational capacity required to detect, defend against, or respond to malicious ICT activities, it is necessary to go back to fundamental elements of a cybersecurity framework. First, detection capability depends on the level of visibility of the threats in question, and relies on security monitoring mechanisms, including relevant tools, technology, skills, and people. Response and defense capacity depend on the level of proactive measures in place. Effective response can only be performed with proper control measures in place. Second, the identification of where and what security controls must be in place depends on cumulative risk assessment at the national level. Risk assessment will assist states in identifying suitable security controls, as well as the dependency and vulnerabilities of each of the assets associated with the relevant risks. Malaysia thanks Kuwait for elaborating the elements of people, process, and technology relating to effective cybersecurity baselining, supported by good governance. Just as cybersecurity is not amenable to a one-size-fits-all approach, neither are capacity building needs for each state. In this regard, Malaysia supports the comments of Bangladesh on the importance of the needs-based approach for capacity building. Malaysia also shares the views of many member states on the inclusion of industry and other stakeholders, given the nature and complexity of the cyber domain. Malaysia commends India on the technical aspect of the Global Cyber Security Cooperation Portal. We concur with Germany and Japan on including discussions on the possibility of consolidating existing portals or drawing linkages between them during the roundtable discussion on capacity building to be convened by the Chair next May. Thank you, Chair.

Ambassador Gafoor

Thank you very much, Malaysia. North Macedonia to be followed by Uruguay.

North Macedonia

Thank you, Mr. Chair. On behalf of North Macedonia, we want to thank you for your work in advancing the proceedings of the OEWG. North Macedonia aligns itself with the statement delivered by the delegation of the European Union and would like to deliver the following statement in its national capacity. Cybersecurity challenges are expanding in width and depth, targeting not only public institutions and the private sector but affecting the everyday personal life of our citizens. The lack of guidance and capacity to resist and defend leaves individuals, business sectors, and institutions highly vulnerable, especially in small and developing countries. Increasing resilience through capacity building involves bolstering infrastructure, communication networks, and response mechanisms to mitigate cyberattacks and deter the misuse of cyberspace. There is a clear need for mechanisms that can build trust and confidence in the civilian and business spheres in regard to capacity building. Creating national structures with a clear division of authority over the cybersecurity responsibilities on a national level is crucial for achieving national objectives. We firmly believe that while individual countries can develop their own capacity to protect national ICT infrastructure, regional and international cooperation are very important for accelerating the strengthening of national resilience and advancing response mechanisms. The support and assistance from developed countries in building and enhancing capacity for safeguarding particularly the critical infrastructure and critical information infrastructure is crucial to national resilience and security and is of immense importance for small and developing countries. Training programs, exercises, and workshops address one of the most significant challenges, the shortage of qualified personnel. Assistance in developing and implementing effective policies, sharing information, experiences, expertise, and best practices significantly enhance efficiency in countering cyber threats to critical infrastructure. I express this viewpoint based on our own experience. North Macedonia is currently in the process of identifying the national critical infrastructure, assessing risk, planning effective ways to eliminate and mitigate risk, and developing and implementing mechanisms for sharing information supported by the United States Agency for International Development, to whom we express our deep gratitude on this occasion. Chair, the OSCE cybersecurity conference we organized in Skopje in October showed a significant awareness of the associated risks and challenges. It reflected the inextricable nexus between cybersecurity and human rights. We need to come together and do our utmost to protect ourselves and our way of life in today’s interconnected world because, as it was said at this event, cybersecurity is not only about the virtual but also about the virtues and values we nurture, promote, and fight to safeguard.

Ambassador Gafoor

Thank you, Mr. Chair.

Uruguay

Thank you, Chair. We align with the statement made by Argentina on behalf of a group of countries from Latin America and the Caribbean. Uruguay has spoken at length about capacity building during past sessions of the Working Group, reaffirming at all times the need to increase cooperation in the area of cyber capacities in accordance with the needs and characteristics of each country. We would like to specifically thank UNIDIR for preparing the document “Unpacking Cyber Capacity Building Needs, Part 1, Mapping the Foundational Cyber Capabilities,” in which, through a detailed study with impressive methodology, it concludes that states must cooperate to develop and implement measures that increase stability and security in the use of ICTs, and that this cooperation must be well-structured and appropriate for the constant progress made in the sector. To this end, it is essential that we continue exchanging information and working together in order to contain crime and also eliminate terrorism. In this framework, cooperation between the CSIRTs and CSIRTs in our countries must be more active through bilateral, regional, and multilateral agreements on research, mutual assistance, and respect for laws. Mr. Chair, the growing interconnection in cyberspace, internet, the cloud, etc., continues to evolve and become more complex by the day. Data protection becomes one of the most important priorities of governments, of social organizations, and, of course, of individuals. Today, it is our responsibility to ensure an open and secure digital environment for all. Also, we need to develop tools which help the citizen to protect himself, to protect his or her digital assets and personal information. Thus, capacity building must also exist in the area of education and training of individuals. As we have said several times, technical and know-how capabilities of countries are different. The digital divide is a fact, and developed countries bear the responsibility to bridge this divide through technology transfers, an exchange of successful practices, know-how, and North-South cooperation. Of course, without prejudice to the major progress we have done in the area of South-South and triangular cooperation. Mr. Chair, in addition to what we have said already, we support joint simulation exercises like cyber drills, tabletop exercises, and others, which allow us to be better prepared in cases of cyber attacks. These exercises must be strengthened by educational and training institutions and the training of technical professionals, like the SOC analysts. With regard to checklists, Mr. Chair, we believe that these lists can be a useful instrument to have a baseline of the cyber security landscape in every state. These lists would also allow us to focus our capacity building efforts on the weakest areas which are identified by them. And thus, we would complement other initiatives which exist at the regional and bilateral levels. In the case of Uruguay, our digital government agency, AGESIC, has established checklists based on our cyber security framework, including on payment systems. We believe that at the international level we can further expand these practices and have better cyber security capabilities. Mr. Chair, as was mentioned by the countries of my region, it is essential that we bear in mind that capacity building must be fit for every state. And therefore, we have to take into account existing and future asymmetries with regard to digital capacities of countries. Uruguay therefore promotes the establishment of a standing capacity building framework in this organization, the United Nations. And we also reaffirm once again that the OEWG is the appropriate forum for discussing this matter. Thank you.

Ambassador Gafoor

Thank you very much, Uruguay. Mauritius, to be followed by Brazil.

Mauritius

Thank you, Chair, for giving me the floor. Good afternoon, colleagues. Cyber threats are borderless in nature, and no state alone can deal with the ever-evolving threat landscape. Protecting cyberspace is the responsibility of individuals, families, businesses, governments, and everyone else. By preventing attacks or mitigating the spread of an attack as quickly as possible, cyber threat actors lose their power. Any cyber attack, large-scale or small-scale, is a threat to national security and must be identified, managed, and shut down. In this digital age, it is encouraging to see that many governments, international organizations, and the private sector are increasingly acknowledging the importance of capacity building in dealing with those threats. The development and reinforcement of processes, competencies, resources, and agreements aim at consolidating national capabilities, developing collective capabilities, and facilitating international cooperation and partnerships in order to respond effectively to cyber-related challenges. In this context, Mauritius stands ready to share its expertise and build cyber-security capacity within the African region in operational, technical, legislative, and diplomatic areas. Through its national CERT, which has been given the responsibility of operating as an ITU academy training center for two consecutive mandates, Mauritius focuses on raising awareness in the aforementioned capacities and conducting trainings on cyber-security, including on the implementation of technical norms. Additionally, Mauritius continues to work in close collaboration with the regional and international communities to further strengthen the platforms and procedures for reporting cyber incidents, sharing information, and responding to potential breaches. Finally, Mauritius strongly believes that the network of CERTs could be expanded by signing MOUs with other CERTs in the region or globally in order to boost cyber-incident reporting and response linkages. Before ending, allow me to express our appreciation to India for its insightful presentation on the Global Cyber Security Cooperation Portal.

Ambassador Gafoor

Thank you. Mauritius. Brazil, to be followed by South Africa.

Brazil

Thank you very much, Mr. Chair. Mr. Chair, Brazil aligns itself with the statement made by Argentina on behalf of a number of Latin American countries and would like to add a few comments in its national capacity. Building capacities in the field of information communication technology security is essential for countries to benefit in a sustainable way from digital transformation, a key enabler of socio-economic development, while adequately addressing security vulnerabilities. The digital divide adds another layer to this challenge, rendering international cooperation an imperative and urgent effort to expand the capacity of states to mitigate risks and respond to cyber incidents. In this regard, capacity building has rightly been recognized as a cross-cutting element of our debates, essential to progress in all areas of the OEWG’s mandate. It also constitutes a confidence-building measure in and of itself. Brazil welcomed the mapping exercise mandated by the second APR in order to survey the global landscape of capacity building programs and initiatives and sent its contributions, both in a national capacity and jointly with other Latin American countries, last November. We hope this survey will help identify opportunities for synergies and avoid duplication of efforts, fostering greater and more effective international cooperation with a more efficient use of resources. In this regard, Brazil also welcomes India’s detailed presentation on its proposal on a global cybersecurity cooperation portal. Concentrating cooperation information, including on the multiple capacity building initiatives available on a single portal to be hosted at the UN website, would greatly facilitate access to the available cooperation by those who need it most. As a developing country itself, Brazil faces significant challenges in this area and has greatly benefited from capacity building initiatives from many countries and organizations present in this room. Given the rapidly evolving phase of digital technologies, developing and retaining enough qualified personnel is an ongoing challenge, and even more so from a gender, race, and disability-sensitive lens. Ensuring that women and persons belonging to other historically marginalized populations are duly qualified on cybersecurity is essential to a peaceful cyberspace. So is designing and implementing policies and procedures to tackle an ever-growing number of threats, such as those posed by ransomware, artificial intelligence, quantum computing, and other emerging technologies. At the same time, over the years, Brazil has made significant structural and institutional progress on cyber resilience, enabling us to also assist international capacity building efforts with a focus on South-South cooperation. Among its main international cooperation initiatives, Brazil is assisting Suriname in establishing its national CSIRT, including through training on the management of incident handling procedures, cyber threat analysis, and prevention. Additionally, our Ministry of Science, Technology, and Innovations National Education and Research Network launched last August a security operations center with the aim of monitoring and responding in real time to cyberattacks targeting universities, research institutions, and university hospitals, with more than 500 institutions and 4 million users, playing a crucial role in improving cybersecurity through advanced technologies and detection and response experts, an experience that it is hoping to share with its regional partners in the Latin American Corporation of Advanced Networks and the Regional Security Working Group of Academic Networks of Latin America and the Caribbean, where it already actively contributes with the sharing of good practices and other expertise. Finally, on cyber defense, the Brazilian Army Cyber Defense Command promotes international capacity building activities with its partners. For the past five years, it has held a countrywide multistakeholder tabletop exercise simulating a cyber attack on critical infrastructures called Cyber Guardian, the largest in the southern hemisphere, which has also included the participation of representatives from other countries who are interested in learning from our experience. We have also been fostering cooperation initiatives in cyber defense in the exercise of our chairmanship of the Ibero-American Cyber Defense Forum, including through information sharing, training courses, and joint exercises. I thank you very much, Mr. Chair.

Ambassador Gafoor

Thank you very much, Brazil. South Africa, to be followed by France.

South Africa

Chairperson, you asked us to reflect on foundational capacities required for Member States to effectively address malicious ICT activities, as well as capacities required for effective CIRT-to-CIRT cooperation. Due to the global character of cyberspace and ICT security threats propagation, effective cooperation is key for successful handling of cybersecurity incidents. With countries at different developmental levels, some of the foundational capacities required include assistance with the establishment of new CSIRTs or CIRTs and technical training of CIRT or CSIRT staff. This will assist in proactive monitoring of what is happening in their networks, developing, designing, and deploying secure and resilient networks. Capacity to adequately conduct security assessments and audits, proper configuration of devices, malware analysis, and the ability to detect intrusions is of paramount importance. We agree with Nigeria that gender mainstreaming is a priority for all capacity-building initiatives. We encourage the empowerment of women and girls to take the lead in addressing ICT security threats. Capacity to adequately deal with legal and policy issues involved in providing CIRT services and for efficient CIRT-to-CIRT cooperation is a requirement. We share the sentiment expressed by Uganda yesterday on developing local capacities. And in this regard, we call for a more concerted approach to policy, legal, and technical competence in capacity-building, which focuses on the human capacity within countries. To ensure sustainability and ownership, we believe that train-the-trainer training is key. Chairperson, on your second question, the Global Cyber Security Cooperation Portal is one of the concrete proposals the OEWG has agreed to develop further. And we believe that it can build on experiences of similar mechanisms within the UN system. We envisage a platform which will be interoperable and compatible with existing knowledge-based platforms and at the disposal of UN member states. It should consolidate rather than duplicate what exists already. With regard to the voluntary checklists and other tools to assist states in mainstreaming the capacity-building principles, we see a multidimensional and tiered approach to this. As alluded to earlier, states are at different developmental levels. And as such, the checklist should cater for everyone in keeping with the motto that we should leave no one behind, without creating anxiety and overwhelming those at infant stages, while progressively building on gains achieved thus far. We have taken note of the presentation by India on the portal and will study it further. On the role of the United Nations in the provision, coordination, or facilitation of capacity-building, as previously stated, our view is that the UN should be the body coordinating capacity-building. We are mindful of the many areas of capacity-building, legal, legislative, diplomatic, policy, and technical, as articulated in the reports of this working group and its predecessor, and the role played by multiple stakeholders. However, there is a need for the UN to be the repository of all these initiatives and conduct a thorough and detailed mapping of them with inputs from stakeholders. Thank you.

Ambassador Gafoor

Thank you, South Africa. France to be followed by the UK.

France

Mr. Chair, my delegation aligns itself with the statement made by the EU and would like to make the following comments in its national capacity. First of all, given the growing threats that we described during the dedicated sessions, France has made a strategic priority of the contribution to strengthening cyber-resilience and its partners, and it has done so in a parallel and complementary way to the efforts it has made to strengthen national cyber-security. France systematically aligns its efforts to strengthen cyber-capacity with the UN Framework for Responsible State Behaviour. The trans-regional proposal of the Program of Action (POA), initiated in 2020, is part of the same logic. It deepens this approach and makes it a long-term one. We have developed our national actions based on those of our partners to maximize synergies, as you asked us to do so, Mr. Chair. In this vein, we commend and adhere to the ACRA call, which was published at the GC3P conference. As for the global cyber-security cooperation portal proposed by India, here I’d like to point out the future usefulness of having this kind of modular portal to facilitate access and information sharing in the area of capacity building, together with existing tools. In addition, France is focusing its action on developing regional centers. We thus encourage regional cooperation while ensuring that we meet local needs on the field. We therefore welcome the launch of the Capacity Building Center for the Western Balkans, the WB3C, in May 2023 in partnership with Slovenia and Montenegro. As mentioned by the Slovenian delegate, this center is a platform for institutional and operational capacity building in the region. This is an example that involves several countries in the world, and the future of France is not one of dependence. On the contrary, it is one of solidarity and shared interest to increase cyber-resilience and to contribute to achieving the SDGs. Thirdly, we align ourselves with the concerns expressed by the delegation of the Netherlands during the session on threats. When it comes to cyber-security of international organizations, we must not forget to strengthen capacity in these institutions so that they can fulfill their mandates. Here France announced on December 12th a voluntary contribution, an additional contribution, of €500,000 to build up capacity in cyber-security of the International Criminal Court, or the ICC. France once again condemns threats and cyber-attacks against the court, which constitute a severe threat to its work. Lastly, it is important to accelerate the implementation of capacity building. To contribute to this, we are taking active part in the roundtable on capacity building in May. We underscored the importance that interested stakeholders be involved, and it’s also important to guarantee that delegations of developing countries can share in the needs on the local level on this occasion. These are the needs that should inform our action in the long term.

Ambassador Gafoor

You’re welcome! If you have any text that needs proofreading, please provide it, and I’ll be happy to assist.

UK

Thank you, Chair. In the interest of time, we will focus on three of your questions. First, on the foundational capacities required, we would like to highlight the work conducted by UNIDIR, the GFCE, and the Oxford Global Cyber Security Capacity Centre. Best practice from these organizations suggests there are typically five broad types of capacities that states should consider. First, policy and strategy, which includes national strategies and approaches to incident response. Second, culture and society, which includes trust in online services. Third, building knowledge and capabilities, which includes education and awareness. Fourth, legal and regulatory frameworks. And the fifth capacity dimension is standards and technologies. States are developing their maturity in these five dimensions at different rates, and it is important that all states have access to a wide range of knowledge, expertise, and information. You also asked about effective use of CSIRT to CSIRT mechanisms. We advocate membership of the non-profit organization, the Forum of Incident Response and Security Teams, generally referred to as FIRST. Membership of FIRST enables incident response teams to respond effectively to security incidents. The United Kingdom recently announced sponsorship of a FIRST Africa liaison office. This is a partnership with the incident response community in the African region. There is significant value in enhancing regional CSIRT to CSIRT cooperation like this. And to this end, the UK is also partnering with the OAS to support the training of CSIRTs. Second, you asked about the global cybersecurity cooperation portal and opportunities for synergies with other portals. The presentation showed there are various related portals, and as a number of other countries have already said, we would support connections between these portals to ensure each state can access the information they need in a way that works for them wherever the information sits. The UK’s priority is to ensure that the information and guidance hosted on each portal is high quality and reflects the expertise in the multistakeholder community. The GFCE’s Cybil portal also has useful information that we should further invest in and share with the widest possible audience. Third, you asked what additional role the United Nations could perform in the provision, coordination, or facilitation of capacity building efforts in a manner that complements existing initiatives. As your question says, it is essential that any new activity undertaken by the UN complements rather than duplicates the diverse range of cybersecurity capacity building already occurring in all regions. The UN’s resources are limited, and it is important that we do not introduce more complexity for states or inadvertently harm the maturing cybersecurity capacity building ecosystem. With this in mind, we see potential for the United Nations to help promote synergies between cybersecurity capacity building and the sustainable development agenda. As our economies become more reliant on digital technologies, national cyber resilience is increasingly an important foundation for economic development, but we can do more to convene the diverse stakeholders involved in delivering both sets of activity. The GFCE conference in Ghana was welcome. Existing international development activity under the sustainable development goals, including activity delivered through development banks, has significant potential to accelerate digital development, including cybersecurity. We welcome the forthcoming Global Roundtable on Capacity Building. The UN has a unique role in this type of convening. This event will be an opportunity for the wide range of cybersecurity capacity building experts to share lessons and best practice with the OEWG community. We would advocate a particular emphasis at the Roundtable on the critical role of non-profit organizations who can deliver sustainable and effective cybersecurity solutions. Stakeholder participation is essential to effective capacity building, and it is important that we do not exclude stakeholders. As a number of states have already noted, we will discuss inclusivity and the possible role of stakeholders under a future Program of Action in the next agenda item. Thank you, Chair.

Ambassador Gafoor

Thank you very much. UK, Russian Federation, to be followed by Indonesia.

Russia

Mr. Chair, we believe that the result of the activities of the OEWG in the area of capacity building should be practice-oriented recommendations and proposals for assistance programs. It is important that such measures meet the needs of States and are in line with the universal principles in this field, as set out in the annex to the second report of the group. This means, first and foremost, respect for State sovereignty. Our country is paying increased attention to the issue of capacity building. This topic is an important part of the annual Russian draft GA resolution on international information security, which calls on the OEWG to develop specific mechanisms to meet the needs of States in this regard, including financial needs. In our national capacity, we focus on training personnel in the field of information security. Foreign students from the countries of Asia, Africa, the Middle East, and Latin America study at Russian universities under major higher education programs and additional professional education programs. Specialties include information and computer security, methods of detecting and countering network computer attacks in open information systems, methods and techniques for protecting information from unauthorized access, collecting information from open source data, combating crimes in the field of computer information, techniques for investigating crimes committed using ICTs, and international cooperation in this area, computer forensics, countering telephone fraud, countering the use of ICTs and international postal services for drug trafficking and theft of funds, identification and investigation of illegal transactions using digital assets, including cryptocurrencies and their use for financing of terrorism. We are prepared to accept relevant applications from interested foreign partners. As part of the implementation of bilateral agreements and cooperation programs signed with the competent authorities of foreign countries, expert training courses, roundtables, and working meetings with foreign partners are all held to exchange best practices on information security and to combat crime in the field of ICTs, as well as practices on information on relevant national legislation. We are increasing our efforts in regional formats as well. In 2023, we conducted a series of educational events together with partners in the CIS on the prevention, detection, and investigation of crimes committed using ICTs. At the ASEAN Regional Forum on Security, annual seminars on terminology in the use of ICTs and combating information crime were held. We organized online meetings within the Conference on Interaction and Confidence-Building Measures in Asia on secure development of the internet and digital forensics, as well as a training course on investigating crimes involving financial theft with the use of ICTs. We are planning to increase cooperation with our partners in various regional formats, taking into account the growing interest in our experience. From our perspective, it is important to involve other interested parties in capacity-building efforts, in particular businesses, academia, and non-governmental organizations. Of course, this assistance should be carried out strictly on a non-discriminatory and impartial basis. Capacity-building should not be used to lobby for the interests of individual companies or groups of companies or to make less developed countries technologically dependent. It is necessary to ensure that non-state actors strictly comply with the laws of the countries in which they operate. This includes the need to cooperate with national regulators.

Ambassador Gafoor

Thank you, Russian Federation. Indonesia, to be followed by Mexico. Microphone for Indonesia, please.

Indonesia

Thank you, Chair. Indonesia shares the common view that capacity building is indeed the foundational element on which the other pillars rest, and we believe that all training or capacity building efforts to strengthen state cyber capabilities should be tailored to better match the differing needs and levels of development of states. We thank you for the guiding questions that you have outlined to facilitate our discussion and would like to make some comments. To answer your first question on what foundational capacities are required for states to detect, defend against, or respond to malicious ICT activities, Indonesia views the importance of, first, a routine communication test, tabletop exercise, and cyber drill test. Second, regular trainings to CIRT members to keep updated with the latest security threats, improve monitoring capabilities to anomalies, and defend methods. And third, the strengthening of capabilities for cyber incident response, including through training and support for Computer Security Incident Response Teams, or CSIRTs, and CIRTs, particularly in providing and developing analysis tools that can assist CIRTs in analyzing forensic data, malware, and other security indicators. Furthermore, we are also of the view that development and implementation of emergency response, including encouraging and supporting joint cross-regional CIRT exercises, formulation of contingency plans for cyber crisis management, and safe information exchange mechanisms are equally beneficial to further strengthen states’ capabilities. Concerning the Global Cyber Security Cooperation Portal as a one-stop-shop tool for states, my delegation supports the continuation of discussion to develop such a portal, and our preliminary views are once it’s operationalized, such a portal should be connected to national and regional CIRT to ensure that information could be accessed directly by relevant national and regional operational units. In addition, in regards to credentials of accessing the portal, each state’s credentials should consist of diplomatic as well as technical points of contact. And lastly, we would also suggest that the Portal Module 5, Incident Information Sharing, also contains a mechanism for sharing information regarding the latest cyber threats or attacks, along with the mitigation that can be carried out. I thank you, Chair.

Ambassador Gafoor

Thank you very much, Indonesia. Mexico to be followed by the United States.

Mexico

Thank you, Mr. Chair. Mexico aligns with the statement made by Argentina on behalf of a group of Latin American countries and would like to state the following in our national capacity. We thank India for submitting its proposal of the Global Cyber Security Cooperation Portal. We reiterate the importance of strengthening capacity building through an international cooperation approach adapted to the specific needs of each context, and this based on the implementation of principles, norms, and confidence-building measures adopted at the United Nations. We also stress that capacity building and strengthening are cross-cutting and crucial elements which must be considered in all the dimensions of the work of this group. As several delegations have mentioned, not all countries have the same capacity to detect and counter threats, which means that capacity building and maintenance are key to ensure a more secure digital environment for all. Implementing existing norms must reflect differences in the progress made and consider existing regional frameworks. To understand how international law applies to cyberspace means that we must all have similar tools. Furthermore, the future and permanent institutional dialogue will not be sustainable nor complete without a clear approach to continuous capacity building and strengthening. Mexico is pleased to be part of the ACRA call, an initiative recently adopted in the framework of the Global Forum on Cyber Expertise. This document offers an exceptional opportunity for government and international organizations, academia, civil society, and other relevant actors in their respective areas of expertise to reaffirm their commitment to capacity building and coordinate efforts to strengthen cyber resilience. In particular, we welcome the fact that the document incorporates cyber resilience and capacity building as essential elements for progress in this era of digital interdependence. This can be achieved by strengthening partnerships between the public and private sectors, developing capacities specifically adapted to the individual needs of each state, and making effective use of existing platforms, such as the Global Forum on Cyber Expertise. We also recognize the important work done by regional organizations in promoting and supporting member states in the process of capacity development and cyber resilience. While it is true that important efforts are taking place at the national and regional levels, we believe that there is room for an interregional dimension. We eagerly await the Global Roundtable on Capacity Building, which is scheduled for May 2024. This will be an important effort to add more expert voices to our dialogue. Mexico also joins in the voices which have recognized in this group the aggregate value of establishing partnerships with multistakeholders on capacity building and strengthening. We value and recognize the important work of raising awareness, training, and organizing exchanges, which academia, organized civil society, and the private sector undertake. In conclusion, I thank the sponsors of the Fellowship Women in Cyber. This is a program which has been crucial and has increased the involvement of women delegates in this working group. It has had a significant and positive impact on the progress of our negotiations. Thank you.

Ambassador Gafoor

United States, to be followed by Botswana.

United States

Thank you, Chair. The task of cyber capacity building is vast in scope and urgent, and there are ongoing programs designed to meet this need. This week, we have all heard about some of the capacity building being provided within regional organizations by development organizations such as the World Bank and through global initiatives like the GFCE. We appreciate UNODA’s work in gathering views of member states on the landscape of these ICT capacity building programs and initiatives as requested by the second APR. We also note the ITU is currently undertaking a mapping project to help build awareness on currently available cyber security training and assistance. We believe the OEWG’s unique contribution to effective capacity building is to articulate how best to use capacity building resources to enable global awareness and adoption of the framework, including those measures recommended by the group like the POC directory. This would include, as Bangladesh suggests, providing developing countries means to assess current and emerging areas of need in addition to cataloging existing programs. Chair, in response to your question on capacity building priorities, I’d like to share what we consider to be some foundational capacities to responsibly manage cyber issues. First, states must have the domestic architecture to manage cyber incidents, which includes a functioning CERT with trained employees, national cyber crime laws, effective partnerships with the private sector, and a national cyber strategy. These domestic best practices were cemented in several consensus GA resolutions on the creation of a global culture of cyber security. Second, states need to understand how transnational cyber issues, including the international security dimensions of cyberspace, can impact their domestic cyber environment and also have the familiarity with the UN framework and the commitments all states have made in this regard. Third, states must establish ongoing interagency coordination to respond to any significant cyber incidents and ensure that their domestic and international policies remain aligned and up to date. And last but not least, states need to establish coordination among their officials with multilateral expertise, legal expertise, and cyber expertise within the foreign ministry and government writ large to effectively engage in ongoing international discussions such as the OEWG. Last month, Ghana was host to the inaugural GC3B, the largest gathering to date of the cyber capacity building community, with an aim to mainstream cyber resilience in digital development. Because the United States believes that these discussions should be as inclusive as possible, we funded travel and participation of a dozen participants from G77 countries. At the conference, many states, including the United States, endorsed the ACRA call, which is a practical action framework for the multistakeholder community to further mainstream cyber capacity building into digital development. The United States also supported a session during the conference on the intersection of cyber capacity building and international security, where the U.S. head of delegation highlighted that malicious cyber activity threatens digital development and international security alike. We believe these efforts are useful in mobilizing an ever larger and more inclusive group of stakeholders to advance cyber capabilities worldwide. Moving on, I wanted to take this opportunity to thank the Indian delegation for its detailed presentation on its portal proposal. We look forward to further discussion on this proposal and appreciate India’s efforts to identify those areas for improvement in ongoing member state cyber coordination. We also thank the managers of existing portals for their briefs earlier this year on the scope of their work and potential opportunities for their portal’s growth. We understand that the UNIDIR and GFCE portals are already interconnected, which is one important feature of these existing portals. We recognize that there are ways in which these portals may be improved in the near term, and we look forward to engaging with India and all states to build on rather than duplicate these efforts. Furthermore, it may be that discussions on the functionality that states seek in a portal lead to the conclusion that a longer-term effort is required. In that case, the future POA established under Resolution 7816 would be the ideal forum to take forward such an initiative. Finally, we recognize the importance of a dedicated OEWG agenda on the issue of capacity building, but we have also found related discussions within the other agenda items equally, if not more, important on the question of how capacity building can help states understand the cyber threat landscape and understand how to live up to their commitments to act responsibly in cyberspace. For example, we look forward to further consideration of the proposal for a threat repository to facilitate information sharing among states. As we and many other states have raised, capacity building on international law has contributed substantially to our common understanding of it, and much more can and should be done in this area. And as we have just heard, capacity building focused on helping states connect to the POC directory will be essential to the effective functioning of that directory. Thank you, Chair, for continuing to encourage a robust OEWG discussion on this important area of work.

Ambassador Gafoor

Thank you, United States. Botswana, to be followed by Canada.

Botswana

Thank you, Chair, for giving us the floor. Since it’s our first time on the floor, Chair, my delegation and I would like to express our sincere appreciation to you and your dedicated team for your diligent efforts in advancing the work of this OEWG. Mr. Chair, Botswana underscores that capacity building is essential in assisting developing states in the organization of their national cybersecurity efforts, to develop policy frameworks to counter ICT threats against critical infrastructure and critical information infrastructure, implementing the agreed norms, developing and publishing national positions on international law, among others. The level of digital development affects how a state responds to cyber threats, hence the need to enhance technical and administrative skills. Botswana is faced with threats such as ransomware, phishing, elements of ignorance and curiosity to deal in forex trading, and cryptocurrency. It is therefore critical to strengthen capabilities to identify cyber threats in order to respond to and prevent misuse of ICTs. Capacity building is therefore a priority for our nation. We recognize efforts by those who offer capacity building to those in need. In this regard, Chair, we agree with states that have spoken before us that there is a need for a UN-based centralized portal, where states can indicate their capacity building needs as well as the available initiatives for those that require capacity building. Cybersecurity training programs, tabletop exercises, and public awareness around cybersecurity will go a long way in enhancing cyber capacities. Botswana believes that the UN can work hand-in-hand with regional and sub-regional bodies to roll out capacity building initiatives. We believe that this should be made a continuous process that is formally facilitated from the UN. Regional and sub-regional bodies normally have a greater understanding of the needs of their member states and are better placed to facilitate capacity building from their end. This would ensure that there is a common understanding of norms, rules, and principles of responsible state behavior and of international law by all. There will also be an enhancement of the technical capacity of member states to tackle cyber threats. We appreciate and praise all states, regional and sub-regional bodies who have put in efforts towards cyber capacity building. On how the Voluntary Checklist for Mainstreaming Capacity Building should look like, Botswana believes this checklist should portray more inclusivity, transparency, and be impactful. The checklist can include areas that involve multistakeholder involvement and participation in these discussions. The second APR encourages states to develop and share tools that would assist states in incorporating a gender perspective into capacity building efforts. We agree that incorporating the gender perspective will help bridge the gender divide to ultimately achieve gender equality. Strengthening the capacity of actors designing and implementing cybersecurity policies, the tools should incorporate awareness campaigns that will tackle gendered cyber threats, provide gender-inclusive recommendations on cybersecurity hygiene strategies, and address cross-sectoral cybersecurity resource inequalities. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Botswana. Canada to be followed by Croatia.

Canada

Thank you, Chair. Capacity building is a cross-cutting issue and is relevant for all elements of the framework that we seek to consolidate. It is an important tool for supporting the implementation of norms, the development of national positions on the way in which international law applies in cyberspace, as well as the implementation of confidence-building measures, or CBMs. Chair, Canada is aware that we must continue our capacity building efforts and that we are moving forward with enthusiasm. That is why Canada has allocated $35 million for cyber capacity building, especially in the Americas, so that our partners can establish their CERT teams and establish their national strategies for cybersecurity. In addition, as we mentioned yesterday, Canada has financed trainings on international law in cyberspace for more than 250 beneficiaries from more than 82 states. Canada has a partnership as well with the Organization of American States. This is an example of a tool that incorporates a gender perspective in capacity building in order to improve it. In the same vein, we are proud of promoting the participation of women in international negotiations on cybersecurity thanks to our program Women in International Security and Cyberspace, or Women in Cyber. We support the implementation of the agreed principles on capacity building contained in Annex C of the second APR. The participation of non-governmental stakeholders is crucial for a broader promotion of these principles, and we encourage states to work together with stakeholders to develop tools such as voluntary checklists. Chair, we have taken note of the discussions recently held at the Global Conference on Cyber Capacity Development, GC3B, and we thank Ghana for hosting us. Canada is delighted to endorse the Accra Call for Cyber Resilience, which aims to incorporate cyber measures in development programming. The goal is to facilitate achieving the SDGs. The Accra Call aims to promote coordination of capacity building activities and the promotion of inclusive public-private partnerships. We believe that to further these goals, it is crucial to harness the expertise of specialized organizations such as the Global Forum on Cyber Expertise. This institution supports the efforts of the international community to ensure an optimal impact on cyber capacity building and to prevent duplication. We encourage states that are not yet members of the GFCE to join it. The balance between needs and capacity building efforts is a key element that we are keeping in mind, and that is why we promote the idea of a virtuous cycle in the Program of Action. This virtuous cycle would allow members to identify in voluntary fashion the elements of a responsible behavior framework, which they believe would most be able to benefit capacity building. Targeted capacity building activities in this regard would then be conducted. Then, beneficiary states could assess whether needs remain, and if so, then a new wave of efforts for targeted capacity building would ensue to improve the areas that need improvement. We believe that this virtuous cycle would function continuously, and this would support a constant improvement of capacities and compliance with a responsible behavior framework in cyberspace. We are prepared to discuss this approach with all interested countries. Lastly, Mr. Chair, we would like to thank India for its informative presentation of the portal, and we will be studying it in detail. Thank you, Chair.

Ambassador Gafoor

Thank you very much, Canada. Croatia to be followed by Ghana.

Croatia

Thank you very much, Chair, and also many thanks for the guiding questions. Additionally, we would like to express our full support for the announced Global Roundtable in May, and we would encourage participation not just of governmental representatives, but also of the broader multistakeholder community. Capacity building is a joint effort, and a whole-society approach is needed. Croatia aligns itself with the intervention of the European Union, and in national capacity would like to emphasize some additional points. Capacity building is not a one-way street. In this process, we can learn from each other, and all together contribute to a common understanding and strengthening resilience of all Member States, while at the same time not forgetting that capacity building is an important tool in the fulfillment of sustainable development goals, aiming to bridge the gap and to address the digital divide. In order to detect, deter, defend, and respond to malicious ICT activities, States should develop computer emergency response teams. But before you can establish a team, you need to find adequate experts, but also set up a legal and policy framework, including the National Cyber Security Strategy. So capacity building efforts should be directed into several directions, from technical to political level, and as Kenya also mentioned earlier, those efforts should simultaneously encourage as much as possible a whole-government approach. Regular trainings, lifelong learning, and building of skills should be at the core of our capacity building efforts, as well as exercises. In the European Union, we have three levels of cooperation between Member States. We have technical level through CSIRTs network, operational through CYCLONE network, and political through the Council. And with regular exchanges and tabletop exercises, we are strengthening national and common resilience, as well as capabilities to detect, deter, defend, and respond, but also to recover from malicious cyber activities. So exchanges, sharing expertise, and lessons learned are not just an essential part of the capacity building, but also a confidence-building measure, both on regional and global levels. We would like to support Argentina intervening on behalf of Latin American countries, that in our capacity building efforts, focus should also be given to new and emerging technologies. And I would like to join Egypt on behalf of Arab countries in thanking Singapore and the UN Office for Disarmament Affairs for conducting an excellent cyber fellowship program, which provides valuable training for practitioners from all cyber domains, from cyber crime and cyber security to cyber diplomacy. We would also like to congratulate the Global Forum on Cyber Expertise, the Cyber Peace Institute, the World Bank, the World Economic Forum, and the Ministry of Digitalization and Communication of Ghana for an excellent global conference on cyber capacity building held recently in Accra. It is important to raise awareness on ICT security and to connect cyber with development communities, as well as to mainstream cyber resilience into development assistance. Furthermore, international and regional financial institutions should be encouraged to dedicate more resources for financing cyber projects and the development of secure ICT infrastructure. Bringing all initiatives on capacity building under one roof would be beneficial, especially for smaller countries with limited human resources. So we would encourage integrating proposals in this regard, for example, within the upcoming Program of Action, so that we have synergy and complementarity and not fragmentation. We would like to thank India for presenting their proposal on the portal, which we will study very carefully. It is crucial that we are able to provide help in mapping the needs of countries and strengthening trust among different stakeholders, so that they can provide a tailor-made offer, combining precious knowledge and experience, which can be implemented in our common cyber architecture. The future portal could help in matchmaking between needs and offers, but also provide an overview of different initiatives, both from the public and private sectors, and we would also encourage from academia as well. Strengthening global cybersecurity capacities in order to better protect our economies and societies from cyber attacks can’t be done without taking into account a gender perspective, as many delegations rightly raised earlier. We have already mentioned some numbers and statistics during our last meetings, so allow me just briefly to refer to two projects. One is regional and the other one is international, and already mentioned several times today. The Women for Cyber Initiative gathers women from the public and private sectors, academia, and civil sector from all over Europe, with the objective to promote, encourage, and support the participation of women in the field of cybersecurity, by among others organizing conferences, workshops, and trainings, and sharing information on job opportunities in the field of cybersecurity. Internationally, colleagues have already mentioned the Women in Cyber Fellowship, which aims to ensure equal and effective representation of women diplomats from all regions in UN cyber negotiations. These initiatives are a good example of how a gender perspective could be incorporated into capacity building efforts, and we would like to remind colleagues that it is our obligation, in line with final reports from 2021, annual progress reports from 2022 and 2023, endorsed by the General Assembly, to narrow the gender-digital divide and to promote the effective and meaningful participation and leadership of women in decision-making processes related to the use of ICTs in the context of international security. And as we heard from the stakeholders yesterday, I would like to thank them also very much for their valuable input. It is important to acknowledge that broader participation of women in cybersecurity will also contribute to overall global peace and security. Furthermore, achieving resilience, but also improving the ability to prevent, protect, deter, respond, and recover from cyber incidents, is a joint effort, and cooperation between the public and private sectors, civil society, academia, and the tech community is crucial and indispensable. Dear colleagues, it will not surprise you that football is one of our most successful export products. More than 400 Croatian football players are playing in 135 professional leagues worldwide, which brings us to eighth place in the world among exporters of footballers. Brazil holds, of course, the first place on that list. Croatia has around 140,000 registered football players, but in our public administration, just a few legal experts for cyberspace, mostly for cybercrime, and just two for international law in cyberspace. And since they are not allowed to travel together, I have today only one behind me. Hence, we are among those who would gladly apply for capacity building, also in the area of application of international law in cyberspace, so that in upcoming years, we can also export cyber law experts and not just football players. There is a universal need to make ICT security more appealing and to encourage public administration and practitioners to deep dive into cybersecurity and to boost better connection of technical, operational, and political levels. At the national level, states should pay special attention to the protection of vulnerable groups, including children and youth, as well as older persons, and promote broader digital literacy and security online by strengthening cyber hygiene. Chair, as you and some colleagues rightfully said earlier, also in the capacity building efforts, we should ensure that no one will be left behind. Thank you very much.

Ambassador Gafoor

Thank you very much, Croatia. The football analogy is a very good one because ultimately I think footballers are the ultimate confidence builders around the world. On that score, I should say that Singapore needs considerable capacity building in football. So we definitely would welcome assistance from Croatia in that regard. Let’s go through the speaker’s list. It’s 15 minutes to six. I think I have about maybe 20 speakers, and I think this is an important discussion, so I have not been trying to curtail your remarks. But I gather it’s Friday today, so we have one day left. So we need to wrap up this discussion and then go on to another important discussion, which is Regular Institutional Dialogue and POA, and many of you have already been talking about the POA. So we need to connect the various discussions into the institutional discussion or the Regular Institutional Dialogue discussion. So I will continue to give the floor to speakers till six o’clock, but if you are able to summarize and submit a fuller statement, that would also be welcome and appreciated. So Ghana to be followed by the Netherlands.

Ghana

Thank you very much for giving me the floor, Mr. Chair. Apologies, this will be quite lengthy. I’ll start by reading a statement, a joint statement first, between the Republic of Ghana and the Kingdom of Netherlands, before I proceed to give a statement in my national capacity. So the work of this Open-Ended Working Group demonstrates that while the advent of the fourth industrial revolution presents tremendous opportunities, it also comes with ever-growing cyber security risks. Cyber resilience is a key ingredient in ensuring that all our societies and citizens can reap the benefits of the digital transformation. We are reminded of that as we discuss how these risks affect national and international peace and security. Therefore, Mr. Chair, we are committed to working towards greater resilience of our cyber ecosystem in order to avoid the increase of vulnerabilities for states, the private sector, civil society organizations, and individuals, in particular those who are already in vulnerable situations. Indeed, we have a shared responsibility to ensure that the migration to digital platforms takes place in a way that benefits every individual regardless of their age, gender, and level of education. If we want to ensure that no one is left behind in a digitized society, we need to invest in cyber security at the same time. Ghana and the Netherlands therefore share a strong commitment to international cooperation and capacity building to advance cyber resilient development. We believe this is a key piece of the puzzle to ensure we bridge the digital divide and advance towards the attainment of the sustainable development goals. Chair, two weeks ago, Ghana hosted the Global Conference on Cyber Capacity Building, or commonly known as the GC3B, in Accra. Organized together with the Global Forum on Cyber Expertise, the World Bank, the Cyber Peace Institute, and the World Economic Forum, we welcomed more than 700 participants from diverse stakeholder communities to engage in conversations around the theme “Cyber Resilience for Development.” During the conference, Ghana and the Netherlands, together with 45 states and organizations, including the African Union and the European Union, endorsed the Accra Call for Cyber Resilience Development. Other countries are currently going through the process of declaring their endorsements. We would like to encourage regional organizations to utilize their platforms to encourage more member states to consider endorsing the Accra Call. This call articulates actions directed to first, strengthen the role of cyber resilience as an enabler for sustainable development; second, advance demand-driven, effective, and sustainable capacity building; third, foster stronger partnerships and better coordination; and fourth, unlock financial resources and implementation modalities. We welcome other states and organizations to join this call to strengthen coordinated action in support of international cyber resilience. Chair, it is imperative that member states put in place the right measures to build a resilient cyber ecosystem. This is important in ensuring that all states can harness the gains of digitalization and consequently contribute to a safe and secure cyberspace, making them less vulnerable to the threats in cyberspace that have been raised in the OEWG over the past days. I thank you, Mr. Chair. And on that note, I would now give a statement in my national capacity. Mr. Chair, it is very evident from the statements that have already been read that capacity building is an integral component of our cyber security efforts. Capacity building has been raised in other areas such as international law, confidence-building measures, and in understanding potential threats. Ghana has been engaging in capacity building initiatives since the appointment of a national cyber security advisor, leading to the establishment of a national cyber security secretariat, which evolved into an international cyber security center and is now a fully-fledged cyber security authority. Ghana’s cyber capacity building initiatives have been witnessed through our partnership with the Council of Europe, World Economic Forum, Freedom Online Coalition, and the Global Forum on Cyber Expertise, among others. Ghana’s interest in capacity building is the reason why we were elated to be selected as the host country for the maiden conference. This conference, which brought together multiple decision-makers and practitioners from governments, international organizations, and the private sector, further provided an opportunity for the world to witness the importance of having a multistakeholder and multi-sectoral approach to cyber capacity building initiatives. Mr. Chair, now in response to your inquiries, my delegation proposes the following foundational capacities to address and respond to malicious activities in the realm of information and communication technology. We believe the following measures are crucial for states to safeguard against cyber threats and make effective use of existing mechanisms, such as CSIRTs channels. Firstly, we believe that the establishment of legal frameworks is of vital importance. It is essential to have robust legal frameworks that clearly define cyber crime, criminalize malicious actors in cyberspace, prescribe penalties, and establish jurisdiction for prosecuting cyber criminals. These frameworks should also protect critical information infrastructure and regulate information sharing between public and private entities. Second is the establishment of a dedicated national cyber security agency. Creating a central national agency responsible for regulating cyber security matters, including monitoring, analyzing, and responding to incidents, is imperative. These agencies can house national CSIRTs and provide them with the necessary tools and resources for their effective operation. Third is establishing dedicated mechanisms and channels for responding to cyber security incidents promptly and securely. In Ghana, the National Cyber Security Incident Reporting Point of Contact, initiated in 2020 by the Ministry of Communications, has proven effective and provided citizens with an opportunity to utilize the platform for fact-checking and due diligence by reaching out to the CSA to assist them in verifying websites before taking action. To date, the CSA has received almost 45,000 contacts. Additionally, the development and regular updating of incident response plans and standard operating procedures that outline procedures for detecting, reporting, and handling, mitigating different types of cyber security incidents is also essential. Implementation of information sharing mechanisms to facilitate the exchange of cyber threat intelligence and incident information among government agencies, private sector entities, and international partners is also beneficial. Finally, international collaboration remains crucial. Actively participating in international cyber security communities like FIRST and forums to strengthen collaboration with other countries and their country CSIRTs, including signing bilateral and multilateral agreements for information sharing and joint response to cross-border cyber incidents, is beneficial to countries. Mr. Chair, to conclude, Ghana would like to commend initiatives like the Women in Cyber Fellowship, in which we have actively participated since 2019. We believe that such programs play a crucial role in equipping member states with the necessary tools, capacity, and training to actively engage in important discussions like this ongoing session. Thank you very much, Mr. Chair. Thank you.

Ambassador Gafoor

Thank you very much, Ghana. Thank you also for sharing the outcome of the meeting in Accra and the Accra Call. I give the floor now to the Netherlands, followed by Czechia.

Netherlands

Netherlands, please. Thank you, Chair. In addition to our joint statement with Ghana that was just delivered by my Ghanaian colleague, please allow me to make a few additional points. The good thing is that I can borrow a few things from different colleagues now that we are quite late in the afternoon. Capacity building is a vital element of our work, ensuring all Member States can learn from each other, cooperate in the implementation of our agreements, and build a more resilient digital future. Before we dive into the question that you asked us, Chair, we would like to highlight the important link between capacity building and the other pillars of our work. In this regard, we would like to refer to the very useful report published by UNIDIR earlier in the summer on unpacking cyber capacity building needs. This work intends to identify the foundational cyber capabilities and how to strengthen the linkage between the agreed norms and capacity building. I won’t repeat the five pillars mentioned by my colleague from the UK, and I will just underline that the report provides an insightful initial review of how capacity building can support the implementation of the norms. Chair, your first guiding question under this agenda item is about effectively using CERT to CERT channels. Underpinning this effort is the need to ensure that all States have a national CERT. According to the ITU, there are currently 118 national CERTs worldwide, so there are still efforts to be done on this matter. Regarding your guiding question on the Global Cyber Security Cooperation Portal, we would like to thank India for their insightful presentation. I swear I didn’t borrow that one from Mauritius. We continue to be interested in this proposal and will bring back home what we heard this morning to better reflect on our continued engagement on this issue. As underlined by others before us, the Netherlands considers it might be useful to look at where we can start, making use of existing initiatives such as the GFCE Cyber Portal on Cyber Capacity Building and the UNIDIR Cyber Portal. Chair, on your question regarding the capacity building principle, the Netherlands attaches great value to the 11 Cyber Capacity Building Principles agreed by the previous Open-Ended Working Group and reaffirmed in our APRs. The guidance states, when engaging in capacity building efforts, in support of our efforts to mainstream the principle, the Chatham House Cyberspace for All project brings together experts from all regions to impact the principle and identify practical ways on how countries, organizers, and implementers can apply those capacity building principles within their national context. We hope these outcomes provide useful input into our discussion in the Open-Ended Working Group. One important element of the principle is that capacity building should be gender-sensitive, as we heard expressed by, among others, Sri Lanka, Bangladesh, and South Africa. We believe that our very own Open-Ended Working Group is a good example of the benefit of gender initiatives, as shown by the Women in Cyber Programme. There are some existing tools that look at how to include a gender perspective in digital policy. For example, in 2021, UNIDIR published some interesting ideas on gender consideration in the Open-Ended Working Group, which are still relevant today. It ranges from mainstreaming gender into the norm implementation to providing gender-sensitive capacity building and ensuring that bridging the gender digital divide is becoming a reality. Those are a great source of inspiration. But we also heard about good initiatives yesterday during our multistakeholder consultation, and in that respect, because we didn’t have so much time yesterday, I would like to thank the stakeholders who shared their views and experiences with us. As UNODA maps capacity building initiatives, the delegates would request if it could provide information as to whether these initiatives feature a gender perspective, supporting the idea of sharing best practices and also allowing us to address the gaps that are still remaining. Thank you very much, Chair. Thank you.

Ambassador Gafoor

Thank you very much, Netherlands. Czechia, you have the floor, please.

Czechia

Thank you for giving me the floor, Mr. Chair. For Czechia, cyber capacity building is an integral part of international cooperation. Sharing cyber security knowledge and expertise among countries increases the collective ability to defend ourselves against ICT threats and strengthen global cyber resilience. In the past, Czechia repeatedly advocated that in regards to cyber capacity building, an effective coordination body under the UN auspices is needed. Czechia supports the idea that the UN and OEWG in particular could promote better understanding of the needs of developing states with the aim of closing the technological gap and facilitating access by states to capacity building programs. Czechia also believes that stakeholders and public-private partnerships have an irreplaceable role in cyber capacity building. The UN, as well as OEWG, should work with relevant stakeholders and practitioners to exchange best practices on cyber capacity building. Czechia appreciates that the UN Secretariat has undergone a mapping exercise to gain an overall knowledge of all cyber capacity building initiatives. That is, in our view, a great step towards tailoring the projects to the beneficiary needs. It also helps to answer one of your questions, Mr. Chair, on the foundational capacities required for states. There is no universal answer since every country has a different local context; thus, it is vital to communicate and address the rising challenges individually. In our paper submitted to the UNODA, we mention some of the existing platforms that are used for cyber capacity building purposes and that we have experience with, inter alia, European Union Cybernet, UNIDIR Cyber Policy Portal, and GFCE Cybil Portal. We believe that our discussions within the OEWG regarding cyber capacity building should draw on their experience. For example, on GFCE, we appreciate its effort to avoid duplications by strengthening the collaboration with other cyber capacity building platforms, including the mentioned UNIDIR Cyber Policy Portal. We also welcome, for example, that GFCE is increasing efforts in the Africa region and opening the GFCE Africa hub on the outcomes from collaboration between GFCE and the African Union. Speaking about GFCE, Czechia also wishes to note that we joined the Accra Call for Cyber Resilience Development, which is the outcome document adopted at the Global Conference on Cyber Capacity Building in Ghana. We also listened with great interest to a very elaborate proposal of India regarding the Global Cyber Security Cooperation Portal. We believe it moves our common effort further forward. In accordance with our general position, we appreciate the intention of our Indian colleagues that this initiative should not duplicate but rather find synergies with other initiatives. As for future development, Czechia believes that the Program of Action would be an ideal platform for the exchange of views and ideas on cyber capacity building. From our point of view, we now, as a working group, have a unique chance when setting up the POA as a new institutional framework to incorporate from the very beginning such mechanisms into it, which will guarantee the effective functioning and financing of cyber capacity building projects. I thank you very much.

Ambassador Gafoor

Thank you very much, Mr. Chair. Thank you very much. The check here is just a little past six o’clock, so we would have to stop here. I have about, in fact, I have 17 delegations who wish to speak on capacity building. We will hear all of them tomorrow when we resume, starting with Antigua and Barbuda, to be followed by the Philippines. So I wish you all a pleasant evening and see you tomorrow morning. The meeting is adjourned.

Leave a Reply

Your email address will not be published. Required fields are marked *