Session 6-9 Transcript
(OEWG 2021-25)

Home » Resources » UN Open-ended Working Group (OEWG) transcripts » Session 6-9 Transcript(OEWG 2021-25)
Ambassador Gafoor

It is now called to order. Distinguished Delegates, we will continue our consideration of Agenda Item 5 on the topic of capacity building. And as I indicated yesterday, we have about 17 delegations which have asked for the floor. And the fact that we have had so many speakers wanting to speak on capacity building is a very good indication of the interest and level of commitment within the Working Group to discussing this issue. And given the fact that we have all recognized that capacity building is cross-cutting, it touches all the pillars of the mandate of the Working Group, and given that it is itself a CBM, it is a good sign that so many of you are wanting to express your views. Therefore, I propose that we continue with the list of speakers. I would, of course, encourage delegations which are able to summarize their presentations, if possible, to do so, on the understanding that they could give me their full statement to the Chair as well as to the Secretariat, so that we can look at it very carefully. But I do not intend to stifle the discussion, because this is a very important discussion, a very foundational discussion, and a very strategic discussion, because capacity building underpins every aspect of the mandate. And it will be helpful to our process in every pillar of the mandate if we have a good discussion here and if we have a clear sense of how we can find additional convergence and how we can move and how we can act with regard to capacity building. So, with those preliminary comments, I give the floor now to Antigua and Barbuda, followed by the Philippines. Antigua, please.

Antigua and Barbuda

Thank you, Chair. Mr. Chair, the State of Antigua and Barbuda is pleased to make our intervention in the area of capacity building. Since it is our first time taking the floor, Chair, on behalf of my delegation, I would like to extend our support to you and thank you and your team for your tireless work, and to also thank our colleagues for what has been an informative session so far. Chair, as indicated in the second APR, capacity building should be state-tailored, taking into consideration the local context. Capacity building cannot be a one-size-fits-all; it should rather be based on the identification of the specific needs of the state, including maturity and digitalization, prioritizing the needs of the recipient party and strengthening areas of partnership with the donor party. Chair, in response to your guiding questions, Antigua and Barbuda, as a small island developing state, views technical expertise, incident response capability to include simulated practical exercises, especially geared towards response to attacks on critical infrastructures, and recognizing the establishment of CSIRTs as foundational capacities required for states to detect, defend against, or respond to malicious ICT activities. We are of the firm view that starting with these critical baseline setting activities, small islands like Antigua and Barbuda will be much better able to protect our critical infrastructure and in turn effectively contribute to institutional dialogue and transboundary threat detection. Chair, you ask what role can the UN perform in the provision, coordination, or facilitation of capacity building efforts in a manner that complements existing initiatives. Antigua and Barbuda believe that the UN is best suited to coordinate capacity building on a global scale to ensure that no state is left behind, recognizing the natural linkages to the SDGs for many. We are quite cognizant that we are all at very different starting points, but a key priority should be to build cyber resilience while maintaining sovereignty and establishing a baseline capacity for every state to at least have some level of cyber response and resilience. After all, in the quest to have an open, peaceful, and secure cyberspace, we are as strong as our weakest state. We recognize and appreciate the efforts of the OAS, Canada, CARICOM IMPACS, and their partners for their efforts at building capacity in areas such as the application of international law, international humanitarian law, cyber diplomacy, and CBMs. Finally, Chair, as one of the beneficiaries of the Women in Cyber Fellowship, please allow me to express profound gratitude to Canada, Australia, the UK, the USA, the Netherlands, and New Zealand for such an excellent confidence and capacity building measure. Thank you, Chair.

Ambassador Gafoor

Thank you very much, Nancy Guer and Barbuda, for your contribution. I give the floor now to the Philippines, to be followed by Singapore.

Philippines

Thank you, Mr. Chair. As this is our first time taking the floor, we would like to express our appreciation for your able leadership in this process. We thank you and your team for the efforts towards achieving meaningful results for this shared endeavor. The Philippines is bolstering cyber security with a comprehensive five-year plan that outlines our strategy in combating potential malicious cyber activities. The National Cyber Security Plan 2023-2028 was unveiled at the 2023 Philippine Critical Information Infrastructure Protection Summit, hosted by the Department of Information and Communications Technology in Manila in October this year. The plan has a renewed focus on the importance of enhancing international cooperation in cyber defense capacities. It empowers sectors to fortify the resilience of critical information infrastructures and offers a gateway to government support in the event of cyber security incidents. At the recent 8th ASEAN Ministerial Conference on Cyber Security, which Singapore hosted in October 2023, the DICT stressed the significance of international collaboration in augmenting these cyber security efforts, which includes capacity building efforts to nurture the local cyber security talent pool and the introduction of tools to secure government online assets, alongside bolstering the capabilities of the National Computer Emergency Response Team, or the NCERT. Mr. Chair, capacity building is key to fostering a more secure digital landscape. With regard to the important guiding questions posed by the Chair, we welcome cooperation on building foundational capacities required for states to detect, defend against, or respond to malicious ICT activities. National-level mapping of such needs would be valuable. In connection with the proposal for a global cyber security cooperation portal as a one-stop-shop tool for states developed under the auspices of the UN, we would like to thank India for its detailed and insightful presentation on a global cyber security portal. Such a presentation provides useful content for interested states to continue the discourse. We also appreciate the Secretariat’s mapping exercise to survey capacity building programs and initiatives within and outside the United Nations and at the global and regional levels. As such, we share the views earlier articulated by Bangladesh and Malaysia. We believe that the mapping exercise and capacity assessment, including the National Survey of Implementation of UN Recommendations on Responsible Use of ICTs by States in the Context of International Security, is critical. Providing a holistic and global menu of both available capacity assessment tools and capacity building programs could be the first step to the implementation of national capacity building programs. The Philippines is therefore keen on exploring building a matrix of such capacity building needs and capacity assessment programs, which at inception could carry the list of existing assessment programs and capacity building providers. The matrix could provide member states with a bird’s-eye view of the needs, including how to assess one’s status compared with industry benchmarks and existing programs available matching the needs of a member state. The Philippines joins similarly situated countries that prioritize capacity building programs and the transfer of technology. However, to be an informed consumer of these programs, we need a starting point, and that proposed matrix could serve as a starting point for such a needs-based approach when availing of capacity building programs. In the alternative, the proposed matrix could also serve as an inventory of capacity building programs and could indicate where the gaps are in terms of support. To socialize this needs-based approach to capacity building, we would invite capacity assessment providers to discuss how existing assessment programs are currently being implemented, where they have succeeded, and how an interested delegation may avail of them. The roundtable discussion on capacity building in May next year could provide that opportunity for this dialogue with assessment program providers. If the proposal on a needs-based approach to capacity building gains traction, then the Philippines will stand ready to work with interested delegations to develop this idea further. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you very much, Philippines, for your statement. Singapore to be followed by Switzerland.

Singapore

Thank you, Mr. Chair. As already highlighted, capacity building is crucial in supporting states in implementing elements of the other pillars of our work in the OEWG. Our experience has been that for capacity building to be effective, it must be built on an interdisciplinary foundation of policy, operational, technical, legal, and diplomatic training. Mr. Chair, capacity building is a two-way street, and deliberately building in peer learning opportunities within capacity building programs will ensure that our interactions and feedback from partners can be a mutually beneficial experience for all. In terms of capacity building, we know that there is a strong appetite for training in areas such as international law and cyberspace, setting up of national CSIRTs, and security operation centers. In terms of technical training, we see the protection of operational technologies and mitigation of ransomware attacks are areas of priority for many countries we work with. Singapore has been delivering multidisciplinary capacity building programs at our ASEAN-Singapore Cyber Security Centre of Excellence, with multistakeholder participation. We are prepared to do more. In October 2023, Singapore launched the Singapore Cyber Leadership and Alumni Programme, a three-tiered structured program at the foundation, executive, and advanced levels, to cater to participants at different stages of their cybersecurity journey. It is open to all countries and aims to equip participants with knowledge on cyber diplomacy concepts, international law and norms in cyberspace, as well as the operational and technical considerations of international cyber policy. It will also provide participants with a better understanding of the cybersecurity threat landscape and mitigation strategies. Finally, Mr. Chair, we would like to thank India for their presentation on the Global Cyber Security Cooperation Portal, and we will be studying it. Thank you, Chair.

Ambassador Gafoor

Thank you very much, Singapore. Switzerland to be followed by Estonia.

Switzerland

Thank you for your guiding questions. Narrowing the digital divide through tailored capacity building efforts remains a key priority for the international community in order to promote an open, free, and secure cyberspace. The second APR contains many valuable suggestions on how this Open-Ended Working Group can contribute to this cause. Promoting synergies and coordination between existing initiatives and programs like the GFCE or initiatives at the regional level and making better use of them, as well as a multistakeholder approach, seem particularly important to us. We thank the Indian delegation for the very substantial proposal for a global cybersecurity cooperation portal and agree with others that it merits further discussions. In doing so, we should examine the potential added value compared to existing portals like the GFCE portal or UNIDIR’s cyber policy portal and avoid duplication with such portals. Mr. Chair, establishing a national CSIRT or a national cybersecurity center which is embedded in trusted exchange with government and private sector partners nationally and internationally is fundamental in building the key capacities regarding detecting, defending, and responding to malicious ICT activities. Such capacities must also be vertically linked from a technical up to a decision-making level. In this regard, there already exist international and regional initiatives and platforms in the field of supporting cyber capacity building projects. The UK delegation made reference to the important work of the Forum of Incident Response and Security Teams, usually called FIRST, in this area. We therefore regret that one delegation has blocked FIRST’s participation in the work of the Open-Ended Working Group. Like other delegations, such as the US or Canada have mentioned, Switzerland considers capacity building in the area of international law to be very important. The development of national positions on the application of international law in cyberspace allows states to participate in substantive discussions here at the Open-Ended Working Group or workshops such as the ones organized by UNIDIR. Such substantive discussions in turn serve to build capacity, and we should therefore allow sufficient time for them. Yesterday we heard that Croatia is a major power in football. Switzerland is one of the countries that benefits greatly from Croatia’s capacity building in this area. We don’t have the same capacity here. What we have is more lawyers. Some would probably say too many. Around 50 lawyers work in the Directorate of International Law at the Federal Department of Foreign Affairs alone. Of course, they can’t all be specialized in the field of cyberspace. Maybe three or four deal with these questions more in depth. So one approach that we try to use is to leverage the specialized knowledge of the others in the respective areas such as human rights, international law, or general international law and to streamline the topics of cyberspace, digitalization, or emerging technologies throughout the entire directorate or other federal offices. Mr. Chair, the Swiss and other delegations mentioned the risks of malicious use of ICTs for international organizations on Monday. Cyber threats in general have grown in scale and complexity, which means that Swiss-based international organizations and NGOs are also affected. As many of these are politically exposed organizations, they may also be targets of cyber attacks. Switzerland, as a host country, strives to create optimal conditions in the digital space for international organizations and international NGOs based in Switzerland. The national cyber strategy also defines measures for boosting international Geneva’s cyber resilience. As one such concrete measure, the Federal Department of Foreign Affairs and the National Cyber Security Center of Switzerland held a cyber capacity and community building event in Geneva in cooperation with the Canton of Geneva and other partners on the 30th of November. This capacity building event was conducted in three parts. In the first part, led by the Cyber Peace Institute, the various cyber risks to which NGOs in international Geneva are exposed were presented and discussed. In the second part, the National Cyber Security Center took participants through a scenario-based cyber exercise involving real cyber incidents experienced in the context of humanitarian work. In the third part, there was a presentation of cybersecurity products and services provided by various partner organizations which are available to international organizations and NGOs in Switzerland. The event enabled participants to get to know each other better and to deal more effectively with risks to which their data is exposed. Finally, I would like to mention the Global Conference for Capacity Building that recently took place in Accra, Ghana. I would like to commend Ghana for hosting this successful conference. Switzerland will host the follow-up conference in 2025 and invites all states to endorse the Accra Call for Cyber Resilient Development and cooperate in its implementation. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you very much, Sussan, for your statement. Estonia, to be followed by Australia.

Estonia

Estonia underscores the fundamental value of capacity building as a prerequisite for achieving the goals and agreements set in the OEWG discussions. We support and continue to promote the use of the principles of capacity building adopted by the OEWG. We believe that States need to mainstream these principles in all capacity building efforts, including national, regional, and international formats and platforms. As a signatory of the ACRA call, Estonia supports global action to enhance cyber-resilience across international and national development agendas. Here we would like to thank Ghana and other partners for hosting and organizing the GC3B conference earlier. We underline the need to foster collaboration through public-private partnerships to collectively implement and promote capacity building initiatives, as well as to make sure that we avoid duplication by leveraging our expertise, resources, and initiatives. Estonia regards cyber-capacity building as a priority area in order to improve the overall resilience of countries against malicious cyber activities and allow the implementation of the agreements reached at the UN level. Capacity building is a key part of our national cybersecurity policy, which is why we remain committed and open to sharing our knowledge, experience, and expertise. In response to your guiding questions, Mr. Chair, Estonia would like to outline some of the foundational elements required for enhancing cybersecurity on a domestic level. Establishing a computer emergency response team plays a fundamental role in effectively detecting, defending against, and responding to malicious ICT activities. Equally, it is essential to put in place effective communication channels with the CSIRTs of other states. States would also benefit from developing robust cybersecurity capabilities, including advanced threat detection systems, effective incident response and crisis management plans, legal frameworks to address cyber threats, secure communication infrastructure, as well as international collaboration channels for information sharing, in order to develop a deeper understanding of the threats. Here, we would like to support Malaysia on the point of security by design, which we also find essential in designing and developing any technological solution. We also see that national strategies can help states to identify domestic roles and responsibilities, identify national priorities and challenges, build connections with other domestic policies, as well as map relevant international processes. All this should be done in close cooperation between the private and public sector through an inclusive multistakeholder approach. We see that the key question here is how to build trust on both national and international levels. The framework of responsible state behavior, as discussed here in the Open-Ended Working Group, has an important role in increasing trust between states. And the proposed UN point-of-contact directory is a positive step towards enhancing international collaboration. Additionally, there is a need for continuous contributions to conduct awareness-raising campaigns and conduct trainings for cybersecurity professionals in order to keep up with evolving cyber threats. We would like to thank India for the comprehensive presentation yesterday about the Global Cyber Security Cooperation Portal. We see that there could be an added value in developing such a one-stop shop. We will study the presented details and are happy to continue discussions on how to ensure that the portal is synergized with other existing portals and mappings. Together with many others, Estonia is a firm believer in gender inclusivity. We work diligently to ensure gender inclusivity in all of our capacity-building efforts. In this regard, the Open-Ended Working Group could discuss how to advance and implement the capacity-building principles with a dedicated section on ensuring gender balance that states could refer to while planning their capacity-building efforts. Finally, Estonia believes that the Program of Action could become an important mechanism for promoting responsible state behavior in cyberspace in an action-oriented manner, based on a multistakeholder approach and supported by capacity-building mechanisms. Estonia sees the potential in the POA to support a pragmatic approach to coordinating capacity-building efforts and meeting capacity-building needs of all countries over the world. International capacity-building is a topic of great importance and key for the implementation of the framework of responsible state behavior, such as international law, norms, and confidence-building measures. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Estonia. Australia, to be followed by the Syrian Arab Republic.

Australia

Thank you very much, Chair. Australia is incredibly encouraged by the very fulsome and substantive discussion thus far under this crucial pillar of our framework. We’re fully supportive of coordinated and targeted capacity building as essential for our individual and collective ability to address the multifaceted known and unknown cyber threats that face the global community today but also into our future. This is why Australia places great importance on strengthening regional cyber resilience. Australia is practicing what we preach by focusing on regional capacity building as part of its recently released 2023 cyber security strategy. In the interest of time, I won’t go into great detail but will upload a full statement setting out a refocus under this strategy upon enabling our neighbors to better prevent cyber incidents and recover quickly when they occur, and establishing a regional crisis response team which draws on the expertise from government, industry, and the technical community to help contain the spread of cyber incidents and restore critical services and infrastructure in response to requests for assistance. It also focuses on partnerships with the private sector to increase connectivity across the Pacific through building subsea cable systems and ensures countries in the Indo-Pacific region can have access to more secure products and services and don’t have to compromise between digital development and security. As always, it continues to consider gender equality, disability, and social inclusion in all that we do. Australia was also very pleased to attend the inaugural GC3B conference, and we extend our thanks to Ghana for hosting this very inclusive and successful global conference on cyber capacity building. We are pleased to provide input to the UNODA capacity building mapping exercise as agreed in our 2023 annual progress report and look forward to working in this group on the results of that exercise and using that as an evidence base for our work into next year. We want to highlight the value of the practicality of the Program of Action in advancing cyber capacity building for effective implementation of the framework, and we hope that this OEWG’s dedicated intersessional meeting on the POA can provide an opportunity to discuss this in detail, particularly on how the POA will incorporate targeted and coordinated capacity building. Chair, you asked us a question on gender mainstreaming in capacity building. I spoke in a lot of detail on this in March, so in the interest of time, I won’t repeat myself, but I will put it in our written statement. Finally, I wanted to thank India for their presentation yesterday on the portal proposal. We found this contains a lot of really innovative ideas, and the details provided in that proposal were incredibly helpful, and Australia hopes we can have constructive discussions about that proposal in this forum. We note that the rationale for the portal includes that accessing multiple platforms and tracking different portals can become excessively time-consuming for small delegations and developing countries. I think this applies to all countries. Finding up-to-date, comprehensive, and accurate information is a challenge for everyone in the digital age. We would encourage care to ensure that the creation of something new doesn’t unintentionally compound this issue when we do have existing portals such as the GFCE civil portal and UNIDIR’s cyber policy portal, which do already perform several of the functions in this proposal. Because I’m afraid we have seen instances in the past where, in an effort to consolidate, say, six competing mechanisms, a new universal mechanism is proposed with the unfortunate eventual result of seven competing mechanisms. Australia’s fundamental interest is to avoid this pitfall. I don’t want to sound unenthusiastic; we see some really valuable ideas in this proposal. We really like the incremental approach to developing content, the search functionality that’s proposed in the structure so that we would allow users to search the content of all documents in the database as opposed to just titles, which is what exists now in some of the databases I mentioned. We like the centralized calendar of conferences all together. We think this would be a very useful tool, and we very much welcome the inclusion of stakeholders being able to contribute specific modules to the portal. Overall, we see this proposal as one that merits much detailed discussion and refinement here. We’d be supportive of engaging in further focused discussions on this proposal over the course of our upcoming meetings, and we also find appealing the proposal by some delegations yesterday that this might prove a good candidate for establishment within a body with a longer time frame like the POA, given how long it takes and how many resources it takes to set up something of this complexity technically. Thank you, Chair.

Ambassador Gafoor

Thank you, Australia. Syrian Arab Republic, to be followed by the Republic of Korea.

Syrian Arab Republic

Thank you, Mr. Chair. With regards to capacity building, we would like to emphasize the following. We emphasize the importance of all states, especially developing states, enjoying access to products and services related to ICT in order to bridge the digital gap. We support the suggestion to build a permanent mechanism for capacity building and providing technical assistance to developing states on a basis that is fair and non-politicized and in a manner that enhances these states’ ability to uncover nefarious uses of ICT and respond accordingly. We also emphasize that any restrictive measures go counter to enhancing ICT technology and undermine technology transfer and international cooperation. This cannot be in line with any credible and effective capacity building efforts. This is especially in light of the continued restrictions forced by unilateral coercive measures. Therefore, the negative impacts of such restrictions should not be undermined, and it must be emphasized that these measures must be lifted. We also emphasize that inclusive multidisciplinary institutional methodologies aiming to enhance training and research in the states receiving assistance and the development of their expertise in terms of ICT in the context of international security, with keenness on the specific needs and features of each recipient state, is equally important. We also emphasize the need for contributions and expertise that can be provided by non-governmental entities, including the academic sector and the private sector, to be consistent with standing national legal frameworks and the specific needs of recipient countries. We also emphasize the importance of recommendations calling for tangible and applicable steps through the mapping of capacity building needs and the goals that need to be achieved. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you very much. Syria, Republic of Korea, followed by Colombia.

South Korea

Thank you, Chair. My delegation would like to highlight the importance of capacity building as it is a cross-cutting issue in promoting an open, secure, and peaceful ICT environment. Korea is carrying out various capacity building initiatives such as the ASEAN Cyber Shield to foster ICT security professionals, training for the CSIRTs in the Asia-Pacific region, and operating the Asia-Pacific Cybercrime Capacity Building Hub to address cybercrimes. We submitted the list of capacity building initiatives to the UN ODA for the mapping exercise. Regarding the global cybersecurity cooperation portal, we appreciate India for making a very interesting presentation with concrete ideas and detailed explanation. My delegation views that the portal will help countries easily access the entire list of cooperation programs and looks forward to having further discussions on this. Nevertheless, we need to minimize the additional financial burden and ensure that existing tools such as the UNIDIR Cyber Policy Portal are integrated into a single platform. Bearing in mind the limited resources to address the ever-growing need for cybersecurity capacity building, my delegation would like to highlight that capacity building programs and their resources are allocated and distributed throughout different regions and areas in an efficient manner without making duplications. To this end, it requires transparent and up-to-date information sharing among states and stakeholders, and in this respect, we welcome the mapping exercise and surveys conducted by the UN ODA. We look forward to hearing the findings of the mapping exercise at the next substantive session of the OEWG. I thank you.

Ambassador Gafoor

Thank you very much, Colombia, to be followed by Chile.

Colombia

Thank you, Chair. The Delegation of Colombia welcomes the statement by Argentina on behalf of a group of Latin American countries on capacity building and reiterates the importance of this subject. We also welcome the statement made by the Delegation of India on the Global Cybersecurity Cooperation Portal, on which are some of the foundational capacities required by states to respond to malicious activities with ICTs. Together with Uruguay, the Netherlands, and the UK, we recognize the document by UNIDIR on the fundamental capacities and support of states within the framework of the use of ICTs and to defend against malicious activity. I would now like to mention some of the foundational capacities mentioned in the document with which we agree. It is important to have a national CIRT as well as a detection center. The points of contact, the classification of incidents, cooperation, and multilateral cooperation for the exchange of information and the importance of exchanges among interested parties and stakeholders. Mr. Chair, with regard to the proposal to develop tools which may assist states in incorporating gender issues in capacity building, we refer to the report on inclusive policymaking, the purpose of which is to increase awareness of the need for development and implementation of inclusive norms and opportunities which offer guidance. We also reiterate the need to incorporate a gender perspective in addressing ICT threats and the specific challenges met by vulnerable people. We refer to the Charisma Foundation’s work in Colombia and its research on the differential impacts which derive from cyber incidents in the health system. The preliminary information was submitted in yesterday’s meeting. Lastly, with regard to the question of the additional role that could be played by the United Nations in providing, coordinating, or facilitating capacity building efforts, we believe that it will be essential to have the conclusions of the mapping exercise, in particular where there is convergence among various topics. Once we can ascertain supply and demand, we can avoid duplication of efforts and undertake greater efforts. In the report by Colombia on the mapping exercise, we refer to technical capacity and legislative and operational support, and we mention some initiatives which have benefited Colombia, in particular the following: the support of the US government for the building of the plan of action of the response office in Colombia, the relationship between the military forces of Colombia and the US program, the cooperation of the government of Estonia with regard to the webinar on cyber crimes and the digital system in Colombia, with the participation of more than 140 Colombian diplomats, closing gaps on cyber security together with the Inter-American Development Bank, and the recent mission on cyber security and artificial intelligence organized by the government of Chequia, with inter-institutional participation. We believe that these initiatives are important because they will have a positive impact on international peace and security. Thank you.

Ambassador Gafoor

Thank you very much, Colombia. Chile, to be followed by Vanuatu.

Chile

Thank you, Chair, and good morning to all and to all here. Chile aligns with the statement by Argentina on behalf of a group of Latin American countries, and I will add a few comments in our national capacity. We’d like to begin our statement by thanking India for its proposal. It is a concrete example for a potential establishment of this portal. We will view with interest these concepts, and we’ll make contributions. For our country, capacity building is an urgent strategic topic, and it’s a fundamental pillar and a critical element when making progress and implementing the framework for responsible state behavior in cyberspace. This is essential for our countries to build an open, secure, peaceful cyberspace. We reiterate our support for the recommendations on international cooperation and capacity building, which have been mentioned in the consensus reports of the Groups of Governmental Experts and in the OEWG as well as in the APRs. We think it important to highlight the role of regional organizations and their capacity building programs, which are essential to generate a more accurate view of the needs of states. Once again, we wish to highlight the important work done by our region with the program of the Organization of American States, SICTE. This program has been working for years on various lines of work and training courses, which have helped our countries improve their national capacities and be able to present as a region a joint statement on this point. We also wish to highlight the contribution made by non-governmental stakeholders, such as the private sector, civil society, academia, the technical community, among others. This is essential to have training programs which are holistic and to analyze the needs of states. With regard to your first question, we think that it is necessary to have constant training programs on new threats and new attack vectors, considering the rapid evolution of technology and its use. Exchanging information is key in this regard to know the anatomy of an attack or malicious activity. To know this in advance can be vital in order to deploy measures to mitigate a future attack. As we have previously stated, training on cyber intelligence can be essential in this regard. With thorough training of this kind together with practical exercises and operational exercises, we can offer concepts on sovereignty and other legal concepts, as well as operational concepts on how, when states can act and when they can engage in self-defense. Simulation exercises, bilateral and multilateral, can also help improve the capacities of states. In that regard, the CERT channels can be very useful. And also CCERT of the OAS is an important program. With regard to the importance of considering a gender perspective, and in order to incorporate in a cross-cutting manner in developing training capabilities and capacity development, the states can follow the peace and security agenda, the sustainable agenda, and reports and resolutions of the Human Rights Council, among others. As other delegations have said, we refer to Women in Cyber Fellows, the purpose of which is to address the need for greater representation of women in United Nations negotiations on cyberspace. The program intends to develop more capacities, offering training, this sponsored by Australia, Canada, Netherlands, New Zealand, the UK, and the US. We thank them for their constant support, which has made it possible to develop a critical mass of women experienced in cyber security and more parity participation in meetings of this group. Also, the UN can facilitate coordination of capacity building efforts, especially with regard to information available on those efforts. In this regard, we could make progress in coordination with other initiatives to generate viable plans and strategies on cooperation, assistance, and capacity building. Also, we should include all stakeholders in order to build bridges and a more comprehensive and effective approach. From the viewpoint of common but differentiated responsibilities, the points of contact in the future could help in coordination and cooperation. Mr. Chair, today there are a large number of global initiatives, and some of these have been playing an important role, such as the Global Forum on Cyber Expertise and the recent launch of African for Cyber Resilience Development. It is also important to generate a global strategy to help to coordinate all of these efforts and to focus capacity building and the areas that need it the most. There are common needs, but there are also challenges which are unique and which respect the realities of each region or state. We should not leave anyone behind. Thank you.

Ambassador Gafoor

Thank you very much. Chile, Vanuatu, to be followed by Saudi Arabia.

Vanuatu

Good morning, Chair. Since this is the first time and only time for Vanuatu to intervene in this session, please allow me to offer you and the Secretariat our delegation’s full support and confidence, and to congratulate us all on these very substantial discussions this week. With respect to time, and with your indulgence, we will incorporate our views on capacity building and on the most pressing issues into this one intervention. Mr. Chair, ICTs have revolutionized the way we live, work, and communicate. Technology has become an integral part of our daily lives, and it is only natural that we harness the potential to safeguard our sovereign nations and cyberspace. On the flip side, Vanuatu sadly knows firsthand the damages and impacts of cyberattacks. In November 2022, the Republic of Vanuatu was targeted by a well-crafted, organized ransomware cyberattack that crippled our nation’s broadband network and impacted our ability to offer essential services to businesses and our people, communicate among government offices, as well as gain access to daily digital online services. Thanks to our experienced in-country experts and generous regional and international support, Vanuatu has now overcome the worst effects of the attack. We are now in an upgrade mode, lesson-learning, and lesson-sharing phase. Two lessons learned from the cyber incident. First was the fact that our defenses simply were not strong enough due to a lack of appropriate technology or skills. Thus, capacity building remains the single most important component and factor in building equity in cyberspace, as well as resilience to cyber threats. We will remain supportive of any efforts to strengthen and build upon existing and new capacity building work, which is in line with the Vanuatu National Cyber Security Strategy of 2023. Effective capacity building is also at the heart of every other area of discussion in this open-ended working group, from norms to international law. Secondly, a lesson learned from our experience is that regional and international collaboration is an integral part of our ability to deter, detect, investigate, and remediate cyberattacks. Cyber security does not work in a vacuum, and regional and international information sharing is a crucial part of our defensive measures. The government of Vanuatu is committed to better protecting our people from ransomware attacks in the future. As a result, Vanuatu has recently lodged its intent to join the International Counter-Ransomware Initiative. We look forward to working with the pillars and projects under the CRI. We would like to also share with colleagues the results of the first-ever Pacific ICT Ministers’ Dialogue in August 2023, where the highlight of the landmark event was the signing of the Lakatoy Declaration on Digital Transformation of the Pacific. The ministers recognized the significance of a united front in achieving their digital goals and deliberated on a range of pivotal ICT matters. Among the six priority areas, the Lakatoy Declaration highlighted the importance of enhanced cyber security measures. It also committed its member states to the aim of promoting capacity-building efforts that go beyond technical skills, fostering an understanding of how people’s behavior and cultural norms interact with technology. This commitment to cyber security, including a risk-averse approach to new technologies like AI or quantum computing, was also echoed in the final communique of the Pacific Islands Forum in November of this year. Vanuatu believes that adherence to the 11 established norms of state behavior, as well as a strong commitment to the principles of international law, including the UN Charter, being applicable in cyberspace, are at the heart of a peaceful, stable, and open cyberspace. Vanuatu is committed to building a cyberspace that is secure, free, and open, and one where accountability is built into the system.

Ambassador Gafoor

Thank you, Chair.

Saudi Arabia

Thank you, Mr. Chair. Saudi Arabia believes that capacity building is an extremely important issue, and effective work in this area could make a real difference. We have launched a number of initiatives in this regard. Specifically, we’ve supported the proposed international portal to merge various resources that already exist into a one-stop shop. We think this is very important and would be a major step forward in terms of exchanging good practices and assisting capacity building. My country is prepared to fully participate in such a cyber security portal, and we would contribute our own national portal that already exists and encompasses various aspects of cyber security. This portal addresses the situation in the various regions of the country. We believe that local, national, regional, and global levels should be reflected in a portal that would be truly effective in exchanging expertise, promoting good practices, and ensuring the security of cyberspace. Thank you very much, Mr. Chair.

Ambassador Gafoor

Thank you, Saudi Arabia. Qatar, to be followed by Ukraine.

Qatar

Mr. Chair, we would like to reiterate our gratitude to you for the excellent conduct of this session. With regard to capacity building, everyone knows that many countries have to deal with a lack of competent resources, including human resources in this area. Capacity building is a confidence-building measure in itself, and it’s essential if we are to promote efficiency and confidence in this domain. We have worked with a number of countries; specifically, we joined forces with the UK in organizing a roundtable of experts under the general auspices of the UN and specifically the Open-Ended Working Group (OEWG). We believe in promoting the exchange of information with the greatest transparency, and countering security issues in cyberspace is something that states can do if they join forces. Chair, let me also mention an aspect of capacity building, which has been the subject of broad and far-reaching discussions, that is, the relationship between the project to create a global portal and the existing national and regional portals in this regard. My country will participate in the international project, but we should be careful not to duplicate efforts and incorporate existing portals rather than work parallel to what is already being done. We have also launched a considerable effort in terms of awareness-raising in our country, working with teenagers and young people, particularly in secondary schools, and this has already yielded positive results. We have updated our methodology and are willing to participate in the creation of a global point of contact directory, which would be a long-term tool for all of us. Our work in this regard will continue, and we appreciate the fact that it has been put on the agenda of this session of the Open-Ended Working Group (OEWG). Thank you for your attention.

Ambassador Gafoor

Thank you, Qatar. Ukraine, to be followed by Costa Rica.

Ukraine

Thank you, Mr. Chair. Mr. Chair, Ukraine aligns itself with the EU statement delivered earlier today. We would also like to make a statement in our national capacity. In the conditions of the rapid development of information and communication technologies, it is essential to develop effective approaches that will ensure the cyber-resilience of information systems. The basis of this is modern legislation, international cooperation, and public-private partnership within the country, as well as developed technological infrastructure. The war of Russia against Ukrainian cyberspace highlighted the importance of international cooperation in preventing and repelling cyber-attacks. We strongly believe that countries should share information between themselves and work together to develop new means of protecting their IT systems. This is especially relevant in the case of cyber-attacks on critical infrastructure, such as power grids and water systems. Ukraine’s experience in the field of cyber security demonstrates that cooperation between government and business is crucial, because an attack on government resources can have a spillover effect and spread to a business, while the intrusion into a private company’s data systems can pose a serious threat to government agencies and the software of that company. Since February 2022, most of Ukraine’s top cyber security experts have joined the state’s special communications service team and other state bodies to strengthen the country’s cyber-resilience. In turn, the CERT-UA emergency response team in Ukraine provides free assistance on cyber security issues to any Ukrainian organization, including commercial. Mr. Chair, the international support in countering cyber-attacks against Ukraine is an important component of our success. Our partners provide us with a wide range of assistance, including technical assistance in the field of cyber security, in particular on detecting and repelling cyber-attacks, as well as in the field of critical infrastructure protection, and financial assistance to strengthen the cyber security of Ukraine. In particular, at the invitation of the U.S. government and taking into account the growth of cyber threats due to attacks with the U.S. ransomware, Ukraine joined the Global Counter-Ransomware Initiative, which was launched in October 2021 by the United States of America. In this regard, a working group was established in January 2022, which includes representatives of the Security Service of Ukraine, cyber police, state special communications, etc. The representatives of the Ukrainian cyber security community regularly participate in this initiative’s activities. In October 2022, for the first time, representatives of Ukrainian cyber security entities took part in trainings conducted by the EU Agency for Cyber Security, ENISA. In addition, in 2022 and 2023, 27 meetings of the National Cyber Security Cluster were held, a platform for discussing challenging issues in the field of cyber security and uniting representatives of Ukrainian cyber security entities and international partners from the EU countries, the USA, and Japan. Based on the results of the cluster’s work, a number of grant programs were implemented in 2022-2023 to strengthen the cyber protection of state bodies and critical infrastructure facilities. In 2023, with the assistance of the U.S. Civilian Research and Development Fund, CRDF Global, the NCCC launched a new initiative, the National Information Resilience Cluster, the fight against disinformation public-private partnership in the context of cyber-war. Based on the results of the work of the clusters, a number of projects are being implemented in the field of international technical assistance for entities providing cyber security of Ukraine from international donors. In November 2023, Ukraine signed a working arrangement with the European Union Agency for Cyber Security focused around capacity building, exchange of best practices, and boosting situational awareness. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you very much, Ukraine. Costa Rica, please.

Costa Rica

Thank you, Chair. As we have stated already, Costa Rica launched its cyber security strategy 2023-2027 almost a month ago. The strategy has four strategic objectives, one of which is devoted to strengthening the capacities in the cyber security ecosystem. The objectives here show the concrete needs that countries face in terms of capacity development and that can be of use in this discussion. I’d like to mention a few elements. One, the capacities which are needed are for all of society. We have identified the need for education and training at all levels of the educational system. In like manner, we intend to develop national awareness campaigns on the overall management of cyber security risks, as well as tools, videos, tutorials, and online education, which allow our citizens to acquire cyber security competencies. This also includes a cyber health program and responsible use of technology. Number two, we also need to promote the establishment of a specialized labor force in the private as well as in the public sector. In this regard, we’d like to mention the development of a cyber security labor force given the needs of the labor markets and trends in cyber security. Also, to promote diversity, gender equality, and social inclusion. It would also include developing capacities for certain groups, for example, professionals and high officials in public institutions or individuals in leadership roles in private entities with an emphasis on micro, medium, and small enterprises. Number three, we have also identified needs on specialized topics. For example, in the case of professionals who protect national critical infrastructure and essential operators. One case I would like to mention is that a priority has been given to training professionals within law enforcement entities, including a victim-oriented approach in areas such as cyber harassment, abuse, and sexual exploitation. Mr. Chair, Costa Rica agrees with delegations that have highlighted the importance of incorporating a gender-sensitive approach and capacity building. Our new national strategy also refers to this point in promoting a consideration of gender aspects and diversity and an active and effective participation of women in international debates on international security, including the cyber component and state efforts in implementation of Resolution 1325 of the Security Council. As long as women do not yet participate fully in all activities, we will be losing half of the population that could develop this sector. We urge all delegations to continue to work to this end. Thank you.

Ambassador Gafoor

Thank you very much, Costa Rica, for your contribution. I’ll now take comments from three others who have wanted to speak, UN entities and international organizations. We’ll start with OSCE, Interpol, and then UNIDO. OSCE, please.

OSCE

Thank you, Chair. Good morning, colleagues. In line with the second annual progress report, stating states in a position to do so are invited to continue to support capacity-building programs, including in collaboration where appropriate with regional and sub-regional organizations, I would like to share some capacity-building activities carried out recently within the OSCE, and also relevant for the implementation of the Framework of Responsible State Behavior in Cyberspace. OSCE CBM No. 15 deals with critical infrastructure protection, which includes the promotion of the use of national cyber incident classification systems. The objective of the relevant OSCE project, funded by France and Germany, is to increase states’ capacities to deal with significant cyber ICT incidents in an effective way. As part of these efforts, the OSCE Secretariat conducted a workshop this September in Tashkent, Uzbekistan. The event was attended by representatives of Armenia, Azerbaijan, Georgia, Kazakhstan, Kyrgyzstan, Mongolia, Tajikistan, and Uzbekistan. The workshop built on the good practice report titled Cyber Incident Classification, a report on emerging practices within the OSCE region, and was facilitated by experts from Czechia, France, Kazakhstan, and Switzerland. The participants, together with the contribution by the experts, exchanged good practices and discussed recommendations and challenges on implementing these systems, especially in their specific regional context. The workshop was another good example of how open and transparent engagement between cyber experts can build capacities, trust, and partnership. The sharing of information on vulnerabilities has been mentioned by many delegations this week. CBM No. 16 covers this issue within the OSCE. Four OSCE participating states, namely Czechia, Hungary, the Netherlands, and Romania, engage under the Adopt-a-CBM initiative by developing implementation modalities for that specific CBM. This September, we organized a workshop in Istanbul, Turkey, for participating states of the OSCE subregions of Eastern and Southeastern Europe, Central Asia, South Caucasus, as well as Mongolia, with the aim to discuss coordinated vulnerability disclosure as a keystone of a comprehensive approach to national and regional cybersecurity. The event provided a platform for the exchange of good practices and examples of national coordinated vulnerability disclosure policies. Most notably, it was organized in cooperation with the Dutch National Cybersecurity Center and the Public Prosecutor’s Office, who had a practical exercise on the second day of the event, which further created understanding about the nuances of vulnerability disclosure. Based on the feedback received from the participants, the workshop contributed to their understanding of the CVD process, as well as the importance of defining national ICT vulnerability sharing processes. Besides implementing CBMs, the OSCE Secretariat also aims to raise awareness on the UN framework of responsible state behavior in cyberspace and cyber diplomacy in general, with the aim to create better understanding of the global processes and enable participating states to engage in international cyber policy deliberations, both at the OSCE Informal Working Group, as well as the UN Open-Ended Working Group. The training held in Vienna this November gathered 21 delegates from Eastern and Southeastern Europe, Central Asia, South Caucasus, and Mongolia, and provided them with opportunities to exchange views with renowned cyber practitioners and diplomats closely involved in these processes. During the event, cyber diplomacy practitioners shared their experiences related to cyber diplomacy, covered past and present UN cybersecurity policy processes, with a specific focus on the framework. I would like to again express my gratitude to Catherine Priesman, who accepted our invitation to speak at the training and shared the most recent developments on the work of the OEWG. And on a very personal note, I have to say I’m very impressed that Catherine did that at 5 a.m. in the morning, so her commitment is really fantastic. Further, the training event also engaged participants in a practical exercise on coordinating national cybersecurity positions, and prompted participants to share information on their national organization pertaining to cyber ICT security. Participants also elaborated on some of the obstacles they face in engaging in international cyber deliberations, which provided valuable insight into future capacity-building needs, which the OSCE Secretariat will aim to address in upcoming training events. Thank you very much.

Ambassador Gafoor

Thank you, OSCE, for sharing your activities. Can I give the floor now to INTERPOL?

Interpol

Mr. Chair, Interpol thanks you for the opportunity to engage with the Open-Ended Working Group and makes this statement in its capacity as a permanent observer to the United Nations. Interpol’s constitutional aim is to ensure and promote the widest possible mutual assistance between all criminal police authorities within the limits of the laws existing in the different countries and in the spirit of a universal declaration of human rights, as well as to establish and develop all institutions likely to contribute effectively to the prevention and suppression of ordinary law crimes. In this vein, and given Interpol’s apolitical and neutral status, the organization’s mandate covers exclusively non-state threat actors. However, the support Interpol provides to its 196 member countries contributes substantially to the capabilities of its memberships and, by extension, their implementation of cyber norms and regulations. Colleagues, as we heard this week, cybercrime can constitute a national security threat to countries, which will continue to grow and indiscriminately harm communities, spreading instability for the foreseeable future. With a broad understanding of these cyber threats, Interpol’s dedicated cybercrime program assists member countries in the prevention, detection, investigation, and disruption of cybercrime to reduce the global impact of cybercrime and protect communities for a safer world. Interpol strives to facilitate closer collaboration between countries against cyber harms and emphasizes the importance of optimizing the use of existing mechanisms, platforms, and networks. Much of the work of the cybercrime program contributes to fostering confidence building and trust between law enforcement authorities in different countries. Additionally, Interpol’s apolitical nature allows it to act as a neutral interlocutor for technical exchanges between countries, oftentimes in spite of geopolitical differences that otherwise would have made such bilateral cooperation difficult. On capacity building measures, Interpol is actively engaged globally in capacity building and provides technical assistance to beneficiary national law enforcement agencies to equip them with the knowledge, skills, and best practices needed to meet today’s security challenges. The difference in member states’ level of cyber capabilities and capacities is stark and should not be overlooked. In this context, Interpol commends the Chair’s decision to hold a dedicated roundtable on capacity building next May, and we would be in a position to support, if permitted. Finally, Interpol believes that regular institutional dialogue and a concerted global approach to tackling cybercrime is paramount to ensuring any progress made is transformative and sustainable. Fragmentation of efforts goes hand in hand with the creation of detrimental silos and a duplication of work. In this regard, Interpol is actively involved across cyber-related processes at the United Nations and beyond, including the Ad Hoc Committee process to elaborate a comprehensive international convention on countering the use of ICTs for criminal purposes. Interpol views cyber as a key area of the wider UN development agenda and therefore actively participates in the preparation process towards a summit of the future and the global digital compact. To further align the law enforcement community with Agenda 2030 and the Sustainable Development Goals, Interpol has launched its own Global Policing Goals, or GPGs. GPG4 focuses on reducing the global harm and impact of cybercrime and directly relates to eight of the UN SDGs, reflecting the inherently cross-cutting and far-reaching effect of cyber. Colleagues, in conclusion, let us ensure that we do not focus on reinventing the wheel but grease and align the ones we have. Let us focus on creating synergies and, in the words of the United Nations Secretary-General, embark on a shared vision of digital cooperation. Interpol stands ready to provide its expertise and support to this endeavor within the remit of its mandate.

Ambassador Gafoor

Thank you very much Interpol. We certainly welcome your continued engagement in this process. I give floor now to the last speaker, UNIDIR.

UNIDIR

Thank you, Mr. Chair, for giving me the floor. I’m aware I’m the last speaker before the next agenda item, so I promise I’ll be quick. I would like to start by thanking you, Mr. Chair, and all delegations that in the past few days have shared words of appreciation and support for the scenario-based workshop we organized last month on international law. I just want to say in this regard that we have heard you, and we will be organizing more of these events, including to support knowledge and capacity building. We are ready to work with all of you to explore when, where, and how more of these workshops could be organized. These activities will be a great complement to our already planned increased efforts to support states in their implementation of the framework of responsible state behavior, particularly in relation to international law. We will be organizing dedicated training and in-country support that we will be offering as of 2024, thanks to the generous support of the United States. We will be sharing more information on these capacity building opportunities very soon. The second point I would like to make refers directly to your guiding question on foundational cyber capacities. In this regard, I would like to highlight a two-part study that we released earlier in the summer, just ahead of the July session. This study, that was also mentioned by some delegations yesterday, mapped foundational cyber capabilities recommended to successfully implement all elements of the framework. And the study, in its second part, was also the first of its kind, attempting to map how such foundational cyber capabilities could be leveraged to increase cyber resilience against some of the most commonly referred to threats within this group, including data attacks, such as ransomware, or supply chain attacks. Both parts of this study are accessible on UNIDIR’s website. Lastly, I would like to reflect on the several instances over the past few days in which we have heard how important it would be to have a one-stop shop to access information, for example, on existing national cybersecurity strategies or policies, agencies and departments, or existing cyber capacity building initiatives and projects. I would like to provide you all with three numbers: 1528, 55, and 897. 1528 is the number of policies, strategies, national positions, and statements currently accessible and searchable by content, not just by title, with just a few clicks through UNIDIR’s cyber policy portal. 55 is the number of languages of such documents, and 897 is the number of cyber capacity building projects currently accessible through our portal, thanks to a recent partnership with GFCE and the data exchange that we have finalized with their great Cybil portal. If you would like to know more about this latest addition, I invite you to join our side event at lunchtime. We will be providing lunch, although you have to be very fast in getting there because it tends to disappear relatively quickly. These numbers explain better than many words why the international ICT security community in the last four years, whether meeting as a GGE or OEWG, made sure to include explicit references in all outcome documents to how the cyber policy portal could be leveraged by states to access or share information. And we’re grateful that this OEWG recognized the portal as a global confidence building measure in the last APR. In addition, those states that would like to flag capacity building needs or opportunities on a portal managed by a UN entity, they can already do that today. Since March 2022, thanks to the generous support of Australia, UNIDIR Cyber Policy Portal also hosts the survey of national implementation, which includes a dedicated part to capacity building. You can leverage that part of the survey to identify and describe your needs or your offerings and make that information available and searchable on your national profile. This is to stress once more that there is still a lot of value that can be extracted today from existing tools, while this group discusses how to best take forward the proposal of creating a new portal which was so well articulated by India yesterday afternoon. Perhaps the issue is not a lack of adequate platforms, but limited awareness of how to best use the ones we already have. To be clear, UNIDIR Cyber Policy Portal is not perfect. Since its inception in 2018 and launch in 2019, we have continuously improved its functionalities and accessibility thanks to the generous support of our donors. We are on the right trajectory as 2023 represented a record-breaking year with more than 23,000 visits. We remain at full disposal of this group to identify specific features that are currently missing. Adding such missing features, like a non-public area reserved for states, to an already existing, tried, tested, and trusted platform will achieve the desired end goal at a fraction of time and costs compared to the financial, technical, and human resources necessary to build a new platform from the ground up. In practice, this means that you could have what you need, for example, a reserved area to exchange information on threats, already operational by the time you will be negotiating the adoption of the next APR, if you like. We have heard at the beginning of the week how all states are concerned by how fast the threat landscape is evolving. Perhaps building on already established and reliable tools would allow for a more timely response to such evolution. And allow me to conclude by informing you and all delegations that, building on the success of the 2023 edition, we are exploring the option of organizing our 2024 Cyber Stability Conference here in New York the Friday before the start of the next formal session of the OEWG in March. As you know, rooms here at the UN are a precious commodity, so we cannot confirm yet, but I wanted to take this opportunity to inform you all of our intentions so you can pencil this in your diaries. Thank you.

Ambassador Gafoor

Thank you very much, UNIDIR, for that comprehensive overview of what you’ve been doing, including your offer of lunch. We’ll make time for that so that delegations can go to that. Distinguished delegates, this has been a really intense but very, very meaningful discussion on capacity building, which started yesterday, and I wanted to share some observations – not a summary, certainly not exhaustive, but some reflections at this point – and then we’ll move on to the next topic. First, listening to the number of statements, I think we had more than maybe 60 statements, and given the length of the statements plus the level of preparation that had gone into these statements, it is very, very clear that there is a strong desire and a strong commitment to make progress on this issue. And I also have the sense that we are beginning to understand the strategic nature of capacity building, how it underpins every different pillar within this process, how it can potentially facilitate and catalyze movement with regard to so many other pillars, whether it’s in terms of building trust, whether it’s in terms of building confidence, whether it’s in terms of creating foundational capacities, building resilience. So it is truly a cross-cutting issue, and it’s certainly a CBM in itself. And I think the discussions yesterday and today demonstrate that this is understood and accepted by all, and I think that in itself is a very good foundation within capacity building, that we all have this common understanding of the value, the strategic value, and the importance of capacity building. Second, I think we should also keep in mind that capacity building should be seen as a process. If we say that it’s a CBM, then CBMs are also a process. Likewise, capacity building is a process, meaning that the exchange between countries, between partners, will have to be continuous, will have to be constant, and there is no final point where we can arrive and say, “I have absolute or perfect capacity, and no capacity building is needed any further.” So it’s a constant process of engagement, sharing, understanding, listening, helping, that we need to do. But because it’s a constant process, we can’t just say, “Let’s go on talking continuously and constantly.” We also need to show progress. And I said that yesterday, or rather at the beginning of the session, we can’t wait for progress, we can’t wait for demonstrable achievements, a sense that things are moving, because that is needed to build capacity, but also needed to build confidence. So let’s keep that in mind. We are not going to achieve everything we need to do with regard to capacity building by a certain deadline, but at the same time, we also cannot say, “Let’s do it later, let’s continue to talk.” I think we need to start acting even as we continue talking. That’s my second point. Third, I want to thank delegations for responding to the guiding questions. A lot of you gave your views on foundational capacities and also addressed the other questions, and I think that’s very useful that we had those responses well thought out, well prepared, and I was listening very carefully, and so are members of the team here on the podium. And I think there’s a clear sense that the foundational capacity is important. One of you referred to it as baseline capacities, and I was very struck by what Banu Watsu said: the single most important factor in building equity in cyberspace is capacity building. And I thought that’s worth reflecting about. We have been talking about cyber resilience, we have been talking about cyber security, but we also need to keep in mind that there is a digital divide out there. There are fundamental development challenges, and many of you also referred to the SDGs and Agenda 2030, etc. The question of how do we achieve that leveling to some extent of the playing field, how do we achieve that equity between nations in the area of cyber resilience, I think it’s a very important point to think about. So the core notion of foundational capacities, I think, is very important. And related to that, I think we also need to keep in mind that capacity building is very vast. It’s a vast area, I think some of you have also said that. And we are in the middle of a digital transformation, meaning the world is in the middle of a digital transformation. Nations individually are grappling with this digital transformation. The UN is talking about the digital divide in various committees in the context of sustainable development goals. There is a discussion on a global digital compact. And in the context of that digital transformation, building cyber resilience becomes even more important, because if digital technologies are an accelerator for sustainable development, then a lot of sustainable development will depend on having that cyber resilience. So it becomes very critical. But at the same time, in this working group, we cannot address everything digital. We cannot resolve all the challenges of digital transformation. We cannot resolve possibly all the challenges of the digital divide. I think we must, as a working group, with this clear mandate, be focused specifically to the aspects of cyber resilience in the context of international peace and security. And so that clear focus will help us achieve some concrete progress. Because if you try to focus on everything, we may end up not achieving anything. So even as it is important to understand the overall digital context, because cyber strategies do not exist in a vacuum, national cyber strategic plans do not exist in a vacuum. It exists in the context of the total digital transformation or total digital framework of a country. But at the same time, it is important that we must be focused. I think that’s the main point that I’d like you all to take away. Because it’s such a vast field that if we try to do everything in this working group, we will not be able to make very concrete progress. So I think, and that’s what I think we should aim to do, take very concrete, pragmatic steps forward each time we meet, or each annual progress must make forward momentum. Now, there was also a lot of reaction to India’s proposal. And I want to first of all thank India for making a very well-prepared presentation. And the discussion on the Global Cyber Security Cooperation Portal as a one-stop shop for states to be developed under the UN auspices is something that we had agreed last year. It’s part of the second APR. So in a sense, we have begun that discussion. I was also gratified to see that there were many of you who said that it merits further discussion. So we need that further discussion. And we will have, I will make time to allow that further discussion. There were also many of you who said that emphasize the point about synergy, emphasize the point about building and leveraging on existing structures and arrangements. And I think that too was a point that came up in the previous discussions we had in July and prior to that. So clearly the further discussion we need to have on the Global Cyber Security Cooperation Portal is something that will need to address very sharply the question of synergy. How do we build and leverage? How do we not duplicate what is already there so that if we decide to do something under UN auspices, the value added must be clear, the value added must be concrete and meaningful for all countries in the context of ICT security. So I think that’s the kind of further discussions we need to have. And here too, I think we need to keep in mind, in my view, an ecosystem approach. I think one of you used that phrase, maybe one or two of you used that phrase. There’s an ecosystem out there for capacity building. And we want that ecosystem to thrive so that collectively we are enriched in terms of obtaining the support we need. So likewise, if we are thinking of some kind of arrangement or mechanism, some of you also used the word a permanent mechanism at the United Nations for capacity building. Quite a number of you said that. So if you are thinking of some kind of mechanism or portal at the UN, under UN auspices, I think it’s important to think of it in terms of an ecosystem approach where we synergize, where we leverage, where we optimize the offerings that are available around the table. And many of you had already spoken about what you’re offering, not just delegations, but also UN entities. And not all UN entities are here. They are also international organizations. And let’s not forget the stakeholders. And that leads me to the point about stakeholders. I think it is absolutely fundamental that if you are talking about meaningful capacity building, we need to bring in the stakeholders in a big, big way. If we want to go big on capacity building, we need to bring in the stakeholders. And by stakeholders, I mean private sector. I mean non-governmental organizations. I mean foundations. It could be universities. It could be think tanks. It could be organizations like FIRST. It could be everyone seated at the back who perhaps haven’t spoken today. We need to think of stakeholders in a win-win way. And it is important that as a process, we have that engagement with stakeholders if we want to benefit from the offerings that others can bring to capacity building. And talking about offerings, I think quite a number of you also say capacity building is a two-way street. I think that’s fundamental. I think we should not get into this mindset that capacity building is donor-recipient. It is not one way, as one of you said. I think everyone can bring something to the table. Even the smallest country can bring something to the capacity building discussion. Because if we say capacity building is a confidence-building measure, then the challenges faced by a small country are going to be different from that faced by a larger country. A country with a population of a hundred thousand people, an island state for example, that’s going to be different as opposed to a country with a population of a hundred million people. So there are challenges that are going to be different and perhaps not understood by any other country in the world. So they have a contribution to make. So I think we should start from that perspective of every country being able to make a contribution. And that leads me to the capacity building principles that we have already adopted in the previous open-ended working group and that has now been endorsed and put as a framework or rather as an annex to the second annual progress report. And that gives a very, very good, it’s annex B, sorry, it’s annex C, agreed principles of capacity building. So the point about respecting human rights, respecting sovereignty, you know, demand-driven, politically neutral, everything is there. And I think the agreed principles of capacity building are intended to give comfort and assurance to everyone that capacity building must be done in a politically neutral way. I think quite a number of you also alluded to this. So I think even as we discuss how we take further steps in capacity building, I think it’s important to keep the agreed capacity building principles in mind. And I think gender mainstreaming is something that’s very, very important. I think if we want to make this a meaningful exercise, it has to be inclusive. And I think the Women in Cyber Fellowship Program, supported by several countries, which has enabled, you know, many countries to be represented here, shows the value of how mainstreaming gender also leads to collectively better outcomes. For example, within this process, we have certain countries who are represented who may not have otherwise been represented. And I think that is a net positive for our process. And also in the context of women, peace, and security, that’s a big issue around the world. The nature of conflicts are different. The nature of resolving conflicts or mediating conflicts are different. And the role of women in peace and security is important. And I think it’s important that even as we do capacity building, we should keep that in mind. The last point I want to make is with regard to the global roundtable and the mapping exercise. I think the mapping exercise, which we had asked for the report, will come in March, before the March session. So that will give us a landscape survey, will allow us to have that overview of where we are at this point in time, look at the ecosystem in a way, and then that hopefully will inform our discussion when we next get to this topic in March. And the other point, the final point, is about the global roundtable. I think many of you said they were looking forward to this global roundtable. So am I. In my view, the global roundtable gives us an opportunity to demonstrate to each other that we attach the greatest of seriousness to capacity building. And second, it gives us an opportunity to demonstrate that we are delivering on capacity building. And the global roundtable, which is to be convened under the auspices of the chair of the OEWG, in my thinking will be and should be a gathering of practitioners and decision-makers in the area of capacity building. It will include, I hope, all representatives from countries. And it is also my hope that countries will be represented at the level of decision-makers, as senior as possible, who can come here and articulate and reach out to representatives from other countries, engage in partnerships, engage in discussions, and senior officials and representatives who can come here and make things happen for capacity building. The global roundtable should also be a gathering of practitioners and stakeholders. People in this domain who can come and showcase what they are doing, showcase what they can offer, and be ready to form new partnerships. Yes, there is a lot that is already being done. But it should be a meeting place, the global roundtable in May, where there could be matching of needs, matching of potential offers and opportunities and demands. So there is a variety of options in terms of making the global roundtable a very important milestone in the OEWG. But most importantly, it will be an opportunity to demonstrate that we, as the OEWG, and we, as the United Nations, are doing something in the domain of capacity building. We are not waiting. We are doing something. We are starting to do more things. And of course, as I said, capacity building is a process, so it will never end. There will be more things to do with each passing year. But in order to demonstrate and signal to everyone that we are not waiting to do capacity building, but starting already in earnest to do capacity building, the global roundtable would be an important milestone. And it is my intention to discuss with the Secretariat in terms of how we should structure that, and I will set out a note on arrangements for the global roundtable earlier in the year. There are quite a number of things to do, but if any of you have interesting ideas on how we can make the global roundtable an exciting and action-oriented event, you know, I’d welcome any ideas that you might have. But it could be a way not only to demonstrate that we are doing things, but also to demonstrate that the UN framework of rules, norms, and principles is a live document, that everyone is serious and committed to this cumulative and evolving framework. Everyone is committed to preserving a peaceful, open, secure, stable ICT domain. So the benefits are not just with regard to the capacity building per se, but on a whole range of issues that, you know, we are continuing the task of building an open, stable, secure cyberspace. So friends, this has taken much, much longer than I just scribbled a few points on paper, but it became a much larger, a longer set of comments than I had anticipated. But in some ways, I hope it does justice to the richness of the discussions we have had. It’s my intention now to transition to the next agenda item, which is another important, important, important item. So I do not want to rush that, so we certainly will have to go into the afternoon session. So I’m sorry if I’ve dashed your hopes that, you know, you might have Friday afternoon off in New York and take a quick stroll by Fifth Avenue. You can still do that after 6 p.m. So I will devote the time to the discussion on regular institutional dialogue. Now before we do that, I think I just need to change my channels on my brain before we go to the next topic. So I propose a five-minute pause before we come back to regular institutional dialogue. Meeting is adjourned. Five-minute pause. Distinguished delegates, I resume our discussion on agenda item five, and we will start our discussion at this point on regular institutional dialogue. And before I open the floor to delegations, and in fact many of you have indicated your desire to speak, we will first hear a briefing by the Office for Disarmament Affairs, pursuant to paragraph 58 of the second annual progress report, in which the ODA is requested to brief the working group on the report of the Secretary General submitted to the General Assembly at its 78th session, contained in document A/78/76. So I give the floor now to Ms. Katherine Prizeman.

Katherine Prizeman (Political Affairs Officer UNODA)

Thank you very much, Mr. Chairman, for the floor, and thank you very much to the Open-Ended Working Group for requesting this briefing on the report of the Secretary-General contained in A/70/76. Kindly just ask the technician to please put up the slides. Pursuant to the General Assembly Resolution 77/37, adopted on 12 December 2022, which welcomes the proposal to establish a United Nations Program of Action to advance responsible state behavior and the use of ICTs in the context of international security. The resolution underlined in particular the complementarity of the POA proposal with the work of this Open-Ended Working Group, and that any future mechanism for regular institutional dialogue under the auspices of the UN on ICT security should be action-oriented with specific objectives, building on previous outcomes, be inclusive, transparent, consensus-driven, and results-based. Two requests of the Secretariat were made in this resolution by the General Assembly. One, a report of the Secretary-General, and two, collaboration with regional organizations to convene consultations on the POA proposal. This presentation will focus on the report of the Secretary-General pursuant to the request of the Working Group. So the report of the Secretary-General was requested via Operational Paragraph 3 of 77/37, which requests the Secretary-General to seek the views of member states on the scope, structure, and content of the POA, and the preparatory work and modalities for its establishment, including an international conference, taking into account various General Assembly resolutions, consensus reports of the GGEs, the 2021 report of the OEWG, the first annual progress report of this group, and the views and contributions submitted by member states in the framework of this group, as well as the regional consultations. So the report was to be requested based on those views and to be submitted to the General Assembly at the 78th session for further discussion between states in the meetings of this Working Group. Member state views were received following a note verbale that was circulated by the Office for Disarmament Affairs. And as of today, there are 41 inputs that have been received, and those are all available in full on our webpage, our meetings place. And they variously cover scope, structure, principles, content, preparatory work modalities for establishment, a form of a follow-up mechanism, and implementation. I should note that member states, while the deadline has passed for reflecting views in the report of the Secretary-General, certainly views may still be submitted to the Secretariat for posting on our webpage. Pursuant to the request, the report was made available to the 78th session of the General Assembly in document A/78/76. It is available in all UN official languages. And the annex includes replies received from member states by the extended deadline. So if your input is not included there but was received after the extended deadline, I believe it was April 15th, it is still included on the webpage. The report is a substantive consolidated summary of the elements received from member states. So it’s worth underscoring. That is not a fully comprehensive explanation of state views. Of course, because it’s only based on the views that we received. So just to make that important point. It addresses scope, structure, and principles, content, preparatory work, and modalities for establishment, functions, and follow-up mechanism and implementation. It variously demonstrates some convergence of views amongst some states on these aspects. For example, on scope, structure, and principles. The importance of securing the peace, security, and stability of cyberspace. That it could support the practical implementation of the framework for responsible state behavior. That various principles should underpin such a mechanism such as inclusivity, transparency, be results-based, action-oriented, undertake decision-making by consensus, and be permanent. It should also focus, for example, on capacity building, and also the possibility of such a framework discussing a legally binding instrument. Other aspects that came to light were the importance of having such a mechanism under the auspices of the UN, possibly the first committee, given its focus on international security. That it could be politically binding in nature, support narrowing the digital divide, including the gender digital divide. That it should support multistakeholder engagement. That there could be a possible international conference to support the establishment of such a framework. That it could support the exchange of information, the identification of existing gaps, and to consider elaboration of new norms, principles, and rules. That it could further discuss application of international law. And that frequency of regular follow-up meetings would support the permanence and the long-term endeavor of the framework. That it could have intersessional work, variously organized, including possible working groups, review conferences. It could incorporate voluntary reporting by states, and once again, support the participation of stakeholders. So again, this is not an exhaustive list of elements, but just a few of the common elements that emerged based on the views that we received. And finally, given the nature of the report, being that of the Secretary-General, he provides some observations and conclusions at the end of the report in the final section. And he highlights a few elements, including the urgency of strengthening the safety and security of the ICT environment, including enhancing the protection of civilians from malicious activity. Two, that the ICT environment is not a lawless space, and that the rule of law exists in the digital sphere, just as it does in the physical world. Thirdly, that the consideration of the POA proposal in an inclusive and transparent manner, firmly based on previous consensus agreements and progress made in the General Assembly, including this OEWG, is a worthwhile endeavor. That given the dynamic nature of ICT technologies and the rapidly changing digital environment, flexibility and adaptability will remain important factors. And finally, that there is broad agreement in his view that the Open-Ended Working Group, this group should continue to play a key role in further work on this proposal, and that its current mandate set to complete the OEWG by the end of this year, and that its current mandate set to conclude in 2025, could facilitate additional exchanges. And finally, to conclude, I wanted to highlight the Secretary-General’s recommendation that it is therefore recommended that states continue to discuss the potential scope, structure, principles, content, functions, and follow-up of this proposal under the auspices of the OEWG, drawing on the views expressed in this report, which I’m presenting, but also taking into account other exchanges, including those that were held at the regional and sub-regional levels in the format of the consultations. And that such discussions should also take into account procedural questions, including budgetary requirements, and that this could be done under the auspices of the regular institutional dialogue agenda item. And that dedicated intersessional meetings on the POA could be convened. And of course, such a decision has already been taken in the annual progress report, and this discussion in and of itself today represents those further discussions. So I thank you very much again, Mr. Chairman, for the opportunity and the request to the Secretariat, and invite delegations to please have a look at the report, as well as the primary source inputs that were received from member states for further details. Thank you very much.

Ambassador Gafoor

Thank you very much, Catherine, for that overview of the report of the Secretary-General. And of course, as Chair, I completely agree with the Secretary-General’s observation that this is a worthwhile endeavor for us to discuss within the Open-Ended Working Group, regular institutional dialogue, and how the Program of Action fits into a future mechanism. Here, I want to highlight before we get to speakers that as part of our recommended next steps in paragraph 44, we did agree that we will continue discussions on elaborating common understandings on the most effective format for regular institutional dialogue. In that context, we agreed on common elements in July, and we also agreed that we will continue discussions on additional common elements. I think it’s important that we pick up from where we left off the discussions in July. So, it’s important that as part of the recommended actions, we should focus on how we can build on the common elements. And then, of course, we also agreed, and the report of the Secretary-General makes that very clear, that we will have two dedicated intersessional meetings to discuss the POA as well as proposals on regular institutional dialogue, including, of course, the POA. So, it is my intention to devote sufficient time needed for this, and this is a very important issue that has to do with the future of how we proceed beyond 2025. So, I would like to at this point say that all your views and discussions within this working group can help us find more common elements, build common ground, and hopefully a consensus way or a consensus path forward. So, with those comments, the floor is open, and I wanted to give the floor first to the European Union, followed by France. EU, please.

EU

Thank you, Chair, for giving me the floor. I have the honour to speak on behalf of the European Union and the 27 Member States. The candidate countries North Macedonia, Montenegro, Albania, Ukraine, the Republic of Moldova, and Bosnia and Herzegovina, the potential candidate country Georgia, and the EFTA country Norway, member of the European Economic Area, aligned themselves with this statement. The overwhelming support of 161 positive votes for the POA resolution in this year’s UN General Assembly has shown that ensuring a seamless transition from the Open-Ended Working Group to a permanent, inclusive, and action-oriented mechanism is now a common objective of a vast majority of states from all regions. The European Union has been supporting the establishment of the POA to advance responsible state behaviour in the use of ICTs in the context of international security from early on, mainly because this is where we see the need is assisting countries with the implementation of agreed norms and ensuring practical and needs-driven capacity building to increase cyber resilience. Since 2020, we have taken an incremental approach to building the content of the POA, first and foremost because we want every UN member state to have a voice and that the agreed elements we determine are needs-driven. We strongly believe that the multistakeholder approach and the inclusion of all relevant stakeholders would lend legitimacy and help to shape any future instrument. Addressing cyber threats and the impact and harm they inflict on infrastructure and ultimately on citizens will require a collective and coordinated response across diplomatic, policy, and technical communities, as well as other relevant experts. The UN system can and should be leveraged to carry out multistakeholder consultations and initiatives designed to implement the agreed normative framework. In this year’s resolution 78-16, the future steps of the Program of Action have collectively been set to allow member states to elaborate this mechanism in 2024 and 2025 within the Open-Ended Working Group, both at its substantial sessions and its dedicated international meetings. The resolution clearly states that the scope, structure, content, and modalities of this mechanism shall be based on consensus outcomes of this Open-Ended Working Group. In light of that, the Open-Ended Working Group deliberations on the future establishment of the mechanism must also become more granular, both when it comes to discussing the broader framework of the POA, but also when designing an action-oriented instrument that serves everyone’s interest. In order to facilitate a smooth transition and an effective implementation of the Open-Ended Working Group results, we have to start reaching clarity on the modalities of the future mechanism based on the common elements agreed in the second annual progress report. To us, for instance, the instrument’s objective should be threefold. First, this future mechanism would support states, including through capacity building, in the implementation of the framework for responsible state behaviour. Second, it would enable discussions on the further development of the framework, including by identifying any gaps in the framework and, if appropriate, considering the need for additional voluntary non-binding norms or additional legally binding obligations. And third, it would facilitate inclusive dialogue and cooperation, including with relevant stakeholders where appropriate. In closing, allow me to come back to my opening statement. We also see the POA as a way to help to close the current digital gap, to reinforce the positive actions that can be taken to support cyber security. This includes in relation to building awareness of and supporting implementation of agreed norms and law. Let’s jointly make sure that we use the time and opportunity to design the future mechanism as an inclusive and transparent platform that provides for responsible state behaviour in cyberspace. The EU therefore welcomes this discussion and your proposal, Chair, to continue substantive discussion on this topic in 2024. Thank you.

Ambassador Gafoor

Thank you very much, European Union. I give the floor now to France.

France

Thank you, Mr. Chair. My delegation aligns itself with the statement made by the European Union and would like to add the following elements in its national capacity. My delegation would like to first of all welcome the richness of exchanges that took place this week. This is a truly strategic discussion that addresses the key elements of cybersecurity. It has also just concluded on capacity building. The richness of this debate shows the value added of the inclusive format of this working group. These exchanges on the five first pillars of the group’s mandate must guide our reflection in terms of a regular institutional dialogue, guided by the objective of institutional stability in such discussions. Chair, your second guiding question invites us to consider discussions on the regular institutional dialogue, taking into account recent important developments with regard to the Program of Action. The General Assembly adopted for the second consecutive year by 161 votes in favor a resolution on a Program of Action sponsored by a cross-regional group of 67 states. This vote demonstrated the will of the vast majority of states to move forward on this issue of regular institutional dialogue, an issue that has been on our agenda since September 2019. This resolution collectively creates the following obligations for us. We now have a clear, sequenced, and realistic calendar to establish a mechanism for a regular institutional dialogue. Namely, after the conclusion of OEWG in July 2025, and before the end of the year 2026, to ensure an uninterrupted transition in our work. We have three years in front of us. By way of comparison, this is more or less the same period that was necessary to implement the Program of Action on light and small caliber weapons. Substantial discussions, therefore, must start now. This resolution entrusts the OEWG with defining the content and modalities for establishing a future mechanism. To make sure that the form of our discussion does not impose the substance, reflections on these two aspects must proceed in parallel. We have all of the material necessary to start this work, specifically owing to the multiple contributions of states on this issue, within the framework of the previous and the current open-ended working group. We also have the Secretary-General’s report on the Program of Action presented by UNIDIR. Chair, your second guiding question also invites us to identify synergies between the Program of Action and other proposals put forward within the framework of this working group. My delegation would like to join the vast support expressed by many states through Kenya’s proposal on a threat repository and India’s proposal on a global portal. The synergies between these proposals and a future mechanism for regular institutional dialogue seem clear. We believe that the exchange of information on threats and the various ways of countering them would be indispensable in the framework of a Program of Action. Furthermore, a global portal, making it possible to fit the needs expressed by states to the available expertise resources, specifically in the area of capacity building, becomes essential. Furthermore, certain existing initiatives could also contribute to the action-oriented dimension of the Program of Action. Regarding the implementation of the Program of Action, I would like to highlight a number of key initiatives in the framework of this working group. The first is the implementation of a normative framework. The national implementation questionnaire put forward by UNIDIR would make it possible to identify the challenges and needs that states encounter in implementing a normative framework and would make it possible to exchange good practices in this regard. Furthermore, and that’s another initiative that we’ve discussed here at length, the global intergovernmental directory of points of contact, which should be operationalized shortly, could be a central element of a future mechanism and would serve as a foundation for implementing other confidence-building measures. We see that the specific development within the framework of OEWG of these various initiatives would be a useful preparation for implementing a Program of Action. This Program of Action could become, in time, an institutional envelope. We are not starting from scratch. We must rely on what is working within OEWG and make it continuous. In the same spirit, I’d like to suggest that the Program of Action should include discussions in the same manner as the discussions we’re holding here at OEWG. Delegations appreciate this format. It’s not too heavy, and it allows us to conduct discussions in an inclusive and regular fashion on subjects that evolve fast. Now, I’d like to turn to your first guiding question, Mr. Chair, where you invite us to identify elements that can be added to the list of common elements for the future mechanism of regular institutional dialogue. In a preliminary way, I’d like to emphasize the need to start thinking right now about the operational implications of the first common element, namely, the permanent and unique character of the mechanism. This permanent nature of the mechanism would need a dedicated institutional structure, having the appropriate human resources and budgetary resources. Budgetary implications and the identification of relevant actors within the United Nations to ensure that it functions should be a subject of discussion in the following sessions. The third common element, which emphasizes the fact that the mechanism should be based on a voluntary framework of behavior agreed by states, should be completed. Indeed, it seems important to leave open the possibility of further development of that framework. We have collectively recognized that additional norms could be developed in the future, if necessary. The mechanism, therefore, must be dynamic and flexible to make sure that these possible new norms might be integrated. Furthermore, if we periodically review progress accomplished in implementing the existing framework, the mechanism could be used to identify potential lacunae gaps in the existing international law. And if that is the case, we must be led to consider new norms that would be legally binding to fill those gaps. My delegation would like to further propose considering two additional common elements. First, a common element based on the action-oriented nature of the future mechanism. To support states in capacity building specifically, during this week, many delegations have extremely eloquently emphasized the need to stress the capacity building aspect to reduce the digital gap in the cyber domain. The second common element that we propose, a new one, emphasizes the inclusive nature of the mechanism. We all agree that the future mechanism will, of course, be led by states. Nobody contests the prerogative of states in the field of international security. However, the participation of non-governmental actors in our work on cybersecurity is indispensable. We need their expertise and their resources. But we also need to emphasize the responsibility of these actors in implementing certain aspects of the normative framework. I am thinking in particular of the private sector, which could very usefully contribute to our discussions on the security of digital products. Mr. Chair, as you have encouraged us, we plan to shortly submit to this group specific proposals in a consolidated way within the framework of cross-regional coordination. This cross-regional coordination group or network is open to all states that wish to contribute to collective thinking. My delegation is ready to continue working in an inclusive, transparent, and constructive fashion, which we have adopted on these issues in the first committee. To conclude, I’d like to illustrate what I’ve just said with a metaphor. We have already heard in this group references to aircraft, forests, canoes, and even football players. I don’t have either the imagination or the poetic talent of my esteemed colleagues. Therefore, I will be content for my part with the metaphor from the digital world, specifically the metaphor of an operating system. The Program of Action could indeed be our operating system in the field of international cybersecurity. An operating system in which it will be possible to download and install different programs and applications of various sources. It would be an operating system that could be updated on a regular basis to make sure it stays in sync with the security environment. Finally, it would be an operating system of an open-source nature, naturally. The source code will be open, accessible, and modifiable by all. Thank you very much. Thank you.

Ambassador Gafoor

Thank you very much, France, for your statement and also for your additional metaphor. I think an open-source program is a good one for an Open-Ended Working Group. So let’s build on common elements, and I also take note of your suggestions. The Islamic Republic of Iran is the next speaker.

Iran

We advocate for any future mechanism facilitating regular institutional dialogue on ICT security within the UN to be intergovernmental, consensus-based, democratic, transparent, and political. It should prioritize considering the concerns and interests of all states through equal and fair participation. Both paragraph 77 of the 2021 OEWG and paragraph 18b of the first APR recognize the variety of proposals for promoting responsible state behavior in the use of ICTs. The first annual progress report recommends ongoing exchanges of views at the OEWG and encourages states to propose mechanisms for regular institutional dialogue on ICT security. Hence, the Program of Action should be deliberated within the OEWG, ensuring equal footing with other states’ proposals. The draft proposal from the last two years highlights the potential polarization if the POA is tabled outside of the OEWG. We strongly support the integrity of the OEWG and emphasize that tabling the POA beyond its purview will hinder consensus. Considering the current OEWG’s lifespan, we believe that any successor should also operate on a consensus basis, inheriting the positive features of the existing OEWG. In line with OP8 of the recently adopted resolution in the First Committee, urging member states to inform the Secretary-General of their views on ICT security, particularly regarding the future regular institutional dialogue, we emphasize the importance of expressing views on the future mechanism. We encourage all OEWG supporters to sustain their backing for this process, safeguarding the positive progress achieved thus far. As the Secretary-General is expected to submit a report to the General Assembly during the OEWG’s eighth substantive session, it is important that member states share their inputs with the Secretary-General and also actively engage in discussions during the Open-Ended Working Group’s relevant session in 2024. Having said that, we welcome the initiative by Russia, supported by many like-minded countries, and we will be more than happy to contribute to its discussion in the coming future. I thank you.

Ambassador Gafoor

Thank you, Mr. Chair. Thank you very much, Iran. Distinguished friends, it’s my intention to adjourn at this point. We have about 30 speakers, in fact, more than 30 speakers who have been inscribed, so certainly we will have to meet this afternoon. I know that UNIDIR is offering a free lunch, so it’s important that you get there early. But in any event, I wanted to say that this has been an intense morning, and we have made a good start with the last topic under discussion, so please come back refreshed for another intense round of discussion this afternoon. The meeting is adjourned, and enjoy your afternoon lunch. Thank you.

Leave a Reply

Your email address will not be published. Required fields are marked *