Ambassador Gafoor
Good afternoon distinguished delegates.The eighth meeting of the seventh substantive session of the Open-ended Working Group, on security of and in the use of ICTs. Established pursuant to General Assembly resolution 75/240, is now called to order. This afternoon, we’ll proceed to the section on capacity building. And then, and I provided my various comments on the first day as well as just before the lunch break. So we’ll go straight to hearing the list of speakers. The floor is now open, I have a long list of people who have asked for the floor and an accordance with our practice, I’d like to receive an indication that there is a request from a delegation to make a presentation, I will give them an opportunity to go first Philippines and then to be followed by, And then after the Philippines, we’ll go to Argentina on behalf of a group as well. And then European Union and then their list of speakers as is reflected. Yeah, so Philippines, you had the floor please.
Philippines
This may not be as elegant as the proposal of India, I am not as creative or maybe as visual as their earlier proposal, but this is my attempt, maybe to easily inform the plenary on the Philippine proposal. In the second APR, states were called on to continue discussion on the global cybersecurity cooperation portal as a one-stop-shop tool for states to be developed under the auspices of the UN. The chair also asked us how how it will look like in practice and for possible modules to include their integrating this one-stop-shop. The Philippines recognizes India’s proposal captures two modules and capacity building, one module on capacity building calendar, and another module on assistance mapping. Nevertheless, we offer this food for thought on a needs based capacity building catalog to be considered as a possible module in our future one stop shop portal. Building the catalog is envisioned as a means to match capacity building needs with capacity building providers in a manner driven by demand or the needs of recipient states. responding, to the call of the chair for concrete suggestions for effective capacity building, I am pleased to present highlights of this draft working paper currently a non paper on capacity building a proposal aimed at enhancing cyber capacity across UN member states. This draft is entitled needs based capacity building cat needs based capacity building catalog. This attempts to outline a comprehensive approach to address the evolving challenges in the realm of cybersecurity. The Philippines is pleased to note that although we initiated the concept many experts in this room from our region and other regions who equally valued Capacity Building has helped to shape this proposal in its current draft form. Allow me to describe its rational principles, elements and features. So I’ll present first, the rational and then the elements of of the of his working paper. So the catalog is envisioned to help member states independently identify their capacity building needs, match their needs would existing providers study their national experience. So the the national experience of previous years receiving countries and provide information on an inquiry or how to apply for a capacity building program. The paper emphasizes the importance of partnerships and capacity building, highlighting principles such as mutual trust, demand driven initiatives, national ownership share responsibilities, it sets the stage for a collaborative and inclusive framework. So what are the elements of this capacity building catalog? The catalog is structured into four key headings, capacity needs, providers, models, and then the inquiry or information column. The systematic approach allows for efficient navigation and access to relevant information for both providers and recipients. So how does it look like? So as an example, we present this one as an entry. This is a single entry into this catalog, for example, setting up a cert and then providers are what we have for The mapping exercise presented by the Secretariat last week, we have the ITU and first. So in this, well, another idea is that we can hyperlink the providers with website, or the web page with a subject capacity building program is being featured. If anyone, if any of the delegations of course, browse through them, small arms and light weapons website, that one features, when you click maybe, a country, and the list of capacity building programs, you can see there the program of work of each of the program. So that’s also something that we can include in this. In this catalog, we can hyperlink for example, in the models, we can hyperlink the program of work, or the result of the program of each of the capacity building program that has been availed off by countries. And then we can learn from their national experience. And we can use it as a jumping off point to evaluate if this is a capacity building program that we also want to replicate in their own countries. And then the next heading is under inquiry or for more information. We have received some feedback from Capital that sometimes access the capacity building program becomes challenging, because you have to navigate through a lot of information before finding the right focal person, because there can be a lot of several capacity building programs for each provider. By by in this catalog, we envision that once the member states try to access the inquirer hero or contact here button, it exactly linked them with the focal person of the specific capacity building program they wanted access to. So the paper advocates for a menu of capacities needed for cybersecurity, drawing on the experience of other states. We suggest using foundational studies such as the UNIDIR’s unpacking cyber capacity needs study, as a starting point to identify evolving capacity needs. For example, again, we see on screen we chose setting up a CERT as an example. And UNIDIRs to use unpacking cyber capacity needs study, this is one of those foundational cyber capacities that was identified. Recognizing the difference cybersecurity maturity of member states, after populating the data catalog will foundational capacity building needs, the catalog could also capture more advanced capacity building needs in the future. For starters, the Philippines has identified the capacity building need, the need to address and improve our CERT team operation and our CII cybersecurity assessment. We also recognize the diversity of providers globally. So this capacity building catalog aims to be as comprehensive as possible, ensuring that states have wide access to a wide array of options when addressing their specific capacity needs. Although the sample that we presented here, on screen refers to non-state providers, the catalog could also capture bilateral partnerships. Taking an example from our national experience the Philippines and Australia just recently signed an MOU on cyber and critical technology cooperation. The Philippines looks forward to contributing to the catalog by reporting on the practical partnerships that the Philippines and Australia will implement by virtue of this concluded MOU and the good practices and models the CB catalog goes beyond listing provided by featuring good practices and model programs. This allows aspiring recipients to learn again from successful implementations and encourages the replication of effective capacity building initiatives. Again on the inquiry button, the idea behind is to streamline the process. The Capacity Building catalog facilitates direct correspondence between program recipients and providers. As mentioned, like Contact Us button, we envision this inquiry button to immediately link interested member states to designated focal persons of CB providers. Other features about this proposal. The proposal introduces the concept of use of a user friendly capacity building catalog. I know my chart was a lot of text, but we envision it’s something maybe maybe intuitive, maybe with images, but with the help of a programmer that can happen but it’s designed to be a repository that organizes existing capacity building programs. This catalog serves as a valuable resource for States seeking guidance on cybersecurity Initiative. The catalog also wants once the catalog is populated and made available to member states, states who feel reluctant being assessed by a third party and assessing their national vulnerabilities can make a domestic assessment. Use the catalog as a starting point to build on improving national capacity. So it avoids the hazards of exposing your vulnerabilities if you’re not ready to. Once a catalog is also populated, there could be a real realization that there are capacity needs for capacity building providers are lacking. The catalog will then serve as an empirical basis for the creation of new capacity building programs to meet our new or an underserved capacity needs. Feedback mechanism, development, development and updating of the catalog can also serve as a natural feedback mechanism on the capacity building program implementation. As additional providers good practices models can share or link their program of work and their implementation report to the catalog. Another possible feature is that it can be integrated to the global cybersecurity cooperation portal. The proposal envisions the capacity building catalog as a living document, regularly updated and could be integrated. So module two in this global cybersecurity cooperation portal, fostering continuous improvement and global cooperation. We also see the possibility of using Kenya’s threats, threats repository as a source of ideation in identifying cyber capacity needs. In closing, Mr. Chair, we just wish to emphasize that the proposal is still a draft form, and it’s still open to inputs, questions and refinements. We welcome collaboration and hope this initiative will serve as a valuable and complementary asset to existing proposals designed to meet the diverse and dynamic needs of UN member states in the field of cyber capacity building, we look forward to constructive engagement and contributions from all delegations to enrich and refine this proposal for the collective benefit of our global cybersecurity efforts. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much Philippines for your statement, as well as your presentation, which was actually quite intuitive and easy to understand. And I would also encourage and welcome any others who wish to make similar presentations at future sessions, or even at this session to let me know in advance happy to allow for that, because that is precisely why we are here to have an exchange of views. So thank you very much for that Philippines. And I certainly would encourage you to continue talking to everyone else in the working group, as well as others to talk to the Philippines to see how we can bring things forward. Let me now give the floor to Argentina, on behalf of our group, you have the floor.
Argentina
Thank you very much Chairman. I’m taking the floor on behalf of the following delegations from the Latin American region Brazil, Chile, Colombia, Costa Rica, Ecuador, El Salvador, Guatemala, Honduras, Mexico, Paraguay, Peru, the Dominican Republic, Uruguay and my own delegation, Argentina. We’d like to take the opportunity in the seventh session to repeat our shared position with regard to capacity building, and also to highlight the questions that we believe are priority and therefore require specific actions. Also, with regard to drafting the third annual progress report of 2024, which will be circulated for the consideration of this working group next July, we will propose language with a view for their inclusion in the upcoming APR. Mr. Chairman, addressing capacity building from a comprehensive, holistic and human rights based focus is in is necessary to ensure that our working group can submit proposals, which lead to lasting and effective results to bring benefits for all for that reason. Our delegations welcomed last December, the recognition by the APR of 2023 that capacity building is a confidence building measure in itself. Recognizing the digital divide and the crucial role played by capacity building, in its broadest terms is fundamental. Digital transformation which is necessary to overcome this gap is part of the path towards achieving a common goal, a resilient, open, safe, stable, accessible, peaceful and free cyberspace that everybody can operate within. Aiming our efforts of our group towards developing and updating the capacities of all its members taking into account their different starting points is essential to identify and overcome cyber cyber risks. Having an inclusive and equitable approach will help to improve digital security not only at the individual level, but also at the collective level and the context, we believe that the institution ongoing dialogue should incorporate clear and precise guidelines on the ongoing development of capacities to ensure that it is genuinely open, inclusive, transparent, sustainable and flexibility and can change in depending on the different different needs of states, and an assessment of the ICT environment. And a focus on action oriented capacity building particularly with regard to implementing norms for Responsible state behavior and cyberspace is vital. Since no state can be safe until we are all safe. Also, and taking as a guiding light the safe, effective and significant participation of all states in cyberspace. We believe that the implementation of a responsible free framework should be part of a promoting of innovation, technical assistance, capacity, building and transfer of technologies in line with current international law, but also taking into account the needs of developing countries. This will contribute not only to the wellbeing and the economic and social development of our countries, but also to applying and adopting on equal footing the growing and evolving framework of responsible behavior in the use of ICTs. We highlight the role of multilateral organizations and regional and sub regional initiatives as key platforms for coordination and cooperation between states. Thanks to their experience in designing specific training programs, they provide significant added value to the process of capacity building. Also, we encourage states to continue to support capacity building initiatives in line with the principles of Annex C of the 2023 APR, and to encourage cooperation with regional sub regional organization and other stakeholders such as the private sector, NGOs, academia, and civil society. This cooperation can enhance regional international cooperation, such as the initiatives of north -south cooperation, south-south and triangular cooperation in terms of science, technology innovation, promoting specific actions of technical assistance to full capacity building that takes special account of the needs of developing countries. To summarize, Mr. Chairman, we believe that cooperation and capacity building must be seen as fundamental pillars for building a safe and resilient cyberspace. It’s vital that we continue to work together that we share our knowledge, experiences, and resources to encourage an inclusive and equitable digital space. International cooperation in capacity building is not just vital to close the digital gap, but also it’s crucial to maintain international peace and security. Given that, Mr. Chairman, and with a view to drafting the annual progress report of 2024, our delegations would like to make the following proposals for recommended and recommended measures to be included in the annual progress report in the working group on theme five of the program, particularly in the paragraph related to capacity building. Number one, to current courage states that are able to do so to build on technical assistance, including workshops, training, in cyber diplomacy and responsible behavior of states in cyberspace, including the application of norms, Confidence Building Measures and international law. Next, critical infrastructure. This should include methodologies to ensure that states identify sectors and operators of essential services, who are actors that can have an impact on cyber cyber incidents, including early warning, identification, and building resilience, applying international law in cyberspace, taking into account the in fundamental importance of including different viewpoints in this debate, and to present doctrinal differences with regard to implementing it. Capacity Building to establish and to enhance the maturity of national country teams in cybersecurity incident response teams CRT, existing and emerging threats with regard to ransomware and the challenges to cybersecurity of new technologies such as the use of artificial intelligence and quantum computing, exchange of information and experiences aimed at the particular circumstances in each country. Second, encouraged state to exchange experience in risk with regard to response protocols, and the management of threats that identify potential threats to security in ICT. Three, encourage states that can do so to promote innovation, technical assistance for the DEA capacity building, transfer of technology, in line with existing international law aimed at enhancing our resilience in cyberspace. Finally, we reiterate that capacity building is a fundamental and cross cutting aspect. And it relates to all the issues dealt with in this Open-ended Working Group. And therefore, it’s important that they be sustainable and permanent. We believe that the creation of a tool which serves this end would be a key cooperative tool, and should be seen as the future mechanism for regular institutional dialogue. Thank you very much.
Ambassador Gafoor
Thank you very much, Argentina, for that statement on behalf of the group and please do make available a copy of your statement. Thank you very much. I’ll give the floor now to the European Union please.
EU
Thank you, Mr. Chair. The candidate countries North Macedonia, Montenegro, Serbia, Albania, the Republic of Moldova, Bosnia and Herzegovina and Georgia and the EFTA countries, Iceland and Norway, members of the European Economic Area, as well as San Marino aligned themselves with this statement. Mr. Chair, with the increasing demand for and supply of capacity building, and its importance for the maintenance of peace and security in cyberspace. We are delighted to see that capacity building has taken a central place in the discussion of the Open-ended Working Group. To advance the demand driven approach and cyber capacity building and contribute to the implementation of the UN framework of responsible state behavior in cyberspace. It is important that the Open-ended Working Group continue to exchange on needs for cyber capacity building help to great partnerships and define the framework for member states and stakeholders capacity building initiatives. So all member states can reap the benefits of ICTs. In light of that, we welcome the global roundtable is scheduled for May on capacity building. It is a good example of how the UN can leverage its convening role, help to build partnerships, facilitate multi stakeholder involvement, and ensure complementarity with existing national and regional initiatives. While the UNODA survey during March will give us a better overview of the cyber capacity building ecosystem and provide an evidence base for future capacity building initiatives. Through the last few years member states have already referred to various capacity needs. The EU otso observed that these generally fall under the five broad capacity building pillars identified in unity and the Global Forum on Cyber Expertise, capacity building mapping, policy and structure the culture and society, building knowledge and capabilities regulate regulatory frameworks and standards and technologies. We would also like to highlight the importance of the Accra call for cyber resilient development, which provides guidance to ensure that cyber capacity building is designed and implemented to support broader Sustainable Development Goals. Mr. Chair, the EU is attaching great importance to improving means and tools for the implementation and delivery of cyber capacity building allow me to share two best practices the EU as identified in our own cyber capacity building efforts. First, the operational guidance for iOS international cooperation on cyber capacity building. It’s a practical framework for formulating, designing, implementing and evaluating the EU’s external action in areas such as national strategic Cyber Framework, cyber crisis prevention and management, criminal justice, cybersecurity education and culture and cyber diplomacy. The second tool is the cybersecurity mainstreaming toolbox. for cooperation project in partner countries, it aims to ensure the security by design of digital connectivity and infrastructure projects. Whilst considering the cyber maturity of the country in which the project is taking place. It is anchored in the security dimension of the Global Gateway and has, under such will support the sustainability and security of its investments. Building on these two initiatives and the light of the upcoming high level roundtable on on cyber capacity building, the EU aims to present its efforts on how to assist states in mainstreaming mean Capacity Building Principles, including those reflected in the 2021 Open-ended Working Group report and the 2023 annual progress report into capacity building initiatives related to ICT security. By looking into different models, the Open-ended Working Group could help to define the framework for member states capacity building, and determine what capacities member states need to meet as a global minimum capability while re by recognizing the link to the SDGs and potential of its convening role to build partnerships, facilitate multistakeholder involvement, and ensure complementarity with existing national or regional initiatives. Mr. Chair, while the involving threat landscape requires us us, requires us to constantly adapt our approaches. Implementing foundational capacities remain the backbone of cyber resilience, putting the legislation in place setting up a domestic architecture with clear roles and responsibilities, allocating points of contacts and testing internal processes or actions that are important for every state’s to undertake. These actions will not only help to protect critical infrastructure, they will also directly contribute to the adherence to the UN framework of responsible state behavior. In conclusion share their open union will continue its efforts in regional settings to foster practical implementation of the framework of responsible state behavior in cyberspace, as well as efforts to address technical needs in relation to state conduct in cyberspace. The EU stands ready to continue to show for to Mr. Chair in the effort of advancing capacity building efforts at the global level. Thank you.
Ambassador Gafoor
Thank you very much European Union. I give the floor now to Nigeria to be followed by Peru, Nigeria please.
Nigeria
Thank you, Mr. Chair. Nigeria identifies capacity building as one of the major pillars and bureau a productive discussion at international level. Capacity Building is an instrument that bridges the gap of mistrust among states when discussing a range of pivotal issues. We can all agree that within the context of our present discussion, the merits of capacity building in cybersecurity will reinforce inclusivity and transparency. The benefits of capacity building, particularly within the ambit of the Open-ended Working Group on ICT are not far fetched as equal forcing on acquired knowledge further accelerates consensus on either two conflicting views. Nigeria believes that capacity building should be specific and tailored to the peculiarities of recipient countries. While the technical gap could be breached through workshops on best practices, and scenario based discussion. Capacity building should also target existing technologies in line with emerging trends, including the development of software that elevates the challenges of developing countries. The transfer of relevant technical knowhow promotion of research oriented technology, developments in existing and emerging ICT fields, as well as incorporation of indigenous knowledge development would in the long run reduce dependence on external solutions and system. In line with my delegations commitment to gender equality, gender mainstreaming should be encouraged and implemented as women are famous for the peacemaking rules in conflicts. Engaging representative of 50% of humanity would no doubt create an ambience of fairness and equity when discussed Since cyber related issues in order to build a formidable society in the context of ICT. Finally Mr. Chair, Nigeria will continue to work with other parties to build a permanent mechanism for capacity building within the cyber contexts. I thank you.
Ambassador Gafoor
Thank you very much, Nigeria, Peru to be followed by Mauritius.
Peru
Thank you very much, Mr. Chairman. Since this is the first time that I take the floor in this seventh session, allow me first of all to congratulate you for your leadership in this important working group. Secondly, I’d like to express our full support to your work in making progress and greater commitments to ensure that we achieve a safe and reliable cyberspace. First of all, we align ourselves with the joint statement made by Argentina on behalf of the group of Latin American countries. Cybersecurity is one of the themes of growing concern in Peru as my country moves towards greater digitalization in various economic sectors, and in the face of the presence of threats at the global and local level, aware of these threats and the malicious loose use of ICTs. We believe that together with other states, and multi party actors, we must seek cooperation, so that we can achieve a cyberspace that is peaceful. In this regard, the Secretary of the Government and Digital Transformation of Peru, it is the body that guides our work in terms of the digital transformation, together with the national digital security body, which is the platform which managers and supervisors the education promotion cooperation with regard to digital security at the national level. I should also mention that together with a view to support the working group, as was mentioned by you, Mr. Chairman, the Peruvian government recently appointed contact points for the global directory and the technical contact point which is the National Center of digital security for Peru, which I met referred to a moment ago. And then we have the Council of Ministers, which with its ref with its representative, and it’s diplomatic contact point in the Office of Security and Defense of the Ministry of Foreign Affairs in the person of its director. Those appointments, contact information points, has been sent to the relevant bodies to the Secretariat and so that they can participate in future events planned for this year. Mr. Chairman, capacity building is crucial and cross collecting to implement the commitments we have assumed therefore, we’d like to highlight the importance of dealing with capacity building of member states in the light of the different needs of those states technical assistance to address the digital divide transfer of technologies, taking into account the needs of developing countries, amongst other elements. We believe that a good start has been given to this with the global cooperation portal on cybersecurity of the United Nations, which is a useful tool for states in exchange and cooperation to seek respective synergies with other regional portals that have already been set up and we welcome the initiative submitted by Philippines Peru is actively participating regional bodies that deal with cybersecurity in the digital market, both at the level of the Pacific Alliance as well as in the Organization of American States. In both we promote and embrace themes of capacity building confidence building and responsible behavior of states through cooperation. At the UN, the alliance of the Pacific, which is a sub regional body made up of Peru, Mexico, Chile, and Colombia. We have a roadmap for the digital market. This was submitted in 2021 by all member states, it is to create a environment to promote digital services we promote we propose amongst other goals to promote cybersecurity, digital security, through enhancing regional and national integration of our systems or national centers of response to cybernetic incidents affecting digital security in the Organization of American States. Peru has worked in the CIC te This provides dialogue for member states of the Organization of American States to deal with measures to ensure competence building and reduce the risks of the malnterpretation of conflicts which could derive from the use of ICTs. It’s also important to highlight the synergies which can be generated between the work carried out by this Open-ended Working Group, the United Nations and the work of these regional organizations I’ve just referred to. And this has been referred to in the joint statement on Confidence Building Measures, which was made by Chile on behalf of a group of countries. Similarly, and as we’ve said, Peru will seek to play an active role in the global directory of contact points. We believe that this will be the cornerstone for the interchange of information, good practices, and cooperation. Mr. Chairman, in conclusion, we hope that this seventh substantive session of the OEWG will be fruitful, and that we will achieve concrete objectives of the third annual progress report. Thank you very much.
Ambassador Gafoor
Thank you very much, Peru for your statement, Mauritius to be followed by Rwanda.
Mauritius
Good afternoon Chair. Thank you for giving me the floor. As you have rightly mentioned, capacity building is an enabler of trust and confidence that cut across all domains of the OEWG discussions. We are here today to learn and exchange and see how we, as an international community, can improve our collaboration in building cyber capacity, together with our regional partners. In a region where technology and change are speeding countries, at the same time, becoming more vulnerable to cyber threats. It becomes therefore critical to reinforce our human and institutional capacity to secure our cyberspace. By building trust and confidence in the in the use of technologies chair, we need to be prepared and resilient if we want to reduce the impact of cyber threats and ensure that we are able to continue our operations effectively. To that effect, Mauritius is releasing a comprehensive three year National cybersecurity strategy, which focuses on the importance of addressing cyber threats and promoting a secure digital practices. I would also like to take this opportunity to mention that one of the pillars of this strategy focuses on capacity building initiatives at the local and regional levels. Moreover, Mauritius totally agree with your statement that capacity building is foundational and that we have to deliver and implement initiatives in that in this regard, and most importantly, we need to have results. Now, let me highlight some of the initiatives that Mauritius is taking in terms of capacity building. In 2022, Mauritius was designated as a regional cyber resilience hub in Africa by the cyber resilience for development Cyber for Dev, which is a European Union project designed to promote cyber resilience and cybersecurity in order to protect public and private enterprises across the globe. As part of this designation, Mauritius has been assisting several countries in the region in cybersecurity capacity building in operational, technical cyber policy and diplomatic areas. Moreover, the National CERT is running the ITU academy training center since 2020, after being chosen by the ITU as a global training center in the field of cybersecurity. For this center, Mauritius is building capacity in various cybersecurity domains. I would like to highlight that some of the focus areas for this year’s capacity building programs include cybersecurity risk around AI, and cyber threat intelligence. We welcome participants to register for these capacity building programs which are being offered free of charge. Moreover, Mauritius is also actively engaged with regional partners and international partners such as Africa CERT, SADC and the ITU on cybersecurity capacity building, including carry out cybersecurity drills. As a concluding note, Mauritius supports for efforts of the OEWG in promoting capacity building as the foundation of trust and confidence, and believes that this is a good platform for engaging with experts to share knowledge and best practices in this critical domain. By bolstering our collective cybersecurity capabilities, we can effectively protect our societies, economies and critical infrastructure from the ever evolving cyber threats we face today and in the future. Thank you, Chair.
Ambassador Gafoor
Thank you very much, Mauritius for your statement. I give the floor now to Rwanda to be followed by India, Rwanda, please,
Rwanda
Chair. This being the first time that our delegation is taking the floor, Rwanda would like to express its appreciation to you and the Secretariat for your dedication in the in executing the mandate of the OEWG you have our full support and commitment to build consensus through common understanding in the domain of ICT. Rwanda’s Delegation appreciate your efforts to steer discussions towards concrete proposals in the areas of our work in the security and use of ICTs. And to this endeavor, allow me to touch on the key items for consideration as far as capacity building is concerned. ICT has been a key enabler for socio economic development for the Global South, and their partners have demonstrated this through milestones in closing the digital divide. We cannot risk losing the momentum gained in this endeavor by not recognizing the threats posed by the very tools that power critical areas of our lives today, we have made strides together through critical partnerships and the exchange of knowledge and experiences. Similarly, we are capable of addressing the threats to our digital advancements if we work together. Rwanda is a strong believer in impact generated by efforts that are intentional about not leaving anyone behind such efforts especially crucial when it concerns the use of ICTs because of the interconnectedness in cyberspace that calls for international cooperation to achieve and sustain peace, security and development. It is of the utmost importance to think beyond national interest and current understanding of the ICT cyber threat threat, the ICT and threat landscape in order to be best prepared for emerging threats and a future that benefits all member states, including those without representation and active participation in this room. Chair, capacity building remains the foundation without which achieving security in the use of ICT will not be possible. As you rightly pointed out in your opening remarks. This is an area that calls for a pragmatic approach backed by meaningful action to be able to demonstrate results. Rhonda believes that identifying context specific foundational capacities in cybersecurity requires groundwork such as reviews based on the cybersecurity capacity, maturity model, development of strategies, and finally their implementation towards different capacity maturity levels. In order to be proactive in addressing the ever evolving threats in cyberspace. It is important for cybersecurity capacity building to target the root of the problem by employing the secure by design model in all initiatives, considering that cybersecurity entails balancing competing priorities with limited resources. Impactful capacity building initiatives will be those that empower member states to make good security decisions at the design stage of all ICT solutions in areas of demand. This takes the power away from threat actors and places it into the hands of defenders of the critical ICT infrastructure and services we have come to depend on. Finally Chair, appreciating the conversation and regional and international cooperation in building capacity to address cyber threats. Rwanda assures cooperation as we strive to implement meaningful and impactful cybersecurity capacity building initiatives. Thank you Chair.
Ambassador Gafoor
Thank you very much, Rwanda for your statement, India to be followed by Kuwait.
India
Mr. Chair, the world’s increasing interconnectivity necessitates a globally skilled community to navigate cyberspace complexities, capacity building and cyberspace and ICTs is no longer optional but essential for innovation, economic growth and digital infrastructure resilience. The international community’s ability to mitigate malicious ICT activity depends on each state’s readiness. Capacity building should address the digital divide on both national and global scales, especially focusing on developing state cyber preparedness and addressing critical infrastructure vulnerabilities. Capacity Building is crucial for enhancing skills, human resources, policies and institutions to increase state’s resilience and security, promoting adherence to international law and implementing norms of responsible state behavior. The OEWG should focus on practical cooperation initiatives and regular activities among member states for capacity building, benefiting small and developing countries. The OEWG should consider how cybersecurity considerations and good practices can be integrated into future digital development projects, while recognizing the unique needs, circumstances and state of cybersecurity developments, both in low and high income countries. India CERT is willing to explore the idea of developing an awareness booklet on ICT security and best practices, taking into account the views of other member states. It may be posted on the proposed global cybersecurity cooperation portal, and other relevant websites. Suggestions for the OEWG’s capacity building framework includes training cybersecurity professionals creating cooperative mechanisms, fostering public private partnerships, developing cost models for cross country training and building CERTs in developing countries. Of course, taking into account the request of receiving member states and their priorities. Member states can develop such a course model for providing training to other member states in collaboration with academic and industrial organizations. Such modules will be of benefit to member states that need to improve the capacities in specific areas of ICT security. Information about the same may also be added in the proposed our global cybersecurity cooperation portal. Lastly, India applauds the Chair’s initiative on convening a global roundtable on capacity building and looks forward to contributing to the same. Thank you Mr. Chair.
Ambassador Gafoor
Thank you very much indeed for your statement, Kuwait to be followed by Cuba.
Kuwait
Distinguished Chairperson, distinguished delegates in alignment with the guiding questions regarding the call for continued discussion on the global cybersecurity cooperation portal as a comprehensive tool for states and to act as a one stop-shop platform. And in reference to the suggested modules by India, Kuwait would like to propose a module that aligns with the suggested portal, and will aid in implementing rules norms and principles as follows. Given the rapid advancement in ICT, it’s crucial to keep pace with these changes. Therefore, it’s expected that we need to enhance and update the current existing norms or establish new ones. And since there is an urgency to implement those norms, we believe it’s necessary to make easier for member state to have tools for follow up and collaboration. Therefore, Kuwait proposes the development of a module that contains a repository and compressing both established and newly proposed norms. This model would feature two functions. Function one collaboration to facilitate collaboration among Member States, enabling them to suggest updates, proposing new norms and engage in discussion, function two prioritization and implementation tracking, assists in prioritization norms based on the relevance, urgency and most importantly, consensus among Member States. Also to include features to track and implementation progress of of privatized norms, ensuring continuous updates on advancement, where that would take place after an agreement is reached by Member States regarding the tracking mechanism. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much Kuwait. Cuba to be followed by Uruguay.
Cuba
Mr. Chairman. This is one of the priorities of our joint work. Cuba aligns itself with the initiatives which contribute to capacity building in all countries. Although in previous sessions, we have expressed considerations on this subject, we will try to contribute to this debate on the basis of your questions. Capacity Building depends generally on having external funding. We insist on the fact that the United Nations through its funds and its working systems should ensure that there is capacity building based on the needs of developing countries, considering that is those countries with the least capacities and resources, regional initiatives and those by group countries are in no way in contradiction with capacity building measures undertaken by the United Nations. Nevertheless, they need to be supervised, since they must be in line with the needs of the countries requesting that assistance and should not be subject to any political conditions. There is a need for a diagnosis undertaken by the United Nations to establish a global index of cybersecurity, it would be useful in order to establish and identify needs and priorities. We believe that the problems that need to be given priority for capacity building are related. Basically, with technical issues. Many of these issues are frequently referred to in this group, they are the most significant as I will list here, designing policies and strategies for cybersecurity, the governance of cybersecurity management of cybernetic incidents, and identifying protecting critical infrastructure and awareness of threats, analysis, threat analysis, and also developing platforms and tools for cybersecurity. goober advocates that beyond the efforts by the government, also the academic academic world, the business sector, service providers and civil society should be involved in capacity building initiatives. And they should concentrate their efforts on creating skills to identify in a proactive manner, the threats and deal with them as required and mitigate their impact, and also to develop skills for an effective and rapid resilience. We reiterate that capacity building should not be limited to training. Developing countries also need even more funding and the transfer of technologies which would allow them to assimilate those technologies, manage them and develop them. Mr. Chairman, we insist on the right of all states to have access on a universal basis, which is inclusive and non discriminatory to information and to knowledge related to ICTs. We also demand the lifting of any unilateral coercive measure, which impedes restricts or denies this access. Thank you very much.
Ambassador Gafoor
Thank you very much, Cuba, for your contribution all Uruguay to be followed by Albania.
Uruguay
Thank you very much, Chairman. Uruguay aligns itself with the statement made on behalf of a group of countries by the Argentinian delegation. We’d also thank the distinguished delegates of the Philippines for the presentation of the proposal for a catalogue of Confidence Building Measures, and we will study that. First of all, we would like to welcome the document entitled analysis reconsidering the programs and initiatives of capacity building, within and outside the United Nations at the global and regional scale. This was supported and called for by my country within the context of this working group. That report recognizes various things that my delegation welcomes, and we’d like to echo them. The first is capacity building in the context of ICTs. It is and continues to be one of the most important priorities for states, it must continue to be a basic and cross cutting pillar of all the debates which are undertaken within the United Nations taking into account that in order to make progress and effective way, we need to have the corresponding resources. Number two, not all countries enjoy on an equal basis the benefits of this technology. Therefore, it’s a priority. That capacity building should meet the needs of all states, in particular, developing countries with a view to bridging the digital and gender divide. The opportunities and risks that come from the rapid development of emerging technologies such as artificial intelligence, and quantum technologies will have impact on the needs and priorities of states in terms of capacity building. For example, on full as we improve the detection and analysis of threats, and to respond in an automatic way to these incidents. Here, my delegation supports the international cooperation mechanisms to increase cyber resilience through the transfer of knowledge, best practices, lessons learned and technology. Fourth, the universal character of this working group allows us to avoid duplication of capacity building measures, and to ensure that we have as far as possible, the necessary resources. Therefore, taking into account the inclusions in the route and the report, and many others, as well as the consensus that exist on the importance of capacity building, you’re required considers it relevant to give its support to implementing a permanent framework, which would allow us to generate this in a timely way with sustainable and predictable funding. And this could perhaps be ensured through creating a fund, which would ensure that there is financing through voluntary contributions. Mr. Chairman, this permanent framework that we’ve just referred to, should include with, amongst other things, three initiatives, technical training, tools for combating the malicious use of ICTs, and proposals for advice, technical training could be focused on issues related to security in the iCloud. The training of trainers, industrial security infrastructure, in public key infrastructure and safe development tools to combat the malicious use of ICTs must be linked amongst other things with forensic laboratories, life testing, artificial intelligence applied to detecting instance, as to the possibility of holding consultancy and evaluations, we propose an applied focus to identify and protect critical infrastructure and the themes related to the impact of quantum computing, for example, in digital identification, amongst other ideas, Mr. Chairman, we appreciate the proposal presented by Kenya on a registry of threats, we believe it’s fundamental that they should take into account other initiatives that exist at the regional level, for example, within the Organization of American States, and through the cybersecurity incident response team of the Americas, we actually have an initiative to share indicators, which could be aligned with the proposal that has been made and to ensure that there’s no duplication, establishing a common taxonomy for this registry is a vital importance. And if we make progress in this regard, we need to provide ensure that there is a specific segment to define and catalog the threats and incidents. With regard to the proposal submitted by India in the earlier session, we believe it’s important to avoid duplication of efforts with other portals that already exist, for example, in what is referred to in module five of that proposal, we could have a joint proposal with that made by Kenya to ensure that we have include both initiatives in one single initiative. Finally, Mr. Chairman, I would like to express our appreciation for the capacity building initiatives now underway, offered to the membership, which have taken place within the context of this group. They provide added value for our countries in our capacity building. Thank you very much.
Ambassador Gafoor
Thank you Uruguay for your statement Albania to be followed by Kingdom of the Netherlands.
Albania
Thank you, Mr. Chair for giving me the floor. Dear colleagues, the foundation of enhancing a cybersecurity posture for Albania lies in setting up resilient system and cultivating a well trained workforce. As digital threats evolve, the importance of human expertise in managing and mitigating these risks should be in the focus. Albania has made significant steps in responding to cyber incidents. The national authority responsible for cybersecurity has adopted a forward thinking and reactive approach to offensive security and fostering a culture or information sharing. Albania’s approach to achieving this vision of a very trained workforce is it has several is multi phased focused on both immediate and long term strategies and to build a resilient cyber defense force. This initiative is structured around a strategic plan that unfolds in several phases, targeting different sectors and educational levels to ensure a wide region impact. In the initial phase, the focus is on establishing a pool of cyber experts drawn from various sectors, including government and critical information infrastructures in the training of trainers format to lead and mentor the next generation of professionals. This phase addresses the immediate need for skilled professionals to defend against cyber threats. The capacity the capacity building on the Human Resources is in the last two years has been supported from international expertise. And Albania has a strong need to continue with this support. For 2024 alone, at least the 1000s of professionals will be trained in a good portion it will be trained now offered from the public and private sector, from own from our own expertise at the national authority of cybersecurity, and in small numbers. But for Albania, it’s very important and significant. We have a number of experts who have reached the capacity of training and sharing their experience internationally as well. As part of capacity building, our experts have been supported to participate in numerous events, training conferences in the international arena to exchange infos and best practices supported from EU, EU member states, OSCE United States, NATO group members Global Forum on Cyber Expertise, UNIDIR, Israel, Saudi Arabia, we have been able to be participating in all those events. Even the last example is clear myself and plus 40 Women in Cyber would not be able to participate in this excellent week of Open-ended Working Group without the support of international partners. The second phase, the strategy expense to incorporate higher education institutions, encouraging them to develop their own cybersecurity programs. This enhances the academic landscape in Albania, and set a precedent for Regional Cooperation in cybersecurity education. Albania is committed to developing a robust cybersecurity education and training ecosystem. This commitment will be embedded in the establishment of the National cybersecurity Academy and initiative designed to prepare the next generation of cybersecurity experts for Albania. In parallel, the efforts will focus on integrating cyber city security education into the curricula of primary and secondary education. We would like to ensure that future generations are equipped with the basic skills necessary to navigate and secure the digital world. This long-term vision underscores the importance of CyberSecurity awareness from an early age, laying the ground force for a society that is both knowledgeable and vigilant against cyber threats. In the same terms Albania’s vision extends beyond safeguarding its own digital frontiers. It aspires to become a cybersecurity hub in the Western Balkans, sharing acknowledges and experiences especially of the last years with neighbor countries, to foster a culture of cooperation and knowledge sharing across the region. We are currently promoting and participating in a number of regional programs in the Western Balkans. The establishment or National cybersecurity Academy will allow Albanians commitment to not just defend its own digital infrastructure, but also contribute to cybersecurity resilience in the Western Balkans. We are committed to push forward this initiative in enhancing the Collective Security making the Balkans a stronger and more united front against cyber threats. This vision serves the regional empowerment, demonstrating how shared challenges can lead to share solution and stronger bonds between the nations. Last but not least, Albania’s dedication to cybersecurity extends to protecting its younger citizens in the digital space. Despite the constraint of a small team, Albanian national authority access has ambiguously planned numerous activities throughout the country during the entire year and in the future, in The focus will be child online protection and awareness for parents, teachers and school security and social workers. This multifaceted approach underscores Albanians determination to secure its digital landscape and safeguard all users, affirming that a small size of a country does not limit the scope and the effectiveness of a national cybersecurity effort. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Albania, Netherlands to be followed by United States.
Netherlands
Thank you very much chair. The Ne therlands aligns itself with the statement delivered by the European Union and I will make some additional remarks in my national capacity. To ensure free open and secure digital world, all states should have access to resources, knowledge and skills they need to invest in a digital future. To this end, a large number of states regional organizations and stakeholders came together in Accra last November for the global conference on cyber capacity building. The critical and important outcome of the meeting aims to stimulate a global action to elevate cyber resilience across international and national development agendas, as well as to promote and cyber capacity building that supports broader development goals. The Netherlands signed a call and encourages others to do so to do the same chair, I would like to thank the UNIDIR for conducting the mapping exercise on cyber capacity building efforts, the Netherlands was pleased to see the wide range of capacity building initiatives undertaken by states and state stakeholders. As the report highlights, it’s essential that cyber capacity building effectively serves the needs and priorities of all states, particularly developing countries with a view to closing the digital divide, as well as the gender and digital divide. The Netherlands believes that agreed language in the second APR on the need for gender responsive cyber capacity building is an important step forward in bridging the gender digital divide. Agenda responsive approach focuses on specific actions with programming to try and reduce gender inequalities. In response to your guiding question, on the tools available in this regard, we would like to highlight that the Association for progressive communications, UNIDIR, Chatham House, and GFCE are some of the organizations that focus on gender mainstreaming in the cyber domain. For example, the Association of progressive communications worked on a framework for developing gender responsive cybersecurity policy, including cyber capacity building. Apart from these initiatives, states could also draw upon relevant tools and frameworks from the women peace and security agenda, and the Committee on the Elimination of Discrimination Against Women. Chair, I would like to thank the Philippines for the presentation on the interesting proposal for a catalogue. Furthermore, the Netherlands continues to study with interest a proposal for a global cybersecurity cooperation portal, and wishes to extend his appreciation to India. For putting the proposal forward. We shouldn’t see merit in a practical tool to make information concerning the work of the Open-ended Working Group of available in one place. Such an initiative could make effective use of the UNIDIR Cyber Policy Portal, which is also linked to the Cybil portal of GFCE. Both contain a lot of useful information on style, safe state cyber policies, strategies, and capacity building initiatives and programs. Lastly, Chair allow me to address your guiding question regarding tools to assist states and mainstreaming to capacity building principles contained in Annex C of the second APR. We look we’d like to highlight the useful contribution of Chatham House in this regard. Yesterday Chatham House organized a round table to collect feedback from states and stakeholders on the work on the upper section of the principles. The round table on the light on the line the interconnectedness of the 10 principles and the need to see them in conjunction with each other. By advancing a common understanding of the principles, we could foster the implementation of the principles with capacity building cooperation. We look forward to the report that Chatham House will publish on on this later this year. Thank you very much.
Ambassador Gafoor
Thank you very much, Netherlands for your statement, United States to be followed by Russian Federation.
United States
Thank you Chair. First, I wish to express my thanks to the Secretariat for its work on the capacity building mapping exercise pursuant to last year’s APR. As is apparent in the report, there is significant ongoing activity in this space. Many governments regional bodies, civil society organizations and other institutions are already offering assistance of various types. We encourage states to use this report as a resource when seeking to develop or receive capacity building assistance. The United States views the evolving and complex landscape of cyber capacity building efforts as a source of optimism. Increasingly, we are seeing global development institutions take up cybersecurity as a major line of effort. The United States provides financial support to the World Bank, which is issuing hundreds of millions of dollars in loans for states to build up their cyber capacity. We and dozens of other states have endorsed the Accra call that encourages mainstreaming cybersecurity in digital development circles. at the regional level, great work is being done through the OAS OSCE, ASEAN, and the ASEAN Regional Forum and the African Union among others. Regional cybersecurity centers of excellence are being established all over the world, and serve as useful hubs for coordination, information exchange, and sharing of best practices to build capacity. Through multilateral regional and bilateral initiatives, the United States has provided more than $300 million dollas in cyber capacity building assistance to countries around the world. We are proud to have worked with many of you on these efforts. We also welcome the investments made by technology companies and other stakeholders to cyber capacity building from immediate support in the aftermath of a serious cyber incident. To long-term efforts that strengthen domestic cybersecurity ecosystems. We ask all stakeholders including states to consider ways in which the good work that is being done at the OEWG can be absorbed by the cyber capacity building community, as well as how that community can offer feedback and expertise on capacity buildings practical implementation. We also urge States seeking to enhance their cyber capacity to start with needs assessments. This often includes an assessment or an internal mapping of existing policies and structure. And there are a number of helpful models to guide states through this practice. The OEWG’s role in capacity building is directly related to implementing the framework of responsible state behavior, helping us deepen our understanding of what we collectively need to achieve for increased international peace and security in the field of cybersecurity. As we have heard from many states in the room, discussion of implementing consensus, norms and competence building measures, naturally leads to consideration of capacity building as a requirement for some states to accomplish these goals. Developing an understanding of how international law applies to state activity in cyberspace and drafting of national positions on international law, similarly implicates capacity building for many states. As we mentioned in the norms discussion, there are a number of fundamental competencies states require to enable their engagement as active and responsible cyber actors at the transnational level. The set of competencies has been recognized by the UN for more than 20 years, including the UNGA resolutions 58/199 and 64/211. On the creation of a global culture of cybersecurity. These competencies include the creation of CERT, creation of national strategies and policies, including with regard to national critical infrastructure, and the development of public private partnerships. We welcome more discussions on how to ensure the availability of needs based capacity building to improve global cyber resilience, including at the chairs capacity building roundtable on meeting on May 10. In that regard, I want to express my thanks to the Philippines for its proposal, particularly its needs based approach, and we look forward to discussing it and other proposals further. Thank you, Chair.
Ambassador Gafoor
Thank you very much United States for your statement. And also for your update on your own bilateral activities and contributions. Russian Federation to be followed by portugal.
Russia
Mr. Chairman, we consider capacity building in the field of ICT security. is one of the key aspects of the OEWG’s mandate. We assume that our work in this area should result in the elaboration of a practice oriented recommendations and proposals for assistance programs. It’s important to ensure that such measures meet the needs of states and are in lines with the universal principles in this field, as set out in the annex to the second report of the group, particularly with regard to respect for state sovereignty. We take note of the vigorous efforts by the chair of the OEWG in particular, the initiative to hold a global round table on the issue of capacity building in the field of ICT security on the 10th of May this year. For our part, we are currently working on the level of participation composition of the Russian delegation at that at the event, we expect it to be held in a professional and deep politicized manner, with due respect to the central role of states and with the participation of other interested parties. In this context, we would like to comment on the mapping exercise to survey the landscape of capacity building programs initiatives within and outside the United Nations at the global and regional levels conducted by the United Nations Office for Disarmament affairs. We regret to note that we have serious concerns about the document, both in terms of its content and structure in Russia, as well as a number of states has provided an extensive national contribution to the paper, which unfortunately has not been adequately reflected there in. Moreover, we have noticed of this bias in favor of efforts by certain countries, while many other states listed among the participants of the mapping exercise are either mentioned briefly in the text or not named at all. We do not see any logic in the current division intersections, two main substantive segments regional cooperation and thematic areas. As a result, the document represents a confusing compilation of odd ideas contains repetitions. We do not understand the reason why certain sections of the document cover such issues as gender, and youth which are highly controversial for virtual and even not related to the matter mandate of BYD, or OEWG the subsection on international law mainly cites the approaches of states and organizations without specifying efforts to assist countries in developing national positions in this regard. Finally, it’s completely unacceptable for us the fact that the contributions of states that play the central role in the negotiation process are mixed up with the opinions of international and regional organizations, and let alone private entities. In general, the current version of the mapping exercise requires radical revision. We suggest structuring this document with the assistance providers. That is states international organizations, regional sub regional organizations, the private sector, and specific forms of such assistance, that is seminars, research and development, personnel training, technology transfer, etc. We expect an updated version of the document will be prepared and distributed promptly, so that states may be able to familiarize themselves with the final product well ahead of the roundtable to be held in May. As for Russia’s efforts in the field of capacity building, our country pays special attention to this matter. This issue has a prominent place in the Russian annual draft United Nations General Assembly Resolution on international information security, which tasks the Open-ended Working Group to develop specific mechanisms to meet the needs of states in this regard, including financial needs. In our national capacity, we focus on personnel training in the field of information security of foreign students from countries in Asia, Africa, the Middle East, and Latin America study Russian universities within the main programs of higher education and additional of professional education, we expect that comprehensive information on this matter will be reflected in the updated edition of the mapping exercise, as was indicated in our contribution. Thank you for your attention.
Ambassador Gafoor
Thank you very much Russian Federation for your statement. Your comments are well noted, with regard to the paper prepared by the secretariat. And I just want to say, first of all, that this is a paper prepared by the Secretariat in response to a mandate by the working group. So it’s not an intergovernmental document, nor was it prepared by the chair in the capacity of the chair, so to put things in perspective. And to be fair to the Secretariat, they have prepared this report as they saw appropriate, and I had no role and nor did any members have any role in that. So let’s respect it as an input from the secretariat. That’s point number one. Point number two, all the inputs that were sought, with regard to drafting this report are reflected in the website on the OEWG. So I would also draw the attention of all member states to look at the input that was submitted by Member States, which led to the drafting of this report. So the primary material for the drafting of the Secretariat paper, is on the website, and the Secretariat has confirmed it. Now, it is a challenge for anyone to draft a report, and there are many ways to do it. So I’m not as Chergui to make a judgment on the paper, I think it is, for each one of us to look at it, and come to our own conclusions as to how it helps us, and whether it helps us. So I leave that to you. But I will also add that if members feel that they’re missing elements, then I would encourage members to submit their inputs, and these submit additional inputs that are missing. And these inputs can be reflected also on the web site, I think we have to take the approach of constantly seeking information, constantly enriching ourselves with additional information and constantly trying to enhance our understanding and knowledge, not just of the capacity building landscape, but across the board. As to whether the secretariat will be able to issue a revision? I do not know, I am not sure in. Firstly, I don’t think it’s the standard practice. But you know, I think the secretariat will take it back. And secondly, I don’t think you have any funds to write another report. The UN is in the middle of a liquidity crisis. So I just wanted to put that in context, Russian Federation, your points are well noted. But I think the report does serve the purpose of giving people an overview of the landscape. And if there are missing elements that you think ought to be underlined, to send your additional inputs, and then we’ll find a way to have it reflected in the OEWG website. And I would also encourage all of you to submit additional inputs, because when the inputs was sought for this report, and this report is issued, I think maybe about 30 countries submitted inputs. So it’s not all 193. So there are members who have not submitted inputs for this mapping exercise report, and you think that you having read the report, you want to submit your own inputs, please do so. I think this working group is about sharing information. So there is no censorship, certainly not on the part of the chair. And no, there’s no reason why we should restrict the sharing of information. So those of you who have not yet submitted inputs and you want to share additional inputs, please do not hesitate to hesitate to do so. But I also note that many of you are already sharing information in your interventions about what you’re doing. Different countries already talking about what they’re doing in terms of capacity building pad is also information that is also good. So in that sense, this discussion is also another mapping exercise, because we are sharing information. So this mapping exercise is not a static document, it is a snapshot of a photo, the landscape is evolving, the tides are moving. And we are hoping for a wave of new capacity building offerings. We don’t want a tsunami. But a wave would be a good start of capacity building. Supply, which is there already. But also from the point of view of demand demand is there, I think there is also a wave of demand for capacity building. And I think within the Open-ended Working Group, we also need to have a clear mind because this is a working group that’s focused on with a very specific mandate from the First Committee. The digital divide is a big thing, I’m not sure that this working group can bridge the digital divide, and is not a fair burden on this working group to resolve the digital divide. I’m not even sure that the second committee can do that, with due respect to our colleagues in the second committee, but you know that there is a discussion at the UN on a global digital compact. So this digital issue is taking place in multiple fora. So we in the working group, we need to be very focused in terms of what we can do, what are the very concrete steps we can do in the area of capacity building, how we can support implementation of the decisions we have taken in the context of the Open-ended Working Group. The framework of rules, norms and principles, Confidence Building Measures, the discussion on threats, the need to understand international law. So we need to be focused in prioritize. So thank you very much Russian Federation. For your statement, your comments are well noted. And I think it’s good that there any additional information that members wish to share, we should encourage that. So let’s let’s work on that basis. Very good. Let me see. It’s a very long list of speakers. So I’ve decided to extend the meeting to Saturday. I was just saying that to check whether you were all really paying attention. It looks like you are indeed listening to me. No, we will not be meeting on Saturday. But we need to wrap up by the end of tomorrow. But I think we do have time to cover all the issues that we need to cover. So we’ll continue with the list of speakers for capacity building. And we’ll see how far we can go today. Portugal to be followed by Singapore.
Portugal
Mr. Chairman.
Ambassador Gafoor
Microphone please.
Portugal
Okay, so I’m sorry, Mr. Chairman, Portugal aligns with European Union intervention on capacity building. But we just like to add not a statement but only a very brief comment on the roundtable, which you invited us to attend on the 10th of May here in New York. Portugal concurs that the time is ripe. To gather around the table high level national government officials responsible for digital transition, cybersecurity, and capacity building. These representatives should come to New York to meet their counterparts from other member states. And when required and possible, enter a new, constructive bilateral relations with review to learn from each other and assist in improving their mutual capacity to comply with the framework for Responsible state behavior in cyberspace in all its components, we are having general elections this Sunday, and therefore do not know yet who will represent our country. But your invitation letter was forwarded to the current member of government who has the double portfolio of digital transition and cybersecurity with a recommendation that his or her successor should head our delegation, which should also include the heads of our National cybersecurity agency and of our development agency. We know that our recommendation was well received by the three of them. And therefore that the current member of government with that responsibility will exhort his or her successor to come and bring along those two agency leaders. We trust that these high level roundtable will be a success becomes a habit, and at the largest at a later stage will also co opt systematically, representatives of other interested parties. Thank you, Mr. Chairman.
Ambassador Gafoor
Thank you very much particle for your statement. I very much appreciate you giving us an update on your efforts internally to bring the letter of invitation to your government. If you do need a new invitation address to a newly appointed Minister. If you are in need of such a letter to approach my office, it’s a serious offer I prepared to prepare a very specific invitation letter address to who you think it would be appropriate when a new government is successfully formed. And that invitation also applies to all of you. If any of you here as you navigate that invitation to your respective ministries, ministers, cabinet officers, bureaucracies, cubicles, hierarchies. If you think that a specific letter addressed to a specific minister would help in your exercise of bringing the letter to the most appropriate high destination, please contact the chess team. And I’ll be very prepared to do a personally signed letter with some personal remarks at the end and salutations to all this in an effort precisely as you say, Portugal, we have to make this a success. And we have to make this a habit as well. Thank you very much for your comments. Let’s go on with the speaker’s list, Singapore to be followed by the Islamic Republic of Iran. Thank
Singapore
Thank you, Mr. Chair. Capacity building by its nature should be demand driven to ensure that participants receive training in the fields required to effectively raise the baseline capabilities of all regions. In this regard, we should seek ways in which the experiences and best practices of capacity building work done in capacity building centers across the globe can be shared with each other. In this regard, the Philippines proposal on a needs based cyber capacity building catalog is a useful one and could be explored and developed further. Mr. Chair a key part of capacity building is also to support the ongoing development of senior civil leaders at a national level with a strong appreciation of the policy, operational, technical, legal and diplomatic aspects of cybersecurity. Singapore is doing this in collaboration with Singapore is doing such training in collaboration with UNODA, on the UN Singapore Cyber Fellowship. This capacity building program is a holistic one, cutting across various disciplines of cybersecurity. Today, we have an alumnus of over 70 Senior cyber government officials from 62 Member States. We also recently launched our Singapore Cybil leadership and alumni program, which will be extended to ASEAN states as well as states outside the region. We are looking forward to deepen our networks of exchange to collectively build the global capacity to address evolving cyber threats. The global cyber capacity building roundtable organized by the chair in May, is also a good platform for us to do so. This would allow for a focus discussion to provide useful guidance on specific capacity building required to address the current cybersecurity threat landscape. Other suggestion suggestions from international partners, such as India’s global cyber security cooperation portal could also be a possible means to facilitate threat information sharing and matching capacity building efforts, reason needs based assessment surveys and prior interventions by fellow states and I’ve also highlighted the need for assistance in cert focused capacity building programs. We look forward to contributing towards the capacity building efforts to onboard colleagues who are new to the POCs network. Working together closely on this will allow us to share best practices and efforts to ensure the efficient and effective implementation of the POCs directory. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Singapore for your statement and also for an update of your various activities in this domain, Islamic Republic of Iran to be followed by Italy.
Iran
Mr. Chair, thank you for giving me the floor. In response to your guiding question. Regarding the United Nations additional role in the providing coordinating or facilitating capacity building efforts, my delegation would like to express the following. Despite the OEWG acknowledging that capacity building is a topic that cuts across all the pillars of its work, and recognizing that indispensable, and recognizing the indispensable need for sustainable, effective and affordable solution. It is regrettable that the capacity building section of the first and second APR was substantially substantially undermined, reduced to mere coordination among among existing initiatives. Throughout the OEWG discussions developing countries have consistently emphasized the need to establish a dedicated assistant program on phone for ICT security within the United Nations. To ensure comprehensive, fair and depoliticize provision of assistance. The effectiveness of the ICT security capacity building can be enhanced by an inclusive and holistic approach that entails both both establishing a specific un ICT security capacity building mechanism and coordination of existing capacity building efforts outlined in the comprehensive mapping exercise of the secretariat. Mr. Chair, thriving on the formation considerations, we contend that the idea of establishing a permanent mechanism for capacity building for ICT within the United Nations holds considerable merit and warrants discussion within the ongoing OEWG deliberations. The importance of this important mechanism which should be guided by the principles contained contained in paragraph 56 of the first OEWG could include inter alia some concrete measures that have been already identified by consensus in paragraphs 59 to 61 of the 2021 OEWG report. We are of the view that the OEWG could also consider the potentials of the International Telecommunication Union, which is the United Nations a specialized agency for information and communication technologies to leverage capacity building. The ITU could be invited to provide a briefing during the dedicated global roundtable meeting on ICT security capacity building. Mr. Chair, We echo the concern you raised at the conclusion of the morning meeting, that if we take a wait and see approach, then delivery or capacity building may not begin as soon as it should. You encouraged all of us to see what we can do in a step by step by a survey by July 2024. In light of this new proposal, that is discussion paper, after learning the essential elements of a dedicated un ICT security capacity building mechanism be prepared by the chair to serve as a tool to facilitate further focused discussions on the issue of capacity building and to help us find the path forward towards a consensus on this important matter. Finally, it would be unjust to conclude my statement on capacity building without expressing gratitude for the UN Singapore fellowship program. This initiative serves as an exemplary model for establishing a dedicated fellowship program under the United Nations is specifically tailored for ICT related training and education. I thank you Mr. Chair.
Ambassador Gafoor
Thank you very much Islamic Republic of Iran for your statement and as well as for your suggestions which are well noted. Italy to be followed by the United Kingdom.
Italy
Thank you, Mr. Chair for giving me the floor. We fully align ourselves with the statement delivered by the European Union. I will add the following elements in my national capacity. The growth of cyber threats together with the awareness of the need to protect ICT systems and build more resilient cyber environments and has led to increasing demands for capacity building activities and programs. capacity building activities do not only help building safer and more resilient systems and protect critical infrastructures. They also directly contribute to the adherence to the UN framework of responsible state behavior. In the cyberspace. Capacity Building is an enabler of cyber resilience of states fast contributing to economic growth and prosperity. Capacity Building shall be sustainable a transparent process, demand driven based on mutual trust in carried out in respect of human rights and fundamental freedoms. The gender perspective shall also be considered in carrying out such activities. Capacity Building is a confidence building measure itself and should continue to be at the center of our works. Italy grant great importance of the capacity be Italian cybersecurity strategy contains specific measures on development of cyber capacity programs, both at bilateral and international level with with involvement also of private sector, Italy and knowledge the role that international financial institutions and the World Bank in particular play in fostering the achievement of capacity building objectives. We welcome the mapping exercise to survey the landscape on capacity building programs and initiatives which provides an important overview of existing programs both at multilateral and regional level. We will want to take this opportunity to praise regional initiatives such as the Accra call for cyber resilience. You share the objective to elevate cyber resilience and ensure that cyber capacity building is designed and implemented in a way that contributes to development goals. We look forward to the first global roundtables on capacity building, scheduled for next May, with his potential role to build new partnerships facilitate multi stakeholders involvement, and share best practices and ensure complementarity with existing national and regional initiatives. Thank you.
Ambassador Gafoor
Thank you very much, Italy, United Kingdom to be followed by South Africa.
UK
Thank you Chair. I’d like to begin by thanking the delegation of the Philippines for their presentation, which we will study further. Chair Tomorrow marks International Women’s Day, celebrating the social, economic, cultural and political achievements of women. My delegation would like to address your guiding question on gender perspectives, and reflect on the relevance of gender and inclusion issues in the context of cyber threats and capacity building, both in the United Kingdom and internationally. My delegation is troubled by the use of cyber capabilities by state actors to exploit social divisions based on gender, ethnic and religious identities. We are equally concerned about increases in repressive cyber activity, targeting politically active women and human rights defenders. Chair this trend is part of a wider, persistent effort to undermine democratic systems and open societies. Non Governmental Organizations are often targeted as part of this trend. In a 2023 survey of nongovernmental organizations by the cyber cyber Peace Institute, over 40% has been a victim of cyber incidents. And a 2023 report by Microsoft found that think tanks and NGOs were the third most targeted sector by state sponsored threats. The International Center for journalists estimates that 40% of Women Journalists have been exploited by cyber activity while carrying out their work with 20% reporting physical violence as a result. With these trends in mind, we support Fiji suggestion for further discussion of the cyber threats affecting women and vulnerable groups. domestically in the UK, we recognize that the equal participation of women in the cybersecurity sector is directly related to our ability to recognize and tackle the cyber threats faced by women are so cyber first initiative aims to develop a skilled and diverse pipeline of talent. Since 2017, 56,000 girls but Between the ages of 12 and 13 have participated in the cyber first girls competition. Chair to protect open societies and democratic systems. We’re working with international partners to deliver effective cybersecurity capacity building for civil society and other high risk communities. reliable data shine shining a light on the scale of malicious cyber activity, targeting vulnerable communities and civil society organizations remains a challenge. Cyber Threat Intelligence companies do not typically focus on threats to civil society, resulting in lower priorities prioritization of the cyber threat that they face. Research conducted by several organizations, including Citizen Lab at the University of Toronto cyber Peace Institute, and the Center for long-term cybersecurity at the University of California, Berkeley, is helping to provide a more complete picture. These organizations applied to be accredited to the OEWG, but were blocked by Russia. This represents a needless hindrance to information sharing on this topic at the OEWG. Chair despite this challenging context, this OEWG remains a positive reminder of what is possible with the strong participation of women. The United Kingdom is a proud donor of the UN Women in Cyber fellowship. And we commend the work of women in all their divided diversity, who are shaping the governance of cyberspace. Thank you.
Ambassador Gafoor
Thank you, United Kingdom for your statement, South Africa to be followed by Australia.
South Africa
We thank you for the guiding questions, and we wish to share our thoughts on some of them. Firstly, as we examine some of the foundational capacities required to detect, defend against and respond to malicious ICT activities, it is of utmost importance to recognize the central role of CERTs in this. This institutions need to be adequately capacitated. With regards to technology and skills, they should enjoy political leadership for efficient execution of their functions. In our view, fostering a culture of cybersecurity awareness for a clear understanding of cyber risks within ICT networks. Establishing policies and procedures. capacity to conduct cybersecurity risk assessments are some of the foundational capacities required for states to adequately address malicious ICT activities. Furthermore, it is a must to possess technical capacities to monitor ICT networks for early detection of threats, coupled with implementation of technical measures to protect against the exploitation of vulnerabilities and to prevent unauthorized activities. It is also crucial to have a comprehensive incident response plan to provide guidance in the event of a cyber attack. This foundational capacities can be used to inform a more strategic approach to capacity building based on the real needs of the recipient country, thus addressing the specific demands of that country. This will help member states to move away from supply base to needs based capacity building programs. With regard to tools to assist states to incorporate gender perspectives into capacity building tools, our delegation is of the view that such tools should go beyond just equal participation. And that emphasis should be on cybersecurity decision making processes that are based on gender responsive data and policies. We believe that it is crucial as people use and are impacted by digital technologies in different ways. And that’s cash should be given to designing a secure and stable cyberspace that takes into account different experiences, needs and priorities of those who use it. Also, such tools should avoid replicating the social inequalities by challenging gender stereotypes. Finally, Chair On the additional role the UN can perform in relation to capacity building efforts. We are cognizant of the role the ITU. The UN specialized agency responsible for ICTs has as part of its mandate. The ITU conducts a number of activities, ranging from support in the establishment of harmonized ICT policies to conducting cyber drills in different regions worldwide. Similarly, other UN agencies such as the UN Development Programme and the UN ODC play an active role in this space. Our delegation believes that the UN has a central role to play to increase international cooperation among cybersecurity capacity builders, thus avoiding duplication of efforts and maximizing the available limited capacity building resources. In this vein, we support India’s proposal for the establishment of a global cybersecurity cooperation portal. And we have taken note of the presentation by the Philippines and who was studied. Thank you Chair.
Ambassador Gafoor
Thank you very much, South Africa for your contribution. Australia to be followed by Republic of Korea.
Australia
Thank you very much chair, Australia first echos the statement that you made in your opening remarks chair that capacity building is a cross cutting issue underpinning all the pillars of our framework, and providing the basis upon which our work to advance and implement the framework of responsible state behavior being international law norms, and building trust and confidence, advancement and universal implementation of which relies upon sustainable targeted co designed and inclusive capacity building efforts. Australia commends the recently published mapping exercise conducted by the Secretariat to survey the landscape of capacity building programs and initiatives, we welcome the reflection in the report that diversity and in particular gender mainstreaming has become a global priority for cyber capacity building issue initiatives and forms part of the existing cyber capacity building landscape. Like many Nigeria, Fiji, Qatar, Uruguay, the Netherlands, United Kingdom, and most recently, South Africa, have mentioned today and to many others over the course of the weekend during our previous sessions. Australia recognizes that people engage with cybersecurity issues in different ways. And this group’s efforts should continue to consider gender equality, and provide examples of incorporating agenda perspective into capacity building efforts. The Secretary, the Secretariat mapping report, usefully sets out regional, sub regional and cross regional cooperation on capacity building initiatives, as well as an initiative, an illustrative overview of capacity building initiatives with thematic areas of focus. And we very much appreciate the focus on international law, given so much of the focus of our discussions on capacity building for international law, particularly this week. And the mapping report demonstrates that cyber capacity building and the ecosystem is a rich and diverse one. cybersecurity is not something that states can achieve alone. Neither can capacity building be effective if it is performed by States alone. And it re-emphasizes to Australia, a very core aspect of this Open-ended Working Group, which if one were to play, OEWG bingo, I believe would represent a center square on every bingo card, and that is that we are not starting from scratch. There exists and has existed for some time, years and decades. In some instances, technical cyber assistance programs that aim to increase cybersecurity of all countries to narrow the digital divide and build resilience for all countries to protect and to mitigate the effects of malicious cyber activities. And we welcome the recognition of the considerable work work both within and also outside the UN to identify cyber capacity building needs and deliver technical assistance to meet some of these needs. Some of these efforts have already been mentioned this afternoon. Australia supports the Accra call and the people see the inaugural cyber Pacific cyber capacity building and coordination conference which was hosted in Fiji last year. Bilateral relationships and bilateral efforts, like the recently signed Memorandum of Understanding mentioned by my dear friend and the distinguished delegates of the Philippines, about the MOU between Philippines and Australia signed only hours ago, which aims to build diverse skills and strengthen connections between our two countries. And the cybersecurity capacity building model which was also mentioned by Rwanda. But the mapping exercise also underscores another theme of our work here in the OEWG and that is just like norms implementation and developing national positions on the application of international law and continuing to exercise CBMs to maintain trust. Cyber capacity building is not something that is actioned once ticked off and then done, like everything in cyberspace and in peace and security efforts. Generally, cyber capacity building priorities and needs evolve, just as technology evolves, just as the threat environment evolves and our framework to address those threats also deepens. I think that the Secretariat mapping exercise is particularly valuable in this regard promoting the identification and deeper understanding of the needs of developing states for specific capacity building efforts, with the aim of narrowing the digital divide and uplifting security and resilience. This work to identify evolving capacity building needs and gaps remains ongoing and important to fast track here in our OEWG in parallel with other forums as eloquently explained by Fiji earlier this today, the cyber capacity building and coordination conference P4C provides a helpful model bringing together all the relevant parties and actors with the aim of recalibrating the priorities of the Pacific Island countries and understanding what’s working, what’s not working, why it isn’t working, and to streamline capacity building so that it is effective and impactful. And we welcome further efforts within this Open-ended Working Group to identify the most drought stricken areas towards which we should be directing the capacity building wave. Regarding our future work in the OEWG Australia considers this to be a unique position to collect experiences, collecting our mistakes, our successes and our lessons learned in providing and receiving and participating in organizing capacity building programs. Collecting these experiences into guidance for how we interpret and implement the principles. We’ve already agreed for capacity building which was annexed to our 2023 annual progress report, including through complex, complex and concrete examples. So that capacity building programs and efforts directly relevant to our framework, implementing the norms and international law and operationalizing Confidence Building Measures are consistent with our agreed overarching principles. And we welcome new ideas to help us collect and present collective experiences and expertise to this group to make capacity building more efficient, including the proposal by the Philippines this afternoon, which we will consider closely. Australia looks forward to the high level roundtable in May to continue this discussion and raise awareness at the highest levels of the issues and the avenues that we are working on here to address those issues of cyber capacity building to maintain international peace and security in cyberspace. Thank you, Chair.
Ambassador Gafoor
Thank you very much Australia for your statement. Republic of Korea to be followed by Brazil.
South Korea
Thank you chair. Capacity building has a cross cutting nature in promoting an open, secure and peaceful ICT environment is the gap among countries widened. It will exacerbate vulnerability to emerging cybersecurity threats. The group should encourage the incorporation of capacity building program efforts in legal and policy realm as well as technological capacity. My delegation will come to the Secretariat to paper of the mid mapping exercise to survey the landscape of capacity building and would like to share some of Korea’s diverse capacity building measures. In collaborations with USAID Rok is carrying out the capacity building development project for nurturing cybersecurity professionals in Indonesia, aiming to establish a cybersecurity Job Training Center. Additionally, together with the World Bank and the Global Forum on Cyber Expertise, Rok provides training on combating cybercrime for legal experts in the Asia Pacific region through the Asia Pacific cybercrime capacity building hub regarding the global cybersecurity cooperation portal, my delegation is of the view that the portal will help countries easily access to a wide range of information, including POC directory key documents, cooperation programs and events as a one stop shop, one stop shop tool for state. We also appreciate the effort of the Philippines for detailed presentation of needs based capacity building catalog, or even so we should thoroughly review the existing tools to minimize the financial burdens, and creating a new institutions can be considered if it cannot be done otherwise. In this regard, the functions of the portal could be embodied and integrated into existing tools. such as the Unity or Cyber Policy Portal. Thank you.
Ambassador Gafoor
Thank you, Republic of Korea, Brazil to be followed by Greece.
Brazil
Thank you very much, Mr. Chair. Brazil aligns itself with the statement made by Argentina on behalf of a number of Latin American countries and would also like to add a few comments in its national capacity. building capacities in the field of ICT security is the foundation for all Tareekh the socio economic benefits from digital transformation in a sustainable way. The digital divide renders international cooperation in urgent imperative to expand the capacity of states to mitigate risks and respond to cyber incidents. And this context Capacity Building has rightly been recognized as a cross cutting element of the entire OEWG mandate, and constitutes a confidence building measure in and of itself. Brazil Welcome to the mapping exercise mandated by the second APR to serve the global landscape of capacity building programs and initiatives and sent its contributions. We welcome the publishing of the compilation report by the Secretariat and hope it will help optimize synergies and avoid duplication of efforts resulting in more effective international cooperation with a more efficient use of resources. Brazil also welcomed India’s detailed presentation on its proposal on a global cybersecurity cooperation portal in December. And we also thank the Philippines for the presentation earlier this afternoon on the needs based capacity building catalog that would integrate that portal. Having a single portal to be hosted at the UN website to concentrate cooperation information, including capacity building, would greatly facilitate access to the available information on this issue. The UN must play a larger role in capacity building on cybersecurity, the UN Singapore fellowship and the many units your conferences and seminars are of great value. But an even greater involvement is needed. centralizing the many existing capacity building initiatives would facilitate access by those who need them by concentrating all possibilities in one place. More importantly, having the one take part in those efforts will ensure a closer alignment with the priority issues identified by the oil WG and better compliance with the Capacity Building Principles adopted by the second APR. As stated in principles capacity building must be needs based respectful state sovereignty and designed and implemented in a collaborative manner by all parties. It must not be implemented in a top down manner, but in a negotiated way, so that it is mutually beneficial to all parties involved. Therefore, Mr. Chair Brazil is very supportive of your decision to convene a ministerial roundtable on capacity building on May 10, and are making the necessary arrangements to secure a high level representation. Given the rapid, evolving pace of digital technologies developing and retaining enough qualified personnel is an ongoing challenge, and even more so from a gender race and disability sensitive lens. Ensuring that women and persons relocating to other historically marginalized populations are duly qualified in this field is essential to more secure cyberspace. In conclusion, Mr. Chair, things are connected and transnational nature of cyberspace means that security is even more of a collective endeavor than in other arenas. No country can be safe from threats in the digital domain in isolation, we are only as strong as our weakest link. Therefore, capacity building will continue to play a crucial role in our common goal of an open, secure, stable, peaceful, accessible ICT environment. I thank you.
Ambassador Gafoor
Thank you very much, Brazil for your statement Greece to be followed by Israel.
Greece
Thank you, sir, for giving me the floor. Greece fully aligns with the statements delivered by the European Union. And we would like to make the following remarks in our national capacity. Mr. Chair, distinguished delegates, it is our view that capacity building is not only a national effort, and adequate resources is not the only prerequisite for developing and maintaining a high level of cyber resilience. The global industry beated nature of cyberspace and the gap in expertise and capabilities between states make international cooperation of this topic a necessity. Furthermore, we fully subscribe to the view that capacity building is a confidence building measure. International cooperation and capacity builds trust, transparency and predictability and facilitates easier information sharing and cooperation when cyber incidents take place. In addition, the exchange of experiences and best practices in capacity building also creates common understandings on the implementation of the framework of responsible state behavior. With all this in mind, Greece parties in a variety of initiatives in regional cooperation mechanisms, in which capacity building takes center states, for example, beyond the common capacity building efforts at the EU level, we actively participate at the aforementioned international counter ransomware initiative, whose goal is to address one of the most prolific cyber threats ransomware. We are also members of the three plus one cooperation mechanism alongside Cyprus Israel in the US. And so far, this mechanism has facilitated cooperation in a variety of critical areas, such as cyber resilience of the energy and the maritime sector. Furthermore, being committed to the security and stability of our neighborhood, we have supported or co-organized several capacity building initiatives that focused on the Western Balkans. And with this opportunity, I’m happy to report that we are currently planning a new capacity building workshop for the region in cooperation with the European Commission and the European Union agency for cybersecurity the organiser. The workshop is being scheduled for quarter two of this year and will focus on a variety of capacity building topics, such as the National experiences implementing EU legislation, on the protection of critical infrastructure, best practices on the cybersecurity certification of products and services, cert to cert cooperation, cybercrime legislation, cyber diplomacy, cybersecurity strategies and lessons learned to incident response. In conclusion, Mr. Chair, we strongly support our executives from capacity building, as they contribute in the advancement of a global minimum capacity in cybersecurity. And in this regard, we are of course, welcome the global roundtable scheduled for May on capacity building. Thank you very much.
Ambassador Gafoor
Thank you very much, Greece, for your statement, Israel to be followed by France.
Isreal
Thank you Chair for giving us the floor to share a national perspective on the always timely and important topic of capacity building. As many member states have alluded, cybersecurity is an urgent issue. Currently, the growth of risk far outpaces defensive capacities, and capacity building. The global community needs to do more and to do it much faster. Developing Countries struggling to bridge the digital digital divide sic to leapfrog their digital economies and to do so securely. Capacity Building in in this context in Israel’s perception, refers to the family of efforts conducted to empower partner countries so they can achieve this objective. Specifically, capacity building can also serve as an important measure in building trust, as well as promoting the stable and resilient global cyberspace and facilitating continued human prosperity and progress in the in the information age is your capacity building efforts are aimed at improving global resilience on a political neutral bases, thus adopting a constructive and cooperative approach. While encouraging innovation. Israel published its international cyber cooperation strategy, and continues to contribute to raise the cybersecurity of foreign markets by donating funds for the Inter American Development Bank, the European Bank for Reconstruction and Development, and the World Bank, assisting countries to build their strategies, methodologies and established the National cybersecurity mechanisms. At the government’s initiative, all public universities in Israel now have their own r&d centers for cybersecurity, and offer extensive courses and training facilities managing to more than quintuple the amount of cyber related research. Leading Israeli researchers in academia have developed a sectorial survey which allows sector regulators and decision makers to get a holistic view of their sector cyber posture is really experts have worked successfully together with some countries to use this novel methodology and assist them in assessing and improving the cybersecurity maturity of some of the most critical sectors. We stand ready to cooperate with interested parties and share this know how and experience. Mr. Chair, Israel is actively sharing best practices with many countries and organizations who wish to build their own national cybersecurity capacities, and we are ready to collaborate with other states and organizations on this important matter. Israel is leading together with the UAE an initiative that includes the presentation of crystal ball and information sharing system that will allow the easy sharing of information between countries on cyber attacks. This is done under the leadership of the US with dozens of partners including very fruitful cooperation with the private sector. And once ready will serve as a tool to prevent attacks on the go. cybersecurity is a cutting edge field and the gaps in skilled cyber professionals are huge on global scale. The needs to have skilled hands, hands on and updated training is crucial in order to establish and sustain an effective cyber defending force. Israel is the hub for online hands on updated simulation scenarios that may serve many other nations to build the National Cyber capacities. Israel experience has shown that cyber can also serve as a means to improve social mobility and economic growth. We have therefore continued to invest in capacity building programs to reach out to citizens living in socio economic periphery with inclusive training and educational programs aimed at underrepresented sectors, especially relevant for young girls and women. And this is especially relevant, relevant as we will mark tomorrow, the International Women’s Day. The cyber domain is not just a threats, it holds possibilities and opportunities. Israel continues to build its cyber ecosystem while reinforcing its periphery bringing together government, academia and the private sector. We are, we are gladly sharing our experience in this field. Cyber has created novel policy and regulatory challenges due to among others the involvement of the private sector. So it merits a broad discussion that requires thinking out of the box, breaking existing silos, and strengthening multi national cooperation together with broadening the participation of all stakeholders. Finally, Mr. Chair, however, we tend to speak in the context of cyber capacity building about technology. It is indeed mostly people driven, and it should be treated as such, starting from education at young age and working rapidly to minimize any existing gaps. We are looking forward to participate in the high level capacity building roundtable in May 10, and continue to share our national and international experience. Thank you.
Ambassador Gafoor
Thank you very much, Israel, for your statement, France to be followed by Thailand.
France
Mr. President, Chair. My delegation endorses the statement delivered by the European Union and we would like to add the following remote center national capacity. Fences, resilience hinges on that of its European and international partners, and it hinges on the security and the security, the security and stability of cyberspace as the whole. As I recall the national strategic review for 2022. As presented at the sixth substantive session, France has made strengthening of cyber security of its international partners a strategic priority. France acknowledges capacity building to be a central part of collective efforts to institute a normative framework for Responsible state behavior. The Program of Action initiated in 2020 adopt such an approach and in transit and long-term. To respond to the needs of its partners France has grounded its approach and and cooperation approach on development of regional centers. The in bolstering of these in 2020 to 2023 will continue in 2024. The Dakar Cyber National School, which France was instrumental in has provided many different people with training on cyber security and cyber governance inter alia. Beyond that the call the school provides education to many people in the regions to over 202,023. The Western Balkans cyber capacity center launched in 2023, with France and Slovenia, together with the assistance of Montenegro organized its first training mission for the six countries in the region. The international status of the organization allowed for better integration of the country’s efforts in the region. The CIC, the capacity building region, has allowed for major strides to as regards governance. We are convinced that all digital develop Many projects to digitalize society and need to be accompanied by a by efforts to ensure they have secure too. This is why the Expertise France has been part of initiatives for cybersecurity iner alia in the Horn of Africa to benefit Djibouti, Kenya and Somalia. Expertise France has expanded its mandate to cybersecurity challenges. With IZAD, it has ensured capacity building projects for security with Asia as well. This effort is financed by the European Union to facilitate a cyber dialogue between the EU and its key partners in that region. France has also participated in the first high level dialogue on cybersecurity between the European Union and Latin America and St. Domingo on the in. That meeting was organized by expertise France and the European Commission in the context of the EU Latin American Alliance, financed by European Union funding. The dialogue brought together over 30 countries and arrived at operational results to bolster cyber cooperation between our two regions. We thank the European Union for convening this dialogue, and we thank the Dominican Republic for hosting it. Finally, I want to say that my delegation will provide more details in the next session on regular institutional dialogue will provide more detail about how we see capacity building in the future standing, action oriented permanent mechanism which will be a platform for continuing discussions and initiatives launched in this Open-ended Working Group I thank you.
Ambassador Gafoor
Thank you very much, France, for your statement, Thailand to be followed by Bangladesh.
Thailand
Thank you, Mr. Chair, on capacity building Thailand wish to highlight the following policies. First,Thailand recognize a pivotal roles of capacity building on cybersecurity for achieving an open, secure, stable, accessible and peaceful ICT environment. We are of the view that the efficiencies of the Capacity Building Initiative hinge on a nice base approach and tailor a system that address the specific needs of each countries. In this regard, Thailand support the proposal made by the Philippines on the need based cyber capacity building catalog. We believe that the initiative would help streamline the capacity building, requesting and offering process and facilitating the application for cyber for capacity building initiatives. The catalog can serve as a tool for matching the needs of recipients with available assistance from providers as well as looking into a capacity building model which fit the specific requirements of each state’s. Considering the need to have a single platform for corporations. We are of the view that it is also possible to incorporate the catalog into other existing or potential cyber security facilities such as UNIDIR Cyber Policy Portal, and a global cybersecurity Corporation portal as proposed by India, Thailand is expecting to work with the Philippines as well as our interested parties to further develop these ideas. Second, regarding your question on foundational capacity required for demand driven capacity building, we would like to highlight the importance of having a national policies on cybersecurity and legal framework in place. Such national policy with specific goals priorities, and strategy for state to enforce is cybersecurity. On our part, Thailand has implemented the policy and action plan on cybersecurity 2022- 2027 to serve as a roadmap for cyber security’s implementation efforts. This policy provides a crucial guidance for ensuring the protection of CI and CIIs as identified under the Thailand cybersecurity Act 2019. Third, regarding the question on additional roles of the UN and potential cyber capacity building providers beyond facilitating networking and training for high level officials to support long-term cybersecurity strategy planning, we propose exploiting the actions of instructor and expert in cyber surveillance, threat analysis and response. This action could prove beneficial especially for the developing states and may offer a promising area for cyber for cyber capacity building corporations. Finally, in line with the second APR, we support the operationalisation of the agreed principles of the capacity building to ensure the sustainable inclusive national approach to cybers capacity building initiatives while respecting national ownership. Such operations also require assessment and we will and the development of checklists and tools, which would be instrumental for responding to the specific needs of states. In this regard, we would like to thank Japan for the continuous afford for the ASEAN Japan cybersecurity Capacity Building Center, established in Bangkok’s in 2018. The center had been successful at building capacity for governmental officials and the private sector alike in line with the principle above in the past five years. We would like to also time the Women in Cyber fellowship program for promoting gender responsive capacity building effort in line with such principle in disregard Thailand fully supported gender sensitive approach towards cyber capacity building, it is essential to ensure such inclusivity and to continue to empower women in the cybersecurity field. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Thailand for your statement, Bangladesh to be followed by Montenegro.
Bangladesh
Thank you, Mr. Chair. Bangladesh reaffirms that capacity building is at the core of the success of this group. There is no denial that the developing countries are in critical need of robust capacity building to develop the knowledge, skills and resources necessary to effectively implement responsible state behavior in the use of ICTs. The mapping exercise done by the Secretariat to survey the landscape of capacity building programs and initiatives, has also underscored that capacity building should remain a fundamental and cross cutting plot of all related discussion on ICT security. Chair, you asked about fundamental capacities required for states to detect defend against or respond to malicious ICT activities. My delegation would like to highlight the following; first, building robust capacity of cyber security capacities requires in the first place a skilled workforce in areas like cybersecurity, forensic analysis, threat intelligence and incident response. Second, dedicated national entities focused on ICT security play a crucial role in leading and coordinating responses, extending or creating such institutions, serves as frontline defense for detecting responding to and recovering from ICT incidents. Third, clear legal and policy frameworks provide the foundation for taking legal actions against malicious activities. A whole of government approach, engaging with stakeholders and fostering partnership enhances its effectiveness. Fourth, effective collaboration with other states and international organizations through established channels like CERT to CERT cooperation is paramount. It is equally important to share information, best practices, and collaborative responses to address cross border cyber threats. Chair, while the mentioned, the steps are basic yet critical as a fastest way for initiating capacity building programs. At the same time, it is very important to acknowledge that capacity building requirements vary from country to country, and there is no one size fits all solution. Therefore, my delegation highlighted the importance of needs based approaches for capacity building in previous sessions. The pivotal questions then become how do we effectively assess the specific needs of countries for capacity building and what are the available programs we have. To this end, we support the idea presented by our distinguished colleague from the Philippines, which may have the potential to address this question. It is also important to ensure that such metrics should be updated regularly to incorporate new programs and needs as they emerge. global cyber security cooperation portal as presented by India in last session could also be the possible host of such metrics that we believe that for a capacity building program to be successful, it is imperative to involve the industry without enhanced collaboration between a state and industry, we may not be able to achieve the desired result that we will aspire to attain. The roundtable discussion on capacity building is scheduled in May could provide The valuable opportunity to delve deeper into this matter. Finally, a gender sensitive approach to capacity building is critical. We must consider the gender impacts and implications of cyber threats and addresses the needs, priorities and capacities of women and girls. Additionally, it is crucial for states to actively engage with your activist and young professionals in the field of ICTs. As they are driving innovation and making remarkable contribution to the field of technology, I thank you.
Ambassador Gafoor
Thank you very much, Bangladesh for your statement. Montenegro to be followed by Japan.
Montenegeo
Montenegro aligns itself with the statement of the European Union and we wish to make additional remarks in our national capacity. We want to use this opportunity to emphasize the role of capacity building, especially in cyber domain and for this working group as it underpins our overall work as rightly pointed out by many speaker before us. We need to continue with cybersecurity capacity building as a diplomatic priority in order to enable all the stakeholders including governments, SMEs and societies to become cyber resilient and establish effective cyber defense. And that way, we welcome the upcoming global roundtable on ICT security capacity building, and from the perspective of the Ministry of Foreign Affairs. We will try to to influence ICT minister to take participation. We also welcome the Accra call for ensuring that cybersecurity building supports broader SDGs. As for the national and regional level efforts when it comes to the cyber capacity building, we would like to bring your attention to the Western Balkans Cyber Capacity Center, which Montenegro is proud to be host of and which our official inauguration is expected next month. the center is joint project of France, Slovenia and Montenegro and has three focus areas dissemination of cyber culture through education and awareness, strengthening the operational capacities and promotion of regional and international cooperation. We are dedicated to use the center to actively contribute to strengthening the global cybersec Capacity Building landscape. And we see it as our national contribution to that. And finally, we would also want to commend Women in Cyber initiative, which empowers women to develop skills for better gender inclusion in cybersecurity. Thanks to which representatives of Montenegro participated in the last two substantive sessions. Thank you.
Ambassador Gafoor
Thank you very much Montenegro, Japan to be followed by China.
Japan
Thank you. Thank you, Mr. Chair. Um, Japan believes that capacity building is essential for maintaining peace and stability and promoting a free, fair and secure cyberspace. The United Nation is in a good position to compile and share information and experiences related to the existing capacity building efforts, as well as to identify the gaps where capacity building is needed. To this end, Japan, like many other states in this room, appreciates the work of Secretariat on the mapping exercise, it is useful and helpful. As for the area of capacity building, Japan believes it is important to focus our efforts, especially in the area of implementation of the framework of responsible state behavior. We should also promote multistakeholder approach, as we believe capacity building is not only a matter of state, but also of non-state, non-state stakeholders, such as businesses and academia. coordinating and collaborating with with the efforts by non-state stakeholders is crucially important. In this regard, Japan welcomes chairs initiative of convening a dedicated global roundtable on ICT security capacity building, and look forward to participating in Japan wishes to provide constructive inputs based on on our experience to exchange ideas, share best practices, and build partnerships among state representatives, practitioners and interested stakeholders with the end aim of building synergies and advancing the international committee’s work on capacity building in concrete ways. Furthermore, India’s proposal on GCSCP is an interesting idea, which merits further discussion. I’d also like to thank the Philippines for today’s presentation. Mr. Chair, with regard to the chairs guiding question about existing studies of foundational capacities, allow me to introduce one item, which is the cluster strategy on cybersecurity employed by Japan International Cooperation Agency. This strategy aims to improve resilience of the recipient country by strengthening the following five perspectives in a balanced manner and according to each country’s situation, so that they will be equipped with sufficient capacity to be able to respond by themselves to the continuously evolving cyber threats. First, legal perspective, such as developing legal systems for the protection of personal information, regulation of illicit acts and crimes and protection of critical infrastructure. Second, organization and strategy perspective, such as developing national strategies, and relevant roadmaps, nominating and clarifying responsible organization in charge of cybersecurity, and structuring evaluation and review systems. Third, technical technical perspective, such as improving risk handling capabilities of public institutions and industries, fourth, capacity building perspective, such as promoting and implementing cybersecurity education, and raising awareness among public and private sector in order to develop and strengthen relevant human resources and last fifth, cooperation prospective, such as strengthening partnership among cybersecurity institutions, and building information sharing network in order to enhance capacity to coordinate within and outside out of the country. Before ending, I wish to thank Thailand for mentioning about the joint cybersecurity Capacity Building Center of ASEAN, Japan during each iteration. It is always our pleasure to work together with other member states. We are happy with successful results that the center is producing and look forward to continue working together. That ends my intervention. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much. Japan will statement China to be followed by Mexico.
China
Thank you chair. China appreciates the chairs efforts to promote capacity building cooperation, and believes that a strengthening capacity building will help enhance cooperation in cybersecurity ensure fair, equitable and universal internet access, and the popularization of ICTs and bridge the digital divide, which is significant for all countries and in particular developing countries. In this process, all parties should follow the principles of non interference and internal affairs, no preconditions, non discrimination, sustainability and transparency and focus on the real needs of recipient countries. I’m guiding question one. China values international cooperation in cybersecurity capacity building, and has engaged in cooperation with countries in the region in such areas as emergency response and industrial development. In emergency response. The National Computer Network Emergency Response Center of China Sea insert carries out exchanges in cooperation with major national certs, governmental departments, international organizations and alliances globally. By the end of 2023. It has established CERT international cooperation partnership with 289 organizations in 83 countries and regions. Each year. The center works with over 50 countries to hand over 10,000 cross border cybersecurity incidents and has organized events such as CERT, international partnership forum, the cybersecurity forum for technology development and international cooperation and the China ASEAN network security emergency response capacity building seminar in industrial cooperation in recent years, or China has been organizing the China ASEAN digital ministers meeting the China as the emerging industries forum, the China Africa digital capacity building Cooperation Forum, and the China’s say luck digital technology Cooperation forum. We have worked to establish the China branch of the BRICS Institute of future networks, and through platforms such as the meeting of BRICS communications ministers, and the BRICS forum on partnership on new industrial revolution. China has strengthened exchanges in cooperation with other countries of the global south on cybersecurity, digital economy and law enforcement cooperation. Meanwhile, to effectively help countries improve the capability to detect and respond to malicious cyber activities. China believes that national governments and it businesses capable of detecting vulnerabilities and threats should be open just and non discriminatory in publishing in a timely manner, cyber threats or vulnerabilities and stay committed to common security. At the same time, all countries should follow the principle of political neutrality, and refrain from using cyber security cooperation or assistance to other countries as a pretext for carrying out malicious cyber activities against recipient or third countries. Thank you, Chair.
Ambassador Gafoor
Thank you very much, China for your statement, Mexico to be followed by Colombia.
Mexico
Mr. Chairman Mexico aligns itself with the statement made by Argentina on behalf of a group of Latin American countries, we recognize the fundamental character and the cross cutting nature of capacity building for making progress in the discussions of this working group. This session must come up with the basis for results oriented actions that are be evidence based, based on the principles of international cooperation, transparency, non discrimination, and universality of norms, as well as closing the gaps in terms of implementation. And therefore, we would like to express our thanks for the presentation by the delegate of Philippines which is identity, which was seeing the independent identification of capacity needs, and the connection with existing providers of training. In particular, we continue to promote ongoing exercises to monitor national capacities through best practices, and shared experience, the aim being to build on the echo ecosystem of cybersecurity and, and come up with adequate strategies to close the digital gaps. As we have done in said in our previous statements, we encourage the incorporation of all interested parties, their contributions bring added value, both in efforts to close the digital divide, as well as those that are aimed at implementation of standardized capacity frame, capacity building frameworks, and we welcome the convening of a global round table on capacity building to be held here in this headquarters in May, Mexico, calls upon all interested parties. To take part in it, we believe it’s a good platform to repeat the collective appeal with regard to developing capacity building, in order to implement the global framework on peaceful and responsible behavior in cyberspace. Mr. Chairman, we reassert the importance of the accurate call, we recognize the efforts of the Global Forum on Cyber Expertise. This is an organic body, which can come channel the needs for capacity building, and coordinate actions between the relevant players who are represented in this body Mexico welcomes the fact that we are party to the utricle, which is adopted in the most recent annual report, meeting in Garner. That document provides solid elements allowing states international organizations economic world, civil society and other relevant players to reassert their determination for capacity building, and to coordinate their efforts to enhance the role of cyber and cyber resilience to facilitate sustainable development, innovation, digital cooperation. We would like to thank the Secretariat for drafting the document it analyzes the programs and initiatives for capacity building, inside and outside of the United Nations and at the global and regional levels. And it was drawn up in line with what was requested in the second annual progress report, we recognize the value of all the initiatives in terms of cooperation for core capacity building, particularly at the regional level and between regions, we make an appeal that through these additional initiatives, they should echo the important work that we are promoting within the context of the United Nations. We believe that aligning, aligning our efforts will make them more effective and efficient in our collective aim. To build a resilient cyber space. We agree with the vision that cooperation for capacity building must be flexible, it must adapt itself to the interest in the areas identified by the receiving country. They are the ones that know what are their specific needs and priorities in their country. Finally, we echo those who have emphasized the importance of incompetence of incorporating in a systematic manner, the gender perspective, as a part of the international cooperation efforts in terms of capacity building. This will allow us to promote and ensure access of women, young people and girls to technology, close the gender gaps in cyberspace, and also identify and mitigate in an effective way, the threats and risks risks that women face in cyberspace. I’d like to close by thanking the co sponsors of the Women in Cyber fellowship, this program has been vital to ensure the significant involvement of female delegates in this working group. And it’s had an impact on progress in non negotiations. Thank you.
Ambassador Gafoor
Thank you very much, Mexico, and give the floor now to Colombia. Please.
Colombia
Thank you, Mr. Chairman. Colombia, aligns itself with a statement made by Argentina on behalf of a number of countries. on capacity building, we reiterate the importance of having a tool which is sustainable and ongoing, which serves this and also we are in the process of transforming our digital security public policy, we are establishing a national strategy of digital security and creating the national agency as the guiding entity for our public policies in this area. In this process of transformation, it has been vital for our country to know about the best practices of other states, both in the region, and in other areas of the world, in terms of the design and establishment of these processes, as well as the support and participation of stakeholders in them. In particular, I’d like to take this opportunity to thank the cybersecurity program of the Inter American CounterTerrorism Committee and the skill center of Latin America, and the support from the Government of Colombia to develop our comprehensive digital security strategy. Concerning the outcomes of the analysis document considering the programs and initiatives for capacity building. We believe that this does contribute to having a balance in existing efforts in terms of capacity building. It also establishes new synergies and coordination between different efforts and avoids duplication. We welcome the fact that around the world initiatives are being undertaken in terms of capacity building to allow states to develop their national policies and elaborate strategies and establish their institutions that are required in line with their own needs. Taking into account the information that has been given, we’d like to highlight the importance of workout now underway to support National Computer Emergency Response Teams. We believe that is is one of the needs for states to detect and respond to the malicious use of ICT. Also, we note the various programs mentioned in the mapping exercise include for its development and as a reference, the global cybersecurity capacity Center of the University of Oxford’s program. This is on the basis of this information was provided as well as training workshops and technical assistance. We consider that the participation of experts from the center could be envisaged for the high level roundtable on capacity building. Mr. Chairman, we believe that the outcome of this exercise the mapping exercise, with regard to existing programs, is the basis which will allow us to integrate the needs of states to provide The necessary assistance in this work, the list of good best practices for implementing voluntary standards will be an excellent tool for identifying their needs. We believe that the proposed catalog on capacity building, which was submitted by the Philippines deserves further consideration, in concluding my statement to take into account the importance of continuing to promote the capacity of building with a gender perspective. And as well as the selection and launching of capacity building projects in the use of technology and ICT. We would like to thank the co sponsors of Women in Cyber program, particularly the Government of Canada, because our government in Colombia has benefited from this, and it provides an useful panel with regard to gender and cyber, this is an important support from the Stimson Center, also, thank you.
Ambassador Gafoor
Thank you very much. I was just looking at the time thank you very much, Colombia for your statement, I think we are almost close to six, I’m not sure we can take another speaker. To be fair to the interpreters. So we have about maybe another 15 speakers left on capacity building. And we will take that up tomorrow morning. And then after we finish that, we’ll go to regular institutional dialogue and the other remaining items should not take as much salt as much time. So we can deal with the other matters and the closure of the session fairly expeditiously. So tomorrow, we’ll allocate as much time as is needed to finish the discussions on capacity building, capacity building and then take off regular institutional dialogue. So on that note, thank you very much for a productive day today and I wish you all a pleasant evening. The meeting is adjourned.
Leave a Reply