The OEWG’s final report and CCB

Today, 11 July 2025, the UN Open Ended Working Group on the security of and in the use of ICTs (OEWG) agreed its final report after five years of work.  I’ve had the privilege to be an accredited observer since the start in 2021 and this is my hot take on what was just agreed regarding cybersecurity capacity building (CCB). 

TLDR: there is still all to play for if you support a multistakeholder approach to CCB that avoids duplicating existing portals and funds.

Cybersecurity capacity building was unanimously agreed to be important and worth investing in.  Maintaining political support and encouraging investment were the most important things the OEWG could have done for CCB and it has delivered.  It would have been nice to see more evidence of the benefits of CCB in the final draft, but that is a minor quibble considering the issues at stake and the nature of these reports.

States further emphasized that capacity-building is foundational to developing the resources, skills, policies and institutions necessary to increase the resilience and ICT security of States and to accelerate the digital transformation of States and the implementation of the 2030 Agenda for Sustainable Development. (para 9)

States reaffirmed the continued value and relevance of a principles-based approach to CCB .  With the support of the Dutch government, I joined Chatham House in preparing a report on operationalising the OEWG’s principles for CCB.  I was therefore pleased to see the principles reaffirmed and referenced in multiple places: the preamble; the recommendations on CCB for international law; and the recommendations for capacity building more broadly.  Hopefully the follow-on process – a Global Mechanism on developments in the field of ICTs in the context of international security and advancing responsible State behaviour in the use of ICTs (G-Mech) – will use Chatham House’s report to turn commitments into actions.

The future process will contain regular Global Roundtables on CCB. These are in addition to the primary vehicle of the future process: annual plenary sessions that discuss all five pillars of the framework of responsible state behaviour in the use of ICTs. While not explicitly required, the report suggests that the Global Roundtables should differentiate themselves from thematic groups (see next section) by being at a higher level.

States to convene regular Global Roundtables, including at a high-level as appropriate, on ICT
security capacity-building under the auspices of the future permanent mechanism to allow for
strategic as well as action-oriented discussions on capacity-building in the context of ICT
security. Such Global Roundtables could include technical-level discussions between capacitybuilding practitioners, representatives of interested States, and other interested parties and
stakeholders, including businesses, non-governmental organizations and academia, with due
consideration given to equitable geographical representation. States in a position to do so are
encouraged to provide support to representatives and experts from developing countries to
attend the Roundtables. (para 55)

The report agreed that the plenary sessions will be supported by a thematic group dedicated to CCB. This is one of only two thematic groups – potentially a sign of how important CCB will be within UN cyber diplomacy and how engaged the UN will be in the field’s governance. The thematic groups are to meet annually in hybrid format.

The Global Mechanism would comprise the following dedicated thematic groups:

  • An integrated, policy-oriented and cross-cutting dedicated thematic group drawing on
    the five pillars of the framework to address specific challenges in the sphere of ICT
    security in the context of international security in order to promote an open, secure,
    stable, accessible, peaceful, and interoperable ICT environment, with the participation
    of, inter alia, technical experts and other stakeholders. (DTG 1)
  • An integrated, policy-oriented and cross-cutting dedicated thematic group drawing on
    the five pillars of the framework to accelerate ICT security capacity-building, with the
    participation of, inter alia, capacity-building experts, practitioners, and other stakeholders. (DTG2)

Stakeholder participation in the next five years of the UN process was secured.  Countries will continue to have the right to veto stakeholders from receiving accreditation to observe, but they will have to explain their reasons to the Chair.  Furthermore, there is a process to try to unblock vetoes if they are applied.  This may feel like cold comfort to those stakeholders who have been vetoed before.  But the options on the table included no stakeholder participation at all and even the removal of the word “stakeholder” from the report entirely, to be replaced by the lower status “interested party”.  Personally, I’m relieved that there will be UNWebTV coverage of the future process and that there are hooks for stakeholder participation in the modalities for the Global Round Tables on capacity building, plenary sessions and the dedicated thematic groups.  It is that last – the thematic groups – where the process for applying to engage as a stakeholder feels least clearly defined.  Yet is arguably the stage at which experts and stakeholders could add the most value.

Initiatives that supported the participation of women and developing countries in the OEWG were welcomed and further investment in them encouraged.  The subject of gender was a fiercely contested one, with both Russia and the USA requesting the term “gender” be removed from the final report.  Nonetheless the projects promoting inclusion were strongly championed by many middle ground states, the EU, UK, Australia and Canada.  This was reflected in the final report.  And at this eleventh and final OEWG session, 53% of state representatives taking the microphone were women.  In the coming weeks I intend to share further analysis on the impact of their participation.

In the areas where there was the greatest risk of duplicating existing efforts – a new UN portal and a voluntary trust fund – no hasty decisions were taken.  There will be a new Global ICT Security Cooperation and Capacity Building Portal (GSCCP), but it “should first be developed to function as an online platform to support the future permanent mechanism” (para 56).  This is what I recommended, but I am under no illusion that my view on the matter had much influence on the final outcome!  In short, there is still time and political space to develop partnerships between the GSCCP and its nearest peers, the UNIDIR Cyber Policy Portal and the Cybil Portal, rather than duplicating their content or functions.  Similarly, the agreement to continue discussions on a potential UN Voluntary Trust Fund buys time to head off duplication – a risk that the report explicitly notes (para 53h).

Reference was made to “existing initiatives” in which views and ideas on CCB were exchanged, but states were not aligned on their role or relevance (para 53j).  The report did not mention by name any of the multistakeholder fora in which CCB was already discussed and advanced, such the Global Forum on Cyber Expertise, the Internet Governance Forum or the World Summit on the Information Society. 

Going forward, there remains two competing visions for the future of CCB: one in which it is a state-governed activity with a very limited role for interested parties in guiding the field’s development; and an alternative multistakeholder vision in which companies, non-governmental organizations and academia are actively involved in governing and guiding CCB.  The implications of the OEWG’s final report for which of these visions will be closer to what actually plays out are too complex to cover in this hot take.  But it’s fair to say the Chair sought to achieve a difficult balancing act between two very different positions on the role of stakeholders in CCB and that this is reflected in a final report that leaves all to play for.  If you are reading this as an official of a government that supports the multistakeholder approach to CCB, and more broadly the governance of cyberspace, then the most impactful action you could take is to actively support multistakeholder processes and platforms. That would ensure they have the resources and momentum to co-exist alongside the UN Global Mechanism.

All in all, I come away from a week at the UN feeling more hopeful for its future work on CCB than I did on Monday.  It is an achievement that unanimity was reached on so much given the geopolitical backdrop.  As the Chair said, this is a win for the UN and that is a win for us all.  Nonetheless, there is plenty of paddling ahead in our much-mentioned canoe.

Leave a Reply

Your email address will not be published. Required fields are marked *