Good afternoon.
The fourth meeting of the substantive plenary session of 2026 of the global mechanism on developments in the field of information communication technologies in the context of international security and advancing responsible state behavior in the use of ICTs.
As I indicated prior to lunch, we're going to continue with our list of speakers under the topic of threats, and so we are going to hear first from the representative of Ghana, who will conclude her intervention.
I would ask her to begin where she left off.
And then we will continue with Pakistan, Romania, Nicaragua, and Armenia.
Ghana, you have the floor.
Thank you, Chair.
Madam Chair, Ghana remains committed to working with member states, regional organizations, and other stakeholders to address both existing and emerging ICT threats.
We are particularly concerned by the growing impact of cyber threats on critical information infrastructure whose disruption can have significant consequences for national security, economic stability, and public confidence.
The damage to submarine cable seven Gamma in 2024 and the resulting disruption to ductile services reinforced the importance of protecting such infrastructure as a strategic national asset.
At the national level, Ghana has identified 13 critical information infrastructure sectors under the Cybersecurity Act, which provides for the registration of critical information infrastructure, establishes obligations for operators and requires regular compliance audits.
Ghana is also strengthening its national incident response architecture through national and sectoral Computer Emergency Response Teams.
Currently, four sectoral sets are operational and plans are underway to operationalize additional sets for health, energy, utilities, transportation, military, and academic sectors.
Ghana has also established a 247 national incident response capability, enabling the public to report cyber incidents directly to the national set that is set GH.
This has significantly strengthened our ability to respond to cyber incidents and support affected individuals and organizations.
In this regard, Ghana welcomes the establishment of the global point of contact directory as an important voluntary mechanism to facilitate timely communication and cooperation among states for incident response.
Like many countries, Ghana continues to confront threats such as business email compromise, online fraud, scams, and other forms of cyber enabled crime.
Emerging technologies, including artificial intelligence and quantum computing, present both significant opportunities and new security challenges.
Garner National's artificial intelligence strategy, seeks to harness artificial intelligence to promote inclusive development while ensuring that its adoption is secure, responsible, and resilient.
We therefore support enhanced international cooperation and capacity building to help developing countries Adré the evolving risk associated with AI and other emerging technologies.
As we move forward, Ghana believes that no country can address these challenges alone.
We remain committed to working with member states and all relevant stakeholders to strengthen international cooperation, address existing and emerging ICT threats, and contribute to a secure and resilient cyberspace for all.
Thank you, Madam Chair.
Thank you.
I give the floor next to the delegation of Pakistan.
Thank you, Madam Chair.
I congratulate you on assumption of your responsibilities, as well as your able and dynamic team.
As we begin substantive work of the global mechanism, the ICT threat landscape continues to evolve.
Threats have evolved from localized IT risks into major geopolitical tools capable of disrupting global stability.
Attacks targeting critical infrastructure have increased in number, sophistication, and severity, threatening human life and national stability.
Cyber operations routinely paralyze public administration and essential services across borders.
Miliitarization of cyberspace is well underway.
States increasingly deploy cyber instruments for espionage, sabotage or political influence, often leveraging private proxy groups, criminal syndicates, or commercial spyware vendors.
Commercial hardware, cloud infrastructure, and software tools have been repurposed for military or intelligence operations, making non proliferation and oversight exceptionally challenging.
In addition, the AI accelerated cyber warfare poses new challenges to international peace and security.
Sophisticated surveillance tools sold to state and non state actors are frequently used without safeguards or oversight.
Amongst potent threats affecting international ICT security environment are misinformation and disinformation, both by states and non state actors.
Disinformation contributes to the outbreak and escalation of violence by manipulating threat perceptions, deepening identity based divisions, and mobilizing populations toward confrontation.
It obscures violations of international law, including international humanitarian law and international human rights law, distards humanitarian realities, and sustains military operations through narrative control.
When combined with cyber capabilities, coordinated campaigns can overwhelm information ecosystems, disrupt decision making and accelerate conflict dynamics.
Madam Chair, member states must commit to voluntary norms of responsible state behavior alongside international law, including the UN Charter.
In addition, we need to establish clear international commitments that critical infrastructure, especially healthcare, energy, and water must remain strictly off limits during peace and conflict.
This challenging environment, implementing confidence building buyers assume greater importance.
Operational coordination of cybersecurity authorities is critical to facilitate rapid communication during crisis events and to avoid accidental conflict.
This respect, we suggest three points.
Global mechanism is an important opportunity to democratize global cyber diplomacy.
We should focus our dialogues on practical issues affecting all regions such as ransomware mitigation, critical infrastructure protection, and de escalation channels.
Two, establish international consensus and regulatory guard leads regarding offensive cyber capabilities and the misuse of commercial surveillance tools.
Three, examine how disinformation, including as part of cyber and hybrid warfare, contributes to the outbreak, escalation, and prolongation of armed conflict and seek to address this critical issue.
Madam Chair, cybersecurity, especially for developing nations, is not merely an IT challenge.
It is an economic, sovereign and human security issue.
Maintaining international cyber sttability requires moving from passive agreements on norms to active implementation, combining clear legal guardrails with operational communication channels, targeted capacity building, and working on practical confidence building mas.
I thank you, ma'am.
Thank you very much.
I now give the floor to the delegation of Romania.
Thank you, Madam Chair.
Romania fully aligns with the statement made by the EU and makes the following remarks in its national capacity.
As it is the first time I'm taking the floor, I would like to thank you Madam Chair and your team for all the work in order to ensure a fruitful session of the global mechanism.
Romania expressed its interest to contribute constructively to the work of this new global mechanism.
Madam Chair, a clear understanding of the threats and challenges in the cyber domain is of high importance for our future activity within the GMAC framework and for enduring meaningful results.
This is as important as ever nowadays, given the fact that cyber threats are more and more prominent, they continue to target our societies, economies and are having increasingly negative effects on our societies and our citizens.
In the last years, Romania witnessed a significant increase in number, complexity, impact, and persistence of cyberattacks.
Phishing, social engineering, ransomware, cyber frauds, attacks against informing networks, as we have recently seen for data exfiltration continue to represent persistent threats amplified by the rapid development of AI models.
At the same time, we have been exposed to cyberattacks as part of sophisticated hybrid and interference campaigns.
As malicious behavior in cyberspace is intensifying, we are concerned by the blurring lines between non state and state actors into conducting coordinated attacks.
We are particularly concerned of the attacks targeting critical national infrastructure, democratic institutions, and democratic processes.
On the 13th of July, Romania, together with other EU member states and allies had condemned hostile cyber activities conducted by groups controlled by the Russian Federation.
These activities form a part of a well established pattern characterized by the use of a complex cyber ecosystem, comprises both state institutions and non state entities.
Madam Chair, raising awareness on cyber threats is essential for ensuring international security and stability.
We remain committed to continue to contribute to the international efforts meant to prevent that, and counter such destabilizing actions.
The DTGs could play an important role in this respect as the right venues for exchanging views and formulating recommendations on better implementing the existing normative framework.
As well, our focus should be on applying the international law and international humanitarian law in cyberspace and build capacities looking at critical infrastructure and critical information infrastructure.
Thank you, Madam Chair.
Much McGrath.
Thank you very much.
I now give the floor to the delegation of Nicaragua.
They will be followed by Armenia and Bangladesh.
Thank you, Madam Chair.
Nicaragua welcomes the convening of this first substantive session of the global mechanism, and we reaffirm our readiness to participate constructively in this work.
The creation of the mechanism represents an opportunity for consolidating a permanent and transparent, inclusive space where all can participate under conditions of equality and contribute to building common understandings.
Our work should be focused on promoting an environment for ICTs that is secure, safe, stable, accessible, peaceful, and interoperable based on the purposes and principles of the charter of the United Nations, including the sovereign and quantity of states, non interference in internal affairs, and the peaceful settlement of disputes.
Madam Chair, Nicaragua recognizes that the existing and emerging threats in the area of ICTs is developing swiftly and can impact the security of states, the functioning critical infrastructure, the provision of essential services, and the well being of our peoples.
Amongst them.
For this reason, we have been strengthening our legal and institutional framework by adopting laws with the aim of strengthening the protection of telecommunication systems and infrastructure to promote a more secure and resilient digital environment.
Broadening access to ICTs and consolidating national capacity for tackling threats derived from their malicious use.
Similarly, our country is driving initiatives aimed at promoting a culture of cybersecurity to strengthen digital security and to broaden technical capacity to tackle with cybernetic threats, where we recognize that no country, especially in developing countries can tackle these challenges in isolation.
In this context, international cooperation and exchange of experiences, technical support and capacity building should be the basic building blocks for all countries to tackle the threats resulting from malicious abuse of ICTs while fully respecting the national sovereignty and their priorities.
Similarly, NCR underscores that the application of unilateral coercive measures has a direct impact on developing ICTs and also in terms of response to attacks, access to technology, to software, digital services, and financing, and knowledge transfer also impact.
These measures deepen the digital divide, they weaken national capacity, they make it difficult to protect critical infrastructure and they are an impediment to the right to development of our people.
This is why we call for an end to these illegal measures that are in breach of the purposes and principles of the Charter of the United Nations.
Madam Chair Nicaragua, will continue contributing to an inclusive, transparent and balanced mechanism aimed at concrete results that promote the peaceful use of information and telecommunications technologies and to strengthen international cooperation and contribute to the development and well being of all of our peoples.
I thank you.
Thank you very much.
I now give the floor to the delegation of Armenia.
Thank you, Madam Chair.
As this is the first intervention by this delegation, we would like to join others in congratulating you on your election as the first chair of the global mechanism.
You can count on our constructive engagement.
Taking into account your request to limit our interventions, I will now intervene on both items of today's agenda.
I and communications technologies have become an integral component of international peace and security.
As digitalization advances, ICT related threats continue to evolve in scale, sophistication and frequency posing risks to states, critical infrastructure and the international stability.
The evolving ICT threat landscape underscores the importance of the international cooperation.
Given the transboundary nature of cyberspace, no state can effectively address these challenges alone.
Collective efforts are therefore essential to strengthen resilience, promote responsible state behavior, and ensure global peace and security.
We are confident that the global mechanism We provide an effective and inclusive platform for addressing ICT threats, fostering dialogue, and strengthening international cooperation.
The dedicated thematic groups will facilitate focused and action oriented discussions, while DTG two dedicated to accelerating ICT security capacity building will play a vital role in identifying needs, facilitating partnerships, and strengthening the capacities of all states to effectively implement the agreed UN framework.
We recognize the importance of the voluntary non binding norms of responsible state behavior in the use of ICTs as set out in the 2015 GGE report, which established the common understanding of responsible state conduct.
We further acknowledge that the 2021 GGE report provided an additional layer of understanding regarding the interpretation, application, and implementation of these norms.
We support efforts to advance responsible state behavior and the further development of the framework over time.
We recognize that states have different levels of capacity and resources to implement the framework of responsible state behavior in the use of ICTs.
We emphasize the importance of capacity building, international cooperation, and support to enable all states to effectively implement these norms.
Furthermore, we recognize that the framework for responsible state behavior in cyberspace is dynamic and evolving and that additional voluntary non binding norms could be developed over time.
Where appropriate in response to emerging challenges and developments in ICTs.
We emphasize that any further development of norms should continue to contribute to international peace and security and be guided by inclusiveness, transparency, and consensus among states.
We support continued exchange of views and best practices among states to enhance common understanding and promote the practical implementation of the framework for responsible state behavior.
Thank you.
M.
Thank you very much.
I now give the floor to Bangladesh to be followed by the International Committee of the Red Cross.
Madam Chair, Excellency, Distinguished delegates.
At the outset, my delegation congratulates you on becoming the chair of this global mechanism and pledges its full and constructive support to your stewardship of this mechanism.
We also thank the Secretariat for its work in preparing the first substantive plenary.
Bangladesh Warne welcomes the launch of this global mechanism as the achievement of five years of work by the open ended working group.
Madam Chair, as a country whose international connectivity depends heavily on a limited number of submarine cable lending stations, Bangladesh attaches particular priority to the production of submarine cables and other cross border critical information infrastructure and sees its merit in dedicating confidence building measures on this issue.
We also note with concern that the rising incidence of ransomware and denial of service attacks against government services and platforms and the financial sector and support a comprehensive cooperative international approach to ransomware, including cooperation on tracing illicit finance.
Like many delegations, we are increasingly concerned by AI enabled threats and by disinformation and defects generated through advanced technologies which carry implications for both international security and social stability.
Madam Chair, for Bangladesh, confidence building remains the pillar that makes every other pillar meaningful.
In closing, Bangladesh remains committed to working with every delegation towards an open, secure, stable, accessible, and peaceful ICT environment.
Bangladesh should remain constructively engaged in this global mechanism.
I thank you, Madam Chair.
Thank you very much.
I now give the floor to the International Committee of the Red Cross to be followed by Interpol and then the African Union.
Gracias.
Thank you, Ambassador Pxcellc, distinguished delegates.
The International Committee of the Red Cross is grateful for the opportunity to take part in the first substantive plenary session of the global mechanism.
The ICRC commends the important progress achieved by states throughout the work of the open ended working group, including in identifying threats posed by the use of ICTs during armed conflict.
Building such shared understanding is a key step towards developing measures to address these threats collectively.
Over the past year, the number of armed conflict has risen to alarming levels with over 130 armed conflicts in 2025.
The ICRC observed an increasing use of ICT capabilities for military operations by state and non state actors, and we are concerned about the risks that this poses to the civilian population.
The ICRC therefore wishes to highlight some of the trends it observes in today's armed conflicts.
We have submitted these observations in a working paper to the global mechanism.
First, ICT operations disable the provision of essential services for civilian populations.
Recent uses of ICTs have shown that even in the absence of physical damage, ICT operations can severely disable civilian infrastructure, damage or destroy civilian data, and disrupt the delivery of essential services.
The consequences of these operations include power outages, disruption to transport systems, banking, water supply, and food production.
They also to the denial of contact with loved ones and of access to lifesaving information.
Second, ICT operations do not spare medical facilities, aggravating the hardships suffered by affected populations.
In addition, humanitarian organizations including the ICRC, continue to be targeted or affected by ICT activities.
From the intrusion of the systems and exfiltration of sensitive data to the disabling of computer systems aimed at disrupting humanitarian operations.
The targeting of humanitarian organizations causes them harm and most importantly, threatens the safety and dignity of the people they serve.
Third, recent armed conflicts have revealed how ICTs are used to harm children.
Social media and messaging apps are used by parties to armed conflict to recruit children into their armed forces or to use them in hostilities.
Children no longer need to be physically close to an armed force or armed group to be drawn into their operations.
Recruiters now contact more children more quickly via online communities.
The involvement of children in armed conflicts is unlawful and harms them.
Fourth, as the use of ICTs and armed conflicts evolve rapidly, new actors are playing increasingly significant role.
On the one hand, while technology companies provide much of the ICT infrastructure, assets and services to civilian populations, these companies also provide similar assets and services to parties to armed conflicts.
In times of armed conflict, this exposes company infrastructure to real risks with potentially wide ranging effects on civilian populations who rely on the very same infrastructure and services in their daily lives.
On the other hand, civilian hackers or haivists are now operating in several armed conflicts.
Too often, they do not know or ignore the limits that IHL imposes on ICT operations.
In practice, many of these actors have directed their operations against civilian infrastructure and services.
Finally, the growing use of artificial intelligence in ICT activities will increase their speed, scale, and potential for harm.
With states and non state actors integrating AI into the cyber operations, the ICRC is concerned about risks of indiscriminate attacks, incidental civilian harm, damage to critical civilian infrastructure, and uncontrolled escalation, particularly in complex and interconnected digital environment.
Madam Chair, as the global mechanism assumes its critical role in advancing the responsible behavior of states in the use of ICTs, the ICRC calls upon member states to work together towards reflecting the realities of today's armed conflicts in the discussions and to identify practical measures to mitigate harm to affected civilian populations and civilian objects.
The ICRC stands ready to support states in these efforts.
Thank you.
Thank you.
I now give the floor to Interpol.
Thank you, Madam Chair.
As this is the first time that Interpol takes the floor, we congratulate you on your appointment and wish you every success in guiding this important process.
In the interest of time, I will deliver an abridged version of our statement.
As many of the distinguished delegates have shared over the past two days, the nature and volume of cyber threats we face continues to grow rapidly from ransomware attacks against critical infrastructure to supply chain vulnerabilities and now increasingly risks associated with artificial intelligence.
From Interpol's global perspective, one reality is clear, an open, secure, and stable cyberspace cannot be achieved without addressing one of the principal drivers of insecurity, that is the criminal misuse of ICTs.
Cybercrime has become one of the world's most significant illicit economies, generating trillions of dollars and affecting governments, businesses, and citizens across every region.
Cybercrime is becoming increasingly industrialized.
Specialized actors offer malware as a service, rent malicious infrastructure, and provide services supporting every stage of the criminal lifecycle.
The rapid development of AI is only supercharging this criminal supply chain, increasing the volume, speed, scale, and accessibility of cyberattacks and even creating new targets.
Importantly, the tools and infrastructures developed within criminal ecosystems can also be exploited by a broader range of malicious actors.
Combating cybercrime is therefore not only a law enforcement imperative, it is essential to advancing a safer and more resilient cyberspace.
This is where Interpol provides a distinctive contribution.
Through our secure communications network, cyber threat intelligence capabilities, operational coordination, and specialized capacity building activities, Interpol supports police cooperation worldwide.
These efforts deliver tangible results.
Earlier this year, Interpol's Operation synergy of three brought together more than 70 countries, many of which are represented in this room here today against phishing, ransomware, and other forms of malware.
The operation resulted in close to 100 arrests and took down some 45,000 malicious infrastructure.
Looking ahead, Interpol is also working with its member countries and partners to address key challenges, shaping the future threat landscape, from tackling the enablers of cybercrime as a service like residential proxies and bulletproof hosting to responding to both the challenges and the opportunities presented by the rapid evolution of AI.
To conclude, Interpol remains committed to supporting UN member states to strengthen international cooperation to combat cyber threats and to enhance collective cyber resilience.
We stand ready to contribute our operational expertise to the work of this global mechanism, including through its future thematic discussions so that together we can build a safer digital future.
I thank you.
Mu Thank you very much.
I now give the floor to the delegation of the African Union.
Madam Chair, the African Union Commission congratulates you on your leadership in convening this first substantive session of the global mechanism and in guiding the operationalization of the dedicated thematic groups.
The commissioner reaffirms its full support for this important process.
The Commission aligns itself with the statement delivered by the Afghan group and wishes to provide complimentary observations based on the Afghan Union's continental mandates.
Madam Chair, the establishment of this global mechanism represents an important opportunity to build on the progress achieved through the open ended working group.
At this stage, our collective focus should be on translating agreed commitment into action and delivering outcomes that respond to the realities and priorities of all Afghan Union member states across all regions.
The Afrhan Union has established a strong continental foundation to support this process through the development of the African Union Convention on cybersecurity and personal data Protection and the common African position on the application of international law to the use of ICs in cyberspace.
Furthermore, the ongoing development of the EU guidelines for the implementation of the norms of responsible state behavior in cyberspace, and the initiation of a Continental Declaration on peace and security in cyberspace demonstrate Africa's commitment to translating global commitment into practical Regional actions.
Madam Chair, Africa continues to face an evolving ICT threat landscape, including malicious cyber activities, targeting critical infrastructures, lonesome wear, online fraud, supply chain vulnerabilities, and the growing challenges of artificial intelligence.
For security.
The commission encourages the dedicated thematic groups Group one, to prioritize areas of practical progress, including the implementation of international law in cyberspace, critical infrastructure protection, artificial intelligence, and other emerging threats affecting patient security.
In this regard, the Afghan Union, Continental artificial intelligence strategy, and the advisory group on artificial intelligence that was nominated or appointed to support the AU Peace and Security Council can contribute to this discussion.
For Africa, practical implementation begins with capacity.
Capacity building must remain at the heart of this mechanism and should ensure gender mainstreaming and youth employment to promote innovation on the continent.
The Afrhan Union Commission welcomes the establishment of the dedicated thematic Group two, and we encourage early progress toward the global ICT security cooperation and capacity building portal.
Madam Chair, we continue to encourage the work of those two groups and we wish also that they will be aligned and mutually reinforcing.
Madam Chair, thank you and I submit.
Thank you very much.
We have now exhausted the list of speakers under this agenda item.
I have nonetheless received another request for the floor under the right of reply, and so I give the floor to this round.
Thank you, Madam Chair.
I regret we must ask for the floor again to respond to the stunning hypocrisy of the Iranian regime statements about international law and aggression.
For years, Iran has consistently and systematically violated every possible international obligation and norm, including by slaughtering tens of thousands of its own people, by intentionally attacking civilian centers in Israel and in other states across the Middle East, and by intentionally holding international maritime and tgation hostage at the expense of all member states.
This malicious and rogue Iranian regime has also continued financing, training, and arming its non state proxies, including Hezbollah Hamas and the Hoots, spreading death and destruction all across the Middle East.
If only the Iranian people could enjoy the benefits of the vast Iranian resources devoted to ongoing brutal aggression against other member states, so many innocent lives could have been spared.
Let me remind this chamber that the Iranian regime openly calls for the annihilation of Israel.
The situation of a member states of the UN actively and publicly pursuing the annihilation of another member state is unacceptable.
This regime has no moral standing whatsoever to preach against others, nor to lay false and outrageous claims while hypocritically invoking international law.
This is a farce that we should not and will not tolerate.
Madam Chair, we request that you exercise your leadership.
Iran cannot be allowed to continue and derail our discussions and waste our precious times.
Thank you.
Thank you very much.
I hope that all delegations will bear in mind that we have a very limited amount of time and that we should be focused on covering the agenda item before us, and I think that there are ways of better using our time and not entering into these discussions and I would ask all delegations to bear in mind that we have a lot to tackle and it is already 3:40 P.M.
I have been informed that the delegation of Iran has requested the floor.
I imagine that this is your second and last intervention under the right of reply.
I will give the floor to you and I would ask you to be very brief.
Thank you.
Thank you, Madam Chair.
I have already addressed the observed allegations made by the representative of the Israeli regime.
I don't intend to take up any more of the global mechanism valuable time or that of other delegations by responding to a repetition of those baseless claims.
They don't warrant any further response, and I don't intend it to dignify them with one.
I would, however, like to briefly react to one point in his intervention.
Nothing is more astonishing that hearing the representative of the Israeli regime speaks about Iranian people and the protection of civilians.
The people of Iran don't need crocodile tears from those responsible for the death of thousands of Iranians, including 168 school girls killed in the attack on an elementary school in Mino, the assassinations of our senior officials and the widespread destruction of civilian infrastructure across my country.
It is difficult to reconcile such rhetoric with the well documented consequences of the actions of the Israeli regime.
Those responsible for such atrocities in our region, including in my country, are in no position to lecture others on international law.
Chair, the Israeli regime has consistently sought to mislabel legitimate resistance groups in the region as terrorists or proxies.
Let us be clear.
According to United Nations General Assembly resolution 46 slash 51, these groups are not terrorists.
They are legitimate resistance movements fighting against occupation, apartheid, aggression, and genocide in the Palestinian and other occupied territories.
International law explicitly recognizes the right of peoples to resist foreign occupation and defend themselves against aggression.
The real terrorists are those who bomb hospitals and schools, massacre civilians, strike an elementary school in Minch killing 168 school girls and violate international law with impunity.
I thank you Madam Chair.
Thank you.
Distinguished delegates, before we begin the next topic, I would like to recall the following, which is set out in Annex one of a 80 slash 257 and accredited interested parties may attend substantive plenary sessions and the review conferences of the global mechanism.
And make oral statements during the sessions dedicated to interested parties.
It will also be possible to deliver interventions after states according to the availability of time and subject to the discretion of the chair at the substantive plenary sessions and the review conferences.
According to these modalities and in the spirit of cooperation with the community of stakeholders as indeed you have delegations, I intend to give the floor to those entities that are duly accredited to the global mechanism.
In this regard and specifically to provide information on this topic, which is existing and emerging threats in the area of ICTs.
I will be giving the floor for 3 minutes.
This will be strictly enforced.
I now give the floor to Kenya ICT Action Network.
Can you press the mic.
Thank you so much for Can you press the mic because we cannot hear you.
All right.
All right.
Thank you so much, chair, for this opportunity and for demonstrating your commitment to engaging stakeholders.
You have demonstrated that by engaging us even before the session started.
We are really grateful.
I think the other thing I need to note is that I have seen more women from the delegations making their statements, and that is really commendable because in the previous session, we didn't see that, so that demonstrates the training.
So I just want to make a short statement on behalf of different civil society organizations working to protect digital rights, human security, and peace.
For civil society, cybersecurity is not an abstract exercise in navigating geopolitics, but a matter of human safety, fundamental rights, and democratic survival.
Today, the existing threats that alarm us most are those that directly strike citizens.
We are witnessing unchecked proliferation of commercial spyware surveillance and state sponsored cyber harassment used to monitor, intimidate, and silence journalists, bloggers, human rights defenders, and political are dissenters, simultaneously emerging threats fueled by artificial intelligence driven automated surveillance and deep fix are weaponizing digital spaces to erode electoral integrity and supercharge tech facilitated gender based violence.
These tools disproportionately target women, persons with disabilities, minorities, and vulnerable groups facing out of public and civic life.
National security cannot exist without human security.
If global mechanism is to build genuine digital peace, we urge member states to prioritize three critical demands.
One, ground all cyber norms in human rights, and this calls for measuring to secure cyberspace that must never be used for censorship, Internet shutdowns, or criminalization of privacy and secure encryption.
We need states to also protect civic space and end intrusive surveillance, as well as ensure meaningful multi stakeholder participation because civil society acts as frontline defenders who monitor local harms and support victims on the ground.
A secure digital world is one Thank you very much for that intervention.
Now, I give the floor to Discover MUN Foundation.
Thank you, Madam Chair.
My name is Edward Yankel.
I take the floor on behalf of the Youth Publications and Socio Economic Forum, a subsidiary program of the DMUN Foundation.
The threats discussed this week demonstrate that ICT security depends on technologies and institutions.
It is important to note that they are also reliant on human capacity as well.
In that regard, I would like to emphasize one central message, invest in people, especially in young people.
Young people are the next generation of cybersecurity professionals, but we are already active participants in the digital ecosystem.
We are students, developers, researchers, and innovators.
The question then is, how should we make that investment? I would like to briefly share preliminary findings from a study I was part of involving more than 700 secondary school students at a New York City public high school with specialized academic majors.
Because students select their disciplines, we could compare perceptions of artificial intelligence among a diverse group of STEM oriented and non STEM oriented students.
We observed that students in non STEM disciplines expressed significantly greater concern about AI related job displacement than their STEM peers.
This gap persisted even after accounting for self reported AI use and skill.
In other words, more frequent and more proficient use of AI did not necessarily translate into greater confidence about broader consequences.
This finding could suggest a broader lesson for cyber capacity building.
Mere exposure to technology does not necessarily create understanding, preparedness, or most importantly, resilience.
We want to be precise about what this data does and does not show.
The study examined attitudes toward AI and employment, not cybersecurity knowledge or threat recognition.
Nevertheless, the findings offer a takeaway relevant to this discussion.
Access to an emerging technology and familiarity with it should not be treated as evidence that young people understand its broader consequences or feel prepared to address them.
As AI enabled capabilities become increasingly relevant to ICT security, young people should be resilient.
The youth should be equipped to use these technologies responsibly and also be equipped to recognize AI enabled threats such as phishing and malicious and deep fakes.
Concretely, we ask that youth serving organizations and youth capacity building practitioners be recognized as important stakeholders set out for the global mechanism.
Furthermore, we demand member states to nominate qualified youth capacity building practitioners to the DTGs.
Excellencies, we must invest in technology, but we must also remember the importance of an investment in people, and that investment must include young people.
Thank you very much.
Thank you very much.
So Distinguished delegates, I thank all of the delegations for this substantive discussion.
My team and I have taken due note of all of your statements, and I believe we can identify some common themes that have emerged over the course of our discussion.
What I'm going to now list is not intended by way of any hierarchy or intended to prejudge what is going to be discussed in the specific thematic groups, rather, I'm just providing some feedback as the chair saying what I've heard yesterday and today.
First of all the threat landscape, including complexity, the number of actors, but also the range of tools that are being used, the impact of emerging technologies such as artificial intelligence and other technologies.
Also impacting the security of ICDs and these offer opportunities, but they also give challenges.
The continued relevance of threats such as ransomware, the specific vulnerabilities of critical infrastructure, mainly in areas such as health, education, public administration, financial services, and also the critical information infrastructure such as subsidy cables.
You also indicated that there is a need to protect the supply chains for ICT services.
There were also many other topics that you delved into with a degree of technical detail.
We will take this into account with other things as well and this will inform the remainder of our program because it provides the context or the background that we need in order to develop the pillars of the framework for responsible behavior.
I have also heard concrete calls to action and for concrete solutions.
Many delegations emphasized the need for the mechanism to make progress and move to more action oriented decisions, exchange of information on threats, cooperation, capacity building, incident response, recovery.
And the creation of resilience implementation of the responsible use framework.
As I indicated at the beginning, this does not in any way prejudice or prejudge the discussions that we'll be having over the next couple of months as we prepare for the thematic groups.
Now Based on the program of work, we are going to begin the second substantive topic, which is voluntary non binding norms on the responsible behavior of states and the ways of their implementation, recognizing that over time additional norms may be developed.
I would be grateful if at this time, you could indicate whether you're interested in taking the floor so that together with the Secretariat, we may have some clarity as to the amount of time that will be required to cover this agenda item.
As I said yesterday, There is no established time limit for you to deliver your statement.
However, as chair, I would respectfully ask you to consider delivering an abridged version of your statement and send the whole complete version of this statement to the Secretariat to the chair.
Once again, you will also have a timer available for you on screen to help you manage your time.
I will now give the floor to Tonga on behalf of the Pacific Island Forum.
Thank you, Chair.
I have the honor to deliver this statement on behalf of the members of the Pacific Islands Forum, with a presence at the United Nations, namely Australia, the Cook Islands, Fiji, Kris, the Federated States of Micronesia, the Republic of the Marshall Islands, Nairo, New Zealand, Palau, Papua New Guinea, Samoa, Solomon Islands, Tuvalu, Vanuatu, in my own country, Ta.
Chair, or norms, the Pacific Islands Forum reiterates its longstanding position that the priority must remain the implementation of the existing voluntary non binding norms of responsible state behavior.
Our member states are at varying stages of operationalizing these norms, including identifying national critical infrastructure and critical information infrastructure, strengthening incident response capacity, Developing whole of government approaches and building the technical and policy foundations needed for implementation.
Our priority at this stage is the full implementation of the 11 agreed norms.
Many states, including small island developing states, are still building the capacity needed to operationalize these commitments and we see considerable value in the global mechanism supporting this work, including through a shared understanding of where implementation gaps remain and how capacity building efforts can best be targeted.
Strong and demonstrable record of implementation across all states will strengthen the framework of responsible state behavior as a whole.
The voluntary norms implementation checklist is a helpful step towards mainstreaming implementation.
To realize its potential, however, we also need consolidated guidance, capacity support and peer exchanges.
We would welcome the mechanism taking the checklist forward in a concrete action oriented fashion.
We see this as precisely the kind of practical task that dedicated thematic groups are well placed to advance.
This is also an area where stakeholders can make a meaningful contribution.
Technical experts, regional organizations, the private sector, academia, and civil society can help states understand how norms translate into practical steps.
For instance, expert briefings in the DTGs can provide practical input on implementation without changing the intergovernmental nature of decision making.
Global mechanism should therefore be a place where norms are made operational.
Its work should help states move from endorsement to implementation and from implementation in principle to implementation in practice.
Thank you Chair.
Thank you very much for that statement.
I now give the floor to the European Union.
They will be followed by Pakistan, Costa Rica, Colombia, and then South Africa.
EU, you have the floor.
Thank you very much, Chair and bear with me.
I tried to trim to the extent I'm able to on behalf of the EU and its member states.
Also candidate countries North Macedonia, Montenegro, Serbia, Albania, Ukraine, the Republic of Moldova, Bosnia, Herzevina and Georgia, and the Efta country, Norway member of the European economic area, as well as San Marino align themselves with this statement.
The EU and its member states reaffirm their strong commitment to the full and effective implementation of the UN framework of responsible state behavior in cyberspace.
As part of the framework, the 11 non binding voluntary norms of responsible state behavior constitute a central pillar and the practical implementation of the norms contribute to enhance transparency, predictability, and accountability of states in cyberspace.
It reduces also the risk of misperception and escalation and strengthens trust, and it supports the secure and resilient functioning of critical infrastructure and digital services upon which our modern societies depend.
The norms first agreed upon in the 215 UN group of governmental experts have been reconfirmed and reaffirmed at the open ended working group and are the basis of our future efforts.
In view of the actionable work by the UN on the implementation under the global mechanism, the UNS member states presented ahead of the plenary session an initial overview of our efforts to implement the norms of responsible state behavior.
For this contribution, which is published on the website of the global mechanism, we use the consensus norms guidance included in the 2021 report of the UN groups of governmental experts and we detailed our main pieces of legislation, our policies, our structures, mechanisms, and networks that we have put in place in order to implement the UN norms of responsible state behavior.
For instance, as regards Norm 13 B, that in case of ICT incidents, states should consider all relevant information, including the nature and the extent of the impact as well as in the event of a needed response included attribution, we have outlined our approach.
At union level, the most relevant EU level actors that contribute to shared situation awareness are the EU member states and their national cyber agencies.
The European Commission, the External Action Service include its intelligence and Analysis capacity, the EU Agency for Cybersecurity, ESA, and the Cybersecurity Service for the Union's Institutions CTU, as well as Europol's Cybercrime Center.
Under the framework of the Network and Information Security Directive, our cybersecurity legislation, the member states and EU actors cooperate at a strategic, operational and technical level and have created structures to cooperate at each level, such as the NIS cooperation group, the certs network of all EU member states, certs, as well as cyclone that compiles all EU cyber agencies.
Based on their shared situation awareness, these EU actors work together, consider all relevant information and provide a comprehensive assessment.
Further enhance our situational awareness, we have also put in place cooperative mechanisms with the multi stakeholder community, including through ESA's partnership program.
Based on this shared situation awareness, the EU and its 27 member states could decide upon an appropriate response, including diplomatic measures under a cyber diplomacy toolbox that also includes the option of attribution.
The agreed principles for such a response include, for instance, the need for it to be based on shared situation awareness among all 27 member states and for the response to be proportionate to the scope, skill, duration, intensity, complexity, and sophistication of the impact of the cyberacivity.
In other words, for us to consider all relevant information.
Like this, we have elaborated on each norm using the UNGGE norms guidance and detailing our main efforts.
We aim to further work on detailing our efforts, including providing more insights in the efforts by individual member states in the implementation at national level, notably also in the fields of capacity building assistance and mitigation and recovery after incidents.
This EU contribution complements the 2024 declaration by the EU and its member states on the application of international law in cyberspace as we should not forget that voluntary norms do not exist in isolation, but they sit along in international law.
While norms are voluntary and non binding, international law itself is binding.
To take one example, international law prohibits the use of ICTs, including ransomware to interfere coercively in the internal or external affairs of other states.
The norms make it clear that states should not use ICT tools such as ransomware to disrupt critical infrastructure.
To further build our common understanding on the ways and means to implement the norms of responsible state behavior, we encourage also other states in sharing their experiences in implementing the norms, which will help to enhance our implementation efforts.
In addition to such written contributions that some regions already made, the DGGs are best placed to elaborate on the implementation of the norms connected also to a specific cybersecurity challenge, such as the protection of critical infrastructure or ransomware and to exchange best practices between states that could feed into concrete recommendations on how to enhance national cyber resilience.
This context, we also see the draft voluntary norms checklist as a valuable tool to take our work forward.
The checklist could be treated as a living document and serves as the primary reference as states continue to implement the framework.
We could use the checklist as a reference document facilitating the discussions in our DTGs to which we look forward.
Thank you very much Chair.
Thank you very much.
I now give the floor to the delegation of Costa Rica to be followed by Colombia.
Or Madam Chair, Costa Rica appreciates the opportunity to speak on this pillar relating to the norms, rules, and principles of responsible state behavior in cyberspace.
For Costa Rica, the global mechanism must build on the accumulated body of work of the groups of governmental experts in the open ended working groups.
Goal is not to reopen previously reached consensuses, but rather to consolidate them and translate them into national practices, institutional capacities, and concrete cooperation.
In particular, the voluntary norms of responsible behavior agreed upon in 2015 and the 2024 voluntary list of practical actions continue to provide a foundation for guiding state conduct, reducing risks, and promoting international stability and security.
Costa Rica emphasizes that these voluntary norms do not replace international law that is applicable to cyberspace.
Rather, they complement it by offering practical guidance to foster transparency, predictability, restraint, and trust.
The strength of this framework lies precisely in its ability to link general principles with concrete measures for prevention, cooperation and resilience.
In this regard, we consider it important to move towards practical implementation of norms that are particularly relevant to the protection of critical infrastructure, essential services, and government functions, areas that states must refrain from targeting.
The recognition of trusted technical actors, CRTs, and CSRTs distinct from offensive intelligence or other law enforcement functions, and a good faith response to requests for assistance must be central to our discussions.
Furthermore, Costa Rica believes that due diligence actions should be approached in a balanced manner.
Both as a responsibility to adopt reasonable measures commensurate with national capabilities to prevent a state's territory or infrastructure from being used for harmful cyber acts against other states, and also as an agenda for cooperation technical assistance and institutional capacity building, Madam Chair, responsible state behavior, must not remain merely at the level of declarations.
It must be translated into public policies, communication channels, responsible vulnerability disclosure of multi stakeholder cooperation and measures that can reduce the risk of escalation in the event of conflict.
Costa Rica hopes that this mechanism will contribute to transforming the existing consensus into concrete, inclusive and results oriented action.
I thank you.
Thank you very much.
I now give the floor to Colombia to be followed by South Africa Microphone, please.
Microphone for Colombia please.
Madam Chair, under this item, Columbia highlights the importance and the practical approach of the norms, rules, and principles of the framework for responsible behavior of states.
Pillars, it helps to strengthen internal digital resilience.
My delegation believes that the existing norms have breadth and flexibility to address an environment that is constantly changing without prejudice to the idea that other principles may be considered to address the challenges from emerging technologies, especially those linked to the differentiated impact on individuals and communities and situations of vulnerability.
However, the principal challenge that we're facing today is not the absence of norms, but rather effective implementation.
There are still questions as to how states will interpret and apply the norms that have been agreed and also as to the understanding of challenges that limit cooperation, time and exchange of information, and active participation in confidence building mechanisms such as the global directory of points of contact.
This is why Colombia considers that the initiatives to strengthen capacity that will be taking place under the second thematic group should be focused prioritaly as operationalizing the norms.
Sharing national experiences, developing practical tools, and strengthening institutional capacities.
This will allow us to translate our decisions into concrete actions.
In this regard, we invite states to consider voluntary publication of their national positions on interpretation and application of specific norms.
This exercise would contribute to promoting greater mutual understanding.
It would facilitate the exchange of best practices and help us identify common areas and move towards more coherent and effective implementation of the existing framework.
Madam Chair, in a geopolitical context where a growing part of interactions between states are taking place in cyberspace, the norms represent a common language that will allow us to reduce uncertainty guide expected behavior and reinforce trust between states through dialogue and transparency.
The global mechanism provides a unique opportunity for translating this common language into practical tools to guide action by states and strengthen international cooperation.
I would like to take this opportunity to say this will be one of the major contributions this process can offer to international stability and security.
Colombia reiterates its readiness to continue working with all delegations to achieve this goal.
I thank you.
Thank you very much.
I now give the floor to the delegation of South Africa and I will just tell you the next five speakers, Malawi, Brazil, Italy, Morocco, and Cuba, South Africa, you have the floor.
Thank you, Chair.
There is no doubt that as the world's reliance on ICTs continues to grow, the responsible conduct of states in the use of ICTs has become crucial for the preservation of international peace and security.
When discussing norms for responsible state behavior, it is essential to maintain a balance in keeping the cumulative normative framework current while transitioning from a conceptual discussion to an action oriented approach facilitated through the DTGs.
South Africa considers the further development of norms as a systematic evaluation, updating where required, and enhancement of the framework, which can be achieved through the implementation of voluntary non binding norms, which will reveal both effective practices and potential gaps, thereby enriching the discussions.
As indicated in the African group statement, states will require effective tools and guidelines to implement the UN NMT framework for responsible state behavior.
In this context, the efforts of the DTGs should focus on finalizing the voluntary checklist in accordance with paragraph 38 of the OEWG 2021 to 2025 final report.
Furthermore, given the sage of attacks targeted at critical infrastructure and critical information infrastructure, South Africa proposes a discussion on NMS F, G and H regarding the safeguarding of critical infrastructure and critical information infrastructure under DTG one as a practical step for focused deliberations, sharing of knowledge, lessons learned, exchange of expertise, and efficient use of time allocated to the Ds in December.
Madam Chair, South Africa's Critical Infrastructure Protection Act of 2019 recognizes that specific infrastructure is essential for public safety, national security, and the continuous delivery of vital public services.
Accordingly, this act mandates the identification and implementation of appropriate measures to safeguard and ensure the security of critical infrastructure.
It defines infrastructure as critical infrastructure if its operation is vital for the economy, national security, public safety, and the uninterrupted provision of essential public services.
Any loss, damage, disruption, or immobilization of such infrastructure could significantly impact our country's functioning or stability, the public interest in terms of safety and the maintenance of law and order.
We look forward to hearing about others approaches and experiences at the DTGs meeting in December.
Thank you chair.
Mu.
Thank you very much.
I now give the floor to the delegation of Malawi.
Okay.
Madam Chair, the Republic of Malawi thanks you for giving us the floor.
Before turning to the substance of our intervention, the Republic of Malawi wishes to underscore one important consideration.
Norms do not exist because cyberspace is predictable.
They exist precisely because it is not.
In an environment where technologies evolve rapidly and misunderstandings can have far reaching consequences, voluntary non binding norms provide something invaluable predictability, confidence, and a shared understanding of responsible state behavior, even when our laws differ.
Through the work of the GGEs and OEWG and now this global mechanism, member states have progressively built a cumulative and evolving framework on consensus.
This demonstrates that even in a rapidly changing technological landscape, cooperation remains possible.
The Republic of Malawi, just like South Africa, acknowledges that the DTG has to pay close attention to norms F, G and H, noting that destruction of critical information infrastructure does in most cases, lead to the breach of international humanitarian law because data is usually involved.
We have prioritized the implementation of norms relating to the protection of critical information infrastructure.
International cooperation and capacity building through the Malawi Computer Emergency Response Team, and our Data Protection authority, regularly engaging with the national and international community to conduct cybersecurity awareness, child online protection initiatives, threat intelligence sharing, and vulnerability management, support to critical information infrastructure operators, national cyber drills, and multistakeholder engagements, which normally involve government, the private sector, academia, and civil society through established sector seers.
These practical measures strengthen resilience while fostering trust and confidence among stakeholders at both the national and international levels.
For us, the value of these norms lies not in what they encourage states to do, but in the confidence they foster among states.
Promoting restraint, transparency and cooperation, reducing the risk of misunderstanding and miscalculation.
My delegation therefore welcomes the emphasis on practical and technical discussions within the dedicated thematic groups, recognizing their role in advancing inclusive, action oriented recommendations and strengthening the implementation of the framework.
As recognized in previous consensus reports, this framework is cumulative and evolving.
However, its strength will not be measured by the number of additional norms we develop, but by our collective commitment to uphold those we have already agreed.
Looking ahead, my delegation considers the dedicated thematic groups an important opportunity for member states to exchange practical experiences, share lessons learned, and identify good practices that strengthen confidence and support the effective implementation of the framework.
Finally, Madam Chair, consensus has been the strength of this framework.
Let implementation become its legacy.
I thank you.
Thank you very much.
I now give the floor to the delegation of Brazil.
Madam Chair, Brazil is a staunch supporter of the achy of previous UN processes on ICTs and international security, particularly the voluntary norms of responsible state behavior.
Their continued relevance after a decade of exponentially accelerating technological innovations is a testament to how well they were drafted by focusing on actions rather than on specific technologies.
The norms have guided us on the establishing and updating of our national norms and policies to secure our critical infrastructures and critical information infrastructures against cyber threats, including our most recent national cybersecurity strategy adopted last year.
In this regard, we welcome efforts to facilitate norms implementation, including the voluntary checklist of practical actions drafted within the OAWG which could be further developed in the context of this global mechanism.
We also recognize the importance of international cooperation efforts in promoting the national implementation of norms.
We have greatly benefited from the national experiences of other countries and therefore fully welcome continued knowledge sharing this area, which is something that this global mechanism could promote.
Regional cooperation has also been particularly relevant in this area.
Brazil has been engaged in multiple initiatives in this regard, such as the OAS C Cert Americas, which has been instrumental in advancing the norms related to information sharing on threats and vulnerabilities.
Mercosur Cybersecurity Commission has also fostered national implementation of these norms through information exchange on cybersecurity institutional and legal frameworks, as well as the ongoing development of a common regional taxonomy.
The promotion of gender equality is a key component to the adequate implementation of the norms.
Promoting the inclusion of women to the cybersecurity workforce, as well as having policies that address the differentiated impact of cyber threats to women and other vulnerable groups in our society is an important component of our new national cybersecurity strategy.
Madam Chair, we have heard throughout our debates arguments for advancing the implementation of the existing norms and for the adoption of new ones.
In our view, these positions are not in any way mutually exclusive and this global mechanism can have room for both as long as there is consensus.
In any efforts aimed at eventually developing new norms of behavior in the cyber domain must be inclusive and therefore take place within this mechanism where the needs of all countries are duly taken into account.
The truth of the matter is that there are many initiatives currently underway outside of our multilateral process that aim to shape a state behaving in areas that clearly fall within our purview.
I thank you.
M.
Thank you very much.
I now give the floor to Italy to be followed by Morocco.
Good afternoon, Madam Chair.
Thank you for giving me the floor.
Italy fully aligns itself with a statement delivered by the European Union and wishes to add a few considerations in its national capacity, also benefiting from contributions of the four stakeholders objected by the Russian Federation.
Madam Chair, the framework of responsible state behavior developed through the GGE and UEWG provides a solid foundation for the international community that requires systematic and continuous implementation.
Priority should be given to supporting states in translating agreed norms, international policies, institutional procedures, and operational practices.
In our view, being responsible in the use of ICTs means to understand the duties that each country has to contribute to international peace and stability, as well as to be accountable for its actions and non actions.
In light of the many challenges and possible difficulties in implementing the 11 norms, we believe that the voluntary checklist adopted by the third APR was a very precious tool for all member states and thus, we hope that the global mechanism can take advantage of it, promoting a discussion on its finalization.
Italy continues to align to the 11 norms, building on strong normative foundations domestically, thanks to EU directives, regulations, and national law while adapting to technological evolution and maintaining a strong commitment to international cooperation for stability and security in cyberspace.
A few examples.
Italy keeps implementing a range of measures to ensure the integrity of supply chain as in Norm I through the National Cybersecurity Agency, which implements and oversees the National Cybersecurity perimeter, acts as the National Evaluation and Certification Center, and is responsible for the implementation of the EU NIS two Directive, strengthening ICT supply chain security and trusted Procurement.
The National Cybersecurity Agency serving as the National cryptographic Center, also promotes the use of cryptography as one of the cybersecurity tools for guaranteeing an effective resilience and long lasting level of protection of critical infrastructures from ICT threats as you know F.
Particular attention should be also given to the integration of IT and OT security requirements, which are still too often addressed separately despite their increasing convergence.
It could be interesting to exchange views on possible common baseline security principles, secure by design approaches throughout the life cycle of digital and industrial systems and internationally recognized methodologies for cyber maturity assessment.
Academia should be actively involved in such exchanges.
States should also promote coordinated vulnerability disclosure procedures and clear legal safeguards for good faith security researchers.
Multi stakeholder partnerships are essential in this regard, allowing governments to leverage technical expertise, operational experience, and innovation capabilities developed by competence centers, research organizations, and the private sector.
That is why we firmly believe that DTG one can play a key role in facilitating a thorough discussion across the five pillars, helping deepen the practical implementation of norms.
DTG two then can produce tailored CCB projects that will also contribute to a more responsible behavior of states in the use of ICTs.
Thank you very much.
Thank you very much.
I now give the floor to the delegation of Morocco.
Madam President.
Madam Chair, voluntary and non binding norms remain one of the key pillars of the framework responsible behavior by states.
Their goal is clear to reduce the risk of conflict and escalation in cyberspace by governing the way in which member states conduct their cyber activities.
They aim to protect critical infrastructure as well as emergency response teams and promote information exchange and mutual assistance between states.
In the event of an incident.
The goal is to establish a climate of trust between state actors.
In this card, Al Gson would like to highlight two observations.
First of all, The list of norms should not be set in stone given the rapid evolution of threats and emergency technologies and modes of operation, including AI.
In light of this, our framework must be able to evolve.
The 11 voluntary non binding norms of the GG report 2015 serve as our foundation, and all of us should maintain the ability to enrich or clarify them if necessary.
Role of future dedicated theoretic groups in this regard is invaluable.
We encourage these groups to when the time comes, examine this topic and present concrete proposals for enriching them.
Secondly, action must be focused on effectively implementing existing norms and norm only maintains its value if it is implemented coherently by all states.
To ensure that is effective, it is important to intensify our actions when it comes to ctical capacity building.
We place great importance on the fact that states, especially developing states should be supported in taking ownership of these norms through tools, information, and necessary resources.
Thank you.
Thank you very much.
I now give the floor to the delegation of Cuba, which will be followed by the next five speakers, which are Portugal, Republic of Korea, Vanuatu, Nigeria, and China.
Cuba, you have the floor.
Thank you very much, Madam Chair.
We reaffirm our position in favor of developing legally binding norms under the auspices of the United Nations that would complement the applicable principles of international law, respond to legal gaps in the area of cybersecurity and facilitate impartial handling of the growing challenges and threats faced by states in this area.
Non binding norms are limited by their voluntary nature as their implementation depends on the political will of states.
The non binding voluntary norms, therefore only constitute an intermediary step towards achieving our goal.
The alarming statistics reveal that Voluntary norms on their own are not enough.
This is demonstrated by the annual increase in cyberattacks with ever greater speed scale and sophistication.
This is also demonstrated by the growing militarization of cyberspace, with an increase in the development of cyber offensive capabilities.
A considerable proportion of these attacks are based on politically motivated false attributions and the eagerness to justify hostile actions against states.
We recall that the norms, rules, and principles elaborated by the GGE in the past where not all member states participated do not enjoy universal acceptance, the mandate of this global mechanism recognizes that additional norms may be developed over time.
We see a need to strengthen the regulatory framework to address matters in the field of security and the use of ICTs in a context of growing threats.
The development and implementation of norms for responsible behavior of states in cyberspace should be grounded in respect for the principles of sovereignty, sovereign equality, political independence, and territorial integrity.
Should also promote peaceful coexistence and international cooperation for mutual benefit and interests.
Developing countries stand at a disadvantage in developing technical, technological, regulatory capacities.
This disadvantage is further exacerbated when such countries suffer the impact of unilateral coercive measures.
The lack of conditions in developing countries to determine when they are used for attacks on others has even become an industry with really quite considerable dividends.
The countries of the South, even though we have common responsibilities, these must be differentiated from those fully developed countries.
Standards are needed, for example, in relation to prevention and militarization of cyberspace, promotion of cooperation to close the digital divide, and matching capacities to respond to the threats faced by states as well as to the peaceful settlement of potential disputes.
The urgency required to jointly confront the growing threats means that we cannot be left at the mercy of a world based on voluntary norms of supposedly good behavior.
This is a notion that can be manipulated according to political interests and contexts.
A broad legally binding instrument that establishes obligations with permanent monitoring would be, in our view, the most effective contribution to establishing a model of responsible behavior by states.
One could start, for instance, by considering the development of a roadmap, a global cybersecurity index established by the ITU includes a set of indicators that could be a starting point.
Thank you.
Thank you very much.
I now give the floor to the delegation of Portugal.
Thank you, Madam Chair.
We aligned with the intervention of the EU, but would like to add a very brief comment in our national capacity.
The mandate of this permanent mechanism to promote responsible state behavior in cyberspace in the context of international security, provides for regular institutional dialogue focused on the implementation of the consensually agreed framework endorsed by the UN General Assembly since 2015.
As we have often emphasized, this dialogue is meant to contribute to upgrade national cyber capabilities across divides and thus enabling us to move on to a formal system of mutual accountability that levels up all member states contributions to peace and security in the digital space so that all of them can peacefully and securely benefit from the digital transition.
For more than five years, it has been clear that the majority of the membership is in favor of prioritizing an exchange of lessons learned in combating the increasing degree of insecurity, which has been documented year after year and again yesterday and today.
The plurality of member states which patiently negotiated the mandate of an action oriented, permanent mechanism within the framework of the open ended working group and with the constant support of the overwhelming majority that voted in favor of its establishment have demonstrated the strength of our consensus.
Therefore, Portugal strongly believes that the two dedicated thematic groups designed to address specific security challenges and to accelerate cybersecurity capacity building to confront them have the potential to lead us towards action oriented results to be debated during our next plenary session on the basis of their recommendations which you, Madam Chair, will then convey to us.
It was that ambition that led us to establish a permanent mechanism of regular institutional dialogue with its present architecture, deliberately meant to be more stable than its predecessors and more oriented towards implementation of the 11 voluntary norms of responsible state behavior already endorsed and of the applicable international law than towards the discussion of even more norms or even more binding instruments.
Thank you, Madam Chair.
Thank you very much.
I now give the floor to the delegation of the Republic of Korea to be followed by Vanuatu.
Thank you, Madam Chair.
As noted earlier, the work of the global mechanism should build upon the consensus achieved through the GGE and the OAWG process.
In this regard, we should focus on identifying practical ways to effectively implement the 11 voluntary non binding norms of responsible state behavior that were agreed by the GGE and subsequently endorsed by the United Nations General Assembly.
In particular, we believe that the voluntary checklist of practical actions for the implementation of voluntary non binding norms of responsive CPA reduced ICT should continue to serve as a living document.
The global mechanism should continue discussions on the checklist with a view to its eventual finalization while ensuring that it remains practical, relevant, and responsive to evolving needs.
Global mechanism should continue to strengthen efforts to support and facilitate the implementation of the norms that have been agreed.
Therefore, our priority of global mechanism should be the effective implementation of existing commitments rather than the development of new norms at this stage.
I thank you.
Thank you very much.
I now give the floor to Vanuatu.
Madam Chair, Vanuatu aligns itself with this statement delivered by Tonga on behalf of the Pacific Alllands Forum members.
The 11 norms of responsible state behavior were agreed by every state in this room.
Vanuatu's interest now lies in a single question.
What do those commitments require of states in practice and how do we know they are being met? Fu wishes to offer a perspective on that question that comes directly from our national circumstances.
The norms concerning critical infrastructure, the commitment not to conduct or knowingly support ICT activity that damages it, the commitment to protect one's own and the commitment to respond to requests for assistance when it is attacked, carry particular weight for a country whose survival infrastructure is digital.
Our multi hazard early warning network, our emergency broadcast, capability, our systems for coordinating relief across 83 islands.
These are the assets that stand between a natural hazard and a humanitarian catastrophe.
Vanuatu invites states to affirm through their conduct and their statements in this mechanism that infrastructure enabling disaster preparedness and response falls squarely within the protection these norms describe.
There could be no clearer test of responsible behavior than restraint towards the systems that keep vulnerable populations alive.
We also underline the non relevant duty of states not to allow the territory to be used for international wrongful acts using ICTs.
For small states on the receiving end of transnational malicious activity, this expectation of diligence is among the most consequential elements of the framework, and we encourage continued exchange in this mechanism on what reasonable capacity approach diligence looks like for states at different levels of development.
Vanuatus product position on this pillar has been consistent across the OEWG and remains so.
The task before us is observance, not expansion.
The existing commitments have not yet been implemented by all states to a standard that would refill any genuine gap.
We support using this mechanism, including the cross cutting dedicated thematic group in December to examine implementation in operational detail.
What national arrangements give effect to each norm, what evidence of implementation looks like, and where support is required.
Fano two is prepared to share its own experience candidly, including where our implementation remains work in progress, and we encourage others large and small to do the same.
Honesty about implementation is itself a contribution to accountability.
The norms where the international community's answer to the question of how states should behave towards one another in cyberspace.
Vanuatus answer to the question of what comes next is simple, show it in practice.
I thank you.
Thank you.
Thank you, look forward to Nigeria.
Madam Chair, Nigeria once again congratulates you on your steering leadership.
You can count on my delegation's full support and constructive engagement as you lead this important process.
Nigeria aligns itself with the statements delivered by the African Group and wishes to make the following remarks in our national capacity.
Nigeria remains firmly committed to preserving the state led, single track, inclusive, transparent, and consensus based nature of this mechanism.
Consensus has consistently enabled progress in this process and should continue to guide our collective efforts.
Distinguished delegates, as we embark on this new phase, our priority should be implementation.
The extensive body of recommendations developed by the group of governmental experts and the open ended working groups have provided a comprehensive nome framework for responsible state behavior in cyberspace.
The task before us is, therefore, to translate these agreed commitments into practical measures that strengthen national capacities, enhance resilience, and deliver tangible benefits for all member states, particularly developing countries.
Nigeria welcomes the establishment of the dedicated thematic groups and supports scenario based discussions as an effective means of strengthening implementation, improving collective preparedness, and facilitating practical cooperation.
Such exchanges provide valuable opportunities to share national experiences, strengthen incident response capabilities, and deepen our collective understanding of evolving cyber threats.
The rapidly evolving cyber threat landscape demands our audience attention.
Attacks on critical infrastructure, and critical information infrastructure, ransomware, ICT supply chain vulnerabilities, threats to undersea cables, electoral process, disinformation, and the malicious use of artificial intelligence pose significant risks to international peace and security.
These threats disproportionately affect developing countries, widening digital divides, and undermining sustainable development.
Madam Chair, Nigeria reaffirms that international law, including the Charter of the United Nations, applies to the use of ICTs.
We underscore the principles of sovereignty, sovereign equality, non intervention, and due diligence, as well as the applicability of international humanitarian law and international human rights law as essential to maintaining international peace and security in cyberspace.
Capacity building remains indispensable to the effective implementation of the agreed framework.
It is central to reducing vulnerabilities, narrowing the digital divide, and enabling all states to participate meaningfully in promoting international ICT security.
Madam Chair, Niger recognizes the valuable contributions of relevant stakeholders, including civil society, academia, and the private sector in support of the state led and intergovernmental mechanism.
We encourage the Chairs continue consultations towards a pragmatic solution of the outstanding stakeholder participation issues.
In conclusion, Madam Chair, the success of this global mechanism will ultimately be measured not by the number of meetings we convene, but by the practical outcomes we deliver.
Stronger national capacities, effective implementation mechanisms, enhanced confidence among states and a more resilient global ICT environment.
Nigeria remains committed to working constructively with all member states to ensure that this mechanism delivers meaningful results and contributes to an open, secure, stable, accessible, peaceful, and interoperable cyberspace for the benefit of all.
I thank you, Madam Chair.
Much Thank you very much.
I now give the floor to China, followed by the following five.
Botswana, Thailand, Islam, New Zealand and Iran.
You have the floor.
Thank you, Madam Chair.
Confronted with a new landscape and new danger in cyberspace, we must uphold multilateralism to effectively respond to risks developed and draft the framework for responsible state behavior to make sure the framework can evolve with the times and can also be a cumulative and progressive.
China believe that we should develop new norms regarding the following issues first.
AI's impact on cybersecurity.
AI defensively and offensively has a profound impact on global cybersecurity.
We should establish barrier for the frontier AI models and to guard against possible security risks and geopolitical risks due to the convergence of cyber technologies with AI.
Second, the importance of data security has been increasingly prominent.
At present, data security is increasingly prominent.
Global mechanism should discuss developing a universal non discriminatory international norms on data security to provide effective institutional guarantee for the protection of data security across the world that we need to strengthen the protection of critical infrastructure.
Safeguarding critical infrastructure security is a shared concern of all countries.
Global mechanism should improve and develop norms for responsible state behavior regarding Yes.
The protection and promotion of critical infrastructure security states should not use cyber means to damage other countries' critical infrastructure, especially key information infrastructure concerning national economy, livelihoods, and public interests such as energy, transportation, water conservancy, finance, public services, e government, and other key information infrastructure.
Nor should that damage or CO key data from other countries' critical infrastructure.
Fourth, maintaining open, secure, and stable global digital, intelligent, industrial, and supply chains, It's also important building upon existing consensus, which will further refine and specify the effort to develop and implement globally interoperable common rules and standards for supply chain security and oppose the man made fragmentation of supply chains driven by political motives.
Madam Chair, China hopes that the DTG one of the global mechanism can give serious consideration to China's proposal.
China stands ready to adopt a constructive attitude to work together to make sure our global mechanism achieve new progress in developing and improving the norms regarding responsible state behavior.
Thank you.
Thank you very much Botswana.
Thank you, Chair.
Botsana reaffirms a steadfast commitment to the UN cyber framework and emphasizes that the 11 voluntary norms reinforced by the UN charter and the existing international law are sufficient to govern state conduct in the cyberspace.
For developing states such as Botswana, the debate initiated at the OAWG regarding the implementation of the existing norms against the formulation of new norms is secondary to the immediate reality of the digital divide.
Developing countries cannot effectively protect critical infrastructure, prevent cross border cybercrime, or guarantee the integrity of their supply chains if they lack the underlying technical and institutional capacity to do so.
We emphasize the role of the DTGs in formulating concrete and action oriented strategies to effectively implement the existing norms.
These will provide a structured and predictable avenue for the private sector, civil society, and academia to contribute technical expertise in norm implementation and targeted capacity building in that regard.
The National Cyber Survey and the UN Cyber noms National implementation checklist serve as baseline instruments for the global mechanism and its DTGs by providing clear and actionable tracking where UN member states systematically document, monitor, and update their domestic progress in executing the 11 voluntary noms.
These tools provide practical framework for identifying national and regional capacity gaps to make the work of the DTGs targeted and actionable.
Domestically, Botswana, through its national cybersecurity strategy and its progressive legislative tools such as the Cybersecurity Act has advanced to safeguard its critical national infrastructure.
Our national set further acts as an operational engine responsible for implementing the voluntary norms of responsible state behavior.
Their work also involves the response to requests for assistance, sharing of threat intelligence and best practices, coordination of local investigations, as well as mitigation of malicious cyber incidents on Botana' networks and to also ensure a secure and stable digital environment.
Botana reiterates its commitment to implement these global norms through a phased approach aligned with its national capacity and available resources.
Thank you, chair.
Thank you and I give the floor to Thailand.
Madam Chair, Thailand elements committed to the 11 voluntary non binding norms of responsible state behavior in cyberspace, recognizing that they complement existing International law applicable to the use of ICTs in cyberspace and should be interpreted in a manner consistent with the purposes and principle of the UN Charter.
These norms meaningfully real risk to international peace, security and stability by providing a practical foundation for enhancing transparency, fostering cooperation, and promoting predictability in cyberspace, thereby building mutual trust and confidence among states.
In addition, Thailand is of the view that the voluntary checklist of practical actions serves as a useful capacity building tool that supports this in developing baseline ICT security capacities and resilience.
While respecting this prerogative to structure its implementation in accordance with its national circumstances.
At the regional level, AN, as the first regional organization to have adopted the cyberspace norms in principle, has finalized its norms implementation checklist to support member states in translating norms into practice.
At the national level, Thailand has integrated these norms of responsible behavior into our national policy and action plan on cybersecurity 2022 to 2027.
The next plan for 2028 to 2032 is currently under development guided by the RCNNO EWG checklist.
Thailand values and encourage regional organizations and frameworks to adopt and implement these norms, rules, and principles of responsible state behavior as part of the global confidence building efforts.
As we move forward, Thailand supports continued exchanges of views on the rules, norms, and principles of responsible state behavior in the use of ICTs within the global mechanism.
Thailand remains open to discussions on the possible development of additional norms, rules, and principles of responsible state behavior in the use of ICTs, particularly in response to emerging threats.
At the same time, such discussions should take into account the diverse context, needs, and capacities of states.
Any additional frameworks should not impose obligations beyond states capacities or serve as a means of technological exclusion.
Instead, they should contribute to bridging the digital divide and strengthening the resilience of developing countries against evolving cyber threats.
Thank you, Madam Chair.
Thank you, followed by New Zealand.
Thank you, Madam Chair.
The Kingdom of the Netherlands aligns itself with the statement delivered by the European Union.
Please allow me to make some further comments in my national capacity.
To the Kingdom of the Netherlands, the 11 non binding voluntary norms form an integral and essential part of the consensus normative framework for responsible state behavior.
We consider it pivotal that while the norms are not in themselves binding, they do confer a degree of mutual expectations on states to behave responsibly in cyberspace.
They point towards our collective path forward and the implementation should be front and center of a work within the UN global mechanism, but also within our national policies.
Chair, please allow me to highlight three elements to aid the implementation of the 11 voluntary norms.
First, the DTGs should provide the opportunity for states to discuss the norms not in isolation, but in a cross cutting manner with the other pillars of the normative framework when addressing specific cyber threats and dilemmas.
One way to do so is by providing guiding questions that prompt member states to discuss the norms in conjunction with the international law, confidence building measures, and capacity building instead of tackling each pillar one by one.
The norms are best implemented in the recognition that the normative framework is a unitary framework rather than a collection of parts.
Second, the Kingdom of the Netherlands believes that a voluntary checklist for the implementation of norms as developed by the previous open end working group, remains a tool of great potential for the implementation of the 11 norms.
We should endeavor to strengthen and operationalize the checklist and lay the basis for a voluntary instrument for self reporting on the implementation of the 11 norms.
The EU paper on Norms implementation is a perfect example of what such reporting could look like.
Finally, in order to ensure that the norms can be implemented by the whole membership of the U and global mechanism, the Kingdom of Is believes that the collective efforts at cyber capacity building should be well aligned with the aims and contents of the 11 norms for responsible state behavior.
Co production and demand driven approach to such capacity building efforts remains essential for their success.
We will do well not to reinvent the wheel, but to draw upon resources already available.
Examples of such resources are the norms implementation guides as published by members of the multi stakeholder community, such as the Geneva Dialogue, but also by UN entities such as UDR and regional groups such as the OS.
Chair, by combining practical DTGs with a well developed voluntary checklist, and effective capacity building, the Kingdom of the Netherlands believes that we can collectively make great strides in the implementation of the 11 voluntary non binding norms for responsible state behavior.
We trust in your guidance and assure you of our support in your efforts.
Thank you.
Thank you very much.
I now give the floor to New Zealand.
Thank you, Chair.
We are aligned with the statement by the Kingdom of Tonga on behalf of the Pacific Islands Forum and offer the following in our national capacity.
Implementing the norms of responsible state behavior improves stability in cyberspace and strengthens the resilience of the ICT systems on which our economic and social interests depend.
The question is how in a very practical sense, can we support norms of implementation? On this point, we have been struck by the valuable contributions that regional groups are making.
We welcome that you use non paper detailing how it is implementing the norms.
It's a practical and substantive demonstration of what implementation can look like.
Even if implementation may look different in other regions, the paper offers inspiration and useful food for thought.
Likewise, the Asean norms implementation checklist is a valuable point of reference not only for Asean, but for all states who want to implement the norms.
We also look forward to the African Union finalizing its guidelines on norms implementation.
From the Pacific region, we reiterate the message from the Pacific Islands forum that the regional priority for now is fully implementing the existing norms.
To this end, the key value that the global mechanism could provide is further guidance and capacity building coordination to support implementation at the national level.
This is where the DTGs could prove their worth.
By considering specific scenarios or specific cybersecurity challenges, experts and states could share experience on what best practice looks like, offer peer learning, and identify specific areas where capacity building would support implementation.
This in turn could generate further practical contributions both to address capacity building needs and to develop further guidance such as the voluntary checklist discussed in the OWG.
Thank you.
Thank you very much.
Indeed.
I now give the floor to the Islamic Republic of Iran to be followed by the following five speakers, Ireland, then Ukraine, Canada, Japan, and then Singapore.
Iran, you have the floor.
Thank you, Madam Chair.
Paragraph 36 D of the OEWG final report reaffirms that given the unique attributes of ICTs, additional norms could continue to be developed over time.
Accordingly, paragraph nine of Annex C explicitly assigns the global mechanism the task of elaborating additional rules, norms, and principles of responsible estate behavior.
Recent developments further demonstrate why the continued elaboration of additional voluntary norms remain necessary.
As my delegation as illustrated under the agenda item on threats, recent unlawful cyber operations carried out by the United States and the Israeli regime in conjunction with their unlawful military attacks against my country have targeted critical infrastructure and essential civilian services, exploited private sector technologies, ICT supply chains, and digital platforms, involved cyber espionage, disinformation and cognitive operations, and integrated cyber capabilities with conventional military operations, including electronic warfare and interference with communications and satellite navigation systems.
These developments revealed important gaps in the existing normative framework and underscored the need for the global mechanism to elaborate additional voluntary norms to promote the exclusively peaceful use of ICTs and contribute to international peace, security and stability.
In light of these developments, my delegation believes that particular attention should now be given to several areas where further normative developments is both necessary and timely.
These include inter aa data security, including cross border data flows, the accountability of private sector entities operating in ICT environment, and the use of ICTs for unilateral coercive measures.
Madam Chair, throughout the OEWG process, many delegations consistently emphasized that the future development of additional norms and the implementation of existing norms are complementary objectives that should proceed in parallel.
At present, however, this balance has not been maintained.
While work on the implementation of existing voluntary norms has advanced, no comparable process has been established to facilitate the elaboration of additional norms as envisaged in the agreed mandate of the global mechanism.
Accordingly, my delegation considers that negotiations on the proposed voluntary checklist of practical actions for the implementation of voluntary non binding norms should proceed alongside a structured process for the elaboration of additional norms.
In this regard, my delegation proposed that the chair prepare an initial consolidated draft compiling the proposals for additional rules, norms, and principles submitted by member states drawing from the annex to the first OEWG chair summary.
Such a draft would provide a practical basis for structured discussions in both the plenary sessions and the dedicated thematic groups.
I thank you Madam Chair.
Thank you very much.
I now give the floor to Ireland.
Thank you, Madam Chair.
To begin, Ireland aligns with the intervention made on behalf of the European Union and makes the following comments in our national capacity.
Ireland supported the consensus development of the UN normative framework for responsible state behavior in cyberspace.
This was a major achievement in our collective path towards a global, open, secure cyberspace.
Now we need to focus on its implementation.
The 11 voluntary non binding norms of responsible state behavior are central to maintaining international security and stability and their practical implementation enhances transparency, predictability, and accountability of state conduct in cyberspace.
It is important that states show how they are seeking to implement the norms.
I refer to the EU's paper on implementation as an example of this.
There is much that we can learn from one another and great value in all states sharing our experiences in implementing the norms.
It is also important to note that the voluntary norms are, of course, complementary to international law which applies in cyberspace.
Ireland believes that there is a strong role for the DTGs to discuss the implementation of the 11 voluntary norms connected to specific challenges such as the protection of critical infrastructure or ransomware, to exchange best practices that could feed into recommendations.
As others have indicated earlier, stakeholders expertise can and should play an important role in this.
Ireland also strongly supports the voluntary checklist of practical actions for the implementation of norms developed in the OEWG, which we see as a valuable reference to take states implementation of the framework forward and which can be further developed.
We would also welcome discussion of capacity building programs to assist with the implementation of existing norms, particularly on the applicability of international law in cyberspace at the DTGs.
Thank you, Madam Chair.
Thank you very much.
I now give the floor to Ukraine.
Thank you, Madam Chair.
Ukraine aligns itself with the statement delivered earlier by the European Union and would like to add some considerations in our national capacity.
The 11 voluntary norms, together with international law, confidence building measures, and capacity building, constitute a balanced and comprehensive framework for promoting international peace and security in cyberspace.
The cumulative framework already provides a solid foundation.
The key challenge before us is not whether the agreed norms remain relevant, they clearly do.
But the question is how to ensure their effective implementation in an increasingly complex security environment.
The rapidly evolving cyber threat landscape demonstrates the continued relevance of the agreed framework.
Against this background, the voluntary norms of responsible state behavior remain as relevant today as when they were first agreed upon.
Their effective implementation is essential for reducing risks, strengthening resilience, and preventing conflict.
Some states insist on the voluntary nature of these norms and suggest that where these norms put into legal framework and had they become legally binding, then states would have adhered to them with more dedication.
In this respect, it is necessary to bring to the attention that the UN charter is an international legally binding document and this not prevent, for example, Russia to act in breach of its provisions.
And the International Criminal Court is already taking important steps to hold relevant Russian criminals accountable.
At the same time, we think that the states should primarily adhere to the norms for the purpose of progress and development and not due to their fear of persecution.
Chair, Ukraine would like to focus on two norms that have already been mentioned by many speakers before and have become particularly important in light of today's security environment.
The first concerns the protection of critical infrastructure.
States have agreed that they should not conduct or knowingly support ICT activities that intentionally damage critical infrastructure or otherwise impair its use and operation in providing services to the public.
Ukraine's experience demonstrates why this norm is indispensable.
Russia's cyberattacks have targeted the energy sector, telecommunication networks, public administration systems, transport infrastructure, and other essential civilian services.
Their purpose has been not merely to disrupt computer systems, but to undermine the resilience of the state, amplify the effects of missile and drone attacks and inflict maximum hardship on the civilian population.
The second norm we wish to highlight concerns the responsibility of states not to knowingly allow their territory to be used for intentionally wrongful acts using ICTs.
This principle, commonly referred to as due diligence, remains one of the cornerstones of responsible state behavior in cyberspace.
No state should knowingly permit malicious cyber infrastructure operating within its jurisdiction to be used against the rights of other states.
At the same time, we observe the growing convergence between state sponsored cyber operations and cybercriminal ecosystems.
Malicious actors operating from Russian territory, including ransomware groups and other cybercriminal entities have repeatedly targeted Ukraine and partner states while benefiting from a permissive environment.
This further underscores the importance of implementing the due diligence norm and ensuring that no state knowingly allows its territory or infrastructure to be used for malicious ICT activities.
Chair, Ukraine believes that the global mechanism provides an important opportunity to move to implementation.
Thematic discussions should increasingly focus on practical measures that assist states in implementing the agreed norms.
This includes exchanging national practices, identifying implementation challenges, strengthening the protection of critical infrastructure, improving information sharing, and developing practical guidance on the implementation of due diligence.
Ukraine stands ready to contribute its unique practical experience acquired while defending itself against Russia's cyber threats.
As many have noted already, norms of responsible state behavior complement the existing international law and derive their value from consistent implementation.
Thus states that systematically conduct malicious ICT activities against critical infrastructure or knowingly tolerate malicious cyber operations originating from their jurisdiction undermine confidence in the very framework they have committed to uphold.
Global mechanism should therefore serve not only as a platform for dialogue, but also as a catalyst for strengthening implementation, promoting accountability, and reinforcing responsible state behavior in cyberspace.
Ukraine remains committed to working constructively with all peace loving nations to ensure that the global mechanism delivers practical outcomes that contribute to international peace, security and stability.
Thank you.
Thank you very much.
I will now read out the next five speakers, Canada, followed by Japan, Singapore, Tonga, Australia, and Kira Canada, you have the floor.
Thank you, Madam Chair.
The 11 agreed norms are at the core of the UN framework for responsible state behavior.
Over the years, we have made attempts at clarifying how they apply, including through guidance in the 2021 GGE Consensus report.
We also commend the work of the chair of the 2021 2025 OEWG on a voluntary checklist for the implementation of the norms.
In this first plenary of the global mechanism, our priority should be to set the stage to move these implementation efforts towards more practical and concrete applications of the norms to real world situations.
We welcome the EU's efforts to provide transparency on how they engage responsibly in cyberspace through norms implementation.
In the same spirit, Canada has recently published its survey of national implementation of the framework.
It is on the Canada page of the Unir Cyber portal.
It provides information on how we implement the pillars of the framework, including norms, CBMs, and capacity building.
The survey also refers to our 2022 national position on how existing international law applies.
The new format of dedicated thematic groups will be a key venue to deepen this conversation.
Indeed, DTGs will enable us to focus on specific challenges that have been top of mind for delegations over the OEWG years, but that have not yet been sufficiently addressed.
This certainly includes the protection of critical infrastructure and ransomware incidents affecting hospitals.
In Canada, a large segment of the ICT systems that form part of public service delivery is owned and operated by non governmental stakeholders.
We could share best practices in terms of national measures and in working with key stakeholders.
For example, Canada could provide lessons learned and best practices from its experience with Bill C eight, an Act respecting cybersecurity.
The legislative process for this bill was concluded last month and the bill is now being implemented.
It provides a number of new obligations for designated operators within financial, telecommunications and energy industries, such as the establishment of cybersecurity programs, the management of risks associated with the supply chain and third party attacks, the reporting of incidents to Canada's Cert within 72 hours, and certain record keeping.
There are enforcement mechanisms, including penalties to ensure that designated operators improve their cyber resilience.
Canada could also provide information on our cyber incident response plan.
This governance tool helps us coordinate across governmental and non governmental actors to address cyber incidents efficiently.
Madam Chair, for the global mechanism to bring real value to the UN membership, it must move beyond high level pillar by pillar discussions and engage on how norms and other pillars apply to specific challenges.
These discussions should engage on practical implementation from the policy, legal, and technical angles.
Contributions from experts and participants from within government and beyond are essential.
Governments can act, but our effectiveness depends on strong buy in from the private sector, engaged communities, including civil society, and innovative leaders who think across boundaries.
Thank you, Madam Chair.
Thank you very much.
I now give the floor to Japan.
It will be followed by Singapore.
Well, thank you, Madam Chair.
In countering the growing threats in cyberspace, it is crucial that existing international law applies and norms are implemented in cyberspace.
Regarding norms, while making use of the voluntary checklist and so called non binding 11 norms on which the consensus reached among member states and recognized in the OEWG, it is essential for each member states to steadily implement those norms as a first step.
Regarding the global mechanism, particularly through DTG one, we hope to deepen practical and concrete discussions on how to implement specific norms in response to particular incidents, including cyber attacks against critical infrastructure, thereby fostering deeper and shared understandings among member states.
Madam Chair, to give one example in the context of states responsibility under existing international law, Japan attaches great importance on the fact that the member states bear due diligence obligation under international law with regards to cyber activities as well.
The 11 norms also reflect a fundamentally similar understanding and we believe that the consistent implementation of these obligations and norms by all member states will contribute to the prevention and deterrence of cyberattacks.
We'd like to deepen our understanding on this point through DDG one.
Thank you, Madam Chair.
Thank you very much.
Next, we'll hear from Singapore.
Thank you, Madam Chair.
The pace of technological advancement we discussed in the previous section of this meeting requires us to continue adapting to new opportunities, challenges, and to uplift our efforts in addressing the threats to cyberspace.
Therefore, we would like to see the moving forward on the implementation of the existing 11 non binding voluntary norms of responsible state behavior in cyberspace, which remain a priority.
The UN OEWG had developed a voluntary checklist of practical actions, and we should move towards discussing how we can implement it.
As noted by my distinguished colleague from Thailand, regional frameworks such as the Asean Norms implementation checklist can also offer a useful reference on how the voluntary checklist of practical actions can be implemented and we would be happy to share our experience in this.
Madam Chair, any discussion on the implementation of norms will also require a discussion on capacity building.
This is because states need to build significant capacity to implement the existing norms because these norms are multidimensional.
Each norm has a policy, operational, technical, legal, and diplomatic aspect to it that be addressed and capacity that needs to be built before we can effectively implement these norms.
Only after developing the capacity to implement these norms will states be able to identify gaps and take the necessary measures to fully implement them.
This interconnected and coordinated approach ensures that we remain both grounded in practice and forward looking in strategy.
Thank you, Madam Chair.
Thank you very much.
I now give the floor to the delegation of Tonga.
Madam Chair, Tonga aligns itself with the statement delivered by my colleague on behalf of the Pacific Islands Forum members and adds the following in its national capacity.
Tonga's position on this pillar is grounded in our experience.
The framework of voluntary, non binding norms agreed by all states is sound.
What the world needs now is not new commitments, but the implementation of those commitments already made.
Every hour this mechanism spends drafting new language is an hour spent helping states give effect to the language we already have.
Madam Chair, the norms are not obstructions for Tonga.
When our national health information system was encrypted by ransomware last year, the norms on refraining from ICT activity that damages critical infrastructure on protecting that infrastructure and on responding to requests for assistance from states whose infrastructure is targeted were tested in the real world.
We are grateful to the partners whose swift assistance embodied the cooperative spirit of those norms.
The sabotage of submarine cables, the threat that concerns Tonga most deeply, is addressed squarely by the existing norms on critical infrastructure.
What remains is for all states to live up to them.
TMA therefore encourages this mechanism to devote its work under this pillar to practical implementation.
We see three priorities.
First, the voluntary checklist of practical actions annexed to the OEWG's final report should become a working tool supporting states to survey in advance their own implementation.
Second, implementation must be understood as a capacity question.
Many states, including our own, require support to translate norms into national policy, legislation, and operational practice.
Tonga is from here.
We were the first Pacific island country to join the Budapest Convention and we know from that experience that international commitments become real.
Through sustained domestic efforts, patiently supported.
Third, the dedicated thematic groups meeting in December offer the right setting for the granular, expert level exchange that implementation demands, and their cross cutting design should be used to connect norms implementation with capacity building rather than treating them as a separate conversation.
Madam Chair, some may see a small island kingdom as an unlikely voice on questions of state behavior.
We see it differently.
States like Tonga rely more than any other on all states behaving responsibly because we bear the consequences of irresponsibility most accurately and with the fewest defenses.
The noms are our protection, their implementation is our security.
Tonga will continue to work with all partners in this room and in our region to move this pillar from articulation to action.
I thank you.
Thank you very much.
I now give the floor to Australia.
Thank you, Madam Chair.
Australia aligns itself with the statement delivered by the Kingdom of Tonga on behalf of the Pacific Islands Forum members and strongly supports its emphasis on the practical implementation of the 11 agreed voluntary non binding norms.
These norms are a fundamental pillar of the framework for responsible state behavior in cyberspace.
But their value depends on whether they are understood, operationalized, and implemented by all states.
Implementation remains an ongoing task for us all.
States are progressing at different rates in identifying and protecting critical infrastructure, enhancing incident response capabilities, fostering whole of government approaches, and building the technical and policy foundations necessary to implement the norms effectively while continuing to review and update implementation mechanisms.
The global mechanism should remain focused on helping states implement the norms that have already been agreed.
This means supporting practical, action oriented work that helps states move from endorsement to implementation and from implementation in principle to implementation in practice.
The global mechanism should support states to assess where they are in implementing the norms and where gaps or barriers remain.
These barriers may be technical, institutional, financial, resourcing related, or linked to awareness and coordination across government.
A clearer understanding of these challenges will help ensure that capacity building is targeted, practical, and effective.
To that end, Australia also considers the voluntary norms implementation checklist to be a valuable mechanism for supporting general implementation efforts.
It can help states self assess progress, share experiences, and best practices, and identify where further support is needed.
In addition to exploring the contribution of specific voluntary norms to the protection of critical infrastructure and critical information infrastructure, the dedicated thematic groups are well positioned to advance the work already commenced on the implementation checklist and further develop it as a practical tool for states.
We encourage the mechanism to continue this work and ensure that implementation gaps identified by states are linked to effective capacity building support.
Here again, we wish to highlight the role of multi stakeholders.
Effective implementation depends on collaboration with a broad range of stakeholders.
Regional organizations, the private sector, technical experts, academia, and civil society bring specialized knowledge and on the ground experience that can help states operationalize the norms and apply them in real world contexts.
Chair, Australia wants the global mechanism to be a place where the norms are made operational.
Its work should strengthen implementation, support capacity building, enable peer exchange, and help all states apply the agreed framework in their national contexts.
Thank you.
Thank you.
I now give the floor to Kirbas to be followed by Malaysia, the Philippines, Ghana, Switzerland, and North Macedonia.
Madam Chair, b has aligned itself with the statement delivered by the Kingdom of Tonga on behalf of the Pacific Island Forum members.
We associate ourselves fully with the forums position and speak now in our national capacity to civet the human face.
Madam Chair, at the first session of the permanent mechanism, this pillar asks us a simple question.
What are norms for? Ub answer is that a norm is not a sentence in a report.
It is a promise about how state will behave and a promise is only worth keeping it.
We have 11 such promises agreed by consensus.
They are real achievements.
The work before us now is not to write more of them, but to keep the ones we have.
The forum have spoken of implementation as a priority and of the varying stage, our members are in operationalizing these norms.
Let me tell you plainly that what stage looks like for S.
It looks like a young national set finding its feet.
It looks like a new law, our Cyber Grime Act, our Digital Government Act, our Data Protection Act, and our Cybersecurity Act, each one built in the last five years.
It looks like identifying for the first time what our critical infrastructure even is when our connection to the world rest on a submarine cable serving our eastern islands and a second cable about to bring our capital online and satellite links carrying much of the rest of our nation into the Internet.
This is what implementation means for small island states.
It's not a debate.
It is the daily and glamorous work of building a house while the weather is already upon us.
This, Madam Chair, is why best speaks so firmly for implementation first.
A small state cannot afford an open ended renegotiation of what we have already agreed.
We do not have the delegation to send the penches of expert to spare all the years to give while the threat we face do not wait.
Like what our colleagues from Dong outlined, every hour spent litigating the settled is an hour stolen from defending our people.
For us, implementation is not a preference among many options.
It's a matter of necessity.
We therefore welcome with the Pacific Island Forum members the voluntary implementation checklist, and we ask this mechanism to take it forward in a concrete and action oriented way through the dedicated demotic groups.
But Kivas asked for one thing more.
A checklist tells a state what to do.
It does not on its own tell a state like ours how to do it or resources to do it.
Let this mechanism bear the checklist with what actually build capacity such as consolidated guidance, harness mapping of where the caps remain, be exchanged between states walking the same road and the practical expertise that our technical partners, regional body, and stakeholders can bring into the thematic groups.
That is our norm on Beba becomes a norm in practice.
Madam Chair, Cité does not foreclose the conversation some delegation wish to have about No norm in the meantime.
The mechanism works in cycle with a review conference at which we can take stock together.
That is our chance to act first on what we have agreed, to learn from the doing, and to consider what more is needed on the evidence of experience rather than on the session.
But at this first session, our message and the message of our region is one message.
Prove these norms by leaving them.
Madam Chair, the smallest state in this room are, in a sense, the truest test of these norms.
If a norm protects Kibis, a nation of 220,000 people spread across an ocean, holding its connection to the world together with a handful of cable and satellite link, then it protects everyone.
If it does not reach us, then it's not yet the universal commitment we claim it to be.
We ask this mechanism to make this norm reaches all of us.
Gaba best for its part will keep its promise.
We'll ask only that together, we keep them for one another.
I thank you Madam Chair.
Mu.
Thank you very much.
I now give the floor to Malaysia.
Thank you, Madam Chair.
The voluntary norms that states have agreed upon over the past decade remain a cornerstone of the UN framework for responsible state behavior.
The framework rests on a foundation of voluntary, non binding norms carefully developed through years of dialogue under the GGEs and OEWGs.
They represent an essential complement to binding international law.
They also provide us practical guidance on how to promote stability, reduce risks, and strengthen responsible behavior in cyberspace.
That said, Malaysia believes that our immediate priority should be to strengthen the implementation of these norms.
Cyber threat continues to evolve and emerging technologies are adding new layers of complexity.
The real test of these norms will be whether we can put them into practice.
In Malaysia's view, there are two key actions we can take through the global mechanism.
First, DPG one offers a valuable platform for states to share experiences and challenges in implementing the 11 voluntary NoOMs to real world scenarios.
We see particular values in focusing on NMG, which calls on states to protect their critical infrastructure.
Given the increasing frequency and sophistication of attacks targeting such critical assets, this will help us identify common challenges, learn from one another, and develop practical approach that actually work.
Second, discussions from DTG one should inform targeted and needs based capacity building efforts under DTG two.
Capacity building must respond directly to the practical challenges that states have identified.
In doing so, we can better support states in translating norms into national policies, institutional arrangements, and operational practices, taking into account their respective national circumstances and priorities.
Madam Chair, at the regional level, Asean has developed the Asean norms implementation checklists that translate policy norms into practical actions and serve as a regional reference for national implementation.
This is a concrete example of how international cooperation can also support the practical implementation of norms.
Lastly, Madam Chair, Malaysia believes that the real value of the global mechanism will be measured by its ability to help states fulfill what they have committed to do even when those commitments are voluntary.
Thank you.
Thank you very much.
As I thank all of the speakers who are inscribed on the list.
Let me be the next one.
Philippines, Ghana, Switerland, North Macedonia, Albania, and lastly, Israel, Philippines, you have the floor.
Madam Chair, the Philippines believes that the immediate priority before the global mechanism is the effective implementation of the voluntary, non binding norms of responsible state behavior.
These norms remain an essential component of the agreed framework for promoting international peace, security and stability in the use of ICTs.
Their value lies not only in the guidance they provide, but in how consistently they are translated into national practice and international cooperation.
The global mechanism begins its substantive work, we should focus on practical implementation.
In this regard, the Philippines supports an implementation oriented, action focused global mechanism.
We likewise believe that the dedicated thematic groups complement rather than duplicate the work of the plenary by generating practical, consensus based recommendations that assist member states in implementing the agreed framework.
The voluntary norms provide practical guidance for reducing risk and preventing misunderstandings and promoting responsible state behavior in an increasingly interconnected digital environment.
Their implementation strengthens national resilience while fostering confidence, transparency, and cooperation amongst states.
At the national level, the Philippines continues to implement these norms through a whole of government approach to cybersecurity.
Guided by the National Cybersecurity Plan 2023 to 2028, we continue to strengthen interagency coordination, cyber threat intelligence, incidents response, and the protection of critical information infrastructure.
We also continue to expand partnerships with the private sector, academia, the technical community, civil society, the international partners, recognizing that effective cybersecurity requires sustained cooperation across multiple stakeholders.
The Philippines therefore supports continued voluntary exchanges of national experiences, implementation practices, and lessons learned.
Such exchanges can strengthen collective understanding of how the voluntary norms are being applied in practice, identify implementation challenges and good practices, and strengthen cooperation in a manner that respects national circumstances, priorities, and levels of technological development.
Over time, these practical experiences can also help inform discussions on whether additional norms may be beneficial in addressing emerging challenges while preserving the consensus based and state led nature of this process.
As Asean chair in 2026, the Philippines continues to advance regional cybersecurity cooperation, through the implementation of the Asean Cybersecurity cooperation Strategy 2026 to 2030.
Regional initiatives including cyber exercises, trusted information sharing, operational collaboration among competent authorities, and the Asean Norms implementation checklist demonstrate how the voluntary norms can be translated into practical cooperation, strengthen trust and resilience among member states, and reinforce resilience across the region.
The Philippines also believes that effective implementation benefits from appropriate technical expertise.
Consistent with the global mechanisms agreed modalities, accredited stakeholders can contribute operational experience, technical knowledge, and research to assist member states in implementing the agreed framework, particularly in understanding emerging technologies and addressing cyber threats.
Voluntary norms have provided the international community with a practical foundation for promoting responsible state behavior in cyberspace.
Our shared task now is to ensure their effective implementation and to continue learning from that experience.
The Philippines remains committed to working constructively with all member states to advance practical implementation, strengthen international cooperation, and contribute to an open, secure, stable, accessible, peaceful, and interoperable ICT environment.
Thank you, Madam Chair.
Thank you.
I now give the floor to Ghana.
Thank you, Madam Chair.
Ghana comes to this first plenary with both a sense of responsibility and a strong commitment to the success of this global mechanism.
Ghana has had the privilege of serving on the 2014 2015 group of governmental experts whose 2015 consensus report introduced the 11 voluntary non binding norms of responsible state behavior.
We also participated actively throughout the opening ended working group process.
The establishment of this global mechanism reflects years of sustained dialogue, compromise, and collective efforts.
As we begin this new chapter, Ghana joins the African group in reaffirming that consensus should remain the foundation of our work, enabling us to deliver practical outcomes that strengthen resilience, build confidence, and support the meaningful participation of all member states.
On norms, Ghana supports the continued use of voluntary checklists as a practical tool to assist states in implementing the framework while recognizing that implementation must remain flexible and responsible to national circumstances.
We also welcome the ongoing work of the African Union to develop guidelines on the implementation of the voluntary norms of responsible state behavior and the African Declaration on Peace and Security in cyberspace, which will provide an important regional perspective and further support implementation across the continent.
Madam Chair, Garner believes that the value of the voluntary norms lies in their effective implementation.
This requires sustained capacity building, strong partnership, and the sharing of best practices.
Garner remains committed to working with member states and all relevant stakeholders to advance the implementation of the framework in a practical, inclusive, and cooperative manner.
Thank you.
M.
Thank you very much.
I now give the floor to Switzerland.
Thank you, Madam Chair.
As we have heard from many other delegations, Switzerland believes that before developing new voluntary norms, we should focus on the implementation of the existing ones which were confirmed and endorsed by all states in the General Assembly.
States stressed that these norms reflect the expectations and standards of the international community regarding the behavior of states in their use of ICTs and allow the international community to assess the activities of states.
We see the global mechanism as a process that will enable us to make concrete progress in implementing these norms and the DGTs will play a central role in this process.
In addition to the strategic discussions that will take place in the plenary session, the DGTs will hold more in depth, targeted and scenario based discussions on the specific topics that are relevant for states and the reality on the ground.
UNDER could, for example, be tasked to develop such scenario based discussions.
During the discussions on threats, many states referred to the increasing intensity of ransomware attacks and state sponsored cyberattacks against critical infrastructures.
We therefore see merit in focusing on norms 13 C, F, G and H, calling for the protection of all critical infrastructure supporting essential services to the public, medical and health care facilities, as well as cooperation between states for this purpose.
States have recalled the importance of the principle of due diligence in this regard.
Regarding ransom attacks, it is important that states do not serve as safe havens for criminal groups and take measures against them.
Switzerland stands ready to share its experience on mandatory reporting of cyber incidents affecting critical infrastructure or the timely information sharing between governmental authorities and operators of critical infrastructures via a secured platform as a concrete contribution to the capacity building work of this mechanism.
Similarly, our discussions should address the risk to critical infrastructures arising from malicious use of artificial intelligence by states, state sponsored actors, and criminals, as well as risks stemming from vulnerabilities in the supply chain, data poisoning, and the manipulation of AI systems.
Sir, Switzerland believes the cooperation with the non governmental stakeholder is essential for the implementation of the voluntary norms.
For that reason, Switzerland has established a Geneva dialogue on responsible behavior in cyberspace.
The dialogue and then analyzes and maps the roles and responsibility of various actors in implementing voluntary norms and ensuring the security and stability of cyberspace.
The Geneva manual is a product of this dialogue.
The manual is a living document.
The first two chapters of the manual focus on the norms related to supply chain security, reporting of ICT vulnerabilities, and the protection of critical infrastructure.
Based on this experience, we are firmly convinced that broad and meaningful participation of stakeholders in the work of the global mechanism, in particular, the DGTs is not only necessary, but also to the advantage of all states.
Finally, we would like to thank the EU for the non paper on the implementation of voluntary norms.
This document, alongside other useful tools such as the Asean Voluntary implementation checklist, provides the global mechanisms and state with valuable guidance and resources for putting the voluntary norms into practice.
I thank you.
Mus.
Thank you very much.
I'll now give the floor to North Macedonia.
Thank you, Madam Chair.
As this is the first time my delegation takes the floor, allow us to express our appreciation for your guidance throughout the intersectional period.
We would also like to thank you for the efficient appointment of the co facilitators, which has provide a solid basis for advancing our work.
North Macedonia aligns itself with the EU statement delivered by this agenda item.
In our national capacity, we wish to highlight the following brief remarks.
As we begin our discussion on norms, rules, and principles, we believe that the global mechanism should remain practical, inclusive, and implementation oriented.
Our efforts should focus on supporting the efficient implementation on the existing framework of responsible state behavior in cybersplace, including the 11 voluntary non binding norms agreed by all member states.
Their effective implementation contributes to greater transparency, predictability, and accountability of state behavior in cyberspace, while strengthening trust and international security.
In this regard, thematic discussions will provide a valuable opportunity to exchange national experiences, share good practices, and identify practical approaches that can support implementation at the national level.
We believe that continued exchanges of national experiences and practical approaches will enrich our discussions and support the effective implementation of the agreed norms.
We look forward to engaging constructively throughout this process.
I thank you.
M.
Thank you very much.
I now give the floor to Albania.
Thank you, Chair.
Albania fully aligns itself with a statement delivered by the European Union and would like to add the following remarks in its national capacity.
For Albania, the implementation of agreed UN norms is essential.
Their value lies not only in the political commitment, but in their translation into national legislation, institutions, operational procedure, and international cooperation mechanisms.
Albania has approved and has enforced the law on cybersecurity since May 2022, which fully transposes the EU NIS two Directive.
In accordance with the provisions of this Directive, all implementing by laws have now been adopted, providing the necessary legal framework for the operationalization of national cybersecurity structures and the functioning of the national cybersecurity ecosystem.
The adopted S Legal Acts regulate, among other matters, the organization, responsibilities and functioning of the National Cybersecurity Authority, the Cybersecurity Emergency and Crisis Response Team, the procedures for identifying, classifying, escalating, and managing cyber crisis and large scale cybersecurity incidents, the identification and protection of critical and important information infrastructures, and assessment and analysis of cybersecurity risks, the National cybersecurity certification scheme and the registration of cybersecurity conformity assessment bodies, organizational, technical, and operational cybersecurity measures, coordinated vulnerability disclosure, et cetera Part of this sub legal Act is also the National Cybersecurity Strategy 25 30 and its action plan, and it gives policy goals covering protection and digital infrastructure, online protection of citizens and promotion of cybersecurity culture, strengthening international cooperation, promotion of innovation and scientific research, and protection against hybrid threats.
These act give concrete effect to the application of the agreed UN norms.
Just to provide a few examples, Albania has now fully operational cybersecurity structures such as National SOC and Cert.
The establishment of national cyber incident monitoring and response structures, together with cybersecurity strategy, procedures for cyber incident and crisis management, the identification of critical and important information infrastructure and cybersecurity measures, support several norms such as preventing harmful ICT practices and activities, considering all relevant information in cases of ICT incident, on information exchange to address such threats and on protection of critical infrastructure from ICT threats, while also strengthening Albania capacity to cooperate with partners at national and international level.
Cybersecurity certification frameworks contribute to supply chain security and assurance, while Albania is currently in the process of harmonizing its legal framework with the EU Cybersecurity Resilience Act, which will further contribute to this norm.
Having in place a coordinated vulnerability disclosure policy, the necessary technical capacities to discover and address them, such as national SOC and certs, and the mechanisms to share information with critical and important information infrastructures to take the necessary measures directly support the norm of responsible reporting of ICT vulnerabilities and sharing information to limit and possibly eliminate potential threats.
Clearly, Albania is practically implementing UN norms, rules, and principles of responsible state behavior in cyberspace and we believe that the global mechanism should place practical implementation at the center of its work on norms, rules, and principles.
The dedicated thematic groups can provide an inclusive space to share national practices, identify legal, institutional, and capacity gaps, and develop action oriented recommendations and measures.
This regard, Albania calls upon all states to strengthen their commitment to the vulnerability norms of responsible state behavior.
In particular, states should ensure that their territory and ICT infrastructures are not knowingly used for internationally wrongful act conducted through ICTs against the critical infrastructure and essential services to other states.
States should also cooperate in preventing, mitigating, and responding to malicious ICT activity and provide assistance where appropriate when critical infrastructure is subjected to malicious cyber operation.
Albania further emphasized the importance of protecting the integrity and functioning of computer emergency response team and computer security incident response teams whose work is essential for maintaining international cybersecurity and resilience.
We also encourage all state to support responsible vulnerability disclosure practices and to promote greater security and integrity throughout the ICT ecosystems.
Strengthening those commitments will contribute to reducing opportunities for malicious actors to explose vulnerabilities and conduct harmful cyber operations.
Albania remains committed to the UN framework of responsible state behavior in cyberspace and stands ready to contribute constructively to the work of the global mechanism and its dedicated thematic groups in this regard.
Thank you, Chair.
Thank you.
I give the floor to Israel.
Thank you, Madam Chair.
Israel's position on the framework of responsible state behavior remains firm, consistent, and carefully considered.
In our view, there is no need to develop or elaborate upon any new norms before we adequately address the gap in compliance to the current framework.
Reality of the current landscape demonstrates that the voluntary and non binding norms established in 2015 are currently being floated by certain states.
As we've highlighted when we discuss the existing potential threats, malicious actors continue to disregard this framework we all agreed upon.
Against this background, we also see no need to develop legally binding instruments.
Pursuing efforts and attempting to develop a legally binding instrument without the underlining of broad agreement on key concepts would waste a considerable diplomatic capital invested in the GMAC, as well as its potential.
Such an effort would be both premature and counterperproductive.
This does not mean that we should not celebrate our collective achievement so far and continue to further refine the normative framework we have built together for responsible state behavior.
This framework, including the 2015 GGE norms, rules, and principles, which are voluntary and nonbinding signals the expectations of the international community for state activity in the cyber domain.
We should focus the efforts on strengthening the implementation of the existing voluntary norms and promoting a broader shared understanding of this framework.
In our view, the DTGs could provide a practical cross cutting forum for sharing national best practices and evaluating whether and how the existing norms of responsible state behavior are understood and applied.
Furthermore, the DTGs could offer an opportunity to revisit ideas that could not have been adequately discussed in sufficient length and thoroughness in the non permanent process.
For example, the DTGs can serve as a much more appropriate platform to contemplating the implementation checklists explored in APR three report.
A more granular and cautious way.
Such checklists provide that they are carefully revisited, considered, and redrafted as necessary.
Could serve as a voluntary tool for developing a common language and understanding.
Finally, Madam Chair, and in response to the Iranian regime's representative, Israel will not dignify the ridiculous and re degerated claims the Iranian regime just made with a detailed response.
Despite the constructive engagement by vast majority of delegations and despite repeated calls by many delegations here to avoid politicization and despite your chair's call for the member states to present professional and constructive contribution, Iran seems adamant to impudently waste our time In doing so, the Iranian delegation continues to show Iran's determination to disregard the international community and to disrespect other member states, both inside and outside this building in the cyber domain and in other domains.
We invite all delegations here to draw their own conclusions on where this vile approach will lead us.
Thank you.
Right.
We have concluded the list of speakers under this agenda item.
However, a variety of reply has been requested, and so I give the floor to the Russian Federation.
Distinguished Chair of my delegation was forced to use its right of reply with regard to the outrageous anti Russian attacks from the Ukrainian delegation.
The accusations leveled against my country are not only false and groundless, but are ridiculous.
The irony is that the victims of computer attacks are if I to say they're victims of cyberattacks when actually they're a country that have become a hub for hackers and online fraudsters acting with support of their own government with a single goal to damage the Russian civilian infrastructure and to defraud Russian citizens.
In this case, we don't even need to prove the participation of Kyiv in many attacks because the officials of that country themselves have repeatedly acknowledged and even bragged about carrying attacks against Russia.
It is a well known fact that Ukraine has become the largest haven for online fraudsters in the world, the number of these so called call centers which defraud retirees and blackmail and extort people and encourage young people to carry out terrorist attacks in Russia number in the thousands.
The victims of these attacks are not only Russians, but also Europeans, citizens of those countries that are sponsoring the defrauding of Russians.
Chair, it's difficult for me to call any of this a norm of responsible state behavior in the list as laid out by the UNGA.
They've been violated by Ukraine in the most glaring manner.
It's clear that there is no more brazen violator of the framework of responsibility behavior than Ukraine.
Thank you.
Thank you.
I give the floor to the delegation of the Islamic Republic of Iran.
I take it that is also for a right of reply.
Okay.
Thank you, Madam Chair.
In response to the absurd and misleading remarks we have just heard from the representative of the Israeli regime, I wish to make one brief observation.
The action of the Israeli regime in our region, particularly its two unlawful acts of aggression against Iran over the past year, strike at the very foundation of every pillar of the global mechanism, just as they strike at the very foundations of international law and the charter of the United Nations.
Referring to these actions neither politicizes nor derails our discussions or waste time.
On the contrary, they constitute a clear illustration of the very malicious ICT activities that this process seek to prevent and address, thereby assisting member states in deepening their discussions and informing the work of the global mechanism.
I thank you, Madam Chair.
Okay.
Thank you.
I give the floor to the delegation of Ukraine to exercise the right to reply.
Madam Chair, I would like to exercise the right of reply tomorrow during the session of tomorrow not to keep the delegations over time, please.
Thank you.
Thank you.
However, I would like to point out that we have an additional 10 minutes, thanks to the interpreters.
If you would like to use your right to reply now, you may do so.
Okay.
Why not? All right.
Well, we would have preferred to close this item today, but we do note that request.
What I'm going to do now is similar to what I did with the former agenda item, which is I'm going to share with you some very general reflections.
It is not intended to be any exhaustive summary, but I do want to perhaps touch on some of the questions that we have heard raised by a number of delegations.
We have noted that there has been an emphasis on shifting to implementation.
This is a major significance for all states, but I think especially so for small ones, given their realities and national circumstances.
I have also heard calls to continue the discussion on common understandings as to how these norms will be applied in practice and the global mechanism through the DG Ts.
This will be the main forum for these exchanges.
A number of you also mentioned the checklist for implementation.
A number of you also emphasize and that additional norms could also be considered given the evolving nature of the digital environment.
I've also heard a lot of you highlight the interconnection of the norms with some of the pillars, especially capacity building, underscoring that this should be shored up by the various diplomatic and other institutions of state.
It does seem that there is a great deal of common sentiment as regards implementation.
Thank you very much for that.
In this regard, the global mechanism will meet again tomorrow at 10:00 A.M.
In this same room, please come prepared to begin with the agenda item on the continued study of how international law applies in the use of ICTs, including consideration of whether gaps exist and the possible future elaboration of additional legally binding obligations if appropriate.
Before I adjourn the meeting for today, I would like to remind you that tomorrow afternoon at 3:00 P.M.
According to our program of work, We will be holding the dedicated stakeholder segment under the work of this mechanism.
I would encourage delegations also to participate actively in that stakeholder segment.
If there is any time remaining, we will continue with the speaker's list to try and conclude the morning session.
The meeting is adjourned.
Thank you.
(4th meeting) Plenary Session, Global Mechanism on ICTs in the Context of International Security (20-24 July)
Substantive Plenary Session of the new Global Mechanism on Information and Communications Technology (ICT) Security.
Description
Discussions on the five pillars of the framework for responsible State behaviour in the use of information and communications technologies in accordance with annex C of A/79/214 and annex I of A/80/257 (continued)
Norms, rules and principles
Full transcript en transcript
Machine-generated · not human-reviewed · verify against the official record before citing or relying on this transcript
Session Summary Auto generated from session transcript
Synthesis hasn't been generated for this session yet.
The summarize pipeline runs after the English transcript is available.
Machine-generated · not human-reviewed · verify against the official record before citing or relying on this summary