A very good afternoon.
I call to order the sixth meeting of the plenary session 2026 of the global mechanism on ICTs in the context of international security.
And advancing responsible state behavior in the use of ICTs.
The meeting is called to order.
According to our program of work and also the consensus based modalities on the participation of non governmental stakeholders in the works of our mechanism, we will now have our meeting on accredited entities for our work.
Right now, I have 14 accredited organizations who have requested the floor.
I will give the floor to each speaker for 4 minutes.
Before I give the floor to the first speaker, who is Discover MUN Foundation, I'd like to express my thanks to all of you for participating in this first plenary session of the mechanism.
Thank you.
I know that many of you are not based in New York, so thank you for the interest that you've shown.
Thank you for your time and coming and contributing to the work of this mechanism.
The chair is very grateful to all of you.
I now give the floor to Discover M UN Foundation.
Madam Chair, I have the honor to take the floor on behalf of the major group for Children and Youth, the mandated Children and Youth constituency at the UN, representing over 20,000 distinct youth organizations.
Excellencies, cybersecurity risks and automated exploits are escalating at an unprecedented speed today.
Dual use technologies from AI driven malware to deep fake social engineering are being weaponized to target digital spaces.
When everyday ICT tools are repurposed for malicious cyber activities, it is young people, particularly children who face immediate attacks to their digital safety and rights.
In this context, please allow me to deliver the following demands on behalf of children and youth.
First, we believe the member states must consider age related disaggregated data on malicious ICT activity in their submissions under this pillar.
We call upon delegations to consider general comment number 25 of the committee on Rights of the Child, which establishes that rights of children apply fully and equally in the digital environment.
Second, for capacity building, we call for the establishment of a dedicated Children and Youth track within the mechanism sponsorship and capacity building activities.
We believe that such activities must be modeled on successful examples of capacity building for marginalized stakeholders in the UN system, such as the Women and International Security and Cyberspace Fellowship organized by the UN Institute for Disarmament Research, which effectively integrates young technical experts in national delegations.
Third, consistent with the youth peace and security agenda under Security Council resolution 22 50, we call for meaningful engagement with children and youth to be recognized by the mechanism as a confidence building measure in its own right.
Madam Chair, please allow me now to turn to the critical issue of stakeholder participation.
My delegation thanks you for your letter dated first June and for your tireless efforts to uphold the transparency required by the modalities document in ASroke 80 stroke 257.
We note that these modalities were agreed by consensus on the understanding that inclusivity would be the norm and objection be the exception.
But objections that are lodged against more than 60 stakeholder entities, including non governmental organizations, universities and technical bodies without any stated basis whatsoever cannot be considered as inclusivity.
We call upon member states to honor the multi stakeholder principles that they affirmed in both the Global Digital Compact and the World Summit for Information Society plus 20 review by disclosing the basis of their objections.
In this context, we thank the distinguished delegations of the European Union and its member states for acting as a leading example of what transparency means pertaining to stakeholder participation.
Excellencies, we fully support the chair's efforts for mediation, but further demand that this mechanism work towards transparent criteria based accreditation practices to ensure predictable, principled, and objective procedures concerning stakeholder and rightholder participation.
Excellencies, an open, secure, stable, accessible ICT environment cannot and will never be built behind closed doors.
Just like many of our distinguished colleagues present here today, children and youth remain ready to bring constructive contributions.
Thank you.
Thank you very much.
I now give the floor to the Internet cooperation for assigning numbers.
For assigned numbers rather, followed by future systems.
Thank you, Chair for the opportunity to contribute to this discussion.
Internet corporation for assigned names and numbers, or otherwise, ICAN coordinates the Internet unique identifier systems and works to help ensure the security, stability, and interoperability of the domain name system or the DNS.
Addressing harm perpetrated through the DNS is an important part of that mission.
Misuse of domain names for phishing, malware, botnets, and farming possesses risks to Internet users around the world and requires coordinated action across the Internet ecosystem.
ICN does not regulate Internet content or investigate cybercrime.
Instead, it plays its part with regard of the wider online harm mitigation efforts by combating misuse of domain names through contractual obligations, consensus policies, technical coordination, capacity development, and collaboration with organizations that operate the DNS.
No single stakeholder can address these challenges alone.
Registries, registrars, governments, law enforcement, technical experts, civil society, the private sector, and others across the Internet community, each brings different responsibilities, expertise and capabilities.
ICAN works to increase the visibility of capacity building efforts among UN member states.
One example is the Coalition for Digital Africa, which brings together African governments, regional organizations, academia, the private sector, and the technical community to strengthen DNS security and resilience, build local technical expertise, and expand opportunities for participation in the Internet governance.
ICAN multi stakeholder model provides the mechanism for this cooperation.
It's supporting organizations and advisory committees bring technical expertise, operational experience, business perspective, public interest, and end user needs into policy development.
Governments have a unique and essential role within this model through the Government Advisory Committee or the GC.
GAC advises the CAN board on public policy issues related to CN's mission, including matters affecting the security, stability, and resilience of Internet's unique identifier systems that includes domain name system.
Through the government Advisory Committee, governments bring a public policy perspective directly into CN's work as integral part of the multi stakeholder model.
I would like to use this opportunity to encourage all member states to actively participate in the work of government Advisory Committee, ensuring the DNS flawless functioning.
If you do not have a representative, please reach out to us.
We have a staff here in New York, and we would be happy to provide all the information you might need.
Last but not least, I would like to invite you to the briefing entitled demystifying the Internet, Collaborative Security Approaches that ICA, the Internet Society, and the ITU are giving tomorrow in conference room eight during the lunch break.
Madam Chair, Excellencies, dear colleagues, we're looking forward to observing the global mechanism plenary sessions and we are at your disposal should you have any questions on the technical functioning of the Internet.
Thank you.
Thank you very much.
I now give the floor to Future Earth Systems, followed by form of Incident Response and Security Teams first.
Thank you, Madam Chair, for your leadership and the opportunity to address this plenary.
My name is Chris Sampson from Future Earth Systems.
I have the privilege of participating as an independent accredited stakeholder.
I have spent many decades designing whole of government systems, ICT policy and strategy, public and private sector innovation, and socioeconomic development with a special interest in regional, rural and remote community, socioeconomic equity in the digital age.
I have also had the benefit of discussing and analyzing the GGE and open ended working group as part of the ongoing Geneva dialogue with many thanks to the government of Switzerland.
I want to highlight the potential value of the practice of enterprise architecture to the work of this general mechanism.
Enterprise architecture maps out how policy intent, legal and regulatory frameworks, capabilities, and processes, data, and technical systems all align.
Think of it like a city plan.
It ensures that roads, utilities, and buildings work together efficiently and can adapt as the city grows.
Using architectural practice in this way can bridge from policy and guidance to implemented operational systems, ensuring optimal alignment of resources and a clearer focus on achieving measurable strategic outcomes.
This approach can help us harness the positive opportunities of ICTs, including AI and quantum.
It forms the blueprints for real time sensory systems which can adapt themselves much more dynamically to changing conditions and challenges.
These are the new generation of systems that will enable human society to operate at the next level of complexity with peace and security for all.
Madam Chair, industry is already innovating at this level.
We can see it in both regulated and unregulated global trade, including cybercrime.
Cyber Defense needs to be a globally interconnected ecosystem itself with much more effective collaborative systems and shared data between our state institutions and our regional and global institutions so we can strengthen the capabilities collectively and continuously, enabling every community to operate in peace and security.
An architectural approach will help us build on the norms as systems and realize the value of the multi stakeholder participation that you have all worked so hard to bring together.
Importantly, such an approach would not alter negotiated outcomes.
Rather, it could strengthen the mechanism, improve capacity building, and support implementation for all communities, ensuring human use of ICTs are stewarded responsibly, enabling human flourishing for generations to come.
I commend the work of all involved and would be honored to contribute.
Thank you very much, Madam Chair.
Thank you very much.
I give the floor now to first, followed by Center for Humanitarian Dialogue.
Honorable chair, distinguished delegates and stakeholders, thank you for inviting first to contribute to the first plenary meetings of the UN Global mechanism.
We reiterate our appreciation for the chair's sincere and sustained effort to engage all stakeholders in an open, transparent, and inclusive manner.
In this regard, first supports the joint multi stakeholder statement on the objection to the participation of stakeholders in the plenary meeting of the global mechanism in line with the agreed modalities contained in the 2025 OEWG final report.
Stakeholders from industry, academia, and professional and technical organizations, including first, play indispensable roles in supporting the implementation of cyber norms and confidence building measures, providing timely operational responses to emerging cyber threats, facilitating the responsible disclosure of vulnerabilities affecting ICT enabled critical infrastructure, strengthening cybersecurity capacity building efforts at the national, regional and global levels.
Members of First have participated in their individual capacities in the UN GGE process since 2012 and First has proudly supported the work of the open ended working group since 2019.
As the Global Forum of Incident Response and security teams established over 35 years ago.
First membership currently includes 874 incident response and security teams across 118 countries.
Our members include national certs, private sector, academic certs, as well as product security and incident response teams.
With respect to the ongoing discussions on international law, the stakeholder community can make valuable contributions by facilitating and expanding capacity building efforts in this area.
Particular, the technical community and especially incident response and security professionals can provide practical experiences and expertise on how international law applies in cyberspace and help strengthen states cyber resilience and preparedness in support of the UN framework for responsible state behavior in cyberspace, including the implementation of cyber norms and confidence building measures.
We are pleased to contribute in the past to the OEWG global roundtable on cybersecurity capacity building held two years ago and looking ahead, we hope that similar open, transparent, inclusive consultations will continue to convene through the dedicated thematic groups.
We emphasize the importance of a holistic approach to cybersecurity that is grounded on good governance, meaningful stakeholder engagement, and strong cybersecurity communities.
Addressing today's rapidly evolving cyber threats requires diverse expertise, close collaboration among government, industry, academia, and the technical community.
During cyber incidents, certs and security professional routinely exchange threat intelligence coordinated mitigation measures in real time through trusted, secure, and often informal channels.
First, calls upon states to support international collaboration among incident responders and to ensure that such cooperation remains non politicized, consistent with the relevant UNGGE 2021 report.
We look forward to continuing to support the work of the global mechanism and contributing to the shared objectives of a secure, stable, peaceful and resilient cyberspace.
Thank you.
Thank you very much.
I give the floor to Center for Humanitarian Dialogue, followed by Developing Capacity LTD.
Madam Chairperson, thank you for giving me the floor.
I'm speaking on behalf of the Center for Humanitarian Dialogue, a private diplomacy organization acting from principles of humanity, impartiality, neutrality, and independence.
Allow me to suggest an issue for consideration that the United Nations have not fully explored, confidence building in the cyber and information domain after an armed conflict.
Preparing for peace after war has become timely again.
The end of a war is not the beginning of peace.
It is the beginning of a volatile in between situation.
Forces are still opposing each other, trust does not exist.
There's a risk of renewed hostilities and small incidents can carry big consequences.
Military and diplomatic experts have learned to address such hazards.
They have developed mechanisms to stabilize a truce, surrendering weapons, placing them under third party control, nominating mediators, exchanging invoices, establishing joint commissions.
Such measures typically focus on the physical, reflecting the traditional domains of warfare, land, sea, and air.
Technological progress has opened a new non physical domain, cyberspace.
No cease fire, armistice, or peace agreement in history ever had to pay heed to the cyber and information domain.
This must not change.
Designing confidence building measures for the non physical cyber and information domain is a struggle.
It is possible to follow troop deployments, to count guns, to observe ships and aircraft, but it is not possible to watch computer code, nor can algorithms be conveniently cantoned, assembled in one place, or disabled.
Malware can be developed anywhere, transported on a ship, deployed from any point of earth.
It is effectively indestructible.
Moreover, since cyber operations are often used in hybrid campaigns or to prepare a kinetic battlefield, ICT incidents can raise suspicion.
In a no trust security environment such as shortly after a war, this is ever more dangerous.
With this in mind, I encourage the global mechanism to consider and develop ideas for confidence building in the cyber and information domain after armed conflict.
The center of Humanitarian Dialogue, which has some expertise in mediating for peace would be happy to assist to take this up.
Thank you.
Thank you very much.
I now give the floor to Developing Capacity LDT, followed by IMQPA.
Thank you, Madam Chair and Distinguished delegates for the opportunity to speak today.
My name is Robert Collett and I'm the Director of Developing Capacity, an organization focused on capacity building and AI for diplomacy.
During the OEWG we were pleased to support the process by providing unofficial transcripts, contributing to politically neutral side events, and producing reports in response to the chair's guiding questions.
Most significant among these was a series of tabletop exercises on the principles agreed by the OEWG culminating in a Chatham House report on how they might be applied in practice.
I am pleased to say that stakeholders have already begun mobilizing to support the mechanism.
My organization joined meetings in advance of this session to agree how we can best assist and we hope that more experts will be able to speak alongside us in the future.
Several capacity building practitioners, including myself, have recently published articles with practical suggestions for the mechanism that we will submit to the document repository.
But you also have more than two decades of research, conference outcomes, and lessons to draw upon.
This includes the work of previous OEWGs, organizations in the UN system such as ITU, World Bank, and Unitir, regional organizations, and specialist forums.
Many excellent suggestions have already been made.
However, if I were to prioritize three areas as you structure the work of DTG two, they would be the following.
First, aim for quick wins by coordinating, matchmaking, and mobilizing funding for capacity building activities that directly support the global mechanism and the implementation of the agreed framework.
Second, address the deeper strategic challenge of increasing the resources available for cyber capacity building both internationally and domestically.
Third, aim to improve the quality, efficiency, and demand driven nature of cyber capacity building.
This could be achieved by promoting and operationalizing the principles already agreed by the OEWG.
Stakeholders stand ready to assist with this work and developing capacity looks forward to contributing.
Thank you, Madam Chair.
Thank you very much.
I now give the floor to IM Q Ituity SPA, followed by the Moscow State Institute of International Relations.
Madam Chair, Distinguished delegates, thank you for giving stakeholders the opportunity to contribute to these important discussions.
My name is Matto Tomazo and I represent IMQntui, an Italian company specializing in cyber resilience through realistic attack simulations, contributing to Italy's national cyber Capacity Building Program.
Across standards of realistic attack simulations, rapidly observed the same pattern.
Cyber risk rarely emerge from a single vulnerability.
More often it emerged from the interaction between technology, people, processes, suppliers, physical infrastructure, and the decisions that connect them.
The challenge is no longer the number of vulnerabilities.
It is the growing number of interdependencies.
As our societies become increasingly interconnected, cyber incidents no longer remain confined to technology.
A technical compromise can rapidly become operational disruption, economic impact, and ultimately societal consequences.
Our experience has taught us that resilience begins by turning the map around.
Rather than asking how we defend ourselves, we ask different questions.
If we were the attacker, where do we begin? Looking at ourselves through the eyes of those who seek to exploit us reveals in dependencies, challenges assumptions, and help us understand what truly matters before a crisis occurs.
We have learned another important lessons.
Resilience is rarely limited by technology alone.
More often it is limited by assumptions that have never been challenged.
Technology helps us protect what we already know.
Changing perspective helps us discover what we have not yet seen.
Realistic simulations do more than test technologies.
They reveal systematic interactions, expose cascading effects, and challenge assumptions before real adversaries do.
Resilience is not about protecting everything equally.
It begins by understanding what is truly critical.
Every security decision is ultimately a decision about risk.
Madam Chair, the framework developed through the global mechanisms provides an essential foundation for responsible state behavior in cyberspace.
From our operational experience, we would like to offer one practical reflection.
Responsible behavior requires responsible preparation.
Preparation means more than deploying technologies.
It means understanding complexity, recognizing interdependencies, preparing leaders and institution to make sound decisions under uncertainty and challenging assumption before they become vulnerabilities.
Stakeholders have a unique role to play in reaching the open discussion with natural, factual, and operational evidence from the field.
Cybersecurity has been described as a technological challenge.
Our experience suggests something different.
It is fundamentally a challenge of understanding complexity and understanding complexity always begin by changing perspective.
Thank you, Madam Chair.
Thank you very much.
I now give the floor to the Moscow State Institute of International Relations, followed by the Internet Society.
Chair, Distinguished delegates, thank you for the opportunity to address this session.
Thank you, Madam Chair for extensive preliminary work conducted before the start of the session.
We appreciate the opportunity to engage with accredited NGOs and interested states on capacity building initiatives.
Gilmore University has a longstanding academic tradition and expertise in international law and security.
From this viewpoint, we believe that universal legally binding international agreements in information security domain will deliver sustainable long term outcomes rather than voluntary non binding norms of state behavior.
On capacity building initiatives.
In 2023, we launched a training program to enhance the digital skills for Migo students studying in non technical fields, including the future diplomats.
More than 2,300 students completed the program to date.
This year, we proposed an educational project called Identity, which stands for ICT Digital Related Education for non technical and international affairs talented youth.
This project was recognized at the World Summit on Information Society in Geneva as a champion in eLearning category.
This award allows us to present our best cases, our best practices to a wider audience by offering free, short term, open enrollment, distance education courses called Digital Weeks, focusing on international agenda in ICT and information security, national IT strategies, fostering data, AI, and data governance skills, as well as addressing best practices on engaging with IT companies and technology vendors.
We're also open to share our curriculum details and competence framework that other universities and training centers can adopt in interested member states.
On research agenda, In the research field, Guilre calls for recognition of importance of neutrality of large language models with regard to international affairs, every day work of diplomats and media coverage of world events.
We were able to identify profound inconsistencies, irregularities, and sentiment shifts in large language model responses on international affairs issues and problems.
Lack of language and cultural diversity in the outputs of LM is also an area of concern.
Developing a set of reproducible tests of benchmark designed to identify these anomalies.
We believe that this work could be the basis of a standardization of large language model evaluation.
More University stands ready to cooperate with accredited partners and member states on education programs, research projects, and practical capacity building initiatives.
Thank you, Madam Chair.
Thank you very much.
I I give the floor to Internet Society, who will be followed by Kenya ICT Action Network.
Thank you, Madam Chair.
As this is my first time participating in the global mechanism on behalf of the Internet society, I would like to welcome the launch of the first substantive plenary session and congratulate you on your election as chair.
This mechanism represents years of hard won consensus and its success will be determined by whether it can turn around agreed norms into practical real world impact for the billions of people who rely on the Internet every day.
Since 1992, the Internet Society, a global nonprofit organization founded by Internet pioneers, has promoted the development of the Internet as a global technical infrastructure, a resource to enrich people's lives and a force for good in society.
Through our community members, special interest groups, and over 130 chapters worldwide, our organization advocates for Internet policies and technologies that keep the Internet open, globally connected, and secure.
We come to the table with operational experience and technical expertise as a part of the broader technical community, which is comprised of various organizations.
These organizations build the Internet and make It resilience.
Specifically standards developed through the Internet Engineering Task Force or the IETF through its open bottom up process underpin much of the day to day security of the Internet.
The same open participation model proves that effective multi stakeholder collaboration can deliver.
Beyond standards through initiatives like mutually agreed norms and routing security or manners, support the development of routing security practices to reduce systemic vulnerability and global routing.
By working with local communities to build Internet infrastructure and skills through community networks and Internet exchange points.
This mechanism directly advances the capacity building goals that it has rightfully prioritized.
Additionally, sorry, through our global common good cyber initiative and our engagement with cybersecurity community, we help connect resources seeking to fund non profits across the globe whose work support the following objectives.
Maintenance of critical cybersecurity infrastructure, delivery of scalable support to secure Internet users from digital harm, including state directed cyberacivity and digital transactional repression, and the advancement of safer Internet for vulnerable groups and high risk communities, including civil society and journalists.
We would be really glad to bring these perspectives to the dedicated thematic groups, particularly that on capacity building.
Our core message today is this, we believe that this mechanisms long term success will be served by meaningful and sustained engagement of non governmental stakeholders.
This is not a courtesy.
It is essential.
The Internet is not solely run by governments.
It is run by a distributed ecosystem of network operators, standard bodies like the IATF and technical experts.
Decisions on cyber norms, international law, and confidence building should make the input from the stakeholders who build and secure its infrastructure prioritized.
Otherwise, the mechanism risks being disconnected from operational reality.
Therefore, we would like to call on member states to ensure stakeholder accreditation and participation modalities are implemented in predictable, transparent, and non reactive manner to include actors without EcoSoc status through fair application and the non objective process.
Preserve and strengthen the multi stakeholder model that keeps the Internet resilient, innovative, and globally interoperable, and offer stakeholders an opportunity to contribute substantively to the DTGs allowing stakeholders to bring their insights and perspectives, to continue to contribute and better the results to be implemented and supported.
The Internet society looks forward to constructively and substantively contributing to the global mechanism.
Before I close, I would like to invite you all to the briefing that will be co organizing with the permanent missions of Kenya and Bulgaria, alongside ICN and the ITU entitled demystifying the Internet Collaborative Security Approaches.
It will be taking place tomorrow at 1:15 in conference room eight.
I hope to see you there.
Lunch will be provided.
Thank you.
Okay.
Thank you very much.
And now give the floor to Kenya ICT Action Network, followed by Association for Progressive Communications.
Thank you so much, Madam Chair.
I'm making this statement on behalf of KikTanet and it reflects outcomes from consultations with the broader multi stakeholder community that have been taking place in preparation for this week.
We congratulate you, Madam Chair, on convening this historic substantive plenary.
As this global mechanism establishes its first permanent foundation, we face a decisive choice.
Either repeat the familiar rituals of diplomatic deliberations or pioneer a collaborative more capable of confronting borderless digital threats.
To deliver real stability, this mechanism will need to consider new ground in several ways as as we put it to you.
In our humble consideration, one, we would like consideration of consultations with a structural integration that considers multi stakeholder approaches.
We call for the recognition and utilization of non state expertise to be systematically woven into informal consultations.
Technical drafting and policy implementation.
So there is need for multi stakeholder approaches in the ways that things will move from now.
Two, we call for the delivery of human centric, demand driven capacity building, and we are saying that digital security is fundamentally about human safety.
Resources therefore need to move beyond high level legal meetings towards strengthening local incident response teams, defending civic space, and protecting vulnerable communities from technology facilitated abuse.
Three, make the dedicated thematic groups actionable vehicles for problem solving and aim to create real world impact.
We propose that the DTGs be practical problem solving spaces.
We technical experts, civil society and governments co design workable responses to critical infrastructure vulnerabilities, and AI amplified harms in space.
Finally, four, anchor policy in ground level cyber threats.
Non state actors and private sector operate on the front lines of threat detection, incident response, and human rights monitoring.
We humbly call for consideration to establish formal channels to ingest grassroots data, in particular from developing nations.
This will ensure internal norms respond to real world harms.
Chair, we also request that if we can set up meetings, either virtual where we can just be appraising ourselves either quarterly or half yearly with you so that we make this engagement real.
To secure cyberspace, we call for shared stewardship across all sectors and KikTNet and the broader multi stakeholder community that have been participating this week remain fully committed to partnering with member states to ensure our digital future remains safe, open, and anchored in human dignity.
Thank you so much, Madam Chair.
Thank you, et, and I've heard you loud and clear.
I now get the floor to Association for Progressive Communications, followed by the Royal Institute of International Affairs.
Chair, colleagues, I speak to you today on behalf of the Association for Progressive Communications.
Since this is the first time that APC is taking the floor, let me first congratulate you on your appointment, Madam Chair, and our appreciation for the efforts that you, the Secretariat, as well as the co facilitators have been helping us engage and aid the mechanism.
For those of you who may be unfamiliar, APC is an international not for profit membership organization born in 1990, whose network includes 74 organizational members and many associates across 60 countries.
We are also proud to have several of our members present here in the mechanism today.
From our beginning, our network has believed that it is crucial for the international system to engage with civil society, public interest technologists, and grassroots communities on the political and policy aspects of technology development.
APC has engaged with the UN's discussions on global cybersecurity across the successive OAWGs and we are glad to see this permanent mechanism come into operation.
We do believe that state led and multilateral system capacity building programs must address the disproportionate impact of cyber threats faced by vulnerable communities, including women, LGBTQI plus people, and human rights defenders.
The unique threats that different communities in the global South face are often unrecognized or even unrecorded and therefore not catered for in these discussions and processes.
In effect, they are invisible.
Your Excellencies, the reality is that cyber threats, models, and actors are different in different communities.
Civil society can support this by providing evidence to better understand and mitigate these differentiated effects.
Based on interviews and testimonies from women in public facing roles, members of the APC network have documented how digital surveillance is used to intimidate, silence and restrict women's participation in civic and political life.
In that regard, we therefore hope that the global mechanism builds on the recognition documented by the secondary AWG of the harms posed by the global growth of the cyber mercenary hack for hire spyware sector and the harms it unleashes on human rights defenders, journalists and activists working on women and LGBTQI issues.
We call on further work on the gender impact of these efforts and how vulnerable communities are impacted by cyber mercenary actors.
Chair, as you've heard from me, it has often been society and academic research has documented the empirical evidence of the harms of matters such as ransomware or more.
It is therefore crucial that the global mechanism overcome the injury it inflicted on itself by the initial blocking of so many stakeholders who we need to see sitting besides us here.
Madam Chair, APCNS members have been organizing training activities to equip stakeholders with the capacities needed to engage in global cybersecurity policy discussions.
We urge you to ensure this process is both enabling and a safe space so that these communities who we are building capacity with training can take part and we have civil society, vulnerable communities and security researchers actively participating here.
We also believe that the global mechanism and it DTGs must help states build appropriate cybersecurity laws and policies that aid and do not overreach or oppress.
Our members and partners have urged governments to implement gender sensitive cybersecurity laws that holistically address digital violence and build appropriate rapid response mechanisms.
We hope that this is prioritized by the DTGs.
Excellencies, we urge you to pay attention to how the race or AI development impacts the global majority, particularly with the information security context.
We believe that the mechanism and the DTGs should focus on how the current race or AI deployment, particularly in the public sector, is impacting security vulnerabilities and in turn affecting vulnerable communities.
We also believe that in the sphere of AI and cybersecurity, the mechanism should ensure that the lessons of the last two decades of human rights and feminist approaches to technology is the foundation we build on.
Madam Chair, rest assured that all stakeholders, whether accredited or not stand ready to help you in this process.
Urge you to listen to us.
We share critical information that helps patch the problems that we see in our global ICT systems.
Thank you.
Thank you very much.
I now give the floor to the Royal Institute of International Affairs, followed by Internet Love.
Thank you, Madam Chair for the opportunity to speak today and for your tremendous efforts in fostering an inclusive process and establishing strong foundations for the work of this mechanism.
The global mechanism gives us something two decades of cyber diplomacy have been working towards a standing space to continue building shared understanding and to support implementation over time.
States have agreed on a framework for responsive state behavior and that agreement provides an important foundation.
Our focus now should be on what it will take to ensure that the framework is reflected in practice.
First, on implementation, as many delegations highlighted yesterday, the dedicated thematic groups will be central to closing the implementation gap, and we have shared our views on how best they can be structured and we will continue to do so.
States also have a strong foundation to build on.
They have already developed a significant body of guidance through previous UN processes and at the national level complemented by practical resources from the multi stakeholder community, such as, for example, the paper Chatham House developed on the operationalization of the cyber capacity building principles that my colleague mentioned.
But we should also be honest, the existence of resources is not the same as the capacity to use them.
Guidance cannot implement itself.
Many states are committed to implementing the framework, but continue to face technical, institutional or financial constraints as well as competing priorities that make doing so difficult even when practical guidance is readily available.
This is where the multi stakeholder community is not a bystander, but a partner in implementation.
Industry, technical organizations, academia and civil society already help translate the framework into operation guidance, often in direct partnership with states.
The challenge is not whether this expertise exists, but whether states will make full use of it.
We therefore encourage states to draw more deliberately on that expertise.
Both within and beyond these official sessions, especially as many stakeholders actively working on these issues have had their accreditation to the official meetings denied.
Second, wide implementation is rightly the priority for this phase of this mechanism.
We should not lose sight of the fact that the environment the framework is intended to govern continues to evolve.
More states are adopting offensive cyber postures, the growing use of proxy actors, the emergence of frontier AI models and their implications for cybersecurity, and the wider availability of sophisticated cyber intrusion tools are all changing the operational landscape.
This is precisely why the mechanism has such an important role to play, not only in supporting implementation of existing commitments.
By continuing to build shared understanding of what responsive behavior means as technology and state practice evolve.
Finally, we would note that resonance matters as much as resourcing.
The norms will only shape behavior if they are understood beyond this room, not as list of letters, but as the practical expectations that sit behind them.
Expectations such as protecting critical infrastructure, cooperating and responding to cyber incidents, or taking reasonable steps to ensure that a state's territory is not used for internationally wrongful ICT activity.
Connecting those expectations to real incidents and real operational challenges helps make the framework something people can recognize, relate to, and ultimately implement.
Making it tangible is in itself a form of implementation and multi stakeholders can help with that provided states create space to bring them into that work.
We are committed to continuing to coordinate amongst the broader multi stakeholder community to provide expertise in all available to us and help ensure that the global mechanism delivers on its objectives.
Thank you.
Thank you very much.
I now give the floor to Internet Lab and lastly to Access Lab.
Madam Chair, I'm delivering this statement on behalf of Internet Lb, a Brazilian think tank dedicated to producing knowledge at the intersection of digital technologies and human rights.
This statement also reflects consultations with the broader muod stakeholder community conducted in preparation for this week's discussions.
I want to start by briefly manifesting or disappointment with the number of organizations that have been blocked from participating in the form of sessions of the global mechanism, many of whom have provided their support and expertise to this process without any political agenda.
We therefore appreciate your commitment, Madam Chair, to ensuring broader and meaningful stakeholder participation in the DTGs including the participation of NOA accredited stakeholders in line with established UN practice for informal working methods.
Looking ahead, we encourage discussions that are closely connected to the needs identified by member states during the plenary and that focus on practical implementation.
For DTG one, discussion should examine how emerging developments affect the implementation of existing UN framework rather than creating parallel normative processes.
In this regard, we underscore that this framework operates within international law, including international human rights law and where applicable international humanitarian law.
We also encourage discussions grounded in concrete cases studies and implementation expertises.
This exercise should be guided by a set of previously identified guiding questions allowing stakeholders contributions to address the issue that co facilitators consider most relevant in light of the views expressed by member states.
We also believe that it is essential to examine how the use and misuse of ICTs affect individuals and communities differently.
This includes considering specific risks faced by women and other historically marginalized groups.
Just a second.
An inclusive and evidence based understanding of these differentiated impacts is necessary to ensure that responses to cybersecurity challenges are both effective and rights respecting.
For instance, For instance, our own research on online gender based political violence against women politicians in Brazil has documented how coordinated attacks disproportionately target women and members of other historically marginalized communities with clear implications for democratic participation and for the design of effective rights respecting cybersecurity responses.
DTG two, we encourage discussions on sustainable, demand driven, and inclusive cyber capacity building that build on the process achieving the WGG and focus on implementation.
Priorities should include better coordination among existing initiatives, support for states with limited resources, and cooperation for open source source cybersecurity tools.
As an organization for the global majority, we emphasize that effective capacity building requires meaningful engagement with priorities of the global majority states.
While drawing on the expertise of civil society, academia, the technical community, and the private sector.
Capacity building initiatives should also be accessible, context sensitive, and responsive to those most affected by cyber threats.
Madam Chair, we remain committed to supporting this process in a constructive spirit and look forward to continue to work with member states and all stakeholders to ensure that the global mechanism becomes an effective, inclusive, and action oriented platform.
Thank you.
Thank you very much.
I now give the floor to Access now.
Thank you, Madam Chair.
I'm making this statement on behalf of Access Now, a grassroots to global organization that defends and extends the digital rights of individuals and communities most at risk.
Our statement today reflects outcomes from consultations with the broader stakeholder community that had been taking place in preparation for this week.
As stakeholders, we look forward to sharing our expertise and experiences during the DTG in December in a constructive and evidence based manner.
On existing and potential threats, A now fully aligns itself with the statement made yesterday by Kenya ICT Action Network, particularly the existing threats surrounding the unchecked proliferation of commercial spyware, surveillance, and state sponsored cyber harassment used to monitor, intimidate, and silence journalists, human rights defenders, and political dissent.
With respect to threats posed by ICTs in armed conflict, we echo the statement made yesterday by ICRC regarding the alarming range of ICT operations that have disabled the provision of essential services for civilian populations.
Out of the 313 Internet shutdowns documented by Access Now and the Keep it on Coalition in 2025, 125 shutdowns occurred in situations of conflict, impeding access to essential services and communications.
In light of these existing and potential threats, we would like to underscore three priority areas for further discussion during the DTGs.
First, we urge that the DTGs to make the human cost of critical infrastructure attacks visible and foreground the role of civil society in its defense.
This requires direct engagement with and the protection of the human beings who make cybersecurity possible, including those who provide research and handle incident response, especially regarding to digital security threats against those most vulnerable.
This cannot remain an aspiration.
States must ensure that national critical infrastructure protection frameworks give real operational effect to their human rights obligations while protecting tools like strong encryption and independent research capabilities that enable civil society to contribute.
Second, the rapid increase in capabilities of AI models is a major topic of discussion.
We echo calls not to duplicate existing UN processes grappling the questions regarding AI, but rather to build on such discussions with a focus on the unique issues and value of the global mechanism.
With that, we call for the specific recognition of how AI tools are beset by glaring security vulnerabilities that have grave consequences for the confidentiality of our data, information integrity, and access to and the availability of systems.
These are all problems that a human rights respecting approach can help solve.
When human rights are successfully placed at the center of discussions on AI, as witnessed in other UN processes, the outcomes shift to concrete enforceable protections for those most at risk.
Third, DTG one should build on the substantial body of state practice already affirming that international human rights law and international humanitarian law apply to state cyber behavior.
Turn consensus into shared understanding implementation.
We commend the growing number of states that have proactively published national positions on the application of international law to cyberspace and call on states to ensure that the same rigor is reflected domestically so that national cybersecurity laws, policies and strategies are developed and implemented consistent with their international human rights law and international humanitarian law obligations.
Inclusion, Madam Chair, we reiterate our intention to support all states present in this room, especially small states and those with limited resources in delivering on the commitments made in the framework of responsible state behavior and the objectives for the global mechanism.
Thank you.
Thank you very much to all of you.
First, for your very substantial contributions, all of you who are here in the room, like I said, at the beginning of this segment, as well as to all of you who are following us remotely.
The community of stakeholders is without a doubt, a fundamental part of our work.
You have a lot of experience and considerable knowledge, and we will continue to work closely with you to achieve meaningful progress.
My team and I have taken due note of all of your comments, your invitations, the calls to action that you've made.
We would also be grateful if you could please share your statements with us, not only with the Secretariat but with the chairs team, please.
We'd be grateful for that.
Thank you.
I'd now like to open the floor for any delegation who would like to react to any of the statements made by the organizations that we've just heard from this afternoon in the spirit of having an interactive dialogue.
If any delegation would like to take the floor, you may do so now by pressing your microphone button and the Secretariat will take note of it.
Canada, you have the floor.
Thank you very much, Madam Chair, for this new opportunity to take the floor on this important matter.
We welcome the interventions by the stakeholders that have been accredited to disciplinary session.
Unfortunately, they are too few.
A number of interventions delivered today demonstrate the readiness and willingness of colleagues from the multi stakeholder community to contribute further on practical matters in the context of the dedicated thematic groups.
Contributions span the breadth of priorities identified by states over the course of the week for each of the DTGs including on technical and other forms of capacity building on international law and norms implementation, as well as other important matters such as the particular impacts of giving threats on gender and youth.
While we heard stakeholders from a number of regions today, we would have benefited from much more robust cross regional representation of stakeholders if they had not been vetoed.
I am referring here to stakeholders from Mexico, Brazil, Peru, Panama, Ghana, Nigeria, and South Africa.
We look forward to more meaningful and more inclusive opportunities for all stakeholders to engage in December.
Thank you, Madam Chair.
Thank you very much.
I'll give the floor to the delegation of Japan.
Well, thank you, Madam Chair.
Now cybersecurity cyber threat become increasingly sophisticated and complex, it is critical to draw on the private sectors expertise for recognizing threats and implementing concrete countermeasures.
Japan attaches great importance to a multi stakeholder approach in the global mechanism.
In this regard, Japan highly values this session and strongly hopes to further strengthen public private collaboration within the United Nations framework through expert briefings and interactive discussions between the public and private sectors, especially including the discussion of the DTGs.
With a wide range of stakeholder participation, we hope that member states awareness and understanding of cybersecurity will deepen further.
Thank you very much.
Thank you very much.
I'd like to ask whether any other delegation would like to take the floor in this interactive segment.
Mexico, you have the floor.
Thank you very much, Madam Chair.
I'd like to begin by thanking you and the Secretariat for organizing this segment, which is a very important one for Mexico.
We'd like to welcome the fact that on this occasion, The screens reflect the names of the organization second the floor and for Mexico.
This is a practice that does not only give visibility to the valuable contributions of each and every organization, but also reflects the importance that this mechanism attaches to the meaningful participation of all stakeholders.
My country took note of the contributions made in addition to the ones also made in writing.
Preparing for the meeting on the dedicated thematic groups in December, my country would like to urge stakeholders to consider drafting specific inputs for the issues under discussion so that we can use these not only for the discussions in the meetings, but also for the technical analysis that member states will be engaging in on this process in their respective capitals.
Further as far as possible.
I'd like to ask a question.
It's more of a general question.
I don't necessarily need a response, but if there's any stakeholder that is in a position to answer it, we'd be grateful to have an answer to it.
Of course, we also remain available outside of the room to discuss it.
It would be very beneficial if you could be able to share any example of any, any ongoing work that you are engaging in, for example, any guides, guidelines, methodologies, models, or any good practices to support states to implement the framework on responsible behavior.
In particular, Mexico would like to know whether there's any example that you could share that could benefit a developing country like Mexico and that takes account of our perspectives.
Thank you, says the Chef, your question and your statement.
Would any delegation like to take the floor right now? I see is that the European Union? Please go ahead.
Thank you very much Chair.
First of all, thank you very much for offering the opportunity for stakeholders to speak during our session today, but also for your earlier engagement with the stakeholders prior to this plenary session.
Also, yesterday, the two stakeholders that were able to come in after the threat section really dedicating their interventions to the topic that we are discussing at that moment is very useful to bring the stakeholders and states closer to each other when it comes to advancing international security and stability in cyberspace.
Welcome your efforts.
We also wanted to say thank you to the stakeholders for participating.
We know it's been a challenging environment for you, but we are very much interested in your contributions, not only when it comes to the statements that you are able to make today, as well as the statements that you have been able to make in the run up to this session, but also your contribution when it comes to specific challenges that we will be discussing in the dedicated thematic groups.
Furthermore, we encourage you to continue to contribute to this effort by enhancing the cooperation with states working together on the ground, building capacities also from states in implementing the UN framework of responsible state behavior and enhancing their cyber resilience through your research, through your trainings, and through the dedicated activities that you employ.
We look very much forward to continue the cooperation with you and with states on this important matter.
Thank you very much.
Miscis, Thank you very much.
I don't have any other delegation on my list to take the floor in this segment.
So I will give the different stakeholder organizations the opportunity to answer the question posed by the delegation of Mexico and whether you could share any example of any work that you are engaging in, whether it's guide, model, methodologies to support states for the implementation of the framework on responsible behavior.
If any of you would be interested in briefly answering this question, Then please press your microphone button so that we can see who is requesting the floor.
Before that, though, I'll give the floor to the International Chamber of Commerce, who had asked to take the floor in this space and you have 4 minutes.
E.
I have the honor to deliver this statement on behalf of the International Chamber of Commerce, the institutional representative of more than 45 million companies in over 170 countries, and observer to the United Nations General Assembly.
ICC has engaged in the open ended working group since its inception and looks forward to contributing with the same commitment to the work of the new UN global mechanism on cybersecurity.
The mechanism begins its work at a critical moment.
Businesses are operating in an environment marked by geopolitical tension, economic uncertainty, and a sustained rise in malicious cyber activity targeting governments, companies, critical infrastructure, and essential services.
The success of the mechanism will depend not only on the quality of intergovernmental exchange dialogue, but also on its ability to draw on the expertise, experience, and capabilities of the broader cybersecurity community.
The OEWG demonstrated the value of stakeholder engagement and the global mechanism should build on that experience by ensuring that industry, the technical community, and civil society can contribute in a meaningful, structured, and predictable manner across all areas of its work.
The dedicated thematic groups provide an important opportunity to translate dialogue into practical cooperation.
Business stands ready to contribute operational expertise, technical knowledge, and implementation experience, particularly in the areas of existing and emerging threats and cybersecurity capacity building.
First, on existing and emerging threats.
The private sector is often the first to identify, analyze, and respond to new cyber risks.
Companies possess real time visibility into threat trends across networks, sectors and geographies, as well as practical experience in mitigating attacks and strengthening resilience.
This operational insight can help the DTGs develop a more comprehensive understanding of the evolving threat landscape, identify emerging risks, and support the sharing of good practices that reduce cyber risks across the digital ecosystem.
Industry expertise and practical experience can support discussions on topics such as protecting critical infrastructure, essential services, and global supply chains, strengthening cyber resilience and incident preparedness, particularly for small and medium sized enterprises, improving coordinated vulnerability disclosure and reducing systemic risks, facilitating threat information sharing and public private cooperation, promoting secure by design approaches and responsible security practices, addressing emerging technological developments and their cybersecurity implications, and supporting the practical implementation of agreed norms and confidence building measures.
Second, capacity building should be an integral part of the mechanisms work.
Cybersecurity capacity strengthens confidence in the online environment, supports meaningful digital inclusion, and helps countries protect their citizens, businesses, and critical infrastructure.
Yet significant gaps remain, particularly in the development and implementation of national cyber strategies, incident response capabilities, technical expertise, and institutional frameworks.
The private sector is making substantial contributions through technical assistance, workforce and skills development, awareness raising, knowledge sharing, incident preparedness, and the provision of practical tools and resources.
Businesses also work alongside governments and other stakeholders to strengthen institutional capabilities, improve resilience, and share operational expertise.
Finally, meaningful stakeholder participation is not merely desirable, it is essential to the success of the global mechanism.
Cybersecurity discussions cannot be separated from the systems, services, and infrastructure they seek to secure.
Much of the world's digital infrastructure is designed, operated and maintained by the private sector while technical experts and civil society bring additional expertise and perspectives that strengthen cybersecurity outcomes.
In closing, business looks forward to being a constructive and active partner in the global mechanism.
We can contribute by sharing real time threat intelligence, operational expertise and lessons learned from securing networks, supporting incident response, strengthening supply chain resilience and helping build cyber capacity where it is most needed.
Mr..
Thank you very much.
Thank you.
I have a request from the delegation of Chile.
Please go ahead.
Thank you very much, Madam Chair.
We just wanted to take the floor like Canada and the European Union on this stakeholder segment, and we wish to thank you for facilitating the work of the global mechanism to all of the organizations.
We thank you very much for being here this afternoon with us.
Your participation is fundamental.
You bring practical experience, specialized knowledge, and talk about concrete challenges that can help us and to support the effective implementation of the mechanism.
We reject the amount of objections voiced on your participation, including from institutions from our own region.
Your voice is very important in order to listen to a diverse voice and reflect the reality on the ground and we hope that you'll be able to continue to contribute through the dedicated thematic groups.
Thank you very much.
Thank you.
Now we'll give the floor back to the different stakeholders so that they can answers the question made by the Mexican delegation.
I'd be grateful if you could do it as briefly and concisely as possible so that we can hear from everyone who's requested the floor.
I'll give the floor first to the Royal Institute of International Affairs, who will be followed by the Association for Progressive Communications.
Thank you for the delegate from Mexico for this concrete question and for other delegations for their words of support.
There's already a meaningful body of practical work drawn.
I mentioned in my intervention the Chatham House report providing concrete recommendations for the operationalization of the cyber capacity building principles.
This could be obviously highly relevant to DTG too, but also other organizations have produced important tools and resources and mentioned the one I'm aware of and colleagues might want to complement.
And the Geneva Dialogues manual offers concrete guidance on implementing specific norms like supply chain security and responsible vulnerability disclosure.
The Paris Call for trust and security in cyberspace brings together commitments from states, companies, and civil society around shared principles and organization like the Cyber Peace Institute now called Protect NGO, have produced sector specific guidance, for example, on protecting the healthcare sector from cyber harm.
We have been discussing as a multi stakeholder community, perhaps mapping these resources and making them available to states and we welcome views on what would be the most useful format to you when we do so.
Thank you.
Thank you very much.
Yes, that would certainly be very valuable.
I now give the floor to the Association for Progressive Communication.
Please go ahead.
Thank you so much, Madam Chair.
Again, thank you to the delegate from Mexico for the pointed question.
As my colleague from the Royal Society for International Affairs mentioned, there are a range of resources Society makes available from the Association for Progressive Communications.
We also provide direct support and capacity building at key meetings and trainings.
Form we conduct the African School for Internet Governance, which has been taking place year on year with a range of partners focused on the Africa region with increasing focus on cybersecurity, cyber norms, including the OEWG and the norms on international cybersecurity and security.
We conduct the feminist tech exchange, which looks at providing security building capacity, particularly vulnerable communities and others, including understanding how existing international cyber processes and more engage with feminist technology and security conversations.
Additionally, we have directly provided frameworks for developing gender responsive cybersecurity policy and assessment tools in multiple languages including Spanish and I believe that that was also referred to and built on by our colleagues in Unidir who launched their compilation of resources on gender and Cyberd which builds off that.
We are also very happy to note that partner organizations such as Global Partners, digital and others have tools such as inclusive cyber norms, toolkit, and more.
These are a small set of examples of resources that stakeholders have already prepared and hope to build on for the mechanism and more.
Thank you so much.
Muchiss Thank you very much.
I now give the floor to developing capacity.
So the international community of stakeholders and governments have for several years been building a repository to answer that very question.
It's called the civil portal.
It has 74 documents which are on the thematic area that you're interested in, and also information on 100 past cyber capacity building projects in that area.
It's received a lot of support in the past from the Dutch government.
It's currently going for a period of renewal, which I was discussing with other stakeholders earlier today and it stands ready to be a state and stakeholder platform for hosting these resources going into the future.
Thank you very much.
I now give the floor to foreign Incident Response Force and security teams.
Thank you for the delegate from Mexico.
We really appreciate any joint cooperation that would result in supporting Mexico applying the models for best practices and implementing state responsible behavior in cyberspace.
In relation to first, the form of Incident Response and Security team, we already 31 team members from Mexico, which is really a sizable number of members.
There is an upcoming event happening in Mexico city.
It's the Mexico City technical colloquium taking place next month.
We have different mechanisms by which we can support efforts in different parts of the world and evidently, if we have so many members, it set the ground for further cooperation.
We can also share experiences from other parts of the world.
We welcome continuous dialogue with countries that are interested in support from F and F membership would be more than happy to give that support extended in different shapes and forms depending on the current situation.
Thank you.
Thank you very much.
First, I now give the floor to future Earth Systems.
Thank you, Madam Chair.
Rather than take time up during this session, I will be happy to meet with the honorable representatives from Mexico as a follow up to explore how enterprise architecture can assist states with implementation of the norms.
Also, thank you to representatives for your positive feedback to our participation today.
Thank you, Madam Chair.
Thank you very much for your kind availability.
I give the floor finally to Internet Society.
Thank you, Madam Chair.
I already mentioned the IATF, the Internet Engineering Task Force.
The Internet society specifically offers a policymaker program to policymakers and it specifically goes over how the Internet works, provides visibility on Internet standards development processes.
The idea is to work with diplomats to understand how the Internet works, how it evolves, and the standards that underpin it so that we can all collectively develop and implement better policies.
I'm happy to connect after this as well to provide more information to the Mexican delegate.
Thank you.
Thank you very much, all of you.
For these responses and follow up comments, I see that Germany has requested the floor.
Thank you, Madam Chair.
I would like to take the opportunity to echo what colleagues have said from the EU, Canada, Mexico, and Chile with regard to the importance of this exchange, and that we also regret once more, and we have to highlight this that we only had a limited number of participants in this interactive exchange that we very much value.
In this regard, we just want to highlight one piece of work that has been presented by an organization that was not allowed to come here.
It's the organization interface that has presented a study and a survey that compares the global state of play with regard to CBM implementation.
We consider this survey and this analysis quite useful for the interaction and engagement that we have very likely already this afternoon.
Thank you very much, chair.
Thank you very much, Germany, for this information.
Once again, thank you very much to all of you.
There was just one question from the delegation in Mexico.
Nevertheless, that interaction was very valuable with all of you stakeholders.
I'd like to close this part of the meeting and just like I said this morning, we're going to go back to international law.
There are still six speakers on my list, so I'll read them out.
So that we can begin with the statement.
We have Switzerland, the United States, Australia, Nicaragua, Algeria, the African Union, and the ICRC, you have the floor.
Madam Chair, Switzerland fully aligns itself with the joint statement on international law and IHL that we delivered this morning on behalf of a cross regional group of states.
We will therefore limit ourselves to the following points in our national capacity.
Switzerland welcomes the second joint statement on international law delivered by Australia and many other statements in this regard.
The number of states that have issued these, more than 40 underscores the relevance of the discussions to date on international law, especially also on IHL and international human rights law.
Additionally, more than 36 national and two regional positions on the application of international law in cyberspace have been published.
All of this shows that there is great interest in continuing these discussions, but not in any manner.
The new mechanism offers the opportunity to turn statements and written positions into lively and substantial discussions based on real world scenarios in the DTGs that is likely to be an innovative step forward.
Madam Chair, Switzerland stands ready to participate actively in the dedicated thematic groups.
As mentioned in our joint statement, we support concrete discussions on real world scenarios, particularly on the protection of critical infrastructure such as hospitals, water systems, and energy networks from malicious ICT operations, both in times of peace and an armed conflict.
We also support expert briefings on specific topics of international law, IHL, and international human rights law and would also like to once again highlight the importance of the inclusion of stakeholders in these discussions.
In our view, the success of the global mechanism is connected to the recording of both emerging convergence and open questions.
Documenting this progression is what will distinguish this mechanism from its predecessors.
Madam Chair, discussions on the concrete application of international law take place not only here in New York, but also elsewhere.
In this regard, we would like to highlight the ICT workstream under the global initiative to galvanize political commitment to IHL and the meetings of our cross regional group on international law and IHL in cyberspace.
Switzerland is honored to co chair together with Ghana, Luxembourg, and Mexico, the ICT workstream of the global IHL Initiative.
This process provided an invaluable complementary platform for very substantive discussions on IHL and ICTs among states and key stakeholders.
We have moved beyond the question of whether IHL applies to ICT activities in armed conflict to the more practical and pressing question of how it applies.
The discussions have reaffirmed that reliable ICT infrastructure and services are indispensable for civilians, governments, and humanitarian actors, particularly in conflict affected areas.
Have equally underscored that civilians and other protected persons and objects must be safeguarded against the dangers arising from ICT activities during armed conflict.
We encourage everyone to draw on these rich discussions and the outcome document and to continue developing and promoting a shared understanding on how IHL applies concretely.
In addition, in April this year, representatives from 15 states from our cross regional group gathered for the second time on Mount Rg in Switzerland to discuss the concrete application of international law and IHL in cyberspace in an informal setting, allowing us to dive deeper into real world scenarios.
Initiatives like these foster a better understanding of other states concerns and support the discussions in the UN without duplicating them.
Finally, we would like to thank the ICRC for submitting their working paper entitled Preventing ICT threats to the civilian population in times of armed conflict, six humanitarian and legal priorities to the GMAC.
We invite states to use it as a basis for focused discussions on international humanitarian law.
While all six priorities are important, we believe that the issue of ICT operations targeting medical facilities and humanitarian organizations is one that all states should be interested in addressing urgently.
I thank you.
Thank you very much.
I give the floor to the delegation of the United States, who will be followed by Australia.
Thank you, Madam Chair.
Further to the statement we set out yesterday, I wanted to reiterate again our view that existing international law applies to activities in cyberspace and remains fit for purpose.
The United States will not support language suggesting new binding obligations are required or that existing legal obligations are somehow insufficient.
We believe that any proposal to use this pillar or to use the TG one to relitigate international law as a stalking horse for treaty making duplicates work that has already been done and it keeps discussions on this topic very stagnant.
We have shown extreme flexibility over the course of these discussions in the OAWG, but we will not agree to a discussion topic that will be hijacked for that purpose.
Our previous discussions on international law have demonstrated that existing legal obligations remain fit for purpose.
Further discussion of international law in this mechanism should be anchored in concrete threats and practical tools for addressing them.
I believe that's also something that's been echoed throughout the day.
Finally, Madam Chair, the United States believes that we should use our time in this GPM to implement the 11 norms states have already committed to and not to litigate settled ground to manufacture, the appearance of a gap that does not already exist.
Thank you so much.
Thank you very much.
I now give the floor to Australia, who will be followed by Nicaragua.
Thank you, Chair.
Australia is pleased to align with the Pacific Islands Forum statement delivered by Tonga and the cross regional statement on international law delivered by my colleague.
We make the following remarks in our national capacity.
All states have agreed existing international law applies to state conduct in cyberspace and that as my colleague from Kirbas powerfully set out, it is indispensable in advancing responsible state behavior in cyberspace and in maintaining the international peace and security on which all states rely.
In the GGEs in the OEWG that preceded this forum, and in other valuable platforms, we have discussed and reached convergences on how international law applies to cyber activities.
And the OEWG saw states solidify and add granularity to several specific areas of convergence.
Some of these, including on the application of the principle of sovereignty, non intervention, the prohibition on the use of force, and the peaceful settlement of disputes were reflected in the OEWG's 2025 final report.
This report provides a strong foundation for our work.
However, we regret that it did not reflect other areas in which states had worked hard to identify common ground, including on the ways in which international human rights law, the law of state responsibility, and international humanitarian law apply.
In this respect, the two cross regional groups of states on international law made significant contributions to advance and to document discussions in the OEWG and the number and diversity of states that joined statements delivered by those groups today demonstrates the broad appetite to prioritize international law in this mechanism.
Taking the work of these groups as our baseline and their cross regional character as our example, we must now take up the opportunity that this mechanism offers to consolidate common understandings between states to actionable effect.
This can start by leveraging the integrated and inclusive platform of the DTGs, bringing together legal, technical, and diplomatic expertise to elaborate in substantive ways exactly how these areas of law apply.
Here, states can have tangible and cross cutting engagement on how relevant law intersects with norms and practical measures to address the pressing security threats that states have outlined in recent days.
Australia's experience has shown that applying international law to concrete cyber incident scenarios helps to build confidence and shared understanding, demonstrate the practical value and comprehensiveness of the existing legal framework, and connect it tangibly to implementation actions.
Incorporating the perspective of legal and technical experts will enrich and ground the outcomes of these discussions.
Chair, we echo the views expressed by others in this session that capacity building remains essential to ensuring that the outcomes of our discussion reflect the full breadth of experience in this room.
Australia will continue supporting efforts, including through DTG two to ensure all states can contribute meaningfully to and benefit from the discussions on how international law applies to cyberspace.
This includes identifying and championing needs driven training and supporting more states to develop and share their national positions.
Chair, international law's contribution to peace and stability in relation to cyberspace can only be fully realized when states share common understandings of what our international legal obligations require and in practice and a robust commitment to implement and to adhere to them.
Australia looks forward to working with you and with all delegations toward this important goal.
Thank you.
M Thank you very much.
I give the floor now to the delegation of Nicaragua.
Mr.
Thank you very much, Madam Chair.
For Nicaragua, the particularities of cyberspace require the debate on the application of international law to continue to be engaged in in a careful, inclusive, and intergovernmental manner.
In this regard, for us, it's necessary to continue to build a common understanding on the way international law should apply to this sphere, bearing in mind its specific characteristics and avoiding interpretations that could favor the militarization of cyberspace.
The UN Convention against cybercrime demonstrates that against the new challenges derived from the use of ICTs, The international community can make headway through dialogue and consensus towards multilateral instruments.
This experience confirms the importance of keeping open the debate on the progressive development of the international legal framework, including the possibility of drafting international legally binding instruments that enable us to respond to emerging challenges in this area.
Madam Chair, For developing countries, this process must be coupled with effective international cooperation, capacity building, and technology transfer that enable everyone to participate in equal conditions in the debate on and drafting of international law.
National capacities are limited, including by UCMs that widen the digital gap and affect the right to development of our peoples.
Nicaragua reiterates its commitment to a balanced mechanism focused on concrete results that promotes the peaceful use of ICTs.
Thank you very much, Madam Chair.
Thank you very much.
I keep the floor now to Algeria.
Thank you, Madam Chair.
Algeria aligns itself with the statement delivered earlier by Nigeria on behalf of the African group and wishes to express the following points to share its views on the applicability of international law to cyberspace, a matter of fundamental importance for our collective security and stability.
First, Algeria fully endorses the common position of the African Union on the application of international law and the use of ICTs.
This common position is grounded in clear principles of international law which form the basis of our engagement in the global mechanism.
In this regard, Algeria reaffirms that international law, along with the purposes and principles enshrined in the United Nations Charter, apply fully in cyberspace.
State sovereignty, the principles of non interference in internal affairs, non intervention govern the conduct of states in the cyber domain.
The prohibition of the threat or use of force also fully applies to cyberspace.
Both international humanitarian law and international human rights law apply offline and online.
And the rules of state responsibility and due diligence are fully applicable in this context.
Second, Algeria emphasizes that developing countries face unique challenges in meeting their obligation in the applicability of international law in the use of ICTs due to resource constraints and technical gaps.
Algeria calls for enhanced international cooperation and concrete capacity building measures.
Grounded in state sovereignty, national ownership, and respect for national identified priorities.
The legal framework and the development dimension are inseparable since the effective application of international law in cyberspace requires that all states have the capacity needed to implement their obligations meaningfully and equitably.
Third, on the question of the elaboration of a legally binding international instruments, Algeria supports the elaboration of such an instrument.
While discussions on how existing international law applies to cyberspace remain of paramount importance, we should now move towards a more focused and practical stage, collectively negotiating how states must behave in cyberspace.
Of course, building on the existing relevant United Nations framework.
Unique attributes of cyberspace, particularly the speed and sophistication of attacks, the difficulty of attribution, the vulnerability of critical infrastructure, and the evolving nature of cyber threats demand legal clarity and certainty, not interpretative ambiguity.
Furthermore, a legally binding international instrument would provide this global mechanism with institutional vitality, direction, and the ability to translate decades of productive discussions into meaningful and action oriented outcomes.
The technicity and the complexity of cyberspace, alongside time consuming elaboration of legally binding instruments are without any doubt conditions to be taken into consideration, but they are certainly not insurmountable obstacles.
The international community has a longstanding experience and practice in codifying norms and customary law into legally binding international instruments.
This is why since we have successfully and collectively agreed on 11 non binding norms, we should certainly be able to elaborate legally binding rules.
I thank you Madam Chair.
Thank you very much.
I now give the floor to the African Union.
Thank you, Madam Chair.
The Afghan Union aligned itself with the statement of the Afghan group and welcomes the opportunity to contribute to discussions on the applicability of international law in the use of ICTs.
The EU's engagement on this issue is guided by the common African position on the application of international law to the use of ICs in cyberspace, which represents an important milestone in strengthening Africa's collective voice on international cyber policy.
The common African position provides a shared foundation for EU member states to engage constructively in global discussions while recognizing that member states may continue to develop and articulate their own national legal positions.
We are encouraged to see that this work is increasingly reflected at the national levels.
Some EU member states are already starting to develop their own national positions.
These developments demonstrate that EU member states are making meaningful contributions to the evolution of state practice and the clarification of how international law applies in cyberspace.
Recognizing that many member states continue to seek technical and legal expertise in this area, the EU has also promoted capacity building.
The EU Commission convened a workshop from first to third June 20, 26 in Adis Ababa to strengthen capacity of EU member states to develop national positions on the application of international law to cyberspace.
The workshop reflected the growing demand among EU member states for practical support in understanding international law, engaging in legal analysis, and translating global consensus into national policy.
Madam Chair, these experiences demonstrate that capacity building is not only about strengthening technical capacity, but it is also including building legal, diplomatic, and institutional expertise to enable all member states to participate effectively and on an equal footing in the development and implementation of international law in cyberspace.
In this regard, the EU considers that capacity building on the applicability of international law to be an important area of work for global mechanism, including within the dedicated thematic groups, which we contribute to a more inclusive, informed, and representative global discussions.
To conclude, Madam Chair, the EU remains committed to working with regional organizations and international partners to strengthen shared understanding of international law in cyberspace and to ensure that all member states have the capacity to participate meaningfully in shaping a secure, stable, accessible, and peaceful ICT environment.
I thank you, Madam Chair.
Musa.
Thank you very much.
I now give the floor to the ICRC.
President, Distinguished delegates, the ICRC is grateful for the opportunity to address the global mechanism on the issue of how international law applies to the use of ICTs.
As highlighted by many delegations, the use of ICTs by states and non state actors is a reality in many of today's armed conflicts.
Against this background, the ICRC would like to emphasize three key points on international law.
First, when ICT capabilities are used for military purposes in situations of armed conflicts, their use must comply with the existing rules of IHL.
Many delegations have stressed this point in their statements today, as well as the national and regional positions on how international law applies to the use of ICTs.
Importantly, in October 2024, the 34th International Conference of the Red Cross and Red Crescent, which brought together all states It adopted a resolution on ICT activities during armed conflict, which affirms that and I quote, in situations of armed conflict, IHL rules and principles serve to protect civilian populations and other protected persons and objects, including against the risks arising from ICT activities.
This should be the starting point for further discussions in this global mechanism, while recognizing that nothing in IHL can be construed as legitimizing or authorizing any act of aggression or any other use of force inconsistent with the charter of the UN.
Building on this achy, the ICRC urges states to focus discussions on fostering common understanding on how international humanitarian law applies to the use of ICTs by states.
As highlighted in our statement on threats yesterday, contemporary armed conflicts show that military ICT activities pose risks to civilian populations, to civilian infrastructure, and to civilian data.
While shared understanding on the limits that IHL imposes on the use of ICTs are emerging, for instance, on the obligation to respect and protect medical services, states have recognized that certain questions require further discussion.
This respect, the ICRC calls on states to focus especially on the limits that IHL imposes on ICT activities that result in non physical damage.
Because in today's ICT reliant societies, it is critical to protect the ICT systems that underpin civilian life in societies as well as digital data against damage and destruction.
This respect and as mentioned also by the joint statement delivered by Switzerland earlier, we invite you to build on the in depth discussions held by over 100 states and other stakeholders under the ICT workstream of the global initiative to galvanize political commitment to international humanitarian law and to consider its forthcoming outcome document on upholding international humanitarian law in the use of ICTs during armed conflicts.
Document provides guidance to facilitate the implementation of IHL obligations in a manner consistent with the protective purpose of IHL.
Third, with conflict dynamics and technology evolving at great speed, ICSC calls on states to focus parts of the dedicated thematic groups to how international law addresses some of these new developments and technologies.
This includes, for instance, identifying legal and practical measures to implement the international law rules that prohibit child recruitment and use in hostilities.
Agreeing on practical measures that states must take to prevent civilian hackers from committing IHL violations through ICT activities.
Building shared understanding on the risks that arise when ICT infrastructure such as civilian data centers are used for military purposes and identify practical measures to protect civilian ICT infrastructure from the dangers of hostilities.
In addition, as we have heard by several delegations, the use of artificial intelligence in ICT activities may increase the speed, scale, and potential for harm.
While IHL applies to ICT operations in armed conflict, including those that involve the use of AI, or other emerging technologies, the ICRC calls on member states to consider whether existing international law provides sufficient safeguards against the harm that increasingly autonomous ICT capabilities can cause or whether additional limits are needed.
We thank you for your attention.
Thank you very much.
We've just heard our last speaker under this agenda item.
I thank all of the delegations for this very substantial exchange on international law and like I did for other agenda items that we've dealt with, I'd just like to give you a brief recap and some feedback on what we've just heard.
I thank you all for your statements not only on a national level, but also for your joint statements made on behalf of groups.
I encourage you to engage in these interregional efforts as we engage in these discussion, especially given the limited capacity of small delegations who find it difficult to participate across the process.
Now, without attempting to be exhaustive rather, I'd like to give you a brief summary of what we've just heard.
The majority of the delegations underscored that the global mechanism must continue to encourage the discussions that were begun during the first open ended working group.
On the way that international law is applicable to ICTs.
Furthermore, it was reaffirmed that the development of a common understanding is fundamental if we are to establish a safe, stable, and predictable digital environment.
Some delegations stated that it was still necessary to continue to explore and discuss fundamental legal concepts, including and I'm just mentioning some of them, mentioned in the room, sovereignty, non interference, the peaceful settlements of disputes, the responsibility of states for internationally illicit acts, international humanitarian law, and international human rights law, among others.
I thank the delegations that shared their good practices.
On the elaboration of their national positions on the way to interpret the applicability of international law in cyberspace, as well as the update on previously updated positions.
Finally, delegations underscored that these legal debates must be accessible to all states and that capacity building and technical cooperation based on scenarios are fundamental.
Furthermore, they underscored that these can support the work undertaken by states to develop national perspectives without losing sight of regional efforts.
I'd encourage you to continue your efforts to support capacity building to facilitate these regional exchanges, and also to promote dialogue between the different legal and technical communities to foster an exchange of specialized knowledge.
Thank you very much.
Right now, we will begin the agenda item on developing and implementing confidence building measures.
You're welcome to press the microphone button to indicate your interest in taking the floor.
I would like to make an announcement also in terms of housekeeping, that the interpreters would be very grateful if you could send your statements to e statements before you deliver your statement on the floor as far as possible.
Thank you very much.
Now, just like I mentioned, there's no established time limit for your statements.
However, I would be very grateful if you could kindly consider delivering a much shorter abridged version of your statement and you can send the full version of your statements to the Secretariat and to the chairs team.
This way, we can hear from all delegations.
Just for reference, we're going to continue to use the countdown clock that will remain visible on the screens.
If any of you would like to take the floor on behalf of a group of states, Please approach the Secretariat so that we can correctly reflect that on the list of speakers.
Finally, we'd be very grateful if you could also take this moment to reflect your interest in taking the floor because it's getting close to 5:00 P.M.
And it's very likely we'll be continuing this agenda item tomorrow.
We need to have the full list of speakers.
We need to have the full list of all of those who want to state the floor on this agenda item this afternoon.
Thank you.
Now, I give the floor to the delegation of the Dominican Republic, who will be speaking on behalf of a group of states.
Thank you, Madam Chairman and a very good afternoon.
Behalf of the open informal cross regional group of the global Mechanism Comfist Builders.
Over the years, we have grown into one of the biggest cross regional groups now comprising the following states, Argentina, Australia, Brazil, Canada, Chile, Colombia, Czech Republic, Fiji, Germany, Israel, Republic of Korea, Mexico, the Kingdom of the Netherlands, Singapore, Uruguay, and my own, the Dominican Republic.
We welcome the adoption of and reaffirm our commitment to the eight voluntary global confidence building measures adopted by the previous open ended working group.
These measures constitute a fundamental pillar of the framework for responsible state behavior in cyberspace.
The establishment of the global mechanism now provides an important opportunity to move progressively from their endorsement towards their practical and inclusive operationalization and implementation.
As a group, we recognize that the global mechanisms, plenary sessions and the meetings of the dedicated thematic working groups, DTGs with their modalities in accordance with Annex one of the final report of the 2021 2025 OEWG could provide complementary, but distinct ways for states to identify areas of convergence and needs for further discussions in the area of CBM implementation.
Discussions of the CBMs cannot be had in isolation.
It is our view that capacity building and international cooperation are essential to enabling all states, particularly developing countries, to participate meaningfully in the implementation of global CBMs.
In addition, the CBMs can support the implementation of the different pillars of the framework by strengthening communication, facilitating cooperation, increasing transparency, and helping states prevent and manage risks associated with ICT incidents.
We see the DTGs as playing a particularly important role in facilitating cross cutting, integrated and policy oriented discussions on commonly shared challenges and identifying these synergies across pillars.
To this end, this group is currently preparing a working paper ahead of the December session in which we will highlight the practical value of CBMs in addressing specific policy challenges.
Drawing on implementation experience at the regional and sub regional levels.
The paper will present best practices and offer a comparative perspective on how CBMs are operationalized in practice.
On this basis, it seeks to provide guidance on how CBMs can be integrated in DTG discussions on specific challenges, including by drawing on contributions from stakeholders in accordance with Annex one of the final report of the 2021, 2025 OEWG.
The paper is expected to be ready ahead of the December session and will be uploaded to the website accordingly.
To close, this group looks forward to working with you, Madam Chair, on advancing the implementation of this pillar of the framework in a constructive, inclusive and practical way.
Thank you, Madam Chair.
Thank you very much.
I give the floor to Tonga, speaking on behalf of the Forum of Pacific Island States.
Thank you, Chair.
I have the honor to deliver this statement on behalf of the members of the Pacific Islands Forum with a presence at the United Nations, namely Australia, the Cook Islands, Fiji, Cori Bus, the Federated States of Micronesia, the Republic of the Marshall Islands, Nero, New Zealand, Palau, Papua New Guinea, Samoa, Solomon Islands, Tuvalu, Vanuatu, and my own country, Tonga.
Chair, CPMs are particularly important for regions and states with limited capacity.
They help build trust, reduce the risk of misperception and escalation, and create channels that can be used before, during, and after cyber incidents.
For the Pacific regional level CBMs, such as the Pacific Cybersecurity Operational Network, are especially valuable, including side to side cooperation, national and regional exercises, practical incident communication procedures, and opportunities for officials and technical experts to build relationships before a crisis occurs.
As with norms, our focus at this stage is the implementation of the existing CBMs.
We need support to make the agreed CBMs operational in national and regional context.
This requires capacity building, technical assistance, guidance, exercises, and sustained engagement.
The global mechanism should help states use the CBMs, not simply continue to describe them.
The Pacific commends the successful operationalization of the global points of contact, POC directory.
To remain effective, it is important that this directory is actively maintained, strengthened, and made genuinely useful in practice under the global mechanism, including through regular communication checks and continued support for those states that still completing their nominations.
Confidence building play a critical role in building trust, and they matter most in regions such as ours with limited capacity.
For a network of this kind to build trust rather than strain it, it must be used in good faith.
We will welcome a shared understanding that the POC network be used proportionately, purposefully, and with due regard for the capacity constraints of smaller states.
Used in that spirit, the directory remains among the most valuable confidence building tools available to us.
Thank you, Chair.
Thank you very much to Tonga.
I now give the floor to the European Union, who will be followed by the following countries, the Republic of Korea, Costa Rica, Albania, Italy, Kurbas, and the United Kingdom.
The EU, please.
Chair, colleagues.
I have the honor to speak on behalf of the EU and its member states.
The candidate countries Turkea, North Macedonia, Montenegro, Serbia, Albania, Ukraine, the Republic of Moldova, Bosnia, Herzegovina, and Georgia, and the EFA country Norway, member of the European economic area, as well as San Marino aligned themselves with this statement.
Building trust and confidence is a long term progressive commitment that requires a sustained and genuine engagement of states.
Under the Open Net working group, we have made significant progress in launching concrete initiatives to contribute to this, including the agreement of eight confidence building measures.
The measures agreed upon under the Openet working group, but also those at regional level are crucial for deepening common understandings, prevent misunderstandings, reducing the risk of misperception and escalation, and increasing the predictability of state behavior, which ultimately will contribute to greater stability in cyberspace.
The work on confidence building measures under the global mechanism should therefore, as a priority, focus on the operationalization of the voluntary non exhaustive list of CBMs as agreed under the Op Ed working group.
Efforts should aim to encourage active participation by states as well as to complement the work of regional organizations, notably the OSEE, OAS, ARF, and ECOWAS.
In this regard, the global mechanism should initially focus on raising awareness and elaborating on the existing confidence building measures, both at global and regional level, as well as to provide states and regional groups with practical tools, best practices, and examples to translate the CBNs into our national legislation, policies, and mechanisms.
In this context, we welcome simulation exercises that could support the identification of practical measures in this context.
The ENS member states affirmed the value of the POC directory as a CBM and as a tool to provide states with direct means of contact in situations where they do not have these means already existing.
The global POC directory could facilitate engagement between states in case of cyber incidents when dealing with a lack of understanding on whom to reach out to.
In this way, the POC directory could provide a complementary tool to member states incident response in cases where they do not have these contexts already, or they don't already have existing relationships on cybersecurity matters.
To further develop the directory, the EU and its member states initially support the integration of the directory into the GSCCP, the portal that we agreed upon under the Openet working group, which could support cooperation and communication under the global mechanism.
We're also open to exploring further development of the directory, however, based on lessons learned from its use.
We consider it important, however, to avoid duplication of efforts with existing networks of POCs and with existing regional and bilateral relations.
We stress that the POC directory is a tool that can be useful when other means are lacking, but which should not replace existing cooperation efforts or established means of contact between states.
In addition to the voluntary POC directory, the EU and its member states support the operationalization of the other eight CBMs, and the plenary and the DDGs could facilitate this work.
For instance, by sharing national ICT strategies, policies, legislation, concept papers, best practices on a voluntary basis under DDG one in line with CBM three, and in our exchanges on protection of critical infrastructure in line with CBM seven.
We could also promote the information exchange on cooperation and partnerships between states to strengthen ICT security capacity and enable CBM implementation, which is in line with CBM five.
And intersectionally and in the margins of our sessions, as well as part of our capacity building efforts and we could organize regular seminars, workshops and training programs on ICT security in line with CBM six.
The global mechanism discussions will enable us to take forward the achievements on the CBMs under the Op Ed working group, further outlining their value in preventing cyber incidents and in building trust, transparency, and stability in cyberspace.
We can also incorporate them into our regional and national practices as complementary tools to the application of international law and norms of responsible state behavior in cyberspace and we look forward to working with you on this.
Thank you very much.
Thank you very much.
I yield the floor now to the Republic of Korea.
Thank you, Madam Chair.
As technology continues to advance, cyber threats are growing in both scale and sophistication and such threats have the potential to undermine trust among states.
In this context, confidence building measures are essential to enhance predictability and stability in cyberspace and to prevent misunderstanding and miscalculation among states.
Strengthening confidence building measures at the international level is also indispensable to enhancing resilience in cyberspace.
Just as the open ended working group itself served as an important confidence building measure by fostering dialogue and transparency amongst states, we expect the global mechanism to play a similar role in promoting trust, transparency, and sustained cooperation.
The Republic of Korea believes that establishment of the UN Global mechanism point of contact directory to be one of the most significant achievements of the OAWG.
The directory has the potential to strengthen confidence among states by facilitating timely and effective communication during cyber incidents and crisis.
We therefore look forward to the continued operation of the PUC directory, including regular exercise and capacity building activities under the global mechanism.
At the same time, UN POC directory is intended to be used on a voluntary basis by member states and should not be misused or exploited for purposes inconsistent with its original intent.
The POC directory should be used responsibly and in good faith, consistent with its purpose of facilitating cooperation and effective communication among member states.
Additionally, we reaffirm our strong support for the joint statement delivered by Dominican Republic.
The Republic of Korea looks forward to actively participating in these efforts to further strengthen discussions on confidence building measures under the global mechanism.
In particular, we believe the experiences and the best practices of regional organizations that have successfully implemented confidence building measures can provide valuable guidance for developing effective confidence building measures at the global level as well.
I thank you.
Thank you very much.
I now give the floor to the delegation of Costa Rica, followed by Albania.
Madam Chair, Costa Rica considers confidence building measures to be an essential element of stability in cyberspace, not only because they reduce the risk of escalation in conflicts between states, but also because they foster cooperation among them.
First, confidence building measures should be understood as practical preventive tools achieved through the creation of known, accessible, and functional communication channels prior to the onset of a crisis.
To this end, Costa Rica supports the voluntary exchange of information, communication protocols for incidents, and regional exercises and simulations that strengthen collective preparedness.
Second, Costa Rica highlights the utility of the global directory at points of contact.
This instrument is a valuable operational tool for facilitating urgent communication, managing cross border incidents, reducing misunderstandings and preventing escalation in the event of conflict.
To fulfill this function, it must be kept up to date, tested periodically, and integrated with actual national capabilities, including computer security incident response teams, competent authorities, diplomatic channels, and regional mechanisms.
Third, Legal transparency also serves as a confidence building measure.
National positions regarding international law in cyberspace provide insight into how states interpret principles such as sovereignty, non intervention, due diligence, attribution, the use of force, international humanitarian law, and human rights.
By publishing its national position on the application of international law in cyberspace, Costa Rica states its conviction that this type of transparency helps reduce uncertainty, strengthen shared expectations, and facilitate dialogue among states.
Finally, building trust in cyberspace requires linking law, technology, and diplomacy.
Attribution, evidence, incidents, response and crisis communication are simultaneously legal, technical, and political matters.
Therefore, the global mechanism must promote forums for exchange among diplomats, legal advisors, technical experts, CSIRTs, the private sector, the technical community, academia, and civil society.
Madam Chair, Costa Rica hopes that this mechanism will foster concrete, inclusive and results oriented confidence building measures.
Greater communication, transparency and cooperation mean reduced risks in cyberspace, enhanced security for people and essential services, and greater international stability.
I thank you.
Thank you.
I give the floor now to Albania, who will be followed by Italy.
Thank you, Madam Chair.
Albania aligns itself with the EU statement on this am and wishes to add the following on its national capacity.
As a country which continues to face persistent malicious cyber activities against its critical infrastructure, we know firsthand that trust between countries and state built through practical cooperation is what determines how quickly and effectively we can respond when an incident occurs.
Confidence building measures remain for Albania, one of the most concrete and immediate useful outcomes of this process.
Albania's approach to CBMs rests on cooperation across several layers, political, diplomatic, and technical through the UN, European Union, OSCE, ITU, Western Balkan, first trusted introducer and numerous other countries organizations which we work on bilteral relations, each of those cooperation reinforcing each other.
At the United Nations level, Albania has appointed its point of contact at the global point of contact directory and continues to support its further or personalization as a practical tool that turns confidence into concrete communication channel in time of crisis.
We also value highly the woman in cyber Fellowship, which we consider a confidence building measures in itself, having brought valuable perspectives and a more resilient cyberspace.
With the support of the Netherlands, Germany, previously from the United States, we have been present and part of these discussions in the UN since 2022, and now at the global mechanism, we are present with a bigger delegation, diplomatic and technical.
Participation on those meetings have not only increased our confidence and understanding on the cyberspace, but we understood that Albania has taken the necessary steps forward in cybersecurity, learn from experience of other countries, but also given contribution to share our own experiences.
With the European Union, Albania as a candidate country for membership is progressively aligning with the EU cybersecurity arche, including through the transposion of all the NIS two Directive into national laws, sub laws, and numerous procedures and benefiting from the EU support programs, then strengthen operational cooperation and information sharing among Western Balkan cybersecurity, diplomatic and technical bodies.
Through the OSC, Albania actively participate the informal working group on cyber CBMs, regularly reporting and implementation of CBM eight and 15, working particularly on the protection of critical information infrastructure and the exchange of national point of contact.
With ITU, Albania engages in joint project training dialogues that strengthen collective security while using many resources of ITU in cooperating with other countries.
At the regional level, Albania has invested significantly in building trust among Western Balkan states and beyond.
This includes initiatives such the Adriatic five meetings, the Western Balkans Policy Roundtable supported from the Dutch government, the Western Balkans Cyber Dialogue supported from DCAv, technical workshops supported by UNDP, and numerous training and conferences organized with the WB three centers.
Albania has on launched programs such as Western Balkan cyber camps, alumni events for participants, and it's preparing for the next regional cyber marathon now under development.
These projects bring together young cyber professionals from across the region and help build the professional and institutional relationship on which CBMs ultimately depend.
Albania also seek new and less conventional partnership because we believe that international relations always leave room for deeper cooperation and confidence building.
For example, just yesterday, we became as the newest member of the International Coalition on cybersecurity workforce, joining United Kingdom, Canada, United Arab Emirates, Ghana, Japan, Singapore, and Nigeria.
For Albania, these different frameworks are not parallel tracks but are single one, mutually reinforcing all the efforts we're doing in cybersecurity.
Cooperation with all those frameworks together with our regional partnership have directly strengthened our national capacities.
And it is this increase of capacities that in turn allow us to be more reliable and predictable partner for the others.
This is, in Albania's view exactly how confidence building is meant to work.
Cooperation building capacity, capacity building trust, and trust build still back cooperation among the countries.
Albania therefore reiterates its support for the integration of CBMs across the work of the global mechanism and stands ready to share its national experience with the other states, particularly on the operationalization of points of contact, information sharing arrangements, and joint training and exercises.
At the end of the day, it's important to know who do we call, who we trust, and where we turn for the support in a moment of difficulty when we have a big cyberattack.
This is why confidence building sustained through cooperation at every level, global, regional, bilateral remains for Albania central to a more stable, secure, and predictable cyberspace.
Thank you, Madam Chair.
Thank you very much.
I give the floor to the delegation of Italy, followed by Kirbas, the United Kingdom, Papua, New Guinea, Canada, Serbia, South Africa, Italy, please.
Italy fully aligns itself with the statement delivered by the European Union and wishes to add few considerations from its national perspective, also benefiting from contributions of the four stakeholders objected by the Russian Federation.
In an environment where cyber threats increasingly transcend national borders, CBM remains essential tool to strengthen trust transparency and cooperation among states.
Reducing risks of misunderstanding contribute to preventing escalation and supporting stability in the use of ICTs.
The initial list of voluntary global confidence building measures contained in Annex B to the third OEWG annual Progress Report was a very useful tool and we hope that this global mechanism will take that into consideration for its future works.
Regarding the implementation of the UN confidence building measures, I would like to briefly share that Italy has nominated since the very beginning its POCs for the global directory.
We keep exchanging views on ICT matters at bilateral and multilateral level.
We regularly share concept papers, national strategies, policies and programs, as well as information on ICT institutions and structures, for example, through advisories, alerts, reports of our national cybersecurity agency.
We promote and support capacity building projects, we organize workshops and seminars with a whole society approach.
We contribute to the EU policies regarding the protection of critical infrastructure and critical information infrastructure.
We actively promote opportunities for public private partnership at national and multilateral level.
But more work has to be done and we are committed to continue on this path.
We also would like to emphasize the particular importance of regional confidence building measures, for instance, those developed by the OSCE, which we regard as highly effective.
Among the others, Italy actively contributes to CBM eight on points of contact and CBM 14 fostering public private partnerships to address shared cybersecurity challenges.
Italy underscores the private sector's pivotal role in enhancing resilience and addressing multifaceted cyber threats.
We recognize the importance of cross regional collaboration to enhance CBMs.
By integrating lessons learned from diverse frameworks and sharing experiences, Italy is committed to contribute to a more adaptable and comprehensive approach to trust building in cyberspace.
Existing experiences demonstrate the value of multinational cyber exercises, cyber ranges, crisis management simulations, and structured information sharing mechanisms involving governments, critical infrastructure operators, industry, academia, and research organizations.
Developing common operational playbooks and trusted networks before crises occur can strengthen collective preparedness and coordinated response capabilities.
The active involvement of technical stakeholders in all these activities and exchanges can significantly enhance the effectiveness of these measures by providing practical expertise and facilitating cooperation across sectors.
This is why once again, DTGs can play a crucial role also in this area.
DTG one can discuss how to apply CBMs in a specific situation or scenario, whereas DTG two can craft tailored projects to build capacity.
Italy always stands ready to share its experiences, lessons learned and proposals in implementing CBMs.
Thank you.
Thank you very much.
I'll give the floor now to the delegation of Kirbas.
Thank you, Madam Chair.
Ribas aligns up with a statement delivered by the Kingdom of Donna on behalf of the Pacific Islands forum members and adds the following in its national capacity.
Madam Chair, if this first session is to set a pattern for all that follow, confidence building is where this mechanism can show its values unit.
For small island developing states like ribs, CBMs are among the most immediately practical elements of the framework of responsible state behavior.
We do not maintain extensive networks of bilateral channels or cyber attaches.
Predictable trusted mechanisms for communication between states are for us, not a convenience.
They are the difference between facing an incident alone and facing it with help.
For this reason, Gibas attaches great importance to the global points of contact directory.
We commend the Secretariat and UN ODA for its establishment and operationalization, and Gubaas is working to finalize its own participation.
We encourage continued practical support for its use so that the directory works as intended in the real incident and not only on paper.
We would gently encourage all states to use the network in the cooperative incident related spirit for which it was designed, mindful that for a small administration, every message received draws on the same small team that defends our networks.
We were encouraged to hear earlier this week offers of assistance extended to states such as ours.
We value such offers greatly.
They are a reminder of what these gatherings are truly for.
This plenary is not only where we discuss confidence building in the abstract.
It is where confidence is built, where a small states like Kibus can meet the partners, it may one day need to call upon and where offers of assistance are made and remembered.
For state like ours, that is among the most valuable things this mechanism can offer.
Madam Chair, the Pacific experience is that confidence is built through practice, not declarations.
Our region has been doing this work for years through the Pacific Cybersecurity operational Network, Paxson, our response shared threat information and build the personal trust on which crisis communication ultimately depends.
Ibis was proud to host a recent Paxon gathering, bringing our region's cybersecurity professionals together to train, share, and strengthen the relationships that make cooperation work when an incident strikes.
Through cyber saafety Pacifica and other regional programs, our law enforcement agencies cooperate daily.
Under the Boyer Declaration, Pacific Islands forum members have recognized cybersecurity within our expanded concept of security, giving regional political packing to this practical collaboration.
We draw two lessons from this experience that we believe are relevant globally.
First, CBMs succeed when they are simple, sustained, and relationship based.
Their ambition should be measured in reliability, not in the number of measures adopted.
Second, regional organizations are not merely implementers of globally agreed CBMs, they are laboratories for them.
This mechanism should draw systematically on regional experience, including through regular exchanges with regional parties and should help connect regional networks such as Paxton with their counterparts in other regions so that what works in one part of the world does not have to be discovered anew in every other.
Ribus therefore encourages the mechanism to keep its works on CBMs firmly practical, strengthening the directory, supporting exercises, and communication checks, ensuring designated points of contact receive the training their role demands, and enabling hybrid participation so that officials from Capitols distance at Tarawa in ribas can take part meaningfully.
Confidence, Madam Chair, is our region's currency.
This first session, let us begin to invest it in this mechanism and to return it in return.
I thank you Madam Chair.
Ms Thank you very much, Kibas.
I now give the floor to the United Kingdom, followed by Papua New Guinea.
Thank you, Chair.
The United Kingdom supports the identification of concrete action oriented ways to implement the UN framework on responsible state behavior in cyberspace, including through confidence building measures.
As recognized in previous consensus reports, confidence building measures can contribute to preventing conflicts, avoiding misperception and misunderstandings, and the reduction of tensions.
The UN point of contact directory is a positive, practical example of a CBM emerging from the 2021 to 2025 OEWG as QRS has just outlined so clearly.
According to OEWG and GG Consensus reports, the directory's purpose is to provide a way to facilitate secure and direct communications between states to prevent and address serious ICT incidents through a network of points of contact that could be reached in times of urgency.
It complements a range of formal and informal networks that exist to share information on cyber incidents.
If a state detects malicious cyber activity emerging from another state, they may choose to use the POC directory or other networks if they feel this will help to address the incident.
Equally, they may decide that using the POC directory is not an appropriate response if it is clear that the malicious cyber activity is part of a deliberate state sponsored campaign.
The existence of the POC directory doesn't alter a state's right to attribute irresponsible cyber behavior to another state if they wish to do so.
Thank you, Chair.
Thank you very much.
I give the floor now to Papua New Guinea, followed by Canada and Serbia.
Madam Chair, Excellencies and distinguished delegates, at the outset, Papua Nwinea congratulates Madam Chair and your distinguished delegation of El Salvador on your important mandate and for the laudable leadership in guiding this process.
This comes immediately on the heels of the recently highly successful and landmark inaugural global AI governance dialogue in Geneva, whose process, Madam Chair, you so ably also co chaired with the distinguished delegation of Estonia.
Be rest assured of Papua Nwuine's trust and confidence in you, Madam Chair, and also our constructive support and best wishes.
Let me also take this opportunity to pay special tribute to the distinguished delegation of Singapore for the sting role and leadership in setting the stage through the OEWG process that has brought us to this stage.
Madam Chair, Papua New Guinea agned with a statement delivered on behalf of the Pacific Islands Forum by the Distinguished delegation of Tonga and we would like to make additional points in our national capacity.
The welcome, robust exchanges so far in this meeting is a clear statement to the high importance we all place on this critical agenda.
For Papua Ne Guinea, information and communication technology is one of the 12 core national development strategic priorities under our current medium term development plan for.
This week in Papua New Guinea, leaders from government, industry, international partners have convened for the Pacific Regional Digital Transformation Summit and the Pacific Cyber Week to consider how digital technologies are shaping our shared future.
We recognize a fundamental and clear message in this domain.
That is, digital transformation can only succeed when people, governments, businesses, and other stakeholders have confidence and trust that the digital environment is safe, secure, and reliable.
As Papua New Guinea recently highlighted during the global dialogue on AI governance, digital technologies must remain human centered and serve as an enabler of sustainable development.
Building trust and confidence in cyberspace is therefore fundamental to ensuring that all countries can harness the opportunities of digital transformation while safeguarding international peace and security.
For us, such confidence is built through trusted relationships, open communication, and practical cooperation.
It also depends on countries having the capacity to prevent, detect, and respond to cyber incidents, protect critical infrastructure, and maintain essential services during times of disruption.
Madam Chair, Papua New Guinea believes that global mechanism should help countries strengthen the core capabilities needed to manage cyber risk This includes strengthening cyber hygiene, national incident response, C certs and certs, legal and policy frameworks, and the skills required by officials, technical experts, regulators, law enforcement agencies, and critical infrastructure operators.
These practical investments strengthens resilience and deepen trust between states.
Importantly, in our view, capacity building for this sector is critical.
It should be demand driven, nationally owned, and responsive to each country's level of digital maturity.
For developing countries, particularly small island developing states, including my own country, Papua New Guinea, strengthening institutional and technical capacities remains pivotal to implementing the agreed framework for responsible state behavior in cyberspace.
Confidence building measures should likewise produce practical outcomes.
Regular communication between national point of contact, timely information sharing, joint cyber exercises, technical cooperation, and the exchange of lessons learned can help countries prepare for cyber incidents before they occur.
This partnership build trust, reduce misunderstandings and strengthen regional and international cooperation.
Madam Chair, the Pacific Regional discussion taking place this week in Papua New Guinea also remind us that cybersecurity is not only a technical method.
It is a foundation for economic growth, digital trade, investment, innovation, and public confidence in digital services.
As more countries expand digital government and digital economies, strengthening cyber resilience becomes a shared responsibility.
The rapid advancement of emerging technologies, including AI further reinforces the importance of resilient cyber ecosystem and international cooperation that must keep pace with technological change.
We must ensure that technological progress narrows, not widens the digital divide, enabling all states to participate safely, securely, and meaningfully in the global digital economy.
In this context, Papua New Guinea would like to acknowledge the support of its development partners such as Unir and the delegation of Australia for the continuing gender sensitive capacity building support, including this meeting for our representatives participation and that of other female representation in the Pacific region.
This is of added value and most welcome with gratitude.
Papua New Guinea believes partnership in the ICT domain must be based on respect for international law and each country's national sovereignty and territorial integrity.
Madam Chair, to conclude, we encourage the global mechanism and its dedicated the groups to remain focused on implementation.
Success should be measured by concrete progress.
Stronger national systems, more effective international partnership and cooperation between countries and targeted support that enable all states, particularly developing countries and small island states to shape, own and drive the national engagement in the digital domain in a safe, secure and trustworthy environment.
Papua New Guinea is committed to do its part in implementing the UN framework for responsible state behavior in cyberspace, including its five pillars.
Thank you.
Thank you very much.
I now give the floor to Canada, followed by Serbia and South Africa.
Madam President.
Thank you, Madam Chair.
As mentioned earlier this week we recall we recently published the responses of Canada to the survey managed by Unidir on implementation of norms, international law, confidence building measures, and capacity building.
This is an example of the concrete practice of the CBM three on information sharing which is increasing today.
The survey is available on the website of Canada within the Unidir cyber Portal.
I make this information public and easily accessible.
Canada is demonstrating transparency with regard to certain practices that could inspire others.
Madam Chair, we take note of the efforts of Secretariat to build up the capacity of states to use the global contact points directory.
The directory has the main goal of facilitating communication during significant or urgent incidents, and this is laid out in its mandate as reflected in paragraph five of Annex A of the annual report 2022.
Canada welcomed the information session on the global Directory reorganized by the Secretariat on June 26th.
We support the holding of a second simulation exercise in the fall, which will help to reduce the risk of misunderstanding or escalation during significant or urgent incidents.
In addition, and to give you an example of the practice of other CBMs, we note that Canada is organizing and takes part in seminars, webinars, and side events as planned for CBM six.
For example, since March alone, Canada has taken part in a webinar organized by Let's Talk Cyber on the outcomes of the OEWG and the future of the GMAC, a webinar organized by EU Cyber Drect on trans regional collaboration of stakeholders.
The Cyber Diplomacy School of Talent, as well as the Unear Conference on cyber stability.
Madam Chair, allow me to speak for a moment about soccer or football as it's called in the rest of the world.
Another practice of operationalizing the CPMs would be exercises involving simulation or rather tabletop exercises.
As one of the host countries of the FIFA World Cup, we organized these tabletop exercises with cities that were hosting matches as well as critical infrastructure operators.
We also collaborated with Mexico, Mexican, and US certs by helping to coordinate relevant information sharing.
These are the practices that we can talk about during the DTGs that will take place in December.
Confidence building measures are a bit like sportsmanship in soccer.
They foster healthy communication between players playing in good faith, whether they come from cyber agencies, Ministries of Foreign Affairs, or non governmental stakeholders.
Thank you, Madam Chair.
Thank you very much.
I give the floor to the delegation of Serbia.
Thank you, Madam Chair.
Republic of Serbia aligned itself with the EU statement.
Allow me to add just a few remarks from the national perspective.
In an environment of heightened tension, confidence building measures are among the most valuable instruments at our disposal.
Practical, voluntary, non politicized tools that enhance transparency and predictability and reduce the risk that an ICT incident is misperceived and escalates.
CBMs allow states with different perspectives to cooperate directly.
Serbia sees this area as one where the mechanism can deliver visible results quickly.
Serbia welcomes the operationalization of the global points of contact directory as a concrete universal confidence building measure.
We designated both diplomatic and technical point of contact, and we believe that regular communication checks, pings exercises, and scenario based simulation exercises will keep the directory alt and genuinely useful in a crisis.
Serbia also draws on its regional experience.
As a participating state of the OSCE, we are actively contributed to the development and implementation of the cyber ICT security confidence building measures, including by sponsoring CBM nine on national terminologies and definitions in the field of information security.
This experience demonstrates the value of practical cooperation aimed at improving mutual understanding and reducing the risk of misunderstandings among states.
I thank you.
Thank you very much.
I give the floor to the delegation of South Africa, who will be followed by Singapore, Nauru, Switzerland, Vanuatu, and Chile, South Africa, please.
Thank you, Chairperson.
We recognize that the adoption of the third annual progress report of the previous open ended working group in which member states agreed to establish this global mechanism on security of and in the use of information communications technologies was an important confidence building measure.
The final report of the OEWG recommended that states should continue discussions on the development and implementation of CBMs in the GM.
It has been critical that member states have a forum to discuss the rapid development of technology in the United Nations and to address matters related to the responsible behavior of states in the use of ICTs.
Member states can support and facilitate full operationalization of the eight global CBMs through international cooperation at a UN, regional, and sub regional levels.
This support could take the form of workshops and roundtable discussions, share experiences and expertise, engage in dialogue to identify some of the non contentious areas and move to more sensitive ones as we continue to build layers of understandings and trust between states.
Chairperson, the increasing participation by member states in the global points of contact directory is another CBM.
We believe that by narrowing the capacity gap through capacity building programs, the goal of achieving maximum participation in the global POC directory is attainable.
Member states are encouraged to share success stories from assistance received through interaction with the global POCs during a cyber incident.
We regard the POC directory as a first step to greater cooperation between states on identifying and responding to threats to ICT security.
The eight voluntary CBMs adopted by the OEWG in its third APR are simple steps that member states take every day to a greater or lesser degree.
CBM one requests that member states nominate points of contact for the global POC directory.
CBM two requests that member states continue exchanging views and undertaking bilateral, sub regional, regional, and cross regional and multilateral dialogs and consultations.
CBM eight requests that states strengthen public private partnerships on ICT security.
It is a sign of member states commitment that several CBMs are already being undertaken by many delegations at the national level.
Further discussion on all eight CBMs could take place in the DTGs at appropriate intervals.
Chairperson, capacity building initiatives have also brought member states together at the UN and achieved consensus in a difficult geopolitical context.
Our delegation believes that the proposal for a global cybersecurity cooperation and capacity building portal linked to the work of the global mechanism should be further elaborated in the dedicated thematic group meetings in December 2026.
The proposed voluntary fund to support participation of developing countries in the global mechanism, and capacity building is also a CBM.
In this regard, we support the continuation of the UNDER Women in International Security and Cyberspace Fellowship, which has created a support system for delegations regardless of their affiliations with the global North or the global South.
I thank you.
Thank you very much.
I now give the floor to Singapore.
Thank you, Madam Chair.
Singapore believes that one of the key needs in this global mechanism is for states which are already implementing CBMs to share best practices, the potential pitfalls in implementations, and the ways around them.
Madam Chair, like cybersecurity, CBMs are a team effort.
They are not a concept that can be practiced in isolation by one state alone.
Having the respective CBMs as a concept is a good start, but we need to work towards actionable efforts towards the implementation.
We need to deepen efforts to collectively enhance one another's capacity to implement these measures.
Regional organizations are very important to this course.
Different regions have different ways of implementing CBMs.
DTG one should consider how we can involve regional organizations to share the experiences that could be useful from a cross regional perspective.
Madam Chair, we are also pleased to see the efforts to ensure that the global intergovernmental points of contact directory remains a useful and effective initiative for all UN member states.
The POCs directory is an important addition to the other existing channels that can be leveraged by states to reach out to each other in the event of a cyber incident, thus strengthening international cooperation, peace and stability.
At the same time, not all states have had prior experience with implementing the POC's directory and may require capacity building at the national level to implement processes to allow for the effective operationalization of the directory.
In this regard, it would be important to allow for the POCs directory to be used in a flexible way so that states may use it as needed before we develop more standard templates and procedures for its use.
As such, we support UNODC ongoing efforts to operationalize the use of the POC directory to capacity building initiatives, simulation exercises, and engagement with regional mechanisms to promote interoperability and the sharing of best practices.
The feedback from these activities can then be collated to form the basis for the further refining of the directory.
Singapore has participated in the pink tests conducted and will continue to do so to ensure that the directory remains a practical tool and relevant initiative for our continued cooperation.
Thank you, Madam Chair.
Thank you very much.
I give the floor now to arrow.
Thank you, Madam Chair.
NATO speaks in alignment with the statement delivered on behalf of the Pacific Islands Forum members with regards to CBMs.
We offer a national statement as follows.
In NATO, the people responsible for our cybersecurity, our diplomacy, and our digital policy are often one and the same within our public service.
This is not a complaint, rather, this is our context.
Where measures for transparency and communication are built, the consideration for us is, how can administrations like ours use them? Measures can assume large bureaucracies as well as small ones.
To be so, they have to be without exception, inclusive by design.
Our intention is not at all to slow down the progress of any state, but to be confident in moving forward from where we are.
It is precisely because we are small that CBMs matter so much to NRU, to NATO.
In a serious ICT incident, a small states response begins with the question, who do we call? The global points of contact directory exists to answer that question and NATO values it accordingly.
We are committed to registering to the POC and playing our full part in the directory.
We support the continuing program of capacity building for states to make full use of it.
Thank you to UN ODA for steering us.
We also see value in states sharing their national frameworks and legislative developments through this mechanism.
Openness about how each of us organizes our cyber governance is itself a confidence building measure and one NATO is applying through the reform that our government is undergoing as alluded to in previous statements.
Madam Chair, in a few days' time, NATO will assume the chairmanship of the Pacific Cybersecurity operational Network, Paxon for the coming year.
We are proud to take on this responsibility, and we do so with purpose.
Paxon connects the incident responders of our region in working level cooperation week in and week out.
It has shown that trust between technical teams is built through routine contact long before a crisis makes it necessary.
As incoming chair, NATRO intends to bring that regional experience to bear here.
We will work to strengthen the connection between the Pacific's operational cooperation and the global measure this mechanism develops so that each informs the other.
We invite other regions and the mechanism itself to engage with us in that spirit during our chairmanship.
Our priorities for this pillar follow from all of the above.
Keep the directory practical and exercised.
Invest in the training of designated officials whose competence is what the measures ultimately rest on.
Draw deliberately on regional networks as sources of tested practice.
I thank you.
Thank you very much.
I wish you every success in the role that you'll be assuming soon.
We don't have long left, so we're not going to be able to finish our list of speakers this afternoon.
I'll give the floor to Switzerland and if we have enough time, I'll give it to Vanuatu after Switzerland.
Otherwise, Vanuatu will be the first speaker tomorrow morning.
Switzerland, please.
Switzerland recognizes the importance of confidence building measures as an essential part of the UN framework for responsible state behavior in cyberspace.
Such measures help to reduce the risk of misunderstandings, misperceptions, and unintended escalations arising from the use of ICTs.
They promote transparency, predictability, and cooperation between states, thereby strengthening international peace and security.
Our dependence on digital technologies grows, so does the importance of implementing practical measures to foster trust and resilience.
Switzerland would like to emphasize that the challenge is not to develop new confidence building measures, but to implement those that have already been agreed effectively.
The eight initial CBMs developed at the open ended working group provides a solid foundation.
Our efforts should therefore focus on translating these commitments into practice, sharing experiences and identifying both implementation gaps and good practices.
DGT one is particularly well suited to this task.
This will take time and is an ongoing process, as our experience at the OEC shows.
In this regard, regional sub regional organizations play a particularly important role.
They are well placed to promote dialogue among neighboring states, facilitate capacity building, develop practical implementation guidance, and adapt confidence building measures to regional contexts while remaining firmly anchored in the global UN framework.
We would like to refer to the non papers submitted to the open ended working group in June 2025 on the role of regional organizations in implementing the UN framework for responsible state behavior in cyberspace.
One of its key recommendations is to establishment of a structured exchange between the global mechanism and regional sub regional organizations.
This would enable lessons learned to be shared, promote coherence across regions, avoid duplication of efforts, and strengthen the implementation of the framework at all levels.
Switzerland believes that the global mechanism should serve as both a forum for dialogue among states and a platform connecting regional implementation efforts, facilitating the exchange of best practices, and supporting the dissemination of successful confidence building initiatives.
I witnessed such an exchange in June this year at the meeting organized by the OEC with support and saw the added value it brought between regional organizations.
We also wish to emphasize the value of voluntary transparency measures, including designating national points of contact, exchanging information on national implementation, and cooperation through exercises and information sharing.
These measures strengthen communication channels prior to incidents and foster the trust essential for effective crisis prevention and management.
Chair, confidence building measures must remain closely linked to the other pillars of the UN framework.
Implementing them supports the application of agreed norms of responsible state behavior, contributes to capacity building and facilitates a common understanding of how international law applies in cyberspace.
During the discussion on threats and norms, Switzerland and many other delegations emphasized the importance of protecting critical infrastructure.
States therefore are encouraged to continue raising awareness on the importance of critical infrastructure protection when implementing CBMs, promoting information sharing among critical infrastructure stakeholders and sharing of good practices and guidance.
Doing so will help implementing norms 13 F, G and H.
Finally, we are looking forward to the paper announced by the cross regional group on CBMs, and thank them for their engagement.
Chair, Switzerland is committed to constructive cooperation with all delegations to ensure that confidence building measures are practical, inclusive, and oriented towards implementation.
Strengthening cooperation at global, regional, regional and national levels can further reinforce trust, stability, and security in cyberspace for all.
I thank you.
Okay.
Thank you very much.
I'll take it that we've run out of time for this afternoon.
I still have 18 requests on my list to take the floor on confidence building measures on this item, we'll hear from all of those delegations tomorrow.
Just like Kai said, once we finish this agenda item, we'll move on to the next one.
I'm just going to read the first five delegations on the list so that they can be ready to speak tomorrow at 10:00 A.M.
We have Vanuatu, Chile, Israel, Cote de Voie, and fifthly, Ireland.
And then we'll go further down the list until we're finished and the mechanism will come back here in this room tomorrow morning at 10:00 A.M.
The meeting is adjourned.
M&E
Meetings & Events
(6th meeting) Plenary Session, Global Mechanism on ICTs in the Context of International Security (20-24 July)
Substantive Plenary Session of the new Global Mechanism on Information and Communications Technology (ICT) Security.
Description
Dedicated stakeholder segment
Full transcript en transcript
Machine-generated · not human-reviewed · verify against the official record before citing or relying on this transcript
Session Summary Auto generated from session transcript
Synthesis hasn't been generated for this session yet.
The summarize pipeline runs after the English transcript is available.
Machine-generated · not human-reviewed · verify against the official record before citing or relying on this summary