Substantive Plenary Session of the new Global Mechanism on Information and Communications Technology (ICT) Security.
Discussions on the five pillars of the framework for responsible State behaviour in the use of information and communications technologies in accordance with annex C of A/79/214 and annex I of A/80/257 (continued) Norms, rules and principles
Machine-readable formats: Plain text · JSON
Transcripts available through this tool are created by using automatic speech recognition and are not official records nor official documents of the United Nations. Official records and official documents are available on the Official Document System of the United Nations. Learn more
Muy buenas tardes. Good afternoon. Se declara abierto. The fourth meeting of the substantive plenary session of 2026 of the Global Mechanism on Developments in the Field of Information Communication Technologies in the Context of International Security. Security and Advancing Responsible State Behavior in the Use of ICTs. As I indicated prior to lunch, we're going to continue with our list of speakers under the topic of threats. And so we are going to hear first from the representative of Ghana, who will conclude her intervention. I would ask her to begin where she left off. Thank you. And then we will continue with Pakistan, Romania, Nicaragua, and Armenia. Ghana, you have the floor.
Thank you, Chair. Madam Chair, Ghana remains committed to working with member states, regional organizations, and other stakeholders to address both existing and emerging ICT threats. We are particularly concerned by the growing impact of cyber threats on critical information infrastructure, whose disruption can have significant consequences for national security, economic stability, and public confidence. The damage to submarine cable serving Ghana in 2024 and the resulting disruption to digital services reinforce the importance of protecting such infrastructure as a strategic national asset. At the national level, Ghana has identified 13 critical information infrastructure sectors under the Cybersecurity Act, which provides for the registration of critical information infrastructure, establishes obligations for operators, and requires regular compliance audits. Ghana is also strengthening its national incident response architecture through national and sectoral computer emergency response teams. Currently, 4 sectoral CERTs are operational, And plans are underway to operationalize additional CERTs for health, energy, utilities, transportation, military, and academic sectors. Ghana has also established a 24/7 national incident response capability, enabling the public to report cyber incidents directly to the national CERT, that is CERT-GH. This has significantly strengthened our ability to respond to cyber incidents and support affected individuals and organizations. In this regard, Ghana welcomes the establishment of the Global Point of Contact Directory as an important voluntary mechanism to facilitate timely communication and cooperation among states for incident response. Like many countries, Ghana continues to confront threats such as business email compromise, online fraud, scams, and other forms of cyber-enabled crime. Emerging technologies, including artificial intelligence, and quantum computing present both significant opportunities and new security challenges. Ghana's National Artificial Intelligence Strategy seeks to harness artificial intelligence to promote inclusive development while ensuring that its adoption is secure, responsible, responsible and resilient. We therefore support enhanced international cooperation and capacity building to help developing countries address the evolving risks associated with AI and other emerging technologies. As we move forward, Ghana believes that no country can address these challenges alone. We remain committed to working with member states, and all relevant stakeholders to strengthen international cooperation, address existing and emerging ICT threats, and contribute to a secure and resilient cyberspace for all. Thank you, Madam Chair.
Thank you. I give the floor next to the delegation of Pakistan.
Thank you, Madam Chair. I congratulate you on assumption of your responsibilities. As well as your able and dynamic team. As we begin substantive work of the global mechanism, the ICT threat landscape continues to evolve. Threats have evolved from localized IT risks into major geopolitical tools capable of disrupting global stability. Attacks targeting critical infrastructure have increased in number. Sophistication and severity, threatening human life and national stability. Cyber operations routinely paralyze public administration and essential services across borders. Militarization of cyberspace is well underway. States increasingly deploy cyber instruments for espionage, sabotage, or political influence. Often leveraging private proxy groups, criminal syndicates, or commercial spyware vendors. Commercial hardware, cloud infrastructure, and software tools have been repurposed for military or intelligence operations, making nonproliferation and oversight exceptionally challenging. In addition, the AI-accelerated cyber warfare poses new challenges to international peace and security. Sophisticated surveillance tools sold to state and non-state actors are frequently used without safeguards or oversight. Amongst potent threats affecting international ICT security environment are misinformation and disinformation, both by states and non-state actors. Disinformation contributes to the outbreak and escalation of violence by manipulating threat perceptions, deepening identity-based divisions, and mobilizing populations toward confrontation. It obscures violations of international law, including international humanitarian law and international human rights law, distorts humanitarian realities, and sustains misinformation. Military operations through narrative control. When combined with cyber capabilities, coordinated campaigns can overwhelm information ecosystems, disrupt decision-making, and accelerate conflict dynamics. Madam Chair, member states must commit to voluntary norms of responsible state behavior alongside international law including the UN Charter. In addition, we need to establish clear international commitments that critical infrastructure, especially healthcare, energy, and water, must remain strictly off-limits during peace and conflict. In this challenging environment, implementing confidence-building measures assume greater importance. Operational coordination of cybersecurity authorities is critical to facilitate rapid communication during crisis events and to avoid accidental conflict. In this respect, we suggest 3 points. Global mechanism is an important opportunity to democratize global cyber diplomacy. We should focus our dialogues on practical issues affecting all regions such as ransomware mitigation, critical infrastructure protection, and de-escalation channels. 2, establish international consensus and regulatory guardrails regarding offensive cyber capabilities and the misuse of commercial surveillance tools. 3, examine how disinformation, including as part of cyber and hybrid warfare, contributes to the outbreak, escalation, and prolongation of armed conflict and seek to address this critical issue. Madam Chair, cybersecurity, especially for developing nations, is not merely an IT challenge. It is an economic, sovereign, and human security issue. Maintaining international cyber stability requires moving from passive agreements on norms to active implementation, combining clear legal guardrails with operational communication channels, targeted capacity building, and working on practical confidence-building measures. I thank you, Madam Chair.
Muchísimas gracias. Thank you very much. I now give the floor to the delegation of Romania.
Thank you, Madam Chair. Romania fully aligns with the statement made by the EU and makes the following remarks in its national capacity. As it is the first time I'm taking the floor, I would like to thank you, Madam Chair, and your team for all the work in order to ensure a fruitful session of the Global Mechanism. Romania expressed its interest to contribute constructively to the work of this new Global Mechanism. Madam Chair, a clear understanding of the threats and challenges in the cyber domain is of high importance for our future activity within the GMAC framework and for enduring meaningful results. This is as important as ever nowadays, given the fact that cyber threats are more and more prominent. They continue to target our societies, economies, and are having increasingly negative effects on our societies and our citizens. In the last years, Romania witnessed a significant increase in number, complexity, impact, and persistence of cyberattacks. Phishing, social engineering, ransomware, cyber frauds, attacks against informatic networks, as we have recently seen, for data exfiltration continue to represent persistent threats amplified by the rapid development of AI models. At the same time, we have been exposed to cyberattacks as part of sophisticated hybrid and interference campaigns. As malicious behavior in cyberspace is intensifying, intensifying, we are concerned by the blurring lines between non-state and state actors in conducting coordinated attacks. We are particularly concerned of the attacks targeting critical national infrastructure, democratic institutions, and democratic processes. On the 13th of July, Romania, together, together with other EU member states and allies, had condemned hostile cyber activities conducted by groups controlled by the Russian Federation. These activities form a part of a well-established pattern, characterised by the use of a complex cyber ecosystem comprising both state institutions and non-state entities. Madam Chair, raising awareness on cyber threats is essential for ensuring international security and stability. We remain committed to continue to contribute to the international efforts meant to prevent, better encounter such destabilizing actions. The DTGs could play an important role in this respect as the right venues for exchanging views and formulating recommendations on better implementing the existing normative framework. As well, our focus should be on applying the international law and international humanitarian law in cyberspace and build capacities looking at critical infrastructure and critical information infrastructure. Thank you, Madam Chair.
Thank you very much. I now give the floor to the delegation of Nicaragua. They will be followed by Armenia and Bangladesh.
Thank you, Madam Chair. Nicaragua welcomes the convening of this first substantive session of the Global Mechanism, and we reaffirm our readiness to participate constructively in this work. The creation of the mechanism represents an opportunity consolidating a permanent and transparent inclusive space where all can participate under conditions of equality and contribute to building common understandings. Our work should be focused on promoting an environment for ICTs that is secure, safe, stable, accessible, peaceful, and interoperable based on the purposes and principles of the Charter of the United Nations including the sovereign sovereignty of states, non-interference in internal affairs, and the peaceful settlement of disputes. Madam Chair, Nicaragua recognizes that the existing and emerging threats in the area of ICTs is developing swiftly and can impact the security of states, the functioning critical infrastructure, the provision of essential services, and the well-being of our peoples amongst them. For this reason, we have been strengthening our legal and institutional framework by adopting laws with the aim of strengthening the protection of telecommunications systems and infrastructure to promote a more secure and resilient digital environment, broadening access to ICTs, and consolidating national capacity for tackling threats derived from their malicious use. Similarly, our country is driving initiatives aimed at promoting a culture of cybersecurity, to strengthen digital security, and to broaden technical capacity to tackle with cybernetic threats. Well, we recognize that no country, especially in developing countries, can tackle these challenges in isolation. In this context, international cooperation and exchange of experiences, technical support, and capacity building should be the basic building blocks for all countries to tackle the threats resulting from malicious use of ICTs while fully respecting the national sovereignty and their priorities. Similarly, NICRA underscores that the application of unilateral coercive measures has a direct impact on developing ICTs and also in terms of response to attacks, access to technology, to software, digital services, and financing, and knowledge transfer. Also impact. These measures deepen the digital divide. They weaken national capacity. They make it difficult to protect critical infrastructure. And they are an impediment to the right to development of our people. This is why we call for an end to these illegal measures that are in breach of the purposes and principles of the Charter of the United Nations. Madam Chair, Nicaragua will continue contributing to an inclusive, transparent, and balanced mechanism aimed at concrete results that promote the peaceful use of information and telecommunications technologies to and to strengthen international cooperation and contribute to the development and well-being of all of our peoples. I thank you.
Muchísimas gracias. Thank you very much. I now give the floor to the delegation of Armenia.
Thank you, Madam Chair. As this is the first intervention by this delegation, we would like to join others in congratulating you on your election as the first Chair of the Global Mechanism. You can count on our constructive engagement. Taking into account your request to limit our interventions, I will now intervene under both items of today's agenda. Information and communications technologies have become an integral component of international peace and security. As digitalization advances, ICT-related threats continue to evolve in scale, sophistication, and frequency, posing risks to states, critical infrastructure, and international stability. The evolving ICT threat landscape underscores the importance of international cooperation. Given the transboundary nature of cyberspace, no state can effectively address these challenges alone. Collective efforts are therefore essential to strengthen resilience, promote responsible state behavior, and ensure global peace and security. We are confident that the Global Mechanism will provide an effective and inclusive platform for addressing ICT threats, fostering dialogue, and strengthening international cooperation. The dedicated thematic groups will facilitate focused and action-oriented discussions, while DTG2, dedicated to accelerating ICT security capacity building, will play a vital role in identifying needs, facilitating partnerships, and strengthening the capacities of all states to effectively implement the agreed UN framework. We recognize the importance of the voluntary non-binding norms of responsible state behavior in the use of ICTs, as set out in the 2015 GGE report, which established a common understanding of responsible state conduct. We further acknowledge that the 2021 GGE report provided an additional layer of understanding regarding the interpretation, application, and implementation of these norms. We support efforts to advance responsible state behavior and the further development of the framework over time. We recognize that states have different levels of capacity and resources to implement the framework of responsible state behavior in the use of ICTs. We emphasize the importance of capacity building, international cooperation, and support to enable all states to effectively implement these norms. Furthermore, we recognize that the framework for responsible state behavior in cyberspace is dynamic and evolving, and that additional voluntary non-binding norms could be developed over time where appropriate in response to emerging challenges and developments in ICTs. We emphasize that any further development of norms should continue. To contribute to international peace and security and be guided by inclusiveness, transparency, and consensus among states. We support continued exchange of views and best practices among states to enhance common understanding and promote the practical implementation of the framework for responsible state behavior. Thank you.
Muchísimas gracias. Thank you very much. I now give the floor to Bangladesh to be followed by the International Committee of the Red Cross.
Madam Chair, Excellencies, distinguished delegates, at the outset, my delegation congratulates you on becoming the chair of this global mechanism and pledges its full and constructive support to your stewardship of this mechanism. We also thank the Secretariat for its work in preparing the first substantive plenary. Bangladesh warmly welcomes the launch of this global mechanism as the achievement of 5 years of work by the Open-Ended Working Group. Madam Chair, as a country whose international connectivity depends heavily on a limited number of submarine cable landing stations, Bangladesh attaches particular priority to the protection of submarine cables and other cross-border critical information infrastructure and sees its merit in dedicating confidence-building measures on this issue. We also note with concern that the rising incidence of ransomware and denial of service attacks against government e-services and platforms and the financial sector, and support a comprehensive cooperative international approach to ransomware, including cooperation on tracing illicit finance. Like many delegations, we are increasingly concerned by AI-enabled threats and by disinformation and deepfakes generated through advanced technologies, which carry implications for both international security and social stability. Madam Chair, for Bangladesh, confidence building remains the pillar that makes every other pillar meaningful. In closing, Bangladesh remains committed to working with every delegation towards an open, secure, stable, accessible, and peaceful ICT environment. Bangladesh shall remain constructively engaged in this global mechanism. I thank you, Madam Chair.
Muchísimas gracias. Thank you very much. I now give the floor to the International Committee of the Red Cross, to be followed by Interpol, and then the African Union.
Gracias, Ambassador López. Thank you, Ambassador López. Excellencies, distinguished delegates, the International Committee of the Red Cross is grateful for the opportunity to take part in the first substantive plenary session of the Global Mechanism. The ICRC commends the important progress achieved by States throughout the work of the Open-Ended Working Group, including in identifying threats posed by the use of ICTs during armed conflict. Building such shared understanding is a key step towards developing measures to address these threats collectively. Over the past year, the number of armed conflicts has risen to alarming levels, with over 130 armed conflicts in 2025. The ICRC observed an increasing use of ICT capabilities for military operations by state and non-state actors, and we are concerned about the risks that this poses to the civilian population. The ICRC therefore wishes to highlight some of the trends it observes in today's armed conflicts. We have submitted these observations in a working paper to the Global Mechanism. First, ICT operations disable the provision of essential services. For civilian populations. Recent uses of ICTs have shown that even in the absence of physical damage, ICT operations can severely disable civilian infrastructure, damage or destroy civilian data, and disrupt the delivery of essential services. The consequences of these operations include power outages, disruption to transport systems, banking, water supply, and food production. They also led to the denial of contact with loved ones and of access to life-saving information. Second, ICT operations do not spare medical facilities, aggravating the hardships suffered by affected populations. In addition, humanitarian organizations, including the ICRC, continue to be targeted or affected by ICT activities. From the intrusion of their systems and exfiltration of sensitive data to the disabling of computer systems aimed at disrupting humanitarian operations, the targeting of humanitarian organizations causes them harm and, most importantly, threatens the safety and dignity of the people they serve. Third, recent armed conflicts have revealed how ICTs are used to harm children, Social media and messaging apps are used by parties to armed conflict to recruit children into their armed forces or to use them in hostilities. Children no longer need to be physically close to an armed force or armed group to be drawn into their operations. Recruiters now contact more children more quickly via online communities. The involvement of children in armed conflicts is unlawful and harms them. Fourth, as the use of ICTs in armed conflicts evolve rapidly, new actors are playing increasingly significant role. On the one hand, while technology companies provide much of the ICT infrastructure, assets, and services to civilian populations, these companies also provide similar assets and services to parties to armed conflicts. In times of armed conflict, this exposes company infrastructure to real risks, with potentially wide-ranging effects on civilian populations who rely on the very same infrastructure and services in their daily lives. On the other hand, civilian hackers or hacktivists are now operating in several armed conflicts. Too often, they do not know or ignore the limits that IHL imposes on ICT operations. In practice, many of these actors have directed their operations against civilian infrastructure and services. Finally, the growing use of artificial intelligence in ICT activities will increase their speed, scale, and potential for harm, with states and non-state actors integrating AI into their cyber operations The ICRC is concerned about risks of indiscriminate attacks, incidental civilian harm, damage to critical civilian infrastructure, and uncontrolled escalation, particularly in complex and interconnected digital environment. Madam Chair, as the Global Mechanism assumes its critical role in advancing the responsible behavior of states in the use of ICTs, the ICRC calls upon member states to work together towards reflecting the realities of today's armed conflicts in their discussions and to identify practical measures to mitigate harm to affected civilian populations and civilian objects. The ICRC stands ready to support states in these efforts. Thank you.
Thank you. I now give the floor to Interpol.
Thank you, Madam Chair. As this is the first time that Interpol takes the floor, we congratulate you on your appointment and wish you every success in guiding this important process. In the interest of time, I will deliver an abridged version of our statement. As many of the distinguished delegates have shared over the past 2 days, the nature and volume of cyber threats we face continues to grow rapidly, from ransomware attacks against critical infrastructure to supply chain vulnerabilities and now increasingly risks associated with artificial intelligence. From Interpol's global perspective, one reality is clear: an open, secure, and stable cyberspace cannot be achieved without addressing one of the principal drivers of insecurity, that is, the criminal misuse of ICTs. Cybercrime has become one of the world's most significant illicit economies, generating trillions of dollars and affecting governments, businesses, and citizens across every region. And cybercrime is becoming increasingly industrialized. Specialized actors offer malware as a service, rent malicious infrastructure, and provide services supporting every stage of the criminal lifecycle. The rapid development of AI is only supercharging this criminal supply chain, increasing the volume, speed, scale, and accessibility of cyberattacks, and even creating new targets. Importantly, the tools and infrastructures developed within criminal ecosystems can also be exploited by a broader range of malicious actors. Combating cybercrime is therefore not only a law enforcement imperative, it is essential to advancing a safer and more resilient cyberspace. And this is where Interpol provides a distinctive contribution. Through our secure communications network, cyber threat intelligence capabilities, operational coordination, and specialized capacity building activities, Interpol supports police cooperation worldwide. These efforts deliver tangible results. Earlier this year, Interpol's Operation Synergy F3 brought together more than 70 countries, many of which are represented in this room here today, against phishing, ransomware, and other forms of malware. The operation resulted in close to 100 arrests and took down some 45,000 malicious infrastructure. And looking ahead, Interpol is also working with its member countries and partners to address key challenges— key challenges, sorry— shaping the future threat landscape, from tackling the enablers of cybercrime as a service like residential proxies and bulletproof hosting, to responding to both the challenges and the opportunities presented by the rapid evolution of AI. To conclude, Interpol remains committed to supporting UN member states to strengthen international cooperation to combat cyber threats and to enhance collective cyber resilience. And we stand ready to contribute our operational expertise to the work of this global mechanism, including through its future thematic discussions, so that together we can build a safer digital future. I thank you.
Muchísimas gracias. Thank you very much. I now give the floor to the delegation of the African Union.
Madam Chair, the African Union Commission congratulates you on your leadership in convening this first substantive session of the global mechanism and in guiding the operationalization of the dedicated thematic groups. The Commission reaffirms its full support for this important process. The Commission aligns itself with the statement delivered by the African Group and wishes to provide complementary observations based on the African Union's continental mandates. Madam Chair, the establishment of this global mechanism represents an important opportunity to build on the progress achieved through the Open-Ended Working Group. At this stage, our collective focus should be on translating agreed commitments into action delivering outcomes that respond to the realities and priorities of all African Union member states across all regions. The African Union has established a strong continental foundation to support this process through the development of the African Union Convention on Cybersecurity and Personal Data Protection, and the common African position on the application of international law to the use of ICTs in cyberspace. Furthermore, the ongoing development of the AU guidelines for the implementation of the norms of responsible state behavior in cyberspace and the initiation of a continental declaration on peace and security in cyberspace demonstrate Africa's commitment to translating global commitment into practical regional actions. Madam Chair, Africa continues to face an evolving ICT threat landscape, including malicious cyber activities targeting critical infrastructures, ransomware, online fraud, supply chain vulnerabilities, and the growing challenges of artificial intelligence for security. The Commission encourages the dedicated thematic groups, Group 1, to prioritize areas of practical progress, including the implementation of international law in cyberspace, critical infrastructure protection, artificial intelligence, and other emerging threats, affecting peace and security. In this regard, the African Union Continental Artificial Intelligence Strategy and the Advisory Group on Artificial Intelligence that was nominated or appointed to support the AU Peace and Security Council can contribute to this discussion. For Africa, practical implementation begins with capacity. Capacity building must remain at the heart of this mechanism and should ensure gender mainstreaming and youth employment to promote innovation on the continent. The African Union Commission welcomes the establishment of the dedicated DMATI Group 2, and we encourage early progress toward the Global ICT Security Cooperation and Capacity Building Portal. Madam Chair, we continue to encourage the work of those two groups, and we wish also that they will be aligned and mutually reinforcing. Madam Chair, thank you, and I submit.
Muchísimas gracias. Thank you very much. We have now exhausted the list of speakers under this. and item. I have nonetheless received another request for the floor under the right of reply, and so I give the floor to Israel.
Thank you, Madam Chair. I regret we must ask for the floor again to respond to the stunning hypocrisy of the Iranian regime's statements about international law and aggression. For years, Iran has constantly and systematically violated every possible international obligation and norm, including by slaughtering tens of thousands of its own people, by intentionally attacking civilian centers in Israel and in other states across the Middle East, and by intentionally holding international maritime and navigation hostage at the expense of all member states. This malicious and rogue Iranian regime has also continued financing, training, and arming its non-state proxies, including Hezbollah, Hamas, and the Houthis, spreading death and destruction all across the Middle East. If only the Iranian people could enjoy the benefits of the vast Iranian resources devoted to ongoing brutal aggression against other member states, so many innocent lives could have been spared. Let me remind this chamber that the Iranian regime openly calls for the annihilation of Israel. A situation of a member state of the UN actively and publicly pursuing the annihilation of another member state is unacceptable. This regime has no moral standing whatsoever to preach against others, nor to lay false and outrageous claims while hypocritical— hypocritically invoking international law. This is a farce that we should not and will not tolerate. Madam Chair, we request that you exercise your leadership. Iran cannot be allowed to continue and derail our discussions and waste our precious times. Thank you.
Muchas gracias. Thank you very much. I hope that all delegations will bear in mind that we have a very limited amount of time and that we should be focused on covering the agenda item before us, and I think that there are ways of better using our time and not entering into these discussions. And I would ask all delegations just to bear in mind that we have a lot to tackle and it is already 3:40 PM. I have been informed that the delegation of Iran has requested the floor. I imagine that this is your second and last intervention under the right of reply. I will give the floor to you, and I would ask you to be very brief.
Thank you. Thank you, Madam Chair. I have already addressed the absurd allegations made by the representative of the Israeli regime. I don't intend to take up any more of the global mechanism's valuable time. Or that of other delegations by responding to a repetition of those baseless claims. They don't warrant any further response, and I don't intend to dignify them with one. I would, however, like to briefly react to one point in his intervention. Nothing is more astonishing than hearing the representative of the Israeli regime speak about Iranian people and the protection of civilians. The people of Iran don't need crocodile tears from those responsible for the deaths of thousands of Iranians, including 168 schoolgirls killed in the attack on an elementary school in Minok, the assassinations of our senior officials, and the widespread destruction of civilian infrastructure across my country. Thank you. It is difficult to reconcile such rhetoric with the well-documented consequences of the actions of the Israeli regime. Those responsible for such atrocities in our region, including in my country, are in no position to lecture others on international law. Madam Chair, the Israeli regime has consistently sought to mislabel legitimate resistance groups in the region as terrorists or proxies. Let us be clear. According to United Nations General Assembly Resolution 4651, these groups are not terrorists. They are legitimate resistance movements fighting against occupation, apartheid, aggression, and genocide in the Palestinian and other occupied territories. International law explicitly recognizes the right of peoples to resist foreign occupation and defend themselves against aggression. The real terrorists are those who bomb hospitals and schools, massacre civilians, strike an elementary school in Minok killing 168 schoolgirls, and violate international law with impunity. I thank you, Madam Chair.
Thank you. Thank you. Distinguished delegates, before we begin the next topic, I would like to recall the following, which is set out in Annex 1 of A/80/257, and I quote, the interested Accredited interested parties may attend the plenary substantive plenary sessions and the review conferences of the global mechanism, and make oral statements during the sessions dedicated to interested parties. They it will also be possible to deliver interventions after states according to the availability of time and subject to the discretion of the chair. At the substantive plenary sessions and the review conferences. According to these modalities and in the spirit of cooperation with the community of stakeholders, as indeed you have delegations, I intend to give the floor to those entities that are duly accredited to the global mechanism. And so in this regard, and specifically to provide information on this topic, which is existing and emerging threats in the area of ICTs. So I will be giving the floor for 3 minutes. This will be strictly enforced. And so I now give the floor to Kenya ICT Action Network. Can you press the mic?
Thank you so much, Chair, for this opportunity to make a few—
Can you press the mic? Because we cannot hear you.
Thank you so much, Chair, for this opportunity and for demonstrating your commitment to engaging stakeholders. You have demonstrated that by engaging us even before the session began. Thank you. you know, started. So, we are really grateful. I think the other thing I need to note is that I have seen more women from the delegations making their statements, and that is really commendable because in the previous session, you know, we didn't see that. So, that demonstrates the training. So, I just want to make a short statement on behalf of different civil society organizations. Working to protect digital rights, human security, and peace. For civil society, cybersecurity is not an abstract exercise in navigating geopolitics, but a matter of human safety, fundamental rights, and democratic survival. Today, the existing threats that alarm us most are those that directly strike citizens. We are witnessing unchecked proliferation of commercial spyware, surveillance, and state-sponsored cyber harassment used to monitor, intimidate, and silence journalists, bloggers, human rights defenders, and political dissenters. Simultaneously, emerging threats fueled by artificial intelligence-driven automated surveillance and deepfakes are weaponizing digital spaces to erode electoral integrity and supercharge tech-facilitated gender-based violence. These tools disproportionately target women, persons with disabilities, minorities, and vulnerable groups, forcing them out of public and civic life. National security cannot exist without human security. If global mechanism is to build genuine digital peace, we urge member states to prioritize 3 critical demands. One, ground all cyber norms in human rights, and this calls for measuring to secure cyberspace that must never be used for censorship, internet shutdowns, or criminalization of privacy and secure encryption. We need states to also protect civic space and end intrusive surveillance, as well as ensure meaningful multi-stakeholder participation, because civil society act as frontline defenders who monitor local harms and support victims on the ground. A secure digital world is one—
Thank you very much for that intervention. Now, I give the floor to DiscoverMUN Foundation.
Thank you, Madam Chair. My name is Edward Yonko. I take the floor on behalf of the Youth Publications and Socioeconomic Forum, a subsidiary program of the DMUN Foundation. The threats discussed this week demonstrate that ICT security depends on technologies and institutions. It is important to note that they are also reliant on human capacity as well. In that regard, I would like to emphasize one central message. Invest in people, especially in young people. Young people are the next generation of cybersecurity professionals, but we are already active participation— participants in the digital ecosystem. We are students, developers, researchers, and innovators. The question then is, how should we make that investment? I would like to briefly share preliminary findings from a study I was part of involving more than 700 secondary school students at a New York City public high school with specialized academic majors. Because students select their disciplines, we could compare perceptions of artificial intelligence among a diverse group of STEM-oriented and non-STEM-oriented students. We observed that students in non-STEM disciplines expressed significantly greater concern about AI-related job displacement than their STEM peers. This gap persisted even after accounting for self-reported AI use and skill. In other words, more frequent and more proficient use of AI did not necessarily translate into greater confidence about broader consequences. This finding could suggest a broader lesson for cyber capacity building. Mere exposure to technology does not necessarily create understanding, preparedness, or most importantly, resilience. We want to be precise about what this data does and does not show. The study examined attitudes toward AI and employment, not cybersecurity knowledge or threat recognition. Nevertheless, the findings offer a takeaway relevant to this discussion. Access to an emerging technology and familiarity with it should not be treated as evidence that young people understand its broader consequences or feel prepared to address them. As AI-enabled capabilities become increasingly relevant to ICT security, young people should be resilient. The youth should be equipped to use these technologies responsibly and also be equipped to recognize AI-enabled threats such as phishing and malicious deepfakes. Concretely, we ask that youth-serving organizations and youth capacity-building practitioners be recognized as important stakeholders set out for the global mechanism. Furthermore, we demand member states to nominate qualified youth capacity-building practitioners to the DTGs. Excellencies, we must invest in technology, but we must also remember the importance of an investment in people, and that investment must include young people. Thank you very much.
Thank you. Muchísimas gracias. Thank you very much. So distinguished delegates, I thank all of the delegations for this substantive discussion. My team and I have taken due note of all of your statements, and I believe we can identify some. some common themes that have emerged over the course of our discussion. And so, what I'm going to now list is not intended by way of any kind of hierarchy or intended to prejudge what is going to be discussed in these specific thematic groups. Rather, I'm just providing some feedback as the Chair to explain what I've heard yesterday and today. First of all, the threat landscape, including complexity, the number of actors, but also the range of tools that are being used, the impact of emerging technologies such as artificial intelligence and other technologies also impacting the security of ICTs. And these offer opportunities, but they also give challenges. The continued relevance of threats such as ransomware, the specific vulnerabilities of critical infrastructure, mainly in areas such as health, education, public administration, financial services, and also the critical information infrastructure such as subsea cables. You also indicated that there is a need to protect tech, to the supply chains for ICT services. And there were also many other topics that you delved into with a degree of technical detail. We will take this into account with other things as well. And all of this will inform the remainder of our program because it provides the context or the background that we need in order to develop the pillars of the framework for responsible behavior. I have also heard concrete calls to action and for concrete solutions. Many delegations emphasized the need for the mechanism to make progress and move to more action-oriented decisions— exchange of information on threats, cooperation, capacity building, incident response, recovery, and the creation of resilience, implementation of the responsible use framework. As I indicated at the beginning, this does not in any way prejudice or prejudge the discussions that we will be having over the next couple of months as we prepare for the thematic groups. Now, based on the program of work, we are going to begin the We now move on to our second substantive topic, which is voluntary and non-binding norms on the responsible behavior of states and the ways of their implementation, recognizing that over time additional norms may be developed. And I would be grateful if at this time you could indicate whether you are interested in taking the floor so that together with the Secretariat we may have some Thank you, Mr. Chair. I would like to provide some clarity as to the amount of time that would be required to cover this agenda item. As I said yesterday, there is no established time limit for you to deliver your statements. However, as chair, I would respectfully ask you to consider delivering an abridged version of your statement and send the whole complete version of this statement to the Secretariat and to the Chair. And once again, you will also have a timer available for you on screen to help you manage your time. I will now give the floor to Tonga on behalf of the Pacific Island Forum.
Thank you, Chair. I have the honor to deliver this statement on behalf of the members of the Pacific Islands Forum with a presence at the United Nations, namely Australia, the Cook Islands, Fiji, Kiribati, the Federated States of Micronesia, the Republic of the Marshall Islands, Nauru, New Zealand, Palau, Papua New Guinea, Samoa, Solomon Islands, Tuvalu, Vanuatu, and my own country, Tonga. Chair, on norms, the Pacific Islands Forum reiterates its longstanding position that the priority must remain the implementation of the existing voluntary non-binding norms of responsible state behavior. Our member states are at varying stages of operationalizing these norms, including identifying national critical infrastructure and critical information infrastructure, strengthening incident response capacity, developing whole-of-government approaches, and building the technical and policy foundations needed for implementation. Our priority at this stage is the full implementation of the 11 agreed norms. Many states, including small island developing states, are still building the capacity needed to operationalize these commitments, and we see considerable value in the global mechanism supporting this work, including through a shared understanding of where implementation gaps remain and how capacity-building efforts can best be targeted. A strong and demonstrable record of implementation across all states will strengthen the framework of responsible state behavior as a whole. The Voluntary Norms Implementation Checklist is a helpful step towards mainstreaming implementation. To realize its potential, however, we also need consolidated guidance, capacity support, and peer exchanges. We would welcome the mechanism taking the checklist forward in a concrete, action-oriented fashion, and we see this as precisely the kind of practical task that dedicated thematic groups are well placed to advance. This is also an area where stakeholders can make a meaningful contribution— technical experts, regional organizations, the private sector, academia, and civil society can help states understand how norms translate into practical steps. For instance, expert briefings in the DTGs can provide practical input on implementation without changing the intergovernmental nature of decision-making. The global mechanism should therefore be a place where norms are made operational. Its work should help states move from endorsement to implementation, and from implementation in principle to implementation in practice. Thank you, Chair.
Muchísimas gracias. Thank you very much for that statement. I now give the floor to the European Union. They will be followed by Pakistan, Costa Rica, Colombia. And then South Africa. EU, you have the floor.
Thank you very much, Chair, and bear with me. I try to trim to the extent I'm able to on behalf of the EU and its member states. Also candidate countries North Macedonia, Montenegro, Serbia, Albania, Ukraine, the Republic of Moldova, Bosnia-Herzegovina, and Georgia And the EFTA country Norway, member of the Economic— European Economic Area, as well as San Marino, aligned themselves with this statement. The EU and its member states reaffirmed their strong commitment to the full and effective implementation of the UN Framework of Responsible State Behavior in Cyberspace. As part of the framework, the 11 non-binding voluntary norms of responsible state behavior constitute a central pillar, and the practical implementation of the norms contributes to enhanced transparency, predictability, and accountability of states in cyberspace. It reduces also the risk of misperception and escalation and strengthens trust. And it supports the secure and resilient functioning of critical infrastructure and digital services upon which our modern societies depend. The norms, first agreed upon in the 2015 UN Group of Governmental Experts, have been reconfirmed and reaffirmed at the Open-Ended Working Group and are the basis of our future efforts. In view of the actionable work by the UN on the implementation under the Global Mechanism, the UN and its Member States presented ahead of the plenary session an initial overview of our efforts to implement the Norms of Responsible State Behavior. For this contribution, which is published on the website of the Global Mechanism, We use the consensus norms guidance included in the 2021 report of the UN Groups of Governmental Experts, and we detailed our main pieces of legislation, our policies, our structures, mechanisms, and networks that we have put in place in order to implement the UN Norms of Responsible State Behavior. For instance, as regards Norm 13B, that in case of ICT incidents, states should consider all relevant information, including the nature and the extent of the impact, as well as, in the event of a needed response, included attribution, we have outlined our approach. At Union level, the most relevant EU-level actors that contribute to shared situational awareness are the EU member states and their national cyber agencies, the European Commission, the External Action Service, including its intelligence and analysis capacity, the EU Agency for Cybersecurity, Security, ENISA, and the Cybersecurity Service for the Union's Institutions, CERT-EU, as well as Europol's Cybercrime Centre. Under the framework of the Network and Information Security Directive, our cybersecurity legislation, the Member States and EU actors cooperate at a strategic, operational, and technical level and have created structures to cooperate at each level, such as the NIS Cooperation Group, the CERT network of all EU member states' CERTs, as well as CYCLONE, that compiles all EU cyber agencies. Based on their shared situational awareness, these EU actors work together, consider all relevant information, and provide a comprehensive assessment. To further enhance our situational awareness, we have also put in place cooperative mechanisms with the multi-stakeholder community, including through ENISA's Partnership Programme. Based on this shared situational awareness, the EU and its 27 member states could decide upon an appropriate response, including diplomatic measures under a cyber diplomacy toolbox that also includes the option of attribution. The agreed principles for such response include, for instance, the need for it to be based on shared situational awareness among all 27 member states, and for the response to be proportionate to the scope, scale, duration, intensity, complexity, and sophistication of the impact of the cyber activity. In other words, for us to consider all relevant information. Like this, we have elaborated on each norm using the UNGGE norms guidance and detailing our main efforts. And we aim to further work on detailing our efforts, including providing more insights in the efforts by individual member states in the implementation at national level, notably also in the fields of capacity building assistance and in mitigation and recovery after incidents. This EU contribution complements the 2024 Declaration by the EU and its Member States on the Application of International Law in Cyberspace, as we should not forget that voluntary norms do not exist in isolation, but they sit along international law. While norms are voluntary and non-binding, international law itself is binding. And to take one example, International law prohibits the use of ICTs, including ransomware, to interfere coercively in the internal or external affairs of other states. The norms make it clear that states should not use ICT tools such as ransomware to disrupt critical infrastructure. To further build our common understanding on the ways and means to implement the Norms of Responsible State Behavior, we encourage also other states in sharing their experiences in implementing the norms. Which will help to enhance our implementation efforts. In addition to such written contributions that some regions already made, the DTGs are best placed to elaborate on the implementation of the norms connected also to a specific cybersecurity challenge, such as the protection of critical infrastructure or ransomware, and to exchange best practices between states that could feed into concrete recommendations on how to enhance national cyber resilience. In this context, we also see the draft voluntary norms checklist as a valuable tool to take our work forward. The checklist could be treated as a living document and serves as the primary reference as States continue to implement the framework. We could use the checklist as a reference document facilitating the discussions in our DTGs, to which we look forward. Thank you very much, Chair.
Thank you very much. I now give the I now give the floor to the delegation of Costa Rica, to be followed by Colombia.
Madam Chair, Costa Rica appreciates the opportunity to speak on this pillar relating to the norms, rules, and principles of responsible state behavior in cyberspace. For Costa Rica, the global mechanism must build on the accumulated body of work of the groups of governmental experts in the Open The goal is not to reopen previously reached consensus, but rather to consolidate them and translate them into national practices, institutional capacities, and concrete cooperation. In particular, the voluntary norms of responsible behavior agreed upon in 2015 and the 2024 voluntary list of practical actions continue to provide a foundation for guiding state conduct, reducing risks, and promoting international cooperation. International stability and security. Costa Rica emphasizes that these voluntary norms do not replace international law that is applicable to cyberspace. Rather, they complement it by offering practical guidance to foster transparency, predictability, restraint, and trust. The strength of this framework lies precisely in its ability to link general principles with concrete measures for prevention, cooperation, resilience. In this regard, we consider it important to move towards practical implementation of norms that are particularly relevant to the protection of critical infrastructure, essential services, and government functions— areas that states must refrain from targeting. The recognition of technical— trusted technical access actors, CERTs and CCERTs, distinct from offensive intelligence or other law enforcement functions. The good faith response to requests for assistance must be central to our discussions. Furthermore, Costa Rica believes that due diligence actions should be approached in a balanced manner, both as a responsibility to adopt reasonable measures commensurate with national capabilities to prevent a state's territory or infrastructure from being used for harmful cyber acts against other states, and also as an agenda for cooperation, technical assistance, and institutional capacity building. Madam Chair, responsible state behavior must not remain merely at the level of declarations. It must be translated into public policies, communication channels, responsible vulnerability disclosure, multi-stakeholder cooperation, and measures that can reduce the risk of escalation in the event of conflict. Costa Rica hopes that this mechanism will contribute to transforming the existing consensus into concrete, inclusive, and results-oriented action. I thank you.
Thank you very much. I now give the floor to Colombia to be followed by South Africa. Microphone, please. Microphone for Colombia, please.
Madam Chair, under this item, Colombia highlights the importance and the practical approach of the norms, rules, and principles of the Framework for Responsible Behavior of States. Pillars, it helps to strengthen internal digital resilience. My delegation believes that the existing norms have breadth and flexibility to address an environment that is constantly changing without prejudice to the idea that other principles may be considered to address the challenges from emerging technologies, especially those linked to their differentiated impact on individuals and communities in situations of vulnerability. However, the principal challenge that we're facing today is not the absence of norms but rather effective implementation. There are still questions as to how states will interpret and apply the norms that have been agreed and also as to the understanding of challenges that limit cooperation, timely exchange of information, and active participation in trust-building, competence-building mechanisms such as the Global Directory of Points of Contact. And this is why Colombia considers that the initiatives to strengthen capacity that will be taking place under the second thematic group should be focused prioritarily as operationalizing the norms, sharing national experiences, developing practical tools, and strengthening institutional capacities. And this will allow us to translate our decisions into concrete actions. In this regard, we invite states to consider voluntary publication of their national positions on interpretation and application of specific norms. This exercise would contribute to promoting greater mutual understanding. It would facilitate the exchange of best practices and help us identify common areas and to move towards more coherent and effective implementation of the existing framework. Madam Chair, in a geopolitical context where a growing part of interactions between states are taking place in cyberspace, space, the norms represent a common language that will allow us to reduce uncertainty, guide expected behavior, and reinforce trust between states through dialogue and transparency. The global mechanism provides a unique opportunity for translating this common language into practical tools to guide action by states and strengthen international cooperation. I would like to take this opportunity to say this is one— this will be one of the major contributions this process can offer to international stability and security. Colombia reiterates its readiness to continue working with all delegations to achieve this goal. I thank you.
Thank you very much. I now give the floor to the delegation of South Africa, and I will just tell you the next 5 speakers: Malawi, Brazil, Italy, Morocco, and Cuba. South Africa, you have the floor.
Thank you, Chair. There is no doubt that as the world's reliance on ICTs continues to grow, the responsible conduct of states in the use of ICTs has become crucial for the preservation of international peace and security. When discussing norms for responsible state behavior, it is essential to maintain a balance in keeping the cumulative normative framework current while transitioning from a conceptual discussion to an action-oriented approach facilitated through the DTGs. South Africa considers the further development of norms as a systematic evaluation, updating where required, and enhancement of the framework, which can be achieved through the implementation of voluntary non-binding norms, which will reveal both effective practices and potential gaps, thereby enriching the discussions. As indicated in the African Group statement, states will require effective tools and guidelines to implement the UN normative framework for responsible state behavior. In this context, the efforts of the DTGs should focus on finalizing the voluntary checklist in accordance with paragraph 38 of the OEWG 2021-22 2025 final report. Furthermore, given the surge of attacks targeted at critical infrastructure and critical information infrastructure, South Africa proposes a discussion on Norms F, G, and H regarding the safeguarding of critical infrastructure and critical information infrastructure under DTG 1 as a practical step for focused deliberations, sharing of knowledge, lessons learned, exchange of expertise, and efficient use of time allocated to the DDGs— DTGs in December. Madam Chair, South Africa's Critical Infrastructure Protection Act of 2019 recognizes that specific infrastructure is essential for public safety, national security, and the continuous delivery of vital public services. Accordingly, this Act mandates the identification and implementation of appropriate measures to safeguard and ensure the security of critical infrastructure. It defines infrastructure as critical infrastructure if it operates— if its operation is is vital for the economy, national security, public safety, and the uninterrupted provision of essential public services. Any loss, damage, disruption, or immobilization of such infrastructure could significantly impact our country's functioning or stability, the public interest in terms of safety, and the maintenance of law and order. We look forward to hearing about others' approaches and experiences at the DTG's meeting in December. Thank you, Chair.
Muchísimas gracias. Thank you very much. I now give the floor to the delegation of Malawi.
Madam Chair, the Republic of Malawi thanks you for giving us the floor. Before turning to the substance of our intervention, the Republic of Malawi wishes to underscore one important consideration. Norms do not exist because cyberspace is predictable. They exist precisely because it is not. In an environment where technologies evolve rapidly and misunderstandings can have far-reaching consequences, voluntary, non-binding norms provide something invaluable. Predictability, confidence, and a shared understanding of responsible state behavior, even when our laws differ. Through the work of the GGEs and OEWG, and now this global mechanism, member states have progressed— progressively built a cumulative and evolving framework on consensus. This demonstrates that even in a rapidly changing technological landscape, Cooperation remains possible. The Republic of Malawi, just like South Africa, acknowledges that the DTG has to pay close attention to Norms F, G, and H, noting that destruction of critical information infrastructure does, in most cases, lead to the breach of international humanitarian law, because data is usually involved. We have prioritized the implementation of norms relating to the protection of of critical information infrastructure, international cooperation and capacity building through the Malawi Computer Emergency Response Team and our Data Protection Authority, regularly engaging with the national and international community to conduct cybersecurity awareness, child online protection initiatives, threat intelligence sharing, and vulnerability management. Support to critical information infrastructure operators, national cyber drills, and multi-stakeholder engagements, which normally involve government, the private sector, academia, and civil society through established sector certs. These practical measures strengthen resilience while fostering trust and confidence among stakeholders at both the national and international levels. For us, the value of these norms lies not in what they encourage states to do, but in the confidence they foster among states, promoting restraint, transparency, and cooperation, reducing the risks of misunderstanding and miscalculation. My delegation therefore welcomes the emphasis on practical and technical discussions within the dedicated thematic groups recognizing their role in advancing inclusive, action-oriented recommendations and strengthening the implementation of the framework. As recognized in previous consensus reports, this framework is cumulative and evolving. However, its strength will not be measured by the number of additional norms we, we develop, but by our collective commitment to uphold those we have already agreed. Looking ahead, my delegation considers the dedicated thematic groups an important opportunity for member states to exchange practical experiences, share lessons learned, and identify good practices that strengthen confidence and support the effective implementation of the framework. Finally, Madam Chair, consensus has been the strength of this framework. Let implementation become its legacy. I thank you.
Thank you very much. I now give the floor to the delegation of Brazil.
Madam Chair, Brazil is a staunch supporter of the acquis of previous UN processes on ICTs and international security, particularly the Voluntary Norms of Responsible behavior. Their continued relevance after a decade of exponentially accelerating technological innovations is a testament to how well they were drafted by focusing on actions rather than on specific technologies. The norms have guided us on the establishing and updating of our national norms and policies to secure our critical infrastructure. And critical information infrastructures against cyber threats, including our most recent National Cybersecurity Strategy adopted last year. In this regard, we welcome efforts to facilitate norms implementation, including the voluntary checklist of practical actions drafted within the OEWG, which could be further developed in the context of this global mechanism. We also recognize the importance of international cooperation efforts in promoting the national implementation of norms. We have greatly benefited from the national experiences of other countries and therefore fully welcome continued knowledge sharing in this area, which is something that this global mechanism could promote. Regional cooperation has also been particularly relevant in this area. Brazil has been engaged in multiple initiatives in this regard, such as the OAS CSIRT Americas, which has been instrumental in advancing the norms related to information sharing on threats and vulnerabilities. Mercosur Cybersecurity Commission has also fostered national implementation of these norms through information exchange on cybersecurity institutional and legal frameworks, as well as the ongoing development of a common regional taxonomy. The promotion of gender equality is a key component to the adequate implementation of the norms. Promoting the inclusion of women to the cybersecurity workforce, as well as having policies that address the differentiated impact of cyber threats to women and other vulnerable groups in our society is an important component of our new national cybersecurity strategy. Madam Chair, we have heard throughout our debates arguments for advancing the implementation of the existing norms and for the adoption of new ones. In our view, these positions are not in any way mutually exclusive, and this global mechanism can have room for both. As long as there is consensus. In any efforts aimed— any efforts aimed at eventually developing new norms of behavior in the cyber domain must be inclusive and therefore take place within this mechanism where the needs of all countries are duly taken into account. The truth of the matter is that there are many initiatives currently underway outside of our multilateral process that aim to shape state behavior in areas that clearly fall within our purview. I thank you.
Thank you very much. I now give the floor to Italy, to be followed by Morocco.
Good afternoon, Madam Chair. Thank you for giving me the floor. Italy fully aligns itself with the statement delivered by the European Union. And wishes to add a few considerations in its national capacity, also benefiting from contributions of the 4 stakeholders objected by the Russian Federation. Madam Chair, the framework of responsible state behavior developed through the GGE and the OEWG provides a solid foundation for the international community that requires systematic and continuous implementation. Priority should be given to supporting States in translating agreed norms into national policies, institutional procedures and operational practices. In our view, being responsible in the use of ICTs means to understand the duties that each country has to contribute to international peace and stability, as well as to be accountable for its actions and non-actions. In light of the many challenges and possible difficulties in implementing the 11 norms, we believe that the voluntary checklist adopted by the 3rd APR was a very precious tool for all Member States, and thus we hope that the Global Mechanism can take advantage of it, promoting a discussion on its finalization. Italy continues to align to the 11 norms, building on strong normative foundations domestically, thanks to EU directives, regulations, and national law, while adapting to technological evolution and maintaining a strong commitment to international cooperation for stability and security in cyberspace. A few examples: Italy keeps implementing a range of measures to ensure the integrity of supply chain, as in Norm I, through the National Cybersecurity Agency, which implements and oversees the National Cybersecurity Perimeter, acts as the national evaluation and certification center, and is responsible for the implementation of the EU NIS2 Directive, strengthening ICT supply chain security and trusted procurement. The National Cybersecurity Agency, serving as the national cryptographic also promotes the use of cryptography as one of the cybersecurity tools for guaranteeing an effective resilience and long-lasting level of protection of critical infrastructures from ICT threats, as in Norm F. Particular attention should be also given to the integration of IT and OT security requirements, which are still too often addressed separately despite their increasing convergence. It could be interesting to exchange views on possible common baseline security principles, secure-by-design approaches throughout the lifecycle of digital industrial systems, and internationally recognized methodologies for cyber maturity assessment. Academia should be actively involved in such exchanges. States should also promote coordinated vulnerability disclosure procedures, and clear legal safeguards for good-faith security researchers. Multi-stakeholder partnerships are essential in this regard, allowing governments to leverage technical expertise, operational experience, and innovation capabilities developed by competence centers, research organizations, and the private sector. That is why we firmly believe that that DTG 1 can play a key role in facilitating a thorough discussion across the 5 pillars, helping deepen the practical implementation of norms. DTG 2, then, can produce tailored CCB projects that will also contribute to a more responsible behavior of states in the use of ICTs. Thank you very much.
Thank you very much. I now give the floor to the
Madam Chair, voluntary and non-binding norms remain one of the key pillars of the framework of responsible behavior by states. Their goal is clear: to reduce the risk of conflict and escalation in cyberspace by governing the way in which member states conduct their cyber activities. They aim to protect critical infrastructure as well as emergency response teams and promote information exchange and mutual assistance between states in the event of an incident. The goal is to establish a climate of trust between state actors. In this regard, Bangladesh would like to highlight 2 observations. First of all, The list of norms should not be set in stone given the rapid evolution of threats and emergence of new technologies and modes of operation, including AI. In light of this, our framework must be able to evolve. The 11 voluntary non-binding norms of the GGE Report 2015 serve as our foundation, and all of us should maintain the ability to enrich or clarify them if necessary. The role of future dedicated thematic groups in this regard is invaluable. We encourage these groups to, when the time comes, examine this topic and present concrete proposals for enriching them. Secondly, action must be focused on effectively implementing existing Thank you. We are developing norms, and norm only maintains its value if it is implemented coherently by all states. To ensure its implementation is effective, it is important to intensify our actions when it comes to technical capacity building. We place great importance on the fact that states, especially developing states, should be supported in taking ownership of these norms through through tools, information, and necessary resources. Thank you.
Thank you very much. I now give the floor to the delegation of Cuba, to be followed by the next 5 speakers, which are Portugal, Republic of Korea, Vanuatu, Nigeria, and China. Cuba, you have the floor.
Thank you very much, Madam Chair. I would like to reaffirm our position in favor of developing legally binding norms under the auspices of the United Nations that would complement the applicable principles of international law, respond to legal gaps in the area of cybersecurity, and facilitate impartial handling of the growing challenges and threats faced by states in this area. Non-binding norms are limited by their voluntary nature. As their implementation depends on the political will of states. Non-binding voluntary norms therefore only constitute an intermediary step towards achieving our goal. The alarming statistics reveal that voluntary norms on their own are not enough. This is demonstrated by the annual increase in cyberattacks with ever greater speed, scale, and sophistication. This is also demonstrated by the growing militarization of cyberspace. With an increase in the development of cyber offensive capabilities, a considerable proportion of these attacks are based on politically motivated false attributions in the eagerness to justify hostile actions against states. We recall that the norms, rules, and principles elaborated by the GGE in the past, where not all member states participated, do not enjoy universal acceptance. The mandate of this global mechanism recognizes that additional norms may be developed over time. We see a need to strengthen the regulatory framework to address matters in the field of security and the use of ICTs in a context of growing threats. The development and implementation of norms for responsible behavior of states in cyberspace should be grounded in respect for the principles of sovereignty, sovereign equality, political independence, and territorial integrity. The work should also promote peaceful coexistence and international cooperation for mutual benefit and interest. Developing countries stand at a disadvantage in developing technical, technological, and regulatory capacities, and this disadvantage is further exacerbated when such countries suffer the impact of unilateral coercive measures. The lack of conditions in developing countries to determine when they are used for attacks on others has even become an industry with really quite considerable dividends. The countries of the South, even though we have common responsibilities, these must be differentiated from those falling to developed countries. Standards are needed, for example, in relation prevention and militarization of cyberspace, promotion of cooperation to close the digital divide, and matching capacities to respond to the threats faced by states as well as to the peaceful settlement of potential disputes. The urgency required to jointly confront the growing threats means that we cannot be left at the mercy of a world based on voluntary norms of supposedly good behavior. This is a notion that can be manipulated according to political interests and contexts. A broad legally binding instrument that establishes obligations with permanent monitoring would be, in our view, the most effective contribution to establishing a model of responsible behavior by states. One could start, for instance, by considering the development of a roadmap. A global cybersecurity index established by the ITU includes a set of indicators that could be a starting point. Thank you.
Thank you very much. I now give the floor to the delegation of Portugal.
Thank you, Madam Chair. We align with the intervention of the EU but would like to add a very brief comment in our national capacity. The mandate of this permanent mechanism to promote responsible state behavior in cyberspace in the context of international security provides for regular institutional dialogue focused on the implementation of the consensually agreed framework endorsed by the UN General Assembly since 2015. As we have often emphasized, this dialogue is meant to contribute to upgrade national cyber capabilities across divides, and thus enabling us to move on to a formal system of mutual accountability and that levels up all member states' contributions to peace and security in the digital space, so that all of them can peacefully and securely benefit from the digital transition. For more than 5 years, it has been clear that the majority of the membership is in favour of prioritizing an exchange of lessons learned in combating the increasing degree of insecurity, which has been documented year after year and again yesterday and today. The plurality of Member States which patiently negotiated the mandate of an action-oriented permanent mechanism within the framework of the Open-Ended Working Group and with the constant support of the overwhelming majority that voted in favour of its establishment have demonstrated the strength of our consensus. Therefore, Portugal strongly believes that the 2 dedicated thematic groups designed to address specific security challenges and to accelerate cybersecurity capacity building to confront them have the potential to lead us towards action-oriented results to be debated during our next plenary session on the basis of their recommendations which you, Madam Chair, will then convey to us. It was that ambition that led us to establish a permanent mechanism of regular institutional dialogue with its present architecture, deliberately meant to be more stable than its predecessors and more oriented towards implementation of the 11 Voluntary Norms of Responsible State Behaviour already endorsed and of the applicable international law than towards the discussion of even more norms or even more binding instruments. Thank you, Madam Chair.
Muchas gracias. Thank you very much. I now give the floor to the delegation of the Republic of Korea to be followed by Vanuatu.
Thank you, Madam Chair. As noted earlier, the work of the global mechanism should build upon the consensus achieved through the GGE and the OEWG process. In this regard, we should focus on identifying practical ways to effectively implement the 11 voluntary non-binding norms of responsible state behavior that were agreed by the GGE and subsequently endorsed by the United Nations General Assembly. In particular, we believe that the Voluntary Checklist of Practical Actions for the Implementation of Voluntary Non-Binding Norms of Responsible State Behavior in the Use of ICT should continue to serve as a living document. The Global Mechanism should continue discussions on the Checklist with a view to its eventual finalization while ensuring that it remains practical, relevant, and responsive. To evolving needs. The global mechanism should continue to strengthen efforts to support and facilitate the implementation of the norms that have been agreed. Therefore, our priority of global mechanism should be the effective implementation of existing commitments rather than the development of new norms at this stage. I thank you.
Muchísimas gracias. Doy ahora la palabra. Thank you. Thank you very much. I now give the floor to Vanuatu.
Madam Chair, Vanuatu aligns itself with this statement delivered by Tonga on behalf of the Pacific Islands Forum members. The 11 norms of responsible state behavior were agreed by every state in this room. Vanuatu's interest now lies in a single question: what do those commitments require of states in practice, and how do we know they are being met? Vanuatu wishes to offer a perspective on that question that comes directly from our national circumstances. The norms concerning critical infrastructure, the commitment not to conduct or knowingly support ICT activity that damages it, the commitment to protect one's own, and the commitment to respond to requests for assistance when it is attacked carry particular weight for a country whose survival infrastructure is digital. Our multi-hazard early warning network, our emergency broadcast capability, our systems for coordinating relief across 83 islands— these are the assets that stand between a natural hazard and a humanitarian catastrophe. Vanuatu invites States to affirm through their conduct and their statements in this mechanism that infrastructure enabling disaster preparedness and response falls squarely within the protection these norms describe. There could be no clearer test of responsible behavior than restraint towards the systems that keep vulnerable populations alive. We also underline the norm-relevant duty of not to allow their territory to be used for international wrongful acts using ICTs. For small states on the receiving end of transnational malicious activity, this expectation of diligence is among the most consequential elements of the framework, and we encourage continued exchange in this mechanism on what reasonable capacity approach diligence looks like like for states at different levels of development. Vanuatu's broader position on this pillar has been consistent across the OEWG and remains so. The task before us is observance, not expansion. The existing commitments have not yet been implemented by all states to a standard that would refill any genuine gap. We support using this mechanism including the cross-cutting dedicated thematic group in December, to examine implementation in operational detail. What national arrangements give effect to each norm, what evidence of implementation looks like, and where support is required. Vanuatu is prepared to share its own experience candidly, including where our implementation remains work in progress And we encourage others, large and small, to do the same. Honesty about implementation is itself a contribution to accountability. The norms were the international community's answer to the question of how states should behave towards one another in cyberspace. Vanuatu's answer to the question of what comes next is simple: show it in practice. I thank you.
Muchísimas gracias. Doy ahora. Thank you. I give the floor to Nigeria.
Madam Chair, Nigeria once again congratulates you on your sterling leadership. You can count on my delegation's full support and constructive engagement as you lead this important process. Nigeria aligns itself with the statements delivered by the African Group and wishes to make the following remarks in our national capacity. Nigeria remains firmly committed to preserving the state-led, single-track, inclusive transparent, and consensus-based nature of this mechanism. Consensus has consistently enabled progress in this process and should continue to guide our collective efforts. Distinguished delegates, as we embark on this new phase, our priority should be implementation. The extensive body of recommendations developed by the Group of Governmental Experts and the open-ended working groups have provided a comprehensive normative framework for responsible state behavior in cyberspace. The task before us is, therefore, to translate these agreed commitments into practical measures that strengthen national capacities, enhance resilience, and deliver tangible benefits for all member states, particularly developing countries. Nigeria welcomes the establishment of the dedicated thematic groups and supports scenario-based discussions as an effective means of strengthening implementation, improving collective preparedness, and facilitating practical cooperation. Such exchanges provide valuable opportunities to share national experiences, strengthen incident response capabilities, and deepen our collective understanding of evolving cyber threats. The rapidly evolving cyber threat landscape demands our audience's attention. Attacks on critical infrastructure and critical information infrastructure, ransomware, ICT supply chain vulnerabilities, threats to undersea cables, electoral process disinformation, and the malicious use of artificial intelligence pose significant risks to international peace and security. These threats disproportionately affect developing countries, widening digital divides, and undermining sustainable development. Madam Chair, Nigeria reaffirms that international law, including the Charter of the United Nations, applies to the use of ICTs. We underscore the principles of sovereignty, sovereign equality, non-intervention, and due diligence, as well as the applicability of international humanitarian law. And international human rights law as essential to maintaining international peace and security in cyberspace. Capacity building remains indispensable to the effective implementation of the agreed framework. It is central to reducing vulnerabilities, narrowing the digital divide, and enabling all states to participate meaningfully in promoting international ICT security. Madam Chair, Nigeria recognizes the valuable contributions of relevant stakeholders, including civil society, academia, and the private sector, in support of this state-led and intergovernmental mechanism. We encourage the chair's continued consultations towards a pragmatic solution of the outstanding stakeholder participation issues. In conclusion, Madam Chair, the success of this global mechanism will ultimately be measured not by the number of meetings we convene, but by the practical outcomes we deliver: stronger national capacities, effective implementation mechanisms, enhanced confidence among states, and a more resilient global ICT environment. Nigeria remains committed to working constructively with all member states to ensure that this mechanism delivers meaningful results and contributes to an open, secure, stable, accessible, peaceful, and interoperable cyberspace for the benefit of all. I thank you, Madam Chair.
Thank you very much. I now give the floor to China, followed by the following 5. Botswana, Thailand, the Republic of the Netherlands, and Iran. China, you have the floor.
Thank you, Madam Chair. Confronted with a new landscape, a new danger in cyberspace, we must uphold multilateralism to effectively respond to risks, develop and draft the framework for responsible state behavior to make sure the framework can evolve with the times and can also be cumulative and progressive. China believes that we should develop new norms regarding the following issues first. AI's impact on cybersecurity. AI defensively and offensively has a profound impact on global cybersecurity. We should establish a barrier for the frontier AI models and to guard against possible security risks and geopolitical risks due to the convergence of cybersecurity Cyber technologies with AI. Second, the importance of data security has been increasingly prominent. At present, data security is increasingly prominent. Global mechanisms should discuss developing universal, non-discriminatory international norms on data security to provide effective institutional guarantee for the protection of data security across the world that we need to Strengthen the protection of critical infrastructure. Safeguarding critical infrastructure security is a shared concern of all countries. Global mechanism should improve and develop norms for responsible state behavior regarding the protection and promotion of critical infrastructure security. States should not use cyber means to damage other countries' critical infrastructure, especially key information infrastructure concerning national economy, livelihoods, and public interests such as energy, transportation, water conservancy, finance, public services, e-government, and other key information infrastructure, not show that damage or steal key data from other countries' critical infrastructure. Fourth, maintaining open, secure, and stable global digital, intelligent, industrial, and supply chains It's also important, building upon existing consensus, we should further refine and specify the effort to develop and implement globally interoperable common rules and standards for supply chain security and oppose the man-made fragmentation of supply chains driven by political motives. Madam Chair, China hopes that the DTG1 of the global mechanism can give serious consideration to China's proposal, China stands ready to adopt a constructive attitude to work together to make sure our global mechanism achieves new progress in developing and improving the norms regarding responsible state behavior. Thank you.
Thank you very much, and now I give the floor to Botswana.
Thank you, Chair. Chair, Botswana reaffirms her steadfast commitment to the UN Cyber Framework and emphasizes that the 11 voluntary norms reinforced by the UN Charter and the existing international law are sufficient to govern state conduct in cyberspace. For developing states such as Botswana, the debate initiated at the OEWG regarding the implementation of the existing norms against the formulation of new norms is secondary to the immediate reality of the digital divide. Developing countries cannot effectively protect critical infrastructure, prevent cross-border cybercrime, or guarantee the integrity of their supply chains if they lack the underlying technical and institutional capacity to do so. We emphasize the role of the DTGs in formulating concrete and action-oriented strategies to effectively implement the existing norms. These will provide a structured and predictable avenue for the private sector, civil society, and academia contribute technical expertise in norm implementation and targeted capacity building in that regard. The UNIDIS Cyber Survey— National Cyber Survey and the UN Cyber Norms National Implementation Checklist serve as baseline instruments for the global mechanism and its DTGs by providing clear and actionable tracking where UN member states systematically document, monitor, and update and their domestic progress in executing the 11 voluntary norms. These tools provide practical framework for identifying national and regional capacity gaps to make the work of the DTGs targeted and actionable. Domestically, Botswana, through its National Cybersecurity Strategy and its progressive legislative tools such as the Cybersecurity Act, has advanced to safeguard its critical national infrastructure. Our national CERT further acts as an operational engine responsible for implementing the voluntary norms of responsible state behavior. Their work also involves the response to requests for assistance, sharing of threat intelligence and best practices, coordination of local investigations, as well as mitigation of malicious cyber incidents on Botswana's networks, and to also ensure a secure and stable stable digital environment. Botswana reiterates its commitment to implement these global norms through a phased approach aligned with its national capacity and available resources. Thank you, Chair.
Thank you. And I'll give the floor to Thailand.
Madam Chair, Thailand remains committed to the 11 voluntary non-binding norms of responsible state behavior in cyberspace, recognizing that they complement existing international law applicable to the use of ICTs in cyberspace and should be interpreted in a manner consistent with the purposes and principles of the UN Charter. These norms meaningfully reduce risk to international peace, security, and stability by providing a practical foundation for enhancing transparency, fostering cooperation, and promoting predictability in cyberspace, thereby building mutual trust and confidence amongst states. In addition, Thailand is of the view that the voluntary checklist of practical actions serves as a useful capacity-building tool that supports states in developing baseline ICT security capacities and resilience, while respecting each state's prerogative to structure its implementation in accordance with its national circumstances. At the regional level, ASEAN, as the first regional organization to have adopted these cyberspace norms in principle, has finalized its norms implementation checklist to support member states in translating norms into practice. At the national level, Thailand has integrated these norms of responsible behavior into our National Policy and Action Plan on Cybersecurity 2022 to 2027. The next plan for 2028 to 2032 is currently under development, guided by the ASEAN and/or EWG checklist. Thailand values and encourages regional organizations and frameworks to adopt and implement these norms, rules, and principles of responsible state behavior as part of the global confidence-building efforts. As we move forward, Thailand supports continued exchanges of views on the rules, norms, and principles of responsible state behavior in the use of ICTs within the global mechanism. Thailand remains open to discussions on the possible development of additional norms, rules, and principles of responsible state behavior in the use of ICTs, particularly in response to emerging threats. At the same time, such discussions should take into account the diverse contexts, needs, and capacities of states. Any additional frameworks should not impose obligations beyond states' capacities or serve as a means of technological exclusion. Instead, they should contribute to bridging the digital divide and strengthening the resilience of developing countries countries against evolving cyber threats. Thank you, Madam Chair.
Thank you. Netherlands, please, followed by New Zealand.
Thank you, Madam Chair. The Kingdom of the Netherlands aligns itself with the statement delivered by the European Union, and please allow me to make some further comments in my national capacity. To the Kingdom of the Netherlands, the 11 non-binding voluntary norms form an integral and essential part of the consensus normative framework for responsible state behavior. We consider it pivotal that while the norms are not in themselves binding, they do confer a degree of mutual expectations on states to behave responsibly in cyberspace. They point towards our collective path forward, and the implementation should be front and center of our work within the UN Global Mechanism, but also within our national policies. Chair, please allow me to highlight 3 elements to aid the implementation of the 11 Voluntary Norms. First, the DTGs should provide the opportunity for states to discuss the norms not in isolation, but in a cross-cutting manner with the other pillars of the normative framework when addressing specific cyber threats and dilemmas. One way to do so is by providing guiding questions that prompt member states to discuss the norms in conjunction with international law, confidence-building measures, and capacity-building instead of tackling each pillar one by one. The norms are best implemented in the recognition that the normative framework is a unitary framework rather than a collection of parts. Second, the Kingdom of the Netherlands believes that the voluntary checklist for the implementation of norms, as developed by the previous Open-Ended Working Group, remains a tool of great potential for the implementation of the 11 norms. We should endeavor to strengthen and operationalize the checklist and lay the basis for a voluntary instrument for self-reporting on the implementation of the 11 norms. The EU paper on norms implementation is a perfect example of what such reporting could look like. And finally, in order to ensure that the norms can be implemented by the whole membership of the UN Global Mechanism, the Kingdom of the Netherlands believes that our collective efforts at cyber capacity building should be well aligned with the aims and contents of the 11 Norms for Responsible State Behavior. Co-production and demand-driven approach to such capacity building efforts remains essential for their success. We would do well not to reinvent the wheel, but to draw upon resources already available. Examples of such resources are the norms implementation guides as published by members of the multi-stakeholder community, such as the Geneva Dialogue, but also by UN entities such as UNIDIR and regional groups such as the OAS. Chair, by combining practical DTGs With a well-developed voluntary checklist and effective capacity building, the Kingdom of the Netherlands believes that we can collectively make great strides in the implementation of the 11 voluntary non-binding norms for responsible state behavior. And we trust in your guidance and assure you of our support in your efforts. Thank you.
Thank you very much. The floor to New Zealand.
Thank you, Chair. We align with the statement by the Kingdom of Tonga on behalf of the Pacific Islands Forum and offer the following in our national capacity. Implementing the norms of responsible state behavior improves stability in cyberspace and strengthens the resilience of the ICT systems on which our economic and social interests depend. The question is how, in a very practical sense, can we support norms implementation? On this point, we have been struck by the valuable contributions that regional groups are making. We welcome the EU's non-paper detailing how it is implementing the norms. It's a practical and substantive demonstration of what implementation can look like. Even if implementation may look different in other regions, the paper offers inspiration and useful food for thought. Likewise, the ASEAN Norms Implementation Checklist is a valuable point of reference not only for ASEAN, but for all states who want to implement the norms. We also look forward to the African Union finalizing its guidelines on norms implementation. From the Pacific region, we reiterate the message from the Pacific Islands Forum that the regional priority for now is fully implementing the existing norms. To this end, the key value that the global mechanism provide is further guidance and capacity-building coordination to support implementation at the national level. This is where the DTGs could prove their worth. By considering specific scenarios or specific cybersecurity challenges, experts and states could share experience on what best practice looks like, offer peer learning, and identify specific areas where capacity-building would support norms implementation. This, in turn, could generate further practical contributions, both to address capacity-building needs and to develop further guidance such as the voluntary checklist discussed in the OEWG. Thank you.
Thank you very much indeed. I now give the floor to the Islamic Republic of Iran, to be followed by the following 5 speakers: Ireland, then Ukraine, Canada, Japan, and then Singapore. Iran, you have the floor.
Thank you, Madam Chair. Paragraph 36D of the OEWG final report reaffirms that given the unique attributes of ICTs, additional norms could continue to be developed over time. Accordingly, paragraph 9 of Annex C explicitly assigns the global mechanism the task of elaborating additional rules, norms, and principles of responsible state behavior. Recent developments further demonstrate why the continued elaboration of additional voluntary norms remains necessary. As my delegation has illustrated under the agenda item on threats, recent unlawful cyber operations carried out by the United States and the Israeli regime in conjunction with their unlawful military attacks against my country, have targeted critical infrastructure and essential civilian services, exploited private sector technologies, ICT supply chains, and digital platforms, involved cyber espionage, disinformation, and cognitive operations, and integrated cyber capabilities with conventional military operations including electronic warfare and interference with communications and satellite navigation systems. These developments revealed important gaps in the existing normative framework and underscored the need for the global mechanism to elaborate additional voluntary norms to promote the exclusively peaceful use of ICTs and contribute to international peace security and stability. In light of these developments, my delegation believes that particular attention should now be given to several areas where further normative developments is both necessary and timely. These include inter-area data security, including cross-border data flows, the accountability of private sector entities operating in ICT environment and the use of ICTs for unilateral coercive measures. Madam Chair, throughout the OEWG process, many delegations consistently emphasized that the future development of additional norms and the implementation of existing norms are complementary objectives that should be— should proceed in parallel. At present, however, this balance has not been maintained. While work on the implementation of existing voluntary norms has advanced, no comparable process has been established to facilitate the elaboration of additional norms as envisaged in the agreed mandate of the global mechanism. Accordingly, my delegation considers that negotiations on the proposed voluntary checklist of practical actions for the implementation of voluntary non-binding norms should proceed alongside a structured process for the elaboration of additional norms. In this regard, my delegation proposed that the Chair prepare an initial consolidated draft compiling the proposals for additional rules, norms, and principles submitted by Member States, drawing from the Annex to the First OEWG Chair's summary. Such a draft would provide a practical basis for structured discussions in both the plenary sessions and the dedicated thematic groups. I thank you, Madam Chair.
Muchísimas gracias. Thank you very much. I now give the floor to Ireland.
Thank you, Madam Chair. To begin, Ireland aligns with the intervention made on behalf of the European Union and makes the following comments in our national capacity. Ireland supported the consensus development of the UN normative framework for responsible state behavior in cyberspace. This was a major achievement in our collective path towards a global, open, secure cyberspace. Now we need to focus on its implementation. The 11 voluntary non-binding norms of responsible state behavior are central to maintaining international security and stability, and their practical implementation enhances transparency, predictability, and accountability of state conduct in cyberspace. It is important that states show how they are seeking to implement the norms, and I refer to the EU's paper on implementation as an example of this. There is much that we can learn from one another and great value in all states sharing our experiences and implementing the norms. It is also important to note that the voluntary norms are of course complementary to international law which applies in cyberspace. Ireland believes that there is a strong role for the DTGs to discuss the implementation of the 11 voluntary norms connected to specific challenges such as the protection of critical infrastructure or ransomware, to exchange best practices that could feed into recommendations. As others have indicated earlier, stakeholders' expertise can and should play an important role in this. Ireland also strongly supports the voluntary checklist of practical actions for the implementation of norms developed in the OEWG, which we see as a valuable reference to take states' implementation of the framework forward and which can be further developed. We would also welcome discussion of capacity building programs to assist with the implementation of existing norms, particularly on the applicability of international law in cyberspace at the DTGs. Thank you, Madam Chair.
Thank you very much. I now give the floor to Ukraine.
Thank you, Madam Chair. Ukraine aligns itself with the statement delivered earlier by the European Union and and would like to add some considerations in our national capacity. The 11 voluntary norms, together with international law, confidence-building measures, and capacity-building, constitute a balanced and comprehensive framework for promoting international peace and security in cyberspace. The cumulative framework already provides a solid foundation. The key challenge before us is not whether the agreed norms remain relevant, They clearly do, but the question is how to ensure their effective implementation in an increasingly complex security environment. The rapidly evolving cyber threat landscape demonstrates the continued relevance of the agreed framework. Against this background, the Voluntary Norms of Responsible State Behaviour remain as relevant today as when they were first agreed upon. Their effective implementation is essential for reducing risks strengthening resilience and preventing conflict. Some states insist on the voluntary nature of these norms and suggest that were these norms put into legal framework and had they become legally binding, then states would have adhered to them with more dedication. In this respect, it is necessary to bring to the attention that the UN Charter is an international legally binding document, and this does not prevent for example, Russia, to act in breach of its provisions. And the International Criminal Court is already taking important steps to hold relevant Russian criminals accountable. At the same time, we think that the states should primarily adhere to the norms for the purpose of progress and development, and not due to their fear of persecution. Chair, Ukraine would like to focus on 2 norms that have already been mentioned by many speakers before and have become particularly important in light of today's security environment. The first concerns the protection of critical infrastructure. States have agreed that they should not conduct or knowingly support ICT activities that intentionally damage critical infrastructure or otherwise impair its use and operation in providing services to the public. Ukraine's experience demonstrates why this norm is indispensable. Russia's cyberattacks have targeted the energy sector, telecommunication networks, public administration systems, transport infrastructure, and other essential civilian services. Their purpose has been not merely to disrupt computer systems, but to undermine the resilience of the state, amplify the effects of missile and drone attacks, and inflict maximum hardship on the civilian population. The second norm we wish to highlight concerns the responsibility of states not to knowingly allow their territory to be used for intentionally wrongful acts using ICTs. This principle, commonly referred to as due diligence, remains one of the cornerstones of responsible state behavior in cyberspace. No state should knowingly permit malicious cyber infrastructure operating from within its jurisdiction. To be used against the rights of other states. At the same time, we observe the growing convergence between state-sponsored cyber operations and cybercriminal ecosystems. Malicious actors operating from Russian territory, including ransomware groups and other cybercriminal entities, have repeatedly targeted Ukraine and partner states while benefiting from a permissive environment. This further underscores the importance of implementing the due diligence norm, and ensuring that no state knowingly allows its territory or infrastructure to be used for malicious ICT activities. Chair, Ukraine believes that the Global Mechanism provides an important opportunity to move to implementation. Thematic discussions should increasingly focus on practical measures that assist states in implementing the agreed norms. This includes exchanging national practices, identifying implementation challenges, strengthening the protection of critical infrastructure, improving information sharing, and developing practical guidance on the implementation of due diligence. Ukraine stands ready to contribute its unique practical experience acquired while defending itself against Russia's cyber threats. As many have noted already, norms of responsible state behavior complement the existing cyber— the existing international law, and derive their value from consistent implementation. Thus, states that systematically conduct malicious ICT activities against critical infrastructure or knowingly tolerate malicious cyber operations originating from their jurisdiction undermine confidence in the very framework they have committed to uphold. The global mechanism should therefore serve not only as a platform for dialogue, but also as a catalyst for strengthening implementation, promoting accountability, and reinforcing responsible state behavior in cyberspace. Ukraine remains committed to work— to working constructively with all peace-loving nations to ensure that the global mechanism delivers practical outcomes that contribute to international peace, security, and stability. Thank you.
Muchas gracias. Thank you very much. I will now read out the next 5 speakers. Canada, followed by Japan, Singapore, Tonga, Australia, and Kiribati. Canada, you have the floor.
Thank you, Madam Chair. The 11 agreed norms are at the core of the UN framework for responsible state behavior. Over the years, we have made attempts at clarifying how they apply, including through guidance in the 2021 GGE Consensus Report. We also commend the work of the Chair of the 2021-2025 OEWG on a voluntary checklist for the implementation of the norms. In this first plenary of the Global Mechanism, our priority should be to set the stage to move these implementation efforts towards more practical and concrete application of the norms to real-world situations. We welcome the EU's efforts to provide transparency on how they engage responsibly in cyberspace through norms implementation. In the same spirit, Canada has recently published its survey of national implementation of the framework. It is on the Canada page of the UNIDIR Cyber Portal. It provides information on how we implement the pillars of the framework, including norms, CBMs, and capacity building. The survey also refers to our 2022 national position on how existing international law applies. The new format of dedicated thematic groups will be a key venue to deepen this conversation. Indeed, DTGs will enable us focus on specific challenges that have been top of mind for delegations over the OEWG years but that have not yet been sufficiently addressed. This is— this certainly includes the protection of critical infrastructure and ransomware incidents affecting hospitals. In Canada, a large segment of the ICT systems that form part of public service delivery is owned and operated by non-governmental stakeholders. We could share best practices in terms of national measures and in working with key stakeholders. For example, Canada could provide lessons learned and best practices from its experience with Bill C-8, an Act respecting Cybersecurity. The legislative process for this bill was concluded last month, and the bill is now being implemented. It provides a number of new obligations for designated operators within financial, telecommunications, and energy industries, such as the establishment of cybersecurity programs, the management of risks associated with the supply chain and third-party attacks, the reporting of incidents to Canada's CERT within 72 hours, and certain record-keeping. There are enforcement mechanisms, including penalties, ensure that designated operators improve their cyber resilience. Canada could also provide information on our Cyber Incident Response Plan. This governance tool helps us coordinate across governmental and non-governmental actors to address cyber incidents efficiently. Madam Chair, for the Global Mechanism to bring real value to the UN membership, it must move beyond high-level pillar-by-pillar discussions and engage on how norms and other pillars apply to specific challenges. These discussions should engage on practical implementation from the policy, legal, and technical angles. Contributions from experts and participants from within government and beyond are essential. Governments can act, but our effectiveness depends on strong buy-in from the private sector engaged communities, including civil society, and innovative leaders who think across boundaries. Thank you, Madam Chair.
Thank you very much. I now give the floor to Japan. It will be followed by Singapore.
Well, thank you, Madam Chair. In countering the growing threats in cyberspace, it is crucial that existing international law applies and norms are implemented in cyberspace. Regarding norms, while making use of the voluntary checklist and so-called non-binding 11 norms on which the consensus reached among member states and recognized in the OEWG, it is essential for each member state to steadily implement those norms as a first step. Regarding the global mechanism, particularly through DTG1, we hope to deepen practical and concrete discussions on how to implement specific norms in response to particular incidents, including cyber attacks against critical infrastructure, thereby fostering deeper and shared understandings among member states. Madam Chair, to give one example, in the context of states' responsibility under existing international law, Japan attaches great importance on the fact that the member states bear due diligence obligation under international law with regards to cyber activities as well. The 11 norms also reflect We share a fundamentally similar understanding, and we believe that the consistent implementation of these obligations and norms by all member states will contribute to the prevention and deterrence of cyberattacks. We would like to deepen our understandings on this point through DTG 1. Thank you, Madam Chair.
Thank you very much. Next, we'll hear from Singapore.
Thank you, Madam Chair. The pace of technological development— advancement we discussed in the previous section of this meeting requires us to continue adapting to new opportunities, challenges, and to uplift our efforts in addressing the threats to cyberspace. Therefore, we would like to see the moving forward on the implementation of the existing 11 non-binding voluntary norms which remain— of responsible state behavior in cyberspace, which remain a priority. The UN OEWG had developed the Voluntary Checklist of Practical Actions, and we should move towards discussing how we can implement it. As noted by my distinguished colleague from Thailand, regional frameworks such as the ASEAN Norms Implementation Checklist can also offer a useful reference on how the voluntary checklist of practical actions can be implemented, and we would be happy to share our experience in this. Madam Chair, any discussion on the implementation of norms will also require a discussion on capacity building. This is because states need to build significant capacity to implement the existing norms because these norms are multidimensional. Each norm has a policy, operational, technical, legal, and diplomatic aspect to it that needs to be addressed and capacity that needs to be built before we can effectively implement these norms. Only after developing the capacity to implement these norms will states be able to identify gaps and take the necessary measures to fully implement them. This interconnected and coordinated approach ensures that we remain both grounded in practice and forward-looking in strategy. Thank you, Madam Chair.
Thank you very much. I now give the floor to the delegation of Tonga.
Madam Chair, Tonga aligns itself with the statement delivered by my colleague on behalf of the Pacific Islands Forum members and adds the following in its national capacity. Tonga's position on this pillar is grounded in our experience. The framework of voluntary, non-binding norms agreed by all states is sound. What the world needs now is not new commitments, but the implementation of those commitments already made. Every hour this mechanism spends drafting new language is an hour not spent spent helping states give effect to the language we already have. Madam Chair, the norms are not abstractions for Tonga. When our national health information system was encrypted by ransomware last year, the norms on refraining from ICT activity that damages critical infrastructure, on protecting that infrastructure, and on responding to requests for assistance from states whose infrastructure is targeted were tested in the real world. We are grateful to the partners whose swift assistance embodied the cooperative spirit of those norms. And the sabotage of submarine cables, the threat that concerns Tonga most deeply, is addressed squarely by the existing norms on critical infrastructure. What remains is for all states to live up to them. Tonga therefore encourages this mechanism to devote its work under this pillar to practical implementation. We see 3 priorities. First, the voluntary checklist of practical actions annexed to the OEWG's final report should become a working tool supporting states to to survey and advance their own implementation. Second, implementation must be understood as a capacity question. Many states, including our own, require support to translate norms into national policy, legislation, and operational practice. Tonga is from here. We were the first Pacific Island country to join the Budapest Convention, and we know from that experience that international commitments become real through sustained domestic efforts patiently supported. Third, the dedicated thematic groups meeting in December offered the right setting for the granular expert-level exchange that implementation demands and their cross-cutting design should be used to connect norms implementation with capacity building rather than treating them as a separate conversation. Madam Chair, some may see a small island kingdom as an unlikely voice on questions of state behavior. We see it differently. States like Tonga rely more than any other on all states behaving responsibly. because we bear the consequences of irresponsibility most acutely and with the fewest defenses. The norms are our protection. Their implementation is our security. Tonga will continue to work with all partners in this room and in our region to move this pillar from articulation to action. I thank you.
Thank you. Thank you very much. I now give the floor to Australia.
Thank you, Madam Chair. Australia aligns itself with the statement delivered by the Kingdom of Tonga on behalf of the Pacific Islands Forum members and strongly supports its emphasis on the practical implementation of the 11 agreed voluntary non-binding norms. These norms are a fundamental pillar of the framework for responsible state behavior in cyberspace. Ways, but their value depends on whether they are understood, operationalized, and implemented by all states. Implementation remains an ongoing task for us all. States are progressing at different rates in identifying and protecting critical infrastructure, enhancing incident response capabilities, fostering whole-of-government approaches, and building the technical and policy foundations necessary to implement the norms effectively while continuing to review and update implementation mechanisms. The Global Mechanism should remain focused on helping states implement the norms that have already been agreed. This means supporting practical, action-oriented work that helps states move from endorsement to implementation and from implementation in principle to implementation in practice. The Global Mechanism should support states states to assess where they are in implementing the norms and where gaps or barriers remain. These barriers may be technical, institutional, financial, resourcing-related, or linked to awareness and coordination across government. A clearer understanding of these challenges will help ensure that capacity building is targeted, practical, and effective. To that end, Australia also considers the Voluntary Norms Implementation Checklist to be a valuable mechanism for supporting general implementation efforts. It can help states self-assess progress, share experiences and best practices, and identify where further support is needed. In addition to exploring the contribution of specific voluntary norms to the protection of critical infrastructure and critical information infrastructure, the dedicated thematic groups are well positioned to advance the work already commenced on the implementation checklist and further develop it as a tool, as a practical tool for states. We encourage the mechanism to continue this work and ensure that implementation gaps identified by states are linked to effective capacity-building support. Here again, we wish to highlight the role of multistakeholders. Effective implementation depends on collaboration with a broad range of stakeholders, regional organizations, the private sector, technical experts, academia, and civil society bring specialized knowledge and on-the-ground experience that can help states operationalize the norms and apply them in real-world contexts. Chair, Australia wants the global mechanism to be a place where the norms are made operational. It should— its work should strengthen implementation, support capacity building, enable peer exchange, and help all states apply the agreed framework in their national contexts. Thank you.
Gracias. Thank you. I now give the floor to Kiribati, to be followed by Malaysia, the Philippines, Ghana, Switzerland, and North Macedonia.
Madam Chair, Kiribati aligns itself with statement delivered by the Kingdom of Tonga on behalf of the Pacific Island Forum members. We associate ourselves fully with the Forum's position and speak now in our national capacity to give it a human face. Madam Chair, at the first session of the Permanent Mechanism, this pillar asked us a simple question: what are norms for? Kiribati's answer is that a norm is not a sentence in a report. It is a promise about how states will behave and a promise is only worth keeping it. We have 11 such promises agreed by consensus. They are real achievements. The work before us now is not to write more of them but to keep the ones we have. The Forum have spoken of implementation as a priority And of the varying stage our members are in operationalizing these norms. Let me tell you plainly what stage looks like for Kiribati. It looks like a young national CERT finding its feet. It looks like a new law, our Cybercrime Act, our Digital Government Act, our Data Protection Act, and our Cybersecurity Act, each one building the the last 5 years. It looks like identifying for the first time what our critical infrastructure even is, when our connection to the world rests on a submarine cable serving our eastern islands and a second cable about to bring our capital online, and satellite links carrying much of the rest of our nation into the internet. This is what implementation means for small island states. It's not a debate. It is the daily unglamorous work of building a house while the weather is already upon us. And this, Madam Chair, is why Kiribati speaks so firmly for implementation first. A small state cannot afford an open-ended renegotiation of what we have already agreed. We do not have the delegation to send, the benches of experts to spare, or the years to give, while the threats we face do not wait. Like what our colleagues from Tuonga outlined, every hour spent litigating the Third Road is an hour stolen from defending our people. For us, implementation is not a preference among many options. It's a matter of necessity. We therefore welcome with the Pacific Island Forum members the voluntary implementation checklist, and we ask this mechanism to take it forward in a concrete and action-oriented way through the dedicated thematic groups. But Kiribati asks for one thing more. A checklist tells a state what to do. It does not on its own tell a state like ours how to do it, or resources to do it. So let this mechanism bear the checklist with what actually builds capacity, such as consolidated guidance, honest mapping of where the gaps remain, peer exchange between states walking the same road, and the practical expertise that our technical partners, regional bodies, and stakeholders can bring into the thematic groups. That is our norm on BEPA becomes a norm in practice. Madam Chair, Kiribati does not foreclose the conversation some delegations wish to have about new norms in the meantime. The mechanism works in cycle with a review conference at which we can take stock together. That is our chance to act first on what we have agreed, to learn from the doing, and to consider what more is needed on the evidence of experience rather than on a session. But at this first session, our message and the message of our region is one message: prove these norms by living them. Madam Chair, the smallest states in this room are, in a sense, the truest test of these norms. If a norm protects Kiribati, a nation of 220,000 people, spread across an ocean, holding its connection to the world together with a handful of cable and satellite links, then it protects everyone. If it does not reach us, then it's not yet the universal commitment we claim it to be. We ask this mechanism to make this norm reach all of us. Kiribati, for its part, will keep its promise. We'll ask only that together we keep them for one another. I thank you, Madam Chair.
Thank you very much. I now give the floor to Malaysia.
Thank you, Madam Chair. The voluntary norms that states have agreed upon over the past decade remain a cornerstone of the UN framework for responsible state behavior. The framework rests on a foundation of voluntary Non-binding norms carefully developed through years of dialogue under the GGEs and OEWGs. They represent an essential complement to binding international law. They also provide us practical guidance on how to promote stability, reduce risks, and strengthen responsible behavior in cyberspace. That said, Malaysia believes that our immediate priority should be to strengthen the implementation of these norms. Cyber threat continues to evolve, and emerging technologies are adding new layers of complexity. The real test of these norms will be whether we can put them into practice. In Malaysia's view, there are 2 key actions we can take through the global mechanism. First, DTG1 offers a valuable platform for states to share experiences and challenges in implementing the 11 Voluntary Norms real-world scenarios. We see particular values in focusing on Norm G, which calls on states to protect their critical infrastructure. Given the increasing frequency and sophistication of attacks targeting such critical assets, this will help us identify common challenges, learn from one another, and develop practical approaches that actually work. Second, discussions from DTG1 should inform targeted and and needs-based capacity-building efforts under DTG II. Capacity-building must respond directly to the practical challenges that States have identified. In doing so, we can better support States in translating norms into national policies, institutional arrangements, and operational practices, taking into account their respective national circumstances and priorities. Madam Chair, at the regional level, ASEAN, has developed the ASEAN Norms Implementation Checklist that translates voluntary norms into practical actions and serves as a regional reference for national implementation. This is a concrete example of how international cooperation can also support the practical implementation of norms. Lastly, Madam Chair, Malaysia believes that the real value of the global mechanism will be measured by its ability to help states fulfill what they have committed to do even when those commitments are voluntary. Thank you.
Thank you very much. I thank all of the speakers who are inscribed on the list. Let me read the next ones: Philippines, Ghana, Switzerland, North Macedonia, Albania, and lastly Israel. Philippines, you have You have the floor.
Madam Chair, the Philippines believes that the immediate priority before the global mechanism is the effective implementation of the voluntary non-binding norms of responsible state behavior. These norms remain an essential component of the agreed framework for promoting international peace, security, and stability in the use of ICTs. Their value lies not only in the guidance they provide, but in how consistently they are translated into national practice and international cooperation. As the global mechanism begins its substantive work, we should focus on practical implementation. In this regard, the Philippines supports an implementation-oriented, action-focused global mechanism. We likewise believe that the dedicated thematic groups complement rather than duplicate the work of the plenary by generating practical consensus-based recommendations that assist member states in implementing the agreed framework. The voluntary norms provide practical guidance for reducing risk and preventing misunderstandings and promoting responsible state behavior in an increasingly interconnected digital environment. Their implementation strengthens national resilience While fostering confidence, transparency, and cooperation among states. At the national level, the Philippines continues to implement these norms through a whole-of-government approach to cybersecurity. Guided by the National Cybersecurity Plan 2023 to 2028, we continue to strengthen interagency coordination, cyber threat intelligence, incident response, and the protection of critical information infrastructure. We also continue to expand partnerships with the private sector, academia, the technical community, civil society, the international partners, recognizing that effective cybersecurity requires sustained cooperation across multiple stakeholders. The Philippines therefore supports continued voluntary exchanges of national experiences, implementation practices, and lessons learned. Such exchanges can strengthen collective understanding of how the voluntary norms are being applied in practice, identify implementation challenges and good practices, and strengthen cooperation in a manner that respects national circumstances, priorities, and levels of technological development. Over time, these practical experiences can also help inform discussions on whether additional norms may be beneficial in addressing emerging challenges while preserving the consensus-based and state-led nature of this process. As ASEAN chair in 2026, the Philippines continues to advance regional cybersecurity cooperation through the implementation of the ASEAN Cybersecurity Cooperation Strategy 2026-2030. To 2030. Regional initiatives including cyber exercises, trusted information sharing, operational collaboration among competent authorities, and the ASEAN Norms Implementation Checklist demonstrate how the voluntary norms can be translated into practical cooperation, strengthen trust and resilience among member states, and reinforce resilience across the region. The Philippines also believes that effective implementation benefits from appropriate technical expertise consistent with the global mechanism's agreed modalities. Accredited stakeholders can contribute operational experience, technical knowledge, and research to assist member states in implementing the agreed framework, particularly in understanding emerging technologies and addressing cyber threats. The voluntary norms have provided the international international community with a practical foundation for promoting responsible state behavior in cyberspace. Our shared task now is to ensure their effective implementation and to continue learning from that experience. The Philippines remains committed to working constructively with all member states to advance practical implementation, strengthen international cooperation, and contribute to an open, secure, stable, accessible, peaceful, and interoperable ICT environment. Thank you, Madam Chair.
Thank you. I now give the floor to Ghana.
Thank you, Madam Chair. Ghana comes to this first plenary with both a sense of responsibility and a strong commitment to the success of this global mechanism. Ghana has had the privilege of serving on the 2014-2015 Group of Governmental Experts, whose 2015 consensus report introduced the 11 voluntary non-binding norms of responsible state behavior. We also participated actively throughout the opening extended working group process. The establishment of this global mechanism reflects years of sustained dialogue, compromise, and collective effort. As we begin this new chapter, Ghana joins the African group in reaffirming that consensus should remain the foundation of our work, enabling us to deliver practical outcomes that strengthen resilience, build confidence, and support the meaningful participation of all member states. On norms, Ghana supports the continued use of voluntary checklists as a practical tool to assist states in implementing the framework, while recognizing that implementation must remain flexible and responsible to national circumstances. We also welcome the ongoing work of the African Union to develop guidelines on the implementation of the Voluntary Norms of Responsible State Behavior and the African Declaration on Peace and Security in Cyberspace, which will provide an important regional perspective and further support implementation across the continent. Madam Chair, Ghana believes that the value of the voluntary norms lies in their effective implementation. This requires sustained capacity building, strong partnership, and the sharing of best practices. Ghana remains committed to working with member states and all relevant stakeholders to advance the implementation of the framework in a practical, inclusive, and cooperative manner. Thank you.
Thank you very much. I now give the floor to Switzerland.
Thank you, Madam Chair. As we have heard from many other delegations, Switzerland believes that before developing new voluntary norms, we should focus on the implementation of the existing ones which were confirmed and endorsed by all States in the General Assembly. States stressed that these norms reflect the expectations and standards of the international community regarding the behavior of States in their use of ICTs and allow the international community to assess the activities of States. We see the global mechanism as a process that will enable us to make concrete progress in implementing these norms and the DGTs will play a central role in this process. In addition to the strategic discussions that will take place in the plenary session, the DGTs will hold more in-depth, targeted and scenario-based discussions on the specific topics that are relevant for States and the reality on the ground. UNIDIR could, for example, be tasked to develop such scenario-based discussions. discussions. During the discussions on threats, many states referred to the increasing intensity of ransomware attacks and state-sponsored cyberattacks against critical infrastructures. We therefore see merit in focusing on Norms 13, , , and , calling for the protection of all critical infrastructure supporting essential services to the public, medical and healthcare facilities, as well as cooperation between states for this purpose. States have recalled the importance of the principle of due diligence in this regard. Regarding ransomware attacks, it is important that states do not serve as safe havens for criminal groups and take measures against them. Switzerland stands ready to share its experience on mandatory reporting of cyber incidents affecting critical infrastructure or the timely information sharing between governmental authorities and operators of critical infrastructures via a secured platform as a concrete contribution to the capacity-building work of this mechanism. Similarly, our discussions should address the risk to critical infrastructures arising from malicious use of artificial intelligence by states, state-sponsored actors, and criminals, as well as risks stemming from vulnerabilities in the supply chain, data poisoning, and the manipulation of AI systems. Chair, Switzerland believes that cooperation with the non-governmental stakeholders is essential for the implementation of the voluntary norms. For that reason, Switzerland has established a Geneva Dialogue on Responsible Behavior in Cyberspace. The dialogue analyzes and maps the roles and responsibilities of various actors in implementing voluntary norms and ensuring the security and stability of cyberspace. The Geneva Manual is a product of this dialogue. The manual is a living document. The first 2 chapters of the manual focus on the norms related to supply chain security, reporting of ICT vulnerabilities, and the protection of critical infrastructure. Based on this experience, we are firmly convinced that broader, meaningful participation of stakeholders in the work of the global mechanism, in particular the DGTs, is not only necessary but also to the advantage of all states. Finally, we would like to thank the EU for the non-paper on the implementation of voluntary norms. This document, alongside other useful tools such as the ASEAN Voluntary Implementation Checklist, provides the global mechanisms and states with valuable guidance and resources for putting the voluntary norms norms into practice. I thank you.
Thank you very much. I'll now give the floor to North Macedonia.
Thank you, Madam Chair. As this is the first time my delegation takes the floor, allow us to express our appreciation for your guidance throughout the intersessional period. We would also like to thank you for the efficient appointment of the co-facilitators which has provided a solid basis for advancing our work. North Macedonia aligns itself with the EU statement delivered by this agenda item. And in our national capacity, we wish to highlight the following brief remarks. As we begin our discussion on norms, rules, and principles, we believe that the global mechanism should remain practical, inclusive, and implementation-oriented. Our efforts should focus on supporting the efficient implementation on an existing framework of responsible state behavior in cyberspace, including the 11 voluntary non-binding norms agreed by all member states. Their effective implementation contributes to greater transparency, predictability, and accountability of state behavior in cyberspace, while strengthening trust and international security. In this regard, thematic discussions will provide a valuable opportunity to exchange national experiences, share good practices, and identify practical approaches that can support implementation at the national level. We believe that continued exchanges of national experiences and practical approaches will enrich our discussions and support the effective implementation of the agreed norms. We look forward to engaging constructively throughout this process. I thank you.
Thank you very much. I now give the floor to Albania.
Thank you, Chair. Albania fully aligns itself with the statement delivered by the European Union And would like to add the following remarks in its national capacity. For Albania, the implementation of agreed UN norms is essential. Their value lies not only in the political commitment, but in their translation into national legislation, institutions, operational procedure, and international cooperation mechanisms. Albania has approved as and has enforced the law on cybersecurity since May. 2022, which fully transposes the EU NIS II Directive. In accordance with the provisions of this directive, all implementing bylaws have now been adopted, providing the necessary legal framework for the operationalization of national cybersecurity structures and the functioning of the national cybersecurity ecosystem. The adopted sublegal acts regulate, among other matters, the organization, responsibilities, and functioning of the National Cybersecurity Authority, the Cybersecurity Emergency and Crisis Response Team, the procedures for identifying, classifying, escalating, and managing cybercrisis and large-scale cybersecurity incidents, the identification and protection of critical and important information infrastructure, and assessment and analysis of cybersecurity risks, the national cybersecurity certification scheme and the registration of cybersecurity conformity assessment bodies, organizational, technical, and operational cybersecurity measures, coordinated vulnerability disclosure, et cetera. Part of this sublegal act is also the national cybersecurity strategy. Strategy 2530 and its action plan, and it gives policy goals covering protection and digital infrastructure, online protection of citizens and promotion of cybersecurity culture, strengthening international cooperation, promotion of innovation and scientific research, and protection against hybrid threats. This act give concrete effect to the application of the agreed UN norms. Just to provide a few examples, Albania has now fully operational cybersecurity structures such as national SOC and CERT. The establishment of national cyber incident monitoring and response structures, together with cybersecurity strategy procedures for cyber incident and crisis management, The identification of critical and important infrastructure, information infrastructure, and cybersecurity measures supports several norms such as preventing harmful ICT practices and activities, considering all relevant information in cases of ICT incident, on information exchange to address such threats, and on protection of critical infrastructure from ICT threats, while also strengthening Albanian capacity to cooperate with partners at national and international level. Cybersecurity certification frameworks contribute to supply chain security and assurance, while Albania is currently in the process of harmonizing its legal framework with the EU Cybersecurity Resilience Act, which will further contribute to this norm. Having in place a coordinated vulnerability disclosure policy the necessary technical capacities to discover and address them, such as national SOC and CERTs, and the mechanisms to share information with critical and important information infrastructures to take the necessary measures, directly support the norm of responsible reporting of ICT vulnerabilities and sharing information to limit and possibly eliminate potential threats. Clearly, Albania is practically implementing UN norms, rules, and principles of responsible state behavior in cyberspace. And we believe that the Global Mechanism should place practical implementation at the center of its work on norms, rules, and principles. The dedicated thematic groups can provide an inclusive space to share national practices, identify legal, institutional, and capacity gaps, and develop action-oriented recommendations and measures. In this regard, Albania calls upon all states to strengthen their commitment to the voluntary norms of responsible state behavior. In particular, states should ensure that their territory and ICT infrastructures are not knowingly used for internationally wrongful acts conducted through ICTs against the critical infrastructure and essential services to other States. States should also cooperate in preventing, mitigating, and responding to malicious ICT activity, and provide assistance where appropriate when critical infrastructure is subjected to malicious cyber operations. Albania further emphasized the importance of protecting the integrity and functioning of computer emergency response response team and computer security incident response teams, whose work is essential for maintaining international cybersecurity and resilience. We also encourage all states to support responsible vulnerability disclosure practices and to promote greater security and integrity throughout the ICT ecosystems. Strengthening those commitments will contribute to reducing opportunities for malicious actors to exploit vulnerabilities and conduct harmful cyber operations. Albania remains committed to the UN Framework of Responsible State Behavior in Cyberspace and stands ready to contribute constructively to the work of the Global Mechanism and its dedicated thematic groups in this regard. Thank you, Chair.
Thank you. I give the floor to Israel.
Thank you, Madam Chair. Israel's position on the framework of responsible state behavior remains firm, consistent, and carefully considered. In our view, there is no need to develop or elaborate upon any new norms before we adequately address the gap in compliance to the current framework. The reality of the current landscape demonstrates that the voluntary and non-binding norms established in 2015 are currently being floated by certain states. As we've highlighted when we discussed the existing potential threats, malicious actors continue to disregard this framework we all agreed upon. Against this background, we also see no need to develop legally binding instruments. Pursuing efforts and attempting to develop a legally binding instrument without the underlining of broad agreement on key concepts would waste the considerable diplomatic capital invested in the GMAC as well as its potential. Such an effort would be both premature and counterproductive. This does not mean that we should not celebrate our collective achievements so far and continue to further refine the normative framework we have built together for responsible state behavior. This framework, including the 2015 GGE norms, rules, and principles, which are voluntary and non-binding, signals the expectations of the international community for state activity in the cyber domain. We should focus the efforts on strengthening the implementation of the existing voluntary norms and promoting a broader shared understanding of this framework. In our view, the DTGs could provide a practical cross-cutting forum for sharing national best practices and evaluating whether and how the existing norms of responsible state behavior are understood and applied. Furthermore, the DTGs could offer an opportunity to revisit ideas that could not have been adequately discussed in sufficient length and thoroughness in the non-permanent process. For example, the DTGs can serve as a much more appropriate platform to contemplating the implementation checklists explored in APR3 report in a more granular and cautious way. Such checklists provide that they are carefully revisited, considered, and redrafted as necessary. Could serve as a voluntary tool for developing a common language and understanding. Finally, Madam Chair, and in response to the Iranian regime's representative, Israel will not dignify the ridiculous and exaggerated claims the Iranian regime just made with a detailed response. Despite the constructive engagement by vast majority of delegations, and despite repeated calls by many delegations here to avoid politicization, and despite Your chair's call for the member states to present professional and constructive contribution, Iran seems adamant to impudently waste our time. In doing so, the Iranian delegation continues to show Iran's determination to disregard the international community and to disrespect other member states, both inside this and outside this building, in the cyber domain and in other domains. We invite all delegations here to draw their own conclusions on where this vile approach will lead us. Thank you.
Right, we have concluded the list of speakers under this agenda item. However, a right of reply has been requested, and so I give the floor to the Russian Federation.
Distinguished Chair, my delegation was forced to use its right of reply with regard to the outrageous anti-Russian attacks from the Ukrainian delegation. The accusations leveled against my country are not only false and groundless, but are ridiculous. The irony is that the victims of computer attacks attacks— or they're trying to say they're victims of cyberattacks when actually they're a country that have become a hub for hackers and online fraudsters acting with support of their own government with a single goal: to damage the Russian civilian infrastructure and to defraud Russian citizens. And in this case, we don't even need to prove the participation of Kyiv in many attacks. Because the officials of that country themselves have repeatedly acknowledged and even bragged about carrying out these attacks against Russia. It is a well-known fact that Ukraine has become the largest haven for online fraudsters in the world. The number of these so-called call centers which defraud retirees and blackmail and extort people and encourage young people to carry out terrorist attacks in Russia number in the thousands. And the victims of these attacks are not only Russians but also Europeans, citizens of those countries that are sponsoring the defrauding of Russians. Chair, it's difficult for me to call any of this a norm of responsible state behavior in the list as laid out by the UNGA. They've been violated by Ukraine in the most glaring manner. It's clear that there is no more brazen violator of the framework of responsible state behavior than Ukraine. Thank you.
Gracias. Thank you. I give the floor to the delegation of the Islamic Republic of Iran. take it that is also for a right of reply.
Thank you, Madam Chair. In response to the absurd and misleading remarks we have just heard from the representative of the Israeli regime, I wish to make one brief observation. The action of the Israeli regime in our region, particularly its 2 unlawful acts of aggression against Iran over the past year, a strike and at the very foundation of every pillar of the global mechanism, just as they strike at the very foundations of international law and the Charter of the United Nations. Referring to these actions neither politicizes nor derails our discussions or wastes time. On the contrary, they constitute a clear illustration of the very malicious ICT activities that this process seeks to prevent and address, thereby assisting member states in deepening their discussions and informing the work of the global mechanism. I thank you, Madam Chair.
Gracias. Thank you. I give the floor to the delegation of Ukraine to exercise the right of reply.
Madam Chair, I would like to exercise the right of reply tomorrow during the session of tomorrow, not to keep the delegations over time, please. Thank you.
Gracias. Thank you. However, I would like to point out that we have an additional 10 minutes thanks to the interpreters. So if you would like to use your right of reply now, you may do so. Okay. Bueno. All right. Well, we would have preferred to close this item today, but we do note that request. What I'm going to do now is similar to what I did with the former agenda item which is I'm going to share with you some very general reflections. It is not intended to be any kind of exhaustive summary, but I do want to perhaps touch on some of the questions that we have heard raised by a number of delegations. We have noted that there has been an emphasis on shifting to implementation. This is— of major significance for all states, but I think especially so for small ones given their realities and national circumstances. I have also heard calls to continue the discussion on common understandings as to how these norms will be applied in practice and the global mechanism through the DG TEAS, this will be the main forum for these exchanges. A number of you also mentioned the checklist for implementation. A number of you also emphasized that additional norms could also be considered given the evolving nature of the digital environment. I've also heard a lot of you highlight the interconnection of the norms with some of the pillars, especially capacity building, underscoring that this should be shored up by the various diplomatic and other institutions of states. So it does seem that there is a great deal of common sentiment as regards implementation, so thank you very much for that. In this regard, the global mechanism will We will meet again tomorrow at 10:00 a.m. in this same room. Please come prepared to begin with the agenda item on the continued study of how international law applies in the use of ICTs, including consideration of whether gaps exist and the possible future elaboration of additional legally binding obligations if appropriate. And so before I adjourn the meeting for today, I would like to remind you that tomorrow afternoon at 3:00 PM, according to our program of work, we will be holding the dedicated stakeholder segment under the work of this mechanism. I would encourage delegations also to participate actively in that stakeholder segment. If there is any time remaining, we will continue with the speakers' list to try and conclude the morning session. The meeting is adjourned. Thank you.