Substantive Plenary Session of the new Global Mechanism on Information and Communications Technology (ICT) Security.
Discussions on the five pillars of the framework for responsible State behaviour in the use of information and communications technologies in accordance with annex C of A/79/214 and annex I of A/80/257 Existing and potential threats
Machine-readable formats: Plain text · JSON
Transcripts available through this tool are created by using automatic speech recognition and are not official records nor official documents of the United Nations. Official records and official documents are available on the Official Document System of the United Nations. Learn more
The third meeting of the substantive plenary session of 2020. 26 of the Global Mechanism on Developments in the Field of Information and Communication Technologies and Advancing Responsible State Behavior. Good morning, delegates. As I announced yesterday, we first of all need to complete the list under current and potential threats. We have 30 remaining requests on this list. So as indicated yesterday, while there is no established limit for delivering statements, it would be appreciated if you could deliver an abridged version and submit the full statement to e-statements and also to the chair's team. This would help us hear all delegations. And also just for reference, we are going to be projecting a timer on the screen. Let us proceed then with the list of speakers as it stood yesterday. And so I am going to give the floor to the first 5 speakers. They are Egypt, Kiribati, New Zealand, Tonga, and Kingdom of the Netherlands. Egypt, you have the floor.
Thank you, Madam Chair.
Good morning to all colleagues. First, allow us to congratulate you on the smooth moderation and chairing of the session. And as the topic we're discussing, I have a few points to share. First, Egypt views threats that they are not specific to certain regions or countries. All countries and regions have equal rights to see the challenges and threats they deem as national priorities to be reflected and discussed equally in the plenary and in the thematic groups. For the second point, discussions of those threats in the dedicated thematic groups cannot go business as usual and cannot be a replica or mirror the discussions of those threats in the plenary, because this will not only be a waste of time, but it will also be a miss of a very useful opportunity for all delegations. For this to happen, Egypt is of the view that we need to focus on 2 main aspects on how we discuss threats. First, the discussions should be dynamic, based on real-case scenarios, where we discuss a threat from all aspects and First by analyzing it and then seeing how to deal with it in coordination with the national authorities, regional authorities, and even seeking help for international cooperation. And the second aspect, and we deem this aspect as the most important factor in discussing those threats, is that we have to compile and agree on a pool of experts that will help us in those discussions. Having discussions on threats without a professional, experienced, and relevant pool of experts is again a waste of time. So it's our view again that discussions on threats in the dedicated thematic groups should be based on a proper and accepted pool of experts by delegations. This is not to say that we will use certain tactics to block certain experts we don't want to see. Consensus is the key. That's true, but we should put in our minds that the bigger picture is to have a relevant pool of experts to help us as diplomats understand the threats and produce tangible outcomes. Thank you, Chair.
Muchísimas gracias.
Thank you very much. I now give the floor to Kiribati.
Madam Chair, I will be very brief. Kiribati aligns itself with the statement delivered by the Kingdom of Tonga on behalf of the Pacific Island Forum members and offers the following remarks in its national capacity. Madam Chair, this is the first substantive session of a permanent mechanism, and this is no small thing. For years, our collective work on ICT security has moved from one limited-time process to the next, while the threats we face have never paused between them. This mechanism gives us at last a standing home for this work. Kiribati welcomes that permanence, and we encourage that this mechanism was— encourage that this mechanism was designed to be action-oriented. We intend to hold it and ourselves to that standard, beginning with how we treat the threats before us. Madam Chair, the threat landscape is not abstract for Kiribati. Last year, East— the East Micronesian cables landed on— at Tarawa, the first submarine cable ever to reach our capital, connecting Nauru and the Federated States of Micronesia. This connectivity is transformative. It underpins our Digital Government Master Plan and our delivery of services across some of the most dispersed islands on Earth. But we are clear-eyed. Every step forward in connectivity is also a step forward in exposure. For a nation served by a small number of cables, landing stations, and satellite links, Critical infrastructure protection is not one threat among many. It is existential. Damage to or disruption of our submarine cable, whether by malicious cyber activity or otherwise, will not degrade our services. It will sever them. We are equally concerned by the threat that arrives first for our newly connected communities. Cyber-enabled fraud and scams, phishing, ransomware against government systems, and online harm directed at our children. These threats do not distinguish between large and small states, but they impact far hardest on those with the least redundancy and the thinnest technical workforce. Kiribati is not standing still. Our Cybercrime Act 2021, Our Digital Government Act 2023, which established our national CERT and cybersecurity mandate of our Digital Transformation Office, our Data Protection Act 2025, and our new Cybersecurity Act 2026 form the legislative backbone of our response, building on our National Cybersecurity Strategy. This is what a small state can do with its own hand. But national action has limits that only cooperation can overcome. And cooperation is the very reason these mechanisms exist. Madam Chair, our Helsinki symbol— we make it in the spirit of a first session that should set the tone for all that follow. Discussion of threats must not end as descriptions of threats. Each threat identified in this room should connect to a concrete step through this plenary and through the dedicated thematic groups, or DDGs, in December. That leaves every state, including the smallest, better able to prevent, detect, and respond. If this mechanism can do that from its very first session, it would have proven its worth. Not only to the states in this room, but to every community that depends on us to get this right. I thank you, Madam Chair.
Muchísimas gracias.
Thank you.
I now give the floor to New Zealand.
Thank you, Chair.
We support the statement by the Kingdom of Tonga on behalf of the Pacific Islands Forum and offer some additional remarks in our national capacity on three aspects. Of the threat environment. First, as elsewhere, ransomware continues to have serious consequences in New Zealand, with opportunistic actors impacting organisations in all sectors of the economy. We have spoken out publicly on some ransomware incidents, as have others in the Pacific who have also been affected by ransomware affecting the healthcare sector. Second, we have heard many delegations speak on the need to protect the cybersecurity of critical infrastructure. This is something we're working to address domestically at the moment. In doing so, we are studying closely the steps that others in this room have taken as we look to learn lessons that we can apply in our own context. This is an example of why we continue to value exchanging information on threats and best practice in addressing them. We hope that discussions in the DTGs can also serve this function. Finally, Artificial intelligence is rapidly transforming the cybersecurity landscape. We welcome the opportunity to hear how others are seeing AI affect cybersecurity risks and what they are learning about how this powerful technology can support cybersecurity defense. We also note that there are a variety of other UN processes that are actively grappling with questions related to artificial intelligence, including governance issues. It's important that the global mechanism does not duplicate those processes. Instead, it should only focus on the issues that it is uniquely well placed to add value, namely in building shared understanding of the implications of AI for cybersecurity.
Thank you.
Muchísimas gracias.
Thank you very much. I now give the floor to Tonga, to be followed by Netherlands, Bahamas, Iran and Australia.
Thank you, Madam Chair. Tonga aligns itself with the statement delivered by my colleague on behalf of the Pacific Islands Forum members and offers the following remarks in its national capacity. Madam Chair, when the mechanism discusses threats, Tonga does not speak abstractly. We speak from memory. In January 2022, the eruption of Hunga Tonga-Hunga Ha'apai severed the single submarine cable connecting our kingdom to the world. For weeks, Tonga was silent, cut off at the very moment we most needed to call for help, coordinate relief, and reassure families abroad that their loved ones were safe. Our 'aira islands waited far longer still. This was nature's work, But we ask this room to consider that we learned— what we learned, everything a volcano did to Tonga by accident, a malicious actor could choose to do deliberately. This is why Tonga regards the sabotage of submarine cables and other critical infrastructure not as a distant scenario, but as one of the gravest threats before this mechanism. It is why we joined the 2024 Joint Statement on the Security and Resilience of Undersea Cables and why we urge all states to treat the protection of this infrastructure against intentional and unintentional damage alike as a shared responsibility under the framework of responsible state behavior. Our concern with man-made disaster is not confined to the seabed. In June last year, a ransomware attack encrypted our national health information system, holding the medical records of our entire population to ransom and forcing our hospitals back to pen and paper. Our state-owned telecommunications provider was attacked in 2023. These incidents against the essential services of a small state show that no country is too too small or too remote to be targeted. But Tonga's experience also shows what cooperation can achieve. With the support of partners, our health systems were restored and services maintained. And this year, together with Australia and New Zealand, Tonga jointly attributed the attack on our Ministry of Health to an affiliate of a known ransomware group demonstrating that even the smallest states acting with partners can pursue accountability for malicious cyber activity. Madam Chair, Tonga's message on threats is therefore simple. We have lived the disconnection others theorize about, and we have endured the attacks others read about. We ask that this mechanism honor that experience by ensuring that every threat discussed here is matched by practical cooperation to prevent it, withstand it, and respond to it for all states of every size. I thank you.
Muchísimas gracias.
Thank you very much. I now give the floor to the Netherlands.
Thank you, Madam Chair. The Kingdom of the Netherlands aligns itself with the statement delivered by the European Union, and please allow me to make some further comments in my national capacity. Over the course of last year, the Kingdom of the Netherlands has observed a steady increase in the scale, sophistication, and diversity of cyber incidents affecting our society. Attacks range from ransomware to disruptive DDoS campaigns and exploitation of vulnerabilities in edge devices and widely used software. These incidents impact our society at large, having implications for vital sectors like public administration, healthcare, education, transport and financial services, as well as for the many international organizations based in the Netherlands. Madam Chair, we would like to highlight 3 emerging threats. First, the Kingdom of the Netherlands considers the observed blurring of lines between state actors and non-state actors, such as hacktivist groups, as one of the most problematic trends in the current threat landscape. Different types of actors increasingly use similar tools, target similar systems, and sometimes operate in concert. This blurs the traditional distinctions between motives and methods and constitutes a worrying trend of state actors hiding behind state proxies to maintain plausible deniability. Second, in the last year, critical infrastructure has been repeatedly targeted and continues to face persistent risks. Especially the recent shift towards the targeting of means of communications, such as messaging services, is troublesome, as such infrastructure underpins the functioning of almost all critical sectors. Compromises can enable large-scale espionage, manipulation of communications, or disruptions with cascading effects far beyond the specific target itself. This underlines the need for continuous investment in resilience and secure architecture across all critical sectors, as well as structured dialogues in this global mechanism on how to best protect our critical infrastructure from malicious cyber actors. The Netherlands is keen to engage with UN members to exchange best practices on the protection of critical infrastructure, from a policy and operational perspective. And third, generative artificial intelligence amplifies existing cyber threats. Large language models and other AI systems can lower the barrier for conducting sophisticated operations. From writing convincing phishing messages, to assisting in the discovery of zero-days, vulnerabilities, and their exploitation. With the use of agentic AI on the rise, the development of such threats continues to accelerate, making the threat landscape more complex by the day. These same tools can and should be harnessed defensively, for example, to improve detection, analysis, and response. Madam Chair, as the threat landscape that we collectively face continues to grow ever more complex, it is through the adequate implementation of the consensus UN framework that we can try, and we should try, to inject a degree of predictability in global affairs. Thank you very much.
Muchísimas gracias.
Thank you. I now give the floor to the distinguished representative of the Bahamas, to be followed by the Islamic Republic of Iran and then Australia. Microphone for the Bahamas, please.
Madam Chair.
Good.
Go ahead.
Madam Chair. As this is the first time I am taking the floor, the Commonwealth of the Bahamas congratulates you on your assumption of the chair of the inaugural Global Mechanism and offers its full support for your role, mandate, and vision. We look forward to working with you and alongside fellow delegates. The establishment of this Global Mechanism is a milestone built on years of work in the Open-Ending Working Group, and the Bahamas is committed to building on that foundation and to ensuring it delivers real security for those most exposed by digital risk. As a Small Island Developing State, the Bahamas knows that cyber resilience is built through collaboration, cooperation, and coordination, but also through public-private partnership. But above all, it's built by people and for people. It's against this backdrop that we underscore 3 priorities. First, cyber threats to youth.
Youth—
young people are the fastest adopters of digital technology and will live with the consequences of decisions made in this room. The Bahamas supports deliberate efforts to engage youth in capacity building, training, and dialogue on ICT security. ICT security, sorry. Second, cyber threat to women. We call for concrete attention to technology-facilitated gender-based violence, including online harassment and image-based abuse, which disproportionately target women and girls and threaten both their safety and their participation. Therefore, participation for women is not complete unless women are at the table, in delegation, in technical decision-making, and in the design of national ICT policies. We support continued effort to close the gender digital divide. Third, capacity building. For Small Island Developing States, capacity building is a precondition for participation. It must be sustained, tailored to national circumstances, and directed towards durable institutions and a trained workforce, so that developing states can be genuine contributors to global ICT security, not just recipients of it. Madam Chair, the Bahamas welcomes the dedicated thematic groups as a platform for translating dialogue in practical outcomes. Including identifying capacity-building needs and ensuring developing countries participate meaningfully. In the threat landscape— sorry, the threat landscape is a pressing concern for us. Our economy depends on digital-enabled sectors, for example, tourism, financial services, port and maritime logistics. So we're faced with ransomware, cybercrime as a service, attacks on our critical infrastructure, AI-enabled fraud, the mis- and disinformation, and very importantly, the nexus between cyber threat and natural disaster. They all carry consequences for small island states that are disproportionate to our size. In response, we have launched the National Computer Incident Response Team in December 2023, adopted a national cybersecurity strategy in 2024, our Data Protection Act in 2025, and we are advancing a national cybersecurity bill and a child online protection strategy. We recommend that cyber threat discussions remain grounded in the operational experience of national CERTs and CCERT networks, that cyber threat information sharing be genuinely accessible to small island states, and that this work stay connected to capacity building. Finally, Madam Chair, international law, including the UN Charter, is the foundation of a secure and peaceful ICT environment. It is the guarantee of this process, not a constraint to it. Voluntary norms and confidence-building measures operate in service of a binding legal obligation, not in place of them. In closing, the Bahamas calls on the global mechanism to keep international law meaningful, inclusion and sustainable capacity building at its center. to advance a secure and stabilized IT environment for all. I thank you, Madam Chair.
Thank you very much for that statement. We will now hear from the representative of the Islamic Republic of Iran.
You have the floor.
Madam Chair, distinguished colleagues, over the past year, the United States and the Israeli regime have carried out unlawful military attacks against the Islamic Republic of Iran. These acts of aggression resulted in the loss of thousands of innocent lives, including hundreds of women and children, and caused widespread destruction of civilian infrastructure. These unlawful attacks were accompanied by extensive malicious cyber operations directed against Iran's critical infrastructure and civilian services, disrupting the daily lives of our people and the functioning of essential services. While my delegation has addressed the kinetic dimension of these attacks in other relevant international forums, this forum provides the appropriate platform to address their cyber dimension. During the February 2026 aggression alone, more than 100 cyberattacks were launched every day against Iran's critical and civilian infrastructure. These operations include in their inter-area: first, coordinated cyber and kinetic attacks targeting critical ICT infrastructure, including telecommunications facilities, data centers, artificial intelligence infrastructure, and private sector electronics and ICT manufacturing plants. Critical sectors affected included the banking and financial system, telecommunications networks, energy facilities, fuel distribution systems, industrial control systems, and other infrastructure providing essential public services. Second, cyberattacks against civilian institutions and essential services, including schools, universities, media and broadcasting infrastructure, and digital platforms supporting education and public communications. With the aim of disrupting public services and the daily lives of ordinary civilians. Third, attacks exploiting private sector technologies and ICT supply chains, including commercial ICT products and services, software, hardware, and digital supply chains, as well as the misuse of Starlink satellite communication services to facilitate hostile operations. My delegation is also concerned by cyber operations exploiting commercial technologies, including products and services supplied by companies such as Cisco and HP, to undermine the security and resilience of national ICT infrastructure. Fourth, cyber espionage and information operations, including attacks against telecommunication networks, the unlawful use of mobile interception technologies, cyber-enabled surveillance, disinformation and cognitive operations, and the manipulation of digital platforms, including Instagram, X, and Telegram, to incite violence, spread hatred, deepen social divisions, and arbitrarily restrict or remove accounts associated with the Islamic Republic of Iran. Fifth, electronic warfare and hybrid operations, including cyber-enabled support, for military operations, interference with communications and satellite navigation systems through jamming and GPS spoofing, and the integration of cyber capabilities with conventional military attacks. States that consistently advocate respect for the Charter of the United Nations, international law, and the framework for responsible state behavior in ICTs should apply those principles consistently and condemn such kinetic and malicious cyber activities directed against the Islamic Republic of Iran. The United States and the Israeli regime must be held accountable for these violations. Madam Chair, the experiences of my country, particularly those arising from the unlawful cyber and kinetic attacks carried out by the U.S. and the Israeli regime, underscore the need a more comprehensive and shared understanding of existing and emerging threats. While the OEWG made important progress, there is still no common understanding that fully reflects the security concerns and experience of all member states. From the outset of the OEWG process, a number of states, including my own, identified specific ICT-related threats that were ultimately not reflected in the consensus reports. Addressing these gaps should therefore be a priority for the global mechanism. In our view, the global mechanism should first give due attention to the threats already identified by member states before expanding discussions on new threat areas. We therefore support the preparation under your authority of a consolidated compilation of the threats identified by member states and reflected in the first OEWG Chair's Summary as the basis for discussions in both the plenary and the dedicated thematic groups with a view to develop practical cooperative measures to prevent and address such threats. In this regard, my delegation wishes once again to draw attention to a number of threats previously identified by Iran, including the weaponization of the ICT environment, monopoly in internet governance, false flag operations and fabricated attribution, the use of ICTs for disinformation and cognitive operations, unilateral coercive measures in the ICT domain, and the responsibility— responsibilities of private sector entities and digital platforms whose activities have extraordinary extraterritorial impacts. I thank you, Madam Chair.
Thank you very much.
I now give the floor to the delegation of Australia, to be followed by Japan, Guyana, Greece, the United States, and Tuvalu. Australia, you have the floor.
Thank you, Chair. Australia aligns itself with the statement delivered on behalf of the Pacific Islands Forum and would like to make a few comments in our national capacity. As we begin the work of the global mechanism, Our discussions on threats should be current, evidence-based, and connected to practical implementation of the framework of responsible state behavior in cyberspace. The cyber threat environment continues to intensify. Individuals, businesses, and governments continue to be adversely affected. Those threats can expose sensitive information, disrupt essential services, undermine trust and economic prosperity, and contribute to the risks to international peace and security. These threats are real. Last year, the Australian Cyber Security Centre responded to over 1,200 cybersecurity incidents and received more than 84,700 cybercrime reports, roughly one report every 6 minutes. No country is immune to persistent threats. These include state-sponsored activity targeting government, critical infrastructure and businesses, ransomware and cybercrime as a service, business email compromise, identity fraud, and exploitation of edge devices and systems. This mechanism should help states understand how these threats affect us, the practical steps that reduce risks, and how international cooperation can support mitigation, preparedness, and response. The tools already available to us international law, the norms of responsible state behavior, confidence-building measures, and effective capacity building are well placed to help states meet these threats in a practical and coordinated way. Critical infrastructure and critical information infrastructure protection should be an early focus for this mechanism, including through DTG1. For many countries, including our own, in the region, The resilience of undersea cable infrastructure is fundamental to economic and social connectivity and to access to the global internet. The mechanism should also help states understand and respond to the ways emerging technologies are changing the scale, speed, and character of malicious activity. Artificial intelligence is being used to scale social engineering, create more convincing phishing content, and analyse stolen data, and lower the cost and skill barriers required to cause harm. Australia is particularly concerned that AI is making it easier for malicious actors to generate and spread propaganda and to prepare to carry out physical strikes by supporting planning and target selection. As capabilities advance, AI may also enhance the ability for malicious actors to coordinate complex activities that combine physical and digital elements. Australia underlines the importance of responding to these threats in line with the agreed norms of responsible state behaviour. State responses, including the development and use of cyber capabilities, must be consistent with international law, including the UN Charter in its entirety, international human rights law, and international humanitarian law. All states must be supported to build capacity to implement the framework and respond to the threats they are facing. Cyber threats are shared, but their impacts are not experienced equally. Differences in national capacity can affect vulnerability to malicious cyber activity and the ability to recover when incidents occur. Australia looks forward to working with all states, as well as you, Chair, to ensure that our discussions on threats, particularly within the DTGs, remain current, practical, and directed towards implementation. Thank you, Chair.
Muchísimas gracias. Doy ahora la palabra.
Thank you very much, Japan. You have the floor.
Thank you, Madam Chair. As cyber threats have continued to grow due to increasingly sophisticated and complex methods of cyber attacks, ensuring a free, fair, and secure cyberspace based on the rule of laws has become indispensable for all. Member states. In addition, with the advancement of frontier AI models, responding to malicious cyber activities that leverage AI is also an urgent challenge, while AI models also provide opportunities for cyber defense. In cyberspace, attackers hold an overwhelming advantage. It is important to have broad discussions on a wide range of approaches, from efforts to create an environment where attackers find it more difficult to operate, to efforts by defenders to raise the cost of cyberattacks through improved security. Focusing on critical infrastructure, Japan recognizes that cyberattacks using ransomware, particularly when they impair the operations of critical infrastructure, such as hospitals and power plants, can pose a threat to international peace and security. For example, at the Security Council briefing on ransomware on November 8th, 2024, Japan stated that ransomware is one of the most destructive cyber threats, undermining the operations of critical infrastructure in society, including hospitals and power plants. Given the overall impacts and ramifications, ransomware could certainly pose direct threats to international peace and security. Japan would like to foster this kind of a common understanding on existing and potential cyber threats in the UN global mechanism. Lastly, in conducting such discussions, it is essential to draw on the expertise of a wide range of stakeholders, including the private sector. Japan also places great importance on holding expert briefings and interactive public-private discussions in the substantive plenary sessions and DTGs. I thank you, Madam Chair.
Thank you very much. I now give the floor to the delegation of Guyana.
Thank you, Madam Chair. At the outset, Guyana congratulates you on your appointment as Chair of the Global Mechanism on ICTs and assures you of our full support. Guyana believes that discussions on existing and potential ICT threats in the context of international security are critical as we advance the framework for responsible state behavior in the use of information and communications technologies. The ICT threat landscape is evolving rapidly due to growing developments in ICT capabilities without concomitant oversight and governance structures. Effectively addressing existing and potential threats requires integration of security considerations across the lifecycle of ICT products. While acknowledging the benefits of using ICTs for development, Guyana is concerned about the malicious use of ICTs which can undermine peace and security, erode trust among states, and constitute a violation of international law. We are particularly concerned about the malicious use of ICTs against critical information— critical infrastructure and critical information infrastructure, and the use of this technology by non-state actors to exacerbate conflicts, including through attacks targeting civilians and civilian objects. A holistic approach is therefore required to address ICT threats considering the multifaceted challenges and transboundary nature of these threats. Awareness, capacity building, international cooperation, public-private partnerships, and continued dialogue among relevant stakeholders are essential for detecting, defending, and responding to these threats. These efforts must be made at the national, regional, and international levels. At the national level, Guyana is building its ICT infrastructure, and we are strengthening our digital resilience and cybersecurity security capabilities. In this regard, we have enacted legislation on data protection and cybercrime and have developed a cybersecurity policy framework. Guyana is also looking at establishing a cyber emergency response system to respond to cyber threats on a 24/7 basis. And moving forward, Guyana recognizes the urgency of stronger cooperation and collaboration among states as we seek to address ICT threats in the context of international security. GAN also stresses the need for continued multilateral engagement to generate awareness and address ICT threats towards promoting a safe ICT environment. I thank you, Madam Chair.
Thank you very much. I now give the floor to Greece.
Madam Chair, First of all, I would like to thank you, you and your team, for all your efforts so far facilitating a smooth transition from the OAWG to the Global Mechanism. Once again, you have our full support in your endeavor to reach concrete outcomes. On the topic at hand, Greece aligns with the statement made by the European Union, and please allow me to make the following remarks in my national capacity. Distinguished delegates, We are witnessing a rapid-evolving threat landscape where the misuse of emerging new technologies such as artificial intelligence, the growing prevalence of ransomware, and the proliferation of sophisticated cyber tools pose significant risks to international peace, security, and human rights. These emerging threats increasingly target critical infrastructure, public institutions, businesses, and individuals, often with cross-border consequences. While AI offers great potential for innovation and global progress, its misuse, such as through autonomous cyber tools and the recent advancement of frontier models, can amplify existing vulnerabilities and undermine democratic processes and human rights. These capabilities are expected to soon become widely available, and they significantly lower the entry barrier for actors to perform sophisticated attacks. In this context, last year Greece, as a non-permanent member of the Security Council, organized an Area Formula meeting on harnessing a safe, inclusive, trustworthy AI for the maintenance of international peace and security. Another important topic relates to the proliferation of commercial cyber tools and capabilities. The commercial distribution of these capabilities has the potential to undermine privacy, human rights, democratic institutions, and international security when deployed without adequate safeguards. In this regard, we welcome initiatives such as the POMOL process, which seek to build international consensus on the responsible development, distribution, and use of commercial cyber intrusion capabilities. It is our view that the continued dialogue and cooperation on this topic can help strengthen accountability, transparency, and the development of shared principles that reduce the risk of misuse of these technologies. I thank you, Madam Chair.
Thank you very much. I now give the floor to the delegation of the United States, to be followed by Tuvalu, Zimbabwe, Albania, and the Russian Federation. United States, you have the floor.
Thank you, Madam Chair. I would like to present now the national statement of the United States of America. The United States is grateful for your leadership since the March organizational session and looks forward to the mechanism's first substantive work under your stewardship. As the global mechanism begins to move from procedure to substance, the United States continues to approach it with the same objective we have carried since the OEWG, grounded in practical implementation of the 11 consensus norms. Not a vehicle for new legally binding agreements. As long as some members in this hall are maliciously conducting cyber actions against other members, a legally binding agreement is impossible. This mechanism is the successor to a working group in which the United States invested real effort to secure a non-binding, action-oriented outcome. This mechanism was established to do real work. to implement the commitments states have already made to confront the actual threats hitting our critical infrastructure every single day. Chair, states should not conduct or knowingly support malicious cyber activity targeting critical infrastructure. However, there are members in this chamber right now who are planning and conducting malicious cyber actions against other members' critical infrastructure. Thank you, EU, Poland, Estonia, France, for pointing out these malicious actions. To Tonga and Kiribati, the United States hears you, and we thank you for your strong statements. While others in this chamber are planning and targeting you, the United States will be there to help protect you. The United States remains focused on the implementation of the consensus framework, holding states accountable to the consensus norms, strengthening resilience, and advancing concrete confidence-building measures. This is where we are directing our energy, and we invite every delegation to do the same. The United States sees DTG II's work in particular as an opportunity for practical discussion of gaps in cybersecurity— cyber capacity and how U.S. industry expertise can help close them, work that builds real security outcomes. Also, the United States is going to work to specifically identify the states and non-state actors who are perpetuating malicious cyber activities against others in this room. President Trump has been clear. If a country is utilizing the cyber domain to hurt others in this chamber, the United States will make them pay a heavy price. Our message is consistent and clear. This mechanism succeeds by building on the consensus we already have, not by searching for gaps that do not exist. The United States will demand adherence to the consensus norms and the 5 pillars to ensure the cyber domain remains a secure and safe space for everyone. Freedom is not a characteristic but is an essential part of this mechanism. Finally, President Trump's mandate is clear. For those in this chamber who think the cyber domain is a venue to abuse and exploit others, be warned, the cyber domain is about to change. And one last postscript to my Iranian colleague. Thanks for illustrating my point. I'm glad you noticed the cyber domain is changing. And like I said, President Trump is not going to stand idly by while the oppressive Iranian regime seeks to destroy regional stability and the inalienable right of all Iranians to be free. Thank you, Madam Chair.
Muchísimas gracias. Doy ahora la palabra Thank you.
Tuvali, you have the floor.
Madam Chair, allow me to begin by congratulating you and your team for your dedicated efforts in successfully conveying this first substantive session of the Global Mechanism on ICTs. Tuvalu aligns itself with the statement delivered by the Kingdom of Tonga on behalf of the Pacific Islands Forum states. Madam Chair, for Tuvalu, the United— UN Framework for Responsible State Behavior in Cyberspace is not merely a diplomatic exercise. It is fundamental to our national security and long-term responsibility. As we finalize our National Security Policy and advance our Digital Nation Initiative, ensuring sovereign continuity in the digital age, cybersecurity has become the cornerstone of our statehood resilience. Our approach is anchored in our core values. Through kaitasi, our principle of communal stewardship, we recognize that safeguarding cyberspace is a shared responsibility. Complementing this, our practice of falepili, or good neighborliness, drives us to uphold these norms as vital contributions to the peace and prosperity of our Blue Pacific continent. Madam Chair, cybersecurity isn't just a technical safeguard. It is a development enabler. For Tuvalu's development plan, the GATE framework, and the Global Sustainable Development Goals, strong cyber resilience ensures that digital transformation governance and community outreach can thrive without disruption. However, policy commitments require operational execution to be Our active engagement with regional partners, including the Pacific Security Operations Network, the Australian Cybersecurity Centre, as well as the New Zealand and other partner-supported Women in International Security and Cyberspace Fellowship, demonstrates that practical operational cooperation is the pathway to robust resilience. In line with the integrated approach of A/79/214 and A/80/257, Tuvalu emphasizes that norms, international law, and capacity building cannot be treated as separate silos. We urge this global mechanism to focus on the tangible— shared threat intelligence, clear protocols for protecting subsea infrastructure like Altevaga Cable, and the development of local expertise. Tuvalu stands ready to engage constructively to ensure that this mechanism serves as a driver of meaningful action that truly leaves no one behind. I thank you, Madam Chair.
Thank you very much. I now give the floor to the delegation of Zimbabwe.
Madam Chair, Zimbabwe aligns itself with the statement delivered by the African Group and wishes to make the following remarks in a national capacity. Zimbabwe congratulates you, Ambassador Lopez, on assuming the chair of the inaugural biennial meeting of the Global Mechanism. We assure you of Zimbabwe's full support. Madam Chair, Zimbabwe welcomes the discussions under this pillar on existing and potential ICT threats in the context of international security. These deliberations, which are being conducted in the integrated, policy-driven, and cross-cutting spirit envisioned under the 5 pillars of the Framework for Responsible State Behavior, are essential reference points for our collective efforts. The threat landscape, as we observe it, is anything but static. Malicious ICT activity continues to grow both in scale and sophistication, evolving from isolated incidents into persistent and layered challenges that carry implications for international peace and security, sustainable development, and the resilience of nations. My delegation is concerned by the rising frequency of ransomware attacks, targeting critical infrastructure, interference with electoral processes, and the unchecked spread of disinformation and misinformation through digital platforms. We are equally concerned by the rapid advancement and malicious use of artificial intelligence, which is reshaping the cyber threat landscape, enabling more convincing deception and introducing fresh complexities for cybersecurity resilience, and response. For developing countries, these threats are particularly acute. Capacity constraints and uneven cyber resilience increase our vulnerability and limit our ability to effectively respond to cyber incidents, risking progress towards digital transformation and sustainable development. We cannot afford to be left exposed, nor can we afford to be left Zimbabwe's National Development Strategy 2 and National AI Strategy place digital transformation at the center of our socioeconomic development as we continue to expand e-government services, digital financial services, and digital connectivity, protecting critical ICT infrastructure and strengthening services. Excuse me, strengthening cybersecurity resilience become national priorities. As a land-linked developing country that relies on interconnected regional telecommunications networks for connectivity, trade, and essential services, we recognize that vulnerabilities within shared digital infrastructure can have cross-border consequences. This reinforces the importance of enhancing regional cooperation and building the technical capacity of developing countries to prevent, detect, and respond to malicious ICT activity. We therefore support continued information sharing on emerging threats, the exchange of national experiences and best practices, and strengthened international cooperation to enhance collective resilience. Zimbabwe remains steadfast in its commitment to work constructively with all member states to promote an open, secure, stable, accessible, and peaceful ICT environment consistent with the purposes and principles of the Charter of the United Nations.
Thank you.
Muchísimas gracias.
Thank you very much. Now we will hear from the representative of Albania. You have the floor.
Thank you, Madam Chair, Excellencies, distinguished colleagues. Albania aligns itself with the statement delivered by the European Union and wishes to make the following remarks in its national capacity. Albania remains deeply concerned by the evolving threat landscape in the sphere of information and communication technologies. The current environment is characterized by increasingly sophisticated, persistent, and coordinated malicious cyber activities targeting us— public institutions, critical infrastructure, and citizens. As a country that has been directly affected by such activities, Albania attaches particular importance to the discussion on existing and potential threats to international peace and security. The scale and persistence of these threats are reflected in the recent national statistics. During 2025, Albania registered 51 cyber incidents with significant impact. In 2026, the volume of malicious activity and their sophistication has increased substantially. More than 17 million attempted cyber attacks recorded against Albanian system critical infrastructure, public and private. While only 9 incidents were ultimately classified as confirmed cyber security incident. The sheer volume of attempted attacks illustrates the intensity of the threat environment and the continued interest of malicious actors in targeting Albanian institutions and critical infrastructure. Recent incidents, 4 of them only in March 2026, to public institutions including Albanian Parliament, Albanian Post Office, the Office of the General Prosecutor, and the General Director of Prison— Directory of Prisons were supported by state-sponsored cyber operation on which we have always spoken publicly. A particularly concerning trend in the continual— is the continued combination of cyber operations with information manipulation activities. Following above-mentioned incident, Albania observed attempt to spread disinformation and manipulate public perception through social media and communication platforms, specifically via Telegram. These activities sought to amplify the psychological impact of cyber incidents, generate public uncertainty, and erode trust in public institutions. They demonstrate that contemporary cyber threats are no longer limited to technical instructions but increasingly combine cyber operations disinformation, and influence activities. Other incidents recorded during 2026 include phishing, spear phishing campaigns, smishing attacks, distributed denial of service attacks, or DDoS attempts, unauthorized modification of service, and ATM scheming activities. Phishing and smishing campaigns remain among the most widespread threats, affecting both institutions and citizens directly and forming part of broader campaign targeting user and organization across multiple countries. A further area of growing concern for Albania is the impact of malicious online activity on young people. The rapid spread of disinformation, manipulation of online content, and cyberbullying through social media and digital platforms possess increasing risk to the safety, well-being, and resilience of younger generations. The use of AI has made the ecosystem even more insecure and greater the exposure of the risk of young people who are more easily manipulated online. These phenomena have the potential to undermine trust in public information, fuel social polarization, and expose children and youth to psychological harm. As digital technologies become even more integrated into everyday life, addressing cyberbullying and deliberate disinformation of false and misleading information targeting young people should be considered an important element of our collective effort to promote security and stability in cyberspace. In Albania's view, these challenges represent not only a social issue, but also an emerging security concern that deserves greater international attention in the years ahead, but which should be addressed today. The threats faced by Albania, the region, and beyond reflect a wider international challenge. Malicious ICT activities are becoming more complex, increasingly combining technical compromise, theft of information, disruption attempts, and coordinated influence operations. These developments underscore the importance of ensuring the full implementation of the Framework of Responsible State Behaviour in Cyberspace agreed by the United Nations. Ensuring that states act responsibly in cyberspace, refrain from supporting malicious ICT activities, and cooperate in addressing threats is essential for preserving international peace, security and stability, in an increasingly interconnected world. Albania remains fully committed to working constructively with the global mechanism and with all partners to strengthen the international cooperation, build trust, and advance the implementation of UN Framework for Responsible State Behavior in cyberspace. Thank you, Madam Chair.
Muchas gracias.
Thank you very much. I now give the floor to the Russian Federation, to be followed by the Philippines, France, Ukraine, Chile, and Malawi.
Madam Chair, with the rapid development of information communication technologies, including artificial intelligence, threats to international information security are growing in scale and becoming more acute. The greatest danger lies in the use of ICTs for purposes that contradict the UN Charter to undermine the sovereignty of states, violate their territorial integrity, and interfere in their internal affairs. In concrete terms, I propose discussing the following threats within the framework of the global mechanism at its plenary meetings and in the first dedicated thematic group. Militarization of the private sector. In recent years, the world has witnessed this dangerous trend in which major ICT developers, which supply their products throughout the world, and including AI, and present themselves as neutral, client-oriented transnational corporations, now make no secret of how deeply they are embedded in the military-industrial complexes of the countries where they are registered. They often act as contractors for intelligence agencies and military departments, providing their developments for use in intelligence and espionage activities. This situation predictably undermines trust in the products of these companies, but more importantly creates serious risks for international stability and security. The use of ICTs for offensive purposes. For many years, there was a consensus within the UN that ICTs should not be used for purposes incompatible with the maintenance of peace and security. However, in recent years, we've seen this consensus Backdoors at the software and hardware levels embedded by developers in the interests of intelligence agencies without notifying end users. Such tools are used for intelligence espionage, interception of personal data and private correspondence, and as shown by the infamous pager incident in Lebanon in 2024, they're used for causing physical damage. Low-orbit satellite communication systems created under the pretext of providing reliable internet connectivity for civilian purposes— these technologies are in fact used for military-political objectives in the interests of certain countries. We're well aware of cases in which such systems have been used to interfere in the internal affairs of states by inciting protests, as well as their use in armed conflicts. This topic, that is, the risk of uncontrolled use of low-orbit satellite communication systems, was discussed at an informal UN Security Council Area Formula meeting in December 2025. We are convinced that to address this problem, low-orbit satellite communication systems operators must act in strict accordance with the national legislation of the countries in which they provide their services. Madam Chair, now I'd like to make a statement as the right of reply. During discussion of this agenda item, a number of delegations made outrageous anti-Russian remarks. We strongly reject these false and fabricated accusations against my country. Let me recall that in accordance with UNJA Resolution 73/2018, 27, accusations of organizing and implementing wrongful acts brought against states should be substantiated. Of course, as in all similar cases in the past, no evidence has been provided, neither in public nor bilaterally, nor have the existing channels for identifying the true sources of malicious activity been used. And this includes the UN Points of Contact Directory, to which all countries that have joined this campaign of accusations are parties. There is only one conclusion to be drawn: either no evidence exists, or the incidents never happened at all. The purpose of such blatant disinformation is to portray Russia as a threat in the information space in order to serve the Russophobic policies of the governments of these states. The real threat to international information security comes from the West. Let me recall that it is NATO countries that have recognized cyberspace as a theater of military operations. It is NATO and its members that are building up offensive digital capabilities and conducting computer operations against Russian critical information infrastructure in regular drills. I also note the hypocrisy of NATO's member states, which not only turn a blind eye to numerous crimes committed by the Ukrainian hackers against Russian citizens and Russian civilian critical information infrastructure, but also provide them with all possible assistance. In closing, Madam Chair, I would like to mention your call to shorten the duration of statements. We fully understand the reason behind this. You'd like to ensure that all delegations willing to speak Unfortunately, this is largely due to the irresponsible behavior of certain delegations who are wasting our precious time on politicizing the discussions. We consider such an approach to be unacceptable and call upon you, Madam Chair, to prevent the discussions within the global mechanism from turning into a political sideshow. Thank you.
Thank you very much for that statement, and thank you also to all of you for cooperating as regards the very limited time that we have for these interventions. I thank you also for a very productive meeting today. We have taken note of the right of reply, but we would indicate that this This should be done at the end of the meeting so that every delegation wishing to speak in their national capacity may be able to do so. And then if any delegation wishes to speak under the right of reply, they should make the request to the Secretariat so that this speaking time can be requested at the end of the list of the speaker as was done in prior meetings of this group. So now we will continue with the list. I will just read out who the next speakers are: Philippines, Ukraine, Chile, and Malawi. Philippines, you have the floor.
Thank you again, Madam Chair. As the Philippines noted during the organizational session last March, implementation remains central to the success of this mechanism. As we commence its substantive work, we remain committed to working constructively with all member states and encourage the same spirit of cooperation from all. The cyber threat landscape continues to evolve in scale and sophistication. Ransomware attacks against critical information infrastructure, cyber espionage, cyber-enabled criminal activities, and the malicious use of emerging technologies continue to challenge national resilience and international security. The Philippines believes that the value of the agreed framework lies in its effective implementation. At the national level, we continue to strengthen our cybersecurity posture through enhanced coordination across government, cyber threat information sharing, incident response, and partnerships with the private sector, academia, civil society, civil society, and international partners. The National Cyber Intelligence Network serves as the country's cyber intelligence center, enabling trusted information sharing, coordinated situational awareness, and collaborative response while contributing to regional and international cybersecurity cooperation. In addition, the proposed Cybersecurity and Critical Information Infrastructure Protection Bill, which remains part of the country's priority legislative agenda reflects our continuing efforts to strengthen national resilience. The Philippines recognizes that existing international law provides an important framework for responsible state behavior in cyberspace. Continued dialogue under this mechanism should promote practical exchanges on national implementation while respecting differing legal systems, levels of technological maturity and national circumstances. Confidence building and capacity building remain essential to translating our commitments into practice. As ASEAN Chair in 2026, the Philippines remains committed to advancing regional cybersecurity cooperation through cyber exercises, operational collaboration, and the exchange of best practices. We likewise support capacity building that is demand-driven nationally owned, sustainable, and responsive to the differing needs of member states. In this regard, we appreciate the continued support of international partners, including UNIDIR, whose technical engagements have strengthened national expertise and participation in the evolving UN cyber dialogue. We also welcome initiatives such as the ITU Academy's HER Cyber Track Program, which helps strengthen technical expertise, promote inclusivity in international cybersecurity discussions, and contribute to sustainable national capacity development. The Philippines has benefited immensely from their technical assistance. Madam Chair, among the evolving cyber threats confronting all member states, the Philippines wishes to highlight ransomware as an area where practical implementation and international cooperation can deliver immediate benefits. Addressing ransomware requires timely information sharing, strengthened incident response capabilities, public-private partnerships, technical assistance, and sustainable capacity building. As we continue to enhance our national legal policy and institutional frameworks, we recognize the value of cooperation that is demand-driven, respects national ownership and sovereignty and responds to the priorities of member states. Given the transnational nature of ransomware, continued cooperation among member states remains essential to strengthening collective resilience. The Philippines remains committed to practical implementation, inclusive dialogue, and consensus-based outcomes. We look forward to working with all member states to ensure that this This mechanism delivers meaningful, practical results that contribute to an open, secure, stable, accessible, and peaceful ICT environment. Thank you.
Muchísimas gracias.
Thank you very much. I now give the floor to the delegation of Ukraine, to be followed by Chile.
Thank you, Madam Chair. Ukraine aligns itself with the statement delivered by the European Union And would like to add some points in our national capacity. We continue to witness an increasingly complex and dangerous cyber threat landscape. Malicious ICT activities have become more frequent, more sophisticated, and more disruptive. They increasingly target critical infrastructure, public institutions, and essential services and democratic processes, while hybrid campaigns combining cyber operations, disinformation, and economic coercion seek to undermine international peace and security. At the same time, rapid technological developments, including artificial intelligence, quantum technologies, and increasingly interconnected digital ecosystems, create unprecedented opportunities for innovation while simultaneously expanding the attack surface available to malicious actors. As cyber threats do not respect national borders. No state is immune from their consequences. These developments underscore the need for the international community to strengthen cooperation, improve resilience, and ensure the effective implementation of the cumulative framework developed through previous UN processes. Chair, Ukraine experience clearly demonstrates that malicious ICT activities are not just theoretical risks. Besides the threats that were broadly described in the interventions by the distinguished representatives of Nigeria, Portugal, Italy, Kiribati, Türkiye, Switzerland, Albania, and many others, our threat landscape continues to be determined also by an actor that has a malicious intention as the essence of its attitude towards my country and its partners. For over a decade now, cyberspace remains one of the principal theatres of Russia's ongoing war of aggression against Ukraine. Ukraine. Russian malicious ICT activities are not isolated incidents, but form part of the broader strategy that combines cyberattacks with kinetic strikes, disinformation campaigns, and other hybrid warfare tools. Since the beginning of its full-scale invasion, Russia has deliberately targeted public authorities, critical infrastructure, and energy sector, telecommunications networks, state registries, and private businesses in Ukraine and beyond, thus attempting to undermine the very idea of the current global mechanism. Over time, its cyber operations have evolved from destructive attacks into sophisticated campaigns involving attempts for cyber espionage, long-term network persistence, supply chain compromise, and information manipulation. This activity forced the international community to impose the restrictive measures, sanctions, against the individuals and entities as a manifest of protest against their malicious behavior that undermines the security in the use of ICTs and on the global scale. Ukraine's experience of being a target of a long-lasting, unprovoked, and unjustified aggression by a neighbor state clearly demonstrates that cyber operations have become an integral component of modern warfare, producing tangible humanitarian, economic, and security consequences. And it is only a matter of time that this strategy can be used against any member of the international community. Chair, despite systematic cyberattacks, Ukraine has preserved the functioning of its digital state while continuously strengthening its national cyber resilience. Still, we believe that acts of deliberate cyber aggression should not be tolerated by the international community. In this respect, it is important that responsible states would join and coordinate their efforts to modernize instruments for countering hybrid threats, strengthening strategic communication, improve cyber threat intelligence sharing, reinforce international deterrence mechanisms, and ensure that malicious actors are held accountable for violations of the international law and the agreed framework of the responsible state behavior in cyberspace.
cyberspace.
Ukraine remains fully committed to constructive engagement with the global mechanism and looks forward to working with other delegations to ensure that this process delivers practical and meaningful outcomes that enhance international peace, security, and stability in cyberspace. Thank you.
Muchas gracias.
Thank you very much. I now give the floor to the delegation of Chile.
Muchas gracias.
Thank you very much, Madam Chair. For our country, this pillar is an area of priority in the global mechanism. Adequate understanding of the threats is an indispensable prerequisite in order to join forces to ensure the responsible behavior of states. Chile believes that malicious threats in cyberspace can constitute a series of threats to international peace and security. Their effects can vary considerably between states depending on their institutional capacity and on the security and resilience of their infrastructure and services. We know with concern that the threat landscape continues to evolve in terms of scale, velocity, sophistication, and capacity to generate cross-border impacts through malicious activity aimed at infrastructure and essential services. For this reason, for Chile, the protection of critical infrastructure represents a national priority and an essential component of international security in the use of ICTs. Gradual digitization and interconnection of critical sectors increases the possibility of attacks and the risk of cybernetic incidents having systemic effects in this way impacting the provision of services that are essential for the population. In certain cases, this can have direct consequences on economic stability and on the functioning of our societies. Societies. And this is why the strengthening of the resilience of critical infrastructure must continue to be a priority for this global mechanism. Chile also has noted with attention how emerging technologies continue to generate new vectors and vulnerabilities that can be exploited for malicious ends. In particular, AI is changing the reach of malicious cybernetic attacks and making it easier for them to adapt. Without prejudice to the important benefits that this technology offers for development, it's important for us to have a better understanding of its implications for international security and to strengthen cooperation between states in order to tackle with the, uh, out— the results of malicious use of AI. They're also contributing to the expansion of phishing attacks, malicious software, and increasing the sophistication of cybernetic attacks, and also fostering the dissemination of manipulated content. AI must be understood in this context as having the potential to multiply existing threats and also as a source of new risk factors and vectors. We also believe it is necessary, Chair, to keep attention on ransomware and other destructive forms of malicious software, the exploitation of the digital supply chain, connect— cloud-connected software, and future risks related to quantum computing, amongst others. These topics have already been identified by my country as Topics requiring continued attention. Chile believes that the Dedicated Thematic Group Number 1 aimed at policies and cross-cutting issues gives us a particularly valuable opportunity for driving a regular, structured dialogue that is evidence-based on the evolution of threats and their implications for international peace and security. This work— should have a forward-looking approach as regards threats with a view to identifying concrete areas for international cooperation in the area of cybersecurity. And to do this, it will be essential to have the participation of experts, regional organizations, the scientific community, the private sector, as well as other interested parties. A substantive discussion on emerging threats requires us to incorporate evidence and information that very often lies outside of governments. We unfortunately feel that the response to this continues to be uneven, and so the response must be closely linked to capacity building and the exchange of timely information and strengthening national response services to incidents and development of effective mechanisms for technical and diplomatic cooperation. In this regard, Chile looks forward to actively contributing to the work of the dedicated thematic group and to a discussion that will allow us to lead to a better understanding of the threats with a view to strengthening security, stability, and international resilience.
I thank you.
Thank you very much. I now give the floor to the delegation of Malawi, to be followed by France.
Madam Chair, Excellencies, and distinguished delegates, the Republic of Malawi aligns itself with the statement delivered by Nigeria on behalf of the African Group and thanks you and the co-facilitators for guiding our work. We also align ourselves with the interventions by the European Union, Portugal, South Africa, Saudi Arabia, Turkey, Singapore, Switzerland, Botswana, and Vanuatu, particularly on the growing sophistication of cyber threats, the importance of capacity building, the protection of critical infrastructure, and the need for strengthened international cooperation. We have carefully listened to member states and note a broad convergence of views regarding the growing threats. Malicious ICT activities are becoming increasingly sophisticated, persistent, and transnational. The growing misuse of artificial intelligence, ransomware, supply chain compromises, attacks on critical infrastructure, computer emergency response teams, undersea cables, and cloud services demonstrates that no state is immune. However, Chair, the Republic of Malawi wishes to emphasize one additional concern. It is not only the emergence of these threats that should concern us, but their persistence. Persistent and covert malicious ICT activities can remain undetected for extended periods of time, gradually undermining public trust disrupting essential services, weakening national resilience, and causing significant economic and societal harm. For many developing countries, just like Malawi, responding to one cyber incident is already difficult. Responding to sustained campaigns is an even greater challenge. As reaffirmed in successive reports of the UNGGE, GGEs, and the Open-Ended Working Group, international law, including the Charter of the United Nations, applies to the use of ICTs by states. We also reaffirm the voluntary norm that states should not knowingly allow their territory to be used for internationally wrong acts— wrong acts using ICTs. Madam Chair, We therefore cannot discuss these threats without discussing our collective ability to respond to them. National capacities remain uneven. Many developing countries continue to face shortages of skilled professionals, digital forensic capabilities, sustainable financing, and technical resources. In this regard, the Republic of Malawi believes that strengthening national computer emergency teams, enhancing cyber threat intelligence, promoting early warning mechanisms, and improving trusted information sharing should feature prominently in the work of the global— in the work of the dedicated thematic groups. Resilient response capabilities are just as important as resilient infrastructure. On artificial intelligence, My delegation recognizes both its opportunities and its risks. Artificial intelligence can significantly strengthen cyber defense through automation, vulnerability management, and threat detection. At the same time, it is lowering the barriers for malicious actors to conduct phishing, malware development, fraud, and disinformation at unprecedented speeds and scale. Our discussions should therefore focus on enabling responsible innovation while preventing malicious use. Finally, Madam Chair, as recognized in the 2025 OEWG Final Report, capacity building must remain sustainable, demand-driven, and tailored to the needs of states. If this global mechanism is to be implementation-oriented, And our discussions should move— our discussions should move beyond identifying threats and more towards strengthening the capacities, institutions, and partnerships required to address them effectively. I thank you, Chair.
Thank you very much. I now give the floor to the delegation of France, to be followed by Germany and Latvia.
Madam Chair.
Madam Chair, colleagues, my delegation aligns itself with the statement delivered by the European Union and wishes to add the following remarks on its national capacity. We have noticed 3 trends directly impacting our work in the global mechanism. First, the first trend is the gradual blurring of boundaries between state and non-state actors in cyberspace.
Space.
Throughout 2025, the threat landscape and affiliations became increasingly difficult to discern. The boundaries between state-sponsored acts and cybercriminals are blurring, and the use of proxies by nation-states is spreading. Certainly, the threats posed by state-sponsored actors remain significant. They continue their efforts in espionage and destabilization within a context of escalating global geopolitical tensions. On the 13th of July, France announced that it had been the target for more than 10 years of persistent cyberattacks carried out by the Russian Federal Security Service, the FSB. Contrary to what the Russian Federation has stated, this attribution process was conducted in accordance with the norms for responsible state behavior and following— having exhausted appropriate channels. But beyond purely state-sponsored activities, the threat is becoming increasingly widespread, originating from commercial activities, unscrupulous individuals, or individuals claiming ideological motivations. Naturally, no one is fooled behind these disguises and attempts to The intention to destabilize remains the same. This is why on the 13th of July, the EU adopted new sanctions against actors from the Russian cyber threat ecosystem, whose activities Russia either uses or or actively tolerates from its territory in violation of the framework for responsible state behavior in cyberspace. The second trend relates. To the opportunities and concerns raised by the increasing capabilities of AI models in the field of cybersecurity. While not yet fundamentally altering the nature of attacks, AI is increasing the speed at which malicious actors can conduct offensive operations. It is also— it also enables the scaling up of existing practices such as seeking vulnerabilities, as is well known. But more importantly, the rapid increase in cyber capabilities of the AI frontier models carries the risk of a new digital divide— the divide between those who have access to these models and everybody else, between those who are able to independently assess the risks associated with these models and those who are not. As recognized in the final report of the OEWG, this perspective on risks associated, associated with AI should not overshadow the opportunities that this technology offers to cybersecurity professionals. As we have seen, that we can collectively organize ourselves effectively. The mechanism must address these 2 aspects and delve deeper into how the framework for responsible behavior applies to these issues, and especially the voluntary norms. The thematic groups will provide a suitable platform for going deeper in our discussions, drawing on the relevant expertise of stakeholders, including non-state actors. France will actively contribute to feeding into discussions on this topic within the DTGs. And finally, the third trend relates to the uncontrolled proliferation of cyber intrusion capabilities available on the market. This third trend, fueled by the first two, is now a veritable ticking Time bomb. Without minimal oversight and accountability measures, the number of actors, including non-state actors capable of acquiring advanced capabilities, will continue to grow. And in this way, it will multiply the risks to the stability of cyberspace.
As—
because of the urgency of the issue, I would like to share with the members of the United Nations present here the progress that has been made with the United Kingdom as part of the Pall Mall process. Following the adoption in April 2025 of a Code of Good Practices for states, this week we are launching negotiations on the guidelines for the cyber intrusion industry. These voluntary document— documents aim to contribute to the implementation of a framework for responsible behavior and especially Standard 13. Thank you, colleagues. Madam Chair, the discussions on cyber threats targeting our states and societies are rightly at the heart of our UN discussions on cybersecurity. They remind us of the often harsh realities that exist outside of these walls. If it is to remain a relevant tool, the new mechanism must be able to identify the evolving nature of these threats. thematic group can fulfill this role by focusing on one or two major trends in cyber threats that have an impact on international peace and security, and by guiding our collective action to address them. I thank you.
Gracias.
Thank you. I now give the floor to the delegation of Germany, to be followed by Latvia.
Thank you, Madam Chair. Germany aligns itself with the statement of the European Union, and we will deliver the following remarks our national capacity. Chair, we commence our discussion in the first plenary of the Global Mechanism against the backdrop of a high level of global cyber threats, which have been even further spurred by the rapid evolution of artificial intelligence and geopolitical tensions. The leading German digital business group estimates last year's total damage of cyberattacks in Germany to be around $230 billion. This comprises state-sponsored cyber activities, economic espionage, and cybercriminal activities. The severe impact makes clear why cybersecurity is a core element of Germany's national security. Over the past year, Germany has experienced a continuously high level of ransomware attacks targeted especially at critical infrastructure providers, municipal and government services, but also not-for-profit organizations. For example, a ransomware attack paralyzed a leading humanitarian organization that provides food relief in conflict regions with risks of famine, putting people's lives abroad at risk. In addition, Germany notes with concern the virulence of politically motivated hacktivist activities both in Germany and abroad. Over the past year, Germany also observed a 25% increase in DDoS attacks. Especially against government entities, public administration, the transportation sector, and logistics companies. Attacks against industrial control systems and OT in critical infrastructures by politically motivated hacktivist groups have the potential to threaten the stability of public safety, public order, and human security. Such activities are also often aimed at attracting public attention, affecting public discourse, and undermining trust in the government's ability to provide secure digital services. Germany also faced a high level of state and state-sponsored cyber threats. Last week, together with the European Union and its member states and the North Atlantic Council, Germany has exposed and condemned a series of very concrete malicious cyber activities conducted by Russian state actors, in particular its intelligence service FSB, and by state-supported cybercriminal and hacktivist groups. The activities targeted government entities and critical infrastructures in several EU member states and in Ukraine, some of which had the potential for catastrophic damage of civilian energy infrastructure such as electricity networks or hydroelectric dams. Contrary to the claims of the Russian Federation, Germany has also communicated the unacceptability of these activities via the appropriate direct bilateral channels. Such malicious cyber activities contravene the framework for responsible state behavior, which all states have reaffirmed just last summer at the conclusion of the open-ended working group. Chair, allow me to add also an observation on artificial intelligence. The advent of advanced cyber capabilities facilitates large-scale attacks, including language-agnostic credible phishing, voice phishing, social engineering attacks. The barrier to entry for opportunistic malicious cyber actors is continuously lowered. We observe an increasing strain on defenders' resources and on maintainers of open source repositories and a need to reprioritize patching and rehab system, which put particular strain on less resourced and small countries. In response to this strategic challenge, the German government decided to establish the German AI Safety and Security Cybersecurity Institute, which will not only address cyber threats but potentially wider challenges of AI safety and security. Chair, against this backdrop, I want to reiterate Germany's commitment to working constructively with all states who want to make tangible progress on the substantive matters in cybersecurity we collectively face. We call on all states to take a pragmatic, solution-oriented approach towards the unresolved procedural matters before us. We want this mechanism to start working to deliver action-oriented, practical answers to the many challenges in front of us that have been presented by colleagues. In that endeavor, you can count on Germany's continued support and trust in your leadership, Madam Chair. Before I close, allow me to advertise a side event that the Dominican Republic, Ghana, and Germany are jointly hosting during the lunch break tomorrow at the German House. The event focuses on best practices for the operationalization of confidence-building measures for the protection of critical infrastructure and how regional perspectives on CBM operationalization can help advance implementation at the global level. A light lunch will also be provided. Thank you, Chair.
Gracias.
Damos la palabra ahora al—
Thank you. I now give the floor to Latvia, followed by Israel, Canada, Indonesia, Thailand, and Mozambique.
Your Excellency, Madam Chair, as this is the first time my delegation takes the floor, I would like to thank you and your team for the hard-working preparations for this first plenary session. Let me assure you of Latvia's constructive cooperation throughout this session, and we align ourselves with the statements by the European Union. Madam Chair, the international community is facing an increasingly complex and volatile ICT security landscape. Cyber threats have become persistent challenges that affect national security, economic stability, and social cohesion. They have a significant impact on the very functioning of our critical systems. In Latvia, a recent ransomware attack on state information systems once again reminded us of this Malicious ICT activity continues to rise in frequency, scale, sophistication, and impact. States and non-state actors alike exploit vulnerabilities in digital infrastructure targeting critical services that societies depend upon. Health, energy, financial, and transportation sectors, as well as government institutions, have all become targets of attacks. Ransomware remains one of the most pervasive threats. Criminal groups have developed industrial-scale operations leveraging encryption, info stealer malware, data theft, and extortion to generate enormous profits. State-linked cyber operations, as also outlined by France and Germany before me, also pose significant risks. Incidents targeting electoral systems, public administration, and critical infrastructure have raised concerns about the potential for destabilization and escalation through cyber means. Malicious cyber activity, including by proxy actors, can undermine trust in institutions, disrupt essential services, and create uncertainty that reverberates far beyond the digital domain. Such operations conducted during periods of heightened geopolitical friction carry significant risks of miscalculation. While traditional challenges persist, AI is transforming the cyber threat landscape as a whole. AI-enabled tools can automate reconnaissance, accelerate and scale vulnerability discovery, and generate highly convincing phishing campaigns. The access to and ease of use of AI-enabled tool supercharges the potential vectors and scale of malicious cyber activities, which can overwhelm cyber defenders' capacity to respond. To offer a deep-dive discussion on risks and opportunities posed by development of AI, Latvia, together with Estonia and Oxford Information Labs, will be co-hosting a briefing on Wednesday on Frontier AI and the Cyber Threat Landscape. Madam Chair, The establishment of the global mechanism provides us with an opportunity to work collectively on mitigating these threats in a structured manner. To achieve this, we must capitalize on the mechanism's architecture, which reflects the UN framework of the 5 pillars of responsible state behavior. A key priority for my delegation will be promoting transition from recognition that international law fully applies in cyberspace to fostering its practical implementation. Furthermore, the dedicated thematic groups, DTGs, will be central to our goal towards action-oriented approach. The DTGs should focus on specific ICT security challenges, enabling states to examine threats, share experience, and develop practical approaches. They should also help turbocharge capacity-building efforts, recognizing that global cyber resilience depends on ensuring that all states can protect their digital infrastructure. To conclude, the challenges before us are significant, but our recent work shows that progress is possible. To address existing and emerging cyber threats, we must continue developing the global mechanism and deepen cooperation across all 5 pillars.
Thank you.
Muchísimas gracias por la intervención.
Thank you very much. Thank you for those remarks. Before giving the floor to the next speaker, I would like to remind you of what I said earlier. That is to say that please be careful to stay within your time, keep your statements concise. I'd like to ask for shorter statements, and you could then send the full version to e-statements. I'm saying something because we have a very busy schedule. We have time limits on the use of conference services and this room. And 1:00 PM is the time that is set for ending our work. We have 21 speakers still on the list, and that means that we have exactly 1 hour, 45 minutes Rather 40 minutes. So let us try to stay within the schedule, and I ask you once again, therefore, to please try to cooperate and remain brief so that we can stay within our agreed-upon timeframe. Once again, thank you to all of you for your cooperation, and thank you for your patience.
Thank you.
these very interesting exchanges, but we'll be very grateful if you could please cooperate in this regard. I give the floor to Israel.
Thank you, Madam Chair. As this is the first time my delegation takes the floor during our first session of the Permanent Mechanism, allow me first to extend our delegation's best wishes to you, Ambassador López, and on taking the role of the Chair of this Permanent Global Mechanism. We have full confidence in your leadership as well as in your highly capable team. Israel approaches this first plenary session committed, as we were in all former processes, to contribute and working together constructively with the Chair, the Secretariat, and all Member States in this new Global Mechanism, sharing our extensive expertise and experience. Madam Chair, mindful of the very valuable time of this forum, I regret that we have to be compelled to respond to the outrageous statement made by earlier— made earlier by the representative of the Islamic Republic of Iran. Before moving to the constructive contribution we have prepared for this discussion we are meant to have here today, let me be clear: Israel's actions during Operations Rising Lion and Roaring Lion were conducted in accordance with international law, including the UN Charter and all the laws of armed conflict, and they were carried out in a context of an ongoing armed conflict with Iran.
Sorry.
I'll get back to you in a minute.
Thank you.
Okay, um, I give the floor now to Canada, followed by Indonesia, Thailand, and Mozambique.
Thank you, Madam Chair. This week, we are privileged to welcome again 38 Women in Cyber Fellows from a total of 31 states spanning the Americas, Europe, Africa, Asia, and Oceania. The participation of these women delegates is an important contribution to inclusivity, gender equality, and a vital component of our debate. Now moving to threats. We continue to be concerned by the evolving threat of ransomware. We observe that threat actors have demonstrated adaptability to changes in technology and will very likely continue to leverage advancements like AI to increase exploitation opportunities. We have observed that SMS text messaging has become one of the most common vectors for threat actors to target and scam victims. Referring to the statement delivered by the EU and the UK, Canada stands in full support with allies who recently condemned malicious cyber activities and foreign information manipulation and interference by Russian actors. Canada notes the joint statement issued by the cybersecurity agencies of Canada, the United States, the United Kingdom, New Zealand, and Australia on the risks posed by rapidly accelerating offensive and defensive capabilities of frontier AI models to the security of information technology and critical infrastructure worldwide. These models have displayed unprecedented capabilities in autonomous vulnerability discovery, zero-day vulnerability exploit generation, and multi-stage orchestration of malicious cyber activity. We must also emphasize the urgency for governments and enterprises to prioritize strengthening cyber resilience with traditional security practices and controls, as well as integrating frontier-capable AI models into their defensive security architecture. In Canada, we see that cyber threats to our critical infrastructure are almost certainly increasing. Of particular concern to us are growing threats to the water and wastewater systems. We judge that primary threats to these systems come from cybercriminals state-sponsored actors, and increasingly non-state actors. In the spirit of sharing information with the UN global mechanism, we note that Canada has joined the United Kingdom Joint Cyber Advisory on Defending Against State-Linked Covert Networks, along with Australia, Germany, Japan, the Netherlands, New Zealand, Spain, Sweden, and the United States. The advisory warns of large-scale scale covert networks of internet-connected devices being used to disguise the origins and attributions of cyberattacks. Further, it provides guidance on understanding and defending against this cyber threat. Finally, Madam Chair, Canada looks forward to the integrated policy-oriented and cross-cutting dedicated thematic groups to remedy this challenge and turn our UN discussions into a more practical forum with concrete value added. Our discussions in informal thematic groups will enable us to leverage the expertise and experience of governmental and non-governmental actors alike. Thank you, Madam Chair.
Thank you very much for that statement. I will now give the floor to the delegation of Israel a second
Thank you, Chair.
Sorry, uh, thank you for indulgence. I'll just continue where I stopped. Let me be clear. Israeli actions during Operations Rising Lion and Roaring Lion were conducted in accordance with international law, including the UN Charter and the laws of armed conflict, and they were carried out in the context of an ongoing armed conflict with Iran that Iran has been waging against Israel. Together with its non-state terrorist armed groups proxies, while bluntly violating international law. The Iranian regime acts of hostility against Israel span over all domains of warfare: on land, sea, air, and yes, also in the cyber domain. Iranian malicious cyberattacks specifically targeted and continue to target critical civilian infrastructure as well as especially protected objects under IHL. Such as hospitals, with complete disregard of humanitarian law. The attempt by the representative of the Islamic Republic of Iran to derail this forum and misuse international legal terminology and the framework of responsible state behavior in the cyber domain represents a shameful attempt to obscure Iran's own conduct and blunt violations of the most fundamental international norms.
Chair, And particularly during the recent consecutive rounds of large-scale conflict in our region, which included many cyber or cyber-enabled attacks against Israel and other states in our region, the threat landscape has evolved drastically and intensified. The multifaceted nature of the threat profile has also increased in complexity, involving elements relating to capabilities and activities of both state and non-state actors, as well as the intersections between states and non-state proxies. In the face of these developing threats, allow me to share a few practical insights which reveal critical transformation in the cyber threat landscape. The first one, cognitive and influence operations. We have witnessed a dangerous convergence of cyber manipulation and psychological warfare. This includes malicious targeted phishing campaigns masquerading as legitimate communication platforms. These threats feature in both cyberterrorism and in cybercrime. Second, cyber non-state proxies and irresponsible or unlawful state behavior. A core threat remains the clandestine direction, control, or support of non-state actors, actors which may serve rogue states as an attempt to undermine attributing unlawful activities or activities that are otherwise inconsistent with the GGE norms of responsible state behavior, or to the state that it is in effect responsible for malicious cyber activities. Another substantial threat is the absolute impunity granted by certain states to criminal syndicates and terrorist proxies offering hacking as a service. These actors operate from state-sanctioned safe havens. Furthermore, the illicit financing of these operations via digital assets in a global trend which should preoccupy the global mechanism discussions, including on international cooperation relating to tracking, freezing, and seizing of cryptocurrencies used for illicit activities. Taking together, these trends underscore the importance of of any future discussions to allocate sufficient time and attention to the activities of non-state actors and to the nexus of state and non-state actors' activity in the cybersphere. The DTGs could serve as a vehicle to further discuss these issues. Thirdly, the pace of technological development, an additional facet that impacts That impacts the fast pace of innovation in the sphere necessitates that all the discussions continue to be informed by thorough and up-to-date technical information. To this end, the global mechanism should allow sufficient time and opportunities for relevant technological experts to provide the forum with an appropriate professional. Presentations, including as part of the DTG's work. As many delegations have already noted, these issues are not theoretical. Israel's National Cyber Directorate, together with other government agencies and security bodies, has mitigated thousands of significant malicious cyber incidents which specifically targeted or attempted to target our civilian critical services, including specially protected civilian infrastructure in the health sector, Many of these incidents involve states that seemingly stress the importance of international law in the cyber domain while disrespecting it, as well as frameworks for responsible state behavior. The brazen statement made earlier by the Iranian delegation today is a particularly shameful example of this bad faith practice. Nevertheless, the way we approach and address the evolving threat landscape must remain technologically neutral. Taking into account the many benefits of emerging technologies, including AI's capacity to increase cyber resiliency. We should also consider where emerging technologies are the subject of other international processes and avoid duplication of diplomatic efforts. As other delegates have noted today, a focused approach can serve as a proof of concept for the GMAC and particularly for the DTGs, and ultimately contribute to its overall success. Thank you. Gracias. Doya. Thank you.
Indonesia followed by Thailand.
Thank you, Madam Chair. My delegation congratulates you for your elections and for the steady leadership you have demonstrated in guiding the global mechanisms. The landscape of existing and potential ICT cybersecurity threats continues to evolve rapidly. The growing sophistication of malicious activities, including advanced persistent threats, ransomware, and phishing activities, poses serious risks. Threats targeting critical infrastructure and critical information infrastructures, including cross-border systems, have intensified not only periodically but every single day, reflecting constant and relentless pressures on national and regional stability. The cascading effect can disrupt essential services, undermine public trust, and destabilize national and global security. Emerging technologies such as artificial intelligence and quantum computing further complicate the threat landscapes, lowering barriers to malicious activity while simultaneously creating new dependencies and vulnerabilities. A threat environment of this scale and complexity requires the global mechanisms to prioritize practical, needs-based support that enables all states, particularly developing countries, to detect, prevent, and respond to malicious ICT activities effectively. The global mechanisms, including its DTGs, should also focus on fostering cooperation in threat analysis, shared early warning arrangements, and structured exchange on incident trends to ensure that developing countries are not left behind in understanding and mitigating the complexities of ICT threats. Strengthening cooperation among computer emergency response teams and computer security incident response teams, enhancing public-private partnerships, and improving information sharing mechanisms are also indispensable to building resilience. Indonesia actively participates in regional and international mechanisms, including ASEAN OIC, and Asia-Pacific mechanisms for technical information sharing, coordinated incident response, and joint capacity building, in particular through the role of CERTs and CCERTs in essential components of national, regional, and international cybersecurity cooperation. As the global mechanisms, with its inclusive universal membership, embarks its process to ensure an open, safe, secure, stable and interoperable ICT environment, Indonesia stands ready to contribute constructively to advancing collective understanding, strengthening cooperative measures, and supporting the implementations for responsible state behavior. Thank you, Madam Chair.
Thank you very much for that statement. I now give the floor to the delegation of Thailand.
Thank you, Madam Chair. Thailand is of the view The misuse of information and communication by both state and non-state actors continues to pose a serious threat to international peace and security. Against the backdrop of rapid technological advances and growing geopolitical tensions, Thailand firmly believes that only through collective efforts can promote an open, safe, secure, stable, accessible, interoperable, peaceful, and resilient cyberspace. Madam Chair, Thailand is deeply concerned by the increasing number and sophistication of cyber threats, particularly those targeting critical infrastructure and critical information infrastructure. Our national assessment for 2025 indicates a continued rise in cyber incidents, especially those involving information content security, cyber fraud, and intrusion attempts. Malicious actors, including advanced persistent threat groups, are employing increasingly sophisticated techniques that pose serious risks to national security, economic stability, and the delivery of essential public services. These challenges are particularly acute for developing countries with limited cybersecurity capacities. Thailand also highlights the growing impact of emerging technologies, including AI and quantum computing. While these technologies are not threats in themselves, They can significantly increase the scale, speed, and sophistication of existing ICT-related threats. At the same time, ICT supply chain disruptions, including deliberate insertion of vulnerability, backdoor, or other forms of interference, undermine economic and digital development, particularly in developing countries. Addressing these challenges requires strengthened international cooperation to ensure that emerging technologies are developed and used in a safe, secure, and responsible manner. Because cyber threats transcend borders and affect all sectors, an effective cyber defense policy requires robust domestic measures in tandem with strong international cooperation. Given that much of the world's critical infrastructure is owned or operated by the private sector and that cyber threats transcend national borders, meaningful cooperation among states as well as effective public-private partnerships remain indispensable. Thailand reaffirms its commitment to engaging constructively in this global mechanism. We remain committed to working with our partners to address existing and emerging ICT threats in an inclusive, collaborative, and responsible manner. Thank you.
Thank you for that statement. Before I give the Before I give the floor to the next speaker, Mozambique, I would like to ask the Secretariat to close the list of speakers for inscriptions. And while I am very grateful to all of you for your interest in taking the floor since yesterday, we have been offering this possibility to try and calculate how much time we would need The list is still growing much longer than we had predicted and this could impact our ability to address the other items on the agenda. So please bear in mind the requests from the Chair to limit your use of the floor and let me now tell you who is next.
Thank you.
to Mozambique, Iraq, Poland, Morocco, Micronesia, and Malaysia. These are the next to take the floor in this segment. Mozambique, you have the floor.
Madam Chair, as this is our first intervention in this session, my delegation takes this opportunity to congratulate you, Madam Chair, on your appointment.
Meetings held, but by the concrete support delivered, stronger national resilience, and the ability of all states to participate meaningfully in shaping a secure, peaceful, stable, and inclusive digital future. Mozambique approaches this mechanism not only with with elevated expectations, but also with a strong commitment to contribute actively to international cooperation and implementation of the agreed UN framework. At the national level, Mozambique is undertaking comprehensive reforms to strengthen a secure and resilient digital ecosystem. These include the adoption of the cybersecurity law and the cybercrime law, as well as the development of complementary legal and regulatory frameworks on data governance, digital platforms interoperability, digital trust services, and emerging technologies, including artificial intelligence. These reforms demonstrate that political commitment is essential. However, legislation alone is not sufficient. Sustainable cybersecurity requires strong institutions, skilled professionals, trusted partnerships, and effective international cooperation to address increasingly sophisticated and transnational cyber threats. Mozambique expects this mechanism to become an implementation-oriented platform that translates agreed commitments into tangible outcomes, particularly for developing countries. Capacity building should be predictable, sustainable, demand-driven, and accompanied by technology transfer, institutional strengthening, and equitable access to knowledge and expertise. We also believe that mechanisms should strengthen collective preparedness to address existing and emerging ICT threats, including ransomware attacks against critical infrastructure, the malicious use of artificial intelligence, and other rapidly evolving cyber risks that increasingly affect developing countries. Madam Chair, the interconnected nature of the digital environment makes its security a shared responsibility. Through solidarity, mutual trust, respect for international law, and meaningful cooperation, we can transform this mechanism into an effective platform that delivers practical results and advances international peace, security, and sustainable development. I thank you.
Thank you very much.
I now give the floor to Iraq, to be followed by Poland.
Thank you, Madam Chair. At the outset, I would like to congratulate you on assuming the chairmanship of the Global Mechanism, and we assure you of our full support to make it a success. With regard to existing and potential threats, We wish to affirm that the rapid developments in the field of information and communications technology and the significant opportunities they offer for achieving development and prosperity are met with growing challenges arising from the malicious use of this technology, which has come to constitute a threat to international security and stability and to the functioning of governmental institutions, critical infrastructure, economic sectors, and essential services. We wish to express concern at the increasing cyber activities targeting civil— civilian critical infrastructure, including the energy, telecommunications, and financial sectors, and the serious humanitarian and economic effects that may result therefrom, particularly for developing countries that continue to face challenges in strengthening their national capacities in the field of cybersecurity. In this regard, we affirm the importance of enabling developing countries to benefit from international cooperation mechanisms for the exchange of cyber threat information and related technical indicators in a manner that enhances their capacity for early detection of and effective response to cyber threats. And we also wish to affirm the growing risks arising from the exploitation of ICT by terrorist groups, including the use of cyberspace for recruitment, the dissemination of extremist ideology, financing, planning, and coordination of terrorist operations, as well as the targeting of critical infrastructure. Drawing on Iraq's national experience in combating terrorism, we affirm the importance of confronting these unlawful uses. We further believe that strengthening the security of information and communications technology supply chains, and exchanging relevant international best practices and standards constitute an important element in reducing cross-border cyber risks. In this context, we affirm that addressing these threats requires strengthening international cooperation, exchanging information and expertise, and supporting efforts aimed at building national capacity, including expanding capacity-building programs facilitating the utilization of cyber threat information sharing initiatives and enhancing cooperation in the areas of cyber incident response and the transfer of knowledge and technical expertise so as to enable all states, particularly developing countries, to prevent, respond to, and recover from cyber threats. This would contribute to narrowing the digital divide strengthening global cybersecurity. In conclusion, we affirm that building a safe and stable cyber environment requires the continuation of comprehensive dialogue among all states and the strengthening of trust and international cooperation with working— and working in a spirit of consensus to ensure that information communications technology remains a tool for achieving development and peace rather than a source of conflict and instability.
I thank Thank you very much. I now give the floor to the delegation of Poland, to be followed by Morocco.
Madam Chair, Poland aligns itself with the statement of the European Union. Let me just make some remarks in my national capacity. The security environment in cyberspace is changing dynamically. Both the number and the scale of threats are growing. From hacktivist activities through profit-oriented cybercrime to operations carried out by entities related to other countries. These threats have an impact on the daily functioning of citizens, businesses, and public institutions, as well as on the security and privacy of internet users, including children, young people, and the elderly. The year 2025 has confirmed that cyberspace has become one of the key areas of state security, and the scale and piece of threats are systematically increasing. In Poland last year, we had 682,000 reports. Nearly 273,000 incidents were handled, and then— which means an increase of 144% year on year. In the era of growing aggression in cyberspace, we must act decisively because cybersecurity is our common cause. How? Building a digitally resilient society, developing technologies, strengthening cooperation between institutions responsible for cybersecurity, and fighting cybercrime more effectively. Those are our goals. At the same time, we should not hesitate to expose those responsible for malicious action in cyberspace. I would like to refer here to the European Union High Representative statement, which was announced 13th of July, as well as consequent EU cyber sanctions and North Atlantic Council statement. In Poland, a sustained pattern of malicious cyber activity by Russian actors has been observed since at least 2010. The Russia's security services have undertaken actions to gain unauthorized access to sensitive networks and to exfiltrate protected information from government, Polish Armed Forces, and private entities. They engage in strategic reconnaissance, prepositioning, and disruptive sabotage operations targeting Polish critical infrastructure, including water treatment plants and energy sector. Malicious cyber actors have engaged in deliberately establishing persistent footholds within critical systems with apparent intent to enable future disruptive or destructive effects against basic and essential civilian services. Our response to to the repetitive and unacceptable malicious cyber activities must remain strong and decisive. We will continue our efforts and denounce irresponsible malicious behavior in cyberspace in violation of international law, norms, and principles. In a world of growing threats in cyberspace, we need a clear action plan that will strengthen the protection of our institutions, economy, and the whole society. That's why our works here within the global mechanism, which have a global international dimension, are of paramount importance. We reiterate our full commitment to this major effort. Thank you, Madam Chair. Gracias.
Thank you. I now give the floor to Morocco, to be followed by the Federated States of Micronesia.
Madam Chair, with regard to existing and potential threats, this is an important pillar. This is a cornerstone of the global mechanism. An informed reading of current threats will allow us to collectively be able to establish effective norms apply international law, strengthen confidence, and deploy well-adapted capacity. The landscape of challenges that we are facing on the ground currently is characterized by the following elements: intensification of cyberattacks led by state and non-state actors, with a transfer of sophisticated capacity to criminal groups, as well as systematic targeting of critical infrastructure and essential services. Exacerbated by the growing vulnerability of supply— digital supply chains, the proliferation of cybercrime service models that facilitate large-scale attacks, especially through ransomware and DDoS attacks, misinformation campaigns that use digital technology to reduce confidence and jeopardize stability, the impact of emerging technologies which include AI first and foremost, which multiply the scale and the speed of attacks. In light of this, we must constantly adapt with a sense of urgency so that our decisions can keep pace with technological innovations. That is why we are placing our trust in the first DTG that is strongly turned toward action. It should help us to deepen our understanding of this topic and to propose concrete solutions. We also hope that sustained efforts may be made to ensure that cooperation serves collective resilience. Today we have a new mechanism that is a real asset embodying our common will to find concrete solutions. Through diagnosis and action. And we have an opportunity to build an open cyberspace that is safe, stable, and accessible for all of our societies. Thank you.
Muchísimas gracias.
Thank you very much. I now give the floor to the delegation of the Federated States of Micronesia, to be followed by Malaysia and Cameroon.
Madam Chair, as this is the first time for Micronesia to take the floor, I would like to congratulate you on your leadership and assure you of our support. Madam Chair, Micronesia aligns with the statement delivered by the Kingdom of Tonga on behalf of the Pacific Island Forum. Please allow me to deliver my remarks in my national capacity. Micronesia relies on information and communications technologies for development, disaster preparedness, health responses, education, and the preservation of our cultures. Yet these same technologies also enable malicious cyber activity and the rapid spread of disinformation threatening governance, resilience, and social cohesion. For small island developing states with limited technical capacity, disperse populations and acute exposure to climate and humanitarian shocks, these risks are especially pronounced. Madam Chair, Micronesia values active engagement with Interpol and international partners, recognizing that a secure and stable ICT environment underpins development and resilience. We remain committed to addressing cybercrime through cooperation and information sharing, while expressing concern over malicious ICT activities that threaten critical infrastructure and disproportionately affect vulnerable states. We therefore support efforts within the United Nations to promote responsible state behavior in cyberspace, including adherence to existing international law, the implementation of agreed norms of responsible behavior, confidence-building measures, and capacity-building that is needs-driven and inclusive. It is vital that all states, regardless of size or level of development, can participate meaningfully in shaping these norms and benefiting from a secure digital environment. We affirm that international law applies in cyberspace. Respect for sovereignty, the prohibition on the threat or use of force, and human rights obligations must guide state conduct online as they do offline. We support the voluntary consensus-based frameworks of norms for responsible state behavior, as this remains fundamental to addressing both existing. And potential ICT-related threats to international security. We therefore call for the broad adoption and practical implementation of these norms in the use of ICTs. Micronesia advocates for clear and rights-respecting definitions of disinformation, as vague approaches can suppress dissent and independent media erode human rights, politicize enforcement, weaken trust in institutions, and disproportionately harm marginalized and remote communities, while also impairing crisis response. To prevent these harms, we urge states to adopt precise, time-bound, and rights-based definitions of disinformation. The UN must remain the principal forum for inclusive dialogue. The Global Mechanism can consolidate best practices, coordinate capacity building for small island needs, and promote shared rights-respecting norms on disinformation and ICT security. Micronesia stands ready to work with all partners to protect our societies, uphold rights, and strengthen resilience in the digital age. I thank you.
Muchísimas gracias.
Thank you very much. I now give the floor to
Thank you, Madam Chair.
Malaysia appreciates your leadership in guiding the work of the Global Mechanism and we look forward to engage constructively on this agenda item. Madam Chair, Malaysia's national experience is, in many aspects, a reflection of the broader challenges identified in the OEWG Final Report and the 5 pillars of our framework. The threats we face, from sophisticated Advanced Persistent Threats, or APTs, to ransomware, are not unique to our region. They highlight our— the urgency of our collective work under this mechanism. Existing and emerging threats in the field of ICTs continue to pose real challenges to international peace and security. Malicious cyber activities directly impact governments, businesses, and critical information infrastructure. With far-reaching implications for economic stability, public services, and the daily lives of our citizens. Malaysia continues to observe malicious cyber activities across a wide range of sectors. Our national monitoring shows that a large share of reported incidents involve critical information infrastructure, most notably across trade and industry, government, agriculture and plantations, defence and security, healthcare, as well as banking and finance. This experience makes one thing clear: building the resilience of critical information infrastructure must remain a top priority for all of us. At the same time, the threat landscape is growing more complex. From our own experience, APTs, followed closely by ransomware, remain among our most serious concerns. We are also tracking new risks tied to the misuse of artificial intelligence, and other emerging technologies. To stay ahead of longer-term risks, Malaysia is also preparing for the security implications of quantum computing, especially regarding current encryption systems. We are currently developing a national post-quantum cryptography migration plan focused on safeguarding critical information infrastructure. This work forms a core part of our broader strategy to build long-term cyber resilience. Madam Chair, Malaysia believes our work under this pillar should focus on practical, grounded discussions that can help us collectively better understand the threat landscape. This may include sharing national experience on how we protect critical assets, handle the threats of APTs and ransomware, and manage the risk of emerging technologies. While national contexts differ, many of these challenges are common across states. Practical exchange will help us improve readiness and meaningfully carry out the Framework for Responsible State Behavior in cyberspace.
Thank you, Madam Chair.
Thank you very much.
I give the floor to the delegation of Cameroon, to be followed by Pakistan and China.
Madam Chair, Excellencies, distinguished delegates, my delegation welcomes the adoption of the provisional program of work and wishes to express its appreciation to the Chair for her able leadership and tireless efforts in preparing this substantive session. We look forward to engaging constructively in a spirit of cooperation and consensus in discussions on the 5 pillars of the Framework for Responsible State Behavior. Madam Chair, the topic before us today is existing and potential ICT threats in the context of international security. Which is of particular significance and importance to my delegation, as well as to developing countries more broadly. It speaks directly to one of the defining security challenges of our time, with far-reaching implications for international peace and security, sustainable development, and the resilience of our societies. As recognized in the consensus final report of the OUWG, malicious ICT activities have become increasingly sophisticated, frequent, and consequential, posing a growing threat to international peace and security. These threats are no longer theoretical or prospective. They have tangible repercussions on the security and integrity of critical infrastructure, the stability of economies, the delivery of essential public services, and the daily lives and well-being of our populations. Against a backdrop of accelerating digital transformation and increasing geopolitical tensions, the misuse of ICTs has emerged as a complex and evolving challenge that transcends national borders. It underscores the imperative of strengthening international cooperation, promoting responsible state behavior in cyberspace, and ensuring that the digital domain remains secure, stable, peaceful, accessible, and conducive to sustainable sustainable development for all. The OEWG discussions identified several key threat areas that require our collective attention. Firstly, attacks against critical infrastructure and critical information infrastructure. Secondly, ransomware, cybercrime, and the proliferation of malware. Thirdly, emerging technologies such as artificial intelligence and quantum computing. Madam Chair, identifying threats is necessary, but it is no longer sufficient. We must now move from diagnosis to action. My delegation calls on the DCGs to develop practical guidelines building on the OEWG recommendations for protecting critical infrastructure in developing countries. These guidelines should address the specific challenges faced by countries with limited resources. Promote public-private partnerships, given that much critical infrastructure is privately owned. Include best practices for securing industrial control systems, energy grids, and other essential services. Provide model legislation and regulatory frameworks for national adoption. My delegation recognizes that many developing countries continue to face significant capacity constraints including limited financial, technical, and institutional resources, which impedes the ability to effectively implement cybersecurity measures and strengthen national resilience in the use of ICTs. In this regard, we reaffirm our support for the establishment of the Dedicated Voluntary Fund under the Global Mechanism as an essential instrument to support national cybersecurity institution building, provide resources for training and skills development, facilitate participation in DCG meetings and capacity-building programs. As we move from deliberation to implementation, stakeholder engagement becomes more important than ever. Given that critical infrastructure is largely owned and operated by the private sector, strengthening its resilience requires effective partnerships among governments, industry, academia, and the technical community in accordance with agreed modalities of of the global mechanism. Madam Chair, drawing on African wisdom, we are reminded that if you want to go fast, go alone. If you want to go far, go together. In today's interconnected digital landscape, this message is particularly apt. No state, regardless of its level of technological advancement, can effectively address ICT threats in isolation. Building a secure, stable, peaceful, and resilient ICT environment is therefore a shared responsibility that calls for solidarity, mutual trust, and genuine international cooperation. Cameroon remains fully committed to working with all member states to ensure that the global mechanism effectively addresses existing and emerging ICT threats, narrows digital and capacity gaps, and delivers tangible benefits for all countries, particularly developing countries. Together, through dialogue, partnership and a shared sense of responsibility, we can foster a cyberspace that not only embraces our collective security but also supports sustainable development and shared prosperity for present and future generations. Thank you, Madam Chair.
Gracias.
Thank you. The next speakers are Pakistan, the next speaker on the list, but I don't see them in a chair, so I will give the floor now to China and then other countries. So just please be ready. Oman, Mauritius, Republic of Korea, and Ghana.
Thank you, Madam Chair. At present, the international situation is complex and turbulent, and the international system built after World War II faces multiple shocks. Emerging technologies, including AI, have escalated cybersecurity risks, exposing critical infrastructure to high cybersecurity risks. Cyberspace has become a new battlefield of geopolitical conflicts. And meanwhile, the global digital and intelligence industrial chains and supply chains are deliberately severed. While striving to seize opportunities of new challenges and bridge the digital divide, Global South countries are forced to take sides. The digital intelligence world faces a danger of division and disorder. Last September, Chinese President Xi Jinping put forward the Global Governance Initiative. Not long ago, Chinese Foreign Minister Wang Yi chaired the U.N. Security Council high-level meeting upholding— and called for the development of comprehensive solutions to the governance of cyberspace. Space, with a view to preventing new domains from turning into lawless zones of zero-sum games. Given the new features of digital intelligence age and the new trends in global governance, China has formally submitted to the Secretariat China's position paper on global cyber governance in the digital intelligence age. Its main content include abiding by international rules and safeguarding peace and stability. States should oppose acts of of aggression through cyber means, respecting digital sovereignty, and promoting development for all. Countries should respect each other's digital sovereignty, upholding multilateralism and addressing risks effectively. States should focus on the impact of emerging technologies and formulate new international rules. China hopes that the Secretariat will circulate the position paper to all member states. as an official document. Madam Chair, regarding existing and potential threats from China's perspective, cyberspace faces 3 major threats. First, cyberspace faces the risks of conflicts and unrest. A certain country seeks so-called unrivaled supremacy and aggressively develops offensive cyber military capabilities. They integrate AI into offensive national cyber strategies, designate major tech companies as digital defense contractors, and even enlist relevant companies to directly involve in cyber military operations. They openly declare that cyber capacity— capability is used to destroy other countries' critical infrastructure, completely break the taboo on cyber warfare. These Negative moves may easily cause strategic miscalculations among countries, greatly raise the risks of cyber frictions and conflicts, and seriously endanger international peace and security. Cyberspace is an extension of the real world. All countries should observe the purposes and principles of the UN Charter in cyberspace, in particular the principles of non-use or threat of force, peaceful settlement of disputes, and non-interference in internal affairs. If they do not abide by the UN Charter in the physical space, then in the online cyberspace, the Charter and the framework will not be abided by either. Countries, especially major countries, should play an exemplary role in abiding by the UN Charter. Countries should strengthen mutual trust through dialogue and resolve disputes through dialogue and consultation, and should not engage in aggression on cyberspace, especially that sectors that affect people's welfare, such as critical infrastructure, energy and water conservancy, governance, et cetera. National actors that threaten Chinese security— China has a clear position on that. National actors that threaten China's critical infrastructure. China sends out a clear message: China will take all measures necessary to resolutely safeguard our own cybersecurity. Second, the principle of sovereignty is challenged Seizing opportunities for new technology development and bridging the digital divide is a common aspiration of all countries, especially the Global South. The right to independently choose the path of digital technology development, as well as to independently choose AI technologies, products, and services in light of their own national conditions, lies at the heart of digital sovereignty. However, driven by geopolitical motives, a certain country draws an ideological line and coerces others into taking sides under the guise of cybersecurity, building trust, and fostering innovation, and splits global digital industrial chains and ecosystems. Countries should respect each other's digital sovereignty, promote innovation, keep digital— global digital intelligence industrial chains and supply chains open, secure and stable and build an open, universally beneficial, and inclusive ecosystem, which are rooted in facts, aimed at inclusiveness and openness, and underpinned by fair competition, rather than pursuing over-securitization, seeking technological monopoly, or exclusionary arrangements, which undermine the fairness, effectiveness, and inclusiveness of global digital intelligence development. Third, global cyberspace governance is at the risk of marginalization. Not long ago, a company issued— a new generation of large models issued by certain AI companies have demonstrated powerful cyber capabilities, both offensive and defensive, which led to global concern. In the past, the AI— the risk posed by AI was merely theoretical, but now we see firsthand the real threats AI poses. So this mechanism, including the DTG, is not an option. It is our responsibility. And the approach of private sector governance and the small circle governance adopted by a certain country is more worrying. Small circle governance cannot solve the big challenges facing the world. Given the disruptive impact of emerging technologies, countries should stick to multilateralism and consider establishing a— establishing global standards and system for testing and assessing the risk of large AI models to ensure that AI will serve as a new shield for cybersecurity rather than a new tool for unilateral pursuit of hegemony. Madam Chair, this year marks the launch of the global mechanism. China is ready to join hands with the international community to leverage the mechanism to strengthen communication exchanges, advance mutually beneficial cooperation, and deepen cooperation, deepened exchange sharing, experience sharing, and mutual learning with a view to jointly building international community with a shared future in cyberspace. Thank you, Madam Chair.
Thank you very much. I now give the floor to the delegation of Oman.
Madam Chair, ladies and gentlemen, first of all, Iman thanks you for convening this session, and we support the Framework for Responsible State Behavior and the Use of ICTs. He'd like to share some information with regard to existing and potential threats and our vision as to the future. First of all, cyber threats. Are growing in scale and sophistication. They are used with the help of AI by terrorist groups which use malware including backdoors. And the national experience of Sultanate of Oman is relevant in this regard. We have an electronic defense center which between 2024— since 2024 has addressed many cyber threats and risks that targeted national and governmental institutions. We had to address 19 cyber incidents. targeting private and public institutions as well. This led to data breaches and the disruption of information systems. These attacks targeted the energy, healthcare, financial, and education sectors, and our center combated these incidents and accelerated recovery. This highlights the importance of ICTs and it's their impact on all sectors. Secondly, cyber resilience as a key pillar. Based on this information, we recently launched a national strategy for cybersecurity 2026-2030, and this strategy places cyber resilience at the heart of our national approach as a vital pillar. We have learned the lessons of the past, and in 2024, the Electronic Defense Center reported 5 attacks against mobile phones and websites, and we have carried out awareness-raising campaigns that reached over 3,700 beneficiaries, including governmental institutions. And these figures are rising— rose last year. Cyber resilience aims at combating the impact of these cyber attacks, identifying and diagnosing them through an approach that brings together the public and private sectors. Starting this year, Oman adopted 11 responsible behavior norms for states, and we have incorporated these norms into all of our cyber policies, including our national strategy. And this will be published next month. We've also launched outreach campaigns in the public and private sectors with regard to these norms, and within our national policy, it is based on these norms. Thirdly, when it comes to ransomware, we are concerned by this issue, and within this mechanism, and the OEWG, we mentioned this, these attacks target various sectors, including essential services, and they have major impacts on international peace and security, especially since this ransomware is widespread and certain entities use them to further their own agendas. We are also troubled by threats to ICT supply chains and the spread of malware, as in which end users suffer the impact. Oman once again reaffirms that it is important to implement Norms 13 and with regard to the protection of critical infrastructure The protection of supply chains. And we hope that during the course of our discussions in DTG 1, we will focus on the fact that states must not allow groups to use their territories to launch these attacks in accordance with Norm 13C. We believe that we must adopt a pragmatic approach approach and develop a tool to tell if states are abiding by these norms. Discussions should also focus on the fact that we should not focus solely on threats but also practices. Otherwise, we will be discussing this issue endlessly without any outcome. We support exchanges of information on cyberattacks, and Sultanate of Oman remains committed to creating an open, stable cyberspace governed by international law and other consensus-based norms.
Thank you.
Muchas gracias. Doy ahora la palabra.
Thank you, Mauritius.
You have the floor.
Thank you, Chair, distinguished delegates, colleagues, and all those following the proceedings via UN Web TV. Speaking in our national capacity, the Mauritian delegation wishes to highlight our perspectives on the evolving cyber threat landscape, the challenges faced, and the measures undertaken to strengthen national cyber resilience. Mauritius attaches great importance to promoting a secure and resilient ICT environment that supports sustainable development, economic prosperity, and digital transformation. As a SIDS, we remain committed to strengthening our cyber resilience and ensuring that the benefits of digital technologies can be enjoyed safely and securely by all. The cyber threat landscape continues to evolve at an unprecedented pace. Cybercriminals are increasingly leveraging emerging technologies, including artificial intelligence, to conduct more sophisticated and targeted malicious cyber activities. Mauritius is particularly concerned by cyber incidents affecting critical information infrastructure and essential services, malicious activities conducted through social media platforms, phishing and online fraud targeting individuals and businesses, identity theft, online financial scams, data breaches involving personal information, and distributed denial-of-service attacks. We are also mindful of the growing risks posed by the malicious misuse of artificial intelligence to generate convincing deepfakes, clone voices, spread disinformation, and enable sophisticated forms of fraud, including cryptocurrency-related scams. Such misuse has the potential to facilitate cybercrime, undermine public trust, compromise the integrity of information, and disproportionately impact vulnerable groups, including children and older persons. For Mauritius, cybersecurity is ultimately about protecting people. As we continue our digital transformation journey, safeguarding the rights, safety, and trust of our citizens remain at the heart of our national cybersecurity efforts. To achieve this, Mauritius has adopted a proactive and whole-of-society approach to cybersecurity. We continue to advance our national cybersecurity framework through legislative and regulatory measures, including the enhancement of mechanisms to protect our critical information infrastructure to ensure the continuity and resilience of essential services upon which our citizens depend. We are also strengthening our national cybersecurity capabilities through CERT-MU, our national computer emergency response team, which plays a central role in enhancing incident response, threat monitoring, and cyber resilience. Through initiatives such as our national incident cyber— cyber incident reporting and threat intelligence platforms, and the security operations center supporting government services, Mauritius is reinforcing its ability to detect, analyze, respond to, and mitigate cyber threats in a timely manner. In parallel, we are investing in cybersecurity awareness programs, recognizing that an informed and cyber-aware population is our first line of defense against cyber threats. Against many forms of cybercrime. Mauritius is equally committed to ensuring that cybersecurity measures are implemented in a manner that respects international law and upholds human rights. We believe that security and the protection of fundamental rights are mutually reinforcing. Our objective is to create a digital environment where citizens can confidently access online services, conduct business, communicate freely, and benefit from innovation while knowing that their privacy, personal data, and digital rights are protected. Chair, addressing these evolving cyber threats requires collective action. Mauritius therefore supports enhanced international cooperation, capacity building, the timely exchange of information, and the sharing of best practices to strengthen collective resilience against cyber threat. In this regard, we reiterate that even small states can make meaningful contributions to international cybersecurity efforts. In this spirit, I would like to reassure you of Mauritius's continued commitment to engaging constructively with all member states, as we have done throughout previous open-ended working groups, to strengthen international peace and security in cyberspace and to build a trusted and resilient digital future for all. I thank you, Chair.
Muchas gracias.
Thank you very much. I thank all delegations for this substantive exchange. I have to say that there are still 9 speakers on the list under this item. However, given that I have received a request for a right of reply, I am going to suspend the plenary meeting and I would kindly remind you that we just have 12 minutes remaining for this morning's meeting and so I will give the floor to the delegation of the Islamic Republic of Iran.
Thank you, Madam Chair. My delegation categorically rejects the baseless, unsubstantiated, and politically motivated accusations made by the representatives of the Israeli regime and the United States. Once again, we have witnessed a desperate attempt by the U.S. and the Israeli regime to distort facts through disinformation and misinformation. Misleading narratives. Such attempts cannot change the reality and absolve those responsible for accountability. They seek to invert the facts by portraying the aggressor as the victim and the victim as the aggressor. The international community is fully aware of what has occurred and cannot be misled by such narratives. The Islamic Republic of Iran has long been one of the principal targets and victims of malicious cyber activities. The Stuxnet attack against Iran's peaceful nuclear facilities, the first known cyber weapon deployed against critical infrastructure, is only one example of a long pattern of malicious cyber activities directed against my country by the Israeli regime and the U.S. In my earlier statement, I placed on record numerous examples of cyberattacks carried out by the United States and the Israeli regime against Iran over the past year in conjunction with their unlawful military attacks. I will therefore not repeat those facts here. In this forum, the United States and the Israeli regime hypocritically invoke the norms of responsible state behavior in cyberspace. Yet, as with international law more broadly, They are among the first to violate those norms in the most blatant manner. Their unlawful attacks against Iran constitute one of the most egregious examples of such violations. After all the atrocities committed by the Israeli regime and the U.S. in our region, it is deeply ironic that their representatives continue to lecture others on compliance with international international law and norms. Finally, I cannot refrain from saying how ridiculous it is to hear representatives of the Israeli regime claim that it acts in accordance with international law. In light of the well-documented facts, I believe the only people in the world who could accept such a claim are the representatives of the regime themselves. I thank you.
Thank you.
Gracias.
Thank you. I have not received any other requests for— under the right of reply, and so given that we need to use every last minute that we have available to us, I am going to return to the list of speakers, and I will now give the floor to the distinguished representative of the Republic of Korea.
Thank you, Madam Chair. The cyber threat landscape continues to evolve as technology advances. Malicious cyber activities are becoming increasingly sophisticated, complex, and difficult to detect and respond to. We recall that the OEWG final report recognized the growing cyber risks associated with emerging technologies, including artificial intelligence. However, since the adoption of that report, the rapid advancement of frontier AI models has further transformed the cyber threat landscape. AI is enabling increasingly sophisticated cyber operations while raising concerns that existing cyber defense mechanisms may become less effective against evolving threats. The global mechanism should therefore deepen discussions on AI-enabled cyber threats and ensure that our international dialogue remains timely and responsive to the rapidly changing technological environment. Madam Chair, we recall that the final report of the open-ended working group recognized cryptocurrency theft as a threat with implications for international peace and security. As the global mechanism builds progressively upon the work of the GGE and OEWG, discussions on this issue should continue and be further deepened under the new process. In particular, ransomware and cryptocurrency theft have become major sources of financing for illicit activities. We should reaffirm that such activities threaten international peace and security especially when they are linked to illicit arms trafficking or the development of weapons of mass destruction. Chair, cyberspace is inherently transboundary. Its borderless nature, the anonymity it affords malicious actors, and the spread— the speed at which cyberattacks can spread make it impossible for any single state to address cyber threats effectively on its own. International cooperation is therefore indispensable. It's precisely because of this shared understanding that we have come together under the auspices of the United Nations to discuss cyber threats. The global mechanism should therefore be a platform for sustained and in-depth discussion on the evolving threat landscape, enabling member states to strengthen our collective understanding and enhance our collective capacity to prevent, respond to, and recover from cyber threats. I thank you. Muchísimas gracias.
Thank you very much. I now give the floor to the delegation of Ghana.
Madam Chair, Excellencies, and distinguished delegates, since this is the first time I'm taking the floor, my delegation and I extend our warmest congratulations to you, Madam Chair, on your leadership for this first biennium and assure you of Ghana's full support and cooperation. We welcome the indicative program of work you have circulated and commend the nomination of co-facilitators to the dedicated thematic groups— Egypt, Malaysia, the Netherlands, Australia— who are serving in their individual capacities and under your overall guidance. We are confident that under your guidance, they will carry out their responsibilities with impartiality, inclusive— inclusiveness, and professionalism. Ghana aligns itself with a statement delivered by the distinguished representative of Nigeria on behalf of the African Group and wishes to add the following remarks in its national capacity. Madam Chair, Ghana remains committed to work with member states, regional organizations, and other stakeholders to address both existing and emerging ICT threats. We are particularly concerned by the growing impacts of cyber threats on critical information infrastructure, whose disruption can have significant consequences for national security, economic stability, and public confidence. The damage to submarine cable serving Ghana in 2004— in 2024, and the resulting disruption to digital services reinforce the importance of protecting such infrastructure as a strategic national asset. At the national level, Ghana has identified 13 critical information infrastructure sectors under the Cybersecurity Act 2020, which provides for the registration of critical information infrastructure, establishes obligations for operators, and requires regular compliance audits. Ghana is also strengthening its national incident response architecture through the national and sectorial computer emergency response teams. Currently, 4 sectoral CERTs are operational for the following sectors: government, telecommunications, Banking and finance, and national security, with plans underway to operationalize additional sets for the health, energy and utilities, transportation, military, and academic sectors.
Ghana.
Madam Chair, please, I'll continue later.
Okay, we don't have much time.
Um, actually, we have just heard the last one speaking in this session.
So, el mecanismo—
The mechanism will return at 3 PM this afternoon to complete this agenda item. I am now going to read out the names of the delegations that I have on my list. so that they can be ready to begin at 3:00 p.m. sharp. Pakistan, Romania, Nicaragua, Armenia, African Union, ICRC, and Interpol. As soon as we complete this agenda item, we are going to immediately begin the next agenda item, which is the Voluntary Norms for Responsible State Behavior in Cyberspace and Forums of implementation, recognizing that over time additional norms may be elaborated. So please be ready. The meeting is adjourned.
Thank you.