Cyber Confidence-Building Measures

CBM 2: Points of Contact (political level)

Organization of American States

OASWidely implemented2018

Measure

CBM 2 (2018): Identify a national point of contact at the political level to discuss the implications of hemispheric cyber threats.

Background: CBM 2 aims to enhance regional cyber stability by designating national PoCs at the political level that provide a reliable channel for timely, high-level communication between states in response to cyber incidents, helping to clarify intent, share information, and prevent escalation. In this context, member states emphasise the importance of recognising that ICT-related incidents often originate from, or impact, third countries. Thus, when a state is contacted regarding such an incident, this should not be interpreted as an accusation of involvement or wrongdoing. Instead, communication via the PoCs established under CBM 2 is intended to facilitate dialogue and clarification. At the same time, the initiation of contact indicates that the reporting state considers the incident potentially relevant to its national security. Overall, the measure strengthens trust and cooperation by ensuring that every member state has a known and dependable channel for diplomatic engagement in cybersecurity matters.

Practice: CBM 2, though adopted earlier, has been implemented in parallel with CBM 3, which focuses on contacts within Ministries of Foreign Affairs (MFAs). While both measures involve the nomination of national PoCs, CBM 2 PoCs operate at the strategic and political levels, complementing the work of law enforcement, CSIRTs, and other technical actors engaged in combating cybercrime and managing technical incidents.

Each member state is responsible for designating a policy-level PoC and keeping that information regularly updated. These individuals should be strategically positioned within government and supported by institutional structures that enable meaningful engagement in cybersecurity matters. To complete a PoC profile, the following details are shared: country, full name, official position, affiliated institution, email address, and category of designation (cyber policy or foreign affairs contact). The CICTE Secretariat maintains the official PoC Directory and ensures secure access for authorised users via the web portal, which since its launch in 2021 has served as the primary tool for maintaining and sharing PoC information, accessible only to nominated contacts. Since 2025 the portal also allows direct communication via the portal between PoCs.

A clearly defined procedure governs the use of the PoC system during cyber incidents, requiring timely responses in a spirit of cooperation and shared interest in preventing escalation. A notable example occurred in 2022 during a major ransomware campaign by the Conti group, which “marked a turning point for regional cybersecurity collaboration” by underscoring the necessity of timely information sharing.

To further operationalise the CBM, the CICTE Secretariat has organised targeted activities, including a workshop on the role of PoCs and a scenario-based tabletop exercise during the second Working Group Meeting in 2019, which tested the effectiveness of the PoC network under simulated crisis conditions. CBM 2 PoCs also benefit from access to CICTE's training and capacity-building programmes, as well as the dedicated web portal – efforts designed to foster community, trust, and shared purpose. Implementation is additionally reinforced by synergies with CBMs 4, 5, and 6. To ensure readiness, the Secretariat conducts regular ping tests of the PoC network, reporting consistently high response rates. Looking forward, it plans to continue these tests and expand tabletop exercises to further strengthen communication and responsiveness.

Participation in the PoC Directory has risen steadily, and by 2026, it included 82 Cyber Policy Points of Contact, 22 of whom represent MFAs (CBM 3). This reflects near-universal engagement by member states and underscores CBM 2's foundational role within the broader CBM framework. Indeed, CBMs 2 and 3 remain the most widely implemented, serving as cornerstones of the regional architecture for cyber stability. Building on this solid base, efforts are now underway to align the OAS PoC Directory with the UN PoC Directory to improve cross-regional coordination, a proposal discussed among member states on the margins of the 2025 OEWG meeting, where it received broad support.

Key Implementation Activities and Resources

  • Since 2018, 29 OAS member states have designated and regularly updated their PoCs (including 82 Cyber Policy PoCs, 22 of whom represent MFAs (CBM 3), whose details are maintained by the CICTE Secretariat.

  • Implementation is – aligned with CBM 3 – supported by dedicated resources, including a secure web portal with direct messaging functionality, regular network readiness ("ping") tests, tabletop exercises, workshops for PoCs, and ongoing capacity-building programmes.