Cyber Confidence-Building Measures

CBM 3: Points of Contact (diplomatic level)

Organization of American States

OASWidely implemented2019

Measure

CBM 3 (2019): Designate points of contact, if they do not currently exist, in the Ministries of Foreign Affairs with the purpose of facilitating work for cooperation and international dialogues on cybersecurity and cyberspace.

Background: CBM 3 calls on OAS member states to designate PoCs within their MFAs to strengthen international cooperation on cybersecurity and cyberspace issues. Adopted one year after CBM 2, this measure responded to a clear regional need: integrating MFAs more directly into cybersecurity governance. Traditionally, cybersecurity was viewed primarily as a technical issue, with MFA involvement often seen as secondary or even unnecessary. Yet diplomatic-level contacts play a vital role in facilitating dialogue, coordinating regionally and internationally, and aligning cybersecurity with broader foreign policy priorities. By formalising MFA involvement, CBM 3 underscores that cybersecurity is not only a technical challenge but also a strategic foreign policy priority, one that must be embedded within each state's national cybersecurity architecture. In doing so, it establishes formal channels for cyber diplomacy, strengthening the region's ability to engage in multilateral discussions, respond collectively to cyber incidents, and promote responsible state behaviour in cyberspace.

Practice: The implementation of CBM 3 builds directly on the foundation established by CBM 2, with both measures working in tandem to strengthen communication and coordination at the political and diplomatic levels. As with CBM 2, a complete PoC profile must include key details such as the individual's name, position, institution, and contact information. This information is maintained in the secure web portal managed by the CICTE Secretariat, which facilitates access for authorised users and ensures regular updates. Requests for information and the exchange of data through the directory follow the same procedures as outlined for CBM 2. MFA PoCs are also encouraged to take part in cyber-related capacity-building initiatives and diplomacy-focused trainings under CICTE's CCB framework, creating natural synergies with CBMs 4, 5, and 6.

As of 2026, 22 MFA PoCs have been formally nominated and registered in the web portal, reflecting the CBM's wide implementation. These contacts frequently serve as the primary actors in regional and international cyber diplomacy. Efforts are also underway to align the OAS PoC Directory with the UN's cyber diplomacy contact list, further reinforcing CBM 3's role in bridging regional and global cybersecurity cooperation.

Together with CBM 2, this measure has already had a tangible impact by providing the foundation for deeper cooperation. As Chile noted, “The PoCs have contributed to the exchange of information, strengthening cooperation on capacity-building and technical assistance, coordinating policies and positions with other states on multilateral and regional processes, responding to queries and requirements from other states and international stakeholders, requesting information on cyber-attacks and strengthening bilateral relations, among others.”

Key Implementation Activities and Resources

  • Currently, 22 PoCs have been nominated representing MFAs, whose details are maintained by the CICTE Secretariat within the PoC Directory.

  • Implementation is – aligned with CBM 2 – supported by dedicated resources, including a secure web portal with direct messaging functionality, regular network readiness ("ping") tests, tabletop exercises, workshops for PoCs, and ongoing capacity-building programmes.