CBM 1: Threat information sharing
Organization for Security and Co-operation in Europe
Measure
CBM 1 (2013): Participating States will voluntarily provide their national views on various aspects of national and transnational threats to and in the use of ICTs. The extent of such information will be determined by the providing Parties.
Background: The aim of this CBM is to exchange information on national and transnational threats with ICTs. In doing so, this CBM fosters transparency and helps identify potential opportunities for cooperation between states. This was a meaningful step forward at the time, given that even a voluntary exchange of national threat assessments was politically sensitive and required extensive negotiation, reflecting the broader challenges of building trust in the cyber domain.
Practice: Within the OSCE, national views on ICT‑related threats are shared through three main channels. First, the internal POLIS Knowledge and Learning Platform allows states to share threat assessments with other participating states. Routine advisories posted there directly serve the goals of this CBM. In line with CBM 1, participating states regularly release cybersecurity assessments and advisories, offering insights into evolving cyber threats and their potential impact on national security. Second, and central to this CBM, the exchange of threat-related information has grown with the expanded use of the communication network established under CBM 10. While only a subset of participating states use it regularly, it provides a trusted channel for secure information sharing, particularly for distributing sensitive threat reports.
In 2025 an interactive workshop was conducted with participants from Moldova and Ukraine connecting this CBM to CBM 15 and 16 aiming to enhance national preparedness, bolster crisis management and coordination mechanisms. Finally, IWG meets several times a year (while CBM 11 stipulates at least three meetings annually, in practice four sessions are held each year), as well as the annual meeting of the national PoCs providing important fora for in‑person exchange of such information.
Rather than create new structures or specific activities focusing explicitly on the implementation of this CBM, the OSCE focuses on leveraging these existing platforms to foster continuous, transparent information‑sharing. With this in mind, it is hard to assess the explicit implementation of this CBM. Overall, however, this CBM is implemented, but not widely.
Key Implementation Activities and Resources
Participating states share information on ICT-related threats through the POLIS Knowledge and Learning Platform, the OSCE Communications Network, IWG meetings, workshops, and annual PoC meetings.