Cyber Confidence-Building Measures

CBM 14: Public-Private Partnerships (PPP's)

Organization for Security and Co-operation in Europe

OSCEWidely implemented2016

Measure

CBM 14 (2016): Participating States will, on a voluntary basis and consistent with national legislation, promote public-private partnerships and develop mechanisms to exchange best practices of responses to common security challenges stemming from the use of ICTs.

Background: This CBM recognises that most critical ICT infrastructure is owned and operated by private actors, making PPPs essential for addressing shared cybersecurity threats. It encourages participating states to voluntarily foster collaboration between governments and the private sector and to establish mechanisms for exchanging best practices in incident response, threat mitigation, and resilience-building. Thus, the CBM describes steps to consider at the national level.

Practice: In 2021, the states that adopted CBM 14 – Austria, Belgium, Estonia, Finland, Italy, and Sweden (later joined by Bosnia and Herzegovina) – initiated a study titled “Report on Main Insights from the OSCE Cyber/ICT Security Confidence-Building Measure 14 Questionnaire on Public-Private Partnerships.” Based on a questionnaire sent to all participating states, it assessed engagement with CBM 14 and mapped emerging practices in cybersecurity-related PPPs.

Building on this effort, the OSCE Secretariat's TNTD, together with two researchers, published a good practice report in 2023 showcasing real-world examples and offering baseline recommendations to support future PPP initiatives. The findings demonstrate that significant attention has been to the objective of CBM 14, with numerous states – including the UK, Albania, Czech Republic, Denmark, Estonia, Finland, Italy, Slovakia, Serbia, Türkiye, the US, and the EU – recognising PPPs in national policy frameworks, legislation, or cybersecurity strategies. For example, the UK's 2022 National Cyber Security Strategy emphasises a whole-of-society approach with enduring partnerships across the public, private, and third sectors.

The implementation of CBM 14 is further supported through workshops: for example, in 2026 a workshop was conducted including a table-top exercise designed to test crisis procedures and co-ordination mechanisms in the event of a cyber incident. This workshop connected CBM 14 and 15. Meanwhile, another interactive workshop in 2025 aiming to enhance national preparedness, bolster crisis management and coordination mechanisms also connects it to CBM 1 and 14.

Another aspect supporting its implementation is the IWG. In rare cases, these meetings also include external stakeholders, such as private sector representatives and academic experts who contribute input and share experiences. As the report highlights, “some participating States have noted that lessons shared on CBM 14 implementation within the (...) [IWG have] been very useful, helping them shape similar initiatives in their own countries, redesign or redirect them.” It further notes that “[t]here is a clear appetite among most participating States to continue sharing emerging practices and lessons on cybersecurity-related public-private partnerships within the OSCE framework.”

CBM 14 functions primarily as a strategic objective rather than a narrowly defined measure. Many of its envisioned initiatives, such as enhancing national cyber resilience through collaboration with private actors, occur implicitly, thereby fulfilling its goals. Information exchange on national approaches and best practices is therefore central in analysing its implementation. Moreover, OSCE capacity-building activities frequently involve various non-state actors, implicitly advancing CBM 14 by fostering inclusive dialogue and multi-stakeholder cooperation. Overall, this CBM is widely implemented, however, a lot of it happens implicitly.

Key Implementation Activities and Resources

  • Participating states exchange experiences and best practices on public-private partnerships and regularly discuss approaches to cooperation between governments and private-sector stakeholders.

  • Implementation is supported by a good-practice report, workshops, tabletop exercises, and OSCE activities that facilitate dialogue among governments, industry, academia, and civil society.