CBM 15: Critical infrastructure protection
Organization for Security and Co-operation in Europe
Measure
CBM 15 (2016): Participating States, on a voluntary basis, will encourage, facilitate and/or participate in regional and subregional collaboration between legally authorized authorities responsible for securing critical infrastructures to discuss opportunities and address challenges to national as well as trans-border ICT networks, upon which such critical infrastructure relies. Collaboration may, inter alia, include:
Sharing information on ICT threats;
Exchanging best practices;
Developing, where appropriate, shared responses to common challenges including crisis management procedures in case of widespread or transnational disruption of ICT-enabled critical infrastructure;
Adopting voluntary national arrangements to classify ICT incidents in terms of the scale and seriousness of the incident;
Sharing national views of categories of ICT-enabled infrastructure States consider critical;
Improving the security of national and transnational ICT-enabled critical infrastructure including their integrity at the regional and subregional levels; and
Raising awareness about the importance of protecting industrial control systems and about issues related to their ICT-related security, and the necessity of developing processes and mechanisms to respond to those issues.
Background: This CBM encourages participating states to voluntarily collaborate at the regional and subregional levels – for example, via CERTs and critical-infrastructure regulators – to strengthen the security and resilience of ICT-dependent critical infrastructure, while also considering steps at the national level. Suggested activities include sharing threat intelligence, exchanging best practices, coordinating crisis management plans for cross-border incidents, harmonising incident classification schemes, and raising awareness on the protection of industrial control systems. This CBM underscores the importance of a comprehensive, multi-stakeholder approach by actively involving diverse actors, while standing out from other CBMs for its more technical focus.
Practice: Progress has been made in the implementation of this CBM in recent years. Many activities under CBM 15 are closely connected to others, for example, CBM 1 on sharing ICT threat information, CBM 9 on mapping critical infrastructure definitions, and CBM 3 on crisis communication and management. Workshops organised within the OSCE framework also indirectly contribute to its implementation.
A central focus of implementation has been the development of voluntary national arrangements for classifying ICT incidents by scale and seriousness, commonly known as national cyber incident severity scales (NCISS). Such systems are vital for prioritising responses to incidents affecting critical infrastructure and for strengthening both national and international crisis communication by fostering transparency, predictability, and a shared understanding of incident severity. They also help states to “speak the same language” when responding to cyber threats, thereby reducing the risk of misunderstandings.
To support this, the OSCE Secretariat's TNTD has implemented, since 2021, the “Facilitation of the development and implementation of national cyber incident severity scales (NCISS) and related measures to protect critical infrastructures” project, focused on CBMs 15 and 3 and funded by France and Germany. Within this framework, customised support has been provided to Uzbekistan, Moldova, and Ukraine. These activities have explored the rationale for establishing severity scales, supported their development and implementation, and enabled the exchange of best practices, including through practical simulations involving hypothetical cyber operations on critical infrastructure, workshops, and best practice exchanges. Moreover, for example, in 2026 a workshop was conducted connecting CBM 14 and 15 highlighting the importance of timely information-sharing and collaboration between national authorities and private sector operators. Another interactive workshop focused on the connection between this CBM and CBM 1 and 14 providing the opportunity to apply practical approaches to managing cyber incidents affecting critical infrastructure.
Parallel efforts have reinforced this work: in 2020, France launched a survey to identify participating states' needs regarding severity scales, followed in 2022 by a TNTD study analysing emerging practices. That same year, a good practice report on cyber incident classification was published, highlighting common approaches, challenges, and lessons learned. Despite some differences, the report concluded that the lessons learned serve as a valuable capacity- and trust-building tool to promote the broader use of such systems within the OSCE region and beyond. The adopters of this CBM circulated a new survey in 2024 to update the overview of national measures. In 2025, another handbook on national cyber incident classification was published, drawing on survey results and offering a step-by-step guide for developing and implementing NCISS. The handbook aims to support participating states in increasing this CBM's implementation rate.
Today, many participating states have either established or are developing classification systems (35 out of 57 participating states), often backed by new legal or policy frameworks. Within the EU, the NIS Directive has ensured that such systems exist in (almost) all EU member states (although developed independently of this CBM, they still contribute to its objectives). Other states, including the USA and UK also maintain similar frameworks. Overall, the CBM is widely implemented, however, a lot of it happens implicitly.
Key Implementation Activities and Resources
Participating states exchange on practices for protecting critical infrastructure, including cyber incident classification systems, crisis management procedures, and information-sharing mechanisms.
Resources supporting implementation include OSCE-funded projects on national cyber incident severity scales, tailored support for participating states via workshops, and handbooks on national cyber incident classification and emerging practices in this regard within the region.