CBM 2: Cross-border co-operation
Organization for Security and Co-operation in Europe
Measure
CBM 2 (2013): Participating States will voluntarily facilitate co-operation among the competent national bodies and exchange of information in relation with security of and in the use of ICTs.
Background: Because cyber operations are transnational and technically complex, timely exchange of threat information is indispensable for early detection, confident attribution, and collective action such as sanctions. However, one key obstacle to such collaboration is trust: actors must be confident in the quality and intent behind the shared information. This CBM calls on OSCE participating states to deepen voluntary cooperation and information-sharing among their national cybersecurity bodies like CERTs, law-enforcement, regulators, and policy agencies so they can mount faster, better-coordinated responses to ICT threats. Thus, it promotes cyber resilience and readiness.
Practice: This CBM has so far been implemented, but not widely compared to others, particularly in terms of explicit activities, partly due to its lower uptake within the "Adopt a CBM" initiative. However, in connection with CBM 4 and CBM 6, the OSCE regularly conducts regional and subregional exercises that simulate fictitious cyber incidents. These exercises require coordination among relevant national entities to formulate an effective response, serving both to test the robustness of national cybersecurity mechanisms and to identify gaps and areas for improvement.
Key Implementation Activities and Resources
The rather limited implementation is primarily enabled through activities conducted under related CBMs, particularly exercises and capacity-building initiatives focused on cooperation, information-sharing, and operational readiness.