CBM 3: Hold consultations
Organization for Security and Co-operation in Europe
Measure
CBM 3 (2013): Participating States will on a voluntary basis and at the appropriate level hold consultations in order to reduce the risks of misperception, and on possible emergence of political or military tension or conflict that may stem from the use of ICTs, and to protect critical national and international ICT infrastructures including their integrity.
Background: This CBMis particularly relevant when a state detects a serious incident and, based on limited information, suspects another OSCE participant of involvement. In such cases, bilateral consultations are encouraged to enable early information-sharing, reduce misinterpretation, and build a fuller picture of events. The process may confirm or challenge initial assumptions, while also offering a discreet diplomatic channel for states unwilling to publicly attribute an operation - whether to avoid exposing capabilities, vulnerabilities, or for political reasons. Through this mechanism, states can seek clarification, request harmful activity to stop, or ask for assistance. In essence, the CBM provides a concrete procedure for information exchange during cyber incidents as a responsive crisis communication tool that lowers the risk of unintended escalation.
Practice: Germany and Switzerland, as the CBM-adopters, have prioritized advancing the implementation of this CBM, viewing it as a core measure. Their first task was to design clear procedures for requesting information and consultations in the event of an incident, a process they successfully developed.
Although CBM 3 has not yet been applied in a real case, it was tested in a 2024 scenario-based table-top exercise that combined it with other relevant CBMs. The exercise was considered a success, with all participating states engaging constructively. A follow-up exercise is planned for 2025, to be conducted remotely and in coordination with PoCs (CBM 8), the communication network (CBM 10), and information-exchange templates (CBM 13), ensuring a more realistic starting point. With these procedures in place and tested, the CBM is now widely implemented and actively practiced through such exercises.
Overall, this CBM is closely linked to CBM 8, CBM 10, and CBM 13, together forming an interconnected framework offering a practical tool to manage international cyber incidents. This framework helps clarify key questions: who initiates which mechanism, and under what circumstances. In addition, the CBM is connected to CBM 15: since 2021, the OSCE has launched extra-budgetary projects focusing on both CBMs, particularly on crisis communication, incident classification, and ICT crisis management. A new project is currently underway to further strengthen implementation and build capacity in these areas.
Key Implementation Activities and Resources
The adopting states Switzerland and Germany developed procedures for requesting information and consultations during cyber incidents and participating states regularly test them through tabletop exercises.
Implementation is supported by a broader crisis communication framework consisting of the PoC Network (CBM 8), the Communications Network (CBM 10), information-exchange templates (CBM 13), and OSCE projects on crisis communication and incident management.