Cyber Confidence-Building Measures

CBM 5: Capacity building platform

Organization for Security and Co-operation in Europe

OSCEWidely implemented2013

Measure

CBM 5 (2013): The participating States will use the OSCE as a platform for dialogue, exchange of best practices, awareness-raising and information on capacity-building regarding security of and in the use of ICTs, including effective responses to related threats. The participating States will explore further developing the OSCE role in this regard.

Background:This CBM designates the OSCE itself as a central forum where participating states exchange best practices, coordinate CCB programs, and raise collective awareness on ICT security. The objective is to bolster regional cyber resilience while complementing (not duplicating) existing initiatives.

Practice: This CBM is also broadly framed and centers on information exchange as a means of promoting transparency and identifying opportunities for cooperation in the field of CCB. The POLIS Knowledge and Learning Platform plays a central role in supporting this exchange. In the OSCE’s e-learning course on cyber CBMs, the UK, one of its adopters, highlighted its work with over 100 countries and investments of more than £36 million in CCB since 2012, including the development of national cyber strategies, law enforcement training, and public awareness campaigns. These efforts illustrate the types of activities relevant to this CBM. However, it is important to note that not all CCB initiatives by OSCE states automatically count as implementation; rather, the CBM lies in the sharing of information about such initiatives.

The OSCE itself also conducts CCB activities that contribute to this CBM’s being widely implemented. Through the project “Activities and Customized Support for the Implementation of OSCE Cyber/ICT Security Confidence-Building Measures”, the organization has delivered workshops on gender perspectives in cybersecurity, cyber diplomacy, norms, and the CBMs themselves, alongside table-top exercises testing their practical applicability. These efforts - implemented by the OSCE Secretariat’s TNTD and regional missions, sometimes in cooperation with partners - naturally advance multiple CBMs at once. For example, a scenario-based discussion on responding to a major cyber incident linked this CBM to CBM 15. Such activities are funded by multiple states including Switzerland, the UK, and the Netherlands. A concrete illustration comes from Serbia, where the OSCE Mission supported initiatives ranging from awareness-raising and national strategy development to building effective communication channels, strengthening public-private partnerships, and securing critical infrastructure.

Finally, to enhance transparency and track implementation, the adopters distributed a questionnaire to participating states in 2024, with results expected to be presented in the IWG.

Key Implementation Activities and Resources

  • This CBM can be understood as a commitment to upholding this objective. Participating states exchange information on cybersecurity capacity-building initiatives, lessons learned, and national experiences through OSCE platforms and meetings.

  • Implementation is supported by OSCE workshops and trainings, tabletop exercises, often combining multiple CBMs.