Cyber Confidence-Building Measures

CBM 8: Points of Contact

Organization for Security and Co-operation in Europe

OSCEWidely implemented2013

Measure

CBM 8 (2013): Participating States will nominate a contact point to facilitate pertinent communications and dialogue on security of and in the use of ICTs. Participating States will voluntarily provide contact data of existing official national structures that manage ICT-related incidents and co-ordinate responses to enable a direct dialogue and to facilitate interaction among responsible national bodies and experts. Participating States will update contact information annually and notify changes no later than thirty days after a change has occurred. Participating States will voluntarily establish measures to ensure rapid communication at policy levels of authority, to permit concerns to be raised at the national security level.

Background: This CBM establishes a network of designated national Points of Contact (PoCs) to facilitate communication between participating states on matters of cyber/ICT security, including during incidents. Its purpose is to enable rapid coordination, reduce response times, and minimise the risk of misinterpretation or escalation by ensuring that relevant authorities – both technical and political – can reach each other. Establishing a PoC-network was also a crucial CBM in the past as well as in other domains. Some regard it as the most critical CBM of all, as it underpins the effective functioning of the other CBMs and represents a fundamental objective of the confidence-building process. Together with CBM 3, CBM 10, and CBM 13, it constitutes a central element of the OSCE’s cyber crisis communication mechanism.

Practice: This CBM is among the best-known and most widely implemented. While only around 60% of participating states had nominated PoCs in 2015, today all but one participating state have voluntarily shared at least one PoC, typically comprising technical contacts from CERTs/CSIRTs and policy contacts from Ministries of Foreign Affairs.

This success is largely the result of sustained outreach and capacity-building efforts by the OSCE Secretariat’s TNTD. For instance, the project “Strengthening the Work of the CBM 8 Points of Contact Crisis Communication Network”, supported over the years by the Netherlands, Germany, the US, and other states, has fostered bilateral visits (also of non-like-minded states), study tours, online events, and practical engagement among PoCs. Since 2019, annual PoC conferences and expert online sessions have further ensured that these contacts are more than names in a database, helping to build a genuine community of trust. Moreover, every workshop and each IWG meeting under CBM 11 contributes to sustaining this network, strengthening the familiarity and relationships that are critical for effective crisis communication.

Participating states are required to update PoC information within 30 days of any changes. The OSCE Secretariat’s TNTD manages the contact data via the POLIS platform, which also hosts a dedicated cyber/ICT security workspace. To maintain reliability, the OSCE conducts biannual Communication Checks (CommsChecks), a practice initiated in 2016 and continually refined. These exercises test responsiveness and coordination, ranging from verifying contact details (with confirmation required within 24 hours) to addressing complex, cross-border incident scenarios within 48 hours, using both the POLIS platform and information-exchange templates under CBM 13. Shared information in these processes are often linked to CBM 1 or CBM 15, and exercises also encourage inter-agency and cross-national coordination. The OSCE Secretariat’s TNTD monitors implementation and provides anonymised reports on CommsCheck performance, such as participation and response times, during IWG meetings and in reports to states. There is a good response rate overall.

While the Secretariat does not track the actual use of the PoC directory, some states have publicly shared their experiences, including within UN discussions related to the Global PoC Directory (UN CBM 1). For example, Kazakhstan requested information from another state via the PoC network during a cyber incident, the Czech Republic used the network during the COVID-19 pandemic to warn OSCE partners of malicious cyber activities on hospitals, and Germany has actively used the network since May 2022 to share information on major incidents amid heightened geopolitical tensions, including the 2023 cyber operation on municipal IT service provider Südwestfalen-IT (SIT) in North Rhine-Westphalia.

Key Implementation Activities and Resources

  • To strengthen communication the PoC directory includes policy and technical PoCs from each state. It is the best known cyber CBM and also part of a broader crisis communication framework consisting of the Consultation Mechanism (CBM 3), the Communications Network (CBM 10), and information-exchange templates (CBM 13).

  • Implementation is supported by the OSCE Secretariat’s TNTD which maintains the POLIS-hosted PoC directory and organises annual PoC conferences and biannual Communication Checks testing responsiveness and operational readiness.