CBM 2: Hold consultations
United Nations
Measure
Background: This CBM was first articulated in its current form in the second APR (2023), building on earlier GGE and OEWG outputs. It emphasises the value of open and transparent exchanges on threat perceptions, vulnerabilities, responsible state behaviour, and good practices, with the aim of broadening perspectives and improving state preparedness, including early warnings of emerging threats. This CBM also encourages the exploration of mechanisms for regular cross-regional exchanges of lessons learned and good practices related to CBMs. It underscores the importance of considering CBMs at the bilateral, regional, and multilateral levels, while recognising regional differences and the institutional structures of relevant organisations. Ultimately, the measure seeks to advance the collective development and implementation of the framework for responsible state behaviour in the use of ICTs, while enhancing transparency and predictability of state behaviour in cyberspace.
Practice: This CBM is broadly formulated, encompassing a wide spectrum of activities. Member states often stress that the OEWG itself functioned as a CBM by providing a platform for regular exchanges of views on threats, responsible state behaviour, and the implementation of CBMs. This is particularly relevant in the context of CBM 2 and contributes significantly – albeit implicitly – to its implementation. Even though such exchanges are sometimes criticised for remaining surface level, the very fact that they take place in an inclusive, multilateral setting is seen as a success. The aim of this CBM is to continue fostering such exchanges, highlighting the spirit that “the OEWG itself served as a CBM.” This function could be carried forward under the future Global Mechanism: “States highlighted that the future permanent mechanism could likewise serve as a CBM as well as a platform for the implementation of CBMs.”
Overall, this CBM can be understood as one that may not necessarily require explicit activities for its implementation but that is primarily realised through ongoing dialogue and engagement. At present, there is no clearly defined global vision for what its implementation should concretely entail. Nevertheless, an open, informal, cross-regional group of states (“Confidence Builders” consisting of Australia, Brazil, Canada, Chile, Colombia, Czech Republic, Dominican Republic, Fiji, Ghana, Germany, Israel, Jordan, Republic of Korea, Mexico, The Netherlands, Singapore, Uruguay) has put forward suggestions to shape its future implementation: “States should consider using existing dialogues and fora to voluntarily share information and good practices, lessons or white papers on existing and emerging ICT security-related threats and incidents, national strategies and standards for vulnerability analysis of ICT products, national and regional approaches to risk management and conflict prevention and national approaches to classifying ICT incidents in terms of scale and seriousness.” These proposals demonstrate that this CBM's implementation is linked to CBMs 3 and 4.
While no explicit global implementation measures have yet been adopted, implicit progress can already be observed through activities within the OEWG and related fora. Thus, this CBM is implemented, but not widely. Nevertheless, the CBM's practical application remains somewhat undefined, and its future development will likely depend on the extent to which states are willing to operationalise these proposals under the Global Mechanism.
Key Implementation Activities and Resources
States exchange views on cyber threats, responsible state behaviour, and CBM implementation through the UN discussions and other bilateral, regional, and multilateral dialogue formats implicitly supporting implementing this CBM.