Cyber Confidence-Building Measures

CBM 4: Strengthen (regional) CBM implementation

United Nations

UNWidely implemented2023

Measure

Background: First articulated in the second APR (2023), this CBM builds on earlier reports and emphasises the importance of cooperation in CBM implementation at the bilateral, regional, and multilateral levels. Regional organisations play a particularly important role, as many already operate cyber CBMs tailored to their specific contexts. The measure also stresses that the global list of CBMs is not exhaustive, and that existing CBMs must be implemented cooperatively rather than remain only on paper.

Practice: This CBM is broad in scope, recognising that CBM implementation must account for diverse national and regional circumstances and can extend beyond measures formally defined by the UN. In this context, the exchange of views within the dedicated UN discussions on the development and application of CBMs directly fulfills this measure under the UN framework. It should be noted that cross-regional dialogue also occurred within the OEWG, since representatives from OAS and OSCE – who specialise in cyber issues – participate in these discussions.

CBM 4 also acknowledges the possibility of developing new measures. This has already materialised: four additional CBMs were articulated in the third APR (2024) and later endorsed in the OEWG's final report. These can be seen as an outcome of this CBM, even though their explicit practical implementation is still pending. Thus, this CBM can be considered widely implemented, though difficult to quantify, as there is no agreed upon vision of what full implementation should look like.

The Confidence Builders have further emphasised the links between this CBM and OAS CBM 4 and OSCE CBM 5.

Key Implementation Activities and Resources

  • States agreed to discuss, develop, and refine cyber CBMs, including the possible adoption of additional measures under the UN framework or regional organisations.