Cyber Confidence-Building Measures

CBM 7: Critical infrastructure protection

United Nations

UNNot implemented2023

Measure

Background: First articulated in the third APR (2024), this CBM focuses on strengthening state resilience in protecting CI and CII. It highlights the cross-cutting role of capacity-building (linking it to CBM 5) and recognizes a strong connection with CBM 8, since much critical infrastructure is operated by private actors.

Practice: To date, no implementation, or at least no concrete steps have been taken to explicitly implement this CBM. However, states have used the OEWG to exchange information and practices related to CI and CII protection, which implicitly contributes to the CBM’s implementation since the CBM is to be implemented primarily through the exchange of information. The 2025 final report of the OEWG specifically proposes “further study of concrete measures on how CBMs can be used in the case of severe ICT incidents affecting CI and CII.”

Key Implementation Activities and Resources

  • States agreed to exchange information and experiences related to the protection of critical infrastructure and critical information infrastructure through UN discussions and related processes.