CBM 8: Public Private Partnerships (PPP’s)
United Nations
Measure
Background: This CBM was also first articulated in its current form in the third APR in 2024. The CBM acknowledges that “[a] range of technical capabilities and knowledge are required to detect, defend against and respond to and recover from ICT incidents.” Much of the digital infrastructure is privately owned, and private companies are frequently the primary targets of cyber operations, thus, it is crucial to build public-private sector partnerships to effectively address ICT security.
Practice: To date, no implementation, or at least no concrete steps have been taken to explicitly implement this CBM. However, the OEWG has served as a platform for states to share information on national efforts and good practices, which contributes implicitly to this CBM since the CBM is to be implemented primarily through the exchange of good practices. In addition, the measure anticipates regular public–private dialogue. While private sector participation in the OEWG was limited - restricted to accredited representatives who had only brief opportunities to contribute - their presence nonetheless supported partial implementation of this CBM. This is also supposed to be the case in the future Global Mechanism.
Key Implementation Activities and Resources
States agreed to share national experiences and good practices related to public-private partnerships and stakeholder engagement in cybersecurity.
Implementation is implicitly supported by stakeholder participation in UN processes.