EU outlines priorities for confidence-building measures at UN Global Mechanism on cybersecurity
The European Union has called for the early implementation of existing confidence-building measures under the UN Global Mechanism on ICTs in the Context of International Security, emphasizing practical cooperation, transparency, and communication between states to reduce the risk of cyber incidents.
During the First Substantive Session of the UN Global Mechanism on Developments in the Field of ICTs in the Context of International Security, held in New York from 20 to 24 July 2026, the European Union presented its priorities for advancing confidence-building measures (CBMs) aimed at strengthening international cybersecurity cooperation and promoting responsible state behaviour in cyberspace.
Speaking on behalf of the EU and its member states, the Union stated that building trust in cyberspace requires sustained engagement by states and highlighted the progress achieved under the UN Open-Ended Working Group (OEWG), particularly the agreement on eight voluntary global confidence-building measures.
According to the EU, these measures play an important role in reducing misunderstandings, preventing escalation during cyber incidents, improving the predictability of state behaviour, and contributing to greater international stability. The Union argued that the Global Mechanism should initially focus on implementing these existing measures rather than developing new ones.
The EU also encouraged the Global Mechanism to complement, rather than duplicate, the work of regional organisations such as the Organization for Security and Co-operation in Europe (OSCE), the Organization of American States (OAS), the ASEAN Regional Forum (ARF), and the Economic Community of West African States (ECOWAS). It stressed the importance of sharing practical tools, best practices, and examples that can help states incorporate confidence-building measures into national legislation, cybersecurity policies, and institutional frameworks.
Among its specific proposals, the EU expressed support for simulation exercises to help governments operationalise confidence-building measures and improve preparedness to respond to cyber incidents.
The statement also highlighted the importance of the Point of Contact (POC) Directory, one of the eight confidence-building measures agreed under the OEWG. According to the EU, the directory provides governments with direct channels of communication during cyber incidents, particularly where bilateral or regional contacts do not already exist. The Union supported integrating the directory into the Global Security and Cyber Capacity Platform (GSCCP) while emphasising that it should complement, rather than replace, existing national, regional, and bilateral communication mechanisms.
In addition, the EU outlined several practical areas for future cooperation under the Global Mechanism. These include the voluntary exchange of national ICT strategies, cybersecurity legislation, institutional practices, and policy documents; cooperation on protecting critical infrastructure; sharing information on cybersecurity capacity-building partnerships; and organising seminars, workshops, and training programmes to strengthen the implementation of confidence-building measures.
The EU concluded that the Global Mechanism provides an opportunity to build upon the achievements of the OEWG by embedding confidence-building measures into national and regional cybersecurity practices and reinforcing their role alongside international law and the existing framework of responsible state behaviour in cyberspace.
