EU Statement – UN Global Mechanism on ICTs in international security: First Substantive Session Key EU messages for Agenda item on Existing and Potential Threats

21.07.2026
New York

20 July 2026, New York - Key EU messages for Agenda item: Existing and Potential Threats at the Global Mechanism on developments in the field of ICTs in the context of international security and advancing responsible State behaviour in the use of ICTs First Substantive Session (20 – 24 July 2026)

  1. Chair, colleagues, it is my honour during the first substantive session of the UN Global Mechanism to deliver this statement on behalf of the EU and Its Member States.

    The Candidate Countries North Macedonia, Montenegro*, Albania*, Ukraine, the Republic of Moldova, Bosnia and Herzegovina* and Georgia, and the EFTA country Norway, member of the European Economic Area, as well as San Marino align themselves with this statement.

  2. The start of our discussions under the UNGGEs and OEWGs has always been, and should continue to be under the Global Mechanism, to enhance our common understanding on the threat landscape.

  3. Understanding the cyber threats and challenges we face allows us to exchange upon our best practices to tackle these and can help us to identify the topics we need to address in more detail, as a matter of priority, during our work in the Dedicated Thematic Groups.

  4. The continued proliferation of new threats in the cyber domain, paired with a more hostile geopolitical context, continue to concern the EU and its Member States. To enhance our collective resilience against such threats, discussions like today’s remain ever more relevant.

  5. Developments in the threat landscape are manyfold. Malicious actors continue to target our government services and critical infrastructure, such as our hospitals, financial institutions, and energy grids. We see cyber tools being used as fully integrated instruments of war, even being used against international humanitarian organizations. And we see how new AI models are used to exploit zero-day vulnerabilities nearly instantly upon their discovery.

  6. Cyber threats continue to target our societies, economies and democracies, having profound effect, causing disruptions in essential services and directly affecting citizens.

  7. Particularly, the healthcare sector has become a prime target for ransomware actors due to the vast amount of sensitive patient data it holds, and the criticality of its operations.

  8. Discussing the protection of the healthcare sector as a critical infrastructure, notably against ransomware attacks, could be one of the topics to be discussed under the DTGs in December.

  9. The EU would be keen to share its experiences gained through the implementation of its 2024 EU Action Plan to Protect the Health Sector from Cyberattacks in enhancing cyber threat detection, reinforcing crisis preparedness, and fostering closer coordination.

  10. Furthermore, we are increasingly seeing non-state actors supporting states in their conduct of malicious activities. Non-state actors that are being tolerated by, linked to, or controlled by a State, function and can be leveraged as highly effective and deniable proxies. The direct or indirect tolerance, or even incentivization of such actors increases the threat of attacks on third parties, as well as the risk of uncontrolled spillover effects.

  11. This evolving cyber threat represents a maturation of a proxy model, cultivating specialised non-state actors that conduct disruptive cyber operations while the sponsor State seeks to keep its distance in order to claim plausible deniability and thus avoid complying with the obligations arising from its responsibility.

  12. This is a concerning trend, that we should not allow to develop further. Actively using and encouraging proxies is irresponsible behaviour, contrary to the UN norms of responsible state behaviour advising not to allow your territory to be used for malicious cyber activities and not to target the critical infrastructure of others.

  13. It is important that States take responsibility and are held accountable for their activities, including if they are using proxies to execute them – in line with the law of State responsibility.

  14. Therefore, last week the EU and its Member States, alongside the United Kingdom, exposed and condemned the misuse by Russia of an eco-system of Russian actors, including a government agency, private sector, hacktivists and criminals, to target the EU, its Member States and partners consistently through cyber-attacks.

  15. Russia's security services are using private companies and individuals to conduct malicious cyber activities for them. They contract such companies to secure technical infrastructure, vulnerability research, malware development specific hardware and any other relevant enabling activities targeting the EU and Member States.

  16. The EU therefore has imposed sanctions on those individuals and entities that support Russia in their malicious behaviour against the EU, its Member States and partners.

  17. It is also for this reason, that Estonia, supported by the EU and all Member States, objected to the stakeholder JSC Positive Technologies, who we already knew were supporting Russian operations, behaviour that contradicts the ambition of the UN Global Mechanism to enhance international security and stability in cyberspace.

  18. The EU and Member States see a need to ensure international security and stability by raising awareness on the most pertinent cyber threats. The trends of malicious behaviour that pose risks to security and stability should be known, so we are able to uphold responsible state behaviour and exchange on best practices to prevent, mitigate and respond to these types of threats.

  19. To this end, the EU will also continue to raise awareness about cyber threats, including through threat advisories such as by the EU Cybersecurity Agency (ENISA) and the CERT for the EU institutions, bodies and agencies (CERT-EU) on particular Advanced Persistent Threats that continue to conduct malicious cyber activities against business and governments in the EU, and likely also target other governments around the world.

  20. The EU and its Member States will continue to cooperate with our international partners to promote an open, free, stable and secure cyberspace and to support states in their understanding of and response to cyber threats.

  21. The DTGs could support the exchange on cyber threats, allowing us to formulate recommendations as to how to reinforce responsible state behaviour by advancing the implementation of the framework and moreover enhance our collective resilience.

     

    *North Macedonia, Montenegro, Serbia, Albania and Bosnia and Herzegovina continue to be part of the Stabilisation and Association Process.