New York. 9 July 2025.
Chair, Excellencies, distinguished delegates,
I am Christopher Painter, Strategic Advisor to the Global Cyber Alliance. GCA is a not-for-profit which works internationally to improve the Internet and help people and organizations be more secure online.
We thank the Chair for the inclusive approach and the Zero Draft and Rev1 documents. GCA welcomes the emphasis on practical capacity building as a core element of cyber stability. However, we are concerned that several proposed initiatives risk duplicating existing, effective mechanisms.
Here’s four examples:
- The draft’s call for a new Global ICT Security Cooperation and Capacity Building Portal risks duplicating with existing platforms like the GFCE’s Cybil Portal and UNIDIR’s policy portal, both of which already catalog projects and connect donors with implementers.
- The creation of a UN-managed sponsorship program would divert from successful initiatives such as the Women in Cyber Fellowship program or the France-Irish sponsorship program for small islands and developing States. Member States should consider the UN additional overhead costs and decide whether they want less beneficiaries for more money.
- The proposal for standardised training and curriculum and a UN CyberResilience Academy would need to be carefully calibrated to avoid duplicating the UNIDIR Academy and decades of work by civil society organisations like FIRST, which has trained national CSIRTs with technical hands-on training already tailored, trusted, and deployed in more than 70 countries, or CREST working with regulators in building standards and certifications for critical infrastructure protection.
- Future discussions on a new UN voluntary fund should consider the serious risk of diverting funds from existing funding streams like the World Bank Cybersecurity Multi-Donor Trust Fund, and public–private partnerships like the Common Good Cyber Fund recently launched to support nonprofit work protecting vulnerable civil society and digital infrastructure. If established, the UN voluntary fund should be limited to helping states participate in UN meetings and activity.
These existing efforts are not theoretical, they are functioning, field-tested, and responsive to national priorities. Creating new structures in a State-only context and without integrating stakeholders risks duplication, confusion, and inefficiency.
The recent Common Good Cyber report “Nonprofit Contributions to Cybersecurity”, commissioned by the EU Institute for Security Studies and funded by the Global Gateway, documents 334 nonprofit-led initiatives. But it also highlights ongoing challenges: lack of funding, limited policy access, and weak coordination with multilateral bodies.
We need to scale what works, not replace it.
For this reason, stakeholders must be actively and meaningfully involved in any permanent mechanism. We align with the Joint Civil Society Statement in expressing concern that stakeholder involvement is still not ensured in a consistent and substantive way.
In that spirit, we offer two recommendations:
- Assess before you build: Include a commitment for annual mapping exercises in the final report to identify where to create partnerships with existing stakeholders. GCA and Common Good Cyber can support this with current data.
- Enhance stakeholder accreditation and participation : To be truly inclusive and transparent, and to better respond to contemporary challenges, the permanent mechanism needs to overcome the veto and to enable more interaction with stakeholders in formal and informal meetings.
Chair, cybersecurity capacity building must be inclusive, efficient, and grounded in what already works. We urge the OEWG not to multiply new mechanisms, but to multiply impact by reinforcing the expertise, infrastructure, and trust networks already serving the global community.
In conclusion, GCA supports the OEWG’s goals and priorities through its ongoing efforts in standards setting, capacity building, and stakeholder engagement; and looks forward to continued collaboration with States and stakeholders.
Thank you.



