From July 20 to 24, the United Nations hosted the first Substantive Meeting of the Global Mechanism on ICTs in the Context of International Security, the new permanent mechanism dedicated to international security in the digital domain and to promoting responsible behavior by states in the use of technology.
Behind this complex term lie very concrete issues: attacks on hospitals, energy infrastructure, and public services; ransomware; the security of digital supply chains; the use of artificial intelligence to make attacks more effective; and the risk that a cyber incident could fuel tensions between countries.
The Mechanism builds on the legacyof the United NationsOpen-Ended Working Group United Nations, which established a common framework based on five pillars: threats, norms of responsible state behavior, international law, confidence-building measures, and cyber capacity building. The real innovation now lies in the effort to transform a negotiation process into a permanent, implementation-oriented body.

The main message that emerged from the meeting can be summarized simply: after years spent establishing shared principles, we must now demonstrate that these principles can produce concrete results.
States have already agreed that international law, starting with the United Nations Charter, also applies to cyberspace. They have also established eleven voluntary norms of responsible behavior, which include the protection of critical infrastructure, cooperation in the event of an incident, and combating the use of their territory for illicit cyber activities.
The challenge now is to translate these commitments into national strategies, institutional frameworks, and prevention and response capabilities. After all, an international standard alone cannot protect a hospital or an energy grid. What is needed are competent authorities, trained personnel, incident management procedures, threat analysis capabilities, public-private collaboration, and drills.
The discussions in New York confirmed this pragmatic approach. Ransomware, critical infrastructure, and the malicious use of artificial intelligence were identified as priorities for cooperation. The discussion on international law also shifted from general statements to an examination of concrete scenarios, such as attacks on hospitals, water systems, and energy infrastructure.
“The success of the Global Mechanism will be measured not only by the quality of the documents approved, but by its ability to help states prevent incidents, protect essential services, and cooperate when a crisis occurs,” emphasizes Matteo Lucchetti, Director of Cyber 4.0. “The challenge is to build a stable link between diplomacy, public policy, and operational capabilities.”

The Role of Stakeholders
The Mechanism remains an intergovernmental body: it is the states that set the rules and assume international commitments. However, cybersecurity depends largely on infrastructure, technologies, and expertise that lie outside the purview of public administrations.
Businesses, essential service providers, universities, research centers, civil society organizations, and technical communities can help understand threats, develop solutions, build expertise, and assess the effectiveness of the policies adopted.
The session dedicated to stakeholders thus highlighted the need for their more systematic participation. The participating organizations provided methodologies, training platforms, technical tools, and operational expertise that will also be useful for the Dedicated Thematic Groups—the thematic groups that will meet in December 2026.
However, the issue of accreditation procedures remains unresolved. The Russian Federation has raised objections to 43 organizations, including Cyber 4.0, START 4.0, the CINI Cybersecurity National Lab, and international universities and research institutes. The system allows each state to oppose accreditation without being required to provide a detailed justification. The European Union has also expressed regret over the lack of transparency and predictability in the process.
Cyber 4.0 was nevertheless able to participate in the proceedings thanks to the decision by the Ministry of Foreign Affairs and International Cooperation to include the Center in the official Italian delegation, alongside the National Cybersecurity Agency and START 4.0.
This is a point worth noting without turning it into a political issue, but one that highlights a fundamental question: if the Mechanism is expected to produce operational results, it must have transparent access to the necessary expertise.
“We greatly appreciated the MAECI’s decision to highlight the various components of the national ecosystem within the Italian delegation,” notes Lucchetti. “The hope is that the thematic groups meeting in December will be able to define mechanisms that allow qualified organizations to make an active and direct contribution—not to replace the states, but to help them transform international commitments into capabilities, tools, and verifiable results.”
Cyber Capacity Building at the Heart of the Mechanism
Among the five pillars, cyber capacity building is becoming increasingly important. The rules may be global, but the capacity to enforce them remains unevenly distributed.
Many countries are still in the process of establishing national strategies, competent authorities, incident response structures, and training programs. These gaps are not merely a development issue: in an interconnected world, the vulnerability of a system or supply chain can have repercussions beyond national borders.
Capacity building cannot, therefore, be limited to occasional training courses. It must encompass institutional development, governance, training, the creation of professional communities, and access to technical tools, addressing the priorities of the beneficiary countries and producing sustainable results.
In this context, Cyber 4.0 collaborates with MAECI and other Italian government agencies, bringing together institutional cooperation, technical expertise, and technology transfer. The Italy-Ghana partnership supports the implementation of the national cybersecurity strategy, skills development, and dialogue on cyber diplomacy. As part of the Mattei Plan and the AI Hub for Sustainable Development, Cyber4Africa, on the other hand, assists African startups active in artificial intelligence in adopting security-by-design practices.
In addition to these initiatives, there are programs funded by the European Union and international organizations: ranging from the revision of the regional plan on cybersecurity and cybercrime for Caribbean countries to the training of Ukrainian civil servants, and including courses on cyber diplomacy for Latin American diplomats.
A New Phase for Cyber Diplomacy
The first Substantive Meeting indicates that cyber diplomacy is entering a more mature phase. While the discussions remain marked by deep differences, the establishment of a permanent forum represents a significant achievement.
The next test will be the thematic groups in December. It is in those forums that the Mechanism will have to demonstrate its ability to engage the appropriate expertise and produce recommendations that States can actually use.
“Cyber diplomacy should not be viewed as a subject reserved for specialists,”concludes Lucchetti. “It concerns the continuity of essential services, the security of businesses, the protection of citizens, and the ability of countries to benefit from the digital transformation without increasing its risks. The Global Mechanism can succeed if it is able to balance these two dimensions: building political trust and achieving concrete, shared resilience. “.
