Chapter 1 Background and Introduction In 2021, the OSCE initiated an extra-budgetary project focused on CBM 3 and CBM 15, specifically on cyber/ICT crisis communication procedures, crisis management and the classification of ICT incidents in terms of the scale and seriousness of the incident. The project aims to raise the implementation rate of the OSCE cyber/ICT CBMs, as well as enhance capacities of OSCE participating States to deal with significant cyber/ICT incidents in an effective way through providing support in developing national cyber incident severity scales. Recognizing the increasing complexity of cyber/ICT security incidents and the need for advancing crisis management procedures and expanding the classification of cyber/ICT incidents in terms of their scale and seriousness, the OSCE Secretariat’s Transnational Threats Department aims to promote, assist and foster the use of national cyber incident severity scales in OSCE participating States through the aforementioned extra-budgetary project. Rather than only focusing on severity scales per se, the project is taking a broader approach to cover the processes, capacities, resources and institutional arrangements required to design, develop and implement such scales, hence the reference throughout the document to national cyber incident classification systems. Drawing from CBM 15 on critical infrastructure protection and CBM 3 on consultation procedures in particular, the project acknowledges that creating a cyber/ICT incident classification system can contribute significantly to enabling the proper prioritization and management of

Select target paragraph3