decision making involved in publicly or privately attributing malicious activity. These being that a decision to attribute will be based on an objective technical assessment and international law considerations. States will also want to take a national decision, based on diplomatic considerations, about whether to make known the results of any attribution they have conducted – publicly or privately. Further proposals touching on principles of existing international law, such as that of the principle of non-intervention,f may be better reflected in Section C. A final group of proposals, whilst worthy of concerted international attention, address topics that the UK considers to beyond the mandate of the OEWG for instance: data protection, internet governance, national regulation, and free trade. We continue to actively support international discussion of these topics in appropriate fora. E. Confidence Building Measures We welcome the focus placed on operationalisation of confidence building measures (CBMs) (E41). It could be prefaced by a reference to the fact that States reaffirmed the value of CBMs. Listing all those CBMs mentioned in discussion may be challenging (E42). It could be better to note that there was detailed discussion of many existing, agreed CBMs, as well as some new proposals. The pre-draft could then move onto specific CBMs such as the Points of Contact (E44). On this issue, we note that Points of Contact are not just a prerequisite to CBMs, but also a CBM in their own right. We consider that the importance of national and regional structures being in place (E46) cannot be underestimated. Such structures enable States to provide credible and wellexercised responses to incidents and require effort and resource to maintain. National Computer Emergency Response Teams (CERTs) are particularly important in this regard and should be highlighted. Equally important, but different, is the work regional organisations do to develop and implement CBMs. We consider this element, including the need for inclusion and possible universalisation could merit its own paragraph. F. Capacity Building The crucial nature of capacity building in supporting both the international cyberspace stability framework and the Sustainable Development Goals is well captured (Chapeau, F48). We fully support the references to two-way processes (F53) and the United Nations Women, Peace and Security agenda (F56). We consider any mention of the concept of the ‘development of a global capacity-building agenda’ (F55) would benefit from some clarification. We suggest that additional text could be included in this section to note the richness of the discussion on this topic, as well as strengthening the reference to the need for cyber diplomats to participate in OEWG discussions (F50). We consider that this section of the pre-draft must recognise that coordination is key (F55), but should also highlight the need for all States and stakeholders to contribute to the mobilisation of funding and resource for capacity building wherever possible, as this underpins our ability to implement the framework and achieve the recommendations made in this pre-draft. G. Regular Institutional Dialogue We welcome the description of the history of the processes (G58) and the capturing of the proposal for Regular Institutional Dialogue based on the existing process (G62). Efforts to capture the proposals for Regular Institutional Dialogue based on new arrangements (G59, G60, G61) must reflect the call from several Member States that is was important to start from the purpose of any possible dialogue and how it would further international peace and

Select target paragraph3