A/76/135
II. Existing and emerging threats
6.
While ICTs and an increasingly digitalized and connected world provide
immense opportunities for societies across the globe, the Group reaffirms that the
serious ICT threats identified in previous reports persist. Incidents involving the
malicious use of ICTs by States and non-State actors have increased in scope, scale,
severity and sophistication. While ICT threats manifest themselves differently across
regions, their effects can also be global.
7.
The Group underlines the assessments of the 2015 report that a number of States
are developing ICT capabilities for military purposes; and that the use of ICTs in
future conflicts between States is becoming more likely.
8.
Malicious ICT activity by persistent threat actors, including States and other
actors, can pose a significant risk to international security and stabil ity, economic and
social development, as well as the safety and well-being of individuals.
9.
In addition, States and other actors are actively using more complex and
sophisticated ICT capabilities for political and other purposes. Furthermore, the
Group notes a worrying increase in States’ malicious use of ICT-enabled covert
information campaigns to influence the processes, systems and overall stability of
another State. These uses undermine trust, are potentially escalatory and can threaten
international peace and security. They may also pose direct and indirect harm to
individuals.
10. Harmful ICT activity against critical infrastructure that provides services
domestically, regionally or globally, which was discussed in earlier GGE reports, has
become increasingly serious. Of specific concern is malicious ICT activity affecting
critical information infrastructure, infrastructure providing essential services to the
public, the technical infrastructure essential to the general availability or integrity of
the Internet and health sector entities. The COVID-19 pandemic has demonstrated the
risks and consequences of malicious ICT activities that seek to exploit vulnerabilities
in times when our societies are under enormous strain.
11. New and emerging technologies are expanding development opportunities. Yet,
their ever-evolving properties and characteristics also expand the attack surface,
creating new vectors and vulnerabilities that can be exploited for malicious ICT
activity. Ensuring that vulnerabilities in operational technology and in the
interconnected computing devices, platforms, machines or objects that constitute the
Internet of Things are not exploited for malicious purposes has become a serious
challenge.
12. Capacities to secure information systems continue to differ worldwide, as do the
capacities to develop resilience, protect critical information infrastructure, identify
threats and respond to them in a timely manner. These differences in capacities and
resources, as well as disparities in national law, regulation and practices related to the
use of ICTs, and unequal awareness of and access to existing regional and global
cooperative measures available to mitigate, investigate or recover from such
incidents, increase vulnerabilities and risk for all States.
13. The Group reaffirms that the use of ICTs for terrorist purposes, beyond
recruitment, financing, training and incitement, including for terrorist attacks against
ICTs or ICT-dependent infrastructure, is an increasing possibility that, if left
unaddressed, may threaten international peace and security.
14. The Group also reaffirms that the diversity of malicious non -State actors,
including criminal groups and terrorists, their differing motives, the speed at which
21-04030
7/26