A/76/135 II. Existing and emerging threats 6. While ICTs and an increasingly digitalized and connected world provide immense opportunities for societies across the globe, the Group reaffirms that the serious ICT threats identified in previous reports persist. Incidents involving the malicious use of ICTs by States and non-State actors have increased in scope, scale, severity and sophistication. While ICT threats manifest themselves differently across regions, their effects can also be global. 7. The Group underlines the assessments of the 2015 report that a number of States are developing ICT capabilities for military purposes; and that the use of ICTs in future conflicts between States is becoming more likely. 8. Malicious ICT activity by persistent threat actors, including States and other actors, can pose a significant risk to international security and stabil ity, economic and social development, as well as the safety and well-being of individuals. 9. In addition, States and other actors are actively using more complex and sophisticated ICT capabilities for political and other purposes. Furthermore, the Group notes a worrying increase in States’ malicious use of ICT-enabled covert information campaigns to influence the processes, systems and overall stability of another State. These uses undermine trust, are potentially escalatory and can threaten international peace and security. They may also pose direct and indirect harm to individuals. 10. Harmful ICT activity against critical infrastructure that provides services domestically, regionally or globally, which was discussed in earlier GGE reports, has become increasingly serious. Of specific concern is malicious ICT activity affecting critical information infrastructure, infrastructure providing essential services to the public, the technical infrastructure essential to the general availability or integrity of the Internet and health sector entities. The COVID-19 pandemic has demonstrated the risks and consequences of malicious ICT activities that seek to exploit vulnerabilities in times when our societies are under enormous strain. 11. New and emerging technologies are expanding development opportunities. Yet, their ever-evolving properties and characteristics also expand the attack surface, creating new vectors and vulnerabilities that can be exploited for malicious ICT activity. Ensuring that vulnerabilities in operational technology and in the interconnected computing devices, platforms, machines or objects that constitute the Internet of Things are not exploited for malicious purposes has become a serious challenge. 12. Capacities to secure information systems continue to differ worldwide, as do the capacities to develop resilience, protect critical information infrastructure, identify threats and respond to them in a timely manner. These differences in capacities and resources, as well as disparities in national law, regulation and practices related to the use of ICTs, and unequal awareness of and access to existing regional and global cooperative measures available to mitigate, investigate or recover from such incidents, increase vulnerabilities and risk for all States. 13. The Group reaffirms that the use of ICTs for terrorist purposes, beyond recruitment, financing, training and incitement, including for terrorist attacks against ICTs or ICT-dependent infrastructure, is an increasing possibility that, if left unaddressed, may threaten international peace and security. 14. The Group also reaffirms that the diversity of malicious non -State actors, including criminal groups and terrorists, their differing motives, the speed at which 21-04030 7/26

Select target paragraph3