2017 to develop a framework for a joint EU diplomatic response to malicious cyber activities, the cyber diplomacy toolbox. Taken together with the EU Cyber Security Strategy, this demonstrates the importance the EU places on cyber security of the EU and its neighbourhood and the UK will continue to look for opportunities to build on this important work. The NCSC will play a key role in the UK’s work to promote international collaboration: engagement with a wide range of international partners will include building technical capabilities and capacity, incident handling, and information sharing and situational awareness. Over the next five years, the UK will therefore pursue international action to: - collaborate operationally in tackling threats to common interests; - develop a common understanding of responsible state behaviour in cyberspace; - develop the cyber security capabilities of our international partners; and, - safeguard the benefits of a free, open, peaceful and secure cyberspace. This work will build on and reinforce the United Kingdom’s role in helping to stimulate international debate, showcased prominently through the launch of the London Process of Global Conferences on Cyberspace in 2011, which succeeded in putting this issue on the international agenda. Further work is required to help build global consensus around the rules of the road for state behaviour in cyberspace, and the next Conference in this series hosted by India in 2017 will provide an important platform to continue this debate. The United Kingdom has been an active member of the United Nations Group of Government Experts (UNGGE) on developments in the field of information and telecommunications in the context of international security. Despite the lack of consensus in the 2017 group, we are committed to promoting an international stability framework for cyberspace based on the application of existing international law, agreed voluntary norms of responsible state behaviour and confidence building measures (CBMs), supported by coordinated capacity building programmes. This work will augment our efforts in the OSCE to encourage implementation of CBMs – the United Kingdom leads by example in adopting measures and we are pressing for movement from paper commitments to practical implementation. We continue to work closely with the NATO Co-operative Cyber Defence Centre of Excellence in Estonia. The recognition by NATO of cyberspace as a domain of operations has sparked meaningful conversations on building resilience across the membership. In February 2017, the UK signed the NATO Cyber Defence Memorandum of Understanding so that we can share our expertise with our international allies, and learn from their experiences. The UK also funded the Commonwealth Telecommunications Organisation (CTO) to develop and implement a national cyber governance model for Commonwealth countries. This had directly supported the Commonwealth in developing National Cyber Security Strategies with Botswana, Cameroon and Uganda. The CTO are now expanding that assistance to a second large tranche of Commonwealth countries. The United Kingdom ratified the Convention on Cybercrime (the Budapest Convention) in 2011 and reiterates it is the best model in the bid to tackle international cybercrime. It aims to facilitate international cooperation on cybercrime, provide for national criminal procedural 6

Select target paragraph3