ANNEX 1 Cybersecurity Multi-Donor Trust Fund Description This Annex shall be applicable to and form an integral part of all administration agreements for the Trust Fund (collectively, the “Administration Agreements” and each an “Administration Agreement”) between the Bank and any entities that provide any funds to the Trust Fund (collectively, the “Donors”). 1. Objectives The objective of the Trust Fund is to build cybersecurity capacity and resilience of low- and middleincome countries to safely take advantage of ongoing digital transformation and development. 2. Activities The activities to be financed by the Trust Fund are: 2.1. Bank-executed activities, for which the Bank has implementation responsibility: (a) Global Knowledge. Activities under this component will focus on the generation and sharing of cybersecurity knowledge and best practices to help low- and middle-income countries understand and improve their cyber capacity. Specific activities will include, but not be limited to: developing tools and indicators to assess countries’ cybersecurity capacity; preparing global flagship reports and toolkits; and, organizing knowledge events to share experiences among cybersecurity experts. (b) Country-Specific Analysis. Activities under this component will focus on assessing countries’ cybersecurity readiness and maturity to respond to cybersecurity threats. Specific activities will include, but not be limited to, carrying out country-specific assessments using the tools and indicators developed under para (a) above, as well as globally recognized assessment methodologies and frameworks that cover various dimensions of cybersecurity capacity, including cybersecurity policy and strategy; cyber culture and society; cybersecurity education, training and skills; legal and regulatory frameworks; and cybersecurity standards, organizations, and technologies. (c) Technical Assistance. Activities under this component will focus on providing technical assistance to countries to strengthen their capacity to prevent, mitigate and manage cybersecurity risks. Specific activities will include, but not be limited to, organizing trainings and workshops on cybersecurity best practices, including strategies, country readiness and maturity assessments to respond to cybersecurity threats, incident response, culture and awareness, regulatory frameworks, public private partnerships, technical standards and critical information infrastructure protection. (d) Identification, appraisal and implementation support. Carry out identification and appraisal of, and provide implementation support to, Recipient-executed activities. (e) Program management and administration activities for the Trust Fund, including but not limited to, supporting any program governance arrangements and Trust Fund related meetings; planning and executing work plans and budgets; managing communications and 4

Select target paragraph3