Accessibility

Conclusions from the Workshop to Strengthen Regional Cyber Norms Guidance through Practice-Based Approaches and the Case of Ransomware

EU CyberNet and LAC4 co-hosted on 8th July a workshop in New York in the premises of Estonian Mission to the UN to strengthen regional cyber norms guidance through practice-based approaches and the case of ransomware as a side-event of the UN Open-ended Working Group on ICTs together with RUSI, Estonia, Chile and the Dominican Republic.

The workshop aimed to enhance a practice-based and regionally sensitive norms guidance by addressing ransomware incidents in Latin America and the Caribbean. Participants shared experiences to collectively map how this cross-cutting regional concern can inform regional norms guidance.

Representatives of Chile and the Dominican Republic shared lessons from ransomware incidents. Chile detailed its Ministry of Foreign Affairs’ efforts to implement norms of responsible state behavior, focusing on international cooperation and information exchange. The Dominican Republic described their cybersecurity governance model, which enables quick interagency cooperation and collaboration with private sector actors, which crucial in handling major ransomware incidents.

Further insights were provided by representatives from Colombia, Uruguay, and Brazil. Colombia reported their swift and efficient response to ransomware attacks through cooperation with public institutions and private sector actors, emphasizing the importance of establishing incident response protocols and learning from past incidents. Uruguay discussed applying norms of responsible state behavior to ransomware cases, highlighting their participation in the Counter Ransomware Initiative and efforts to strengthen national cybercrime capabilities. Brazil outlined the role of government coordination, describing their Federal Incident Management Networks and special cybercrime directorate that coordinate responses at the state level, and mentioning their National Cybersecurity Council, which includes civil society organizations.

Participants discussed ransomware as an emerging threat to international peace and security, as recognized in the Annual Progress Report of the OEWG. The need for further steps towards a practice-oriented dialogue on how norms connect with such emerging threats was emphasized. It was acknowledged that countries in Latin America and the Caribbean have been dealing with an increasing number of ransomware incidents in recent years, disproportionately impacting governments and critical national infrastructure.

In response, LAC4 highlighted their work in enhancing regional capabilities to combat ransomware through awareness and technical trainings, crisis response, and collaboration at various levels. This ongoing effort by LAC4 serves as a mean to assist countries, underscoring the importance of collective regional efforts to address and mitigate the growing threat of ransomware.

The side-event workshop was organized by EU CyberNet, LAC4, Permanent Mission of Estonia to the United Nation, Ministry of Foreign Affairs of Chile, Ministry of Foreign Affairs of the Dominican Republic and Royal United Services Intitute (RUSI).



Keep reading similar articles
EU CyberNet Launches Expert Podcast Series

EU CyberNet launches a podcast series to bridge the expertise from EU CyberNet’s Expert Pool and its partners to wider cybersecurity and cyber capacity building community on people, policies and practices shaping cybersecurity globally.

The 9th Blog Article of the EU CyberNet Expert Blog Series: When AI Makes Cybersecurity Decisions: Five Governance Questions Every Organisation Should Answer

EU CyberNet has published the ninth blog article in its Expert Blog Series. The ninth article, titled “When AI Makes Cybersecurity Decisions: Five Governance Questions Every Organisation Should Answer” is written by EU CyberNet Expert Anahiby Becerril.

The 8th Blog Article of the EU CyberNet Expert Blog Series: The Institutional AI Dependency Test: Can Public Services Continue When AI Cannot Be Trusted? An Evidence-Led Governance Exercise for Cyber Resilience

EU CyberNet has published the eight blog article in its Expert Blog Series. The eight article, titled “The Institutional AI Dependency Test: Can Public Services Continue When AI Cannot Be Trusted? An Evidence-Led Governance Exercise for Cyber Resilience” is written by EU CyberNet Expert Andra T. Alcalá.

Reflecting EU CyberNet Summer School 2026: Participants’ Testimonials

EU CyberNet asked four EU CyberNet Summer School 2026 participants – Gabrielle Botbol, Emmanuel Chagara, Olesya Danylchenko and Lisbeth Laurie – to share their experience in the Summer School.

Reflecting EU CyberNet Summer School 2026: Andrea Calderaro

EU CyberNet discussed with Summer School 2026 participants their experience and thoughts on the future of cyber diplomacy. Read an interview with our co-organiser Andrea Calderaro, Project Director of EU Cyber Direct.

EU CyberNet Participated in Regional Cybersecurity Exchange and the Launch of the Cyber Cluster Global Alliance in Costa Rica

EU CyberNet,together with LAC4, participated in the EU-LAC Digital Alliance technical exchange visit on cybersecurity and secure connectivity in Central America and the Cybersec Summit 2026 in San José, Costa Rica on 11-12 August 2026.