Keeping the Lights On: How the OSCE is navigating growing cybersecurity challenges
Shownotes
As geopolitical tensions shift into cyberspace, the OSCE faces mounting challenges. With Russia among its 57 members, the concept of consensus-based security is under strain. Alexandra Paulus and Nadja Douglas analyse if and how the OSCE can adapt to an increasingly contested cyber landscape.
Guests:
Nadja Douglas is a Senior Associate of SWP‘s Eastern Europe/Eurasia Research Division. She leads the SWP OSCE project, working to define the OSCE's changing role in a new European security order.
Alexandra Paulus is a Senior Associate of the International Security Research Division at SWP. She heads up SWP's research cluster „Cyber Security and Digital Policy“.
Host: Esme Nicholson
Recommended Reading:
Nadja Douglas: The OSCE as a Yardstick for Multilateral Security, SWP Comment 2025/C 51, 16.12.2025
Transkript anzeigen
00:00:02: As geopolitical tensions play out increasingly in cyberspace and these evolving security threats are compounded by the rapid rise of AI, The Organization for Security and Cooperation in Europe better known as OSCE has its work cut-out.
00:00:17: And with Russia among the OSCE's fifty seven members it's consensus based approach to security is being undermined by an aggressor sitting at a table.
00:00:28: You're listening to the latest podcast from The German Institute for International and Security Affairs, or SWP For Short here in Berlin.
00:00:36: In today's episode we are asking how keep the lights on increasingly dark times.
00:00:41: as Russia continues its war in Ukraine targets fellow OSCE states with cyber attacks AND as Five Eyes Intelligence agencies warn that AI will render cyber defence capabilities outdated...in months not years!
00:00:58: I'm your host, Desmi Nicholson.
00:00:59: And to discuss the state of cybersecurity in Europe and beyond... ...I am joined today by SWPs Alexandra Paulus and Nadja Douglas.
00:01:08: Alexandra Paulous heads up SWP's research cluster Cybersecurity & Digital Policy,... ...and her work intersects technology security- and defence policy,….
00:01:18: …and examines the societal political and military potential….
00:01:21: ..of critical technologies as well as risks that they pose.
00:01:24: Alexandra welcome to the studio!
00:01:26: Thanks for having me.
00:01:28: Nadia Douglas leads the SWP OSCE project, working to define the OSCE's changing role in a new European security order.
00:01:37: Nadia's research focuses on the political and defence aspects of European Security, Eastern Partnerships & The Republic Of Moldova.
00:01:50: So we have a rather fraught cyber security situation within the OSCE's fifty-seven nation membership set against a challenging geopolitical situation and rapidly changing technological landscape, not least because of AI.
00:02:06: How resilient is the cyber defence sector?
00:02:09: And the OSC.
00:02:11: Alexandra perhaps you could start by painting a picture Sure.
00:02:17: So the cybersecurity situation has been worsening for years or decades even.
00:02:23: to illustrate only last year, twenty-twenty five cyber operations caused harms to the German economy two and equivalent of four point five off the German GDP.
00:02:34: so that is a huge number.
00:02:36: and also just to illustrate with one incident that can show us what harm such cyber operations can cause.
00:02:44: At the end of last year as well in December, Russian actors came very close taking out parts from Polish energy sector.
00:02:52: so it would have caused a massive blackout at the end when it was very cold, so with creating huge harms for the civilian populations in a EU and NATO country.
00:03:05: So the challenge of cybersecurity and cyber operations really affects all parts of society—it can affect individuals but also critical infrastructures like energy sector militaries.
00:03:16: And yeah, cyber diplomacy is really the quest to have international dialogues and alleviate these threats to international security.
00:03:28: There you can sort of have four pillars.
00:03:31: You could have the International Law question that defines what states are legally not permitted to do with each other.
00:03:39: You can have norms that aren't legally but more politically binding seen as a softer instrument guardrails and rules for what states should, and shouldn't do.
00:03:52: Then you have confidence-building measures that are supposed to decrease the chance of inadvertent escalation of conflict.
00:04:00: And then there's cyber capacity building that is meant to increase the capability levels of all players involved.
00:04:07: so in all we've seen some important successes but overall they remain rather limited.
00:04:13: I'd
00:04:13: say We'll come to some more detail on that later.
00:04:16: And you mentioned cyber diplomacy, Nadia... What are the OSCE's main challenges right now?
00:04:22: It places a lot of emphasis on consensus.
00:04:27: We all know DOC is all about peace, security stability in Europe.
00:04:33: I don't want to go into too much historical detail now but confidence building measures have always been at the core and heart of this organization.
00:04:42: so here do you see differentiates between conventional sort of military CBM CSBMs information exchanges transparency verification measures.
00:04:52: are that the answers end?
00:04:53: non-military CBM's are there to build trust through active activities in the fields of political, economic agreements, societal and cultural measures.
00:05:05: So cyber-CBMs, Confidence & Security Building Measures.
00:05:09: they have come on top because participating states during their last decade realized that first there is rapid digitalization happening.
00:05:18: second no state will be able own national cyber security without international cooperation because of the cross-border nature of the cyber realm, and third simply extending existing political military CSBMs would not work.
00:05:38: DOC has adopted in total sixteen so-called cyber ICT CBMs.
00:05:44: What's an ICT CBM?
00:05:46: You're about to tell me, aren't you!
00:05:48: So there is no consensus within the organization whether to call it now cyber or information and communication technology... ...so that's why it's slash Cyber ICT.
00:05:58: On the basis of decisions on permanent counsel which are the principle decision making body The biggest challenge now is loss of geopolitical trust since twenty-twenty two.
00:06:09: Russia's war for aggression against Ukraine has eroded the basis of consensus within DOC as a whole, and as Alexander already said we're witnessing growing numbers of cyber incidents of course, but the political will to further develop the CBMS it's not there anymore because we're facing a low trust environment.
00:06:36: What is remarkable and I close with that um...is that there isn't informal working group on cyber-ICT security within DOC in which remains basically one off the last places within the organization and i would even say anywhere where Russia still participates into discussion exchange is possible.
00:06:56: So CBMs continue to be implemented by the majority of.
00:07:03: that's quite stunning and the organization could potentially or eventually build upon this.
00:07:11: Just to get what they can build on, you maybe give me an example of some of the CBMs being implemented?
00:07:17: And then assess whether these existing confidence building measures are actually adequate.
00:07:23: I would say there two CBMs kind stand out because they're picking up what CSBMs, the Confidence and Security Building measures were initially meant to do.
00:07:34: They reduced risk of war escalation or escalation arising from miscalculations, misperceptions, all lack of communication.
00:07:43: There's first CBM-AID, The National Points Of Contact Network.
00:07:47: it facilitates direct communication that is kind of a structural analog to cold war classical red telephone between US and Soviet Union, these direct communications links are essential today.
00:08:02: Also they're kind of analog to the military-to-military consultation mechanism built into the Vienna document which is a principle confidence building measure instrument for political and military dimension of DOC.
00:08:14: The second one is CBM III on voluntary consultations to reduce risk of misperception in event of cyber security incident And this mirrors basically clarification mechanisms in chapter three of the Vienna document.
00:08:29: What's the idea behind it?
00:08:30: It's better to raise it directly and get clarification before drawing false conclusions or retaliating,
00:08:38: And these all sound perfectly sensible.
00:08:41: I guess my question is considering the rapidly changing cyber security landscape are these measures then adequate?
00:08:48: again if i can just ask Nadia to respond on that I'm going come back to Alexandra.
00:08:52: I guess the question is not really whether they are adequate or not.
00:08:56: It's, um... The only thing we have on the participating states has as you rightly mentioned DOC is a consensus-based organization and therefore at the moment there is no leeway No room for maneuver to actually reach a consensus on something else And it's good that they exist.
00:09:16: had they not been adopted previously today would be impossible.
00:09:20: And Alex, what's your take?
00:09:22: Does technology itself present additional hurdles or even complicate these confidence-building measures.
00:09:30: So maybe let's focus on cyber operations here rather than technologies in general because I think that may be for another podcast episode.
00:09:37: but so as Nadja said if the idea is that confidence building measures are supposed to prevent unintended conflict escalation The first question should be, well do cyber operations tend to contribute to conflict escalation?
00:09:51: And there it's actually quite interesting.
00:09:53: To look at some research that answers the question and found that actually cyber operations often tend to be rather de-escalatory.
00:10:01: so we have seen many cases in which cyber operations were for example conducted as an alternative to a kinetic air strike For example.
00:10:09: So they're most famous examples probably the joint US Israeli Stuxnet malware, which was supposed to prevent Iran from gaining nuclear weapons.
00:10:21: That was really used as an alternative to kinetic strike on a nuclear enrichment facility in Iran.
00:10:27: so that is not maybe seen as really an escalator measure.
00:10:32: but I'm sure there can be some cases where cyber operations also contribute to escalation and it's important always have this in mind because cyber is now seen, or the cyber domain as a domain of war.
00:10:49: And I think that's true.
00:10:51: but it's also important to keep in mind... ...the role that cyber operations have played in military conflicts so far because this holds lesson for us on the design of such confidence building measures and what we've been seeing.
00:11:07: Cyber operations are much more of a critical enabler that support other military functions and they're much less used to conduct harm in itself.
00:11:20: For example, cyber-operations have been used a lot together intelligence to prepare other operations For example, to gather location data.
00:11:29: We've seen this in the recent US and Israeli war in Iran.
00:11:34: They have also been used to support traditional kinetic strikes or for example turn off air defenses And then make airstrikes easier and Then much more select cases they have been use to conduct sabotage.
00:11:48: But I think it's important to keep that in mind.
00:11:52: But if we, of course consider the fact that as Nadja well pointed out information and communications technologies are inherently dual use so they can be used for both civilian and military purposes.
00:12:05: Still, the main threats are outside of armed conflict.
00:12:09: When we look at for example the threat that Germany is facing... ...the main threats aren't even coming from state actors but criminals.
00:12:18: and so one problem with cyber security very many different actors that are sometimes using even similar tooling, but with different objectives to different effects.
00:12:30: And it's quite hard to disentangle that and then to understand well what can a policy instrument like the confidence building measure do for me in this case?
00:12:39: So its just important.
00:12:39: keep in mind there were many different actors at play.
00:12:42: an instruments like Confidence Building Measures could only have effect on some of these.
00:12:48: Yes, that's very true.
00:12:49: And I want to concur.
00:12:50: one point Alexandra made.
00:12:53: as part of the OC project we look at incident data for the European repository for cyber incidents and interestingly the severity factor of incidence usually lies below what would be considered a threat hold for conventional response.
00:13:09: so although there are no standard thresholds yet but one thing i would rectify.
00:13:14: first CBMS is not designed or reduce the number of malicious cyber attacks, particularly not those originating from non-state actors.
00:13:24: Or criminal organizations and proxies.
00:13:26: but they can make their accidental deployment less likely.
00:13:33: there's a less unintended escalation And then even though they are below certain thresholds cumulative effect of being targeted can be destabilizing over longer periods of time.
00:13:49: Well, and you've given us both if you're giving a sense of the current cybersecurity situation.
00:13:55: but perhaps we could dig a little deeper.
00:13:57: and Nadia actually just started to talk about the rise in incidents?
00:14:01: But would tell more about the rising incidence within the OSCE among members.
00:14:07: Yes, that's exactly what we're looking at in our project.
00:14:11: The overall number of cyber incidents has increased.
00:14:14: since I cannot give you the exact data, but in a period before twenty-twenty two it was just above one hundred and now since Twenty-Twenty five were over thousand.
00:14:28: Since Russia's full scale invasion of Ukraine?
00:14:31: Yeah
00:14:31: so... The incidents they are definitely driven by the war.
00:14:35: Russia is one of the main aggressors.
00:14:37: Well Alexander tell us more about the aggressors And the main actors that their targeting.
00:14:43: Looking at the aggressor entirely clear that the main threat is coming from Russia, both for state-sponsored operations and also for non-state actors because Russia is the most important safe harbor so to speak.
00:14:58: For cyber criminals.
00:15:00: but it's also important to see there really a large grey area between these two ends of spectrums.
00:15:05: So theres also a myriad ways in which cooperating, directing tolerating just having different symbiotic relationships with non-state actors be they criminals or activists etc.
00:15:21: and so that makes it of course much harder to respond when you're not entirely sure if you want to respond politically or diplomatically.
00:15:28: If you are not entirely.
00:15:33: And then I think with a view to the operations, it's just important to keep in mind that you need to distinguish between espionage operations on one hand and sabotage on another.
00:15:44: So we've spoken about incidents up-to date.
00:15:47: happened for example at the energy sector of Poland which is a sabotage operation.
00:15:53: These tend to target critical infrastructure.
00:15:56: Another blatant example we saw also in twenty-twenty five and last year was one that targeted a hydropower dam in Norway, which basically they opened the floodgates left them open for hours until people noticed something was off And were not sure what happened there or what perpetrators objectives were, so probably they're just testing.
00:16:23: when are people noticing how they responding?
00:16:26: much as in the Polish case.
00:16:28: Where by-the way there has been absolutely no diplomatic or any other response to date
00:16:34: testing the waters.
00:16:35: Exactly, and then the other factor is espionage right?
00:16:39: So the newspapers here in Germany have been full over the past months regarding Russian cyber-espionage using the messaging app signal.
00:16:49: but again it would work with any other messaging app because what they're targeting or abusing are people's trust from other people.
00:16:59: And so there, of course cyber espionage is again just a really critical enabler for actors like Russia to gather information about.
00:17:12: For example in that case political leadership.
00:17:14: So coming back two attempts to find solutions an idea which regional organizations are implementing some of the measures you've mentioned and well?
00:17:24: What are those measures and what results have they yielded so far?
00:17:29: from our qualitative research and interviews.
00:17:33: It emerged that inter-regional cooperation becomes increasingly important, looking at it from the global UN level regional organizations they are regarded as incubators.
00:17:47: I would say even various regional organizations have specialized in different pillars of this UN framework.
00:17:59: The OC, by the way was the frontrunner and first organization to develop cyber confidence building measures.
00:18:06: other organizations have followed suit.
00:18:09: if i would mention here the Organization Of American States or AS they address traditional Confidence Building Measures since the nineteen nineties so-called non traditional, that's mainly but not only cyber confidence building measures.
00:18:27: And then there are other organizations like ASEAN, which is the Association of Southeast Asian Nations.
00:18:34: They engage in a context of preventive diplomacy and also in the context of the ASEan Regional Forum with Cyber Security and Confidence Building Measures.
00:18:44: Finally I want to mention one African organization called ECOVAS, it's the Economic Union on West African States.
00:18:52: The first region in Africa that has successfully established a set of three CBMs for cyber security and the OC served sort-of as role model here.
00:19:04: And now at UN level, there's since last year new UN permanent global mechanism and it is being discussed these interregional exchanges between various regional organizations.
00:19:18: they could take place more frequently for example, at the margins of plenary meetings.
00:19:24: And it's even discussed if this could become institutionalized.
00:19:28: Alexandra, there are various measures that these organizations are implementing.
00:19:34: to what extent or have they helped fend off cyberattacks?
00:19:38: So which ones and how?
00:19:39: yeah so I'm really a bit pessimistic when it comes to that because um There are of course important methodological challenges When we want to answer their question.
00:19:51: If CBMs are effective at what they do in the sense of preventing unintended conflict escalation, it is very likely that from outside we won't know because very likely military planners etc.
00:20:02: simply wont tell us what would have been done with a point-of-contact in country X, Y and Z. But from the outside what IAS political scientists can study?
00:20:13: I can look at statements in which one country blames another for a cyber operation, for example.
00:20:19: And I can also look at cybersecurity policy strategies and other diplomatic statements
00:20:26: etc.,
00:20:27: and basically conveying building measures play no role whatsoever on any of these.
00:20:33: That then made me wonder why is that so?
00:20:37: It's important to once again take the step back back and look at what cyber-CBMs are doing.
00:20:43: So in essence, you're transposing an established concept that was developed for conventional weapons and want to apply it into a new technology or space which simply functions differently.
00:21:02: kinds of confidence-building measures.
00:21:04: that works well.
00:21:05: I think also for cyber security, you can share information about points organizational settings, you can share information about your strategy.
00:21:17: About your policies.
00:21:18: so that works well.
00:21:20: but for example when it comes to sharing information about our weapons um... It is not problematic if I tell how many tanks i have because that does not diminish the number or quality of tank.
00:21:32: however If I tell exactly what kind of software exploits in what way I intend to use my cyber force that then does diminish the value of these skills, exploits etc.
00:21:49: because this information loses value over time.
00:21:52: so it's just almost impossible quote-unquote cyber weapons because I think that term is not analytically useful, but yeah it just doesn't translate very well.
00:22:03: Well considering the difficulties that cyber security presents simply because of its nature as Alexandra has described Nadia how effective is the OSCE at all right now given that Russia at the table.
00:22:18: CBNs have multiple functions and I do believe that we should not look at a topic only from an Eurocentric, NATO-centric perspective where we're here comfortably set in Western security alliances.
00:22:34: but DOC has another function.
00:22:36: We already touched upon it.
00:22:37: The Capacity Building is an important platform and process for capacity building for smaller states, on the one hand but also for states that are relatively new to the cyber security discussion.
00:22:54: And provide them with opportunity to discuss this issue.
00:22:58: more cyber mature states.
00:23:00: I want give you example.
00:23:03: As part of our research, among others we also focus on vulnerable states and them being targeted for example by Russia.
00:23:12: And two countries have faced major hybrid destabilization campaigns by Kremlin-oriented actors.
00:23:20: that has been the Republic of Moldova and Armenia.
00:23:24: So both countries struggled because they were targeted by coordinated hybrid campaigns That linked That was the interesting thing.
00:23:33: They linked cyber operations with foreign information manipulation and interference, short FEMAE.
00:23:42: So despite the fact that they faced these enormous challenges during election periods.
00:23:47: beyond that... ...they managed this difficult period.
00:23:51: And why has it been the case?
00:23:53: Because they have built up their resilience.. ..and there are receivers of capacity building endeavors among others in the context of DOC, and they do not have so many other forums to engage with other states.
00:24:08: Of course Moldova now has other avenues due its status as an accession country to DEU but within DOC they do exchange about these issues in their informal working group.
00:24:24: for example they give updates on cyber infrastructure about new legislation, and they do that despite the fact that Russia is sitting at a table.
00:24:39: Yes so I do believe there really profit from this exchange under DOC.
00:24:45: Alexander what are other options?
00:24:47: Where should we look to for solutions which will actually improve cyber security and cyber diplomacy as you've been talking about?
00:24:55: So i think it's fair maintain these forms.
00:24:59: Nadja, you mentioned the global mechanism at The United Nations and also of course we've spoken a lot about regional organizations.
00:25:06: so I think it's very valuable to have this communication channels with different actors.
00:25:11: So is of course important to maintain the dialogue.
00:25:14: but i think Also the case can be made that states should not dedicate too many resources on These forms because With view to the current international situation it is just very likely that they won't yield many results.
00:25:30: So instead, I think states should do or are important to focus on two things.
00:25:36: first
00:25:37: there can be smaller bilateral and even mini-lateral formats which make progress in specific issues.
00:25:43: one example of this is the counter ransomware initiative where more than sixty countries have come together who want fight ransomware because they've seen this as an important political problem and that are just focusing on these one problems.
00:25:56: It's a big problem, of course but there very focused in what we do I think makes it more likely to have results.
00:26:02: then another such process exists for the problem of spyware and other surveillance tools.
00:26:08: so i think is much more helpful way forward than all encompassing processes.
00:26:15: And then the second thing is that states should use tools to hold irresponsible States accountable.
00:26:20: So again, there are instruments available.
00:26:23: There's the EU cyber diplomacy tool toolbox.
00:26:26: Well state should use them for example by discussing sanctions or at least responding diplomatically To incidents like one in Poland.
00:26:35: Well, finally it's policy recommendations time.
00:26:38: If you continue Alexandra what are the next steps in concrete terms?
00:26:42: What should states and organizations be doing?
00:26:45: so I think In addition to these points to really impose costs on aggressors?
00:26:49: a very basic thing.
00:26:50: But can ever hurt to say again in cyber security circles we just need to get better at protecting ourselves, and at getting the basics right.
00:26:59: When you look at cybersecurity incidents and why they were successful it's always the same reasons And It has been so for At least a decade if not decades.
00:27:10: as A government You can use incentives?
00:27:11: You Can Use regulation or end-you should.
00:27:14: in my view you Should impose sanctions If entities like For example critical infrastructures don't comply Or also especially for military targets.
00:27:23: But then I think a really important point in my view is that, The rise in cyber operations from Russia points to the need for a coherent EU strategy on Russia and for coherent EU responses.
00:27:53: To cyber operations, just like other operations from
00:27:55: russia And Nadia.
00:27:57: what are your policy recommendations?
00:27:59: It's actually difficult to define concrete policy recommendations because it remains a balancing act between what is necessary and what is politically feasible.
00:28:09: And as we already said, the situation within the OSCE is rather complicated because its consensus-based organization.
00:28:16: I've already stated that the informal working group where Russia has part of is considered technical body.
00:28:27: political questions, questions of attributions.
00:28:30: They are kept outside and this is what we should focus on if relations under diplomatic political level turn sour it's more important to focus on the collaboration between at a technical level between CERDS and CSERDS.
00:28:50: so keep talking in as far it's possible.
00:28:53: And, and keep the attribution question excluded for example.
00:28:59: Well, no doubt we will keep talking at a later date but that just about runs off our discussion on cyber security threats.
00:29:04: For now I'd like to thank our guests Alexandra Paulos and Nadia Douglas for their insight.
00:29:09: you can find links to the latest work in publications in the podcast show notes And if you liked what you hear You can subscribe to us In The Usual Places including Spotify & Apple.
00:29:23: Today's episode was brought to you by our editor, Maya Dana.
00:29:26: By me your host and of course my guests Alexandra Paulus and Nadia Douglas.
00:29:31: Thank You for tuning in.
Neuer Kommentar