CR2 Briefs WTO on Cybersecurity Components in Trade

By: Ines Jordan-Zoob

In January, the Coalition to Reduce Cyber Risk (CR2) held a briefing at the World Trade Organization (WTO) in Geneva, Switzerland focused on our forthcoming research around the inclusion of digital trade and cybersecurity components in trade agreements. The briefing was attended by 40+ countries, including the U.S., Spain, Australia, Germany, Kazakhstan, Brazil, Japan, and China. 

Cybersecurity provisions have been incorporated in 11 trade agreements to date. These provisions revolve around establishing a cyber-trade link, government capacity building efforts, operational collaboration efforts, and the use of risk-based approaches and consensus standards. 

We focused on:

  • The nature of these existing cyber-trade provisions.

  • The steps taken by governments to implement them.

  • The capacity-building resources available to assist with implementation. 

The session was followed by a Q&A, with questions around defining cybersecurity versus information security, as well around best practices for incident/vulnerability reporting and capacity-building. 

The briefing landed right in the middle of the ongoing negotiations for the  90-country Joint Statement Initiative (JSI) on Electronic Commerce, and in advance of the 13th WTO ministerial conference next week in Abu Dhabi. The JSI has been in development since 2017, and the negotiations have been marked by controversy, including most recently by the withdrawal of United States support for objectives around cross-border data flows, data localization, and source code transfer. Nonetheless, the JSI contains harmonized rules for a number of issues including e-signatures, e-contracts, open government data, consumer protection, unsolicited commercial messages, and crucially, foundational cybersecurity language. 

While there was hope that the JSI could be finalized by Abu Dhabi, it now appears highly unlikely. Negotiations have been further impeded by debate around the temporary WTO Moratorium on Customs Duties on Electronic Transmissions. 

CR2 recently co-signed a letter calling for the renewal of the moratorium with over 170 global business associations. As the negotiations continue, trade optimists hope for a finalization of the text towards the fall of 2024. Despite controversies over other topics, the proposed cybersecurity language in the draft seems relatively uncontentious. 

Previous
Previous

CR2 Publishes “Guarding Global Commerce: How Cybersecurity is Addressed in International Trade Agreements” Whitepaper

Next
Next

CR2 Publishes Statement of Support for the National Institute of Standards and Technology’s Cybersecurity Framework Version 2.0