Estonia Estonia CCDCOE cyber defence NATO

Estonia's €20 Million Election Cyber Bill Is Cheap Insurance, but Plan B Must Be Funded Too

Estonia wants €5 million next year and over €20 million across four years to secure March 2027 voting. Shifting existing money is sensible if the paper fallback is protected.

Estonia's election cyber picture People of Internet Research · Estonia ~51% Online share of 2023 votes 312,181 of 613,801 votes were cast… 756 DDoS attacks recorded 2025 Up about a third; fewer than 100 h… 10,185 Cyber incidents registered 2025 A record, mostly fraud and phishin… >€20M Four-year security need About €5 million is needed next ye… peopleofinternet.com
Estonia's election cyber picture People of Internet Research · Estonia ~51% Online share of 2023 votes 756 DDoS attacks recorded 2025 10,185 Cyber incidents registered 2025 >€20M Four-year security need peopleofinternet.com

Key Takeaways

Estonia's government says it will raise cybersecurity spending ahead of the March 2027 parliamentary elections. ERR News reported that officials put the need at about €5 million next year and more than €20 million over four years. Information System Authority (RIA) director Joonas Heiter said attacks have become massive and that machines now scan for vulnerabilities that criminals once hunted by hand. The headline number is modest. The more interesting questions are where the money comes from and what happens if the system fails.

The strongest case for spending more

The sceptic's argument deserves a fair hearing. Electronic voting concentrates risk in a way paper does not. A successful attack on one national system can, in principle, touch every i-voter at once. The attacker also doesn't need to alter a single vote. A convincing rumour that the system was compromised can damage trust in the result on its own.

Estonia's exposure is large because it is the world's most committed i-voting country. In the 2023 Riigikogu election, the Electoral Office reports that 312,181 of 613,801 votes (about 51%) were cast online. More than half of the national vote therefore runs through one digital channel.

The threat data supports urgency. RIA's Cyber Security Yearbook recorded a record 10,185 incidents in 2025, most of them fraud, phishing and malicious redirects. It also recorded 756 denial-of-service attacks, up roughly a third on the year before. Fewer than 100 of those had any operational impact. Heiter's remark about automated scanning describes the same shift. Attackers use tooling to find unpatched systems faster than defenders can patch them, and the yearbook cites delayed patching as the cause of compromises of government VPN devices and library systems.

Why the funding approach is mostly right

Government officials told ERR that no new money is needed on the table. Prime Minister Kristen Michal said the necessary funding exists and can be shifted within the field. Justice and Digital Minister Liisa-Ly Pakosta said extra money could come from the reserve fund, and that something else would be shut down to pay for security.

That is a defensible approach for a small state with a tight budget. Reprioritising within an existing envelope forces a ranking of what actually matters. It also avoids a pattern common in security policy, where a threat headline produces a large new appropriation that is spent on whatever vendors are selling. A figure of €5 million a year is small against the stakes. It is also small enough that a single bad procurement could consume a large share of it.

The pro-innovation reading is that Estonia should not retreat from digital government because attackers are getting faster. The country's model of public services built on secure identity and open standards is the reason the state can respond quickly. The right response to automated scanning is automated defence. That means faster patching, continuous vulnerability scanning of election-related systems, rehearsed incident response, and independent review. It does not mean fewer digital services.

The risk in 'shift it within the field'

The weakness in the plan is its vagueness. Reallocation is only as good as what gets cut. If money moves from slower, unglamorous work such as patch management for municipal and regional systems to a visible election project, the yearbook's own finding applies: delayed patching is how attackers get in. Election systems depend on the wider government network around them.

There is also a timing problem. March 2027 is five months away, and the €5 million is described as a next-year need. Hardening systems takes procurement, testing and staff time, and none of those can be compressed into the final weeks. Officials should publish what will be done before the vote and what is a longer-term programme. Without that split, nobody can judge whether the money arrived in time.

Plan B is a security feature, not an admission

State Electoral Office head Arne Koitmäe told ERR that the office has a plan to switch entirely to paper voting if the system can no longer be trusted. Critics may read this as a sign of weakness. It is the opposite. A credible fallback is what lets a government keep a digital option available without staking the legitimacy of the election on it.

The fallback is only credible if it is real. A full switch to paper requires polling-station capacity, ballot printing, trained staff and a trigger that is decided in advance. A trigger decided in the middle of a crisis will be seen as political. Estonia should publish the criteria for invoking plan B well before voting starts. It should also test the logistics at least once, because a plan that has never been exercised is a hope.

This is where Estonia's wider cyber-defence ecosystem is relevant, with a caveat. The ERR report does not mention NATO or the Tallinn-based Cooperative Cyber Defence Centre of Excellence, and we should not claim it is part of this funding. But the country does host an institution that runs Locked Shields, described by NATO as the world's largest cyber defence exercise, which drew more than 3,000 participants from 38 countries in 2023. Estonia has the know-how to run realistic tabletop and live exercises on its own election chain. Using that kind of exercise before March would be a cheap way to test both the defences and the paper fallback.

What good looks like

The evidence supports a measured approach. Spending should be proportionate, targeted at basic hygiene and resilience, and transparent enough for the public and parliament to check.

Estonia is making the right call to spend, and the amount is reasonable. It will be judged on whether the money and the fallback are visible and tested before voters go to the polls.

Sources & Citations

  1. ERR News: Estonia pushes for cybersecurity boost ahead of elections
  2. Estonian National Electoral Office: Riigikogu 2023 turnout and i-votes
  3. RIA: Cyber Security in Estonia, new records, old mistakes
  4. NATO: Locked Shields 2023 cyber defence exercise