Estonia's government says it will raise cybersecurity spending ahead of the March 2027 parliamentary elections. ERR News reported that officials put the need at about €5 million next year and more than €20 million over four years. Information System Authority (RIA) director Joonas Heiter said attacks have become massive and that machines now scan for vulnerabilities that criminals once hunted by hand. The headline number is modest. The more interesting questions are where the money comes from and what happens if the system fails.
The strongest case for spending more
The sceptic's argument deserves a fair hearing. Electronic voting concentrates risk in a way paper does not. A successful attack on one national system can, in principle, touch every i-voter at once. The attacker also doesn't need to alter a single vote. A convincing rumour that the system was compromised can damage trust in the result on its own.
Estonia's exposure is large because it is the world's most committed i-voting country. In the 2023 Riigikogu election, the Electoral Office reports that 312,181 of 613,801 votes (about 51%) were cast online. More than half of the national vote therefore runs through one digital channel.
The threat data supports urgency. RIA's Cyber Security Yearbook recorded a record 10,185 incidents in 2025, most of them fraud, phishing and malicious redirects. It also recorded 756 denial-of-service attacks, up roughly a third on the year before. Fewer than 100 of those had any operational impact. Heiter's remark about automated scanning describes the same shift. Attackers use tooling to find unpatched systems faster than defenders can patch them, and the yearbook cites delayed patching as the cause of compromises of government VPN devices and library systems.
Why the funding approach is mostly right
Government officials told ERR that no new money is needed on the table. Prime Minister Kristen Michal said the necessary funding exists and can be shifted within the field. Justice and Digital Minister Liisa-Ly Pakosta said extra money could come from the reserve fund, and that something else would be shut down to pay for security.
That is a defensible approach for a small state with a tight budget. Reprioritising within an existing envelope forces a ranking of what actually matters. It also avoids a pattern common in security policy, where a threat headline produces a large new appropriation that is spent on whatever vendors are selling. A figure of €5 million a year is small against the stakes. It is also small enough that a single bad procurement could consume a large share of it.
The pro-innovation reading is that Estonia should not retreat from digital government because attackers are getting faster. The country's model of public services built on secure identity and open standards is the reason the state can respond quickly. The right response to automated scanning is automated defence. That means faster patching, continuous vulnerability scanning of election-related systems, rehearsed incident response, and independent review. It does not mean fewer digital services.
The risk in 'shift it within the field'
The weakness in the plan is its vagueness. Reallocation is only as good as what gets cut. If money moves from slower, unglamorous work such as patch management for municipal and regional systems to a visible election project, the yearbook's own finding applies: delayed patching is how attackers get in. Election systems depend on the wider government network around them.
There is also a timing problem. March 2027 is five months away, and the €5 million is described as a next-year need. Hardening systems takes procurement, testing and staff time, and none of those can be compressed into the final weeks. Officials should publish what will be done before the vote and what is a longer-term programme. Without that split, nobody can judge whether the money arrived in time.
Plan B is a security feature, not an admission
State Electoral Office head Arne Koitmäe told ERR that the office has a plan to switch entirely to paper voting if the system can no longer be trusted. Critics may read this as a sign of weakness. It is the opposite. A credible fallback is what lets a government keep a digital option available without staking the legitimacy of the election on it.
The fallback is only credible if it is real. A full switch to paper requires polling-station capacity, ballot printing, trained staff and a trigger that is decided in advance. A trigger decided in the middle of a crisis will be seen as political. Estonia should publish the criteria for invoking plan B well before voting starts. It should also test the logistics at least once, because a plan that has never been exercised is a hope.
This is where Estonia's wider cyber-defence ecosystem is relevant, with a caveat. The ERR report does not mention NATO or the Tallinn-based Cooperative Cyber Defence Centre of Excellence, and we should not claim it is part of this funding. But the country does host an institution that runs Locked Shields, described by NATO as the world's largest cyber defence exercise, which drew more than 3,000 participants from 38 countries in 2023. Estonia has the know-how to run realistic tabletop and live exercises on its own election chain. Using that kind of exercise before March would be a cheap way to test both the defences and the paper fallback.
What good looks like
The evidence supports a measured approach. Spending should be proportionate, targeted at basic hygiene and resilience, and transparent enough for the public and parliament to check.
- Publish the list of what is being cut or delayed to fund the election work.
- Set out the criteria and decision-maker for switching to paper before the campaign begins.
- Rehearse the paper fallback and the incident response, and report the results.
- Commission independent review of the i-voting system and publish its findings.
- Keep election-time communications fast and factual, because rumours about compromise are a threat in themselves.
Estonia is making the right call to spend, and the amount is reasonable. It will be judged on whether the money and the fallback are visible and tested before voters go to the polls.