Estonia has a credible claim to know something about cyber defence. It absorbed a national-scale attack in 2007, and Tallinn hosts NATO's Cooperative Cyber Defence Centre of Excellence (CCDCOE). On 16 September 2026 the country published a doctrine paper, National Cyber Resilience in the Age of AI. Experts from government, universities, technology firms and banks wrote it, including TalTech's Dr. Rain Ottis. Its central argument is a rare admission for a security document: perfect invulnerability is impossible, so a small state should aim to make attacks non-decisive.
What the paper recommends
The TalTech summary frames the premise as AI shifting "the economics of cyber conflict against the defender", because attacking has become cheaper than defending. The Ministry of Justice and Digital Affairs' page lists six moves:
- Define a "minimum viable state" of critical functions and rehearse the fallback for each.
- Harden the national trust backbone, meaning digital identity, signatures and registers, with zero-trust architecture.
- Enforce security baselines with independent audits and regulatory oversight.
- Give defenders pre-delegated authority to respond at machine speed, within legal bounds.
- Mobilise the whole of society against threats such as phishing and deepfakes.
- Keep incident communication transparent, with independent oversight of defensive measures.
The threat is rising, but impact is not
The paper arrives against a steady increase in volume. The Information System Authority (RIA) counted 484 DDoS attacks in 2023, 580 in 2024 and 756 in 2025. The share of attacks with tangible impact moved the other way: 27% in 2023, 18% in 2024 and 12.5% in 2025. In absolute terms that is 139 impactful attacks in 2023 and 95 in 2025.
This matters for how the doctrine should be read. Estonia's existing defences have been absorbing more hostile traffic with less visible damage. The 2025 campaigns also brought new actors. RIA reports that groups from Algeria and Morocco sent more than half a billion requests at about 15 sites in three hours in April and roughly 225 million in May. ERR News quotes RIA's deputy director general saying the new groups used different tools and that defenders relied heavily on manual intervention. That last detail is the real argument for the paper's fourth recommendation.
The strongest case for the mandates
The case for tougher enforcement deserves a fair hearing. Voluntary standards tend to be followed by the organisations that already care, and a single weak link in a connected state, such as a poorly run supplier or a hospital without backups, can spread harm well beyond its own systems. If AI makes reconnaissance and exploitation cheaper, the cost of the laggards' negligence rises for everyone. Independent audits and regulatory oversight are a reasonable response, and Estonia's high-trust, digital-first administration is well placed to run them.
Where proportionality should bite
The pro-innovation reading of the paper is that its best idea is the least coercive one. The minimum viable state accepts that not everything can or should be defended equally. It asks which handful of functions would harm life, the financial system, public order or the workings of the state if lost, and then makes the state practise operating without them. A fallback that has never been rehearsed is a hypothesis. Narrow scoping also keeps regulation proportionate, because the heaviest obligations fall on a short list of functions and not on every firm with a website.
Three cautions follow.
- Keep the scope list short and reviewable. Designation creates obligations, and lists tend to grow. A sunset or periodic re-justification requirement would stop "critical" from becoming a catch-all that burdens startups and small service providers.
- Audit outcomes, not paperwork. Baselines that become checklists reward compliance theatre. Rehearsal results, such as recovery times in drills, are better evidence of resilience than certificates.
- Bound machine-speed authority tightly. Pre-delegating response powers is the most delicate recommendation. Automated defence that blocks traffic, quarantines systems or filters content can misfire at the same speed it works. The paper's own phrase, "within legal limits", should be turned into specifics: defined action classes, logging, rapid human review and a route to challenge mistakes. The fifth recommendation, on phishing and deepfakes, carries a speech risk. Whole-of-society resilience should mean media literacy, authentication tools and fast debunking by trusted institutions. It should not mean pressure on platforms to remove lawful but unwelcome content.
Transparency is the doctrine's safeguard
The sixth recommendation, prompt disclosure and independent oversight, is what makes the others defensible. Democracies that centralise defensive authority need public evidence that it is used narrowly. Estonia already publishes detailed attack statistics, which is how outsiders can verify claims such as the falling impact rate. Carrying that habit into incidents and into the use of automated responses would tell other small states that resilience and openness can go together.
What other governments should take from it
The doctrine's value is the framing, not any single measure. Treating compromise as inevitable shifts spending from preventing every breach to limiting what a breach can do and recovering quickly. For a state of Estonia's size, with a growing DDoS caseload and adversaries who now include non-Russian groups, that is more realistic than a perimeter strategy. It is also friendlier to innovation, because it asks for demonstrated recovery and not for pre-approval of every technology choice. The test of the paper will be implementation: whether the critical list stays short, audits measure outcomes, and automation arrives with the legal detail it currently only promises.