Estonia Estonia CCDCOE cyber defence NATO

Estonia's Cyber Doctrine Is Right to Bet on Rehearsed Fallbacks, but Machine-Speed Defence Needs Hard Legal Limits

Estonia's September 2026 resilience paper accepts that invulnerability is impossible. Its six moves are sound, and automation and mandates need the most care.

Estonia's DDoS Trend, 2023-2025 People of Internet Research · Estonia 756 DDoS attacks, 2025 Up from 484 in 2023. 12.5% Attacks with impact, 2025 Down from 27% in 2023. 6 Core policy recommendations Led by the minimum viable state. peopleofinternet.com
Estonia's DDoS Trend, 2023-2025 People of Internet Research · Estonia 756 DDoS attacks, 2025 12.5% Attacks with impact, 2025 6 Core policy recommendations peopleofinternet.com

Key Takeaways

Estonia has a credible claim to know something about cyber defence. It absorbed a national-scale attack in 2007, and Tallinn hosts NATO's Cooperative Cyber Defence Centre of Excellence (CCDCOE). On 16 September 2026 the country published a doctrine paper, National Cyber Resilience in the Age of AI. Experts from government, universities, technology firms and banks wrote it, including TalTech's Dr. Rain Ottis. Its central argument is a rare admission for a security document: perfect invulnerability is impossible, so a small state should aim to make attacks non-decisive.

What the paper recommends

The TalTech summary frames the premise as AI shifting "the economics of cyber conflict against the defender", because attacking has become cheaper than defending. The Ministry of Justice and Digital Affairs' page lists six moves:

The threat is rising, but impact is not

The paper arrives against a steady increase in volume. The Information System Authority (RIA) counted 484 DDoS attacks in 2023, 580 in 2024 and 756 in 2025. The share of attacks with tangible impact moved the other way: 27% in 2023, 18% in 2024 and 12.5% in 2025. In absolute terms that is 139 impactful attacks in 2023 and 95 in 2025.

This matters for how the doctrine should be read. Estonia's existing defences have been absorbing more hostile traffic with less visible damage. The 2025 campaigns also brought new actors. RIA reports that groups from Algeria and Morocco sent more than half a billion requests at about 15 sites in three hours in April and roughly 225 million in May. ERR News quotes RIA's deputy director general saying the new groups used different tools and that defenders relied heavily on manual intervention. That last detail is the real argument for the paper's fourth recommendation.

The strongest case for the mandates

The case for tougher enforcement deserves a fair hearing. Voluntary standards tend to be followed by the organisations that already care, and a single weak link in a connected state, such as a poorly run supplier or a hospital without backups, can spread harm well beyond its own systems. If AI makes reconnaissance and exploitation cheaper, the cost of the laggards' negligence rises for everyone. Independent audits and regulatory oversight are a reasonable response, and Estonia's high-trust, digital-first administration is well placed to run them.

Where proportionality should bite

The pro-innovation reading of the paper is that its best idea is the least coercive one. The minimum viable state accepts that not everything can or should be defended equally. It asks which handful of functions would harm life, the financial system, public order or the workings of the state if lost, and then makes the state practise operating without them. A fallback that has never been rehearsed is a hypothesis. Narrow scoping also keeps regulation proportionate, because the heaviest obligations fall on a short list of functions and not on every firm with a website.

Three cautions follow.

Transparency is the doctrine's safeguard

The sixth recommendation, prompt disclosure and independent oversight, is what makes the others defensible. Democracies that centralise defensive authority need public evidence that it is used narrowly. Estonia already publishes detailed attack statistics, which is how outsiders can verify claims such as the falling impact rate. Carrying that habit into incidents and into the use of automated responses would tell other small states that resilience and openness can go together.

What other governments should take from it

The doctrine's value is the framing, not any single measure. Treating compromise as inevitable shifts spending from preventing every breach to limiting what a breach can do and recovering quickly. For a state of Estonia's size, with a growing DDoS caseload and adversaries who now include non-Russian groups, that is more realistic than a perimeter strategy. It is also friendlier to innovation, because it asks for demonstrated recovery and not for pre-approval of every technology choice. The test of the paper will be implementation: whether the critical list stays short, audits measure outcomes, and automation arrives with the legal detail it currently only promises.

Sources & Citations

  1. RIA: DDoS attacks, new groups target Estonia
  2. Ministry of Justice and Digital Affairs: National Cyber Resilience in the Age of AI
  3. TalTech: National Cyber Resilience in the Age of AI
  4. ERR News: Pro-Palestine hackers launched cyberattacks on Estonia in 2025