Estonia Estonia CCDCOE cyber defence NATO

Estonia's Cyber-Energy Tabletop Shows Resilience Is Built by Rehearsal, Not Regulation

NB8 energy ministers rehearsed a fictional electricity crisis at NATO's Tallinn cyber centre. Practice with operators beats new mandates.

Estonia's Cyber Defence Hub in Numbers People of Internet Research · Estonia 41 Locked Shields nations Nations took part in Locked Shield… 4,000+ Cyber defenders trained Defenders took part in the 2026 ex… 39 CCDCOE member nations Members include NATO and partner n… 8 NB8 states Five Nordic and three Baltic state… peopleofinternet.com
Estonia's Cyber Defence Hub in Numbers People of Internet Research · Estonia 41 Locked Shields nations 4,000+ Cyber defenders trained 39 CCDCOE member nations 8 NB8 states peopleofinternet.com

Key Takeaways

On 4 September 2026, energy ministers and senior officials from the Nordic-Baltic Eight (NB8) visited the NATO Cooperative Cyber Defence Centre of Excellence in Tallinn. They took part in a tabletop exercise built around a fictional electricity crisis in the region. The visit closed the first NB8 energy ministers' meeting, hosted in Tallinn on 3-4 September by Estonian Energy and Environment Minister Andres Sutt. The agenda covered Ukraine's winter energy supply, the resilience of critical energy infrastructure against physical, cyber and hybrid threats, the protection of Baltic Sea energy assets, and a competitive regional market.

The public record on the exercise is thin. The CCDCOE listing confirms the visit and the format, but no scenario details or outcomes have been published. This article therefore analyses what the format signals, not what was decided.

The case for binding rules

The strongest argument for heavy regulation is that a grid is a shared system. One weakly defended utility can cascade failure across borders. Private operators underinvest in security because the costs of an outage fall on society, not on their balance sheets. Regulators point to this externality when they impose mandatory standards, audits and incident reporting. The EU's NIS 2 Directive (2022/2555) is built on that logic. Its recitals stress the growing interdependencies of cross-border service provision in sectors such as energy, transport and digital infrastructure. That case is serious, and the Nordic-Baltic grids are tightly coupled.

Why the exercise model is the better instrument

A mandate can tell an operator to have an incident plan. It cannot tell whether the plan works when the person who owns the decision is a minister, the data is incomplete, and a neighbouring country is asking for help. A tabletop is designed to expose that gap. Ministers who have already argued through a fictional blackout are better placed to coordinate in a real one, and they have learned it without a compliance regime.

The choice of venue matters. CCDCOE was founded on 14 May 2008 by Estonia and six other nations and received NATO accreditation that October. It now has 39 member nations, including non-NATO partners. It is not a regulator. It works in technology, operations, strategy and law, and it runs training. That mix is what a cross-border energy crisis needs, because such a crisis is technical, legal and political at once.

The Centre's flagship exercise shows the scale of what it can do. Locked Shields 2026 brought together more than 4,000 cyber defenders from 41 nations, in 16 teams. They defended a fictional country, Berylia, against roughly 8,000 simulated attacks on targets including power grids, 5G networks and satellite systems. The Exercise Director describes the goal as going beyond technical defence to strategic communications, international law, digital forensics and national-level decision-making. Over 100 industry partners contributed. Ministerial tabletops move the same ideas up one level, from the operator's control room to the cabinet table.

What the NB8 format adds

NB8 is an informal grouping. Estonia's foreign ministry describes it as a regional cooperation format that has brought together five Nordic and three Baltic states since 1992. It has no treaty powers, no secretariat that can fine anyone, and no supranational court. That is a strength here. Informal formats can move quickly and be candid about weaknesses. Ministers are more willing to admit an interdependency problem in a closed exercise than in a legislative hearing.

The region's energy politics is also unusually integrated. Sutt's own framing at the meeting was that energy security today is not just about having enough electricity, but about whether infrastructure can withstand potential threats. That reflects a shift from supply adequacy to threat resilience, and the shift is best addressed by people who operate and coordinate the systems.

Where policy should go next

Three principles follow from this evidence.

The pro-innovation concern is that reflexive compliance burdens land hardest on smaller energy firms and new entrants, such as storage and flexibility providers, whom a decarbonising grid needs. Layered obligations can push them toward legal paperwork and away from engineering. An approach centred on shared exercises, proportionate baseline duties and transparent lessons keeps the security benefits while leaving room for new entrants.

The limits

A tabletop is not a guarantee. It tests decisions, not code, and its value depends on whether findings become funded action. A single visit says nothing about whether grid operators have patched their systems. Estonia and its neighbours should treat this exercise as a starting point and show, over the next year, that lessons turn into concrete changes such as clearer cross-border escalation contacts, shared incident playbooks and joint drills that include operators. If they do, Tallinn's approach will be a credible alternative to regulation-first models.

Sources & Citations

  1. CCDCOE news: NB8 energy ministers visit
  2. CCDCOE: Locked Shields 2026
  3. Estonian Foreign Ministry: NB8
  4. EU NIS 2 Directive 2022/2555
  5. Baltic Times: NB8 energy ministers' meeting
  6. CCDCOE: About us