On 4 September 2026, energy ministers and senior officials from the Nordic-Baltic Eight (NB8) visited the NATO Cooperative Cyber Defence Centre of Excellence in Tallinn. They took part in a tabletop exercise built around a fictional electricity crisis in the region. The visit closed the first NB8 energy ministers' meeting, hosted in Tallinn on 3-4 September by Estonian Energy and Environment Minister Andres Sutt. The agenda covered Ukraine's winter energy supply, the resilience of critical energy infrastructure against physical, cyber and hybrid threats, the protection of Baltic Sea energy assets, and a competitive regional market.
The public record on the exercise is thin. The CCDCOE listing confirms the visit and the format, but no scenario details or outcomes have been published. This article therefore analyses what the format signals, not what was decided.
The case for binding rules
The strongest argument for heavy regulation is that a grid is a shared system. One weakly defended utility can cascade failure across borders. Private operators underinvest in security because the costs of an outage fall on society, not on their balance sheets. Regulators point to this externality when they impose mandatory standards, audits and incident reporting. The EU's NIS 2 Directive (2022/2555) is built on that logic. Its recitals stress the growing interdependencies of cross-border service provision in sectors such as energy, transport and digital infrastructure. That case is serious, and the Nordic-Baltic grids are tightly coupled.
Why the exercise model is the better instrument
A mandate can tell an operator to have an incident plan. It cannot tell whether the plan works when the person who owns the decision is a minister, the data is incomplete, and a neighbouring country is asking for help. A tabletop is designed to expose that gap. Ministers who have already argued through a fictional blackout are better placed to coordinate in a real one, and they have learned it without a compliance regime.
The choice of venue matters. CCDCOE was founded on 14 May 2008 by Estonia and six other nations and received NATO accreditation that October. It now has 39 member nations, including non-NATO partners. It is not a regulator. It works in technology, operations, strategy and law, and it runs training. That mix is what a cross-border energy crisis needs, because such a crisis is technical, legal and political at once.
The Centre's flagship exercise shows the scale of what it can do. Locked Shields 2026 brought together more than 4,000 cyber defenders from 41 nations, in 16 teams. They defended a fictional country, Berylia, against roughly 8,000 simulated attacks on targets including power grids, 5G networks and satellite systems. The Exercise Director describes the goal as going beyond technical defence to strategic communications, international law, digital forensics and national-level decision-making. Over 100 industry partners contributed. Ministerial tabletops move the same ideas up one level, from the operator's control room to the cabinet table.
What the NB8 format adds
NB8 is an informal grouping. Estonia's foreign ministry describes it as a regional cooperation format that has brought together five Nordic and three Baltic states since 1992. It has no treaty powers, no secretariat that can fine anyone, and no supranational court. That is a strength here. Informal formats can move quickly and be candid about weaknesses. Ministers are more willing to admit an interdependency problem in a closed exercise than in a legislative hearing.
The region's energy politics is also unusually integrated. Sutt's own framing at the meeting was that energy security today is not just about having enough electricity, but about whether infrastructure can withstand potential threats. That reflects a shift from supply adequacy to threat resilience, and the shift is best addressed by people who operate and coordinate the systems.
Where policy should go next
Three principles follow from this evidence.
- Test before you mandate. Regulators should require evidence that plans have been exercised, not just documented. A rule that says "run a joint drill annually and publish the lessons" is cheaper and more informative than a prescriptive technical checklist that dates quickly.
- Keep operators and vendors in the room. Locked Shields works partly because more than 100 industry partners build and defend the environment. A ministerial tabletop that excludes transmission operators and equipment suppliers tests politics, not resilience.
- Publish what can be published. The lack of public detail on this exercise is understandable given the security sensitivities. Even so, sanitised after-action summaries would let other regions copy what worked. They would also let parliaments and the public judge whether the exercise changed anything.
The pro-innovation concern is that reflexive compliance burdens land hardest on smaller energy firms and new entrants, such as storage and flexibility providers, whom a decarbonising grid needs. Layered obligations can push them toward legal paperwork and away from engineering. An approach centred on shared exercises, proportionate baseline duties and transparent lessons keeps the security benefits while leaving room for new entrants.
The limits
A tabletop is not a guarantee. It tests decisions, not code, and its value depends on whether findings become funded action. A single visit says nothing about whether grid operators have patched their systems. Estonia and its neighbours should treat this exercise as a starting point and show, over the next year, that lessons turn into concrete changes such as clearer cross-border escalation contacts, shared incident playbooks and joint drills that include operators. If they do, Tallinn's approach will be a credible alternative to regulation-first models.