Estonia's Information System Authority (RIA) logged 1,044 cyber incidents with impact on confidentiality, integrity, or availability of data in July 2026 — "slightly below the average for the last six months," according to the agency's monthly Situation in Cyberspace report. Buried in that count is a small but instructive episode: a wave of website defacements traced to unpatched plugins in the Joomla content management system, hitting a driving school, a construction-machinery hire firm, and an online shop early in the month, followed by 24 more defaced sites in the final week. RIA notified more than 90 website owners whose sites were flagged as hosting malicious files.
None of this touched X-Road, the decentralized data-exchange layer that underpins Estonia's digital government and is often cited — accurately — as a model that has not suffered a known major breach in two decades of operation, by design: Security Servers exchange data directly between members, with no central repository to compromise, so a defaced small-business site does not create a path into tax records, health data, or population registers. RIA itself was careful to describe the July defacements as "most likely a case of cyber vandalism" rather than a targeted attack — no malicious content was actually displayed to visitors on most of the affected sites. That containment is a genuine institutional achievement, not luck, and it deserves more attention than the fact that Joomla sites got popped.
The steelman: this is exactly why mandatory cybersecurity regulation exists
The case for tighter regulation writes itself here. A driving school and a machinery-rental firm are not going to run vulnerability scans on their CMS plugins; they hired a web developer once and forgot the site existed. If a government wants a baseline of hygiene across the economy — patched software, monitored infrastructure, someone accountable when something breaks — voluntary best practice will not get there. That is the logic behind the EU's second Network and Information Security Directive (NIS2), which Estonia transposed into domestic law via amendments to the Cybersecurity Act that the Riigikogu adopted on 10 December 2025, taking effect 1 January 2026. The reform nearly doubled the number of regulated entities in Estonia, from roughly 3,500 to close to 6,500, and it now attaches personal liability to board members and fines up to €10 million or 2% of turnover for the sectors it covers.
That is a defensible policy response to a real problem: critical infrastructure operators — energy, transport, healthcare, finance — genuinely do need mandatory baselines, because the externalities of their failure fall on the public, not just their shareholders. Estonia's government also deserves credit for building the softer side of the same system: RIA's operations centre, launched in mid-2025, monitors state e-services broadly, not just RIA's own systems, and the agency's practice of proactively notifying affected site owners — the 90-plus notifications in July — is exactly the kind of low-friction, high-leverage intervention that doesn't require a statute.
Why the July wave argues against extending the regulatory net further
But the July defacements are a useful natural experiment, because none of the affected sites plausibly clear NIS2's thresholds. The directive's "important entity" tier alone requires 50 or more employees and either €10 million in turnover or an equivalent balance sheet. A driving school and a rental-equipment shop running Joomla are not going to be pulled into that perimeter under any plausible reading of the sectoral scope — and if they were, extending mandatory cybersecurity compliance to every small business running a CMS would be a regulatory program several orders of magnitude larger than the one Estonia just built, for an incident category (unpatched plugin, opportunistic botnet scan, no data exfiltrated) that doesn't rise to the harm NIS2 was designed to prevent.
Even within the population NIS2 does cover, the early results are not encouraging on cost-effectiveness. Grant Thornton's compliance review found that only about a third of the roughly 3,000 newly-included entities had submitted the required self-registration notifications to RIA by the 31 March 2026 deadline — not because those firms are indifferent to security, but because sector classification, group-structure thresholds, and definitional cross-references in the law proved genuinely difficult to apply. If a third compliance rate is what a well-resourced regulator gets from firms large enough to already have compliance functions, imposing the same statutory machinery on driving schools would produce paperwork, not patched plugins.
What actually worked
The more instructive story in RIA's July report is the one regulation didn't write: architectural isolation kept a mass CMS exploit away from anything that mattered, and a notify-and-remediate model — cheap, fast, no statute required — cleaned up the damage that did occur. That's the model worth scaling for the long tail of small-business web infrastructure: better CERT-EE outreach, plugin-vulnerability disclosure feeds, and hosting-provider defaults, not a widened NIS2 perimeter chasing incidents that were never going to reach the systems NIS2 exists to protect.