Estonia's Information System Authority (RIA) logged 1,044 cyber incidents with real impact in July 2026 — and buried in that count is a detail that says more about Estonian cyber policy than the headline number does. Over 100 Estonian websites were defaced during the month, and RIA's own assessment is almost anticlimactic: "most of them ran on the Joomla content management system, and access was likely gained through security vulnerabilities in Joomla plugins," according to the agency's July cyberspace report published on ria.ee.
An Unsophisticated Break-In, At Scale
This was not a nation-state intrusion. Dorel Kiik, an analyst in RIA's Analysis and Prevention Department, described the campaign in plain terms: "Defacement means an attacker gains access to a website and adds content of their choosing." Crucially, no malicious content was shown to visitors — but malicious files were uploaded to the web servers themselves, which RIA classifies as cyber-vandalism rather than a targeted espionage or sabotage operation. It is the digital equivalent of graffiti, except the spray can is an unpatched plugin and the wall is a municipal or small-organisation website that nobody has logged into in months.
That is precisely what makes the incident instructive. Estonia is not a country short on cyber-defence capability. Tallinn has hosted NATO's Cooperative Cyber Defence Centre of Excellence for close to two decades, and the country runs some of the most digitally advanced public services in Europe. Yet a mass-exploitation campaign against a popular but unglamorous open-source CMS still put triple-digit numbers of Estonian sites in attackers' hands in a single month. Sophisticated national cyber-defence infrastructure and basic web hygiene are not the same asset, and July's numbers show the gap between them.
NIS2 Raises the Bar — For the Entities It Reaches
Estonia transposed the EU's second Network and Information Security Directive (NIS2) into domestic law on 1 January 2026, amending the Cybersecurity Act. The Riigikogu's own press release on the bill states plainly that the reform brings roughly 3,000 additional organisations under statutory cybersecurity obligations, lifting the total to around 6,500 entities, with the explanatory memorandum arguing the harmonised requirements will "raise the cybersecurity level of the organisations crucial to society and the economy."
That case deserves to be stated fairly before it's contested. NIS2's core innovation is not another checklist — it pushes accountability to board level, requiring at least one director to sign off on security measures and own the consequences of skipping them. For hospitals, grid operators, and digital infrastructure providers, that is a defensible, proportionate response to a threat environment RIA's own 2026 yearbook (ria.ee/en/cyber-security-estonia-2026) describes as worsening on every axis: ransomware attacks trending up globally, DDoS actors expanding from the Middle East, North Africa and Southeast Asia, and 2025 fraud losses in Estonia reaching a record €29 million.
The Threshold Problem
But NIS2 does not apply universally — it applies above a size threshold. "Important" entities need 50 or more employees and €10 million or more in turnover; "essential" entities need 250-plus staff and €50 million-plus turnover. A parish council or small municipal office running a Joomla site almost certainly sits below both lines. It is not that these organisations are failing a NIS2 obligation — they were never in scope to begin with.
That gap is compounded by a compliance problem even among entities that are in scope. Research from Grant Thornton Estonia found that of the roughly 3,000 organisations newly captured by the law, more than 2,000 had likely missed the March 2026 deadline to submit the notification RIA requires to determine applicability — with the firm noting that current supervisory priority explicitly includes "educational institutions, local governments, providers of vital services, and selected public sector organisations." RIA itself has acknowledged, per that same reporting, that "fully automating the process is not realistic."
Put together: the law is still working out how to onboard the mid-sized public bodies it does cover, while the smallest ones — the exact tier where an under-resourced webmaster runs a five-year-old Joomla install with three unpatched plugins — sit outside its reach entirely.
What Proportionate Actually Looks Like
The instinct after a defacement wave like this is to expand the regulatory net — pull small municipalities and public bodies under NIS2-style board accountability regardless of size. That would be the wrong lesson. A parish office does not need a director signing off on an information security management system; it needs someone to run automatic updates. Compliance paperwork scaled down to fit a five-person office produces exactly what Grant Thornton is already documenting at the mid-size tier: missed deadlines and confusion, not better patching.
The proportionate fix is operational, not statutory. RIA already runs CERT-EE and could extend a shared, centrally-patched CMS platform or a mandatory vulnerability-scanning service for public-sector sites below the NIS2 threshold — the model several Estonian e-government services already use. That closes the actual gap July exposed without dragging thousands of small entities into a governance regime built for hospitals and grid operators. Estonia's cyber-defence reputation was built on centralised infrastructure like X-Road, not on universal compliance mandates; the fix for a hundred defaced Joomla sites should follow the same logic.