Estonia Estonia CCDCOE cyber defence NATO

NATO's Cyber Centre Is Quietly Institutionalizing Ukraine's War Lessons — and That's the Right Call

A CCDCOE visit to Kyiv signals NATO wants to formalize, not just admire, Ukraine's wartime cyber-defence playbook.

Ukraine's Cyber Defence, By the Numbers People of Internet Research · Estonia 2023 CCDCOE member since Ukraine joined as a contributing p… 4,300+ 2024 cyber incidents recorded CERT-UA logged over 4,300 incident… 85%+ Reliance on US providers Share of surveyed Ukrainian organi… 21 Organizations surveyed for brief CCDCOE's March 2026 brief drew on … peopleofinternet.com
Ukraine's Cyber Defence, By the Number… People of Internet Research · Estonia 2023 CCDCOE member since 4,300+ 2024 cyber incidents record… 85%+ Reliance on US providers 21 Organizations surveyed for bri… peopleofinternet.com

Key Takeaways

On August 17, 2026, a delegation from the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE), the Tallinn-based hub that has anchored NATO's cyber-defence research since 2008, traveled to Kyiv for a working visit with Ukraine's State Service of Special Communications and Information Protection (SSSCIP). The Norwegian researcher Erik Kursetgjerde, CCDCOE's senior national representative for Norway, met SSSCIP chief Maj. Gen. Oleksandr Potii and briefed with Ukrainian government, military, and academic officials. According to CCDCOE's own account of the visit, the two sides "outlined promising areas for strategic partnership" and discussed "joint initiatives aimed at strengthening collective cyber resilience."

That sentence sounds anodyne. It is not. Ukraine has been a CCDCOE contributing participant since a flag-raising ceremony in Tallinn on May 16, 2023 — alongside Japan, Iceland, and Ireland — but contributing-participant status was always a foot in the door, not a seat at the table. Three years into a war that has made Ukraine the most cyber-attacked state on the planet, the practical question is whether NATO turns an observer relationship into something with teeth: shared threat-intel pipelines, standing liaison staff, and doctrine that actually absorbs what Ukrainian defenders have learned under fire.

Why the Caution Is Reasonable

Skeptics of deeper integration have a real argument, not just bureaucratic inertia. CCDCOE is a NATO-accredited research and training body, not a command structure — folding a non-NATO, actively-invaded state more tightly into its work raises genuine questions about what obligations, security clearances, and information-sharing risk NATO members would be taking on with a country whose networks are, by definition, the most contested in Europe. A researcher's laptop in Kyiv is a different threat-model than one in Tallinn. NATO's caution about full membership status for Ukraine — it remains a contributing participant, not a sponsoring nation with Steering Committee votes — reflects a defensible instinct to keep the accreditation boundary between allies and partners legible, especially while accession to NATO itself remains unresolved.

That instinct has costs, though, and this month's visit is evidence NATO's own cyber experts think the costs are now higher than the risk.

What Ukraine Actually Brings

A CCDCOE policy brief published in March 2026, "Ukraine's Cyber Defence Evolution: The Role of Non-State Actors and Public-Private Partnerships," is the clearest public evidence of why. Drawing on interviews and surveys with 39 respondents across 21 Ukrainian organizations spanning government, military, private sector, and civil society, the brief identifies four pillars sustaining Ukraine's cyber resilience — government innovation, private-sector expansion, international partnerships, and integration with technology companies — built largely through "informal networks and ad hoc arrangements" rather than a pre-war public-private partnership model. Kursetgjerde, one of the brief's authors, put it plainly: those improvised arrangements "are impressive, but they also reveal structural gaps that NATO and allies must address swiftly."

The scale of what Ukraine is defending against is not in dispute. CERT-UA, Ukraine's national response team, recorded more than 4,300 cyber incidents in 2024, a 70% jump from the prior year, according to reporting on Ukraine's cybersecurity sector by Recorded Future's The Record. Potii, at the August 17 meeting, described the country as "countering intensive cyberattacks against critical infrastructure and the public sector on a daily basis, accumulating unique institutional and practical experience." That is not a boast; it is the kind of empirical dataset that no NATO member has generated at comparable scale, because no NATO member has been fighting a peer cyber adversary at war-time intensity for four straight years.

The Case for Formalizing, Not Just Visiting

Kursetgjerde's own framing of the threat should settle the proportionality question: "Threat actors are targeting local government and critical infrastructure in Ukraine and across Europe alike, and that is exactly where knowledge and capacity are thinnest." If the vulnerability is shared — and Russian-linked intrusion campaigns against European municipal networks and utilities suggest it is — then the knowledge asymmetry runs the wrong way. Ukraine has the operational experience; smaller NATO and EU member states have the institutional capacity gaps the March brief warns about. A one-way flow of goodwill visits doesn't close that gap. Structured mechanisms would: standing CCDCOE-SSSCIP liaison staff, a formal channel for Ukrainian incident data to feed CCDCOE's research and Locked Shields exercise design, and — the brief's own recommendation — pre-negotiated public-private partnership templates that NATO members can adopt before their own crises, not after.

The brief also flags a less comfortable finding: over 85% of surveyed Ukrainian organizations depend on US-based cloud and security providers, a concentration that is both a resilience asset (scale, redundancy) and a sovereignty risk NATO planners should not wave away. Formalizing cooperation is also the venue where that conversation — diversifying critical-infrastructure vendor dependence without sacrificing capability — belongs, rather than being left to individual ministries to solve ad hoc.

None of this requires resolving Ukraine's NATO accession question, which is a separate and far more fraught political track. Cyber-defence cooperation has historically moved faster and with less friction than membership politics precisely because it is technical, mutually beneficial, and hard to frame as escalatory. CCDCOE should use that latitude. A single August visit, however warmly described, is not formalization. The test of whether NATO has actually absorbed the lesson Ukraine is paying to teach it will be whether the next report on this relationship describes an agreement, not another visit.

Sources & Citations

  1. CCDCOE: NATO CCDCOE visits SSSCIP and other Ukrainian institutions
  2. CCDCOE: New policy brief on Ukraine's cyber defence transformation
  3. RNBO Ukraine: Ukraine becomes member of NATO CCDCOE
  4. The Record: Ukrainian cyber market grows amid war
  5. The Defense Post: Ukraine joins NATO cyber-defense center