OVERVIEW OF 2024 ●
cyber groups have exploited to expand their
activities.
In response, Estonia has significantly
increased its investments in cybersecurity and
the protection of critical infrastructure. Central
to this effort is the services provided by the
Information System Authority, which helps government agencies secure their networks, continuously search for vulnerabilities, and notify government institutions and businesses about identified issues. If an incident does occur, CERT-EE
experts are available to investigate the causes
and assist in resolving the situation.
Although most private companies in Estonia
are not legally required to report cyber incidents,
doing so is highly recommended. Reporting incidents enables CERT-EE to gain a better overview of Estonia’s cyber landscape and improve
the protection of both businesses and the national system as a whole. It also helps identify the
activities of state-sponsored cyber actors.
State-run cyber units are characterised by
persistence: if an attack fails once, it can be
expected to be attempted again. Government
institutions and critical infrastructure companies are undoubtedly at the highest risk, but
firms providing services to them – such as IT or
accounting companies – are also vulnerable to
supply chain attacks. Often, similar attack patterns are used against multiple organisations
simultaneously, making every piece of information vital for understanding the bigger picture.
An anomaly that might seem insignificant at
first could, upon closer examination, turn out to
be a serious cyberattack.
Ultimately, each organisation is responsible
for protecting its own systems and much
depends on how seriously its leadership prioritises information security. If necessary, the
Information System Authority’s supervision
department can remind organisations of the
importance of cybersecurity. This department
has significantly expanded its reach, having initiated nearly 150 supervisory review proceedings over the past three years. The work is mainly preventive: instead of reacting solely to identified problems, the department proactively
monitors the situation in critical institutions
and companies based on threat forecasts. ●
CYBER SECURITY IN ESTONIA 2025
How to protect yourself
from cyber espionage
As state-sponsored cyber groups often
employ the same methods and tools as
financially motivated cybercriminals, general
cybersecurity recommendations remain
relevant. However, some specific aspects
should be kept in mind:
- Preserve system logs. Retaining system
logs is critical for detecting any cyberattacks. Record as much information as
possible (e.g. firewall logs) to understand
what attackers did and how they did it.
However, logs are only useful if they can be
analysed effectively and threats are acted
upon promptly. Remote access solutions
and the accounts they use should be
monitored with particular care.
- Segment internal networks. Depending
on organisational needs, internal networks
should be divided into segments, with
access permissions granted strictly on a
need-to-know basis. Administrators must
use separate accounts – one with
user-level permissions for daily tasks and
another with elevated privileges only when
necessary. Passwords should never be
reused across systems, and two-factor
authentication should be implemented
wherever possible.
- Modernise systems. Keep centralised
management systems up to date and
phase out outdated software and hardware. While an upfront investment to
eliminate legacy systems might seem
high, it can prevent much greater
damage in the long run.
- Address supply chain risks. When using
services provided by external partners,
consider supply chain vulnerabilities.
Regularly audit external partners’ access
to your systems and grant them only the
minimal permissions required for their
work.
For more detailed technical guidance, consult
recommendations from the US Cybersecurity
and Infrastructure Security Agency (CISA)
here.
23