Contents Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 The vision and fundamental principles of the cybersecurity strategy . . . . . . . . . . . . . . . . . . . . . 1 0 Strategic objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14 Priority activities. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16 1. The current state of cybersecurity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18 1.1 Trends affecting cybersecurity. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19 1.2 Estonia’s strengths. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24 1.3 Challenges for Estonia. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26 2. Coordination and implementation of the strategy. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28 2.1 Role and scope of the cybersecurity strategy. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28 2.2 Linkage with other strategies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 29 2.3 Linkage with strategies of other countries and international strategies. . . . . 33 2.4 National cybersecurity coordination and organization of management. . . . . 33 3. Strategic objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 36 A sustainable digital society . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40 Activity area 1.1 Making technological resilience more effective. . . . . . . . . . . . . . . . . . . . . . . . . 41 Activity area 1.2 Prevention of, readiness for and management of incidents and crises. . . . . . . . 45 Activity area 1.3 Integral management of the sector and shaping a cohesive community. . . . . 47 Cybersecurity Industry, Research and Development . . . . . . . . . . . . . . . . . . . . . . . . . . 51 Activity area 2.1 Supporting and promoting cybersecurity r&d and research-based enterprise. 52 Leading international contributor . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 56 Activity area 3.1 Making cooperation with strategic foreign partners more effective. . . . . . . . . . . 58 Activity area 3.2 International promotion of sustainable cyber capability. . . . . . . . . . . . . . . . . . . . . 60 A cyber-literate society . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64 Activity area 4.1 Raising the cyber awareness of citizens, state and private sector. . . . . . . . . . . . . 66 Activity area 4.2 Development of talent corresponding to state and private sector demand. . . 70 6

Select target paragraph3