OVERVIEW OF 2024 ● cyber groups have exploited to expand their activities. In response, Estonia has significantly increased its investments in cybersecurity and the protection of critical infrastructure. Central to this effort is the services provided by the Information System Authority, which helps government agencies secure their networks, continuously search for vulnerabilities, and notify government institutions and businesses about identified issues. If an incident does occur, CERT-EE experts are available to investigate the causes and assist in resolving the situation. Although most private companies in Estonia are not legally required to report cyber incidents, doing so is highly recommended. Reporting incidents enables CERT-EE to gain a better overview of Estonia’s cyber landscape and improve the protection of both businesses and the national system as a whole. It also helps identify the activities of state-sponsored cyber actors. State-run cyber units are characterised by persistence: if an attack fails once, it can be expected to be attempted again. Government institutions and critical infrastructure companies are undoubtedly at the highest risk, but firms providing services to them – such as IT or accounting companies – are also vulnerable to supply chain attacks. Often, similar attack patterns are used against multiple organisations simultaneously, making every piece of information vital for understanding the bigger picture. An anomaly that might seem insignificant at first could, upon closer examination, turn out to be a serious cyberattack. Ultimately, each organisation is responsible for protecting its own systems and much depends on how seriously its leadership prioritises information security. If necessary, the Information System Authority’s supervision department can remind organisations of the importance of cybersecurity. This department has significantly expanded its reach, having initiated nearly 150 supervisory review proceedings over the past three years. The work is mainly preventive: instead of reacting solely to identified problems, the department proactively monitors the situation in critical institutions and companies based on threat forecasts. ● CYBER SECURITY IN ESTONIA 2025 How to protect yourself from cyber espionage As state-sponsored cyber groups often employ the same methods and tools as financially motivated cybercriminals, general cybersecurity recommendations remain relevant. However, some specific aspects should be kept in mind: - Preserve system logs. Retaining system logs is critical for detecting any cyberattacks. Record as much information as possible (e.g. firewall logs) to understand what attackers did and how they did it. However, logs are only useful if they can be analysed effectively and threats are acted upon promptly. Remote access solutions and the accounts they use should be monitored with particular care. - Segment internal networks. Depending on organisational needs, internal networks should be divided into segments, with access permissions granted strictly on a need-to-know basis. Administrators must use separate accounts – one with user-level permissions for daily tasks and another with elevated privileges only when necessary. Passwords should never be reused across systems, and two-factor authentication should be implemented wherever possible. - Modernise systems. Keep centralised management systems up to date and phase out outdated software and hardware. While an upfront investment to eliminate legacy systems might seem high, it can prevent much greater damage in the long run. - Address supply chain risks. When using services provided by external partners, consider supply chain vulnerabilities. Regularly audit external partners’ access to your systems and grant them only the minimal permissions required for their work. For more detailed technical guidance, consult recommendations from the US Cybersecurity and Infrastructure Security Agency (CISA) here. 23

Select target paragraph3