Photo: JMinistry of Justice and Digital Affairs SAFER CYBERSPACE ● Kaido Tee, Irina Klementi and Taavi Viilukas. ments are vital, so too is analysing the overall resilience of organisations and the state as a whole. A UNIFIED LEGAL FRAMEWORK Given the evolving security landscape, it is essential to harmonise the legal framework for cybersecurity, network and information security, and crisis management to make sure it reflects best practices and secures the continuity and safety of Estonia’s services in even the most challenging situations. In the near future, it will be important to incorporate international directives into Estonian law in a way that balances national defence, business freedom and cybersecurity requirements. European Union (EU) directives form a critical part of Estonia’s cybersecurity framework. However, their implementation should avoid rigid and unconsidered solutions. Too often, Estonian legislators fall into the trap of rigorously and meticulously implementing EU directives and regulations while losing sight of their purpose and intended benefits. A smart approach to implementing EU directives involves analysing their impact and adapting them to local conditions. For example, when adopting the NIS2 directive in Estonia – which outlines cybersecurity CYBER SECURITY IN ESTONIA 2025 requirements for essential service providers – the focus should go beyond merely meeting technical requirements. Instead, priority should be given to fostering local business development and strengthening the country’s digital resilience. This involves considering the size of local businesses, the unique characteristics of various sectors and the state of infrastructure development. Such an approach ensures that regulations genuinely enhance security rather than devolving into burdensome bureaucracy. Otherwise, large international corporations with greater resources and experience would gain a competitive edge – an outcome that is clearly not in Estonia’s best interests. LOOKING TO THE FUTURE As policymakers shaping cybersecurity, we must address immediate issues while also preparing for the future. Within the next decade, quantum computing will fundamentally transform data protection and cybersecurity, breaking the currently secure and reliable cryptographic methods. Thus, it is essential to begin adopting quantum-resistant algorithms, also known as post-quantum cryptography. Within the next decade, quantum computing will fundamentally transform data protection and cybersecurity. Cybersecurity requires more than implementing physical, technical and procedural measures. It demands a systemic and community-based approach to protecting the nation as a whole. Cybersecurity is a matter of national sustainability and must not be underestimated. To enhance our defences, we must combine our knowledge and skills and collaborate not only within the public sector but also with the private sector and internationally. Cybersecurity demands a unified ‘we’ mindset, moving beyond blame games and divisive ‘us versus them’ attitudes to work together towards a shared goal. Only then can we ensure the security of our digital state. ● 43

Select target paragraph3