Photo: JMinistry of Justice and Digital Affairs
SAFER CYBERSPACE ●
Kaido Tee, Irina Klementi and Taavi Viilukas.
ments are vital, so too is analysing the overall
resilience of organisations and the state as a
whole.
A UNIFIED LEGAL FRAMEWORK
Given the evolving security landscape, it is
essential to harmonise the legal framework for
cybersecurity, network and information security, and crisis management to make sure it
reflects best practices and secures the continuity and safety of Estonia’s services in even the
most challenging situations.
In the near future, it will be important to
incorporate international directives into Estonian law in a way that balances national
defence, business freedom and cybersecurity
requirements.
European Union (EU) directives form a critical
part of Estonia’s cybersecurity framework. However, their implementation should avoid rigid and
unconsidered solutions. Too often, Estonian legislators fall into the trap of rigorously and meticulously implementing EU directives and regulations while losing sight of their purpose and
intended benefits. A smart approach to implementing EU directives involves analysing their
impact and adapting them to local conditions.
For example, when adopting the NIS2 directive in Estonia – which outlines cybersecurity
CYBER SECURITY IN ESTONIA 2025
requirements for essential service providers –
the focus should go beyond merely meeting technical requirements. Instead, priority should be
given to fostering local business development
and strengthening the country’s digital resilience. This involves considering the size of local
businesses, the unique characteristics of various
sectors and the state of infrastructure development. Such an approach ensures that regulations genuinely enhance security rather than
devolving into burdensome bureaucracy. Otherwise, large international corporations with
greater resources and experience would gain a
competitive edge – an outcome that is clearly not
in Estonia’s best interests.
LOOKING TO THE FUTURE
As policymakers shaping cybersecurity, we
must address immediate issues while also preparing for the future. Within the next decade,
quantum computing will fundamentally transform data protection and cybersecurity, breaking the currently secure and reliable cryptographic methods. Thus, it is essential to begin
adopting quantum-resistant algorithms, also
known as post-quantum cryptography.
Within the next decade,
quantum computing will
fundamentally transform data
protection and cybersecurity.
Cybersecurity requires more than implementing physical, technical and procedural measures.
It demands a systemic and community-based
approach to protecting the nation as a whole.
Cybersecurity is a matter of national sustainability and must not be underestimated. To enhance
our defences, we must combine our knowledge
and skills and collaborate not only within the
public sector but also with the private sector and
internationally. Cybersecurity demands a unified ‘we’ mindset, moving beyond blame games
and divisive ‘us versus them’ attitudes to work
together towards a shared goal. Only then can
we ensure the security of our digital state. ●
43