National Cyber Resilience in the Age of AI

A doctrine for asymmetric cyber defence. A white paper setting out six policies for keeping a state running, and trusted, under sustained AI-era cyberattack – drawing on nearly two decades of Estonian experience.

About the paper

The economics of cyberattack have turned against the defender. AI has made offensive operations cheaper, faster and easier to scale, while the defender's duty to be lawful, reliable and right has not changed. The cost of cybercrime now runs into the trillions annually, and the window for patching a newly disclosed flaw has collapsed from months to days. Most nations now face an adversarial volume larger than their defensive capacity.

Estonia has faced this asymmetry since 2007. The lesson of those years is that the right response is not to defend everything against everyone, but to choose where national effort changes the economics of attack and defence — and to deny the attacker the political prize even when a technical attack succeeds. A sustained campaign against a parliamentary democracy is rarely fought to destroy; it is fought to make a country look broken to its own citizens. Disruption is the means. The erosion of public trust is the end.

The paper sets out six policies, intended to be read as one doctrine:

  1. Designate the Minimum Viable State. Name in law the functions whose loss would harm life, the financial system, public order or the workings of the state, and rehearse the fallback for each.
  2. Harden the National Trust Backbone. Anchor digital trust — identity, signature, registers, exchange, audit, hosting — in a federated family of services hardened past the point where breaking them is affordable.
  3. Raise the security baseline through enforceable standards. Close the cheap path with non-negotiable controls, statutory independent audit, and a regulator empowered to ground an unsafe system the way an aviation authority grounds a fleet.
  4. Defend at machine speed, lawfully. Map and shrink the national digital estate, and give defenders pre-delegated legal authority — reviewable in court — to act within the attacker's window.
  5. Mobilise total cyber defence. Plan cyber capacity as one national workforce, from the professional through the reservist and the student to the citizen, the way the Nordics plan total defence.
  6. Defend democratic trust through proactive transparency. Disclose incidents within the news cycle, pre-bunk manipulation, and place every defensive instrument under independent oversight. Trust survives openness, not suppression.

The outcome the doctrine pursues is not invulnerability but resilience: a country that fails well, where incidents stop becoming crises, an attacker pays more than the result is worth, and a citizen, watching the system bend, still trusts that it will hold.

Background

The white paper was co-authored by an expert working group convened across government, the private sector and academia, including the Ministry of Justice and Digital Affairs, the National Cyber Security Centre (NCSC-EE) and Information System Authority, the Estonian IT Centre, the Estonian Internet Foundation, TalTech, Nortal, Luminor and Swedbank.

For the Ministry, the paper reflects the policy questions now before every digital state: which functions must remain operational under sustained attack, where digital trust is anchored, and how defence is organised when attacks arrive at machine speed. It is offered as a contribution to that debate, in Estonia and among allies.

Authors

Andres Raieste, Global Head of Public Sector, Nortal · Tõnu Grünberg, Deputy Secretary General for Digital Infrastructure and Cyber Security, Ministry of Justice and Digital Affairs · Joonas Heiter, Director General, NCSC-EE and Information System Authority · Andri Rebane, Director of Information Security Department, Estonian IT Centre · Dr Taavi Viilukas, Head of National Cyber Security, Ministry of Justice and Digital Affairs · Madis Tapupere, CTO for Core Banking, Luminor · Toomas Vaks, Cyber Risk Manager, Swedbank · Priit Liivak, Chief Government Technology Officer, Nortal · Andres Kütt, Supervisory Board Member, Estonian Internet Foundation · Dr Rain Ottis, Professor of Cyber Operations, TalTech

Download

Tallinn, 2026. 48 pages, English.

Citation

Raieste, A., Grünberg, T., Heiter, J., Rebane, A., Tapupere, M., Viilukas, T., Vaks, T., Liivak, P., Kütt, A., & Ottis, R. (2026). National Cyber Resilience in the Age of AI. Tallinn.


Last updated: 18.06.2026