National Cyber Resilience in the Age of AI
A doctrine for asymmetric cyber defence. A white paper co-authored by experts from TalTech, the Estonian government and the private sector on how a nation defends itself when AI has made attack cheaper than defence.
About the paper
Artificial intelligence has shifted the economics of cyber conflict against the defender. The window between a software flaw becoming public and its exploitation has collapsed from months to days, sometimes hours. Reconnaissance, phishing and exploit development are increasingly automated and sold as services, putting capability that once belonged to state intelligence agencies within reach of a much broader set of actors. Most nations now face an adversarial volume larger than their defensive capacity. They are, in effect, the smaller force.
Estonia has been in that position since 2007, when it absorbed the first national-scale cyberattack, and has defended against sustained campaigns by a far larger adversary ever since. The doctrine that emerges from that experience is asymmetric by design: lower the cost of defence, raise the cost of attack, and deny the political payoff that makes a country worth attacking in the first place.
National Cyber Resilience in the Age of AI sets out that doctrine as six policy moves, in the order a state should make them:
- Designate the Minimum Viable State — choose what must not fail, and rehearse the fallback for each function.
- Harden the National Trust Backbone — anchor digital trust in services hardened past the point where breaking them is affordable.
- Raise the security baseline through enforceable standards — make security an operating licence, not paperwork, and give the regulator the power to ground an unsafe system.
- Defend at machine speed, lawfully — give defenders pre-delegated legal authority to act within the hours an attacker now has.
- Mobilise total cyber defence — plan cyber capacity the way the Nordics plan total defence: one national workforce, from professional to reservist to citizen.
- Defend democratic trust through proactive transparency — tell the truth first, because trust survives openness, not suppression.
The aim is not invulnerability. It is to make attacks non-decisive: incidents stop becoming crises, crises stop becoming national paralysis, and an attacker pays more than the result is worth.
TalTech's contribution
The paper was co-authored by an expert working group from government, the private sector and academia, including Dr Rain Ottis, Professor of Cyber Operations at TalTech. It reflects TalTech's continuing role in shaping Estonian and allied thinking on cyber defence, from research and doctrine to the education pipeline the paper itself identifies as a pillar of national resilience.
Authors
Andres Raieste (Nortal), Tõnu Grünberg (Ministry of Justice and Digital Affairs), Joonas Heiter (NCSC-EE / Information System Authority), Andri Rebane (Estonian IT Centre), Dr Taavi Viilukas (Ministry of Justice and Digital Affairs), Madis Tapupere (Luminor), Toomas Vaks (Swedbank), Priit Liivak (Nortal), Andres Kütt (Estonian Internet Foundation), and Dr Rain Ottis (TalTech).
Download
National Cyber Resilience in the Age of AI: A doctrine for asymmetric cyber defence, Tallinn, 2026. 48 pages, English.
Citation
Raieste, Andres; Grünberg, Tõnu; Heiter, Joonas; Rebane, Andri; Viilukas, Taavi; Tapupere, Madis; Vaks, Toomas; Liivak, Priit; Kütt, Andres; Ottis, Rain (2026). National Cyber Resilience in the Age of AI. TalTech. DOI: 10.48726/1wy7m-z3y77.