Experts and researchers from various Estonian state authorities, universities, technology companies, and banks have completed a comprehensive cyber defense thought paper that offers recommendations to countries for protecting the digital society in the age of artificial intelligence.
Initially aimed primarily at small countries, the doctrine has also attracted interest from larger nations upon its presentation. The thought paper relies on Estonia's experience and the solutions implemented here.
According to Tõnu Grünberg, Deputy Secretary General for Digital Infrastructure and Cybersecurity at the Ministry of Justice and Digital Affairs (JDM), artificial intelligence has profoundly changed both cyber attacks and defense: artificial intelligence enables attacking faster, cheaper, on a larger scale, and targeting a very large number of targets simultaneously.
"An attacker, who may also be politically motivated, can afford thousands and millions of failed attempts, because the cost of one additional attempt is almost non-existent. Complex attack capabilities can also be purchased by people who do not have deep technical skills themselves," said Grünberg, who is one of the authors of the thought paper.
According to the authors of the thought paper, artificial intelligence is capable of constantly looking for new vulnerabilities, and there may be only days or hours left to eliminate them instead of weeks. The goal of the created asymmetric cyber defense doctrine is not complete invulnerability, but a clever approach is necessary: lowering the costs of defense, making attacking expensive, and ensuring that cyber incidents do not become decisive for countries in terms of the functioning of digital services.
The thought paper "National Cyber Resilience in the Age of AI" proposes six main recommendations or solutions that countries should adopt to secure their digital services in the age of artificial intelligence based on the above.
First, the doctrine envisions that countries should define a minimum viable state: the list must include those vital e-services and state functions that must remain operational at all costs even during the most severe possible attack, and switching to backup solutions must also be practiced.
"First, the main perimeter must be defined, which must be protected in any case. Alongside this, digital services of secondary and tertiary importance may exceptionally be temporarily suspended to save resources," Tõnu Grünberg explained. "It is not possible to protect everything with the same strength. Therefore, the state must clearly define the services and functions whose interruption the state cannot afford: whether it is identity, communications, electricity, or basic state functions. For these selected ones, it is necessary to know not only how to prevent an attack, but also how to continue working if a system or service provider fails."
Second, according to the doctrine, the national trust infrastructure must be strengthened: digital trust must be anchored in services that are protected to a level where breaking them is economically unreasonable for the attacker. In doing so, the term zero-trust architecture is introduced, which means that in the case of systems, no external data request or device is trusted.
Third, security must become a license to operate for systems, which is guaranteed by enforceable standards: national regulations must raise the general baseline level of security for services and eliminate cheap entry paths for attackers.
The fourth main message of the thought paper is that automating attacks requires operating at machine speed and legally. "Humans can no longer resist attacks created by artificial intelligence with sufficient speed: artificial intelligence can only be countered with artificial intelligence," said Grünberg. Countries must see a real-time map of all their systems, reduce the number of unattended devices, and be able to respond to attacks within the attacker's window of operation, not only after it.
According to Grünberg, countries should also more boldly use public cloud services secured by global service providers in the public sector.
Fifth, the doctrine sets the goal of mobilizing the entire country for cyber defense: the entire country, including citizens, must be taught to recognize phishing and deepfakes, not just a narrow cyber team.
The sixth and final pillar is protecting democratic trust through transparency: countries must tell the truth first, because trust relies on openness, not concealment.
The importance of cyber defense will grow even more in the future, when artificial intelligence agents start using digital services independently on behalf of people. Their activities must also be controllable and secure. The secure functioning of such proactive digital services requires strong and asymmetric cyber defense.
Experts and researchers from several institutions contributed to the completion of the thought paper "National Cyber Resilience in the Age of AI," and its authors are Andres Raieste (Nortal), Tõnu Grünberg (JDM), Joonas Heiter (The Information System Authority (RIA)), Andri Rebane, Taavi Viilukas (JDM), Madis Tapupere (Luninor), Toomas Vaks (Swedbank), Priit Liivak (Nortal), Andres Kütt (Estonian Internet Foundation), and Rain Ottis (TalTech).
Link to the doctrine: see comments
Make sure to share your own thoughts with the author by leaving a comment below
Log in or sign up to continue the conversation