The doctrine, originally aimed at smaller countries, has also attracted the interest of larger nations. The paper is based on the experience and solutions implemented in Estonia.
According to Tõnu Grünberg, the Director of the Ministry of Justice and Digital Affairs and the Chief of the Cyber Security Agency, artificial intelligence has fundamentally changed both cyberattacks and defense: AI allows for faster, cheaper, larger-scale, and more frequent targeting of a very large number of targets.
"An attacker, who may also be politically motivated, can allow themselves to launch thousands and millions of unsuccessful attacks, as the cost of a single attack is almost negligible," said Grünberg, one of the authors of the paper. "Attackers can also buy the capability of launching attacks for people who lack deep technical skills," Grünberg said.
According to the authors of the paper, AI attackers can constantly search for new vulnerabilities, and in order to counter them, it may take days or hours instead of weeks. The goal of the asymmetric cyber defense doctrine is not complete invulnerability, but rather a cautious approach: reducing defense costs, making attacks more costly, and ensuring that cyber incidents do not become decisive for countries in the context of the functioning of digital services.
The paper "National Cyber Resilience in the Age of AI" proposes five main recommendations or solutions that countries should adopt to protect their digital services in the age of AI.
First, the doctrine suggests that countries should define a minimum viable state: the list must include the essential e-services and state functions that must continue to operate even during the most severe attack, and transition to contingency plans.
"First, they must define the basic parameters that must be protected. Alongside this, there is the importance of other and third levels, where digital services can be temporarily suspended to save resources," explained Tõnu Grünberg. "It is not possible to protect everything with the same strength. Therefore, the state must clearly define the services and functions whose absence the state cannot allow: identity, communication, electricity, and the basic functions of the state. In these areas, one must know not only how to repel an attack but also how to continue the work if some system or service provider is under attack."
Second, according to the doctrine, national trust must be strengthened: digital trust must be anchored in services that are protected to a level where their breach is economically unfeasible for the attacker. In this regard, the concept of zero-trust architecture is adopted, which means that no single data source or device is trusted in systems.
Third, security must grant systems the right to operate, guaranteed by robust standards: state regulations must raise the general security level of services and eliminate cheap entry points for attackers.
The fourth main principle of the paper is that the automation of attacks requires action at machine speed and legality. "Humans cannot keep up with attacks generated by AI: one can only keep up with AI by means of AI," said Grünberg. Countries must see the entire map of their systems in real-time, reduce the number of regulated devices, and be able to react to the attacker's actions in real-time, not afterwards.
According to Grünberg, countries should also use publicly available cloud services protected by globally trusted providers in the public sector.
The fifth point of the doctrine sets the goal of mobilizing the entire country for cyber resilience: the healthy nation, including its citizens' instincts and reflexes, must be taught to recognize not only a harsh cyber threat but also deep infiltration.
Finally, to maintain democratic trust, transparency must be ensured: states must speak first, as trust resides in openness, not concealment.
The importance of cyber resilience grows even further in the future as AI agents begin to use digital services independently on behalf of people. Their actions must also be controllable and secure. The secure functioning of such proactive digital services requires strong and asymmetric cyber defense.
"In the age of AI, the goal of cyber resilience cannot be just to repel all attacks. The digital state must be built in a way that it can fulfill its most important functions even under a strong attack. To this end, we must know what must be protected at any cost, reduce critical dependencies, and be ready to recover quickly. Cyber resilience must be built into the architecture of the digital state. And when an incident occurs, it must be explained to the public as openly as possible to maintain credibility," said Joonas Heiter, the RIA Director-General and one of the authors of the paper.
Experts and scientists from various institutions contributed to the paper "National Cyber Resilience in the Age of AI," and the authors include Andres Raieste, Tõnu Grünberg, Joonas Heiter, Andri Rebane, Taavi Viilukas, Madis Tapupere, Toomas Vaks, Priit Liivak, Andres Kütt, and Rain Ottis.
Ministry of Justice and Digital Affairs press release, September 15, 2026
