10 cyber commands for top managers

Cyber incidents occur continuously around the world, and some of them can disrupt an organisation’s operations for days, sometimes even longer. Data breaches, malware infections, or ransomware attacks can derail even the most carefully laid plans. In most cases, cyber incidents can be successfully prevented if employees maintain good cyber hygiene and information security is managed systematically across the organisation

The organisation's top management is responsible for information security and must ensure that it is managed systematically, that the necessary resources are allocated, and that a culture that values cybersecurity is fostered throughout the organisation.

1. Appoint a capable head of information security

The role of the head of information security is to protect the data essential to the organisation in accordance with best practice, ensuring systematic control over your information assets, staff, and working procedures. This role can only be fulfilled successfully if the head of information security is involved in the governance of the organisation, is independent of the IT department and the rest of the organisation feels fully supported by the top manager in the guidance they provide.

Under the General Data Protection Regulation (GDPR), organisations are required in certain circumstances to appoint a Data Protection Officer (DPO). You can read more about this on the website of the Data Protection Inspectorate (in Estonian).

2. Follow the Information Security Standard

Standards make information security systematically manageable by providing requirements and guidance for establishing an organisation's information security management system. Information System Authority (RIA) has established the Estonian Information Security Standard (E-ITS), which provides a basis for information security in Estonian, compliant with the Estonian legal system. E-ITS is aligned with the internationally recognised information security management standard ISO/IEC 27001.

  • Require that the organisation’s information security be managed in accordance with either the E-ITS or the ISO/IEC 27001 standard.

3. Implement a risk management process and plan resources for information security

The resources allocated to cyber security depend on the business risks of the organisation, and the security requirements of the service. 

  • Insist that the organisation implements a risk management process which sets out the procedures for carrying out risk analysis and regular reviews, as well as risk treatment activities (which risks to accept, mitigate, transfer, or avoid).
  • Ensure that the head of IT and the head of information security are involved in risk analysis and risk management activities, in order to establish a comprehensive overview of what constitutes critical data, threats, and vulnerabilities based on the service lifecycle, and what investments are needed to mitigate the associated risks.
  • Highlight cyber security costs when planning organisation’s ICT budget.

The E-ITS risk management manual developed by RIA helps with risk management planning. More information

4. Invest in the protection and monitoring of your network

Use intrusion prevention and detection equipment (Intrusion Detection System IDS / Intrusion Protection System IPS) and require the head of information security to record and analyse network traffic.

  • Require that management be informed of the results of monitoring and of any incidents, and that a post-incident analysis be carried out for incidents with an impact, together with a review of the risk assessment and recommendations for further measures to prevent similar incidents from recurring in the future.

The CERT-EE solution Suricata for All (S4A) can provide support in the management of network traffic monitoring and protection. It facilitates the building of a freeware-based network traffic monitoring solution, providing assistance from CERT-EE to detect attacks and malware. More information: [email protected]

5. Make sure your email is secure

One of the main attack vectors against businesses relates to the misuse of organisational email correspondence.

  • Establish rules regarding whether, to whom, and from which devices access should be granted to work emails, and ensure that the organisation’s data exchange, especially email, is encrypted and that forging your organisation’s email addresses is made as difficult as possible for criminals (SPF, DKIM, and DMARC are keywords).

More information on the manual compiled by RIA (in Estonian):

Turvaline meilivahetus avalikus sektoris 2019 | 1020.5 KB | pdf

6. Test the security of services and systems regularly and plan for the management of security vulnerabilities

Security vulnerabilities are constantly being discovered in systems and are immediately exploited by criminals or hostile countries. The resources spent on managing security vulnerabilities and testing system security are an investment that helps to reduce the costs of critical incidents.

  • Insist on the systematic management of security vulnerabilities in the technology used within your organisation and establish a policy within your organisation that security tests should always be carried out before new services or new versions of existing services are introduced. We recommend carrying out systematic testing of your core services at least every two years.
  • Insist that the resources required for security testing are included in the budget and that the relevant contracts are in place.

7. Use the cyber test to improve the cyber hygiene of your organisation

Cyber security depends on the awareness of employees, as cyber incidents often stem from the action or inaction of a user. The cyber test offered by RIA provides a quick and free way to give the employees a basic understanding of cyber hygiene and an operational overview of their cyber security awareness. On this basis, it is possible to commission specific training courses or carry out further awareness-raising activities. The content of the cyber test is updated every year and it is recommended to be taken once a year.

  • Insist that the head of information security provides a regular update on the results of the cyber test and on the planned follow-up actions, such as targeted training.

8. Work with CERT-EE

Each incident report is necessary to maintain the whole picture and rapid notification and information exchange with CERT-EE contributes to risk mitigation in the country as a whole. The obligation to report incidents applies to public authorities and the private sector service providers listed in the Cybersecurity Act, but all other organisations are also welcome to report incidents.

  • Ask your head of information security or head of IT for a regular update on the incidents that the organisation has reported to CERT-EE.

Further information and reporting: [email protected] or raport.cert.ee

9. Require logs to be kept and regular monitoring

  • Require the head of information security and the head of IT to agree on principles for logging, log retention, and log monitoring, in order to identify potential misuse and service-related issues.

The principles must clearly specify what logs are collected, where they are securely stored, and for how long, so that they can be used to analyse a cyber incident. In addition, requirements for the regular monitoring of logs and guidelines for action in the event of anomalies must be established.

10. Make sure you have a crisis plan in place and practice it regularly

As well as preventing cyber incidents, it is important to establish guidelines for situations where an incident has nevertheless occurred, for example, where a workstation, email system, document management system, or any other information system is not functioning.

  • Based on the business risks of your organisation, draw up a Plan B – or contingency plan – to ensure that a cyber incident does not disrupt the availability of services, and set out how to recover from such an incident (key elements include the roles, work processes, backups, and service provider contracts required for recovery) and return to normal operations.

In a crisis situation, a plan that is years old is of no use, so make sure to schedule regular reviews of the crisis plan and regular crisis drills for all roles involved in crisis management, including senior management.

An additional recommendation for public authorities: Use the state network

The state network is a state-provided internet service, the RIA is responsible for its quality and security. RIA's Incident Response Department CERT-EE conducts security monitoring of the state network with the support of Estonia’s best threat indicators, technical and substantive capabilities. Joining the state network will significantly improve the cyber security of your establishment and also provide a more comprehensive view of what is happening in the Estonian cyberspace. More information

Further reading

To help organisations manage their cyber security, RIA has drawn up a brief guide which provides an overview of the areas to focus on and what to require from an IT specialist:

Cybersecurity quick guide for companies (2025) | 350.35 KB | pdf

Last updated: 24.07.2026

search block image