Cyber security recommendations for top managers

11+ recommendations for top managers on ensuring cyber security

1. Recruit a head of information security and guarantee their autonomy

You need someone to systematically check your information assets, staff, and working procedures. This role can only be fulfilled successfully if the head of information security is involved in the governance of the organisation, is independent of the IT department and the rest of the organisation feels supported by the top manager in the guidance they provide.

If possible, create a dedicated position for data management in the form of a data protection specialist. Under the General Data Protection Regulation, there is also an obligation to appoint a data protection specialist in certain cases. You can read more about this on the website of the Data Protection Inspectorate (in Estonian).

2. Follow the Information Security Standard

The information security organisation of an establishment should be built on a standard or best practice. This provides an opportunity to require compliance with the rules and systematic reporting on the management of information and network security. The standard provides answers to the question of how to organise the management of information assets, access, and user rights; how to back up data and protect data media, etc. Information System Authority (RIA) has established the Estonian Information Security Standard (E-ITS) and its objective is to develop and promote the level of information security in both the Estonian public and private sectors by presenting a basis for information security in Estonian, compliant with the Estonian legal system, which is also aligned with the internationally recognised information security management standard ISO/IEC 27001. More information

3. Plan resources for information security

The resources allocated to cyber security depend on the security requirements of the service and the business risks of the establishment. For example, an e-shop is often a key part of the business model of a company. In this case, it is important to ensure that the e-shop runs smoothly and is easy to use, i.e. that it is available whenever the customer goes there. Otherwise, the company will simply miss out on the desired revenue. However, customers expect secure integration with the banking interface and that their data is not leaked. In other words, integrity and confidentiality requirements. If the online shop offers services from other parties, it also has contracts with them and they in turn have requirements for manageability, integrity, and confidentiality. These requirements are often accompanied by sanctions or fines, which need to be prevented by security measures. It is also important to make sure that different security measures are in place if the automation of systems, which people also work on, depends on IT. Ask your head of IT to carry out a risk assessment (and to identify cyber security costs when approving your ICT budget). The E-ITS set up by the RIA may help you assess the risks. More information

4. Test the security of services and systems regularly

Agree on a policy within your organisation that security tests should always be carried out before new services or new versions of existing services are introduced.

Insist on systematic testing of your core services at least once a year, if possible, and have the necessary contracts in place and budget for it.

5. Use the cyber test to improve the cyber hygiene of your establishment

Cyber security depends on the awareness of employees. Unfortunately, experience shows that behaviours are often reckless and risky. The cyber test provides a quick and free way to give the employees a basic understanding of cyber hygiene and an operational overview of their cyber security awareness. The RIA updates the content of the cyber test every year to provide the most up-to-date information to users of the test. This in turn is a good input for ordering further training. The RIA will help organise the training by organising outreach events for both regular users and technical experts. More information

6. Invest in network protection and monitoring

Use intrusion prevention and detection equipment and require the head of information security to record and analyse network traffic. Network traffic should be recorded for at least one week, preferably one month. Network traffic monitoring capabilities (including intrusion detection, storage and indexing of all network traffic) can be built using free components, while hardware investments may be necessary. The CERT-EE solution CERT-EE Suricata for All (S4A) can provide additional support in the management of network traffic monitoring and protection. The latter facilitates the building of a freeware-based network traffic monitoring solution, providing rules and assistance from CERT-EE to detect attacks and malware. More information: [email protected]

7. Require critical logs to be kept

Agree on a policy for keeping logs, as this will help to identify potential abuses and problems with the service later. It is important to agree which critical logs are to be stored. It is recommended that logs are stored intact in a secure environment for the time you need, with the assumption that they can also be used to analyse a cyber incident.

8. Encrypt data exchange

One of the main attack vectors against businesses relates to the misuse of organisational email correspondence. Require that your establishment’s data exchange, especially email, is encrypted and that forging your establishment’s email addresses is made as difficult as possible for criminals (SPF, DKIM, and DMARC are keywords). The guide (in Estonian) on the RIA website provides more information on these safeguards and helps to make email exchanges more secure:

Turvaline meilivahetus avalikus sektoris 2019 | 1020.5 KB | pdf

A guide drawn up by the United States Cybersecurity and Infrastructure Security Agency can also help improve the security of email and web server communications.

9. Require reporting of security breaches and incidents to CERT-EE

Don’t keep cyber incidents to yourself and share information with CERT-EE, that monitors the Estonian cyber space. Each incident report is necessary to maintain the whole picture and often to mitigate the risks for other users. Rapid notification and information exchange with CERT-EE contributes to risk mitigation in the country as a whole. The obligation to report incidents applies to public authorities and the private sector service providers listed in the Cybersecurity Act, but all other authorities are also welcome to report incidents. Further information and reporting: [email protected] or raport.cert.ee

10. Make sure you have a crisis plan in place and practice it regularly

Assess your business risks and prepare a plan B, i.e. how to make sure a cyber incident does not disrupt your services. Consider what happens if an e-service (e.g. emails, warehouse management software) is down for a while, the website is down, etc., and how to mitigate the impact. It is important to have an action plan for crisis management, but this is not enough – a crisis plan should also be systematically practised in the organisation.

11. Check out the short guide of the RIA about cyber security for businesses

The short guide of the RIA about cyber security for businesses is designed to help companies take the first steps towards more cybersecure business processes. It provides principles on how to protect your customers, systems, employees, and brand. The need for these principles should be understood by every business manager, and every IT service provider with any level of information security awareness should be able to implement them.

Cybersecurity quick guide for companies (2025) | 350.35 KB | pdf

In addition: Use a secure public network (recommendation for public authorities)

The state network is a state-provided internet service, the RIA is responsible for its quality and security. CERT-EE conducts security monitoring of the state network with the support of Estonia’s best threat indicators, technical and substantive capabilities. Joining the state network will significantly improve the cyber security of your establishment and also provide a more comprehensive view of what is happening in the Estonian cyberspace. More information

Last updated: 26.03.2026

search block image