You can read more about all the recommendations on our website in Estonian, English, and Russian. In short:
- Recruit a head of information security and guarantee their autonomy
- Follow the Information Security Standard
- Plan resources for information security
- Test the security of your services and systems regularly
- Use the cyber test to improve the cyber hygiene of your establishment
- Invest in network protection and monitoring
- Require critical logs to be kept
- Encrypt data exchange
- Require reporting of security breaches and incidents to CERT-EE
- Make sure you have a crisis plan in place and practice it regularly
- Check out the short guide of the RIA about cyber security for businesses
In addition, the RIA recommends that public authorities use a secure public network.