Opens in a new tab

Organizations struggle to meet cybersecurity requirements

Friday 18th September 2026 on 17:15 in Estonia

cybersecurity, Estonia, NIS2

Organizations often lack the knowledge, experts and resources needed to meet cybersecurity requirements, ERR reports. Mari Seeba, who has studied cybersecurity assessments, said resistance to security requirements is usually not caused by bad intentions.

Although Estonia is among the world leaders in the range of digital services it offers, many organizations are still learning what cybersecurity means in practice and how to implement it.

The European Union’s NIS2 directive and Estonia’s Cybersecurity Act, which enforces its aims, require many organizations to assess cyber risks and introduce security measures. The requirements are intended to protect the digital state, the economy and critical services, but can seem like a complicated additional obligation.

According to Seeba, difficulties often begin with basic concepts. A threat is a potentially harmful event, such as a technical failure, human error or cyberattack. Risk depends on the specific organization, including the value of its data and services, the potential damage and the likelihood of the threat occurring.

“An abstract warning that an attacker could enter the network and cause damage may not yet prompt anyone to act,” Seeba said.

If an organization has never experienced a serious incident, cybersecurity may seem like a theoretical issue. Even simple measures can appear complicated. For example, encrypting a computer’s drive may in practice require only one selection during setup.

Seeba’s research found that resistance can be reduced when an organization gains a clear picture of its security level. When it sees that some measures are already in place, the question shifts from “Why do we have to do this?” to “How can we improve the situation?”

Framework assesses ten security areas

Seeba proposed a self-assessment framework called F4SLE, or the Framework for Security Level Evaluation. It provides an overview of how security measures are applied across ten areas, including information security management, the organization and personnel, incident management, infrastructure, networks, IT systems, applications and industrial automation.

Instead of checking every possible security measure, Seeba aimed to give organizations a clear overall view. The framework therefore uses 200 questions. The assessment shows which areas of security are stronger and where the biggest deficiencies lie. Organizations can compare their results with the average for similar organizations and use the findings to choose suitable improvements.

Because technology and attack methods change quickly, Seeba also developed the MUSE method. It helps update the assessment tool while keeping results collected in different years comparable. Instead of evaluating individual security measures, the method assesses broader security areas.

Trust remains a key issue

Seeba and her colleagues tested the F4SLE framework 284 times in small businesses in Estonia, the Czech Republic and Central America. The data was collected so that detailed responses remained on the organizations’ own computers.

Source 
(via ERR)