All posts

Lauri Tankler: Cybersecurity must become simpler, cheaper and more accessible

Estonia’s strong reputation in cybersecurity is both an advantage and a challenge for our companies. On the one hand, it opens doors. Estonia is associated with a digital state, cyber defence and practical technological capability. On the other hand, it sets a very high bar for anyone looking to bring a new cybersecurity product to market. When expectations are exceptionally high, a good idea or general technological ambition is no longer enough, writes Lauri Tankler, Head of Research and Development Coordination at the Estonian Information System Authority.

Cybersecurity is not a field that can be entered with a random application or a half-finished solution. From the outset, companies need to prove that their technology works, that it can be trusted and that it solves a real problem. This may be one reason why early-stage companies do not always dare to take the first step in this sector. Estonia’s reputation is strong, but for new entrants, that reputation can also act as pressure and as a filter.

The startups that have gone through the Cyber Accelerator so far have each been at very different stages of development. Some are working on artificial intelligence applications, some focus on educating people, while others are solving more specific technical problems. This diversity is necessary, because the challenges in cybersecurity are not uniform either. At the same time, it means that every team must find a very clear answer to one question: what risk are they reducing, and for whom?

Trust is difficult to earn in cybersecurity

One of the most difficult barriers is earning trust. In the cybersecurity market, purchasing decisions are usually not made by ordinary users, but by specialists who need to believe both in the technical quality of the solution and in the long-term viability of the provider. Unlike in many other sectors, it is not enough to rely on a good user experience or fast marketing. When a customer gives someone access to their systems, data or security processes, trust must be exceptionally strong.

In this environment, it is difficult for new entrants to compete with large and well-funded companies. Established players already have a name, a customer base, a sales network and the ability to hire experienced cybersecurity experts who may also be able to sell a new product to their former employers. A smaller company may be more flexible and technologically inventive, but it must first prove that it deserves a place in an already established market. In cybersecurity, that path to proof is often a long one.

A second, much larger bottleneck is Europe’s ability to bring research to market, a challenge highlighted in countless analysis papers. A great deal of research is also being done in cybersecurity, but its results do not reach the market often enough as products, patents, utility models or fast-growing companies. In the United States and in several Asian countries, cooperation between universities and companies is more forcefully geared towards creating commercial value. There, research results move more quickly into capital, products and exportable solutions.

In Europe, research funding has been carried more by the public sector. This has created a strong knowledge base, but not always a sufficiently strong bridge to the market. If research remains an article, a report or a pilot project, it may not make organisations safer in practice. In cybersecurity, however, time matters. Threats evolve quickly, and defensive solutions need to reach real-world use before they become yesterday’s answer.

The state cannot do everything on behalf of companies. Nor should the state keep every idea alive artificially. The market must have its say, and sometimes failure is a necessary part of entrepreneurship. But that does not mean the public sector can step aside. Every country supports the development and international visibility of its companies in one way or another. Estonia cannot afford to be naive in this competition, especially in a field where we already have strong experience and a strong reputation.

Estonia’s advantage lies in its small size and compact cybersecurity community. We know one another. In certain areas, such as ensuring information security, we should not always think only in terms of competition, but also in terms of how we can make one another stronger. The state can do a great deal here by helping to create functioning cooperation models between the public sector, companies and research institutions. Not declarative forms of cooperation, but models where problems, knowledge and solutions genuinely meet.

Cybersecurity must move from the experts’ back room to a much broader group of users

Cybersecurity strategy documents mostly, and inevitably, focus on public sector activities and the protection of critical infrastructure. That is understandable and necessary. But society’s cybersecurity does not end where the list of critical infrastructure ends. Smaller companies, educational institutions, local governments and people also need to become more secure. These organisations and individuals do not always need the most complex high-end solutions. They need something that is understandable, affordable and usable.

As long as cybersecurity is perceived as too complex and too expensive, it will remain a secondary obligation for many. The real goal should be the opposite: to make cybersecurity simpler, cheaper and more accessible. This does not mean compromising on quality. It means that good solutions must also be usable by those who do not have a large IT department, a dedicated cybersecurity manager or a significant budget.

This is where new startups and technologies have an important role to play. They can bring solutions to market that make complex risks easier to understand, automate manual processes or help smaller organisations reach a level of security that was previously available only to larger players. The next leap in cybersecurity may not come only from the most complex technology, but also from how well we are able to make security practically usable.

Estonia’s cybersecurity reputation is valuable, but it must not become a memory of past success. If we want Estonia to remain a strong cyber nation, new ideas must move from research labs, classrooms and early prototypes to real customers and users. This requires entrepreneurs who are willing to enter a difficult field, and an environment that helps them understand more quickly whether their solution also works in the market.

The Cyber Accelerator is one way to shorten that journey. It does not replace the market or make difficult decisions on behalf of entrepreneurs, but it helps bring together technology, experts, public sector experience and real problems. There is one final week left to apply, and this is an opportunity for those who have a product, service or strong idea in cybersecurity with clear market potential.

The question is not only how many new companies go through the accelerator. The question is whether Estonia can build, alongside its cybersecurity reputation, the next generation of solutions that genuinely make society safer. For that to happen, cybersecurity must move from the experts’ back room to a much broader group of users.

Developed by Ballers