Estonia, state as infrastructure¶
Estonia, and cyber power when the state itself becomes an information system
Estonia comes labelled twice over. There is the e-government showcase: digital identity for nearly everyone, voting from a laptop, a state that runs online. And there is the victim of 2007, the country knocked offline by Russian-aligned denial-of-service and later called the site of the first cyberwar. Both are true, and both miss what Estonia has actually been doing, which is running a long experiment in making the state itself into an information system, so that the state’s continuity becomes a cyber question. Estonia does not so much have cyber capability as it is, increasingly, cyber infrastructure.
Cyber power is usually pointed outward, at someone else’s systems. Here the direction reverses: the state runs on its own digital systems so completely that a threat to those systems is a threat to its ability to exist. The boundary this dissolves is the one between the state and the infrastructure it runs on. They have become the same object.
Two memories¶
The substrate is two memories, one recent and one old. The recent one is 2007: after Estonia moved a Soviet war memorial, weeks of denial-of-service attacks took down government, bank and media sites, and cyber-resilience entered the national self-conception. The older memory is 1940, when the Soviet Union occupied and annexed Estonia and the state disappeared for half a century, surviving only as a claim of legal continuity kept alive from abroad. The fear that organises Estonian security is therefore not only attack but annexation, the loss of the ground itself. The question underneath the apparatus is how a small state on Russia’s border makes sure that next time, even if the territory is taken, the state is not.
The state built as software¶
Rebuilt from nothing after 1991, with no legacy systems to preserve, Estonia constructed the state digitally. A near-universal digital identity gives every citizen a cryptographic key to the state; X-Road is the exchange layer that lets the country’s registries talk to one another; and the great majority of public services run online, signatures, taxes, health records, voting. The state was not digitised after the fact. It was, to an unusual degree, designed as software from the start.
The state that can be restarted¶
If the state runs as data, the data can be copied, and a state can be backed up. Estonia’s data embassy in Luxembourg, established under a 2017 agreement, holds a copy of critical state registries on servers that remain Estonian state property, the data itself Estonian state archives, with an immunity modelled on the Vienna Convention but granted by the treaty itself, so that the running state could in principle continue from the copy even if its home data centres were lost. It is exile rebuilt as a technical fact: not a government on foreign soil but the state’s databases, kept alive and sovereign abroad. Continuity of statehood moved from constitutional doctrine into a data centre abroad.
When a chip flaw is a crisis¶
The same move that makes the state resilient makes it attackable, and 2017 showed how completely. A cryptographic weakness in the chips used in Estonian ID-cards, the ROCA vulnerability, put the keys of around 800,000 cards at risk, and Estonia responded by suspending the affected certificates and re-keying the cards remotely. A flaw in a component became a matter for the state rather than for a vendor, because the component was the citizen’s link to the state. Seen as effects, occupation memory drives the digitalisation of the state; the digital state is restorable, which yields resilience and standing; and the standing funds more of it, a loop that reinforces. Off it hangs a grey branch that is the price of the same move: the more the state is data, the larger the surface on which it can be attacked, and the more a breach becomes an attack on the state as such. The resilience and the exposure are one decision seen from two sides.
The copy is untested¶
The restorable state has never been restored. The data embassy holds registries; no government has run a country from a backup. A state is not only its records but its people, its officials, its capacity to compel, and a restored database is not a restored state. Digital continuity is, so far, a well-built hypothesis, exercised but never used.
Doctrine as export¶
Estonia turned its experience into more than its own defences. The NATO Cooperative Cyber Defence Centre of Excellence, stood up in Tallinn the year after 2007, hosts the alliance’s cyber-defence research and the annual Locked Shields exercise, and convened the Tallinn Manual, the reference work on how international law applies to cyber operations. The capability here is partly Estonian and partly not: a centre accredited by NATO, a manual written by an international panel, housed at an Estonian address. The actor dissolves, and the doctrine Estonia is best known for exporting is doctrine about a domain no single state owns.
Lithuania sits inside this arrangement too. It was one of the seven founding nations of the CCDCOE in 2008, so the centre Estonia hosts is partly Lithuania’s. Seen from Tallinn, that is a mesh: two exposed Baltic states turning exposure into multinational cyber institutions housed at a national address, the capability they build belonging to more than themselves. The actor dissolves the same way twice.
The line worn away¶
A state usually keeps some line between itself and the capability it uses, whether it owns, borrows, tolerates or distributes it. Estonia has worn that line away from the inside. The state and its infrastructure are one object now, resilient and exposed in the same breath, restorable in theory and never yet restored. It is the strangest answer to where cyber power resides, because the answer is no longer beside the state or inside it. It is the state. And once the state has become an information system, the next line to go is the one between the system and the war fought through it.