Cyberattack Cyber security
19.03 2026

A threefold increase in cyber incidents creates a pressing need for a Chief Information Security Officer

Over the past few years, the number of cyber incidents in Estonia has tripled, and this worrying trend is affecting every company. To protect themselves, organizations must address cybersecurity proactively and in a timely manner, take a systematic and holistic approach, and ensure they have competent information security leadership, says Mihkel Kukk, Head of Cybersecurity Services at KPMG.

In recent years, Estonian companies have made a massive leap in digitalization—cloud services, e-commerce, remote and hybrid work, automated supply chains. However, convenience and speed have brought an unpleasant reality: cyber incidents are no longer an exception, but an inevitability, with impacts measured in downtime, contractual penalties, reputational crises, and loss of customer trust.

Statistics from the Estonian Information System Authority show a clear year-on-year increase in cyber incidents: 3,314 impactful incidents were recorded in 2023, 6,515 in 2024, and the growth continued in 2025, reaching 10,185 incidents. At the same time, regulatory pressure is intensifying. From January 2026, amendments to Estonia’s Cybersecurity Act implementing the NIS2 directive came into force, expanding its scope to thousands of companies. In this situation, the question is no longer “do we need cybersecurity,” but “who leads it and how is it aligned with business objectives?”

This is where the CISO (Chief Information Security Officer) comes in. The role of a CISO is not “just another IT manager” or “the person who buys security software.” In a well-functioning organization, the CISO translates cybersecurity into an understandable management system: mapping risks, setting priorities, implementing controls, measuring their effectiveness, and providing management with a clear and regular overview of what is under control and what is not.

The core responsibility of an information security leader is to ensure the availability, integrity, and confidentiality of data and systems, and to manage both technical and organizational measures. This is not limited to digital data but also includes paper documents, verbal information, and processes. In other words, the CISO turns cybersecurity into a manageable and auditable capability, rather than a random “collection of projects.”

A cyberattack is no longer an IT issue, but a management issue

Why is it difficult to find a good CISO in Estonia? First, the role requires a mix of skills: strong technical expertise, understanding of business processes and supply chains, experience in managing people and change, and the ability to communicate at executive level. Second, the threat landscape is evolving faster than ever, as artificial intelligence makes attacks smarter and more scalable, while there is a global shortage of qualified specialists.

ERR Novaator has reported on a study by the Estonian Academy of Security Sciences, highlighting that the growing cyber threat is driven, among other factors, by rapid AI development and the shortage of cybersecurity professionals. Third, there are few professionals who meet CISO requirements, and competition is intense: banking, healthcare, telecoms, large tech firms, and the public sector all need the same expertise. Fourth, companies do not hire a CISO only for today—they also take on the responsibility to keep capabilities up to date, requiring continuous training, certification, and updating of practices.

If the CISO position is unfilled, a vacuum emerges: there is no central leader or competent decision-maker for cybersecurity issues, and responsibilities become fragmented. The result is a classic “no one is truly accountable” situation—exactly what attackers exploit. A practical example is invoice fraud, where attackers breach an email account, wait for the right moment, and alter bank account details on an invoice. The damage does not arise from the “hack” itself, but from missing controls and weak processes. This is why the Estonian Information System Authority clearly states: cyberattacks are no longer just IT problems—they are management issues.

This is where CISO-as-a-Service (CISOaaS) becomes a practical solution. If a company cannot find—or does not find it economically reasonable to hire—a full-time top-level CISO, it can source this capability as a service and quickly establish governance without lengthy recruitment. The service provides access to experienced professionals and certified expertise, and instead of relying on a single individual, it leverages a full team covering various roles and skills (e.g. security management, system administration, penetration testing, digital forensics). This model is especially suitable for small and medium-sized enterprises and growing companies, but also for larger organizations that need temporary coverage (e.g. during a CISO transition), support for specific programs (ISMS, risk management, supply chain security), or executive-level translation of cybersecurity into business terms.

In practice, CISOaaS means that cybersecurity management becomes structured. It starts with mapping the current situation and risk landscape, defining objectives and an action plan, assigning responsibilities, establishing metrics, and implementing critical controls. At the same time, management gains assurance that decisions are consistent and well-informed—whether the focus is on complying with NIS2 requirements in Estonia or DORA regulation in the financial sector, which took effect on January 17, 2025. Clear expectations are also set for digital resilience and ICT risk management.

The end result is not “more documents,” but better preparedness and a lower likelihood that one wrong click or an unpatched vulnerability will lead to downtime, a data breach crisis, or costly recovery.

Mihkel Kukk

Cybersecurity Strategic Advisor

Neglecting cybersecurity can cause forced downtime and give competitors an advantage

Organizations can no longer view cyber risk as a separate issue; it is an integral part of the b..

Cyber security

KPMG: A properly selected information security standard serves as a quality mark for partners

Companies that rely on external service providers for data processing increasingly face a key que..

Cyber security

For a small business, a cyber incident can cost nearly €13,000 per day

Friday evenings, weekends, and holiday periods are the most attractive times to carry out cybera..

Cyber security Cyberattack

Why Purple Teaming is the Missing Link in Modern Cybersecurity

In today’s cybersecurity landscape, most organizations are caught between two realities: they kn..

Cyber security

Reflections from the Field - A Red Team’s Perspective on Cybersecurity in Estonia

Over the past several years, our red team has conducted extensive offensive security assessments..

Provide a safe and sustainable business environment for your company. We help build a resilient and reliable digital landscape, even in the face of changing threats.

KPMG Baltics OÜ

+372 626 8700
cyber@kpmg.ee
Ahtri 4, 10151 Tallinn, Estonia
${item.title}
KPMG Baltics KPMG Global Privacy KPMG IT Audit
Email again:

Analysis of employee awareness

Analysis of employee awareness focuses on mapping the skills and increasing the competencies of the weakest link in cyber security: the users, the employees.

Email again:

Threat assessment

Threat assessment is a tactical and technical service that allows a company to get a quick overview of external threats.

Email again:

Maturity assessment

Maturity assessment helps plan IT investments and design further steps to mitigate vulnerabilities and ensure better security.

Email again: