When George Santayana said "Those who cannot remember the past are condemned to repeat it", I don't think he had digital government and cyber warfare in mind; after all, they weren't really hot topics at the turn of the 20th century. Nonetheless, with the UK government publishing its Blueprint for Modern Digital Government, I was reminded that this is a journey that our friends in Estonia have been on for some time.

Estonia first started building the infrastructure for its 'digital government and society' after it gained independence from the Soviet Union in 1991. In 1997, the country launched its first major digital initiative, the "Tiigrihüpe" (Tiger Leap) project, which focused on developing IT infrastructure and integrating technology into schools. By 2000, Estonia became one of the first countries to declare internet access a basic human right.

The introduction of e-Governance began in earnest in 2001 with the launch of the X-Road, a secure data exchange platform that allows government institutions and private-sector entities to share information seamlessly. In 2002, Estonia implemented digital ID cards, enabling citizens to access various e-services, including online voting, introduced in 2005.

Many of these advancements are echoed in the UK's blueprint for modern digital government. For example, the creation of a Digital Wallet to store government credentials and the introduction of a 'Digital Backbone' and 'National Data Library' to facilitate integration of multiple government services, simplify end-to-end customer journeys and make it easier to share information across the public sector.

The parallels don't stop there, however. In 2007, Estonia experienced one of the first large-scale cyberattacks attributed to a nation-state. These attacks, allegedly orchestrated by Russian actors, occurred during a political dispute over the relocation of a Soviet-era war memorial in Tallinn. The attacks disrupted government websites, banks, and media outlets, forcing Estonia to strengthen its cybersecurity infrastructure. This experience led Estonia to establish NATO's Cooperative Cyber Defence Centre of Excellence. More recently, Estonia also blamed pro-Russia groups for cyber attacks on their country in 2022 and 2023. Back in the UK, last year, customers' journeys were disrupted as the result of an attack against Transport for London. We also saw a cyber attack against Synnovis (a pathology testing supplier to the NHS) which led to more than 3,000 hospital and GP appointments being disrupted.

In 2025, then, the launch of a strategy to build a 'modern digital government' at the same time as there being reports of Russian ships targeting the UK's underwater cables and allegedly targeting us (and our European neighbours) in cyber attacks raised my eyebrows. And it's not just me that has concerns: a 2025 National Audit Office report raised concerns about the level of cyber risk that the UK public sector is facing. Similarly, a paper that supplements the Blueprint for Modern Digital Government notes that:

Despite prior funding for legacy remediation, organisations still report that high percentages of their services depend on unsupported, unpatched legacy technology systems: the count of the highest risk and most critical systems rose by 26% from 2023 to 2024 as organisations struggle to maintain focus on risk remediation alongside other priorities.

Most senior leaders don't get the training or preparation they need to run digital organisations. Most organisations do not have digital leaders on their executive committee. Linked to this, there is a skills shortfall; the remuneration offer and overall employee value proposition is not competitive with private industry.

Government is also carrying significant cyber and technology resilience risk. We have seen a number of high-profile incidents across the public sector that have had real world impacts on citizens' lives and incurred new costs to repair the damage done.

The UK does have a strategy in place to help to reduce these risks, and cyber security is featured within the Blueprint, but compared to Estonia, where cyber security is the third pillar of its 'vision and action plan to advance its economy, state, and society with digital technology', it is somewhat concerning that the topics of digital public services and cyber security are by and large being treated as separate issues. Furthermore, I see two other points that are worth pointing out:

What's clear, then, is that the two topics of digital public services and cyber security are closely linked. The more we rely on digital services, the more we raise the stakes (increase the potential impact of an incident) and thus the more stringent and robust we need to be in the way that we manage cyber risks.

From qualitative to quantitative

In the world of cyber security, risk management has been evolving from largely qualitative approaches to more quantitative methods. Traditionally, organisations made use of qualitative assessments, which relied upon subjective judgements, expert opinions, and high-level categorisations of risk (e.g. low, medium, high). While this approach provided a general sense of priorities, it lacked precision and often made it challenging to measure risk consistently across different domains or to justify investments in cybersecurity. In contrast, quantitative risk management makes more use of metrics and data to model cyber risks. Two methodologies have emerged as front runners: FAIR (Factor Analysis of Information Risk) and CyberVaR (Cyber Value at Risk). While they are undoubtedly a big improvement on qualitative methods, there are still difficulties in implementing them in the public sector.

The first is that these methodologies aim to communicate risk based on a dollar value. For the private sector this makes sense, and to a certain degree it does for the public sector too. After all, the public sector needs to prioritise what it spends its limited resources on and demonstrate that it is providing good value to the taxpayer. However, in the public sector, decision makers often need to prioritise resources to reduce potential risks such as economic damage, loss of citizen confidence in digital services and diplomatic incidents. This can be overcome by adapting quantitative risk assessment methodologies to include non-financial impacts. This, however, leads to the second challenge: availability of data to calculate these risks. While there are some fairly limited datasets in the public domain, much of it is held by threat intelligence companies, the insurance industry or hyper-scale technology companies, many of whom seek to monetise their data or guard it in the hope of gaining a competitive advantage. This challenge will be further compounded by adapting the risk assessment methodologies, as different datasets which aren't readily available might be needed in order to calculate the risk accurately.

Two things within government's gift

The good news is that both of these challenges are within government's gift to address.

The UK's approach to risk management, which is set out in the Orange Book, is already internationally recognised (though only formally adopted in the UK) and there is more specific guidance from the NCSC on managing cyber security risks. However, both of these sets of guidance stop short of recommending a specific risk assessment methodology. The first initiative would be to extend existing guidance to include a quantitative risk assessment approach for use across government, that includes assessing non-financial impacts.

The second initiative builds upon existing work to take a more 'interventionist' approach to cyber security, build a stronger cross-government data sharing capability, and existing mandatory breach disclosure legislation. It would require that departments, arm's length bodies and local authorities share data about security incidents and near misses so that it can be centrally compiled and reused to inform strategy and risk management.

For both initiatives, it is vital that the focus extends beyond central government to the wider public sector. This will help to ensure resilient end-to-end digital journeys that benefit all citizens, regardless of service provider, while getting the balance right between this and the government's many other challenges.