Minimum Viable Cyber Governance

Startup people talk about the minimum viable product: the smallest version of a thing that actually works, built before you invest in polish. I want to apply that idea to something much bigger — national cyber governance.

Here is the problem it solves. International bodies produce excellent cyber-governance frameworks. They are written by and for states with mature regulators, deep budgets, and functioning public-private trust. When a state without those foundations tries to adopt one, the framework does not fail loudly. It gets transposed into law, reported on, and quietly ignored, because the machinery it assumes does not exist.

So the useful question for most of the world is not "which framework should we adopt?" It is "what is the minimum stack that must exist before any framework is even transferable?"

My answer is four things. Not forty. Four.

1. An accountable agency

Somebody has to own the problem. One named institution with cybersecurity in its mandate, a director who can be summoned and held to account, and the standing to convene other ministries.

Without this, cyber policy is an orphan. Every ministry touches it — telecoms, interior, defense, finance — so no ministry owns it, and in a crisis the first hour is spent discovering that fact.

The agency does not need to be large. It needs to be findable. When something national-scale happens, everyone from a bank CISO to a foreign counterpart should know, without research, whose phone rings.

I made the same argument at institutional scale in my piece on CSIRT capacity building: capability without an accountable institution around it evaporates. The national CSIRT itself — explained here if the term is new to you — usually lives inside or beside this agency. Agency first, team second.

2. A strategy short enough to be read

Most national cyber strategies are long documents that commit to everything and assign nothing. They are written to be launched, not used.

The minimum viable strategy fits in a few pages and does exactly three jobs. It names priorities — which sectors and risks come first, which explicitly wait. It assigns responsibilities — which institution does what, by name. And it states how progress will be judged, even crudely.

I learned this at a much smaller scale. When I co-founded a software startup in Estonia, I wrote our information security policy from scratch. The first draft imitated the big templates and ran long. The version that actually changed behavior was short, and its only real content was names: who owns patching, who approves access, who gets woken up. A strategy is a routing table for responsibility. Everything else is preamble.

If drafting one, write it in language a minister can repeat without notes. My plain-language glossary for policymakers exists precisely because strategies written in vendor English get signed but not understood — and unread strategies govern nothing.

3. A recurring budget line

Not a donor grant. Not a one-time capital allocation. A line in the ordinary national budget that recurs.

This is the least glamorous item and the most predictive one. Grant-funded capacity has a shape everyone in this field has seen: equipment arrives, training happens, the project ends, salaries stall, people leave, and three years later the capability exists only in the closing report.

The recurring line can start small. Its purpose in the minimum viable stack is less about the amount than about what it structurally guarantees: salaries that survive the political cycle, and the boring continuities — renewals, memberships, exercises — that capability actually consists of. A state that cannot commit recurring money is not yet ready to absorb any framework, and no framework fixes that.

4. A legal basis

The minimum here is narrow. Two authorities in actual law, not circulars:

First, the national incident-response function's right to receive incident reports and to coordinate across government and, where designated, critical-infrastructure operators. Second, a definition of what counts as critical infrastructure, so obligations attach to someone specific.

That is enough to start. Data-protection regimes, cybercrime statutes, certification schemes — all valuable, all later. The trap is drafting the comprehensive law first, which routinely consumes years while nothing operational exists. A two-page decree that lets the CERT lawfully do its job this year beats a landmark act in three years.

The 80/20 claim

My honest estimate — held with practitioner confidence, not academic proof — is that these four items are the twenty percent of national cyber governance that produces most of the outcome. A state with an accountable agency, a readable strategy, recurring money, and a narrow legal basis will muddle through incidents adequately even with modest technical maturity. A state with none of them will fail even with excellent engineers, because in a crisis the engineers will not know who is in charge, what they may lawfully do, or who pays them next quarter.

MINIMUM VIABLE CYBER GOVERNANCE — FOUR THINGS THAT MUST EXIST

   +---------------------------------------------------+
   | (4)  A LEGAL BASIS        powers, duties, limits  |
   +---------------------------------------------------+
   | (3)  A RECURRING BUDGET   money that comes back   |
   +---------------------------------------------------+
   | (2)  A SHORT STRATEGY     read in one sitting     |
   +---------------------------------------------------+
   | (1)  ACCOUNTABLE AGENCY   someone clearly owns it |
   +---------------------------------------------------+
     remove any layer and the ones above it wobble
Four layers that must exist before richer OECD/EU-style regulation can transfer.

The corollary matters just as much: sophisticated regulation transfers onto this stack, and only onto this stack. An EU-style regime assumes a regulator that can supervise, a legal system that can sanction, and operators who can absorb compliance costs. Adopted on top of the four foundations, such regimes have something to grip. Adopted instead of them, they become what I would call paper convergence — laws that mirror European texts while daily practice mirrors nothing.

Where this goes next

This piece deliberately stayed at the foundation layer. The obvious next question is what happens above it: when a state does reach for the international frameworks — OECD recommendations, EU directives, African Union instruments — what does each of them silently assume about the state adopting it? The assumptions differ more than the texts do, and reading frameworks through that lens changes which one you would recommend to whom. I'll return to this.


OWASP Top 10, Five Years Later →

← All writeups