Research // Agenda

Cyber-Resilience Under Isolation

How do states and organizations that are cut off — by sanctions, by isolation, by infrastructure failure — build cyber-resilience, when they can't lean on the frameworks, vendors, and cooperation channels everyone else takes for granted?

Most of the world's cybersecurity guidance quietly assumes a connected, cooperating country: you can buy the tooling, join the information-sharing bodies, call the vendor, adopt the framework. Remove those assumptions and the guidance doesn't degrade gracefully — much of it simply stops applying. Yet hundreds of millions of people live and work behind exactly those removed assumptions. Their infrastructure still gets attacked. Someone still has to defend it.

Why me, why this

This agenda isn't academic curiosity — it grew out of lived facts. My bachelor's thesis at Tallinn University of Technology examined VPN solutions for peer-to-peer content delivery under the network restrictions of the Iranian internet, including fieldwork interviewing people who depended on those workarounds to reach their own families. Later, I experienced national-scale internet shutdowns from the inside, running a consulting practice through them. And my current MA in International Relations gives the regional and institutional lens the technical training alone never provided. I can study this question honestly because I have lived on both sides of it: as the engineer defending systems, and as the user cut off from them.

The research strands

1. Comparative resilience models. How do isolated states (Iran and North Korea are the sharpest contrasts) actually organize cyber-defense — institutionally, technically, economically — compared with states embedded in OECD/EU frameworks? What substitutes emerge for the cooperation channels they can't access, and at what cost?

2. Shutdowns as governance failure. National internet shutdowns studied as an infrastructure governance problem: what breaks first, what recovers slowest, what institutional capacity determines whether digital trust can be rebuilt afterward. Analytical, not political — the unit of study is the system, not the regime.

3. CSIRT and incident-response capacity-building. What is the minimum viable national incident-response capability, and how have states outside the wealthy-country club actually built one? Ghana's decade of CSIRT build-out is a leading case worth close study.

4. Sanctions and the security supply chain. What happens to patching, tooling, threat intelligence, and cloud dependence when a country's defenders are cut off from the commercial security market — and what do the workarounds teach everyone else about resilience without dependence?

Method and stance

Comparative case study grounded in primary sources and, where safely possible, practitioner interviews — the same method as my thesis fieldwork. Two standing rules: every piece stays policy-analytical (systems and institutions, never personal political activity — mine or anyone else's), and every claim is verifiable or explicitly flagged as open. Resilience-under-constraint is not an endorsement of the constraint.

Where this is heading

I intend to develop this agenda into a graduate thesis in public policy: how states under sanctions or international isolation build cyber-resilience differently from states that can lean on OECD or EU frameworks. The longer arc is practical, not just scholarly — advising public institutions on infrastructure resilience, helping build the incident-response capacity my region still lacks, and keeping digital literacy flowing to the people who suffer first when governance fails.

Related writing on this site

The blog develops these strands in public, deliberately in the open, piece by piece — starting with Why Isolated States Build Cyber-Resilience Differently, and continuing through the governance and region-focused series. If you research adjacent questions — shutdowns, CIIP frameworks, CSIRT capacity, digital sovereignty — I'd genuinely like to compare notes.