Riigi Infosüsteemi Amet // Estonian Information System Authority (NCSC-EE)

Riigi Infosüsteemi Amet // Estonian Information System Authority (NCSC-EE)

Speciality: Web Application Security

Tallinn, Estonia 200 employees
[01] About

Estonian government IT and cybersecurity agency with 141 employees; provides digital identity, security systems, and pentesting services; 6.4% YoY growth; based in Tallinn, Estonia; known for manual WebApp pentesting, PTES methodology, and automated testing via CyberTested.

Oleme riiklik kompetentsikeskus, kes kujundab ja kindlustab Eesti infoühiskonna alustalasid: arendame ja haldame e-riigi keskseid taristuteenuseid ning tagame riigi küberturvalisuse. Ühtlasi tegutseme Euroopa Liidu struktuuritoetuste rakendusüksusena ja korraldame e-riigi IKT projektide rahastamist ELi struktuuritoetustest. Haldame ja kaitseme riigi internetivõrku ning hoolitseme turvaliste e-valimiste eest. Seisame selle eest, et Eesti digitaalne identiteet oleks jätkusuutlik ning leiaks laialdast kasutamist üle maailma. Viime riigiportaali eesti.ee haldamisega olulise riiki puudutava info inimese juurde. 🇬🇧 We manage and protect the state Internet network and ensure secure e-elections. We aim for a sustainable digital identity of Estonia and its wide use around the world. By managing the State Portal eesti.ee, we deliver citizens important information regarding the state. The reliability and development of the digital state depend on us. We increase confidence in the state and its services.
[02] Services
Penetration Testing
Cybersecurity Services
E-government Infrastructure Management
Cyber Incident Handling
Security Awareness And Training
Vulnerability Assessment
Automated Penetration Testing
Dark Web Monitoring
[03] Certifications
ISO/IEC 27001

ISO/IEC 27001: Information Security Management System Certification


Origin


ISO/IEC 27001 was developed jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), first published in 2005 and most recently updated in 2022. It evolved from the British Standard BS 7799, which was created in the 1990s by the UK government and industry experts to address growing information security concerns. The standard was developed to provide organizations with a systematic framework for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS), helping them protect sensitive data in an increasingly digital business environment.


Industry Value and Importance


ISO/IEC 27001 is globally recognized as the gold standard for information security management, valued because it demonstrates an organization's commitment to protecting confidential information through risk-based controls and continuous improvement. The certification is particularly important for organizations handling sensitive data, as it helps them comply with legal and regulatory requirements, win contracts (especially with government entities and large enterprises), and build customer trust. Many industries require or strongly prefer vendors with ISO 27001 certification, as it provides independent verification that appropriate security controls are in place, reducing the risk of data breaches and ensuring business continuity in the face of evolving cybersecurity threats.

E-ITS (estonian Information Security Standard)
[05] Notable Clients
  • Estonian government ministries
  • Estonian public sector entities