- InfoSec Blog
- VEITS E-ITS or primary security measures
March 14, 2026
VEITS E-ITS or primary security measures
Primary security measures are the minimum level of cybersecurity for smaller organizations. It is a reasonable compromise that creates a reasonable and proportionate baseline and helps organizations get started with cybersecurity in a conscious way. Security is not a goal in itself, but a prerequisite for reliable and uninterrupted operation.
Primary security measures are clear and practical requirements prepared by the Estonian Information System Authority (RIA) to help smaller organizations ensure basic protection of their information systems in an understandable manner and to an appropriate extent. They are aimed primarily at micro and small enterprises subject to the Cybersecurity Act (KÜTS) and local government-administered institutions with fewer than 50 employees.
The nature of primary security measures
Primary security measures focus on basic protection – ensuring that an organization's critical information systems are protected from the most common threats.
If basic protection is not enough or the organization's risk level increases, E-ITS measures or controls from the international ISO/IEC 27001 standard must be implemented. We discuss the differences between these two approaches separately in this blog post: ISO/IEC 27001 or E-ITS: which information security standard should you prefer?.
Primary security measures are mandatory for all service providers specified in the Cybersecurity Act, regardless of their field of activity. The requirements apply to both family medical centers and providers of vital services, provided that the organization meets the criteria for a micro or small enterprise.
General education schools must continue to comply with the E-ITS or ISO/IEC 27001 standard. However, they are exempt from the obligation to order an audit if they are not the controller or processor of the database. However, if sensitive personal data is processed on a large scale, basic security measures are no longer sufficient.
Risk-based approach and flexibility
The Primary Security Measures Regulation gives organisations significant flexibility. They are allowed to implement equivalent risk reduction measures and certain measures do not have to be implemented if they are not appropriate or practically feasible – provided that the organisation is aware of the risks involved.
This means that the goal is not simply "checking the boxes", but an informed and meaningful organization of information security.
Implementation and monitoring of primary security measures
Primary security measures are formulated in an outcome-oriented manner, rather than as step-by-step instructions. This gives organizations the freedom to achieve the required outcome in a way that suits them.
It is important to understand that this is not a one-time project, but an ongoing process. The organization must learn from experience and adapt its actions to changing risks and needs.
However, implementing basic security measures does not reduce an organization's liability. Failure to implement measures constitutes a violation of the law and may sooner or later result in a cyber incident, work interruption, and reputational or financial damage.
Critical information security topics by field
Information security organization
The information security organization creates the basis for the rest of the system. The organization must have clearly defined roles and responsibilities – who deals with information security on a daily basis, who makes decisions and how problems are escalated. In a smaller organization, this does not mean a complex management model, but rather a clear and practical agreement on how information security issues are dealt with on a daily basis. It is important that information security management does not remain a formality, but is understandable and applicable in everyday work.
User awareness and training
User awareness is one of the most critical components of information security, as a large part of the risks are related to human behavior. Therefore, one-time training is not enough, but a consistent and systematic approach is necessary. Employees must be given simple and understandable instructions and reminded of them regularly. A working solution is, for example, a practical user manual with daily rules of conduct and a continuous cycle of notifications and training.
Data security
Data security starts with an awareness of what data is processed in an organization and how critical it is. It is important to look at the entire life cycle of data – from creation and use to archiving and deletion. This includes data retention, sharing, backup and secure destruction. Well-designed data handling significantly reduces the risk of both accidental errors and malicious activities.
Suppliers and external service providers
Using external service providers is common these days, but it also comes with additional risks. Any new service or partner should undergo at least a simplified risk assessment and be clear about what requirements are placed on the supplier. It is equally important to regularly review or monitor existing partners to ensure they are meeting the organization’s expectations and security requirements.
Incident management
No organization is completely immune to incidents, so it’s important to be prepared to respond. Employees need to know how to recognize a security incident and who to report it to. A clear and consistent action logic—from detection to resolution and lessons learned—helps minimize damage and accelerate recovery.
Cloud services and web applications
Cloud services and web applications have become everyday tools, but their use requires a conscious approach. It is important to define simple rules for selecting services, managing user accounts, and controlling access. Well-organized access management helps prevent situations where data or systems are available to the wrong people.
Security of IT equipment and systems
The security of IT devices and systems covers their entire life cycle – from deployment to decommissioning. The goal is to ensure that devices are properly managed, up-to-date, and protected from loss and misuse. Well-thought-out device management significantly reduces everyday security risks.
Communications and network security
Secure and reliable communications are the foundation of an organization's operations, both in the office and remotely. It is important to ensure that network connections are adequately protected and that employees have clear instructions on, for example, using WiFi and working remotely. This avoids situations where security vulnerabilities arise in everyday work practices.
Physical security
Although the focus is often on digital security, the role of physical security should not be underestimated. Controlling premises, devices and access helps prevent situations where data or devices fall into the hands of unauthorized persons. Clean desktop policy. Physical security is an important part of a comprehensive information security approach.