In May 2026, the Tallinn Mechanism Project Office (TMPO), together with the European Cyber Security Organisation (ECSO), the European External Action Service (EEAS), GIZ, the German Federal Foreign Office, and the European Commission, organised the first in-person event for the private sector under the Tallinn Mechanism framework. Held in Brussels, the event brought together more than 70 representatives of the Ukrainian and European cybersecurity community, international organisations, donors, and Ukrainian government institutions.
This event marked an important milestone. It showed how the Tallinn Mechanism in three years has evolved from an initial ambitious idea into a framework where governments and industry work together on real cyber resilience solutions for Ukraine.
How it started
Ukraine has been facing massive Russian cyberattacks since 2014. For more than a decade, the country has remained on the frontline of cyber aggression, with attacks steadily increasing in scale and complexity.
The full-scale invasion in 2022 made this even more visible. Cyberattacks became an integrated part of military operations. February to April 2022 marked a peak period. On 15 February, one of the most powerful DDoS attacks in Ukraine’s history targeted 15 banks, as well as government and defence websites. Just days later, another wave hit financial and public sector resources again. Energy infrastructure became another key target, especially around 23 and 24 February, when Ukraine was synchronising its power grid with the European ENTSO-E network.
In total, around 2,100 cyber incidents were recorded in the first year of the full-scale invasion, according to CERT-UA. At the same time, according to the Microsoft Digital Defense Report, Ukraine consistently ranks among the top countries affected by state-sponsored cyber threats. Cyberattacks were often synchronised with information operations.
Under these conditions, international support for Ukraine in cybersecurity became critical. Even before 2023, Ukraine actively cooperated with international partners. However, this cooperation was fragmented. It was mostly based on individual projects, separate donor programmes, international interagency cooperation, or bilateral agreements.
A system is what was missing. A structure that could bring priorities together, reduce duplication, and make support more predictable and strategic. This new approach also needed transparent project evaluation and clear funding procedures. This idea became the foundation of the Tallinn Mechanism.
The first challenges
In May 2023, the Ministries of Foreign Affairs of Ukraine, Canada, Denmark, France, Germany, the Netherlands, Poland, Sweden, the United Kingdom, and the United States Department of State (DoS), at the initiative of the Estonian Ministry of Foreign Affairs, agreed to establish a coordinated international initiative for cyber support to Ukraine. The Tallinn Mechanism was officially launched in December 2023.
From the very beginning, the Tallinn Mechanism focused on strengthening cyber defence and cyber resilience, as well as developing Ukraine’s civilian cyber capabilities. A systematic approach is the main feature that distinguishes the Tallinn Mechanism from other similar formats of international assistance.
One of the first challenges that emerged at that time was practical: how to translate Ukraine’s national cybersecurity needs into donor-ready projects. Cybersecurity is a sensitive domain. Not all details can be shared publicly, especially during wartime. At the same time, donors need clarity, structure, and transparency.
Another key principle was (and still is) – “nothing about Ukraine without Ukraine.” Priorities in cyber had to be defined jointly by all key national cyber stakeholders, ensuring that only the most relevant projects reach international partners.
Over time, a structured selection process was introduced. Projects submitted by Ukrainian beneficiaries go through technical review and then strategic review. This ensures that proposals are both feasible and aligned with national priorities before being presented to donors.
To support this process, two working groups were created. The Technical Working Group (TWG) assesses feasibility, technical quality, and relevance. The Interagency Working Group (IWG) includes representatives of a wide range of government bodies and reviews strategic importance and alignment with national cyber priorities.
In June 2024, this system was strengthened with the launch of the Catalog – a digital portal that allows structured submission, verification, and selection of cyber projects. This was an important step forward. It brought more transparency and consistency into a highly complex domain.
Overcoming the gap: the need for TMPO
Once the system was in place, another challenge appeared. This model ensured accountability, but it also created multiple coordination layers.
After a project is selected from the Catalog, donor countries need to choose whether and how to support it. Ukrainian authorities do not manage project funds directly. To manage procurements and implement the projects, Tallinn Mechanism donors are working with their development agencies and implementing partners such as Sida, Norad, HAUS, ESTDEV, DAI, Expertise France, GIZ, and CRDF.
However, this multi-step structure created delays. By early 2025, many projects were approved, donors were ready to fund them, but the implementation process was slow. There was a clear coordination gap between donors, Ukrainian stakeholders, and implementing partners.
To address this issue, the Ministry of Digital Transformation of Ukraine initiated the launch of the Tallinn Mechanism Project Office (TMPO) in May 2025.
TMPO acts as a coordination hub between:
- international partners (Tallinn Mechanism donor countries)
- Ukrainian governmental counterparts (Ministry of Foreign Affairs, Ministry of Digital Transformation, State Service of Special Communications, Security Service of Ukraine, and National Cyber Security Coordination Center)
- and Ukrainian recipients (government institutions and critical infrastructure operators)
In its first year, TMPO has already supported tangible delivery. Seven cyber projects have been completed with funding from Canada, the Netherlands, and the United Kingdom, with a total value of more than 300 million UAH (nearly 6 million euros).
The list of Ukrainian beneficiaries includes key state institutions and critical infrastructure operators such as the Chornobyl Nuclear Power Plant, the National Security and Defence Council, the Cabinet of Ministers Secretariat, the State Border Guard Service, and others.
More than 20 projects are currently in implementation. These are supported by Sweden, Italy, Norway, the United Kingdom, Germany, the Netherlands, and Estonia. Around 70 additional projects are under donor review.
Tallinn Mechanism Platform
As of May 2026, the Tallinn Mechanism includes 14 Member States. The EU, NATO, and the World Bank participate as official observers. However, from the beginning, the Tallinn Mechanism was designed not only to respond to urgent cyber needs, but also to build long-term resilience.
Its mission is built around three lines of effort:
- Support (short-term): immediate cyber assistance and incident response.
- Build (medium-term): sustainable cybersecurity solutions, workforce development, and public-private partnerships.
- Sustain (long-term): long-term resilience, innovation, and research.
How can public-private cooperation be effectively incorporated under the Tallinn Mechanism framework? That became another major challenge for TMPO. Cybersecurity companies are key actors in resilience building, innovation, and incident response. This understanding led to a new stage in the evolution of the initiative: the development of the Tallinn Mechanism Platform.
The main goal of the Platform was to create a web resource that helps potential partners and a wider audience better understand the Tallinn Mechanism and engage with its activities. In particular, on the Platform, the private sector can explore current tenders, procurements, and cooperation opportunities. It also supports matchmaking between verified companies and encourages joint participation in projects.
In its first three months, more than 150 companies from 19 countries registered on the Platform. For a relatively new initiative, this signals strong interest from the global cybersecurity market.
This year alone, TMPO has already presented the Tallinn Mechanism and the Platform in 12 webinars for the cybersecurity community across Ukraine, Norway, Canada, Poland, the United Kingdom, the Netherlands, Germany, France, and the United States.
This brings us back to where this article began: in May 2026, the Tallinn Mechanism Project Office (TMPO), together with the European Cyber Security Organisation (ECSO), the European External Action Service (EEAS), GIZ, the German Federal Foreign Office, and the European Commission, organised the first in-person event for the private sector under the Tallinn Mechanism framework. Held in Brussels, the event brought together more than 70 representatives of the Ukrainian and European cybersecurity community, international organisations, donors, and Ukrainian government institutions to share insights, discuss opportunities, and build cyber resilience together.
In three years, the Tallinn Mechanism has evolved significantly. What started as a response to urgent cyber threats has become a structured international initiative for cyber resilience. It connects governments, donors, implementing partners, and, now increasingly, the private sector. It is not a single programme or a set of isolated projects. It is an evolving system. And perhaps its most important shift is this: cyber resilience is no longer treated only as a government responsibility. It is becoming a shared effort, built through partnerships, expertise, and long-term cooperation.