Skip to content
The ColumnOp-Ed· No. 2018

OPEN LETTER: Rome takes over from London — Italy leads Ukraine's cyber defense

The Tallinn Mechanism is not a line in the NATO budget. It is a voluntary construction — countries individually deciding to contribute to something no one was required to create. That is precisely why

Premium reading
MadMax
Key takeaways
  1. The Tallinn Mechanism is not a line in the NATO budget. It is a voluntary construction — countries individually deciding to contribute to something no one was required to create. That is precisely why
  2. Introduction: A presidency changes hands, a war goes on
  3. July 1, 2026 in Kyiv and Rome
Transparency

Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.

Introduction: A presidency changes hands, a war goes on

July 1, 2026 in Kyiv and Rome

To my European partners and NATO allies, I want to name something happening in the shadow of the headlines about missiles, drones, and diplomatic negotiations. On July 1, 2026, Italy assumed the presidency of the Tallinn Mechanism — the principal international coordination framework for support to Ukraine's cyber defense. It succeeds the United Kingdom, which held this presidency since the mechanism's creation in December 2023. With this transfer of responsibility, Italy also announced an additional contribution of one million euros, bringing the total Italian contribution to two million euros — approximately 2.28 million U.S. dollars.

This letter is not addressed to the Italian public, even though it deserves to know. It is addressed to each of the 14 partner countries of the Tallinn Mechanism: the United States, Germany, France, the United Kingdom, Canada, Norway, Sweden, and the other members. The question is not whether Italy deserves congratulations. The question is whether this mechanism, created two and a half years ago, is receiving the resources demanded by a war fought as much on servers as on front lines.

A 14-country mechanism built on collective will

The Tallinn Mechanism currently brings together 14 partner countries — including the United States, Germany, France, the United Kingdom, Canada, Norway, Sweden, and several other allies. Its structure is voluntary: no treaty compels it, no automatic clause sustains it. Every contribution is a national political decision. This voluntary nature is both its strength — every contribution is a deliberate choice — and its weakness, because it depends on the continuity of political will in each member state.

Since its creation in December 2023, the mechanism has enabled coordinating substantial assistance to several key Ukrainian institutions. Its very existence reflects a realization — late but real — that the war in Ukraine is also fought in the digital domain, and that this dimension requires a response as coordinated as conventional military aid.

What the Tallinn Mechanism is — and why it exists

A cyber support architecture born of necessity

The Tallinn Mechanism was created in December 2023, at the initiative of the Baltic and Nordic countries, to coordinate international assistance to Ukraine's cyber defense. Ukraine is the world's most targeted state by state-sponsored cyberattacks since the Russian invasion began in 2022. Government infrastructure, military communication systems, energy networks, and civilian databases are regularly targeted by actors linked to Russian intelligence services — notably the GRU and the FSB. The mechanism aims to coordinate the technical, human, and financial assistance of partners so that these efforts are complementary rather than redundant.

The choice of the name "Tallinn" is not incidental. The Estonian capital has been one of the world's centers of cyber defense expertise for years — notably through the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE), based there since 2008. Estonia, which suffered the first major state cyberattack in history in 2007 — attributed to Russia — has developed unique expertise and sensitivity on the issue. Naming the mechanism after this city is to inscribe the initiative in a history of European cyber resistance.

What the United Kingdom accomplished during its presidency

A concrete British track record

Before discussing what Italy will do, we must acknowledge what the United Kingdom accomplished during its presidency of the Tallinn Mechanism. London directly funded initiatives within the Ukrainian Ministry of Foreign Affairs, the State Service of Special Communications, and the Border Guard — institutions whose systems are priority targets for Russian cyberattacks. The United Kingdom also launched the CYFER project in partnership with the Netherlands and the Czech Republic — a program for strengthening institutional-level cyber defense capabilities.

In total, the United Kingdom funded or co-funded seven distinct initiatives within the framework of the mechanism during its presidency. This number says something important: the British presidency was not a symbolic one. It was operational. It produced verifiable results on the ground — reinforced systems, trained personnel, established protocols. That is the minimum standard that the mechanism's partners should expect from every presidency.

The CYFER project: a model for multilateral cooperation

The CYFER project, launched by the United Kingdom in partnership with the Netherlands and the Czech Republic, deserves particular attention. It illustrates how the presidency of a mechanism can catalyze additional bilateral partnerships that might otherwise have taken longer to materialize without this structuring framework. CYFER is not a British initiative alone — it is an initiative that the British presidency of the Tallinn Mechanism made possible by creating the diplomatic conditions for a three-way partnership.

This model — a presidency that acts as catalyst rather than sole actor — is what the Italian presidency should strive to replicate. Italy has diplomatic and economic ties with countries not yet fully engaged in the Tallinn Mechanism. Its presidency could be the occasion to involve them more — thereby broadening the financial and technical base of the mechanism beyond its current members.

The Italian presidency's priorities

Four declared axes of action

Italy announced four priority axes for its Tallinn Mechanism presidency: cyber defense of Ukrainian national and regional government agencies, protection of critical infrastructure, strengthening overall cyber resilience, and training Ukrainian cybersecurity experts. These four axes cover both the institutional dimension (government), the economic and social dimension (critical infrastructure), and the human dimension (expert training). It is a coherent approach that acknowledges that cyber defense is not a single tool but an ecosystem of complementary capabilities.

The additional contribution of one million euros announced by Italy brings its total contribution to two million euros. For perspective: Sweden has contributed approximately 14.5 million U.S. dollars to the mechanism, notably through the Sida agency, for IT infrastructure improvements, digital services security, and personnel training. Italy, the third-largest economy in the eurozone, still has room to increase its financial engagement if its presidency is to match its declared ambition.

Why Ukrainian cyber defense matters for all of NATO

Ukraine as a laboratory for modern cyberwarfare

There is a reason why NATO members have a strategic — not merely moral — interest in supporting Ukrainian cyber defense. Ukraine is today the most advanced testing ground for large-scale cyberwarfare. The techniques developed by Russian hackers against Ukrainian systems — NotPetya, attacks on the electricity grid, intrusions into military communications — have been or will be adapted to target NATO member states. Every technique that Ukraine learns to detect and counter is a technique that allied countries learn to avoid.

This real-time expertise sharing — between Ukrainian cyber defense teams and partner countries — is one of the least publicized strategic benefits of supporting Ukraine. The cyber defense teams of Tallinn Mechanism member countries access, through their cooperation with Ukraine, data on the tactics, techniques, and procedures of Russian intelligence services that would have no peacetime equivalent. The financial contribution to the mechanism is also, in this sense, an investment in cybersecurity intelligence.

What the 14 partners should commit to doing

An open letter to the allies

I now address directly the governments of the 14 partner countries of the Tallinn Mechanism. Italy's assumption of the presidency is an opportunity to take stock of what has been accomplished and what remains to be done. The mechanism's creation in 2023 responded to a genuine need. Its two and a half years of existence have produced tangible results. But the war in Ukraine is not over — and Russian cyber pressure on Ukrainian infrastructure is not diminishing.

What is needed now is not a larger-format mechanism — it is a better-funded, better-coordinated, and more responsive one. Individual contributions vary considerably among partners, creating burden asymmetries that are not sustainable over the long term. Sweden contributes proportionally far more than other larger economies. This situation must be corrected — not by asking Sweden to contribute less, but by asking the larger economies to contribute more.

Coordination with Ukrainian institutions: practical challenges

Who receives the aid and how

The question of operational coordination with Ukrainian institutions is often absent from official Tallinn Mechanism communiqués — but it is central to its effectiveness. Cyber defense assistance does not arrive in a vacuum. It must be integrated into existing structures — the teams of the State Service of Special Communications and Information Protection, the cyber units of Ukrainian intelligence services, the technical teams of ministries. This integration requires a precise understanding of existing capabilities, gaps, and priorities as defined by the Ukrainians themselves — not by donors.

The British presidency worked directly with the Ukrainian Ministry of Foreign Affairs and other institutions. This choice of working with official institutions rather than intermediaries is important: it strengthens Ukrainian state structures themselves, rather than creating donor-dependent parallel structures. It is a capacity-building approach rather than an external assistance approach — and it is the only one that produces lasting effects.

The risks of redundancy and fragmentation

A mechanism with 14 partner countries carries a structural risk: fragmentation of efforts and redundancy of initiatives. Without strong coordination among members, each country may fund similar projects in the same Ukrainian institutions, creating costly duplications and excessive administrative burden for Ukrainian teams managing multiple donors. The presidency of the mechanism exists precisely to prevent this fragmentation.

The Italian presidency will therefore need to invest in coordination among members — not only in Italy's own direct projects. Organizing regular follow-up meetings between partners, maintaining a map of ongoing initiatives, identifying gaps that no one is covering — this coordination work is less visible than financial contribution announcements, but equally crucial for the mechanism's effectiveness.

The training dimension: investing in the next generation

Training Ukrainian experts — a 20-year investment

One of the Italian presidency's priority axes — training Ukrainian cybersecurity experts — may be the most important over the long term. Hardware and software systems can be improved relatively quickly. Training high-level cybersecurity experts takes years. Ukraine, which has lost part of its skilled population to war-related displacement, needs to train a new generation of experts capable of defending its digital infrastructure not only during the war, but in post-war Ukraine.

This training program also has a nation-building dimension. A Ukraine with a strong and independent cybersecurity sector will be a more resilient Ukraine in the face of future Russian pressure — even after a ceasefire or peace agreement. Russian attempts at destabilization via cyberattacks will not end with conventional warfare. They will continue, in evolved forms, in the years that follow. Investing now in training Ukrainian experts is investing in the long-term stability of Eastern Europe.

Conclusion: Ukrainian cyber defense is everyone's cyber defense

What Rome must now demonstrate

Italy has assumed the Tallinn Mechanism presidency with solid statements of intent and an initial financial contribution. This is only the beginning. The British presidency set an operational standard — seven initiatives, partnerships built, measurable results. The Italian presidency will be judged by the same criteria. Not on communiqués. On what will have been concretely done to strengthen Ukraine's capacity to defend itself in cyberspace by the time the Italian presidency concludes.

To the other mechanism partners, I ask a simple question: is your contribution to the Tallinn Mechanism proportional to the size of your economy and your dependence on Ukraine's stability? If the answer is no — and for many of you, it is not — it is time to correct that. Not out of guilt, but out of strategic calculation. Ukraine's cyber defense is not a humanitarian cause. It is a collective security infrastructure that benefits every member of the alliance.

By Maxime Marquette, columnist

Columnist's transparency note

What I am and what I am not

I am a columnist and analyst — not a government expert in cyber defense. This open letter rests on public sources available as of July 1, 2026: the United24 communiqué on the Italian contribution, Kyiv Independent reports on the mechanism, and information available on national contributions. The figures cited — Italian contribution of two million euros, Swedish contribution of approximately 14.5 million U.S. dollars — come from verifiable public sources. I do not know the full breakdown of all partners' contributions, which is an explicit limitation of this analysis.

Editorial biases and limits

I am pro-Ukraine and I believe that support for Ukrainian cyber defense is in the strategic interest of the West. This bias shapes the angle of this open letter. The implicit criticism of contribution asymmetries rests on incomplete data — I do not have access to detailed contributions from all 14 partners. Before judging any specific country's contribution, a complete comparative table would be needed — one that is not available in the public sources consulted.

Sources

Primary sources

Secondary sources

Get the geopolitics analyses

Conflicts, powers, alliances: the MadMax thread without the noise.

Cite this article

Maxime Marquette (2026). OPEN LETTER: Rome takes over from London — Italy leads Ukraine's cyber defense. MadMax. https://mad-max.co/en/article/lettre-ouverte-rome-prend-le-relais-de-londres-l-italie-a-la-tete-de-la-cyberdef

How does this piece make you feel?
MM
Maxime Marquette
Independent columnist

Maxime Marquette writes most of the analyses and columns published on MadMax — geopolitics, technology, and current events, no filler.

The Newsletter

Enjoyed this piece? Get the next one.

One chronicle a week, straight to your inbox. No noise.

Comments

0 / 2000

Be the first to weigh in.

This article was generated with AI assistance, under human supervision.

Op-Ed1 reads2210 words4 min read