Short answer: Estonia's National Cyber Resilience in the Age of AI report proposes a "Minimum Viable State" (MVS): the minimum set of state functions that must remain operational under continuous cyberattack. Dr. Alper Ozbilen reads this as the technology industry's Minimum Viable Product concept translated into national-security language — and argues it names one of the most concrete decisions available in asymmetric cyber defense: where a defender concentrates, as the attack surface expands faster than any defense budget can follow.

📎 Source: Dr. Alper Ozbilen (@dralperozbilen), X, September 2026, commenting on Estonia's National Cyber Resilience in the Age of AI report.

From product design to state design

In software development, a Minimum Viable Product asks a narrow question: what is the smallest version of a product that still does the one thing it has to do? Estonia's doctrine asks the same question of the state itself: under sustained, continuous cyberattack, which government functions are truly non-negotiable — and which can degrade, pause, or fail without the state itself failing?

That reframing matters because it inverts the usual instinct in cybersecurity planning, which is to try to defend everything to the same standard. Ozbilen's reading of the concept is direct: as digitalization and AI multiply the number of attackable systems and the methods available to attack them, trying to defend every system at equal intensity becomes progressively more expensive — and eventually, impossible.

Narrowing the priority, not narrowing the defense

The risk in a concept like MVS is that it can sound like permission to leave some systems undefended. Ozbilen is explicit that this is not the intent: the idea is not to protect some systems and abandon others, but to know, in advance, where a defender concentrates when the attack surface has already outgrown what any real budget or headcount can fully cover.

This is the same operational logic behind triage in any resource-constrained emergency response: it is not a statement that everything else doesn't matter — it is an acknowledgment that intensity has to be allocated, not distributed evenly, once true equal-coverage becomes physically or financially unrealistic.

The strategic decision this makes explicit

Read as doctrine rather than as a technical framework, MVS forces a government to answer a question in advance rather than in the middle of a crisis: which functions — energy distribution, emergency communications, core financial settlement, continuity of government — actually cannot be allowed to fail, and which functions can be allowed to degrade temporarily while defenders concentrate elsewhere?

Ozbilen frames this as one of the most concrete decisions available inside asymmetric cyber defense specifically because it is falsifiable and plannable in a way "defend everything" never is. A state that has actually enumerated its MVS can rehearse for it, resource it, and measure whether it held. A state that has only committed to defending everything has no way to know, in advance, whether its plan matches its actual capacity.

The second half of the doctrine: response, not just resilience

Ozbilen adds a second component that he considers underexplored relative to resilience planning itself: the capacity to respond — directly or indirectly punishing an attacker — as part of the same defense doctrine, rather than treating deterrence and resilience as separate tracks. In his framing, a credible ability to impose cost on an attacker, not only to withstand the attack, is one of the least openly discussed but most effective components of an asymmetric cyber defense posture.

Does this connect to ALP AI's framework?

This is a direct application of the same optionality logic ALP AI has traced elsewhere under Decision Sovereignty: the test of a system is not whether it can be attacked — everything connected can be — but whether the state retains the ability to decide, in advance and under pressure, what it protects, what it lets degrade, and how it responds. A Minimum Viable State is, in that sense, a decision-sovereignty framework applied specifically to the question of what a government cannot afford to lose.