Written by the ENSI Foresight Division on a library of 114 primary documents from the EU institutions, OECD, UN bodies, NATO, world governments, and the leading think tanks. Compiled August 2026.
The argument, before the list
The first report in this series mapped what a modern state must control — the seven layers of sovereign digital assets, from energy and chips through registers, platforms, and models to people and trust. This report answers the harder question: what is all of it for, and how does a state actually run it? The answer the library forces on us is uncomfortable for any government that measures digital progress in strategies published and portals launched. Sovereignty is not a stack of assets. It is a set of capabilities exercised under stress — and a capability that has never been exercised is a hypothesis, not a capability.
The distinction is not rhetorical; it is the single sharpest lesson in the evidence base. Ukraine survived the first weeks of the 2022 invasion digitally not because it had a resilience strategy on a shelf, but because it had made itself capable of acting in days: the Verkhovna Rada amended the laws that had barred government use of cloud services in February 2022 — days before the invasion — so that Amazon, Microsoft, Google, and Cloudflare could help migrate critical state data out of the data centres Russia’s early strikes specifically targeted (Atlantic Council, Building the Digital Front Line). A decade of institution-building sat underneath that single legislative reflex: ProZorro procurement reform, a Ministry of Digital Transformation with direct relationships into the technology sector, a deputy prime minister who sent more than 4,000 personally signed assistance requests in the first month of the war. Estonia, having absorbed the lesson of the 2007 attacks (NATO CCDCOE, Estonia 2007 Cyber Attacks Analysis), built the world’s first data embassy — ten strategic registers, from the population registry to the land cadastre, continuously replicated to a Tier 4 facility in Luxembourg under an agreement that grants the servers embassy-grade immunity (e-Estonia, Data Embassy Factsheet). Finland never stopped exercising: its comprehensive-security model assigns seven vital functions of society — leadership; international and EU activities; defence capability; internal security; economy, infrastructure and security of supply; the functional capacity of the population; psychological resilience — to named ministries, rehearsed across government, business, and municipalities (Finland Security Committee, Security Strategy for Society 2017). Three small and mid-sized states; three proofs that the plan is not the capability — the exercised institution is.
What, then, should the capability do? The whole seven-layer stack exists to serve four sovereign functions. First, crisis management: sense, decide, communicate, and continue operating when systems are under attack or under water. Second, decision-making: evidence, simulation, and anticipation wired into how the centre of government actually chooses, not shelved in a foresight unit’s annual report. Third, mapping the nation’s assets and economy: a continuously updated national balance sheet — what the country has, who depends on what, what breaks first. Fourth, science and discovery planning: steering national research capacity, compute, and data toward strategic problems, and absorbing what they produce. A state sovereign in these four functions can lose systems and still govern. A state that has rented all seven layers — and never exercised the functions — can be switched off politely, contractually, and completely.
This report is the playbook for building the four functions as operating capabilities, plus the two enablers without which they collapse: the cyber floor that keeps the machinery defensible, and the measurement regime that tells a government whether the capability is real or theatrical. Each area gets a full operating brief: what it is, why it ranks where it does, the foresight questions it must answer, the signals to watch, the methods that fit, the agentic engine that runs it continuously — the ENSI signature, because a four-function state in 2026 is run by fleets of AI agents with humans owning judgement and accountability — and the institutional wiring with first moves. The close assembles it into a first-twelve-months sequence for a mid-sized EU state, with the Czech Republic as the worked example. The option-value argument runs throughout: none of this requires predicting which crisis arrives. It requires being the state that still functions when one does.
The main points
Resilience is a capability, not a plan. Ukraine’s 2022 cloud migration, Estonia’s data embassy, and Finland’s comprehensive-security exercises all show that what survives contact with a crisis is exercised institutional muscle — legal authority, rehearsed teams, pre-signed agreements — not documents.
The digital stack exists to serve four sovereign functions: crisis management, decision-making, national asset and economy mapping, and science planning. Build the functions, and the asset questions answer themselves.
Crisis management ranks first because it is the function under which all others are stress-tested: NATO’s seven baseline requirements, the Sendai Framework’s four priorities, and the UN’s Early Warnings for All four-pillar architecture give a state a complete, already-negotiated blueprint.
Decision infrastructure ranks second: the OECD’s 2025 anticipatory-governance guidelines, the UK Futures Toolkit, and the arXiv frontier of policy digital twins and multi-LLM-agent simulation define a centre of government that tests policies before reality does.
Asset and economy mapping ranks third: economic complexity (Harvard), strategic-dependency reviews (EU), systemically-important-entity ranking (RAND), and real-time nowcasting from scanner and payments data (ECB, arXiv) turn the national balance sheet into a live system.
Science planning ranks fourth: the ESFRI roadmap process, EOSC, mission governance (Mazzucato), Singapore’s RIE2025, and national compute programmes (NAIRR, UK AIRR) show how a state points discovery at national needs.
Two enablers make the four functions possible: a cyber floor (NIS2/CER, NIST CSF 2.0, national strategies from Washington to Prague) and a measurement regime (UN EGDI, ITU GCI, OECD DGI, World Bank GTMI) that distinguishes real capability from digital theatre.
Every function gets an agentic engine: scanning, simulation, early-warning, red-team, and briefing agents operating continuously, with humans owning judgement — the only way a mid-sized state staffs four standing functions without quadrupling its civil service.
The first twelve months for a mid-sized EU state are sequenced at the close: a centre-of-government resilience unit, a data-embassy agreement, a national risk register, a live dependency map, and eight to ten concrete moves with named owners.
How this playbook is organised
Six areas, ranked. The four sovereign functions come first, in order of how quickly their absence kills a government under stress: crisis management fails in hours, decision-making in weeks, asset mapping in months, science planning in years. The two enablers follow — not because they matter less, but because they are means: the cyber floor keeps the functions defensible; measurement keeps them honest. Each area receives the same seven-part operating brief — In short · Why it ranks here · The foresight questions & horizons · Signals & data to watch · Methods that fit · The agentic engine · Institutional wiring & first moves — because a playbook that changes shape with each chapter is a collection of essays, not an operating document.
Priority 1 — Crisis management and digital continuity
In short. The capability to sense a shock early, decide and communicate under degraded conditions, keep the state’s vital functions running, and recover fast — with the digital substrate (registers, communications, cloud continuity, early-warning channels) engineered so that losing buildings, data centres, or even territory does not mean losing the state.
Why it ranks here. Because it is the function with the shortest fuse and the harshest audit. Every other function degrades gracefully; this one fails catastrophically, publicly, and first. It is also the best-specified function in the entire library — a state does not need to invent its crisis architecture, only to assemble and exercise it. NATO’s civil-preparedness work gives the demand side: seven baseline requirements for national resilience, agreed at the Warsaw Summit in 2016, beginning with assured continuity of government and critical government services — “the ability to make decisions, communicate them and enforce them in a crisis” — and running through resilient energy, the ability to deal with uncontrolled movement of people, food and water, mass casualties, resilient civil communications, and resilient transport (NATO CIMIC COE, Resilience through Civil Preparedness). The same factsheet quantifies why the state cannot do this alone: 90 per cent of military transport uses civilian assets, over half of defence satellite communications are commercial, and 75 per cent of host-nation support comes from local commercial sources — resilience is civil preparedness or it is nothing. The Sendai Framework supplies the risk-reduction logic in four priorities — understanding disaster risk; strengthening risk governance; investing in reduction; enhancing preparedness to “Build Back Better” — and seven global targets, of which Target G, multi-hazard early-warning coverage, is the digital one (UNDRR, Sendai Framework 2015–2030). And Ukraine supplies the live audit: the war has tested autonomous systems, information operations, electronic warfare, contested logistics, and air defence simultaneously (CSIS, Lessons from the Ukraine Conflict), with the pre-invasion Viasat hack — which cascaded into roughly 5,800 German wind turbines — as the standing reminder that digital crises do not respect borders or sectors.
The foresight questions & horizons. At 0–2 years: which of the seven NATO baseline requirements would fail first in this country, and what is the reasonable worst case for each — the question the UK now answers publicly through a National Risk Register of 89 acute risks in nine themes (UK Cabinet Office, National Risk Register 2025)? Can the state’s ten most critical registers survive the loss of every domestic data centre? At 2–5 years: what does continuity of government mean when core services run on foreign hyperscalers — which workloads must have a sovereign or allied fallback, on the Estonian data-embassy pattern? At 5–10 years: how do climate-driven compound disasters, hybrid campaigns, and infrastructure sabotage converge — and does the crisis architecture handle three simultaneous emergencies, or one at a time?
Signals & data to watch. The state’s own early-warning coverage, benchmarked against the Early Warnings for All gap data: only one third of WMO members report multi-hazard monitoring and forecasting systems, 56 per cent use hazard-exposure-vulnerability data in forecasts, 67 per cent have 24/7 alerting, and fewer than four in ten have the legal arrangements a multi-hazard early-warning system requires (WMO, EW4All Factsheet) — each a checkbox a mid-sized state can audit against itself this quarter. Dependency data on lifeline infrastructure — energy, water, transport, communications — mapped building-by-building on the NIST community-resilience method (NIST, SP 1190). Cyber pre-positioning indicators from the annual threat picture (ENISA, Threat Landscape 2024). Population-trust signals: the IFRC’s warning that harmful information is now itself a humanitarian-scale crisis dimension (IFRC, World Disasters Report 2026) makes information integrity a crisis-management telemetry stream, not a communications afterthought.
Methods that fit. Assemble, do not invent. The WMO’s four-pillar architecture — risk knowledge (UNDRR), detection and forecasting (WMO), warning dissemination (ITU), preparedness and response (IFRC) — is a complete reference design for national early warning with a near-tenfold return on investment (WMO, EW4All Overview and Pillar 2). NIST SP 1190’s six-step planning process — collaborative team, situation understanding across social and built environments, goals, plan, approval, implementation — scales from municipality to nation and forces the crucial discipline of recovery-time targets per social function. Finland’s model supplies the governance: assign each vital function a lead ministry, run a standing Security Committee, and exercise relentlessly. Estonia supplies the continuity pattern: identify the strategic registers, replicate them under sovereign legal control abroad, rehearse restoration. Ukraine supplies the wartime procurement lesson: pre-draft the legal instruments (its Resolution 169 streamlining emergency procurement passed four days after the invasion began) rather than improvising them under fire.
The agentic engine. Crisis management is the natural home of the always-on agent fleet. Sensing agents fuse meteorological, seismic, epidemiological, grid, and cyber telemetry into a single anomaly stream — the machine layer of EW4All Pillar 2. Common-operating-picture agents maintain the live state of lifeline networks and NATO-baseline indicators, so the situation room’s first hour is not spent asking who knows what. Cascade-simulation agents run the dependency graph forward — if this substation, then which hospitals, which water pumps, which registers — continuously, not as an annual tabletop. Communication agents draft multilingual, channel-specific public warnings for human release, closing the dissemination gap Pillar 3 documents. Red-team agents attack the crisis architecture itself between exercises. Humans hold the two things agents must never hold: the declaration of emergency and the voice of the state.
Institutional wiring & first moves. Ownership belongs at the centre of government — a national resilience unit chaired from the prime minister’s office on the Finnish Security Committee pattern, with the interior ministry running operations, the cyber agency running the digital dimension, and every vital function assigned a named lead ministry. First moves: publish a national risk register with reasonable-worst-case scenarios; audit the state against the seven NATO baselines and the four EW4All pillars; select the ten registers that constitute the state’s continuity core and negotiate a data-embassy agreement for them; pre-draft the emergency legal instruments Ukraine had to pass in days; and put the whole apparatus through a full-scale, ministers-in-the-room exercise within twelve months — because the first time the machinery runs must not be the first time it matters.
Priority 2 — Decision infrastructure and policy intelligence
In short. The machinery by which the centre of government perceives what is coming, tests options before committing to them, and decides on evidence under uncertainty — strategic foresight, systems analysis, and simulation wired into budgeting, legislation, and cabinet process rather than orbiting them as a boutique unit.
Why it ranks here. Because a state that survives the crisis but cannot decide well afterwards has merely postponed its failure. The OECD’s diagnosis is blunt: systematic use of strategic foresight in government “is not widespread,” and where foresight processes exist they are “insufficiently connected with policy development” (OECD OPSI, Towards Anticipatory Governance Guidelines). That is the gap this priority closes — not the absence of futures work, which most governments now perform ritually, but the absence of decision infrastructure: the standing capability to convert anticipation into different choices. The OECD’s 2025 guidelines give the target state a name and a test. Five dimensions of anticipatory governance — future-readiness, innovation, endurance, long-term perspective, direction — supported by six enabling factors: leadership support, competencies, observation of trends and signals, participatory processes, cross-country exchange of intelligence, and structures and procedures. The exemplars are named and instructive precisely because they are institutional, not methodological: Finland’s statutory Report on the Future each government term, Wales’s legally mandated Future Generations Commissioner, Singapore’s central foresight unit sitting next to a strategy unit inside the Prime Minister’s Office (OECD OPSI, Towards Anticipatory Governance Guidelines). In each case anticipation has an address, a budget, and a route into decisions. The frontier, meanwhile, has moved from workshop to simulation: multi-level agent-based policy digital twins designed explicitly for government decision support (arXiv, Design of Policy Digital Twins) and multi-LLM-agent frameworks that simulate the responses of heterogeneous economic actors to a policy before it is adopted (arXiv, Multi-LLM-Agent Framework for Economic and Public Policy Analysis). A mid-sized state that wires even a fraction of this into its cabinet process gains something rare: the ability to be wrong in silico, cheaply, instead of in public, expensively.
The foresight questions & horizons. At 0–2 years: which five decisions on the government’s current agenda would most benefit from being stress-tested against divergent futures — and what would it take to run each through a scenario exercise before, not after, the political commitment? Does the centre of government have a single, maintained trend-and-signal base, or does every ministry scan alone? At 2–5 years: which policy domains — energy transition, migration, labour markets, health-system load — justify a standing digital twin, and what data plumbing do they require from the statistical office? At 5–10 years: what does cabinet decision-making look like when every major proposal arrives with a machine-generated stress-test annex — and what new failure modes (automation bias, model capture, narrowed imagination) must the institution guard against from the start?
Signals & data to watch. The state’s own anticipatory maturity, self-assessed against the OECD’s FIELD/SCOPES questions — the guidelines ship with assessment tables designed for exactly this audit. The connection rate between foresight outputs and decisions: how many scenario exercises in the past two years changed a budget line, a bill, or a procurement — the honest metric, and usually a humiliating one. Signal flow from the crisis function (Priority 1) and the asset map (Priority 3) into policy processes: a centre of government that learns about a supply-chain dependency from the newspaper has a wiring failure, not an information failure. The systems-mapping capability of the civil service itself — the UK’s introduction to systems thinking for civil servants exists precisely because linear policy logic fails on interconnected national problems (UK GO-Science, Introduction to Systems Thinking). And internationally: which peer governments are institutionalising — the OECD guidelines emerged from a working group of fifteen countries, which is itself a signal that anticipatory capacity is becoming a norm against which states will be measured.
Methods that fit. The UK Futures Toolkit is the canonical method suite: twelve tools organised around three questions — what is changing (Delphi, Seven Questions, horizon scanning, Three Horizons, driver mapping), so what for our futures (SWOT, scenarios, visioning, futures wheels), and now what do we do (policy stress-testing, roadmapping, backcasting) — with assembled pathways for common objectives (UK GO-Science, The Futures Toolkit Edition 2). The discipline that matters most is the third column: stress-testing named policies against scenario sets, which converts foresight from cultural enrichment into due diligence. Systems mapping should precede any major intervention in a complex domain, on the GO-Science method. Simulation ascends a maturity ladder: from spreadsheet models through agent-based policy twins to multi-agent LLM simulation of stakeholder response — with the arXiv literature clear that these are decision-support instruments, demanding validation, uncertainty communication, and human sign-off, not oracle machines. The UNDP’s framing supplies the governance wrapper: digital governance is institutional capability, built deliberately, not a procurement of dashboards (UNDP, A Shared Vision for Technology and Governance).
The agentic engine. This is the function where agents change the economics most decisively, because the binding constraint on national foresight has always been analyst hours. Scanning agents maintain the horizon-scanning base continuously across languages and sources, surfacing weak signals ranked by relevance to the government’s standing priorities — the OECD’s “observation of trends and signals” enabler, industrialised. Scenario agents generate and refresh divergent futures for each major policy domain, keeping them alive as conditions change instead of letting them fossilise in a 2024 PDF. Simulation agents operate the policy twins: parameterising the agent-based models, running Monte Carlo sweeps, and translating distributions into ministerial language. Stress-test agents take any draft policy and run it against the scenario base overnight — the Futures Toolkit’s policy stress-test as a standing service rather than a workshop. Briefing agents compile the daily anticipatory brief for the centre of government, with every claim linked to its source signal. Humans own the questions, the interpretation, and the decision; the agents own the coverage and the tempo. A foresight unit of eight people with this engine outperforms a directorate of eighty without it.
Institutional wiring & first moves. The pattern that works is Singaporean: a foresight unit and a strategy unit adjacent to each other at the centre of government, so anticipation and decision share a corridor. Wire it with three statutory connections — a futures annex requirement for major cabinet submissions, a government-term Report on the Future to parliament on the Finnish model, and a standing seat in the budget process. The statistical office supplies the data substrate for simulation; the science ministry supplies the modelling partnerships. First moves: run the OECD FIELD/SCOPES self-assessment and publish the result internally; stand up the central signal base with scanning agents in the first quarter; pick two live policy questions and stress-test them against scenarios within six months, with ministers in the room for the findings; commission one policy digital twin in a data-rich domain as the pathfinder; and train the top three grades of the civil service on the Futures Toolkit and systems thinking — because decision infrastructure is, in the end, made of people who know what to ask of it.
Priority 3 — Mapping the nation’s assets and the economy
In short. The continuously updated national balance sheet: what the country has — infrastructure, firms, capabilities, skills — who depends on what, where the chokepoints are, and what breaks first under stress. Not an annual statistical publication but a live system fusing trade, firm, payments, and infrastructure data into a single queryable map of the nation.
Why it ranks here. Because both functions above it run on it. Crisis management without a dependency map is improvisation; decision simulation without a real economic network model is fiction. And because the evidence is now overwhelming that the aggregate view conceals exactly what a sovereign state needs to see. The BIS shows that shocks propagate through inter-sectoral supply-chain linkages in ways aggregate statistics structurally miss (BIS, Supply Chain Transmission of Climate-Related Physical Risks); the WTO’s empirical mapping of value chains under shock — energy, semiconductors, reshoring — makes the same point at global scale (WTO, Global Value Chain Development Report 2023). The state of the art has three tiers, and a capable state runs all three. Capability mapping: the Harvard economic-complexity method reads what a country knows how to make from its export structure — the ECI/PCI apparatus — and, more usefully, what it could plausibly learn to make next, turning industrial strategy from lobbying contest into adjacency analysis (Harvard Growth Lab, Atlas of Economic Complexity; Hausmann-Hidalgo Economic Complexity). Dependency mapping: the EU’s in-depth reviews supply the official method for tracing critical import dependencies to specific products and source countries — the first round covered rare earths, chemicals, solar, cybersecurity, and IT software (Council of the EU, EU Strategic Dependencies and Capacities In-Depth Reviews) — while RAND supplies the analytic core for ranking which entities are systemically important to national functions, the shift from listing assets to prioritising them (RAND, Identifying and Prioritizing Systemically Important Entities; CISA, National Critical Functions Overview). Nowcasting: the ECB demonstrates that granular scanner data plus machine learning reads inflation in near-real time (ECB, Nowcasting Consumer Price Inflation with Granular Scanner Data), and the payments frontier goes further — granular payment-network data reconstructing a disaggregated, real-time map of an economy’s transaction structure (arXiv, Mapping the Disaggregated Economy in Real Time with Payment Network Data). The reframe: the census was the founding act of the modern state; the live national map is its twenty-first-century successor, and states that still see their economies quarterly are governing by rear-view mirror.
The foresight questions & horizons. At 0–2 years: for the state’s ten most critical functions, which specific entities — firms, facilities, networks — are systemically important, and does government know their failure modes? Which imported inputs have no substitute within ninety days? At 2–5 years: where does the country’s economic-complexity position say it can credibly diversify, and which dependencies are worth the cost of redundancy — the calculus the OECD’s supply-chain toolkit frames as anticipate, minimise exposure, build trust, and keep markets open (OECD, Keys to Resilient Supply Chains)? At 5–10 years: what does the national balance sheet look like as energy, compute, and critical materials become the binding constraints — and is the state accumulating or shedding the capabilities adjacent to where the technological frontier is moving?
Signals & data to watch. Customs microdata read through the dependency lens: concentration of critical imports by product and origin, updated continuously rather than in one-off reviews. Payments telemetry as the economy’s pulse — the real-time layer the arXiv work proves feasible. Scanner and price data for inflation nowcasts. Firm-registry and ownership-graph changes around systemically important entities: acquisitions, insolvencies, foreign-control events. Infrastructure-network state from the lifeline systems mapped under Priority 1 — the same graph, viewed economically. Export-structure drift in the complexity data: a country’s position in product space moves slowly, which is exactly why it must be watched deliberately. And global risk-interconnection context from the annual landscape (WEF, Global Risks Report 2025) to keep the national map honest about imported shocks.
Methods that fit. Run the three tiers as one architecture. Foundation: a national asset and entity registry built on the CISA critical-functions taxonomy — functions first, then the entities that sustain them — with RAND’s prioritisation method ranking them by systemic importance. Analysis: EU-style in-depth dependency reviews on the top imported vulnerabilities, refreshed annually; Harvard complexity analysis for the capability map and diversification frontier; BIS-style network stress propagation on the inter-sectoral graph. Tempo: ECB-pattern nowcasting on scanner and payments data, run by the statistical office as a standing product. The institutional principle throughout: the map must be a shared substrate — statistical office, central bank, cyber agency, and crisis centre reading the same graph — or it fragments back into departmental fiefdoms and dies.
The agentic engine. Cartographer agents maintain the entity and dependency graph, ingesting registry filings, customs records, and infrastructure data, and flagging structural changes for human review. Chokepoint agents continuously scan the import matrix for concentration, single-source exposure, and emerging substitution options, on the EU review method but at weekly tempo. Nowcast agents run the scanner- and payments-data pipelines, publishing real-time activity and price estimates with uncertainty bands. Stress agents propagate hypothetical shocks — a port closure, a sanctioned supplier, a failed grid region — through the network graph and hand the cascade results to the crisis and decision functions. Complexity agents track the country’s product-space position and simulate diversification paths. Humans own the classification decisions (what counts as critical), the confidentiality boundaries (firm-level data is radioactive if mishandled), and every act of publication.
Institutional wiring & first moves. The natural owner is a partnership: the national statistical office as data steward and methodological authority, a centre-of-government analytical unit as the customer and integrator, the central bank as partner on payments and nowcasting, and the cyber agency contributing the critical-entity view it already builds under NIS2 and CER obligations. First moves: adopt a national critical-functions taxonomy and stand up the entity registry; commission the first three dependency in-depth reviews on the EU method; give the statistical office a mandate and legal gateway for scanner and payments data nowcasting; run the first full network stress-test against the Priority 1 exercise scenario; and publish an unclassified national resilience map annually — because a balance sheet the parliament and public never see disciplines no one.
Priority 4 — Science and discovery planning
In short. The capability to decide, deliberately and on evidence, where the nation’s research capacity, compute, data, and talent should point — and to absorb what they produce. Research-infrastructure roadmapping, mission governance, national compute provision, and open research data, run as one system with a planning cadence rather than as a grants lottery.
Why it ranks here. Because it is the slowest function — its failures take a decade to surface and another to repair — and because AI has just changed its economics. The Royal Society’s assessment is that AI is transforming the conduct of science itself, which converts research infrastructure, data, and compute from sectoral concerns into sovereign ones: a state whose scientists cannot access frontier-scale tools does its discovery elsewhere or not at all (Royal Society, Science in the Age of AI). Microsoft’s AI4Science evidence base shows large models already functioning as discovery infrastructure across chemistry, biology, and materials (Microsoft AI4Science, Impact of LLMs on Scientific Discovery). The planning methods, meanwhile, are mature and documented. Europe’s ESFRI process — running since 2002, with the 2021 Roadmap its sixth edition — is the reference discipline for infrastructure choice: proposals require a funding commitment from a lead member state, political support from at least two more, and a consortium agreement; projects are monitored against a ten-year implementation window; and the 2021 round admitted eleven new projects from eighteen proposals, alongside forty-one implemented Landmarks — evidence that a transparent, criteria-based process can say no (ESFRI, Roadmap 2021 Strategy Report). Its prerequisite is the Landscape Analysis: map what exists before funding what is missing — a discipline most national research systems still lack. EOSC extends the logic to data, federating research-data infrastructure so that publicly funded outputs become FAIR, reusable inputs to the next discovery (EOSC Association, Strategic Research and Innovation Agenda 1.2). Mission governance supplies the demand side: Mazzucato’s framework for the EU makes missions governable through citizen engagement, public-sector capabilities, and dedicated finance rather than through exhortation (European Commission, Governing Missions in the European Union). And Singapore proves the whole assembly at national scale: five-year plans since 1991, rising from S$2 billion to roughly S$25 billion — about one per cent of GDP — for RIE2025, organised into four strategic domains and three horizontals, with S$3.75 billion held as deliberately unallocated “white space” for the futures the plan did not foresee (NRF Singapore, RIE2025 Plan). That last detail is the sovereign-planning masterstroke: a plan that budgets for its own wrongness.
The foresight questions & horizons. At 0–2 years: does the state know what research infrastructure and compute it actually has — the ESFRI-style landscape analysis — and where its researchers currently go abroad for what they cannot get at home? What share of nationally funded research data is findable and reusable? At 2–5 years: which two or three missions deserve mission-grade governance, and what compute capacity must be secured as AI-for-science demand compounds — the question the UK’s Future of Compute review answered by recommending a national AI Research Resource, and the US NAIRR Task Force answered with a blueprint for democratising compute access as public infrastructure (UK Government, Independent Review of the Future of Compute; NSF, NAIRR Task Force Final Report)? At 5–10 years: where will AI-accelerated discovery move the frontier in the domains this country depends on — and is the research system building the absorptive capacity to use what global science produces, which for a mid-sized state matters more than producing it all?
Signals & data to watch. Compute demand and queue data from national facilities against the OECD’s capacity–effectiveness–resilience framework for national AI compute planning (OECD, Blueprint for Building National Compute Capacity for AI). Placement on the EuroHPC map — machines, AI factories, and access calls — as the realistic sovereign-compute route for an EU mid-sized state (EuroHPC JU, Multi-Annual Strategic Programme 2021–2027). Research-talent flows in and out. The mission portfolio’s health against the OECD’s warning that science systems are being reshaped by disruption and strategic competition, not steady-state growth (OECD, Science, Technology and Innovation Outlook 2023). Uptake signals from the AI-for-science literature: which disciplines are tipping into model-driven discovery, since those are where infrastructure demand arrives next. And the honest lagging indicator: how much of the last plan was actually spent where it was pledged.
Methods that fit. Adopt the ESFRI discipline nationally: a periodic, criteria-based roadmap with landscape analysis first, political and financial commitment as the entry ticket, and continuous monitoring — the cadence, not the size, is what Singapore proves matters. Run missions on the Mazzucato governance model, with each mission owning a budget, a public-engagement mechanism, and an experimentation mandate. Treat compute as planned infrastructure on the OECD blueprint, blending national capacity, EuroHPC access, and negotiated commercial provision. Mandate FAIR data on the EOSC pattern as a funding condition, not an aspiration. And hold white space — a fixed share of the research budget explicitly reserved for the unforeseen, reviewed mid-plan.
The agentic engine. Landscape agents maintain the live map of national research infrastructure, instruments, datasets, and capabilities — the ESFRI landscape analysis as a continuously updated graph rather than a quinquennial report. Frontier agents scan global preprints, patents, and facility announcements to detect where fields are accelerating, feeding the roadmap’s next revision. Portfolio agents track every funded project against mission objectives, flagging drift and duplication across funders. Matchmaking agents connect national problems from the asset map (Priority 3) to research groups and infrastructure that could address them. Discovery agents — the AI-for-science layer itself — run literature synthesis, hypothesis generation, and simulation for national research teams, which is precisely the capability the Royal Society argues research systems must now provide as infrastructure. Humans — the research councils and the scientific community — own the scientific judgement, the ethics, and the allocation decisions.
Institutional wiring & first moves. Ownership splits three ways: a national research and innovation council at the centre sets missions and owns the roadmap; the research-funding agencies execute the portfolio; the science ministry secures the infrastructure and the EuroHPC relationships. First moves: commission the national research-infrastructure landscape analysis; publish the first national roadmap on ESFRI rules with a five-year budget envelope; designate two missions with mission-grade governance; negotiate national access to EuroHPC AI capacity and stand up a national research-compute access scheme on the NAIRR pattern; make FAIR data a condition of public funding; and reserve an explicit white-space allocation — ten to fifteen per cent — for what the plan cannot yet name.
Priority 5 — The cyber floor
In short. The regulatory, technical, and operational baseline that keeps the four functions defensible: national cyber strategy, the NIS2/CER machinery that drags critical operators up to a common floor, framework-based risk governance in every entity that matters, and an incident-response capability that has been exercised against the real threat landscape.
Why it ranks here. Below the functions because it is a means; immediately below them because without it they are a liability — a networked state without a cyber floor has simply automated its attack surface. The design logic is best read from the strategies themselves. The United States states the reframe openly: responsibility for cyber defence must shift from end users to the “most capable and best-positioned actors,” and market incentives must be reshaped to favour long-term security investment (White House, National Cybersecurity Strategy 2023) — cybersecurity as market design, not user exhortation. Its operational arm phrases the floor as three campaigns: address immediate threats, harden the terrain, drive security at scale through secure-by-design (CISA, Cybersecurity Strategic Plan FY2024–2026). The EU builds the same floor by directive: NIS2 imposes a union-wide cybersecurity baseline on essential and important entities across the critical sectors, paired with the CER regime obliging member states to identify and protect the critical entities themselves (EPRS, The NIS2 Directive; European Commission, Guidelines on the Resilience of Critical Entities) — and the first EU-wide stocktake of how member-state capability actually measures up now exists (ENISA, 2024 Report on the State of Cybersecurity in the Union). The UK shows what it means to apply the floor to government itself, hardening public services and government functions to 2030 rather than merely regulating the private sector (UK Cabinet Office, Government Cyber Security Strategy 2022–2030). The Czech Republic proves the small-state version is viable: a full national strategy with a sovereign cyber agency, NÚKIB, at its centre (NUKIB, National Cyber Security Strategy 2021–2025). And the organisational grammar is now standard: NIST CSF 2.0’s six functions — Govern, Identify, Protect, Detect, Respond, Recover — with the new Govern function deliberately placed at the centre of the wheel, making cyber risk a board-level governance discipline rather than an IT property (NIST, Cybersecurity Framework CSF 2.0).
The foresight questions & horizons. At 0–2 years: which essential and important entities under NIS2 scope are actually compliant, and which merely registered? Can the national CSIRT see across sectors, and has government exercised a multi-sector incident with the operators in the room? At 2–5 years: how does the threat landscape’s industrialisation — ransomware as a service, supply-chain compromise, AI-assisted intrusion (ENISA, Threat Landscape 2024) — change the floor’s height, and where does the cyber skills gap bind hardest, given the WEF’s evidence of a widening divide between organisations that can staff cyber resilience and those that cannot (WEF, Global Cybersecurity Outlook 2025)? At 5–10 years: what must be engineered for survivability rather than protection — the NIST SP 800-160 question of systems that continue their mission while compromised — and what does the post-quantum migration timetable demand of the state’s cryptographic estate now?
Signals & data to watch. The national position and pillar profile in the ITU’s Global Cybersecurity Index — its 2024 edition scores 194 countries across legal, technical, organisational, capacity-development, and cooperation pillars, finding countries strongest on legal measures and weakest on capacity development and technical measures (ITU, Global Cybersecurity Index 2024) — a free diagnosis of where the national floor sags. Incident and near-miss telemetry from the CSIRT, read against ENISA’s prime-threat taxonomy. Compliance depth (not registration counts) across NIS2-scope entities. Exercise performance: time-to-detect and time-to-recover in drills, trending over years. The cyber labour market. And the state’s own estate: the share of government systems under CSF-style governance with Govern-function accountability actually assigned.
Methods that fit. Regulate the floor on the NIS2/CER pattern — obligations on entities, identification of critical operators, enforcement with teeth. Govern every material entity on CSF 2.0, using Organizational Profiles to state current and target posture. Engineer the crown jewels — registers, crisis systems, the platforms under Priorities 1–4 — for cyber resiliency on SP 800-160 v2: assume compromise, design for degraded operation. Exercise on the Estonian lesson: the 2007 attacks made Tallinn the alliance’s cyber-defence school precisely because the response was institutionalised (NATO CCDCOE, Estonia 2007 Analysis). And buy security by design, using state procurement to move the market the way the US strategy prescribes.
The agentic engine. Sentinel agents fuse sensor, log, and threat-intelligence feeds into the national SOC picture, triaging at machine tempo. Exposure agents continuously inventory the state’s attack surface — assets, dependencies, vulnerabilities — against the asset map from Priority 3. Compliance agents read evidence from NIS2-scope entities and score control implementation, freeing scarce human auditors for the hard cases. Adversary-emulation agents run continuous purple-team campaigns against government systems, standing in for the red teams no mid-sized state can hire enough of. Patch-and-hygiene agents verify remediation at fleet scale. Humans own attribution, proportionate response, regulatory sanction, and the decision to disconnect anything that matters.
Institutional wiring & first moves. A single sovereign cyber agency on the NÚKIB pattern owns the floor: strategy, regulation, the national CSIRT, and government-systems assurance, reporting to the centre of government, with sectoral regulators enforcing in their domains. First moves: complete the NIS2/CER entity identification and publish the obligation map; mandate CSF 2.0 profiles for every ministry and critical operator with named Govern-function owners; stand up the national vulnerability-disclosure and threat-sharing machinery; run a full-scale, cross-sector cyber exercise linked to the Priority 1 national exercise; begin the post-quantum cryptographic inventory of the state’s estate; and put the agentic SOC stack into the national CSIRT — because the adversary already automates, and a floor patrolled at human speed is a floor in name only.
Priority 6 — Measurement and accountability
In short. The instrumentation that tells a government — and its parliament and public — whether the four functions are real: international benchmarks used as diagnostics rather than trophies, a national indicator set tied to the functions, and an accountability loop in which measured gaps change budgets.
Why it ranks here. Last in sequence, first in honesty. Every capability in this playbook can be simulated bureaucratically — a strategy published, a unit named, a portal launched — and the only defence against a state that grades its own homework is external, methodical measurement. The instruments exist, they are free, and together they triangulate almost the entire playbook. The UN E-Government Survey assesses all 193 member states through the EGDI — a composite of the Online Services Index, the Telecommunications Infrastructure Index, and the Human Capital Index, with a local-government counterpart (LOSI) and an e-participation index alongside (UN DESA, E-Government Survey 2024): the platform layer, measured. The ITU’s Global Cybersecurity Index scores 194 countries from 83 questions rolled into 20 indicators across five pillars, sorting them into five tiers from role-modelling to building; its 2024 finding — a global average of 65.7, strength in legal measures, weakness in capacity development and technical measures — is a template for reading a national profile against the floor described in Priority 5 (ITU, Global Cybersecurity Index 2024). The OECD’s Digital Government Index measures the foundations: six dimensions — digital by design, data-driven public sector, government as a platform, open by default, user-driven, proactiveness — each assessed across the policy cycle from strategy to monitoring; its 2023 finding that governments score best on strategic approach and worst on monitoring is this priority’s thesis stated as data (OECD, 2023 Digital Government Index). The World Bank’s GovTech Maturity Index covers 198 economies with 48 indicators across core government systems, service delivery, citizen engagement, and enablers — global average rising from 0.519 to 0.552 between 2020 and 2022, with citizen engagement the weakest area at 0.449 (World Bank, GovTech Maturity Index 2022 Update). Around these four sit the calibration set: the EU’s DESI indicators with published methodology (European Commission, DESI 2023 Methodological Note), the Network Readiness Index across technology, people, governance, and impact (Portulans Institute, NRI 2024), the Arup/Rockefeller City Resilience Index’s four-dimension, 52-indicator method as the reference for measuring resilience itself (Arup, City Resilience Index), and the WMO’s in-progress EW4All maturity index for early-warning capability (WMO, EW4All Factsheet). The reframe: these indices are commonly consumed as national vanity metrics. Used properly, they are a free external audit of the four sovereign functions, published on a cadence no domestic actor can suppress.
The foresight questions & horizons. At 0–2 years: where does the country sit, pillar by pillar and dimension by dimension, across EGDI, GCI, DGI, and GTMI — and which specific sub-indicators explain the gaps to the peer group it claims? At 2–5 years: which of the four functions still has no meaningful external measure — crisis-exercise performance and decision-infrastructure maturity are the persistent blind spots — and what national indicators must be built where the international ones stop, on the OECD’s anticipatory-governance self-assessment and the Arup resilience method? At 5–10 years: as the indices themselves evolve — the EGDI’s methodology has been revised continuously for two decades; the GCI is on its fifth edition — is the state tracking capability or chasing the metric, and does it have the discipline to keep measuring what the rankings do not reward?
Signals & data to watch. The country’s own sub-indicator movements, not headline ranks — the diagnosis lives two levels down. Divergence patterns: a high EGDI with a sagging GCI capacity-development pillar describes a state digitising faster than it can defend itself, which is a strategy risk, not a statistics curiosity. The monitoring facet of the OECD DGI, since that is where accountability failure shows first. Domestic delivery telemetry: service uptime and uptake, register data quality, exercise results, time-to-decision in cabinet process. And the honesty indicators no index captures: how many measured gaps changed a budget line last year — the only metric that proves the loop is closed.
Methods that fit. Build a national resilience scorecard on three layers. Layer one: the four international indices, decomposed to sub-indicator level, refreshed each cycle, benchmarked against a named peer group — for a Czech-scale state, the Baltics, the Nordics, Austria, and the Netherlands. Layer two: national function indicators — crisis-exercise metrics from Priority 1, the FIELD/SCOPES anticipatory self-assessment from Priority 2, dependency-coverage measures from Priority 3, roadmap-delivery measures from Priority 4 — using the Arup method’s discipline of qualitative and quantitative indicators per dimension. Layer three: the accountability loop — an annual state-of-resilience report to parliament pairing every red indicator with an owner and a funded remediation. Measurement without consequence is decoration.
The agentic engine. Index agents decompose each international benchmark release, map every sub-indicator to the responsible ministry, and draft the gap analysis the day results publish. Telemetry agents maintain the national scorecard from live administrative and operational data, replacing the annual data-call ritual. Peer agents monitor what the comparison group is doing — a Baltic neighbour’s leap on a GCI pillar is an early signal of a practice worth stealing. Audit agents verify claimed progress against evidence, the internal red team of the measurement function. Narrative agents draft the parliamentary report with every claim traceable to a measured value. Humans own target-setting, the interpretation of trade-offs, and the political act of publishing bad news — which is, in the end, what accountability means.
Institutional wiring & first moves. Joint ownership: the national statistical office guarantees methodology and data integrity; a centre-of-government delivery unit owns the scorecard and the parliamentary report; each function’s lead institution owns its indicators. First moves: commission the four-index decomposition and peer benchmark this quarter; adopt the national scorecard with no more than forty indicators tied to the four functions; legislate the annual state-of-resilience report; and rule, in standing orders, that no digital or resilience programme is approved without stating which indicator it moves — the sentence that converts measurement from commentary into steering.
The close: the first twelve months, through a Czech lens
A playbook that ends without a calendar is a wish. Here is the first-year sequence for a mid-sized EU state — written for the Czech Republic, portable to any of its peers — with the wiring named and the moves concrete. The premise throughout is the one the evidence base keeps repeating: Ukraine’s survival was prepared in the decade before February 2022 and enacted in days; Estonia’s data embassy went from concept to signed Luxembourg agreement because someone owned it; Finland’s model works because every vital function has a lead ministry and an exercise date. Ownership first, then motion.
The wiring. A National Resilience Council at the Office of the Government, chaired by the prime minister on the Finnish Security Committee pattern, with a small permanent secretariat — the centre-of-government unit that owns this playbook, the risk register, the exercise calendar, and the annual report to parliament. The Czech Statistical Office as data steward of the national map and the measurement layer, with new legal gateways to scanner, payments, and customs microdata. NÚKIB as the cyber floor’s owner — already the strongest institution on the board, per its own national strategy — extended with the agentic SOC mandate. The Ministry of the Interior and the integrated rescue system as crisis-operations owner; the Digital and Information Agency as owner of registers, identity, and continuity engineering; the Council for Research, Development and Innovation with the funding agencies as owner of the science roadmap; the Czech National Bank as nowcasting partner. One council, six named owners, one public scorecard.
The first moves.
Month 1 — stand up the Council and its secretariat, with a mandate letter assigning each of the six areas a named institutional owner and a twelve-month deliverable. No new ministry; a centre with convening power and a budget line.
Months 1–3 — publish the national risk register, on the UK model of acute risks with reasonable-worst-case scenarios, and audit the state against NATO’s seven baseline requirements and the four EW4All pillars. This is the gap map everything else prioritises against.
Months 2–4 — designate the continuity core: the ten registers and systems without which the Czech state cannot govern, on the Estonian ten-dataset pattern; begin engineering their replication and open negotiations for a data-embassy agreement with an allied host, Vienna Convention-style immunity included.
Months 2–5 — pre-draft the emergency instruments: the cloud-migration authorisation, emergency-procurement resolution, and data-sharing powers Ukraine had to improvise in the invasion’s first week, drafted now, debated calmly, and left ready for signature.
Months 3–6 — stand up the foresight-and-decision unit beside the strategy function at the Office of the Government: scanning agents running from day one, the OECD FIELD/SCOPES self-assessment completed, and two live policy questions — energy security and labour-market exposure to AI are the obvious Czech candidates — stress-tested against scenarios with ministers present.
Months 3–8 — build the first national dependency map: critical-functions taxonomy adopted, systemically important entities identified on the RAND method, and the first three EU-style in-depth reviews commissioned on the imports where Czech industry is most exposed; the Statistical Office and the central bank launch the scanner- and payments-data nowcast pilot in parallel.
Months 4–9 — close the cyber floor’s known gaps: NIS2/CER entity identification completed and published, CSF 2.0 profiles with named Govern-function owners mandated across ministries, the post-quantum inventory begun, and the GCI pillar profile answered gap by gap.
Months 6–10 — publish the research-infrastructure landscape analysis and the first national roadmap on ESFRI rules; designate two missions with Mazzucato-grade governance; secure EuroHPC AI-factory access and open a national research-compute scheme on the NAIRR pattern, with a white-space reserve written into the envelope.
Months 9–12 — run the national exercise: a compound scenario — cyber campaign plus infrastructure failure plus disinformation surge — with ministers in the room, operators at the table, the agentic common-operating-picture live, and the data-embassy restoration rehearsed. The exercise report goes to parliament unredacted wherever possible.
Month 12 — publish the first annual State of National Resilience report: the forty-indicator scorecard, the four-index benchmark, every red field paired with an owner and a funded fix — the document that turns the playbook from a programme into a habit.
Twelve months, no science fiction, nothing that a state of ten million cannot afford — most of it assembly of frameworks other institutions have already written, exercised by agent fleets that are already buildable, on data the state already holds. That is the closing argument, and it is an option-value argument. Building the four functions does not require knowing whether the next decade brings a war, a pandemic, a grid failure, or a quiet dependency trap. It requires deciding to be the kind of state that finds out early, decides quickly, knows what it has, and keeps discovering — the kind of state that can lose systems and still govern. The library’s verdict is that such states are made, not born: made in the unglamorous years before the crisis, by governments that treated resilience as a capability to be exercised rather than a report to be filed. The plan on the shelf saves no one. The rehearsed institution, wired to its data and its agents, with a human hand on every consequential decision — that is what sovereignty looks like when it is stressed. Build it now, while it is still cheap.




