Cybersecurity 2026

FINLAND Law and Practice Contributed by: Rosa Lång, Joona Linner, Toni Tainio and Oliver Lönnblad, Lieke Attorneys Ltd

• energy – supervision shared between the Energy Authority and the Finnish Safety and Chemicals Agency (Tukes); • transport – Traficom; • banking and financial market infrastructures – the Financial Supervisory Authority; • health – the Finnish Supervisory Authority; • drinking water supply and distribution – the Eco - nomic Development Centre; • wastewater – the Economic Development Centre; • digital infrastructure – Traficom; • ICT service management – Traficom; • space – Traficom; and • public administration – Traficom (provisions are contained in Section 4a of the Act on Information Management in Public Administration). (Other) critical sectors (Annex II to the Cybersecurity Act) The following sectors are also deemed to be critical, subject to the oversight of the listed authority: • postal and courier – Traficom; • waste management – the Finnish Supervisory Authority; • the manufacture, production and distribution of chemicals – Tukes; • the manufacture of medical devices and in vitro diagnostic medical devices, computer, electronic and optical products (C26 of NACE Rev.2), electri - cal equipment (C27 of NACE Rev.2), machinery and equipment (C28 of NACE Rev. 2), motor vehi - cles, trailers and semi-trailers C29 of NACE Rev.2), and other transport equipment (C30 of NACE Rev.2) – supervision shared between the Finnish Medicines Agency (Fimea) and Tukes; • digital service providers – Traficom; and • research organisations – Traficom. 2.2 Critical Infrastructure Cybersecurity Requirements The main responsibilities set out for important and essential entities under the Cybersecurity Act and for public administration falling within the scope of Chapter 4a of the Act on Information Management in Public Administration centre on risk management to prevent or minimise the impact of incidents on oper - ations, operational continuity, service recipients and

other services. Generally, entities and authorities are required to identify, assess and manage risks to the security of the communications networks and IT sys - tems that they use. The risk management measures must be up-to-date, appropriate and sufficient in rela - tion to the risks and the significance of the network or system to the operations and services of the entity or authority. The Cybersecurity Act imposes the following obliga - tions on entities within its scope. • Registration – entities must assess independently whether they fall within the scope of the Cyberse - curity Act and, if so, register with the competent authority responsible for their sector. • Risk management – as described below. • Reporting – as described in 2.3 Incident Response Entities are required to implement an up-to-date cybersecurity risk management operating model to protect their communications networks and IT sys - tems against incidents and to mitigate their poten - tial impacts. The risk management operating model must take all relevant risk factors into account and define the objectives, procedures and responsibilities of cybersecurity risk management, as well as the risk management measures. The Cybersecurity Act and Chapter 4a of the Act on Information Management in Public Administration include a 12-point list of factors that must, at a mini - mum, be addressed in the risk management operating model and the risk management measures. The risk management measures may be technical, operational or organisational, but they must be proportionate to the scope of the operations, the expected impacts of an incident, the risk susceptibility of the networks and systems, the likelihood and severity of incidents, and the costs of the measures and their technical feasibil - ity. and Notification Obligations . Risk Management Obligations Responsibility for the implementation and supervi - sion of risk management under the Cybersecurity Act is imposed on the top management of important or essential entities (the board of directors, the supervi -

102 CHAMBERS.COM

Powered by