FINLAND Law and Practice Contributed by: Rosa Lång, Joona Linner, Toni Tainio and Oliver Lönnblad, Lieke Attorneys Ltd
sory board, the managing director and their respective deputies). The competent authorities may restrict indi - viduals from acting in the top management of essen - tial entities for up to five years if they fail to discharge this responsibility. However, this restriction does not apply to partnerships. Complying with the requirements of the Cybersecurity Act largely also ensures compliance with the cyberse - curity requirements set out for critical entities under the Act on the Protection of Infrastructure Critical to Society and Improvement of Resilience. In addition to the cybersecurity requirements, the latter Act impos - es numerous other requirements to ensure resilience against other threats, such as natural disasters, large- scale accidents and public health crises. 2.3 Incident Response and Notification Obligations The Cybersecurity Act and Chapter 4a of the Act on Information Management in Public Administration impose similar incident response and notification obli - gations. An initial notification of a significant incident must be submitted to the competent authority within 24 hours of becoming aware of the incident, and a follow-up notification within 72 hours. An incident is considered significant if it has caused or is capable of causing either severe operational disruption to ser - vices or financial loss for the entity concerned, or con - siderable material or non-material damage to other natural or legal persons. The initial notification must include: • confirmation of the detection of a significant inci - dent; • an indication of whether the incident is suspected of being caused by a criminal or other unlawful or malicious act; and • information regarding any potential cross-border impacts. The follow-up notification must include an assess - ment of the nature, severity and impacts of the inci - dent, indicators of compromise, where available, and any updates to the information provided in the initial notification.
Within one month of the follow-up notification, a final report detailing the incident must be submitted to the competent authority. This must include: • the severity and impacts of the incident; • the type of threat or root cause that likely triggered the incident; • applied and ongoing mitigation measures; and • possible cross-border impacts. If the incident is still ongoing when the final report should be submitted, or at the request of the com - petent authority, an interim report must be submitted with relevant status updates and progress on handling the incident. In addition to the notification obligations vis-à-vis the competent authorities, the recipients of the service must be notified of the significant incident if it is likely to hinder delivery of the services. The affected recipi - ents of the services must also be notified of any sig - nificant cyber threat and mitigation measures. The competent authority forwards the incident notifi - cations and reports it has received to the CSIRT oper - ating under Traficom. The affected entity or authority may request guidance and operational advice on miti - gation measures from the CSIRT. The competent authority itself is subject to separate notification obligations arising from incident reports, depending on the nature of the incident. These obli - gations include, for example, an obligation to notify the Data Protection Ombudsman where the incident involves a personal data breach. Where a significant incident notification is submitted by a critical entity under the Act on the Protection of Infrastructure Criti - cal to Society and Improvement of Resilience, the receiving authority must forward it to the competent authority under that Act, which is, however, largely the same as under the Cybersecurity Act. The NCSC-FI serves as the single point of contact in Finland facilitating cross-border co-operation and co- ordination between competent authorities in different EU member states. It also submits regular summary reports on significant incidents, cyber threats and near misses to ENISA.
103 CHAMBERS.COM
Powered by FlippingBook