FINLAND Law and Practice Contributed by: Rosa Lång, Joona Linner, Toni Tainio and Oliver Lönnblad, Lieke Attorneys Ltd
3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation DORA is a directly applicable EU regulation that also applies in Finland. The financial sector operational resilience legislation applicable in Finland is largely consolidated under DORA. The scope of DORA encompasses a comprehensive list of 21 categories of entities in the financial sector, including third-party ICT service providers designated as critical. In Fin - land, only pension insurance companies are excluded from the scope of DORA, and micro enterprises are exempt from many of its requirements. For the most part, DORA applies uniformly to all financial institu - tions providing services in the EU. DORA does not apply directly to ICT service providers other than those designated as critical. Instead, financial entities are responsible for ensuring that the ICT service pro - viders and systems they use comply with the require - ments of DORA. 3.2 ICT Service Provider Contractual Requirements The definition of an ICT service provider in DORA is broad and encompasses all entities and other under - takings providing any digital and data services to financial entities through ICT systems. It includes ser - vices like cloud storage and software development, as well as hardware services such as the provision of firmware updates. The contractual requirements in DORA include detailed lists of mandatory contractual elements that must be included in all ICT service contracts and in contracts for ICT services supporting critical or important func - tions. Required elements include, for example: • access to data in case of an ICT service provider’s insolvency; • specifying the locations of data storage and pro - cessing; and • terms on security measures and data protection. Contracts must clearly allocate the rights and obliga - tions of each party, and these must be documented in one written document. More extensive require -
It should also be noted that, where an incident occurs but is not significant, a voluntary notification may be submitted to the competent authorities. In such cases, the deadlines prescribed by the Cybersecurity Act do not apply. Voluntary notifications may also be submit - ted by entities that are not subject to the Cybersecu - rity Act. 2.4 State Responsibilities and Obligations Traficom provides support, guidance and supervision on information security issues and the implementation of privacy protection in electronic communications. It also maintains national cybersecurity situational awareness. The overall objective of the activities of the NCSC-FI is to promote and ensure the information security of information systems and data communica - tion arrangements. The Finnish national CSIRT unit also operates under the NCSC-FI. The responsibilities of the CSIRT are defined in the Cybersecurity Act and include moni - toring and analysing cyber threats and vulnerabilities, providing guidance and recommendations, and sup - porting the maintenance of national cybersecurity situational awareness. The CSIRT may conduct proactive vulnerability scans of publicly available networks and IT systems to detect vulnerable and unsafely configured networks and IT systems. Furthermore, entities can request the CSIRT to conduct a targeted scan of their networks or IT systems. Methods permitted in targeted scans are subject to considerably fewer restrictions than in proactive scans. The CSIRT can facilitate a voluntary exchange of cybersecurity information between itself and any entities. Participating entities can share relevant information considered confidential under the Act on Electronic Communications Services. The CSIRT also co-ordinates the disclosure of vulnerabilities by receiving notifications of vulnerabilities, contacting entities affected by vulnerabilities and co-ordinating the management of vulnerabilities affecting multiple entities. It also reports, and advises entities on report - ing, vulnerabilities to the European vulnerability data - base.
104 CHAMBERS.COM
Powered by FlippingBook