Cybersecurity 2026

FINLAND Law and Practice Contributed by: Rosa Lång, Joona Linner, Toni Tainio and Oliver Lönnblad, Lieke Attorneys Ltd

ments on contractual provisions apply to contractual arrangements concerning ICT services supporting critical or important functions. These include, for example, precise quantitative and qualitative perfor - mance targets within the agreed service levels and exit strategies. 3.3 Key Operational Resilience Obligations The obligations imposed by DORA are subject to the proportionality principle. Financial entities’ size and risk profile, as well as the nature, scale and complexity of their operations, are considered when determining how certain rules in DORA are applied. DORA and the Commission Delegated Regulation (EU) 2024/1774 supplementing DORA include detailed rules on ICT risk management. The regulation requires financial entities to, inter alia, ensure the adequacy of ICT systems, identify ICT dependencies, implement an ICT business continuity policy and train their staff. The management bodies of financial entities are ulti - mately responsible for the implementation of appro - priate ICT risk management frameworks. Financial entities are required to implement an ICT- related incident management process to detect, man - age and notify ICT incidents. They are also required to classify incidents and cyber threats in accordance with the criteria set out in DORA, taking into consid - eration the severity, extent and types of impacts. DORA emphasises the obligation of financial entities to monitor and manage potential risks arising from ICT services provided by third parties. Among other requirements, financial entities must report to the competent authority at least annually on the number of arrangements concerning ICT services, and must submit, upon request, either the full register of infor - mation or the relevant parts thereof. In addition, finan - cial entities must have systematic processes in place for the selection and assessment of ICT service pro - viders. This includes a structured assessment of the content of contractual arrangements, an evaluation of whether the supervisory conditions for contracting are met, and an assessment of whether the ICT concen - tration risk is identified.

Incidents classified as major must be reported to the Finnish Financial Supervisory Authority within four hours of classification and within 24 hours of becom - ing aware of the incident. Within 72 hours of the ini - tial report, an intermediate report must be submitted, which must be updated in the event of status changes or upon request by the authority. Within one month of the intermediate report, a final report must be submit - ted, including root cause analysis, resolution details and impact assessment. 3.4 Operational Resilience Enforcement A special oversight framework applies to ICT ser - vice providers designated as critical by the Euro - pean Supervisory Authorities. This designation takes into account, for example, the number and systemic importance of entities relying on the services, the sub - stitutability of the services and the potential impacts of a failure in providing said services. One of the European Supervisory Authorities is appointed as Lead Overseer for each critical ICT ser - vice provider, to assess its risk management meas - ures. The Lead Overseer has broad powers to access information and carry out general investigations and inspections. The Lead Overseer’s powers extend to ICT service providers established outside the EU that provide services to financial entities within the EU. However, the powers outside the EU are subject to additional restrictions. If a critical ICT service provider does not comply with requests of the Lead Overseer within 30 calendar days, it may be subject to a periodic penalty payment that accrues daily. The penalty payment may amount to up to 1% of the average daily worldwide turnover of the critical ICT service provider in the preceding business year, and may be imposed for a maximum period of six months. In addition to the EU-level enforcement against criti - cal ICT service providers, all ICT service providers are subject to an obligation to provide information requested by the Financial Supervisory Authority under the Act on the Financial Supervisory Authority (878/2008, Laki Finanssivalvonnasta ). If an ICT ser - vice provider does not comply with the obligation, the Financial Supervisory Authority may impose a penalty

105 CHAMBERS.COM

Powered by