Cybersecurity 2026

FINLAND Trends and Developments Contributed by: Rosa Lång and Joona Linner, Lieke Attorneys Ltd

Introduction In today’s digital economy, cybersecurity has rapidly moved from being an IT specialist concern to a core business priority. For organisations operating in Fin - land, this shift reflects a combination of technological transformation, heightened regulatory expectations and a fast-evolving threat landscape. Traditional cyber risks have been compounded by geopolitical ten - sions, hybrid threats and increasingly sophisticated malware and ransomware campaigns. These dynam - ics ripple across sectors, and demand that boards, executives and risk owners understand not only the legal obligations but also the strategic and operational implications. Finland’s cybersecurity ecosystem reflects both mature preparedness and growing challenges. Fin - land was one of the first EU member states to imple - ment NIS 2, enshrined in its national Cybersecurity Act in spring 2025. At the same time, businesses face uncertainty about how future designations and national implementations – including those under the Critical Entities Resilience Directive (CER) and the Cyber Resilience Act (CRA) – will affect them. National authorities are increasingly visible in shaping expecta - tions, providing guidance and facilitating co-operation between government and private sector actors. Cybersecurity is not only a regulatory or operational issue in Finland – it is explicitly framed as a matter of national security and societal resilience at the highest political level. In the current Government Programme of the Finnish Government, cybersecurity and prepar - edness are embedded in broader objectives concern - ing comprehensive security, the resilience of critical infrastructure, and strengthening national defence and internal security. The programme emphasises improving cyber situational awareness, safeguarding critical digital infrastructure, reinforcing public-private co-operation, and ensuring that authorities have suf - ficient powers and resources to prevent and respond to cyber incidents. In addition, cybersecurity priorities are reflected in Finland’s long-term strategic planning documents, including the national cybersecurity strategy adopted by the Finnish Government and co-ordinated by the Ministry of Transport and Communications. The strat -

egy highlights securing digital public services, pro - tecting supply chains, enhancing incident response capabilities, and promoting cybersecurity compe - tence and workforce development. These objectives align closely with EU-level regulatory reforms and demonstrate that cybersecurity is treated as a cross- sectoral policy priority rather than a narrow technical domain. Operationally, the role of national authorities has expanded. The Finnish Transport and Communica - tions Agency, Traficom, through its National Cyber Security Centre (NCSC-FI), plays a central role in threat monitoring, incident response co-ordination, and guidance under NIS 2. Other sectoral regulators, as well as security authorities, contribute to supervi - sory and resilience-building efforts. The Government Programme explicitly supports strengthening these authorities’ mandates and improving information shar - ing between public and private actors. This high-level political prioritisation has practical consequences for organisations. Cybersecurity is increasingly integrated into risk management, busi - ness continuity planning, procurement requirements and board-level governance. Companies operating in critical sectors – such as energy, transport, finance, healthcare, digital infrastructure and public adminis - tration – must now navigate not only technical controls but also reporting obligations, supply chain security expectations and enhanced supervisory oversight. The clear message from the Finnish policy framework is that cybersecurity is a cornerstone of economic sta - bility, national security and trust in digital services. Regulatory Context: High-Level Overview Finland’s early adoption of NIS 2 signals strong national commitment to enhancing digital resilience, particularly for providers of essential services and dig - ital infrastructure. For organisations with operations or digital dependencies in Finland, this means an earlier transition into the new EU cybersecurity baseline than in many other member states. Beyond NIS 2, Finland is actively aligning with several major EU cybersecurity and resilience initiatives, each at varying stages of national implementation, as fol - lows.

112 CHAMBERS.COM

Powered by