FINLAND Trends and Developments Contributed by: Rosa Lång and Joona Linner, Lieke Attorneys Ltd
State-sponsored cyber operations Finland’s highly digitalised public administration, advanced industrial base and strategic position at the EU’s external border materially influence its cyber risk profile. For legal practitioners advising boards and executive management, it is essential to recog - nise that cyber risk in Finland goes significantly fur - ther than sole opportunistic criminality; it increasingly intersects with national security considerations, sanc - tions compliance, supply chain integrity and regula - tory oversight. From a risk advisory perspective, Finland’s advanced digital infrastructure, open economy and geopoliti - cal location render it an attractive target for state- sponsored and state-aligned cyber activity. Finnish authorities, including the NCSC-FI operating under Traficom, have repeatedly highlighted the presence of advanced persistent threat (APT) activity directed at public administration, critical infrastructure and high- technology sectors. Such campaigns are typically characterised by: • extended dwell times – threat actors remain undetected within networks for prolonged periods, enabling strategic intelligence gathering and the preparation of follow-on activity; • multi-stage attack chains, combining reconnais - sance, credential harvesting, exploitation of vulner - abilities, lateral movement and data exfiltration before any overt disruption occurs; and • targeted disruption and influence, including attempts to interfere with critical infrastructure, logistics chains, telecommunications and energy supply. Unlike opportunistic cybercrime, state-linked opera - tions are persistent, adaptive and strategically moti - vated. From a governance standpoint, this requires organisations to move beyond traditional perimeter- based security models and to adopt continuous moni - toring, zero-trust architectures and board-level cyber risk oversight, aligned with enterprise risk manage - ment frameworks.
• Cyber Resilience Act: the CRA establishes security requirements for products with digital components. Some provisions have begun to apply, and staged implementation of broader requirements is under - way, with full application expected by 2027. • Critical Entities Resilience Directive: the CER expands obligations for operators of critical ser - vices across sectors. However, the formal list of nationally designated entities under CER is not yet finalised in Finland and is expected by mid 2026. • Digital Operational Resilience Act (DORA): DORA introduces harmonised digital resilience require - ments for the financial sector. Finland has a sig - nificant financial and fintech ecosystem, including banks, payment service providers and emerging digital finance platforms. National legislative adjust - ments and supervisory practices are progressing alongside EU-wide application timelines, with authorities increasingly expecting firms to demon - strate robust operational resilience, third-party risk management and incident response capabilities. • Network Code on Cybersecurity (NCCS) for Elec - tricity: this EU network code sets sector-specific cybersecurity standards for cross-border electricity flows. Alongside legislative instruments, the National Cyber Security Centre, Finland (NCSC FI) plays an integral role in threat monitoring, incident response co-ordina - tion and stakeholder engagement. NCSC FI’s regular advisories and threat assessments reinforce expecta - tions that organisations understand, prepare for and mitigate risks beyond basic compliance. While Finland’s legal frameworks already establish obligations and a certain level of clarity regarding requirements, businesses should anticipate ongoing developments, particularly as scope definitions are refined and implementation timelines are clarified. Geopolitical Drivers of Cyber Risk Finland’s cybersecurity landscape cannot be sepa - rated from its geopolitical context. Proximity to global flashpoints and active state-level cyber actors ele - vates the risk profile for organisations across sectors. The following three interconnected geopolitical drivers are particularly relevant.
113 CHAMBERS.COM
Powered by FlippingBook