Cybersecurity 2026

FINLAND Trends and Developments Contributed by: Rosa Lång and Joona Linner, Lieke Attorneys Ltd

Hybrid threats and information operations Modern cyber threats in Finland are not limited to purely technical intrusions. They increasingly form part of broader hybrid operations, combining cyber disruption with disinformation, social engineering, physical reconnaissance and influence campaigns. Finnish authorities have publicly emphasised that the threat environment must be assessed holistically, par - ticularly in light of Finland’s NATO membership and its strategic geographic position. From a legal risk perspective, these hybrid activities are designed not only to exploit technical vulnerabili - ties but also to: • undermine organisational trust by creating uncer - tainty about the integrity of systems, leadership and decision-making; • erode customer and stakeholder confidence, particularly in regulated sectors such as energy, finance, telecommunications and healthcare; and • destabilise public perception during sensitive peri - ods such as elections, geopolitical crises or major infrastructure developments. Recent media reporting in Finland has highlighted inci - dents involving drones and unidentified third parties operating in or near security-sensitive areas, includ - ing critical infrastructure and restricted zones. While investigations and attributions are matters for the competent authorities, these cases illustrate the con - vergence between physical and digital risk domains. Drone overflights near energy facilities, ports or other strategic sites may serve reconnaissance purposes, test response protocols or form part of a broader intelligence-gathering effort that can subsequently support cyber intrusion or influence operations. For organisations, this convergence has concrete compliance implications. The traditional separation between “cybersecurity” and “physical security” is increasingly artificial. Boards are expected to ensure that: • physical access controls and surveillance policies are aligned with cybersecurity risk management;

• incident response plans address hybrid scenarios involving both IT compromise and physical disrup - tion; and • communications strategies are prepared in advance to mitigate reputational harm arising from disinformation or co-ordinated media amplification. Campaigns targeting supply chains or public services may therefore pursue broader political or economic leverage rather than immediate financial gain. For example, disruption of logistics chains, telecommuni - cations infrastructure or energy distribution – whether through cyber means, physical probing or co-ordinat - ed narrative operations – can generate effects that extend well beyond the directly affected entity. In the Finnish regulatory context, such hybrid risks intersect with obligations under the national Cyber - security Act (implementing NIS 2), sector-specific resilience requirements and broader national security considerations. Authorities including Traficom and other security actors operating under the framework of the Finnish Government’s comprehensive security model increasingly emphasise cross-sector informa - tion sharing and preparedness for combined cyber- physical incidents. For legal advisers, the practical takeaway is clear: modern cyber risk assessments in Finland must extend beyond technical controls and regulatory tick- box exercises. They must incorporate hybrid threat modelling, crisis communications planning, supply chain due diligence and board-level oversight capa - ble of addressing incidents that simultaneously affect systems, facilities, personnel and public trust. Global and regional dependencies No organisation operates in isolation. Cloud platforms, third-party software providers and multinational ser - vice vendors create interconnected risk surfaces. An incident affecting a widely used service can rapidly cascade through domestic ecosystems. Past global supply chain compromises have demonstrated how vulnerabilities embedded in third-party code or infra - structure can be leveraged at scale, exposing other - wise well-managed organisations to systemic disrup - tion.

114 CHAMBERS.COM

Powered by