FINLAND Trends and Developments Contributed by: Rosa Lång and Joona Linner, Lieke Attorneys Ltd
From a strategic and regulatory standpoint, this rein - forces the need for Finnish organisations to prioritise structured supply chain visibility, documented vendor risk assessments and resilient architecture design. Under Finland’s Cybersecurity Act implementing NIS 2, regulated entities are required to address supply chain risks explicitly, including through contractual safeguards, incident notification mechanisms and active oversight of critical ICT providers. Within parts of the Finnish financial sector, a discern - ible recalibration has emerged in response to these dependencies. While cloud adoption remains central to digital transformation, certain financial institutions have strengthened on-premise environments and invested in proprietary data centre capacity located in multiple domestic sites. This development reflects a reassessment of concentration risk, operational resil - ience requirements and jurisdictional exposure linked to hyperscale cloud models. The shift is not a retreat from cloud services but rather a hybridisation strat - egy: combining private infrastructure, geographically distributed Finnish data centres and carefully struc - tured outsourcing arrangements designed to satisfy supervisory expectations and ensure recoverability under stress scenarios. Finland has concurrently positioned itself as an attrac - tive jurisdiction for large-scale data centre invest - ments. International operators such as Google and Microsoft have expanded or announced significant data centre projects in Finland. These investments are underpinned by legal predictability, political stability, renewable energy availability and favourable climatic conditions. From a resilience perspective, growing domestic data centre capacity creates practical pos - sibilities to define and document where certain cate - gories of sensitive data are processed and stored. For public sector entities, critical infrastructure operators and regulated industries, the ability to demonstrate geographic control and supervisory transparency can carry both legal and strategic weight. The expansion of cybersecurity-intensive infrastruc - ture also intersects with Finland’s energy sector. Data centres are energy-intensive assets requiring stable, long-term power arrangements, increasingly tied to renewable generation. In certain cases, excess heat
produced by data centres has been integrated into district heating systems, creating new forms of indus - trial co-operation and a distinct business opportunity within the energy market. This convergence of digital and energy infrastructure heightens the importance of securing industrial control systems, grid manage - ment technologies and cross-sector dependencies. Cybersecurity in this context becomes not merely an IT compliance function, but a prerequisite for safe - guarding interconnected national infrastructure. These structural dependencies materially affect investment and transactional activity. Cybersecurity due diligence has become a central component of Finnish M&A processes. Buyers assess regulatory compliance under NIS 2-derived obligations, incident history, governance maturity and supply chain expo - sure. Identified deficiencies may influence valuation, purchase price adjustments or post-closing remedia - tion commitments. Representations and warranties relating to information security and data protection are negotiated with increasing specificity, and insurers providing warranty and indemnity coverage frequently scrutinise cyber risk management frameworks. Carve-out transactions in particular raise complex questions regarding the separation of shared IT envi - ronments, data migration and transitional service arrangements. Where infrastructure assets such as data centres, telecommunications networks or man - aged security service providers are involved, transac - tions may attract heightened regulatory attention due to national security or critical infrastructure considera - tions. In this environment, cybersecurity functions simul - taneously as a compliance obligation, a resilience measure and a transaction variable. For organisations operating in Finland, global and regional dependen - cies – whether cloud-based, infrastructural or energy- linked – must be analysed not only from a technical perspective but also through the lenses of govern - ance, regulatory exposure and strategic risk alloca - tion. Emerging Trends in Finland Several distinct threat trends have gained prominence in Finland’s cyber landscape in recent years. These
115 CHAMBERS.COM
Powered by FlippingBook