FINLAND Law and Practice Contributed by: Rosa Lång, Joona Linner, Toni Tainio and Oliver Lönnblad, Lieke Attorneys Ltd
Lieke Attorneys Ltd Aleksanterinkatu 11 00100 Helsinki Finland Tel: +358 9 6844 410 Fax: +358 9 6844 4141 Email: attorneys@lieke.com Web: lieke.com
1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy A Changing Cybersecurity Landscape in Finland Historically, the Finnish regulatory framework for cybersecurity has been relatively fragmented, with separate specialised regulations for different indus - tries and sectors. Cybersecurity matters were treated as sector-specific operating requirements, and were supervised independently by the relevant sector-spe - cific authorities. In 2024, the Finnish Cybersecurity Strategy was updated to better address technological advance - ments and shifts in the geopolitical landscape that cut across sectors more than ever before. According to the Cybersecurity Strategy, the current cybersecu - rity situation in Finland is relatively stable; however, given that Finnish society is almost entirely digitalised, cybersecurity requires constant attention, to ensure trust in the safety and reliability of digital services. The Cybersecurity Strategy recognises cybersecurity not only as a cornerstone of modern society but also as a vital matter of national security. The Four Pillars of Cybersecurity Development The Cybersecurity Strategy is built on four distinct pil - lars, each setting out sub-objectives defining the tar - get state for national cybersecurity and guiding future legislation and other public sector activity.
Pillar I: competence, technology, and research, development and innovation Under the first pillar, cybersecurity competence is regarded as a fundamental civic skill. A high level of competence will require strengthening cybersecurity education in schools, universities, non-governmen - tal organisations and workplaces. Furthermore, the objectives under the first pillar include promoting business competitiveness in the cybersecurity sector and Finland’s role as a leader in the implementation of emerging and disruptive technologies. Pillar II: preparedness The second pillar emphasises cyber resilience and operational reliability across society. Under this pillar, public authorities and private sector organisations are expected to define and apply cybersecurity require - ments to the information systems they use, procure and maintain, and to allocate sufficient resources to meet these requirements and develop preparedness capabilities. The pillar also encourages collaboration and dialogue with the EU and NATO to promote pre - paredness and share best practices. Pillar III: co-operation The third pillar further encourages international col - laboration and dialogue. In addition, the strategy emphasises well-co-ordinated and smooth co-oper - ation between authorities based on shared situational awareness, as well as the use of centralised cyberse - curity services. Pillar IV: response and countermeasures The final pillar aims to ensure timely responses to cyber threats and to safeguard national sovereignty.
97 CHAMBERS.COM
Powered by FlippingBook