FINLAND’S
CYBER SECURITY
STRATEGY 2019
INTRODUCTION
The Finnish Cyber Security Strategy 2019 sets out
the key national objectives for the development
of the cyber environment and the safeguarding of
related vital functions.1 The strategy also aims to
support the development of accessible and reliable digital services and business development. The
strategy is based on the general principles of Finland’s cyber security strategy of 2013. Finland’s goal
remains to be among the top experts in cyber security internationally. The implementation of national cyber security is linked to the Security Strategy
of the Society (2017) and to the general principles
of preparedness and security coordination as described in the Security Strategy, as well as to the
principles of the competent authority. The strategy
and its implementation are also part of the implementation of the EU Cyber Security Strategy.
The need to update the cyber security strategy has
been influenced by significant changes in the operating environment and identified development
needs in the work at the national level. The development of the digital operating environment offers
new significant opportunities associated with, for
example, with platform economy, ecosystems, new
service production models and the development of
terminal equipment and telecommunications. On
the other hand, the operating environment faces
not only known risks, such as human mistakes, but
also evolving and changing threats that may endanger the vital functions of society, in particular cyber crime, espionage, state intelligence and various
forms of hybrid influencing. Several studies have
been conducted on the state of national cyber security in Finland.2 The proposals that were made as
a result were taken into account in this strategy and
they will also be taken into account in the development programme that will be prepared on the basis of the strategy.
The cyber security strategy 2019 will launch the
preparation of the National Cyber Security Development Programme. A new management coordination model supports the preparation of the development programme, taking into account the
planning and cooperation for cyber security for
public administration and the business community. The programme will improve the cyber security
situation picture and integrate planning with other
activities, such as economic planning.
1
Cyber security is understood as a space in which the cyber environment can be trusted and its functioning is secured (Vocabulary of
Cyber Security 2018). The cyber environment, on the other hand, can be understood in the same way as the digital environment, which
evolves rapidly as part of society and as services.
2
The VTT report on cyber competence in Finland (2016) presents 12 measures to further develop and strengthen cyber security competence in Finland. A report by Jyväskylä University and Aalto University on the current state of cyber security in Finland (2017) highlights the
identified shortcomings and development needs, and these have been divided into 12 areas. In addition, the National Audit Office of Finland
has published a report on the organisation of cyber protection in Finland (2017), containing five positions and four recommendations for
the development of the whole. The Ministry of Justice’s report on the preconditions for online voting in Finland (2017) examined how to
conduct online voting. The working group does not recommend the introduction of online voting in Finland, as its risks currently outweigh
its benefits. Prepared by Jyväskylä University and Aalto University, a report on the strategic management of cyber security in Finland (2018)
proposed measures to manage strategic cyber security in society and public administration, to manage major disruptions in the cyber environment and to measure the state of cyber security.
4