Publications of the Prime Minister’s Office 2024:13
It may not be possible to fully repair the damage caused by cyber incidents that
result in such outcomes as destruction or permanent disclosure of data. Some
small businesses have even had to discontinue operations after cybersecurity
risks materialised. Personal data breaches can have a massive impact on human
welfare and on the trust of individuals in the functioning of society. These prospects
further highlight the importance of adequately resourcing cybersecurity, and of
collaboration and shared operating methods.
4.2
The significant role of businesses in ensuring national
cybersecurity
Maintaining and developing the digital infrastructure and its services in Finland are
largely the responsibility of the business community. The national sector-specific
information exchange networks are dynamic. Business competitors actively share
cybersecurity information with one another and with the public sector.
A global trend that divides businesses and sectors can also be noticed in Finland,
with an increasingly clear gulf between organisations that have ensured their own
cybersecurity and those that have not. This is risky for society as a whole in an
interdependent world.
4.3
Wellbeing services counties and municipalities must
consider cybersecurity
The most significant recent reform in public administration was the establishment
of autonomous wellbeing services counties that began operating at the beginning
of 2023. This reform also had a considerable impact on the critical infrastructure
and public services of the regions that it affected. Wellbeing services counties
oversee their own services and related cybersecurity. The average standard of
cybersecurity in municipalities, by contrast, falls short of that realised in national
and regional administration, although municipal actors vary in size and resources.
Both wellbeing services counties and municipalities need more support to ensure
cybersecurity, for example in the form of centralised cybersecurity services. The
response to cyber threats must be seamless between actors of varying size, and it
must be prompt at all levels of public administration.
18