Publications of the Prime Minister’s Office 2024:13
Finland is a constructive, reliable and capable NATO ally, maintaining a strong
national defence capability as part of shared NATO deterrence and defence, and
actively participating in the development of NATO cyber defence. As a NATO
member, Finland seeks to work at the core of cyber capability building with a view
to becoming an important provider of cybersecurity and cyber defence solutions
within the alliance.
As a member of the military alliance, Finland will continue to promote the
development of NATO cyber defence and apply alliance capabilities. This is
supported by systematic development and maintenance of cyber defence as
part of national cybersecurity. Finnish infrastructure will be developed as part of
alliance infrastructure, boosting cooperation and cyber defence. Most of the seven
baseline requirements of resilience defined by NATO also impose requirements for
developing national cybersecurity.
It is important to harmonise national EU and NATO views on cybersecurity
and cyber defence. Mutual compatibility of EU and NATO cyber operations
complements and reinforces both international cybersecurity and Finnish national
cybersecurity.
Shared situational awareness based on information exchange as a basis for
measures
Close cooperation, establishing shared situational awareness, and ensuring
conditions for acquiring information are crucial for realising the target state. Shared
situational awareness based on information exchange enables public authorities,
businesses and organisations to cooperate effectively and reliably in the cyber
domain. This increases trust and supports the realisation of sectoral responsibilities.
Information gathering should be systematised with respect to the cyber domain
in order to form a more comprehensive understanding of serious cyber threats
against Finland. Specifying and legislating the conditions and parties involved is a
requirement for expanded information exchange, as is reassessing the grounds for
current restrictions. Information exchange must also be enhanced by harmonising
and specifying current statutory interpretations and modifying shared operating
models.
Information exchange must be adequate, trust-building, balanced, conformed
to purpose, and based on the right to disclose and receive information and on
an interest in sharing and an authorisation to share information between parties
that need it. Situational understanding should enable producers or custodians
34