Publications of the Prime Minister’s Office 2024:13
4.6
Increased importance of shared situational awareness
Besides political decision-making, the information gathering and influencing efforts
of state-sponsored operators in the cyber environment target public authorities,
vital functions of society, services and their supporting critical infrastructure, the
knowledge capital of businesses and research institutions, and innovations. Hostile
state-sponsored operators may also coordinate their operations to pursue their
goals more effectively. The key aim of offensive cyberoperations is to disrupt or
debilitate the operating capacity of critical infrastructure, such as energy and water
supplies or healthcare. A further goal is usually to influence national government
and the capacity for political decision-making. One of the most important lessons
learned from the Russian invasion of Ukraine, for example, concerns the key
importance of applying the capabilities of public authorities and businesses in
the cybersecurity sector, and close cooperation between them in defending
infrastructure operations against state-sponsored threats.
The competent authorities oversee incident management in accordance with
their respective duties and powers whenever cybersecurity is threatened. While
cooperation currently functions well, there are indications that the operating
conditions of public authorities are currently inadequate to effectively prepare for
and combat the most serious cyber threats to national cybersecurity and national
defence. Challenges to cybersecurity cooperation arise from the decentralisation
of regulation and duties across multiple actors, the diversity of operating models
applied in cooperation, and a lack of suitable shared information systems.
Cybersecurity data from public services is also insufficiently shared at present with
all public administrative and business actors from the perspectives of strategic,
normative, resource and information guidance.
An incident that compromises security in a cyber domain can simultaneously
be an information security threat, a criminal offence, and a threat to national
security and national defence that affects foreign and security policy. This means
that investigating such an incident becomes the responsibility of several public
authorities. Finnish provisions governing coordination and cooperation between
public authorities in the cyber domain are nevertheless still inadequate, with too
little consideration given to the special characteristics of the cyber domain when
exchanging information and responding to cyber threats.
Public authorities, businesses and organisations currently formulate situational
awareness pictures for discharging their functions at varying levels, for differing
purposes and with diverse content. Administrative branches also generate their
own situational pictures for the needs of government. The National Cyber Security
20