Publications of the Prime Minister’s Office 2024:13
The response to cyber threats must be comprehensive, long-term and timely.
This requires extensive and determined application of measures that strengthen
cybersecurity and prevent cyber threats. Finland responds to the challenges of the
geopolitical situation for the cyber environment through active cyber diplomacy,
cyber defence and cybersecurity measures, both independently and as part of
multilateral activities. Finland must also ensure national sovereignty in the cyber
domain.
The opportunities and capacity of societal actors to respond to cyber threats must
be assured in all circumstances. For society to be able to function without incidents,
organisations must be capable of swiftly recovering from cyber incidents and
attacks, and restoring their systems promptly and securely.
Operative authorities are required to prevent, respond to and investigate cyber
threats, and to generate situational awareness concerning them. The nature of
cyber threats imposes requirements on cooperation between authorities. The
responses to, and measures taken against state-sponsored cyber operations differ
from those that are applied against regular cyber threats. Responding to statesponsored hostile cyber operations by imputing criminal liability to the perpetrator
is not necessarily the most effective method. Threat responses combine various
methods and measures in the cyber domain as a whole and at varying levels
of operation, and assessing perspectives of international law. The threats of a
continually evolving cyber domain require comprehensive specification of the roles
and responsibilities of various actors in order to respond to cyberattacks.
The ability to apply a comprehensive and broad range of methods is particularly
highlighted in responding to state-sponsored operations and serious cybercrime.
Specifying roles and responsibilities solely in terms of technical and operational
protection of operations and infrastructure does not suffice in a new operating
and threat environment. It must also be possible to respond to hostile operations
across the operating environment as a whole. Besides applying regular measures
to ensure resilience and information security, the target-oriented approach must
be supplemented to incorporate more extensive and comprehensive measures.
It no longer suffices to protect information systems through information security
alone, for example, and new methods, such as international information exchange,
sanctions or active cyber defence, are instead required.
37