Introduction Finland’s first Cyber Security Strategy was published on 24 January 2013 in the form of a Government Resolution. It defined the central objectives and policies for meeting challenges in the cyber domain and for securing its functioning. The Strategy described the vision and strategic policy settings of cyber security and noted that an implementation programme was needed to execute the strategic policy settings and achieve the desired end state of the Cyber Security Strategy Vision. On 11 March 2014 the Security Committee adopted the first Implementation Programme and since then has regularly evaluated the realisation of the Programme. The new Implementation Programme for 2017–2020 addresses the development of cyber security within the service complex comprising the state, counties, municipalities, the business sector and the third sector in which the individual citizen is the customer. The business community provides most digital services and their cyber security through international service complexes and networks. Since the publication of the Cyber Security Strategy the operating environment of the cyber domain has changed as a result of new service production models and technologies and the new threats directed at them. According to the February 2017 Government research project “Finland’s cyber security: the present state, vision and the actions needed to achieve the vision” (later: Finland’s cyber security report 2017), the most noteworthy cyber threat trends in recent years have been the growth of ransomware, the exploitation of vulnerabilities, threats against devices as well as hacking business operations or breaches of personal data. Also, hoaxes, phishing, denial-of-service attacks and targeted attacks are still relevant threats. The most attacked branches particularly include the health sector, manufacturing and production, banking and financing, the public administration as well as the transport and haulage sector. We will likely see increasingly sophisticated cyber-attacks and more leaks of information in the future. The volume of devices connected to the network is increasing, which means that future attackers will gain a vast amount of new targets in conjunction with the expansion of the Internet of Things. Moreover, Finland’s cyber security report 2017 stated that ‘even though in recent years Finland has better grasped the political nature of matters in the cyber domain and the need for political awareness in reaching the Cyber Security Vision, the strengthening of political commitment can still be considered as a goal. Political commitment is also about promoting and communicating the national ambition (Cyber Security Vision) internationally’. According to the report Finland’s international action in cyber related matters needs further strengthening: ‘Finland needs to prepare a distinct “cyber agenda”, i.e. publicly declare the goals it aims to advance in international cooperation’. On the basis of evaluations provided by administrative branches, the business community, the academia and NGOs the Secretariat of the Security Committee prepared an assessment on the progress of the Implementation Programme for Finland’s Cyber 4 The Security Committee

Select target paragraph3