Introduction
Finland’s first Cyber Security Strategy was published on 24 January 2013 in the form
of a Government Resolution. It defined the central objectives and policies for meeting
challenges in the cyber domain and for securing its functioning. The Strategy described
the vision and strategic policy settings of cyber security and noted that an implementation programme was needed to execute the strategic policy settings and achieve the
desired end state of the Cyber Security Strategy Vision. On 11 March 2014 the Security
Committee adopted the first Implementation Programme and since then has regularly
evaluated the realisation of the Programme.
The new Implementation Programme for 2017–2020 addresses the development of
cyber security within the service complex comprising the state, counties, municipalities, the business sector and the third sector in which the individual citizen is the customer. The business community provides most digital services and their cyber security
through international service complexes and networks.
Since the publication of the Cyber Security Strategy the operating environment of the
cyber domain has changed as a result of new service production models and technologies and the new threats directed at them. According to the February 2017 Government research project “Finland’s cyber security: the present state, vision and the
actions needed to achieve the vision” (later: Finland’s cyber security report 2017), the
most noteworthy cyber threat trends in recent years have been the growth of ransomware, the exploitation of vulnerabilities, threats against devices as well as hacking
business operations or breaches of personal data. Also, hoaxes, phishing, denial-of-service attacks and targeted attacks are still relevant threats. The most attacked branches
particularly include the health sector, manufacturing and production, banking and financing, the public administration as well as the transport and haulage sector. We will
likely see increasingly sophisticated cyber-attacks and more leaks of information in the
future. The volume of devices connected to the network is increasing, which means
that future attackers will gain a vast amount of new targets in conjunction with the
expansion of the Internet of Things.
Moreover, Finland’s cyber security report 2017 stated that ‘even though in recent years
Finland has better grasped the political nature of matters in the cyber domain and the
need for political awareness in reaching the Cyber Security Vision, the strengthening
of political commitment can still be considered as a goal. Political commitment is also
about promoting and communicating the national ambition (Cyber Security Vision)
internationally’. According to the report Finland’s international action in cyber related matters needs further strengthening: ‘Finland needs to prepare a distinct “cyber
agenda”, i.e. publicly declare the goals it aims to advance in international cooperation’.
On the basis of evaluations provided by administrative branches, the business community, the academia and NGOs the Secretariat of the Security Committee prepared
an assessment on the progress of the Implementation Programme for Finland’s Cyber
4
The Security Committee