Publications of the Prime Minister’s Office 2024:13 4.6 Increased importance of shared situational awareness Besides political decision-making, the information gathering and influencing efforts of state-sponsored operators in the cyber environment target public authorities, vital functions of society, services and their supporting critical infrastructure, the knowledge capital of businesses and research institutions, and innovations. Hostile state-sponsored operators may also coordinate their operations to pursue their goals more effectively. The key aim of offensive cyberoperations is to disrupt or debilitate the operating capacity of critical infrastructure, such as energy and water supplies or healthcare. A further goal is usually to influence national government and the capacity for political decision-making. One of the most important lessons learned from the Russian invasion of Ukraine, for example, concerns the key importance of applying the capabilities of public authorities and businesses in the cybersecurity sector, and close cooperation between them in defending infrastructure operations against state-sponsored threats. The competent authorities oversee incident management in accordance with their respective duties and powers whenever cybersecurity is threatened. While cooperation currently functions well, there are indications that the operating conditions of public authorities are currently inadequate to effectively prepare for and combat the most serious cyber threats to national cybersecurity and national defence. Challenges to cybersecurity cooperation arise from the decentralisation of regulation and duties across multiple actors, the diversity of operating models applied in cooperation, and a lack of suitable shared information systems. Cybersecurity data from public services is also insufficiently shared at present with all public administrative and business actors from the perspectives of strategic, normative, resource and information guidance. An incident that compromises security in a cyber domain can simultaneously be an information security threat, a criminal offence, and a threat to national security and national defence that affects foreign and security policy. This means that investigating such an incident becomes the responsibility of several public authorities. Finnish provisions governing coordination and cooperation between public authorities in the cyber domain are nevertheless still inadequate, with too little consideration given to the special characteristics of the cyber domain when exchanging information and responding to cyber threats. Public authorities, businesses and organisations currently formulate situational awareness pictures for discharging their functions at varying levels, for differing purposes and with diverse content. Administrative branches also generate their own situational pictures for the needs of government. The National Cyber Security 20

Select target paragraph3