Publications of the Prime Minister’s Office 2024:13 The response to cyber threats must be comprehensive, long-term and timely. This requires extensive and determined application of measures that strengthen cybersecurity and prevent cyber threats. Finland responds to the challenges of the geopolitical situation for the cyber environment through active cyber diplomacy, cyber defence and cybersecurity measures, both independently and as part of multilateral activities. Finland must also ensure national sovereignty in the cyber domain. The opportunities and capacity of societal actors to respond to cyber threats must be assured in all circumstances. For society to be able to function without incidents, organisations must be capable of swiftly recovering from cyber incidents and attacks, and restoring their systems promptly and securely. Operative authorities are required to prevent, respond to and investigate cyber threats, and to generate situational awareness concerning them. The nature of cyber threats imposes requirements on cooperation between authorities. The responses to, and measures taken against state-sponsored cyber operations differ from those that are applied against regular cyber threats. Responding to statesponsored hostile cyber operations by imputing criminal liability to the perpetrator is not necessarily the most effective method. Threat responses combine various methods and measures in the cyber domain as a whole and at varying levels of operation, and assessing perspectives of international law. The threats of a continually evolving cyber domain require comprehensive specification of the roles and responsibilities of various actors in order to respond to cyberattacks. The ability to apply a comprehensive and broad range of methods is particularly highlighted in responding to state-sponsored operations and serious cybercrime. Specifying roles and responsibilities solely in terms of technical and operational protection of operations and infrastructure does not suffice in a new operating and threat environment. It must also be possible to respond to hostile operations across the operating environment as a whole. Besides applying regular measures to ensure resilience and information security, the target-oriented approach must be supplemented to incorporate more extensive and comprehensive measures. It no longer suffices to protect information systems through information security alone, for example, and new methods, such as international information exchange, sanctions or active cyber defence, are instead required. 37

Select target paragraph3