Alessandro AleddaInsider Threat and Risk

ITER/FIFinland

What the record establishes for Finland: the bodies an insider event is reported to, the channel each takes, and the act that transposes the NIS2 Directive, Directive (EU) 2022/2555.

Recipients
4 of 4
Reporting address
Recorded
NIS2
In force 8 April 2025, by § 47
Terms moved
Yes
Sources cited
5
Last read
3 SEPTEMBER 2026

Recipients

Reached underBodyChannelSource
Data protection authorityGDPR, article 33Office of the Data Protection Ombudsman reportededpb members
CSIRT or competent authorityNIS2, article 23The supervising authority, which is sectoral under § 43. Traficom's Kyberturvallisuuskeskus is the single point of contact under § 18. reported

https://eservices.traficom.fi/ContactForms/form/NIS2-ilmoituschecked 2026-09-03

Not set by the act. The Cyber Security Centre runs a NIS2 incident reporting application which takes the initial report, the follow-up and the final report, and forwards every notification to its own CSIRT unit as well as to the sector's supervising authority.

fi kyberturvallisuuslaki 124 2025 · traficom nis2 ilmoitus
Financial supervisorDORA, article 19Finanssivalvonta reportedeba competent authorities
Market authorityMAR, article 17Finanssivalvonta (FIN-FSA) reportedesma mar nca

Transposition of NIS2 binding

ActKyberturvallisuuslaki 124/2025
In force8 April 2025, by § 47. Given 4 April 2025, published 7 April 2025.
RecipientThe supervising authority, which is sectoral under § 43. Traficom's Kyberturvallisuuskeskus is the single point of contact under § 18.
Moves a termYes. The anchor is detection, not awareness. Section 11 reads «Ensi-ilmoitus on tehtävä 24 tunnin kuluessa merkittävän poikkeaman havaitsemisesta ja jatkoilmoitus 72 tunnin kuluessa merkittävän poikkeaman havaitsemisesta»: both stages run from havaitseminen, the detecting of the significant incident, where the Directive runs them from having become aware of it. The phrase for coming to know, tuli tietoon, does not appear in the act at all. The final report keeps the Directive's shape: within a month of the follow-up report, or for a long-running incident within a month of the end of its handling, with an interim report at the latest a month after the follow-up.
StandingRead in the act as published by Finlex, which serves it through a script and had to be rendered rather than fetched. Whether havaitseminen is read in Finnish administrative practice as earlier than awareness is not settled here. What is settled is that the act does not use the Directive's word.
Sourcefi kyberturvallisuuslaki 124 2025

An event in Finland

The five types, each opened on this jurisdiction: the acts it obliges, the term on each, and where the report goes.