Finnish companies have a lot of work ahead in implementing the European Network and Information Systems Directive


According to Nordic study conducted by Telenor in collaboration with DNA and other Nordic subsidiaries, companies have significant room for improvement in terms of cybersecurity.  Also implementing the European Network and Information Systems Directive (NIS2) needs a lot of work in the companies. 

According to Nordic study conducted by Telenor in collaboration with DNA and other Nordic subsidiaries, companies have significant room for improvement in terms of cybersecurity.
According to Nordic study conducted by Telenor in collaboration with DNA and other Nordic subsidiaries, companies have significant room for improvement in terms of cybersecurity.

The European Network and Information Systems Directive (NIS2) aims to ensure a common level of cybersecurity throughout the European Union. This directive will become part of national legislation in Finland during this year. The requirements of the directive apply to a large portion of Finnish companies, either directly or through subcontracting chains. The study reveals that Nordic companies perceive their cybersecurity levels and threats similarly.

Nearly all Nordic companies consider themselves somewhat aware of cyber threats

However, one crucial aspect of cybersecurity is employee awareness of cyber risks and appropriate responses. NIS2 emphasizes better communication and training on cybersecurity matters for employees. Surprisingly, in Finland, approximately 49% of respondents mentioned that they currently provide the required cybersecurity training related to NIS2 for their staff. In Norway, 61% of companies offer such training, while in Sweden and Denmark, approximately one-third of companies do so.

“Of particular concern is the finding that firewall protection is lacking in up to a quarter of companies. This deficiency should raise alarms not only for the companies themselves but also for their customers who use their services. Good cybersecurity practices not only protect the companies but also reduce the risk of infection for partners and customers”, says Dominique Akl, VP, Network and Cloud Solutions at DNA Corporate Business.

According to the survey, only 75% of companies protect their operations with firewall solutions, and nearly the same percentage mention that their company has any malware protection (76%).

As per the directive, responsibility of company’s cybersecurity lies with its management, and executives can be held personally accountable for any negligence. Almost all respondents (95%) felt they were somewhat aware of cybersecurity threats. However, 10% of respondents were unaware of the specific cybersecurity tools their company had in place.

Preparedness plans are lacking in the majority of Finnish companies

When NIS2 comes into force, it requires that cybersecurity risks be analyzed, and policies related to information system security be implemented. Despite this, only about a third (36%) of Finnish companies have developed incident response plans for cybersecurity threats. Nevertheless, a significant portion (86%) of respondents were confident or fairly confident in their ability to respond to cybersecurity incidents. 

Based on the responses, it is likely that a significant number of Finnish companies have weak capabilities to effectively address various security threats. 

Resource constraints and expertise pose obstacles to improving cybersecurity

Meeting NIS2 requirements demands increased investment in cybersecurity capabilities and its maintenance from companies. 

“Every company should act in line with the intentions of the directive, regardless of whether the directive directly obligates the company,” says Akl. 

The most significant barriers to enhancing cybersecurity capabilities were resource and funding constraints (25%), expertise (27%), and staff skills gap (26%). While most respondents (51%) believed that cybersecurity resourcing would increase, only 7% considered it highly likely to happen. 

This press release is based on a web survey conducted by Telenor Group with Norstat in October 2023. The study targeted companies in Finland, Norway, Sweden, and Denmark, with respondents being business directors responsible for their respective companies. The total number of respondents was 2134, including 518 from Finland. The survey’s margin of error is 1.9–4.5 percentage points. 

Media Inquiries:

Attachement: survey summary

Dominique Akl, Vice President, Network and Cloud Solutions, DNA Plc, tel. +38 (0)44 044 2602, dominique.akl@dna.fi

DNA Corporate Communications, tel. +358 44 044 8000, communications@dna.fi


According to Nordic study conducted by Telenor in collaboration with DNA and other Nordic subsidiaries, companies have significant room for improvement in terms of cybersecurity.
According to Nordic study conducted by Telenor in collaboration with DNA and other Nordic subsidiaries, companies have significant room for improvement in terms of cybersecurity.


DNA is one of the leading telecommunications companies in Finland. Our purpose is to connect you to what matters most. We offer connections, services and devices for homes and workplaces, contributing to the digitalisation of society. Already for years, DNA customers have been among the world leaders in mobile data usage. DNA has about 3.7 million subscriptions in its fixed and mobile communications networks. The company has been awarded numerous times as an excellent employer and family-friendly workplace. In 2023, our total revenues was EUR 1,067 million and we employed about 1,700 people around Finland. DNA is a part of Telenor Group, a leading telecommunications company across the Nordics. More information: www.dna.fi, X @DNA_fi, Facebook @DNA.fi and LinkedIn @DNA-Oyj.

Alternative languages

Subscribe to releases from DNA Oyj

Subscribe to all the latest releases from DNA Oyj by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from DNA Oyj

DNA:n tutkimus: Älä häiritse -tilan käytössä valtava harppaus vuoden aikana12.7.2024 10:00:00 EEST | Tiedote

Yli kolmasosa 16–24-vuotiaista suomalaisista on rajoittanut puhelimensa parissa tai internetissä viettämäänsä aikaa, kertoo DNA:n yli tuhannen vastaajan Digitaalinen elämä 2024 -tutkimus. Suosituimmat keinot digivapaiden hetkien pyhittämiseksi ovat muunlaisen ajanvietteen lisääminen arjessa, puhelimen käytön rajoittaminen ennen nukkumaanmenoa ja puhelimen pitäminen äänettömällä ainakin osan päivästä. Suurinta kasvua edellisvuoteen verrattuna nähdään Älä häiritse -tilan käytössä: vuosi sitten keinoon turvautui 16 prosenttia digirajoittamista harjoittavista vastaajista, nyt peräti 27 prosenttia.

DNA survey: Enormous surge in the use of Do Not Disturb mode in the past year12.7.2024 10:00:00 EEST | Press release

Over a third of 16–24-year-old Finns have cut down on the time they spend on their phone or the Internet, reveals DNA’s Digital Life 2024 survey of over 1,000 respondents. The most popular ways of cutting down on screen time are engaging in other pastimes, restricting phone usage before bed and keeping one’s phone muted for at least part of the day. The method that has gained the most traction since last year has been the use of Do Not Disturb mode. Last year, the mode was used by 16% of respondents who were restricting their digital device use. Now, that proportion has climbed to 27%.

DNA:lle kansainvälisesti arvostettu tietoturvasertifikaatti – erityistä tunnustusta organisaation toiminnasta9.7.2024 15:03:43 EEST | Tiedote

DNA:lle on myönnetty ulkoisen auditoinnin jälkeen kansainvälisesti arvostettu ISO 27001 -tietoturvasertifikaatti. ISO/IEC 27001 -standardin pohjalta sertifioitu tietoturvallisuuden hallintajärjestelmä (Information Security Management System, ISMS) osoittaa, että organisaatio johtaa tietojensa turvaamista pitääkseen ne virheettöminä, helposti käytettävissä ja hyvin suojattuina. Auditoinnissa ulkopuolinen toimija todentaa tietoturvan vahvan toteutumisen eri tilanteissa sekä digitaalisissa että fyysisissä ympäristöissä. Näin asiakkaat ja yhteistyökumppanit voivat olla entistä turvallisemmin mielin DNA:n kyvykkyydestä huolehtia asiakkaiden tietoturvasta ja liiketoiminnan jatkuvuudesta ensiluokkaisesti.

DNA achieves internationally respected information security certification – special recognition of the organisation’s work9.7.2024 15:03:43 EEST | Press release

Following an external audit, DNA has been certified to the internationally respected ISO/IEC 27001 information security standard. An information security management system (ISMS) certified to the ISO/IEC 27001 standard demonstrates that the organisation has taken the initiative in securing its data and ensuring that data remains reliable, easy to use and safe. The audit involves an independent party confirming that the organisation’s information security is effective in a variety of situations in both digital and physical environments. This allows customers and partners to rest assured in the knowledge that DNA is taking first-class care of their data and ensuring their business continuity.

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
HiddenA line styled icon from Orion Icon Library.Eye