Published
Reading time
3 min
Category
- Development
Published
Reading time
3 min
Category
Author
Antti Lassila
On April 8, 2025, a new cybersecurity law came into effect in Finland, bringing major changes for hundreds of organisations. This is the national implementation of the EU’s NIS2 Directive. And yes, it may apply to your organisation as well.
NIS2 (Network and Information Security Directive 2) is a cybersecurity directive of the European Union. Its goals are to:
In practice, NIS2 requires a wide range of companies and public organisations to systematically and thoroughly identify, manage and report cybersecurity risks in a planned and documented way.
A wider range of entities now falls under the scope of the new regulations.
NIS2 applies to operators in sectors such as energy, transport, banking, healthcare and digital infrastructure. You can explore the specific sectors in more detail through this table provided by the National Cyber Security Centre (table in Finnish).
The directive is not just about firewalls or changing passwords. It demands a comprehensive approach to cybersecurity. The key requirements include:
In practice, NIS2 requires companies to properly manage and document their cybersecurity processes. And yes, the law includes penalties. In worst cases, administrative fines can reach into the millions.
If you offer or use digital services – such as websites, e-services or other online solutions – NIS2 may impact you on several levels:
At Into-Digital, we build digital services that stand the test of time and cyber threats. With NIS2, more and more of our clients are asking: how is our website’s cybersecurity managed?
A good question, and a very timely one.
While NIS2 does not apply to us directly, we are a partner to many clients who are affected by the regulation. This makes us part of the supply chain that must meet the obligations and expectations placed on our clients – with high standards and reliability.
Here’s a checklist for addressing NIS2 requirements:
We are a partner who does more than just build digital services. We advance our clients’ business through digital solutions. Cybersecurity is a key part of this whole. We help our clients to: