Disclosure obligations – Experiences and views from Finnish industry Mr. Mika Susi Chief Policy Adviser Confederation of Finnish Industries
Experiences • History of voluntary reporting based on public-private- partnership – CERT-FI – HAVARO − the national early warning and monitoring system • Current trend shifting towards regulation and sanctions – General Data Protection Regulation (GDPR) – The Directive on Security of Network and Information Systems (NIS) 2
Views on challenges and opportunities • Basic questions – Why? What? Who? • Challenges – Administrative burden – Can you focus on right things? – ” Cost of trying to be perfect in imperfect world ” • Opportunities – Situation awareness and resilience – Cost-benefit ratio in investments – Corporate responsibility and reputation 3
Conclusions 1) Regulation dilemma: voluntary or mandatory? 2) Create incentives, not disincentives 3) Clear rules and processes for reporting ” Two way street ” − if you share, you´ll receive 4) 4
“Strength of information security lies in cooperation”
Recommend
More recommend