Suomi.fi for Service Developers
Go directly to contents.
VAHTI best practices
Digital security risk management

To get the best help for your situation, first answer the questions on the guide's start page.

Learn the principles

What is digital security?

Digital security refers to actions and ways of protecting against cyber threats, security breaches, and other electronic attacks. Digital security protects

  • information systems
  • networks
  • software
  • data.

By law, digital security risk management is mandatory for organisations. The organisation must

  1. determine the material risks to its data processing
  2. scale the information security measures based on the risk assessment.

Updated: 29/10/2024

Digital security risk management is basic operation of an organisation

Management of risks related to digital security includes coordinated actions within or between organisations that aim to address the digital security risk while maximising opportunities.

− Organization for Economic Co-operation and Development (OECD)

Preparing for a rainy day by carrying an umbrella and putting money aside for a bad day are examples of everyday risk management. In addition to anticipating risks in the physical world, digital security risk management is also an activity that should be normal for both individuals and organisations.

Digital security risk management is an activity that consciously aims to influence uncertainties related to digital security that may make it more difficult for the organisation to achieve its goals.

Updated: 29/10/2024

What are the digital security risks?

Digital security risks can refer to risks that occur in either a physical or digital operating environment. Risks to digital security include

  • disruptions caused by electricity distribution
  • disruptions in data connections, that is, disruptions in either the network connection or network services
  • threats caused by cyber criminals.

Threats posed by cyber criminals include data leaks or breaches, malware, denial of service attacks, scams, and phishing.

Updated: 29/10/2024

Everyone has a role in digital security risk management

Digital security must be built into the company and default at all levels of the organisation and in all its activities. Every employee must be familiar with the basic principles of risk management and be able to prepare for the digital security risks related to their own work roles and methods.

At its simplest, risk management can mean telling your own supervisor if you have observed something that differs from normal activities.

Updated: 29/10/2024

Learn about the areas of digital security

Updated: 29/10/2024

Get to know the training courses

Updated: 29/10/2024

Participate in events

Follow the Digital security event calendar on the website Suomi.fi for Service Developers (in Finnish).

Updated: 13/11/2025

Are you satisfied with the content on this page?

Checklist