To get the best help for your situation, first answer the questions on the guide's start page.
To get the best help for your situation, first answer the questions on the guide's start page.

Once the security vulnerability has been blocked, it is important to plan what kind of possible more extensive changes should be made to the information system. Schedule and plan the technical changes together with the system supplier.
As a result of a data breach and a data leak, you may have to
It is important to go through the processes and practices of your organisation to determine whether any changes are required in them.
It may be necessary for your organisation to
The criminal procedure proceeds from the reported offence to the consideration of charges
Read more about the process of investigating a cyber crime in the publication of the Police University College and Jyväskylä University of Applied Sciences Cyber crime is a police matter‒ a guide to the cyber crime investigation process (in Finnish)Opens in a new window..
In certain cases, it is possible for an organisation to receive compensation for the costs caused by a data breach/data leak. The compensation may be
The organisation can demand contractual compensations from the system supplier if an entry on compensations has been recorded in the contract between the organisation and the system supplier. Typically, the possibility of contractual compensation in situations, in which the system supplier has not complied with the contractual obligations or has in some other way caused the data breach or data security risk, have been recorded in the contract.
It is possible to take out insurances for data security breaches. The extent of the insurances varies: some insurances compensate for only the salary costs of the IT specialist needed to deal with the incident, while some insurances compensate also for the costs of business interruption and compensations paid to outsiders Some insurances also include expert help in data breach and data leak situations.
If you suspect an offence such as a data breach, report an offence. In this case, you can submit claims for compensation for damages to the suspected offender.
Your customer may have the right to demand compensation for damage from your organisation if your organisation has violated the EU’s General Data Protection Regulation (GDPR). Read more about claiming compensation for damages for GDPR violations on the website of the Office of the Data Protection Ombudsman.Opens in a new window.
If an offence has been committed, your customer may demand compensation from the suspected offender. Read about compensation related to criminal damages on the Victim Support Finland (RIKU) website. Opens in a new window.
The General Data Protection Regulation (GDPR) regulates the processing of personal data. If the organisation does not comply with the GDPR requirements, the Office of the Data Protection Ombudsman may issue a warning, a caution or an order to the organisation, depending on the severity of the negligence. The Office may also restrict the processing of personal data by the organisation or impose a ban on processing it.
In addition to or instead of other corrective measures, the supervisory authority may also impose an administrative fine which may be 4 per cent of the turnover or EUR 20 million at the most.

If you feel overwhelmed by the situation, you can always seek help from:
You can also seek help from the health centre of your home municipality (link in Finnish)Opens in a new window..