New duties for Traficom
The Cybersecurity Act also entails new supervisory duties for Traficom compared to the old NIS Directive. In future, Traficom will be the competent authority supervising cybersecurity issues also in the following sectors: postal and courier services, space, public administration, managed service providers, managed security service providers, research, and the manufacture of vehicles and other transport equipment. New types of entities have also been added to the scope of supervision in sectors that were already covered by NIS regulation.
Competence for the supervision of different sectors is divided among sectoral authorities. The NCSC-FI at Traficom also acts as the single point of contact referred to in the Cybersecurity Act. Its tasks include promoting cooperation and coordination among supervisory authorities.
The NCSC-FI also has a computer security incident response team (CSIRT) whose tasks include responding to incident notifications and, if necessary, assisting the notifying entity in handling the incident. This may also involve the technical investigation of severe information security violations. The CSIRT also participates in maintaining national situational awareness of cybersecurity and provides early warnings, alerts, announcements and information on cybersecurity issues.
The CSIRT is not responsible for supervising the entities governed by the Cybersecurity Act, which is why its operations are separate from the supervisory duties related to the Act. CSIRT activities are based on trust between the team and various actors of society and on the voluntary reporting of information security violations to the CSIRT. This is reflected in the Cybersecurity Act according to which information voluntarily disclosed to the CSIRT may not be used without the notifier’s consent in criminal investigations or in administrative or other decision-making processes concerning the notifier.