Skip to content
Home » About us » Cybersecurity from Finland » Cyber risk management directory

Directory service for cybersecurity risk management products and services

Last modified 01.09.2026 at 10:30

A classification based on the internationally recognized and widely used cybersecurity risk management process model (NIST CSF 2.0), particularly for meeting the compliance requirements of the NIS2 Directive.

NIST CSF 2.0 (National Institute of Standards and Technology Cybersecurity Framework 2.0) is an updated version of NIST’s cybersecurity framework. This framework helps organizations manage cybersecurity risks effectively. CSF 2.0 provides high-level cybersecurity outcomes that can be applied regardless of an organization’s size, sector, or level of maturity.

NIST CSF 2.0 includes six core functions that support effective cybersecurity risk management:

Identify: Identifying and understanding the organization’s cybersecurity risks, assets, and operating environment.

Protect: Implementing safeguards to protect critical services and data.

Detect: Developing and implementing measures to enable the timely detection of cybersecurity incidents.

Respond: Planning and implementing measures to enable effective response to cybersecurity incidents.

Recover: Supporting and implementing measures that enhance recovery and ensure continuity of operations after cybersecurity incidents.

The purpose of the classification is to categorize and identify the cybersecurity products and services offered by the cybersecurity sector. Companies are listed in drop-down menus according to each process function.

Identify

  • Identification and assessment of an organization’s cybersecurity risks
  • Management of information and digital assets
  • Selection of risk management measures

Protect

  • Implementation and monitoring of risk management measures
  • Technical and administrative security of information and communication systems
  • Identity management, authentication, and access control
  • Awareness and training
  • Security of networks, information systems, and data platforms
  • Resilience of information and communication systems

Detect

  • Detection and analysis of security breaches
  • Continuous monitoring of information and communication systems
  • Analysis of malicious and harmful events

Respond

  • Cybersecurity incident response measures
  • Implementation of incident recovery plans
  • Communication related to incident management

Recover

  • Restoration of assets and operations affected by a cybersecurity incident
  • Management and analysis of incidents
  • Incident reporting and communication
  • Minimization of the adverse impacts of incidents

Govern

  • Design and monitoring of the risk management strategy and process
  • Supply chain risk management
  • Roles, responsibilities, and authorities of the organization and its stakeholders
  • The organization’s cybersecurity policies, processes, and procedures