Currently reading: Aalto Leaders' Insight: Cyber Risks Becoming the New Normal: What Does That Mean for SMEs?

Cyber Risks Becoming the New Normal: What Does That Mean for SMEs?

While the increasing digitalization has the potential to offer a number of benefits in the form of efficiencies, convenience, and new services, it also adds to the likelihood of cybersecurity incidents. Incidents such as cyberattacks are becoming more common across the globe, and Finland is no exception. Attempted data breaches and serious cybersecurity incidents have been reported to be on the rise and call for cost-efficient solutions available also for companies with more limited resources.

Kari Koskinen , 22.09.2025

|

Articles

The Finnish Transport and Communications Agency Traficom has stated that attackers have become faster at identifying existing vulnerabilities in systems, and the technologies to conduct cyberattacks continue to evolve. In addition, the existing geopolitical tensions further contribute to cyber threats, targeting various institutions.

If successful, these attacks have direct and possibly dire consequences for citizens, businesses, and societies as a whole.

While the efforts to prevent and counter cyberattacks have worked relatively well in Finland, business and operational continuity and resilience are nevertheless of growing importance. Organizations are faced with a range of cybersecurity challenges calling for solutions.

If successful, these attacks have direct and possibly dire consequences for citizens, businesses, and societies as a whole.

Among others, there is a shortage of skilled cybersecurity professionals, while technological developments enable attackers to use increasingly sophisticated methods.

Furthermore, more traditional challenges, such as a lack of resources and misconceptions about cybersecurity, continue to exist and are often seen as particularly pertinent in many small and medium-sized enterprises (SMEs).

As systems are interconnected to one another, a vulnerability in one system may affect others, increasing the available attack surface for attackers and paving the way to supply chain attacks.

Many SMEs with their products and services form part of digital supply chains, providing, for instance, features or components for a software that other actors in the supply chain rely on. Thus, ensuring that SMEs are properly protected is not just important for the SMEs themselves, but also for many others.

Similarly, solutions in this space not only benefit the SMEs but also a larger group of actors, both directly and indirectly.

While technological developments create new avenues for malicious hackers to attack digital systems, it is worth noting that they can also be used to make systems and organizations more secure.

To illustrate, digitalization not only creates security risks but also allows better security monitoring and facilitates the delivery of security training to employees.

In addition, the development of generative AI offers interesting possibilities for addressing cybersecurity challenges. Among these, we envision a gen AI-based tool that could help SMEs improve their information security.

In essence, the tool would provide assistance for SMEs and other entities in areas such as cybersecurity policy development, threat landscape mapping, incident response, and business continuity.

As systems are interconnected to one another, a vulnerability in one system may affect others.

We see that this kind of tool could offer a cost-efficient approach to enhance cybersecurity, particularly in organisations with more limited resources. In developing the tool, data on relevant issues ranging from incident response plans to actual incidents are required.

This may also act as a barrier for the tool’s development, since companies are occasionally less inclined to disclose this kind of data. Nevertheless, being more open and sharing such data would enable collective learning and preparedness.

It is often noted that among the key actions after a cybersecurity incident is to see what could be learned from it. Having avenues to disclose this kind of information to other organizations would help to spread these learnings and improve the overall state of cybersecurity in an increasingly interconnected society.

At the same time, it could ensure that organizations would not repeat each other’s mistakes, but learn from one another and avoid the associated costs that tend to follow cybersecurity incidents.

The CYCERONE project is a European initiative that aims to close the cybersecurity skills gap by offering accessible, high-quality training for professionals in SMEs and the public sector. As part of the consortium, Aalto EE is involved in planning the platform concept and course format offering, as well as designing the courses and their associated content. Aalto EE draws on its expertise in executive education and lifewide learning to ensure the training meets the needs of both individuals and organizations.

Who?

Kari Koskinen

Kari Koskinen works as a University Lecturer at Aalto University. He conducts research on topic areas such as information security, digital platforms, and ethics of digital innovation, focusing on issues such as users’ trust formation towards highly automated systems and data responsibility in organizations. He has co-authored several teaching cases concentrating on information security in organisations, and his work has been published in journals such as the Information Systems Journal and in a number of conferences like the European Conference on Information Systems. 


Back to Aalto Leaders' Insight main page

Find more content on