Published On: 27.08.2026Last Updated: 27.08.2026Categories: Business Continuity, Critical communications, Preparedness

The aim of the European Union’s CER Directive is to strengthen the resilience of entities and services that are critical to society in a changed security and operating environment. In Finland, the requirements of the Directive have been implemented through national legislation, the key statute being the Act on the Protection of Critical Infrastructure and the Enhancement of Resilience.¹

The Act on the Protection of Critical Infrastructure and the Enhancement of Resilience² requires critical entities to prepare for various disruptions, prevent and mitigate their impacts, and ensure the continuity and recovery of critical services. In practice, the aim is to strengthen organisations’ ability to prevent disruptions, respond to them, mitigate their impacts and recover from them.

Critical services and the infrastructure supporting them may be exposed to natural disasters, terrorism, cyber threats and technical failures, for example. If such a threat materialises, it may disrupt or interrupt a critical service. The entity must therefore be able to contain the impacts, maintain its operational capability and restore the service as quickly as possible.

For this reason, CER regulation requires critical entities to assess risks, prepare systematically and have measures in place to prevent disruptions, contain their impacts and manage the situation. The CER Directive complements the NIS2 Directive, which is part of the same EU regulatory framework and focuses particularly on the security of network and information systems.²

The CER Handbook – a guide for critical entities (in Finnish), prepared by the Finnish Ministry of the Interior, brings together the obligations that apply to critical entities and provides guidance on their practical implementation.

This article covers:

The key obligations of the CER Act for critical entities

The CER Act requires critical entities to assess the risks affecting their operations and, based on that assessment, draw up a plan to ensure resilience.² The Finnish Ministry of the Interior’s CER Handbook states that the plan must address the prevention and management of disruptions, the mitigation of their impacts and the restoration of critical services.¹

The organisation must also ensure that its personnel are informed and trained, that exercises are conducted regularly, and that effective cooperation is maintained with authorities, service providers and other key partners. Significant disruptions, their impacts and the measures taken must also be reported to the authorities.¹ Secapp can support the organisation particularly in conducting and documenting exercises: the same alerting, communication and acknowledgement processes can be practised in advance, and the event data generated during an exercise can be used to evaluate and develop operating models.

In practice, in addition to having plans in place, the Act requires the ability to initiate agreed measures quickly, contain the impacts of a disruption, safeguard the continuity of a critical service and restore operations in a controlled manner.¹ Secapp can support the organisation in implementing these operating models.

More information about the reporting obligation is available in the section of the CER Handbook covering incident notifications.

Turning plans into practical operational capability

Meeting the obligations cannot be achieved through a plan alone. What matters is whether the organisation can initiate the agreed measures quickly and in a controlled manner when normal operations are disrupted.

In practice, this requires reaching the right people without delay, providing them with clear instructions and creating an up-to-date overview of the situation to support decision-making. At the same time, the organisation must be able to contain the impacts of the disruption, safeguard the continuity of the critical service and restore normal operations in a controlled manner.

Operating models must therefore be prepared before a disruption occurs. Responsibilities, contact details, message templates and instructions must be ready so that they do not have to be created once the situation is already under way. The faster the organisation can move from plans to action, the better it can contain the impacts of the disruption and safeguard the continuity of critical services.

Secapp alone does not ensure compliance with the requirements of the CER Act, but it helps turn resilience plans into operating models that can be put into action in practice. Next, we will examine how Secapp can support preparedness, incident management and the restoration of operations.

Secapp enables fast, independent communication during disruptions

Containing the impacts of a disruption and maintaining the operational capability of critical services require information to reach the right people quickly. Communication must also work when the organisation’s normal communication channels are disrupted or unavailable.

With Secapp, alerts can be targeted directly to the right individuals or groups based on their role, expertise, availability or location, for example. Instructions, images and other attachments can be included with the message so that recipients immediately know what to do. Acknowledgements allow the organisation to see who has received the message and who still needs to be reached.

The system also supports continuity of communication when the organisation’s own systems are disrupted. During an exceptional situation, it cannot be assumed that email, Teams or other everyday communication tools will be available. Communication channels for disruptions, and the operating models governing their use, must therefore be planned in advance.

During a cyber disruption, for example, email and other internal systems may be unavailable or their use may have to be restricted. In this case, information about the situation, the necessary instructions and tasks can be communicated to personnel independently of the organisation’s own IT environment. In an evacuation, acknowledgements show who has received the instruction and who still needs to be reached.

– During an exceptional situation, communication must work even when the organisation’s usual systems or communication channels are unavailable. A communication channel that is independent of the tools used in everyday operations helps ensure that information about an incident quickly reaches the right people, situational awareness remains consistent, and authorised decision-makers can initiate the necessary measures without delay. It is not only about sending a message, but about safeguarding the organisation’s management and operational capability. Without effective communication, the organisation’s continuity, operational capability and personnel safety may be put at risk. – Kari Aho, CEO, Co-founder, Secapp

Shared situational awareness supports the continuity of critical services

Decision-making during a disruption quickly slows down if the management team does not share a common understanding of the situation. Knowing that a disruption has occurred is not enough. Decision-makers also need to know who has been reached, what measures have already been taken and where additional resources are still required.

With Secapp, the organisation can monitor message delivery and acknowledgements, personnel availability, task progress and observations received from the field. This allows management to identify quickly where additional resources are needed and where measures should be directed.

Shared situational awareness also supports cooperation across organisational boundaries. In addition to the organisation’s own personnel, the same operating model can include subcontractors, maintenance companies, security providers, transport partners and other critical stakeholders. When the different parties have access to up-to-date information and clear tasks, activities can be coordinated more effectively and duplicate work reduced.

The solution can also be integrated with the organisation’s other technical systems. An observation from a sensor, monitoring system or cybersecurity solution, for example, can be converted automatically into a targeted alert and instructions. This ensures that a technical observation does not remain an isolated notification but triggers a predefined operating model without unnecessary delay.

Up-to-date situational awareness, a clear division of responsibilities and effective cooperation with partners help direct resources to the functions that are most essential to the continuity of the critical service.

– During the first minutes of a disruption, management must quickly obtain answers to at least three questions: who has been reached, what measures have already been initiated and what resources are available. Without up-to-date situational awareness, decisions can easily be based on assumptions and fragmented information. This is why simply sending an alert is not enough. The situation must be managed throughout its entire lifecycle: ensuring message delivery, gathering acknowledgements and observations, assigning tasks and monitoring their completion. Secapp brings this information into a single view and helps management turn fragmented information into controlled decisions and practical action. – Kari Aho, CEO, Co-founder, Secapp

Exercising and documenting disruption scenarios support continuous improvement

Resilience under the CER Act requires operating models to be exercised and developed regularly. Secapp can be used in exercises in the same way as in real disruptions, allowing the organisation to test, for example, personnel reachability, alerting and acknowledgement processes, management team operations, evacuation, cooperation between partners and the effectiveness of pre-prepared instructions.

The purpose of exercises is not merely to test the system but to ensure that the entire organisation can operate as planned, even under pressure. Exercises can identify gaps in responsibilities, communication chains and instructions, and ensure that personnel and other key parties understand their roles.

In real situations, the event history created in Secapp supports subsequent evaluation. The system records information such as alert transmission times, receipt and acknowledgements, situation updates, tasks, decisions and the progression of events.

Documented information can be used to develop operating models and prepare the incident notification submitted to the authorities. However, Secapp does not replace the official notification required under the CER Act; it provides situational information and an event history that support its preparation.

Secapp supports operations from preparedness to recovery

Secapp can support an organisation throughout the entire lifecycle of a disruption. Before a disruption, recipient groups, responsibilities, instructions and message templates for different situations can be defined in the system. This means that operations do not have to be planned once the situation is already under way; the agreed measures can be initiated quickly. During a disruption, the right people can be reached, up-to-date instructions can be shared with them and shared situational awareness can be established as the situation develops.

As the situation changes, the system can be used to assign tasks, call in additional resources and communicate new instructions to personnel and partners. During the recovery phase, the solution supports the controlled restoration of critical services. After the event, messages, acknowledgements, situation updates and tasks stored in the system can be used to evaluate the situation, develop operating models and plan future exercises.

However, Secapp does not conduct the organisation’s risk assessment, draw up its entire resilience plan or replace physical protection measures such as access control, locks and backup systems. Nor does it alone ensure compliance with the requirements of the CER Act. Its role is to help turn the organisation’s plans, responsibilities and instructions into operating models that can be implemented in practice – from preparedness and disruption management to recovery and continuous improvement.

Practical example: Port of Rauma

The Port of Rauma is part of Finland’s critical infrastructure from a security-of-supply perspective. The port uses Secapp to reach not only its own personnel but also the various operators in the port area. In a multi-operator environment, messages must quickly reach parties such as terminal operators, maintenance personnel, security providers and others working in the area.

During evacuations, acknowledgements can be used to confirm message delivery and monitor, for each operator, whether personnel have left the area. The chain of events recorded in Secapp helps monitor the progression of the situation and supports subsequent evaluation. The Port of Rauma’s experience demonstrates in practice how the rapid flow of information, cooperation across organisational boundaries and up-to-date situational awareness can support the continuity of critical operations during a disruption.

Read the full customer story about the Port of Rauma’s experience with Secapp.

Sources:

  1. Ministry of the Interior. CER Handbook: A Guide for Critical Entities. Available at: https://intermin.fi/cer-kasikirja (in Finnish). Accessed 10 August 2026.
  2. Finlex. Act on the Protection of Infrastructure Critical to Society and on the Improvement of Resilience (310/2025). Available at: https://www.finlex.fi/en/legislation/2025/310. Accessed 10 August 2026.

The aim of the European Union’s CER Directive is to strengthen the resilience of entities and services that are critical to society in a changed security and operating environment. In Finland, the requirements of the Directive have been implemented through national legislation, the key statute being the Act on the Protection of Critical Infrastructure and the Enhancement of Resilience.¹

The Act on the Protection of Critical Infrastructure and the Enhancement of Resilience² requires critical entities to prepare for various disruptions, prevent and mitigate their impacts, and ensure the continuity and recovery of critical services. In practice, the aim is to strengthen organisations’ ability to prevent disruptions, respond to them, mitigate their impacts and recover from them.

Critical services and the infrastructure supporting them may be exposed to natural disasters, terrorism, cyber threats and technical failures, for example. If such a threat materialises, it may disrupt or interrupt a critical service. The entity must therefore be able to contain the impacts, maintain its operational capability and restore the service as quickly as possible.

For this reason, CER regulation requires critical entities to assess risks, prepare systematically and have measures in place to prevent disruptions, contain their impacts and manage the situation. The CER Directive complements the NIS2 Directive, which is part of the same EU regulatory framework and focuses particularly on the security of network and information systems.²

The CER Handbook – a guide for critical entities (in Finnish), prepared by the Finnish Ministry of the Interior, brings together the obligations that apply to critical entities and provides guidance on their practical implementation.

This article covers:

The key obligations of the CER Act for critical entities

The CER Act requires critical entities to assess the risks affecting their operations and, based on that assessment, draw up a plan to ensure resilience.² The Finnish Ministry of the Interior’s CER Handbook states that the plan must address the prevention and management of disruptions, the mitigation of their impacts and the restoration of critical services.¹

The organisation must also ensure that its personnel are informed and trained, that exercises are conducted regularly, and that effective cooperation is maintained with authorities, service providers and other key partners. Significant disruptions, their impacts and the measures taken must also be reported to the authorities.¹ Secapp can support the organisation particularly in conducting and documenting exercises: the same alerting, communication and acknowledgement processes can be practised in advance, and the event data generated during an exercise can be used to evaluate and develop operating models.

In practice, in addition to having plans in place, the Act requires the ability to initiate agreed measures quickly, contain the impacts of a disruption, safeguard the continuity of a critical service and restore operations in a controlled manner.¹ Secapp can support the organisation in implementing these operating models.

More information about the reporting obligation is available in the section of the CER Handbook covering incident notifications.

Turning plans into practical operational capability

Meeting the obligations cannot be achieved through a plan alone. What matters is whether the organisation can initiate the agreed measures quickly and in a controlled manner when normal operations are disrupted.

In practice, this requires reaching the right people without delay, providing them with clear instructions and creating an up-to-date overview of the situation to support decision-making. At the same time, the organisation must be able to contain the impacts of the disruption, safeguard the continuity of the critical service and restore normal operations in a controlled manner.

Operating models must therefore be prepared before a disruption occurs. Responsibilities, contact details, message templates and instructions must be ready so that they do not have to be created once the situation is already under way. The faster the organisation can move from plans to action, the better it can contain the impacts of the disruption and safeguard the continuity of critical services.

Secapp alone does not ensure compliance with the requirements of the CER Act, but it helps turn resilience plans into operating models that can be put into action in practice. Next, we will examine how Secapp can support preparedness, incident management and the restoration of operations.

Secapp enables fast, independent communication during disruptions

Containing the impacts of a disruption and maintaining the operational capability of critical services require information to reach the right people quickly. Communication must also work when the organisation’s normal communication channels are disrupted or unavailable.

With Secapp, alerts can be targeted directly to the right individuals or groups based on their role, expertise, availability or location, for example. Instructions, images and other attachments can be included with the message so that recipients immediately know what to do. Acknowledgements allow the organisation to see who has received the message and who still needs to be reached.

The system also supports continuity of communication when the organisation’s own systems are disrupted. During an exceptional situation, it cannot be assumed that email, Teams or other everyday communication tools will be available. Communication channels for disruptions, and the operating models governing their use, must therefore be planned in advance.

During a cyber disruption, for example, email and other internal systems may be unavailable or their use may have to be restricted. In this case, information about the situation, the necessary instructions and tasks can be communicated to personnel independently of the organisation’s own IT environment. In an evacuation, acknowledgements show who has received the instruction and who still needs to be reached.

– During an exceptional situation, communication must work even when the organisation’s usual systems or communication channels are unavailable. A communication channel that is independent of the tools used in everyday operations helps ensure that information about an incident quickly reaches the right people, situational awareness remains consistent, and authorised decision-makers can initiate the necessary measures without delay. It is not only about sending a message, but about safeguarding the organisation’s management and operational capability. Without effective communication, the organisation’s continuity, operational capability and personnel safety may be put at risk. – Kari Aho, CEO, Co-founder, Secapp

Shared situational awareness supports the continuity of critical services

Decision-making during a disruption quickly slows down if the management team does not share a common understanding of the situation. Knowing that a disruption has occurred is not enough. Decision-makers also need to know who has been reached, what measures have already been taken and where additional resources are still required.

With Secapp, the organisation can monitor message delivery and acknowledgements, personnel availability, task progress and observations received from the field. This allows management to identify quickly where additional resources are needed and where measures should be directed.

Shared situational awareness also supports cooperation across organisational boundaries. In addition to the organisation’s own personnel, the same operating model can include subcontractors, maintenance companies, security providers, transport partners and other critical stakeholders. When the different parties have access to up-to-date information and clear tasks, activities can be coordinated more effectively and duplicate work reduced.

The solution can also be integrated with the organisation’s other technical systems. An observation from a sensor, monitoring system or cybersecurity solution, for example, can be converted automatically into a targeted alert and instructions. This ensures that a technical observation does not remain an isolated notification but triggers a predefined operating model without unnecessary delay.

Up-to-date situational awareness, a clear division of responsibilities and effective cooperation with partners help direct resources to the functions that are most essential to the continuity of the critical service.

– During the first minutes of a disruption, management must quickly obtain answers to at least three questions: who has been reached, what measures have already been initiated and what resources are available. Without up-to-date situational awareness, decisions can easily be based on assumptions and fragmented information. This is why simply sending an alert is not enough. The situation must be managed throughout its entire lifecycle: ensuring message delivery, gathering acknowledgements and observations, assigning tasks and monitoring their completion. Secapp brings this information into a single view and helps management turn fragmented information into controlled decisions and practical action. – Kari Aho, CEO, Co-founder, Secapp

Exercising and documenting disruption scenarios support continuous improvement

Resilience under the CER Act requires operating models to be exercised and developed regularly. Secapp can be used in exercises in the same way as in real disruptions, allowing the organisation to test, for example, personnel reachability, alerting and acknowledgement processes, management team operations, evacuation, cooperation between partners and the effectiveness of pre-prepared instructions.

The purpose of exercises is not merely to test the system but to ensure that the entire organisation can operate as planned, even under pressure. Exercises can identify gaps in responsibilities, communication chains and instructions, and ensure that personnel and other key parties understand their roles.

In real situations, the event history created in Secapp supports subsequent evaluation. The system records information such as alert transmission times, receipt and acknowledgements, situation updates, tasks, decisions and the progression of events.

Documented information can be used to develop operating models and prepare the incident notification submitted to the authorities. However, Secapp does not replace the official notification required under the CER Act; it provides situational information and an event history that support its preparation.

Secapp supports operations from preparedness to recovery

Secapp can support an organisation throughout the entire lifecycle of a disruption. Before a disruption, recipient groups, responsibilities, instructions and message templates for different situations can be defined in the system. This means that operations do not have to be planned once the situation is already under way; the agreed measures can be initiated quickly. During a disruption, the right people can be reached, up-to-date instructions can be shared with them and shared situational awareness can be established as the situation develops.

As the situation changes, the system can be used to assign tasks, call in additional resources and communicate new instructions to personnel and partners. During the recovery phase, the solution supports the controlled restoration of critical services. After the event, messages, acknowledgements, situation updates and tasks stored in the system can be used to evaluate the situation, develop operating models and plan future exercises.

However, Secapp does not conduct the organisation’s risk assessment, draw up its entire resilience plan or replace physical protection measures such as access control, locks and backup systems. Nor does it alone ensure compliance with the requirements of the CER Act. Its role is to help turn the organisation’s plans, responsibilities and instructions into operating models that can be implemented in practice – from preparedness and disruption management to recovery and continuous improvement.

Practical example: Port of Rauma

The Port of Rauma is part of Finland’s critical infrastructure from a security-of-supply perspective. The port uses Secapp to reach not only its own personnel but also the various operators in the port area. In a multi-operator environment, messages must quickly reach parties such as terminal operators, maintenance personnel, security providers and others working in the area.

During evacuations, acknowledgements can be used to confirm message delivery and monitor, for each operator, whether personnel have left the area. The chain of events recorded in Secapp helps monitor the progression of the situation and supports subsequent evaluation. The Port of Rauma’s experience demonstrates in practice how the rapid flow of information, cooperation across organisational boundaries and up-to-date situational awareness can support the continuity of critical operations during a disruption.

Read the full customer story about the Port of Rauma’s experience with Secapp.

Sources:

  1. Ministry of the Interior. CER Handbook: A Guide for Critical Entities. Available at: https://intermin.fi/cer-kasikirja (in Finnish). Accessed 10 August 2026.
  2. Finlex. Act on the Protection of Infrastructure Critical to Society and on the Improvement of Resilience (310/2025). Available at: https://www.finlex.fi/en/legislation/2025/310. Accessed 10 August 2026.