Join the FINMISP service

FINMISP is the National Cyber Security Centre Finland’s (NCSC-FI) cyber threat intelligence sharing service for organisations. Join the service if you want to use and share technical threat intelligence efficiently.

What is FINMISP?

FINMISP is a national cyber threat intelligence sharing service provided by the NCSC-FI. It is based on the MISP platform (MISP Threat Sharing).

The service makes it easier to share technical threat intelligence related to nationally and internationally detected information security incidents. The NCSC-FI acts as the central node of the network and distributes information to service users.

Service customers can also share information with each other and with the NCSC-FI, which then forwards the information to international networks. Shared threat intelligence helps prevent information security breaches, especially in organisations critical to security of supply and in public authorities.

FINMISP complements the NCSC-FI’s range of services. It does not replace reporting information security breaches.

FINMISP yhdistää viranomaiset, organisaatiot ja kansainväliset verkostot uhkatiedon jakamiseen

FINMISP connects public authorities, organisations and international networks for threat intelligence sharing.

When is FINMISP suitable for you?

You will benefit most from the service if your organisation

  • needs to receive and use technical threat intelligence
  • is able to produce and share threat intelligence with other actors
  • understands whether the MISP platform is suitable for its activities
  • wants to develop cyber threat intelligence sharing through cooperation

As a general rule, the service is intended for Finnish organisations critical to security of supply.

How to join the FINMISP service

  1. Step 1

    Assess suitability for your organisation

    Find out how your organisation uses cyber threat intelligence and whether you are able to process and share it.

  2. Step 2

    Learn how the service works

    FINMISP is based on the MISP platform, which enables the sharing, storage and correlation of technical indicators related to cyber attacks.

  3. Step 3

    Choose how to use the service

    You can use the service through your own MISP instance or through the NCSC-FI’s web interface. You can also use both in parallel.

  4. Step 4

    Order the service

    Order the FINMISP service using the form. On the form, you also accept the service’s community rules.
    Ordering the service requires Suomi.fi e-Identification and authorisation to act on behalf of the organisation.

    See more detailed information in the section More information about the FINMISP service at the bottom of the page.

How FINMISP works and how to use the service

FINMISP forms a national threat intelligence sharing network in which the NCSC-FI acts as a central node.

The service brings together

  • national threat intelligence sharing
  • international information sources
  • exchange of information between organisations

You can use the FINMISP service in two ways:

  • through your own MISP instance
  • through the web interface

The web interface gives you quick access to the service’s information content and enables you to start producing and sharing threat intelligence.

Your own MISP instance enables you to create an automated and real-time information sharing pipeline between your organisation and FINMISP. Your organisation is responsible for installing and maintaining your own instance. The NCSC-FI will provide support and guidance on deploying and using FINMISP.

 

FINMISP yhdistää tietoturvapoikkeamista kerätyn datan ja muuntaa sen uhkatiedoksi

FINMISP combines data collected from information security incidents and turns it into threat intelligence.

Through the service, your organisation gets

  • comprehensive and relevant information from high-quality sources
  • fast information sharing between actors critical to security of supply
  • a tool for reactive and proactive measures
  • better capabilities to analyse information security incidents

FINMISP data and classification

FINMISP is mainly used to share technical threat intelligence, meaning indicators of compromise.

An indicator of compromise (IOC) is a technical indicator that may point to an information security breach or cyber attack.

FINMISP has its own classification system, which determines how context and metadata are attached to information. This ensures that shared threat intelligence is consistent and usable.

In FINMISP

  • confidential information is not shared
  • information sharing is restricted using the TLP protocol

TLP (Traffic Light Protocol) defines who information may be shared with and how it may be used.

FINMISP kokoaa uhkatiedon eri lähteistä ja yhdistää sen analysoitavaksi kokonaisuudeksi

More information about the FINMISP service

Threat intelligence is information that helps an organisation identify, assess, monitor, analyse and counter cyber threats. It includes technical indicators and information about the tactics, techniques and procedures used by threat actors.

MISP (Malware Information Sharing Platform) is an open-source platform for sharing cyber threat intelligence. It enables organisations to share, store and correlate technical indicators.

The community rules describe the terms for using the service. 

Frequently asked questions about the FINMISP service

As a general rule, FINMISP is intended for Finnish organisations critical to security of supply. Your organisation must be able to use and share threat intelligence.

The service is currently free of charge.

Ordering the service requires authorisation to act on behalf of the organisation. 

The rights of representation accepted on the order form are:

  • Private trader (ELI)
  • Managing director (TJ)
  • Acting managing director (TJS)
  • Deputy managing director (VTJ)
  • Chairperson of the board of directors of a limited liability company or housing company (PJ)
  • Person authorised to sign for the organisation and entitled to represent the organisation alone (NIMKO)

If the person does not have a right of representation recorded in the Trade Register, the Business Information System or the Register of Associations, a person with the right to represent the organisation can grant them an authorisation via Suomi.fi e-Authorizations Ulkoinen verkkopalvelu.. Authorisations can be granted and viewed in the Suomi.fi e-Authorizations Ulkoinen verkkopalvelu. service.

In addition to the persons with the rights of representation listed above, the FINMISP service can be ordered by a person who has been granted the Suomi.fi mandate “Ordering of cyber security services”.

You can define who the information is shared with. You can restrict the sharing and use of information using TLP and PAP classifications.

You can join the service even if you do not yet know how to use MISP. However, explore the platform in advance and assess whether it is suitable for your organisation’s activities.

Do you have any questions?

Send us a message using the FINMISP service contact form. Sending a message does not commit you to anything.

Page was last updated