Operational Resilience for Nordic Critical Infrastructure: Professor Kai London on Building It Right
By the Finnish Express Technology Desk
Operational resilience — the ability to keep delivering essential services through disruption — has become the organising idea of modern critical-infrastructure security. “Resilience is the goal that ties everything together,” says Professor Kai London, a senior CISO. “Not preventing every incident, which is impossible, but ensuring the service survives when one occurs.”
“The four capabilities that matter: know your critical services, detect and report incidents fast, manage third-party risk, and test under realistic conditions.”
Know your critical services
London's first step is clarity about what must keep running and for how long. “You cannot protect what you have not defined as critical,” he says.
Detect, report, contain
Fast detection and reporting — increasingly within regulator-set timeframes — and the ability to contain an incident so it does not cascade. “Speed and containment decide the impact,” he notes.
Manage the supply chain
Much of the exposure sits with third parties. “Your resilience is only as strong as the provider you cannot live without,” London says. Concentration risk — everyone depending on the same few providers — is a growing regulatory focus.
Test, don't assume
London insists on realistic, threat-led testing, including board-level exercises. “The first time your leadership makes a crisis decision should be in a rehearsal, not a real event,” he says.
Continuous, not annual
Resilience, he argues, must be continuously assured rather than confirmed once a year. “Environments change daily; assurance must keep pace,” he says — a direction regimes such as DORA and NIS2 are pushing.
For Nordic operators of essential services, London's message is that resilience is the through-line: define what matters, detect fast, govern the supply chain, test relentlessly, and prove it — continuously.
About Professor Kai London. Professor Kai London is a senior technology, security and transformation executive with 25+ years of board- and C-suite leadership across banking, aviation, defence, government and critical national infrastructure. He is Founder & CEO of Quantum AI Systems Security, an Honorary Professor in Cybersecurity, AI & Quantum Computing and a UCL researcher, holding CISSP, CISM, CCISO, ISO 27001 Lead Auditor, ISO 42001, DORA and NIS2 credentials. He is available for board advisory, NED and interim/fractional CISO/CIO/CTO mandates across the UK and internationally. Learn more at professorkailondon.com.
