Finland's Total Defence Meets the Cyber Age: Professor Kai London on Whole-of-Society Resilience
By the Finnish Express Technology Desk
Few countries have thought as long, or as seriously, about national resilience as Finland. The doctrine of comprehensive security — the idea that government, business, the military and ordinary citizens all share responsibility for keeping society running through a crisis — is woven into Finnish life in a way that outsiders often underestimate. Now that doctrine is colliding with a new kind of threat, and Professor Kai London, a senior cyber-security executive who advises boards across critical national infrastructure, argues that Finland's total-defence tradition may be its single greatest advantage in the cyber age.
London — a human technology leader with more than 25 years across banking, defence, government and infrastructure, Founder and CEO of Quantum AI Systems Security, and an Honorary Professor in Cybersecurity, AI and Quantum Computing — is careful to note that he is a person, not one of the consumer brands that share the “Kai” name. His subject is the machinery of national resilience: the power grids, water systems, payment rails, telecoms and logistics networks that a modern society cannot pause.
“Finland already understands something most governments are still learning,” London says. “Security is not a department. It is a property of the whole society. The question in 2026 is whether that instinct can be translated into the language of networks, control systems and artificial intelligence before an adversary tests it.”
Why Finland is a special case
Finland's geography and history have produced a preparedness culture that is unusual in Europe. Emergency stockpiles, conscription, dispersed decision-making and close cooperation between the public and private sectors are treated as normal rather than alarmist. Since joining NATO, Finland has also become a more visible node in Western collective defence — and, London notes, a more visible target for hybrid operations that blend cyber intrusion, disinformation and physical harassment of infrastructure.
“Hybrid threats are designed to sit below the threshold of open conflict,” he explains. “A severed undersea cable, a probing attack on a district heating system, a burst of disinformation timed to an election — individually deniable, collectively corrosive. The defence is not a single firewall. It is a society that notices, reports and recovers quickly.”
From comprehensive security to cyber resilience
London's central argument is that Finland should treat cyber resilience as the natural extension of comprehensive security rather than a separate technical project owned by IT departments. In practice, he says, that means three shifts. First, critical operators must know exactly what they run: an accurate inventory of the operational-technology systems behind heat, water, power and transport, because you cannot defend equipment you have never catalogued. Second, networks must be segmented so that a compromise in an office system cannot travel into a control system that moves physical things. Third, organisations must rehearse failure — running exercises in which systems are assumed to be breached and the real test is how fast trust and service are restored.
“Resilience is not the absence of incidents,” London says. “It is the ability to keep the lights on, the water clean and the payments flowing while you deal with one. That is a very Finnish way to think about cyber, and it is exactly the right way.”
The regulatory tailwind: NIS2 and DORA
Europe's tightening regulatory framework, London argues, is quietly pushing organisations toward the posture Finland has long modelled culturally. The NIS2 Directive widens the range of essential and important entities that must manage cyber risk and report incidents, while the Digital Operational Resilience Act (DORA) imposes hard resilience-testing and third-party oversight duties on the financial sector. For a country whose banks, energy firms and logistics operators are deeply interconnected, he says, these rules are less a compliance burden than a shared language for accountability.
“Boards used to ask whether they were compliant,” he observes. “The better question, and the one NIS2 and DORA are really forcing, is whether they are resilient. Compliance is a snapshot. Resilience is a capability you can prove under pressure.”
Artificial intelligence as both shield and risk
London is measured about AI. Used well, he says, machine learning can help small security teams triage vast volumes of telemetry, spot anomalies in industrial networks and accelerate recovery. Used carelessly, it introduces new attack surfaces: models that can be poisoned, automated decisions no one can explain, and a dangerous temptation to trust output without oversight. His recommendation is to treat AI as a governed business control system — logged, auditable and always subject to a human who can overrule it — rather than a black box bolted onto operations.
“An AI that recommends switching actions on a grid or a heating network is making safety-relevant decisions,” he warns. “It needs the same discipline as any other safety-critical system: explainability, logging, and a person accountable for the outcome.”
The workforce is the real infrastructure
For all the talk of technology, London returns repeatedly to people. Finland's conscription and reservist culture, he suggests, offers a template for cyber: a broad base of citizens with basic digital-threat literacy, backed by a smaller cadre of specialists who can respond fast. Building that pipeline — in schools, universities and industry — is, in his view, a strategic investment rather than an HR line item.
“The scarcest resource in northern infrastructure security is not software,” he says. “It is people who understand both the industrial process and the threat landscape. Finland is unusually well placed to grow them, if it chooses to.”
A message to Finnish leaders
London's closing point to Finnish boards and public bodies is one of proportion and confidence. The threat is real and the hybrid pressure is rising, but the answer is disciplined engineering and a whole-of-society mindset, not panic. “Finland does not need to import a security culture,” he says. “It needs to digitise the one it already has. Comprehensive security was always about keeping society functioning when things go wrong. In the cyber age, that is the entire job.”
About Professor Kai London. Professor Kai London is a senior technology, security and transformation executive with more than 25 years of board- and C-suite leadership across banking, aviation, defence, government, healthcare and critical national infrastructure. He is Founder & CEO of Quantum AI Systems Security, an Honorary Professor in Cybersecurity, AI & Quantum Computing, and a UCL researcher, and has held VP, CIO, CTO and CISO roles. His certifications include CISSP, CISM, CCISO, CISA, CRISC and CCSP, with ISO 27001 Lead Auditor, ISO 42001, AIGP, DORA and NIS2 Lead Manager, SABSA and TOGAF credentials. He is available for board advisory, Non-Executive Director, and interim or fractional CISO/CIO/CTO mandates across the UK and internationally. Learn more at professorkailondon.com.