Electricity distribution company Caruna keeps cybercriminals at bay through continuous staff training in information security, the Elisa Cyber Security Center, and modern technology.
A prolonged disruption to electricity distribution caused by a cyberattack is one of the most serious threat scenarios facing modern society. Electricity is needed for almost everything, including getting food and water to people across Finland. Fortunately, such a scenario is highly unlikely.
Caruna is responsible for one fifth of Finland’s electricity distribution. The company works continuously to ensure that cyber risks do not disrupt Finland’s power supply even for a moment. At Caruna, trust is placed in ongoing information security training for personnel, the ability of machine-learning technology to detect security anomalies at an early stage, and the rapid response capability of the Elisa Cyber Security Center to investigate anomalies and prevent damage.
Cyber security exercises are continuous
“I want to emphasize the importance of continuous training and exercises for personnel,” says Kimmo Juntunen, Head of Cyber Security at Caruna.
Caruna has an information security training program that is mandatory for all employees. In addition, tips and instructions related to information security are actively communicated across the company on a weekly basis, keeping cyber security awareness top of mind.
“Every year we organize a large cyber security exercise involving 20–30 Caruna employees. Through different scenarios, we practice how to handle various types of security incidents. These exercises provide an excellent measure of the level of cyber security competence within our company,” Juntunen explains.
In addition to large-scale exercises, Caruna conducts smaller system- and service-specific recovery exercises. These test whether continuity plans are functional and up to date.
At Caruna, cyber security as a whole is an integral part of business risk management, whose primary objective is to ensure business continuity and uninterrupted operations.
“This is not something you can do alone. In addition to our own personnel, we are supported by Elisa’s cyber security experts. We set out to develop our detection and response capabilities, and through a competitive tendering process we selected Elisa as the provider of our SOC service,” Juntunen says.
“At the Elisa Cyber Security Center, people play a critically important role. We support continuous training and learning, as well as the acquisition of the best cyber security certifications and qualifications. In addition, we have our own cyber security community that enables peer learning among Elisans working in or interested in cyber security,” says Ilari Karinen, Director of Cyber Security Services at Elisa.
Rapid response is built on effective processes
In addition to skilled people, effective cyber security requires well-functioning processes and best practices. When a security incident is detected, cyber security experts investigate it in accordance with jointly agreed industry best practices, leveraging both technology and their professional expertise.
“When operations are standardized – when certain checks are always performed and documentation is ensured – the risk of human error is reduced. At the same time, processes and operating models can be continuously developed and shared for the benefit of Cyber Security Center customers,” Karinen explains.
At Caruna, these processes are tested through cyber security exercises. “We have also updated our processes together with the Elisa Cyber Security Center in connection with the introduction of the SOC service,” Juntunen adds.
“Caruna uses IT systems from several different IT partners, and in the systems they provide, it must be possible to take preventive security measures around the clock in the event of an incident. If handling an incident requires approval from an IT partner, we need to know exactly who to call – say, at three o’clock on a Saturday morning,” Juntunen illustrates the importance of effective cyber security processes.
AI-driven automation detects security incidents at an early stage
In cyber security, rapid response must be supported by technology that enables early and automated detection of security anomalies. At Caruna, this includes reliance on Palo Alto Networks’ Cortex XDR technology.
“Using machine learning and artificial intelligence, it is possible to analyze enormous volumes of data in real time. This data is collected from endpoints, network traffic, cloud applications, and IoT devices. When security anomalies are detected, some can be blocked automatically, while others are forwarded to cyber security experts for analysis. Thanks to AI, we can also analyze and prevent previously unknown new threats,” says Jari Hemminki, Country Manager at Palo Alto Networks.
AI is also used for behavioral analysis, profiling both endpoints and users. This makes it possible to identify security incidents at an earlier stage – particularly those that occur when cybercriminals infiltrate an organization using stolen but legitimate credentials.
“With rich data, it becomes much easier to determine what has actually happened, identify attack chains, and block them.”
Hemminki emphasizes the importance of companies having access to the same kind of automated, machine-driven defensive capabilities as the criminals carrying out cyberattacks.
“We are seeing increasing probing at the network perimeter. Various botnets automatically test IT environments and search for vulnerabilities to exploit,” Juntunen says, describing Caruna’s experience.
Developing cyber security is therefore a continuous effort – a race against cybercriminals.
“We hold regular joint cyber security development meetings with Elisa. We have a cyber security roadmap for the next couple of years, and it is updated annually,” Juntunen concludes.
Learn more about Elisa’s Cyber Security Services
Photo: Caruna
Avainsanat





