Big case handling @ NCSC-FI - Matias Mesiä

Matias Mesiä (Head of Operations · NCSC-FI)

Disobey 2026 · Main Stage

Overview

Matias Mesiä, Head of Operations at the National Cyber Security Centre Finland (NCSC-FI), delivered a compelling talk at Disobey, offering an insider's perspective on the complexities and critical importance of managing "big cases" – major cyber incidents – at a national level. The presentation, aptly titled "Big case handling @ NCSC-FI," delves into the strategies, processes, and challenges faced by a national Computer Emergency Response Team (CERT) responsible for the cybersecurity of an entire nation, encompassing every citizen, organization, and agency in Finland. Mesiä's talk highlights the sheer scale of operations, from automated incident handling to deeply involved, multi-agency "seizure operations" that demand significant resources and intricate coordination.

Watch on YouTube

Visual summary for Big case handling @ NCSC-FI - Matias Mesiä by Matias Mesiä
Visual summary for Big case handling @ NCSC-FI - Matias Mesiä by Matias Mesiä

Key moments

  1. 0:00 Introduction to NCSC-FI and big case handling
  2. 2:00 NCSC-FI's annual incident volume and 'seizure operations'
  3. 3:20 Real-world examples of NCSC-FI's diverse major incidents
  4. 7:00 Step-by-step process for handling major cyber incidents
  5. 10:00 Challenges in implementing lessons learned and hot reporting
  6. 11:00 NCSC-FI's three-tier model and monitoring challenges

Big case handling @ NCSC-FI - Matias Mesiä

Speakers: Matias Mesiä, Head of Operations, NCSC-FI

Conference: Disobey

YouTube: https://www.youtube.com/watch?v=7PCKYSREZvU

Overview

Matias Mesiä, Head of Operations at the National Cyber Security Centre Finland (NCSC-FI), delivered a compelling talk at Disobey, offering an insider's perspective on the complexities and critical importance of managing "big cases" – major cyber incidents – at a national level. The presentation, aptly titled "Big case handling @ NCSC-FI," delves into the strategies, processes, and challenges faced by a national Computer Emergency Response Team (CERT) responsible for the cybersecurity of an entire nation, encompassing every citizen, organization, and agency in Finland. Mesiä's talk highlights the sheer scale of operations, from automated incident handling to deeply involved, multi-agency "seizure operations" that demand significant resources and intricate coordination.

The talk provides a candid look at the high-stakes environment where NCSC-FI operates, balancing rapid response to evolving threats with long-term strategic improvements. Mesiä uses a metaphor of a pelican hitting a turbine to illustrate the disruptive nature of cyber incidents on critical infrastructure, emphasizing the constant vigilance required. Through real-world examples, including high-profile data breaches and zero-day vulnerabilities affecting government and critical sectors, he underscores the persistent threat landscape and the unique pressures faced by a national cybersecurity authority. The presentation is not merely a description of processes but a reflection on the lessons learned, the inevitable failures, and the continuous drive for improvement in an ever-challenging domain.

This article aims to dissect Mesiä's insights, exploring the operational framework, technical challenges, and strategic imperatives that define national-level cyber incident management. It will detail the practical aspects of incident response, from initial detection and prioritization to cross-organizational collaboration and public communication. By examining NCSC-FI's approach, organizations and policymakers can glean valuable lessons on enhancing their own cybersecurity resilience and understanding the broader ecosystem of national cyber defense.

Background

▶ Watch: Introduction to NCSC-FI and big case handling (0:00)

The National Cyber Security Centre Finland (NCSC-FI), an integral part of the Finnish Transport and Communications Agency (Traficom), plays a pivotal role in safeguarding Finland's digital landscape. While NCSC-FI itself was founded in 2014, its CERT operations, known as Safi, trace their origins back to 2002, establishing a long-standing commitment to national cyber defense. The scale of NCSC-FI's operations is immense: they automatically handle approximately 200,000 incident cases per year, while manually addressing around 20,000. Crucially, Mesiä highlighted a specific category of incidents – "seizure operations" or "big cases" – with 18 such operations recorded in 2024 and a similar number projected for 2025. These are the most critical and resource-intensive incidents, typically requiring the active involvement of 10 to 20 NCSC-FI personnel during their peak phase.

NCSC-FI's unique position means its "customers" include every citizen, organization, and agency in Finland, necessitating a highly adaptable and comprehensive incident management strategy. Mesiä provided several illustrative examples of these significant incidents:

  • Helsinki Data Breach (2024): A major incident affecting the city of Helsinki, which served as a prime case study for the challenges of managing large-scale data breaches.
  • Submarine Cable Failures (2023-2024): Incidents affecting critical national infrastructure, demanding immediate and coordinated responses.
  • CrowdStrike Bad Patches (July 2024): A rapid-response scenario requiring NCSC-FI to issue urgent communications and guidance to critical sector organizations within a single day.
  • Monitoring National Events: Proactive cybersecurity monitoring during significant events like presidential elections or high-profile visits (e.g., Talinski Biden), often involving the mitigation of Distributed Denial of Service (DDoS) attacks.
  • Government Incidents (Vtory, January 2024): A recent and critical case involving a zero-day vulnerability that led to approximately 50,000 government personnel losing some information. This incident, still under police investigation, highlighted the challenges of responding to novel threats.
  • Critical Sector Data Breaches and Niagras Attacks (2024): Further examples of significant incidents impacting vital services and infrastructure.
  • Malware Campaigns (Flubot, 2021): NCSC-FI, acting as a regulator for ISPs, leveraged its authority to enforce filtering of SMS/MMS messages and blocking of scams, demonstrating its proactive role in mitigating widespread threats. This also extends to ongoing cooperation with banks and ISPs to block phishing sites.

These diverse incidents underscore the dynamic and broad scope of NCSC-FI's responsibilities. The center must not only react to immediate threats but also anticipate emerging risks, coordinate with a vast network of stakeholders, and continuously refine its processes to maintain national cyber resilience. The background sets the stage for understanding the structured yet flexible approach NCSC-FI employs to tackle these "big cases."

Key Findings

▶ Watch: Real-world examples of NCSC-FI's diverse major incidents (3:20)

Matias Mesiä's presentation unveiled several critical findings derived from NCSC-FI's extensive experience in handling major cyber incidents, collectively known as "seizure operations" or "big cases." These findings offer valuable insights into the persistent challenges and effective strategies in national-level cybersecurity.

First and foremost, the major incident management process is indispensable for effective national cyber defense. NCSC-FI’s structured approach, encompassing clear phases from initiation to lessons learned, is vital for coordinating complex responses involving multiple internal teams, victim organizations, law enforcement, and other government bodies. The talk highlighted that initiating this process isn't always immediate; incidents can "grow" into major operations over days or weeks, requiring continuous monitoring and assessment.

A recurring and significant threat vector identified is edge devices, particularly VPNs, firewalls, and other perimeter security solutions. Mesiä stated that these devices "remain a constant target for malicious actors," estimating 30 to 50 critical incidents related to edge devices in Finland over the past five years. High-profile cases like the Helsinki data breach and the recent Vtory incident underscore this vulnerability. The Helsinki case, involving a Cisco ASA VPN device running an 8-9-year-old software version, exemplified the danger of outdated systems. The Vtory incident was particularly concerning as it exploited a zero-day vulnerability, demonstrating that even fully patched systems can be at risk, though unpatched systems remain a far more common entry point. NCSC-FI's proactive scanning efforts (using Shodan, Census, etc.) frequently reveal hundreds of vulnerable devices across Finland, many belonging to critical sector organizations.

Another critical finding revolves around the pervasive issue of outdated and unlicensed software. Mesiä shared anecdotes of organizations, even those with multi-million-euro revenues, running critical VPN devices without valid licenses. This prevents them from applying essential security updates, leaving them exposed to known vulnerabilities. This self-inflicted vulnerability significantly exacerbates the risk posed by edge devices.

Proactive monitoring and outreach are crucial. NCSC-FI’s ability to identify vulnerable organizations through scans and then directly contact them (via email, phone, or even chat/Signal for established contacts) has been instrumental in mitigating widespread threats. For instance, after the Helsinki data breach, NCSC-FI identified 384 organizations using similar vulnerable Cisco ASA SSLVPN devices; this number quickly dropped to around 20 following their direct intervention.

Effective information sharing is paramount, yet fraught with challenges. NCSC-FI utilizes protocols like TLP Amber to share Indicators of Compromise (IOCs) from live cases with critical sector organizations. The upcoming Finn Misp platform is anticipated to streamline this process further. However, Mesiä also candidly shared an internal NCSC-FI failure involving a data leak notification sent with CC instead of BCC, highlighting the human element and the importance of meticulous communication. The incident also underscored the need for multi-lingual communication in Finland (Swedish).

Finally, the talk emphasized the difficulty but absolute necessity of lessons learned processes. Mesiä admitted that even NCSC-FI struggles with effectively integrating lessons learned into production. He stressed that without dedicated ownership and prioritization, valuable insights from incidents are often lost, preventing continuous improvement. This finding extends to the broader need for incident response processes to be flexible, easy to start, and regularly tested and practiced to ensure they are truly operational rather than merely audit-compliant.

Technical Deep Dive

▶ Watch: Step-by-step process for handling major cyber incidents (7:00)

NCSC-FI's approach to "big cases" is underpinned by a structured yet adaptable major incident management process, designed to scale from initial detection to post-incident analysis. This process, while resembling standard enterprise incident response frameworks, is tailored for the national scale and its diverse stakeholders.

The process begins with initiation, which isn't always on "day one" of an incident. Mesiä explained that some events, like a submarine cable failure, might immediately trigger a CERT operation. However, others, such as the Helsinki data breach, can evolve from a smaller incident over days or even weeks before being classified as a "big case." This necessitates continuous monitoring and assessment.

Once initiated, a case organization is established, assigning specific roles: a coordinator, a lead, technical experts, communications personnel, and situation awareness specialists. This ensures clear responsibilities and efficient information flow. Daily check-ins are a critical component, involving internal NCSC-FI teams, the victim organization, and sometimes law enforcement (e.g., three separate check-ins for the Vtory case with internal teams, the victim, and police). A crucial aspect is calming down incidents; NCSC-FI, with finite resources, must strategically scale down resolved or less critical cases to free up capacity for new ones.

Reporting extends beyond post-incident summaries. NCSC-FI often produces "hot reports" for policymakers during ongoing incidents, especially for cases that generate significant political discussion, like the Nordi Adidos cases. These white papers provide real-time situational awareness to government officials. The most challenging phase is lessons learned, which Mesiä candidly described as often failing. He emphasized the need for dedicated personnel responsible for gathering, prioritizing, and implementing findings from past incidents.

NCSC-FI employs a three-tier model for incident classification: Critical, High, and Medium. The most challenging aspect is the monitoring layer, where NCSC-FI sifts through 20,000 annual incident tickets to identify the 100-200 cases that might escalate into full "seizure operations." This requires sophisticated triage and early warning capabilities.

A significant portion of Mesiä's talk focused on edge device vulnerabilities, which are a persistent and critical threat. He highlighted common culprits like Cisco ASA, Citrix NetScaler, Palo Alto, and Ivanti VPN devices. NCSC-FI proactively identifies vulnerable instances through techniques like scanning and leveraging services like Shodan and Census. In a simulated scenario, Mesiä presented a critical Remote Code Execution (RCE) vulnerability in a VPN device, with 300 vulnerable organizations in Finland and two already breached. This simulation underscored the complex prioritization decisions involved:

  • ISP (Internet Service Provider): Often the first priority due to the potential for a single ISP to host 30 or more vulnerable devices, affecting numerous customers simultaneously. NCSC-FI leverages strong existing contacts with ISPs for rapid communication.
  • High-Risk Victims: Organizations like municipalities and smaller industry organizations are often prioritized due to their typically weaker monitoring capabilities and tendency to run older, unpatched software (e.g., VPN devices from 2019). These are considered high-potential ransomware targets.
  • Critical Infrastructure/Services: Organizations in transport, logistics, food sectors, private hospitals, and government agencies also receive high priority due to their societal impact.

Real-world examples reinforced these priorities:

  • The Foreign Ministry suspected hacking (2023) and the Vtory case (January 2024) illustrate government-level incidents linked to edge devices, with Vtory specifically involving a zero-day vulnerability affecting 50,000 government employees.
  • The Helsinki data breach (May 2024) involved a Cisco ASA SSLVPN device running an 8-9-year-old version. NCSC-FI identified 384 similar vulnerable devices across Finland, including in critical sectors and municipalities. Direct outreach reduced this number to around 20, demonstrating the impact of proactive notifications.
  • Mesiä also shared instances from Ivanti cases (2024) and other Cisco ASA incidents (September 2023) where organizations were unable to patch critical vulnerabilities because they were using devices without valid licenses, preventing software updates.

Information sharing is a cornerstone of NCSC-FI's strategy. They regularly share Indicators of Compromise (IOCs) from active cases with critical sector organizations using TLP Amber protocol. This rapid dissemination allows other organizations to check their environments for signs of compromise. The upcoming Finn Misp platform aims to enhance this capability, providing a more effective channel than traditional email for sharing threat intelligence.

Finally, Mesiä briefly touched upon DDoS attacks, noting that while they remain a threat to availability in Finland, improved information sharing and collaboration with banks and ISPs have significantly enhanced the collective response, making these incidents more manageable and transparent. The goal is to reach a point where organizations can openly discuss DDoS incidents as a technical challenge, similar to DNS issues, rather than a hidden embarrassment.

Demo / Proof of Concept

▶ Watch: Challenges in implementing lessons learned and hot reporting (10:00)

Matias Mesiä's presentation did not include a traditional technical demonstration or proof of concept in the sense of showcasing an exploit or a live tool. Instead, the "NCSC-FI simulator" segment served as a conceptual, interactive exercise designed to illustrate the real-world decision-making challenges faced by a duty officer at NCSC-FI.

This simulator presented a hypothetical scenario: a critical Remote Code Execution (RCE) vulnerability discovered in a widely used VPN device (e.g., Cisco ASA, Citrix NetScaler, Palo Alto, Ivanti), already being exploited globally. The duty officer (represented by the audience) is then tasked with prioritizing which of 300 vulnerable Finnish organizations, including critical entities like ISPs, municipalities, hospitals, and government agencies, should be contacted first, especially given that two devices are already known to be breached.

Mesiä used this exercise, which is actually employed in NCSC-FI's top interviews, to highlight the nuanced factors influencing prioritization: the potential for cascading impact (e.g., an ISP affecting 30 customers), the likelihood of inadequate internal security capabilities (e.g., smaller municipalities lacking a Security Operations Center), and the criticality of the services provided. While not a technical demo, this interactive segment effectively demonstrated the complex, high-pressure environment of national cyber incident response and the critical thinking required to allocate limited resources effectively.

Defensive Implications

▶ Watch: NCSC-FI's three-tier model and monitoring challenges (11:00)

Matias Mesiä's insights from NCSC-FI's "big case" handling offer crucial defensive implications for organizations of all sizes, emphasizing proactive measures, robust processes, and collaborative defense.

  1. Prioritize Edge Device Security: The talk unequivocally identifies edge devices (VPNs, firewalls, remote access solutions like Cisco ASA, Citrix NetScaler, Palo Alto, and Ivanti) as primary targets. Defenders must implement stringent security practices for these devices:
  • Aggressive Patching: Maintain an extremely short patch cycle for all internet-facing devices. The Helsinki data breach with an 8-9-year-old Cisco ASA version serves as a stark warning.
  • License Compliance: Ensure all critical software and hardware are properly licensed. Unlicensed software prevents essential updates, creating critical vulnerabilities as seen in Ivanti and Cisco ASA cases.
  • Continuous Monitoring: Implement robust monitoring for these devices to detect suspicious activity, even if a zero-day vulnerability (like in the Vtory incident) bypasses patches.
  1. Develop and Practice a Flexible Incident Response Plan: A well-defined Major Incident Management (MIM) process is non-negotiable.
  • Clear Roles and Responsibilities: Pre-define who leads, investigates, documents, communicates, and gathers information during an incident. Avoid a "complete storm" by assigning these roles beforehand.
  • External Contracts: Have pre-negotiated contracts with Digital Forensics and Incident Response (DFIR) companies. Waiting until an incident occurs to find help wastes critical time.
  • Documentation: Emphasize documentation during the incident. Consider having a dedicated person to write down timelines and actions, allowing technical responders to focus on investigation.
  • Flexibility and Ease of Start: The process must be adaptable to both small and large incidents. If the process is too cumbersome, it won't be used. NCSC-FI's experience shows that a culture of "just starting" the process is vital.
  • Regular Testing and Practice: Don't let the MIM process be "only for audits." Conduct regular tabletop exercises and simulations to test the process, communication channels, and team readiness.
  1. Proactive Vulnerability Management and Outreach:
  • Self-Scanning: Organizations should regularly scan their own external-facing assets using tools and techniques similar to those NCSC-FI employs (Shodan, Census) to identify vulnerabilities from an attacker's perspective.
  • Heed Notifications: Respond promptly to notifications from national CERTs like NCSC-FI regarding identified vulnerabilities in your infrastructure. These notifications are often based on real-time threat intelligence.
  1. Embrace Information Sharing:
  • Join Threat Intelligence Platforms: Actively participate in platforms like the upcoming Finn Misp to receive and contribute IOCs and TTPs (Tactics, Techniques, and Procedures). This collective defense mechanism is crucial.
  • Inform NCSC-FI (or your national CERT): Share details of incidents, even anonymously. This information helps the CERT build a broader picture of threats, identify campaigns, and warn other organizations, as NCSC-FI does by sharing details without revealing the source incident.
  1. Strategic Public Communication:
  • Transparency is Key: As demonstrated by the Vtory case's successful media handling, open and timely communication about a cyber incident often garners more understanding and trust from media, politicians, and the public. Trying to hide or downplay incidents usually backfires, leading to more scrutiny.
  • Prepare for Multi-Lingual Communication: Organizations operating in multi-lingual environments (like Finland with Swedish) must ensure their incident communications are accessible in all relevant languages.
  1. Continuous Improvement through Lessons Learned:
  • Dedicated Ownership: Assign responsibility for the "lessons learned" phase. It's often the hardest part, but without it, organizations repeat past mistakes.
  • Integrate Findings: Ensure lessons learned are translated into actionable changes in policies, processes, and technical controls.

By adopting these defensive postures, organizations can significantly enhance their resilience against the "cyber pelicans" that threaten critical infrastructure and data, transforming potential "big cases" into manageable incidents.

Key Takeaways

  • Edge Devices are Primary Targets: VPNs and other internet-facing perimeter devices are constantly under attack. Organizations must prioritize aggressive patching, vigilant monitoring, and ensuring proper licensing for these critical assets to prevent breaches like the Helsinki data breach and Vtory incident.
  • Robust, Flexible Incident Management is Essential: A well-defined, practiced, and easily initiable major incident management process, with clear roles and communication channels, is crucial for effective response, rather than merely being an audit-compliant document.
  • Proactive Vulnerability Identification and Outreach Works: National CERTs like NCSC-FI actively scan for vulnerable systems (e.g., using Shodan and Census) and proactively notify organizations. Responding promptly to these notifications can prevent widespread compromise, as demonstrated by the reduction of vulnerable Cisco ASA devices after NCSC-FI's intervention.
  • Information Sharing Fuels Collective Defense: Sharing Indicators of Compromise (IOCs) and Tactics, Techniques, and Procedures (TTPs) through platforms like TLP Amber and the upcoming Finn Misp between government, critical sectors, and international partners significantly strengthens national cyber resilience.
  • Transparency in Public Communication Builds Trust: Openly communicating about cyber incidents, rather than attempting to conceal details, generally leads to better reception from media, politicians, and the public, as exemplified by the Vtory case's communication strategy.
  • Lessons Learned Must Be Actionable: The "lessons learned" phase of incident response is often neglected but critical. Organizations must dedicate resources to systematically capture, prioritize, and integrate findings from incidents into their operational practices to drive continuous improvement.

About the Speaker(s)

Matias Mesiä is the Head of Operations at the National Cyber Security Centre Finland (NCSC-FI), a critical national authority responsible for safeguarding Finland's digital infrastructure. He has been with NCSC-FI for nearly six years, dedicating his expertise to managing the country's most significant cyber incidents, which he refers to as "big cases" or "seizure operations." Mesiä holds a Master of Engineering degree from Jyväskylä University of Applied Sciences.

Known for his practical and candid approach, Mesiä has previously appeared on Finnish television shows like "Rico Spika," commenting on high-profile cyber events such as the Helsinki data breach. He often uses humor and self-deprecating remarks, describing himself as a "dump guy from NCSC-FI," to make complex topics relatable. His extensive experience in the trenches of national cyber defense provides him with a unique perspective on the challenges of incident response, inter-organizational cooperation, and the continuous evolution of the threat landscape.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Mesiä delivers a rare, unfiltered look at how a national CERT actually operates under fire — not a polished comms piece, but a practitioner talking honestly about failures, resource constraints, and the unglamorous grind of big-case coordination. The Helsinki breach, Vtory zero-day, and Flubot regulatory action aren't just name-drops; they're used to illustrate real decision-making friction that peers can learn from.

Heather Calloway (CISO) — STRONG ACCEPT

A practitioner talk from someone who has actually run national-scale incident response, with real cases, honest failure acknowledgment, and concrete operational lessons. It stops short of a must-see because it operates primarily at the program and process level rather than surfacing governance or accountability gaps that would force institutional change — but it earns its place on any serious defender's watch list.

→ Top-rated talks at Disobey 2026

All talks from Disobey 2026