Pohjois-Suomen Hallituspartnerit ry has awarded the Tamminen Nuija to Netox Oy. The recognition is granted annually to a company that has achieved significant value creation through high-quality board work. The award was presented at the Board Summit – Elotreffit event on 27 August 2026.

Chairman of the Board Henry Nieminen and CEO Mikko Luhtaniemi accepted the award on behalf of the company.

Netox has grown from a company founded in Oulu in 2004 into a nationally significant cybersecurity and IT services provider. Revenue was EUR 34.5 million in 2025 with approximately 150 employees.

The jury’s criteria emphasise the genuine impact of an active board on company performance, a clear direction and strategy, and the presence of independent, capable board members.

End-to-end security cannot be added afterwards

Netox’s particular expertise lies in the end-to-end security of its services. Networks, servers, endpoints and network devices are not separate purchases but a single system whose security must be designed in from the start. Added afterwards, security leaves seams – and seams are exactly where an attacker gets in.

In sectors critical to security of supply and in defence, this is not a matter of preference. Requirements apply across the entire chain and the entire lifecycle, and they must be demonstrable – including under emergency conditions. A single unmanaged node is enough to compromise the whole.

“Our customers do not buy hardware or licences from us. They buy the assurance that their operations continue. That promise cannot be kept if security is scattered in pieces across different suppliers,” Luhtaniemi says.

Regulation now demands the same. The NIS2 Directive requires organisations to assess the governance and management system maturity of their partners — not only their technical controls.

Certifications are evidence of management, not a badge on a website

Netox has been certified to ISO 27001 since 2014 – at a time when IT service providers were rarely validated externally. Alongside it are ISO 9001 (quality management), ISO/IEC 20000-1 (service management), ISO 14001 (environmental management) and ISO 22301 (business continuity management).

In addition, Netox holds a KATAKRI assessment audited by KPMG, covering the capability to handle classified information. KATAKRI is the Finnish authorities’ audit criteria for assessing an organisation’s ability to protect classified material.

No single certificate is the point. ISO 27001 is now a minimum requirement in many tenders and does not by itself distinguish suppliers. Two things do.

First, maintaining five management systems in parallel: quality, information security, service delivery, environment and continuity within the same audited framework. ISO 22301 deserves particular attention, because it addresses precisely what Netox promises its customers – operational continuity.

Second, KATAKRI. It is not a voluntary quality mark but an assessment against authority requirements, and passing it requires documented and verifiable practices across the whole organisation – from personnel security to physical security and technical implementation.

“A certificate can be acquired as a project. Five parallel management systems and a national-authority-level audit cannot be maintained as a project. They require management structures that hold up under daily scrutiny. That is independently verified evidence that this company does what it says it does,” says Henry Nieminen, Chair of the Board of Netox.

The same discipline shows in customer selection. Netox has recently won several significant public sector tenders, including IT and cybersecurity contracts with Apotti, the City of Turku, Senate Properties and HSL (EUR [2.2] million). Microsoft named Netox its Partner of the Year 2025 in Finland in the Security First category. In 2025 Netox was also a finalist in the Buyout category of the Building Growth competition (FVCA / PwC).

The founder’s choice

Luhtaniemi founded Netox in 2004 and still leads it. The board was opened to external members later.

“Moving from an entrepreneur-led company to a professionally managed growth company is a deliberate choice, not an accident. Opening the board to independent members has been one of the most important decisions I have made. It did not take power away from me — it brought challenge and experience of stages I had not yet seen myself,” Luhtaniemi says.

Netox’s board work is built around an annual cycle: strategy review, metrics and target setting, risk management and preparation of corporate transactions are handled in a predictable rhythm.

“A board’s job is not to run the company. It is to make sure the company is well run and the direction is right. Netox has done the work that most companies of this size never get to: the management structures were built before growth forced them,” Nieminen says.

The Tamminen Nuija recipient becomes a candidate for the national Kultainen Nuija award, presented at the Hallituspaikka event in Tampere.