A Swedish book on cybersecurity

Sveriges Digitala
Motståndskraft

Sweden's Digital Resilience: for organisations, leadership and society

Sweden's Cybersecurity Act entered into force on 15 January 2026, transposing the EU NIS 2 directive into Swedish law. Most organisations are not yet ready. This book, written in Swedish, shows what the law requires of you, your leadership and the society around you.

Take the self-assessment

Just want to know when the book is released? Sign up

Free self-assessment against the law's ten requirement areas. A first name and an email address is all it takes.

Front cover of the book: Sveriges Digitala Motståndskraft (Sweden's Digital Resilience), for organisations, leadership and society, by Kim Borg
Back cover of the book with the back-cover text

Written for three readers

Three links in the same chain

One law, three kinds of responsibility. A security chain is never stronger than its weakest link, and the book speaks to each reader without losing the context that connects them.

CISOs and security officers

Practical guidance from requirement areas and ISO 27001 to systematic security work that lasts over time.

Boards and executives

The responsibility the law places on leadership, and the questions every board needs to ask and get answered.

Citizens and small businesses

Why collective resilience concerns everyone, and what even a small business can do in practice.

Contents

Six parts: from Sweden's Cybersecurity Act to practical resilience

From the threat landscape and regulation to the citizen's everyday life. Twenty-seven chapters that belong together. The book is written in Swedish.

15 Jan 2026law in force
18sectors covered
10requirement areas
  1. I

    The landscape

    Threat picture, regulation, the Swedish ecosystem and digital sovereignty.

  2. II

    Strategy

    Cybersecurity as a leadership issue, strategy and management systems.

  3. III

    Practice

    Risk analysis, controls, incident handling, supply chain, AI and OT.

  4. IV

    Collaboration

    Threat intelligence and continuity in a cyber reality.

  5. V

    Society

    Digital preparedness for citizens and small businesses.

  6. VI

    The Toolbox

    Templates, control mapping and checklists ready to use.

Part VI is also available digitally, with fillable templates and interactive tools (in Swedish): open the Toolbox.

What you take away

From requirements to action

  1. 01

    Know where you stand

    A clear picture of your position against the law's requirement areas, without unnecessary theory.

  2. 02

    Give the board the right questions

    What leadership needs to understand about its responsibility, phrased so it can be acted on.

  3. 03

    Build security work that lasts

    Systematic security work that survives audits, incidents and staff turnover.

  4. 04

    See the whole

    How your organisation connects to the collective resilience of society.

About the author

Kim Borg

Founder and CEO, VER&IT AB

Kim Borg has worked in business and technology leadership in the public and private sectors for more than thirty years. He has been group CIO of an international group with operations in eight countries and a member of its executive team, and has since held roles as head of IT and digitalisation in Swedish local government.

Over the years he has built information security organisations, held NIS responsibility for essential services and served as duty officer with crisis management responsibility linked to Sweden's total defence. The book is written from that work, close to the responsibility rather than beside it.

Today he runs VER&IT AB, which offers advisory services, CISO-as-a-Service and AI-driven efficiency, supporting organisations in their work with the Swedish Cybersecurity Act, the EU AI Act and the GDPR. He is a member of Cybercampus Sverige, Cybernode (NCC-SE), SIG Security and ISACA. The book's starting point is that regulation, leadership responsibility and national resilience belong together, three perspectives that are usually treated separately.

Portrait of Kim Borg, author and CEO of VER&IT AB.
Watercolour from the book: a Swedish community where the town hall, hospital, power plant, waterworks, school and homes are joined by a glowing network.

Society as a whole

Resilience is built from below

In an interconnected society we are all links: the organisation, the leadership and the citizen. Collective resilience is built in every organisation, in every decision, every single day.

Resilience is not something we have. It is something we build, every day, together.

Common questions

Questions and answers about Sweden's Cybersecurity Act

What is Sweden's Cybersecurity Act?

The Cybersecurity Act (cybersäkerhetslagen) is the Swedish law transposing the EU NIS 2 directive. It entered into force on 15 January 2026 and requires systematic cybersecurity work across ten requirement areas, from risk management and incident handling to supply chain security.

What is the NIS 2 directive?

NIS 2, often written NIS2, is the EU directive on a high common level of cybersecurity across the union. It replaces the first NIS directive, tightens the requirements and expands the number of sectors covered. In Sweden, the directive is transposed through the Cybersecurity Act.

When did Sweden's Cybersecurity Act enter into force?

The Cybersecurity Act entered into force on 15 January 2026. Organisations in scope must register, run systematic cybersecurity work across ten requirement areas and meet the incident reporting duty, from early warning to final report. The supervisory authority can impose administrative fines for shortcomings.

Who is covered by the Cybersecurity Act?

The law covers organisations in 18 sectors, both private and public. The book explains which organisations count as essential or important entities and what the registration duty means in practice.

What does NIS2 require of boards and management?

Management must approve the risk management measures, follow up that they are implemented and undergo cybersecurity training themselves. The law makes this the leadership's own responsibility, and serious shortcomings can lead to administrative fines.

How does ISO 27001 relate to the Cybersecurity Act?

ISO 27001 is an international standard for information security management systems. It is not mandatory, but an established way to structure the work so that the law's requirement areas are covered. The book includes a control mapping between the requirement areas and the standard's controls.

How does the Cyber Resilience Act differ from Sweden's Cybersecurity Act?

The Cyber Resilience Act (CRA) is an EU regulation setting cybersecurity requirements for products with digital elements on the EU market, fully applying from December 2027. The Cybersecurity Act instead targets organisations and their security work. Many organisations are covered by both: the law for the organisation, the CRA for its products. The toolbox's regulatory navigator shows which frameworks are likely to apply to you.

Primary sources: The Cybersecurity Act (SFS 2025:1506) at the Swedish Riksdag · The NIS 2 directive at EUR-Lex · MCF regulations and incident reporting

Be first

Get notified when the book is released

Sign up and we will let you know as soon as the book is available, plus the occasional update along the way.

A first name and an email address is all it takes. No self-assessment required, no noise, and you can unsubscribe at any time. Please note that the book is written in Swedish.

Be first when the book is released

Launching in autumn 2026, in Swedish. Sign up now, take the self-assessment right away and get a note as soon as the book is available.

Sign up