CISOs and security officers
Practical guidance from requirement areas and ISO 27001 to systematic security work that lasts over time.
A Swedish book on cybersecurity
Sweden's Digital Resilience: for organisations, leadership and society
Sweden's Cybersecurity Act entered into force on 15 January 2026, transposing the EU NIS 2 directive into Swedish law. Most organisations are not yet ready. This book, written in Swedish, shows what the law requires of you, your leadership and the society around you.
Take the self-assessmentJust want to know when the book is released? Sign up
Free self-assessment against the law's ten requirement areas. A first name and an email address is all it takes.
Written for three readers
One law, three kinds of responsibility. A security chain is never stronger than its weakest link, and the book speaks to each reader without losing the context that connects them.
Practical guidance from requirement areas and ISO 27001 to systematic security work that lasts over time.
The responsibility the law places on leadership, and the questions every board needs to ask and get answered.
Why collective resilience concerns everyone, and what even a small business can do in practice.
Contents
From the threat landscape and regulation to the citizen's everyday life. Twenty-seven chapters that belong together. The book is written in Swedish.
Threat picture, regulation, the Swedish ecosystem and digital sovereignty.
Cybersecurity as a leadership issue, strategy and management systems.
Risk analysis, controls, incident handling, supply chain, AI and OT.
Threat intelligence and continuity in a cyber reality.
Digital preparedness for citizens and small businesses.
Templates, control mapping and checklists ready to use.
Part VI is also available digitally, with fillable templates and interactive tools (in Swedish): open the Toolbox.
What you take away
A clear picture of your position against the law's requirement areas, without unnecessary theory.
What leadership needs to understand about its responsibility, phrased so it can be acted on.
Systematic security work that survives audits, incidents and staff turnover.
How your organisation connects to the collective resilience of society.
Look inside
Throughout the book, illustrations mirror the content. Here is a selection.
Society as a whole
In an interconnected society we are all links: the organisation, the leadership and the citizen. Collective resilience is built in every organisation, in every decision, every single day.
Resilience is not something we have. It is something we build, every day, together.
Common questions
The Cybersecurity Act (cybersäkerhetslagen) is the Swedish law transposing the EU NIS 2 directive. It entered into force on 15 January 2026 and requires systematic cybersecurity work across ten requirement areas, from risk management and incident handling to supply chain security.
NIS 2, often written NIS2, is the EU directive on a high common level of cybersecurity across the union. It replaces the first NIS directive, tightens the requirements and expands the number of sectors covered. In Sweden, the directive is transposed through the Cybersecurity Act.
The Cybersecurity Act entered into force on 15 January 2026. Organisations in scope must register, run systematic cybersecurity work across ten requirement areas and meet the incident reporting duty, from early warning to final report. The supervisory authority can impose administrative fines for shortcomings.
The law covers organisations in 18 sectors, both private and public. The book explains which organisations count as essential or important entities and what the registration duty means in practice.
Management must approve the risk management measures, follow up that they are implemented and undergo cybersecurity training themselves. The law makes this the leadership's own responsibility, and serious shortcomings can lead to administrative fines.
ISO 27001 is an international standard for information security management systems. It is not mandatory, but an established way to structure the work so that the law's requirement areas are covered. The book includes a control mapping between the requirement areas and the standard's controls.
The Cyber Resilience Act (CRA) is an EU regulation setting cybersecurity requirements for products with digital elements on the EU market, fully applying from December 2027. The Cybersecurity Act instead targets organisations and their security work. Many organisations are covered by both: the law for the organisation, the CRA for its products. The toolbox's regulatory navigator shows which frameworks are likely to apply to you.
Primary sources: The Cybersecurity Act (SFS 2025:1506) at the Swedish Riksdag · The NIS 2 directive at EUR-Lex · MCF regulations and incident reporting
Be first
Sign up and we will let you know as soon as the book is available, plus the occasional update along the way.
A first name and an email address is all it takes. No self-assessment required, no noise, and you can unsubscribe at any time. Please note that the book is written in Swedish.
Thank you, you are on the list. We will be in touch when the book is released. Check your spam folder if the confirmation does not arrive.
Launching in autumn 2026, in Swedish. Sign up now, take the self-assessment right away and get a note as soon as the book is available.
Sign up