Part I · Chapter 6

Cyber defence, Sweden's new doctrine

Swedish cyber defence is part of total defence, and total defence takes in civilian operations too. This chapter separates the three levels of cybersecurity, describes the capability of the Armed Forces and the civil military cooperation inside NCSC, and answers the question that concerns every organisation. What does it mean to be part of something larger than your own operation?

  • CISOs and security leads
  • Boards and leadership teams

Last reviewed

Cyber defence sounds like something that concerns the Armed Forces and nobody else. This chapter shows why that boundary does not hold, and why a municipality, an energy company or a food wholesaler has a role in the question even without a uniform. The point is not that civilian operations should conduct defence, but that national capability depends on them continuing to function.

The chapter opens by separating the three levels. Cybersecurity is the work every organisation does for its own operation. Protective cybersecurity is what applies to operations covered by protective security obligations. Cyber defence is the national capability. The distinction is not academic. It determines who holds the mandate, which body of law governs, who takes the decisions and what is permitted at all. After that comes the cyber defence capability of the Armed Forces and how it has been built up, NCSC as the hub between civil and military, and the cyber component of total defence with the dependencies running in both directions. One section deals with international cooperation within NATO, the EU and the Nordic region, what membership actually means in the cyber domain. The chapter closes with what all of this means for an individual organisation, plus a defence industry perspective on the supplier chain. Who does what on the civilian side is sorted out in chapter 5 on the cybersecurity ecosystem.

The question carries different weight since Sweden joined NATO and since total defence planning was taken up again in earnest. The Cybersecurity Act rests on the same logic. The reason the law names certain sectors is that society stops working if they do, not that those particular organisations would be more exposed than others. That makes the law a total defence question in civilian dress, and it explains why the requirements look the way they do. For an entity covered by the law, it means the value of its own security work reaches further than its own balance sheet.

This page shows what the chapter covers and why the levels are worth keeping apart. The doctrine, the capabilities and the international cooperation in detail are in chapter 6 of the book.

You are not only defending your organisation. You are defending a part of Sweden.

Key insights

  • Cybersecurity, protective cybersecurity and cyber defence are three separate levels with different owners and different legal bases.
  • The digital dimension of total defence rests on civilian operations continuing to function, not on military capability alone.
  • NATO and the EU have moved cyber from a technical support function to a part of collective defence.
  • An organisation with no protective security obligation can still have a role in total defence through the function it serves in society.

Tools that belong to this chapter

The templates and interactive tools are in the Toolbox, free of charge.

Read on

Next step

Where does your organisation stand?

The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.