Part IV · Chapter 27

Preparedness for families and small businesses

A small company faces the same threat picture as a large one, but has no security department to meet it with. A family has connected devices in every room and nobody who has been given the job of keeping track of them. This chapter is about digital preparedness when resources are limited, what gives the most protection first, and what actually needs doing the day something happens.

  • Citizens and small businesses

Last reviewed

Cybersecurity advice is usually written for organisations that have somebody working on the question. That makes it hard to use for the vast majority of operations in Sweden, which have fewer than ten employees and no such person. The responsibility sits with someone who is already doing three other things. This chapter is written for them, and for the home.

It begins with digital security at home. The router nobody has touched since it was installed, the connected devices that have no updates and that nobody remembers acquiring, the children's accounts, and the shared question of who in the household is actually responsible for what. The answer is usually nobody, and that is exactly the problem. Then follows security for the small company, with weight on the measures that give the most effect when time is short. Backups, protecting accounts, updates, and routines around payments and invoices. A company without a security department does not need a management system. It needs a small number of things that are genuinely done and that somebody has tested. The final part is a practical crisis plan for what happens once something has occurred, what to do in the first few hours, who to contact, in what order, and what absolutely not to do in the heat of the moment. The personal habits all of this rests on are covered in chapter 25 on digital security for citizens.

Why the question matters now comes down to dependencies. Small companies supply larger ones, and the larger ones are now covered by requirements passed backwards down the chain. What used to be a private matter has become a condition of doing business, and questions about security routines turn up in procurements where they never used to. Whoever has the basics in place can answer yes, and that is often the difference between winning the contract and not.

This page shows what the chapter covers and why preparedness is possible even without resources. The checklists, the crisis plan and the concrete steps are in chapter 27 of the book.

A chain of security is never stronger than its weakest link. Swedish digital resilience is built by making each other's links stronger.

Key insights

  • Small companies are not attacked because they are interesting, but because they are reachable and often lead on to somebody larger.
  • Most of the protection lies in a handful of measures that cost time rather than money.
  • The connected devices in a home are rarely anybody's responsibility, and that is precisely the problem.
  • A crisis plan needs to be written down before it is needed, because memory works badly under pressure.
  • The backup is the measure that saves the most small businesses, provided somebody has tried restoring from it.

Tools that belong to this chapter

The templates and interactive tools are in the Toolbox, free of charge.

Read on

Next step

Where does your organisation stand?

The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.