Part I · Chapter 1

The new security landscape

The threat picture facing Sweden does not look the way it did ten years ago. Attacks no longer come only from criminals after money, but just as often from actors after something else, trust, freedom of action or access to someone further along the chain. This chapter draws the situational picture the rest of the book rests on, and explains why the line between peace and conflict has become so hard to draw.

  • CISOs and security leads
  • Boards and leadership teams
  • Citizens and small businesses

Last reviewed

The question of cybersecurity is often posed as if it were technical. Which tools are needed, which systems to protect, what it costs. This chapter starts somewhere else, in what has actually changed in the world outside and why that change reaches organisations that have never seen themselves as interesting targets. The most common objection in a boardroom is that the operation is too small, too local or too uninteresting for anyone to care. The chapter shows why that objection rests on an assumption that no longer holds.

The chapter works through what the grey zone means, the space between peace and conflict where influence operations, sabotage and intelligence gathering run continuously without any war having been declared. It describes how the attack surface has grown alongside digitalisation, and why that growth is rarely the result of one decision but of a hundred small ones, taken by different people at different times without anyone adding them up. Then comes a review of who attacks Swedish organisations and what they want, a question taken further in chapter 2 on the threat actors. After that, the downside of digitalisation, the vulnerabilities that follow efficiency, and the digital dimension of total defence. The closing sections deal with the shift in responsibility the Cybersecurity Act brings, and the idea that every organisation is a link in a chain held in common. The chapter ends with the distinction the book is built on, between invulnerability and resilience, which is the posture everything that follows proceeds from.

The question sharpened when the Cybersecurity Act entered into force on 15 January 2026. Where security work previously rested largely on goodwill and personal ambition, there is now a legal requirement pointing at the leadership, with supervision and administrative fines as the ultimate consequence. At the same time, the security situation around Sweden has changed fundamentally. Organisations that used to sit outside the threat picture end up inside it through their dependencies, through who they supply and through what function they serve in something larger. That is a change no purchase can meet, because it concerns how the operation is built.

This page shows what the chapter covers and why the situational picture is the starting point for everything else. The analysis, the examples and the Swedish cases are in chapter 1 of the book.

Cybersecurity is not a state. It is a posture that has to be renewed every day.

Key insights

  • The grey zone is not a state of exception but the normal condition. Attacks happen continuously, below the threshold of what counts as armed conflict.
  • The attack surface grows faster than most organisations can map it, because every new service and every new integration adds exposure.
  • Chains of dependency mean an organisation can be hit hard without ever being the target.
  • Invulnerability is not a reasonable goal. Resilience, the ability to keep functioning and recover, is.

Read on

Next step

Where does your organisation stand?

The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.