Chapters in this part
- 1 The new security landscape The threat picture facing Sweden does not look the way it did ten years ago. Attacks no longer come only from criminals after money, but just as often from actors after something else, trust, freedom of action or access to someone further along the chain. This chapter draws the situational picture the rest of the book rests on, and explains why the line between peace and conflict has become so hard to draw.
- 2 Hackers and threat actors, who, why and how Behind every attack there are people with motives. Understanding threat actors, who they are, what they want and how they work, says more about the protection you need than whichever piece of malware happened to be used. This chapter works through the four main categories of attacker, how the criminal cyber economy functions as a market, and how an attack is actually carried out step by step.
- 3 The regulatory map, what applies to you? The Cybersecurity Act and NIS2, what actually applies to your organisation? The question is harder than it sounds, because the rules overlap and one and the same operation is often caught by several at once. This chapter draws the map of the base layer, GDPR, the Protective Security Act, DORA, the Cybersecurity Act and the regulations issued for central government agencies, and shows how they relate to each other.
- 4 Products, AI and the regulation navigator The Cybersecurity Act regulates operations. The Cyber Resilience Act and the AI Act regulate what is built and sold. This chapter picks up where the regulatory map ends and works through the requirements on products with digital elements, on AI systems and on electronic communications, and how one organisation can navigate several sets of rules without building four parallel security programmes.
- 5 The Swedish cybersecurity ecosystem MCF, NCSC and CERT-SE are names often mentioned in the same breath while doing different things. This chapter sorts out the roles in the Swedish cybersecurity ecosystem, which authorities are responsible for what, which of them supervise the Cybersecurity Act, and above all where an organisation actually turns once an incident is a fact and the clock is running.
- 6 Cyber defence, Sweden's new doctrine Swedish cyber defence is part of total defence, and total defence takes in civilian operations too. This chapter separates the three levels of cybersecurity, describes the capability of the Armed Forces and the civil military cooperation inside NCSC, and answers the question that concerns every organisation. What does it mean to be part of something larger than your own operation?