The parts of the book · Part II

Strategy

The second part moves the question to the leadership table. Digital sovereignty, the responsibility the Cybersecurity Act places on the board, how a strategy is built, how security is communicated so that it becomes behaviour, and how ISO 27001 becomes the hub.

Chapters in this part

  1. 7 Digital sovereignty Digital sovereignty is not about owning your servers. It is about what an organisation can keep doing the day a supplier disappears, changes its terms or shuts you off. This chapter works through the dependencies Sweden actually has, the legal grey zone where foreign law meets Swedish, and the pragmatic path between building everything yourself and never thinking about it at all.
  2. 8 Cybersecurity as a leadership issue Board responsibility for cybersecurity is no longer a recommendation but a requirement. The Cybersecurity Act names the leadership, sets a training duty and makes the responsibility enforceable. This chapter works through what that means in practice, the five areas a board needs to own, and what the relationship between leadership and security lead has to look like in order to work.
  3. 9 Building a cybersecurity strategy A cybersecurity strategy nobody takes decisions from is a document, not a strategy. This chapter works through what a strategy has to achieve, the seven components it needs to contain, how the requirement areas of the Cybersecurity Act can give it structure, and what the path from current state to roadmap looks like when it works. Zero Trust is treated as a principle rather than a product.
  4. 10 Security communication, from information to behaviour Security culture is not built by more training sessions. It is built by communication that lands and changes what people actually do. This chapter works through why security messages so often stop at having been sent, what separates information from communication, and which conditions have to be in place for knowledge to turn into behaviour.
  5. 11 The management system, ISO 27001 as the hub ISO 27001 is the structure that makes the Cybersecurity Act manageable. Not because the standard is named in the legal text, but because it answers the same questions in an order that holds. This chapter works through how the standard is built, how it meets the requirement areas of the law, what the national methodological guidance adds in a Swedish context, and when certification is actually worth its cost.
  6. 12 Budget and board communication How much should an organisation spend on cybersecurity? The question has no universal answer, but it has a better and a worse way of being answered. This chapter works through how the need is derived, how the cost of inaction is made visible, which metrics a board can actually decide from, and how a board presentation should be built so that it leads to a decision.

All parts and chapters