Chapters in this part
- 13 Step by step to an information security management system Building an information security management system is not a project that gets finished. It is a way of working that has to be started and then kept going. This chapter walks the road there in four phases, from identifying and analysing to following up and improving, with a realistic timeline and a review of the mistakes that most often force a restart.
- 14 Risk analysis and gap analysis Information security risk analysis is the work everything else rests on. Without a picture of what can go wrong, how likely it is and what it would cost, every security investment is a guess. This chapter works through how risks are identified, valued and treated, and how the gap analysis shows the distance between the requirements of the Cybersecurity Act and what you actually do today.
- 15 The new controls in ISO 27001:2022 The 2022 version of ISO 27001 added eleven controls that did not exist before. They reflect a reality of cloud services, threat intelligence, data leakage and code written on platforms outside your own organisation. This chapter works through each of them, what they actually require, and in what order it is reasonable to take them on.
- 16 SOC and IRT, detection and response An attack nobody detects continues until the attacker chooses to show themselves. Detection and response decide whether an incident becomes a disruption or a disaster. This chapter sorts out the difference between a SOC and an IRT, works through what a security centre actually does, and takes on the question every organisation faces, whether the capability should be built or bought.
- 17 Incident response and reporting Incident reporting under the Cybersecurity Act follows a clock that starts running before anyone has grasped what is happening. Early warning within 24 hours, a full report within 72. This chapter works through the four phases of incident response, from preparation to lessons learned, deals with the case where several sets of rules demand a report at once, and shows why exercise is what decides the outcome.
- 18 Supply chain security The Cybersecurity Act sets requirements on the security of those you depend on, not only on your own. That makes supplier security one of the most demanding areas, because the control sits outside your own organisation. This chapter works through a five step model for supplier governance, treats cloud providers as a special case, and makes visible the dependency on software nobody ordered.
- 19 AI security AI changes both how attacks are carried out and how they are detected, while the technology itself becomes something that needs protecting and governing. This chapter takes on all three perspectives. AI as a threat vector, AI as defence and AI as an object of regulation, together with the question most organisations find hardest to answer, which AI tools are actually in use internally.
- 20 OT security and cyber physical systems In industrial environments a security failure can have physical consequences. That makes OT security something other than IT security, with different priorities and different constraints. This chapter explains what OT is, what happens when IT and OT grow together, what the threat to Swedish industrial systems looks like, and how security work can begin in systems that are not allowed to stop.
- 21 Compliance automation Compliance work done by hand produces a snapshot that starts ageing the day it is created. Automation makes it possible to know how things stand now rather than how they stood at the last audit. This chapter works through what can actually be automated, what the road there looks like in three phases, and where the limit runs for what technology can take over.
- 22 Threat intelligence in practice Threat intelligence nobody acts on is a subscription, not a defence. This chapter is about the difference. Why sharing threat intelligence gives an advantage no organisation can build alone, how MISP-SE works as the national platform, what the road from raw data to decision looks like, and how an organisation can start at small scale without an analysis function of its own.
- 23 Continuity planning and cyber resilience Continuity planning was once written for fire and power cuts. Cyber resilience asks different questions, because an attacker actively seeks out and destroys the very thing the plan relies on. This chapter works through the business impact analysis, the backup strategy in a reality where the copy is a target in itself, the crisis management plan and the exercises that decide whether any of it works.
- 24 On the horizon, future threats and how you prepare Some threats sit close enough that preparation has to start now, even if the consequences are years away. Quantum computers breaking today's encryption, AI agents attacking without human direction, and hybrid threats where the digital meets the physical. This chapter works through what is actually coming, separates the likely from the speculative and points out what needs doing today.