Toolbox

All tools in the Toolbox

Toolbox · System support

System support

Which categories of system support exist for the work with the Cybersecurity Act, what each one actually does, and what to weigh before you commit.

Before you commit to a supplier, run a sovereignty assessment of the service.

VER&IT owns products within two of the categories below, management systems and risk management. They are therefore not listed here. The ownership is disclosed on the About page. About this initiative.

Information security management systems (ISMS), GRC and compliance

Chapters 11, 13 and 21

Platforms for management systems (ISO 27001), GDPR, supplier and policy governance, and continuous compliance.

What the category does

Gathers policies, controls, deviations and actions in one place, ties them to a framework and shows the coverage. The value lies in traceability. You can show what applies, who owns it and when it was last reviewed.

What to weigh

A management system is a way of working, not a licence. A tool bought before the way of working exists becomes an expensive document archive. Ask how you get your data out the day you switch, and where it is stored.

Risk management

Chapter 14 · Appendix A.4

Support for identifying, valuing, treating and reporting risks, ideally tied to ISO 31000 and a living risk register.

What the category does

Keeps a risk register alive over time, with owner, valuation, treatment and follow up per risk. The difference from a spreadsheet is the history and the reminders, meaning that risks actually get revisited.

What to weigh

A spreadsheet lasts longer than suppliers tend to claim. Switch when the number of risks or the number of people working in the register makes the spreadsheet unmanageable. Check that the tool scale can be explained to a board.

Maturity measurement and self assessment

Chapters 8 and 12

Measure where you stand against the requirements and follow the development over time.

What the category does

Gives a picture of where you stand per requirement area and makes the development comparable between measurements. Most useful as material ahead of a management or board review, where a profile says more than a single grade.

What to weigh

A maturity score is material for a conversation, not a result. Free alternatives exist and are enough for most, see the bottom of this page.

Training and security awareness

Chapters 7 and 10

Recurring training and communication that builds cyber hygiene and a security culture among all employees, not only IT.

What the category does

Spreads short training moments across the year instead of one annual session, and measures who did what. The recurrence is the whole point. A one off session does not show up in behaviour six months later.

What to weigh

Measure behaviour, not completion rate. That everyone clicked through a module says nothing about whether anyone reports a suspicious email. Check that the content exists in the languages your employees actually use.

Threat intelligence sharing

Chapter 22

Receive and share indicators and threat intelligence, ideally Sweden specific.

What the category does

Receives indicators from other organisations and authorities and matches them against your own environment. The benefit is proportional to how fast you can act on an indicator, not to how many feeds you subscribe to.

What to weigh

Without someone reading and acting, the feed becomes noise. Start with the national sharing, which is free, and expand once you have a receiving function.

Free services

Named exceptions. All three are free and none of them sells anything.

This page names no commercial products. The market changes faster than a book can be printed, a list here would age badly, and it would carry more weight than it deserves. The categories are explained instead, so you can ask any supplier the right questions.

← Back to the Toolbox