Before you commit to a supplier, run a sovereignty assessment of the service.
VER&IT owns products within two of the categories below, management systems and risk management. They are therefore not listed here. The ownership is disclosed on the About page. About this initiative.
Information security management systems (ISMS), GRC and compliance
Chapters 11, 13 and 21Platforms for management systems (ISO 27001), GDPR, supplier and policy governance, and continuous compliance.
What the category does
Gathers policies, controls, deviations and actions in one place, ties them to a framework and shows the coverage. The value lies in traceability. You can show what applies, who owns it and when it was last reviewed.
What to weigh
A management system is a way of working, not a licence. A tool bought before the way of working exists becomes an expensive document archive. Ask how you get your data out the day you switch, and where it is stored.
Risk management
Chapter 14 · Appendix A.4Support for identifying, valuing, treating and reporting risks, ideally tied to ISO 31000 and a living risk register.
What the category does
Keeps a risk register alive over time, with owner, valuation, treatment and follow up per risk. The difference from a spreadsheet is the history and the reminders, meaning that risks actually get revisited.
What to weigh
A spreadsheet lasts longer than suppliers tend to claim. Switch when the number of risks or the number of people working in the register makes the spreadsheet unmanageable. Check that the tool scale can be explained to a board.
Maturity measurement and self assessment
Chapters 8 and 12Measure where you stand against the requirements and follow the development over time.
What the category does
Gives a picture of where you stand per requirement area and makes the development comparable between measurements. Most useful as material ahead of a management or board review, where a profile says more than a single grade.
What to weigh
A maturity score is material for a conversation, not a result. Free alternatives exist and are enough for most, see the bottom of this page.
Training and security awareness
Chapters 7 and 10Recurring training and communication that builds cyber hygiene and a security culture among all employees, not only IT.
What the category does
Spreads short training moments across the year instead of one annual session, and measures who did what. The recurrence is the whole point. A one off session does not show up in behaviour six months later.
What to weigh
Measure behaviour, not completion rate. That everyone clicked through a module says nothing about whether anyone reports a suspicious email. Check that the content exists in the languages your employees actually use.
Threat intelligence sharing
Chapter 22Receive and share indicators and threat intelligence, ideally Sweden specific.
What the category does
Receives indicators from other organisations and authorities and matches them against your own environment. The benefit is proportional to how fast you can act on an indicator, not to how many feeds you subscribe to.
What to weigh
Without someone reading and acting, the feed becomes noise. Start with the national sharing, which is free, and expand once you have a receiving function.
Free services
Named exceptions. All three are free and none of them sells anything.
- Cybersakerhetskollen (MCF)
National, free maturity tool from the Swedish Civil Defence Agency. In Swedish.
- MISP-SE (CERT-SE)
National platform for threat intelligence sharing, free for connected organisations.
- Self-assessment against the ten requirement areas
The self-assessment on this site. Ten questions, a maturity profile straight on screen.
This page names no commercial products. The market changes faster than a book can be printed, a list here would age badly, and it would carry more weight than it deserves. The categories are explained instead, so you can ask any supplier the right questions.