THURSDAY 1 OCTOBER· STOCKHOLM · THE DAY IN 5 STORIES

New cybersecurity rules put security duties on management

Server cabinets and overhead cables of the Berzelius computer at Linköping University.
Erik And30 / CC BY-SA 4.0

Companies and public authorities covered by Sweden’s cybersecurity law face more detailed security requirements from 1 October. The rules cover management training as well as the practical work of preventing and handling disruptions.

The civil defence agency says the regulations clarify the duties of most operators covered by the law, which took effect in January. They set minimum requirements while allowing measures to reflect each organisation’s risks, size and circumstances.

The work includes assessing risks, valuing information assets and choosing suitable protection. Incident response and continuity planning, security during development and outsourcing, and protection of staff and premises all fall within the rules.

Management must also oversee and follow up cybersecurity work. The requirements call for sustained work to prevent disruptions and reduce their consequences, rather than a single completed checklist.

Organisations may therefore need different measures to reach an adequate level of protection. The practical task is to connect management training and oversight with the risks in their own operations.

#SwedenNews
DailySweden logo

DailySweden

DailySweden's desk of editors, reporters, researchers and investigative journalists. We bring readers factual, truthful and objective reporting on the issues that matter to them.

Contact the editorial desk ›