Sammanfattning

The purpose of this study is to examine and analyze how Swedish public sector organizations manage IT-related supply chain attacks, with a focus on the processes, routines and working methods used to prevent, detect and handle such threats. The study is based on a qualitative research design consisting of five semi-structured interviews with respondents working in IT security, information security, risk management or supplier governance within Swedish public sector organizations. The interviews were complemented with a document analysis of relevant regulations, guidelines and policy documents, including NIS2, ENISA reports and Swedish national cybersecurity guidance. The results show that public sector organizations are highly dependent on external IT suppliers and cloud-based services. Preventive work is mainly concentrated in the procurement phase, where organizations use security requirements, contractual terms and supplier assessments to influence supplier security. However, the study also identifies a gap between requirements set during procurement and continuous followup after contracts have been signed. Supplier monitoring, insight into subcontractors and fourth-party risks remain underdeveloped areas. The findings further show that regulations such as NIS2 strengthen the legitimacy of cybersecurity work, but formal compliance is not sufficient to ensure practical security. Incident management processes exist in all studied organizations, but detecting supplier-related incidents remains challenging. The study concludes that Swedish public sector organizations have begun to develop more structured approaches to IT supply chain security. However, greater emphasis is needed on continuous supplier follow-up, clearer responsibilities, stronger organizational mandates and improved collaboration with suppliers throughout the entire supplier relationship.

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.