Uppsats

Navigating the Swedish Cybersecurity Act : A qualitative study of NIS2 supply chain risk management in Swedish municipalities

Kandidat-uppsats

Högskolan i Skövde/Institutionen för informationsteknologi

Publicerad: 2026

Språk: Engelska

Sammanfattning

With the implementation of the Swedish Cybersecurity Act (Cybersäkerhetslagen 2025:1506) on January 15, 2026, Swedish municipalities are subject to stricter legislation regarding many aspects of their cyber and information security operations. In a constantly evolving threat landscape, public administrations have become the primary target for threat actors in the European Union (EU), as demonstrated by the August 2025 “Miljödata” supply chain attack, which exposed the personal data of 1.5 million Swedish residents. This thesis examines the extent to which Swedish municipalities have integrated the supply chain risk management requirements of the EU’s NIS2 Directive into their procurement and operational processes. This study utilises a qualitative semi-structured interview methodology, and 12 interviews were conducted with relevant municipal IT and information security experts. The collected data were then analysed using thematic analysis. The findings reveal that Swedish municipalities have begun work on organisation-wide changes by standardising procurement processes. This has been done using tools such as the Swedish Association of Local Authorities and Regions (SALAR)’s KLASSA (a web-based information classification tool that generates security requirements for IT systems based on ISO 27002), thereby simplifying the process. Performing compliance verification remains a weak point across all municipalities for several reasons. One of the primary challenges is the sheer number of suppliers across different municipal entities; in many cases, they must manage from 200 to 800 suppliers for whom compliance verification is required, while facing severe resource and personnel shortages. Many Swedish municipalities have begun restructuring to implement information security coordinators, either through new roles or by assigning responsibilities across departments. This has been done because the whole organisation needs to work towards the same goal of heightened information security. There have been reports that individuals with these responsibilities have had difficulty balancing their normal work and their information security responsibilities. The study reveals that many municipalities are left waiting for Swedish Civil Defence and Resilience Agency (Myndigheten för civilt försvar, MCF) regulations, which are intended to serve as the foundation for future audits. Work to secure the supply chain is well underway in Swedish municipalities, but it remains years away from full implementation.

Information

Lärosäte / institution
Högskolan i Skövde/Institutionen för informationsteknologi
Publiceringsdatum
2026
Uppsatstyp
Kandidat-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.