Melinda From
Transformationsledare
Contact Melinda
Digital violence never pauses. It travels in your pocket around the clock — through surveillance, financial control, image-based abuse, threats and online harassment. Add to that a new wave of AI-driven threats: deepfakes used to humiliate and silence, chatbots that groom children and young people, and disinformation targeting individuals.
Sweden's Gender Equality Agency's report "The Boundless Violence" (2026:1) establishes that sexual offences account for nearly a third of all reported online crimes against girls, and that girls' vulnerability becomes increasingly sexualised with age. This is not just about isolated crimes. It is about how digital environments can be systematically exploited for power and exploitation — and about who bears that risk.
It is also a question of democracy. Female politicians, journalists and researchers face disproportionately high levels of sexualised threats and harassment online. Then there is the role of algorithms. Sweden's Minister for Gender Equality Nina Larsson recently highlighted a study published in Nature in which American users on X were randomly assigned either an algorithmic or a chronological feed for seven weeks. The results were clear: those exposed to the algorithmic feed became more politically conservative, including in their views on the war in Ukraine. The algorithm prioritised conservative content and downranked traditional media. This is a concrete example of how design choices in digital environments can have real effects on political views — and of how forces seeking to destabilise democracy know exactly how to exploit this. When people leave public life or fall silent because of digital threats, the entire democratic conversation shrinks.
Technological development often follows a pattern. First comes the technology — optimised for function and performance. Then, through experience and setbacks, we recognise that it is people who are meant to use it. That is when the sociotechnical perspective takes hold: usability, UX design, accessibility principles. The human being is placed at the centre.
That shift has begun within cybersecurity. The EU's cybersecurity legislation (NIS2), which entered into force in Sweden on 15 January 2026, is a clear signal: the directive covers 18 societal sectors and makes cybersecurity a matter for senior leadership. But NIS2's definition is also broader than the traditional one — it encompasses societal resilience. This means that protection against automated manipulation such as deepfakes, security in AI systems that interact with people, and AI-based information influence operations are already within the framework. Cybersecurity has, in other words, already begun moving towards protecting people — not just systems. The question is whether practice is keeping up.
The legal foundation is already there. The EU's Cybersecurity Act (Regulation 2019/881) defines a cyber threat as something that can harm or adversely affect network and information systems — but also their users and others. People are therefore already recognised as worthy of protection under EU law. And in a democratic society where inclusion is a prerequisite for legitimacy, that must mean all people — regardless of gender, age or background. Yet this is rarely reflected in how cybersecurity work is carried out in practice. That is the gap we must take seriously.
From a total defence and civil preparedness perspective, this becomes even clearer. A society in which people are silenced, surveilled or driven away from digital spaces develops new vulnerabilities. Digital violence is therefore not only a gender equality problem — it is a question of societal resilience.
What needs to happen now?
Platforms must be held accountable. Real age verification, meaningful sanctions and algorithmic transparency are not requests — they are requirements. The EU's Digital Services Act provides the tools. What is needed now is the will to use them.
Cybersecurity strategies must put people at the centre. Gender equality research, social work and child protection belong at the same table as IT security and total defence — not as an afterthought, but from the very start.
The public sector must lead. Authorities, municipalities and regions working with cybersecurity need to require that suppliers and systems meet both technical and human security standards — including protection against deepfakes, AI-grooming and information influence operations.
Inclusion is not a soft issue. Cybersecurity work that fails to protect everyone — regardless of gender, age or background — creates blind spots that adversaries are already exploiting.
Cybersecurity is ultimately about protecting what matters in society. And in a democratic society, all people are part of the infrastructure — not just the norm.
So the next time cybersecurity comes up on the agenda — in the boardroom, in politics or in your own work — ask the question: for whom? And if the answer does not include everyone, it is time to change that.
References
Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification (Cybersecurity Act). eur-lex.europa.eu
Swedish Gender Equality Agency (2026). Det gränslösa våldet [The Boundless Violence] (Report 2026:1). Final report on government commission on digital violence against women and girls. jamstalldhetsmyndigheten.se
Swedish Civil Contingencies Agency/MSB (2026). The Cybersecurity Act (2025:1506) and the Cybersecurity Ordinance (2025:1507). Implementation of the EU NIS2 Directive in Sweden, entered into force 15 January 2026. msb.se
Swedish Gender Equality Agency (2024). Serious EU statistics on violence. EU survey on gender-based violence against women, conducted by Eurostat, FRA and EIGE with responses from 114,023 women in the EU. jamstalldhetsmyndigheten.se
Roks/Örebro University (2022). Kvinnors trygghet – ett jämställt samhälle fyllt av våld [Women's Safety – an Equal Society Full of Violence]. Survey on men's violence against women in Sweden, 15,000 randomly selected women. roks.se
Swedish Government (2024). National Cybersecurity Strategy. Based on the NIS2 Directive. regeringen.se
Huszár et al. (2026). Algorithmic amplification of political content on X. Nature. nature.com/articles/s41586-026-10098-2
Larsson, Nina (2025). Vad gör sociala medier med vår demokrati? [What are social media doing to our democracy?] LinkedIn post by Sweden's Minister for Gender Equality on algorithmic influence on political views and democratic resilience. linkedin.com/in/ninalarsson1