Jump directly to content

AI sandbox – a closed test environment with open-source AI models

Name of service (page headline, shown in promos – maximum of 70 characters incl. spaces): AI sandbox for testing with sensitive information Lead (include SEO-words and the main benefits for your target groups. Stick to one paragraph, maximum 2-3 sentences):

Many organisations hold off on testing AI with real work when the information is sensitive. In an AI sandbox, you work with open-source AI models in a closed environment – on your own network or on servers at RISE. You choose the models with RISE and see what AI can actually do before you invest in new solutions.

Purpose/Benefit:

Many organisations are ready to put AI to work on material that could make a real difference to how they operate. That might be case files, notes, permit applications, patents or product data. But that is usually where caution sets in. Where does the information go? Who owns the model? What happens if access to it changes?

The result is that the benefits never materialise, while expectations of shorter processing times and simpler ways of working stay exactly as they were.

Sensitive information might refer to confidentiality or security classification, but it might also be a patent, a unique product, or anything else that is business-critical. An AI sandbox lets you try out AI models without any of it leaving your control, and the environment is built around what you actually need to test.

Method (what/which methods are used to perform the service):

The sandbox consists of one or more servers with substantial processing power and memory, built solely to run AI models. They look much like powerful desktop computers.

The servers sit either on your own network or at RISE, on hardware dedicated to you. The environment is closed and can be run entirely offline if needed, with no external communication at all. Nothing leaves it.

The sandbox uses open-source AI models. These are not owned by commercial providers, which means you can see how they were trained, and you are not at risk of losing access due to decisions taken somewhere else in the world. Several models can be installed simultaneously and compared during the test period.

How we get you up and running:

  1. We go through what you want to test and what information it will use.
  2. We configure the servers and install AI models tailored to your use cases.
  3. We install the environment on-site and train your staff.
  4. You run your tests, with our support throughout.
  5. We summarise what the test showed about capacity, quality and benefit.
Delivery (what does the client get after performed service – e.g. a report, certificate etc.):

Throughout the period, you have a complete, closed environment to work in without having to invest in your own infrastructure. We train your team so you can use it independently, and we are on hand throughout.

Once the test is complete, you have a solid basis for decisions: the capacity your organisation needs, how different AI models compare for your particular tasks, and where the real benefits lie. From there, you can either continue in the environment or move the solution into your own operations, working with your usual IT or managed service provider.

Area: Digitalisation Contact person (Enter one name per field. Activated personal contact pages will appear automatically): Conny Björnehall, Focus Area Leader Digitalization Public Sector Field measurements: No Price type: 1 Division: Division Digital Systems and Societal Transformation Preparation: No preparation required Certification and marking: Not applicable Type of service: Not applicable Instrument: Not applicable General area: Not applicable Delivery level: Not applicable
conny.bjornehall@ri.se,
/en
More information:

The EU AI Act requires every member state to provide a regulatory sandbox for AI, where AI systems can be developed and tested under supervision. An AI sandbox at RISE complements this – it is a technical test environment where you can start building practical experience of AI and sensitive information now.

The sandbox is one of several strands in RISE's work on AI. If you want to get started more broadly, there is RISE GPT and the AI partnership for the public sector. If you are interested in sustainable and efficient data centre solutions, RISE ICE Datacenter offers a research and test environment for digitalisation and IT infrastructure.

Purpose - Header: Why AI testing needs a secure environment Metod - Header: How an AI sandbox works Delivery - Header: What you get out of the test period More information - Header: The AI sandbox in a wider context
Request for quote
form
Artificial intelligence Sekundär områdes navigation: Cybersecurity Tjänstetyp tagg: Konsultuppdrag Rubrik (text på knapp): Try AI securely, in your own environment

Increased requirements with the new cyber security law

Developers

The Cybersecurity Act imposes stricter requirements on organisations in both the public and private sectors. At the same time, many organisations find the field so broad and complex that they do not know where to start.
'Rapid technological developments mean there is an urgent need to develop knowledge, working methods and structures,' says Johanna Parikka Altenstedt, Head of the Digital Security Unit at RISE.

Despite increased awareness of cyber threats, many organisations still lack a systematic approach to cybersecurity. Furthermore, according to Cybersäkerhetskollen, the Swedish Civil Contingencies Agency’s tool for measuring cybersecurity maturity in Swedish organisations, the pace of improvement has stalled in several areas.

There is an increasing demand for systematic risk management.

At the same time, the Cybersecurity Act – Sweden’s implementation of the EU’s NIS2 Directive – means that the requirements for public and private sector organisations are increasing. Those covered by the Act must work systematically on risk management, report serious incidents, and manage cyber security risks in the supply chain.

However, legislation does not build capacity.

”Many people feel that the field is so vast and overwhelming that they don’t know where to start,” says Johanna Parikka Altenstedt, acting head of the Digital Security unit at RISE.

She compares the current situation with sustainability efforts to where they stood 15–20 years ago. Since then, sustainability has progressed from its infancy to the point where everyone now has management systems in place and is fully on top of things. Cybersecurity is now set to follow the same path, but Johanna Parikka Altenstedt says we don’t have much time to protect our most valuable assets against cyberattacks.

Lessons can also be learnt from the sustainability transition.

”There, you eventually learnt that you have to start somewhere. You have to prioritise and make up your mind,” says Johanna Parikka Altenstedt.

'Cybersecurity must be integrated into the organisational structure.'

One reason why the pace of improvement has stalled may be that Sweden was relatively late in implementing the NIS2 Directive. Many organisations chose not to start work until the legislation was in place.

'We’ve also been slow to consider how other countries have dealt with the situation. There's no need to reinvent the wheel. Denmark, for example, has produced a checklist for local authorities detailing what they need to do and bear in mind. Here, each local authority has to learn the law independently. That takes time,' says Johanna Parikka Altenstedt.

In many cases, cybersecurity work has been treated as an additional task carried out alongside day-to-day operations, rather than as the business-critical issue it is.

”It’s simply not part of the structure. Cybersecurity must be integrated into organisational structures, becoming part of management teams and boards,” says Johanna Parikka Altenstedt.

”You need to consider issues other than just IT. These may include physical security, personnel matters, access rights, key management, and protection against insider threats. Cybersecurity concerns the entire organisation.”

Essentially, it's about taking a proactive rather than a reactive approach.

”Of course, targeted measures are needed if a serious shortcoming is identified that requires addressing. However, you can’t just patch things up; a systematic approach and continuity are required. This pays off in the long run,” says Johanna Parikka Altenstedt.

Cybersecurity must be integrated into organisational structures, becoming part of management teams and boards

The challenge lies in translating legal requirements into practical, long-term cybersecurity work.

For many organisations, the challenge lies not in understanding the requirements, but in translating them into practical, long-term cybersecurity work.

As an independent organisation, RISE can provide cybersecurity assistance tailored to the specific needs of both public and private sector organisations.

”Cybersecurity remains an undefined area of operation for many organisations. That is why we sit down with the client to analyse the situation and carry out a vulnerability assessment. We can then help address any issues that have come to light, with RISE involved every step of the way”, says Johanna Parikka Altenstedt.

As a research institute, RISE has expertise in technology, AI, law, management, and strategic analysis. AI presents both risks and opportunities: while the technology creates new vulnerabilities, it can also be used to detect threats, analyse large volumes of data, and strengthen digital defences.

”We also have certification expertise and can provide training. We have the technical infrastructure of the Cyber Range, where we can carry out advanced exercises. We can collaborate with our clients' IT departments, create a replica of their systems and demonstrate the consequences of an attack. This enables them to determine their response strategy”, explains Johanna Parikka Altenstedt.

She believes that it is easy to become overwhelmed by technology, legal requirements and security measures. Ultimately, however, cybersecurity is about creating organisations that are both resilient and capable of evolving.

”If you take it to its logical conclusion, the safest option would be to stop running any operations. But that is obviously not the aim. Our goal is to be able to carry out operations, produce goods, and maintain a functioning society, all while ensuring that we are adequately protected.”

How the Cybersecurity Act works:

The Cybersecurity Act, which came into force in January 2026, constitutes Sweden’s implementation of the EU’s NIS2 Directive. Its purpose is to bolster cybersecurity and resilience in the face of cyberattacks and other digital disruptions. The Act covers a wide range of activities in the public and private sectors, including energy, transport, healthcare, food and water supply, and digital infrastructure.

Among other things, organisations covered by the legislation must work systematically on risk management, report serious incidents within specified timeframes, and manage cybersecurity risks in the supply chain. The Act also places greater demands on management.

Supervision is carried out by specially appointed authorities, who may conduct inspections and issue fines for non-compliance.

Depending on the type of business concerned, the maximum fines can amount to €10 million or 2 per cent of global annual turnover.

Johanna Parikka Altenstedt

Gruppchef
+46 10 228 46 60 Read more about Johanna
Profile image

Contact Johanna

CAPTCHA

* Mandatory 

By submitting the form, RISE will process your personal data.
Cybersecurity Sekundär områdes navigation: Digitalisation

Cyberlyftet - An introduction to cyber security

Cyber security

Most cyberattacks succeed because people lack basic knowledge of how to respond. Cyberlyftet provides you with this knowledge in two hours, whether you’re taking the course on your own or as part of your organisation.

The course is available in Swedish, English and Finnish, takes approximately two hours and can be undertaken individually or as a group activity, for example as part of a professional development day.

Upon completion of the course, participants are expected to be able to:

  • Understand the fundamental principles of cybersecurity.
  • Identify potential cyber threats and understand their consequences.
  • Apply basic security measures to protect digital information and infrastructure.
  • Follow the organisation’s reporting procedures in the event of suspected security threats.

The course has been developed by RISE in collaboration with Cybercampus and is based on current research and real-world threat scenarios.

For those wishing to take the course independently

This course provides a basic understanding of how to protect digital systems, networks and data against cyber attacks. It is aimed at those with no previous experience in this field. Through a series of chapters and practical exercises, you will learn to identify and manage various cyber attacks.

Start Cyberlyftet free of charge – click on the ‘Start course’ button.

For those responsible for your organisation’s security

Most cyber attacks against organisations succeed because staff do not recognise the threats or know how to report them. A single staff member clicking on the wrong link can give attackers access to your entire infrastructure. Without basic training, the risk is unnecessarily high. This is a problem that can be resolved quickly.

The course can be integrated directly into your intranet, making it easy to reach everyone in the organisation. You’ll also be able to track what proportion of staff have completed the training.

Fill in the form below and we’ll be in touch.

Online
Online
Free (excluding VAT)
Självstudie
Digital
2 hours
Course certificate
Swedish, English or Finnish
Division: Division Digital Systems and Societal Transformation

What is Cyberlyftet?

+

Do I need any prior knowledge to take the Cyberlyftet course?

+

How can an organisation integrate Cyberlyftet for its staff?

+

How long does it take to complete the Cyberlyftet programme?

+

What will I learn from taking the Cyberlyftet course?

+

Johanna Parikka Altenstedt

Gruppchef
+46 10 228 46 60 Read more about Johanna
Profile image

Contact Johanna

CAPTCHA

* Mandatory 

By submitting the form, RISE will process your personal data.
karl.resare@ri.se
/en/personal-data-processing/candidate-database
Cybersecurity Sekundär områdes navigation:
Cybersecurity
Digital infrastructure
Digitalisation

Development of Structured Test Methods for Drones and Cybersecurity

Name of service (page headline, shown in promos – maximum of 70 characters incl. spaces): Development of Structured Test Methods for Drones and Cybersecurity Lead (include SEO-words and the main benefits for your target groups. Stick to one paragraph, maximum 2-3 sentences):

RISE helps you develop structured test methods that ensure the cybersecurity of your drone systems. Through research‑based approaches, we create test strategies and frameworks built on threat modelling, risk analysis and clear requirements aligned with relevant standards.

Purpose/Benefit:

We support you in establishing a robust and standardised test process for assessing the cybersecurity of your drone systems. By combining threat modelling, risk analysis and clear requirement specifications, we develop a test strategy that identifies vulnerabilities before they affect operations or safety. The result is a methodology that strengthens your protection, reduces risks and builds trust among customers, users and authorities.

Method (what/which methods are used to perform the service):

We work closely with your organisation to develop test methods tailored to your systems, risks and objectives. Our R&D process includes:

  • Definition of test requirements and acceptance criteria according to relevant testing standards
  • Threat modelling to identify realistic attack scenarios
  • Risk analysis to prioritise testing efforts
  • Modelling and testing of cyberattacks, faults and threats in controlled test environments
  • Reproducible tests in physical or simulation‑based environments adapted to your needs

The methodology we develop is traceable, scalable and designed to be implemented directly in your operations. It provides a clear structure for how cybersecurity tests should be planned, executed and followed up, whether you work in a lab environment or in operational settings.

Delivery (what does the client get after performed service – e.g. a report, certificate etc.):
  • A complete cybersecurity test strategy for drone systems
  • Documented test requirements and acceptance criteria
  • Threat modelling and risk analysis as decision support
  • Recommended test cases and method descriptions
  • Full documentation and reporting of results

If needed, we can also support you in implementing the test methods within your organisation and training your teams.

Area: Cyber security Contact person (Enter one name per field. Activated personal contact pages will appear automatically): Aria Mirzai, Forskare
Test methods for drones and cybersecurity
Field measurements: Yes Price type: 1 Division: Division Safety and Transport Preparation: No preparation required Certification and marking: Not applicable Type of service: Innovation services Instrument: Not applicable General area: Not applicable Delivery level: Not applicable
aria.mirzai@ri.se,
/en/personal-data-processing/candidate-database
More information:

We also offer advanced R&D support, workshops, training and advisory services related to standards, regulatory requirements and technical solutions. You can also receive assistance in analysing specific threat scenarios, attacks or system architectures to further strengthen your security work.

Contact us

We are happy to help you strengthen the cybersecurity of your drone systems. Contact Mateen Malik or Aria Mirzai for more information.

Purpose - Header: Strengthening the security of your drone systems Metod - Header: Our cybersecurity testing approach Delivery - Header: You recieve More information - Header: More information
form
Drones Sekundär områdes navigation: Cybersecurity Tjänstetyp tagg: Verifiering och validering

Advanced safety analysis and cybersecurity for drones

Safety and cybersecurity for drones
Advanced safety analysis and cybersecurity for drones

Organisations using drones face complex security challenges: data leaks, cyberattacks, limited testing methods and increasing regulatory demands. With RISE’s research‑based expertise, you gain support in identifying risks, verifying safety and developing robust drone systems that can withstand real‑world conditions.

As drones become smarter, their security must become stronger

An increasing number of organisations rely on drones for critical operations in public authorities, municipalities, industry, energy, logistics and technology development. As these systems become more autonomous and connected, the demands on security, data protection and reliability grow accordingly.

RISE combines technical expertise in drone technology, cybersecurity, and simulation‑based research to provide the knowledge needed to develop and operate drone systems that are safe, robust, and suited for complex environments.

Why security in drone systems is essential

For organisations using drones in safety‑critical or societally important operations, it is crucial that the systems function reliably and that sensitive information is handled securely.

Our researchers help you understand the risks in your drone systems and build a solid foundation for responsible use. As requirements for security, data protection, and reliability increase, this expertise becomes an important part of your decision‑making.

Our research‑based expertise in drone security

RISE’s work covers the entire security chain and supports you in working systematically with drone safety. This includes assessing network communication and resilience against intrusion, analysing data security and the risk of information leakage, and applying knowledge of testing methods and relevant standards. We also address physical security and tampering risks, conduct risk analyses for both autonomous and manually operated drones, and draw insights from testing in both simulated and real environments to understand requirements and conditions in realistic scenarios.

This expertise gives you a clearer understanding of how your drones handle sensitive information and what security risks may arise. You also receive support in working more effectively with CE‑marking and other regulatory requirements, as well as guidance on relevant security measures across the entire drone system. Together, this creates strong conditions for developing solutions that are safe, reliable, and competitive.

Research forming the foundation of our expertise

Our work in drone security is built on extensive experience in simulation‑based safety research, the development of testing methods, and the verification of drones. This is complemented by research in cybersecurity for autonomous systems and close collaboration with industry and public authorities, forming a solid foundation for analysing and understanding drone systems from a security perspective.

Why collaborate with RISE

We combine independent research with technical expertise in both drone technology and cybersecurity. Through advanced test environments, both simulated and physical, we help identify security vulnerabilities early and provide a reliable basis for further development. Our independent analyses strengthen your position in procurement and regulatory processes, and all work is grounded in international standards.

Ready to take the next step?

Feel free to contact us to explore how our expertise can strengthen the security of your drone systems and support your continued development.

Aria Mirzai

Forskare
Read more about Aria

Contact Aria

CAPTCHA

* Mandatory 

By submitting the form, RISE will process your personal data.

Peter Folkesson

Teknologie doktor
+46 10 516 54 16 Read more about Peter
Profile image

Contact Peter

CAPTCHA

* Mandatory 

By submitting the form, RISE will process your personal data.
Offer-pages: Cyber Security Assessment of Drones for critical infrastructure Division: Division Safety and Transport Drones Sekundär områdes navigation: Cybersecurity

Evaluation of cybersecurity standard ISA/IEC 62443-4 for industrial Automation and Control Systems(IACS)

Name of service (page headline, shown in promos – maximum of 70 characters incl. spaces): ISA/IEC 62443-4 for industrial Automation and Control Systems, IACS Lead (include SEO-words and the main benefits for your target groups. Stick to one paragraph, maximum 2-3 sentences):

RISE performs accredited testing and evaluation of cybersecurity for IACS components. Cybersecurity testing is conducted according to the product parts of the IACS based on 62443-4 standards, SS-EN IEC 62443-4-1 and SS-EN IEC 62443-4-2.

Purpose/Benefit:

The standard consists of two core parts that together address both the development process and the technical security requirements for industrial components.

Part 1: Swedish Standard SS‑EN IEC 62443‑4‑1

Security for industrial automation systems – Part 4‑1: Secure product development lifecycle requirements

This part defines the requirements for designing, implementing, verifying, maintaining, and supporting a product throughout its entire lifecycle. It covers areas such as security management, requirements specification, secure design and implementation, verification and validation, vulnerability and update management, and security guidelines.

Part 2: Swedish Standard SS‑EN IEC 62443‑4‑2

Security for industrial automation systems – Part 4‑2: Technical security requirements for IACS components

This part defines technical security requirements for four categories of components:

  • Software applications
  • Embedded devices
  • Host devices
  • Network devices

Key requirement areas include identification and authentication, access control, system integration, data confidentiality, data flow control, event handling, and resource availability.

Why evaluation according to 62443‑4‑X matters

Manufacturers of industrial components want to demonstrate that their products meet international cybersecurity requirements, that their development processes follow best practices according to 4‑1, and that their components fulfil the technical security requirements in 4‑2. An evaluation according to 62443‑4‑X also shows that products can be integrated into secure IACS environments. For customers—especially within critical infrastructure—this reduces both risk and uncertainty during procurement.

How RISE conducts the evaluation

RISE performs evaluations according to ISA/IEC 62443‑4‑X by focusing on the practical cybersecurity requirements for industrial components and how parts 4‑1 (secure development) and 4‑2 (technical product requirements) work together. This provides a clear foundation for understanding which requirements apply and how they are implemented throughout the product lifecycle. For those who want to deepen their knowledge, RISE also offers a course that covers the 62443‑4 series in practice.

How the evaluation benefits you as a customer

  • Clear cybersecurity level — you receive an independent assessment of component security against internationally recognized requirements.
  • Stronger supplier trust — suppliers can demonstrate that their products and processes are reliable.
  • Security by design — the evaluation aligns with industry expectations for products that are secure from the outset.
  • Meets regulatory expectations — procurers and authorities receive the documentation they need to make informed decisions.
Method (what/which methods are used to perform the service):

Evaluation will be carried out in accordance with ISO/IEC 17025 and the accredited standards in our laboratories in Borås.

Delivery (what does the client get after performed service – e.g. a report, certificate etc.):

The result of our evaluation is compiled in an accredited report.

Area: Cyber security Contact person (Enter one name per field. Activated personal contact pages will appear automatically):
Ted Strandberg, Projektledare
Anithasree Maroju, TIC-ingenjör
ISA/IEC 62443‑4‑X – Cybersecurity Evaluation of IACS Components
Field measurements: No Price type: 1 Division: Division Safety and Transport Preparation: No preparation required Standards:
  • SS‑EN IEC 62443‑4‑1 (säkra utvecklingsprocesser)
  • SS‑EN IEC 62443‑4‑2 (tekniska säkerhetskrav)
Certification and marking: Other Certifications Type of service: Testing / Analysis / Evaluation Instrument: Not applicable General area: Not applicable Delivery level: Accredited
ted.strandberg@ri.se,anithasree.maroju@ri.se
/en/personal-data-processing/candidate-database
Purpose - Header: What Standard 62443‑4‑X covers Metod - Header: Method Delivery - Header: Delivery
Request for quote
form
Cybersecurity Tjänstetyp tagg:
Provning
Verifiering och validering

NIS2 is here – is your organisation ready?

People crossing the street

Energy, transport, finance and drinking water production are some of the 18 sectors that the EU has identified as critical to society in NIS2, the directive that affects Swedish companies through the new Cybersecurity Act and Cybersecurity Regulation. Cyber lawyer, Johanna Parikka Altenstedt answers questions for those who are affected.

How can we help you?

Do you need guidance on how the new Cybersecurity Act and Cybersecurity Regulation affect your business and how you can adapt to the new requirements? Contact us by filling out the form:

CAPTCHA
By submitting the form, RISE will process your personal data.

"The background to NIS2 is a major need for coordination across national borders, particularly for companies operating in several countries. It became clear that different countries were handling cybersecurity in different ways," says Johanna Parikka Altenstedt, lawyer and coordinator of Cybernode (the EU's national competence community for cybersecurity, which in Sweden is hosted by RISE). She continues:

"To create an understanding that extends beyond our national borders – because malicious code doesn't stop at one country, it spreads to the neighbours too – the EU passed the NIS Directive in 2016."

How NIS2 is being implemented through the Swedish Cybersecurity Act

NIS2 is an expansion of its predecessor NIS, strengthening the protection of essential services and extending the scope to 18 sectors (see fact box) affected by the new requirements. As a rule, NIS2 applies to companies with at least 50 employees or an annual turnover of at least 10 million euros. Certain operations, such as providers of critical internet infrastructure, are covered regardless of size. In a fact box further down in the article, you will find more information on whether NIS2 applies to you.

"This is a broad directive spanning so many industries that essentially every company with more than 50 employees should investigate whether they are affected. The risks of failing to act, when you are actually required to, are considerable," says Johanna Parikka Altenstedt, who is also acting head of the Centre for Cybersecurity at RISE.

She explains why NIS2 became a directive rather than a regulation, and why that matters.

"NIS2 is the result of a compromise between the member states. Some wanted NIS2 to be a regulation, which would have meant the law being directly binding in all EU countries at the same time. Instead, it became a directive, so each country has some flexibility to adapt the requirements to its own legal system," explains Johanna Parikka Altenstedt.

In Sweden, NIS2 has been implemented through the Cybersecurity Act, which came into force on 15 January 2026. The Act is specified in the Cybersecurity Regulation, which regulates how supervision should be carried out and how reporting should take place.

At the time of writing this article, in February 2026, the supervisory authorities, the Swedish Civil Contingencies Agency (formerly MSB) and the Swedish Post and Telecom Authority, are establishing detailed regulations that further specify how the legal requirements are to be met. In short, it is a three-step process that converts NIS2 into Swedish requirements.

What is most important for doing the right thing – and where should one begin?

"That's an excellent question! You need to analyse your business and really get down to the nitty-gritty. What is the most essential thing you do that creates societal value? That's what you need to protect", says Johanna Parikka Altenstedt.

What is the most essential thing you do that creates societal value? That's what you must protect.

A risk analysis and a gap analysis (a strategic method for identifying the difference between the current situation and the desired target situation) help to identify threats and security gaps. RISE can help companies and organisations to carry out this type of analysis.

"Employees shouldn't have to worry about national security; it's more about protecting their own work. If you've been working on a project for two years and have built up a collection of large Excel spreadsheets, it's not fun if malware gets in. That's why it's a good idea to have a backup. By going down to the team and individual level, it becomes easier to motivate employees to work more cyber securely", says Johanna Parikka Altenstedt.

A management responsibility: cyber security cannot be delegated

Management responsibility is a central part of NIS2 and thus also of the Cybersecurity Act. It is not possible to delegate responsibility for cybersecurity or view compliance as just another IT project among many others.

If management has not decided on appropriate measures or followed up on known deficiencies, this may result in penalty fees. Persons in management positions may also be held personally liable for regulatory violations, through temporary bans on CEO or board assignments in NIS2-covered operations.

A clear regulatory framework to adhere to is better and fairer than an unregulated market.

RISE trains management teams in NIS2 to help companies and their management teams tackle the new regulations with a solid knowledge base. The next step could be to put their products and services under the microscope in RISE's Cyber Range test and demonstration environment, or to certify their information security management system.

NIS2 and cybersecurity – primarily a question of people

Johanna Parikka Altenstedt points out that people generally think that cyber security issues are primarily about technology. That misses the point, she says.

"People start with technical firewalls, when what they really need are human firewalls. I usually talk about the four cornerstones of cyber security. The first is that people working in the organisation are knowledgeable about cyber security issues at their level. Some are super experts, while others have basic cyber hygiene – but everyone has the knowledge. It's also important to consider cybersecurity when departments are eager to create or order new digital products and solutions", says Johanna Parikka Altenstedt.

The second cornerstone is safety culture. There needs to be an open atmosphere so that people dare to speak up when something goes wrong. An employee who is afraid of making mistakes and risking sanctions will not speak up when something goes wrong. And that poses a major risk to the entire organisation.

The third cornerstone is compliance. This is where NIS2 and the Swedish Cybersecurity Act come into play. Only then, as the fourth cornerstone, does technology come into play.

“A clear regulatory framework is fairer”

Johanna Parikka Altenstedt believes that everyone covered by the rules discussed in this article should view the regulations as a tool for protecting what is worth protecting.

"Some people think that there are so many rules from the EU that it slows down business development. That is not the view we hear at Cybernoden. A clear set of rules to follow is better and fairer than an unregulated market", says Johanna Parikka Altenstedt.

She also points out that the EU's cybersecurity regulations are largely based on the same fundamental principles:

  • A risk-based approach.
  • A thorough analysis of your own operations, including both IT and OT (Operational Technology).
  • Clear responsibility for cyber security, including requirements for suppliers and others who depend on socially important activities.
  • An established cyber security management system with procedures for handling incidents and ensuring continued operation.

"If you have already done this work, for example within the framework of ISO 27000 or IEC 62443 certifications, it goes a long way regardless of which regulatory framework we are talking about," she says.

NIS2 and the Swedish Cybersecurity Act

What is NIS2?
NIS2 is the EU's new cybersecurity directive that tightens the requirements for how socially important and digital businesses must protect their IT and information systems. The directive replaces the previous NIS directive.

When was NIS2 decided and when did it come into force?

  • Adopted at EU level in December 2022.
  • To be implemented in national law by 17 October 2024.

How has NIS2 been implemented in Sweden?
Sweden has NIS2 and the Swedish Cybersecurity Act

The regulations came into force on 15 January 2026 and replace the previous NIS Act.

Who is affected?

Medium-sized and large organisations within:

  • energy,
  • transport
  • banking, finance and financial market infrastructure
  • health care
  • drinking water
  • sewer
  • digital infrastructure and IT services (including operations and cloud delivery)
  • public administration
  • space sector
  • postal and courier services
  • waste management
  • manufacture and distribution of chemicals
  • foodstuffs
  • manufacturing
  • research

Operations are divided into essential and important entities. Some are covered regardless of size.

Cybernode

Cybernoden is Sweden's national competence community within cybersecurity research and innovation. It is run by RISE on behalf of Sweden's National Coordination Centre for Research and Innovation in Cybersecurity (NCC-SE) within the framework of the EU project European Cybersecurity Competence Centre and Network (ECCC) and is funded by Vinnova. Together with NCC-SE, Cybernoden constitutes a national arena with the aim of initiating research and innovation in cybersecurity. The Swedish competence community is currently the largest in all EU countries, with over 450 organisations from the private and public sectors and academia.

Johanna Parikka Altenstedt

Gruppchef
+46 10 228 46 60 Read more about Johanna
Profile image

Contact Johanna

CAPTCHA

* Mandatory 

By submitting the form, RISE will process your personal data.
Last published: Cybersecurity