SWEDEN Law and Practice Contributed by: Anders Bergsten and Victoria Nordenberg, Mannheimer Swartling Advokatbyrå AB
Channels and Content Notifications are filed to MCF via MCF’s incident- reporting process, and forwarded to the compe - tent supervisor. The early warning is treated as a rapid “heads-up” and should indicate, at minimum, whether the incident is suspected malicious/unlawful and whether it is likely to have cross-border impact; the 72-hour (or 24-hour) incident notification should add an initial assessment of severity/consequences and relevant technical indicators; and the final report should describe the circumstances in more depth, including impact, likely cause, and measures taken. Parallel Reporting Depending on facts, entities may also have to notify (i) IMY under GDPR where the incident is a personal data breach (and the Swedish framework anticipates co-operation with IMY), and/or (ii) law enforcement if criminality is suspected (MCF notes it may pass on information indicating suspected offences and encourages police reporting). In addition, the Act includes duties to inform service recipients in certain cases. 2.4 State Responsibilities and Obligations State Responsibilities and Obligations CERT-SE is Sweden’s national CSIRT, tasked with supporting society in managing and preventing IT incidents. CERT-SE is part of MCF, which helps inte - grate their efforts into the broader national security framework. CERT-SE’s responsibilities include providing assis - tance and guidance to the public sector, private com - panies, and organisations in handling cybersecurity threats and incidents. They aim to enhance the overall cybersecurity posture by offering expertise, co-ordi - nating responses to incidents, and promoting best practices for IT security. Supervisory authorities shall co-operate with the Data Protection Authority when handling incidents that also constitute personal data breaches, and if a supervi - sory authority becomes aware of a circumstance that may constitute a personal data breach reportable under the GDPR, the supervisory authority shall inform the Data Protection Authority about the incident as soon as possible.
If the supervisory authority exercises supervision over an entity identified as a critical third-party ICT service provider under the DORA Regulation, the supervisory authority shall inform the oversight forum established under that regulation. 3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation Scope In Sweden, the scope of financial sector operational resilience regulation is primarily governed by DORA. This regulation applies to a wide range of financial entities, including (but not limited to) banks, credit institutions, payment institutions, insurance com - panies, and alternative investment fund managers. DORA aims to enhance digital operational resilience by setting uniform requirements across the EU, and it is directly applicable in Sweden, requiring national legislation to supplement it. Under DORA, third-party ICT service providers can be designated as “critical” if they provide ICT ser - vices to financial entities within the EU. Once desig - nated as critical, these providers become subject to the EU oversight framework established under DORA, In Sweden, under the framework of DORA, “ICT ser - vice providers” are defined broadly to encompass enti - ties that offer information and communication technol - ogy services to financial institutions. This includes a wide range of services such as cloud computing, data analytics, software development, and cybersecurity services. The definition is intended to cover any third- party service that could impact the operational resil - ience of financial entities. Critical ICT Services Not all ICT services are classified as critical. The clas - sification of an ICT service as critical depends on sev - eral factors, such as the systemic impact of a failure regardless of where they are established. 3.2 ICT Service Provider Contractual Requirements ICT Service Providers
360 CHAMBERS.COM
Powered by FlippingBook