Cybersecurity 2026

SWEDEN Law and Practice Contributed by: Anders Bergsten and Victoria Nordenberg, Mannheimer Swartling Advokatbyrå AB

tions, service downtime, geographical spread, data losses and economic impact). An incident is classified as major where it has affected critical services and either (i) the malicious unauthorised access materiality threshold is met, or (ii) two or more of the other mate - riality thresholds are met. The malicious unauthorised access threshold is met where any successful, mali - cious and unauthorised access occurs to network and information systems, where such access may result in data losses. Major incident reporting follows a staged timeline: an initial notification as early as possible, in any case within four hours from classification as major and no later than 24 hours from awareness; an inter - mediate report at the latest within 72 hours from the initial notification; and a final report within one month thereafter. 3.4 Operational Resilience Enforcement Enforcement in Regards to Critical ICT Service Providers The supervision of critical ICT service providers is to be carried out at Union level by the Lead Overseer. One of the three European Supervisory Authorities; European Banking Authority, European Securities and Markets Authority or European Insurance and Occu - pational Pensions Authority, is to be designated as Lead Overseer for each of the critical third-party ser - vice providers. In order to fulfil its tasks under DORA, the Lead Overseer may, inter alia, conduct general investigations and inspections. Within three months of the conclusion of an investigation or an inspec - tion, the Lead Overseer shall adopt recommendations addressed to the critical third party provider. The Lead Overseer can impose a periodic penalty payment on the critical ICT service providers. Deci - sions on periodic penalty payments taken by the Lead Overseer should therefore be enforceable under the Swedish Enforcement Code (Sw. Utsökningsbalken (1981:774)) in the same way as a Swedish judgment that has acquired legal force. The Swedish Enforce - ment Authority is the Swedish authority that will be responsible for the practical enforcement and its deci - sions can be appealed to the Swedish court. Enforcement in Regards to Financial Entities In regards to financial entities, the enforcement of operational resilience obligations is carried out by

the Swedish Financial Supervisory Authority. The authority has the power to conduct inspections, request information, and impose sanctions or correc - tive measures on financial institutions and critical ICT service providers that fail to comply with operational resilience requirements. This includes fines, orders to cease certain activities, or other regulatory actions to ensure compliance. 3.5 International Data Transfers DORA does not impose data localisation requirements (it “does not require data storage or processing to be undertaken in the Union”), so cross-border and third- country outsourcing is in principle possible, but must be managed as ICT third-party risk. Contracts must specify the locations (countries/ regions) where services are provided and where data is processed/stored, and require advance notice of changes. Where critical/important functions are out - sourced to a third-country provider, entities must con - sider compliance with Union data-protection rules and the effective enforcement of law in that third country. Entities must also assess third-country subcontract - ing and whether subcontracting chains hinder moni - toring/supervision. Before contracting, entities must assess criticality, supervisory conditions, concentra - tion risk, due diligence, and conflicts of interest, and ensure appropriate information-security standards. 3.6 Threat-Led Penetration Testing Threat-Led Penetration Testing In Sweden, DORA mandates threat-led penetration testing (TLPT) for financial entities. These tests must be conducted every three years, or more frequent - ly if required by the competent authority. The tests simulate cyberattacks to identify vulnerabilities in an organisation’s ICT infrastructure. Each test must cover several or all critical or important functions of the financial entity on live production systems, with entities identifying all relevant underlying ICT systems, processes and technologies. The tests must be executed by an external party every third time, while internal testers can be used but require specific approval and must meet conflict-of-interest requirements. The Swedish authorities, primarily the Swedish Financial Supervisory Authority and the Swed -

362 CHAMBERS.COM

Powered by