SWEDEN Trends and Developments Contributed by: Anders Bergsten and Victoria Nordenberg, Mannheimer Swartling Advokatbyrå
A further development that increasingly sits within practice, is the push towards European solutions and reduced dependency risk in critical digital infrastruc - ture outside Europe. For many organisations, this is often framed as a procurement, whether to rely on a single cloud provider, and how to address concentra - tion risk, exit planning, and control requirements. The legal relevance is that supplier dependency and sup - ply-chain security are now explicit compliance consid - erations under NIS2 and the Swedish Cybersecurity Act, and supervisory authorities will likely focus on such. In this context, “European alternatives” are not necessarily a political choice; they are often evaluated as part of a broader risk assessment of where sensi - tive services are hosted, who has operational control, and how resilience is ensured if a provider fails, is disrupted or is taken over by a hostile actor. Summary The new Swedish Cybersecurity Act introduces a broader scope of regulated sectors and entities than the Information Security for Critical and Digital Servic - es Act, and it places increased emphasis on supply- chain security, management-level accountability and operational incident preparedness. Incident reporting is structured in mandatory steps and short time lim - its, and the sanctions framework includes turnover- based maximum fees for private essential and impor - tant operators as well as a fixed maximum for public operators.
Supervision is organised through central co-ordina - tion by MCF combined with sector-based supervisory authorities. Early supervisory activity can be expected to focus on scope classification, evidence of imple - mented measures, and the practical ability to comply with incident reporting obligations. Finally, organisations should not approach cyberse - curity compliance in isolation. Many will also need to align their compliance programmes with adjacent regimes, including the Swedish Protective Security Act and the forthcoming Swedish implementation of CER, which may impose additional and overlap - ping governance, resilience and cybersecurity-related requirements.
373 CHAMBERS.COM
Powered by FlippingBook