New · AIDR AI Detection & Response now in early access

Cybersecurity for Sweden’s Education Sector

One partner, full coverage for cybersecurity in the education sector, from a compromised login to a national exam going down. Since 2002, eBuilder Security has delivered cybersecurity for schools and other education providers, so no institution has to build its own 24/7 team.

Download the Education Sector NIS2 Readiness Checklist

Trusted by 100+ Swedish Kommuner, Regions and
EU-Regulated Organisations Since 2002

Who We Protect

Who We Protect Across Swedish Education

“Swedish education providers” covers far more than schools and universities. Skolverket’s remit spans preschool, compulsory school, upper secondary, komvux and higher education, and our services fit each differently.

Preschool and Early Years

Förskola and school-age childcare rely on careful handling of guardian and safeguarding data.

Compulsory Schools

Grundskola runs on student records, grades and special education plans every day.

Upper Secondary Schools

Gymnasieskola carries real risk through digital exams and shared student devices.

Komvux and Adult Education

Komvux data often shares municipal systems with school-age records.

Universities and Higher Education

Universities manage research data, identity federation and large student portals.

Municipal Education Departments

Municipal departments oversee every school a skolhuvudman is responsible for.

Independent School Operators

Friskolor often run smaller IT teams with heavier vendor reliance.

Regional Education Authorities

Regional authorities oversee several municipalities and education types at once.

The Threat Picture

You Hold Student Data. Attackers Know It.

Student records, grades and staff data, held by schools with thin IT teams and dozens of vendor logins nobody reviewed. Attackers do not pick targets at random, which is exactly why ransomware protection for schools cannot wait until after an incident.

NIS2 & Legal Requirements

NIS2, Mapped to How Education Providers Work

On 15 January 2026, Sweden’s Cybersäkerhetslagen (2025:1506) brought the EU NIS2 directive into national law. Education providers, including schools, universities, municipal education departments and independent operators known as friskolor, should assess their position carefully.

Most education providers already run a version of this discipline. Staff need MFA to reach Skolverket services through Skolfederation. NIS2 asks schools to extend that same discipline, secure access, vendor oversight, documented incident response, across every system, not only the exam platform.

€10M Rektorer and school board members are held personally accountable under Article 20 for compliance, with penalties reaching €10 million or 2% of turnover under the law. Cybersäkerhetslagen (2025:1506)
Art. 21 · MFA Secure Every Login

Use MFA for staff, admin and vendor accounts across Skolfederation, Microsoft 365, Google Workspace and learning platforms.

Art. 23 Know When to Report

Prepare clear steps for serious cyber incidents, including when reporting to the MCF (formerly MSB) may be required.

Art. 21 · Vendors Review Every EdTech Vendor

Check learning platforms, classroom apps and support tools connected to student or staff data.

Art. 20 Make Leadership Accountable

Help rektorer, huvudmän and school boards understand what they must approve, monitor and document.

NIS2 · Free Checklist

Everything Your Leadership Needs to Know About NIS2

Our services directly address all Article 21 technical controls and support Article 20 management accountability. The Education Sector NIS2 Readiness Checklist maps your current state against Articles 20 and 21, written for Swedish education providers.

  • Risk management & incident handling: Article 21(2) requires documented risk-management policies and incident handling, and Article 23 sets the 24-hour early warning, 72-hour notification and one-month final report to the MCF (formerly MSB).
  • EdTech vendor security: Article 21(2)(d) requires every vendor relationship, including classroom apps and support tools, to be assessed, documented and kept current.
  • Board accountability: Under Article 20, school leadership carries personal liability, including rektorer and board members. Fines reach €10 million or 2% of global annual turnover.

Plain language, built for Swedish education providers, takes around 20 minutes to complete.

Education Sector NIS2 Readiness Checklist

Board-ready output reflecting current MCF guidance for Swedish education providers. Delivered to your inbox instantly.

No spam. EU data residency. Unsubscribe any time.

One Partner, Everything Covered

Built for Education Providers, Not Enterprises.

Whatever your school runs into, one partner covers it, identity, cloud accounts, vendors, exams, all of it.

NEW

AI Detection & Response

Catch AI-Assisted Phishing Early

As education providers adopt AI tools for teaching and administration, new risks emerge around student data and AI-assisted phishing. AIDR monitors AI usage, model interactions and data flows in real time.

Learn About AIDR

24/7 MDR & SOC

Protect Identities and Learning Platforms

Most education providers cannot staff a 24/7 security team internally. Our Sweden-based SOC watches endpoints, identities and cloud environments around the clock, including Google Workspace and Microsoft 365. A named analyst responds in minutes.

Learn About MDR

Penetration Testing

Find the Gap Before an Attacker Does

Expert-led testing across web applications, cloud environments, APIs, network infrastructure and Active Directory environments common in Swedish education sector IT. Clear prioritised findings, not a report that sits unread.

Learn About Penetration Testing

Security Awareness

Protect Staff from Phishing

Short, role-based training lessons and realistic phishing simulations designed for teaching staff, administrators and IT teams. Builds genuine awareness rather than checkbox compliance, with measurable results from week one.

Learn About Security Awareness

CISO as a Service

Protect Leadership from Blind Spots

Most education providers do not have a dedicated CISO. We provide senior security leadership for NIS2 governance, incident reporting, ed-tech vendor risk management and school board accountability without the cost of a full-time hire.

Learn About CISO as a Service

Not Sure
Where to Start?

FREE 30-MIN SECURITY REVIEW

Book a 30-minute review. We’ll review your current posture and tell you exactly what matters most.

Talk to a Security Analyst
Built in Sweden. Backed by Experience.

Security You Can Verify, Not Just Claim.

We are a Swedish security partner focused on transparency, consistency and long-term trust for Swedish education providers. One of our longest active MDR engagements has run for over 4 years with zero breaches recorded.

See How We Map to Article 21

2m 50s
Average Response Time

The industry talks in hours. We measure in minutes.

24/7
Sweden-Based SOC

Human analysts watching every signal. Logs stay within Sweden-based infrastructure.

<72h
Onboard in Days, Not Quarters

MDR can be live within 72 hours once access and approvals are in place.

20+
Years in Cybersecurity

Cybersecurity practice within eBuilder, a Swedish technology company operating since 2002.

ISO 27001
Independently Certified

Independently audited and certified to the ISO 27001 standard for our SOC.

ISO 27001 certification mark

NIS2
Mapped to Article 21

All services mapped to NIS2 Article 21 risk-management measures and aligned with MCF guidance for Swedish education providers.

GDPR
& Schrems II Aligned

Human-led monitoring and infrastructure aligned with GDPR and Schrems II requirements.

DORA
Operational Resilience

Services support ICT risk management, incident reporting and third-party oversight under DORA.

Getting Started

Term Continues. We Start Watching.

We build the rollout around your school calendar. Most education providers are live within 72 hours, timed to avoid exams and enrolment.

01
Day 0

Quiet Rollout

Sensors install through your existing device management. Nothing changes for teachers or students.

02
Day 1 to 2

Learning Your Environment

Our systems spend a couple of days learning what normal traffic looks like, so real alerts stand out.

03
Within 72 Hours

Live Coverage Begins

Your school is active inside our 24/7 SOC, with a named analyst and runbooks built for how you operate.

04
Ongoing

Steady Reporting

Monthly summaries and quarterly check-ins keep your board briefed and NIS2 records current.

What Clients Say

Voices from the Organisations We Protect

Common Questions

The Questions We Hear from Education Sector Teams

Browse by topic to find the answer you need.

Does our school or municipality need to comply with Sweden’s Cybersecurity Act?

Cybersäkerhetslagen (SFS 2025:1506) entered into force on 15 January 2026 and applies broadly across Swedish public administration. Schools, universities, municipal school boards, friskolor and regional education authorities should each assess their own position, since exact scope depends on size and role rather than being automatic for every organisation. The MCF (formerly MSB) is the supervisory authority for most education providers.

What are the penalties for schools that do not comply with Cybersäkerhetslagen?

Essential entities face penalties of up to 10 million euros or 2 percent of annual turnover, and important entities face up to 7 million euros. Beyond fines, supervisory authorities can prohibit a senior manager from exercising management functions. This makes cybersecurity a board-level issue for school leadership, not just an IT responsibility.

What happened with Skolverket’s national digital exam platform?

In March 2025, Skolverket shut down its national digital exam platform after student data became visible to teachers at other schools, an access control failure rather than an attack. Skolverket confirmed in November 2025 that exams stay on paper for years while it is rebuilt. Identity and access control failures stop real operations, not just IT tickets.

How do you assess risk from ed-tech vendors we didn’t choose ourselves?

Teachers connect new classroom apps all year without IT ever reviewing them. We identify who has access to student data, which vendors connect directly to school systems, whether those accounts carry MFA, and whether anyone would notice unusual vendor activity, then document findings against Article 21 supply chain requirements on an ongoing basis.

What is MDR and why do schools need it if they already have IT support?

MDR is a 24/7 service where dedicated analysts monitor your environment, investigate alerts and contain threats in real time. IT support keeps systems running. MDR keeps attackers out. Most schools do not have a security operations centre watching for threats at 2am on a Saturday, and that is what MDR provides.

Does MDR replace our school’s internal IT team?

No. MDR works alongside your internal IT team and does not replace them. Your IT team manages infrastructure, devices and user support. Our SOC focuses on threat detection, investigation and containment. We define clear escalation paths at the start of every engagement so everyone knows their role when something is detected.

How quickly can a school or university go live with MDR?

Once onboarding access and approvals are in place, most education providers are live in our 24/7 SOC within 72 hours. Sensors deploy silently through your existing MDM on day zero with no disruption to lessons. By hour 72, a named analyst is assigned and escalation runbooks are written for your school.

Will MDR onboarding disrupt classes or student-facing systems?

No. Onboarding is completely silent. Sensors deploy through your MDM with no notifications, no system restarts and no changes to learning platforms or student-facing systems. Teachers and students will not notice anything has changed. This matters most during exam periods and enrolment windows when disruption has real consequences.

Does eBuilder Security support Skolfederation or the national exam platform?

Skolfederation itself is operated by Skolverket, not eBuilder Security. What we do is extend the same MFA and identity discipline your school already uses for national exam access across your other systems, and our SOC pays close attention during exam weeks and other high-stakes periods when disruption matters most.

What categories of student and staff data should we be protecting?

Three categories matter most: children’s personal data such as records, contact details and guardian information; staff and administrative data including payroll and leadership communications; and learning or exam data such as grades and assessment files. IMY, Sweden’s data protection authority, treats children’s data as carrying extra weight under GDPR.

Where is our student data stored and processed?

Security logs and telemetry are processed in Sweden-based infrastructure, aligned with GDPR and Schrems II requirements. This is a contractual commitment in the service agreement, not a marketing claim. eBuilder Security does not route student or staff data through US-based infrastructure. Full data flow documentation is available for your DPO.

Does parent and guardian portal access need to be secured too?

Yes. Parent and guardian accounts often reach grades, attendance and contact details, which makes them a route into student data that gets less attention than staff accounts. Treating parent portal access as part of your identity and access review, not an afterthought, closes a gap that ed-tech vendor risk reviews commonly miss.

Do personal devices used by students and staff create extra risk?

Yes. Students and teachers regularly log into school systems from personal laptops and phones that IT never fully controls, and that gap in visibility is a real target for attackers. We cannot manage the device itself, but our identity and cloud monitoring can flag suspicious sign-ins and account activity regardless of what device they come from.

How does eBuilder Security price its MDR service for schools?

Pricing for education providers is based on endpoint count, with one predictable monthly fee covering MDR. That fee already includes incident response, analyst escalation and alert handling, none of it comes as a surprise extra. Penetration testing, CISO as a Service and security awareness training sit outside MDR and are scoped separately based on what you need.

Why choose eBuilder Security over a larger global cybersecurity platform?

Larger platforms are built for enterprise corporations, not Swedish education providers. eBuilder Security is Sweden-based, Swedish-speaking and has served Swedish public sector organisations since 2002. Your student data stays in Sweden, your analyst knows your environment by name, and our service is sized for teams that cannot build a 24/7 security operation internally.

Book a Briefing

Keep Learning Running.
Even When Threats Appear.

Talk to a Sweden-based analyst for 30 minutes, no cost, no obligation. We’ll walk through your current setup, flag what actually needs attention first, and show you the SOC in action.

Get the Education Sector NIS2 Checklist
No commitment required Sweden-based advisor responds same business day