18 Sectors Now Regulated, Up From 7
NIS2 expanded the regulated landscape and placed much of the public sector in scope for the first time including municipalities, regions and kommunalförbund.
Swedish municipalities, regions and government agencies face cyber threats weekly while protecting sensitive citizen data with smaller teams and tighter budgets. Since 2003, eBuilder Security has delivered cybersecurity for the public sector without them building a 24/7 team of their own.
Download the Public Sector NIS2 Readiness ChecklistTrusted by 100+ Swedish Kommuner, Regions and
EU-Regulated Enterprises Since 2002








On 15 January 2026, Sweden’s Cybersäkerhetslagen (2025:1506) brought the EU NIS2 directive into national law expanding the regulated landscape from 7 sectors to 18 and placing much of the public sector in scope for the first time including municipalities, regions, agencies and kommunalförbund, regardless of size.
It arrived against a stark backdrop: a 2025 ransomware attack on a single IT supplier exposed data connected to over 1.5 million Swedish citizens across more than 160 municipalities and regions. eBuilder Security helps you meet these obligations without building a 24/7 team of your own.
NIS2 expanded the regulated landscape and placed much of the public sector in scope for the first time including municipalities, regions and kommunalförbund.
Article 23 sets a 24-hour early-warning deadline to the MCF (formerly MSB) starting the moment an incident is discovered.
Article 21 requires every third-party ICT vendor relationship to be risk-assessed and documented, not just listed on a spreadsheet.
Management must complete cybersecurity training and can be held personally accountable for inadequate risk management.
Sensitive citizen data, critical infrastructure, limited security resources and suppliers with broad access. Public sector organisations are not random targets, they are chosen. By the time most realise they are under attack, the attacker has already been inside for days.
Sensitive citizen data was exposed after a ransomware supply-chain attack compromised a single shared IT platform used across the country. Miljödata incident, Sweden 2025.
A ransomware group targeted Tietoevry, a major Nordic IT supplier. Thousands lost access to critical systems for days. Tietoevry incident, Nordic region.
Year-on-year rise in ransomware attacks targeting government bodies in the first half of 2025. Comparitech, 2025.
Average time an attacker spends inside a network before anyone notices without 24/7 monitoring. Industry average dwell time.
Our services directly address all Article 21 technical controls and support Article 20 management accountability through CISO as a Service.
Documented risk-management policies and board-level reporting, reviewed regularly.
Continuous monitoring with a 2m 50s average analyst response, day and night.
Evidence packages and reporting runbooks aligned to the MCF (formerly MSB) cascade deadline.
Third-party risk assessments and documented ongoing vendor monitoring including suppliers with network access.
Continuity plans and resilience frameworks for citizen-facing and critical services.
Identity monitoring, MFA policy support and access-control hardening across endpoints and identities.
Testing across web, cloud, API, network and Active Directory environments common in municipal IT.
Role-based training and phishing simulations across municipalities and regions, not checkbox compliance.
Senior security leadership for NIS2 governance, MCF reporting and board accountability without a full-time hire.
Our services directly address all Article 21 technical controls and support Article 20 management accountability. The Public Sector NIS2 Readiness Checklist maps your current state against Articles 20 and 21, written for the Swedish regulatory context.
Plain language, built for the Swedish regulatory context, takes around 20 minutes to complete.
Board-ready output reflecting current MCF guidance for municipalities and regions. Delivered to your inbox instantly.
No spam. EU data residency. Unsubscribe any time.
Each service is designed for how municipalities and regions actually operate. Sweden-based, Swedish-speaking built for the way public sector organisations work.
Safe AI Adoption
As public sector organisations adopt AI tools, new risks emerge around citizen data and AI-assisted phishing. AIDR monitors AI usage, model interactions and data flows in real time.
Managed Detection & Response
You cannot staff a 24/7 security team internally. Our Sweden-based SOC watches endpoints, identities and cloud around the clock. A named analyst responds in minutes.
Offensive Security
Expert-led testing across web apps, cloud, APIs, network and Active Directory environments common in municipal IT. Clear prioritised findings, not a report that sits unread.
Training & Phishing Simulation
Short, role-based lessons and realistic phishing simulations for staff across municipalities and regions. Builds genuine awareness, not checkbox compliance.
Strategic Advisory
Most municipalities have no dedicated CISO. We provide senior security leadership for NIS2 governance, MCF reporting and board accountability without a full-time hire.
FREE 30-MIN SECURITY REVIEW
We’ll review your current posture and tell you exactly what matters most.
Talk to a Security AnalystA Swedish security partner focused on transparency, consistency and long-term trust. One of our longest active MDR engagements has run for over 4 years with zero breaches recorded.
See How We Map to Article 21The industry talks in hours. We measure in minutes.
Human analysts watching every signal. Logs stay within Sweden-based infrastructure.
MDR can be live within 72 hours once access and approvals are in place.
Cybersecurity practice within eBuilder, a Swedish technology company since 1999.
Independently audited and certified to the ISO 27001 standard for our SOC.
All services mapped to NIS2 Article 21 risk-management measures, aligned with MCF guidance.
Human-led monitoring and infrastructure aligned with GDPR and Schrems II requirements.
Services support ICT risk management, incident reporting and third-party oversight under DORA.
Our process is silent, fast and built around your existing environment. Once access and approvals are in place, most clients are live within 72 hours.
Sensors deploy through your existing MDM. No user interruption, no visible change to how your team works.
Detection systems learn what normal looks like in your environment, keeping alert volume low and analyst focus high.
Your environment is active in our 24/7 SOC with a named senior analyst and escalation runbooks written for you.
Monthly threat summaries and quarterly reviews keep leadership informed and NIS2 documentation current.
The product increases knowledge and security awareness. I am particularly pleased that it is an end-to-end solution where eBuilder Security takes care of the entire process from kick-off to reporting while allowing for customization to suit the conditions unique to our business.
Per Eriksson
Information Security Strategist, Varbergs Kommun, Sweden
Through their range of security services and our decision to choose their MDR solution, eBuilder Security has significantly elevated our security posture. During the implementation phase, they were quick to assist and propose solutions to any challenges we encountered. The transition from project to production has been smooth.
Gerth Ericsson
IT Manager, Vandewiele, Sweden
eBuilder Security helps us meet our IT and information security needs. We are very satisfied by their deep knowledge, comprehensive services and dedication to strengthening our cybersecurity posture. eBuilder Security has been a reliable partner in safeguarding our organization.
Christian Sørensen
Internal Operations Director, Médecins Sans Frontières, Norway
Real questions a security leader types, answered in two to three sentences.
Yes. All Swedish municipalities and regions are covered by Cybersäkerhetslagen (SFS 2025:1506) in force since 15 January 2026. Unlike the EU NIS2 Directive, Sweden extended the scope to include all municipalities regardless of size. Kommunalförbund and agencies within the 18 sectors are also in scope with MCF (formerly MSB) as the supervisory authority for most public sector organisations.
MDR is a 24/7 service that detects, investigates and responds to active threats. IT support keeps systems running; MDR keeps attackers out. Most municipalities have strong IT teams managing infrastructure and user support but typically lack a dedicated SOC watching for threats at 2am on a Saturday. Our Sweden-based SOC monitors endpoints, identities and cloud with a named analyst who responds within minutes.
Essential entities face penalties of up to €10 million or 2% of global annual turnover. Important entities face up to €7 million or 1.4%. Beyond financial penalties, supervisory authorities can issue binding corrective instructions and apply to a court to prohibit a senior manager from exercising management functions which makes cybersecurity a board-level issue.
Once onboarding access and approvals are in place, most municipalities are live in our 24/7 SOC within 72 hours. Sensors deploy silently on day zero through your existing MDM with no user interruption. Days one and two involve behaviour baselining. By hour 72, your environment is active, a named analyst is assigned and escalation runbooks are written for your organisation.
Security logs and telemetry are processed in Sweden-based infrastructure, aligned with GDPR and Schrems II requirements. This is a contractual commitment, not a marketing claim. eBuilder Security does not route your data through US-based infrastructure and our ISO 27001 certified SOC provides independently audited evidence of our practices.
MDR is priced per endpoint per month with a fixed monthly fee. There are no hidden charges for incident response, analyst escalation or alert volume. The per-endpoint model makes costs predictable for public sector budget cycles. We provide a clear written proposal after the initial 30-minute briefing with no obligation.
When the contract ends, all security telemetry and log data is deleted within a defined retention period set out in the Data Processing Agreement. You receive written confirmation of deletion and no data is retained for any other purpose. The full offboarding process is documented in the service agreement and available for review before you sign.
Article 21 requires ten specific measures covering risk management, incident handling, business continuity, supply chain security, access control, encryption and staff training. Management bodies must approve these measures, oversee implementation and complete cybersecurity training. eBuilder Security maps all Article 21 requirements to its services so you have documented evidence for your supervisory authority.
It means a human analyst has detected, investigated and begun containing a real threat within 2m 50s of it occurring in your environment. This is not an automated alert. A trained analyst confirms the threat, isolates the affected host if necessary and notifies your team. The global industry average dwell time is around 11 days.
No. MDR onboarding is silent and has no impact on staff, systems or citizen-facing services. Sensors deploy through your existing MDM with no user notifications, no restarts and no changes to business applications. This matters where disruption to healthcare booking, social services or municipal e-services has real consequences for citizens.
Yes. We have experience supporting Swedish public sector procurement under LOU and can help before during and after your tender process. We help define skall-krav and bör-krav so your tender evaluates real security capability and provide service descriptions, NIS2 mapping, ISO 27001 certification and reference contacts. We recommend contacting us before you publish your tender.
Larger platforms are built for enterprise corporations, not Swedish municipalities. We are Sweden-based, Swedish-speaking and have worked with the public sector since 2003. Your data stays in Sweden, your analyst knows your environment by name and our service is sized for teams that cannot build a 24/7 operation internally. We also understand Swedish procurement and MCF reporting obligations.
Book a free 30-minute call with a Sweden-based analyst. We’ll review your current security posture and show how our SOC works in practice with no sales pitch and no commitment.
Get the Public Sector NIS2 Checklist