Public Sector · Sweden New · AI Detection & Response now in early access

Cybersecurity for the Swedish Public Sector

Swedish municipalities, regions and government agencies face cyber threats weekly while protecting sensitive citizen data with smaller teams and tighter budgets. Since 2003, eBuilder Security has delivered cybersecurity for the public sector without them building a 24/7 team of their own.

Download the Public Sector NIS2 Readiness Checklist

Trusted by 100+ Swedish Kommuner, Regions and
EU-Regulated Enterprises Since 2002

The 2026 Reality

The Law Changed. Is Your Organisation Ready?

On 15 January 2026, Sweden’s Cybersäkerhetslagen (2025:1506) brought the EU NIS2 directive into national law expanding the regulated landscape from 7 sectors to 18 and placing much of the public sector in scope for the first time including municipalities, regions, agencies and kommunalförbund, regardless of size.

It arrived against a stark backdrop: a 2025 ransomware attack on a single IT supplier exposed data connected to over 1.5 million Swedish citizens across more than 160 municipalities and regions. eBuilder Security helps you meet these obligations without building a 24/7 team of your own.

Under Cybersäkerhetslagen Article 20, penalties reach €10M and board members are held personally accountable for compliance
Scope

18 Sectors Now Regulated, Up From 7

NIS2 expanded the regulated landscape and placed much of the public sector in scope for the first time including municipalities, regions and kommunalförbund.

Reporting

24 Hours to Notify MCF

Article 23 sets a 24-hour early-warning deadline to the MCF (formerly MSB) starting the moment an incident is discovered.

Supply Chain

Every ICT Vendor Must Be Assessed

Article 21 requires every third-party ICT vendor relationship to be risk-assessed and documented, not just listed on a spreadsheet.

Article 20

Board Training Is a Personal Obligation

Management must complete cybersecurity training and can be held personally accountable for inadequate risk management.

The Threat Picture

You Hold Citizen Data. Attackers Know It.

Sensitive citizen data, critical infrastructure, limited security resources and suppliers with broad access. Public sector organisations are not random targets, they are chosen. By the time most realise they are under attack, the attacker has already been inside for days.

NIS2 · Cybersäkerhetslagen

Every NIS2 Control. One Partner. Zero Gaps.

Our services directly address all Article 21 technical controls and support Article 20 management accountability through CISO as a Service.

Art. 21(2)(a) Risk Management Policies & Governance

Documented risk-management policies and board-level reporting, reviewed regularly.

Art. 21(2)(b) Incident Detection & Handling

Continuous monitoring with a 2m 50s average analyst response, day and night.

Art. 23 Incident Reporting to MCF Within 24 Hours

Evidence packages and reporting runbooks aligned to the MCF (formerly MSB) cascade deadline.

Art. 21(2)(d) Supply Chain Security & Vendor Risk

Third-party risk assessments and documented ongoing vendor monitoring including suppliers with network access.

Art. 21(2)(c) Business Continuity & Backup

Continuity plans and resilience frameworks for citizen-facing and critical services.

Art. 21(2)(i–j) Secure Access Including MFA

Identity monitoring, MFA policy support and access-control hardening across endpoints and identities.

Art. 21(2)(e–f) Security Testing & Vulnerability Management

Testing across web, cloud, API, network and Active Directory environments common in municipal IT.

Art. 21(2)(g) Cyber Hygiene & Staff Training

Role-based training and phishing simulations across municipalities and regions, not checkbox compliance.

Art. 20 (Governance) Management Accountability & Board Training

Senior security leadership for NIS2 governance, MCF reporting and board accountability without a full-time hire.

NIS2 · Free Checklist

Everything Your Board Needs to Know About NIS2

Our services directly address all Article 21 technical controls and support Article 20 management accountability. The Public Sector NIS2 Readiness Checklist maps your current state against Articles 20 and 21, written for the Swedish regulatory context.

  • Risk management & incident handling: Article 21(2) requires documented risk-management policies and incident handling and Article 23 sets the 24-hour early warning, 72-hour notification and one-month final report to MCF via CERT-SE.
  • Supply-chain security: Article 21(2)(d) requires every third-party vendor relationship including small suppliers with network access, to be assessed, documented and kept current.
  • Board accountability: Under Article 20, board members carry personal liability. Fines reach €10 million or 2% of global annual turnover.

Plain language, built for the Swedish regulatory context, takes around 20 minutes to complete.

Swedish Public Sector NIS2 Readiness Checklist

Board-ready output reflecting current MCF guidance for municipalities and regions. Delivered to your inbox instantly.

No spam. EU data residency. Unsubscribe any time.

One Partner, Everything Covered

Everything You Need. Nothing You Don’t.

Each service is designed for how municipalities and regions actually operate. Sweden-based, Swedish-speaking built for the way public sector organisations work.

NEW

AI Detection & Response

Safe AI Adoption

As public sector organisations adopt AI tools, new risks emerge around citizen data and AI-assisted phishing. AIDR monitors AI usage, model interactions and data flows in real time.

Learn About AIDR

24/7 MDR & SOC

Managed Detection & Response

You cannot staff a 24/7 security team internally. Our Sweden-based SOC watches endpoints, identities and cloud around the clock. A named analyst responds in minutes.

Learn About MDR

Penetration Testing

Offensive Security

Expert-led testing across web apps, cloud, APIs, network and Active Directory environments common in municipal IT. Clear prioritised findings, not a report that sits unread.

Learn About Penetration Testing

Security Awareness

Training & Phishing Simulation

Short, role-based lessons and realistic phishing simulations for staff across municipalities and regions. Builds genuine awareness, not checkbox compliance.

Learn About Security Awareness

CISO as a Service

Strategic Advisory

Most municipalities have no dedicated CISO. We provide senior security leadership for NIS2 governance, MCF reporting and board accountability without a full-time hire.

Learn About CISO as a Service

Not Sure
Where to Start?

FREE 30-MIN SECURITY REVIEW

We’ll review your current posture and tell you exactly what matters most.

Talk to a Security Analyst
Built in Sweden. Backed by Experience.

Security You Can Verify, Not Just Claim.

A Swedish security partner focused on transparency, consistency and long-term trust. One of our longest active MDR engagements has run for over 4 years with zero breaches recorded.

See How We Map to Article 21

2m 50s
Average Response Time

The industry talks in hours. We measure in minutes.

24/7
Sweden-Based SOC

Human analysts watching every signal. Logs stay within Sweden-based infrastructure.

<72h
Onboard in Days, Not Quarters

MDR can be live within 72 hours once access and approvals are in place.

20+
Years in Cybersecurity

Cybersecurity practice within eBuilder, a Swedish technology company since 1999.

ISO 27001
Independently Certified

Independently audited and certified to the ISO 27001 standard for our SOC.

ISO 27001 certification mark

NIS2
Mapped to Article 21

All services mapped to NIS2 Article 21 risk-management measures, aligned with MCF guidance.

GDPR
& Schrems II Aligned

Human-led monitoring and infrastructure aligned with GDPR and Schrems II requirements.

DORA
Operational Resilience

Services support ICT risk management, incident reporting and third-party oversight under DORA.

Getting Started

Your Team Keeps Working. Ours Starts Watching.

Our process is silent, fast and built around your existing environment. Once access and approvals are in place, most clients are live within 72 hours.

01
Day 0

Silent Sensor Deployment

Sensors deploy through your existing MDM. No user interruption, no visible change to how your team works.

02
Day 1 to 2

Behaviour Baselining

Detection systems learn what normal looks like in your environment, keeping alert volume low and analyst focus high.

03
Within 72 Hours

SOC Goes Live, Often Sooner

Your environment is active in our 24/7 SOC with a named senior analyst and escalation runbooks written for you.

04
Ongoing

Continuous Protection

Monthly threat summaries and quarterly reviews keep leadership informed and NIS2 documentation current.

What Clients Say

Hear It from the Organisations We Protect

Common Questions

The Questions We Hear from Public Sector Teams

Real questions a security leader types, answered in two to three sentences.

Does our municipality or region need to comply with Sweden’s Cybersecurity Act?

Yes. All Swedish municipalities and regions are covered by Cybersäkerhetslagen (SFS 2025:1506) in force since 15 January 2026. Unlike the EU NIS2 Directive, Sweden extended the scope to include all municipalities regardless of size. Kommunalförbund and agencies within the 18 sectors are also in scope with MCF (formerly MSB) as the supervisory authority for most public sector organisations.

What is MDR and why do municipalities need it if they already have IT support?

MDR is a 24/7 service that detects, investigates and responds to active threats. IT support keeps systems running; MDR keeps attackers out. Most municipalities have strong IT teams managing infrastructure and user support but typically lack a dedicated SOC watching for threats at 2am on a Saturday. Our Sweden-based SOC monitors endpoints, identities and cloud with a named analyst who responds within minutes.

What are the penalties for a municipality that does not comply with Cybersäkerhetslagen?

Essential entities face penalties of up to €10 million or 2% of global annual turnover. Important entities face up to €7 million or 1.4%. Beyond financial penalties, supervisory authorities can issue binding corrective instructions and apply to a court to prohibit a senior manager from exercising management functions which makes cybersecurity a board-level issue.

How quickly can a municipality or region go live with MDR?

Once onboarding access and approvals are in place, most municipalities are live in our 24/7 SOC within 72 hours. Sensors deploy silently on day zero through your existing MDM with no user interruption. Days one and two involve behaviour baselining. By hour 72, your environment is active, a named analyst is assigned and escalation runbooks are written for your organisation.

Where is our security data stored and processed?

Security logs and telemetry are processed in Sweden-based infrastructure, aligned with GDPR and Schrems II requirements. This is a contractual commitment, not a marketing claim. eBuilder Security does not route your data through US-based infrastructure and our ISO 27001 certified SOC provides independently audited evidence of our practices.

How does eBuilder Security price its MDR service?

MDR is priced per endpoint per month with a fixed monthly fee. There are no hidden charges for incident response, analyst escalation or alert volume. The per-endpoint model makes costs predictable for public sector budget cycles. We provide a clear written proposal after the initial 30-minute briefing with no obligation.

What happens to our data if we end the contract?

When the contract ends, all security telemetry and log data is deleted within a defined retention period set out in the Data Processing Agreement. You receive written confirmation of deletion and no data is retained for any other purpose. The full offboarding process is documented in the service agreement and available for review before you sign.

What does NIS2 Article 21 require from Swedish municipalities and regions?

Article 21 requires ten specific measures covering risk management, incident handling, business continuity, supply chain security, access control, encryption and staff training. Management bodies must approve these measures, oversee implementation and complete cybersecurity training. eBuilder Security maps all Article 21 requirements to its services so you have documented evidence for your supervisory authority.

What does a 2 minute 50 second average response time mean in practice?

It means a human analyst has detected, investigated and begun containing a real threat within 2m 50s of it occurring in your environment. This is not an automated alert. A trained analyst confirms the threat, isolates the affected host if necessary and notifies your team. The global industry average dwell time is around 11 days.

Will MDR onboarding disrupt our staff or citizen-facing services?

No. MDR onboarding is silent and has no impact on staff, systems or citizen-facing services. Sensors deploy through your existing MDM with no user notifications, no restarts and no changes to business applications. This matters where disruption to healthcare booking, social services or municipal e-services has real consequences for citizens.

Can eBuilder Security support our public procurement process under LOU?

Yes. We have experience supporting Swedish public sector procurement under LOU and can help before during and after your tender process. We help define skall-krav and bör-krav so your tender evaluates real security capability and provide service descriptions, NIS2 mapping, ISO 27001 certification and reference contacts. We recommend contacting us before you publish your tender.

Why choose eBuilder Security over a larger global cybersecurity platform?

Larger platforms are built for enterprise corporations, not Swedish municipalities. We are Sweden-based, Swedish-speaking and have worked with the public sector since 2003. Your data stays in Sweden, your analyst knows your environment by name and our service is sized for teams that cannot build a 24/7 operation internally. We also understand Swedish procurement and MCF reporting obligations.

Book a Briefing

Stop Watching Dashboards.
Start Sleeping at Night.

Book a free 30-minute call with a Sweden-based analyst. We’ll review your current security posture and show how our SOC works in practice with no sales pitch and no commitment.

Get the Public Sector NIS2 Checklist
No commitment required Sweden-based advisor responds same business day