Strong protection for network and information systems - a new cybersecurity law
Translated from Swedish by AI; the translation may contain errors. The Swedish text is the original.
Summary AI, written in advance
1 M considers the new cybersecurity law to be the most comprehensive legislation to strengthen resilience against cyberattacks 1 2. M defends the government's strategy as being rich in content with concrete measures 3 and is proud of the reform work 4 5. 6 S argues that the strategy is fragmented, lacks clear distribution of responsibility, and contains unmeasurable goals 6 7 8. S wants to see a coherent national cyber responsibility with reinforced competence 8 and argues that dispersed responsibility is a serious matter 9 10. 11 KD urges approval to protect infrastructure 11. 12 V wants cybersecurity to be seen as a core activity 12 and that 5G is jointly owned 12. 13 L argues that the law is crucial for the total defense 13. 14 KD demands clarity regarding the leadership's responsibility and harmonization of sanction fees 14. 15 MP welcomes the proposal but expresses concern over the financing 15.
Written by AI in advance and may contain errors. The numbers lead to the speech a statement builds on; check against the text below.
Speakers (16)
Camilla Brunsberg (M)
Mr. Speaker! The Riksdag is debating today one of the more important decisions for Sweden's security, namely the proposal for a new cybersecurity law. This is a legal framework that will strengthen Sweden's resilience in a time when the threats against our country are becoming increasingly advanced, increasingly systematic, and increasingly targeted.
Cyberattacks are no longer hypothetical scenarios but a part of everyday life. They are directed at our authorities, our companies, our municipalities and our critical societal functions. The attacks are increasing in both scope and complexity. Therefore, we are now acting in the Riksdag and the government.
The government is now presenting the most extensive cybersecurity legislation Sweden has ever had. It is primarily based on the NIS 2 Directive, which is to be implemented in all EU member states and which is described in the report as an entirely necessary step to achieve a high and common level of cybersecurity in the union.
I would like to emphasize three important points in this bill.
Firstly, we strengthen Sweden's baseline regarding cybersecurity. The law tightens the requirements and expands the circle of actors covered. 18 critical sectors, from energy, transport, and healthcare to food, drinking water, digital infrastructure, and public administration, will now be covered by clearer requirements. It is about actors having to have strategies for risk analysis, incident management, supply chains, and continuity. The management in the affected operations shall also undergo training in cybersecurity. This is completely in line with the directive and crucial for creating accountability at the highest level.
Secondly, we improve the ability to detect and manage incidents. Actors within the designated sectors must report significant incidents within 24 or 72 hours. This ensures that the spread can be limited and that the state quickly receives a consolidated situational picture. The supervisory authorities also receive sharper tools in the form of orders, sanction fees, and in specific cases, the possibility to prohibit an executive from holding a management position. These are necessary tools, and the committee stands behind them.
For the third, the municipalities receive both clearer requirements and increased resources.
Mr. Speaker! Municipalities and regions are central parts of the total defense. Their digital systems are important for everything from elderly care and healthcare to water and schools. The new law clarifies responsibilities, tightens requirements, and presupposes a systematic security work.
The state does not leave them alone, however. In the budget, 250 million kronor are allocated to municipalities and regions to ensure that they can live up to the new requirements. This is part of the government's broad cybersecurity initiative in the budget bill.
Mr. Speaker! Cybersecurity is now a part of the total defense, and just as in the total defense, everyone has a role. This applies to the state, the municipalities, the regions and the companies, but also to each one of us who use digital systems in everyday life. Basic cyber hygiene and a conscious approach can be what prevents the next attack from succeeding.
Let me also emphasize that the government has chosen quality over speed in the implementation of the NIS 2 Directive. The aim has been to create a long-term sustainable regulatory framework and not to unnecessarily burden companies and actors with disproportionate costs. It is responsible politics.
The government has also presented a new national cybersecurity strategy, carried out a restructuring of the national cybersecurity center and strengthened support for municipalities, regions and companies.
Mr. Speaker! Our society today is deeply dependent on digital systems. This makes us strong but also vulnerable. Cyberattacks can shut down our power supply, disrupt payments, threaten our healthcare, and affect our democracy. To stand passive would be a betrayal of the Swedish people.
That is why the Tidö parties are now taking responsibility. With this law, we increase Sweden's resilience and protect welfare, companies, and citizens, and we do so with a powerful, modern, and proportionate regulatory framework.
I therefore move for approval of the committee's proposal and thereby of the government bill.
Markus Selin (S)
Mr. Speaker! I agree with the Moderate Party member Camilla Brunsberg: The issue we are now debating is extremely important.
We Social Democrats have previously reacted to the government's various cyber strategies, and therefore I am reacting now when I hear the member speak about this cyber strategy. In recent years, many different strategies have been stacked on top of each other.
In the spring of 2023, the National Audit Office pointed out that society's governance and distribution of responsibility must become even clearer in everything concerning cybersecurity. What has then happened during the SD-M-KD-L government? The Minister for Digitalization, who is a Christian Democrat, delivered his own strategy this spring, and a year ago, the Minister for Foreign Affairs also delivered his own cyber strategy for foreign affairs. The government has also launched an ambassador responsible for cybersecurity issues, which is interesting because the digital has no national borders. In addition to this, the Minister for Justice shall handle cyber issues if they involve terrorism. Furthermore, the Minister for Education goes to Cybercampus and cuts ribbons as well as writes opinion pieces about cyber strategy.
Mr. Speaker! I do not know how the handful of different strategies that have been delivered make the whole thing more strategic. I do not understand that.
Camilla Brunsberg (M)
Mr. Speaker! I understand that Member Markus Selin is concerned about cybersecurity given that the Social Democrats failed to deliver during their time in power. Just as the Member pointed out, the National Audit Office's criticism was brutal. Nothing worked. Despite the fact that we were one of the world's most digitized countries, our national cybersecurity was seriously neglected.
It is, however, good that the member points out today's high level of ambition and large reforms. Extensive initiatives are being taken to increase national cybersecurity. For example, we are now debating the new cybersecurity law, which is the most ambitious legislation ever in Sweden regarding cybersecurity. I hope that we are at least in agreement that this legislation is sharp and sufficiently good.
As I pointed out in my speech, we have undertaken extensive reform work because cybersecurity was severely neglected and the National Audit Office's criticism was brutal – a criticism directed at precisely the Social Democratic government. The National Cybersecurity Centre has received a new, clear and strategic governance and leadership, a new cybersecurity strategy is in place, and Sweden is now receiving its sharpest legislation ever for cybersecurity.
I understand, as I said, the member's concern, but it was good that the member took the opportunity to tell the Chamber what high level of ambition our bourgeois government has in this matter.
Markus Selin (S)
Mr. Speaker! I get no answer. Which strategy applies – and when? This is serious, because during the mandate period, the cybersecurity strategies have become a mess. It has become very messy.
The Minister for Civil Defence, Moderate Carl-Oskar Bohlin, was supposed to be here today but has unfortunately fallen ill. During his press conference last spring, he made the famous statement that the strategy does not contain fluff and immeasurable goals. Since I am interested in cybersecurity, I went in and looked at the Moderates' updated strategy. Here, 73 measures are listed, which looks nice. But 38 of these measures, i.e., more than half, are pure nonsense. If one can manage projects and looks at the strategy, one probably asks what this is. For example, it says that the National Cybersecurity Centre shall, for the time being, have operations with FRA. That is a non-statement. Furthermore, a favorite is that the police shall continue to deal with cybercrime. This is, therefore, one of these 73 measures. This is nonsense!
Camilla Brunsberg (M)
Mr. Speaker! I would like to assert that the member's criticism is nonsense. Here stands a member whose government was responsible for Sweden having a severely neglected cybersecurity for several years.
I think this cybersecurity strategy is incredibly good, and I am proud that we have developed it. It contains concrete measures and annual follow-ups, which should be compared to the policy in the area that received brutal criticism from the Swedish National Audit Office because it lacked both governance and management. This cybersecurity strategy receives the highest grade from me because it, as said, contains concrete action plans and annual follow-ups.
Today, the Riksdag also passes the strictest law ever on cybersecurity.
I understand the member's concern given his baggage and history, but I am proud that we have taken action and strengthened cybersecurity in Sweden. I also think the National Cybersecurity Centre is doing an outstanding job, and the centre is and will continue to be a good support to all of Sweden's municipalities and regions. I am proud of the policy we are implementing and the law that will be passed today.
Markus Selin (S)
Mr. Speaker! We are now debating the Committee on Defence's report, A strong protection for network and information systems – a new cybersecurity law. It is about our digital resilience, about securing the systems that keep Sweden running and about protecting our society as the threat landscape grows.
We find ourselves in one of the most serious security policy situations since the Cold War. Cyberattacks are used today as part of modern conflicts. Municipalities, regions, authorities, and companies have in recent years been subjected to intrusions, extortion, and attacks that have struck directly against all of us and against welfare and security. Society is dependent on the digital, and the digital is dependent on society. A single intrusion can affect healthcare, transport, payments, and electricity and water supply. It is against this background that we today address the new legislation.
Mr. Speaker! With this cybersecurity law, the EU's NIS 2 Directive is being implemented, but it is also a necessary modernization for Sweden. The law entails, among other things, stricter security requirements and that more operations are covered than before. Societally important actors receive clear obligations to analyze risks, take security measures, and report incidents.
The law also entails, among other things, a significantly strengthened supervision. The Government decides which authority or authorities shall be the supervisory authority. The supervision will become more effective, with possibilities for orders and sanction fees.
The law also implies, among other things, increased security in supply chains. We have seen that attackers often strike via subcontractors. With the new law, authorities and companies will be obliged to check and secure their chains and dependencies.
The law also implies, among other things, better adaptation to the EU. Interoperability is an important prerequisite for the total defense. Sweden must be able to cooperate digitally with our partners when it comes to that.
Mr. Speaker! This is a comprehensive reform, and the Social Democrats stand behind the main features. But the law we establish today is only the framework; more deficiencies must also continue to be addressed if the law is to have a real effect.
Small steps are being taken in the right direction, slowly, but overall, the national governance is still lacking. Sweden's cybersecurity structure is still fragmented.
The Defence Radio Establishment performs very important and advanced work regarding signals intelligence but also information security, and it is welcome that they have taken over the primary responsibility for the National Cybersecurity Centre.
Despite the fact that the Swedish National Audit Office already in April 2023 submitted recommendations in its report on the government's management of society's information and cyber security, the responsibility is still unclearly distributed between different agencies, ministers and departments.
Two of the main messages in the National Audit Office's report were that the work must become more strategic and that unified governance with a clear distribution of responsibility must be ensured.
We support the government's bill today, but at the same time, much of the policy is in other debates and reports. We therefore move for approval of our reservation today under the heading Development of Cyber Policy, with emphasis on key phrases in our reservation text. It is about "systematic" and that we must let "the state's responsibility and capacity within cybersecurity continue to be built out and deepened" as well as that all this shall occur "coordinated and powerfully".
It can be reminded here that when the updated national strategy for cybersecurity was presented this spring by the Moderate Minister for Civil Defence, words were used such as "this is not a strategy that contains vagueness and immeasurable goals." But if we look at the appendix, we see that there are 73 actions of action in bullet points, of which more than half are precisely immeasurable. At times it is downright nonsense, for example that the Swedish Police Authority shall work with cybercrime.
We have seen a stacking of different strategies in Sweden in recent years, despite what the Swedish National Audit Office informed us in the spring of 2023. I do not know, and I do not believe anyone knows, how a stacking of different strategies is suddenly supposed to make our entire collective cybersecurity strategy even more strategic.
For example, the Minister for Digitalization released their own digitalization strategy this spring. The Minister for Foreign Affairs released their own cybersecurity strategy for foreign relations almost exactly one year ago. The Government has also appointed a special envoy responsible for cyber issues – an ambassador – which is interesting because the digital does not have any national borders at all.
The Minister for Defence from the Moderaterna has a separate cyber strategy that arrived in the summer of 2024 and which is about how digital communication, for example, can go via satellites. Also, the Minister for Justice shall handle cybersecurity issues, because if someone quickly finds out that it could involve a terrorist crime, it falls on the Minister for Justice's desk.
This is not a unified governance, rather it is unclear. Ultimately, it is about our security.
An interesting thing is that as a response to the Swedish National Audit Office's report from the spring of 2023, a letter was issued from the government where the national security advisor was highlighted as a possible unifying link that would drive things forward. Without twisting this too much, we can say that the Moderate Prime Minister saw a national security advisor as a prestige project. It was also supposed to have a direct impact on our cybersecurity, but it turned into a mess.
Still, we do not really know how all of this is linked to the next possible major cyberattack in Sweden. On the government's website, it states that the Prime Minister's State Secretary is to lead the collective crisis management work.
Mr. Speaker! The Social Democrats want to see a more cohesive national cyber responsibility, clear governance, clear support for municipalities, regions and the business sector, reinforced public IT security competence and, in large terms, a Swedish innovation and industrial policy that strengthens our own cybersecurity capability.
In its simplest form, we can express it like this: By increasing broad IT knowledge in Sweden, we gain stronger resilience, statistically more experts on the purchase, more business ideas, and a genuine chance to become world-best at seizing the opportunities of digitalization.
We Social Democrats will continue to push for Sweden to stand strong even within the digital domain – a Sweden where welfare, business, infrastructure and democracy can be protected as attacks increase and a Sweden that is a reliable partner in an increasingly uncertain world.
Camilla Brunsberg (M)
Mr. Speaker! Once again we hear Member Markus Selin from the rostrum tell us about the extensive and ambitious reform work that the government has now carried out regarding cybersecurity. I think it is good that the Member points this out time and again, because it is important that we now make ambitious investments, make reforms, and make changes and improvements to get cybersecurity in place. It was powerfully pursued.
It is easy to criticize what a government does, but what I would specifically like to know from Member Markus Selin now is exactly which parts the Member intends to remove from the extremely ambitious reform work that the government has carried out. What is it that you intend to remove? Which strategy do you intend to cut if the Social Democrats get into power?
It is easy to just sit in the stands and say that it is bad, but now I want to know concretely which parts the member intends to remove in the extremely ambitious reform work that our government has carried out. It is a bourgeois government that has the support of the Sverigedemokraterna and a strong majority in the chamber.
It would be interesting for the voters to know how you intend to dismantle Swedish cybersecurity and which strategies you intend to remove, since you were so clear in your speech.
FÖRSTE VICE TALMANNEN
I must remind the member that we do not use "du" as a form of address.
Markus Selin (S)
Mr. Speaker! Yes, where shall we begin? When it comes to how society's collective cybersecurity should become more strategic, the answer is not five strategies. One strategy is enough.
If we want to gather the management of and stewardship for our common cyber strategy, it is sufficient with one state councilor or a minister, or possibly two since we have two in the Ministry of Defence right now. But now it is starting to become both the Minister for Justice, the Minister for Education, the Minister for Civil Affairs as well as the Minister for Digitalisation, the Minister for Civil Defence and the Minister for Defence and additionally the Minister for Foreign Affairs, who has appointed a foreign ambassador with responsibility for cyber issues and an own strategy.
I believe there are more of us than just me who hear that this is not strategic.
How would we do it then? I have almost answered that. We would consolidate the management with as few strategies as possible, but they would be flexible, crisp, and clear. Do not spread the responsibility across several departments, more agencies, and more ministers! I actually believe that is what has happened.
I have noticed that this thing with cyber is a buzzword. I might be wrong, but I think it is a bit cool to spread the word cyber in society. It sounds a bit hip and modern and so. But the consequences can be devastating when one makes paper products with 73 different activity goals, because when one actually reads them, one sees that it is just hot air. Then the minister says at the press conference that it is not fluff, but it is precisely what we have received.
Camilla Brunsberg (M)
Mr. Speaker! I can state that the member considers the cybersecurity strategy to be nonsense, that we have far too many strategies, and that one actually wants to remove them all.
I would like to point out once again that I am incredibly proud of our reform work and the level of ambition that our bourgeois government has when it comes to cybersecurity. Not only have we reformed the National Cybersecurity Centre and developed a sharp cybersecurity strategy with action plans and annual follow-ups, but today we are passing the sharpest law we have ever seen in the area. We have also appointed a minister who is responsible for civil defense, where cybersecurity is included.
I can state that although the Social Democrats failed to manage cybersecurity during their time in power, the promise from them to dismantle all the ambitious reform work that our government has carried out and go back to square one is what the National Audit Office so brutally criticized.
Markus Selin (S)
Mr. Speaker! The member says that we want to "dismantle everything." No, there is no one here who has said anything about dismantling everything. Let me be clear: If this government, in a prestige project, appoints a national security advisor who is also to be responsible for cybersecurity and it turns into a mess – yes, then it is a mess!
I am not interested in an appendix with 73 made-up points in the government's cyber strategy. I am genuinely worried: Who is in charge? We could get a cyberattack this afternoon. We have not seen the worst consequences yet. We have been hit hard, but it could get even worse this afternoon. Who is in charge in the event of a serious cyberattack? Is it the Prime Minister's State Secretary, or is it the national security advisor? And which of the five ministers I mentioned is it who has the ultimate responsibility? Is it the Minister for Justice, the Minister for Foreign Affairs, the Minister for Digitalization as well as the Minister for Civil Affairs, the Minister for Defence or the Minister for Civil Defence?
This concerns all of us. Everyone should be very eager to get clarity here. Who is it that is in charge? What strategy is it that we are to follow? Which department is it that we are to follow? Which press conference and which department should the journalists go to when they scrutinize our work? We have 290 municipalities and 21 regions. Which authority is it that they are to rely on?
I am not standing here because it was a funny appendix and a funny statement by the Moderate minister last time. I say that this is serious. We see it all around us. The consequences can become very serious if one does not take this fully seriously.
I promise one thing: the Social Democrats will continue to take these issues very seriously. It concerns our ultimate security.
Mikael Oscarsson (KD)
Mr. Speaker! We are debating the Committee on Defence's report number 2, A strengthened protection for network and information systems – a new cybersecurity law. Let me begin by moving for the approval of the committee's proposal in its entirety and the rejection of the reservations.
Mr. Speaker! Sweden is today one of the world's most digitized countries. It is definitely a fantastic strength but also, of course, a vulnerability. We see how cyberattacks are no longer only directed at authorities or individual companies. They are directed at our most fundamental societal functions: power grids, payment systems, communications, healthcare, and transport. Today we are therefore debating one of the most important pieces of legislation for Sweden's collective resilience, the new cybersecurity law, which implements the EU's NIS 2 Directive. Ultimately, it is about protecting Sweden – not just our data but our way of life.
There are a couple of reasons why this legislation is so important. The first is that the threat against Sweden is now more serious than it has been in many decades. Cyberattacks are being used as a weapon by authoritarian states and criminal actors. We have seen sabotage against municipalities, regions, and companies. We have seen how sensitive information has been stolen and how ransomware attacks have paralyzed society's functions.
Let me take some examples. During the past year, we had an extensive attack against Nordea that was massive and lasted for 25 days in a row. Previously, the attacks had lasted for a couple of days, but now it was, therefore, 25 days in a row with heavy DDOS attacks. It is one of the most persistent attacks that has hit a Nordic bank.
The attack had major consequences. Internet banking and the mobile app were disrupted. Payments, Swish, and card transactions were affected. Both companies and private individuals had difficulty carrying out transactions. This shows how vulnerable our financial system is and how quickly a cyberattack can strike against the entire society's payment flows.
Another example that deserves to be reminded of is last year's cyberattacks against Region Skåne, where journal systems and healthcare processes were knocked out. We have also both this year and during last year seen attacks directed at Finland and Norway that have struck critical infrastructure. Authorities and services have been knocked out, and personal data has risked being exposed.
This is truly a strong threat that is ongoing right now. We also know that particularly Russia, China, North Korea, and Iran are the largest actors. Therefore, Mr. Speaker, it is important to close the digital gaps that exist. Companies and authorities that form a part of our society-critical infrastructure must have a robust baseline of security. This varies greatly today. It is not sustainable.
The law sets clear requirements for risk analyses, incident reporting, management, and control. It is absolutely necessary. It is also worth pointing out that we have had a cybersecurity effort that has been very fragmented for many decades. For example, the cybersecurity center initially had four primary stakeholders and even more that one was supposed to cooperate with. Now it has become FRA that is primarily responsible for the center, which is very good. But here there are probably more things that need to be done to achieve further centralization. I believe that in the long run we need to have an agency that takes primary responsibility for this work, as is the case in many other countries.
Hanna Gunnarsson (V)
Mr. Speaker! Hello to everyone listening or watching at home! Today we are debating a new cybersecurity law. I want to start by moving for the approval of reservation 3.
Mr. Speaker! We live in a very vulnerable world. Not only has Russia invaded Ukraine and Israel's occupation of Palestine continues – in both places with a large number of civilian deaths and great material destruction – but we also have a galloping climate crisis leading to people needing to flee after climate-related crises. We see a polarization in the world that causes groups to be pitted against each other. We see a very large number of cyberattacks that affect the functionality of society at its core.
A few months ago, I and a delegation of Members of Parliament visited Taiwan. There, they told us about how they are subjected to millions of cyberattacks every day. It is a real threat to very many of society's important functions, but it also entails a very large risk of disinformation through fake news and propaganda that enters society, for example through organized troll factories. In Sweden, it is not quite as many attacks, but we are still subjected to a very large number of cyberattacks every day.
Cybersecurity must therefore be a core part of our total defense. Our society is today digitized to a very high degree. Much will cease to function if the digital systems go down. In many cases, a cyberattack can have devastating consequences, not only for people in the form of a more complicated everyday life but also for the way society-critical activities function and, ultimately, in the worst case, for life and health. Cybersecurity is therefore one of the pieces of the puzzle in being able to have a robust and secure society for all our inhabitants.
Mr. Speaker! Cybersecurity is a shared responsibility. It is a responsibility for the individual, who must keep track of their own digital presence, their passwords and their logins, and know how to behave in a correct manner in the digital world. It is a responsibility for the business sector, where every company must secure its own operations and its digital systems. A large part of our total defense and civil defense lies precisely with private companies. But it is, above all, a joint state and public responsibility.
Vänsterpartiet argues that the state and public society have a special responsibility to provide support and assistance to other operations so that the whole society shall be secure and safe. There is a great need for coordination, advice, support, information exchange, and exercises also in this area, so that not all operations, municipalities, or companies will have to develop their own solutions.
Protection of IT and information must be regarded as a core activity of all, both public and private operations, and be allocated the resources required for a core activity. This applies primarily to state agencies and other public organizations. Public cybersecurity must lead by example, which unfortunately it has not always done. Ultimately, it is the government's responsibility to ensure that the necessary conditions exist for the agencies to do this. It is of the utmost importance that cybersecurity is not outsourced but is truly regarded as a part of the core activity.
It is very good that the government recently announced that cyber will become a part of the civil obligation. It means that we can strengthen the direct and acute cybersecurity during high alert by calling up persons who have that type of knowledge. It is a great state responsibility to take on in the area. But the work must, of course, be done long before we end up in high alert.
Mr. Speaker! The large-scale privatizations and sell-offs of public activities in recent years have resulted in the public sector no longer having full control over socially important activities. This is a major problem. We see, among other things, how Chinese companies with strong links to the Chinese state invest strategically in, and take over, socially important infrastructure in other countries.
Vänsterpartiet argues that this development must be broken and that major changes must be made. We believe that it is in the citizens' interest that activities and infrastructure that are important for society's development are owned jointly by the citizens, through the state, the regions or the municipalities. This applies, for example, to the expansion of the 5G infrastructure.
Gulan Avci (L)
Mr. Speaker! Society's resilience is no longer determined solely by military capability. Today, conflicts are also directed against our modern society – against our digital systems, our authorities, our companies, and our infrastructure. These are attacks that often occur in silence, but whose consequences are just as devastating as if someone had smashed our physical infrastructure.
We see how attackers try to paralyze operations that form the foundation of our society. Today, water supply, healthcare, energy systems, and transport must withstand pressures that, just a few years ago, would have been perceived as completely unthinkable.
In a time when digital attacks can become system-threatening, Sweden needs stronger protection than we have today. The new cybersecurity law is therefore not just a technical adjustment or an adaptation to EU rules. It is absolutely crucial for strengthening Sweden's total defense.
For the Liberals, cybersecurity is also a matter of safeguarding the very structure of society. A free country must not only have military muscles but must also be able to deliver welfare, the rule of law, and security in everyday life. It is a prerequisite for people to be able to live free and independent lives in a free society.
Mr. Speaker! This concerns, among other things, the school. We Liberals want to build a world-class school that both levels the playing field and secures Sweden's future as a strong knowledge nation. This, however, requires that the systems behind the school function – that students' tasks are protected and that digital services are safe to use. A modern school cannot stand or fall on lacking cybersecurity.
The year 2025 seems to be becoming a bleak but clear example of how vulnerable our digital ecosystem is. Unfortunately, we have seen concrete cases where children and students have been directly affected by cyberattacks.
In August, the system supplier Miljödata was subjected to a massive ransomware attack. The company provides IT systems to approximately two hundred municipalities and regions. The attack knocked out personnel systems, hindered municipal operations, and risks having exposed sensitive information about municipal employees, students, and former employees.
It is difficult to imagine a clearer illustration of how a single attack against a central supplier can have enormous ripple effects in large parts of the public sector. This is the new reality and a clear signal of how vulnerable we are when central nodes in our digital infrastructure are hit.
Mr. Speaker! Cyberattacks are becoming increasingly sophisticated, and the consequences are becoming increasingly serious. The technological developments within artificial intelligence and quantum computers will fundamentally change the threat landscape. What we are facing is not only more attacks, but the attacks are also becoming much faster, more advanced, and significantly harder to detect than before.
The attacks come from criminal networks and from state-supported groups, actors who want to destabilize and undermine trust in our social fabric.
When it comes to Russia, we know that their view of us is that the conflict is already ongoing on all arenas except the openly military – economically, psychologically, informationally, and in the digital domain. Therefore, Sweden must plug the holes and build a resilience that holds both technically, organizationally, and legally.
Mr. Speaker! The law we are now deciding on does all of this. It sets clear and high requirements for security measures. It introduces rapid and structured incident reporting. It places a direct responsibility on the management in both the private and public sectors, a responsibility that cannot be delegated away. It means that our authorities get better tools to act when systems fail. It also introduces sanction possibilities that are both proportionate and deterrent.
Cybersecurity is today one of the most important components for a free, open and successful Sweden. It is about protecting our society, our democracy and our citizens. It is further about our ability to withstand those who want to destabilize, divide or harm us. The law makes Sweden safer; it strengthens our total defense, and it strengthens our democracy.
Mr. Speaker! Before I move to approve the proposal in the committee report, I would like to address the Speaker and wish the Speaker, the Speaker's Presidium, and all the staff in the house of democracy, who every day facilitate our work in the Riksdag, a very Merry Christmas as it approaches. I also, of course, want to address my colleagues in the Committee on Defence and also wish you a very wonderful Christmas. Then we shall see each other on the barricades, rested and with a fighting spirit.
Mr. Speaker! I wish to approve the proposal in the report and reject all reservations.
Mikael Larsson (C)
Mr. Speaker! We are subjected to attacks in the cyber domain daily, and while we stand here and debate, someone, some company, or some organization is being targeted. It is a new reality that we need to prepare well for.
Centerpartiet welcomes that the government has submitted a proposal for a new cybersecurity law. Even though the law is long-awaited, Centerpartiet wishes to submit a number of points. Centerpartiet calls for more clarity regarding management's responsibility to ensure that the cybersecurity in an operation meets the law's requirements. According to the NIS 2 Directive, one of the reasons for the law, management within individual operations would be given personal responsibility for violations of the requirements for security measures. This is missing in the cybersecurity law and has in practice been replaced by a requirement that management shall be trained.
This change entails significantly reduced requirements for the management in designated and critical organizations for society. Clarity and responsibility are essential.
Mr. Speaker! Several referral bodies have pointed out deficiencies in the proposed law regarding which companies or activities will actually be affected. For many actors, the new law may clearly cover part of the operations, while other parts are not relevant. It should be clarified how the law is to be interpreted and whether it is only those parts of the operations that affect security in relevant services that are to be covered. Today's lack of clarity can create major problems for smaller companies, for example within the green industries, which LRF has been careful to point out.
The government's changes in the cyber area do not create optimal conditions for strengthening the resilience of Swedish companies and smaller organizations. The Center Party believes that the government should return with clarifications on these issues to avoid unreasonable demands on smaller companies and organizations.
In the government's proposal for a cybersecurity law, there is a possibility to impose sanction fees for violations. According to the proposal, the sanction fee can be determined to a maximum of 10 million euro for companies and 10 million kronor for 20 public organizations. It is a significant difference in the fine amount which, together with the lack of clarity regarding when sanctions can become applicable, creates a risk of unreasonable differences between different types of organizations.
Centerpartiet considers that the design of the sanction fees should be reviewed to ensure that they are reasonable, proportionate and predictable, especially for the smaller operations. Centerpartiet also considers that the law misses to harmonize the size of the sanction fees between the Cybersecurity Act and the Security Protection Act, which can create unequal treatment and uncertainty. Centerpartiet further considers that the government should return to the Riksdag with proposals in this direction.
Mr. Speaker! It should further be clarified which authorities are responsible for the supervision and enforcement of the Cybersecurity Act and the Security Protection Act. Furthermore, coordination between the two regulatory frameworks should be ensured to avoid multiple authorities having overlapping supervision and that the same type of violation leads to different sanctions depending on which regulatory framework it is handled under. The Government must also clarify the authorities' responsibilities through requirements in regulatory letters and in instructions to the authorities.
A majority of Sweden's companies point out that they need increased support and information from authorities to create the high level of cybersecurity we all want to see. This law is no exception and risks contributing to increased uncertainty. A nationally coordinated supervision model was needed where roles and responsibilities are clarified. Centerpartiet therefore considers that a national coordination mechanism for supervision and knowledge sharing should be introduced, so that if one authority has exercised supervision over an operation, other supervisory authorities can also take part of it.
Funding and support for smaller actors who have not previously been covered by similar legislation is needed if it is to be possible to comply with the law in time. Alternatively, the Center Party believes there is a need for a phased implementation of the law so that more time is given to those organizations that do not have such large resources and competence in the area. This is particularly relevant for smaller companies and organizations.
In conclusion, Mr. Speaker, I would like to move for the approval of the Center Party's reservation, number 2. I would also like to wish the Speaker, the members and substitutes of the Committee on Defence, and the Committee on Defence's secretariat a very Merry Christmas and a Happy New Year.
Ulf Holm (MP)
Mr. Speaker! In 2022, the EU adopted a directive on measures for a high common level of cybersecurity within the EU, the so-called NIS 2 directive. As a result of this, among other things, the government has proposed that a new cybersecurity law should be introduced in Sweden.
We from Miljöpartiet welcome this proposal from the government in all respects as an important step to strengthen resilience against cyber threats. In a time of increased security policy tensions where hybrid threats, for example cyberattacks, sabotage and influence operations, are part of everyday life, a strong systematic cybersecurity effort is absolutely crucial. It represents a major threat to Sweden with all these countless cyberattacks that hit our IT environment every day. They hit banks, hospitals and various companies, and they affect our everyday lives more and more in all respects. It also means that the work must become more systematic and more integrated.
The new law means that all public and private operators within certain designated sectors shall take measures to protect their network and information systems and report significant incidents.
The government has itself noted that these new rules will cost money. A large number of referral bodies have pointed out that today's implementation risks becoming very costly, especially for municipalities and regions that are already in a financially tight position today. Therefore, we from Miljöpartiet want to emphasize our concern regarding the financing of the new law. Even though the government has signaled increased general state grants for next year to, among other things, implement the law, it is uncertain whether these funds will be sufficient for municipalities and regions, especially considering the many other requirements imposed on the sector in the expansion of the total defense. This is worrying.
Mr. Speaker! Municipalities and regions are central actors in civil defense. It is therefore unreasonable that the state does not simultaneously ensure that they have the economic conditions to secure welfare and fulfill the tasks that accompany the expansion of total defense. Miljöpartiet therefore considers that the government should return with an in-depth analysis of the economic consequences for the public sector.
Mr. Speaker! The second point I want to raise in this debate concerns several referral bodies' criticism regarding which companies or activities will actually be affected. This lack of clarity can create major problems for, for example, smaller companies and organizations. It does not create the optimal conditions for strengthening resilience. Miljöpartiet therefore has a joint reservation on this issue with C and V, number 3 in the report.
Mr. Speaker! I naturally stand behind all of the Green Party's motions, but for the sake of time, I only move for approval of reservation 1 under point 2.
The deliberation was hereby concluded.
Source: The Swedish Parliament. The speeches come from the open data of the Riksdag, translated into English by AI, which may contain errors.