Kammarkoll

Search everything said in the debates of the Swedish Riksdag

← To the search

National strategy for cybersecurity 2025-2029

12 June 2025 · 8 speeches · S, C, M, MP

Translated from Swedish by AI; the translation may contain errors. The Swedish text is the original.

Summary AI, written in advance

The debate concerns the national strategy for cybersecurity 2025–2029. S criticizes the strategy for being unclear with unmeasurable goals and unclear distribution of responsibility 1. C thanks for the strategy but argues that more is needed, criticizes FRA's sole responsibility 2 and opposes backdoors in encrypted services as it creates vulnerabilities 2. C wants end-to-end encrypted services without backdoors 2. M wants to approve the defense committee's proposal and emphasizes systematic work 3. M argues that the government has not decided on backdoors but is preparing the issue 4 and that end-to-end encryption is too complex for a simple yes or no 5. MP wants to increase cybersecurity through resources and practical action 6. MP wants to strengthen the psychological defense against disinformation 6 and spread competence within both public and private operations 6.

Written by AI in advance and may contain errors. The numbers lead to the speech a statement builds on; check against the text below.

Markus Selin (S)

Madam Speaker! Over two years ago, the Swedish National Audit Office wrote an audit report on the governance of society's information and cyber security. Two of the main messages to the government and to us in the Riksdag were 1) that the work must become even more strategic and 2) that unified governance must be ensured, with a clear distribution of responsibilities.

Madam Speaker! Stay with me now, for I shall attempt to depict the SD-supported M-KD-L government's work with our cybersecurity over the last two years.

Minister for Digitalisation Slottner, Christian Democrat, released his own digitalisation strategy two weeks ago. Minister for Foreign Affairs Malmer Stenergard, Moderate, released his own cyber strategy for foreign relations six months ago. Minister for Defence Jonson, Moderate, has his own cyber strategy concerning satellite communication. And finally came – we are debating it today – the updated national strategy for cybersecurity, which has the Minister for Civil Defence, Bohlin, Moderate, as the sender.

It is clear that the Minister for Education from the Liberals is to cut the ribbon when a new cyber campus is opened and may also get to write an op-ed about cyber together with other ministers. But we do not know if and when Justice Minister Gunnar Strömmer, M, can be expected to handle cyber issues. He is supposed to, however, if there is a clear connection to terrorism, which is also stated in Bohlins strategy.

The Tidö parties have also appointed a special envoy for international cyber issues with the title ambassador, which is interesting in itself as the digital and the internet do not relate to land borders at all.

To this end, the government has a national security strategy intended to capture conceivable or diffuse threats, including hybrid threats, the digital and cyber, which is a sub-area. It is said that the new role as national security advisor includes responsibility for the follow-up of precisely this security strategy on the government's mandate.

Madam Speaker! It may seem tragicomic, but when we debated the National Audit Office's audit report on the management of society's information and cybersecurity here in the Riksdag, the SD-supported MKD-L government pointed out in its communication 2023/24:26 that – listen! – the establishment of a national security advisor would provide good conditions to achieve unified management and effective forms for just the cybersecurity issues.

Now we all know how it went: a disaster. The first national security advisor was Prime Minister Ulf Kristersson's childhood friend, as well as brother to the Moderaternas party secretary, and was directly appointed by the Prime Minister. That security advisor had to resign after a series of security mistakes.

Take two: The second recruited national security advisor took office at lunchtime on a Thursday in May and resigned at midnight, after twelve hours. It is said that there is six-related material circulating somewhere.

The role is now vacant again, but we still do not know how this connects to the next cyber crisis. On the government's website, it states that it is nevertheless the Prime Minister's State Secretary who shall lead the crisis work.

At the same time, despite the fact that we live in an uncertain world, it is remarkably quiet from the government regarding how and when cyber and the digital could be used for influence operations, misleading digital information and communication, and the spread of disinformation – this despite the fact that the strategy we are debating today has been given the name A new era of cybersecurity and that we live in a time with artificial intelligence that can do even more, even faster, and even more sophisticatedly.

A significant dimension within cyber warfare is often described as when information is gathered, spread, and reshaped, often with political motives. The phenomenon, however, should be said, is mentioned in Foreign Minister Malmer Stenergård's cyber strategy for foreign relations. Minister for Culture Liljestrand, M, who also has a broader responsibility for democracy issues in the government, said in the autumn on SVT that she would very much like to stop anonymous troll accounts and does not rule out legislation. That would be completely correct, and it is welcome from our side. But otherwise, it is very quiet about this.

The connection to psychological defense is completely missing in Bohlin's strategy, which we are now debating. It is probably no wild guess, but the silence from Moderates, Christian Democrats, and Liberals may have to do with TV4's investigation of the Sweden Democrats' anonymous accounts on social media last summer. As you know, Kalla fakta was able to link 23 anonymous accounts to SD's communications department, a troll factory.

Madam Speaker! In the large scale, Sweden stands out negatively regarding cyberattacks. And Check Point Research recently showed that cyberattacks in Sweden during the first quarter of this year increased by 75 percent compared to the first quarter of last year. Right now, as we speak, SVT is being subjected to a massive attack.

Extensive investments need to continue to be made in Swedish cybersecurity. We Social Democrats, of course, welcome an increase in ambition within the area. The then Social Democrat-led government actually submitted Sweden's first national strategy for cybersecurity to the Riksdag on 22 June 2017.

We understand that strategies and methods of work must also be updated, but we Social Democrats nevertheless view the updated strategy with skepticism, where six areas have been renamed and become three. It is quite similar. Let me be clear: We Social Democrats are very skeptical that a stacking of different strategies would make the whole more strategic or more unified. Added to this is a growing lack of clarity regarding the distribution of responsibility among different ministers and departments and the appointment of different roles.

An updated or new cyber strategy should also have been in place before the bickering over personnel appointments began. Ultimately, this is about our, Sweden's, security. The word "cyber" must not be tossed around just because it sounds cool, hip, and modern today. It is serious.

In conclusion, I also want to be somewhat more detailed. To the cybersecurity strategy that we are debating today, there is an appendix designated Action Plan. During the press conference on March 20, we could hear Minister Bohlin, M, say that "this is not a strategy that contains vagueness and immeasurable goals." After a look at the appendix, I can say that it is remarkable that more than half of the seventy-odd activities listed among the goals are ongoing "until further notice." It is, therefore, such things that would have been done anyway and such things that are ongoing in any case.

Anyone with an interest in planning or project management can see that the whole thing is very fluffy – or to borrow the Moderate Minister's own words: "fluff and immeasurable goals".

In summary, we Social Democrats intend to closely monitor the government. We will, of course, continue our work. We will return with more concrete proposals to the Riksdag in other contexts and are submitting a special statement today.

(Applause)

The speech at riksdagen.se, in Swedish (opens in a new tab)

Niels Paarup-Petersen (C)

Madam Speaker! I would like to begin by moving for the approval of reservation 2.

Today we are going to discuss how Sweden can prevent, detect and manage digital attacks on what is particularly important to us. But I want to start by leaving the digital for that which is very down-to-earth.

A person who with passion and commitment has tried to precisely prevent, detect and manage attacks on the most important thing we have in the country, namely Swedish democracy, is Ulrica Schenström. Yesterday she left us. Many in this chamber have lost a person who has contributed to their understanding of the world and to their place in the politics as it looks today. Therefore, I want to begin with a thank you to Ulrica for everything.

With this said, I want to continue with the discussion of the report we have before us today. First and foremost, I want to thank the government for having developed a national strategy. It is good. It was needed. Much more was needed, one could also say.

I can honestly say that I find it somewhat remarkable that the Center Party is the only party that has felt there are enough challenges with this report for one to actually express reservations.

Sweden is under constant attack, as it looks today. Every week Swish, Bank-id or SVT is down. Hospitals and Försäkringskassan are down. Norrmejerier has been down. Elen has been down, just like the Riksdag. We are at war, we would have said if it were in the physical world.

We allow completely crucial services to be down every single week. It is actually a scandal. We have not done enough together here in the chamber. But, as said, we are the only party that at the current moment has a clear cyber policy beyond what the government has presented. We do have some views.

Madam Speaker! What then are the major challenges? First and foremost, the entire responsibility for this has been given to FRA. It is a challenge to give the responsibility for the entire society at large to increase its capacity – which requires an enormous amount of cooperation, a lot of communication, a lot of sharing of also difficult communication and things that perhaps are not so open – to Sweden's most secret agency. It is a challenge. Many, also within the more secret world, are very worried about this.

In the USA, power over this area was given to the NSA, which is the most secret agency in the USA. Then it was taken away from the NSA again, because it didn't work, because they could not communicate. Their entire culture is built on keeping quiet, and now they were supposed to share. It is a challenge that is difficult.

We have repeatedly highlighted this to the government, but every single time we get the answer that it will probably work itself out. But nothing works itself out if one does not act to get it resolved. This is an enormous cultural challenge for the agency that is perhaps best in the world at keeping quiet.

FRA is fantastic. All other countries use our capabilities when it comes to cable monitoring etcetera. But FRA tells nothing. No one finds out what is happening there except those who one wants to know it. That agency should now spread knowledge broadly in society, to small businesses and so on so that they can increase their resilience. It is difficult, because then the agency shall have contact with the whole of society.

Competitiveness, Madam Speaker, is defensive power. If we do not manage to build a society that actually functions all the way around and that stands firm, where we continue to achieve growth because, for example, our companies stand firm, we have no strong defensive power. It is a huge challenge. The companies, of course, have a different logic than the defense.

I can also give another example. I have understood that it is a small challenge sometimes when the defense sends communication to some other actors around the world. That is done with the entire secret apparatus, and then the others send back with Signal, because that works. But we have a structure in all of this that is incredibly heavy and is based on the fact that everything must be protected and be secret. But when we then simultaneously want to increase communication with many other parties, it becomes a big challenge.

Here we need to do more to make it easier to do the right thing and easier to get answers from the authorities. How Sweden's most secret and most closed agency is to succeed in creating the world's best and most open cooperation is still up in the air, and the government still has no answer on how it is actually to be done. It is a challenge.

Madam Speaker! Then there is this matter of backdoors in our communication apps and so on. According to the strategy, which we are all going to discuss here, it is absolutely crucial that we have secure communication in society. In a crisis situation, very many people are going to communicate with each other. It is municipalities and companies – it could be telecom and all sorts of things – that are going to communicate for the whole thing to function. Then one must have secure communication channels that the enemy must not have access to.

But the government wants to ban this. They do not want to allow, for example, Signal in the future, which Ukraine uses all the time.

The Center Party has long been opposed to the bill on what is called chat control, which came from the Social Democrats' commissioner Ylva Johansson from the beginning and which implies that digital backdoors should be installed in all encrypted communication services, for example Signal but also WhatsApp and iMessage on iPhone.

Fortunately, chat control has become stuck in the EU's legislative wheels. Poland, which is now the presidency, realizes that it is not sensible. They have stopped it, at least for now. We will see what happens when Denmark takes over.

But now the government is presenting a bill on the same thing – that there should be backdoors in all our communication apps. One could say: Yes, but is it that dangerous if the police are constantly able to access what we write?

First and foremost, we are of the fundamental view that the police do not have the right, by definition, to see everything that I or anyone else in society does. Specific conditions must actually be required in order to be able to do that. No one else has the right to it either. I think that is a good principle.

But with the government's proposal, the communication that we, I, Swedish authorities and Swedish companies want to keep secret can become accessible to third parties with technical expertise. I can guarantee that China, Russia, Iran etcetera have the technical expertise for this. It has turned out to be so. When the USA introduced similar legislation, China, for example, gained access to the logs from Trump's phones – it also concerned Kamala Harris and JD Vance. One can imagine that has some value. But it is that type of legislation that the government wants.

That is why the Armed Forces and FRA are clear about the importance of access to the end-to-end encrypted communication services without backdoors. They are very clear. The Armed Forces themselves write in their response to the government's proposal that the requirement for backdoors will not be able to be met. I can quote: without introducing vulnerabilities or backdoors that could be exploited by a third party.

A third party can be criminals or countries that do not want Sweden well, Madam Speaker.

So this is what the government wants to introduce.

The Armed Forces have also stated that the intelligence threat against the Armed Forces is high, and wiretapping of telephone calls and messages is, of course, a known method. Therefore, all employees, when it is not super-duper secret, shall use Signal – which the government wants to have backdoors, so that China, Russia etc. can access this.

It is also the case that Sweden's national cybersecurity center urges us all to use Signal for our own communications that are somewhat private.

We in the Center Party, just like the Armed Forces, Madam Speaker, want Swedish citizens, authorities, companies, etcetera to have access to end-to-end encrypted communication services without installed backdoors because it is secure. It is a must for Sweden's security, as the defense itself states.

Access to secure communication is also crucial for journalists, who are a challenged group nowadays, for whistleblowers, for opposition politicians, for crime victims and for other vulnerable groups. For many in other countries, it is extremely crucial. But the government wants to stop it here. Therefore, we ask time and again whether the government will change its mind and actually listen to the Armed Forces or if the government will continue to work to undermine Sweden's security by demanding that we install backdoors in our secure communication apps.

There is much more to say in this area, but my speaking time is up.

Thank you to the government for having developed this! But if we are to do it properly, more needs to be done. I hope that we can cooperate also in the future.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Camilla Brunsberg (M)

Madam Speaker! I would like to begin by moving to approve the Defense Committee's proposal for a decision.

Today we are debating the government's communication regarding the national strategy for cybersecurity. It is a strategic guidance in a time where the threats and attacks against our country have become increasingly complex and cross-border. And they have significantly increased in both number and strength in recent years.

Cybersecurity is no longer just about technology. It is about trust, about the security of our democracy, and about being able to protect the Swedish society's nervous system – power grids, water supply, hospitals, payments and communication, things that we often take for granted until one day they stop functioning.

This strategy is built on three pillars, which I intended to mention: systematic and effective cybersecurity work, developed knowledge and competence, and the ability to handle cybersecurity incidents.

This strategy aims to enable the necessary relocations to be carried out and to address the threats and vulnerabilities that exist. The government's and our vision is clear: a resilient Sweden, where society-critical activities function even during serious crises or cyberattacks.

And it was needed. We see how the cyber threats and attacks against Sweden are increasing – from foreign powers, from organized crime, and from ideologically driven cyber activists. It is about overload attacks, which we have seen on a large scale this week, about technology theft, about ransomware attacks, and about influence on the public debate.

In the security policy situation we find ourselves in right now, cybersecurity is a strongly integrated part of the total defense.

I would like to take the opportunity to highlight how this strategy also matters locally. In Blekinge, where I am active myself, there are several key actors within cybersecurity and defense. Karlskrona is the hub for our Swedish Navy. The air wing is also located here. We have Blekinge Institute of Technology and a business sector that actively collaborates in total defense initiatives.

This makes Blekinge a natural location for high-level expertise within the field of cybersecurity. There are also good conditions here to build up exactly that research and innovation that the strategy highlights as crucial. Blekinge Institute of Technology already conducts research in cybersecurity and systems technology today, and with the government's investment in Cybercampus Sweden, this type of regional expertise can take an even clearer role.

It is this way that we strengthen national security and regional development.

The strategy also clearly points out the need and the importance of strengthening civil defense. We know that our enemies seek our weaknesses, not only in the military systems but also in municipal IT operations, in school platforms, in water treatment plants and in healthcare systems. Therefore, it is important that the entire society is involved.

Government agencies, municipalities and regions but also companies – large, small and medium-sized – often have much to protect but fewer resources to be able to do so. The strategy contains goals to strengthen the support for these companies and organizations through education, technical support and guidance.

We also need people and competence. The strategy focuses on that. We need to increase public awareness. We need to strengthen education – from primary school to university. We must be able to offer career changes and trainee programs and invest in research and innovation. We have world-leading companies and strong research groups, but we need more interdisciplinary work, more collaboration and long-term resources.

The government is currently doing this through the research bill and through support for EU funding. It is an investment in both competitiveness and security.

A special initiative concerns the national cybersecurity center, which has now received a clear mandate. It is the right step to take, as we need a strong hub that can coordinate, analyze, and provide guidance during incidents.

Cybersecurity is one of the major issues of freedom in our time, for we see to what extent this affects our everyday lives. One must be able to trust society's services. It is about protecting our infrastructure and about safeguarding our privacy and our self-determination.

With this strategy, our government shows that it takes the issue most seriously. We strengthen the protection of our country – digitally, civilly, and militarily. We create security, and we create resilience. And we do it together – from Blekinge to the Riksdag, from the classroom to the server hall, and from small businesses to the core of the total defense.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Niels Paarup-Petersen (C)

Madam Speaker! As I noted before, it is very good that we have produced a strategy, an updated one. But there are certain challenges. One of them concerns precisely this fact that it is very clear in the strategy that one must have secure communication broadly in society and that at the same time a work is ongoing by the government to undermine the only secure communications that we have, those that both NCSC, that is National Cyber Security Centre, and the Defence say must exist and must remain.

Therefore, I want to ask the member: How do the government and the Moderaterna think about the fact that the basic services required for us to be able to communicate securely without China, Russia, Iran or criminals gaining access to our communication are being erased from Sweden due to the government's other policies?

The speech at riksdagen.se, in Swedish (opens in a new tab)

Camilla Brunsberg (M)

Madam Speaker! Thank you, Member, for appreciating our national cybersecurity strategy! We have longed for it together, and it feels reassuring that it is also appreciated by the opposition. I believe that it will contribute to a very good redundancy in our society.

The issue itself regarding end-to-end encryption is very complex and pressing. However, it is not part of the cybersecurity strategy but an ongoing work that is now being handled by the government and prepared in the Ministry of Justice. Just as the member says, there is a legislative proposal that referral bodies are now analyzing. It is not true, however, that the government has decided to introduce the possibility of building in backdoors in end-to-end encryption.

We are, of course, analyzing the Council on Legislation's referral and the consultation responses carefully, as it is a complex issue. On one hand, we must protect vulnerable children from sexual abuse on the internet, and on the other hand, we must simultaneously find technical and legal solutions that ensure we can still have secure communication for the country's security.

I share the member's concern and fears regarding removing the possibility of secure communication, and I believe everyone in this chamber agrees that we need to have secure communication. However, it is not as the member says that decisions have been made that it should be obvious to be able to build in backdoors. The matter is currently being prepared in the Government Offices.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Niels Paarup-Petersen (C)

Madam Speaker! We have somewhat different views on this. The government has nevertheless presented a proposal that is out for consultation and has thus indicated that it thinks it is right. One has also been in favor of chat control, which is the same thing. If one has both been in favor of it in the EU and sent a proposal for consultation, I think it feels a bit strange to say that one is not in favor. It has not been decided, but the government has thus on several different occasions said that it supports the proposal for a backdoor, and that would in normal cases indicate that the government is in favor.

But we can make it very simple for the Moderates and Camilla Brunsberg, Madam Speaker: Can fully end-to-end encrypted services be allowed to remain in Sweden? Are the Moderates for or against?

The speech at riksdagen.se, in Swedish (opens in a new tab)

Camilla Brunsberg (M)

Madam Speaker! Now I think the member is making it a bit easy for themselves. The question of a guaranteed end-to-end encryption in all situations and with all technologies is too complex for that.

The government has not presented any sharp legislative proposal, but they are preparing the issue, an issue that I believe the member and I and everyone here in the chamber agree is extremely complex and serious. It is necessary to find technical and legal solutions that both guarantee personal privacy and secure communication and that enable tools to find perpetrators who commit sexual abuse against children.

I therefore do not believe that the question can be answered with a simple yes or no. The question is being prepared by the Ministry of Justice, and I am convinced that we all take this complex issue most seriously. We need secure communication in Sweden in the future, but we also need to find legal and technical solutions to be able to protect children from sexual abuse.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Emma Berginger (MP)

Madam Speaker! Every day, many of us open our mobile phones and check the news, send messages to loved ones, chat with colleagues, and send an important email. We check the timetable for the bus and the train and beep when we board or go through the gate. We listen to podcasts and music and order something nice to wear. We Swish a sum to the class fund and use mobile BankID to check the balance on the account and set up some bills for payment. But what happens when it doesn't work? In the recent past, we have seen how various cyberattacks have affected everything from Swish and BankID to SVT's broadcasts. The disruptions have admittedly been temporary and the consequences still relatively limited.

But what happens if the disruptions become more extensive? What happens if the disruptions don't just mean that I have to pay my bills a day later or miss a news broadcast? It is not just our private lives that are dependent on digital systems. Everything from healthcare to the energy supply is, in today's society, heavily dependent on functioning digital systems.

Miljöpartiet believes that cybersecurity must be increased in all activities in society, both in the public sector and the private sector. We believe that Sweden needs to strengthen its ability to prevent and respond to cyberattacks. Therefore, it is good to have an updated national strategy for cybersecurity.

Miljöpartiet and Socialdemokraterna presented the first national strategy for society's information and cyber security in 2017. That strategy expressed the government's overall priorities and constituted a platform for Sweden's continued development work in the area. The strategy was intended to provide long-term perspective and efficiency in the work and raise awareness and knowledge in the whole of society.

The strategy from 2017 had six main areas. For each of these areas, the government set a number of objectives and directions for how the objectives should be reached. It was a good strategy, but we can simultaneously observe that time and development move forward and that much has happened since 2017. Not least, the security policy situation is completely different today. We have a large-scale war of aggression in Europe, and we see how different antagonistic great powers are prepared to use cyberattacks as part of their toolbox in a more extensive way. At the same time, there are also criminals driven by economic motives to carry out cyberattacks. Technological development, especially in the field of AI, is also moving forward rapidly and changing the conditions both for how attacks are carried out and for how we can create protection.

There are therefore great expectations that society should strengthen cybersecurity. But for a strategy from a government to become effective, it is required that the strategy be resourced and translated into practical action. Clear mandates and clear responsibility are also required. The government has chosen to present a number of different strategies that overlap with one another, and more are on the way. A strategy is, of course, a grateful communicative tool for a government, but within this important area, action is required.

In addition to what the strategy covers regarding technical cybersecurity, this area also touches upon what is conveyed in digital channels. We need to strengthen the psychological defense in society and build up resilience against disinformation and influence campaigns. This means, among other things, that we need to increase the population's ability to distinguish between reliable sources and sources that are not reliable. It is difficult today to know where a disinformation campaign originates from. It can be national and international actors behind it or individuals, political organizations, and organized crime. We all move in the same digital space, which leads to an ambiguity about who should handle the threat.

To address this, a large cooperation network between relevant authorities is required, but without us compromising personal integrity. We also need to strengthen media and information literacy, what we call MIK, in the population, which includes both text and image analysis. This is something that we from Miljöpartiet highlight in our party motion Strengthened preparedness and a more robust society, which has been treated in another report.

Miljöpartiet also considers that the EU should expand its cooperation in the area of cyber defense. The EU should continue to exert joint pressure on social media giants, for example, so that they do not allow disinformation to spread on their platforms.

In conclusion, Madam Speaker: Given the security policy situation, it is more important than ever that we strengthen our ability to meet and manage cyberattacks but also disinformation and influence campaigns. Such so-called hybrid attacks and attacks occur constantly. It is not a question of whether they will occur, but when and to what extent.

National Strategy for Cybersecurity 2025–2029

The knowledge and competence to meet the threats must be spread within both public and private activities, and also among private individuals. An updated strategy can be a good way to focus on the issues, but it is crucial how one intends to follow up the strategy with action and resources. We from Miljöpartiet intend to closely monitor the government's work.

(Applause)

The deliberation was hereby concluded.

(A decision was to be taken on 17 June.)

The speech at riksdagen.se, in Swedish (opens in a new tab)

Source: The Swedish Parliament. The speeches come from the open data of the Riksdag, translated into English by AI, which may contain errors.