Kammarkoll

Search everything said in the debates of the Swedish Riksdag

← To the search

The National Audit Office's report on the government's management of society's information and cyber security

24 January 2024 · 21 speeches · SD, S, M, V, KD, C, L, MP

Translated from Swedish by AI; the translation may contain errors. The Swedish text is the original.

Summary AI, written in advance

The debate concerns the Swedish National Audit Office's report on the government's management of information and cyber security. SD considers the previous government's management to be a failure 1 and that the current government is improving the situation through a special responsibility for civil defense 1. SD expresses confidence that the government is addressing deficiencies in cooperation 1 2 and argues that the previous government launched unclear projects. S argues that the distribution of responsibility is unclear and that the government lacks a clear strategy 3. S argues that they strengthened the defense during their time 3 but want to see a clarified strategy 3. M argues that they are making a new start and building up security through fast tracks. V proposes an IT inquiry commission 4. KD advocates for a specific agency for the main responsibility 5. C proposes an IT crime center 6. L argues that the previous government did not do its homework 7. MP wants agencies to develop a national strategy against disinformation 8.

Written by AI in advance and may contain errors. The numbers lead to the speech a statement builds on; check against the text below.

Speakers (21)
  1. Björn Söder (SD)
  2. Markus Selin (S)
  3. Björn Söder (SD)
  4. Markus Selin (S)
  5. Björn Söder (SD)
  6. Markus Selin (S)
  7. Björn Söder (SD)
  8. Markus Selin (S)
  9. Björn Söder (SD)
  10. Markus Selin (S)
  11. Camilla Brunsberg (M)
  12. Markus Selin (S)
  13. Camilla Brunsberg (M)
  14. Markus Selin (S)
  15. Camilla Brunsberg (M)
  16. Lotta Johnsson Fornarve (V)
  17. Mikael Oscarsson (KD)
  18. Mikael Larsson (C)
  19. Joar Forssell (L)
  20. Emma Berginger (MP)
  21. Sara-Lena Bjälkö (SD)

Björn Söder (SD)

Mr. Speaker! The National Audit Office's report on the government's management of society's information and cyber security focuses on the previous government's strategy for information and cyber security and covers the period 2017-2022.

In the report, it has been investigated how the government works to strengthen Sweden's information and cyber security. The Swedish National Audit Office has examined whether the national information and cyber security strategy, which was adopted in 2017, is effectively designed and whether the government has implemented the national information and cyber security strategy in an effective manner.

The need for information and cyber security is great today. At all levels of society, digitalization has broken through, and accordingly, the threats have also increased. In the information and cyber security strategy developed by the previous government, a number of objectives for the work are described.

The Swedish National Audit Office's report on the government's management of society's information and cyber security

But even six years after the strategy's introduction, there are still problems within all areas of the strategy. The National Audit Office's review of whether the government's work to strengthen our country's information and cyber security has been effective shows that is not the case. The National Audit Office states that the central deficiency is a lack of strategic trade-offs and priorities that focus the information and cyber security work.

It is further considered that the government has also not developed or implemented the national strategy for society's information and cyber security in accordance with international best practice. The National Audit Office also considers that the strategy lacks a clear vision, trackable objectives, and those responsible for implementing measures and allocating resources for the work.

Furthermore, the Swedish National Audit Office (Riksrevisionen) criticizes that the business sector was involved only to a limited extent both in the development of the strategy and in the establishment of the national cybersecurity center, which the previous government first established in 2020. Despite the government establishing a national center, and also interdepartmental working groups, to achieve better cohesion in the work, the Swedish National Audit Office can state that it has not led to an increased ability to prioritize efforts based on Sweden's collective needs in the field of information and cybersecurity. It has also not led to a long-term, strategic, holistic, and coherent governance of the area.

The barriers have, according to the Swedish National Audit Office, led to weak governance of the information and cybersecurity area from the government's side. The exchange of information, both within the public sector and between the public and private sectors, does not function effectively. The business community experiences a lack of interest from the authorities to receive information from them.

The current government agrees with the Swedish National Audit Office's assessment and considers the report to be a valuable basis in the work of developing a new information and cybersecurity strategy that is in line with the European Parliament's and the Council's directive on measures for a high common level of cybersecurity across the Union. The government also emphasizes the importance of support for and cooperation with state agencies and the business sector in the development of a new strategy. This is welcome.

Furthermore, the government is now undertaking a series of measures to address the extensive criticism that the National Audit Office directs towards the previous government's management of information and cyber security. Measures are also being undertaken to develop the national cyber security center and to strengthen the work with information and cyber security in general.

The Committee views the measures that the Government announces in its communication positively and, taken as a whole, sees no reason to take any further measures at this time.

I would like to, Mr. Speaker, move for approval of the committee's proposal in the report.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Markus Selin (S)

Mr. Speaker and Member Söder! The Sweden Democrats do not formally and technically sit in the government. But I, like so many others, have skimmed the Tidö Agreement, and it states, among other things, that all parties including the Sweden Democrats have "full and equal influence" over the conducted policy.

Mr. Speaker! We are under a cyberattack right now. Cyberattacks can have similar consequences as traditional, conventional warfare. Right now, the company Rusta is having problems. It also concerns Granngården, the cinema chain Filmstaden, the sports chain Stadium, Statens servicecenter, and 120 authorities. The system Primula is down. We in the Riksdag are also under attack.

I have a few questions for Member Söder. If we are to look at the present and the way forward here and now – does the Member think that the handling by the current government right now is sufficient? Do we know who the responsible minister is? Do we know who is leading the work here and now?

The speech at riksdagen.se, in Swedish (opens in a new tab)

Björn Söder (SD)

Mr. Speaker! Thank you, Member Selin, for the question! Now, the fact is that this comes in the wake of the previous government's handling of this issue in the area of information and cyber security. This is the result of the failure that the previous government was responsible for.

With the current government, we now have for the first time a minister with special responsibility for civil defense. The previous government did not think that was sufficient, or they did not think it was particularly prioritized. Now we have a minister who has responsibility for this.

The National Audit Office's report, which we are dealing with here and now, deals to a large extent with the previous government's handling of this issue.

From the government's side, a new strategy will now be developed. They will also ensure that the deficiencies raised by the Swedish National Audit Office are addressed. They will ensure that the contact between agencies and between agencies and the business sector is improved. They will ensure that a unified management and a clear distribution of responsibility are achieved. It is not just about cooperation but also about coordination in this area, and that is a big difference.

One will also review this center's mandate and ensure that it becomes more efficient. This regarding the national cybersecurity center, we highlighted for many years before the government finally acted and established one. It took a very long time.

I have full confidence that the government will handle what we are seeing now, because it is extremely serious. Just as the member points out, what we are now exposed to is extremely serious. It will have major consequences for the entire society. But I still want to say that this is actually a consequence of the previous government's deficient handling.

But, again, I have great confidence that the government will handle this in the best possible way. I also see that we finally have a minister who takes primary responsibility for this.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Markus Selin (S)

Mr. Speaker! As a Social Democrat, one is proud but never satisfied. In eight years in government, we did a lot for a strengthened total defense, and we increased the appropriations by 85 percent. We opened the Agency for Digital Governance. We opened the National Cybersecurity Centre, just as the member highlighted. We also opened the Agency for Psychological Defense and the Agency for Total Defense Analysis.

But I don't even think member Söder knows which minister has the responsibility here and now. Is it the Moderate Carl-Oskar Bohlin? Is it Defense Minister Pål Jonson, Moderate? Or is it Gunnar Strömmer, Moderate? He and the Ministry of Justice are supposed to handle cyber if it can be a terror threat. We have a major competence shortage in society when it comes to cyber and cybersecurity, and it is Education Minister Mats Persson, Liberal, who is supposed to handle it.

It is not enough with this. During the ongoing cyberattack, it is actually Erik Slottner, the Kristdemokrater, who is Sweden's Minister for Digitalization.

I do not believe, Mr. Speaker, that the member Söder from Sverigedemokraterna has any grounds to claim that it would be the new minister, the Moderate Carl-Oskar Bohlin, who is responsible. For I have asked questions. No one knows.

This is like a hot potato being tossed around in Agency Sweden and, ultimately, in the government. This is serious here and now. We are under a cyberattack, and it can have consequences just as great as conventional warfare.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Björn Söder (SD)

Mr. Speaker! Yes, it is quite right as the member points out that a number of different agencies were created in this area, even though it was a very belated action. The problem is that it doesn't matter if one creates a lot of agencies if those agencies cannot cooperate in a good way and coordinate with each other. That is what the Swedish National Audit Office points out in this report.

I think the member describes this in a good way, that it is very complex. It affects very many sectors in society. It also affects very many departments. This is also what has been criticized. The interdepartmental work has not functioned during the previous government. One has not had any good contact and structure.

Now we have another government in place where this issue is taken most seriously. I have full confidence that this will be handled in the best possible way and also ensure that the interdepartmental work and cooperation will function much better than it has done previously.

I have full confidence that this is being handled in the best possible way.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Markus Selin (S)

Mr. Speaker! We are currently debating cybersecurity, and here are the motions from members and parties as well as the Swedish National Audit Office's audit report Government's management of society's information and cybersecurity.

Let me begin with a classic quote: If you don't know where you are going, it doesn't matter which path you take.

It is the cat's answer to Alice in the book Alice in Wonderland, written by Lewis Carroll 1865.

Alice in Wonderland helps us put our finger on the most important message in the Swedish National Audit Office's 80-page audit report - or in the Swedish National Audit Office's own words: "The central deficiency is the lack of strategic trade-offs and priorities that direct the information and cybersecurity work."

With a high degree of tail-wagging, the Tidö government representatives in general, and actually the Moderates in particular, have spoken about the need for a strategic cyber policy.

After having sat in government for 15 months, we are still waiting for their unclearly promised strategy. We have received more uncertainties and vague roles. The latest offer is that the promised strategy will come in some one year, halfway through the mandate period.

Sweden is being hit by cyberattacks continuously, and we are under a major cyberattack right now. Cyber warfare is war in a gray zone, and it can have consequences just as serious as conventional warfare. Cyber warfare is complex. The line between external and internal security is blurred, and our enemies and antagonists exploit precisely those ambiguities and boundary issues that exist between agencies and administrations. Responses and countermeasures are hindered as are finding and understanding the villains and understanding the scope and ultimate intent of the cyberattack itself.

The distribution of responsibility in Sweden is however anything but clear regarding digitalization and cybersecurity, and it is actually heading in the wrong direction.

For example, it is now the Minister of Justice Gunnar Strömmer, M, and the Ministry of Justice that handle cyber issues if they can be linked to terrorism.

The Ministry of Defence now houses two ministers who are to handle cyber threats. It is the Moderate Pål Jonson and the Minister for Civil Defence, Carl-Oskar Bohlin, Moderate. But it is highly unclear which of the ministers does what and when and why.

Competence issues in the cyber area fall to Education Minister Mats Persson, Liberal, and the Ministry of Education.

Generally, however, the current Minister for Civil Affairs, Erik Slottner, Kristdemokraterna, is responsible for the government's general digitalization policy, and he is referred to as Sweden's Minister for Digitalization.

The lack of clarity, Mr. Speaker, does not only concern ministers. When we in the Committee on EU Affairs handle important EU documents and international work regarding artificial intelligence, these documents end up in the Ministry of Finance.

Our Minister of Defence also recently announced that Swedish intelligence activities are to be reviewed, and the word cyber is mentioned a handful of times. The special investigator became Carl Bildt, M. The result is expected to arrive in about a year. And Sweden is under a major cyber attack here and now.

The Tidö parties also recently appointed a special envoy for international cyber issues, placed at the Ministry for Foreign Affairs with the title of ambassador. Tobias Billström is the Minister for Foreign Affairs. He is Moderate and head of the Ministry for Foreign Affairs. The government has additionally promised another special strategy for cyber issues for foreign and security policy. It is, however, unclear when this strategy will be developed, and we are under a major cyber attack here and now, right now.

Parallel to all this, the general and overall crisis management is being fragmented even further in Sweden. Let me give some examples, Mr. Speaker.

The Government Offices coordinates the Government Offices' work with security. For coordination, there is also a national security council led by the Moderate Prime Minister Ulf Kristersson. A national security advisor has also recently been appointed and shall provide advice regarding today's "complex threat picture and risks". According to the government's website, however, it is the Prime Minister's State Secretary who leads the collective crisis management work.

In the Government Offices, there is also a special chief official and an office for crisis management. The chief official for crisis management also serves as the deputy for the national security advisor. In addition, there is the Crisis Management Council, which is a forum for information exchange between the Government Offices and agencies.

Mr. Speaker! We see now that it is highly unclear with the Tidöregeringen when, how, where, why and by whom exactly the cybersecurity shall be handled.

In government, we Social Democrats did a lot for a stronger defense and cyber policy. With a major restructuring of Sweden's total defense, where a long period of cuts was broken, many investments followed for a popularly anchored total defense. We shifted to the defense of Sweden by increasing the appropriations by 85 percent, and significant cooperation agreements were entered into with other countries. With a digitalization strategy, a strategy for information and cyber security followed simultaneously. We Social Democrats opened the National Cybersecurity Centre, the Agency for Digital Government, the Agency for Psychological Defence, and the Agency for Total Defence Analysis.

But as a social democrat, one is proud but never satisfied. Therefore, we social democrats want even more in the report that we are now debating, and we therefore have three reservations.

A reservation is about a clarified strategy and coordinated decision-making. We also want to consider a commission of inquiry.

Another reservation concerns the fact that we Social Democrats want to see cyber competence in Sweden strengthened.

A third reservation concerns our desire to secure the state's control over sensitive information that can be stored both in the cloud and on servers.

We Social Democrats, of course, stand behind all our three reservations, but for the sake of time, we move for approval only of the latter, reservation 8, which concerns the fact that the use of cloud services is a prerequisite for combat capability.

The word "cyber" must not, as it now appears, be tossed around just because it sounds hip, modern, and cool. The cyber strategy from the Social Democratic government is probably perfectly okay. That is how it seems, and the Tidö government proudly displays it on its website.

An updated or new cyber strategy, which the Tidö parties have promised, should have been in place before the maneuvering with various personnel appointments began. Instead, and if so, Sweden's 342 agencies and 1.2 million companies currently lack the promised strategy.

I do not know if it is fair to call this a Swiss cheese or a patchwork quilt. But if we continue on the path already taken, it will be like the cat's answer to Alice in Alice in Wonderland: If you don't know where you are going, it doesn't matter which way you take.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Björn Söder (SD)

Mr. Speaker! Member Selin thinks that the government is slow in producing a new strategy, 15 months after taking office. I want to remind Selin that it took three years for the previous government to produce a strategy and six years to establish a national center, even though it had been pointed out at times and again that it was needed. Perhaps a little humility should be shown.

What we are now seeing from the Social Democrats' side is a revisionism of history of a rarely seen magnitude, not only in this area but in all areas of society. It seems as if the Social Democrats have never governed this country but have been in eternal opposition. They are constantly coming with complaints.

But what we see happening today with all the cyberattacks, which Markus Selin raised in the previous exchange, is a consequence of the previous government's deficient work in the area. That can hardly be blamed on the current government. A little humility perhaps could therefore be requested.

On 27 April 2023, that is half a year after taking office, the government acted and tasked the Defence Signals Agency, the Swedish Civil Contingencies Agency, the Swedish Armed Forces and the Swedish Security Service to begin cooperating with the business sector within the framework of the national center - also something that the National Audit Office points out - because it, just as Selin said in his previous exchange when he listed various companies that are now subject to cyberattacks, is incredibly important that the business sector is engaged in this.

On the contrary, however, the business community has experienced that the authorities have shown a lack of interest. Then the question is: Why did the previous government not take action on the issue and involve the business community in this significant work? It includes the entire society, after all.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Markus Selin (S)

Mr. Speaker! I disregard attributions regarding historical revisionism and the like, and I have already begun to respond to Member Söder from the Sverigedemokraterna.

I am proud but never satisfied. We did not finish, but we were on a better path than the Tidöre government is.

I did not receive any answer to the question I asked in the previous exchange of remarks regarding whether Member Björn Söder from Sverigedemokraterna is satisfied or if he knows who is responsible here and now when we are under cyber attacks.

We did a great deal for a strengthened cyber policy during our eight years in government, but we did not finish. It would be absolutely futile and foolish to believe that anything will be finished. That is not why we are here.

To return to the promised strategy, we will probably receive a new, updated strategy in the middle of the mandate period. The Tidö government, where the Sweden Democrats are the largest ingredient, is to develop a new strategy. When will it be in place? What need is it to satisfy? What analysis has been made since one is out in the major morning newspapers writing debate articles about the fact that it is not just one but two new strategies? A cyber strategy with a focus on foreign policy has also been promised.

I do not know what kind of need it is. Somewhere, one must sit down and start thinking about why we need a new strategy. And then one can ask, Member Söder from Sverigedemokraterna: Why is our strategy still on the government's website? I do not understand it.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Björn Söder (SD)

Mr. Speaker! The member himself was involved in how extensive these cyberattacks were, also specifically against the private sector, but I do not perceive that I have received any answer to my question as to why the business community was not involved early in this.

I still do not understand how one can continue to blame the current government for a new strategy being developed halfway through the mandate period. It is, after all, much faster than the previous government's actions in this area. Again: Perhaps a little humility is needed.

There were very many deficiencies in the previous government's actions, which we see in the Swedish National Audit Office's report. The new strategy will, of course, plug those holes and ensure that this starts to work seriously and that it also aligns with the European Parliament's and the Council's directives on high common security, also something that the previous strategy falls short in.

I would like to see some humility from the Social Democrats. A lot was done, but it was a long starting distance. And now enormous deficiencies are being demonstrated in the report from the Swedish National Audit Office.

When it comes to who has the primary responsibility and how the government shall coordinate the work, that is a question that must be asked of those who reside in the departments. But I can see in the government's communication, which responds to the Swedish National Audit Office's report in a good way, that they will plug the holes that have existed regarding the interdepartmental deficiencies where the previous government did not take any measures. I have full confidence that they will resolve the issue in a good way. The government's communication also shows that they are tackling the work in a serious manner.

I would like to know, Member Selin, why the government did not involve the business community to a greater extent from the start, given that they are highly involved. Why does the business community experience such a lack of interest from the authorities to receive information from them? Most often, it is the business community that has higher competence in many areas than what exists in the public sector.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Markus Selin (S)

Mr. Speaker! We did a lot, but we did not finish. That is why we established the national cybersecurity center. We can discuss for a long time whether it arrived in time or late. But we launched it.

We launched the Agency for Digital Government in 2018 and the Agency for Psychological Defence in 2022, and the Agency for Total Defence Analysis was inaugurated on 1 January 2023. We introduced about thirty cooperation agreements with other countries, and we increased the defence appropriations by 85 percent.

The large Cybersecurity Investigation submitted its final report in the summer of 2021. With all due respect to the audit report from the Swedish National Audit Office, but we know - and I have seen many reports over the years - that the report is significantly more extensive than the report we are debating today. It was we Social Democrats when we were in government who commissioned the report. We always want more.

Given all the fuss with personal appointments, but I believe this government thinks it is a bit hip, modern and cool to scatter the word cyber around. I see that clearly.

We are now in a cyber attack. I have listed organizations and companies that are suffering in this now. As a Member of Parliament, I should be able to demand accountability, but I do not know who is responsible for this. Is it the Minister for Digitalization, Erik Slottner, Christian Democrat? Is it Persson, the Minister for Education? Is it Pål Jonson, the Minister for Defence, Moderate? Is it Carl-Oskar Bohlin, who holds the new role of Minister for Civil Defence, Moderate? Is it an ongoing terror threat? Then it is the Minister for Justice, Gunnar Strömmer, Moderate. It is to the highest degree unclear.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Camilla Brunsberg (M)

Mr. Speaker! I would like to begin by expressing my approval of the proposal in the committee's report.

Sweden is not only being attacked today in the cyber domain, but Sweden is attacked every day in the cyber domain. This is not news. A hybrid war is being waged against our country by state, private, anonymous actors and by foreign powers - precisely in the cyber domain.

It is extremely serious that one of the world's most digitized countries, which Sweden is, fell so far behind when it comes to cybersecurity during the two terms of the previous Social Democratic government. FRA could already six years ago demonstrate that approximately 10,000 attacks occurred every day against our country. This means that daily, several different actors work in different ways to crack our banking systems, our private data, and our security systems. The attacks have certainly increased in scale since then.

We also know that the full-scale invasion of Ukraine was preceded by heavy attacks in the cyber domain and that a large part of the warfare in Ukraine is taking place precisely in the cyber domain. The security situation has deteriorated significantly here.

Thanks to our new moderate-led government and the cooperation with the Tidö parties, a paradigm shift is underway in Sweden. We are building up the civil defense with full force, and it is moving forward, Mr. Speaker. In the work of building up the civil defense, it is always the weakest link that defines the chain. With the stinging criticism that the Swedish National Audit Office is now presenting against the former S-led government, I am both proud and relieved that our government, ever since it took office, has with full force made a course correction in the work with cybersecurity. The truth is that even when we sat in opposition, we pushed for the security work to be strengthened in the cyber domain. It has been completely necessary for our newly appointed government to make a course correction. The protection must, like the civil defense, be dimensioned against total war, and it is being built up right now.

What we are to debate in the chamber today is the audit from the Swedish National Audit Office, which was carried out on behalf of the previous Social Democratic government during the previous parliamentary term. It is an audit of the previous S-government's governance, or rather inability to govern, of cybersecurity.

The review shows that the S government's work to strengthen information and cyber security in Sweden was not effective. This is due partly to deficiencies in the national information and cyber security strategy, and partly to the fact that the government's governance is weak and fragmented.

This is, therefore, from a completely impartial review conducted by the Swedish National Audit Office regarding Sweden's past cybersecurity policy during the previous mandate of the previous S-government. It is essentially stated that all cybersecurity work was either far too slow, poorly executed, or far too weak. We can point to a few reasons why this has crystallized.

The S-government, as has been said earlier in the rostrum, was last in the EU to produce a cybersecurity strategy and was last in the Nordic countries with a national cybersecurity center. The Social Democratic government essentially short-circuited the business community's opportunities to cooperate with the national cybersecurity center. It is because of the Social Democrats' previous sluggishness and reluctance to take measures that so little has happened with civil defense and cybersecurity during the recent years. It is therefore that we are taking measures with force.

Why is cybersecurity then so important for us Moderates and for the coalition partners in Tidö?

We can begin by stating that the cyber domain of several actors is considered the fifth domain of warfare and has been defined as being as important for military operations as land, air, sea, and space. It is also an area that encompasses everything from information, communication, and infrastructure to data transmitted via many different systems, that is to say, everything in our society is built on digitalization and cybersecurity.

This means that a dimensioned cyber defense against total war is the prerequisite for our society to function fully and have the redundancy that we need. There is a lack of concrete examples that show the vulnerability and the risk of a cybersecurity that is not fully functional.

I can, for example, mention the hacking and extortion of Kalix municipality, Coops' cash failure, attacks from Notpetya and attacks against Solarwinds, which have forcefully knocked out infrastructure, energy systems, defense branches and global surveillance systems. In recent days, reports are being made of yet another attack. But these attacks have been ongoing for several years and have been many both day and night, and it cannot be news for the members of the Riksdag.

We see all possible forms of cyber tools being used against Ukraine to cause as much destruction as possible. Hacking of precisely energy systems and banking systems can cause immense damage to the entire society and for the individual.

An expanded cyber defense and increased cybersecurity in both the public and private sectors is one of the most important areas that we are now building up in Sweden. Therefore, Mr. Speaker, we are putting such great effort and focus on building up cybersecurity in our entire country.

Before I proceed to specifically account for which measures we have taken, I would like to point out another serious deficiency. The reason I think it is important that we address the Swedish National Audit Office's criticism and the deficiencies that exist is that we must be able to learn from history, because that is how we do things better.

Our fantastic business sector, where technical innovations and knowledge flourish, developing our society and maintaining our welfare, was left completely in the dark under the Social Democrats' government. When there was, for once, an obvious opportunity for—and a necessity of—cooperation between the state and companies, the Social Democrats did not act. They were last in the Nordics with a cybersecurity center. They also failed in the task of cooperating with the business sector. Instead, a handful of people at various agency levels sat and tried to tinker with this issue.

When we Moderates took over government power, there were serious deficiencies. We know that the work ahead of us is great and needs to be done quickly, as we stand in a security-politically threatening time where speed must be prioritized over the perfect solution. That is why we are working with several different fast-tracks.

Mr. Speaker! I will be over the time limit. This is an important and current issue, so I want to point that out already now.

When we now forcefully activate the civil obligation, we have prioritized fast tracks within rescue services and energy supply. These are two prioritized areas that will go first. We also provide powerful digital tools to the police to curb crime, and we strengthen the defense to an extent that has not been seen since the 50s.

All of this is, of course, included in cybersecurity, but we have introduced a number of concrete fast-tracks that specifically concern cybersecurity which I intended to mention here.

We have strengthened the management and established a clear leadership for the National Cybersecurity Centre and given a sharp mandate to involve the business sector.

Strengthening international cooperation is another priority task, as there are no national borders in the cyber domain.

We have also appointed an international cybersecurity coordinator to ensure that contacts with the EU, UN, Nato and bilateral actors function, because as has been said, there are no national borders in the cyber domain.

We are funding a Swedish cyber campus at KTH, and we continue to fund the expansion and maintenance of the Armed Forces' excellent cyber education.

We have also appointed a national security council that coordinates the major strategic security issues. Previously, there has been a lack of governance and leadership.

But we Moderates are not naive. We know that more will be needed than the proposals here and now, because we know that there are great challenges that the cyber defense faces. But one must prioritize fast tracks in order to move forward quickly.

We are therefore building up cybersecurity from a low level where many components are still missing. There are measures that must be put in place quickly, including the new cybersecurity strategy. Work is being done there in broad dialogue with many actors.

One must also learn what was wrong with the previous cybersecurity strategy. A strategy is supposed to hold over time, and therefore it is important that it is allowed to take time so that it becomes sufficiently good and one does not need to tear it up as we have now been forced to do.

But the most important ingredient for building up our security is that there is now a clear political commitment and a clear political leadership for cybersecurity. It is therefore the Minister for Civil Defence who is responsible for cybersecurity in Sweden's government.

There is also a fundamental insight in the current government regarding the business sector's role in these issues. And, perhaps most importantly, unlike before, there is a fundamental support here in the Riksdag for the government's budget.

It can therefore be clarified that it is the business community, the business community and the business community that are both the key and the lock in this challenge. Therefore, we must involve the companies to cooperate in this work.

Mr. Speaker! I am very proud to stand here in the speaker's chair as a Moderate representative. The government is implementing an enormous paradigm shift in many different areas such as defense, the justice system, and energy. More digital tools are being given to the police, penalties are being tightened, crime victims are being put in the foreground, defense spending is being doubled, and nuclear power is being built up.

We have lost so many years under the previous red-green governments, but that time is now over. We can finally tackle the societal challenges seriously, and I am proud that the cyber area now has the political momentum and the political reforms that the cyber area has lacked for so long. I am proud of our first year in government and our work within cybersecurity.

But we are also humble and aware that much remains to be done. We will therefore continue at full pace to strengthen and reform Sweden's cyber capability, for that is how we make Sweden safer.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Markus Selin (S)

Mr. Speaker! Thanks to Member Camilla Brunsberg from the Moderates for the speech! I listened but did not understand.

According to Chapter 7, Section 5 of the Instrument of Government, it appears to be the Minister for Civil Defence who is responsible, among other things, for administrative matters regarding cyber and digitalisation - to the extent that such matters do not belong to another department. So I still do not understand who it is that has the responsibility. Is it the Minister for Justice if there is a connection to terror? Is it the Christian Democrat Erik Slottner, who calls himself Sweden's Minister for Digitalisation? Is it Pål Jonson if it is cyber policy or cyber attacks that we can use? I do not know.

"The central deficiency is the lack of strategic trade-offs and priorities that direct the information and cybersecurity work," it says in the Riksrevisionen audit report. We take that to heart, but I hear no answers from the Moderaterna.

The Moderates have had a poor track record when it comes to cyber, both in opposition and when they came to power. The Moderates have been in government for 15 months. They have promised a new strategy. Most recently, when I asked the Minister for Civil Defence, Carl-Oskar Bohlin from the Moderates, I received the answer that it could take about a year. We will therefore be in a situation where half of the parliamentary term has passed, and we have not seen the Moderates' promised strategy.

No one knows why the new cyber strategy from the Moderaterna is to be submitted at all. Where is the shoe pinching? What hole is the strategy supposed to fill?

The speech at riksdagen.se, in Swedish (opens in a new tab)

Camilla Brunsberg (M)

Mr. Speaker! It is unfortunate that the member does not understand, but I want to point out that knowledge is the basis for understanding.

I have a question for you, Markus Selin: Are you aware that already six years ago, 10,000 attacks occurred daily against our country? In your speech, it sounded a bit like it was a surprise that we are being attacked here and now. These large-scale attacks have occurred over several years, so I just want to say that the basis for understanding is knowledge.

Now, the member seems to have familiarized themselves quite well with certain structures in our government and security councils. It was good that you explained that in a concrete way here, but I want to be very clear that it is our Minister for Civil Defence who is responsible for cybersecurity. But just like all other operations, digitalization and cybersecurity are integrated into all operations.

I did not sit in the Riksdag during the last parliamentary term, but perhaps you did. If I remember correctly, you even had a minister who had to resign due to an IT failure. The cybersecurity strategy that you developed, are you satisfied with it? I can state that the National Audit Office is impartial, and in my role as a politician, I have always taken audit reviews very seriously – their role is, after all, to contribute to making things better. I am also very open to us finding a consensus on this.

My questions to you are therefore: Are you satisfied with your cybersecurity strategy from the previous mandate period? Which parts do you think we should include in the new one? If you are not satisfied with it, what do you think we should include then? And do you not agree that it is better to work in parallel with fast tracks, where one picks the low-hanging fruit and ensures that governance and management function, and when it comes to something such as a strategy, which is to hold over time, spend a bit more time so that you do not need to tear it up when the Swedish National Audit Office comes in and audits again?

Now I have asked you a couple of questions that I would like to have answers to.

(FIRST DEPUTY SPEAKER: I must remind the member that we do not use "you" as a form of address in the chamber, but rather "the member" or first name and surname.)

The speech at riksdagen.se, in Swedish (opens in a new tab)

Markus Selin (S)

Mr. Speaker! I asked a few questions and received even more questions in return. As polite as I am, I shall try to sort this out.

Let me begin by saying that we, with all respect for the current review report from the Swedish National Audit Office, ordered a significantly larger report, namely the Cybersecurity Investigation, which was tabled in the summer of 2021. Most of it we already know.

Regarding the strategy, the current strategy is published on the current government's website right now, as we speak - excuse me that I do not speak Swedish. It is about, among other things, that we shall have a systematic and unified approach. We shall review security in hardware and software. We must prevent cyberattacks and IT crime. We shall increase knowledge throughout society. And we must increase international cooperation.

After having answered these questions, I return to my question. How can it be that one as a Moderate, both in opposition and in government, speaks about the importance of a new strategy? One talks and talks, and one writes op-eds in the morning newspapers. But 15 months of this mandate period have already passed, and it will probably take about another year before we get the promised strategy in place.

And in parallel with this, people have started talking about a specific, separate strategy for cyber policy with a focus on foreign policy – and that is not in place either. No one knows when it will arrive. The Minister for Foreign Affairs stood here at the rostrum a year ago and said: We will develop a cyber strategy also with a focus on foreign policy.

And now we stand here. Where I began, I conclude: The central deficiency is the lack of strategic trade-offs and priorities.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Camilla Brunsberg (M)

Mr. Speaker! As I said earlier, the basis for understanding is knowledge. This Swedish National Audit Office report points out that the strategy is substandard. Since you Social Democrats were the last in the EU to produce a cybersecurity strategy – as we have heard from the rostrum earlier, it took at least three years to produce it – I have presented which fast-tracks we are already implementing while we choose to work out a cybersecurity strategy that can hold up over a long period.

What the member did not answer is what he is satisfied with in the current strategy and what he wants to include in the upcoming one. A broad approach and a broad dialogue are currently underway with several different actors, including the business community, to obtain a broad, sustainable, and functional strategy that does not need to be torn up when the National Audit Office enters and audits.

But if the member does not agree with the alarming criticism from the National Audit Office, which points out that management, governance and strategies are too slow, too weak and substandard, he should be glad that the Social Democratic strategy still remains. We cannot be without a strategy, so we keep it until we have produced the new strategy, which we choose to work through carefully so that it will hold up over time.

I think this says quite a lot. If this is the only thing you have to criticize, you are certainly quite satisfied with the extensive overhaul we are making regarding cybersecurity.

It is a pity that you Social Democrats were not as agitating and engaged during your eight years in government. This review shows that the work you did was completely substandard, far too clumsy and far too slow. I therefore take it as praise for the current government that we have actually implemented so many changes that the only thing you can criticize is that we are keeping your Social Democratic strategy for a few more months. I do not think that is such serious criticism.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Lotta Johnsson Fornarve (V)

Mr. Speaker! Cyberattacks are one of the greatest civilian threats to our society. Our society has a very high degree of digitalization. A great deal is dependent on our digital systems functioning, and this makes us vulnerable. We know that we are exposed to cyberattacks all the time, both large and small. Just recently, we have heard about large, serious attacks, including against the Church of Sweden, and right now an attack is underway that affects not only a number of companies but also municipalities, regions, and a large number of authorities. It is a serious situation.

In a cyberattack, our society's functionality is affected. Important systems are shut down, information can be intercepted, and important activities cannot be carried out. In the worst case, it can mean very large problems for both individuals and organizations. Cyberattacks can involve extortion to make money, but they can also be carried out to harm our society and make it harder for us to keep society running.

Mr. Speaker! This matter concerns an audit by the Swedish National Audit Office regarding society's information and cyber security, and the Swedish National Audit Office has some criticism.

We are probably all in agreement that Sweden must become much better at countering cyberattacks and improve cybersecurity at all levels – from the individual person to large companies and public organizations. Sensitive personal data and important systems are handled today by both companies and the public sector, which requires strengthened protection at all levels.

It is of great importance that we view Swedish cybersecurity as a whole. The entire society must have strong protection for information and against cyberattacks; we are not stronger than the weakest link. In a survey of operations managers conducted by the think tank Fores, the question was asked whether the authorities' support is satisfactory, and there the grade was the lowest among all questions. It is therefore evident that much needs to be done to coordinate and strengthen our cybersecurity.

Mr. Speaker! The Left Party submitted a motion regarding cybersecurity during the autumn's general motion period, so I will focus on our proposals.

In our motion on cybersecurity, we propose that an IT incident commission be established. Today, all government agencies report serious IT incidents to MSB. We believe that extensive IT incidents need to be reported, followed up, and reviewed to a greater extent in a unified process. This should also apply to other organizations that are subjected to attacks. An IT incident commission should therefore be established in cooperation between the relevant agencies so that large attacks can be analyzed for a better defense against cyberattacks in the future.

In our motion on cybersecurity, we also propose that a state cloud service be established, where information and data can be stored securely over the internet, in a so-called cloud. That such a cloud service is specifically state-owned is important so that we have our own control over the information that is stored, instead of handing this over to some company in another country.

We also mean that international regulations must become much clearer when it comes to cyber issues. Cybersecurity is an international issue because many of our digital systems are precisely international. Sweden must work for an international regulatory framework regarding cybersecurity.

Vänsterpartiet is also strongly critical of outsourcing of IT activities, i.e., that an organization contracts out to another organization to take care of specifically IT activities. We believe that this should be avoided as far as possible and, when it concerns public activities, only be done in extreme exceptional cases. Clear security requirements and conditions should be developed for procurements in the IT field in those cases where this really needs to be done.

Protection of IT and information must be regarded as a core activity of all, both public and private operations, and be allocated the resources required. Short-term profit must not become a driving force for maintaining functioning IT systems.

Mr. Speaker! I therefore move for approval of reservation number 7 on rules for procurement and outsourcing of IT activities.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Mikael Oscarsson (KD)

Mr. Speaker! Today we are discussing the Defense Committee's report FöU2, the National Audit Office's report on the government's management of society's information and cyber security. This is an important area. As several of my colleagues have already pointed out, it is growing in significance.

We see how Russia used this type of attacks in Ukraine before the war began and the attack almost two years ago. We see it also now, where they practice warfare in different ways. We also see how there have been cyberattacks in our neighboring countries Estonia, Latvia, Lithuania, Norway and Finland and also in our country. We must understand that it will also increase in the future.

The National Audit Office has a real criticism that it is not efficient, that it is weak and that it is fragmented. The problem is the fragmentation, which has existed for 50 years. Very many have had shared responsibility, but it is not sufficient.

The Defence Preparation Committee submitted its report before Christmas. We in the Defence Preparation Committee were recently in Estonia, which is the world's most digitized country. There, and in many other countries, there is a specific authority that has the primary responsibility. This is something that I have long advocated for. In our report, we in the committee write that this is something that should be considered. This concerns, among other things, the responsibility that currently lies under MSB, where they look at incident reporting and the NIS Directive.

But it is a problem that many agencies share these issues. Take this with the cybersecurity center. There, there are four agencies that are, so to speak, the principals, and then there are an additional three agencies that are involved. And if you then add the NIS Directive, it becomes seven agencies.

Even though I support the committee's proposal and argue that progress has been made – for it has – we cannot say that we are finished. We need to do much more.

This, which I have now freely quoted from the Defence Preparedness Board, I hope will become a reality. Already a number of years ago, as someone pointed out, FRA stated that 10,000 cyberattacks are carried out per month - by a foreign power, note well!

We have only seen the beginning of this. We have made progress. This is something that we have raised in the Defence Preparation Board, but we must do significantly more. The damage that can be inflicted on our country is so great that we must take this significantly more seriously and organize it significantly better moving forward.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Mikael Larsson (C)

Mr. Speaker! Right now, as we debate the National Audit Office's report on the government's management of society's information and cyber security, Sweden is being subjected to cyberattacks. We have seen this over the past few days. There have been attacks against everything from government agencies and the Riksdag itself to private companies.

The National Audit Office has drawn serious conclusions, which are reported in the report, regarding the government's management of society's information and cyber security. The government's and the Government Offices' working methods have not been effectively designed. There is a lack of strategic trade-offs and priorities to focus the activities needed to protect and strengthen our IT infrastructure and counter cyberattacks in Sweden. Sufficient has not been done during recent years, and more must be done moving forward. This applies both to the current government and also to previous governments.

Mr. Speaker! The Swedish National Audit Office assesses, among other things, that there is a lack of sufficient operational and tactical knowledge regarding how cybersecurity work is conducted in agencies and in the private sector. Furthermore, the National Audit Office's review shows that certain actors do not feel included in the work. This could, for example, involve the business community at large, both large companies and small and medium-sized enterprises. There are problems investigating IT-related crimes and providing support to different actors during incidents. The lack of competence in society linked to information and cybersecurity continues to be critical.

One such thing we saw before Christmas was the attack against the Church of Sweden, which took several weeks to restore and caused a number of difficulties for the operations.

Mr. Speaker! When it comes to IT-related crime, it is stated in the National Audit Office's report that there are problems investigating just such crime. The police have today a mandate to increase the capacity to handle cybercrime. But there is much to do. One measure could be to simplify reports of cybercrime, for example via e-reports, something that would enable a national situational awareness and management of the cyber security attacks that occur.

For Sweden's citizens and companies, an IT crime center is something we view positively. It can be a good help against precisely cybercrime and cyber-criminality. The cybersecurity center that exists is good, but it must and shall be developed. It should be easier for the whole society to turn to the cybersecurity center to get support and help. But precisely that which is IT crime-related must be able to be handled in a separate way. Thus, the cybersecurity center cannot be considered the only spearhead in the fight against cyber threats. More must be done to strengthen the conditions also with an IT crime center.

Let me summarize this. The Centre Party proposes that cooperation between the cybersecurity center, the business sector, and the IT crime center should be strengthened and that the government shall act precisely so that the IT crime center shall be the most important actor in providing assistance to the business sector and organizations so that cybercrime and cyber-offending shall be investigated. They shall receive the help that is needed.

This is a task that must take place today, tomorrow, and in the future. The work has begun but must proceed.

I myself sit in the Defense Preparedness Committee. In previous contributions, we have heard about the committee's work, and precisely this work is something that will also be extremely important to strengthen the entire chain, not just the defense-related parts but the entire society, so that we obtain a resilient cyber defense with secure systems that are sustainable today and in the future.

With this, Mr. Speaker, I wish to move for approval of the Center Party's reservation number 3.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Joar Forssell (L)

Mr. Speaker! I thank you for a good debate.

Right now, the axis of evil, Iran, Russia, and China, are waging a more or less coordinated war globally against us democracies. It is about Russia's full-scale invasion of Ukraine, it is about Iran's attacks against Israel through the terrorist organization Hamas, and it is about China's repeated aggressions against Taiwan, just to mention a few conflict hotspots driven by precisely the axis of evil, Iran, Russia, and China.

Mr. Speaker! Nor is Sweden spared from this, but we are constantly subjected to cyberattacks. We are constantly subjected to needle pricks from these powers and their subordinates or accomplices.

We are proud of our digitalization. We are proud that we have been able to build a prosperity in Sweden that is dependent on the fact that we are highly digitized. This is fundamentally a strength, but it also means that we become more sensitive to that type of attack. It can mean a weakness to be digitized.

One can compare it with more rural parts of Russia which are basically not digitized at all. Of course, it is simpler or more efficient to attack, for example, Sweden with cyberattacks. That is why this is so incredibly important - not because it is something abstract or something that could happen, but because it is something that is happening here and now.

Mr. Speaker! The full-scale invasion of Ukraine began with a very large cyberattack from Russia. Ukraine had done its homework and succeeded in repelling it to a very high degree, but one should not be certain that that type of attack can be repelled if one has not done its homework.

This is exactly what the Swedish National Audit Office's complete dismantling of the former Social Democratic government is about. They had not done their homework, but instead, they had exposed Sweden to the type of attacks that Russia used against Ukraine before the full-scale invasion. That is why it is so serious, Mr. Speaker. One must do one's homework.

This is recurring. Taiwan is, as I mentioned, the country in the world that is most vulnerable to cyberattacks because their adversary – the antagonistic actor that wants them harm – is China. Sweden can very well also end up not only in Russia's and Iran's sights but also in China's.

Mr. Speaker! The Government is implementing and has implemented a number of measures and will do even more to strengthen cybersecurity to tackle the vulnerabilities that the Social Democrats have left open. It also falls upon the business sector and other parts of the public sphere than the state to ensure that these parts are in place, as no part of society can function if the business sector is not also protected and protects itself.

There must be a cooperation between the state and the business sector. It is not one or the other that has the responsibility, but we have it together. That is seen in Ukraine, in Israel and in Taiwan when they are under attack. It is about all of us working together to protect what we value most - our freedom and democracy - against the axis of evil Russia, Iran and China, who wish us ill and who subject us to that type of attack every day.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Emma Berginger (MP)

Mr. Speaker, members of the chamber and you who are watching at home! I regret that I am entering just at the end of the debate and have not followed it so closely. This is because the Defence Preparation Committee has had an ongoing meeting that continued when I left it to come here and deliver my speech. I nevertheless want to take the opportunity to say that cybersecurity is incredibly important, and this is something that we consider in the committee's work and which will be an important part of our conclusions.

We in Miljöpartiet stand behind both of our reservations in this matter, and since there are only two, we choose to move for approval of both reservation 2 and reservation 6.

The digital development brings great advantages for society. We can communicate, we can share information, we can create things together and we can take part in culture but also conduct banking and agency matters digitally. It is fantastic.

At the same time, the digital development entails vulnerabilities. Antagonists are constantly looking for vulnerabilities both to disrupt and knock out our systems and to gain access to steal data and that which we want to protect. Not least the weekend's extensive cyberattacks demonstrate the need to prepare ourselves in a much better way and create a cyber readiness.

The hybrid attacks will continue. Different antagonists, both foreign powers and criminal organizations, know that this is a means they can resort to, and it is up to us in society to ensure that we are as protected as we can possibly be.

We are dealing here today with the government's communication in response to the criticism in the National Audit Office's report on the government's management of society's information and cyber security, which is both urgent and important.

The National Audit Office's overall conclusion is that the government's work in the area has not been effectively designed. According to the National Audit Office, the central deficiency concerns a lack of strategic trade-offs and priorities that direct the information and cybersecurity work.

I want to emphasize that Miljöpartiet wants the cybersecurity in the public sector and especially in socially important parts of the private sector to be strengthened, because modern warfare exploits weaknesses in society and actively contributes to polarization and unrest that can be used to ensure that society is governed in a way that suits various actors' own purposes.

For example, we see the impact on opinions in Sweden and in other countries with the aim of destabilizing society, and this happens continuously. It happens by increasing contradictions between groups, and it happens by undermining trust in our authorities. Many actors are interested in this.

An open world benefits Sweden in very many ways and is a prerequisite for us to be able to handle both environmental threats and security threats as well as other parts of building up our society, but for the open society to be able to function we need to secure our digital systems and protect ourselves against attacks, regardless of whether these are carried out by criminals seeking to steal money or by foreign powers seeking security-sensitive information. Ultimately, it is about the citizens being able to feel safety and trust in the authorities and society.

Against the background of what has been stated, Miljöpartiet proposes that cybersecurity in the public sector and in particularly society-critical parts of the private sector should be strengthened and argues that the Riksdag should stand behind what is stated in our reservation on this and announce it to the government. We also propose that one or more agencies should be tasked with developing a national strategy for strengthened resilience against disinformation and propaganda so that media and information literacy can be strengthened.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Sara-Lena Bjälkö (SD)

Mr. Speaker! I would like to begin by expressing my approval of the proposal in the committee's report.

Cybersecurity is a constant and growing threat to organizations, authorities, and actors through the constantly increasing digitized society that we have. We can only see how fragile we are here in Sweden's Riksdag.

Cyberattacks can lead to consequences that can prevent organizations' operations. This lays the foundation for the work to see how the defense capability has developed or not.

The National Audit Office's conclusion is that Sweden's information and cyber security has not been effective. It is assessed that, among other things, there is a lack of sufficient operational and tactical knowledge regarding how cyber security work is conducted within the authorities and within the private sector.

When it comes to IT security and the cyber threat, we can read, hear, and experience how the digital threat landscape against Sweden is escalating.

Mr. Speaker! Which important societal functions should we then prioritize? What kind of cyberattacks are being carried out? How should we work to protect Swedish society against serious cyberattacks? And how should the correct authorities act to stay ahead? Should the Defence Research Agency, FRA, have the primary responsibility for a cybersecurity center?

The National Cyber Security Centre, NCSC, aims to strengthen the agencies' abilities to carry out their respective missions while also providing improved opportunities to increase the national capacity to prevent, detect, and manage cyberattacks and other IT incidents that risk harming Sweden's security.

Four authorities received the same assignment from previous governments. According to the assignment, they were to work together and in consensus. It has been a challenge for them to become as agile as desired.

Mr. Speaker! That is why it is good that an investigation is currently underway to review the ownership of the National Cyber Security Centre, NCSC, and their mission, mandate and organizational home to ensure their contribution to the entire society's information security and cyber security.

Mr. Speaker! It concerns many issues, and much has truly gone the wrong way when it comes to, for example, authorities, actors etcetera not knowing what they should do.

The report points out that the authorities have had difficulty coordinating their activities, and a lack of leadership and follow-up has resulted in that the desired result has not been achieved.

The strategy is unclear in several parts regarding which actors and sectors are intended to be affected and how.

There are also ambiguities regarding how different objectives and activities are intended to affect society, the economy, and the citizens at large.

In this context, it is stated in the National Audit Office's report that it has taken a long time to build up NCSC. The reason for this is explained to lie in the fact that much time has been spent on resolving issues regarding the forms of cooperation and that the responsibility for issues that required actions from several different actors, or even issues that do not belong to any actor's main priorities, has to some extent been unclear.

This will be yet another example, alongside the report on the army's reconstruction and the staffing of group commanders, soldiers, and sailors, where the previous government has launched vague projects that have subsequently not been followed up on or prioritized.

The Tidö parties are now taking a clear grip and will rectify the deficiencies that the Swedish National Audit Office has pointed out in its report.

Sverigedemokraterna will carefully follow up to ensure that words turn into action and that a clear distribution of responsibility - just like follow-up and control - becomes the norm for the operation.

Mr. Speaker! Now it must be an end to talk and unclear leadership. Sweden and everyone who works with the society's cybersecurity deserve better.

The deliberation was hereby concluded.

(Decisions were made under § 7.)

The speech at riksdagen.se, in Swedish (opens in a new tab)

Source: The Swedish Parliament. The speeches come from the open data of the Riksdag, translated into English by AI, which may contain errors.