Response to interpellation 2023/24:131 on Sweden's cyber defense
Translated from Swedish by AI; the translation may contain errors. The Swedish text is the original.
Summary AI, written in advance
The debate concerns Sweden's cyber defense and the need for a national strategy. M argues that the national strategy is under development and will be decided during the autumn of 2024. M emphasizes the importance of cooperation between the state, the business sector, and academia and notes that the previous strategy was deficient 1 2. M wants to give the National Cybersecurity Centre clearer leadership 2 and argues that the previous strategy has been condemned by the National Audit Office 3. M believes that the government is working as quickly as possible on a new strategy 3. S argues that it is urgent to produce a plan 4 and that the previous strategy was good 4.
Written by AI in advance and may contain errors. The numbers lead to the speech a statement builds on; check against the text below.
Statsrådet Carl-Oskar Bohlin (M)
Madam Speaker! Markus Selin has asked me when the national strategy for society's information and cyber security will be in place, whether an analysis has been made to see which needs the strategy should address, and if I can, in that case, account for the results of the analysis. Markus Selin has also asked me what concrete steps I and the government intend to take to provide the national strategy for society's information and cyber security with a clear vision, measurable goals, and distribution of responsibility.
I share Markus Selin's view that the global situation is serious. Information and cyber security work is therefore high on the government's agenda.
The starting point with the new strategy is to achieve a resilient Sweden where reinforced cybersecurity and protection of vital functions are prioritized, while deepened and targeted cooperation between the state, the business sector, and academia lays the foundation for a secure digital future. With this starting point, the government wants to emphasize the importance of getting the basics in place as well as the need to prioritize functioning cooperation between the key actors within the cybersecurity area.
The Government's objective is that the strategy shall be decided during the autumn of 2024. In that work, I am mindful of involving as many affected actors as possible. During the autumn, a number of workshops will therefore be organized together with the National Cybersecurity Centre, to which industry and interest organizations as well as a number of public organizations are invited to participate. In parallel, dialogues are also being conducted with a number of individual actors. Vulnerabilities and risks that need to be addressed in the strategy and its associated action plan will be inventoried and analyzed.
The national strategy also constitutes part of the implementation of the directive on measures for a high common level of cybersecurity across the Union, the so-called NIS 2 directive, which requires all EU countries to have a national cybersecurity strategy. In accordance with the directive, the strategy will identify measures that ensure preparedness for, response to, and recovery after incidents, including cooperation between the public and private sectors.
Let me also mention that the government – in parallel with the national work I have described – is now developing a strategy for cyber issues and digital issues in foreign and security policy.
In summary, I can state that the urgent work on the new national information and cybersecurity strategy is underway and proceeding according to plan. I look forward to presenting it in more detail as soon as it is completed.
Markus Selin (S)
Madam Speaker! Thank you, Minister Bohlin, for a good answer! I am proud but not satisfied.
Madam Speaker! If you don't know where you are going, it doesn't matter which way you take. The words are taken from Alice in Wonderland. The book was written by Lewis Carroll in 1865. This is the cat's answer to Alice when she wonders where she is going.
Madam Speaker! With these words from Alice in Wonderland, I direct my greatest fears and my criticism to the Minister regarding our common cyber policy today. We have no strategy.
In the spring, I read a debate article in Dagens Nyheter which was signed by Minister Bohlin, the Prime Minister, and others. It was striking how they tried to highlight a new strategy for cyber policy in Sweden. And just as the Minister accounted for in his response here, one also begins to emphasize the need for an international cyber policy. That is when I start to get a little worried. I do not want a common cyber policy that can be likened to a Swiss cheese. I would rather that our common cyber policy is a Swiss cheese fondue, a common melt.
Madam Speaker! What do I actually want with this? Let me take some examples.
Crisis management in our common government, with slightly different colors, has often had to be adjusted. But linked to cyber policy, I become quite worried. I read between the lines in the answer that State Secretary Bohlin mentioned the new envoy, with international responsibility for our cyber issues. At the same time, we have a new security advisor in the government. Since before, it is the State Council Secretariat that coordinates the general security work. And the Prime Minister leads the Security Council. This is not enough. The Prime Minister's State Secretary leads the collective crisis management. I am not finished yet. In addition, we have a special chief official responsible for crisis management and, in addition, an office for specifically security and crisis issues.
I mentioned an opinion piece in Dagens Nyheter this spring. It is quite clear that it is six ministers who sign one and the same opinion piece, which ultimately concerns our common security.
Unfortunately, we now have a serious security situation. It is cyberattacks. It concerns our collective cyber defense. Let us say it is conventional warfare. When it comes to Russia's unjustifiable and unjust war in Ukraine, we have seen how it began brutally with cyberattacks - 2014 and 2005. Power supply, infrastructure, and so on were under constant attack.
Statsrådet Carl-Oskar Bohlin (M)
Madam Speaker! I will not review Markus Selin's contribution; I only note that it was rather broad brushstrokes. He did not actually dwell on any of the three rather clear questions that he posed in the interpellation.
He begins by saying that we do not have any strategy. On that point, one has to give him half right and half wrong. That is because we do have a cybersecurity strategy that was adopted by the previous Social Democratic government. I have to give him credit that it is not much of a strategy. It has received a great deal of criticism, and not only that – the entire way of handling cybersecurity issues in the previous government has received a great deal of criticism from the Swedish National Audit Office. You have now received the government's response to this letter, where the government in all material respects agrees with the criticism directed at the Government Offices and relevant agencies during the period 2017 to October 2022.
It is naturally the case that the government has high levels of ambition when it comes to addressing many of these problems, because just as Member Selin says, we find ourselves in a very serious security policy situation. We see how antagonism is directed towards Sweden in the cyber domain in a way that harms Swedish security and Swedish interests.
Some of the criticism in the National Audit Office's report is precisely that the coordination in the Government Offices has been too deficient and that the cybersecurity center that the previous Social Democratic government let start simply has not gotten off the ground, despite the activity having been ongoing for a number of years.
The debate article that Markus Selin refers to should be seen as an ambition for this center and for the collective work with cybersecurity and cyber defense. The reason why there were many ministers who signed this article is quite simple, namely that the cybersecurity work must not be characterized by unnecessary silos. It is one of the most cross-sectoral tasks we have in society. The cyber domain affects the entire society, and therefore this is naturally an issue that has many and important stakeholders in and outside the Government Offices.
The criticism being made is that the coordination has not functioned. We are addressing this, among other things, with the establishment of a national security council and with the reorganization that is currently taking place in the Ministry of Defence to achieve better coordination, for example, between cyber defense and cybersecurity issues.
I naturally look forward very much to returning to Markus Selin's three questions, but it is not the time now to anticipate the answers to these questions for the reason that we need to have a cybersecurity strategy that is anchored. For precisely this reason, as I mentioned in my opening response, the government has taken the initiative to speak with the industry that must be involved in the development of this strategy so that it does not become a shelf-warmer, as the previous strategy in all material respects has become.
Markus Selin (S)
Madam Speaker! In some respects, I like what I hear from Minister Bohlin. But I do not agree. I even think that the Minister is completely out of touch, Madam Speaker.
I started with Alice in Wonderland, and all of us who have read Alice in Wonderland know it is the strategy I mean. If I were a minister responsible for cyber issues, I would, for example, have started with the strategy before I appointed Carl Bildt as a special investigator of our common security policy, something we could take part in last week. And before Carl Bildt, we have had to take part in a new security advisor and an international envoy for cyber issues.
This is diverse, Madam Speaker! That is what I am looking for.
In that debate article in Dagens Nyheter that we have both mentioned, it is striking with the high frequency of the tail-end regarding that we need a new strategy. We have no strategy! The word "effectively" is used in contexts such as "effective work," "more effective coordination," and "effective support."
What I mean, Madam Speaker, is that one should have started with the strategy before one starts poking a bit at the Swiss cheese!
What Minister Bohlin should get credit for, as the youth say, is that they have set a date. Next autumn the strategy shall be in place. That is good! But it should have been in place already last autumn. One must start with the strategy, otherwise it becomes like Alice in Wonderland.
Back to the op-ed in Dagens Nyheter this spring, just to underline all of this: "The cybersecurity area has not been sufficiently strategic or cohesive." It cannot be any clearer or more distinct than that.
It has now been seven months since we read this in Sweden's largest morning newspaper. It has now been nearly thirteen months since the government took office, and now we are to wait approximately twelve to thirteen months more for our common cyber policy.
That is why I am concerned. That is why, Madam Speaker, I stand here with you today. Cyberattacks can be equated with conventional warfare. It is serious now.
Back to the division of roles, which also worries me somewhat. It has actually become less clear with today's government. Let us take the op-ed in Dagens Nyheter as an example: The systematicity in the world of digitalization in general, who is it that is responsible for it? It is the Minister for Civil Affairs. There were two other signatories, Defense Minister Pål Jonson and the Minister for Civil Defence Carl-Oskar Bohlin, who stand here with me today. I am also not sure when Bohlin is responsible for cyber issues and when Jonson does. When it concerns preventive cyber work and if it concerns terrorist organizations, who is it then? Well, then it is precisely Justice Minister Gunnar Strömmer. I have also met many companies that talk about a lack of competence. Who is it then that is responsible for cyber policy? Well, then it is Education Minister Mats Persson, the Liberal! And we are not finished yet, for who is it that is responsible for the international envoy for cyber policy, which both I and State Secretary Bohlin have highlighted? It is the Ministry for Foreign Affairs!
The government has now had thirteen months. Seven months ago, there was a high level of uncertainty, and then they say that the strategy will arrive in twelve months.
Statsrådet Carl-Oskar Bohlin (M)
Madam Speaker! The alleged lack of focus in this discussion is, to no insignificant extent, attributable to the lack of coherence in the presentation from Member Selin.
The fact is that if we, as Markus Selin claims, had already had this strategy in place last autumn, then that work would have needed to be carried out by the government that served until October 18, 2022, at approximately 13:00. After that, we received a new government, and as soon as that government took office, this work began.
That Carl Bildt has been given a special assignment to review the Swedish intelligence system has a very limited impact on taking a collective grip on cybersecurity issues. But for the record, it is in the sense that the investigator of, for example, the national cybersecurity center was appointed earlier.
We want a cybersecurity strategy worthy of the name. One of the important issues here is to establish a clear vision of the goal. To achieve this, one needs a good basis regarding what the problem picture looks like. It is this work we are currently engaged in.
I completely agree that the cybersecurity strategy should have been in place much earlier. But for that reason, one cannot rush a strategy so that it becomes unusable in reality. In the best of worlds, we would also want a strategy with a clear action and implementation plan. That is also why the government aims to structure the strategy in a different way, that is, through a government decision with an accompanying appendix. The previous strategy was presented to the Riksdag as a communication, with the disadvantage that it became a very static document. This needs to be more of a living document where the action plan attached to the cyber strategy can also be changed as the world around us changes.
I would like to say, to broaden the perspective a bit, that one of the truly great challenges for, for example, the National Cybersecurity Centre is to harness the competence and drive that exists in the business sector. It is therefore not just about communicating the situation and participating in remediating vulnerabilities, but it is also about a public-private cooperation where the public sector, through its representation in the centre, can also receive help from the private business sector in taking this holistic approach to cybersecurity issues. It is one of the things that the special investigator who is now looking at this centre formation has to examine.
One of the problems with the National Cybersecurity Centre is that there has been a lack of clear leadership and governance. We now want to try to rectify this by – as we describe in the debate article that Markus Selin refers to – giving the centre a leadership through a special head of agency. Exactly what this is to look like is one of the things that the special investigator is now looking into.
Markus Selin (S)
Madam Speaker! It is time to hurry now, Minister Bohlin! Cyberattacks are occurring around the clock in Sweden. This is beginning to resemble Alice in Wonderland. If you do not know where you are going, it does not matter which path you take, regardless of how many envoys Minister Bohlin wants to appoint or if Carl Bildt makes a comeback in politics. Bring forward the plan - it is urgent now!
Many of us usually visit the government's website. On Friday, I could, to my surprise, see that the website had been updated, and there they had posted the Social Democrats' old strategy. This spring, it was said that we needed a new strategy. We have no strategy, they said. It was said that we are to have an international strategy, and we are to have envoys!
This is disjointed. It is a Swiss cheese that we do not want to see.
I then assume that Minister Bohlin likes the Social Democrats' strategy. That is the one that applies. And it is good. We Social Democrats did very much for Sweden's common security and cyber policy in a few years. Three agencies that are directly related to this were established in a few years, namely the Agency for Digital Governance, the Agency for Psychological Defence, and the Agency for Total Defence Analysis. In addition to a civil private digitalisation strategy, a cyber policy was also introduced.
We have 342 authorities in Sweden today and 1.2 million companies. There is no more time for Minister Bohlin to have group projects.
Statsrådet Carl-Oskar Bohlin (M)
Madam Speaker! The cybersecurity strategy that is currently in effect, which was developed by the previous government, has been condemned by, among others, the National Audit Office. The entire cybersecurity work from 2017 to the autumn of 2022 receives a great deal of criticism. It is partly for that reason, but also due to the requirements set out in the NIS 2 Directive, that Sweden is now developing a new strategy.
The timeline for the new strategy is also affected by the implementation of the directive. The implementation could have been in place if that work had been started earlier. It was one of all the heavy stones that this government had to start handling in the Government Offices immediately after taking office.
I am the first to agree with Markus Selin's point of view that everything should have happened yesterday and that everything should have been done earlier. But this government has only been in power for a year, and we are working with the strength we have to establish a new and more purposeful cybersecurity strategy as quickly as possible.
I note that Markus Selin is questioning why so many cabinet ministers are involved in this issue. It boils down to the basic principle of responsibility, which Markus Selin perhaps should familiarize himself with a bit further. The person who normally has responsibility for an issue also has it during a crisis and, at most, during high alert and an armed attack. In the same way, every agency is responsible for its own cybersecurity work.
The national coordination to provide support for this must naturally become better. That is why we are reviewing the center. But every government minister, every agency, every municipality and every region has a fundamental responsibility for its own cybersecurity work, which must be improved.
Source: The Swedish Parliament. The speeches come from the open data of the Riksdag, translated into English by AI, which may contain errors.