Response to interpellation 2024/25:115 on Sweden's information and cybersecurity strategy
Translated from Swedish by AI; the translation may contain errors. The Swedish text is the original.
Summary AI, written in advance
M argues that cybersecurity is a priority and that a new national strategy is under development 1. The government wants the strategy to include an action plan with measurable goals and distribution of responsibilities 1. M emphasizes that the government proposes an investment of 196 million kronor in the budget bill for 2025 1. M also argues that the National Cybersecurity Centre should be moved to FRA to strengthen the ability to handle cyber threats 1. S considers that the government manages cybersecurity poorly 2. S argues that what the small government has achieved is a legacy from previous Social Democratic-led governments 2.
Written by AI in advance and may contain errors. The numbers lead to the speech a statement builds on; check against the text below.
Statsrådet Carl-Oskar Bohlin (M)
Madam Speaker! Markus Selin has asked the Minister for Civil Affairs when a new information and cybersecurity strategy will be in place, whether he has conducted any analysis of which needs the new strategy is to address, and if the Minister for Civil Affairs can, in that case, account for the results of the analysis. Markus Selin has also asked what concrete steps the Minister for Civil Affairs and the government intend to take to provide the national strategy for society's information and cybersecurity with a clear vision, measurable goals, and distribution of responsibility.
The interpellation has been handed over to me.
Markus Selin has previously asked me the same questions, which I answered on November 9, 2023. Cybersecurity work is high on the government's agenda, and a new national strategy for cybersecurity is under development. That work includes describing the government's policy direction for the work in the coming years and Sweden's cyber ecosystem, as well as deciding on a traceable action plan whose results will be inventoried and analyzed based on qualitative and quantitative indicators. The government's goal is that the strategy shall be decided during the coming months.
The strategy is based on a comprehensive threat and vulnerability analysis as well as close dialogues with key actors from both the public and private sectors. During the end of 2023, a number of workshops were conducted where industry and interest organizations as well as a number of public organizations participated. In parallel, dialogues were also conducted with a number of individual actors. Based on these, an analysis has been made of which needs the strategy has to meet. In this way, the government ensures that the strategy meets Sweden's specific needs and challenges.
It is of great importance to strengthen cybersecurity in society and achieve effective cooperation between key actors within the cybersecurity field.
The government has a great deal of work to do after cybersecurity has been a deprioritized issue for far too long, but this government now clearly shows that these issues are a priority. The new cybersecurity strategy naturally constitutes an important part of this work, but the government has taken several initiatives to strengthen Sweden's cybersecurity and is continuously considering new measures.
In the budget proposal for 2025, the government proposes an investment of 196 million to strengthen information and cybersecurity work in Swedish society. The investment is the largest investment in national cybersecurity work that the government has carried out to date. The government has also decided that the National Cybersecurity Centre, with the task of developing and strengthening Sweden's collective ability to prevent, detect, and manage antagonistic cyber threats and other IT incidents, shall be located at FRA from November 1 of this year, and that the government shall appoint the centre's head. This is a step in creating a new and stronger national cybersecurity centre.
Markus Selin (S)
Madam Speaker! I thank Minister Bohlin for the answer.
I will get straight to the point. I think the SD-supported M-KD-L government is handling this matter of cybersecurity quite poorly. Just as State Secretary Bohlin said, I stood here and asked the same questions 13 months ago.
Is there any party in this government that has had a particularly high level of commitment regarding the view on information and cybersecurity? It is precisely the Moderaterna. I have reviewed the Moderaterna's committee motions from both the autumn of 2020 and the autumn of 2021. They entered government position in the autumn of 2022. They submitted a government statement 777 days ago. One and a half years ago, it was a handful of ministers in the government, including the Prime Minister, who spoke about the importance and the need for a strategic cyber policy.
Madam Speaker! Now we stand here again. The years pass. We can go back to when the Social Democratic-led government ordered a major cybersecurity investigation. It was delivered in July 2021. The little that this government has been able to achieve is already described there. I could actually go as far as to say that the little this government has done in terms of cybersecurity is an inheritance from the Social Democratic-led governments and direct effects of what they have carried out.
This does not actually have anything to do with the question, but I respect that Minister Bohlin, both in the oral and the written response, highlights the large budget investments. But, Madam Speaker, all parties in the Riksdag stand behind these budget investments. No one is opposing them. We are in the greatest security policy crisis since World War II. Yes, we must invest massively in both military and civil defense. This naturally also includes cybersecurity.
Madam Speaker! What is this ultimately about? Let me give a brutal example: pathological changes in the right breast. That is what it says in one of the 10,000 records that are currently circulating in cyberspace. These 10,000 records come from Sophiahemmet, a short walk from here. And this does not only concern the average person and ordinary citizens. It even concerns contact details and personal data of well-known individuals in leading positions.
Madam Speaker! I can continue: Munkfors, Härjedalen, Bjuv, Vellinge, Kalmar, Bjurholm, Norrköping, Kalix, Region Västerbotten, Region Uppsala - the list can be made long of municipalities and regions that have been hit very hard by cyber and IT attacks. Let us add Svenskt Näringsliv's report, which says that every third company was hit by cyberattacks last year. Recently, it was Kumla that had to shut down all its operations. Sveriges Radio P4 reported that they simply had to return to pen and paper.
Madam Speaker! This is the reality we are in now, and we are still waiting for the Moderates' and the government's cyber strategy.
Source: The Swedish Parliament. The speeches come from the open data of the Riksdag, translated into English by AI, which may contain errors.