Response to interpellation 2024/25:434 on system and data security in crisis and war
Translated from Swedish by AI; the translation may contain errors. The Swedish text is the original.
Summary AI, written in advance
The debate concerns Sweden's ability to ensure digital resilience and data security in the event of a crisis or war. M argues that the government is carrying out extensive analyses and concrete measures, including a historic investment of 196 million SEK in the budget bill for 2025 1. M emphasizes that the government is moving the ownership of the national cybersecurity center to FRA for clearer leadership and is working with the NIS 2 directive 1 2. M underlines that investments in infrastructure are necessary for robustness 1 3. S welcomes the investments but requests clarity regarding priorities in the supply chain and how the most critical systems for society's nervous system are identified 4 5. S emphasizes that a chain is never stronger than its weakest link.
Written by AI in advance and may contain errors. The numbers lead to the speech a statement builds on; check against the text below.
Statsrådet Carl-Oskar Bohlin (M)
Mr. Speaker! Lena Johansson has asked me what analysis has been carried out regarding Sweden's ability to ensure resilience for critical data and applications in the event of a crisis or war. She has also asked me what measures have been taken to identify and protect the data and the systems that are crucial for the functioning of society. Furthermore, Lena Johansson has asked me how it is ensured that there is a unified understanding of which systems and which data are most critical within both the public and private sectors, and how I and the government are working to coordinate the efforts for digital resilience between different agencies, regions, municipalities, and the business sector.
Questions regarding society's preparedness and cybersecurity have historically often been sidelined for other priorities. The Government has been clear that this is no longer an option. There is danger in delay, and the time for action is now.
To strengthen society's preparedness and raise the level of cybersecurity, the government has carried out extensive analytical work in parallel with a large number of concrete measures being taken.
In the budget bill for 2025, the government is implementing, for example, a historic investment of 196 million kronor to strengthen cybersecurity in society. Activities within the preparedness sector Electronic Communications and Post are also an area that is particularly prioritized in the investments in civil defense. The government is expected to contribute approximately 6.7 billion kronor to the sector during the years 2025–2030. This includes, among other things, measures to strengthen robustness and redundancy in the infrastructure for electronic communication. Investments are absolutely necessary to strengthen digital resilience and critical societal functions.
As part of creating a new and stronger national cybersecurity center with the task of developing and strengthening Sweden's collective ability to prevent, detect, and manage antagonistic cyber threats and other IT incidents, the government decided in the autumn to transfer the ownership of the national cybersecurity center to FRA.
The Government will also present a national strategy for cybersecurity 2025–2029 in the near future. In parallel, work is ongoing to implement the EU directive on measures for a high common level of cybersecurity across the Union, the so-called NIS 2 directive. The Government has also appointed an inquiry to analyze the need for and propose measures and supplementary statutory provisions in order to adapt Swedish law to the EU's Cyber Resilience Act. The inquirer shall report on its assignment by December 15, 2025, at the latest. The strategy, the cybersecurity center, and a purposeful implementation of EU legislation on cybersecurity are all important parts of the analysis capability and capability building in the area.
The analysis of our capability and preparedness is also something that must continue continuously. It is never finished. As an example, the government has recently tasked MSB with carrying out a mapping of digital supply chains within the preparedness and NIS 2 sectors and to develop a model for monitoring digital supply chains.
Cybersecurity and data management is fundamentally the responsibility of the information owner. The threat landscape against Sweden has changed, which entails high requirements for the information and cybersecurity work of government agencies. The Government has therefore decided on a new ordinance aimed at increasing the security and cost-effectiveness in the IT operations of state agencies. The ordinance provides the conditions for coordinated and secure state IT operations with several so-called provider agencies. That agencies with high cyber competence and significant experience in IT operations can offer secure services to other agencies is an effective way to raise security within the entire public sector.
Lena Johansson (S)
Mr. Speaker! Thank you, Minister, for the answer!
I want to begin by welcoming these initiatives. They are really important – for real. I agree with every single initiative, I was about to say. It is fantastic. We really need to scale up in this issue. It is both long-awaited and necessary.
At the same time, I think we must dare to go a little deeper into the question of what actually are the most critical parts to protect and how this should be done in practice. It is perhaps also ultimately about us needing to prioritize things. It is not just data security in itself that determines our resilience. It is about connectivity, i.e., that everything actually hangs together and that it should function even in crisis and war.
We know that today's society is extremely dependent on data being able to move freely, quickly, and securely between systems. This applies to healthcare, emergency services, payment flows, information flows, and communication between authorities, and also within our defense.
I actually have a whole lot of sub-questions, but I am not going to ask them. I am thinking like this: I have a question that I really want to focus on. I think it is so important. It concerns the supply chain, which the minister mentioned. It is so important to me that I would like to know: Will there be prioritizations when it comes to that? I am thinking about whether it would be addressed and we would need to prioritize. What will then happen with just the supply chain? Will we prioritize streaming services or public service? I hope that the minister understands what I am looking for.
I call for more clarity on how the digital chain can actually be protected from interruptions, vulnerability – absolutely – and intrusion. But I also wonder when and where the priorities will be made.
Statsrådet Carl-Oskar Bohlin (M)
Mr. Speaker! I unfortunately cannot anticipate the assignment that MSB has received here. I believe we might also be talking about two slightly different things.
It is about looking at what vulnerabilities exist in different types of supply chains, that is to say, what third-party dependencies one has. It became very clear, for example, during the so-called Tietoevry attack, which affected authorities. They were not directly affected, but they had the company in question as a service provider and were thus affected. It is that type of scrutiny that also needs to be carried out.
Let me also say that there is work ongoing regarding the physical protection of IT operations at a long line of government agencies – I cannot say more about it, as it is surrounded by confidentiality. This is, of course, also important. It is easy to think that what happens in the cyber environment only exists in some abstract environment, but somewhere there is the physical infrastructure for this, and we must become better at protecting it.
A large part of the investments being made in the electronic communications and postal sector aim to achieve higher robustness and redundancy in this entire sector.
Lena Johansson (S)
Mr. Speaker! I can absolutely agree with that. But if we are to build digital resilience for real, we must first know what is most important, I think. It is about identifying which systems and which data absolutely must not be knocked out. That is where one must build this resilience and robustness. If something is knocked out, it must be compensated for in another way. It is about prioritizing measures based on this.
I mean that the Minister's answer actually raises a lot of questions for me. It is about how this prioritization is made. I myself sit in various situations with confidential information. That is not what I am looking for. It concerns more the system, how one jointly at a national level cobbles this together.
It is not just about authorities. It is about companies. It is about municipalities. It is about voluntary organizations within the defense. There are many who are affected by data security and systems security.
My point is that, in practice, it concerns the society's nervous system, as we have concluded. We had industrialism. Now we have digitalization, and it is important for all of us.
Statsrådet Carl-Oskar Bohlin (M)
Mr. Speaker! I fundamentally agree that maintaining digital resilience is the upcoming task, as I often say, for modern civil defense. The government is currently making both substantial investments and substantial structural changes in this landscape.
We are allocating, as I mentioned, over 6 billion to this sector to build more robustness and redundancy. We are reshaping the national cybersecurity center, which until today has not functioned in the way we desired. The National Audit Office has also directed criticism at how that work has been conducted. The Government was aware of this conclusion already when it took office – that we needed to reshape the national cybersecurity center. Now it has happened and is being implemented. It will move under FRA. There will be a clearer ownership for this operation, and we believe that is absolutely necessary. In combination with this, it is about getting a purposeful implementation of the NIS 2 directive in place as soon as possible, which will affect more operators than before, which is completely necessary given how the environment around us looks.
Lena Johansson (S)
Mr. Speaker! Thank you, Minister, for the answer!
In conclusion, I want to emphasize the digital chain which is so important. A chain is not stronger than its weakest link, something I have pointed out on another occasion in a debate with the Minister, and that applies to this supply chain as well.
We do, therefore, have a plan, we receive directives and we have goals and strategies – good. But security, upgrading and creating resilience around various systems is also associated with costs. Many systems are also privately owned. Now, this interpellation is not primarily about financing, but I assume that our cybersecurity will require continued investments in the future.
There are four questions that we must be able to answer: What is important to protect? How do we do it concretely and practically? Who has the responsibility to ensure that it actually works when it comes down to it? How do we finance this?
Statsrådet Carl-Oskar Bohlin (M)
Mr. Speaker! This is important, and we look forward to being able to provide further answers in the upcoming national cybersecurity strategy, which has been anticipated for some time. It will arrive in the very near future.
It is important with financing; I agree with that fundamentally. I accounted for the path that exists, among other things, in the electronic communications and postal sector. In our government bill 2025, we carry out the largest investments in cybersecurity. We are beefing up the national cybersecurity center.
This is, however, all the time a work towards a moving target. I cannot, of course, anticipate future budget processes, but these are undoubtedly important issues.
Source: The Swedish Parliament. The speeches come from the open data of the Riksdag, translated into English by AI, which may contain errors.