Kammarkoll

Search everything said in the debates of the Swedish Riksdag

← To the search

Response to interpellation 2025/26:12 on strengthened protection against cyberattacks

3 October 2025 · 7 speeches · M, S

Translated from Swedish by AI; the translation may contain errors. The Swedish text is the original.

Summary AI, written in advance

The government takes cyberattacks very seriously and views them as threats to safety and essential societal activities 1. M argues that a holistic approach has been taken through a new national cybersecurity strategy, a restructuring of the national cybersecurity center, and a proposed new cybersecurity law with higher requirements for municipalities and regions 1. M proposes an investment of over 1 billion kronor over three years to strengthen security 1 2. S emphasizes that attacks affect individuals and damage trust in authorities 3. S requests short-term support for municipalities and regions during acute attacks 3 4. M responds that CERT-SE already provides assistance during incidents 5.

Written by AI in advance and may contain errors. The numbers lead to the speech a statement builds on; check against the text below.

Minister för civilt försvar CARL-OSKAR BOHLIN (M)

Madam Speaker! Lena Johansson has asked me how I view the development with the latest cyberattacks and their consequences for individuals, as well as what measures the government intends to take to strengthen protection against cyberattacks against both the public sector and the private business sector.

The government takes cyberattacks very seriously. The attack against the company Miljödata clearly demonstrates the threats that exist in the digital environment and the risks that can arise when many actors are dependent on the same suppliers. I agree with Lena Johansson that cyberattacks cannot be regarded as merely technical incidents. It is about security, about ensuring that Swedes' data is kept safe and that society-critical activities function without disruptions. I understand the concern and uncertainty that this type of serious incident can create for those affected.

That is why cybersecurity is a priority issue for the government, and since we took office, we have taken a holistic approach to the area. At the Ministry of Defence, we have established a special unit for cyber issues that drives the work forward.

During the past year, the government has decided on a new national cybersecurity strategy with clear goals and an action plan that is updated annually. We have simultaneously begun the restructuring of the national cybersecurity center, which is now being centralized under FRA's leadership, with the goal that the center shall more clearly be the hub of the national cybersecurity work.

Furthermore, the government intends to shortly submit a bill to the Riksdag regarding a new cybersecurity law. It is proposed to include, among other things, municipalities and regions and set more far-reaching requirements, also regarding security in the supply chain, in order to reduce the risk of just the type of incidents that we are discussing today.

This is backed up by substantial investments. In the budget bill for 2026, the government proposes a significant increase in funds for national cybersecurity – over 1 billion kronor over three years – to further strengthen the national cybersecurity center and simultaneously support municipalities and regions in raising their baseline and meeting the more extensive requirements that now await. This is done in addition to the historical investments in cybersecurity that the government decided on in last year's budget bill.

In conclusion, I want to emphasize that cybersecurity begins with prevention. Every organization has a responsibility to work systematically with these issues. This applies particularly to those actors who conduct society-critical activities. In recent years, Sweden has strengthened governance, added resources, and increased national capability. But cybersecurity is built throughout the entire society; now all actors must contribute to making Sweden even more resilient, even in the cyber domain.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Lena Johansson (S)

Madam Speaker! Thank you, Minister, for the answer! I think it was a good answer, but I have some reflections beyond those that the Minister answered.

I want to start by saying that it is not some future scenario, but cyberattacks are here and now. The Minister and I debated this earlier this spring regarding public service. When our municipalities, regions, authorities, and companies are knocked out digitally, it is not just a technical problem, but it is also a problem that affects people at an individual level. It therefore does not only affect companies. Patient data has been leaked out, sick leave certificates, registered addresses and personal identity numbers have ended up in the wrong hands and people have lost their security as the data has been posted on the darknet for sale. This creates anxiety about being subjected to fraud attempts, which is a reality today.

It is important to remind that some have protected information and protected identity, and on an individual basis, they are naturally even more affected. Ultimately, if we do not get a handle on this, it is about people ultimately losing trust in authorities and systems.

I want to ask if there is also anything short-term in the long-term work that the government has begun, some intervention that can be made at such times.

The Minister pointed out in his answer that the government will work with security in supply chains, and I think that is very good. But it is not a technicality, it becomes a question of trust – how we can trust that our common basic societal functions work. Does the Minister believe that these measures are sufficient?

The speech at riksdagen.se, in Swedish (opens in a new tab)

Minister för civilt försvar CARL-OSKAR BOHLIN (M)

Madam Speaker! I thank you for the good questions from Lena Johansson.

The government is working on both the short term and the slightly longer term. In the short term, there are naturally the immediate investments that we are carrying out in the current budget. The budget for 2025 contained the largest investment in cybersecurity that any government has ever carried out. Now we are raising that bar even further in the budget for 2026, where we carry out additional investments that will primarily be directed at municipalities and regions, where we see that the work has been neglected. It is naturally urgent.

When it comes to the more immediate and operational work, it is, as I mentioned in my opening remarks, the government's objective to reshape the national cybersecurity center to give it better power to participate in this type of incident management. It is currently concentrated primarily at CERT-SE, which today falls under MSB but will be moved over to the center as it stands. This is being done to build a center that becomes more powerful and that has the ability to support and help. I know that CERT-SE was involved in the specific incident that was referred to.

It is important to point out what I also mentioned in my opening speech, namely that the fundamental responsibility for cybersecurity must be taken by each operator. The state cannot step in on behalf of the operator, but the state can assist through various types of support and by having a clear steering path for where we are headed. This is now being set out in a much clearer way than before with the national cybersecurity strategy, which is also associated with an action plan, that is to say measures that we as a society must check off to constantly keep pace with and stay ahead in the very negative global developments.

As a concluding answer to the question of whether we will reach our goal with this, the answer is that it is work towards a moving target. We also work against dynamic antagonists who try to exploit vulnerabilities and are constantly finding new vulnerabilities. It is to some extent a work that is never finished but which must be constantly maintained.

We can state that we have historically not had the focus we should have had on this task, and it has left us with all too great vulnerabilities in Swedish society.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Lena Johansson (S)

Madam Speaker! Thank you, Minister, for a good answer! It is difficult to go into polemics on this issue, because we all want it to be resolved and become as good as possible.

Region Västmanland, which I come from, and Folktandvården issued a letter stating that they had been affected by this cyberattack. People have contacted me and asked: What happens now, and what can we do? We also know that SVT has reported that the personal data of 8,000 children has been exposed and ended up on the darknet in this attack. We know that what is posted on the internet takes on a life of its own. Many are affected, and many are worried.

I am also worried. Infrastructure, electricity, water and means of communication are also affected in some form – here and there. Then perhaps they are not affected on as large a scale as it is regarding the other.

I am glad that the issue is being addressed, and I am aware that it is not so incredibly easy to handle. As the minister said, we are at the forefront regarding the antagonists we are dealing with. We may never become completely free from cyberattacks, but it is about us having good protection and about us trying to work proactively as much as we possibly can.

I agree that it is important that everyone stays in their lane and takes responsibility where they are, but there is a lot that municipalities and regions are now to take responsibility for. There is a lot of responsibility that also requires funding regarding preparedness. This is also, in a way, a question of robustness for society.

My question is: Does the Minister see future support, also on an economic basis, for our municipalities and regions in this matter?

The speech at riksdagen.se, in Swedish (opens in a new tab)

Minister för civilt försvar CARL-OSKAR BOHLIN (M)

Madam Speaker! The answer to the question posed by Lena Johansson is that we are once again carrying out the largest investment in cybersecurity that any government has ever made. We are therefore exceeding last year's investment – even then, it was the largest investment that had been made in cybersecurity.

The investment presented in the budget for 2026 is an investment of 1 billion over three years. It will go to municipalities and regions that need to strengthen and increase their cybersecurity work, but it will be combined with higher requirements. We believe, in fact, that it is absolutely necessary. It is about becoming more aware of the work that must be carried out, that one considers this more clearly in the requirements one sets when procuring, and that one has better cybersecurity in the systems one is responsible for and operates, for example.

This is an important initiative. But it is not an initiative that comes without requirements – on the contrary. In the new cybersecurity legislation that we will soon place before the Riksdag, we are increasing the requirements on the municipalities. It is absolutely necessary. No person in a municipality should have to be afraid that their personal data will end up in the wrong hands or, for that matter, that the critical societal activities conducted in the municipality can be compromised by antagonists. So, we simply shall not have that.

I welcome that Lena Johansson supports these investments. We will, of course, read the Social Democrats' shadow budget with excitement to see if they follow in the government's footsteps and also embrace the investment that the government has now pushed forward for.

One can observe that this should have been done earlier, but it is welcome that we have finally arrived here.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Lena Johansson (S)

Madam Speaker! Thank you, Minister, for the answer!

Yes, the world is changing. Cyberattacks did not exist when I was a child, for example. There were hardly any computers then. We can stop there when it comes to talking about age.

It is clear that the development has occurred rapidly – we have noted that. The question is multidimensional. We are talking about safety and the individuals' trust in our society. One could even extend this to the will to defend. One can actually extend this question as far as one likes, but it is about trust at the individual level and about security.

It is also about the municipalities and whether they can cope with all the collective assignments that are now required to achieve a robust society and a robust organization. Where should municipalities and regions turn today? The Cybersecurity Centre is working, as I understand it, on an overarching level right now. As I have understood it, there is no cyber force that helps the municipalities, en masse, when things are burning and such large attacks occur. It is important in the short and long term. We need to ensure that there is a possibility to get support also in the short term.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Minister för civilt försvar CARL-OSKAR BOHLIN (M)

Madam Speaker! The possibility of support has been increasing in recent years. Already today, CERT-SE provides support to those affected when it comes to incident management. The best thing, of course, is if one does not need to reach the point of being affected, but instead takes the preventive work seriously.

We do not need to turn back the clock as far as to when the interpellor was young. It is enough to turn back the clock to 2017, when the previous cybersecurity strategy was adopted. Unfortunately, very little happened after it was adopted. The Swedish National Audit Office has, in a report, criticized the national cybersecurity work conducted during the period 2017–2022. It was stated that there have been unclear responsibility and management conditions and that these issues have not been prioritized in the Government Offices. In reality, very much of the work that has been conducted was suppressed.

It is against the background of these experiences and the criticism that the National Audit Office has put forward regarding the previous work that we are now trying to rectify this. It is naturally a task to reach the point where we would like to be. It would have been better if it had been done earlier. But I naturally welcome that the Social Democrats have now joined the government's work in this area.

The interpellations debate was hereby concluded.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Source: The Swedish Parliament. The speeches come from the open data of the Riksdag, translated into English by AI, which may contain errors.