Högskolan i Skövde

his.sePublications
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Exploring the Role and Challenges of CISO: Comparative Case Study of Swedish Municipalities
University of Skövde, School of Informatics.
2025 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

This thesis explores the role and challenges of Chief Information Security Officers (CISOs)—or their functional equivalents—in cyber security governance and policy resilience within Swedish municipalities. As cyber threats increase and regulatory demands grow under frameworks like NIS2 and GDPR, municipalities are under pressure to strengthen their cybersecurity capabilities. However, the effectiveness of these efforts depends heavily on governance structures and the individuals responsible for leading cybersecurity work. The study adopts a qualitative case study approach, focusing on eight Swedish municipalities with 14 participants. Semi-structured interviews and document analysis were conducted to investigate three main research questions concerning:(1) the role of CISOs in local cybersecurity governance, (2) the challenges they face in carrying out their responsibilities, and (3) how governance structures influence municipal cybersecurity resilience. The findings reveal significant differences in how cybersecurity is structured, resourced, and governed across municipalities. Key challenges include limited authority, budgetary constraints, competence shortages, and unclear organizational mandates. The application of Agency Theory highlights the misalignment between responsibility and control, while Resilience Theory provides insight into how governance affects adaptive capacity in response to cyber threats. The study concludes that formalizing cybersecurity roles, improving leadership engagement, and aligning local governance with national frameworks are essential to strengthening cybersecurity resilience in Swedish municipalities. These insights contribute to both academic understanding and practical improvements in public-sector cybersecurity governance.

Place, publisher, year, edition, pages
2025. , p. 75
Keywords [en]
Chief Information Security Officer (CISO); Municipal Cybersecurity; Governance; Cyber Resilience; Agency Theory; Resilience Theory; NIS2; GDPR
National Category
Information Systems
Identifiers
URN: urn:nbn:se:his:diva-25901OAI: oai:DiVA.org:his-25901DiVA, id: diva2:2004233
Subject / course
Informationsteknologi
Educational program
Privacy, Information and Cyber Security - Master's Programme 120 ECTS
Supervisors
Examiners
Available from: 2025-10-07 Created: 2025-10-07 Last updated: 2025-10-07Bibliographically approved

Open Access in DiVA

fulltext(1220 kB)152 downloads
File information
File name FULLTEXT01.pdfFile size 1220 kBChecksum SHA-512
91b150feb3babbfffa5160ff480afbb4763dd345292d6ac64a9b9a116e24af5dfe179e86c2039db4946844e5859e8418389a65109d57196981f72cd7226bd5cc
Type fulltextMimetype application/pdf

By organisation
School of Informatics
Information Systems

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 977 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf