Examining the progress, challenges, and strategies of Swedish companies and municipalities in preparing for the NIS2-directive
2025 (English)Independent thesis Basic level (degree of Bachelor), 20 credits / 30 HE credits
Student thesis
Abstract [en]
As the digital landscape rapidly evolves, organisations face heightened risks such as data breaches and ransomware attacks. In response, the European Commission introduced the NIS2-Directive, officially titled Directive (EU) 2022/2555, to strengthen cybersecurity across the EU. This new directive replaces the original NIS1-Directive, officially titled Directive (EU) 2016/1148, due to the limitations of the original legislation. This qualitative study investigates the preparedness of Swedish companies and municipalities for NIS2 implementation, focusing on their current readiness, challenges, strategies, and perceptions.
The authors aimed to learn more by conducting interviews with cybersecurity professionals from both sectors to explore how organisations are navigating the transition. The findings reveal a significant disparity in preparedness: companies are generally further ahead than municipalities, largely due to differences in resources, expertise, and organisational structure. Key challenges include unclear legislation, limited governmental support, fragmented regulatory responsibilities, and difficulties in acquiring relevant competence, particularly among smaller municipalities.
Despite these challenges, the NIS2-Directive is broadly viewed as a necessary step toward improving cybersecurity awareness and resilience. Organisations that already align with frameworks such as ISO 27000 report an easier adaptation process. The study highlights the need for clearer guidance, stronger institutional support, and improved communication from Swedish authorities to facilitate effective implementation. This study contributes valuable insights into the real-world impact of the NIS2-Directive in Sweden and offers practical recommendations to help organisations to strengthen their cybersecurity work ahead of the directive’s enforcement.
Place, publisher, year, edition, pages
2025. , p. 75
Keywords [en]
NIS2-directive, information security, cybersecurity, Europe, Sweden, compliance, regulation, companies, municipalities
National Category
Information Systems, Social aspects
Identifiers
URN: urn:nbn:se:his:diva-25618OAI: oai:DiVA.org:his-25618DiVA, id: diva2:1985767
Subject / course
Informationsteknologi
Educational program
Network and Systems Administration
Supervisors
Examiners
2025-07-282025-07-282025-09-29Bibliographically approved