Reference Cases

At Kristensson i Skåne AB, we deliver practical value in IT, information security, cybersecurity, and data protection through senior expertise and a structured approach. We support organizations in planning, structuring, implementing, and protecting their IT environments, always tailored to business needs. Working across the full scope from strategy and architecture to information security management, technical cybersecurity, privacy and compliance, we bring structure, clarity and practical progress, whether through senior advisory or hands-on delivery. Below are nine anonymized reference cases that demonstrate the breadth of our services, our professional approach, and the tangible outcomes we have delivered for clients.

Project Manager for DORA Implementation

For a large insurance company, Kristensson is guiding the implementation of the EU’s Digital Operational Resilience Act (DORA) requirements. We began by mapping the new regulatory requirements to the client’s current operations and identifying gaps that needed to be addressed. Based on this analysis, we developed a comprehensive roadmap for compliance, outlining initiatives across technology, processes, and governance. Our consultants are working closely with the client’s internal teams to execute key parts of the plan, for example, strengthening IT risk management practices and improving incident response capabilities. By providing targeted expertise and support on critical tasks, we ensure the DORA implementation stays on track and meet all deadlines. As a result, the insurance company is significantly improving its operational resilience to comply with DORA.

Cybersecurity & IT Security Implementation

For a mid-sized company in the security sector, Kristensson conducted a comprehensive IT risk analysis to identify vulnerabilities. We then developed a clear action plan to strengthen the firm’s cybersecurity posture. Now on a retainer basis, our security expert collaborates with the internal IT team each week to co-implement these improvements. This involves updating security policies, deploying new technical controls, and regularly reviewing progress during scheduled check-ins. By providing continuous guidance and working hand-in-hand with the client’s staff, we ensure that security enhancements are effectively integrated into daily operations. As a result, the company has significantly reduced its risk exposure and established a sustainable security practice supported by both internal and external expertise.

Third-Party Risk Management
(IT & InfoSec)

For a financial institution, Kristensson provided expertise to strengthen the organization’s third-party risk management framework. We reviewed and enhanced how the financial institution assesses and oversees its suppliers and service providers. This included maintaining and implementing a robust process for initial risk evaluation, ongoing vendor monitoring, and clear reporting on third-party risks. A key focus was integrating business continuity planning (BCP) into vendor management, ensuring the organization is prepared for any disruption in a supplier’s services. We also helped develop detailed exit plans for critical providers so the financial institution can smoothly transition or replace services if needed, without impacting operations. These measures have given the organization greater confidence in its vendor resilience and ensured compliance with regulatory expectations on third-party risk.

Implementation of
ISO 27001 ISMS

Kristensson is currently supporting a small software development firm in building an Information Security Management System (ISMS) aligned with ISO 27001. The engagement began with a detailed risk assessment to identify key information assets, potential threats, and areas for improvement. Based on these insights, we are now helping the client define and implement policies, controls, and governance processes that meet ISO 27001 requirements and fit their business. Our consultants work closely with the internal team, providing structure, templates, and expert guidance throughout each step of the process. The project is progressing steadily, with several foundational elements already in place. As the engagement continues, we are supporting the client through implementation and preparation for future certification. The result will be a fully operational, audit-ready ISMS that strengthens their overall security posture and meets growing customer and regulatory expectations.

Data Protection Maturity Program

For a medical technology company, Kristensson helped establish a structured data protection program to improve their privacy practices. We started by assessing the company’s existing privacy procedures and compliance against regulatory requirements and industry best practices. Based on this maturity assessment, we created a detailed roadmap outlining steps to strengthen their data protection governance. Our team then assisted in implementing key initiatives, such as developing clear data management policies, introducing regular privacy impact assessments, and providing staff training on GDPR. We also helped set up governance structures like a data protection committee and scheduled compliance reviews to ensure privacy practices are sustained over the long term. As a result, the company significantly improved its data protection maturity, reducing compliance risks and fostering greater trust with customers and regulators.

Trusted Advisor
(Strategy, Delivery & Operations)

For a global healthcare company, Kristensson has been a trusted IT partner through a multi-year engagement. Over several years, we have provided consistent support across the client’s IT operations, blending strategic advisory services with hands-on managed IT services. The partnership began with high-level IT consulting and gradually expanded to include managing key IT functions and projects as a long-term service provider. Our team works closely with the client’s internal IT department, advising on technology strategy, optimizing processes, and ensuring day-to-day operations run reliably. As part of our managed services role, we take on specific operational tasks and projects (from infrastructure maintenance to project implementation), allowing the client’s staff to focus on core initiatives. This ongoing collaboration has given the company a stable, expert-led IT environment and guidance, supporting their global growth and innovation.

IT Manager

For a small company (around 35 employees), Kristensson provides an IT Manager to oversee IT operations and strategy. This ongoing role is fully integrated into the client’s organization, ensuring day-to-day IT services run smoothly and all user support needs are met. In addition to managing daily operations, our IT Manager drives key technology projects to support the company’s growth.
For example, we have led the planning and rollout of a new planning system, modernizing the client’s core business processes. By delivering consistent leadership and technical expertise, Kristensson has helped stabilize the client’s IT environment and improve end-user satisfaction. The client’s management can focus on their core operations, confident that a senior IT professional is handling their technology needs.

Independent Review of IT and Security

Kristensson was engaged by a semi-governmental organization in the insurance sector to conduct an independent review of their outsourced IT operations. The client had several strategic and regulated services managed by external suppliers, and sought a third-party assessment of how these operations were governed and delivered from an IT and information security perspective.
Our consultants performed a structured review, covering areas such as contractual responsibilities, operational maturity, compliance with security frameworks, and alignment with internal policies. This included document analysis, interviews, and technical review sessions with both the client and its suppliers. We assessed whether critical functions were being delivered in a secure and resilient way, and identified potential gaps in governance, risk management and supplier oversight.
The result was a set of clear, actionable recommendations to improve control, reduce risk, and clarify roles between client and supplier. The review provided valuable assurance to internal stakeholders and served as a foundation for future improvements in third-party management.

Managed IT Services for Municipal Infrastructure Provider

Kristensson supports a municipally owned company operating in the communications infrastructure sector by managing key parts of its IT environment. We are responsible for the operations and maintenance of the organization’s network infrastructure and monitoring platform, which are critical to ensuring uptime and service quality across their operations.
Our role includes daily operational responsibility, technical support, and continuous development of these services. This involves monitoring network performance, handling incidents, implementing improvements, and ensuring the platforms are secure, up to date, and aligned with best practices. We work closely with the client’s internal team, providing both proactive management and reactive support as part of a long-term service engagement.
Through this partnership, the client benefits from a stable, well-maintained infrastructure, improved visibility into operational status, and a reduction in reactive troubleshooting. By combining technical expertise with structured delivery, Kristensson ensures these core IT functions remain reliable and resilient – forming a secure foundation for the company’s broader service delivery.