Guides
Practical walk-throughs for anyone facing a decision: are we in scope, what should we ask a supplier, and how do we compare the answers.
The guides are written for someone standing in front of a concrete choice who needs to move forward without first reading an entire regulation. They take one question at a time — whether the Swedish Cybersecurity Act applies to you, what management needs to be able to answer, how to compare quotations for an external data protection officer — and work through it in the order the question actually arises.
They are deliberately independent of us as a supplier. A guide whose only conclusion is that you need to hire us is a brochure, and it helps nobody decide anything. Where a question has several reasonable answers, all of them are there; where the answer depends on your situation, it says what it depends on. If you want help afterwards we are here, but the guide should be usable without it.
All guides
- Are we affected by the Swedish Cybersecurity Act? A simple self-assessmentFive steps to assess whether your organisation is affected by the Swedish Cybersecurity Act: sector, size, public administration, DORA and the essential or important category.
- The Swedish Cybersecurity Act: ten questions for managementTen questions a management team or board should be able to get answers to under the Swedish Cybersecurity Act and the regulations in force since 1 October 2026, with what a good answer contains.
- External data protection officer: how to compare providersDo you have to appoint a DPO, what may the role do, internal or external, and eight criteria for comparing providers of an external data protection officer.
- How to choose a data protection consultantA buyer’s guide: when you need a data protection consultant, what to require as deliverables, seven questions that reveal the differences between providers and the warning signs.
Looking for analysis and news instead? Those are collected under Insights and news.




