Insights
Insights and news
Analysis, guides and news on information security, data protection, cybersecurity and regulatory compliance.
Latest news
- When is an information security consultant enough, and when do you need an interim CISO?Sometimes a senior consultant for a defined task, sometimes an interim CISO leading the security work for a period. Kristensson i Skåne offers both – with local presence in Malmö, Lund, Helsingborg and the rest of Skåne.
- When do you need an external GDPR consultant, DPO support or a DPIA?GDPR work does not have to be a constant documentation project. Senior consulting in GDPR, DPO support and DPIA – structured, completed and possible to maintain over time. Clients across Sweden, with local presence in Skåne.
- IT consultant in Malmö, Lund and Helsingborg with a focus on secure Microsoft 365Microsoft 365 is at the heart of everyday work – but identity, email, sharing and logging need to be configured correctly. Kristensson i Skåne helps companies in Malmö, Lund, Helsingborg and the rest of Skåne with a security-oriented review of Microsoft 365.
- New partner – NimblrKristensson i Skåne AB has partnered with Nimblr and now offers their security awareness services as part of our overall security portfolio. Nimblr is a Swedish-built security awareness… Read more: New partner – Nimblr
Latest insights
- Why IT and security projects stall – five problems that are rarely technicalMandate, target state, business resources, dependencies and handover into operations. Five reasons IT, security and regulatory projects grind to a halt.
- When does an organisation need a data protection officer? How to make a documented DPO assessmentMust you designate a data protection officer? The Article 37 obligation depends on what you do with personal data, not on company size. How to assess core activities, monitoring, special categories and scale, and document the answer.
- Interim IT manager or IT consultant – which support does the business actually need?Sometimes the problem is not a lack of technical expertise but a lack of IT leadership. On mandate, supplier management, IT strategy, scope and handover.
- Microsoft 365 backup – what Microsoft protects and what you need to own yourselfMicrosoft 365 has built-in recovery, but it does not replace a considered backup strategy. On Exchange, OneDrive, SharePoint, Entra, RPO and RTO, and how recovery should be tested.
- Information classification with Microsoft Purview – from classification model to actual protectionHow to turn a classification model into Microsoft Purview: sensitivity labels, content marking, encryption, container labels, auto-labelling, DLP and licensing.
- Management training under the Swedish Cybersecurity Act and DORA – what is actually requiredThe Swedish Cybersecurity Act and DORA both require management to be trained. What the requirements mean, where they differ, what the training should contain and how to document it for supervision.
Guides
- How close to ISO 27001 are you? A quick check with or without Annex AA quick check against ISO 27001: 12 questions on the ISMS, or 20 with Annex A. The result appears straight away, red to green, with suggested next steps.
- Are your products ready for the CRA? A self-test in 20 questions20 questions for manufacturers show how far you have come with the Cyber Resilience Act: secure development, vulnerabilities, reporting and documentation.
- How far have you come with DORA? A self-test in 20 questions20 questions in five areas show how far you have come with DORA: governance, ICT risk, incidents, testing and third-party risk. See the result straight away.
- Are you ready for the Swedish Cybersecurity Act? A self-test in 20 questions20 questions in five areas show how far you have come with the Swedish Cybersecurity Act and its regulations. The result appears straight away, red to green.
- Are your GDPR basics in place? A self-test in 20 questions20 questions in five areas show whether the basics of your GDPR work are in place. Takes 15 minutes and shows the result straight away, red to green.
- What does a gap analysis against ISO 27001 and the Cybersecurity Act (NIS2) cost?A defined gap analysis against ISO 27001 or the Swedish Cybersecurity Act (NIS2) normally costs from around SEK 25,000 excluding VAT. Scope, depth and purpose decide. How to compare quotes.
















