Five common mistakes in working with the Cybersecurity Act and NIS2

Five common mistakes in working with the Cybersecurity Act (NIS2)

The Swedish Cybersecurity Act is in place. The question is less about when NIS2 arrives and more about how the requirements become effective security work. Here are five common mistakes that create a lot of documentation but too little actual risk reduction.

Summary: The Swedish Cybersecurity Act is already in place. For the organisations concerned, the question is therefore less and less about when NIS2 is coming and more and more about how the requirements become effective security work. Here are five common mistakes that risk creating a lot of documentation – but too little actual risk reduction.

The Swedish Cybersecurity Act, which implements NIS2, has been in force since 15 January 2026. The requirements mean, among other things, that affected entities need to work systematically and in a risk-based way with cybersecurity and take appropriate security measures. Management also has a clear responsibility to govern and follow up on the work.

On paper, it is fairly simple to describe.

In practice, however, a number of recurring problems arise.

Here are five we often think are especially important to avoid.

1. Building a separate “NIS2 project”

It is understandable.

A new regulation arrives, a project group is created and someone is tasked with “implementing NIS2”.

The problem arises if the result becomes yet another security track alongside the organisation’s ordinary governance.

According to the new regulations, the cybersecurity work should be integrated with the organisation’s existing way of leading and governing the business. It should include an ongoing cycle where requirements and risks are identified, security measures are introduced, results are followed up and the work is improved.

For organisations that already work with, for example, ISO 27001, information security, risk management, GDPR, continuity or internal governance, the starting point is therefore not to begin again.

Better questions are:

  • What do we already have that works?
  • Which requirements are already covered?
  • Where are the real gaps?
  • What needs to be added?

A separate project can be necessary to get implementation going. A separate permanent governance system is rarely the goal.

2. Starting with a checklist instead of with the risks

There are plenty of checklists for NIS2.

They can be useful for creating structure, but become problematic if the organisation starts there and treats all measures as equally important.

The Cybersecurity Act and the regulations are based on a risk-based approach.

The risk analysis should, among other things, take into account information classification, threat monitoring, incidents and near misses. The risks should be evaluated based on consequence and likelihood, and the organisation needs criteria for risk acceptance.

That means two organisations may need to prioritise entirely different things:

  • For one, the biggest risk may be identity and access management.
  • For another, it may be an old OT environment.
  • For a third, it is dependence on a critical cloud or operations provider.
  • For a fourth, it is a lack of recovery capability.

The checklist helps ask the questions. The risk analysis determines what you need to do first.

3. Making cybersecurity the IT department’s responsibility

IT obviously has a central role in the cybersecurity work. But IT cannot own the organisation’s risks on its own.

Management is responsible for governing the organisation’s cybersecurity work so that it is conducted systematically and in a risk-based way. The new rules also place requirements on management’s knowledge and ability to set goals, assess security measures and follow up on implementation.

In practice, the work therefore needs to involve more than IT:

  • business owners
  • information and system owners
  • information security
  • risk and compliance
  • data protection
  • procurement and supplier owners
  • continuity and crisis functions
  • management and the board

A technical vulnerability can mean a business risk. A supplier contract can create a cyber risk. A continuity gap can have greater consequences than the technical incident that triggers it.

That is why the risks need to be owned where the consequences actually lie.

4. The gap analysis becomes the final deliverable

A current-state or gap analysis is often a very good first step.

It helps the organisation understand what already exists, which requirements are not addressed and which areas need to be developed.

But a gap analysis solves nothing on its own. The real value comes when each important shortcoming is linked to:

  • a risk
  • a priority
  • a concrete measure
  • an owner
  • a realistic timeline
  • a method for follow-up

The new regulations point in the same direction. Identified risks should lead to security measures, and the action planning should clarify, among other things, responsibility and when security measures are to be implemented. Follow-up and improvement are then part of the ongoing work.

A report with 70 identified gaps but no prioritisation therefore risks only giving the organisation 70 new problems.

A good analysis should make the next decision easier. It should be able to say:

  • This you need to solve now.
  • This needs to be planned.
  • This can wait.

5. Thinking the work is done once the controls are in place

This is perhaps the most long-term problem.

The organisation has done the analysis. The policies are decided. MFA is enabled. Backup exists. The supplier contracts have been updated. The incident plan is on SharePoint. And then the organisation moves on.

But security work changes all the time. New systems are introduced. Suppliers switch subcontractors. Staff change roles. Permissions grow. New vulnerabilities are discovered. The threat landscape changes.

That is why the Cybersecurity Act does not stop at measures being introduced. The organisation also needs to follow up and evaluate whether the security measures are still appropriate and proportionate. For sector-critical systems, such follow-up should take place when needed and at least annually. The regulations mention review, measurement, tests, self-assessment and internal and external audit as possible methods.

The same applies to continuity and suppliers. Alternative ways of working and recovery need to be exercised. Critical suppliers need to be followed up throughout the contract period. Risk analyses need to be updated when threats and vulnerabilities change.

Compliance is therefore not an end state. It is a management responsibility over time.

From NIS2 project to effective security work

The five mistakes really have the same underlying problem. The organisation focuses on getting done. But effective cybersecurity work is never really finished.

The goal should instead be an organisation where:

  • management understands the risks and makes relevant decisions
  • the business owns its risks
  • security measures are prioritised according to real needs
  • incidents and disruptions can be handled
  • critical suppliers are known and followed up
  • controls are verified
  • identified shortcomings lead to improvement

That is also why the NCSC describes the work as systematic, risk-based and continuous rather than as a list of measures to be ticked off once.

How Kristensson i Skåne works

At Kristensson i Skåne, we work with the Cybersecurity Act/NIS2 as part of the organisation’s overall information security and risk work.

It can start with a scoping assessment or gap analysis, but our focus is just as much on what happens after the analysis.

We can support with, among other things:

  • current-state and gap analyses
  • risk assessment and prioritisation
  • establishing and developing an ISMS
  • governance documents, roles and responsibilities
  • technical and organisational security measures
  • incident and continuity handling
  • supplier review and third-party risk
  • management support and reporting
  • training
  • testing, follow-up and internal control
  • ongoing GRC and CISO support

Our starting point is that the security work needs to be proportionate.

A smaller company should not build the same organisation as an international group. But the security measures need to match the business’s risks, dependencies and requirements.

The Cybersecurity Act should therefore not result in yet another package of documents produced ahead of an audit or supervision. It should help the organisation become better at understanding its risks, preventing incidents, handling disruptions and making the right decisions when something actually happens.

That is where compliance starts to create business value.

Would you like to take your NIS2 work from project to effective security work? Read more about our work with information security and governance or contact us and we will have a first conversation about your current state and next steps.

Sources and further reading: the Swedish National Cybersecurity Centre (NCSC) and the Swedish Government on the Cybersecurity Act, and MCFFS 2026:11. This is an overview and not legal advice.