Management cybersecurity training
The Swedish Cybersecurity Act makes security a management responsibility, and from 1 October 2026 regulations on security measures and management training apply. We train your management team and board in what the requirements mean for your organisation, and document the attendance.
Who it is for and when
The training suits management teams and boards in organisations affected by the Swedish Cybersecurity Act, and organisations that want management to understand its responsibility even without a legal requirement.
- You are affected by the Swedish Cybersecurity Act and need to show that management has been trained.
- Management has to approve risk assessments and security measures but lacks the basis to ask the right questions.
- The board wants to understand what a supervisory case or a serious incident would actually mean.
- You have a technical security function but the decision paths up to management are unclear.
What we do
- Tailored to your organisation. We go through which sector you belong to, whether you are an essential or important entity, which services are in scope and which risks are yours.
- The training session. Half a day with management and the board: the legal requirements, the areas covered by the regulations, management’s own responsibility, the reporting duty and what supervision involves.
- Your own risk picture. We use your real systems, suppliers and dependencies as examples, not generic scenarios.
- Decision points. We go through what management needs to decide and follow up, and how it is documented so that it holds up under review.
- Documentation. Attendance list, agenda, materials and a short summary you can add to your governing documents.
You get
- A half-day training session for management and the board, tailored to your organisation
- Materials and slides that are yours to keep
- Documented attendance with agenda and attendance list
- A list of decision points for management
- Answers to your questions after the session
Scope and price
A defined engagement: preparation, one half-day session and documentation afterwards. Where several companies or administrations are involved we set it up as a series of sessions.
The price varies from engagement to engagement and depends on how many people are to be trained, how many organisations are in scope and how much tailoring is needed. You get a clear proposal after the first conversation.
How it works
- A first conversation. We listen to your situation and explain how we usually set the work up. You get our assessment straight away, at no cost.
- A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
- Delivery and handover. We work alongside your organisation, report as we go and hand over so that you can manage the result yourselves.
Frequently asked questions
Is management training a legal requirement?
The Swedish Cybersecurity Act places responsibility for the systematic security work with management, and the regulations on security measures and management training (MCFFS 2026:11) apply from 1 October 2026 to essential and important entities. The training must be possible to demonstrate under supervision.
Who should attend?
The management team and the board, plus those who decide on budget, procurement and outsourcing. Security and IT leads are welcome, but the session is aimed at the decision makers.
Is half a day enough?
For management to understand its responsibility, ask the right questions and know what has to be decided, yes. If you want to go deeper into risk and continuity work we add a session or combine it with an exercise.
What does it cost?
It varies from engagement to engagement and depends on the number of participants, the number of organisations and how much tailoring is needed. We give a clear proposal after the first conversation.
Would you like your management trained before 1 October?
Contact us