cyberspace

Important Lessons for Sweden from the Cyber War in Ukraine

The MSB's report highlights the importance of strengthening Sweden's cybersecurity, with lessons from Ukraine's cyber defence against Russia. The report recommends improved procedures and collaborations to counteract cyber incidents.

Important Lessons for Sweden from the Cyber War in Ukraine
In MSB's report "When War Came Close – Annual Report on IT Incidents 2022," important lessons are highlighted on how Sweden should improve information and cyber security. Making the digital infrastructure more robust is crucial for the Swedish total defence.

In 2022, 330 IT incidents were reported to MSB. This is fewer than in 2021, when 343 incidents were reported. The number of incident reports from authorities decreased from 261 in 2021 to 231 in 2022, while reports from other critical societal functions increased from 82 in 2021 to 99 in 2022.

– The fact that fewer incidents are reported likely does not mean that fewer incidents occur; there is a dark figure that may be due to, for example, incomplete routines, fear that the trust in the operation may be questioned, lack of time, or a desire to avoid police reports. MSB wants to see more reports in 2023 and urges all organisations obliged to report to take their responsibility. The more information MSB receives about IT incidents, the better we can support preventive work, says Mathias Antonsson, senior officer in the department for cyber security and secure communications at MSB.

Many IT incidents can be avoided

Of the IT incidents reported to MSB in 2022, 41 percent were due to system errors, 26 percent to mistakes, and 12 percent to some form of attack. MSB's assessment is that many of the incidents could be avoided with better routines and staff competence development.

– The fundamental systematic information and cyber security work must be prioritised higher and allocated more resources by organisations within critical societal functions. Reviewing all conceivable risks and making plans for continued operations if something happens makes a big difference in the impact of an incident. If critical services do not function, it can lead to serious consequences for citizens, says Charlotte Petri Gornitzka, Director General at MSB.

Theme on cyber warfare against Ukraine

The report includes a theme on Ukraine's defence against Russia's cyber warfare, a cyber war that has highlighted the importance of a resilient cyber defence in Sweden as well.

– The cyber attacks against Ukraine have largely been countered, and important societal functions have been maintained or quickly restored, something largely explained by good preparations where cooperation with other states and companies has been crucial. Sweden has much to learn there; we need to cooperate to make the digital infrastructure more robust and able to withstand serious cyber incidents, says Johan Turell, head of the department for cyber security and secure communications at MSB.

Measures for a strengthened cyber defence in Sweden

By mapping supply chains, avoiding dependencies on individual services, strengthening relevant collaborations, and planning for all kinds of risks, organisations can limit the effects of IT incidents. MSB presents several recommendations in the report to strengthen information and cyber security in Sweden. It mainly concerns three areas:

  • MSB needs to be able to demand more information from critical societal functions and be given an expanded mandate to act on risks and vulnerabilities.
  • Several investigations need to be conducted to clarify the missions and powers of central authorities related to cyber defence.
  • MSB suggests, for example, that all critical societal functions should be subject to comprehensive information security requirements, which could be achieved by expanding the scope of the upcoming NIS2 regulation.

– Despite relatively few reported cyber attacks in Sweden, the risks should not be underestimated, especially in connection with the serious international situation. Being able to withstand serious cyber attacks is an important part of total defence since cyber attacks pose a constant threat to all parts of society. If information and cyber security work is prioritised and resourced, Sweden has the opportunity to be much better prepared in a short time than today, says Åke Holmgren, head of the department for cyber security and secure communications at MSB.

FAQ

Hur kan Sverige förbättra sin cybersäkerhet enligt MSB?
Sverige kan förbättra sin cybersäkerhet genom att prioritera systematiskt informations- och cybersäkerhetsarbete. MSB betonar vikten av att tilldela mer resurser och se över risker. Att stärka samarbeten och planera för olika risker är också avgörande. Senast faktagranskad: 2025-09-21.
Vad lärde sig Sverige från cyberkriget i Ukraina?
Sverige lärde sig vikten av ett motståndskraftigt cyberförsvar från Ukrainas erfarenheter. Cyberangreppen mot Ukraina kunde motverkas tack vare goda förberedelser och internationellt samarbete. Sverige behöver stärka sin digitala infrastruktur för att stå emot cyberincidenter. Senast faktagranskad: 2025-09-21.
Varför är det viktigt att rapportera it-incidenter till MSB?
Det är viktigt att rapportera it-incidenter till MSB för att förbättra det förebyggande arbetet. Fler rapporter ger MSB bättre möjligheter att stötta samhällsviktiga verksamheter. Ofullständiga rutiner och rädsla för förtroendeförlust kan påverka rapporteringen. Senast faktagranskad: 2025-09-21.
När minskade antalet rapporterade it-incidenter i Sverige?
Antalet rapporterade it-incidenter i Sverige minskade under 2022 jämfört med 2021. Under 2022 rapporterades 330 incidenter, medan 343 rapporterades 2021. Minskningen kan bero på mörkertal och ofullständiga rutiner. Senast faktagranskad: 2025-09-21.
Vilka åtgärder föreslår MSB för att stärka Sveriges cyberförsvar?
MSB föreslår att stärka Sveriges cyberförsvar genom att kartlägga leverantörskedjor och undvika beroenden. De rekommenderar också att utöka MSB:s mandat och genomföra utredningar för att tydliggöra myndigheters uppdrag. Ett utvidgat tillämpningsområde i NIS2-regleringen föreslås. Senast faktagranskad: 2025-09-21.