OWN THE FUTURE · SEASON 1 · TECHNOLOGICAL BREAKTHROUGH
What is cybersecurity? Counted in Swedish incidents
Cybersecurity means that only the right people can read, that nobody changes anything without permission, and that systems work when they are needed. We explain what counts as an incident and how incidents are counted in Sweden.
Published 9 Sep 2026 · About 9 minutes to read
You log in to your bank with your phone. You pay in a shop with your card. You get a text message about a parcel you have not ordered. Cybersecurity is involved in all three cases, and in the third case you yourself are the security system.
The word is used for everything from state intelligence services to the password on your router. This article explains what the word means, counts how many incidents are reported in Sweden and to whom, and shows what causes them. The answer to the last question is not what most people expect.
What the word means: three things that must hold
Cybersecurity is the umbrella term for the work of protecting networks, information systems and their users against threats, and information security is the part of that work that deals with the information itself.1, 15 And information security has a definition that is surprisingly simple once it has been translated.
The US standards agency NIST defines information security as keeping information and information systems safe from unauthorised access, use, disclosure, disruption, modification or destruction, in order to achieve three properties: confidentiality, integrity and availability.5, 7, 8 The same three properties are the core of the definition in the ISO/IEC 27000 family of standards, where the vocabulary sat in the family's overview document until the summer of 2026.9
Take them one at a time, with everyday examples.
Confidentiality means that only the people allowed to read something can read it. Your doctor should be able to read your medical records, not your neighbour.
Integrity means that nobody has changed anything without permission. The amount on the invoice should be the amount the sender wrote, not a different one.
Availability means that the system works when it should. A health centre that cannot reach its patient records on a Monday morning has a security problem, even if nobody has stolen anything.
The last example matters, because it shows that cybersecurity is about more than attackers. A system that stops working because of a software bug is a security incident, just like a break-in.1 It is one of the reasons the statistics below look the way they do.
How many incidents are reported in Sweden?
Sweden has had a duty to report for several years: government agencies and providers of essential services, for example in healthcare, drinking water and transport, must report serious IT incidents to an agency.1 In 2025 the reports were received by the Swedish Civil Contingencies Agency, which changed its name at the turn of the year to the Swedish Civil Defence Agency, and the agency compiles them itself in an annual report.1, 10
In 2025, 266 cyber incidents were reported, from 95 different organisations.1 Of the reports, 122 came from government agencies and 144 from providers of essential and digital services.1
cyber incidents were reported to the Swedish Civil Contingencies Agency in 2025, from 95 organisations. The year before, there were 319 reports from 163 organisations.
Source: Swedish Civil Defence Agency, annual report on cyber incident reporting 2025Over four years the number of reports was fairly stable and then fell: 330 reports in 2022, 333 in 2023, 319 in 2024 and 266 in 2025.1 Government agencies account for the whole fall: from 231 reports in 2022 to 122 in 2025.1 Reports from providers rose from 99 in 2022 and have since stayed at about the same level: 144, 149 and 144.1
Two things to know before you draw conclusions from the curve.
The first is that the reports come from a small share of all organisations. In 2025, 16% of the government agencies with a duty to report reported at least one incident, and among providers the agency estimates the share at 9%.1 The agency points out that many incidents still go unreported.1 So fewer reports do not necessarily mean fewer incidents.
The second is who reports. Of the reports from providers, 80% came from healthcare, 13% from the drinking water sector and 4% from the transport sector.1 Healthcare is the sector that reports the most, which is not the same as being the most exposed.1
Most reported incidents are not attacks
The causes behind the incidents
Here is the figure that tends to surprise people. Of all incidents reported in 2025, 9% were cyberattacks.1 The year before, the share was 20%.1
The rest had other causes. The most common causes given were unknown cause, followed by mistakes and system failures.1 The agency's own analysis is that the unknown causes can usually be traced to system failures when you look more closely.1
The agency sorts the causes into four groups: mistake, attack, system failure and natural event.1 On top of these comes a fifth, unknown cause, which has gone from 12% of reports in 2022 to 32% in 2025.1
The agency cannot say for sure what is behind the rise, but it points to the reporting rather than to the threats. It has read the free-text answers in the reports and found that the organisation often knows the cause, but the person filling in the form still ticks unknown.1 A common case is software that does not start properly after a planned security update.1 The fault can be pinpointed, but what triggered it cannot be established exactly, so the answer becomes unknown.
Among the causes that are given, changes made to the organisation's own IT systems account for the largest share of both the mistakes and the system failures.1
The incident often comes from a supplier
Just over 44% of the reports in 2025 were about incidents that started at a supplier and then hit the organisation buying the service.1 The year before, the share was 51%.1
That fits the definition at the start. A system that stops working because an update went wrong can be an incident that must be reported, if it hits an organisation covered by the rules and reaches the agency's threshold. It happens more often than someone breaking in. The picture of cybersecurity we get from films, a person in a hood in front of a screen, describes barely a tenth of everything that is reported.1
Personal data is counted somewhere else, and the figures must not be added together
There is a second count in Sweden, at the Swedish Authority for Privacy Protection. Organisations must notify it when personal data has gone astray, for example if a file with customer details has been sent to the wrong person or leaked in a break-in.2, 11
In 2025 the Swedish Authority for Privacy Protection received 12,276 personal data breach notifications.2, 11 That is a rise of almost 90% on 2024, and the highest number since the General Data Protection Regulation took effect in 2018.2 In total the authority registered about 28,300 cases during the year, against about 18,100 the year before, and complaints from individuals more than doubled.11
The authority itself names one main reason for the volume. It is break-ins at organisations that have many other companies and agencies as customers.2, 11 When such a supplier is hit, each of its customers reports separately, and in the 2025 case data on a large part of Sweden's population was published on the dark web after an extortion attempt.2, 11
Do not add 266 and 12,276 together. The two figures measure different things at different agencies, with different rules on who must report. The first is serious IT incidents at organisations with a duty to report. The second is events where personal data has been mishandled, with a much lower threshold. Breaches that are unlikely to pose a risk to people's rights do not have to be reported.11 The same break-in can appear in both counts, once as an IT incident and many times as a personal data breach.1
The fraud that hits you as a private person
Neither of the two counts above is about ordinary people. That count is kept by the Swedish National Council for Crime Prevention, which compiles all reported crimes.
Fraud in the reported crime figures
In 2025, 1,439,163 crimes were reported in Sweden, 3% fewer than in 2024.3, 12 Fraud went the other way and rose by 1%, to 232,862 reported offences.12 That means 16% of all crimes reported in 2025 were fraud, worked out as 232,862 divided by 1,439,163.12
of all crimes reported in Sweden in 2025 were fraud offences: 232,862 of 1,439,163. The type that rose most was card fraud without a physical card, up 8,867 offences in one year.
Source: Swedish National Council for Crime Prevention, Reported crimes 2025, final statisticsThe type of fraud that rose most was card fraud without a physical card, that is, when someone uses your card details online without holding the card: up 8,867 offences, or 10%.12 Advert fraud and card fraud with a physical card fell the most, by 3,207 and 3,025 reported offences respectively.12
How it looks to the people targeted
Seen from the other side, from the people targeted, it looks different. The Swedish Internet Foundation's survey Svenskarna och internet 2025 (Swedes and the internet 2025) gives some figures. Six in ten internet users aged 16 and over have seen a scam advert on social media in the past year.13 3% say they have also been victims of advert fraud, and men of retirement age are the group hit most often, twice as often as the average.13 Only a third of those who have seen a scam advert have reported it to the platform, and older people are the least likely to report.13
Fraud also costs people who do not fall for it. A third of Swedes have held back from buying a product they were interested in, because they suspected it was shown in a scam advert.13 And the most common way to spot a scam advert is the oldest of all: the offer seems too good to be true.13
The survey is based on 3,362 respondents, most from a randomly recruited panel and the rest from extra telephone interviews, collected in January 2025 and weighted to match the population by sex, age, education and region, among other things.14 That is an unusually clear account of method, and it is why the figures are here.
The law that has just come into force
On 15 January 2026 the Cybersecurity Act came into force.15, 17 It is how Sweden puts the EU's NIS2 Directive into law, and it greatly widens the duty to report.15, 16 The agency estimates that 2,000 or more organisations are covered by the new law, against about 600 companies covered by the earlier legislation.1
At the same time the job has moved. On 1 July 2026 the public-facing cyber remit moved to the National Cyber Security Centre, part of the National Defence Radio Establishment, which takes over collecting the reports that the annual report is based on.1, 17 The agency itself writes that the next annual report will be published by the new centre, with more organisations with a duty to report behind the figures.1 Anyone comparing 2026 with 2025 needs to keep this in mind, because more reports in the next count could just as well mean more organisations reporting as more incidents.
What to take away
Cybersecurity means that only the right people can read, that nobody changes anything without permission and that the system works when it should. In 2025, 266 serious incidents were reported to the receiving agency, barely a tenth of them attacks, while personal data breaches are counted separately, 12,276 of them, and reported fraud offences numbered 232,862.1, 2, 12 The structure behind the figures is that the most common reported incident is dull: a system that stops working, a file that goes the wrong way. At the same time the requirements are widening. Since January 2026 a law has applied that, according to the agency's estimate, covers 2,000 or more organisations, against about 600 companies under the earlier legislation.1 Follow three recurring publications: the annual report on cyber incidents, the Swedish Authority for Privacy Protection's February figures and the Council for Crime Prevention's final crime statistics in March.1, 2, 3
The next episode is S1:E4 Semiconductors, about how a chip is made and what Moore's law really says.
Education, not advice.
The fund
Behind the library stands a fund.
Own The Future is published by AIX. The library is the knowledge; AIX Dynamic is the tool, a systematic securities fund (UCITS) that follows the trend and steps aside when risk rises.
This is marketing. Fund units can both rise and fall in value. Read the key information document (KID) and the prospectus before you invest; you will find them on the fund's page at Avanza.
34 UNITHOLDERS · AS OF 15 SEP 2026The future in your inbox.
The most important things from each area, without the noise and without the hype.
Sources
- Swedish Civil Defence Agency (Myndigheten för civilt försvar), Cyberangreppens utveckling 2023 till 2025: Årsrapport cyberincidentrapportering 2025 (Trends in cyberattacks 2023 to 2025: annual report on cyber incident reporting 2025), publication number MCF0108, March 2026. The report is hosted at ncsc.se, which took over the remit on 1 Jul 2026. Number of reports per year and sector, causes, share of cyberattacks, unreported incidents, the Cybersecurity Act and the transfer to the National Cyber Security Centre.
- Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten), Rekordmånga personuppgiftsincidenter under 2025 (A record number of personal data breaches in 2025), published 20 Feb 2026, and the authority's annual report for 2025. Number of reported personal data breaches, cases and complaints in 2025.
- Swedish National Council for Crime Prevention (Brottsförebyggande rådet), Anmälda brott 2025 (Reported crimes 2025), final statistics published 31 Mar 2026, bra.se. Total number of reported crimes, and fraud offences by type.
- Swedish Internet Foundation (Internetstiftelsen), Svenskarna och internet 2025 (Swedes and the internet 2025), chapters 1 and 4. Scam adverts, who is targeted and how willing people are to report. The report is CC BY 4.0.
- NIST Computer Security Resource Center, glossary, "information security", the definition from FIPS 200 and 44 U.S.C. 3552: confidentiality, integrity and availability.
- ISO/IEC 27000, Information technology, Security techniques, Information security management systems, Overview and vocabulary. Information security is defined as preserving confidentiality, integrity and availability.
- National Institute of Standards and Technology, FIPS PUB 200, Minimum Security Requirements for Federal Information and Federal Information Systems, March 2006. Supports the definition the article gives, and shows that the agency itself traces it to the statute.
- United States Government Publishing Office, United States Code, 2024 Edition, Title 44, Section 3552, Definitions. Supports that the statutory definition of information security in force is in 3552 b 3, and that it lists integrity, confidentiality and availability in that order.
- ISO and IEC, ISO/IEC 27000:2026, Information security, cybersecurity and privacy protection, Information security management systems, Overview, sixth edition, published 3 Jul 2026. Supports that, according to the publisher, the sixth edition has been reworked into an overview document and no longer serves as a terminology document. Replaces the address in entry 6.
- Government Offices of Sweden (Regeringskansliet), Startskott för Myndigheten för civilt försvar (Launch of the Swedish Civil Defence Agency), press release 1 Jan 2026. Supports that the change of name took effect on 1 Jan 2026, so the agency was called the Swedish Civil Contingencies Agency (Myndigheten för samhällsskydd och beredskap) throughout 2025.
- Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten), Årsredovisning 2025 (Annual report 2025), February 2026. Supports about 28,300 registered cases against about 18,100 the year before, the 102% rise in complaints, the 89% rise in personal data breaches, the 12,276 notifications, that more than 1.5 million people were affected, and that the duty to report covers breaches likely to pose a risk to the rights and freedoms of those affected.
- Swedish National Council for Crime Prevention (Brottsförebyggande rådet), Anmälda brott 2025, Slutlig statistik (Reported crimes 2025, final statistics), Report 2026:9. Supports 1,439,163 reported crimes, the fall of 50,156 crimes or 3%, 232,862 fraud offences, the rise of 2,532 offences or 1%, the 16% share for fraud offences, the rise in card fraud without a physical card of 8,867 offences or 10%, and the falls of 3,207 and 3,025 offences.
- Swedish Internet Foundation (Internetstiftelsen), Svenskarna och internet 2025, kapitel 4, Annonsbedrägerier (Swedes and the internet 2025, chapter 4, advert fraud). Supports the 6 in 10 who have seen a scam advert, the 3% who have been victims, the men of retirement age, the third who reported it, the third who held back from buying, and that an offer that seems too good to be true is the most common way to spot a scam.
- Swedish Internet Foundation (Internetstiftelsen), Metodbeskrivning, Svenskarna och internet 2025 (Method description, Swedes and the internet 2025). Supports n=3,362 in Study 1, the 60% participation rate, the fieldwork period 2 to 20 Jan 2025, the weighting, and that 2,609 of the 3,362 interviews were done in the web panel while 753 were supplementary.
- Swedish Code of Statutes (Svensk författningssamling), Cybersäkerhetslag (2025:1506) (Cybersecurity Act), issued 11 Dec 2025, published 17 Dec 2025. Supports that the Act came into force on 15 Jan 2026, that it repeals the act on information security for essential and digital services, that it partly implements the NIS2 Directive, and how the Act defines cybersecurity. The text of the Act is also available from the Swedish Parliament (Sveriges riksdag).
- European Union, Europaparlamentets och rådets direktiv (EU) 2022/2555 av den 14 december 2022 om åtgärder för en hög gemensam cybersäkerhetsnivå i hela unionen, om ändring av förordning (EU) nr 910/2014 och direktiv (EU) 2018/1972 och om upphävande av direktiv (EU) 2016/1148 (NIS 2-direktivet) (the NIS2 Directive, Swedish language version), via EUR-Lex. Supports that the law the article describes implements the Directive.
- Swedish National Cyber Security Centre (Nationellt cybersäkerhetscenter), Det här är cybersäkerhetslagen (This is the Cybersecurity Act). Supports that the Cybersecurity Act applies from 15 Jan 2026, that the cyber work moved on 1 Jul 2026 from the Swedish Civil Defence Agency to the centre at the National Defence Radio Establishment, and that the organisations covered are in 18 sectors.
Sources read on 6 and 7 Sep 2026, links checked on 8 Sep 2026. The ISO standard page does not respond to automated requests and is therefore given with publisher and website.
Extended on 14 Sep 2026 with the original document behind the US definition and the statute in force, the current edition of the international standard, the report behind the final crime statistics, the data protection authority's annual report, the survey's fourth chapter and its method description, the Cybersecurity Act in the Swedish Code of Statutes, the NIS2 Directive and the centre that took over the remit on 1 Jul 2026. The agency's report puts the share of incidents with an unknown cause in 2025 at 32%, in the main text and in chart 7. The edition of the international standard that the source list referred to was withdrawn on 3 Jul 2026.