Sweden Cyberincident Reporting Context
Sweden 2025 Cyberincident Reporting — Reported Activity from Obliged Organisations
Market context — not industry-specific evidence
The following data reflects cyberincident reports submitted to Myndigheten för civilt försvar (MCF) by reporting-obliged state authorities and NIS suppliers during 2025. MCF notes a significant underreporting issue; these figures represent reported context only, not the full scale of cyber incidents in Sweden.
Cyberincident reports by organisation type — 2025
- Total cyberincident reports received
- 266
- Unit
- cyberincident reports received from reporting-obliged organisations
- Period
- Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
- Scope
- Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
- Reports from state authorities
- 122
- Unit
- cyberincident reports from state authorities
- Period
- Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
- Scope
- Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
- Reports from NIS suppliers
- 144
- Unit
- cyberincident reports from NIS suppliers
- Period
- Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
- Scope
- Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
Myndigheten för civilt försvar (MCF) received 266 cyberincident reports in 2025 from reporting-obliged organisations: 122 from 41 state authorities and 144 from 54 NIS suppliers.
Reported cyberincident context from reporting-obliged state authorities and NIS suppliers under Sweden's 2025 cyberincident reporting framework only. MCF notes a significant underreporting/dark-figure issue; 266 reported incidents do not represent the full scale of cyber incidents in Sweden.
Reporting-obliged organisations that submitted reports — 2025
- Reporting-obliged organisations that submitted reports
- 95
- Unit
- reporting-obliged organisations that submitted at least one cyberincident report
- Period
- Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
- Scope
- Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
95 reporting-obliged organisations submitted cyberincident reports in 2025.
Reflects organisations that submitted at least one cyberincident report in 2025 under the reporting framework. Does not represent incident prevalence across all organisations in Sweden.
State authorities that submitted reports — 2025
- State authorities that submitted reports
- 41
- Unit
- state authorities that submitted cyberincident reports
- Period
- Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
- Scope
- Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
41 state authorities submitted cyberincident reports in 2025.
Reflects state authorities that submitted at least one cyberincident report in 2025 under the reporting framework. Does not represent incident prevalence across all state authorities in Sweden.
NIS suppliers that submitted reports — 2025
- NIS suppliers that submitted reports
- 54
- Unit
- NIS suppliers that submitted cyberincident reports
- Period
- Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
- Scope
- Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
54 NIS suppliers submitted cyberincident reports in 2025.
Reflects NIS suppliers that submitted at least one cyberincident report in 2025 under the reporting framework. Does not represent incident prevalence across all NIS suppliers in Sweden.
Reporting-obliged state authorities that had not reported since 2018 — 2025
- Reporting-obliged state authorities that had not reported since 2018
- 28%
- Unit
- percent of reporting-obliged state authorities that had not reported any cyberincident since 2018
- Period
- Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
- Scope
- Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
28% of reporting-obliged state authorities had not submitted any cyberincident report since 2018.
The 28% non-reporting share applies to reporting-obliged state authorities only. Does not represent incident prevalence across all organisations in Sweden.
NIS supplier incident reports by sector — 2025
- Health and healthcare — 80%
- 80%
- Unit
- percent — health and healthcare sector share within NIS supplier reports (2025)
- Period
- Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
- Scope
- Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
- Drinking water — 13%
- 13%
- Unit
- percent — drinking-water sector share within NIS supplier reports (2025)
- Period
- Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
- Scope
- Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
- Transport — 4%
- 4%
- Unit
- percent — transport sector share within NIS supplier reports (2025)
- Period
- Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
- Scope
- Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
- Energy supply — 3%
- 3%
- Unit
- percent — energy-supply sector share within NIS supplier reports (2025)
- Period
- Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
- Scope
- Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
Of the 144 cyberincident reports from NIS suppliers: approximately 80% from health and healthcare, 13% from drinking water, 4% from transport, and 3% from energy supply.
Sector percentages apply only to the 144 cyberincident reports from NIS suppliers in 2025. Not all-Sweden sector incident prevalence, not all-business sector prevalence, and not BilgeQor industry-specific evidence.
Supplier-originated incident context — 2025
- Cyberincident reports described as supplier-originated (just over 44%)
- 44%
- Unit
- percent (just over) — reported cyberincident reports described as supplier-originated
- Period
- Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
- Scope
- Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
Just over 44% of received cyberincident reports described the incident as supplier-originated in 2025.
Source uses approximate language ("just over 44%"). Reflects the proportion of received reports that described the incident as supplier-originated under the 2025 reporting framework. Not a general measure of supply chain risk prevalence across Sweden.
Reported cyberattacks — 2024 vs 2025
- Reported cyberattacks in 2025
- 25
- Unit
- reported cyberattacks in 2025
- Period
- Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
- Scope
- Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
- Reported cyberattacks in 2024
- 104
- Unit
- reported cyberattacks in 2024
- Period
- Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
- Scope
- Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
25 cyberattacks were reported in 2025, compared with 104 reported in 2024, under the cyberincident reporting framework.
Reported attack counts under the Swedish cyberincident reporting framework for each year. The decrease from 104 to 25 reported cyberattacks does not constitute proof that actual cyberattack activity decreased across Sweden. Reporting-framework scope and interpretation may affect year-over-year comparability.
Overload attack incident context — 2025
- Overload attacks among received incident reports (just over 4%)
- 4%
- Unit
- percent (just over) — overload attacks among received incident reports
- Period
- Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
- Scope
- Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
Overload attacks represented just over 4% of received cyberincident reports in 2025.
Source uses approximate language ("just over 4%"). Share of overload attacks among received cyberincident reports under the 2025 reporting framework only. Not total overload attack prevalence across Sweden.
Source: Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025
Source: Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025. Covers cyberincident reports from state authorities and NIS suppliers obliged to report under the Swedish reporting framework. Does not represent total Swedish business incident prevalence, total public-sector prevalence, hidden incident prevalence, or industry-specific evidence. MCF explicitly acknowledges significant underreporting.
Methodology: Data covers cyberincident reports submitted to Myndigheten för civilt försvar (MCF) by reporting-obliged organisations (state authorities and NIS suppliers) under the Swedish cyberincident reporting framework in 2025. MCF notes a significant underreporting/dark-figure issue; reported figures do not represent the full scale of cyber incidents in Sweden. The 80%, 13%, 4%, and 3% sector percentages apply only to cyberincident reports from NIS suppliers in 2025 and must not be presented as all-Sweden sector incident prevalence, all-business sector prevalence, or industry-specific evidence. The 25 reported cyberattacks in 2025 and 104 reported cyberattacks in 2024 are reported attack-count context under the reporting framework; the year-over-year decrease does not constitute proof that actual cyberattack activity decreased across Sweden.
Accessible data table
| Metric | Value | Source | Scope | Reporting period |
|---|---|---|---|---|
| Total cyberincident reports received | 266 cyberincident reports received from reporting-obliged organisations | Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025 | Sweden 2025 cyberincident reporting context — reporting-obliged organisations only | Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework |
| Reports from state authorities | 122 cyberincident reports from state authorities | Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025 | Sweden 2025 cyberincident reporting context — reporting-obliged organisations only | Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework |
| Reports from NIS suppliers | 144 cyberincident reports from NIS suppliers | Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025 | Sweden 2025 cyberincident reporting context — reporting-obliged organisations only | Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework |
| Reporting-obliged organisations that submitted reports | 95 reporting-obliged organisations that submitted at least one cyberincident report | Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025 | Sweden 2025 cyberincident reporting context — reporting-obliged organisations only | Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework |
| State authorities that submitted reports | 41 state authorities that submitted cyberincident reports | Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025 | Sweden 2025 cyberincident reporting context — reporting-obliged organisations only | Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework |
| NIS suppliers that submitted reports | 54 NIS suppliers that submitted cyberincident reports | Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025 | Sweden 2025 cyberincident reporting context — reporting-obliged organisations only | Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework |
| Reporting-obliged state authorities that had not reported since 2018 | 28% percent of reporting-obliged state authorities that had not reported any cyberincident since 2018 | Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025 | Sweden 2025 cyberincident reporting context — reporting-obliged organisations only | Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework |
| Health and healthcare — 80% | 80% percent — health and healthcare sector share within NIS supplier reports (2025) | Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025 | Sweden 2025 cyberincident reporting context — reporting-obliged organisations only | Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework |
| Drinking water — 13% | 13% percent — drinking-water sector share within NIS supplier reports (2025) | Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025 | Sweden 2025 cyberincident reporting context — reporting-obliged organisations only | Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework |
| Transport — 4% | 4% percent — transport sector share within NIS supplier reports (2025) | Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025 | Sweden 2025 cyberincident reporting context — reporting-obliged organisations only | Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework |
| Energy supply — 3% | 3% percent — energy-supply sector share within NIS supplier reports (2025) | Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025 | Sweden 2025 cyberincident reporting context — reporting-obliged organisations only | Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework |
| Cyberincident reports described as supplier-originated (just over 44%) | 44% percent (just over) — reported cyberincident reports described as supplier-originated | Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025 | Sweden 2025 cyberincident reporting context — reporting-obliged organisations only | Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework |
| Reported cyberattacks in 2025 | 25 reported cyberattacks in 2025 | Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025 | Sweden 2025 cyberincident reporting context — reporting-obliged organisations only | Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework |
| Reported cyberattacks in 2024 | 104 reported cyberattacks in 2024 | Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025 | Sweden 2025 cyberincident reporting context — reporting-obliged organisations only | Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework |
| Overload attacks among received incident reports (just over 4%) | 4% percent (just over) — overload attacks among received incident reports | Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025 | Sweden 2025 cyberincident reporting context — reporting-obliged organisations only | Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework |
