Skip to main content
BilgeQor
Back to industries

CTO, IT Director, CISO

Manufacturing & Supplier Portals

Sweden Cyberincident Reporting Context

Sweden 2025 Cyberincident Reporting — Reported Activity from Obliged Organisations

Market context — not industry-specific evidence

The following data reflects cyberincident reports submitted to Myndigheten för civilt försvar (MCF) by reporting-obliged state authorities and NIS suppliers during 2025. MCF notes a significant underreporting issue; these figures represent reported context only, not the full scale of cyber incidents in Sweden.

Sweden — reporting-obliged organisations under the 2025 cyberincident reporting framework2025 reporting year (publication date: 26 March 2026)

Cyberincident reports by organisation type — 2025

Total cyberincident reports received
266
Unit
cyberincident reports received from reporting-obliged organisations
Period
Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Scope
Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
Reports from state authorities
122
Unit
cyberincident reports from state authorities
Period
Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Scope
Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
Reports from NIS suppliers
144
Unit
cyberincident reports from NIS suppliers
Period
Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Scope
Sweden 2025 cyberincident reporting context — reporting-obliged organisations only

Myndigheten för civilt försvar (MCF) received 266 cyberincident reports in 2025 from reporting-obliged organisations: 122 from 41 state authorities and 144 from 54 NIS suppliers.

Reported cyberincident context from reporting-obliged state authorities and NIS suppliers under Sweden's 2025 cyberincident reporting framework only. MCF notes a significant underreporting/dark-figure issue; 266 reported incidents do not represent the full scale of cyber incidents in Sweden.

Reporting-obliged organisations that submitted reports — 2025

Reporting-obliged organisations that submitted reports
95
Unit
reporting-obliged organisations that submitted at least one cyberincident report
Period
Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Scope
Sweden 2025 cyberincident reporting context — reporting-obliged organisations only

95 reporting-obliged organisations submitted cyberincident reports in 2025.

Reflects organisations that submitted at least one cyberincident report in 2025 under the reporting framework. Does not represent incident prevalence across all organisations in Sweden.

State authorities that submitted reports — 2025

State authorities that submitted reports
41
Unit
state authorities that submitted cyberincident reports
Period
Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Scope
Sweden 2025 cyberincident reporting context — reporting-obliged organisations only

41 state authorities submitted cyberincident reports in 2025.

Reflects state authorities that submitted at least one cyberincident report in 2025 under the reporting framework. Does not represent incident prevalence across all state authorities in Sweden.

NIS suppliers that submitted reports — 2025

NIS suppliers that submitted reports
54
Unit
NIS suppliers that submitted cyberincident reports
Period
Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Scope
Sweden 2025 cyberincident reporting context — reporting-obliged organisations only

54 NIS suppliers submitted cyberincident reports in 2025.

Reflects NIS suppliers that submitted at least one cyberincident report in 2025 under the reporting framework. Does not represent incident prevalence across all NIS suppliers in Sweden.

Reporting-obliged state authorities that had not reported since 2018 — 2025

Reporting-obliged state authorities that had not reported since 2018
28%
Unit
percent of reporting-obliged state authorities that had not reported any cyberincident since 2018
Period
Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Scope
Sweden 2025 cyberincident reporting context — reporting-obliged organisations only

28% of reporting-obliged state authorities had not submitted any cyberincident report since 2018.

The 28% non-reporting share applies to reporting-obliged state authorities only. Does not represent incident prevalence across all organisations in Sweden.

NIS supplier incident reports by sector — 2025

Health and healthcare — 80%
80%
Unit
percent — health and healthcare sector share within NIS supplier reports (2025)
Period
Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Scope
Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
Drinking water — 13%
13%
Unit
percent — drinking-water sector share within NIS supplier reports (2025)
Period
Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Scope
Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
Transport — 4%
4%
Unit
percent — transport sector share within NIS supplier reports (2025)
Period
Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Scope
Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
Energy supply — 3%
3%
Unit
percent — energy-supply sector share within NIS supplier reports (2025)
Period
Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Scope
Sweden 2025 cyberincident reporting context — reporting-obliged organisations only

Of the 144 cyberincident reports from NIS suppliers: approximately 80% from health and healthcare, 13% from drinking water, 4% from transport, and 3% from energy supply.

Sector percentages apply only to the 144 cyberincident reports from NIS suppliers in 2025. Not all-Sweden sector incident prevalence, not all-business sector prevalence, and not BilgeQor industry-specific evidence.

Supplier-originated incident context — 2025

Cyberincident reports described as supplier-originated (just over 44%)
44%
Unit
percent (just over) — reported cyberincident reports described as supplier-originated
Period
Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Scope
Sweden 2025 cyberincident reporting context — reporting-obliged organisations only

Just over 44% of received cyberincident reports described the incident as supplier-originated in 2025.

Source uses approximate language ("just over 44%"). Reflects the proportion of received reports that described the incident as supplier-originated under the 2025 reporting framework. Not a general measure of supply chain risk prevalence across Sweden.

Reported cyberattacks — 2024 vs 2025

Reported cyberattacks in 2025
25
Unit
reported cyberattacks in 2025
Period
Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Scope
Sweden 2025 cyberincident reporting context — reporting-obliged organisations only
Reported cyberattacks in 2024
104
Unit
reported cyberattacks in 2024
Period
Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Scope
Sweden 2025 cyberincident reporting context — reporting-obliged organisations only

25 cyberattacks were reported in 2025, compared with 104 reported in 2024, under the cyberincident reporting framework.

Reported attack counts under the Swedish cyberincident reporting framework for each year. The decrease from 104 to 25 reported cyberattacks does not constitute proof that actual cyberattack activity decreased across Sweden. Reporting-framework scope and interpretation may affect year-over-year comparability.

Overload attack incident context — 2025

Overload attacks among received incident reports (just over 4%)
4%
Unit
percent (just over) — overload attacks among received incident reports
Period
Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Scope
Sweden 2025 cyberincident reporting context — reporting-obliged organisations only

Overload attacks represented just over 4% of received cyberincident reports in 2025.

Source uses approximate language ("just over 4%"). Share of overload attacks among received cyberincident reports under the 2025 reporting framework only. Not total overload attack prevalence across Sweden.

Source: Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025

Source: Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025. Covers cyberincident reports from state authorities and NIS suppliers obliged to report under the Swedish reporting framework. Does not represent total Swedish business incident prevalence, total public-sector prevalence, hidden incident prevalence, or industry-specific evidence. MCF explicitly acknowledges significant underreporting.

Methodology: Data covers cyberincident reports submitted to Myndigheten för civilt försvar (MCF) by reporting-obliged organisations (state authorities and NIS suppliers) under the Swedish cyberincident reporting framework in 2025. MCF notes a significant underreporting/dark-figure issue; reported figures do not represent the full scale of cyber incidents in Sweden. The 80%, 13%, 4%, and 3% sector percentages apply only to cyberincident reports from NIS suppliers in 2025 and must not be presented as all-Sweden sector incident prevalence, all-business sector prevalence, or industry-specific evidence. The 25 reported cyberattacks in 2025 and 104 reported cyberattacks in 2024 are reported attack-count context under the reporting framework; the year-over-year decrease does not constitute proof that actual cyberattack activity decreased across Sweden.

Accessible data table
Verified Sweden Myndigheten för civilt försvar (MCF) 2025 cyberincident reporting context from reporting-obliged state authorities and NIS suppliers data from Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025, reporting period Calendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework.
MetricValueSourceScopeReporting period
Total cyberincident reports received266 cyberincident reports received from reporting-obliged organisationsMyndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025Sweden 2025 cyberincident reporting context — reporting-obliged organisations onlyCalendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Reports from state authorities122 cyberincident reports from state authoritiesMyndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025Sweden 2025 cyberincident reporting context — reporting-obliged organisations onlyCalendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Reports from NIS suppliers144 cyberincident reports from NIS suppliersMyndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025Sweden 2025 cyberincident reporting context — reporting-obliged organisations onlyCalendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Reporting-obliged organisations that submitted reports95 reporting-obliged organisations that submitted at least one cyberincident reportMyndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025Sweden 2025 cyberincident reporting context — reporting-obliged organisations onlyCalendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
State authorities that submitted reports41 state authorities that submitted cyberincident reportsMyndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025Sweden 2025 cyberincident reporting context — reporting-obliged organisations onlyCalendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
NIS suppliers that submitted reports54 NIS suppliers that submitted cyberincident reportsMyndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025Sweden 2025 cyberincident reporting context — reporting-obliged organisations onlyCalendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Reporting-obliged state authorities that had not reported since 201828% percent of reporting-obliged state authorities that had not reported any cyberincident since 2018Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025Sweden 2025 cyberincident reporting context — reporting-obliged organisations onlyCalendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Health and healthcare — 80%80% percent — health and healthcare sector share within NIS supplier reports (2025)Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025Sweden 2025 cyberincident reporting context — reporting-obliged organisations onlyCalendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Drinking water — 13%13% percent — drinking-water sector share within NIS supplier reports (2025)Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025Sweden 2025 cyberincident reporting context — reporting-obliged organisations onlyCalendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Transport — 4%4% percent — transport sector share within NIS supplier reports (2025)Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025Sweden 2025 cyberincident reporting context — reporting-obliged organisations onlyCalendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Energy supply — 3%3% percent — energy-supply sector share within NIS supplier reports (2025)Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025Sweden 2025 cyberincident reporting context — reporting-obliged organisations onlyCalendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Cyberincident reports described as supplier-originated (just over 44%)44% percent (just over) — reported cyberincident reports described as supplier-originatedMyndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025Sweden 2025 cyberincident reporting context — reporting-obliged organisations onlyCalendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Reported cyberattacks in 202525 reported cyberattacks in 2025Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025Sweden 2025 cyberincident reporting context — reporting-obliged organisations onlyCalendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Reported cyberattacks in 2024104 reported cyberattacks in 2024Myndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025Sweden 2025 cyberincident reporting context — reporting-obliged organisations onlyCalendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework
Overload attacks among received incident reports (just over 4%)4% percent (just over) — overload attacks among received incident reportsMyndigheten för civilt försvar — Årsrapport cyberincidentrapportering 2025Sweden 2025 cyberincident reporting context — reporting-obliged organisations onlyCalendar year 2025 cyberincident reports received from reporting-obliged state authorities and NIS suppliers under the Swedish cyberincident reporting framework

Relevant loss and exposure areas

These existing industry scoping prompts help frame a proposal. They do not assert an incident, loss, or market-specific condition.

Industry themes

  • Supply Chain Attacks
  • Data Exfiltration
  • Ransomware

Digital surfaces in scope

Vendor PortalsSupply Chain DashboardsOrder Management

What structured security support changes

The Security File turns risk signals into decisions.

Official market data shows where risk exists. The BilgeQor Security File connects that context to your real websites, apps, accounts, payment flows and team responsibilities, so leaders can decide what to fix first.

Why this matters

The file gives your team one place to understand what was reviewed, what matters, what changed, and what still needs a decision.

BilgeQor Method

What the Security File contains

A Security File is not a generic report. It is a structured decision record for the assets, workflows and risks covered by the agreed scope.

01

Market and sector context

We connect official market signals and industry exposure to the business surfaces in scope.

02

Exposure map

We map websites, apps, accounts, payment journeys, admin roles, vendors and customer-facing workflows.

03

Priority register

We separate urgent risks, important improvements and lower-priority findings so the next action is clear.

04

Executive summary

We provide a concise summary that leadership, operations, vendors or insurers can read without needing raw technical detail.

05

Remediation roadmap

We turn findings into a 14 / 30 / 90-day action path with ownership, evidence notes and follow-through guidance.

What it is not

  • Not a guarantee of perfect security.
  • Not a certification or compliance verdict.
  • Not a per-company loss estimate or fear-based claim.