For teams · NIS2

Your people are the attack surface. Now the law agrees.

Sweden's Cybersecurity Act took effect on 15 January 2026, and registration with MSB closed on 2 February. Four things close the gap it leaves: watch what an attacker can see, train the people they target, investigate what you already leak, and test the doors email never reaches.

  • MONITOR
  • TRAIN
  • INVESTIGATE
  • TEST
Four ways we cover you

One attacker, every door. We cover them.

Monitor keeps a permanent eye on your exposure. Train builds the reflex in your people. Investigate digs, by hand, into everything an attacker could find. Test & probe attacks you — with permission — to prove it works. Tap any card to see how it runs.

Monitoring · what it costs

Pick how much water you want watched.

Watch · S

€90/ MONTH

The essentials, for a small team

  • 1 company domain
  • Up to 6 corporate mailboxes
  • Email auth + breach check, monthly
  • Alert on any change
Start free

Watch · M

Popular
€190/ MONTH

Growing, with more to lose

  • Everything in S
  • Up to 25 mailboxes
  • Look-alike domain monitoring
  • New-subdomain alerts
Start free

Watch · L

€390/ MONTH

Cover you can put in the file

  • Everything in M
  • Unlimited mailboxes
  • Certificate-transparency watch
  • A written report every quarter
Start free

Indicative pricing, excluding VAT. Monitoring covers company assets only — your domain and corporate mailboxes, never an employee's private accounts. Training, investigation and testing are quoted per engagement.

Start here

Every path begins with one free report.

Free exposure report

See what an attacker sees before they use it.

Tell us the domain. You get a written report on what is publicly exposed around your company — no call, no demo, no obligation.

Public sources only. We do not scan, probe or send anything to your systems — a simulated campaign happens later and only on written authorisation. Your details are used to answer you and nothing else.

NIS2 · Sweden

Awareness training stopped being a nice-to-have.

Sweden implemented NIS2 as Cybersäkerhetslagen. It entered into force on 15 January 2026, and entities in scope had to notify the Swedish Civil Contingencies Agency by 2 February 2026. Supervision sits with MSB and PTS, alongside sector authorities.

Scope generally starts at 50 employees, or €10M turnover, for organisations in the sectors listed in the directive's annexes — transport, manufacturing, food, water, health, digital providers and others. Among the required measures: cyber hygiene and training, explicitly covering both staff and management.

Sanction fees run up to €10M depending on classification, and management can be barred from holding leadership positions. An annual slideshow does not build the reflex the law is asking for. Repeated, realistic drills do.

15 Jan 2026Cybersäkerhetslagen in force
2 Feb 2026Notification deadline to MSB
50+ staffGeneral scope threshold
up to €10MMaximum sanction fee

This is a summary for orientation, not legal advice. Whether your organisation falls in scope, and what exactly it must do, is a question for your own counsel or the relevant supervisory authority.

Whether this is for you
A good fit
  • 50–250 employees, in a sector covered by NIS2
  • No in-house security team, and no appetite to build one
  • A compliance obligation with a date attached to it
  • People who have never been trained on this, ever
Not for you
  • You already run a mature awareness programme
  • You need in-person, on-site delivery
  • You want a per-seat platform with SSO and an admin console
  • You are looking for penetration testing or incident response

Want to see the training before you talk to anyone? The whole path is free and needs no account.

Open the training
Before you ask

Do we have to install anything?

No. The training runs in a browser, monitoring reads public records, and the simulation runs from our side. No agent, no plug-in, no integration to approve.

Do you touch our systems?

No. Monitoring and the report are public sources only. A simulated campaign is the one thing that reaches your people, and it happens only after you authorise the scope in writing.

How is this different from the free training on the site?

Same engine, different product. The corporate version is delivered by private link to named staff, refreshed every quarter with current context, tracked, and turned into a compliance record. The public version is none of those.

What language is it in?

English — training, reports and monitoring alerts. Everything runs remotely. A Swedish training version is on the roadmap.