Your people are the attack surface. Now the law agrees.
Sweden's Cybersecurity Act took effect on 15 January 2026, and registration with MSB closed on 2 February. Four things close the gap it leaves: watch what an attacker can see, train the people they target, investigate what you already leak, and test the doors email never reaches.
- MONITOR
- TRAIN
- INVESTIGATE
- TEST
One attacker, every door. We cover them.
Monitor keeps a permanent eye on your exposure. Train builds the reflex in your people. Investigate digs, by hand, into everything an attacker could find. Test & probe attacks you — with permission — to prove it works. Tap any card to see how it runs.
Pick how much water you want watched.
Watch · S
The essentials, for a small team
- ✓1 company domain
- ✓Up to 6 corporate mailboxes
- ✓Email auth + breach check, monthly
- ✓Alert on any change
Watch · M
PopularGrowing, with more to lose
- ✓Everything in S
- ✓Up to 25 mailboxes
- ✓Look-alike domain monitoring
- ✓New-subdomain alerts
Watch · L
Cover you can put in the file
- ✓Everything in M
- ✓Unlimited mailboxes
- ✓Certificate-transparency watch
- ✓A written report every quarter
Indicative pricing, excluding VAT. Monitoring covers company assets only — your domain and corporate mailboxes, never an employee's private accounts. Training, investigation and testing are quoted per engagement.
Every path begins with one free report.
See what an attacker sees before they use it.
Tell us the domain. You get a written report on what is publicly exposed around your company — no call, no demo, no obligation.
Awareness training stopped being a nice-to-have.
Sweden implemented NIS2 as Cybersäkerhetslagen. It entered into force on 15 January 2026, and entities in scope had to notify the Swedish Civil Contingencies Agency by 2 February 2026. Supervision sits with MSB and PTS, alongside sector authorities.
Scope generally starts at 50 employees, or €10M turnover, for organisations in the sectors listed in the directive's annexes — transport, manufacturing, food, water, health, digital providers and others. Among the required measures: cyber hygiene and training, explicitly covering both staff and management.
Sanction fees run up to €10M depending on classification, and management can be barred from holding leadership positions. An annual slideshow does not build the reflex the law is asking for. Repeated, realistic drills do.
This is a summary for orientation, not legal advice. Whether your organisation falls in scope, and what exactly it must do, is a question for your own counsel or the relevant supervisory authority.
- ✓50–250 employees, in a sector covered by NIS2
- ✓No in-house security team, and no appetite to build one
- ✓A compliance obligation with a date attached to it
- ✓People who have never been trained on this, ever
- ✗You already run a mature awareness programme
- ✗You need in-person, on-site delivery
- ✗You want a per-seat platform with SSO and an admin console
- ✗You are looking for penetration testing or incident response
Want to see the training before you talk to anyone? The whole path is free and needs no account.
Open the trainingDo we have to install anything?
No. The training runs in a browser, monitoring reads public records, and the simulation runs from our side. No agent, no plug-in, no integration to approve.
Do you touch our systems?
No. Monitoring and the report are public sources only. A simulated campaign is the one thing that reaches your people, and it happens only after you authorise the scope in writing.
How is this different from the free training on the site?
Same engine, different product. The corporate version is delivered by private link to named staff, refreshed every quarter with current context, tracked, and turned into a compliance record. The public version is none of those.
What language is it in?
English — training, reports and monitoring alerts. Everything runs remotely. A Swedish training version is on the roadmap.