NIS2 and Cybersäkerhetslagen
Governance, management accountability, capability assessment and evidence-based compliance for essential and important entities.
Cybersecurity · Risk · Transformation
I help boards, leadership teams and regulated organisations turn cybersecurity obligations into defensible decisions, quantified risk reduction and operational capabilities that can be demonstrated with evidence.
Bridging regulation, technology, finance and leadership so that cybersecurity becomes a managed business capability rather than a collection of isolated controls.
Governance, management accountability, capability assessment and evidence-based compliance for essential and important entities.
Secure-by-design governance, product lifecycle assurance, vulnerability handling, SBOM traceability and supplier responsibility.
FAIR-based analysis that translates loss event frequency and magnitude into monetary exposure and decision-ready scenarios.
Procurement requirements, contractual flow-down, acceptance criteria and verifiable evidence across complex supplier ecosystems.
Structured open-source intelligence to establish an external risk baseline, identify dependencies and support prioritisation.
Mobilising multi-stakeholder organisations, establishing practical methods and leading change from strategic intent to measurable operation.
Effective compliance requires more than policies. The organisation must be able to show how obligations become owned risks, funded controls, tested capabilities and retained evidence.
Cybersecurity is credible when leadership can explain the risk, justify the investment and prove that the capability works.
Map assets, dependencies, threat exposure, vulnerabilities and regulatory scope.
Translate scenarios into financial and operational impact with explicit uncertainty.
Connect legal duties to controls, owners, tests, acceptance criteria and retained proof.
Use capability and process measurements to shorten remediation time and demonstrate progress.
A multidisciplinary foundation combining technology, mathematics, operational leadership, business transformation and information-security governance.
Long experience in strategy, business development, operations and large transformation programmes involving multiple stakeholders.
Experience from a CISO role in a cybersecurity company and advisory work on security programmes, NIS2 and ISO 27001.
Development of methods for quantitative risk assessment, prioritisation and improved delivery performance in complex environments.
Bachelor-level studies in physics and applied mathematics at KTH, with continuing interests in mathematics, Ada/SPARK and applied AI.
Contact
Connect to discuss executive briefings, regulatory readiness, quantitative risk, supply-chain assurance or AI-assisted cybersecurity analysis.