Mobile menu

Blog | 25 November 2025

How to build a secure IT organisation

In the first part on cybersecurity with Linus Kvarnhammar, we talked about the most common mistakes an organisation makes. In this instalment, we delve into what it actually takes to build long-term security – beyond firewalls and products. Linus is a security specialist and professional hacker. For over fifteen years, he has helped organisations understand how attackers think.

"Security must come from the top. When it is driven from below, it often becomes ad hoc solutions and quick product purchases. But when it comes from the top, the whole organisation's processes follow."

Map the threats before they become problems

Many IT managers today still think about individual systems but forget the pathways between them. That's where the attacks happen. As an IT manager, you need to understand the attack paths you provide. Which systems are vulnerable? Where are the access points? How will all this be exploited? A good exercise is to do a threat modelling and build a map of your systems and see where the risks are.

Threat modelling is a systematic approach to identifying and assessing potential threats to an IT system, network or service. By analysing and classifying the threats, concrete measures can be developed to mitigate the risks and meet the security objectives, already early in the development process, when it is both easier and cheaper to act. There are several established tools for doing this, and the most important thing is not which one you choose, but that you actually take the time to identify your weaknesses before someone else does.

Choose the right supplier to work with

But a secure IT organisation is of course also based on the supplier you choose to work with. Here it is important to know what to look for. I usually highlight one specific factor as one of the most important – transparency. A good supplier is open about its processes, its audits and their results. They should dare to tell how they handle incidents and welcome customers' own audits. Swedish suppliers are often more open than many others and that is a good sign.

Summary – how to stay ahead:

  • Let security efforts be driven from management, not from individual projects. It is management that sets the tone for the security culture.
  • Map the attack paths before anyone else does. Think about the pathways between systems, not just the systems themselves.
  • Choose suppliers who are transparent and open about their processes.
  • Invest in knowledge and awareness throughout the organisation, it is the best protection.
Linus Kvarnhammar

Ready to turn ambition into action?

Whether you're looking to engage employees, serve citizens or accelerate growth – Sitevision gives you the foundation to make it happen.

Subscribe to our newsletter

You’ll get the lowdown on new features in Sitevision, what’s happening with us and a whole bunch of tips. The idea? To make your work smart, smooth and fun.

Certifikat ISO/IEC 27001:2022

Certifikat ISO/IEC 27001:2022