LODLINE
EN / SV

director-liability

Board duties under the cyber security rules: step by step

Board duties under the cyber security rules: step by step means the board approves a risk framework, oversees incident response, ensures breach notification within the applicable deadline, and documents every decision. Under Swedish law as it currently stands, that oversight duty cannot be delegated to management alone; the board carries it personally, from initial risk mapping through to post-incident review.

Who this concerns

This concerns the board of a Swedish aktiebolag whose activities fall within scope of the applicable cyber security and incident reporting framework, whether because the company operates in a sector treated as essential or important, or because a group parent or a major customer has pushed equivalent obligations down through contract. It also concerns boards of subsidiaries of foreign groups, where the parent's compliance programme is assumed, wrongly, to cover the Swedish entity automatically.

The board's oversight duty is personal and cannot be discharged by pointing to a chief information security officer, an outsourced IT provider, or a group-wide policy that was never formally adopted at Swedish board level. A board that has never discussed cyber risk as a board matter, with a minute to show it, has not discharged the duty even if the company's technical controls are adequate.

Where the company has a foreign parent, foreign shareholders, or a material dependency on a foreign supplier, three things change. First, the Swedish board still bears the statutory oversight duty even where a group policy exists; adopting it formally, at board level, in Sweden, is not optional. Second, incident notification obligations run to the Swedish supervisory authority regardless of where the parent reports separately. Third, evidence of board oversight, minutes, risk registers, approved policies, needs to exist in a form a Swedish court or authority can read, not only in a group intranet in another language.

The director-liability practice hub sets out how this oversight duty sits alongside the board's other statutory duties; this material focuses specifically on the cyber security dimension and the sequence a board should follow.

What the law says

Swedish company law imposes a general duty of care and loyalty on board members that extends to risks capable of causing material harm to the company, and cyber risk is treated as one of those risks once the exposure is foreseeable. Sector-specific security legislation layers a more concrete set of obligations on top: governance arrangements, incident reporting within a fixed timeframe, and record-keeping that a supervisory authority can inspect after the fact.

Under Swedish law as it currently stands, the precise scope of the sector-specific obligations depends on how the company is classified under the applicable framework, and that classification is not something the board should assume; it needs to be checked against the company's actual activities, not against a generic description of the sector. A company that assumes it falls outside scope because of its size, when the relevant test is based on the nature of the service provided, carries that assumption at the board's own risk.

The general duty of care does not disappear where the sector-specific rules do not apply. Even outside scope of a specific security framework, a board that ignores a known, material cyber exposure, and that exposure later causes loss, faces exposure under the ordinary duty of care standard applied to any foreseeable operational risk.

How it works in practice

Map what the company actually depends on

Before any policy is drafted, the board needs a written account of which systems, data sets, and third-party providers the company's operations actually depend on. This is not an IT department exercise conducted in isolation; the board commissions it, reviews it, and the review is minuted. Without this map, every later step is built on a guess.

Put cyber risk on the board's own agenda

The risk map is presented to the board as a board matter, not circulated as an information pack. The board discusses it, asks questions, and records in the minutes that the discussion took place, what was decided, and what was deferred for further work. A policy adopted by circular resolution without discussion is weaker evidence of oversight than one discussed and minuted at a meeting.

Approve a written cyber security policy

The board formally approves a policy that names who is responsible for day-to-day security, what must be reported to the board and how often, and what triggers immediate escalation to the board outside the normal reporting cycle. The policy is signed off by board resolution, not adopted by reference to a document nobody at board level has read.

Fix the incident response chain of command

The policy names, by role, who declares an incident, who decides on containment measures, who is authorised to notify the supervisory authority, and who communicates with counterparties and, where relevant, customers. Ambiguity here is what turns a technical incident into a governance failure, because decisions get made by whoever happens to be available rather than by whoever is authorised.

Set the internal notification deadline

Whatever external notification deadline the applicable framework sets, the board fixes an internal deadline that is shorter, so that the decision on external notification can be made calmly rather than against the external clock. A policy that only restates the external deadline gives the company no margin for internal escalation and decision-making.

Test the response plan before it is needed

A response plan that has never been rehearsed is a plan on paper only. The board requires, and records that it has required, at least one exercise or walk-through of the incident response plan, and reviews what the exercise revealed. Gaps found in a test are far cheaper to close than gaps found during an actual incident.

Document every board-level decision

Every decision connected to cyber risk, adopting the policy, reviewing an incident, approving a budget for remediation, deferring an investment, is minuted with enough specificity that a reviewer reading the minute a year later understands what was decided and why. Vague minutes are the single most common reason a board's oversight cannot later be demonstrated.

Review formally after any incident

After any incident, however minor, the board holds a formal post-incident review, records what happened, what worked, what did not, and what changes to the policy or the response plan follow from it. A board that treats an incident as closed once the technical problem is fixed has not closed the governance loop.

Reassess the policy on a fixed cycle and after material change

The policy is reassessed on a fixed cycle set by the board itself, and additionally whenever the company's risk profile changes materially, a new supplier, a new market, a merger, or a significant change in the group's ownership structure. A policy that has not been revisited since adoption is treated, in practice, as evidence that oversight lapsed.

What to check before relying on the current arrangement

  • Whether the risk map was commissioned and reviewed by the board itself, not only by management
  • Whether the policy was adopted by board resolution, with a minute that names the resolution
  • Whether the chain of command for declaring and escalating an incident is unambiguous on paper
  • Whether the internal notification deadline is shorter than the external one, not identical to it
  • Whether at least one response exercise has taken place and its findings were reported to the board
  • Whether post-incident reviews exist for every incident logged, not only the significant ones
  • Whether the policy has been reassessed since the last material change to the business

Common questions boards raise at this stage

What does the trustee's investigation mean for the board if a cyber incident tips the company into insolvency?

Where a cyber incident causes losses severe enough to affect solvency, a subsequent insolvency process brings scrutiny of board conduct in the period before the company failed, including whether cyber risk was managed with appropriate care. The mechanics of that scrutiny, and what it looks for, are set out in the trustee's review of board conduct.

Does directors' insurance cover losses arising from a cyber incident?

Not automatically, and not in full. Many director and officer policies exclude or sharply limit cover for losses connected to data breaches, regulatory fines, or failures of technical controls, treating these as risks the company should insure separately. What a standard policy typically does not cover in this area is set out in what directors' insurance excludes.

Who within the board is personally exposed if the policy exists but was never followed?

Personal exposure attaches to board members individually where they knew, or ought to have known, that the approved policy was not being followed and took no steps to correct it. A policy that exists on paper but is contradicted by actual practice does not protect the board; it can be used as evidence that the gap between policy and practice was foreseeable.

The numbers

Under Swedish law as it currently stands, the exact notification deadline, and the exact threshold that triggers a sector-specific reporting duty, depend on which framework applies to the company's specific activity, and that varies by sector and by the nature of the incident. Where the applicable framework sets a fixed period for notification, that period applies uniformly and is not negotiable case by case. Where the framework instead leaves the timing to be assessed against the severity of the incident, the supervisory authority's expectation is that notification happens without avoidable delay, and delay caused by internal indecision is treated less favourably than delay caused by the genuine complexity of establishing what happened.

Boards should not rely on a remembered number of hours or days without checking it against the specific framework that applies to the company's classification, because the figure that applies to one sector does not necessarily apply to another, and using the wrong figure as an internal benchmark creates a false sense of comfort.

Where it usually goes wrong

The most common failure is not a missing policy; it is a policy that exists but was never discussed at board level in a way that left a paper trail. A policy drafted by an external adviser or an IT provider, forwarded to the board for information, and never formally adopted, gives the appearance of governance without the substance of it.

The second common failure is delegation without oversight. Naming a chief information security officer or an external managed-service provider as responsible for security is normal and sensible; treating that appointment as discharging the board's own oversight duty is not. The board still needs to know, and to be able to show that it asked, whether the delegated function is actually working.

The third failure appears after a group restructuring or acquisition. A newly acquired Swedish subsidiary is assumed to be covered by the parent's existing cyber security programme, but the Swedish board never formally adopts anything, and no Swedish-language record exists that a Swedish authority or court could rely on. The gap only becomes visible once an incident occurs and the company needs to show what its own board actually decided.

A further limit worth naming directly: none of the steps above substitute for technical competence the company does not have. A board that follows every governance step correctly but relies on technical controls that are genuinely inadequate has discharged the governance duty without eliminating the underlying risk. Governance reduces legal exposure connected to how the risk was managed; it does not reduce the risk itself.

Finally, where the incident originates with a foreign supplier or a foreign parent's shared infrastructure, the Swedish board's obligations do not shrink to match its limited practical control over that infrastructure. The obligation to assess, escalate, and notify sits with the Swedish board regardless of where the underlying failure occurred, and contractual arrangements with the foreign party affect recovery, not the board's own reporting duty.

What to do next

The steps above cover what a board can and should do on its own: commissioning the risk map, adopting the policy, fixing the chain of command, and building the paper trail that makes oversight demonstrable. Where the open question is whether the current arrangement would actually hold up if tested, whether by a supervisory authority after an incident, or by a trustee reviewing board conduct after insolvency, that is a document-level review rather than a governance checklist, and it is where a preliminary assessment becomes useful.

A related decision boards sometimes reach at this stage is whether an individual director should step down given a specific, unresolved cyber exposure; the timing and effect of that decision are covered separately in resigning from the board: timing and effect.

Two further points worth checking while reviewing the current arrangement: how payment respite and enforcement work during an appeal if a cyber-related loss triggers a tax dispute, and what reconsideration by the Tax Agency requires where the incident touches an energy supply contract.

Book a preliminary assessment to have the current policy, minutes, and response plan reviewed against what a supervisory authority or a trustee would actually look for. Start with a preliminary assessment.

Request a preliminary assessment