{"title":"Incidenthantering \u0026 Cyberkris – Mallar","description":"\u003cp\u003eMallar och operativa verktyg för incidenthantering, cyberkris, incidentrapportering, återställning och efteranalys. Samlingen omfattar bland annat NIS2\/cybersäkerhetslagen, GDPR-personuppgiftsincidenter och bred Incident Response\/Cyber Crisis Management.\u003c\/p\u003e\u003cp\u003eFokus ligger på praktiskt genomförande: klassning, 24h\/72h-frister, beslutsloggar, kommunikation, evidens, recovery och förbättring efter incident.\u003c\/p\u003e","products":[{"product_id":"nis2-mallpaket-cybersakerhetslagen-2026-word-pdf","title":"NIS2 Template Package – Cybersecurity Act 2026 Word\/PDF","description":"\u003ch2\u003eNIS2 template package for Swedish organizations – Word and PDF\u003c\/h2\u003e\u003cp\u003eThis comprehensive \u003cstrong\u003eNIS2 template package\u003c\/strong\u003e is designed for companies, organizations, and other operators that need to structure and document their cybersecurity work in accordance with the Swedish \u003cstrong\u003eCybersecurity Act (2025:1506)\u003c\/strong\u003e and the Swedish implementation of NIS2.\u003c\/p\u003e\u003cp\u003eThe package contains \u003cstrong\u003e15 integrated document templates, checklists, and decision support documents\u003c\/strong\u003e in a professionally designed and editable Word file, as well as a ready-to-use PDF version. The material is updated for the rules applicable in 2026 and is also structured with consideration for \u003cstrong\u003eMCFFS 2026:11\u003c\/strong\u003e, which enters into force on October 1, 2026, and specifies requirements and general advice regarding security measures and management training.\u003c\/p\u003e\u003cp\u003e\u003cstrong\u003eYou receive both Word (DOCX) and PDF.\u003c\/strong\u003e The Word version is fully editable so that the organization's name, roles, risk levels, systems, suppliers, responsible parties, and decisions can be customized. The PDF version can be used as a reference, for printing, or as documentation for internal reviews.\u003c\/p\u003e\u003ch2\u003eIncluded in the NIS2 template package\u003c\/h2\u003e\u003col\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eApplicability assessment and organizational classification\u003c\/strong\u003e – support for documenting whether the organization is covered by the Cybersecurity Act, sector\/subsector, classification, and relevant supervision.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eCybersecurity and information security policy\u003c\/strong\u003e – goals, principles, responsibilities, management direction, and follow-up.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eRisk management methodology\u003c\/strong\u003e – model for identification, analysis, evaluation, treatment, and acceptance of cybersecurity risks.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eRisk register and action plan\u003c\/strong\u003e – practical table for assets, threats, vulnerabilities, consequences, probability, measures, responsibility, and deadlines.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eIncident management plan\u003c\/strong\u003e – roles, classification, escalation, containment, recovery, root cause analysis, and lessons learned.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eIncident reporting 24\/72 hours and final report\u003c\/strong\u003e – ready-made forms for notification, incident report, and final report.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eContinuity and crisis management plan\u003c\/strong\u003e – support for prioritization, RTO, RPO, backup, reserve solutions, crisis activation, and drills.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSupplier and supply chain security\u003c\/strong\u003e – due diligence, criticality, subcontractors, continuity, and follow-up.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSecurity appendix to supplier agreements\u003c\/strong\u003e – contractual clauses regarding incidents, access, logging, vulnerabilities, continuity, audit, subcontractors, and exit.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSecure development, acquisition, and change management\u003c\/strong\u003e – requirements for procurement, development, configuration, patching, and changes.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eFollow-up, metrics, and internal evaluation\u003c\/strong\u003e – KPI\/KRI, target values, trends, responsibilities, and improvement measures.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eCyber hygiene and training plan\u003c\/strong\u003e – customized for employees, IT administrators, incident teams, and management.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eEncryption, authentication, and secure communication\u003c\/strong\u003e – rules for MFA, encryption, key management, and emergency communication.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003ePersonnel, access, and asset security\u003c\/strong\u003e – system and information ownership, permissions, and Joiner-Mover-Leaver process.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eManagement’s annual cybersecurity review\u003c\/strong\u003e – ready-made documentation for structured management review and decision-making.\u003c\/li\u003e\n\n\n\u003c\/ol\u003e\u003ch2\u003eAdapted to the 2026 Cybersecurity Act\u003c\/h2\u003e\u003cp\u003eThe Cybersecurity Act entered into force on \u003cstrong\u003eJanuary 15, 2026\u003c\/strong\u003e. For organizations covered by the act, security work must be based on an all-risk perspective and include appropriate and proportionate technical, operational, and organizational security measures.\u003c\/p\u003e\u003cp\u003eThe template package is built around the central areas that the act requires affected operators to manage, including risk analysis, incident management, continuity, supply chains, secure system acquisition, follow-up of security measures, cyber hygiene, training, cryptography, access control, and authentication.\u003c\/p\u003e\u003ch3\u003eBuilt-in support for incident reporting\u003c\/h3\u003e\u003cp\u003eIn the event of a \u003cstrong\u003esignificant incident\u003c\/strong\u003e, the regulatory framework imposes time-critical obligations. The package therefore contains separate forms and control points for the initial notification, incident report, and final reporting. As a general rule, a significant incident must be reported as soon as possible and no later than within 24 hours, followed by an incident report within the deadline applicable to the organization and subsequently a final report.\u003c\/p\u003e\u003cp\u003eThe forms are designed to help the organization collect information regarding the sequence of events, discovery, affected systems, impact on sector operations, supplier dependencies, consequences, probable root cause, and taken measures.\u003c\/p\u003e\u003ch2\u003ePrepared for MCFFS 2026:11 from October 1, 2026\u003c\/h2\u003e\u003cp\u003eAs of October 1, 2026, \u003cstrong\u003eMCFFS 2026:11\u003c\/strong\u003e enters into force. The regulation contains more detailed requirements and general advice on security measures and management training for essential and important entities.\u003c\/p\u003e\u003cp\u003eThe template package therefore includes, among other things, support for:\u003c\/p\u003e\u003cul\u003e\n\n\u003cli\u003esystematic and risk-based cybersecurity work,\u003c\/li\u003e\n\n\u003cli\u003egoals and direction from management,\u003c\/li\u003e\n\n\u003cli\u003erisk acceptance criteria,\u003c\/li\u003e\n\n\u003cli\u003einformation and system ownership,\u003c\/li\u003e\n\n\u003cli\u003erisk registers and documented action plans,\u003c\/li\u003e\n\n\u003cli\u003eincident and crisis management,\u003c\/li\u003e\n\n\u003cli\u003econtinuity and recovery prioritization,\u003c\/li\u003e\n\n\u003cli\u003esupplier agreements and digital supply chains,\u003c\/li\u003e\n\n\u003cli\u003eaccess management and multi-factor authentication,\u003c\/li\u003e\n\n\u003cli\u003eencryption and secure communication,\u003c\/li\u003e\n\n\u003cli\u003efollow-up and evaluation of security measures,\u003c\/li\u003e\n\n\u003cli\u003emanagement training and annual follow-up.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\u003ch2\u003eWho is this template for?\u003c\/h2\u003e\u003cp\u003eThe package is suitable for Swedish companies, organizations, and other operators who need to create or improve their documentation regarding NIS2 and the Cybersecurity Act. It can be used by, for example, the CEO, board, management team, CISO, IT manager, information security manager, compliance function, legal counsel, data protection officer, system owners, and operations managers.\u003c\/p\u003e\u003cp\u003eThe templates are general and can be adapted to different sectors, organizational sizes, and technical environments. The organization fills in responsible roles, systems, classifications, risk levels, deadlines, suppliers, decision paths, and control levels themselves.\u003c\/p\u003e\u003ch2\u003eProfessional and practical design\u003c\/h2\u003e\u003cp\u003eThe document is not merely an information guide. It is built as a \u003cstrong\u003epractical working material\u003c\/strong\u003e with fillable fields, tables, checklists, decision boxes, and ready-made formulations. The purpose is to reduce the time from regulatory requirements to usable internal documentation.\u003c\/p\u003e\u003cul\u003e\n\n\u003cli\u003e22 professionally designed pages\u003c\/li\u003e\n\n\u003cli\u003e15 integrated templates\u003c\/li\u003e\n\n\u003cli\u003eEditable DOCX file\u003c\/li\u003e\n\n\u003cli\u003ePDF version\u003c\/li\u003e\n\n\u003cli\u003eRisk register and action plan\u003c\/li\u003e\n\n\u003cli\u003eIncident forms\u003c\/li\u003e\n\n\u003cli\u003eSupplier clauses\u003c\/li\u003e\n\n\u003cli\u003eManagement review\u003c\/li\u003e\n\n\u003cli\u003eImplementation checklist ahead of October 1, 2026\u003c\/li\u003e\n\n\u003cli\u003eLegal sources and version information\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\u003ch2\u003eImportant note on legal and technical adaptation\u003c\/h2\u003e\u003cp\u003eThe Cybersecurity Act is risk-based and business-specific. No general document template can alone guarantee that an organization meets all requirements. The documents must be adapted according to the organization's sector, size, system environment, risks, supervisory authority, and any sector-specific or directly applicable EU rules.\u003c\/p\u003e\u003cp\u003eFor organizations exclusively conducting activities within certain digital sectors, other detailed rules may be directly applicable, including the European Commission's Implementing Regulation (EU) 2024\/2690. Therefore, always check the current act, ordinance, regulations, and sector-specific rules before the material is finalized internally.\u003c\/p\u003e\u003ch2\u003eFormat and delivery\u003c\/h2\u003e\u003cp\u003e\u003cstrong\u003eDigital product – immediate download.\u003c\/strong\u003e The delivery contains a ZIP file with:\u003c\/p\u003e\u003cul\u003e\n\n\u003cli\u003eNIS2_CybersecurityAct_TemplatePackage_2026.docx\u003c\/li\u003e\n\n\u003cli\u003eNIS2_CybersecurityAct_TemplatePackage_2026.pdf\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\u003cp\u003eNo physical product is sent.\u003c\/p\u003e\u003ch2\u003eFrequently asked questions\u003c\/h2\u003e\u003ch3\u003eIs this a NIS2 policy?\u003c\/h3\u003e\u003cp\u003eYes, the package contains a complete policy for cybersecurity and information security, but also risk management, incident reporting, continuity, supplier security, MFA, encryption, training, and management follow-up.\u003c\/p\u003e\u003ch3\u003eCan I edit the template?\u003c\/h3\u003e\u003cp\u003eYes. The Word file is fully editable. The PDF version is included as a ready-made reference and print version.\u003c\/p\u003e\u003ch3\u003eIs the template updated for 2026?\u003c\/h3\u003e\u003cp\u003eYes. Version 1.0 is legally reviewed as of September 27, 2026, based on the Cybersecurity Act (2025:1506), the Cybersecurity Ordinance (2025:1507), MCFFS 2026:1, MCFFS 2026:8, and MCFFS 2026:11, which enters into force on October 1, 2026.\u003c\/p\u003e\u003ch3\u003eDoes the package suit all organizations?\u003c\/h3\u003e\u003cp\u003eIt is constructed as a broad base package but must always be adapted. Sector-specific rules and EU law may impose additional or deviating requirements.\u003c\/p\u003e","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55510623617366,"sku":null,"price":199.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/nis2-cybersakerhetslagen-mallpaket-hero.png?v=1790493508"},{"product_id":"personuppgiftsincident-gdpr-mallpaket-2026","title":"GDPR Personal Data Breach Template Package 2026 – Word\/PDF\/Excel","description":"\n\u003ch2\u003ePersonal Data Breach GDPR Template Package 2026 – incident report, IMY notification \u0026amp; 72-hour tool\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eA complete template package for companies and organizations that need to detect, assess, document, and manage personal data breaches according to the GDPR.\u003c\/strong\u003e The package contains professional Word\/PDF templates as well as an Excel tool for incident registers, 72-hour deadlines, risk assessments, IMY (Swedish Authority for Privacy Protection) notifications, information to data subjects, processor reporting, and post-incident analysis.\u003c\/p\u003e\n\n\u003cp\u003eThe GDPR requires that \u003cstrong\u003eall personal data breaches be documented\u003c\/strong\u003e. A breach must be reported to the supervisory authority unless it is unlikely that it will result in a risk to the rights and freedoms of natural persons. If a notification is required, it must be made without undue delay and, where feasible, within \u003cstrong\u003e72 hours\u003c\/strong\u003e of the controller becoming aware of the breach.\u003c\/p\u003e\n\n\u003ch3\u003eIncluded – 9 files\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003ePersonal Data Breach – Incident Report \u0026amp; 72-hour assessment, Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eNotification to IMY – preparation documentation, Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eInformation to data subjects according to Article 34 GDPR, Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eProcedure for personal data breaches \/ Incident Response Playbook, Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eExcel tool with incident register, 72h status, risk classification, IMY log, data subjects, processor notices, measures, and post-incident analysis\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eIncident report with complete decision-making process\u003c\/h3\u003e\n\u003cp\u003eThe main template helps the organization document the entire incident from initial detection to closure:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003etime of incident, detection, and organization awareness\u003c\/li\u003e\n\n\u003cli\u003eautomatic\/clear 72-hour deadline\u003c\/li\u003e\n\n\u003cli\u003eclassification as a confidentiality, integrity, or availability breach\u003c\/li\u003e\n\n\u003cli\u003eaffected data subjects and personal data\u003c\/li\u003e\n\n\u003cli\u003esensitive data, Article 10 data, protected personal data, and children\/vulnerable individuals\u003c\/li\u003e\n\n\u003cli\u003eimmediate containment and recovery measures\u003c\/li\u003e\n\n\u003cli\u003erisk assessment for the rights and freedoms of data subjects\u003c\/li\u003e\n\n\u003cli\u003edecision regarding IMY notification\u003c\/li\u003e\n\n\u003cli\u003edecision regarding information to data subjects\u003c\/li\u003e\n\n\u003cli\u003eroot cause, corrective measures, and lessons learned\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eWhen should the breach be reported?\u003c\/h3\u003e\n\u003cp\u003eAs a data controller, you must report the breach if it is \u003cstrong\u003enot unlikely\u003c\/strong\u003e that it will result in a risk to the rights and freedoms of natural persons. If all information is not available within 72 hours, the information may be provided in phases without undue further delay. In the event of a late notification, the reasons for the delay must be documented.\u003c\/p\u003e\n\n\u003cp\u003eThe package therefore contains a separate \u003cstrong\u003eIMY preparation template\u003c\/strong\u003e with the central information that needs to be collected before or during the reporting. The actual notification is made via IMY's current e-service or other channel designated by the authority.\u003c\/p\u003e\n\n\u003ch3\u003eHigh risk – information to data subjects\u003c\/h3\u003e\n\u003cp\u003eIf the personal data breach is likely to result in a \u003cstrong\u003ehigh risk\u003c\/strong\u003e, the data subjects must, as a general rule, be informed without undue delay. The package contains a ready-to-use and editable communication template with:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eclear description of what has happened\u003c\/li\u003e\n\n\u003cli\u003ewhat personal data is affected\u003c\/li\u003e\n\n\u003cli\u003elikely consequences\u003c\/li\u003e\n\n\u003cli\u003eimplemented and planned measures\u003c\/li\u003e\n\n\u003cli\u003epractical advice to the data subjects\u003c\/li\u003e\n\n\u003cli\u003econtact details for the Data Protection Officer or other point of contact\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe template also includes a check against Article 34 exceptions, for example, if the data was effectively encrypted, if subsequent measures eliminated the high risk, or if individual notification involves disproportionate effort.\u003c\/p\u003e\n\n\u003ch3\u003eObligations of the processor\u003c\/h3\u003e\n\u003cp\u003eA processor must report a personal data breach to the controller \u003cstrong\u003ewithout undue delay\u003c\/strong\u003e. The processor does not need to determine whether the incident entails such a risk that it must be reported to IMY – the primary responsibility for the risk and notification assessment lies with the controller.\u003c\/p\u003e\n\n\u003cp\u003eThe Excel tool therefore contains a separate register for processor notices with awareness time, initial report, time difference, missing information, and next update.\u003c\/p\u003e\n\n\u003ch3\u003eExcel – incident register with 72-hour check\u003c\/h3\u003e\n\u003cp\u003eThe Excel file serves as a practical incident management tool and contains:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003edashboard with key performance indicators\u003c\/li\u003e\n\n\u003cli\u003eincident register\u003c\/li\u003e\n\n\u003cli\u003e72-hour deadline and status \u003cem\u003eOn time \/ Urgent \/ Overdue\u003c\/em\u003e\n\n\u003c\/li\u003e\n\n\u003cli\u003erisk classification based on probability and impact\u003c\/li\u003e\n\n\u003cli\u003eIMY notification register\u003c\/li\u003e\n\n\u003cli\u003ecommunication to data subjects\u003c\/li\u003e\n\n\u003cli\u003eprocessor reporting\u003c\/li\u003e\n\n\u003cli\u003emeasures register\u003c\/li\u003e\n\n\u003cli\u003ePost-Incident Review \/ root cause analysis\u003c\/li\u003e\n\n\u003cli\u003esources and legal references\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eAll breaches must be documented\u003c\/h3\u003e\n\u003cp\u003eEven breaches that do not need to be reported to IMY must be documented. The documentation should, among other things, make it possible to verify that the organization has followed the GDPR and should also include the reasons for the decision not to notify or not to inform data subjects.\u003c\/p\u003e\n\n\u003ch3\u003eCommon incidents for which the package can be used\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003emisdirected emails or documents\u003c\/li\u003e\n\n\u003cli\u003ephishing and compromised accounts\u003c\/li\u003e\n\n\u003cli\u003eransomware and data breaches\u003c\/li\u003e\n\n\u003cli\u003eincorrect access rights\u003c\/li\u003e\n\n\u003cli\u003elost computer, phone, or storage media\u003c\/li\u003e\n\n\u003cli\u003eaccidental publication\u003c\/li\u003e\n\n\u003cli\u003eincorrect sharing via cloud service or link\u003c\/li\u003e\n\n\u003cli\u003edeletion or loss of personal data\u003c\/li\u003e\n\n\u003cli\u003eincident at a processor or subcontractor\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cp\u003eThe template package has been legally reviewed as of \u003cstrong\u003eOctober 3, 2026\u003c\/strong\u003e, based on:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eGDPR Article 4(12)\u003c\/li\u003e\n\n\u003cli\u003eGDPR Article 33 – notification to the supervisory authority and documentation\u003c\/li\u003e\n\n\u003cli\u003eGDPR Article 34 – information to data subjects\u003c\/li\u003e\n\n\u003cli\u003eIMY's current guidance on personal data breaches and e-service\u003c\/li\u003e\n\n\u003cli\u003eEDPB Guidelines 01\/2021 on Examples regarding Personal Data Breach Notification\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eDuring 2026, the EDPB also published a proposal for a common European breach-notification-template for public consultation. The legal accuracy of this package is not based on a consultation document that has not yet been fully implemented, but on current GDPR, IMY's current guidance, and adopted EDPB guidelines.\u003c\/p\u003e\n\n\u003ch3\u003ePlease note\u003c\/h3\u003e\n\u003cp\u003eThe package is a general compliance and documentation framework. An actual incident may simultaneously be covered by other reporting regulations, such as sector-specific requirements in finance, cybersecurity, healthcare, or public operations. Therefore, always check whether additional authorities, contracting parties, insurers, or other actors need to be informed.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF + Excel (XLSX)\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden \/ EU\u003cbr\u003e\n\u003cstrong\u003eNumber of files:\u003c\/strong\u003e 9\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 1.0 – 2026-10-03\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55590536610134,"sku":"GDPR-INCIDENT-2026","price":249.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/personuppgiftsincident-gdpr-mallpaket-2026.png?v=1791040791"},{"product_id":"incident-response-cyber-crisis-2026-2027-svenska-english-nis2-gdpr-dora-word-pdf-excel","title":"Incident Response \u0026 Cyber Crisis 2026\/2027 – Swedish + English | NIS2, GDPR, DORA Word\/PDF\/Excel","description":"\u003cdiv id=\"about-the-template\"\u003e\n\u003ch2\u003eIncident Response \u0026amp; Cyber Crisis 2026\/2027 – complete operational template package in Swedish + English\u003c\/h2\u003e\n\u003cp\u003eA complete template package for companies and organisations that need to manage \u003cstrong\u003eIT incidents, cyber incidents and cyber crises\u003c\/strong\u003e from the first alert through final reporting, recovery and improvement. The package is intentionally broader than a pure NIS2 or GDPR package: it serves as the operational incident backbone and helps the organisation determine when the \u003cstrong\u003eSwedish Cybersecurity Act\/NIS2, GDPR, DORA, customer agreements, supplier agreements or cyber insurance\u003c\/strong\u003e trigger specific reporting or communication requirements.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e2-in-1 Swedish + English:\u003c\/strong\u003e seven documents are included in both language versions. All are delivered in Word and PDF and are complemented by an advanced Excel register with automatic regulatory reporting clocks. The package contains \u003cstrong\u003e29 delivery files\u003c\/strong\u003e in total.\u003c\/p\u003e\n\n\u003cnav aria-label=\"About the template\" style=\"border:1px solid #dbe4ea;padding:16px;border-radius:10px;background:#f7fafc;margin:18px 0;\"\u003e\n\u003cstrong\u003eAbout the template\u003c\/strong\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"#reviewed\"\u003eLegally and operationally reviewed 2026\/2027\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#included\"\u003eWhat is included\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#built-for\"\u003eBuilt for the full incident lifecycle\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#nis2\"\u003eSwedish Cybersecurity Act\/NIS2 – 24h, 72h and final report\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#gdpr-dora\"\u003eGDPR and DORA – separate reporting tracks\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#classification\"\u003eIncident classification and severity\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#crisis\"\u003eCyber crisis and communications\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#evidence\"\u003eEvidence, chain of custody and forensics\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#recovery\"\u003eRecovery and Post-Incident Review\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#excel\"\u003eExcel register and automatic deadlines\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#faq\"\u003eFrequently asked questions\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#sources\"\u003eLegal basis and official sources\u003c\/a\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/nav\u003e\n\n\u003cdiv id=\"reviewed\" style=\"border:1px solid #b7dec5;background:#e9f6ee;padding:18px;border-radius:10px;margin:18px 0;\"\u003e\n\u003cstrong\u003eLegally and operationally reviewed: 6 October 2026\u003c\/strong\u003e\u003cbr\u003e\nThe package has been reviewed against the current \u003cstrong\u003eSwedish Cybersecurity Act (2025:1506)\u003c\/strong\u003e, the NIS2 incident-reporting structure, the GDPR rules on personal data breaches and current DORA reporting for relevant financial entities. The templates are designed for use during \u003cstrong\u003e2026\/2027\u003c\/strong\u003e and explicitly separate the trigger criteria and deadlines under the different regulatory frameworks.\n\u003c\/div\u003e\n\n\u003ch2 id=\"included\"\u003eWhat is included in the package\u003c\/h2\u003e\n\u003cdiv style=\"overflow-x:auto;\"\u003e\n\u003ctable style=\"width:100%;border-collapse:collapse;\"\u003e\n\u003cthead\u003e\u003ctr\u003e\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eDocument\u003c\/th\u003e\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eSwedish\u003c\/th\u003e\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eEnglish\u003c\/th\u003e\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eUse\u003c\/th\u003e\n\u003c\/tr\u003e\u003c\/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eIncident Response \u0026amp; Cyber Crisis Plan\u003c\/strong\u003e\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eMaster plan, roles, authority, the first 60 minutes and regulatory trigger points.\u003c\/td\u003e\u003c\/tr\u003e\n\u003ctr\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eIncident Intake, Classification \u0026amp; Severity\u003c\/strong\u003e\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eCIA impact, severity, regulatory screening and classification decision.\u003c\/td\u003e\u003c\/tr\u003e\n\u003ctr\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003e24h \/ 72h \/ Final Report\u003c\/strong\u003e\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWorking fields for the Swedish Cybersecurity Act\/NIS2 reporting chain and GDPR\/DORA cross-checks.\u003c\/td\u003e\u003c\/tr\u003e\n\u003ctr\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eCyber Crisis \u0026amp; Communications Plan\u003c\/strong\u003e\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eSITREP, audience matrix, customer notice and communications log.\u003c\/td\u003e\u003c\/tr\u003e\n\u003ctr\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eTechnical Containment, Evidence \u0026amp; Forensics Log\u003c\/strong\u003e\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eTechnical action register, chain of custody, IoCs and supplier evidence.\u003c\/td\u003e\u003c\/tr\u003e\n\u003ctr\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eRecovery, Continuity \u0026amp; Post-Incident Review\u003c\/strong\u003e\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eRecovery gates, verification, root cause and remediation plan.\u003c\/td\u003e\u003c\/tr\u003e\n\u003ctr\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eDetailed user guide\u003c\/strong\u003e\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWorkflow, legal cross-checks, incident types and common pitfalls.\u003c\/td\u003e\u003c\/tr\u003e\n\u003ctr\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eIncident Response Excel Register\u003c\/strong\u003e\u003c\/td\u003e\u003ctd colspan=\"2\" style=\"border:1px solid #d5dde3;padding:10px;\"\u003eXLSX\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eDashboard, incident register, regulatory deadlines, actions, evidence, communications, contacts and PIR.\u003c\/td\u003e\u003c\/tr\u003e\n\u003c\/tbody\u003e\n\u003c\/table\u003e\n\u003c\/div\u003e\n\n\u003cdiv id=\"built-for\" style=\"background:#fff4cc;border-left:5px solid #d9a800;padding:20px;border-radius:8px;margin:22px 0;\"\u003e\n\u003cstrong style=\"font-size:1.1em;\"\u003eBuilt for the full incident lifecycle – not only the regulatory notification\u003c\/strong\u003e\u003cbr\u003e\nA major risk during a cyber incident is treating technology, legal obligations, communications and recovery as separate workstreams. This package connects \u003cstrong\u003edetection → classification → containment → reporting assessment → communications → recovery → Post-Incident Review\u003c\/strong\u003e. The same Incident ID follows the case throughout the process.\n\u003c\/div\u003e\n\n\u003ch2\u003eThe first 60 minutes – one common structure\u003c\/h2\u003e\n\u003cp\u003eThe master plan starts with decisions that often need to be taken before the organisation has a complete picture. The Incident ID and awareness time are recorded immediately, an Incident Lead is appointed, an alternative communications channel is secured and volatile evidence is preserved before irreversible actions are taken.\u003c\/p\u003e\n\u003cp\u003eThis is also where regulatory clocks should be started. The moment when the organisation actually becomes \u003cem\u003eaware\u003c\/em\u003e of an incident can be central under the Swedish Cybersecurity Act, GDPR and DORA. The templates therefore distinguish between detection time, awareness time and classification time.\u003c\/p\u003e\n\n\u003ch2 id=\"nis2\"\u003eSwedish Cybersecurity Act\/NIS2 – 24 hours, 72 hours and one month\u003c\/h2\u003e\n\u003cp\u003eSweden's \u003cstrong\u003eCybersecurity Act (2025:1506)\u003c\/strong\u003e entered into force on 15 January 2026. It requires appropriate and proportionate technical, operational and organisational security measures. The areas expressly covered include \u003cstrong\u003eincident handling\u003c\/strong\u003e and \u003cstrong\u003ebusiness continuity and crisis management\u003c\/strong\u003e.\u003c\/p\u003e\n\u003cp\u003eFor an entity covered by the Act that suffers a \u003cstrong\u003esignificant incident\u003c\/strong\u003e, the package supports the following operational sequence:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ewithin 24 hours:\u003c\/strong\u003e early warning after the entity becomes aware of the incident,\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003ewithin 72 hours:\u003c\/strong\u003e incident notification for other entities; trust service providers have a 24-hour deadline for the incident notification as well,\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003eon request:\u003c\/strong\u003e an intermediate report with relevant status updates,\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003ewithin one month after the incident notification:\u003c\/strong\u003e final report; if the incident is still ongoing, a progress report is followed by a later final report.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eUnder the Act, a significant incident is an incident that has caused or is capable of causing severe operational disruption to the service or financial loss to the entity, or that has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.\u003c\/p\u003e\n\n\u003ch2 id=\"gdpr-dora\"\u003eThe same incident may trigger several legal reporting tracks\u003c\/h2\u003e\n\u003cp\u003eThe package does not make the common mistake of treating NIS2, GDPR and DORA as the same thing. They have different scopes, trigger criteria and recipients.\u003c\/p\u003e\n\n\u003ch3\u003eGDPR – personal data breach\u003c\/h3\u003e\n\u003cp\u003eIf the incident means that personal data has been destroyed, altered, lost or disclosed to or accessed by unauthorised persons, the GDPR track must be assessed separately. Where a personal data breach is reportable, the starting point is notification to the Swedish Authority for Privacy Protection (IMY) within \u003cstrong\u003e72 hours of becoming aware\u003c\/strong\u003e. Where the breach is likely to result in a high risk, affected data subjects may also need to be informed without undue delay.\u003c\/p\u003e\n\n\u003ch3\u003eDORA – financial entities\u003c\/h3\u003e\n\u003cp\u003eDORA applies to relevant financial entities. For a major ICT-related incident, the current reporting standards include:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003ean initial report as soon as possible, \u003cstrong\u003ewithin four hours after classification as major\u003c\/strong\u003e and no later than \u003cstrong\u003e24 hours after awareness\u003c\/strong\u003e,\u003c\/li\u003e\n\u003cli\u003ean intermediate report no later than \u003cstrong\u003e72 hours after the initial report\u003c\/strong\u003e,\u003c\/li\u003e\n\u003cli\u003ea final report no later than \u003cstrong\u003eone month after the intermediate report\u003c\/strong\u003e or the latest updated intermediate report.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eThe Excel register therefore uses a separate DORA clock instead of mixing it with the NIS2 timeline.\u003c\/p\u003e\n\n\u003ch2 id=\"classification\"\u003eIncident classification – from technical event to SEV level\u003c\/h2\u003e\n\u003cp\u003eThe Incident Intake template helps the team assess confidentiality, integrity and availability together with physical\/safety, financial and third-party impact. The incident is then classified into four levels from SEV-4 to SEV-1.\u003c\/p\u003e\n\u003cp\u003eThe SEV level is an internal governance tool and does not replace the legal assessment of whether an incident is, for example, “significant” under the Swedish Cybersecurity Act or “major” under DORA. Regulatory screening is therefore a separate decision step.\u003c\/p\u003e\n\n\u003ch2 id=\"crisis\"\u003eCyber crisis and communications\u003c\/h2\u003e\n\u003cp\u003eFor larger incidents, technical incident handling is not enough. The Cyber Crisis plan establishes a crisis organisation with roles such as Incident Lead, Crisis Manager, Legal\/Compliance, Communications, DPO\/Privacy and Supplier Lead.\u003c\/p\u003e\n\u003cp\u003eIt includes a reusable \u003cstrong\u003eSITREP\u003c\/strong\u003e for management, an audience matrix for employees\/customers\/authorities\/suppliers\/media, a customer-notification structure and a communications log. The pre-publication checklist reduces the risk of releasing unverified information or security details that could be exploited by an attacker.\u003c\/p\u003e\n\n\u003ch2 id=\"evidence\"\u003eEvidence, chain of custody and technical containment\u003c\/h2\u003e\n\u003cp\u003eTechnical actions can destroy evidence if they are carried out without documentation. The package therefore includes a separate action register and chain-of-custody section for logs, disk\/memory data, cloud exports and other relevant evidence.\u003c\/p\u003e\n\u003cp\u003eThe document covers, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003etime and time zone,\u003c\/li\u003e\n\u003cli\u003esource\/system and the person who collected the material,\u003c\/li\u003e\n\u003cli\u003ehash\/integrity reference where relevant,\u003c\/li\u003e\n\u003cli\u003estorage location and access\/transfer history,\u003c\/li\u003e\n\u003cli\u003eIndicators of Compromise – IP address, domain, hash, account, process and TTP,\u003c\/li\u003e\n\u003cli\u003esupplier incidents and which logs\/evidence have been requested.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch2 id=\"recovery\"\u003eRecovery, continuity and Post-Incident Review\u003c\/h2\u003e\n\u003cp\u003eThe recovery template uses clear reconnection gates: backups should be verified, clean installation sources available, compromised credentials rotated and the vulnerability or root cause addressed before systems are reconnected.\u003c\/p\u003e\n\u003cp\u003eAfter restoration, a Post-Incident Review is carried out covering root cause, contributing factors, what worked, what did not work, regulatory lessons and supplier lessons. Improvement actions are assigned an owner, priority, deadline and evidence requirement.\u003c\/p\u003e\n\n\u003ch2 id=\"excel\"\u003eExcel register with automatic reporting clocks\u003c\/h2\u003e\n\u003cp\u003eThe Excel workbook is more than a list. It acts as an operational control panel and includes:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eDashboard\u003c\/strong\u003e – open incidents, SEV-1\/2 and active reporting tracks,\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003eIncident Register\u003c\/strong\u003e – detection, awareness, phase, impact and next update,\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003eRegulatory Deadlines\u003c\/strong\u003e – separate NIS2, GDPR and DORA clocks,\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003eAction Log\u003c\/strong\u003e – containment, recovery, regulatory and communications actions,\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003eEvidence Chain\u003c\/strong\u003e – chain of custody and integrity,\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003eCommunications\u003c\/strong\u003e – version, audience, approval and evidence,\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003eContacts\u003c\/strong\u003e – incident team, authorities, suppliers, insurer and forensics,\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003ePost Incident\u003c\/strong\u003e – PIR, remediation and residual risk.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eFor example, the Swedish Cybersecurity Act's 24-hour and 72-hour deadlines are calculated automatically from the recorded awareness time. DORA uses a separate formula that takes both awareness time and the time of classification as a major incident into account.\u003c\/p\u003e\n\n\u003ch2\u003eWhen the package is particularly useful\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003ecompanies that want to establish a professional Incident Response process,\u003c\/li\u003e\n\u003cli\u003eNIS2\/Swedish Cybersecurity Act-regulated entities that want to complement their broader NIS2 programme,\u003c\/li\u003e\n\u003cli\u003eSaaS, IT, MSP and cloud organisations,\u003c\/li\u003e\n\u003cli\u003eorganisations processing significant volumes of personal data,\u003c\/li\u003e\n\u003cli\u003efinancial entities that need to coordinate DORA with internal cyber-crisis management,\u003c\/li\u003e\n\u003cli\u003eorganisations with critical supplier and third-party dependencies.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch2\u003eHow this differs from Mallbutiken's other incident templates\u003c\/h2\u003e\n\u003cp\u003eThe \u003cstrong\u003eNIS2 Template Package\u003c\/strong\u003e covers the broader systematic cybersecurity programme. The \u003cstrong\u003eGDPR Personal Data Breach\u003c\/strong\u003e package goes deeper into Articles 33\/34 and the IMY process. This package instead focuses on \u003cstrong\u003ethe operational incident and cyber crisis as a whole\u003c\/strong\u003e – from the first alert to containment, regulatory triage, customer communications, recovery and Post-Incident Review.\u003c\/p\u003e\n\n\u003ch2 id=\"faq\"\u003eFrequently asked questions\u003c\/h2\u003e\n\u003ch3\u003eIs the package only for organisations covered by NIS2?\u003c\/h3\u003e\n\u003cp\u003eNo. The Incident Response process can be used by most organisations. The Swedish Cybersecurity Act\/NIS2 track is activated only if the organisation and incident fall within that regulatory framework.\u003c\/p\u003e\n\n\u003ch3\u003eAre all cyber incidents reportable within 24 or 72 hours?\u003c\/h3\u003e\n\u003cp\u003eNo. The deadlines apply only when the trigger criteria under the relevant framework are met. The package therefore contains separate screening and decision points.\u003c\/p\u003e\n\n\u003ch3\u003eCan the same incident need to be reported under both NIS2 and GDPR?\u003c\/h3\u003e\n\u003cp\u003eYes. An incident can simultaneously be significant under the Swedish Cybersecurity Act and constitute a reportable personal data breach. The two assessments should be carried out in parallel.\u003c\/p\u003e\n\n\u003ch3\u003eIs DORA included?\u003c\/h3\u003e\n\u003cp\u003eYes, as a separate cross-track for relevant financial entities. The package does not, however, replace a complete DORA compliance programme.\u003c\/p\u003e\n\n\u003ch3\u003eAre English documents included?\u003c\/h3\u003e\n\u003cp\u003eYes. All seven Word\/PDF templates are provided in a separate English version. The Excel register uses clear internationally usable incident fields.\u003c\/p\u003e\n\n\u003ch3\u003eIs Excel included?\u003c\/h3\u003e\n\u003cp\u003eYes. The Excel register is a central part of the product and includes automatic regulatory deadlines and registers for incidents, actions, evidence, communications and Post-Incident Review.\u003c\/p\u003e\n\n\u003ch2\u003eFormat and delivery\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e14 document templates\u003c\/strong\u003e – 7 Swedish + 7 English.\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003e14 DOCX + 14 PDF + 1 XLSX = 29 delivery files.\u003c\/strong\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003e28 A4 pages per Word\/PDF format series across both language versions.\u003c\/strong\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003eWord (DOCX) + PDF + Excel (XLSX).\u003c\/strong\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003eDigital product – no physical item is shipped.\u003c\/strong\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch2 id=\"sources\"\u003eLegal basis and official sources\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https:\/\/www.riksdagen.se\/sv\/dokument-och-lagar\/dokument\/svensk-forfattningssamling\/cybersakerhetslag-20251506_sfs-2025-1506\/\"\u003eSwedish Cybersecurity Act (2025:1506)\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN-SV\/ALL\/?uri=CELEX:32022L2555\"\u003eDirective (EU) 2022\/2555 – NIS2\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"https:\/\/www.imy.se\/verksamhet\/dataskydd\/det-har-galler-enligt-gdpr\/personuppgiftsincidenter\/hantering-av-personuppgiftsincidenter\/\"\u003eIMY – Personal data breach handling\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"https:\/\/www.fi.se\/sv\/marknad\/rapportering2\/ikt-risker-dora\/\"\u003eSwedish Financial Supervisory Authority – ICT risks and DORA\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"https:\/\/eur-lex.europa.eu\/legal-content\/SV\/TXT\/?uri=CELEX:32025R0301\"\u003eCommission Delegated Regulation (EU) 2025\/301 – DORA incident reporting\u003c\/a\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003cdiv style=\"background:#f3f5f7;border:1px solid #d5dde3;padding:16px;border-radius:8px;margin-top:20px;\"\u003e\n\u003cstrong\u003eImportant:\u003c\/strong\u003e The package is an operational and documentation aid. It does not automatically determine whether an organisation is subject to a particular regulatory framework or whether a specific incident meets a legal reporting threshold. Always verify the current sector, competent authority, regulations, contractual requirements and the actual incident circumstances.\n\u003c\/div\u003e\n\u003c\/div\u003e","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55615332614486,"sku":"INCIDENT-RESPONSE-CYBER-CRISIS-2026-2027","price":79.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/incident-response-cyber-crisis-2026-2027.png?v=1791245747"}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/collections\/incident-response-cyber-crisis-2026-2027.png?v=1791245776","url":"https:\/\/mallbutiken.se\/en\/collections\/incidenthantering-cyberkris-mallar.oembed","provider":"Mallbutiken","version":"1.0","type":"link"}