Skip to product information
1 of 3

Svenska Dokumentmallar

Incident Response & Cyber Crisis 2026/2027 – Swedish + English | NIS2, GDPR, DORA Word/PDF/Excel

Incident Response & Cyber Crisis 2026/2027 – Swedish + English | NIS2, GDPR, DORA Word/PDF/Excel

File format
DOCX, PDF, XLSX
Document language
Swedish
Number of files
15

Digital download. No physical product is shipped.

Regular price 79 SEK
Regular price Sale price 79 SEK
Sale Sold out
Taxes included.
View full details

About this template

Incident Response & Cyber Crisis 2026/2027 – complete operational template package in Swedish + English

A complete template package for companies and organisations that need to manage IT incidents, cyber incidents and cyber crises from the first alert through final reporting, recovery and improvement. The package is intentionally broader than a pure NIS2 or GDPR package: it serves as the operational incident backbone and helps the organisation determine when the Swedish Cybersecurity Act/NIS2, GDPR, DORA, customer agreements, supplier agreements or cyber insurance trigger specific reporting or communication requirements.

2-in-1 Swedish + English: seven documents are included in both language versions. All are delivered in Word and PDF and are complemented by an advanced Excel register with automatic regulatory reporting clocks. The package contains 29 delivery files in total.

Legally and operationally reviewed: 6 October 2026
The package has been reviewed against the current Swedish Cybersecurity Act (2025:1506), the NIS2 incident-reporting structure, the GDPR rules on personal data breaches and current DORA reporting for relevant financial entities. The templates are designed for use during 2026/2027 and explicitly separate the trigger criteria and deadlines under the different regulatory frameworks.

What is included in the package

Document Swedish English Use
Incident Response & Cyber Crisis Plan2 pages2 pagesMaster plan, roles, authority, the first 60 minutes and regulatory trigger points.
Incident Intake, Classification & Severity2 pages2 pagesCIA impact, severity, regulatory screening and classification decision.
24h / 72h / Final Report2 pages2 pagesWorking fields for the Swedish Cybersecurity Act/NIS2 reporting chain and GDPR/DORA cross-checks.
Cyber Crisis & Communications Plan2 pages2 pagesSITREP, audience matrix, customer notice and communications log.
Technical Containment, Evidence & Forensics Log2 pages2 pagesTechnical action register, chain of custody, IoCs and supplier evidence.
Recovery, Continuity & Post-Incident Review2 pages2 pagesRecovery gates, verification, root cause and remediation plan.
Detailed user guide2 pages2 pagesWorkflow, legal cross-checks, incident types and common pitfalls.
Incident Response Excel RegisterXLSXDashboard, incident register, regulatory deadlines, actions, evidence, communications, contacts and PIR.
Built for the full incident lifecycle – not only the regulatory notification
A major risk during a cyber incident is treating technology, legal obligations, communications and recovery as separate workstreams. This package connects detection → classification → containment → reporting assessment → communications → recovery → Post-Incident Review. The same Incident ID follows the case throughout the process.

The first 60 minutes – one common structure

The master plan starts with decisions that often need to be taken before the organisation has a complete picture. The Incident ID and awareness time are recorded immediately, an Incident Lead is appointed, an alternative communications channel is secured and volatile evidence is preserved before irreversible actions are taken.

This is also where regulatory clocks should be started. The moment when the organisation actually becomes aware of an incident can be central under the Swedish Cybersecurity Act, GDPR and DORA. The templates therefore distinguish between detection time, awareness time and classification time.

Swedish Cybersecurity Act/NIS2 – 24 hours, 72 hours and one month

Sweden's Cybersecurity Act (2025:1506) entered into force on 15 January 2026. It requires appropriate and proportionate technical, operational and organisational security measures. The areas expressly covered include incident handling and business continuity and crisis management.

For an entity covered by the Act that suffers a significant incident, the package supports the following operational sequence:

  • within 24 hours: early warning after the entity becomes aware of the incident,
  • within 72 hours: incident notification for other entities; trust service providers have a 24-hour deadline for the incident notification as well,
  • on request: an intermediate report with relevant status updates,
  • within one month after the incident notification: final report; if the incident is still ongoing, a progress report is followed by a later final report.

Under the Act, a significant incident is an incident that has caused or is capable of causing severe operational disruption to the service or financial loss to the entity, or that has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.

The same incident may trigger several legal reporting tracks

The package does not make the common mistake of treating NIS2, GDPR and DORA as the same thing. They have different scopes, trigger criteria and recipients.

GDPR – personal data breach

If the incident means that personal data has been destroyed, altered, lost or disclosed to or accessed by unauthorised persons, the GDPR track must be assessed separately. Where a personal data breach is reportable, the starting point is notification to the Swedish Authority for Privacy Protection (IMY) within 72 hours of becoming aware. Where the breach is likely to result in a high risk, affected data subjects may also need to be informed without undue delay.

DORA – financial entities

DORA applies to relevant financial entities. For a major ICT-related incident, the current reporting standards include:

  • an initial report as soon as possible, within four hours after classification as major and no later than 24 hours after awareness,
  • an intermediate report no later than 72 hours after the initial report,
  • a final report no later than one month after the intermediate report or the latest updated intermediate report.

The Excel register therefore uses a separate DORA clock instead of mixing it with the NIS2 timeline.

Incident classification – from technical event to SEV level

The Incident Intake template helps the team assess confidentiality, integrity and availability together with physical/safety, financial and third-party impact. The incident is then classified into four levels from SEV-4 to SEV-1.

The SEV level is an internal governance tool and does not replace the legal assessment of whether an incident is, for example, “significant” under the Swedish Cybersecurity Act or “major” under DORA. Regulatory screening is therefore a separate decision step.

Cyber crisis and communications

For larger incidents, technical incident handling is not enough. The Cyber Crisis plan establishes a crisis organisation with roles such as Incident Lead, Crisis Manager, Legal/Compliance, Communications, DPO/Privacy and Supplier Lead.

It includes a reusable SITREP for management, an audience matrix for employees/customers/authorities/suppliers/media, a customer-notification structure and a communications log. The pre-publication checklist reduces the risk of releasing unverified information or security details that could be exploited by an attacker.

Evidence, chain of custody and technical containment

Technical actions can destroy evidence if they are carried out without documentation. The package therefore includes a separate action register and chain-of-custody section for logs, disk/memory data, cloud exports and other relevant evidence.

The document covers, among other things:

  • time and time zone,
  • source/system and the person who collected the material,
  • hash/integrity reference where relevant,
  • storage location and access/transfer history,
  • Indicators of Compromise – IP address, domain, hash, account, process and TTP,
  • supplier incidents and which logs/evidence have been requested.

Recovery, continuity and Post-Incident Review

The recovery template uses clear reconnection gates: backups should be verified, clean installation sources available, compromised credentials rotated and the vulnerability or root cause addressed before systems are reconnected.

After restoration, a Post-Incident Review is carried out covering root cause, contributing factors, what worked, what did not work, regulatory lessons and supplier lessons. Improvement actions are assigned an owner, priority, deadline and evidence requirement.

Excel register with automatic reporting clocks

The Excel workbook is more than a list. It acts as an operational control panel and includes:

  • Dashboard – open incidents, SEV-1/2 and active reporting tracks,
  • Incident Register – detection, awareness, phase, impact and next update,
  • Regulatory Deadlines – separate NIS2, GDPR and DORA clocks,
  • Action Log – containment, recovery, regulatory and communications actions,
  • Evidence Chain – chain of custody and integrity,
  • Communications – version, audience, approval and evidence,
  • Contacts – incident team, authorities, suppliers, insurer and forensics,
  • Post Incident – PIR, remediation and residual risk.

For example, the Swedish Cybersecurity Act's 24-hour and 72-hour deadlines are calculated automatically from the recorded awareness time. DORA uses a separate formula that takes both awareness time and the time of classification as a major incident into account.

When the package is particularly useful

  • companies that want to establish a professional Incident Response process,
  • NIS2/Swedish Cybersecurity Act-regulated entities that want to complement their broader NIS2 programme,
  • SaaS, IT, MSP and cloud organisations,
  • organisations processing significant volumes of personal data,
  • financial entities that need to coordinate DORA with internal cyber-crisis management,
  • organisations with critical supplier and third-party dependencies.

How this differs from Mallbutiken's other incident templates

The NIS2 Template Package covers the broader systematic cybersecurity programme. The GDPR Personal Data Breach package goes deeper into Articles 33/34 and the IMY process. This package instead focuses on the operational incident and cyber crisis as a whole – from the first alert to containment, regulatory triage, customer communications, recovery and Post-Incident Review.

Frequently asked questions

Is the package only for organisations covered by NIS2?

No. The Incident Response process can be used by most organisations. The Swedish Cybersecurity Act/NIS2 track is activated only if the organisation and incident fall within that regulatory framework.

Are all cyber incidents reportable within 24 or 72 hours?

No. The deadlines apply only when the trigger criteria under the relevant framework are met. The package therefore contains separate screening and decision points.

Can the same incident need to be reported under both NIS2 and GDPR?

Yes. An incident can simultaneously be significant under the Swedish Cybersecurity Act and constitute a reportable personal data breach. The two assessments should be carried out in parallel.

Is DORA included?

Yes, as a separate cross-track for relevant financial entities. The package does not, however, replace a complete DORA compliance programme.

Are English documents included?

Yes. All seven Word/PDF templates are provided in a separate English version. The Excel register uses clear internationally usable incident fields.

Is Excel included?

Yes. The Excel register is a central part of the product and includes automatic regulatory deadlines and registers for incidents, actions, evidence, communications and Post-Incident Review.

Format and delivery

  • 14 document templates – 7 Swedish + 7 English.
  • 14 DOCX + 14 PDF + 1 XLSX = 29 delivery files.
  • 28 A4 pages per Word/PDF format series across both language versions.
  • Word (DOCX) + PDF + Excel (XLSX).
  • Digital product – no physical item is shipped.

Legal basis and official sources

Important: The package is an operational and documentation aid. It does not automatically determine whether an organisation is subject to a particular regulatory framework or whether a specific incident meets a legal reporting threshold. Always verify the current sector, competent authority, regulations, contractual requirements and the actual incident circumstances.