{"product_id":"incident-response-cyber-crisis-2026-2027-svenska-english-nis2-gdpr-dora-word-pdf-excel","title":"Incident Response \u0026 Cyber Crisis 2026\/2027 – Swedish + English | NIS2, GDPR, DORA Word\/PDF\/Excel","description":"\u003cdiv id=\"about-the-template\"\u003e\n\u003ch2\u003eIncident Response \u0026amp; Cyber Crisis 2026\/2027 – complete operational template package in Swedish + English\u003c\/h2\u003e\n\u003cp\u003eA complete template package for companies and organisations that need to manage \u003cstrong\u003eIT incidents, cyber incidents and cyber crises\u003c\/strong\u003e from the first alert through final reporting, recovery and improvement. The package is intentionally broader than a pure NIS2 or GDPR package: it serves as the operational incident backbone and helps the organisation determine when the \u003cstrong\u003eSwedish Cybersecurity Act\/NIS2, GDPR, DORA, customer agreements, supplier agreements or cyber insurance\u003c\/strong\u003e trigger specific reporting or communication requirements.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e2-in-1 Swedish + English:\u003c\/strong\u003e seven documents are included in both language versions. All are delivered in Word and PDF and are complemented by an advanced Excel register with automatic regulatory reporting clocks. The package contains \u003cstrong\u003e29 delivery files\u003c\/strong\u003e in total.\u003c\/p\u003e\n\n\u003cnav aria-label=\"About the template\" style=\"border:1px solid #dbe4ea;padding:16px;border-radius:10px;background:#f7fafc;margin:18px 0;\"\u003e\n\u003cstrong\u003eAbout the template\u003c\/strong\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"#reviewed\"\u003eLegally and operationally reviewed 2026\/2027\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#included\"\u003eWhat is included\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#built-for\"\u003eBuilt for the full incident lifecycle\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#nis2\"\u003eSwedish Cybersecurity Act\/NIS2 – 24h, 72h and final report\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#gdpr-dora\"\u003eGDPR and DORA – separate reporting tracks\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#classification\"\u003eIncident classification and severity\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#crisis\"\u003eCyber crisis and communications\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#evidence\"\u003eEvidence, chain of custody and forensics\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#recovery\"\u003eRecovery and Post-Incident Review\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#excel\"\u003eExcel register and automatic deadlines\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#faq\"\u003eFrequently asked questions\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"#sources\"\u003eLegal basis and official sources\u003c\/a\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/nav\u003e\n\n\u003cdiv id=\"reviewed\" style=\"border:1px solid #b7dec5;background:#e9f6ee;padding:18px;border-radius:10px;margin:18px 0;\"\u003e\n\u003cstrong\u003eLegally and operationally reviewed: 6 October 2026\u003c\/strong\u003e\u003cbr\u003e\nThe package has been reviewed against the current \u003cstrong\u003eSwedish Cybersecurity Act (2025:1506)\u003c\/strong\u003e, the NIS2 incident-reporting structure, the GDPR rules on personal data breaches and current DORA reporting for relevant financial entities. The templates are designed for use during \u003cstrong\u003e2026\/2027\u003c\/strong\u003e and explicitly separate the trigger criteria and deadlines under the different regulatory frameworks.\n\u003c\/div\u003e\n\n\u003ch2 id=\"included\"\u003eWhat is included in the package\u003c\/h2\u003e\n\u003cdiv style=\"overflow-x:auto;\"\u003e\n\u003ctable style=\"width:100%;border-collapse:collapse;\"\u003e\n\u003cthead\u003e\u003ctr\u003e\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eDocument\u003c\/th\u003e\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eSwedish\u003c\/th\u003e\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eEnglish\u003c\/th\u003e\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eUse\u003c\/th\u003e\n\u003c\/tr\u003e\u003c\/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eIncident Response \u0026amp; Cyber Crisis Plan\u003c\/strong\u003e\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eMaster plan, roles, authority, the first 60 minutes and regulatory trigger points.\u003c\/td\u003e\u003c\/tr\u003e\n\u003ctr\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eIncident Intake, Classification \u0026amp; Severity\u003c\/strong\u003e\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eCIA impact, severity, regulatory screening and classification decision.\u003c\/td\u003e\u003c\/tr\u003e\n\u003ctr\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003e24h \/ 72h \/ Final Report\u003c\/strong\u003e\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWorking fields for the Swedish Cybersecurity Act\/NIS2 reporting chain and GDPR\/DORA cross-checks.\u003c\/td\u003e\u003c\/tr\u003e\n\u003ctr\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eCyber Crisis \u0026amp; Communications Plan\u003c\/strong\u003e\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eSITREP, audience matrix, customer notice and communications log.\u003c\/td\u003e\u003c\/tr\u003e\n\u003ctr\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eTechnical Containment, Evidence \u0026amp; Forensics Log\u003c\/strong\u003e\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eTechnical action register, chain of custody, IoCs and supplier evidence.\u003c\/td\u003e\u003c\/tr\u003e\n\u003ctr\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eRecovery, Continuity \u0026amp; Post-Incident Review\u003c\/strong\u003e\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eRecovery gates, verification, root cause and remediation plan.\u003c\/td\u003e\u003c\/tr\u003e\n\u003ctr\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eDetailed user guide\u003c\/strong\u003e\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWorkflow, legal cross-checks, incident types and common pitfalls.\u003c\/td\u003e\u003c\/tr\u003e\n\u003ctr\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eIncident Response Excel Register\u003c\/strong\u003e\u003c\/td\u003e\u003ctd colspan=\"2\" style=\"border:1px solid #d5dde3;padding:10px;\"\u003eXLSX\u003c\/td\u003e\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eDashboard, incident register, regulatory deadlines, actions, evidence, communications, contacts and PIR.\u003c\/td\u003e\u003c\/tr\u003e\n\u003c\/tbody\u003e\n\u003c\/table\u003e\n\u003c\/div\u003e\n\n\u003cdiv id=\"built-for\" style=\"background:#fff4cc;border-left:5px solid #d9a800;padding:20px;border-radius:8px;margin:22px 0;\"\u003e\n\u003cstrong style=\"font-size:1.1em;\"\u003eBuilt for the full incident lifecycle – not only the regulatory notification\u003c\/strong\u003e\u003cbr\u003e\nA major risk during a cyber incident is treating technology, legal obligations, communications and recovery as separate workstreams. This package connects \u003cstrong\u003edetection → classification → containment → reporting assessment → communications → recovery → Post-Incident Review\u003c\/strong\u003e. The same Incident ID follows the case throughout the process.\n\u003c\/div\u003e\n\n\u003ch2\u003eThe first 60 minutes – one common structure\u003c\/h2\u003e\n\u003cp\u003eThe master plan starts with decisions that often need to be taken before the organisation has a complete picture. The Incident ID and awareness time are recorded immediately, an Incident Lead is appointed, an alternative communications channel is secured and volatile evidence is preserved before irreversible actions are taken.\u003c\/p\u003e\n\u003cp\u003eThis is also where regulatory clocks should be started. The moment when the organisation actually becomes \u003cem\u003eaware\u003c\/em\u003e of an incident can be central under the Swedish Cybersecurity Act, GDPR and DORA. The templates therefore distinguish between detection time, awareness time and classification time.\u003c\/p\u003e\n\n\u003ch2 id=\"nis2\"\u003eSwedish Cybersecurity Act\/NIS2 – 24 hours, 72 hours and one month\u003c\/h2\u003e\n\u003cp\u003eSweden's \u003cstrong\u003eCybersecurity Act (2025:1506)\u003c\/strong\u003e entered into force on 15 January 2026. It requires appropriate and proportionate technical, operational and organisational security measures. The areas expressly covered include \u003cstrong\u003eincident handling\u003c\/strong\u003e and \u003cstrong\u003ebusiness continuity and crisis management\u003c\/strong\u003e.\u003c\/p\u003e\n\u003cp\u003eFor an entity covered by the Act that suffers a \u003cstrong\u003esignificant incident\u003c\/strong\u003e, the package supports the following operational sequence:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ewithin 24 hours:\u003c\/strong\u003e early warning after the entity becomes aware of the incident,\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003ewithin 72 hours:\u003c\/strong\u003e incident notification for other entities; trust service providers have a 24-hour deadline for the incident notification as well,\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003eon request:\u003c\/strong\u003e an intermediate report with relevant status updates,\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003ewithin one month after the incident notification:\u003c\/strong\u003e final report; if the incident is still ongoing, a progress report is followed by a later final report.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eUnder the Act, a significant incident is an incident that has caused or is capable of causing severe operational disruption to the service or financial loss to the entity, or that has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.\u003c\/p\u003e\n\n\u003ch2 id=\"gdpr-dora\"\u003eThe same incident may trigger several legal reporting tracks\u003c\/h2\u003e\n\u003cp\u003eThe package does not make the common mistake of treating NIS2, GDPR and DORA as the same thing. They have different scopes, trigger criteria and recipients.\u003c\/p\u003e\n\n\u003ch3\u003eGDPR – personal data breach\u003c\/h3\u003e\n\u003cp\u003eIf the incident means that personal data has been destroyed, altered, lost or disclosed to or accessed by unauthorised persons, the GDPR track must be assessed separately. Where a personal data breach is reportable, the starting point is notification to the Swedish Authority for Privacy Protection (IMY) within \u003cstrong\u003e72 hours of becoming aware\u003c\/strong\u003e. Where the breach is likely to result in a high risk, affected data subjects may also need to be informed without undue delay.\u003c\/p\u003e\n\n\u003ch3\u003eDORA – financial entities\u003c\/h3\u003e\n\u003cp\u003eDORA applies to relevant financial entities. For a major ICT-related incident, the current reporting standards include:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003ean initial report as soon as possible, \u003cstrong\u003ewithin four hours after classification as major\u003c\/strong\u003e and no later than \u003cstrong\u003e24 hours after awareness\u003c\/strong\u003e,\u003c\/li\u003e\n\u003cli\u003ean intermediate report no later than \u003cstrong\u003e72 hours after the initial report\u003c\/strong\u003e,\u003c\/li\u003e\n\u003cli\u003ea final report no later than \u003cstrong\u003eone month after the intermediate report\u003c\/strong\u003e or the latest updated intermediate report.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eThe Excel register therefore uses a separate DORA clock instead of mixing it with the NIS2 timeline.\u003c\/p\u003e\n\n\u003ch2 id=\"classification\"\u003eIncident classification – from technical event to SEV level\u003c\/h2\u003e\n\u003cp\u003eThe Incident Intake template helps the team assess confidentiality, integrity and availability together with physical\/safety, financial and third-party impact. The incident is then classified into four levels from SEV-4 to SEV-1.\u003c\/p\u003e\n\u003cp\u003eThe SEV level is an internal governance tool and does not replace the legal assessment of whether an incident is, for example, “significant” under the Swedish Cybersecurity Act or “major” under DORA. Regulatory screening is therefore a separate decision step.\u003c\/p\u003e\n\n\u003ch2 id=\"crisis\"\u003eCyber crisis and communications\u003c\/h2\u003e\n\u003cp\u003eFor larger incidents, technical incident handling is not enough. The Cyber Crisis plan establishes a crisis organisation with roles such as Incident Lead, Crisis Manager, Legal\/Compliance, Communications, DPO\/Privacy and Supplier Lead.\u003c\/p\u003e\n\u003cp\u003eIt includes a reusable \u003cstrong\u003eSITREP\u003c\/strong\u003e for management, an audience matrix for employees\/customers\/authorities\/suppliers\/media, a customer-notification structure and a communications log. The pre-publication checklist reduces the risk of releasing unverified information or security details that could be exploited by an attacker.\u003c\/p\u003e\n\n\u003ch2 id=\"evidence\"\u003eEvidence, chain of custody and technical containment\u003c\/h2\u003e\n\u003cp\u003eTechnical actions can destroy evidence if they are carried out without documentation. The package therefore includes a separate action register and chain-of-custody section for logs, disk\/memory data, cloud exports and other relevant evidence.\u003c\/p\u003e\n\u003cp\u003eThe document covers, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003etime and time zone,\u003c\/li\u003e\n\u003cli\u003esource\/system and the person who collected the material,\u003c\/li\u003e\n\u003cli\u003ehash\/integrity reference where relevant,\u003c\/li\u003e\n\u003cli\u003estorage location and access\/transfer history,\u003c\/li\u003e\n\u003cli\u003eIndicators of Compromise – IP address, domain, hash, account, process and TTP,\u003c\/li\u003e\n\u003cli\u003esupplier incidents and which logs\/evidence have been requested.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch2 id=\"recovery\"\u003eRecovery, continuity and Post-Incident Review\u003c\/h2\u003e\n\u003cp\u003eThe recovery template uses clear reconnection gates: backups should be verified, clean installation sources available, compromised credentials rotated and the vulnerability or root cause addressed before systems are reconnected.\u003c\/p\u003e\n\u003cp\u003eAfter restoration, a Post-Incident Review is carried out covering root cause, contributing factors, what worked, what did not work, regulatory lessons and supplier lessons. Improvement actions are assigned an owner, priority, deadline and evidence requirement.\u003c\/p\u003e\n\n\u003ch2 id=\"excel\"\u003eExcel register with automatic reporting clocks\u003c\/h2\u003e\n\u003cp\u003eThe Excel workbook is more than a list. It acts as an operational control panel and includes:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eDashboard\u003c\/strong\u003e – open incidents, SEV-1\/2 and active reporting tracks,\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003eIncident Register\u003c\/strong\u003e – detection, awareness, phase, impact and next update,\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003eRegulatory Deadlines\u003c\/strong\u003e – separate NIS2, GDPR and DORA clocks,\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003eAction Log\u003c\/strong\u003e – containment, recovery, regulatory and communications actions,\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003eEvidence Chain\u003c\/strong\u003e – chain of custody and integrity,\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003eCommunications\u003c\/strong\u003e – version, audience, approval and evidence,\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003eContacts\u003c\/strong\u003e – incident team, authorities, suppliers, insurer and forensics,\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003ePost Incident\u003c\/strong\u003e – PIR, remediation and residual risk.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eFor example, the Swedish Cybersecurity Act's 24-hour and 72-hour deadlines are calculated automatically from the recorded awareness time. DORA uses a separate formula that takes both awareness time and the time of classification as a major incident into account.\u003c\/p\u003e\n\n\u003ch2\u003eWhen the package is particularly useful\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003ecompanies that want to establish a professional Incident Response process,\u003c\/li\u003e\n\u003cli\u003eNIS2\/Swedish Cybersecurity Act-regulated entities that want to complement their broader NIS2 programme,\u003c\/li\u003e\n\u003cli\u003eSaaS, IT, MSP and cloud organisations,\u003c\/li\u003e\n\u003cli\u003eorganisations processing significant volumes of personal data,\u003c\/li\u003e\n\u003cli\u003efinancial entities that need to coordinate DORA with internal cyber-crisis management,\u003c\/li\u003e\n\u003cli\u003eorganisations with critical supplier and third-party dependencies.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch2\u003eHow this differs from Mallbutiken's other incident templates\u003c\/h2\u003e\n\u003cp\u003eThe \u003cstrong\u003eNIS2 Template Package\u003c\/strong\u003e covers the broader systematic cybersecurity programme. The \u003cstrong\u003eGDPR Personal Data Breach\u003c\/strong\u003e package goes deeper into Articles 33\/34 and the IMY process. This package instead focuses on \u003cstrong\u003ethe operational incident and cyber crisis as a whole\u003c\/strong\u003e – from the first alert to containment, regulatory triage, customer communications, recovery and Post-Incident Review.\u003c\/p\u003e\n\n\u003ch2 id=\"faq\"\u003eFrequently asked questions\u003c\/h2\u003e\n\u003ch3\u003eIs the package only for organisations covered by NIS2?\u003c\/h3\u003e\n\u003cp\u003eNo. The Incident Response process can be used by most organisations. The Swedish Cybersecurity Act\/NIS2 track is activated only if the organisation and incident fall within that regulatory framework.\u003c\/p\u003e\n\n\u003ch3\u003eAre all cyber incidents reportable within 24 or 72 hours?\u003c\/h3\u003e\n\u003cp\u003eNo. The deadlines apply only when the trigger criteria under the relevant framework are met. The package therefore contains separate screening and decision points.\u003c\/p\u003e\n\n\u003ch3\u003eCan the same incident need to be reported under both NIS2 and GDPR?\u003c\/h3\u003e\n\u003cp\u003eYes. An incident can simultaneously be significant under the Swedish Cybersecurity Act and constitute a reportable personal data breach. The two assessments should be carried out in parallel.\u003c\/p\u003e\n\n\u003ch3\u003eIs DORA included?\u003c\/h3\u003e\n\u003cp\u003eYes, as a separate cross-track for relevant financial entities. The package does not, however, replace a complete DORA compliance programme.\u003c\/p\u003e\n\n\u003ch3\u003eAre English documents included?\u003c\/h3\u003e\n\u003cp\u003eYes. All seven Word\/PDF templates are provided in a separate English version. The Excel register uses clear internationally usable incident fields.\u003c\/p\u003e\n\n\u003ch3\u003eIs Excel included?\u003c\/h3\u003e\n\u003cp\u003eYes. The Excel register is a central part of the product and includes automatic regulatory deadlines and registers for incidents, actions, evidence, communications and Post-Incident Review.\u003c\/p\u003e\n\n\u003ch2\u003eFormat and delivery\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e14 document templates\u003c\/strong\u003e – 7 Swedish + 7 English.\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003e14 DOCX + 14 PDF + 1 XLSX = 29 delivery files.\u003c\/strong\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003e28 A4 pages per Word\/PDF format series across both language versions.\u003c\/strong\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003eWord (DOCX) + PDF + Excel (XLSX).\u003c\/strong\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cstrong\u003eDigital product – no physical item is shipped.\u003c\/strong\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch2 id=\"sources\"\u003eLegal basis and official sources\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https:\/\/www.riksdagen.se\/sv\/dokument-och-lagar\/dokument\/svensk-forfattningssamling\/cybersakerhetslag-20251506_sfs-2025-1506\/\"\u003eSwedish Cybersecurity Act (2025:1506)\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN-SV\/ALL\/?uri=CELEX:32022L2555\"\u003eDirective (EU) 2022\/2555 – NIS2\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"https:\/\/www.imy.se\/verksamhet\/dataskydd\/det-har-galler-enligt-gdpr\/personuppgiftsincidenter\/hantering-av-personuppgiftsincidenter\/\"\u003eIMY – Personal data breach handling\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"https:\/\/www.fi.se\/sv\/marknad\/rapportering2\/ikt-risker-dora\/\"\u003eSwedish Financial Supervisory Authority – ICT risks and DORA\u003c\/a\u003e\u003c\/li\u003e\n\u003cli\u003e\u003ca href=\"https:\/\/eur-lex.europa.eu\/legal-content\/SV\/TXT\/?uri=CELEX:32025R0301\"\u003eCommission Delegated Regulation (EU) 2025\/301 – DORA incident reporting\u003c\/a\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003cdiv style=\"background:#f3f5f7;border:1px solid #d5dde3;padding:16px;border-radius:8px;margin-top:20px;\"\u003e\n\u003cstrong\u003eImportant:\u003c\/strong\u003e The package is an operational and documentation aid. It does not automatically determine whether an organisation is subject to a particular regulatory framework or whether a specific incident meets a legal reporting threshold. Always verify the current sector, competent authority, regulations, contractual requirements and the actual incident circumstances.\n\u003c\/div\u003e\n\u003c\/div\u003e","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55615332614486,"sku":"INCIDENT-RESPONSE-CYBER-CRISIS-2026-2027","price":79.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/incident-response-cyber-crisis-2026-2027.png?v=1791245747","url":"https:\/\/mallbutiken.se\/en\/products\/incident-response-cyber-crisis-2026-2027-svenska-english-nis2-gdpr-dora-word-pdf-excel","provider":"Mallbutiken","version":"1.0","type":"link"}