Case Studies

Real clients. Measurable outcomes.

Every engagement below is real work for an organisation operating in Sweden and across Europe. The numbers are the ones our clients measured, not the ones we hoped for.

By Service

Browse the work by capability

2m 47s

Mean Time to Contain

Ransomware Contained Before a Single File Was Encrypted

A Swedish municipality was targeted after hours. Our SOC picked up anomalous lateral movement, isolated the infected host and notified the CTO within 2 minutes 47 seconds. No data was lost.

24/7 MDR AIDR Public Sector
Explore MDR & SOC

72hrs

NIS2 Compliant from Zero

NIS2 Article 21 Alignment Reached in 72 Hours, Ahead of the Audit Deadline

A 400-employee manufacturer with no dedicated security function needed Article 21 documentation in place before a regulatory audit. We assessed, deployed and documented in 68 hours, completing two days ahead of schedule.

NIS2 CISO as a Service Manufacturing
Explore CISO Advisory

94%

Training Completion Rate

Security Awareness Training Rolled Out to 3,200 Staff Before a National Audit

A Swedish retail group needed to demonstrate NIS2-aligned security awareness across its full workforce in four weeks. Complorer delivered role-based training to 3,200 employees, reaching 94% completion. The audit passed with zero findings.

Security Awareness Complorer Retail
Explore Security Awareness

14days

Time to Close All Criticals

Active Directory Compromise Path Closed Before It Could Be Used

An internal penetration test of a Swedish insurance firm uncovered a full domain takeover path through unconstrained Kerberos delegation. All critical and high findings were remediated and confirmed clean on retest within 14 days.

Penetration Testing Financial Services
Explore Penetration Testing

4yrs

Zero Breaches Under Coverage

Four Years of Continuous MDR Coverage Across a National Logistics Network

A Swedish logistics operator running 14 sites has been under 24/7 MDR coverage with a named analyst team for four years. No successful breaches detected. Full NIS2 Article 21 compliance documentation has been maintained throughout the engagement.

24/7 MDR SOC Logistics
Explore MDR & SOC
NIS2 · Cybersäkerhetslagen

Everything Your Board Needs
to Ask About NIS2

Sweden's Cybersäkerhetslagen brought NIS2 into national law. If your organisation operates in energy, transport, health, digital infrastructure or public administration, you are in scope. Here is what Article 21 requires in practice.

  • Risk management and incident handling: Article 21(2)(a) and (b) require documented policies, active detection capability and incident reporting to MCF (formerly MSB) within 24 hours.
  • Supply-chain security: Article 21(2)(d) requires every third-party vendor relationship to be assessed, documented and kept current.
  • Management accountability: Under Article 20, board members carry personal liability for non-compliance. Fines reach up to 10 million euros.

Our NIS2 gap checklist maps your current state against every Article 21 control. It is written in plain English, built for the Swedish regulatory context and takes around 20 minutes to complete.

NIS2 Compliance Gap Checklist

See where you stand on Articles 20 and 21, scored in plain language. The output is board-ready and reflects current MCF guidance.

No spam. EU data residency. Unsubscribe any time.

Trusted by IT & Security Leaders
Across Sweden & Europe

See What This Looks Like for Your Organisation.
Book a 30-Minute Briefing.

Walk through the outcomes above with a Sweden-based analyst. We'll review your current posture, map gaps to NIS2 and show you live SOC in action. No pitch deck. No commitment.

Book a 30-Minute Briefing
No commitment Sweden-based analyst