To Think for Yourself: An analysis of supply chain responsibilities under Sweden’s proposed Cybersecurity Law
2024 (English)Independent thesis Advanced level (professional degree), 20 credits / 30 HE credits
Student thesisAlternative title
Att tänka själv : En analys av leveranskedjeansvaret enligt Sveriges föreslagna cybersäkerhetslag (Swedish)
Abstract [en]
The original idea was to investigate how the all-hazards approach could affect supply chain risk management measures and liability. However, other issues needed to be resolved before writing a thesis on that topic. This then became an attempt to see the forest despite all the trees while still trying to navigate a tangled trail. The first issue to be addressed is:1) Considering the overarching aim in the NIS2 Directive of increasing cybersecurity within the EU, how effective is the supply chain requirement in Chapter 3, section 1, point 3 of the proposed Cybersecurity Law? The short answer to the question of effectiveness is that neither the NIS2 Directive nor the proposed Cybersecurity Law provides robust protection by themselves and that other sources are necessary to address the supply chain security issue. Components such as what is required by judicial and non-judicial sources when discussing risk assessments, risk management measures, risk mitigation, and allocation must be examined to assess the effectiveness of the legal informatics framework. In many of these discussions, the legal situation seems unclear. Further research is recommended to strengthen foreseeability. Given the need for a foreseeable legal system, there was a curiosity to examine how some ambiguities can be resolved, which inspired the second research question:2) How can entities and suppliers mitigate cybersecurity and regulatory risks in the framework of the NIS2 Directive and the proposed Cybersecurity Law?The investigation showed that entities may consider the ambiguity a risk. The contractual relationship between the entity and the provider is the only way for entities to transfer liability to suppliers not covered by the Cybersecurity Law. This seems to be the solution even if supervisory authorities would publish clarifying regulations in the future. Only the entity can be directly subject to penalties. Still, like other contractual relationships, an entity can pass on a contractual lia- bility to a negligent supplier that has failed to exercise due care.
As neither the Cybersecurity Law nor the NIS2 Directive provides clear solutions, entities and suppliers must think for themselves in their cybersecurity risk management.
Place, publisher, year, edition, pages
2024.
Keywords [en]
NIS2 directive, Cybersecurity, Supply Chain Security, Supply Chain Attack, All-hazards approach, Systematic and Risk-Based approach
Keywords [sv]
NIS2-direktivet, Cybersäkerhetslag, Cybersäkerhet, Leveranskedjeansvar, Leveranskedjeattack
National Category
Law
Identifiers
URN: urn:nbn:se:su:diva-232760OAI: oai:DiVA.org:su-232760DiVA, id: diva2:1891735
Supervisors
Examiners
2024-09-102024-08-232024-09-10Bibliographically approved