FAQ

Frequently asked questions and answers about our platform

What is DirSys solution?

The DIRSYS solution is a system support for organizations that need to work in a structured way with cybersecurity, IT governance andregulatory compliance. The solution brings together requirements, risks, actions and follow-up in a coherent way of working — and makes it possible to monitor how security work actually works in practice.

What differentiates DirSys from traditional GRC tools?

Many GRC tools focus primarily on documentation and self-assessment. DirSys combines documentation with follow-up and verification, so that security requirements are not only described — but can be followed up and checked over time.

What is meant by “verified compliance”?

Verified compliance means that you not only document how security should work, but you can also follow up on how it actually works. Through integrations and automated controls, settings, permissions and protections can be confirmed directly against your IT environment.

What regulations and standards does DirSys support?

DirSys supports, among other things:

  • GDPR
  • Cybersecurity Act (NIS2)
  • ISO/IEC 27002
  • CIS Controls
  • NIST

Frameworks and control plans can be used ready-made or customized according to your business.

Is DirSys suitable for both public and private sectors?

Yes. DirSys is used by both public organizations and private operations, especially where:

  • compliance is a management responsibility
  • Cybersecurity is business critical
  • requirements for traceability and follow-up are high
  • They are looking for an easy solution

How does DirSys help reduce administration?

Automation, clear flows and burden sharing reduces the need for manual checklists, Excel sheets and duplication. You only take a position on relevant requirements thanks to our terms and conditions control in the platform.

Is DirSys just a tool, or do we also get advice?

DirSys is more than a tool. The platform is developed together with our own advisors, and can be supplemented with advice in cybersecurity, IT governance and data protection when needed. It provides support both in structure and in practical implementation.

Where is the DirSys solution deployed?

DirSys is developed and operated in Sweden. Among other things, this means:

  • Servers in Sweden
  • support for SSO and MFA
  • high traceability and audit support
  • possibility of on-prem installation if necessary

If you wish, we can also offer ON-PREM installation.

For which organizations is DirSys best suited?

DirSys is suitable for organizations such as:

  • need to be able to demonstrate how they work with security and compliance
  • want to go beyond point inserts and documentation
  • seeking control, predictability and long-term

How do we take the next step?

The easiest way is to book a demo. Then we will review your situation, your requirements and show how DirSys solution can be used in practice.

Frequently Asked Questions about Frameworks

What frameworks and laws are supported?

The DirSys solution provides ready-made frameworks for, among other things:

  • GDPR
  • Cybersecurity Act (NIS2)
  • CIS Controls v8
  • ISO 27002
  • Incident management
  • Supplier Controls
  • Procurement

If you have your own framework or other standards you want to work with, we will help you further.

Can we use the solution even if we are not covered by all laws?

Yes. The solution is built to adapt to your reality. With conditionality management, you avoid requirements that do not apply to you and can focus on the right level of security and compliance.

Can we build our own framework?

Yes. You can start from existing standards that you adapt or build your own framework. Structure, concepts and help texts can be customized to suit your organization and language.

Can we help implement frameworks in the solution?

Yes. Our information and cybersecurity advisors will help you find the right framework based on your maturity level. In addition, we help you establish effective working methods and follow-up in your business.

How do we check compliance with frameworks in real life?

Policies and policies are only valuable if they are implemented in practice. Therefore, you can supplement your work with automatic checks that verify that the requirements are actually being complied with in your systems.

By linking control plans to your IT environment, settings, permissions and protection are analyzed on an ongoing basis. Deviations are detected automatically — without manual checklists.

How do we get started?

Book a demo and we will show you how the frameworks work in practice and how they can be adapted to your particular organization.

GDPR Tools FAQ

How does a GDPR tool help us?

According to the GDPR, all organisations are required to keep a record of how personal data is handled. Documenting all treatments and keeping the information up to date quickly becomes time consuming — especially when information needs to be gathered from many parts of the organization.

We are convinced that it does not have to be so complicated. And we know that Excel is not the solution. That's why we've developed a GDPR tool that's simple. For real. With clear templates, smooth flows and intuitive system support, you reduce administration and get better structure in your data protection work.

Book a demo

What is DirSys Integrity?

DirSys Integrity is our GDPR tool that helps you carry out structured data protection work and comply with GDPR. The product is part of our cybersecurity and regulatory compliance platform.

Here you manage your register list in a simple way, with support for high quality, updating and follow-up over time.

How does DirSys GDPR tool work?

DirSy's GDPR tool makes it possible to make visible an existing register list, document new personal data processing and carry out impact assessments (DPIA). The built-in audit flow makes it easy for Data Protection Officers or the like to review new and modified treatments.

The system is permission-driven, so users only see what's relevant to them, and you can easily filter out the right types of treatments.

In addition, you will be supported in monitoring your GDPR compliance and identifying improvement measures. All with a focus on being easy and efficient to work in.

Who is the tool suitable for?

Our GDPR tool is suitable for any organisation that processes personal data and needs a secure and structured way to work with GDPR.

The tool is specifically designed to be simple even for infrequent users, making it well suited for organizations with decentralized data protection work — where many contribute, but where coordination and control are still required.

We already have a GDPR tool - how do we do it?

If you already have a system that you are happy with, that is great! If not, we are happy to help you compare to see if our solution meets your needs better.

In addition, we can easily review your existing register list. You don't have to start over just because you choose a different solution.

We have a register list in Excel — do we need to start from scratch?

The No. If you already have a register list you are happy with, it is easy to import it into our solution.

Can we bring together GDPR, information security and requirements such as NIS2 or ISO 27002 in DirSys solution?

Yes. DirSys makes it possible to work together with GDPR, information and cybersecurity as well as requirements from, for example, the Cybersecurity Act (NIS2) and ISO/IEC 27002 — in the same solution.

This means that you do not have to work in several different systems or parallel processes. Risks, requirements and actions are interconnected, making it easier to prioritize correctly, avoid duplication and show how your work on data protection and security actually reinforce each other.

Can we export our registry list from DirSys?

Yes. The registry list can be easily exported to Excel, for example in case of supervision or other external audit.

How do we get started?

Start by book a demo with us. Then we will review how you work today and what you want to improve.

Once you have decided on DirSys, you are quickly up and running. There is both the possibility to import existing material ourselves or get support from us. We also offer onboarding and training for a safe start.

Cybersecurity Solution FAQ

How does a cybersecurity solution help us?

You get a unified view, control over compliance and easier collaboration.

It helps you make more informed decisions, prioritize the right security measures and enhance your cybersecurity.

What is DirSys Security?

DirSys Security is our cybersecurity solution that helps organizations work in a structured way with their information security and cybersecurity. With support for risk analysis, action plans and automation, it gives you a clear and simple picture of how secure your organization is and how you comply with applicable legal requirements.

Who is DirSys cybersecurity solution for?

The solution is suitable for organizations that want to work proactively with cybersecurity and information security. It is used by the CISO to run the information security work, the IT manager who wants to raise the organization's cybersecurity, and legal professionals who want to check the organization's legal compliance.

Above all, it suits organizations that want to work simply and pragmatically and be able to control what it looks like for real — not just document it.

How is DirSys solution different from a GRC tool?

Many GRC tools are broad platforms that address everything from environment and sustainability to legal, risk and compliance. This often makes them heavy, complex and difficult to adapt to the rapid developments in cybersecurity and data protection.

Instead, DirSys is built with a full focus on cybersecurity, IT governance and data protection — areas where requirements are increasing most rapidly and where the consequences of deficiencies are greatest.

Unlike classic GRC tools, DirSys does not stop at documentation and self-assessment. Through integrations and automation, you can monitor how safety requirements are actually being complied with in practice, over time.

In a situation of new regulations, increased threats and limited resources, a focused and verifiable approach provides faster overview, less administration and better control than broad GRC solutions.

What will be the result of using DirSys solution?

The result is control over your information and cyber security - so you can rest assured that you are protected. Both from an organizational as well as a technical perspective. The solution helps you comply with applicable legal requirements and minimize security risks before they occur.

Can we run DIRSYS cybersecurity solution ON-PREM?

Yes. We offer both the solution as a cloud service with high security requirements, but we can also help you set it up as an On-Prem service.

Is it possible to coordinate data protection and information security work?

Yes, it goes along with our GDPR tool. This means that you do not need to document information carriers in several places and you can perform different types of risk analysis in the same interface. A common thread between data protection and cybersecurity!

How do we get started?

Start by book a demo with us. Then we will review how you work today and what you want to improve.

At a first demo, we will look at your existing working methods and needs to see if we can help you move forward. Once you have decided to get started, the implementation takes place smoothly with support from us.

Frequently Asked Questions about Data Protection & GDPR

What is GDPR and why is it important?

GDPR (General Data Protection Regulation) is an EU regulation that has been in force since 25 May 2018. The aim is to protect individuals' personal data and strengthen their rights. The regulation imposes requirements on how organizations collect, store and use personal data — in a legal, fair and transparent manner. GDPR is important because it clarifies both responsibilities and obligations when handling personal data.

How does GDPR affect our organization?

GDPR affects all organizations that handle personal data. This means that organizations need, among other things:

- Have a legal basis for processing personal data
- Inform individuals about how their personal data is used
- Ensure that personal data is accurate and up to date
- Implement technical and organizational security measures
- Report personal data breaches to supervisory authorities within 72 hours
- Document and be able to show that you are complying with GDPR

In short, organizations need clear procedures and structures that protect individuals' personal data.

How can we ensure that we comply with GDPR?

By working in a structured and continuous manner. Among other things, it is about:

  • map and document personal data processing
  • introduce technical and organisational protection
  • educate the organization
  • Continuous monitoring and improvement of work

With the right tools and support, it will be much easier.

What happens if we do not comply with GDPR?

If you do not comply with GDPR, you may face sanctions, including:

- Warnings and reprimands: For minor infractions.
- Fines: Up to 20 million euros or 4% of the global annual turnover, whichever is the highest. For the public sector, a maximum amount of SEK 8 million applies.
- Prohibition: Temporary or permanent prohibition on the processing of personal data.

What does a GDPR consultant do?

A GDPR consultant helps organizations understand and comply with GDPR. They can:
- Identify the personal data processed.
- Carry out risk assessments and create action plans.
- Implement new procedures and write governance documents.
- Educate staff about GDPR and IT security.
- Ensure compliance with the GDPR within the organization.

If you need a GDPR consultant, you are welcome to contact us.

Do we need a Data Protection Officer?

Some organisations are required by the GDPR to appoint a Data Protection Officer (DSO). This applies, among other things, to:

  • public authorities and bodies
  • organizations that extensively monitor individuals
  • organizations that process sensitive personal data on a large scale

Other organisations voluntarily choose to appoint Data Protection Officers in order to obtain quality, independent review and continuity of data protection work.

Read more about Data Protection Officer here.

How can DirSys help us comply with GDPR?

DirSys helps you move from requirements to functional ways of working. With our platform, you get a structure and overview of your personal data management, and with our advisors you get support in interpreting the requirements and putting them into practice.

If necessary, we can also act as an external Data Protection Officer, as independent support in both follow-up and advice. This means that you not only document your GDPR work — but also follow up, improve and demonstrate compliance over time.

How do we get started with DirSys?

We start with a conversation. Here we go over how you work today, what challenges you have and what you want to improve. Next, we propose a solution that suits you and that you can take a position on.

Frequently asked questions and answers about the Cybersecurity Act

What does the Cybersecurity Act mean in practice?

To work in a structured and risk-based way with information and cyber security, be able to manage incidents and demonstrate compliance with requirements over time.

How to determine whether an organization is covered by the Cybersecurity Act?

The assessment is based on a combination of sector, size, possible exemptions and the organisation's role in vital supply chains, not just industry.

When does the law come into force?

15 January 2026, and many requirements require preparation well in advance — especially around governance, risk analysis and supplier management.

What are the main requirements of the Cybersecurity Act?

The key requirements concern:

  • risk analysis and safety management
  • technical and organisational protection measures
  • Incident management and reporting
  • responsibility of management
  • security in the supply chain

Does the Cybersecurity Act also apply to suppliers?

Yes, often indirectly through requirements for security in the supply chain. This is especially true if the supplier supplies IT services or systems to socially important activities.

What happens in the case of supervision under the Cybersecurity Act?

Organisations need to be able to demonstrate compliance, for example through documentation, risk assessments and follow-up. Deficiencies can lead to injunctions or penalty fees.

Is a one-time intervention enough?

The No. The law requires ongoing work, follow-up and improvement. Risks, threats and supplier relationships change over time and must be monitored continuously.

How does a system support help us comply with the Cybersecurity Act?

A system support provides overview, structure and traceability, makes it easier to follow up on actions, and clearly shows how the organization works with compliance over time.

Frequently Asked Questions about Data Protection Officer (DSO/DPO)

Does our organisation need to appoint a Data Protection Officer?

The Privacy Protection Authority recommends that all organisations appoint a DSO. However, there are some types of organizations that according to the GDPR outta appoint a Data Protection Officer.

These are:

  • Public bodies as public authorities
  • Organisations that process personal data on a regular, systematic and/or extensive basis in their core activities
  • Organisations that, in their core activities, process sensitive personal data or personal data relating to crimes on a large scale.

What does a Data Protection Officer do?

The task of a Data Protection Officer is to monitor your compliance with the requirements of the GDPR and to protect your personal data. This means, among other things, that:

  • Inform and advise businesses about their obligations under GDPR
  • Assist in the investigation of suspicious personal data breaches, such as data breaches or the dissemination of personal data
  • Act as a point of contact for the supervisory authority in matters relating to the processing of personal data
  • Educate and inform on the issue of personal data management and about recent events in the field
  • Establishing and reviewing impact assessments (DPIAs)
  • Monitor compliance with GDPR

Does the Data Protection Officer have to be employed?

No, a DSO does not have to be employed. A DSO should be independent which is why it is even advantageous to hire an external DSO.

What is the advantage of having an external Data Protection Officer?

The advantage of having an external data protection officer is that you follow best practices and have access to an independent DSO. It will also be a more cost-effective and flexible solution than hiring, training and retaining an employee.

With DirSys DSO as a service, you can customize the scope according to your needs and you get access to a broad portfolio of expertise in data protection, law, information security and IT.

Can our CISO, Municipal Attorney, Business Developer or CEO be a Data Protection Officer?

There are requirements for a DSO to be someone who has an independent position in the organization. It can be difficult to be independent if you already have another position in the organization. According to the Privacy Protection Authority, it is inappropriate if the DSO is part of the organization's management or otherwise participates in making overall decisions about the operations.

Who can act as Data Protection Officer?

In order to act as a DSO, one must have knowledge of GDPR, be able to understand the core business and have the ability to disseminate a data protection culture.

Who should a Data Protection Officer report to?

The DSO shall report to the management or board of the organisation as a starting point.

Can we be fined if we do not have a Data Protection Officer?

The short answer is yes. Also, be sure to notify the appointed DSO to the IMY Privacy Protection Authority.

Cybersecurity FAQ

What is meant by cybersecurity?

Cybersecurity is about protecting your organization's information, systems, and services from attack, disruption, and misuse — and being able to handle incidents when they occur.

Why is cybersecurity business critical?

Cybersecurity flaws can lead to downtime, loss of trust, legal consequences and lost business. For many organizations today it is a management issue.

How does DirSys help us with cybersecurity?

We combine cybersecurity consulting with a seamless platform for follow-up. This allows you to work systematically, prioritize correctly and show how you manage risks over time.

Do we need to comply with the Cybersecurity Act (NIS2)?

It depends on your business, role and dependencies. We help you make a clear assessment and put the requirements into practice. Read more about the Cybersecurity Act.

Is DirSys a technical security provider?

The No. We complement technical security solutions by focusing on governance, risk, responsibility and compliance — so that security work is connected.

How do we get started?

We start with a conversation. We will review your current situation, your needs and see if — and how — we can help you further. If we can help you further, we will provide a proposal based on your needs that you can take a position on. Talk to an Advisor

Frequently Asked Questions about CISO as a Service

Does your organization need a CISO?

Whether it's achieving legal compliance, maintaining a good brand, or protecting sensitive data from unauthorized persons, someone is needed to lead and coordinate the overall work on information security. That responsibility usually falls to a CISO. Depending on your level of risk, what legal requirements you are subject to and which customers you do business with, the need varies widely. Some have a need for a full-time CISO, while others need the resource at a certain percentage.

What does a CISO do?

A CISO has the overall responsibility to lead and coordinate the work on information security (and sometimes also cybersecurity). The aim is to create conditions for the organization to become resilient and resistant to cyber attacks and to comply with legislation in the field of information security. The CISO reports to management on status and works to enhance the organization's maturity level and information security culture.

Does the CISO have to be employed?

No, a CISO does not have to be employed. The advantage of hiring a CISO is that over time it develops a deep business knowledge. An external CISO gives you flexibility. Both in terms of scope, for those of you who are not in need of a full-time resource, and in terms of how quickly you can get started, since you do not need to recruit.

What is the advantage of having an external CISO?

With an external CISO, you gain the skills, perspective and experience that come with many years of work with information security in different types of organizations. You will gain knowledge of how systematic information security work is built up and established, and that work starts right at start-up. It will also be a more cost-effective and flexible solution than hiring, training and retaining an employee.

Who should a CISO report to?

The CISO shall report to the management or board of the organization as a starting point.

We are a municipality or government agency - how do we buy into CISO as a service?

Our offer is below the direct procurement limit, which means that you can make a direct procurement. If you need to make a procurement, we are involved in most consulting brokerage agreements that are available through national framework agreements. Contact us and we will be happy to help you further.

FAQs on ISO 27001 and Information Security Management Systems

What is ISO 27001?

ISO 27001 is an international standard for how organizations should work systematically with information security. It describes how an information security management system (LIS) should be built, managed and followed up — focusing on risk, responsibility and continuous improvement.

What is an Information Security Management System (LIS)?

An LIS is the structure that makes information security a part of business management. It is also available to measure the performance of your systematic information security work.
It includes, among other things:

  • risk analysis
  • governing documents and procedures
  • Roles and Responsibilities
  • follow-up and improvement

ISO 27001 is a framework for how a LIS can be designed and used in practice.

Do you have to be certified according to ISO 27001?

The No. Many organizations use ISO 27001 as a guide without certifying themselves.
The standard works just as well as support to:

  • create structure in information security work
  • demonstrate maturity towards customers and partners
  • meet regulatory and procurement requirements

We help you choose the right level of ambition — with or without certification.

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 describes how a management system should be built and controlled.
ISO 27002 contains concrete safety measures that can be used to manage identified risks.

Together, they provide both structure and content in information security work.

How does ISO 27001 relate to legal requirements such as NIS2 and GDPR?

ISO 27001 is not a legal requirement, but it provides a way of working that makes it much easier to comply with laws such as NIS2 and GDPR.
A working LIS helps you to:

  • Identify and manage risks
  • demonstrate governance and responsibility
  • Follow up on security measures over time

It creates order even as demands increase.

For which organisations are ISO 27001 and LIS suitable?

ISO 27001 and an LIS are suitable for organizations that:

  • handle sensitive or business-critical information
  • meet increased demands from customers, legislation or procurement
  • wants to work in a long-term and structured way with information security

This applies to both the public and private sectors — regardless of size.

Do we need a system to work with ISO 27001?

It is possible to work manually, but it quickly becomes difficult to keep it together over time.
One system provides:

  • overview of risks and measures
  • clear responsibility
  • traceability and follow-up

The DirSys platform is built to support the systematic work required by ISO 27001.

How can DirSys help us with ISO 27001 and LIS?

We help you all the way — from structure to everyday work.
It implies:

  • advice on how ISO 27001 should be interpreted and applied in your business
  • support in building or further developing your LIS
  • a system support that brings together risks, actions and follow-up;

The focus is that information security should not stay in your documents, but work in practice.

Frequently Asked Questions about IT Procurement

When do you need to bring in external help in an IT procurement?

When procurement is complex, business-critical or involves many stakeholders.
Many organizations notice that it is difficult to keep together the business needs, the legal requirements of the LOU and the technical requirements. Then external help is often crucial to avoid delays, wrong requirements picture or over-examination.

What is the most common reason why IT procurements are not successful?

That the requirements picture becomes too technical or too detached from the actual needs of the business.
This often results in the right suppliers being sorted out, the solution not being fully used or the deal not delivering the desired value.

How is DirSys different from traditional procurement consultants?

We combine procurement expertise, IT understanding and business perspective.
This means that we not only ensure that the procurement complies with the LOU — but also that you actually get a solution that works in everyday life and can be implemented in your business.

Do you help with both requirements work and the procurement itself?

Yes. We support all the way: from needs analysis and market analysis, to requirements specification, evaluation of tenders and introduction of the selected solution. You get a cohesive process instead of many separate efforts.

Can you help us even if we have already started the procurement process?

Often, yes. We can step into ongoing procurements to support with requirements review, evaluation model or dialogue for the next step — depending on where you are in the process.

How do you reduce the risk of redress?

Through clear structure, balanced requirements and a well-thought-out evaluation model.
We ensure that the requirements are relevant, proportionate and actionable — and that the process is transparent throughout.

Do you only work in the public sector?

Our focus is primarily on the public sector and activities covered by LOU, but we also work with procurement in other regulated environments where structure, transparency and business benefit are crucial.

What do we get out of using your model?

In short:

  • better dialogue between business and IT
  • Better chance of getting the right supplier
  • fewer detours and less stress
  • a solution that is delivered on time — and actually used

How do we get started?

Start with a first call. Then we look at your situation, where you stand today and what you want to achieve. Next, we suggest how we can best support you. Book a consultation or contact us and we'll take it from there.

Frequently asked questions and answers about our NIS2 training

What is included in the course?

The course includes a half-day with all the contents described above and the presentation from the day. In addition, you will have the chance to ask your questions about NIS2. After completing the training, you will receive a certificate that you have completed the training.

What can I expect after completing the training?

After completing the training, you will be able to:

  • What the requirements of NIS2 mean for your organization
  • The process for determining whether your business is covered by the new law
  • Develop internal working methods to strengthen your work with information security according to NIS2
  • What the national adaptation of NIS2 means

What payment methods are accepted?

You pay by invoice with 30-day payment terms.

Frequently asked questions and answers about training in Dirsys platform

Are the trainings customer-specific?

Yes, we carry out the training in your solution and adapt it to your way of working.

How many people can attend the trainings?

To get the value out of being able to discuss and ask questions, we recommend a maximum of 10 participants in the courses. If there are more participants than that, we recommend a series of trainings and/or that we carry them out on site with you.

Do I need prior knowledge?

No, no prior knowledge is required. We customize the material according to your level.

Are the trainings digital or on-site?

We can perform the training both digitally and on site.