Trollhättan Energi – from hidden silos to unified control over information security

With a flexible platform and a structured approach, Trollhättan Energi has centralized its information security in one place.

By integrating this work into their existing company culture, they have moved from working on separate documents to having a clear and scalable overview.

Security should be an inherent part of your existing culture. It is about working with the culture you already have, rather than trying to impose an entirely new security culture.

When Trollhättan Energi looked ahead in 2022, the organization faced a classic challenge. Information was scattered across various Excel files, making it difficult to get a clear overview. At the same time, updated ISO 27002 guidelines set clear requirements for systematic work—something that felt nearly impossible to achieve without dedicated system support.

Taking the step from scattered documents to a standardized platform proved to be a hurdle in itself, as it can be difficult to know exactly what you need before you have started working in a system. The choice eventually fell on DirSys, where user-friendliness and long-term flexibility were the deciding factors.

"It’s not about compliance, but it is about compliance."

Johan Bogfors works as an Information and Security Officer in the organization's security department. His broad responsibilities range from physical security and civil defense to GDPR and information security.

Focus on simplicity and scalability

For Trollhättan Energi, the selection criteria were clear from the start. The system obviously needed to solve immediate challenges, but it was just as important that it be easy to work with—both during the initial setup and in daily operations moving forward. The fact that the platform offered choices regarding which modules to activate, combined with scalability that allowed the tool to evolve with the business's needs, made a big difference.

Another major advantage was the flexibility in handling information. The ability to upload existing files, such as risk analyses, and customize templates to fit their specific needs and workflows has been invaluable. Ready-made standard templates are often a good foundation, but since every organization operates differently, there must be room for business-specific adjustments.

From system integration to active classification

The implementation has been carried out in stages and allowed to take time. The first year focused on integrating the systems. After that, the work ramped up, and the process of adding registers and conducting system and information classifications began.

The goal has always been clear: to gather all systems in one place to enable effective, long-term follow-up. Through this systematic approach, Trollhättan Energi has moved from hidden silos to a living, visual picture of what their security work actually looks like.

"By working systematically, we gain better control. And when we have control, it leads to a reliable delivery of our services. After all, our main task is to provide critical societal infrastructure to others. If we can't deliver power to our customers, both we and they have serious problems."

The tool requires commitment

Experience from the implementation also shows that a digital system is, at the end of the day, just a tool. Johan points out that there can sometimes be an expectation within an organization that a new system will solve all problems on its own, but it is how you actually choose to use the tool that determines the final result. Adjusting these expectations and continuously integrating new routines is an ongoing process.

The goal moving forward is to add more users to the platform over time, thereby spreading the responsibility for documentation throughout the organization. This is a transition that is being allowed the time it needs to be done correctly and effectively. The dialogue with DirSys regarding further development is described as highly valuable, not least because changes in laws and strategies can quickly have a major impact on operations. We are currently preparing to test DirSys's tool for supplier control.

Building on the existing culture

For other organizations facing a similar journey, Johan emphasizes the importance of a clear mandate and strong support from management. The organization must be given the actual resources and time for the work to yield results. He likes to draw a direct parallel to how we view other strategic functions within a company.

I think you can view information security much like you view finance. It needs to be reported to leadership, and it must be seen as relevant and vital to the organization's survival. By distributing responsibility for security among more people, you also build a deeper understanding of the work and achieve better coordination.

Ultimately, success is about integrating security into daily operations, rather than trying to force entirely new behaviors from the outside.

Get started with DirSys platform

Curious about how to get started with DirSys platform?
Book a demo here.