Nearly half of all data breaches involve a supplier. Swedish municipalities are particularly exposed
When a supplier fails, hundreds of organisations can be affected at the same time. For the public sector, the supplier chain is therefore no longer an administrative issue, but a central part of cybersecurity.

In a review published on 21 September 2026, the EU auditors state that Member States still struggle to share information when cyberattacks cross borders. At the same time, developments in Sweden point to the same vulnerability in practice: when a system supplier is affected, the consequences can quickly spread to municipalities, regions and residents.
In 2025, this became clear when a ransomware attack against the system supplier Miljödata affected a large number of Swedish municipalities and regions. Because the supplier’s systems were widely used in the public sector, the attack quickly had knock-on effects. At least 164 municipalities and four regions were affected, around 250 reports were submitted to the Swedish Authority for Privacy Protection, and sensitive personal data was later published on the darknet.
This is not an isolated exception, but part of a broader pattern. According to Verizon’s Data Breach Investigations Report 2026, third-party involvement now occurs in 48 percent of all data breaches, an increase of 60 percent in one year.
Shared systems create shared vulnerabilities
Digitalisation has made it possible for municipalities and regions to share systems, streamline processes and procure specialised services. Fundamentally, this is both reasonable and necessary. But when many organisations rely on the same suppliers, shared vulnerabilities also emerge.
An attack on a single actor can therefore have consequences far beyond that organisation itself. This is especially true in the public sector, where systems often handle sensitive personal data, critical societal processes and services that residents depend on in their everyday lives.
Insufficient information sharing weakens resilience
The EU review also shows that information sharing between Member States still does not function fully. In 2025, only 14 significant cross-border incidents were reported by seven Member States, and no Member State has reported a large-scale incident since 2016. In a connected Europe, where attacks often move across both national borders and supplier networks, this becomes a clear weakness.
One example is the ransomware attack against an IT supplier to the aviation industry in September 2025. The attack disrupted airports in London, Brussels, Berlin and Dublin, among others, but according to the auditors, neither the EU cybersecurity agency ENISA nor the other Member States were notified by the affected countries.
Swedish municipalities have already seen the consequences
In Sweden, supplier risk became concrete on 23 August 2025, when the attack against Miljödata was detected. Around 80 percent of the country’s municipalities used the supplier’s systems, meaning the consequences were not local, but systemic.
The vulnerability does not stop with a single supplier. On 9 April 2026, the municipalities of Vilhelmina and Dorotea were hit by a ransomware attack. Dorotea Municipality entered crisis management mode and operations fell back on paper-based routines. At the same time, Vilhelmina’s municipal chief executive Christer Staaf stated that the municipality had indications that it was part of a larger IT attack. Recovery work dragged on for weeks, showing that the real challenge is not only stopping the attack, but keeping operations running when digital systems do not work.
NIS2 raises the bar for governance and accountability
Since 15 January 2026, the Cybersecurity Act, Sweden’s implementation of the EU NIS2 Directive, has been in force. The law requires, among other things, risk management in the supplier chain, incident reporting and clear management accountability.
However, several of the key regulations are not expected until later in 2026, including those on incident reporting, security measures and mandatory training for management. Even so, for many organisations this means that cybersecurity can no longer be treated as a technical specialist issue. It needs to be integrated into governance, procurement, contracts, continuity planning and management work.
At the same time, the 2024 follow-up by the Swedish Association of Local Authorities and Regions showed that around 72 percent of municipalities had an established process for setting information security requirements in relevant procurements. This means that roughly one in four municipalities lacked such a process.
Three things the public sector should do now
- Map dependencies. Start by identifying which suppliers are critical to core operations. These are not always the largest contracts, but the systems and services the organisation cannot function without.
- Include incident requirements in contracts. Reporting times, recovery capability, logging, security levels and the right to insight during an incident should be clear requirements already in procurement and contracts. They should not have to be negotiated in the middle of a crisis.
- Practise the outage, not just the attack. Many organisations practise incident response, but fewer practise how operations should continue without digital systems. Continuity plans, manual routines and clear decision paths can be the difference between a disruption and a societal crisis.
Cybersecurity starts with dependencies
The supplier chain is now one of the most decisive parts of public sector resilience. Securing your own environment is not enough if the organisation is simultaneously dependent on external systems that can become a shared weak point.
For municipalities, regions and government agencies, the next step is therefore to make supplier risk visible, measurable and actionable. Only then will cybersecurity become as robust as the public services it is meant to protect.