SEOM – Sollentuna Energi

Compliance Through Structure and Skills

How can an energy company strengthen security and accountability while staying compliant?

SEOM – Sollentuna Energi

 
Headquarters
Sollentuna, Sweden
 
 
Website

www.seom.se

 
 
Sites/Employees
Regional energy provider, ~200 employees
 
 
 
Year Founded
1916
 
 
 
Cypro Services Delivered
NIS2 compliance, strengthened governance and documentation, and built long-term security maturity with empowered staff.

The Challenge

Sollentuna Energi (SEOM), a local energy provider, faced increasing regulatory pressure from the NIS2 directive. Internally, SEOM struggled with inadequate documentation processes, unclear security roles, and limited knowledge of both information security and NIS2 requirements. These gaps created risks of data leakage, inefficiencies, and compliance challenges.

Engagement Approach

Cypro supported SEOM with a structured program that combined governance, skills, and process improvements:

  • Skills development:  continuous training for management and staff to raise awareness and practical understanding of NIS2.
  • Risk management & planning:  thorough risk assessments followed by a structured plan of strategic actions.
  • Role clarification:  clear definition of responsibilities and powers to improve accountability and efficiency across the organization.

Results & Impact

  • NIS2 compliance achieved:  SEOM established a foundation for potential ISO 27001 certification.
  • Streamlined documentation:  improved classification and management of information.
  • Clearer accountability: well-defined roles strengthened efficiency and responsibility.
  • Supply chain security: better risk management and third-party guidelines.
  • Stronger staff competence: employees gained the skills to act quickly and effectively on security tasks.

Compliance is not just about ticking regulatory boxes; it’s about building sustainable practices. By investing in staff competence, clarifying responsibilities, and embedding risk management, SEOM turned regulatory pressure into an opportunity for long-term resilience and trust.

Other Clients’ Stories

How can a nationwide organization with limited resources defend against phishing, hacktivist threats, and advanced attacks, while maintaining compliance and trust?

Read more

How can AwardIt, a fast-growing company, turn fragmented security into long-term resilience?

Read more

How can a global manufacturer ensure that its internal networks are resilient against unauthorized access, data exposure, and system misconfigurations?

Read more

How can an industrial manufacturer safeguard its IT systems from unauthorized access, misconfigurations, and data exposure while meeting stricter compliance demands?

Read more