Protective security analysis.
Nordan Shield turns complex security requirements into actionable protection. Assess threats and vulnerabilities, identify critical assets and dependencies, and use AI to prioritise the measures that matter most. From analysis to action, built for security-critical environments.
For security managers responsible for Swedish protective security work.
Protective security
The information sits in several departments.
The security manager needs details about systems, facilities, staff and suppliers, usually from people across the organisation. A new contractor or a change to a system can make the previous analysis out of date. Shield collects the answers and helps the security manager review them together.
For security-sensitive activities in Sweden, the analysis documents what needs protection, the threats and vulnerabilities, and the measures needed. The subsequent plan assigns responsibility and dates to those measures. Applicable rules depend on the organisation's supervisory area.
Säkerhetspolisen: PMFS 2022:1, chapter 2 (PDF)Examples
Security tasks
Security analysis
Bring the answers into one analysis.
IT, HR and operations each hold part of the information. Shield brings their answers into a draft analysis and keeps unanswered questions visible for the security manager to resolve.
Background and source
Säkerhetspolisen reported that Stockholm District Court lacked a protective security analysis. Its October 2024 report explains why the analysis is needed to assess whether protection is adequate. Säkerhetspolisen's report on Stockholm District Court, October 2024.
Supporting informationOpen question Defence suppliers
Review a contractor's access.
A new assignment involves sensitive information. Record what the contractor needs to reach, clarify the requirements with the customer and assign the measures needed before access is granted.
Background and source
The Swedish Armed Forces determines protective security agreement requirements for each assignment. Its guidance asks suppliers to clarify their obligations with the customer. The Swedish Armed Forces' guidance on protective security in procurement.
Protected informationAccess to review Personnel security
Check roles after a reorganisation.
Responsibilities and access have changed. Compare the new roles with recorded vetting decisions and flag gaps for the security manager. Shield records the assessment; it does not vet people.
Background and source
In April 2023, PTS reported that Telia had allowed communications security staff to take part in sensitive activities without carrying out the required security vetting. PTS's decision concerning Telia, April 2023.
Recorded assignmentChange to review
Reviewing the documents
Unanswered questions are recorded for review.
If one answer says a contractor has access to a system and another says no outside access is allowed, the security manager needs to resolve the difference. Shield checks answers against earlier information and the relevant requirements. Missing or conflicting information goes on a list for review.
- Analysis
- The operation, what needs protection, the threats and vulnerabilities, and the measures proposed to address them.
- Open questions
- Missing information and answers that do not agree. These stay visible until the security manager resolves them.
- Security plan
- The approved measures, who is responsible for each one, when it is due and whether it has been completed.
How it works
Using Shield
- 01
Answer the questions
Describe the operation with the people who know it. The interview covers assets, requirements, threats and vulnerabilities, using existing documents where available.
- 02
Check the draft
Review the suggested text, resolve missing information and agree on the measures. The responsible people in your organisation approve the analysis.
- 03
Maintain the plan
Assign the approved measures, set deadlines and record progress. The analysis and plan can be exported as PDF or Word documents in Swedish.
Your organisation makes the security assessments and remains responsible for compliance. Shield helps with the analysis and documentation.
Deployment
Run the software on your own servers.
Compass, Shield and the AI models can run on your organisation's own infrastructure. Your administrators decide who has access, how long records are kept and when the software and models are updated.
Your infrastructure