Skip to content
PlatformShield

Protective security analysis.

Nordan Shield turns complex security requirements into actionable protection. Assess threats and vulnerabilities, identify critical assets and dependencies, and use AI to prioritise the measures that matter most. From analysis to action, built for security-critical environments.

For security managers responsible for Swedish protective security work.

Protective security

The information sits in several departments.

The security manager needs details about systems, facilities, staff and suppliers, usually from people across the organisation. A new contractor or a change to a system can make the previous analysis out of date. Shield collects the answers and helps the security manager review them together.

For security-sensitive activities in Sweden, the analysis documents what needs protection, the threats and vulnerabilities, and the measures needed. The subsequent plan assigns responsibility and dates to those measures. Applicable rules depend on the organisation's supervisory area.

Säkerhetspolisen: PMFS 2022:1, chapter 2 (PDF)

Examples

Security tasks

  • Security analysis

    Bring the answers into one analysis.

    IT, HR and operations each hold part of the information. Shield brings their answers into a draft analysis and keeps unanswered questions visible for the security manager to resolve.

    Background and source

    Säkerhetspolisen reported that Stockholm District Court lacked a protective security analysis. Its October 2024 report explains why the analysis is needed to assess whether protection is adequate. Säkerhetspolisen's report on Stockholm District Court, October 2024.

    Supporting informationOpen question
  • Defence suppliers

    Review a contractor's access.

    A new assignment involves sensitive information. Record what the contractor needs to reach, clarify the requirements with the customer and assign the measures needed before access is granted.

    Background and source

    The Swedish Armed Forces determines protective security agreement requirements for each assignment. Its guidance asks suppliers to clarify their obligations with the customer. The Swedish Armed Forces' guidance on protective security in procurement.

    Protected informationAccess to review
  • Personnel security

    Check roles after a reorganisation.

    Responsibilities and access have changed. Compare the new roles with recorded vetting decisions and flag gaps for the security manager. Shield records the assessment; it does not vet people.

    Background and source

    In April 2023, PTS reported that Telia had allowed communications security staff to take part in sensitive activities without carrying out the required security vetting. PTS's decision concerning Telia, April 2023.

    Recorded assignmentChange to review

Reviewing the documents

Unanswered questions are recorded for review.

If one answer says a contractor has access to a system and another says no outside access is allowed, the security manager needs to resolve the difference. Shield checks answers against earlier information and the relevant requirements. Missing or conflicting information goes on a list for review.

Analysis
The operation, what needs protection, the threats and vulnerabilities, and the measures proposed to address them.
Open questions
Missing information and answers that do not agree. These stay visible until the security manager resolves them.
Security plan
The approved measures, who is responsible for each one, when it is due and whether it has been completed.

How it works

Using Shield

  1. 01

    Answer the questions

    Describe the operation with the people who know it. The interview covers assets, requirements, threats and vulnerabilities, using existing documents where available.

  2. 02

    Check the draft

    Review the suggested text, resolve missing information and agree on the measures. The responsible people in your organisation approve the analysis.

  3. 03

    Maintain the plan

    Assign the approved measures, set deadlines and record progress. The analysis and plan can be exported as PDF or Word documents in Swedish.

Your organisation makes the security assessments and remains responsible for compliance. Shield helps with the analysis and documentation.

Deployment

Run the software on your own servers.

Compass, Shield and the AI models can run on your organisation's own infrastructure. Your administrators decide who has access, how long records are kept and when the software and models are updated.

Your infrastructure

Compass
Shield
Your dataAI models