Skip to content
Cybersecurity: digital risk and resilience

We help leadership lead through cyber threats and regulation.

Cyber threats are getting sharper and regulations are raising the bar. Organizations face a double pressure: defend against advanced attacks while proving resilience to regulators, customers, and stakeholders. It's no longer enough to be secure, you have to show it, every single day.

The newsletter for executives and boards

Every Friday. NIS2, AI Act and DORA summarized so you can act in five minutes.

Thank you! Check your inbox to confirm your subscription.

Something went wrong. Try again or email info@novudom.se.

From compliance to competitive edge

Cybersecurity used to be about avoiding fines or staying out of the headlines. Today, it's something bigger. Done right, it becomes a strategic investment that builds trust with customers, strengthens your brand, and fuels sustainable growth. Think of it as moving from defense to offense, turning compliance into confidence, and resilience into reputation.

We're seasoned professionals who've led security programs in some of the world's most complex organizations. We've sat at the leadership table, stood in the control room during crises, and worked alongside teams to embed resilience into everyday operations. That experience means we understand both the big picture and the small details that make security work in practice.

Novudom: Guardians of Trust, Architects of Resilience
Björn Nyhus, Client Director & Head of Business Development, Novudom

Björn Nyhus

Client Director & Head of Business Development

Björn helps executive teams, boards and public sector decision makers navigate complex risks, regulatory requirements and strategic choices in security and digital development.

Over 30 years of experience in the IT industry, with a focus on sales, business development and executive-level advisory across both the public sector and private enterprise. He has founded and built two consulting firms from the ground up to 20 employees and profitable operations.

With a focus on business development and client relationships, he turns uncertainty, risk and requirements into clear priorities and decisions that can be acted on. His strength lies in creating alignment between management, board and specialists, and in developing solutions that deliver lasting, measurable business value.

LinkedIn
Jonas Landström, Executive Cyber Advisor & Head of Delivery, Novudom

Jonas Landström

Executive Cyber Advisor & Head of Delivery

Jonas supports boards and executive teams in navigating a shifting threat and regulatory landscape where cyber risk has become a core business issue.

Over 20 years of establishing and operationally leading advanced security capabilities across OT, IT, information security, cyber security and GRC, in global groups, connected vehicle environments, industrial production and critical national infrastructure. He has built and run everything from secure infrastructure for connected vehicles to global functions for monitoring, incident response and data driven cyber defence with more than 100 specialists.

By combining experience from global cyber security leadership with strong governance and risk management expertise, he helps organisations build resilience, strengthen decision making and create long term security capabilities that work in practice.

LinkedIn
Caroline Kraft, Principal Advisor, Information Security & Cyber Resilience, Novudom

Caroline Kraft

Principal Advisor, Information Security & Cyber Resilience

Caroline helps executive teams and boards manage risk, strengthen resilience and turn regulatory requirements into effective governance and sustainable ways of working.

With expertise in ISO 27001, NIS2, risk management and management systems, she combines strategic advisory with internal audit and independent review. Her strength lies in making complex issues understandable and turning requirements and risks into clear decisions and concrete results.

LinkedIn
Michael Wolde, Principal Advisor, Leadership & Crisis Resilience, Novudom

Michael Wolde

Principal Advisor, Leadership & Crisis Resilience

Michael helps executive teams and organisations strengthen their decision making, collaboration and ability to act in complex change and crisis situations.

With extensive experience in leadership development, change management and crisis management, he brings the human perspective to security and resilience work. His strength lies in developing leadership and organisational resilience that holds when the business comes under pressure and conditions change quickly.

LinkedIn
Leadership lacks decision-making basis for digital risk and strategic resilience
NIS2, AI Act and DORA require concrete action, not just policies on paper
Security work lacks connection to business goals and operational value
Incident readiness is untested and the organization responds too late

Four concrete deliveries

Four sharp deliveries with clear outcomes, timelines, and regulatory fit. Each stands on its own or fits into an ongoing program.

Quick check: how far along are you with digital risk?

Take the assessment in 3 minutes →

Incident Response

A complete package that makes you ready when the incident hits. Current-state analysis, a tailored incident response plan, and a tabletop exercise that tests the capability in practice, aligned with NIS2.
Read more →

SOC, Modern SOC Framework

Establish a modern SOC that handles all digital security incidents, without building the capability in-house. Facilitated workshop, requirements, and vendor-neutral procurement support, from target state to signed contract.
Read more →

Secure Procurement

A full-day workshop that builds an internal capability to procure digital security with confidence. You leave with standardized role descriptions, contract templates, and a tailored supplier network.
Read more →

Supply Chain

Full control over your supply chain with a self-assessment method you run yourselves. Scalable to any number of suppliers, with NIS2 requirements built in if and when they apply.
Read more →

From insight to resilience

NovuLens gives you the starting point. Then NovuFlow and NovuLearn take over in an ongoing cycle that builds resilience over time, as a subscription.

Starting point

NovuLens™

Strategic analysis
Map current state, gaps, and risks. Leadership gets a clear decision basis to act on immediately.
Ongoing

NovuFlow™

Governance & execution
Ongoing governance of your security program, with milestones, ownership, and reporting to leadership.
Ongoing

NovuLearn™

Training & exercises
Training and scenario exercises that give leadership and key stakeholders decision-making capability in digital risk.
↻ Continuous subscription
1

Confident leadership in digital risk

Leadership makes informed decisions about digital risk, based on facts, not gut feeling.
2

Compliance that drives trust

NIS2, AI Act and DORA are met with concrete actions that build stakeholder confidence.
3

Measurable risk management

Clear metrics and reporting that show improvement over time, visible across the organization.
4

Business-driven resilience

Security work that protects business value, customer trust, and competitive advantage.
NIS2
Swedish Cybersecurity Act 2025:1506, management responsibility, risk management and reporting
AI Act
EU AI Regulation, risk classification, governance and documentation
DORA
Digital Operational Resilience, ICT risk, testing and incident management
GDPR
Data protection as part of security governance and risk management

Four steps to resilience

A proven process that takes you from uncertainty to confident leadership, at your pace, with clear ownership.

01
NovuLens™ analysis
We map current state, gaps and risks. You get a decision basis that leadership can act on immediately.
02
Prioritization
Together we identify the actions that deliver the greatest impact relative to your risk appetite and resources.
03
Implementation
We drive or support implementation with clear milestones, ownership, and reporting to leadership.
04
Ongoing governance
Continuous follow-up, reporting and adaptation, security evolves with your operations.

What Good Looks Like

for modern digital security

It always starts the same way. An organisation that grows. A digital landscape that becomes more complex. A responsibility that moves from the IT department to the boardroom. And an insight that eventually lands with everyone who succeeds:

Digital security is not technology.
It is a strategic capability.

Novudom Blueprint is our collected experience of what actually works in reality, not in theory. It is shaped by incidents, crises, transformations and hundreds of decisions in organisations that needed to stand firm when the storm hit.

At its core sits one simple principle: We do not build security for organisations. We build their capability to do it themselves.

The Blueprint describes what a modern security capability looks like when it works:

And above all: security is no longer a feeling. It is measurable, governed and real.

This is not a vision. It is not a powerpoint. It is a model that has been implemented in complex organisations, and that works.

This is What Good Looks Like.
This is Novudom Blueprint™.

Book NovuLens™, your starting point

A structured review that gives leadership a clear picture of your digital risk, strategic position, and prioritized actions.
Contact us →