Lösenordsfri autentisering inom den offentliga sektorn: En analys av säkerhet och organisatoriska utmaningar under NIS2 och cybersäkerhetslagen
2026 (Swedish)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE credits
Student thesisAlternative title
Passwordless authentication in the public sector : An analysis of security and organizational challenges under NIS2 and the cybersecurity act (English)
Abstract [sv]
Den snabba tekniska utvecklingen och ökade cyberhot mot den offentliga sektorn ställer högre krav på robusta autentiseringsmetoder. Syftet med detta examensarbete är att undersöka förutsättningarna samt organisatoriska utmaningar vid ett införande av lösenordsfri autentisering (LFA) inom svenska offentliga verksamheter, särskilt fokus på hur regelverk som NIS2-direktivet och cybersäkerhetslagen påverkar styrningen. Studiens frågeställningar besvaras genom en kvalitativ forskningsansats baserad på en dokumentanalys av gällande lagstiftning i kombination med semistrukturerade intervjuer med IT-ansvariga inom offentliga verksamheter. Den insamlade datan analyserades tematiskt för att identifiera tekniska, ekonomiska och regulatoriska faktorer som styr myndigheters strategiska IT-prioriteringar.
Studiens resultat visar att offentliga verksamheter har en positiv inställning till lösenordsfri autentisering som en del av en multifaktorsautentisering (MFA), men att det ofta rör sig om organisatoriska och ekonomiska hinder som stoppar en fullskalig lösenordsfri autentiseringslösning. Det framkommer att lagkraven är för ospecifika för att driva större arbete inom lösenordsfri autentisering utöver de krav som finns på multifaktorsautentisering.
För att underlätta övergången till LFA rekommenderas att skiftet förankras strategiskt i organisationens ledningssystem för informationssäkerhet (LIS) och att biometrisk teknik integreras i ordinarie hårdvaruupphandlingar.
Slutligen bör resultaten tolkas utifrån studiens specifika avgränsning. Undersökningen har avsiktligt begränsats till offentliga verksamhetsutövare, och analysen har strikt koncentrerats kring effekterna av NIS2-direktivet och cybersäkerhetslagen.
Abstract [en]
The rapid pace of technological development and increasing cyber threats against the public sector place stricter demands on robust authentication methods. The purpose of this bachelor thesis was to investigate the conditions and organizational challenges surrounding the implementation of passwordless authentication within Swedish public organizations, with a specific focus on how regulations such as the NIS2 Directive and the Cybersecurity Act influence governance. A qualitative research approach was applied, based on a document analysis of current legislation combined with semi-structured interviews with IT managers within public organizations. The collected data was analyzed thematically.
The results show that public organizations have a positive attitude toward passwordless authentication as part of multi-factor authentication (MFA), however, organizational and economic barriers often prevent full-scale implementations. Furthermore, legal requirements are too non-specific to drive major efforts beyond existing requirements .
To facilitate the transition, it is recommended that the shift be strategically integrated into the information security management system (ISMS) and that biometric technology be incorporated into regular hardware procurement processes .
Finally, the findings should be interpreted within the study's specific limitations. The study was intentionally restricted to public sector entities, and the analysis concentrated strictly on the effects of the NIS2 Directive and the Cybersecurity Act.
Place, publisher, year, edition, pages
2026. , p. 43
Keywords [en]
Cybersecurity act, MFA, NIS2-directive, passwordless authentication, public sector
Keywords [sv]
cybersäkerhetslagen, LFA, lösenordsfri autentisering, MFA, NIS2-direktivet, offentlig sektor
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:hj:diva-73562OAI: oai:DiVA.org:hj-73562DiVA, id: diva2:2092567
Subject / course
JTH, Informatics
Supervisors
Examiners
2026-08-182026-08-172026-08-18Bibliographically approved