Dynamic Decision-Making and Crisis Management under the NIS2 Directive: A thematic analysis of cybersecurity consulting frameworks
2026 (English)Independent thesis Advanced level (degree of Master (One Year)), 10 credits / 15 HE credits
Student thesis
Abstract [en]
The digitalisation of the energy sector and the introduction of the NIS2 directive create a highly complex landscape for crisis management. The directive mandates strict 24-hour incident reporting, which structurally conflicts with the operational realities of cyber-physical attacks on operational technology. This thesis investigates how the crisis leader’s operational scope of action is constructed in the tension between NIS2 compliance and dynamic crisis management within the Swedish energy sector.
Employing Dynamic Decision-Making (DDM) as the theoretical framework, this study conducts a thematic document analysis of strategic guidelines published by leading cybersecurity consulting firms. The findings demonstrate that the formal leadership’s scope of action is limited during an acute cyber-physical incident. Faced with the conflict between rapid technical threat progression and administrative deadlines, the formal leadership experiences severe time constraints and information ambiguity. This leads to cognitive overload and a rapidly shrinking space of possibilities.
The operational scope of action is constructed by external cybersecurity consultants acting as boundary spanners. These consultants filter technical noise, reconstruct operational feedback loops and dictate the available strategic options. The thesis concludes that while this outsourced expertise is a functional necessity to navigate the compliance trap, it introduces a systemic vulnerability. It creates a critical decoupling of accountability, where legal liability remains centralised with the formal leadership. However, practical operational understanding and decision-making are outsourced to commercial third-party entities.
Key words: dynamic decision-making, nis2 directive, cybersecurity, crisis management, critical infrastructure
Place, publisher, year, edition, pages
2026. , p. 54
Keywords [en]
Cybersecurity, NIS2-directive, Thematic analysis, Consulting frameworks, crisis management
Keywords [sv]
Cybersäkerhet, NIS2, Tematisk analys
National Category
War, Crisis, and Security Studies Political Science Information Systems, Social aspects
Identifiers
URN: urn:nbn:se:fhs:diva-14979OAI: oai:DiVA.org:fhs-14979DiVA, id: diva2:2078898
Subject / course
Ledarskap och ledning för försvar, krishantering och säkerhet
Educational program
Masterprogram i Ledarskap och ledning för försvar, krishantering och säkerhet
Uppsok
Social and Behavioural Science, Law
Supervisors
Examiners
2026-06-252026-06-242026-06-25Bibliographically approved