Blog

blog image

July 13, 2026

The Cybersecurity Act: What Smaller Companies Need to Know About Supply Chains and Cyber Hygiene

The new Cybersecurity Act (based on EU legislation) has become a hot topic of conversation in the business world. The main purpose of the law is clear: to raise cybersecurity and incident readiness across society, while giving corporate management clearer ownership of security issues. The focus lies on socially critical operations, such as government agencies, municipalities, energy companies, and food supply. So why is a law specifically targeting critical societal functions being discussed so broadly? The answer is the supply chain. ### Requirements Inherited Down the Line The legislation includes a strict requirement for covered organizations to ensure that their entire supply chain is secure. When a government agency or an energy company procures goods and services, they must vet their suppliers. In practice, this means that regardless of whether you run a large or small company, you will face tough security questions in future procurements. The requirements are simply inherited down the line. A vulnerability in a sub-contractor several tiers down ultimately becomes a vulnerability for the socially critical organization. ### Compliance Burden or Real Benefit? It is easy to view new laws as mostly unnecessary administration. However, much of the work provides a tangible benefit, and if approached wisely, it does not have to be overly burdensome. Information security is fundamentally about structure, and once you have those structures in place, it translates into security improvements that protect your business every single day. In an era of frequent cyberattacks and phishing attempts, good "cyber hygiene" is absolutely vital for any company. ### Three Steps to Tackle the Project For smaller organizations lacking a large IT budget or a dedicated compliance department, it is all about being concrete and narrowing the scope. The work can be boiled down to three central steps: 1. Get the technology right: Start with the low-hanging fruit. Implement two-factor authentication on all systems, ensure firewalls are enabled, and perform continuous security updates. Also, train your staff regularly so they recognize threats such as phishing (fraudulent emails) and vishing (phone scams). 2. Document: Conduct a simple inventory of your assets—what software, hardware, and networks do you use? Identify the risks associated with these and establish clear policies. For example, how do you manage "Shadow IT" (when employees use private phones or computers for work)? By documenting your processes, you will have ready-made answers when clients ask questions during a procurement. 3. Follow up: Cybersecurity is a moving target. At regular intervals, you must evaluate whether your routines align with reality, perform new risk assessments when purchasing new technology, and stay updated on emerging threats. ### Do You Need ISO 27001 Certification? Larger organizations often run heavy projects to get certified according to ISO 27001. For a smaller company—perhaps around 50 employees with a less complex operation—a formal certification is rarely necessary, unless explicitly required by your clients. It is far more important that you actually do the right things and have them documented in a well-functioning information security management system that mirrors the structure of ISO 27001, rather than having the actual certificate on the wall. Here at Lantero, we have developed ready-made, easy-to-understand templates and pre-filled examples to help you inventory your resources, conduct risk assessments, and establish the right structure from the start—without making the process heavier than it needs to be.
blog image

July 6, 2026

Whistleblowing in municipalities – trends and challenges

Lantero currently partners with around 80 of Sweden’s municipalities. Through this unique insight, we see a clear development: activity within municipal whistleblowing channels is increasing. But what is actually driving this development, how are the incoming cases best managed, and what new administrative challenges are waiting around the corner? We summarize some of the key insights based on a conversation with whistleblowing expert Andreas Wahlström. ### Increased Awareness and Turbulent Periods The fact that more reports are being submitted is primarily due to two things: increased trust and better information. Employees are becoming increasingly aware that these channels exist and trust that they are secure. However, this is not an entirely universal trend; activity varies greatly from one municipality to another. We see a clear link to two specific factors: 1. Focus on Welfare Crime: In municipalities that actively combat corruption and welfare crime, the propensity to report increases. 2. Turbulence and Change: Organizations undergoing a phase of restructuring or turbulence often experience higher pressure in their channels. Experience also shows that municipalities that are engaged and skilled at continuously training their staff receive more—and more relevant—reports. ### Screening and the Need for Investigative Expertise One of the greatest challenges for a municipality is managing the breadth of what is reported. Less than half of the incoming cases actually fall under the strict definition of the Whistleblowing Act. Much of it instead concerns general complaints or personnel matters. Despite this, a large portion of the reports carry significant value for the employer to be made aware of and to follow up on. Once a complex case has been identified, the next challenge arises: the investigation. Conducting an investigation internally can be legally and operationally complicated. A clear trend is therefore that more and more municipalities choose to bring in external expertise to quality-assure the investigative work and guarantee an independent review. ### The New Administrative Challenge: "War of the AI:s” Once a case has been handled, it does not always end there. Awareness among journalists and the public regarding the existence of these channels has increased, which has led to a significant spike in requests to extract documents from the systems. This is largely driven by AI technology. Since reviewers can now use AI to read and summarize vast amounts of text, they do not hesitate to request extensive logs and all available cases. For the already heavily burdened municipal case officers, this creates immense administrative pressure, as confidentiality and harm assessments (skadeprövning) must be carried out promptly and meticulously, since accidental disclosure of sensitive information can have severe consequences. To meet this AI-driven wave of requests, the municipalities themselves have begun implementing AI support in their processes. By allowing an AI to handle the groundwork and flag potential confidentiality risks, administrative time can often be cut by around 80%. This frees up time so that case officers can focus on what only a human can do: the final, qualified harm assessment.
blog image

June 29, 2026

Four Years with the Whistleblowing Act: The Market Matures as Municipal Contracts Are Renewed

Approximately four years have now passed since the Swedish Whistleblowing Act entered into force for the country's municipalities. This means that the first generation of procured contracts and system solutions is now expiring, which has triggered an intensive wave of contract renewals and direct procurements. Looking back at the past four years, it is clear that much has changed. From being a completely new and untested legal requirement, the field has matured significantly. Here, we summarize the three clearest trends and challenges shaping municipal whistleblowing solutions right now. 1. Higher Quality and the Decline of Clusters When the legislation was first introduced, uncertainty was high. Many municipalities pooled their resources into large clusters for joint procurements, and several attempted to build their own internal solutions. Today, we see a completely different level of confidence in the market. Clearer Specifications: Municipalities have gathered valuable experience. They know exactly what they want, and the procurement specifications are of a significantly higher quality. There is a demand for system solutions with specific functionality, such as integrated login (Single Sign-on) and advanced AI support for masking sensitive information when responding to public records requests. More External Sourcing: Organizations that previously attempted to manage channels entirely internally are now increasingly choosing to seek external assistance, both with the reporting solution and with parts of the case management. Independent Sourcing Replaces Coordination: The tendency to join large clusters has decreased. Because the process has proven to be smooth and uncomplicated, most municipalities now choose to handle their procurements independently. Furthermore, contracts are being signed for significantly longer periods than before (often up to 6 or 7 years), as the cost structure has stabilized and trust in suppliers has grown. 2. Large vs. Small Municipality: Independence in Focus The need for support in the process naturally varies depending on the size of the organization, but interestingly, resources are not the primary deciding factor. The very large municipalities often have the capacity to handle a large part of the case management internally. For other municipalities, it instead comes down to two critical factors: independence and competence. In a smaller municipality, where a case officer might only handle a handful of cases per year, the learning curve is steep and the challenges are completely new each time. Additionally, it is operationally difficult to guarantee a completely independent and impartial internal process. Therefore, external parties are increasingly in demand to step in more actively in the workflow, perform initial assessments, and act as a sounding board or investigator in more complex cases. 3. The Swedish Work Environment Authority Steps Up Inspections After maintaining a relatively passive profile during the initial years, the Swedish Work Environment Authority (Arbetsmiljöverket), as the supervisory authority, has now sharply increased its audits. They conduct regular inspections to review how channels actually function—and there is a clear common thread in what they look for. Right now, the authority’s focus is primarily on the written word. They compare the literal text of the law with the organization's internal policy documents and documented routines. They simply assume that what is written in the organization's guidelines reflects their practice. Sooner or later, the authority will knock on the door of most public actors, and when that happens, the documentation must hold up to scrutiny. How are you preparing? The market has shifted from uncertainty toward standardization and stability. This is highly visible among municipally owned companies—even those with well under 50 employees that are not formally covered by the legal mandate. Many of them still proactively choose to implement external whistleblowing channels, both for the purely business value of capturing useful information and as an important part of their employer branding. Should you receive an inquiry from the Swedish Work Environment Authority, or are you about to renew your current contracts? As a Lantero client, we are always available to provide direct support. We help you prepare accurate responses for the authority and continuously update our documentation and texts based on current practice and experiences from previous supervisory cases.
blog image

June 23, 2026

World Whistleblowers Day – A tribute to our vital troublemakers

Every year on June 23rd, we recognize World Whistleblowers Day. The day was established to acknowledge and honor those who blow the whistle on corruption, misconduct, and irregularities, as well as to recognize heroic efforts in defending human rights and democracy. In public debate, being a whistleblower is generally perceived as something highly honorable. In practice, however, it is often a very thankless role, rarely met with goodwill. The whole idea is that you fight for what you believe is right, but in opposition to the prevailing order where you operate. In reality, this also frequently means entering into conflict with your employer, your colleagues, and your superiors. At Lantero, we work with whistleblowers and whistleblowing cases every single day. We know that reported cases often miss the mark. Sometimes they are matters that do not belong in the channel at all, such as issues concerning interpersonal conflicts or leadership. Other times, they stem from a misinterpretation of the circumstances. Those who report are often driven by a strong sense of justice. But just as often as actual violations are brought to light, the report may be based on an overinterpretation or misconstruction of the situation. Whistleblowers tend to be of a personality type that dares to go against consensus, which in certain situations is admirable and valuable. In practice, however, the individual is often perceived as a crank or a troublemaker. We at Lantero constantly remind ourselves of this duality. It is easy to see the troublemaker and focus on cases that perhaps should be handled face-to-face between a couple of colleagues. At the same time, these are the very individuals who are prepared to stand up and sound the alarm when something is genuinely wrong. As professionals working with these issues daily, we tip our hats to this often thankless commitment. Today, let us celebrate our challenging, yet upstanding and vital whistleblowers!
blog image

May 6, 2026

Summary of Recent Technical Developments

Lantero maintains an active agenda for ongoing technical development. This applies to our whistleblowing service as well as support services regarding compliance, user management, and the redaction service, Redact. The following is a summary of some of the technical and security-related changes implemented over the past year. ### Cloudflare Turnstile The reporting form in the whistleblowing service now utilizes Cloudflare Turnstile, which provides a seamless way to protect against bots without disrupting the user experience. ### Infrastructure Overview Our internal monitoring has been better structured to allow us to proactively handle issues before they impact the customer. We have real-time monitoring in place, providing immediate feedback regarding any disturbances in our systems or services. Bitdefender is active on all our servers, and we apply maintenance and upgrade procedures on a daily, weekly, and monthly basis to ensure everything runs smoothly and predictably. ### Information and Operational Security Some of our initiatives during the year include: - Anonymized Application Logs: We have established anonymized logs to protect personal data. - Vulnerability Patching: Patched several known vulnerabilities (CVEs) across the npm ecosystem. - Dependency Updates: Ensured that all major code libraries have been updated, such as Express, Vite, and Qs. - JWT-based Verification: We have modernized the authentication flow by switching to JWT-based user verification. In practice, this means the server does not need to store information about logged-in users, providing a more secure and reliable method for session management. - Deletion Protection: Implemented protection against deleting a channel that still contains active cases, serving as an extra safeguard for case information. ### Infrastructure and Performance Several efforts have been made to make the platform faster, more stable, and easier to maintain. During the past year, we have, among other things, completed the following: - MongoDB Upgrade: Upgraded to version, v7. This brings several security enhancements, as well as improvements in encryption, stability, and cluster management, while securing long-term support. - React Upgrade: Upgraded to React v19.2, the latest stable version of React 19. This version represents a paradigm shift in how the framework handles interface updates. Among other benefits, it reduces the need for manual routines and offers advantages for search engine optimization (SEO). - Node.js 24 Support: Provides more efficient memory management and improved support for the latest API standards. - Email Queue: Implementation of an email queue to avoid issues caused by too many simultaneous SMTP connections. - Autosave Functionality: Improved functionality for automatic saving. - Session Renewal: Minute-by-minute session renewal to reduce the risk of being logged out while working. - Nginx Improvements: Updated to follow best practices, including log rotation and HTTP/2 configuration. Do not hesitate to contact us if you would like to learn more about our development and security efforts.
blog image

May 6, 2026

Last year's development of the whistleblowing service

Lantero has offered whistleblowing services since 2014 and has long maintained a well-established service where changes on the surface may appear minor. At the same time, looking back at the past year, we can conclude that it has been a very active year of development, featuring plenty of new functionality, security enhancements, and "under the hood" improvements that bolster both user experience and stability. The following is a brief summary of the past year's developments, and we welcome any questions or feedback from our users. ### Integration of Redact Handling whistleblowing cases involves working with sensitive information where there is a particular responsibility to protect both the whistleblower and other individuals appearing in the cases. When information is requested as a public document, or when information needs to be shared with other parts of the organization, a need for redaction may arise. Lantero has therefore built this functionality directly into the whistleblowing service. The Lantero Redact service is a tool for masking documents, providing the caseworker with AI-generated suggestions for redactions, which can then be adjusted before a new masked document is generated. While offered as a standalone tool, it is now also available as a feature directly within the whistleblowing channel. This means you can save a redacted copy of a whistleblowing case directly within your standard workflow. ### Customized Options for Anonymity Different organizations take different approaches to anonymity. While legislation sets strict requirements for the protection of confidentiality, it does not mandate that reporting must be possible anonymously. We have now made it possible for individual customers to customize their setup regarding anonymity. ### Activity Log Notifications and Daily Summaries Many different types of events can occur during the management of a case in Lantero's whistleblowing system. We have now expanded the notification options so that you can be alerted to more types of events in the case management process. At the same time, we know that organizations with high case volumes may find that they receive too many email notifications. We would therefore like to highlight the daily summary function. This feature allows you to limit email notifications to one per day, summarizing the day's activity. ### Smarter Case Management During the initial assessment of cases, it is now easier to see which caseworkers are staffing each part of the process, particularly to identify available options for staffing the Investigation stage. The case summary generated in PDF format has been improved, with the structure reviewed and refined. ### Improved User Experience As a caseworker, there are new options to customize the case management view, including the ability to collapse sections that are not currently in use. We have added security prompts that require extra confirmation before high-risk activities, such as deleting a channel. The shortcut to the overview page has been made clearer and established as its own button. Previously, the shortcut was located within the Lantero logo, which proved to be too indistinct. Language options have been expanded, and 22 languages are currently available. A series of improvements have been made to the integration with Lantero's portal for login and user management, making the user experience even smoother.
blog image

February 11, 2026

AI Development and Risk Management: Navigating Technology and Law

Implementing AI in an organization today is not merely a technical challenge, but very much a legal and security-oriented one. In a conversation between Lantero and expert Joakim Karlén (in Swedish), we highlight the complex issues that arise when Large Language Models (LLMs) encounter European legislation such as GDPR and the new AI Act. ### Innovation in the US, Regulation in the EU Technological development is largely driven by American companies, but for Swedish and European organizations, local legislation sets the boundaries. Joakim Karlén notes that the current dynamic is challenging because the pace of innovation is lightning-fast while regulation is brand new. There is still a lack of clear legal precedent and court rulings, which places high demands on an organization’s internal capacity for risk analysis. ### The Clash Between GDPR and AI Dynamics One of the most central questions is how AI systems—which are by nature dynamic and non-deterministic—can live up to GDPR’s requirements for accuracy. Traditional IT systems are static; you know what you input and what you will get as output. An LLM works differently. By simulating human behavior with a degree of randomness, the output is not always predictable. This creates fundamental uncertainty regarding individual rights and the accuracy of the processed data. ### From Chatbots to Autonomous Agents We are seeing a clear shift from simple chatbots to autonomous agents capable of performing tasks independently. This introduces new risk vectors. Joakim emphasizes that an organization deploying an AI system is considered a "deployer" under the AI Act and thus bears the legal responsibility. This becomes particularly critical when agents are given the mandate to act without human intervention. The risk of incorrect decisions or random behavior means that traceability—the ability to explain why a machine acted in a certain way—becomes both a technical and legal challenge. Not least when it comes to cybersecurity. ### Internal Risks and "Oversharing" While many focus on external hackers, one of the greatest risks is internal. The concept of "oversharing" describes when an AI agent, due to a lack of permission management or classification, gives employees access to sensitive information they are not authorized to see. Protecting the "machine" itself and its access to internal data sources is therefore just as important as protecting the raw data. ### Methodology Wins in the Long Run To succeed, Joakim suggests a methodical approach. Instead of simply "trial and error," organizations should begin with a holistic analysis based on the AI Act, GDPR, and cybersecurity legislation (NIS2). By understanding the purpose of the technology and maintaining control over the information structure, you can build correctly from the start.
blog image

January 20, 2026

What to Consider as a New Whistleblowing Case Handler

Below is a lightly edited version of an interview (in Swedish) we conducted with Sara Johansson, who works with whistleblowing assessments at Lantero. We asked her what new case officers need to keep in mind when they start handling whistleblowing cases, what types of situations they may encounter, and which common pitfalls to watch out for. Interviewer: When someone steps into a role as a new case officer in a municipality and begins working with the whistleblowing function, what should they keep in mind or expect? Sara Johansson: You’ll need to find a way to separate the wheat from the chaff, because many of the reports you receive are not, in fact, whistleblowing cases. They may involve an employee having issues with their manager, comments on organisational efficiency, or opinions on how things are structured. These are typically not whistleblowing matters. Then there are cases where there is actually something to look into. In those situations, you need to determine whether the reporting individual belongs to the protected group under the legislation, and whether the report concerns a public-interest wrongdoing. This might involve signs of corruption, serious conflicts of interest, or questionable recruitment processes carried out without proper advertising. In some types of operations, there may also be risks to patient safety or collaboration difficulties in critical environments. The key is to identify and distinguish these cases from the rest. Interviewer: There is a lot of legislation underlying this work, and case officers need to apply it in their assessments. And in many organisations—especially smaller ones—actual cases are infrequent. How should one stay up to date on these issues? Sara Johansson: One challenge is that there are very few court decisions in this area, which means there's not much case law to rely on. My recommendation is therefore to read everything that is published: follow relevant accounts on LinkedIn—ours, for example—and stay updated on news reporting around the topic. At the same time, you need to keep in mind that there is a clear sequence for handling these cases: there must be a wrongdoing, and it must concern a group defined as the public. Interviewer: And if someone has questions? Sara Johansson: Then they contact Lantero. Interviewer: Do you have an example of a situation that may arise—something many case officers will encounter early on? Sara Johansson: Do you want an example of a case that isn’t a whistleblowing matter? Because most cases are not. Interviewer: Yes, describe that type of case. Sara Johansson: The most common goes something like: “You have to do something. We can’t take it anymore. Our manager has completely lost control.” Then follows a long description of everything that is not working. This is by far the most common scenario. Interviewer: And what is your advice to the client in that situation? Sara Johansson: My advice is to explain that this is not a serious wrongdoing under the law, but something that needs to be addressed through another process. Often, you raise it within the organisation as a tip—an indication that the organisation should take a closer look at how the work environment is functioning—rather than treating it as a whistleblowing case. Interviewer: If you have further thoughts or questions on this topic, you are very welcome to contact us. Otherwise, we wish you the best of luck—and thank you for watching.
blog image

December 3, 2025

Redacting Whistleblowing Cases – What Do Case Officers Need to Know?

When a public authority receives a request to disclose documents, the same question often arises: how much may – or must – we redact in a whistleblowing case? Many case officers find this difficult, as whistleblowing cases involve sensitive information while the principle of public access imposes strict requirements to release documents. We interviewed Andreas Wahlström (in Swedish), who works with assessments and redaction of whistleblowing cases at Lantero. He explains both the legal requirements and the practical challenges faced by municipalities and government agencies. Andreas reminds us that public documents are, as a rule, public. This means that “anyone has the right to request a whistleblowing report.” But the obligation to disclose also comes with a significant responsibility to redact. This applies to both directly identifying information and indirect details that could reveal the whistleblower. Redaction is therefore a central part of managing whistleblowing cases. The legal basis primarily comes from two chapters in the Swedish Public Access to Information and Secrecy Act: OSL Chapter 32, Section 3 b and OSL Chapter 17, Section 3 b. These regulate the protection of reporting individuals – as well as other persons mentioned in the report. In practice, the guidance is clear: redact rather more than less. If there is any uncertainty, the case officer should act cautiously to protect everyone involved. For many case officers in municipalities and government agencies, redaction is still a manual process. Andreas notes that in the past six months, new tools have emerged that make the work both faster and safer. These tools propose what should be redacted, simplify the workflow, and help the case officer produce a document that can be safely disclosed. One such example is Lantero Redact, a tool developed to help public-sector organisations manage redaction in accordance with legal requirements. It provides concrete suggestions on what to redact, is easy to use, and ensures that the material is properly anonymised before disclosure. For those who want to dive deeper or need support in a specific case, Andreas and the team at Lantero are available to help. Redaction is not only a legal requirement – it is also a crucial part of maintaining trust in the whistleblowing function and protecting reporting individuals.
blog image

November 20, 2025

Practical experiences of AI-supported masking

Lantero interviewed Therese Forsberg, an investigator at the Department of Administration in Uddevalla Municipality. Therese works with redaction of documents in response to requests for public records, and she has been using Lantero Redact over the past months — receiving AI-based support for assessment and redaction. Below is a slightly shortened version of the interview. (Video version is in Swedish) Interviewer: Uddevalla is a municipality with around 60,000 residents. When it comes to requests for public records, what kind of volumes are you dealing with? Interviewee: It varies. It depends on what’s happening in the organisation. When incidents occur that lead to deviations or Lex Sarah cases, the volume increases. We also have some media outlets that submit weekly requests for all incoming records from the past week. That’s the case for municipalities across Sweden — some outlets do this continuously. So the amount can fluctuate a lot, especially if serious cases have come in. Interviewer: To what extent is this possible to plan for? Interviewee: Some parts are always manageable, but it becomes difficult when large volumes come in — sometimes thousands of documents. We don’t have a dedicated person working on this full-time, so our department has to share the workload. How the process used to work Interviewer: What did the routines look like before? Interviewee: We did everything the old-fashioned way. We printed out the documents and redacted them manually using Tipp-Ex. Then we copied and scanned them before sending them off. Adobe has some tools, but they haven’t been reliable. You could sometimes lift off the redaction digitally, so we always had to print and scan everything anyway. It was time-consuming and difficult to manage when working remotely. How the work is done now Interviewer: What does the routine look like now? Interviewee: It’s much faster. With the redaction service, we can mark what we want to redact digitally and save it directly. We avoid all the printing and scanning, which saves a lot of time. I also feel that we have better oversight of the documents and the process. Interviewer: One idea with the AI support is that more people could participate in the work by accepting or rejecting suggested redactions. Have you started expanding that responsibility? Interviewee: Not yet. We’ve involved some colleagues, but they have the same level of knowledge as we do. So for now, the responsibility remains within our department. Model training and new updates Interviewer: You recently received an updated version of the service. Have you had a chance to test the new capabilities? Interviewee: Very briefly, but what I saw looked good. I need to test it more before I can say anything definite. Interviewer: Do you think the assessments look similar across different municipalities? Interviewee: Yes, I think so. We all work with the same types of documents and the same regulations. The goal is always to protect the individual and avoid revealing personal data. That should lead to similar approaches to what needs to be redacted. User experience of the service Interviewer: Any final reflections? Interviewee: The service has been easy to use. We’ve found it user-friendly and free from issues. It has worked throughout the entire test period, which has been very valuable since we’ve had unusually large volumes of cases recently.
1of 7