

– Like Sicra, we prefer to help organizations before something goes wrong. That is the best outcome for everyone involved, both from a socioeconomic and a commercial perspective, says Hedvig Moe, partner and lawyer at Thommessen.
As part of Sicra’s 10th anniversary, we interviewed Hedvig Moe about the future of cybersecurity. Moe began her legal career at Thommessen in 2000 before continuing her career at, among others, Økokrim, the Norwegian National Authority for Investigation and Prosecution of Economic and Environmental Crime, and PST, the Norwegian Police Security Service. She returned to Thommessen in May 2023.
Along the way, she developed extensive expertise in areas including geopolitics, national security and foreign intelligence, political processes, and legislative work. At Thommessen, she heads the firm’s national security practice, providing legal and strategic advice in areas where national security is relevant to businesses and public-sector organizations.
– When I returned to Thommessen in 2023, we saw that “national security” would become increasingly relevant to a growing number of organizations. At the same time, we expected more new legislation covering security, particularly digital security. I thought it was very interesting to be part of developing a new practice area, Moe explains.
In hindsight, there is little doubt that Thommessen was right. New legislation is coming both from the EU and at the national level. NIS2, which addresses cybersecurity and digital security, is on its way. The same applies to the CER Directive, which concerns physical security and the resilience of critical societal functions. In addition, “national security” applies to far more organizations than those most people immediately associate with “critical infrastructure,” such as energy companies. Moe gives a few examples:
– If we look at information security, organizations should consider the data they hold. Could it be of interest to foreign intelligence services? Could China or Russia be interested in what the organization is doing? Is the data valuable? Could the information be used to damage or sabotage something, either digitally or physically? Could information in the wrong hands be used to influence important decision-making processes? From this perspective, many organizations need to consider the requirements of the Norwegian Security Act, says Moe.
She adds that awareness of cybersecurity increased significantly following Russia’s full-scale invasion of Ukraine and the first Nord Stream incident.
– That was when many organizations realized that they needed to protect themselves against these kinds of actors, Moe says.
– How do you work with Sicra on cybersecurity? Who does what?
– Cybersecurity is most effective when the legal, strategic, operational, and technical aspects work together. We make sure organizations comply with the law and have the right agreements in place. We provide strategic advice, while Sicra handles the operational and technical aspects. We try to be practical and risk-based. We are very focused on not making the scope broader than necessary, but instead addressing what actually needs to be done. Security work must be simple and precise so that it meets the needs of the organization. You need to devote sufficient resources to security, but not more than necessary, says Moe.
While Thommessen handles the legal and strategic aspects, Sicra ensures that the operational and technical elements are in place. In practice, this means that Sicra’s experts carry out what can be described as digital due diligence, a systematic review of an organization’s digital infrastructure, data flows, and vulnerabilities. Who has access to which data? Where is sensitive information stored? Which systems are exposed to the outside world?
This mapping is essential because effective security depends on understanding what needs to be protected. Sicra understands the data, systems, and networks and knows which measures will actually reduce risk for the specific organization. This knowledge makes it possible to translate the legal requirements identified by Thommessen into concrete technical solutions.
The result is two specialist teams working from different directions toward the same goal: ensuring that legal requirements are met, data is protected, and the organization is prepared to withstand a cyberattack.
Looking ahead, Moe expects legislation concerning digital security to become increasingly extensive. NIS2, the EU directive on cybersecurity, is already in force in the EU and will be incorporated into Norwegian law. The CER Directive is also likely to extend security requirements to more organizations than those currently covered by the Norwegian Security Act.
At the same time, Moe highlights three challenges related to artificial intelligence:
– AI must become part of an organization’s overall security efforts. If AI is treated as a separate area, there is a real risk that it will not be managed properly, Moe warns.
Cyberattacks are costly. On average, it takes 24 days to recover from a ransomware attack. That is equivalent to five working weeks. And the financial consequences are significant. According to an IBM report, the average cost of a data breach is more than NOK 40 million. For most medium-sized organizations, that represents a substantial impact on the bottom line.
On top of this come costs associated with GDPR and other regulatory violations, lost customer contracts, reputational damage, and more.
– The knock-on effects of a cyberattack can be significant. This is particularly true today, when organizations rely on long supply chains and complex digital structures, says Moe.
Thommessen is often contacted by organizations that have been affected by cyberattacks. At that point, they need assistance complying with regulatory requirements related to notifying authorities, customers, partners, and other stakeholders.
– If you are hit by a cyberattack, it costs a great deal of money. In addition to handling the attack itself, enormous amounts of time and resources are spent dealing with agreements and contracts relating to compensation and insurance. On top of that come reputational and often ethical issues. And you may not know whether information has fallen into the wrong hands or how it is being used, says Moe.
– That is why we are most concerned with the slightly less exciting part: trying to prevent organizations from being attacked in the first place. That is what we are working with Sicra to achieve. More and more organizations understand this, and the willingness to invest resources and money in preventive measures is increasing, Moe concludes.


.jpg?width=292&height=365&name=Sicra_office_3076%20(1).jpg)
