Sweden’s CISOs include some of the least conventional career paths in this series. One of the six below spent two decades at McKinsey, Bain, a venture capital firm, and several startups before taking charge of security at an industrial group. Another built a global social media team for H&M before running security for an air purifier maker in more than 80 countries. A third started as a business controller at Sweden’s debt enforcement agency. Alongside them are two long-serving bank and industrial security leaders and an IT manager who runs security from the island of Gotland. Together they protect two banks, a vehicle manufacturer, an industrial group, an island transport operator, and a digital services company.
Kimmy Nordqvist – CISO, Vend
Kimmy Nordqvist started as an IT instructor and project manager in Malmö and worked as an application developer at CSC, building call center applications and a pilot idea management system for Stockholm Arlanda Airport. As a digital business developer at H&M she created a global technical social media division for H&M and five other brands across 50 countries, growing a virtual team of more than 200. She joined Blueair, a Unilever company, as a consultant in 2017 and became its first Security and Compliance Officer, building security and privacy programs from scratch for e-commerce operations in more than 80 countries. She went on to lead cybersecurity at Menigo, a Sysco company, and served as Group CISO for Nobina Group. Nordqvist became CISO of Vend in August 2025. She also sits on PocketSafe’s NIS2 advisory board, leading workshops that help Swedish municipalities prepare for NIS2 through the Swedish Civil Contingencies Agency. She holds a master’s degree in applied information technology and CIPP/E, CIPM, and PMP certifications.
Marcus Berglund – CISO, SEB Group
Marcus Berglund spent his first years in IT security consulting at Parallel Consulting Group, Icon Medialab, and Ernst & Young, followed by six years at Canvisa Consulting working on IT strategy, enterprise architecture, and security. After a year as network security manager at EADS, he joined SEB in 2010 as an information security officer. He has led SEB’s information security for most of the time since, first as head of group information security in 2012, managing local security officers across three business units and about 20 sites worldwide. He has served as CISO for SEB Group since March 2021. Berglund has represented SEB in the Swedish Bankers’ Association and has been Sweden’s representative in FI-ISAC since 2013.
Nicolas Gomez – VP, CISO & Head of Information Security, Volvo Group
Nicolas Gomez began as a security consultant at PROTEGO in Denmark and spent seven years at PwC there as a senior security consultant, working on risk analysis, contingency planning, IT auditing, and penetration testing. He joined Novo Nordisk in 2011 and spent more than a decade in IT assurance, rising to director and then director of AI and technology projects. Gomez became VP, CISO, and Head of Information Security at Volvo Group in Gothenburg in December 2022. He holds CISSP, CPSA, and CPP certifications.
Peri Shabbir – CSO & CISO, Skandiabanken
Peri Shabbir started as a business controller at Kronofogden, Sweden’s enforcement authority, and then at Trafikverket, the Swedish Transport Administration. She moved into security at Regeringskansliet, the Government Offices of Sweden, working as a security strategist and then security operations manager. She went on to work as a cybersecurity specialist at Arbetsförmedlingen, the Swedish Public Employment Service, and as cybersecurity manager at Bonnier News, with a short stint as an information security specialist at Handelsbanken. Shabbir joined Skandiabanken as a senior cybersecurity advisor in 2023 and became its Chief Security Officer and CISO in 2024, leading security strategy, risk management, regulatory compliance, and resilience. She sits on the board of Women4Cyber Sweden and serves as a subject matter expert for the Swedish Institute for Standards.
Anna Thulin – CISO, Destination Gotland
Anna Thulin started as a system administrator and webmaster at Flextronics, then managed systems at PayEx Finance for nearly six years. At Svenska Spel, the state gaming company, she led a support systems team and then the support systems operations section. She moved to Gotland in 2011 to lead operations and service desk at Riksantikvarieämbetet, the Swedish National Heritage Board, later becoming its IT service delivery manager and acting IT chief. From 2019 to 2024 she was IT chief for infrastructure at Region Gotland, responsible for cybersecurity, networks, and the platforms behind all of the region’s systems, with up to 28 staff and the region’s entire IT budget. Thulin became CISO of Destination Gotland in Visby in March 2024, where she maintains the information security management system under PCI DSS, GDPR, ISO 27001, and NIS2. She is a certified coach.
Jörgen Andersson – CISO, Sandvik
Jörgen Andersson spent the first half of his career in strategy and startups. He started at McKinsey and Bain, co-founded the consulting firm Ariad Nordic and the venture capital firm Real Venture Group, and then co-founded Incirco, a mobile messaging company that grew to more than 50 staff before closing in the 2001 telecom crash. He supported the launch of 3G services in Sweden for 3 and Telenor, turned around the online gaming company Expekt.com in Malta and sold it, and as CEO of Nordic Leisure took the company from losses to profit. As an independent consultant he led digital transformation and GDPR compliance work at Ericsson and served as interim head of a project office. He then joined Sandvik as a program lead before becoming its CISO in May 2024.
Security From Every Direction
Sweden’s CISOs show how many different paths lead to the same seat. Berglund and Gomez built careers in security consulting and assurance before leading two of Sweden’s best-known institutions. Shabbir came up through government agencies, from debt enforcement to the Government Offices. Thulin spent decades running IT operations before taking on security for the island where she lives. Nordqvist moved from social media and digital business into building security programs from scratch, and Andersson brought a strategy consultant’s and entrepreneur’s lens to industrial security. That mix of public service, consulting, operations, and business leadership gives Sweden’s security bench unusual range.
Discover more CISOs securing their organizations:
- From Audit Rooms to Smart Cards: France’s CISOs to Watch
- Beyond the Ringstrasse: Austria’s Cybersecurity Leaders to Watch
- From the Carabinieri to the Grid: Italy’s Cybersecurity Leaders to Watch
- Beyond the Silicon Docks: Ireland’s Cybersecurity Leaders to Watch
- The Nokia Generation: Finland’s Cybersecurity Leaders to Watch
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

