Cybersecurity in practice — on-site with a Seclight client

Maria Svärd is training to become a cybersecurity specialist. She is doing her internship at a major direct client of Seclight.
The programme is run by the vocational college (YH) Frans Schartau. This autumn, Maria completed the first of two work-placement periods, learning in the workplace (LIA1 and LIA2). Maria took part on site with the client, working in a team together with three consultants from Seclight tasked with strengthening information and IT security to meet the requirements of NIS2.
— The programme is broad by design, and that's how it should be. It's only during the internship that I've really understood the bigger picture. The internship is an important part of the education, and doing it at one of Seclight's clients has deepened my understanding of just how difficult cybersecurity can be, says Maria.
— It's not just about implementing security requirements — there's so much else that affects what the client can prioritise. Being there to listen to the client has taught me a great deal.
The programme runs for two years and demands time, structure and discipline, Maria notes.
— I'm also taking other courses on the side. IT and cyber are constantly changing, with new technologies, new laws and new threats all the time. What you learned a few years ago can become irrelevant. The programme gives you a foundation and a general grounding. We definitely won't be finished learning after two years — but that's not really the point either.
Seclight likes to work in teams, but consultants sometimes work alone at a client site. That same trust can extend to interns.
— I've had a great chance to try that, with a very welcoming client where I've felt at home, says Maria.
At Seclight's office.
An open and structured personality is a good foundation for anyone who wants to work as a consultant.
— You need to be able to switch gears quickly and handle different information channels and many points of contact, since a consultant can have several clients at once, she notes.
Maria already has previous work experience.
— I've had roles at several different levels with previous employers, which means I understand both operational staff and management. That's a big advantage. There are also concepts and frameworks I already knew, like PCI DSS.
The internship exceeded expectations and has been valuable to the client.
— It suited me as a person to be able to figure things out on my own sometimes and to contribute. What I've contributed has genuinely made it into the delivery — that matters a lot for confidence, and I've learned enormously from not just sitting on the sidelines listening.
For Seclight, Maria as an intern is part of the team, not a separate track handled on the side. As an organisation, Seclight works to make sure students are prepared for working life ahead, rather than just marking time during their studies.
Challenge the student and keep the dialogue close — that's Seclight's message to clients and industry colleagues who may not yet have made the most of what internships can offer.
Maria still has one more internship period ahead of her but is already planning for working life, perhaps as a consultant in a team with driven, experienced colleagues.
— I think I'll need some support early on. Being employed rather than going out on my own could suit me well at first. I'm interested in work in society's critical functions and hope to be able to work in that area going forward.
She has one tip for anyone who wants to move forward in cybersecurity.
— Keep your ear to the ground! Take an interest in what's happening in the world around you. And don't think of it as a regular nine-to-five job. I was worried my knowledge wouldn't be enough, but it's gone really well.
Seclight — the right security, in the right order.
+46 8 94 55 99 info@seclight.com


