Delivering security is all about trust.
Our customers trust our expertise and our delivery. Since 2022 we have helped pharmacy chains, education companies, retail and industry get the right security in the right order. Here are a few of them.




Pharmacy and healthcare

Security work had to follow NIS2 and the Swedish Cybersecurity Act, with stronger internal capabilities in place before the law took effect.
Everything from governing documents to training: NIS2 requirements turned into practical, sustainable ways of working, with improvements to access management, risk governance and continuity planning.
A security structure and culture that is both compliant and sustainable in the long run.
“They delivered both technical and organisational improvements in a pragmatic, cost-effective way. We now have a security structure and culture that is both compliant and sustainable.”
A pharmacy chain needed support through its PCI DSS card-payment certification.
We led the preparations, made sure every part of the business was on board, dealt with weak spots ahead of time and sat in on the audit interviews.
The certification passed.
Education

A growing edtech company with international acquisitions needed a structured security programme sized for a medium-sized business.
Maturity assessment, business continuity planning, NIS2 gap analysis and risk mitigation, plus documented policies, risks, supplier register and data flows.
A clear structure, confidence in the work, and a data protection officer who no longer stands alone.
“Nina rolled up her sleeves and took responsibility for documenting our policies, risks, supplier register and data-flow descriptions, which has given us a clear structure and confidence in our work.”
Retail
A major food retail chain needed more security expertise in its IT and OT projects.
Senior consultants joining project teams on demand, across a significant portfolio of projects.
The client kept calling off several Seclight consultants in the role over multiple years.
A major Nordic retailer needed to modernise an ageing certificate authority infrastructure.
We architected a PKI solution and led the migration of 40,000 certificates: HSM, CA hierarchy, policies and cutover planning.
A scalable, standards-based PKI platform with minimal disruption, and an end-of-life dependency retired.
Industry
An international pulp and paper company wanted to reduce AI regulatory risk and stop shadow AI.
An AI risk and approval process, technical blocks via secure service edge, and a change programme with communications and staff training.
Staff knew how AI may be used, and management got a handle on AI sprawl.
A gym equipment vendor wanted a CISO on tap and ISO 27001 certification.
An interim CISO who built a security roadmap (CIS Controls) and expanded it into an ISO 27001 programme, handing over to the company's newly hired CISO.
Certified on time.