Case Studies & Success Stories

Real-world results from organisations that trusted Solvere Group to transform their operations and strengthen their security posture.

NIS 2 & Security Protection Act: Enterprise-Wide Compliance Programme
NIS 2 / CIR / Security Protection Global Industrial Group

NIS 2 & Security Protection Act: Enterprise-Wide Compliance Programme

A comprehensive security analysis and five-year implementation programme for a major industrial company with global presence — achieving full alignment with the EU NIS 2 Directive, CIR requirements, and the Swedish Security Protection Act.


A major industrial group with operations across multiple countries faced an urgent need to align with the EU NIS 2 Directive (2022/2555) and its Commission Implementing Regulation (CIR), while simultaneously meeting obligations under the Swedish Security Protection Act (2018:585). The organisation's existing security governance was fragmented across business units, lacked centralized oversight, and did not meet the heightened requirements for incident reporting, supply chain security, risk management, and board-level accountability introduced by NIS 2. Additionally, classified operations required dedicated controls under SÄPO guidance.

Solvere Group performed a total security analysis covering the full scope of NIS 2, CIR, and the Swedish Security Protection Act — mapping all operational, technical, and organisational gaps. Based on the findings, a detailed five-year implementation plan was developed covering governance restructuring, risk management frameworks, incident response capabilities, supply chain security controls, technical hardening, employee awareness programmes, and board reporting mechanisms. The plan was structured in phases — immediate quick wins, year-one foundational controls, and a progressive maturity roadmap through year five — with clear milestones, ownership assignments, and measurable KPIs.

Complete gap analysis across NIS 2, CIR, and Security Protection Act
Five-year phased implementation roadmap with prioritised actions
Governance restructuring with board-level security accountability
Incident response and reporting framework aligned with NIS 2 timelines
Supply chain risk management programme established
Ongoing advisory partnership for continuous compliance assurance
M365 Solutions for Defence Contractors
Cloud & Compliance Defence Industrial Base

M365 Solutions for Defence Contractors

A hybrid Microsoft 365 deployment achieving full NIST compliance while leveraging modern cloud efficiencies for a major Swedish defence contractor.


A defence contractor needed to modernize its workplace tools and adopt Microsoft 365, but faced strict regulatory requirements including NIST SP 800-171 compliance and data sovereignty obligations under Swedish law. Standard M365 deployments did not meet the classification and control requirements for handling defence-related information.

Solvere Group developed a unique hybrid approach — combining cloud-native Microsoft 365 capabilities with specific Swedish Microsoft commercial offerings and custom on-premises services. The implementation leveraged Data Loss Prevention (DLP), sensitivity labels, conditional access, and designated on-premises functions for classified workloads.

Full NIST SP 800-171 compliance achieved
Sensitive workloads isolated using dedicated on-premises services
Modern collaboration tools available to all staff
Data sovereignty ensured through a tailored hybrid architecture
Modern Workplace in Security-Protected Environment
Secure Workplace Government & Security

Modern Workplace in Security-Protected Environment

Delivering a user-friendly, modern workplace for security-sensitive operations — compliant with the Swedish Security Protection Act and SÄPO guidance for red environments.


An organisation handling security-sensitive information under the Swedish Security Protection Act (2018:585) needed a modern workplace solution that met SÄPO's strict guidance for red (highly classified) environments. The existing setup was outdated, difficult to maintain, and created friction for end users — while new solutions had to meet demanding requirements for access control, traceability, and information handling.

Solvere Group delivered a modern, user-friendly workplace solution with clear protective domains, strict access controls, full traceability, and controlled information handling — while keeping operational burden to a minimum. End users received a familiar, consistent experience using established tools and practices. Security requirements were met through standardized control mechanisms, system hardening, and customized on-premises functionality where required.

Full compliance with the Security Protection Act (2018:585)
SÄPO red environment guidance requirements met
Familiar end-user experience with minimal training needed
Reduced operational burden through standardized controls
CIS Controls Level 2: Review & Modernization
Compliance & Governance Professional Services

CIS Controls Level 2: Review & Modernization

A comprehensive CIS Controls Level 2 assessment and full modernization of governance, processes, and technical controls for a large consulting firm.


A large consulting firm needed to understand its current security maturity against CIS Controls Level 2 and modernize its governance, processes, and technical control environment. Key areas — including identity management, devices, logging, vulnerability management, and information classification — required significant uplift to meet client and regulatory expectations.

Solvere Group conducted a complete CIS Controls Level 2 assessment, including a detailed current-state analysis and a prioritized remediation roadmap. The team then led the implementation of enhanced security and compliance controls using Microsoft 365 as the primary platform — providing strategic advisory support, maturity improvement across key work practices, and a new classification model linking information value to practical protective measures.

Full CIS Controls Level 2 assessment completed
Prioritized remediation roadmap delivered and executed
Microsoft 365-based security controls implemented
Updated classification model linking data value to protection
Revolutionizing Legacy Processes
Digital Transformation Defence & Food Supply

Revolutionizing Legacy Processes

Replaced landlines and legacy payment systems with a fully automated digital platform — boosting sales by 200% and cutting carbon emissions.


Food vendors serving the defence industry were still relying on landlines and manual payment systems. Orders were slow, error-prone, and required significant staff overhead. The supply chain lacked visibility, and transport logistics were inefficient — driving up costs and carbon emissions.

Solvere Group designed and developed QFOOD.store — a complete digital ordering and payment platform tailored to the defence food supply chain. The system automates the entire order-to-delivery workflow, replacing manual processes with a modern, mobile-first interface backed by a robust cloud-hosted backend.

Sales increased by over 200% with the same staff count
End-to-end order automation — from placement to fulfilment
Transport needs reduced significantly, lowering carbon emissions
Vendors now operate efficiently with modern, scalable technology