CIO Analytics Logo

Statens IT: Preparedness in a World Without a Script

Statens IT carries a central part of the digital infrastructure of the Danish state - operating at the intersection of security and resilience in an era where the unpredictable has become the new normal.

8 oktober 2026

Covid. Drones. War in Europe. Critical incidents don’t follow a script, and that reality has fundamentally shaped the way Statens IT thinks about security.

“Many of the services we deliver reach many, many thousands of users. It has to be secure, but it  also has to be a service that makes their workday better,” says Charlotte Nielsen, Deputy Director at Statens IT.

Statens IT serves a broad and diverse customer base, from ministries handling GDPR-sensitive data to institutions where physical security is the defining concern. That demands differentiated solutions, not a one-size-fits-all model.

 

“It makes no sense to put seven locks on the front door while the back door stands wide open. It is about maintaining focus in the right places at all times.”

Charlotte Nielsen, Deputy Director, Statens IT

 

The customer base includes some of the most security-critical organizations in the country, and that attracts a certain type of professional.

“Demand for security competencies outstrips supply, and we feel that too. But I think we are in a somewhat privileged position. If security is your passion, you want to work somewhere where it truly matters. And it does with us.”

One thing Charlotte Nielsen holds on to above all is practice: you can only act quickly and correctly under pressure if you have done it before.

“If you need to do something fast and effectively, practice is the path to mastery. Time is a critically important parameter. And when we practice, we also gain new insight. We discover things we perhaps did not know we needed to know.”

Statens IT holds ISO certification and meets requirements for regular preparedness exercises, supplemented by its own internal exercises. The geopolitical threat landscape has sharpened the approach, and frameworks like NIS2 have done the same. Charlotte Nielsen doesn’t see it as a burden.

“Some people treat it as bureaucratic box-ticking. I don’t buy that. Regulation forces you to confront reality: Is something critical here, or is it not? The speed requirements exist for a reason. You have remarkably little time before things go seriously wrong.” 

“In reality, you're training for something you don't know the shape of yet. In the old days, it was a rigid, step-by-step plan. Now we work with components we can assemble in different ways, depending on what actually happens.”

For Charlotte Nielsen, the human dimension matters at least as much as the technical. At Statens IT, access to certain AI tools requires completing a training course first. A kind of license for digital tools. And subtle nudges in daily routines remind people to think before they act, for example, before an email reaches the wrong recipient.

“If you compromise usability to increase security, you end up in an even worse place. People find creative workarounds, and then you haven’t solved the problem.”

Looking ahead, knowing exactly where your data resides and what you actually commit to when choosing a platform will matter at least as much as traditional security.

“It is about asking the question: Where is my data? Am I okay with that? And am I aware of the decisions I make when I say yes to something?” says Charlotte Nielsen.

“We advocate for sharpening that awareness, within our own organization and among our customers.”