forumNordic

Global Visibility for Nordic Innovations

The Cloud State – Rigorous Swedish Study Points Out the Challenges of Outsourcing Public Sector Data to the Cloud 

The Cloud State – Rigorous Swedish Study Points Out the Challenges of Outsourcing Public Sector Data to the Cloud 

The most revealing innovation in Sweden’s public-sector cloud transition is not the cloud. It is the administrative machinery now being forced to evolve around it.

On the surface, the study by M. Sirajul Islam and Fredrik Karlsson is a measured academic investigation of cloud-service procurement in Swedish public agencies and municipalities. It asks two practical questions: how public organisations use cloud services, and what information-security challenges they face when procuring them. Yet beneath those questions lies a more consequential story. Sweden’s decentralised public sector is not simply buying software, storage or computing capacity. It is being pushed into a new form of statecraft, one in which contracts, risk assessment, municipal autonomy, data location, supplier dependency and managerial competence become the real infrastructure of digital government.

The paper’s explicit findings are important enough. Three quarters of surveyed Swedish public-sector organisations had contracted cloud services. Municipalities were more likely than public agencies to have done so, with 88 per cent of municipalities reporting contracted cloud use compared with 63 per cent of agencies. Software as a Service dominated, while Platform as a Service appeared less frequently and Infrastructure as a Service remained marginal. The reasons for adoption were familiar: flexibility, cost savings, access to specialised IT resources, reduced need for installation and maintenance, and the ability to scale services as demand rose or fell.

But the hidden innovation is not in the technology stack. It is in the emerging governance stack.

Sweden’s cloud transition reveals a public sector trying to invent ways of operating inside a digital environment it does not fully control. Public organisations are learning to procure services whose technical architecture is often opaque, whose legal footprint may cross borders, whose terms are frequently supplier-driven, and whose failures may disrupt citizen-facing services. They are being asked to innovate not by building everything themselves, but by creating new capacities to judge, negotiate, monitor and govern what others build.

The article’s first conceptual image captures this puzzle: cloud challenges are grouped into contractual and legal, operational, and managerial competency dimensions. The model looks simple, but its implications are far-reaching. It suggests that public-sector innovation has shifted from the server room to the procurement office, from code to contracts, from administrative routines to organisational judgement.

A decentralised state meets a centralising technology

The Swedish context matters. Public administration in Sweden is divided between national agencies, regions and municipalities, with agencies and municipalities enjoying a high degree of autonomy. The national government has limited direct control over local government decisions. Joint decision-making is not imposed centrally, but negotiated through discussions, agreements and organisational choices.

This decentralised structure has long been considered a feature of Swedish public administration. In cloud procurement, however, it becomes a stress test. Cloud computing often centralises technical dependency in the hands of a small number of providers, some of them large international firms. Sweden’s governance model distributes decision-making across hundreds of bodies, while the cloud market concentrates operational power in external suppliers.

That tension is one of the most important hidden findings in the study. The Swedish public sector is innovating inside a structural mismatch. Autonomous municipalities and agencies must make their own cloud decisions, yet the consequences of those decisions may involve common national concerns: information security, personal data protection, public trust, service continuity and digital sovereignty.

This creates a distinctive innovation challenge. In a centralised system, government might develop a single cloud procurement framework, mandate approved providers and standardise legal controls. In Sweden, innovation must be distributed. Each public organisation needs enough competence to assess suppliers, interpret law, classify information, monitor contracts and understand risk. In other words, Sweden’s cloud innovation is not just technological diffusion. It is capability diffusion.

The paper reports that Sweden lacked centrally administered public or government cloud solutions, meaning that public organisations largely outsourced cloud services. At the same time, institutions such as the Swedish Civil Contingencies Agency, the Swedish Data Protection Authority and the Swedish Association of Local Authorities and Regions provided support, guidelines and coordination. This is not central command. It is a softer, more networked model of digital governance.

That model is innovative, but fragile. It depends on local competence. It assumes that procurement managers, information-security officers and organisational leaders can translate general guidance into concrete contract terms. The survey suggests that this assumption is only partly justified.

The quiet rise of procurement as innovation policy

The most striking hidden innovation in the paper is the transformation of procurement itself. In older administrative thinking, procurement is often treated as a back-office purchasing function. The cloud turns it into a strategic site of innovation policy.

A cloud contract does not merely buy a product. It defines who controls data, where information may be processed, how breaches are reported, whether audits are possible, how service interruption is handled, how liability is allocated, and whether the public organisation can exit the arrangement without being trapped by supplier lock-in.

The paper’s findings show that public-sector cloud contracts are often supplier-driven unless the services are mission-critical. That detail should make policymakers pause. If suppliers set the terms for ordinary cloud services, then the public sector may be adopting innovation on private-sector legal architecture. In that scenario, the real design of digital government is taking place inside contract templates.

The study’s Table 1 identifies the leading procurement challenges. Handling national security ranked highest. Procurement issues came next, followed by contract issues, supplier lock-in, laws applicable to cross-border cloud services, conflicting national laws, service comparisons, joint procurement and technical issues. The order is revealing. Technical problems are not absent, but they are not the dominant concern. The major obstacles are legal, contractual and managerial.

This is a crucial innovation insight. The bottleneck in public-sector cloud adoption is not primarily technological availability. It is institutional readiness. Sweden’s public bodies can buy cloud services, but the harder question is whether they can govern them.

When standardised contracts are not used, public organisations try to push a range of information-security requirements into agreements. These include ownership of information, national legal requirements, responsibility for data loss, encryption, physical security, penalties for service-level failure, redundant infrastructure, protection against malicious code, continuity planning, audit opportunities, rules for administrative staff, cross-border legal requirements and intellectual property claims.

This list looks like bureaucracy. It is actually a map of digital sovereignty in miniature. Every clause encodes a public value: accountability, continuity, privacy, legal certainty, resilience, recoverability and control. Procurement becomes the place where innovation is either made governable or allowed to drift.

The cloud as a sovereignty machine

Cloud adoption is often described in the language of efficiency: cheaper systems, faster deployment, scalable resources, easier maintenance. The Swedish study confirms that these motives are real. Greater flexibility was reported as the most common reason for adopting cloud services, followed by cost savings, access to IT resources and reduced installation and maintenance burdens.

The figure on reasons for cloud adoption makes the efficiency story visible. Yet the more interesting story begins where efficiency meets sovereignty.

Public-sector data is not ordinary data. It may include personal information, school records, welfare files, healthcare-related information, administrative decisions, case documents, public records and information linked to national security. Public organisations must balance openness and protection. Some public-sector data should be accessible. Other data must be shielded. Cloud services complicate that balance because data may be stored, processed or accessed through infrastructures that cross organisational and national boundaries.

The paper repeatedly notes concerns about national security, applicable cross-border laws, conflicting national laws and the location of data processing. Only 34 per cent of surveyed organisations always had contract information naming the countries where information was processed. In 44 per cent of organisations this was true only in some cases, while 8 per cent said the location was not mentioned in contracts and 13 per cent did not know.

That uncertainty is not a technical footnote. It is a governance alarm. If a public organisation does not reliably know where its information is processed, it may struggle to determine which legal regimes apply, what risks exist and how to respond to incidents. The cloud makes geography both less visible and more important.

The study found that, among respondents who provided location information, most cloud data processing was within the EU or EEA. Sweden accounted for an estimated 62 per cent of cloud services, followed by Ireland, the Netherlands, Norway, the United States, France, the United Kingdom and Germany. This national and European pattern likely reduces some legal complexity, but it does not eliminate the underlying problem: public-sector digital sovereignty now depends on contractual visibility into infrastructure geography.

Here lies another hidden innovation. Sweden’s public sector is developing a new geographic imagination of administration. Public managers must think not only about where a municipal office sits, or where a national agency is headquartered, but where data travels, where servers operate, where suppliers are incorporated, and which jurisdictions may touch public information.

Why municipalities matter more than they seem

One of the paper’s overlooked findings concerns municipalities. They are not peripheral actors in the story. In several respects, they are cloud adoption laboratories.

Municipalities in the survey were more likely than national agencies to have contracted cloud services. They also reported particularly varied use of cloud services in educational administration, learning platforms and pedagogical tools. The study notes that some municipalities faced pressure from schools that wanted to use digital classroom services, even when cloud use created legal or security concerns.

This deserves more attention than the paper gives it. Education appears to be a pathway through which cloud innovation enters local government. Schools need collaborative tools, learning-management systems and digital classroom functions. Suppliers increasingly deliver those functions through cloud-based models. Municipalities, responsible for local services, then become sites where public-sector cloud governance is tested under practical pressure.

The innovation here is not simply that schools use cloud services. It is that education becomes an accelerator of municipal digital transformation. The classroom pushes the municipality into procurement dilemmas that may later spread across other domains: data protection, supplier terms, service continuity, user identity, platform dependency and staff behaviour.

This is why municipalities’ concerns about confidentiality are especially interesting. The study found that municipalities appeared more concerned than agencies about compromising confidential information as a reason for not adopting cloud services. That may reflect the nature of local services, which often involve sensitive personal data and direct citizen interaction.

The figure on reasons for not adopting cloud services reveals the counterweight to enthusiasm. Loss of control over information, inability to meet legislation, compromised confidentiality and low organisational readiness were the leading barriers. These are not signs of backwardness. They are signs of public organisations trying to understand what responsible innovation requires.

In innovation policy, adoption is often treated as success. The Swedish case suggests that hesitation may also be intelligent. A municipality that slows cloud adoption because it cannot ensure lawful handling of sensitive information is not necessarily resisting innovation. It may be preserving the conditions under which innovation remains legitimate.

Shadow cloud and the innovation of everyday workaround

Another hidden innovation in the study is less comfortable: employees using non-procured or non-work-related cloud services to perform work tasks. The paper gives Dropbox as an example. Approximately 46 per cent of organisations reported such use to a certain or large extent, with the phenomenon more evident in municipalities than in agencies. A further 26 per cent of respondents did not know the extent of such use.

This is shadow IT in cloud form. But it is also a form of grassroots innovation.

When employees use non-procured cloud services, they may be trying to solve real problems: share files, collaborate quickly, bypass slow internal systems or meet service demands. Their behaviour signals unmet organisational needs. It shows where formal systems are too rigid, too slow or too poorly aligned with everyday work.

Yet the risks are obvious. Non-procured services may bypass security review, data classification, contractual safeguards, breach notification duties and audit rights. The organisation may not know where information is stored or whether personal data is being handled lawfully. What appears to be convenience at the employee level may become institutional exposure at the organisational level.

The hidden innovation challenge is therefore to convert workaround energy into governed capability. Public organisations must ask why employees turn to non-procured services and whether official systems fail to meet basic collaboration needs. Shadow cloud should not simply be suppressed. It should be studied as an early-warning system for organisational friction.

If nearly half of surveyed public organisations have some degree of non-procured cloud use, then the formal procurement system is not the only engine of digital transformation. Informal practice is also reshaping the public sector. The question is whether governance can catch up without killing the flexibility that made the workaround attractive in the first place.

Supplier-driven transformation

One of the most politically significant themes in the paper is supplier pressure.

The study reports that public organisations may sometimes have little choice but to use cloud alternatives because certain services are difficult or impossible to access otherwise. Suppliers push modern cloud-based services, and public managers may face a market in which the cloud is not one option among many, but the default delivery model.

This changes the meaning of innovation. In public-sector narratives, digital transformation is often presented as a strategic choice made by government. The Swedish study suggests a more ambiguous picture. Sometimes public organisations adopt cloud services because suppliers reshape the available market. Innovation arrives not only through public policy, but through vendor product strategy.

This supplier-driven model creates both opportunities and risks. On the positive side, vendors may offer more modern, scalable and maintained systems than public organisations could build alone. They may reduce the burden of legacy maintenance and give smaller municipalities access to specialised capabilities. On the negative side, supplier-driven contracts may reduce public leverage, limit customisation, increase lock-in and make public services dependent on private-sector roadmaps.

The study identifies 72 cloud service providers delivering more than 100 unique cloud services to Swedish public-sector organisations. The provider landscape included both small and large firms, with the top four appearing among major global software leaders. Only eight providers were shared between both agencies and municipalities.

That diversity is another underexplored innovation feature. Sweden’s public cloud ecosystem is not simply a story of a few hyperscale’s dominating everything. It includes a varied supplier ecology. But diversity does not automatically equal resilience. Many providers, many services and many contract types can increase complexity. Public organisations must be able to compare services, evaluate supplier histories, handle compliance and manage different contractual relationships.

In this sense, supplier diversity demands managerial sophistication. Without it, variety becomes noise.

SaaS as the administrative cloud

The study’s cloud-service pattern is clear: SaaS dominates. Among organisations with procured cloud services, 76 per cent used SaaS, compared with 35 per cent using PaaS and 9 per cent using IaaS. Municipalities used SaaS more frequently than agencies.

The figure on cloud outsourcing categories illustrates this hierarchy. This matters because SaaS is closest to everyday administrative work. It is where cloud adoption touches case management, document handling, customer relationship management, learning platforms, procurement systems, feedback tools, collaboration suites and productivity applications.

SaaS is therefore not just a technical category. It is the administrative surface of the cloud state.

If IaaS moves infrastructure and PaaS supports development environments, SaaS changes the software people use to run public services. It affects teachers, case workers, administrative staff, managers and citizens. It also shapes work routines, data flows and dependencies. Because SaaS is often delivered as a standardised product, it can bring efficiency while reducing local control over design and customisation.

The paper’s discussion of municipalities using SaaS for educational and administrative services suggests that public-sector innovation may be most consequential where it looks most mundane. A new learning platform, a cloud-based document system or a collaboration tool may seem less dramatic than artificial intelligence or national digital identity infrastructure. Yet these systems structure everyday public work. They determine how information is entered, shared, archived, accessed and protected.

The hidden innovation is an administrative migration. Public-sector work is moving from locally controlled systems into externally managed service environments. The state does not disappear. It logs in.

Information security as organisational literacy

The study’s most important empirical warning is that information-security risk is often managerial rather than purely technical.

When respondents were asked to identify the main information-security risks in cloud use, inadequate knowledge or awareness ranked highest, followed by service interruption, weak identity and access management, data breach, data loss, system or software vulnerability, targeted attacks, account hacking, malicious software, insecure APIs and shared technology problems.

This pattern matters. Cybersecurity discourse often gravitates towards attackers, vulnerabilities and malware. Those risks are real. But the Swedish public-sector managers surveyed placed inadequate knowledge and awareness at the top. That is a profound finding. It suggests that the first line of cloud security is not a firewall. It is comprehension.

One respondent’s view, paraphrased in the paper, is especially telling: IT itself was not the main problem. The deeper issue was managers’ maturity in taking responsibility for information management and information security.

This is the language of organisational literacy. Cloud governance requires managers to understand what information they hold, how sensitive it is, what legislation applies, what suppliers will do with it, what contract clauses matter, how incidents are reported, and how services can be audited. These are not niche skills for technical specialists alone. They are core public-management competencies.

The survey shows gaps. Only 25 per cent of respondents said their organisations always carried out systematic risk analysis before procurement. After procurement, 17 per cent always performed systematic risk analysis on a regular basis, while 60 per cent did so sometimes. Around one fifth said they never carried out such assessments either before or during procurement.

Supplier background checks were also uneven. Thirty-four per cent always considered contractors’ history when procuring cloud services, 36 per cent did so sometimes, 8 per cent never did, and 22 per cent were not aware of doing such checks.

These numbers describe a system in transition. Sweden’s public sector is adopting cloud services faster than it is institutionalising all the practices needed to govern them. That gap is where risk accumulates.

Audit rights, the accountability gap and the problem of trust

Trust is unavoidable in cloud computing. A public organisation cannot directly observe every operation inside a supplier’s infrastructure. It must rely on contracts, assurances, standards, audits, reporting duties and supplier relationships. The question is not whether to trust, but how to make trust accountable.

The study suggests that accountability mechanisms remain incomplete. Only 9 per cent of agencies and municipalities ensured that their contracts were regulated on the basis of international information-security standards such as ISO 27001 and ISO 27002. Forty-six per cent did so sometimes. Notably, 30 per cent of respondents who did not base contracts on such standards were unaware of them.

Breach notification was also inconsistent. Fifty-five per cent of respondents said suppliers were contractually bound to notify them about security incidents or malfunctions. The remainder either said no or did not know.

Auditing was similarly uneven. Seventeen per cent said agreements with cloud contractors were audited regularly, 27 per cent said sometimes, 27 per cent said never, and 29 per cent did not know whether auditing was included in their agreements.

This is a major finding. Public organisations may be placing data and services into external environments without consistently ensuring the right to inspect, verify or monitor supplier behaviour. That creates an accountability gap.

The hidden innovation opportunity is the development of audit-based cloud governance. Future public-sector cloud procurement may need to treat auditability as a core service feature, not a legal add-on. A cloud service that cannot be meaningfully audited may be unsuitable for sensitive public-sector use, no matter how attractive its functionality or price.

But audit rights alone are not enough. The paper notes that organisations also need the resources and competence to execute audits and evaluate whether suppliers deliver according to contracts. This distinction is crucial. A contractual right that an organisation cannot exercise is only symbolic control.

Incidents, interruptions and the resilience question

Most surveyed organisations reported no cloud-related incidents. Among those that did, the incidents were largely service disruptions. The study does not investigate the causes of these interruptions, but it links the issue to the core information-security concepts of confidentiality, integrity and availability.

Availability is often the least glamorous part of security, but in public administration it may be the most visible. A data breach can be severe and long-lasting, but a service outage can immediately stop work, delay citizen services and expose dependency. If a cloud-based system supports welfare processing, education administration, healthcare workflows or municipal communication, interruption becomes more than inconvenience. It becomes a public-service problem.

The hidden innovation here is resilience procurement. Public bodies must learn to buy not just functionality, but recoverability. They need to know how services fail, how quickly they can be restored, what backups exist, what happens if a supplier ceases operation, and whether the public organisation can access or migrate its data under stress.

Supplier lock-in ranked as the fourth most important procurement challenge in the survey. This is not merely commercial inconvenience. Lock-in can become a resilience risk. If an organisation depends on a supplier’s unique platform, data format or workflow model, leaving may be costly or technically difficult. In public-sector terms, that means dependency can become institutionalised.

One municipality respondent, paraphrased in the paper, contrasted the clarity of backing up data on one’s own servers with the uncertainty of knowing how backup and restoration would work when services are bought externally. That comment captures the emotional and operational shift of the cloud: public organisations gain convenience, but lose the reassuring visibility of local control.

The paradox of risk perception

The study reveals a subtle paradox. Many organisations adopt cloud services for flexibility and efficiency, yet nearly half of respondents believed reliance on external cloud services increases risk compared with their own IT operations.

This does not necessarily mean cloud adoption is irrational. It means public managers are making trade-offs. They may accept higher perceived risk in exchange for functionality, cost savings, scalability or access to services unavailable in non-cloud form. Innovation often proceeds through such bargains.

The more troubling issue is whether these bargains are explicit. Responsible innovation requires organisations to know what they are trading. If they understand risks, classify information properly, negotiate controls and plan for incidents, then cloud adoption can be a strategic decision. If they adopt because suppliers leave no alternative, employees create workarounds, or managers lack awareness, then innovation may become drift.

The paper’s findings suggest both patterns exist. Some organisations perform risk analysis, require encryption, specify data ownership, consider national laws and avoid outsourcing inappropriate information. Others lack awareness of standards, do not consistently audit contracts, do not always know where data is processed and may not know the extent of non-procured cloud use.

Sweden’s public-sector cloud transition is therefore not a single story of success or failure. It is a landscape of uneven maturity.

Hidden innovations in the study

The paper explicitly identifies cloud use, procurement challenges and information-security risks. But its deeper contribution is to reveal several innovations that are implied rather than named.

First, cloud readiness is emerging as a public-sector capability. It is not simply a decision to migrate systems. It includes risk analysis, information classification, contract literacy, supplier assessment, legal interpretation, audit capacity and incident response.

Second, procurement is becoming a strategic innovation function. In cloud services, contracts shape technological possibility, legal responsibility and public accountability. Procurement managers are no longer merely buying tools. They are designing the institutional conditions under which digital government operates.

Third, municipalities are becoming innovation laboratories. Their responsibilities in education and citizen services expose them early to cloud-based platforms, supplier pressure, confidentiality concerns and user-driven demand. Municipal cloud adoption deserves more analytical attention than national-level digital policy often grants it.

Fourth, supplier-driven innovation is reshaping public-sector agency. When certain services are difficult or impossible to access without cloud adoption, public organisations do not fully control the timing or form of digital transformation. Market architecture becomes public-administration architecture.

Fifth, shadow cloud use reveals unmet organisational needs. Non-procured cloud services are risky, but they also show where formal systems fail to support everyday work. Studying them can help public organisations design better governed tools.

Sixth, data-location awareness is becoming a new administrative competence. Knowing where information is processed is now part of lawful, secure and sovereign public management.

Seventh, auditability is becoming a core feature of public digital infrastructure. A service that cannot be audited may be functionally useful but institutionally weak.

Finally, managerial maturity is becoming cybersecurity infrastructure. The study’s ranking of inadequate knowledge and awareness as a leading information-security risk shows that security depends on organisational understanding, not only technical control.

What the Swedish case teaches

The Swedish case is especially valuable because it resists easy conclusions. It does not show a reckless public sector rushing blindly into the cloud. Nor does it show a fully mature system with all risks under control. It shows public organisations negotiating a difficult transition in real time.

The benefits are tangible. Cloud services offer flexibility, scalability, cost savings and access to specialised capabilities. They help organisations offload legacy burdens and obtain services that may otherwise be unavailable. For municipalities in particular, cloud-based SaaS appears to support a wide range of educational and administrative functions.

The risks are equally tangible. Public organisations may lose control over information, struggle with cross-border legal uncertainty, depend on supplier-driven contracts, face lock-in, lack audit rights, miss breach notifications, underestimate standards and rely on managers whose cloud-security competence is still developing.

The central lesson is that cloud adoption in government is not an IT project. It is an institutional transformation. It changes what public managers must know, what procurement must achieve, what legal teams must scrutinise, what employees are allowed to do, what suppliers must disclose and what citizens must trust.

In this sense, the paper’s most important contribution is diagnostic. It shows that the future of public-sector innovation will not be measured only by how many services move to the cloud. It will be measured by how well public organisations can govern the dependencies that cloud services create.

The story beneath the study

Read as a journal article, the paper is an exploratory study of Swedish cloud procurement and information-security challenges. Read as a feature story, it is about the state learning to live inside someone else’s machine.

The Swedish public sector is discovering that digital innovation does not always mean building new systems. Sometimes it means knowing how to ask better questions before signing a contract. Where will the data be processed? Which law applies? Who owns the information? What happens when the service fails? Can we audit the supplier? Can we leave? Do our managers understand the risk? Are employees already solving problems outside official systems?

These questions may seem procedural. They are democratic questions in administrative form.

A public cloud service may promise speed, flexibility and efficiency. But in government, efficiency is never the only value. Public institutions must also protect rights, preserve accountability, maintain continuity, follow law and retain public trust. The innovation challenge is to make cloud services compatible with those obligations.

Sweden’s experience suggests that the deepest cloud innovation is governance under dependency. The public sector is moving from ownership to orchestration, from infrastructure control to contractual control, from technical self-sufficiency to managed reliance. That transition may be necessary. It may even be beneficial. But it requires a new kind of administrative intelligence.

The cloud state is not built in data centres alone. It is built in procurement meetings, risk workshops, municipal guidelines, contract clauses, audit routines, information classifications and the judgement of managers who know that a cheap, flexible service may carry a sovereignty question inside it.

Source: (PDF) The Public Sector Cloud Service Procurement in Sweden: An Exploratory Study of Use and Information Security Challenges