GRIDHEART // CEO QUIZ

    Do you know what the law requires before the attack happens?

    15 questions about what the CEO is personally accountable for once an IT incident is a fact - not the things the IT manager can take care of.

    GDPR

    EU General Data Protection Regulation (2018). Governs how you collect, store, share and erase personal data. Penalties up to EUR 20M or 4% of global turnover.

    Cybersecurity Act / NIS2

    Sweden's implementation of the NIS2 directive via the Cybersecurity Act (2026). Governs cybersecurity management, incident reporting and personal liability of leadership. Penalties up to EUR 10M or 2% of global turnover.

    Three rules for the test

    1. Answer first. Read the explanation afterwards. Otherwise you fool yourself.
    2. Be honest. This is not an exam, it is a map of where your company stands.
    3. Discuss the questions you cannot agree on with your IT manager or MSP. Those are your priorities.

    15 questions + 3 discussion scenarios. About 20 minutes.
    Answers and explanations are shown right after the test.

    10-12 out of 15 is a good result. Below 8 means concrete gaps to close.