Information control is your real defense strategy.

An interview with Peter Boström

author profile image by Marta Schluneger, Marketing Lead

Aug 13, 2026

#Podcast
Back to Blog
Person using computer in dark room


Information security can often feel like trying to hit a moving target. Although it’s moving, it’s easier to hit if you know where it is. In a recent Hack & Tell podcast episode, we sat down with Peter Bostrom, CEO and co-founder of Nordic Information Control (NIC), to dissect the current state of data breaches, the myth of perimeter defense, and why knowing what data you hold is the single most critical step toward real security.

From the Arctic Circle to global security

Peter’s path to founding NIC isn't your standard tech founder story. Growing up near the Arctic Circle in Sweden, he realized early on that life in the far north wasn't his calling. He began his career as a telecommunications officer in the Swedish Army during the 1990s, working with advanced military radios. He later transitioned into commercial sales and business development and worked all over the world including Southeast Asia, the Middle East, and Southern Europe.

"I was a lousy engineer. I didn't have the patience for it," Peter jokes. "So I ended up on the commercial side."

That blend of military-grade comms understanding and global business development gave Peter a pragmatic view of technology. He realized that if you don't control the core asset i.e. the information itself, no amount of infrastructure will save you.

Headshot of man on left with quote on right


The timeline of a modern data breach

Now as CEO of NIC, he’s noticed the headlines about breaches coming out of Sweden (and across Europe) all follow a similar script.

  1. Day 1: An organization experiences a breach via a third-party vendor or direct attack. They issue a quick statement: "We've been breached, but no sensitive or personal information (PII) was leaked."
  2. Week 3: A second press release drops: "We are still investigating, but it appears some data may have been accessed."
  3. Week 6: Sensitive files, personal records, and credentials surface for sale on the dark web.

We asked him why he thinks this keeps happening and he responded that it's rarely a deliberate cover-up. It's simply a pure lack of visibility.

"The truth is that organizations in square one simply do not know what was leaked at all," Peter explains. "Ninety-nine out of a hundred companies we meet do not have control over their information."

The "castle and moat" model is now obsolete

For decades, cybersecurity relied on a simple analogy which was to build a heavy perimeter (the moat) around your internal servers (the castle). If you were able to keep the bad guys on the outside, everything on the inside stayed safe. But it’s not that simple anymore.

In the old world, servers sat in a basement where you could physically walk down and touch them. Today, data is scattered across hybrid clouds, SaaS platforms, external vendor environments, and local devices.

In our modern ecosystem, someone will eventually cross the moat. When they do, your defense comes down to whether your sensitive data is lying around in plain text or locked away in a safe room with explicit access controls.

The rise of shadow data and "shadow AI"

To highlight how quickly control slips away, Peter walked us through a common scenario in modern workplaces:

Imagine you have a sensitive document stored in a secure, access-controlled system. An employee opens it in Word, edits it, and saves a copy. They email a draft to an external legal council (bouncing through multiple middle-tier mail servers). Then, they host an internal Microsoft Teams meeting and turn on an AI note-taker to summarize the discussion.

Result: You now have five copies of that sensitive information scattered across four unmonitored locations. Central IT usually knows about the original, but has zero knowledge of the other four.

Add "dark data", the legacy drives and forgotten archives sitting untouched for 10–20 years, and you have a massive, unmapped attack surface. In fact, NIC estimates that roughly one-third of the data most organizations store and back up is completely obsolete.

Compliance vs. safety: Stop ticking boxes

With frameworks like GDPR and NIS2 now in effect, many organizations approach security out of regulatory fear alone. The result is a rush to buy off-the-shelf training modules or write governance documents just to tick a compliance box with minimal effort.

While policies and training matter, they don't actively protect data while you're writing them.

Classification isn't the ultimate goal, it’s the enabler. Once you map and classify your data, you unlock better security, clear compliance audit trails, and immediate cloud storage cost savings by purging unused data.

How Aftra and NIC team up

At Aftra, we focus heavily on offensive security and hacker perspective external attack surface management (outside-in). Partnering with NIC (inside-out) creates a complete defense loop:

  • Inside-out (NIC): Identify, classify, and secure sensitive data where it lives, ensuring that even if a vendor or system is compromised, the data remains protected.
  • Outside-in (Aftra): Find and close external entry points, misconfigurations, supply-chain vectors, and human digital footprints before attackers can exploit them.

Practical steps for security leaders

If you're watching recent breaches unfold and wondering where your organization stands, Peter offers some straightforward advice:

  1. If you have a plan, stick to it. But run practical data control in parallel. Don't wait until all policy documents are written to start discovering what data you own.
  2. Classify early. You cannot protect what you don't know exists.
  3. Clean up dark data. Stop paying to store, backup, and migrate information you no longer need. Reducing your data footprint directly reduces your breach impact.

Listen to or watch the full episode

Want to hear the full conversation with Peter Böstrom, including deep dives into supply chain risks, vendor management, and real-world breach breakdowns?

Catch the full episode on Spotify or watch below on YouTube. Don't forget subscribe to the Hack and Tell podcast for more candid conversations with leaders across the security landscape.

 

Stay informed of the latest content and updates from Aftra.

Sign up to our monthly newsletter.