Information security can often feel like trying to hit a moving target. Although it’s moving, it’s easier to hit if you know where it is. In a recent Hack & Tell podcast episode, we sat down with Peter Bostrom, CEO and co-founder of Nordic Information Control (NIC), to dissect the current state of data breaches, the myth of perimeter defense, and why knowing what data you hold is the single most critical step toward real security.
Peter’s path to founding NIC isn't your standard tech founder story. Growing up near the Arctic Circle in Sweden, he realized early on that life in the far north wasn't his calling. He began his career as a telecommunications officer in the Swedish Army during the 1990s, working with advanced military radios. He later transitioned into commercial sales and business development and worked all over the world including Southeast Asia, the Middle East, and Southern Europe.
That blend of military-grade comms understanding and global business development gave Peter a pragmatic view of technology. He realized that if you don't control the core asset i.e. the information itself, no amount of infrastructure will save you.
Now as CEO of NIC, he’s noticed the headlines about breaches coming out of Sweden (and across Europe) all follow a similar script.
We asked him why he thinks this keeps happening and he responded that it's rarely a deliberate cover-up. It's simply a pure lack of visibility.
For decades, cybersecurity relied on a simple analogy which was to build a heavy perimeter (the moat) around your internal servers (the castle). If you were able to keep the bad guys on the outside, everything on the inside stayed safe. But it’s not that simple anymore.
In the old world, servers sat in a basement where you could physically walk down and touch them. Today, data is scattered across hybrid clouds, SaaS platforms, external vendor environments, and local devices.
In our modern ecosystem, someone will eventually cross the moat. When they do, your defense comes down to whether your sensitive data is lying around in plain text or locked away in a safe room with explicit access controls.
To highlight how quickly control slips away, Peter walked us through a common scenario in modern workplaces:
Imagine you have a sensitive document stored in a secure, access-controlled system. An employee opens it in Word, edits it, and saves a copy. They email a draft to an external legal council (bouncing through multiple middle-tier mail servers). Then, they host an internal Microsoft Teams meeting and turn on an AI note-taker to summarize the discussion.
Result: You now have five copies of that sensitive information scattered across four unmonitored locations. Central IT usually knows about the original, but has zero knowledge of the other four.
Add "dark data", the legacy drives and forgotten archives sitting untouched for 10–20 years, and you have a massive, unmapped attack surface. In fact, NIC estimates that roughly one-third of the data most organizations store and back up is completely obsolete.
With frameworks like GDPR and NIS2 now in effect, many organizations approach security out of regulatory fear alone. The result is a rush to buy off-the-shelf training modules or write governance documents just to tick a compliance box with minimal effort.
While policies and training matter, they don't actively protect data while you're writing them.
Classification isn't the ultimate goal, it’s the enabler. Once you map and classify your data, you unlock better security, clear compliance audit trails, and immediate cloud storage cost savings by purging unused data.
At Aftra, we focus heavily on offensive security and hacker perspective external attack surface management (outside-in). Partnering with NIC (inside-out) creates a complete defense loop:
If you're watching recent breaches unfold and wondering where your organization stands, Peter offers some straightforward advice:
Want to hear the full conversation with Peter Böstrom, including deep dives into supply chain risks, vendor management, and real-world breach breakdowns?
Catch the full episode on Spotify or watch below on YouTube. Don't forget subscribe to the Hack and Tell podcast for more candid conversations with leaders across the security landscape.