Sectra AB (publ) (STO:SECT.B)
Sweden flag Sweden · Delayed Price · Currency is SEK
285.20
+7.20 (2.59%)
Sep 25, 2026, 5:29 PM CET
← View all transcripts

CMD 2019

Sep 26, 2019

Mats Franzén
CFO, Sectra

Welcome everybody to the Sectra Capital Markets Day with focus on cybersecurity. Before we go into the presentation of today's participants, I would like to inform you all for the benefit of your integrity that there will be photo sessions. If you do not want to participate in that, give us notice and we will attend to that request immediately. There will be one session later on in Swedish. If you do not command that language, there will be demos outside for you to delve into those issues. If you are not among the 10 million people out of said billions who doesn't command Swedish. Sorry. Today's presentations will be initially, goes without presentation, is the CEO of the Sectra Group, Torbjörn Kronander, and then please, Simo, who is the vice president of the group and head of the Sectra Secure Communications. Fredrik Sundström, wherever you are.

Always taking a corner position. Robert Lidquist.

Robert Lidquist
VP, Civil Authorities Customer Segment, Sectra Communications

Here.

Mats Franzén
CFO, Sectra

Happens also take a corner position and being a neighbor of mine almost. Lars Larsson, Also there. I can see a pattern here. Jonathan in the adjacent part of the room. From Sectra AB, as I said before, Torbjörn Kronander, myself, the Chief Financial Officer of the company, Helena Pettersson Iyer, outside scope. From MUST, Pia Gruvö. Without further ado, I would like to leave the table to Torbjörn.

Torbjörn Kronander
President and CEO, Sectra

All right. Thank you very much, and welcome here. As we said before, we are doing this a little different. Before we had Capital Markets Day for the entire company, but cybersecurity and medical, although more and more synergies in it, is quite different. We decided this year to have one Capital Markets Day for the medical side and another one for cybersecurity, and that is the one. This is a part B of that two days. Our main businesses, as you might know, is IT for medical imaging, which is about 85%, 90% of the company, and then cybersecurity, which is the rest, and today we will only speak about that part.

Then in our growth areas or our special efforts that we do outside the main business, we have one area in secure communications, and Lars Larsson will speak about that is protecting our critical infrastructure. We have built an incredibly sensitive society, small disturbances can be disastrous. That we work with as well. A little about markets. How do we choose our markets? How come we work in cybersecurity and medical IT far apart and seemingly, why on earth are you doing that in the same company? It's a good question. To be very honest, it's because my predecessor did cybersecurity, and I did the medical side, and we liked each other. That's not very rational, but that's how it came to be, to be honest. We see increasing synergies, and both are definitely growth markets.

The easiest way, when we choose markets to be in, and we have also the startups, is the market should be big enough for us to grow. If we don't think we could reach SEK 1 billion in turnover within some reasonable timeframe, we shouldn't do it. We are that size now. We cannot run around with markets that will end up with SEK 100 million. It's too small. Profitable growth is also much easier in a growing market. You can be on a steady state market, and then you end up fighting on price in the end of it. While in a growth market, you can be as good as the other one or a little better, but you will grow with the market. Both cybersecurity and healthcare is rapidly growing, and I'll come back to what the drivers for the growth are.

Ideal growth markets also have external pressure that makes them grow. It's not only I took an e-scooter here. That's a growth market, but you can have alternatives, and January is not a good idea. It will be a steady market, and there is no external pressure on it. While cybersecurity and medical both have external pressures, they have to grow. Society must invest in these areas, and that will make them grow disregarding the financial temperature of the markets, et cetera. They have to grow. We have to take care of the demographic situation that cannot be 100% of GDP going to healthcare. Healthcare must be more effective, and society must protect itself against cybersecurity or cybercriminals. Healthcare and cybersecurity worlds are in rapid change as well.

As one of our very early board members, Gunnar Rensch, once minted, "Where there's change, there is margin." You just need to be fast enough. A little bit of philosophy about customers. In medical, we have won the most happy customers in the U.S. for large hospitals six years in a row. That has made us in a position would have been almost literally impossible to reach without that award, because that amount of marketing you cannot pay for. That means we are growing rapidly in the U.S. market right now as for medical. It's been a little more difficult in cybersecurity. Some of the customers, we are not even allowed to know who they are, and that is very difficult to find in quality stuff. We have some measures as well to increase quality.

What happens with encryption, if it's not good quality, it will not be used. I know an admiral from my days in the Navy, he simply said, "If it's not easy to use, I will not use it." That is very true. We have to make it simple to use, and it has to be high quality. You have to trust it. Not only that it's safe encryption that we had for a long time, but it has to be easy to use and must work when I need it. We are going there with encryption as well. We are gradually getting more and more happy customers, even though there is no class that measures it. One of the smartest things we did was actually we are forcing everyone in communications to use our own secure phones.

When developers use things themselves, all of a sudden miracles happen with quality on these systems. That's eat your own dog food principle. We have to use it ourselves, and then it will be better if not someone else. Quality is profitable. For us, a very important thing also in cybersecurity is to listen to people using it, even though sometimes we're not allowed to talk to them. In that case, the representatives or the people we know who uses it, and we want to hear, "Yeah, this works better than our normal phones or normal laptops." Otherwise, we've failed because it will not be used. The users of these devices, they will go into what in Swedish called [Foreign language]. That means, you know the thing we discussed yesterday, the thing that begins with a P and ends with an R?

That's how they do. Going into something that is so easy to use, you don't see it. That's where we're going in cybersecurity as well. That's a big change, though. We're doing it. We'll take the questions afterwards if that's okay, because we have a mic. Just remember it and raise your hand when we have questions at the very end. How do you build competitive advantage long term? You who have been to marketing schools, you have the Four Ps. You remember them? I will not check you out. Product, product solves what it's supposed to solve. Promotion, need marketing. Customers need to know about you in order to buy it. Place, are you in the place where people need to buy it, to sell it? Price, that's the Four Ps you learn in business school.

I would add two to that, and we do that also medical. Process. If you don't have a process and everyone does handle in a process, you cannot collectively learn. You have to follow process. You have the development processes. If you do one product, you need to do in the same way in the next product. You improve, and everyone improves as well. Process is super important. Most important, people. If you have the wrong people, you will not succeed. We spend a lot of efforts in finding the best people we can find. Actually, I spend a substantial amount of that myself. We have at least three interviews with new candidates. We still, despite it's difficult to find people, we say no to a very large amount of people. For everyone we recruit, we say no to about 10.

I personally interview every single one as the last interview, which is kind of nuts. You have people say, "You do that? You're almost 1,000 people." And I say, "What more important thing can I do? What is more important getting the right people on the ship? Nothing." It's very strange that other CEOs doesn't do it. Because if you get the right people on the ship, you cannot fail. I can be a lousy manager, and guess what? Sometimes I am. It will work anyways. If you have the wrong people, I can be the best manager on the planet, it will not work. So we spend a lot of time to get the right people on the ship. A little about shareholders, and then we run with culture a lot, but I will not go through that.

As for shareholders, we have the view that if you have happy customers, if you have happy employees, reasonable cost control. We don't stay in Hiltons, we don't go business class. It's too expensive. A rational long-term strategy in a growing markets, and that growing markets is important, shareholders will be happy. It will almost impossible to avoid it. I think over the last six years, we've done okay in the stock market and with this philosophy. Shareholders must understand you're lowest on the list, because if the other things doesn't work, you will be losing in the end anyways. It's only short term if you take shareholders on the top. A little about cybersecurity. What drives the market in cybersecurity? Well, these guys do.

We have an increasing tension that is disturbing, especially for all of Europe, because after the Iron Curtain fell down, we thought, "Oh, it will be nice, and everyone will be kind forever." Well, didn't work out like that, really. Well, we don't know yet, but definitely we have a build-up on the eastern side that is heavy, and tensions increase all over the world. Now it's not only the people next door who are aggressive, it's people sitting on the other side of the planet, because on the internet here, there is no borders. That's one part that drives the market. Tension's going up, nervousness is going up, and people want to protect their secrets. This is news from last week. Example of synergies. 32 million patient records breached in the first half of 2019. 32 million medical records, and some of them are sensitive.

The fines in the U.S., a fine for leaking this, because Americans run everything by money, right? They actually fine you if you leak as a provider hospital, and the top fine for a hospital losing one medical record for one patient is $25,000. 25,000 times 32 million is a heck of a lot of money. That creates a lot of interest in the healthcare industry to protect against leakage. Despite that, 32 million patient records leaked. We have increasing synergies, especially beneficial for the medical side that we have cybersecurity in-house. There was also news last week, and there was also a new technique in computer screen that it was like 350 million X-ray images.

They are not as sensitive as the medical records as a whole, but still, you might have some disease you don't want to be out there in your X-rays available on the network. This is FRA, which is a security side in Sweden as well. IT spies are preparing for attacks on the grid, the electrical supply. If you want to attack a country today, you don't need tanks. Shut off the electricity in Stockholm two weeks in February and wait. We have built a very sensitive society. If you can sit remote on the other side of the planet and shut down electricity in a country, we're in trouble. That's what we do in critical infrastructure. Yet another one, WannaCry 2017, there was a massive attack. You see this in banks, I'm just taking examples from medical now.

In the U.K., there was a terrorist in the U.K. who drove a car over London Bridge. He killed seven people, and it was big news all over the world. This virus, or it's not a virus, it was a Trojan, entered the NHS, went inside the firewalls, covered up as a PDF, looked exactly as a normal PDF sent out by the NHS, but it had active content. People clicked on it, let loose a Trojan inside, or worm, actually, to be really frank, a worm inside the firewalls, and that began to spread in between the computer in a known hole. This was published by Microsoft three months earlier. A problem, SMB, which is a file-sharing protocol.

Went from operating system to operating system, so we were not responsible for the operating system, but it more or less shut down the entire U.K. as for elective surgery and healthcare. Only the acute things could work. Now, that worm killed thousands of people. We just don't know how many. The entire U.K. healthcare was shut down for a week, except very urgent things. These are serious stuff. The cost couldn't even be measured, almost not measured. The problem areas we address in cybersecurity is, of course, wiretapping, which is one concern. We are all wiretapped today. Either when we do things on Facebook, because it's all recorded. I once wrote a message to a friend, "You want to play squash?" You think this messenger is not monitored? Well, it is. Same on Gmail.

If you use Gmail and write, "You want to play squash tonight?" It's recorded somewhere, and I get squash advertisements for the next four weeks. Buy this new racket because they record us. Also, if you have things at home and the phones, you cannot really trust you're not wiretapped, both from nation levels, but also from privacy levels. Individual companies, nations and society and companies are all wiretapped. It's an ugly game. Everyone looks. They can try to listen to everyone else. Our most critical infrastructure, again, is controlled by IT. It needs protection. If you get into a power plant, the Americans have shown, if you get into a power plant, the large generators, there might be some engineers here, they are all the rotor and the stator in a big generator are controlled by computers. They are synchronized with the entire country.

The 50 hertz grid is synchronous in Sweden. All of these generators are on that 50 hertz synchronous mode. If you just move the phase of the rotor or stator, one of them, just like a 10th of degree, that big generator is fighting all the other generators of the country, and it will explode. You can get inside with IT and make a generator in Porjus, for instance, in Sweden, explode. Physically explode. It's as effective as throwing in 50 kilos of dynamite. Those things take weeks. Not weeks. Weeks to order and years to install a new one. You can physically kill a power plant by getting in through IT. Serious stuff. We do our part there and do our best to secure those networks.

They have very thick steel doors, but they are not as good as our team, as they are in very advanced locks and steel. Everything goes mobile. We see that. We want to do everything mobile today. That includes authorities, it definitely includes politicians. The old days when you could have a protected network of three or four things on a network, and you saw the cable, that red cable was visible for everyone because as a rule, if sensitive, you cannot have the cable not visible anywhere, and everything was locked in. Those days are gone. Everyone want to be mobile. Everyone want to have a secure mobile workplace, doing everything they can do in the office, in the laptop. Now, if you want a secure environment working that you have to secure those mobile workplaces. We used to be doing only phones.

We are moving into doing entire mobile workplaces because that is where the future is. We want to raise these to very high secrecy levels now. You guys, for instance, can write about things you know that the other guys here shouldn't know. You're absolutely certain. Not absolutely certain, but very certain, with high probability no one can listen in. Security must be super simple, as I said before. If it's complex to use, if it's a lot of key management and stuff, people won't use it. You fool yourself in a very dangerous way. If you provide very secure things, but people are not using it because it's too difficult to use, that's fake security. That's worse than no security at all, almost. These are the four areas we are solving. Software solutions can be cracked.

That's another thing I'd like to point out. A terrorist in California two years ago had an iPhone. FBI, CIA, everyone to crack it. They were not able to. After three trials with that six-pin number, the phone erased itself. The ones who solved it was the Israelis. The Israelis actually cracked it by taking the entire software, running a supercomputer cluster, and installing the software on that cluster. They emulated an iPhone, but in software. How do you crack it? Well, you try. Brute force. Zero, zero, zero. Didn't work. Zero, zero, zero, one. Zero, zero, two. Boom. Telephone erased. Guess what? You have everything in software. You download a new one, and they crack the phone. This changed their entire mentality because anything on software can be cracked now. Anything. All secrets.

In all secrecy encryption, there is some parts you don't want to be exposed. No software solution is safe. We do the high level, we do in hardware, and we are good at that. We do also in these smartphones, we have a little chip. That only will take three attempts, and then it will go like in "Mission Impossible," boom. That's one of our key strengths. We do things in hardware when it's really important. I'll end up with some financials. That's what's all about really. Some excerpts from our Q1. In communications, we actually acquired a company, a Swedish company called Columbitech, who has a VPN on level 4. I will not go through exactly what that is. Robert will mention it. It's a very good VPN. Exactly the VPN used in the nuclear submarines in the U.S.

Not with encryption we have. Motorola licensed it, but it's the one that is used because they have a lot of interrupted communications with these guys. Order bookings for the group were fine last quarter, but this is mainly medical that rose there. Financial targets for the groups, we have three: stability, profitability, and growth in that order. Unfortunately, for the first time in a long time, we were below on the growth target, but we hope to get that up. We're in heavy investments right now in the medical side because of the large orders, and we had to take cost up. That will last for about two quarters, and the last two quarters of this year we'll be better off getting some financial benefits of that. That's something. We are not fulfilling all three targets right now, but we're getting there. What about communications?

Communications grew not enough. That's not the growth area, so we have to work with that. A little more important, it was combined with actually less growth in profits. That's our communications area. That's not good enough. We have to get this grown. That's why we have these new areas, so critical infrastructure, secure mobile workplaces, and that is the efforts to get communications in the growth trajectory where they should be in this market. Communications does not contribute to our financial goals, but it's good opportunity for growth and margin improvement in the future. We are investment in critical infrastructure and authorized or authorities enterprise segments, and the growth initiatives, critical infrastructure, mobile secure ecosystems, and new geographic areas. With the acquisition of Columbitech, we actually open up communications and security in the U.S. Still small, but one of the largest operators use our VPNs.

Sprint has our VPN as their VPN when they sell to customers. This is how communications develop. Of course, we want that to go up here. Summary. All critical functions in modern society is controlled by IT. Modern terrorists, cyber mafia, aggressive nations will target it. Society must protect itself. Legislation increases, investment will go up. We are growing in the growth market. As exactly we want, it's growing by external pressure. It has to grow. Cybersecurity markets are set up for large growth. Sectra is active in the key areas of critical infrastructure, high-speed network encryption, more or less we only do with the Swedish authorities, and high quality, high security mobile workplaces. That will be the norm of the future. People will not use phones. Well, voice is just one kind of data. That's an introduction where we are. Any questions?

Fredrik Egrelius
Analyst, If P&C Insurance

Fredrik Egrelius from If P&C Insurance. You talked about secure communications not really contributing to earnings, of course, now you are investing in growth in critical infrastructure and other growth opportunities. I guess we'll hear more from Simo about that. Looking at your legacy business, where the lion part of your sales is within this division, you more or less made no money between 2012 and 2016. As I understand it also, these customers sort of limits or puts boundaries on where you can grow and what verticals and in what geographies. That balance, is it worth having those customers still around? How do you see the, yeah, you need to increase your margins or grasp the opportunities in a better way, I guess.

Torbjörn Kronander
President and CEO, Sectra

You're right. We have to increase our profitability or we have to do something else. The way we've done it doesn't work. We believe in this area, and we'll try a little more before we take some actions because as it is today, I assure you are one of our biggest shareholders, right? We can't sustain it. We need to get profitability up and growth up. Otherwise, we have to do something else. We have very smart people, and they can do a lot of things. Let's try it a little more before we change. Any other questions?

Speaker 10

Hello. Yeah. You mentioned your own encrypted phones. Could you just briefly explain the major differences between your phones and regular iPhones or just what's the main differences?

Torbjörn Kronander
President and CEO, Sectra

Well, there is two kind of phones, and you will hear that later. There's secret level phones. We build them entirely ourselves. They cannot be a smartphone because you don't control the operating system. It cannot be really safe. We build that phones, and they are quite different, I guarantee you.

Speaker 10

Yeah.

Torbjörn Kronander
President and CEO, Sectra

We have our Restricted level phones, which is a lower level. We have a chip that is secret, and it cannot be tampered. It can never be cracked in the way they cracked the iPhone.

iPhones cannot have a chip in it. There is no place to put it. It's very difficult, close to impossible to make an iPhone or a software-based system at the security levels we do even our RESTRICTED levels.

Speaker 10

Okay.

Mats Franzén
CFO, Sectra

Okay then.

Torbjörn Kronander
President and CEO, Sectra

All right. Thank you very much.

Mats Franzén
CFO, Sectra

Give the word to the Vice President and the man in charge of this very area we're now discussing, Mr. Simo Pykälistö.

Simo Pykälistö
President, Sectra Communications

Nice to see you so many here. There's a big interest for the cybersecurity. I will start, and I will talk a little bit about what is our role and what is our focus and what we are really trying to do in the large field of cybersecurity. We can't do everything. I'm trying to put some context what we're actually doing. Picture of myself. No need to mention other things, but I've been here since more than 16 years with Sectra, in different roles. I promised to be 3 years, and now it's on the 17th year. Let's see how many years to come. Really good company to work with. Who we are at Communications. Torbjörn didn't talk too much about the history. Company is more than 40 years old.

If you think in the field of cybersecurity, we've been actually doing something in the cybersecurity more than 40 years. I think we can be really proud of that. If you mention also regarding the knowledge and the brand, we are quite known in certain places. Not widely known in the cybersecurity, but we are quite known in the field that we are doing. From the defense, actually starting from the banking sector, which I guess many of you represent here. We're doing the bank automatic teller security in the '80s. That's where we started. Then crypto defense, then going into the smartphone and the critical infrastructure. I come back to that a little bit what more we are doing and what is the aim with that. Moving a little bit into different segments now.

What we do, basically, we divide first a little bit on the three different areas. We have the traditional communication systems for National Security, and with that we mean the defense and the military, and those that are mostly like Fredrik was asking, regulating a little bit also what we are doing. Good and bad, but regulate a little bit what we are doing. Really high security, and that's where our actually foundation is. The people, the smartest people that we have, whatever we do in the other areas, that's where the foundation acts, actually the smart people come from. We should always keep that in mind. In the security solutions and the critical infrastructure, that is the newest part. That's where we are trying to secure. We concentrate mostly on the OT, not so much on the IT.

They are connected. We need to handle that. The operational technology and the SCADA systems, they are actually the ICS and the PLCs and controlling the factories. That's what we want to secure. That's where the bad things happen if something gets in there. Secure mobile solutions for authorities and enterprise. We're also doing it here. Now also we have a focus and concentration on actually doing that for the enterprise, including medical. Torbjörn mentioned there are more and more synergies. Yes, there are. We also already have medical customers, which I think is really exciting and also when we are now going to U.S. A little bit of products. I'm not going to go through all the products that we are doing.

We have Lars and Fredrik and Robert talking a little bit later, so they will talk more what exactly and how do we solve the problems with these products on the different areas. One, what we could say or I want to say is really important here, the services and recurring revenue. You see that Sectra as a whole, has quite big jumps back and forth between the quarters. Of course, the platform and the recurring revenues, even the communications, it's really important we get higher and higher every year so that we have a balance in that rather than doing start and stop projects and development only. That's not what we want to live for. We will do that, but we want to complement the traditional business with also the services and recurring revenue. That's important to get and the balance over the time.

Little bit of the customer, like I was mentioning. We have been working with the EU, NATO, different governments throughout already more than 20 years in Europe. In Sweden, more than 40 years. Even throughout Europe and NATO. NATO, we actually got it first, and we had a press release a year ago, a little bit, I think about a year ago. We are actually now delivering our Sectra products through the Dutch Sectra phone, actually to NATO. That is really exciting and of course, as European countries, there's as many NATO countries in the world that actually we can be targeting. Actually, what we could say in here also is that they're all very demanding customers. That also means that we need to be really smart in whatever we are doing. They don't accept failure. Torbjörn mentioned also quality.

There's no quality. Quality failure is not accepted. You are kicked out right away if it doesn't work. Also, more than half of the EU member states are our customers. We have EU frame agreement, and that's what we want to continue with. The long-term relationships and agreements, same thing with NATO and whatever the customers are. I think like in the medical also, we have more 10-year contracts or even more. If they come and they become a customer, they most likely stay. Otherwise, we have, I think, failed. We need to keep the customer. They most likely will stay. They don't change the systems every year or even in five years. It's more the 7-10-year terms and the development, what we do. But now it's not only, when we go into different segments, it's not only defense and military.

There's also civil defense in Sweden, MSB contingency agencies, and the similar agencies in other countries. Basically, we see, and Pia will talk more about the security law, but in Sweden, it's the same thing and trend happening in other European countries that the market actually is maybe 10 times bigger or becoming 10 times bigger than it was before. Before, the systems were actually only directed to military and defense, but now it's actually the whole civil authorities, which are considered to be critical security in the governments. Also the industry and critical infrastructure. They are regulated, not as much as military and defense, but they are regulated and also by law. More important, it will start being more that we are part of the business development in these companies and when we do work.

Business continuity and operational efficiency are becoming more important rather than just selling products. Where are we going? A few words. Torbjörn also mentioned a little bit about trends and drivers. Digitalization, mobility, and automatization. Of course, that everybody knows. If you're not digitalizing, even in the banking sector, everybody needs to be digitalized. Who is the most digital and most efficient, then they are winning the game. That's where we see the security also becoming more and more an issue. How do we secure the things when people are doing everything remotely and from their home rather than going into the stores or banks or wherever? New geopolitical threats, need for cooperation. I think this we see more and more. The threat landscape in Europe, the most of the countries have basically the same threat landscape.

You had the Russian tank on the Red Square or wherever that was. That's basically the threat landscape. There are other ones too, but Europe, as a common, we see the most countries as the same. You need the cooperation. There's not one country, I think, in Europe that can do everything on their own. You need cooperation, you need trusted partners. That includes the cooperation need. Post-quantum, if that will happen, how it will happen, or when it will happen, Jonathan will talk a little bit more about it. I'm going a little bit more in detail, but there definitely will be something. If somebody would already have done something, we probably would have known if the Chinese would have done that already. I think we need to do something, we need to solve the issue.

I think that's why it's really important we concentrate our focus on research, even within communications, so we are in the forefront of whatever will happen. Increased degree of interconnectivity and complexity. Just an example with the power plants. Lasse will talk more about that, but they are being built 50 years back, and they have been adding systems since 50 years. Every system they add, they're not necessarily taking away another one, they're just adding something. Of course, you think there are more than probably 100 service people running into the plants and doing things. Of course, the security is quite huge. They charge their phones on their normal computers or at work. There are a lot of issues with that, and connectivity and complexity. We will need to solve the issue that how do we in mobility actually solve that.

What are we doing? Focusing. Focus on core competence. We can't do everything. That's absolutely so. This Sectra has always been very good focusing things which we are very good at, and we will continue focusing. We have said, and we put the growth areas where exactly what we think that we can be best at, not that we are the third or fourth or something. We want to be best at whatever we are doing. Third-party integration, that goes through the whole communications. Before we have done development projects quite a lot, and we had done a specialized crypto, and on our own. On the new areas and even on the traditional area, we need to be better in the partnerships and also used in third-party products.

Then you're too focused on one thing, and it's impossible to grow. Organize for customer influence. That also ties a little bit the same thing. More what is the customer needs and what is the solution that they need together with the partnerships rather than, "This is the product. You need to have this." It might be in some cases that, but it can't be only that. What is actually the customer, listen to the customers. Grow segments where outer influence lower. Not that we will take that away, absolutely not, but it's that they will complement each other. Also, as I say, getting more recurring revenue and also recurring profits that how we can grow and complement this together.

Basically, one goes a little bit more even, and the other one, of course, will grow and be growth and stable over time, but it's bigger cycles. The segments what we are focusing on National Security I already mentioned. It's a lot of legal requirements, of course, and that is the base. We go more into Civil Authorities enterprise, including healthcare. It's more the security awareness. They need to be secure, and they have a lot of legal regulations also, but especially the efficiency. When we talk about the roaming or the policeman you see here, it needs to work and it cannot stop. If it stops, it needs to pick up again really soon, otherwise the bad guys will run away. You need to be able to do that efficient way. Operational continuity and Critical Infrastructure.

That's especially, Torbjörn was showing also the examples of, and you will hear more from Lasse too, how much does it cost per minute, per hour, per week if something breaks down? It's millions and millions and millions. We need to be part of the business continuation there. What we are doing, a little bit geographic focus. We have had the Scandinavia and the Northern Europe, and of course, Netherlands is our very important, let's say, like a second home country, and where we work very closely with, and the whole Europe. Of course, with U.S. office, I think that's also tied very much to the medical sector that together with Columbitech and the resources in U.S., we see a very good advantage and a possibility there. Partnerships, I mentioned.

Third-party products and partnerships, really important that we can't do everything our own, and we actually working with that. We could also mention the Columbitech actually has been our partner, I don't remember the year, but I think five, six years, they've been our partner. We actually been using their VPN solution already partially and developed that further in our products. Now they became, that's wholly owned by Sectra. I think that's a good example how we want to work with. It's complementing our organic growth. Robert will also come back a little bit more in the details, but we got the better VPN offering and also the software solutions rather than just only on the hardware, even if that's important in the more secure segments, coming more with the services and recurring revenue.

That's all that is the aim that we will come more to the recurring revenue. Security market. You've seen a lot of pictures. I'm sure that there's a lot of research. This is just one research, and it will grow by this source. I think all the research what I read, it says 10% to 15% annual average growth over next five to six, seven years. That's nothing new. Of course, our aim is we need to grow at least that, otherwise we're not really doing our job really well. We can't be worse than the average. If you look at where actually the growth is most, energy, healthcare, public sector, airspace, defense, those are exactly the sectors that we are very good at. I see a good opportunity actually targeting and continuing with the sectors where we are.

How do we do it? I just wanted to show this. You read the book, and you've probably seen the book in some of our earlier presentations. Dan Brown had his Sectra Tiger XS named in the book, and we didn't pay a dime for that. He actually found us because our brand, and he did research. There's actually another book if you want to read, if you're interested and read. It's in Dutch, but Dutch is almost like Swedish, so it says something about security and spies and all that. It came out last week, and when he did research, he's quite famous journalist in Netherlands. He did research. He, of course, mentioned special Tiger telephone and the ministries and AIVD and all those different places.

It's quite interesting, actually. What I understand that some of the Dutch government officials actually didn't want that this book came out because they still don't know really where did you find all that out. I think it's an interesting book. I don't know if it's in English yet, you should read it. Anyway, what I want to say with this, I think the brand is where the base is. That's what we want to use. Not just having in the books, also in reality. National Security, as I said, collaboration and the crisis preparedness. When there's some crisis in some European country or there's a hostage situation or something, we see a lot of interest to Sectra. We know actually that some of the incidents are handled or the communication is handled with our products.

Civil authorities, besides that it has to be secure, operational efficiency is absolutely the most important and then needs to work all the time, mobility, wherever it is. If it's a doctor, a policeman or whatever it is, you cannot stop the system and okay, then they go back to pen and paper rather than using the product. The energy, especially the business development, when they are digitizing their processes and their work, we have been there and those customers that we have doing the consultation first and helping them with the architecture and security awareness, then all the way that actually step by step becoming on the totally higher level on the security. I think that's really interesting. That's really long-term. It's quite people resource intensive in the beginning, which it's good and bad.

It's not that profitable, but that's needed to do to have the security operations center 24/7 and those customers in long-term, where we have long-term contracts. Not the least, the incident management. That makes the whole loop actually in what we are doing with the customers. Actually now we are working, Lasse will come back to that a little bit, on even an example with the insurance companies that we actually pay to do the incident management. They call Sectra rather than somebody else, and that's a special agreement what we have, so that we actually handle the incident and send people there when something happens. Okay, I think that was my last slide. Questions? Yes.

Speaker 10

Just to understand, when you work, for instance, in energy project.

Simo Pykälistö
President, Sectra Communications

Yes.

Speaker 10

Just what I learned basically. What's the difference in your project versus high-end security consultant project, for instance, the Tietoevry or anyone?

Simo Pykälistö
President, Sectra Communications

Yeah. Us.

Speaker 10

Yes. Different levels.

Simo Pykälistö
President, Sectra Communications

The IT and OT, if it's operational technology or that's the difference. I think we are concentrated on really the factory and the processes. Like you said, let's say same thing. We couldn't even sell in a medical if we didn't understand the doctor's process. We really could understand the overall and the process. That's the difference. A lot of times when they do a security, if you look at the other competitors, when they do a security analysis or a security consultation, they are much more on the higher level, more computers and IT, and okay, then they touch something maybe on the OT level. We come from the other side.

Speaker 10

Yeah.

Simo Pykälistö
President, Sectra Communications

We talk about the SCADA networks and actually the PLCs and how do you control that, and then securing that part.

Speaker 10

Yeah.

Simo Pykälistö
President, Sectra Communications

We use, of course, in our work the solutions that, okay, how do you differentiate those two different levels? I think we come a little bit from the different angles a lot of times.

Speaker 10

What competitors are there on the OT level?

Simo Pykälistö
President, Sectra Communications

There are several competitors that do actually what we see mostly they do systems.

Speaker 10

Yeah.

Simo Pykälistö
President, Sectra Communications

You can find OT security surveillance systems if you Google that, for example. You will find probably five, six different suppliers. The difference with that is that you introduce the system and you monitor yourself, your own system.

Speaker 10

Yeah.

Simo Pykälistö
President, Sectra Communications

We don't do that. Lasse will talk more about that, but we actually are pulling information and securing and monitoring the system from outside with our crypto techniques and products and surveillance systems. It's a totally different thing. Basically, if you're doing it your own, you're basically introducing a security threat to your system yourself.

Speaker 10

Yeah.

Simo Pykälistö
President, Sectra Communications

I think there's a totally different angle what we are doing. In that place, we are unique.

Speaker 10

All the other players are doing their own systems?

Simo Pykälistö
President, Sectra Communications

Not all, but most of them. I think there might be some, but the crypto techniques that we are doing the information are not introducing anything the other way. I think we are unique in that one. Now we come to Jonathan. Now it's into the rabbit hole. What happens if and when quantum computers become a reality? How is the world to handle this?

Jonathan Jogenfors
Research Director, Secure Communications, Sectra

My slides are coming up soon. Thank you Mats for the introduction, and thank you, Pia, for the introduction. Over to post-quantum cryptography, which will be the topic that I will be talking about. Just quickly about myself. I am an information security expert, computer hacker who went to the academic field and got a PhD in quantum cryptography, before joining Sectra about two years ago. I've been working with quantum cryptography and working with information security. I'm also an expert in Bitcoin and cryptocurrencies. I run a consulting firm in this field. I've been working with law enforcements, and I've been very active in Swedish courts as an expert witness in testimonies regarding cryptocurrencies and narcotics smuggling and related areas. Thank you. Now I have my slides back.

We don't do blockchains and cryptocurrencies at Sectra, luckily, but we do a lot of work with the fields I'm working with today. I also work as a post-doctoral researcher at Linköping University in parallel with my work at Sectra, and I represent the research department at Sectra Communications. As Pia talked about before, cryptography is paramount for security. There are three things we talk about, especially in security, that are important to achieve. We have confidentiality. In Swedish, we call it sekretess. We have integrity. In Swedish, the best word to use is riktighet, and availability. You, of course, know about confidentiality, the need to keep things secret, especially about your customers. Now, with GDPR, if you don't do confidentiality within your organization, you will be fined a very large fine.

In integrity, if the data is not correctly sent or correctly authenticated, say that you make a transaction on your bank and someone, like a hacker, adds an extra zero to your transaction amount, that would be pretty bad. Integrity is also something we achieve with cryptography by making sure the data that you sent is the same data that is received on the other end. Availability is the third leg on which information security stands. Things need to be available when you need them. If your banking system fails and you can't do trades for a minute or for an hour or for a week, that would be terrible. All these things we do achieve with cryptography. Good cryptography, we need high-quality cryptography. If you can't trust your cryptography, you can't trust your information security, and your business will fail.

How long do you need to keep your data safe? As we just heard in the long-term security spectrum, we need to keep data safe up to 95 years. If we encrypt some very sensitive information, we encrypt Plan B. Redundancy is important in security. Availability, as we said. It's important to have backups. If something fails, you need to have a threat model that takes care of all possible scenarios. Long-term security, even if we have something extremely sensitive, if we have a good cryptosystem, we can encrypt this information, and then we take the encrypted information and can send it on a postcard to Vladimir Putin, and it should still be secure for 70 or 95 years. That's how good our security and cryptography needs to be. I'll be talking about a new threat that's coming up on the horizon, that is quantum computers.

Quantum computers will have a profound effect on cryptography in the medium to long-term future. You might not need to keep your data safe for 70 years, but in the commercial sector, we usually talk about 30 years of security. Of course, if your security fails, you might violate the GDPR, and it can be very expensive for many organizations, not only in Sweden but also in Europe. Quantum computer can come soon. How long do we have, or how long does it take to migrate to a new cryptosystem that is safe against the quantum computer? Could it be today, in 0 years? In some of the very high assurance systems, we are already safe. For most of us, we need to think about how long time do we have to migrate to new systems, and it can take years.

We learned this in the '90s. It can take decades to develop and fully implement new safe cryptosystems. The question we need to ask ourselves is, if we have a security horizon of, say, 30 years, we need to keep the information secure for 30 years, and then we also have a long deployment time for our new cryptosystems. How long time does this take until a quantum computer arrives? If a quantum computer arrives in, say, 10 years, that's an optimistic example, but 20 years. If that is shorter than the time it takes for us to deploy a new system before we can use it, and the time we need to secure information, we will have a problem. This is not just relevant for defense or national security. It's also relevant for critical systems like energy sectors or finance.

Even though quantum computers are still a bit away in time, we need to start thinking about it. Quantum computers are pretty strange. They work on information in a completely different way than we do today. They don't just do single bits of zeros and ones. They do superpositions of bits where it can be zero and one at the same time. They can do some amazing operations on these qubits or quantum bits. The question is, how long do we have until they come? Well, we are roughly at stage 3 or 4 in this seven-step process that has been discussed for the past few years in the quantum computing sector. A normal computer uses many bits, and if a quantum computer wants to do something important, it needs to do many quantum bits. This is not easy. It takes time.

We can do some very, very basic operations now, but for the future, for quantum computing, we have some really, really difficult steps to achieve before we're here. A good estimate from Michele Mosca, who is leading the Institute for Quantum Computing at the University of Waterloo, in his opinion, it's about one in six chance that we will have a working quantum computer within a decade, and this prediction is two years old. He also says we have a 50% chance of a quantum computer existing within 15 years. Now, I would say that Michele is quite optimistic here. I'm more pessimistic, and I will say, well, maybe 20 years away. Still, it's within our lifetime. This could very much happen. We need to take the appropriate steps to secure our information.

Just the other day, Google, who's working a lot with quantum computers, apparently published or leaked some information that they are actually building a working quantum computer. This quantum computer is now proven to be better than a normal computer. This computer can do tasks that takes 3 minutes, that would, for a normal computer, take 10,000 years. We're now in the post-quantum era, where quantum computers are better than our normal computers. With that said, this new result is amazing, but still, it's a very impractical computer. It can only do one specific problem that is just made to show that this computer is faster. It cannot do anything useful for us. If you run this computer, you have just 1 in 1 million chance that it will produce the correct answer.

You run this difficult quantum computer, it gives you some kind of result. You can't really verify it because it will take you, a normal computer, 10,000 years to check it. I would say it's a good metaphor to think about the first airplane, the Wright Flyers. They flew maybe 100 meters or something. It wasn't very practical to use. If you try to sell that one to someone, they will say, "I don't need this," which is true. The Wright Flyer, just as this quantum computer, is the first in many steps to a working quantum computer, to a future where quantum computers can be a reality. Why is this important? Well, quantum attacks can happen today. Let's say you're the Chinese. You can record our secret encrypted communication. We send a lot of data over the web today, but hard drives are cheap.

Buying a new computer with big storage is very cheap. A nation-state attacker, like the Americans or the Chinese, can record everything we do encrypted. It's just garbage right now, just random ones and zeros, but they store it on a big supercomputer. Then they can wait. Wait 10 years, 20 years, not a problem. Then if they get a quantum computer by then, they can break the communications and decrypt what was said. Things you say today can be recorded and can be cracked later. If you're in defense, you might need to have a 95-year security horizon. Then you really need to make sure that every kind of technological development within these 95 years does not affect the security of your information. Now we know that this is happening. The Americans are doing it, and probably the Chinese and probably the Russians, too.

What will happen when a quantum computer does exist? For the defense, it will probably not happen too much because, as we said, we are mostly secure in the secret domain already. For the rest of us, for the finance sector, for the critical infrastructures of our society, it's back to the dark ages of crypto. You see a locked briefcase with, what's it called, handklovar. That's how we did key management before we had good cryptographic algorithms. You basically sent couriers with new cryptographic key materials to your other end. This is really expensive. It's just information security for the very rich people. We cannot do this on our phones anymore because the phone today negotiates the new cryptographic key with the other party.

If you go to your app to check on your bank account, it will do a cryptographic handshake that will no longer work. It's back really to the dark ages of cryptography. Also, these types of cryptosystems that we need, they're quite easy to screw up. It's much more difficult for a computer programmer to sit down and write the secure software now if the systems are broken. It's hard to audit. It's hard to tell that it's secure or not. Of course, we at Sectra, we know how to do cryptosystems, we can do these things. For the normal guy, normal developer, it's very easy to screw up. I want to show you some few slides. These are just big numbers. Look here, this is a prime number. It's hard for you to check, but trust me, it's a prime number.

This is also a prime number. Now I can tell you to multiply these numbers. It's easier than you think. You learned this in elementary school. You just write it down on pen and paper. You can do it in a few minutes. It's not difficult. You get the product, which is an even larger number. Okay. Now let's say I just gave you the large numbers and you don't know these smaller factors. Now I tell you, show me the prime numbers that I multiplied together. This is more or less impossible. It's very difficult for any computer, except for a quantum computer, to do this kind of thing. It's called a trapdoor function, and this is what we base some of our modern cryptosystems on. It was an amazing discovery back in the 1970s that it could actually do this.

It's very fast to do the encryption, very difficult to crack it, basically. This is the basis for the software called RSA. The problem, of course, is that a quantum computer can do this operation very fast. It can crack RSA, it can crack other similar methods like Diffie-Hellman or elliptic curves. We need to do something else. As I said, RSA is an amazing discovery. To make new safer primitives for cryptosystems, it will require amazing discoveries again in mathematics. For instance, you can do something called lattices. We do vectors in some big abstract vector space. Don't worry, there's no test on this. You don't need to study. We need new trapdoor functions. Really deep-level academic research is needed to make our new system secure. It's nothing that we can just spend a few years on an engineering level.

We need to really delve into deep academic thinking. There's a big process now going on in the United States, but also in the whole world. It's led by the United States. NIST is the National Institute of Standards and Technology, and they're now working on a big process to standardize, to together come up with new cryptographic methods that will withstand quantum attacks. Right now they have 26 algorithms that are advancing to the semifinals. You use cryptographic methods today that was selected by NIST about 20 years ago, things that we assume to work every day. We really will need these methods to work in the future, so we really depend on academics coming together and inventing new cryptographic methods for use in the future. I also forgot to show you, this is an image of a quantum computer, how it looks today.

We have these qubits, these physical qubits that are superconducting things, uses something called transmons. It's very high-grade physical research. This whole thing is then sunk into a bottle. As I said, superconducting means it needs to be very cold. You have to chill this down to about 100 millikelvin. You go down to the absolute zero temperature and just go a tenth of a Celsius above it. That's how cold you need to have your quantum computer so that it actually works. There's some extreme technological difficulties in making a quantum computer work, and I think quantum computers are still quite far away since we have such a difficult time making them. Still, we, as the defenders, need to make sure that when they come, or if they come, we need to be secure, and that development can come quickly.

We won't have any time to prepare unless we start right now. We need good fundamental and good applied research. A quote again from the director of the Institute for Quantum Computing, "Post-quantum cryptography also requires a wide range of research from fundamental studies," that is mathematics and physics, "of the resistance to quantum attacks, to studies of their efficiencies." How can we make them under difficult resource constraints? How can we make sure they resist so-called side-channel attacks? We need at Sectra to make this work, and we need a good research department. Post-quantum cryptography is possible. For instance, a few years ago, Google Chrome, I guess most of you have seen Google Chrome or use it, they did an experimental study to see, can we make a web browser quantum secure?

While it was quite difficult, the report says we did not find any unexpected impediment to developing something or deploying something like NewHope, which is a post-quantum safe cryptography method. There were no reported problems caused by enabling it. The technology is possible. There's a roadmap for it. We can do it. We just need a lot of work and a lot of expertise to make it happen. One of the big hurdles for us who defend against cryptographic attacks is that these new cryptosystems are difficult in a way that new cryptosystems can be broken in some unknown way. There might be some hidden flaw we don't know about. Not that anyone has put it in there, just that mathematics is difficult.

We have a problem where our current or pre-quantum systems are broken by a quantum computer, and the new post-quantum systems, on the other hand, can have unknown flaws. How do we do then? Well, we do something called a hybrid cryptosystem. We combine the best of the two worlds. We use pre-quantum security and post-quantum security together in a so-called hybrid. Okay, I know it's an electric car, but it's a better image than the Prius. We make it into a hybrid cryptosystem that takes the best of both worlds. This is also in the frontier of academic research. Nothing that is available right now, but it needs to be done in the right way. What is Sectra's role in post-quantum cryptography? First thing, post-quantum cryptography or PQC is a high priority for Sectra.

Our customers want it, we want to deliver to them. In the future, say 10, 15 years, also on the restricted side and lower-grade security will also need post-quantum resistance. Now, we are first movers at Sectra in a very rapidly moving field. Those 26 cryptographic algorithms that we see in the previous slide, might be one or two in the future, might be none of them, might have to be something else. It's a moving target. We're working hard to stay ahead. We are the right people to do it. As I said, customers will need the quantum-safe technology, maybe not today, but in the near future. As the technology matures, we will strive to be ahead. I'm proud to say we have a strong academic focus as head of the research department.

We're working closely together with universities, Linköping University and Lund University, and others. As a summary, we need post-quantum cryptography to stay secure in the future. We have challenges. These new algorithms, they are of lower performance. You want to have your phone running the same way as today. You don't want it to be obvious to you that you use some kind of new cryptography. We need it to be transparent. We need it to be usable and easy to deploy. We have higher power consumption with these new methods. How can we make a mobile phone run a heavy algorithm without draining the battery? Also uncharted waters. There will be unknown unknowns coming to us in the future in the post-quantum field. This is a disruptive field. We know we have challenges.

We are the right people to do it, and we have to act now to be prepared. Okay, that was a short summary of some of the challenges and problems facing in the quantum world. I'm happy to take some questions.

Mats Franzén
CFO, Sectra

Thank you, Jonathan, for disrupting us a bit. Do we have any questions from the audience?

Speaker 10

Maybe you said it, I missed some bit, but when will quantum come? What time frame?

Jonathan Jogenfors
Research Director, Secure Communications, Sectra

I quoted Michele Mosca, and he said one in six chance in a decade and 50% chance in, was it 15 years? I think the time frame is longer.

Speaker 10

Okay.

Jonathan Jogenfors
Research Director, Secure Communications, Sectra

I think we are further away from this, but the problem is not really when they come. The problem is it takes a long time for us to switch cryptosystems.

Speaker 10

Yeah.

Jonathan Jogenfors
Research Director, Secure Communications, Sectra

It takes a long time, even if we record something today, we want it to stay secure in, say, 30 years' time or 10 years' time maybe if we have low-grade security requirements.

Speaker 10

Sure.

Jonathan Jogenfors
Research Director, Secure Communications, Sectra

We cannot really wait with development. Development needs to start right away. Even though for the commercial sector, I would say post-quantum cryptography is of lesser importance than some other issues facing them right now, it's really important that we keep track of it.

Speaker 10

Okay. What hurdles need to be solved in order for you to think, like, okay, this was a big step?

Jonathan Jogenfors
Research Director, Secure Communications, Sectra

Yes. We need to, for instance, agree which cryptosystems to use together with our cooperating authorities and also to make sure everyone in the industry agrees on the same system. As I said, 26 different methods. We need to choose one of them.

Speaker 10

Yeah.

Jonathan Jogenfors
Research Director, Secure Communications, Sectra

Performance is difficult. We need to make it run fast. You need to make it run on a phone with power constraints. You don't want to drain your battery just to send one text message. That would be absurd. That's the situation we're in right now.

Speaker 10

Within quantum computing, what do you need to see in order to?

Jonathan Jogenfors
Research Director, Secure Communications, Sectra

All right. Okay, you're asking about what do we need to make a quantum computer run today?

Speaker 10

Yeah. What needs to happen in order for you to think or see that now it's a big leap?

Jonathan Jogenfors
Research Director, Secure Communications, Sectra

Yes.

Speaker 10

Now we see something happens.

Jonathan Jogenfors
Research Director, Secure Communications, Sectra

The Google quantum computer I was talking about has 53 qubits, 53 quantum bits. To be able to run, say, the algorithm that can crack RSA, that can crack cryptography, you need hundreds or thousands of qubits. The problem is these qubits are very noisy. They don't do the thing you need to do. You need to do error correction, which needs 1,000 times more bits. Logically, we're thinking about maybe a million qubits are required to run a decent size algorithms. Going from 53 to a million is a major, we need to have breakthroughs in this technology.

Speaker 10

Such as?

Jonathan Jogenfors
Research Director, Secure Communications, Sectra

Right now, if you run a quantum computer, any kind of noise will destroy it. If you just nudge one of the qubits, everything is destroyed.

Speaker 10

Okay.

Jonathan Jogenfors
Research Director, Secure Communications, Sectra

Which is a difficulty that we don't have in normal computers, and need to scale it up from 53 to 1 million, running at almost absolute zero temperature without any kind of disruption or vibration destroying it.

Speaker 10

Okay.

Jonathan Jogenfors
Research Director, Secure Communications, Sectra

The major technological challenge is in this field. Sir?

Mats Franzén
CFO, Sectra

We had one here in the back first.

Jonathan Jogenfors
Research Director, Secure Communications, Sectra

Oh, sorry. Hi.

Tobias Welin
Analyst, Soman Funder

Hi. Tobias Welin, [Soman Funder]. How about the resources? If you compare your resources at Sectra and with a Chinese military or whatever, is there any point in you guys trying to fix this, or could you elaborate something about that question?

Jonathan Jogenfors
Research Director, Secure Communications, Sectra

Oh, sure. As I said, some products are already secure on the highest levels of domain. You just heard about it from the previous speaker also. Yeah, we can do it for sure. We have candidate algorithms. We just need to make them run better.

Speaker 10

There is a popular belief, whether it's pre-quantum or post-quantum, that if you have a crypto that is going to be used in the United States, you will have to deliver the crypto key to NSA or any other securities organization. Is that a truth, or is it just a popular belief?

Jonathan Jogenfors
Research Director, Secure Communications, Sectra

You're talking about something called escrow, that in some jurisdictions, you need to send your cryptographic key to the authorities before legally being able to encrypt your information. I don't think that's true today, because today we can do high-grade encryption, even using our normal web browser on our computer. It used to be true in the '90s, during the so-called Crypto Wars, but I'm pretty certain that this is no longer the case.

Mats Franzén
CFO, Sectra

Any more questions so far? There is always a backdoor to every security system, and in Sweden, it's called the fika. For now, there will be such an event, obviously, to keep the brains and minds running. At that time, there will also be demonstrations. Don't rush, because there will be a second set of demonstrations at 12 o'clock as well. You can delve into the details one at a time. Off we go.

Jonathan Jogenfors
Research Director, Secure Communications, Sectra

11 o'clock.

Mats Franzén
CFO, Sectra

Welcome back. I hope you enjoyed the fika and the demonstration as far as it goes. There will be, as I said before the break, a second session. As always, where there is change, there is margin. We have made some changes and compressing of the agenda, which means that we will now head on for the rest of the program. Then following that, at around 12:00, there will be some sandwiches and an opportunity to see further demonstrations and some Q&A with the management at your discretion. On the theme of minor changes in the program, now we do not start with what you believe would be 11:00, Robert, who will be later on, but on the other hand, National Security, headed by Fredrik Sundström.

Fredrik Sundström
VP, National Security Customer Segment, Sectra Communications

Thank you. Hi, everybody. My name is Fredrik Sundström. Can you hear me, everybody? Perfect. We will start now to dig into the different kinds of business areas that we are working with. I will talk about national security. I would say that, as Simo mentioned in the beginning, this is the kind of traditional area where Sectra Communications has been working for three decades or something like that. We started with the Swedish defense in the 1990s, or something like that, doing encryption algorithms, after that, developing different kinds of products using those encryption algorithms. That's the kind of starting point of secure communications, I would say. As I said, Fredrik Sundström, responsible for national security. I've been working at Sectra since 2001, reaching 20 years soon.

I would say 20 years is a long time, but it's very easy to stay with Sectra and work there since the people who work there are so engaged in what they do. It's so interesting to work there. Maybe due to what the management do in recruiting, maybe due to skills, I don't know, but it's a very interesting place to work. I have a Masters of Science from Linköping as my background, and this is my first job, actually. For the area of national security, what is the common factor that all of them need to apply to? This comes back to what Pia said before. All of them are required by legal requirements to do things, to handle and to exchange information. Everything they do needs to have approved products. Approving products, that's what MUST and Pia and her organization do.

There is also international organizations like NSM in Norway. We have NBV in the Netherlands, CSG in U.K. We have BSI in Germany and so forth. All of those are focusing on approving products to a certain level. You saw this before. There is a range of levels that you approve products for, and depending on time and consequence of leakage of information, you will require different kinds of levels here. Also, I would like to mention not just time and consequence, but also depending on the potential threats, the environment where you use the products will affect the kind of level you would have for your products. We have been doing this for quite a long time, of course with Sweden, but also international authorities. We know for sure what it takes to approve a product and to follow regulatory requirements that comes with these kinds of improvements.

For Sweden, 30 years, we've done it with the Dutch authorities for 10, 15 years. We have products approved for EU level and also since some time, also for NATO levels. What does the customer actually want? Who's the opponent, what they want to protect themselves from? To your right, it's criminal organizations. Well, not actually. Those are out for stealing things. They are very short-term. They don't care if you notice that they've been there. That's not actually what you're protecting yourself from. Youngsters trying to hack themselves into systems, maybe from time to time. Again, if they succeed, they typically are quite happy of doing it and will announce it, so you know that they've been there. The most dangerous part is the left one here that should represent state actors.

Those are professionals with extensive amount of time, money, resources, technology, and very skilled with what they're doing. They are trying to gain information, steal business intelligence, state secrets, miscredit, or spread disinformation in different kinds of ways. Always they want to do it without being noticed. That's a big difference between those. For those customers we are working for, they are all trying to avoid this. Those areas will be addressed later on with Lasse and Robert, I would say. What do they need then? We talked about security, usability, and availability, those three things is a difficult combination to find. The biggest threat, I would say, is usability. It's very difficult to get this in a usable way. To make something very secure, I would say it's quite easy. Buy yourself a big safe, throw away the key.

It's not that usable. You can't share that kind of information. What we're doing here is finding this very fine balance between availability, usability, and security. From a security perspective, Jonathan mentioned it before, you require a few sets of functions to mitigate the state actor interests. You need to make sure that you are authenticated. You are you. Compare yourself by the cash machines. You will enter a pin code to verify that you are you. We talked about integrity or riktighet, as we said in Sweden. You don't want to have another extra zero in the transaction of money. That would be bad. The third one being confidentiality or encrypted information. That is what we are trying to give to our customers. Taking a bit more from our perspective, what markets are we active in? Of course, Sweden, that's our home market.

That's where we've been active for 30 years, and we will continue to be active there. Another main market is the Netherlands. We have very close cooperation with them. The third one is Norway. Also looking into the European Union, we are active in approximately 50% of the nations being present. Either by the Dutch company or direct from Linköping. Who's the typical customer? I'd say the first sector is, of course, easy to understand. Defense organizations, typically. Swedish defense, of course. Norwegian defense and the Dutch defense. We are also more and more working together with civil authorities. These ones being Swedish, Regeringskansliet or Utrikesdepartementet. Swedish Civil Contingencies Agency, MSB. We are also seeing more and more active dialogue with different kinds of Ministry of Defense and Ministry of Interior Affairs in several countries around Europe. The third part is different kinds of organizations and operations.

We have since quite long a framework together with the European Union. We are supplying communications equipment for all the ministers. We have an agreement together with the EEAS, that's a part of the European Union. They are supplying equipment to external actions within the European organization. We have since one year working together with NATO, European parts of NATO, supplying products there. We are also quite active within civil companies, for instance, Saab in Sweden. What do we do for those customers? First of all, we have the Sectra Tiger ecosystem. That's the most famous product I would say we have. That's a broad range of products. The most known one is the secure mobile phone. This is approved to secret level. It's a proprietary hardware solution that we built. It supports different kinds of networks.

You can use it in fixed line, you can use it in GSM mode, you can use it over satellite links and so forth. It's also possible to use this one and connect to lower security levels on RESTRICTED level with an ordinary phone. Robert will talk a bit more about that later on. This is the product that is most present in Europe, and we work on the international arena. Network encryption. This is moving big data from one point to another. Possible to look at this kind of products outside here later on if you want to. This is developed in Sweden and used in Sweden.

I would say an interesting product to look forward when it comes to the new rules and legislations that Pia talked about that was present from 2019 in April. Third part that we are working a lot with for all products is support and maintenance. All products are sold as a package with a maintenance program, that is of quite big importance since most of them contain software that needs to be updated from security perspective. We work with it quite often, quite close with our customers, making sure that everything is secure. Do we think that there is any growth potential in this area? I don't know if you saw it, last week it was published on the government homepage. There is a decision to rebuild the total defense within Swedish authorities.

Försvarsdepartementet decided to add some SEK 5 billion extra per year, the next coming five years to support this. Also mentioned by Pia, this will cover a lot of signal which is what we're doing. We see the same trend in many European countries. There is extra monies added for their budgets for the years to come to take care of the increased cybersecurity threats. We have very good frameworks with both European Union, EEAS, and NATO organizations. I think we could expand on those and make them even more fruitful than they are today. Finally, also, I would say some of our products, it's only the TIGER product and the TIGER system today that is actually introduced on a European market. We have more things to do there. We have more things that we can introduce within the European Union.

We are today supported by Swedish authorities to actually go in that direction, which is good. Last, I would like to point out here, this is the Dutch minister, Mark Rutte. He is using one of our products. This is a Sectra Tiger phone. He used that through a service agreement we have established in the Netherlands called FACOM, which provide Dutch authorities and ministers with communications equipment, both for communicating speech, transfer data, and for fax installations, both on secret and restricted levels. They use it between ministers and between defense organizations. I think today we have some 200 subscribers or something for this area. All right.

Mats Franzén
CFO, Sectra

Those who are about to listen to the next segment, Sectra mobile workplace and smartphones. Now we move from the Dutch Ministry of Affairs to a more mundane arena, but another segment nonetheless. Robert.

Robert Lidquist
VP, Civil Authorities Customer Segment, Sectra Communications

My name is Robert Lidquist. I have been working at Sectra for 16 years. I had the same idea as Simo. We started almost the same day, three maximum five years. If you meet super talented people every morning when you come to work, you tend to want to go there tomorrow. I think for me, it's very important the purpose of what you're doing, trying to help out in the society. I have been stuck here. I worked at 10 years or so, Tiger ecosystem. I was responsible for that for 10 years, that's been a really interesting journey, too, with EU, NATO, and so on. That's a really interesting journey.

My task now is if you look at those high-end from national security is like Formula One, where we're taking those components and those competence and packages for a broader audience. That's what we will talk about, the mobile smartphones and the mobile workplace. If we look at the risk factors here, Internet is wonderful, but it's also like having criminals just next to your door. You can do attacks from a student room in Moscow or whatever in the world. I mean, it's like this. You can redo the attack, you know the phishing mails and those companies working with 300 people in India just trying to get one phish. Fully paid 300 persons in one company. There are big risk, but we need internet, we need our connections, we need the transport. Of course, it's here. It's not a [Foreign language]fluga.

Also, all the services we have, we need the services. Everything is digitalized and will be digitalized, that makes a big threat. If you have information as your bank vault, all your information is money in some way, we need to protect the servers are like the vault, I would say. Also the personal integrity. You probably heard about the news the last months about collecting your data, selling it off. That's also very valuable and it doesn't feel very well. So that's a reality. We know that. We need this tool, the phone, of course, we need it in work, we need it in defense, we need it at different operations. How do we mitigate the risks? There are a lot of cybersecurity companies today. Probably you've done some research.

A lot of them do just a component, just a thing here, just a thing there. That comes from our heritage in the national security, looking at the real threat. We always look at the threat. What is the level we need to reach? We look at the organization needs to be aware, the training of the organization, the device needs to be secure, and if you lose the device, the access to the device needs to be secure, and the application framework needs to be secure. Then, of course, the connection to your vault, to all your money, your information needs to be secure. On top of that, you have the service. What do you want to do? Open a door with your phone, transaction or so on. This is how we look at security.

Is it too complicated? No. Very simple. Can I use this one? Yeah. What we have done, we have packaged this technology into a mobile workplace, and I think one very important goal of this design, it should be easy to do the right thing and hard to do wrong. This is your tool that replaces the laptop. I have it myself. As Torbjörn talked about, the dog food is excellent from a roaming perspective, I will come into that. This is the sort of the offering we have if you look at the material we deliver. How we build this app is from bottom up. Our experts and Samsung experts worked since 2014 on something called Knox Framework to really make sure that the device itself is secure. We have also mechanism to protect data if there's some data stored on the device.

We recommend to do more sort of your private cloud or on-premise cloud, your own bank vault. There are also something that not shown in this picture. Torbjörn talked about some extra cards that we put in, and that's to prevent from state actors. You know all what state actors is? Like a foreign country. China, Russia, trying to get in to steal your IPRs or your information. That's some extra we do for those critical customers. To something. Yeah, let's use this. Our VPN. This is a really critical component, and that's the connection in the pyramid. This is really fantastic technology, I will say. It's the patent solution from the acquirement of Columbitech. The patent is, yeah, it's very complicated if you look at all the schematics and so on, but what it does is make sure that your connection is always up.

If you switch between Wi-Fi, another base station, I don't know exactly how it will be in the future networks, but if there are a lot of hopping between networks, you don't need to log in again. A typical case that we now found out in healthcare is that tend to switch networks when you go on different floors in a building, and many hospitals are often very high. It's hard to digitalize and use a tablet today because they have a traditional VPN not built for mobile. They go log in, have their pictures, then change floor, logged out, lost the session, and you have to re-log in again. It's a simple little thing, patented, but makes life easier and makes this a usable product.

It's also always on, and that's another thing that's always scared me with your PC, that the PC starts up, it starts to do a lot of communication, and then after a while, you log on on the VPN. Your computer can already be infected. Here, from the first bit, everything is encrypted. Two strong things, I would say. There is something in the pipe that can be a little bit complex to explain, but we can have number of VPN on the same device. If you have a shared service for the Swedish government, for example, but you still want access to your own bank vault, you can have that encrypted as well on the same phone. The VPN, for everyone who doesn't know it, is like on this picture.

All your data going in a secure metal pipe to your bank vault, so you can transfer your money back and forth. What we also done, for me, I replaced, I don't have any laptop anymore. We throw that away. It's too complicated. This one is easier. I'm always on, always running a virtual machine, if anyone knows what that is. I don't have any data on my device. That's really good when you lose your laptop. That happens from time to time, especially when you're a little bit in a hurry. What more to say about that? It's very simple to use. We sell it always now as a service, and that's a bit of a challenge.

We're actually selling a whole sort of IT system for very critical use as a service, and that's, again, the recurring revenue. Looking at the VPN, it's sold actually as well as a standalone component or together with a subscription in the U.S. Here, the typical case is the policeman. He's moving around, and again, the VPN makes sure that you're always connected. It's sold both on security and on availability. There we've got a lot of stamps, HIPAA and FIPS and such approvals to that. I think this is really interesting how crypto things can help in life. The traditional business, which is very close to what Fredrik talked about, is for RESTRICTED level, I would say that's to prevent against state actors.

This is a service also running for smartphones and tablets in Netherlands and Sweden and for EU, where you can connect to one voice and messaging community. This is approved to EU and NATO restricted. That's a quite tough one to get the smartphone approved to EU and NATO restricted. If you look at this, what we're doing right now, this is like product market matrix for the Tiger R, the restricted version. We can't tell you which countries, which organizations, but we have a lot of happy customers there. If we look at the Sectra mobile workplace, we start off with those services in Sweden and Netherlands, our home countries. We have the customers close together and develop it together with the customers.

For North America, which is new together with Columbitech acquisition, it's the VPN together with a telco subscription on the VPN itself. What we see drives this, we got a lot of requests. Actually, the Sectra mobile workplace idea comes from our customers. "Hey guys, you are experts in mobile security. Can you help us out?" We started to do this as like an in-house solution. Then, "But you're experts in holding data as well. Can we buy this as a service from you?" The driving factor is definitely you want to digitize, you want to be mobile with your sensitive data, but also what we see. Have you read about Maersk and Hydro, how much it costs to have a security incident? I think Hydro was about 650 million NOK, something like that.

Torbjörn Kronander
President and CEO, Sectra

300 the first week.

Robert Lidquist
VP, Civil Authorities Customer Segment, Sectra Communications

Yeah. If you look at an insurance ecosystem, I think it should be possible to get lower cost for insurance if you have real trusted and good security equipment. Also, as Pia talked about, and there are new legislations and new laws coming up. I think that goes for the market is growing. Okay.

Torbjörn Kronander
President and CEO, Sectra

We have a gentleman down there.

Speaker 11

For the mobile workplace, do you need hardware always, or can you do it on software?

Robert Lidquist
VP, Civil Authorities Customer Segment, Sectra Communications

We can do it on software. To prevent against state actors, we do some more production things on it. For standard enterprise, I would say for the government, at the level when it's not super critical, but it's critical, then we can do it in software.

Torbjörn Kronander
President and CEO, Sectra

In order to do the breach that or rate that the Israelis do, with the iPhone, you need a supercomputer cluster to emulate the iPhone under you. That's not what the normal criminals have. Some might, but not the normal ones.

Robert Lidquist
VP, Civil Authorities Customer Segment, Sectra Communications

Exactly. This is the case that you need to steal someone's device as well.

Torbjörn Kronander
President and CEO, Sectra

Yep. Kristoffer.

Speaker 12

Also for the Mobile Workplace, could you talk a little bit about competition and also the possibility to expand this outside other markets than Sweden and the Netherlands?

Could you take it to the U.S.? Would that make sense?

Robert Lidquist
VP, Civil Authorities Customer Segment, Sectra Communications

For software, we can take it to outside Sweden, Netherlands. There are competition, of course, on this. There are some big integrators taking components. There are also competitions, I told in the beginning, coming with component there and component there. For this service, there are things growing up next to us, but I think we are in a good position here.

Speaker 12

What do you mean by taking software global?

Robert Lidquist
VP, Civil Authorities Customer Segment, Sectra Communications

Yeah. The state actor thing is just for Europe.

Speaker 12

Okay. That's the shift.

Robert Lidquist
VP, Civil Authorities Customer Segment, Sectra Communications

Yeah.

Speaker 12

Yeah. You did this acquisition of Columbitech.

Robert Lidquist
VP, Civil Authorities Customer Segment, Sectra Communications

Columbit ech.

Speaker 12

Columbitech, sorry.

Robert Lidquist
VP, Civil Authorities Customer Segment, Sectra Communications

Yeah.

Speaker 12

That's another company.

Robert Lidquist
VP, Civil Authorities Customer Segment, Sectra Communications

Yeah. That's next year.

Torbjörn Kronander
President and CEO, Sectra

Next week.

Robert Lidquist
VP, Civil Authorities Customer Segment, Sectra Communications

Yeah.

Speaker 12

You mentioned you had a partnership with Sprint.

Does that generate any revenues or cash flows, or is it just a partnership? Can you tell us something about it?

Robert Lidquist
VP, Civil Authorities Customer Segment, Sectra Communications

It's a good partnership, but the figures I leave out for you to answer.

Torbjörn Kronander
President and CEO, Sectra

It's small. Columbitech has been a very small company, and not much negotiating power, so they have had too low prices in our ID. We are a little bigger, so hopefully we can drive their revenue up a little bit. There is revenue coming, and it's definitely a partnership that makes money, but perhaps it could make more money.

Mats Franzén
CFO, Sectra

Could there be any synergies for medical IT?

Torbjörn Kronander
President and CEO, Sectra

Oh, yes. Actually, this week we have a user group meeting for medical in the United States, and the people from communications selling these devices there, and Sprint was also very interested coming there to discussing selling the VPNs into hospitals.

Mats Franzén
CFO, Sectra

Those of you who are interested in the numbers can look at the supplementary information in the first quarterly report about the acquisition analysis if you're into the number crunching.

Okay. Thank you, Robert. Now we come to something also tying back to what Pia was talking about previously as part of her session, critical infrastructure, increased operational security in the energy sector.

Lars Larsson
VP, Critical Infrastructure Customer Segment, Sectra

Yeah. Hi, I'm Lasse Larsson. We'll talk about the critical infrastructure. I have to correct Mats. We don't only do it in the energy sector. We'll soon dive into which the customers are. Been with the company for three years, next week on Tuesday, to be very specific. Simo gave me a call and say, "Hey, Lasse, you've been doing industrial automation and these kinds of developing and deploying industrial control systems for the last 20, 25 years. Now it's about time to do it properly and securely as well. Would you like to join us?" The answer was, "Yes, of course, I want to do that." Now I'm spending my time on securing some of the systems that I have been part in delivering or developing in my past history. That makes me tick a lot, doing this. To start with, which are the customers?

Obviously, the energy sector, that was the starting point. Easily defined as very critical to society. Our modern society don't work without electricity. Yes, it's super critical. Our very first customers were in that sector, obviously. It's also a sector that is very used to being regulated. The distribution parts, the power grids, they have a monopoly situation in their specific region, so it's highly regulated, both from market perspective, but also from security perspective due to its criticality. They are quite used to taking on new legislations and so on. We do both for customers that do power distribution or electricity distribution, and obviously also generation. The second part that we also work with, especially in Scandinavia, most of the utility companies are multi-utilities. They do water, they do energy, they do local broadband or fiber connectivity for the municipality.

Water was a definitely second and very obvious sector for us also to enter. Another analogy is it's also a continuous process. You always clean the water, and you also always supply the water. We expect whenever we turn on the tap, there will be water. When we flip the light button, there will be light. It's always on. Hence, these guys and their production processes also needs to be always on and cannot be disrupted. That is also a sort of a synergy. Technically, it's the same sort of technical systems that operate this. We talk about industrial control systems or SCADA systems or OT technologies, operational technologies. It comes from the same vendors. To name a few, we talk about ABB, Siemens, Honeywell, General Electric, those kinds of big companies that supply the sort of industrial control systems.

The third sector that we also are active in right now is process industry. That's a bit of a step. Are these critical to society? Yes, they are. Either by the products they supply. Some of the process industries, if we take Sweden, for instance, some of the heat that they produce go back to the energy companies and supply the district heating in those communities, in municipalities. They also consume a lot of energy to run their processes. If you shut down a big process industry, say a pulp and paper mill, you actually influence the balance and the 50 hertz in the power grid. They are very interconnected. It's also a continuous process. If you disrupt one of these and cause an explosion in an oil refinery or a gas depot, you cause serious damage to the society.

Netherlands have identified 293 process industry sites as critical for their society that needs extra protection, to take an example. From state level, they have named these 293 companies. These are the three sectors. Sorry, Mats, not only energy.

Mats Franzén
CFO, Sectra

One out of three.

Lars Larsson
VP, Critical Infrastructure Customer Segment, Sectra

Yeah. You were right, but it was not a complete picture. These are the sectors that we are into. Continuous processes that have a very critical effect on society as it is today. Another commonality for all of these is they are highly automated or highly digitalized. They need computer systems to run their process efficiently. When I started back in the 1990s, or as my kids say, "Oh, in the 20th century. Way back." Actually, the industrial control systems and the office network, or the IT systems, were separate. It was physically separated networks. That is not the case today. The production manager of a process chemical plant wants to read the output from the process and monitor the efficiency of the plant live, maybe back from his TV sofa in the evening. It is interconnected today.

We also see that many of the systems and the maintenance of them are outsourced, and they are dependent on their suppliers. You create systems of systems or dependencies, not only within the company or within the utility, but also to external parties that actually help them maintain and run their services. This has made the utilities and the companies a prime target. You can affect financial markets, like Robert mentioned the Hydro incident. When they were starting to communicate on that they were having serious issues and production shutdowns, it affected aluminum pricing. It affected Hydro's stock price. It is both a target from state actors that want to disrupt the society. Instead of rolling in tanks, going back to Torbjörn's picture, they can actually sit remote and disrupt supply of water, electricity, and so on. To counter that, EU and national legislators are introducing new legislations.

From EU level, its most important is the NIS directive, network and information security. It identifies seven sectors. Bank and finance is one of them, because if payment doesn't work, you would also heavily disrupt the societal functions. Electricity is one, drinking water is one, and so on and so forth. New legislations, increased threats, increased interconnectivity, that is really market drivers for us. Does anything happen or is it like wild goose chasing? Things do happen. That's why I had the numbers so fresh in mind. Norsk Hydro, their incident cost NOK 300 million the very first week when they were disrupted. They were hit by a ransomware on their computer systems that spread rather rapidly through their computers. When the employees came, they were met by a sign on the entry door, "Do not plug in.

Do not turn on your computer." A physical sign. "Don't turn on your computer. Don't connect it to the network to avoid further spread on it." How did they discover it? The computer shut down. They were faced by the ransomware blockage. Same thing has happened to Maersk the year before, or two years before. You actually discovered it when you saw the consequences, and then the cost is pretty high. What if there was a way to counter the threat or counter the consequences a little bit earlier? This is another very famous incident. Did anyone hear about the Ukraine incident in the 23rd of December 2015? A few, yes.

For those that hadn't heard about it, 225,000 people in the Kyiv surroundings were out of electricity due to someone, state actor with interest in Ukraine, not named, actually hacked into the systems and took full control of the SCADA system, the control system that controls the power grid. The operators in the control room, they could see the mouse pointer moving on the screen, and someone was clicking, "Turn off this switch. Turn off electricity here." One of the operators was pretty fast. He got up his cell phone and filmed, and they couldn't do anything on their local keyboards and mouses. Someone had full control of their most critical system. The scary part is that started with a phishing email somewhere in May or June, and the attack happened on the 23rd of December.

The heart and core of what we do today is monitoring as a service. We monitor critical networks so we can detect when something is starting to move and starting to phish around in these critical networks. The Ukraine, they are not stupid, but they had 6 months to actually discover it. It took the opponent 6 months to gain full control of their control system. That gives a little bit time to defend yourself. That is partially what we do, or mainly what we do. As I said, I came from the automation business. This is how I learned cybersecurity. This is thanks to NIST National Institute of Standards and Technology over in the U.S. It's a pretty simple model. You need to identify what you need to protect. Okay, I put locks on my doors back home at my house.

Pretty obvious, I don't want anyone to just enter the door. Identify what you need to protect it with locks or firewalls or whatever virus hunters, what you have in your IT systems that you can resonate to. More and more, it's also about how to detect intrusions and respond to intrusions. I have a home alarm on my house with a camera system that activates if someone enters the house when the alarm is turned on. That is very similar to what we are doing today. We install camera systems or sensors in the critical networks to monitor when something that shouldn't be there is there. We can help our customers respond to that. Recover, yeah, Maersk did that. Ukraine did that. Get back on track again.

The scary part is really the second incident in Ukraine because the same actor went back a year later and caused even more damage. They caused physical damage to it because they were starting to switch on and switch off really big circuit breakers that caused mechanical and physical damage to the power grid. Those things have a long lead time if you want to reorder them and rebuild them. The first time in 2015, they managed to recover in three days because they were not fully automated. They had process engineers and electricians that were used to manually run the power grid. Actually, I would say the consequence is if that attacker would have happened in Sweden, it would have taken us longer because we are even more dependent on the automated systems rather than the people.

What we do, we've been doing critical infrastructure for the last four or five years. The majority of the business has actually been training and helping the market to adopt to the new legislations, to identify risk and vulnerabilities, to do security assessments of their entire organization, technology, people, processes, those kinds of things. The majority of the revenue have come from these advisory services. Now, I would say the last year, we see a major shift going into the monitoring and respond and detect. This is where we want to be. To monitor and run it as a service, a reoccurring revenue, continuously monitoring, 24/7 being able to respond to it. The nice thing is also that we link it also to the insurance business. cyber insurances are getting better and better, and they are becoming more and more commoditized.

The insurance companies has also discovered that it is good that any of their clients have the ability to respond, not only to protect, but also to respond because you can't protect yourself against everything. They give a carte blanche on, "Yes, you should start acting." Like I have in my home insurance, I can run my fire extinguisher, and the insurance company encouraged me to use the fire extinguisher, and they would pay for the costs to sort of sanitize after the powder is all over the place. They'd rather take that cost than risking that the entire house is burning down. The cyber insurance is moving the same way.

They'd rather take the cost for response, which we can do, and which we do for our customers, rather than risking that there is a power outage or a complete halt in the process of a petrochemical plant or drinking water supply. There are analogies and business drivers that helps us. All of the other guys got questions on competition. Also, I think there was a question already to Simo regarding competition and in the CI area or critical infrastructure. Here, yes, definitely we compete with big consultancy companies. Consultancies, technology providers, and there are some ones running also security operations center, but mainly coming from an IT perspective. We are happy to work together with those guys that provide the IT protection, but we do really excellent OT protection. Somewhat of an answer to your question earlier. Great. How does it work then?

Some sort of a plant, electrical plant for drinking water, process industry. There's SCADA and control systems. We install sensors like I have in my home alarm, the camera. We install the sensors that monitor and read as much network traffic as possible. That is also why we came from the core competence on Sectra, which was network. Networks and networks traffics and communications traffics. That is what we have built the sensors around. And the good thing is, here we talk about machines and processes that are pretty deterministic. So it's easy to predict how they should behave. And we teach the system this is normal behavior. And everything outside that, an anomaly triggers an alarm to our 24/7 service, where we can analyze and recommend the customer. "This is something really serious. We need to contain it.

You need to unplug that machine or stop that process." Not giving away too many secrets, but the most common false alarm is a new service technician or a service technician at the energy plant has received a new service laptop and should just do a minor tweak in the system, plugs in his brand new laptop. That we do discover. We call the customer and say, "Hey, we saw a new device on your network." "Oh, yeah. That's Kalle, he's got his brand new laptop." That's the most common false alarm that we see. Not giving away the real ones. This is also a differentiator. We can actually close the loop without compromising customers since we can provide the secure communications. We provide the critical infrastructure customers with Tiger phones, so we can talk to them because still you need the human interaction.

Yes, we are security experts and really good at that, but we are not that fantastic in how you optimize a furnace at a power plant. If we shut down that service, that could be our recommendation, what would that effect have on your district heating power plant? That needs to be in dialogue with the customer so we can do that in a controlled manner. They still own their own core process and we add the security component to it. Good. Monitor it, complete monitoring, 24/7, closing the loop. We can help them do incident response. We also see different business drivers, both from a legislative perspective, and from a business continuity.

It costs very big numbers if one of these plants needs to shut down, either in direct revenue if we talked about process industry or societal consequences if we talked drinking water and energy supply. It's pretty big numbers that helps drive it. I think we open up for questions there instead. Kristoffer?

Mats Franzén
CFO, Sectra

Thank you. The first question, the sensors or the technology, how good is it? Would you detect more or less everything, for example, the examples you were highlighting? Is that something you would have detected?

Lars Larsson
VP, Critical Infrastructure Customer Segment, Sectra

Yes. We had the team do a reverse engineering. We met the analysts that did analyze the Ukraine incident, so we dug into that. We would have detected somewhere between June and December. Yes, the technology allows that. We would have seen that, definitely so.

Speaker 12

Also, is it possible to give some sort of indication of the sales value for if you take one customer as an example, to get a sense for what this could mean for you if this becomes more common?

Torbjörn Kronander
President and CEO, Sectra

I'll take that one. It's very different. There are big players that will pay many millions SEK a year in this supervising on the network or detecting intrusion networks. There are small players that will pay much less. It's a huge variation, but it's millions SEK per year for the big guys, definitely.

Speaker 12

If you take the biggest guy in Sweden, you said many millions. Is that like SEK 10 million for such a customer-

Torbjörn Kronander
President and CEO, Sectra

You get me to-

Speaker 12

Is it five or?

Torbjörn Kronander
President and CEO, Sectra

Can't reply to that.

Lars Larsson
VP, Critical Infrastructure Customer Segment, Sectra

A larger customer would maybe like to have partial coverage and start small with a few sensors on very critical systems and then expand it. It's also the coverage part of it.

Torbjörn Kronander
President and CEO, Sectra

That's a good comment because we see very often they come in with one and then it works. These guys they provide water, sewage, electricity, and then it grows. In the final it's much bigger.

Mats Franzén
CFO, Sectra

Do you see this becoming bigger than the defense side of?

Torbjörn Kronander
President and CEO, Sectra

No, we want to grow both of them. The defense is problem we cannot sell that stuff outside of Europe. This we can sell to anyone.

Mats Franzén
CFO, Sectra

Okay. You think this will eventually get bigger?

Torbjörn Kronander
President and CEO, Sectra

Hopefully it will be big and defense will also be big.

Speaker 10

If you acquire a lot of customers while you monitor the systems, that will in turn mean that Sectra will become a security problem for them in one sense.

Lars Larsson
VP, Critical Infrastructure Customer Segment, Sectra

Yeah.

Speaker 10

Does that have any connotations?

Lars Larsson
VP, Critical Infrastructure Customer Segment, Sectra

Yes, you're absolutely right. One thing Fredrik and Pia has commented on different security levels or threat models or so on. If you aggregate the data, which happens when we grow the number of customers, then the requirements on us increase. We've done our homework and we do the security assessment and analysis of ourselves obviously. The critical parts that handle informations regarding more than one customer, we protect more. Yes, I agree.

Down there.

Speaker 11

Do you take on risks when you accept a new customer? If you don't succeed in this protection, will you be sued?

Lars Larsson
VP, Critical Infrastructure Customer Segment, Sectra

No. Will you be sued? No, I would say we can never assume and guarantee that for any upcoming and future incident, because we also sign the contracts on several years. We cannot guarantee that we would rectify any possible attack and intrusion attempt and do the liabilities and the indirect costs for a power plant outage. The customers do understand that. The rectification is always, I would say best effort, but since we are the experts and we also have the gathered and collected information through our sensors, we have a much bigger chance of doing a good job. It's not a liability question there that at least direct.

Torbjörn Kronander
President and CEO, Sectra

I could answer a little bit on the insurance part. Because that's what we work with and then as them as a partner, it means that they take the liability part in the insurance, they take that from our partners. Of course then they are secured a little bit more for the risks that are coming from outside and not verbally found by us either.

Speaker 13

These sensors, do you develop them yourselves in-house? If not, if they're bought from third parties, I assume other companies can also use the same sensors.

Lars Larsson
VP, Critical Infrastructure Customer Segment, Sectra

Yeah. Good question. The hardware is commercial off the shelf. The software, encryption technologies, how we collect the data, how we do the anomaly detection, that is our proprietary software.

Speaker 13

Can we get any figures on how many sensors have been deployed, how many you expect to deploy?

Lars Larsson
VP, Critical Infrastructure Customer Segment, Sectra

No. I would violate a massive trust from our customers. Sorry.

Speaker 14

The payment model, is that fixed or are there any variable elements in it? If it's more attacks on a company, would you receive more money or is it just fixed based?

Lars Larsson
VP, Critical Infrastructure Customer Segment, Sectra

No, we limit the amount of incident response because same thing, we cannot assume the risk if a company would be attacked once a month or with severe consequences. We have a roof on, and then we can charge extra for the efforts for incident response. That is a moving thing. The other one was the expansion of system based on the coverage or how many networks we monitor and protect at the customer site. That is the two variables, I would say.

Speaker 14

Secondly, as the consequence for your customer, if they fail, they are terrible. Do you think you charge enough for your service?

Torbjörn Kronander
President and CEO, Sectra

Good question. Next question.

Lars Larsson
VP, Critical Infrastructure Customer Segment, Sectra

The customers think we charge enough.

Speaker 10

Do you have a protection for I've lost the word in English? [Foreign language]. Help me out.

Lars Larsson
VP, Critical Infrastructure Customer Segment, Sectra

Denial of services or these kinds of when you spam the network.

Speaker 10

You overload the system.

Lars Larsson
VP, Critical Infrastructure Customer Segment, Sectra

overload the system. We would detect the abnormal traffic and can recommend that the customer shuts down parts of the networks or most of our customers have a big manual switch going into island mode, where they actually physically disconnect the process systems from the administrative networks and everything. That is one way of maintaining and running the process, but disconnecting from the outer world.

Speaker 10

You cannot automatically, when you see such an attack coming.

Lars Larsson
VP, Critical Infrastructure Customer Segment, Sectra

We see the attack.

Speaker 10

somehow mitigate this.

Lars Larsson
VP, Critical Infrastructure Customer Segment, Sectra

Yes. I would answer to that from a security perspective, it would be disastrous if we could go in. That has been a fundamental design principle of our product, that we cannot go in and tamper with the customer systems, because then we would be an attack vector for the system. No, we cannot automate that. We would compromise the security level. Okay. The future of cybersecurity, skate where the puck is going to be. Who should talk about that? None other than Torbjörn.

Torbjörn Kronander
President and CEO, Sectra

All right. It's been a long day. I'll try to be brief in the very end here. As you see, we're trying to move the entire security field over to recurring revenue. We do that with the phones and the smart terminals, charging for a service, and we are definitely doing so in the critical infrastructure with the whole business ideas around that. The consultancy part is an enabler of the recurring revenue. All of these businesses is kind of burden in the beginning. When you have a 24 by seven operation SOC, and it's only one customer, it's a tough call making that profitable. When the 10th or 20th or the 90th customer comes in, it's a very interesting business, because it doesn't happen so much things all the time. That's where we're moving.

Sorry about that. Our position again, it's a market that's global and large. It's forced to grow by external forces, as we said. It's our demand on markets. It's not price sensitive. It is because if you run an electrical power supplies company, every little penny is important, because government is supervising their pricing. Compared to the damage, if you have a petrochemical refinery or something in that area, the cost is hundreds of millions SEK per month, or per week if it breaks down. It's the right thing. Again, it's always a negotiation. Large barriers of entry due to required trust. You wouldn't buy this from anyone. Three guys in a garage can compete on IT security. On our level, if a power supply company wants to protect themselves, they will not give that to any vendor.

They will call the national security of their country and ask, "Are these guys okay?" The national security operations in Europe know us very well, and they will confirm we're okay, which will reduce barriers or increase the barriers of entry very much. It's a trust business. It's a rapid and it's a forever change. It's kind of a hunting game. The bad guys come up with new vector, we protect, so you can't just buy it and let it be. Our position, and again, is that where there's change, there is money. You just have to be fast enough. Growth and margin have to increase in this business. As I said, we're going over to recurring revenue, and that's a very expensive first years. We're clearly seeing it. I cannot reply how much. We don't publicize that yet.

For Sectra as a whole, it's substantially above 50%. We're not saying how much above, but it's substantially above 50%. We are moving security in that direction as well. Going forward, skate where the puck is going to be. When Wayne Gretzky was interviewed on how he could be such a good hockey player, he replied he was not good in anything. Not good in hockey, skating, not good at shooting, nothing. His only response was, "I do not skate to where the puck is. I skate to where the puck is going to be." We've been quite good at that at Sectra. We've seen things. We saw security come into medical IT ways before anyone else did it. When that hits and some of our competitors are issued with severe warning by Department of Homeland Security in the U.S., we're already there.

Nothing is perfectly secure. We've seen it coming. Critical infrastructure, we saw it coming. We started these four or five years and invested a lot of money in that software that supervises these things. We've been good at that. That's what we try to do. What we will see here, we will see new threats. 5G, Internet of Things, everything will be connected. Now, it's not a major disruption if your cooler at home is infected by a virus. If that spreads from that cooler or if all the coolers in the country are disabled all of a sudden, that's a problem. All cars will have internet in them. That's exposure to security that is massive. This is coming right now. That will drive market.

Google has now proven, as Jonathan showed us, that actually there are cases where these quantum computers do work, I don't know if you really understand what the consequences is. If this happens, no BankID, no Swish, no HTTPS connections, no internet banking, no information between the banks of transactions. If those computers really happen before we have a counterattack to it, we are in deep trouble. We're working a lot with that. That will drive the market. All these networks have to be quantum safe. As I said, the highest levels, the secret levels, we already are. That means you have to have a very expensive key distribution because you have to move a physical key to both ends before you start the encryption. Now, that doesn't work for 1 million customers of a bank.

You have to have these public key structures in place, and those algorithms are coming. We just don't know which one will succeed, win yet. Artificial intelligence, we are doing a lot of things in medical around that, but that will impact also this industry. If you have a predetermined algorithm for detecting intrusion and that algorithm is known, you can get around it. If you have an AI system that detects traffic on a network, no one knows exactly with that system how smart it is. It's very difficult to get around it, and we're playing around with that for security as well. There's a first law of technology. I've shown some of you have seen it before. First law of technology says that invariably, we overestimate the short-term impact of new, truly transformative technology.

Everyone says, "Quantum computers, they might happen tomorrow," and then everything will go bad. Medical, there will be no more radiologists. We don't need to educate more radiologists five years from now. That was a Google researcher said four years ago, but they still do educate radiologists. It doesn't happen that fast. It always goes slower, but we also invariably underestimate the long-term effects. The long-term effects of quantum computing, someone will make it work. Perhaps not now, perhaps not in 10 years, but in 100 years, they will work. That will disrupt the entire industry. 5G will happen. That's happening right now. AI will happen. When it does, it really changes things, and that opens huge opportunities for the people who are there already. Keywords going forward for Sectra.

We have not done that perfectly well in security before because some of the encryption systems were very difficult to use. Our previous secret telephone required more or less a full-time assistant making it work before the president or prime minister or whatever could actually talk in it, and it took 10 minutes. That is not an easy enough usability system. We have fixed that now. Now it's like calling a normal phone. Customer satisfaction is very important also here. We will work with that as we do in medical. Top-level security. Assured level secrets in hardware. We do a few software systems. That's not our key point. We need to do that high level because if you do only security, you compete with WhatsApp, all the other things that has encryption in software. We don't want to compete in that space. Too much cheap things there.

We want to be on the high level, and then you need hardware. That's our target. If we're going to sell these things in all countries, we cannot sell that hardware to anyone. Super simple to use. As I said before, ideal security, you don't even see it. Mobility, everything will go mobile. People think you will sit there and do that thing in that closed room. No, it will not. These, what the military call red networks, the networks that are really sensitive, it used to be in a locked-in room. Now it's over the entire building. In the future will be many buildings and many cities, and they should be perfectly secure. That creates completely new demands to build these systems. Critical infrastructure, protect our society. There will be more Ukraines.

There's no doubt that someone will take down a power plant or really hurt a country. If there will be a conflict in Ukraine again, the power grid's the first thing you attack because if the soldiers feel my family don't get food, they don't come into the military. They stay home, make sure their families get food. It has to be solved as part of this total defense. Internationalization and growth, that's another important aspect. We've been mainly in Sweden, increasingly also in Netherlands, and somewhat in some other countries in Europe. The big markets is, of course, outside the 20 million people of Netherlands and the 10 million in Sweden. We have to have products that we can actually allow to sell all over the world. Critical infrastructure is such an area, and some of the encryption stuff we can sell to anyone.

This will set us up on a good path forward. Recurring revenue, high level, and trust. Trust, trust, and brand. Sectra is a brand. If our system stop in medical, I just discussed that with our U.K. manager. She said, "Well, you realize that more than 50% of U.K. hospitals depend on us. If our system stop to work, radiologist stops to work, emergency stops to work, hospitals come to grinding halt." She was concerned as a British citizen that we actually are very careful. Now, this kind of level of trust we also have in this area. If we protect the critical infrastructure of a country, we are severely important, and then we can charge a little money extra for that trust. Okay, that comes to a conclusion of this day. Please give us feedback.

You will all have a survey sent to you because your time is very valuable, and we want these to be productive. Please respond to that. We adapt these days according to your wishes. One of those was 2 years ago, we got that we split up cybersecurity, medical, and we did. We do listen to your advice there. Thank you very much. You can have demonstration, a little snack, and you can have a chat with any one of us outside. Thank you very much for coming.