RESOURCES
Cynode Boosts Team with Gustav Bivstedt's Technical Expertise

In the vast realm of cyber security, there are few people who stand out not just for their technical expertise, but for their passion and vision. Gustav is one such individual, a native of Sweden, who has been making waves in the cyber security sector for around four years.
Background and Experience
Gustav’s academic journey began with a BSc in Business and Economics, Gustav wasn’t satisfied there so decided to pursue his Master’s in Computer System Science, while working full time. His professional trajectory has seen him take on roles such as the Technical Lead at organisations and serving in the Swedish Armed Forces. Currently, he holds the esteemed position of a Cyber Security Advisor. Gustav isn’t just about work; he’s a well-rounded individual with elite-level experience running at 800 metres and is a keen Brazilian Jiu-Jitsu (BJJ) fighter.
Having previously worked with Sebastian and other trusted colleagues in a different company, Gustav values the bonds of trust and camaraderie. He’s driven by the desire to be part of a world beating start-up, and to build something from the ground up.
The Allure of Cyber security
Although Gustav enjoys the inherent diversity of cyber security, he started with a keen interest in penetration testing. His passion then grew into Cyber Threat Intelligence (CTI) and the integration of the National Institute of Standards and Technology (NIST) framework. He likens his role to being a small piece in a vast, intricate puzzle.
In Gustav’s perspective, the predominant threat most companies face today is ransomware, a view shaped by the numerous high-profile cases we witness. He believes that the dynamics of cyber security are evolving, and CTI plays an increasingly pivotal role. While larger organisations are turning to products like CTI to address their challenges, Gustav emphasises that smaller entities first need to nail down the basics before investing in such solutions.
Cynode’s Potential
Gustav sees immense potential in Cynode assisting clients to harness the benefits of CTI. By coupling it with NIST reviews, businesses can derive enhanced value from their assessments. He envisions a future where Cynode pioneers a proactive approach to CTI application and cyber assessment integration. The ultimate goal? To transition from offering an internally built solution that sells as a service to selling a product that stands out from the already well-established competitors in that field.
As Cynode expands, Gustav aspires to be a cornerstone of its growth, contributing his technical expertise, unwavering drive, and vision.
Teamwork and Communication
For Gustav, effective communication is the lifeblood of a successful team. Bringing together brilliant minds is essential to propel technical ideas to fruition.
He’s a staunch advocate for clients seeking guidance from seasoned professionals and believes that understanding the customer’s baseline, is one of the most important things to do. This baseline can be easily determined by initiating a NIST assessment as this can provide businesses with a clear roadmap for their cyber security journey.
Continuous Learning and Building Trust
Gustav’s approach to learning is multifaceted. From creating an RSS feed to collate security updates to tapping into the wealth of information from his local CERT, he believes in diversifying sources of knowledge.
Contrary to the stereotype that cyber security professionals are mere ’geeks’, Gustav emphasises that they are just regular individuals, committed to safeguarding both corporate data and personal privacy.
Building and maintaining trust with clients is paramount for Gustav. Delivering on promises, punctuality, professionalism, and a structured approach are non-negotiable for him.
Vision for the Future
Gustav sees his future as being instrumental in establishing one of the premier cyber security firms, boasting top-tier skills and a relevant workforce. He recognises that not all organisations have expansive budgets and envisions Cynode aiding the broader security community, not just the major organisations with huge budgets.
He appreciates Cynode’s modern ethos, team spirit and the ability to work flexible, which he believes is crucial in today’s landscape. Technology has provided us the ability to be effective from anywhere in the world.
-
Modern SIEM Efficiency Starts at Ingestion: How Microsoft Sentinel’s Data Collection Rules (DCRs) Shape Detection Value
In this blog post, we explore the vital role of selective data collection in modern security operations and examine how Microsoft Azure Sentinel addresses this challenge using its powerful Data Collection Rules (DCRs). Whilst the discussion centres on Sentinel-specific examples, the insights presented are highly relevant for any organisation looking to enhance SIEM efficiency. Whether you're a security architect aiming to streamline detection or an MSSP customer focused on reducing data ingestion and operational costs, adopting a signal-driven logging strategy can yield substantial benefits. By being deliberate in what data is collected, organisations can lower overhead, sharpen threat detection, and ensure cost-effective log management.
-
Understanding Group Managed Service Accounts (gMSAs): Advantages Over Traditional Service Accounts
Nearly all breaches in the last decade were preventable. While intrusions, defence evasions, and human error can occur, good cybersecurity practices can stop threat actors from progressing along the kill chain before achieving their goals. We've been sharing best practices through Tips & Tricks LinkedIn posts to help our followers build cyber-resilient networks. Our VP of Product, Cumhur Hatipoglu, has written a new blog diving deeper into Group Managed Service Accounts (gMSAs)—one of our recent Tips & Tricks topics. This Microsoft feature provides enhanced protection against attack techniques including credential theft, dumping, lateral movement, and privilege escalation. Your detection and response teams and service providers should focus on handling sophisticated attacks that bypass internal defences—not the preventable ones.
-
Managing Cyber Risk with CTEM and Beyond
Cynode Ultima takes the complexity out of cyber threat management with its all-in-one security platform. Building on Gartner's CTEM framework, we've created a solution that brings together essential security tools - from threat intelligence and vulnerability prioritization to dark web monitoring and attack surface management - in one place. The article explores why organizations often struggle to implement security programs that meaningfully reveal their true risks and security gaps. We show how Ultima bridges this gap by providing an integrated approach that helps businesses understand and address their actual security exposures, making advanced threat management both accessible and actionable.
-
Investing in Dark Web Monitoring: A Practical Guide
Should you invest in a Dark Web Monitoring service? The answer is not as straightforward as you might think—it really depends. Whilst Dark Web Monitoring is undoubtedly valuable, where does it rank in your list of priorities? For instance, if you have a limited budget, should you invest in Dark Web Monitoring or a Security Awareness Programme? The answers to such questions vary for each organisation, but there are some general principles that can guide your decision-making process.
-
The Persistent Threat of Business Email Compromise
Business Email Compromise is a sophisticated type of email and identity based attack that doesn't rely on malware or malicious links. Instead, it leverages social engineering tactics to manipulate human trust and judgement. This makes BEC attacks particularly challenging to detect and prevent, even for organisations with robust protection infrastructures and cyber security awareness programmes.
-
The Risks of Increasing SaaS Use
Organisations increasingly rely on cloud applications, with small enterprises using over 20 SaaS apps per user and large companies exceeding 250 per company. This growth introduces significant cyber security risks, including unauthorised access and Shadow IT, where unsanctioned apps are used without oversight. To mitigate these risks, companies need advanced monitoring solutions like Cynode’s MDR for Cloud Apps Shadow IT, which offers visibility, consent policy enforcement, and threat detection across SaaS platforms, ensuring security and compliance.
-
Interview with Senior Cyber Advisor Per-Olov Kask
Delve into the fascinating career journey of a seasoned cyber security professional who has dedicated over three decades to the ever-evolving IT and cyber security landscape. Starting as an IT technician in 1993, our expert quickly rose through the ranks to become a country IT manager, driven by a passion for combating emerging cyber threats. In 2022, this journey led to an impactful role at Cynode as a Senior Cyber Advisor. Join us as we explore his experiences, insights, and the innovative approaches that make Cynode a leader in the cyber security field.
-
Regular EDR Policy Tuning
The cyber security world has recently focused on EDR technology due to its significant impact across industries. This post explores the evolution from early antivirus software to EDR platforms. Key milestones include the introduction of commercial antivirus software in 1987, the emergence of heuristic and behavioural detection methods in the early 2000s, and the development of Next-Gen Antivirus (NGAV) in 2010. EDR solutions, emerging around 2013, are crucial for detecting, investigating, and mitigating security threats but require regular policy updates and meticulous tuning for optimal performance.
-
Mastering Log Management: Enhancing SIEM and SOC Efficacy
Efficient log management is critical for SIEM and SOC efficacy. Challenges include log agent malfunctions, configuration errors, and network issues. This blog explores four log problem categories, from detection failures to incomplete logs, and introduces innovative solutions for proactive threat detection and response. Learn how Cynode's integrated threat simulation and log validation processes ensure optimal log coverage and enhanced security monitoring. Stay ahead of cyber threats with robust log management practices.
-
Understanding WebApp Exposure
WebApp Exposure Monitoring involves regular assessments and updates to perimeter defence platforms like WAF policies, ensuring alignment with the latest threat intelligence. Having a proactive stance to WebApp attacks is crucial as cyber threats incredibly fast, often outpacing traditional security defences. The process of continuously monitoring web applications allows organisations to more readily detect anomalies and respond to threats in real-time, minimising the risk of data breaches and other cyber incidents.
-
Introduction to Managed Security Service Providers (MSSPs)
Businesses increasingly struggle with cyber security management, especially with limited resources. Managed Security Service Providers (MSSPs) like Cynode offer comprehensive, efficient solutions, managing everything from security infrastructure to incident response, often using cloud services for cost efficiency. This article explores the benefits and services MSSPs provide, underscoring their importance in modern cyber security strategies.
-
Improving SIEM Efficacy as the Market Evolves
As the SIEM market evolves with new mergers and partnerships, Cynode supports practitioners to ensure no security event is missed, offering comprehensive services from threat-centric log and rule validation to complete SIEM management.
-
Welcome Konrad Falk as Our New Senior Cyber Advisor & Architect!
Konrad brings extensive experience in Cyber Security and IT, with a background in programming, networking, and security. Passionate about securing companies and educating others, he values the trust of our leadership and is eager to manage security incidents and tackle evolving threats hands-on.
-
“Trust me, I was an engineer” – Björn Nilsson
We are pleased to announce Björn Nilsson as the new Head of Security Operations Sweden at Cynode. His extensive experience in cyber security and IT infrastructure marks a significant milestone in enhancing our capabilities. Björn brings a wealth of expertise from various critical roles within the industry.
-
Meet our "VP of Product" Cumhur Hatipoglu
As Cynode’s CMO, I am constantly impressed by our team's innovation and engagement. Cumhur Hatipoglu, our new VP of Product, enhances our mission to innovate in cyber security and MDR services. His approach integrates NIST CSF and best security practices to ensure our solutions meet clients' evolving needs.
-
Hacking and Cyber Warfare Go Hand in Hand
Sweden, amidst its NATO application and tensions with Russia and Turkey, has experienced a rise in political cyber-attacks. Groups such as Anonymous have targeted governmental infrastructures, leading to data leaks. Escalation of cyber-crime and nation-state backed cyber warfare necessitates global enhancement of defense measures.
-
EU updates NIS Directive. Are you compliant?
The European Union introduced the NIS 2 Directive to improve the cyber security of critical infrastructure systems within its member states and to ensure that digital service providers and operators of essential services have adequate security measures in place to secure their networks and data.
-
Rise of Cyber Due Diligence in M&A Processes
Sweden's post-pandemic economic recovery has spurred M&As. Cynode emphasises integrating cyber due diligence to address vulnerabilities, protect essential information, and optimise security spending, enhancing the security posture before, during and after M&As.