From a data lake to a data map
Two conversations about public sector digitalisation in the same week arrived at the same missing piece: a shared surface. Indexing existing data by location changes which questions can be answered, without changing what is collected.
Indexing data by the location it describes changes which questions an organisation can answer, without changing what it collects. That is the shortest statement of what two conversations about public sector digitalisation produced this week, in different parts of the country, from people who had never met.
What both organisations already had. One department held an architecture diagram. Another held a system catalogue. A third held a risk register. The operational staff held the working knowledge of which service depends on which hall. Every one of those records was accurate, current and maintained by someone competent.
What neither could produce. An answer to the question that decides a budget: if this fails, who is affected, where, and within what time. The material exists to answer it. What is missing is a common index, so the answer is assembled by discussion and delivered as an estimate.
A repository answers questions in the shape of its index. Data organised by source system answers questions about source systems: what is stored, by whom, in what format. Data organised by place answers questions about place: which services depend on this building, which residents are affected when it stops, which requirement applies to this node and who owns it. The content is identical in both cases. The retrievable questions are not.
The starting geography is already public. Municipal boundaries, schools, care homes, water works, fire stations, network routes and population figures are available as open data. Beginning does not require capture, procurement or a platform decision β it requires placing what the organisation already holds onto ground that already exists.
Why the index has a deadline attached. The Swedish cybersecurity act entered into force on 15 January 2026 and places accountability at management and board level. The Cyber Resilience Act brings reporting obligations for actively exploited vulnerabilities from 11 September 2026 and its main obligations from 11 December 2027. A requirement attached to a node can be reported on: scope, owner, status. A requirement held in a document can be described, and description is what supervision asks organisations to move beyond.
What came out of these conversations. A training programme for public sector organisations, in three stages β getting started, getting further, succeeding β with eight modules, six exercises and a ninety-day plan. Dates are being set and registration of interest is open. Four papers were published alongside it, in Swedish and English, covering the cybersecurity act in shared municipal IT, the Cyber Resilience Act from a buyer's position, the standards landscape, and governance that holds when requirements move.
The papers are at winniio.io/whitepapers, the training at winniio.io/utbildning, and the longer argument about reality as the architecture is in insights.
Denna text finns pΓ₯ svenska: [FrΓ₯n datasjΓΆ till datakarta](/insights/fran-datasjo-till-datakarta).
Where this goes next
Want this applied to your organisation?
One call is enough to know if we're a fit.