Cybersecurity consulting ยท Security architecture ยท Cloud security ยท DevSecOps ยท Public ISMS ยท Open Source Transparency
๐ Gothenburg, Sweden ๐ธ๐ช โ 30+ years in IT ยท CISSP ยท CISM ยท AWS Security & Solutions Architect (Professional)
Builder of ISMS-PUBLIC ยท Riksdagsmonitor ยท EU Parliament Monitor ยท European Parliament MCP Server ยท Citizen Intelligence Agency ยท CIA Compliance Manager ยท Black Trigram
- ๐ Sponsor Hack23 โ Support Open Source Security
- ๐ฏ About Me
- ๐ Professional Certifications
- ๐ Commitment to Transparency and Security
- ๐ข Hack23 AB
- ๐ Discordian Cybersecurity Insights
- ๐ Open Source Projects
- ๐ The Hack23 Ecosystem
- ๐ Security Services
- ๐ Project Documentation Index
- ๐ก๏ธ Security Focus Areas (CIA Triad)
- ๐ Press & Media
- ๐ค Technical Talks & Presentations
- ๐ผ About James Pether Sรถrling
- ๐บ๏ธ Hack23.com Site Map
- ๐ซ Connect & Sponsor
Hack23 AB is bootstrapped, vendor-independent, and gives away what most consultancies sell behind a paywall โ a complete public ISMS aligned with ISO 27001:2022 / NIS2 / GDPR / EU CRA / NIST CSF 2.0 / CIS Controls v8.1, production-grade open-source platforms for parliamentary transparency, and a deep Discordian Cybersecurity blog demystifying real-world security practice.
Your sponsorship directly funds:
- ๐ก๏ธ Maintenance and continuous improvement of the public ISMS-PUBLIC โ 40+ policies, free to fork for any organization
- ๐ณ๏ธ Operating costs of the parliamentary transparency platforms: Riksdagsmonitor, EU Parliament Monitor, European Parliament MCP Server, Citizen Intelligence Agency
- ๐ฌ Independent security research โ supply-chain hardening, SBOM tooling, AWS security analyzers (sonar-cloudformation-plugin), threat-model templates
- ๐ Free educational content โ 30+ Discordian Cybersecurity blog posts, the CIA Triad FAQ, security assessment checklists
- ๐ SLSA Level 3 supply-chain hardening of every Hack23 release โ signed attestations, dependency review, OpenSSF Scorecard
- ๐ 14-language accessibility of public-interest political intelligence โ democracy is for everyone, not only English speakers
Why sponsor? Most security knowledge sits behind NDAs and audit-firm paywalls. Hack23 publishes the actual policies, threat models, architectures, and source code we run โ so anyone, anywhere, can learn from them, copy them, and improve them. Sponsorship is how the lights stay on without compromising independence or accepting hidden agendas.
Strong advocate for transparency in organizations, secure software development practices, and innovative open-source solutions. Experienced security professional with over 30 years in information technology, specializing in security architecture, cloud security, DevSecOps, and compliance (ISO 27001, NIS2, GDPR, EU CRA, NIST CSF 2.0, CIS Controls v8.1).
Prior roles include:
- ๐ก๏ธ Application Security Officer โ Stena
- ๐ก๏ธ Information Security Officer โ Polestar
- ๐๏ธ Senior Security Architect โ WirelessCar
Currently CEO/Founder of Hack23 AB โ a Swedish (Gothenburg-based) cybersecurity consultancy delivering practical security architecture, AWS cloud security, secure-SDLC enablement, and ISO 27001 / NIS2 / GDPR / EU CRA compliance through a 100 %-public ISMS and live open-source reference implementations.
At Hack23 AB, we believe that true security comes through transparency and demonstrable practices. Our Information Security Management System (ISMS) is publicly available, showcasing our commitment to open security practices and serving as a live reference for any organization building its own.
Our approach to cybersecurity consulting is built on a foundation of transparent practices:
- ๐ Open Documentation โ Complete ISMS framework available for review
- ๐ Policy Transparency โ Detailed security policies and procedures publicly accessible
- ๐ฏ Demonstrable Expertise โ Our own security implementation serves as a live demonstration
- ๐ Continuous Improvement โ Public documentation enables community feedback and enhancement
"Our commitment to transparency extends to our security practices โ demonstrating that true security comes from robust processes, continuous improvement, and a culture where security considerations are integrated from the start."
โ James Pether Sรถrling, CEO/Founder, Hack23 AB
Swedish innovation hub specializing in cybersecurity consulting & solutions alongside immersive, security-aware game experiences.
๐ https://hack23.com ยท ๐ข Org.nr 559534-7807 ยท ๐ Gothenburg, Sweden ๐ธ๐ช
Explore information security, ISMS policies, and cybersecurity best practices through the unique Discordian lens inspired by the Illuminatus! trilogy. "Think for yourself, question authority."
Featured Content:
- ๐ญ Discordian Manifesto - Everything You Know About Security Is a Lie
- ๐ Complete ISMS Coverage - All 30 posts link directly to ISMS-PUBLIC repository
- ๐ Illuminatus! Style - FNORD detection, Chapel Perilous references, 23 FNORD 5 signatures
All hail Eris! All hail Discordia! ๐
A curated portfolio of Hack23 AB open-source projects โ every one operated under the public ISMS, with OpenSSF Scorecard, SLSA Level 3 attestations, DeepWiki docs, and reproducible builds.
%%{init: {"theme":"base","themeVariables":{"primaryColor":"#0066CC","primaryTextColor":"#fff","primaryBorderColor":"#003366","lineColor":"#94A3B8","secondaryColor":"#003399","tertiaryColor":"#7B1FA2","background":"#0F172A"}}}%%
graph TB
subgraph CONSULT["๐ผ Hack23 AB โ Cybersecurity Consulting"]
SVC["๐ Services<br/>hack23.com/services.html<br/>Architecture ยท Cloud ยท DevSecOps ยท Compliance"]
ISMS["๐ Public ISMS<br/>github.com/Hack23/ISMS-PUBLIC<br/>38 policies ยท ISO 27001:2022 ยท NIST CSF 2.0"]
BLOG["๐ Discordian Blog<br/>hack23.com/blog.html<br/>30+ posts ยท 8 languages"]
end
subgraph SOURCES["๐ก Primary Open Data"]
EP["๐ช๐บ European Parliament<br/>data.europarl.europa.eu"]
RD["๐ธ๐ช Riksdagen<br/>data.riksdagen.se"]
REG["๐ธ๐ช Regeringskansliet<br/>regeringen.se"]
end
subgraph MCP["๐ MCP Servers (AI Bridges)"]
EPMCP["๐ช๐บ European-Parliament-MCP-Server<br/>npm: european-parliament-mcp-server<br/>62 tools ยท 9 resources ยท 7 prompts"]
end
subgraph CIVIC["๐๏ธ Civic-Tech Platforms (Apache 2.0)"]
CIA["๐ต๏ธ Citizen Intelligence Agency<br/>github.com/Hack23/cia<br/>Java 26 ยท Spring ยท 110 DB views ยท 1971โ2024"]
RM["๐ณ๏ธ Riksdagsmonitor<br/>riksdagsmonitor.com<br/>11 agentic workflows ยท 14 languages"]
EUM["๐ช๐บ EU Parliament Monitor<br/>euparliamentmonitor.com<br/>9 agentic workflows ยท 14 languages"]
end
subgraph PRODUCT["๐ Products & Platforms"]
CCM["๐ CIA Compliance Manager<br/>ciacompliancemanager.com<br/>npm: cia-compliance-manager<br/>React 19 ยท TypeScript 6"]
BT["๐ฅ Black Trigram<br/>blacktrigram.com<br/>npm: blacktrigram<br/>Three.js ยท React 19 ยท 70 vital points"]
GAME["๐ฎ Game Template<br/>github.com/Hack23/game<br/>SLSA 3 secure-by-default starter"]
end
subgraph AUDIENCE["๐ฅ Audience"]
USERS["Citizens ยท Journalists ยท Researchers ยท NGOs ยท Security teams ยท AI assistants (Claude ยท Cursor ยท Copilot ยท VS Code)"]
end
EP --> EPMCP
EPMCP --> EUM
RD --> CIA
REG --> CIA
CIA -->|"15 subsystems ยท nightly sync"| RM
EUM --> USERS
RM --> USERS
CIA --> USERS
CCM --> USERS
BT --> USERS
EPMCP -.->|"AI assistants"| USERS
SVC --> USERS
ISMS --> CIVIC
ISMS --> PRODUCT
BLOG --> USERS
style CONSULT fill:#003366,stroke:#0066CC,color:#fff
style ISMS fill:#0066CC,stroke:#003366,color:#fff
style EPMCP fill:#6366F1,stroke:#4F46E5,color:#fff
style CIA fill:#006B3F,stroke:#003F25,color:#fff
style RM fill:#00338D,stroke:#FECC00,color:#fff
style EUM fill:#003399,stroke:#FFCC00,color:#fff
style CCM fill:#0066CC,stroke:#003366,color:#fff
style BT fill:#000000,stroke:#FFD700,color:#FFD700
Single mission, one ISMS, one license (Apache-2.0), one set of compliance frameworks โ applied identically across consulting, civic-tech and commercial products.
Each project has its own ISMS-aligned SECURITY_ARCHITECTURE.md, THREAT_MODEL.md, OpenSSF Scorecard, OpenSSF Best Practices badge, SLSA 3 attestation and SonarCloud quality gate.
AI-driven monitoring of Sweden's Riksdag, Government and public agencies โ 349 current MPs, 2,494 historical politicians (1971โ2024), 3.5M+ votes, 109,000+ documents, 14 languages, every day.
๐ Surfaces: Live ยท Political Intelligence Hub ยท AI Newsroom ยท Dashboard ยท Sitemap ยท Features ยท Docs
Brussels and Strasbourg made readable. AI-newsroom over the European Parliament's open data โ 8 unified gh-aw workflows, 51 analytical artifacts per run, 14 languages, 1,700+ daily artifacts, full Admiralty / WEP / SAT / ACH tradecraft.
๐ Surfaces: Live ยท Political Intelligence Hub ยท Sitemap ยท API Docs ยท Features ยท Docs
Canonical TypeScript Model Context Protocol server bridging the European Parliament Open Data Portal v2 to any MCP-aware AI client (Claude Desktop, VS Code, Cursor, GitHub Copilot). 62 tools, 9 resources, 7 prompts, full GDPR-by-design.
๐ Surfaces: Repository ยท npm ยท API Docs ยท Features ยท Docs
Java/Spring/Vaadin OSINT platform monitoring Sweden's Riksdag, Government and Myndigheter since 2008. 110 database views, 50 risk-detection rules, 1971โ2024 longitudinal coverage, 3.5M+ votes, 109K+ documents. The data backbone behind Riksdagsmonitor.
๐ Surfaces: Repository ยท Architecture ยท Security Architecture ยท Threat Model ยท Features ยท Docs
React 19 / TypeScript 6 platform for CIA-triad assessment, multi-framework compliance, threat modeling and business-impact quantification. Available as a live web app and a tree-shakeable npm library with 10 subpath exports.
๐ Surfaces: Live App ยท npm ยท API Docs ยท Features ยท Docs
Production-ready 3D precision combat simulator. Eight I Ching trigram stances ยท 70 vital points ยท 51 authentic Korean martial-arts techniques ยท 5 fighter archetypes ยท 60fps desktop / 55fps+ mobile. React 19 ยท Three.js ยท TypeScript 6 ยท Vite 8.
๐ Surfaces: Play ยท API Docs ยท Security Architecture ยท Threat Model ยท Features ยท Docs
Reference implementation of a secure web-game project: React + TypeScript + Three.js + Vite, SLSA 3, full SBOM, automated security testing, ISMS-policy mapping ready to fork.
Battle-tested reference implementation: AWS Lambda in a private VPC with VPC endpoints, CloudFront, WAF, KMS encryption, CloudTrail and Security Hub integration.
Open-source SonarQube plugin that brings CloudFormation IaC scanning into existing SonarQube/SonarCloud quality gates.
A fully public, version-controlled, machine-verifiable Information Security Management System. 38 policies covering access control, cryptography, secure development, threat modeling, vulnerability management, AI governance, GDPR privacy, EU CRA, ISO 27001:2022, NIST CSF 2.0, CIS Controls v8.1.
| Domain | Key Policies |
|---|---|
| ๐ ๏ธ Secure Development | Secure Development Policy ยท Threat Modeling ยท Vulnerability Management ยท Change Management |
| ๐ Access & Identity | Access Control Policy ยท Segregation of Duties ยท Mobile Device Management |
| ๐ Network & Crypto | Network Security Policy ยท Cryptography Policy |
| ๐พ Continuity | Backup & Recovery ยท Business Continuity Plan ยท Disaster Recovery Plan |
| ๐จ Incident | Incident Response Plan |
| ๐ค AI & LLM | AI Policy ยท OWASP LLM Security Policy |





