Pontus JohnsonView profile
Professor
Pontus Johnson is a Professor at the KTH Royal Institute of Technology in Stockholm, Sweden. He leads the Center for Cyber Defense and Information Security (collaborating with Swedish Armed Forces, FRA, MSB, FOI, FHS) and serves as vice director of Cybercampus Sweden since 2024. His research focuses on cybersecurity , enterprise architecture analysis , and probabilistic threat modeling , particularly through his development of the Meta Attack Language (MAL) for simulating cyber attacks on networked systems. Education: MSc in Computer Science, Lund Institute of Technology (1997) PhD in Computer Science, KTH (2002) Docent title, KTH (2007) Leadership Roles: Director, Center for Cyber Defense and Information Security (2013–present) Vice Director, Cybercampus Sweden (2024–present) Board Member, Swedish Research Council (2025–present) Deputy Chair, Swedish Royal Academy of Engineering Sciences (IVA) Board (2024–present) His work spans cybersecurity research , attack simulation methodologies , and enterprise architecture frameworks . He has developed tools like securiCAD (acquired by Google) and pwnPr3d for probabilistic threat modeling. His 15 most recent publications highlight advancements in graph-based attack simulations , automated security assessments , and AI applications in cyber defense . Scientific recognition includes: Listed among Tech Awards Sweden's 50 Most Influential People in Swedish Tech (2022, 2023) Discovery of vulnerability in the Universal Turing Machine (2021) He supervises 16 PhD students and alumni (2005–2024), including Simon Gökstorp , Jakob Nyberg , and Sotirios Katsikeas . His academic service includes over 50 program committee roles and leadership positions in international conferences. He contributes to both academic and public domains through media appearances (SVT, Aftonbladet), courses in ethical hacking , and industry collaboration via his role at Google (20% of his time). His research group Software Systems Architecture and Security (SSAS) focuses on predictive security frameworks and system-of-systems analysis.










