ACI Risk Measure

Denmark · owned by Independent (Denmark) · www.acirm.dk · 12 vendors

ACI Risk Measure is a Danish company specializing in quantitative IT risk management and cyber risk quantification (CRQ), helping organizations understand their cyber risks in financial terms (DKK). They provide services that translate complex IT risks into actionable financial insights to support informed decision-making at board and executive level. As of December 2025, the company also acquired Danish Cyber Defence from Danish Cyber Collective.

Resilience scores

Disruption prediction

ACI Risk Measure has an estimated 17% probability of disruption in the next 6 months.

8 of ACI Risk Measure's 12 vendors monitored for disruptions.

Technology vendors

Insights

Last updated 2026-09-13 · revision 2

12 direct vendors, 171 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

ACI Risk Measure exhibits medium migration readiness, leaning towards the lower end of the spectrum. Key challenges include the limited visibility into their core 'Internal Tech Stack', with only WordPress listed for their public website. This suggests a potentially traditional or monolithic infrastructure, which is typically not indicative of cloud-native, containerized, or microservices architectures, thereby complicating migration efforts. The company's strong focus on numerous regulatory compliance frameworks (NIS2, DORA, GDPR, ISO, NIST CSF) means any migration would need to meticulously adhere to these requirements, adding significant complexity, cost, and time to the process. Financial stability (revenue concentration, growth history) is unknown due to missing data, making it impossible to assess the company's capacity to fund a potentially costly migration. Regarding vendor relationships, assuming the vendor data (despite the 'Total Vendors: 0' contradiction) indicates actual relationships, the 'Total Services: 20' provided by vendors from 2 countries could imply a moderate level of vendor lock-in if these services are deeply integrated and provided by a limited number of unique vendors. This would increase the complexity and potential cost of migrating away from these services or vendors. 'Vendor Lock-in Risk' is explicitly 'Unknown'. On the positive side, 'Data Residency Requirements' are 'Not specified', meaning there are no explicit constraints identified that would inherently hinder migration, though this could change upon further investigation.

Compliance

5 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 is highly relevant for cybersecurity consulting firms as it demonstrates information security management capabilities. While not legally mandatory, it's often required by enterprise clients and enhances credibility. ACI Risk Measure's business model and client base in regulated industries would benefit significantly from ISO 27001 certification.

Evidence: https://www.acirm.dk/en/services/

ISAE 3000 (source) — Compliant

ACI Risk Measure has successfully obtained ISAE 3402 Type 1 certification from Grant Thornton, demonstrating compliant control design. This significantly reduces operational and reputational risks while enhancing client confidence. The certification covers their service delivery framework and qAp platform operations.

Evidence: https://www.acirm.dk/aci-risk-measure-opnaar-isae-3402-erklaering/

SOC 2 (source) — Assessment Required

SOC2 is relevant for service organizations that store customer data in the cloud. ACI Risk Measure operates a cloud-based platform (qAp) and provides managed services to clients, making SOC2 compliance valuable for client assurance. While not legally mandatory, it's increasingly expected by enterprise clients for cloud service providers.

Evidence: https://www.acirm.dk/aci-risk-measure-opnaar-isae-3402-erklaering/

Financials

Three-year financials

Financial Resilience Score: 5/10

ACI Risk Measure ApS operates in a high-growth, regulation-driven niche (cyber risk quantification) with strong structural tailwinds from NIS2, DORA, and GDPR compliance mandates. Its reported penetration of approximately 50% of Danish banks and approximately 30% of Danish pension funds is exceptional for a firm of roughly 20 employees, suggesting deep client relationships, high switching costs, and a defensible market position built over 16+ years via the predecessor ACI A/S. The flagship SARA product is structured as an annual recurring assessment, and the Managed Cyber Risk service line further supports predictable, subscription-like revenue — both positive indicators of revenue quality and cash flow stability. However, the company's financial resilience cannot be fully assessed due to the complete absence of publicly accessible filed accounts (revenue, EBIT, equity). No quantitative financial data was confirmed from any accessible source. The score of 5 reflects this fundamental uncertainty: the qualitative picture is encouraging, but without balance sheet data, profitability metrics, or leverage information, it is impossible to confirm whether the company is financially sound or under stress. The two acquisitions completed within a single calendar year (ACI A/S in January 2025, Danish Cyber Defence A/S in December 2025) represent a significant strategic acceleration but also introduce material integration and financing risks. The funding structure of these acquisitions — whether debt, equity, or deferred consideration — is entirely unknown, and leverage could be a significant concern for a ~20-person firm executing two deals in 12 months. Integration complexity at this scale is a genuine operational risk. At approximately 20 employees, the company is pre-scale and highly exposed to key-person risk, revenue concentration in a small number of senior consultants, and limited capacity to absorb large contracts or unexpected cost shocks. Geographic and sector concentration in Danish financial services, while a strength today, also represents a vulnerability if that sector reduces compliance spending or if larger competitors (Big Four, global cybersecurity firms) intensify their focus on the Danish market.

Key strengths: Approximately 50% of Danish banks and approximately 30% of Danish pension funds reported as clients — exceptional market penetration for firm size, Recurring revenue model via annual SARA assessments and Managed Cyber Risk service line, Strong regulatory tailwinds from NIS2, DORA, and GDPR driving mandatory demand, ISAE 3402 assurance statement verified by Grant Thornton — credibility signal for institutional clients, 16+ years of combined operational history via predecessor ACI A/S, Proprietary quantitative cyber risk platform creating IP moat and client switching costs, Strategic acquisitions (ACI A/S, Danish Cyber Defence) expanding capability and client base, High-profile governance addition (Søren Pind, former Minister of Justice) enhancing reputational capital

Risk factors: No publicly accessible financial data — balance sheet health, profitability, and leverage entirely unknown, Very small scale (~20 employees) with high key-person dependency and limited capacity buffer, Two acquisitions in 12 months create significant integration risk and potential balance sheet stress from unknown acquisition financing, Geographic and sector concentration in Danish financial services, Competitive pressure from larger players (Big Four, global cybersecurity firms) with greater sales and marketing resources, Regulatory dependency — demand partly driven by NIS2/DORA compliance deadlines that may moderate post-initial wave, Revenue likely highly concentrated in a small number of senior consultants

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report