A. Hoffskov Consult
Denmark · owned by Independent (Denmark) · ahoffskov.dk · 5 vendors
A. Hoffskov Consult is a Danish consultancy specialising in cyber and information security, offering practical security management (governance) and risk management (GRC) tailored to each client's business. Services include ISMS establishment based on ISO 27001, risk assessment and analysis, compliance with regulations such as NIS2, DORA and CRA, security audits, and employee awareness training. The firm emphasises pragmatic, product-agnostic advice that can be realistically implemented in real-world business environments.
Resilience scores
- Digital Sovereignty: 40
- Digital Resilience: 4
- Financial Resilience: 4
Disruption prediction
A. Hoffskov Consult has an estimated 17% probability of disruption in the next 6 months.
1 of A. Hoffskov Consult's 5 vendors monitored for disruptions.
Technology vendors
- Cibicom A/S — Telecommunications — Denmark
- Veeam Software Group GmbH — Technology — United States
- Webhosting.dk — Technology — Denmark
- and 2 more
Insights
Last updated 2026-09-01 · revision 9
5 direct vendors, 126 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 2
- United States: 2
- United Kingdom: 1
Subvendors by controlling owner country (sample)
- Belgium: 1
- China: 2
- Denmark: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
A. Hoffskov Consult demonstrates high migration readiness (70/100), largely due to the absence of a legacy internal technology stack, which significantly simplifies potential migration efforts. Strengths: * No Legacy Internal Tech Stack: The most significant advantage for migration readiness is the empty "Internal Tech Stack." This indicates the firm does not operate complex, on-premise, or monolithic legacy systems that would typically pose major migration challenges. It is highly probable the firm relies on off-the-shelf SaaS solutions, which are inherently more flexible and easier to migrate between than custom-built or legacy infrastructure. * Implied Cloud-Native Operations: The lack of an internal tech stack suggests the firm is already operating in a "cloud-native" or SaaS-first manner, meaning it has fewer traditional infrastructure components to move or re-architect. Weaknesses and Challenges: * Regulatory and Data Residency Complexity: Migration efforts will be significantly impacted by GDPR Chapter V data transfer restrictions and specific data residency requirements. Any migration involving personal data or cross-border transfers (especially outside the EEA) will necessitate careful planning, Data Processing Agreements (DPAs), Standard Contractual Clauses (SCCs), and Data Transfer Impact Assessments (TIAs). This adds considerable legal and compliance overhead. * Lack of Formal ISMS for Secure Migration: The absence of organizational ISO 27001 certification suggests the firm may lack a fully structured Information Security Management System (ISMS) to guide secure migration processes, potentially increasing security risks during data transfers or system changes. * Limited Resources: As a solo consultancy, the firm has limited human and financial resources to dedicate to complex migration projects, which could slow down or constrain ambitious migration initiatives. * Vendor Lock-in (Unknown but Potentially Low): The data states "Total Vendors: 0" but also lists "Total Services: 9" with diverse vendor HQs. This inconsistency makes assessing explicit vendor lock-in difficult. However, given the likely reliance on SaaS (due to no internal tech stack), vendor lock-in is generally lower than with proprietary on-premise software. The "Vendor Lock-in Risk: Unknown" means this factor cannot be definitively assessed as a strength or weakness, but the overall tech posture leans towards flexibility.
Compliance
7 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
ISO 27001 is the internationally recognized standard for Information Security Management Systems (ISMS). While not legally mandated in Denmark, it is highly relevant for A. Hoffskov Consult for two reasons: (1) The firm explicitly offers ISO 27001 ISMS implementation as a core service, meaning clients will expect the firm to practice what it preaches; (2) NIS2-obligated clients will increasingly require their suppliers and advisors to demonstrate ISO 27001 certification or equivalent security posture under Art. 21 supply chain risk management requirements. The firm's consultant holds an ISO 27005 Risk Manager certification (evidenced on the website), demonstrating personal competence, but this is distinct from organizational ISO 27001 certification. Risk is rated Medium because: lack of ISO 27001 certification creates a credibility and competitive risk for a cybersecurity consultancy, and client contractual requirements may increasingly mandate it.
Evidence: https://ahoffskov.dk, https://ahoffskov.dk/grc/riskmanagement.html, https://www.iso.org/standard/27001, https://www.ds.dk/da/standarder/it/informationssikkerhed/iso-27001
SOC 2 (source) — Assessment Required
SOC 2 is a voluntary US auditing framework (AICPA) applicable to service organizations that store, process, or transmit customer data in the cloud. A. Hoffskov Consult is a Danish consulting firm, not a cloud service provider or SaaS company. SOC 2 is not a regulatory requirement in the EU and is not mandated by any applicable Danish or EU regulation. However, if the firm serves US-based clients or clients who require SOC 2 attestation from their vendors, there could be contractual pressure to obtain a SOC 2 report. Based on the company's profile (EU-focused, micro-enterprise, advisory services), this is unlikely but cannot be entirely ruled out. Risk is rated Low because SOC 2 is voluntary, EU-focused clients typically prefer ISO 27001 over SOC 2, and the firm's service model (advisory/consulting rather than data hosting) reduces the relevance of SOC 2 trust service criteria.
Evidence: https://ahoffskov.dk, https://www.aicpa-cima.com/resources/landing/soc-2-reporting-on-an-examination-of-controls-at-a-service-organization-relevant-to-security-availability-processing-integrity-confidentiality-or-privacy
Cyber Resilience Act (source) — Assessment Required
The EU Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements for products with digital elements placed on the EU market. It primarily targets manufacturers, importers, and distributors of hardware and software products. A. Hoffskov Consult is a pure-play consulting firm — it does not manufacture, develop, or distribute software or hardware products. Therefore, direct CRA obligations are unlikely to apply. However, the firm lists CRA advisory as a service offering, indicating it serves clients who are CRA-obligated (e.g., software vendors, IoT manufacturers). Risk is rated Low for direct applicability, but the firm should monitor CRA developments as its client base may be significantly affected.
Evidence: https://ahoffskov.dk, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202402847
Financials
Three-year financials
- null:
Financial Resilience Score: 4/10
A. Hoffskov Consult appears to be a solo Danish cybersecurity GRC consultancy operating as a micro-entity, likely under the legal name Arkimentum. No financial statements could be retrieved during the research, and as a Danish micro-entity under Regnskabsklasse B, disclosures would typically be limited to equity and possibly profit for the year, with revenue and EBIT not disclosed. This significantly limits financial transparency for external stakeholders. The business benefits from a low fixed cost base as a one-person consultancy, minimal overhead, and a strong regulatory tailwind from NIS2, DORA, and CRA regulations coming into force in 2024-2026. Recognized certifications (ISO 27001, ISO 27005) support premium pricing, and product-agnostic positioning reduces vendor dependence. However, key-person risk dominates: the entire business depends on one individual, Anders Hoffskov. Client concentration risk is high, scalability is capped by billable hours of a single consultant, and the Danish GRC advisory market is crowded with large firms (PwC, Deloitte, KPMG, Netcompany, Dubex) and independents. Overall resilience is moderate-to-low given the single-person structure, despite favorable market tailwinds.
Key strengths: Low fixed cost base as one-person consultancy, Strong regulatory tailwind from NIS2, DORA, and CRA, Recognized certifications (ISO 27001, ISO 27005 Risk Manager), Product-agnostic positioning reduces vendor dependence, Naturally high gross margin
Risk factors: Key-person risk - entire business rests on one individual, Client concentration risk typical of small consultancies, No scalability - revenue capped by billable hours of one consultant, Competitive pressure from large firms and independents, Limited financial transparency as a micro-entity, Illness or career change would immediately halt revenue
Revenue by geography
- Denmark: 100%
Revenue by product/service
- Training & awareness: 0%
- Security audit & review: 0%
- Risk assessment and analysis (ISO 27005): 0%
- Compliance and regulation (NIS2, DORA, CRA): 0%
- Information security management (ISMS / ISO 27001): 0%
Workforce by country
- Denmark: 1
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.