B4Restore A/S
Denmark · owned by CataCap III K/S (Denmark) · b4restore.com · 31 vendors
B4Restore is a leading Data Protection-as-a-Service (DPaaS) provider with over two decades of expertise in backup, storage, and business continuity. The company specializes in delivering enterprise-grade data protection services with ISO-certified Tier 3 data centers located within the EU, addressing critical security needs for organizations facing increasing cyber threats and compliance demands.
Resilience scores
- Digital Sovereignty: 23
- Digital Resilience: 8
- Financial Resilience: 6
Technology vendors
- Hewlett Packard Enterprise — Technology — United States
- Veeam Software Group GmbH — Technology — United States
- VeronaLabs — Technology — Estonia
- and 28 more
Services catalogue
1 service in catalogue across 1 category; runs on 31 sub-vendors.
- Backup Services
Insights
Last updated 2026-09-13 · revision 17
31 direct vendors, 295 subvendors
Direct vendors by controlling owner country (sample)
- New Zealand: 1
- Poland: 1
- Estonia: 1
Subvendors by controlling owner country (sample)
- Andorra: 1
- France: 7
- Bulgaria: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
B4Restore A/S exhibits moderate to high migration readiness, primarily driven by its adoption of cloud-native principles and strong API integration capabilities. The 'B4R Storage Portal' is described as a cloud-native SaaS platform for orchestration and automation, and the company supports backup for major cloud workloads (Microsoft 365, Entra ID, Azure, AWS). The use of REST APIs for integration with ITSM systems further enhances flexibility for migration. Their robust regulatory compliance framework (GDPR, ISO, NIS2/DORA readiness) and clear EU-centric data residency strategy, while a constraint, mean that migration planning can proceed with well-defined compliance requirements. However, significant challenges exist. The company's core services are delivered from on-premises Tier III data centers, indicating that a full migration to a public cloud environment would involve substantial effort to re-platform or re-host this critical infrastructure. The internal tech stack also includes WordPress, which, while adaptable, is not inherently a cloud-native microservices architecture. The vendor relationship data is inconsistent ('Total Vendors: 0' vs. 'Total Services: 40' from diverse countries), making it difficult to accurately assess vendor lock-in. If B4Restore relies on 40 external services, even with geographic diversity, the complexity of migrating or replacing these dependencies could be considerable. Without revenue data, the financial capacity to fund a large-scale migration is also an unknown, though their 'as-a-Service' business model suggests stable operations. Overall, B4Restore has the technical understanding and some cloud-native components, but its existing on-premises infrastructure and unclear vendor lock-in prevent a higher readiness score.
Compliance
9 in-scope frameworks identified; showing 3.
Danish Data Protection Act — Compliant
The Danish Data Protection Act supplements GDPR with national specifications and is mandatory for all Danish companies processing personal data. Risk is LOW because: (1) B4Restore's ISAE 3000 GDPR report covers compliance with both GDPR and its Danish national implementation; (2) the company's data protection practices are audited annually by an independent, state-authorized accountant; (3) as a Danish company with over 20 years of operation, B4Restore has long-standing familiarity with Danish data protection law; (4) the Danish Data Protection Authority (Datatilsynet) is the supervisory authority, and B4Restore's comprehensive compliance program addresses all key requirements.
Evidence: https://b4restore.com/it-security-and-compliance/iso-certified/, https://b4restore.com/wp-content/uploads/2026/01/B4Restore_ISAE_3000_GDPR_2025.pdf, https://b4restore.com/privacy-policy/
NIS2 (source) — Compliant
NIS2 is applicable to B4Restore on two distinct grounds: (1) As a provider of 'digital infrastructure' and 'ICT service management' (managed backup, storage, and business continuity services), B4Restore falls within the NIS2 scope as a digital provider/Important Entity or potentially Essential Entity depending on Danish national transposition; (2) B4Restore explicitly markets its services as NIS2-compliant and has obtained a formal ISAE 3000 NIS2 assurance report — the highest available third-party evidence of compliance. Risk is assessed as LOW because: the company has proactively embedded NIS2 Article 21 controls (backup management, business continuity, MFA, zero-trust architecture, supply-chain assurance, incident response within 72 hours) directly into its service platform; an independent state-authorized auditor has issued a 2025 ISAE 3000 NIS2 report; the company operates ISO 27001 and ISO 22301 certified infrastructure; and NIS2 compliance is a core commercial differentiator for B4Restore, meaning sustained investment in compliance is structurally incentivized. Denmark transposed NIS2 into national law (Lov om sikkerhed i net- og informationssystemer, effective October 2024). Enforcement risk is low given the depth of documented controls.
Evidence: https://b4restore.com/it-security-and-compliance/nis2-compliance/, https://b4restore.com/wp-content/uploads/2026/01/B4Restore_ISAE_3000_NIS2_2025.pdf, https://b4restore.com/it-security-and-compliance/iso-certified/, https://b4restore.com/it-security-and-compliance/nis2-compliance-scorecard/, https://b4restore.com/it-security-and-compliance/
ISAE 3000 (source) — Compliant
ISAE 3000 is directly applicable and B4Restore holds multiple active ISAE 3000 assurance reports. Risk is assessed as LOW because: (1) B4Restore obtains annual ISAE 3000 reports covering GDPR, NIS2, and DORA — three distinct assurance engagements demonstrating comprehensive third-party validation; (2) reports are prepared by independent, state-authorized accountants specializing in IT security; (3) the 2025 reports are publicly available, demonstrating transparency and ongoing compliance investment; (4) ISAE 3000 assurance is a core commercial differentiator for B4Restore and is explicitly marketed to customers as evidence of compliance; (5) the annual cadence of assurance engagements ensures continuous monitoring and remediation of any control gaps. The risk of material non-compliance is very low given the depth and breadth of assurance coverage.
Evidence: https://b4restore.com/it-security-and-compliance/iso-certified/, https://b4restore.com/wp-content/uploads/2026/01/B4Restore_ISAE_3000_GDPR_2025.pdf, https://b4restore.com/wp-content/uploads/2026/01/B4Restore_ISAE_3000_NIS2_2025.pdf, https://b4restore.com/wp-content/uploads/2026/01/B4Restore_ISAE_3402_2025.pdf, https://b4restore.com/it-security-and-compliance/
Financials
Three-year financials
- 2025: gross profit DKK 56.7M, EBIT DKK 8.76M, equity DKK 27.7M
- 2024: gross profit DKK 53.1M, EBIT DKK 4.76M, equity DKK 24.3M
- 2023: gross profit DKK 46.9M, EBIT DKK 4.06M, equity DKK 21.8M
Financial Resilience Score: 6/10
B4Restore A/S demonstrates qualitative resilience through a 20+ year operating history in a niche (enterprise backup/DR) that benefits from tightening EU regulation (NIS2, DORA, GDPR). Its recurring 'as-a-service' revenue model (BaaS, STaaS, BCaaS) implies contracted, multi-year cash flows with typically high gross retention, and its compliance moat — ISO 27001, ISO 22301 (first in Denmark), ISAE 3000 (NIS2 and DORA scoped), and ISAE 3402 — creates meaningful barriers to entry versus new competitors. However, quantitative financial data (revenue, EBIT, equity) could not be retrieved from CVR/virk.dk or Proff.dk in this session, so a precise resilience score cannot be anchored to leverage, liquidity, or profitability metrics. The score reflects qualitative strengths offset by structural risks: hyperscaler competition (AWS, Azure, Google Cloud Backup) and platform rivals (Veeam, Rubrik, Cohesity, Commvault) create pricing pressure, while Tier 3 data center operations are capital-intensive. As a small Danish specialist (~40–80 employees indicated but unverified), B4Restore likely faces customer concentration risk and limited scale versus consolidating European DPaaS platforms. Talent scarcity in Nordic cybersecurity and potential FX exposure on non-EUR expansion are additional considerations. Overall, the company appears operationally resilient within its niche but financially unverifiable without CVR filings.
Key strengths: 20+ year operating history since 2003, Recurring as-a-service revenue model (BaaS, STaaS, BCaaS), Regulatory tailwind from NIS2, DORA, and GDPR, Strong compliance moat: ISO 27001, ISO 22301 (first in Denmark), ISAE 3000, ISAE 3402, Own Tier 3 EU data centers, 70M+ backup jobs executed annually via B4R Storage Portal, Enterprise reference customers including ITER Organization, Ecosystem leverage via Debriefing Software A/S partnership
Risk factors: Hyperscaler competition (AWS, Azure, Google Cloud Backup), Platform competition from Veeam, Rubrik, Cohesity, Commvault, Capital intensity of Tier 3 data center operations, Likely customer concentration risk typical of Danish B2B specialists, Small absolute scale vs. consolidating European DPaaS platforms, Talent scarcity in Nordic cybersecurity/backup engineering, FX/expansion risk outside DKK/EUR zones
Revenue by geography
- Denmark: 0%
- Rest of EU: 0%
Revenue by product/service
- Backup-as-a-Service (BaaS): 0%
- Storage-as-a-Service (STaaS): 0%
- IT Security & Compliance Advisory: 0%
- B4R Storage Portal (SaaS orchestration): 0%
- Business Continuity-as-a-Service (BCaaS): 0%
Workforce by country
- Denmark: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.