Campfire Security ApS

Denmark · owned by Independent (Denmark) · campfiresecurity.dk · 10 vendors

Campfire Security ApS is a Danish cybersecurity training company that provides hands-on, gamified cyber security education for IT professionals and organisations through its Bonfire platform. The company grew out of research at Aalborg University and offers virtual labs covering real-world threats across 12 security competency areas. It is trusted by 40+ Danish companies and public institutions, with offices in Aarhus and Copenhagen.

Resilience scores

Technology vendors

Insights

Last updated 2026-09-15 · revision 8

10 direct vendors, 226 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Campfire Security ApS exhibits medium to high migration readiness. A key strength is its modern, cloud-native tech stack, utilizing Microsoft Azure and Next.js, along with browser-based virtual labs and AI-assisted mentoring. This suggests a highly adaptable and modular architecture for its core platform. Furthermore, the company maintains strong EU-centric data residency for its primary platform data (Azure West Europe, Hetzner Germany), which simplifies compliance with EU data localisation preferences for its core service. However, migration readiness is tempered by several factors. There is significant vendor lock-in due to reliance on several US-based SaaS vendors (HubSpot for CRM, Mailchimp for marketing, Stripe for payments) for core business operations. Migrating away from these integrated services would involve substantial effort in data migration, process re-engineering, and potential disruption. The complex regulatory environment, particularly managing GDPR Chapter V requirements for cross-border data transfers and the legal uncertainties surrounding the EU-US DPF, adds complexity to any migration involving changes to these vendor relationships or data flows. The EU AI Act also introduces new compliance considerations for the AI Mentor. Finally, while growing, the company is still relatively small (7 employees, DKK 2.77M gross profit in 2025), which could limit its ability to fund a large-scale, complex migration project without significant impact on operations.

Compliance

4 in-scope frameworks identified; showing 3.

Digital Services Act — Assessment Required

The company provides an online platform where users can interact and potentially share content. This could classify them as a 'hosting service' and therefore an 'intermediary service provider' under the DSA.

The risk is likely low as their platform is for professional training and not a major public forum for user-generated content, making the most stringent obligations unlikely to apply. However, non-compliance with applicable provisions can still lead to penalties.

Evidence: https://artificialintelligenceact.eu/high-level-summary/, https://www.modelop.com/ai-governance/ai-regulations-standards/eu-ai-act, https://www.dpo-consulting.com/blog/eu-ai-act, https://qz.com/what-is-eu-ai-act, https://safetica.com/resources/blogs/the-eu-ai-act-the-scope-purpose-and-how-to-comply

NIS2 (source) — Assessment Required

The company provides cybersecurity services to Danish public sector entities, which may be considered 'Essential' or 'Important' under NIS2. However, with 21 employees, they are below the 50-employee threshold, making applicability dependent on their annual turnover exceeding EUR 10 million.

If applicable, non-compliance could result in significant fines and reputational damage, especially given their cybersecurity focus. The company's small size makes full compliance challenging, increasing the risk of falling short.

Cyber Resilience Act (source) — Assessment Required

The company develops and provides a software platform for cybersecurity training, which falls under the definition of a 'product with digital elements' covered by this regulation.

As a provider of a software-based training platform, non-compliance could lead to market withdrawal and fines. The regulation is new, and the company's preparedness is unknown.

Evidence: https://artificialintelligenceact.eu/high-level-summary/, https://www.kusari.dev/learning-center/eu-cyber-resilience-act/, https://www.dpo-consulting.com/blog/eu-ai-act, https://www.pinsentmasons.com/out-law/guides/guide-to-high-risk-ai-systems-under-the-eu-ai-act, https://www.avixa.org/explore/articles/cyber-resilience-act, https://www.european-cyber-resilience-act.com/Cyber_Resilience_Act_Article_2.html

Financials

Three-year financials

Financial Resilience Score: 4/10

Campfire Security ApS is a young Danish cybersecurity spin-out from Aalborg University in a scale-up phase. FY 2025 shows a deliberate swing from a modest profit (DKK +191K in the 15-month FY 2024 stub) to a DKK -1.93M net loss, driven by aggressive hiring (average FTE rose from 2 to 7, registered headcount ~21 by year-end). Equity was rebuilt roughly 9x from DKK 231K to DKK 2.10M, implying a fresh capital injection of approximately DKK 3.8M during 2025 that more than absorbed the loss and lifted solvency to ~36.1% (from 24.8%). Liquidity metrics are strong (third-party liquidity ratio 562.6%, rated 'very good'), and the company benefits from institutional validation via InnoFounder and Aalborg University, a strong regulatory tailwind from EU NIS2, and a highly credentialed founder team including Denmark's first professor of cybersecurity. However, the equity cushion of DKK 2.10M would be exhausted in roughly one year at the current burn rate absent revenue acceleration or further capital raises. The accounts are unaudited (Class B, audit opted out), revenue is undisclosed, and the business is single-country (Denmark), founder-led with only $112K in external capital raised, creating meaningful key-person and concentration risks. Overall resilience is adequate but not comfortable — sufficient short-term liquidity but limited buffer against continued losses.

Key strengths: Equity recapitalized ~9x to DKK 2.10M despite DKK 1.93M loss, implying ~DKK 3.8M fresh capital injection in 2025, Strong liquidity ratio of 562.6% (rated 'very good'), Solvency ratio improved to 36.1% in 2025 from 24.8% in 2024, Institutional backing from InnoFounder and Aalborg University, Regulatory tailwind from EU NIS2 driving cybersecurity training demand, Strong academic anchor and IP license from Aalborg University, Highly credentialed founder team including Denmark's first professor of cybersecurity, Gross profit growth of 54.7% (understated as prior period was 15 months)

Risk factors: Cash-burning growth stage with DKK -1.93M net loss in FY 2025, Thin equity cushion of DKK 2.10M — roughly 1 year runway at current burn, Return on assets deteriorated from +20.5% to -33.3%, Accounts unaudited (Regnskabsklasse B, audit opted out), Key-person risk with small team (~7 avg FTE) and founders holding university appointments, Revenue undisclosed, limiting external visibility into commercial momentum, Market concentration risk — essentially 100% Danish revenue base, Product concentration in single vertical (cybersecurity training), Only $112K raised externally — dependent on continued shareholder support

Revenue by geography

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report