Cybercom Group

Sweden · www.knowit.eu · 32 vendors

Knowit AB is a Nordic consultancy company that supports organizations in their digital transformation. The company offers a unique combination of expertise in strategy, creativity, and technology to develop innovative and sustainable digital solutions. Their services encompass system development, data-driven customer experiences, cloud services, cybersecurity, and management consulting.

Resilience scores

Technology vendors

Insights

Last updated 2026-07-30 · revision 5

32 direct vendors, 337 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Cybercom Group exhibits a good level of migration readiness, primarily driven by its strong technological foundation. The internal tech stack is highly modern and cloud-native, featuring tools like Microsoft Azure, Docker, Kubernetes, Terraform, Azure DevOps, GitHub, and GitLab CI/CD. This robust infrastructure is well-suited for agile and efficient cloud migrations. The company also possesses expertise in multiple major cloud platforms (Azure, AWS, GCP), providing significant flexibility in choosing migration targets. Despite the contradictory 'Total Vendors: 0' data point, the information on 'Total Services: 52' and 'Vendor Geographic Diversity: 11 unique countries' suggests a diverse vendor landscape. This diversity typically reduces vendor lock-in, simplifying the process of migrating services and data. However, several factors introduce complexity and potential challenges to migration. The most significant are the regulatory compliance gaps, with GDPR, NIS2, SOC2, and ISO 27001 all requiring assessment and lacking audit evidence. Addressing these compliance requirements, especially concerning data security, privacy, and cross-border transfers, will add considerable complexity, cost, and potential delays to any migration project. Furthermore, EU data residency requirements under GDPR necessitate careful planning for data placement and transfer mechanisms to ensure ongoing compliance. The 'Vendor Lock-in Risk' remains unknown, which could pose unforeseen challenges, although the apparent vendor diversity mitigates this to some extent.

Compliance

4 in-scope frameworks identified; showing 3.

GDPR (source) — Assessment Required

GDPR applies to all companies in the EU/EEA that process personal data. As a Swedish technology company, Cybercom Group is subject to GDPR with high certainty. The risk level is High because: (1) GDPR fines can reach up to 4% of annual global turnover or €20 million, whichever is higher; (2) Technology companies typically process significant amounts of personal data including employee, customer, and user data; (3) Swedish Data Protection Authority (IMY) actively enforces GDPR; (4) Technology sector faces heightened scrutiny for data processing practices.

NIS2 (source) — Assessment Required

NIS2 applicability depends on specific technology services provided and company size. The risk level is Medium because: (1) If applicable, non-compliance can result in significant fines up to €10 million or 2% of annual global turnover; (2) Technology companies may qualify as 'digital service providers' or 'ICT service management' entities under NIS2; (3) Size threshold requirements (50+ employees or €10M+ turnover) are unknown; (4) Enforcement is still developing across EU member states.

SOC 2 (source) — Assessment Required

SOC2 applicability depends on whether Cybercom Group provides cloud services or SaaS solutions to customers. The risk level is Medium because: (1) While not legally mandated, SOC2 compliance is often contractually required by enterprise customers; (2) Lack of SOC2 certification can result in lost business opportunities and reduced customer trust; (3) Technology service providers increasingly need SOC2 to compete in enterprise markets; (4) Implementation costs and audit requirements represent moderate business impact.

Financials

Three-year financials

Financial Resilience Score: 6/10

Cybercom Group operated as a mid-sized Nordic IT consultancy with stable revenue around SEK 1.4-1.5 billion and approximately 1,200-1,300 employees in the years leading up to its 2022 acquisition by Knowit AB. The company demonstrated resilience by recovering from a strained post-financial-crisis balance sheet (2008-2012) through restructuring under JCE Group ownership, and maintained steady performance after being taken private in 2017. Its asset-light consulting model, diversified client base across public sector, telecom, energy, banking, and manufacturing, and Nordic scale provided a solid foundation. However, as a privately held company during 2017-2021, detailed profitability and equity figures were not publicly disclosed beyond Bolagsverket filings, limiting transparency. Following integration into the listed Knowit AB, the combined entity benefits from access to capital markets and audited disclosure, but faces cyclical headwinds in Nordic IT consulting demand (2023-2024 slowdown), wage inflation, and integration risks. Goodwill from acquisitions also poses impairment risk if margins remain depressed.

Key strengths: Nordic scale with ~4,000+ consultants in combined Knowit+Cybercom entity, Diversified client base across public sector, telecom, energy, banking, manufacturing, Sustainability positioning ('Sustainable Connected Society') appealing to Nordic public-sector buyers, Listed parent (Knowit) provides access to capital markets and audited disclosure, Asset-light consulting model with low capex and scalability, Stable revenue ~SEK 1.4-1.5 bn during 2017-2021 private ownership period

Risk factors: Cyclical demand for IT consulting with 2023-2024 Nordic-wide slowdown, Integration risk from overlapping practice areas between Cybercom and Knowit, Wage inflation in tight Nordic IT labor market outpacing billable rate increases, Geographic concentration in Sweden with SEK/NOK currency exposure, Significant goodwill on balance sheet from acquisitions with impairment risk, Dependence on Swedish public-sector budgets

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report