CyberPilot ApS
Denmark · owned by Optus 1047 GmbH (Germany) · cyberpilot.io · 50 vendors
CyberPilot is a Danish cybersecurity company specializing in security awareness training and phishing simulation training for small and medium-sized businesses. Their platform provides interactive courses, simulated phishing attacks, and security culture assessments to help organizations reduce human-related cyber risks. They serve over 1,000 companies across multiple European markets including Denmark, Norway, Germany, the Netherlands, and Sweden.
Resilience scores
- Digital Sovereignty: 24
- Digital Resilience: 5
- Financial Resilience: 6
Disruption prediction
CyberPilot ApS has an estimated 17% probability of disruption in the next 6 months.
17 of CyberPilot ApS's 50 vendors monitored for disruptions.
Technology vendors
- OneLogin — Cybersecurity — United States
- Stripe, Inc. — Financial Services — United States
- Usercentrics GmbH — Technology — Germany
- and 51 more
Insights
Last updated 2026-09-13 · revision 79
50 direct vendors, 389 subvendors
Direct vendors by controlling owner country (sample)
- Switzerland: 1
- Austria: 1
- Denmark: 2
Subvendors by controlling owner country (sample)
- Japan: 5
- Israel: 2
- Canada: 11
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
CyberPilot ApS demonstrates a high degree of migration readiness, primarily driven by its existing cloud-native architecture. The core "CyberPilot Platform" is a centralized SaaS platform hosted on Amazon Web Services (AWS), indicating a modern, scalable, and flexible infrastructure that is inherently well-suited for migration. This eliminates the significant challenges associated with migrating legacy on-premise systems. Furthermore, the company extensively utilizes various Software-as-a-Service (SaaS) solutions for its internal tech stack, such as HubSpot, PostHog, and Gong. These services are already managed by external vendors, effectively offloading their migration burden and simplifying the company's internal infrastructure footprint. While the platform is cloud-native, a migration away from AWS to a different cloud provider would still require careful planning, especially if CyberPilot leverages AWS-specific services that would need re-architecting or replacement. The company's operations across multiple EU/EEA countries necessitate strict adherence to GDPR and data residency requirements, meaning any migration strategy must ensure continued compliance with data protection and transfer regulations, potentially requiring data to remain within specific geographic boundaries. The financial stability to fund a significant migration is not fully ascertainable due to missing revenue concentration data. Although the overall vendor landscape shows good geographic diversity (10 unique countries), the explicit "Vendor Lock-in Risk: Unknown" for critical services like AWS means this factor needs further assessment to fully understand potential complexities and costs associated with changing core infrastructure providers. Despite these considerations, the fundamental cloud-native nature of its primary platform positions CyberPilot ApS favorably for future migration initiatives.
Compliance
7 in-scope frameworks identified; showing 3.
ePrivacy Directive — Partially Compliant
The ePrivacy Directive (implemented in Denmark via the Danish Executive Order on Electronic Communications Networks and Services) governs the use of cookies and electronic marketing. CyberPilot's website uses multiple cookie categories including targeting/advertising cookies (Facebook 'fr', Google AdSense '_gcl_au', Leadfeeder '_lfa'). Their privacy policy provides a cookie consent mechanism and lists cookies by category. Risk is Low because: (1) a cookie consent mechanism is in place; (2) the company is in the cybersecurity sector and demonstrates awareness of privacy requirements; (3) Datatilsynet's cookie enforcement has focused on larger organizations. Risk is not negligible because the cookie policy does not clearly indicate whether consent is obtained before non-essential cookies are set, and Leadfeeder (B2B visitor tracking) raises specific consent questions.
Evidence: https://www.cyberpilot.io/privacy-policy, https://www.datatilsynet.dk/english/cookies, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32002L0058
Danish Data Protection Act — Partially Compliant
The Danish Data Protection Act (Act No. 502 of 23 May 2018, as amended) supplements GDPR with national specifications applicable to all Danish data controllers and processors. CyberPilot, as a Danish company, is directly subject to this law. Key Danish-specific provisions include stricter rules on processing of sensitive data, specific rules on employee monitoring (relevant given CyberPilot's phishing simulation services which track employee behavior), and mandatory registration requirements for certain processing activities. Risk is Medium because: (1) phishing simulations involve monitoring employee email behavior, which may trigger specific employee surveillance provisions under Danish law; (2) Datatilsynet has been active in enforcement against Danish companies; (3) the company's privacy policy references Datatilsynet but does not detail compliance with Danish-specific provisions.
Evidence: https://www.cyberpilot.io/privacy-policy, https://www.datatilsynet.dk/english, https://www.retsinformation.dk/eli/lta/2018/502, https://www.datatilsynet.dk/afgoerelser
ISAE 3000 (source) — Assessment Required
ISAE 3000 is an international assurance standard used by auditors to provide independent assurance on non-financial information, including IT controls, sustainability reports, and compliance statements. In the Danish/Nordic context, ISAE 3402 (assurance on controls at service organizations) is commonly used as an alternative to SOC 2 for EU-based cloud and SaaS providers. CyberPilot, as a SaaS provider processing customer data, could benefit from an ISAE 3000/3402 report to provide customers with independent assurance over their controls. Risk is Low because: (1) ISAE 3000/3402 is voluntary; (2) it is more commonly required by larger enterprise or financial sector clients; (3) CyberPilot primarily targets SMEs where such assurance reports are less commonly demanded; (4) GDPR compliance and privacy policy may suffice for their current customer base.
Evidence: https://www.iaasb.org/publications/international-standard-assurance-engagements-isae-3000-revised-assurance-engagements-other-audits, https://www.cyberpilot.io/privacy-policy, https://www.cyberpilot.io/cases
Financials
Three-year financials
- 2025: gross profit DKK 22.2M, EBIT DKK 621K, equity DKK -5.26M
- 2024: gross profit DKK 19.4M, EBIT DKK 657K, equity DKK -5.73M
- 2023: gross profit DKK 11.6M, EBIT DKK -4.74M, equity DKK -5.01M
Financial Resilience Score: 6/10
CyberPilot ApS operates a recurring SaaS revenue model in cybersecurity awareness training, which typically provides revenue visibility and high gross margins. The company benefits from strong regulatory tailwinds including GDPR, NIS2 (effective in Denmark from 2024/2025), and DORA, all of which mandate security awareness training. A diversified customer base of over 1,000 companies, including blue-chip references like Sparekassen Kronjylland, Sport24, HiFi Klubben, and DTU, reduces single-customer concentration risk. The company appears to be bootstrapped/founder-owned with a capital-efficient, content-led inbound marketing motion, suggesting steady rather than hyper-growth. However, as a Class B ApS, actual financial figures (revenue, EBIT, equity) could not be retrieved in this session, limiting the ability to numerically assess resilience. ApS structures typically have modest equity buffers, and the company operates in a crowded competitive landscape with rivals including KnowBe4, Hoxhunt, Junglemap/Nimblr, Moxso, and Proofpoint, creating pricing pressure. Talent cost inflation in the Danish tech labor market and SME customer churn sensitivity in economic downturns present additional risks. FX exposure exists as revenue expands into NOK, SEK, and EUR while costs remain in DKK.
Key strengths: Recurring SaaS revenue model with high gross margins, Diversified customer base of 1,000+ companies, Regulatory tailwinds from GDPR, NIS2, and DORA, Multi-language product footprint (6 languages) enabling European expansion, Blue-chip reference customers across banking, retail, and public sector, Capital-efficient bootstrapped growth model
Risk factors: Small-cap/undercapitalised private company with modest equity buffer, Crowded competitive landscape with pricing pressure, Talent cost inflation in Danish tech labour market, SME customer churn sensitivity in economic downturns, FX exposure across NOK, SEK, EUR revenue vs DKK costs, Limited public financial disclosure as Class B ApS
Revenue by geography
- Denmark: 0%
- DACH/Benelux: 0%
- Other Nordics (NO, SE): 0%
Revenue by product/service
- Awareness Training: 0%
- Phishing Training/Campaigns: 0%
- Security Culture Assessment: 0%
Workforce by country
- Denmark: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.