CyberShield

Denmark · owned by Independent (Denmark) · cybershield.dk · 6 vendors

CyberShield is an independent Danish IT security consultancy that helps small and medium-sized businesses protect their data, comply with GDPR, and reduce the risk of cyberattacks. Services include IT security advisory, vulnerability testing and audits, employee awareness training, and GDPR compliance support. The company operates as a sole consultant practice, working from frameworks such as ISO 27001, NIS2, and CIS Controls.

Resilience scores

Disruption prediction

CyberShield has an estimated 17% probability of disruption in the next 6 months.

2 of CyberShield's 6 vendors monitored for disruptions.

Technology vendors

Insights

Last updated 2026-09-01 · revision 35

6 direct vendors, 142 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 2/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

CyberShield's migration readiness is low, primarily due to its existing technology stack, stringent regulatory environment, limited financial resources, and significant vendor lock-in. The core operational tech stack, heavily reliant on the TSplus suite (Remote Support, Remote Access, Advanced Security, Server Monitoring), appears to be based on traditional server-based application delivery rather than cloud-native, containerized, or microservices architectures. This would necessitate substantial re-architecture and development effort for a modern cloud migration. The regulatory environment, particularly GDPR's strict Chapter V rules on international data transfers and the strong recommendation for all personal data processing to remain within EU/EEA data centers, imposes significant constraints on the choice of cloud providers and regions, adding complexity and cost to any migration strategy. The Danish Bookkeeping Act also mandates specific data retention periods that must be upheld during migration. Financially, as a sole trader with limited disclosed growth, CyberShield likely has constrained resources to fund a complex and potentially costly migration project. Furthermore, despite the 'Vendor Relationships' section stating 'Total Vendors: 0' (which is contradictory to other data), the deep integration of TSplus into CyberShield's internal infrastructure and its product offerings (reselling TSplus products and using them for client remote support) creates substantial vendor lock-in. Migrating away from this deeply embedded vendor would be highly complex, disruptive, and expensive. While the company utilizes some cloud-friendly components like Cloudflare and a static site generator, and its small size could theoretically allow for agile decision-making, these advantages are significantly overshadowed by the technical, regulatory, financial, and vendor-related challenges.

Compliance

6 in-scope frameworks identified; showing 3.

GDPR (source) — Partially Compliant

GDPR is universally applicable to CyberShield as a Danish (EU) company that processes personal data of clients, prospects, and website visitors. The risk level is assessed as Medium rather than High because: (1) CyberShield has demonstrably implemented a detailed, GDPR-article-referenced Privacy Policy (updated April 2026), showing active compliance effort; (2) the company operates a privacy-by-design website with no tracking cookies or analytics; (3) it is a micro-enterprise (sole trader, 1 person), meaning data volumes and processing complexity are inherently low; (4) however, as a cybersecurity consultant, CyberShield may access client systems containing personal data during vulnerability assessments and audits, creating data processor obligations that require formal Data Processing Agreements (DPAs) — the adequacy of these cannot be fully verified from public sources; (5) Danish DPA (Datatilsynet) enforcement is active, with fines issued to SMEs. The residual risk is moderate: strong public-facing compliance signals exist, but processor-side obligations and internal documentation completeness are unverified.

Evidence: https://www.cybershield.dk/privatlivspolitik/, https://www.cybershield.dk/ydelser/gdpr/, https://www.cybershield.dk/, https://www.datatilsynet.dk, https://www.cybershield.dk/om/

ISO 27001 (source) — Assessment Required

ISO 27001 risk is Medium because CyberShield explicitly references ISO 27001 principles as part of its working methodology and service framework, but no formal certification has been identified. For a cybersecurity consulting firm, the absence of ISO 27001 certification creates a credibility and commercial risk — clients seeking security assurance from their security advisor may expect the advisor itself to be certified. The risk is not High because: (1) ISO 27001 certification is not legally mandated; (2) CyberShield is a micro-enterprise where full ISMS implementation may be disproportionate; (3) the company's demonstrated security practices (MFA, HTTPS/HSTS, CSP headers, privacy-by-design) show alignment with ISO 27001 principles even without formal certification. The risk is not Low because the reputational and commercial impact of lacking certification in the cybersecurity advisory market is meaningful.

Evidence: https://www.cybershield.dk/, https://www.cybershield.dk/om/, https://www.cybershield.dk/ydelser/

CIS Controls — Assessment Required

CIS Controls is a voluntary cybersecurity framework, not a legal requirement. Risk is Low. CyberShield explicitly references CIS Controls as part of its working methodology, indicating adoption of the framework in service delivery. No formal CIS certification exists, so assessment relates to implementation depth.

Evidence: https://www.cybershield.dk/, https://www.cisecurity.org/controls

Financials

Three-year financials

Financial Resilience Score: 5/10

CyberShield is a Danish sole proprietorship (enkeltmandsvirksomhed) operated by Henrik K. Sørensen under CVR 26243157. Because Danish sole proprietorships are not required to file annual reports with Erhvervsstyrelsen, no public revenue, EBIT, or equity figures exist for the last three fiscal years, making a quantitative resilience assessment impossible. Any specific numbers would be fabricated. Qualitatively, the business has a very low fixed-cost base (no staff payroll, minimal premises overhead), giving it a low break-even point and high cash conversion on billable hours. The owner has been active in Danish IT since 1991, and the entity has been registered for roughly two decades, indicating survival through multiple economic cycles. Market tailwinds from NIS2, GDPR compliance, awareness training, and vulnerability testing support ongoing SME demand. However, resilience is capped by absolute key-person risk: the business is fully dependent on one person, with no team to absorb workload if the owner becomes unavailable. As a sole proprietorship, the owner bears unlimited personal liability, and there is no visible equity cushion. Revenue is also bounded by one consultant's billable capacity (~1,500–1,800 hrs/yr), and larger customers or public tenders may reject bids lacking audited financials or minimum equity requirements.

Key strengths: Very low fixed-cost base with minimal overhead as a one-person consultancy, Long operator tenure (owner active in Danish IT since 1991), Entity registered for roughly two decades, indicating survival through cycles, Favorable market tailwind from NIS2, GDPR, and cybersecurity demand among Danish SMEs, Independent positioning without vendor kickback model, Recognized affiliations: IT-Branchens IT-Sikkerhedsudvalg, Defend Denmark, prior NC3 collaboration

Risk factors: Absolute key-person risk — business is entirely dependent on Henrik K. Sørensen, Unlimited personal liability as an enkeltmandsvirksomhed with no equity cushion, Scale ceiling bounded by one consultant's billable capacity (~1,500–1,800 hrs/yr), Concentration risk on Danish SMEs, sensitive to macro slowdowns and IT budget cuts, Opaqueness to procurement — cannot supply audited accounts for larger tenders, No public financial disclosure available for counterparty due diligence

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report